Relay discovery for service network driven scenarios

By acquiring and transmitting PLMN information in 5G ProSe U2U/U2N relay scenarios, the problem of insufficient relay discovery security in existing technologies is solved, and a more efficient and reliable relay discovery process is achieved.

CN121040101APending Publication Date: 2025-11-28ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380097628.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-05-22
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

In 5G ProSe U2U/U2N relay scenarios, existing technologies struggle to effectively acquire the serving PLMN of potential U2U/U2N relays, resulting in insufficient relay discovery security and impacting communication performance and efficiency.

Method used

The first network device receives and sends information requests and responses about the PLMN, obtains and provides security parameters for relay discovery, and ensures the security and efficiency of the relay discovery process.

Benefits of technology

It improves the security and communication performance of relay discovery, enhances communication efficiency, and ensures the reliability and accuracy of the relay discovery process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121040101A_ABST
    Figure CN121040101A_ABST
Patent Text Reader

Abstract

Example embodiments of the present disclosure relate to protecting relay discovery for service network driving scenarios. A first network device receives, from a second network device, a request for information about at least one public land mobile network (PLMN) in which a terminal device is authorized to use a relay service. Then, the first network device obtains the information about the at least one PLMN based on the request. Furthermore, the first network device sends, to the second network device, a response including the information about the at least one PLMN. In this way, relay discovery security can be ensured, and thus communication performance and communication efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunications, and in particular, to devices, methods, apparatuses, and computer-readable storage media for protecting relay discovery for service network driven scenarios. BACKGROUND

[0002] A fifth generation (5G) system supports a proximity-based service (ProSe) feature. The 5G ProSe feature can include: 5G ProSe direct discovery, 5G ProSe direct communication, 5G ProSe UE-to-network (U2N) relay, and 5G ProSe UE-to-UE (U2U) relay. In the 5G ProSe U2N relay feature, a remote user equipment (UE) can connect to a U2U relay via a PC5 interface with 5G ProSe direct communication and communicate with a data network via the U2U relay and a 5G network. To perform 5G ProSe direct communication between the remote UE and the U2N relay, the remote UE and the U2N relay can perform a 5G ProSe direct discovery procedure using security information for relay discovery. In the 5G ProSe U2U relay feature, 5G ProSe end UEs communicate with each other via a 5G ProSe U2E relay. Similar to the 5G ProSe U2U relay case, the 5G ProSe end UEs (e.g., a source UE or a target UE) and the U2U relay can perform a 5G ProSe direct discovery procedure using security information for 5G ProSe U2U relay discovery. SUMMARY

[0003] Generally, example embodiments of the present disclosure provide a solution for protecting relay discovery for service network driven scenarios.

[0004] In a first aspect, a first network device is provided. The first network device includes at least one processor and at least one memory storing instructions. The instructions, when executed by the at least one processor, cause the first network device at least to: receive, from a second network device, a request for information about at least one public land mobile network (PLMN) in which a terminal device is authorized to use a relay service; based on the request, obtain the information about the at least one PLMN; and send, to the second network device, a response including the information about the at least one PLMN.

[0005] In a second aspect, a second network device is provided. The second network device includes at least one processor and at least one memory storing instructions. The instructions, when executed by the at least one processor, cause the second network device to at least: send, to a first network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service; and receive, from the first network device, a response including the information about the at least one PLMN.

[0006] In a third aspect, an apparatus is provided. The apparatus includes: means for receiving, at a first network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service, from a second network device; means for obtaining the information about the at least one PLMN based on the request; and means for sending, to the second network device, a response including the information about the at least one PLMN.

[0007] In a fourth aspect, an apparatus is provided. The apparatus includes: means for sending, at a second network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service, to a first network device; and means for receiving, from the first network device, a response including the information about the at least one PLMN.

[0008] In a fifth aspect, a method is provided. The method includes: receiving, at a first network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service, from a second network device; obtaining the information about the at least one PLMN based on the request; and sending, to the second network device, a response including the information about the at least one PLMN.

[0009] In a sixth aspect, a method is provided. The method includes: sending, at a second network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service, to a first network device; and receiving, from the first network device, a response including the information about the at least one PLMN.

[0010] In a seventh aspect, a computer readable medium is provided. The computer readable medium includes program instructions that, when executed by at least one processor, cause an apparatus to at least perform a method according to the fifth aspect or the sixth aspect.

[0011] In an eighth aspect, a computer program including instructions which, when executed by an apparatus, cause the apparatus to at least perform a method according to the fifth aspect or the sixth aspect is provided.

[0012] In a ninth aspect, a first network device is provided. The first device comprises receiving circuitry configured to receive, from a second network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service; obtaining circuitry configured to obtain, based on the request, information about the at least one PLMN; and transmitting circuitry configured to transmit, to the second network device, a response comprising the information about the at least one PLMN.

[0013] In a tenth aspect, a second network device is provided. The first device comprises transmitting circuitry configured to transmit, to a first network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service; and receiving circuitry configured to receive, from the first network device, a response comprising the information about the at least one PLMN.

[0014] It is to be understood that the Summary is not intended to identify key or essential features of example embodiments of the disclosure, nor is it intended to limit the scope of the disclosure. Other features of the disclosure will be readily apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0015] Some example embodiments will now be described with reference to the drawings, in which:

[0016] Figures 1A-1D a communication network in which example embodiments of the disclosure can be implemented is illustrated;

[0017] Figure 2 a signalling diagram illustrating an example implementation of a procedure for obtaining security information for relay discovery in a 5G ProSe U2N relay scenario is illustrated;

[0018] Figure 3 a signalling diagram illustrating a procedure for protecting relay discovery according to some example embodiments of the disclosure is illustrated;

[0019] Figure 4 a signalling diagram illustrating an example implementation of a procedure for protecting relay discovery according to some example embodiments of the disclosure is illustrated;

[0020] Figure 5 a flow diagram illustrating a method implemented at a first network device according to some example embodiments of the disclosure is illustrated;

[0021] Figure 6 a flow diagram illustrating a method implemented at a second network device according to some example embodiments of the disclosure is illustrated;

[0022] Figure 7a simplified block diagram of an apparatus suitable for implementing example embodiments of the present disclosure; and

[0023] Figure 8 a block diagram of an example computer-readable medium, in accordance with some example embodiments of the present disclosure.

[0024] Throughout the drawings, identical or similar reference numerals can designate identical or similar elements throughout the several views. DETAILED DESCRIPTION

[0025] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that these example embodiments are described for illustrative purposes only and help the skilled person to understand and implement the present disclosure and do not represent any limitation on the scope of the present disclosure. The disclosure described herein can be implemented in various other ways than those described below.

[0026] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0027] In the present disclosure, references to “one embodiment”, “an embodiment”, “example embodiments” etc. indicate that the embodiment described can include a particular feature, structure, or characteristic, but every embodiment can not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an example embodiment, it is submitted that it is within the knowledge of those skilled in the art to effect such feature, structure, or characteristic in connection with other example embodiments whether or not explicitly described.

[0028] It can be understood that, although the terms “first” and “second” etc. can be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element, without departing from the scope of the example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the associated terms.

[0029] The terminology used herein is for the purpose of describing particular example embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises," "comprising," "includes" and / or "including," when used herein, specify the presence of stated features, elements and / or components etc. but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0030] As used in this application, the term "circuitry" can refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable): (i) combinations of analog and / or digital hardware circuit(s) with software / firmware (ii) portions of hardware processor(s) with software (including digital signal processors); software, including digital signal processors); and memory parts) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but it does not require software to be present during operation.

[0031] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation that includes hardware-only circuit implementations (e.g., implementations in only analog hardware, or in only digital hardware) and / or implementations that include both hardware and software elements. For example, if a particular claim element makes reference to a baseband integrated circuit or processor integrated circuit for a mobile device, and such a claim element is intended to cover the case where only the hardware circuit, or only the processor (or a portion thereof) is used, then such a claim element does not foreclose a software implementation for an equivalent baseband integrated circuit or processor integrated circuit for a mobile device. In other words, the claim element is intended to cover all equivalents whether they are hardware-only or software-only or some combination of both.

[0032] As used herein, the term “communication network” refers to a network that follows any suitable communication standard, such as a fifth generation (5G) system, long term evolution (LTE), LTE-Advanced (LTE-A), wideband code division multiple access (WCDMA), high-speed packet access (HSPA), narrow band internet of things (NB-IoT), etc. Further, the communication between terminal devices and network devices in a communication network can be performed according to any suitable generation of communication protocol, including but not limited to first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G) new radio (NR) communication protocols, and / or any other protocols that are currently known or that will be developed in the future. Example embodiments of the present disclosure can be applied in various communication systems. In consideration of the rapid development of communication, there will of course be future types of communication technology and systems that can be used to embody the present disclosure. It should not be seen as limiting the scope of the present disclosure only to the above-described systems.

[0033] As used herein, the term “network device” refers to a node in a communication network, via which a terminal device accesses the network and receives services from the network. The network device can refer to a base station (BS) or an access point (AP), e.g., a NodeB (NB), an evolved NodeB (eNodeB or eNB), a NR Next Generation NodeB (gNB), a remote radio unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, a low power node (such as a femto, pico), etc. A radio access network (RAN) split architecture includes a gNB centralized unit (gNB-CU, which hosts radio resource control (RRC), service data adaptation protocol (SDAP), and packet data convergence protocol (PDCP)) that controls multiple gNB distributed units (gNB-DU, which hosts radio link control (RLC), medium access control (MAC), and physical layer (PHY)), depending on the terminology and technology applied.

[0034] As used herein, the term "network device" refers to a device capable of communicating with an access network device and providing services to terminal devices in a core network. Examples of core network devices can include a user plane function (UPF), an application server, a mobile switching center (MSC), a mobile management entity (MME), an operation and management (O&M) node, an operation support system (OSS) node, a self-organizing network (SON) node, a positioning node (such as an enhanced serving mobile location center (E-SMLC)), a mobile data terminal (MDT), a common control network function (CCNF), an access and mobility management function (AMF), a session management function (SMF), a policy control function (PCF), a location management function (LMF), a direct discovery name management function (DDNMF), and / or a ProSe key management function (PKMF).

[0035] The term "terminal device" refers to any end device capable of wireless communication. By way of example, and not limitation, a terminal device can also be referred to as a communication device, user equipment (UE), a subscriber station (SS), a portable subscriber station, a mobile station (MS), or an access terminal (AT). A terminal device can include, but is not limited to, a mobile telephone, a cellular telephone, a smart phone, a voice over Internet Protocol (VoIP) phone, a wireless local loop phone, a tablet, a wearable terminal device, a personal digital assistant (PDA), a portable computer, a desktop computer, an image capture terminal device, such as a digital camera, a game terminal device, a music storage and playback appliance, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a laptop-embedded equipment (LEE), a laptop-mounted equipment (LME), a USB dongle, a smart device, a wireless customer-premise equipment (CPE), an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical appliance or application, such as a remote surgery appliance or application, an industrial appliance or application, such as a robot or other wireless devices operating in an industrial and / or an automated processing chain environment, a consumer electronics, a device operating on a commercial and / or industrial wireless network, etc. In the following description, the terms "terminal device," "communication device," "terminal," "user equipment," and "UE" can be used interchangeably.

[0036] Although in various example embodiments the functionality described herein can be performed in fixed and / or wireless network nodes, in other example embodiments the functionality can be implemented in user equipment devices such as mobile phones or tablets or laptops or desktop computers or mobile loT devices or fixed loT devices. For example, the user equipment devices can be equipped with corresponding functionality related to the fixed and / or wireless network node(s) as needed. The user equipment devices can be user equipment and / or control devices such as chipsets or processors configured to control the user equipment when installed in the user equipment. Examples of such functionality include bootstrap server functionality and / or home subscriber server, which can be implemented in the user equipment devices by providing the user equipment devices with software configured to cause the user equipment devices to perform from the perspective of these functionalities / nodes.

[0037] Figures 1A-1D Example communication environments 100A-100D in which example embodiments of the present disclosure can be implemented are shown.

[0038] Each of the environments 100A-100D can be part of a communication network. Each of the environments 100A, 100B, and 100D can include a first serving public land mobile network (SPLMN) 102, a first home PLMN (HPLMN) 104, and a second SPLMN 106. The environment 100C includes the first SPLMN 102 and the second SPLMN 106.

[0039] The terminal device 140 can communicate with a PKMF device or a DDNMF device 160 in the second SPLMN 106.

[0040] In the environment 100A, the terminal device 110 can communicate with a first network device 120 and a second network device 130 in the first SPLMN 102 and with a third network device 150 in the home HPLMN 104. The first network device 120 can be a visited PCF (V-PCF) device, the second network device 130 can be a DDNMF device or a PKMF device, and the third network device 150 can be a home PCF (H-PCF) device.

[0041] Environment 100B is similar to environment 100A. Environment 100B differs from environment 100A in that the first network device 120 can be a Home-PCF (H-PCF) device, the second network device 130 can be a V-PCF device, and the first SPLMN 102 further includes a PKMF device or a DDNMF device 170. The terminal device 110 can communicate with the PKMF device or DDNMF device 170, the second network device 130 in the first SPLMN 102, and the first network device 120 in the home HPLMN 104.

[0042] Environment 100C is similar to environment 100A. Environment 100C differs from environment 100A in that the first SPLMN 102 is the same as the first HPLMN 104. In this case, the first network device 120 can be a H-PCF device, and the second network device 130 can be a DDNMF device or a PKMF device. The terminal device 110 can communicate with the first network device 120 and the second network device 130 in the first SPLMN 102.

[0043] Environment 100D is similar to environment 100C. Environment 100D differs from environment 100C in that the first SPLMN 102 is different from the first HPLMN 104. In this case, the first network device 120 can be a H-PCF device, and the second network device 130 can be a DDNMF device or a PKMF device. The terminal device 110 can communicate with the first network device 120 in the first HPLMN 104 and the second network device 130 in the first SPLMN 102.

[0044] It should be appreciated that the number of devices is merely for ease of understanding and does not represent any limitation. The communication environments 100A-100D can include any suitable number or type of devices suitable for implementing embodiments of the present disclosure.

[0045] Communications in the communication environments 100A-100D can be implemented according to any suitable communication protocol(s), including but not limited to, first generation (1G), second generation (2G), third generation (3G), fourth generation (4G), fifth generation (5G), or future sixth generation (6G) cellular communication protocols, wireless local area network communication protocols (such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, etc.), and / or any other protocol that is currently known or that will be developed in the future. Moreover, communications can utilize any suitable wireless communication techniques, including but not limited to: code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplexing (FDD), time division duplexing (TDD), multiple-input multiple-output (MIMO), orthogonal frequency division multiplexing (OFDM), discrete Fourier transform spread OFDM (DFT-s-OFDM), and / or any other techniques that are currently known or that will be developed in the future.

[0046] In some example embodiments, the communication environments 100A-100D can support a ProSe feature, such as 5G ProSe, 4G ProSe, etc. In the following, example embodiments of the present disclosure will be described with 5G ProSe as an example. However, the present disclosure can be applicable to 4G ProSe or any future ProSe.

[0047] The 5G ProSe feature can include: 5G ProSe direct discovery, 5G ProSe direct communication, 5G ProSe U2N relay, and 5G ProSe U2U relay.

[0048] In the 5G ProSe U2N relay feature, the terminal device 110 can be connected to the terminal device 140 via a PC5 interface with 5G ProSe direct communication, and communicate with a data network via the terminal device 140 and a 5G network. In this regard, the terminal device 110 can be referred to as a remote terminal device or remote UE, and the terminal device 140 can be referred to as a U2N relay. In some example embodiments, the terminal device 110 and the terminal device 140 can perform a 5G ProSe direct discovery procedure using security information for 5G ProSe U2N relay discovery.

[0049] In the 5G ProSe U2U relay feature, the terminal device 110 can communicate with another terminal device (not shown) via the terminal device 140. In this regard, the terminal device 110 and the other terminal device can be referred to as end terminal devices or end UEs, and the terminal device 140 can be referred to as a U2U relay. One of the terminal device 110 and the other terminal device can act as a source terminal device or source UE, and the other can act as a target terminal device or target UE.

[0050] In some example embodiments, a final terminal device, such as a source terminal device or a target source terminal device, and the terminal device 140 can perform a 5G ProSe direct discovery procedure using the security information for 5G ProSe U2U relay discovery.

[0051] Figure 2 A signaling diagram is illustrated, which illustrates a procedure 200 for acquiring security information for relay discovery in a 5G ProSe U2N relay scenario.

[0052] Generally, in the procedure 200, the HPLMN of a potential ProSe U2N relay is determined either with local configuration or from a remote UE's PCF. Then, the HPLMN is used to discover the DDNMF / PKMF of the potential ProSe U2N relay, and acquire security parameters to protect the U2N relay discovery messages.

[0053] Specifically, at 210, the U2N relay 203 sends a discovery key request to its DDNMF / PKMF 209 to acquire security information for relay discovery to protect the PC5 discovery messages. The request can include a Relay Service Code (RSC) and security capabilities of the U2N relay 203.

[0054] Then, the DDNMF / PKMF 209 of the U2N relay 203 generates a relay restricted identifier (ID) for the U2N relay 203 with a validity timer. The relay restricted ID is associated with the RSC and a relay ID for discovery of the U2N relay 203. In the following, for brevity, the relay ID for discovery is also referred to as "relay ID". For example, the relay ID can include an HPLMN ID of the U2N relay 203, such as PLMN ID #2. Then, the DDNMF / PKMF 209 acquires security information associated with the relay restricted ID. For example, the DDNMF / PKMF 209 can generate security parameters and select a PC5 encryption algorithm.

[0055] At 212, the DDNMF / PKMF 209 sends a discovery key response to the U2N relay 203. The response includes: the RSC, ProSe Restriction Code and validity timer, code specific security parameters and selected PC5 encryption algorithm, CURRENT TIME, MAX OFFSET, and optionally PC5 security policy.

[0056] At 214, the remote UE 201 sends a discovery key request to its DDNMF / PKMF 205 to acquire security information for relay discovery to protect the PC5 discovery messages. The request can include: a UE identifier of the remote UE 201, the RSC, and security capabilities of the remote UE 201.

[0057] At 216, the DDNMF / PKMF 205 of the remote UE 201 sends a request to its PCF device 207 to get the ID of the HPLMN supporting the RSC for the remote UE 201. The request can include the UE identifier of the remote UE 201 and the RSC. The request is also referred to as “Get HPLMN of potential relay request”.

[0058] At 218, the PCF device 207 of the remote UE 201 locally gets the HPLMN of potential relay based on the RSC.

[0059] At 220, the PCF device 207 of the remote UE 201 sends a response to the DDNMF / PKMF 205. The response is also referred to as “Get HPLMN response”. The response can include the UE identifier of the remote UE 201, the RSC, and the list of PLMN IDs.

[0060] At 222, the DDNMF / PKMF 205 of the remote UE 201 generates the Relay Restricted id and gets the Code Security parameters linked to the PLMN id.

[0061] At 224, the DDNMF / PKMF 205 of the remote UE 201 sends a discovery key request to the DDNMF / PKMF 209 of the HPLMN 120 to get the security information associated with the RSC. The request can include the security capabilities of the remote UE 201 and the RSC. At 226, the DDNMF / PKMF 205 of the remote UE 201 receives a discovery key response from the DDNMF / PKMF 209 of the U2N relay 203. The response can include the list of Relay Restricted IDs with corresponding validity timer, Code Security parameters, and PC5 encryption algorithms. Actions 224 and 226 are repeated for each PLMN of potential relay associated with the RSC.

[0062] At 228, the DDNMF / PKMF 205 of the remote UE 201 builds the list of Relay Restricted IDs with corresponding validity timer, Code Security parameters, DUIK, and PC5 encryption algorithms.

[0063] At 230, the DDNMF / PKMF 205 of the remote UE 201 sends a discovery key response to the remote UE 201. The response can include the RSC, optional PC5 security policy, CURRENT_TIME, MAX_OFFSET, the list of (Relay Restricted ID, validity timer, Code-Rcv-SecParams (i.e., security parameters), selected PC5 encryption algorithms).

[0064] At 232, the remote UE 201 and the U2N relay 203 perform relay discovery over PC5. The discovery message is protected by at least one set of security information. Each security information in the at least one set of security information is associated with a relay restricted ID, which is per each RSC for each relay.

[0065] Thus, it is allowed to support the acquisition of discovery security parameters from a DDNMF / PKMF in the HPLMN of the remote UE and potential U2N relay. Thus, in such 5G ProSe U2N relay scenario, for performing 5G ProSe direct communication between the remote UE and the U2N relay, the remote UE and the U2N relay can perform a 5G ProSe direct discovery procedure using the acquired security parameters for 5G ProSe U2N relay discovery.

[0066] Likewise, in 5G U2U relay scenario, the 5G ProSe final UE (such as source UE or target UE) and the U2U relay can perform a 5G ProSe direct discovery procedure using the acquired security information for 5G ProSe U2U relay discovery.

[0067] When these UEs are registered to the 5G network, the 5G ProSe remote UE, the 5G ProSe U2N relay UE, the 5G ProSe final UE and the 5G ProSe U2U relay UE are provisioned with authorization related information by the corresponding PCF in the HPLMN of the UE.

[0068] The basic principles of service authorization and regulation for 5G ProSe direct discovery, 5G ProSe direct communication, 5G ProSe U2N relay, and 5G ProSe U2U relay services are as follows:

[0069] - The PCF in the HPLMN can configure a list of PLMNs in which the UE is authorized to use 5G ProSe direct discovery.

[0070] - The PCF in the HPLMN can configure a list of PLMNs in which the UE is authorized to use 5G ProSe direct communication.

[0071] - The PCF in the HPLMN can configure a list of PLMNs in which the UE is authorized to act as a 5G ProSe U2N relay. The authorization of 5G ProSe layer 2 U2N relay and 5G ProSe layer 3 U2N relay is independent of each other.

[0072] - The PCF in the HPLMN can configure a PLMN list in which the UE is authorized to access 5GC via 5G ProSe U2N relay (i.e., acting as 5G ProSe Remote UE). The authorization for access via 5G ProSe Layer 2 U2N relay and via 5G ProSe Layer 3 U2N relay are independent of each other.

[0073] - The PCF in the HPLMN can configure a PLMN list in which the UE is authorized to act as 5G ProSe U2U relay. The authorization for 5G ProSe Layer 2 U2U relay and 5G ProSe Layer 3 U2U relay are independent of each other.

[0074] - The PCF in the HPLMN can configure a PLMN list in which the UE is authorized to access 5G ProSe U2U relay (i.e., acting as 5G ProSe Final UE). The authorization for access via 5G ProSe Layer 2 U2U relay and via 5G ProSe Layer 3 U2U relay are independent of each other.

[0075] - The PCF in the HPLMN consolidates authorization information from home and other PLMNs and provides the final authorization information to the UE.

[0076] - The PCF in the VPLMN or HPLMN can revoke authorization at any time (via H-PCF when roaming) by using the UE configuration update procedure to implement a transparent UE policy delivery procedure.

[0077] Only 5G ProSe Layer 2 U2U / U2N services require configuration of a PLMN list in which the UE is authorized to access 5G ProSe U2U / U2N relay, as ProSe Final UE / Remote UE only checks authorization to access a PLMN in 5G ProSe Layer 2 U2U / U2N scenarios, but not necessarily in 5G ProSe Layer 3 U2U / U2N scenarios.

[0078] In some scenarios, especially for ProSe U2U relay discovery introduced in Release 18 (Rel-18), a ProSe Final UE (such as a source UE or a target UE) and a U2U UE relay can connect to a PKMF in its SPLMN to obtain discovery security parameters. If the PKMFs serving the U2U relay UE and the final UE are located in different SPLMNs, the PKMF of the final UE cannot locate the PKMF of the U2U relay UE.

[0079] Therefore, when a discovery key request from an ultimate / remote UE is received, there is a need for an improved method for the ultimate / remote UE’s PKMF to acquire the serving PLMN of a potential U2U / U2N relay. Then, the ultimate / remote UE’s PKMF can discover the PKMF(s) of the potential U2U / U2N relay UE and acquire the corresponding security parameters for U2U / U2N relay discovery.

[0080] The present disclosure provides a solution for relay discovery for service network driven scenario. According to the solution, a first network device receives, from a second network device, a request for information about at least one PLMN in which a terminal device is authorized to use a relay service. Then, the first network device acquires the information about the at least one PLMN based on the request. Further, the first network device sends, to the second network device, a response including the information about the at least one PLMN. In this way, the second network device can discover a target DDNMF or PKMF and acquire security parameters for U2U / U2N relay discovery. Therefore, relay discovery security can be ensured and thus communication performance and communication efficiency can be improved.

[0081] Hereinafter, the principles of the present disclosure will be described with reference to Figures 3-8

[0082] Figure 3 A signaling diagram of a procedure 300 for protecting relay discovery according to some example embodiments of the present disclosure is illustrated. For the purpose of discussion, the procedure 300 will be described with reference to Figures 1A-1D The first network device 120 is a visited PCF device located in a first SPLMN 102 of a terminal device 110, and the second network device 130 can be a DDNMF device or a PKMF device located in the first SPLMN 102 of the terminal device 110, as shown in Figure 1A

[0083] In such example embodiments, after receiving the request from the second device 130, the first network device 120 can forward the request to a third network device 150 (acting as an H-PCF device) in a first HPLMN 104 of the terminal device 110, if the SPLMN 102 is different from the HPLMN 104. The third network device 150 can be preconfigured or provisioned with the information about the at least one PLMN. Then, the third network device 150 can determine the information and send it to the first network device 120. Therefore, the first network device 120 can acquire the information about the at least one PLMN from the third network device 150.

[0084] ​​Alternatively, the first network device 120 can be pre-configured, provisioned, or cached with information about at least one PLMN. In this case, the first network device 120 can determine the information based on the request and its local configuration. For example, the first network device 120 can determine the information based on at least one of: an identifier of the terminal device 110, the RSC, an identifier of the first SPLMN 102 of the terminal device 110, the relay indicator, and its local configuration.

[0085] Alternatively, in some example embodiments, the first network device 120 can be an H-PCF device located in the first HPLMN 104 of the terminal device 110, and the second network device 130 can be a V-PCF device located in the first SPLMN 102 of the terminal device 110, as shown in FIG. 1. Figure 1B

[0086] In such example embodiments, the second network device 130 can receive the request for information about at least one PLMN from the PKMF device or the DDNMF device 170. The second network device 130 can forward the request to the first network device 120.

[0087] The first network device 120 can be pre-configured or provisioned with information about at least one PLMN. Accordingly, the first network device 120 can determine the information based on the received request and its local configuration. For example, the first network device 120 can determine the information based on at least one of: an identifier of the terminal device 110, the RSC, an identifier of the first SPLMN 102 of the terminal device 110, the relay indicator, and its local configuration.

[0088] Alternatively, in some example embodiments, the first SPLMN 102 is the same as the first HPLMN 104, the first network device 120 can be an H-PCF device located in the first SPLMN 102 of the terminal device 110, and the second network device 130 can be a DDNMF device or a PKMF device located in the first SPLMN 102, as shown in FIG. 1. In such example embodiments, the second network device 130 can send the request for information about at least one PLMN directly to the first network device 120. Then, the first network device 120 can determine the information in a similar manner as described above with reference to Figure 1C Figure 1B Thus, for brevity, details of the determination of the information are omitted.

[0089] ​​Alternatively, in some example embodiments, the first SPLMN 102 is different from the first HPLMN 104, the first network equipment 120 can be an H-PCF device located in the first HPLMN 104 of the terminal device 110, and the second network equipment 130 can be a DDNMF device or a PKMF device located in the first SPLMN 102, as shown in Figure 1D Figure 1B In such example embodiments, the second network equipment 130 can send the request for the information about the at least one PLMN directly to the first network equipment 120. The first network equipment 120 can then determine the information in a similar manner as described above with reference to Figure 1B Thus, for brevity, details of the determination of the information are omitted.

[0090] As shown in Figure 3 The first network equipment 120 sends (315) a response including the information about the at least one PLMN to the second network equipment 130. Thus, the second network equipment 130 receives the response from the first network equipment 120.

[0091] In some example embodiments, the response can include an identifier of the terminal device 110. Alternatively or additionally, the response can include an RSC.

[0092] In some example embodiments, the information can include a list of PLMNs (also referred to as a first list of PLMNs) associated with the RSC. For example, the first list of PLMNs can include at least one of: a first list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 2 relays, a second list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 3 relays, a third list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 2 relays, or a fourth list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 3 relays.

[0093] Alternatively or additionally, the information can comprise a set of PLMN lists (also referred to as a first set of PLMN lists), and each of the PLMN lists can be associated with a relay indicator. For example, the first set of PLMN lists can comprise at least one of: a first list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 2 relays, a second list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 3 relays, a third list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 2 relays, or a fourth list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 3 relays.

[0094] It will be appreciated that the authorization to access 5G ProSe U2N layer 3 relays via 5G ProSe U2N layer 3 relays, to access 5G ProSe U2U layer 2 relays via 5G ProSe U2U layer 2 relays, and to access 5G ProSe U2N layer 2 relays via 5G ProSe U2U layer 3 relays can be independent of each other.

[0095] Based on the information about the at least one PLMN in which the terminal device 110 is authorized to use relay services, the second network device 130 can locate one or more network devices (e.g., a PKMF device or a DDNMF device) that serve potential ProSe U2U / U2N relay terminal devices (e.g., the fourth network device 160). The second network device 130 can obtain security parameters for U2U / U2N relay discovery from the located network devices that serve potential ProSe U2U / U2N relay terminal devices. The second network device 130 can then construct a discovery key response with the security parameters and return it to the terminal device 110.

[0096] In some example embodiments, the second network device 130 can subscribe to the first network device 120 for updates or changes to the information about the at least one PLMN. For example, the second network device 130 can send a subscription request to the first network device 120 for updates to the information about the at least one PLMN. Then, if it is determined that the information is updated, the first network device 120 can send a subscription notification including the updated information to the second network device 130.

[0097] For example, the subscription request can comprise an identifier of the terminal device 110. Alternatively or additionally, the subscription request can comprise an RSC. Alternatively or additionally, the subscription request can comprise a relay indicator.

[0098] As an example, the relay indicator can comprise at least one of: a 5G ProSe U2N relay indicator; a 5G ProSe U2U relay indicator; a 5G ProSe layer 2 relay indicator; a 5G ProSe layer 3 relay indicator; a 5G ProSe U2N layer 2 relay indicator; a 5G ProSe U2N layer 3 relay indicator; a 5G ProSe U2U layer 2 relay indicator; or a 5G ProSe U2U layer 3 relay indicator.

[0099] As an example, the subscription notification can comprise an identifier of the terminal device 110. Alternatively or additionally, the subscription notification can comprise the RSC.

[0100] In some example embodiments, the updated information can comprise a further list of PLMNs (also referred to as a second list of PLMNs) associated with the RSC. The second list of PLMNs can comprise at least one of: the first updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 2 relays, the second updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 3 relays, the third updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 2 relays, or the fourth updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 3 relays.

[0101] Alternatively or additionally, the updated information can comprise a further set of lists of PLMNs (also referred to as a second set of lists of PLMNs), and each list of PLMNs of the set of lists of PLMNs can be associated with a relay indicator. For example, the second set of lists of PLMNs can comprise at least one of: the first updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 2 relays, the second updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2N layer 3 relays, the third updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 2 relays, or the fourth updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe U2U layer 3 relays.

[0102] In some example embodiments, the first network device 120 can subscribe the second network device 130 to more than one terminal device. In this case, the second network device 130 can send multiple sets of PLMN list to the first network device 120, and each of the multiple sets can be associated with one of the more than one terminal device.

[0103] In some example embodiments, the first network device 120 can include a new service to enable the second network device 130 to get a (service) PLMN in which the terminal device 110 is authorized to access 5G ProSe U2U / U2N relay. Alternatively or additionally, the first network device 120 can include a new service to enable the second network device 130 to subscribe to be notified of a change of authorization (service) PLMN. The service to get a PLMN in which the terminal device 110 is authorized to access 5G ProSe U2U relay and the service to get a PLMN in which the terminal device 110 is authorized to access 5G ProSe U2N relay can be different services, or can be the same service but with different input parameters.

[0104] In some example embodiments, a new reference point can be provided between the first network device 110 and the second network device 120. The new reference point can be used to define the interaction between the first network device 110 and the second network device 120 to get the authorized PLMN from the first network device 110.

[0105] In this way, the security procedure of 5G ProSe U2U / U2N relay discovery can be enhanced.

[0106] Figure 4 A signaling diagram is illustrated, which illustrates an example procedure 400 for protecting relay discovery according to some example embodiments of the present disclosure. It should be appreciated that the procedure 400 can be considered as an example implementation of the procedure 300 as Figure 3 illustrated. For the purpose of discussion, the procedure 400 will be described with reference to Figure 1A the example of the procedure 300. In the procedure 400, the remote / ultimate UE 401 can be an example of the terminal device 110 in Figure 1A the PKMF 403 can be an example of the second network device 130 in Figure 1A the PCF 405 can be an example of the first network device 120 in Figure 1A the U2N / U2U relay 407 can be an example of the terminal device 140 in Figure 1A and the PKMF 409 can be an example of the PKMF device 160 in Figure 1A .

[0107] As Figure 4As shown in the middle, at 410, the U2N / U2U relay 407 sends a discovery key request to the PKMF 409 in its SPLMN 106 to obtain a discovery key to protect PC5 discovery messages.

[0108] The PKMF 409 of the U2N / U2U relay 407 generates security parameters and selects a PC5 encryption algorithm, and then sends a discovery key response to the U2N / U2U relay 407 at 412.

[0109] At 414, the remote / destination UE 401 sends a discovery key request to the PKMF 403 in its SPLMN 102. The discovery key request includes an identifier of the remote / destination UE 401, an RSC, and security capabilities of the remote / destination UE 401.

[0110] At 416, the PKMF 403 of the remote / destination UE 401 sends a request to the PCF 405 in its SPLMN 102 to obtain information about at least one PLMN in which the remote / destination UE 401 is authorized to access a 5G ProSe U2N relay and / or a U2U relay. For example, the request can include: an identifier of the remote / destination UE 401; at least one of: a 5G ProSe U2N relay indicator, a 5G ProSe U2U relay indicator, a 5G ProSe layer 2 relay indicator, a 5G ProSe layer 3 relay indicator, a 5G ProSe U2N layer 2 relay indicator, a 5G ProSe U2N layer 3 relay indicator, a 5G ProSe U2U layer 2 relay indicator, or a 5G ProSe U2U layer 3 relay indicator; an RSC; and an ID of the SPLMN 102 of the remote / destination UE 401.

[0111] At 418, the PCF 405 of the remote / destination UE 401 obtains information about at least one PLMN in which the remote / destination UE 401 is authorized to access a 5G ProSe U2N relay and / or a U2U relay, according to input parameters in the request from the remote / destination UE 401. For example, the PCF 405 can obtain information about at least one PLMN based on the identifier of the remote / destination UE 401, the RSC, at least one of the 5G ProSe relay indicators as described with respect to action 416, and the ID of the SPLMN 102 of the remote / destination UE 401.

[0112] For example, the PCF 405 can act as a V-PCF. In this case, the PCF 405 can forward the request to the third network equipment 150 (acting as an H-PCF) and obtain the information about the at least one PLMN in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2N relay and / or U2U relay from the third network equipment 150.

[0113] Alternatively, the PCF 405 can be a serving PCF (in case the SPLMN 102 is the same as the HPLMN 104) or an H-PCF (in case the SPLMN 102 is different from the HPLMN 104), which can be preconfigured with the information about the at least one PLMN in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2N relay and / or U2U relay. Thus, the PCF 405 can obtain the information based on the request and the local configuration.

[0114] At 420, the PCF 405 sends a response to the PKMF 403. The response includes: an identifier of the remote / ultimate UE 401; and at least one of: a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2N layer 2 relay, a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2N layer 3 relay, a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2U layer 2 relay, a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2U layer 3 relay. Optionally, the response includes the RSC.

[0115] At 422, the PKMF 403 of the remote / ultimate UE 401 sends a discovery key request (e.g., along with other PKMF(s) of potential relay(s)) to the PKMF 409 of the U2N / U2U relay 407. The request can include the security capabilities of the remote / ultimate UE 401 and the RSC. The PKMF 403 of the remote / ultimate UE 401 determines or locates the PKMF 409 of the U2N / U2U relay 407 and other PKMF(s) of potential relay(s) based on the list of PLMNs received from the PCF 405 at action 420.

[0116] At 424, the PKMF 403 of the remote / destination UE 401 receives a discovery key response from the PKMF 409 of the U2N / U2U relay 407 (e.g., along with other PKMF(s) of potential relay(s)). The response includes security parameters and a selected PC5 encryption algorithm. For example, the security parameters include Code-SecParams and a discovery user integrity key (DUIK). Actions 422 and 424 can be repeated for each PLMN in the list of PLMNs received at action 420.

[0117] At 426, the PKMF 403 of the remote / destination UE 401 sends a discovery key response to the remote / destination UE 401. The response includes the RSC, an optional PC5 security policy, CURRENT TIME, MAX OFFSET, Code-SecParams, and a selected PC5 encryption algorithm. The Code-SecParams can be associated with authorized PLMN(s). The security-related information, such as Code-SecParams and the selected PC5 encryption algorithm, is constructed from the security parameters received from the PKMF(s) of potential relay(s) at actions 422 and 424.

[0118] At 428, the remote / destination UE 401 and the U2N / U2U relay 407 perform discovery over PC5. The discovery messages are protected with the specific security parameters and the selected PC5 encryption algorithm.

[0119] At 430, the PKMF 403 of the remote / destination UE 401 subscribes to the PCF 405 of the remote / destination UE 401 to receive notification of a change in a PLMN in which the remote / destination UE 401 is authorized to access 5G ProSe U2N relay and / or U2U relay. The request includes an identifier of the remote / destination UE 401; and at least one of the following: a 5G ProSe U2N relay indicator, a 5G ProSe U2U relay indicator, a 5G ProSe layer 2 relay indicator, a 5G ProSe layer 3 relay indicator, a 5G ProSe U2N layer 2 relay indicator, a 5G ProSe U2N layer 3 relay indicator, a 5G ProSe U2U layer 2 relay indicator, and a 5G ProSe U2U layer 3 relay indicator.

[0120] At 432, if there is a change in a PLMN in which the remote / destination UE 401 is authorized to access 5G ProSe U2N relay and / or U2U relay, the PCF 405 checks the subscription, updates the authorized PLMN of the remote / destination UE 401, and generates a notification accordingly.

[0121] At 434, the PCF 405 sends the notification to the PKMF 403. The notification includes: an identifier of the remote / ultimate UE 401; at least one of: a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2N layer 2 relay, a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2N layer 3 relay, a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2U layer 2 relay, a list of PLMNs in which the remote / ultimate UE 401 is authorized to access 5G ProSe U2U layer 3 relay; and optionally, the RSC.

[0122] It should be appreciated that Figure 4 Actions 430, 432, and 434 are shown as being performed after action 428 by way of example. In other example embodiments, actions 430, 432, and 434 are performed after action 420 and before action 422. Alternatively, actions 430, 432, and 434 are performed after any one of actions 422, 424, 426, and 428.

[0123] It should be appreciated that process 400 has been described by way of example with respect to Figure 1A In other example embodiments, process 400 can also be applied to environments 100B-100D in Figures 1B-1D For brevity, details of these example embodiments are omitted.

[0124] In some example embodiments, process 400 can be performed after using a “user plane” security solution.

[0125] In some example embodiments, Figure 4 Each of the PKMF 403 and the PKMF 409 in can be replaced with a DDNMF. In such example embodiments, process 400 can be performed after using a “control plane” security solution.

[0126] In some example embodiments, the procedure 400 can be applied to a Model A relay discovery procedure. A procedure similar to the procedure 400 can be applied to a Model B relay discovery procedure. In the Model B relay discovery procedure, a remote UE (such as the remote / destination UE 401) sends a relay request message, a relay UE (such as the U2N / U2U relay 407) sends a relay response message, and the remote UE can send multiple relay request messages, and each relay request message is protected using security information corresponding to a PLMN of a potential relay UE. Alternatively, in another solution, a PKMF of a relay UE can apply a procedure similar to the procedure 400 to obtain and construct security information of a potential remote / destination UE. In this solution, the remote UE only needs to send one relay request message, and the relay UE uses the corresponding security information to process the request message received from the remote UE.

[0127] Figure 5 A flowchart illustrating an example method 500 implemented at a first network device, in accordance with some example embodiments of the present disclosure, is shown. For purposes of discussion, the method 500 will be described with reference to any one of the first network devices 120. Figures 1A-1D The method 500 will be described from the perspective of the first network device 120.

[0128] At block 510, the first network device 120 receives, from a second network device 130, a request for information about at least one PLMN for which a terminal device 110 is authorized to use a relay service. At block 520, the first network device 120 obtains the information about the at least one PLMN based on the request. At block 530, the first network device 120 sends, to the second network device 130, a response including the information about the at least one PLMN.

[0129] In some example embodiments, the request can include at least one of: an identifier of the terminal device 110; a relay indicator; a relay service code (RSC); or an identifier of a serving PLMN of the terminal device 110.

[0130] In some example embodiments, the relay indicator can include at least one of: a fifth generation (5G) proximity-based services (ProSe) user equipment (UE) to network relay indicator; a 5G ProSe UE to UE relay indicator; a 5G ProSe layer 2 relay indicator; a 5G ProSe layer 3 relay indicator; a 5G ProSe UE to network layer 2 relay indicator; a 5G ProSe UE to network layer 3 relay indicator; a 5G ProSe UE to UE layer 2 relay indicator; or a 5G ProSe UE to UE layer 3 relay indicator.

[0131] In some example embodiments, the response can further comprise an identifier of the terminal device 110.

[0132] In some example embodiments, the information can comprise a first list of PLMNs associated with a Relay Service Code (RSC). Alternatively or additionally, the information can comprise a first set of PLMN lists, each of the PLMN lists being associated with a Relay Indicator.

[0133] In some example embodiments, the first list of PLMNs or the first set of PLMN lists can comprise at least one of: a first list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-Network Layer 2 relaying, a second list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-Network Layer 3 relaying, a third list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-UE Layer 2 relaying, or a fourth list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-UE Layer 3 relaying.

[0134] In some example embodiments, the first network device 120 can further receive, from the second network device 130, a subscription request for an update of the information about the at least one PLMN; and based on determining that the information is updated, transmit, to the second network device 130, a subscription notification comprising the updated information.

[0135] In some example embodiments, the subscription request can comprise at least one of: an identifier of the terminal device 110; a Relay Service Code (RSC); or a Relay Indicator.

[0136] In some example embodiments, the subscription notification can comprise an identifier of the terminal device 110.

[0137] In some example embodiments, the updated information can comprise a second list of PLMNs associated with a Relay Service Code (RSC). Alternatively or additionally, the updated information can comprise a second set of PLMN lists, each of the PLMN lists being associated with a Relay Indicator.

[0138] In some example embodiments, the second list of PLMNs or the second set of the list of PLMNs can comprise at least one of: a first updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-Network layer 2 relay; a second updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-Network layer 3 relay; a third updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-UE layer 2 relay; or a fourth updated list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-UE layer 3 relay.

[0139] In some example embodiments, the first network device 120 can be a home policy control function (PCF) device located in a home PLMN of the terminal device 110, and the second network device 130 can be a visited PCF device, a direct discovery name management function (DDNMF) device, or a proximity-based service (ProSe) key management function (PKMF) device located in a serving PLMN of the terminal device 110.

[0140] In some example embodiments, the first network device 120 can be a visited PCF device located in a serving PLMN of the terminal device 110, and the second network device 130 can be a direct discovery name management function (DDNMF) device, or a proximity-based service (ProSe) key management function (PKMF) device located in the serving PLMN of the terminal device 110.

[0141] In some example embodiments, the first network device 120 can further forward the request to a third network device in the home PLMN of the terminal device 110; and to obtain the information of the at least one PLMN, the first network device 120 can obtain the information of the at least one PLMN from the third network device.

[0142] Figure 6 A flowchart of an example method 600 implemented at a second network device according to some example embodiments of the present disclosure is shown. For purposes of discussion, the method 600 will be described with reference to any one of the Figures 1A-1D The method 600 will be described from the perspective of the second network device 130.

[0143] At block 610, the second network device 130 sends, to the first network device 120, a request for information about at least one public land mobile network (PLMN) in which the terminal device 110 is authorized to use a relay service. At block 620, the second network device 130 receives, from the first network device 120, a response that includes information about the at least one PLMN.

[0144] In some example embodiments, the request can include at least one of: an identifier of the terminal device 110; a relay indicator; a relay service code (RSC); or an identifier of a serving PLMN of the terminal device 110.

[0145] In some example embodiments, the relay indicator can include at least one of: a fifth generation (5G) proximity-based services (ProSe) user equipment (UE) to network relay indicator; a 5G ProSe UE to UE relay indicator; a 5G ProSe layer 2 relay indicator; a 5G ProSe layer 3 relay indicator; a 5G ProSe UE to network layer 2 relay indicator; a 5G ProSe UE to network layer 3 relay indicator; a 5G ProSe UE to UE layer 2 relay indicator; or a 5G ProSe UE to UE layer 3 relay indicator.

[0146] In some example embodiments, the response can include an identifier of the terminal device 110.

[0147] In some example embodiments, the information includes: a first list of PLMNs associated with a relay service code (RSC). Alternatively or additionally, the information can include a first set of PLMN lists, each of the PLMN lists being associated with a relay indicator.

[0148] In some example embodiments, the first list of PLMNs or the first set of PLMN lists can include at least one of: a first list of PLMNs in which the terminal device 110 is authorized to access a 5G ProSe UE to network layer 2 relay, a second list of PLMNs in which the terminal device 110 is authorized to access a 5G ProSe UE to network layer 3 relay, a third list of PLMNs in which the terminal device 110 is authorized to access a 5G ProSe UE to UE layer 2 relay, a fourth list of PLMNs in which the terminal device 110 is authorized to access a 5G ProSe UE to UE layer 3 relay.

[0149] In some example embodiments, the first network device 120 can further send, to the first network device 120, a subscription request for an update of the information about the at least one PLMN; and receive, from the first network device 120, a subscription notification including the updated information.

[0150] In some example embodiments, the subscription can include at least one of: an identifier of the terminal device 110; a relay service code (RSC); or a relay indicator.

[0151] In some example embodiments, the notification can include an identifier of the terminal device 110.

[0152] In some example embodiments, the updated information can include: a second list of PLMNs associated with a relay service code (RSC). Alternatively or additionally, the updated information can include a second set of PLMN lists, each of the PLMN lists being associated with a relay indicator.

[0153] In some example embodiments, the second list of PLMNs or the second set of PLMN lists can include at least one of: a first update list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-network layer 2 relays; a second update list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-network layer 3 relays; a third update list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-UE layer 2 relays; or a fourth update list of PLMNs in which the terminal device 110 is authorized to access 5G ProSe UE-to-UE layer 3 relays.

[0154] In some example embodiments, the first network device 120 can be a home policy control function (PCF) device located in a home PLMN of the terminal device 110, and the second network device 130 can be a visited PCF device, a direct discovery name management function (DDNMF) device, or a ProSe key management function (PKMF) device located in a serving PLMN of the terminal device 110.

[0155] In some example embodiments, the first network device 120 can be a visited PCF device located in a serving PLMN of the terminal device 110, and the second network device 130 can be a direct discovery name management function (DDNMF) device or a ProSe key management function (PKMF) device located in the serving PLMN of the terminal device 110.

[0156] In some example embodiments, an apparatus (e.g., the first network device 120) capable of performing any of the methods 500 can include means for performing the corresponding operations of the methods 500. The means can be implemented in any suitable form. For example, the means can be implemented in circuitry or software modules. The apparatus can be implemented as or included in the first network device 120. In some example embodiments, the means can include a processor and a memory.

[0157] In some example embodiments, the apparatus includes means for receiving, from a second network device, a request for information about at least one public land mobile network (PLMN) in which a terminal device is authorized to use a relay service; means for obtaining, based on the request, information about the at least one PLMN; and means for sending, to the second network device, a response including the information about the at least one PLMN.

[0158] In some example embodiments, the request includes at least one of: an identifier of the terminal device; a relay indicator; a relay service code (RSC); or an identifier of a serving PLMN of the terminal device.

[0159] In some example embodiments, the relay indicator includes at least one of: a fifth generation (5G) proximity-based services (ProSe) user equipment (UE) to network relay indicator; a 5G ProSe UE to UE relay indicator; a 5G ProSe layer 2 relay indicator; a 5G ProSe layer 3 relay indicator; a 5G ProSe UE to network layer 2 relay indicator; a 5G ProSe UE to network layer 3 relay indicator; a 5G ProSe UE to UE layer 2 relay indicator; or a 5G ProSe UE to UE layer 3 relay indicator.

[0160] In some example embodiments, the response further includes an identifier of the terminal device.

[0161] In some example embodiments, the information includes: a first list of PLMNs associated with a relay service code (RSC); or the information includes a first set of PLMN lists, each of the PLMN lists being associated with a relay indicator.

[0162] In some example embodiments, the first list of PLMNs or the first set of lists of PLMNs comprises at least one of: the first list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-Network Layer 2 relays, a second list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-Network Layer 3 relays, a third list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-UE Layer 2 relays, or a fourth list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-UE Layer 3 relays.

[0163] In some example embodiments, the apparatus further comprises means for receiving, from the second network device, a subscription request for an update to the information about the at least one PLMN; and means for transmitting, to the second network device, a subscription notification comprising the updated information based on a determination that the information is updated.

[0164] In some example embodiments, the subscription request comprises at least one of: an identifier of the terminal device; a relay service code (RSC); or a relay indicator.

[0165] In some example embodiments, the subscription notification comprises: an identifier of the terminal device.

[0166] In some example embodiments, the updated information comprises: a second list of PLMNs associated with a relay service code (RSC); or the updated information comprises a second set of lists of PLMNs, each of the lists of PLMNs being associated with a relay indicator.

[0167] In some example embodiments, the second list of PLMNs or the second set of lists of PLMNs comprises at least one of: a first updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-Network Layer 2 relays; a second updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-Network Layer 3 relays; a third updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-UE Layer 2 relays; or a fourth updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-UE Layer 3 relays.

[0168] In some example embodiments, the first network device is a home policy control function (PCF) device located in a home PLMN of the terminal device, and the second network device is a visited PCF device, a direct discovery name management function (DDNMF) device, or a proximity-based services (ProSe) key management function (PKMF) device located in a serving PLMN of the terminal device.

[0169] In some example embodiments, the first network device is a visited PCF device located in a serving PLMN of the terminal device, and the second network device is a direct discovery name management function (DDNMF) device or a proximity-based services (ProSe) key management function (PKMF) device located in the serving PLMN of the terminal device.

[0170] In some example embodiments, the apparatus further comprises means for forwarding the request to a third network device in a home PLMN of the terminal device; and the means for obtaining the information about the at least one PLMN comprises means for obtaining the information about the at least one PLMN from the third network device.

[0171] In some example embodiments, an apparatus (e.g., the second network device 130) capable of performing any of the methods 600 can include means for performing the corresponding operations of the methods 600. The means can be implemented in any suitable form. For example, the means can be implemented in circuitry or software modules. The apparatus can be implemented as or included in the second network device 130. In some example embodiments, the means can include a processor and a memory.

[0172] In some example embodiments, the apparatus comprises means for sending, to a first network device, a request for information about at least one public land mobile network (PLMN) in which a terminal device is authorized to use a relay service; and means for receiving, from the first network device, a response comprising the information about the at least one PLMN.

[0173] In some example embodiments, the request comprises at least one of: an identifier of the terminal device; a relay indicator; a relay service code (RSC); or an identifier of a serving PLMN of the terminal device.

[0174] In some example embodiments, the relay indicator comprises at least one of: a Fifth Generation (5G) Proximity-based Services (ProSe) User Equipment (UE) to network relay indicator; a 5G ProSe UE to UE relay indicator; a 5G ProSe Layer 2 relay indicator; a 5G ProSe Layer 3 relay indicator; a 5G ProSe UE to network Layer 2 relay indicator; a 5G ProSe UE to network Layer 3 relay indicator; a 5G ProSe UE to UE Layer 2 relay indicator; or a 5G ProSe UE to UE Layer 3 relay indicator.

[0175] In some example embodiments, the response comprises an identifier of the terminal device.

[0176] In some example embodiments, the information comprises: a first list of PLMNs associated with a Relay Service Code (RSC); or the information comprises a first set of lists of PLMNs, each of the lists of PLMNs being associated with a relay indicator.

[0177] In some example embodiments, the first list of PLMNs or the first set of lists of PLMNs comprises at least one of: a first list of PLMNs in which the terminal device is authorized to access a 5G ProSe UE to network Layer 2 relay, a second list of PLMNs in which the terminal device is authorized to access a 5G ProSe UE to network Layer 3 relay, a third list of PLMNs in which the terminal device is authorized to access a 5G ProSe UE to UE Layer 2 relay, a fourth list of PLMNs in which the terminal device is authorized to access a 5G ProSe UE to UE Layer 3 relay.

[0178] In some example embodiments, the apparatus further comprises: means for sending, to the first network device, a subscription request for an update of the information about the at least one PLMN; and means for receiving, from the first network device, a subscription notification comprising the updated information.

[0179] In some example embodiments, the subscription comprises at least one of: an identifier of the terminal device; a Relay Service Code (RSC); or a relay indicator.

[0180] In some example embodiments, the notification comprises an identifier of the terminal device.

[0181] In some example embodiments, the updated information comprises: a second list of PLMNs associated with a Relay Service Code (RSC). Alternatively or additionally, the updated information comprises a second set of lists of PLMNs, each of the lists of PLMNs being associated with a relay indicator.

[0182] In some example embodiments, the second list of PLMNs or the second set of the list of PLMNs comprises at least one of: a first updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-Network Layer 2 relaying; a second updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-Network Layer 3 relaying; a third updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-UE Layer 2 relaying; or a fourth updated list of PLMNs in which the terminal device is authorized to access 5G ProSe UE-to-UE Layer 3 relaying.

[0183] In some example embodiments, the first network device is a home policy control function (PCF) device located in a home PLMN of the terminal device, and the second network device is a visited PCF device, a direct discovery name management function (DDNMF) device, or a ProSe key management function (PKMF) device located in a serving PLMN of the terminal device.

[0184] In some example embodiments, the first network device is a visited PCF device located in a serving PLMN of the terminal device, and the second network device is a direct discovery name management function (DDNMF) device or a ProSe key management function (PKMF) device located in the serving PLMN of the terminal device.

[0185] It is to be understood that the details of the example embodiments of the disclosure described with reference to Figure 3 and Figure 4 are also applicable to the methods 500 and 600.

[0186] Figure 7 is a simplified block diagram of a device 700 suitable for implementing embodiments of the disclosure. The device 700 can be provided to implement a communication device, for example, the first network device 120 or the second network device 130 as shown in any one of Figures 1A-1D As shown, the device 700 includes one or more processors 710, one or more memories 720 coupled to the processors 710, and one or more communication modules 740 coupled to the processors 710.

[0187] The communication module 740 is for bidirectional communication. The communication module 740 has at least one antenna to facilitate communication. The communication interface can represent any interface needed for communication with other network elements.

[0188] The processor 710 can be of any type suitable to the local technical network, and can include, by way of non-limiting example, one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multi-core processor architectures, as non-limiting examples. The device 700 can have multiple processors such as a special purpose integrated circuit chip that is time-slaved to a clock that is synchronized with a master processor.

[0189] The memory 720 can include one or more non-transitory memories and one or more transitory memories. Examples of non-transitory memories include, but are not limited to, read-only memory (ROM) 724, electrically programmable read only memory (EPROM), flash memory, a hard disk, a compact disc (CD), a digital video disc (DVD), and other magnetic and / or optical storage. Examples of transitory memories include, but are not limited to, random access memory (RAM) 722 and other volatile memories that do not persist in the absence of power.

[0190] The computer program 730 includes computer executable instructions which, when executed by the associated processor 710, carry out the processes discussed above with respect to the present disclosure. The program 730 can be stored in the ROM 724. The processor 710 can carry out any suitable action and processing by loading the program 730 into the RAM 722.

[0191] Embodiments of the present disclosure can be implemented by the program 730 so that the device 700 can perform any of the processes of the present disclosure discussed with reference to FIGS. 1 to Figure 6 Embodiments of the present disclosure can also be implemented by hardware or by a combination of software and hardware.

[0192] In some example embodiments, the program 730 can be tangibly embodied in a computer readable medium, which can be included in the device 700 (such as in the memory 720) or in another storage device accessible by the device 700. The device 700 can load the program 730 from the computer readable medium into the RAM 722 for execution. The computer readable medium can include any type of tangible non-transitory memory, such as ROM, EPROM, flash memory, a hard disk, a CD, a DVD, and the like. Figure 8 An example of a computer readable medium 800 in the form of a CD or DVD is shown. The computer readable medium has the program 730 stored thereon.

[0193] In general, the various embodiments of the present disclosure can be implemented using hardware or special-purpose circuits, software, logic or any combination thereof. Some aspects can be implemented using hardware, while other aspects can be implemented using software or firmware that is executed by a controller, microprocessor or other computing device. Although the various aspects of the embodiments of the present disclosure are illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that the blocks, apparatus, systems, techniques or methods described herein can be implemented using hardware, software, firmware, special- purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0194] The present disclosure also provides at least one computer program product tangibly embodied on a non-transitory computer readable storage medium. The computer program product includes computer executable instructions, such as included in program modules, executed by devices on a target real or virtual processor to perform the methods 500 and 600 described above with reference to Figure 5 and Figure 6 The program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules can be combined or split between program modules as desired in various embodiments. Machine executable instructions for a program module can be executed within a local or distributed device. In a distributed device, program modules can be located in both local and remote storage media.

[0195] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, causes the machine to perform the functions / operations described in the flow diagrams and / or block diagrams. The program code can execute entirely on a machine, partly on a machine, as a stand-alone software package, partly on a machine and partly on a remote machine or entirely on a remote machine or server.

[0196] In the context of the present disclosure, computer program code or related data can be embodied by any suitable carrier wave, including a signal, computer readable medium, etc.

[0197] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the foregoing. More specific examples of computer-readable storage media will include electrical connections having one or more wires, portable computer floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0198] Furthermore, although operations are described in a specific order, this should not be construed as requiring the operations to be performed in the specific order shown or sequentially, or to perform all of the shown operations to obtain the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0199] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms of implementing the claims.

Claims

1. A first network device, comprising: At least one processor; as well as At least one memory storing instructions, which, when executed by the at least one processor, cause the first network device to at least: Receive a request from a second network device for information about at least one Public Land Mobile Network (PLMN), in which the terminal device is authorized to use relay services; Based on the request, obtain the information regarding the at least one PLMN; as well as Send a response to the second network device, including the information about the at least one PLMN.

2. The first network device according to claim 1, wherein the request includes at least one of the following: The identifier of the terminal device; Relay indicator; Relay Service Code (RSC); or The identifier of the service PLMN of the terminal device.

3. The first network device according to claim 2, wherein the relay indicator includes at least one of the following: Fifth-generation (5G) based on Proximity Serving (ProSe) User Equipment (UE) to Network Relay Indicator; 5G ProSe UE-to-UE relay indicator; 5G ProSe Layer 2 relay indicator; 5G ProSe Layer 3 relay indicator; 5G ProSe UE to Network Layer 2 Relay Indicator; 5G ProSe UE to Network Layer 3 Relay Indicator; 5G ProSe UE to UE Layer 2 relay indicator; or 5G ProSe UE to UE Layer 3 relay indicator.

4. The first network device according to claim 2, wherein the response further includes: The identifier of the terminal device.

5. The first network device according to claim 1, wherein: The information includes: a first list of PLMNs associated with a Relay Service Code (RSC); or The information includes a first set of PLMN lists, each of which is associated with a relay indicator.

6. The first network device of claim 5, wherein the first list of PLMNs or the first set of the PLMN list comprises at least one of the following: The first list of PLMNs, in which terminal devices are authorized to access 5G ProSe UEs to network layer 2 relays. The second list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to network layer 3 relay, The third list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to UE Layer 2 relay, or The fourth list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to UE Layer 3 relay.

7. The first network device according to claim 1, wherein the first network device is further configured to: Receive a subscription request from the second network device for updates to the information regarding the at least one PLMN; and Based on the determination that the information has been updated, a subscription notification including the updated information is sent to the second network device.

8. The first network device of claim 7, wherein the subscription request includes at least one of the following: The identifier of the terminal device; Relay Service Code (RSC); or Relay indicator.

9. The first network device according to claim 7, wherein the subscription notification includes an identifier of the terminal device.

10. The first network device according to claim 7, wherein: The updated information includes: a second list of PLMNs associated with Relay Service Codes (RSCs); or The updated information includes a second set of PLMN lists, each of which is associated with a relay indicator.

11. The first network device of claim 10, wherein the second list of PLMNs or the second set of the PLMN list comprises at least one of the following: The first update list of the PLMN, in which the terminal devices described in the first update list of the PLMN are authorized to access 5G ProSe UE to network layer 2 relay; The second update list of the PLMN, in which the terminal devices described in the second update list of the PLMN are authorized to access 5G ProSe UE to network layer 3 relay; The third update list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to UE Layer 2 relay; or The fourth update list of the PLMN, in which the terminal devices are authorized to access 5G ProSe UE to UE Layer 3 relay.

12. The first network device according to claim 1, wherein the first network device is a Home Policy Control Function (PCF) device located in the home PLMN of the terminal device, and the second network device is a visited PCF device, a Direct Discovery Name Management Function (DDNMF) device, or a Proximity-Based Service (ProSe) Key Management Function (PKMF) device located in the serving PLMN of the terminal device.

13. The first network device of claim 1, wherein the first network device is a visited PCF device located in the serving PLMN of the terminal device, and the second network device is a Direct Discovery Name Management Function (DDNMF) device or a Proximity-Based Service (ProSe) Key Management Function (PKMF) device located in the serving PLMN of the terminal device.

14. The first network device according to claim 13, wherein: The first network device is also used to: The request is forwarded to a third network device in the home PLMN of the terminal device; and The first network device is configured to obtain the information about the at least one PLMN by: The information about the at least one PLMN is obtained from the third network device.

15. A second network device, comprising: At least one processor; as well as At least one memory storing instructions, which, when executed by the at least one processor, cause the second network device to at least: Send a request to a first network device for information about at least one Public Land Mobile Network (PLMN), in which the terminal device is authorized to use relay services; as well as Receive a response from the first network device including the information about the at least one PLMN.

16. The second network device of claim 15, wherein the request includes at least one of the following: The identifier of the terminal device; Relay indicator; Relay Service Code (RSC); or The identifier of the service PLMN of the terminal device.

17. The second network device of claim 16, wherein the relay indicator comprises at least one of the following: Fifth-generation (5G) based on Proximity Serving (ProSe) User Equipment (UE) to Network Relay Indicator; 5G ProSe UE-to-UE relay indicator; 5G ProSe Layer 2 relay indicator; 5G ProSe Layer 3 relay indicator; 5G ProSe UE to Network Layer 2 Relay Indicator; 5G ProSe UE to Network Layer 3 Relay Indicator; 5G ProSe UE to UE Layer 2 relay indicator; or 5G ProSe UE to UE Layer 3 relay indicator.

18. The second network device of claim 16, wherein the response comprises: The identifier of the terminal device.

19. The second network device according to claim 15, wherein: The information includes: a first list of PLMNs associated with a Relay Service Code (RSC); or The information includes a first set of PLMN lists, each of which is associated with a relay indicator.

20. The second network device of claim 19, wherein the first list of PLMNs or the first set of the PLMN list comprises at least one of the following: The first list of PLMNs, in which terminal devices are authorized to access 5G ProSe UEs to network layer 2 relays. The second list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to network layer 3 relay, The third list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to UE Layer 2 relay, The fourth list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to UE Layer 3 relay.

21. The second network device according to claim 15, wherein the first network device is further configured to: Send a subscription request to the first network device for updates to the information regarding the at least one PLMN; and Receive a subscription notification from the first network device, including the updated information.

22. The second network device of claim 21, wherein the subscription includes at least one of the following: The identifier of the terminal device; Relay Service Code (RSC); or Relay indicator.

23. The second network device according to claim 21, wherein the notification includes: The identifier of the terminal device.

24. The second network device according to claim 21, wherein: The updated information includes: a second list of PLMNs associated with Relay Service Codes (RSCs); or The updated information includes a second set of PLMN lists, each of which is associated with a relay indicator.

25. The second network device of claim 24, wherein the second list of PLMNs or the second set of the PLMN list comprises at least one of the following: The first update list of the PLMN, in which the terminal devices described in the first update list of the PLMN are authorized to access 5G ProSe UE to network layer 2 relay; The second update list of the PLMN, in which the terminal devices described in the second update list of the PLMN are authorized to access 5G ProSe UE to network layer 3 relay; The third update list of the PLMN, in which terminal devices are authorized to access 5G ProSe UE to UE Layer 2 relay; or The fourth update list of the PLMN, in which the terminal devices are authorized to access 5G ProSe UE to UE Layer 3 relay.

26. The second network device according to claim 15, wherein the first network device is a Home Policy Control Function (PCF) device located in the home PLMN of the terminal device, and the second network device is a visited PCF device, or a Direct Discovery Name Management Function (DDNMF) device, or a ProSe Key Management Function (PKMF) device located in the serving PLMN of the terminal device.

27. The second network device of claim 15, wherein the first network device is a visited PCF device located in the serving PLMN of the terminal device, and the second network device is a Direct Discovery Name Management Function (DDNMF) device or a ProSe Key Management Function (PKMF) device located in the serving PLMN of the terminal device.

28. An apparatus comprising: A component for receiving, at a first network device and from a second network device, a request for information about at least one Public Land Mobile Network (PLMN), in which the terminal device is authorized to use relay services; Components for obtaining the information about the at least one PLMN based on the request; as well as A component for sending a response to the second network device, including the information about the at least one PLMN.

29. An apparatus comprising: A component for sending a request for information about at least one Public Land Mobile Network (PLMN) from a second network device to a first network device, in which the terminal device is authorized to use relay services; as well as A component for receiving a response from the first network device, including the information about the at least one PLMN.

30. A method comprising: At the first network device, a request for information about at least one Public Land Mobile Network (PLMN) is received from the second network device, in which the terminal device is authorized to use relay services; Based on the request, obtain the information regarding the at least one PLMN; as well as Send a response to the second network device, including the information about the at least one PLMN.

31. A method comprising: At the second network device, a request for information about at least one Public Land Mobile Network (PLMN) is sent to the first network device, in which the terminal device is authorized to use relay services; as well as Receive a response from the first network device including the information about the at least one PLMN.

32. A computer-readable medium comprising program instructions that cause a device to perform at least the method according to claim 30 or 31.