Apparatus, method and computer program

By managing the flow of key materials between the access point and the core network, the problem of key management during user equipment switching in the communication system is solved, ensuring the security and stability of communication, and achieving secure encryption during the rapid switching process.

CN120457734APending Publication Date: 2025-08-08ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380090213.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-01-06
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

In communication systems, it is difficult for the prior art to effectively manage the key material switching between user equipment between the access point and the core network, especially during the rapid switching process, resulting in communication security and stability problems.

Method used

A method and device are provided to ensure communication security by receiving user equipment switching instructions, determining an interface connection status, and determining an encryption key material according to the status, managing the flow of key material between the source interoperability function and the target interoperability function, including identifying the generation and provision of the primary paired master key and the secondary paired master key, ensuring communication security.

Benefits of technology

It realizes secure and stable communication between the access point and the core network, ensures effective management of key materials during the rapid switching process, and improves the security and reliability of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120457734A_ABST
    Figure CN120457734A_ABST
Patent Text Reader

Abstract

A method, apparatus and computer program are provided for causing an apparatus for a source interworking function for interfacing between a source access point and a core network to perform the following: receiving an indication that a user equipment is to switch from the source access point to a target access point; making a first determination that determines whether the source interworking function interconnects between the target access point and the core network; and determining a key material for encrypting communication between the target access point and the user equipment according to the first determination.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Examples described herein relate generally to apparatus, methods, and computer programs, and more particularly (but not limited to) to apparatus, methods, and computer programs for apparatuses. Background Art

[0002] A communication system may be viewed as a facility that enables communication sessions between two or more entities (such as communication devices, base stations, and / or other nodes) by providing carrier waves between the various entities involved in the communication path.

[0003] The communication system may be a wireless communication system. Examples of wireless systems include public land mobile networks (PLMNs) operating based on radio standards, such as those provided by the Third Generation Partnership Project (3GPP), satellite-based communication systems, and various wireless local area networks, such as wireless local area networks (WLANs). Wireless systems can typically be divided into cells and are therefore often referred to as cellular systems.

[0004] Communication systems and related equipment typically operate according to a given standard or specification, which specifies what the various entities associated with the system are allowed to do and how this should be achieved. Communication protocols and / or parameters used for connections are also typically defined. Examples of standards are the so-called 5G standards. 3GPP has published several releases (Rel) that define the operational communication protocols associated with communication networks. Currently, work is underway on Release 18 (Rel. 18). Summary of the Invention

[0005] According to a first aspect, a method for a source interworking function for interfacing between a source access point and a core network is provided, the method comprising: receiving an indication that a user equipment is to be handed over from the source access point to a target access point; making a first determination, the first determination determining whether the source interworking function is to interface between the target access point and the core network; and determining key material for encrypting communications between the target access point and the user equipment based on the first determination.

[0006] The first determination may determine that a source interworking function interfaces between a target access point and a core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user device; and using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user device.

[0007] The first determination may determine that a source interworking function is not interfacing between the target access point and the core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; identifying a target interworking function that is interfacing between the target access point and the core network; and providing the primary pairwise master key to the target interworking function.

[0008] The indication may be received from the source access point in a request for fast handover, the request for fast handover including a first query, and the method may include: providing the first query to a target interworking function; receiving a first response to the first query from the target interworking function; and forwarding the first response to the source access point.

[0009] Providing the master pairwise key to the target interworking function may include providing the master pairwise key as part of a first fast transition information element included in an Xn user device context forwarding service operation, and wherein receiving the first response to the first query may include receiving a second fast transition information element included in the Xn user device context forwarding service operation.

[0010] The first determination may determine that the source interworking function does not interface between the target access point and the core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; and providing the primary pairwise master key to an access and mobility function in the core network.

[0011] The indication may be received from the source access point in a request for fast handover, the request for fast handover including a first query, and the method may include: providing the first query to an access and mobility function; receiving a first response to the first query from the access and mobility function; and forwarding the first response to the source access point.

[0012] Providing the master pairwise key to the access and mobility function may include providing the master pairwise key as part of a first fast transition information element included in an N2 handover required service operation, and wherein receiving the first response to the first query may include receiving a second fast transition information element included in an N2 handover command service operation.

[0013] The method may include, after a user equipment is handed off from a source access point to a target access point, receiving an instruction to remove a master pair-wise master key, and removing the master pair-wise master key from local storage.

[0014] An instruction to remove the master pair-wise master key may be included in the user device context release message, and the method may include disabling an Internet Protocol security endpoint for the user device in response to receiving the instruction to remove the master pair-wise master key.

[0015] According to a second aspect, a method for a target interworking function for interfacing between a target access point and a core network is provided, the method comprising: receiving an indication that a user equipment is to be handed over from a source access point to a target access point; obtaining key material, the key material comprising a primary pairwise master key, the primary pairwise master key being used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user equipment; and causing the target secondary pairwise master key to be provided to the target access point.

[0016] The indication may be received from the target access point, and wherein obtaining the primary pairwise master key may include: making a first determination that the target interworking function is also a source interworking function that interfaces between the source access point and the core network; and identifying the primary pairwise master key as a key previously used by the target interworking function to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment.

[0017] The indication may be received from the target access point, and wherein obtaining the primary pairwise master key may include: making a first determination that the target interworking function is not interfacing between the source access point and the core network; identifying a source interworking function that is interfacing between the source access point and the core network; signaling a request for the primary pairwise master key to at least one of an access and mobility function associated with the core network; and receiving the primary pairwise master key in response to the request.

[0018] The indication may be received from the target access point in a request for fast handover, the request for fast handover including the first query, and the method may include providing the target secondary pairwise master key to the target access point in response to receiving the indication.

[0019] Receiving the master pair-wise key from the source interworking function may include receiving the master pair-wise key as part of a first fast transition information element included in an Xn-User-Equipment-Context Service operation.

[0020] The indication may be received from at least one of: an access and mobility function associated with the core network, and a source interworking function interfacing between the source access point and the core network, and wherein obtaining the master pairwise master key may include receiving the master pairwise master key with the indication.

[0021] The indication may be included in a handover request to handover the user equipment from the source access point to the target access point.

[0022] The indication may be included in a user equipment context message.

[0023] The method may include, after a user equipment is handed over from a source access point to a target access point, signaling to a source interworking function interfacing between the source access point and a core network an instruction to remove the master pairwise master key from the source interworking function.

[0024] The method may include, after causing the target secondary pairwise master key to be provided to the target access point, causing an internet protocol security endpoint to be established for traffic of the user equipment.

[0025] According to a third aspect, there is provided a method for an access and mobility function associated with a core network, the method comprising: receiving key material from a source interworking function interfacing between a source access point and the core network, the key material comprising a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user equipment; and providing the key material to a target interworking function interfacing between a target access point and the core network.

[0026] The method may comprise: receiving a request for key material from a target interworking function; signalling the request for key material to a source interworking function; and receiving the key material in response to the signalling.

[0027] According to a fourth aspect, a method for an access point is provided, the method comprising: providing a request for a fast transition to an interworking function that interfaces between the access point and a core network, the fast transition to be performed with respect to a user equipment to be switched from or to the access point, the request comprising a first fast transition information element associated with a primary key material; receiving a response to the request from the interworking function, the response comprising: a second fast transition information element associated with a secondary key material derived from the primary key material; and providing the second fast transition information element to the user equipment as part of the fast transition process.

[0028] The method may include completing a fast transition procedure with the user equipment; and signaling an indication to an interworking function that the fast transition procedure has been successfully completed, the indication including respective identifiers of the user equipment and the access point.

[0029] According to a fifth aspect, a method for a target access point is provided, the method comprising: receiving, from an interworking function interfacing between the target access point and a core network, a request indicating that a user equipment is to be switched from a source access point to a target access point using a fast transition procedure, the request comprising a first fast transition information element and secondary key material; generating, using the secondary key material and the first fast transition information, a second fast transition information element serving as a response to the first fast transition information element to enable the fast transition procedure to continue; and signaling the second fast transition element to the interworking function.

[0030] The method may include completing a fast transition procedure with the user equipment; and signaling an indication to an interworking function that the fast transition procedure has been successfully completed, the indication including respective identifiers of the user equipment and the access point.

[0031] According to a sixth aspect, an apparatus for a source interworking function for interfacing between a source access point and a core network is provided, the apparatus comprising means for: receiving an indication that a user equipment is to be handed over from the source access point to a target access point; making a first determination, the first determination determining whether the source interworking function is to interface between the target access point and the core network; and determining key material for encrypting communications between the target access point and the user equipment based on the first determination.

[0032] The first determination may determine that a source interworking function interfaces between the target access point and the core network, and the components for determining the key material may include components for: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user device; and using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user device.

[0033] The first determination may determine that the source interworking function is not interfacing between the target access point and the core network, and the means for determining the key material may include means for: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; identifying a target interworking function that is interfacing between the target access point and the core network; and providing the primary pairwise master key to the target interworking function.

[0034] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may include means for: providing the first query to a target interworking function; receiving a first response to the first query from the target interworking function; and forwarding the first response to the source access point.

[0035] The means for providing the master pairwise key to the target interworking function may include means for providing the master pairwise key as part of a first fast transition information element included in the Xn user equipment context forwarding service operation, and wherein the means for receiving the first response to the first query may include means for receiving a second fast transition information element included in the Xn user equipment context forwarding service operation.

[0036] The first determination may determine that the source interworking function does not interface between the target access point and the core network, and the means for determining the key material may include means for: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; and providing the primary pairwise master key to an access and mobility function in the core network.

[0037] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may include means for: providing the first query to an access and mobility function; receiving a first response to the first query from the access and mobility function; and forwarding the first response to the source access point.

[0038] The means for providing the master pairwise key to the access and mobility function may include means for providing the master pairwise key as part of a first fast transition information element included in an N2 handover required service operation, and wherein the means for receiving the first response to the first query may include means for receiving a second fast transition information element included in an N2 handover command service operation.

[0039] The apparatus may include means for: after a user equipment is handed off from a source access point to a target access point: receiving an instruction to remove a primary pair-wise master key; and removing the primary pair-wise master key from local storage.

[0040] The instruction to remove the master pair-wise master key may be included in the user equipment context release message, and the apparatus may include means for disabling an Internet Protocol security endpoint for the user equipment in response to receiving the instruction to remove the master pair-wise master key.

[0041] According to a seventh aspect, there is provided a component for a target interworking function for interfacing between a target access point and a core network, the apparatus comprising components for: receiving an indication that a user equipment is to be handed over from a source access point to a target access point; obtaining key material comprising a primary pairwise master key, the primary pairwise master key being used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user equipment; and causing the target secondary pairwise master key to be provided to the target access point.

[0042] The indication may be received from the target access point, and wherein the means for obtaining the primary pairwise master key may include means for: making a first determination that the target interworking function is also a source interworking function that interfaces between the source access point and the core network; and identifying the primary pairwise master key as a key previously used by the target interworking function to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment.

[0043] The indication may be received from the target access point, and wherein the means for obtaining the primary pairwise master key may include means for: making a first determination that the target interworking function is not interfacing between the source access point and the core network; identifying a source interworking function that is interfacing between the source access point and the core network; signaling a request for the primary pairwise master key to at least one of an access and mobility function associated with the core network; and receiving the primary pairwise master key in response to the request.

[0044] The indication may be received from the target access point in a request for fast handover, the request for fast handover comprising the first query, and the apparatus may include means for providing the target secondary pairwise master key to the target access point in response to receiving the indication.

[0045] The means for receiving the primary pairwise key from the source interworking function may include means for receiving the primary pairwise key as part of a first fast transition information element included in an Xn user equipment context service operation.

[0046] The indication may be received from at least one of: an access and mobility function associated with the core network, and a source interworking function interfacing between the source access point and the core network, and wherein the means for obtaining the primary pairwise master key may include means for receiving the primary pairwise master key with the indication.

[0047] The indication may be included in a handover request to handover the user equipment from the source access point to the target access point.

[0048] The indication may be included in a user equipment context message.

[0049] The apparatus may include means for signaling to a source interworking function interfacing between the source access point and a core network an instruction to remove the master pairwise master key from the source interworking function after a user equipment is handed over from the source access point to the target access point.

[0050] The apparatus may include means for causing establishment of an Internet Protocol security endpoint for traffic of the user equipment after causing the target secondary pairwise master key to be provided to the target access point.

[0051] According to an eighth aspect, there is provided an apparatus for an access and mobility function associated with a core network, the apparatus comprising means for: receiving key material from a source interworking function interfacing between a source access point and the core network, the key material comprising a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user equipment; and providing key material to a target interworking function interfacing between a target access point and the core network.

[0052] The apparatus may include means for: receiving a request for key material from a target interworking function; signaling the request for key material to a source interworking function; and receiving the key material in response to the signaling.

[0053] According to a ninth aspect, there is provided an apparatus for an access point, the apparatus comprising components for: providing a request for a fast transition to an interworking function that interfaces between the access point and a core network, the fast transition to be performed with respect to a user equipment to be switched from or to the access point, the request comprising a first fast transition information element associated with a primary key material; receiving a response to the request from the interworking function, the response comprising: a second fast transition information element associated with a secondary key material derived from the primary key material; and providing the second fast transition information element to the user equipment as part of the fast transition process.

[0054] The apparatus may include means for completing a fast transition procedure with the user equipment and signaling an indication to an interworking function that the fast transition procedure has completed successfully, the indication including respective identifiers of the user equipment and the access point.

[0055] According to a tenth aspect, there is provided an apparatus for a target access point, the apparatus comprising components for: receiving, from an interworking function interfacing between the target access point and a core network, a request indicating that a user equipment is to be switched from a source access point to the target access point using a fast transition procedure, the request comprising a first fast transition information element and secondary key material; generating, using the secondary key material and the first fast transition information, a second fast transition information element serving as a response to the first fast transition information element to enable the fast transition procedure to continue; and signaling the second fast transition element to the interworking function.

[0056] The apparatus may include means for completing a fast transition procedure with the user equipment and signaling an indication to an interworking function that the fast transition procedure has completed successfully, the indication including respective identifiers of the user equipment and the access point.

[0057] According to an eleventh aspect, an apparatus for a source interworking function for interfacing between a source access point and a core network is provided, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to: receive an indication that a user equipment is to be handed over from a source access point to a target access point; make a first determination, the first determination determining whether the source interworking function is to interface between the target access point and the core network; and determine, based on the first determination, key material for encrypting communications between the target access point and the user equipment.

[0058] The first determination may determine that a source interworking function interfaces between a target access point and a core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user device; and using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user device.

[0059] The first determination may determine that a source interworking function is not interfacing between the target access point and the core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; identifying a target interworking function that is interfacing between the target access point and the core network; and providing the primary pairwise master key to the target interworking function.

[0060] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may be caused to perform: providing the first query to a target interworking function; receiving a first response to the first query from the target interworking function; and forwarding the first response to the source access point.

[0061] Providing the master pairwise key to the target interworking function may include providing the master pairwise key as part of a first fast transition information element included in an Xn user device context forwarding service operation, and wherein receiving the first response to the first query may include receiving a second fast transition information element included in the Xn user device context forwarding service operation.

[0062] The first determination may determine that the source interworking function does not interface between the target access point and the core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; and providing the primary pairwise master key to an access and mobility function in the core network.

[0063] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may be caused to perform: providing the first query to an access and mobility function; receiving a first response to the first query from the access and mobility function; and forwarding the first response to the source access point.

[0064] Providing the master pairwise key to the access and mobility function may include providing the master pairwise key as part of a first fast transition information element included in an N2 handover required service operation, and wherein receiving the first response to the first query may include receiving a second fast transition information element included in an N2 handover command service operation.

[0065] The apparatus may be caused to perform: after a user equipment is handed over from a source access point to a target access point: receiving an instruction to remove a master pairwise master key; and removing the master pairwise master key from a local storage.

[0066] An instruction to remove the master pairwise master key may be included in the user device context release message, and the apparatus may be caused to perform, in response to receiving the instruction to remove the master pairwise master key, disabling an Internet Protocol security endpoint for the user device.

[0067] According to a twelfth aspect, there is provided an apparatus for a target interworking function for interfacing between a target access point and a core network, the apparatus comprising: at least one processor; and at least one memory comprising code, which, when executed by the at least one processor, causes the apparatus to: receive an indication that a user equipment is to be handed over from a source access point to a target access point; obtain key material comprising a primary pairwise master key, the primary pairwise master key being used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; use the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user equipment; and cause the target secondary pairwise master key to be provided to the target access point.

[0068] The indication may be received from the target access point, and wherein obtaining the primary pairwise master key may include: making a first determination that the target interworking function is also a source interworking function that interfaces between the source access point and the core network; and identifying the primary pairwise master key as a key previously used by the target interworking function to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment.

[0069] The indication may be received from the target access point, and wherein obtaining the primary pairwise master key may include: making a first determination that the target interworking function is not interfacing between the source access point and the core network; identifying a source interworking function that is interfacing between the source access point and the core network; signaling a request for the primary pairwise master key to at least one of an access and mobility function associated with the core network; and receiving the primary pairwise master key in response to the request.

[0070] The indication may be received from the target access point in a request for fast handover, the request for fast handover including the first query, and the apparatus may be caused to perform, in response to receiving the indication, providing the target secondary pairwise master key to the target access point.

[0071] Receiving the master pair-wise key from the source interworking function may include receiving the master pair-wise key as part of a first fast transition information element included in an Xn-User-Equipment-Context Service operation.

[0072] The indication may be received from at least one of: an access and mobility function associated with the core network, and a source interworking function interfacing between the source access point and the core network, and wherein obtaining the master pairwise master key may include receiving the master pairwise master key with the indication.

[0073] The indication may be included in a handover request to handover the user equipment from the source access point to the target access point.

[0074] The indication may be included in a user equipment context message.

[0075] The apparatus may be caused to perform, after a user equipment is handed over from a source access point to a target access point, signaling to a source interworking function interfacing between the source access point and a core network an instruction to remove the master pairwise master key from the source interworking function.

[0076] The apparatus may be caused to perform, after causing the target secondary pairwise master key to be provided to the target access point, causing an internet protocol security endpoint to be established for traffic of the user equipment.

[0077] According to a thirteenth aspect, there is provided an apparatus for access and mobility functions associated with a core network, the apparatus comprising: at least one processor; and at least one memory comprising code, which, when executed by the at least one processor, causes the apparatus to: receive key material from a source interworking function that interfaces between a source access point and the core network, the key material comprising a primary pairwise master key that is used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user device; and provide key material to a target interworking function that interfaces between a target access point and the core network.

[0078] The apparatus may be caused to perform: receiving a request for key material from a target interworking function; signaling the request for key material to a source interworking function; and receiving the key material in response to the signaling.

[0079] According to a fourteenth aspect, there is provided an apparatus for an access point, the apparatus comprising: at least one processor; and at least one memory comprising code, which, when executed by the at least one processor, causes the apparatus to: provide a request for a fast transition to an interworking function that interfaces between the access point and a core network, the fast transition to be performed with respect to a user equipment to be switched from or to the access point, the request comprising a first fast transition information element associated with a primary key material; receive a response to the request from the interworking function, the response comprising: a second fast transition information element associated with a secondary key material derived from the primary key material; and provide the second fast transition information element to the user equipment as part of the fast transition process.

[0080] The apparatus may be caused to perform: completing a fast transition procedure with the user equipment; and signaling an indication to an interworking function that the fast transition procedure has been successfully completed, the indication including respective identifiers of the user equipment and the access point.

[0081] According to a fifteenth aspect, a device for a target access point is provided, the device comprising: at least one processor; and at least one memory comprising code, which, when executed by the at least one processor, causes the device to perform: receiving a request from an interworking function that interfaces between the target access point and a core network indicating that a user equipment will switch from a source access point to a target access point using a fast transition procedure, the request comprising a first fast transition information element and a secondary key material; using the secondary key material and the first fast transition information to generate a second fast transition information element serving as a response to the first fast transition information element to enable the fast transition procedure to continue; and signaling the second fast transition element to the interworking function.

[0082] The apparatus may be caused to perform: completing a fast transition procedure with the user equipment; and signaling an indication to an interworking function that the fast transition procedure has been successfully completed, the indication including respective identifiers of the user equipment and the access point.

[0083] According to a sixteenth aspect, there is provided an apparatus for a source interworking function for interfacing between a source access point and a core network, the apparatus comprising: a receiving circuit system for receiving an indication that a user equipment is to be handed over from the source access point to a target access point; a determining circuit system for making a first determination, the first determination determining whether the source interworking function is to interface between the target access point and the core network; and a determining circuit system for determining key material for encrypting communications between the target access point and the user equipment based on the first determination.

[0084] The first determination may determine that a source interworking function interfaces between a target access point and a core network, and the determination circuitry for determining the key material may include: an identification circuitry for identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user device; and a usage circuitry for using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user device.

[0085] The first determination may determine that the source interworking function is not interfacing between the target access point and the core network, and the determination circuitry for determining the key material may include: identification circuitry for identifying a primary pairwise master key used to derive a source secondary pairwise master key used to encrypt communications between the source access point and the user equipment; identification circuitry for identifying a target interworking function that is interfacing between the target access point and the core network; and provision circuitry for providing the primary pairwise master key to the target interworking function.

[0086] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may include: providing circuitry for providing the first query to a target interworking function; receiving circuitry for receiving a first response to the first query from the target interworking function; and forwarding circuitry for forwarding the first response to the source access point.

[0087] The providing circuit system for providing the master pairwise key to the target interworking function may include a providing circuit system for providing the master pairwise key as part of a first fast transition information element included in the Xn user device context forwarding service operation, and wherein the receiving circuit system for receiving the first response to the first query may include a receiving circuit system for receiving a second fast transition information element included in the Xn user device context forwarding service operation.

[0088] The first determination may determine that the source interworking function does not interface between the target access point and the core network, and the determination circuitry for determining the key material may include: identification circuitry for identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; and provision circuitry for providing the primary pairwise master key to an access and mobility function in the core network.

[0089] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may include providing circuitry for providing the first query to an access and mobility function; receiving circuitry for receiving a first response to the first query from the access and mobility function; and forwarding circuitry for forwarding the first response to the source access point.

[0090] The providing circuitry for providing a master pairwise key to an access and mobility function may include providing circuitry for providing the master pairwise key as part of a first fast transition information element included in an N2 handover request service operation, and wherein the receiving circuitry for receiving a first response to a first query may include receiving circuitry for receiving a second fast transition information element included in an N2 handover command service operation.

[0091] The apparatus may include: after a user device is handed off from a source access point to a target access point: receiving circuitry for receiving an instruction to remove a master pair-wise master key; and removing circuitry for removing the master pair-wise master key from local storage.

[0092] The instruction to remove the master pairwise master key may be included in the user device context release message, and the apparatus may include disabling circuitry for disabling an internet protocol security endpoint for the user device in response to receiving the instruction to remove the master pairwise master key.

[0093] According to a seventeenth aspect, there is provided an apparatus for a target interworking function for interfacing between a target access point and a core network, the apparatus comprising: a receiving circuit system for receiving an indication that a user equipment is to switch from a source access point to a target access point; an acquisition circuit system for acquiring key material, the key material comprising a primary pairwise master key for deriving a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; a using circuit system for using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user equipment; and a causing circuit system for causing the target secondary pairwise master key to be provided to the target access point.

[0094] The indication may be received from the target access point, and wherein the acquisition circuitry for acquiring the primary pairwise master key may include: a determination circuitry for making a first determination that the target interworking function is also a source interworking function that interfaces between the source access point and the core network; and an identification circuitry for identifying the primary pairwise master key as a key previously used by the target interworking function to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment.

[0095] The indication may be received from the target access point, and wherein the acquisition circuitry for acquiring the primary pairwise master key may include: determination circuitry for making a first determination that the target interworking function is not interfacing between the source access point and the core network; identification circuitry for identifying the source interworking function interfacing between the source access point and the core network; signaling circuitry for signaling a request for the primary pairwise master key to at least one of an access and mobility function associated with the core network; and receiving circuitry for receiving the primary pairwise master key in response to the request.

[0096] The indication may be received from the target access point in a request for fast handover, the request for fast handover comprising the first query, and the apparatus may include providing circuitry for providing the target secondary pairwise master key to the target access point in response to receiving the indication.

[0097] The receiving circuitry for receiving the master pair-wise key from the slave source interworking function may include receiving circuitry for receiving the master pair-wise key as part of a first fast transition information element included in an Xn user equipment context service operation.

[0098] The indication may be received from at least one of: an access and mobility function associated with the core network, and a source interworking function interfacing between the source access point and the core network, and wherein the acquisition circuitry for acquiring the primary pairwise master key may include: a receiving circuitry for receiving the primary pairwise master key with the indication.

[0099] The indication may be included in a handover request to handover the user equipment from the source access point to the target access point.

[0100] The indication may be included in a user equipment context message.

[0101] The apparatus may include signaling circuitry for signaling to a source interworking function interfacing between the source access point and a core network an instruction to remove a master pairwise master key from the source interworking function after a user equipment is handed over from the source access point to the target access point.

[0102] The apparatus may include causing circuitry for causing establishment of an Internet Protocol security endpoint for traffic of the user equipment after causing the target secondary pairwise master key to be provided to the target access point.

[0103] According to an eighteenth aspect, there is provided an apparatus for access and mobility functions associated with a core network, the apparatus comprising: a receiving circuit system for receiving key material from a source interworking function that interfaces between a source access point and the core network, the key material comprising a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user device; and a providing circuit system for providing key material to a target interworking function that interfaces between a target access point and the core network.

[0104] The apparatus may include receiving circuitry for receiving a request for key material from a target interworking function; signaling circuitry for signaling the request for key material to a source interworking function; and receiving circuitry for receiving key material in response to the signaling.

[0105] According to the nineteenth aspect, there is provided an apparatus for an access point, the apparatus comprising: a providing circuit system for providing a request for a fast transition to an interworking function that interfaces between the access point and a core network, the fast transition to be performed with respect to a user equipment to be switched from or to the access point, the request comprising a first fast transition information element associated with a primary key material; a receiving circuit system for receiving a response to the request from the interworking function, the response comprising: a second fast transition information element associated with a secondary key material derived from the primary key material; and a providing circuit system for providing the second fast transition information element to the user equipment as part of the fast transition process.

[0106] The apparatus may include completion circuitry for completing the fast transition procedure with the user equipment and signaling circuitry for signaling an indication to an interworking function that the fast transition procedure has completed successfully, the indication including respective identifiers of the user equipment and the access point.

[0107] According to the twentieth aspect, there is provided an apparatus for a target access point, comprising: a receiving circuit system for receiving a request from an interworking function that interfaces between the target access point and a core network indicating that a user equipment is to switch from a source access point to a target access point using a fast transition procedure, the request comprising a first fast transition information element and a secondary key material; a circuit system for generating a second fast transition information element using the secondary key material and the first fast transition information to serve as a response to the first fast transition information element so that the fast transition procedure can continue to use the circuit system; and a signaling circuit system for signaling the second fast transition element to the interworking function.

[0108] The apparatus may include completion circuitry for completing the fast transition procedure with the user equipment and signaling circuitry for signaling an indication to an interworking function that the fast transition procedure has completed successfully, the indication including respective identifiers of the user equipment and the access point.

[0109] According to a twenty-first aspect, a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program instructions for causing an apparatus for a source interworking function for interfacing between a source access point and a core network to perform: receiving an indication that a user equipment is to be handed over from the source access point to a target access point; making a first determination, the first determination determining whether the source interworking function is to interface between the target access point and the core network; and determining key material for encrypting communications between the target access point and the user equipment based on the first determination.

[0110] The first determination may determine that a source interworking function interfaces between a target access point and a core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user device; and using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user device.

[0111] The first determination may determine that a source interworking function is not interfacing between the target access point and the core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; identifying a target interworking function that is interfacing between the target access point and the core network; and providing the primary pairwise master key to the target interworking function.

[0112] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may be caused to perform: providing the first query to a target interworking function; receiving a first response to the first query from the target interworking function; and forwarding the first response to the source access point.

[0113] Providing the master pairwise key to the target interworking function may include providing the master pairwise key as part of a first fast transition information element included in an Xn user device context forwarding service operation, and wherein receiving the first response to the first query may include receiving a second fast transition information element included in the Xn user device context forwarding service operation.

[0114] The first determination may determine that the source interworking function does not interface between the target access point and the core network, and determining the key material may include: identifying a primary pairwise master key used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; and providing the primary pairwise master key to an access and mobility function in the core network.

[0115] The indication may be received from a source access point in a request for fast handover, the request for fast handover including a first query, and the apparatus may be caused to perform: providing the first query to an access and mobility function; receiving a first response to the first query from the access and mobility function; and forwarding the first response to the source access point.

[0116] Providing the master pairwise key to the access and mobility function may include providing the master pairwise key as part of a first fast transition information element included in an N2 handover required service operation, and wherein receiving the first response to the first query may include receiving a second fast transition information element included in an N2 handover command service operation.

[0117] The apparatus may be caused to perform: after a user equipment is handed over from a source access point to a target access point: receiving an instruction to remove a master pairwise master key; and removing the master pairwise master key from a local storage.

[0118] An instruction to remove the master pairwise master key may be included in the user device context release message, and the apparatus may be caused to perform, in response to receiving the instruction to remove the master pairwise master key, disabling an Internet Protocol security endpoint for the user device.

[0119] According to a twenty-second aspect, a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program instructions for causing an apparatus for a target interworking function for interfacing between a target access point and a core network to: receive an indication that a user equipment will switch from a source access point to a target access point; obtain key material including a primary pairwise master key for deriving a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; use the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user equipment; and cause the target secondary pairwise master key to be provided to the target access point.

[0120] The indication may be received from the target access point, and wherein obtaining the primary pairwise master key may include: making a first determination that the target interworking function is also a source interworking function that interfaces between the source access point and the core network; and identifying the primary pairwise master key as a key previously used by the target interworking function to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment.

[0121] The indication may be received from the target access point, and wherein obtaining the primary pairwise master key may include: making a first determination that the target interworking function is not interfacing between the source access point and the core network; identifying a source interworking function that is interfacing between the source access point and the core network; signaling a request for the primary pairwise master key to at least one of an access and mobility function associated with the core network; and receiving the primary pairwise master key in response to the request.

[0122] The indication may be received from the target access point in a request for fast handover, the request for fast handover including the first query, and the apparatus may be caused to perform, in response to receiving the indication, providing the target secondary pairwise master key to the target access point.

[0123] Receiving the master pair-wise key from the source interworking function may include receiving the master pair-wise key as part of a first fast transition information element included in an Xn-User-Equipment-Context Service operation.

[0124] The indication may be received from at least one of: an access and mobility function associated with the core network, and a source interworking function interfacing between the source access point and the core network, and wherein obtaining the master pairwise master key may include receiving the master pairwise master key with the indication.

[0125] The indication may be included in a handover request to handover the user equipment from the source access point to the target access point.

[0126] The indication may be included in a user equipment context message.

[0127] The apparatus may be caused to perform, after a user equipment is handed over from a source access point to a target access point, signaling to a source interworking function interfacing between the source access point and a core network an instruction to remove the master pairwise master key from the source interworking function.

[0128] The apparatus may be caused to perform, after causing the target secondary pairwise master key to be provided to the target access point, causing an internet protocol security endpoint to be established for traffic of the user equipment.

[0129] According to the twenty-third aspect, a non-transitory computer-readable medium is provided, which includes program instructions for causing an apparatus for access and mobility functions associated with a core network to perform: receiving key material from a source interworking function that interfaces between a source access point and the core network, the key material including a primary pairwise master key, the primary pairwise master key being used to derive a source secondary pairwise master key for encrypting communications between the source access point and a user device; and providing key material to a target interworking function that interfaces between a target access point and the core network.

[0130] The apparatus may be caused to perform: receiving a request for key material from a target interworking function; signaling the request for key material to a source interworking function; and receiving the key material in response to the signaling.

[0131] According to the twenty-fourth aspect, a non-transitory computer-readable medium is provided, which includes program instructions for causing an apparatus for an access point to execute: providing a request for a fast transition to an interworking function that interfaces between the access point and a core network, the fast transition to be performed with respect to a user device to be switched from or to the access point, the request including a first fast transition information element associated with a primary key material; receiving a response to the request from the interworking function, the response including: a second fast transition information element associated with a secondary key material derived from the primary key material; and providing the second fast transition information element to the user device as part of the fast transition process.

[0132] The apparatus may be caused to perform: completing a fast transition procedure with the user equipment; and signaling an indication to an interworking function that the fast transition procedure has been successfully completed, the indication including respective identifiers of the user equipment and the access point.

[0133] According to the twenty-fifth aspect, a non-transitory computer-readable medium is provided, which includes program instructions for causing an apparatus for a target access point to execute: receiving a request from an interworking function that interfaces between the target access point and a core network indicating that a user equipment will switch from a source access point to a target access point using a fast transition process, the request including a first fast transition information element and a secondary key material; using the secondary key material and the first fast transition information to generate a second fast transition information element used as a response to the first fast transition information element to enable the fast transition process to continue; and signaling the second fast transition element to the interworking function.

[0134] The apparatus may be caused to perform: completing a fast transition procedure with the user equipment; and signaling an indication to an interworking function that the fast transition procedure has been successfully completed, the indication including respective identifiers of the user equipment and the access point.

[0135] According to a twenty-sixth aspect, there is provided a computer program product stored on a medium, which can cause an apparatus to perform any of the methods described herein.

[0136] According to a twenty-seventh aspect, there is provided an electronic device, which may comprise the apparatus as described herein.

[0137] According to a twenty-eighth aspect, there is provided a chipset, which may include an apparatus as described herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0138] Some examples will now be described, by way of illustration only, with reference to the accompanying drawings, in which:

[0139] Figure 1 shows a schematic representation of a 5G system;

[0140] Figure 2 shows a schematic representation of a network device;

[0141] Figure 3 A schematic representation of a user equipment is shown;

[0142] Figure 4 The diagram shows the network architecture;

[0143] Figure 5 The diagram shows the access architecture;

[0144] Figure 6 An example protocol stack is illustrated;

[0145] Figure 7 The signaling is illustrated;

[0146] Figure 8 The architecture is illustrated;

[0147] Figure 9 illustrates an example architecture;

[0148] Figures 10 to 15 illustrates example signaling operations; and

[0149] Figures 16 to 20 The diagram illustrates operations that may be performed by the apparatus described herein. DETAILED DESCRIPTION

[0150] In the following description of examples, certain aspects are explained with reference to devices that are generally capable of communicating via wireless cellular systems and mobile communication systems that serve such mobile communication devices. For the sake of brevity and clarity, such aspects are described below with reference to 5G wireless communication systems. However, it should be understood that such aspects are not limited to 5G wireless communication systems and, for example, may be applied to other wireless communication systems (e.g., current 6G proposals, IEEE 802.11, etc.).

[0151] Before describing the example in detail, refer to Figures 1 to 3 Briefly explain some general principles of 5G wireless communication systems.

[0152] Figure 1 A schematic representation of a 5G system (5GS) 100 is shown. The 5GS may include a user equipment (UE) 102 (which may also be referred to as a communication device or terminal), a 5G access network (AN) (which may be a 5G radio access network (RAN) or any other type of 5GAN, such as a non-3GPP interworking function (N3IWF) / trusted non-3GPP gateway function (TNGF) for non-trusted / trusted non-3GPP access, or a wired access gateway function (W-AGF) for wired access) 104, a 5G core (5GC) 106, one or more application functions (AFs) 108, and one or more data networks (DNs) 110.

[0153] Figure 2An example of a control device for a communications system is shown, for example, coupled to and / or used to control a station of the access system, such as a RAN node, e.g., a base station, gNB, a central unit of a cloud architecture, or a node of a core network, such as an MME or S-GW, a scheduling entity, such as a spectrum management entity, or a server or host, such as a device hosting an NRF, NWDAF, AMF, SMF, UDM / UDR, etc. The control device may be integrated with a node or module of the core network or RAN, or located externally thereto. In some examples, the base station includes a separate control device unit or module. In other examples, the control device may be another network element, such as a radio network controller or spectrum controller. The control device 200 may be arranged to provide control of communications within the service area of the system. The device 200 includes at least one memory 201, at least one data processing unit 202, 203, and an input / output interface 204. Via this interface, the control device may be coupled to a receiver and a transmitter of the device. The receiver and / or transmitter may be implemented as a radio front end or a remote radio head. For example, the control device 200 or the processor 201 may be configured to execute appropriate software code to provide control functionality.

[0154] Now refer to Figure 3 describing in more detail possible wireless communication devices, Figure 3 A schematic partial cross-sectional view of a communication device 300 is shown. Such a communication device is generally referred to as a user equipment (UE) or terminal. Suitable mobile communication devices can be provided by any device capable of sending and receiving radio signals. Non-limiting examples include a mobile station (MS) or mobile device, such as a mobile phone or so-called 'smartphone', a computer equipped with a wireless interface card or other wireless interface facility (such as a USB dongle), a personal data assistant (PDA) or tablet computer equipped with wireless communication capabilities, or any combination of these. Mobile communication devices can provide communication, for example, for carrying data such as voice, electronic mail (email), text messaging, multimedia, etc. Thus, users can be provided with and offered a variety of services via their communication devices. Non-limiting examples of these services include two-way or multi-way calls, data communication or multimedia services, or simply access to a data communication network system (such as the Internet). Users can also be provided with broadcast or multicast data. Non-limiting examples of content include downloads, television and radio programs, videos, announcements, various alerts, and other information.

[0155] A wireless communication device can be, for example, a mobile device (i.e., a device not fixed to a specific location) or a fixed device. A wireless device may or may not require human interaction for communication. As described herein, the term UE or "user" is used to refer to any type of wireless communication device.

[0156] The wireless device 300 may receive signals over the air or radio interface 307 via suitable means for receiving, and may transmit signals via suitable means for transmitting radio signals. Figure 3 In FIG, the transceiver arrangement is schematically represented by block 306. The transceiver arrangement 306 may be provided, for example, by a radio component and an associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the wireless device.

[0157] A wireless device is typically equipped with at least one data processing entity 301, at least one memory 302, and possibly other components 303 for software and hardware-assisted execution of the tasks it is designed to perform, including controlling access to and communications with access systems and other communication devices. The data processing, storage, and other related control means may be provided on an appropriate circuit board and / or in a chipset. This feature is denoted by reference numeral 304. The user may control the operation of the wireless device by means of a suitable user interface such as a keypad 305, voice commands, a touch-sensitive screen or touchpad, or a combination thereof. A display 308, a speaker, and a microphone may also be provided. In addition, the wireless communication device may include appropriate connectors (wired or wireless) to other devices and / or for connecting external accessories (e.g., a hands-free device).

[0158] The 3GPP Release 15 architecture supports access to the 5G system using at least one of 5G NR and non-3GPP access networks. Non-3GPP access networks are generally untrusted within the 3GPP network. Importantly, the 5GCN is defined as access-agnostic. This means that both 5G NR and non-3GPP access networks interface to the 5G core using the same user plane (N3) and control plane (N2) interfaces.

[0159] Therefore, to help enable these dual access paths, a Non-3GPP Interworking Function (N3IWF) is defined to help facilitate communications between 3GPP networks and untrusted non-3GPP accesses. The N3IWF terminates the N2 and N3 interfaces extending to and from 5GC and non-3GPP accesses.

[0160] Figure 4 The diagram illustrates the different protocol layers interfacing within a network architecture where an untrusted non-3GPP access network is used to provide UE access to the 5GC.

[0161] Figure 4A UE is shown, which includes a protocol data unit (PDU) protocol layer, a generic routing encapsulation (GRE) protocol layer, an Internet Protocol (IP) inner layer, an IP security (IPsec) layer, an IP layer, and non-3GPP layers. GRE is a tunneling protocol that can encapsulate many OSI layer 3 (i.e., network layer) protocols. The GRE protocol can be used for both point-to-point links (where two endpoints communicate with each other) and / or point-to-multipoint links (where one node can send data to many nodes).

[0162] The UE's IP and non-3GPP layers interact with the corresponding IP and non-3GPP layers of the untrusted non-3GPP access network. The IP and lower layers of the non-3GPP access network interact with the corresponding IP and lower layers of the N3IWF through the NWu interface.

[0163] The GRE layer, IP inner layer, and IPsec layer of the UE interact with the corresponding GRE layer, IP inner layer, and IPsec layer on the N3IWF through the NWu interface.

[0164] The N2IWF acting as a relay interfaces with the user plane functions using the N3 protocol stack over the N3 interface.

[0165] The user plane function, which also acts as a relay, interacts with the UPF, which acts as the session anchor for the PDU session, using the N9 protocol stack over the N9 interface. The UE's PDU layer is also connected to the corresponding PDU layer interface of the UPF, which acts as the session anchor for the PDU session.

[0166] 3GPP Release 16 takes a step towards enabling non-3GPP accesses to become trusted access networks by introducing an architecture that supports the integration of wireless local area network (WLAN) systems into the 5GS architecture using a “trust model.”

[0167] Under this trusted model, WLAN access is deployed and managed by the 5G mobile operator or a third party trusted by the 5G mobile operator. In this case, after the WLAN access is registered as trusted in the 5G system, it is trusted by both the 5G core and the 5G terminal.

[0168] The Trusted WLAN Access Network (TNAN) includes two types of network functions:

[0169] 1. A Trusted WLAN Access Point (TNAP), which terminates the UE's IEEE 802.11 protocol stack over the air access link defined in IEEE standard 802.11; and 2. A Trusted WLAN Gateway Function (TNGF), which exposes the N2 / N3 interface and enables the UE to connect to the 5G core via WLAN access technology.

[0170] This is about Figure 5 To illustrate.

[0171] Figure 5 The diagram shows that the UE is connected to the 5GC interface via the N1 interface and is connected to the TNAP interface of the TNAN via the Yt interface. The TNAN also includes a TNGF, which is connected to the 5GC interface via the N2 interface and / or the N3 interface.

[0172] Trusted and Untrusted Non-3GPP Access deploy very similar methods for interfacing with the 5GS. The main difference between the trusted and untrusted methods is that Trusted Non-3GPP allows disabling encryption on the IPsec connection between the TNGF and the UE (Y1) in the trusted access case, whereas this disabling is not allowed in the untrusted access case. Apart from the encryption decision, all frames and signaling are the same for the trusted and untrusted cases. This can be achieved by Figure 4 The protocol stack of the untrusted non-3GPP access architecture in Figure 6 This can be seen by comparing the protocol stack of the trusted non-3GPP access architecture.

[0173] Figure 6 The diagram illustrates the different protocol layers that interface in a network architecture, where a trusted non-3GPP access network is used to provide UE access to the 5GC.

[0174] Figure 6 A UE is shown, which includes a protocol data unit (PDU) protocol layer, a generic routing encapsulation (GRE) protocol layer, an Internet Protocol (IP) inner layer, an IP security (IPsec) layer, an IP layer, and a non-3GPP layer.

[0175] The IP and non-3GPP layers of the UE interact with the corresponding IP and non-3GPP layers of the TNAP. The IP and lower layers of the TNAP interact with the corresponding IP and lower layers of the TNGF through the NWt interface.

[0176] The GRE layer, IP inner layer and IPsec layer of the UE interact with the corresponding GRE layer, IP inner layer and IPsec layer on the TNGF through the NWt interface.

[0177] The TNGF used as a relay is connected to the user plane function interface through the N3 interface using the N3 protocol stack.

[0178] The user plane function, which also acts as a relay, interacts with the UPF, which acts as the session anchor for the PDU session, using the N9 protocol stack over the N9 interface. The UE's PDU layer is also connected to the corresponding PDU layer interface of the UPF, which acts as the session anchor for the PDU session.

[0179] Figure 7The diagram shows how a UE registers with the 5GC via the TNGF. This procedure is currently defined in TS 23.502, which describes how to perform the registration procedure on a trusted non-3GPP access in an Xn-based or N2-based handover scenario. (Note that in this context, Xn refers to the interface between two access nodes. Therefore, an Xn-based handover refers to a handover that includes signaling over the Xn interface. Furthermore, in this context, N2 refers to the interface between an access node and the access and mobility function. Therefore, an N2-based handover refers to a handover that includes signaling over the N2 interface.)

[0180] Figure 7 The diagram illustrates signaling that can be performed between UE 701, gNB 702, source TNAP 703, target access point 704, source TNGF 705, target N3IWF or TNGF 706 and AMF 705.

[0181] During 7001, UE 701 and source TNAP 703 exchange signaling to establish a layer 2 connection therebetween.

[0182] During 7002, UE 701 and source TNAP 703 exchange signaling to initiate the Extensible Authentication Protocol (EAP) process. EAP is a protocol for wireless networks that extends the authentication method used by Point-to-Point Protocol (PPP), a protocol often used when connecting computers to the Internet. EAP is used to encrypt the network, providing a secure way to send identification information, thereby providing network authentication.

[0183] During this signaling, a registration request is encapsulated in an EAP message that is encapsulated in a layer 2 packet over the wireless interface, the registration request including a network access identifier (NAI) to the source TNAP 703, which indicates that the UE is requesting a "5G connection" to a specific operator and / or administrative domain (e.g., a public land mobile network (PLMN)).

[0184] The provision of the NAI triggers the source TNAP 703 to send an AAA request to the source TNGF 705 during 7003. The source TNGF 705 operates as an AAA proxy. Between the source TNAP 703 and the source TNGF 705, EAP packets are signaled after being encapsulated as AAA messages.

[0185] During 7004, the source TNGF 705 forwards the registration request received from the UE 701 via the signaling of 7003 to the AMF 707. The signaling of 7004 may be included in an N2 message including N2 parameters (such as, for example, the selected PLMN identifier corresponding to the network access identifier and the establishment cause).

[0186] During 7005, the UE 701 and the source TNAP 703 exchange signaling. This signaling may include the TNGF keys (e.g., PMK-R0) created in the UE 701 and AMF 707 as part of a successful authentication. The TNAP key (PMK-R1) can be derived from PMK-R0 to establish layer 2 security between the UE and the TNAP. In the case of IEEE 802.11, a 4-way handshake may be performed during 7005 to establish a security context between the WLAN access point and the UE, which is used to protect over-the-air unicast and multicast traffic.

[0187] During 7006, UE 701 and TGNF 705 exchange signaling. During this signaling of 7006, UE 701 receives Internet Protocol (IP) configuration from TGNF 705 to establish an IP connection therebetween.

[0188] During 7007, UE 701 and TGNF 705 exchange signaling. During this signaling at 7007, TGNF 705 provides UE 701 with an IP "inner" address, a non-access stratum (NAS) IP address (NAS_IP_ADDRESS), a Transmission Control Protocol (TCP) port number, and a Differentiated Services Code Point (DSCP) value. After 7007, an IPsec SA is established between the UE and the source TNGF. This is referred to as "signaling an IPsec SA" in 3GPP and operates in tunnel mode.

[0189] During 7008, UE 701 and TGNF 705 exchange signaling. After the NWt connection (ie, the connection between the UE and the TNGF) is successfully established, the signaling includes the UE signaling to the NAS to switch the source TNGF 705.

[0190] During 7009, the source TNGF 705 exchanges signaling with the AMF 707. This signaling includes an N2 Initial Context Setup Request message. The source TNGF 705 forwards the NAS Registration Accept message received from the AMF 707 to the UE 701 via the established NWt connection. After this is established, the UE 701 can signal services to the 5GC via the source TNGF 705.

[0191] WLAN IEEE 802.11 defines a process called Fast Basic Service Set Transition (FT) through IEEE 802.11r-2009. This process enables faster handovers and shorter service interruptions. However, the deployment and integration of FT within a single TNAN, as well as intra-TNGF and inter-TNGF mobility, has never been considered.

[0192] FT allows client devices to roam quickly in environments that implement Wi-Fi Protected Access 2 (WPA2) Enterprise security by ensuring that client devices do not need to reauthenticate with a RADIUS server each time they roam from one access point to another. This is achieved by modifying the standard authentication, association, and four-way handshake processes used when a device roams (i.e., reassociates) to a new Wi-Fi access point.

[0193] Listed below are the steps performed for general authentication in Wi-Fi when a client device connects to an access point or roams from one access point to another.

[0194] 1. Authentication (client)

[0195] 2. Authentication response (access point)

[0196] 3. (Re)association request (client)

[0197] 4. (Re)Association Response (Access Point)

[0198] WPA2 Enterprise 802.1X / EAP (client, access point, and authentication server) also includes the following steps (skipped in WPA2 Personal)

[0199] 5. Four-way handshake #1 - Access point nonce passed to the client (access point)

[0200] 6. Four-way handshake #2 - Supplicant random number passed to the access point (client)

[0201] 6.5 Derivation of Encryption Keys (AP and Client Independently)

[0202] 7. Four-way handshake #3 - Verification of derived encryption keys and communication of group transient keys (access point)

[0203] 8. Four-way handshake #4 — Confirmation of successful decryption (client)

[0204] A nonce is a pseudo-random number generated for seeding cryptographic algorithms. As part of the negotiation described above, both the access point (anonce) and the client supplicant device (snonce) generate their own nonce.

[0205] The following lists the revised 802.11r steps that a client device follows when moving from one access point to another using Fast BSS Transition (FT).

[0206] 1. FT authentication; includes the PMK seed information from the original association and the requester's random number (client)

[0207] 2. FT Authentication Response - includes PMK seed information and access point random number (access point)

[0208] 2.5 Derivation of Encryption Keys (AP and Client Independently)

[0209] 3. FT reassociation request - verification of the derived encryption key (client)

[0210] 4. FT Reassociation Response – Confirmation of successful decryption and Group Transient Key (Access Point)

[0211] This FT process applies to both WPA2 Enterprise and WPA2 Personal reassociation. In both cases, the eight messages passed between the access point and the client device for authentication, association, and the four-way handshake are reduced to four messages.

[0212] Typically, FT enables a client to become "secured" after it connects to its first access point on a Wi-Fi network. This means that when the secured client roams to a new access point, information from the original association is passed to the new access point to provide the client with credentials. As a result, the new access point knows that the client has been approved by the authentication server and therefore does not need to repeat the entire 802.1X / EAP exchange again.

[0213] FT also introduces efficiencies into the process of establishing new encryption keys between new access points and client devices, which benefits both WPA2 Personal (i.e., pre-shared keys or passphrases) and WPA2 Enterprise (i.e., 802.1X or EAP). Support for 802.11r is advertised in access point beacon and probe response frames.

[0214] IEEE 802.11r-2009 introduced the fast transition capability to mitigate the long connectivity interruptions during handovers, which are primarily caused by the more extensive signaling required to reestablish the WLAN security context at the target access point after reassociation. Fast transition introduces a two-level key hierarchy that provides the ability to derive a secondary pairwise master key (referred to herein as PMK-R1) from a single primary pairwise master key (referred to herein as PMK-R0) generated during the initial EAP authentication exchange. The resulting unique secondary PMK can be distributed to each access point in the same mobility domain. This key expansion eliminates the need to re-perform EAP (re)authentication for each transition between adjacent access points. A mobility domain is a collection of basic service sets (BSSs) within the same extended service set (ESS) that support fast BSS transition between them. A mobility domain is typically limited to the WLAN access points of a single bridging domain, i.e., to the TNAP of at most a single TNGF.

[0215] Deploying the IEEE 802.11 Fast Transition method, which is widely deployed in commercial WLAN equipment and access points, can speed up WLAN handovers within a single mobility domain beyond what can be achieved through the EAP reauthentication protocol specified in RFC 6696, which is rarely implemented in commercial WLAN equipment.

[0216] The use of IEEE 802.11r Fast Transition introduces the use of a key hierarchy consisting of a first key (PMK-R0, also referred to herein as a Primary Pairwise Master Key or Primary PMK) established at the Non-Access Stratum (NAS) signaling in the TNGF during EAP authentication (instead of the Figure 7 PMK-R0 is used to establish the IPsec tunnel and replaces the previously used PMK1.

[0217] However, PMK-R0 is not used directly by the WLAN access point and the WLAN UE to ensure secure over-the-air communications. Instead, the TNGF derives an access point-specific key, PMK-R1 (also referred to herein as a secondary pairwise master key or secondary PMK), which is forwarded to the access point and used for link layer encryption between the access point and the UE. In other words, Figure 7 In the example, PMK-R0 and / or PMK-R1 can be used for communication between the UE and the source TNAP 703, PMK-R1 can be used for communication between the source TNAP and the source TNGF, and PMK-R0 can be used for communication between the source TNGF and the AMF and / or UPF.

[0218] All access points that can be served by the key distribution of NAS in TNGF build a mobility domain, which is signaled to the UE in beacon frames and probe responses to allow the UE to determine whether a fast transition is possible in the handover process.

[0219] In addition to the PMK-R0 / PMK-R1 key hierarchy (which allows each access point within a mobility domain to be provisioned with new encryption keys without having to repeat the EAP authentication process or requiring the rarely supported EAP re-authentication process), the Mobility Domain Information Element (MDIE) sent in beacons and probe responses, there is also the FTIE (Fast Transition Information Element), which is also carried in 802.11 authentication and reassociation frames to allow a 4-way handshake to be performed to generate working time keys that are appended to the authentication and reassociation frame exchanges, further reducing handover latency by an additional 4 message transmissions. An access point uses its broadcasted MDIE to advertise its inclusion in the group of APs that make up the mobility domain, its support for FT capabilities, and its FT policy information.

[0220] Two different fast transition methods are specified, depending on whether peer-to-peer communication is available between the serving access point and the target access point. These are referred to as "distribution system fast transition" and "over-the-air fast transition." These are discussed further below. The access point's MDIE can be used to signal which FT method, if any, a particular access point supports.

[0221] When peer-to-peer communication on the distribution system is possible, the UE can initiate a fast transition at the serving access point to exchange the first two messages with the target access point while remaining connected to the serving access point and able to transmit user data. User data transmission is only interrupted and briefly stalled for the reassociation request and reassociation response. This process is called a fast transition of the distribution system.

[0222] When peer-to-peer communication via the distribution system is unavailable, the UE must stop transmitting user data and perform a complete over-the-air message exchange with the target access point. Consequently, the interruption of user data transmission takes longer. This process is called an over-the-air fast transition.

[0223] Most public WLAN access networks offer a secure access mode (currently based on the WPA2 / 3 Enterprise security protocol), where the UE automatically attaches using its Subscriber Identity Module (SIM) credentials and / or its Authentication and Key Agreement (AKA) credentials. However, when IPsec security is deployed for the connection between the UE and the 5GC, link layer security on the trusted WLAN link is not required. Therefore, untrusted non-3GPP access does not enforce the use of WLAN mode access authentication (e.g., WPA2 / 3 Enterprise security protocol), but instead uses only the 5G-EAP authentication method to establish a security association for the IPsec tunnel (which can be based on the IKEv2 protocol).

[0224] Global roaming across public WLANs with this secure access model is currently being widely deployed through the OpenRoaming project of the Wireless Broadband Alliance (WBA), an organization established to reduce the operational overhead of becoming a partner in a global roaming alliance.

[0225] The WLAN technology deployed in the OpenRoaming network is the same technology that mobile operators use in their own trusted WLAN access networks. With this convergence of access technologies, it becomes feasible for mobile operators to establish global WLAN roaming capabilities for their subscribers by leveraging OpenRoaming technology, and with compatible security levels, seamless mobility across all WLAN access providers is required. Mobile operators can even signal a single global mobility domain through a virtual WLAN access network to indicate the same service set identifier (SSID) and mobility domain across multiple WLAN access providers.

[0226] Even though this deployment scenario does not formally correspond to the 3GPP trusted WLAN access architecture, the access procedures defined for trusted WLAN access can be deployed to provide an extended coverage access infrastructure consisting of several access networks belonging to different access providers, each connected to the 5GC via a corresponding dedicated N3IWF. In this case, each N3IWF behaves exactly like a TNGF and can establish wide-area WLAN access across multiple WLAN access domains under the control of the 5G mobile network operator.

[0227] Although the current 3GPP specifications only specify mobility within a single TNAN, and the use of the EAP-Re authentication protocol specified in RFC6696 can be enhanced to speed up handover, intra-TNAN mobility has not yet been considered.

[0228] Example Architecture of Handover / Mobility Procedures within TNGF Figure 8 To illustrate.

[0229] Figure 8 An example deployment is illustrated in which a UE 801 can connect to an AMF and / or UPF 802 via at least one of two different paths. The first path includes a first TNAP 803A connected to the AMF / UPF 802 via a first interworking function 804A (e.g., N3IWF or TNGF). The second path includes a second TNAP 803B connected to the AMF / UPF 802 via a second interworking function 804B (e.g., N3IWF or TNGF).

[0230] It is recognized below that a 3GPP Xn / N2 mobility procedure based on the NG-RAN inter-handover procedure is useful that does not destroy and re-establish the IPsec tunnel. This can be achieved by enabling the target TNGF to provide the UE identifier (e.g., UE MAC address) and the identifiers of the source and target access points (e.g., the respective MAC addresses of these entities) to the source TNGF. The source TNGF can then replay the EAP reauthentication root key (Rrk) and IPSec related parameters (e.g., Security Parameter Index (SPI), which is an identifier used to uniquely identify an IPSec security association and can be configured / set by the customer (e.g., for manual security associations) or by the Internet Key Exchange Daemon (IKED) (e.g., for dynamic security associations), SA list (security associations), traffic filters per SA, IPSec sequence number per SA).

[0231] Even when using the EAP-RE authentication protocol, handover between adjacent TNAPs requires a complete re-establishment of the WLAN link layer encryption keys after EAP re-authentication.

[0232] For example, the Access Gateway Function (AGF) of 5G Fixed Mobile Convergence (FMC) is responsible for serving a specific access area, and when the UE moves to another access area in the fixed network, an IP address update is required. Similarly, the current 3GPP architecture for integrating Wi-Fi with 5GC allows only sporadic coverage, and there is no seamless mobility support between adjacent Wi-Fi access areas. Each Wi-Fi access network defined by N3IWF / TNGF establishes an independent access area, and when the UE moves between them, full re-authentication and re-authorization is required. In the current 3GPP specifications, there is no mobility support available for transitions within the same N3IWF, within the same TNGF, between different N3IWFs, and between different TNGFs. In other words, the current 3GPP specifications do not include any mobility support for transitions within a TNGF, between TNGFs, within a N3IWF, and / or between N3IWFs.

[0233] The lack of mobility procedures can be problematic for time-critical applications (such as voice-based applications), which can experience severe service degradation due to the long outage caused by the re-establishment of security associations during handover. IEEE 802.11 aims to provide shorter outages through fast transitions and introduced this feature in IEEE 802.11r. However, support for fast transitions between adjacent access points belonging to different N3IWF / TNGF access zones (e.g., service areas) is not addressed in current 3GPP specifications and is not functional.

[0234] For untrusted non-3GPP networks, in current 3GPP specifications, the N3IWF uses MOBIKE, defined in IETF RFC 4555, to support a local mobility anchor within the untrusted non-3GPP access network. MOBIKE is a 5GC dual-homing solution that supports intra-N3IWF handover for the user plane, which may be required when a single N3IWF serves multiple WLAN access areas that deploy different SSIDs and do not provide link layer mobility. This enables the UE to change its IP address when moving from one area to another.

[0235] On the UE side, an adapter is introduced by establishing an operator self-service cell to simulate eNB / gNB behavior. The UE adapter provides a dedicated voice service mobility solution between the N3IWF and TNGF.

[0236] The issue of faster handover of WLAN UEs between different (eg, neighboring) TNGFs has been discussed within 3GPP and addressed by TR 23.716 Chapter 7.1.3.5.

[0237] TR 23.716, Section 7.1.3.5 proposes to avoid a full re-authentication process after switching between different TNGFs by using the EAP re-authentication protocol RFC 6696. This utilizes many round trips between the WLAN access authenticator and the authentication server.

[0238] To enable and prepare for efficient intra-TNGF mobility (i.e., handovers across different TNAPs connected to the same TNGF), the following proposes utilizing the IEEE 802.11 Fast Transition method, rather than the previously proposed EAP reauthentication protocol specified in RFC 6696, for generating new keys during handovers across adjacent TNAPs within the same TNGF. This means that the target access technology does not have to perform a full EAP authentication process with the AMF, nor does it need to re-perform the 4-way handshake to generate and activate working keys. IEEE 802.11 Fast Transition is widely supported in commercial UEs and in bridged WLAN access networks that operate using a central WLAN controller for configuration and security management.

[0239] In particular, the pairing master key (PMK) used by the target TNGF to authenticate the UE can be generated by locally generating the PMK using a previously generated master key at the EAP-Re authentication server, rather than performing a full EAP authentication message exchange. This process speeds up the establishment of the target TNGF's PMK, but still requires a full network entry signaling sequence in WLAN IEEE 802.11, such as a 4-way handshake. In other words, this mechanism still results in longer interruptions during WLAN handovers compared to non-WLAN handovers, which can severely impact the quality of time-critical services such as VoWLAN / VoWi-Fi. Thus, TR 23.716 has identified the issues and requirements involved in inter-WLAN mobility, but ultimately has not provided a mechanism that can truly meet the needs of mission-critical services.

[0240] The following content refers to the Xn interface (e.g., the interface between different access points, including the interface between two TNGFs) and / or the N2 interface (e.g., the interface between an access point (e.g., TNGF) and the Access and Mobility Function (AMF) in a 5G network) for Wi-Fi specific attributes and features to enable fast transition support and seamless handover, thereby maintaining quality of service even for demanding applications such as VoWi-Fi.

[0241] In WLAN, the handover process is triggered by the UE based on the UE's link quality measurements and assistance information received from the serving access point. Assisted WLAN handover information has been specified in IEEE 802.11k and IEEE 802.11v. The Wi-Fi Alliance requires that UEs and access points supporting fast transitions support a subset of information elements.

[0242] The UE is configured to measure and periodically report to its serving access point the WLAN access point / TNAP identities and signal quality metrics of all neighboring access points (even those belonging to different WLAN access networks). To guide handover decisions, the UE receives information about the neighborhood from the serving access point.

[0243] To enable fast transitions, all access points / TNAPs belong to the same mobility domain. This mobility domain is typically limited to access points / TNAPs served by a single interworking function. However, modern WLAN equipment allows for the configuration of multiple service set identifiers (SSIDs), each of which can be used to establish access via a dedicated WLAN access network. When mobile operators seek to support seamless mobility across WLAN access networks, they can, through business agreements with local WLAN network owners, determine that the same SSID will be supported across multiple independently owned WLAN access networks, with each SSID indicating the same mobility domain identifier.

[0244] In this configuration, the UE can assume that all visible access points (including TNAP and 3GPP access points) belong to the same access network (even across multiple interworking functions). As a result, when the UE reassociates from an access point belonging to one interworking function to a neighboring access point belonging to another interworking function, the UE can quickly transition message delivery.

[0245] To allow such configurations, it is proposed to enhance the signaling between neighboring interworking functions to provide a fast transition process in various network configurations (including across different WLAN access networks).

[0246] In order to solve at least one of the above problems, the following proposes a mechanism for enhancing the seamless mobility of standard WLAN UEs within a TNAN served by a single TNGF or across multiple TNGFs ( / N3IWFs) via an evolved 3GPP Xn / N2 mobility procedure based on an inter-NG-RAN handover procedure, without destroying and re-establishing the IPsec tunnel and without involving any EAP signaling to re-establish security measures in the WLAN link layer.

[0247] To achieve this goal, the standard IEEE 802.11 fast transition procedure is enabled within a single TNGF region or across multiple TNGFs carrying keying material to allow the target TNGF to enable the fast transition procedure and seamlessly re-establish the IPsec connection.

[0248] Compared to previously used mechanisms, the currently described technology enables faster handover between WLAN access areas served by a single or different TNGFs (e.g., between WLAN service areas) by introducing IEEE 802.11 fast transition support over existing 3GPP communication paths. The currently described technology can be consistent with the procedures for intra-TNGF mobility supported by XN or N2. The same premise assumptions apply to the configuration of WLAN access networks attached to different TNGFs. Even if the networks belong to different operating domains (e.g., different public land mobile networks (PLMNs)), seamless handover is still possible when there is an agreement between operators to coordinate WLAN operation processing.

[0249] Figure 9 The diagram illustrates a network configuration that can be used to deploy the presently described technology. Figure 9 In the example of FIG, a UE 901 is shown, which can be connected to the AMF and / or UPF 902 via at least one of two different paths. The first path includes a first TNAP 903A connected to the AMF / UPF 902 via a first interworking function 904A (e.g., N3IWF or TNGF). The second path includes a second TNAP 903B connected to the AMF / UPF 902 via a second interworking function 904B (e.g., N3IWF or TNGF). The first interworking function 904A and the second interworking function 904B may include an interface (e.g., an Xn interface) therebetween for exchanging information.

[0250] These mechanisms can be implemented by providing new signaling within the TNAN, new information elements in N2 / Xn signaling, and / or new support functions (e.g., new N3IWF and / or TNGF) in the interworking functions that interface the access network to the 5GC. This can enable the 5GCN to support rapid transitions within access areas served by multiple interworking functions, thereby establishing a common mobility domain that was previously impossible. The same message delivery changes can support the deployment of FT within a TNAN served by a single TNGF.

[0251] For example, the intercommunication function may provide the following additional functions.

[0252] First, the interworking function may generate and store PMK-R0. PMK-R0 may be derived from the PMK provided by the AMF according to the IEEE 802.11 specification.

[0253] Second, the interworking function may generate a secondary PMK-R1 and forward it to the serving access point to which the UE originally attached with full EAP authentication.

[0254] Third, the interworking function may generate and locally store a secondary PMK-R1 for other access points belonging to the local WLAN access network of the serving access point. This WLAN access network is referred to herein as the "local WLAN access network."

[0255] Fourth, in the case where the UE performs a fast transition to an access point within the local WLAN access network, the interworking function may provide at least one PMK-R1 to the local access point.

[0256] Fifth, in the case of a fast transition across WLAN access networks in the service areas of different interworking functions, interworking function message delivery can be provided for forwarding key material to the target WLAN access network (e.g., not the local WLAN access network). This can be achieved in at least one of two different ways.

[0257] For example, when the UE moves into a coverage area provided by a target access network, PMK-R0 can be provided to the interworking function of the target WLAN access network. In this case, the target interworking function can generate PMK-R1 for all access points within the target WLAN access network. This mechanism can utilize highly secure and trusted transport protocols between adjacent interworking functions (such as, for example, already defined procedures for providing Xn and / or N2 security).

[0258] As another example, a target interworking function may be authorized to identify a serving interworking function after being contacted to provide access to the 5GC for the UE. The serving interworking function may then be signaled by the target interworking function to request key material associated with the mobile UE. In this example, a directory service across multiple interworking functions may be provided that lists the current PMK-R0 storage locations for all UEs. When accessing the directory, at least one identifier associated with the UE (e.g., a media access control (MAC) address of the UE) may be used as the identifier of the UE. The at least one identifier may be an identifier of the UE that is maintained during transitions between different access points.

[0259] Sixth, the interworking functions can exchange interworking function signaling to provide additional configuration parameters related to the UE. For example, the interworking function can provide information to allow the new interworking function (e.g., TNGF or N3IWF) to issue an NGAP / N2 path switch request with the correct NGAP parameters. The correct NGAP parameters can include all parameters of the PDU session resources established on the source TNGF, as well as the radio resource management (RRM) information of the neighboring WLAN access network to provide more seamless auxiliary WLAN environment information, protect the timer used to guarantee the FT request, and during the N2-based handover using over-the-air fast transition, the N2 handover is connected to the UE, TNGF, and AMF pipeline.

[0260] For example, the handover target N3IWF / TNGF may send an N2 Path Switch Request message to the AMF to inform the AMF that the UE has moved to the new target WLAN and provide the AMF with a list of PDU sessions to be switched by the AMF. The access node tunnel information for each PDU session to be switched may be included in the N2 session management information.

[0261] In the case of intra-TNGF mobility, Xn / N2 signaling may not occur when the source and target TNGFs are the same. In this example, the messaging between the TNAP and the TNGF is the same whether FT is performed within a TNAN served by a single TNGF or across multiple TNGFs.

[0262] The following provides examples to illustrate how the presently described techniques can be implemented in different deployments. In particular, Figures 10 to 12 illustrates example signaling related to "FT over distribution system" and Figures 13 to 15 Example signaling related to "over-the-air FT" is illustrated.

[0263] The initial WLAN connection is performed with the fast transfer mode enabled. This means that after EAP-SIM / EAP-AKA authentication, a primary pairwise master key (PMK-R0) is established at the authenticator (i.e., the entity that causes the authentication of the UE, which can be the source TNGF), which provides the possibility to derive the PMK-R1 pairwise master key for distribution to other access points within the same defined mobility zone.

[0264] An authenticated UE may perform WLAN-related measurements to measure the signal quality and / or quality of experience of transmitted and / or received signals, respectively, sent and / or received via the WLAN. The UE may receive information about surrounding network neighbors from the UE's serving access point, which provides guidance to help the UE find an access point that provides a predetermined connection.

[0265] The UE may determine, based on an internal policy configured in the UE, that the current WLAN radio link provided by the serving access point does not provide a predetermined quality of service and / or quality of experience. Based on (e.g., in response to) such a determination, the UE scans the surrounding radio environment and selects a target access point for providing handover to maintain the predetermined quality of service and / or quality of experience. Specifically, the UE checks and verifies whether the target access point has the same SSID and mobility domain as the serving access point.

[0266] Depending on the WLAN infrastructure, at least two different WLAN FT (Fast Transition) modes are possible.

[0267] As mentioned above, one type of FT mode is called FT on a distribution system. This FT mode involves when it is possible for a serving access point to directly contact other access points of the same mobility domain.

[0268] Another type of FT mode is called over-the-air FT. In over-the-air FT mode, the UE directly establishes a new security context with the new target access point without requiring signaling between the serving access point and the target access point.

[0269] These two FT modes will be considered separately.

[0270] First, FT on the distribution system (DS) will be considered.

[0271] During this process, the UE sends an FT Action Request message to the target AP via the serving AP. Since the target AP may belong to a different WLAN access zone belonging to another TNGF, this message is relayed to both the serving TNGF and the target TNGF, as determined by the information provided by the UE in its FT Action Request. Since the serving TNGF is the key holder for PMK-R0, it forwards PMK-R0 to the target TNGF, allowing the target TNGF to generate and distribute PMK-R1 at the target AP.

[0272] The target access node processes the information included in the FT information element received from the source access point and responds to the source access point via the target TNGF and the source TNGF with a revised FT information element to continue the key update procedure.

[0273] After successful completion of a WLAN fast transition (which includes relocation of an IPsec tunnel across different access zones (eg, across different service areas)), PMK-R0 is removed at the source TNGF and continues to exist only at the target TNGF.

[0274] Figure 10 The diagram illustrates how to perform FT on DS across multiple TNGFs through the Xn interface to achieve fast transition of inter-TNGF WLAN on the distribution system.

[0275] Figure 10 The diagram illustrates signaling that may be performed between a UE 1001, a gNB 1002, a source access point 1003, a target access point 1004, a source TNGF 1005, a target TNGF 1006, and an AMF 1007. It is assumed that the UE is configured with a primary keying material (referred to herein as PMK-R0) and at least one secondary keying material derived from PMK-R0 (referred to herein as at least one PMK-R1), and that the source TNGF is configured with PMK-R0.

[0276] Before performing any handover, the UE performs WLAN measurements to determine whether to request a handover from the source access point 1003 to the target access point 1004. This determination may also be performed based on neighborhood information delivered from the source access point to the UE 1001, which provides information for discovering the target access point 1004.

[0277] This means that when the UE determines that the current WLAN radio link does not provide the required service level based on the UE's pre-configured internal policy, the UE 1001 scans the environment and selects a target access point that exposes the same mobility domain information element (MDIE) as the source access point to achieve the most seamless handover, thereby maintaining the required quality of service. The MDIE can be as described above. In addition to the same MDIE, the selected target access point can also indicate the same SSID as the source access point, and finally indicate the homogeneous extended service set identifier (HESSID) (if provided). The HESSID attribute includes an address (e.g., a MAC address) that identifies the homogeneous extended service set. The HESSID is a globally unique identifier that, in combination with the SSID, can be used to provide a network identity for a subscription service provider network (SSPN). This process is currently described in IEEE-802.11 Section 8.4.2.94.

[0278] Furthermore, knowing the target access point MAC address, UE 1001 is able to calculate a new PMK-R1 that is used to derive the working encryption key used to encrypt communications to target access point 1004. After making the decision to perform a handover operation, the UE proceeds to 10001.

[0279] During 10001, UE 1001 signals to source access point 1003. This signaling may be performed while UE 1001 is still connected to source access point 1003 to receive services (eg, while still connected to source access point 1003 to exchange user data).

[0280] The signaling notification 10001 may include an FT action request message that includes an identifier of the target access point 1004 (e.g., the MAC address of the target access point) and a fast transition information element (FTIE1). The fast transition process involves embedding the WLAN process's four-way handshake into the authentication and reassociation message exchanges. FTIE1 includes information elements from the first message of the four-way handshake, which are forwarded to the target access point for use in calculating the second message of the four-way handshake information to be embedded in the response frame. Similarly, FTIE2, mentioned later, may include information elements from the second message of the four-way handshake, which are forwarded to the target access point for use in calculating the third message of the four-way handshake information to be embedded in the response frame, and so on for FTIE3 and FTIE4.

[0281] The signaling of 10001 may cause the source access point 1003 to prepare for a quick transition of the UE 1001 from the source access point 1003 to the target access point 1004 by pre-establishing the required keying material.

[0282] During 10002, the source access point 1003 signals the source TNGF 1005. This signaling of 10002 may include the information included in the signaling of 10001. This signaling of 10002 may cause the source TNGF 1005 to determine whether the target access point 1004 belongs to the source TNGF 1005 (and therefore can use the standard fast transition procedure between two access points served by the same TNGF), or to determine whether the target access point 1004 belongs to another TNGF other than TNGF 1005 (and therefore desires a transition addressing another TNGF served by another TNGF).

[0283] When the target access point 1004 belongs to another TNGF than the source TNGF 1005 (which can be determined by checking the identifier of the target access point provided in the signaling of 10002 ), the source TNGF 1005 proceeds to 10003 .

[0284] During 10003, the source TNGF determines (eg, identifies) the target TNGF 1006 via the target access point identifier (eg, via the target MAC address). The source TNGF 1005 may determine the target TNGF using any mechanism.

[0285] For example, the source TNGF 1005 may determine the target TGNF 1006 using a pre-configured (in the source TNGF 1005 ) access point list that serves neighboring TNGFs that are adjacent to the source TNGF 1005 .

[0286] As another example, the source TNGF may use a public database and / or registry (e.g., an NRF) to perform this determination. As an example, each TNGF (including the target TNGF) may register its address (e.g., its Xn address) with the NRF, which has a corresponding list of associated MAC addresses of the access points served by the TNGF. This registration may be performed using, for example, the Nnrf_NFManagement_NFRegister service operation (defined in 3GPP TS 23.502). This determination may be performed by the source TNGF by performing, for example, the Nnrf_NFDiscovery_Request operation defined in 3GPP TS 23.502 to discover the target TNGF and providing the target access point MAC address as an input parameter.

[0287] During 10004, the source TNGF 1005 signals the target TNGF 1006 determined during 10003. The signaling of 10004 may include the information received during 10002 (e.g., FTIE1 received during 10002). The signaling of 10004 may include a global PMK (e.g., PMK-R0). The signaling of 10004 may be performed using, for example, an Xn UE Context Fwd Message service operation.

[0288] During 10005, the target TNGF 1006 signals the target access point 1004. The signaling of 10005 may be performed after the target TNGF 1006 derives PMK-R1 from the received PMK-R0. The signaling may be performed based on information received from the source TNGF during 10004. The signaling may notify the target access point 1004 of the upcoming handover. The signaling may include PMK-R1. The signaling may include an identifier of the UE 1001 being handed over. The signaling may include respective identifiers (e.g., respective MAC identifiers) of the target access point 1004 and the source access point 1003. The signaling of 10005 may be performed using an FT_Indication message.

[0289] Using the information received from the target TNGF 1006 during 10005, the target access point uses the received PMK-R1 to calculate a working key (e.g., a key used to encrypt communications between the UE and the target access point) and the contents of a final FTIE (labeled herein as FTIE2). During 10006, this FTIE2 is signaled from the target access point 1004 to the target TNGF 1006. The FTIE2 may be as discussed above with respect to FTIE2. The signaling of 10006 may include an identifier of the UE 1001 and respective identifiers of the target access point and the source access point. The signaling of 10006 may be provided via an FT Ack message.

[0290] During 10007, the target TGNF 1006 signals to the source TNGF 1005. The signaling may include FTIE2. The signaling may be included in an Xn UE Context Fwd message.

[0291] During 10008, the source TGNF 1005 signals to the source access point 1003. The signaling may include FTIE2. The signaling may include an identifier of the UE. The signaling may include respective identifiers of the source access point and the target access point.

[0292] During 10009, source access point 1003 signals UE 1001. The signaling may include a response to the signaling of 10001. The signaling may include an FT action response service operation. The signaling may be provided to UE 1001 over the air when the UE is still able to perform user data transmission to the 5GC via the source access point. The signaling of 10009 may include FTIE2.

[0293] After receiving the preparation information required to perform the final steps of the fast transition, during 10010 , the UE 1001 adjusts its radio parameters for transmission and / or reception and issues an IEEE 802.11 reassociation request message to the target access point 1004 .

[0294] During 10011, the target access point 1004 responds to the signaling of 10010. This response can be performed based on (e.g., using) information already available at the target access point. This means that the target access point 1004 can immediately respond to the request of 10010 with a corresponding IEEE 802 reassociation response message to end the transition and enable the UE to continue exchanging user data with the 5GC via the target access node.

[0295] During 10012, the target access point 1004 signals the target TGNF 1006, which may be performed simultaneously or serially with the signaling 10011. The signaling 10012 may indicate that the FT procedure between the target access point 1004 and the UE 1001 has successfully completed. The signaling 10012 may include an identifier of the UE 1001. The signaling 10012 may include the respective identifiers of the source access point 1003 and the target access point 1004. The signaling 10012 may cause the target TNGF 1006 to activate any IPsec endpoints for the transitioned UE that have been prepared at the target TNGF since the source TNGF indicated the handover and the provision of the necessary keying material.

[0296] During 10013, target TNGF 1006 and UE 1001 exchange signaling. This signaling involves establishing an IPSec endpoint at the target TNGF. For example, this signaling may result in the continuation of UE 1001's previous IP connection using the previous IP context used by UE 1001 with source TNGF 1005. Furthermore, this signaling may result in the use of an IPSec tunnel between UE 1001 and target TNGF 1006, which is still based on the use of a PMK-R0 security association.

[0297] During 10014, the target TNGF 1006 signals the source TNGF 1005. The signaling may indicate that the handover operation of the UE from the source access point 1003 to the target access point 1004 has been successfully completed.

[0298] During 10015, based on the signaling notification of 10014, the source TNGF 1005 signals the target TNGF 1006 to indicate that the source TNGF 1005 has disabled the IPSec endpoint for the UE at the source TNGF 1005, the source TNGF 1005 has removed any local storage of PMK-R0 at the source TNGF 1005, and forwarded the UE's data (e.g., user plane data) to the target TNGF 1006, which data was not previously forwarded by the source TNGF 1005 to the target TNTF 1006.

[0299] During 10016, the target TNGF 1006 signals to the AMF 1007. The signaling may include a path switch request, which is used to cause the data of the UE 1001 to be forwarded to the target TNGF 1006 instead of the source TNGF 1006.

[0300] During 10017, the target TNGF 1006 and the AMF 1007 exchange signaling to cause the packet data unit (PDU) session of the UE 1001 to be updated, thereby rendering the TNGF 1006 as the endpoint of the user data of the UE 1001. This can be performed according to the 3GPP standard (for example, according to 3GPP TS 23.502).

[0301] During 10018, the AMF 1007 signals the target TNGF 1006 to indicate that the path switch request has been successfully completed.

[0302] During 10019 , the target TNGF 1006 signals the source TNGF 1005 to indicate that the source TNGF 1005 may release any resources currently reserved by the source TNGF 1005 for use by the UE 1001 . The source TNGF 1005 may perform this release based on receipt of the signaling of 10019 .

[0303] Figure 11 Another example of FT on DS is illustrated. Figure 11 The example involves support for providing inter-TNGF WLAN FT on DS across multiple TNGFs over the N2 interface.

[0304] Figure 11 The diagram illustrates signaling that can be performed between a UE 1101, a gNB 1102, a source access point 1103, a target access point 1104, a source TNGF 1105, a target TNGF 1106, an AMF 1107, and a 5GC network function 1108 (e.g., an SMF and / or UPF). It is assumed that the UE is configured with PMK-R0 and at least one PMK-R1 derived from PMK-R0, and that the source TNGF is configured with PMK-R0.

[0305] Before performing any handover, the UE performs WLAN measurements to determine whether to request a handover from the source access point 1103 to the target access point 1104. This determination may also be made based on neighborhood information delivered from the source access point to the UE 1101, which provides information for discovering the target access point 1104.

[0306] This means that when the UE determines that the current WLAN radio link does not provide the required service level based on the UE's pre-configured internal policy, the UE 1101 scans the environment and selects a target access point that exposes the same mobility domain information element (MDIE) as the source access point to achieve the most seamless handover, thereby maintaining the required quality of service. In addition to the same MDIE, the selected target access point may also indicate the same SSID as the source access point, and ultimately indicate the HESSID (if provided).

[0307] Furthermore, knowing the target access point MAC address, UE 1101 is able to calculate a new PMK-R1 that is used to derive a working encryption key for encrypting communications with target access point 1104. After making the decision to perform a handover operation, the UE proceeds to 11001.

[0308] During 11001, UE 1101 signals to source access point 1103. This signaling may be performed while UE 1101 is still connected to source access point 1103 to receive services (eg, while still connected to source access point 1103 to exchange user data).

[0309] The signaling of 11001 may include an FT action request message including an identifier of the target access point 1104 (e.g., the MAC address of the target access point) and a fast transition information element (FTIE1), which may be as described above. This signaling may cause the source access point 1103 to prepare for the fast transition of the UE 1101 from the source access point 1103 to the target access point 1104 by pre-establishing the required key material.

[0310] During 11002, the source access point 1103 signals the source TNGF 1105. The signaling of 11002 may include the information included in the signaling of 11001. The signaling of 11002 may cause the source TNGF 1105 to determine whether the target access point 1104 belongs to the source TNGF 1105 (and therefore can use the standard fast transition procedure between two access points served by the same TNGF), or to determine whether the target access point 1104 belongs to another TNGF other than TNGF 1105 (and therefore desires a transition addressing another TNGF served by another TNGF).

[0311] When the target access point 1104 belongs to another TNGF than the source TNGF 1105 (which can be determined by checking the identifier of the target access point provided in the signaling of 11002 ), the source TNGF 1105 proceeds to 11003 .

[0312] During 11003, the source TNGF determines (eg, identifies) the target TNGF 1106 via the target access point identifier (eg, via the target MAC address). The source TNGF 1105 may determine the target TNGF using any mechanism.

[0313] For example, the source TNGF 1105 may determine the target TGNF 1106 using a pre-configured (in the source TNGF 1105 ) access point list that serves neighboring TNGFs that are adjacent to the source TNGF 1105 .

[0314] As another example, the source TNGF may use a public database and / or registry (e.g., an NRF) to perform this determination. As an example, each TNGF (including the target TNGF) may register its address (e.g., its Xn address) with the NRF, which has a corresponding list of associated MAC addresses of the access points served by the TNGF. This registration may be performed using, for example, the Nnrf_NFManagement_NFRegister service operation (defined in 3GPP TS 23.502). This determination may be performed by the source TNGF by performing, for example, the Nnrf_NFDiscovery_Request operation defined in 3GPP TS 23.502 to discover the target TNGF and providing the target access point MAC address as an input parameter.

[0315] During 11004, the source TNGF 1105 signals to the AMF 1107 that a handover to the target TNGF 1106 is to be performed. This signaling may include the FTIE1 received during 11002. This signaling may include the PMK-R0. In other words, during 11004, the source TNGF provides the AMF 1107 with the fast transition information provided via the FT_Request message (FTIE1), as well as the identity of the target TNGF and the global PMK (PMK-R0). This signaling may be included in an N2 Handover Required Request service operation.

[0316] During 11005, the AMF 1107 and the user plane entity 1108 exchange signaling to prepare the UE for handover from the source TNGF 1105 to the target TNGF 1106. As part of this preparation (which may largely conform to the handover preparation described in 3GPP standards, such as 3GPP TS 23.502 Figure 4 .9.1.3.2-1 steps 1 to 12), a second FTIE (e.g., as described above regarding Figure 10 FTIE2) and PMK-R0 as described.

[0317] During 11006, the AMF 1107 signals the target TNGF 1106. The signaling may include a handover request for requesting the UE 1101 to handover from the source TNGF 1105 to the target TNGF 1106. The signaling may include, for example, FTIE1 and PMK-R0. The signaling may be included in a handover request service operation.

[0318] During 11007, the target TNGF 1106 signals the target access point 1104. This signaling may be performed based on the information received from the AMF during 10006. This signaling may inform the target access point 1104 of the upcoming handover. This signaling may include PMK-R1, which is derived by the target TNGF 1106 using the received PMK-R0. This signaling of 11007 may include FTIE1. This signaling may include an identifier of the UE 1101 being handed over. This signaling may include respective identifiers (e.g., respective MAC identifiers) of the target access point and the source access point 1103. The signaling of 11007 may be performed using an FT_Indication message.

[0319] Using the information received from target TNGF 1106 during 11007, the target access point uses the received PMK-R1 to calculate the working key for communicating with UE 1101 and the contents of the resulting FTIE (labeled herein as FTIE2). During 11008, this FTIE2 is signaled from target access point 1104 to target TNGF 1106. The signaling of 10008 may include an identifier of UE 1101 and corresponding identifiers of the target access point and the source access point. The signaling of 10006 may be provided via an FT Acknowledge message.

[0320] During 11009, the target TGNF 1106 signals to the AMF 1107. This signaling may be a response to the signaling of 11006. The signaling may include FTIE2. The signaling may be included in the N2 Handover Request Acknowledgement. After receiving and forwarding the FTIE2 container during 11008 and 11009, the target TGNF initiates and enables an IPsec endpoint for the UE based on the configuration information received from the AMF 1107 during 11006.

[0321] 111010 to 11017 relate to the handover of the UE from the source TNGF 1105 to the target TNGF 1106. At least a portion of these operations may include 3GPP TS 23.502 Figure 4.9.1.3.3-1 Features of the operations in steps 6 to 15. Although not explicitly shown or discussed in the signaling below, the handover execution includes interactions with the SMF and UPF and a UE context release command from the AMF 1107 to the source TNGF 1105.

[0322] During 11010, the AMF 1107 signals the source TNGF 1105. The signaling may include a handover command. The signaling may include FTIE2. The signaling may be signaled using the N2 interface (e.g., using an N2 handover command message).

[0323] During 11011, the source TNGF 1105 signals to the source access point 1103. The signaling may be a response to the signaling of 11002. The signaling of 11011 may include FTIE2. The signaling of 11011 may include an identifier of the UE. The signaling may include respective identifiers of the source access point and the target access point.

[0324] During 11012, source access point 1103 signals UE 1101. The signaling may include a response to the signaling of 11001. The signaling may include an FT action response service operation. The signaling may be provided to UE 1101 over the air when the UE is still able to perform user data transmission to the 5GC via the source access point.

[0325] After receiving the preparation information required to perform the final steps of the fast transition during 11012 , the UE 1001 adjusts its radio parameters for transmission and / or reception and issues an IEEE 802.11 reassociation request message to the target access point 1104 during 11013 .

[0326] During 11014, the target access point 1104 responds to the signaling of 11013. This response can be performed based on (e.g., using) information already available at the target access point. This means that the target access point 1104 can immediately respond to the request of 11013 with a corresponding IEEE 802 reassociation response message to end the transition and enable the UE to continue exchanging user data with the 5GC via the target access point.

[0327] During 11015, target access point 1104 signals target TGNF 1106, which may be performed simultaneously or serially with the signaling at 11013. The signaling at 11015 may indicate that the FT procedure between target access point 1104 and UE 1101 has successfully completed. The signaling at 11015 may include an identifier for UE 1101. The signaling at 11015 may include the respective identifiers for source access point 11003 and target access point 1104. The signaling at 11015 may cause target TNGF 1106 to activate any IPsec endpoints for the transitioned UE that have been prepared at the target TNGF since the source TNGF indicated the handover and the provision of the necessary keying material.

[0328] During 11016, the target TNGF 1106 signals the AMF 1107 to inform the AMF 1107 that handover of the UE to the target access point 1104 has been initiated.

[0329] During 11017, target TNGF 1106 and UE 1101 exchange signaling. This signaling involves establishing an IPSec endpoint at the target TNGF. For example, this signaling may cause UE 1101's previous IP connection to continue using the previous IP context used by UE 1101 with source TNGF 1105. Furthermore, this signaling may cause the use of an IPSec tunnel between UE 1101 and target TNGF 1106, which is still based on the use of a PMK-R0 security association.

[0330] During 11018, the target AMF 1107 signals the source TNGF 1105. This signaling may indicate that the handover operation of the UE from the source access point 1103 to the target access point 1104 has been successfully completed.

[0331] During 11019 , based on the signaling of 11018 , the source TNGF 1105 signals to the AMF 1107 to indicate that the source TNGF 1105 has disabled the IPSec endpoint for the UE at the source TNGF 1105 and that the source TNGF 1105 has removed any local storage of PMK-R0 at the source TNGF 1105 .

[0332] Figure 12 Another example of FT on DS is illustrated. Figure 12 This example involves intra-TNGF WLAN FT on a single intra-TNGF DS.

[0333] Figure 12The diagram illustrates signaling that may be performed between a UE 1201, a gNB 1202, a source access point 1103, a target access point 1204, and a source TNGF 1205. It is assumed that the UE is configured with PMK-R0 and at least one PMK-R1 derived from PMK-R0, and that the source TNGF is configured with PMK-R0.

[0334] Before performing any handover, the UE performs WLAN measurements to determine whether to request a handover from the source access point 1203 to the target access point 1204. This determination may also be made based on neighborhood information delivered from the source access point to the UE 1201, which provides information for discovering the target access point 1204.

[0335] This means that when the UE determines based on the UE's pre-configured internal policy that the current WLAN radio link does not provide the required service level, the UE 1201 scans the environment and selects a target access point that exposes the same mobility domain information element (MDIE) as the source access point to achieve the most seamless handover, thereby maintaining the required quality of service. In addition to the same MDIE, the selected target access point may also indicate the same SSID as the source access point, and ultimately indicate the HESSID (if provided).

[0336] Furthermore, knowing the target access point MAC address, UE 1201 is able to calculate a new PMK-R1 that is used to derive the working encryption key used to encrypt communications to target access point 1204. After making the decision to perform a handover operation, the UE proceeds to 12001.

[0337] During 12001, UE 1201 signals to source access point 1203. This signaling may be performed while UE 1201 is still connected to source access point 1203 to receive services (eg, while still connected to source access point 1203 to exchange user data).

[0338] The signaling of 12001 may include an FT Action Request message including an identifier of the target access point 1204 (e.g., the MAC address of the target access point) and a Fast Transition Information Element (FTIE1). This signaling may cause the source access point 1203 to prepare for the fast transition of the UE 1201 from the source access point 1203 to the target access point 1204 by pre-establishing the required key material.

[0339] During 12002, the source access point 1203 signals the source TNGF 1205. The signaling of 12002 may include the information included in the signaling of 12001. The signaling of 12002 may cause the source TNGF to determine whether the target access point 1204 belongs to the source TNGF 1205 (and therefore can use the standard fast transition procedure between two access points served by the same TNGF), or to determine whether the target access point 1204 belongs to another TNGF other than TNGF 1205 (and therefore desires a transition addressing another TNGF served by another TNGF).

[0340] During 12003, the source TNGF determines (e.g., identifies) the target TNGF via the target access point identifier (e.g., via the target MAC address). In the present case, the source TNGF is also the target TNGF (i.e., the TNGF that manages access to the 5GC by the target access point 1204).

[0341] For example, the source TNGF 1205 may determine the target TGNF using a pre-configured (in the source TNGF 1205 ) access point list that serves TNGFs neighboring the source TNGF 1205 .

[0342] As another example, the source TNGF may use a public database and / or registry (e.g., an NRF) to perform this determination. As an example, each TNGF (including the target TNGF) may register its address (e.g., its Xn address) with the NRF, which has a corresponding list of associated MAC addresses of the access points served by the TNGF. This registration may be performed using, for example, the Nnrf_NFManagement_NFRegister service operation (defined in 3GPP TS 23.502). This determination may be performed by the source TNGF by performing, for example, the Nnrf_NFDiscovery_Request operation defined in 3GPP TS 23.502 to discover the target TNGF and providing the target access point MAC address as an input parameter.

[0343] During 12004, the source TNGF 1205 signals the target access point 1204. The signaling may inform the target access point 1204 of the upcoming handover. The signaling may include PMK-R1. The signaling may include an identifier of the UE 1201 being handed over. The signaling may include respective identifiers (e.g., respective MAC identifiers) of the target access point and the source access point 1203. The signaling of 12004 may be performed using an FT_Indication message.

[0344] Using the information received from the source TNGF 1205 during 12004, the target access point uses the received PMK-R1 to derive the working key and the contents of the final FTIE (labeled herein as FTIE2). During 12005, this FTIE2 is signaled from the target access point 1204 to the source TNGF 1205. The signaling of 12005 may include an identifier of the UE 1201 and the respective identifiers of the target access point and the source access point. The signaling of 12005 may be provided via an FT Ack message.

[0345] During 12006, the source TGNF 1205 signals to the source access point 1203. The signaling may include FTIE2. The signaling may include the identifier of the UE. The signaling may include the respective identifiers of the source access point and the target access point.

[0346] During 12007, source access point 1203 signals UE 1201. The signaling may include a response to the signaling of 12001. The signaling may include an FT action response service operation. The signaling may be provided to UE 1201 over the air while the UE is still able to perform user data transmission to the 5GC via the source access point.

[0347] After receiving the preparation information required to perform the final steps of the fast transition, during 12008 , UE 1201 adjusts its radio parameters for transmission and / or reception and issues an IEEE 802.11 reassociation request message to the target access point 1204 .

[0348] During 12009, the target access point 1204 responds to the signaling of 12008. This response can be performed based on (e.g., using) information already available at the target access point. This means that the target access point 1204 can immediately respond to the request of 12008 with a corresponding IEEE 802 reassociation response message to end the transition and enable the UE to continue exchanging user data with the 5GC via the target access node.

[0349] During 12010, target access point 1204 signals source TGNF 1205, which may be performed simultaneously or serially with the signaling at 12009. The signaling at 12010 may indicate that the FT procedure between target access point 1204 and UE 1201 has successfully completed. The signaling at 12010 may include an identifier of UE 1201. The signaling at 12010 may include respective identifiers of source access point 1203 and target access point 1204.

[0350] During 12011, source TNGF 1205 and UE 1201 exchange signaling. This signaling involves establishing an IPSec endpoint at the target TNGF. For example, this signaling may cause UE 1201's previous IP connection to continue using the previous IP context used by UE 1201 with source TNGF 1205. Furthermore, this signaling may cause the use of an IPSec tunnel between UE 1201 and source TNGF 1205, which is still based on the use of a PMK-R0 security association.

[0351] Since the TNGF has not changed from the source TNGF to another TNGF, entities within the 5GC are not informed of the change of the access point.

[0352] An example involving over-the-air FT will now be described.

[0353] In the case of over-the-air FT, the UE ceases sending user data to the serving access point and initiates a fast transition with an authentication message directly to the target access point. Since the target access point may belong to a different WLAN access zone belonging to another TNGF, the target TNGF determines the serving TNGF based on the information provided by the UE in its authentication request. Since the serving TNGF holds the key holder for PMK-R0, the serving TNGF is requested to forward PMK-R0 to the target TNGF, allowing the target TNGF to generate and distribute PMK-R1 at the target access point. The target access point processes the information included in the FTIE and responds directly to the UE with an authentication response message to continue the key update process.

[0354] After the WLAN fast transition (which includes relocation of IPsec tunnels across different access zones) is successfully completed, PMK-R0 is removed at the source TNGF so that PMK-R0 continues to exist only at the target TNGF.

[0355] Now refer to Figures 13 to 15 Some examples of signaling that may be performed for architecture and deployment options involving over-the-air FT are described.

[0356] Figure 13 Operations related to signaling to support WLAN over-the-air fast transition across multiple TNFs over the Xn interface are illustrated.

[0357] The diagram illustrates signaling that may be performed between a UE 1301, a gNB 1302, a source access point 1303, a target access point 1304, a source TNGF 1305, a target TNGF 1306, an AMF 1307, and a 5GC network function 1308 (e.g., an SMF and / or UPF). It is assumed that the UE is configured with PMK-R0 and at least one PMK-R1 derived from PMK-R0, the source access point is configured with at least one PMK-R1, and the source TNGF is configured with PMK-R0.

[0358] Before performing any handover, the UE performs WLAN measurements to determine whether to request a handover from the source access point 1303 to the target access point 1304. This determination may also be made based on neighborhood information delivered from the source access point to the UE 1301, which provides information for discovering the target access point 1304.

[0359] This means that when the UE determines that the current WLAN radio link does not provide the required service level based on the UE's pre-configured internal policy, the UE 1301 scans the environment and selects a target access point that exposes the same mobility domain information element (MDIE) as the source access point to achieve the most seamless handover, thereby maintaining the required quality of service. In addition to the same MDIE, the selected target access point may also indicate the same SSID as the source access point, and ultimately indicate the HESSID (if provided).

[0360] Furthermore, knowing the target access point MAC address, UE 1301 is able to calculate a new PMK-R1 that is used to derive a working encryption key for encrypting communications to target access point 1304. After making the decision to perform a handover operation, the UE proceeds to 13001.

[0361] During 13001, UE 1301 signals to target access point 1304. This signaling may be performed while UE 1301 is still connected to source access point 1303 to receive services (eg, while still connected to source access point 1303 to exchange user data).

[0362] The signaling of 13001 may include a fast transition information element (FTIE1). The FTIE1 may include identifiers of the UE and the source access point 1303 and cause the target access point 1304 to prepare for the fast transition of the UE 1301 from the source access point 1303 to the target access point 1304 by pre-establishing the required keying material. By establishing the keying material through a 4-way handshake coupled with the delivery of authentication and reassociation messages, the fast transition to the target access point may be initiated.

[0363] During 13002, the target access point 1304 signals the target TNGF 1306. The signaling of 13002 may include the information included in the signaling of 13001 (e.g., the respective identifiers (such as MAC addresses) of the UE 1301, the source access point 1303, and the target access point 1304). The signaling of 13002 may cause the target TNGF to determine whether the source access point 1303 belongs to the target TNGF 1305 (and therefore can use the standard fast transition procedure between two access points served by the same TNGF), or to determine whether the source access point 1303 belongs to another TNGF other than the target TNGF 1305 (and therefore desires to transition to another TNGF served by another TNGF).

[0364] The signaling of 13002 may be performed based on (eg, in response to) the target access point receiving an indication of FT handover and identifying that PMK-R1 is lost. The signaling of 13002 may request provision of the relevant key material (PMK-R1).

[0365] When the source access point 1303 belongs to another TNGF than the target TNGF (which can be determined by checking the identifier of the target access point provided in the signaling of 13002 ), the target TNGF 1306 proceeds to 13003 .

[0366] During 13003, the target TNGF determines (eg, identifies) the source TNGF 1305 via a source access point identifier (eg, via a source MAC address). The target TNGF 1306 may determine the source TNGF using any mechanism.

[0367] For example, the target TNGF 1306 may determine the source TGNF 1305 using a preconfigured (in the target TNGF 1306 ) access point list that serves neighboring TNGFs that are adjacent to the target TNGF 1306 .

[0368] As another example, the target TNGF may use a public database and / or registry (e.g., an NRF) to perform this determination. As an example, each TNGF (including the target and source TNGFs) may register its address (e.g., its Xn address) with the NRF, which has a corresponding list of associated MAC addresses of the access points served by the TNGF. This registration may be performed using, for example, the Nnrf_NFManagement_NFRegister service operation (defined in 3GPP TS 23.502). This determination may be performed by the source TNGF by performing, for example, the Nnrf_NFDiscovery_Request operation defined in 3GPP TS 23.502 to discover the target TNGF and providing the target access point MAC address as an input parameter.

[0369] During 13004, the target TNGF 1306 signals the source TNGF 1305. The signaling may include a request for PMK-R0. The signaling may include a UE context request (e.g., an Xn UE context request currently defined in 3GPP 38.300 (e.g., Section 9.2.3.2.1)). The signaling may include respective identifiers of the UE, the source access point, and the target access point. For example, the signaling may include respective MAC addresses of the UE, the source access point, and the target access point. The signaling of 13004 may include an address at which the source TNGF may forward downlink traffic not delivered to the UE to the target TNGF 1306 after the handover is complete.

[0370] During 13005, the source TNGF 1305 stops its IPSec state machine to freeze the counters and allow a clean transfer of state to the target TNGF, and responds to the signaling notification of 13004. The signaling notification may include the requested key material (PMK-R0). The signaling notification may include IPSec related parameters (e.g., SPI, SA (Security Association) list, traffic filter for each SA, IPSec sequence number for each SA), and 3GPP key material received from the 5GC).

[0371] During 13006, the target TNGF 1306 initiates activation of the IPSec endpoint for the UE 1301 and signals the target access point 1304. The signaling of 13006 may include a response to the signaling of 13002. The signaling of 13006 may include an identifier of the UE (e.g., a MAC address of the UE) and PMK-R1, which is derived by the target TNGF 1306 using the key material received from the source TNGF during 13005.

[0372] With knowledge of PMK-R1, the target access point 1304 can continue to perform over-the-air FT messaging according to the IEEE 802.11 specification without any further interaction with its TNGF. For example, the target access point 1304 determines FTIE2 (as described above with reference to Figures 10 to 12 13007), and signals an authentication response to the signaling of 13001 during 13007. The signaling of 13007 may include an 802.11 authentication response.

[0373] During 13008, UE 1301 signals target access point 1304 to initiate the final step of the handover by sending a reassociation request containing FTIE3 (this may correspond to step 3 of the 4-way handshake described above).

[0374] During 13009, the WLAN transition ends with the target access point 1306 responding to the UE's signaling of 13008 with a reassociation response that includes FTIE4, the final step of the 4-way handshake. In 13010, in parallel or serially with sending the reassociation response to the UE during 13009, the target access point notifies the target TNGF of the successful handover (e.g., using an FT_success message). The signaling of 13010 may include respective identifiers (e.g., MAC addresses) of each of the UE, the source access point, and the target access point.

[0375] During 13011, the target TNGF 1306 signals to the AMF 1307. The signaling may include a path switch request to cause the data of the UE 1301 to be forwarded to the target TNGF 1306.

[0376] During 13012, the 5GC network function 1308 and the AMF 1307 exchange signaling to cause the packet data unit (PDU) session of the UE 1301 to be updated, thereby rendering the target TNGF 1306 as the endpoint of the user data of the UE 1301. This can be performed according to the 3GPP standard (e.g., according to 3GPP TS 23.502).

[0377] During 13013, UE 1301 and target TNGF 1306 exchange signaling. This signaling involves establishing an IPSec endpoint at the target TNGF. For example, this signaling may result in the continuation of UE 1301's previous IP connection using the previous IP context used by UE 1301 with source TNGF 1305. Furthermore, this signaling may result in the use of an IPSec tunnel between UE 1301 and target TNGF 1306, which is still based on the use of a PMK-R0 security association.

[0378] During 13014, the AMF 1307 signals the target TNGF 1306 to indicate that the path switch request has been successfully completed.

[0379] During 13015, the target TNGF 1306 signals the source TNGF 1305 to indicate that the source TNGF 1305 may release any resources currently reserved by the source TNGF 1305 for use by the UE 1301. The source TNGF 1305 may perform the release based on receipt of the signaling of 13015 and respond to the signaling of 13015 during 13016. The signaling of 13016 may include an indication that the source TNGF 1305 has released the resources currently reserved by the UE 1301, as well as any user plane traffic for the UE 1301 that was not previously provided to the target TNGF 1306.

[0380] Figure 14 Another example of signaling that may be performed for WLAN over-the-air FT is illustrated. Figure 14 The signaling involves an example of fast transition of TNGF WLAN over the air across multiple TNGFs via N2.

[0381] Figure 14 The diagram illustrates signaling that may be performed between a UE 1401, a gNB 1402, a source access point 1403, a target access point 1404, a source TNGF 1405, a target TNGF 1406, an AMF 1407, and a 5GC network function 1408 (e.g., an SMF and / or UPF). It is assumed that the UE is configured with PMK-R0 and at least one PMK-R1 derived from PMK-R0, the source access point is configured with at least one PMK-R1, and the source TNGF is configured with PMK-R0.

[0382] Before performing any handover, the UE performs WLAN measurements to determine whether to request a handover from the source access point 1403 to the target access point 1404. This determination may also be made based on neighborhood information delivered from the source access point to the UE 1401, which provides information for discovering the target access point 1404.

[0383] This means that when the UE determines that the current WLAN radio link does not provide the required service level based on the UE's pre-configured internal policy, the UE 1401 scans the environment and selects a target access point that exposes the same mobility domain information element (MDIE) as the source access point to achieve the most seamless handover, thereby maintaining the required quality of service. In addition to the same MDIE, the selected target access point may also indicate the same SSID as the source access point, and ultimately indicate the HESSID (if provided).

[0384] Furthermore, knowing the target access point MAC address, UE 1401 is able to calculate a new PMK-R1 that is used to derive the working encryption key used to encrypt communications to target access point 1404. After making the decision to perform a handover operation, the UE proceeds to 14001.

[0385] During 14001, UE 1401 signals to source TNGF 1405. This signaling may be performed while UE 1401 is still connected to source access point 1403 to receive services (eg, while still connected to source access point 1403 to exchange user data).

[0386] The signaling notification of 14001 may include a handover request, which includes an identifier of the target access point 1404 (e.g., the MAC address of the target access point) and an identifier of the UE 1401 (e.g., the MAC address of the UE). The signaling notification may cause the source TNGF 1405 to prepare for the handover of the UE 1401 from the source access point 1403 to the target access point 1404.

[0387] During 14002, the source TNGF 1405 determines whether the target access point 1404 belongs to the source TNGF 1405, or determines whether the target access point 1404 belongs to another TNGF other than the source TNGF 1405. In this example, the target access point 1401 belongs to the target TNGF 1406.

[0388] During 14002, the source TNGF 1405 determines (eg, identifies) the target TNGF 1406 via a target access point identifier (eg, via a target MAC address). The source TNGF 1405 may determine the target TNGF using any mechanism.

[0389] For example, the source TNGF 1405 may determine the target TGNF 1406 using a pre-configured (in the source TNGF 1405 ) access point list that serves neighboring TNGFs that are adjacent to the source TNGF 1405 .

[0390] As another example, the source TNGF may use a public database and / or registry (e.g., an NRF) to perform this determination. As an example, each TNGF (including the target TNGF) may register its address (e.g., its Xn address) with the NRF, which has a corresponding list of associated MAC addresses of the access points served by the TNGF. This registration may be performed using, for example, the Nnrf_NFManagement_NFRegister service operation (defined in 3GPP TS 23.502). This determination may be performed by the source TNGF by performing, for example, the Nnrf_NFDiscovery_Request operation defined in 3GPP TS 23.502 to discover the target TNGF and providing the target access point MAC address as an input parameter.

[0391] When the target access point 1404 belongs to another TNGF than the source TNGF (which can be determined by checking the identifier of the target access point provided in the signaling of 14001 ) and the target TNGF 1406 has been identified, the source TNGF 1405 proceeds to 14003 .

[0392] During 14003, the source TNGF 1405 signals to the AMF 1407. The signaling may indicate that the UE will be handed over to another TNGF 1406 other than the source TNGF 1605. The signaling may include the master key material PMK-R0. The signaling may include an N2 handover required service operation.

[0393] During 14004, the AMF 1407 and the user plane entity 1408 exchange signaling to prepare the UE for handover from the source TNGF 1405 to the target TNGF 1406. As part of this preparation (which may largely conform to the handover preparation described in 3GPP standards, such as 3GPP TS 23.502 Figure 4 .9.1.3.2-1 Steps 1 to 12), PMK-R0 can be exchanged between AMF 1407 and 5GC network function 1408.

[0394] During 14005, the AMF 1407 signals the target TNGF 1406. The signaling may include a handover request for requesting handover of the UE 1401 to the target TNGF 1406. The signaling may include the master key material PMK-R0.

[0395] During 14006, UE 1401 signals the target access point 1404. This signaling may be performed while UE 1401 is still connected to source access point 1403 to receive services (eg, while still connected to source access point 1403 to exchange user data).

[0396] The signaling at 14006 may include an FT Action Request message that includes an identifier of the target access point 1404 (e.g., the MAC address of the target access point) and a Fast Transition Information Element (FTIE1). The FTIE1 may include identifiers of the UE and source access point 1403 and cause the target access point 1404 to prepare for a fast transition of the UE 1401 from the source access point 1403 to the target access point 1404 by pre-establishing the required keying material. By leveraging a 4-way handshake to establish keying material over authentication and reassociation messaging, a fast transition to the target access point may be initiated. The signaling at 14006 may include an 802.11 Authentication Request.

[0397] During 14007, the target access point 1404 signals the target TNGF 1406. The signaling of 14007 may include the information included in the signaling of 14006 (e.g., the respective identifiers (such as MAC addresses) of the UE 1401, the source access point 1403, and the target access point 1404). The signaling of 14007 may cause the target TNGF to determine whether the source access point 1403 belongs to the target TNGF 1406 (and therefore can use the standard fast transition procedure between two access points served by the same TNGF), or to determine whether the source access point 1403 belongs to another TNGF other than the target TNGF 1406 (and therefore desires a transition addressing another TNGF served by another TNGF).

[0398] The signaling of 14007 may be performed based on (eg, in response to) the target access point receiving an indication of FT handover and identifying that PMK-R1 is lost. The signaling of 14007 may request provision of the relevant key material (PMK-R1).

[0399] When the source access point 1403 belongs to another TNGF than the target TNGF (which can be determined by checking any identifier of the target access point provided in the signaling of 14007 ), the target TNGF 1406 proceeds to 14008 .

[0400] During 14008, the target TNGF 1406 initiates activation of the IPSec endpoint for the UE 1401 and signals the target access point 1404. The signaling of 14008 may include a response to the signaling of 14010. The signaling of 14008 may include an identifier of the UE (e.g., a MAC address of the UE) and PMK-R1, which is derived by the target TNGF 1406 using the key material received from the AMF during 14005.

[0401] With knowledge of PMK-R1, the target access point 1404 can continue over-the-air FT message delivery in accordance with the IEEE 802.11 specification without any further interaction with its TNGF. For example, the target access point 1404 determines FTIE2 (as described above with reference to Figures 10 to 13 ), and signals an authentication response to the signaling of 14006 during 14009. The signaling of 14009 may include an 802.11 authentication response.

[0402] During 14010, the target TNGF 1406 signals to the AMF 1407, which may be performed in series or in parallel with the signaling of 14008. The signaling may include a path switch request to cause the data of the UE 1401 to be forwarded to the target TNGF 1406.

[0403] During 14011, the 5GC network function 1408 and the AMF 1307 exchange signaling to cause the packet data unit (PDU) session of the UE 1401 to be updated, thereby rendering the target TNGF 1406 as the endpoint of the user data of the UE 1401. This can be performed according to the 3GPP standard (for example, according to 3GPP TS 23.502).

[0404] During 14012, UE 1401 signals target access point 1404 to initiate the final step of the handover by sending a reassociation request containing FTIE3 (this may correspond to step 3 of the 4-way handshake described above).

[0405] During 14013, the WLAN transition ends with the target access point 1404 responding to the UE's signaling 14013 with a reassociation response, which includes FTIE4, the last step of the 4-way handshake. In 14014, along with sending the reassociation response to the UE, the target access point notifies the target TNGF of the successful handover (e.g., using an FT_success message). The signaling 14014 may include respective identifiers (e.g., MAC addresses) for each of the UE, the source access point, and the target access point.

[0406] During 14016, UE 1401 and target TNGF 1406 exchange signaling. This signaling involves establishing an IPSec endpoint at the target TNGF. For example, this signaling may cause UE 1401's previous IP connection to continue using the previous IP context used by UE 1401 with source TNGF 1405. Furthermore, this signaling may cause the use of an IPSec tunnel between UE 1401 and target TNGF 1406, which is still based on the use of a PMK-R0 security association.

[0407] During 14017, the AMF 1407 signals the target TNGF 1406 to indicate that the path switch request has been successfully completed.

[0408] During 14018, the target TNGF 1406 signals the source TNGF 1405 to indicate that the source TNGF 1405 may release any resources currently reserved by the source TNGF 1405 for use by the UE 1401. The source TNGF 1405 may perform the release based on receipt of the signaling of 14018 and respond during 14021 to confirm the UE context release.

[0409] Figure 15 Another example of signaling that may be performed for over-the-air FT is addressed. Figure 15 An example involves providing support for WLAN over-the-air fast transition within a TNAN served by a single TNGF.

[0410] Figure 15 The diagram illustrates signaling that may be performed between a UE 1501, a gNB 1502, a source access point 1103, a target access point 1504, and a source TNGF 1505. It is assumed that the UE is configured with PMK-R0 and at least one PMK-R1 derived from PMK-R0, and that the source TNGF is configured with PMK-R0.

[0411] Before performing any handover, the UE performs WLAN measurements to determine whether to request a handover from the source access point 1503 to the target access point 1504. This determination may also be made based on neighborhood information delivered from the source access point to the UE 1501, which provides information for discovering the target access point 1504.

[0412] This means that when the UE determines that the current WLAN radio link does not provide the required service level based on the UE's pre-configured internal policy, the UE 1501 scans the environment and selects a target access point that exposes the same mobility domain information element (MDIE) as the source access point to achieve the most seamless handover, thereby maintaining the required quality of service. In addition to the same MDIE, the selected target access point may also indicate the same SSID as the source access point, and ultimately indicate the HESSID (if provided).

[0413] Furthermore, knowing the target access point MAC address, UE 1501 is able to calculate a new PMK-R1 that is used to derive a working encryption key for encrypting communications to target access point 1504. After making the decision to perform a handover operation, the UE proceeds to 15001.

[0414] During 15001, UE 1501 signals to target access point 1504. This signaling may be performed while UE 1501 is still connected to source access point 1503 to receive services (eg, while still connected to source access point 1503 to exchange user data).

[0415] The signaling of 15001 may include a fast transition information element (FTIE1). This signaling may cause the target access point 1504 to prepare for the fast transition of the UE 1501 from the source access point 1503 to the target access point 1504 by pre-establishing the required keying material.

[0416] During 15002, the target access point 1504 signals the source TNGF 1505. The signaling of 15002 may include the information included in the signaling of 15001 (e.g., the respective identifiers (such as MAC addresses) of the UE 1501, the source access point 1503, and the target access point 1504). The signaling of 15002 may cause the TNGF to determine whether the source access point 1503 and / or the target access point 1504 belong to the TNGF 1505 (and therefore a standard fast transition procedure can be used between two access points served by the same TNGF), or whether the source access point 1503 belongs to another TNGF other than the TNGF 1505 (and therefore a transition addressing another TNGF served by another TNGF is desired).

[0417] The signaling at 15002 may be performed based on (e.g., in response to) the target access point receiving an indication of FT handover and identifying that PMK-R1 is lost. The signaling at 15002 may request provision of relevant key material (PMK-R1). The signaling at 15002 may include an FT_Request service operation.

[0418] During 15003, the source TNGF determines (e.g., identifies) the target TNGF via the target access point identifier (e.g., via the target MAC address). In the present case, the source TNGF is also the target TNGF (i.e., the TNGF that manages access to the 5GC by the target access point 1504).

[0419] For example, the source TNGF 1505 may determine the target TGNF using a preconfigured (in the source TNGF 1505 ) access point list that serves neighboring TNGFs that are adjacent to the source TNGF 1505 .

[0420] As another example, the source TNGF may use a public database and / or registry (e.g., an NRF) to perform this determination. As an example, each TNGF (including the target TNGF) may register its address (e.g., its Xn address) with the NRF, which has a corresponding list of associated MAC addresses of the access points served by the TNGF. This registration may be performed using, for example, the Nnrf_NFManagement_NFRegister service operation (defined in 3GPP TS 23.502). This determination may be performed by the source TNGF by performing, for example, the Nnrf_NFDiscovery_Request operation defined in 3GPP TS 23.502 to discover the target TNGF and providing the target access point MAC address as an input parameter.

[0421] During 15003, the source TNGF 1505 uses the source access point identifier and the UE identifier received during 15002 to determine PMK-R0 and derive PMK-R1 for use by the target access point in generating the working encryption key.

[0422] During 15004, the source TNGF 1505 signals the target access point 1504. The signaling may include PMK-R1. The signaling may include the UE's identifier. The signaling may include the respective identifiers of the source access point 1503 and the target access point 1504. The signaling may include an FT action response service operation.

[0423] During 15005, target access point 1504 signals UE 1501. The signaling may include a response to the signaling of 15001. The signaling may be provided to UE 1501 over the air while the UE is still able to perform user data transmission to the 5GC via the source access point. The signaling may include FTIE2. The signaling may include an 802.11 authentication response service operation.

[0424] During 15005, after receiving the preparation information required to perform the final steps of the fast transition (e.g., FTIE2), UE 1501 adjusts its radio parameters for transmission and / or reception and issues an IEEE 802.11 reassociation request message to the target access point 1504 during 15006. The signaling of 15006 may include FTIE3.

[0425] During 15007, the target access point 1504 responds to the signaling notification of 15006. This response can be performed based on (e.g., using) information already available at the target access point. This means that the target access point 1504 can immediately respond to the request of 15006 with a corresponding IEEE 802 reassociation response message to end the transition and enable the UE to continue exchanging user data with the 5GC via the target access node. The signaling notification of 15006 can include FTIE4.

[0426] During 15008 , the target access point 1504 signals the source TNGF 1505 to indicate that the handover operation between the target access point and the UE 1501 has been completed, which may be performed in parallel with the signaling of 15007 or may be performed after the signaling of 15007 .

[0427] During 15009, TNGF 1505 and UE 1501 exchange signaling. This signaling involves establishing an IPSec endpoint at the target TNGF. For example, this signaling may cause UE 1501's previous IP connection to continue using the previous IP context used by UE 1501 with the source TNGF 1505. Furthermore, this signaling may cause the use of an IPSec tunnel between UE 1501 and TNGF 1505, which is still based on the use of the PMK-R0 security association.

[0428] Figures 16 to 20 The features of the above examples are illustrated. Therefore, it is understood that the above features may be functionally equivalent to the features described below. It is further understood that the above examples may provide additional features to supplement the features described below in some implementations.

[0429] Figure 16The diagram illustrates features that may be performed by a source interworking function that interfaces between a source access point and a core network. The source interworking function may include an N2IWF. The source interworking function may include a TNGF.

[0430] During 1601 , a source interworking function receives an indication that a user equipment is to be handed over from a source access point to a target access point.

[0431] During 1602, the source interworking function makes a first determination, which determines whether the source interworking function is interfacing between the target access point and the core network.

[0432] During 1603 , the source interworking function determines key material for encrypting communications between the target access point and the user equipment according to (eg, based on) the first determination.

[0433] When the first determination determines that the source interworking function interfaces between the target access point and the core network, determining the key material may include: identifying a primary pairwise master key (e.g., PMK-R0) used to derive a source secondary pairwise master key (e.g., PMK-R1) used to encrypt communications between the source access point and the user equipment; and using the primary pairwise master key to derive a target secondary pairwise master key used to encrypt communications between the target access point and the user equipment. Thus, this example may correspond to a case where the source interworking function is also the target interworking function.

[0434] When the first determination determines that the source interworking function is not interfacing between the target access point and the core network, determining the key material may include: identifying a primary pairwise master key (e.g., PMK-R0) used to derive a source secondary pairwise master key (e.g., PMK-R1 of the source) used to encrypt communications between the source access point and the user equipment; identifying a target interworking function interfacing between the target access point and the core network; and providing the primary pairwise master key to the target interworking function. In this example (where the source interworking function is not the target interworking function), the source interworking function may not derive a target secondary pairwise master key used to encrypt communications between the target access point and the user equipment. The target interworking function may include an N2IWF. The target interworking function may include a TNGF.

[0435] The indication may be received from the source access point in a request for fast handover (FT_req). The request for fast handover may include a first query (e.g., FTIE1). The first query may include the first step in a four-step handshake operation for completing the fast handover. The source interworking function may provide the first query to the target interworking function. The providing may be performed via an Xn interface (e.g., the providing may be performed using an interface between the source and target interworking functions). For example, the providing may be performed using a UE context forwarding message.

[0436] The source interworking function may receive a first response (e.g., FTIE2) to the first query from the target interworking function. The first response may include the second step of a four-step handshake operation. The receiving may be performed via an Xn interface (e.g., the receiving may be performed using an interface between the source and target interworking functions). For example, the receiving may be performed using a UE context forwarding message.

[0437] The source interworking function may forward the first response to the source access point.

[0438] As another example, when the first determination determines that the source interworking function is not to interface between the target access point and the core network, determining the key material may include: identifying a primary pairwise master key (e.g., PMK-R0) that is used to derive a source secondary pairwise master key (e.g., PMK-R1) for encrypting communications between the source access point and the user equipment; and providing the primary pairwise master key to an access and mobility function in the core network.

[0439] When the indication is received from the source access point in a request for fast handover, the request for fast handover may include a first query, and the source interworking function may: provide the first query to the access and mobility function; receive a first response to the first query from the access and mobility function; and forward the first response to the source access point. As mentioned above, the first query may include FTIE1, and the first response may include FTIE2. The first query may include the first step in a four-step handshake operation for completing the fast handover. The providing may be performed via an N2 interface (e.g., the providing may be performed using respective interfaces between the access and mobility function and the source and target interworking functions). For example, the providing may be performed using an N2 handover required message. The receiving may be performed via an N2 interface (e.g., the receiving may be performed using an interface between the access and mobility function and the source interworking function). For example, the receiving may be performed using an N2 handover command message.

[0440] In the above example involving the source and target interworking functions being included in separate functions, after the user equipment is handed over from the source access point to the target access point, the source interworking function may receive an instruction to remove the primary pairwise master key; and remove the primary pairwise master key from local storage. The instruction to remove the primary pairwise master key may be included in a user equipment context release message. The UE context release message may be received from the target interworking function (e.g., via an Xn interface). The source interworking function may disable the Internet Protocol security endpoint for the user equipment in response to receiving the instruction to remove the primary pairwise master key.

[0441] Figure 17The diagram illustrates operations that may be performed by a target interworking function that interfaces between a target access point and a core network. The target interworking function may include an N2IWF. The target interworking function may include a TNGF. The target interworking function may be the same as described above with respect to Figure 16 The target intercommunication function mentioned.

[0442] During 1701 , the target interworking function may receive an indication that a user equipment is to be handed over from a source access point to a target access point.

[0443] During 1702, the target interworking function may obtain keying material including a primary pairwise master key (eg, PMK-R0) used to derive a source secondary pairwise master key used to encrypt communications between the source access point and the user equipment.

[0444] During 1703 , the target interworking function may use the primary pairwise master key to derive a target secondary pairwise master key (eg, PMK-R1 ) for encrypting communications between the target access point and the user equipment.

[0445] During 1704, the target interworking function may cause a target secondary pairwise master key to be provided to the target access point.

[0446] When the indication is received from the target access point, obtaining the primary pairwise master key may include making a first determination that the target interworking function is also a source interworking function that interfaces between the source access point and the core network; and identifying the primary pairwise master key as a key previously used by the target interworking function to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment.

[0447] When the indication is received from the target access point, obtaining the primary pairwise master key may include: making a first determination that the target interworking function is not interfacing between the source access point and the core network; identifying a source interworking function that is interfacing between the source access point and the core network; signaling a request for the primary pairwise master key to at least one of an access and mobility function associated with the core network; and receiving the primary pairwise master key in response to the request. The source interworking function may be as described above with respect to Figure 16 As described. Signaling a request for a primary pairwise master key may include signaling the request to the source interworking function using an Xn interface (e.g., using a UE context request). Signaling a request for a primary pairwise master key may include signaling the request to the source interworking function via an AMF (e.g., using an N2 interface). Receiving the primary pairwise key may include receiving the key from the source interworking function using an Xn interface (e.g., using a UE context message). Receiving the primary pairwise key may include receiving the key from the source interworking function via an AMF (e.g., using an N2 interface).

[0448] The indication may be received at the target interworking function from the target access point in a request for fast handover. In this case, the request for fast handover may include a first query (e.g., FTIE1, which may be the first step in a four-step handshake as discussed above). The target interworking function may provide the target secondary pairwise master key to the target access point in response to (based on) receiving the indication. Furthermore, in this example, receiving the primary pairwise key from the source interworking function may include receiving the primary pairwise key as part of a first fast transition information element included in an Xn user equipment context message.

[0449] The indication may be received from at least one of: an access and mobility function associated with the core network, and a source interworking function interfacing between the source access point and the core network. When the indication is received from the source interworking function, the indication may be received via an X2 interface (e.g., via a UE context message). When the indication is received from the access and mobility function (e.g., via a handover request), the indication may be received via an N2 interface. Retrieving the primary pairwise master key may include receiving the primary pairwise master key with the indication.

[0450] In all of the above examples, after the user equipment switches from the source access point to the target access point (e.g., when the user equipment has completed the fast transition procedure), the target interworking function may signal an instruction to the source interworking function interfacing between the source access point and the core network to remove the master pairwise master key from the source interworking function. It will be appreciated that the AMF may signal this instruction when the user equipment has completed the fast transition procedure (e.g., autonomously or in response to an indication to that effect from the target interworking function).

[0451] In all of the above examples, after causing the target secondary pairwise master key to be provided to the target access point, the target interworking function may cause an Internet Protocol security endpoint to be established for traffic of the user equipment.

[0452] Figure 18 The diagram illustrates operations that may be performed by an access and mobility function associated with a core network. The AMF may be the Figure 16 and Figure 17 The AMF discussed in at least one of the above.

[0453] During 1801, the AMF receives key material from a source interworking function interfacing between the source access point and the core network, the key material comprising a primary pairwise master key (PMK-R0) used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment. The source interworking function may be as described above with respect to Figure 16 and Figure 17 The receiving may be performed on a first N2 interface between the AMF and the source interworking function.

[0454] During 1802, the AMF provides key material to the target interworking function that interfaces between the target access point and the core network. The target interworking function may be as described above with respect to Figure 16 and Figure 17 The provision may be performed over a second N2 interface between the AMF and the target interworking function.

[0455] The AMF may receive a request for key material from the target interworking function (e.g., via a handover request signaled on the second N2 interface). The AMF may signal the request for key material to the source interworking function. The AMF may receive the key material in response to the signaling.

[0456] Figure 19 The diagram illustrates operations that may be performed by an access point. The access point may be a source access point or a target access point, as described above with respect to Figures 16 to 18 Any of the items described.

[0457] During 1901, the access point provides a request for a fast transition to be performed with respect to a user equipment to be handed over from or to the access point to an interworking function interfacing between the access point and a core network, the request including a first fast transition information element (e.g., FTIE1) associated with a master key material. The interworking function may be such as with respect to Figures 16 to 18 The intercommunication function may be as described in any of the source intercommunication functions. Figures 16 to 18 Any of the target intercommunication functions described in .

[0458] During 1902, the access point receives a response to the request from the interworking function, the response comprising a second fast transition information element associated with secondary key material derived from the primary key material.

[0459] During 1903, the access point provides a second fast transition information element (eg, FTIE2) to the user equipment as part of the fast transition procedure.

[0460] Figure 20 The target access point may be as described above with respect to Figures 16 to 19 Any of the items described.

[0461] During 2001, the target access point receives a request from an interworking function interfacing between the target access point and the core network indicating that a user equipment will be handed over from the source access point to the target access point using a fast transition procedure, the request including a first fast transition information element (e.g., FTIE1) and secondary key material (e.g., PMK-R1 generated by the interworking function).

[0462] During 2002, the target access point uses the secondary key material and the first fast transition information to generate a second fast transition information element (eg, FTIE2) serving as a response to the first fast transition information element to enable the fast transition process to continue.

[0463] During 2003, the target access point signals a second fast transition element to the interworking function.

[0464] exist Figure 19 and Figure 20 In the above two examples, the access point may complete the fast transition procedure with the user equipment and signal an indication to the interworking function that the fast transition procedure has been successfully completed, the indication including the respective identifiers of the user equipment and the access point.

[0465] The foregoing description provides a complete and informative description of some examples by way of non-limiting examples. However, various modifications and adaptations will become apparent to those skilled in the relevant art in view of the foregoing description when read in conjunction with the accompanying drawings and claims. Nevertheless, all such and similar modifications of these teachings will still fall within the scope of the appended claims.

[0466] In the above, different examples are described using radio access architectures based on Long Term Evolution Advanced (LTE-Advanced, LTE-A) or New Radio (NR, 5G) as examples of access architectures to which the described techniques can be applied, however, the examples are not limited to such architectures. By appropriately adjusting parameters and procedures, these examples can also be applied to other types of communication networks with appropriate means. Some examples of other options for suitable systems are Universal Mobile Telecommunications System (UMTS) Radio Access Network (UTRAN), Wireless Local Area Network (WLAN or WiFi), Worldwide Interoperability for Microwave Access (WiMAX), Personal Communications Service (PCS), Wideband Code Division Multiple Access (WCDMA), systems using Ultra-Wideband (UWB) technology, sensor networks, Mobile Ad Hoc Networks (MANETs), and Internet Protocol Multimedia Subsystem (IMS), or any combination thereof.

[0467] As provided herein, various aspects are described in the detailed description of examples and in the claims. Generally, some examples can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. For example, some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software, which can be executed by a controller, microprocessor, or other computing device, but the examples are not limited thereto. Although various examples can be illustrated and described as block diagrams, flow charts, or using some other graphical representation, it is well understood that, as non-limiting examples, the blocks, devices, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0468] These examples may be implemented by computer software stored in a memory and executable by at least one data processor of the entity involved, or by hardware, or by a combination of software and hardware. Furthermore, in this regard, it should be noted that any process (e.g. Figure 16 and / or Figure 17 and / or Figure 18 and / or Figure 19 and / or Figure 20 The software may be stored on physical media such as memory chips or memory blocks implemented within a processor, magnetic media such as hard disk or floppy disks, and optical media such as, for example, DVDs and their data variants, CDs, etc.

[0469] The memory may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor may be of any type suitable for the local technical environment and may include, by way of non-limiting example, one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a gate-level circuit, and a processor based on a multi-core processor architecture.

[0470] Alternatively or additionally, some examples may be implemented using circuitry. The circuitry may be configured to perform one or more of the previously described functions and / or method steps. The circuitry may be provided in a base station and / or a communication device and / or a core network entity.

[0471] As used in this application, the term "circuitry" may refer to one or more or all of the following:

[0472] (a) Pure hardware circuit implementation (such as implementation in analog and / or digital circuit systems only)

[0473] now);

[0474] (b) A combination of hardware circuitry and software, such as:

[0475] (i) a combination of analog and / or digital hardware circuits and software / firmware, and

[0476] (ii) any portion of hardware processor(s) (including digital signal processor(s)) with software, software and memory(s) that work together to cause an apparatus (such as a communication device or base station) to perform the various functions previously described;

[0477] as well as

[0478] (c) Hardware circuit(s) and / or processor(s), such as microprocessor(s) or portion(s) of microprocessor(s), that require software (e.g., firmware) for operation, but the software may not be present when not required for operation.

[0479] This definition of circuitry applies to all uses of this term in this application, including in any claims. As another example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example, an integrated device.

Claims

1. A method for performing a source interworking function of an interface connection between a source access point and a core network, the method comprising: receiving an indication that a user equipment is to be handed over from the source access point to a target access point; making a first determination, the first determination determining whether the source interworking function interfaces between the target access point and the core network; as well as Based on the first determination, key material for encrypting communications between the target access point and the user equipment is determined.

2. The method of claim 1 , wherein the first determining determines that the source interworking function interfaces between the target access point and the core network, and wherein determining the key material comprises: identifying a primary pairwise master key used to derive a source secondary pairwise master key used to encrypt communications between the source access point and the user equipment; as well as The primary pairwise master key is used to derive a target secondary pairwise master key for encrypting communications between the target access point and the user equipment.

3. The method of claim 1 , wherein the first determination determines that the source interworking function does not interface between the target access point and the core network, and wherein determining key material comprises: identifying a primary pairwise master key used to derive a source secondary pairwise master key used to encrypt communications between the source access point and the user equipment; identifying a target intercommunication function for interfacing between the target access point and the core network; as well as The master pairwise master key is provided to the target interworking function.

4. The method of claim 3 , wherein the indication is received from the source access point in a request for a fast handoff, the request for the fast handoff comprising a first query, the method comprising: providing the first query to the target intercommunication function; receiving a first response to the first query from the target interworking function; as well as The first response is forwarded to the source access point.

5. The method of claim 4 , wherein providing the master pairwise key to the target interworking function comprises: The master pairwise key is provided as part of a first fast transition information element included in an Xn user equipment context forwarding service operation, and wherein receiving the first response to the first query includes receiving a second fast transition information element included in the Xn user equipment context forwarding service operation.

6. The method of claim 1 , wherein the first determination determines that the source interworking function does not interface between the target access point and the core network, and wherein the determining key material comprises: identifying a primary pairwise master key used to derive a source secondary pairwise master key used to encrypt communications between the source access point and the user equipment; as well as The master pairwise master key is provided to an access and mobility function in the core network.

7. The method of claim 6, wherein the indication is received from the source access point in a request for a fast handoff, the request for the fast handoff comprising a first query, the method comprising: providing the first query to the access and mobility function; receiving a first response to the first query from the access and mobility function; as well as The first response is forwarded to the source access point.

8. The method of claim 7, wherein said providing said master pairwise key to said access and mobility function comprises: The primary pairwise key is provided as part of a first rapid transition information element included in an N2 handover required service operation, and wherein receiving the first response to the first query comprises receiving a second rapid transition information element included in an N2 handover command service operation.

9. The method according to any one of claims 2 to 8, comprising: after the user equipment is handed over from the source access point to the target access point: receiving an instruction to remove the master pair-wise master key; and Remove the master pair-wise master key from local storage.

10. The method of claim 9, wherein the instruction to remove the master pairwise master key is included in a user equipment context release message, and the method further comprises: In response to receiving the instruction to remove the master pair-wise master key, disabling an Internet Protocol security endpoint for the user device.

11. A method for performing a target interworking function of an interface connection between a target access point and a core network, the method comprising: receiving an indication that the user equipment is to be handed over from the source access point to the target access point; obtaining key material, the key material comprising a primary pairwise master key, the primary pairwise master key being used to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment; using the primary pairwise master key to derive a target secondary pairwise master key for encrypting communications between the target access point and the user equipment; as well as Causing the target secondary pairwise master key to be provided to the target access point.

12. The method of claim 11 , wherein the indication is received from a target access point, and wherein obtaining the master pairwise master key comprises: making a first determination, the first determination determining that the target interworking function is also a source interworking function that interfaces between the source access point and the core network; as well as The primary pairwise master key is identified as a key previously used by the target interworking function to derive a source secondary pairwise master key for encrypting communications between the source access point and the user equipment.

13. The method of claim 11 , wherein the indication is received from a target access point, and wherein obtaining the master pairwise master key comprises: making a first determination, the first determination determining that the target interworking function does not interface between the source access point and the core network; Identifying a source interworking function for interfacing between the source access point and the core network; signaling a request for the master pairwise master key to at least one of an access and mobility function associated with the core network; as well as In response to the request, the master pair-wise master key is received.

14. The method of claim 13, wherein the indication is received from the target access point in a request for a fast handoff, the request for the fast handoff comprising a first query, the method comprising: In response to receiving the indication, the target secondary pairwise master key is provided to the target access point.

15. The method of claim 14, wherein receiving the master pairwise key from the source interworking function comprises: The master pairwise key is received as part of a first fast transition information element included in an Xn user-equipment context service operation.

16. The method of claim 11 , wherein the indication is received from at least one of: an access and mobility function associated with a core network, and a source interworking function interfacing between the source access point and the core network, and wherein obtaining the primary pairwise master key comprises: The master pair-wise master key is received with the indication.

17. The method of claim 16, wherein the indication is included in a handover request to handover the user equipment from the source access point to the target access point. The method of claim 16 , wherein the indication is included in a user equipment context message.

19. The method according to any one of claims 11 to 18, comprising, after the user equipment is handed over from the source access point to the target access point, signaling to a source interworking function interfacing between the source access point and the core network an instruction to remove the master pairwise master key from the source interworking function.

20. The method according to any one of claims 11 to 19, comprising: After causing the target secondary pairwise master key to be provided to the target access point, causing an Internet Protocol security endpoint to be established for traffic of the user equipment.

21. A method for access and mobility functions associated with a core network, the method comprising: receiving keying material from a source interworking function interfacing between a source access point and the core network, the keying material comprising a primary pairwise master key used to derive a source secondary pairwise master key used to encrypt communications between the source access point and the user equipment; as well as The key material is provided to a target interworking function interfacing between a target access point and the core network.

22. The method according to claim 21, comprising: receiving a request for the key material from the target interworking function; signaling said request for said key material to said source interworking function; as well as In response to the signaling, the key material is received.

23. A method for an access point, the method comprising: providing a request for a fast transition to be performed in relation to a user equipment to be handed over from or to the access point to an interworking function interfacing between the access point and a core network, the request including a first fast transition information element associated with master key material; receiving a response to the request from the interworking function, the response comprising: a second rapid transition information element associated with secondary keying material derived from the primary keying material; as well as The second rapid transition information element is provided to the user equipment as part of a rapid transition procedure.

24. A method for a target access point, the method comprising: receiving, from an interworking function interfacing between the target access point and a core network, a request indicating that a user equipment is to be handed over from a source access point to the target access point using a fast transition procedure, the request including a first fast transition information element and secondary key material; generating a second rapid transition information element as a response to the first rapid transition information element using the secondary key material and the first rapid transition information to enable the rapid transition process to continue; as well as The second fast transition element is signaled to the interworking function.

25. The method according to any one of claims 23 to 24, comprising: completing the rapid transition process with the user equipment; as well as An indication is signaled to the interworking function that the fast transition procedure has completed successfully, the indication including respective identifiers of the user equipment and the access point.

26. An apparatus for performing a source interworking function for interfacing between a source access point and a core network, the apparatus comprising means for performing the method according to any one of claims 1 to 10.

27. An apparatus for performing a target interworking function of an interface connection between a target access point and a core network, the apparatus comprising means for performing the method according to any one of claims 11 to 20.

28. An apparatus for access and mobility functions associated with a core network, the apparatus comprising means for performing the method according to any one of claims 21 to 22.

29. An apparatus for an access point, the apparatus comprising means for performing the method according to claim 23, or claim 25 when dependent thereon.

30. An apparatus for a target access point, the apparatus comprising means for performing the method according to claim 24, or claim 25 when dependent thereon.

31. A computer program comprising instructions which, when executed by an apparatus of a source interworking function for interfacing between a source access point and a core network, comprise means for performing the method according to any one of claims 1 to 10.

32. A computer program comprising instructions which, when executed by an apparatus of a target interworking function for interfacing between a target source access point and a core network, cause the apparatus to perform the method according to any one of claims 11 to 20.

33. A computer program comprising instructions which, when executed by an apparatus for access and mobility functions associated with a core network, cause the apparatus to perform the method according to any one of claims 21 to 22.

34. A computer program comprising instructions which, when executed by an apparatus for an access point, cause the apparatus to perform the method according to any one of claim 23, or claim 25 when dependent thereon.

35. A computer program comprising instructions which, when executed by an apparatus for a target access point, cause the apparatus to perform the method according to claim 24, or claim 25 when dependent thereon.