Acquisition of security information for relay discovery
By acquiring and sending secure information for relay discovery between network equipment and terminal equipment, the difficulty of sharing and verification of secure information in the relay discovery process between different HPLMNs in the 5G ProSe UE to network relay function is solved, and a secure and effective relay discovery process is achieved.
Patent Information
- Application Number
- CN202280101751.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-13
- Publication Date
- 2025-06-27
AI Technical Summary
In the 5G ProSe UE to network relay function, remote UE and U2N relay are difficult to obtain and use security information during the relay discovery process between different public land mobile networks (HPLMNs), resulting in difficulty in sharing and verifying security information.
Provides a solution to obtain security information for relay discovery through communication between network devices and terminal devices. The specific steps include: receiving a request related to the relay service code (RSC) from the terminal device, obtaining an identification based on the request, using the identification and RSC to obtain a security information set, and sending the security information set to the terminal device.
It realizes the secure discovery and verification of the relay terminal equipment between remote UE and U2N relays between different HPLMNs, ensuring the security and effectiveness of the relay process.
Smart Images

Figure CN120226444A_ABST
Abstract
Description
Technical Field
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunications, and in particular, to a device, method, apparatus, and computer-readable storage medium for obtaining security information for relay discovery. Background Art
[0002] The fifth-generation (5G) system supports the proximity-based service (ProSe) function. The 5G ProSe function may include 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-to-network (U2N) relay. In the 5G ProSe UE-to-network relay function, a remote user equipment (UE) may connect to a UE-to-network relay via a PC5 interface with 5G ProSe direct communication, and communicate with a data network via the UE-to-network relay and the 5G network. To perform 5G ProSe direct communication between a remote UE and a U2N relay, the remote UE and the U2 relay may use security information for relay discovery to perform a 5G ProSe direct discovery process. Summary of the Invention
[0003] Generally, example embodiments of the present disclosure provide a solution for obtaining security information for relay discovery.
[0004] In a first aspect, a first network device in a first home public land mobile network (HPLMN) is provided. The first network device includes at least one processor and at least one memory storing instructions. When the instructions are executed by the at least one processor, the instructions cause the first network device to at least: receive, from a terminal device served by the first network device, a first request for security information for relay discovery, the first request including at least a relay service code (RSC); obtain at least one identifier based on the first request, each identifier in the at least one identifier being for at least one of at least one group of target relay terminal devices supporting the RSC; obtain at least one set of security information based on the at least one identifier and the RSC, each set in the at least one set of security information being associated with at least one of at least one group of target relay terminal devices; and send the at least one set of security information to the terminal device.
[0005] In a second aspect, a terminal device is provided. The terminal device includes at least one processor and at least one memory storing instructions. When the instructions are executed by the at least one processor, the instructions cause the terminal device to at least: send a request for security information for relay discovery to a network device in a home public land mobile network (HPLMN), the request including at least a relay service code (RSC); receive at least one set of security information from the network device, each set in the at least one set of security information being associated with at least one of at least one group of target relay terminal devices supporting the RSC; and perform relay discovery based on the at least one set of security information.
[0006] In a third aspect, a first policy control function (PCF) device in a first home public land mobile network (HPLMN) is provided. The first PCF device includes at least one processor and at least one memory storing instructions. When the instructions are executed by the at least one processor, the instructions cause the first PCF device to at least: receive a second request for at least one identifier from a first network device in the first HPLMN, each identifier in the at least one identifier being for at least one of at least one group of target relay terminal devices supporting a relay service code (RSC), the second request including at least the RSC; obtain the at least one identifier based on the second request; and send a second response to the second request to the first network device, the second response including at least the at least one identifier.
[0007] In a fourth aspect, a second network device in a second home public land mobile network (HPLMN) is provided. The second network device includes at least one processor and at least one memory storing instructions. When the instructions are executed by the at least one processor, the instructions cause the second network device to at least: receive a third request for at least one second set of security information for a relay service code (RSC) from a first network device in a first HPLM, the request including at least the RSC, the second HPLMN being different from the first HPLMN; obtain the at least one second set of security information based on the third request; and send a third response to the first network device, the third response including at least the at least one second set of security information.
[0008] In a fifth aspect, a second policy control function (PCF) device in a second home public land mobile network (HPLMN) is provided. The second PCF device includes at least one processor and at least one memory storing instructions. When the instructions are executed by the at least one processor, the instructions cause the second PCF device to at least: receive a request for at least one identifier, each identifier in the at least one identifier being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; obtain the at least one identifier based on the request; and send a response to the request, the response including at least the at least one identifier.
[0009] In a sixth aspect, an apparatus is provided. The apparatus includes: means for receiving, at a first network device in a first home public land mobile network (HPLMN), a first request for security information for relay discovery from a terminal device served by the first network device, the first request including at least a relay service code (RSC); means for obtaining at least one identifier based on the first request, each of the at least one identifier being for at least one of at least one group of target relay terminal devices supporting the RSC; means for obtaining at least one set of security information based on the at least one identifier and the RSC, each of the at least one set of security information being associated with at least one of at least one group of target relay terminal devices; and means for sending the at least one set of security information to the terminal device.
[0010] In a seventh aspect, an apparatus is provided. The apparatus includes: means for sending, from a terminal device to a network device in a home public land mobile network (HPLMN), a request for security information for relay discovery, the request including at least a relay service code (RSC); means for receiving at least one set of security information from the network device, each of the at least one set of security information being associated with at least one of at least one group of target relay terminal devices supporting the RSC; and means for performing relay discovery based on the at least one set of security information.
[0011] In an eighth aspect, an apparatus is provided. The apparatus includes: means for receiving, at a first policy control function (PCF) device in a first home public land mobile network (HPLMN), a second request for at least one identifier from a first network device in the first HPLMN, each of the at least one identifier being for at least one of at least one group of target relay terminal devices supporting a relay service code (RSC), the second request including at least the RSC; means for obtaining the at least one identifier based on the second request; and means for sending a second response to the second request to the first network device, the second response including at least the at least one identifier.
[0012] In a ninth aspect, an apparatus is provided. The apparatus includes: means for receiving, at a second network device in a second home public land mobile network (HPLMN), a third request for at least one second set of security information for a relay service code (RSC) from a first network device in a first HPLM, the request including at least the RSC, the second HPLMN being different from the first HPLMN; means for obtaining the at least one second set of security information based on the third request; and means for sending a third response to the first network device, the third response including at least the at least one second set of security information.
[0013] In a tenth aspect, an apparatus is provided. The apparatus includes: components for receiving, at a second PCF device in a second home public land mobile network (HPLMN), a request for at least one identifier, each of the at least one identifier being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; components for obtaining the at least one identifier based on the request; and components for sending a response to the request, the response including the at least one identifier.
[0014] In an eleventh aspect, a method is provided. The method includes: at a first network device in a first home public land mobile network (HPLMN), receiving, from a terminal device served by the first network device, a first request for security information for relay discovery, the first request including at least a relay service code (RSC); obtaining at least one identifier based on the first request, each of the at least one identifier being for at least one of at least one group of target relay terminal devices supporting the RSC; obtaining at least one set of security information based on the at least one identifier and the RSC, each of the at least one set of security information being associated with at least one of at least one group of target relay terminal devices; and sending the at least one set of security information to the terminal device.
[0015] In a twelfth aspect, a method is provided. The method includes: sending, from a terminal device to a network device in a home public land mobile network (HPLMN), a request for security information for relay discovery, the request including at least a relay service code (RSC); receiving, from the network device, at least one set of security information, each of the at least one set of security information being associated with at least one of at least one group of target relay terminal devices supporting the RSC; and performing relay discovery based on the at least one set of security information.
[0016] In a thirteenth aspect, a method is provided. The method includes: at a first policy control function (PCF) device in a first home public land mobile network (HPLMN), receiving, from a first network device in the first HPLMN, a second request for at least one identifier, each of the at least one identifier being for at least one of at least one group of target relay terminal devices supporting a relay service code (RSC), the second request including at least the RSC; obtaining the at least one identifier based on the second request; and sending a second response to the second request to the first network device, the second response including at least the at least one identifier.
[0017] In a fourteenth aspect, a method is provided. The method includes: at a second network device in a second home public land mobile network (HPLMN), receiving, from a first network device in a first HPLMN, a third request for at least a second set of security information for a relay service code (RSC), the request including at least the RSC, where the second HPLMN is different from the first HPLMN; obtaining at least a second set of security information based on the third request; and sending a third response to the first network device, the third response including at least the second set of security information.
[0018] In a fifteenth aspect, a method is provided. The method includes: at a second PCF device in a second home public land mobile network (HPLMN), receiving a request for at least one identifier, each identifier in the at least one identifier being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; obtaining at least one identifier based on the request; and sending a response to the request, the response including at least one identifier.
[0019] In a sixteenth aspect, a computer-readable medium is provided. The computer-readable medium includes program instructions that, when executed by at least one processor, cause a device to perform at least the method according to any one of the eleventh aspect to the fifteenth aspect.
[0020] It should be understood that the summary section is not intended to identify key or essential features of the example embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily apparent through the following description. Brief Description of the Drawings
[0021] Some example embodiments will now be described with reference to the drawings, in which:
[0022] Figure 1 An example communication network in which example embodiments of the present disclosure can be implemented is illustrated;
[0023] Figure 2 A signaling diagram is illustrated, which illustrates the security process of the restricted 5G ProSe direct discovery model A;
[0024] Figure 3 A signaling diagram is illustrated, which illustrates the PC5 security establishment process for 5G ProSe UE-to-network relay communication on the user plane;
[0025] Figure 4 A signaling diagram according to some example embodiments of the present disclosure is illustrated, which illustrates the process for obtaining security information for relay discovery;
[0026] Figure 5Illustrates a signaling diagram according to some other example embodiments of the present disclosure, which illustrates a process for obtaining security information for relaying discovery;
[0027] Figure 6 Illustrates a signaling diagram according to some other example embodiments of the present disclosure, which illustrates a process for obtaining security information for relaying discovery;
[0028] Figure 7 Illustrates a signaling diagram according to some example embodiments of the present disclosure, which illustrates an example implementation of a process for obtaining security information for relaying discovery;
[0029] Figure 8 Illustrates a signaling diagram according to some other example embodiments of the present disclosure, which illustrates an example implementation of a process for obtaining security information for relaying discovery;
[0030] Figure 9 Illustrates a signaling diagram according to some other example embodiments of the present disclosure, which illustrates an example implementation of a process for obtaining security information for relaying discovery;
[0031] Figure 10 Illustrates a signaling diagram according to yet another example embodiment of the present disclosure, which illustrates an example implementation of a process for obtaining security information for relaying discovery;
[0032] Figure 11 Illustrates a signaling diagram according to yet another example embodiment of the present disclosure, which illustrates an example implementation of a process for obtaining security information for relaying discovery;
[0033] Figure 12 Illustrates a flowchart of a method implemented at a first network device according to some example embodiments of the present disclosure;
[0034] Figure 13 Illustrates a flowchart of a method implemented at a terminal device according to some example embodiments of the present disclosure;
[0035] Figure 14 Illustrates a flowchart of a method implemented at a first Policy Control Function (PCF) device according to some example embodiments of the present disclosure;
[0036] Figure 15 Illustrates a flowchart of a method implemented at a second network device according to some example embodiments of the present disclosure;
[0037] Figure 16 Illustrates a flowchart of a method implemented at a second PCF device according to some example embodiments of the present disclosure;
[0038] Figure 17The figure illustrates a simplified block diagram of an apparatus suitable for implementing an example embodiment of the present disclosure; and
[0039] Figure 18 The figure illustrates a block diagram of an example computer-readable medium in accordance with some example embodiments of the present disclosure.
[0040] Throughout the drawings, the same or similar reference numerals denote the same or similar elements. Detailed Description
[0041] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that these example embodiments are described for illustrative purposes only and to assist those skilled in the art in understanding and implementing the present disclosure, and do not represent any limitation on the scope of the present disclosure. The disclosure described herein can be implemented in various other ways than those described below.
[0042] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.
[0043] In the present disclosure, references to "an embodiment", "embodiment", "example embodiment", etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment must include the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an example embodiment, it is within the knowledge of one of ordinary skill in the art to effect such feature, structure, or characteristic in connection with other example embodiments whether or not explicitly described.
[0044] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the example embodiments, the first element may be referred to as the second element, and similarly, the second element may be referred to as the first element. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.
[0045] The terms used herein are for the purpose of describing particular example embodiments only and are not intended to limit the example embodiments. The singular forms "a", "an" and "the" as used herein also include the plural forms unless the context clearly dictates otherwise. Further understood, the terms "comprises", "comprising", "has", "having", "includes" and / or "including" when used herein specify the presence of the stated features, elements and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0046] As used in this application, the term "circuitry" may refer to one or more or all of the following:
[0047] (a) A pure hardware circuit implementation (such as an implementation using only analog and / or digital circuitry), and
[0048] (b) A combination of hardware circuitry and software, such as (if applicable):
[0049] (i) A combination of (multiple) analog and / or digital hardware circuitry and software / firmware, and
[0050] (ii) Any part of (multiple) hardware processors (including (multiple) digital signal processors), software, and (multiple) memories with software that work together to cause a device (such as a mobile phone or a server) to perform various functions, and
[0051] (c) (Multiple) hardware circuitry and / or (multiple) processors, such as (multiple) microprocessors or a part of (multiple) microprocessors, which require software (e.g., firmware) to operate, but the software may be absent when not needed for operation.
[0052] This definition of circuitry is applicable to all uses of the term in this application, including in any claims. As another example, as used in this application, the term circuitry also encompasses an implementation of only hardware circuitry or a processor (or multiple processors) or a part of hardware circuitry or a processor and its accompanying software and / or firmware. For example, if applicable to a particular claim element, the term circuitry also encompasses a baseband integrated circuit or a processor integrated circuit for a mobile device, or a similar integrated circuit in a server, a cellular network device, or other computing or network devices.
[0053] As used herein, the term "communication network" refers to a network that complies with any suitable communication standard, such as a fifth-generation (5G) system, Long-Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), NarrowBand Internet of Things (NB-IoT), etc. Additionally, the communication between the terminal device and the network device in the communication network can be performed according to any suitable generation of communication protocol, including but not limited to the first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G) New Radio (NR) communication protocol, and / or any other protocol currently known or to be developed in the future. Example embodiments of the present disclosure can be applied to various communication systems. Given the rapid development of communication, there will of course also be future types of communication technologies and systems that can be used to embody the present disclosure. It should not be construed as limiting the scope of the present disclosure to only the above systems.
[0054] As used herein, the term "network device" refers to a node in a communication network through which a terminal device accesses the network and receives services from the network. Depending on the terminology and technology applied, the network device can refer to a base station (BS) or an access point (AP), such as Node B (NodeB or NB), evolved Node B (eNodeB or eNB), NR next-generation Node B (gNB), Remote Radio Unit (RRU), Radio Header (RH), Remote Radio Head (RRH), relay, low-power node (such as femto, pico), etc. The RAN split architecture includes a gNB-CU (centralized unit that hosts RRC, SDAP, and PDCP), which controls multiple gNB-DUs (distributed units that host RLC, MAC, and PHY).
[0055] The term "terminal device" refers to any terminal device capable of wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smart phones, IP voice (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), game terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop mounted devices (LME), USB dongles, smart devices, wireless customer premises equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMD), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in an industrial and / or automation processing chain environment), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. In the following description, the terms "terminal device", "communication device", "terminal", "user equipment", and "UE" may be used interchangeably.
[0056] Although in various example embodiments, the functions described herein may be performed in fixed and / or wireless network nodes, in other example embodiments, the functions may be implemented in a user equipment device (such as a mobile phone or a tablet or a laptop or a desktop computer or a mobile IoT device or a fixed IoT device). For example, as needed, the user equipment device may be equipped with the corresponding capabilities described in conjunction with (one or more) fixed and / or wireless network nodes. The user equipment device may be a user equipment and / or a control device, such as a chipset or a processor, which is configured to control the user equipment when installed in the user equipment. Examples of such functions include a bootstrapping server function and / or a home subscriber server, which may be implemented in the user equipment device by providing software to the user equipment device, the software being configured to cause the user equipment device to perform from the perspective of these functions / nodes.
[0057] Figure 1 An example communication environment 100 in which example embodiments of the present disclosure may be implemented is shown. Environment 100 may include a first home public land mobile network (HPLMN) 110 and a second HPLMN 120.
[0058] The first terminal device 112 may use the subscription of the first HPLMN 110. The first terminal device 112 may communicate with the first network device 114 and the first PCF 116 in the first HPLMN 110.
[0059] In some example embodiments, the first network device 114 may include a 5G direct discovery name management function (DDNMF) device or a ProSe key management function (PKMF) device.
[0060] The second terminal device 122 may use the subscription of the second HPLMN 120. The second terminal device 122 may communicate with the second network device 124 and the second PCF 126 in the second HPLMN 120.
[0061] In some example embodiments, the second network device 124 may include a 5G direct discovery name management function (DDNMF) device or a ProSe key management function (PKMF) device.
[0062] It should be understood that the number of devices is only for ease of understanding and does not represent any limitation. The communication environment 100 may include any suitable number or type of devices suitable for implementing the embodiments of the present disclosure.
[0063] The communication in the communication environment 100 may be implemented according to any suitable communication protocol(s), including but not limited to: cellular communication protocols of the first generation (1G), second generation (2G), third generation (3G), fourth generation (4G), fifth generation (5G), or future sixth generation (6G), wireless local area network communication protocols (such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, etc.), and / or any other protocol known currently or developed in the future. In addition, the communication may utilize any suitable wireless communication technology, including but not limited to: code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplexing (FDD), time division duplexing (TDD), multiple input multiple output (MIMO), orthogonal frequency division multiplexing (OFDM), discrete Fourier transform spread OFDM (DFT-s-OFDM), and / or any other technology known currently or developed in the future.
[0064] In some example embodiments, the communication environment 100 may support proximity-based service (ProSe) functions, such as 5G ProSe, 4G ProSe, etc. Hereinafter, example embodiments of the present disclosure will be described by taking 5G ProSe as an example. However, the present disclosure may be applied to 4G ProSe or any future ProSe.
[0065] The 5G ProSe function may include 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-to-network (U2N) relay.
[0066] In the 5G ProSe UE-to-network relay function, the first terminal device 112 may be connected to the second terminal device 122 via the PC5 interface with 5G ProSe direct communication and communicate with the data network via the second terminal device 122 and the 5G network. In this regard, the first terminal device 112 may be referred to as a remote terminal device or a remote user equipment (UE), and the second terminal device 122 may be referred to as a UE-to-network (U2N) relay.
[0067] To perform 5G ProSe direct communication between the first terminal device 112 and the second terminal device 122, the first terminal device 112 and the second terminal device 122 may use the security information for relay discovery to perform the 5G ProSe direct discovery process. Therefore, it is necessary to obtain the security information for relay discovery.
[0068] Figure 2 The signaling diagram illustrates the security process 200 of the restricted 5G ProSe direct discovery model A.
[0069] In process 200, steps 211-214 relate to the announcement of UE 202.
[0070] At 211, the announcing UE 202 sends a discovery request message containing the restricted ProSe application user ID (RPAUID) to the 5G DDNMF 205 in its HPLMN to obtain the ProSe code to be announced and obtain the associated security material. In addition, the announcing UE 202 shall include its PC5 UE security capabilities, which include the list of encryption algorithms supported by the UE in the discovery request message.
[0071] For 5G ProSe UE-to-network relay discovery, the 5G ProSe UE-to-network relay acts as the announcing UE 202 and sends a relay discovery key request instead of a discovery request. The relay discovery key request message includes the relay service code (RSC) and the PC5 security capabilities of the 5G ProSe UE-to-network relay.
[0072] At 212, the 5G DDNMF 205 may check the announcement authorization with the ProSe application server. For 5G ProSe UE-to-network relay discovery, this step is skipped.
[0073] At 213, if it is declared that the UE 202 is roaming, the 5G DDNMF 205 in the HPLMN and VPLMN 204 of the declared UE 202 exchange declaration authorizations.
[0074] At 214, the 5G DDNMF 205 in the HPLMN of the declared UE 202 returns a ProSe restricted code and the corresponding code transmission security parameters, as well as the CURRENT_TIME and MAX_OFFSET parameters. The code transmission security parameters provide the necessary information for the declared UE 202 to protect the transmission of the ProSe restricted code, and it is stored together with the ProSe restricted code. The declared UE 202 takes the same actions for CURRENT_TIME and MAX_OFFSET. The 5G DDNMF 205 in the HPLMN of the declared UE 202 shall include the selected PC5 encryption algorithm in the discovery response message. In step 211, the 5G DDNMF 205 determines the selected PC5 encryption algorithm based on the ProSe restricted code and the received PC5 UE security capabilities. The UE stores the selected PC5 encryption algorithm together with the ProSe restricted code.
[0075] In addition, the 5G DDNMF 205 in the HPLMN of the declared UE 202 may associate the ProSe restricted code with a PC5 security policy and include the PC5 security policy in the discovery response message.
[0076] For 5G ProSe UE-to-network relay discovery, a relay discovery key response is used instead of a discovery response, and an RSC is used instead of a ProSe restricted code. The response message contains discovery security material.
[0077] It should be noted that the 5G DDNMF can obtain the PC5 security policy in different ways (e.g., from the PCF, from the ProSe application server, or based on local configuration).
[0078] Steps 215 - 220 involve monitoring the UE 201.
[0079] At 215, the monitoring UE 201 sends a discovery request message containing the RPAUID and its PC5 UE security capabilities to the 5G DDNMF 203 in its HPLMN in order to be allowed to monitor one or more restricted ProSe application user IDs.
[0080] For 5G ProSe UE-to-network relay discovery, the 5G ProSe remote UE acts as the monitoring UE 201 and sends a relay discovery key request instead of a discovery request. The relay discovery key request message includes the RSC and the PC5 security capabilities of the 5G ProSe remote UE.
[0081] At 216, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 sends an authorization request to the ProSe application server. If, based on the permission settings, the RPAUID is allowed to discover at least one of the target RPAUIDs contained in the application-level container, the ProSe application server returns an authorization response.
[0082] For 5G ProSe UE-to-network relay discovery, this step is skipped.
[0083] At 217, if the discovery request is authorized and the PLMN ID in the target RPAUID indicates a different PLMN, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 contacts the 5G DDNMF of the indicated PLMN (i.e., the 5G DDNMF in the HPLMN of the announcing UE 202) by sending a discovery key request message including the PC5 UE security capabilities received in step 215.
[0084] For 5G ProSe UE-to-network relay discovery, use the relay discovery key request and RSC instead of the discovery request and RPAUID.
[0085] At 218, the 5G DDNMF 205 in the HPLMN of the announcing UE 202 can exchange authorization messages with the ProSe application server 206.
[0086] For 5G ProSe UE-to-network relay discovery, this step is skipped.
[0087] At 219, if the PC5 UE security capabilities in step 5 include the selected PC5 encryption algorithm, the 5G DDNMF 205 in the HPLMN of the announcing UE 202 responds to the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 with a discovery key response message including the ProSe restricted code, the corresponding code reception security parameters, the optional discovery user integrity key (DUIK), and the selected PC5 encryption algorithm (based on the information / keys stored in step 214). The code reception security parameters provide the information required for the monitoring UE 201 to revoke the protection applied by the announcing UE 202. If the code reception security parameters indicate that the monitoring UE 201 uses a matching report for MIC checking, the DUIK shall be included as a separate parameter. The 5G DDNMF 203 in the HPLMN of the monitoring UE 201 stores the ProSe restricted code and the discovery user integrity key (if it receives the parameter outside the code reception security parameters).
[0088] For 5G ProSe UE-to-network relay discovery, use a relay discovery key response instead of a discovery response, and use an RSC instead of a ProSe restricted code. The response message contains discovery security material.
[0089] The 5G DDNMF 205 in the HPLMN of the announcing UE 202 may send a PC5 security policy associated with the ProSe restricted code to the 5G DDNMF 203 in the HPLMN of the monitoring UE 201.
[0090] It should be noted that there are two possible configurations for the integrity check, namely, the MIC checked by the 5G DDNMF 203 of the monitoring UE 201 and the MIC checked on the side of the monitoring UE 201. Which configuration to use is determined by the 5G DDNMF, which allocates the monitored ProSe restricted code and signals the monitoring UE 201 in the code reception security parameters.
[0091] It should be noted that the selected PC5 encryption algorithm is associated with the ProSe restricted code.
[0092] At 220, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 returns a discovery filter and code reception security parameters, as well as CURRENT_TIME and MAX_OFFSET parameters and the selected PC5 encryption algorithm. The monitoring UE 201 takes the same actions on CURRENT_TIME and MAX_OFFSET. The UE stores the discovery filter, code reception security parameters, and the selected PC5 encryption algorithm together with the ProSe restricted code.
[0093] If in step 219, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 receives a PC5 security policy associated with the ProSe restricted code, the 5G DDNMF of the monitoring UE 201 forwards the PC5 security policy to the monitoring UE 201.
[0094] Steps 11 and 12 occur on PC5.
[0095] At 221, if the UTC-based counter provided by the system associated with the discovery time slot is within the MAX_OFFSET of the ProSe clock of the announcing UE 202 and if the validity timer has not expired, the UE starts announcing. The UE forms a discovery message and protects it. The four least significant bits of the UTC-based counter are sent together with the protected discovery message.
[0096] At 222, if the UTC-based counter associated with the discovery time slot is within the MAX_OFFSET of the ProSe clock of the monitoring UE, the monitoring UE 201 listens for discovery messages that satisfy its discovery filter. To find such a matching message, it processes the message. If the monitoring UE 201 is not required to send a matching report for MIC check, from a security perspective, it stops at this step. Otherwise, it proceeds to step 223.
[0097] It should be noted that due to the requirements of TS23.304, the UE's self-check of the integrity of the discovery message does not prevent the UE from sending a matching report. If such a matching report is sent, no security function is involved.
[0098] Steps 13 - 16 involve the monitoring UE 201 that has encountered a match.
[0099] At 223, if the UE has not previously had the 5G DDNMF check the MIC of the discovered ProSe restricted code, or the 5G DDNMF has already checked the MIC of the ProSe restricted code and the relevant matching report refresh timer (details of which are given in step 225) has expired, or due to the requirements of the procedure specified in TS23.304, the monitoring UE 201 sends a matching report message to the 5G DDNMF 203 in the HPLMN of the monitoring UE 201. The matching report contains the UTC-based counter value, where the four least significant bits are equal to the four least significant bits received with the discovery message and which is closest to the UTC-based counter of the monitoring UE 201 associated with the heard announced discovery time slot, and the matching report also contains other discovery message parameters, which include the ProSe restricted code and the MIC. The 5G DDNMF checks the MIC.
[0100] At 224, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 can exchange an authorization request / authorization response with the ProSe application server 206 to ensure that the monitoring UE 201 is authorized to discover the announcing UE 202.
[0101] For 5G ProSe UE-to-network relay discovery, this step is skipped.
[0102] At 225, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 returns to the monitoring UE 201 an acknowledgement that the integrity check has passed. It also provides the CURRENT_TIME parameter by which the UE (re)sets its ProSe clock. The 5G DDNMF 203 in the HPLMN of the monitoring UE 201 includes in the message to the monitoring UE 201 a matching report refresh timer. The matching report refresh timer indicates how long the UE will wait before sending a new matching report for the ProSe restricted code.
[0103] At 226, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 may send a matching report information message to the 5G DDNMF 205 in the HPLMN of the announcing UE 202.
[0104] Figure 3 The signaling diagram illustrates the PC5 security establishment process 300 for 5G ProSe UE-to-network relay communication on the user plane.
[0105] When the 5G ProSe remote UE 301 is within coverage, it is provisioned with discovery security material and a ProSe remote user key (UP-PRUK). This security material is associated with an expiration time after which it will become invalid. If the UE does not have valid discovery security material, the 5G ProSe remote UE needs to connect to the 5G PKMF and obtain new material to use the 5G ProSe UE-to-network relay service.
[0106] It should be noted that this process is described for the case where the 5G PKMF for the 5G ProSe remote UE is different from the 5G PKMF for 5G ProSe UE-to-network relay. If both the 5G ProSe remote UE and 5G ProSe UE-to-network relay are served by a single 5G PKMF, the 5G PKMF acts as the 5G PKMF for the 5G ProSe remote UE and the 5G PKMF for 5G ProSe UE-to-network relay, and no 5G PKMF-to-5G PKMF message exchange is required.
[0107] When the 5G ProSe remote UE 301 is within coverage, steps 310a, 310b, 311a, 311b are performed.
[0108] At 310a, the 5G ProSe Remote UE 301 obtains the 5G PKMF address from the 5G DDNMF 303 of its HPLMN. Alternatively, the 5G ProSe Remote UE 301 may be provisioned with the 5G PKMF address by the PCF. If the 5G ProSe Remote UE 301 is provisioned with the 5G PKMF address, the 5G ProSe Remote UE 301 may directly access the 5G PKMF without requesting the 5G PKMF from the 5G DDNMF. In the case where the 5G ProSe Remote UE 310 cannot access the 5G PKMF using the provisioned 5G PKMF address, the 5G ProSe Remote UE 301 may request the 5G PMKF address from the 5G DDNMF.
[0109] At 310b, the 5G ProSe Remote UE 301 shall establish a secure connection with the 5G PKMF 304 via the PC8 reference point. If GBA specified in TS 33.220 is used (see clause 5.2.3.4), the security of the PC8 interface depends on the Ua security, and if AKMA specified in TS 33.335 is used (see clause 5.2.5.4), the security of the PC8 interface depends on the Ua* security. The 5G PKMF 304 of the 5G ProSe Remote UE 301 shall check whether the 5G ProSe Remote UE 301 is authorized to receive the UE-to-network relay service, and if the UE is authorized, the 5G PKMF 304 of the 5G ProSe Remote UE 301 provides the discovery security material to the 5G ProSe Remote UE 301. If the 5G ProSe Remote UE 301 provides the visited network list, the 5G PKMF 304 of the 5G ProSe Remote UE 301 shall request the discovery security material from the 5G PKMF of the potential 5G ProSe UE-to-network relay, from which the 5G ProSe Remote UE 301 obtains the relay service. The 5G PKMF of the 5G ProSe UE-to-network relay may include the PC5 security policy for the 5G ProSe Remote UE 301.
[0110] It should be noted that the 5G PKMF may be locally configured with the authorization information of the UE. Otherwise, the 5G PKMF interacts with the UDM of the UE to retrieve the authorization information of the UE.
[0111] It should be noted that the 5G ProSe Remote UE 301 is provisioned by the PCF with the potential visited network list of the 5G ProSe UE-to-network relay service (identified by the RSC).
[0112] At 310c, the 5G ProSe UE-to-network relay 302 obtains the 5G PKMF address from its HPLMN in the same manner as described in step 310a.
[0113] At 310d, as shown in step 310b, the 5G ProSe UE-to-network relay 302 shall establish a secure connection with the 5G PKMF via the PC8 reference point. The 5G PKMF 306 of the 5G ProSe UE-to-network relay 302 shall check whether the 5G ProSe UE-to-network relay 302 is authorized to provide 5G ProSe UE-to-network relay services, and if the UE is authorized, the 5G PKMF 306 of the 5G ProSe UE-to-network relay 302 provides discovery security material to the 5G ProSe UE-to-network relay 302. The 5G PKMF 306 of the 5G ProSe UE-to-network relay 302 may include a PC5 security policy for the 5G ProSe UE-to-network relay 302.
[0114] At 311a, the 5G ProSe remote UE 301 sends a PRUK request message to its 5G PKMF. This message indicates that the 5G ProSe remote UE 301 is requesting UP-PRUK from the 5G PKMF. If the 5G ProSe remote UE 301 already has UP-PRUK from this 5G PKMF, the message shall also include the UP-PRUIKID of the UP-PRUK.
[0115] The UP-PRUK ID shall be in the form of an NAI or a 64-bit string. If the UP-PRUK ID is in NAI format, i.e., username@realm, the realm part shall include the home network identifier (i.e., HPLMN ID). The username part shall include a 64-bit string.
[0116] At 311b, the 5G PKMF 304 checks whether the 5G ProSe Remote UE 301 is authorized to receive the UE-to-Network Relay Service. This is done by using the identity of the 5G ProSe Remote UE 301 associated with the key used to establish a secure connection between the 5G ProSe Remote UE 301 and the 5G PKMF in step 310b. If the 5G ProSe Remote UE 301 is authorized to receive the service, the 5G PKMF sends the UP-PRUK and UP-PRUKID to the 5G ProSe Remote UE 301. If the UP-PRUK and UP-PRUKID are included, the 5G ProSe Remote UE 301 shall store these parameters and delete any previous UP-PRUK and UP-PRUKID stored for this 5G PKMF.
[0117] At 312, the discovery process is performed between the 5G ProSe Remote UE 301 and the 5G ProSe UE-to-Network Relay 302 using the discovery parameters and the discovery security material.
[0118] Using steps 313 - 315, a secure direct communication is established between the 5G ProSe Remote UE 301 and the U2N Relay.
[0119] Below, the authorization and provisioning of the ProSe service will be described.
[0120] Generally, in the 5GS, the parameters for 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-to-Network Relay Service can be made available to the UE in the following ways:
[0121] - Provisioned in the ME; or
[0122] - Configured in the UICC; or
[0123] - Provisioned in the ME and configured in the UICC; or
[0124] - Provided or updated by the ProSe Application Server via the PCF and / or the PC1 reference point; or
[0125] - Provided or updated by the PCF to the UE.
[0126] If the same parameters described in Article 5.1.2.1, Article 5.1.3.1, and Article 5.1.4.1 are provided by different sources, the UE shall consider them in the following priority order:
[0127] - Provided or updated by the PCF (including parameters determined by the PCF itself and parameters provided by the ProSe Application Server to the PCF);
[0128] - Provided or updated by the ProSe Application Server via the PC1 reference point;
[0129] - Configured in the UICC;
[0130] - Provisioned in the ME.
[0131] The parameters provided or updated by the ProSe Application Server via the PC1 reference point may need to be supplemented with configuration data from the other sources mentioned above.
[0132] It should be noted that the ProSe Application Server may supply the same ProSe parameters directly to the UE via the 5GC or via the PC1 reference point, and may revoke (e.g., delete) the ProSe parameters via the 5GC to make the supply via the PC1 reference point effective.
[0133] The basic principles for service authorization and provisioning of 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-to-network relay services are as follows:
[0134] - The PCF in the HPLMN may configure a PLMN list in which the UE is authorized to use 5G ProSe direct discovery.
[0135] - The PCF in the HPLMN may configure a PLMN list in which the UE is authorized to use 5G ProSe direct communication.
[0136] - The PCF in the HPLMN may configure a PLMN list in which the UE is authorized to act as a 5G ProSe UE-to-network relay. The authorization for 5G ProSe Layer 2 UE-to-network relay and 5G ProSe Layer 3 UE-to-network relay is independent of each other.
[0137] - The PCF in the HPLMN may configure a PLMN list in which the UE is authorized to access the 5GC via a 5G ProSe UE-to-network relay (i.e., act as a 5G ProSe remote UE). The authorization for access via 5G ProSe Layer 2 UE-to-network relay and via 5G ProSe Layer 3 UE-to-network relay is independent of each other.
[0138] - The PCF in the HPLMN combines the authorization information from the home and other PLMNs and provides the UE with the final authorization information.
[0139] - The PCF in a visited public land mobile network (VPLMN) or the HPLMN may revoke the authorization at any time (via the H-PCF during roaming) through the UE configuration update procedure using the transparent UE policy delivery procedure defined in clause 4.2.4.3 of TS 23.502.
[0140] - The supply of ProSe policies / parameters to the UE is controlled by the PCF and can be triggered by the UE. The PCF supplies one or more of the following ProSe policies / parameters:
[0141] - ProSe policies / parameters for 5G ProSe direct discovery as specified in Clause 5.1.2.1;
[0142] - ProSe policies / parameters for 5G ProSe direct communication as specified in Clause 5.1.3.1;
[0143] - 5G ProSe layer 2 and / or layer 3 UE-to-network
[0144] relay ProSe policies / parameters as specified in Clause 5.1.4.1;
[0145] - 5G ProSe layer 2 and / or layer 3 remote UE ProSe policies / parameters as specified in Clause 5.1.4.1.
[0146] - As specified in subclause 6.1.2.2.2 of TS 23.503 [9], the PCF includes the 5G ProSe policies / parameters in the policy part identified by the Policy Section Identifier (PSI).
[0147] In addition to the above, the ProSe usage reporting configuration and charging rules can be (pre)-configured in the UE or provided by the PCF.
[0148] In addition to the above, as defined in Clause 5.11, the path selection policy can be (pre)-configured in the UE or provided by the PCF. The path preference for the ProSe service can be provided by the ProSe application server to the UDR and can be used by the PCF for path selection policy generation and update.
[0149] When a 5G ProSe layer 3 remote UE uses 5G ProSe layer 3 UE-to-network relay without involving the Non-3GPP Access Interworking Function (N3IWF), the PCF-based supply and update of 5G ProSe policies / parameters to the 5G ProSe layer 3 remote UE are not supported.
[0150] Based on the background information, there are two problems in the security process of restricted 5G ProSe direct discovery, especially for 5G ProSe UE-to-network relay discovery.
[0151] On the one hand, if the remote UE and the potential relay belong to different HPLMNs, the DDNMF / PKMF of the remote UE cannot locate or discover the DDNMF / PKMF of the potential relay, as described below.
[0152] According to the 5G DDNMF discovery in Section 4.3.2.2 of TS23.304, the 5G DDNMF in the HPLMN uses the Network Repository Function (NRF) to discover other 5G DDNMFs in other PLMNs. Based on Section 6.3.1 of TS23.501, the NRF of the source PLMN uses the target PLMN ID to reach the NRF in the remote PLMN. However, the 5G DDNMF of the remote UE does not have information on the IDs of the HPLMNs of at least one target or potential relay.
[0153] From the description of "Authorization and Provisioning of ProSe Services", only the possible VPLMN or serving PLMN of the remote UE is provisioned on the remote UE, and as shown in 310b of Figure 3 , the remote UE can report these PLMNs to its DDNMF in the discovery key request. However, these PLMNs are the possible VPLMN or serving PLMN of the remote UE, which is surely different from the HPLMN of the relay. Therefore, there is an obvious gap in the current specification if the remote UE and the relay UE belong to different HPLMNs, especially if the remote UE or the relay UE is in a roaming state.
[0154] Specifically, at 217 of Figure 2 , the DDNMF of the remote UE cannot locate or discover the DDNMF of at least one potential relay because it does not know the HPLMN IDs of all potential relays.
[0155] On the other hand, if the RSC associated with the discovery is supported / authorized by more than one potential U2N relay of at least different HPLMNs, the secure discovery process cannot be used for the U2N relay case.
[0156] Based on the current discovery process, especially at 219 and 220 of Figure 2 , the security parameters and encryption algorithms are associated with the RSC. If there are more than one potential U2N relays supporting the RSC, it is impossible to distinguish the security parameters and encryption algorithms unless all relays share the same security parameters and algorithms. Since the security parameters and encryption algorithms are used to protect the discovery messages exchanged via the PC5 link, it is unsafe and even infeasible to share the security parameters and encryption algorithms among all potential relays or at least among relays belonging to different HPLMNs.
[0157] The present disclosure provides a solution for obtaining security information for relay discovery. According to this solution, a first network device in a first HPLMN receives a first request for security information for relay discovery from a terminal device served by the first network device. The first request includes at least a Relay Service Code (RSC). The first network device obtains at least one identifier based on the first request. Each of the at least one identifier is for at least one of at least one group of target relay terminal devices that support the RSC. In turn, the first network device obtains at least one set of security information based on the at least one identifier information. Each of the at least one set of security information is associated with at least one of at least one group of target relay terminal devices. The first network device sends at least one set of security information to the terminal device. In this way, the first network device can discover the target DDNMF and distinguish the security information of different groups of target relay terminal devices.
[0158] In the following, reference will be made to Figures 4 to 18 describe the principle of the present disclosure.
[0159] Figure 4 illustrates a signaling diagram that illustrates a process 400 for obtaining security information for relay discovery according to some example embodiments of the present disclosure. For the purpose of discussion, reference will be made to Figure 1 describe process 400. Process 400 may involve Figure 1 the first terminal device 112 and the first network device 114 in Figure 1 Alternatively, process 400 may involve Figure 1 the second terminal device 122 and the second network device 124 in
[0160] As Figure 4 shown, the first terminal device 112 sends 410 a first request for security information for relay discovery to the first network device 114. The first request includes at least a Relay Service Code (RSC).
[0161] Accordingly, the first network device 114 receives a first request for security information for relay discovery from the first terminal device 112.
[0162] The first network device 114 obtains 420 at least one identifier based on the first request. Each of the at least one identifier is for at least one of at least one group of target relay terminal devices that support the RSC. In the following, the target relay terminal device is also referred to as one of the following: target relay UE, target relay, potential relay terminal device, potential relay UE, or potential relay.
[0163] In sequence, the first network device 114 obtains 430 at least one set of security information based on at least one identification information. Each set in the at least one set of security information is associated with at least one of the groups of the target relay terminal device.
[0164] The first network device 114 sends 450 at least one set of security information to the first terminal device 112.
[0165] Accordingly, the first terminal device 112 receives at least one set of security information from the first network device 114.
[0166] In sequence, the first terminal device 112 performs 460 relay discovery based on the at least one set of security information.
[0167] Using process 400, the first network device 114 can discover the target DDNMF and distinguish the security information of different groups of the target relay terminal device.
[0168] In some example embodiments, the first network device 114 can obtain a set of security information associated with a relay restricted identifier (ID). The relay restricted ID can be generated based on the RSC and the identifier of the group of the target relay terminal device. The first network device 114 can send the set of security information associated with the relay restricted ID.
[0169] In some example embodiments, optionally, before sending the at least one set of security information, the first network device 114 can construct 440 a security information list for relay discovery. Each element in the list can be associated with one of the at least one set of security information.
[0170] In some example embodiments, each element in the list can be associated with a set of security information and a relay restricted ID associated with the set of security information. Table 1 provides an example of the list.
[0171] Table 1
[0172] Relay - restricted ID#1 Security information set#1 Relay - restricted ID#2 Security information set#2 Relay - restricted ID#3 Security information set#3
[0173] In Table 1, each row can represent an element of the security information list for relay discovery. Each element can be associated with a set of security information of the group of the target relay terminal device and a relay restricted ID. For example, security information set #1 is associated with relay restricted ID #1.
[0174] It should be noted that the number of sets of security information and the number of relay restricted IDs associated with the sets of security information are illustrative. More or fewer sets of security information and relay restricted IDs can be applied to the present disclosure.
[0175] In some example embodiments, each set of at least one set of security information may include at least one of the following: security parameters for relay discovery, or a PC5 encryption algorithm, or a discovery user integrity key (DUIK) for relay discovery.
[0176] In some example embodiments, the first PCF device 116 may be configured with the identities of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second PCF device 126 may be configured with the identities of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC. In such example embodiments, the first network device 114 may obtain at least one identity from the first PCF device 116 in the first HPLMN 110. This will be described with reference to Figure 5 below.
[0177] Figure 5 FIG. illustrates a signaling diagram that illustrates a process 500 for obtaining security information for relay discovery according to some example embodiments of the present disclosure. For the purposes of discussion, process 500 will be described with reference to Figure 1 below. Process 500 may involve Figure 1 the first network device 114 and the first PCF device 116 in
[0178] As Figure 5 shown, the first network device 114 sends 510 a second request for at least one identity to the first PCF device 116. Each identity of the at least one identity is for at least one of at least one group of target relay terminal devices that support RSC. The second request includes at least RSC.
[0179] Accordingly, the first PCF device 116 receives the second request for at least one identity from the first network device 114.
[0180] The first PCF device 116 obtains 520 at least one identity based on the second request.
[0181] Subsequently, the first PCF device 116 sends 530 a second response to the second request to the first network device 114. The second response includes at least at least one identity.
[0182] Accordingly, the first network device 114 receives the second response that includes at least one identity.
[0183] In some example embodiments, the first network device 114 may be configured with the identities of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second network device 124 may be configured with the identities of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.
[0184] In such an exemplary embodiment, if the first group of target relay terminal devices in at least one group belongs to the first HPLMN 110, the first network device 114 may locally obtain the first identifier of the first group of target relay terminal devices. Subsequently, the first network device 114 may locally obtain the first set of security information associated with the first group of target relay terminal devices.
[0185] In such an exemplary embodiment, if the second group of target relay terminal devices in at least one group belongs to the second HPLMN 120, the first network device 114 may obtain from the second network device 124 the second set of security information associated with the second group of target relay terminal devices. This will be described with reference to Figure 6 below.
[0186] Figure 6 FIG. illustrates a signaling diagram that illustrates a process 600 for obtaining security information for relay discovery according to some exemplary embodiments of the present disclosure. For the purpose of discussion, process 600 will be described with reference to Figure 1 below. Process 600 may involve Figure 1 the first network device 114 and the second network device 124 in
[0187] As Figure 6 shown, the first network device 114 sends 610 a third request for at least one second set of security information for the RSC to the second network device 124. The third request includes at least the RSC.
[0188] Accordingly, the second network device 124 receives from the first network device 114 the third request for at least one second set of security information for the RSC.
[0189] The second network device 124 obtains 620 at least one second set of security information based on the third request. Each second set of security information in the at least one second set of security information is associated with the second group of target relay terminal devices belonging to the second HPLMN 120.
[0190] Subsequently, the second network device 124 sends 630 a third response to the third request to the first network device 114. The third response includes at least the at least one second set of security information.
[0191] Hereinafter, some exemplary implementations of processes 400, 500, and 600 will be described with reference to Figures 7 to 11 below.
[0192] In Figures 7 to 11In an example implementation, a remote UE and a U2N relay are taken as examples of the first terminal device 112 and the second terminal device 122, respectively. DDNMF or PKMF is taken as an example of each of the first network device 114 and the second network device 124. In addition, the first HPLMN 110 is configured with PLMNID#1, and the second HPLMN 120 is configured with PLMNID#2.
[0193] Figure 7 Illustrates a signaling diagram that illustrates a process 700 for obtaining security information for relay discovery according to some example embodiments of the present disclosure. For purposes of discussion, reference will be made to Figure 1 Describe process 700. Process 700 may involve Figure 1 the first terminal device 112 (such as the remote UE 112), the second terminal device 122 (such as the U2N relay 122), the first network device 114 (such as the DDNMF 114), the first PCF device 116, the second network device 124 (such as the DDNMF 124), and the second PCF device 126 in
[0194] In step 700, the first PCF device 116 is configured with the identity of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second PCF device 126 is configured with the identity of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.
[0195] In addition, in process 700, each group in at least one group of target relay terminal devices includes a single target relay terminal device, and the identity of the group of target relay terminal devices includes a relay identity for discovery.
[0196] As Figure 7 shown, at 701, the U2N relay 122 sends a discovery key request to its DDNMF 124 to obtain security information for relay discovery to protect PC5 discovery messages. The request may include RSC and the security capabilities of the U2N relay 122.
[0197] The action at 701 can be regarded as Figure 4 an example implementation of the action at 410 in
[0198] At 702, the DDNMF 124 of the U2N relay 122 generates a relay restricted ID for the U2N relay 122 with an active timer. The relay restricted ID is associated with the RSC and the discovered relay identity for the U2N relay 122. Hereinafter, for simplicity, the discovered relay identity is also referred to as the "relay ID". For example, the relay ID may include the HPLMN ID of the U2N relay 122 (such as PLMN ID #2). Then, the DDNMF 124 obtains the security information associated with the relay restricted ID. For example, the DDNMF 124 may generate security parameters and select a PC5 encryption algorithm.
[0199] Subsequently, the DDNMF 124 sends a discovery key response to the U2N relay 122. The response includes the RSC, the ProSe restricted code and the active timer, the code specific security parameters and the selected PC5 encryption algorithm, CURRENT_TIME, MAX_OFFSET, and an optional PC5 security policy.
[0200] The actions at 702 can be regarded as Figure 4 an example implementation of the actions at 420, 430, 440, and 450 in
[0201] At 703, the remote UE 112 sends a discovery key request to its DDNMF 114 to obtain the security information for relay discovery, so as to protect the PC5 discovery message. The request may include the UE identity of the remote UE 112, the RSC, and the security capabilities of the remote UE 112.
[0202] The actions at 703 can be regarded as Figure 4 another example implementation of the actions at 410 in
[0203] At 704, the DDNMF 114 of the remote UE 112 sends a request to its PCF device 116 to obtain the identities of potential relays that support the RSC for the remote UE 112. The request may include the UE identity of the remote UE 112, and the RSC.
[0204] The actions at 704 can be regarded as Figure 5 an example implementation of the actions at 510 in
[0205] At 705, the PCF device 116 of the remote UE 112 locally obtains the ID of the HPLMN of the potential relays based on the RSC and the local configuration.
[0206] At 706a, the PCF device 116 of the remote UE 112 locally obtains the IDs of the potential relays based on the RSC and the local configuration of those potential relays that belong to the same HPLMN as the remote UE 112.
[0207] At 706b, for those potential relays belonging to different HPLMNs of the remote UE 112, the PCF device 116 of the remote UE 112 obtains the identities of the potential relays from the PCF device of another PLMN. For example, for those potential relays belonging to the second HPLMN 120, the PCF device 116 of the remote UE 112 obtains the identities of the potential relays from the PCF device 126.
[0208] At 706b.1, the PCF device 116 of the remote UE 112 sends a request for the identities of the potential relays belonging to the second HPLMN 120 to the PCF device 126 of the U2N relay 112. This request is also referred to as a "Get Potential Relay Request". The request may include the PLMNID#1 of the first HPLMN 110 of the remote UE 112, and the RSC.
[0209] At 706b.2, the PCF device 116 of the remote UE 112 receives a response to the "Get Potential Relay Request". This response is also referred to as a "Get Potential Relay Response". The "Get Potential Relay Response" may include the PLMNID#2 of the second HPLMN 120, the RSC, and a list of relay IDs.
[0210] The actions at 705, 706a, 706b.1, 706b.2 can be regarded as Figure 5 an example implementation of the action at 520 in
[0211] In some example implementations, the actions at 706a, 706b.1, 706b.2 can be repeated for each HPLMN of the potential relays.
[0212] At 707, the PCF device 116 of the remote UE 112 sends a response to the DDNMF 114 of the remote UE 112. This response is also referred to as a "Get Potential Relay Response". The response may include the UE identity of the remote UE 112, the RSC, and a list of relay IDs of the potential relays.
[0213] The action at 707 can be regarded as Figure 5 an example implementation of the action at 530 in
[0214] At 708a, if the potential relay belongs to the same HPLMN of the remote UE 112, the DDNMF 114 generates a relay-restricted ID for the potential relay with a valid timer. The relay-restricted ID is associated with the RSC and the relay ID of the potential relay. Then, the DDNMF 114 obtains the security information associated with the relay-restricted ID. For example, the DDNMF 114 may generate security parameters, DUIK, and select a PC5 encryption algorithm associated with the relay-restricted ID.
[0215] At 708b.1, if the potential relay belongs to a different HPLMN, the DDNMF 114 of the remote UE 112 sends a discovery key request to the DDNMF of the HPLMN of the potential relay to obtain security information associated with the RSC. For example, the DDNMF 114 of the remote UE 112 may send a discovery key request to the DDNMF 124 of the second HPLMN 120. The DDNMF 114 of the remote UE 112 may discover the DDNMF of the potential relay based on the PLMNID of the HPLMN of the potential relay (which may be part of the relay ID of the potential relay). The request may include the security capabilities of the remote UE 112, the RSC, and the relay ID of the potential relay.
[0216] The action at 708b.1 can be regarded as Figure 6 an example implementation of the action at 610 in
[0217] At 708b.2, the DDNMF 114 of the remote UE 112 receives a discovery key response from the DDNMF 124 of the U2N relay 122. The response may include the relay restricted ID of the potential relay with a valid timer, security parameters, DUIK, and the selected PC5 encryption algorithm associated with the relay restricted ID. The relay restricted ID is associated with the RSC and the relay ID.
[0218] The action at 708b.2 can be regarded as Figure 6 an example implementation of the action at 630 in
[0219] In some example implementations, the actions at 708a, 708b.1, and 708b.2 can be repeated for each potential relay.
[0220] At 709, the DDNMF 114 of the remote UE 112 constructs a list of relay restricted IDs with corresponding valid timers, code security parameters, DUIK, and PC5 encryption algorithms.
[0221] The action at 709 can be regarded as Figure 4 an example implementation of the action at 440 in
[0222] At 710, the DDNMF of the remote UE 112 sends a discovery key response to the remote UE 112. The response may include the RSC, an optional PC5 security policy, CURRENT_TIME, MAX_OFFSET, a list of (relay restricted ID, valid timer, Code - Rcv - SecParams (i.e., security parameters), selected PC5 encryption algorithm).
[0223] CURRENT_TIME contains the current UTC-based time at the 5G DDNMF. The UE may obtain the UTC time from any available source, such as the RAN via SIB9, NITZ, NTP, GPS, via the Ub interface (in GBA) (depending on which is available).
[0224] The MAX_OFFSET parameter is used to limit the ability of an attacker to successfully replay discovery messages or obtain correctly MICed discovery messages for later use. This is achieved by using MAX_OFFSET as the maximum difference between a UTC-based counter associated with a discovery time slot and the ProSe clock held by the UE.
[0225] The action at 710 can be regarded as Figure 4 an example implementation of the action at 450 in
[0226] At 711, the remote UE 112 and the U2N relay 122 perform relay discovery over PC5. The discovery messages are protected by at least one set of security information. Each set in the at least one set of security information is associated with a relay-restricted ID (which is per-relay per-RSC).
[0227] The action at 711 can be regarded as Figure 4 an example implementation of the action at 460 in
[0228] Procedure 700 may be consistent with traditional evolved packet system (EPS) / 5G direct discovery procedures and extended to support discovery key requests for relay discovery. Additionally, procedure 700 may reduce the signaling load from the remote UE 112 to its HPLMN 110.
[0229] Figure 8 Illustrated is a signaling diagram that illustrates a procedure 800 for obtaining security information for relay discovery according to some example embodiments of the present disclosure. For purposes of discussion, procedure 800 will be described with reference to Figure 1 Procedure 800 may involve Figure 1 a first terminal device 112 (such as the remote UE 112), a second terminal device 122 (such as the U2N relay 122), a first network device 114 (such as the DDNMF 114), a first PCF device 116, a second network device 124 (such as the DDNMF 124), and a second PCF device 126 in
[0230] The similarity between procedure 800 and procedure 700 is that the first PCF device 116 is configured with the identification of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second PCF device 126 is configured with the identification of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.
[0231] In addition, the similarity between procedure 800 and procedure 700 is that each group in at least one group of target relay terminal devices includes a single target relay terminal device, and the identification of the group of target relay terminal devices includes a relay identification for discovery.
[0232] The difference between procedure 800 and procedure 700 is that the interaction between PCF devices of different HPLMNs can be avoided, and the messages between the DDNMFs of the two HPLMNs can be reduced.
[0233] Specifically, the actions at 801, 802, 803, 805, 808a, 809, 810, and 811 in procedure 800 are similar to the actions at 701, 702, 703, 705, 708a, 709, 710, and 711 in procedure 700. Therefore, for the sake of brevity, the details of these actions are omitted.
[0234] The actions at 804, 806, 807, 808b.1, 808b.2, and 808b.3 in procedure 800 are different from the actions in procedure 700.
[0235] At 804, the DDNMF 114 of the remote UE 112 sends a request to its PCF device 116 to obtain the ID of the HPLMN that supports RSC remotely for the UE 112. This request may include the UE identification of the remote UE 112 and RSC. This request is also referred to as "obtain the HPLMN of the potential relay request".
[0236] The action at 804 can be regarded as Figure 5 another example implementation of the action at 510 in
[0237] At 805, the PCF device 116 of the remote UE 112 locally obtains the ID of the potential relay HPLMN based on RSC and local configuration.
[0238] The action at 805 can be regarded as Figure 5 another example implementation of the action at 530 in
[0239] At 806, the PCF device 116 of the remote UE 112 sends a response to the DDNMF 114. This response is also referred to as the "HPLMN for obtaining potential relay response". The response may include the UE identifier of the remote UE 112, the RSC, and a list of PLMN IDs. For example, the list of PLMN IDs may include at least one of the following: the ID of the first HPLMN 110 (such as PLMNID#1), or the ID of the second HPLMN 120 (such as PLMNID#2).
[0240] The action at 806 can be regarded as Figure 5 another example implementation of the action at 530 in
[0241] At 807, if the list of PLMN IDs can include the ID of the first HPLMN 110 (such as PLMN ID#1), the DDNMF 114 of the remote UE 112 obtains the ID of the potential relay from the PCF device 116 of the remote UE 112 based on the RSC.
[0242] The action at 807 can be regarded as Figure 5 another example implementation of the actions at 510, 520, and 530 in
[0243] At 808b.1, if the list of PLMN IDs can include the ID of the second HPLMN 120 (such as PLMNID#2), the DDNMF 114 of the remote UE 112 sends a discovery key request to the DDNMF 124 of the HPLMN 120 to obtain security information associated with the RSC. The request may include the security capabilities of the remote UE 112, as well as the RSC. It should be noted that the request may or may not include the ID of the second HPLM 120 (such as PLMN ID#2). This means that it is necessary to obtain the security information associated with each potential relay in the second HPLMN 120.
[0244] The action at 808b.1 can be regarded as Figure 6 another example implementation of the action at 610 in
[0245] At 808b.2, the DDNMF 124 of the U2N relay 122 obtains the relay IDs of potential relays in the second HPLMN 120 from the PCF device 126 based on the RSC. Then, the DDNMF 124 generates relay-restricted IDs for each potential relay with a valid timer. The relay-restricted ID is associated with the RSC and the relay ID of the potential relay. Then, the DDNMF 124 obtains the security information associated with the relay-restricted ID. For example, the DDNMF 124 can generate security parameters and select a PC5 encryption algorithm associated with the relay-restricted ID. In turn, the DDNMF 124 constructs a list of relay-restricted IDs with corresponding valid timers, code security parameters, and PC5 encryption algorithms.
[0246] In some example embodiments, each element in the list can be associated with a second set of security information and a relay-restricted ID associated with the second set of security information. Table 2 provides an example of the list.
[0247] Table 2
[0248] Relay - restricted ID#3 Second security information set#3 Relay - restricted ID#4 Second security information set#4
[0249] In Table 2, each row can represent an element of the list of security information for relay discovery. Each element can be associated with a second set of security information of the target relay terminal device and a relay-restricted ID. For example, the second set of security information #3 is associated with the first target relay terminal device and the relay-restricted ID #3. The relay-restricted ID #3 can be generated based on the RSC and the relay ID of the first target relay terminal device.
[0250] It should be noted that the number of sets of security information and the number of relay-restricted IDs associated with the sets of security information are illustrative. More or fewer sets of security information and relay-restricted IDs can be applied to the present disclosure.
[0251] At 808b.3, the DDNMF 114 of the remote UE 112 receives a discovery key response from the DDNMF 124 of the U2N relay 122. The response can include a list of relay-restricted IDs with corresponding valid timers, code security parameters, and PC5 encryption algorithms.
[0252] The action at 808b.3 can be regarded as Figure 6 another example implementation of the action at 630 in
[0253] Figure 9 The signaling diagram illustrates a process 900 for obtaining security information for relay discovery according to some example embodiments of the present disclosure. For the purpose of discussion, the process 900 will be described with reference to Figure 1 The process 900 can involveFigure 1 a first terminal device 112 (such as a remote UE 112), a second terminal device 122 (such as a U2N relay 122), a first network device 114 (such as a DDNMF 114), a first PCF device 116, and a second network device 124 (such as a DDNMF 124) in
[0254] The process 900 is similar to the process 800 in that the first PCF device 116 is configured with the identification of at least one target relay terminal device belonging to the first HPLMN 110 and supporting RSC. Similarly, the second PCF device 126 is configured with the identification of at least one target relay terminal device belonging to the second HPLMN 120 and supporting RSC.
[0255] In addition, the process 900 is different from the process 800 in that each group in at least one group of target relay terminal devices includes a plurality of target relay terminal devices in one of the first HPLMN 110 or the second HPLMN 120. The identification of the group of target relay terminal devices includes one of the following: the PLMN identification (ID) of the first HPLMN 110 or the second HPLMN 120 to which the plurality of target relay terminal devices belong, or the group ID of the plurality of target relay terminal devices. For example, the group ID may include the PLMN ID of the first HPLMN 110 or the second HPLMN 120.
[0256] Specifically, the actions at 901, 902, 903, 904, 905, 906, 908b.1, 909, 910, and 911 in the process 900 are similar to the actions at 801, 802, 803, 804, 805, 806, 808b.1, 809, 810, and 811 in the process 800. Therefore, for the sake of brevity, the details of these actions are omitted.
[0257] The actions at 908a and 908b.2 in the process 900 are different from the actions in the process 800.
[0258] At 908a, if the PLMN ID list may include the ID of the first HPLMN 110 (such as PLMN ID #1), the DDNMF 114 of the remote UE 112 generates a relay restricted ID for all potential relays in the first HPLMN 110 that support RSC. The relay restricted ID is associated with the RSC and PLMN ID #1. Then, the DDNMF 114 obtains the security information associated with the relay restricted ID. For example, the DDNMF 114 may generate security parameters and select a PC5 encryption algorithm associated with the relay restricted ID. In addition, the DDNMF 114 of the remote UE 112 may generate a validity timer for the relay restricted ID.
[0259] At 908b.1, if the PLMNID list can include the ID of the second HPLMN 120 (such as PLMNID #2), the DDNMF 114 of the remote UE 112 sends a discovery key request to the DDNMF 124 of the HPLMN 120 to obtain the security information associated with the RSC. The request can include the security capabilities of the remote UE 112 and the RSC. It should be noted that the request may or may not include the ID of the second HPLM 120 (such as PLMN ID #2). This means that it is necessary to obtain the security information associated with all potential relays in the second HPLMN 120.
[0260] The action at 908b.1 can be regarded as Figure 6 another example implementation of the action at 610 in
[0261] At 908b.2, the DDNMF 114 of the remote UE 112 receives a discovery key response from the DDNMF 124 of the U2N relay 122. The response can include a relay restricted ID with a corresponding valid timer, code security parameter, and PC5 encryption algorithm.
[0262] The action at 908b.2 can be regarded as Figure 6 another example implementation of the action at 630 in
[0263] In some example implementations, the actions at 908b.1 and 908b.2 can be repeated for each HPLMN of the potential relays associated with the RSC.
[0264] Figure 10 The signaling diagram illustrates a process 1000 for obtaining security information for relay discovery according to some example embodiments of the present disclosure. For the purpose of discussion, process 1000 will be described with reference to Figure 1 Process 1000 may involve Figure 1 the first terminal device 112 (such as the remote UE 112), the second terminal device 122 (such as the U2N relay 122), the first network device 114 (such as the DDNMF 114), and the second network device 124 (such as the DDNMF 124) in
[0265] Process 1000 is similar to process 800 in that each group in at least one group of target relay terminal devices includes a single target relay terminal device, and the identification of the group of target relay terminal devices includes a relay identification for discovery.
[0266] The difference between procedure 1000 and procedure 800 is that the first network device 114 is configured with the identification of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second network device 124 is configured with the identification of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.
[0267] Specifically, the actions at 1001, 1002, 1003, 1008a, 1008b.1, 1008b.4, 1009, 1010, and 1011 in procedure 1000 are similar to the actions at 801, 802, 803, 808a, 808b.1, 808b.3, 809, 810, and 811 in procedure 800. Therefore, for the sake of brevity, the details of these actions are omitted.
[0268] The actions at 1005, 1006, 1008b.2, and 1008b.3 in procedure 900 are different from the actions in procedure 800.
[0269] At 1005, the DDNMF 114 of the remote UE 112 locally obtains the ID of the HPLMN of potential relays based on RSC and local configuration.
[0270] At 1006, the DDNMF 114 of the remote UE 112 locally obtains the IDs of potential relays based on RSC and the local configurations of those potential relays that belong to the same HPLMN as the remote UE 112.
[0271] At 1008b.2, the DDNMF 114 of the remote UE 112 obtains the relay IDs of potential relays in the second HPLMN 120 based on RSC and local configuration.
[0272] At 1008b.3, the DDNMF 124 generates a relay-restricted ID for each potential relay with a valid timer. The relay-restricted ID is associated with RSC and the relay ID of the potential relay. The DDNMF 124 also obtains the security information associated with the relay-restricted ID. For example, the DDNMF 124 can generate security parameters and select a PC5 encryption algorithm associated with the relay-restricted ID. In turn, the DDNMF 124 constructs a list of relay-restricted IDs with corresponding valid timers, code security parameters, and PC5 encryption algorithms. An example of this list has been described in Table 2.
[0273] In some example embodiments, the actions from 1008b.1 to 1008b.4 can be repeated for each PLMN of potential relays associated with RSC.
[0274] Figure 11The signaling diagram is illustrated, which illustrates a process 1100 for obtaining security information for relaying discovery according to some example embodiments of the present disclosure. For the purpose of discussion, reference will be made to Figure 1 to describe the process 1100. The process 1100 may involve Figure 1 a first terminal device 112 (such as a remote UE 112), a second terminal device 122 (such as a U2N relay 122), a first network device 114 (such as a DDNMF 114), and a second network device 124 (such as a DDNMF 124) in
[0275] The similarity between the process 1100 and the process 900 is that each group in at least one group of target relay terminal devices includes multiple target relay terminal devices in one of the first HPLMN 110 or the second HPLMN 120. The identification of the group of target relay terminal devices includes one of the following: the PLMN identification (ID) of the first HPLMN 110 or the second HPLMN 120 to which the multiple target relay terminal devices belong, or the group ID of the multiple target relay terminal devices. For example, the group ID may include the PLMN ID of the first HPLMN 110 or the second HPLMN 120.
[0276] The difference between the process 1100 and the process 900 is that the first network device 114 is configured with the identification of at least one target relay terminal device that belongs to the first HPLMN 110 and supports the RSC. Similarly, the second network device 124 is configured with the identification of at least one target relay terminal device that belongs to the second HPLMN 120 and supports the RSC.
[0277] Specifically, the actions at 1101, 1102, 1103, 1108a, 1108b.1, 1108b.2, 1109, 1110, and 1111 in the process 1100 are similar to the actions at 901, 902, 903, 908a, 908b.1, 908b.2, 909, 910, and 911 in the process 900. Therefore, for the sake of brevity, the details of these actions are omitted.
[0278] The action at 1105 in the process 1100 is different from the action in the process 900.
[0279] At 1105, the DDNMF 114 of the remote UE 112 locally obtains the ID of the HPLMN of potential relays based on the RSC and local configuration.
[0280] In some example embodiments, the actions at 1108b.1 and 1108b.2 may be repeated for each PLMN of potential relays associated with the RSC.
[0281] Figure 12 FIG. 1200 shows a flowchart of an example method implemented at a first network device according to some example embodiments of the present disclosure. For purposes of discussion, method 1200 will be described with reference to Figure 1 the perspective of the first network device 114.
[0282] At block 1210, the first network device 114 receives a first request for security information for relay discovery from a terminal device served by the first network device. The first request includes at least a Relay Service Code (RSC).
[0283] At block 1220, the first network device 114 obtains at least one identifier based on the first request. Each of the at least one identifier is for at least one of at least one group of target relay terminal devices that support the RSC.
[0284] At block 1230, the first network device 114 obtains at least one set of security information based on the at least one identifier and the RSC. Each of the at least one set of security information is associated with at least one of at least one group of target relay terminal devices.
[0285] At block 1240, the first network device 114 sends at least one set of security information to the terminal device.
[0286] In some example embodiments, obtaining at least one identifier may include: obtaining at least one identifier from a first Policy Control Function (PCF) device in a first Home Public Land Mobile Network (HPLMN).
[0287] In some example embodiments, obtaining at least one identifier from the first PCF device may include: sending a second request for at least one identifier to the first PCF device, the second request including at least the RSC; and receiving a second response to the second request from the first PCF device, the second response including at least the at least one identifier.
[0288] In some example embodiments, obtaining at least one set of security information may include: obtaining a set of security information associated with a relay restricted identifier, the relay restricted identifier being generated based on the RSC and an identifier of at least one of at least one group of target relay terminal devices. In some example embodiments, sending at least one set of security information may include: sending a set of security information associated with the relay restricted identifier.
[0289] In some example embodiments, obtaining at least one set of security information may include: based on determining that a first group of target relay terminal devices in at least one group belongs to the first HPLMN, generating a first relay restricted identifier based on the RSC and a first identifier of the first group of target relay terminal devices, and obtaining a first set of security information associated with the first relay restricted identifier.
[0290] In some example embodiments, obtaining at least one set of security information may include: based on determining that a second group of target relay terminal devices in at least one group belongs to a second HPLMN different from the first HPLMN, sending a third request for a second set of security information for the RSC to a second network device in the second HPLMN, and receiving a third response to the third request from the second network device, the third response including the second set of security information and a second relay restriction identifier associated with the RSC and a second identifier of the second group.
[0291] In some example embodiments, the third request includes the second identifier.
[0292] In some example embodiments, obtaining at least one identifier may include: obtaining at least one identifier locally.
[0293] In some example embodiments, each group in at least one group of target relay terminal devices belongs to the first HPLMN or the second HPLMN, and the second HPLMN is different from the first HPLMN.
[0294] In some example embodiments, each group in at least one group of target relay terminal devices includes a single target relay terminal device, and each identifier in at least one identifier includes a relay identifier for discovery.
[0295] In some example embodiments, each group in at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and each identifier in at least one identifier includes one of the following: a PLMN identifier of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong, or a group identifier of the plurality of target relay terminal devices.
[0296] Figure 13 A flowchart of an example method 1300 implemented at a terminal device according to some example embodiments of the present disclosure is shown. For purposes of discussion, method 1300 will be described from the perspective of a first terminal device 112. Alternatively, method 1300 may be implemented at a second terminal device 122. Figure 1 At block 1310, the first terminal device 112 sends a request for security information for relay discovery to a network device in a home public land mobile network (HPLMN). The request includes at least a relay service code (RSC).
[0297] At block 1320, the first terminal device 112 receives at least one set of security information from the network device. Each set of at least one set of security information is associated with one of at least one group of target relay terminal devices supporting the RSC.
[0298] At block 1320, the first terminal device 112 receives at least one set of security information from the network device. Each set of at least one set of security information is associated with one of at least one group of target relay terminal devices supporting the RSC.
[0299] At block 1330, the first terminal device 112 performs relay discovery based on at least one set of security information.
[0300] In some example embodiments, receiving at least one set of security information may include: receiving a set of security information associated with a relay restricted identifier, the relay restricted identifier being associated with one of at least a group of the RSC and an identifier of a target relay terminal device.
[0301] In some example embodiments, each group in at least one group of target relay terminal devices belongs to a first HPLMN or a second HPLMN, and the second HPLMN is different from the first HPLMN.
[0302] In some example embodiments, each group in at least one group of target relay terminal devices includes a single target relay terminal device, and each identifier in at least one identifier includes a relay identifier for discovery.
[0303] In some example embodiments, each group in at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and each identifier in at least one identifier includes one of the following: a PLMN identifier of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong, or a group identifier of the plurality of target relay terminal devices.
[0304] Figure 14 A flowchart of an example method 1400 implemented at a first PCF device according to some example embodiments of the present disclosure is shown. For purposes of discussion, method 1400 will be described with reference to Figure 1 the perspective of the first PCF device 116.
[0305] At block 1410, the first PCF device 116 receives a second request for at least one identifier from a first network device in a first HPLMN. Each identifier in at least one identifier is for at least one group of target relay terminal devices that support a Relay Service Code (RSC), and the second request includes at least the RSC.
[0306] At block 1420, the first PCF device 116 obtains at least one identifier based on the second request.
[0307] At block 1430, the first PCF device 116 sends a second response to the second request to the first network device. The second response includes at least the at least one identifier.
[0308] In some example embodiments, each group in at least one group of target relay terminal devices belongs to a first HPLMN or a second HPLMN. The second HPLMN is different from the first HPLMN.
[0309] In some example embodiments, each group in at least one group of target relay terminal devices includes a single target relay terminal device, and each identification in at least one identification includes a relay identification for discovery.
[0310] In some example embodiments, obtaining at least one identification may include: based on determining that at least one group of target relay terminal devices belongs to a first HPLMN; based on a second request, locally obtaining a first identification of the first HPLMN; and locally obtaining, for each group in at least one group of target relay terminal devices, a relay identification for discovery.
[0311] In some example embodiments, obtaining at least one identification may include: based on determining that at least one group of target relay terminal devices belongs to a second HPLMN, sending a fourth request for at least one relay identification for discovery of at least one group of target relay terminal devices to a second PCF device in the second HPLMN, and receiving a fourth response to the fourth request from the second PCF device, the fourth response including at least one relay identification.
[0312] In some example embodiments, each group in at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and at least one identification includes one of the following: a PLMN identification of a first HPLMN or a second HPLMN to which the plurality of target relay terminal devices belong, or a group identification of the plurality of target relay terminal devices.
[0313] In some example embodiments, obtaining at least one identification may include: obtaining a PLMN identification or a group identification based on a second request.
[0314] Figure 15 A flowchart of an example method 1500 implemented at a second network device according to some example embodiments of the present disclosure is shown. For purposes of discussion, method 1500 will be described with reference to Figure 1 the perspective of the second network device 124.
[0315] At block 1510, the second network device 124 receives a third request for at least one second set of security information for a relay service code (RSC) from a first network device in a first HPLM. The request includes at least the RSC, and the second HPLMN is different from the first HPLMN.
[0316] At block 1520, the second network device 124 obtains at least one second set of security information based on the third request.
[0317] At block 1530, the second network device 124 sends a third response to the first network device. The third response includes at least at least one second set of security information.
[0318] In some example embodiments, each second security information set in at least one second security information set is associated with a second group of target relay terminal devices belonging to a second HPLMN.
[0319] In some example embodiments, the second group of target relay terminal devices includes a single target relay terminal device, and the second identifier of the second group includes a relay identifier for discovery.
[0320] In some example embodiments, the second group of target relay terminal devices includes a plurality of target relay terminal devices, and the second identifier of the second group includes one of the following: the PLMN identifier of the second HPLMN to which the plurality of target relay terminal devices belong, or the group identifier of the plurality of target relay terminal devices.
[0321] In some example embodiments, obtaining at least one second security information set may include: generating a second relay restricted identifier based on the RSC and the second identifier of the second group, and obtaining a second security information set in at least one second security information set associated with the second relay restricted identifier.
[0322] In some example embodiments, sending at least one second security information set may include: sending a second security information set in at least one second security information set associated with the second relay restricted identifier.
[0323] In some example embodiments, the third request includes: a second identifier for the second group of target relay terminal devices.
[0324] Figure 16 A flowchart of an example method 1600 implemented at a second PCF device according to some example embodiments of the present disclosure is shown. For purposes of discussion, method 1600 will be described Figure 1 from the perspective of the second PCF device 126.
[0325] At block 1610, the second PCF device 126 receives a request for at least one identifier, each identifier in the at least one identifier being for a target relay terminal device supporting a Relay Service Code (RSC), the request including at least the RSC.
[0326] At block 1620, the second PCF device 126 obtains at least one identifier based on the request.
[0327] At block 1630, the second PCF device 126 sends a response to the request, the response including the at least one identifier.
[0328] In some example embodiments, receiving a request for at least one identifier includes receiving the request from one of the following: a first network device in a first home public land mobile network (HPLMN) that is different from a second HPLMN, or a second network device in the second HPLMN.
[0329] In some example embodiments, an apparatus (e.g., the first network device 114) capable of performing any of the methods 1200 may include components for performing the corresponding operations of the method 1200. The components may be implemented in any suitable form. For example, the components may be implemented in circuitry or software modules. The apparatus may be implemented as the first network device 114 or included in the first network device 114. In some example embodiments, the components may include a processor and a memory.
[0330] In some example embodiments, the apparatus includes: components for receiving, at a first network device in a first home public land mobile network (HPLMN), a first request for security information for relay discovery from a terminal device served by the first network device, the first request including at least a relay service code (RSC); components for obtaining at least one identifier based on the first request, each identifier of the at least one identifier being for at least one of at least one group of target relay terminal devices that support the RSC; components for obtaining at least one set of security information based on the at least one identifier and the RSC, each set of the at least one set of security information being associated with at least one of at least one group of target relay terminal devices; and components for sending the at least one set of security information to the terminal device.
[0331] In some example embodiments, the components for obtaining at least one identifier may include: components for obtaining at least one identifier from a first policy control function (PCF) device in the first HPLMN.
[0332] In some example embodiments, the components for obtaining at least one identifier from the first PCF device may include: components for sending a second request for at least one identifier to the first PCF device, the second request including at least the RSC; and components for receiving a second response to the second request from the first PCF device, the second response including at least the at least one identifier.
[0333] In some example embodiments, the components for obtaining at least one set of security information may include: components for obtaining a set of security information associated with a relay restricted identifier, the relay restricted identifier being generated based on the RSC and an identifier of at least one of at least one group of target relay terminal devices. In some example embodiments, the components for sending the at least one set of security information may include: components for sending the set of security information associated with the relay restricted identifier.
[0334] In some example embodiments, the component for obtaining at least one set of security information may include: a component for generating a first relay restricted identifier based on determining that a first group of target relay terminal devices in at least one group belongs to a first HPLMN, based on an RSC and a first identifier of the first group of target relay terminal devices, and a component for obtaining a first set of security information associated with the first relay restricted identifier.
[0335] In some example embodiments, the component for obtaining at least one set of security information may include: a component for sending a third request for a second set of security information for an RSC to a second network device in a second HPLMN based on determining that a second group of target relay terminal devices in at least one group belongs to a second HPLMN different from the first HPLMN, and a component for receiving a third response to the third request from the second network device, the third response including the second set of security information and a second relay restricted identifier, the second relay restricted identifier being associated with the RSC and a second identifier of the second group.
[0336] In some example embodiments, the third request includes a second identifier.
[0337] In some example embodiments, the component for obtaining at least one identifier may include: a component for locally obtaining at least one identifier.
[0338] In some example embodiments, each group in at least one group of target relay terminal devices belongs to a first HPLMN or a second HPLMN, and the second HPLMN is different from the first HPLMN.
[0339] In some example embodiments, each group in at least one group of target relay terminal devices includes a single target relay terminal device, and each identifier in at least one identifier includes a relay identifier for discovery.
[0340] In some example embodiments, each group in at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and each identifier in at least one identifier includes one of the following: a PLMN identifier of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong, or a group identifier of the plurality of target relay terminal devices.
[0341] In some example embodiments, a device (e.g., the first terminal device 112) capable of performing any one of the methods 1300 may include components for performing the corresponding operations of the method 1300. The components may be implemented in any suitable form. For example, the components may be implemented in a circuit system or a software module. The device may be implemented as the first terminal device 112 or included in the first terminal device 112. In some example embodiments, the components may include a processor and a memory.
[0342] In some example embodiments, the apparatus includes: means for sending a request for security information for relay discovery from a terminal device to a network device in a home public land mobile network (HPLMN), the request including at least a relay service code (RSC); means for receiving at least one set of security information from the network device, each set of the at least one set of security information being associated with at least one of at least one group of target relay terminal devices supporting the RSC; and means for performing relay discovery based on the at least one set of security information.
[0343] In some example embodiments, receiving at least one set of security information may include: receiving a set of security information associated with a relay restricted identifier, the relay restricted identifier being associated with the RSC and an identifier of at least one of at least one group of target relay terminal devices.
[0344] In some example embodiments, each of at least one group of target relay terminal devices belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.
[0345] In some example embodiments, each of at least one group of target relay terminal devices includes a single target relay terminal device, and each of the at least one identifier includes a relay identifier for discovery.
[0346] In some example embodiments, each of at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and each of the at least one identifier includes one of the following: a PLMN identifier of a first HPLMN or a second HPLMN to which the plurality of target relay terminal devices belong, or a group identifier of the plurality of target relay terminal devices.
[0347] In some example embodiments, an apparatus (e.g., the first PCF device 116) capable of performing any of the methods 1400 may include means for performing the corresponding operations of the method 1400. The means may be implemented in any suitable form. For example, the means may be implemented in circuitry or a software module. The apparatus may be implemented as the first PCF device 116 or included in the first PCF device 116. In some example embodiments, the means may include a processor and a memory.
[0348] In some example embodiments, the apparatus comprises: means for receiving, at a first Policy Control Function (PCF) device in a first Home Public Land Mobile Network (HPLMN), a second request for at least one identifier from a first network device in the first HPLMN, each of the at least one identifier being for one of at least one group of target relay terminal devices supporting a Relay Service Code (RSC), the second request including at least the RSC; means for obtaining the at least one identifier based on the second request; and means for sending a second response to the second request to the first network device, the second response including at least the at least one identifier.
[0349] In some example embodiments, each of the at least one group of target relay terminal devices belongs to the first HPLMN or a second HPLMN. The second HPLMN is different from the first HPLMN.
[0350] In some example embodiments, each of the at least one group of target relay terminal devices includes a single target relay terminal device, and each of the at least one identifier includes a relay identifier for discovery.
[0351] In some exemplary embodiments, the means for obtaining the at least one identifier may include: means for obtaining, based on determining that the at least one group of target relay terminal devices belongs to the first HPLMN, a first identifier of the first HPLMN locally based on the second request; and means for obtaining locally a relay identifier for discovery for each of the at least one group of target relay terminal devices.
[0352] In some example embodiments, the means for obtaining the at least one identifier may include: means for sending, based on determining that the at least one group of target relay terminal devices belongs to the second HPLMN, a fourth request for at least one relay identifier for discovery of the at least one group of target relay terminal devices to a second PCF device in the second HPLMN, and means for receiving a fourth response to the fourth request from the second PCF device, the fourth response including the at least one relay identifier.
[0353] In some example embodiments, each of the at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and the at least one identifier includes one of the following: a Public Land Mobile Network (PLMN) identifier of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong, or a group identifier of the plurality of target relay terminal devices.
[0354] In some example embodiments, the means for obtaining the at least one identifier may include: means for obtaining a PLMN identifier or a group identifier based on the second request.
[0355] In some example embodiments, an apparatus (e.g., the second network device 124) capable of performing any of the methods 1500 may include components for performing the corresponding operations of the method 1500. The components may be implemented in any suitable form. For example, the components may be implemented in circuitry or software modules. The apparatus may be implemented as the second network device 124 or be included in the second network device 124. In some example embodiments, the components may include a processor and a memory.
[0356] In some example embodiments, the apparatus includes: components for receiving, at a second network device in a second home public land mobile network (HPLMN), a third request for at least one second set of security information for a relay service code (RSC) from a first network device in a first HPLMN, the request including at least the RSC, the second HPLMN being different from the first HPLMN; components for obtaining at least one second set of security information based on the third request; and components for sending a third response to the first network device, the third response including at least the at least one second set of security information.
[0357] In some example embodiments, each second set of security information in the at least one second set of security information is associated with a second group of target relay terminal devices belonging to the second HPLMN.
[0358] In some example embodiments, the second group of target relay terminal devices includes a single target relay terminal device, and the second identifier of the second group includes a relay identifier for discovery.
[0359] In some example embodiments, the second group of target relay terminal devices includes a plurality of target relay terminal devices, and the second identifier of the second group includes one of the following: the PLMN identifier of the second HPLMN to which the plurality of target relay terminal devices belong, or the group identifier of the plurality of target relay terminal devices.
[0360] In some example embodiments, the components for obtaining at least one second set of security information may include: components for generating a second relay restricted identifier based on the RSC and the second identifier of the second group, and components for obtaining one second set of security information from the at least one second set of security information associated with the second relay restricted identifier.
[0361] In some example embodiments, the components for sending the at least one second set of security information may include: components for sending one second set of security information from the at least one second set of security information associated with the second relay restricted identifier.
[0362] In some example embodiments, the third request includes the second identifier of the second group of target relay terminal devices.
[0363] In some example embodiments, a device (e.g., the second PCF device 126) capable of performing any of the methods 1600 may include components for performing the corresponding operations of the method 1600. The components may be implemented in any suitable form. For example, the components may be implemented in circuitry or software modules. The device may be implemented as the second PCF device 126 or included in the second PCC device 126. In some example embodiments, the components may include a processor and a memory.
[0364] In some example embodiments, the device includes: components for receiving, at a second PCF device in a second home public land mobile network (HPLMN), a request for at least one identifier, each of the at least one identifier being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; components for obtaining the at least one identifier based on the request; and components for sending a response to the request, the response including the at least one identifier.
[0365] In some example embodiments, the components for receiving a request for at least one identifier include components for receiving a request for at least one identifier from one of the following: a first network device in a first HPLMN different from the second HPLMN, or a second network device in the second HPLMN.
[0366] It should be understood that the details of the example embodiments of the present disclosure already described also apply to methods 1200 to 1600. Figures 7 to 11 already described also apply to methods 1200 to 1600.
[0367] Figure 17 is a simplified block diagram of a device 1700 suitable for implementing embodiments of the present disclosure. The device 1700 may be provided to implement a communication device, e.g., such as Figure 1 shown the first terminal device 112, the first network device 114, the first PCF device 116, the second terminal device 122, the second network device 124, or the second PCF device 126. As shown, the device 1700 includes one or more processors 1710, one or more memories 1720 coupled to the processors 1710, and one or more communication modules 1740 coupled to the processors 1710.
[0368] The communication module 1740 is for two-way communication. The communication module 1740 has at least one antenna to facilitate communication. The communication interface may represent any interface required for communication with other network elements.
[0369] The processor 1710 can be of any type suitable for the local technical network and, by way of non-limiting example, can include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. The device 1700 can have multiple processors, such as an application specific integrated circuit chip that is subordinate in time to a clock synchronized with the main processor.
[0370] The memory 1720 can include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1724, electrically programmable read-only memory (EPROM), flash memory, a hard disk, a compact disc (CD), a digital video disc (DVD), and other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1722 and other volatile memories that do not persist during a power outage.
[0371] The computer program 1730 includes computer-executable instructions that are executed by the associated processor 1710. The program 1730 can be stored in the ROM 1724. The processor 1710 can execute any suitable actions and processes by loading the program 1730 into the RAM 1722.
[0372] Embodiments of the present disclosure can be implemented by the program 1730 such that the device 1700 can execute any process of the present disclosure discussed with reference to Figures 1 to 16 Embodiments of the present disclosure can also be implemented by hardware or by a combination of software and hardware.
[0373] In some example embodiments, the program 1730 can be tangibly embodied in a computer-readable medium that can be included in the device 1700 (such as in the memory 1720) or in other storage devices accessible by the device 1700. The device 1700 can load the program 1730 from the computer-readable medium into the RAM 1722 for execution. The computer-readable medium can include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, a hard disk, a CD, a DVD, etc. Figure 18 An example of a computer-readable medium 1800 in the form of a CD or DVD is shown. The program 1730 is stored on the computer-readable medium.
[0374] In general, the various embodiments of the present disclosure may be implemented using hardware or specific circuits, software, logic, or any combination thereof. Some aspects may be implemented using hardware, while other aspects may be implemented using firmware or software that can be executed by a controller, a microprocessor, or other computing devices. Although the various aspects of the embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, by way of non-limiting example, the blocks, devices, systems, techniques, or methods described herein may be implemented using hardware, software, firmware, specific circuits or logic, general-purpose hardware or a controller or other computing devices, or some combination thereof.
[0375] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as the instructions included in program modules, which are executed in a device on a target real or virtual processor to perform the methods 1200 to 1600 referred to above Figures 12 to 16 Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. In various embodiments, the functions of the program modules may be combined or split as needed among the program modules. The machine-executable instructions of the program modules may be executed within a local or distributed device. In a distributed device, the program modules may be located in both local and remote storage media.
[0376] The program code for performing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0377] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.
[0378] A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer-readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0379] Moreover, although operations are described in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In some instances, multitasking and parallel processing may be advantageous. Also, while several specific implementation details are included in the foregoing discussion, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination within a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.
[0380] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the above specific features or acts are disclosed as example forms of implementing the claims.
Claims
1. A first network device, comprising: At least one processor; And At least one memory storing instructions which, when executed by the at least one processor, cause the first network device in a first home public land mobile network (HPLMN) to at least: Receive, from a terminal device served by the first network device, a first request for security information for relay discovery, the first request including at least a relay service code (RSC); Obtain at least one identifier based on the first request, each of the at least one identifier being for at least one of at least one group of target relay terminal devices supporting the RSC; Obtain at least one set of security information based on the at least one identifier and the RSC, each of the at least one set of security information being associated with at least one of at least one group of the target relay terminal devices; And Send the at least one set of security information to the terminal device.
2. The first network device according to claim 1, wherein the first network device is caused to obtain the at least one identifier by: Obtaining the at least one identifier from a first policy control function (PCF) device in the first HPLMN.
3. The first network device according to claim 2, wherein the first network device is caused to obtain the at least one identifier from the first PCF device by: Sending a second request for the at least one identifier to the first PCF device, the second request including at least the RSC; and Receiving a second response to the second request from the first PCF device, the second response including at least the at least one identifier.
4. The first network device according to claim 1, wherein: The first network device is caused to obtain the at least one set of security information by: Obtaining a set of security information associated with a relay restricted identifier, the relay restricted identifier being generated based on the RSC and an identifier of at least one of at least one group of the target relay terminal devices; and The first network device is caused to send the at least one set of security information by: Sending the set of security information associated with the relay restricted identifier.
5. The first network device according to claim 4, wherein the first network device is caused to obtain the at least one set of security information by: Based on determining that a first group of target relay terminal devices in the at least one group belongs to the first HPLMN, Generating a first relay restricted identifier based on the RSC and a first identifier of the first group of the target relay terminal devices, and Obtaining a first set of security information associated with the first relay restricted identifier.
6. The first network device according to claim 4, wherein the first network device is caused to obtain the at least one set of security information by: Based on determining that a second group of target relay terminal devices in the at least one group belongs to a second HPLMN different from the first HPLMN, Send a third request for a second set of security information for the RSC to a second network device in the second HPLMN, and Receive a third response to the third request from the second network device, the third response including: the second set of security information and a second relay restriction identifier, the second relay restriction identifier being associated with the RSC and a second identifier of the second group.
7. The first network device according to claim 6, wherein the third request includes the second identifier.
8. The first network device according to claim 1, wherein the first network device is caused to obtain the at least one identifier by: Obtaining the at least one identifier locally.
9. The first network device according to claim 1, wherein each group in the at least one group of target relay terminal devices belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.
10. The first network device according to claim 9, wherein each group in the at least one group of target relay terminal devices includes a single target relay terminal device, and each identifier in the at least one identifier includes a relay identifier for discovery.
11. The first network device according to claim 9, wherein each group in the at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and each identifier in the at least one identifier includes one of the following: a PLMN identifier of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong, or a group identifier of the plurality of target relay terminal devices.
12. A terminal device, comprising: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the terminal device to at least: send a request for security information for relay discovery to a network device in a home public land mobile network (HPLMN), the request including at least a relay service code (RSC); receive at least one set of security information, each set in the at least one set of security information being associated with one of at least one group of target relay terminal devices supporting the RSC; and perform the relay discovery based on the at least one set of security information.
13. The terminal device according to claim 12, wherein the terminal device is caused to receive the at least one set of security information by: receiving a set of security information associated with a relay restriction identifier, the relay restriction identifier being associated with the RSC and an identifier of one of the at least one group of target relay terminal devices.
14. The terminal device according to claim 12, wherein each group in the at least one group of target relay terminal devices belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.
15. The terminal device according to claim 14, wherein each group in at least one group of the target relay terminal devices includes a single target relay terminal device, and each of the at least one identifier includes a relay identifier for discovery.
16. The terminal device according to claim 14, wherein each group in at least one group of the target relay terminal devices includes a plurality of target relay terminal devices, and each of the at least one identifier includes one of the following: a PLMN identifier of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong, or a group identifier of the plurality of target relay terminal devices.
17. A first Policy Control Function (PCF) device, comprising: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the first PCF device in a first Home Public Land Mobile Network (HPLMN) to at least: receive, from a first network device in the first HPLMN, a second request for at least one identifier, each of the at least one identifier being for one of at least one group of target relay terminal devices supporting a Relay Service Code (RSC), the second request including at least the RSC; obtain the at least one identifier based on the second request; and send a second response to the second request to the first network device, the second response including at least the at least one identifier.
18. The first PCF device according to claim 17, wherein each group in at least one group of the target relay terminal devices belongs to the first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.
19. The first PCF device according to claim 18, wherein each group in at least one group of the target relay terminal devices includes a single target relay terminal device, and each of the at least one identifier includes a relay identifier for discovery.
20. The first PCF device according to claim 19, wherein the first PCF device is caused to obtain the at least one identifier by: based on determining that at least one group of the target relay terminal devices belongs to the first HPLMN, locally obtaining a first identifier of the first HPLMN based on the second request; and locally obtaining a relay identifier for discovery for each group in at least one group of the target relay terminal devices.
21. The first PCF device according to claim 19, wherein the first PCF device is caused to obtain the at least one identifier by: based on determining that at least one group of the target relay terminal devices belongs to the second HPLMN, sending a fourth request for at least one relay identifier for discovery of at least one group of the target relay terminal devices to a second PCF device in the second HPLMN, and Receive a fourth response to the fourth request from the second PCF device, the fourth response including the at least one relay identifier.
22. The first PCF device according to claim 18, wherein each group of the at least one group of target relay terminal devices includes a plurality of target relay terminal devices, and the at least one identifier includes one of the following: A PLMN identifier of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong, or A group identifier of the plurality of target relay terminal devices.
23. The first PCF device according to claim 22, wherein the first PCF device is caused to obtain the at least one identifier by: Obtaining the PLMN identifier or the group identifier based on the second request.
24. A second network device, comprising: At least one processor; And At least one memory storing instructions which, when executed by the at least one processor, cause the second network device in the second home public land mobile network (HPLMN) to at least: Receive a third request for at least one second set of security information for a relay service code (RSC) from a first network device in a first HPLM, the request including at least the RSC, the second HPLMN being different from the first HPLMN; Obtain the at least one second set of security information based on the third request; And Send a third response to the first network device, the third response including at least the at least one second set of security information.
25. The second network device according to claim 24, wherein each second set of security information in the at least one second set of security information is associated with a second group of target relay terminal devices belonging to the second HPLMN.
26. The second network device according to claim 25, wherein the second group of target relay terminal devices includes a single target relay terminal device, and the second identifier of the second group includes a relay identifier for discovery.
27. The second network device according to claim 25, wherein the second group of target relay terminal devices includes a plurality of target relay terminal devices, and the second identifier of the second group includes one of the following: A PLMN identifier of the second HPLMN to which the plurality of target relay terminal devices belong, or A group identifier of the plurality of target relay terminal devices.
28. The second network device according to claim 25, wherein: The second network device is caused to obtain the at least one second set of security information by: Generating a second relay restricted identifier based on the RSC and the second identifier of the second group, Obtaining one second set of security information in the at least one second set of security information associated with the second relay restricted identifier; and The second network device is caused to send the at least one second set of security information by: Sending the one second set of security information in the at least one second set of security information associated with the second relay restricted identifier.
29. The second network device according to claim 24, wherein the third request includes: The second identifier for the second group of the target relay terminal device.
30. A second Policy Control Function (PCF) device, comprising: At least one processor; And At least one memory storing instructions that, when executed by the at least one processor, cause the second PCF device in the second Home Public Land Mobile Network (HPLMN) to at least: Receive a request for at least one identifier, each of the at least one identifier being for a target relay terminal device supporting a Relay Service Code (RSC), the request including at least the RSC; Obtain the at least one identifier based on the request; and Send a response to the request, the response including the at least one identifier.
31. The second PCF device according to claim 30, wherein the second PCF device is caused to receive the request for at least one identifier from one of the following: A first network device in a first HPLMN different from the second HPLMN, or A second network device in the second HPLMN.
32. A device, comprising: Means for receiving, at a first network device in a first Home Public Land Mobile Network (HPLMN), a first request for security information for relay discovery from a terminal device served by the first network device, the first request including at least a Relay Service Code (RSC); Means for obtaining at least one identifier based on the first request, each of the at least one identifier being for at least one of at least one group of target relay terminal devices supporting the RSC; Means for obtaining at least one set of security information based on the at least one identifier and the RSC, each of the at least one set of security information being associated with at least one of at least one group of the target relay terminal devices; And Means for sending the at least one set of security information to the terminal device.
33. A device, comprising: Means for sending, from a terminal device, a request for security information for relay discovery to a network device in a Home Public Land Mobile Network (HPLMN), the request including at least a Relay Service Code (RSC); Means for receiving at least one set of security information from the network device, each of the at least one set of security information being associated with at least one of at least one group of target relay terminal devices supporting the RSC; And Means for performing the relay discovery based on the at least one set of security information.
34. A device, comprising: Means for receiving, at a first Policy Control Function (PCF) device in a first Home Public Land Mobile Network (HPLMN), a second request for at least one identifier from a first network device in the first HPLMN, each of the at least one identifier being for at least one of at least one group of target relay terminal devices supporting a Relay Service Code (RSC), the second request including at least the RSC; Means for obtaining the at least one identifier based on the second request; And A component for sending a second response to the second request to the first network device, the second response at least including the at least one identifier.
35. An apparatus, comprising: A component for receiving, at a second network device in a second Home Public Land Mobile Network (HPLMN), a third request for at least one second set of security information for a Relay Service Code (RSC) from a first network device in a first HPLMN, the request at least including the RSC, the second HPLMN being different from the first HPLMN; A component for obtaining the at least one second set of security information based on the third request; And A component for sending a third response to the first network device, the third response at least including the at least one second set of security information.
36. An apparatus, comprising: A component for receiving, at a second PCF device in a second Home Public Land Mobile Network (HPLMN), a request for at least one identifier, each identifier in the at least one identifier being for a target relay terminal device supporting a Relay Service Code (RSC), the request at least including the RSC; A component for obtaining the at least one identifier based on the request; And A component for sending a response to the request, the response including the at least one identifier.
37. A method, comprising: At a first network device in a first Home Public Land Mobile Network (HPLMN), receiving a first request for security information for relay discovery from a terminal device served by the first network device, the first request at least including a Relay Service Code (RSC); Obtaining at least one identifier based on the first request, each identifier in the at least one identifier being for at least one group of target relay terminal devices supporting the RSC; Obtaining at least one set of security information based on the at least one identifier and the RSC, each set in the at least one set of security information being associated with at least one group of the target relay terminal devices; And Sending the at least one set of security information to the terminal device.
38. A method, comprising: Sending, from a terminal device, a request for security information for relay discovery to a network device in a Home Public Land Mobile Network (HPLMN), the request at least including a Relay Service Code (RSC); Receiving at least one set of security information from the network device, each set in the at least one set of security information being associated with at least one group of target relay terminal devices supporting the RSC; And Performing the relay discovery based on the at least one set of security information.
39. A method, comprising: At a first Policy Control Function (PCF) device in a first Home Public Land Mobile Network (HPLMN), receiving a second request for at least one identifier from a first network device in the first HPLMN, each identifier in the at least one identifier being for at least one group of target relay terminal devices supporting a Relay Service Code (RSC), the second request at least including the RSC; Obtain the at least one identifier based on the second request; and Send a second response to the second request to the first network device, the second response including at least the at least one identifier.
40. A method includes: At a second network device in a second Home Public Land Mobile Network (HPLMN), receive a third request for at least one second set of security information for a Relay Service Code (RSC) from a first network device in a first HPLMN, the request including at least the RSC, the second HPLMN being different from the first HPLMN; Obtain the at least one second set of security information based on the third request; and Send a third response to the first network device, the third response including at least the at least one second set of security information.
41. A method includes: At a second PCF device in a second Home Public Land Mobile Network (HPLMN), receive a request for at least one identifier, each of the at least one identifier being for a target relay terminal device supporting a Relay Service Code (RSC), the request including at least the RSC; Obtain the at least one identifier based on the request; and Send a response to the request, the response including the at least one identifier.
42. A computer-readable medium includes program instructions for causing a device to at least perform the method according to any one of claims 37 to 41.