Connectionless service message transfer

CN122765764APending Publication Date: 2026-09-15NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610309987.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-03-14
Filing Date
2026-03-13
Publication Date
2026-09-15

Smart Images

  • Figure CN122765764A_ABST
    Figure CN122765764A_ABST
Patent Text Reader

Abstract

Example embodiments of the present disclosure relate to connectionless service messaging. In one method, an apparatus receives a request from a network entity for a change in service delivery mode. The request includes an identifier of a connectionless service. The apparatus is in a connectionless access mode. The apparatus determines that the service delivery mode is to be changed from the connectionless access mode to a connection-oriented access mode. The apparatus performs data transfer with the network entity in the connection-oriented access mode by establishing a connection-oriented tunnel between the apparatus and the network entity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various exemplary embodiments of this disclosure generally relate to the telecommunications field, and particularly to methods, apparatuses, devices, and computer-readable storage media for connectionless (CL) service message transmission. Background Technology

[0002] A communication network can act as a facility that enables communication between two or more communication devices, or provides communication devices with access to a data network. Mobile or wireless communication networks are an example of a communication network. Communication devices may be served by application servers.

[0003] Communication networks can operate according to standards provided by organizations such as the 3rd Generation Partnership Project (3GPP) or the European Telecommunications Standards Institute (ETSI). Examples of standards provided by 3GPP are the so-called 3GPP standards for cellular technologies, such as those for 4G, 5G, and 6G technologies. Summary of the Invention

[0004] In a first aspect of this disclosure, an apparatus is provided. The apparatus includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: receive from a network entity a request for changing a service delivery mode, wherein the request includes an identifier of a connectionless service, and wherein the apparatus is in a connectionless access mode; determine that the service delivery mode will be changed from a connectionless access mode to a connection-oriented access mode; and perform data transmission with the network entity in the connection-oriented access mode by establishing a connection-oriented tunnel between the apparatus and the network entity.

[0005] In a second aspect of this disclosure, a network entity is provided. The network entity includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the network entity to at least: send a request to the device for changing the service delivery mode based on a determination that a service delivery mode associated with the device will be changed, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode; and perform data transmission with the device in a connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

[0006] In a third aspect of this disclosure, a method is provided. The method includes: receiving from a network entity a request for changing a service delivery mode, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode; determining that the service delivery mode will be changed from a connectionless access mode to a connection-oriented access mode; and performing data transmission with the network entity in the connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

[0007] In a fourth aspect of this disclosure, a method is provided. The method includes: sending a request to the device for changing the service delivery mode based on a determination that a service delivery mode associated with the device will be changed, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode; and performing data transmission with the device in a connection-oriented access mode by establishing a connection-oriented tunnel between the device and a network entity.

[0008] In a fifth aspect of this disclosure, an apparatus is provided. The apparatus includes: components for receiving from a network entity a request for changing a service delivery mode, wherein the request includes an identifier of a connectionless service, and wherein the apparatus is in a connectionless access mode; components for determining that the service delivery mode will be changed from the connectionless access mode to a connection-oriented access mode; and components for performing data transmission with the network entity in the connection-oriented access mode by establishing a connection-oriented tunnel between the apparatus and the network entity.

[0009] In a sixth aspect of this disclosure, a network entity is provided. The network entity includes: components for determining that a service delivery mode associated with the device will be changed and sending a request to the device for changing the service delivery mode, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode; and components for performing data transmission with the device in a connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

[0010] In a seventh aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to perform at least the method according to the third aspect.

[0011] In an eighth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to perform at least the method according to the fourth aspect.

[0012] It should be understood that the Summary of the Invention section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0013] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:

[0014] Figure 1 The illustration shows an example communication environment in which example embodiments of this disclosure can be implemented;

[0015] Figure 2A The diagram illustrates an example of connection-oriented (CO) user plane access.

[0016] Figure 2B The diagram illustrates an example of the CL access mode;

[0017] Figure 3 The illustration shows a signaling flow for CL service message transmission according to some example embodiments of the present disclosure;

[0018] Figure 4 The diagram illustrates a signaling flow for association establishment for CL services according to some example embodiments of this disclosure;

[0019] Figure 5 The illustration shows another signaling flow for association establishment for CL services according to some example embodiments of this disclosure;

[0020] Figure 6 The illustration shows signaling flows for changing service delivery modes according to some example embodiments of the present disclosure;

[0021] Figure 7 The illustration shows another signaling flow for changing the service delivery mode according to some example embodiments of the present disclosure;

[0022] Figure 8 The illustration shows a flowchart of a method implemented at a device according to some exemplary embodiments of the present disclosure;

[0023] Figure 9 The illustration shows a flowchart of a method implemented at a network entity according to some embodiments of the present disclosure;

[0024] Figure 10 The illustration shows a flowchart of another method implemented at a device according to some exemplary embodiments of the present disclosure;

[0025] Figure 11 The illustration shows another flowchart of another method implemented at a network entity according to some embodiments of the present disclosure;

[0026] Figure 12 Another flowchart illustrating a method implemented at a device according to some exemplary embodiments of the present disclosure is shown;

[0027] Figure 13 A simplified block diagram of a device suitable for implementing exemplary embodiments of the present disclosure is illustrated; and

[0028] Figure 14 A block diagram of an example computer-readable medium according to some example embodiments of the present disclosure is illustrated.

[0029] Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0030] The principles of this disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described for illustrative purposes only and to assist those skilled in the art in understanding and implementing this disclosure, and do not impose any limitation on the scope of this disclosure. The embodiments described herein can be implemented in various ways besides the methods described below.

[0031] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0032] The embodiments described in this disclosure using references to "an embodiment," "an embodiment," "an example embodiment," etc., may include specific features, structures, or characteristics, but each embodiment does not necessarily include that specific feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. In addition, when a specific feature, structure, or characteristic is described in conjunction with an embodiment, it should be understood that, whether explicitly described or not, in conjunction with other embodiments, influencing such feature, structure, or characteristic is within the knowledge of those skilled in the art.

[0033] It should be understood that while the terms "first," "second," etc., preceding the noun(s) may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another and do not restrict the order of the noun(s). For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term "and / or" includes any and all combinations of one or more of the listed items.

[0034] As used herein, “at least one of the following: ” and “at least one of ” and similar wording (where a list of two or more elements is joined by “and” or “or”) means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0035] As used herein, unless explicitly stated otherwise, “responding to A” does not indicate that the step is performed immediately after “A” occurs, and may include one or more intermediate steps.

[0036] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. As used herein, the singular forms “a,” “an,” and “the” are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that, when used herein, the terms “comprises,” “comprising,” “has,” “having,” “includes,” and / or “including” specify the presence of the described features, elements, and / or components, but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0037] As used in this application, the term "circuit system" may refer to one or more, or all of the following: (a) Hardware circuit implementation only (such as implementation in analog and / or digital circuit systems); and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of (multiple) analog and / or digital hardware circuits and software / firmware, and (ii) Any part of a hardware processor (including a digital signal processor), software, and memory (including a plurality of) working together to enable a device such as a mobile phone or server to perform various functions) and (c) (Multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or a portion thereof, which require software (e.g. firmware) to operate, but may be absent when operation is not required.

[0038] This definition of "circuit system" applies to all uses of the term in this application, including in any claim. As another example, as used herein, the term "circuit system" will also cover only the hardware circuitry or processor (or processors) or portions thereof and its (or their) accompanying software and / or firmware implementation. For example, and if applicable to a particular claim element, the term "circuit system" will also cover baseband integrated circuits or processor integrated circuits for mobile devices, or similar integrated circuits in servers, cellular network devices, or other computing or network devices.

[0039] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in a communication network can be performed according to any suitable generation of communication protocol, including but not limited to first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G), 5.5G, sixth-generation (6G) communication protocols and / or any other currently known or to be developed in the future. Embodiments of this disclosure can be applied in various communication systems. Given the rapid development of communications, there will naturally be communication technologies and systems that embody future types of this disclosure. This disclosure should not be construed as limiting its scope to the systems described above.

[0040] As used herein, the terms "network equipment" and "Radio Access Network (RAN) equipment" or "RAN node" refer to a node in a communication network through which terminal equipment accesses the network and receives services. Network equipment can refer to a base station (BS) or access point (AP), such as a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), an NR NB (also known as a gNB), a Remote Radio Unit (RRU), a Radio Header (RH), a Remote Radio Header (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low-power node (such as a femtosecond or picosecond), a non-terrestrial network (NTN) or non-terrestrial network equipment (such as satellite network equipment), low Earth orbit (LEO) satellites and geostationary Earth orbit (GEO) satellites, spacecraft network equipment, etc., depending on the terminology and technology used. In some example embodiments, a RAN split architecture can be applied. That is, a RAN node can include a centralized unit (CU) and a distributed unit (DU). A CU can include a control plane (CP) (i.e., CU-CP) and a user plane (UP) (i.e., CU-UP). For example, the CU and DU may be located at the IAB donor node. The IAB node includes the mobile terminal (IAB-MT) portion, which behaves like a UE towards the parent node, and the DU portion of the IAB node behaves like a base station towards the next-hop IAB node.

[0041] The term "terminal device" refers to any end device that may be capable of wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smartphones, VoIP phones, wireless local loop phones, tablet computers, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop mounted devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPEs), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. Terminal devices may also correspond to the mobile terminal (MT) portion of an IAB node (e.g., a relay node). In the following description, the terms "terminal device," "communication device," "terminal," "user equipment," and "UE" are used interchangeably.

[0042] As used herein, the term "core network function" can be implemented as a core network entity comprising a combination of hardware processing circuitry and software and / or firmware (including machine-readable instructions) or software (including machine-readable instructions executable by at least one processor of the hardware processing circuitry of the device). The hardware processing circuitry includes at least one processor and at least one memory storing machine-readable instructions executable by the at least one processor of the hardware processing circuitry. The processor includes any or a combination of an accelerator, microprocessor, core of a multi-core microprocessor, microcontroller, programmable integrated circuit, programmable gate array, digital signal processor, central processing unit, graphics processing unit, and tensor processing unit. The memory includes any or a combination of volatile or non-volatile memory (e.g., flash memory, cache, random access memory (RAM), and / or read-only memory (ROM)). The memory stores machine-readable instructions of the software and / or firmware for execution by at least one processor of the hardware processing circuitry. The machine-readable instructions, executable by at least one processor of the hardware processing circuitry, cause the hardware processing circuitry to perform the actions or operations of the methods described herein. For example, the session management functions described in this paper can be implemented as session management entities, and the session management policy control functions described in this paper can be implemented as session management policy control entities.

[0043] As used herein, the terms “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” can refer to any resource used to perform communication (e.g., communication between a terminal device and a network device), such as resources in the time domain, resources in the frequency domain, resources in the spatial domain, resources in the code domain, or any other combination of time-domain resources, frequency-domain resources, spatial-domain resources, and / or code-domain resources that enable communication. In the following, unless explicitly stated otherwise, resources in both the frequency and time domains will be used as examples of transmission resources to describe some exemplary embodiments of this disclosure. It should be noted that the exemplary embodiments of this disclosure are equally applicable to other resources in other domains.

[0044] Figure 1 An example communication environment 100 in which exemplary embodiments of the present disclosure may be implemented is shown. The communication environment 100 includes a plurality of devices or apparatuses, such as terminal device 110, node 120 and network entity 130.

[0045] RAN node 120 can provide one or more coverage areas (or cells) for terminal equipment 110. RAN node 120 may include CU and DU. CU and DU can be connected to each other via a so-called FL interface. RAN node 120 may refer to a base station (such as a next-generation node B, gNB), gNB-CU, and / or gNB-DU.

[0046] Terminal device 110 and / or RAN node 120 can communicate with the CN. For example, terminal device 110 and / or RAN node 120 can communicate with network entity 130. In some examples, the network entity may include or implement a User Plane Function (UPF). The UPF can handle user data services, including packet routing, forwarding, and Quality of Service (QoS) enforcement. Network entity 130 can connect the RAN to an external data network (DN) 150, such as the Internet or any other suitable network. Network entity 130 can forward data services from terminal device 110 to data network 150. Network entity 130 can perform tasks such as service optimization, data buffering, and local breakout for edge computing.

[0047] Additionally, another network entity 140 may exist within the communication environment 100. For example, network entity 130, RAN node 120, and / or terminal device 110 may communicate with network entity 140. By way of example, network entity 140 may include or implement Access and Mobility Management Functions (AMF), Session Management Functions (SMF), etc. AMF can manage device connectivity and mobility, such as registration, authentication, and tracking location changes. SMF can control user sessions, including setting, modifying, and terminating user sessions.

[0048] In some example embodiments, the direction from RAN node 120, network entity 130, or network entity 140 to terminal device 110 is referred to as the downlink (DL), while the direction from terminal device 110 to RAN node 120, network entity 130, or network entity 140 is referred to as the uplink (UL). In the DL, RAN node 120, network entity 130, or network entity 140 is a transmitting (TX) device (or transmitter), and terminal device 110 is a receiving (RX) device (or receiver). In the UL, terminal device 110 is a TX device (or transmitter), and RAN node 120, network entity 130, or network entity 140 is an RX device (or receiver).

[0049] It should be understood that, Figure 1 The number of devices and their connections shown are for illustrative purposes only and do not impose any limitations. Communication environment 100 may include any suitable number of devices configured to implement the exemplary embodiments of this disclosure. Although not shown, it should be understood that one or more additional devices may be located in a cell provided by RAN node 120, and one or more additional cells may be deployed in communication environment 100. It should be noted that although illustrated as a network node or entity, RAN node 120, network entity 130, or network entity 140 may be another device besides a network node or entity. Although illustrated as a terminal device, terminal device 110 may be another device besides a terminal device.

[0050] Communication in communication environment 100 can be implemented according to any suitable communication protocol(s), including but not limited to cellular communication protocols, wireless local network communication protocols (such as IEEE 802.11, etc.), and / or any other protocol currently known or to be developed in the future. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple Input Multiple Output (MIMO), Orthogonal Frequency Division Multiple Access (OFDM), Discrete Fourier Transform Extended OFDM (DFT-s-OFDM), and / or any other technology currently known or to be developed in the future.

[0051] In some examples, communication between devices and nodes in communication environment 100 can utilize CO access and / or CL access. Figure 2AThe illustration shows an example diagram 200A illustrating CO user plane access. As shown, multiple UEs (such as UE 210-1, ..., UE 210-N (N is a positive integer)) are connected to RAN 220. For discussion purposes, UE 210-1, ..., UE 210-N may be collectively referred to or individually as "(multiple) UE 210". In CO access mode, UE 210 can communicate with AMF or SMF 240 via Radio Resource Control (RRC) Packet Data Convergence Protocol (PDCPc) for the control plane. UE 210 can communicate with UPF 230 via Data Radio Bearer (DRB) Packet Data Convergence Protocol (PDCPu) for the user plane. UPF 230 can be connected to DN 250 via Protocol Data Unit (PDU) anchors. This CO access mode uses the RRC Connected (RRC_CONNECTED) mode.

[0052] Figure 2B Example diagram 200B illustrates the CL access mode. In CL access mode, UE 210 can communicate with CL Service (CLS) trunk 260 via CL-PDCPu. CLS trunk 260 is connected to CLS trunk 270 in UPF 230. CLS trunk 270 can be connected to the PDU anchor for DN 250 via at least one association (such as association 280-1 for UE 210-1 and association 280-N for UE 210-N). For the purposes of discussion, associations 280-1, ..., associations 280-N can be collectively referred to or individually as "(multiple) associations 280". Association 280 can refer to the association between UE 210 and UPF 230.

[0053] The CL concept for networks such as 6G provides a mechanism for UEs to obtain limited PDU session access when they are in an RRC_IDLE state. CL access can be used as a supplement to CO mode access using RRC_CONNECTED and Small Data Transmission (SDT) when in an RRC_INACTIVE state.

[0054] The overall concept of connectionless access is based on the assumption that the UE can obtain a radio configuration for connectionless access, and that this configuration remains valid within the defined set of cells when the UE is in RRC_IDLE. If the UE remains within the area where the radio configuration is valid and has a valid temporary identifier for connectionless access, then the UE can initiate connectionless access without requiring RRC or Non-Access Stratum (NAS) signaling, and the RAN can serve the UE without any stored UE context information.

[0055] Furthermore, since connectionless access will be supported using shared transports for user plane services within the RAN and on the RAN-core interface instead of dedicated transports, no dedicated network interface control plane signaling is required each time a UE initiates connectionless access.

[0056] Connectionless access offers the potential to significantly reduce the need for UEs to send context information and RRC and NAS signaling every time a UE needs to send a short data message. Additionally, it reduces the need for the RAN to maintain collected UE context information when the UE is in Connection Management (CM)_CONNECTED (i.e., RRC_CONNECTED or RRC_INACTIVE), and the need to configure the RAN and core to set up and hold dedicated user plane connections for each active PDU session held by a given UE.

[0057] Work is underway to ensure the secure transmission of CL messages between the UE and the UPF. In particular, the establishment of an association between the UE and the UPF, and the protocols or messages used for this association, have become issues of concern.

[0058] In some mechanisms, it is assumed that secure message delivery is guaranteed using PDCPU, where the radio protocol is transmitted from the RAN to the UPF. The RRC_INACTIVE state and the associated mechanism for providing SDT when the UE is in RRC_INACTIVE are specified. This mechanism requires the last serving RAN to hold the UE context information and requires substantial RAN internal signaling to process the SDT when in the RRC_INACTIVE mechanism. In another mechanism, connectionless access is proposed in the mobile network and radio interface aspects of a possible connectionless access mechanism.

[0059] Secure transport tunnels are well-known (IPsec, etc.), but secure tunneling protocols that provide the services required for secure connectionless transport have not yet been identified. Therefore, a secure message transmission and reception solution between the UE and the UPF needs to be defined.

[0060] To address at least some of the above-mentioned or other potential problems, several solutions regarding CL service message transmission have been proposed. In one solution, a device (such as a terminal device or UPF) receives or sends a message related to a CL service associated with that device and another device. For example, a CL service may be associated with a terminal device and a UPF. The CL service supports data transmission without an RRC connection. The message includes a header and a body. Specifically, the header includes an identifier (ID) for the CL service. The body includes at least a common portion indicating information about the message.

[0061] In this way, the CL service identifier in the message header can be used to identify the sending or receiving device. For example, based on the CL service identifier, an appropriate UPF can be selected for the terminal device. The UPF can use the CL service identifier to identify the corresponding UE. Therefore, CL service data transmission can be implemented.

[0062] Figure 3 The illustration shows a signaling stream 300 for CL service message transmission according to some example embodiments of the present disclosure. Signaling stream 300 relates to apparatus 310 and apparatus 320. By way of example, apparatus 310 may include or be implemented as Figure 1 The terminal device 110, and the device 320 may include or be implemented as Figure 1 Network entity 130. Network entity 130 may include or implement UPF.

[0063] In operation, device 320 sends message (3010) to device 310 (referred to as the "first message" for discussion purposes). Accordingly, device 310 receives message (3015) of the first message. Alternatively or otherwise, device 310 sends message (3020) to device 320 (referred to as the "second message" for discussion purposes). Thus, device 320 receives message (3025) of the second message. The first and second messages are related to the CL service, which is associated with devices 310 and 320. The CL service supports data transmission without an RRC connection. As used herein, messages associated with the CL service (such as the first and second messages) may be referred to as CL service messages or CLS messages.

[0064] A CL service message consists of a header (or header portion) and a body (also called a message portion). Specifically, the header includes the ID of the CL service, such as the CL Service ID (CLSI). The CLSI can be a unique ID for a specific PDU session used by device 310 (such as a UE). The CLSI can be used by the RAN to select the appropriate UPF assigned to support the PDU session, and by the UPF to retrieve UE session information including security keys. The CLSI in the header can also be used by the UE to distinguish DL messages for one of a potential multiple parallel PDU sessions using connectionless access. The header may also further carry an indication of the total message length, which is useful for the RAN to determine whether segmentation is required to map the message into one or more transport blocks.

[0065] The body includes at least a common portion indicating information about the CLS message. The body may also include a payload (also called a payload portion). The payload may include CL access messages to be delivered, such as CL user plane packets. In this way, CL access messages can be included in the encrypted payload portion of the CLS message body.

[0066] In some examples, the header can be unencrypted, and the body can be encrypted. That is, the header can be plaintext. Message transmission between device 310 and device 320 can be performed via a RAN node (such as RAN node 120). The unencrypted header can be inspected by the RAN node. In contrast, the encrypted body may not be decryptable by the RAN node. In this way, the RAN node can identify device 310 or device 320 based on the CLSI. For example, the RAN node can identify the UE based on an integrity-protected but unencrypted CLSI and select an appropriate UPF for the UE. Alternatively, the UPF can use the CLSI to identify the UE and select an appropriate security key for performing both integrity and encryption procedures.

[0067] The first message may include a DL message. The common portion of the body of the first message may include at least one of the following: the message type (or service type) of the first message, a sequence number used for message reordering, another identifier for the connectionless service (such as a new CLSI), or information regarding message integrity protection. The second message may include a UL message. The common portion of the body of the second message may include at least one of the following: the message type (or service type) of the second message, a sequence number used for message reordering, or information regarding message integrity protection. In this way, the message format for DL ​​and UL messages used for CL services is specified. The common portion may contain an indication of the type of message carried. The message type can be used to distinguish different messages. The sequence number can be used to sort or reorder received messages. Another identifier, such as a new CLSI, can be used to update the identifier of the CL service. For example, the UPF can assign a new CLSI to the CL service. The new CLSI can be an identifier for a specific service used by a specific UE. Information regarding message integrity protection can be used to ensure the integrity protection of the entire message.

[0068] For the first message, the message type or service type can be a DL message, such as a DL CLS message, a security mode command, or a request to change the service delivery mode. In this way, the message format and message type of the DL message used for CL services are specified. This CL service message can be used in any process associated with the CL service. For example, a DL CLS message can be used to send a data payload from the UE to the UPF. A security mode command can be used to establish an association between the UPF and the UE, which will be relative to... Figure 4 and Figure 5 This will be described. A request to change the service delivery mode can be used to change the service delivery mode from CL service to CO service, which will be relative to... Figure 6 and Figure 7 Describe it.

[0069] For the second message, the message type or service type can be a UL message, such as a UL CLS message, security mode completion, security mode failure, or a response to a change in service delivery mode. For example, a UL CLS message can be used to send a data payload from the UPF to the UE. Security mode completion can be used to indicate acknowledgment (ACK) of a security mode command, which will be relative to... Figure 4 and Figure 5 The description is as follows. A response to a change in service delivery mode can be used to indicate an ACK to a request for a change in service delivery mode, which will be relative to... Figure 6 and Figure 7 Describe it.

[0070] In some embodiments, the header and / or body may include other content. Example message formats for the CL service are shown in Table 1 below. It should be understood that the components, content, or parameters shown in Table 1 are for illustrative purposes only and do not imply any limitations. Any suitable message format may be defined for the CL service. Table 1

[0071] Several embodiments regarding CL service messages have been implemented relative to... Figure 3The message format described in Table 1 can be used for association between a UE and a UPF for CL mode. The message format can be applied as a new protocol for CL services. The protocol for CL services can include a plaintext header and a security body (such as a security message). The body carries the UL or DL ​​CLS message, the new CLSI, and the security mode command, while the plaintext header visible to the RAN and UPF carries the CLSI. As used herein, the protocol for CL services can be referred to as the "CL Service Tunneling Protocol (CLS-tp)". This CLS-tp can be a secure tunnel established between the UE and the UPF. CLS-tp supports encrypted message portions that securely carry messages between the UE and the UPF. CLS-tp supports plaintext header portions that can be inspected by the node between the UE and the UPF, which can use this information for message routing decisions. The proposed CLI-tp and the proposed message format can be used in processes associated with CL services, such as association establishment for CL services. This protocol for CL services does not introduce additional signaling overhead.

[0072] In a solution for establishing associations for CL services, a device such as a UE sends a connectionless service message, including an identifier for the connectionless service, to a network entity such as a UPF. A session supporting the connectionless service has been established between the device and the network entity. An association for the session based on the protocol for the connectionless service has not yet been established. The device receives a security mode command message from the network entity. The security mode command includes integrity protection security information. If the integrity check of the integrity protection security information is successful, the device establishes an association with the network entity based on the protocol for the connectionless service to perform secure transport. In this way, the security mode command message can trigger the establishment of an association. If the integrity check is successful, the association between the device and the network entity can be established based on the CL service protocol. Therefore, the established association can be a secure association.

[0073] Figure 4 The illustration shows a signaling flow 400 for establishing an association for a CL service according to some example embodiments of the present disclosure. Signaling flow 400 relates to apparatus 410 and... Figure 1 Network entity 130. For the purposes of discussion, device 410 can be described as... Figure 1 Terminal device 110 in the middle.

[0074] In operation, device 410 sends a (4010) CL service message to network entity 130, which includes an identifier for the connectionless service, such as CLSI. A session supporting the connectionless service has been established between device 410 and network entity 130. An association for the session based on the protocol used for the CL service has not yet been established. The protocol used for the CL service can be relative to... Figure 3 The described protocol or any other suitable protocol. The session can be a PDU session associated with device 410 or any other suitable session. Correspondingly, the network entity receives the (4015) CL service message.

[0075] In some examples, a CL service message may include a header and a body. The header includes an identifier for the connectionless service, such as CLSI. The body includes at least a common portion indicating information about the connectionless service message. A CL service message can be an uplink message. For uplink messages, the common portion indicates the message type of the CL service message, the sequence number used for message reordering, and / or information about integrity protection for the connectionless service message. These contents of the CL service message are already relative to... Figure 3 The above has already been described and will not be repeated here.

[0076] Network entity 130 determines (4020) whether an association based on the protocol used for CL services for the session has been established. If the association has not been established, network entity 130 sends a (4030) security mode command message to device 410, which includes integrity protection security information. Correspondingly, device 410 receives a (4035) security mode command message. The security mode command message can use relative to... Figure 3 The message format is as described in Table 1. For example, a safe mode command message can be a DL message, whose body indicates that the message type is a safe mode command. The message body may include integrity protection information.

[0077] In some embodiments, in response to receiving (4015) a CL service message, network entity 130 can obtain service information related to device 410. Network entity 130 can determine, based on the obtained service information, that an association has not yet been established. For example, the body of the (UL) CL service message may not include a payload, meaning the CL service message is an empty (NULL) message. Upon receiving such an empty message, network entity 130 can know that an association has not yet been established.

[0078] Device 410 performs an integrity check (4040) on the integrity protection security information included in the security mode command message. If the integrity check on the integrity protection security information is successful, device 410 establishes (4050) an association (4050) with network entity 130 based on the protocol for CL services for secure transmission. In this way, the security mode command message can trigger the establishment of the association. If the integrity check is successful, the association between device 410 and network entity 130 can be established based on the CL service protocol. Therefore, the established association can be a secure association.

[0079] After the association is successfully established, device 410 can enter the CLS active state. During the CLS active state, device 410 can initiate data transmission to network entity 130. Network entity 130 can receive data transmission.

[0080] In some examples, device 410 can send a message to network entity 130 indicating whether the association establishment was successful. Network entity 130 can receive this message. In this way, network entity 130 can be notified whether the association establishment was successful.

[0081] By way of example, if the association is established successfully, device 410 can send a security mode completion message to network entity 130. Upon receiving the security mode completion message, it can notify network entity 130 that the association was established successfully. If the association is not established successfully, device 410 can send a security mode failure message to network entity 130. Upon receiving the security mode failure message, it can notify network entity 130 that the association failed. The security mode completion message and / or the security mode failure message can use relative to... Figure 3 The message format is as described in Table 1. For example, a safety mode complete message and / or safety mode failure message can be a UL message, the body of which indicates that the message type is safety mode complete or safety mode failure.

[0082] Apparatus 410 can determine a secure session key based at least on security information included in a secure mode command message. Apparatus 410 can perform secure transmissions with network entity 130 based on the secure session key. In some embodiments, the secure session key can be derived by apparatus 410 using information carried in a secure mode command, as well as information previously obtained by apparatus 410 using secure transmission connections (such as NAS signaling) and the latest authentication and key agreement (AKA). Similarly, network entity 130 can determine a secure session key based at least on security information included in a secure mode command message. Network entity 130 can perform secure transmissions with apparatus 410 based on the secure session key. Multiple security keys for apparatus 410 can be derived using information delivered during session establishment (such as PDU session establishment) and can potentially be refreshed during subsequent service request processes. Using multiple security keys, secure data transmission for CL services can be implemented.

[0083] In some embodiments, CL association security or CL tunnel security can be established by running an SMC procedure between network entity 130 and device 410 based on a Security Mode Command (SMC) procedure. The key used to protect the CL tunnel can be derived in the core network based on the result key of the most recently successful AKA procedure (e.g., Kseaf) plus a combination of other key set information, which may include, for example, a PDU session ID and other information. Network entity 130 initiates an integrity protection SMC procedure to device 410, which includes key set information used by device 410 to identify and derive the same key owned by network entity 130.

[0084] Using these embodiments, secure CL access for CL services can be implemented. This secure CL access can rely on an association (i.e., a secure tunnel) established between device 140 and network entity 130, and is maintained using in-band user plane signaling, thus eliminating the need for RAN and core control plane signaling. (The last sentence appears to be incomplete and possibly refers to a different implementation.) Figure 5 Other embodiments for establishing associations for CL services are described below. Figure 5 The diagram illustrates another signaling flow 500 used for association establishment in CL services. Signaling flow 500 involves... Figure 1 The system includes terminal equipment 110, RAN node 120, and DN 150, and also involves a core network 510. The core network 510 includes a UPF 512 in the user plane and an AMF 524 and SMF 528 in the control plane 520. The UPF may include or be implemented as... Figure 1 Network entity 130 in the network. AMF 524 and / or SMF 528 may include or be implemented as Figure 1 Network entity 140.

[0085] Whenever terminal device 110 fails to establish a secure association between terminal device 110 and UPF 512 for a specific PDU session, the process for establishing the association may be initiated by terminal device 110. For discussion purposes, in the following description, this association may be described as a secure CLS-TP tunnel. This state will occur immediately after the PDU session is established, and may also occur after a service request is triggered upon CLSI expiration.

[0086] Several prerequisites may exist for establishing a secure CLS-TP tunnel. One prerequisite may be that terminal device 110 has already established a PDU session supporting CLS access. Another prerequisite may be that terminal device 110 holds a valid CLSI and can derive the corresponding security key. Yet another prerequisite may be that terminal device 110 does not have a corresponding CLS-TP tunnel in a secure state. It should be understood that these conditions are for illustrative purposes only and do not impose any limitations. Any suitable prerequisites may be applied.

[0087] During operation, terminal device 110 may have previously obtained (5010) CLS-related security information. Terminal device 110 may currently be in a CLI inactive state. In a CLI inactive state, terminal device 110 may not initiate CL services.

[0088] In 5020, if CLS-tp is not initialized, terminal device 110 determines that it needs to initialize a secure CLS-tp tunnel between terminal device 110 and UPF 512. Terminal device 110 can set the CLS message to an empty message.

[0089] Terminal device 110 sends a (5030) UL CLS message to RAN node 120. The UL CLS message includes a CLSI and is an empty message. That is, terminal device 110 sends an empty message using a UE-initiated CLS message with a CLSI. RAN node 120 forwards the UL CLS message (5035) to UPF 512. The UL CLS message may include a UE binding request.

[0090] UPF 512 receives an empty message from terminal device 110 and identifies (5060) that a secure CLS-tp for a specific PDU session has not yet been established. For example, UPF 512 can retrieve UE service information using the CLSI in the received message (5040). UPF 512 can obtain the service information (5060) from SMF 526. If the UL message is empty, UPF 512 identifies (5060) that a secure CLS-tp for a specific PDU session has not yet been established.

[0091] Then, the UPF 512 sends (5070) a security mode command message, such as a CLS-tp security mode command message, to the terminal device 110. For example, the UPF 512 can use CLS-tp to send an in-band security mode command carrying integrity protection security information to the terminal device.

[0092] In response to receiving the CLS-tp secure mode command message, terminal device 110 establishes a secure transport mode and replies with either secure mode completion or secure mode failure (not shown) (5090). For example, terminal device 110 verifies (5080) the integrity of the command based on integrity protection security information. If integrity is verified, terminal device 110 establishes a secure transport mode.

[0093] After the CLS-tp is established, terminal device 110 can be in a CLS active state. Terminal device 110 can now use the active connectionless messaging service to send and receive messages over a secure connection.

[0094] In this way, secure associations or secure CLS-tp can be established for (multiple) sessions of CL services. The established CLS-tp can support CL user plane messages and support services. CL message transmission and reception rely on the CLS-tp tunnel to carry integrity-protected and encrypted messages, as well as a plaintext header carrying the CLSI to identify the specific PDU session for a specific UE.

[0095] CLS DL and CLS UL messages using an established CLS-tp can be in the message format shown in Table 1. Specifically, the plaintext header in the CLS message contains a unique identifier (such as CLSI) for the specific PDU session of terminal device 110. This unique identifier can be used by RAN node 120 to select the appropriate UPF 512 assigned to support the PDU session, and can be used by UPF 512 to retrieve UE session information including the security key. The CLSI in the header is also used by terminal device 110 to distinguish DL messages for one of a potential multiple parallel PDU sessions using connectionless access. The header also carries an indication of the total message length, which is useful for RAN node 120 to determine whether segmentation is needed to map the message into one or more transport blocks.

[0096] After the security key is recovered using CLSI in UPF 512, the message portion can be decrypted and inspected. The message portion contains a common part (containing the message type), an optional new CLSI value used in subsequent messages and integrity protection, and an optional payload part (containing connectionless messages).

[0097] Already relative to Figure 4 and Figure 5Several example embodiments regarding association establishment for CL services are described. In some example embodiments, the service delivery mode can be changed. Embodiments of this disclosure propose a solution for changing the service delivery mode. In this solution, a device, such as a terminal device, receives a request from a network entity, such as a UPF, to change the service delivery mode. The request includes an identifier for a connectionless service. The device is in a connectionless access mode. The device determines that the service delivery mode will change from a connectionless access mode to a connection-oriented access mode. The device performs data transmission with the network entity in connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity. In this way, the service delivery mode can be changed from CL access mode to CO access mode. This flexible service delivery can enhance service performance.

[0098] Figure 6 The illustration shows a signaling flow 600 for changing a service delivery mode according to some example embodiments of the present disclosure. The signaling flow 600 relates to device 410 and network entity 130.

[0099] In operation, network entity 130 determines (6010) whether the service delivery mode associated with device 410 will be changed. If network entity 130 determines (6010) that the service delivery mode will be changed, network entity 130 sends (6020) a request to device 140 for changing the service delivery mode. The request includes an identifier for the connectionless service, such as a CLSI. The CLSI may be a unique ID associated with a PDU session of device 410. Device 410 is in CL access mode. Correspondingly, device 410 receives (6025) the request.

[0100] In the example, if traffic between device 410 and network entity 130 exceeds a threshold in CL access mode, network entity 130 can determine (6010) that the service delivery mode will be changed. The threshold can be predefined or (pre)configured. In this way, network entity 130 can trigger a service delivery mode change based on traffic volume. In another example, network entity 130 can receive information from network devices in the RAN (such as RAN node 120) indicating that traffic between device 410 and network entity 130 exceeds a threshold in CL access mode. Network entity 130 can determine (6010) that the service delivery mode will be changed based on the received information. In this way, network entity 130 can trigger a service delivery mode change based on the received information.

[0101] A request to change the service delivery mode may include a header and a body. The header includes an identifier for the connectionless service, such as a CLSI. The body includes at least a common portion indicating information about the request to change the service delivery mode. The request to change the service delivery mode may be a DL CL service message. The common portion of the request may indicate at least one of the following: the message type of the connectionless service message (in this example, a change in service delivery mode), a sequence number used to reorder the message, another identifier for the connectionless service (such as a new CLSI), or information about the integrity protection of the connectionless service message. Details of the DL CL service message are already relative to... Figure 3 As described above, and will not be repeated here. Using this DL CL service message, the CLSI can be used to identify terminal device 110. The message type can instruct terminal device 110 to change the service delivery mode.

[0102] In response to receiving (6025) the request, device 410 determines (6030) that the service delivery mode will change from CL access mode to CO access mode. Then, device 410 performs (6040) data transmission with network entity 130 in CO access mode by establishing a CO tunnel between device 410 and network entity 130. Similarly, network entity 130 performs (6050) data transmission with device 410 in CO access mode by establishing a CO tunnel between device 410 and network entity 130.

[0103] In some examples, device 410 can send a service request for CO access mode to network entity 130. Correspondingly, network entity 130 can receive the service request for CO access mode. Then, device 410 and network entity 130 can establish a CO tunnel between device 410 and network entity 130. In this way, the establishment of the CO tunnel can be triggered by the service request.

[0104] Network entity 130 can send remaining data held by network entity 130 to device 410 via a CO tunnel. Correspondingly, device 410 can receive remaining data held by network entity 130 from network entity 130 via a connection-oriented tunnel. In this way, the held remaining data can be sent in CO access mode. Therefore, the remaining data may not be discarded. In some embodiments, device 410 may send a response to the request to network entity 130. This response indicates whether the CL access mode has been successfully changed to CO access mode. In this way, network entity 130 can be notified of the currently used service delivery mode.

[0105] A response (also known as a "service delivery mode change response") can be a CL UL message. A response may include a header and a body. The header includes an identifier for the CL service, such as CLSI. The body includes at least a common portion indicating information about the response, such as the message type as a service delivery mode change response. The common portion of the response may indicate one or more of the following: the message type of the response, a sequence number used to reorder messages, or information about integrity protection of the response. The information in the common portion can be used to identify the corresponding device 410 and to indicate that the response is a response to a service delivery mode change request. Information about integrity protection can be used to protect the response. Details of the response message format have been provided. Figure 3 It has been described and will not be repeated here.

[0106] Using these embodiments, the service delivery mode can be adaptively changed. For example, for a large volume of traffic, the service delivery mode can be changed from CL access mode to CO access mode. Therefore, data transmission between devices such as UEs and network entities such as UPFs can be enhanced. This will be relative to... Figure 7 Other embodiments describing changes in service delivery patterns, Figure 7 Another signaling flow 700 for changing the service delivery mode is illustrated according to some example embodiments of the present disclosure. The signaling flow 700 relates to terminal device 110, RAN node 120, core network 510 (including UPF 512, AMF 524 and SMF 526) and DN 150.

[0107] Suppose that the process uses in-band user plane signaling from UPF 512 to terminal device 110 over CLS-tp to request terminal device 110 to change from CL access mode to CO access mode. This may only be used for PDU sessions configured to support combined CLS and CO delivery modes.

[0108] During operation, terminal device 110 may initially be in a CLS active state. In the CLS active state, terminal device 110 and DN 150 can exchange CLS messages.

[0109] In 7010, under CLS active state, the UE can be locally bound between RAN node 120 and UPF 512. Packet Data Network (PDN) messages can be exchanged between UPF 512 and DN 150 (7010). CLS messages can be exchanged between terminal device 110 and UPF 512 via CLS-tp tunnel (7030).

[0110] In this scenario, RAN node 120 and / or UPF 512 can detect excessive CLS mode traffic. In one example, RAN node 120 can detect (7040) excessive CLS mode traffic and send a (7050) service delivery mode change request to UPF 512. UPF 512 can then suspend downlink message delivery and begin (7070) buffering traffic. In another example, UPF 512 can detect (7060) excessive CLS mode traffic and begin (7070) buffering traffic such as DL messages.

[0111] UPF 512 sends a (7080) Service Delivery Mode Change Request to terminal device 110 to indicate a mode change from CL access mode to CO access mode. For example, UPF 512 uses a CLS-TP tunnel to request terminal device 110 to change the service delivery mode.

[0112] Terminal device 110 may send a (7090) service delivery mode change response to UPF 512. That is, terminal device 110 acknowledges the service delivery mode change request.

[0113] In some example embodiments, terminal device 110 initiates (7100) a service request for CO access. A dedicated CO tunnel for terminal device 110 may be established. In addition, a dedicated DRB for terminal device 110 may be established.

[0114] Using the established CO tunnel and DRB, CLS mode message sending and receiving are performed (7110). For example, the UPF 512 can use CO access to recover DL message delivery, so as to first send the buffered DL messages stored in the UPF 512 before recovering the delivery of subsequent DL messages.

[0115] Using these embodiments, the service delivery mode can be changed from CL access mode to CO access mode. It should be understood that in some scenarios, the service delivery mode can alternatively be changed from CO access mode to CL access mode. Flexible service delivery mode changes can be beneficial for various business scenarios.

[0116] It should be understood that some example specifications, signaling flows, and implementations have been provided above, and the detailed descriptions can vary. Note that... Figures 3 to 7 The sequence of actions shown is merely an example and not a limitation. Actions can be performed in any suitable manner. (See also...) Figures 3 to 7The described exemplary embodiments can be implemented individually or in any combination. For example, one or more exemplary embodiments shown in a single figure can be combined with one or more exemplary embodiments shown in one or more other figures. It should be noted that in actual implementation, the steps illustrated in one or more figures may be performed selectively. Using these embodiments, service delivery between the UE and the UPF can be enhanced.

[0117] Figure 8 A flowchart of an example method 800 implemented at a device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, method 800 will be discussed from... Figure 4 Angle description of device 401 in the diagram.

[0118] In block 810, device 410 sends a connectionless service message to a network entity, the message including an identifier for the connectionless service. A session supporting the connectionless service has been established between the device and the network entity. An association for the session based on the protocol used for the connectionless service has not yet been established.

[0119] In block 820, device 410 receives a security mode command message from a network entity, the security mode command message including integrity protection security information.

[0120] In box 830, device 410 determines whether the integrity check of the integrity protection security information was successful.

[0121] If the integrity check is successful, then in box 840, device 410 establishes an association with the network entity for performing secure transmission.

[0122] In some example embodiments, method 800 further includes sending information to the network entity indicating whether the association establishment was successful.

[0123] In some example embodiments, method 800 further includes: sending a security mode completion message to the network entity based on the determination that the association was successfully established; and sending a security mode failure message to the network entity based on the determination that the association was not successfully established.

[0124] In some example embodiments, method 800 further includes: determining a secure session key based at least on security information included in a secure mode command message; and performing secure transmission with a network entity based on the secure session key.

[0125] In some example embodiments, the device enters a connectionless service (CLS) active state after the association is successfully established.

[0126] In some example embodiments, a connectionless service message includes a header and a body, the header including an identifier of the connectionless service, and the body including at least a common portion indicating information about the connectionless service message.

[0127] In some example embodiments, the connectionless service message is an uplink message, and the common part indicates at least one of the following: the message type of the connectionless service message, the sequence number used to reorder the message, or information regarding the integrity protection of the connectionless service message.

[0128] In some example implementations, the body of a connectionless service message does not include a payload.

[0129] In some example embodiments, the identifier for a connectionless service includes a connectionless service identifier (CLSI).

[0130] In some example embodiments, the apparatus includes a terminal device, and the network entity includes or implements user plane functionality. Alternatively or otherwise, a session is a Protocol Data Unit (PDU) session associated with the apparatus.

[0131] In some example embodiments, any of the means capable of performing method 800 (e.g.) Figure 4 The device 410 may include a component for performing the corresponding operation of method 800. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The device can be implemented as... Figure 4 The device 410 is included in, or is contained in, the device 410.

[0132] Figure 9 A flowchart of an example method 900 implemented at a network entity according to some example embodiments of the present disclosure is shown. For discussion purposes, method 900 will be discussed from... Figure 1 The perspective description of network entity 130 in the text.

[0133] In box 910, network entity 130 receives a connectionless service message from the device, the connectionless service message including an identifier for the connectionless service. A session supporting the connectionless service has been established between the device and network entity 130.

[0134] In box 920, network entity 130 determines whether an association for a session based on the protocol used for connectionless services has been established.

[0135] If the association has not yet been established, in box 930, network entity 130 sends a security mode command message to the device, which includes integrity protection security information used to establish an association with the network entity for performing secure transmission.

[0136] In some example embodiments, method 900 further includes receiving information from the device indicating whether the association was successfully established.

[0137] In some example embodiments, method 900 further includes: receiving a safe mode completion message from the device. The safe mode completion message indicates that the association was successfully established. Alternatively, method 900 further includes: receiving a safe mode failure message from the device. The safe mode failure message indicates that the association was not successfully established.

[0138] In some example embodiments, method 900 further includes: determining a secure session key based at least on security information included in a secure mode command message; and performing secure transmission with the device based on the secure session key.

[0139] In some example embodiments, method 900 further includes: in response to receiving a connectionless service message, obtaining service information related to the device; and determining, based on the obtained information, that an association has not yet been established.

[0140] In some example embodiments, a connectionless service message includes a header and a body, the header including an identifier of the connectionless service, and the body including at least a common portion indicating information about the connectionless service message.

[0141] In some example embodiments, the connectionless service message is an uplink message, and the common part indicates at least one of the following: the message type of the connectionless service message, the sequence number used to reorder the message, or information regarding the integrity protection of the connectionless service message.

[0142] In some example implementations, the body of a connectionless service message does not include a payload.

[0143] In some example embodiments, the identifier for a connectionless service includes a connectionless service identifier (CLSI).

[0144] In some example embodiments, the apparatus includes a terminal device, and the network entity includes or implements user plane functionality. In some embodiments, a session is a Protocol Data Unit (PDU) session associated with the apparatus.

[0145] In some example embodiments, any network entity in method 900 can be executed (e.g., Figure 1 The network entity 130 in the diagram may include a component for performing the corresponding operation of method 900. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The network entity can be implemented as... Figure 1 Network entity 130, or being included in network entity 130.

[0146] Figure 10 A flowchart of an example method 1000 implemented at a device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, method 1000 will be discussed from... Figure 6 Angle description of device 401 in the diagram.

[0147] In box 1010, device 410 receives a request from a network entity to change the service delivery mode. The request includes an identifier for a connectionless service. Device 410 is in connectionless access mode.

[0148] In box 1020, device 410 determines that the service delivery mode will change from connectionless access mode to connection-oriented access mode.

[0149] In block 1030, device 410 performs data transmission with network entities in connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

[0150] In some example embodiments, method 1000 further includes: sending a service request for a connection-oriented access mode to a network entity; and establishing a connection-oriented tunnel between the device and the network entity.

[0151] In some example embodiments, method 1000 further includes receiving remaining data already held by the network entity from the network entity via a connection-oriented tunnel.

[0152] In some example embodiments, a request to change the service delivery mode includes a header and a body, the header including an identifier of the connectionless service, and the body including a common portion indicating information about the request to change the service delivery mode.

[0153] In some example embodiments, the connectionless service message is a downlink message, and the common part indicates at least one of the following: the message type of the connectionless service message, the sequence number used to reorder the message, another identifier for the connectionless service, or information regarding the integrity protection of the connectionless service message.

[0154] In some example embodiments, method 1000 further includes sending a response to the request to a network entity, the response indicating whether the connectionless access mode has been successfully changed to a connection-oriented access mode.

[0155] In some example embodiments, the response includes a header and a body, the header including an identifier of the connectionless service, and the body including a public portion indicating information about the response.

[0156] In some example embodiments, the response is an uplink message, and the common portion indicates at least one of the following: the message type of the response, the sequence number used to reorder the message, or information regarding the integrity protection of the response.

[0157] In some example embodiments, the identifier for a connectionless service includes a connectionless service identifier (CLSI).

[0158] In some example embodiments, the device includes a terminal device, and the network entity includes or implements user plane functionality.

[0159] In some example embodiments, any of the means capable of performing method 1000 (e.g.) Figure 6 The device 140 may include components for performing the corresponding operations of method 1000. These components can be implemented in any suitable form. For example, the components can be implemented in a circuit system or a software module. The device can be implemented as... Figure 6 The device 410 is included in, or is contained in, the device 410.

[0160] Figure 11 A flowchart of an example method 1100 implemented at a network entity according to some example embodiments of this disclosure is shown. For the purposes of discussion, method 1100 will be discussed from... Figure 1 The perspective description of network entity 130 in the text.

[0161] In box 1110, based on the determination that the service delivery mode associated with the device will be changed, network entity 130 sends a request to the device to change the service delivery mode. This request includes an identifier for a connectionless service. The device is in connectionless access mode.

[0162] In box 1120, network entity 130 performs data transmission with the device in connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

[0163] In some example embodiments, method 1100 further includes: receiving a service request for a connection-oriented access mode from the device; and establishing a connection-oriented tunnel between the device and a network entity.

[0164] In some example embodiments, method 1100 further includes sending the remaining data already held by the network entity to the device via a connection-oriented tunnel.

[0165] In some example embodiments, a request to change the service delivery mode includes a header and a body, the header including an identifier of the connectionless service, and the body including a common portion indicating information about the request to change the service delivery mode.

[0166] In some example embodiments, the connectionless service message is a downlink message, and the common part indicates at least one of the following: the message type of the connectionless service message, the sequence number used to reorder the message, another identifier for the connectionless service, or information regarding the integrity protection of the connectionless service message.

[0167] In some example embodiments, method 1100 further includes receiving a response from the device to a request, the response indicating whether the connectionless access mode has been successfully changed to a connection-oriented access mode.

[0168] In some example embodiments, the response includes a header and a body, the header including an identifier of the connectionless service, and the body including a public portion indicating information about the response.

[0169] In some example embodiments, the response is an uplink message, and the common portion indicates at least one of the following: the message type of the response, the sequence number used to reorder the message, or information regarding the integrity protection of the response.

[0170] In some example embodiments, the identifier for a connectionless service includes a connectionless service identifier (CLSI).

[0171] In some example embodiments, method 1100 further includes: determining that the service delivery mode will be changed based on the determination that the traffic between the device and the network entity in the connectionless access mode exceeds a threshold.

[0172] In some example embodiments, method 1100 further includes: receiving from a network device in a wireless access network information indicating that traffic between the device and a network entity exceeds a threshold in connectionless access mode; and determining, based on the received information, that the service delivery mode will be changed.

[0173] In some example embodiments, the device includes a terminal device, and the network entity includes or implements user plane functionality.

[0174] In some example embodiments, any network entity capable of performing method 1100 (e.g. Figure 1 The network entity 130 may include a component for performing the corresponding operation of method 1100. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The network entity can be implemented as... Figure 1 Network entity 130, or being included in network entity 130.

[0175] Figure 12 A flowchart of an example method 1200 implemented at a device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, method 1200 will be discussed from... Figure 3Angle description of device 310 in the diagram.

[0176] In block 1210, device 310 receives or transmits a message related to a connectionless service associated with both the device and another device. The connectionless service supports data transmission without a Radio Resource Control (RRC) connection. The message includes a header and a body. The header includes an identifier for the connectionless service, and the body includes at least a common portion indicating information about the message.

[0177] In some example implementations, the header is unencrypted, while the body is encrypted.

[0178] In some example embodiments, the message is a downlink message, and the common portion indicates at least one of the following: the message type of the message, the sequence number used to reorder the message, another identifier for the connectionless service, or information about the integrity protection of the message.

[0179] In some example embodiments, the message is an uplink message, and the common portion indicates at least one of the following: the message type, the sequence number used to reorder the message, or information about message integrity protection.

[0180] In some example embodiments, the body also includes a payload portion. In some example embodiments, the message payload includes a connectionless access message to be delivered.

[0181] In some example implementations, the message is one of the following types: downlink message, security mode command, or request to change the service delivery mode.

[0182] In some example implementations, the message is one of the following types: uplink message, security mode completion, security mode failure, or response to a change in service delivery mode.

[0183] In some example embodiments, the identifier for a connectionless service includes a connectionless service identifier (CLSI).

[0184] In some example embodiments, device 310 includes a terminal device, and another device includes a network entity that includes or implements user plane functionality. Alternatively, device 310 includes a network entity that includes or implements user plane functionality, and another device includes a terminal device.

[0185] In some example embodiments, any of the means capable of performing method 1200 (e.g.) Figure 3The device 310 may include a component for performing the corresponding operation of method 1200. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The device can be implemented as... Figure 3 The device 310 is included in, or is contained in, the device 310.

[0186] Figure 13 This is a simplified block diagram of a device 1300 suitable for implementing an example embodiment of the present disclosure. Device 1300 may be provided to implement a communication device, such as... Figure 1 The terminal device 110, RAN node 120, network entity 130, and / or network entity 140 are shown. As shown, device 1300 includes one or more processors 1310, one or more memories 1320 coupled to processor 1310, and one or more communication modules 1340 coupled to processor 1310.

[0187] Communication module 1340 is used for bidirectional communication. Communication module 1340 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface can represent any interface necessary for communication with other network elements. In some example embodiments, communication module 1340 may include at least one antenna.

[0188] Processor 1310 can be any type suitable for a local technology network and can include one or more of the following: general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), and processors based on multi-core processor architectures, as non-limiting examples. Device 1300 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock synchronized with the main processor.

[0189] Memory 1320 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1324, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disc (DVD), optical disc, laser disc, and other magnetic and / or optical storage devices. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1322 and other volatile memories that do not persist during power-off periods.

[0190] Computer program 1330 includes computer-executable instructions that are executed by the associated processor 1310. The instructions of program 1330 may include instructions for performing operations / actions of some example embodiments of this disclosure. Program 1330 may be stored in memory, such as ROM 1324. Processor 1310 can perform any suitable actions and processes by loading program 1330 into RAM 1322.

[0191] Example embodiments of this disclosure can be implemented using program 1330, enabling device 1300 to execute references. Figures 3 to 12 Any process discussed in this disclosure. Exemplary embodiments of this disclosure may also be implemented by hardware or a combination of software and hardware.

[0192] In some example embodiments, program 1330 may be tangibly contained in a computer-readable medium, which may be included in device 1300 (such as memory 1320) or other storage devices accessible by device 1300. Device 1300 may load program 1330 from the computer-readable medium into RAM 1322 for execution. In some example embodiments, the computer-readable medium may include any type of non-transient storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. The term "non-transient" as used herein refers to a limitation on the medium itself (i.e., tangible, not tactile), rather than a limitation on the persistence of data storage (e.g., RAM and ROM).

[0193] Figure 14 An example of a computer-readable medium 1400, which may be in the form of a CD, DVD, or other optical storage disc, is shown. The computer-readable medium 1400 stores a program 1330 thereon.

[0194] In general, various embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this disclosure are illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented as non-limiting examples in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers, or other computing devices, or some combination thereof.

[0195] Some exemplary embodiments of this disclosure also provide at least one computer program product tangibly stored on a computer-readable medium, such as a non-transitory computer-readable medium. The computer program product includes computer-executable instructions, such as those included in a program module that executes in a device on a target physical or virtual processor to perform any of the methods described above. Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., that perform a particular task or implement a particular abstract data type. In various embodiments, the functionality of program modules can be combined or split among program modules as needed. The machine-executable instructions of the program module can be executed within a local or distributed device. In a distributed device, the program module can reside in both local and remote storage media.

[0196] Program code used to perform the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0197] In the context of this disclosure, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.

[0198] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More specific examples of computer-readable storage media will include electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0199] Furthermore, although the operations are depicted in a specific order, this should not be construed as requiring that such operations be performed in the specific order shown or in a sequential order, or that all illustrated operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure, but rather as a description of features that may be specific to particular embodiments. Unless explicitly stated otherwise, certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated otherwise, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0200] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that this disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms for implementing the claims.

Claims

1. A device for communication, comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the device to at least: Receive a request from a network entity to change the service delivery mode, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode. It is determined that the service delivery mode will be changed from the connectionless access mode to a connection-oriented access mode. as well as Data transmission with the network entity is performed in the connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

2. The apparatus of claim 1, wherein the apparatus is configured to: Send a service request for the connection-oriented access mode to the network entity; and Establish the connection-oriented tunnel between the device and the network entity.

3. The apparatus according to claim 1 or 2, wherein the apparatus is configured to: The remaining data already held by the network entity is received from the network entity via the connection-oriented tunnel.

4. The apparatus according to any one of claims 1 to 3, wherein the request for changing the service delivery mode includes a header and a body, the header including the identifier of the connectionless service, and the body including a common portion indicating information regarding the request for changing the service delivery mode.

5. The apparatus of claim 4, wherein the request is a downlink message, and the common portion indicates at least one of the following: The message type of the connectionless service message. The sequence number used to reorder messages. Another identifier for connectionless services, or Information regarding the integrity protection of the connectionless service messages.

6. The apparatus according to any one of claims 1 to 5, wherein the apparatus is configured to: Send a response to the request to the network entity, the response indicating whether the connectionless access mode has been successfully changed to the connection-oriented access mode.

7. The apparatus of claim 6, wherein the response comprises a header and a body, the header comprising the identifier of the connectionless service, and the body comprising a common portion indicating information about the response.

8. The apparatus of claim 7, wherein the response is an uplink message, and the common portion indicates at least one of the following: The message type of the response. The sequence number used to reorder messages, or Information regarding the integrity protection of the response.

9. The apparatus of claims 1 to 8, wherein the identifier of the connectionless service includes a connectionless service identifier (CLSI).

10. The apparatus according to any one of claims 1 to 9, wherein the apparatus includes a terminal device and the network entity includes or implements user plane functionality.

11. A network entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the network entity to at least: Based on the determination that the service delivery mode associated with the device will be changed, a request for changing the service delivery mode is sent to the device, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode. as well as Data transmission with the device is performed in the connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

12. The network entity of claim 11, wherein the network entity is such that: Receive a service request for the connection-oriented access mode from the device; and Establish the connection-oriented tunnel between the device and the network entity.

13. The network entity according to claim 11 or 12, wherein the network entity is such that: The remaining data already held by the network entity is sent to the device via the connection-oriented tunnel.

14. The network entity of any one of claims 11 to 13, wherein the request for changing the service delivery mode includes a header and a body, the header including the identifier of the connectionless service, and the body including a common portion indicating information regarding the request for changing the service delivery mode.

15. The network entity of claim 14, wherein the request is a downlink message, and the common portion indicates at least one of the following: The message type of the connectionless service message. The sequence number used to reorder messages. Another identifier for connectionless services, or Information regarding the integrity protection of the connectionless service messages.

16. The network entity according to any one of claims 11 to 15, wherein the network entity is such that: The device receives a response to the request, the response indicating whether the connectionless access mode has been successfully changed to the connection-oriented access mode.

17. The network entity of claim 16, wherein the response comprises a header and a body, the header comprising the identifier of the connectionless service, and the body comprising a common portion indicating information about the response.

18. The network entity of claim 17, wherein the response is an uplink message, and the common portion indicates at least one of the following: The message type of the response. The sequence number used to reorder messages, or Information regarding the integrity protection of the response.

19. The network entity according to claims 11 to 18, wherein the identifier of the connectionless service includes the connectionless service identifier CLSI.

20. The network entity according to claims 11 to 19, wherein the network entity is such that: If it is determined that the service delivery mode will be changed if the service between the device and the network entity in the connectionless access mode exceeds a threshold.

21. The network entity according to claims 11 to 19, wherein the network entity is such that: Receive from a network device in the wireless access network information indicating that the service between the device and the network entity in the connectionless access mode exceeds a threshold; and Based on the received information, it is determined that the service delivery mode will be changed.

22. The network entity according to any one of claims 11 to 21, wherein the means includes a terminal device, and the network entity includes or implements user plane functionality.

23. A method for communication, comprising: The device receives a request from a network entity for changing the service delivery mode, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode. It is determined that the service delivery mode will be changed from the connectionless access mode to a connection-oriented access mode. as well as Data transmission with the network entity is performed in the connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

24. A method for communication, comprising: Based on the determination that the service delivery mode associated with the device will be changed, a request for changing the service delivery mode is sent to the device at the network entity, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode. as well as Data transmission with the device is performed in the connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

25. An apparatus for communication, comprising: A component for receiving a request from a network entity for changing a service delivery mode, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode. Components for determining that the service delivery mode will be changed from the connectionless access mode to a connection-oriented access mode; as well as A component for performing data transmission with the network entity in the connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

26. A network entity, comprising: A component for sending a request to a device to change the service delivery mode based on a determination that the service delivery mode associated with the device will be changed, wherein the request includes an identifier of a connectionless service, and wherein the device is in a connectionless access mode. as well as A component for performing data transmission with the device in the connection-oriented access mode by establishing a connection-oriented tunnel between the device and the network entity.

27. A computer-readable medium comprising instructions stored on the computer-readable medium, the instructions being configured to cause a device to perform at least the method of claim 23 or the method of claim 24.