Using routing indicators

The terminal device acquires and sends anchoring function and routing indicators for AUSF devices, which solves the uncertainty of AUSF device selection in 5G communication system, and realizes a clear communication establishment process and an efficient AUSF selection mechanism.

CN120380809APending Publication Date: 2025-07-25ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280102686.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-05
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In 5G communication systems, there is a lack of clear routing indicators in the prior art when selecting AUSF devices, which causes the AMF of the relay UE to be unable to determine the AUSF of the remote UE, and there is a lack of clear routing indicator configuration and selection mechanism during the generation of 5GPRUK ids.

Method used

The terminal device acquires routing indicators for the anchor function device and the Authentication Server Function (AUSF) device and sends a communication establishment request including these indicators, and the AMF device determines a suitable AUSF device from among the multiple AUSF devices based on the received routing indicator.

Benefits of technology

It realizes a clear AUSF device selection mechanism in the 5G communication system, ensures the reliability and efficiency of the communication establishment process, and solves the uncertainty problem of routing indicators in the generation of 5GPRUK IDs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120380809A_ABST
    Figure CN120380809A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to using a routing indicator. A terminal device acquires a first routing indicator for an anchor function device for the terminal device, and acquires a second routing indicator for an authentication server function (AUSF) device for the terminal device. And the terminal equipment sends a communication establishment request at least comprising the first routing indicator and the second routing indicator. The solution provided in the present disclosure may locate both the anchor function device and the AUSF device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various example embodiments relate to the field of telecommunications and, in particular, to methods, devices, apparatuses, and computer-readable storage media for using routing indicators. Background Art

[0002] In the field of communications, there has been an ongoing evolution to provide effective and reliable solutions using wireless communication networks. Each new generation has its own technical challenges that target handling the different situations and processes required to connect and serve devices connected to a wireless network. To meet the increasing demand for wireless data services since the deployment of the 4th generation (4G) communication systems, efforts have been made to develop improved 5th generation (5G) or pre-5G communication systems. The new communication systems can support various types of service applications for terminal devices.

[0003] Applying routing indicators in a communication system is necessary. In some scenarios, routing indicators can be used to route network signaling to a device to serve a subscriber. Summary of the Invention

[0004] Generally, example embodiments of the present disclosure provide a solution for using routing indicators.

[0005] In a first aspect, a terminal device is provided. The terminal device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the terminal device to at least: obtain a first routing indicator for an anchoring function device for the terminal device; obtain a second routing indicator for an authentication server function (AUSF) device for the terminal device; and send a communication establishment request including at least the first routing indicator and the second routing indicator.

[0006] In a second aspect, a terminal device is provided. The terminal device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the terminal device to at least: receive a routing indicator for an anchoring function device for the terminal device, the routing indicator provided by an authentication server function (AUSF) device for the terminal device; and send a communication establishment request including at least the routing indicator.

[0007] In a third aspect, an authentication server function (AUSF) device is provided. The AUSF device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the AUSF device to at least: obtain a first routing indicator for an anchoring function device for a terminal device; and send the first routing indicator to be used by the terminal device.

[0008] In a fourth aspect, an access and mobility management (AMF) device for a relay terminal device is provided. The AMF device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the AMF device to at least: receive a relay key request from the relay terminal device, the relay key request including at least a routing indicator for an authentication server function (AUSF) device; and determine the AUSF device from a plurality of AUSF devices based on the routing indicator.

[0009] In a fifth aspect, a unified data management (UDM) device is provided. The UDM device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the UDM device to at least: store a routing indicator for an anchoring function device for the terminal device; and send the routing indicator to the terminal device during a user equipment (UE) parameter update (UPU) procedure.

[0010] In a sixth aspect, a method implemented at a terminal device is provided. The method includes: at the terminal device, obtaining a first routing indicator for an anchoring function device for the terminal device; obtaining a second routing indicator for an authentication server function (AUSF) device for the terminal device; and sending a communication establishment request including at least the first routing indicator and the second routing indicator.

[0011] In a seventh aspect, a method implemented at a terminal device is provided. The method includes: at the terminal device, receiving a routing indicator for an anchoring function device for the terminal device, the routing indicator provided by an authentication server function (AUSF) device for the terminal device; and sending a communication establishment request including at least the routing indicator.

[0012] In an eighth aspect, a method implemented at an authentication server function (AUSF) device is provided. The method includes: at the AUSF device, obtaining a first routing indicator for an anchoring function device for a terminal device; and sending the first routing indicator to be used by the terminal device.

[0013] In a ninth aspect, a method implemented at an access and mobility management (AMF) device of a relay terminal device is provided. The method includes: at the AMF device of the relay terminal device, receiving a relay key request from the relay terminal device, the relay key request including at least a routing indicator for an authentication server function (AUSF) device; and determining the AUSF device from a plurality of AUSF devices based on the routing indicator.

[0014] In a tenth aspect, a method implemented at a Unified Data Management (UDM) device is provided. The method includes: storing, at the Unified Data Management (UDM) device, a routing indicator for an anchoring function device for a terminal device; and sending, during a User Equipment (UE) Parameter Update (UPU) procedure, the routing indicator to the terminal device.

[0015] In an eleventh aspect, a device is provided. The device includes: means for obtaining, at a terminal device, a first routing indicator for an anchoring function device for the terminal device; means for obtaining a second routing indicator for an Authentication Server Function (AUSF) device for the terminal device; and means for sending a communication establishment request including at least the first routing indicator and the second routing indicator.

[0016] In a twelfth aspect, a device is provided. The device includes: means for receiving, at a terminal device, a routing indicator for an anchoring function device for the terminal device, the routing indicator being provided by an Authentication Server Function (AUSF) device for the terminal device; and means for sending a communication establishment request including at least the routing indicator.

[0017] In a thirteenth aspect, a device is provided. The device includes: means for obtaining, at an Authentication Server Function (AUSF) device, a first routing indicator for an anchoring function device for the terminal device; and means for sending the first routing indicator to be used by the terminal device.

[0018] In a fourteenth aspect, a device is provided. The device includes: means for receiving, at an Access and Mobility Management (AMF) device of a relay terminal device, a relay key request from the relay terminal device, the relay key request including at least a routing indicator for an Authentication Server Function (AUSF) device; and means for determining the AUSF device from a plurality of AUSF devices based on the routing indicator.

[0019] In a fifteenth aspect, a device is provided. The device includes: means for storing, at a Unified Data Management (UDM) device, a routing indicator for an anchoring function device for a terminal device; and means for sending, during a User Equipment (UE) Parameter Update (UPU) procedure, the routing indicator to the terminal device.

[0020] In a sixteenth aspect, a non-transitory computer-readable medium including program instructions is provided, the program instructions for causing a device to perform at least the method according to any one of the sixth to tenth aspects above.

[0021] In a seventeenth aspect, there is provided a non-transitory computer-readable medium storing program instructions for at least performing the method according to any one of the above sixth aspect to tenth aspect.

[0022] In an eighteenth aspect, there is provided a computer program comprising instructions which, when executed by a device, cause the device to at least: obtain a first routing indicator for an anchoring function device for a terminal device; obtain a second routing indicator for an authentication server function (AUSF) device for the terminal device; and send a communication establishment request comprising at least the first routing indicator and the second routing indicator.

[0023] In a nineteenth aspect, there is provided a computer program comprising instructions which, when executed by a device, cause the device to at least: receive a routing indicator for an anchoring function device for the terminal device, the routing indicator being provided by an authentication server function (AUSF) device for the terminal device; and send a communication establishment request comprising at least the routing indicator.

[0024] In a twentieth aspect, there is provided a computer program comprising instructions which, when executed by a device, cause the device to at least: obtain a first routing indicator for an anchoring function device for a terminal device; and send the first routing indicator to be used by the terminal device.

[0025] In a twenty-first aspect, there is provided a computer program comprising instructions which, when executed by a device, cause the device to at least: receive a relay key request from a relay terminal device, the relay key request comprising at least a routing indicator for an authentication server function (AUSF) device; and determine the AUSF device from a plurality of AUSF devices based on the routing indicator.

[0026] In a twenty-second aspect, there is provided a computer program comprising instructions which, when executed by a device, cause the device to at least: store a routing indicator for an anchoring function device for a terminal device; and send the routing indicator to the terminal device during a user equipment (UE) parameter update (UPU) procedure.

[0027] In a twenty-third aspect, there is provided a terminal device. The terminal device comprises: a first obtaining circuit system configured to obtain a first routing indicator for an anchoring function device for the terminal device; a second obtaining circuit system configured to obtain a second routing indicator for an authentication server function (AUSF) device for the terminal device; and a sending circuit system configured to send a communication establishment request comprising at least the first routing indicator and the second routing indicator.

[0028] In a twenty-fourth aspect, a terminal device is provided. The terminal device includes: a receiving circuit system configured to receive a routing indicator for an anchoring function device for the terminal device, the routing indicator being provided by an authentication server function (AUSF) device for the terminal device; and a transmitting circuit system configured to transmit a communication establishment request including at least the routing indicator.

[0029] In a twenty-fifth aspect, an authentication server function (AUSF) device is provided. The AUSF device includes: an obtaining circuit system configured to obtain a first routing indicator for an anchoring function device for a terminal device; and a transmitting circuit system configured to transmit the first routing indicator to be used by the terminal device.

[0030] In a twenty-sixth aspect, an access and mobility management (AMF) device for a relay terminal device is provided. The AMF device includes: a receiving circuit system configured to receive a relay key request from the relay terminal device, the relay key request including at least a routing indicator for an authentication server function (AUSF) device; and a determining circuit system configured to determine the AUSF device from a plurality of AUSF devices based on the routing indicator.

[0031] In a twenty-seventh aspect, a unified data management (UDM) device is provided. The UDM device includes: a storage circuit system configured to store a routing indicator for an anchoring function device for a terminal device; and a transmitting circuit system configured to transmit the routing indicator to the terminal device during a user equipment (UE) parameter update (UPU) procedure.

[0032] It should be understood that the Summary of the Invention section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become readily apparent through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Some example embodiments will now be described with reference to the accompanying drawings, in which:

[0034] Figure 1 An example communication system in which embodiments of the present disclosure may be implemented is shown;

[0035] Figure 2 A flowchart of a method implemented at a terminal device according to some embodiments of the present disclosure is shown;

[0036] Figure 3 A flowchart of a method implemented at a terminal device according to some other embodiments of the present disclosure is shown;

[0037] Figure 4A flowchart of a method implemented at an Authentication Server Function (AUSF) device according to some embodiments of the present disclosure;

[0038] Figure 5 A flowchart of a method implemented at an Access and Mobility Management (AMF) device of a relay terminal device according to some embodiments of the present disclosure;

[0039] Figure 6 A flowchart of a method implemented at a Unified Data Management (UDM) device according to some embodiments of the present disclosure;

[0040] Figure 7 A schematic diagram of DCR after ProSe authentication according to some embodiments of the present disclosure;

[0041] Figure 8 A structure of SUCI according to some embodiments of the present disclosure;

[0042] Figure 9 A schematic diagram of 5G PRUKID according to some embodiments of the present disclosure;

[0043] Figure 10 A schematic diagram of A-KID according to some embodiments of the present disclosure;

[0044] Figure 11A and Figure 11B A flowchart of an interaction process between devices according to some embodiments of the present disclosure;

[0045] Figure 12A A flowchart of an interaction process between devices according to some other embodiments of the present disclosure;

[0046] Figure 12B Shows a schematic diagram of the generation of K NR_Prose according to some other embodiments of the present disclosure;

[0047] Figure 13A and Figure 13B A flowchart of an interaction process between devices according to some other embodiments of the present disclosure;

[0048] Figure 14A and Figure 14B A flowchart of an interaction process between devices according to some other embodiments of the present disclosure;

[0049] Figure 15 A flowchart of an interaction process between devices according to some other embodiments of the present disclosure;

[0050] Figure 16A flowchart showing an interaction process between devices according to some other embodiments of the present disclosure;

[0051] Figure 17 A simplified block diagram showing a device suitable for implementing embodiments of the present disclosure; and

[0052] Figure 18 A block diagram showing an example computer-readable medium according to some embodiments of the present disclosure;

[0053] Throughout the drawings, the same or similar reference numerals denote the same or similar elements. Detailed Description

[0054] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that the description of these embodiments is for illustrative purposes only and helps those skilled in the art to understand and implement the present disclosure, without implying any limitation on the scope of the present disclosure. The present disclosure described herein can be implemented in various ways other than those described below.

[0055] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0056] References to "one embodiment", "an embodiment", "example embodiment", etc. in the present disclosure indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment includes that particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an example embodiment, those skilled in the art will recognize that, whether or not explicitly described, the combination of such a feature, structure, or characteristic with other embodiments is within the knowledge of those skilled in the art.

[0057] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the example embodiments, the first element may be referred to as the second element, and similarly, the second element may be referred to as the first element. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0058] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the example embodiments. As used herein, the singular forms "a", "an" and "the" are also intended to include the plural forms unless the context clearly dictates otherwise. It will be further understood that the terms "comprises", "comprising", "has", "having", "includes" and / or "including" when used herein specify the presence of the stated features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof. As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrases, where the list of two or more elements is joined by "and" or "or", means at least any one element, or at least any two or more elements, or at least all elements.

[0059] As used in this application, the term "circuitry" can refer to one or more or all of the following:

[0060] (a) Only hardware circuit implementations (such as implementations only in analog and / or digital circuitry), and

[0061] (b) Combinations of hardware circuits and software, such as (where applicable):

[0062] (i) Combinations of (multiple) analog and / or digital hardware circuits and software / firmware, and

[0063] (ii) Any part of (multiple) hardware processors with software (including

[0064] (multiple) digital signal processors, software, and (multiple) memories, which work together to enable a device (such as a mobile phone or a server) to perform various functions) and

[0065] (c) (Multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or parts of (multiple) microprocessors, which require software (e.g., firmware) to operate, but the software may be absent when not needed.

[0066] This definition of circuitry is suitable for all uses of the term in this application. As a further example, as used in this application, the term circuitry also encompasses implementations of only hardware circuits or processors (or multiple processors) or parts of hardware circuits or processors and their (or their) accompanying software and / or firmware. For example and if applicable to a particular claim element, the term "circuitry" also encompasses a baseband integrated circuit or a processor integrated circuit for a mobile device, or a similar integrated circuit in a server, a cellular network device, or other computing or network devices.

[0067] As used herein, the term "communication network" refers to a network that complies with any suitable communication standard, such as Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High Speed Packet Access (HSPA), NarrowBand Internet of Things (NB-IoT), etc. In addition, the communication between the terminal device and the network device in the communication network can be performed according to any suitable generation of communication protocol, including but not limited to the first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, future fifth generation (5G) communication protocol, and / or any other protocol currently known or to be developed in the future. Embodiments of the present disclosure can be applied to various communication systems. Given the rapid development of communication, there will of course be future types of communication technologies and systems that can be used to embody the present disclosure. It should not be regarded as limiting the scope of the present disclosure to the above systems.

[0068] As used herein, the term "network device" refers to a node in a communication network through which a terminal device accesses the network and receives services from the network. Depending on the terminology and technology applied, the network device may refer to a base station (BS) or an access point (AP), such as Node B (NodeB or NB), evolved Node B (eNodeB or eNB), NR NB (also known as gNB), Remote Radio Unit (RRU), Radio Head (RH), Remote Radio Head (RRH), relay, low-power node (such as femto, pico), etc.

[0069] The term "terminal device" refers to any terminal device capable of wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smart phones, IP voice (VoIP) phones, wireless local loop phones, tablet computers, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices such as digital cameras, game terminal devices, music storage and playback applications, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, lap-mounted embedded devices (LEE), lap-mounted equipment (LME), USB dongles, smart devices, wireless client devices (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMD), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in an industrial and / or automated processing chain environment), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. In the following description, the terms "terminal device", "communication device", "terminal", "user equipment", and "UE" may be used interchangeably.

[0070] According to 3GPP CT4 (TS23.003 & TS24.501), the routing indicator may consist of 1 to 4 decimal digits assigned by the home network operator and may be provided in the USIM, which allows, together with the home network identifier, routing of network signaling with SUCI to the AUSF and UDM instances capable of serving the subscriber. Each decimal digit in the routing indicator will be considered significant (e.g., the value "012" is different from the value "12"). If no routing indicator is configured on the USIM, the data field will be set to the value 0 (i.e., it will consist of only the decimal digit "0").

[0071] The routing indicator (octets 8 - 9) will consist of 1 to 4 digits. The encoding of this field is the responsibility of the home network operator, but BCD encoding will be used. If the network operator decides to assign fewer than 4 digits to the routing indicator, the remaining digits will be encoded as "1111" to fill the 4 - digit encoding of the routing indicator. If no routing indicator is configured in the USIM or ME, the UE shall encode bits 1 to 4 of octet 8 of the routing indicator as "0000" and the remaining digits as "1111".

[0072] According to 3GPP CT6 (clause 5.3.51 & 4.4.11.11 of TS 31.102), for the routing indicator process of the ME: Requirement: Service n 124 is "available". Request: As part of the SUCI calculation performed by the ME, the ME utilizes EF Routing_Indicator to perform a read process. EF Routing_Indicator (Routing Indicator EF): If service n 124 is "available" in EFUST, then this file will exist. This EF contains the routing indicator required for the SUCI calculation content of the routing indicator by the ME or by the USIM. This EF contains the routing indicator which allows, together with the MCC and MNC, to route network signaling with SUCI to the AUSF and UDM instances capable of serving the subscriber, as specified in 3GPP TS23.003. As specified in 3GPP TS24.501, the routing indicator is encoded in 2 bytes. As specified in 3GPP TS24.501, this EF will contain at least one significant digit of the routing ID even if the unique digit is set to 0 (the case when the HPLMN intends not to configure a valid routing indicator in the USIM). Bytes 3 to 4 are for RFU. The above can be seen in Table 1.

[0073] Table 1

[0074]

[0075] The indicator defined in TS23.003 can be used for AUSF or UDM selection. A UDM can include several UDM instances. The routing indicator in SUCI can be used to identify the correct UDM instance capable of serving the subscriber.

[0076] According to 3GPP SA2 (TS23.501), when the routing indicator of the UE is set to its default value as defined in TS23.003, the AUSF NF consumer can select any AUSF instance within the home network for the UE. The UE provides the SUCI to the AMF during the initial registration, which contains the routing indicator and the home network public key identifier as defined in TS23.003. As described in TS23.502, the AMF can provide the UE's routing indicator and the optional home network public key identifier to other AMFs.

[0077] The NF profile of the NF instance maintained in the NRF includes the following information: NF instance ID; NF type; PLMN ID in the case of PLMN, PLMNID + NID in the case of SNPN; routing indicator, home network public key identifier, for UDM and AUSF.

[0078] Referring to Table 2, according to 3GPP SA2 (TS23.502), if the target NF is UDM or AUSF, the request may include the UE's routing indicator, or the UE's routing indicator and the home network public key identifier.

[0079] Table 2

[0080]

[0081] Referring to Table 3, according to the terms of 3GPP's S3-220736, a 5G PRUK ID is introduced for the network to identify 5G PRUK. When the 5G PRUK ID is used, the network should be able to find the PAnF in the home PLMN storing the 5G PRUK ID and 5G PRUK.

[0082] Table 3

[0083]

[0084] The above ProSe use cases are examples to illustrate the technologies related to the embodiments of the present disclosure. Currently, there are still some problems. Specifically: Problem #1, either the 5G PRUK ID or the SUCI will be included in the direct communication request (DCR). In the case of SUCI, the routing information for the AUSF is included in the SUCI, and the AUSF can obtain the routing information (RID) for the PAnF from the UDM of the remote UE, and use this information to generate the 5G PRUK ID (in step 8 of Figure 6 .3.3.3.2-1 in TS 33.503), and select the PAnF based on the 5G PRUK ID (in step 9 of the same figure). However, if the 5G PRUK ID instead of the SUCI is included in the DCR, it is not clear how the AMF of the relay UE selects the AUSF of the remote UE because there is no routing indicator for the AUSF. The RID is added to the 5G PRUK ID for routing to the PAnF, but not for routing to the AUSF. Problem #2, it is not clearly mentioned on the UE side (TS24.501 or TS24.554 or TS 33.503) which RID is used for 5G PRUK ID generation at the AUSF and the UE. Nor is it specified how, when, and under which conditions the RID for 5G PRUK ID should be configured on the UE side. Problem #3, if it is assumed that the RID of the AUSF is used for PAnF selection, why should the AUSF retrieve the RID from the UDM (in response to Figure 6Step 6) of .3.3.3.2-1, and selecting PAnF based on 5GPRUKID (in step 9 of the same figure), although the AUSF has the RID of the AUSF in its own NF profile. According to the previous analysis, the RID used to select PAnF is different from the traditional RID included in the SUCI for AUSF selection. This also makes sense because: the number of AUSFs in the HPLMN may be much larger than the number of PAnFs, so there is no need for the PAnF to have the same identity number as the AUSF. In addition to the traditional RID, in cases where the routing indicator is not sufficient to provide the SUPI range granularity, the home network public key identifier is reused as additional information to find the AUSF of the same PLMN, which means that adding the RID in the 5GPRUKID may still not be sufficient to locate the AUSF. The default RID can be used for the AUSF, in which case the AMF can select any AUSF. Since the AUSF is somewhat "stateless", it may be fine for the AUSF. When the AUSF registers the 5GPRUK with the PAnF, it may be good for selecting the PAnF, but it does not work when the AUSF needs to obtain the 5GPRUK based on the 5GPRUK ID later. There are also some scenarios with similar problems for AKMA. Embodiments of the present disclosure provide some solutions to the above problems.

[0085] The principles and embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. First, refer to Figure 1 , Figure 1 illustrates an example communication system 100 in which embodiments of the present disclosure can be implemented. The system 100 includes a plurality of network devices in the core network 120. The system 100 also includes a plurality of terminal devices 110. In some embodiments, the terminal device 110 among the plurality of terminal devices 110 can be a relay terminal device or a remote terminal device. The relay terminal device is capable of connecting and communicating with both the network devices in the core network 120 and the remote terminal devices. In some embodiments, two network devices in the core network 120 can communicate with each other. In some embodiments, the system can include another (plural) device ( Figure 1 not shown in the figure), such as a (plural) base station.

[0086] It should be understood that the number of network devices and terminal devices 110 is for illustrative purposes only and does not imply any limitation. The system 100 can include any suitable number of network devices and terminal devices 110 suitable for implementing the embodiments of the present disclosure.

[0087] Communication in the communication system 100 can be implemented according to any suitable communication protocol(s), including but not limited to cellular communication protocols such as the first generation (1G), second generation (2G), third generation (3G), fourth generation (4G), and fifth generation (5G), wireless local area network communication protocols such as those of the Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocol known currently or to be developed in the future. Additionally, the communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplexing (FDD), Time Division Duplexing (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiplexing (OFDM), Discrete Fourier Transform Spread OFDM (DFT-s-OFDM), and / or any other technology known currently or to be developed in the future.

[0088] The present disclosure provides a terminal device 110. Figure 2 A flowchart of a method 200 implemented at the terminal device 110 according to some embodiments of the present disclosure is shown. At block 210, the terminal device 110 may obtain a first routing indicator for an anchoring function device for the terminal device 110. At block 220, the terminal device 110 may obtain a second routing indicator for an Authentication Server Function (AUSF) device for the terminal device 110. At block 230, the terminal device 110 may send a communication establishment request including at least the first routing indicator and the second routing indicator.

[0089] In some embodiments, the method 200 may be applied to ProSe use cases (described in detail below). In some embodiments, the terminal device 110 is specifically a remote UE.

[0090] In some embodiments, the terminal device 110 may generate a key identifier (ID) of the terminal device 110 to include the first routing indicator; and send a communication establishment request including at least the second routing indicator and the key ID.

[0091] In some embodiments, the communication establishment request may further include: a home network public key ID (PKID) to be used by the AMF device. In some embodiments, the key ID, the second routing indicator, and the PKID are included in a Subscription Concealed Identifier (SUCI) of the terminal device 110; and the SUCI is included in the communication establishment request.

[0092] In some other embodiments, the terminal device 110 may generate a key identifier (ID) of the terminal device 110 to include the first routing indicator and the second routing indicator; and send a communication establishment request including at least the key ID.

[0093] In some embodiments, the anchoring function device may be a proximity-based service (ProSe) anchoring function device. The key ID may be the ProSe remote user key (PRUK) ID for 5G of the terminal device 110.

[0094] In some embodiments, the terminal device 110 is a remote terminal device, and the remote terminal device may send a communication establishment request by sending a ProSe direct link establishment request, where the ProSe direct link establishment request includes: a first routing indicator to be used by the AUSF device, and a second routing indicator to be used by the access and mobility management (AMF) device of the relay terminal device.

[0095] In some embodiments, the terminal device 110 may obtain the first routing indicator through at least one of the following: receiving the first routing indicator provided by the AUSF device during the authentication process; receiving the first routing indicator provided by the unified data management (UDM) device during the user equipment (UE) parameter update (UPU) process; or retrieving the first routing indicator pre-configured in the universal integrated circuit card (UICC) of the terminal device 110.

[0096] In some embodiments, the terminal device 110 may receive the first routing indicator during the authentication process through the following: during the ProSe-specific authentication process, receiving an Extensible Authentication Protocol (EAP) message including the first routing indicator.

[0097] In some embodiments, the terminal device 110 may receive the first routing indicator during the UPU process through the following: during the UPU process, receiving UPU data including the first routing indicator.

[0098] Figure 3 A flowchart of a method 300 implemented at the terminal device 110 according to some other embodiments of the present disclosure is shown. At block 310, the terminal device 110 may receive a routing indicator for an anchoring function device for the terminal device 110, which is provided by an authentication server function (AUSF) device for the terminal device 110. At block 320, the terminal device 110 may send a communication establishment request including at least the routing indicator.

[0099] In some embodiments, the method 300 may be applied to the AKMA use case (to be described in detail below).

[0100] In some embodiments, the routing indicator may be referred to as a first routing indicator. The terminal device 110 may generate a key identifier (ID) of the terminal device 110 to include the first routing indicator; and send a communication establishment request including at least the key ID.

[0101] In some other embodiments, the routing indicator may be referred to as a first routing indicator, and the terminal device 110 may generate a key identifier (ID) of the terminal device 110 to include a second routing indicator for an authentication server function (AUSF) device for the terminal device 110, and the first routing indicator; and send a communication establishment request including at least the key ID.

[0102] In some embodiments, the anchoring function device is an authentication and key management for applications (AKMA) anchoring function device. In some embodiments, the key ID may be an AKMA key ID (A-KID) of the terminal device 110. In some embodiments, the terminal device 110 may send the communication establishment request in a manner of sending an application session establishment request including a routing indicator to be used by an application function device.

[0103] In some embodiments, the terminal device 110 may obtain the routing indicator in various ways. For example, the terminal device 110 may obtain the routing indicator by at least one of the following: during the authentication process, receiving the routing indicator provided by the AUSF device; during the user equipment (UE) parameter update (UPU) process, receiving the routing indicator from a unified data management (UDM) device; or retrieving the routing indicator pre-configured in the universal integrated circuit card (UICC) of the terminal device 110.

[0104] In some embodiments, the terminal device 110 may receive the routing indicator during the authentication process by receiving an authentication request including the routing indicator during the primary authentication process.

[0105] In some embodiments, to receive the routing indicator during the UPU process, the terminal device 110 may receive UPU data including the routing indicator during the UPU process.

[0106] Figure 4 A flowchart of a method 400 implemented at an authentication server function (AUSF) device according to some embodiments of the present disclosure is shown. At block 410, the AUSF device may obtain a first routing indicator for an anchoring function device for the terminal device 110. At block 420, the AUSF device may send the first routing indicator to be used by the terminal device 110.

[0107] In some embodiments, the anchoring function device is a proximity-based service (ProSe) anchoring function (PAnF) device, and the key ID is a ProSe remote user key (PRUK) ID for 5G of the terminal device 110. These embodiments may be applied to the ProSe use cases of the present disclosure.

[0108] In the ProSe use case, in some embodiments, the terminal device 110 may be a remote terminal device, and the AUSF device may be the AUSF device of the remote terminal device. The AUSF device may send a first routing indicator. Specifically, the AUSF device may send a first routing indicator to be used for the remote terminal device.

[0109] In the ProSe use case, in some embodiments, the terminal device 110 sends a first routing indicator. Specifically, the AUSF device may send a ProSe authentication response including the first routing indicator during a ProSe specific authentication process.

[0110] In some other embodiments, the anchoring function device may be an authentication and key management (AKMA) anchoring function (AAnF) device for an application; and the key ID may be the AKMA key ID (A-KID) of the terminal device 110. These embodiments may be applied to the AKMA use case of the present disclosure.

[0111] In the AKMA use case, the terminal device 110 sends a first routing indicator. Specifically, the terminal device 110 may send an authentication response message including the first routing indicator during a primary authentication process.

[0112] In some embodiments, such as in the ProSe use case or the AKMA use case, the AUSF device may generate a key identifier (ID) for the terminal device 110 to include one of the following items: the first routing indicator; or both the second routing indicator and the first routing indicator for the AUSF device of the terminal device 110.

[0113] In some embodiments, such as in the ProSe use case or the AKMA use case, the AUSF device obtains the first routing indicator. Specifically, the AUSF device may select an anchoring function device from multiple anchoring function devices and retrieve the routing indicator of the selected anchoring function device from a network function (NF).

[0114] In some embodiments, in order to retrieve the routing indicator of the selected anchoring function device from the NF, the AUSF device may retrieve the routing indicator of the selected anchoring function device from the NF profile of an anchoring function device in one of the following items: the anchoring function device, or the network repository function (NRF) device.

[0115] In some embodiments, such as in the ProSe use case or the AKMA use case, in order to obtain the first routing indicator, the AUSF device may receive the first routing indicator pre-configured in the UDM device from the unified data management (UDM) device.

[0116] Figure 5The flowchart of method 500 implemented at an access and mobility management (AMF) device of a relay terminal device according to some embodiments of the present disclosure is shown. At block 510, the AMF device may receive a relay key request from the relay terminal device, where the relay key request includes at least a routing indicator for an authentication server function (AUSF) device. At block 520, the AMF device may determine the AUSF device from a plurality of AUSF devices based on the routing indicator.

[0117] In some embodiments, the relay key request may further include a home network public key ID (PKID), and the AMF device may determine the AUSF device from the plurality of AUSF devices by determining the AUSF device from the plurality of AUSF devices based on both the routing indicator and the PKID.

[0118] The AMF device may be applied to the ProSe use case of the present disclosure.

[0119] Figure 6 The flowchart of method 600 implemented at a unified data management (UDM) device according to some embodiments of the present disclosure is shown. At block 610, the UDM device may store a routing indicator for an anchoring function device for the terminal device 110. At block 620, the UDM device may send the routing indicator to the terminal device 110 during a user equipment (UE) parameter update (UPU) procedure.

[0120] In some embodiments, in order to send the routing indicator during the UPU procedure, the UDM device may send UPU data including the routing indicator during the UPU procedure.

[0121] The UDM device may be applied to the ProSe use case or the AKMA use case of the present disclosure.

[0122] Taking the ProSe use case as an example, Figure 7 The schematic diagram of a direct communication request (DCR) after ProSe authentication according to some embodiments of the present disclosure is shown. As Figure 7 shown, the 5G PRU KID is included in the DCR, and the RID of the selected PAnF is used by the AUSF to generate the 5G PRU KID. In some embodiments, the RID of the selected PAnF may be pre-configured in the UDM and the UE (UICC). In some other embodiments, the AUSF may obtain it from the NRF or the PAnF after the AUSF selects the PAnF for 5G PRU registration, so the AUSF may pass the RID of the selected PAnF to the UE during ProSe authentication.

[0123] Continue to refer to Figure 7, in some embodiments, when the UE sends a Direct Communication Request (DCR) after ProSe-specific authentication, in addition to the 5G PRU K ID and other information, it also includes the RID of the AUSF in the DCR. In these embodiments, the AMF uses the RID AUSF (i.e., the RID of the AUSF) to discover the AUSF, and then the AUSF uses the RID in the 5G PRU K ID PAnF (i.e., the RID of the PAnF) to identify the PAnF to which the 5G PRU K is registered.

[0124] In some embodiments, the 5G PRU K ID is an example of a ProSe Remote User Key (PRU K) ID for 5G. In some other embodiments, an example of a ProSe Remote User Key (PRU K) ID for 5G may be the CP-PRU K. In some embodiments, the DCR is an example of a communication establishment request.

[0125] Continuing to refer to Figure 7 , in some embodiments, when the UE sends a Direct Communication Request (DCR) after ProSe-specific authentication, in addition to the 5G PRU K ID and other information, it also includes the RID of the AUSF and optionally the home network Public Key Identifier (PKID) in the DCR. The AMF uses the RID AUSF , optionally the home network public key identifier (e.g., in cases where the routing indicator is not sufficient to provide SUPI range granularity), to discover the AUSF, and then the AUSF uses the RID in the 5G PRU K ID PAnF to identify the PAnF to which the 5G PRU K is registered.

[0126] In some embodiments, a new SUPI type may be introduced in the SUCI for the 5G PRU K ID. Then, as the structure of the following Subscription Concealed Identifier (SUCI), the 5G PRU K ID can be set as the "scheme output" of the SUCI, the SUPI type can be set to 4 (indicating the 5G PRU K ID), and the protection scheme Id can be set to 0 (null mode). Figure 8 shows the structure of the SUCI according to some embodiments of the present disclosure, as Figure 8 shown, the 5G PRU K ID can be set as the "scheme output" of the SUCI, so the 5G PRU K ID is included in the UE's SUCI.

[0127] In some embodiments, the SUCI can be included in the DCR regardless of whether ProSe authentication occurs.

[0128] In some embodiments, the RID of the AUSF and the RID of the PAnF are retrieved by the AUSF to generate the 5G PRU K ID. Refer toFigure 9 , Figure 9 shows a schematic diagram of a 5G PRUK ID according to some embodiments of the present disclosure. Both the RID of the AUSF and the RID of the PAnF are included in the 5G PRUK ID. In some embodiments, in order for the UE to generate a similar ID, the RID of the PAnF can be pre-configured in the UDM and the UE. In some other embodiments, the RID of the PAnF can be sent via the UPU process or during the ProSe authentication process. In other words, the UE can receive the RID of the PAnF via the UPU process. In some embodiments, the RID of the PAnF sent via the UPU process can be configured by the network side for the UDM. When sending a DCR message with a 5G PRUK ID, then the AMF uses the RID AUSF (which is the traditional RID for the AUSF and the UDM) to identify the AUSF, and the AUSF uses the RID PAnF to identify the PAnF.

[0129] Similarly, in some other embodiments, the RID in the A-KID for the AKMA case should be clarified, and the RID AAnF (i.e., the RID of the AAnF) should be explicitly included in the A-KID. Figure 10 shows a schematic diagram of the A-KID according to some embodiments of the present disclosure, as Figure 10 shown, the RID of the AAnF is included in the A-KID.

[0130] Embodiments of the present disclosure are described below for the ProSe use case and the AKMA use case respectively.

[0131] In the ProSe use case, as described above, in some embodiments, the RID of the PAnF is used in the 5G PRUK ID, but the RID of the AUSF is not used in the 5G PRUK ID. In these embodiments, the RID of the AUSF can be retrieved from the USIM (EF file) that can be included in the DCR message. In some embodiments, the RID of the AUSF is included in the SUCI of the DCR message.

[0132] Figure 11A and Figure 11B are taken as a whole to show a flowchart of the interaction process 1100 between devices according to some embodiments of the present disclosure. Figure 11B is Figure 11AContinuation of. In procedure 1100, the remote UE 111 is registered and authenticated (1101a) by the remote network. The relay UE 112 is registered and authenticated (1101b) by the relay network. Model A or Model B discovery (refer to clause 6.3.1 of TS23.3.4) (1101c). The remote UE 111 sends a ProSe direct link establishment request (SUCI, Nonce_1, relay service code) to the relay UE to network 112 (1102). The relay UE to network 112 sends a relay key request (SUCI, Nonce_1, relay service code, transaction identifier) to the AMF 113 of the relay UE 112 (1103). The AMF 113 of the relay UE 112 authorizes the relay UE 112 (1104). The AMF 113 of the relay UE 112 sends a Nausf_UEAuthenticate_ProseAuthenticate_Request (SUCI, Nonce_1, relay service code) to the AUSF 114 of the remote UE 111 (1105). The AUSF 114 of the remote UE 111 sends a Nudm_UEAuthenticate_GetProseAV request (SUCI, relay service code, SNN) to the UDM 115 of the remote UE 111 (1106a). The UDM 115 of the remote UE 111 sends a Nudm_UEAuthenticate_GetProseAV response (authentication type = primary EAP AKA, EAP AV, SUPI, RID PAnF )(1106c). The AUSF 114 of the remote UE 111 stores XRES, RID PAnF (1106d). The AUSF 114 of the remote UE 111 sends a Nausf_UEAuthentication_ProSeAuthenticateResponse (authentication type = primary EAP AKA, EAP AV, RID PAnF )(1107). The AMF 113 of the relay UE 112 sends a relay authentication request (EAP message, transaction identifier, RID PAnF )(1108). The relay UE to network 112 sends a PC5 EAP message (with RAND, AUTN, RID PAnF )(1109a). The remote UE 111 stores RID PAnF(1109b). The remote UE 111 sends a PC5 EAP response message (with RES) to the relay UE to the network 112 (1109c). The relay UE to the network 112 sends a relay authentication response (EAP message, transaction identifier) to the AMF 113 of the relay UE 112 (1110). The AMF 113 of the relay UE 112 sends a Nudm_UEAuthentication_ProSeAuthenticatieResponse (EAP message) to the AUSF 114 of the remote UE 111 (1111). The AUSF 114 of the remote UE 111 can verify the RES using the XRES (1112a). The AUSF 114 of the remote UE 111 generates a 5G PRUK ID (including RID PAnF ), 5G PRUK (1112b). The remote UE 111 can generate a 5GPRUK ID (including RID PAnF ), 5GPRUK (i.e., 5G PRUK) (1112c); The AUSF 114 of the remote UE 111 sends a Npanf_ProseKey_Register request (5G PRUK ID, 5G PRUK, RSC, SUPI) to the PAnF 116 of the remote UE 111 (1113). The PAnF 116 of the remote UE 111 can store the ProSe context (SUPI, RSC, 5G PRUK, 5G PRUK ID) (1114). The PAnF 116 of the remote UE 111 sends a Npanf_ProseKey_Register response to the AUSF 114 of the remote UE 111 (1115). The AUSF 114 of the remote UE 111 generates K NR_Prose (1116). The AUSF 114 of the remote UE 111 sends a Nausf_UEAuthenticate_ProseAuthenticate response (Nonce_2, K NR_Prose , EAP_Success) to the AMF 113 of the relay UE 112 (1117). The AMF 113 of the relay UE 112 sends a relay key response (EAP_Success, K NR_Prose , Nonce_2) to the relay UE to the network 112 (1118). The relay UE to the network 112 sends a direct security mode command (EAP_Success, Nonce_2) to the remote UE 111 (1119). The remote UE 111 can generate K NR_Prose(1120). The remote UE 111 sends a message (1121) indicating the completion of the direct security mode to the relay UE to the network 112. The remote UE 111 sends a ProSE direct link establishment acceptance (1122) to the relay UE to the network 112. The next DCR message from the UE will have the RID of PAnF in the 5GPRUK ID and the RID of the AUSF retrieved separately from the USIM (1123).

[0133] Figure 11A and Figure 11B The process shown in the flowchart of, specifically, Figure 11A 1101a in Figure 11B The process of 1122 in can be referred to as the first phase of the communication process. Figure 11B The next DCR message mentioned at 1123 in corresponds to the ProSe direct link establishment request sent by the remote UE to the relay UE in the second phase of the communication process. An example of the second phase of the communication process can be shown in Figure 12A and 12B are shown.

[0134] In the above embodiment, the UDM 115 of the remote UE 111 sends a Nudm_UEAuthenticate_GetProseAV response including the RID of PAnF to the AUSF 114 of the remote UE 111. The RID of PAnF can be pre-configured in the UDM 115.

[0135] In some other embodiments, instead of pre-configuring PAnF 116 in the UDM 115, the AUSF114 of the remote UE 111 may also dynamically select a lower load PAnF with the support of the NRF for 5G ProSe registration. The AUSF 114 obtains the RID of PAnF 116 from the NF profile of PAnF116 from the NRF, and generates a 5GPRUKID based on the RID of PAnF 116, and then sends the RID of PAnF 116 to the UE 111 together with the EAP success message.

[0136] Figure 12AA flowchart of an interaction process 1200 between devices according to some other embodiments of the present disclosure is shown. In process 1200, the remote UE 111 is registered and authenticated by the remote network (1201a). The relay UE (i.e., relay UE to network) 112 is registered and authenticated by the relay network (1201b). Model A or Model B discovery (refer to clause 6.3.1 of TS23.3.4) (1201c). The remote UE 111 sends a ProSe direct link establishment request (5GPRUK ID with PAnF's RID, Nonce_1, relay service code, RID of the AUSF) to the relay UE 112 (1202).

[0137] The relay UE 112 sends a relay key request (including 5GPRUK ID, Nonce_1, relay service code, RID of the AUSF, transaction identifier) to the AMF 113 of the relay UE 112 (1203). The AMF 113 of the relay UE 112 authorizes the relay UE 112 (1204). The AMF 113 of the relay UE 112 sends a Nausf_UEAuthenticate_ProseAuthenticate_Request (including 5GPRUK ID, Nonce_1, relay service code, SNN) to the AUSF 114 of the remote UE 111 (1205). The AUSF 114 of the remote UE 111 sends a Npanf_ProseKey_getRequest (including 5GPRUK ID, RSC) to the PAnF 116 of the remote UE 111 (1206a). The PAnF 116 of the remote UE 111 sends a Npanf_ProseKey_getResponse (including 5GPRUK) to the AUSF 114 of the remote UE 111 (1206b). The AUSF 114 of the remote UE 111 generates K NR_Prose (1207). The AUSF 114 of the remote UE 111 sends a Nausf_UEAuthentication_ProSeAuthenticateResponse (including Nonce_2, K NR_Prose , EAP_Success) to the AMF 113 of the relay UE 112 (1208). The AMF 113 of the relay UE 112 sends a relay key response (including EAP success, K NR_Prose , Nonce_2) to the relay UE 112 (1209). The relay UE112 sends a direct security mode command (including EAP success, Nonce_2) to the remote UE 111 (1210). The remote UE 111 can generate K NR_Prose(1211). The remote UE 111 sends a message (1212a) indicating the completion of the direct security mode to the relay UE 112. The remote UE 111 sends a ProSe direct link establishment acceptance (1212b) to the relay UE 112 towards the network. Figure 12A The process shown in the flowchart of, specifically, Figure 12A The processes from 1201a to 1212b in can be referred to as the second stage of the communication process, and in the whole communication process, the second stage of the communication process is a subsequent stage of the first stage of the communication process. Figure 12B Shows K according to some other embodiments of the present disclosure NR_Prose A schematic diagram of the generation of.

[0138] In Figure 12A and Figure 12B In the above process shown in the flowchart of, the 5G PRU KID contains the RID of the PAnF 116. The RID of the AUSF 114 (retrieved from the USIM) is included in the DCR message. Optionally, the home network public key identifier is also included in the DCR message. The RID of the AUSF 114, optionally using the home network public key identifier, can be used by the AMF 113 of the relay UE 112 to route the message to the correct AUSF 114 (of the remote UE 111).

[0139] In some other embodiments, in the ProSe use case, both the RID of the PAnF 116 and the RID of the AUSF 114 are included in the 5G PRU KID. In some embodiments, during the ProSe remote UE authentication and the authentication vector retrieval phase by the AUSF 114, the UDM 115 provides the RID PAnF and the RID AUSF (the RID of the PAnF 116 and the RID of the AUSF 114 entity respectively). The AUSF 114 temporarily stores the two RIDs. The RID of the PAnF 116 is included in the EAP message or 5G AKA message towards the UE 111.

[0140] In some embodiments, the remote UE 111 receives the RID of the PAnF 116 and stores it. After the RES comparison is successful, both the AUSF 114 and the remote UE 111 independently generate a 5G PRU KID with the two RIDs (the RID of the PAnF and the RID of the AUSF).

[0141] In some embodiments, when the next DCR message with a 5G PRUK ID is sent from the remote UE 111, the AMF 113 of the relay UE 112 may use the RID of the AUSF to identify the AUSF 114 of the remote UE 111. Thereafter, the AUSF 114 will retrieve the RID of the PAnF to identify the PAnF 116 of the remote UE 116.

[0142] Figure 13A and Figure 13B are taken as a whole to show a flowchart of the interaction process 1300 between devices according to some other embodiments of the present disclosure. Figure 13B is Figure 13A a continuation of. Figure 13A and Figure 13B as a whole can be used as another example of the first stage of the communication process. For the second stage of the communication process, reference can be made to Figure 12A .

[0143] In process 1300, the remote UE 111 is registered and authenticated by the remote network (1301a); the relay UE 112 is registered and authenticated by the relay network (1301b); Model A or Model B discovery (refer to clause 6.3.1 of TS23.3.4) (1301c); the remote UE 111 sends a ProSe direct link establishment request (including SUCI, Nonce_1, relay service code) to the relay UE 112 (1302); the relay UE 112 sends a relay key request (including SUCI, Nonce_1, relay service code, transaction identifier) to the AMF 113 of the relay UE 112 (1303); the AMF 113 of the relay UE 112 authorizes the relay UE 112 (1304); the AMF113 of the relay UE 112 sends a Nausf_UEAuthenticate_ProseAuthenticate_Request (including SUCI, Nonce_1, relay service code) to the AUSF 114 of the remote UE 111 (1305); the AUSF 114 of the remote UE 111 sends a Nudm_UEAuthenticate_GetProseAV request (including SUCI, relay service code, SNN) to the UDM115 of the remote UE 111 (1306a); the UDM 115 of the remote UE 111 sends a Nudm_UEAuthenticate_GetProseAV response (authentication type = primary EAP AKA, EAP AV, SUPI, RID PAnF )(1306c); the AUSF 114 of the remote UE 111 stores XRES, RID PAnF(1306d); The AUSF 114 of the remote UE 111 sends Nausf_UEAuthentication_ProSeAuthenticateResponse (authentication type = primary EAP AKA, EAP AV, RID PAnF )(1307); The AMF 113 of the relay UE 112 sends a relay authentication request to the relay UE to the network 112 (including EAP message, transaction identifier, RID PAnF )(1308); The relay UE to the network 112 sends a PC5 EAP message to the remote UE 111 (with RAND, AUTN, RID PAnF )(1309a); The remote UE 111 stores the RID PAnF (1309b); The remote UE 111 sends a PC5 EAP response message (with RES) to the relay UE to the network 112 (1309c); The relay UE to the network 112 sends a relay authentication response (EAP message, transaction identifier) to the AMF 113 of the relay UE 112 (1310); The AMF 113 of the relay UE 112 sends Nudm_UEAuthentication_ProSeAuthenticatieResponse (EAP message) to the AUSF 114 of the remote UE 111 (1311); The AUSF 114 of the remote UE 111 can verify RES using XRES (1312a); The AUSF 114 of the remote UE 111 can generate 5G PRUK ID (including RID PAnF and RID AUSF ), 5G PRUK (1312b); The remote UE 111 can generate 5G PRUK ID (including RID PAnF and RID AUSF ), 5G PRUK (1312c); The AUSF 114 of the remote UE 111 sends an Npnf_ProseKey_Register request to the PAnF 116 of the remote UE 111 (including 5G PRUK ID, 5G PRUK, RSC, SUPI) (1313); The PAnF 1116 of the remote UE 111 can store Prose_Context (including SUPI, RSC, 5G PRUK, 5G PRUK ID) (1314); The PAnF 116 of the remote UE 111 sends an Npnf_ProseKey_Register response to the AUSF 114 of the remote UE 111 (1315); The AUSF114 of the remote UE 111 generates K NR_Prose(1316); The AUSF 114 of the remote UE 111 sends a Nausf_UEAuthenticate_ProseAuthenticate response (including Nonce_2, K NR_Prose , EAP_Success) to the AMF 113 of the relay UE 112 (1317); The AMF 113 of the relay UE 112 sends a relay key response (including EAP_Success, K NR_Prose , Nonce_2) to the relay UE to network 112 (1318); The relay UE to network 112 sends a direct security mode command (EAP success, Nonce_2) to the remote UE 111 (1319); The remote UE 111 can generate K NR_Prose (1320); The remote UE 111 sends a message indicating the completion of the direct security mode to the relay UE to network 112 (1321); The remote UE 111 sends a ProSe direct link establishment acceptance to the relay UE to network 112 (1322); The next DCR message from the UE will have both the RID of the AUSF and the RID of the PAnF in the 5GPRUK ID (1323).

[0144] Figure 14A and Figure 14B are taken as a whole to show a flowchart of the interaction process 1400 between devices according to some other embodiments of the present disclosure. Figure 14B is Figure 14A a continuation of. Figure 14A and Figure 14B as a whole can be another example of the first stage of the communication process. For the second stage of the communication process, reference can be made to Figure 12A .

[0145] ​In procedure 1400, the remote UE 111 is registered and authenticated by the remote network (1401a); the relay UE 112 is registered and authenticated by the relay network (1401b); the UPU procedure executed by the UDM 115 of the remote UE 111 to provide the RID of the PAnF for the remote UE 111 (1401c). Model A or Model B discovery (refer to clause 6.3.1 of TS23.3.4) (1401d); the remote UE 111 sends a ProSe direct link establishment request (including SUCI, Nonce_1, relay service code) to the relay UE 112 (1402); the relay UE 112 sends a relay key request (including SUCI, Nonce_1, relay service code, transaction identifier) to the AMF 113 of the relay UE 112 (1403); the AMF 113 of the relay UE 112 authorizes the relay UE 112 (1404); the AMF 113 of the relay UE 112 sends a Nausf_UEAuthenticate_ProseAuthenticate_Request (including SUCI, Nonce_1, relay service code) to the AUSF 114 of the remote UE 111 (1405); the AUSF 114 of the remote UE 111 sends a Nudm_UEAuthenticate_GetProseAV request (including SUCI, relay service code, SNN) to the UDM 115 of the remote UE 111 (1406a); the UDM 115 of the remote UE 111 sends a Nudm_UEAuthenticate_GetProseAV response (authentication type = primary EAP AKA, EAP AV, SUPI, RID PAnF )(1406c); the AUSF 114 of the remote UE 111 stores XRES, RID PAnF(1406d); The AUSF 114 of the remote UE 111 sends Nausf_UEAuthentication_ProSeAuthenticateResponse (authentication type = primary EAP AKA, EAP AV) to the AMF 113 of the relay UE 112 (1407); The AMF 113 of the relay UE 112 sends a relay authentication request (including EAP message, transaction identifier) to the relay UE to the network 112 (1408); The relay UE to the network 112 sends a PC5 EAP message (with RAND, AUTN) to the remote UE 111 (1409a); The remote UE 111 can verify the AUTN and generate RES (1409b); The remote UE 111 sends a PC5 EAP response message (with RES) to the relay UE to the network 112 (1409c); The relay UE to the network 112 sends a relay authentication response (EAP message, transaction identifier) to the AMF 113 of the relay UE 112 (1410); The AMF 113 of the relay UE 112 sends a Nudm_UEAuthentication_ProSeAuthenticatie response (EAP message) to the AUSF 114 of the remote UE 111 (1411); The AUSF 114 of the remote UE 111 can verify the RES using XRES (1412a); The AUSF 114 of the remote UE 111 can generate 5GPRUK ID (including RID PAnF and RID AUSF ), 5GPRUK (1412b); The remote UE 111 can generate 5GPRUK ID (including RID PAnF and RID AUSF ), 5GPRUK (1412c); The AUSF 114 of the remote UE111 sends a Npnf_ProseKey_Register request (including 5G PRUKID, 5G PRUK, RSC, SUPI) to the PAnF 116 of the remote UE 111 (1413); The PAnF 116 of the remote UE 111 can store the Prose_ context (including SUPI, RSC, 5G PRUK, 5G PRUK ID) (1414); The PAnF 116 of the remote UE 111 sends a Npnf_ProseKey_Register response to the AUSF 114 of the remote UE 111 (1415); The AUSF 114 of the remote UE 111 generates K NR_Prose(1416); The AUSF 114 of the remote UE 111 sends a Nausf_UEAuthenticate_ProseAuthenticate response (including Nonce_2, K NR_Prose , EAP_Success) to the AMF 113 of the relay UE 112 (1417); The AMF 113 of the relay UE 112 sends a relay key response (including EAP_Success, K NR_Prose , Nonce_2) to the relay UE to network 112 (1418); The relay UE to network 112 sends a direct security mode command (EAP success, Nonce_2) to the remote UE 111 (1419); The remote UE 111 can generate K NR_Prose (1420); The remote UE 111 sends a message indicating the completion of the direct security mode to the relay UE to network 112 (1421); The remote UE111 sends a ProSe direct link establishment acceptance message to the relay UE to network 112 (1422); The next DCR message from the UE will have both the RID of the AUSF and the RID of the PAnF in the 5GPRUK ID (1423).

[0146] In some embodiments, referring to Figure 14A , if the RID of the PAnF of the remote UE 111 is considered very sensitive data, it can be sent to the UE 111 after initial registration, and if the UE 111 is capable and authorized to use the ProSe U2N relay service, via the UPU procedure (the RID provided by the AUSF that can already be used for the UPU procedure). This will prevent any attacker from obtaining the RID of the PAnF. In this case, the RID of the PAnF during the AKA challenge does not need to be clearly (unprotected) sent to the UE 111.

[0147] In some embodiments, the AUSF 114 of the remote UE 111 can dynamically select a lower load PAnF 116 for 5G ProSe registration with the support of the NRF, rather than pre-configuring the PAnF 116 in the UDM 115. In some embodiments, the AUSF 114 can select the PAnF 116 (an example of an anchoring function device) from multiple PAnF 116s, and retrieve the RID of the selected PAnF 116 from the network function (NF). In some embodiments, the AUSF 114 can obtain the RID of the PAnF 116 from the NF profile of the PAnF 116 from the NRF or the PAnF116, and generate a 5GPRUKID based on the RID of the PAnF 116, and then send the RID of the PAnF 116 together with the EAP success message to the UE 111.

[0148] Figure 15 A flowchart showing the interaction process between devices according to some other embodiments of the present disclosure is presented. In this process, with reference to Figure 15 , the UE may send a request including (SUPI / SUCI) to the AUSF, the AUSF may send a Nudm_UEAuthentication get request (including SUPI / SUCI) to the UDM, the UDM may send back to the AUSF a Nudm_UEAuthentication get response (including AV, AKMA Ind, RID of the AAnF), and the RID of the AAnF is sent by the AUSF to the UE during the primary authentication.

[0149] In this AKMA use case, similar to the Prose use case, the RID AAnF is used in the A-KID, while the RID of the AUSF is not used in the A-KID. During the primary authentication, the RID AANF is sent from the UDM to the UE.

[0150] In some embodiments, the AUSF may send a discovery request to the NRF, and the NRF sends back to the AUSF a discovery response including an AAnF instance. In some embodiments, the AUSF may also send a Naanf_AKMA_AnchorKey_Register request (including SUPI, A-KID, K AKMA ) to the AAnF. The AAnF may store the AKMA context (including SUPI, K AKMA , A-KID), and send back a Naanf_AKMA_AnchorKey_Response to the AUSF.

[0151] Similar to the Prose use case, with reference to Figure 15 , the above process in the AKMA use case may be referred to as the first stage of the communication process. In the second stage of the communication process, the UE may send an application session establishment request (including A-KID with the RID of the AAnF) to the trusted AF. The trusted AF may send back an application session establishment response to the UE.

[0152] Figure 16 A flowchart showing the interaction process between devices according to some other embodiments of the present disclosure is presented. In this process, with reference to Figure 16, the UE may send a request including (SUPI / SUCI) to the AUSF. The AUSF may send a Nudm_UEAuthentication get request (including SUPI / SUCI) to the UDM, and the UDM may send back a Nudm_UEAuthentication get response (including AV, AKMA Ind, RID of AAnF, RID of AUSF) to the AUSF. The RID of AAnF is sent by the AUSF to the UE during the primary authentication.

[0153] In this AKMA use case, similar to the Prose use case, when generating an A-KID during the AKMA process, the RID of the AUSF and the RID of the AAnF (RID AAnF ) are used in both the UE and the AUSF. RID AAnF can be sent from the AUSF to the UE during the primary authentication.

[0154] In some embodiments, the AUSF may send a discovery request to the NRF, and the NRF may send back a discovery response including an AAnF instance to the AUSF. In some embodiments, the AUSF may also send a Naanf_AKMA_AnchorKey_Register request (including SUPI, A-KID, K AKMA ) to the AAnF. The AAnF may store the AKMA context (including SUPI, K AKMA , A-KID), and send back a Naanf_AKMA_AnchorKey_Response to the AUSF.

[0155] Similar to the Prose use case, referring to Figure 16 , the above process in the AKMA use case can be referred to as the first stage of the communication process. In the second stage of the communication process, the UE may send an application session establishment request (including A-KID with the RID of the AAnF and the RID of the AUSF) to the trusted AF. The trusted AF may send back an application session establishment response to the UE.

[0156] Referring to Figure 15 or Figure 16 , the AAnF may send a Naanf_AKMA_ApplicationKey_Get_Request (including A-KID, AF_ID1) to the trusted AF. AF_ID1 is used by the AAnF to generate a key (K AF1 ). The AAnF may send a Naanf_AKMA_ApplicationKey_Get_Response (including K AF1 , K AF1 time, SUPI).

[0157] In some embodiments, a device (e.g., the terminal device 110) capable of performing any method 200 may include components for performing the respective steps of method 200. The components may be implemented in any suitable form. For example, the components may be implemented in the form of circuitry or software modules.

[0158] In some embodiments, the device includes: a component for obtaining, at the terminal device 110, a first routing indicator for an anchoring function device for the terminal device 110; a component for obtaining a second routing indicator for an authentication server function (AUSF) device for the terminal device 110; and a component for sending a communication establishment request including at least the first routing indicator and the second routing indicator.

[0159] In some embodiments, the device further includes: a component for generating a key identifier (ID) of the terminal device 110 to include the first routing indicator; and a component for sending a communication establishment request including at least the second routing indicator and the key ID.

[0160] In some embodiments, the communication establishment request further includes: a home network public key ID (PKID) to be used by the AMF device.

[0161] In some embodiments, the key ID, the second routing indicator, and the PKID are included in a subscription concealment identifier (SUCI) of the terminal device 110; and the SUCI is included in the communication establishment request.

[0162] In some embodiments, the device further includes: a component for generating a key identifier (ID) of the terminal device 110 to include the first routing indicator and the second routing indicator; and a component for sending a communication establishment request including at least the key ID.

[0163] In some embodiments, the anchoring function device is a proximity-based service (ProSe) anchoring function device; the key ID is a ProSe remote user key (PRUK) ID for 5G of the terminal device 110; the terminal device 110 is a remote terminal device; and the component for sending the communication establishment request includes: a component for sending a ProSe direct link establishment request, the ProSe direct link establishment request including: a first routing indicator to be used by the AUSF device, and a second routing indicator to be used by an access and mobility management (AMF) device of a relay terminal device.

[0164] In some embodiments, the component for obtaining the first routing indicator includes at least one of the following: a component for receiving, during an authentication process, the first routing indicator provided by an AUSF device; a component for receiving, during a User Equipment (UE) Parameter Update (UPU) process, the first routing indicator provided by a Unified Data Management (UDM) device; or a component for retrieving the first routing indicator preconfigured in the Universal Integrated Circuit Card (UICC) of the terminal device 110.

[0165] In some embodiments, the component for receiving the first routing indicator during an authentication process includes: a component for receiving, during a ProSe-specific authentication process, an Extensible Authentication Protocol (EAP) message including the first routing indicator.

[0166] In some embodiments, the component for receiving the first routing indicator during a UPU process includes: a component for receiving, during a UPU process, UPU data including the first routing indicator.

[0167] In some embodiments, the apparatus further includes a component for performing other steps in some embodiments of method 200. In some embodiments, the component includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, together with the at least one processor, cause the performance of the apparatus.

[0168] In some embodiments, an apparatus (e.g., the terminal device 110) capable of performing any method 300 may include components for performing the respective steps of method 300. The components may be implemented in any suitable form. For example, the components may be implemented in the form of circuitry or software modules.

[0169] In some embodiments, the apparatus includes: a component for receiving, at the terminal device 110, a routing indicator for an anchoring function device for the terminal device 110, the routing indicator being provided by an Authentication Server Function (AUSF) device for the terminal device 110; and a component for sending a communication establishment request including at least the routing indicator.

[0170] In some embodiments, the routing indicator is a first routing indicator, and the apparatus further includes: a component for generating a key identifier (ID) of the terminal device 110 to include the first routing indicator; and a component for sending a communication establishment request including at least the key ID.

[0171] In some embodiments, the routing indicator is a first routing indicator, and the apparatus further includes: components for generating a key identifier (ID) of the terminal device 110 to include a second routing indicator for an authentication server function (AUSF) device for the terminal device 110 and the first routing indicator; and components for sending a communication establishment request including at least the key ID.

[0172] In some embodiments, the anchoring function device is an authentication and key management for applications (AKMA) anchoring function device; the key ID is an AKMA key ID (A-KID) of the terminal device 110; and the components for sending a communication establishment request include: components for sending an application session establishment request including a routing indicator to be used by an application function device.

[0173] In some embodiments, the components for obtaining a routing indicator include at least one of the following: components for receiving a routing indicator provided by an AUSF device during an authentication process; components for receiving a routing indicator from a unified data management (UDM) device during a user equipment (UE) parameter update (UPU) process; or components for retrieving a routing indicator preconfigured in a universal integrated circuit card (UICC) of the terminal device 110.

[0174] In some embodiments, the components for receiving a routing indicator during an authentication process include: components for receiving an authentication request including a routing indicator during a primary authentication process.

[0175] In some embodiments, the components for receiving a routing indicator during a UPU process include: components for receiving UPU data including a routing indicator during a UPU process.

[0176] In some embodiments, the apparatus further includes components for performing other steps in some embodiments of method 300. In some embodiments, the components include at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, together with the at least one processor, cause the performance of the apparatus.

[0177] In some embodiments, an apparatus (e.g., the terminal device 110) capable of performing any method 400 may include components for performing the respective steps of method 400. The components may be implemented in any suitable form. For example, the components may be implemented in the form of circuitry or software modules.

[0178] In some embodiments, the apparatus includes: components for obtaining, at an Authentication Server Function (AUSF) device, a first routing indicator for an anchoring function device for a terminal device 110; and components for sending the first routing indicator to be used by the terminal device 110.

[0179] In some embodiments, the anchoring function device is a Proximity-based Service (ProSe) Anchoring Function (PAnF) device; and the key ID is the ProSe Remote User Key (PRUK) ID for 5G of the terminal device 110.

[0180] In some embodiments, the terminal device 110 is a remote terminal device, the AUSF device is the AUSF device of the remote terminal device, and the components for sending the first routing indicator include: components for sending the first routing indicator to be used for the remote terminal device.

[0181] In some embodiments, the components for sending the first routing indicator include: components for sending, during a ProSe-specific authentication process, a ProSe authentication response including the first routing indicator.

[0182] In some embodiments, the anchoring function device is an Authentication and Key Management for Applications (AKMA) Anchoring Function (AAnF) device; and the key ID is the AKMA key ID (A-KID) of the terminal device 110.

[0183] In some embodiments, the components for sending the first routing indicator include: components for sending, during a primary authentication process, an authentication response message including the first routing indicator.

[0184] In some embodiments, the AUSF device further includes components for generating a key identifier (ID) for the terminal device 110 to include one of the following: the first routing indicator; or both a second routing indicator and the first routing indicator for the AUSF device for the terminal device 110.

[0185] In some embodiments, the components for obtaining the first routing indicator include: components for selecting an anchoring function device from a plurality of anchoring function devices; and components for retrieving the routing indicator of the selected anchoring function device from a Network Function (NF).

[0186] In some embodiments, the components for retrieving the routing indicator of the selected anchoring function device from the NF include: components for retrieving the routing indicator of the selected anchoring function device from the NF profile of an anchoring function device in one of the following: the anchoring function device, or a Network Repository Function (NRF) device.

[0187] In some embodiments, the component for obtaining the first routing indicator includes: a component for receiving, from a Unified Data Management (UDM) device, the first routing indicator preconfigured in the UDM device.

[0188] In some embodiments, the apparatus further includes a component for performing other steps in some embodiments of method 400. In some embodiments, the component includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, together with the at least one processor, cause the performance of the apparatus.

[0189] In some embodiments, an apparatus (e.g., terminal device 110) capable of performing any method 500 may include components for performing the respective steps of method 500. The components may be implemented in any suitable form. For example, the components may be implemented in the form of a circuit system or a software module.

[0190] In some embodiments, the apparatus includes: a component for receiving, at an access and mobility management (AMF) device of a relay terminal device, a relay key request from the relay terminal device, the relay key request including at least a routing indicator for an authentication server function (AUSF) device; and a component for determining an AUSF device from a plurality of AUSF devices based on the routing indicator.

[0191] In some embodiments, the relay key request further includes a home network public key ID (PKID); and the component for determining an AUSF device from the plurality of AUSF devices includes: a component for determining an AUSF device from the plurality of AUSF devices based on both the routing indicator and the PKID.

[0192] In some embodiments, the apparatus further includes a component for performing other steps in some embodiments of method 500. In some embodiments, the component includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, together with the at least one processor, cause the performance of the apparatus.

[0193] In some embodiments, an apparatus (e.g., terminal device 110) capable of performing any method 300 may include components for performing the respective steps of method 600. The components may be implemented in any suitable form. For example, the components may be implemented in the form of a circuit system or a software module.

[0194] In some embodiments, the apparatus includes: means for storing, at a Unified Data Management (UDM) device, a routing indicator for an anchoring function device for a terminal device 110; and means for sending the routing indicator during a User Equipment (UE) Parameter Update (UPU) procedure.

[0195] In some embodiments, the means for sending the routing indicator during the UPU procedure includes: means for sending, during the UPU procedure, UPU data including the routing indicator.

[0196] In some embodiments, the apparatus further includes means for performing other steps in some embodiments of method 600. In some embodiments, the means includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the performance of the apparatus.

[0197] Figure 17 is a simplified block diagram of a device 1700 suitable for implementing embodiments of the present disclosure. The device 1700 may be provided to implement a communication device, such as Figure 1 the terminal device 110, a network device in the core network 120 as shown. As shown, the device 1700 includes one or more processors 1710, one or more memories 1740 coupled to the processors 1710, and one or more transmitters and / or receivers (TX / RX) 1740 coupled to the processors 1710.

[0198] The TX / RX 1740 is for two-way communication. The TX / RX 1740 has at least one antenna to facilitate communication. The communication interface may represent any interface required to communicate with other network elements.

[0199] The processor 1710 may be of any type suitable for a local technology network and, by way of non-limiting example, may include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a Digital Signal Processor (DSP), and a processor based on a multi-core processor architecture. The device 1700 may have multiple processors, such as an application-specific integrated circuit chip that is subordinate in time to a clock that synchronizes with a main processor.

[0200] The memory 1720 may include one or more non - volatile memories and one or more volatile memories. Examples of non - volatile memories include, but are not limited to, read - only memory (ROM) 1724, electrically programmable read - only memory (EPROM), flash memory, hard disk, optical disk (CD), digital video disk (DVD), and other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1722, and other volatile memories that do not persist during power loss.

[0201] The computer program 1730 includes computer - executable instructions executed by the associated processor 1710. The program 1730 may be stored in the ROM 1020. The processor 1710 may perform any suitable actions and processes by loading the program 1730 into the RAM 1020.

[0202] Embodiments of the present disclosure may be implemented by the program 1730, which enables the device 1700 to perform any process of the present disclosure as referred to Figures 2 to 16 in the description. Embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.

[0203] In some embodiments, the program 1730 may be tangibly embodied in a computer - readable medium, which may be included in the device 1700 (such as in the memory 1720) or in other storage devices accessible by the device 1700. The device 1700 may load the program 1730 from the computer - readable medium into the RAM 1722 for execution. The computer - readable medium may include any type of tangible non - volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. Figure 18 An example of a computer - readable medium 1800 in the form of a CD or DVD is shown. The computer - readable medium has the program 1730 stored thereon.

[0204] Generally, various embodiments of the present disclosure may be implemented in hardware or special - purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented using hardware, while other aspects may be implemented using firmware or software that can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, by way of non - limiting example, the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, special - purpose circuits or logic, general - purpose hardware or controllers, or other computing devices, or some combination thereof.

[0205] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, which are executed in a device on a target real or virtual processor to perform the method 1700 described above with reference to Figures 2 to 16 the method 1700 described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. In various embodiments, the functions of program modules can be combined or split among program modules as needed. Machine-executable instructions for program modules can be executed within local or distributed devices. In a distributed device, program modules can be located in both local and remote storage media.

[0206] The program code for performing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the specific functions / operations in the flowcharts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0207] In the context of the present disclosure, the computer program code or related data can be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.

[0208] The computer-readable media can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses, or any suitable combination of the foregoing. More specific examples of the computer-readable storage medium will include an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The term "non-transitory" as used herein is a limitation on the medium itself (i.e., tangible, not a signal), rather than a limitation on the persistence of data storage (e.g., RAM versus ROM).

[0209] Moreover, although the operations are described in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all of the illustrated operations be performed, to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these details should not be construed as limiting the scope of the disclosure, but rather as descriptions of specific features of particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination within a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0210] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the above specific features and acts are disclosed as example forms of implementing the claims.

Claims

1. A terminal device, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the terminal device to at least: obtain a first routing indicator for an anchoring function device of the terminal device; obtain a second routing indicator for an authentication server function (AUSF) device of the terminal device; and send a communication establishment request including at least the first routing indicator and the second routing indicator.

2. The terminal device according to claim 1, wherein the terminal device is further caused to: generate a key identifier (ID) of the terminal device to include the first routing indicator; and send the communication establishment request including at least the second routing indicator and the key ID.

3. The terminal device according to claim 2, wherein the communication establishment request further includes: The home network public key ID (PKID) to be used by the AMF device.

4. The terminal device according to claim 3, wherein: the key ID, the second routing indicator, and the PKID are included in a subscription concealment identifier (SUCI) of the terminal device; and the SUCI is included in the communication establishment request.

5. The terminal device according to claim 1, wherein the terminal device is further caused to: generate a key identifier (ID) of the terminal device to include the first routing indicator and the second routing indicator; and send the communication establishment request including at least the key ID.

6. The terminal device according to any one of claims 1 to 5, wherein: the anchoring function device is a proximity-based service (ProSe) anchoring function device; the key ID is a ProSe remote user key (PRUK) ID for 5G of the terminal device; the terminal device is a remote terminal device; and the remote terminal device is caused to send the communication establishment request by: sending a ProSe direct link establishment request, the ProSe direct link establishment request including: the first routing indicator to be used by the AUSF device, and the second routing indicator to be used by an access and mobility management (AMF) device of a relay terminal device.

7. The terminal device according to any one of claims 1 to 6, wherein the terminal device is caused to obtain the first routing indicator by at least one of the following: receiving the first routing indicator provided by the AUSF device during an authentication process; receiving the first routing indicator provided by a unified data management (UDM) device during a user equipment (UE) parameter update (UPU) process; or retrieving the first routing indicator pre-configured in a universal integrated circuit card (UICC) of the terminal device.

8. The terminal device according to claim 7, wherein the terminal device is caused to receive the first routing indicator during the authentication process by: receiving an extensible authentication protocol (EAP) message including the first routing indicator during a ProSe specific authentication process.

9. The terminal device according to claim 7, wherein the terminal device is caused to receive the first routing indicator during the UPU process by: During the UPU process, receiving UPU data including the first routing indicator.

10. A terminal device, comprising: At least one processor; And At least one memory storing instructions which, when executed by the at least one processor, cause the terminal device to at least: Receive a routing indicator for an anchoring function device for the terminal device, the routing indicator being provided by an authentication server function (AUSF) device for the terminal device; and Send a communication establishment request including at least the routing indicator.

11. The terminal device according to claim 10, wherein the routing indicator is a first routing indicator, and The terminal device is further caused to: Generate a key identifier (ID) of the terminal device to include the first routing indicator; and Send the communication establishment request including at least the key ID.

12. The terminal device according to claim 10, wherein the routing indicator is a first routing indicator, and The terminal device is further caused to: Generate a key identifier (ID) of the terminal device to include a second routing indicator for an authentication server function (AUSF) device for the terminal device, and the first routing indicator; and Send the communication establishment request including at least the key ID.

13. The terminal device according to any one of claims 10 to 12, wherein: The anchoring function device is an authentication and key management for applications (AKMA) anchoring function device; The key ID is the AKMA key ID (A-KID) of the terminal device; and The terminal device is further caused to send the communication establishment request by: Sending an application session establishment request including the routing indicator to be used by an application function device.

14. The terminal device according to any one of claims 10 to 13, wherein the terminal device is caused to obtain the routing indicator by at least one of the following: During an authentication process, receiving the routing indicator provided by the AUSF device; During a user equipment (UE) parameter update (UPU) process, receiving the routing indicator from a unified data management (UDM) device; Or Retrieving the routing indicator pre-configured in a universal integrated circuit card (UICC) of the terminal device.

15. The terminal device according to claim 14, wherein the terminal device is caused to receive the routing indicator during the authentication process by: During a primary authentication process, receiving an authentication request including the routing indicator.

16. The terminal device according to claim 14, wherein the terminal device is caused to receive the routing indicator during the UPU process by: During the UPU process, receiving UPU data including the routing indicator.

17. An Authentication Server Function (AUSF) device, comprising: At least one processor; And At least one memory storing instructions which, when executed by the at least one processor, cause the AUSF device to at least: Obtain a first routing indicator for an anchoring function device for a terminal device; and Send the first routing indicator to be used by the terminal device.

18. The AUSF device according to claim 17, wherein: The anchoring function device is a Proximity-based Services (ProSe) Anchoring Function (PAnF) device; and The key ID is the ProSe Remote User Key (PRUK) ID for 5G of the terminal device.

19. The AUSF device according to claim 18, wherein the terminal device is a remote terminal device, the AUSF device is the AUSF device of the remote terminal device, and the AUSF device is caused to send the first routing indicator by: Sending the first routing indicator to be used for the remote terminal device.

20. The AUSF device according to claim 18, wherein the terminal device is caused to send the first routing indicator by: During a ProSe-specific authentication process, sending a ProSe authentication response including the first routing indicator.

21. The AUSF device according to claim 17, wherein: The anchoring function device is an Authentication and Key Management for Applications (AKMA) Anchoring Function (AAnF) device; and The key ID is the AKMA key ID (A-KID) of the terminal device.

22. The AUSF device according to claim 21, wherein, The terminal device is caused to send the first routing indicator by: During a primary authentication process, sending an authentication response message including the first routing indicator.

23. The AUSF device according to any one of claims 17 to 22, the AUSF device is further caused to: Generate a key identifier (ID) for the terminal device to include one of the following: The first routing indicator; or Both the second routing indicator and the first routing indicator for the AUSF device for the terminal device.

24. The AUSF device according to any one of claims 17 to 23, wherein the AUSF device is caused to obtain the first routing indicator by: Selecting the anchoring function device from a plurality of anchoring function devices; and Retrieving the routing indicator of the selected anchoring function device from a Network Function (NF).

25. The AUSF device according to claim 24, wherein the AUSF device is caused to retrieve the routing indicator of the selected anchoring function device from the NF by: Retrieving the routing indicator of the selected anchoring function device from the NF profile of the anchoring function device from one of the following: The anchoring function device; or A Network Repository Function (NRF) device.

26. The AUSF device according to any one of claims 17 to 23, wherein the AUSF device is caused to obtain the first routing indicator by: Receiving, from a Unified Data Management (UDM) device, the first routing indicator pre-configured in the UDM device.

27. An Access and Mobility Management (AMF) device for a relay terminal device, comprising: At least one processor; And At least one memory storing instructions which, when executed by the at least one processor, cause the AMF device to at least: Receive, from the relay terminal device, a relay key request that includes at least a routing indicator for an Authentication Server Function (AUSF) device; And Determine the AUSF device from among a plurality of AUSF devices based on the routing indicator.

28. The AMF device according to claim 27, wherein the relay key request further includes a Home Network Public Key ID (PKID); and The AMF device is caused to determine the AUSF device from among the plurality of AUSF devices by: Determining the AUSF device from among the plurality of AUSF devices based on both the routing indicator and the PKID.

29. A Unified Data Management (UDM) device, comprising: At least one processor; And At least one memory storing instructions which, when executed by the at least one processor, cause the UDM device to at least: Store a routing indicator for an anchoring function device for a terminal device; And During a User Equipment (UE) Parameter Update (UPU) procedure, send the routing indicator to the terminal device.

30. The UDM device according to claim 29, wherein the UDM device is caused to send the routing indicator during the UPU procedure by: During the UPU procedure, sending UPU data that includes the routing indicator.

31. A method, comprising: At a terminal device, obtaining a first routing indicator for an anchoring function device for the terminal device; Obtaining a second routing indicator for an Authentication Server Function (AUSF) device for the terminal device; And Sending a communication establishment request that includes at least the first routing indicator and the second routing indicator.

32. A method, comprising: At a terminal device, receiving a routing indicator for an anchoring function device for the terminal device, the routing indicator provided by an Authentication Server Function (AUSF) device for the terminal device; And Sending a communication establishment request that includes at least the routing indicator.

33. A method, comprising: At an Authentication Server Function (AUSF) device, obtaining a first routing indicator for an anchoring function device for a terminal device; And Sending the first routing indicator to be used by the terminal device.

34. A method, comprising: At an access and mobility management (AMF) device of a relay terminal device, receive a relay key request from the relay terminal device, the relay key request including at least a routing indicator for an authentication server function (AUSF) device; And Based on the routing indicator, determine the AUSF device from a plurality of AUSF devices.

35. A method, comprising: At a unified data management (UDM) device, store a routing indicator for an anchoring function device for a terminal device; And During a user equipment (UE) parameter update (UPU) procedure, send the routing indicator to the terminal device.

36. An apparatus, comprising: Components for obtaining, at a terminal device, a first routing indicator for an anchoring function device for the terminal device; Components for obtaining a second routing indicator for an authentication server function (AUSF) device for the terminal device; And Components for sending a communication establishment request including at least the first routing indicator and the second routing indicator.

37. An apparatus, comprising: Components for receiving, at a terminal device, a routing indicator for an anchoring function device for the terminal device, the routing indicator provided by an authentication server function (AUSF) device for the terminal device; And Components for sending a communication establishment request including at least the routing indicator.

38. An apparatus, comprising: Components for obtaining, at an authentication server function (AUSF) device, a first routing indicator for an anchoring function device for a terminal device; And Components for sending the first routing indicator to be used by the terminal device.

39. An apparatus, comprising: Components for receiving, at an access and mobility management (AMF) device of a relay terminal device, a relay key request from the relay terminal device, the relay key request including at least a routing indicator for an authentication server function (AUSF) device; And Components for determining the AUSF device from a plurality of AUSF devices based on the routing indicator.

40. An apparatus, comprising: Components for storing, at a unified data management (UDM) device, a routing indicator for an anchoring function device for a terminal device; And Components for sending, during a user equipment (UE) parameter update (UPU) procedure, the routing indicator to the terminal device.

41. A non-transitory computer-readable medium, comprising program instructions that, when executed by a device, cause the device to perform at least the method according to any one of claims 31 to 35.