Method for establishing non-access hierarchy communication link between user equipment and one of plurality of network functions or services of telecommunication network, user equipment, system or telecommunication network, user equipment boot function or service, program and computer program product

By introducing user equipment guidance functions or services, the non-access-level communication link and security context between user equipment and specific network functions or services is directly established, and the flexibility and security issues of communication between user equipment and core networks in existing telecommunications networks are solved, achieving higher-level privacy protection and flexible deployment of network functions.

CN120303965AActive Publication Date: 2025-07-11DEUTSCHE TELEKOM AG
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202380083206.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-12
Filing Date
2023-12-04
Publication Date
2025-07-11
Estimated Expiration
2043-12-04

AI Technical Summary

Technical Problem

In existing telecommunications networks, the non-access-level communication link between user equipment and the core network lacks flexibility and security, and cannot effectively establish a non-access-level security context between multiple network functions or services under a zero-trust architecture, resulting in high complexity of the core network and insufficient privacy protection.

Method used

By introducing user equipment guidance functions or services, providing non-access hierarchy endpoint information, directly establishing non-access hierarchy communication links and security contexts between user equipment and specific network functions or services, adopting a zero-trust architecture, allowing user equipment and multiple network functions to transparently maintain non-access hierarchy security contexts.

Benefits of technology

It realizes higher level of user privacy protection and security in telecommunications networks, reduces the complexity of the core network, supports more flexible and decentralized network function deployment, and reduces the possibility of configuration errors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120303965A_ABST
    Figure CN120303965A_ABST
Patent Text Reader

Abstract

The present invention relates to a method for establishing a non-access hierarchy communication link between a user equipment and one of a plurality of network functions or services of a telecommunications network, where the non-access hierarchy communication link involves establishing a non-access hierarchy security context between the user equipment and one of the plurality of network functions or services, wherein establishing the non-access hierarchy communication link involves using a user equipment boot function or service that is part of the telecommunication network or is accessible via the telecommunication network or through a network node thereof, in order to establish a specific non-access hierarchy communication link and a specific non-access hierarchy security context between the user equipment and a specific network function or service of the plurality of network functions or services, the method comprises the following steps:-in a first step, the user equipment requests to establish the particular non-access hierarchy communication link to the particular network function or service,-in a second step the user equipment directs the function or service to provide non-access hierarchy endpoint information related to the particular network function or service,-in a third step the user equipment directs the function or service to provide non-access hierarchy endpoint information related to the particular network function or service,-in a fourth step the user equipment directs the function or service to establish the particular non-access hierarchy communication link to the particular network function or service. The non-access stratum endpoint information is used to establish a non-access stratum security context and / or authenticate the user equipment with respect to the particular network function or service.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Background

[0002] The present invention relates to a method for establishing a non-access stratum communication link between a user equipment and one of a plurality of network functions or services of a telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and the one of the plurality of network functions or services.

[0003] Furthermore, the present invention relates to a user equipment for establishing a non-access stratum communication link between the user equipment and one of a plurality of network functions or services of a telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and the one of the plurality of network functions or services.

[0004] Additionally, the present invention relates to a system or a telecommunication network for establishing a non-access stratum communication link between a user equipment and one of a plurality of network functions or services of a telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and the one of the plurality of network functions or services.

[0005] Furthermore, the present invention relates to a user equipment guiding function or service for establishing a non-access stratum communication link between a user equipment and one of a plurality of network functions or services of a telecommunication network, the user equipment guiding function or service being particularly part of a system or a telecommunication network according to the present invention, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and the one of the plurality of network functions or services.

[0006] Furthermore, the present invention relates to a program and a computer-readable medium for establishing a non-access stratum communication link between a user equipment and one of a plurality of network functions or services of a telecommunication network according to the method of the present invention.

[0007] In a conventionally known telecommunication network, the interface used between a user equipment (via an access network such as a radio access network, RAN) and a core network (CN) is based on a non-access stratum protocol stack, or NAS protocol stack. From the perspective of the system architecture, NAS communication refers to the logical interface between the user equipment and the CN.

[0008] Taking a mobile communication network as an example, especially a mobile communication network according to the 5G standard, the non-access stratum protocol (usually the non-access stratum mobility management protocol (NAS-MM)) is transmitted, for example, on top of the NG-AP protocol stack (gNB-5G core application protocol stack). The NG-AP protocol stack typically includes NG-AP on top of the L1 layer (physical layer), L2 layer (data link layer), IP (Internet Protocol) layer, and SCTP (Stream Control Transmission Protocol) layer. Thus, for example, the N2 interface or N2 reference point between the 5G access network and the access and mobility management function (AMF) network function or service of the core (5G) core network is implemented. The NG-AP protocol stack (NG-AP is a 3GPP protocol defined in TS 38.413) is used to transmit control plane (CP) information between the radio access network and the access and mobility management function (AMF) between the user equipment and the core network. In the considered scenario, the (radio) access network acts as a relay for non-access stratum signaling (NAS-MM) (between the 5G access network protocol layer (which is used between the user equipment and the base station entity, especially the gNodeB) and the NG-AP protocol stack (which is transmitted to the AMF using NG-AP as the lower protocol layer)), and the (radio) access network (AN) does not access the content of non-access stratum information (i.e., NAS-MM communication); it just relays the information to the access and mobility management function (AMF), that is, the so-called non-access stratum security context terminates at the access and mobility management function (AMF).

[0009] In a conventionally known telecommunication network, the (radio) access network determines, based on configuration, usually based on the requested telecommunication network (especially a public land mobile network, PLMN) and network slice (or multiple network slices), the AMF network function or service (from among potentially multiple different AMF network functions or services or multiple different instances in the telecommunication network) with which to communicate. The (radio) access network routes a given registration request (transmitted by the user equipment) to one AMF network function or service, or one AMF from a potentially possible list of AMFs.

[0010] In a conventionally known telecommunication network, non-access stratum communication involves control plane information exchanged between a UE and a CN element or a network node of the core network: for example, in the case of a 5G system, this includes communication between a user equipment and a plurality of different network function functionalities (such as, for example, an AMF (for access and mobility), an SMF (for session management), a PCF (for policy information), and an LMF (for location information)). Thus, the access and mobility management function acts as a core element of non-access stratum communication between the user equipment and (other types of) network functions or services of the core network (i.e., different network function functionalities), and the (non-access stratum) communication between the user equipment and other network function functionalities (i.e., network functions or services other than the access and mobility management function) is achieved by the following mix: on the one hand, using a non-access stratum protocol for transmission between the radio access network and the access and mobility management function; and on the other hand, based on the Nxxx service for communication between the access and mobility management function and other types of network functions or services (or multiple network function functionalities) (e.g., N11 / Nsmf of NAS-SM towards the session management function, N20 / Nsmsf towards the short message service function, N15 / Npcf of UE policy towards the policy and charging function, or NL1 / Nlmf of LCS (location service) towards the location management function).

[0011] Regarding security in a conventionally known telecommunication network, when a user equipment registers with the telecommunication network, a non-access stratum security context is created. The security context applies to non-access stratum connections, i.e., the connection between the user equipment and the access and mobility management function; this means that information sent via the access and mobility management function (e.g., to the session management function, etc.) is visible to the access and mobility management function. This is a drawback in cases where it cannot be guaranteed (or is not desired to guarantee) that all components or network functions or services of the core network are part of a trusted domain; the same drawback also exists in roaming related to the home and / or visited network. This is due to the current architecture, in which a single control plane towards the core network is established, (i.e., NAS communication), and in particular, the NAS security context terminates at the AMF.

[0012] Overview

[0013] An object of the present invention is to provide a technically simple, effective and cost-efficient solution for establishing a non-access stratum communication link between a user equipment and one of a plurality of network functions or services in a telecommunication network, in particular in terms of network architecture, and allowing a higher level of user privacy and user data privacy when operating the user equipment connected to the telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and the one of the plurality of network functions or services. A further object of the present invention is to provide a corresponding user equipment, a corresponding system or telecommunication network, a corresponding user equipment bootstrapping function or service, and a corresponding program and computer-readable medium.

[0014] The object of the present invention is achieved by a method for establishing a non-access stratum communication link between a user equipment and one of a plurality of network functions or services in a telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and one of the plurality of network functions or services, the plurality of network functions or services being capable of providing different types of network function functionality, wherein establishing the non-access stratum communication link involves using a user equipment bootstrapping function or service, which is part of the telecommunication network or accessible via the telecommunication network or through its network nodes, and wherein, in order to establish the considered non-access stratum communication link involving the user equipment and the considered non-access stratum security context, the method comprises the following steps:

[0015] -- In a first step, the user equipment requests to establish the considered non-access stratum communication link, the considered non-access stratum communication link involving a specific network function or service or a specific type of network function functionality.

[0016] -- In a second step, the user equipment bootstrapping function or service provides non-access stratum endpoint information related to the specific network function or service (which is identified, for example, by a network function identifier); or provides non-access stratum endpoint information related to a designated network function or service corresponding to a specific type of network function functionality (which is identified, for example, by the type of network functionality (such as "session management", "policy management", "location management"), or by a set of features that should be provided via the non-access stratum (such as security capabilities required for establishing a security context)).

[0017] -- In a third step, the non-access stratum endpoint information is used to establish the considered non-access stratum security context and / or authenticate the user equipment with respect to the specific network function or service or the designated network function or service corresponding to a specific kind of network function functionality.

[0018] According to the present invention, it may be more advantageous that the user equipment includes additional information that can be used by the guidance function to guide the third step, or by the telecommunications network to forward the message to the guidance function in the first step, such as the capabilities of the user equipment, subscriber-related information, security-related information, such as public keys or certificates.

[0019] According to the present invention, it may be more advantageous to establish a direct non-access stratum communication link by using non-access stratum endpoint information, where the non-access stratum communication link includes non-access stratum security context and / or authenticates the user equipment with respect to the corresponding endpoints of the non-access stratum security context (i.e., specific network functions or services, or designated network functions or services corresponding to specific types of network function functionality), enabling a higher level of security and / or trust within the core network of a telecommunication network, which makes it possible to implement a zero-trust architecture. This is in contrast to the conventional architecture of such non-access stratum communication links, which typically mainly relies on establishing a non-access stratum security context between the user equipment and the access and mobility management function, and where the security context or trust relationship of other network functions or services or network nodes (i.e., nodes other than the access and mobility management function) is entirely based on the assumption that the core network of the telecommunication network is regarded as a trusted domain, and the trust between network elements within such a trusted domain is provided only in a hop-by-hop manner. According to the present invention, it may also be additionally advantageous that the user equipment transparently maintains non-access stratum security contexts with multiple network functions or services (or other entities) of the core network via the (radio) access network for different purposes, i.e., maintains multiple non-access stratum security contexts, rather than using only one network function or service, especially using only or mainly the access and mobility management function as the main trusted termination point of the non-access stratum security context. In particular, this enables network functions or services that are part of the core network of a telecommunication network to be placed in different trust domains, i.e., there is no longer a need to place these network functions or services in the same trust domain, which may reduce the complexity within the core network and thereby potentially increase the level of security and trust within the telecommunication network (since lower complexity generally results in fewer errors, especially regarding configuration errors). Additionally, according to the present invention, it is advantageous that the user equipment is able to know the network functions or services with which it is communicating, because there is a direct and authenticated communication or connection between the user equipment and these different network functions or services (especially these network functions or services can provide different types of network function functionality), which is in contrast to implicitly trusting the next hop. Allowing a zero-trust architecture enables a more decentralized and flexible deployment. For example, certain network functions or services can be deployed in a public cloud or a less trusted environment (such as a customer premise); in a conventionally known telecommunication network, this is not possible because according to the current method, core network deployment, especially 5G core network deployment, assumes a trust domain, and if this cannot be guaranteed, "so-called trusted network functions or services" can perform arbitrary operations on the messages they receive, while other elements (including the user equipment) will not be aware of such behavior. According to the present invention, it may further be advantageous that the current non-access stratum protocol and core network architecture can be reused (although other protocols such as HTTP / 2 can also be used for communication between the user equipment and the core network).

[0020] According to the present application, a telecommunication network - in particular its core network - includes a user equipment steering function or service, or at least, a user equipment steering function or service can be accessed via the telecommunication network, in particular via its core network, or via its network nodes. Thus, it is more advantageous to use or involve the user equipment steering function or service, and provide non-access stratum endpoint information about the endpoints of the non-access stratum communication link (and non-access stratum security context) to be established in the second step of the method of the present invention through the user equipment steering function or service, for establishing the non-access stratum communication link - and non-access stratum security context. The endpoints of the non-access stratum communication link to be established correspond to the specific network function or service that the user equipment initially (i.e., in the first step of the method of the present invention) explicitly requests to connect to, or correspond to the designated network function or service corresponding to the functionality of a specific type of network function (i.e., the specific instance of the requested type of network function functionality that the user equipment initially, i.e., in the first step of the method of the present invention, explicitly requests to connect to, and which specific instance is typically selected by the access network, in particular by the user equipment steering function or service). According to the present invention, a solution to the problem of which network function or service (or potentially which instance among multiple network functions or services) to select for a given user equipment request can thus be advantageously provided: Given that the (radio) access network must route the control plane messages from the user equipment to the core network, how can the (radio) access network route the control plane messages to the correct network function or service (instance of the network function or service)? Generally, a user equipment cannot (or is unable to) be associated with more than one control plane network function or service for a given subscription, and in particular cannot be dynamically assigned; thus, an instance is needed to make a decision and provide this information.

[0021] Accordingly, in accordance with the present invention, there is advantageously provided a method for establishing a non-access stratum communication link between a user equipment and an instance of a network function or service - in particular a direct (or end-to-end) non-access stratum communication link between the user equipment and the instance of the network function or service. Generally, a telecommunication network includes a plurality of network functions or services, and these network functions or services are capable of providing different kinds of network function functionality to a user equipment within the telecommunication network. In accordance with the present invention, establishing a non-access stratum communication link between the user equipment and a specific or designated network function or service further involves establishing a non-access stratum security context between the user equipment and the corresponding specific or designated network function or service, which non-access stratum security context corresponds to the non-access stratum communication link. In accordance with the present invention, establishing the non-access stratum communication link involves using a user equipment bootstrapping function or service of the telecommunication network, or a user equipment bootstrapping function or service accessible via the telecommunication network or its network nodes. In the method according to the present invention, and with respect to the non-access stratum communication link under consideration, in a first step, the user equipment requests to establish the non-access stratum communication link under consideration, which non-access stratum communication link relates to a specific network function or service or a specific type of network function functionality; in a second step, the user equipment bootstrapping function or service provides non-access stratum endpoint information related to the request of the user equipment: in the case where the user equipment request is directed to a specific network function or service, i.e., a network function or service specifically defined by the request of the user equipment, the non-access stratum endpoint information can be provided by the user equipment bootstrapping function or service; otherwise, in the case where the user equipment is only directed to a specific type of network function functionality (i.e., not directed to a network function or service specifically defined by the request of the user equipment), the user equipment bootstrapping function or service provides non-access stratum endpoint information related to a designated network function or service corresponding to the specific type of network function functionality. In a third step, the non-access stratum endpoint information is used to establish the non-access stratum security context under consideration and / or to authenticate the user equipment with respect to the specific network function or service or the designated network function or service corresponding to the specific kind of network function functionality.

[0022] In a conventionally known telecommunication network and according to the present invention, non-access stratum communication relates to control plane information exchanged between a user equipment and a core network or a network node of the core network, where such network functions or services include different network functional capabilities, such as, for example, at least in the case of a 5G system, including an access and mobility management function (for access and mobility), a session management function (for session management), a policy and charging function (for providing policy information), and a location management function (for location information). Additionally, in a conventionally known telecommunication network and according to the present invention, at a certain point in time, the question of which one or which several different types of network functions or services (such as SMF, SMSF, PCF, LMF, etc.) (or which instances of different types of network functions or services) actually provide services to a particular user equipment (which user equipment, for example, initiated non-access stratum communication by means of a request, etc.) is determined by the telecommunication network based on at least one of the following: the (s)ervices requested by the user equipment, subscription parameters, network deployment, and other parameters. The (radio) access network and / or the user equipment generally do not specifically determine which instance among multiple different SMF / SMSF / PCF / LMF instances (i.e., other types of network functions or services other than the access and mobility management function) provides services to the user equipment (e.g., based on a given PDU session (protocol data unit session) establishment request of the user equipment, or a user equipment policy message, or a location-related message), while the (radio) access network can determine to which instance of the access and mobility management function the user equipment network registration is routed (although the receiving access and mobility management function instance can inform the (radio) access network to redirect the request to another access and mobility management function instance). The non-access stratum interface terminates at the access and mobility management function, and thus how non-access stratum messages are forwarded, routed, or otherwise processed cannot be seen outside the core network.

[0023] However, in a conventional telecommunications network, the Access and Mobility Management Function (AMF) serves as the sole central element for non-access stratum communication between the User Equipment (UE) and network functions or services (of other types) in the Core Network; for example, for session management (function) communication between the UE and the Session Management Function (SMF), the AMF performs a similar function - only, or at least mainly, a forwarding - function, just like the (Radio) Access Network (RAN) mentioned earlier. Similar to the RAN only relaying the information (of NAS-MM communication) to the AMF, in a conventional telecommunications network, the AMF performs the transmission or relay of non-access stratum message containers to and from the SMF, where the security context typically terminates at the AMF via the service-based interface and the corresponding SBIN1-N2 message request. In this scenario (i.e., communication between the UE and the SMF via the AMF), the service-based interface (SBI) (the interface between the AMF and the SMF) uses the HTTP / 2 protocol with JSON as the application layer serialization protocol; in addition, the protocol stack (above the L2 layer) includes the IP layer, the Transmission Control Protocol (TCP) layer, the Transport Layer Security (TLS) layer, the HTTP / 2 layer, and the application layer, and additionally, regarding security protection at the transport layer, all 3GPP Core Network functions or services support the SBI; authorization is typically achieved through OAuth2, which allows network functions or services to obtain authorization for specific network function services (i.e., obtain tokens providing a specific level of authorization for the APIs exposed for specific network function services) via the Network Repository Function (NRF); however, static authorization is also possible. This also applies to all different N1 message categories defined in TS 29.518 (5GMM (the entire NAS message received (e.g., for forwarding the registration message to the target AMF in a registration procedure with AMF redirection), SM (N1 session management messages), LPP (N1 LTE positioning protocol messages), SMS (N1 SMS messages as specified in TS23.040 and TS24.011), UPDP (N1 message for UE policy delivery (see Appendix D of TS24.501)), LCS (N1 messages of the location service message type).Regarding secure connections between the various components of the core network - as previously mentioned - in the context of 5G, an HTTP / 2-based interface (service-based interface SBI) can use TLS, but this only concerns the connection between a pair of individual network functions or services (NFs), rather than an end-to-end (E2E) security mechanism; with regard to security, when a user equipment registers with the network, a non-access stratum security context is created, which applies to non-access stratum connections, i.e., the connection between the user equipment and the access and mobility management function. Therefore, information sent via the access and mobility management function (e.g., information sent to the session management function or other network functions or services) is visible to the access and mobility management function, which becomes a drawback in situations where it cannot be guaranteed (or is not even intended to be guaranteed) that all components, network functions, or services of the core network are part of a trusted domain; the same drawback also applies to roaming regarding the home network and / or visited network. In conventionally known telecommunication networks (e.g., in the 5G core network and earlier versions of 3GPP systems), the design principle is that the core network is part of a trusted domain, i.e., the network elements within the core network are trusted, and security is provided on a hop-by-hop basis. In conventionally known telecommunication networks, there is a similar approach for roaming, where the inter-PLMN connection (N32 interface) can be secured by using TLS or PRINS: inter-PLMN user plane security (IPUPS) is a Release 16 feature of the user plane function that enforces GTP-U security on the N9 interface between the user plane functions of the visited PLMN and the home PLMN; to enable roaming, certain network functions or services need to communicate with each other, mainly the session management functions and the policy and charging functions of the visited PLMN (V-PLMN) and the home PLMN (H-PLMN), in order to establish a protocol data unit session (PDU session) that connects the user equipment and the data network (DN) via the V-PLMN; control plane and user plane connectivity are ensured between PLMNs (but not within a PLMN) via SEPP and IPUPS. The V-PLMN can locate the appropriate network functions or services in the H-PLMN (via SEPP) either based on configuration or by using a network function or service discovery procedure via the network repository function.

[0024] According to the present invention, it is more advantageous and preferred that, in a first step, a non-access stratum security context is established between the user equipment and the user equipment guiding function or service, wherein the user equipment requests a contemplated non-access stratum communication link to a specific network function or service or a specific type of network function functionality by transmitting a non-access stratum request message to the user equipment guiding function or service, wherein, in a second step, the non-access stratum endpoint information is transmitted by the user equipment guiding function or service to the user equipment, the non-access stratum endpoint information pointing to a specific network function or service or a designated network function or service corresponding to a specific type of network function functionality, wherein, in particular as part of or prior to the non-access stratum security context established between the user equipment and the user equipment guiding function or service, the user equipment transmits an initial message to the access network or access network node of the telecommunication network, and wherein, in particular based on the information provided as part of the initial message, the initial message is forwarded by the access network or access network node of the telecommunication network to the user equipment guiding function or service.

[0025] Thus, the method of the present invention can be implemented and carried out in a relatively simple and effective manner: by using the user equipment guiding function or service as an independent non-access stratum component, the user equipment guiding function or service being the only component required to be configured in the (radio) access network for guiding the non-access stratum connectivity of the user equipment.

[0026] According to the present invention, it is more advantageous and preferred that, in a first step, a non-access stratum security context is established between the user equipment and another network function or service, wherein the another network function or service includes or accesses the user equipment guiding function or service, wherein the user equipment requests a contemplated non-access stratum communication link to one of a specific network function or service or a specific type of network function functionality by transmitting a non-access stratum request message to the another network function or service, wherein the another network function or service requests non-access stratum endpoint information from the user equipment guiding function or service, and wherein, in a second step, the non-access stratum endpoint information is transmitted by the user equipment guiding function or service to the another network function or service and from the another network function or service to the user equipment, the non-access stratum endpoint information pointing to a specific network function or service or a designated network function or service corresponding to a specific type of network function functionality.

[0027] Thus, by implementing the user equipment guiding function or service after another (in particular existing) network function or service (such as, for example, the access and mobility management function (or an instance of the access and mobility management function)), the method of the present invention can be implemented and carried out in a relatively simple and effective manner, and it is beneficial to reduce the impact on the (radio) access network.

[0028] Furthermore, according to the invention, it is advantageous and preferred that, in particular in the third step, the non-access stratum endpoint information is used by the user equipment to establish the non-access stratum security context under consideration and / or to authenticate the user equipment with respect to a specific network function or service or with respect to a designated network function or service, wherein the non-access stratum endpoint information comprises at least one of the following or consists of the following:

[0029] -- IP address information,

[0030] -- information that can be mapped to an IP address, in particular a fully qualified domain name FQDN, or information that can be used to construct a fully qualified domain name, in particular a well-known fully qualified domain name,

[0031] -- an indication pointing to data that is part of a configured list,

[0032] -- an indication pointing to a default value, in particular a pre-configured default value or a well-known default value,

[0033] -- a network function identifier, in particular a universally unique identifier.

[0034] Thus, the method of the invention can be implemented and carried out in a relatively simple and effective manner.

[0035] Furthermore, according to the invention, it is advantageous and preferred that - in addition to the non-access stratum communication link and the non-access stratum security context under consideration between the user equipment and a specific network function or service or a designated network function or service - in particular in a roaming scenario where the user equipment is connected to another telecommunication network or is roaming within another telecommunication network, another non-access stratum communication link and another non-access stratum security context between the user equipment and another specific network function or service, in particular another network function or service of another telecommunication network, are required, wherein in particular different keys and / or different encryption methods are used for the specific non-access stratum security context and the other specific non-access stratum security context,

[0036] wherein in particular

[0037] -- the specific or designated network function or service and the other specific network function or service are corresponding network functions or services that particularly respectively provide the same type of network function functionality of a telecommunication network and another telecommunication network, wherein in particular the non-access stratum communication link and / or the non-access stratum security context under consideration and the other non-access stratum communication link and / or the other non-access stratum security context are implemented in a nested manner,

[0038] --A specific or designated network function or service and another specific network function or service are used in parallel by a user equipment, and are non-corresponding network functions or services providing different types of network function functionality.

[0039] Furthermore, according to the invention, it is advantageous and preferred that, with respect to information elements and / or messages sent by the user equipment to a specific or designated network function or service or another specific network function or service, corresponding non-access stratum endpoint information is included in such information elements and / or messages sent by the user equipment, wherein the access network or access network node of the telecommunication network uses the corresponding non-access stratum endpoint information to forward such information elements and / or messages to their destination, and wherein such information elements and / or messages sent by the user equipment particularly include destination information pointing to or indicating a specific or designated network function or service or another specific network function or service, or both source information and destination information pointing to or indicating the user equipment.

[0040] Therefore, the method of the present invention can be implemented and carried out in a relatively simple and effective manner.

[0041] Furthermore, according to the invention, it is advantageous and preferred that the user equipment is configured with non-access stratum endpoint information of the user equipment, particularly in a subscriber identity module, or the non-access stratum endpoint information assigned to the user equipment by the telecommunication network, particularly by a user equipment guiding function or service or at network registration, and wherein for non-access stratum communication, the non-access stratum endpoint information can be used to reach the user equipment.

[0042] Therefore, the method of the present invention can be implemented and carried out in a relatively simple and effective manner.

[0043] Furthermore, according to the invention, it is advantageous and preferred that, with respect to information elements and / or messages sent by a specific or designated network function or service or another specific network function or service to the user equipment, the non-access stratum endpoint information of the user equipment is included in such information elements and / or messages sent by a specific or designated network function or service or another specific network function or service, and wherein the access network or access network node of the telecommunication network uses the non-access stratum endpoint information of the user equipment to forward such information elements and / or messages to the user equipment. Furthermore, according to the invention, it is advantageous and preferred that the access network learns the non-access stratum endpoint information of the user equipment from messages exchanged between the user equipment and a guiding function, and associates the non-access stratum endpoint information of the user equipment with the user equipment, subscriber identifier, and / or user equipment identifier, particularly the user equipment or subscriber identifier included in a registration request.

[0044] Therefore, according to the present invention, the method of the present invention can be implemented and carried out in a relatively simple and effective manner.

[0045] Furthermore, according to the invention, it is advantageous and preferred that a first information element of the considered non-access stratum security context or a first information element transmitted using the considered non-access stratum security context can be referenced by a second information element of another considered non-access stratum security context or a second information element transmitted using another considered non-access stratum security context, and vice versa, wherein the first information element or the second information element, when used as a reference information segment for referencing another information element, includes at least one of the following:

[0046] -- Non-access stratum security context identifier information for the referenced non-access stratum communication link or the referenced non-access stratum security context, wherein the non-access stratum security context identifier information particularly includes non-access stratum endpoint information of the referenced non-access stratum security context,

[0047] -- Information element identifier of the referenced information element,

[0048] wherein in particular the first information element and the second information element include information related to the same type of network function functionality or different types of network function functionality, in particular information related to policy and charging function functionality and / or session management function functionality and / or access and mobility management function functionality.

[0049] Furthermore, according to the invention, it is advantageous and preferred that in non-access stratum communication involving both a user equipment and a specific network function or service and another specific network function or service, a plurality of different non-access stratum security contexts are used, in particular for transmitting user equipment routing policy rules, wherein in particular an information element or a part thereof is only visible and / or decodable to a specific network function or service or another specific network function or service if the information element or a part thereof is part of the corresponding non-access stratum security context.

[0050] Furthermore, the invention relates to a user equipment for establishing a non-access stratum communication link between the user equipment and one of a plurality of network functions or services of a telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and one of the plurality of network functions or services, and the plurality of network functions or services can provide different types of network function functionality, wherein the user equipment is configured such that a user equipment guiding function or service is used to establish the non-access stratum communication link, and wherein, in order to establish the considered non-access stratum communication link and the considered non-access stratum security context involving the user equipment, the user equipment is configured such that:

[0051] -- The user equipment requests to establish a non-access stratum communication link under consideration, and the non-access stratum communication link under consideration involves a specific network function or service or a specific type of network function functionality.

[0052] -- The user equipment guiding function or service provides non-access stratum endpoint information related to a specific network function or service or to a designated network function or service corresponding to a specific type of network function functionality.

[0053] -- The non-access stratum endpoint information is used to establish the non-access stratum security context under consideration and / or to authenticate the user equipment with respect to a specific network function or service or a designated network function or service corresponding to a specific kind of network function functionality.

[0054] Furthermore, the present invention relates to a system or a telecommunication network for establishing a non-access stratum communication link between a user equipment and one of a plurality of network functions or services of a telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and one of the plurality of network functions or services, and the plurality of network functions or services are capable of providing different types of network function functionality. Establishing the non-access stratum communication link involves using a user equipment guiding function or service that is part of the telecommunication network or can be accessed via the telecommunication network or through its network nodes. In order to establish the non-access stratum communication link under consideration involving the user equipment and the non-access stratum security context under consideration, the system or the telecommunication network is configured such that:

[0055] -- The telecommunication network particularly receives from the user equipment a request for establishing the non-access stratum communication link under consideration, and the non-access stratum communication link under consideration involves a specific network function or service or a specific type of network function functionality.

[0056] -- The user equipment guiding function or service provides non-access stratum endpoint information related to a specific network function or service or to a designated network function or service corresponding to a specific type of network function functionality.

[0057] -- The non-access stratum endpoint information is used to establish the non-access stratum security context under consideration and / or to authenticate the user equipment with respect to a specific network function or service or a designated network function or service corresponding to a specific kind of network function functionality.

[0058] Furthermore, the present invention relates to a user equipment bootstrapping function or service, which is in particular part of a system or a telecommunication network according to the present invention, for establishing a non-access stratum communication link between the user equipment and one of a plurality of network functions or services of the telecommunication network, wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment and one of the plurality of network functions or services, the plurality of network functions or services being capable of providing different types of network function functionality, wherein establishing the non-access stratum communication link involves using the user equipment bootstrapping function or service, which is part of the telecommunication network or is accessible via the telecommunication network or through its network nodes, and wherein, in order to establish the considered non-access stratum communication link and the considered non-access stratum security context involving the user equipment, the user equipment bootstrapping function or service is configured such that:

[0059] -- the telecommunication network, in particular the user equipment bootstrapping function or service, in particular receives a request from the user equipment for establishing the considered non-access stratum communication link, the considered non-access stratum communication link involving a specific network function or service or a specific type of network function functionality,

[0060] -- the user equipment bootstrapping function or service provides non-access stratum endpoint information related to a specific network function or service or to a designated network function or service corresponding to a specific type of network function functionality,

[0061] -- the non-access stratum endpoint information is used for establishing the considered non-access stratum security context and / or for authenticating the user equipment with respect to a specific network function or service or a designated network function or service corresponding to a specific kind of network function functionality.

[0062] Additionally, the present invention relates to a program comprising computer-readable program code which, when executed on a computer and / or on a user equipment and / or on a network node of a telecommunication network (in particular a network function or service and / or a user equipment bootstrapping function or service), or partly on the user equipment and / or partly on a network node of a telecommunication network (in particular a network function or service and / or partly on a user equipment bootstrapping function or service), causes the computer and / or the user equipment and / or the network node of the telecommunication network to execute the method of the present invention.

[0063] Additionally, the present invention relates to a computer-readable medium comprising instructions which, when executed on a computer and / or user equipment and / or a network node of a telecommunication network (in particular a network function or service and / or a user equipment bootstrapping function or service), or partially on the user equipment and / or partially on a network node of a telecommunication network (in particular a network function or service and / or a user equipment bootstrapping function or service in part), cause the computer and / or user equipment and / or the network node of the telecommunication network to perform the method of the present invention.

[0064] These and other features, characteristics and advantages of the present invention will become apparent from the following detailed description in conjunction with the accompanying drawings, which illustrate the principles of the present invention by way of example. The description is for illustrative purposes only and does not limit the scope of the present invention. The reference numbers cited below refer to the drawings. Brief Description of the Drawings

[0066] Figure 1 Schematically illustrates a telecommunication network comprising an access network, a core network and user equipment, wherein the core network typically comprises several network functions or services, such as an access and mobility management function and other network functions or services, and wherein the telecommunication network additionally comprises a user equipment bootstrapping function or service.

[0067] Figure 2 Schematically illustrates that the user equipment has established a plurality of direct non-access stratum communication links with different network functions or services of the core network of the telecommunication network.

[0068] Figure 3 Schematically illustrates a communication diagram showing direct communication between the user equipment and the user equipment bootstrapping function or service.

[0069] Figure 4 Schematically illustrates a communication diagram showing communication between the user equipment and the user equipment bootstrapping function or service via the access and mobility management function.

[0070] Figure 5 Schematically illustrates that the user equipment has established two different non-access stratum communication links with two different network functions or services of the core network of the telecommunication network.

[0071] Figure 6 Schematically illustrates that the user equipment has established non-access stratum communication links with a network function or service of the core network of the telecommunication network and with a network function or service of the core network of another telecommunication network (in particular the home public land mobile network of the user equipment), respectively.

[0072] Figure 7Schematically illustrates that a user equipment has established a non-access stratum communication link with a network function or service of the core network of a telecommunication network and with a network function or service of the core network of another telecommunication network (in particular, the home public land mobile network of the user equipment).

[0073] Figure 8 Schematically illustrates a communication diagram showing message examples between different network functions or services of a user equipment with the core network of a telecommunication network and with the core network of another telecommunication network (in particular, the home public land mobile network of the user equipment).

[0074] Detailed description

[0075] The present invention will be described in connection with specific embodiments and with reference to certain drawings, but the present invention is not limited to these and is only limited by the claims. The described drawings are merely schematic and non-limiting. In the drawings, the sizes of some elements may be exaggerated and not drawn to scale for ease of illustration.

[0076] When referring to a singular noun, the indefinite or definite article is used, e.g., "a", "a certain", "the", which includes the plural form of the noun, unless otherwise expressly stated.

[0077] Furthermore, the terms "first", "second", "third", etc. used in the description and claims are used to distinguish similar elements and are not necessarily used to describe an order or a time sequence. It should be understood that, where appropriate, these terms are interchangeable and that the embodiments described in the present invention are capable of operating in sequences different from those described or shown herein.

[0078] In Figure 1 a telecommunication network 100 including an access network 110 and a core network 120 is schematically shown. In Figure 1 the telecommunication network 100 is schematically shown as a mobile communication network 100, typically a cellular mobile communication network 100. However, the telecommunication network 100 may also be (at least partially) implemented as a fixed-line telecommunication network 100 (not shown). The telecommunication network 100, in particular the core network 120, typically includes several network functions or services 140. Among the network functions or services 140, there may be different (types of) network functions or services, i.e., network functions or services providing different network function functionalities, such as, for example, an access and mobility management function (AMF), a session management function (SMF), a policy and charging function (PCF), and a location management function (LMF). The access network 110 includes a plurality of radio cells 11, 12. In Figure 1In the exemplary situation or scenario shown, a first base station entity 111 generates or is associated with or spans a first radio cell 11, and a second base station entity 112 generates or is associated with or spans a second radio cell 12. Figure 1 In FIG, a user equipment 20 is schematically shown as part of or within the radio coverage of a first radio cell 11 / first base station entity 111. The user equipment 20 is typically (but not necessarily) mobile, i.e., can move relative to a (typically, but not necessarily, static) radio cell 11, 12 or a corresponding base station entity 111, 112 of an access network 110. Figure 1 In the exemplary illustration shown, the core network 120 of the telecommunications network 100 includes a specific network function or service 141, another network function or service 142, and another specific network function or service 143. Figure 1 In the embodiment, the core network 120 is schematically shown as including a user equipment steering function or service 130. According to the present invention, the user equipment steering function or service 130 can be accessed by at least the user equipment 20 or by a network node, network function or service 140 of the core network (i.e., the user equipment steering function or service 130 is located outside the core network 120 (e.g., as part of another network, Figure 1 )), but of course, according to the present invention, the user equipment steering function or service 130 may also be part of the telecommunications network 100.

[0079] in addition, Figure 1 A further telecommunication network 200 is shown, which is likewise indicated as another mobile communication network 200, comprising another access network 210 and another core network 220, and - exemplary - comprising another radio cell 13 and another base station entity 211. The further telecommunication network 200, in particular the further core network 220, also typically comprises several further network functions or services 240. Among the further network functions or services 240, there may be different kinds of network functions or services, i.e. network functions or services that provide similar but different network function functionalities as in the telecommunication network 100 scenario. Figure 1 In the exemplary illustration shown, a further core network 220 of the further telecommunication network 200 comprises a network function or service denoted by reference numeral 241 , which in particular belongs to the same category (or network function functionality) as the specific network function or service 141 .

[0080] Figure 1 Mainly shows a simple situation, the user equipment 20 is connected to its home network 100, in particular its home public land mobile network, that is, Figure 1The telecommunications network 100 shown corresponds to the home network of the user equipment 20, that is, the network related to the subscription information in the user equipment 20. In any case, the user equipment 20 can use the access network 120 (usually a radio access network) to connect. In the case where the access network 120 does not correspond to (or does not belong to) the home network of the user equipment 20 or the home public land mobile network (that is, in the case where the telecommunications network 100 is not the home network of the user equipment 20), the access network 120 to which the user equipment 20 is connected is referred to as the visited network or visited public land mobile network of the user equipment 20; and in this case, the user equipment 20 is usually also connected to its home network, or the core network of its home network. In the latter case, the telecommunications network 100 corresponds to the visited telecommunications network (or visited public land mobile network or visited network), and another telecommunications network 200 corresponds to the home telecommunications network (or home public land mobile network or home network) of the user equipment 20.

[0081] The present invention provides a method for establishing a non-access stratum communication link between a user equipment 20 and one of a plurality of network functions or services 140 of a telecommunication network 100. The non-access stratum communication link involves establishing a non-access stratum security context between the user equipment 20 and one of the plurality of network functions or services 140. As already mentioned, the plurality of network functions or services 140 can be of different kinds, i.e., they can provide different kinds of network function functionalities, but a subset of the plurality of network functions or services 140 can also be of the same kind and then constitute different instances of the same kind of network function functionality (or the same kind of network function or service). According to the present invention, establishing the non-access stratum communication link involves using a user equipment bootstrapping function or service 130 (which is part of the telecommunication network 100 or at least can be accessed via the telecommunication network 100 or its network nodes). According to the present invention, the establishment of the considered non-access stratum communication link and the considered non-access stratum security context involving the user equipment 20 is achieved by the user equipment 20 requesting in a first step to establish the considered non-access stratum communication link. According to the present invention, the user equipment 20 requests to implement or establish the considered non-access stratum communication link to a specific network function or service 141 (i.e., not only a specific type of network function functionality but also its specific instance), or the user equipment requests to implement or establish the considered non-access stratum communication link to a specific type of network function functionality (and leaves the decision as to which instance of the plurality of network functions or services of the same type is involved to the access network 110 or the core network 120). In either case, in a second step, the user equipment bootstrapping function or service 130 provides non-access stratum endpoint information 141' related to the specific network function or service 141 or to a designated network function or service (i.e., a network function or service instance) corresponding to the specific type of network function functionality, and in a third step, the non-access stratum endpoint information 141' is used to establish the considered non-access stratum security context and / or authenticate the user equipment 20 with respect to the specific network function or service 141 or the designated network function or service corresponding to the specific kind of network function functionality.

[0082] In Figure 2 it is schematically shown that the user equipment 20 has established a plurality of direct non-access stratum communication links with different network functions or services 140 of the core network 120 of the telecommunication network 100. As Figure 2As shown or provided, examples of the network functions or services 140 are the Access and Mobility Management Function (AMF), the Session Management Function (SMF), and the Policy and Charging Function (PCF). The User Plane Function (UPF) is also shown, and the User Plane Function (UPF) is also one of the multiple network functions or services 140, but the User Equipment 20 uses the N3 interface or N3 reference point between the Base Station Entity 111 (or gNB or Access Network 110) and the User Plane Function (other than the Uu interface or Uu reference point between the User Equipment 20 and the Base Station Entity 111 (or gNB or Access Network 110)), and uses the User Plane (UP) connection (indicated by a solid line in Figure 2 to connect to the User Plane Function, while the connection between the User Equipment 20 and another network function or service 140 (other than the User Plane Function) corresponds to a Non-Access Stratum communication link, i.e., a Control Plane (CP) connection towards the Core Network (indicated by a dashed line in Figure 2 : NAS-MM with the Access and Mobility Management Function, NAS-SM with the Session Management Function, and NAS-P with the Policy and Charging Function. The User Plane Function connects the User Equipment 20 to the Data Network 300, such as the Internet. According to the present invention, through Figure 2The architecture shown (e.g., via different direct non-access stratum communication links (or multiple non-access stratum communication links and non-access stratum security contexts) between user equipment 20 and different network functions or services 140) has the advantage that the user equipment 20 can transparently maintain corresponding non-access stratum security contexts with multiple core network entities (i.e., different network functions or services) via the access network for different purposes, i.e., the user equipment 20 maintains multiple non-access stratum security contexts instead of using the access and mobility management function as the (especially the only) trusted endpoint for the user equipment non-access stratum security context. In particular, this enables network functions or services to be placed in different trust domains: the user equipment 20 knows the network function or service it is communicating with (authenticated communication) rather than implicitly trusting the next hop. Thus, this enables a zero-trust architecture and correspondingly supports more decentralized and flexible deployments, e.g., deploying certain network functions or services in a public cloud or a less trusted environment (such as a customer premise); in a conventional known telecommunications network, this is not possible because a conventional 5G core network deployment assumes a single trust domain, e.g., if not, the "presumed trusted NF" can handle the messages it receives arbitrarily, and other elements (including the user equipment 20) will not be aware of this. According to the present invention, such an architecture can be achieved particularly by implementing bootstrapping, i.e., using the user equipment bootstrapping function or service 130. Given that the access network 110 must route control plane messages from the user equipment 20 to the core network 120, the access network needs to know which network function or service 140 (in the core network 120) it needs to route the corresponding control plane message to, especially in a scenario where the user equipment 20 will be associated with many control plane network functions or services 140 and potentially be dynamically assigned. To address this situation, the user equipment 20 is provided with non-access stratum endpoints (or endpoint information) such that the user equipment 20 can address different network functions or services 140, and this endpoint information can then be used by the access network 110 (or the base station entity 111) to route (non-access stratum) messages, and thus the user equipment bootstrapping function or service 130 (UBF) is needed. According to the present invention, two implementation schemes are particularly considered for the user equipment bootstrapping function or service 130: According to the first embodiment, the user equipment bootstrapping function or service 130 can be regarded as or correspond to a non-access stratum component, while according to the second embodiment, the user equipment bootstrapping function or service 130 is located or regarded as being after a network function or service (especially the access and mobility management function) (or another interpretation, an enhanced version of the access and mobility management function can include the functionality of the user equipment bootstrapping function or service 130). Particularly according to the present invention, different key / encryption methods can be used for different NAS security contexts.

[0083] In Figure 3In it, a communication diagram between a user equipment 20, a base station entity 111, a user equipment guiding function or service 130, and an access and mobility management function as a specific network function or service 141 is schematically shown. According to a first embodiment of the present invention, this communication diagram shows - the user equipment guiding function or service 130 as a non-access stratum component - direct communication between the user equipment 20 and the user equipment guiding function or service 130, and explains the establishment of a (contemplated) non-access stratum communication link (and a (contemplated) non-access stratum security context) with the access and mobility management function as a specific network function or service 141. In a first processing step 501, an initial message (user equipment request) is sent by the user equipment 20 to the access network 110 (i.e., to the base station entity 111), and this initial message is directed to or intended to be sent to the user equipment guiding function or service 130 (this first message particularly includes network identifier information and user identifier information); in a second processing step 502, the access network 110 (or the base station entity 111) routes the user equipment request to the user equipment guiding function or service 130 (or an instance of the user equipment guiding function or service 130) based on the provided information and configuration. In a third processing step 503, the initial message (user equipment request) is transmitted to the user equipment guiding function or service 130 (based on the network identifier information and the user identifier information). In a fourth processing step 504, a non-access stratum security context is established or authenticated towards the user equipment guiding function or service 130 (i.e., between the user equipment 20 and the user equipment guiding function or service 130). In a fifth processing step 505, a non-access stratum message requesting non-access stratum endpoint information for NAS-MM and parameters (i.e., towards a specific network function or service 141 of the type of the access and mobility management function) is sent by the user equipment 20 to the user equipment guiding function or service 130. In a sixth processing step 506, the user equipment guiding function or service 130 maps the request, and in a seventh processing step 507, the requested non-access stratum endpoint information 141' ((the) NAS-MM endpoints) is returned to the user equipment 20. In an eighth processing step 508, a (contemplated) non-access stratum security context is established and / or authenticated (between the user equipment 20 and the access and mobility management function as a specific network function or service 141) using the non-access stratum endpoint information 141' (i.e., the non-access stratum endpoint for NAS-MM). In a ninth processing step 509, the access network routes the corresponding user equipment request to the specific network function or service 141 based on the provided non-access stratum endpoint information 141'. In a tenth processing step 510, non-access stratum messages (in the contemplated scenario of the access and mobility management function, NAS-MM messages) can be directly and securely exchanged between the user equipment 20 and the specific network function or service 141.Thus, in a scenario where the UE Bootstrapping Function or Service 130 is or is considered a non-access stratum component (direct communication with the UE 20), the UE Bootstrapping Function or Service 130 is the only component in the access network that needs to be configured to bootstrap the UE non-access stratum connectivity; based on the initial bootstrap message (first processing step 501) containing network-related information and user-related information, the access network 110 / 111 can route the message to the UE Bootstrapping Function or Service 130 (third processing step 503) so that a non-access stratum security context can be established. From this point on, the access network 110 plays a transparent role (information relay) in the information exchange between the UE 20 and the UE Bootstrapping Function or Service 130. To retrieve the non-access stratum endpoint (or non-access stratum endpoint information 141') including the requested non-access stratum endpoint type (e.g., NAS-MM), the UE 20 queries the UE Bootstrapping Function or Service 130 (processing steps 505, 506, 507). Based on the request, one or more non-access stratum endpoints or non-access stratum endpoint information fragments are returned. With the provided endpoint (information 141'), the UE 20 can establish a non-access stratum security context. The non-access stratum endpoint contains information that enables the access network to route messages to the corresponding network function or service. In particular (depending on different embodiments), the non-access stratum endpoint (information) 141' is or contains an IP address and / or contains information that can be mapped to an IP address (e.g., FQDN, information for constructing a known FQDN), and / or points to data in a configuration list, and / or is mapped to a default value (pre-configured or known default value). After establishing the non-access stratum security context (see processing step 508), the UE 20 can communicate securely with the non-access stratum endpoint.

[0084] According to the present invention, any type of (non-user plane) network function or service can be used as the specific network function or service 141, instead of the access and mobility management function as the specific network function or service 141, in order to establish the corresponding (considered) non-access stratum communication link and (considered) non-access stratum security context, e.g., instead of the access and mobility management function: session management function, policy and charging function, location management function, short message service function.

[0085] In Figure 4In it, a communication diagram between a user equipment 20, a base station entity 111, a user equipment guiding function or service 130, a session management function as a specific network function or service 141, and an access and mobility management function as another network function or service 142 is schematically shown. According to a second embodiment of the present invention, this communication diagram shows that the user equipment guiding function or service 130 is located or regarded as being after another network function or service 142 (in particular, the access and mobility management function). The communication between the user equipment 20 and the user equipment guiding function or service 130 is via the access and mobility management function (i.e., via another network function or service 142), and illustrates the establishment of a (contemplated) non-access stratum communication link (and a (contemplated) non-access stratum security context) with the session management function as a specific network function or service 141. In a first processing step 511, the user equipment 20 registers with the network (i.e., the user equipment registration is completed especially via a request according to an established procedure); this includes establishing a non-access stratum security context between the user equipment 20 and the access and mobility management function, and involves the communication between the user equipment 20 and the access and mobility management function as another network function or service 142. In a second processing step 512, the access network 110, especially the base station entity 111, routes the user equipment request to the access and mobility management function as another network function or service 142 (i.e., an instance among potential multiple access and mobility management function instances); this occurs based on the provided information and configuration. In a third processing step 513, the user equipment 20 transmits a non-access stratum message requesting an endpoint of a non-access stratum communication link for NAS-SM communication (i.e., towards the session management function, or an instance providing session management functionality); this non-access stratum message also includes appropriate parameters. In a fourth processing step 514, another network function or service 142 (usually but not necessarily the access and mobility management function) retrieves NAS-SM related endpoint request information from the user equipment guiding function or service 130, including, in a fifth processing step 515, requesting (a) NAS-SM endpoint or endpoint information 141' from the user equipment guiding function or service 130, and, in a sixth processing step 516, retrieving (or receiving) (a) NAS-SM endpoint or endpoint information 141' from the user equipment guiding function or service 130. In a seventh processing step 517, the access and mobility management function (as another network function or service 142) generates (a) NAS-SM endpoint (i.e., non-access stratum endpoint information 141') to be sent to the user equipment 20 based on the information received from the user equipment guiding function or service 130, and transmits the non-access stratum endpoint information 141' to the user equipment 20 via the access network 110 (i.e., the base station entity 111), see Figure 4The eighth processing step 518 and the ninth processing step 519 in. In the tenth processing step 520, a non-access stratum security context (to be considered) between the user equipment 20 and a session management function as a specific network function or service 141 is established and / or authenticated using the non-access stratum endpoint information 141' (i.e., the non-access stratum endpoint for NAS-SM). In the eleventh processing step 521, the access network routes the corresponding user equipment request to a specific network function or service 141 (which is the session management function in Figure 4 ), based on the provided non-access stratum endpoint information 141'; subsequently, non-access stratum messages (NAS-SM messages in the case of the session management function to be considered) can be directly and securely exchanged between the user equipment 20 and the specific network function or service 141. Thus, according to the second embodiment, in order to reduce the necessity of modifying the access network functionality (or the impact on the access network), the access and mobility management function is enhanced to further include the functionality of providing the non-access stratum endpoint (or non-access stratum endpoint information) to the user equipment 20. In this case, the user equipment network registration and the establishment of the non-access stratum security context with the access and mobility management function (as another network function or service) are performed based on conventionally known procedures, and the messages are routed to the access and mobility management function based on existing methods. The user equipment 20 can then request the access and mobility management function (as another network function or service 142) to provide the non-access stratum endpoint towards the session management function (e.g., NAS-SM to establish a PDU session). Then, the access and mobility management function as another network function or service 142 retrieves the non-access stratum endpoint information from the user equipment guiding function or service 130 based on the information provided by the user equipment 20 (the user equipment guiding function or service functionality can in particular be a component of the access and mobility management function and is based on a simple method (such as configuration within the access and mobility management function)), and one or more non-access stratum endpoints (or fragments of endpoint information) are returned to the user equipment 20; with the provided non-access stratum endpoints, the user equipment 20 can then establish the non-access stratum security context (to be considered) with the session management function (i.e., the specific network function or service 141).

[0086] The present invention not only relates to establishing different non-access stratum communication links and different non-access stratum security contexts from a user equipment to multiple different network functions or services, but also provides a solution for linking (or concatenating) different non-access stratum communication links or non-access stratum security contexts together - or in other words, provides a possibility of achieving a certain connection between different non-access stratum communication links and / or non-access stratum security contexts. This is particularly relevant in the case of roaming: especially in the case of roaming, particularly home routing, when the user equipment 20 is not within its home network, the visited network (V-PLMN) and the home network (H-PLMN) need to exchange information in order to build an end-to-end (E2E) path including policies, charging, etc. to provide connectivity to the user equipment 20. When adopting a zero-trust approach, the network functions or services of the V-PLMN do not know any parameters exchanged between the user equipment 20 and its home network (H-PLMN); for example, if the V-PLMN does not know what the user equipment 20 actually requests, the V-PLMN cannot relay control plane messages to the correct network function or service (such as a session management function) in the H-PLMN. Therefore, in order for roaming to work properly, information needs to be shared between the network functions or services in the visited network and the home network. However, the secure communication between the user equipment and the network functions or services in the home network makes it impossible for the visited network to perform its role properly. As already mentioned, according to the present invention, it is proposed to use multiple (or different) non-access stratum security contexts in parallel, for example for policy (PCF) and session management (SMF). Supplementary information can be obtained via different channels, such as, by way of example:

[0087] -- User Equipment Routing Selection Policy (URSP) rules (related to policy) that require metadata from a PDU session (related to session management) and / or

[0088] -- PDU session establishment (related to session management) that requires information related to the user equipment capabilities (usually exchanged during user equipment registration, i.e., related to access management) and / or

[0089] -- Setting "placeholder" information elements (IEs) that are unknown to the network functions, but are known to be included in another security context for privacy reasons. Although the same information (or the same (control) content) may be sent via multiple non-access stratum security contexts so that each non-access stratum security context is self-contained, it would be more efficient to be able to link different non-access stratum security contexts in a complementary manner.

[0090] In this regard, Figure 5Schematically illustrates that the user equipment 20 (i.e., in parallel) has established two different non-access stratum communication links 21, 22 with two different network functions or services 141, 143 in the core network 120 of the telecommunication network 100, namely, a first non-access stratum communication link 21 with a specific network function or service 141, and a second non-access stratum communication link 22 with another specific network function or service 143. Between the user equipment 20 and the (radio) access network 110, non-access stratum signaling is transmitted via the air interface (in the case of a mobile communication network) towards the base station entity 111 (specifically, gNB). The (radio) access network 110 forwards the non-access stratum signaling (transparently forwarded by the gNB), but its content is encrypted. Between the (radio) access network 110 and the core network 120, the security context transmits in parallel the non-access stratum signaling between the user equipment 20 and several network functions or services in the core network 120.

[0091] Figure 6 Schematically illustrates another example of two parallel non-access stratum security contexts, where the user equipment 20 has established a first non-access stratum communication link 21 with a specific network function or service 141 in the core network 120 of the telecommunication network 100 (e.g., as its visited network), and a second non-access stratum communication link 22 with another specific network function or service 241 in another core network 220 of another telecommunication network 200 (e.g., as its home network). Thus, Figure 6 Particularly shows the case of roaming and the application of multiple security contexts 21, 22 (e.g., in policy and charging functions): In this case, the H-PCF (another specific network function or service 143) can directly send the information that needs to be protected via the security context 22 from the user equipment to the H-PCF 241, and send a reference to the V-PCF 141. In the case where the information (even though the content is unknown to the V-PCF) needs to be referenced in its communication with the user equipment 20, the V-PCF 141 can use this reference to construct its message. The two-way arrow between the specific network function or service 141 (e.g., the policy and charging function of the visited network) and another specific network function or service 241 (e.g., the policy and charging function of the home network) illustrates the inter-PLMN interaction between the network functions or services for the roaming case.

[0092] Figure 7Schematically illustrates that the user equipment 20 communicates with different network functions in a nested manner using multiple non-access stratum security contexts, where the user equipment 20 establishes a first non-access stratum communication link 21 with a specific network function or service 141 in the core network 120 of the telecommunications network 100, and a second non-access stratum communication link 22 with another specific network function or service 241 in another core network 220 of another telecommunications network 200. In particular, the telecommunications network 100 corresponds to the visited network of the user equipment 20, and the other telecommunications network 200 corresponds to the home network of the user equipment 20. Figure 7 Shows an example where the non-access stratum communication links between the user equipment 20 and multiple network functions or services are connected in series or nested together (realizing a network function chain through nested security contexts), such as in the case of URSP rule signaling in home routed roaming. In this case, two PCFs are required (i.e., the specific network function or service is the policy and charging function (V-PCF) in the visited network, and the other specific network function or service is the policy and charging function (H-PCF) in the home network of the user equipment 20); in its simplest form, the forwarding entity has no knowledge of the information content being forwarded: the gNB or base station entity 111 in the radio access network 110 may not even be aware of the existence of multiple nested non-access stratum security contexts (nevertheless, it still performs the same role of transparent forwarding as previously explained); between the radio access network 110 and the core network 120 of the visited network, the nested non-access stratum security context conveys the non-access stratum signaling between the user equipment 20 and the network functions or services in the core network; the V-PCF 141 can access the information in its security context, but otherwise, it realizes the transparent forwarding of the nested security content. Although the H-PCF 241 is responsible for setting the URSP rules, the V-PCF 141 needs to set the V-SMF ( Figure 7 not shown in the figure), and thus indirectly in the V-UPF ( Figure 7Quality of service (QoS) is set in (not shown in the figure) to enable the establishment of an agreed QoS. However, the H-PLMN may wish to hide some information from the V-PLMN. However, it may be beneficial to enable different levels of visibility for the forwarding entity. To enable different levels of visibility for different elements in the transmitted information fragments, the URSP rules can be sent from the H-PCF 241 to the V-PCF 141 via the current method. However, the part of the information that the H-PLMN does not want to disclose to the V-PLMN (such as the application ID) can be sent via the NAS security context between the H-PCF and the UE, either in parallel with the NAS security context of the V-PCF 141 or nested within the NAS security context of the V-PCF 141. Therefore, it is possible for an information element in one non-access stratum security context to reference another non-access stratum security context or its information element. The same situation may also exist on the interface between the H-PCF 241 and the V-PCF 141 (this interface may be implemented using N24). Using the V / H-PCF + H-NAS-P interface or protocol or alternatively using the N32 and SEPP interfaces or protocols, the relay functionality of the V-PCF 141 (for forwarding communications to and receiving from the H-PCF 241) can access the information transmitted in the N24 (or N32 / SEPP) interface between the H-PCF 241 and the V-PCF 141, but cannot access the information transmitted between the H-PCF 241 and the user equipment 20, so that the user equipment 20 can reconstruct the complete information received via the NAS security context between the PCF 141 of the V-PLMN and the PCF 241 of the H-PLMN, and information elements can be referenced between security contexts. The references include:

[0093] -- Non-access stratum security context identifier information for the referenced non-access stratum communication link or the referenced non-access stratum security context, where the non-access stratum security context identifier information particularly includes the non-access stratum endpoint information of the referenced non-access stratum security context,

[0094] -- Information element identifier of the referenced information element.

[0095] The V-PCF 141 (intermediate network function / service) relays NAS messages between the user equipment 20 and the H-PCF 241 (final network function / service). Although the intermediate network function or service 141 knows that some information is transmitted via the second channel, it cannot access this information.

[0096] In a replacement embodiment, the H-PCF 241 is able to send data elements consisting of information elements (IEs) (e.g., NAS IEs in the case of the UE policy container) to the V-PCF 141 (e.g., UE policy container), where some of the IEs are visible to the V-PCF 141 (e.g., securely transmitted using the security context between the H-PCF 241 and the V-PCF 141), while some other elements are not visible: the content of the IE (e.g., the V-PCF 141 may know that the URSP rule references an application descriptor but cannot see the actual descriptor), or the IE content and IE type (e.g., the V-PCF 141 may only see that some of the information contained in the URSP rule is encrypted). Preferably and advantageously, an encryption method (e.g., signature) is applied to ensure that the non-encrypted IEs cannot be modified by the V-PCF 141; in this case, the data elements received by the user equipment 20 (e.g., the URSP rule described above) may contain or include information from two security contexts, i.e., these IEs can be verified as originating from the V-PCF 141 and / or the H-PCF 241. Such scenarios are in Figure 8is schematically shown, which shows a communication diagram between a user equipment 20, a base station entity 111, another network function or service 142 (such as an access and mobility management function, AMF), a visited policy and charging function V-PCF as a specific network function or service 141, and a home policy and charging function H-PCF as another specific network function or service 241. The communication diagram shows examples of messages: a first message from the H-PCF 241 to the V-PCF 141 (in the first processing step 531), a second message from the V-PCF 141 to the AMF 142 (in the second processing step 532), and a third message from the AMF 142 to the user equipment 20 (in the third processing step 533). The first message includes: a parameter A (or information element A), which is transmitted from the H-PCF 241 to the V-PCF 141 in a non-access stratum security context, and a parameter B (or information element B), which is transmitted from the H-PCF 241 to the user equipment 20 in a non-access stratum security context. The second message includes: a parameter A (or information element A), which is transmitted from the V-PCF 141 to the user equipment 20 in a non-access stratum security context; a parameter B (or information element B), which is transmitted from the H-PCF 241 to the user equipment 20 in a non-access stratum security context; and a parameter C (or information element C), which is transmitted from the V-PCF 141 to the AMF 142 in a non-access stratum security context. The third message includes: a parameter A (or information element A), which is transmitted from the V-PCF 141 to the user equipment 20 in a non-access stratum security context; a parameter B (or information element B), which is transmitted from the H-PCF 241 to the user equipment 20 in a non-access stratum security context; and a parameter C (or information element C), which is transmitted from the AMF 142 to the user equipment 20 in a non-access stratum security context. Thus, a given parameter can be sent so that an intermediate recipient can be aware of it (if this is desired), and information can also be hidden from the intermediate recipient (if this is desired).

[0097] According to the present invention, in particular, these two embodiments or methods are preferably combined for sending non-access stratum information elements (IEs):

[0098] -- via multiple non-access stratum security contexts, i.e., in an authenticated, secure, and integrity-protected manner,

[0099] -- through multiple forwarding entities, and / or

[0100] -- allowing fine-grained control over which / which entities can view, add, remove, and / or change values in the non-access stratum signaling chain, and / or

[0101] -- There is no need to copy the data used by entities that need to communicate via different non-access stratum security contexts.

Claims

1. A method for establishing a non-access stratum communication link between a user equipment (20) and one of a plurality of network functions or services (140) of a telecommunication network (100), wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment (20) and the one of the plurality of network functions or services (140), and the plurality of network functions or services (140) are capable of providing different types of network function functionality. Wherein establishing the non-access stratum communication link involves using a user equipment guiding function or service (130), which is part of the telecommunication network (100) or can be accessed via the telecommunication network (100) or through a network node of the telecommunication network. Among them, In order to establish the considered non-access stratum communication link and the considered non-access stratum security context involving the user equipment (20), the method comprises the following steps: -- In a first step, the user equipment (20) requests to establish the considered non-access stratum communication link, which involves a specific network function or service (141) or a specific type of network function functionality. -- In a second step, the user equipment guiding function or service (130) provides non-access stratum endpoint information (141') related to the specific network function or service (141) or to a designated network function or service corresponding to the specific type of network function functionality. -- In a third step, the non-access stratum endpoint information (141') is used to establish the considered non-access stratum security context and / or authenticate the user equipment (20) with respect to the specific network function or service (141) or the designated network function or service corresponding to the specific type of network function functionality.

2. The method according to claim 1, wherein In the first step, a non-access stratum security context is established between the user equipment (20) and the user equipment bootstrapping function or service (130), wherein the user equipment (20) requests a considered non-access stratum communication link to the specific network function or service (141) or the specific type of network function functionality by transmitting a non-access stratum request message to the user equipment bootstrapping function or service (130), wherein, in the second step, the non-access stratum endpoint information (141') pointing to the specific network function or service (141) or the designated network function or service corresponding to the specific type of network function functionality is transmitted by the user equipment bootstrapping function or service (130) to the user equipment (20), wherein in particular, as part of or prior to establishing the non-access stratum security context between the user equipment (20) and the user equipment bootstrapping function or service (130), the user equipment (20) transmits an initial message to the access network (110) or access network node (111) of the telecommunication network (100), and wherein in particular based on information provided as part of the initial message, the initial message is forwarded by the access network (110) or the access network node (111) of the telecommunication network (100) to the user equipment bootstrapping function or service (130).

3. The method according to any one of the preceding claims, wherein In the first step, a non-access stratum security context is established between the user equipment (20) and another network function or service (142), wherein the another network function or service (142) includes or has access to the user equipment bootstrapping function or service (130), wherein the user equipment (20) requests a considered non-access stratum communication link to the specific network function or service (141) or the specific type of network function functionality by transmitting a non-access stratum request message to the another network function or service (142), wherein the another network function or service (142) requests the non-access stratum endpoint information (141') from the user equipment bootstrapping function or service (130), and wherein, in the second step, the non-access stratum endpoint information (141') pointing to the specific network function or service (141) or the designated network function or service corresponding to the specific type of network function functionality is transmitted by the user equipment bootstrapping function or service (130) to the another network function or service (142) and from the another network function or service (142) to the user equipment (20).

4. The method according to any one of the preceding claims, wherein In particular, in the third step, the non-access stratum endpoint information (141') is used by the user equipment (20) to establish the non-access stratum security context under consideration and / or to authenticate the user equipment (20) with respect to the specific network function or service (141) or with respect to the designated network function or service, wherein the non-access stratum endpoint information (141') comprises at least one of the following, or consists of: -- IP address information, -- information that can be mapped to an IP address, in particular a fully qualified domain name FQDN, or information that can be used to construct a fully qualified domain name, in particular a well-known fully qualified domain name, -- an indication pointing to data that is part of a configured list, -- an indication pointing to a default value, in particular a pre-configured default value or a well-known default value, -- a network function identifier, in particular a universally unique identifier.

5. The method according to any one of the preceding claims, wherein – in addition to the non-access stratum communication link under consideration and the non-access stratum security context between the user equipment (20) and the specific network function or service (141) or the designated network function or service – in particular in a roaming scenario where the user equipment (20) is connected to another telecommunication network (200) or is roaming within the other telecommunication network (200), another non-access stratum communication link under consideration and another non-access stratum security context between the user equipment (20) and another specific network function or service (143, 241), in particular with another specific network function or service (143, 241) of the other telecommunication network (200), are required, wherein in particular different keys and / or different encryption methods are used for the specific non-access stratum security context and the other specific non-access stratum security context, wherein in particular -- the designated or specific network function or service (141) and the other specific network function or service (143, 241) are corresponding network functions or services that in particular respectively provide the same type of network function functionality of the telecommunication network (100) and the other telecommunication network (200), wherein in particular the non-access stratum communication link under consideration and / or the non-access stratum security context and the other non-access stratum communication link under consideration and / or the other non-access stratum security context are implemented in a nested manner, -- the designated or specific network function or service (141) and the other specific network function or service (143, 241) are used in parallel by the user equipment (20) and are non-corresponding network functions or services that provide different types of network function functionality.

6. The method according to any one of the preceding claims, wherein, Regarding information elements and / or messages sent by the user equipment (20) to the specific or designated network function or service (141) or the other specific network function or service (143, 241), corresponding non-access stratum endpoint information (141') is included in such information elements and / or messages sent by the user equipment (20), wherein the access network (110) or access network node (111) of the telecommunication network (100) uses the corresponding non-access stratum endpoint information (141') to forward such information elements and / or messages to their destination, wherein such information elements and / or messages sent by the user equipment (20) particularly include destination information referring to or indicating the specific or designated network function or service (141) or the other specific network function or service (143, 241), or both source information and destination information referring to or indicating the user equipment (20).

7. The method according to any one of the preceding claims, wherein the user equipment (20) is configured with non-access stratum endpoint information of the user equipment (20), particularly in a subscriber identity module, or the user equipment (20) is assigned non-access stratum endpoint information by the telecommunication network (100), particularly by the user equipment guiding function or service (130) or during network registration, wherein for non-access stratum communication, the non-access stratum endpoint information can be used to reach the user equipment (20).

8. The method according to any one of the preceding claims, wherein Regarding information elements and / or messages sent by the specific or designated network function or service (141) or the other specific network function or service (143, 241) to the user equipment (20), the non-access stratum endpoint information of the user equipment (20) is included in such information elements and / or messages sent by the specific or designated network function or service (141) or the other specific network function or service (143, 241), wherein the access network (110) or the access network node (111) in the telecommunication network (100) uses the non-access stratum endpoint information of the user equipment (20) to forward such information elements and / or messages to the user equipment (20).

9. The method according to any one of the preceding claims, wherein a first information element of the considered non-access stratum security context or a first information element transmitted using the considered non-access stratum security context can be referenced by a second information element of another considered non-access stratum security context or a second information element transmitted using another considered non-access stratum security context, and vice versa, wherein the first information element or the second information element, when used as a reference information segment for referencing another information element, includes at least one of the following: -- NAS security context identifier information for a referenced NAS communication link or a referenced NAS security context, wherein the NAS security context identifier information particularly includes the NAS endpoint information (141') of the referenced NAS security context. -- Information element identifier of a referenced information element, wherein particularly the first information element and the second information element include information related to the same type of network function functionality or different types of network function functionality, particularly information related to policy and charging function functionality and / or session management function functionality and / or access and mobility management function functionality.

10. The method according to any one of the preceding claims, wherein in NAS communication involving both the user equipment (20) and the specific network function or service (141) and the other specific network function or service (143, 241), a plurality of different NAS security contexts are used, particularly for transmitting user equipment routing policy rules, wherein particularly only in the case where an information element or a part thereof is part of the corresponding NAS security context, the information element or a part thereof is visible and / or decodable to the specific network function or service (141) or the other specific network function or service (143, 241).

11. A user equipment (20) for establishing a non-access stratum communication link between the user equipment (20) and one of a plurality of network functions or services (140) of a telecommunication network (100), wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment (20) and the one of the plurality of network functions or services (140), the plurality of network functions or services (140) being capable of providing different types of network function functionality, wherein the user equipment (20) is configured such that a user equipment guiding function or service (130) is used to establish the non-access stratum communication link, wherein, To establish the considered NAS communication link and the considered NAS security context involving the user equipment (20), the user equipment (20) is configured such that: -- The user equipment (20) requests to establish the considered NAS communication link, which involves a specific network function or service (141) or a specific type of network function functionality. -- The user equipment guiding function or service (130) provides NAS endpoint information (141') related to the specific network function or service (141) or to a designated network function or service corresponding to the specific type of network function functionality. -- The NAS endpoint information (141') is used to establish the considered NAS security context and / or to authenticate the user equipment (20) with respect to the specific network function or service (140) or the designated network function or service corresponding to the specific type of network function functionality.

12. A system or telecommunications network (100) for establishing a non-access stratum communication link between a user equipment (20) and one of a plurality of network functions or services (140) of a telecommunications network (100), wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment (20) and the one of the plurality of network functions or services (140), the plurality of network functions or services (140) being capable of providing different types of network function functionality, wherein establishing the non-access stratum communication link involves using a user equipment guiding function or service (130), the user equipment guiding function or service (130) being part of the telecommunications network (100) or accessible via the telecommunications network (100) or through a network node of the telecommunications network, wherein, To establish the considered NAS communication link and the considered NAS security context involving the user equipment (20), the system or telecommunication network (100) is configured such that: -- The telecommunication network (100) particularly receives from the user equipment (20) a request to establish the considered NAS communication link, which involves a specific network function or service (141) or a specific type of network function functionality. -- The user equipment bootstrapping function or service (130) provides non-access stratum endpoint information (141') related to the specific network function or service (141), or to the designated network function or service corresponding to the functionality of the specific type of network function. -- The non-access stratum endpoint information (141') is used to establish the non-access stratum security context under consideration and / or to authenticate the user equipment (20) with respect to the specific network function or service (140), or the designated network function or service corresponding to the functionality of the specific type of network function.

13. A user equipment guiding function or service (130) that is particularly part of a system or a telecommunication network (100) as claimed in claim 11 and is used to establish a non-access stratum communication link between a user equipment (20) and one of a plurality of network functions or services (140) of the telecommunication network (100), wherein the non-access stratum communication link involves establishing a non-access stratum security context between the user equipment (20) and the plurality of network functions or services (140), the plurality of network functions or services (140) being capable of providing different types of network function functionality, wherein establishing the non-access stratum communication link involves using the user equipment guiding function or service (130), the user equipment guiding function or service (130) being part of the telecommunication network (100) or accessible via the telecommunication network (100) or through a network node of the telecommunication network, wherein, To establish the non-access stratum communication link under consideration and the non-access stratum security context involving the user equipment (20), the user equipment bootstrapping function or service (130) is configured such that: -- The telecommunication network (100), in particular the user equipment bootstrapping function or service (130), receives a request for establishing the non-access stratum communication link under consideration, which involves a specific network function or service (141) or a specific type of network function functionality, from the user equipment (20). -- The user equipment bootstrapping function or service (130) provides non-access stratum endpoint information (141') related to the specific network function or service (141), or to the designated network function or service corresponding to the functionality of the specific type of network function. -- The non-access stratum endpoint information (141') is used to establish the non-access stratum security context under consideration and / or to authenticate the user equipment (20) with respect to the specific network function or service (140), or the designated network function or service corresponding to the functionality of the specific type of network function.

14. A program comprising computer-readable program code which, when the program code is executed on a computer and / or on a network node of the user equipment (20) and / or the telecommunication network (100), in particular on a network function or service (140) and / or the user equipment bootstrapping function or service (130), or partly on the user equipment (20) and partly on the network node of the telecommunication network (100), in particular the network function or service (140), and / or partly on the user equipment bootstrapping function or service (130), causes the computer and / or the user equipment (20) and / or the network node of the telecommunication network (100) to perform the method according to one of claims 1 - 10.

15. A computer-readable medium comprising instructions which, when executed on a computer and / or a user equipment (20) and / or a network node of a telecommunication network (100), in particular a network function or service (140) and / or a user equipment bootstrapping function or service (130), or partly on the user equipment (20) and / or partly on the network node of the telecommunication network (100), in particular the network function or service (140) and / or partly on the user equipment bootstrapping function or service (130), cause the computer and / or the user equipment (20) and / or the network node of the telecommunication network (100) to perform the method according to one of claims 1-10.

Citation Information

Patent Citations

  • Method for provisioning enhanced communication capabilities to user equipment

    CN110063064A

  • Method for interworking between networks in wireless communication system and apparatus thereof

    US20180376384A1

  • Wireless communications

    US20190387407A1

  • Access restriction for a private or neutral-host network

    US20210297936A1

  • ue

    WO2021132190A1