Establishing secure connection
The method addresses the lack of secure key establishment in 5G ProSe systems by dynamically generating a pre-shared key using AKMA and TLS v1.3 with PSK authentication, ensuring secure and reliable communication by verifying UE and AF capabilities.
Patent Information
- Application Number
- JP2025113414
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2020-10-02
- Filing Date
- 2025-07-04
- Publication Date
- 2025-10-22
AI Technical Summary
The existing 5G ProSe communication systems lack a secure method for establishing a shared key between the UE and the ProSe function, assuming the AF supports the AKMA procedure, which may not always be the case, leading to potential security vulnerabilities.
A method is introduced to dynamically generate a new pre-shared key (KAF) using the AKMA procedure, ensuring the 3GPP network and AF support AKMA, and utilizing TLS v1.3 with PSK authentication to establish a secure connection between the UE and the AF, with the UE indicating its AKMA capability during registration.
This approach ensures secure and reliable communication by verifying the UE's and AF's AKMA capabilities, enabling secure key establishment without separate authentication, thus enhancing network security and compatibility.
Smart Images

Figure 2025160214000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates generally to communications, and more particularly to communication methods and associated devices and nodes that support wireless communications. [Background technology]
[0002] In 3GPP TR 23.752, SA2 is developing an architecture option called the "User Plane-Based Architecture." This architecture proposes adopting the functionality for Proximity Services (ProSe) functions specified in TS 23.303 into the 5G system architecture. According to 3GPP TS 23.303, a Direct Discovery Name Management Function (DDNMF) and a Direct Provisioning Function (DPF) for ProSe functions are required to support ProSe in the 5G system architecture. The DPF is used to provision the UE with the necessary parameters to use 5G ProSe Direct Discovery and 5G ProSe Direct Communication, which can replace the Policy Control Function (PCF). The DDNMF is used to provide the following procedures over the PC3 interface: - A discovery request / response procedure to provide IDs and filters for direct discovery. - Match reporting procedures to confirm direct discoveries and provide mapping information for direct discoveries. - Alarm reporting procedures to support "on-demand" ProSe Direct Discovery in case of ProSe Limited Discovery Model A. - Discovery update procedure to update / revoke previously assigned IDs, filters.
[0003] 5GS supports a service-based architecture, and the DDNMF may be a network function (NF) that is not only capable of interacting with 5G NFs (e.g., to consume Nudm service operations) but also connects with UEs via user plane connectivity to support procedures over the PC3 interface. In the architecture, it is proposed to introduce a 5G DDNMF as shown in Figure 1. The 5G DDNMF shown in Figure 1 is managed by a mobile network operator (MNO). The 5G DDNMF is capable of consuming service operations from other NFs in 5GC (e.g., Nudm or Npcf).
[0004] The PC3 interface supports the following basic functions specified in 3GPP TS 23.303: discovery request / response, match reporting procedure, alarm reporting procedure, and discovery update procedure. Which Network Slice Selection Assistance Information (NSSAI) or Data Network Name (DNN) should be used for user plane connectivity for the PC3 interface is up to the MNO configuration (e.g., it can be controlled by the UE Route Selection Policy (URSP) or local configuration in the UE). Authentication and Key Management (AKMA) functions for applications are specified in 3GPP TS 33.535.
[0005] Figure 2 illustrates the AKMA network model, as well as the interfaces between them. There is no separate authentication of the UE to support the AKMA functionality. Instead, it reuses the 5G primary authentication procedure, performed, for example, during UE registration, to authenticate the UE. A successful 5G primary authentication is performed by the K AUSF is stored in the Authentication Server Function (AUSF) and the UE.
[0006] During the primary authentication procedure, the AUSF interacts with the Unified Data Management (UDM) to fetch authentication information such as subscription credentials (e.g., AKA authentication vector) and authentication method using the Nudm_UEAuthentication_Get request service operation. In response, the UDM may also indicate to the AUSF whether an AKMA key needs to be generated for the UE. If the AUSF receives an AKMA indication from the UDM, the AUSF will generate the K AUSF Remember, K AUSF From AKMA anchor key (K AKMA After the AKMA keying material is generated, the AUSF sends the generated A-KID and K along with the UE Subscriber Permanent Identifier (SUPI) to the AKMA Anchor Function (AAnF) using the Naanf_AKMA_KeyRegistration request service operation, as shown in Figure 2. AKMA The AAnF stores the latest information sent by the AUSF.
[0007] Before initiating communication with the AKMA application function, the UE AUSF From AKMA anchor key (K AKMA ) and A-KID. The A-KID is the UE's KID from which the other AKMA keys are derived. AKMA Identifies the key. The A-KID is in the Network Access Identifier (NAI) format specified in section 2.2 of IETF RFC 7542, i.e., username@realm. The username part contains the routing identifier and the A-TID (AKMA Temporary UE Identifier), and the realm part contains the home network identifier.
[0008] A-TID is a K AUSF It is derived from K AKMA The key derivation of K is performed using the Key Derivation Function (KDF) specified in TS 33.220 [5]. AKMA is K AKMA=KDF(K AUSF , "AKMA", SUPI) (per Annex A.2), where the key derivation parameters consist of the static string "AKMA" and SUPI. The AKMA key is calculated using the K AUSF , the AKMA key can only be refreshed by performing a fresh primary authentication. Figure 3 illustrates the procedure used by an Application Function (AF) to request an Application Function specific AKMA key directly from the 5G Core (5GC) when the AF is located in the operator's network.
[0009] FIG. 3 shows that after the first authentication, the UE AUSF K from key AF 1 illustrates the generation of an A-KID and the generation of an A-KID. The UE requests the AF to establish a secure connection with the UE. The UE includes the A-KID to the AF in an application establishment request message to the AF. The AF contacts the AAnF using the A-KID and AF ID. The AAnF uses the AF ID as input to generate the K AUSF AAnF generates a KAF key from the key. AAnF sends the KAF key to AF along with the expiration time. AF Provide the key.
[0010] In ProSe in 4G systems, the PC3 interface is protected by establishing a shared key between the UE and the ProSe function by using the GBA (Generic Bootstrapping Architecture) procedure in Evolved Packet Systems (EPS) systems. GBA is specified in TS 33.220 [5]. In ProSe in 5G systems, one option is to establish a shared key (K AF However, the current solution assumes that the AF providing the ProSe service supports the AKMA procedure and that the UE is authorized to utilize the AKMA procedure, which may not be the case. Summary of the Invention
[0011] In some embodiments, a method is performed by a control network node for establishing a secure connection in a wireless communication network, the method including receiving a request to use a communication service provided by the wireless communication network, the request including an indication that the communication device can support the requested communication service and an AKMA service provided by the wireless communication network, determining whether the requested communication service and the AKMA service can be provided to the communication device, and communicating information to the communication device indicating whether the requested communication service and the AKMA service can be provided to the communication device to establish a secure connection in the wireless communication network.
[0012] In some embodiments, a method is performed by a communication device for establishing a secure connection in a wireless communication network, the method including: communicating a request to use a communication service provided by the wireless communication network, the request including an indication that the communication device can support the requested communication service and an AKMA service provided by the wireless communication network; and receiving, in response to communicating the request, a communication comprising information indicating whether the requested communication service and the AKMA service can be provided to the communication device for establishing the secure connection in the wireless communication network.
[0013] In some embodiments, a network node implements a method for establishing a secure connection in a wireless communication network, the method including receiving a request from a core network node for AKMA service availability information indicating whether the network node can provide AKMA services for establishing a secure connection for a requested communication service between a communication device operating in the wireless communication network and the network node, and communicating the AKMA service availability information to the core network node indicating whether the network node can provide AKMA services for establishing the secure connection for the requested communication service.
[0014] The accompanying drawings, which are included to provide a further understanding of the present disclosure and are incorporated in and constitute a part of this application, illustrate certain non-limiting embodiments of the inventive concepts. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is a block diagram illustrating an example 5G system architecture for ProSe services, in accordance with some embodiments of the present disclosure. [Figure 2] FIG. 1 illustrates a basic network model of an AKMA, according to some embodiments of the present disclosure. [Figure 3] 1 is a signal flow diagram illustrating a procedure for deriving an AKMA root key after primary authentication according to some embodiments of the present disclosure. [Figure 4] FIG. 10 is a signal flow diagram illustrating a procedure used by an AF to request an application function specific AKAMA key directly from a 5GC, according to some embodiments of the present disclosure. [Figure 5] 1 is a block diagram illustrating a wireless device UE according to some embodiments of the present disclosure. [Figure 6]FIG. 1 is a block diagram illustrating a radio access network RAN node (e.g., base station eNB / gNB) in accordance with some embodiments of the inventive concept. [Figure 7] A block diagram illustrating a core network CN node (e.g., an AMF node, an SMF node, etc.) according to some embodiments of the inventive concept. [Figure 8] FIG. 10 is a signal flow diagram illustrating a PCF inquiring about the AF's capability to support AKAMA, according to some embodiments of the present disclosure. [Figure 9A] FIG. 1 is a signal flow diagram illustrating a procedure for establishing a secure connection between an AF and a UE, according to some embodiments of the present disclosure. [Figure 9B] FIG. 1 is a signal flow diagram illustrating a procedure for establishing a secure connection between an AF and a UE, according to some embodiments of the present disclosure. [Figure 9C] FIG. 1 is a signal flow diagram illustrating a procedure for establishing a secure connection between an AF and a UE, according to some embodiments of the present disclosure. [Figure 10] 1 is a flowchart illustrating the operation of a core network node according to some embodiments of the present disclosure. [Figure 11] 10 is a flowchart illustrating the operation of a core network node, including communicating information indicating that a communications device is allowed to use an AKMA service, according to some embodiments of the present disclosure. [Figure 12] 10 is a flowchart illustrating the operation of a core network node, including communicating information indicating that a communications device is unable to use AKMA services, in accordance with some embodiments of the present disclosure. [Figure 13] 10 is a flowchart illustrating the operation of a core network node, including communicating information indicating that a requested communication service and AKMA service cannot be provided, according to some embodiments of the present disclosure. [Figure 14]1 is a flowchart illustrating the operation of a communications device according to some embodiments of the present disclosure. [Figure 15] 10 is a flowchart illustrating the operation of a communications device, including establishing a secure connection with an AF based on a PSK identity, in accordance with some embodiments of the present disclosure. [Figure 16] 1 is a flowchart illustrating the operation of a network node according to some embodiments of the present disclosure. [Figure 17] 1 is a flowchart illustrating the operation of a network node, including establishing a secure connection with a communication device based on a PSK identity, in accordance with some embodiments of the present disclosure. [Figure 18] 1 is a block diagram of a wireless network according to some embodiments. [Figure 19] FIG. 2 is a block diagram of a user equipment according to some embodiments. [Figure 20] FIG. 1 is a block diagram of a virtualized environment, according to some embodiments. [Figure 21] FIG. 1 is a block diagram of a communications network connected to a host computer through an intermediate network, according to some embodiments. [Figure 22] FIG. 1 is a block diagram of a host computer communicating with user equipment via a base station over a partially wireless connection, according to some embodiments. [Figure 23] 1 is a block diagram of a method implemented in a communication system including a host computer, a base station, and user equipment, according to some embodiments. [Figure 24] 1 is a block diagram of a method implemented in a communication system including a host computer, a base station, and user equipment, according to some embodiments. [Figure 25] 1 is a block diagram of a method implemented in a communication system including a host computer, a base station, and user equipment, according to some embodiments. [Figure 26]1 is a block diagram of a method implemented in a communication system including a host computer, a base station, and user equipment, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0016] The inventive concepts will now be described more fully hereinafter with reference to the accompanying drawings, in which example embodiments of the inventive concepts are shown. However, the inventive concepts may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concepts to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. It can be implicitly assumed that elements from one embodiment are present / used in another embodiment.
[0017] The following description presents various embodiments of the disclosed subject matter. These embodiments are presented as instructional examples and should not be construed as limiting the scope of the disclosed subject matter. For example, some details of the described embodiments may be modified, omitted, or expanded without departing from the scope of the described subject matter.
[0018] 5 is a block diagram illustrating elements of a communications device UE 300 (also referred to as a mobile terminal, mobile communications terminal, wireless device, wireless communications device, wireless terminal, mobile device, wireless communications terminal, user equipment (UE), user equipment node / terminal / device, etc.) configured to provide wireless communications in accordance with the claims of the inventive concept. (Communications device 300 may be provided, for example, as discussed below with respect to wireless device 4110 of FIG. 18.) As shown, communications device UE may include antenna 307 (e.g., corresponding to antenna 4111 of FIG. 18) and radio transceiver circuitry 301 (e.g., also referred to as a transceiver, corresponding to interface 4114 of FIG. 18) including a transmitter and a receiver configured to provide uplink and downlink wireless communications with base stations of a radio access network (e.g., corresponding to network node 4160 of FIG. 18, also referred to as a RAN node). The communications device UE may also include a processing circuit 303 (e.g., corresponding to processing circuit 4120 of FIG. 18 , also referred to as a processor) coupled to the transceiver circuit, and a memory circuit 305 (e.g., corresponding to device-readable medium 4130 of FIG. 18 , also referred to as a memory) coupled to the processing circuit. The memory circuit 305 may include computer-readable program code that, when executed by the processing circuit 303, causes the processing circuit to perform operations according to the claims disclosed herein. According to other embodiments, the processing circuit 303 may be defined to include memory such that a separate memory circuit is not required. The communications device UE may also include an interface (e.g., a user interface) coupled to the processing circuit 303, and / or the communications device UE may be incorporated into a vehicle.
[0019] As discussed herein, operations of the communication device UE may be performed by the processing circuitry 303 and / or the transceiver circuitry 301. For example, the processing circuitry 303 may control the transceiver circuitry 301 to transmit communications through the transceiver circuitry 301 over an air interface to a radio access network node (also called a base station) and / or receive communications through the transceiver circuitry 301 over an air interface from a RAN node. Moreover, modules may be stored in the memory circuitry 305 that, when executed by the processing circuitry 303, cause the processing circuitry 303 to perform respective operations (e.g., operations discussed below with respect to exemplary embodiments relating to wireless communication devices).
[0020] 6 is a block diagram illustrating elements of a radio access network (RAN) node 400 (also referred to as a network node, base station, eNodeB / eNB, gNodeB / gNB, etc.) of a RAN configured to provide cellular communications in accordance with the claimed inventive concept. (The RAN node 400 may be provided, for example, as discussed below with respect to network node 4160 of FIG. 18.) As shown, the RAN node may include radio transceiver circuitry 401 (e.g., corresponding to part of interface 4190 of FIG. 18 , also referred to as a transceiver) including a transmitter and a receiver configured to provide uplink and downlink wireless communications with mobile terminals. The RAN node may include network interface circuitry 407 (e.g., corresponding to part of interface 4190 of FIG. 18 , also referred to as a network interface) configured to provide communications with other nodes of the RAN and / or core network CN (e.g., with other base stations). The network node may also include a processing circuit 403 (e.g., corresponding to processing circuit 4170, also referred to as a processor) coupled to the transceiver circuit, and a memory circuit 405 (e.g., corresponding to device-readable medium 4180 of FIG. 18, also referred to as a memory) coupled to the processing circuit. The memory circuit 405 may include computer-readable program code that, when executed by the processing circuit 403, causes the processing circuit to perform operations according to the claims disclosed herein. According to other embodiments, the processing circuit 403 may be defined to include memory such that a separate memory circuit is not required.
[0021] As discussed herein, operations of the RAN node may be performed by the processing circuitry 403, the network interface 407, and / or the transceiver 401. For example, the processing circuitry 403 may control the transceiver 401 to transmit downlink communications through the transceiver 401 over the air interface to one or more mobile terminals UE and / or receive uplink communications through the transceiver 401 over the air interface from one or more mobile terminals UE. Similarly, the processing circuitry 403 may control the network interface 407 to transmit communications through the network interface 407 to one or more other network nodes and / or receive communications through the network interface from one or more other network nodes. Moreover, modules may be stored in the memory 405 that, when executed by the processing circuitry 403, cause the processing circuitry 403 to perform respective operations (e.g., operations discussed below with respect to exemplary embodiments relating to a RAN node).
[0022] According to some other embodiments, the network node may be implemented as a core network CN node lacking a radio transceiver. In such embodiments, a transmission to the wireless communication device UE may be initiated by the network node such that the transmission to the wireless communication device UE is provided through a network node including a radio transceiver (e.g., through a base station or a RAN node). According to claims in which the network node is a RAN node including a transceiver, initiating the transmission may include transmitting through the transceiver.
[0023] 7 is a block diagram illustrating elements of a core network CN node (e.g., an SMF node, an AMF node, a PCF node, etc.) of a communications network configured to provide cellular communications in accordance with the claims of the inventive concept. As shown, the CN node may include a network interface circuit 507 (also referred to as a network interface) configured to provide communications with other nodes in the core network and / or radio access network RAN. The CN node may also include a processing circuit 503 (also referred to as a processor) coupled to the network interface circuit and a memory circuit 505 (also referred to as a memory) coupled to the processing circuit. The memory circuit 505 may include computer-readable program code that, when executed by the processing circuit 503, causes the processing circuit to perform operations in accordance with the claims disclosed herein. According to other embodiments, the processing circuit 503 may be defined to include memory such that a separate memory circuit is not required.
[0024] As discussed herein, the operations of a CN node may be performed by the processing circuitry 503 and / or the network interface circuitry 507. For example, the processing circuitry 503 may control the network interface circuitry 507 to send communications to one or more other network nodes through the network interface circuitry 507 and / or to receive communications from one or more other network nodes through the network interface circuitry. Moreover, modules may be stored in the memory 505 that, when executed by the processing circuitry 503, cause the processing circuitry 503 to perform respective operations (e.g., operations discussed below with respect to exemplary embodiments relating to core network nodes).
[0025] The method and device described herein allows the AKMA procedure to dynamically generate a new pre-shared key (K AF), which implies that the 3GPP network and AF need to support AKMA. The AF needs to support connection to the AAnF in AKMA as described in TS 33.535 [6]. It should be understood that the methods and devices described herein can be mapped to any Application Function (AF) used for any service. The ProSe service is used throughout this disclosure as an example where the service helps the Policy Control Function (PCF) determine which AF the UE needs to contact.
[0026] This disclosure assumes that TLS v1.3 with Pre-Shared Key (PSK) authentication as specified in RFC 8446 is used to set up a secure connection between the UE and the AF. The UE sends the A-KID (K AKMA The AF should include a "3GPP-akma" hint that the UE supports and wishes to use AKMA (key identifier) and should include a hint that the UE supports and wishes to use AKMA by including the "3GPP-akma" hint. The AF can be any application function that supports TLS v1.3 with PSK authentication. For ProSe services, the AF can be mapped to any application function used for the ProSe service, for example, the 5G DDNMF and PC3 interface specified in TS 23.502
[88] , or the new key management function used by ProSe services in 5G. Another option could be to use IPsec with PSK authentication in IKEv2 in RFC 5996.
[0027] The UE and the network can perform a secure negotiation to use the AKMA procedure to establish a pre-shared key in the UE and the AF (Application Function). A secure connection can be established between the UE and the AF using the pre-shared key established from the AKMA procedure. The UE and the network need to securely negotiate which AKMA procedure will be used. This implies the following: - The home PLMN has AKMA capability. - The UE has AKMA capability. - The AF has AKMA capability and an interface to the AAnF.
[0028] The UE includes its UE capability to support the AKMA procedure in the registration request message. Whether the UE is enabled to use the AKMA service and whether the UE is enabled to use the ProSe service are configured in the subscription in the UDM. The AF's capability to support AKMA may be as follows: a) provisioned to the PCF, or b) The PCF may inquire of the AF about the AF's capabilities to support AKMA.
[0029] Figure 8 illustrates the PCF requesting AKMA capability support. In case a), this step occurs before the UE accesses the 3GPP network and can indicate its capability to support AKMA. In case b), this step occurs when the UE accesses the 3GPP core network and can indicate its capability to support AKMA. When the PCF queries the AF, it includes the UE's capability to support AKMA.
[0030] When a UE wishes to use the ProSe service, the UE sends a UE policy provisioning request to the 3GPP network, as shown in Figure 9A, to provide the 3GPP network with its UE capability to support both ProSe and AKMA services and to provide a request to use the ProSe service. If the UE subscription enables the UE to use AKMA, and if the 3GPP network supports the AKMA procedure and the AF supports AKMA, the PCF in the network provides the UE with an AF address. If the AF does not support AKMA, the PCF still points to the AF address with an instruction to the UE not to use AKMA with this AF.
[0031] The PCF decision to provide the UE with an AF address can be combined with additional UE capabilities included by the UE in the network to support specific services, e.g., proximity services (ProSe). This UE capability for ProSe support helps the PCF determine which AF the UE needs to access to support the requested service. For example, if the UE requests a ProSe service and indicates the UE's capability to use the ProSe service, the AF can be mapped to the 5GDDNMF in the ProSe, or any other ProSe function in the network, that can perform key management for ProServices. Note that the use of the 5GDDNMF assumes that the 5GDDNMF is a separate entity and is not a function of the PCF.
[0032] This solution proposes using Transport Layer Security (TLS) 1.3 with PSK authentication as the security mechanism for establishing a secure connection between the UE and the AF, as described in RFC 8446
[10] . The following signaling flow describes the establishment of TLS 1.3 with PSK authentication. PSK authentication can be combined with Diffie-Hellman key exchange (pk_dhe_ke) or without Diffie-Hellman (psk_ke). The TLS client and server may use the interface (draft-ietf-tls-external-psk-importer) to import external PSK identities into TLS 1.3. The UE sends a Client Hello, where the Client Hello includes, for example, a pre_shared_key extension containing the PSK identities formatted from the A-KID, a "3GPP-akma" hint, along with a psk_key_exchange_modes extension pointing to psk_dhe_ke.
[0033] There is no separate authentication of the UE to support the AKMA functionality as described in TS 33.535 [6]. Instead, it reuses the 5G primary authentication procedure performed, for example, during UE registration, to authenticate the UE. A successful 5G primary authentication is AUSF is stored in AUSF and UE. AUSF is AUSF From K AKMA Generate a new generated K AKMA Generate A-KID mapped to K and assign K to AAnF. AKMA and A-KID. According to some embodiments, the UE is configured in the subscription in the UDM whether the UE is enabled to use the AKMA service. The UE is configured in the subscription in the UDM whether the UE is enabled to use the ProSe service. In some embodiments, the AF's capability to support AKMA is provisioned to the PCF.
[0034] It is assumed that the 3GPP core network has authenticated the UE by initiating a primary authentication either before or after step 1(a) shown in FIG. 9A. In step 1(a), when the UE 902 wishes to use the ProSe service, the UE 902 sends a request to use the ProSe service and a UE policy provisioning request to the 3GPP network, providing the 3GPP network with its UE capability to support both the ProSe service and the AKMA service. In step 1(b) shown in FIG. 9A, the AMF 906 sends an Npcf_UEpolicycontrol_update request on the service-based interface to discover the corresponding PCF 900 and sends a request for the AF 904 address needed for the ProSe service. The AMF 906 forwards the UE 902 request to use the ProSe service and the UE capability to support both the ProSe service and the AKMA service to the PCF 900.
[0035] FIG. 9A also illustrates that in step 1(c), the PCF 900 checks with the UDM 908 whether the UE 902 is enabled to use AKMA. The PCF 900 contacts the UDM 908 in a Nudm_UEAuthentication_request with a Subscription Confidentiality Identifier (SUCI) or a 5G Globally Unique Temporary Identifier (5G-GUTI) and the UE's capability to support both ProSe and AKMA services. The UDM 908 maintains an indicator in the UE subscription of whether the UE 902 is enabled to use AKMA. In other words, the UE 902 may support AKMA, but the UE 902 may not be enabled to use AKMA. The UDM 908 maintains an indicator in the UE subscription of whether the UE 902 is enabled to use ProSe services. In other words, the UE 902 may support ProSe services, but the UE 902 may not be enabled to use ProSe services.
[0036] FIG. 9A also illustrates that in step 1(d), the UDM 908 replies in a Nudm_UEAuthentication_response with the SUPI, whether the UE 902 is enabled to use the AKMA service, and whether the UE 902 is enabled to use the ProSe service. Step 1(e) in FIG. 9B is an optional step in which the PCF 900 contacts the AF 904 that supports the ProSe service and inquires about the UE capability to support AKMA as well as whether the AF 904 supports AKMA. If the PCF has provisioned the AF's capability to support the AKMA service, this step 1(e) is not required. Step 1(f) in FIG. 9B is an optional step in which the AF 904 that supports the ProSe service responds to the PCF 900 with whether the AF 904 supports AKMA, which is based on the AF's AKMA capability and whether the UE 902 supports AKMA. The PCF 900 can then determine whether the UE 902 is allowed to use the AKMA per public land mobile network (PLMN) policy with the AF 904 for ProSe services.
[0037] If the UE 902 is enabled to use the AKMA service and the ProSe service and the AF 904 for the ProSe service supports AKMA, Figure 9B illustrates a first option, step 1(g)-option 1, in which the PCF 900 returns to the UE 902 the AF address of the AF 904 that supports the ProSe service, along with an indication that the UE 902 is enabled to use AKMA with the AF 904 for the ProSe service. If the UE 902 is not enabled to use the AKMA service but the UE 902 is enabled to use the ProSe service, and the AF 904 for the ProSe service supports AKMA, Figure 9B illustrates a second option, step 1(g)-option 2, in which the PCF 900 does not provide the AF 904 address to the UE 902. In another embodiment, if the UE 902 is enabled to use the AKMA service and the UE 902 is enabled to use the ProSe service but the AF 904 for the ProSe service does not support AKMA, the PCF 900 returns to the UE 902 the AF address of the AF 904 that supports the ProSe service, along with an indication that the UE 902 is not enabled to use AKMA with the AF 904 for the ProSe service.
[0038] Steps 2(a)-2(c) shown in Figure 9B are part of the AKMA procedure in TS 33.535 [6]. Figure 9B shows that AUSF912, in step 2(a), AUSF From K AKMA 9B, AUSF912 generates K to AAnF914, as shown in steps 2(b)-2(c) in FIG. AKMA Step 3 shown in FIG. 9C is when the UE 902 pushes the key and A-KID. AUSF From K AKMA , and generate an A-KID. AKMA From K AFIn some embodiments, this step may also occur in step 4(e) after the UE 902 receives the Server Hello message. Figure 9C illustrates the UE 902 initiating TLS 1.3 with PSK authentication with the AF server 904 in step 4 using the address to the AF 904.
[0039] Step 4(a) in Figure 9C illustrates that the UE 902 sends a Client Hello, where the Client Hello includes a pre_shared_key extension containing the PSK identity formatted from the A-KID, a 3GPP-akma hint, and a psk_key_exchange_modes extension pointing to the psk_dhe_ke. For example, if an interface such as draft-ietf-tls-external-psk-importer is used to import an external PSK into TLS 1.3, the PSK identity in the pre_shared_key extension is the imported identity. The Client Hello may also include other extensions. The following steps in Figure 9C are part of the AKMA procedure specified in TS 33.535 [6]. 4(b). The AF server 904 contacts the AAnF 914 with the A-KID. 4(c).AAnF914 uses A-KID to AKMA Search for the key, K AKMA K from key AF Generate a key. 4(d). The AAnF server 914 AF Key, and K AF Responds to the AF with the expiration time for the key. 4(e). The AF Server 914 responds with a Server Hello with a pre_shared_key extension pointing to the chosen PSK identity. The Server Hello may include other extensions. Along with the Server Hello, the server sends other handshake messages, such as EncryptedExtensions and Finished. Optional Step: The UE 902 sends the K AUSF From KAKMA , and generates A-KID. The UE generates K AKMA From K AF This step may be performed in step 3 as a first option. 4(f). The UE 902 responds with a Finished message. 5. The UE 902 and the AF server 904 can exchange data over a secure link.
[0040] Next, the operation of a core network CN node 500 (implemented using the structure of FIG. 7) will be discussed with reference to the flowcharts of FIGS. 11-13, according to some embodiments of the present disclosure. It should be understood that the PCF 900 described above may comprise a CN node 500, according to some embodiments described herein. For example, modules may be stored in memory 505 of FIG. 7, and these modules may provide instructions such that, when the instructions of the modules are executed by the respective CN node processing circuitry 503, the processing circuitry 503 performs the respective operations of the flowcharts.
[0041] FIG. 10 illustrates a method for establishing a secure connection in a wireless communication network according to the claims of the present disclosure. In this embodiment, the method is performed by a control network node of the wireless communication network. FIG. 10 illustrates that the method includes receiving 1000 a request to use a communication service provided by the wireless communication network. In some embodiments, the request includes an indication that the communication device can support the requested communication service and authentication and key management (AKMA) services for the application provided by the wireless communication network. FIG. 10 also illustrates that the method includes determining 1002 whether the requested communication service and AKMA services can be provided to the communication device. The method also includes communicating 1004 information to the communication device indicating whether the requested communication service and AKMA services can be provided to the communication device for establishing a secure connection in the wireless communication network.
[0042] In some embodiments, the controlling network node comprises a policy control function (PCF) network node of the wireless communication network, such as, for example, the PCF 900 described above with respect to FIG. 8 and FIG. 9A-9C. In some embodiments, the requested communication service is provided by an application function (AF) of the wireless communication network. For example, the AF 904 described above with respect to FIG. 8 and FIG. 9A-9C. The requested communication service, in some embodiments, comprises proximity services (ProSe) provided by the AF. In some embodiments, the method includes obtaining information indicating whether the communication device is authorized to utilize the AKMA service. For example, FIG. 9A-9C illustrate the PCF 900 obtaining information indicating whether the communication device 902 is authorized to utilize the AKMA service in steps 1c-1d of FIG. 9A. In some embodiments, the method includes obtaining AKMA service availability information indicating whether the AF can provide the AKMA service. For example, Figures 8 and 9A-9C illustrate that a PCF (such as PCF 900) obtains AKMA service availability information indicating whether the AF can provide the AKMA service in steps 1e-1f of Figure 9B.
[0043] According to some embodiments, the method includes determining 1100 that the AF can provide the AKMA service based on the AKMA service availability information, as illustrated in FIG. 11 . In this embodiment, the method also includes determining 1102 that the communication device is authorized to use the AKMA service based on the information indicating whether the communication device is authorized to use the AKMA service. In this embodiment, the method further includes communicating 1104 information to the communication device indicating that the communication device is authorized to use the AKMA service with the AF to establish a secure connection to receive the requested communication service. In this embodiment, the information includes addresses associated with AFs that can provide the AKMA service and the requested communication service. For example, FIG. 9B illustrates the PCF 900 communicating, in step 1g and 1g—option 1 of FIG. 9B , information indicating that the UE 902 is authorized to use the AKMA service with the AF 904 and that the AF supports the AKMA service, and the address of the AF 904.
[0044] FIG. 12 illustrates that the method, according to an embodiment, includes determining 1200 that the AF is unable to provide the AKMA service based on the AKMA service availability information. FIG. 12 also illustrates that, in this embodiment, the method also includes determining 1202 that the communication device is authorized to use the AKMA service based on information indicating whether the communication device is authorized to use the AKMA service. FIG. 12 further illustrates that, in this embodiment, the method further includes communicating 1204 to the communication device information indicating that the communication device is unable to use the AKMA service with the AF (904) to establish a secure connection to receive the requested communication service. In this embodiment, the information includes addresses associated with AFs that can provide the AKMA service and the requested communication service. For example, FIG. 9B illustrates that, in steps 1g and 1g—option 1 of FIG. 9B , the PCF 900 communicates information indicating that the UE 902 is not authorized to use the AKMA service with the AF 904 and that the AF does not support the AKMA service, as well as the address of the AF 904.
[0045] Figure 13 illustrates that a method, according to an embodiment, includes determining 1300 that an AF can provide an AKMA service based on AKMA service availability information. Figure 13 also illustrates that, in this embodiment, the method includes determining 1302 that the communication device is not authorized to use the AKMA service based on information indicating whether the communication device is authorized to use the AKMA service. Figure 13 also illustrates that, according to this embodiment, the method includes determining 1304 that the requested communication service and AKMA service cannot be provided to the communication device based on information indicating that the communication device is not authorized to use the AKMA service and information indicating that the AF providing the requested communication service supports the AKMA service. Figure 13 further illustrates that the method includes communicating 1306 information to the communication device indicating that the requested communication service and AKMA service cannot be provided to the communication device. In this embodiment, the information does not include the address of an AF that can provide the requested communication service. For example, FIG. 9B illustrates that the PCF 900 communicates information indicating that the requested communication service and AKMA service cannot be provided in steps 1g and 1g-option 2 of FIG. 9B.
[0046] Operation of communications device 300 (implemented using the block diagram structure of FIG. 5) will now be discussed with reference to the flowcharts of FIG. 14-15, in accordance with some embodiments of the inventive concept. For example, modules may be stored in memory 305 of FIG. 5, and these modules may provide instructions such that, when the instructions of the modules are executed by respective communications device processing circuitry 303, the processing circuitry 303 performs the respective operations of the flowcharts.
[0047] Various operations from the flowchart of Figure 14 may be optional with respect to some embodiments of communications devices and related methods. With respect to an example embodiment method of establishing a secure connection (described below), for example, the operation of block 1404 of Figure 14 may be optional.
[0048] FIG. 14 illustrates a method for establishing a secure connection in a wireless communication network according to some embodiments of the present disclosure. In this embodiment, the method is performed by a communication device operating in the wireless communication network. FIG. 14 illustrates that the method includes communicating 1400 a request to use a communication service provided by the wireless communication network. In some embodiments, the method includes communicating the request toward a Policy Control Function (PCF) network node of the wireless communication network. For example, FIG. 9A illustrates an exemplary UE 902 communicating the request toward the PCF 900 in step 1a of FIG. 9A.
[0049] FIG. 14 also illustrates that the method includes receiving 1402, in response to communicating the request, a communication comprising information indicating whether the requested communication service and AKMA service can be provided to the communication device for establishing a secure connection in the wireless communication network. In some embodiments, the method includes receiving the information from a PCF network node. For example, FIG. 9B illustrates an exemplary UE 902 receiving information from a PCF 900 in step 1g (options 1 and 2) of FIG. 9B. In some embodiments, the requested communication service is provided by an Application Function (AF) of the wireless communication network. The requested communication service, in some embodiments, comprises proximity services (ProSe) provided by the AF.
[0050] Returning to FIG. 14, the method, according to some embodiments, includes establishing 1404 a secure connection with the AF using an AKMA service to use the requested communication service from the AF based on the address of the AF included in the communication and information indicating that the requested communication service and the AKMA service can be provided to the communication device to establish a secure connection in the wireless communication network. In some embodiments, FIG. 15 illustrates that the method includes 1500 generating a pre-shared key (PSK) identity based on an AKMA key identifier (A-KID) associated with the AKMA service. FIG. 15 also illustrates that the method includes 1502 communicating a message toward the AF comprising a pre-shared key (PSK) extension including the PSK identity, the A-KID, and an AKMA hint. The AKMA hint indicates to the AF that the communication device supports the AKMA service and wishes to use the AKMA service to establish the secure connection.
[0051] FIG. 15 also illustrates the method including receiving 1504 a communication from the AF comprising a PSK identity for the secure connection. The method further includes establishing 1506 a secure connection with the AF based on the PSK identity, according to some embodiments. For example, FIG. 9C illustrates an exemplary UE 902 establishing a secure connection with the AF 904 based on the PSK identity in steps 3-5 of FIG. 9C. Alternatively, in some other embodiments, the method includes establishing a secure connection with the AF to receive the requested communication service from the AF based on an address of the AF included in the communication and information indicating that the requested communication service can be provided to the communication device without the communication device utilizing an AKMA service to establish a secure connection in the wireless communication network.
[0052] Next, the operation of a network node (implemented using the structure of FIG. 7) will be discussed with reference to the flowcharts of FIGS. 16-17, according to some embodiments of the present disclosure. It should be understood that the AF 904 described above may comprise a network node, or a core network node, such as a CN node 500, according to some embodiments described herein. For example, modules may be stored in memory 505 of FIG. 7, and these modules may provide instructions such that, when the instructions of the modules are executed by the respective CN node processing circuitry 503, the processing circuitry 503 performs the respective operations of the flowcharts.
[0053] FIG. 16 illustrates a method for establishing a secure connection in a wireless communication network, according to some embodiments. The method is performed by a network node of the wireless communication network. FIG. 16 illustrates the method includes receiving 1600 from a core network node a request for AKMA service availability information indicating whether the network node can provide an AKMA service for establishing a secure connection for a requested communication service between a communication device operating in the wireless communication network and the network node. In some embodiments, the network node comprises an Application Function (AF) of the wireless communication network configured to provide the requested communication service. The core network node, according to some embodiments, comprises a Policy Control Function (PCF) network node of the wireless communication network. In some embodiments, the requested communication service comprises Proximity Services (ProSe) provided by the AF.
[0054] 16 also illustrates that the method further includes communicating 1602 AKMA service availability information to the core network node indicating whether the network node is capable of providing the AKMA service to establish a secure connection for the requested communication service. For example, FIG. 9B illustrates the example AF 904 communicating service availability information indicating whether the network node is capable of providing the AKMA service in steps 1e-1f of FIG. 9B. In some embodiments, the AKMA service availability information indicates that the network node is capable of providing the AKMA service.
[0055] FIG. 17 illustrates a method, according to some embodiments, including receiving 1700 from a communication device a message comprising a pre-shared key (PSK) extension based on an AKMA key identifier (A-KID) associated with the AKMA service, an A-KID, and an AKMA hint. The AKMA hint indicates to the AF that the communication device supports the AKMA service and wishes to use the AKMA service to establish a secure connection. For example, FIG. 9C illustrates an exemplary AF 904 receiving a ClientHello message comprising a PSK extension based on the A-KID, the A-KID, and an AKMA hint in steps 3-4a of FIG. 9C. FIG. 17 also illustrates the method including communicating 1702 a communication comprising a PSK identification for the secure connection to the communication device and establishing 1704 a secure connection with the communication device based on the PSK identification. For example, FIG. 9C illustrates an exemplary AF 904 establishing a secure connection with an exemplary UE 902 in steps 4b-5 of FIG. 9C.
[0056] In some other embodiments, the AKMA service availability information indicates that the network node is unable to provide the AKMA service. In this embodiment, the method includes providing the requested communication service to the communication device without utilizing the AKMA service. For example, the AF 904 illustrated in Figures 8 and 9 may not be configured to provide the AKMA service and provides the requested communication service to the UE 902 without using the AKMA service.
[0057] In general, all terms used herein should be interpreted according to their ordinary meaning in the relevant technical field unless a different meaning is clearly given and / or implied from the context in which the term is used. All references to an element, apparatus, component, means, step, etc. should be openly interpreted as referring to at least one instance of that element, apparatus, component, means, step, etc., unless expressly stated otherwise. The steps of any method disclosed herein need not be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or if it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may be applied to any other embodiment, and vice versa. Other objects, features, and advantages of the enclosed embodiments will become apparent from the following description.
[0058] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. However, other embodiments are included within the scope of the subject matter disclosed herein, and the disclosed subject matter should not be construed as being limited to only the embodiments described herein; rather, these embodiments are provided as examples to convey the scope of the subject matter to those skilled in the art.
[0059] FIG. 18 illustrates a wireless network, according to some embodiments.
[0060] Although the subject matter described herein may be implemented in any suitable type of system using any suitable components, the embodiments disclosed herein are described with reference to a wireless network, such as the exemplary wireless network illustrated in FIG. 18. For simplicity, the wireless network of FIG. 18 depicts only network 4106, network nodes 4160 and 4160b, and WDs 4110, 4110b, and 4110c (also referred to as mobile terminals). In practice, a wireless network may further include any additional elements suitable for supporting communication between wireless devices or between a wireless device and another communication device, such as a landline telephone, a service provider, or any other network node or end device. Of the components shown, network node 4160 and wireless device (WD) 4110 are depicted with additional detail. A wireless network may provide communication and other types of services to one or more wireless devices to facilitate wireless device access to the wireless network and / or use of services offered by or via the wireless network.
[0061] A wireless network may comprise and / or interface with any type of communication, telecommunication, data, cellular, and / or radio network, or other similar type of system. In some embodiments, a wireless network may be configured to operate according to a particular standard or other type of predefined rules or procedures. Thus, particular embodiments of a wireless network may implement communication standards such as Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, or 5G standards, wireless local area network (WLAN) standards such as the IEEE 802.11 standard, and / or any other suitable wireless communication standard, such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, and / or ZigBee standards.
[0062] The network 4106 may comprise one or more backhaul networks, core networks, IP networks, public switched telephone networks (PSTN), packet data networks, optical networks, wide area networks (WANs), local area networks (LANs), wireless local area networks (WLANs), wired networks, wireless networks, metropolitan area networks, and other networks for enabling communication between devices.
[0063] The network node 4160 and the WD4110 comprise various components, which are described in more detail below. These components cooperate to provide network node and / or wireless device functionality, such as providing wireless connectivity in a wireless network. In different embodiments, a wireless network may comprise any number of wired or wireless networks, network nodes, base stations, controllers, wireless devices, relay stations, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals, whether via wired or wireless connections.
[0064] As used herein, a network node refers to a device capable of, set up, configured, and / or operable to communicate directly or indirectly with wireless devices and / or other network nodes or devices in a wireless network to enable and / or provide wireless access to wireless devices and / or to perform other functions (e.g., administration) in the wireless network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., wireless access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), and NR Node Bs (gNBs)). Base stations may be categorized based on the amount of coverage they provide (or, stated another way, their transmit power level), and may then be referred to as femto, pico, micro, or macro base stations. A base station may also be a relay node or a relay donor node, controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU), sometimes referred to as a remote radio head (RRH). Such remote radio units may or may not be integrated with an antenna as an antenna-integrated radio. Portions of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS). Still further examples of network nodes include multi-standard radio (MSR) equipment such as an MSR BS, a network controller such as a radio network controller (RNC) or base station controller (BSC), a base transceiver station (BTS), a transmission point, a transmitting node, a multi-cell / multicast coordination entity (MCE), a core network node (e.g., MSC, MME), an O&M node, an OSS node, a SON node, a positioning node (e.g., E-SMLC), and / or an MDT. As another example, a network node may be a virtual network node, as described in more detail below.However, more generally, a network node may represent any suitable device (or group of devices) that is capable of, set up, configured, and / or operable to enable and / or provide wireless devices with access to a wireless network or to provide some service to wireless devices that have accessed the wireless network.
[0065] In FIG. 18 , the network node 4160 includes a processing circuit 4170, a device-readable medium 4180, an interface 4190, auxiliary equipment 4184, a power source 4186, a power circuit 4187, and an antenna 4162. While the network node 4160 depicted in the example wireless network of FIG. 18 may represent a device including the depicted combination of hardware components, other embodiments may comprise a network node with a different combination of components. It should be understood that a network node comprises any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. Moreover, while the components of the network node 4160 are depicted as a single box located within a larger box or nested within multiple boxes, in reality the network node may comprise multiple different physical components that make up a single depicted component (e.g., the device-readable medium 4180 may comprise multiple separate hard drives as well as multiple RAM modules).
[0066] Similarly, the network node 4160 may be assembled from multiple physically separate components (e.g., a Node B component and an RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In some scenarios in which the network node 4160 comprises multiple separate components (e.g., a BTS component and a BSC component), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple Node Bs. In such scenarios, each unique Node B and RNC pair may, in some cases, be considered a single separate network node. In some embodiments, the network node 4160 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate device-readable media 4180 for different RATs) and some components may be reused (e.g., the same antenna 4162 may be shared by the RATs). The network node 4160 may also include multiple sets of the various illustrated components for different wireless technologies, such as, for example, GSM, WCDMA, LTE, NR, WiFi, or Bluetooth wireless technologies, integrated into the network node 4160. These wireless technologies may be integrated into the same or different chips or sets of chips and other components within the network node 4160.
[0067] The processing circuit 4170 is configured to perform any decision, computation, or similar operations (e.g., some acquisition operations) described herein as being provided by a network node. These operations performed by the processing circuit 4170 may include processing information obtained by the processing circuit 4170, for example, by transforming the obtained information into other information, comparing the obtained or transformed information with information stored in the network node, and / or performing one or more operations based on the obtained or transformed information and as a result of said processing making a decision.
[0068] The processing circuit 4170 may comprise one or more combinations of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable to provide network node 4160 functionality, either alone or in conjunction with other network node 4160 components, such as device readable medium 4180. For example, the processing circuit 4170 may execute instructions stored on the device readable medium 4180 or in memory within the processing circuit 4170. Such functionality may include providing any of the various wireless features, functions, or benefits discussed herein. In some embodiments, the processing circuit 4170 may include a system on a chip (SOC).
[0069] In some embodiments, the processing circuit 4170 may include one or more of a radio frequency (RF) transceiver circuit 4172 and a baseband processing circuit 4174. In some embodiments, the radio frequency (RF) transceiver circuit 4172 and the baseband processing circuit 4174 may be on separate chips (or sets of chips), boards, or units such as a radio unit and a digital unit. In alternative embodiments, some or all of the RF transceiver circuit 4172 and the baseband processing circuit 4174 may be on the same chip or set of chips, board, or unit.
[0070] In some embodiments, some or all of the functionality described herein as being provided by a network node, base station, eNB, or other such network device may be performed by the processing circuitry 4170 executing instructions stored on a device-readable medium 4180, or on a memory within the processing circuitry 4170. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry 4170 without executing instructions stored on a separate or distinct device-readable medium, such as in a hardwired manner. In any of those embodiments, the processing circuitry 4170 may be configured to perform the described functionality, regardless of whether or not it executes instructions stored on a device-readable storage medium. Benefits provided by such functionality are enjoyed by the network node 4160 as a whole, and / or by end users and the wireless network generally, and not by the processing circuitry 4170 alone or by other components of the network node 4160.
[0071] The device-readable medium 4180 may comprise any form of volatile or non-volatile computer-readable memory, including, but not limited to, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disk), removable storage media (e.g., flash drive, compact disc (CD) or digital video disc (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions that can be used by the processing circuit 4170. The device-readable medium 4180 may store any suitable instructions, data, or information, including applications including one or more of computer programs, software, logic, rules, code, tables, etc., and / or other instructions that can be executed by the processing circuit 4170 and utilized by the network node 4160. The device-readable medium 4180 may be used to store calculations performed by the processing circuit 4170 and / or data received via the interface 4190. In some embodiments, the processing circuit 4170 and the device-readable medium 4180 may be considered to be integrated.
[0072] The interface 4190 is used in wired or wireless communication of signaling and / or data between the network node 4160, the network 4106, and / or the WD 4110. As shown, the interface 4190 comprises a port / terminal 4194 for sending and receiving data to and from the network 4106, for example, over a wired connection. The interface 4190 also includes a radio front-end circuit 4192 that is coupled to the antenna 4162 or, in some embodiments, may be part of the antenna 4162. The radio front-end circuit 4192 comprises a filter 4198 and an amplifier 4196. The radio front-end circuit 4192 may be connected to the antenna 4162 and the processing circuit 4170. The radio front-end circuit 4192 may be configured to condition signals communicated between the antenna 4162 and the processing circuit 4170. The radio front-end circuit 4192 may receive digital data to be sent to another network node or WD via a wireless connection. The radio front-end circuit 4192 may convert the digital data into a radio signal having appropriate channel and bandwidth parameters using a combination of filters 4198 and / or amplifiers 4196. The radio signal may then be transmitted via the antenna 4162. Similarly, when receiving data, the antenna 4162 may collect the radio signal, which is then converted into digital data by the radio front-end circuit 4192. The digital data may be passed to the processing circuit 4170. In other embodiments, the interface may comprise different components and / or different combinations of components.
[0073] In some alternative embodiments, the network node 4160 may not include a separate radio front-end circuit 4192; instead, the processing circuit 4170 may comprise a radio front-end circuit and may be connected to the antenna 4162 without a separate radio front-end circuit 4192. Similarly, in some embodiments, all or a portion of the RF transceiver circuit 4172 may be considered part of the interface 4190. In still other embodiments, the interface 4190 may include one or more ports or terminals 4194, the radio front-end circuit 4192, and the RF transceiver circuit 4172 as part of a radio unit (not shown), and the interface 4190 may communicate with a baseband processing circuit 4174 that is part of a digital unit (not shown).
[0074] The antenna 4162 may include one or more antennas or antenna arrays configured to send and / or receive wireless signals. The antenna 4162 may be coupled to the radio front-end circuitry 4192 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, the antenna 4162 may comprise one or more omnidirectional, sector, or panel antennas operable to transmit / receive wireless signals, for example, between 2 GHz and 66 GHz. An omnidirectional antenna may be used to transmit / receive wireless signals in any direction, a sector antenna may be used to transmit / receive wireless signals from devices within a specific area, and a panel antenna may be a line-of-sight antenna used to transmit / receive wireless signals in a relatively straight line. In some instances, the use of two or more antennas may be referred to as MIMO. In some embodiments, the antenna 4162 may be separate from the network node 4160 and connectable to the network node 4160 through an interface or port.
[0075] The antenna 4162, the interface 4190, and / or the processing circuit 4170 may be configured to perform any receiving operations and / or some obtaining operations described herein as being performed by a network node. Any information, data, and / or signals may be received from a wireless device, another network node, and / or any other network equipment. Similarly, the antenna 4162, the interface 4190, and / or the processing circuit 4170 may be configured to perform any transmitting operations described herein as being performed by a network node. Any information, data, and / or signals may be transmitted to a wireless device, another network node, and / or any other network equipment.
[0076] The power circuit 4187 may comprise or be coupled to power management circuitry and is configured to supply power to the components of the network node 4160 for performing the functions described herein. The power circuit 4187 may receive power from a power source 4186. The power source 4186 and / or the power circuit 4187 may be configured to provide power to the various components of the network node 4160 in a form suitable for each component (e.g., at the voltage and current levels required for each respective component). The power source 4186 may either be included in the power circuit 4187 and / or the network node 4160 or may be external to the power circuit 4187 and / or the network node 4160. For example, the network node 4160 may be connectable to an external power source (e.g., an electrical outlet) via an input circuit or interface such as an electrical cable, whereby the external power source supplies power to the power circuit 4187. As a further example, power supply 4186 may comprise a power source in the form of a battery or battery pack connected to or integrated in power circuit 4187. The battery may provide backup power if the external power source fails. Other types of power sources, such as photovoltaic devices, may also be used.
[0077] 18 that may be responsible for providing some aspects of the network node's functionality, including any of the functionality described herein and / or functionality necessary to support the subject matter described herein. For example, the network node 4160 may include user interface devices to enable input of information into the network node 4160 and output of information from the network node 4160. This may enable a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 4160.
[0078] As used herein, a wireless device (WD) refers to a device capable of, configured to, and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Unless otherwise noted, the term WD may be used interchangeably with user equipment (UE) herein. Communicating wirelessly may involve transmitting and / or receiving radio signals using electromagnetic, radio, infrared, and / or other types of signals suitable for conveying information over the air. In some embodiments, a WD may be configured to transmit and / or receive information without direct human interaction. For example, a WD may be designed to transmit information to a network on a predetermined schedule, when triggered by an internal or external event, or in response to a request from the network. Examples of WDs include, but are not limited to, smartphones, mobile phones, cell phones, voice-over-IP (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, gaming consoles or devices, music storage devices, playback appliances, wearable terminal devices, wireless endpoints, mobile stations, tablets, laptop computers, laptop embedded devices (LEEs), laptop mounted devices (LMEs), smart devices, wireless customer premises equipment (CPEs), in-vehicle wireless terminal devices, etc. A WD may support device-to-device (D2D) communications, for example, by implementing 3GPP standards for sidelink communications, vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-everything (V2X), in which case it may be referred to as a D2D communications device. As yet another specific example, in an Internet of Things (IoT) scenario, a WD may represent a machine or other device that performs monitoring and / or measurements and transmits results of such monitoring and / or measurements to another WD and / or network node. The WD in this case may be a machine-to-machine (M2M) device, which may be referred to as an MTC device in the 3GPP context.As one specific example, a WD may be a UE implementing the 3GPP Narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or household or personal appliances (e.g., refrigerators, televisions, etc.), and personal wearables (e.g., watches, fitness trackers, etc.). In other scenarios, a WD may represent a vehicle or other equipment capable of monitoring and / or reporting on its operational status or other functions related to its operation. The WD described above may represent an endpoint of a wireless connection, in which case the device may be referred to as a wireless terminal. Moreover, the WD described above may be mobile, in which case the device may be referred to as a mobile device or mobile terminal.
[0079] As shown, wireless device 4110 includes antenna 4111, interface 4114, processing circuitry 4120, device-readable medium 4130, user interface equipment 4132, auxiliary equipment 4134, power supply 4136, and power circuitry 4137. WD4110 may include multiple sets of one or more of the illustrated components for different wireless technologies supported by WD4110, such as, for example, GSM, WCDMA, LTE, NR, WiFi, WiMAX, or Bluetooth wireless technologies, to name just a few. These wireless technologies may be integrated on the same or different chip or set of chips as other components within WD4110.
[0080] The antenna 4111 may include one or more antennas or antenna arrays configured to send and / or receive wireless signals and is connected to the interface 4114. In some alternative embodiments, the antenna 4111 may be separate from the WD4110 and connectable to the WD4110 through an interface or port. The antenna 4111, the interface 4114, and / or the processing circuit 4120 may be configured to perform any receiving or transmitting operations described herein as being performed by a WD. Any information, data, and / or signals may be received from a network node and / or another WD. In some embodiments, the wireless front-end circuit and / or the antenna 4111 may be considered an interface.
[0081] As shown, the interface 4114 comprises a radio front-end circuit 4112 and an antenna 4111. The radio front-end circuit 4112 comprises one or more filters 4118 and an amplifier 4116. The radio front-end circuit 4112 is connected to the antenna 4111 and the processing circuit 4120 and is configured to condition signals communicated between the antenna 4111 and the processing circuit 4120. The radio front-end circuit 4112 may be coupled to or part of the antenna 4111. In some embodiments, the WD 4110 may not include a separate radio front-end circuit 4112; rather, the processing circuit 4120 may comprise the radio front-end circuit and be connected to the antenna 4111. Similarly, in some embodiments, some or all of the RF transceiver circuit 4122 may be considered part of the interface 4114. The radio front-end circuit 4112 may receive digital data to be sent to another network node or WD via a wireless connection. The radio front-end circuitry 4112 may convert the digital data into a radio signal having appropriate channel and bandwidth parameters using a combination of filters 4118 and / or amplifiers 4116. The radio signal may then be transmitted via the antenna 4111. Similarly, when receiving data, the antenna 4111 may collect the radio signal, which is then converted into digital data by the radio front-end circuitry 4112. The digital data may be passed to the processing circuitry 4120. In other embodiments, the interface may comprise different components and / or different combinations of components.
[0082] The processing circuitry 4120 may comprise one or more combinations of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable to provide WD4110 functionality, either alone or in conjunction with other WD4110 components, such as the device-readable medium 4130. Such functionality may include providing any of the various wireless features or benefits discussed herein. For example, the processing circuitry 4120 may execute instructions stored on the device-readable medium 4130 or in memory within the processing circuitry 4120 to provide the functionality disclosed herein.
[0083] As shown, the processing circuit 4120 includes one or more of an RF transceiver circuit 4122, a baseband processing circuit 4124, and an application processing circuit 4126. In other embodiments, the processing circuit may comprise different components and / or different combinations of components. In some embodiments, the processing circuit 4120 of the WD4110 may comprise a SOC. In some embodiments, the RF transceiver circuit 4122, the baseband processing circuit 4124, and the application processing circuit 4126 may be on separate chips or sets of chips. In alternative embodiments, some or all of the baseband processing circuit 4124 and the application processing circuit 4126 may be combined into one chip or set of chips, and the RF transceiver circuit 4122 may be on a separate chip or set of chips. In yet further alternative embodiments, some or all of the RF transceiver circuit 4122 and the baseband processing circuit 4124 may be on the same chip or set of chips, and the application processing circuit 4126 may be on a separate chip or set of chips. In yet other alternative embodiments, some or all of the RF transceiver circuitry 4122, the baseband processing circuitry 4124, and the application processing circuitry 4126 may be combined in the same chip or set of chips. In some embodiments, the RF transceiver circuitry 4122 may be part of the interface 4114. The RF transceiver circuitry 4122 may condition RF signals for the processing circuitry 4120.
[0084] In some embodiments, some or all of the functionality described herein as being performed by the WD may be provided by the processing circuitry 4120 executing instructions stored on a device-readable medium 4130, which in some embodiments may be a computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry 4120 without executing instructions stored on a separate or distinct device-readable storage medium, such as in a hardwired manner. In any of these particular embodiments, the processing circuitry 4120 may be configured to perform the described functionality, regardless of whether it executes instructions stored on a device-readable storage medium. Benefits provided by such functionality are enjoyed by the WD4110 as a whole and / or by end users and wireless networks generally, and not by the processing circuitry 4120 alone or by other components of the WD4110.
[0085] The processing circuit 4120 may be configured to perform any of the determination, calculation, or similar operations (e.g., some acquisition operations) described herein as being performed by a WD. These operations as performed by the processing circuit 4120 may include processing information obtained by the processing circuit 4120, for example, by converting the obtained information into other information, comparing the obtained or converted information with information stored by the WD 4110, and / or performing one or more operations based on the obtained or converted information and as a result of the processing making a decision.
[0086] The device-readable medium 4130 may be operable to store applications including one or more of computer programs, software, logic, rules, codes, tables, etc., and / or other instructions that can be executed by the processing circuit 4120. The device-readable medium 4130 may include computer memory (e.g., random access memory (RAM) or read-only memory (ROM)), mass storage media (e.g., hard disk), removable storage media (e.g., compact discs (CDs) or digital video discs (DVDs)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions that can be used by the processing circuit 4120. In some embodiments, the processing circuit 4120 and the device-readable medium 4130 may be considered to be integrated.
[0087] The user interface device 4132 may provide components that allow a human user to interact with the WD4110. Such interaction may be in many forms, such as visual, auditory, tactile, etc. The user interface device 4132 may be operable to produce output to the user and to allow the user to provide input to the WD4110. The type of interaction may vary depending on the type of user interface device 4132 installed on the WD4110. For example, if the WD4110 is a smartphone, interaction may be via a touchscreen; if the WD4110 is a smart meter, interaction may be through a screen that provides usage (e.g., number of gallons used) or a speaker that provides an audible alarm (e.g., if smoke is detected). The user interface device 4132 may include input interfaces, devices, and circuits, as well as output interfaces, devices, and circuits. The user interface device 4132 is configured to allow input of information to the WD4110 and is connected to the processing circuit 4120 to allow the processing circuit 4120 to process the input information. The user interface devices 4132 may include, for example, a microphone, proximity or other sensors, keys / buttons, a touch display, one or more cameras, a USB port, or other input circuitry. The user interface devices 4132 are also configured to enable output of information from the WD4110 and to enable the processing circuit 4120 to output information from the WD4110. The user interface devices 4132 may include, for example, a speaker, a display, vibration circuitry, a USB port, a headphone interface, or other output circuitry. Using one or more input and output interfaces, devices, and circuits of the user interface devices 4132, the WD4110 may communicate with end users and / or wireless networks, enabling the end users and / or wireless networks to benefit from the functionality described herein.
[0088] The auxiliary device 4134 is operable to provide more specific functionality that may not generally be performed by the WD. It may include specialized sensors for taking measurements for various purposes, interfaces for additional types of communication such as wired communication, etc. The inclusion and type of components of the auxiliary device 4134 may vary depending on the embodiment and / or scenario.
[0089] The power source 4136 may be in the form of a battery or battery pack in some embodiments. Other types of power sources may also be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or cells. The WD4110 may further comprise a power circuit 4137 for delivering power from the power source 4136 to various portions of the WD4110 that require power from the power source 4136 to perform any of the functions described or indicated herein. The power circuit 4137 may, in some embodiments, comprise a power management circuit. The power circuit 4137 may additionally or alternatively be operable to receive power from an external power source, in which case the WD4110 may be connectable to an external power source (such as an electrical outlet) via an input circuit or interface, such as a power cable. The power circuit 4137 may also, in some embodiments, be operable to deliver power from the external power source to the power source 4136. This may be, for example, for charging the power source 4136. The power circuitry 4137 may perform any formatting, conversion, or other modification on the power from the power supply 4136 to make the power suitable for each component of the WD4110 being powered.
[0090] FIG. 19 illustrates a user equipment, according to some embodiments.
[0091] FIG. 19 illustrates one embodiment of a UE in accordance with various aspects described herein. User equipment or UE, as used herein, may not necessarily have a user in the sense of a human user who owns and / or operates an associated device. Instead, a UE may represent a device (e.g., a smart sprinkler controller) that is intended for sale to or operation by a human user, but may not be associated with or initially associated with a particular human user. Alternatively, a UE may represent a device (e.g., a smart power meter) that is not intended for sale to or operation by an end user, but may be associated with or operated for the benefit of a user. The UE 42200 may be any UE identified by the 3rd Generation Partnership Project (3GPP), including an NB-IoT UE, a machine-type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE. The UE 4200 illustrated in Figure 19 is an example of a WD configured for communication according to one or more communications standards promulgated by the 3rd Generation Partnership Project (3GPP), such as the 3GPP's GSM, UMTS, LTE, and / or 5G standards. As mentioned above, the terms WD and UE may be used interchangeably. Thus, while Figure 19 is a UE, the components discussed herein are equally applicable to a WD, and vice versa.
[0092] In FIG. 19, UE 4200 includes a processing circuit 4201 operably coupled to an input / output interface 4205, a radio frequency (RF) interface 4209, a network connection interface 4211, memory 4215 including random access memory (RAM) 4217, read-only memory (ROM) 4219, and storage medium 4221, a communications subsystem 4231, a power source 4213, and / or other components, or any combination thereof. Storage medium 4221 includes an operating system 4223, application programs 4225, and data 4227. In other embodiments, storage medium 4221 may include other similar types of information. Some UEs may utilize all of the components shown in FIG. 19 or only a subset of those components. The level of integration between components may vary from UE to UE. Additionally, some UEs may include multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0093] 19, processing circuit 4201 may be configured to process computer instructions and data. Processing circuit 4201 may be configured to implement any sequential state machine operable to execute machine instructions stored in memory as a machine-readable computer program, such as one or more hardware-implemented state machines (e.g., in discrete logic, FPGA, ASIC, etc.), programmable logic with appropriate firmware, one or more pre-programmed, general-purpose processors, such as a microprocessor or digital signal processor (DSP) with appropriate software, or any combination of the above. For example, processing circuit 4201 may include two central processing units (CPUs). Data may be information in a form suitable for use by a computer.
[0094] In the depicted embodiment, the input / output interface 4205 may be configured to provide an input device, an output device, or a communication interface for an input / output device. The UE 4200 may be configured to use an output device via the input / output interface 4205. The output device may use the same type of interface port as the input device. For example, a USB port may be used to provide input to and output from the UE 4200. The output device may be a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smart card, another output device, or any combination thereof. The UE 4200 may be configured to use an input device via the input / output interface 4205 to allow a user to capture information into the UE 4200. The input device may include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a webcam, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smart card, etc. The presence-sensitive display may include a capacitive or resistive touch sensor for detecting input from a user. The sensor may be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, a light sensor, a proximity sensor, another similar sensor, or any combination thereof. For example, the input device may be an accelerometer, a magnetometer, a digital camera, a microphone, and a light sensor.
[0095] In FIG. 19 , the RF interface 4209 may be configured to provide a communication interface to RF components, such as a transmitter, receiver, and antenna. The network connection interface 4211 may be configured to provide a communication interface to a network 4243a. The network 4243a may encompass a wired and / or wireless network, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a communications network, another similar network, or any combination thereof. For example, the network 4243a may comprise a Wi-Fi network. The network connection interface 4211 may be configured to include a receiver and transmitter interface used to communicate with one or more other devices over a communications network according to one or more communications protocols, such as Ethernet, TCP / IP, SONET, ATM, etc. The network connection interface 4211 may implement receiver and transmitter functionality appropriate for a communications network link (e.g., optical, electrical, etc.). The transmitter and receiver functionality may share circuit components, software, or firmware, or alternatively, may be implemented separately.
[0096] The RAM 4217 may be configured to interface to the processing circuit 4201 via the bus 4202 to provide storage or caching of data or computer instructions during the execution of software programs, such as an operating system, application programs, and device drivers. The ROM 4219 may be configured to provide computer instructions or data to the processing circuit 4201. For example, the ROM 4219 may be configured to store unchanging low-level system code or data for basic system functions, such as basic input / output (I / O), booting, or receiving keystrokes from a keyboard, stored in non-volatile memory. The storage medium 4221 may be configured to include memory, such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, floppy disk, hard disk, removable cartridge, or flash drive. In one example, the storage medium 4221 may be configured to include an operating system 4223, an application program 4225, such as a web browser application, a widget or gadget engine, or another application, and data files 4227. The storage medium 4221 may store any of a variety of different operating systems or combinations of operating systems for use by the UE 4200.
[0097] The storage medium 4221 may be configured to include several physical drive units, such as a redundant array of independent disks (RAID), a floppy disk drive, a flash memory, a USB flash drive, an external hard disk drive, a thumb drive, a pen drive, a key drive, a high-density digital versatile disk (HD-DVD) optical disk drive, an internal hard disk drive, a Blu-ray optical disk drive, a holographic digital data storage (HDDS) optical disk drive, an external mini dual in-line memory module (DIMM), a synchronous dynamic random access memory (SDRAM), an external micro-DIMM SDRAM, a smart card memory such as a subscriber identity module or removable user identity module (SIM / RUIM) module, other memory, or any combination thereof. The storage medium 4221 may enable the UE 4200 to access, offload data, or upload data to computer-executable instructions, application programs, etc. stored on a temporary or non-transitory memory medium. An article of manufacture, such as an article of manufacture utilizing the communication system, may be tangibly embodied in storage medium 4221, which may comprise a device-readable medium.
[0098] In FIG. 19, the processing circuit 4201 may be configured to communicate with network 4243b using a communications subsystem 4231. Network 4243a and network 4243b may be the same network or networks or different networks or networks. The communications subsystem 4231 may be configured to include one or more transceivers used to communicate with network 4243b. For example, the communications subsystem 4231 may be configured to include one or more transceivers used to communicate with one or more remote transceivers of another device capable of wireless communication, such as another WD, UE, or base station of a radio access network (RAN), according to one or more communications protocols such as IEEE 802.11, CDMA, WCDMA, GSM, LTE, UTRAN, WiMax, etc. Each transceiver may include a transmitter 4233 and / or a receiver 4235 for implementing transmitter or receiver functions, respectively, appropriate for the RAN link (e.g., frequency allocation, etc.). Furthermore, the transmitter 4233 and receiver 4235 of each transceiver may share circuit components, software or firmware, or may alternatively be implemented separately.
[0099] In the illustrated embodiment, the communication capabilities of the communication subsystem 4231 may include data communications, voice communications, multimedia communications, short-range communications such as Bluetooth, near-field communications, location-based communications such as using a global positioning system (GPS) to determine location, another similar communication capability, or any combination thereof. For example, the communication subsystem 4231 may include cellular communications, Wi-Fi communications, Bluetooth communications, and GPS communications. The network 4243b may encompass wired and / or wireless networks, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a communications network, another similar network, or any combination thereof. For example, the network 4243b may be a cellular network, a Wi-Fi network, and / or a near-field network. The power supply 4213 may be configured to provide alternating current (AC) or direct current (DC) power to the components of the UE 4200.
[0100] The features, benefits, and / or functionality described herein may be implemented in one of the components of the UE 4200 or distributed across multiple components of the UE 4200. Furthermore, the features, benefits, and / or functionality described herein may be implemented in any combination of hardware, software, or firmware. In one example, the communication subsystem 4231 may be configured to include any of the components described herein. Furthermore, the processing circuit 4201 may be configured to communicate with any of such components over the bus 4202. In another example, any of such components may be represented by program instructions stored in memory that, when executed by the processing circuit 4201, perform the corresponding functions described herein. In another example, the functionality of any of such components may be distributed between the processing circuit 4201 and the communication subsystem 4231. In another example, non-computationally intensive functionality of any of such components may be implemented in software or firmware, and computationally intensive functionality may be implemented in hardware.
[0101] FIG. 20 illustrates a virtualized environment, according to some embodiments.
[0102] 20 is a schematic block diagram illustrating a virtualization environment 4300 in which functionality implemented by some embodiments may be virtualized. In this context, virtualizing means creating a virtual version of an apparatus or device, which may include virtualizing a hardware platform, storage devices, and networking resources. Virtualization, as used herein, may apply to a node (e.g., a virtualized base station or a virtualized radio access node) or to a device (e.g., a UE, a wireless device, or any other type of communication device) or component of that device, and relates to implementations in which at least a portion of the functionality is implemented as one or more virtual components (e.g., via one or more applications, components, functions, virtual machines, or containers executing on one or more physical processing nodes in one or more networks).
[0103] In some embodiments, some or all of the functionality described herein may be implemented as virtual components executed by one or more virtual machines implemented in one or more virtual environments 4300 hosted by one or more of the hardware nodes 4330. Furthermore, in embodiments where the virtual nodes are not wireless access nodes or do not require wireless connectivity (e.g., core network nodes), the network nodes may be fully virtualized.
[0104] The functionality may be implemented by one or more applications 4320 (which may alternatively be referred to as software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) operable to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. The applications 4320 are run in a virtualized environment 4300, which provides hardware 4330 comprising processing circuitry 4360 and memory 4390. The memory 4390 includes instructions 4395 executable by the processing circuitry 4360, such that the applications 4320 are operable to provide one or more of the features, benefits, and / or functions disclosed herein.
[0105] The virtualization environment 4300 includes general-purpose or dedicated network hardware devices 4330 that include one or more sets of processors or processing circuits 4360, which may be commercial off-the-shelf (COTS) processors, dedicated application-specific integrated circuits (ASICs), or any other type of processing circuitry, including digital or analog hardware components or dedicated processors. Each hardware device may include memory 4390-1, which may be non-persistent memory for temporarily storing instructions 4395 or software executed by the processing circuits 4360. Each hardware device may include one or more network interface controllers (NICs) 4370, also known as network interface cards, which include physical network interfaces 4380. Each hardware device may also include a non-transitory, persistent, machine-readable storage medium 4390-2 that stores software 4395 and / or instructions executable by the processing circuits 4360. Software 4395 may include any type of software, including software for instantiating one or more virtualization layers 4350 (also called hypervisors), software for running virtual machines 4340, and software that enables it to perform the functions, features, and / or benefits described in connection with some embodiments described herein.
[0106] The virtual machines 4340 may comprise virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and may be run by a corresponding virtualization layer 4350 or hypervisor. Different embodiments of the virtual appliance 4320 instance may be implemented on one or more of the virtual machines 4340, and the implementation may be done in different ways.
[0107] During operation, processing circuitry 4360 executes software 4395 to instantiate a hypervisor or virtualization layer 4350, which may sometimes be referred to as a virtual machine monitor (VMM). The virtualization layer 4350 may present to the virtual machine 4340 a virtual operating platform that appears to be networking hardware.
[0108] 20, hardware 4330 may be a standalone network node with general or specific components. Hardware 4330 may include antenna 43225 and may implement some functionality through virtualization. Alternatively, hardware 4330 may be part of a larger cluster of hardware (e.g., as in a data center or customer premises equipment (CPE)) where many hardware nodes work together and are managed via a management and orchestration (MANO) 43100 that, among other things, oversees the lifecycle management of application 4320.
[0109] Hardware virtualization, in some contexts, is called network functions virtualization (NFV). NFV can be used to consolidate many network equipment types onto industry-standard high-volume server hardware, physical switches, and physical storage that may be located in data centers and customer premises equipment.
[0110] In the context of NFV, virtual machine 4340 may be a software implementation of a physical machine that runs programs as if those programs were running on a physical, non-virtualized machine. Each virtual machine 4340 and the portion of hardware 4330 on which it runs, whether hardware dedicated to that virtual machine and / or hardware shared by that virtual machine with other ones of virtual machines 4340, form a separate virtual network element (VNE).
[0111] Further in the context of NFV, a virtual network function (VNF) is responsible for handling a specific network function running in one or more virtual machines 4340 on top of the hardware networking infrastructure 4330 and corresponds to application 4320 in FIG. 20.
[0112] In some embodiments, one or more radio units 43200, each including one or more transmitters 43220 and one or more receivers 43210, may be coupled to one or more antennas 43225. The radio units 43200 may communicate directly with the hardware node 4330 via one or more appropriate network interfaces and may be used in combination with a virtualization component to provide a virtual node with wireless capabilities, such as a wireless access node or base station.
[0113] In some embodiments, some signaling may be accomplished using a control system 43230, which may alternatively be used for communication between the hardware node 4330 and the radio unit 43200.
[0114] FIG. 21 illustrates a communications network connected to a host computer through an intermediate network, according to some embodiments.
[0115] 21 , according to an embodiment, a communication system includes a communication network 4410, such as a 3GPP-type cellular network, comprising an access network 4411, such as a wireless access network, and a core network 4414. The access network 4411 includes a plurality of base stations 4412a, 4412b, 4412c, such as NBs, eNBs, gNBs, or other types of wireless access points, each defining a corresponding coverage area 4413a, 4413b, 4413c. Each base station 4412a, 4412b, 4412c can be connected to the core network 4414 over a wired or wireless connection 4415. A first UE 4491 located in the coverage area 4413c is configured to wirelessly connect to or be paged by the corresponding base station 4412c. A second UE 4492 in coverage area 4413a can wirelessly connect to corresponding base station 4412a. While multiple UEs 4491, 4492 are shown in this example, the disclosed embodiments are equally applicable to situations where only one UE is in a coverage area or connected to corresponding base station 4412a.
[0116] The communications network 4410 is itself connected to a host computer 4430, which may be embodied in hardware and / or software of a standalone server, a cloud-implemented server, a distributed server, or as a processing resource in a server farm. The host computer 4430 may be owned or controlled by a service provider, or may be operated by or on behalf of the service provider. Connections 4421 and 4422 between the communications network 4410 and the host computer 4430 may extend directly from the core network 4414 to the host computer 4430 or may proceed through an optional intermediate network 4420. The intermediate network 4420 may be one of a public network, a private network, or a hosted network, or a combination of two or more of them; the intermediate network 4420 may be a backbone network or the Internet, if any; in particular, the intermediate network 4420 may comprise two or more subnetworks (not shown).
[0117] The communication system of FIG. 21 as a whole enables connectivity between connected UEs 4491, 4492 and a host computer 4430. The connectivity may be described as an over-the-top (OTT) connection 4450. The host computer 4430 and connected UEs 4491, 4492 are configured to communicate data and / or signaling via the OTT connection 4450 using the access network 4411, the core network 4414, any intermediate networks 4420, and possible further infrastructure (not shown) as intermediaries. The OTT connection 4450 may be transparent in the sense that participating communication devices through which the OTT connection 4450 passes are unaware of the routing of uplink and downlink communications. For example, the base station 4412 may not, or need not, be informed about the past routing of incoming downlink communications involving data originating from the host computer 4430 that is to be forwarded (e.g., handed over) to the connected UE 4491. Similarly, the base station 4412 does not need to be aware of the future routing of outgoing uplink communications originating from the UE 4491 and destined for the host computer 4430.
[0118] FIG. 22 illustrates a host computer communicating with user equipment via a base station over a partially wireless connection, according to some embodiments.
[0119] Next, an exemplary implementation of the UE, base station, and host computer discussed in the previous paragraph according to an embodiment will be described with reference to FIG. 22. In the communication system 4500, the host computer 4510 comprises hardware 4515 including a communication interface 4516 configured to set up and maintain wired or wireless connections with interfaces of different communication devices of the communication system 4500. The host computer 4510 further comprises processing circuitry 4518, which may have storage and / or processing capabilities. In particular, the processing circuitry 4518 may comprise one or more programmable processors, application specific integrated circuits, field programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The host computer 4510 further comprises software 4511 stored on or accessible by the host computer 4510 and executable by the processing circuitry 4518. The software 4511 includes a host application 4512. The host application 4512 may be operable to provide services to a remote user, such as a UE 4530 connecting via an OTT connection 4550 that terminates at the UE 4530 and the host computer 4510. In providing services to the remote user, the host application 4512 may provide user data that is transmitted using the OTT connection 4550.
[0120] The communications system 4500 further includes a base station 4520 provided in the communications system, the base station 4520 comprising hardware 4525 that enables the base station 4520 to communicate with the host computer 4510 and the UE 4530. The hardware 4525 may include a communications interface 4526 for setting up and maintaining wired or wireless connections with interfaces of different communications devices of the communications system 4500, as well as a wireless interface 4527 for setting up and maintaining at least a wireless connection 4570 with a UE 4530 located within a coverage area (not shown in FIG. 22) served by the base station 4520. The communications interface 4526 may be configured to facilitate a connection 4560 to the host computer 4510. The connection 4560 may be direct, or the connection 4560 may pass through a core network (not shown in FIG. 22) of the communications system and / or one or more intermediate networks outside the communications system. In the embodiment shown, the hardware 4525 of the base station 4520 further includes processing circuitry 4528, which may comprise one or more programmable processors, application specific integrated circuits, field programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The base station 4520 further has software 4521 stored internally or accessible via an external connection.
[0121] The communication system 4500 further includes the previously mentioned UE 4530. The hardware 4535 of the UE 4530 may include a wireless interface 4537 configured to set up and maintain a wireless connection 4570 with a base station serving the coverage area in which the UE 4530 is currently located. The hardware 4535 of the UE 4530 further includes processing circuitry 4538, which may comprise one or more programmable processors, application specific integrated circuits, field programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The UE 4530 further includes software 4531 stored on or accessible by the UE 4530 and executable by the processing circuitry 4538. The software 4531 includes a client application 4532. The client application 4532 may be operable, with support from the host computer 4510, to provide services to a human or non-human user via the UE 4530. On the host computer 4510, a running host application 4512 may communicate with a running client application 4532 via an OTT connection 4550 that terminates at the UE 4530 and the host computer 4510. In providing services to a user, the client application 4532 may receive request data from the host application 4512 and provide user data in response to the request data. The OTT connection 4550 may transfer both the request data and the user data. The client application 4532 may interact with the user to generate the user data that the client application 4532 provides.
[0122] It should be noted that the host computer 4510, base station 4520, and UE 4530 illustrated in Figure 22 may be similar to or equivalent to the host computer 4430, one of the base stations 4412a, 4412b, and 4412c, and one of the UEs 4491 and 4492, respectively, of Figure 21. That is, the inner workings of these entities may be as shown in Figure 22, and separately, the surrounding network topology may be that of Figure 21.
[0123] 22, the OTT connection 4550 is drawn abstractly to illustrate communication between the host computer 4510 and the UE 4530 via the base station 4520, without explicit reference to intermediary devices and the exact routing of messages through those devices. The network infrastructure may determine the routing, and the network infrastructure may be configured to hide the routing from the UE 4530, or from the service provider operating the host computer 4510, or both. While the OTT connection 4550 is active, the network infrastructure may also make decisions to dynamically change the routing (e.g., based on load balancing considerations or reconfiguration of the network).
[0124] The wireless connection 4570 between the UE 4530 and the base station 4520 follows the teachings of embodiments described throughout this disclosure. One or more of various embodiments may improve performance of the OTT service provided to the UE 4530 using the OTT connection 4550 of which the wireless connection 4570 forms the last segment. More precisely, the teachings of these embodiments may improve random access speed and / or reduce random access failure rates, thereby providing benefits such as faster and / or more reliable random access.
[0125] Measurement procedures may be provided for the purpose of monitoring data rates, latency, and other factors that one or more embodiments improve upon. There may further be optional network functionality for reconfiguring the OTT connection 4550 between the host computer 4510 and the UE 4530 in response to fluctuations in the measurement results. The measurement procedures and / or the network functionality for reconfiguring the OTT connection 4550 may be implemented in software 4511 and hardware 4515 of the host computer 4510 or in software 4531 and hardware 4535 of the UE 4530, or both. In embodiments, sensors (not shown) may be deployed in or associated with communication devices through which the OTT connection 4550 passes, and the sensors may participate in the measurement procedures by providing values of the monitored quantities exemplified above, or other physical quantities from which the software 4511, 4531 may calculate or estimate the monitored quantities. Reconfiguration of the OTT connection 4550 may include message formats, retransmission settings, preferred routing, etc.; the reconfiguration need not affect the base station 4520, and the reconfiguration may be unknown or imperceptible to the base station 4520. Such procedures and functions may be known and practiced in the art. In some embodiments, the measurements may involve proprietary UE signaling that facilitates the host computer 4510's measurements of throughput, propagation time, latency, etc. The measurements may be implemented in software 4511 and 4531 causing messages, particularly empty or "dummy" messages, to be sent using the OTT connection 4550 while the software 4511 and 4531 monitors propagation times, errors, etc.
[0126] FIG. 23 illustrates a method implemented in a communications system including a host computer, a base station, and user equipment, according to some embodiments.
[0127] FIG. 23 is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be as described with reference to FIGS. 21 and 22. For simplicity of this disclosure, only a drawing reference to FIG. 23 is included in this section. In step 4610, the host computer provides user data. In sub-step 4611 of step 4610 (which may be optional), the host computer provides the user data by executing a host application. In step 4620, the host computer initiates a transmission carrying the user data to the UE. In step 4630 (which may be optional), the base station transmits the user data carried in the host computer initiated transmission to the UE, according to the teachings of the embodiments described throughout this disclosure. In step 4640 (which may also be optional), the UE executes a client application associated with the host application executed by the host computer.
[0128] FIG. 24 illustrates a method implemented in a communications system including a host computer, a base station, and user equipment, according to some embodiments.
[0129] FIG. 24 is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be as described with reference to FIGS. 21 and 22. For simplicity of this disclosure, only a drawing reference to FIG. 24 is included in this section. In step 4710 of the method, the host computer provides user data. In an optional sub-step (not shown), the host computer provides the user data by executing a host application. In step 4720, the host computer initiates a transmission carrying the user data to the UE. The transmission may proceed via the base station in accordance with the teachings of the embodiments described throughout this disclosure. In step 4730 (which may be optional), the UE receives the user data carried in the transmission.
[0130] FIG. 25 illustrates a method implemented in a communications system including a host computer, a base station, and user equipment, according to some embodiments.
[0131] FIG. 25 is a flowchart illustrating a method implemented in a communications system according to one embodiment. The communications system includes a host computer, a base station, and a UE, which may be as described with reference to FIGS. 21 and 22. For simplicity of this disclosure, only a drawing reference to FIG. 25 is included in this section. In step 4810 (which may be optional), the UE receives input data provided by the host computer. Additionally or alternatively, in step 4820, the UE provides user data. In sub-step 4821 (which may be optional) of step 4820, the UE provides the user data by executing a client application. In sub-step 4811 (which may be optional) of step 4810, the UE executes a client application that provides the user data in response to the received input data provided by the host computer. In providing the user data, the executed client application may further consider user input received from the user. Regardless of the particular manner in which the user data is provided, the UE initiates transmission of the user data to the host computer in sub-step 4830 (which may be optional). In method step 4840, the host computer receives user data transmitted from the UE according to the teachings of the embodiments described throughout this disclosure.
[0132] FIG. 26 illustrates a method implemented in a communication system including a host computer, a base station, and user equipment, according to some embodiments.
[0133] Figure 26 is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be as described with reference to Figures 21 and 22. For simplicity of this disclosure, only a drawing reference to Figure 26 is included in this section. In step 4910 (which may be optional), the base station receives user data from the UE in accordance with the teachings of embodiments described throughout this disclosure. In step 4920 (which may be optional), the base station initiates transmission of the received user data to the host computer. In step 4930 (which may be optional), the host computer receives the user data carried in the transmission initiated by the base station.
[0134] Any suitable step, method, feature, function, or benefit disclosed herein may be implemented through one or more functional units or modules of one or more virtual devices. Each virtual device may comprise several of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), dedicated digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory devices, optical storage devices, and the like. The program code stored in memory includes program instructions for implementing one or more communication and / or data communication protocols, as well as instructions for performing one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause each functional unit to perform a corresponding function according to one or more embodiments of the present disclosure.
[0135] The term unit may have its usual meaning in the field of electronics, electrical devices, and / or electronic devices, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logical solids and / or discrete devices, computer programs or instructions, etc., for performing respective tasks, procedures, calculations, output, and / or display functions, such as those described herein.
[0136] Further definitions and embodiments are discussed below.
[0137] In the above description of various embodiments of the inventive concept, it should be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the inventive concept. Unless otherwise specified, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the inventive concept belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning in accordance with the meaning of those terms in the context of this specification and the related art, and should not be interpreted in an idealized or overly formal sense unless expressly so defined herein.
[0138] When an element is referred to as being "connected," "coupled," or "responsive" to another element, or variations thereof, the element may be directly connected, coupled, or responsive to the other element, or intervening elements may be present. In contrast, when an element is referred to as being "directly connected," "directly coupled," or "directly responsive" to another element, or variations thereof, there are no intervening elements present. Like numbers refer to like elements throughout. Moreover, as used herein, "coupled," "connected," "responsive," or variations thereof may include wirelessly coupled, wirelessly connected, or wirelessly responsive. As used herein, the singular forms "a," "an," and "the" are intended to include the plural unless the context clearly dictates otherwise. For brevity and / or clarity, well-known functions or constructions may not be described in detail. The term "and / or" (abbreviated " / ") includes any and all combinations of one or more of the associated listed items.
[0139] Although terms such as first, second, third, etc. may be used herein to describe various elements / operations, it will be understood that these elements / operations are not limited by these terms. These terms are merely used to distinguish one element / operation from another. Thus, a first element / operation in some embodiments may be referred to as a second element / operation in other embodiments without departing from the teachings of the inventive concept. The same reference numbers or characters may refer to the same or similar elements throughout this specification.
[0140] As used herein, the terms "comprise," "comprising," "comprises," "include," "including," "includes," "have," "has," "having," or variations thereof, are open-ended and include one or more stated features, integers, elements, steps, components, or functions, but do not exclude the presence or addition of one or more other features, integers, elements, steps, components, functions, or groups thereof. Moreover, as used herein, the common abbreviation "eg," derived from the Latin phrase "exempli gratia," may be used to introduce or specifically name one or more general examples of the aforementioned items, without limiting such items. The common abbreviation "ie," derived from the Latin phrase "id est," may be used to specifically name a particular item from a more general statement.
[0141] Exemplary embodiments have been described herein with reference to block diagrams and / or flowchart illustrations of computer-implemented methods, apparatus (systems and / or devices), and / or computer program products. It should be understood that blocks of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, may be implemented by computer program instructions performed by one or more computer circuits. These computer program instructions may be provided to processor circuits of general-purpose computer circuits, special-purpose computer circuits, and / or other programmable data processing circuits to create machines, such that the instructions executing via the processor of the computer and / or other programmable data processing apparatus transform and control transistors, values stored in memory locations, and other hardware components within such circuits to implement the functions / acts specified in one or more blocks of the block diagrams and / or flowcharts, and thereby create means (functions) and / or structures for implementing the functions / acts specified in the block diagram and / or flowchart blocks.
[0142] The computer program instructions may also be stored on a tangible computer-readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored on the computer-readable medium produce an article of manufacture containing instructions that implement the functions / acts specified in one or more blocks of the block diagrams and / or flowcharts. Thus, embodiments of the inventive concepts may be embodied in hardware and / or in software (including firmware, resident software, microcode, etc.) running on a processor, such as a digital signal processor, which may be collectively referred to as a "circuit," "module," or variations thereof.
[0143] It should also be noted that in some alternative implementations, the functions / acts noted in the blocks may occur out of the order noted in the flowcharts. For example, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functions / acts involved. Moreover, the functionality of a given block of the flowcharts and / or block diagrams may be separated into multiple blocks, and / or the functionality of two or more blocks of the flowcharts and / or block diagrams may be at least partially integrated. Finally, other blocks may be added / inserted between the illustrated blocks, and / or blocks / acts may be omitted, without departing from the scope of the inventive concepts. Moreover, while some of the figures include arrows on communication paths to indicate a primary direction of communication, it should be understood that communication may occur in the opposite direction to the depicted arrows.
[0144] Numerous variations and modifications may be made to the embodiments without substantially departing from the principles of the inventive concept. All such variations and modifications are intended to be included herein within the scope of the inventive concept. Accordingly, the subject matter disclosed above should be considered illustrative and not limiting, and the example embodiments are intended to cover all such modifications, extensions, and other embodiments that fall within the spirit and scope of the inventive concept. Thereby, to the fullest extent permitted by law, the scope of the inventive concept should be determined by the broadest permissible interpretation of this disclosure, including example embodiments and their equivalents, and should not be limited or restricted by the above detailed description.
Claims
1. A method for establishing a secure connection in a wireless communication network, said method being executed by a control network node (500, 900) of said wireless communication network, said method comprising the steps of: receiving (1000) a request to use a communication service provided by the wireless communication network, the request including an indication that a communication device (300, 902) is capable of supporting authentication and key management (AKMA) services for the requested communication service and an application provided by the wireless communication network; determining (1002) whether the requested communication service and the AKMA service can be provided to the communication device (300, 902); communicating (1004) to the communication device (300, 902) information indicating whether the requested communication service and the AKMA service can be provided to the communication device for establishing the secure connection in the wireless communication network; A method comprising:
2. 2. The method of claim 1, wherein the control network node (500, 900) comprises a Policy Control Function (PCF) network node (900) of the wireless communication network.
3. The method according to any one of claims 1 to 2, wherein the requested communication service is provided by an Application Function (AF) (904) of the wireless communication network.
4. The method of claim 1 , wherein the requested communication service comprises a proximity service (ProSe) provided by an AF (904).
5. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) comprises: Obtaining information indicating whether said communication device (300, 902) is authorized to utilize said AKMA service. Including, 5. The method according to any one of claims 1 to 4.
6. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) comprises: Obtaining AKMA service availability information indicating whether the AF (904) is able to provide said AKMA service. Including, 6. The method according to any one of claims 1 to 5.
7. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) comprises: Based on the AKMA service availability information, the AF (904) determines (1100) that it can provide the AKMA service; determining (1102) that the communication device (300, 902) is authorized to use the AKMA service based on the information indicating whether the communication device (300, 902) is authorized to use the AKMA service; Including, Communicating the information comprises: and communicating (1104) information to the communication device (300, 902) indicating that the communication device (300, 902) is authorized to use the AKMA service with the AF (904) to establish the secure connection to receive the requested communication service. Including, 7. The method according to any one of claims 1 to 6.
8. The method of any one of claims 1 to 7, wherein the information includes an address associated with an AF (904) that can provide the AKMA service and the requested communication service.
9. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) comprises: Based on the AKMA service availability information, the AF (904) determines (1200) that it is unable to provide the AKMA service; determining (1202) that the communication device (300, 902) is authorized to use the AKMA service based on the information indicating whether the communication device (300, 902) is authorized to use the AKMA service; Including, Communicating the information comprises: and communicating (1204) information to the communication device (300, 902) indicating that the communication device (300, 902) is unable to use the AKMA service with the AF (904) to establish the secure connection to receive the requested communication service. Including, 7. The method according to any one of claims 1 to 6.
10. The method of any one of claims 1 to 6 and 9, wherein the information includes an address associated with an AF (904) that can provide the requested communication service.
11. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) comprises: Based on the AKMA service availability information, the AF (904) determines (1300) that it can provide the AKMA service; determining (1302) that the communication device (300, 902) is not authorized to use the AKMA service based on the information indicating whether the communication device (300, 902) is authorized to use the AKMA service; determining (1304) that the requested communication service and the AKMA service cannot be provided to the communication device (300, 902) based on information indicating that the communication device (300, 902) is not authorized to use the AKMA service and information indicating that the AF (904) providing the requested communication service supports the AKMA service; Including, 7. The method according to any one of claims 1 to 6.
12. Communicating to the communication device (300, 902) information indicating whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) comprises: communicating (1306) to the communication device (300, 902) information indicating that the requested communication service and the AKMA service cannot be provided to the communication device (300, 902), wherein the information does not include an address of an AF (904) that can provide the requested communication service. Including, 12. The method of any one of claims 1 to 6 and 11.
13. 1. A method for establishing a secure connection in a wireless communication network, the method being performed by a communication device (300, 902) operating in the wireless communication network, the method comprising: Communicating (1400) a request to use a communication service provided by the wireless communication network, the request including an indication that the communication device (300, 902) is capable of supporting authentication and key management (AKMA) services for the requested communication service and an application provided by the wireless communication network; receiving (1402) in response to communicating the request, a communication comprising information indicating whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) for establishing the secure connection in the wireless communication network; A method comprising:
14. communicating the request includes communicating the request towards a Policy Control Function (PCF) network node (500, 900) of the wireless communication network; receiving the communication comprising the information includes receiving the communication comprising the information from the PCF network node (500, 900); The method of claim 13.
15. The method according to any one of claims 13 to 14, wherein the requested communication service is provided by an Application Function (AF) (904) of the wireless communication network.
16. The method of any one of claims 13 to 15, wherein the requested communication service comprises a proximity service (ProSe) provided by an AF (904).
17. and establishing (1404) the secure connection with the AF (904) using the AKMA service to use the requested communication service from the AF (904) based on the address of the AF (904) included in the communication and information indicating that the requested communication service and the AKMA service can be provided to the communication device (300, 902) for establishing the secure connection in the wireless communication network.
17. The method of any one of claims 13 to 16, further comprising:
18. Establishing the secure connection comprises: generating 1500 a pre-shared key (PSK) identity based on an AKMA key identifier (A-KID) associated with the AKMA service; communicating (1502) a message to an AF (904) comprising a pre-shared key (PSK) extension containing the PSK identity, the A-KID, and an AKMA hint, the AKMA hint indicating to the AF (904) that the communication device (300, 902) supports the AKMA service and wishes to use the AKMA service to establish the secure connection; receiving (1504) a communication from the AF (904) comprising a PSK identity for the secure connection; Establishing (1506) the secure connection with the AF (904) based on the PSK identity; Including, 18. The method of any one of claims 13 to 17.
19. Establishing the secure connection with the AF (904) to receive the requested communication service from the AF (904) based on the address of the AF (904) included in the communication and information indicating that the requested communication service can be provided to the communication device (300, 902) without the communication device (300, 902) utilizing the AKMA service to establish the secure connection in the wireless communication network.
17. The method of any one of claims 13 to 16, further comprising:
20. A method for establishing a secure connection in a wireless communication network, the method being performed by a network node (500, 904) of the wireless communication network, the method comprising the steps of: receiving (1600) from a core network node (500, 902) a request for AKMA service availability information indicating whether the network node is able to provide AKMA services for establishing a secure connection for a requested communication service between a communication device (300, 902) operating in the wireless communication network and the network node (500, 904); communicating (1602) the AKMA service availability information to the core network node (500, 902) indicating whether the network node (500, 904) is able to provide the AKMA service for establishing the secure connection for the requested communication service; A method comprising:
21. the network node (500, 904) comprises an Application Function (AF) of the wireless communication network configured to provide the requested communication service; the core network node (500, 902) comprises a Policy Control Function (PCF) network node (902) of the wireless communication network; 21. The method of claim 20.
22. The method of any one of claims 20 to 21, wherein the requested communication service comprises a proximity service (ProSe) provided by an AF (904).
23. The AKMA service availability information indicates that the network node (500, 904) is capable of providing the AKMA service, and the method comprises: receiving (1700) a message from the communication device (300, 902) comprising a Pre-Shared Key (PSK) extension based on an AKMA Key Identifier (A-KID) associated with the AKMA service, the A-KID, and an AKMA hint, the AKMA hint indicating to an AF (904) that the communication device (300, 902) supports the AKMA service and wishes to use the AKMA service to establish the secure connection; communicating (1702) a communication to the communication device (300, 902) comprising a PSK identification for the secure connection; establishing (1704) the secure connection with the communication device (300, 902) based on the PSK identification; further comprising:
23. The method of any one of claims 20 to 22.
24. the AKMA service availability information indicates that the network node is unable to provide the AKMA service, and the method further comprises: Providing the requested communication service to the communication device (300, 902) without utilizing the AKMA service. further comprising:
23. The method of any one of claims 20 to 22.
25. A communication device (300), A processing circuit (303); a memory (305) coupled to said processing circuit; Equipped with The memory includes instructions that, when executed by the processing circuitry, cause the communications device to perform the operations of any one of claims 13 to 19. A communication device (300).
26. A communication device (300) adapted to perform according to any one of claims 13 to 19.
27. 20. A computer program comprising program code to be executed by a processing circuit (303) of a communications device (300), whereby execution of said program code causes said communications device (300) to perform the operations of any one of claims 13 to 19.
28. A core network (CN) node (500, 900), A processing circuit (503); a memory (505) coupled to said processing circuit; Equipped with The memory includes instructions that, when executed by the processing circuitry, cause the CN node (500, 900) to perform the operations of any one of claims 1 to 12. Core Network (CN) nodes (500, 900).
29. A Core Network (CN) node (500, 900) adapted to perform according to any one of claims 1 to 12.
30. 13. A computer program comprising program code to be executed by a processing circuit (403) of a core network (CN) node (500, 900), whereby execution of the program code causes the CN node (500, 900) to perform the operations of any one of claims 1 to 12.
31. A network node (500, 904), A processing circuit (503); a memory (505) coupled to said processing circuit; Equipped with The memory includes instructions that, when executed by the processing circuitry, cause the network node (500, 904) to perform the operations of any one of claims 20 to 24. A network node (500, 904).
32. A network node (500, 904) adapted to perform according to any one of claims 20 to 24.
33. 25. A computer program comprising program code to be executed by a processing circuit (403) of a network node (500, 904), whereby execution of the program code causes the network node (500, 904) to perform the operations of any one of claims 20 to 24.