Relay and security procedure routing

The relay selection and security authentication procedures are optimized using a CP security indicator to improve service continuity and reduce interruptions during path switching in UE-to-network relays.

JP2025537194APending Publication Date: 2025-11-14NOKIA TECHNOLOGIES OY
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025526199
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-11-07
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Path switching in UE-to-network relays can cause service continuity issues, service delays, and interruptions due to authentication and key generation processes during path switching between indirect network communication paths.

Method used

Optimizes the relay selection procedure by using a CP security indicator associated with the RSC and enhancing the security authentication process to improve service continuity during path switching between ProSe L3 relays.

Benefits of technology

Enhances service continuity and reduces service interruptions by optimizing the relay selection and security authentication procedures in UE-to-network relays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025537194000001_ABST
    Figure 2025537194000001_ABST
Patent Text Reader

Abstract

An embodiment of the present disclosure relates to a path switching between a relay and a security procedure. A terminal device obtains a selection policy for selecting an RSC from a plurality of RSCs, each of which is associated with an indicator for indicating whether the RSC supports a CP security procedure or a UP security procedure. Based on determining that a path switching is triggered from a source relay terminal device having a source RSC, the terminal device selects a target RSC based on the selection policy, the source indicator being associated with the source RSC, and the indicators being associated with the plurality of RSCs. For the path switching, the terminal device selects a target relay terminal device based on the target RSC. In this way, service continuity after a path switching between relays can be improved, and service delays and interruptions can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Various exemplary embodiments relate to the field of communications, and more particularly to devices, methods, apparatus, and computer-readable storage media for routing between relays and security procedures. [Background technology]

[0002] A user equipment (UE)-to-network relay may involve one or more relays, such as a Layer 3 UE-to-network (U2N) relay and a Layer 2 UE-to-network relay. Path switching between two indirect network communication paths for a UE-to-network relay may include multiple path switching scenarios. During path switching, service continuity, service delay, or interruption may be considered. Summary of the Invention

[0003] Generally, exemplary embodiments of the present disclosure provide devices, methods, apparatus, and computer-readable storage media for routing between relay security procedures.

[0004] In a first aspect, a remote terminal device is provided, the remote terminal device comprising: at least one processor; and at least one memory that stores instructions that, when executed by the at least one processor, cause the remote terminal device to at least: obtain a selection policy for selecting a relay selection code (RSC) from a plurality of RSCs, the RSCs among the plurality of RSCs being associated with an indicator indicating whether the RSC supports control plane (CP) security procedures or user plane (UP) security procedures; select a target RSC based on the selection policy, the source indicator associated with the source RSC, and a plurality of indicators associated with the plurality of RSCs based on determining that a path switch from a source relay terminal device having a source RSC has been triggered; and select a target relay terminal device based on the target RSC for path switch.

[0005] In a second aspect, a remote terminal is provided, the remote terminal comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the remote terminal to at least obtain an authentication policy used by the remote terminal to determine whether to trigger a Proximity Services (ProSe) authentication procedure, and determine to trigger the ProSe authentication procedure based at least on the authentication policy.

[0006] In a third aspect, an Authentication Server Function (AUSF) device is provided. The AUSF device includes at least one processor and at least one memory that stores instructions that, when executed by the at least one processor, cause the AUSF device to at least generate a root key that is independent of a Relay Selection Code (RSC), the root key being used to generate at least one Proximity-Based Services (ProSe) key for establishing a security link for direct communication between a remote terminal device and a relay terminal device, and to send a ProSe key registration request to a ProSe Anchor Function (PAnF) device without using the RSC.

[0007] In a fourth aspect, a method is provided, the method including: acquiring, at a remote terminal device, a selection policy for selecting a relay selection code (RSC) from a plurality of RSCs, where the RSC among the plurality of RSCs is associated with an indicator indicating whether the RSC supports control plane (CP) security procedures or user plane (UP) security procedures; selecting a target RSC based on the selection policy, a source indicator associated with the source RSC, and a plurality of indicators associated with the plurality of RSCs based on determining that a path switch from a source relay terminal device having a source RSC has been triggered; and selecting a target relay terminal device based on the target RSC for path switch.

[0008] In a fifth aspect, a method is provided, the method including: obtaining, in a remote terminal device, an authentication policy used by the remote terminal device to determine whether to trigger a Proximity Services (ProSe) authentication procedure; and determining to trigger the ProSe authentication procedure based at least on the authentication policy.

[0009] In a sixth aspect, a method is provided, the method including: generating, in an authentication server function (AUSF) device, a root key independent of a relay selection code (RSC), the root key being used to generate at least one proximity-based service (ProSe) key for establishing a security link for direct communication between a remote terminal device and a relay terminal device; and sending, to a ProSe anchor function (PAnF) device, a ProSe key registration request without using the RSC.

[0010] In a seventh aspect, there is provided an apparatus comprising means for carrying out a method according to the third, fourth or fifth aspects.

[0011] In an eighth aspect, there is provided a computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform a method according to the third, fourth or fifth aspect.

[0012] In a ninth aspect, there is provided a computer program comprising instructions which, when executed by an apparatus, causes the apparatus to perform at least a method according to the third, fourth or fifth aspect.

[0013] In a tenth aspect, an apparatus is provided, the apparatus including: a circuit for obtaining, in a remote terminal device, a selection policy for selecting an RSC from a plurality of relay selection codes (RSCs), where the RSC among the plurality of RSCs is associated with an indicator indicating whether the RSC supports control plane (CP) security procedures or user plane (UP) security procedures; a circuit for selecting a target RSC based on determining that a path switch from a source relay terminal device having a source RSC has been triggered, based on the selection policy, a source indicator associated with the source RSC, and a plurality of indicators associated with the plurality of RSCs; and a circuit for selecting a target relay terminal device for path switch based on the target RSC.

[0014] In an eleventh aspect, an apparatus is provided, the apparatus comprising: a circuit for, in a remote terminal device, obtaining an authentication policy used by the remote terminal device to determine whether to trigger a Proximity Services (ProSe) authentication procedure; and determining to trigger the ProSe authentication procedure based on at least the authentication policy.

[0015] In a twelfth aspect, an apparatus is provided, the apparatus comprising: a circuit for generating, in an authentication server function (AUSF) device, a root key independent of a relay selection code (RSC), the root key being used to generate at least one proximity-based service (ProSe) key for establishing a security link for direct communication between a remote terminal device and a relay terminal device; and sending, to a ProSe anchor function (PAnF) device, a ProSe key registration request without using the RSC.

[0016] Other features and preferred embodiments of the present disclosure will become apparent from the following description of specific embodiments, taken in conjunction with the accompanying drawings which illustrate, in illustrative embodiments, the principles of the presently disclosed embodiments. [Brief explanation of the drawings]

[0017] Embodiments of the present disclosure are presented by way of example, and the advantages thereof will be explained in more detail below with reference to the accompanying drawings. [Figure 1A] FIG. 1A illustrates an exemplary communication environment in which embodiments of the present disclosure may be implemented. [Figure 1B] FIG. 1B illustrates a PC5 security establishment procedure for 5G ProSe UE-to-network relay communication over the user plane. [Figure 1C] FIG. 1C illustrates the PC5 security establishment procedure for 5G ProSe UE-to-network relay communication over the control plane. [Figure 2] FIG. 2 is a flowchart illustrating an example process of RSC selection in some example embodiments of the present disclosure. [Figure 3] FIG. 3 shows an example signaling chart illustrating an example process of RSC selection in some embodiments of the present disclosure. [Figure 4] FIG. 4 illustrates an example flowchart illustrating an example process for selecting an RSC and a relay based on a CP security indicator in accordance with some exemplary embodiments of the present disclosure. [Figure 5] FIG. 5 shows an example of a flowchart illustrating an exemplary process for optimizing security procedures in some embodiments of the present disclosure. [Figure 6] FIG. 6 illustrates an example flowchart illustrating an exemplary process for optimizing CP security procedures in some embodiments of the present disclosure. [Figure 7] FIG. 7 shows an example signaling chart illustrating an optimized UP security procedure in some embodiments of the present disclosure. [Figure 8] FIG. 8 shows an example signaling chart illustrating an optimized CP security procedure in some embodiments of the present disclosure. [Figure 9]FIG. 9 shows a simplified block diagram of an apparatus suitable for implementing exemplary embodiments of the present disclosure. [Figure 10] 10 is a block diagram of an exemplary computer-readable medium in accordance with some embodiments of the present disclosure. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. DETAILED DESCRIPTION OF THE INVENTION

[0018] The principles of the present disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are set forth merely to facilitate understanding and to assist those skilled in the art in understanding and practicing the present disclosure, and are not intended to imply any limitation on the scope of the present disclosure. The disclosure described herein may be implemented in various forms other than those described below.

[0019] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0020] References in this disclosure to "one embodiment," "embodiment," "exemplary embodiment," etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not all embodiments need include the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an exemplary embodiment, it is understood by those skilled in the art that such feature, structure, or characteristic may be affected in connection with other embodiments, whether or not explicitly stated.

[0021] Although terms such as "first" and "second" may be used herein to describe various elements, it should be understood that these elements should not be limited by these terms. These terms are used only to distinguish the function of the various elements. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0022] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit example embodiments. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise. It will be further understood that the terms "comprises," "comprising," "has," "having," "includes," and / or "including," as used herein, identify the presence of stated features, elements, and / or components, etc., but do not exclude their presence. As used herein, "at least one of, " and "at least one of ," and similar expressions where a list of two or more elements is joined by "and" or "or," mean at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0023] As used in this application, the term "circuit" means (a) hardware-only circuit implementations (e.g., analog and / or digital-only implementations); (b) a combination of hardware circuitry and software, e.g., (where applicable); (i) a combination of analog and / or digital hardware circuitry and software / firmware; (ii) software (including digital signal processors), which, in conjunction with software and hardware processor(s) with memory(s), cause a device, such as a mobile phone or server, to perform various functions; (c) hardware circuitry(s) and processor(s), such as microprocessor(s) or portions of microprocessors(s), that require software (e.g., firmware) to operate, but that may be absent when not necessary for operation; It may refer to one or more or all of the following:

[0024] This definition of circuit applies to all uses of the term in this application, including the claims. As a further example, as used herein, the term circuit also covers simply a hardware circuit or processor (or processors) or part of a hardware circuit or processor and its (or their) accompanying software and / or firmware implementation. The term circuit also covers, for example, a baseband or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device, if applicable to particular claim elements.

[0025] As used herein, the term "communication network" refers to a network conforming to any suitable communication standard, such as a fifth-generation (5G) system, Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), or Narrowband Internet of Things (NB-IoT). Furthermore, communications between terminal devices and network devices in a communication network may be performed according to any suitable generation of communication protocols, including, but not limited to, fourth-generation (4G), 4.5G, future fifth-generation (5G) New Radio (NR) communication protocols, and / or other protocols currently known or developed in the future. Embodiments of the present disclosure may be applied to various communication systems. Given the rapid development of communications, there will, of course, be future communication technologies and systems in which the present disclosure may be embodied. The scope of the present disclosure should not be considered limited to only the aforementioned systems.

[0026] As used herein, the term "network equipment" refers to a node in a communication network through which terminal devices access the network and receive services therefrom. Depending on the applicable terminology and technology, the network equipment may refer to a base station (BS) or access point (AP), e.g., a Node B (Node B or NB), an evolved Node B (eNode B or eNB), a NR next-generation Node B (gNB), a remote radio unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, or a low-power node such as a femto or pico. The RAN-split architecture includes a gNB-CU (centralized unit, hosting RRC, SDAP, and PDCP) that controls multiple gNB-DUs (distributed units, hosting RLC, MAC, and PHY). A relay node corresponds to the DU portion of an IAB node.

[0027] The term "terminal" refers to any terminal capable of wireless communication. By way of example and not limitation, a terminal may also be referred to as a communication device, UE, subscriber station (SS), mobile subscriber station, mobile station (MS), or access terminal (AT). Terminal devices include, but are not limited to, mobile phones, cellular phones, smartphones, voice-over-IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop mounted devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPEs), Internet of Things (IoT) devices, wearables such as watches, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronics devices, devices operating in commercial and / or industrial wireless networks, etc. Terminal devices may also correspond to the mobile termination (MT) portion of an integrated access backhaul (IAB) node (relay node). In the following description, the terms "terminal equipment", "communication equipment", "terminal", "user equipment" and "UE" may be used interchangeably.

[0028] While the functions described in this example may be performed in fixed and / or wireless network nodes in various exemplary embodiments, the functions in other exemplary embodiments may be implemented in a user equipment device (such as a mobile phone, tablet computer, laptop computer, desktop computer, mobile IoT device, or fixed IoT device). The user equipment in this example may include corresponding functions as described in connection with, for example, a fixed network node, a wireless network node, and / or a non-wired network node(s). The user equipment device may be a user equipment control device, such as a chipset or processor, configured to control the user equipment when attached to the user equipment. Examples of such functions include a bootstrap server function and / or a home subscriber server, which may be implemented in the user equipment device by providing the user equipment device with software configured to cause the user equipment device to execute in terms of these functions / nodes.

[0029] As described, path switching between two indirect network communication paths for a UE-to-network relay can include, for example, switching of a Layer 3 UE-to-network relay with a non-3GPP interworking function (N3IWF) from a Layer 3 UE-to-network relay with an N3IWF to a Layer 3 UE-to-network relay with an N3IWF, switching of a Layer 3 UE-to-network relay without an N3IWF to a Layer 3 UE-to-network relay without an N3IWF, switching of a Layer 3 UE-to-network relay without an N3IWF to a Layer 3 UE-to-network relay with an N3IWF, switching of a Layer 2 UE-to-network relay to a Layer 2 UE-to-network relay, switching of a Layer 2 UE-to-network relay to a Layer 2 UE-to-network relay without an N3IWF, switching of a Layer 2 UE-to-network relay to a Layer 3 UE-to-network relay with an N3IWF, This may include several path switching scenarios, such as switching to a UE-to-network relay.

[0030] It should be understood that service continuity in different path switching cases can be achieved by application layer or session continuity. For service continuity during path switching, several aspects may be considered, such as what are the triggers and criteria for path switching, how to select a UE-to-network relay for path switching, specifying a path switching procedure that takes service continuity into consideration, and specifying how service continuity is achieved for a path switching solution.

[0031] Regarding triggers and criteria for path switching, the remote UE can switch paths when the measurement thresholds and criteria set by the NG-RAN are met, or based on reselection rules from the application layer, if any. Furthermore, if multiple UE-to-network relay UEs meet the relay reselection criteria, the remote UE selects a target UE-to-network relay for path switching based on the 5G ProSe policy or UE path selection policy (URSP) rules and the remote UE's traffic processing, taking into account the following: Furthermore, the remote UE may use reselection rules from the application layer (e.g., provided by the application server), and when the remote UE discovers that there are multiple UE-to-network relay UEs that meet the reselection rules, it selects a target UE-to-network relay UE based on the priority in the reselection rules from the application layer.

[0032] In the case of path switching between two indirect Layer 3 UE-to-network relay paths using an N3IWF, the use of the Mobility and Multihoming Protocol (MOBIKE) may be chosen as an exemplary work.

[0033] However, when a remote UE switches to another relay UE, a new authentication and ProSe Remote User Key (PRUK) generation may be triggered, which requires time and resources and may affect service continuity and cause service interruptions.

[0034] In some embodiments, the present disclosure proposes a solution to optimize the relay selection procedure based on the CP security indicator associated with the RSC, further optimizing the security authentication procedure and improving service continuity after path switching between ProSe L3 relays.

[0035] The principles and embodiments of the present disclosure are described in detail below with reference to Figures 1A-10. Figure 1A illustrates a schematic diagram of an exemplary communication environment 100 in which embodiments of the present disclosure may be implemented. As shown in Figure 1A, the communication environment 100 may include a remote UE 110, UE-to-network relays 121 and 122, NG-RANs 131 and 132, a 5G Core (5GC) 140, and a data network 145. Furthermore, it should be understood that the number of devices is for ease of understanding only, without implying any limitation. The communication environment 100 may include any suitable number or types of devices adapted to implement embodiments of the present disclosure.

[0036] 1A , remote UE 110 may connect to UE-to-network relay 121 via a PC5 interface and communicate with data network 145 via a UE-to-network relay or a UE-to-network relay with N3IWF access. Furthermore, communication environment 100 may support service continuity when remote UE 110 connected to data network 145 via 5G ProSe UE-to-network relay 121 (i.e., an indirect network communication path) switches to another indirect network communication path, for example, via 5G ProSe UE-to-network relay 122.

[0037] In the context of this disclosure, the term "UE-to-network relay" may be used interchangeably with "5G ProSe Layer 3 UE-to-network relay," "5G ProSe UE-to-network relay," "U2N relay," "relay UE," or "relay terminal equipment." The term "remote UE" may be used interchangeably with "5G ProSe remote UE" or "relay terminal equipment."

[0038] ProSe may be a service that can be provided by a 3rd Generation Partnership Project (3GPP®) system based on UEs in close proximity to each other. This feature was introduced in LTE and evolved in 5G systems (5GS). 5GS enablers for ProSe include the functions of 5G ProSe Direct Discovery, 5G ProSe Direct Communication, and 5G ProSe U2N Relay.

[0039] PC5 is the reference point between ProSe-enabled UEs used for the control and user planes of 5G ProSe Direct Discovery, 5G ProSe Direct Communication, and 5G ProSe U2N Relay.

[0040] Communications in communication environment 100 may be implemented according to any suitable communications protocol(s), including, but not limited to, a first-generation (1G), second-generation (2G), third-generation (3G), fourth-generation (4G), fifth-generation (5G), or future sixth-generation (6G) wireless local network communications protocol, a cellular communications protocol such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or other protocols now known or developed in the future. Further, communications may utilize any suitable wireless communications technology, including, but not limited to, code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplex (FDD), time division duplex (TDD), multiple-input multiple-output (MIMO), orthogonal frequency division multiple access (OFDM), discrete Fourier transform spread OFDM (DFT-s-OFDM), and / or any other technology now known or developed in the future.

[0041] 1B shows a PC5 security establishment procedure 150 for 5G ProSe UE-to-network relay communication over the user plane (UP). The procedure 150 may involve a remote UE 110, a UE-to-network relay 121, a 5G Direct Discovery Name Management Function (DDNMF) 151 of the remote UE 110, a ProSe Key Management Function (PKMF) 152 of the remote UE 110, a 5G DDNMF 153 of the relay 121, a PKMF 154 of the relay 121, and a Unified Data Management (UDM) (or Binding Support Function (BSF) or Home Subscriber Server (HSS)) 155 of the remote UE 110.

[0042] A 5G ProSe remote UE may be provisioned with discovery security material and a ProSe remote user key (i.e., UP-PRUK) when it is in coverage. These security materials may have an expiration date, after which they become invalid. If the UE does not have valid discovery security material, the 5G ProSe remote UE may need to contact the 5G ProSe Key Management Function (PKMF) and obtain new ones to use the 5G ProSe UE-to-network relay service.

[0043] This procedure describes a scenario where the 5G PKMF of the 5G ProSe remote UE is different from the 5G PKMF of the 5G ProSe UE-to-network relay. When both the 5G ProSe remote UE and the 5G ProSe UE-to-network relay are served by a single 5G PKMF, the 5G PKMF can take on the roles of the 5G PKMF of the 5G ProSe remote UE and the 5G PKMF of the 5G ProSe UE-to-network relay, and message exchange between the 5G PKMFs is not required.

[0044] As shown in FIG. 1B, at 160a, the 5G ProSe remote UE can obtain a 5G PKMF address from the 5G DDNMF of its HPLMN. Alternatively, the 5G ProSe remote UE may be provisioned with a 5G PKMF address by a Policy Control Function (PCF). If the 5G ProSe remote UE is provisioned with a 5G PKMF address, the 5G ProSe remote UE can directly access the 5G PKMF without requesting the 5G DDNMF. If the 5G ProSe remote UE cannot access the 5G PKMF using its provisioned 5G PKMF address, the 5G ProSe remote UE can request a 5G PMKF address from the 5G DDNMF.

[0045] In 160b, the 5G ProSe remote UE can establish a secure connection with the 5G PKMF over the PC8 reference point. Security of the PC8 interface depends on Ua security when the Generic Bootstrapping Architecture (GBA) is used, or on Ua* security when the Application Authentication and Key Management (AKMA) is used. The 5G PKMF of the 5G ProSe remote UE can check whether the 5G ProSe remote UE is authorized to receive UE-to-network relay services, and if the UE is authorized, the 5G PKMF of the 5G ProSe remote UE provides discovery security material to the 5G ProSe remote UE. If the 5G ProSe remote UE provides a list of visited networks, the 5G PKMF of the 5G ProSe remote UE can request discovery security material from the 5G PKMF of a potential 5G ProSe UE-to-network relay from which the 5G ProSe remote UE obtains relay services. The 5G PKMF of the 5G ProSe UE-to-network relay can include a PC5 security policy in the 5G ProSe remote UE.

[0046] Note that the 5G PKMF may locally configure the authorization information of the UE. If not, the 5G PKMF may interact with the UE's UDM to obtain the UE's authorization information. Furthermore, the 5G ProSe remote UE may be provisioned by the PCF with a list of networks that may be visited for the 5G ProSe UE-to-network relay service (identified by the RSC).

[0047] At 160c, the 5G ProSe UE-to-network relay may obtain a 5G PKMF address from the Home Public Land Mobile Network (HPLMN) in the same manner as described in step 160a.

[0048] In 160d, the 5G ProSe UE-to-network relay may establish a secure connection with the 5G PKMF over the PC8 reference point, similar to step 160b. The 5G PKMF of the 5G ProSe UE-to-network relay checks whether the 5G ProSe UE-to-network relay is authorized to provide the 5G ProSe UE-to-network relay service, and if the UE is authorized, the 5G PKMF of the 5G ProSe UE-to-network relay may provide discovery security material to the 5G ProSe UE-to-network relay. The 5G PKMF of the 5G ProSe UE-to-network relay may include a PC5 security policy in the 5G ProSe UE-to-network relay.

[0049] In 161a, the 5G ProSe remote UE may send a PRUK request message to its 5G PKMF. This message may indicate that the 5G ProSe remote UE is requesting a UP-PRUK from the 5G PKMF. If the 5G ProSe remote UE already has a UP-PRUK from this 5G PKMF, the message may also include the UP-PRUK ID of the UP-PRUK.

[0050] The UP-PRUK Identifier (ID) takes the form of either a Network Access Identifier (NAI) or a 64-bit string. If the UP-PRUK ID is in NAI format, i.e. username@realm, the realm part may contain the HPLMN ID. The username part may contain a 64-bit string.

[0051] In 161b, the 5G PKMF may check whether the 5G ProSe remote UE is authorized to receive the UE-to-network relay service. This is done by using the ID of the 5G ProSe remote UE associated with the key used to establish the secure connection between the 5G ProSe remote UE and the 5G PKMF in step 160b. If the 5G ProSe remote UE is authorized to receive the service, the 5G PKMF may send the UP-PRUK and UP-PRUK ID to the 5G ProSe remote UE. If the UP-PRUK and UP-PRUK ID are included, the 5G ProSe remote UE may store them and delete any previously stored for this 5G PKMF.

[0052] It should be noted that steps 160a, 160b, 161a, 161b are performed when the 5G ProSe remote UE is in coverage.

[0053] At 162, a discovery procedure may be performed between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay using the discovery parameters and discovery security material.

[0054] In 163, the 5G ProSe remote UE may send a direct communication request (DCR) to the 5G ProSe UE-to-network relay, including the UP-PRUK ID or an encrypted subscriber identity (SUCI) if the remote UE does not have a valid UP-PRUK, the RSC of the 5G ProSe UE-to-network relay service, and a key for freshness parameter 1 of NR PC5 (KNRP). If the UP-PRUK ID is not in NAI format, the DCR message may include the HPLMN ID of the 5G ProSe remote UE. The PC5 security establishment procedure between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay, including security parameter, security policy negotiation, and message protection, may follow the one-to-one security establishment.

[0055] At 164a, the 5G ProSe UE-to-network relay may send a key request message to the 5G PKMF including the UP-PRUK ID or SUCI, RSC, and KNRP freshness parameter 1. The key request message may also include the HPLMN ID of the 5G ProSe remote UE if included in the DCR.

[0056] At 164b, upon receiving the key request message, the 5G PKMF of the 5G ProSe UE-to-network relay may check whether the 5G ProSe UE-to-network relay is authorized to provide relay services to the 5G ProSe remote UE based on the ID of the 5G ProSe UE-to-network relay associated with the key used to establish the secure PC8 connection and the received RSC.

[0057] Note that the 5G PKMF of the 5G ProSe UE-to-network relay may need to authorize the RSC based on its implementation. Furthermore, if the authorization information of the 5G ProSe UE-to-network relay is not locally available, the 5G PKMF can request the authorization information from the UDM (not shown) of the 5G ProSe UE-to-network relay using the Nudm_SDM_Get service. If the 5G ProSe UE-to-network relay is authorized to provide relay services based on ProSe subscriber data, the 5G PKMF of the 5G ProSe UE-to-network relay can send a key request including the UP-PRUK ID or SUCI to the 5G PKMF of the 5G ProSe remote UE. If the UP-PRUK ID, HPLMN ID, or SUCI of the 5G ProSe remote UE is included in the key request message, the 5G PKMF of the 5G ProSe UE-to-network relay identifies the 5G PKMF address of the 5G ProSe remote UE based on it.

[0058] It should be noted that the 5G PKMF of the 5G ProSe remote UE may need to authorize the RSC based on its implementation.

[0059] In 164c, upon receiving a key request message from the 5G PKMF of the 5G ProSe UE-to-network relay, the 5G PKMF of the 5G ProSe remote UE can check whether the 5G ProSe remote UE is authorized to use the relay service. The authorization check for the relay service is performed based on the UP-PRUK ID and RSC included in the key request message, or the SUPI and RSC of the remote UE included in the key request message. If the SUCI is included in the key request message, the 5G PKMF of the 5G ProSe remote UE can request the UDM of the 5G ProSe remote UE to deconceal the SUCI to obtain the SUPI using the Nudm_UEIdentifier_Deconceal service, and the UDM invokes a Subscriber Identifier Deconcealment Function (SIDF) to deconceal the SUCI to obtain the Subscriber Persistent Identifier (SUPI). If the authorization information of the 5G ProSe remote UE is not available locally, the 5G PKMF can request the authorization information from the UDM of the 5G ProSe remote UE (not shown).

[0060] Note that privacy issues may need to be considered while deciding whether to send the SUPI to the PKMF. For privacy control, the UDM can authorize the PKMF based on the NF type or the service provider domain.

[0061] If a new UP-PRUK is required, the 5G PKMF may perform one of the following procedures (as shown in step 164c):

[0062] If the 5G PKMF of the 5G ProSe remote UE supports a Zpn interface to the BSF of the 5G ProSe remote UE, the 5G PKMF of the 5G ProSe remote UE can request the GBA Push Information (GPI) of the 5G ProSe remote UE from the BSF. When requesting the GPI, the 5G PKMF can include the UP-PRUK ID in the P-TID field. Upon receiving the GPI, the 5G PKMF can use Ks(_ext)_NAF as the UP-PRUK.

[0063] If the 5G PKMF of the 5G ProSe remote UE supports a service-based interface (SBI) to the BSF of the 5G ProSe remote UE, the 5G PKMF can request the GPI via the SBI interface. Upon receiving the GPI, the 5G PKMF can use Ks(_ext)_NAF as the UP-PRUK.

[0064] If the 5G PKMF of the 5G ProSe remote UE supports a PC4a interface to the UE's HSS, the 5G PKMF of the 5G ProSe remote UE can request the GBA authentication vector (AV) of the 5G ProSe remote UE from the HSS. Upon receiving the AV, the 5G PKMF locally forms a GPI that includes the UP-PRUK ID in the P-TID field. The 5G PKMF can use Ks(_ext)_NAF as the UP-PRUK.

[0065] If the 5G PKMF of the 5G ProSe remote UE is collocated or integrated with the BSF function and supports the SBI interface to the UDM / HSS of the 5G ProSe remote UE, the 5G PKMF can request the GBA AV via the SBI interface. Upon receiving the AV, the 5G PKMF locally forms a GPI that includes the UP-PRUK ID in the P-TID field. The 5G PKMF can use Ks(_ext)_NAF as the UP-PRUK.

[0066] Note that GPI is only supported when a GBA is used.

[0067] In 164d, the 5G PKMF of the 5G ProSe remote UE may generate a KNRP freshness parameter 2 and derive the KNRP using the UP-PRUK ID, the RSC, the KNRP freshness parameter 1, and the UP-PRUK identified by the KNRP freshness parameter 2. Then, the 5G PKMF of the 5G ProSe remote UE sends a key response message including the KNRP and the KNRP freshness parameter 2 to the 5G PKMF of the 5G ProSe UE-to-network relay. This message may include a GPI, if generated. The 5G PKMF of the 5G ProSe remote UE may include a remote user ID of the 5G ProSe remote UE in the key response message to the 5G ProSe UE-to-network relay. The UP-PRUK ID is used as a remote user ID in this specification.

[0068] In 164e, the 5G PKMF of the 5G ProSe UE-to-network relay may send a key response message to the 5G ProSe UE-to-network relay, including the GPI, if used to calculate the remote user ID, the KNRP, the KNRP freshness parameter 2, and the freshness UP-PRUK to the UE-to-network relay.

[0069] In 165a, the 5G ProSe UE-to-network relay may derive a session key (KNRP-SESS) from the KNRP and may derive a confidentiality key (NRPEK) (if applicable) and an integrity key (NRPIK) based on the security policy of PC5. The 5G ProSe UE-to-network relay may store the remote user identity received in step 4d. The 5G ProSe UE-to-network relay may send a Direct Security Mode Command message to the 5G ProSe remote UE. This message may also include the KNRP freshness parameter 2.

[0070] In 165b, when the 5G ProSe remote UE receives a message including the GPI, it processes the GPI, and the 5G ProSe remote UE can derive the UP-PRUK and obtain the UP-PRUK ID from the GPI.

[0071] The 5G ProSe remote UE derives KNRP from the UP-PRUK, RSC, KNRP freshness parameter 1, and the received KNRP freshness parameter 2. Then, just like the 5G ProSe UE-to-network relay, it derives the session key (KNRP-SESS), confidentiality key (NRPEK) (if applicable), and integrity key (NRPIK) based on the PC5 security policy, and processes the direct security mode command. By successfully verifying the direct security mode command, the 5G ProSe remote UE securely ensures that the 5G ProSe UE-to-network relay is authorized to provide relay services.

[0072] A synchronization failure process (details of synchronization failure) is performed when the UE processes the authentication challenge with the GPI. The 5G ProSe remote UE may send a Direct Security Mode Failure message and include RAND and AUTS in the message. When the 5G ProSe UE-to-network relay receives the Direct Security Mode Failure message from the 5G ProSe remote UE, it may send a key request message to the 5G PKMF of the 5G ProSe remote UE via the 5G PKMF of the 5G ProSe UE-to-network relay. The key request message may include the HPLMN ID of the 5G ProSe remote UE, the relay service code, and the KNRP freshness parameter 1, along with the RAND and AUTS received from the 5G ProSe remote UE. If the 5G PKMF of the 5G ProSe remote UE decides to retry the GBA Push procedure, the 5G PKMF of the 5G ProSe remote UE may request a GPI as described in step 164c.

[0073] At 165c, the 5G ProSe remote UE may respond to the 5G ProSe UE-to-network relay with a direct security mode complete message.

[0074] In 165d, upon receiving the direct security mode complete message, the 5G ProSe UE-to-network relay may verify the direct security mode complete message. If the direct security mode complete message is successfully verified, the 5G ProSe UE-to-network relay securely ensures that the 5G ProSe remote UE is authorized to obtain relay service.

[0075] In 165e, after successful verification, the 5G ProSe UE-network relay responds with a direct communication acceptance message to the 5G ProSe remote UE, completing the PC5 connection establishment procedure.

[0076] At 166, the 5G ProSe remote UE and the 5G ProSe UE-to-network relay continue with the remaining procedures for relay service over the secure PC5 link, including establishing a new protocol data unit (PDU) session or modifying an existing PDU session for relaying, if necessary.

[0077] When the 5G ProSe Layer 3 UE-to-network relay sends the remote UE report to the session management function (SMF), the 5G ProSe Layer 3 UE-to-network relay may include the remote user ID received in step 164d. If the PRUK ID used as the remote user ID is not in NAI format, the 5G ProSe Layer 3 UE-to-network relay may include the HPLMN ID of the 5G ProSe remote UE in the remote UE report.

[0078] 1C shows a PC5 security establishment procedure 170 for 5G ProSe UE-to-network relay communication over the control plane (CP). The procedure 170 may involve a remote UE 110, a UE-to-network relay 121, an Access and Mobility Management Function (AMF) 171 of the remote UE 110, an AMF 172 of the relay 121, an Authentication Server Function (AUSF) 173 of the remote UE 110, a UDM 155 of the remote UE 110, and a ProSe Anchor Function (PAnF) 174 of the remote UE 110.

[0079] Procedure 170 describes a procedure for establishing a PC5 link between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay. This procedure includes a method for authenticating the 5G ProSe remote UE by the AUSF of the 5G ProSe remote UE via the 5G ProSe UE-to-network relay and the AMF of the 5G ProSe UE-to-network relay during the 5G ProSe PC5 establishment. This mechanism can be used when the 5G ProSe remote UE is out of coverage.

[0080] At 180, the 5G ProSe remote UE and the 5G ProSe UE-to-network relay may be registered with the network. The 5G ProSe UE-to-network relay may be authenticated and authorized by the network to provide the UE-to-network relay service. The 5G ProSe remote UE may be authenticated and authorized by the network to receive the UE-to-network relay service. A PC5 security policy is provisioned to the 5G ProSe remote UE and the 5G ProSe UE-to-network relay, respectively, during this authentication and information provisioning procedure.

[0081] At 181, the 5G ProSe remote UE or relay UE can initiate a discovery procedure using either the Model A or Model B method.

[0082] At 182, after discovering the 5G ProSe UE-to-network relay, the 5G ProSe remote UE can send a direct communication request to the 5G ProSe UE-to-network relay to establish a secure PC5 unicast link. The 5G ProSe remote UE can include its security capabilities and PC5 signaling security policy in a DCR message. The message can also include a relay service code, Nonce_1.

[0083] If the 5G ProSe remote UE does not have a valid 5G ProSe remote user key (CP-PRUK), the 5G ProSe remote UE may include the SUCI in the DCR to trigger 5G ProSe remote UE-specific authentication and establish the CP-PRUK.

[0084] If the 5G ProSe remote UE already has a CP-P for a valid relay service code, the 5G ProSe remote UE may include the CP-PRUK ID associated with the DCR to indicate that it wants to obtain a relay connection using the CP-PRUK.

[0085] In 183, upon receiving the DCR message, the 5G ProSe UE-to-network relay may send a relay key request including the SUCI or CP-PRUK ID, RSC, and Nonce_1 received in the DCR message to the 5G ProSe UE-to-network relay's AMF. The 5G ProSe UE-to-network relay may also include in the message a transaction identifier that identifies the 5G ProSe remote UE for subsequent messages on the 5G ProSe UE-to-network relay's NAS message.

[0086] At 184, the AMF of the 5G ProSe UE-network relay may verify with the UDM whether the 5G ProSe UE-network relay is authorized to provide the UE-network relay service.

[0087] In 185, the AMF of the 5G ProSe UE-network relay selects an AUSF based on the SUCI or CP-PRUK ID and forwards the parameters received in the relay key request to the AUSF in a Nausf_UEAuthentication_ProseAuthenticate Request message. The Nausf_UEAuthentication_ProseAuthenticate Request message includes the SUCI or CP-PRUK ID of the 5G ProSe remote UE, a relay service code, and Nonce_1. If the CP-PRUK ID is received from the AMF of the 5G ProSe UE-network relay, the AUSF of the 5G ProSe remote UE temporarily stores Nonce_1, and the UE skips steps 186 to 189. If the SUCI of the 5G ProSe remote UE is received from the AMF of the 5G ProSe UE-network relay, the AUSF of the 5G ProSe remote UE temporarily stores Nonce_1 and the relay service code, and skips step 190.

[0088] At 186, the AUSF may use the received ProSe-specific parameters (i.e., RSC, etc.) to initiate 5G ProSe remote UE-specific authentication.

[0089] The AUSF of the 5G ProSe remote UE can obtain the authentication vector and routing indicator of the 5G ProSe remote UE from the UDM via the Nudm_UEAuthentication_GetProseAv Request message. Upon receiving the Nudm_UEAuthentication_GetProSeAv Request, the UDM can call the unencrypted SUCI of the SIDF to obtain the SUPI before processing the request. The UDM checks whether the UE is authorized to use the ProSe UE-to-network relay service based on the authorization information in the UE's subscriber data. If the UE is authorized, the UDM can select the EAP-AKA (extensible authentication protocol authentication and key agreement) authentication method based on the received Nudm_UEAuthentication_GetProseAv Request.

[0090] In 187a, the AUSF may temporarily store the XRES, the routing indicator, and the SUPI. The AUSF of the 5G ProSe remote UE may trigger authentication of the 5G ProSe remote UE based on EAP-AKA. The AUSF of the 5G ProSe remote UE generates an EAP-Request / AKA-Challenge message and sends the EAP-Request / AKA-Challenge message to the AMF of the 5G ProSe UE-to-network relay in a Nausf_UEAuthentication_ProSeAuthenticate response message.

[0091] In 187b, the AMF of the 5G ProSe UE-to-network relay may forward the Relay Authentication Request (including the EAP-Request / AKA´-Challenge) to the 5G ProSe UE-to-network relay on an NAS message and include the transaction identifier of the 5G ProSe remote UE in the message. The NAS message is secured using the NAS security context created for the 5G ProSe UE-to-network relay.

[0092] At 187c, based on the transaction identifier, the 5G ProSe UE-to-network relay can forward the EAP-Request / AKA´-Challenge to the 5G ProSe remote UE on a PC5 message.

[0093] The USIM of the 5G ProSe remote UE can verify the freshness of the received value by checking whether it can accept the AUTN.

[0094] For EAP-AKA', the USIM calculates the response RES. The USIM may return RES, CK, and IK to the ME. The ME may derive CK' and IK'.

[0095] At 187d, the 5G ProSe remote UE returns the EAP-Response / AKA´-Challenge to the 5G ProSe UE-to-Network Relay in a PC5 message.

[0096] In 187e, the 5G ProSe UE-network relay forwards the EAP-Response / AKA´-Challenge together with the transaction identifier of the 5G ProSe remote UE to the AMF of the 5G ProSe UE-network relay in the NAS message Relay Authentication Response.

[0097] In 187f, the AMF of the 5G ProSe UE-network relay can forward the EAP-Response / AKA´-Challenge to the AUSF of the 5G ProSe remote UE via Nausf_UEA Authentication_ProSeAuthenticate Request.

[0098] The AUSF of the 5G ProSe remote UE can perform UE authentication by verifying the received information.

[0099] For EAP-AKA´, the AUSF of the 5G ProSe remote UE and the 5G ProSe remote UE can exchange EAP-Request / AKA´-Notification and EAP-Response / AKA´-Notification messages via the AMF of the 5G ProSe UE-to-network relay and the 5G ProSe UE-to-network relay. After the exchange, the 5G ProSe remote UE and the AUSF of the 5G ProSe remote UE can derive the KAUSF_P in the same way as the KAUSF is derived.

[0100] At 188, upon successful authentication, the 5G ProSe remote UE and the AUSF of the 5G ProSe remote UE can generate a CP-PRUK and a CP-PRUK ID.

[0101] The CP-PRUK ID is in NAI format, i.e. username@realm, where the username part contains the routing indicator and CP-PRUK ID from step 186, and the realm part contains the home network identifier.

[0102] In 189a, the AUSF of the 5G ProSe remote UE selects a PAnF based on the CP-PRUK ID and sends the SUPI, RSC, CP-PRUK, and CP-PRUK ID to the PAnF in an Npanf_ProseKey_Register Request message.

[0103] At 189b, the PAnF stores the 5G ProSe remote UE's rose context information (i.e., SUPI, RSC, CP-PRUK, CP-PRUK ID) and sends an Npanf_ProseKey_Register Response message to the AUSF.

[0104] At 190a, the AUSF of the 5G ProSe remote UE selects a PAnF based on the CP-PRUK ID and sends the received CP-PRUK ID and RSC in a Npanf_ProseKey_get Request message.

[0105] In 190b, the PAnF obtains the CP-PRUK based on the CP-PRUK ID and checks whether the 5G ProSe remote UE is authorized to use the UE-to-network relay service based on the received RSC. If the 5G ProSe remote UE is authorized and the obtained CP-PRUK is valid, the PAnF sends an Npanf_ProseKey_get response message including the CP-PRUK to the AUSF.

[0106] At 191, the AUSF of the 5G ProSe remote UE generates Nonce_2 and derives the KNR_ProSe key using CP-PRUK, Nonce_1, and Nonce_2 as defined in section A.4.

[0107] In 192, the AUSF of the 5G ProSe remote UE may send KNR_ProSe, Nonce_2 in a Nausf_UEA Authentication_ProseAuthenticate Response message to the 5G ProSe UE-to-network relay via the AMF of the 5G ProSe UE-to-network relay. If step 187 is performed successfully, an EAP success message may be included. The AUSF of the 5G ProSe remote UE may also include the CP-PRUK ID in the message.

[0108] In 193, upon receiving KNR_ProSe from the AUSF of the 5G ProSe remote UE via the AMF of the 5G ProSe UE-network relay, the 5G ProSe UE-network relay may derive the PC5 session key Krelay-sess, the confidentiality key Krelay-enc (if applicable), and the integrity key Krelay-int from KNR_ProSe. The KNR_ProSe ID and Krelay-sess ID are established in the same manner as the KNRP ID and KNRP-sess ID. The 5G PRUK ID may be sent from the AMF of the 5G ProSe UE-network relay to the UE-network relay. If an EAP success message is received from the AUSF, it may also be sent from the AMF of the 5G ProSe UE-network relay to the UE-network relay.

[0109] At 194, the 5G ProSe UE-to-network relay may send the received Nonce_2 and the PC5 signaling security policy of the 5G ProSe remote UE to the 5G ProSe remote UE in a Direct Security Mode Command message that is integrity protected using Krelay-int. If received from the AMF of the 5G ProSe UE-to-network relay, an EAP success message may be included.

[0110] In 195, the 5G ProSe remote UE may generate a KNR_ProSe key to be used for remote access via the 5G ProSe UE-to-network relay in the same manner as defined in step 191. The 5G ProSe remote UE may derive a PC5 session key Krelay-sess and confidentiality and integrity keys from the KNR_ProSe in the same manner as defined in step 193.

[0111] The 5G ProSe remote UE may verify the Direct Security Mode Command message. If the Direct Security Mode Command message is successfully verified, the 5G ProSe remote UE securely ensures that the 5G ProSe UE-to-network relay is authorized to provide relay services.

[0112] At 196, the 5G ProSe remote UE may send a Direct Security Mode Complete message including its PC5 user plane security policy to the 5G ProSe UE-to-network relay, where the message is protected by a Krelay-enc derived from a Krelay-int or / and a Krelay-sess in accordance with the PC5 signaling policy negotiated between the 5G ProSe remote UE and the 5G ProSe UE-to-network relay.

[0113] In 197, upon receiving the direct security mode complete message, the 5G ProSe UE-to-network relay may verify the direct security mode complete message. If the direct security mode complete message is successfully verified, the 5G ProSe UE-to-network relay securely ensures that the 5G ProSe remote UE is authorized to obtain relay service.

[0114] After successfully verifying the direct security mode complete message, the 5G ProSe UE-network relay can respond with a direct communication accept message to the 5G ProSe remote UE, terminate the PC5 connection establishment procedure, and store the CP-PRUK ID in the security context associated with the PC5 link with the 5G ProSe remote UE.

[0115] Further communication between the 5G ProSe remote UE and the network is performed securely via a 5G ProSe UE-to-network relay.

[0116] When the 5G ProSe Layer 3 UE-to-network relay sends a remote UE report to the SMF, the 5G ProSe Layer 3 UE-to-network relay may include the remote user ID (i.e., the 5G PRUK ID received in step 13) in the message.

[0117] As described, a remote UE can switch between different UE-to-Network (U2N) relays, including switching between U2N L3 relays.

[0118] Furthermore, a secure link can be established between the remote UE and the U2N relay before the remote UE uses the relay to send traffic. Security procedures can be performed to authenticate and authorize the UE to use the ProSe relay service and to generate keys to protect the link between the remote UE and the U2N relay. 3GPP supports two modes of security procedures for authentication and key generation for L3 relay: UP-based and CP-based.

[0119] There are six possible use cases: CP-based re-authentication and key generation may be triggered, UP-based re-authentication and key generation may be triggered, or no re-authentication may be triggered and the same PRUK may be used to derive the communication key. Table 1 below lists the route switching cases and whether or not re-authentication and key generation is triggered in each case. [Table 1]

[0120] As shown in the table above, when a remote UE switches to another relay UE, a new authentication and PRUK generation may be triggered, which requires time and resources and may cause service interruptions and affect service continuity.

[0121] In some embodiments, the present disclosure proposes a solution that optimizes the relay selection procedure based on a CP security indicator associated with an RSC. For example, a remote UE (i.e., a remote terminal device) can select an RSC with a valid security context. In some embodiments, the remote UE can select an RSC without a CP security indication and include a UP-PRUK ID in the DCR if the corresponding UP-PRUK is valid. In some embodiments, if both the CP-PRUK and UP-PRUK corresponding to an RSC are valid, the remote UE can select an RSC with the same CP / UP mode as the current RSC and include a CP / UP-PRUK ID in the DCR. In some embodiments, if neither the CP-PRUK nor the UP-PRUK corresponding to an RSC is valid, the remote UE can prioritize an RSC with the same CP / UP mode as the current RSC and include a SUCI in the DCR. In some embodiments, the priority is preset by the HPLMN of the remote UE through authorization and provisioning procedures or depends on the UE implementation.

[0122] 2 shows an example of a flowchart illustrating an example process 200 of RSC selection in some embodiments of the present disclosure. For ease of understanding, the process 200 may include a remote UE 110 (which may also be referred to as a remote terminal device) as shown in FIGS.

[0123] At block 210, the remote UE 110 obtains a selection policy for selecting an RSC from a plurality of RSCs, one of which is associated with an indicator (e.g., a CP security indicator) for indicating whether the RSC supports CP security procedures or UP security procedures.

[0124] In block 220, based on determining that a path switch from a source relay terminal device having a source RSC has been triggered, the remote UE 110 selects a target RSC based on a selection policy. A source indicator is associated with the source RSC, and multiple indicators are associated with multiple RSCs. In block 230, the remote UE 110 selects a target relay UE (i.e., target terminal device) for the path switch based on the target RSC.

[0125] In some embodiments, the remote UE 110 can select a target relay terminal device having a target RSC that is the same as the source RSC. In some embodiments, the remote UE 110 can determine multiple RSCs and obtain multiple indicators. Furthermore, the remote UE 110 can determine whether the source RSC and multiple RSCs support CP security procedures or UP security procedures based on the source RSC and the multiple indicators.

[0126] In some embodiments, the remote UE 110 may select as the target RSC one of a plurality of RSCs for which the remote terminal device has a valid root key. In some embodiments, based on determining that the source RSC supports the CP security procedure, the remote UE 110 may select as the target RSC one of a plurality of RSCs for which the remote terminal device has a valid root key and which supports the CP security procedure.

[0127] Alternatively or additionally, based on determining that the source RSC supports the UP security procedure, the remote UE 110 may select as the target RSC one of a plurality of RSCs for which the remote terminal device has a valid root key and which supports the UP security procedure.

[0128] In some embodiments, the remote UE 110 can generate a DCR that includes the ID of a valid root key that is used for at least one secure connection to establish a security link for direct communication between the remote terminal device and the target relay terminal device.

[0129] In some embodiments, based on determining that the source RSC supports the CP security procedure, remote UE 110 may select one of at least one candidate RSC that supports the CP security procedure as the target RSC. Alternatively or additionally, based on determining that the source RSC supports the UP security procedure, remote UE 110 may select one of multiple RSCs that support the UP security procedure as the target RSC. Alternatively, or in addition, remote UE 110 may randomly select one of the multiple RSCs as the target RSC.

[0130] In some embodiments, the remote UE 110 may generate a DCR that includes a SUCI that is used to trigger a ProSe authentication procedure for the remote terminal device.

[0131] In some embodiments, the selection policy may include a selection order based on CP security procedures or UP security procedures supported by the source RSC and the target RSC, and may be further based on an authentication policy. Alternatively or additionally, the selection policy may include an authentication policy used by the remote terminal device to determine whether to trigger a ProSe authentication procedure. In some embodiments, the selection policy and / or the authentication policy may be pre-configured by the HPLMN of the remote UE or based on the implementation of the remote UE.

[0132] 3 shows an example signaling chart illustrating an example process 300 for RSC selection in some embodiments of the present disclosure. The example process 300 may involve the remote UE 110, relays 121 and 122, the AMF 171 of the remote UE 110 or the PKMF 152 (referred to as 201) of the remote UE 110, the PKMF 154 of the relay 121, the PKMF 202 of the relay 122, the PCF 203 of the remote UE 110, and the AUSF 173 of the remote UE 110.

[0133] 3, the remote UE 110 may be equipped with a CP indicator-related RSC selection policy (e.g., RSC selection priority) at 310. Alternatively, or in addition, the remote UE 110 may be provisioned with a re-authentication policy, etc.

[0134] At 311, the remote UE 110 may select a relay UE 121 for communication.

[0135] At 312, a path switch may be triggered from relay UE 121 to, for example, relay UE 122.

[0136] At 313, the remote UE 110 may select an RSC and corresponding relay based on the CP indicator associated with the RSC. If the priority associated with the CP security indicator is pre-configured in the remote UE, the UE should follow the order required by the HPLMN to select an RSC, but may otherwise depend on the UE implementation.

[0137] 4 shows an example 400 of RSC selection based on a CP indicator. As shown in FIG. 4, after a path switch is triggered (401), the remote UE 110 may determine (402) whether a relay exists that has the same RSC as the current relay (i.e., the source relay). If a relay with the same RSC is found, the remote UE 110 may select that relay as the target relay for the path switch. If a relay with the same RSC is not found (403), the remote UE 110 may select a candidate RSC (404).

[0138] Next, remote UE 110 may obtain CP security indicators associated with the source RSC and the candidate RSC to determine whether the RSCs support CP- or UP-based security procedures (405). For example, if a CP security indicator is present, it may indicate that the corresponding RSC supports CP-based security procedures; otherwise, if no CP- or UP-based security procedures are present, it may indicate that the corresponding RSC supports UP-based security procedures. It should be understood that the format of the CP security indicator is described for ease of understanding only, without implying any limitation on the scope of the present disclosure, and that the CP security indicator may be implemented in any suitable format.

[0139] The remote UE 110 may determine whether there is an RSC that has a valid PRUK and supports the same security procedures as the source RSC (406). If an RSC that has a valid PRUK and supports the same security procedures is found, the remote UE 110 may select that RSC as the target RSC, use the target RSC to select a target relay, and include the PRUK ID in the DCR (408). If an RSC that has a valid PRUK and supports the same security procedures is not found, the remote UE 110 may determine whether there is an RSC with a valid PRUK. If an RSC with a valid PRUK is found, the remote UE 110 may select that RSC as the target RSC, use the target RSC to select a target relay, and include the PRUK ID in the DCR (408).

[0140] If an RSC with a valid PRUK is not found, the remote UE 110 may determine whether there is an RSC that supports the same security procedures as the source RSC. If an RSC that supports the same security procedures is found, the remote UE 110 may select that RSC as the target RSC, use the target RSC to select a target relay, and include the SUCI in the DCR. If an RSC that supports the same security procedures is not found, the remote UE 110 may randomly select an RSC from the candidate RSCs or based on the remote UE implementation. The remote UE 110 may then select the randomly selected RSC as the target RSC, use the target RSC 410 to select a target relay, and include the SUCI in the DCR.

[0141] It should be understood that flowchart 400 is provided for ease of understanding only, with no limitation implied, and that the RSC selection policies of the present disclosure may be performed in any suitable order.

[0142] Returning to Figure 3, at 314 (i.e., 314a-d), the procedure for direct communication can be followed as shown in Figures 1B and 1C. For brevity, the procedure will not be repeated here.

[0143] According to the above embodiments, the present disclosure proposes a solution to optimize the relay selection procedure based on the CP security indicator associated with the RSC, which can improve service continuity after path switching between ProSe L3 relays and avoid service delays or interruptions.

[0144] According to other embodiments, the present disclosure further proposes a solution for optimizing CP and UP security procedures to reduce re-authentication during route switching while maintaining the freshness of the PRUK during remote UE mobility. For example, in UP and CP-based procedures, ProSe re-authentication / authorization and PRUK regeneration may be triggered in the following cases: If the remote UE moves to a new PLMN, ProSe re-authentication / authorization and PRUK regeneration may be triggered by the remote UE, similar to primary authentication. If the remote UE selects relaying in the new PLMN, ProSe re-authentication / authorization and PRUK regeneration may be triggered by the remote UE. The HPLMN may trigger re-authentication in cases of PRUK expiration, subscription data change, etc. In some embodiments, if the remote UE switches to a different RSC, re-authentication may not be triggered even in CP-based procedures.

[0145] In some embodiments, the present disclosure proposes a re-authentication policy, where the same PRUK is used for the remote UE regardless of the RSC change. Re-authentication may be determined based on a re-authentication policy provisioned to the remote UE through authorization and provisioning procedures, or may be UE implementation dependent.

[0146] 5 is a flowchart illustrating an example process 500 for optimizing security procedures in some embodiments of the present disclosure. For ease of understanding, the process 500 may include a remote UE 110 (which may also be referred to as a remote terminal device) as shown in FIGS.

[0147] In block 510, the remote UE 110 obtains an authentication policy that the remote terminal device uses to determine whether to trigger a ProSe authentication procedure. In block 520, the remote UE 110 determines to trigger a ProSe authentication procedure based at least on the authentication policy.

[0148] In some embodiments, the authentication policy may be based on the mobility of the remote terminal device. In some embodiments, the remote UE 110 may decide to trigger a ProSe authentication procedure based on the remote terminal device moving to a new serving PLMN. In some embodiments, the remote UE 110 may decide to trigger a ProSe authentication procedure based on the remote terminal device selecting a relay terminal device in the new serving PLMN.

[0149] In some embodiments, the remote UE 110 may determine to trigger a ProSe authentication procedure based on the root key being invalid, which may be used to generate at least one security key for establishing a security link for direct communication between the remote terminal device and the relay terminal device.

[0150] In some embodiments, the ProSe authentication procedure can constitute a CP security procedure. Furthermore, the remote UE 110 can decide to trigger the ProSe authentication procedure based on the authentication policy, regardless of changes in the RSC, and the generation of the root key is independent of the RSC.

[0151] 6 is a flowchart illustrating an example process 600 for optimizing CP security procedures according to some embodiments of the present disclosure. For ease of understanding, the process 600 may include an AUSF 173, as shown in FIG. 1C.

[0152] In block 610, the AUSF 173 generates a root key independently of the RSC. The root key is used to generate at least one ProSe key for establishing a security link for direct communication between the remote terminal device and the relay terminal device. In block 620, the AUSF 173 sends a ProSe key registration request to the PAnF device 174 without using the RSC.

[0153] In some embodiments, the AUSF 173 may send a ProSe key acquisition request to the PAnF device to trigger a relay service authorization procedure for the remote terminal device based on the RSC. In some embodiments, the AUSF 173 may generate at least a ProSe security key based on at least the RSC. The at least ProSe security key may be RSC-specific. In some embodiments, the root key may include a CP-PRUK.

[0154] 7 shows an example signaling chart illustrating an optimized UP security procedure 700 in accordance with some embodiments of the present disclosure. The procedure 700 may include a remote UE 110, a UE-to-network relay 121, a 5G DDNMF 151 of the remote UE 110, a PKMF 152 of the remote UE 110, a 5G DDNMF 153 of the relay 121, a PKMF 154 of the relay 121, and a UDM (or BSF or HSS) 155 of the remote UE 110.

[0155] As shown in Figure 7, at 710a, the remote UE 110 may be provisioned with a re-authentication policy, etc. At 710b-710d, the remote UE 110 may follow the procedures as shown in Figure 1B for PRUK request, discovery, and communication with the L3 U2N relay.

[0156] At 710e, the remote UE 110 may move to a new area. At 711, based on the availability of a UPPRUK and a re-authentication policy pre-configured in the remote UE or UE implementation, the remote UE 110 may trigger re-authentication. For example, the remote UE 110 may trigger re-authentication if the UE moves to a new serving PLMN or if the local PRUK is invalid (e.g., expired, in error, etc.).

[0157] At 712a, if the remote UE 110 is in the coverage area, the remote UE 110 sends a PRUK request to the HPLMN to obtain a new key, which may trigger re-authentication / authorization and PRUK generation. At 712b, if the remote UE 110 is not in the coverage area, the remote UE 110 includes the SUCI in its next DCR request to the U2N relay.

[0158] The remaining procedures of the relay service may be similar to those shown in FIG. 1B and will not be repeated here.

[0159] 8 illustrates an example signaling chart illustrating an optimized CP security procedure 800 in accordance with some embodiments of the present disclosure. The procedure 800 may involve the remote UE 110, the UE-to-network relay 121, the AMF 171 of the remote UE 110, the AMF 172 of the relay 121, the AUSF 173 of the remote UE 110, the UDM 155 of the remote UE 110, and the PAnF 174 of the remote UE 110.

[0160] At 810, the 5G ProSe remote UE and the 5G ProSe UE-to-network relay may be registered with the network. The 5G ProSe UE-to-network relay may be authenticated and authorized by the network to provide the UE-to-network relay service. The 5G ProSe remote UE is authenticated and authorized by the network to receive the UE-to-network relay service. A PC5 security policy is provided to the 5G ProSe remote UE and the 5G ProSe UE-to-network relay, respectively, during this authentication and information provisioning procedure.

[0161] Furthermore, unlike the procedure shown in Figure 1C, a re-authentication policy is provided to the 5G ProSe remote UE.

[0162] At 811, based on the availability of the CP-PRUK and re-authentication policy pre-configured in the remote UE or UE implementation, the remote UE can trigger ProSe authentication / re-authentication. For example, the remote UE can trigger re-authentication if the UE moves to a new serving PLMN or if the local PRUK is invalid (e.g., expired, error, etc.).

[0163] At 812, after discovering the 5G ProSe UE-to-network relay, the 5G ProSe remote UE may send a direct communication request to the 5G ProSe UE-to-network relay to establish a secure PC5 unicast link. The 5G ProSe remote UE may include security capabilities and PC5 signaling security policies in a DCR message. The message may also include a relay service code, Nonce_1.

[0164] If the 5G ProSe remote UE does not have a valid 5G ProSe remote user key (CP-PRUK) and re-authentication is required, the 5G ProSe remote UE can trigger 5G ProSe remote UE-specific authentication and establish the CP-PRUK by including the SUCI in the DCR.

[0165] If the 5G ProSe remote UE already has a valid CP-P for the relay service code and no re-authentication is required, the 5G ProSe remote UE may include the CP-PRUK ID associated with the DCR to indicate that it wants to obtain a relay connection using the CP-PRUK.

[0166] Steps 813 and 814 are similar to steps 183 and 184 shown in FIG. 1C and will not be repeated here.

[0167] In 815, the AMF of the 5G ProSe UE-to-network relay selects an AUSF based on the SUCI or CP-PRUK ID and forwards the parameters received in the relay key request to the AUSF in a Nausf_UEA Authentication_ProseAuthenticate Request message. The Nausf_UEA Authentication_ProseAuthenticate Request message includes the SUCI or CP-PRUK ID of the 5G ProSe remote UE, a relay service code, and Nonce_1. If the CP-PRUK ID is received from the AMF of the 5G ProSe UE-to-network relay, the AUSF of the 5G ProSe remote UE temporarily stores Nonce_1, and the UE skips steps 186 to 189. If the SUCI of the 5G ProSe remote UE is received from the AMF of the 5G ProSe UE-to-network relay, the AUSF of the 5G ProSe remote UE temporarily stores Nonce_1 and the relay service code. Unlike step 185 shown in FIG. 1C , step 820 is not skipped.

[0168] At 816, the AUSF may initiate 5G ProSe remote UE-specific authentication without using the received ProSe-specific parameters (i.e., RSC, etc.).

[0169] Steps 817a-818 are similar to steps 187a-188 shown in FIG. 1C and will not be repeated here.

[0170] In 819a, the AUSF of the 5G ProSe remote UE selects a PAnF based on the CP-PRUK ID and sends the SUPI, CP-PRUK, and CP-PRUK ID in an Npanf_ProseKey_Register Request message to the PAnF. Unlike step 189a shown in Figure 1C, the AUSF of the 5G ProSe remote UE does not send the RSC in the Npanf_ProseKey_Register Request message to the PAnF.

[0171] In 819b, the PAnF stores the prose context information (i.e., SUPI, CP-PRUK, CP-PRUK ID) of the 5G ProSe remote UE and sends an Npanf_ProseKey_Register Response message to the AUSF. Unlike step 189b shown in Figure 1C, the AUSF of the 5G ProSe remote UE may store the prose context information without the RSC.

[0172] At 820a, select a PAnF based on the 5G ProSe remote UE AUSF CP-PRUK ID and send the received CP-PRUK ID and RSC in a Npanf_ProseKey_get Request message.

[0173] In 820b, the PAnF may be able to obtain the CP-PRUK based on the CP-PRUK ID and checks whether the 5G ProSe remote UE is authorized to use the UE-to-network relay service based on the received RSC. If the 5G ProSe remote UE is authorized and the obtained CP-PRUK is valid, the PAnF sends an Npanf_ProseKey_get response message including the CP-PRUK to the AUSF.

[0174] At 821, the AUSF of the 5G ProSe remote UE generates Nonce_2 and derives the KNR_ProSe key using CP-PRUK, RSC, Nonce_1, and Nonce_2.

[0175] Steps 822-827 are similar to steps 192-197 shown in FIG. 1C and will not be repeated here.

[0176] In some embodiments, an apparatus capable of performing any of the methods 200 (e.g., a remote UE 110) may comprise means for performing each step of the method 200. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module.

[0177] In some embodiments, the apparatus comprises: means for obtaining, in a remote terminal device, a selection policy for selecting a relay selection code (RSC) from a plurality of RSCs, wherein the RSC among the plurality of RSCs is associated with an indicator for indicating whether the RSC supports control plane (CP) security procedures or user plane (UP) security procedures; means for selecting a target RSC based on the selection policy, a source indicator associated with the source RSC, and a plurality of indicators associated with the plurality of RSCs based on determining that a path switch from a source relay terminal device having a source RSC has been triggered; and means for selecting a target relay terminal device based on the target RSC for path switch.

[0178] In some embodiments, the means for selecting a target relay terminal device based on the target RSC comprises means for selecting a target relay terminal device having a target RSC that is the same as the source RSC. In some embodiments, the apparatus further comprises means for determining a plurality of RSCs, means for obtaining a plurality of indicators, and means for determining, based on the source RSC and the plurality of indicators, whether the source RSC and the plurality of RSCs support CP security procedures or UP security procedures.

[0179] In some embodiments, the means for selecting a target relay terminal device based on the target RSC comprises means for selecting one of a plurality of RSCs for which the remote terminal device has a valid root key as the target RSC. In some embodiments, the means for selecting a target relay terminal device based on the target RSC comprises means for selecting one of a plurality of RSCs for which the remote terminal device has a valid root key and which support the CP security procedure as the target RSC based on determining that the source RSC supports the CP security procedure.

[0180] In some embodiments, the means for selecting a target relay terminal device based on the target RSC comprises means for selecting, as the target RSC, one of a plurality of RSCs for which the remote terminal device has a valid root key and which supports UP security procedures, based on determining that the source RSC supports UP security procedures.

[0181] In some embodiments, the apparatus further comprises means for generating a direct communication request (DCR) including an ID of a valid root key, the valid root key being used to generate at least one security key for establishing a security link for direct communication between the remote terminal device and the target relay terminal device.

[0182] In some embodiments, the apparatus further comprises means for selecting one of at least one candidate RSC supporting CP security procedures as the target RSC based on determining that the source RSC supports CP security procedures, means for selecting one of a plurality of RSCs supporting UP security procedures as the target RSC based on determining that the source RSC supports UP security procedures, or means for randomly selecting one of the plurality of RSCs as the target RSC.

[0183] In some embodiments, the device further comprises means for generating a DCR including an encrypted subscriber identity (SUCI) used to trigger a proximity-based services (ProSe) authentication procedure of the remote terminal device. In some embodiments, the selection policy includes at least one of a selection order based on CP security procedures or UP security procedures supported by the source RSC and the target RSC, or an authentication policy used by the remote terminal device to determine whether to trigger a proximity-based services (ProSe) authentication procedure. In some embodiments, the selection policy is preset by the home public land mobile network (HPLMN) of the remote terminal device or based on the remote terminal device's implementation.

[0184] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 200. In some embodiments, the means comprises at least one processor and at least one memory containing computer program code, the at least one memory and the computer program code configured, together with the at least one processor, to cause the apparatus to execute.

[0185] In some embodiments, an apparatus capable of performing any of the methods 500 (e.g., a remote UE 110) may comprise means for performing each step of the method 500. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module.

[0186] In some embodiments, the apparatus comprises means, in a remote terminal device, for obtaining an authentication policy used by the remote terminal device to determine whether to trigger a proximity-based service (ProSe) authentication procedure, and means for determining to trigger the ProSe authentication procedure based on at least the authentication policy.

[0187] In some embodiments, the authentication policy is based on mobility of the remote terminal. In some embodiments, the means for determining to trigger a ProSe authentication procedure comprises means for determining to trigger a ProSe authentication procedure based on the remote terminal moving to a new serving public land mobile network (PLMN). In some embodiments, the means for determining to trigger a ProSe authentication procedure comprises means for determining to trigger a ProSe authentication procedure based on the remote terminal selecting a relay terminal in the new serving PLMN.

[0188] In some embodiments, the means for determining to trigger a ProSe authentication procedure comprises means for determining to trigger a ProSe authentication procedure based on a root key being invalid, the root key being used to generate at least one security key for establishing a security link for direct communication between the remote terminal device and the relay terminal device.

[0189] In some embodiments, the ProSe authentication procedure comprises a control plane (CP) security procedure. Further, the means for determining to trigger the ProSe authentication procedure based on at least an authentication policy comprises means for determining to trigger the ProSe authentication procedure based on the authentication policy regardless of a change in the RSC, and means for generating the root key independent of the RSC.

[0190] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 500. In some embodiments, the means comprises at least one processor and at least one memory containing computer program code, the at least one memory and the computer program code, together with the at least one processor, configured to cause the apparatus to execute.

[0191] In some embodiments, a device capable of performing any of the methods 600 (such as the AUSF device 173 in the exemplary embodiment) may comprise means for performing each step of the method 600. The means may be embodied in any suitable form. For example, the means may be implemented in a circuit or a software module.

[0192] In some embodiments, the apparatus includes: means for generating, in an authentication server function (AUSF) device, a root key that is independent of a relay selection code (RSC), the root key being used to generate at least one proximity-based service (ProSe) key for establishing a security link for direct communication between a remote terminal device and a relay terminal device; and means for sending, to a ProSe anchor function (PAnF) device, a ProSe key registration request that does not include the RSC.

[0193] In some embodiments, the device further comprises means for sending, to the PAnF device, a ProSe key acquisition request for triggering a relay service authorization procedure of the remote terminal device based on the RSC. In some embodiments, the device further comprises means for generating at least a ProSe security key based on at least the RSC, where the at least ProSe security key is RSC-specific. In some embodiments, the root key includes a control plane ProSe remote user key (CP-PRUK).

[0194] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 600. In some embodiments, the means comprises at least one processor and at least one memory containing computer program code, the at least one memory and the computer program code, together with the at least one processor, configured to cause the apparatus to execute.

[0195] 9 is a simplified block diagram of an apparatus 900 suitable for practicing embodiments of the present disclosure. The apparatus 900 may be provided to implement a communication apparatus such as, for example, the remote UE 110 and the AUSF device 173. As shown, the apparatus 900 includes one or more processors 910, one or more memories 920 coupled to the processors 910, and one or more communication modules (TX / RX) 940 coupled to the processors 910.

[0196] One or more communication modules 940 are for bidirectional communication. One or more communication modules 940 have at least one antenna to facilitate communication. The communication interface may represent any interface necessary for communication with other network elements.

[0197] The processor 910 may be of any type suitable for a local technology network and may include, by way of non-limiting example, one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. The device 900 may have multiple processors, such as application-specific integrated circuit chips that are time-slaved to a clock that synchronizes the main processor.

[0198] The memory 920 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memory include, but are not limited to, read-only memory (ROM) 924, electronically programmable read-only memory (EPROM), flash memory, hard disks, compact disks (CDs), digital video disks (DVDs), and other magnetic and / or optical storage devices. Examples of volatile memory include, but are not limited to, random access memory (RAM) 922 and other volatile memories that do not persist across power-down durations.

[0199] The computer program 930 includes computer-executable instructions that are executed by the associated processor 910. The program 930 may be stored in ROM 920. The processor 910 can load the program 930 into RAM 920 to perform any suitable operations and processes.

[0200] 2 to 8, the embodiment of the present disclosure may be implemented by a program 930 such that the device 900 can execute any process of the present disclosure. The embodiment of the present disclosure may also be implemented by hardware or a combination of software and hardware.

[0201] In some embodiments, the program 930 may be accessible to a computer-readable medium included in the device 900 (such as in memory 920) or other storage accessible by the device 900. The device 900 may load the program 930 from the computer-readable medium into RAM 922 for execution. The computer-readable medium may include any type of tangible non-volatile storage device, such as a ROM, an EPROM, a flash memory, a hard disk, a CD, a DVD, etc. FIG. 10 shows an example of a computer-readable medium 1000 in the form of a CD or DVD. This computer-readable medium has the program 930 stored thereon.

[0202] In general, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device. While various aspects of embodiments of the present disclosure have been illustrated and described using block diagrams, flowcharts, or some other pictorial representations, it should be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing device, or some combination thereof, in non-limiting illustrative examples.

[0203] The present disclosure also provides at least one computer program product tangibly stored on a transient or non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, that execute on a target real or virtual processor device to perform methods 200, 500, and 500, as described above with reference to FIGS. 2, 5, and 6. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split among program modules as desired in various embodiments. The machine-executable instructions of the program modules may be executed in local or distributed devices. In a distributed device, the program modules may be located in both local and remote storage media.

[0204] Program code for carrying out the methods of the present disclosure can be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, and when executed by the processor or controller, the program code performs the functions / acts specified in the flowcharts and / or block diagrams. The program code may run entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0205] In the context of the present disclosure, instructions or associated data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations as described above. Examples of carriers include signals, computer-readable media, etc.

[0206] The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. Computer-readable media include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, devices, or any suitable combination thereof. More specific examples of computer-readable storage media include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The term "non-transitory" as used herein refers to the medium itself (i.e., tangible, not a signal), as opposed to the data storage permanence (e.g., RAM vs. ROM).

[0207] Furthermore, although operations are depicted in a particular order, this should not be understood as requiring such operations to be performed in the particular order shown, or sequentially, or to perform all of the operations shown, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be preferable. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the disclosure, but rather as descriptions of features that may be unique to particular embodiments. Certain features that are described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable subcombination.

[0208] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the present disclosure, as defined by the appended claims, is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A remote terminal device, at least one processor; When executed by the at least one processor, the remote terminal device is provided with at least: obtaining a selection policy for selecting a relay selection code (RSC) from a plurality of RSCs, each RSC being associated with an indicator indicating whether the RSC supports a control plane (CP) security procedure or a user plane (UP) security procedure; selecting a target RSC based on the selection policy, a source indicator associated with the source RSC, and a plurality of indicators associated with the plurality of RSCs based on determining that a path switch from a source relay terminal device having a source RSC has been triggered; selecting a target relay terminal device based on the target RSC for the path switching; at least one memory storing instructions for executing the A remote terminal device comprising:

2. The remote terminal device selecting the target relay terminal device having the target RSC same as the source RSC; and selecting a target relay terminal device based on the target RSC by 2. The remote terminal of claim 1.

3. The remote terminal device further comprises: determining the plurality of RSCs; obtaining the plurality of indicators; determining whether the source RSC and the plurality of RSCs support the CP security procedure or the UP security procedure based on the source RSC and the plurality of indicators; To execute 3. A remote terminal device according to claim 1 or 2.

4. The remote terminal device the remote terminal selecting one of the plurality of RSCs having a valid root key as the target RSC; to select the target RSC based on the selection policy. A remote terminal device according to any one of claims 1 to 3.

5. The remote terminal device further comprises: selecting, as the target RSC, one of the plurality of RSCs for which the remote terminal device has the valid root key and which supports the CP security procedure based on determining that the source RSC supports the CP security procedure; to select the target RSC based on the selection policy.

5. The remote terminal of claim 4.

6. The remote terminal device further comprises: selecting, as the target RSC, one of the plurality of RSCs for which the remote terminal device has the valid root key and which supports the UP security procedure based on determining that the source RSC supports the UP security procedure; to select the target RSC based on the selection policy.

5. The remote terminal of claim 4.

7. The remote terminal device further comprises: generating a direct communication request (DCR) including an identity (ID) of the valid root key, the valid root key being used to generate at least one security key for establishing a security link for direct communication between the remote terminal device and the target relay terminal device; 7. A remote terminal according to any preceding claim, adapted to execute:

8. The remote terminal device further comprises: selecting, as the target RSC, one of the at least one candidate RSCs that supports the CP security procedure based on determining that the source RSC supports the CP security procedure; selecting, as the target RSC, one of the plurality of RSCs that supports the UP security procedure based on determining that the source RSC supports the UP security procedure; or randomly selecting one of the plurality of RSCs as the target RSC; and adapted to perform at least one of:

4. The remote terminal of claim 3.

9. The remote terminal device further comprises: generating a DCR containing an encrypted subscriber identity (SUCI) used to trigger a Proximity Services (ProSe) authentication procedure of the remote terminal; 9. The remote terminal of claim 8.

10. The selection policy is: a selection order based on the CP security procedures or the UP security procedures supported by the source RSC and the target RSC; or an authentication policy used by the remote terminal device to determine whether to trigger a ProSe authentication procedure; at least one of: A remote terminal according to any one of claims 1 to 9.

11. 11. The remote terminal of claim 1, wherein the selection policy is preset by a Home Public Land Mobile Network (HPLMN) of the remote terminal or based on the implementation of the remote terminal.

12. A remote terminal device, at least one processor; When executed by the at least one processor, the remote terminal device is provided with at least: obtaining an authentication policy used by the remote terminal device to determine whether to trigger a Proximity Services (ProSe) authentication procedure; determining to trigger the ProSe authentication procedure based at least on the authentication policy; and at least one memory storing instructions for executing the a remote terminal device,

13. The remote terminal of claim 12 , wherein the authentication policy is based on mobility of the remote terminal.

14. The remote terminal device determining to trigger the ProSe authentication procedure based on the remote terminal moving to a new serving public land mobile network (PLMN); determining to trigger the ProSe authentication procedure by A remote terminal according to claim 12 or 13.

15. The remote terminal device determining to trigger the ProSe authentication procedure based on the remote terminal device selecting a relay terminal device of the new serving PLMN; determining to trigger the ProSe authentication procedure by A remote terminal according to any one of claims 12 to 14.

16. The remote terminal device further comprises: determining to trigger the ProSe authentication procedure based on a root key being invalid, the root key being used to generate at least one security key for establishing a security link for the direct communication between the remote terminal device and the relay terminal device; determining to trigger the ProSe authentication procedure by A remote terminal according to any one of claims 12 to 15.

17. The ProSe authentication procedure includes a control plane (CP) security procedure, and the remote terminal device performs at least: determining to trigger the ProSe authentication procedure based on the authentication policy, regardless of a change in RSC, generation of the root key independent of the RSC; 17. The remote terminal device according to claim 12, wherein the remote terminal device is adapted to trigger the ProSe authentication procedure based on the authentication policy by

18. An authentication server function (AUSF) device, comprising: at least one processor; When executed by the at least one processor, the AUSF device performs at least: generating a root key independent of a Relay Selection Code (RSC), the root key being used to generate at least one Proximity Service (ProSe) key for establishing a security link for direct communication between a remote terminal device and a relay terminal device; sending a ProSe Key Registration Request to a ProSe Anchor Function (PAnF) device without using the RSC; at least one memory storing instructions for executing the An AUSF device comprising:

19. The AUSF device further comprises: sending, to the PAnF device, a ProSe key acquisition request for triggering a relay service authorization procedure of the remote terminal device based on the RSC; The AUSF device of claim 18,

20. The AUSF device further comprises: generating the at least ProSe security key based on at least the RSC, wherein the at least ProSe security key is RSC specific; will be executed, 20. The AUSF device of claim 18 or 19.

21. The AUSF device according to any one of claims 18 to 20, wherein the root key comprises a Control Plane ProSe Remote User Key (CP-PRUK).

22. obtaining, at a remote terminal device, a selection policy for selecting a relay selection code (RSC) from a plurality of RSCs, each RSC being associated with an indicator indicating whether the RSC supports control plane (CP) security procedures or user plane (UP) security procedures; selecting a target RSC based on the selection policy, a source indicator associated with the source RSC, and a plurality of indicators associated with the plurality of RSCs based on determining that a path switch from a source relay terminal device having a source RSC has been triggered; selecting a target relay terminal device based on the target RSC for the path switching; A method comprising:

23. obtaining, at a remote terminal device, an authentication policy used by the remote terminal device to determine whether to trigger a Proximity Services (ProSe) authentication procedure; determining to trigger the ProSe authentication procedure based at least on the authentication policy; and A method comprising:

24. generating, in an Authentication Server Function (AUSF) device, a root key independent of a Relay Selection Code (RSC), the root key being used to generate at least one Proximity-Based Services (ProSe) key for establishing a security link for direct communication between a remote terminal device and a relay terminal device; sending a ProSe Key Registration Request to a ProSe Anchor Function (PAnF) device without using the RSC; A method comprising:

25. means for obtaining a selection policy for selecting a relay selection code (RSC) from a plurality of RSCs, each RSC being associated with an indicator indicating whether the RSC supports a control plane (CP) security procedure or a user plane (UP) security procedure; means for selecting a target RSC based on determining that a path switch from a source relay terminal device having a source RSC is triggered, based on the selection policy, a source indicator associated with the source RSC, and a plurality of indicators associated with the plurality of RSCs; means for selecting a target relay terminal device for the path switching based on the target RSC; An apparatus comprising:

26. means for obtaining an authentication policy used by the remote terminal device to decide whether to trigger a Proximity Services (ProSe) authentication procedure; means for determining to trigger the ProSe authentication procedure based at least on the authentication policy; and An apparatus comprising:

27. means for generating a root key independent of a Relay Selection Code (RSC), the root key being used to generate at least one Proximity-Based Services (ProSe) key for establishing a security link for direct communication between a remote terminal device and a relay terminal device; and means for sending a ProSe Key Registration Request to a ProSe Anchor Function (PAnF) device without using the RSC; An apparatus comprising:

28. A computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least one of the methods of claims 22 to 24.

Citation Information

Patent Citations

  • COMMUNICATION METHOD, APPARATUS, AND SYSTEM

    JP2025533162A

  • Relay sidelink communications for secure link establishment

    US20210345104A1

  • Method and apparatus for supporting UE-to-network relay communication in a wireless communication system

    US20220095398A1

  • Communication control method, user equipment, server device, and communication system

    WO2015170690A1