Method for a user equipment to communicate with at least two network functions or services on one or more telecommunication networks

By using multiple non-access stratum communication links and security contexts in the telecommunications network, the security and trust issues between user equipment and the core network are resolved, enabling more efficient and secure communication. This is suitable for communication between user equipment and multiple network functions or services in 5G networks.

CN120239982BActive Publication Date: 2026-03-24DEUTSCHE TELEKOM AG
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-04
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing telecommunications networks, non-access layer communication between user equipment and the core network presents security and trust issues, especially in roaming scenarios, where information cannot be effectively shared, resulting in network complexity and insufficient security.

Method used

It employs at least two non-access layer communication links and security contexts to establish direct connections with different network functions or services. Secure communication between user equipment and multiple network functions or services is achieved through the endpoint information of the first and second non-access layers. A zero-trust architecture is adopted to ensure secure transmission and authentication of information between different network nodes.

Benefits of technology

It improves the security and trustworthiness of telecommunications networks, reduces network complexity, supports flexible deployment and information sharing in different trust domains, and achieves efficient end-to-end communication, especially in roaming scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120239982B_ABST
    Figure CN120239982B_ABST
Patent Text Reader

Abstract

The invention relates to a method for operating a user equipment with a telecommunication network, comprising the following steps: - in a first step, establishing a first non-access stratum communication link and a first non-access stratum security context using first non-access stratum endpoint information and establishing a second non-access stratum communication link and a second non-access stratum security context using second non-access stratum endpoint information, - in a second step, using the first and the second non-access stratum communication link between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] background

[0002] The present invention relates to a method for operating user equipment and communicating with a telecommunications network and at least two of a plurality of network functions or services of the telecommunications network or another telecommunications network.

[0003] In addition, the present invention relates to a user equipment for operating with a telecommunications network and communicating with at least two of a plurality of network functions or services of the telecommunications network or another telecommunications network.

[0004] Additionally, the present invention relates to a system or telecommunications network for operating user equipment and a telecommunications network, and for providing at least two of a plurality of network functions or services of the telecommunications network or another telecommunications network.

[0005] In addition, the present invention relates to a user equipment guidance function or service, particularly as part of a system or telecommunications network according to the invention, for operating a user equipment with the telecommunications network using at least two of a plurality of network functions or services in the telecommunications network or another telecommunications network.

[0006] Additionally, the present invention relates to a program and a computer-readable medium for operating user equipment and a telecommunications network and for communicating with at least two of a plurality of network functions or services of the telecommunications network or another telecommunications network, according to the method of the present invention.

[0007] In conventional telecommunications networks, the interface used between user equipment (via access networks such as radio access networks, RAN) and the core network (CN) is based on a non-access stratum protocol stack, or NAS protocol stack. From a system architecture perspective, NAS communication refers to the logical interface between user equipment and the CN. Taking mobile communication networks as an example, especially mobile communication networks based on the 5G standard, the non-access stratum protocol (usually the non-access stratum mobility management protocol (NAS-MM)) is transmitted, for example, on top of the NG-AP protocol stack (gNB-5G core application protocol stack). The NG-AP protocol stack typically includes NG-APs above the L1 (physical layer), L2 (data link layer), IP (Internet Protocol) layer, and SCTP (flow control transmission protocol) layer, thereby realizing, for example, the N2 interface, or N2 reference point, between the 5G access network and the access and mobility management function (AMF) network functions or services of the core (5G) network. The NG-AP protocol stack (NG-AP is a 3GPP protocol defined in TS 38.413) is used to transmit control plane (CP) information between the radio access network and the Access and Mobility Management Function (AMF) between the user equipment and the core network. In the scenario under consideration, the (radio) access network acts as a relay for Non-Access Layer Signaling (NAS-MM) (used between the 5G access network protocol layer (which is used between user equipment and base station entities, particularly gNodeBs) and the NG-AP protocol stack (which uses NG-AP as a lower protocol layer to be transmitted to the AMF)), and the (radio) access network (AN) does not access the NAS-MM information (i.e., the content of NAS-MM communication); it merely relays the information to the Access and Mobility Management Function (AMF), meaning that the so-called NAS-MM security context terminates at the Access and Mobility Management Function (AMF). In conventionally known telecommunications networks, the (radio) access network determines, based on configuration, typically, the requested telecommunications network (particularly the Public Land Mobile Network, PLMN) and network slice (or multiple network slices), the AMF network function or service to which to communicate (among multiple different potential AMF network functions or services or multiple different instances in the telecommunications network). The (radio) access network routes a given registration request (transmitted by the user equipment) to an AMF network function or service, or to one of the potential AMFs in the list of possible AMFs.

[0008] In conventional telecommunications networks, non-access stratum communication involves the exchange of control plane information between the UE and network nodes of the CN element or core network. For example, in the case of 5G systems, this includes communication between the user equipment and multiple different network function functionalities, such as, for example, AMF (for access and mobility), SMF (for session management), PCF (for policy information), and LMF (for location information). Therefore, the Access and Mobility Management (AMM) function serves as a core element of non-access stratum communication between the user equipment (UE) and other network functions or services (i.e., different network function functionalities) of the core network. Non-access stratum communication between the UE and other network function functionalities (i.e., network functions or services other than AMM) is achieved through a combination of the following: on the one hand, using non-access stratum protocols for transmission between the radio access network and AMM; and on the other hand, based on Nxxx services (e.g., N11 / Nsmf for NAS-SM towards session management functions, N20 / Nsmsf towards short message service functions, N15 / Npcf towards UE policies for policy and charging functions, or NL1 / Nlmf towards LCS (Location Service) for location management functions).

[0009] Regarding security in conventionally known telecommunications networks, a Non-Access Layer (NAL) security context is created when a user equipment (UE) registers with the network. This security context applies to NAL connections, i.e., connections between the UE and access and mobility management (AM) functions; this means that information sent via AM functions (e.g., to session management functions, etc.) is visible to AM functions. This is a drawback in situations where it cannot be guaranteed (or is undesirable to guarantee) that all components, network functions, or services of the core network are part of a trusted domain; the same drawback exists with roaming related to the home and / or visited network. This is due to the current architecture, which establishes a single control plane oriented towards the core network (i.e., NAS communication), specifically where the NAS security context terminates at the AMF. However, on the other hand, establishing different and separate security contexts between user equipment and different components or network functions or services of the visited and home networks in the core network or roaming scenarios will result in information sent from one network node (e.g., a network node of the visited network in the roaming scenario, or a network node of the access and mobility management function) to another network node (e.g., another network node of the home network in the roaming scenario, or another network node of the session management function) being invisible, and therefore, this information cannot be used by the relay network node.

[0010] Overview

[0011] One objective of this invention is to provide a technically simple, effective, and cost-efficient solution for operating user equipment (UE) to communicate with a telecommunications network and with at least two of a plurality of network functions or services of the telecommunications network or another telecommunications network (i.e., at least two of a plurality of network functions or services of the telecommunications network, or at least one of a plurality of network functions or services of the telecommunications network and at least one of a plurality of network functions or services of another telecommunications network). The UE operates using at least a first non-access stratum (NAS) communication link and a second NAS communication link. The first NAS communication link is established between the UE and a first network function or service, and the second NAS communication link is established between the UE and the second network function or service. The first NAS communication link involves establishing a first NAS security context between the UE and the first network function or service, and the second NAS communication link involves establishing a second NAS security context between the UE and the second network function or service. A further objective of this invention is to provide corresponding UEs, corresponding systems or telecommunications networks, corresponding UE boot functions or services, and corresponding programs and computer-readable media.

[0012] The objective of this invention is achieved by a method for operating a user equipment (UE) to communicate with at least two of a plurality of network functions or services of a telecommunications network or another telecommunications network, wherein the UE operates using at least a first non-access stratum (NAS) communication link and a second NAS communication link, the first NAS communication link being established between the UE and a first network function or service, and the second NAS communication link being established between the UE and the second network function or service, wherein the first NAS communication link involves establishing a first NAS security context between the UE and the first network function or service, and the second NAS communication link involves establishing a second NAS security context between the UE and the second network function or service, wherein operation of the UE using at least the first and second NAS communication links includes the following steps:

[0013] -- In the first step, first non-access stratum endpoint information is used to establish the first non-access stratum communication link and the first non-access stratum security context, and second non-access stratum endpoint information is used to establish the second non-access stratum communication link and the second non-access stratum security context, wherein the first and second endpoint information are received by the user equipment.

[0014] -- In the second step, the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the considered second non-access stratum security context or a second information element transmitted using the considered second non-access stratum security context, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the considered second non-access stratum security context or a second information element transmitted using the considered second non-access stratum security context.

[0015] According to the invention, a higher level of security and / or trust (particularly through a first non-access stratum communication link involving the establishment of a first non-access stratum security context between a user equipment and a first network function or service, and a second non-access stratum communication link involving the establishment of a second non-access stratum security context between a user equipment and a second network function or service) can be advantageously combined with the possibility of providing a solution that links (or concatenates) different non-access stratum communication links or non-access stratum security contexts together, or, in other words, the possibility of achieving some kind of connection between different non-access stratum communication links and / or non-access stratum security contexts, particularly in cases where the different network nodes involved need to share at least a portion of the information content exchanged between these network nodes and the user equipment. Furthermore, according to the invention, by using first and second non-access stratum endpoint information, a direct non-access stratum communication link including a non-access stratum security context and / or including authentication of the user equipment by a corresponding endpoint regarding the non-access stratum security context is realized, thereby leading to the possibility of implementing or using a zero-trust architecture. Therefore, according to the invention, establishing direct (or end-to-end) non-access stratum communication links, particularly between corresponding instances of user equipment and network functions or services, becomes easy and efficient. Typically, telecommunications networks include multiple network functions or services, and these network functions or services can provide different types of network functionality to user equipment within the telecommunications network. According to the present invention, establishing a (first and / or second) non-access stratum communication link between the user equipment and (first and / or second) network functions or services also involves establishing a non-access stratum security context between the user equipment and the corresponding (first and / or second) network functions or services, the non-access stratum security context corresponding to the non-access stratum communication link.

[0016] This contrasts with the conventional architecture of such non-access stratum communication links, which typically relies primarily on establishing a non-access stratum security context between user equipment and access and mobility management functions (AMs). The security contexts or trust relationships of other network functions or services or network nodes (i.e., nodes other than AMs) are entirely based on the assumption that the core network of the telecommunications network is considered a trusted domain, and trust between network elements within such a trusted domain is provided only hop-by-hop. According to the invention, it is also advantageous that user equipment transparently maintains non-access stratum security contexts with multiple network functions or services (or other entities) of the core network via the (radio) access network for different purposes, i.e., maintaining multiple non-access stratum security contexts instead of using only one network function or service, particularly using only or primarily AMs as the primary trusted endpoint of the non-access stratum security context. In particular, this allows network functions or services that are part of the core network of the telecommunications network to be placed in different trust domains, i.e., it is no longer necessary to place these network functions or services in the same trust domain. This can reduce complexity within the core network and potentially improve the level of security and trust within the telecommunications network (because lower complexity generally results in fewer errors, especially regarding configuration errors). Additionally, according to the invention, it is advantageous that the user equipment (UE) is aware of the network functions or services it is communicating with, because there is direct and authenticated communication or connection between the UE and these different network functions or services (especially those that provide different kinds of network functionality), in contrast to implicit trust next hops. Allowing a zero-trust architecture enables more decentralized and flexible deployments, for example, certain network functions or services can be deployed in public clouds or less trusted environments (e.g., customer premises); this is impossible in conventionally known telecommunications networks because, according to current methods, core network deployments, especially 5G core network deployments, assume a trust domain, and if this is not guaranteed, a “so-called trusted network function or service” can arbitrarily manipulate the messages it receives without the other elements (including the UE) being aware of such behavior. A further advantage according to the invention is that current non-access stratum protocols and core network architectures can be reused (although other protocols such as HTTP / 2 can also be used for communication between the UE and the core network).

[0017] In addition to establishing different non-access stratum communication links and different non-access stratum security contexts from user equipment to multiple different network functions or services, this invention particularly relates to providing a solution for linking (or cascading) different non-access stratum communication links or non-access stratum security contexts together—or in other words, providing a possibility for achieving some kind of connection between different non-access stratum communication links and / or non-access stratum security contexts. This is particularly relevant in roaming scenarios: especially in roaming, particularly in home routing scenarios, when user equipment 20 is not within its home network, the visited network (V-PLMN) and the home network (H-PLMN) need to exchange information to construct an end-to-end (E2E) path, including policies, charging, etc., to provide connectivity to user equipment 20. With a zero-trust approach, the network functions or services of the V-PLMN are unaware of any parameters exchanged between user equipment 20 and its home network (H-PLMN); for example, if the V-PLMN does not know what user equipment 20 is actually requesting, the V-PLMN cannot relay control plane messages to the correct network functions or services (e.g., session management functions) in the H-PLMN. Therefore, for roaming to function properly, information sharing is required between network functions or services in the visited network and the home network. However, secure communication between user equipment and network functions or services in the home network prevents the visited network from fulfilling its role. As already mentioned, according to the present invention, it is recommended to use multiple (or different) non-access layer security contexts in parallel, such as those for policy (PCF) and session management (SMF). Supplementary information can be obtained via different channels, such as, for example:

[0018] --User equipment routing policy (URSP) rules (policy-related) and / or metadata from PDU sessions (related to session management)

[0019] -- PDU session establishment (related to session management) and / or requiring information related to user equipment capabilities (typically exchanged during user equipment registration, i.e., related to access management).

[0020] --Sets "placeholder" information elements (IE) that are unknown to NF but are known to be contained in another security context for privacy reasons.

[0021] While it is possible to send the same information (or the same (control) content) through multiple NAS security contexts so that each NAS security context is self-contained, it would be more efficient, secure (e.g., it allows different network functions to have different visibility) and consistent (e.g., it is impossible for them to conflict, i.e., send different values ​​in different security contexts).

[0022] According to the present invention, a user equipment (UE) operates using at least a first non-access stratum (NAS) communication link and a second NAS communication link, wherein the first NAS communication link involves establishing a first NAS security context between the UE and a first network function or service, and the second NAS communication link involves establishing a second NAS security context between the UE and the second network function or service. According to the present invention, operating the UE using at least the first and second NAS communication links includes the following steps:

[0023] -- In the first step, first non-access stratum endpoint information is used to establish a first non-access stratum communication link and a first non-access stratum security context, and second non-access stratum endpoint information is used to establish a second non-access stratum communication link and a second non-access stratum security context, wherein the first and second endpoint information are received by the user equipment.

[0024] -- In the second step, the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the considered second non-access stratum security context or a second information element transmitted using the considered second non-access stratum security context, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the considered second non-access stratum security context or a second information element transmitted using the considered second non-access stratum security context.

[0025] In conventional telecommunications networks and according to the present invention, non-access stratum communication involves the exchange of control plane information between user equipment and the core network or network nodes of the core network. Such network functions or services include various network functionalities, such as, for example, at least in the case of 5G systems, access and mobility management functions (for access and mobility), session management functions (for session management), policy and charging functions (for providing policy information), and location management functions (for location information). Furthermore, in conventional telecommunications networks and according to the present invention, at a given time, the question of which type of network function or service (such as SMF, SMSF, PCF, LMF, etc.) (or which instances of different types of network functions or services) actually provides services to a particular user equipment (which initiated non-access stratum communication, for example, through a request) is determined by the telecommunications network based on at least one of the following: the services requested by the user equipment, subscription parameters, network deployment, and other parameters. The (radio) access network and / or user equipment typically do not specifically determine which of the multiple different SMF / SMSF / PCF / LMF instances (i.e., other types of network functions or services besides the initial access and mobility management function) serves the user equipment (e.g., based on a user equipment-based PDU (Protocol Data Unit Session) establishment request, user equipment policy message, or location-related message). However, the (radio) access network can determine which access and mobility management function instance the user equipment's network registration is routed to (although the receiving access and mobility management function instance can inform the (radio) access network to redirect the request to another access and mobility management function instance). Non-access stratum interfaces terminate at the access and mobility management function, and therefore, it is not visible outside the core network how non-access stratum messages are forwarded, routed, or otherwise processed.

[0026] However, in conventional telecommunications networks, the Access and Mobility Management (AMF) function serves as the sole central element for non-access stratum communication between user equipment (UE) and other network functions or services in the core network. For example, for session management (Function) communication between UE and the Session Management Function (SMF), the AMF performs a similar function—only, or at least primarily, a forwarding function—as the aforementioned (radio) access network. Similar to how the (radio) access network merely relays (NAS-MM communication) information to the AMF, in conventional telecommunications networks, the AMF performs the transmission or relay of non-access stratum message containers to and from the SMF, where the security context typically terminates at the AMF via a service-based interface and corresponding SBI N1-N2 message requests. However, because the security context terminates at the AMF, it is technically possible for the AMF to modify and / or overwrite these messages en route to other network functions. In this scenario (i.e., user equipment and session management functions communicate via access and mobility management functions), the Service-Based Interface (SBI) (the interface between access and mobility management functions and session management functions) uses the HTTP / 2 protocol with JSON as the application layer serialization protocol. Furthermore, the protocol stack (above the L2 layer) includes the IP layer, Transmission Control Protocol (TCP) layer, Transport Layer Security (TLS) layer, HTTP / 2 layer, and application layer. Additionally, regarding security protection at the transport layer, all 3GPP core network functions or services support SBI. Authorization is typically implemented via OAuth2, which allows network functions or services to authorize specific network function(s) services via the Network Repository Function (NRF) (i.e., obtain a token granting a specific level of authorization to the APIs exposed by a particular network function service). However, static authorization is also possible. This also applies to all the different N1 message categories defined in TS29.518 (5GMM (the entire NAS message received, such as for forwarding registration messages to the target AMF in a registration procedure with AMF redirection), SM (N1 Session Management Message), LPP (N1 LTE Location Protocol Message), SMS (such as N1 SMS messages specific to TS 23.040 and TS 24.011), UPDP (N1 messages for UE policy delivery (see Appendix D of TS 24.501)), LCS (N1 messages of the Location Services Message type).Regarding secure connections between components of the core network—as mentioned earlier—in the context of 5G, HTTP / 2-based interfaces (Service-Based Interfaces, SBIs) can use TLS, but this only pertains to connections between individual network functions or services (NFs), not end-to-end (E2E) security mechanisms. Regarding security, when a user equipment registers with the network, a non-access stratum security context is created. This context applies to non-access stratum connections, i.e., connections between the user equipment and access and mobility management functions (AMs). Therefore, information sent via AMs (e.g., to session management functions or other network functions or services) is visible to AMs. This becomes a disadvantage when it is not guaranteed (or not intended to be guaranteed at all) that all components, network functions, or services of the core network are part of a trusted domain. The same disadvantage applies to roaming regarding the home network and / or the visited network. In conventional telecommunications networks (e.g., in early versions of 5G core networks and 3GPP systems), the design principle is that the core network is part of a trusted domain, meaning that network elements within the core network are trusted, and security is provided on a hop-by-hop basis. In conventional telecommunications networks, similar methods exist for roaming, where inter-PLMN connections (N32 interface) can be secured using TLS or PRINS. Inter-PLMN User Plane Security (IPUPS) is a version 16 feature of the user plane function, which enforces GTP-U security on the N9 interface between the user plane functions of the visited PLMN and the home PLMN. For roaming to be possible, certain network functions or services need to communicate with each other, primarily the session management and policy and accounting functions of the visited PLMN (V-PLMN) and the home PLMN (H-PLMN), to establish Protocol Data Unit (PDU) sessions connecting the user equipment and data network (DN) via the V-PLMN. Control plane and user plane connectivity is guaranteed between PLMNs (but not within PLMNs) via SEPP and IPUPS. The V-PLMN can locate the appropriate network functions or services in the H-PLMN (via SEPP) either based on configuration or through network function or service discovery procedures using the network repository function.

[0027] According to the invention, it is further advantageous and preferred that the first non-access layer communication link and the first non-access layer security context are established using first key information and / or a first encryption method, and wherein the second non-access layer communication link and the second non-access layer security context are established using second key information and / or a second encryption method, wherein in particular the first key information and / or the first encryption method are different from the second key information and / or the second encryption method.

[0028] Therefore, the method of the present invention can be implemented and carried out in a relatively simple and effective manner: confidentiality can be provided with respect to the security context of the first and / or second non-access layer by using first key information and / or second key information, thereby enabling the network architecture to be advantageously implemented according to the zero-trust approach.

[0029] According to the invention, it is further advantageous and preferred that the second network function or service is a network function or service of another telecommunications network, particularly in cases where the user equipment is connected to or roams within that other telecommunications network. Specifically, the first network function or service and the second network function or service are corresponding network functions or services that respectively provide the same type of network function functionality for the telecommunications network and the other telecommunications network. Specifically, on the one hand, the first non-access stratum communication link and / or the first non-access stratum security context; on the other hand, the second non-access stratum communication link and / or the second non-access stratum security context are implemented in a nested manner. Specifically, the first network function or service and the second network function or service, providing different types of network function functionality, are used in parallel by the user equipment and are non-corresponding network functions or services.

[0030] Therefore, the method of the present invention can be implemented and carried out in a relatively simple and effective manner, and in particular, the method is also applicable to roaming scenarios.

[0031] Furthermore, according to the present invention, it is further advantageous and preferred that, when one of the first information element or the second information element is used as a reference information segment referencing the other of the first information element and the second information element, it includes at least one of the following:

[0032] --Non-access stratum security context identifier information used for the referenced non-access stratum communication link or the referenced non-access stratum security context, wherein the non-access stratum security context identifier information specifically includes the non-access stratum endpoint information of the referenced non-access stratum security context.

[0033] --The information element identifier of the referenced information element.

[0034] Specifically, the first and second information elements include information related to the functionality of the same type of network function or to the functionality of different types of network functions, particularly information related to the functionality of policy and charging functions and / or session management functions and / or access and mobility management functions.

[0035] Therefore, it is possible to effectively reference parts or fragments of information content transmitted in the first and / or second non-access layer security contexts, that is, parts, elements or information elements of the first non-access layer security context can reference parts, elements or information elements of the second non-access layer security context, or parts, elements or information elements of the second non-access layer security context can reference parts, elements or information elements of the first non-access layer security context.

[0036] Furthermore, according to the invention, it is further advantageous and preferred that, in non-access layer communications involving both user equipment and the first network function or service and the second network function or service, at least first and second non-access layer security contexts are used, particularly for transmitting user equipment routing policy rules, wherein, in particular, the information element or part thereof is visible and / or decodable to the first network function or service or the second network function or service only when the corresponding information element or part thereof is part of the corresponding non-access layer security context.

[0037] Therefore, the information content of the first non-access layer security context can be effectively hidden from network nodes, network functions, or services that are not part of the first non-access layer security context (although these network nodes, functions, or services may participate in transmitting the information content of the first non-access layer security context, for example, by relaying such information), and similarly, the information content of the second non-access layer security context can be effectively hidden from network nodes, network functions, or services that are not part of the second non-access layer security context (although these network nodes, functions, or services may participate in transmitting the information content of the second non-access layer security context, for example, by relaying such information).

[0038] Furthermore, according to the invention, it is further advantageous and preferred that establishing at least one of the first non-access stratum communication link and the second non-access stratum communication link involves using a user equipment bootstrapping function or service, which may be part of a telecommunications network or accessible via a telecommunications network or through its network nodes. Specifically, the user equipment first requests to establish at least one of the first non-access stratum communication link and the second non-access stratum communication link, wherein the user equipment bootstrapping function or service subsequently provides non-access stratum endpoint information related to the first network function or service and the second network function or service, and this non-access stratum endpoint information is used to establish at least one of the first non-access stratum security context and the second non-access stratum security context, and / or to authenticate the user equipment with respect to the first network function or service and the second network function or service.

[0039] Therefore, the method of the present invention can be implemented and carried out in a relatively simple and effective manner using a telecommunications network (especially its core network) that includes user equipment bootstrapping functions or services, or at least via user equipment bootstrapping functions or services accessible through a telecommunications network (especially its core network) or its network nodes. Specifically, the first step of the method of the present invention can be implemented or carried out using user equipment bootstrapping functions or services. This involves providing (first and / or second) non-access stratum communication link (and first and / or second non-access stratum security context) endpoint information related to the endpoints of the (first and / or second) non-access stratum communication link to be established, thereby establishing the (first and / or second) non-access stratum communication link and the (first and / or second) non-access stratum security context. In particular, the endpoints (or these endpoints) of the (first and / or second) non-access stratum communication link to be established correspond to...

[0040] -- (The specific network function or service that the user equipment initially and explicitly requests to connect to, or

[0041] --Corresponding to a specific network function or service of a particular type of network function functionality initially explicitly requested by the user equipment (i.e., a specific instance of the requested type of network function functionality (typically selected by the access network, particularly by the user equipment bootstrapping function or service)). According to the invention, using the user equipment bootstrapping function or service, for a considered non-access stratum communication link, in a first sub-step as part of the first step of the method of the invention, the user equipment requests to establish a considered non-access stratum communication link, which involves a specific network function or service or a specific type of network function; in a second sub-step, the user equipment bootstrapping function or service provides non-access stratum endpoint information related to the user equipment's request: in cases where the user equipment's request refers to a specific network function or service, i.e., a network function or service specifically defined by the user equipment's request, the non-access stratum endpoint information can be provided by the user equipment bootstrapping function or service; otherwise, in cases where the user equipment only specifies a specific type of network function functionality (i.e., not a network function or service specifically defined by the user equipment's request), the user equipment bootstrapping function or service provides non-access stratum endpoint information related to the specific network function or service corresponding to that specific type of network function functionality. In the third sub-step, non-access layer endpoint information is used to establish the non-access layer security context under consideration and / or to authenticate user equipment for specific network functions or services or specific network functions or services corresponding to a specific type of network function functionality.

[0042] Furthermore, according to the invention, it is further advantageous and preferred that, for information elements and / or messages sent by the user equipment to the first network function or service or the second network function or service, corresponding non-access stratum endpoint information is included in such information elements and / or messages sent by the user equipment, wherein the access network or access network node of the telecommunications network uses the non-access stratum endpoint information to forward such information elements and / or messages to their destination, wherein such information elements and / or messages sent by the user equipment specifically include source information (referring to or indicating the user equipment) and destination information (referring to or indicating the first network function or service or the second network function or service).

[0043] Therefore, the method of the present invention can be implemented and carried out in a relatively simple and effective manner.

[0044] Furthermore, according to the invention, it is further advantageous and preferred that, for information elements and / or messages sent to the user equipment by the first network function or service or the second network function or service, the non-access stratum endpoint information of the user equipment is included in such information elements and / or messages sent by the first network function or service or the second network function or service, wherein the access network or access network node of the telecommunications network uses the non-access stratum endpoint information of the user equipment to forward such information elements and / or messages to the user equipment.

[0045] Therefore, according to the present invention, the method of the present invention can be implemented and carried out in a relatively simple and effective manner.

[0046] Additionally, the present invention relates to a user equipment for communicating with a telecommunications network and at least two of a plurality of network functions or services of the telecommunications network or another telecommunications network, wherein the user equipment operates using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service of the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and the second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the user equipment using at least the first and second non-access stratum communication links is configured such that:

[0047] -- First non-access stratum endpoint information is used to establish a first non-access stratum communication link and a first non-access stratum security context, and second non-access stratum endpoint information is used to establish a second non-access stratum communication link and a second non-access stratum security context, wherein the user equipment receives the first and second endpoint information, specifically from the telecommunications network.

[0048] -- The first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.

[0049] Furthermore, the present invention relates to a system or telecommunications network for operating user equipment and a telecommunications network, and for providing at least two of a plurality of network functions or services capable of providing different types of network function functionality, wherein the user equipment operates using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and the first network function or service, and the second non-access stratum communication link being established between the user equipment and the second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the system or telecommunications network is configured such that:

[0050] -- First non-access stratum endpoint information is used to establish a first non-access stratum communication link and a first non-access stratum security context, and second non-access stratum endpoint information is used to establish a second non-access stratum communication link and a second non-access stratum security context, wherein the first and second endpoint information are transmitted from the telecommunications network to the user equipment.

[0051] -- The first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.

[0052] Additionally, the present invention relates to a user equipment bootstrapping function or service for operating a user equipment and a telecommunications network using at least two of a plurality of network functions or services in a telecommunications network or another telecommunications network, wherein the user equipment bootstrapping function or service is used to operate the user equipment using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service, and the second non-access stratum communication link being established between the user equipment and the second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service, and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the user equipment bootstrapping function or service is configured such that:

[0053] -- First non-access stratum endpoint information is used to establish a first non-access stratum communication link and a first non-access stratum security context, and second non-access stratum endpoint information is used to establish a second non-access stratum communication link and a second non-access stratum security context, wherein the first and second endpoint information are transmitted to the user equipment by the telecommunications network, particularly by user equipment bootstrapping functions or services.

[0054] -- The first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context under consideration or a second information element transmitted using the second non-access stratum security context under consideration.

[0055] Additionally, the present invention relates to a program comprising computer-readable program code that, when executed on a computer and / or a network node of a user equipment and / or a telecommunications network (particularly network functions or services and / or user equipment boot functions or services), or partially executed on a user equipment and / or partially on a network node of a telecommunications network (particularly network functions or services and / or partially on a user equipment boot functions or services), causes the computer and / or the user equipment and / or the network node of the telecommunications network to perform the method of the present invention.

[0056] Additionally, the present invention relates to a computer-readable medium comprising instructions that, when executed on a computer and / or a network node of a user equipment and / or a telecommunications network (particularly network functions or services and / or user equipment boot functions or services), or partially executed on a user equipment and / or partially on a network node of a telecommunications network (particularly network functions or services and / or partially on a user equipment boot functions or services), cause the computer and / or the user equipment and / or the network node of the telecommunications network to perform the method of the present invention.

[0057] These and other features, characteristics, and advantages of the present invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings, which illustrate the principles of the invention by way of example. This description is for illustrative purposes only and does not limit the scope of the invention. Reference numerals cited below refer to the accompanying drawings. Brief description of the attached diagram

[0059] Figure 1 The illustration depicts a telecommunications network comprising an access network, a core network, and user equipment. The core network typically includes several network functions or services, such as access and mobility management functions and other network functions or services. Additionally, the telecommunications network includes user equipment guidance functions or services.

[0060] Figure 2 The illustration illustrates how user equipment and the core network of the telecommunications network establish multiple direct non-access layer communication links, representing different network functions or services.

[0061] Figure 3 The diagram illustrates a communication diagram showing direct communication between user equipment and user equipment guidance functions or services.

[0062] Figure 4 The diagram illustrates communication between user equipment and user equipment guidance functions or services via access and mobility management functions.

[0063] Figure 5 This illustration demonstrates how two different network functions or services of the user equipment and the core network of the telecommunications network establish two different non-access stratum communication links.

[0064] Figure 6 The illustration illustrates the establishment of non-access stratum communication links between the user equipment and the core network of a telecommunications network, as well as with the core network of another telecommunications network (particularly the user equipment's home public land mobile network).

[0065] Figure 7 The illustration illustrates the establishment of non-access stratum communication links between the user equipment and the core network of a telecommunications network, as well as with the core network of another telecommunications network (particularly the user equipment's home public land mobile network).

[0066] Figure 8 The diagram illustrates communication examples between different network functions or services of a user equipment and the core network of a telecommunications network, as well as the core network of another telecommunications network (particularly the home public land mobile network of the user equipment).

[0067] Detailed description

[0068] This invention will be described in conjunction with specific embodiments and with reference to certain accompanying drawings, but the invention is not limited thereto, but only by the claims. The described drawings are merely illustrative and not limiting. In the drawings, the dimensions of some elements may be exaggerated and not drawn to scale for illustrative purposes.

[0069] Use the indefinite or definite article when referring to a singular noun, such as “one,” “a,” or “the,” which includes the plural form of the noun, unless otherwise explicitly stated.

[0070] Furthermore, the terms "first," "second," "third," etc., used in the specification and claims are used to distinguish similar elements and are not necessarily used to describe an order or chronological sequence. It should be understood that these terms are interchangeable where appropriate, and the embodiments described in this invention can operate in orders other than those stated or shown herein.

[0071] exist Figure 1 The image schematically illustrates a telecommunications network 100, including an access network 110 and a core network 120. Figure 1In this diagram, telecommunications network 100 is schematically shown as mobile communication network 100, typically a cellular mobile communication network 100. However, telecommunications network 100 can also (at least partially) be implemented as a fixed-line telecommunications network 100 (not shown). Telecommunications network 100, particularly core network 120, typically includes several network functions or services 140. Among the network functions or services 140, there may be different (types) of network functions or services, i.e., network functions or services providing different network function functionalities, such as, for example, Access and Mobility Management Function (AMF), Session Management Function (SMF), Policy and Charging Function (PCF), and Location Management Function (LMF). Access network 110 includes multiple radio cells 11, 12. Figure 1 In the exemplary situation or scenario shown, the first base station entity 111 generates a first radio cell 11 or is associated with or crosses the first radio cell 11, and the second base station entity 112 generates a second radio cell 12 or is associated with or crosses the second radio cell 12. Figure 1 The image schematically illustrates user equipment 20 as part of or within the radio coverage area of ​​a first radio cell 11 / first base station entity 111. User equipment 20 is typically (but not necessarily) mobile, meaning it is capable of moving relative to (typically, but not necessarily, static) the corresponding base station entities 111, 112 of the radio cells 11, 12 or access network 110. Figure 1 In the exemplary description shown, the core network 120 of the telecommunications network 100 includes a first network function or service 141 (hereinafter also referred to as a specific network function or service 141), another network function or service 142, and a second network function or service 143 (hereinafter also referred to as another specific network function or service 143). Additionally, in Figure 1 In the diagram, core network 120 is schematically shown as including user equipment bootstrapping functionality or service 130. According to the invention, user equipment bootstrapping functionality or service 130 can be accessed by user equipment 20 or by network nodes, network functions, or services 140 of the core network (i.e., user equipment bootstrapping functionality or service 130 is located outside core network 120 (e.g., as part of another network)). Figure 1 (not shown in the image), but of course, according to the present invention, the user equipment guidance function or service 130 may also be part of the telecommunications network 100.

[0072] in addition, Figure 1Another telecommunications network 200 is illustrated, also referred to as another mobile communication network 200, including another access network 210 and another core network 220, and—exemplarily—including another radio cell 13 and another base station entity 211. This other telecommunications network 200, particularly the other core network 220, also typically includes several other network functions or services 240. Among these other network functions or services 240, there may be different kinds of network functions or services, i.e., network functions or services that provide similar functionality to those in the telecommunications network 100 scenario but with different network function capabilities. Figure 1 In the exemplary explanation shown, another core network 220 of another telecommunications network 200 includes a network function or service indicated by reference number 241, which in particular belongs to the same class (or has the same network function functionality) as the first network function or service 141.

[0073] Figure 1 This mainly illustrates a simple scenario where user equipment 20 is connected to its home network 100, specifically its home public land mobile network, i.e. Figure 1 The telecommunications network 100 shown corresponds to the home network of user equipment 20. In any case, user equipment 20 can connect using access network 120 (typically a radio access network). In cases where access network 120 does not correspond to (or belong to) the home network or home public land mobile network of user equipment 20 (i.e., where telecommunications network 100 is not the home network of user equipment 20), the access network 120 to which user equipment 20 is connected is referred to as the visited network or visited public land mobile network of user equipment 20; and in this case, user equipment 20 is also typically connected to its home network, or the core network of its home network, i.e., the network associated with the subscription information in user equipment 20. In the latter case, telecommunications network 100 corresponds to the visited telecommunications network (or the visited public land mobile network or the visited network), while another telecommunications network 200 corresponds to the home telecommunications network (or the home public land mobile network or the home network) of user equipment 20.

[0074] The present invention provides a method for operating a user equipment 20 and a telecommunications network 100, and for communicating with at least two of a plurality of network functions or services 140 of the telecommunications network 100 or another telecommunications network 200 (i.e., operating the user equipment 20 with at least two of a plurality of network functions or services of the telecommunications network 100 (e.g., the first network function or service 141 and the second network function or service 143 of the telecommunications network 100), or operating the user equipment 20 with at least one of a plurality of network functions or services of the telecommunications network 100 (e.g., the first network function or service 141) and at least one of a plurality of network functions or services of the other telecommunications network 200 (e.g., the second network function or service 241 of the other telecommunications network 200). In any case, user equipment 20 operates using at least a first non-access stratum communication link 21 and a second non-access stratum communication link 22. The first non-access stratum communication link 21 is established between user equipment 20 and a first network function or service 141 among a plurality of network functions or services 140, and the second non-access stratum communication link 22 is established between user equipment 20 and a second network function or service 143, 241 (either of telecommunications network 100 or another telecommunications network 200). The first non-access stratum communication link 21 involves establishing a first non-access stratum security context between user equipment 20 and the first network function or service 141, and the second non-access stratum communication link 22 involves establishing a second non-access stratum security context between user equipment 20 and the second network function or service 143, 241. In the context of this invention, the term "second network function or service 143, 241" refers to a situation where the endpoints of both the first and second non-access layer communication links 21, 22 (and the first and second non-access layer security contexts) are part of (or located within) the telecommunications network 100; in this scenario, the second network function or service is designated by reference numeral 143 (see [reference numeral]). Figure 5 However, the present invention also relates to roaming scenarios; in such roaming scenarios, the endpoint of the first non-access layer communication link 21 (and the first non-access layer security context) is part of (or located within) telecommunications network 100, while the endpoint of the second non-access layer communication link 22 (and the second non-access layer security context) is part of (or located within) another telecommunications network 200; in this scenario, the second network function or service is indicated by reference numeral 241 (see reference 241). Figure 6 and Figure 7According to the invention, in the first step, first non-access stratum endpoint information is used in particular to establish a first non-access stratum communication link 21 and a first non-access stratum security context; similarly, second non-access stratum endpoint information is used in particular to establish a second non-access stratum communication link 22 and a second non-access stratum security context; in order to establish non-access stratum communication links 21, 22, user equipment 20 receives—in particular from user equipment boot function or service 130—and uses the first and second endpoint information. According to the invention, in the second step, the first and second non-access stratum communication links 21, 22 (and their respective non-access stratum security contexts) are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context or a second information element transmitted using the second non-access stratum security context, and / or a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context or a second information element transmitted using the second non-access stratum security context.

[0075] According to the invention, it is preferred to establish a non-access stratum communication link using user equipment guidance functions or services 130 (particularly as part of telecommunications network 100, or at least accessible via telecommunications network 100 or its network nodes). To achieve this, it is preferred that, according to the invention, in a first sub-step (of the first step), user equipment 20 requests to establish a non-access stratum communication link: user equipment 20 requests to implement or establish a non-access stratum communication link with a first network function or service 141 (i.e., not only a certain type of network function functionality, but also a specific instance thereof); alternatively, user equipment 20 requests to implement or establish a non-access stratum communication link with a certain type of network function functionality, and leaves the decision of which instance of the multiple network functions or services of the same type involves to the access network 110 or the core network 120. In either case, in the second sub-step (of the first step), the user equipment bootstrapping function or service 130 provides non-access stratum endpoint information 141' (or multiple non-access stratum endpoint information for at least two non-access stratum communication links) related to the first network function or service 141 and / or to a specific network function or service (i.e., an instance of a network function or service corresponding to a specific type of network function functionality), and in the third sub-step (of the first step), the non-access stratum endpoint information 141' (or multiple fragments of non-access stratum endpoint information) is used to establish the considered non-access stratum security context, and / or to authenticate the user equipment 20 with respect to the first network function or service 141 and / or the specific network function or service corresponding to a specific type of network function functionality.

[0076] exist Figure 2 The diagram schematically illustrates that user equipment 20 establishes multiple direct non-access stratum communication links with the core network 120 of telecommunications network 100, representing different network functions or services 140. For example... Figure 2 Examples of network functions or services 140 shown or provided are Access and Mobility Management Function (AMF), Session Management Function (SMF), and Policy and Charging Function (PCF). User Plane Function (UPF) is also shown, and the User Plane Function (UPF) is one of several network functions or services 140, but User Equipment 20 uses (other than the Uu interface or Uu reference point between User Equipment 20 and Base Station Entity 111 (or gNB or Access Network 110)) the N3 interface or N3 reference point between Base Station Entity 111 (or gNB or Access Network 110) and the User Plane Function, using the User Plane (UP) connection (in... Figure 2 The connection between user equipment 20 and another network function or service 140 (other than the user plane function) (indicated by solid lines) corresponds to a non-access stratum communication link, i.e., a connection to the control plane (CP) of the core network. Figure 2(Indicated by dashed lines): NAS-MM with access and mobility management functions, NAS-SM with session management functions, and NAS-P with policy and accounting functions. The user plane functions connect user equipment 20 to a data network 300, such as the Internet. According to the present invention, via... Figure 2The architecture illustrated (e.g., through different direct non-access stratum communication links (or multiple non-access stratum communication links and non-access stratum security contexts) between User Equipment 20 and different network functions or services 140) is advantageous because User Equipment 20 can transparently maintain corresponding non-access stratum security contexts with multiple core network entities (i.e., different network functions or services) via the access network for different purposes. That is, User Equipment 20 maintains multiple non-access stratum security contexts instead of using access and mobility management functions as (especially the sole) trusted endpoint for the User Equipment's non-access stratum security context. In particular, this allows network functions or services to be placed in different trust domains: User Equipment 20 is aware of the network function or service it is communicating with (authenticated communication), rather than implicitly trusting the next hop. Therefore, this enables a zero-trust architecture and correspondingly supports more decentralized and flexible deployments, such as deploying certain network functions or services in public clouds or less trusted environments (e.g., customer premises); this is impossible in conventional, known telecommunications networks because conventional 5G core network deployments assume a trust domain, for example, if not, a “presumed trusted NF” could arbitrarily process the messages it receives without the knowledge of other elements (including user equipment 20). According to the invention, such an architecture can be implemented specifically by implementing bootstrapping, i.e., using user equipment bootstrapping functions or services 130. Given that access network 110 must route control plane messages from user equipment 20 to core network 120, access network needs to know which network function or service 140 (in core network 120) it needs to route the corresponding control plane messages to, especially in cases where user equipment 20 will be associated with many control plane network functions or services 140 and potentially dynamically assigned. To address this situation, User Equipment 20 is provided with a Non-Access Stratum (NAS) endpoint (or endpoint information) that enables it to address different network functions or services 140. This endpoint information can then be used by Access Network 110 (or Base Station Entity 111) to route (NAS) messages, thus requiring the use of User Equipment Bootstrapping Function or Service 130 (UBF). According to the invention, two implementations of UBF are particularly considered for UBF: UBF 130 may be considered as or correspond to a NAS component, or alternatively, UBF 130 may be located at or considered as following a network function or service (particularly Access and Mobility Management functions) (or, in another interpretation, an enhanced version of Access and Mobility Management functions may include the functionality of UBF 130). Specifically, according to the invention, different key / encryption methods can be used in different NAS security contexts.

[0077] exist Figure 3The diagram schematically illustrates the communication between User Equipment 20, Base Station Entity 111, User Equipment Bootstrapping Function or Service 130, and Access and Mobility Management Function as First Network Function or Service 141. This communication diagram shows that User Equipment Bootstrapping Function or Service 130 is a non-access stratum component—direct communication between User Equipment 20 and User Equipment Bootstrapping Function or Service 130, and explains the establishment of a non-access stratum communication link (in conjunction with the non-access stratum security context) with Access and Mobility Management Function as First Network Function or Service 141. In the first processing step 501, an initial message (User Equipment Request) is sent by User Equipment 20 to Access Network 110 (i.e., to Base Station Entity 111). This initial message is directed to or intended for User Equipment Bootstrapping Function or Service 130 (the first message specifically includes network identifier information and user identifier information). In the second processing step 502, Access Network 110 (or Base Station Entity 111) routes the User Equipment Request to User Equipment Bootstrapping Function or Service 130 (or an instance of User Equipment Bootstrapping Function or Service 130) based on the provided information and configuration. In the third processing step 503, the initial message (User Equipment Request) is transmitted to User Equipment Bootstrapping Function or Service 130 (based on the network identifier information and user identifier information). In the fourth processing step 504, a non-access stratum security context is established or authenticated for User Equipment Bootstrapping Function or Service 130 (i.e., between User Equipment 20 and User Equipment Bootstrapping Function or Service 130). In the fifth processing step 505, a non-access stratum message requesting non-access stratum endpoint information for NAS-MM and parameters (i.e., toward the first network function or service 141 as an access and mobility management function) is sent by user equipment 20 to user equipment bootstrapping function or service 130. In the sixth processing step 506, user equipment bootstrapping function or service 130 maps the request, and in the seventh processing step 507, returns the requested non-access stratum endpoint information 141' (the NAS-MM endpoint) to user equipment 20. In the eighth processing step 508, using the non-access stratum endpoint information 141' (i.e., the non-access stratum endpoint for NAS-MM), a non-access stratum security context is established and / or authenticated (between user equipment 20 and the access and mobility management function as the first network function or service 141). In the ninth processing step 509, the access network routes the corresponding user equipment request to the first network function or service 141 based on the provided non-access stratum endpoint information 141'. In the tenth processing step 510, non-access stratum messages (NAS-MM messages in the case of access and mobility management functions) can be exchanged directly and securely between user equipment 20 and the first network function or service 141.Therefore, in the case where User Equipment Bootstrapping Function or Service 130 is or is considered a Non-Access Stratum (NAS) component (directly communicating with User Equipment 20), User Equipment Bootstrapping Function or Service 130 is the only component in the access network that needs to be configured for bootstrapping User Equipment NAS connectivity. Based on the initial boot message (first processing step 501) containing network-related and user-related information, access network 110 / 111 can route the message to User Equipment Bootstrapping Function or Service 130 (third processing step 503) to enable the establishment of a NAS security context. From this point onward, access network 110 plays a transparent role (information relay) in the information exchange between User Equipment 20 and User Equipment Bootstrapping Function or Service 130. To retrieve an NAS endpoint (or NAS endpoint information 141') including the requested NAS endpoint type (e.g., NAS-MM), User Equipment 20 queries User Equipment Bootstrapping Function or Service 130 (processing steps 505, 506, 507). Based on the request, one or more NAS endpoints or NAS endpoint information fragments are returned. Using the provided endpoint (information 141'), user equipment 20 can establish a non-access stratum security context. The non-access stratum endpoint contains information that enables the access network to route messages to the appropriate network function or service. Specifically (according to different embodiments), the non-access stratum endpoint (information) 141' is or contains an IP address and / or contains information that can be mapped to an IP address (e.g., an FQDN, which can be used to construct a known FQDN), and / or points to data in a configuration list, and / or maps to default values ​​(pre-configured or known). After establishing the non-access stratum security context (see processing step 508), user equipment 20 can securely communicate with the non-access stratum endpoint.

[0078] According to the present invention, any type of (non-user plane) network function or service can be used as the first network function or service 141 to replace the access and mobility management function as the first network function or service 141, so as to establish the corresponding (considered) non-access layer communication link and (considered) non-access layer security context. For example, the access and mobility management function can be replaced by session management function, policy and charging function, location management function, and short message service function.

[0079] exist Figure 4The diagram schematically illustrates a communication diagram between User Equipment 20, Base Station Entity 111, User Equipment Bootstrapping Function or Service 130, Session Management Function as a First Network Function or Service 141, and Access and Mobility Management Function as another Network Function or Service 142. This communication diagram shows that—User Equipment Bootstrapping Function or Service 130 is located or is considered to be after another Network Function or Service 142 (particularly Access and Mobility Management Function)—communication between User Equipment 20 and User Equipment Bootstrapping Function or Service 130 is via Access and Mobility Management Function (i.e. via another Network Function or Service 142), and explains the establishment of a (considered) non-access stratum communication link with Session Management Function as the First Network Function or Service 141 (along with the (considered) non-access stratum security context). In the first processing step 511, User Equipment 20 registers with the network (i.e., User Equipment registration is specifically accomplished via a request according to established procedures); this includes establishing a non-access stratum security context between User Equipment 20 and the Access and Mobility Management Function (AMS), and involves communication between User Equipment 20 and the AMS as another network function or service 142. In the second processing step 512, Access Network 110, particularly Base Station Entity 111, routes the User Equipment request to the AMS as another network function or service 142 (i.e., one of a potential plurality of AMS instances); this occurs based on the information and configuration provided. In the third processing step 513, User Equipment 20 transmits a non-access stratum message requesting an endpoint for NAS-SM communication (i.e., toward a Session Management Function, or an instance providing Session Management functionality); this non-access stratum message also includes appropriate parameters. In the fourth processing step 514, another network function or service 142 (typically, but not necessarily, the Access and Mobility Management function) retrieves endpoint request information related to NAS-SM from the User Equipment Bootstrapping function or service 130, including requesting (various) NAS-SM endpoints or endpoint information 141' from the User Equipment Bootstrapping function or service 130 in the fifth processing step 515, and retrieving (or receiving) (various) NAS-SM endpoints or endpoint information 141' from the User Equipment Bootstrapping function or service 130 in the sixth processing step 516. In the seventh processing step 517, the Access and Mobility Management function (as another network function or service 142) generates (various) NAS-SM endpoints (i.e., non-access stratum endpoint information 141') to be sent to the User Equipment 20 based on the information received from the User Equipment Bootstrapping function or service 130, and transmits the non-access stratum endpoint information 141' to the User Equipment 20 via the access network 110 (i.e., base station entity 111), see [link to relevant documentation]. Figure 4The eighth and ninth processing steps are 518 and 519, respectively. In the tenth processing step 520, non-access stratum endpoint information 141' (i.e., non-access stratum endpoint for NAS-SM) is used to establish and / or authenticate (between user equipment 20 and session management function as first network function or service 141) the (considered) non-access stratum security context. In the eleventh processing step 521, the access network routes the corresponding user equipment request to the first network function or service 141 (in the provided non-access stratum endpoint information 141') based on the provided non-access stratum endpoint information 141'. Figure 4 (The first network function or service 141 is a session management function). Subsequently, User Equipment 20 and the first network function or service 141 can directly and securely exchange non-access stratum messages (NAS-SM messages in the considered (session management function) scenario). Therefore, to reduce the need to modify access network functionality (or reduce the impact on the access network), (e.g.) the Access and Mobility Management function is enhanced to further include the functionality of providing the User Equipment 20 with a non-access stratum endpoint (or non-access stratum endpoint information). In this scenario, the User Equipment network registration and the establishment of a non-access stratum security context with the Access and Mobility Management function (as another network function or service) are performed based on conventional known procedures, and messages are routed to the Access and Mobility Management function based on existing methods. The User Equipment 20 can then request the Access and Mobility Management function (as another network function or service 142) to provide a non-access stratum endpoint (e.g., NAS-SM) toward the Session Management function to establish a PDU session. Then, the access and mobility management function, as another network function or service 142, retrieves non-access stratum endpoint information from the user equipment bootstrapping function or service 130 based on information provided by the user equipment 20 (the user equipment bootstrapping function or service functionality may be a component of the access and mobility management function, and based on a simple method (such as configuration within the access and mobility management function)), and one or more non-access stratum endpoints (or endpoint information fragments) are returned to the user equipment 20; with the provided non-access stratum endpoints, the user equipment 20 is then able to establish (considered) non-access stratum security context with the session management function (i.e., the first network function or service 141).

[0080] in this regard, Figure 5The illustration schematically explains that User Equipment 20 (i.e., in parallel) establishes two distinct Non-Access Stratum (NAS) communication links 21 and 22 with two different network functions or services 141 and 143 (first and second network functions or services) in the core network 120 of the telecommunications network 100: a first NAS communication link 21 with the first network function or service 141 and a second NAS communication link 22 with the second network function or service 143. Between User Equipment 20 and the (radio) access network 110, NAS signaling is transmitted via (in the case of a mobile communication network) to the air interface of the base station entity 111 (specifically, the gNB). The (radio) access network 110 forwards the NAS signaling (transparently forwarded by the gNB), but its content is encrypted. Between the (radio) access network 110 and the core network 120, secure contexts are transmitted in parallel between User Equipment 20 and several network functions or services in the core network 120 for NAS signaling.

[0081] Figure 6 Another example of two parallel non-access stratum security contexts is illustrated, wherein user equipment 20 establishes a first non-access stratum communication link 21 with a first network function or service 141 in the core network 120 of telecommunications network 100 (e.g., as its visited network), and establishes a second non-access stratum communication link 22 with a second network function or service 241 in another core network 220 of another telecommunications network 200 (e.g., as its home network). Therefore, Figure 6 The illustration specifically depicts a scenario involving roaming and the application of multiple security contexts 21, 22 (e.g., in policy and accounting functions): In this scenario, the H-PCF (second network function or service 241) can directly send information requiring protection via the user equipment to the security context 22 of H-PCF 241, and send a reference to V-PCF 141. V-PCF 141 can use this reference to construct its message if the information (even if its content is unknown to V-PCF) needs to be referenced in its communication with user equipment 20. The bidirectional arrows between the first network function or service 141 (e.g., policy and accounting functions of the visited network) and the second network function or service 241 (e.g., policy and accounting functions of the home network) illustrate the PLMN-to-PLMN interaction between network functions or services in a roaming scenario.

[0082] Figure 7The illustration illustrates how User Equipment 20 communicates with different network functions in a nested manner using multiple non-access stratum security contexts. User Equipment 20 establishes a first non-access stratum communication link 21 with a first network function or service 141 in the core network 120 of telecommunications network 100, and establishes a second non-access stratum communication link 22 with a second network function or service 241 in another core network 220 of another telecommunications network 200. Specifically, telecommunications network 100 corresponds to the visited network of User Equipment 20, and the other telecommunications network 200 corresponds to the home network of User Equipment 20. Figure 7 An example is shown in which non-access stratum communication links between user equipment 20 and multiple network functions or services are cascaded or nested together (network function chaining is implemented through nested security contexts), such as in the case of URSP rule signaling in home route roaming. In this scenario, two PCFs are required (i.e., the first network function or service 141 is the Policy and Charging Function (V-PCF) in the visited network, and the second network function or service 241 is the Policy and Charging Function (H-PCF) in the home network of user equipment 20); in its simplest form, the forwarding entity is unaware of the content of the information being forwarded: the gNB or base station entity 111 in the radio access network 110 may not even be aware of the existence of multiple nested non-access layer security contexts (nevertheless, it still fulfills the same role of transparent forwarding as previously explained); between the radio access network 110 and the core network 120 of the visited network, the nested non-access layer security contexts transmit non-access layer signaling between the user equipment 20 and the network functions or services in the core network; V-PCF 141 can access the information in its security context, but otherwise, it implements transparent forwarding of nested security content. While H-PCF 241 is responsible for setting URSP rules, V-PCF 141 needs to set V-SMF ( Figure 7 (not shown in the image), and therefore indirectly in V-UPF ( Figure 7The Quality of Service (QoS) is set in (not shown) to enable the establishment of agreed-upon QoS. However, the H-PLMN may wish to hide some information from the V-PLMN. Enabling different levels of visibility for forwarding entities may be beneficial. To enable different levels of visibility for different elements within transmitted information fragments, URSP rules can be sent from H-PCF 241 to V-PCF 141 via the current method. However, information portions that the H-PLMN does not want to disclose to the V-PLMN (such as application IDs) can be sent via the NAS security context between the H-PCF and the UE, either in parallel with or nested within the NAS security context of V-PCF 141. Therefore, it is possible for an information element in one non-access stratum security context to reference another non-access stratum security context or its information elements. The same situation may also exist on the interface between H-PCF 241 and V-PCF 141 (which may be implemented using N24). Using the V / H-PCF+H-NAS-P interface or protocol, or alternatively the N32 and SEPP interfaces or protocols, the relay functionality of V-PCF 141 (for forwarding and receiving communications to H-PCF 241) allows access to information transmitted between H-PCF 241 and V-PCF 141 via the N24 (or N32 / SEPP) interface, but not to information transmitted between H-PCF 241 and User Equipment 20. This allows User Equipment 20 to reconstruct the complete information received via the NAS security context between PCF 141 of V-PLMN and PCF 241 of H-PLMN, where information elements can be referenced between security contexts. References include:

[0083] --Non-access stratum security context identifier information used for the referenced non-access stratum communication link or the referenced non-access stratum security context, wherein the non-access stratum security context identifier information specifically includes the non-access stratum endpoint information of the referenced non-access stratum security context.

[0084] --The information element identifier of the referenced information element.

[0085] V-PCF 141 (Intermediate Network Function / Service) relays NAS messages between User Equipment 20 and H-PCF 241 (Final Network Function / Service). Although the Intermediate Network Function or Service is aware that some information is being transmitted via the second channel, it cannot access that information.

[0086] In an alternative embodiment, H-PCF 241 can send data elements consisting of Information Elements (IEs) (e.g., NAS IEs in the case of a UE policy container) to V-PCF 141 (e.g., a UE policy container), some of which are visible to V-PCF 141 (e.g., securely transmitted using the security context between H-PCF 241 and V-PCF 141), while others are not: the content of the IE (e.g., V-PCF 141 may know that the URSP rule references an application descriptor but cannot see the actual descriptor), or the IE content and IE type (e.g., V-PCF 141 may only see that some information contained in the URSP rule is encrypted). Preferably and advantageously, encryption methods (e.g., signatures) are applied to ensure that unencrypted IEs are not modified by V-PCF 141; in this case, data elements received by user equipment 20 (e.g., the aforementioned URSP rules) may contain or include information from both security contexts, i.e., these IEs can be verified as originating from V-PCF 141 and / or H-PCF 241. Such scenarios are... Figure 8The diagram schematically illustrates a communication diagram between User Equipment 20, Base Station Entity 111, another network function or service 142 (e.g., Access and Mobility Management Function, AMF), Visited Policy and Charging Function V-PCF as a first network function or service 141, and Home Policy and Charging Function H-PCF as a second network function or service 241. The communication diagram shows examples of messages: a first message from H-PCF 241 to V-PCF 141 (in the first processing step 531), a second message from V-PCF 141 to AMF 142 (in the second processing step 532), and a third message from AMF 142 to User Equipment 20 (in the third processing step 533). The first message includes: parameter A (or information element A), which is transmitted from H-PCF 241 to V-PCF 141 in a non-access stratum security context, and parameter B (or information element B), which is transmitted from H-PCF 241 to User Equipment 20 in a non-access stratum security context. The second message includes: parameter A (or information element A), which is transmitted from V-PCF 141 to User Equipment 20 in a non-access stratum security context; parameter B (or information element B), which is transmitted from H-PCF 241 to User Equipment 20 in a non-access stratum security context; and parameter C (or information element C), which is transmitted from V-PCF 141 to AMF 142 in a non-access stratum security context. The third message includes: parameter A (or information element A), transmitted from V-PCF 141 to User Equipment 20 in a Non-Access Layer Security Context; parameter B (or information element B), transmitted from H-PCF 241 to User Equipment 20 in a Non-Access Layer Security Context; and parameter C (or information element C), transmitted from AMF 142 to User Equipment 20 in a Non-Access Layer Security Context. Therefore, a given parameter can be sent so that an intermediate receiver can be aware of it (if this is desired), and information can also be hidden from the intermediate receiver (if this is desired). According to the invention, in particular, these two embodiments or methods are preferably combined for transmitting Non-Access Layer Information Elements (IEs):

[0087] --Through multiple non-access layer security contexts, that is, in an authenticated, secure, and integrity-protected manner,

[0088] --Through multiple forwarding entities, and / or

[0089] --Allows fine-grained control over which / which entities can view, add, remove, and / or change values ​​in the non-access layer signaling chain, and / or

[0090] --No need to copy data used by entities that need to communicate via different non-access layer security contexts.

Claims

1. A method for operating user equipment (20) and a telecommunications network (100) and for communicating with at least two of a plurality of network functions or services (140) of said telecommunications network (100) or another telecommunications network (200), wherein the user equipment (20) operates using at least a first non-access stratum communication link (21) and a second non-access stratum communication link (22), the first non-access stratum communication link (21) being established in the user equipment (20) and the plurality of network functions or services (140) of a first network function or service (140) 41), and the second non-access stratum communication link (22) is established between the user equipment (20) and the second network function or service (143, 241), wherein the first non-access stratum communication link (21) involves establishing a first non-access stratum security context between the user equipment (20) and the first network function or service (141), and the second non-access stratum communication link (22) involves establishing a second non-access stratum security context between the user equipment (20) and the second network function or service (143, 241). The operation of the user equipment (20) using at least the first and second non-access stratum communication links (21, 22) includes the following steps: -- In the first step, a first non-access stratum communication link (21) and a first non-access stratum security context are established using first non-access stratum endpoint information related to the first network function or service (141), and a second non-access stratum communication link (22) and a second non-access stratum security context are established using second non-access stratum endpoint information related to the second network function or service (143, 241), wherein the first and second endpoint information are received by the user equipment (20). -- In the second step, the first and second non-access stratum communication links (21, 22) are used between their respective endpoints, wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can be referenced by a second information element of the second non-access stratum security context or a second information element transmitted using the second non-access stratum security context, and / or wherein a first information element of the first non-access stratum security context or a first information element transmitted using the first non-access stratum security context can reference a second information element of the second non-access stratum security context or a second information element transmitted using the second non-access stratum security context, wherein one of the first information element and the second information element, when used as a reference information fragment referencing the other of the first information element and the second information element, includes at least one of the following: --Non-access layer security context identifier information used for the referenced non-access layer communication link or the referenced non-access layer security context. --The information element identifier of the referenced information element.

2. The method of claim 1, wherein the first non-access layer communication link (21) and the first non-access layer security context are established using first key information and / or a first encryption method, and wherein the second non-access layer communication link (22) and the second non-access layer security context are established using second key information and / or a second encryption method. The first key information and / or the first encryption method are different from the second key information and / or the second encryption method.

3. The method of claim 1, wherein, in the case where the user equipment (20) is connected to or roams within the other telecommunications network (200), the second network function or service (143, 241) is a network function or service of the other telecommunications network (200). The first network function or service (141) and the second network function or service (143, 241) are corresponding network functions or services that provide the same type of network function functionality for the telecommunications network (100) and the other telecommunications network (200), respectively. The first non-access layer communication link (21) and / or the first non-access layer security context are implemented in a nested manner with the second non-access layer communication link (22) and / or the second non-access layer security context. The first network function or service (141) and the second network function or service (143, 241) are used in parallel by the user equipment (20), and are non-corresponding network functions or services that provide different types of network function functionality.

4. The method of claim 1, wherein the non-access layer security context identifier information includes the non-access layer endpoint information of the referenced non-access layer security context.

5. The method of claim 1, wherein in non-access layer communications involving the user equipment (20) and both the first network function or service (141) and the second network function or service (143, 241), at least the first and second non-access layer security contexts are used to transmit user equipment routing policy rules. The information element or a portion thereof is visible and / or decodable to the first network function or service (141) or the second network function or service (143, 241) only when the corresponding information element or a portion thereof is part of the corresponding non-access layer security context.

6. The method of claim 1, wherein establishing at least one of the first non-access stratum communication link and the second non-access stratum communication link involves using a user equipment bootstrapping function or service (130), said user equipment bootstrapping function or service (130) being part of the telecommunications network (100), or accessible via the telecommunications network (100) or through its network nodes. The user equipment (20) first requests to establish at least one of the first non-access stratum communication link and the second non-access stratum communication link, wherein the user equipment bootstrapping function or service (130) then provides non-access stratum endpoint information (141') related to at least one of the first network function or service (141) and the second network function or service (143, 241), and the non-access stratum endpoint information (141') is used to establish at least one of the first non-access stratum security context and the second non-access stratum security context, and / or to authenticate the user equipment (20) with respect to one of the first network function or service (141) and the second network function or service (143, 241).

7. The method of claim 1, wherein, For information elements and / or messages sent by the user equipment (20) to the first network function or service (141) or the second network function or service (143, 241), corresponding non-access stratum endpoint information (141') is included in such information elements and / or messages sent by the user equipment (20), wherein the access network (110) or access network node (111) in the telecommunications network (100) uses the non-access stratum endpoint information (141') to forward such information elements and / or messages to their destination, wherein such information elements and / or messages sent by the user equipment (20) include source information referring to or indicating the user equipment (20) and destination information referring to or indicating the first network function or service (141) or the second network function or service (143, 241).

8. The method of claim 1, wherein, For information elements and / or messages sent to the user equipment (20) by the first network function or service (141) or the second network function or service (143, 241), the non-access stratum endpoint information of the user equipment (20) is included in such information elements and / or messages sent by the first network function or service (141) or the second network function or service (143, 241), wherein the access network (110) or access network node (111) of the telecommunications network (100) uses the non-access stratum endpoint information of the user equipment (20) to forward such information elements and / or messages to the user equipment (20).

9. A program product comprising computer-readable program code, which, when executed on a network function or service of a user equipment (20) and / or a telecommunications network (100), causes the user equipment (20) and / or the telecommunications network (100) to perform the method according to any one of claims 1 to 8.

10. A computer-readable medium comprising instructions that, when executed on a network function or service of a user equipment (20) and / or a telecommunications network (100), cause the user equipment (20) and / or the telecommunications network (100) to perform the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method for provisioning enhanced communication capabilities to user equipment

    CN110063064A

  • Method for an improved exchange and / or interworking functionality between a first mobile communication network and a second mobile communication network, system, network exchange function, program and computer program product

    EP3937521A1