Method, system and computer program for user equipment to communicate with at least two network functions or services on one or more telecommunication networks
By establishing multiple non-access-level communication links and security contexts between user equipment and multiple network functions or services in the telecommunications network, using a zero-trust architecture and different key methods, the problems of invisible and untrustworthy information in the prior art are solved, higher security and trust are achieved, and flexible network function deployment is supported.
Patent Information
- Application Number
- CN202380080668.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-12
- Filing Date
- 2023-12-04
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2043-12-04
Smart Images

Figure CN120239982A_ABST
Abstract
Description
[0001] Background
[0002] The present invention relates to a method for operating a user equipment to communicate with a telecommunication network and with at least two of a plurality of network functions or services of the telecommunication network or another telecommunication network.
[0003] Furthermore, the present invention relates to a user equipment for operating with a telecommunication network and for communicating with at least two of a plurality of network functions or services of the telecommunication network or another telecommunication network.
[0004] Additionally, the present invention relates to a system or a telecommunication network for operating a user equipment with a telecommunication network and for providing at least two of a plurality of network functions or services of the telecommunication network or another telecommunication network.
[0005] Furthermore, the present invention relates to a user equipment guidance function or service, in particular as part of a system or a telecommunication network according to the present invention, for operating a user equipment with a telecommunication network using at least two of a plurality of network functions or services in the telecommunication network or another telecommunication network.
[0006] Furthermore, the present invention relates to a program and a computer-readable medium for operating a user equipment with a telecommunication network according to the method of the present invention and for communicating with at least two of a plurality of network functions or services of the telecommunication network or another telecommunication network.
[0007] In a conventionally known telecommunications network, the interface used between user equipment (via an access network such as a radio access network, RAN) and a core network (CN) is based on a non-access stratum protocol stack, or NAS protocol stack. From a system architecture perspective, NAS communication refers to the logical interface between user equipment and the CN. Taking a mobile communication network as an example, especially a mobile communication network according to the 5G standard, the non-access stratum protocol (usually the non-access stratum mobility management protocol (NAS-MM)) is, for example, transmitted on top of the NG-AP protocol stack (gNB-5G core application protocol stack), and the NG-AP protocol stack typically includes NG-AP on top of the L1 layer (physical layer), L2 layer (data link layer), IP (Internet Protocol) layer, and SCTP (Stream Control Transmission Protocol) layer. Thus, for example, the N2 interface, or N2 reference point, between the 5G access network and the access and mobility management function (AMF) network function or service of the core (5G) core network is implemented. The NG-AP protocol stack (NG-AP is a 3GPP protocol defined in TS 38.413) is used to transmit control plane (CP) information between the radio access network and the access and mobility management function (AMF) between user equipment and the core network. In the case considered, the (radio) access network acts as a relay for non-access stratum signaling (NAS-MM) (between the 5G access network protocol layer (which is used between user equipment and a base station entity, especially a gNodeB) and the NG-AP protocol stack (which is transmitted to the AMF using NG-AP as a lower protocol layer)), and the (radio) access network (AN) does not access the content of non-access stratum information (i.e., NAS-MM communication); it simply relays the information to the access and mobility management function (AMF), i.e., the so-called non-access stratum security context terminates at the access and mobility management function (AMF). In a conventionally known telecommunications network, the (radio) access network determines, based on configuration, typically based on the requested telecommunications network (especially a public land mobile network, PLMN) and network slice (or multiple network slices), the AMF network function or service (from among potentially multiple different AMF network functions or services or multiple different instances in the telecommunications network) to communicate with. The (radio) access network routes a given registration request (transmitted by user equipment) to one AMF network function or service, or one AMF from a potentially possible list of AMFs.
[0008] In a conventionally known telecommunications network, non-access stratum communication involves control plane information exchanged between a UE and a CN element or a network node of the core network: for example, in the case of a 5G system, this includes communication between a user equipment and multiple different network function functionals (such as, for example, an AMF (for access and mobility), an SMF (for session management), a PCF (for policy information), and an LMF (for location information)). Thus, the access and mobility management function acts as a core element of non-access stratum communication between the user equipment and (other types of) network functions or services of the core network (i.e., different network function functionals), and the (non-access stratum) communication between the user equipment and other network function functionals (i.e., network functions or services other than the access and mobility management function) is achieved through a combination of: on the one hand, using a non-access stratum protocol for transmission between the radio access network and the access and mobility management function; and on the other hand, based on the Nxxx service for communication between the access and mobility management function and other types of network functions or services (or multiple network function functionals) (for example, N11 / Nsmf of NAS-SM towards the session management function, N20 / Nsmsf towards the short message service function, N15 / Npcf of UE policy towards the policy and charging function, or NL1 / Nlmf of LCS (location service) towards the location management function).
[0009] Regarding security in a conventionally known telecommunications network, when a user equipment registers with the telecommunications network, a non-access stratum security context is created. The security context applies to non-access stratum connections, i.e., the connection between the user equipment and the access and mobility management function; this means that information sent via the access and mobility management function (such as, to the session management function, etc.) is visible to the access and mobility management function. This is a drawback in cases where it cannot be guaranteed (or is not desired to be guaranteed) that all components or network functions or services of the core network are part of a trusted domain; the same drawback also exists in roaming related to the home and / or visited networks. This is due to the current architecture, in which a single control plane towards the core network is established, (i.e., NAS communication), and in particular, the NAS security context terminates at the AMF. However, on the other hand, establishing different and separate security contexts between the user equipment and different components or network functions or services of the core network or the visited and home networks in a roaming scenario would result in information sent from one network node (such as, a network node of the visited network in a roaming scenario, or a network node of the access and mobility management function) to another network node (such as, another network node of the home network in a roaming scenario, or another network node of the session management function) being invisible, and thus, this information cannot be used by the relay network node.
[0010] Overview
[0011] One object of the present invention is to provide a technically simple, effective and cost-efficient solution for operating a user equipment to communicate with a telecommunication network and with at least two of a plurality of network functions or services of the telecommunication network or of another telecommunication network (i.e., at least two of a plurality of network functions or services of the telecommunication network, or at least one of a plurality of network functions or services of the telecommunication network and at least one of a plurality of network functions or services of another telecommunication network), wherein the user equipment operates using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service of the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service. A further object of the present invention is to provide a corresponding user equipment, a corresponding system or telecommunication network, a corresponding user equipment guiding function or service, and a corresponding program and computer-readable medium.
[0012] The object of the present invention is achieved by a method for operating a user equipment to communicate with a telecommunication network and with at least two of a plurality of network functions or services of the telecommunication network or of another telecommunication network, wherein the user equipment operates using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service of the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the operation of the user equipment using at least the first and second non-access stratum communication links comprises the following steps:
[0013] -- In a first step, the first non-access stratum communication link and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the first and second endpoint information is received by the user equipment,
[0014] -- In a second step, the first and second non-access stratum communication links are used between their respective endpoints, where a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or where a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
[0015] According to the present invention, a higher level of security and / or trust (especially by means of a first non-access stratum communication link involving the establishment of a first non-access stratum security context between a user equipment and a first network function or service, and a second non-access stratum communication link involving the establishment of a second non-access stratum security context between the user equipment and a second network function or service) can be advantageously combined with the possibility of providing a solution for linking (or chaining) different non-access stratum communication links or non-access stratum security contexts together, or, in other words, providing a possibility of implementing a certain connection between different non-access stratum communication links and / or non-access stratum security contexts, especially in a situation where the different network nodes involved need to share at least a part of the information content exchanged between these network nodes and the user equipment. Additionally, according to the present invention, by using the first and second non-access stratum endpoint information, a direct non-access stratum communication link for authenticating the user equipment including the non-access stratum security context and / or including the corresponding endpoints regarding the non-access stratum security context is achieved, thus leading to the possibility of implementing or using a zero-trust architecture. Therefore, according to the present invention, it becomes easy and efficient to establish a direct (or end-to-end) non-access stratum communication link, especially between the user equipment and the respective instances of the network function or service. Generally, a telecommunication network includes multiple network functions or services, and these network functions or services can provide different types of network function functionality to the user equipment within the telecommunication network. According to the present invention, establishing the (first and / or second) non-access stratum communication link between the user equipment and the (first and / or second) network function or service also involves establishing a non-access stratum security context between the user equipment and the corresponding (first and / or second) network function or service, and the non-access stratum security context corresponds to the non-access stratum communication link.
[0016] This contrasts with the conventional architecture of such non-access stratum communication links, which typically mainly relies on establishing a non-access stratum security context between the user equipment and the access and mobility management function, and where the security context or trust relationship of other network functions or services or network nodes (i.e., nodes other than the access and mobility management function) is completely based on the assumption that the core network of the telecommunication network is regarded as a trusted domain, and the trust between network elements within such a trusted domain is only provided in a hop-by-hop manner. According to the present invention, it can also be additionally advantageous that the user equipment transparently maintains non-access stratum security contexts with multiple network functions or services (or other entities) of the core network via the (radio) access network for different purposes, that is, maintains multiple non-access stratum security contexts, rather than only using one network function or service, especially only or mainly using the access and mobility management function as the main trusted termination point of the non-access stratum security context. In particular, this enables network functions or services that are part of the core network of the telecommunication network to be placed in different trust domains, that is, it is no longer necessary to place these network functions or services in the same trust domain, which may reduce the complexity within the core network and thus potentially increase the security and trust levels within the telecommunication network (because lower complexity usually results in fewer errors, especially regarding configuration errors). Additionally, according to the present invention, it is advantageous that the user equipment is able to know the network function or service with which it is communicating, because there is a direct and authenticated communication or connection between the user equipment and these different network functions or services (especially these network functions or services can provide different types of network function functionality), which contrasts with implicit trust in the next hop. Allowing a zero-trust architecture makes more decentralized and flexible deployments possible, for example, certain network functions or services can be deployed in a public cloud or a less trusted environment (such as a customer premise); in a conventionally known telecommunication network, this is not possible because according to the current method, core network deployment, especially 5G core network deployment, assumes a trust domain, and if this cannot be guaranteed, the "so-called trusted network functions or services" can perform arbitrary operations on the messages they receive, while other elements (including the user equipment) will not be aware of such behavior. According to the present invention, it may further be advantageous that the current non-access stratum protocol and core network architecture can be reused (although other protocols such as HTTP / 2 can also be used for communication between the user equipment and the core network). In addition to establishing different non-access stratum communication links and different non-access stratum security contexts from the user equipment to multiple different network functions or services, the present invention particularly relates to providing a solution for linking (or concatenating) different non-access stratum communication links or non-access stratum security contexts together - or in other words, providing a possibility to achieve a certain connection between different non-access stratum communication links and / or non-access stratum security contexts.This is particularly relevant in the case of roaming: especially in the case of roaming, and particularly home routing, when the user equipment 20 is not within its home network, the visited network (V-PLMN) and the home network (H-PLMN) need to exchange information in order to build an end-to-end (E2E) path including policies, charging, etc. to provide connectivity to the user equipment 20. When adopting a zero-trust approach, the network functions or services of the V-PLMN do not know any of the parameters exchanged between the user equipment 20 and its home network (H-PLMN); for example, if the V-PLMN does not know what the user equipment 20 actually requests, the V-PLMN cannot relay the control plane message to the correct network function or service (such as the session management function) in the H-PLMN. Therefore, in order for roaming to work properly, information needs to be shared between the network functions or services in the visited network and the home network. However, the secure communication between the user equipment and the network functions or services in the home network prevents the visited network from fulfilling its role properly. As already mentioned, according to the present invention, it is proposed to use multiple (or different) non-access stratum security contexts in parallel, for example for policy (PCF) and session management (SMF). Supplementary information can be obtained via different channels, such as, by way of example:
[0017] -- User Equipment Routing Selection Policy (URSP) rules (related to policy) that require metadata from a PDU session (related to session management) and / or
[0018] -- PDU session establishment (related to session management) that requires information related to the user equipment capabilities (usually exchanged during user equipment registration, i.e., related to access management) and / or
[0019] -- Set "placeholder" information elements (IEs) that are unknown to the NF but are known to be included in another security context for privacy reasons.
[0020] Although the same information (or the same (control) content) can be sent via multiple NAS security contexts so that each NAS security context is self-contained, it is more efficient, secure (e.g., it allows different network functions to have different visibility) and consistent (e.g., there can be no conflict, i.e., different values are sent in different security contexts) to be able to link different non-access stratum security contexts and / or elements thereof in a complementary manner.
[0021] According to the present invention, a user equipment operates using at least a first non-access stratum communication link and a second non-access stratum communication link, wherein the first non-access stratum communication link is involved in establishing a first non-access stratum security context between the user equipment and a first network function or service, and the second non-access stratum communication link is involved in establishing a second non-access stratum security context between the user equipment and a second network function or service. According to the present invention, operating the user equipment using at least the first and second non-access stratum communication links comprises the following steps:
[0022] -- In a first step, the first non-access stratum communication link and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the first and second endpoint information is received by the user equipment,
[0023] -- In a second step, the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
[0024] In a conventionally known telecommunication network as well as according to the present invention, non-access stratum communication relates to control plane information exchanged between a user equipment and a core network or a network node of the core network, where such network functions or services include different network functional capabilities, such as, for example, at least in the case of a 5G system, including an access and mobility management function (for access and mobility), a session management function (for session management), a policy and charging function (for providing policy information), and a location management function (for location information). Additionally, in a conventionally known telecommunication network as well as according to the present invention, at a certain specific time, the issue of which one or which several different types of network functions or services (such as SMF, SMSF, PCF, LMF, etc.) (or which instances of different types of network functions or services) actually provide services for a specific user equipment (which user equipment, for example, initiated non-access stratum communication by means of a request, etc.) is determined by the telecommunication network based on at least one of the following: the service(s) requested by the user equipment, subscription parameters, network deployment, and other parameters. The (radio) access network and / or the user equipment generally do not specifically determine which instance among multiple different SMF / SMSF / PCF / LMF instances (i.e., other types of network functions or services other than the initial access and mobility management function) provides services for the user equipment (for example, based on a given PDU session (protocol data unit session) establishment request of the user equipment, or a user equipment policy message, or a location-related message), while the (radio) access network can determine to which access and mobility management function instance the user equipment network registration is routed (although the receiving access and mobility management function instance can inform the (radio) access network to redirect the request to another access and mobility management function instance). The non-access stratum interface terminates at the access and mobility management function, and thus how non-access stratum messages are forwarded, routed, or otherwise processed cannot be seen outside the core network.
[0025] However, in a conventional telecommunication network, the Access and Mobility Management Function (AMF) serves as the sole central element for non-access stratum communication between the User Equipment (UE) and other types of network functions or services in the Core Network. For example, for session management (function) communication between the UE and the Session Management Function (SMF), the AMF performs a similar function - only, or at least mainly, a forwarding - function, just like the previously mentioned (Radio) Access Network. Similar to how the (Radio) Access Network only relays the information (of NAS-MM communication) to the AMF, in a conventional telecommunication network, the AMF performs the transmission or relay of non-access stratum message containers to and from the SMF, where the security context typically terminates at the AMF via the service-based interface and the corresponding SBIN1-N2 message requests. However, since the security context terminates at the AMF, technically, it is possible for the AMF to modify and / or overwrite these messages on their way to other network functions. In this scenario (i.e., the UE communicates with the SMF via the AMF), the service-based interface (SBI) (the interface between the AMF and the SMF) uses the HTTP / 2 protocol with JSON as the application layer serialization protocol. Additionally, the protocol stack (above the L2 layer) includes the IP layer, the Transmission Control Protocol (TCP) layer, the Transport Layer Security (TLS) layer, the HTTP / 2 layer, and the application layer. And additionally, regarding security protection at the transport layer, all 3GPP Core Network functions or services support the SBI. Authorization is typically achieved through OAuth2, which allows network functions or services to authorize (i.e., obtain tokens providing a specific level of authorization for the APIs exposed for a specific network function service) for specific network function services via the Network Repository Function (NRF). However, static authorization is also possible. This also applies to all different N1 message categories defined in TS29.518 (5GMM (the entire received NAS message (e.g., for forwarding the registration message to the target AMF in a registration procedure with AMF redirection), SM (N1 session management message), LPP (N1 LTE positioning protocol message), SMS (specific N1 SMS messages as in TS23.040 and TS24.011), UPDP (N1 message for UE policy delivery (see Appendix D of TS24.501)), LCS (N1 message of the location service message type).Regarding secure connections between the various components of the core network - as previously mentioned - in the context of 5G, interfaces based on HTTP / 2 (service-based interfaces SBI) can use TLS, but this only concerns the connection between a pair of individual network functions or services (NFs), rather than an end-to-end (E2E) security mechanism; with regard to security, when a user equipment registers to the network, a non-access stratum security context is created, which applies to non-access stratum connections, i.e., the connection between the user equipment and the access and mobility management function. Therefore, the information sent via the access and mobility management function (e.g., information sent to the session management function or other network functions or services) is visible to the access and mobility management function, which becomes a drawback in cases where it cannot be guaranteed (or is not intended to be guaranteed) that all components, network functions, or services of the core network are part of a trusted domain; the same drawback also applies to roaming regarding the home network and / or visited network. In conventionally known telecommunication networks (e.g., in the 5G core network and earlier versions of 3GPP systems), the design principle is that the core network is part of a trusted domain, i.e., the network elements within the core network are trusted, and security is provided on a hop-by-hop basis. In conventionally known telecommunication networks, a similar approach exists for roaming, where the inter-PLMN connection (N32 interface) can be secured by using TLS or PRINS: inter-PLMN user plane security (IPUPS) is a Release 16 feature of the user plane function that enforces GTP-U security on the N9 interface between the user plane functions of the visited PLMN and the home PLMN; to enable roaming, certain network functions or services need to communicate with each other, mainly the session management functions and the policy and charging functions of the visited PLMN (V-PLMN) and the home PLMN (H-PLMN), in order to establish a protocol data unit session (PDU session) that connects the user equipment and the data network (DN) via the V-PLMN; control plane and user plane connectivity are ensured between PLMNs (but not within a PLMN) via SEPP and IPUPS. The V-PLMN can locate the appropriate network functions or services in the H-PLMN (via SEPP) either based on configuration or by using the network function or service discovery procedure via the network repository function.
[0026] According to the present invention, it is further advantageous and preferred that the first non-access stratum communication link and the first non-access stratum security context are established using the first key information and / or the first encryption method, and wherein the second non-access stratum communication link and the second non-access stratum security context are established using the second key information and / or the second encryption method, wherein in particular the first key information and / or the first encryption method are different from the second key information and / or the second encryption method. Thus, the method of the present invention can be implemented and carried out in a relatively simple and effective manner: by using the first key information and / or the second key information, confidentiality can be provided with respect to the first and / or second non-access stratum security contexts, enabling the network architecture to be advantageously implemented according to the zero trust method.
[0027] According to the present invention, it is further advantageous and preferred that the second network function or service is a network function or service of another telecommunication network, particularly in the case where the user equipment is connected to or roaming within the other telecommunication network, wherein in particular, the first network function or service and the second network function or service are corresponding network functions or services that particularly provide the same type of network function functionality of the telecommunication network and another telecommunication network respectively, wherein in particular on the one hand, the first non-access stratum communication link and / or the first non-access stratum security context; on the other hand, the second non-access stratum communication link and / or the second non-access stratum security context, are implemented in a nested manner, wherein in particular, the first network function or service and the second network function or service that provide different types of network function functionality are used in parallel by the user equipment and are non-corresponding network functions or services.
[0028] Thus, the method of the present invention can be implemented and carried out in a relatively simple and effective manner, especially the method is also applicable to the roaming scenario.
[0029] In addition, according to the present invention, it is further advantageous and preferred that one of the first information element or the second information element, when used as a reference information segment for referring to the other of the first information element and the second information element, at least includes at least one of the following:
[0030] -- Non-access stratum security context identifier information for the referred non-access stratum communication link or the referred non-access stratum security context, wherein the non-access stratum security context identifier information particularly includes non-access stratum endpoint information of the referred non-access stratum security context,
[0031] -- Information element identifier of the referred information element,
[0032] In particular, the first information element and the second information element include information related to the same type of network function functionality or different types of network function functionality, in particular information related to policy and charging function functionality and / or session management function functionality and / or access and mobility management function functionality.
[0033] Thus, it is possible to effectively reference a part or a fragment of the information content transmitted in the first and / or second non-access stratum security context, that is, a part, an element or an information element of the first non-access stratum security context can reference a part, an element or an information element of the second non-access stratum security context, or a part, an element or an information element of the second non-access stratum security context can reference a part, an element or an information element of the first non-access stratum security context.
[0034] Furthermore, according to the present invention, it is further advantageous and preferred that at least the first and second non-access stratum security contexts are used in non-access stratum communication involving the user equipment and both the first network function or service and the second network function or service, in particular for transmitting user equipment routing policy rules, where in particular the information element or a part thereof is only visible and / or decodable to the first network function or service or the second network function or service if the information element or a part thereof is part of the corresponding non-access stratum security context.
[0035] Thus, it is possible to effectively hide the information content of the first non-access stratum security context from network nodes, network functions or services that are not part of the first non-access stratum security context (although these network nodes, functions or services may participate in transmitting the information content of the first non-access stratum security context, for example by relaying such information), and similarly, it is possible to effectively hide the information content of the second non-access stratum security context from network nodes, network functions or services that are not part of the second non-access stratum security context (although these network nodes, functions or services may participate in transmitting the information content of the second non-access stratum security context, for example by relaying such information).
[0036] Furthermore, according to the present invention, it is further advantageous and preferred that establishing at least one of the first non-access stratum communication link and the second non-access stratum communication link involves using a user equipment bootstrapping function or service, which may be part of a telecommunication network or accessible via a telecommunication network or through its network nodes, wherein in particular the user equipment first requests to establish at least one of the first non-access stratum communication link and the second non-access stratum communication link, and wherein the user equipment bootstrapping function or service then provides non-access stratum endpoint information related to at least one of the first network function or service and the second network function or service, and the non-access stratum endpoint information is used to establish at least one of the first non-access stratum security context and the second non-access stratum security context, and / or authenticate the user equipment with respect to one of the first network function or service and the second network function or service.
[0037] Thus, a telecommunication network (in particular its core network) including a user equipment bootstrapping function or service, or at least a user equipment bootstrapping function or service accessible via a telecommunication network (in particular its core network) or its network nodes, can be utilized to implement and carry out the method of the present invention in a relatively simple and effective manner, in particular to implement or perform the first step of the method of the present invention: Thus, the user equipment bootstrapping function or service can be used or involved, and the (first and / or second) non-access stratum communication link (and the first and / or second non-access stratum security context) to be established is established by providing the (first and / or second) non-access stratum endpoint information related to the endpoint(s) of the (first and / or second) non-access stratum communication link through the user equipment bootstrapping function or service. In particular, the endpoint(s) of the (first and / or second) non-access stratum communication link to be established (or these endpoints) correspond to
[0038] -- a specific network function or service (to which the user equipment initially explicitly requests to connect), or
[0039] -- corresponding to a specific network function or service that is initially explicitly requested by the user equipment to connect to a specific type of network functionality (i.e., a specific instance of the requested type of network functionality (usually selected by the access network, in particular by the user equipment bootstrapping function or service selection)). According to the present invention, using the user equipment bootstrapping function or service, for the non-access stratum communication link under consideration, in a first sub-step that is part of the first step of the method of the present invention, the user equipment requests to establish the non-access stratum communication link under consideration, which non-access stratum communication link relates to a specific network function or service or a specific type of network functionality; in a second sub-step, the user equipment bootstrapping function or service provides non-access stratum endpoint information related to the request of the user equipment: in the case where the request of the user equipment refers to a specific network function or service, i.e., a network function or service specifically defined by the request of the user equipment, the non-access stratum endpoint information can be provided by the user equipment bootstrapping function or service; otherwise, in the case where the user equipment only specifies a specific type of network functionality (i.e., not a network function or service specifically defined by the request of the user equipment), the user equipment bootstrapping function or service provides non-access stratum endpoint information related to the specific network function or service corresponding to the specific type of network functionality. In a third sub-step, the non-access stratum endpoint information is used to establish the non-access stratum security context and / or authenticate the user equipment with respect to the specific network function or service or the specific network function or service corresponding to the specific type of network functionality.
[0040] Furthermore, according to the present invention, it is further advantageous and preferred that for information elements and / or messages sent by the user equipment to a first network function or service or a second network function or service, the corresponding non-access stratum endpoint information is included in such information elements and / or messages sent by the user equipment, wherein the access network or access network node of the telecommunication network uses the non-access stratum endpoint information to forward such information elements and / or messages to their destination, and such information elements and / or messages sent by the user equipment particularly include source information (referring to or indicating the user equipment) and destination information (referring to or indicating the first network function or service or the second network function or service).
[0041] Thus, the method of the present invention can be implemented and carried out in a relatively simple and effective manner.
[0042] Furthermore, according to the present invention, it is further advantageous and preferred that for information elements and / or messages sent by the first network function or service or the second network function or service to the user equipment, the non-access stratum endpoint information of the user equipment is included in such information elements and / or messages sent by the first network function or service or the second network function or service, wherein the access network or access network node of the telecommunication network uses the non-access stratum endpoint information of the user equipment to forward such information elements and / or messages to the user equipment.
[0043] Therefore, according to the present invention, the method of the present invention can be implemented and carried out in a relatively simple and effective manner.
[0044] In addition, the present invention relates to a user equipment for operating with a telecommunication network and communicating with at least two of a plurality of network functions or services of the telecommunication network or another telecommunication network, wherein the user equipment operates using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service among the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the user equipment using at least the first and second non-access stratum communication links is configured such that:
[0045] - The first non-access stratum communication link and the first non-access stratum security context are established using the first non-access stratum endpoint information, and the second non-access stratum communication link and the second non-access stratum security context are established using the second non-access stratum endpoint information, wherein the user equipment receives the first and second endpoint information especially from the telecommunication network.
[0046] - The first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
[0047] Furthermore, the present invention relates to a system or a telecommunication network for operating a user equipment with a telecommunication network and for providing at least two of a plurality of network functions or services, the plurality of network functions or services being capable of providing different types of network function functionality, wherein the user equipment operates using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service of the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the system or the telecommunication network is configured such that:
[0048] - the first non-access stratum communication link and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the first and second endpoint information is transmitted by the telecommunication network to the user equipment,
[0049] - the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
[0050] Furthermore, the present invention relates to a user equipment bootstrapping function or service, which is in particular part of a system or a telecommunication network according to claim 10, for operating a user equipment with the telecommunication network using at least two of a plurality of network functions or services in the telecommunication network or in another telecommunication network, wherein the user equipment bootstrapping function or service is used to operate the user equipment using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service among the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the user equipment bootstrapping function or service is configured such that:
[0051] -- the first non-access stratum communication link and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the first and second endpoint information is transmitted by the telecommunication network, in particular by the user equipment bootstrapping function or service, to the user equipment,
[0052] -- the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
[0053] Additionally, the present invention relates to a program comprising computer-readable program code which, when executed on a computer and / or a user equipment and / or a network node of a telecommunication network (in particular a network function or service and / or a user equipment bootstrapping function or service), or partly on the user equipment and / or partly on a network node of a telecommunication network (in particular a network function or service and / or partly on a user equipment bootstrapping function or service), causes the computer and / or the user equipment and / or the network node of the telecommunication network to perform the method of the present invention.
[0054] Additionally, the present invention relates to a computer-readable medium comprising instructions which, when executed on a computer and / or a user equipment and / or a network node of a telecommunication network (in particular a network function or service and / or a user equipment bootstrapping function or service), or partly on the user equipment and / or partly on a network node of a telecommunication network (in particular a network function or service and / or a user equipment bootstrapping function or service), cause the computer and / or the user equipment and / or the network node of the telecommunication network to perform the method of the present invention.
[0055] These and other features, characteristics and advantages of the present invention will become apparent from the following detailed description in conjunction with the accompanying drawings, which illustrate by way of example the principles of the present invention. The description is for illustrative purposes only and does not limit the scope of the present invention. The reference numbers cited below refer to the drawings. Brief Description of the Drawings
[0057] Figure 1 A telecommunication network comprising an access network, a core network and a user equipment is schematically illustrated, wherein the core network typically comprises several network functions or services, such as an access and mobility management function and other network functions or services, and wherein the telecommunication network additionally comprises a user equipment bootstrapping function or service.
[0058] Figure 2 A user equipment is schematically illustrated as having established a plurality of direct non-access stratum communication links with different network functions or services of the core network of a telecommunication network.
[0059] Figure 3 A communication diagram showing direct communication between a user equipment and a user equipment bootstrapping function or service is schematically illustrated.
[0060] Figure 4 A communication diagram showing communication between a user equipment and a user equipment bootstrapping function or service via an access and mobility management function is schematically illustrated.
[0061] Figure 5 A user equipment is schematically illustrated as having established two different non-access stratum communication links with two different network functions or services of the core network of a telecommunication network.
[0062] Figure 6 A user equipment is schematically illustrated as having established non-access stratum communication links with a network function or service of the core network of a telecommunication network and with a network function or service of the core network of another telecommunication network (in particular the home public land mobile network of the user equipment), respectively.
[0063] Figure 7Schematically illustrates that a user equipment has established a non-access stratum communication link with a network function or service of the core network of a telecommunication network and with a network function or service of the core network of another telecommunication network (in particular, the home public land mobile network of the user equipment).
[0064] Figure 8 Schematically illustrates a communication diagram showing message examples between different network functions or services of a user equipment with the core network of a telecommunication network and with the core network of another telecommunication network (in particular, the home public land mobile network of the user equipment).
[0065] Detailed description
[0066] The present invention will be described in connection with specific embodiments and with reference to certain drawings, but the present invention is not limited to these and is only limited by the claims. The described drawings are only schematic and non-limiting. In the drawings, the dimensions of some elements may be exaggerated and not drawn to scale for ease of illustration.
[0067] When referring to a singular noun, the indefinite or definite article is used, e.g., "a", "an", "the", which includes the plural form of the noun, unless otherwise expressly stated.
[0068] Furthermore, the terms "first", "second", "third", etc. used in the description and claims are used to distinguish similar elements and are not necessarily used to describe an order or a time sequence. It should be understood that these terms are interchangeable where appropriate and that the embodiments described in the present invention are capable of operating in sequences different from those described or shown herein.
[0069] In Figure 1 a telecommunication network 100 including an access network 110 and a core network 120 is schematically shown. In Figure 1 the telecommunication network 100 is schematically shown as a mobile communication network 100, typically a cellular mobile communication network 100. However, the telecommunication network 100 can also be (at least partially) implemented as a fixed-line telecommunication network 100 (not shown). The telecommunication network 100, in particular the core network 120, typically includes several network functions or services 140. Among the network functions or services 140, there may be different (types of) network functions or services, i.e., network functions or services providing different network functional capabilities, such as, for example, an access and mobility management function (AMF), a session management function (SMF), a policy and charging function (PCF), and a location management function (LMF). The access network 110 includes a plurality of radio cells 11, 12. In Figure 1In the exemplary situation or scenario shown, a first base station entity 111 generates, is associated with, or spans a first radio cell 11, and a second base station entity 112 generates, is associated with, or spans a second radio cell 12. In Figure 1 , a user equipment 20 is schematically shown as part of or within the radio coverage of the first radio cell 11 / first base station entity 111. The user equipment 20 is typically (but not necessarily) mobile, i.e., capable of moving relative to the corresponding base station entities 111, 112 of the (typically, but not necessarily, static) radio cells 11, 12 or the access network 110. In Figure 1 In the exemplary illustration shown, the core network 120 of the telecommunication network 100 includes a first network function or service 141 (hereinafter also referred to as a specific network function or service 141), another network function or service 142, and a second network function or service 143 (hereinafter also referred to as another specific network function or service 143). Additionally, in Figure 1 , the core network 120 is schematically shown as including a user equipment guiding function or service 130. According to the present invention, the user equipment guiding function or service 130 can be accessed at least by the user equipment 20 or a network node, network function, or service 140 of the core network (i.e., the user equipment guiding function or service 130 is located outside the core network 120 (e.g., as part of another network, Figure 1 not shown in the figure)), but of course, according to the present invention, the user equipment guiding function or service 130 can also be part of the telecommunication network 100.
[0070] Furthermore, Figure 1 another telecommunication network 200 is shown, which is also represented as another mobile communication network 200, including another access network 210 and another core network 220, and - exemplarily - including another radio cell 13 and another base station entity 211. Another telecommunication network 200, particularly another core network 220, also typically includes several other network functions or services 240. Among the other network functions or services 240, there may be different kinds of network functions or services, i.e., network functions or services providing similar or different network function functionality as in the scenario of the telecommunication network 100. In Figure 1 In the exemplary illustration shown, the another core network 220 of the another telecommunication network 200 includes a network function or service denoted by reference numeral 241, which is particularly of the same kind (or has the same network function functionality) as the first network function or service 141.
[0071] Figure 1Primarily shows a simple case where user equipment 20 is connected to its home network 100, in particular its home public land mobile network, i.e., Figure 1 the telecommunications network 100 shown in Figure 1 corresponds to the home network of the user equipment 20. In any case, the user equipment 20 can use the access network 120 (usually a radio access network) to connect. In the case where the access network 120 does not correspond to (or does not belong to) the home network or home public land mobile network of the user equipment 20 (i.e., in the case where the telecommunications network 100 is not the home network of the user equipment 20), the access network 120 to which the user equipment 20 is connected is referred to as the visited network or visited public land mobile network of the user equipment 20; and in this case, the user equipment 20 is usually also connected to its home network, or the core network of its home network, i.e., the network related to the subscription information in the user equipment 20. In the latter case, the telecommunications network 100 corresponds to the visited telecommunications network (or visited public land mobile network or visited network), while another telecommunications network 200 corresponds to the home telecommunications network (or home public land mobile network or home network) of the user equipment 20.
[0072] The present invention provides a method for operating a user equipment 20 with a telecommunication network 100 and for communicating with at least two of a plurality of network functions or services 140 of the telecommunication network 100 or another telecommunication network 200 (i.e., the user equipment 20 operates with at least two of the plurality of network functions or services of the telecommunication network 100 (such as a first network function or service 141 and a second network function or service 143 of (the telecommunication network 100)), or the user equipment 20 operates with at least one of the plurality of network functions or services of the telecommunication network 100 (such as a first network function or service 141) and at least one of the plurality of network functions or services of another telecommunication network 200 (such as a second network function or service 241 of the other telecommunication network 200)). In any case, the user equipment 20 operates using at least a first non-access stratum communication link 21 and a second non-access stratum communication link 22, the first non-access stratum communication link 21 being established between the user equipment 20 and a first network function or service 141 of the plurality of network functions or services 140, and the second non-access stratum communication link 22 being established between the user equipment 20 and a second network function or service 143, 241 of (either the telecommunication network 100 or another telecommunication network 200). The first non-access stratum communication link 21 involves establishing a first non-access stratum security context between the user equipment 20 and the first network function or service 141, and the second non-access stratum communication link 22 involves establishing a second non-access stratum security context between the user equipment 20 and the second network function or service 143, 241. In the context of the present invention, the term "second network function or service 143, 241" refers to the case where both endpoints of the first and second non-access stratum communication links 21, 22 (and the first and second non-access stratum security contexts) are part of (or located within) the telecommunication network 100; in this scenario, the second network function or service is denoted by the reference number 143 (see Figure 5 ). However, the present invention also relates to a roaming scenario; in such a roaming scenario, the endpoints of the first non-access stratum communication link 21 (and the first non-access stratum security context) are part of (or located within) the telecommunication network 100, while the endpoints of the second non-access stratum communication link 22 (and the second non-access stratum security context) are part of (or located within) another telecommunication network 200; in this scenario, the second network function or service is denoted by the reference number 241 (see Figure 6 and Figure 7)。In accordance with the present invention, in a first step, a first non-access stratum communication link 21 and a first non-access stratum security context are established, in particular using first non-access stratum endpoint information; similarly, a second non-access stratum communication link 22 and a second non-access stratum security context are established, in particular using second non-access stratum endpoint information; in order to establish the non-access stratum communication links 21, 22, the user equipment 20 receives - in particular from the user equipment bootstrapping function or service 130 - and uses the first and second endpoint information. In accordance with the present invention, in a second step, the first and second non-access stratum communication links 21, 22 (and the corresponding non-access stratum security contexts) are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context or a second information element transmitted using the second non-access stratum security context, and / or a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context or a second information element transmitted using the second non-access stratum security context.
[0073] According to the present invention, it is preferred to use a user equipment guiding function or service 130 (in particular as part of the telecommunication network 100, or at least accessible via the telecommunication network 100 or its network nodes) to establish a non-access stratum communication link. To achieve this, preferably according to the present invention, in a first sub-step of (the first step), the user equipment 20 requests to establish a non-access stratum communication link: the user equipment 20 requests to implement or establish a (the) non-access stratum communication link with a first network function or service 141 (i.e., not only a certain specific type of network function functionality, but also its specific instance); alternatively, the user equipment 20 requests to implement or establish a (the) non-access stratum communication link with a certain specific type of network function functionality, and leaves the decision as to which instance among multiple network functions or services of the same type to the access network 110 or the core network 120 to decide. In either case, in a second sub-step of (the first step), the user equipment guiding function or service 130 provides non-access stratum endpoint information 141' (or multiple non-access stratum endpoint information for at least two non-access stratum communication links) related to the first network function or service 141 and / or related to a specific network function or service (i.e., a network function or service instance corresponding to a specific type of network function functionality), and in a third sub-step of (the first step), the non-access stratum endpoint information 141' (or multiple non-access stratum endpoint information segments) is used to establish the (the) non-access stratum security context being considered, and / or to authenticate the user equipment 20 with respect to the first network function or service 141 and / or a specific network function or service corresponding to a specific type of network function functionality.
[0074] In Figure 2 FIG., multiple direct non-access stratum communication links are schematically shown being established between the user equipment 20 and different network functions or services 140 of the core network 120 of the telecommunication network 100. As Figure 2 shown or provided, examples of the network functions or services 140 are the access and mobility management function (AMF), the session management function (SMF), and the policy and charging function (PCF). The user plane function (UPF) is also shown, and the user plane function (UPF) is also one of the multiple network functions or services 140, but the user equipment 20 uses the N3 interface or N3 reference point between the base station entity 111 (or gNB or access network 110) and the user plane function (in addition to the Uu interface or Uu reference point between the user equipment 20 and the base station entity 111 (or gNB or access network 110)) to connect to the user plane function using a user plane (UP) connection (indicated by a solid line in Figure 2 FIG.), while the connection between the user equipment 20 and another network function or service 140 (other than the user plane function) corresponds to a non-access stratum communication link, i.e., a control plane (CP) connection to the core network (in Figure 2Indicated by a dashed line in the figure): NAS-MM with the access and mobility management function, NAS-SM with the session management function, and NAS-P with the policy and charging function. The user plane function connects the user equipment 20 to a data network 300, such as the Internet. According to the present invention, by Figure 2The architecture shown (e.g., via different direct non-access stratum communication links (or multiple non-access stratum communication links and non-access stratum security contexts) between user equipment 20 and different network functions or services 140) advantageously allows user equipment 20 to transparently maintain corresponding non-access stratum security contexts with multiple core network entities (i.e., different network functions or services) via the access network for different purposes, i.e., user equipment 20 maintains multiple non-access stratum security contexts instead of using the access and mobility management function as the (especially the only) trusted endpoint for the user equipment non-access stratum security context. In particular, this allows network functions or services to be placed in different trust domains: user equipment 20 knows the network function or service it is communicating with (authenticated communication) instead of implicitly trusting the next hop. Thus, this enables a zero-trust architecture and correspondingly supports more decentralized and flexible deployments, e.g., deploying certain network functions or services in a public cloud or a less trusted environment (e.g., customer premises); in a conventional known telecommunications network, this is not possible because conventional 5G core network deployments assume a single trust domain, e.g., if not, the "presumed trusted NF" could process the messages it receives arbitrarily and other elements (including user equipment 20) would not be aware of this. According to the present invention, such an architecture can be achieved in particular by implementing bootstrapping, i.e., using a user equipment bootstrapping function or service 130. Given that the access network 110 must route control plane messages from user equipment 20 to the core network 120, the access network needs to know which network function or service 140 in the core network 120 it needs to route the corresponding control plane message to, especially in cases where user equipment 20 will be associated with many control plane network functions or services 140 and potentially assigned dynamically. To address this, user equipment 20 is provided with non-access stratum endpoints (or endpoint information) such that user equipment 20 can address different network functions or services 140, and this endpoint information can then be used by the access network 110 (or base station entity 111) to route (non-access stratum) messages, and thus a user equipment bootstrapping function or service 130 (UBF) is required. According to the present invention, two implementation options are particularly considered for the user equipment bootstrapping function or service 130: the user equipment bootstrapping function or service 130 can be regarded as or correspond to a non-access stratum component, or alternatively, the user equipment bootstrapping function or service 130 can be located or regarded as being after a network function or service (especially the access and mobility management function) (or another interpretation is that an enhanced version of the access and mobility management function can include the functionality of the user equipment bootstrapping function or service 130). In particular according to the present invention, different key / encryption methods can be used for different NAS security contexts.
[0075] In Figure 3In the figure, a communication diagram between a user equipment 20, a base station entity 111, a user equipment bootstrapping function or service 130, and an access and mobility management function as a first network function or service 141 is schematically shown. This communication diagram shows that the user equipment bootstrapping function or service 130 is a non-access stratum component, the direct communication between the user equipment 20 and the user equipment bootstrapping function or service 130, and explains the establishment of the (considered) non-access stratum communication link (together with the (considered) non-access stratum security context) with the access and mobility management function as the first network function or service 141. In the first processing step 501, an initial message (user equipment request) is sent from the user equipment 20 to the access network 110 (i.e., to the base station entity 111), and this initial message is directed or intended to be sent to the user equipment bootstrapping function or service 130 (this first message particularly includes network identifier information and user identifier information); in the second processing step 502, the access network 110 (or the base station entity 111) routes the user equipment request to the user equipment bootstrapping function or service 130 (or an instance of the user equipment bootstrapping function or service) based on the provided information and configuration. In the third processing step 503, the initial message (user equipment request) is transmitted to the user equipment bootstrapping function or service 130 (based on the network identifier information and user identifier information). In the fourth processing step 504, a non-access stratum security context is established or authenticated towards the user equipment bootstrapping function or service 130 (i.e., between the user equipment 20 and the user equipment bootstrapping function or service 130). In the fifth processing step 505, a non-access stratum message requesting non-access stratum endpoint information for NAS-MM and parameters (i.e., towards the first network function or service 141 of the (type) access and mobility management function) is sent from the user equipment 20 to the user equipment bootstrapping function or service 130. In the sixth processing step 506, the user equipment bootstrapping function or service 130 maps the request, and in the seventh processing step 507, the requested non-access stratum endpoint information 141' ((the) NAS-MM endpoints) is returned to the user equipment 20. In the eighth processing step 508, the (considered) non-access stratum security context is established and / or authenticated (between the user equipment 20 and the access and mobility management function as the first network function or service 141) using the non-access stratum endpoint information 141' (i.e., the non-access stratum endpoint for NAS-MM). In the ninth processing step 509, the access network routes the corresponding user equipment request to the first network function or service 141 based on the provided non-access stratum endpoint information 141'. In the tenth processing step 510, non-access stratum messages (in the considered case of the access and mobility management function, NAS-MM messages) can be directly and securely exchanged between the user equipment 20 and the first network function or service 141.Thus, in a scenario where the UE Bootstrapping Function or Service 130 is or is considered a non-access stratum component (direct communication with the UE 20), the UE Bootstrapping Function or Service 130 is the only component in the access network that needs to be configured to bootstrap the UE non-access stratum connectivity; based on the initial bootstrap message (first processing step 501) containing network-related information and user-related information, the access network 110 / 111 can route the message to the UE Bootstrapping Function or Service 130 (third processing step 503) so that a non-access stratum security context can be established. From this point on, the access network 110 plays a transparent role (information relay) in the information exchange between the UE 20 and the UE Bootstrapping Function or Service 130. To retrieve the non-access stratum endpoint (or non-access stratum endpoint information 141') including the requested non-access stratum endpoint type (e.g., NAS-MM), the UE 20 queries the UE Bootstrapping Function or Service 130 (processing steps 505, 506, 507). Based on the request, one or more non-access stratum endpoints or non-access stratum endpoint information fragments are returned. With the provided endpoint (information 141'), the UE 20 is able to establish a non-access stratum security context. The non-access stratum endpoint contains information that enables the access network to route messages to the corresponding network function or service. In particular (depending on different embodiments), the non-access stratum endpoint (information) 141' is or contains an IP address and / or contains information that can be mapped to an IP address (e.g., FQDN, information available for constructing a known FQDN), and / or points to data in a configuration list, and / or is mapped to a default value (pre-configured or known). After establishing the non-access stratum security context (see processing step 508), the UE 20 can communicate securely with the non-access stratum endpoint.
[0076] According to the present invention, any type of (non-user plane) network function or service can be used as the first network function or service 141 to replace the Access and Mobility Management Function as the first network function or service 141 in order to establish the corresponding (considered) non-access stratum communication link and the (considered) non-access stratum security context. For example, the Access and Mobility Management Function can be replaced with a Session Management Function, a Policy and Charging Function, a Location Management Function, or a Short Message Service Function.
[0077] In Figure 4In it, a communication diagram between a user equipment 20, a base station entity 111, a user equipment guiding function or service 130, a session management function as a first network function or service 141, and an access and mobility management function as another network function or service 142 is schematically shown. This communication diagram shows that the user equipment guiding function or service 130 is located or regarded as being after another network function or service 142 (especially the access and mobility management function). The communication between the user equipment 20 and the user equipment guiding function or service 130 is via the access and mobility management function (i.e., via another network function or service 142), and explains the establishment of a (considered) non-access stratum communication link (together with the (considered) non-access stratum security context) with the session management function as the first network function or service 141. In a first processing step 511, the user equipment 20 registers with the network (i.e., the user equipment registration is completed especially via a request according to an established procedure); this includes establishing a non-access stratum security context between the user equipment 20 and the access and mobility management function, and involves the communication between the user equipment 20 and the access and mobility management function as another network function or service 142. In a second processing step 512, the access network 110, especially the base station entity 111, routes the user equipment request to the access and mobility management function as another network function or service 142 (i.e., an instance among potential multiple access and mobility management function instances); this occurs based on the provided information and configuration. In a third processing step 513, the user equipment 20 transmits a non-access stratum message requesting an endpoint of the (non-access stratum communication link) for NAS-SM communication (i.e., towards the session management function, or an instance providing session management functionality); this non-access stratum message also includes appropriate parameters. In a fourth processing step 514, another network function or service 142 (usually but not necessarily the access and mobility management function) retrieves NAS-SM-related endpoint request information from the user equipment guiding function or service 130, including, in a fifth processing step 515, requesting (the) NAS-SM endpoint or endpoint information 141' from the user equipment guiding function or service 130, and, in a sixth processing step 516, retrieving (or receiving) (the) NAS-SM endpoint or endpoint information 141' from the user equipment guiding function or service 130. In a seventh processing step 517, the access and mobility management function (as another network function or service 142) generates (the) NAS-SM endpoint (i.e., non-access stratum endpoint information 141') to be sent to the user equipment 20 based on the information received from the user equipment guiding function or service 130, and transmits the non-access stratum endpoint information 141' to the user equipment 20 via the access network 110 (i.e., the base station entity 111), see Figure 4The eighth processing step 518 and the ninth processing step 519 in. In the tenth processing step 520, a non-access stratum security context (to be considered) between the user equipment 20 and the session management function as the first network function or service 141 is established and / or authenticated using the non-access stratum endpoint information 141' (i.e., the non-access stratum endpoint for NAS-SM). In the eleventh processing step 521, the access network routes the corresponding user equipment request to the first network function or service 141 based on the provided non-access stratum endpoint information 141' (in Figure 4 it is the session management function); subsequently, non-access stratum messages (in the case of the session management function to be considered, NAS-SM messages) can be directly and securely exchanged between the user equipment 20 and the first network function or service 141. Therefore, in order to reduce the necessity of modifying the access network functionality (or reduce the impact on the access network), for example, the access and mobility management function is enhanced to further include the functionality of providing the non-access stratum endpoint (or non-access stratum endpoint information) to the user equipment 20. In this case, the user equipment network registration and the establishment of the non-access stratum security context with the access and mobility management function (as another network function or service) are performed based on conventionally known procedures, and the messages are routed to the access and mobility management function based on existing methods. The user equipment 20 can then request the access and mobility management function (as another network function or service 142) to provide the non-access stratum endpoint towards the session management function (for example, NAS-SM to establish a PDU session). Then, the access and mobility management function as another network function or service 142 retrieves the non-access stratum endpoint information from the user equipment bootstrapping function or service 130 based on the information provided by the user equipment 20 (the user equipment bootstrapping function or service functionality can in particular be a component of the access and mobility management function and is based on a simple method (such as configuration within the access and mobility management function)), and one or more non-access stratum endpoints (or endpoint information fragments) are returned to the user equipment 20; with the provided non-access stratum endpoint, the user equipment 20 can then establish the non-access stratum security context (to be considered) with the session management function (i.e., the first network function or service 141).
[0078] In this regard, Figure 5Schematically illustrates that the user equipment 20 (i.e., in parallel) has established two different non-access stratum communication links 21, 22 with two different network functions or services 141, 143 (first and second network functions or services) in the core network 120 of the telecommunication network 100, namely, the first non-access stratum communication link 21 with the first network function or service 141, and the second non-access stratum communication link 22 with the second network function or service 143. Between the user equipment 20 and the (radio) access network 110, non-access stratum signaling is transmitted via the air interface (in the case of a mobile communication network) towards the base station entity 111 (specifically, gNB). The (radio) access network 110 forwards the non-access stratum signaling (transparently forwarded by the gNB), but its content is encrypted. Between the (radio) access network 110 and the core network 120, the security context transmits the non-access stratum signaling between the user equipment 20 and several network functions or services in the core network 120 in parallel.
[0079] Figure 6 Schematically illustrates another example of two parallel non-access stratum security contexts, in which the user equipment 20 has established the first non-access stratum communication link 21 with the first network function or service 141 in the core network 120 of the telecommunication network 100 (e.g., as its visited network), and has established the second non-access stratum communication link 22 with the second network function or service 241 in another core network 220 of another telecommunication network 200 (e.g., as its home network). Therefore, Figure 6 Particularly shows the case of roaming and the application of multiple security contexts 21, 22 (e.g., in the policy and charging function): In this case, the H-PCF (the second network function or service 241) can directly send the information that needs to be protected via the security context 22 from the user equipment to the H-PCF 241, and send a reference to the V-PCF 141. In the case where the information (even if the content is unknown to the V-PCF) needs to be referenced in its communication with the user equipment 20, the V-PCF 141 can use this reference to construct its message. The two-way arrow between the first network function or service 141 (e.g., the policy and charging function of the visited network) and the second network function or service 241 (e.g., the policy and charging function of the home network) illustrates the inter-PLMN interaction between the network functions or services for the roaming case.
[0080] Figure 7Schematically illustrates that the user equipment 20 communicates with different network functions in a nested manner using multiple non-access stratum security contexts, where the user equipment 20 establishes a first non-access stratum communication link 21 with a first network function or service 141 in the core network 120 of the telecommunication network 100, and a second non-access stratum communication link 22 with a second network function or service 241 in another core network 220 of another telecommunication network 200. In particular, the telecommunication network 100 corresponds to the visited network of the user equipment 20, and the other telecommunication network 200 corresponds to the home network of the user equipment 20. Figure 7 Shows an example where the non-access stratum communication links between the user equipment 20 and multiple network functions or services are connected in series or nested together (realizing a network function chain through nested security contexts), for example, in the case of URSP rule signaling in home routed roaming. In this case, two PCFs are required (i.e., the first network function or service 141 is the policy and charging function (V-PCF) in the visited network, and the second network function or service 241 is the policy and charging function (H-PCF) in the home network of the user equipment 20); in its simplest form, the forwarding entity has no knowledge of the information content being forwarded: the gNB or base station entity 111 in the radio access network 110 may not even be aware of the existence of multiple nested non-access stratum security contexts (nevertheless, it still performs the same role of transparent forwarding as previously explained); between the radio access network 110 and the core network 120 of the visited network, the nested non-access stratum security context conveys the non-access stratum signaling between the user equipment 20 and the network functions or services in the core network; the V-PCF 141 can access the information in its security context, but otherwise, it realizes the transparent forwarding of the nested security content. Although the H-PCF 241 is responsible for setting the URSP rules, the V-PCF 141 needs to set the V-SMF ( Figure 7 not shown in the figure), and thus indirectly in the V-UPF ( Figure 7Quality of service (QoS) is set in (not shown in the figure) to enable the establishment of a promised QoS. However, the H-PLMN may wish to hide some information from the V-PLMN. However, it may be beneficial to enable different levels of visibility for the forwarding entity. To enable different levels of visibility for different elements in the transmitted information fragments, the URSP rules can be sent from the H-PCF 241 to the V-PCF 141 via the current method. However, the part of the information that the H-PLMN does not want to disclose to the V-PLMN (such as the application ID) can be sent via the NAS security context between the H-PCF and the UE, either in parallel with the NAS security context of the V-PCF 141 or nested in the NAS security context of the V-PCF 141. Therefore, it is possible for an information element in one non-access stratum security context to reference another non-access stratum security context or its information element. The same situation may also exist on the interface between the H-PCF 241 and the V-PCF 141 (which may be implemented using N24). Using the V / H-PCF + H-NAS-P interface or protocol or alternatively using the N32 and SEPP interfaces or protocols, the relay functionality of the V-PCF 141 (for forwarding communications to and receiving from the H-PCF 241) can access the information transmitted in the N24 (or N32 / SEPP) interface between the H-PCF 241 and the V-PCF 141, but cannot access the information transmitted between the H-PCF 241 and the user equipment 20, so that the user equipment 20 can reconstruct the complete information received via the NAS security context between the PCF 141 of the V-PLMN and the PCF 241 of the H-PLMN, and the information elements can be referenced between the security contexts. The references include:
[0081] -- Non-access stratum security context identifier information for the referenced non-access stratum communication link or the referenced non-access stratum security context, where the non-access stratum security context identifier information particularly includes the non-access stratum endpoint information of the referenced non-access stratum security context,
[0082] -- Information element identifier of the referenced information element.
[0083] The V-PCF 141 (intermediate network function / service) relays NAS messages between the user equipment 20 and the H-PCF 241 (final network function / service). Although the intermediate network function or service is aware that some information is transmitted via the second channel, it cannot access that information. In an alternative embodiment, the H-PCF 241 is capable of sending data elements consisting of information elements (IEs) (e.g., NAS IEs in the case of the UE policy container) to the V-PCF 141 (e.g., UE policy container), where some of the IEs are visible to the V-PCF 141 (e.g., securely transmitted using the security context between the H-PCF 241 and the V-PCF 141), while some other elements are not visible: the content of the IE (e.g., the V-PCF 141 may be aware that the URSP rule references an application descriptor but cannot see the actual descriptor), or the IE content and IE type (e.g., the V-PCF 141 may only see that some of the information contained in the URSP rule is encrypted). Preferably and advantageously, an encryption method (e.g., signature) is applied to ensure that the non-encrypted IEs cannot be modified by the V-PCF 141; in this case, the data elements received by the user equipment 20 (e.g., the URSP rule described above) may contain or include information from two security contexts, i.e., these IEs can be verified as originating from the V-PCF 141 and / or the H-PCF 241. Such scenarios are in Figure 8is schematically shown, which shows a communication diagram between a user equipment 20, a base station entity 111, another network function or service 142 (such as an access and mobility management function, AMF), a visited policy and charging function V-PCF as a first network function or service 141, and a home policy and charging function H-PCF as a second network function or service 241. The communication diagram shows examples of messages: a first message from the H-PCF 241 to the V-PCF 141 (in the first processing step 531), a second message from the V-PCF 141 to the AMF 142 (in the second processing step 532), and a third message from the AMF 142 to the user equipment 20 (in the third processing step 533). The first message includes: a parameter A (or information element A), which is transmitted from the H-PCF 241 to the V-PCF 141 in a non-access stratum security context, and a parameter B (or information element B), which is transmitted from the H-PCF 241 to the user equipment 20 in a non-access stratum security context. The second message includes: a parameter A (or information element A), which is transmitted from the V-PCF 141 to the user equipment 20 in a non-access stratum security context; a parameter B (or information element B), which is transmitted from the H-PCF 241 to the user equipment 20 in a non-access stratum security context; and a parameter C (or information element C), which is transmitted from the V-PCF 141 to the AMF 142 in a non-access stratum security context. The third message includes: a parameter A (or information element A), which is transmitted from the V-PCF 141 to the user equipment 20 in a non-access stratum security context; a parameter B (or information element B), which is transmitted from the H-PCF 241 to the user equipment 20 in a non-access stratum security context; and a parameter C (or information element C), which is transmitted from the AMF 142 to the user equipment 20 in a non-access stratum security context. Thus, a given parameter can be sent so that an intermediate recipient can be aware of it (if this is desired), and information can also be hidden from the intermediate recipient (if this is desired). According to the present invention, in particular, these two embodiments or methods are preferably combined for sending non-access stratum information elements (IEs):
[0084] -- via multiple non-access stratum security contexts, i.e., in an authenticated, secure, and integrity-protected manner,
[0085] -- through multiple forwarding entities, and / or
[0086] -- allowing fine-grained control over which / which entities can view, add, remove, and / or change the values in the non-access stratum signaling chain, and / or
[0087] -- without duplicating the data used by entities that need to communicate via different non-access stratum security contexts.
Claims
1. A method for operating a user equipment (20) with a telecommunication network (100) and for communicating with at least two of a plurality of network functions or services (140) of the telecommunication network (100) or another telecommunication network (200), wherein the user equipment (20) operates using at least a first non-access stratum communication link (21) and a second non-access stratum communication link (22), the first non-access stratum communication link (21) being established between the user equipment (20) and a first network function or service (141) of the plurality of network functions or services (140), and the second non-access stratum communication link (22) being established between the user equipment (20) and a second network function or service (143, 241), wherein the first non-access stratum communication link (21) involves establishing a first non-access stratum security context between the user equipment (20) and the first network function or service (141), and the second non-access stratum communication link (22) involves establishing a second non-access stratum security context between the user equipment (20) and the second network function or service (143, 241). Wherein the operation of the user equipment (20) using at least the first and second non-access stratum communication links (21, 22) comprises the following steps: -- In a first step, the first non-access stratum communication link (21) and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link (22) and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the first and second endpoint information is received by the user equipment (20). -- In a second step, the first and second non-access stratum communication links (21, 22) are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
2. The method according to claim 1, wherein the first non-access stratum communication link (21) and the first non-access stratum security context are established using first key information and / or a first encryption method, and wherein the second non-access stratum communication link (22) and the second non-access stratum security context are established using second key information and / or a second encryption method. In particular, the first key information and / or the first encryption method are different from the second key information and / or the second encryption method.
3. The method according to any one of the preceding claims, wherein in particular in the case where the user equipment (20) is connected to another telecommunication network (200) or is roaming within another telecommunication network (200), the second network function or service (143, 241) is a network function or service of the other telecommunication network (200), wherein in particular the first network function or service (141) and the second network function or service (143, 241) are corresponding network functions or services, in particular network functions or services that respectively provide the same type of network function functionality of the telecommunication network (100) and the other telecommunication network (200), wherein in particular the first non-access stratum communication link (21) and / or the first non-access stratum security context are implemented in a nested manner with the second non-access stratum communication link (22) and / or the second non-access stratum security context, wherein in particular the first network function or service (141) and the second network function or service (143, 241) are used in parallel by the user equipment (20) and are non-corresponding network functions or services that provide different types of network function functionality.
4. The method according to any one of the preceding claims, wherein one of the first information element and the second information element, when used as a reference information segment for referring to the other of the first information element and the second information element, at least includes at least one of the following: -- Non-access stratum security context identifier information for the referred non-access stratum communication link or the referred non-access stratum security context, wherein the non-access stratum security context identifier information particularly includes non-access stratum endpoint information of the referred non-access stratum security context, -- Information element identifier of the referred information element, wherein in particular the first information element and the second information element include information related to the same type of network function functionality or different types of network function functionality, in particular information related to policy and charging function functionality and / or session management function functionality and / or access and mobility management function functionality.
5. The method according to any one of the preceding claims, wherein in non-access stratum communication involving the user equipment (20) and both the first network function or service (141) and the second network function or service (143, 241), at least the first and second non-access stratum security contexts are used, in particular for transmitting user equipment routing policy rules, wherein in particular only in the case where the corresponding information element or a part thereof is part of the corresponding non-access stratum security context, the information element or a part thereof is visible and / or decodable to the first network function or service (141) or the second network function or service (143, 241).
6. The method of any of the preceding claims, wherein establishing at least one of the first non-access stratum communication link and the second non-access stratum communication link involves using a user equipment bootstrapping function or service (130), the user equipment bootstrapping function or service (130) being part of the telecommunication network (100) or accessible via the telecommunication network (100) or through its network nodes, wherein in particular the user equipment (20) first requests to establish at least one of the first non-access stratum communication link and the second non-access stratum communication link, wherein the user equipment bootstrapping function or service (130) then provides non-access stratum endpoint information (141') related to at least one of the first network function or service (141) and the second network function or service (143, 241), and the non-access stratum endpoint information (141') is used to establish at least one of the first non-access stratum security context and the second non-access stratum security context, and / or to authenticate the user equipment (20) with respect to one of the first network function or service (141) and the second network function or service (143, 241).
7. The method according to any one of the preceding claims, wherein, For information elements and / or messages sent by the user equipment (20) to the first network function or service (141) or the second network function or service (143, 241), the corresponding non-access stratum endpoint information (141') is included in such information elements and / or messages sent by the user equipment (20), wherein the access network (110) or access network node (111) in the telecommunication network (100) uses the non-access stratum endpoint information (141') to forward such information elements and / or messages to their destination, wherein such information elements and / or messages sent by the user equipment (20) particularly include source information referring to or indicating the user equipment (20) and destination information referring to or indicating the first network function or service (141) or the second network function or service (143, 241).
8. The method of any one of the preceding claims, wherein For information elements and / or messages sent by the first network function or service (141) or the second network function or service (143, 241) to the user equipment (20), the non-access stratum endpoint information of the user equipment (20) is included in such information elements and / or messages sent by the first network function or service (141) or the second network function or service (143, 241), wherein the access network (110) or access network node (111) in the telecommunication network (100) uses the non-access stratum endpoint information of the user equipment (20) to forward such information elements and / or messages to the user equipment (20).
9. A user equipment (20) for operating with a telecommunication network (100) and for communicating with at least two of a plurality of network functions or services (140) of the telecommunication network (100) or another telecommunication network (200), wherein the user equipment (20) operates using at least a first non-access stratum communication link (21) and a second non-access stratum communication link (22), the first non-access stratum communication link (21) being established between the user equipment (20) and a first network function or service (141) of the plurality of network functions or services (140), and the second non-access stratum communication link (22) being established between the user equipment (20) and a second network function or service (143, 241), wherein the first non-access stratum communication link (21) involves establishing a first non-access stratum security context between the user equipment (20) and the first network function or service (141), and the second non-access stratum communication link (22) involves establishing a second non-access stratum security context between the user equipment (20) and the second network function or service (143, 241), wherein the user equipment (20) using at least the first and second non-access stratum communication links is configured such that: -- the first non-access stratum communication link (21) and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link (22) and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the user equipment (20) receives the first and second endpoint information in particular from the telecommunication network (100), -- the first and second non-access stratum communication links (21, 22) are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
10. A system or telecommunications network (100) for operating a user equipment (20) with a telecommunications network (100) and for providing at least two of a plurality of network functions or services (140), the plurality of network functions or services (140) being capable of providing different types of network function functionality, wherein the user equipment (20) operates using at least a first non-access stratum communication link (21) and a second non-access stratum communication link (22), the first non-access stratum communication link (21) being established between the user equipment (20) and a first network function or service (141) of the plurality of network functions or services (140), and the second non-access stratum communication link (22) being established between the user equipment (20) and a second network function or service (143, 241), wherein the first non-access stratum communication link (21) involves establishing a first non-access stratum security context between the user equipment (20) and the first network function or service (141), and the second non-access stratum communication link (22) involves establishing a second non-access stratum security context between the user equipment (20) and the second network function or service (143, 241). Wherein the system or telecommunications network (100) is configured such that: -- the first non-access stratum communication link (21) and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link (22) and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the first and second endpoint information is transmitted by the telecommunications network (100) to the user equipment (20). -- the first and second non-access stratum communication links (21, 22) are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context being considered or a second information element transmitted using the second non-access stratum security context being considered, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context being considered or a second information element transmitted using the second non-access stratum security context being considered.
11. A user equipment bootstrapping function or service (130), in particular as part of a system or telecommunications network (100) according to claim 10, for operating a user equipment (20) with the telecommunications network (100) using at least two of a plurality of network functions or services in the telecommunications network (100) or another telecommunications network (200), wherein the user equipment bootstrapping function or service (130) is used to operate the user equipment (20) using at least a first non-access stratum communication link (21) and a second non-access stratum communication link (22), the first non-access stratum communication link (21) being established between the user equipment (20) and a first network function or service among the plurality of network functions or services (140), and the second non-access stratum communication link (22) being established between the user equipment (20) and a second network function or service (143, 241), wherein the first non-access stratum communication link (21) involves establishing a first non-access stratum security context between the user equipment (20) and the first network function or service (141), and the second non-access stratum communication link (22) involves establishing a second non-access stratum security context between the user equipment (20) and the second network function or service (143, 241). Wherein the user equipment bootstrapping function or service (130) is configured such that: -- the first non-access stratum communication link (21) and the first non-access stratum security context are established using first non-access stratum endpoint information, and the second non-access stratum communication link (22) and the second non-access stratum security context are established using second non-access stratum endpoint information, wherein the first and second endpoint information is transmitted by the telecommunications network (100), in particular by the user equipment bootstrapping function or service (130), to the user equipment (20). -- the first and second non-access stratum communication links (21, 22) are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
12. A program comprising computer-readable program code which, when the program code is executed on a computer and / or a user equipment (20) and / or a network node of a telecommunication network (100), in particular a network function or service (140), and / or a user equipment boot function or service (130), or partly on the user equipment (20) and / or partly on the network node of the telecommunication network (100), in particular the network function or service (140), and / or partly on the user equipment boot function or service (130), causes the computer and / or the user equipment (20) and / or the network node of the telecommunication network (100) to perform a method according to one of claims 1-8.
13. A computer-readable medium comprising instructions which, when the instructions are executed on a computer and / or a user equipment (20) and / or a network node of a telecommunication network (100), in particular a network function or service (140), and / or a user equipment boot function or service (130), or partly on the user equipment (20) and / or partly on the network node of the telecommunication network (100), in particular the network function or service (140), and / or partly on the user equipment boot function or service (130), causes the computer and / or the user equipment (20) and / or the network node of the telecommunication network (100) to perform a method according to one of claims 1-8.
Citation Information
Patent Citations
Method for provisioning enhanced communication capabilities to user equipment
CN110063064A
Method for an improved exchange and / or interworking functionality between a first mobile communication network and a second mobile communication network, system, network exchange function, program and computer program product
EP3937521A1
Wireless communications
US20190387407A1
Handling registrations of a user equipment in different communication networks
WO2022064424A1
NAS counts for multiple wireless connections
WO2022087964A1