User-device-driven handling of security policy for protection in 5G systems at the user level

DE602019082034T2Active Publication Date: 2026-03-04TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602019082034
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-04-06
Filing Date
2019-04-05
Publication Date
2026-03-04
Estimated Expiration
2039-04-05

AI Technical Summary

Technical Problem

In 5G systems, the establishment of multiple integrity protected PDU sessions without considering the UE's maximum DRB-IP rate can lead to rejection of sessions and service delays due to mismatched security policy assignments exceeding the UE's computational capacity.

Method used

A mechanism is introduced to manage the Max DRB-IP rate centrally, allowing the UE to track and adjust its available capacity before AS resource allocation, ensuring it has sufficient computational resources for integrity protection.

Benefits of technology

This approach prevents unnecessary rejection of PDU sessions and optimizes radio resource allocation by aligning security policies with the UE's capacity, reducing service delays and ensuring efficient use of system resources.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates generally to communications, and more particularly, to wireless communications and related wireless devices and network nodes.BACKGROUND

[0002] The 3 rd< Generation Partnership Project (3GPP) is developing standards for 5 th< generation wireless systems (5G) and / or Next Generation (NG) Systems. 5G supports many scenarios and use cases and will be an enabler for the internet of things (IoT). NG systems provide connectivity to a wide range of devices such as sensors, smart wearables, vehicles, and machines. Flexibility can be a valuable characteristic in NG Systems. This can be reflected in the security requirements for network access that are mandating the support of alternative authentication methods and different types of credentials than the usual authentication and key agreement (AKA) credentials pre-provisioned by the operator and securely stored in the universal integrated circuit card (UICC). This can allow factory owners or enterprises to leverage their own identity and credential management systems for authentication and access network security.

[0003] The 3GPP architecture working group (SA2) has finalized the architecture of 5G Systems. FIG. 1 depicts an example of a non-Roaming 5G System Architecture in reference point representation from TS 23.501 [1]. The 3GPP security group (SA3) may finalize the security specification for the 5G Systems in TS 33.501 [2]. Among the new security features in 5G Systems are the introduction of the integrity protection of the User Plane (UP) and the support for a separate mechanism for the negotiation of the UP security. The separate mechanism for the negotiation of the UP security can include a procedure for determining whether and which of integrity or confidentiality should be activated for a UP session.

[0004] In long term evolution (LTE), there is no integrity protection for UP and the negotiation of UP confidentiality is integrated in the activation of the security for the Control Plane (CP) in the Access Stratum (AS) between the evolved node B (eNB) and the user equipment (UE). As described in TS 33.401 [3], the security for the AS CP can be activated by a run of the AS Security Mode Command (SMC) procedure, which can allow selection of cryptographic algorithms and activation of security for the radio resource control (RRC) protocol. A lower level protocol can provide security, for example a packet data convergence protocol in the AS CP protocol stack. Furthermore, since integrity protection of UP is supported in LTE and confidentiality protection is mandatory, the confidentiality algorithm selected during the AS SMC can be automatically used for the protection of the UP traffic.

[0005] The negotiation of UP security in the 5G System can allow the radio access network (RAN) node to receive a UP security policy from the Core Network (CN) during the Packet Data Unit (PDU) Session establishment procedure. This policy can be applied on a PDU Session level. For example, RAN can be applied to the UP security, received from the CN, to all the Data Radio Bearers (DRBs) serving the PDU Session. Furthermore, this UP Security policy can include indications on whether to activate integrity protection, confidentiality protection, or both.

[0006] This kind of flexibility can be important in a 5G System, which can be expected to provide connectivity for various types of services and devices. For example, integrity protection may be sufficient for IoT services while for the usual voice and broadband services, as in LTE, confidentiality protection may be required.

[0007] FIG. 2 depicts an example of a simplified flow of the PDU Session establishment procedure from TS 23.502 [1]. The term Radio Access Network can be used to denote an Access Network (AN) of 3GPP type. Since the 5G System was expected to support both 3GPP and non-3GPP AN type, the system attempts to be agnostic towards the type of AN. Therefore, (R)AN can be used to refer to both types of ANs in all procedures that are in fact agnostic.

[0008] In operation 210, the UE can initiate the procedure by sending a PDU Session Establishment Request Network Access Stratum (NAS) message to the access and mobility management function (AMF). In operation 220, the AMF can trigger different CN interactions, for example, for the selection of the SMF, the retrieval of the subscription data, or the allocation of UP resources. In operation 230, the SMF can acquire the UP Security Policy for this session. The UP Security Policy can be based on subscription data, local configuration, or provisioning from another CN Network Function (NF) such as unified data management (UDM) or policy control function (PCF). In operation 240, the SMF can use the Namf_Communication_N1N2MessageTransfer service to transfer a message containing an N2 part destined to the (R)AN and an N1 part destined to the UE. The N2 part can include among the UP Security policy for the current session being established. In operation 250, the AMF can forward the SMF message to the (R)AN. In operation 260, the (R)AN can act on the N2 part and can forward the N1 part to the UE. The (R)AN can retrieve the UP Security Policy and use it during the AN-specific resource setup to indicate to the UE, via RRC signaling, whether to activate integrity protection, confidentiality protection, or both for each of the DRBs serving the session being established.

[0009] A CN can establish multiple integrity protected PDU sessions creating a risk that the UE rejects a PDU session and is delayed access to service.

[0010] 3GPP Standards Document XP051399817 ("Framework for DRB Integrity Protection") discusses the overall architectural framework applicable to DRB IP and suggests capturing the dateRateDRB-IP as a security capability.SUMMARY

[0011] The present invention is defined by the subject-matter of the independent claims. Preferred embodiments are defined by the dependent claims.

[0012] According to some embodiments of inventive concepts, a mechanism can be provided to prevent rejection of PDU Sessions and unwanted service delays by handling a Max DRB-IP Rate for a user equipment (UE) in a centralized manner to ensure that the UE has capacity prior to AS resource allocation.

[0013] According to some embodiments, a method may be provided to operate a UE for handling security policy for user plane protection of communications in a communications system. The method includes transmitting a packet data unit (PDU) session establishment request network access stratum (NAS) message toward an Access and Mobility Management Function (AMF) to establish a PDU session. The method further includes receiving an access network (AN) specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session. The method may further include summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate. The method further comprises summing DRB Integrity Protected, DRB-IP, rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

[0014] A potential advantage of this method is that radio resources of the communication system are more efficiently used. UEs have varying operationally limits on their computational capacity to process DRBs that are to be integrity protected during PDU sessions, which can be referred to as a maximum DRB-IP rate of a UE. A UE that is operated according to this method may dynamically track how much of its maximum DRB-IP rate is presently being used to provide integrity protection for DRBs of any active PDU sessions. The UE can thereby coordinate with the AMF and / or SMF to avoid erroneous selection of security policies for use in communications between the AN and UE and resulting incompatible assignment of DRB rates for integrity protection that would exceed the available capacity of the UE and result in wasteful allocation of system radio resources.

[0015] According to some other embodiments, a method to be performed by a communications system by a user equipment and by an Access and Mobility Management Function (AMF) of a communications system. The method includes receiving a packet data unit (PDU) session establishment request network access stratum (NAS) message from a user equipment (UE) requesting establishment of a PDU session. The PDU session establishment request NAS message includes an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established. The method further includes communicating toward a Session Management Function (SMF) a PDU session create message containing the indication of the available DRB-IP rate of the UE. The method further includes receiving a SMF message containing an indication of a user plane (UP) security policy for a PDU session being established. The method further includes communicating a message containing the indication of the UP security policy to an access node (AN) that is communicating through a wireless air interface with the UE.

[0016] According to some other embodiments, a method to be performed by a communications system, by a user equipment and a Session Management Function (SMF) of a communications system. The method includes receiving from an Access and Mobility Management Function (AMF) a packet data unit (PDU) session create message for a user equipment (UE) that is requesting establishment of a PDU session. The PDU session create message includes an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established. The method further includes determining a user plane (UP) security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity. The method further includes communicating to the AMF a message containing an indication of the UP security policy for the PDU session being established.BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which are included to provide a further understanding of the disclosure and are incorporated in a constitute a part of this application, illustrate certain non-limiting embodiments of inventive concepts. In the drawings: FIG. 1 is a block diagram illustrating an example of a non-roaming 5G system architecture in reference point representation; FIG. 2 is a flow diagram illustrating an example of a PDU session establishment procedure; FIG. 3 is a flow diagram illustrating an example of management of the max DRB-IP rate during a PDU session establishment procedure according to some embodiments of the present invention; FIG. 4 is a block diagram illustrating an example of a wireless device UE; FIG. 5 is a block diagram illustrating an example of a (R)AN; FIG. 6 is a block diagram illustrating an example of a AMF; FIG. 7 is a block diagram illustrating an example of a SMF; FIGS. 8A-B are flow charts illustrating example operations of a wireless device according to some embodiments of the present invention; FIG. 9 is a flow chart illustrating example operations of an AMF according to some embodiments of the present invention; FIG. 10 is a flow chart illustrating example operations of a SMF according to some embodiments of the present invention; DETAILED DESCRIPTION

[0018] Inventive concepts will now be described more fully hereinafter with reference to the accompanying drawings, in which examples of embodiments of inventive concepts are shown. Inventive concepts may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of present inventive concepts to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment may be tacitly assumed to be present / used in another embodiment.

[0019] The following description presents various embodiments of the disclosed subject matter. These embodiments are presented as teaching examples and are not to be construed as limiting the scope of the disclosed subject matter. For example, certain details of the described embodiments may be modified, omitted, or expanded upon without departing from the scope of the described subject matter.

[0020] FIG. 4 is a block diagram illustrating elements of a UE, which can be interchangeably called any one or more of a wireless terminal, a wireless communication device, wireless device, a wireless communication terminal, and a user equipment node / terminal / device without limitation on the operations thereof. The UE is configured to provide wireless communication according to embodiments of inventive concepts. As shown, UE may include at least one antenna 4007, and at least one transceiver circuit 4001 (also referred to as a transceiver) including a transmitter and a receiver configured to provide uplink and downlink radio communications with a base station eNB of a wireless communication network (also referred to as a radio access network RAN). UE may also include at least one processor circuit 4003 (also referred to as a processor) coupled to the transceiver, and at least one memory circuit 4005 (also referred to as memory) coupled to the processor. The memory 4005 may include computer readable program code that when executed by the processor 4003 causes the processor to perform operations according to embodiments disclosed herein. According to other embodiments, processor 4003 may be defined to include memory so that a separate memory circuit is not required. UE may also include an interface (such as a user interface) coupled with processor 4003, and / or wireless device UE may be an IoT and / or MTC device.

[0021] As discussed herein, operations of wireless device UE may be performed by processor 4003 and / or transceiver 4001. For example, processor 4003 may control transceiver 4001 to transmit uplink communications through transceiver 4001 over a radio interface to a base station eNB of a wireless communication network and / or to receive downlink communications through transceiver 4001 from a base station eNB of the wireless communication network over a radio interface. Moreover, modules may be stored in memory 4005, and these modules may provide instructions so that when instructions of a module are executed by processor 4003, processor 4003 performs respective operations (e.g., operations discussed below with respect to Example Embodiments).

[0022] FIG. 5 is a block diagram illustrating elements of a (R)AN configured to provide cellular communication. As shown, the (R)AN may include at least one transceiver circuit 5001 (also referred to as a transceiver) including a transmitter and a receiver configured to provide uplink and downlink radio communications with wireless devices. The (R)AN may include at least one network interface circuit 5007 (also referred to as a network interface) configured to provide communications with nodes (e.g., with base stations and / or core network nodes). The (R)AN may also include at least one processor circuit 5003 (also referred to as a processor) coupled to the transceiver, and at least one memory circuit 5005 (also referred to as memory) coupled to the processor. The memory 5005 may include computer readable program code that when executed by the processor circuit 5003 causes the processor to perform operations according to embodiments disclosed herein. According to other embodiments, processor 5003 may be defined to include memory so that a separate memory circuit is not required.

[0023] As discussed herein, operations of the (R)AN may be performed by processor 5003, network interface 5007, and / or transceiver 5001. For example, processor 5003 may control transceiver 5001 to transmit downlink communications through transceiver 5001 over a radio interface to one or more UEs and / or to receive uplink communications through transceiver 5001 from one or more UEs over a radio interface. Similarly, processor 5003 may control network interface 5007 to transmit communications through network interface 5007 to one or more other network nodes and / or to receive communications through network interface from one or more other network nodes. Moreover, modules may be stored in memory 5005, and these modules may provide instructions so that when instructions of a module are executed by processor 5003, processor 5003 performs respective operations (e.g., operations discussed below with respect to Example Embodiments).

[0024] FIG. 6 is a block diagram illustrating elements of an AMF configured to provide wireless communication. As shown the AMF may include at least one network interface circuit 6007 (also referred to as a network interface) configured to provide communications with nodes (e.g., with base stations and / or core network nodes). The AMF may also include at least one processor circuit 6003 (also referred to as a processor) coupled to the transceiver, and at least one memory circuit 6005 (also referred to as memory) coupled to the processor. The memory circuit 6005 may include computer readable program code that when executed by the processor 6003 causes the processor 6003 to perform operations according to embodiments disclosed herein. According to other embodiments, processor 6003 may be defined to include memory so that a separate memory circuit is not required.

[0025] As discussed herein, operations of the AMF may be performed by processor 6003 and / or network interface 6007. Modules may be stored in memory 6005, and these modules may provide instructions so that when instructions of a module are executed by processor 6003, processor 6003 performs respective operations (e.g., operations discussed below with respect to Example Embodiments).

[0026] FIG. 7 is a block diagram illustrating elements of an SMF configured to provide wireless communication. As shown the SMF may include at least one network interface circuit 7007 (also referred to as a network interface) configured to provide communications with nodes (e.g., with base stations and / or core network nodes). The SMF may also include at least one processor circuit 7003 (also referred to as a processor) coupled to the network interface, and at least one memory circuit 7005 (also referred to as memory) coupled to the processor. The memory 7005 may include computer readable program code that when executed by the processor 7003 causes the processor to perform operations according to embodiments disclosed herein. According to other embodiments, processor 7003 may be defined to include memory so that a separate memory circuit is not required.

[0027] As discussed herein, operations of the SMF may be performed by processor 7003 and / or network interface 7007. Modules may be stored in memory 7005, and these modules may provide instructions so that when instructions of a module are executed by processor 7003, processor 7003 performs respective operations (e.g., operations discussed below with respect to Example Embodiments).

[0028] In some embodiments, the AMF and SMF may share one or more components. For example, operations of the AMF and SMF may be performed by one or more shared processors. The processors may be included in one or more nodes across one or more RAN.

[0029] In some embodiments, a parameter referred to as Max DRB-IP Rate can be introduced in the UE in response to hardware restrictions and performance overhead. This parameter can be included in the UE capabilities Information Element (IE) and can be used to indicate the UE capacity for integrity protected DRBs. As part of the UE capabilities, the parameter can be signaled to the CN during the initial Registration procedure as described in TS 23.502 [1].

[0030] For a given a UE, in case the CN establishes multiple integrity protected PDU Sessions without considering the MAX DRB-IP rate, then there is a risk that the UE rejects a PDU Sessions and is thus delayed access to service. Furthermore, this new parameter defines the upper bound for the sum of all rates in all integrity protected active DRBs. This, in addition to the fact that the 5G systems allows UE to establish multiple PDU Sessions in parallel and even involving different SMFs, introduces more complexity. In some examples, the Max DRB-IP Rate is managed somewhere that can track, for a given UE, all the active PDU Sessions. The 3GPP 5G standards may not provide a mechanism for how to handle the Max DRB-IP Rate when determining the UP Security Policy.

[0031] In some embodiments of the present disclosure, a mechanism can be provided to handle the Max DRB-IP Rate in a centralized manner to ensure that the UE has capacity prior to AS resource allocation and thus prevent rejection of PDU Sessions and unwanted service delays. In some examples, the UE provides the centralized handling itself. In some examples, handling the Max DRB-IP in a centralized manner can allow full use of the Max DRB-IP Rate and can provide as much security as possible for the given upper bound. In some examples, handling the Max DRB-IP in a centralized manner can prevent unexpected rejection of PDU Sessions to Max DRB-IP rate exhaustion, which can reduce delays to services. In some examples, handling the Max DRB-IP in a centralized manner can support parallel PDU Sessions even involving different SMFs. In some examples, handling the Max DRB-IP in a centralized manner can allow control of which PDU Sessions to prioritize being integrity protected.

[0032] In some embodiments, responsibility for handling of the Max DRB-IP Rate and the book keeping of used resources can be performed by the UE. For example, the UE can indicate the available rate to the core network (CN) during PDU Session Establishment procedure and the CN can determine the UP Security policy based on the provided information. In some examples, assigning the UE to handle UE-specific resources can be advantageous because the UE can track use and availability of the UE-specific resources. In contrast, delegating the handling of the Max DRB-IP Rate to the CN may require additional CN signaling and may not eliminate the risk for a mismatch between the computed available rate in the CN and the amount of available resource in the UE. FIG. 3 depicts an example of UE controlled management of the Max DRB-IP during a PDU session establishment procedure.

[0033] In operation 310, the UE initiates a PDU Session Establishment procedure by sending a PDU Session Establishment Request NAS message to the AMF. The UE can include an indication on the available rate. In some examples, the UE may not have any active PDU Sessions with integrity protection, and the available rate parameter can indicate the full Max DRB-IP rate value.

[0034] In operation 320, the AMF using the indicated signaling, and which may use other not shown CN signaling, can send a Namf_PDUSession_CreateSMContext Request message to the selected SMF. This message can include the available rate forwarded by the UE.

[0035] In operation 330, the SMF can determine the UP Security Policy for the PDU Session based on the available rate provided by the UE through the AMF. For example, the SMF can decide whether to activate integrity protection based on the required Flows quality of service (QoS) and the available rate in order to make sure that the UE can support the required rates with integrity protection.

[0036] Operations 340, 350, and 360 are similar to operations 240, 250, and 260 discussed above in reference to FIG. 2.

[0037] In operation 370, following the setup of the DRBs for the PDU Session and based on whether integrity protection is activated for some of the new DRBs or not, the UE adjusts the internal available rate variable to keep track of the resource usage by subtracting the allocated rates for integrity protected DRBs from the currently stored value.

[0038] Various implementations are possible for how the UE keeps track of the integrity protection resource usage. In some examples, the UE may not store the integrity protection resource usage in a variable. For example, the UE can determine the integrity protection resource usage on a-need-to-know-basis by summing the rates of all active DRBs with integrity protection on.

[0039] In some embodiments, UE controlled management of the Max DRB-IP may not require additional signaling and book keeping overhead in the CN NFs besides that of forwarding the UE signaled indication on available rate. The risks of mismatch and wrong estimation can be reduced or minimized.

[0040] Operations of a wireless device UE will now be discussed with reference to the flow charts of FIGS. 8A-B according to some embodiments of inventive concepts. For example, modules may be stored in wireless terminal memory 4005 of FIG. 4 and these modules may provide instructions so that when the instructions of a module are executed by wireless device processor 4003, processor 4003 performs respective operations of the flow chart of FIG. 8

[0041] FIG. 8A depicts an example of UE operations for handling security policy for UP protection of communications in a communications system according to some embodiments. At block 810, the processor 4003 transmits through the transceiver 4001 a PDU session establishment request NAS message. The PDU session establishment request NAS message can be transmitted toward an AMF to establish a PDU session. At block 820, the processor 4003 receives through the transceiver 4001 an AN specific resource setup message. The AN specific resource setup message can indicate whether the UE is to activate integrity protection for DRBs serving the PDU session. At block 830, the processor 4003 sums DRB-IP rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate. At block 840, the processor 4003 adjusts an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

[0042] In additional or alternative embodiments, the processor 4003 can generate the session consumed DRB-IP rate without including in the summing any DRB-IP rates that are allocated for DRBs of the PDU session that are not indicated by the AN specific resource setup message for the UE to activate integrity protection.

[0043] In additional or alternative embodiments, when the PDU session will be the only active PDU session between the UE and the AN, the adjustment of the available DRB-IP rate of the UE can include determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and the session consumed DRB-IP rate. The maximum DRB-IP rate of the UE can correspond to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

[0044] In additional or alternative embodiments, when the PDU session is one of a plurality of active PDU sessions between the UE and the AN, the adjustment of the available DRB-IP rate of the UE can include determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and a summation of the session consumed DRB-IP rates that have been generated for each of the active PDU sessions. The maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

[0045] FIG. 8B depicts other inventive UE operations for handling security policy for UP protection of communications in a communications system according to some embodiments. FIG. 8B includes block / operations similar to those discussed above with respect to FIG. 8A, but FIG. 8B further includes blocks 802, 850, 860, 870, 880, and 890. At block 802, before transmitting the PDU session establishment request NAS message toward the AMF and when the UE does not have an active PDU session with the AN which has DRBs for which the UE provides integrity protection, the processor 4003 can add an indication of the maximum DRB-IP rate of the UE to the PDU session establishment request NAS message that is transmitted toward the AMF to establish a PDU session. At block 850, the processor 4003 can add the available DRB-IP rate of the UE to another PDU session establishment request NAS message that is transmitted toward the AMF to establish another PDU session. At block 860, the processor 4003 can receive through the transceiver 4001 another AN specific resource setup message indicating whether the UE is to activate integrity protection for DRBs serving the another PDU session. At block 870, the processor 4003 can sum DRB-IP rates that are allocated for the DRBs of the another PDU session that are indicated by the another AN specific resource setup message for the UE to activate integrity protection, to generate another session consumed DRB-IP rate. At block 880, the processor 4003 can further adjust the available DRB-IP rate of the UE based on a difference between the available DRB-IP rate of the UE and the another session consumed DRB-IP rate. At block 890, the processor 4003 can responsive to releasing the PDU session, the processor 4003 can increase the available DRB-IP rate of the UE based on the session consumed DRB-IP rate of the PDU session.

[0046] In the flow chart of FIGS. 8A-B, operations of blocks 802, 850, 860, 870, 880, and 890 of FIGS. 8A-B may be optional.

[0047] Operations of an AMF will now be discussed with reference to the flow chart of FIG. 9. For example, modules may be stored in AMF memory 6005 of FIG. 6 and these modules may provide instructions so that when the instructions of a module are executed by processor 6003, processor 6003 performs respective operations of the flow chart of FIG. 9.

[0048] FIG. 9 depicts an example of AMF operations according to some embodiments. At block 910, processor 6003 can receive through network interface 6007 a PDU session establishment request NAS message from a UE requesting establishment of a PDU session. The PDU session establishment request NAS message can include an indication of an available DRB-IP rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established. At block 920, the processor 6003 can communicate through network interface 6007 toward a Session SMF a PDU session create message containing the indication of the available DRB-IP rate of the UE. At block 930, the processor 6003 can receive through network interface 6007 a SMF message containing an indication of a UP security policy for a PDU session being established. At block 940, the processor 6003 can communicate through network interface 6007 a message containing the indication of the UP security policy to an AN that is communicating through a wireless air interface with the UE.

[0049] Various operations from the flow chart of FIG. 9 may be optional with respect to some embodiments of base stations and related methods.

[0050] Operations of a SMF will now be discussed with reference to the flow chart of FIG. 10. For example, modules may be stored in SMF memory 7005 of FIG. 7 and these modules may provide instructions so that when the instructions of a module are executed by processor 7003, processor 7003 performs respective operations of the flow chart of FIG. 10.

[0051] FIG. 10 depicts an example of SMF operations according to some embodiments. At block 1010, processor 7003 can receive through network interface 7007 from an AMF a PDU session create message for a UE that is requesting establishment of a PDU session. The PDU session create message can include an indication of an available DRB-IP rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established. At block 1020, processor 7003 can determine a UP security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity. At block 1030, processor 7003 can communicate through network interface 7007 to the AMF a message containing an indication of the UP security policy for the PDU session being established.

[0052] Various operations from the flow chart of FIG. 10 may be optional with respect to some embodiments of base stations and related methods.

[0053] In some embodiments, a user equipment (UE) is provided for handling security policy for user plane protection of communications in a communications system. The UE can include a transceiver configured to transmit and receive through a wireless air interface with an access node (AN) of the communications system. The UE can further include at least one processor connected to the transceiver and configured to perform operations. The operations can include transmitting through the transceiver a packet data unit, PDU, session establishment request network access stratum, NAS, message toward an Access and Mobility Management Function (AMF) to establish a PDU session. The operations can further include receiving through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers, DRBs, serving the PDU session. The operations can further include summing DRB Integrity Protected, DRB-IP, rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate. The operations can further include adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

[0054] In additional or alternative embodiments, the operations can further include generation of the session consumed DRB-IP rate can include not including in the summing any DRB-IP rates that are allocated for DRBs of the PDU session that are not indicated by the AN specific resource setup message for the UE to activate integrity protection.

[0055] In additional or alternative embodiments, the operations can further include when the PDU session will be the only active PDU session between the UE and the AN, the adjustment of the available DRB-IP rate of the UE can include determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and the session consumed DRB-IP rate. The maximum DRB-IP rate of the UE can correspond to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

[0056] In additional or alternative embodiments, the operations can further include before transmitting the PDU session establishment request NAS message toward the AMF and when the UE does not have an active PDU session with the AN which has DRBs for which the UE provides integrity protection, adding an indication of the maximum DRB-IP rate of the UE to the PDU session establishment request NAS message that is transmitted toward the AMF to establish a PDU session.

[0057] In additional or alternative embodiments, the operations can further include when the PDU session is one of a plurality of active PDU sessions between the UE and the AN, the adjustment of the available DRB-IP rate of the UE comprises determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and a summation of the session consumed DRB-IP rates that have been generated for each of the active PDU sessions. The maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

[0058] In additional or alternative embodiments, the operations can further include following the adjustment of the available DRB-IP rate of the UE, adding the available DRB-IP rate of the UE to another PDU session establishment request NAS message that is transmitted toward the AMF to establish another PDU session. The operations can further include receiving through the transceiver another AN specific resource setup message indicating whether the UE is to activate integrity protection for DRBs serving the another PDU session. The operations can further include summing DRB-IP rates that are allocated for the DRBs of the another PDU session that are indicated by the another AN specific resource setup message for the UE to activate integrity protection, to generate another session consumed DRB-IP rate. The operations can further include further adjusting the available DRB-IP rate of the UE based on a difference between the available DRB-IP rate of the UE and the another session consumed DRB-IP rate.

[0059] In additional or alternative embodiments, the operations can further include responsive to releasing the PDU session, increasing the available DRB-IP rate of the UE based on the session consumed DRB-IP rate of the PDU session.

[0060] In some embodiments, a method by a user equipment (UE) is provided for handling security policy for user plane protection of communications in a communications system. The method can include transmitting through the transceiver a packet data unit, PDU, session establishment request network access stratum, NAS, message toward an Access and Mobility Management Function (AMF) to establish a PDU session. The method can further include receiving through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers, DRBs, serving the PDU session. The method can further include summing DRB Integrity Protected, DRB-IP, rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate. The method can further include adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

[0061] In some embodiments, an Access and Mobility Management Function (AMF) of a communications system is provided. The AMF can include a network interface configured to communicate with user equipments (UEs) via a network and an access node, AN, of the communications system, and to communicate with a Session Management Function (SMF) of the communications system. The AMF can further include at least one processor configured to perform operations. The operations can include receiving a packet data unit, PDU, session establishment request network access stratum, NAS, message from a UE requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established. The operations can further include communicating toward the SMF a PDU session create message containing the indication of the available DRB-IP rate. The operations can further include receiving a SMF message containing an indication of a user plane, UP, security policy for a PDU session being established. The operations can further include communicating a message containing the indication of the UP security policy to an access node (AN) that is communicating through a wireless air interface with the UE.

[0062] In some embodiments, a method by an Access and Mobility Management Function (AMF) of a communications system can be provided. The method can include receiving a packet data unit, PDU, session establishment request network access stratum, NAS, message from a user equipment (UE) requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established. The method can further include communicating toward a Session Management Function (SMF) a PDU session create message containing the indication of the available DRB-IP rate of the UE. The method can further include receiving a SMF message containing an indication of a user plane, UP, security policy for a PDU session being established. The method can further include communicating a message containing the indication of the UP security policy to an access node (AN) that is communicating through a wireless air interface with the UE.

[0063] In some embodiments, a Session Management Function (SMF) of a communications system can be provided. The SMF can include a network interface configured to communicate with an Access and Mobility Management Function (AMF) of the communications system. The SMF can further include at least one processor configured to perform operations. The operations can include receiving from the AMF a packet data unit, PDU, session create message for a user equipment (UE) that is requesting establishment of a PDU session, the PDU session create message containing an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established. The operations can further include determining a user plane, UP, security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity. The operations can further include communicating to the AMF a message containing an indication of the UP security policy for the PDU session being established.

[0064] In a further embodiment, the operations to determine the UP security policy for the PDU session, can include determining whether the UE is to actively use integrity protection for at least some of the DRBs the UE will use for communication in the PDU session being established.

[0065] In some embodiments, a method by a Session Management Function (SMF) of a communications system can be provided. The method can include receiving from an Access and Mobility Management Function (AMF) a packet data unit, PDU, session create message for a user equipment (UE) that is requesting establishment of a PDU session, the PDU session create message containing an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established. The method can further include determining a user plane, UP, security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity. The method can further include communicating to the AMF a message containing an indication of the UP security policy for the PDU session being established.

[0066] In a further embodiment, the determination of the UP security policy for the PDU session can include determining whether the UE is to actively use integrity protection for at least some of the DRBs the UE will use for communication in the PDU session being established.Further definitions and embodiments are discussed below.

[0067] In the above-description of various embodiments of present inventive concepts, it is to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of present inventive concepts. Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which present inventive concepts belong. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0068] When an element is referred to as being "connected", "coupled", "responsive", or variants thereof to another element, it can be directly connected, coupled, or responsive to the other element or intervening elements may be present. In contrast, when an element is referred to as being "directly connected", "directly coupled", "directly responsive", or variants thereof to another element, there are no intervening elements present. Like numbers refer to like elements throughout. Furthermore, "coupled", "connected", "responsive", or variants thereof as used herein may include wirelessly coupled, connected, or responsive. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. Well-known functions or constructions may not be described in detail for brevity and / or clarity. The term "and / or" includes any and all combinations of one or more of the associated listed items.

[0069] It will be understood that although the terms first, second, third, etc. may be used herein to describe various elements / operations, these elements / operations should not be limited by these terms. These terms are only used to distinguish one element / operation from another element / operation. Thus, a first element / operation in some embodiments could be termed a second element / operation in other embodiments without departing from the teachings of present inventive concepts. The same reference numerals or the same reference designators denote the same or similar elements throughout the specification.

[0070] As used herein, the terms "comprise", "comprising", "comprises", "include", "including", "includes", "have", "has", "having", or variants thereof are open-ended, and include one or more stated features, integers, elements, steps, components, or functions but does not preclude the presence or addition of one or more other features, integers, elements, steps, components, functions, or groups thereof. Furthermore, as used herein, the common abbreviation "e.g.", which derives from the Latin phrase "exempli gratia," may be used to introduce or specify a general example or examples of a previously mentioned item, and is not intended to be limiting of such item. The common abbreviation "i.e.", which derives from the Latin phrase "id est," may be used to specify a particular item from a more general recitation.

[0071] Example embodiments are described herein with reference to block diagrams and / or flowchart illustrations of computer-implemented methods, apparatus (systems and / or devices) and / or computer program products. It is understood that a block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by computer program instructions that are performed by one or more computer circuits. These computer program instructions may be provided to a processor circuit of a general purpose computer circuit, special purpose computer circuit, and / or other programmable data processing circuit to produce a machine, such that the instructions, which execute via the processor of the computer and / or other programmable data processing apparatus, transform and control transistors, values stored in memory locations, and other hardware components within such circuitry to implement the functions / acts specified in the block diagrams and / or flowchart block or blocks, and thereby create means (functionality) and / or structure for implementing the functions / acts specified in the block diagrams and / or flowchart block(s).

[0072] These computer program instructions may also be stored in a tangible computer-readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable medium produce an article of manufacture including instructions which implement the functions / acts specified in the block diagrams and / or flowchart block or blocks. Accordingly, embodiments of present inventive concepts may be embodied in hardware and / or in software (including firmware, resident software, micro-code, etc.) that runs on a processor such as a digital signal processor, which may collectively be referred to as "circuitry," "a module" or variants thereof.Additional explanation is provided below.

[0073] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or where it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may apply to any other embodiments, and vice versa. Other objectives, features and advantages of the enclosed embodiments will be apparent from the following description.

[0074] Explanations for abbreviations from the above disclosure are provided below. AbbreviationExplanation3GPP3 rd< Generation Partnership Project5G5 th< Generation Wireless SystemsNGNext GenerationIoTInternet of ThingsAKAAuthentication and Key AgreementUICCUniversal Integrated Circuit CardSA23GPP architecture working groupSA33GPP security groupUPUser PlaneLTELong Term Evolution (4 th< Generation Wireless System)CPControl PlaneASAccess StratumeNBEvolved Node BUEUser Equipment or End User DeviceSMCSecurity Mode CommandRRCRadio Resource ControlPDCPPacket Data Convergence ProtocolRANRadio Access NetworkCNCore NetworkPDUPacket Data UnitDRBData Radio BearerANAccess Network(R)ANBoth 3GPP and non-3GPP Access NetworksNASNetwork Access StratumAMFAccess and Mobility Management FunctionNFNetwork FunctionUDMUnified Data ManagementPCFPolicy Control FunctionDRB-IPData Radio Bearer Integrity ProtectedIEInformation ElementQoSQuality of Service

[0075] Citations for references from the above disclosure are provided below. Reference [1]: 3GPP TS 23.501 V15.1.0 (2018-03), Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15) Reference [2]: 3GPP TS 33.501 Reference [3]: 3GPP TS 33.401

Claims

1. A user equipment, UE, for handling security policy for user plane protection of communications in a communications system, the UE comprising: a transceiver configured to transmit and receive through a wireless air interface with an access node, AN, of the communications system; and at least one processor connected to the transceiver and configured to perform operations comprising: transmitting (810) through the transceiver a packet data unit, PDU, session establishment request network access stratum, NAS, message toward an Access and Mobility Management Function, AMF, to establish a PDU session; and receiving (820) through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers, DRBs, serving the PDU session; the UE characterised by the processor being configured to perform: summing (830) DRB Integrity Protected, DRB-IP, rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and adjusting (840) an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

2. The UE of Claim 1, wherein: generation of the session consumed DRB-IP rate comprises not including in the summing any DRB-IP rates that are allocated for DRBs of the PDU session that are not indicated by the AN specific resource setup message for the UE to activate integrity protection.

3. The UE of any of Claims 1 to 2, wherein: when the PDU session will be the only active PDU session between the UE and the AN, the adjustment of the available DRB-IP rate of the UE comprises determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and the session consumed DRB-IP rate, wherein the maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

4. The UE of any of Claims 1-3, further comprising: before transmitting the PDU session establishment request NAS message toward the AMF and when the UE does not have an active PDU session with the AN which has DRBs for which the UE provides integrity protection, adding (802) an indication of the maximum DRB-IP rate of the UE to the PDU session establishment request NAS message that is transmitted toward the AMF to establish a PDU session.

5. The UE of any of Claims 1 to 4, wherein: when the PDU session is one of a plurality of active PDU sessions between the UE and the AN, the adjustment of the available DRB-IP rate of the UE comprises determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and a summation of the session consumed DRB-IP rates that have been generated for each of the active PDU sessions, wherein the maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

6. The UE of any of Claims 1 to 5, further comprising: following the adjustment of the available DRB-IP rate of the UE, adding (850) the available DRB-IP rate of the UE to another PDU session establishment request NAS message that is transmitted toward the AMF to establish another PDU session; receiving (860) through the transceiver another AN specific resource setup message indicating whether the UE is to activate integrity protection for DRBs serving the another PDU session; summing (870) DRB-IP rates that are allocated for the DRBs of the another PDU session that are indicated by the another AN specific resource setup message for the UE to activate integrity protection, to generate another session consumed DRB-IP rate; and further adjusting (880) the available DRB-IP rate of the UE based on a difference between the available DRB-IP rate of the UE and the another session consumed DRB-IP rate.

7. The UE of any of Claims 1 to 6, further comprising: responsive to releasing the PDU session, increasing (890) the available DRB-IP rate of the UE based on the session consumed DRB-IP rate of the PDU session.

8. A method by a user equipment, UE, for handling security policy for user plane protection of communications in a communications system, the method comprising: transmitting (810) a packet data unit, PDU, session establishment request network access stratum, NAS, message toward an Access and Mobility Management Function, AMF, to establish a PDU session; and receiving (820) an access node, AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers, DRBs, serving the PDU session; the method characterised by: summing (830) DRB Integrity Protected, DRB-IP, rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and adjusting (840) an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

9. The method of Claim 8, further comprising performing the operations of any of Claims 2 to 7.

10. A system comprising the User Equipment, UE, of any of Claims 1-7, and further comprising an Access and Mobility Management Function, AMF, of a communications system, the AMF comprising: a network interface configured to communicate with user equipments, UEs, via a network and an access node, AN, of the communications system, and to communicate with a Session Management Function, SMF, of the communications system; and at least one processor configured to perform operations comprising: receiving (910) a packet data unit, PDU, session establishment request network access stratum, NAS, message from a UE requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established; communicating (920) toward the SMF a PDU session create message containing the indication of the available DRB-IP rate; receiving (930) a SMF message containing an indication of a user plane, UP, security policy for a PDU session being established; and communicating (940) a message containing the indication of the UP security policy to an access node, AN, that is communicating through a wireless air interface with the UE.

11. A method to be performed by a communications system, the method comprising, by a User Equipment, UE, the method of Claims 8 or 9 and further comprising, by an Access and Mobility Management Function, AMF, : receiving (910) a packet data unit, PDU, session establishment request network access stratum, NAS, message from a user equipment, UE, requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established; communicating (920) toward a Session Management Function, SMF, a PDU session create message containing the indication of the available DRB-IP rate of the UE; receiving (930) a SMF message containing an indication of a user plane, UP, security policy for a PDU session being established; and communicating (940) a message containing the indication of the UP security policy to an access node, AN, that is communicating through a wireless air interface with the UE.

12. A system comprising the User Equipment, UE, of any of Claims 1-7, and further comprising a Session Management Function, SMF, of a communications system, the SMF comprising: a network interface configured to communicate with an Access and Mobility Management Function, AMF, of the communications system; and at least one processor configured to perform operations comprising: receiving (1010) from the AMF a packet data unit, PDU, session create message for a user equipment (UE) that is requesting establishment of a PDU session, the PDU session create message containing an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established; determining (1020) a user plane, UP, security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity; and communicating (1030) to the AMF a message containing an indication of the UP security policy for the PDU session being established.

13. A method to be performed by a communications system, the method comprising, by a User Equipment, UE, the method of Claims 8 or 9 and further comprising, by a Session Management Function, SMF: receiving (1010) from an Access and Mobility Management Function, AMF, a packet data unit, PDU, session create message for a user equipment, UE, that is requesting establishment of a PDU session, the PDU session create message containing an indication of an available data radio bearer integrity protected, DRB-IP, rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established; determining (1020) a user plane, UP, security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity; and communicating (1030) to the AMF a message containing an indication of the UP security policy for the PDU session being established.

14. The method of Claim 13, wherein the determination of the UP security policy for the PDU session comprises determining whether the UE is to actively use integrity protection for at least some of the DRBs the UE will use for communication in the PDU session being established.