SNN for security keys in UE-to-network relays
Through the interaction between the remote UE and the relay UE, the service network name (SNN) is determined and verified, and a shared security key is generated, which solves the problem that the remote UE cannot obtain SNN, and realizes the security of PC5 communication.
Patent Information
- Application Number
- CN202380078642.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-14
- Filing Date
- 2023-11-13
- Publication Date
- 2025-07-11
AI Technical Summary
During the 5G ProSe layer 3UE to the network relay process, the remote UE cannot determine the service network name (SNN), resulting in the inability to generate a shared security key for PC5 communication.
Through the interaction between the remote UE and the relay UE, the service network name (SNN) is determined and verified, and the shared password key CK' and integrity key IK' are generated for PC5 communication.
The problem of how remote UEs obtain SNN knowledge and use the same SNN value as the network is solved, and a security key is generated based on the common SNN value of the network side and the UE side is realized, ensuring the security of PC5 communication.
Smart Images

Figure CN120303967A_ABST
Abstract
Description
[0001] Related Applications
[0002] This application claims the benefit of International Patent Application Serial No. PCT / CN2022 / 131644, filed on Nov. 14, 2022, the disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0003] This disclosure relates to methods and systems for determining a serving network name for a security key for a user equipment (UE) to network relay in a wireless communication system. Background Art
[0004] Security Procedures for UE to Network Relay
[0005] A fifth generation (5G) Proximity Services (ProSe) user equipment (UE) to network relay is a (5G ProSe-enabled) UE that provides a connection to the network for one or more 5G ProSe remote UEs.
[0006] Technical Specification (TS) 33.503 defines security procedures for 5G ProSe communication via a 5G ProSe layer 3 UE to network relay, with two methods, namely a user plane (UP)-based procedure and a control plane (CP)-based procedure.
[0007] Both of these methods can be used for 5G ProSe UE to network relay authorization and security establishment in the PC5 interface. The UP-based procedure uses a UP connection to the ProSe Key Management Function (PKMF) in the 5G Core Network (5GC), while the CP-based procedure uses a ProSe authentication vehicle over a non-access stratum (NAS) procedure towards the Access and Mobility Management Function (AMF) and Authentication Server Function (AUSF) in the 5GC.
[0008] In Figure 1 and Figure 2 show advanced security flows for UE to network relay. In Figure 1 showing a reference architecture for a 5G ProSe layer 3 UE to network relay, a remote UE 102 is connected to a 5G core network 108 via a relay UE 104 via a radio access network 106. Figure 2 shows advanced security flows for UE to network relay, particularly an authorization and security PC5 link establishment procedure for a 5G ProSe UE to network relay for a user plane-based solution.
[0009] Serving Network Name for AKA Security Key
[0010] It is expected that the security material in 5GC will be bound to a specific serving network name, e.g., the serving network Public Land Mobile Network (PLMN) identifier (ID) to which the UE is registered. For example:
[0011] The cipher key (CK') and integrity key (IK') for Extensible Authentication Protocol Authentication and Key Agreement (EAP-AKA') are derived from the EAP-AKA' authentication vector (AV) (CK, IK) and the serving network name (see Appendix A.3 33.501).
[0012] The authentication response (RES*) and expected authentication response (XRES*) are derived from RES and XRES and the serving network name (see Appendix A.4 33.501).
[0013] KAUSF and KSEAF are also bound to the serving network name (see Appendix A.2 / A.4 33.501).
[0014] Information from the discovery procedure for UE-to-network relay
[0015] The 3rd Generation Partnership Project (3GPP) also specifies the discovery procedure for how a remote UE and a relay UE find each other and the information associated with the UE. According to TS23.304, the information that can be discovered includes:
[0016] **Start of TS23.304 reference**
[0017] Based on the procedure defined in clause 6.5.1.3 for 5G ProSe UE-to-network relay, the following parameters can be used in the Relay Discovery Additional Information message (for Model A), where the source layer 2 ID and the destination layer 2 ID are used to send and receive messages, and the other parameters are included in the message:
[0018] - Source layer 2 ID: The 5G ProSe UE-to-network relay selects its own source layer 2 ID to send the Relay Discovery Additional Information message.
[0019] - Destination layer 2 ID: The destination layer 2 ID for sending the Relay Discovery Additional Information message is selected based on the configuration as described in clause 5.1.4.1.
[0020] - Relay service code: The relay service code associated with the message. The relay service code is used to identify the security parameters required for the receiving UE to process the discovery message.
[0021] - Advertiser information: Provides information about the advertising user.
[0022] - Additional parametersDefine additional parameters (when applicable) for 5G ProSe layer 3 UE-to-network relay as defined in clause 5.8.3.2.
[0023] **End of TS23.304 reference**
[0024] Among them, the additional parameters refer to:
[0025] The following additional parameters can be used in the relay discovery additional information message (for model A) for 5G ProSe layer 3 UE-to-network relay:
[0026] - NCGI (NR Cell Global ID): Indicates the NCGI of the serving cell of the 5G ProSe layer 3 UE-to-network relay.
[0027] This parameter can be requested by an application running on the 5G ProSe layer 3 remote UE.
[0028] - TAI (Tracking Area Identity): Indicates the tracking area identity of the serving cell of the 5G ProSe layer 3 UE-to-network relay. This parameter can be used by the 5G ProSe layer 3 remote UE to select the N3IWF.
[0029] That is, the remote UE can send a relay discovery additional information message to obtain the cell information where the relay UE resides.
[0030] Among them, the New Radio (NR) Cell Global Identity (NCGI) consists of the concatenation of the PLMN identifier (PLMN-Id) and the NR cell identity (NCI).
[0031] The Tracking Area Identity (TAI) consists of the Mobile Country Code (MCC), Mobile Network Code (MNC), and Tracking Area Code (TAC).
[0032] It has been confirmed in 3GPP that in the Prose CP-based solution, when generating an authentication vector (AV) for the Prose authentication of the remote UE in the UDM, the SNN (Serving Network Name) is used for network-side authentication vector generation. For example, generating CK'IK' of EAP AKA AV' (RAND, AUTN, XRES, CK', IK'), see clause 6.1.3.1 of TS33.501.
[0033] However, since the remote UE is not registered to the 5GS in this case, it is not known what serving network and its name should be used for the remote UE in the Prose authentication.
[0034] There has already been a proposal to use the serving network name of the relay UE in ProSe authentication as the SNN for AV generation for the remote UE, and the AMF of the relay network should send this SNN to the AUSF / UDM in the home network of the remote UE when triggering ProSe authentication.
[0035] However, it is not clear how the remote UE obtains knowledge of this SNN and uses the same SNN value on the UE side for authentication vector generation. Summary of the Invention
[0036] The present disclosure proposes a method and system for determining a serving network name (SNN) value for proximity service (ProSe) authentication. In a first embodiment, a remote user equipment (UE) and the home network of the remote UE determine to use a fixed value SNN for ProSe authentication, such as "5G:Prose". Thus, regardless of which relay UE is discovered by the remote UE, ProSe authentication vectors can be generated. In another embodiment, the remote UE can derive the SNN from the cell information of the relay UE from the discovery process. In yet another embodiment, the relay UE sends the SNN of the relay network to the remote UE as part of the ProSe authentication process. This allows a security key to be generated for PC5 communication based on the SNN value common to the network side and the UE side.
[0037] In an embodiment, a method for authenticating a 5G ProSe remote UE implemented in a fifth-generation (5G) ProSe remote UE may include: receiving a serving network identifier associated with the relay UE from the relay UE; and receiving a challenge message generated by an authentication server function (AUSF) associated with the 5G ProSe remote UE, where the challenge message includes the SNN associated with the relay UE. The method may further include: verifying the SNN associated with the relay UE by using the serving network identifier associated with the relay UE, determining a cipher key CK' and an integrity key IK' based on the SNN, and providing a response to the challenge message to the relay UE to facilitate the authentication of the 5G ProSe remote UE.
[0038] In an embodiment, the verification is in response to determining that a control-plane based security process is used for a relay service code (RSC) for communication with the relay UE.
[0039] In an embodiment, determining that a control-plane based security process is used for the RSC for communication with the relay UE is based on an authentication request associated with the challenge message.
[0040] In an embodiment, before receiving the serving network identifier from the relay UE, the method includes: providing a direct communication request to the relay UE to establish a PC5 unicast link.
[0041] In an embodiment, the method includes: triggering a discovery process with a relay UE to determine cell information associated with the relay UE.
[0042] In an embodiment, the cell information further includes a tracking area identifier.
[0043] In an embodiment, the SNN included in the challenge message includes the AT_KDF_INPUT of an Extensible Authentication Protocol (EAP) packet.
[0044] In an embodiment, the challenge message is an EAP Request / Authentication and Key Agreement (AKA') challenge message.
[0045] In an embodiment, the response to the challenge message is an EAP Response / AKA' challenge message.
[0046] In an embodiment, the serving network identifier is at least one of the following: the serving network (SN) identifier ID information in the New Radio (NR) Cell Global Identity (NCGI), a part of the NCGI, or associated with the NCGI.
[0047] In an embodiment, the authentication is part of an Extensible Authentication Protocol Authentication and Key Agreement (EAP-AKA') authentication process.
[0048] In another embodiment, a 5G ProSe remote UE may include a processing circuit configured to cause the 5G ProSe remote UE to receive a serving network identifier associated with a relay UE from the relay UE, and to receive a challenge message generated by an Authentication Server Function (AUSF) associated with the 5G ProSe remote UE from the relay UE, wherein the challenge message includes an SNN associated with the relay UE. The processing circuit may also be configured to verify the SNN associated with the relay UE using the serving network identifier associated with the relay UE, determine a cipher key CK' and an integrity key IK' based on the SNN, and provide a response to the challenge message to the relay UE to facilitate authentication of the 5G ProSe remote UE.
[0049] In an embodiment, a computer program including instructions may be provided, which when executed on at least one processor causes the processor to execute the above method. In an embodiment, a carrier containing the computer program is provided, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer-readable storage medium.
[0050] One of the advantages of the proposed embodiments is that they enable a security key to be generated for PC5 communication based on an SNN value common to the network side and the UE side, which solves the problem of how a remote UE in the background art obtains knowledge of the SNN and uses the same SNN value as the network for authentication vector generation on the UE side. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate several aspects of the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0052] Figure 1 shows a reference architecture for fifth generation (5G) proximity services (ProSe) layer 3 user equipment (UE) to network relay according to some embodiments of the present disclosure;
[0053] Figure 2 shows advanced security procedures for UE to network relay according to some embodiments of the present disclosure;
[0054] Figure 3A-3C shows a control plane-based message sequence diagram for 5G ProSe UE to network relay security procedures, where a network ProSe security context is set during PC5 link establishment;
[0055] Figure 4 shows an example of a cellular communication system according to some embodiments of the present disclosure;
[0056] Figure 5 and Figure 6 shows an example embodiment where Figure 4 the cellular communication system is a 5G system (5GS);
[0057] Figure 7 is a schematic block diagram of a radio access node according to some embodiments of the present disclosure;
[0058] Figure 8 is a schematic block diagram showing a virtualized embodiment of a Figure 7 radio access node according to some embodiments of the present disclosure;
[0059] Fig. 9 is a schematic block diagram of a Figure 7 radio access node according to some other embodiments of the present disclosure;
[0060] Fig.10 is a schematic block diagram of a UE according to some embodiments of the present disclosure; and
[0061] Fig.11 is a schematic block diagram of a Fig.10 UE according to some other embodiments of the present disclosure. Detailed Description
[0062] The embodiments described below represent information that enables those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. When reading the following description with reference to the accompanying drawings, those skilled in the art will understand the concepts of the present disclosure and will recognize applications of these concepts that are not specifically set forth herein. It should be understood that these concepts and applications fall within the scope of the present disclosure.
[0063] Core network node: As used herein, a "core network node" is any type of node in the core network or any node that implements core network functions. Some examples of core network nodes include, for example, a Mobility Management Entity (MME), a Packet Data Network Gateway (P-GW), a Service Capability Exposure Function (SCEF), a Home Subscriber Server (HSS), etc. Some other examples of core network nodes include nodes that implement Access and Mobility Management Function (AMF), User Plane Function (UPF), Session Management Function (SMF), Authentication Server Function (AUSF), Network Slice Selection Function (NSSF), Network Exposure Function (NEF), Network Function (NF) Repository Function (NRF), Policy Control Function (PCF), Unified Data Management (UDM), ProSe Key Management Function (PKMF), etc.
[0064] User Equipment (UE) device: One type of UE is a wireless communication device, which can be any type of wireless device that can access (i.e., be served by) a wireless network (e.g., a cellular network). Some examples of UEs include, but are not limited to: devices in a 3rd Generation Partnership Project (3GPP) network, Machine Type Communication (MTC) devices, and Internet of Things (IoT) devices. Such a UE can be or can be integrated into a mobile phone, a smart phone, a sensor device, a meter, a vehicle, a household appliance, a medical device, a media player, a camera, or any type of consumer electronic product, such as, but not limited to, a television, a radio, a lighting arrangement, a tablet computer, a laptop computer, or a personal computer (PC). The wireless communication device can be a portable, handheld, computer-included, or vehicle-mounted mobile device that enables the transmission of voice and / or data via a wireless or wired connection.
[0065] Network node: As used herein, a "network node" is any node that is part of the Radio Access Network (RAN) or the core network of a cellular communication network / system.
[0066] Note that the description given herein focuses on 3GPP cellular communication systems and, therefore, often uses 3GPP terms or terms similar to 3GPP terms. However, the concepts disclosed herein are not limited to 3GPP systems.
[0067] Note that in the description of this document, the term "cell" may be referred to; however, especially with respect to the fifth generation (5G) new radio (NR) concept, beams may be used instead of cells. Therefore, it is important to note that the concepts described herein apply equally to both cells and beams.
[0068] The present disclosure proposes a method and system for determining a service network name (SNN) value for proximity service (ProSe) authentication. In a first embodiment, a remote user equipment (UE) and the home network of the remote UE determine to use a fixed value SNN for ProSe authentication, for example, "5G:Prose". Thus, regardless of which relay UE is discovered by the remote UE, ProSe authentication vectors can be generated. In another embodiment, the remote UE can derive the SNN from the cell information of the relay UE from the discovery process. In yet another embodiment, the relay UE sends the SNN of the relay network to the remote UE as part of the ProSe authentication process. This allows a security key to be generated for PC5 communication based on the SNN value common to both the network side and the UE side.
[0069] One of the advantages of the proposed embodiments is that they enable a security key to be generated for PC5 communication based on the SNN value common to both the network side and the UE side, which solves the problem of how a remote UE in the background art obtains the SNN knowledge and uses the same SNN value as the network for authentication vector generation on the UE side.
[0070] The procedures described below are based on "6.3.3.3.2 PC5 security establishment for 5G ProSe UE-to-network relay communication on the control plane" of TS 33.503. However, new functions are emphasized.
[0071] Embodiment 1 - Setting the SNN with a fixed value
[0072] This clause describes the procedure for establishing a PC5 link between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay. The procedure includes how a 5G ProSe remote UE is authenticated by the AUSF of the 5G ProSe remote UE via the 5G ProSe UE-to-network relay and the AMF of the 5G ProSe UE-to-network relay during 5G ProSe PC5 establishment. This mechanism can be used when the 5G ProSe remote UE is out of coverage.
[0073] The following steps are regarding Figure 3A-3C the message sequence diagram in Figure 3A-3C which shows a control-plane-based message sequence diagram for a 5G ProSe UE-to-network relay security process according to some embodiments of the present disclosure, where the network ProSe security context is set during PC5 link establishment. Figure 3A-3C The entities in the message sequence diagram in Figure 3A-3C include the remote UE 302, the relay UE 304, the access and mobility management function (AMF) 306 of the remote UE, the AMF 308 of the relay UE, the authentication server function (AUSF) 310 of the remote UE, the unified data manager (UDM) 312 of the remote UE, and the ProSe anchoring function (PAnF) 314 of the remote UE. The steps described below correspond to
[0074] The 5G ProSe remote UE 302 and the 5G ProSe UE-to-network relay should register with the network (steps 313 and 315 respectively). The 5G ProSe UE-to-network relay 304 should be authenticated and authorized by the network to provide the UE-to-network relay 304 service. The 5G ProSe remote UE 302 should be authenticated and authorized by the AMF 306 to receive the UE-to-network relay service. During this authorization and information provision process, the PC5 security policy is provided to the 5G ProSe remote UE 302 and the 5G ProSe UE-to-network relay 304 respectively.
[0075] (Step 316) The 5G ProSe remote UE 302 or the relay UE should initiate the discovery process using either the Model A or Model B method as specified in Articles 6.3.1.2 or 6.3.1.3 of TS 23.304 V17.3.0 respectively.
[0076] (Step 318) After discovering the 5G ProSe UE-to-network relay 304, the 5G ProSe remote UE 302 should send a direct communication request to the 5G ProSe UE-to-network relay 304 to establish a secure PC5 unicast link. The 5G ProSe remote UE 302 should include its security capabilities and the PC5 signaling security policy in the DCR message as specified in TS 33.536. This message should also include the relay service code, Nonce_1.
[0077] If the 5G ProSe remote UE 302 does not have a valid 5G Prose remote user key (CP-PRUK), the 5G ProSe remote UE 302 should include the SUCI in the DCR to trigger 5G ProSe remote UE-specific authentication and establish the CP-PRUK.
[0078] If the 5G ProSe Remote UE 302 already has a valid CP-PRUK for the relay service code, the 5G ProSe Remote UE 302 shall include the associated CP-PRUK ID in the DCR to indicate that the 5G ProSe Remote UE 302 wants to use the CP-PRUK to obtain a relay connection.
[0079] (Step 320) After receiving the DCR message, the 5G ProSe UE-to-Network Relay 304 shall send a relay key request to the AMF 308 of the 5G ProSe UE-to-Network Relay 304, which includes the SUCI or CP-PRUK ID received in the DCR message, the relay service code (RSC), and Nonce_1. The 5G ProSe UE-to-Network Relay 304 shall also include a transaction identifier in this message, which identifies the subsequent messages on the NAS messages of the 5G ProSe Remote UE 302 for the 5G ProSe UE-to-Network Relay.
[0080] (Step 322) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 shall verify with the UDM 312 whether the 5G ProSe UE-to-Network Relay 304 is authorized to provide UE-to-network relay services.
[0081] (Step 324) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 shall select the AUSF 310 based on the SUCI or CP-PRUK ID and forward the parameters received in the relay key request to the AUSF 310 in the Nausf_UEAuthentication_ProseAuthenticate Request message. The Nausf_UEAuthentication_ProseAuthenticateRequest message shall contain the SUCI or CP-PRUK ID of the 5G ProSe Remote UE 302, the relay service code, and Nonce_1. If the CP-PRUK ID is received from the AMF 308 of the 5G ProSe UE-to-Network Relay, the AUSF 310 of the 5G ProSe Remote UE 302 temporarily stores Nonce_1, and the UE skips steps 6-9. If the SUCI of the 5G ProSe Remote UE 302 is received from the AMF 308 of the 5G ProSe UE-to-Network Intermediate 304, the AUSF 310 of the 5G ProSe Remote UE 302 temporarily stores Nonce_1 and the relay service code, and skips step 10.
[0082] (Step 326) The AUSF 310 shall initiate 5G ProSe remote UE-specific authentication using the received ProSe-specific parameters (i.e., RSC, etc.).
[0083] AUSF 310 knows that when Nausf_UEAuthentication_ProseAuthenticate is used, authentication Seeking the Right 5G ProSe Long-Range UE 302 for authentication, AUSF 310 Determine to use a specific SNN value (e.g., "5G:Prose") and Include it in the Nudm_UEAuthentication_GetProseAv Request message.
[0084] The AUSF 310 of the 5G ProSe remote UE 302 shall retrieve the authentication vector and routing indicator of the 5G ProSe remote UE 302 from the UDM 312 via the Nudm_UEAuthentication_GetProseAvRequest message. After receiving the Nudm_UEAuthentication_GetProseAv Request, the UDM 312 shall call the SIDF to hide the SUCI to obtain the SUPI before the UDM 312 can process the request. The UDM checks whether the UE is authorized to use the ProSe UE-to-network relay service based on the authorization information in the UE's subscription data. If the UE is authorized, the UDM 312 shall select the EAP-AKA' authentication method based on the received Nudm_UEAuthentication_GetProseAv Request.
[0085] UDM / ARPF 312 uses the parameters in the Nudm_UEAuthentication_GetProseAv Request message, For example, based on the received SNN value, an authentication vector is generated and CK' / IK' is derived.
[0086] (Step 328) The AUSF 310 shall temporarily store the XRES, routing indicator, and SUPI. The AUSF 310 of the 5G ProSe remote UE 302 shall trigger the authentication of the 5G ProSe remote UE 302 based on EAP-AKA'. The AUSF310 of the 5G ProSe remote UE 302 generates an EAP Request / AKA' challenge message defined in Clause 6.1.3.1 of TS 33.501 and sends the EAP Request / AKA' challenge message to the AMF 308 of the 5G ProSe UE-to-network relay 304 in the Nausf_UEAuthentication_ProSeAuthenticate Response message.
[0087] (Step 330) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 shall forward the relay authentication request (including the EAP Request / AKA' challenge) to the 5G ProSe UE-to-Network Relay 304 via a NAS message, including the transaction identifier of the 5G ProSe Remote UE 302 in this message. The NAS message shall be protected using the NAS security context created for the 5G ProSe UE-to-Network Relay 304.
[0088] (Step 332) Based on the transaction identifier, the 5G ProSe UE-to-Network Relay 304 shall forward the EAP Request / AKA' challenge to the 5G ProSe Remote UE 302 via a PC5 message.
[0089] The USIM in the 5G ProSe Remote UE 302 verifies the freshness of the received value by checking whether the AUTN is acceptable, as described in TS 33.102.
[0090] For EAP-AKA', the USIM calculates the response RES. The USIM shall return RES, CK, and IK to the ME. The ME shall derive CK' and IK' according to Article A.3 in TS33.501.
[0091] The UE knows that the authentication request is for authenticating the 5G ProSe remote UE 302, and the UE determines to use a specific SNN value (e.g. "5G:Prase") as input to derive CK' and IK'.
[0092] (Step 334) The 5G ProSe Remote UE 302 shall return the EAP-Response / AKA'-Challenge to the Network Relay 304 via a PC5 message.
[0093] (Step 336) The 5G ProSe UE-to-Network Relay 304 forwards the EAP-Response / AKA'-Challenge together with the transaction identifier of the 5G ProSe Remote UE 302 to the AMF 308 of the 5G ProSe UE-to-Network Relay 304 in the NAS message "Relay Authentication Response".
[0094] (Step 338) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 forwards the EAP-Response / AKA'-Challenge to the AUSF 310 of the 5G ProSe Remote UE302 via Nausf_UEAuthentication_ProSeAuthenticate Request.
[0095] The AUSF 310 of the 5G ProSe remote UE 302 performs UE authentication by verifying the received information, as described in TS 33.501.
[0096] For EAP-AKA', the AUSF 310 of the 5G ProSe remote UE 302 and the 5G ProSe remote UE 302 may exchange EAP Request / AKA'-Notification and EAP Response / AKA'-Notification messages via the AMF 308 of the 5G ProSe UE-to-Network Relay 304 and the 5G ProSe UE-to-Network Relay 304. After the exchange, the AUSF 310 of the 5G ProSe remote UE 302 and the 5G ProSe remote UE 302 shall derive KAUSF_P in the same way as KAUSF is derived in TS 33.501.
[0097] (Steps 340 and 342) After successful authentication, the AUSF 310 of the 5G ProSe remote UE 302 (step 340) and the 5G ProSe remote UE 302 (step 342) shall generate CP-PRUK and CP-PRUK ID as specified in Article A.2.
[0098] The CP-PRUK ID adopts the NAI format specified in Section 2.2 of IETF RFC 7542, i.e., username@realm. The username part includes the routing indicator from step 6 and CP-PRUK ID*, and the realm part includes the home network identifier. CP-PRUK ID* is specified in Article A.3.
[0099] (Step 344) The AUSF 310 of the 5G ProSe remote UE 302 shall select the PAnF 314 (Prose Anchoring Function) based on the CP-PRUK ID and send the SUPI, RSC, CP-PRUK, and CP-PRUK ID to the PAnF in the Npanf_ProseKey_Register Request message.
[0100] (Step 346) The PAnF 314 shall store the Prose context information for the 5G Prose remote UE 302 (i.e., SUPI, RSC, CP-PRUK, CP-PRUK ID) and send the Npanf_ProseKey_Register Response message to the AUSF 310.
[0101] (Step 348) The AUSF 310 of the 5G ProSe remote UE 302 shall select the PAnF 314 based on the CP-PRUK ID and send the received CP-PRUK ID and RSC in the Npanf_ProseKey_get Request message.
[0102] (Step 350) The PAnF 314 retrieves the CP-PRUK based on the CP-PRUK ID and checks whether the 5G ProSe remote UE 302 is authorized to use the UE-to-network relay service based on the received RSC. If the 5G ProSe remote UE 302 is authorized and the retrieved CP-PRUK is valid, the PAnF 314 sends an Npanf_ProseKey_get Response message with the CP-PRUK to the AUSF 310.
[0103] (Step 352) The AUSF 310 of the 5G ProSe remote UE 302 shall generate Nonce_2 and derive the KNR_ProSe key using the CP-PRUK, Nonce_1, and Nonce_2, as defined in Article A.4.
[0104] (Step 354) The AUSF 310 of the 5G ProSe remote UE 302 shall send the KNR_ProSe and Nonce_2 to the 5G ProSe UE-to-network relay 304 in the Nausf_UEAuthentication_ProseAuthenticate Response message via the AMF 308 of the 5G ProSe UE-to-network relay 304. If Step 7 is successfully executed, the EAP success message shall be included. The AUSF 310 of the 5G ProSe remote UE 302 shall also include the CP-PRUK ID in this message.
[0105] (Step 356) When the AMF 308 of the 5G ProSe UE-to-network relay 304 receives the KNR_ProSe from the AUSF 310 of the 5G ProSe remote UE 302, the 5G ProSe UE-to-network relay 304 derives the PC5 session key Krelay-sess and the confidentiality key Krelay-enc (if applicable) and the integrity key Krelay-int from the KNR_ProSe. The KNR_ProSe ID and the Krelay-sess ID are established in the same way as the KNRP ID and the KNRP-sess ID in TS 33.536. The 5GPRUK ID is sent from the AMF 308 of the 5G ProSe UE-to-network relay to the UE-to-network relay 304. The EAP success message, if received from the AUSF 310, is also sent from the AMF 308 of the 5G ProSe UE to the UE-to-network relay.
[0106] (Step 358) The 5G ProSe UE-to-network relay 304 shall send the received Nonce_2 and the PC5 signaling security policy of the 5G ProSe remote UE 302 in a direct security mode command message to the 5G ProSe remote UE 302, and the direct security mode command message is integrity protected using Krelay-int. The EAP success message, if received from the AMF 308 of the 5G ProSe UE-to-network relay 304, shall be included.
[0107] (Step 360) The 5G ProSe remote UE 302 shall generate the KNR_ProSe key in the same way as defined in Step 11 for remote access via the 5G ProSe UE-to-network relay. The 5G ProSe remote UE shall derive the PC5 session key Krelay-sess and the confidentiality key and the integrity key from the KNR_ProSe in the same way as defined in Step 13.
[0108] The 5G ProSe remote UE 302 shall verify the direct security mode command message. The successful verification of the direct security mode command message assures the 5G ProSe remote UE 302 that the 5G ProSe UE-to-network relay 304 is authorized to provide relay services.
[0109] (Step 362) The 5G ProSe Remote UE 302 shall send a Direct Security Mode Complete message containing its PC5 user plane security policy to the 5G ProSe UE-to-Network Relay 304, which is protected by Krelay-int or / and Krelay-enc derived from Krelay-sess according to the PC5 signaling policy negotiated between the 5G ProSe Remote UE 302 and the 5G ProSe UE-to-Network Relay 304.
[0110] (Step 364) After receiving the Direct Security Mode Complete message, the 5G ProSe UE-to-Network Relay 304 shall verify the Direct Security Mode Complete message. The successful verification of the Direct Security Mode Complete message guarantees to the 5G ProSe UE-to-Network Relay 304 that the 5G ProSe Remote UE 302 is authorized to obtain the relay service.
[0111] After the successful verification of the Direct Security Mode Complete message, the 5G ProSe UE-to-Network Relay 304 responds to the 5G ProSe Remote UE 302 with a Direct Communication Accept message to complete the PC5 connection establishment process, and stores the CP-PRUK ID in the security context associated with the PC5 link of the 5G ProSe Remote UE 302.
[0112] Further communication between the 5G ProSe Remote UE 302 and the network is securely conducted via the 5G ProSe UE-to-Network Relay.
[0113] When the 5G ProSe Layer 3 UE-to-Network Relay 304 sends a Remote UE Report (as specified in TS 23.304) to the SMF, the 5G ProSe Layer 3 UE-to-Network Relay 304 shall include the Remote User ID (i.e., the 5G PRUK ID received in Step 13) in the message.
[0114] Embodiment 2: Remotely determine the SNN from the cell information of the relay UE
[0115] The process is similar to Embodiment 1, where the underlines indicate the following differences.
[0116] Prerequisite (part of step 316),
[0117] If the remote UE 302 learns that the CP-based security procedure is used for the RSC communicating with the PC5 of the relay UE 304, then It triggers the discovery process, for example, via the Relay Discovery Additional Information message to learn about the relay UE 304 resident cell information. The relay UE 302 may use the cell information (e.g., NR cell global identifier (NCGI) or tracking area identifier) in which the relay UE 304 resides. (TAI)) derives SNN.
[0118] (Steps 313 and 315) The 5G ProSe Remote UE 302 and the 5G ProSe UE-to-Network Relay 304 shall register with the network. The 5G ProSe UE-to-Network Relay 304 shall be authenticated and authorized by the network to provide the UE-to-Network Relay 304 service. The 5G ProSe Remote UE 302 shall be authenticated and authorized by the network to receive the UE-to-Network Relay service. During this authorization and information provision process, the PC5 security policy shall be provided to the 5G ProSe Remote UE 302 and the 5G ProSe UE-to-Network Relay 304 respectively.
[0119] (Step 316) The 5G ProSe Remote UE 302 or the Relay UE 304 shall initiate the discovery process using either Model A or Model B method as specified in subclauses 6.3.1.2 or 6.3.1.3 of zTS23.304 respectively.
[0120] (Step 318) After discovering the 5G ProSe UE-to-Network Relay 304, the 5G ProSe Remote UE 302 shall send a direct communication request to the 5G ProSe UE-to-Network Relay 304 for establishing a secure PC5 unicast link. The 5G ProSe Remote UE 302 shall include its security capabilities and the PC5 signaling security policy in the DCR message as specified in TS 33.536. The message shall also include the relay service code, Nonce_1.
[0121] If the 5G ProSe Remote UE 302 does not have a valid 5G Prose Remote User Key (CP-PRUK), the 5G ProSe Remote UE 302 shall include the SUCI in the DCR to trigger 5G ProSe Remote UE 302-specific authentication and establish the CP-PRUK.
[0122] If the 5G ProSe Remote UE 302 already has a valid CP-PRUK for the relay service code, the 5G ProSe Remote UE 302 shall include the associated CP-PRUK ID in the DCR to indicate that the 5G ProSe Remote UE 302 wants to use the CP-PRUK to obtain a relay connection.
[0123] (Step 320) After receiving the DCR message, the 5G ProSe UE-to-Network Relay 304 shall send a relay key request to the AMF 308 of the 5G ProSe UE-to-Network Relay 304, which includes the SUCI or CP-PRUKID, RSC, and Nonce_1 received in the DCR message. The 5G ProSe UE-to-Network Relay 304 shall also include a transaction identifier in this message, which identifies the 5G ProSe Remote UE 302 for subsequent messages on the NAS message of the 5G ProSe UE-to-Network Relay.
[0124] (Step 322) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 shall verify with the UDM 312 whether the 5G ProSe UE-to-Network Relay 304 is authorized to provide UE-to-Network Relay services.
[0125] (Step 324) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 shall select the AUSF 310 based on the SUCI or CP-PRUK ID and forward the parameters received in the relay key request to the AUSF 310 in the Nausf_UEAuthentication_ProseAuthenticate Request message. The Nausf_UEAuthentication_ProseAuthenticate Request message shall contain the SUCI or CP-PRUKID of the 5G ProSe Remote UE 302, the relay service code, Nonce_1, and the SNN of the relay UE. If the CP-PRUKID is received from the AMF 308 of the 5G ProSe UE-to-Network Relay, the AUSF 310 of the 5G ProSe Remote UE temporarily stores Nonce_1, and the UE skips steps 6-9. If the SUCI of the 5G ProSe Remote UE 302 is received from the AMF 308 of the 5G ProSe UE-to-Network Relay 304, the AUSF 310 of the 5G ProSe Remote UE 302 temporarily stores Nonce_1 and the relay service code, and skips step 10.
[0126] (Step 326) The AUSF 310 shall initiate 5G ProSe Remote UE 302-specific authentication using the received ProSe-specific parameters (i.e., RSC, etc.).
[0127] The AUSF 310 of the 5G ProSe Remote UE 302 shall retrieve the authentication vector and routing indicator of the 5G ProSe Remote UE 302 from the UDM 312 via the Nudm_UEAuthentication_GetProseAvRequest message. After receiving the Nudm_UEAuthentication_GetProseAv Request, the UDM shall call the SIDF to hide the SUCI to obtain the SUPI, and then the UDM may process the request. The UDM checks whether the UE is authorized to use the ProSe UE-to-Network Relay Service based on the authorization information in the UE's subscription data. If the UE is authorized, the UDM shall select the EAP-AKA' authentication method based on the received Nudm_UEAuthentication_GetProseAv Request.
[0128] The UDM / ARPF 312 uses the parameters in the zNudm_UEAuthentication_GetProseAv Request message, for example, to generate the authentication vector and derive CK' / IK' based on the received SNN value.
[0129] (Step 328) The AUSF 310 shall temporarily store the XRES, routing indicator, and SUPI. The AUSF 310 of the 5G ProSe Remote UE 302 shall trigger the authentication of the 5G ProSe Remote UE 302 based on EAP-AKA'. The AUSF 310 of the 5G ProSe Remote UE 302 generates the EAP Request / AKA' Challenge message defined in clause 6.1.3.1 of TS 33.501 and sends the EAP Request / AKA' Challenge message to the AMF 308 of the 5G ProSe UE-to-Network Relay 304 in the Nausf_UEAuthentication_ProSeAuthenticate Response message.
[0130] (Step 330) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 shall forward the relay authentication request (including the EAP Request / AKA' Challenge) to the 5G ProSe UE-to-Network Relay 304 via a NAS message, including the transaction identifier of the 5G ProSe Remote UE 302 in the message. The NAS message is protected using the NAS security context created for the 5G ProSe UE-to-Network Relay 304.
[0131] (Step 332) Based on the transaction identifier, the 5G ProSe UE-to-network relay 304 shall forward the EAP Request / AKA' Challenge to the 5G ProSe remote UE 302 via a PC5 message.
[0132] The USIM in the 5G ProSe remote UE 302 verifies the freshness of the received values by checking whether the AUTN is acceptable, as described in TS 33.102.
[0133] For EAP-AKA', the USIM calculates the response RES. The USIM shall return RES, CK, and IK to the ME. The ME shall derive CK' and IK' according to Article A.3 in TS 33.501.
[0134] The UE knows that the authentication request is for authenticating the 5G ProSe remote UE 302, and the UE determines to use the SNN value.
[0135] · The SNN value retrieved from the "precondition" step
[0136] · Or the SNN value received from the network side via AT_KDF_INPUT of the EAP packet, and verify the received The SNN value matches the SNN value retrieved from the "precondition" step.
[0137] The UE uses the SNN value as input to derive CK' and IK'.
[0138] The remaining process is the same as that in Embodiment 1.
[0139] Embodiment 3 - Relay UE Sends SNN to Remote for Secure Key Generation
[0140] The process is the same as that in Embodiment 1, where the underlines indicate the following differences.
[0141] (Steps 313 and 315) The 5G ProSe remote UE 302 and the 5G ProSe UE-to-network relay 304 shall register with the network. The 5G ProSe UE-to-network relay 304 shall be authenticated and authorized by the network to provide the UE-to-network relay service. The 5G ProSe remote UE 302 shall be authenticated and authorized by the network to receive the UE-to-network relay service. During this authorization and information provision process, the PC5 security policy is provided to the 5G ProSe remote UE 302 and the 5G ProSe UE-to-network relay 304 respectively.
[0142] (Step 316) The 5G ProSe remote UE 302 or the relay UE shall initiate the discovery process using either Model A or Model B method specified in Articles 6.3.1.2 or 6.3.1.3 of TS 23.304 respectively.
[0143] (Step 318) After discovering the 5G ProSe UE-to-network relay 304, the 5G ProSe Remote UE 302 shall send a direct communication request to the 5G ProSe UE-to-network relay 304 for establishing a secure PC5 unicast link. The 5G ProSe Remote UE 302 shall include its security capabilities and PC5 signaling security policies in the DCR message as specified in TS 33.536. The message shall also include the relay service code, Nonce_1.
[0144] If the 5G ProSe Remote UE 302 does not have a valid 5G Prose Remote User Key (CP-PRUK), the 5G ProSe Remote UE 302 shall include the SUCI in the DCR to trigger 5G ProSe Remote UE 302-specific authentication and establish the CP-PRUK.
[0145] If the 5G ProSe Remote UE 302 already has a valid CP-PRUK for the relay service code, the 5G ProSe Remote UE 302 shall include the associated CP-PRUK ID in the DCR to indicate that the 5G ProSe Remote UE 302 wants to use the CP-PRUK to obtain a relay connection.
[0146] (Step 320) After receiving the DCR message, the 5G ProSe UE-to-network relay 304 shall send a relay key request to the AMF 308 of the 5G ProSe UE-to-network relay 304, which includes the SUCI or CP-PRUK ID, RSC, and Nonce_1 received in the DCR message. The 5G ProSe UE-to-network relay 304 shall also include a transaction identifier in the message, which identifies the 5G ProSe Remote UE 302 for subsequent messages on the NAS message of the 5G ProSe UE-to-network relay.
[0147] (Step 322) The AMF 308 of the 5G ProSe UE-to-network relay 304 shall verify with the UDM 312 whether the 5G ProSe UE-to-network relay 304 is authorized to provide UE-to-network relay services.
[0148] (Step 324) The AMF 308 of the 5G ProSe UE to the network relay 304 shall select the AUSF 310 based on the SUCI or CP-PRUK ID, and forward the parameters received in the relay key request to the AUSF 310 in the Nausf_UEAuthentication_ProseAuthenticate Request message. The Nausf_UEAuthentication_ProseAuthenticate Request message shall contain the SUCI or CP-PRUK ID of the 5G ProSe remote UE 302, the relay service code, Nonce_1, and the SNN of the relay UE. If the CP-PRUK ID is received from the AMF 308 of the 5G ProSe UE to the network relay, the AUSF 310 of the 5G ProSe remote UE temporarily stores Nonce_1, and the UE skips steps 6-9. If the SUCI of the 5G ProSe remote UE 302 is received from the AMF 308 of the 5G ProSe UE to the network relay 304, the AUSF 310 of the 5G ProSe remote UE 302 temporarily stores Nonce_1 and the relay service code, and skips step 10.
[0149] (Step 326) The AUSF 310 shall initiate the authentication specific to the 5G ProSe remote UE 302 using the received ProSe-specific parameters (i.e., RSC, etc.).
[0150] The AUSF 310 of the 5G ProSe remote UE 302 shall retrieve the authentication vector and routing indicator of the 5G ProSe remote UE 302 from the UDM 312 via the Nudm_UEAuthentication_GetProseAvRequest message. After receiving the Nudm_UEAuthentication_GetProseAv Request, the UDM 312 shall call the SIDF to hide the SUCI to obtain the SUPI, and then the UDM 312 can process the request. The UDM checks whether the UE is authorized to use the ProSe UE to network relay service based on the authorization information 312 in the UE's subscription data. If the UE is authorized, the UDM 312 shall select the EAP-AKA' authentication method based on the received Nudm_UEAuthentication_GetProseAv request.
[0151] The UDM / ARPF uses the parameters in the Nudm_UEAuthentication_GetProseAv Request message, for example, generates the authentication vector and derives CK' / IK' based on the received SNN value.
[0152] (Step 328) The AUSF 310 shall temporarily store the XRES, routing indicator, and SUPI. The AUSF 310 of the 5G ProSe Remote UE 302 shall trigger the authentication of the 5G ProSe Remote UE 302 based on EAP-AKA'. The AUSF 310 of the 5G ProSe Remote UE 302 generates an EAP Request / AKA' Challenge message defined in Clause 6.1.3.1 of TS 33.501 and sends the EAP Request / AKA' Challenge message to the AMF 308 of the 5G ProSe UE-to-Network Relay 304 in the Nausf_UEAuthentication_ProSeAuthenticate Response message.
[0153] (Step 330) The AMF 308 of the 5G ProSe UE-to-Network Relay 304 shall forward the relay authentication request (including the EAP Request / AKA' Challenge) to the 5G ProSe UE-to-Network Relay 304 via a NAS message, which includes the transaction identifier of the 5G ProSe Remote UE 302. The NAS message is protected using the NAS security context created for the 5G ProSe UE-to-Network Relay 304.
[0154] (Step 332) Based on the transaction identifier, the 5G ProSe UE-to-Network Relay 304 shall forward the EAP Request / AKA' Challenge to the 5G ProSe Remote UE 302 via a PC5 message. In this message, 5G ProSe UE to network relay 304UE also Includes the SNN of the relay UE.
[0155] The USIM in the 5G ProSe Remote UE 302 verifies the freshness of the received values by checking whether the AUTN is acceptable, as described in TS 33.102.
[0156] For EAP-AKA', the USIM calculates the response RES. The USIM shall return RES, CK, and IK to the ME. The ME shall derive CK' and IK' according to Clause A.3 in TS 33.501.
[0157] The UE knows that the authentication request is for 5G ProSe remote UE 302, and the UE determines to use the SNN value:
[0158] · SNN value retrieved from the relay UE
[0159] · Or the SNN value received from the network side via AT_KDF_INPUT of the EAP packet, and verify the received The SNN value matches the value retrieved from the relay UE.
[0160] The UE uses the SNN value as input to derive CK' and IK'.
[0161] The remaining process is the same as that in Embodiment 1.
[0162] Figure 4 FIG. shows an example of a cellular communication system 400 in which embodiments of the present disclosure can be implemented. In the embodiments described herein, the cellular communication system 400 is a 5G system (5GS) that includes a Next Generation RAN (NG-RAN) and a 5G Core (5GC). In this example, the RAN includes base stations 402-1 and 402-2, which include NR base stations (gNBs) and optionally Next Generation eNBs (ng-eNBs) in the 5GS, and control corresponding (macro) cells 404-1 and 404-2. Base stations 402-1 and 402-2 are generally referred to herein as base station 402 and individually as base station 402. Similarly, (macro) cells 404-1 and 404-2 are generally referred to herein as (macro) cell 404 and individually as (macro) cell 404. The RAN may also include a plurality of low-power nodes 406-1 to 406-4 that control corresponding small cells 408-1 to 408-4. The low-power nodes 406-1 to 406-4 may be small base stations (such as pico or femto base stations) or RRHs, etc. Note that although not shown, one or more of the small cells 408-1 to 408-4 may alternatively be provided by the base station 402. The low-power nodes 406-1 to 406-4 are generally referred to herein as low-power node 406 and individually as low-power node 406. Similarly, the small cells 408-1 to 408-4 are generally referred to herein as small cell 408 and individually as small cell 408. The cellular communication system 400 further includes a core network 410, which is referred to as 5GC in the 5G system (5GS). The base station 402 (and optionally the low-power node 406) is connected to the core network 410.
[0163] The base stations 402 and the low-power nodes 406 provide services to wireless communication devices 412-1 to 412-5 in the corresponding cells 404 and 408. The wireless communication devices 412-1 to 412-5 are generally referred to herein as wireless communication device 412 and individually as wireless communication device 412. In the following description, the wireless communication device 412 is generally a UE, but the present disclosure is not limited thereto. The remote UE 302 and the relay UE 304 may be examples of the wireless communication device 412, and the base station 402 may provide communication to and from the remote UE 302 and the relay UE 304 to network functions such as the AMF 306 and AMF 308, AUSF 310, UDM 312, and PAnF 314.
[0164] Figure 5 FIG. shows a wireless communication system represented by a 5G network architecture composed of core network functions (NFs), where the interaction between any two NFs is represented by a point-to-point reference point / interface. Figure 5can be regarded as Figure 4 a specific implementation of the system 400.
[0165] From the access side,[[]] Figure 5 the 5G network architecture shown includes a plurality of UEs 412 connected to the RAN 402 or the access network (AN) and the AMF 500. Generally, the R(AN) 402 includes base stations, such as eNB or gNB, etc. From the core network side,[[]] Figure 5 the 5GC NFs shown include the NSSF 502, AUSF 504, UDM 506, AMF 500, SMF 508, PCF 510, and the application function (AF) 512. The AUSF 504 described herein may be an example of the AUSF 310 described in the above process. Similarly, the UDM 506 described herein may be an example of the UDM 312 described in the above process.
[0166] The reference points of the 5G network architecture are used to develop detailed call flows in the specification standardization. The N1 reference point is defined to carry signaling between the UE 412 and the AMF 500. The reference points for the connection between the AN 402 and the AMF 500 and between the AN 402 and the UPF 514 are defined as N2 and N3, respectively. There is a reference point N11 between the AMF 500 and the SMF 508, which implies that the SMF 508 is at least partially controlled by the AMF 500. N4 is used by the SMF 508 and the UPF 514 so that the UPF 514 can be set using the control signals generated by the SMF 508, and the UPF 514 can report its status to the SMF 508. N9 is the reference point for the connection between different UPF 514s, and N14 is the reference point for the connection between different AMF 500s. Since the PCF 510 applies policies to the AMF 500 and the SMF 508, respectively, N15 and N7 are defined. N12 is required for the AMF 500 to perform the authentication of the UE 412. Since the subscription data of the UE 412 is required for the AMF 500 and the SMF 508, N8 and N10 are defined. In an embodiment, the AMF 500 described herein may be an example of the AMF 306 and the AMF 308 described in the above process.
[0167] The 5GC network aims to separate the UP and the CP. The UP carries user traffic, while the CP carries signaling in the network. In Figure 5In it, UPF514 is in the UP, while all other NFs, namely AMF 500, SMF 508, PCF 510, AF 512, NSSF 502, AUSF 504, and UDM 506, are in the CP. Separating the UP and CP ensures that each plane's resources are expanded independently. It also allows the UPF to be deployed separately from the CP functions in a distributed manner. In this architecture, the UPF can be deployed very close to the UE to shorten the round-trip time (RTT) between the UE and the data network for some applications that require low latency.
[0168] The core 5G network architecture consists of modular functions. For example, AMF 500 and SMF 508 are independent functions in the CP. The separated AMF 500 and SMF 508 allow for independent evolution and expansion. Other CP functions, such as PCF 510 and AUSF 504, can be separated as Figure 5 shown. The modular function design enables the 5GC network to flexibly support various services.
[0169] Each NF directly interacts with another NF. Intermediate functions can be used to route messages from one NF to another NF. In the CP, a set of interactions between two NFs is defined as a service to enable its reuse. This service enables the support of modularity. The UP supports interactions between different UPFs, such as forwarding operations.
[0170] Figure 6 illustrates a 5G network architecture that uses service-based interfaces between NFs in the CP instead of Figure 5 the point-to-point reference points / interfaces used in the 5G network architecture. However, the NFs described above with reference to Figure 5 correspond to the NFs shown in Figure 6 . The (one or more) services provided by an NF to other authorized NFs can be opened to the authorized NFs through service-based interfaces. In Figure 6 , the service-based interfaces are represented by the letter "N" followed by the name of the NF. For example, the service-based interface for AMF 500 is Namf, and the service-based interface for SMF 508 is Nsmf, etc. Figure 6 The NEF 600 and NRF 602 in Figure 5 are not shown in the Figure 5 discussed above. However, it should be clarified that all the NFs depicted in Figure 6 can interact with the NEF 600 and NRF 602 in Figure 5 as needed, although it is not explicitly indicated in
[0171] Figure 5 and Figure 6Some characteristics of the NFs shown in the figure can be described in the following manner. The AMF 500 provides UE-based authentication, authorization, mobility management, etc. Even when using multiple access technologies, the UE 412 is basically connected to a single AMF 500 because the AMF 500 is independent of the access technology. The SMF 508 is responsible for session management and allocating Internet Protocol (IP) addresses to the UE. It also selects and controls the UPF 514 for data transfer. If the UE 412 has multiple sessions, different SMF 508s can be assigned to each session to manage them separately and possibly provide different functions per session. The AF 512 provides information about packet flows to the PCF 510 responsible for policy control to support QoS. Based on this information, the PCF 510 determines policies regarding mobility and session management to enable the AMF 500 and SMF 508 to operate correctly. The AUSF 504 supports authentication functions for the UE, etc., and thus stores data for UE authentication, etc., while the UDM 506 stores the subscription data of the UE 412. The data network (DN) (which is not part of the 5GC network) provides Internet access or operator services, etc.
[0172] The NF can be implemented as a network element on dedicated hardware, a software instance running on dedicated hardware, or a virtualized function instantiated on a suitable platform (e.g., cloud infrastructure).
[0173] Figure 7FIG. 0 is a schematic block diagram of a radio access node 700 according to some embodiments of the present disclosure. Optional features are indicated by dashed lines. The radio access node 700 may be, for example, a base station 402 or 406, or a network node that implements all or part of the functions of the base station 402 or gNB described herein. As shown, the radio access node 700 includes a control system 702 that includes one or more processors 704 (e.g., a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), etc.), a memory 706, and a network interface 708. The one or more processors 704 are also referred to herein as processing circuitry. Additionally, the radio access node 700 may include one or more radio units 710, each of which includes one or more transmitters 712 and one or more receivers 714 coupled to one or more antennas 716. The radio unit 710 may be referred to as radio interface circuitry or a part of the radio interface circuitry. In some embodiments, the (one or more) radio units 710 are external to the control system 702 and are connected to the control system 702 via, for example, a wired connection (e.g., an optical cable). However, in some other embodiments, the (one or more) radio units 710 and possibly the (one or more) antennas 716 are integrated with the control system 702. The one or more processors 704 operate to provide one or more functions of the radio access node 700 as described herein. In some embodiments, the (one or more) functions are implemented using software stored, for example, in the memory 706 and executed by the one or more processors 704.
[0174] Figure 8 FIG. 4 is a schematic block diagram showing a virtualized embodiment of a radio access node 700 according to some embodiments of the present disclosure. This discussion is equally applicable to other types of network nodes. Further, other types of network nodes may have a similar virtualized architecture. Additionally, optional features are indicated by dashed boxes.
[0175] As used herein, a "virtualized" radio access node is an implementation of radio access node 700 in which at least a portion of the functionality of radio access node 700 is implemented as one or more virtual components (e.g., via one or more virtual machines executing on one or more physical processing nodes in a network). As shown, in this example, radio access node 700 may include a control system 702 and / or one or more radio units 710, as described above. Control system 702 may be connected to one or more radio units 710 via, for example, an optical cable. Radio access node 700 includes one or more processing nodes 800 that are coupled to or included as part of a network 802. If present, control system 702 or one or more radio units are connected to one or more processing nodes 800 via network 802. Each processing node 800 includes one or more processors 804 (e.g., CPU, ASIC, FPGA, and / or the like), a memory 806, and a network interface 808.
[0176] In this example, the functionality 810 of radio access node 700 described herein is implemented at one or more processing nodes 800 or is distributed in any desired manner across one or more processing nodes 800 and control system 702 and / or one or more radio units 710. In some particular embodiments, some or all of the functionality 810 of radio access node 700 described herein is implemented as virtual components executed by one or more virtual machines implemented in one or more virtual environments hosted by one or more processing nodes 800. As would be understood by one of ordinary skill in the art, additional signaling or communication between one or more processing nodes 800 and control system 702 is used in order to perform at least some of the desired functionality 810. Note that in some embodiments, control system 702 may not be included, in which case one or more radio units 710 communicate directly with one or more processing nodes 800 via an appropriate network interface.
[0177] In some embodiments, a computer program is provided that includes instructions that, when executed by at least one processor, cause the at least one processor to perform the functionality of radio access node 700 according to any of the embodiments described herein or of a node (e.g., processing node 800) that implements one or more of the functionality 810 of radio access node 700 in a virtual environment. In some embodiments, a carrier is provided that includes the aforementioned computer program product. The carrier is an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium (e.g., a non-transitory computer-readable medium such as a memory).
[0178] Fig. 9 is a schematic block diagram of a radio access node 700 according to some other embodiments of the present disclosure. The radio access node 700 includes one or more modules 900, each of which is implemented in software. The (one or more) modules 900 provide the functions of the radio access node 700 described herein. This discussion equally applies to Figure 8 the processing node 800, where the module 900 may be implemented at one processing node 800, or distributed over multiple processing nodes 800 and / or distributed over the (one or more) processing nodes 800 and the control system 702.
[0179] Fig.10 is a schematic block diagram of a wireless communication device 1000 according to some embodiments of the present disclosure. As shown, the wireless communication device 1000 includes one or more processors 1002 (e.g., CPU, ASIC, FPGA, and / or the like), a memory 1004, and one or more transceivers 1006, each transceiver including one or more transmitters 1008 and one or more receivers 1010 coupled to one or more antennas 1012. The (one or more) transceivers 1006 include radio front-end circuitry connected to the (one or more) antennas 1012, which is configured to condition signals transmitted between the (one or more) antennas 1012 and the (one or more) processors 1002, as would be understood by one of ordinary skill in the art. The processor 1002 is also referred to herein as processing circuitry. The transceiver 1006 is also referred to herein as radio circuitry. In some embodiments, the functions of the wireless communication device 1000 described above may be implemented fully or partially by software, such as software stored in the memory 1004 and executed by the (one or more) processors 1002. Note that the wireless communication device 1000 may include Fig.10 additional components not shown in
[0180] such as, for example, one or more user interface components (e.g., an input / output interface including a display, buttons, a touch screen, a microphone, the (one or more) speakers, etc. and / or any other component for allowing information to be input into the wireless communication device 1000 and / or allowing information to be output from the wireless communication device 1000), a power source (e.g., a battery and associated power circuitry), etc.
[0181] Fig.11 FIG. 1 is a schematic block diagram of a wireless communication device 1000 according to some other embodiments of the present disclosure. The wireless communication device 1000 includes one or more modules 1100, each of which is implemented in software. The (one or more) modules 1100 provide the functions of the wireless communication device 1000 described herein.
[0182] Any suitable steps, methods, features, functions or benefits disclosed herein may be performed by one or more functional units or modules of one or more virtual devices. Each virtual device may include a plurality of such functional units. These functional units may be implemented via a processing circuit, which may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include a digital signal processor (DSP), dedicated digital logic, etc. The processing circuit may be configured to execute program code stored in a memory, which may include one or several types of memories, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory devices, optical storage devices, etc. The program code stored in the memory includes program instructions for executing one or more telecommunication and / or data communication protocols and instructions for executing one or more of the techniques described herein. In some embodiments, the processing circuit may be used to cause the corresponding functional units to perform corresponding functions according to one or more embodiments of the present disclosure.
[0183] Some embodiments of the present disclosure may include:
[0184] Embodiment 1. A method for authenticating a 5G proximity service ProSe remote user equipment UE (302) implemented in an authentication server function AUSF (310) of a remote network, comprising: receiving (step 324, Figure 3A ) a first Nausf_UEAuthentication_ProseAuthenticate request message from an access and mobility management function AMF (308) associated with a relay UE 304; providing (step 326, Figure 3B ) a Nudm_UEAuthentication_GetProseAv Request message including a predefined service network name SNN associated with the 5G ProSe remote UE (302) to a unified data manager UDM (312); receiving (step 326, Figure 3B ) an authentication vector, a cipher key CK', and an integrity key IK' based on the ProSe parameters and the predefined SSN in the Nudm_UEAuthentication_GetProseAv Request message from the UDM (312); and providing (step 328, Figure 3B ) The Nausf_UEAuthentication_ProSeAuthenticate Response including the EAP request / AKA' challenge message based on the authentication vector, CK', and IK'.
[0185] Embodiment 2: The method according to Embodiment 1 further includes: receiving from an AMF (308) associated with a relay UE (304) (step 338, Figure 3B ) a second Nausf_UEAuthentication_ProseAuthenticate request message including an EAP-Response / AKA'-Challenge from a 5G ProSe remote UE (302); and authenticating the 5G ProSe remote UE (302) based on the EAP-Response / AKA'-Challenge (step 338, Figure 3B )
[0186] Embodiment 3: The method according to Embodiment 2 further includes: generating (steps 340, 342, Figure 3B ) a control plane ProSe remote user key CP-PRUK identifier based on a routing indicator received from a UDM (312) in response to a Nudm_UEAuthentication_GetProseAv Request message.
[0187] Embodiment 4: An authentication server function AUSF (310) for authenticating a 5G proximity service ProSe remote user equipment UE, the AUSF (310) including a processing circuit configured to cause the AUSF (310) to: receive from an access and mobility management function AMF (308) associated with a relay UE (304) (step 324, Figure 3A)The first Nausf_UEAuthentication_ProseAuthenticate request message; providing a Nudm_UEAuthentication_GetProseAv Request message to the Unified Data Manager UDM (312) that includes a predefined Service Network Name SNN associated with the 5G ProSe Remote UE (302); receiving from the UDM (312) an authentication vector, a cipher key CK', and an integrity key IK' based on the ProSe parameters and the predefined SSN in the Nudm_UEAuthentication_GetProseAvRequest message; and providing a Nausf_UEAuthentication_ProseAuthenticate Response to the AMF (308) associated with the Relay UE (304) that includes an EAP Request / AKA' Challenge message based on the authentication vector, CK', and IK'.
[0188] Example 5: The AUSF (310) according to Example 4, wherein the processing circuitry is further configured to receive from the AMF (308) associated with the Relay UE (304) (step 338, Figure 3B ) a second Nausf_UEAuthentication_ProseAuthenticate request message that includes an EAP-Response / AKA'-Challenge from the 5G ProSe Remote UE (302); and authenticating (step 338, Figure 3B ) the 5G ProSe Remote UE (302) based on the EAP-Response / AKA'-Challenge.
[0189] Example 6: The AUSF (310) according to Example 5, wherein the processing circuitry is further configured to generate (steps 340, 342, Figure 3B ) a Control Plane ProSe Remote User Key CP-PRUK identifier based on a routing indicator received from the UDM (312) in response to the Nudm_UEAuthentication_GetProseAv Request message.
[0190] Example 7: A method for authenticating a 5G ProSe Remote User Equipment UE (302) implemented in a 5G Proximity Service ProSe Remote UE (302), including: providing (step 318, Figure 3A ) a direct communication request to the Relay UE (304) to establish a PC5 unicast link; receiving from the Relay UE (304) (step 330, Figure 3B)An EAP request / AKA' challenge message generated by an Authentication Server Function AUSF (310) of a remote network associated with a 5G ProSe remote UE (302); determining (step 316, Figure 3A , step 332, Figure 3B ) a Service Network Name SNN associated with the 5G ProSe remote UE; based on the SNN and the EAP request / AKA' challenge message, determining (step 332, Figure 3B ) a cipher key CK' and an integrity key IK'; and providing (step 334, Figure 3B ) a return EAP response / AKA' challenge message to the relay UE (304) to facilitate authentication of the 5G ProSe remote UE (302) at the AUSF (310), wherein the EAP response / AKA' challenge message is based on CK' and IK'.
[0191] Example 8: The method according to Example 7, wherein determining the SNN further comprises: triggering (step 316, Figure 3A ) a discovery process with the relay UE (304) before providing a direct communication request to the relay UE (304) to determine cell information associated with the relay UE (304); and determining the SSN based on the cell information.
[0192] Example 9: The method according to Example 8, further comprising: verifying (step 332, Figure 3B ) the SNN using another SNN received from the AUSF (310) via an AT_KDF_INPUT of an Extensible Authentication Protocol EAP packet.
[0193] Example 10: The method according to any one of Examples 8 to 9, wherein the cell information includes one or more of a New Radio Cell Global Identity NGCI or a Tracking Area Identity TAI.
[0194] Example 11: The method according to Example 7, wherein the EAP request / AKA' challenge message includes the SNN.
[0195] Example 12: The method according to Example 11, further comprising: verifying (step 332, Figure 3B ) the SNN using another SNN received from the AUSF (310) via an AT_KDF_INPUT of an Extensible Authentication Protocol EAP packet.
[0196] Example 13: A 5G Proximity Service ProSe remote user equipment UE (302) comprising a processing circuit configured to cause the 5G ProSe remote UE (302) to: provide to the relay UE (304) (step 318, Figure 3A)A direct communication request to establish a PC5 unicast link; receiving from the relay UE (304) (step 332, Figure 3B ) an EAP Request / AKA' challenge message generated by an Authentication Server Function AUSF (310) of a remote network associated with the 5G ProSe remote UE (302); determining (step 316, Figure 3A , step 332, Figure 3B ) the Service Network Name SNN associated with the 5G ProSe remote UE (302); determining (step 332, Figure 3B ) the cipher key CK' and the integrity key IK' based on the SNN and the EAP Request / AKA' challenge message; and providing to the relay UE (304) (step 334, Figure 3B ) returning an EAP Response / AKA' challenge message to facilitate the authentication of the 5G ProSe remote UE (302) at the AUSF (310), wherein the EAP Response / AKA' challenge message is based on CK' and IK'.
[0197] Example 14: The 5G ProSe remote UE (302) according to Example 13, wherein the processing circuit is further configured to perform the methods described in Examples 8 - 12.
[0198] Although the processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform operations in a different order, combine certain operations, overlap certain operations, etc.).
[0199] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered to be within the scope of the concepts disclosed herein.
Claims
1. A method for authenticating a 5G ProSe remote user equipment UE (302) implemented in a fifth-generation 5G Proximity Services ProSe remote user equipment UE (302), comprising: Receiving, from a relay UE (304), a service network identifier associated with the relay UE (304); Receiving (332), from the relay UE (304), a challenge message generated by an Authentication Server Function AUSF (310) associated with the 5G ProSe remote UE (302), wherein the challenge message includes a Service Network Name SNN associated with the relay UE (304); Verifying (332) the SNN associated with the relay UE (304) by using the service network identifier associated with the relay UE (304); Determining (332) a cipher key CK' and an integrity key IK' based on the SNN; And Providing (334) a response to the challenge message to the relay UE (304) to facilitate authentication of the 5G ProSe remote UE (302).
2. The method according to claim 1, wherein, The verification is in response to determining (332) that a control-plane based security procedure is used for a Relay Service Code RSC for communication with the relay UE (304).
3. The method according to claim 2, wherein, Determining that the control-plane based security procedure is used for the RSC for communication with the relay UE (304) is based on an authentication request associated with the challenge message.
4. The method according to any one of claims 1 to 3, wherein Before receiving the service network identifier from the relay UE (304), the method includes: Providing (318) a direct communication request to the relay UE (304) to establish a PC5 unicast link.
5. The method according to any one of claims 1 to 4, wherein The method further includes: Triggering (316) a discovery procedure with the relay UE (304) to determine cell information associated with the relay UE (304).
6. The method according to claim 5, wherein The cell information further includes a Tracking Area Identity TAI.
7. The method according to any one of claims 1 to 6, wherein The SNN included in the challenge message includes an AT_KDF_INPUT of an Extensible Authentication Protocol EAP packet.
8. The method according to any one of claims 1 to 7, wherein, The challenge message is an Extensible Authentication Protocol EAP Request / Authentication and Key Agreement AKA' challenge message.
9. The method according to any one of claims 1 to 8, wherein The response to the challenge message is an Extensible Authentication Protocol EAP Response / AKA' challenge message.
10. The method according to any one of claims 1 to 9, wherein The service network identifier is at least one of the following: service network SN identifier ID information in a New Radio NR Cell Global Identity NCGI, a part of the NCGI, or associated with the NCGI.
11. The method according to any one of claims 1 to 10, wherein, The verification is part of an Extensible Authentication Protocol Authentication and Key Agreement EAP-AKA' authentication process.
12. A fifth-generation 5G Proximity Services ProSe remote user equipment UE (302), comprising a processing circuit configured to cause the 5G ProSe remote UE (302) to: Receive, from a relay UE (304), a service network identifier associated with the relay UE (304); Receive (332) from the relay UE (304) a challenge message generated by an authentication server function AUSF (310) associated with the 5G ProSe remote UE (302), wherein, The challenge message includes a Service Network Name SNN associated with the relay UE (304); Verify (332) the SNN associated with the relay UE (304) using the serving network identifier associated with the relay UE (304); Determine (332) a cipher key CK' and an integrity key IK' based on the SNN; And Provide (334) a response challenge message to the relay UE (304) to facilitate the authentication of the 5G ProSe remote UE (302).
13. The 5G ProSe remote UE (302) according to claim 12, wherein, The verification is in response to determining (332) that a control-plane based security procedure is used for a relay service code RSC for communication with the relay UE (304).
14. The 5G ProSe remote UE (302) according to claim 13, wherein, Determining that the control-plane based security procedure is used for the RSC for communication with the relay UE (304) is based on an authentication request associated with the challenge message.
15. The 5G ProSe remote UE (302) according to any one of claims 12 to 14, wherein, Before receiving the serving network identifier from the relay UE (304), the processing circuitry is further configured to: Provide (318) a direct communication request to the relay UE (304) to establish a PC5 unicast link.
16. The 5G ProSe remote UE (302) according to any one of claims 12 to 15, wherein, The processing circuitry is further configured to: Trigger (316) a discovery procedure with the relay UE (304) to determine cell information associated with the relay UE (304).
17. The 5G ProSe Remote UE (302) according to claim 16, wherein, The cell information further includes a tracking area identity TAI.
18. The 5G ProSe remote UE (302) according to any one of claims 12 to 17, wherein, The SNN included in the challenge message includes an AT_KDF_INPUT of an Extensible Authentication Protocol EAP packet. 5G ProSe Remote UE (302) according to any one of claims 12 to 18, wherein, The challenge message is an Extensible Authentication Protocol EAP Request / Authentication and Key Agreement AKA' challenge message.
20. The 5G ProSe remote UE (302) according to any one of claims 12 to 19, wherein, The response challenge message is an Extensible Authentication Protocol EAP Response / AKA' challenge message.
21. The 5G ProSe remote UE (302) according to any one of claims 12 to 20, wherein, The serving network identifier is at least one of the following: serving network SN identifier ID information in a New Radio NR cell global identity NCGI, a part of the NCGI, or associated with the NCGI.
22. The 5G ProSe remote UE (302) according to any one of claims 12 to 21, wherein, The verification is part of an Extensible Authentication Protocol Authentication and Key Agreement EAP-AKA' authentication procedure.
23. A computer program comprising instructions which, when executed by at least one processor, cause the processor to perform the method according to any one of claims 1 to 11.
24. A carrier, comprising the computer program according to claim 23, wherein, The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.