Systems and methods related to split ran architecture and security mode for future x-centric service network

EP4612875A4Pending Publication Date: 2025-11-26HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
EP2022966703
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-11-26

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

Systems and methods related to split RAN architecture and security mode for future X-centric service network are provided. Also provided is a communication network in which the split RAN architecture is deployed. The communication network includes a radio access network (RAN) that has a central unit (CU) and one or more distributed units (DUs). The communication network also includes one or more service modules deployed between the CU and the one or more DUs. The one or more service modules are configured to provide one or more network services for data processing. Systems and methods related to split RAN architecture and security mode for future X-centric service network are provided.
Need to check novelty before this filing date? Find Prior Art

Description

Systems and Methods related to Split RAN architecture and security mode for future X-centric service networkTECHNICAL FIELDThe present disclosure pertains to the field of communication networks, and in particular to systems and methods related to split radio access network (RAN) architecture and security mode for future X-centric service network.BACKGROUNDExisting network architectures, e.g., the radio access network (RAN) architecture, may limit how such new services may be provided. For example, existing network architectures may limit the amount of data that may be needed for processing. Further, current L2 sublayers and PHY layer in existing architectures may lack the functionalities to support the new kinds of services.In addition, deployment of such new services on existing network architectures may further burden and overload the network, thereby weakening the network architecture. For example, some new services may require aggregating data for processing, which may increase the load on the involved interfaces, affecting the traditional connectivity-oriented services.A further limitation of existing networks may be the required security protection needed for services in future networks. Current networks may be unable to provide the required security protection needed for such services.Therefore, there is a need for systems and methods related to Split RAN architecture and security mode for future X-centric service network that obviates or mitigates one or more limitations of the prior art.This background information is provided to reveal information believed by the applicant to be of possible relevance to the present invention. No admission is necessarily intended, nor should be construed, that any of the preceding information constitutes prior art against the present invention.SUMMARYAspects of the disclosure may provide for systems and methods related to Split RAN architecture and security mode for future X-centric service network.An aspect of the disclosure provides for a communication network. A communication network includes a radio access network (RAN) having a central unit (CU) and one or more distributed units (DUs) . The communication network may further include one or more service modules deployed between the CU and the one or more DUs, the one or more of service modules being configured to provide one or more network services for data processing.The data processing may include at least one of data analytics, artificial intelligence (AI) training, AI inference, data privacy protection, data collection, data sanitization, data processing, data management, data cleaning, data normalization, useless data filtering, data feature engineering, data compression, data embedding, data representation learning, and data feature extraction.The one or more of service modules may be deployed in one or more of: the RAN, a core network (CN) and a user equipment (UE) .Each service module of the one or more service modules may include one or more service controller units to control the one or more network services. Each service module of the one or more service modules may further include one or more processing function (PF) units to execute one or more tasks associated with the one or more network services. The one or more service controller units may be deployed on a control plane.The one or more PF units may be deployed on a user plane, a data plane, a computing plane or a data processing plane. The one or more PF units may be configured to perform the data processing under control of the one or more service controller units. The one or more service controller units may be configured to control and configure the one or more PF units for the data processing.The one or more DUs may be connected to the one or more service modules via a T1 interface. The CU may be connected to each of the one or more service modules via a T2 interface. The one of the one more service controller units may be connected to the one or more DUs via a T1 interface on the control plane (T1-C interface) .The one or more PF units may be connected to the one or more DUs via a T1 interface on the user plane, the data plane, the computing plane or the data processing plane (T1-U interface) . The one or more service controller units may be connected to the CU via a T2 interface on the control plane (T2-C interface) .The one or multiple PF units may be connected to the CU via a T2 interface on the user plane, the data plane, the computing plane or the data processing plane (T2-U interface) . One of the one or more PF units may be connected to one of the one or more service controller units via a T3 interface. One of the one or more service controller units may be connected to the one or more PF units via a T3 interface.Different PF units in a same service module or in a different service module of the one or more service modules may be interconnected via a T4 interface. Different service controller units in a same service module or in a different service module of the one or more service modules may be interconnected through a T5 interface. One of the one or more PF units may be connected, directly or indirectly, to a CN function (CNF) via a T6 interface.One of the one or more PF units may be connected to the CNF via the T6 interface indirectly, through an intermediate CU. One of the one or more service controller units may be connected, directly or indirectly, to a CN function (CNF) via a T7 interface. One of the one or more service controller units may be connected to the CNF via the T7 interface indirectly, through an intermediate CU.The CNF may be one of: a service module in the CN, a PF unit in the CN, a service controller unit in the CN, and a function for data forwarding. The function for data forwarding is one of: a user plane function (UPF) , an evolved UPF, or a gateway function.Different service modules of the one or more service modules may be interconnected via a T8 interface. The T8 interface may be an integration of a T4 interface with a T5 interface. The one or more DUs may be connected to the CU via an F1 interface.An application layer signaling protocol on the control plane of the communication network has interfaces T1, T2, T3, T5, T7 and T8, which are respectively referred to as a T1 Application Protocol (T1AP) , a T2 Application Protocol (T2AP) , a T3 Application Protocol (T3AP) , a T5 Application Protocol (T5AP) , a T7 Application Protocol (T7AP) , and a T8 Application Protocol (T8AP) .Underlay protocol stacks of one or more of the T1AP, the T2AP, the T3AP, the T5AP, the T7AP and the T8AP may include one or more of: a General Packet Radio Service  (GPRS) Tunneling Protocol for a user plane (GTP-U) , a User Datagram Protocol (UDP) , an Internet Protocol (IP) , a Quick UDP Internet Connections (QUIC) protocol, a Hypertext Transfer Protocol (HTTP) , a Stream Control Transmission Protocol (SCTP) , and a Segment Routing over IPv6 (SRv6) protocol.Underlay protocol stacks on the data plane for one or more of a T1 interface, a T2 interface, a T4 interface, a T6 interface and a T8 interface may include one or more of: a General Packet Radio Service (GPRS) Tunneling Protocol for a user plane (GTP-U) , a User Datagram Protocol (UDP) , an Internet Protocol (IP) , a Quick UDP Internet Connections (QUIC) protocol, a Hypertext Transfer Protocol (HTTP) , a Stream Control Transmission Protocol (SCTP) , and a Segment Routing over IPv6 (SRv6) protocol.The communication network may further include, on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks: a PF sublayer, at the one or more PF units, deployed on top of a packet data convergence protocol (PDCP) sublayer.The communication network may further include, on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks a corresponding PF sublayer, at the UE, deployed: on top of a respective PDCP sublayer; or between a SDAP sublayer and the respective PDCP sublayer.The communication network may further include, on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks, at the UE, a radio link control (RLC) sublayer, a medium access control (MAC) sublayer deployed at the UE, and a physical (PHY) layer deployed.The communication network may further include, on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks, at the one or more DUs, an RLC sublayer, a MAC sublayer, and a PHY layer.The communication network may further include, on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks, at the CU, a respective SDAP sublayer deployed.The communication network may further include, on the control plane, over the underlay protocol stacks a service controller sublayer, at the one or more service controller units, deployed on top of a packet data convergence protocol (PDCP) sublayer.The communication network may further include, on the control plane, over the underlay protocol stacks, at the UE, a corresponding service controller sublayer, deployed on top of a PDCP sublayer, a radio link control (RLC) sublayer, a medium access control (MAC) sublayer, a physical (PHY) layer.The communication network may further include, on the control plane, over the underlay protocol stacks, at the one or more DUs, an RLC sublayer, a MAC sublayer and a PHY layer.The one or more PF units may be integrated into the CU. The communication network may further include on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks a PF sublayer, at the CU, deployed: on top of a packet data convergence protocol (PDCP) sublayer, or between the PDCP sublayer and a service data adaptation protocol (SDAP) sublayer.The communication network may further include on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks, at the one or more DUs an RLC sublayer, a MAC sublayer and a PHY layer.The communication network may further include on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks, at the UE, a PF sublayer: on top of the PDCP sublayer, or between the PDCP sublayer and an SDAP sublayer. The communication network may further include on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks, at the UE, an RLC sublayer, a MAC sublayer and a PHY layer.The one or more control units may be integrated into the CU, the communication network may further include, on the control plane over the underlay protocol stacks, at the CU, a service controller sublayer deployed: on top of a packet data convergence protocol (PDCP) sublayer; or between the PDCP sublayer and a radio resource controller (RRC) sublayer, or on top of the RRC layer.The communication network may further include, on the control plane over the underlay protocol stacks, at the one or more DUs: a PHY layer deployed, an RLC sublayer and a MAC sublayer.The communication network may further include, on the control plane over the underlay protocol stacks, at the UE, a service controller sublayer deployed: on top of the PDCP sublayer; or between a PDCP sublayer and a RRC sublayer, or on top of the RRC  sublayer. The communication network may further include, on the control plane over the underlay protocol stacks, at the UE, an RLC sublayer, a MAC sublayer and a PHY layer.The one or more PF units may be deployed between the one or more DUs and the CU. A first PF unit of the one or more PF units may include a PF sublayer: deployed on top of a packet data convergence protocol (PDCP) sublayer and corresponding to a PF sublayer of the UE. The first PF unit may further include the PDCP sublayer corresponding to a PDCP sublayer of the UE.The communication network may further include a second PF unit of the one or more PF units deployed between the one or more DUs and the CU, wherein the first PF unit may further include a second PF sublayer corresponding to a PF sublayer of the second PF unit, the second PF sublayer being deployed on top of a second PDCP sublayer of the first PF unit.The CU may be configured to perform at least one of: one or more functions of a packet data convergence protocol (PDCP) sublayer for header (de) compression, and a sequence numbering of a PDCP service data unit (SDU) .The one or more PF units may be configured to perform one or more functions of a PDCP sublayer for security protection, wherein the one or more functions relate to one or more of: integrity protection and ciphering.A network service of the one or more network services may be identified by a network service identifier (ID) . The network service ID may include one or more of: a service type ID, a task ID, a mission ID, and a network ID. The service type ID may identify a service type of the network service. The task ID may identify a data processing task for which the network service is configured to execute. The mission ID may identify a mission for which the network service is configured to execute, the mission comprising one or more of tasks. The network ID may identify a network providing the network service.The communication network may further include plurality of network nodes. Two network nodes of the plurality of network nodes may be configured to exchange their capability on the one or more network services. Each of the two network nodes may be one of: a service module of the one or more service modules, a PF unit of the one or more PF units, a service controller unit of the one or more service controller units, a DU of the one or more DU, and the CU.The two network nodes may be configured to exchange their capability by having a first node of the two network nodes sending a first message to a second node of the two network nodes. The message may include one or more of: a node identifier (ID) identifying the first node, a cell ID identifying a cell providing a network service of the one or more network services, a tracking area ID identifying a tracking area providing a network service of the one or more network services, a network service ID identifying the network service, and a network ID identifying the network providing the network service, wherein the network ID is one of: a public land mobile network (PLMN) ID, or a non-public network (NPN) ID.The two network nodes may be configured to exchange their capability by further having the second node sending a second message to the first node. The second message may include one or more of: a node ID identifying the second node, a second cell ID, a second tracking area ID, a second network service ID, and a second network ID.One or more of the node ID identifying the second node, the second cell ID, the second network service ID, and the second network ID included in the second message may be the same as the one or more of the node ID, the cell ID, the network service ID, and the network ID included in the first message.The second node may be configured to send a failure message to the first node when the second node determines that capability of the second node to provide the network service does not overlap with that of the first node.A network node of the plurality of network nodes sends to the UE a message identifying the one or more network services. The message may include one or more of: a cell identifier (ID) , a network service ID, and a network ID. The network ID may be one of a public land mobile network (PLMN) ID, or a non-public network (NPN) ID. The message may be one of a unicast message or a multicast / broadcast message. Where the message is a unicast message, the message may be one of a dedicated radio resource control (RRC) message, and a dedicated signaling message. Where the message is a multicast / broadcast message, the message may be a system information (SI) message.After receiving the message, the UE may select a network service from the one or more network service to access and sends a second message to the network node. The second message may include one or more of: a network service ID associated with the selected network service, a network ID associated with the selected network service, a cell ID  associated with the selected network service. The second message may be a dedicated radio resource control (RRC) message, or a dedicated signaling message for the network service.The PF sublayer may be configured to perform privacy protection on data processing at one or more of: the one or more PF units, the UE, and the CU. The PDCP sublayer may be configured to perform security protection on data forwarding at the one or more of: the one or more PF units, the one or more service controller units, the CU, and the UE.The communication network may support one or more access stratum (AS) security modes, each AS security mode indicates that none, one or more than one of security protection and privacy protection are to be executed for the one or more network services on one or both of a user plane (UP) and a control plane (CP) .The one or more AS security modes may indicate that a packet data convergence protocol (PDCP) sublayer (e.g., for ciphering and integrity) is to execute the security protection for the one or more network services on the UP. The one or more AS security modes may indicate that a PF sublayer (e.g., for privacy protection) is to execute the privacy protection for the one or more network services on the UP. The one or more AS security modes may indicate that the PDCP sublayer is to execute the security protection and the PF sublayer is to execute the privacy protection for the one or more network services on the UP. The one or more AS security modes may indicate that none of the PDCP sublayer and the PF sublayer are to execute the security protection or the privacy protection for the network services on the UP.The one or more AS security modes indicate that a packet data convergence protocol (PDCP) sublayer is to execute the security protection for the one or more network services on the CP. The one or more AS security modes indicate that a service controller sublayer is to execute the privacy protection for the one or more network services on the CP. The one or more AS security modes indicate that the PDCP sublayer is to execute the security protection for the one or more network services on the CP and the service controller sublayer is to execute the privacy protection for the network service on the CP. The one or more AS security modes indicate that none of the PDCP sublayer and the service controller sublayer are to execute the security protection or the privacy protection for the one or more network services on the CP.The one or more AS security modes may indicate one or more security algorithms according to which one or both of the security protection and privacy protection are to be executed. The one or more security algorithms include one or more of: a ciphering algorithm and an integrity algorithm on a packet data convergence protocol (PDCP) sublayer, privacy protection algorithm on a PF sublayer, and privacy protection algorithm on a controller sublayer.The one or more supported AS security modes may be configured at one or more of: the one or more the service modules, the one or more PF units, the UE, the CU, the one or more service controller units, and an aggregated RAN node. The aggregated RAN node may include two or more of: the one or more the service modules, the one or more PF units, the CU, the one or more service controller units, and the one or more DUs.The communication network may further provide for a first network node notifying, via an AS security mode notification procedure, a second network node of one or more AS security modes supported at the first network node.The AS security mode notification procedure may include the first network node sending a message to the second network node. The message may include one or more AS security mode IDs, each AS security mode ID identifying a supported AS security mode of the first node. The message may further include a priority for each of the supported AS security modes. The message may further include a corresponding quality of service (QoS) guaranteed by each of the supported AS security mode for the one or more network services.The first network node may be the UE. The second network node may be one of: a service module of the one or more service modules, the CU, a service controller unit of the one or more service controller units, the integrated RAN node, and a CN function (CNF) . The first network node sending a message to the second network node may include the UE sending a report indicating its one or more supported AS security modes to the second network node.The AS security mode notification procedure may further include, after receiving the report from the UE, the second network node selecting an AS security mode for the UE, and sending an AS security configuration to the UE. The AS security configuration may include one or more of: the selected AS security mode and AS security parameters. The AS security configuration may be sent to the UE via one or more of: a dedicated radio resource control (RRC) message, a dedicated signaling message for the one or more network services,  and a non-access stratum (NAS) message. The dedicated RRC message may be an AS security mode command message.The AS security mode notification procedure may further include, based on the AS security configuration, on the UP, the UE performing one or more of: an uplink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection on data forwarding, a downlink deciphering on the PDCP sublayer for security protection on data forwarding, an uplink ciphering on a PF sublayer for privacy protection on data processing, and a downlink deciphering on the PF sublayer for privacy protection on data processing.The AS security mode notification procedure may further include, based on the AS security configuration, on the CP, the UE performing one or more of: an uplink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection, a downlink deciphering on the PDCP sublayer for security protection, an uplink ciphering on a service controller sublayer for privacy protection, and a downlink deciphering on the service controller sublayer for privacy protection.The AS security mode notification procedure may further include, based on the AS security configuration, on the UP, the second network node performing one or more of: a downlink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection on data forwarding, an uplink deciphering on the PDCP sublayer for security protection on data forwarding, a downlink ciphering on a PF sublayer for privacy protection on data processing, and an uplink deciphering on the PF sublayer for privacy protection on data processing.The AS security mode notification procedure may further include, based on the AS security configuration, on the CP, the second network node performing one or more of: a downlink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection, an uplink deciphering on the PDCP sublayer for security protection, a downlink ciphering on a service controller sublayer for privacy protection, and an uplink deciphering on the service controller sublayer for privacy protection.The AS security mode notification procedure may further include, based on the selected AS security mode, RAN performing a downlink ciphering on one or more of a packet data convergence protocol (PDCP) sublayer for data forwarding associated with a service data bearer (XDB) on a service UP, and a PF sublayer associated with the XDB on the service UP. The AS security mode notification procedure may further include, based on  the selected AS security mode, RAN performing an uplink deciphering on one or more of: the PDCP sublayer for data forwarding associated with the XDB on the service UP, and the PF sublayer associated with the XDB on the service UP.The AS security mode notification procedure may further include, based on the selected AS security mode, RAN performing a downlink ciphering on one or more of: a PDCP sublayer associated with a service signaling bearer (XSB) on a service CP, and a service controller sublayer associated with the XSB on the CP; and an uplink deciphering on one or more of: the PDCP sublayer associated with the XSB on the service CP; and the service controller sublayer associated with the XSB on the service CP.The first network node may be the one or more PF units and the second network node may be a service controller unit of the one or more service controllers. Each of the one or more PF units may send a message to the service controller unit.The second network node may be a service controller unit of the one or more service controller units. The service controller unit may select a PF unit of the one or more PF units to serve the UE. The selected PF unit may support one or more AS security modes overlapped with the one or more AS security modes supported by the UE. The service controller unit may select an AS security mode supported by one or more of the UE, the selected PF unit and the service controller. The service controller unit may send the PF unit an AS security configuration corresponding to the AS security configuration of the UE.Based on the AS security configuration received from the service controller unit, the selected PF unit performs one or more of: on user plane (UP) , a downlink ciphering on one or more of: a packet data convergence protocol (PDCP) sublayer and PF sublayer. Based on the AS security configuration received from the service controller unit, the selected PF unit performs one or more of: on the UP, an uplink deciphering on one or more of: the PDCP sublayer and the PF sublayer. Based on the AS security configuration received from the service controller unit, the selected PF unit performs one or more of: on control plane (CP) , a downlink ciphering on one or more of: the PDCP sublayer and a service controller sublayer. Based on the AS security configuration received from the service controller unit, the selected PF unit performs one or more of: on control plane (CP) , an uplink deciphering on one or more of: the PDCP sublayer and the service controller sublayer.The communication network where a data bearer for the one or more network services may be established between the UE and a service module of the one or more service  modules on the RAN. The data bearer for the one or more network services may be established between a PF protocol layer on a UE side and a PF protocol layer on a PF unit side of a service module of the one or more service module. The PF protocol layer on UE side and the PF protocol layer on the PF unit side may belong to the data bearer.The communication network may provide for establishment of a signaling bearer for the one or more network services between the UE and a service module of the one or more service modules on the RAN. The signaling bearer for the one or more network services may be established between a service controller protocol layer on a UE side and a service controller protocol layer on a service controller unit side of the service module. The service controller protocol layer on the UE side and the service controller protocol layer on the service controller unit side may belong to the signaling bearer.One or more of security protection on data forwarding and privacy protection on data processing may be executed for one or more of the data bearer of the one or more network services and the signaling bearer of the one or more network services.After receiving the second message, the network node may setup for the selected network service one or more of: a data bearer and a signaling bearer. The network node may then send a bearer configuration information to the UE. The bearer configuration information may include AS security configuration. The AS security configuration may include one or more of: a selected AS security mode and AS security parameters.A service module of the one or more service modules may connect to a CN function (CNF) directly or via the CU.The communication network may provide for establishing one or more sessions on a user plane to provide the one or more network services to the UE, the one or more sessions involving one or more of: one or multiple service modules on RAN side, one or multiple service modules on CN side, the one or multiple DUs, one or multiple CUs, one or multiple PF units on RAN side, one or multiple PF units on CN side, and the UEThe one or more sessions may include one or more of quality of service (QoS) flows of the one or more network services, the one or more QoS flows being a finest granularity of QoS differentiation in the session. Traffic in a same QoS flow of the one or more QoS flows may receive a same data forwarding treatment and data processing treatment.The one or more QoS flows may be mapped, by a service data adaptation protocol sublayer, to one or more data bearer for the one or more network services. The UE sends a  request message to the communication network for establishment of the one or more sessions. The request message includes one or more of: a session identifier (ID) , a QoS flow ID, a QoS requirement, a network service ID, a network ID, a UE ID, and a UE group ID.According to a another aspect, a method may be provided for aligning anything-as-a-service (XaaS) capability between two network nodes. The method may include sending, by a first network node (NN) to a second NN, an interface request message to setup or update an interface between the first NN and the second NN. The interface setup message may include one or more of: a first node identifier (ID) , a cell ID, a service ID, and a network ID. The method may further include receiving, by the first NN from the second NN, an interface response message indicating that the interface between the first NN and the second NN is setup or updated. The interface response message may include a second node ID and information that overlaps with the interface request message, the information including one or more of: a cell ID, a service ID, and a network ID.The first NN may be one of a processing function (PF) node of a RAN and an XaaS controller (XC) node. The second node may be the XC node if the first NN is the PF node. Alternatively, the second node may be the PF node if the first NN is the XC node. In such cases, the interface between the first NN and the second NN may be a T3 interface.The first NN may be an XC node. The one or more service IDs included in the interface request message may indicate one or more services supported by the XC node via the one or more network IDs included in the interface request message. The one or more services supported by the XC node may also be supported by at least one processing function (PF) associated with the XC node. The second NN may be a central unit (CU) node of a RAN. In such cases, the interface between the first NN and the second NN may be a T2 interface.The first NN may be a distributed unit node of a RAN. The second NN may be a CU node of a RAN. In such cases, the interface between the first NN and the second NN may be an F1 interface.The first NN may be a distributed unit node a RAN, and the second NN may be an XC node. In such cases the interface between the first NN and the second NN is an T1 interface.The method may further include sending, by the first NN to a user equipment (UE) , a supported service message including one or more of: a service ID, a network ID and a cell ID.The supported service message may be sent via a unicast method, the supported service message being a dedicated radio resource control message or a dedicated signaling message. The supported service message may be sent via a multi-cast / broadcast method, the supported service message being a system information block.According to another aspect, a method related to establishment of an XaaS bearer is provided. The method may include receiving, by an XC node of a RAN from a UE, a request message for a service. The method further includes sending, by the XC node to a PF associated with the XC node, a UE context setup request message to setup resources for the service. The method further includes receiving, by the XC node from the PF, a UE context setup response indicating establishment of a bearer associated with the service. The method further includes sending, by the XC node to the UE, a service response to configure the UE for the service.The request message may include one or more of: a session ID identifying a session via which the UE can receive the service, a quality of service (QoS) flow ID identifying a QoS flow included in the session, a QoS requirement, a service ID identifying the service, a network ID identifying the network through which the UE can receive the service, a cell ID identifying a cell through which the UE can receive the service, and an ID associated with the UE.The service response may include one or more of: a session ID identifying a session via which the UE can receive the service, a QoS flow ID identifying a QoS flow included in the session, a bearer ID, a data radio bearer (DRB) ID identifying a DRB, a new radio bearer (NRB) ID identifying a radio bearer for point-to-multipoint data transmission. The service response may further include mapping information associated with the session, the QoS flow, the bearer, the DRB. The service response may further include configuration of L1 and L2 layers.The request message may be one of a radio resource control message and dedicated signaling message. The QoS requirement may indicate one or more of: data forwarding parameters and data processing parameters.The UE context setup request message may include one or more of a bearer identifier (ID) identifying a bearer associated with the service, a mapped QoS flow ID identifying a QoS flow, a mapped session ID identifying a session, an ID associated with the UE, a QoS requirement on the bearer or the QoS flow, a node address for forwarding service data to a CU node.The method may further include selecting, by the XC node, the PF from one or more PFs connected to the XC node based on the request message for service.The method may further include sending, by the XC node to a CU node, a second request message for the service, the second request message including one or more information included in the request message. The method may further include receiving, by the XC node from the CU, a bearer context setup request message to setup the resources for the service. The bearer context setup request message may include one or more information in the context setup request message. The method may further include sending, by the XC node to the CU, a UE bearer contest setup response message indicating establishment of the bearer associated with the service.The method may further include receiving, by the XC node from central unit node, a second bearer context update request message to update the bearer. The method may further include sending, by the XC node to the PF, a second context setup request message to update the bearer based on the bearer context update request message.The second bearer context update message may include one or more of: a data radio bearer ID, an NRB ID, a mapped bearer ID, a node address for forwarding service data to a distributed unit (DU) node.According to another aspect, a method for establishment an XaaS bearer is provided. The method may include receiving, by CU node of a RAN from an XC node of the RAN, a request message associated with UE, the request message requesting for a service. The method further includes sending, by the CU node to a core network function (CNF) , a second request message for the service, the second request message including one or more information included in the request message. The method further includes receiving, by the CU node from the CNF, a setup request message to setup resources for the service, the setup request message including one or more information included in the request message and the second request message.The request message includes one or more of: a session ID identifying a session via which the UE can receive the service, a QoS flow ID identifying a QoS flow included in the session, a QoS requirement, a service ID identifying the service, a network ID identifying the network through which the UE can receive the service, a cell ID identifying a cell through which the UE can receive the service, and an ID associated with the UE.The method may further include sending, by the CU node to the XC node, a bearer context setup request message to setup resources for the service based on the setup request message. The method may further include receiving, by the CU node from the XC node, a UE bearer context setup response message indicating establishment of a bearer associated with the service.The bearer context setup request message includes one or more of: a bearer ID identifying a bearer associated with the service, a mapped QoS flow ID identifying a QoS flow, a mapped session ID identifying a session associated with the service, an ID associated with a UE requesting the service, a QoS requirement on the bearer or the QoS flow, a node address for forwarding service data to the CU node.The method may further include sending, by the CU node to a distributed unit (DU) node, a second UE context setup request message to setup resources for the service. The second context setup request message may include one or more of: a DRB ID, an NRB ID, a mapped bearer ID, a node address for forwarding service data to a DU node. The method may further include receiving, by the CU node from the DU node, a second UE bearer context setup response message indicating establishment of a DRB. The second UE bearer context setup response message may include one or more of: the DRB ID, the NRB ID, the mapped bearer ID, configuration information of radio link control (RLC) sublayer, configuration information of MAC sublayer, configuration information of PHY layer.The method may further include sending, by the CU node to the XC node, a second bearer context update request message to setup resource for the service update the bearer. The method may further include receiving, by the CU node from the XC node, a second context setup request message to update the XaaS bearer based on the bearer context update request message. The method may further include sending, by the CU to the UE, a service response message to configure the UE for the service.The second bearer context update message may include one or more of: the DRB ID, the NRB ID, the mapped bearer ID, the node address for forwarding service data to a DU node.According to another aspect, a method for security configuration based on preconfigured access stratum (AS) security modes. The method may include receiving, by an XC node of a RAN from at least one PF associated with the XC node, a security mode message including one or more AS security mode IDs identifying one or more AS security modes supported by the at least one PF. The method may further include receiving, by the XC node from a CU node, a bearer setup request message including one or more of: AS security modes IDs identifying one or more AS security modes supported by a UE. The method may further include selecting, by the XC node, a PF based on the one or more AS security modes supported by the UE and the one or more AS security modes supported by the at least one PF.Each AS security mode of the one or more AS security modes supported by the at least one PF may indicate that security protection should be performed on none, one or more of a packet data convergence protocol (PDCP) sublayer and a PF sublayer. The security mode message may further include one or more AS priority indicators corresponding to the one or more AS security modes, the one or more AS priority indicators indicating a priority of the one or more AS security modes.The method may further include sending, by the XC node to the CN node, a second security mode message including the one or more AS security mode IDs identifying the one or more AS security modes supported by the at least one PF.The bearer setup request message may include one or more of: a selected security mode supported by a core network and a UE, CU-assisted information on AS security mode, and CN-assisted security information. The CN-assisted security information may include one or more of: CN-assisted information on AS security mode, and CN-assisted security parameters for deriving AS security parameters.The method may further include selecting, by the XC node, an AS security mode based on one or more of: the CU-assisted information and CN-assisted information on AS security mode. The method may further include generating, by the XC node, AS security parameters according to on the selected AS security mode and based on the CN-assisted security parameters. The method may further include sending, by the XC node to the at least  one PF, an AS security configuration message including one or more of: an ID of the selected AS security mode and the generated AS security parameters.The CN-assisted security parameters may include one or more of: a first security key, Kx, for generating AS security parameter of a PF sublayer, and a second security key, Kc, for generating AS security parameter of a PDCP sublayer.Generating AS security parameters may include generating, by the XC node, one or more AS security keys based on the first security key, Kx. The one or more AS security keys includes a first AS security key, Kpf-u, for a PF sublayer security between the selected PF and the UE. The one or more AS security keys includes a second AS security key, Kpf-pf, for PF sublayer security between different PF units. The one or more AS security keys includes a third AS security key, Kxc-u, for XC sublayer security between the XC node and the UE. Generating AS security parameters may include generating, by the XC node, based on the second security key, Kc, a fourth AS security key, Kpd-u, for a PDCP sublayer security between the PF and UE.The method may further include sending, by the XC node to the UE, a second AS security configuration message including one or more of: the ID of the selected AS security mode and the generated AS security parameters. The method may further include sending, by the XC node to the CU node, a third AS security configuration message including one or more of: the ID of the selected AS security mode and the generated AS security parameters. Each of the UE and the XC node may be preconfigured with a set of AS supported security modes.According to another aspect, another method is provided. The method may relate to configuring security protection based on preconfigured security modes. The method may include receiving, by a CU node of a RAN from a core network function (CNF) , a setup request message including. The setup request message may include a set of AS security mode IDs identifying one or more AS security modes supported by a UE. The method may further include sending, by the CU node to an XC node of the RAN, a bearer setup request message including the set of AS security mode IDs. The method may further include receiving, by the CU node from the XC node, an AS security configuration message including one or more of: an ID of an AS security mode selected by the XC node and AS security parameters generated by XC node.The method may further include sending, by the CU node to the UE, a second AS security configuration message including one or more of: the ID of the AS security mode selected by the XC node and the AS security parameters generated by the XC node.The method may further include receiving, by the CU node from the XC node, a security mode message indicating one or more AS security modes supported by at least one PF associated with the XC node. The method may further include selecting, by the CU node, an AS security mode for data forwarding on a PDCP sublayer based on one or more of: the one or more AS security modes supported by the UE, the one or more AS security modes supported by the at least one PF, and CN-assisted security information included in the setup request message. The method may further include generating, by the CU node, AS security parameters based on the selected AS security mode. The method may further include generating, by the CU node, CU-assisted information on AS security mode.The setup request message may further include a security key, Kc for generating AS security parameter for a PDCP sublayer. Generating the AS security parameters includes generating an AS security key, Kpd-u, based on the security key, Kc.Each of the UE and the CU node may be preconfigured with a set of AS supported security modes.According to another aspect, a method is provided. The method may provide for security configuration based on preconfigured security modes. The method may include receiving, by a CNF from a user equipment (UE) , a registration request message including: a set of NAS security mode IDs identifying one or more NAS security modes supported by the UE, a second set of AS security mode IDs identifying one or more AS security modes supported by a UE. The method may further include selecting, by the CNF, a NAS security mode for data processing and data forwarding based on one or more of: the one or more NAS security modes supported by the UE and a set of security modes supported b the CNF. The method may further includes sending, by the CNF to the UE, a NAS security configuration message including: an ID of the selected NAS security mode. The method may further include sending, by the CNF to a CU node of a RAN, a setup request message including one or more information included in the registration request message.The setup request message may further include CN-assisted information on AS security mode and CN-assisted security parameter. Each of the UE and the CNF is preconfigured with a set of NAS supported security modes.According to another aspect, a method is provided. The method may provide for security configuration based on preconfigured security capabilities. The method may include receiving, by an XC node of a RAN from at least one PF associated with the XC node, a security capability message. The security capability message may include security capabilities supported by the at least one PF, the security capabilities including one or more of:a set of security capabilities on data processing, and a second set of security capabilities on data forwarding supported by the at least one PF. The method may further include receiving, by the XC node from a CU node, a bearer setup request message including security capabilities supported by a UE, the security capabilities including one or more of: a set of security capabilities on data processing, and a second set of security capabilities on data forwarding. The method may further include selecting, by the XC node, a PF based on the security capabilities supported by the at lease one PF and the security capabilities supported by the UE.The set of security capabilities on data processing may include: a set of security for use on data processing on PF sublayer. The set of security capabilities on data forwarding may include: a set of security algorithms for use on data forwarding on a PDCP sublayer.The method may further include sending, by the XC node to the CN node, a second security capability message including one or more information included in the security capability message.The bearer setup request message may further include CU-assisted information on AS security mode and CN-assisted security information. The CN-assisted security information may include one or more of: CN-assisted information on AS security mode, and CN-assisted security parameters for deriving AS security parameters.The method may further include selecting, by the XC node, an AS security mode based on one or more of: the CU-assisted information and CN-assisted information on AS security mode. The method may further include selecting, by the XC node, AS security algorithms based on one or more of: the selected AS security mode, security capabilities supported by the at least one PF unit and security capabilities supported by the UE. The method may further include generating, by the XC node, AS security parameters according to on the selected AS security mode and based on the CN-assisted security parameters. The method may further include sending, by the XC node to the at least one PF, an AS security  configuration message including one or more of: an ID of the selected AS security mode, selected AS security algorithms, and the generated AS security parameters.The CN-assisted security parameters may include one or more of: a first security key, Kx, for generating AS security parameter of a PF sublayer, and a second security key, Kc, for generating AS security parameter of a PDCP sublayer. Generating AS security parameters may include generating, by the XC node, one or more AS security keys based on the first security key, Kx. The one or more AS security keys may include a first AS security key, Kpf-u, for a PF sublayer security between the selected PF and the UE. The one or more AS security keys may include a second AS security key, Kpf-pf, for PF sublayer security between different PF units of the at least one PF units. The one or more AS security keys may include a third AS security key, Kxc-u, for XC sublayer security between the XC node and the UE. Generating AS security parameters includes generating, by the XC node, based on the second security key, Kc, a fourth AS security key, Kpd-u, for a PDCP sublayer security between the PF and UE.The method may further include sending, by the XC node to the UE, a second AS security configuration message including one or more of: the ID of the selected AS security mode, the selected AS security algorithms, and the generated AS security parameters. The method may further include sending, by the XC node to the CU node, a third AS security configuration message including one or more of: the ID of the selected AS security mode, the selected AS security algorithms, and the generated AS security parameters.Each of the UE and the XC node may be preconfigured with a set of security capabilities indicating one or more lists of algorithms for use on one or both of: data processing and data forwarding.According to another aspect, a method is provided for performing security configuration based on preconfigured security capabilities. The method includes receiving, by a CU node of a RAN from a CNF, a setup request message. The setup request message may include security capabilities supported by a UE, the security capabilities including one or more of: a set of security capabilities on data processing, and a second set of security capabilities on data forwarding. The method may further include sending, by the CU node to an XC node of the RAN, a bearer setup request message including the security capabilities supported by the UE. The method may further include receiving, by the CU node from the XC node, an AS security configuration message including one or more of: an ID of an AS  security mode selected by the XC node, a set of AS security algorithms selected by the XC node, and AS security parameters generated by XC node. The method may further include sending, by the CU node to the UE, a second AS security configuration message including the AS security configuration message.The method may further include receiving, by the CU node from the XC node, a security capability message indicating security capabilities supported by the at least one PF associated with the XC node. The method may further include selecting, by the CU node, a set of AS security capabilities for data forwarding on a PDCP sublayer based on one or more of: the security capabilities supported by the at least one PF, the security capabilities supported by the UE, and CN-assisted security information included in the setup request message. The method may further include generating, by the CU node, AS security parameters based on the selected set of AS security capabilities. The method may further include generating, by the CU node, CU-assisted information on AS security mode.The setup request message may further include a security key, Kc for generating AS security parameter for a PDCP sublayer. Generating AS security parameters may include generating an AS security key, Kpd-u, based on the security key, Kc.Each of the UE and the CU node may be preconfigured with a set of security capabilities indicating one or more lists of algorithms for use on one or both of: data processing and data forwarding.According to another aspect, a method is provided for performing security configuration based on preconfigured security capabilities. The method includes receiving, by a CNF from a UE, a registration request message including: security capabilities supported by the UE, the security capabilities including a set of security algorithms for data processing and a second set of security algorithms for data forwarding. The method may further include selecting, by the CNF, a set of AS security algorithms based on one or more of: the security capabilities supported by the UE, and security capabilities supported by the CNF. The method may further include sending, by the CNF to the UE, a NAS security configuration message including the selected set of AS security algorithms. The method may further include sending, by the CNF to a CU node of a RAN, a setup request message including the security capabilities supported by the UE.The setup request message may further include CN-assisted information on AS security mode and CN-assisted security parameter. Each of the UE and the CNF may be  preconfigured with a set of security capabilities indicating one or more lists of algorithms for use on one or both of: data processing and data forwarding.According to another aspect, an apparatus is provided. The apparatus includes modules configured to perform one or more of the methods and systems described herein.According to one aspect, an apparatus is provided, where the apparatus includes: a memory, configured to store a program; a processor, configured to execute the program stored in the memory, and when the program stored in the memory is executed, the processor is configured to perform one or more of the methods and systems described herein.According to another aspect, a computer readable medium is provided, where the computer readable medium stores program code configured to be executed by a device and the program code is used to perform one or more of the methods and systems described herein.According to one aspect, a chip is provided, where the chip includes a processor and a data interface, and the processor reads, by using the data interface, an instruction stored in a memory, to perform one or more of the methods and systems described herein.Other aspects of the disclosure provide for apparatus, and systems configured to implement the methods according to the first aspect disclosed herein. For example, wireless stations and access points can be configured with machine readable memory containing instructions, which when executed by the processors of these devices, configures the device to perform one or more of the methods and systems described herein.Embodiments have been described above in conjunction with aspects of the present invention upon which they can be implemented. Those skilled in the art will appreciate that embodiments may be implemented in conjunction with the aspect with which they are described but may also be implemented with other embodiments of that aspect. When embodiments are mutually exclusive, or are incompatible with each other, it will be apparent to those skilled in the art. Some embodiments may be described in relation to one aspect, but may also be applicable to other aspects, as will be apparent to those of skill in the art.BRIEF DESCRIPTION OF THE DRAWINGSFurther features and advantages of the present invention will become apparent from the following detailed description, taken in combination with the appended drawings, in which:FIG. 1 illustrates an XaaS module and related interfaces.FIG. 2 illustrates a split RAN architecture.FIG. 3 illustrates potential security protection in future networks.FIG. 4 illustrates a split RAN architecture, according to an aspect.FIG. 5 illustrates deployment of a PF sublayer in a PF unit of an XaaS module, according to an aspect.FIG. 6 illustrates deployment of XC sublayer in an XC unit of an XaaS module, according to an aspect.FIG. 7 illustrates deployment of a PF unit at a CU, according to an aspect.FIG. 8 illustrates deployment of an XC unit at a CU, according to an aspect.FIG. 9 illustrates an XaaS ID according to an aspect.FIG. 10 illustrates a procedure for XaaS capability alignment between two nodes, according to an aspect.FIG. 11 illustrates a procedure for notifying a UE of a support XaaS service, according to an aspect.FIG. 12 illustrates a deployment of PF unit, according to an aspect.FIG. 13 illustrates involvement of multiple PF units in providing an XaaS service to a UE, according to an aspect.FIG. 14 illustrates deployment of multiple PF units, according to an aspect.FIG. 15 illustrates an example table of supported AS security mode, according to an aspect.FIG. 16 illustrates a procedure for a joint security configuration based on preconfigured security modes, according to an aspect.FIG. 17 illustrates a procedure for joint security configuration based on preconfigured security capability, according to an aspect.FIG. 18 illustrates an interface management procedure for split RAN, according to an aspect.FIG. 19A and FIG. 19B illustrate a procedure for establishment of an XaaS session and an XaaS bearer, according to an aspect.FIG. 20 illustrates a procedure for joint PDCP sublayer and PF sublayer security configuration based on preconfigured security modes, according to an aspect.FIG. 21 illustrates a procedure for joint PDCP sublayer and PF sublayer security configuration based on preconfigured security capabilities, according to an aspect.FIG. 22 illustrates an apparatus that may perform any or all of operations of the above methods and features explicitly or implicitly described herein, according to different aspects of the present disclosure.It will be noted that throughout the appended drawings, like features are identified by like reference numerals.DETAILED DESCRIPTIONFuture networks may provide new kinds of services that allow for network-native data processing with one or more methods of: data analytics, AI training, AI inference, data privacy protection, data storage, data collection, data sanitization, data processing, data management, data cleaning, data normalization, useless data filtering, data feature engineering, data compression, data embedding, data representation learning, and data feature extraction.Aspects of the disclosure may provide for systems and methods related to split RAN architecture and security mode for future X-centric service network. Some aspects of the disclosure may provide for deployment of a plug-play XaaS module in a split RAN architecture. According to an aspect, the participating units (e.g., central unit and distributed unit) for data forwarding and the participating units (e.g., PF) unit and XC unit) for data processing may be mutually engaged as described herein. Further aspects of the disclosure may provide for enhanced protocol stacks of the participating units.Some aspects of the disclosure may provide for methods for aligning XaaS capability between two network nodes. For example, a method for aligning XaaS capability  between two network nodes may include: sending, by a first NN to a second NN, an interface request message to setup or update an interface between the first NN and the second NN. The interface setup message includes one or more of: a first node ID, a cell ID, a service ID, and a network ID. The method may further include receiving, by the first NN from the second NN, an interface response message indicating that the interface between the first NN and the second NN is setup or updated. The interface response message may include a second node ID and information that overlaps with the interface request message, the information including one or more of: a cell ID, a service ID, and a network ID.Some aspects, may provide for an interface management procedure. Some aspects may provide for establishment of one or more of XaaS bearer and XaaS session. For example, a method may include receiving, by an XC node of a RAN from a UE, a request message for a service. The method further includes sending, by the XC node to a PF associated with the XC node, a UE context setup request message to setup resources for the service. The method further includes receiving, by the XC node from the PF, a UE context setup response indicating establishment of a bearer associated with the service. The method further includes sending, by the XC node to the UE, a service response to configure the UE for the service.Further aspects may provide for AS security mode selection and configuration based on preconfigured AS security modes, as described herein. For example, a method may include receiving, by an XC node of a RAN from at least one PF associated with the XC node, a security mode message. The security mode message may include one or more AS security mode IDs identifying one or more AS security modes supported by the at least one PF. The method may further include receiving, by the XC node from a CU node, a bearer setup request message including one or more of: AS security modes IDs identifying one or more AS security modes supported by a UE. The method may further include selecting, by the XC node, a PF based on the one or more AS security modes supported by the UE and the one or more AS security modes supported by the at least one PFFurther aspects may provide for AS security mode selection and configuration based on preconfigured AS security capability, as described herein. For example, a method may include receiving, by an XC node of a RAN from at least one PF associated with the XC node, a security capability message. The security capability message may include security capabilities supported by the at least one PF, the security capabilities including one or more of: a set of security capabilities on data processing, and a second set of security capabilities on data forwarding supported by the at least one PF. The method may further include  receiving, by the XC node from a CU node, a bearer setup request message. The bearer setup request message may include security capabilities supported by a UE. The security capabilities may include one or more of: a set of security capabilities on data processing, and a second set of security capabilities on data forwarding. The method may further include selecting, by the XC node, a PF based on the security capabilities supported by the at lease one PF and the security capabilities supported by the UE.Besides traditional connectivity-oriented communication services, 6G includes new kinds of services for network-native data processing. Such services may include data analytics, artificial intelligence (AI) training, AI inference, data privacy protection, data storage, data collection, data sanitization, data processing, data management, data cleaning, data normalization, useless data filtering, data feature engineering, data compression, data embedding, data representation learning, and data feature extraction. One or more of the new kinds of services for network-native data processing may be referred to as X-as-a-service (XaaS) or anything-as-a-service.According to an aspect, X-centric network may be proposed for 6G to provide XaaS. In some aspects, XaaS can be Data Analytics and Management (DAM) as a service, NET4AI as a service, NET4Data as a service, NET4meta as a service, etc. In some aspects, one or more of these services can be provided by one or multiple service providers. The one or multiple service providers may include one or more of: operators, vendors, network functions, network equipment and third parties.In an aspect, a DAM service may include collecting (by one or more service provides) data from a data source and providing the collected data to a data consumer in a privacy-protected form (e.g., de-identified data, or anonymized data or the like) . The data consumer may use the collected data to perform tasks such as data analytics, AI training and AI inference.In some aspects, NET4AI service may include providing connection and intelligent computing service, e.g., for AI training, AI inference. In some aspects, NET4Data service may include providing data storage service and performing data access control.In some aspects, a plurality of these services may be combined and provided to a customer. For combined services, one or more services providers may cooperate with each other in providing the combined service.Each XaaS may involve one or more functions in providing the service. In some aspects, each XaaS may involve an XC. The XaaS XC may control and manage the service. For example, the XC may control and configure an XaaS PF to execute specific tasks involved in an XaaS.In some aspects, each XaaS may further involve one or more PFs. The XaaS PF may execute one or more XaaS tasks under the control of the XC. Some examples of XaaS tasks may include data pre-processing and data privacy protection tasks in DAM service, AI training &AI inference tasks in NET4AI service, data storage &access control tasks in NET4Data service.In some aspects, each XaaS may be provided by an XaaS module. Each module may be associated with an XC and one or more PFs.In some aspects, one or more XaaS functions (e.g., XC, PF) can be deployed in one or more of: a RAN, a CN and a UE. For example, an XC can be deployed in the network control plane (CP) , and a PF can be deployed in the network user plane (UP) or the data plane. According to an aspect, deployment of XaaS PF into a network, e.g., into the RAN and UE side, may be provided.XaaS may be a service that provides data processing between a UE and a XaaS function, e.g., a PF deployed in CN, a PF deployed in RAN, or a Data Network. In some aspects, an XaaS may be a service that provides data processing between an XaaS customer and an XaaS network function, e.g., between a UE and a CN XaaS function, between a server of a third party and a CN XaaS function, between a UE and a DN, between DN and a CN PF, and between a server and a RAN node, etc.In some aspects, XaaS may further involve an XaaS session. An XaaS session may refer to an association between an XaaS customer and an XaaS network function that provides an XaaS. In some aspects, an XaaS session may be an association between a UE and a CN XaaS function (e.g., a PF deployed in CN, or a Data Network) that provides an XaaS. In some aspects, XaaS session can be established between a UE and a CN PF unit, or between a UE and a DN.In some aspects, XaaS may be implemented on the top of 5G PDU connectivity service. In some aspects, establishing an XaaS session may comprise establishing relevant resources (e.g., connectivity resource, computing resource, and storage resource) used to  complete an XaaS task. In some aspects, an XaaS session can be regarded as an improved PDU session aimed at data processing in addition to data forwarding.In some aspects, through the XaaS session, data may be processed in different nodes flexibly, e.g., in CN PF unit, in PF sublayer of RAN, in PF sublayer of UE. The number of participating nodes (e.g., RANs, UEs, and CN functions) in an XaaS session may not be limited. Accordingly, an XaaS session may go through several RAN nodes, and these RAN nodes may cooperate to process the XaaS data in sequence or parallel.In some aspects, XaaS may further involve XaaS bearer (which may include XaaS data bearer and XaaS signaling bearer) . An XaaS bearer may refer to the service provided by the RAN radio Layer 2, including the PF sublayer and the XC sublayer, for both data transfer and data processing between UE and RAN. In some aspects, XaaS bearers may refer to channels offered by RAN radio Layer 2, including PF and XC sublayers, to higher layers for both data transfer and data processing. Accordingly, PF and XC sublayers may provide the upper layers with the service of data forwarding and data processing between the UE and RAN by means of XaaS bearer. The service access points between a PF sublayer and upper layers (or an XC sublayer and upper layers) may be the XaaS bearers.In some aspects, XaaS bearers may include XaaS data bearers (XDB) for user plane data. In some aspect, each XDB may be configured with a PF sublayer at RAN and at UE, a PDCP sublayer at RAN and at UE, an RLC sublayer at RAN and at UE, a MAC sublayer at RAN and at UE, and PHY layer at RAN and at UE.In some aspects, XaaS bearers may include XaaS signaling bearers (XSB) for control plane data. In some aspects, each XSB may be configured with a XC sublayer at RAN and at UE, a PDCP sublayer at RAN and at UE, an RLC sublayer at RAN and at UE, a MAC sublayer at RAN and at UE, and PHY layer at RAN and at UE as illustrated. In some aspects, the XC sublayer at RAN and at UE, may sit on the top of PDCP sublayer at RAN and at UE, to transmit signaling message between RAN and UE, e.g., to configure and control PF sublayer.In some aspects, XaaS may further involve XaaS QoS flow. According to an aspect, XaaS QoS Flow may be the finest granularity of QoS differentiation in XaaS Session. In some aspects, traffic mapped to the same XaaS QoS Flow may receive the same data forwarding treatment and data processing treatment. In some aspects, a XaaS session may comprise one or multiple XaaS QoS flows.Providing different XaaS QoS data processing treatment and data forwarding treatment may requires separate XaaS QoS Flow. An XaaS QoS Flow ID (XQFI) may be used to identify an XaaS QoS Flow. An XQFI may be a scalar ID that is used as a reference for specific XaaS QoS characteristics. Traffic (e.g., User Plane traffic) with the same XQFI within an XaaS Session may receive the same data processing treatment and data forwarding treatment. Data processing treatment may refer to computing accuracy, computing latency, privacy level, storage duration, data processing policy, data cleaning policy, data normalization policy, etc. Data forwarding treatment may include scheduling policy, queue management policy, link layer protocol configuration (e.g., MAC / RLC configuration) , admission threshold, etc. In some aspects, the XQFI may be carried in an encapsulation header (e.g., GTP-U packet header, SDAP packet header) of CN or RAN packets.In some aspects, XaaS in may further involve XaaS QoS parameters. XaaS QoS parameters may include both parameter on data forwarding treatment and parameter on data processing treatment. In some aspects, XaaS QoS parameters can be configured per node (e.g., per UE) , per network function, per XaaS session, per XaaS QoS flow, or per XaaS Bearer.In some aspects, data forwarding treatment parameters may include one or more of:data transfer resource scheduling policy, data queue management policy, data transfer priority level, link layer protocol configuration (e.g., MAC / RLC configuration) , admission threshold, data loss rate, data transfer latency, data forwarding security protection method, security level, etc. Data forwarding treatment parameters may relates to data forwarding in data plane e.g., in RAN L2 / L1 layers, and in CN UPF.In some aspects, data processing treatment parameters may include one or more of: data processing scheduling policy, computing accuracy, computing latency, AI model type, privacy protection method, privacy level, data storage duration, data processing policy, data cleaning policy, data normalization policy, data quality level, data processing priority, etc. Data processing treatment parameters may relate to the data processing in a UE PF sublayer, RAN PF sublayer, or CN PF.In some aspects, the data forwarding treatment parameters and data processing treatment parameters may be cross-adjusted and dynamic adapted, e.g., under the control of XC or other control plane functions. For example, data transfer latency and computing  latency can be cross adjusted to guarantee a total latency threshold of an XaaS task, e.g., reducing the data transfer latency while increasing the computing latency for trade-off.In some aspects, one or more data forwarding treatment parameters may correlate with one or more data processing treatment parameters. For example, guaranteeing a data forwarding treatment parameter (e.g., data loss rate) may be a prerequisite to guarantee a data processing treatment parameter (e.g., computing accuracy) .In some aspects, one XaaS session may be configured with one SDAP entity. Each XaaS Bearer may be configured with one PF entity. Each DRB may be associated with one PDCP entity. In some aspects, the SDAP sublayer may perform mapping between data of XaaS QoS flow (s) and XaaS bearer (s) . One or more XaaS QoS flows may be mapped onto one XaaS bearer. One or more XaaS bearers can be further mapped onto one or more DRBs.FIG. 1 illustrates an XaaS module and related interfaces. As illustrated, the XaaS can be provided by the XaaS module (e.g., XaaS module 102, 104 and 106) . In some aspects, the XaaS module may be a plug-play component which can be deployed in the CN 108, the RAN 110 or even terminals.As described herein an XaaS service may be provided by an XaaS module. According to an aspect, the XaaS module may include at least one PF unit and an XC unit related to the XaaS service. In some aspects, each XaaS module may be responsible for providing a specific XaaS service e.g., DAM service, NET4AI service. In some aspects, an XaaS module may provide one or more XaaS services as per implementation.In some aspects, one or multiple XaaS modules with the same or different responsibilities can be deployed in one or more of CN 108, RAN 110 and terminals, using a centralized or a distributed implementation method. Within one XaaS module 104 or 106, one XC unit 112 or 114 and one or multiple PF units 116 or 118 may be included. One PF unit may be connected to one XC unit via a T3 interface, and one XC unit may be connected to one or more PF units. In some aspects, the one or more of PF units and XC units can be centralized or distributed for implementation.In some aspects, different PF units within an XaaS module can be connected through a T4 interface. A PF unit and an XC unit may connected to CN 108 (directly or via an intermediate node) via the logical T6 and T7 interface respectively. According to an aspect, PF units 116 and 118 in different XaaS modules may be connected via T4 interface. XC units  112 and 114 in different XaaS modules 104 and 106 respectively may be connected via a T5 interface.In some aspects, the T4 and T5 interfaces between different XaaS modules may be replaced by a unified T8 interface between different XaaS modules.FIG. 2 illustrates a split RAN architecture. As illustrated, the split RAN architecture 202 may include a CU 204 and one or more DUs 206. The CU 204 and the DU 206 may connect to each other through F1-U (for user plane) and F1-C (for control plane) interfaces.On the user plane, a Service Data Adaptation Protocol (SDAP) sublayer 211, and a Packet Data Convergence Protocol (PDCP) sublayer 212 may be deployed in the CU 204, and a RLC sublayer 213, a Medium Access Control (MAC) sublayer 214 and a physical (PHY) layer 215 may be deployed in the DU 206. A DRB may be configured with the SDAP 211, the PDCP 212, the RLC 213, the MAC 214 sublayers and the PHY layer 215.On the control plane, a Radio Resource Controller (RRC) sublayer 221 instead of the SDAP sublayer may be deployed in the CU 204, along with the PDCP sublayer 222. At DU 206, the RLC sublayer 223, MAC sublayer 224 and PHY layer 225 may be deployed. A SRB may be configured with the RRC 221, the PDCP 222, the RLC 223, the MAC 224 sublayers and the PHY layer 225. One DU may connect to one CU 204. The CU 204 may connect to multiple DUs 206. DUs may be distributed locally to UEs, and CUs may be distributed in a cloud far away from DU and UE.Data encapsulated in a QoS flow of a PDU session may be mapped to one or more DRB by the SDAP sublayer 211. For example, the RAN SDAP sublayer 211 may map the data of a PDU session or the associated QoS flow to a DRB. A UE may map its uplink data of a PDU session or associated QoS flow to a DRB to transmit to a peer RAN. Similarly, the UE may map its downlink data of a DRB to a PDU session or associated QoS flow to submit to the application layer.As mentioned, a split RAN architecture may include a CU and one or more DUs. One DU may connect to one CU. One CU may connect to multiple DUs. DUs may be distributed locally to UEs, and CUs may be distributed in cloud far away from DU and UE.The coverage of a DU may be small, for example, in mmWave or THz in 6G. Thus, for provision of XaaS in the future, deploying an XaaS module in a DU may limit the amount of data that may be collected due to the DU’s local small coverage area. The data that  may be collected may include, for example, raw data in DAM service, intermediate model data in NET4AI service) . So, the amount of data collected at the DU may not be enough for an XaaS module to adequately execute data processing for the XaaS.With respect to CU, an XaaS module may be deployed at the CU 204, and data collected by DUs 206 may be aggregated at the CU 204 to achieve “big data” . However, transmission of data from DUs to CU may increase the burden of the F1 interface and the CU, thereby negatively affecting the traditional connectivity-oriented service.Moreover, current L2 sublayers and the PHY layer in the CU and the DU may be unable (lack the functionality) to parse and process the data, e.g., no capability to parse and process the Service Data Unit (SDU) of each sublayer or layer.Further, how an XaaS module (i.e., PF unit and XC unit) may be deployed in a RAN, as an internal plug-play component of a RAN node, is not clear yet. A RAN’s split architecture adds further complexity to the challenge.FIG. 3 illustrates potential security protection in future networks. In traditional data forwarding network, ciphering protection may be executed at a PDCP sublayer. In future networks (e.g., future data forwarding and data processing networks) , ciphering protection for XaaS may be executed at one or more of: the PDCP sublayer 212 and the PF unit 306.The PF unit 306, of an XaaS module 302, may perform privacy protection on data processing with ciphering algorithm (s) , e.g., homomorphic encryption (HE) algorithm. In some aspects, a CU 204 (e.g., a PDCP sublayer 212 of the CU) may perform security protection on data forwarding with one or more ciphering algorithms, e.g., traditional 5G Advanced Encryption Standard (AES) , SNOW 3G, Zuc stream cipher (ZUC) algorithms. In some aspects, the security protection on data forwarding may be performed, by the CU, together with (or at the same time as) the privacy protection done by the PF unit.According to an aspect, ciphering protection (e.g., for privacy protection) may be already executed in a PF unit for XaaS data, e.g., the data may be encrypted with homomorphic encryption by PF unit in federated learning (FL) learning (i.e., NET4AI service) . In some aspects, if the security level requirement is already met via the homomorphic encryption scheme, the CU (e.g., the PDCP sublayer of the CU) may not need to perform the traditional 5G ciphering scheme.An AS security mode 310 may indicate what security protection and privacy protection may be required. For example, the AS security mode 310 may indicate that data  ciphering should be executed at, none of, or, one or more of: the PDCP sublayer and the PF unit. In some aspects, the AS security mode (e.g., only the PDCP sublayer, only the PF, both or neither should execute data ciphering) may be aligned and negotiated between the PF unit 306 and the CU 204 on security protection and privacy protection.Some aspects of the disclosure may provide for deployment of an XaaS module in the split RAN architecture together with the CU and the DU. As described herein, the XaaS module (including one or more of: the PF unit and the XC unit) may be a component of a RAN node in 6G. In some aspects, the XaaS module may be an internal component of a RAN node in 6G.In some aspects, different nodes (e.g., UE, DU, CU, XC unit and PF unit) may provide or support different XaaS services to a service customer (e.g., UE, 3rd party server) . The different nodes’ XaaS capability may be aligned and communicated (e.g., via a notification) to the different nodes for interface management, mutual node selection, etc.In some aspects, the XaaS module may provide privacy protection with ciphering, and the CU may provide security protection with ciphering as well. According to an aspect, privacy protection and security protection may be aligned between the XaaS module and the CU on data ciphering.To solve the problems above, we propose the split RAN architecture as shown in Fig. 4. The XaaS module can be an internal component of a RAN, together deployed with a CU and a DU.FIG. 4 illustrates a split RAN architecture, according to an aspect. The RAN 400 may comprise a CU 404 and one or more DUs 406. The RAN may further comprise one or more XaaS module 410 and 420. The one or more XaaS module 410 and 420 may be deployed underneath the CU 404 (e.g., between CU 404 and DU 406) and as internal components of the split RAN architecture. The one or more XaaS modules may have the same or different responsibilities. The one or more XaaS modules may be deployed according to a centralized or a distributed implementation method.In some aspects, the CU 404 may be the control plane and user plane anchor to connect to the CN 408. Accordingly, PF unit (s) and XC unit (s) of the one or more XaaS modules may connect to the CN 408 via the CU 404.The XaaS module 410 may comprise an XC unit 412 and one or multiple PF units 414. One PF unit may be connected to the XC unit 412 via a T3 interface 416, and the XC  unit 412 may be connected to one or more PF units via the T3 interface 416. The different PF units 414 within an XaaS module 410 may be interconnected through a T4 interface 418.According to an aspect, the CU 404 may be connected to the XC unit 412 via a T2-C 421 interface on control plane to send and receive signaling and control message, and to the PF unit (s) 414 via a T2-U interface 422 on user plane to send and receive traffic. In some aspects, the T2-C 421 and T2-U 422 interfaces may be integrated into a T2 interface (e.g., T2 interface 423 between the CU 404 and the XaaS module 420) .In some aspects, the one or more DUs 406 may be connected to the XC unit 412 via a T1-C 425 interface on control plane to send and receive signaling and control message, and to the one or more PF units 414 via a T1-U interface 426 on user plane to send and receive traffic. In some aspects, the T1-C 425 and the T1-U 426 interfaces can be integrated into a T1 interface.In some aspects, some DUs of the one or more DUs 406 may connect to the CU 404 but may not connect to one or more of: the XC unit 412 or the PF units 414. In some aspects, a PF unit, of the one or more PF units 414, may be connected to one or more DUs underneath the same CU. In some aspects, an intermediate PF unit, of the one or more PF units 414, may be not connected to any CU directly.According to an aspect, a DU, of the one or more DUs 4106, may be connected to an XaaS module’s one or more PF units 414, and may be further connected to one XC unit, underneath the same CU. In some aspects, if multiple XaaS modules are deployed underneath the same CU, a DU may be connected to one or more PF units of the one or more XaaS modules and XC unit of each of the XaaS modules.In some aspects, each DU 406 may be connected to the CU 404 via F1-C 429 (for control plane) and F1-U 430 (for user plane) interfaces. In some aspects, traffic of F1-C 429 and F1-U 430 can be carried via T1 and T2 interfaces, in which, the F1 traffic may be encapsulated on T1 and T2 interfaces, and the F1 interface can be physically undone or taken apart. For example, signaling and control message of F1-C may be carried via T1-C 425 and T2-C 421 interfaces and traffic of F1-U may be carried via the T1-U 426 and T2-U 422 interfacesIn some aspects, one or more PF units in different XaaS modules may be interconnected via T4 interface. In some aspects, XC units in different XaaS modules may be  interconnected, directly, via a T5 interface. In some aspects, XC units in different XaaS modules may be interconnected, indirectly, via a CU, or one or more CUs.In some aspects, the T4 and T5 interfaces between different XaaS modules may be replaced by a unified T8 interface between the different XaaS modules.In some aspects, an XC unit and one or more PF units can be deployed as separate entities (e.g., an XC unit and one or more PF unit may be in separate nodes of RAN) or within the same entity (e.g., XC unit and one or more PF units may respectively be deployed as CP sublayer and UP sublayer within the same XaaS module or RAN node) .In some aspects, the one or more of PF unit (s) and XC unit may be deployed between the DU (s) and the CU. In some aspects, the one or more of PF unit (s) and XC unit may be deployed closer to the DU (s) or closer to the CU.The implementation of an XC and one or more PFs of an XaaS module is not limited to the illustrated implementation and other potential implementation are possible. For example, some units may be integrated together as a unified entity, e.g., the CU and the XC unit may be integrated together, the CU and one or more PF units may be integrated together, DU and one or more PF units may be integrated together, or the XC unit and one or more PF units may be integrated into the DU or the CU. Where two or more units maybe integrated together, the interfaces between the units may be based on an internal implementation.According to an aspect, data collected by DUs 406 may be aggregated at one or more XaaS modules to achieve “big data” , thereby obviating the need to transmit data to a CU, thus reducing overhead and burden on a F1 interface. Accordingly, a plug and play XaaS module may be enabled, and the units (CU and DU) for data forwarding and the units (PF unit and XC unit) for data processing may be mutually engaged.In addition, the split RAN architecture of FIG. 4, e.g., the RAN 400, may be backward compatible and have fewer effects on the current connectivity-oriented RAN architecture for data forwarding service. For example, the XaaS module may not affect the F1 interface (between CU and DU) of the current connectivity-oriented RAN node. Further, the protocols and specification on F1 interface may not need to be changed. In addition, the split architecture of the RAN 400 may reduce or prevent the frequent XaaS service task interruption and task context migration, e.g., when a UE inter-DU handover occurs.In FIG. 4, different options may be available for deploying the PF unit (s) and the XC unit of an XaaS module, as illustrated in FIG. 5 and FIG. 6. FIG. 5 illustrates a  deployment of a PF sublayer in a PF unit of an XaaS module, according to an aspect. FIG. 6 illustrates a deployment of an XC sublayer in an XC unit of an XaaS module, according to an aspect. In the context of the present disclosure, an XC sublayer may also refer to an XC protocol layer.According to an aspect, referring to FIG. 5, a PF unit 500 of an XaaS module may comprise an enhanced RAN protocol sublayer (i.e., a PF sublayer 502) to execute an XaaS task. The PF sublayer 502, at PF unit 500, may be deployed on top of the PDCP sublayer 503. Correspondingly, on the user plane, at UE 510, a PF sublayer 512 may be deployed between SDAP sublayer 511 and PDCP sublayer 513. According to an aspect, data processing may be performed at one or more of: the UE side on the PF sublayer 512, and RAN side on the PF sublayer 502. Data processing may be executed with one or more methods of: data analytics, AI training, AI inference, data privacy protection, data sanitization, data processing, data management, data cleaning, data normalization, useless data filtering, data feature engineering, data compression, data embedding, data representation learning, and data feature extraction.For example, the UE 510 may perform AI training at PF sublayer 512 and send the training data, via a radio link, to a DU 520. The DU 520 may send the training data via the T1-U interface to the PF unit 500. PF unit 500 may perform further data processing, e.g., AI training, at PF sublayer 502 to obtain further trained data (e.g., a trained model) . The PF unit 500 may then feedback the further training data to the UE 510, via the T1-U interface and the radio link.According to an aspect, referring to FIG. 6, an XC unit 600 of an XaaS module may comprise an enhanced RAN protocol sublayer (i.e., an XC sublayer 602) to control the execution of an XaaS task. The XC unit 600 may be similar to the aforementioned XC unit 412. The XC sublayer 602 may be deployed on top of the PDCP sublayer 603 at the XC unit 600. On the control plane, at a UE side 510, the XC sublayer 612 may be deployed on top of the PDCP sublayer 613.In some aspects, one or more functions of the PDCP sublayer, including functions related to an XaaS bearer, may be pulled down from a CU to one or both of the PF unit 500 and the XC unit 600 of the XaaS module, to enable the one or both of the PF sublayer 502 and the XC sublayer 602 to parse the data which may be encrypted by a peer PDCP sublayer. For example, data may be encrypted by a PDCP sublayer of a node (e.g., UE or PF unit) , and  the PDCP sublayer of the peer node (e.g., a PF unit or a UE) may decrypt the encrypted data and then forward the decrypted data to a PF sublayer of the peer node (e.g., the PF unit or the UE) for further data processing, e.g., for data parsing.In some aspects, for traditional connectivity-oriented SRB or DRB, the PDCP sublayer may be in the CU.FIG. 5 further illustrates a protocol structure for the interface T1-U 541 (which may be similar to the interface T1-U 426) and the interface T2-U 542 (which may be similar to the interface T2-U 422) . In some aspects, the transport network layer (TNL) may be based on IP transport, comprising the User Datagram Protocol (UDP) and the GPRS Tunneling Protocol for the user plane (GTP-U) sublayers on top of the Internet Protocol (IP) sublayer. According to an aspect, for the T1-U 541 interface, the PF unit 500 may further comprise a GTP-U sublayer 504, a UDP sublayer 505, and an IP sublayer 506 as illustrated in Fig. 5. For the T2-U 542 interface, the PF unit 500 may further comprise a GTP-U sublayer 507, a UDP sublayer 508, and an IP sublayer 509 as illustrated. As explained above, T4 interface is dedicated to sending and receiving traffic between two PF units on data plane, T6 interface is dedicated to sending and receiving traffic between a PF unit and a CNF on data plane. T7 interface is dedicated to sending and receiving singling and control message between a XC unit and a CNF on control plane. A PF unit and a CNF may be connected via a T8-U interface to send and receive traffic on data plane. A XC unit and a CNF may be connected via a T8-C interface to send and receive signalling and control message on control plane. That is, T8-U interface is also termed as T6 interface, and T8-C interface is also termed as T7 interface. Similar to T1-U, and T2-U, the underlay protocol stacks on T4, T6 and T8 can be but not limited to that in FIG. 5, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .In some aspects, the TNL can be based on other protocols, for example, based on IP transport, comprising the Quick UDP Internet Connections (QUIC) or Segment Routing over IPv6 (SRv6) on top of IP. The underlay protocol stacks can be but not limited to that in FIG. 5, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick  UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .Accordingly, in some aspects, with respect to T1-U interface 541, the DU 520 (e.g., a DU of UDs 406) may comprise a corresponding GTP-U sublayer 524, UDP sublayer 525 and IP sublayer 526 as illustrated. Similarly, with respect to the T2-U interface 542, the CU 530 (which may be similar to the CU 404) may comprise a corresponding GTP-U sublayer 537, UDP sublayer 538 and IP sublayer 539 as illustrated.FIG. 6 further illustrates a protocol structure for the T1-C 641 interface (which may be similar to the T1-C 425 interface) and the T2-C 642 interface (which may be similar to the T2-C 421 interface) . In some aspects, the TNL may be based on IP transport, comprising the Stream Control Transmission Protocol (SCTP) on top of IP. In some aspects, the TNL can be based on other protocols, for example, based on IP transport, comprising the QUIC or SRV6 on top of IP. The application layer signaling protocol may be respectively referred to as a T1 Application Protocol (T1AP) and a T2 Application Protocol (T2AP) . Similar to T1AP and T2AP, the application layer signaling protocol on the T3 interface may be referred to as a T3 Application Protocol (T3AP) , the application layer signaling protocol on the T5 interface may be referred to as a T5 Application Protocol (T5AP) , the application layer signaling protocol on the T7 interface may be referred to as a T7 Application Protocol (T7AP) , and the application layer signaling protocol on the T3 interface may be referred to as a T8 Application Protocol (T8AP) . The T1AP, T2AP, T3AP, T5AP, T7AP and T8AP are respectively to send or receive signaling and control message on the corresponding interfaces. The underlay protocol stacks can be but not limited to that in FIG. 6, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .According, in some aspects, referring to FIG. 6, for the T1-C 641 interface, the XC unit 600 may further comprise a T1AP sublayer 604, an SCTP sublayer 605, and an IP sublayer 606 as illustrated. For the T2-C 642 interface, the XC unit 600 may further comprise a T2AP sublayer 607, an a SCTP sublayer 608, and an IP sublayer 609 as illustrated.In some aspects, with respect to the T1-C interface 641, the DU 520 may further comprise a corresponding T1AP sublayer 624, an SCTP sublayer 625, and an IP sublayer 626  as illustrated. Similarly, with respect to the T2-C interface 642, the CU 530 may correspondingly comprise a T2AP sublayer 637, an SCTP sublayer 638, and an IP sublayer 639 as illustrated.According to an aspect, one or more of: a PF unit and an XC unit of an XaaS module may be deployed with a CU or a DU for XaaS services. Thus, one or more of a PF unit and an XC unit may be integrated with a CU or a DU.For example, as an evolution of the 5G split RAN architecture, on the user plane, the SDAP, PF and PDCP sublayers may be deployed in a CU, and the RLC, the MAC sublayers and the PHY layer may be deployed in a DU as illustrated in FIG. 7. FIG. 7 illustrates deployment of a PF unit at a CU, according to an aspect. The CU 730 may be integrated with one or more PF units. Accordingly, the functions of a PF unit and of the CU may be integrated. The CU may communicate with the DU 720 via the enhanced F1’ -U 740 interface. The UE 710 may communicate with the DU 702 and the CU 730 via a radio link.In some aspects, a PF sublayer 702 may be deployed in the CU 730 for an XaaS bearer. The CU 730 may further comprise an SDAP sublayer 701 and a PDCP sublayer 703. Correspondingly, the UE 710 may comprise an SDAP sublayer 711, a PF sublayer 712 and a PDCP sublayer 713.FIG. 7 further illustrates a protocol structure for an enhanced interface F1’ -U 740 between the DU 720 and the CU 730. In some aspects, the TNL may be based on IP transport, comprising the UDP and the GTP-U on top of IP. In some aspects, the TNL can be based on other protocols, for example, based on IP transport, comprising the QUIC or SRV6 on top of IP. The underlay protocol stacks can be but not limited to that in FIG. 7, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .According to an aspect, the DU 720 and the CU 730 may exchange data through an enhanced the F1’ -U interface 740 (an enhancement to the F1-U interface (e.g., F1-U 430) . With respect to the F1’ -U interface 740, the CU 730 may comprise a GTP-U sublayer 704, a UDP sublayer 705, and an IP sublayer 706. Correspondingly, with respect to the F1’ -U interface 740, the DU 720 may comprise a GTP-U sublayer 724, a UDP sublayer 725, and an IP sublayer 726.A person skilled in the art may appreciate that implementation of a PF unit in RAN is not limited to the illustrated implementation and that other implementation may also be possible. In some aspects, when PF unit is integrated with CU 730, the XaaS module may not be flexible plug-play, and the data collected by DU may be aggregated together to CU which may increase the traffic burden on F1’ -U interface.FIG. 8 illustrates a deployment of an XC unit at a CU, according to an aspect. An XC unit of an XaaS module may be deployed at a CU 830. Accordingly, the functions of the XC unit and the CU may be integrated.In an aspect, on the control plane, an XC sublayer 802 and a PDCP sublayer 803 may be deployed at the CU 830, and the RLC 814, the MAC sublayers 815 and the PHY layer 816 may be deployed in a DU 820. Correspondingly, the UE 810 may comprise an XC sublayer 812 on top of the PDCP sublayer 813.The CU 830 and the DU 820 may communicate with each other via the F1’ -C interface 841. The UE 810 may communicate with the DU 820 and the CU 830 via a radio link.FIG. 8 further illustrates a protocol structure for the enhanced interface F1’ -C 841 between the DU 820 and the CU 830. In some aspects, the TNL may be based on IP transport, comprising the SCTP on top of the IP. In some aspects, the TNL can be based on other protocols, for example, based on IP transport, comprising the QUIC or SRV6 on top of IP. In some aspects, the application layer signaling protocol may be referred to as a F1’ Application Protocol (F1’ AP) . The underlay protocol stacks can be but not limited to that in FIG. 8, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .According to an aspect, for the control plane, the DU 820 and the CU 830 may exchange data messages through an enhanced the F1’ -C interface 841 (an enhancement to the F1-C interface (e.g., F1-C 429) . With respect to the F1’ -C interface 841, CU 830 may comprise an F1’AP sublayer 804, an SCTP sublayer 805 and an IP sublayer 806. Correspondingly, with respect to the F1’ -C interface 841, the DU 820 may comprise an F1’ AP sublayer 824, an SCTP sublayer 825 and an IP sublayer 826.According to an aspect, one or more nodes (e.g., UE, DU, CU, XC unit and PF unit) may provide or support different XaaS services to a service customer. In an aspect, each node of a plurality of nodes (e.g., UE, DU, CU, XC unit and PF unit) may, align with and communicate to other nodes of the plurality of nodes via an interface management procedure, based on the capabilities supported by the nodes.The different nodes’ supported capability on the XaaS service may be aligned and communicated to the different nodes for mutual node selection in one or more subsequent or follow up procedures, e.g., a UE initial access procedure for XaaS service, and a UE XaaS bearer establishment procedure, based on the capabilities supported by the nodes.According to an aspect, an XaaS service (e.g., NET4AI service, DAM service) may be identified with an XaaS ID. In some aspects, one or more nodes may provide one or more XaaS services to a UE via different cells of different networks. Each network can be identified with a network identifier (ID) , e.g., a Public Land Mobile Network (PLMN) ID, or a Non-Public Network (NPN) ID. A cell of a network may be identified by a cell ID.FIG. 9 illustrates an XaaS ID 900 according to an aspect. In some aspects, an XaaS ID 900 may comprise one or more of: a service type ID 902, a task ID 904, a mission ID 906, and a network ID 908. The Service type ID 902 may identify the Service type (e.g., NET4AI service, DAM service) of the XaaS service. The Task ID 904 may identify one or more tasks the XaaS service can execute (e.g., DAM service can execute data privacy protection task, data pre-processing task, data analytics task; NET4AI service can execute AI model training task, AI inference task) . The mission ID 906 may identify a mission the XaaS service can participate in. The network ID 908 may identify a network providing the XaaS service. In some aspects, a mission may comprise one or more tasks.FIG. 10 illustrates a procedure 1000 for an XaaS capability alignment between two nodes, according to an aspect. Two nodes may align their XaaS capability with each other by sharing with each other information on XaaS services they each support. Each of the two nodes may be one of: a PF unit, an XC unit, a DU and a CU.In some aspects, the procedure 1000 may include a first node1 1020 sending a request message 1002 to a second node2 1030. The request message may be an interface setup or update request message. The request message may include one or more of: a node1 ID, a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . In some aspects, the request message 1002 may indicate that the node1 identified by the node1 ID supports the  XaaS service identified by the XaaS ID via the network identified by the network ID and the cell identified by the cell ID. In some aspects, the request message 1002 may include a list of one or more of: cell IDs, XaaS IDs and network IDs which Node1 1020 may support.In some aspects, if the first node1 1020 (e.g., the PF) is not configured with a cell, the cell ID may not be included in the request message 1002.In some aspects, the procedure 1000 may further include the second node2 1030 sending a response message 1004 to the node1 1020. The response message 1004 may be an interface setup or update response message to notify the successful setup or the update of the interface. In some aspect, the response message 1004 may include one or more of: a node2 ID, a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . In some aspects, the response message 1004 may indicates that the node2 identified by the node2 ID supports an XaaS service identified by the XaaS ID via the network identified by the network ID and the cell identified by the cell ID. The response message 1004 may include a list of one or more of: cell IDs, XaaS IDs and network IDs. The one or more of: cell ID, XaaS ID and network ID, of node2 1030, included in the interface setup or update response message may overlap (i.e., be similar) to those of node1 1020, included in the interface setup or update request message 10002.In some aspects, if the XaaS ID, cell ID and network ID of node2 1030 indicated in response message 1004 are different from what node1 provided in the interface setup or update request message 1002, then node1 1020 may take this difference into account and use the IDs (e.g., XaaS ID, cell ID and network ID) that are overlapped. For example, Node 1 1020 having knowledge of the difference in IDs (e.g., XaaS ID, cell ID and network ID) may then use or select IDs that are overlapped, e.g., to perform UE access control, and resource scheduling.In some aspects, after receiving the interface setup or update request message 1002, if node2 1030 determines that its capability does not overlap with that of node1 (e.g., , does not support the XaaS service identified by the XaaS ID, Cell ID and network ID indicated in the request message 1002) , then node2 1030 may send an interface setup failure message to notify node 1 1020 of the failure of the setup of the interface.The procedure 1000 relating to the interface setup or the update procedure, may align the XaaS service capability between the first node1 1020 and the second node2 1030. The procedure 1000 may be helpful for mutual node selection in the follow up procedures  e.g., the UE initial access procedure for the XaaS service, and the UE XaaS bearer setup procedure, based on the supported capability.FIG. 11 illustrates a procedure 1100 for notifying a UE of a support XaaS service, according to an aspect. Procedure 1100 may relate to a network notifying a UE of a supported XaaS service to enable the UE to access the suitable network for the XaaS service. The procedure 1100 may comprise a network node (e.g., a DU) sending to a UE 1120 a message 1102 indicating one or more supported XaaS services. In some aspects, the message 1102 may be a unicast message (a dedicated radio resource control (RRC) message, a dedicated XaaS signaling message) or a multicast / broadcast message (e.g., a system information (SI) message such as a system information block1 (SIB1) or other SIBs) . In some aspects, the message 1102 may include one or more of: a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . In some aspects, the message 1102 may indicate that the XaaS service identified by the XaaS ID is supported and can be accessed via the network identified by the network ID and the cell identified by the cell ID. In some aspects, the message 1102 may further include a list of one or more of: cell IDs, XaaS IDs and network IDs. In some aspects, the cell ID, XaaS ID and network ID included may be aligned among a DU, a PF unit, an XC unit and a CU according to operations described in reference to FIG. 10.In some aspects, the procedure 1100 may further include, after receiving the message 1102, the UE 1130 selecting a suitable cell and a network to access for a an XaaS service. In some aspects, the UE 1120 may report the selected XaaS ID and the network ID to the network 1130 to request 1104 for an XaaS, e.g., via a RRC setup complete message. The UE 1120 may send the request 1104 to the network 1130, the request comprising the selected XaaS ID and network ID. In some aspects, the UE 1120 may select a suitable cell and a network to access an XaaS services based on information locally preconfigured and stored at the UE 1120. For example, information on which XaaS service can be received via which network (e.g., allowed XaaS service and network) may be locally preconfigured and stored at the UE 1120, e.g., as subscription information. In some aspects, for data processing and data forwarding, the UE side may be also configured with a UE route selection policy (URSP) related to an XaaS ID.FIG. 12 illustrates a deployment of a PF unit, according to an aspect. FIG. 12 may be similar to FIG. 5, however, one or more functions of the PDCP sublayer 1203, e.g., functions relating to Robust Header Compression (ROHC) 1204, may be performed at the CU 1230. FIG. 12 further illustrates another deployment of T1-U interface (between a DU  1220 and a PF unit 1200) and a T2-U interface (between the PF unit 1200 and the CU 1230) . In some aspects, the PF unit 1200 of an XaaS module may be deployed between the DU 1220 and the CU 1230, such that one or more functions of the PDCP sublayer, including functions related to XaaS bearer may be distributed, shared or divided between the PF unit 1200 and the CU 1230.According to an aspect, one or more functions of a PDCP sublayer may be performed at the CU 1230. For example, the CU 1200 may perform one or both of header (de) compression and sequence numbering of the PDCP SDU.According to an aspect, one or more functions of a PDCP sublayer may be performed at the PF unit 1200. For example, the PF unit 1200 may perform security protection (for XaaS bearer) e.g., integrity protection and ciphering. In some aspects, an integrity protection functionality and a ciphering functionality can be configurable for each XaaS bearer.In some aspects, the distribution of PDCP functions between the PF unit 1200 and the CU 1230 may be transparent to the UE 1210 and, thus, not affect the UE 1210.Similar to FIG. 5, Fig. 12, at PF unit 1200, a PF sublayer 1203 may be deployed on top of the PDCP sublayer 1203. Correspondingly, at the UE 1210, a PF sublayer 512 may be deployed between the SDAP sublayer 1211 and PDCP sublayer 1213.FIG. 13 illustrates an involvement of multiple PF units in providing an XaaS service to a UE 1310, according to an aspect. As illustrated in FIG. 13, multiple PF units (e.g., PF 1304, 1306, 1308) may be involved in providing an XaaS service to the UE 1310. In some aspects, the data processing routine (e.g., XaaS session) may go through the UE 1310, the DU 1320, PF units 1304 and 1308, the CU 1330 and the CN 1340 in sequence or in parallel. According to an aspect, an XaaS traffic path may include a plurality of PFs (PF 1304 and PF 1308) within the RAN 1300.FIG. 14 illustrates deployment of multiple PF units, according to an aspect. FIG. 14 further illustrates a protocol structure for the T1-U 1441 interface, the T4 1443 interface, and the T2-U 1442 interface when multiple PF units (PF unit 1400 and PF unit 1450) may be involved.In some aspects, PF unit1 1400 and PF unit2 1450 may be deployed between the DU 1220 and the CU 1430. The PF unit1 1400 may comprise a PF sublayer 1402 corresponding to a PF sublayer 1412 of a UE 1410. The PF unit1 1400 may further comprise  a PF sublayer 1452 corresponding to the PF sublayer 1462 of the PF unit2 1460. The PF unit1 1400 may further comprise a PDCP sublayer 1403 corresponding to the PDCP sublayer 1413 of the UE 1410. In some aspects, the PF unit1 1400 may further comprise a PDCP sublayer 1453 corresponding to a PDCP sublayer 1463 of PF unit2 1460.The PF unit1 1400 may interface with the DU 1220 via the T1-U 1441 interface. In some aspect, the PF unit1 1400 may have a protocol structure for the T1-U 1441 interface comprising a GTP-U sublayer 1404, a UDP sublayer 1405, and an IP sublayer 1406. The DU 1220 may have a corresponding protocol structure for a T1-U 1441 interface comprising a GTP-U sublayer 1424, a UDP sublayer 1425, and an IP sublayer 1426. The underlay protocol stacks of T1-U interface 1441 can be but not limited to that in FIG. 14, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .In some aspects, the PF unit1 1400 may interface with the PF unit2 1460 via the T4 1443 interface. The PF unit1 1400 may have a protocol structure, for the T4 1443 interface, comprising a GTP-U sublayer 1454, a UDP sublayer 1455, and an IP sublayer 1456. In some aspects, the PF unit2 1460 may have a corresponding protocol structure for the T4 1443 interface comprising a GTP-U sublayer 1464, a UDP sublayer 1465, and an IP sublayer 1466. The underlay protocol stacks of T4 interface 1443 can be but not limited to that in FIG. 14, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .In some aspects, PF unit2 1460 may have a protocol structure for a T2-U 1442 interface comprising a GTP-U sublayer 1467, a UDP sublayer 1468, and an IP sublayer 1469. In some aspects, the CU 140 may have a corresponding protocol structure for the T2-U 1442 interface comprising a GTP-U sublayer 1537, a UDP sublayer 1538, and a IP sublayer 1539. The underlay protocol stacks of T2-U interface 1442 can be but not limited to that in FIG. 14, e.g., the underlay protocol stacks can be one or more of: GPRS Tunneling Protocol for the user plane (GTP-U) , User Datagram Protocol (UDP) , Internet Protocol (IP) , Quick UDP Internet Connections (QUIC) , Hypertext Transfer Protocol (HTTP) , Stream Control Transmission Protocol (SCTP) , and Segment Routing over IPv6 (SRv6) .According to an aspect, the TNL may be based on IP transport, comprising the UDP and GTP-U layer on top of IP as illustrated. In some aspects, the TNL can be based on other protocols, for example, based on an IP transport, comprising the QUIC or SRv6 on top of IP.In some aspects, the involved nodes (e.g., the PF units 1400 and 1460, the DU 1220, the CU 1430, and the UE1410) can be selected and configured by the control plane (e.g., by an XC unit, a CU function or a CN function) , and tunnels (e.g., GTP-U tunnels, QUIC connections, SRv6 connections) between the involved nodes can be configured by the control plane (e.g., the XC unit, the CU function or the CN function) , e.g., when an XaaS Bearer or an XaaS Session is being established. In some aspects, one or both of the XaaS Bearer and the XaaS Session may go through one or more intra-RAN and inter-RAN nodes, which may cooperate to process the XaaS data in sequence or parallel.In some aspects, the involved PF units 1400 and 1460 can be dynamically selected and the data processing routine can be dynamically decided based on routing information included in, e.g., a header of a PF packet. Routing schemes (e.g., SRv6) and algorithms included in the routing information may vary as may be appreciated by a person skilled in the art. For example, one PF unit may determine the next hop to another PF unit based on the routing information included in the header of a received PF packet.In some aspects, both the PDCP sublayer and the PF sublayer may be deployed in one or more PF units of an XaaS module as illustrated in FIGs. 5, 12 and 14. In some aspects the PF sublayers may perform privacy protection with ciphering. In some aspects, the PDCP sublayer may perform security protection with ciphering. In some aspects, data ciphering (for privacy protection) may be already executed in the PF sublayer for XaaS data, e.g., the data may be encrypted with homomorphic encryption by the PF sublayer in FL learning (i.e., NET4AI service) . In some aspects, if the security level requirement is already met via the homomorphic encryption scheme, the PDCP layer may not need to perform further security protection (e.g., traditional 5G AS ciphering scheme) . According to an aspect, the security mode, referring to security and privacy protection, may be aligned and negotiated between the PF sublayer and the PDCP sublayer. According to an aspect, the security mode may indicate protection (security and privacy as the case may be) operations performed at none, one, or more than one of: the PDCP sublayer and the PF sublayer.The Security mode may indicate what security protection and privacy protection may be required. In some aspects, the security mode may indicate privacy protection on data processing. In some aspects, the security mode may indicate security protection on data forwarding. In some aspects, the security mode may indicate both privacy protection on data processing and security protection on data forwarding. In some aspects, the security mode may indicate that neither the privacy protection on data processing nor the security protection on data forwarding may be executed for an XaaS. In some aspects, the security mode may indicate the algorithm according to which the security protection and / or the privacy protection may be executed.In some aspects, an AS security mode may indicate what security and privacy protection may be required on one or both of the UP and the CP. In some aspects, the AS security mode may indicate that the PDCP sublayer (e.g., for ciphering and integrity) should execute security protection for an XaaS on the UP. In some aspects, the AS security mode may indicate that the PF sublayer should execute privacy protection for the XaaS on the UP. In some aspects, the AS security mode may indicate that both the PDCP sublayer should execute security protection and the PF sublayer should execute privacy protection for the XaaS on the UP. In some aspects, the AS security mode may indicate that none of the PDCP sublayer and the PF sublayer should execute security protection or privacy protection for the XaaS on the UP.In some aspects, the AS security mode may indicate that the PDCP sublayer (e.g., for ciphering and integrity) should execute security protection for the XaaS on the CP. In some aspects, the AS security mode may indicate that the XC sublayer (e.g., for privacy protection) should execute privacy protection for the XaaS on the CP. In some aspects, the AS security mode may indicate that both the PDCP sublayer should execute security protection and the XC sublayer should execute privacy protection for the XaaS on the CP. In some aspects, the AS security mode may indicate that none of the PDCP sublayer and the XC sublayer should execute security protection or privacy protection for the XaaS on the CP.In some aspects, the AS security mode may further indicate one or more algorithms according to which the AS security protection and / or AS privacy protection may be executed. The one or more security algorithms include, for example, ciphering algorithms and integrity algorithms on the PDCP sublayers, privacy protection algorithms on the PF sublayer, and privacy protection algorithms on the XC sublayer. As an example, an AS security mode may indicate that both the PDCP sublayer should execute security protection  and the PF sublayer should execute privacy protection on the XaaS UP, and the AS security mode may further indicate a first algorithm for executing a ciphering and integrity protection and a second algorithm for executing privacy protection. According to the AS security mode, the PDCP sublayer may execute ciphering and integrity protection according to the first algorithm, and the PF sublayer may execute privacy protection according to the second algorithm.A non-access stratum (NAS) security mode may indicate what security protection and / or privacy protection on XaaS NAS traffic is required for one or both of data forwarding and data processing. In some aspects, the NAS security mode may indicate that security protection for data forwarding on the XaaS NAS traffic (e.g., one or both of NAS signalling and NAS UP traffic) should be executed. In some aspects, the NAS security mode may indicate that security protection for data processing on the XaaS NAS traffic should be executed. In some aspects, the NAS security mode may indicate that both security protection for data forwarding on the XaaS NAS traffic and security protection for data processing on the XaaS NAS traffic should be executed. In some aspects, the NAS security mode may indicate that neither the security protection for data forwarding on the XaaS NAS traffic nor the security protection for data processing on the XaaS NAS traffic should be executed.In some aspect, the NAS security mode may further indicate one or more security algorithms according to which NAS security protection and / or privacy protection may be executed. In some aspects the one or more algorithms may include e.g., ciphering algorithms and integrity algorithms on one or both of the NAS signalling and the NAS UP traffic, and privacy protection algorithms on one or both of the NAS signalling and the NAS UP traffic.In some aspects, the supported AS Security Mode (s) may be preconfigured at one or more of: a UE or a network node (e.g., CN node, RAN node (e.g., PF unit, XC unit, CU) ) . According to an aspect, a suitable AS Security Mode may be selected or determined by the UE or the network from a list of supported AS securities, e.g., when setting up an XaaS.FIG. 15 illustrates an example table of supported AS security modes, according to an aspect. In some aspects, the table 1500 may be a preconfigured at a node. The supported AS security mode may comprise a first list of supported security modes, e.g., for a first XaaS QoS requirement of an XaaS. The first list of supported security modes may include a first mode, mode 1, indicating a need for security protection for data forwarding (e.g., ciphering and integrity protection in the PDCP sublayer) according to, e.g., algorithm 1.1. The first  mode may further indicate a need for privacy protection for data processing (e.g., privacy protection in PF sublayer) according to, e.g., algorithm 1.2.In some aspects, the first list of supported security modes may further include a second mode, mode 2, indicating a need for security protection for data forwarding (e.g., ciphering and integrity protection in the PDCP sublayer) according to, e.g., algorithm 2.1. The second mode, of the first list of supported security mode, may further indicate a need for privacy protection for data processing (e.g., privacy protection in the PF sublayer) according to, e.g., algorithm 2.2. The first list of supported security modes may further include other modes of security as may be appreciated by a person skilled in the art.The supported AS security mode may further comprise a second list of supported security modes, e.g., for a second XaaS QoS requirement of an XaaS. The second list of supported security modes may include a third mode, mode 3, indicating a need for security protection for data forwarding (e.g., ciphering and integrity protection in the PDCP sublayer) according to, e.g., algorithm 3.1. In some aspects, the third mode may not require a privacy protection for data processing (e.g., privacy protection in PF sublayer) .In some aspects, the second list of supported security modes may further include a fourth mode, mode 4, indicating a need for security protection for data forwarding (e.g., ciphering and integrity protection in a PDCP sublayer) according to algorithm 4.1. In some aspects, the fourth mode may not require a privacy protection for data processing (e.g., privacy protection in the PF sublayer) . The second list of supported security modes may further include other modes of security as may be appreciated by a person skilled in the art.The supported AS security mode may further comprise a third list of supported security modes, e.g., for a third XaaS QoS requirement of an XaaS. The third list of supported security modes may include a fifth mode, mode 5, indicating a need for privacy protection for data processing (e.g., privacy protection in the PF sublayer) according to, e.g., algorithm 5. The fifth mode may not require a security protection for data forwarding (e.g., ciphering and integrity protection in the PDCP sublayer) .The supported AS security mode may further comprise a fourth list of supported security modes, e.g., for a fourth XaaS QoS requirement of an XaaS. The fourth list of supported security modes may include a sixth mode, mode 6, indicating that no security protection for data forwarding nor privacy protection for data processing may be needed. Accordingly, the sixth mode may indicate that neither security protection for data forwarding  (e.g., ciphering and integrity protection in the PDCP sublayer) nor privacy protection for data processing (e.g., privacy protection in the PF sublayer) may be needed.In some aspects, a mode priority may be included or assigned for each mode of the AS security modes in table 1500.In some aspects, two or more nodes (e.g., UE, PF unit, XC unit, CU and CN) may communicate and align their supported AS security modes, e.g., before setting up an XaaS. In some aspects, the one or more nodes involved in the XaaS may be preconfigured with supported AS security modes to improve the alignment and negotiation procedures for determining or selecting AS security modes, e.g., when setting up the XaaS service. In some aspects, different security modes may have different priorities for use.According to an aspect, two or more nodes (e.g., a UE and a CN PF unit) may be preconfigured, for each supported AS security mode, with one or more of supported NAS security protection for data forwarding and data processing on XaaS NAS traffic (e.g., one or both of NAS signalling and NAS UP traffic) involving the two or more nodes.According to an aspect, a first list of support security modes, e.g., for a first XaaS QoS requirement of an XaaS, may include a first mode, mode 1. The first mode may indicate a need for security protection (e.g., one or more of ciphering and integrity protection) for data forwarding on XaaS NAS traffic (e.g., one or more of the NAS signalling and the NAS UP traffic) between e.g., the UE and the CN, according to e.g., algorithm 1.3. In some aspects, the first mode may further indicate a need for security protection for data processing (e.g., privacy protection) on the XaaS NAS traffic (e.g., one or more of the NAS signalling and the NAS UP traffic) between e.g., the UE and the CN, according to e.g., algorithm 1.4.According to an aspect, the first list of support security modes, e.g., for the first XaaS QoS requirement of an XaaS, may include a second mode, mode 2. The second mode may indicate a need for security protection for data processing (e.g., privacy protection) on XaaS NAS traffic (e.g., one or more of NAS signalling and NAS UP traffic) between e.g., the UE and the CN, according to e.g., algorithm 2.4. In some aspects, the second mode may not indicate or not require a need for security protection (e.g., ciphering or integrity protection) for data forwarding on the XaaS NAS traffic (e.g., the NAS signalling or the NAS UP traffic) between e.g., the UE and the CN.The first list of supported security modes may further include other modes of security protection for data forwarding and data processing as may be appreciated by a person  skilled in the art. In some aspects, a priority of NAS security mode may be included or assigned for each mode of the NAS security mode.The one or more security modes may be preconfigured at the UE and the network (e.g., CN, RAN (including XC, PF, XU, DU) ) , and based on the preconfigured security modes, the UE and the network can perform security mode alignment and selection. Accordingly, security protection and / or privacy protection for data forwarding and data processing on one or more of an XaaS XSB, XDB, and an XaaS NAS traffic can be executed.FIG. 16 illustrates a procedure for a joint security configuration based on preconfigured security modes, according to an aspect. Procedure 1600 may provide for selection of an AS Security Mode and a NAS Security Mode based on preconfigured Security Modes.In some aspects, the procedure 1600 may be for a joint PDCP sublayer and PF sublayer security configuration based on preconfigured Security Modes.According to an aspect, procedure 1600 may comprise preconfiguring 1602 one or more network nodes (UE 1630, CN 1650, RAN 1640 (including XC unit, PF unit, CU, DU) ) with a supported security mode (e.g., supported AS security mode, supported NAS security mode) , e.g., via a subscription or a network management procedure. For example, a UE may be preconfigured via a subscription, and the RAN node or a core network function may be preconfigured via the network management procedure.In some aspect, a supported security mode may indicate that privacy protection should be executed on data processing. In some aspects, the supported security mode may indicate that the security protection should be executed on data forwarding. In some aspects, the supported security mode may indicate that both privacy protection on the data processing and security protection on the data forwarding should be executed. In some aspects, the supported security mode may indicate that security protection and privacy protection should be executed on neither the data processing nor the data forwarding.In some aspects, the supported security mode may indicate one or more algorithms according to which security protection and / or privacy protection are to be executed.In some aspects, the procedure 1600 may further include a UE 1630 reporting its support security modes (e.g., supported AS security mode ID, supported NAS security mode  ID) 1604 to a CN 1650. The supported AS security modes and the supported NAS security modes may be identified with AS security mode IDs and NAS security mode IDs respectively.In some aspects, the procedure 1600 may further include the CN 1650 performing 1606 a NAS security mode selection. The selected NAS security mode may have an overlapped or a common security mode (i.e., supported by the UE 1630 and the CN 1650) . In some aspects, the selection may be based on one or more of: security mode priorities and an XaaS QoS requirement sent by the UE 1630 to CN 1650 before the NAS selection is performed 1606. According to an aspect, the CN 1650 may further generate NAS security parameter (s) (e.g., NAS security Key) for security algorithm (s) of the selected security mode. In some aspects, one or more security keys may refer to one or more of: a Key of privacy protection algorithm for privacy protection, and a Key of security protection algorithm for security protection.According to an aspect, the procedure 1600 may further include the CN 1650 sending a NAS security configuration to the UE e.g., via a NAS security mode command message 1608. In some aspects, the message 1608 may include one or more of: an ID of the selected NAS security mode and NAS security parameters.In some aspects, the procedure 1600 may further include the CN 1650 performing 1610 XaaS NAS traffic security protection. According to an aspect, the CN 1650 may begin performing one or more of: (an uplink) a downlink XaaS NAS traffic (De) ciphering on data forwarding and privacy-preserving computing on data processing based on the selected NAS security mode.In some aspects, the procedure 1600 may further include the UE 1630 performing 1612 XaaS NAS traffic security protection. According to an aspect, the UE 1630 may begin performing one or more of: (a downlink) an uplink XaaS NAS traffic (De) ciphering on data forwarding and privacy-preserving computing on data processing based on the selected NAS security mode.In some aspects, the procedure 1600 may further include the CN 1650 generating 1614 CN-assisted security information. In some aspects, the CN-assisted security information may include one or more of: CN-assisted information on AS security mode, and a CN-assisted security parameter.According to an aspect, the CN-assisted information on the AS security mode may help the RAN 1640 (e.g., CU and XC unit) to further decide the AS security mode. For  example, RAN 1640 may select an AS security mode based on or associated with a NAS security mode selected by NAS. In some aspects, the selected AS security mode may be supported by both the RAN 1640 and UE 1630.The assisted security parameters may be used by the RAN (e.g., CU and XC unit) to derive an AS security parameter (e.g., an AS security key) for the PF unit, including the PF sublayer and the PDCP sublayer. The CN-assisted security parameters may include one or more of: a security key Kx to be used by AS to derive the AS security parameter of PF sublayer (termed as the PF sublayer related security key) , and a security key Kc to be used by the AS to derive the AS security parameter of the PDCP sublayer (termed as the PDCP sublayer related security key) . In some aspects, Kx and Kc may be the same or different. As described herein, one or more security keys may refer to one or more of: a Key of privacy protection algorithm for privacy protection, and a Key of security protection algorithm for security protection.In some aspects, the procedure 1600 may further include the CN 1650 sending, to the RAN 1640, one or more of: UE’s AS supported security modes received previously (e.g., UE’s supported security mode 1604) and CN-assisted security information, e.g., via an initial UE context setup request or an XaaS PDU session setup request message 1616.In some aspects, procedure 1600 may further include the RAN 1640 performing 1618 an AS security mode selection. The selected AS security mode may be the overlapped security mode supported by the UE and the RAN. The selection may be based on one or more of: the security mode priorities, the CN-assisted security information, and an XaaS QoS requirement (s) sent by the UE or the CN to the RAN (e.g., one or more XaaS QoS requirements received by the RAN before the RAN performs 1618 the AS security mode selection) . In some aspects, the RAN 1640 may also perform a AS security parameter derivation (e.g., AS security Key) for one or more security algorithms of the selected security mode. In some aspects, one or more security keys may refer to one or more of: a Key of privacy protection algorithm for privacy protection, and a Key of security protection algorithm for security protection.In some aspects, the procedure 1600 may further include the RAN 1640 sending AS security configuration to the UE 1630 e.g., via an AS security mode command message 1620. In some aspects, the message 1620 may include one or more of: the selected AS security mode ID and AS security parameters.In some aspects, the procedure 1600 may further include the RAN 1640 performing 1622 one or more of: (an uplink) a downlink (De) ciphering on the PDCP sublayer, the PF sublayer or both sublayers of an XDB on the XaaS UP, based on the selected AS security mode. In some aspects, the RAN 1640 may perform one or more of: (an uplink) a downlink (De) ciphering on the PDCP sublayer, the XC sublayer or both sublayers of the XSB on the XaaS CP, based on the selected AS security mode.In some aspects, the procedure 1600 may further include the UE performing 1624 an XaaS AS UP traffic security protection. According to an aspect, the UE 1630 may perform one or more of: (a downlink) an uplink (De) ciphering on the PDCP sublayer, privacy-preserving computing on the PF sublayer or both (De) ciphering on the PDCP sublayer and privacy-preserving computing on the PF sublayer of the XDB on XaaS UP, based on the selected AS security mode.According to an aspect, the UE 1630 may perform an XaaS AS signalling security protection. the UE 1630 may perform one or more of: (a downlink) an uplink (De) ciphering on the PDCP sublayer, privacy-preserving computing on the XC sublayer or both (De) ciphering on the PDCP sublayer and privacy-preserving computing on the XC sublayer of an XSB on the XaaS CP, based on the selected AS security mode.In some aspects, the security protection for one or more of: a NAS traffic, an XDB and an XSB may not start right away at one or more of: the CN, the RAN and the UE when sending or receiving the security mode command messages. In some aspects, the security protection may be activated, e.g., after the RAN and the CN send an activation indication, to the UE, for the one or more of NAS traffic, XDB and XSB.In some aspects, when one or more nodes (e.g., the UE, the CN and the RAN) are preconfigured with a supported Security Mode, the supported security algorithm for data processing of the XaaS and the supported security algorithm for data forwarding of the XaaS may be naturally mapped and bound together.According to an aspect, security mode selection may be performed according to another method or procedure, where the supported privacy algorithm for data processing of the XaaS and the supported security algorithm for data forwarding of the XaaS may be preconfigured independently. In some aspects, the supported privacy algorithm for data processing of the XaaS and the supported security algorithm for data forwarding of the XaaS may be preconfigured as independent security capabilities.In some aspects, the UE may be configured, e.g., via a UE subscription, with one or more lists of supported security capabilities (e.g., security algorithms and / or privacy algorithms) , which may be used for data processing and data forwarding. In some aspects, the one or more lists may include a separate or different list of supported security capabilities corresponding for each of the data processing and the data forwarding. In some aspects, the one or more lists may be ordered according to a priority decided by an operator.In some aspects, one or more network nodes (the CN, the RAN (including an XC unit, a PF unit, a CU and a DU) ) may further be configured, e.g., via network management, with one or more lists of supported security capabilities (e.g., security algorithms and / or privacy algorithms) which may be used for data processing and data forwarding. In some aspects, the one or more lists may include a first set of lists of supported security capability for data processing and a second set of lists for data forwarding. In some aspects, the one or more lists may be ordered according to a priority decided by an operator.According to an aspect, the UE’s supported security capability may include supported security capability on data processing of the XaaS (e.g., supported privacy protection algorithms which can be used for one or more of: the PF sublayer and the XaaS NAS traffic (e.g., the NAS signalling and / or the NAS UP traffic) between the UE and the CN) . The UE’s supported security capability may further include the UE’s supported security capability on data forwarding of the XaaS (e.g., supported ciphering algorithms and integrity protection algorithm which can be used for one or more of: the PDCP sublayer and the XaaS NAS traffic (e.g., NAS signalling and / or NAS UP traffic) between the UE and the CN) . The UE’s supported security capability may further include a priority of the different algorithms which may be used for data processing and data forwarding.According to an aspect, based on preconfigured security capabilities, the UE 1730 and a network (e.g., CN 1750, RAN 1740 (including XC unit, PF unit, CU, DU) ) can perform security capability alignment and security mode selection. The UE and the network may further execute the security protection for data forwarding and data processing on the XaaS XSB, the XDB, or XaaS NAS traffic.As illustrated in FIG. 17, AS Security Mode and NAS Security Mode selection may be determined based on the preconfigured Security Capabilities, according to an aspect.FIG. 17 illustrates a procedure for joint security configuration based on a preconfigured security capability, according to an aspect. The procedure 1600 may provide for a joint PDCP sublayer and PF sublayer security configuration.According to an aspect, the procedure 1700 may comprise preconfiguring 1702 one or more network node (UE 1730, CN 1750, RAN 1740 (including XC unit, PF unit, CU, DU) ) , e.g., via a subscription or a network management procedure. The one or more network node may be preconfigured with one or more lists of supported security capabilities (i.e., supported security algorithms and / or privacy algorithms, and each security algorithm can be identified by a security algorithm ID, each privacy algorithm can be identified by a privacy algorithm ID) which may be used for data processing and data forwarding. In some aspects, the one or more lists may include a separate first set of lists for data processing, and a separate second set of lists for data forwarding. The one or more lists may be ordered according to a priority decided by the operator.According to an aspect, the procedure 1700 may further include the UE 1730 sending or reporting its supported security capabilities 1704 to the CN 1750.In some aspects, the procedure 1700 may further include the CN 1750 performing 1706 a NAS security mode selection. The selected NAS security mode may include one or more of: overlapped privacy algorithms supported by the UE and the CN on data processing, and security algorithms supported by the UE and the CN on data forwarding. In some aspects, the selection may be based on one or more of: a priority of the algorithm, and an XaaS QoS requirement sent by the UE to the CN e.g., before the CN selects the NAS security mode. In some aspects, the CN 1750 may generate one or more NAS security parameters (e.g., NAS security Key) for one or more algorithms of the selected security mode. In some aspects, one or more security keys may refer to one or more of: a Key of privacy protection algorithm for privacy protection, and a Key of security protection algorithm for security protection.In some aspects, if the selected NAS security mode indicates that the privacy protection on data processing or security protection on data forwarding is not needed, the corresponding algorithm may not be included.In some aspects, the procedure 1700 may further include the CN 1750 sending a NAS security configuration to the UE e.g., via a NAS security mode command message 1708. The message 1708 may include the selected one or more privacy algorithm and / or security algorithms on one or more of data processing and data forwarding. In some aspects, each  selected security algorithm may be identified by a security algorithm ID, and each selected privacy algorithm may be identified by a privacy algorithm ID. In some aspects, the one or more NAS security parameters may be also included in the message 1708.In some aspects, the procedure 1700 may further include the CN performing 1710 an XaaS NAS traffic security protection. According to an aspect, the CN 1750 may perform one or more of: (an uplink) a downlink XaaS NAS traffic (De) ciphering on data forwarding and privacy-preserving computing on data processing based on the selected NAS security and / or privacy algorithm.In some aspects, the procedure 1700 may further include the UE performing 1712 an XaaS NAS traffic security protection. According to an aspect, the UE 1730 may perform one or more of: (a downlink) an uplink XaaS NAS traffic (De) ciphering on data forwarding and privacy-preserving computing on data processing based on the selected NAS security and / or privacy algorithm.In some aspects, the procedure 1700 may further include the CN 1750 generating 1714 CN-assisted security information. In some aspects, the CN-assisted security information may include one or more of: CN-assisted information on an AS security mode, and a CN-assisted security parameter.According to an aspect, the CN-assisted information on the AS security mode may help the RAN (e.g., the CU and the XC unit) to further decide the AS security mode. The assisted security parameters may be used by the RAN (e.g., the CU and the XC unit) to derive the AS security parameter (e.g., an AS security key) for the PF unit including the PF sublayer and the PDCP sublayer. The CN-assisted security parameters may include one or more of: a security key Kx to be used by AS to derive the AS security parameter of PF sublayer (termed as the PF sublayer related security key) , and a security key Kc to be used by the AS to derive the AS security parameter of the PDCP sublayer (termed as the PDCP sublayer related security key) . In some aspects, Kx and Kc may be the same or different. In some aspects, one or more security keys may refer to one or more of: a Key of privacy protection algorithm for privacy protection, and a Key of security protection algorithm for security protection.In some aspects, the procedure 1700 may further include the CN 1750 sending one or more of: UE’s supported security capabilities 1704 received previously and CN-assisted security information to the RAN 1740, e.g., via an initial UE context setup request or an XaaS PDU session setup request message 1716.In some aspects, the procedure 1700 may further include the RAN 1740 performing 1718 a AS security mode selection. The selected AS security mode may include one or more of: the overlapped privacy algorithms supported by the UE and the CN on data processing, and the overlapped security algorithms supported by the UE and the CN on data forwarding. In some aspects, the selection may be based on one or more of: the algorithm priorities, and the XaaS QoS requirement sent by the UE to the CN (e.g., one or more XaaS QoS requirements received by the RAN before the RAN performs 1718 the AS security mode selection) . In some aspects, the RAN 1740 may also perform an AS security parameter derivation (e.g., an AS security Key) for the one or more security and / or privacy algorithms of the selected security mode. In some aspects, one or more security keys may refer to one or more of: a Key of privacy protection algorithm for privacy protection, and a Key of security protection algorithm for security protection.In some aspects, if the selected NAS security mode indicates that the privacy protection on data processing or security protection on data forwarding is not needed, the corresponding algorithm may not be included.In some aspects, the procedure 1700 may further include the RAN 1740 sending an AS security configuration to the UE e.g., via an AS security mode command message 1720. The message 1720 may include one or more of: the selected AS security algorithms on data processing and data forwarding. In some aspects, each selected AS security algorithm may be identified by a security algorithm ID. In some aspects, AS security parameters may be also included in the message 1720.In some aspects, the procedure 1700 may further include the RAN performing 1722 XaaS AS UP traffic security protection. According to an aspect, the RAN 1740 may perform one or more of: (an uplink) a downlink (De) ciphering on PDCP sublayer, privacy-preserving computing on the PF sublayer or both (De) ciphering on the PDCP sublayer and privacy-preserving computing on the PF sublayer of the XDB on the XaaS UP, based on the selected AS security and / or privacy algorithm.In some aspects, the RAN 1740 may perform an XaaS AS signalling security protection. The RAN 1740 may perform one or more of: (an uplink) a downlink (De) ciphering on the PDCP sublayer, privacy-preserving computing on the XC sublayer or both (De) ciphering on the PDCP sublayer and privacy-preserving computing on the XC  sublayer of the XSB on the XaaS CP, based on the selected AS security and / or privacy algorithm.In some aspects, the procedure 1700 may further include the UE performing 1724 XaaS AS UP traffic security protection. According to an aspect, the UE 1730 may perform one or more of: (a downlink) an uplink (De) ciphering on the PDCP sublayer, privacy-preserving computing on the PF sublayer or both (De) ciphering on the PDCP sublayer and privacy-preserving computing on the PF sublayer of the XDB on the XaaS UP, based on the selected AS security and / or privacy algorithm.In some aspects, the UE 1730 may further perform XaaS AS signalling security protection. The UE 1730 may perform one or more of: (a downlink) an uplink (De) ciphering on the PDCP sublayer, privacy-preserving computing on the XC sublayer or both (De) ciphering on the PDCP sublayer and privacy-preserving computing on the XC sublayer of the XSB on the XaaS CP, based on the selected AS security and / or privacy algorithm.In some aspects, the security protection for one or more of: a NAS traffic, an XDB and an XSB may not start right away at one or more of: the CN, the RAN and the UE when sending or receiving the security mode command messages. In some aspects, the security protection may be activated, e.g., after the RAN and the CN send an activation indication, to the UE, for the one or more of the NAS traffic, the XDB and the XSB.Some aspects of the disclosure may provide for interface management for a split RAN architecture. Some aspects of the disclosure may provide for establishment of one or more of: an XaaS session and an XaaS bearer. Some aspects of the disclosure may provide for a scheme for security and privacy protection scheme.As described in reference to FIG. 9, one or more nodes (e.g., UE, DU, CU, XC unit and PF unit) may provide or support different XaaS services to a service customer. In some aspects, each XaaS service (e.g., NET4AI service, DAM service) may be identified with an XaaS ID. In some aspects, different nodes may provide XaaS services via different networks to the UE, each network can be identified with a Public Land Mobile Network (PLMN) ID, or a Non-Public Network (NPN) ID.In an aspect, each node of a plurality of nodes may align with and communicate to other nodes of the plurality of nodes, the nodes capabilities on an XaaS service being supported via an interface management procedure. The alignment and communication of the nodes’ supported capability may allow for mutual mode selection, among the plurality of  nodes, in one or more follow up procedures e.g., a UE initial access procedure for the XaaS service, and a UE XaaS bearer establishment procedure, based on the supported capability.FIG. 18 illustrates an interface management procedure 1800 for a split RAN, according to an aspect. The procedure 1800 may provide for a workflow of T1, T2, and T3 interface management and for network notification to a UE.According to an aspect, the procedure 1800 may include one or more PF units 1844 sending a T3 setup request message 1802 to an XC unit 1846 to setup a T3 interface. In some aspects, the T3 setup request message 1802 may include one or more of: a PF unit ID, an XaaS ID, a network ID (e.g., PLMN ID, NPN ID) . In some aspects, the T3 setup request message 1802 may indicate that the PF unit identified by the PF unit ID supports the XaaS service identified by the XaaS ID via the network identified by the network ID. In some aspects, the T3 setup request message may further include a list of XaaS IDs and network IDs.In some aspects, the procedure 1800 may further include an XC unit 1846 sending a T3 setup response message 1804 to the one or more PF units 1844 to notify the successful setup of the T3 interface. In some aspects, the T3 setup response message 1804 may include one or more of: an XC unit ID, an XaaS ID, a network ID (e.g., PLMN ID, NPN ID) . In some aspects, the T3 setup response message 1804 may indicate that the XC unit identified by the XC unit ID supports the XaaS service identified by the XaaS ID via the network identified by the network ID. In some aspects, the T3 setup response message 1804 may further include a list of XaaS IDs and network IDs. In some aspects, the XaaS ID and network ID included in the T3 setup response message 1804 may overlap or be common with the XaaS ID and network ID indicated in the T3 setup request message 1802 of the one or more PF units 1844. Accordingly, the overlapped XaaS ID and network ID may indicate an XaaS that is supported by the one or more PF units 1844 and the XC unit 1846.In some aspects, if the XaaS ID and network ID in the T3 setup response message 1804 are different from those that the one or more PF unit 1844 has provided in T3 setup request message 1802, then the one or more PF units 1844 may take such difference into account and may use those IDs (e.g., XaaS ID (s) and network ID (s) ) that are overlapped.In some aspects, after receiving the T3 setup request message 1802, if the XC unit 1846 determines that it has no overlapped capability with the one or more PF units 1844 (i.e., does not support an XaaS indicated by T3 setup request message 1802) , then the XC unit  1846 may send a T3 setup failure message to notify the one or more PF units of the failure of the setup of the T3 interface.In an aspect, the T3 setup procedure may align the XC unit’s capability on the XaaS service with the one or more PF unit’s capability on the XaaS service. Such alignment of the XaaS service capability may be helpful for mutual selection (by the PF unit and the XC unit) in the follow up procedures, e.g., a UE initial access procedure for the XaaS service, and a UE XaaS bearer setup procedure, based on the commonly supported capability.In some aspects, the procedure 1800 may further include the XC unit 1846 sending a T2 setup request message 1806 to a CU 1848 to setup a T2 interface. The T2 setup request message 1806 may include one or more of: an XC unit ID, an XaaS ID, a network ID (e.g., PLMN ID, NPN ID) . The T2 setup request message 1806 may indicate that the XC unit identified by the XC unit ID supports the XaaS service identified by the XaaS ID via the network identified by the network ID. The T2 setup request message 1806 may further include one or more lists of XaaS IDs and network IDs. The included one or more lists of XaaS IDs and Network IDs may be supported by the XC unit and one or more of the PF units connected to the XC unit.In some aspects, the procedure 1800 may further include a CU 1848 sending a T2 setup response message 1808 to the XC unit 1846 to notify the successful setup of the T2 interface. The T2 setup response message 1808 may include one or more of: a CU ID, an XaaS ID, a network ID (e.g., PLMN ID, NPN ID) . The T2 setup response message 1808 may indicate that the CU identified by the CU ID supports the XaaS service identified by the XaaS ID via the network identified by the network ID. The T2 setup response message 1808 can include one or more lists of XaaS IDs and network IDs supported by CU. The one or more XaaS ID and network ID included in the T2 setup response message may overlap with one or more XaaS ID and network ID supported by XC 1846 (i.e., included in the T2 setup request message 1806) . If the XaaS ID and the network ID included in the T2 setup response message 1808 are different from those provided by the XC unit 1846 in the T2 setup request message 1806, then the XC unit 1846 may take this difference into account and use those IDs (e.g., XaaS ID and network ID) that overlap.In some aspects, after receiving the T2 setup request message 1806, if the CU 1848 determines that it has no overlapped capability with the XC unit 1846, the CU 1848  may send a T2 setup failure message to notify the XC unit 1846 of the failure of the setup of T2 interface.According to an aspect, the T2 setup procedure may align the capability on the XaaS service of the XC unit and the CU, which may be helpful for mutual selection (by the CU unit and the XC unit) in the follow up procedures e.g., a UE initial access procedure for the XaaS service, and a UE XaaS bearer setup procedure, based on the supported capability.In some aspects, the procedure 1800 may involve two modes for T1-C and T1-U interface management. In some aspects, for the T1-C interface setup, the XC unit 1846 and one or more DUs 1842 may setup a connection on the user plane (T1-U interface) under the control of the CU 1848. In some aspects, for the T1-U interface setup or the XaaS bearer management on the T1-U, one or more DUs 1842 (under the control of CU 1848) and one or more PF units 1844 (under the control of XC unit 1846) may setup user plane (T1-U interface) connections, during which the XC unit and the CU may interact with each other to transfer necessary information. For example, one or more DUs 1842 may be under the control of the CU 1848 to setup user plane (T1-U interface) connections with one or more PF units 1844, and the one or more PF units may be under the control of the XC unit 1846 to setup user plane (T1-U interface) connections with the one or more DUs 1842, and the CU 1848 and the XC unit 1846 may interact with each other to transfer necessary information between the one or more DUs 1842 and the one or more PF units 1844.According to a first mode, mode 1, one or more DUs may interact with CU directly on the control plane via F1 interface.According to an aspect, the procedure 1800 may further include, in mode 1, one or more DUs sending an F1 setup request message 1810 to the CU to setup an F1 interface. The F1 setup request message 1810 may include one or more of: a DU ID, a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . The F1 setup request message 1810 may indicate that the DU identified by the DU ID supports the XaaS service identified by the XaaS ID via the network identified by the network ID and the cell identified by the cell ID. The F1 setup request message 1810 may further include a list of cell IDs, XaaS IDs and network IDs.According to an aspect, the procedure 1800 may further include, in mode 1, the CU 1848 sending an F1 setup response message 1812 to the one or more DUs 1842 to notify the successful setup of the F1 interface. The F1 setup response message 1812 may include  one or more of: a CU ID, a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . The F1 setup response message 1812 may indicate that the CU identified by the CU ID supports the XaaS service identified by the XaaS ID via the network identified by the network ID and the cell identified by the cell ID. The F1 setup response message 1812 can further include one or more lists of: cell IDs, XaaS IDs and network IDs supported by the CU. The cell ID, the XaaS ID and the network ID included in the F1 setup response message 1812 may overlap with those supported at the one or more DUs (i.e., included in the F1 setup request message 1810) . In some aspects, if the XaaS ID and network ID are different from what the one or more DUs provided in the F1 setup request message 1810, the CU 1848 may take the difference into account and use those overlapped cell IDs, XaaS IDs and network IDs.In some aspects, after receiving the F1 setup request message 1810, if the CU 1848 determines that it has no overlapped capability with the one or more DUs, the CU 1848 may send an F1 setup failure message to notify the one or more DUs of the failure of the setup of the F1 interface.In some aspects, the F1 setup procedure may align the one or more DUs’ capability on an XaaS service with the CU’s capability on the XaaS service, which may be helpful for mutual selection (e.g., mutual node selection) by the CU and the one or more DUs, in follow up procedures e.g., a UE initial access procedure for the XaaS service, and a UE XaaS bearer setup procedure, based on the supported capability.According to an aspect, in a second mode, mode 2, the one or more DUs 1842 may interact with the XC unit 1846 on the CP via a T1-C interface as described herein.In some aspect, the procedure 1800 may involve a T1-U interface setup or an XaaS bearer management on T1-U, where the one or more DUs 1842 and the one or more PFs 1844 may setup a user plane (T1-U interface) connection under single control of the XC unit or the CU. For example, one of XC unit 1846 or CU 1848 may control the one or more DUs 1842 and the one or more PF units 1844 to setup of user plane (T1-U interface) connection.According to an aspect, the procedure 1800 may further include, in mode 2, the one or more DUs 1842 sending a T1 setup request message 1814 to the XC unit 1846 to setup the T1 interface. The T1 setup request message 1814 may include one or more of: a DU ID, a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . The T1 setup request message 1814 may indicate that the DU identified by the DU ID supports the XaaS service  identified by the XaaS ID via the network identified by the network ID and the cell identified by the cell ID. In some aspects, the T1 setup request message 1814 can further include a list of cell IDs, XaaS IDs and network IDs.In some aspect, the procedure 1800 may further include, in mode 2, the XC unit 1846 sending a T1 setup response message 1816 to the one or more DUs 1842 to notify the successful setup of the T1 interface. The T1 setup response message 1816 may include one or more of: an XC ID, a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . In some aspects, the T1 setup response message 1816 may indicate that the XC identified by the XC ID supports the XaaS service identified by the XaaS ID via the network identified by the network ID and the cell identified by the cell ID.In some aspects, the T1 setup response message 1816 may include one or more lists of cell IDs, XaaS IDs and network IDs supported at the XC unit 1846. In some aspects, one or more of a cell ID, an XaaS ID and a network ID included in the T1 setup response message 1816 may overlap with those supported at the one or more DUs (i.e., included in the T1 setup request message 1816) .In some aspects, if the XaaS ID and the network ID received by the one or more DUs are different from what the one or more DUs 1842 provided in T1 setup request message 1814, the one or more DUs 1842 may take such difference into account and use those overlapped IDs (e.g., XaaS ID and network IDs provided in T1 setup response message 1816) .In some aspects, after receiving the T1 setup request message 1814, if the XC unit 1846 determines that it has no overlapped capability with the one or more DUs 1842, then the XC unit 1846 may notify the one or more DUs 1842 of the failure of the setup of T1 interface, e.g., via a T1 setup failure message.According to an aspect, the T1 setup procedure may align the capability on an XaaS service of the one or more DUs and the XC unit, which may be helpful for mutual selection (by the XC unit and the one or more DUs) in the follow up procedures e.g., the UE initial access procedure for XaaS service, and the UE XaaS bearer setup procedure, based on the supported capability.In some aspects, the procedure 1800 may further include the one or more DUs 1842 sending a supported service message 1818 indicating the supported XaaS service to one or more UEs 1830. In some aspects the supported service message is sent via a unicast message (dedicated radio resource control (RRC) message) or multicast / broadcast message  (e.g., system information (SI) such as system information block 1 (SIB1) or other SIBs) . In some aspects, the unicast or multicast / broadcast message, as the case may be, may include one or more of: a cell ID, an XaaS ID, and a network ID (e.g., PLMN ID, NPN ID) . In some aspects, the unicast or multicast / broadcast message, as the case may be, may indicate that the XaaS service identified by the XaaS ID is supported and can be accessed via the network identified by the network ID and the cell identified by the cell ID. In some aspects, the unicast or multicast / broadcast message, as the case may be, can further include one or more lists of cell IDs, XaaS IDs and network IDs. The one or more cell ID, XaaS ID and network ID included may be those IDs aligned among the one or more DUs, the PF units, the XC unit and the CU as described herein.In some aspect, the procedure 1800 may further include, after receiving the message, the one or more UEs 1830 selecting a suitable cell and a network to access an XaaS service.In some aspects, the XaaS ID and network ID may be integrated together, e.g., the XaaS ID may include information related to network ID. In such cases, the network ID may be not sent when the XaaS ID is sent.In some aspects, the T3 setup procedure may be triggered by the XC unit 1846 sending a T3 setup request message, and then, the one or more PF units 1844 may send a T3 setup response message.In some aspects, the T2 setup procedure may be triggered by the CU 1848 sending a T2 setup request message, and then, the XC unit 1846 may send a T2 setup response message.In some aspects, the F1 setup procedure may be triggered by the CU 1848 sending an F1 setup request message, and then, the one or more DUs may send an F1 setup response message.In some aspects, the T1 setup procedure may be triggered by the XC unit 1846 sending a T1 setup request message, and then, the one or more DUs may send a T1 setup response message.In some aspects, a UE may select a suitable cell and a network to access or request an XaaS service. In some aspects, a UE may request an XaaS service after the procedure 1800. For example, a UE may request the RAN and CN for an XaaS service.According to an aspect, after receiving the request, the CN and the RAN may setup an XaaS session and an XaaS bearer, associated with the request XaaS service, to serve the UE. FIG. 19A and FIG. 19B illustrate a procedure for establishment of an XaaS session and an XaaS bearer, according to an aspect.According to an aspect, the procedure 1900 may include a UE 1930 sending an XaaS service request message 1901 to an XC unit 1946 to request for an XaaS service. In some aspects, the UE 1930 may refer to two or more UEs. In some aspects, the XaaS service request message 1901 may be sent, e.g., via a RRC message or a dedicated XaaS signalling message. The XaaS service request message 1901 may include one or more of: an XaaS session ID, an XaaS QoS flow ID, XaaS QoS requirement (e.g., a data forwarding parameter and a data processing parameter) . The XaaS QoS requirement can be indicated by one or more of slice ID, an XaaS ID, a network ID (e.g., PLMN ID, NPN ID) , a Cell ID, and a UE ID or a UE group ID.The XaaS session ID may identify the XaaS session via which the UE 1930 may receive the XaaS service. In some aspects, a range of session ID values (e.g., one or more session ID values) may be retained, at one or more participating entities (e.g., UE, network nodes and network function) to identify the XaaS session.The XaaS QoS flow ID may identify the XaaS QoS flow included in the XaaS session. A range of QoS flow ID values (e.g., one or more QoS flow ID values) may be retained, at one or more participating entities (e.g., UE, network nodes and network functions) to identify the XaaS QoS flow. In some aspects, a list of XaaS QoS flow IDs may be included in an XaaS service request message 1901.The XaaS QoS requirement (which may include one or more of: data forwarding parameters and data processing parameters) may indicate an XaaS service requirement e.g., on one or more of a data forwarding treatment parameter and a data processing treatment parameter. The XaaS QoS requirement can be indicated by a specific slice ID.The XaaS ID may identify the XaaS service required by the UE. The Network ID (e.g., PLMN ID, NPN ID) may identify the network selected by the UE via which it may receive the XaaS service. In some aspects, the information, e.g., the network ID, through which the XaaS service may be received may be locally preconfigured and stored at the UE, e.g., as subscription information.The cell ID may identify the selected cell by the UE via which it may receive the XaaS service. The UE ID or a UE group ID may identify, respectively, the UE or the UE group in which the UE is joining.In some aspects, the procedure 1900 may include, after receiving the XaaS service request 1901, the RAN (i.e., XC 1946) determining whether the requested XaaS service can be provided and completed by the RAN alone. In some aspects, if the XC 1946 determines that the RAN can provide the XaaS service on its own, then the XaaS session may be terminated at the RAN and the CN need not be involved, e.g., the XaaS bearer may be established.According to some aspect, the procedure 1900 may further include the XC unit 1946 sending an XaaS service request message 1903 to the CU 1948 to notify the CU of the UE’s request for the XaaS service. The XaaS service Request message 1903 may include one or more of: an XaaS session ID, an XaaS QoS flow ID, an XaaS QoS requirement, an XaaS ID, a network ID, a Cell ID, a UE ID or a UE group ID. In some aspects, before sending the XaaS service Request message 1903, the XC unit 1946 may select a suitable CU 1948 based on the UE’s requested XaaS service and the CU’s supported XaaS service. In some aspect, if the XC 1946 determines that the RAN can provide the XaaS service on its own, and the CN need not be involved, the XaaS service Request message 1903 may include an indication to indicate to CU that the CN need not be involved. After receiving the indication, the CU may not send further message to CN. That is, in aspects in which the CN may not be involved in providing XaaS service, the procedure 1900 may skip operations described in reference to 1904, 1905, 1906, and 1907 and continue at operations described in reference to 1908.In some aspects, if the RAN cannot provide the XaaS service on its own, e.g., the CN may need to be involved, the procedure 1900 may continue with operations described in reference to 1904.In some aspects, the procedure 1900 may further include the CU 1948 sending an XaaS service request message 1904 to the CN 1950 to notify the CN of the UE’s request for the XaaS service. The XaaS service request message 1904 may include one or more of: an XaaS session ID, an XaaS QoS flow ID, an XaaS QoS requirement, an XaaS ID, a network ID, a UE ID or a UE group ID.In some aspects, after receiving the XaaS service request message 1904, the CN 1950 may decide whether the UE 1930 is allowed to access the XaaS service e.g., based on  the UE’s request and the UE’s subscription information (e.g., allowed network, allowed XaaS service) stored at the CN 1950.In some aspects, the procedure 1900 may further include, after receiving the XaaS service request message 1904, the CN 1950 deciding 1905 whether the CN should be involved in the XaaS service. In some aspects, if the CN 1950 determines that it should be involved, the CN 1950 may setup the required XaaS session. In some aspects, the XaaS session may be terminated at a CN function (e.g., a CN PF unit) or a data network (DN) .In some aspects, the procedure 1900 may further include the CN 1950 sending an initial context setup request or an XaaS session setup request message 1906 to the RAN (e.g., CU 1948) to notify the RAN to setup the resource for the UE’s requested XaaS service.In some aspects, if the CN 1950 decides that the required XaaS service should be provided and completed by the RAN side and the CN together, the initial context setup request or the XaaS session setup request message 1906 may include one or more of: a UE ID or a UE group ID, an XaaS session ID, an XaaS QoS flow ID, an XaaS QoS requirement, and a node address to receive XaaS data (e.g., UP Transport Network Layer (TNL) information on the CN side) .In some aspects, the UE ID or the UE group ID, the XaaS session ID, the XaaS QoS flow ID, and the XaaS QoS requirement in the initial context setup request or the XaaS session setup request message 1906 may be the same as or align with operations described in reference to the XaaS service request message 1901, 1903, and 1904 to notify that the associated resource (s) are for setting up the XaaS service required by the UE or the UE group.In some aspects, the node address (e.g., UP Transport Network Layer (TNL) information) may be used by the RAN to forward the XaaS data to a CN node (e.g., CN PF unit) .In some aspects, if the CN 1950 decides that the required XaaS service should be provided and completed by the RAN side alone and the CN need not be involved, the initial context setup request or the XaaS session setup request message 1906 may include one or more of: a UE ID or a UE group ID, an XaaS session ID, an XaaS QoS flow ID, an XaaS QoS requirement, and an indication.In some aspects, the indication (e.g., a string, or a value 0) may notify the RAN that the required XaaS service may be provided and completed by the RAN side alone and the CN need not be involved. In some aspect, the indication indicating how the XaaS service  may be provided may be notified via default methods e.g., if the UP TNL information is not included in the message 1906, or the XaaS QoS requirement is included while the XaaS session ID and XaaS QoS flow ID are not included, the indication may imply or indicate that the required XaaS service may be provided and completed by the RAN side alone and the CN need not be involved.In some aspects, after receiving the initial context setup request or the XaaS session setup request message 1906, the SDAP sublayer of the CU 1948 may perform 1907 mapping between one or more XaaS QoS flows and one or more XaaS bearers. As described in reference to FIG. 20 and FIG. 21, one XaaS QoS flow of an XaaS session may be mapped to one or more XaaS data Bearers e.g., by the SDAP sublayer, given or based on an XaaS QoS requirement (e.g., both data forwarding requirement and data processing requirement) . In some aspects, one XaaS Bearer may transfer data of one or multiple XaaS QoS flows from the same or different XaaS sessions.In some aspects, after receiving the initial context setup request or XaaS session setup request message 1906, a UP tunnel used by the RAN to transmit XaaS data to the CN may be established.In some aspects, the XaaS session establishment can be triggered by the UE performing operations described in reference to action 2001 in FIG. 20. In some aspects, the XaaS session establishment may be triggered by the CN 1950 performing operations described in reference to action 1906 (i.e., the CN 1950 sending the initial context setup request or XaaS session setup request message 1906.In some aspects, the procedure 1900 may further include the CU 1948 sending a UE bearer context setup request 1908 to the XC unit 1946 to notify the XC unit to setup the resource (s) for the UE’s requested XaaS service. The UE bearer context setup request 1908 may include one or more of: an XaaS Bearer ID, a mapped XaaS QoS flow ID, a mapped XaaS session ID, a UE ID or a UE group ID served by an XaaS bearer, an XaaS QoS requirement on the XaaS bearer or the XaaS QoS flow, and a node address on the CU side (e.g., T2-U TNL information on the CU side) . In some aspects, the UE Bearer context setup request 1908 may further include one or more lists of XaaS bearer IDs, mapped XaaS QoS flow IDs and mapped XaaS session IDs.The XaaS bearer ID may identify the XaaS bearer to be setup. The mapped XaaS QoS flow ID may identify the XaaS QoS flow mapped to the XaaS bearer. In some aspects,  the mapped XaaS session ID may identify the XaaS session mapped to the XaaS bearer, and the XaaS QoS flow identified by the XaaS QoS flow ID may belong to the XaaS session identified by the XaaS session ID.In some aspects, the UE ID or the UE group ID may identify the UE or the UEs served by the XaaS bearer. In some aspects, the XaaS QoS requirement on the XaaS bearer or XaaS QoS flow may indicate, respectively, the XaaS QoS requirement on the XaaS bearer or the mapped XaaS QoS flow.In some aspects, the node address on the CU side (e.g., T2-U TNL information on the CU side) may indicate to be used by an XaaS module (e.g., a PF unit) to forward the XaaS data to the CU (e.g., CU-UP) .In some aspects, the procedure 1900 may further include, after receiving the UE bearer context setup request 1908, the XC unit 1946 selecting 1909 one or more suitable PF units from its connected PF unit set e.g., based on the UE’s requested XaaS service and the PF unit’s supported XaaS service.In some aspects, procedure 1900 may further include, the XC unit 1946 helping the PF unit to decide one or more of: mapping between a PF entity and a PDCP entity, and related configuration parameters (e.g., security parameter, buffer size) of the PF entity and the PDCP entity. The XC unit 1946 may help the PF unit by provide information for mapping purposes.In some aspects, procedure the 1900 may further include the XC unit 1946 sending a UE context setup request message 1910 to the PF unit 1944, to notify the PF unit to setup the resource for the UE’s requested XaaS service. In some aspects, the PF unit 1944 may refer to multiple PF units.The UE context setup request message 1910 may include one or more of: an XaaS Bearer ID, a mapped XaaS QoS flow ID, a mapped XaaS session ID, a UE ID or a UE group ID served by an XaaS bearer, an XaaS QoS requirement on the XaaS bearer or an XaaS QoS flow, node address on the CU side (e.g., T2-U TNL information on the CU side) for the PF unit to forward XaaS data to the CU. In some aspects, the UE context setup request message 1910 may further include one or more lists of XaaS bearer IDs, mapped XaaS QoS flow IDs and mapped XaaS session IDs.In some aspects, after receiving the UE context setup request message 1910, the procedure 1900 may further include the PF unit 1944 performing 1911 one or more of:  deciding the mapping between the PF entity and the PDCP entity, setting up and configuring the PF entity and the PDCP entity (e.g., security parameter, buffer size) for the XaaS bearer.After receiving the UE context setup request message 1910, the UP tunnel for the PF unit to transmit the XaaS data to CU may be established.In some aspects, the procedure 1900 may further include the PF unit 1944 sending a UE context setup response message 1912 to the XC unit 1946 to notify the successful setup of the XaaS bearer. The UE context setup response message 1912 may include one or more of: an XaaS Bearer ID, PF entity and PDCP entity configuration information, and a node address on the PF side (e.g., T1-U TNL information, T2-U TNL information) .In some aspects, one XaaS bearer may be mapped to one new type of Radio Bearer (NRB) to carry the data of the XaaS bearer. The NRB may be for point-to-multipoint data transmission between the network and the UE, e.g., with multicast or broadcast method. According to an aspect, the NRB may be configured with one PDCP entity. So, data of one PF entity can be mapped to one PDCP entity configured for a group of UEs. In some aspects, mapping may be based on the XaaS QoS requirement, e.g., a data forwarding treatment requirement and a data processing treatment requirement. Mapping information between the XaaS bearer and NRB may be configured via a dedicated XaaS signalling message or RRC message, e.g., via an XSB by the XC sublayer or other control plane functions. In some aspects, one NRB may only carry the data of one XaaS bearer. In some aspects, the NRB can be the Multimedia Broadcast Multicast Service (MBMS) point to multipoint radio bearer (MRB) .In some aspects, the PF entity and PDCP entity configuration information may include one or more of: XaaS bearer and DRB mapping information, XaaS bearer and NRB mapping information, PF data split information, PDCP data split information, PF entity parameter, and PDCP entity parameter.The XaaS bearer and DRB mapping information (e.g., the PF entity and PDCP entity mapping information) may be used to map the XaaS bearer (e.g., identified by an XaaS bearer ID) to a DRB (e.g., identified by a DRB ID) for a UE. The XaaS bearer and NRB mapping information may be used to map the XaaS bearer to a radio bearer for a group of UEs. The PF data split information may be used to split the PF sublayer data to multiple PDCP entities. The PDCP data split information may be used to split the PDCP sublayer data to multiple RLC entities. The PF entity parameter may include e.g., data privacy protection  algorithm, an AI inference model, a buffer size. The PDCP entity parameter may include, e.g., a security parameter.The node address on the PF side (e.g., T1-U TNL information) may be used for the DU to forward the XaaS data to the PF unit. The node address on the PF side (e.g., T2-U TNL information) may be used for the CU to forward the XaaS data to the PF entity.In some aspects, the procedure 1900 may further include the XC unit 1946 sending a UE bearer context setup response message 1913 to the CU to notify the successful setup of the XaaS bearer. The UE bearer context setup response message 1913 may include one or more of: an XaaS bearer ID, a PF entity and PDCP entity configuration information, and a node address on PF side (e.g., T1-U TNL information, T2-U TNL information) .In some aspects, after receiving the UE bearer context setup response message 1913, the UP tunnel for the CU to transmit the XaaS data to the PF entity may be established.Referring to FIG. 19B, in some aspects, the procedure 1900 may further include the CU 1950 sending a UE context setup request message 1914 to the DU 1942 to notify the DU to setup the resource (s) for the UE’s requested XaaS service. The UE context setup request message 1914 may include one or more of: a DRB ID or a NRB ID, a mapped XaaS bearer ID, an XaaS QoS requirement on the DRB, a Cell ID, a UE ID or a UE group ID served by the DRB or the NRB, a PDCP entity and a RLC entity mapping information, and a node address on the PF side (e.g., T1-U TNL information on PF side) . In some aspects, the UE context setup request message 1914 my further include one or more lists of XaaS bearer IDs.The DRB ID or NRB ID may identify the DRB or NRB to be setup. The mapped XaaS bearer ID may identify the XaaS bearer mapped to the DRB or the NRB. The XaaS QoS requirement on the DRB may indicate the XaaS QoS requirement (e.g., data forwarding treatment) on the DRB. The cell ID may identify the serving cell for the UE via which the UE may receive the XaaS service. The UE ID or UE group ID may identify the UE or UEs served by the DRB or NRB. The PDCP entity and RLC entity mapping information may indicate how the data of the PDCP entity on PF unit side may be mapped to the RLC entity on DU side. The node address on the PF side (e.g., T1-U TNL information on PF side) may be used for the DU to forward the XaaS data to the PF unit.In some aspects, the procedure 1900 may further include, after receiving the UE context setup request message 1914, the DU 1942 performing action 1915 to set up and  configure one or more of: a RLC sublayer, a MAC sublayer and a PHY layer, e.g., based on the mapping information and XaaS QoS requirement on the DRB or NRB.In some aspects, after receiving the UE context setup request message 1914, the UP tunnel for the DU to transmit the XaaS data to the FP unit may be established.In some aspects, the procedure 1900 may further include the DU 1942 sending a UE context setup response message 1916 to the CU 1948 to notify the successful setup of the DRB or NRB. The UE context setup response message 1916 may include one or more of: a DRB ID or a NRB ID, a mapped XaaS bearer ID, a configuration information of RLC sublayer, a MAC sublayer, a PHY layer e.g., via RRC container, and a node address on the DU side (e.g., T1-U TNL information on DU side) . The node address on the DU side (e.g., T1-U TNL information) may be used by the PF unit to forward the XaaS data to the DU.In some aspects, the procedure 1900 may further include the CU 1948 sending a UE bearer context update request message 1917 to the XC unit 1946 to update the configuration of the XaaS bearer. The UE bearer context update request message 1917 may include one or more of: a DRB ID or a NRB ID, a mapped XaaS bearer ID, and a T1-U TNL information on the DU side.In some aspects, the DRB ID or the NRB ID may identify the established DRB or the NRB to be updated. The mapped XaaS bearer ID may identify the XaaS bearer mapped to the DRB or the NRB. In some aspects, the UE bearer context update request message 1917 may comprise one or more lists of XaaS Bearer IDs. The node address on the DU side (e.g., T1-U TNL information on DU side) may be used by the PF to forward the XaaS data to the DU.In some aspects, the procedure 1900 may further include the XC unit 1946 sending a UE context update request message 1918 to the PF unit 1944 to update the configuration of the XaaS bearer. The UE context update request message 1918 may include one or more of: a DRB ID or a NRB ID, a mapped XaaS bearer ID, and a T1-U TNL information on the DU side.In some aspects, after receiving the UE context update request message 1918, the UP tunnel for the FP unit to transmit the XaaS data to DU may be established.In some aspects the procedure 1900 may further include the XC unit 1946 or the CU 1948 configuring necessary information for the UE.According to an aspect, the procedure 1900 may further include the CU 1948 sending an XaaS service response message 1919 to the UE 1930 to configure the UE for the requested XaaS service, e.g., via a RRC Reconfiguration message or other dedicated RRC message between the UE and the CU. The XaaS service response message 1919 may include one or more of: an XaaS session ID, an XaaS QoS flow ID, an XaaS bearer ID, a DRB ID and a NRB ID. In some aspects, a list of one or more of: an XaaS session ID, an XaaS QoS flow ID, an XaaS bearer ID, a DRB ID and a NRB ID can be included in the XaaS service response message 1919. In some aspects, the XaaS service response message 1919 may notify the UE that the XaaS session, the XaaS QoS flow, the XaaS bearer, and the DRB / NRB are successfully established for the UE to receive the requested XaaS service.In some aspects, the XaaS service response message 1919 may further include mapping information related to an XaaS session, an XaaS QoS flow, an XaaS bearer, and a DRB / NRB, e.g., an XaaS session and an XaaS bearer mapping information (e.g., an XaaS session ID and XaaS bearer ID mapping) .In some aspects, the XaaS service response message 1919 may further include configuration of the L2 layer, e.g., the configuration parameter of different L2 entities, and the mapping between the PF entity and the PDCP entity. In some aspects, the XaaS service response message 1919 may further include configuration of the L1 layer, e.g., a physical resource block.In some aspects, the procedure 1900 may further include the XC unit 1946 sending an XaaS service response message 1920 to the UE 1930 to configure the UE for the requested XaaS service, e.g., via a dedicated XaaS signalling message between XC unit and UE. The XaaS service response message 1920 may include one or more information included in the XaaS service response message 1919.Some aspects of the disclosure may provide for joint PF sublayer and PDCP sublayer security configuration based on preconfigured security modes.According to an aspect, in a split RAN architecture, as illustrated in FIG. 5, FIG. 7, and FIG. 12, for an XaaS service, both the PF sublayer and (all or parts of) a PDCP sublayer may be deployed at the PF unit.In some aspects, the configuration (including security configuration) of PF sublayer may be assigned to the XC unit, while the configuration of the PDCP sublayer may be retained at the CU or assigned to the XC unit.In some aspects, if the configuration of the PDCP sublayer is retained at the CU, the CU and the XC unit may need to cooperate to configure the PF unit for the PDCP sublayer and the PF sublayer, respectively.In some aspects, if the configuration of the PDCP sublayer is assigned to the XC unit, then the XC unit may configure the PF unit for both the PDCP sublayer and the PF sublayer.FIG. 20 illustrates a procedure for a joint PDCP sublayer and PF sublayer security configuration based on preconfigured security modes, according to an aspect. The procedure 2000 may provide for security configuration for one or both of PDCP and PF sublayers in a split RAN architecture.According to an aspect, each network node (UE 2030, CN 2050, XC unit 2046, PF unit 2044, CU 2048) may be preconfigured, e.g., via a subscription or a network management procedure, with one or more list of supported security modes on data processing and data forwarding. In some aspects, the supported security modes can be notified to and aligned among the different nodes.Based on the preconfigured security capabilities, in some aspects, the UE 2030 and the network (e.g., CN 2050, XC unit 2046, PF unit 2044, CU 2050) can perform one or more of: a NAS and AS security mode selection, and an execution of security protection for data forwarding and data processing on an XaaS XSB, an XDB and an XaaS NAS traffic.In some aspects, one or more AS security parameters (e.g., security keys for XaaS bearer XSB and XDB) may be derived from a RAN node key. The RAN node key may be derived based on a CN key, which is handled by upper layers. In some aspects, the CU 2048 may forward one or more of: the RAN node key and the CN key to an XaaS module to enable the XaaS module to encrypt, decrypt and parse data.According to an aspect, workflow or procedure 2000 may include the UE reporting or sending its supported security mode (e.g., identified by security mode ID) 2001 on data processing and data forwarding to the CN e.g., via a registration request message. The supported security mode 2001 may include one or more of a AS security mode and NAS security mode as described hereinIn some aspects, one or more UEs, including the UE 2020, may be configured, via subscription, with one or more lists of security modes for data processing and data  forwarding. The one or more lists may be ordered according to a priority decided by an operator.The UE 2030 may report its support security modes 2001 to the network (e.g., CN) via various methods. In some aspects, UE 2030 may report its supported security mode to the XC unit 2046 and the CU 2048, respectively. That is, the UE sends its supported security mode to XC unit in a first message, and then the UE sends its same supported security mode to CU in separate second message. Then, the XC unit 2046 and the CU 2048 may further forward the UE supported security modes to the CN 2050.In some aspects, the UE 2030 may report its supported security mode to the XC unit 2046, which forwards the UE’s supported security mode to the CU 2048. Then, the CU 2048 may forward the UE’s supported security mode to the CN 2050.In some aspects, UE 2030 may report is supported security mode to the CU 2048, which forwards the UE’s supported security mode to the XC unit 2046. Then, the XC unit 2046 may forward the UE’s supported security mode to the CN 2050.In some aspects, the UE 2030 may report its supported security mode to the CN, which forwards the UE’s supported security mode to one or more of: the XC unit 2046 and the CU 2048. If the CN forwarded the UE’s supported security mode to the XC unit 2046, then the XC unit 2046 may forward the received UE’s supported security mode to the CU 2048. Similarly, if the CN forwarded UE’s supported security mode to the CU 2048, then the CU 2048 may forward the received UE’s supported security mode to the XC unit 2046.In some aspects, the UE 2030 may report its supported security mode to the DU, and the DU may forward the received UE’s supported security mode to either the CU or the XC unit or both. If the DU forwarded the UE’s supported security mode to the XC unit, then the XC unit may forward the received UE’s supported security mode to the CU. Similarly, if the DU forwarded the UE’s supported security mode to the CU, then the CU may forward the received UE’s supported security mode to the XC unit. The one or more of the XC unit and the CU may then forward the UE’s supported security mode to the CN.In some aspects, the procedure 2000 may further include the PF unit 2044 reporting its supported AS security modes 2002 (e.g., identified by AS security mode ID) to the XC unit. In some aspects, the priority of different security modes can be also reported. In some aspects, the PF unit 2044 may refer to multiple PF units.In some aspects, one or more PF units may be configured via a network management procedure with one or more lists of security modes for data processing and data forwarding. The one or more lists may be ordered according to a priority decided by an operator.In some aspects, the procedure 2000 may further include the XC unit 2046 reporting the supported AS security mode 2003 (e.g., identified by AS security mode ID) on data forwarding of the XaaS to the CU. In some aspects, the priority of different ciphering and integrity protection algorithms may also be reported. The supported AS security mode 2003 may indicate one or more AS security modes supported at one or more of: PF 2044 and XC unit 2046. In some aspects, the supported AS security mode 2003 may include one or more AS security mode supported at both the XC unit 2046 and at least one PF 2044 connected to the XC 2046 (e.g., an overlapped AS security mode among the XC unit and the at least one PF) .In some aspects, the included supported AS security modes 2003 may be supported by at least one of the PF units connected to the XC unit. Or, the AS security mode 2003 may be the overlapped security mode supported by both the XC unit 2046 and at least one of the PF units 2044 connected to the XC unit.In some aspects, procedure 2000 may further include the CN sending a selected NAS security modes (e.g., identified by NAS security mode ID) to the UE, e.g., via a NAS security mode command message 2004. In some aspects, the selected security modes may be used to protect the CN XaaS data on one or both of the control plane or user (data) plane between the UE and the CN, e.g., to protect NAS traffic for the XaaS.In some aspects, the CN 2050 may be configured via network management with one or more lists of security modes for data processing and data forwarding. According to an aspect, based on the received UE’s supported security modes and the configured CN’s supported security modes, the CN 2050 may select a suitable security mode for data processing and data forwarding, e.g., a security mode which overlaps with a security mode supported by UE and the CN and may have a high or highest priority.In some aspects, when sending its supported security mode 2001, the UE may request for establishment or setup of an XaaS PDU session via, e.g., an XaaS PDU session setup request. In some aspects, the XaaS PDU session setup request may comprise one or more XaaS QoS parameter (e.g., security level, privacy level) on the XaaS service.According to an aspect, based on the XaaS QoS parameter and the received UE security capability, the CN 2050 may decide the data forwarding treatment and the data processing treatment for the XaaS PDU session. For example, based on the XaaS QoS parameter and the UE security capability, the CN 2050 may perform one or more of: determining or selecting a CN security mode on data processing and data forwarding, and generating one or more security parameters for CN XaaS traffic.In some aspects, the procedure 2000 may further include the CN sending one or more of: the UE’s supported security mode 2001 and CN-assisted security information to the CU 2048, e.g., via an initial UE context setup request or an XaaS PDU session setup request message 2005. The CN-assisted security information may include one or more of: a CN-assisted information on AS security mode and a CN-assisted security parameter.In some aspects, the CN-assisted information on AS security mode may provide information for the CU and the XC unit to further decide the AS security mode. In some aspects, the assisted security parameters may be used by one or both of the CU and the XC unit to derive an AS security parameter (e.g., AS security key) for the PF unit including the PF sublayer and the PDCP sublayer. The CN-assisted security parameters may include one or more of: a security key Kx to be used by one or more of: CU, XC unit and PF unit to derive the AS security parameter of the PF sublayer (termed as PF sublayer related security key) , and a security key Kc to be used by one or more of: CU, XC unit and PF unit to derive the AS security parameter of the PDCP sublayer (termed as PDCP sublayer related security key) . In some aspects, Kx and Kc may be the same or different. In some aspects, one or more keys may refer to one or more of: a Key of privacy protection algorithm for privacy protection, and a Key of security protection algorithm for security protection.In some aspects, if the configuration of PDCP sublayer is assigned to the CU, the procedure 2000 may further include the CU 2048 selecting 2006 a suitable security mode for data forwarding on the PDCP sublayer, based on one or more of: a supported security mode 2003 received from XC 2046, a UE’s support security mode 2005 received from the CN and CN-assisted security information. In some aspects, the selected security mode may be a security mode that is supported by both the UE and the XC and may have a high or highest priority.In some aspects, the selected security mode may be used to protect the PDCP sublayer XaaS data on one or more of: control plane or user (data) plane between UE and PF  unit. In some aspects, e.g., based on PDCP sublayer related security key Kc, CU 2048 may further generate one or more security parameters corresponding to the selected security algorithm (e.g., ciphering key Kpd-u which may be used for PDCP sublayer data e.g., for XSB on CP or XDB on UP) .In some aspects, the CU 2048 may further perform one or more of: generate CU-assisted information on an AS security mode, and help the XC unit to further decide the AS security mode. In some aspects, the CU and the XC unit may undergo one or more rounds of interactions and negotiations, between them, to cooperatively decide the AS security mode.In some aspects, the CU 2048 may help the XC unit to decide the AS security mode by providing information, for example, the CU-assisted information on the AS security mode, which may include a list of preferred security modes (e.g., indicating one or more of: ciphering algorithm, and integrity protection algorithm) for data forwarding on the PDCP sublayer. In some aspects, CU 2048 may send the list of preferred security modes on PDCP sublayer to XC unit 2046, and XC unit 2046 may select one or more of the preferred security modes from the list and feedback the selected one or more preferred security modes to CU. In some aspects, CU 2048 may further select one or more of the received, from XC unit, selected one or more preferred security modes and feedback to XC. XC 2046 and CU 2048 may continue the back-and-forth feedback of selected security modes for one or more rounds to obtain a consensus between CU and XC.In some aspects, the procedure 2000 may further include the CU 2048 sending an XaaS bearer setup request message 2007 to the XC unit 2046. The XaaS bearer setup request message 2007 may include one or more of: the UE’s security mode, CU-assisted security information, and CN-assisted security information included in the request message 2005.In some aspects, if the configuration of a PDCP sublayer is assigned to the CU 2048, the CU 2048 may further send, in the XaaS bearer setup request message 2007 or a different message, to the XC 2046 one or more of: the selected security mode (e.g., indicating ciphering algorithm, integrity protection algorithm) for data forwarding on the PDCP sublayer, the security parameter (e.g., ciphering key Kpd-u) , and CU-assisted information on the AS security mode.In some aspects, if or when the CU determines that security protection is not needed at the PDCP sublayer, one or more of the following may occur: the CU may not send  a security algorithm to the XC unit, the CU may send a default value or a null value as a security parameter to the XC unit.In some aspects, the procedure 2000 may further include the XC 2046 performing 2008 one or more of: selecting a PF unit, and selecting an AS security mode. In some aspects, the XC 2046 may select the PF unit which has overlapped supported security mode with the UE.In some aspects, the XC 2046 may select the AS security mode based on one or more of: the received information in the XaaS bearer setup request message 2007 and the received information in the supported AS security mode 2002. In some aspects, the XC 2046 may select the AS security mode based on one or more of: an XaaS QoS requirement, CN-assisted information on AS security mode, CU-assisted information, etc.In some aspects, based on the selected AS security mode, the XC unit 2046 may further derive or generate one or more AS security parameters (e.g., based on one or more of: CU-assisted security information and CN-assisted security parameter) . In some aspect the one or more derived AS security parameter may correspond to the AS security algorithms for the PF unit to execute security protection in one or more of the PF sublayer and the PDCP sublayer.In some aspects, the XC unit may select one or more suitable AS security algorithms corresponding to the security mode. For example, the security mode may indicate that security protection should be executed at none, one or more than one of: the PF sublayer and the PDCP sublayer. Based on the security mode, the XC unit may select one or more security algorithm associated with one or both of: the PDCP sublayer and the PF sublayer. In some aspects, based on the security mode, e.g., no security protection should be executed at the PDCP sublayer and the PF sublayer, the XC unit may not select a security algorithm for neither the PDCP sublayer nor the PF sublayer.According to an aspect, the XC unit 2046 may derive one or more AS security parameters based on related security keys. For example, the XC unit 2046 may derive, e.g., an AS security key Kpf-u for the PF sublayer security between the PF unit and the UE based on the PF sublayer related security key Kx. The XC unit 2046 may further derive e.g., a security key Kpf-pf for the PF sublayer security between different PF units based on the PF sublayer related security key Kx. The XC unit 2046 may further derive e.g., an AS security key Kxc-u for the XC sublayer security between the XC unit and the UE.In some aspects, if the configuration of the PDCP sublayer is assigned to the XC unit, the XC unit 2046 may also derive an AS security key Kpd-u for the PDCP sublayer security between the UE and the PF unit based on the PDCP sublayer related security key Kc.According to an aspect, the selected security mode and the derived security parameters corresponding to the security algorithm may be used to protect the data (e.g., to protect data privacy) on the XDB and the XSB.In some aspects, the procedure 2000 may further include the XC unit 2046 sending the AS security configuration information 2009 to the PF 2044. The AS security configuration information may include the selected AS security mode (e.g., identified by a security mode ID) , and the AS security parameter (e.g., AS security key Kpf-u, Kpf-pf, Kpd-u) .In some aspects, the XC unit may sends the selected security mode (e.g., identified by security mode ID) , and the CN-assisted security parameter (e.g., PF sublayer related security key Kx, and PDCP sublayer related security key Kc) to the PF. Accordingly, the procedure 2000 may further include the PF 2044 deriving or generating 2010 the AS security parameters (e.g., AS security key Kpf-u, Kpf-pf, Kpf-u) . Based on the AS security mode and the AS security parameter, the PF unit 2044 may execute the security protection on one or more of the PF sublayer data and the PDCP sublayer data.In some aspects, the procedure 2000 may further include the XC unit 2046 sending an AS security configuration message 2011. The AS security configuration message 2011 may include one or more of: the selected AS security mode (e.g., identified by security mode ID) and AS security parameters. In some aspects, the AS security configuration message 2011 may be sent via e.g., an AS security mode command message or other XaaS signalling message on the XSB between the XC unit and the UE. The AS security configuration message 2011 may be sent to the UE for the UE to perform the security protection between the UE and the PF unit at one or more of the PF sublayer and the PDCP sublayer. In some aspects, e.g., when the UE itself can derive the AS security parameter, the AS security configuration message 2011 may not include the AS security parameters.In some aspects, the procedure 2000 may further include the XC unit 2046 sending the AS security configuration information message 2012 to the CU 2048. The AS security configuration information message may include one or more of the selected AS  security mode (e.g., identified by security mode ID) and the AS security parameter (e.g., AS security key Kpf-u, Kpf-pf, Kpd-u) .In some aspects, the procedure 2000 may further include the CU 2048 sending an AS security configuration message 2013 to the UE. The AS security configuration message 2013 may include one or more of: the selected AS security mode (e.g., identified by security mode ID) , and AS security parameters. In some aspects, the AS security configuration message 2013 may be sent via an AS security mode command message or other XaaS signalling message on an SRB between the CU and the UE. In some aspects, the AS security configuration message 2013 may be sent to the UE for the UE to perform the security protection between the UE and the PF unit at one or more of the PF sublayer and the PDCP sublayer. In some aspects, e.g., when the UE itself can derive the AS security parameter, the AS security configuration message 2011 may not include the AS security parameters.In some aspects, operations described in reference to AS security configuration messages 2012 and 2013 may be alternative to operations described in reference to AS security configuration message 2011.Some Aspects of the disclosure may provide for joint PF sublayer and PDCP sublayer security configuration based on preconfigured security capabilities.In reference to FIG. 21, in some aspects, one or more network node (UE 2130, CN 2150, XC unit 2146, PF unit 2144, CU 2148) may be preconfigured, e.g., via subscription or network management procedure, with one or more lists of supported security capabilities (i.e., supported security algorithms) on data processing and data forwarding.Based on the preconfigured security capabilities, the UE 2130 and the network (e.g., CN 2150, XC unit 2146, PF unit 2144, CU 2148) can perform one or more of: security capability alignment, security mode selection and security algorithm negotiation, and execution of security protection for data forwarding and data processing on an XaaS XSB, an XDB and XaaS NAS traffic.FIG. 21 illustrates a procedure for joint PDCP sublayer and PF sublayer security configuration based on preconfigured security capabilities, according to an aspect. The procedure 2100 may provide for security configuration for one or both of the PDCP sublayer and the PF sublayer in a split RAN architecture.According to an aspect, the workflow or procedure 2100 may include theUE 2130 reporting or sending its security capability on data processing and data forwarding to the CN  2150, e.g., via a registration request message 2101. The registration request message 2101 may include the UE’s supported security capability on data processing of an XaaS (e.g., supported privacy protection algorithm) which can be used for one or more of the PF sublayer and XaaS NAS traffic (e.g., NAS signalling and / or NAS UP traffic) between the UE and the CN. In some aspects, the registration request message 2101 may further include the UE’s supported security capability on data forwarding of the XaaS (e.g., supported ciphering algorithm and integrity protection algorithm which can be used for one or more of: PDCP sublayer and XaaS NAS traffic (e.g., NAS signalling and / or NAS UP traffic) between the UE and the CN.In some aspects, the registration request message 2101 may further include a priority of algorithms indicated in the UE’s supported security capability on one or more of: data forwarding and data processing.In some aspects, one or more UEs, including the UE 2130, may be configured, via subscription, with one or more lists of security algorithms which may be used on data processing and data forwarding. The one or more lists may include a first set of lists for data processing and a second set of lists for data forwarding. The one or more lists may be ordered according to a priority decided by the operator.In some aspects, the UE 2130 reporting its security capability to the network (e.g., CN) may involve one or more operations. In some aspects, the UE 2130 may report the UE’s security capability (e.g., for privacy protection) on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS to the XC unit 2146 and the CU 2146, respectively. Then, the XC unit 2146 and the CU 2148 may further forward the UE security capability to the CN 2150.In some aspects, the UE 2130 may report the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS to the XC unit 2146. The XC unit 2146 may store locally the UE’s security capability on data processing of the XaaS. The XC unit 2146 may further forward the UE’s security capability on data forwarding of the XaaS to the CU 2148. Then XC 2146 may further forward both the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS to the CN 2150.In some aspects, the UE 2130 may report the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS to  the CU 2148. The CU 2148 may store locally the UE’s security capability on data forwarding of the XaaS. The CU 2148 may further forward the UE’s security capability on data processing of the XaaS to the XC unit 2146. Then the CU 2148 may further forward both the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS to the CN 2150.In some aspects, the UE 2130 may report one or both of: the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS to the CN 2150. The CN 2150 may inform or send to the XC unit 2146 one or more of: the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. If received, the XC unit 2146 may store locally the UE’s security capability on data processing of the XaaS. If the XC unit 2146 also received the UE’s security capability on data forwarding of XaaS from the CN 2150, then the XC unit 2146 may further forward the UE’s security capability on data forwarding of the XaaS to the CU 2148.In some aspects, the UE 2130 may report one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS to the CN 2150. the CN 2150 may further inform or send to the CU 2148 one or more of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. If received, the CU 2148 may store locally the UE’s security capability on data forwarding of the XaaS. If the CU 2148 also received the UE’s security capability on data processing of the XaaS from the CN 2150, then the CU 2148 may further forward the UE’s security capability on data processing of the XaaS to the XC unit 2146.In some aspects, the UE 2130 may report to the DU one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. The DU may then forward to the XC unit 2146 one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. If received, the XC unit 2146 may store locally the UE’s security capability on data processing of the XaaS. If the XC unit 2146 also received the UE’s security capability on data forwarding of the XaaS, then the XC unit 2146 may further forward the UE’s security capability on data forwarding of the XaaS to the CU 2148. The one or both of the XC unit 2146 and the CU 2148 may further forward to CN one or both of the  UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS.In some aspects, the UE 2130 may report to the DU one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. The DU may then forward to the CU 2148 one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. If received, the CU 2148 may store locally the UE’s security capability on data forwarding of the XaaS. If the CU 2148 also received the UE’s security capability on data processing of the XaaS, then the CU 2148 may further forward the UE’s security capability on data processing of the XaaS to the XC unit 2146. The one or both of the XC unit 2146 and the CU 2148 may further forward to the CN one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS.In some aspects, the UE 2130 may report to the DU one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. The DU may then forward to both the XC unit 2146 and the CU 2148 one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS. If received, the XC unit 2146 may store locally the UE’s security capability on data processing of the XaaS. In some aspects, if received, the XC unit 2146 may further forward the UE’s security capability on data forwarding of the XaaS to the CU 2148. Similarly, if received, the CU 2148 may store locally the UE’s security capability on data forwarding of the XaaS. Further, if received, the CU 2148 may further forward the UE’s security capability on data processing of the XaaS to the XC unit 2146. The one or both of the XC unit 2146 and the CU 2148 may further forward to the CN one or both of the UE’s security capability on data processing of the XaaS and the UE’s security capability on data forwarding of the XaaS.In some aspect, the procedure 2100 may further include the PF unit 2144 reporting or sending its security capability 2102 to the XC unit 2146. In some aspect, security capability 2102 may include security capability on data processing of the XaaS. The security capability on data processing of the XaaS 2102 may include one or more of: supported privacy protection algorithm by the PF sublayer and a priority of different algorithms. In some aspects, the security capability 2102 may further include the PF unit’s security capability on data forwarding. The security capability on data forwarding may include one or  more of: supported ciphering algorithm by the PDCP sublayer, integrity protection algorithm by the PDCP sublayer, and a priority of different ciphering and integrity protection algorithms.In some aspects, each PF may be configured via network management with one or more lists of security algorithms for use on data processing and data forwarding. The one or more lists may include a first set of lists for data processing and a second set of lists for data forwarding. In some aspects, the one or more lists may be ordered according to a priority decided by an operator.In some aspects, the procedure 2100 may further include the XC unit 2146 reporting or sending the security capability 2103 of the one or more PF units 2144 to the CU 2148. The XC unit’s security capability may include security capability on data forwarding of the XaaS. The security capability on data forwarding of the XaaS may include one or more of: a supported ciphering algorithm and integrity protection algorithm by the PDCP sublayer, and the priority of different ciphering and integrity protection algorithms. The security capability 2103 may indicate one or more security capabilities supported at one or more of: PF 2144 and XC unit 2146. In some aspects, the security capability 2103 may include one or more security capabilities supported at both the XC unit 2146 and at least one PF 2144 connected to the XC 2046 (e.g., an overlapped security capability among the XC unit and the at least one PF) .Thus, in some aspects, the security capability 2103 may be supported at the one or more of the PF units 2144 connected to the XC unit. Or, the security capability 2103 may be the overlapped security capability supported by both the XC unit 2146 and at least one of the PF units 2144 connected to the XC unit.In some aspects, the procedure 2100 may further include the CN 2150 sending one or more selected security algorithms to the UE 2130, e.g., via a NAS security mode command message 2104. The one or more selected security algorithms may be used to protect the CN XaaS data on one or both of the control plane and the user (data) plane between the UE and the CN, e.g., to protect NAS traffic for the XaaS.In some aspects, the CN 2150 may be configured via network management with one or more lists of security algorithms for use on data processing and data forwarding. The one or more lists may include a first list for data processing, and a second list for data  forwarding. The one or more lists may be ordered according to a priority decided by the operator.In some aspects, based on the received UE’s supported security algorithm (in the registration request message 2101) and the configured CN’s supported security algorithms, the CN 2150 may select one or more of: a suitable security algorithm for data processing and a suitable security algorithm for data forwarding, e.g., which may be the overlapped security algorithms supported by the UE and the CN, and have a high or highest priorities.According to an aspect, when sending the registration request message 2101, the UE may request for establishment or setup of an XaaS PDU session via e.g., an XaaS PUD session setup request. In some aspects, the XaaS PDU session setup request may comprise one or more XaaS QoS parameter (e.g., security level, privacy level) on the XaaS service.According to an aspect, based on the XaaS QoS parameter and the received UE security capability, the CN 2150 may determine the data forwarding treatment and data processing treatment for the XaaS PDU session. For example, based on the XaaS QoS parameter and the UE security capability, the CN 2150 may perform one or more of: determining the CN security algorithm on data processing and data forwarding, and generates the security parameter for CN XaaS traffic.In some aspects, the procedure 2100 may include the CN 2150 sending one or more of: the UE’s supported security capability received in the registration request message 2101 and CN-assisted security information to the CU 2148, e.g., via an initial UE context setup request or an XaaS PDU session setup request message 2105. The CN-assisted security information may include one or more of: CN-assisted information on AS security mode and a CN-assisted security parameter.In some aspects, the CN-assisted information on AS security mode may provide information for the CU and the XC unit to further decide the AS security mode. In some aspects, the assisted security parameters may be used by one or both of the CU and the XC unit to derive the AS security parameter (e.g., AS security key) for the PF unit including the PF sublayer and the PDCP sublayer. The CN-assisted security parameters may include one or more of: a security key Kx to be used by one or more of: CU, XC unit and PF unit to derive the AS security parameter of the PF sublayer (termed as PF sublayer related security key) , and a security key Kc to be used by one or more of: CU, XC unit and PF unit to derive the  AS security parameter of the PDCP sublayer (termed as the PDCP sublayer related security key) . In some aspects, Kx and Kc may be the same or different.In some aspects, if the configuration of the PDCP sublayer is assigned to the CU, the procedure 2100 may further include the CU 2148 selecting 2106 a suitable algorithm for data forwarding on the PDCP sublayer, based on one or more of: a security capability 2103 received from the XC, a UE’s supported security capability received in the UE context setup request 2105, and a CN-assisted security information. In some aspects, the CU may select a suitable algorithm for data forwarding on the PDCP sublayer, e.g., which may overlap with a security algorithm supported by the UE and the XC and may have a high or highest priorities.In some aspects, the selected security algorithm may be used to protect the PDCP sublayer XaaS data on one or more of: the control plane or the user (data) plane between the UE and the PF unit. In some aspects, e.g., based on the PDCP sublayer related security key Kc, the CU 2148 may generate one or more security parameters corresponding to the selected security algorithm (e.g., ciphering key Kpd-u which may be used for PDCP sublayer data e.g., for XSB on CP or XDB on UP) .In some aspects, the CU 2148 may further perform one or more of generate CU-assisted information on the AS security mode, and help the XC unit to further decide the AS security mode. In some aspects, the CU and the XC unit may undergo one or more rounds of interactions and negotiations, between them, to cooperatively decide the AS security mode.In some aspects, the CU 2148 may help the XC unit 2146 to decide the AS security mode by providing information, for example, the CU-assisted information on the AS security mode, which may include a list of preferred security modes (e.g., indicating one or more of: ciphering algorithm, and integrity protection algorithm) for data forwarding on the PDCP sublayer. In some aspects, CU 2148 may send the list of preferred security modes on PDCP sublayer to XC unit 2146, and XC unit 2146 may select one or more of the preferred security modes from the list and feedback the selected one or more preferred security modes to CU. In some aspects, CU 2148 may further select one or more of the received, from XC unit, selected one or more preferred security modes and feedback to XC. XC 2146 and CU 2148 may continue the back-and-forth feedback of selected security modes for one or more rounds to obtain a consensus between CU and XC.In some aspects, the procedure 2100 may further include the CU 2148 sending to the XC unit 2146 an XaaS bearer setup request message 2107. The XaaS bearer setup request  message 2107 may include one or more of: the UE’s security capability and CN-assisted security information received in the UE context setup request 2105.In some aspects, if the configuration of the PDCP sublayer is assigned to the CU 2148, the CU 2148 may further send, in the XaaS bearer setup request message 2107 or a different message, to the XC 2146 one or more of: the selected security algorithm (e.g., ciphering algorithm, integrity protection algorithm) for data forwarding on the PDCP sublayer, a security parameter (e.g., ciphering key Kpd-u) , and CU-assisted information on AS security mode.In some aspects, if or when the CU decides that security protection is not needed at PDCP sublayer, one or more of the following may occur: the CU may not send a selected security algorithm to the XC unit and the CU may send a default value or a null value as a security parameter to XC unit.In some aspects, the procedure 2100 may further include the XC performing 2108 one or more of: selecting a PF uni, and selecting an AS security mode. In some aspects, the XC 2146 may select the PF unit which has overlapped support security capability with the UE.In some aspects, the XC 2146 may select the AS security mode based on one or more of: information received in the XaaS bearer setup request message 2107 and information received in the security capability 2102. In some aspects, XC 2146 may select the AS security mode further based on one or more of: an XaaS QoS requirement, CN-assisted information on AS security mode, CU-assisted information, etc.In some aspects, based on the selected AS security mode, the XC unit may select on or more suitable AS security algorithms for the PF unit to execute security protection in one or more of: the PF sublayer and the PDCP sublayer. The selection of one or more AS security algorithm may be based on (e.g., security algorithms that may overlap with security algorithms supported by UE and PF unit, and the algorithm priority) . In some aspects, based on the selected AS security mode, the XC unit may further derive one or more AS security parameters (e.g., based on a CN-assisted security parameter) .As described herein, the XC unit may select one or more suitable AS security algorithms corresponding to the selected security mode. For example, the selected security mode may indicate that security protection should be executed at none or at one or more of: the PF sublayer and the PDCP sublayer. Based on the security mode, the XC unit may select  one or more security algorithms associated with one or both of: the PDCP sublayer and the PF sublayer. In some aspects, based on the security mode, e.g., no security protection should be executed at the PDCP sublayer and at the PF sublayer, the XC unit may not select a security algorithm for neither the PDCP sublayer nor the PF sublayer.In some aspects, the XC unit 2146 may derive one or more AS security parameters based on related security key. For example, the XC unit 2046 may derive, e.g., an AS security key Kpf-u for the PF sublayer security between PF unit and UE based on PF sublayer related security key Kx. The XC unit 2046 may further derive, e.g., a security key Kpf-pf for the PF sublayer security between different PF units based on PF sublayer related security key Kx. The XC unit 2046 may further derive e.g., an AS security key Kxc-u for the XC sublayer security between the XC unit and the UE.In some aspects, if the configuration of the PDCP sublayer is assigned to the XC unit, the XC unit 2146 may further derive an AS security key Kpd-u for the PDCP sublayer security between the UE and the PF unit based on the PDCP sublayer related security key Kc.According to an aspect, the selected security algorithm and derived security parameters may be used to protect the data (e.g., to protect data privacy) on an XDB and an XSB.In some aspects, the procedure 2100 may further include the XC unit sending an AS security configuration information message 2109 to thePF 2144. The AS security configuration information message 2109 may include one or more of: the selected AS security mode, the selected AS security algorithm, and the AS security parameter (e.g., AS security key Kpf-u, Kpf-pf, Kpd-u) .In some aspects, the XC unit may send the security mode, the AS security algorithm and the CN-assisted security parameter (e.g., PF sublayer related security key Kx, and PDCP sublayer related security key Kc) to the PF, and the PF 2144 may derive 2110 the AS security parameters (e.g., AS security key Kpf-u, Kpf-pf, Kpf-u) . According to an aspect, based on one or more of: the AS security mode, the AS security algorithm, and the AS security parameter, the PF unit 2144 may execute the security protection on one or more of: the PF sublayer data and the PDCP sublayer data.In some aspects, the procedure 2100 may further include the XC unit 2146 sending to the UE 2130 an AS security configuration information message 2111. The AS security configuration message may include one or more of: the selected AS security mode,  the selected AS security algorithm, and the AS security parameter to UE. The AS security configuration message may be sent via e.g., a AS security mode command message or another XaaS signalling message on the XSB between the XC unit and the UE. The AS security configuration information message may be sent to the UE for the UE to perform the security protection between the UE and the PF unit at one or more of: the PF sublayer and the PDCP sublayer. In some aspects, e.g., when the UE itself can derive the AS security parameter, the AS security configuration message 2111 may not include the AS security parameter.In some aspects, the procedure 2100 may further include the XC unit 2146 sending an AS security configuration information message 2112 to the CU 2148. The AS security information message may include one or more of: the selected AS security mode, the selected AS security algorithm, and the AS security parameter (e.g., AS security key Kpf-u, Kpf-pf, Kpd-u) .In some aspect, the procedure 2100 may further include the CU 2148 sending an AS security configuration message 2110 to the UE 2130. The AS security configuration message 2113 may include one or more of: the selected AS security mode, the selected AS security algorithm, and the AS security parameter. In some aspects, the AS security configuration message 2013 may be sent via e.g., an AS security mode command message or another XaaS signalling message on the SRB between the CU and the UE for the UE to perform the security protection between the UE and the PF unit at one or more of: the PF sublayer and the PDCP sublayer. In some aspects, e.g., when the UE itself can derive the AS security parameter, the AS security configuration message 2113 may not include the AS security parameter.In some aspects, operations described in reference to AS security configuration messages 2112 and 2113 may be alternative to operations described in reference to the AS security configuration message 2111.Aspects of the disclosure may provide for one or more interface designs among network nodes e.g., CU, DU, PF unit and XC unit entities in a split RAN architecture where an XaaS module is an internal component of the RAN. Some aspects of the disclosure may provide for an XaaS ID for identifying an XaaS service. Some aspects of the disclosure may provide for interface management procedure, e.g., for XaaS capability alignment among the CU, the DU, the PF unit and the XC unit. Some aspects of the disclosure may provide  enhanced protocol stack design for one or more network nodes (e.g., PF unit, SC unit, CU, and DU) and their interfaces in the XaaS service.Some aspects may provide for deployment of a plug and play XaaS module in a split RAN for future XaaS service. According to an aspect, the units (CU and DU) for data forwarding and the units (PF unit and XC unit) for data processing may be mutually engaged. Aspects of the disclosure may have fewer effects on current connectivity-oriented split RAN architecture for data forwarding service.Some aspects may enable a UE to discover and access a network for an XaaS service. Relatedly, aspects of the disclosure provide for an XaaS ID design and notification to the UE. Further aspects may provide for an XaaS session and an XaaS bearer establishment procedure design.Some aspects may provide for one or more of: a NAS and AS security mode on data processing and data forwarding. Further aspects may provide for selection of one or more of: a NAS and AS security mode.Some aspects may provide for joint security configuration for PDCP and PF sublayers based on preconfigured security mode (NAS security mode, AS security mode) . Further aspects may provide for joint security configuration for PDCP and PF sublayers, based on preconfigured supported security capability.One or more aspects of the disclosure may enable, security protection (e.g., data ciphering &integrity protection on data forwarding, and data privacy protection on data processing) for an XDB, an XSB and an XaaS NAS traffic in future XaaS service.FIG. 22 illustrates an apparatus 2200 that may perform any or all of operations of the above methods and features explicitly or implicitly described herein, according to different aspects of the present disclosure. For example, a computer equipped with network function may be configured as the apparatus 2200. In some aspects, the apparatus 2200 may be an XaaS module, an XC node or unit, a PF, a CU node or unit, a DU node or unit, a network node, a RAN node, a CN function, or any other entity, as the case may be, described herein. In some aspect, apparatus 2200 may be a device that connects to the network infrastructure over a radio interface, such as a mobile phone, smart phone or other such device that may be classified as user equipment (UE) . In some aspects, the apparatus 2200 may be a Machine Type Communications (MTC) device (also referred to as a machine-to-machine (m2m) device) , or another such device that may be categorized as a UE despite not  providing a direct service to a user. In some aspects, apparatus 2200 may be used to implement one or more aspects described herein. In some aspects, the apparatus 2200 may be configured to perform operations by one or more entities or functions described herein.As shown, the apparatus 2200 may include a processor 2210, such as a Central Processing Unit (CPU) or specialized processors such as a Graphics Processing Unit (GPU) or other such processor unit, memory 2220, non-transitory mass storage 2230, input-output interface 2240, network interface 2250, and a transceiver 2260, all of which are communicatively coupled via bi-directional bus 2270. According to certain aspects, any or all of the depicted elements may be utilized, or only a subset of the elements. Further, apparatus 2200 may contain multiple instances of certain elements, such as multiple processors, memories, or transceivers. Also, elements of the hardware device may be directly coupled to other elements without the bi-directional bus. Additionally, or alternatively to a processor and memory, other electronics, such as integrated circuits, may be employed for performing the required logical operations.The memory 2220 may include any type of non-transitory memory such as static random-access memory (SRAM) , dynamic random-access memory (DRAM) , synchronous DRAM (SDRAM) , read-only memory (ROM) , any combination of such, or the like. The mass storage element 2230 may include any type of non-transitory storage device, such as a solid-state drive, hard disk drive, a magnetic disk drive, an optical disk drive, USB drive, or any computer program product configured to store data and machine executable program code. According to certain aspects, the memory 2220 or mass storage 2230 may have recorded thereon statements and instructions executable by the processor 2210 for performing any of the aforementioned method operations described above.Aspects of the present disclosure can be implemented using electronics hardware, software, or a combination thereof. In some aspects, this may be is implemented by one or multiple computer processors executing program instructions stored in memory. In some aspects, the invention is implemented partially or fully in hardware, for example using one or more field programmable gate arrays (FPGAs) or application specific integrated circuits (ASICs) to rapidly perform processing operations.It will be appreciated that, although specific aspects of the technology have been described herein for purposes of illustration, various modifications may be made without departing from the scope of the technology. The specification and drawings are, accordingly,  to be regarded simply as an illustration of the invention as defined by the appended claims, and are contemplated to cover any and all modifications, variations, combinations or equivalents that fall within the scope of the present invention. In particular, it is within the scope of the technology to provide a computer program product or program element, or a program storage or memory device such as a magnetic or optical wire, tape or disc, or the like, for storing signals readable by a machine, for controlling the operation of a computer according to the method of the technology and / or to structure some or all of its components in accordance with the system of the technology.Acts associated with the method described herein can be implemented as coded instructions in a computer program product. In other words, the computer program product is a computer-readable medium upon which software code is recorded to execute the method when the computer program product is loaded into memory and executed on the microprocessor of the wireless communication device.Further, each operation of the method may be executed on any computing device, such as a personal computer, server, PDA, or the like and pursuant to one or more, or a part of one or more, program elements, modules or objects generated from any programming language, such as C++, Java, or the like. In addition, each operation, or a file or object or the like implementing each said operation, may be executed by special purpose hardware or a circuit module designed for that purpose.Through the descriptions of the preceding aspects, the present invention may be implemented by using hardware only or by using software and a necessary universal hardware platform. Based on such understandings, the technical solution of the present invention may be embodied in the form of a software product. The software product may be stored in a non-volatile or non-transitory storage medium, which can be a compact disc read-only memory (CD-ROM) , USB flash disk, or a removable hard disk. The software product includes a number of instructions that enable a computer device (personal computer, server, or network device) to execute the methods provided in the aspects of the present invention. For example, such an execution may correspond to a simulation of the logical operations as described herein. The software product may additionally or alternatively include a number of instructions that enable a computer device to execute operations for configuring or programming a digital logic apparatus in accordance with aspects of the present invention.Although the present invention has been described with reference to specific features and aspects thereof, it is evident that various modifications and combinations can be made thereto without departing from the invention. The specification and drawings are, accordingly, to be regarded simply as an illustration of the invention as defined by the appended claims, and are contemplated to cover any and all modifications, variations, combinations or equivalents that fall within the scope of the present invention.

Claims

1.A communication network, comprising:a radio access network (RAN) having a central unit (CU) and one or more distributed units (DUs) ; andone or more service modules deployed between the CU and the one or more DUs, the one or more of service modules being configured to provide one or more network services for data processing.2.The communication network of claim [0076] , wherein:the data processing comprises at least one of data analytics, artificial intelligence (AI) training, AI inference, data privacy protection, data collection, data sanitization, data processing, data management, data cleaning, data normalization, useless data filtering, data feature engineering, data compression, data embedding, data representation learning, and data feature extraction.3.The communication network of claim 2, wherein:the one or more of service modules are deployed in one or more of: the RAN, a core network (CN) and a user equipment (UE) .4.The communication network of claim 3, wherein:each service module of the one or more service modules comprises:one or more service controller units to control the one or more network services, andone or more processing function (PF) units to execute one or more tasks associated with the one or more network services;the one or more service controller units being deployed on a control plane;the one or more PF units being deployed on a user plane, a data plane, a computing plane or a data processing plane;the one or more PF units being configured to perform the data processing under control of the one or more service controller units; andthe one or more service controller units being configured to control and configure the one or more PF units for the data processing.5.The communication network of claim 1, wherein the one or more DUs connected to the one or more service modules via a T1 interface.6.The communication network of claim 1, wherein:the CU is connected to each of the one or more service modules via a T2 interface.7.The communication network of claim 4 or claim 5, wherein:the one of the one or more service controller units is connected to the one or more DUs via a T1 interface on the control plane (T1-C interface) .8.The communication network of claim 4 or claim 5, wherein:the one or more PF units are connected to the one or more DUs via a T1 interface on the user plane, the data plane, the computing plane or the data processing plane (T1-U interface) .9.The communication network of claim 4 or claim 6, wherein:the one or more service controller units are connected to the CU via a T2 interface on the control plane (T2-C interface) .10.The communication network of claim 4 or claim 6, wherein:the one or more PF units are connected to the CU via a T2 interface on the user plane, the data plane, the computing plane or the data processing plane (T2-U interface) .11.The communication network of claim 4, wherein:one of the one or more PF units is connected to one of the one or more service controller units via a T3 interface.12.The communication network of any one of claims 4, wherein:one of the one or more service controller units is connected to the one or more PF units via a T3 interface.13.The communication network of claim 4, wherein:different PF units in a same service module or in a different service module of the one or more service modules are interconnected via a T4 interface.14.The communication network of claim 4, wherein:different service controller units in a same service module or in a different service module of the one or more service modules are interconnected through a T5 interface.15.The communication network of claim 4, wherein:one of the one or more PF units is connected, directly or indirectly, to a CN function (CNF) via a T6 interface.16.The communication network of claim 15, wherein:the one of the one or more PF units is connected to the CNF via the T6 interface indirectly, through an intermediate CU.17.The communication network of claim 4, wherein:one of the one or more service controller units is connected, directly or indirectly, to a CN function (CNF) via a T7 interface.18.The communication network of claim 17, wherein:the one of the one or more service controller units is connected to the CNF via the T7 interface indirectly, through an intermediate CU.19.The communication network of any one of claims 15 to 18, wherein:the CNF is one of: a service module in the CN, a PF unit in the CN, a service controller unit in the CN, and a function for data forwarding; andthe function for data forwarding is one of: a user plane function (UPF) , an evolved UPF, or a gateway function.20.The communication network of any one of claim 1 and claim 3, wherein:different service modules of the one or more service modules are interconnected via a T8 interface.21.The communication network of claim 20, wherein:the T8 interface is an integration of a T4 interface with a T5 interface.22.The communication network of any one of claims of 1-21, wherein:the one or more DUs are connected to the CU via an F1 interface.23.The communication network of claim 4, wherein:an application layer signaling protocol on the control plane has interfaces T1, T2, T3, T5, T7 and T8, which are respectively referred to as a T1 Application Protocol (T1AP) , a T2 Application Protocol (T2AP) , a T3 Application Protocol (T3AP) , a T5 Application Protocol (T5AP) , a T7 Application Protocol (T7AP) , and a T8 Application Protocol (T8AP) ; andunderlay protocol stacks of one or more of the T1AP, the T2AP, the T3AP, the T5AP, the T7AP and the T8AP include one or more of:a General Packet Radio Service (GPRS) Tunneling Protocol for a user plane (GTP-U) ,a User Datagram Protocol (UDP) ,an Internet Protocol (IP) ,a Quick UDP Internet Connections (QUIC) protocol,a Hypertext Transfer Protocol (HTTP) ,a Stream Control Transmission Protocol (SCTP) , anda Segment Routing over IPv6 (SRv6) protocol.24.The communication network of claim 4, wherein underlay protocol stacks on the user plane for one or more of a T1 interface, a T2 interface, a T4 interface, a T6 interface and a T8 interface include one or more of:a General Packet Radio Service (GPRS) Tunneling Protocol for a user plane (GTP-U) ,a User Datagram Protocol (UDP) ,an Internet Protocol (IP) ,a Quick UDP Internet Connections (QUIC) protocol,a Hypertext Transfer Protocol (HTTP) ,a Stream Control Transmission Protocol (SCTP) , anda Segment Routing over IPv6 (SRv6) protocol.25.The communication network of claim 23 or 24 further comprising: on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol  stacks:a PF sublayer, at the one or more PF units, deployed on top of a packet data convergence protocol (PDCP) sublayer;a corresponding PF sublayer, at the UE, deployed:on top of a respective PDCP sublayer; orbetween a SDAP sublayer and the respective PDCP sublayer;a radio link control (RLC) sublayer and a medium access control (MAC) sublayer deployed at the UE;a physical (PHY) layer deployed at the UE;an RLC sublayer and a MAC sublayer deployed at the one or more DUs;a PHY layer deployed at the one or more DUs; anda respective SDAP sublayer deployed at the CU.26.The communication network of claim 23 or 24 further comprising, on the control plane, over the underlay protocol stacks:a service controller sublayer, at the one or more service controller units, deployed on top of a packet data convergence protocol (PDCP) sublayer;a corresponding service controller sublayer, at the UE, deployed on top of a PDCP sublayer;a radio link control (RLC) sublayer and a medium access control (MAC) sublayer deployed at the UE;a physical (PHY) layer deployed at the UE;an RLC sublayer and a MAC sublayer deployed at the one or more DUs; anda PHY layer deployed at the one or more DUs.27.The communication network of claim 23 or 24, wherein the one or more PF units are integrated into the CU, the communication network further comprising:on the user plane, the data plane, the computing plane, or the data processing plane over the underlay protocol stacks:a PF sublayer, at the CU, deployed:on top of a packet data convergence protocol (PDCP) sublayer, or between the PDCP sublayer and a service data adaptation protocol (SDAP) sublayer;an RLC sublayer, a MAC sublayer and a PHY layer deployed at the one or more  DUs;at the UE:a PF sublayer:on top of the PDCP sublayer, orbetween the PDCP sublayer and an SDAP sublayer;an RLC sublayer;a MAC sublayer; anda PHY layer.28.The communication network of claim 23 or 24, wherein the one or more control units are integrated into the CU, the communication network further comprising, on the control plane over the underlay protocol stacks:at the CU:a service controller sublayer deployed:on top of a packet data convergence protocol (PDCP) sublayer; orbetween the PDCP sublayer and a radio resource controller (RRC) sublayer; oron top of the RRC sublayer;at the one or more DUs:a PHY layer deployed, an RLC sublayer and a MAC sublayer; andat the UE:a service controller sublayer deployed:on top of the PDCP sublayer; orbetween a PDCP sublayer and a RRC sublayer; oron top of the RRC sublayer; andan RLC sublayer, a MAC sublayer and a PHY layer.29.The communication network of claim 23 or 24, wherein:the one or more PF units are deployed between the one or more DUs and the CU; anda first PF unit of the one or more PF units comprises:a PF sublayer:deployed on top of a packet data convergence protocol (PDCP) sublayer; andcorresponding to a PF sublayer of the UE;the PDCP sublayer corresponding to a PDCP sublayer of the UE.30.The communication network of claim 29 further comprising:a second PF unit of the one or more PF units deployed between the one or more DUs and the CU, wherein the first PF unit further comprises:a second PF sublayer corresponding to a PF sublayer of the second PF unit, the second PF sublayer deployed on top of a second PDCP sublayer of the first PF unit.31.The communication network of claim 24, wherein:the CU is configured to perform at least one of:one or more functions of a packet data convergence protocol (PDCP) sublayer for header (de) compression; anda sequence numbering of a PDCP service data unit (SDU) ;the one or more PF units are configured to perform one or more functions of a PDCP sublayer for security protection, wherein the one or more functions relate to one or more of: integrity protection and ciphering.32.The communication network of claim 1, wherein:a network service of the one or more network services is identified by a network service identifier (ID) ;the network service ID comprises one or more of:a service type ID,a task ID,a mission ID, anda network ID;the service type ID identifies a service type of the network service;the task ID identifies a data processing task for which the network service is configured to execute;the mission ID identify a mission for which the network service is configured to execute, the mission comprising one or more of tasks; andthe network ID identifies a network providing the network service.33.The communication network of claim 4, further comprising plurality of network nodes, wherein:two network nodes of the plurality of network nodes are configured to exchange their capability on the one or more network services;each of the two network nodes is one of:a service module of the one or more service modules,a PF unit of the one or more PF units,a service controller unit of the one or more service controller units,a DU of the one or more DU, andthe CU.34.The communication network of claim 32, wherein:the two network nodes are configured to exchange their capability by having a first node of the two network nodes sending a first message to a second node of the two network nodes, the message including one or more of:a node identifier (ID) identifying the first node,a cell ID identifying a cell providing a network service of the one or more network services,a tracking area ID identifying a tracking area providing a network service of the one or more network services,a network service ID identifying the network service, anda network ID identifying the network providing the network service, wherein the network ID is one of: a public land mobile network (PLMN) ID, or a non-public network (NPN) ID.35.The communication network of claim 33, wherein:the two network nodes are configured to exchange their capability by further having the second node sending a second message to the first node, the second message including one or more of:a node ID identifying the second node,a second cell ID,a second tracking area ID,a second network service ID, anda second network ID.36.The communication network of claim 34, wherein:one or more of the node ID identifying the second node, the second cell ID, the second network service ID, and the second network ID included in the second message are the same as the one or more of the node ID, the cell ID, the network service ID, and the network ID included in the first message.37.The communication network of claims 33, wherein:the second node is configured to send a failure message to the first node when the second node determines that capability of the second node to provide the network service does not overlap with that of the first node.38.The communication network of any one of claims 33, wherein:a network node of the plurality of network nodes sends to the UE a message identifying the one or more network services, the message including one or more of: a cell identifier (ID) , a network service ID, and a network ID;the network ID is one of a public land mobile network (PLMN) ID, or a non-public network (NPN) ID.39.The communication network of claim 38, wherein: the message is one of a unicast message or a multicast / broadcast message.40.The communication network of claim 39, wherein the message is a unicast message, the message is one of a dedicated radio resource control (RRC) message, and a dedicated signaling message.41.The communication network of claim 39, wherein the message is a multicast / broadcast message, the message is a system information (SI) message.42.The communication network of claim 38, wherein:after receiving the message, the UE selects a network service from the one or more network service to access and sends a second message to a the network node;the second message includes one or more of: a network service ID associated with the selected network service, a network ID associated with the selected network service, a cell ID associated with the selected network service; andthe second message is a dedicated radio resource control (RRC) message, or a  dedicated signaling message for the network service.43.The communication network of any one of claims 25, 27 and 29, wherein:the PF sublayer is configured to perform privacy protection on data processing at one or more of: the one or more PF units, the UE, and the CU; andthe PDCP sublayer is configured to perform security protection on data forwarding at the one or more of: the one or more PF units, the one or more service controller units, the CU, and the UE.44.The communication network of claim 4, wherein the communication network supports one or more access stratum (AS) security modes, each AS security mode indicates that none, one or more than one of security protection and privacy protection are to be executed for the one or more network services on one or both of a user plane (UP) and a control plane (CP) .45.The communication network of claim 44, wherein the one or more AS security modes indicate that:a packet data convergence protocol (PDCP) sublayer (e.g., for ciphering and integrity) is to execute the security protection for the one or more network services on the UP; ora PF sublayer (e.g., for privacy protection) is to execute the privacy protection for the one or more network services on the UP; orthe PDCP sublayer is to execute the security protection and the PF sublayer is to execute the privacy protection for the one or more network services on the UP; ornone of the PDCP sublayer and the PF sublayer are to execute the security protection or the privacy protection for the network services on the UP.46.The communication network of claim 44, wherein the one or more AS security modes indicate that:a packet data convergence protocol (PDCP) sublayer is to execute the security protection for the one or more network services on the CP; ora service controller sublayer is to execute the privacy protection for the one or more network services on the CP; orthe PDCP sublayer is to execute the security protection for the one or more network services on the CP and the service controller sublayer is to execute the privacy protection for the network service on the CP; ornone of the PDCP sublayer and the service controller sublayer are to execute the security protection or the privacy protection for the one or more network services on the CP.47.The communication network of claim 44, wherein:the one or more AS security modes indicate one or more security algorithms according to which one or more of the security protection and privacy protection are to be executed;the one or more security algorithms include one or more of:a ciphering algorithm and an integrity algorithm on a packet data convergence protocol (PDCP) sublayer;privacy protection algorithm on a PF sublayer; andprivacy protection algorithm on a controller sublayer.48.The communication network of claim 44, wherein:the one or more supported AS security modes are configured at one or more of: the one or more the service modules, the one or more PF units, the UE, the CU, the one or more service controller units, and an aggregated RAN node; and the aggregated RAN node including two or more of: the one or more the service modules, the one or more PF units, the CU, the one or more service controller units, and the one or more DUs.49.The communication network of claim 48, wherein:a first network node notifies, via an AS security mode notification procedure, a second network node of one or more AS security modes supported at the first network node.50.The communication network of claim 49 wherein:the AS security mode notification procedure includes the first network node sending a message to the second network node; andthe message including one or more of:one or more AS security mode IDs, each AS security mode ID identifying a supported AS security mode of the first node,a priority for each of the supported AS security modes, anda corresponding quality of service (QoS) guaranteed by each of the supported AS security mode for the one or more network services.51.The communication network of claim 50, wherein:the first network node is the UE;the second network node is one of: a service module of the one or more service modules, the CU, a service controller unit of the one or more service controller units, the integrated RAN node, and a CN function (CNF) ; andthe first network node sending a message to the second network node comprises the UE sending a report indicating its one or more supported AS security modes to the second network node.52.The communication network of claim 51, wherein: the AS security mode notification procedure further comprises, after receiving the report from the UE, the second network node selecting an AS security mode for the UE, and sending an AS security configuration to the UE;the AS security configuration include one or more of: the selected AS security mode and AS security parameters;wherein the AS security configuration is sent to the UE via one or more of: a dedicated radio resource control (RRC) message, a dedicated signaling message for the one or more network services, and a non-access stratum (NAS) message.53.The communication network of claim 52, wherein the dedicated RRC message is an AS security mode command message.54.The communication network of claim 53, wherein the AS security mode notification procedure further comprises, based on the AS security configuration, on the UP, the UE performing one or more of:an uplink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection on data forwarding;a downlink deciphering on the PDCP sublayer for security protection on data forwarding;an uplink ciphering on a PF sublayer for privacy protection on data processing; anda downlink deciphering on the PF sublayer for privacy protection on data processing.55.The communication network of claim 53 or 54, wherein the AS security mode notification procedure further comprises, based on the AS security configuration, on the CP, the UE performing one or more of:an uplink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection;a downlink deciphering on the PDCP sublayer for security protection;an uplink ciphering on a service controller sublayer for privacy protection; anda downlink deciphering on the service controller sublayer for privacy protection.56.The communication network of claim 53 or 54, wherein the AS security mode notification procedure further comprises, based on the AS security configuration, on the UP, the second network node performing one or more of:a downlink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection on data forwarding;an uplink deciphering on the PDCP sublayer for security protection on data forwarding;a downlink ciphering on a PF sublayer for privacy protection on data processing; andan uplink deciphering on the PF sublayer for privacy protection on data processing.57.The communication network of claim 53 or 54, wherein the AS security mode notification procedure further comprises, based on the AS security configuration, on the CP, the second network node performing one or more of:a downlink ciphering on a packet data convergence protocol (PDCP) sublayer for security protection;an uplink deciphering on the PDCP sublayer for security protection;a downlink ciphering on a service controller sublayer for privacy protection; andan uplink deciphering on the service controller sublayer for privacy protection.58.The communication network of any one of claims 53 to 57, wherein: the AS security mode notification procedure further comprises, based on the selected AS security mode, RAN performing one or more of:a downlink ciphering on one or more of:a packet data convergence protocol (PDCP) sublayer for data forwarding associated with a service data bearer (XDB) on a service UP; anda PF sublayer associated with the XDB on the service UP;an uplink deciphering on one or more of:the PDCP sublayer for data forwarding associated with the XDB on the service UP; andthe PF sublayer associated with the XDB on the service UP;a downlink ciphering on one or more of:a PDCP sublayer associated with a service signaling bearer (XSB) on a service CP; anda service controller sublayer associated with the XSB on the service CP; andan uplink deciphering on one or more of:the PDCP sublayer associated with the XSB on the service CP; andthe service controller sublayer associated with the XSB on the service CP.59.The communication network of claim 50, wherein:the first network node is the one or more PF units and the second network node is a service controller unit of the one or more service controllers;each of the one or more PF units sends a message to the service controller unit.60.The communication network of claim 52, wherein:the second network node is a service controller unit of the one or more service controller units;the service controller unit selects a PF unit of the one or more PF units to serve the UE;the selected PF unit supports one or more AS security modes overlapped with the one or more AS security modes supported by the UE;the service controller unit selects an AS security mode supported by one or more of the UE, the selected PF unit and the service controller.61.The communication network of claims 60, wherein:the service controller unit sends the PF unit an AS security configuration corresponding to the AS security configuration of the UE.62.The communication network of claim 61, wherein based on the AS security configuration received from the service controller unit, the selected PF unit performs one or more of:on user plane (UP) , a downlink ciphering on one or more of: a packet data convergence protocol (PDCP) sublayer and PF sublayer;on the UP, an uplink deciphering on one or more of: the PDCP sublayer and the PF sublayer;on control plane (CP) , a downlink ciphering on one or more of: the PDCP sublayer and a service controller sublayer; andon control plane (CP) , an uplink deciphering on one or more of: the PDCP sublayer and the service controller sublayer.63.The communication network of any one of claims 4, 7 to 19, 24, 26, 28, 31, 37 to 42, 44, 46, 48 to 53, 55, 57, 59 to 61, and 62 wherein:a data bearer for the one or more network services is established between the UE and a service module of the one or more service modules on the RAN.64.The communication network of claims 63, wherein:the data bearer for the one or more network services is established between a PF protocol layer on a UE side and a PF protocol layer on a PF unit side of a service module of the one or more service module;the PF protocol layer on UE side and the PF protocol layer on the PF unit side belong to the data bearer.65.The communication network of any one of claims 4, 7-19, 23-25, 29 to 31, 33-35, 37-45, 48 to 54, 59-61, 63 and 64 wherein:a signaling bearer for the one or more network services is established between the UE and a service module of the one or more service modules on the RAN.66.The communication network of claims 65, wherein:the signaling bearer for the one or more network services is established between a service controller protocol layer on a UE side and a service controller protocol layer on a service controller unit side of the service module;the service controller protocol layer on the UE side and the service controller protocol layer on the service controller unit side belong to the signaling bearer.67.The communication network of any one of claims 63 to 66, wherein:one or more of security protection on data forwarding and privacy protection on data processing are executed for one or more of the data bearer of the one or more network services and the signaling bearer of the one or more network services.68.The communication network of claim 48, wherein:after receiving the second message, the network node setups for the selected network service one or more of: a data bearer and a signaling bearer; andthe network node sends bearer configuration information to the UE.69.The communication network of claims 68, wherein:the bearer configuration information includes AS security configuration;the AS security configuration including one or more of: a selected AS security mode and AS security parameters.70.The communication network of claims 1-64, whereina service module of the one or more service modules connects to a CN function (CNF) directly or via the CU.71.The communication network of claim 4 further establishing one or more sessions on a user plane to provide the one or more network services to the UE, the one or more sessions involving one or more of: one or more service modules on RAN side, one or more service modules on CN side, the one or more DUs, one or more CUs, one or more PF units on RAN side, one or more PF units on CN side, and the UE.72.The communication network of claims 71, wherein:the one or more sessions includes one or more of quality of service (QoS) flows of the one or more network services, a single QoS flow of the one or more QoS flows  being a finest granularity of QoS differentiation in the session;traffic in a same QoS flow of the one or more QoS flows receives a same data forwarding treatment and data processing treatment.73.The communication network of claim 71 or 72, wherein:The one or more QoS flows are mapped, by a service data adaptation protocol sublayer, to one or more data bearer for the one or more network services.74.The communication network of any one of claims 71-73, wherein:the UE sends a request message to the communication network for establishment of the one or more sessions; andthe request message includes one or more of: a session identifier (ID) , a QoS flow ID, a QoS requirement, a network service ID, a network ID, a UE ID, and a UE group ID.

Citation Information

Patent Citations

  • Containerized router with a disjoint data plane

    US20220286940A1

  • Ultra-reliable and low latency communications local breakout method and system for next generation radio access network

    US20220345361A1

  • Selective user plane protection in 5g virtual ran

    WO2021186215A1