Obtaining security information for relay discovery

The network and terminal devices facilitate secure relay discovery by exchanging relay service codes and security information, addressing the challenge of relay discovery across different HPLMNs in 5G ProSe systems, thereby enhancing the reliability of direct communication.

JP2025542094APending Publication Date: 2025-12-25NOKIA TECHNOLOGIES OY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025527099
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-11-13
Publication Date
2025-12-25

AI Technical Summary

Technical Problem

Existing 5G ProSe systems face challenges in efficiently obtaining security information for relay discovery, which is crucial for direct communication between remote UEs and UE-to-network relays, particularly in scenarios involving different home public land mobile networks (HPLMNs).

Method used

A network device and terminal device are provided with processors and memory to facilitate the exchange of security information by sending and receiving requests for relay service codes (RSC), obtaining identities and security information for target relay terminal device groups, and performing relay discovery based on these sets of information.

Benefits of technology

Enables secure and efficient relay discovery by ensuring that terminal devices can communicate securely with UE-to-network relays across different HPLMNs, enhancing the reliability and integrity of 5G ProSe direct communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025542094000001_ABST
    Figure 2025542094000001_ABST
Patent Text Reader

Abstract

An exemplary embodiment of the present disclosure relates to obtaining security information for relay discovery. A first network device receives a first request for security information for relay discovery from a terminal device served by the first network device. The first request includes at least a relay service code (RSC). The first network device obtains at least one identity based on the first request. Each of the at least one identity is for one of at least one target relay terminal device group that supports the RSC. The first network device obtains at least one set of security information based on the at least one identity and the RSC. Each of the at least one set of security information is associated with one of the at least one target relay terminal device group. The first network device transmits the at least one set of security information to the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Various exemplary embodiments of the present disclosure relate generally to the field of telecommunications, and more particularly to devices, methods, apparatus, and computer-readable storage media for obtaining security information for relay discovery. [Background technology]

[0002] Fifth-generation (5G) systems support proximity-based service (ProSe) functions. 5G ProSe functions may include 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-to-UE (U2N) relay. In the 5G ProSe UE-to-network relay function, a remote user equipment (UE) can connect to a UE-to-network relay via a PC5 interface in 5G ProSe direct communication and communicate with a data network via the UE-to-network relay and the 5G network. To perform 5G ProSe direct communication between a remote UE and a U2N relay, the remote UE and the U2N relay can perform a 5G ProSe direct discovery procedure using security information for relay discovery. Summary of the Invention

[0003] Generally, the exemplary embodiments of the present disclosure provide a solution for obtaining security information for relay discovery.

[0004] In a first aspect, a first network device in a first home public land mobile network (HPLMN) is provided, the first network device comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the first network device to perform the following steps: receive, from a terminal device served by the first network device, a first request for security information for relay discovery, the first request including at least a Relay Service Code (RSC); obtain, based on the first request, at least one identity, each of the at least one identity being for one of at least one target relay terminal device groups that supports the RSC; obtain, based on the at least one identity and the RSC, at least one set of security information, each of the at least one set of security information being associated with one of the at least one target relay terminal device groups; and transmit the at least one set of security information to the terminal device.

[0005] In a second aspect, a terminal device is provided, the terminal device comprising at least one processor and at least one memory that stores instructions that, when executed by the at least one processor, cause the terminal device to at least: send a request for security information for relay discovery to a network device in a home public land mobile network (HPLMN), the request including at least a relay service code (RSC); receive at least one set of security information from the network device, each set of security information being associated with one of at least one target relay terminal device group that supports the RSC; and perform relay discovery based on the at least one set of security information.

[0006] In a third aspect, a first policy control function (PCF) device in a first home public land mobile network (HPLMN) is provided. The first PCF device comprises at least one processor and at least one memory that stores instructions. When executed by the at least one processor, the instructions cause the first PCF device to at least receive, from a first network device in the first HPLMN, a second request for at least one identity, where each of the at least one identity is for one of at least one target relay terminal device group that supports a relay service code (RSC), the second request including at least the RSC; obtain the at least one identity based on the second request; and send, to the first network device, a second response to the second request, where the second response includes at least the at least one identity.

[0007] In a fourth aspect, a second network device in a second home public land mobile network (HPLMN) is provided, the second network device comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the second network device to at least: receive, from a first network device in a first HPLM, a third request for at least one second set of security information for a relay service code (RSC), the request including at least the RSC, and the second HPLMN being different from the first HPLMN; obtain, based on the third request, the at least one second set of security information; and send a third response to the first network device, the third response including at least the at least one second set of security information.

[0008] In a fifth aspect, a second policy control function (PCF) device in a second home public land mobile network (HPLMN) is provided. The second PCF device comprises at least one processor and at least one memory that stores instructions. When executed by the at least one processor, the instructions cause the second PCF device to at least perform the following: receive a request for at least one identity, each of the at least one identity being for a target relay terminal device that supports a relay service code (RSC), the request including at least the RSC; obtain the at least one identity based on the request; and send a response to the request, the response including the at least one identity.

[0009] In a sixth aspect, an apparatus is provided, comprising: means for receiving, at a first network device in a first home public land mobile network (HPLMN), from a terminal device served by the first network device, a first request for security information for relay discovery, the first request including at least a Relay Service Code (RSC), means for acquiring at least one identity based on the first request, where each of the at least one identity is for one of at least one target relay terminal device groups that supports the RSC, means for acquiring at least one set of security information based on the at least one identity and the RSC, where each of the at least one set of security information is associated with one of the at least one target relay terminal device groups, and means for transmitting the at least one set of security information to the terminal device.

[0010] In a seventh aspect, an apparatus is provided, comprising: means for transmitting a request for security information for relay discovery from a terminal device to a network device in a home public land mobile network (HPLMN), the request including at least a relay service code (RSC), means for receiving at least one set of security information from the network device, each of the at least one set of security information being associated with one of at least one target relay terminal device group that supports the RSC, and means for performing relay discovery based on the at least one set of security information.

[0011] In an eighth aspect, an apparatus is provided, comprising: means, in a first policy control function (PCF) device in a first home public land mobile network (HPLMN), for receiving a second request for at least one identity from a first network device in the first HPLMN, where each of the at least one identity is for one of at least one target relay terminal device group supporting a relay service code (RSC), the second request including at least the RSC; means for obtaining the at least one identity based on the second request; and means for sending a second response to the second request to the first network device, where the second response includes at least the at least one identity.

[0012] In a ninth aspect, an apparatus is provided, comprising: means for receiving, at a second network device in a second Home Public Land Mobile Network (HPLMN), from a first network device in a first HPLMN, a third request for a second set of at least one security information for a relay service code (RSC), the request including at least the RSC, the second HPLMN being different from the first HPLMN; means for obtaining the at least one second set of security information based on the third request; and means for sending a third response to the first network device, the third response including at least the at least one second set of security information.

[0013] In a tenth aspect, an apparatus is provided, comprising: means, at a second PCF device in a second home public land mobile network (HPLMN), for receiving a request for at least one identity, each of the at least one identity being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; means for obtaining the at least one identity based on the request; and means for transmitting a response to the request, the response including the at least one identity.

[0014] In an eleventh aspect, a method is provided, the method including: receiving, at a first network device in a first home public land mobile network (HPLMN), from a terminal device served by the first network device, a first request for security information for relay discovery, the first request including at least a relay service code (RSC), obtaining at least one identity based on the first request, each of the at least one identity being for one of at least one target relay terminal device group that supports the RSC, obtaining at least one set of security information based on the at least one identity and the RSC, each of the at least one set of security information being associated with one of the at least one target relay terminal device group, and transmitting the at least one set of security information to the terminal device.

[0015] In a twelfth aspect, a method is provided, the method including: transmitting a request for security information for relay discovery from a terminal device to a network device in a home public land mobile network (HPLMN), the request including at least a relay service code (RSC), receiving at least one set of security information from the network device, each of the at least one set of security information associated with one of at least one target relay terminal device group that supports the RSC, and performing relay discovery based on the at least one set of security information.

[0016] In a thirteenth aspect, a method is provided, the method including: receiving, at a first policy control function (PCF) device in a first home public land mobile network (HPLMN), a second request for at least one identity from a first network device in the first HPLMN, where each of the at least one identity is for one of at least one target relay terminal device group that supports a relay service code (RSC), the second request including at least the RSC, obtaining the at least one identity based on the second request, and sending, to the first network device, a second response to the second request, where the second response includes at least the at least one identity.

[0017] In a fourteenth aspect, a method is provided, the method including: receiving, at a second network device in a second home public land mobile network (HPLMN), from a first network device in the first HPLMN, a third request for at least one second set of security information for a relay service code (RSC), the request including at least the RSC, the second HPLMN being different from the first HPLMN; obtaining the at least one second set of security information based on the third request; and transmitting a third response to the first network device, the third response including at least the at least one second set of security information.

[0018] In a fifteenth aspect, a method is provided, the method including: receiving, at a second PCF device in a second home public land mobile network (HPLMN), a request for at least one identity, each of the at least one identity being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC, obtaining the at least one identity based on the request, and transmitting a response to the request, the response including the at least one identity.

[0019] In a sixteenth aspect, there is provided a computer readable medium comprising program instructions which, when executed by at least one processor, cause at least an apparatus to perform a method according to any of the eleventh to fifteenth aspects.

[0020] It should be understood that the Abstract is not intended to identify key features or essential features of exemplary embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become readily apparent through the following description. [Brief explanation of the drawings]

[0021] Some exemplary embodiments will now be described with reference to the accompanying drawings. [Figure 1] FIG. 1 illustrates an exemplary communication network in which exemplary embodiments of the present disclosure may be implemented. [Figure 2] Figure 2 is a signaling chart illustrating the security procedures of restricted 5G ProSe direct discovery model A. [Figure 3] FIG. 3 is a signaling chart illustrating a PC5 security establishment procedure for 5G ProSe UE-to-network relay communication over the user plane. [Figure 4] FIG. 4 is a signaling chart illustrating a process for obtaining security information for relay discovery in accordance with some exemplary embodiments of the present disclosure. [Figure 5] FIG. 5 is a signaling chart illustrating a process for obtaining security information for relay discovery in accordance with some other exemplary embodiments of the present disclosure. [Figure 6] FIG. 6 is a signaling chart illustrating a process for obtaining security information for relay discovery in accordance with some other exemplary embodiments of the present disclosure. [Figure 7]FIG. 7 illustrates a signaling chart illustrating an example implementation of a process for obtaining security information for relay discovery in accordance with some example embodiments of the present disclosure. [Figure 8] FIG. 8 is a signaling chart illustrating an example process for obtaining security information for relay discovery in accordance with some other exemplary embodiments of the present disclosure. [Figure 9] FIG. 9 is a signaling chart illustrating an example process for obtaining security information for relay discovery in accordance with some other exemplary embodiments of the present disclosure. [Figure 10] FIG. 10 is a signaling chart illustrating an example process for obtaining security information for relay discovery in accordance with yet another exemplary embodiment of the present disclosure. [Figure 11] FIG. 11 is a signaling chart illustrating an example process for obtaining security information for relay discovery in accordance with yet another exemplary embodiment of the present disclosure. [Figure 12] FIG. 12 illustrates a flowchart of a method implemented in a first network device in some exemplary embodiments of the present disclosure. [Figure 13] FIG. 13 illustrates a flowchart of a method implemented in a terminal device in some exemplary embodiments of the present disclosure. [Figure 14] FIG. 14 illustrates a flowchart of a method implemented in a first policy control function (PCF) device in some example embodiments of the present disclosure. [Figure 15] FIG. 15 illustrates a flowchart of a method implemented in a second network device in some exemplary embodiments of the present disclosure. [Figure 16] FIG. 16 illustrates a flowchart of a method implemented in the second PCF device in some exemplary embodiments of the present disclosure. [Figure 17] FIG. 17 shows a simplified block diagram of an apparatus suitable for implementing exemplary embodiments of the present disclosure. [Figure 18] 18 illustrates a block diagram of an exemplary computer-readable medium in an exemplary embodiment of the present disclosure. Throughout the drawings, identical or similar reference numerals represent identical or similar elements. DETAILED DESCRIPTION OF THE INVENTION

[0022] The principles of the present disclosure will now be described with reference to several exemplary embodiments. It should be understood that these exemplary embodiments are provided for illustrative purposes to help those skilled in the art understand and practice the present disclosure, and are not intended to imply any limitation on the scope of the present disclosure. The disclosure described herein may be implemented in various forms other than those described below.

[0023] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0024] References in this disclosure to "one embodiment," "embodiment," "exemplary embodiment," etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not all embodiments need include the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an exemplary embodiment, it is understood by those skilled in the art to affect such feature, structure, or characteristic in connection with other exemplary embodiments, whether or not explicitly stated.

[0025] Although terms such as "first" and "second" may be used herein to describe various elements, it should be understood that these elements are not limited by these terms. These terms are merely used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of the exemplary embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0026] The terminology in the examples is for the purpose of describing particular exemplary embodiments only and is not intended to limit the exemplary embodiments. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that as used herein, the terms "comprises," "comprising," "has," "having," "includes," and / or "including" specify the presence of stated features, elements, and / or components, etc., but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0027] As used herein, the term "circuit" means (a) hardware-only circuit implementations (e.g., analog and / or digital-only implementations); (b) a combination of hardware circuitry and software, e.g., (where applicable); (i) a combination of analog and / or digital hardware circuitry and software / firmware; (ii) software (including digital signal processors), which cooperate with software and hardware processor(s) with memory(s) to cause a device such as a mobile phone or server to perform various functions; (c) hardware circuit(s) and processor(s), such as microprocessor(s) or portions of microprocessor(s), that require software (e.g., firmware) to operate, but the software may be absent when not necessary for operation; It may refer to one or more or all of the following:

[0028] This definition of circuit applies to all uses of the term in this application, including the claims. As a further example, as used herein, the term circuit also covers simply a hardware circuit or processor (or processors) or part of a hardware circuit or processor and its (or their) accompanying software and / or firmware implementation. The term circuit also covers, for example, a baseband or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device, if applicable to particular claim elements.

[0029] As used herein, the term "communication network" refers to a network conforming to any suitable communication standard, such as a fifth-generation (5G) system, Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), or Narrowband Internet of Things (NB-IoT). Furthermore, communications between terminal devices and network devices in a communication network may be performed according to any suitable generation of communication protocols, including, but not limited to, first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G) New Radio (NR) communication protocols, and / or any other protocols currently known or developed in the future. Exemplary embodiments of the present disclosure may be applied to various communication systems. Given the rapid development of communications, there will, of course, be future communication technologies and systems in which the present disclosure may be embodied. The scope of the present disclosure should not be considered as being limited to only the aforementioned systems.

[0030] As used herein, the term "network equipment" refers to a node in a communication network through which terminal devices access the network and receive services therefrom. Depending on the terminology and technology applied, the network equipment may refer to a base station (BS) or access point (AP), e.g., a Node B (NodeB or NB), evolved Node B (eNodeB or eNB), NR next generation Node B (gNB), remote radio unit (RRU), radio header (RH), remote radio head (RRH), relay, low power node such as femto, pico, etc. The RAN split architecture includes a gNB-CU (centralized unit, hosting RRC, SDAP, PDCP) that controls multiple gNB-DUs (distributed units, hosting RLC, MAC, PHY).

[0031] The term "terminal" refers to any end device capable of wireless communication. By way of example and not limitation, a terminal may also be referred to as communication equipment, user equipment (UE), subscriber station (SS), mobile subscriber station, mobile station (MS), or access terminal (AT). Terminal devices include, but are not limited to, mobile phones, cellular phones, smartphones, voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop mounted devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPEs), Internet of Things (IoT) devices, wearables such as watches, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronics devices, devices operating in commercial and / or industrial wireless networks, etc. In the following description, the terms “terminal device,” “communications equipment,” “terminal,” “user equipment,” and “UE” may be used interchangeably.

[0032] In various exemplary embodiments, the functions described herein may be performed in a fixed network node and / or a radio network node, while in other exemplary embodiments, the functions may be implemented in a user equipment device (such as a mobile phone, tablet computer, laptop computer, desktop computer, mobile IoT device, or fixed IoT device). The user equipment device in these examples may, for example, include corresponding functions as described in connection with a fixed network node and / or a radio network node, as appropriate. The user equipment device may be user equipment and / or a control device, such as a chipset or processor, configured to control the user equipment when installed therein. Examples of such functions include a bootstrap server function and / or a home subscriber server, which may be implemented in the user equipment device by providing the user equipment device with software configured to cause the user equipment device to execute from the perspective of these functions / nodes.

[0033] 1 illustrates an exemplary communication environment 100 in which exemplary embodiments of the present disclosure may be implemented. The environment 100 may include a first home public land mobile network (HPLMN) 110 and a second HPLMN 120.

[0034] The first terminal device 112 can use a subscription to the first HPLMN 110. The first terminal device 112 can communicate with a first network device 114 and a first PCF 116 within the first HPLMN 110.

[0035] In some exemplary embodiments, the first network device 114 may include a 5G Direct Discovery Name Management Function (DDNMF) device or a ProSe Key Management Function (PKMF) device.

[0036] The second terminal device 122 can use the subscription of the second HPLMN 120. The second terminal device 122 can communicate with a second network device 124 and a second PCF 126 of the second HPLMN 120.

[0037] In some exemplary embodiments, the second network device 124 may include a 5G Direct Discovery Name Management Function (DDNMF) device or a ProSe Key Management Function (PKMF) device.

[0038] It should be understood that the number of devices is for ease of understanding only and does not imply any limitation, and communication environment 100 may include any suitable number or type of devices adapted to implement embodiments of the present disclosure.

[0039] Communications in communication environment 100 may be conducted according to any suitable communications protocol(s), including, but not limited to, first-generation (1G), second-generation (2G), third-generation (3G), fourth-generation (4G), fifth-generation (5G), or future sixth-generation (6G) cellular communications protocols, wireless local network communications protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or other protocols now known or developed in the future. Furthermore, communications may utilize suitable wireless communications technologies, including, but not limited to, code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplex (FDD), time division duplex (TDD), multiple-input multiple-output (MIMO), orthogonal frequency division multiple access (OFDM), discrete Fourier transform spread OFDM (DFT-s-OFDM), and / or any other technology now known or developed in the future.

[0040] In some exemplary embodiments, the communication environment 100 may support proximity-based service (ProSe) features such as 5G ProSe, 4G ProSe, etc. Hereinafter, exemplary embodiments of the present disclosure will be described using 5G ProSe as an example. However, the present disclosure may be applicable to 4G ProSe or any future ProSe.

[0041] 5G ProSe capabilities may include 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-to-UE (U2N) relay.

[0042] In a 5G ProSe UE-to-network relay function, a first terminal device 112 can connect to a second terminal device 122 via a PC5 interface in a 5G ProSe direct communication and communicate with a data network via the second terminal device 122 and the 5G network. In this regard, the first terminal device 112 may be referred to as a remote terminal device or remote user equipment (UE), and the second terminal device 122 may be referred to as a UE-to-N (U2N) relay.

[0043] To perform 5G ProSe direct communication between the first terminal device 112 and the second terminal device 122, the first terminal device 112 and the second terminal device 122 can perform a 5G ProSe direct discovery procedure using security information for relay discovery. In this way, it is necessary to obtain security information for relay discovery.

[0044] FIG. 2 is a signaling chart illustrating restricted 5G ProSe direct discovery model A security procedures 200.

[0045] In procedure 200 , steps 211 to 214 involve announcing UE 202 .

[0046] At 211, the notifying UE 202 sends a discovery request message including a restricted ProSe application user ID (RPAUID) to the 5G DDNMF 205 in its HPLMN to obtain a ProSe code for notification and to obtain the associated security material. Additionally, the notifying UE 202 must include PC5 UE security capabilities in the discovery request message, including a list of encryption algorithms that the UE supports.

[0047] In the case of 5G ProSe UE-to-network relay discovery, the 5G ProSe UE-to-network relay acts as the notifying UE 202 and sends a relay discovery key request instead of a discovery request. The relay discovery key request message includes a relay service code (RSC) and the PC5 security capabilities of the 5G ProSe UE-to-network relay.

[0048] At 212, the 5G DDNMF 205 may check notification authorization with the ProSe application server. In the case of 5G ProSe UE-to-network relay discovery, this step is skipped.

[0049] At 213, if the notifying UE 202 is roaming, the 5G DDNMF 205 in the HPLMN and VPLMN 204 of the notifying UE 202 exchange notification authorizations.

[0050] In step 214, the 5G DDNMF 205 in the HPLMN of the notifying UE 202 returns the ProSe restriction code and corresponding Code-Sending Security Parameters, along with the CURRENT_TIME and MAX_OFFSET parameters. The Code-Sending Security Parameters provide the information the notifying UE 202 needs to protect the transmission of the ProSe restriction code and are stored together with the ProSe restriction code. The notifying UE 202 performs the same operation using the CURRENT_TIME and MAX_OFFSET. The 5G DDNMF 205 in the HPLMN of the notifying UE 202 must include the selected PC5 encryption algorithm in a Discovery Response message. In step 211, the 5G DDNMF 205 determines the selected PC5 encryption algorithm based on the ProSe restriction code and the received PC5 UE security capabilities. The UE stores the selected PC5 encryption algorithm together with the ProSe restriction code.

[0051] Additionally, the 5G DDNMF205 in the HPLMN of the notifying UE202 may associate the ProSe restriction code with a PC5 security policy and include the PC5 security policy in the discovery response message.

[0052] For 5G ProSe UE-to-network relay discovery, a relay discovery key response is used instead of a discovery response, and an RSC is used instead of a ProSe restriction code. The response message contains discovery security material.

[0053] It should be noted that the 5G DDNMF can obtain the PC5 security policy in different ways (such as from the PCF, from the ProSe application server, or based on local configuration).

[0054] Steps 215 to 220 relate to the monitoring UE 201 .

[0055] At 215, the monitoring UE 201 sends a discovery request message including the RPAUID and its PC5 UE security capabilities to the 5G DDNMF 203 in its HPLMN to be authorized to monitor one or more restricted ProSe application user IDs.

[0056] For 5G ProSe UE-to-network relay discovery, the 5G ProSe remote UE plays the role of a monitoring UE 201 and sends a relay discovery key request instead of a discovery request. The relay discovery key request message includes the RSC and PC5 security capabilities of the 5G ProSe remote UE.

[0057] At 216, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 sends an authentication request to the ProSe application server. If, based on the authentication configuration, the RPAUID is authorized to discover at least one of the target RPAUIDs included in the application level container, the ProSe application server returns an authentication response.

[0058] In the case of 5G ProSe UE-to-network relay discovery, this step is skipped.

[0059] At 217, if the discovery request is granted and the PLMN ID in the target RPAUID indicates a different PLMN, the 5G DDNMF203 in the HPLMN of the monitoring UE201 contacts the 5G DDNMF of the indicated PLMN (i.e., the 5G DDNMF in the HPLMN of the notifying UE202) by sending a discovery key request message including the PC5 UE security capabilities received in step 215.

[0060] For 5G ProSe UE-to-network relay discovery, a relay discovery key request and RSC are used instead of a discovery request and RPAUID.

[0061] At 218, the 5G DDNMF 205 in the HPLMN of the notifying UE 202 may exchange authorization messages with the ProSe application server 206.

[0062] In the case of 5G ProSe UE-to-network relay discovery, this step is skipped.

[0063] In 219, if the PC5 UE security capabilities of step 5 include the selected PC5 encryption algorithm, the 5G DDNMF 205 in the HPLMN of the notifying UE 202 responds to the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 with a discovery key response message including the ProSe restriction code, the corresponding code-receiving security parameters, an optional discovery user integrity key (DUIK), and the selected PC5 encryption algorithm (based on the information / key stored in step 214). The code-receiving security parameters provide the information necessary for the monitoring UE 201 to remove the protection applied by the notifying UE 202. The DUIK must be included as another parameter if the code-receiving security parameters indicate that the monitoring UE 201 will use the matching report for MIC checking. The 5G DDNMF 203 in the HPLMN of the monitoring UE 201 stores the ProSe restriction code and the discovery user integrity key (if received outside the Code-Receiving Security Parameters).

[0064] In 5G ProSe UE-network relay discovery, a relay discovery key response is used instead of a discovery response, and an RSC is used instead of a ProSe restriction code. The response message contains discovery security material.

[0065] The 5G DDNMF205 in the HPLMN of the notifying UE202 may send the PC5 security policy associated with the ProSe restriction code to the 5G DDNMF203 in the HPLMN of the monitoring UE201.

[0066] It should be noted that there are two possible configurations for the integrity check: MIC checked by the 5G DDNMF 203 of the monitoring UE 201, or MIC checked at the monitoring UE 201 side. Which configuration to use is decided by the 5G DDNMF, which allocates the ProSe restriction codes to be monitored and signals them to the monitoring UE 201 in the Code-Receiving Security Parameters.

[0067] Note that the selected PC5 encryption algorithm is associated with the ProSe restricted code.

[0068] At 220, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 returns the discovery filter and code reception security parameters along with the CURRENT_TIME and MAX_OFFSET parameters and the selected PC5 encryption algorithm. The monitoring UE 201 performs the same operation with CURRENT_TIME and MAX_OFFSET. The UE stores the discovery filter, code reception security parameters, and the selected PC5 encryption algorithm along with the ProSe restriction code.

[0069] If the 5G DDNMF203 in the HPLMN of the monitoring UE201 receives the PC5 security policy associated with the ProSe restriction code in step 219, the 5G DDNMF of the monitoring UE201 forwards the PC5 security policy to the monitoring UE201.

[0070] Steps 11 and 12 are performed on PC5.

[0071] At 221, the UE initiates an announcement if the system-provided UTC-based counter associated with the discovery slot is within the MAX_OFFSET of the announcing UE's 202 ProSe clock and the validity timer has not expired. The UE forms a discovery message and protects it. The four least significant bits of the UTC-based counter are transmitted with the protected discovery message.

[0072] In 222, the monitoring UE 201 listens for discovery messages that satisfy its discovery filter if the UTC-based counter associated with that discovery slot is within the MAX_OFFSET of the monitoring UE's ProSe clock. It processes the messages to find such a matching message. If the monitoring UE 201 was not required to send a matching report for MIC checking, it stops at this step for security reasons. Otherwise, it proceeds to step 223.

[0073] Note that even if the UE checks the integrity of discovery messages on its own, the requirements of TS 23.304 do not prevent the UE from sending a matching report. If such a matching report is sent, security functions are not relevant.

[0074] Steps 13 to 16 relate to the matched monitored UE 201 .

[0075] In 223, if the UE has not previously had the 5G DDNMF check the MIC of the discovered ProSe restricted code, or if the 5G DDNMF has checked the MIC of the ProSe restricted code and the associated matching report refresh timer (see step 225 for details of this timer) has expired, or if requested according to the procedures specified in TS 23.304, the monitoring UE 201 sends a matching report message to the 5G DDNMF 203 in the HPLMN of the monitoring UE 201. The matching report includes the UTC-based counter value with the four least significant bits closest to the UTC-based counter of the monitoring UE 201 that was received with the discovery message and associated with the notified discovery slot, as well as other discovery message parameters, including the ProSe restricted code and the MIC. The 5G DDNMF checks the MIC.

[0076] At 224, the 5G DDNMF203 in the HPLMN of the monitoring UE201 can exchange an authentication request (Auth Req) / authentication response (Auth Resp) with the ProSe application server 206 to confirm that the monitoring UE201 is authorized to discover the notifying UE202.

[0077] In the case of 5G ProSe UE-to-network relay discovery, this step is skipped.

[0078] At 225, the 5G DDNMF 203 in the HPLMN of the monitoring UE 201 returns confirmation to the monitoring UE 201 that the consistency check has passed, and also provides a CURRENT_TIME parameter for the UE to (re)set its ProSe clock. The 5G DDNMF 203 in the HPLMN of the monitoring UE 201 included a matching report refresh timer in the message to the monitoring UE 201. The matching report refresh timer indicates how long the UE should wait before sending a new matching report for the ProSe restriction code.

[0079] At 226, the 5G DDNMF203 in the HPLMN of the monitoring UE201 may send a matching report information message to the 5G DDNMF205 in the HPLMN of the notifying UE202.

[0080] FIG. 3 is a signaling chart illustrating a PC5 security establishment procedure 300 for 5G ProSe UE-to-network relay communication over the user plane.

[0081] When the 5G ProSe remote UE 301 is in coverage, it is provisioned with discovery security material and a ProSe remote user key (UP-PRUK). These security materials have an expiration date and become invalid after the expiration date. If the UE does not have valid discovery security material, the 5G ProSe remote UE must connect to the 5G PKMF and obtain new material to use the 5G ProSe UE-to-network relay service.

[0082] Note that this procedure is described for a scenario where the 5G PKMF of the 5G ProSe remote UE is different from the 5G PKMF of the 5G ProSe UE-to-network relay. If both the 5G ProSe remote UE and the 5G ProSe UE-to-network relay are served by a single 5G PKMF, the 5G PKMF plays the role of the 5G PKMF of the 5G ProSe remote UE and the 5G PKMF of the 5G ProSe UE-to-network relay, and no message exchange between the 5G PKMFs is required.

[0083] Steps 310a, 310b, 311a, 311b are performed when the 5G ProSe remote UE 301 is in coverage.

[0084] In 310a, the 5G ProSe remote UE 301 obtains a 5G PKMF address from the 5G DDNMF 303 of its HPLMN. Alternatively, the 5G ProSe remote UE 301 may be provisioned with a 5G PKMF address by the PCF. If the 5G ProSe remote UE 301 is provisioned with a 5G PKMF address, the 5G ProSe remote UE 301 can directly access the 5G PKMF without requesting from the 5G DDNMF. If the 5G ProSe remote UE 310 cannot access the 5G PKMF using the provisioned 5G PKMF address, the 5G ProSe remote UE 301 can request a 5G PMKF address from the 5G DDNMF.

[0085] In 310b, the 5G ProSe remote UE 301 establishes a secure connection with the 5G PKMF 304 via the PC8 reference point. The security of the PC8 interface depends on Ua security if the GBA specified in TS 33.220 is used (see Section 5.2.3.4), or on Ua* security if the AKMA specified in TS 33.535 is used (see Section 5.2.5.4). The 5G PKMF 304 in the 5G ProSe remote UE 301 checks whether the 5G ProSe remote UE 301 is authorized to receive UE-to-UE relay services, and if the UE is authorized, the 5G PKMF 304 in the 5G ProSe remote UE 301 provides discovery security material to the 5G ProSe remote UE 301. If the 5G ProSe remote UE301 provides a list of visited networks, the 5G PKMF304 of the 5G ProSe remote UE301 requests discovery security material from the 5G PKMF of a potential 5G ProSe UE-to-network relay from which the 5G ProSe remote UE301 obtains relay service. The 5G PKMF of the 5G ProSe UE-to-network relay can include a PC5 security policy in the 5G ProSe remote UE301.

[0086] Note that the 5G PKMF may locally configure the authorization information of the UE, otherwise the 5G PKMF interacts with the UDM of the UE to obtain the authentication information of the UE.

[0087] It should be noted that the 5G ProSe remote UE 301 is provisioned by the PCF with a list of networks (identified by the RSC) that may be visited for the 5G ProSe UE-to-network relay service.

[0088] At 310c, the 5G ProSe UE-to-network relay 302 obtains a 5G PKMF address from the HPLMN in the same manner as described in step 310a.

[0089] In 310d, the 5G ProSe UE-to-network relay 302 establishes a secure connection with the 5G PKMF over the PC8 reference point, similar to step 310b. The 5G PKMF 306 of the 5G ProSe UE-to-network relay 302 checks whether the 5G ProSe UE-to-network relay 302 is authorized to provide 5G ProSe UE-to-network relay services, and if the UE is authorized, the 5G PKMF 306 of the 5G ProSe UE-to-network relay 302 provides discovery security material to the 5G ProSe UE-to-network relay 302. The 5G PKMF 306 of the 5G ProSe UE-to-network relay 302 can include a PC5 security policy in the 5G ProSe UE-to-network relay 302.

[0090] In 311a, the 5G ProSe remote UE 301 sends a PRUK request message to its 5G PKMF. This message indicates that the 5G ProSe remote UE 301 is requesting a UP-PRUK from the 5G PKMF. If the 5G ProSe remote UE 301 already has a UP-PRUK from this 5G PKMF, the message shall also include the UP-PRUK ID of the UP-PRUK.

[0091] The UP-PRUK ID takes the form of either an NAI or a 64-bit string. If the UP-PRUK ID is in NAI format, i.e. username@realm, the realm part must contain the home network identifier (i.e. HPLMN ID). The username part contains a 64-bit string.

[0092] In step 311b, the 5G PKMF 304 checks whether the 5G ProSe remote UE 301 is authorized to receive the UE-to-UE relay service. This is done by using the ID of the 5G ProSe remote UE 301 associated with the key used to securely establish a connection between the 5G ProSe remote UE 301 and the 5G PKMF in step 310b. If the 5G ProSe remote UE 301 is authorized to receive the service, the 5G PKMF sends the UP-PRUK and UP-PRUK ID to the 5G ProSe remote UE 301. If the UP-PRUK and UP-PRUK ID are included, the 5G ProSe remote UE 301 stores them and deletes any previously stored ones for this 5G PKMF.

[0093] In step 312, a discovery procedure is performed between the 5G ProSe remote UE 301 and the 5G ProSe UE-to-network relay 302 using the discovery parameters and discovery security material.

[0094] Steps 313 to 315 establish secure direct communication between the 5G ProSe remote UE 301 and the U2N relay.

[0095] In the following, we will discuss authorization and provisioning of ProSe services.

[0096] Generally, in 5GS, the parameters of 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-to-network relay services are: be provisioned in the ME, Consists of a UICC; be provisioned in the ME and configured on the UICC; be provided or updated by the ProSe Application Server via the PCF and / or PC1 reference points, be provided or updated by the PCF to the UE; may be provided to the UE by

[0097] If the same parameters described in clauses 5.1.2.1, 5.1.3.1 and 5.1.4.1 are provided by different sources, the UE shall parameters provided or updated by the PCF (including parameters determined by the PCF itself and parameters provided to the PCF by the ProSe application server); be provided or updated by the ProSe Application Server via the PC1 reference point, be configured within the UICC, be provisioned in the ME, The following items must be considered in order of priority:

[0098] The parameters provided or updated by the ProSe Application Server via the PC1 reference point may need to be supplemented with configuration data from the other sources mentioned above.

[0099] It should be noted that the ProSe application server can provision the same ProSe parameters to the UE via 5GC or directly via the PC1 reference point, and can revoke (e.g., delete) the ProSe parameters via 5GC to enable provisioning via the PC1 reference point.

[0100] The basic principles of service authorization and provisioning for 5G ProSe direct discovery, 5G ProSe direct communication, and 5G ProSe UE-network relay services are as follows:

[0101] The PCF of the HPLMN can configure a list of PLMNs for which the UE is authorized to use 5G ProSe direct discovery.

[0102] The PCF of the HPLMN may configure a list of PLMNs for which the UE is authorized to use 5G ProSe direct communication. The PCF of the HPLMN can configure a list of PLMNs for which the UE is authorized to act as a 5G ProSe UE-to-network relay. The authorizations for 5G ProSe Layer 2 UE-to-network relay and 5G ProSe Layer 3 UE-to-network relay are independent of each other. The PCF of the HPLMN can configure a list of PLMNs where the UE is authorized to access the 5GC via a 5G ProSe UE-to-network relay (i.e., act as a 5G ProSe remote UE). The authorization for access via a 5G ProSe Layer 2 UE-to-network relay and via a 5G ProSe Layer 3 UE-to-network relay are independent of each other. The PCF in the HPLMN merges the authorization information from the home and other PLMNs and provides the final authorization information to the UE. The PCF of the visited public land mobile network (VPLMN) or HPLMN can revoke authorization at any time (via the H-PCF when roaming) by using the UE Configuration Update procedure for transparent UE policy distribution defined in TS 23.502, clause 4.2.4.3. The provisioning of ProSe policies / parameters to the UE is controlled by the PCF and may be triggered by the UE. The PCF provisions one or more of the following ProSe policies / parameters: ProSe policies / parameters for 5G ProSe direct discovery as specified in Section 5.1.2.1; ProSe policies / parameters for 5G ProSe direct communication as specified in clause 5.1.3.1; ProSe policies / parameters for 5G ProSe Layer 2 and / or Layer 3 UE-to-UE relay as specified in clause 5.1.4.1; 5G ProSe Layer 2 and / or Layer 3 Remote UE ProSe policies / parameters as specified in clause 5.1.4.1; The PCF includes the 5G ProSe policies / parameters in a policy section identified by the Policy Section Identifier (PSI) specified in clause 6.1.2.2.2 of TS 23.503 [9].

[0103] In addition to the above, the rules for ProSe usage reporting configuration and charging can be configured (pre-) in the UE or provided by the PCF.

[0104] In addition to the above, the routing selection policy can be configured (pre-configured) in the UE or provided by the PCF, as defined in clause 5.11. The routing preferences for ProSe services can be provided to the UDR by the ProSe application server and can be used by the PCF to generate and update the routing selection policy.

[0105] If the 5G ProSe Layer 3 remote UE uses a 5G ProSe Layer 3 UE-to-network relay without going through a Non-3GPP access InterWorking Function (N3IWF), PCF-based 5G ProSe policy / parameter provisioning and update for the 5G ProSe Layer 3 remote UE is not supported.

[0106] Based on background information, there are two issues with the restricted security procedures of 5G ProSe direct discovery, especially 5G ProSe UE-to-network relay discovery.

[0107] On the other hand, if the remote UE and the relay candidate belong to different HPLMNs, the DDNMF / PKMF of the remote UE cannot know or discover the location of the DDNMF / PKMF of the relay candidate for reasons explained below.

[0108] According to TS 23.304, clause 4.3.2.2, 5G DDNMF Discovery, the 5G DDNMF of the HPLMN uses the Network Repository Function (NRF) to discover other 5G DDNMFs of other PLMNs. Based on TS 23.501, clause 6.3.1, the NRF of the source PLMN uses the target PLMN ID to reach the NRF of the remote PLMN. However, the 5G DDNMF of the remote UE does not have information about the ID of at least one target or relay candidate HPLMN.

[0109] From the description on "Authorization and Provisioning of ProSe Services," it can be seen that only the remote UE's possible VPLMNs or serving PLMNs are provisioned to the remote UE, and the remote UE can report these PLMNs to its DDNMF in the discovery key request, as shown in 310b of Figure 3. However, these PLMNs may be the remote UE's VPLMNs or serving PLMNs, and may certainly be different from the relay's HPLMN. Therefore, there is an obvious gap in the current specification when the remote UE and relay UE belong to different HPLMNs, especially when the remote UE or relay UE is roaming.

[0110] Specifically, in 217 of FIG. 2, the DDNMF of the remote UE does not know the HPLMN IDs of all relay candidates, and therefore cannot know or discover the location of the DDNMF of at least one relay candidate.

[0111] On the other hand, the security discovery procedure does not work in the U2N relay case if the RSC involved in the discovery is securely supported / authenticated by multiple U2N relay candidates, at least in different HPLMNs.

[0112] Based on the current discovery procedure, specifically 219 and 220 in Figure 2, security parameters and encryption algorithms are associated with the RSC. If there are multiple potential U2N relays that support RSC, the security parameters and encryption algorithms cannot be distinguished unless all relays share the same security parameters and algorithms. Since the security parameters and encryption algorithms are used to protect discovery messages exchanged over the PC5 link, it is not secure or even feasible to share them among all relay candidates, or at least among relays belonging to different HPLMNs.

[0113] The present disclosure provides a method for acquiring security information for relay discovery. According to this method, a first network device in a first HPLMN receives a first request for security information for relay discovery from a terminal device served by the first network device. The first request includes at least a relay service code (RSC). The first network device acquires at least one identity based on the first request. Each of the at least one identity is for one of at least one target relay terminal device group that supports the RSC. In turn, the first network device acquires at least one set of security information based on the at least one identity information. Each of the at least one set of security information is associated with one of the at least one target relay terminal device group. The first network device transmits the at least one set of security information to the terminal device. In this way, the first network device can discover the target DDNMF and distinguish security information for different groups of target relay terminal devices.

[0114] The principles of the present disclosure will be described below with reference to FIGS.

[0115] 4 is a signaling chart illustrating a process 400 for obtaining security information for relay discovery in some example embodiments of the present disclosure. For illustrative purposes, the process 400 will be described with reference to FIG. 1. The process 400 may include the first terminal device 112 and the first network device 114 of FIG. 1. Alternatively, the process 400 may include the second terminal device 122 and the second terminal device 124 of FIG. 1. Hereinafter, the process 400 will be described using the first terminal device 112 and the first network device 114 as an example.

[0116] 4, the first terminal device 112 sends 410 a first request for security information for relay discovery to the first network device 114. The first request includes at least a relay service code (RSC).

[0117] Accordingly, the first network device 114 receives from the first end device 112 a first request for security information for relay discovery.

[0118] The first network device 114 obtains 420 at least one identity based on the first request. Each of the at least one identity is for one of a group of at least one target relay terminal device that supports RSC. Hereinafter, the target relay terminal device is also referred to as one of the target relay UE, target relay, relay candidate terminal device, relay candidate UE, or relay candidate.

[0119] Next, the first network device 114 obtains 430 at least one set of security information based on the at least one identity information, each of the at least one set of security information being associated with one of the at least one target relay terminal device group.

[0120] The first network device 114 transmits (450) at least one set of security information to the first terminal device 112.

[0121] Thus, the first terminal device 112 receives at least one set of security information from the first network device 114 .

[0122] Subsequently, the first terminal device 112 performs relay discovery based on the at least one set of security information (460).

[0123] The process 400 allows the first network device 114 to discover the target DDNMF and distinguish the security information of different groups of target relay terminal devices.

[0124] In some exemplary embodiments, the first network device 114 can obtain a set of security information associated with a relay restriction identity (ID). The relay restriction ID can be generated based on the RSC and the identity of a group of target relay terminal devices. The first network device 114 can transmit the set of security information in association with the relay restriction ID.

[0125] In some demonstrative embodiments, optionally, before transmitting the at least one set of security information, the first network device 114 may build a list of security information for relay discovery 440. Each element in the list may be associated with one of the at least one set of security information.

[0126] In some example embodiments, each element in the list may be associated with a set of security information and a relay restriction ID associated with the set of security information. Table 1 shows an example list. [Table 1]

[0127] In Table 1, each row can represent an element of the list of security information for relay discovery. Each element is associated with a set of security information for a group of target relay terminal devices and a relay restriction ID. For example, security information set #1 is associated with relay restriction ID #1.

[0128] It should be noted that the number of sets of security information and relay restriction IDs associated with the sets of security information are exemplary, and more or fewer sets of security information and relay restriction IDs may be applied to the present disclosure.

[0129] In some example embodiments, each of the at least one set of security information may include at least one of security parameters for relay discovery, or a PC5 encryption algorithm, or a discovery user integrity key (DUIK) for relay discovery.

[0130] In some exemplary embodiments, the first PCF device 116 may be configured with the identity of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second PCF device 126 may be configured with the identity of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC. In such exemplary embodiments, the first network device 114 may obtain the at least one identity from the first PCF device 116 in the first HPLMN 110, as will be described with reference to FIG. 5.

[0131] 5 is a signaling chart illustrating a process 500 for obtaining security information for relay discovery in some exemplary embodiments of the present disclosure. For purposes of illustration, the process 500 will be described with reference to FIG. 1. The process 500 may include the first network device 114 and the first PCF device 116 of FIG. 1.

[0132] 5, the first network device 114 sends (510) a second request for at least one identity to the first PCF device 116. Each of the at least one identity is for one of a group of at least one target relay terminal device that supports RSC. The second request includes at least the RSC.

[0133] Accordingly, the first PCF device 116 receives a second request for at least one identity from the first network device 114 .

[0134] The first PCF device 116 obtains at least one identity based on the second request.

[0135] The first PCF device 116 then sends 530 a second response to the second request to the first network device 114. The second response includes at least one identity.

[0136] Accordingly, the first network device 114 receives a second response that includes at least one identity.

[0137] In some exemplary embodiments, the first network device 114 may be configured with the identity of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second network device 124 may be configured with the identity of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.

[0138] In such an exemplary embodiment, if a first group of target relay terminal devices of the at least one group belongs to the first HPLMN 110, the first network device 114 may locally obtain a first identity for the first group of target relay terminal devices. The first network device 114 may then locally obtain a first set of security information associated with the first group of target relay terminal devices.

[0139] In an exemplary embodiment, if a second group of target relay terminal devices of the at least one group belongs to the second HPLMN 120, the first network device 114 may obtain a second set of security information associated with the second group of target relay terminal devices from the second network device 124. This is described with reference to FIG.

[0140] 6 is a signaling chart illustrating a process 600 for obtaining security information for relay discovery in some example embodiments of the present disclosure. For purposes of explanation, the process 600 will be described with reference to FIG. 1. The process 600 may include the first network device 114 and the SSNND 124 of FIG. 1.

[0141] 6, the first network device 114 sends 610 a third request for a second set of at least one security information for the RSC to the second network device 124. The third request includes at least the RSC.

[0142] Accordingly, the second network device 124 receives a third request from the first network device 114 for a second set of at least one security information for the RSC.

[0143] The second network device 124 obtains 620 at least one second set of security information based on the third request, each of the at least one second set of security information being associated with a second group of target relay terminal devices belonging to the second HPLMN 120.

[0144] The second network device 124 in turn sends a third response 630 to the third request to the first network device 114. The third response includes at least a second set of at least one security information.

[0145] Some implementations of the processes 400, 500 and 600 are described below with reference to FIGS.

[0146] 7 to 11, the first terminal device 112 and the second terminal device 122 are exemplified by a remote UE and a U2N relay, respectively. The first network device 114 and the second network device 124 are exemplified by a DDNMF or a PKMF, respectively. Furthermore, the first HPLMN 110 is configured with PLMN ID#1, and the second HPLMN 120 is configured with PLMN ID#2.

[0147] 7 is a signaling chart illustrating a process 700 for obtaining security information for relay discovery in some example embodiments of the present disclosure. For illustrative purposes, the process 700 will be described with reference to FIG. 1. The process 700 may involve the first terminal device 112 (e.g., the remote UE 112), the second terminal device 122 (e.g., the U2N relay 122), the first network device 114 (e.g., the DDNMF 114), the first PCF device 116, the second network device 124 (e.g., the DDNMF 124), and the second PCF device 126 of FIG. 1.

[0148] In process 700, the first PCF device 116 is configured with the identity of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second PCF device 126 is configured with the identity of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.

[0149] Further, in the process 700, each of the at least one target relay terminal device group includes a single target relay terminal device, and the identity for the group of target relay terminal devices includes a relay identity for discovery.

[0150] 7, at 701, the U2N relay 122 sends a discovery key request to its DDNMF 124 to obtain security information for relay discovery to protect the PC5 discovery message. The request may include the RSC and security capabilities of the U2N relay 122.

[0151] The operation at 701 can be considered an example of the operation at 410 in FIG.

[0152] At 702, the DDNMF 124 of the U2N relay 122 generates a relay restriction ID for the U2N relay 122 with a valid timer. The relay restriction ID is associated with the RSC and the discovery relay identity of the U2N relay 122. Hereinafter, the discovery relay identity is also referred to as the "relay ID" for simplicity. For example, the relay ID may include the HPLMN ID (e.g., PLMN ID#2) of the U2N relay 122. Next, the DDNMF 124 obtains security information associated with the relay restriction ID. For example, the DDNMF 124 may generate security parameters and select a PC5 encryption algorithm.

[0153] The DDNMF 124 then sends a discovery key response to the U2N relay 122. The response includes the RSC, the ProSe restriction code and validity timer, code-specific security parameters and the selected PC5 encryption algorithm, CURRENT_TIME, MAX_OFFSET, and an optional PC5 security policy.

[0154] The operations at 702 can be considered an implementation of the operations at 420, 430, 440 and 450 in FIG.

[0155] At 703, the remote UE 112 sends a discovery key request to its DDNMF 114 to obtain relay discovery security information for protecting the PC5 discovery message. The request may include the UE identity, RSC, and security capabilities of the remote UE 112.

[0156] The operation at 703 can be considered another embodiment of the operation at 410 in FIG.

[0157] At 704, the DDNMF 114 of the remote UE 112 sends a request to its PCF device 116 to obtain the identities of relay candidates that support the RSC of the remote UE 112. The request may include the UE identity and RSC of the remote UE 112.

[0158] The operations at 704 may be considered an example implementation of the operations at 510 in FIG.

[0159] At 705, the PCF device 116 of the remote UE 112 locally obtains the IDs of the HPLMNs of the relay candidates based on the RSC and local configuration.

[0160] At 706a, the PCF device 116 of the remote UE 112 locally obtains the IDs of the relay candidates that belong to the same HPLMN of the remote UE 112 based on the RSC and local configuration.

[0161] At 706b, for those relay candidates that belong to a different HPLMN from the remote UE 112, the PCF device 116 of the remote UE 112 obtains the identities of the relay candidates from the PCF devices of the other PLMNs. For example, for those relay candidates that belong to the second HPLMN 120, the PCF device 116 of the remote UE 112 obtains the identities of the relay candidates from the PCF device 126.

[0162] At 706b.1, the PCF device 116 of the remote UE 112 sends a request to the PCF device 126 of the U2N relay 112 for the identities of relay candidates belonging to the second HPLMN 120. This request is also referred to as a "get relay candidate request." This request may include the PLMN ID#1 of the first HPLMN 110 of the remote UE 112 and the RSC.

[0163] At 706b.2, the PCF device 116 of the remote UE 112 receives a response to the "get relay candidate request." This response is also referred to as a "get relay candidate response." The "get relay candidate response" may include a list of PLMN ID#2, RSC, and relay IDs for the second HPLMN 120.

[0164] The operations at 705, 706a, 706b.1, and 706b.2 may be considered exemplary implementations of the operations at 520 in FIG.

[0165] In some implementations, the operations at 706a, 706b.1, and 706b.2 may be repeated for each HPLMN that is a relay candidate.

[0166] At 707, the PCF device 116 of the remote UE 112 sends a response to the DDNMF 114 of the remote UE 112. This response is also referred to as a "get relay candidate response." This response may include the UE identity of the remote UE 112, the RSC, and a list of relay IDs of the relay candidates.

[0167] The operation at 707 can be considered an example implementation of the operation at 530 in FIG.

[0168] At 708a, if the relay candidate belongs to the same HPLMN of the remote UE 112, the DDNMF 114 generates a relay restriction ID for the relay candidate with a valid timer. The relay restriction ID is associated with the RSC and the relay ID of the relay candidate. The DDNMF 114 then obtains security information associated with the relay restriction ID. For example, the DDNMF 114 can generate security parameters, a DUIK, and select a PC5 encryption algorithm associated with the relay restriction ID.

[0169] At 708b.1, if the relay candidate belongs to a different HPLMN, the DDNMF 114 of the remote UE 112 sends a discovery key request to the DDNMF of the HPLMN of the relay candidate to obtain security information associated with the RSC. For example, the DDNMF 114 of the remote UE 112 sends a discovery key request to the DDNMF 124 of the second HPLMN 120. The DDNMF 114 of the remote UE 112 can discover the DDNMF of the relay candidate based on the PLMN ID of the HPLMN of the relay candidate, which may be part of the relay ID of the relay candidate. The request may include the security capabilities of the remote UE 112, the RSC, and the relay ID of the relay candidate.

[0170] The act at 708b.1 may be considered an example of the act at 610 in FIG.

[0171] At 708b.2, the DDNMF 114 of the remote UE 112 receives a discovery key response from the DDNMF 124 of the U2N relay 122. This response may include a valid timer, security parameters, a DUIK, and a relay restriction ID of the relay candidate with the selected PC5 encryption algorithm associated with the relay restriction ID. The relay restriction ID is associated with the RSC and the relay ID.

[0172] The operations at 708b.2 can be considered an example implementation of the operations at 630 in FIG.

[0173] In some embodiments, the operations at 708a, 708b.1, and 708b.2 may be repeated for the relay candidates.

[0174] At 709, the DDNMF 114 of the remote UE 112 builds a list of relay restriction IDs with corresponding validity timers, code security parameters, DUIKs, and PC5 encryption algorithms.

[0175] The operations at 709 can be considered an example implementation of the operations at 440 in FIG.

[0176] At 710, the DDNMF of the remote UE 112 sends a discovery key response to the remote UE 112. The response can include the RSC, an optional PC5 security policy, CURRENT_TIME, MAX_OFFSET, (Relay Restriction ID, Validity Timer, Code-Rcv-SecParams (i.e., security parameters), and a list of selected PC5 encryption algorithms).

[0177] CURRENT_TIME contains the current UTC-based time in 5G DDNMF. The UE can obtain UTC time from available sources, such as RAN via SIB9, NITZ, NTP, GPS, or the Ub interface (in GBA), depending on the available sources.

[0178] The MAX_OFFSET parameter is used to limit the ability of an attacker to successfully replay a discovery message or to obtain a correctly MIC'd discovery message for later use. This is achieved by using MAX_OFFSET as the maximum difference between a UTC-based counter associated with a discovery slot and the ProSe clock maintained by the UE.

[0179] The operations at 710 can be considered an example implementation of the operations at 450 in FIG.

[0180] At 711, the remote UE 112 and U2N relay 122 perform relay discovery via PC5. The discovery message is protected with at least one set of security information, each of which is associated with a relay restriction ID (one per relay per RSC).

[0181] The operations at 711 can be considered an example of the operations at 460 in FIG.

[0182] Process 700 can be aligned with legacy Evolved Packet System (EPS) / 5G Direct Discovery procedures extended to support discovery key requests for relay discovery. Additionally, process 700 can reduce the signaling load from a remote UE 112 to its HPLMN 110.

[0183] 8 shows a signaling chart illustrating a process 800 for obtaining security information for relay discovery in some example embodiments of the present disclosure. For illustrative purposes, the process 800 will be described with reference to FIG. 1. The process 800 may include the first terminal device 112 (e.g., the remote UE 112), the second terminal device 122 (e.g., the U2N relay 122), the first network device 114 (e.g., the DDNMF 114), the first PCF device 116, the second network device 124 (e.g., the DDNMF 124), and the second PCF device 126 of FIG. 1.

[0184] Process 800 is similar to process 700 in that the first PCF device 116 is configured with the identity of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second PCF device 126 is configured with the identity of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.

[0185] Additionally, process 800 is similar to process 700 in that each of the at least one target relay terminal device groups comprises a single target relay terminal device, and the ID for the group of target relay terminal devices includes a relay ID for discovery.

[0186] Process 800 differs from process 700 in that interactions between PCF devices of different HPLMNs are avoided and messages between the DDNMFs of two HPLMNs may be reduced.

[0187] Specifically, the operations at 801, 802, 803, 805, 808a, 809, 810, and 811 in process 800 are similar to the operations at 701, 702, 703, 705, 708a, 709, 710, and 711 in process 700. Therefore, details of these operations are omitted for the sake of brevity.

[0188] The operations at 804, 806, 807, 808b.1, 808b.2 and 808b.3 in process 800 are different from the operations in process 700.

[0189] At 804, the DDNMF 114 of the remote UE 112 sends a request to its PCF device 116 to obtain the ID of the HPLMN that supports the RSC of the remote UE 112. The request may include the UE identity and RSC of the remote UE 112. This request is also referred to as a "request to obtain HPLMN of relay candidate."

[0190] The operation at 804 can be considered as another example of the operation at 510 in FIG.

[0191] At 805, the PCF device 116 of the remote UE 112 locally obtains the IDs of the HPLMNs of the relay candidates based on the RSC and local configuration.

[0192] The operation at 805 may be considered another example of the operation at 530 in FIG.

[0193] At 806, the PCF device 116 of the remote UE 112 sends a response to the DDNMF 114. This response is also referred to as a "response for obtaining relay candidate HPLMNs." The response may include a UE identity, an RSC, and a list of PLMN IDs of the remote UE 112. For example, the list of PLMN IDs may include at least one of an ID of the first HPLMN 110 (e.g., PLMN ID#1) or an ID of the second HPLMN 120 (e.g., PLMN ID#2).

[0194] The operation at 806 may be considered another example of the operation at 530 in FIG.

[0195] At 807, if the list of PLMN IDs may include the ID of the first HPLMN 110 (such as PLMN ID#1), the DDNMF 114 of the remote UE 112 obtains the IDs of the relay candidates from the PCF device 116 of the remote UE 112 based on the RSC.

[0196] The operations at 807 can be considered as another example of the operations at 510, 520 and 530 in FIG.

[0197] At 808b.1, if the list of PLMN IDs may include the ID of the second HPLMN 120 (e.g., PLMN ID #2), the DDNMF 114 of the remote UE 112 sends a discovery key request to the DDNMF 124 of the HPLMN 120 to obtain security information associated with the RSC. This request may include the security capabilities of the remote UE 112 and the RSC. Note that the request may or may not include the ID of the second HPLMN 120 (e.g., PLMN ID #2). This means that security information associated with each of the relay candidates of the second HPLMN 120 needs to be obtained.

[0198] The operations at 808b.1 can be considered as another example of the operations at 610 in FIG.

[0199] At 808b.2, the DDNMF 124 of the U2N relay 122 obtains the relay IDs of relay candidates in the second HPLMN 120 from the PCF device 126 based on the RSC. The DDNMF 124 then generates a relay restriction ID for each of the relay candidates that have a valid timer. The relay restriction ID is associated with the RSC and the relay ID of the relay candidate. The DDNMF 124 then obtains security information associated with the relay restriction ID. For example, the DDNMF 124 can generate security parameters and select a PC5 encryption algorithm associated with the relay restriction ID. In turn, the DDNMF 124 builds a list of relay restriction IDs with corresponding valid timers, code security parameters, and PC5 encryption algorithms.

[0200] In some example embodiments, each element of the list may be associated with a second set of security information and a relay restriction ID associated with the second set of security information. Table 2 shows an example list. [Table 2]

[0201] In Table 2, each row may represent an element of a list of security information for relay discovery. Each element may be associated with a second set of security information for a target relay terminal device and a relay restriction ID. For example, second set of security information #3 may be associated with a first target relay terminal device and relay restriction ID #3. Relay restriction ID #3 may be generated based on the RSC and the relay ID of the first target relay terminal device.

[0202] It should be noted that the number of sets of security information and the relay restriction IDs associated with the sets of security information are exemplary, and more or fewer sets of security information and relay restriction IDs may be applied to the present disclosure.

[0203] At 808b.3, the DDNMF 114 of the remote UE 112 receives a discovery key response from the DDNMF 124 of the U2N relay 122. The response may include a list of relay restriction IDs with corresponding validity timers, code security parameters, and PC5 encryption algorithms.

[0204] The operation at 808b.3 can be considered another embodiment of the operation at 630 in FIG.

[0205] 9 is a signaling chart illustrating a process 900 for obtaining security information for relay discovery in some example embodiments of the present disclosure. For illustrative purposes, the process 900 will be described with reference to FIG. 1. The process 900 may include the first terminal device 112 (e.g., the remote UE 112), the second terminal device 122 (e.g., the U2N relay 122), the first network device 114 (e.g., the DDNMF 114), the first PCF device 116, and the second network device 124 (e.g., the DDNMF 124) of FIG. 1.

[0206] Process 900 is similar to process 800 in that the first PCF device 116 is configured to have the identity of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second PCF device 126 is configured to have the identity of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.

[0207] Additionally, process 900 differs from process 800 in that each of the at least one target relay terminal device group includes multiple target relay terminal devices in one of the first HPLMN 110 or the second HPLMN 120. The identity of the group of target relay terminal devices includes one of the PLMN identities (IDs) of the first HPLMN 110 or the second HPLMN 120 to which the multiple target relay terminal devices belong, or group IDs of the multiple target relay terminal devices. For example, the group ID may include the PLMN ID of the first HPLMN 110 or the second HPLMN 120.

[0208] Specifically, the operations at 901, 902, 903, 904, 905, 906, 908b.1, 909, 910, and 911 in process 900 are similar to the operations at 801, 802, 803, 804, 805, 806, 808b.1, 809, 810, and 811 in process 800. Therefore, details of these operations are omitted for the sake of brevity.

[0209] The operations at 908a and 908b.2 in process 900 differ from those in process 800.

[0210] At 908a, if the list of PLMN IDs may include the ID of the first HPLMN 110 (e.g., PLMN ID #1), the DDNMF 114 of the remote UE 112 generates relay restriction IDs for all relay candidates that support RSC in the first HPLMN 110. The relay restriction IDs are associated with the RSC and PLMN ID #1. The DDNMF 114 then obtains security information associated with the relay restriction IDs. For example, the DDNMF 114 may generate security parameters and select a PC5 encryption algorithm associated with the relay restriction IDs. Additionally, the DDNMF 114 of the remote UE 112 may generate a valid timer for the relay restriction IDs.

[0211] At 908b.1, if the list of PLMN IDs may include the ID of the second HPLMN 120 (e.g., PLMN ID #2), the DDNMF 114 of the remote UE 112 sends a discovery key request to the DDNMF 124 of the HPLMN 120 to obtain security information associated with the RSC. This request may include the security capabilities of the remote UE 112 and the RSC. Note that the request may or may not include the ID of the second HPLMN 120 (e.g., PLMN ID #2). This means that security information related to all relay candidates of the second HPLMN 120 needs to be obtained.

[0212] The operation at 908b.1 can be considered another example of the operation at 610 in FIG.

[0213] At 908b.2, the DDNMF 114 of the remote UE 112 receives a discovery key response from the DDNMF 124 of the U2N relay 122. This response may include a relay restriction ID with a corresponding validity timer, code security parameters, and PC5 encryption algorithm.

[0214] The act at 908b.2 can be considered another example of the act at 630 in FIG.

[0215] In some implementations, the operations at 908b.1 and 908b.2 may be repeated for each HPLMN that is a relay candidate associated with the RSC.

[0216] 10 is a signaling chart illustrating a process 1000 for obtaining security information for relay discovery in some example embodiments of the present disclosure. For illustrative purposes, the process 1000 will be described with reference to FIG. 1. The process 1000 may include the first terminal device 112 (e.g., the remote UE 112), the second terminal device 122 (e.g., the U2N relay 122), the first network device 114 (e.g., the DDNMF 114), and the second network device 124 (e.g., the DDNMF 124) of FIG. 1.

[0217] Process 1000 is similar to process 800 in that each of the at least one target relay terminal device group comprises a single target relay terminal device, and the ID for the group of target relay terminal devices constitutes the relay ID for discovery.

[0218] Process 1000 differs from process 800 in that the first network device 114 is configured with the identity of at least one target relay terminal device belonging to the first HPLMN 110 and supporting RSC. Similarly, the second network device 124 is configured with the identity of at least one target relay terminal device belonging to the second HPLMN 120 and supporting RSC.

[0219] Specifically, the operations at 1001, 1002, 1003, 1008a, 1008b.1, 1008b.4, 1009, 1010, and 1011 in process 1000 are similar to the operations at 801, 802, 803, 808a, 808b.1, 808b.3, 809, 810, and 811 in process 800. Therefore, details of these operations are omitted for the sake of brevity.

[0220] The operations at 1005, 1006, 1008b.2 and 1008b.3 in process 900 are different from those in process 800.

[0221] At 1005, the DDNMF 114 of the remote UE 112 locally obtains the IDs of the HPLMNs of the relay candidates based on the RSC and local configuration.

[0222] At 1006, the DDNMF 114 of the remote UE 112 locally obtains the IDs of the relay candidates that belong to the same HPLMN of the remote UE 112 based on the RSC and local configuration.

[0223] At 1008b.2, the DDNMF 114 of the remote UE 112 obtains the relay IDs of the relay candidates in the second HPLMN 120 based on the RSC and the local configuration.

[0224] At 1008b.3, the DDNMF 124 generates a relay restriction ID for each relay candidate that has a valid timer. The relay restriction ID is associated with the RSC and the relay ID of the relay candidate. The DDNMF 124 also obtains security information associated with the relay restriction ID. For example, the DDNMF 124 may generate security parameters and select a PC5 encryption algorithm associated with the relay restriction ID. The DDNMF 124 then builds a list of relay restriction IDs with corresponding valid timers, code security parameters, and PC5 encryption algorithms. An example list is provided in Table 2.

[0225] In some demonstrative embodiments, operations 1008b.1 through 1008b.4 may be repeated for each PLMN of a relay candidate associated with the RSC.

[0226] 11 is a signaling chart illustrating a process 1100 for obtaining security information for relay discovery in some example embodiments of the present disclosure. For illustrative purposes, the process 1100 is described with reference to FIG. 1. The process 1100 may include the first terminal device 112 (e.g., the remote UE 112), the second terminal device 122 (e.g., the U2N relay 122), the first network device 114 (e.g., the DDNMF 114), and the second network device 124 (e.g., the DDNMF 124) of FIG. 1.

[0227] Process 1100 is similar to process 900 in that each of the at least one target relay terminal device group includes multiple target relay terminal devices in one of the first HPLMN 110 or the second HPLMN 120. The ID of the group of target relay terminal devices includes one of the PLMN identities (IDs) of the first HPLMN 110 or the second HPLMN 120 to which the multiple target relay terminal devices belong, or group IDs of the multiple target relay terminal devices. For example, the group ID may include the PLMN ID of the first HPLMN 110 or the second HPLMN 120.

[0228] Process 1100 differs from process 900 in that the first network device 114 is configured with the identity of at least one target relay terminal device that belongs to the first HPLMN 110 and supports RSC. Similarly, the second network device 124 is configured with the identity of at least one target relay terminal device that belongs to the second HPLMN 120 and supports RSC.

[0229] Specifically, the operations at 1101, 1102, 1103, 1108a, 1108b.1, 1108b.2, 1109, 1110, and 1111 in process 1100 are similar to the operations at 901, 902, 903, 908a, 908b.1, 908b.2, 909, 910, and 911 in process 900. Therefore, details of these operations are omitted for brevity.

[0230] The actions at 1105 in process 1100 differ from those in process 900.

[0231] At 1105, the DDNMF 114 of the remote UE 112 locally obtains the IDs of the HPLMNs of the relay candidates based on the RSC and local configuration.

[0232] In some demonstrative embodiments, the operations at 1108b.1 and 1108b.2 may be repeated for each PLMN of the relay candidate associated with the RSC.

[0233] 12 illustrates a flowchart of an example method 1200 implemented by a first network device in accordance with some exemplary embodiments of the present disclosure. For purposes of explanation, the method 1200 will be described from the perspective of the first network device 114 with respect to FIG.

[0234] In block 1210, the first network device 114 receives a first request for security information for relay discovery from an end device served by the first network device, the first request including at least a relay service code (RSC).

[0235] In block 1220, the first network device 114 obtains at least one identity based on the first request, each of the at least one identity being for one of the at least one target relay terminal device group that supports RSC.

[0236] In block 1230, the first network device 114 obtains at least one set of security information based on the at least one identity and the RSC, each of the at least one set of security information being associated with one of the at least one target relay terminal device group.

[0237] In block 1240, the first network device 114 transmits at least one set of security information to the end device.

[0238] In some example embodiments, obtaining the at least one identity may include obtaining the at least one identity from a first Policy Control Function (PCF) device in the first HPLMN.

[0239] In some example embodiments, obtaining at least one identity from the first PCF device may include sending a second request for the at least one identity to the first PCF device, the second request including at least the RSC, and receiving a second response to the second request from the first PCF device, the second response including at least the at least one identity.

[0240] In some exemplary embodiments, obtaining the at least one set of security information may include obtaining a set of security information associated with a relay restriction ID, the relay restriction ID being generated based on an ID for one of the RSC and the at least one target relay terminal device group. In some exemplary embodiments, transmitting the at least one set of security information may include transmitting the set of security information associated with the relay restriction ID.

[0241] In some exemplary embodiments, obtaining at least one set of security information may include generating a first relay restriction ID based on the RSC and a first identity for the first group of target relay terminal devices based on determining that a first group of target relay terminal devices of the at least one group belongs to a first HPLMN, and obtaining a first set of security information associated with the first relay restriction ID.

[0242] In some exemplary embodiments, obtaining at least one set of security information may include: sending a third request for a second set of security information for the RSC to a second network device in the second HPLMN based on determining that a second group of the target relay terminal devices among the at least one group belongs to a second HPLMN different from the first HPLMN; and receiving a third response to the third request from the second network device, the third response including the second set of security information and a second relay restriction ID, the second relay restriction ID being associated with a second identity for the RSC and the second group.

[0243] In an exemplary embodiment, the third request includes the second identity.

[0244] In some example embodiments, obtaining at least one identity may include obtaining the at least one identity locally.

[0245] In some exemplary embodiments, each of the at least one target relay terminal equipment group belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.

[0246] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a single target relay terminal device, and each of the at least one identity includes a discovery relay ID.

[0247] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and each of the at least one identity includes one of a PLMN identity of a first HPLMN or a second HPLMN to which the plurality of target relay terminal devices belong, or a group identity of the plurality of target relay terminal devices.

[0248] 13 illustrates a flowchart of an example method 1300 implemented in a terminal device in accordance with some exemplary embodiments of the present disclosure. For illustrative purposes, the method 1300 is described from the perspective of the first terminal device 112 with respect to FIG. 1. Alternatively, the method 1300 may be implemented in the second terminal device 122.

[0249] In block 1310, the first terminal device 112 sends a request for security information for relay discovery to a network device in a Home Public Land Mobile Network (HPLMN), the request including at least a Relay Service Code (RSC).

[0250] In block 1320, the first terminal device 112 receives at least one set of security information from the network device, each of the at least one set of security information being associated with one of the at least one target relay terminal device group that supports RSC.

[0251] In block 1330, the first terminal device 112 performs relay discovery based on the at least one set of security information.

[0252] In some exemplary embodiments, receiving the at least one set of security information may include receiving a set of security information associated with a relay restriction ID, the relay restriction ID being associated with an ID for one of the RSC and the at least one target relay terminal device group.

[0253] In an exemplary embodiment, each of the at least one target relay terminal equipment group belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.

[0254] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a single target relay terminal device, and each of the at least one identity includes a discovery relay ID.

[0255] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and each of the at least one identity includes one of a PLMN identity of a first or second HPLMN to which the plurality of target relay terminal devices belong, or a group identity of the plurality of target relay terminal devices.

[0256] 14 illustrates a flowchart of an example method 1400 implemented in a first PCF device in accordance with some exemplary embodiments of the present disclosure. For purposes of explanation, the method 1400 is described from the perspective of the first PCF device 116 with respect to FIG.

[0257] In block 1410, the first PCF device 116 receives a second request for at least one identity from a first network device in the first HPLMN, each of the at least one identity being for one of at least one target relay terminal device group that supports a relay service code (RSC), and the second request includes at least the RSC.

[0258] In block 1420, the first PCF device 116 obtains at least one identity based on the second request.

[0259] In block 1430, the first PCF device 116 sends a second response to the second request to the first network device, the second response including at least the at least one identity.

[0260] In some exemplary embodiments, each of the at least one target relay terminal equipment group belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.

[0261] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a single target relay terminal device, and each of the at least one identity includes a relay ID for discovery.

[0262] In some exemplary embodiments, obtaining at least one identity may include locally obtaining a first identity of the first HPLMN based on the second request based on determining that the at least one target relay terminal device group belongs to the first HPLMN, and locally obtaining a relay ID for discovery for each of the at least one target relay terminal device group.

[0263] In some exemplary embodiments, obtaining the at least one identity may include, based on determining that the at least one target relay terminal device group belongs to the second HPLMN, sending a fourth request for discovery of at least one relay ID for the at least one target relay terminal device group to a second PCF device in the second HPLMN, and receiving a fourth response to the fourth request from the second PCF device, the fourth response including the at least one relay ID.

[0264] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and the at least one identity includes one of a PLMN ID of a first or second HPLMN to which the plurality of target relay terminal devices belong, or a group ID of the plurality of target relay terminal devices.

[0265] In some exemplary embodiments, obtaining at least one identity may include obtaining a PLMN identity or a group identity based on the second request.

[0266] 15 shows a flowchart of an example method 1500 implemented in a second network device in some example embodiments of the present disclosure. For purposes of explanation, the method 1500 is described from the perspective of the second network device 124 with respect to FIG.

[0267] At block 1510, the second network device 124 receives a third request for a second set of at least one security information for a relay service code (RSC) from the first network device in the first HPLM, the request including at least the RSC, and the second HPLMN being different from the first HPLMN.

[0268] At block 1520, the second network device 124 obtains a second set of at least one security information based on the third request.

[0269] At block 1530, the second network device 124 sends a third response to the first network device, the third response including at least a second set of at least one security information.

[0270] In some exemplary embodiments, each of the at least one second set of security information is associated with a second group of target relay terminal devices belonging to a second HPLMN.

[0271] In some exemplary embodiments, the second group of target relay terminal devices comprises a single target relay terminal device, and the second identity of the second group includes a relay ID for discovery.

[0272] In some exemplary embodiments, the second group of target relay terminal devices comprises a plurality of target relay terminal devices, and the second identity for the second group includes one of a PLMN identity for a second HPLMN to which the plurality of target relay terminal devices belong, or a group identity for the plurality of target relay terminal devices.

[0273] In some exemplary embodiments, obtaining the second set of at least one security information may include generating a second relay restriction ID based on the second identity for the RSC and the second group, and obtaining one of the second set of at least one security information associated with the second relay restriction ID.

[0274] In some demonstrative embodiments, transmitting the second set of at least one security information may include transmitting one of the second set of at least one security information associated with the second relay restriction identity.

[0275] In an exemplary embodiment, the third request includes second identities for a second group of target relay terminal devices.

[0276] 16 illustrates a flowchart of an example method 1600 implemented in a second PCF device in accordance with some exemplary embodiments of the present disclosure. For purposes of explanation, the method 1600 is described from the perspective of the second PCF device 126 with respect to FIG.

[0277] In block 1610, the second PCF device 126 receives a request for at least one identity, each of the at least one identity being for a target relay terminal device that supports a relay service code (RSC), and the request includes at least the RSC.

[0278] In block 1620, the second PCF device 126 obtains at least one identity based on the request.

[0279] In block 1630, the second PCF device 126 sends a response to the request, the response including at least one identity.

[0280] In some exemplary embodiments, receiving the request for the at least one identity includes receiving the request from one of a first network device in a first HPLMN different from the second HPLMN, or a second network device in the second HPLMN.

[0281] In some exemplary embodiments, an apparatus capable of performing any of the methods 1200 (e.g., the first network device 114) may comprise means for performing each operation of the method 1200. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module. The apparatus may be implemented as or included in the first network device 114. In some exemplary embodiments, the means may comprise a processor and a memory.

[0282] In some exemplary embodiments, the apparatus comprises: means for receiving, in a first network device of a first home public land mobile network (HPLMN), a first request for security information for relay discovery from a terminal device served by the first network device, the first request including at least a relay service code (RSC); means for acquiring at least one identity based on the first request, each of the at least one identity being for one of at least one target relay terminal device group that supports the RSC; means for acquiring at least one set of security information based on the at least one identity and the RSC, each of the at least one set of security information being associated with one of the at least one target relay terminal device group; and means for transmitting the at least one set of security information to the terminal device.

[0283] In some example embodiments, the means for obtaining at least one identity may comprise means for obtaining the at least one identity from a first Policy Control Function (PCF) device in the first HPLMN.

[0284] In some exemplary embodiments, the means for obtaining at least one identity from the first PCF device may comprise means for sending a second request for the at least one identity to the first PCF device, the second request including at least the RSC, and means for receiving a second response to the second request from the first PCF device, the second response including at least the at least one identity.

[0285] In some exemplary embodiments, the means for obtaining the at least one set of security information may comprise means for obtaining a set of security information associated with a relay restriction ID, the relay restriction ID being generated based on an ID for one of the RSC and the at least one target relay terminal device group. In some exemplary embodiments, the means for transmitting the at least one set of security information may comprise means for transmitting the set of security information associated with the relay restriction ID.

[0286] In some exemplary embodiments, the means for obtaining at least one set of security information may include means for generating a first relay restriction ID based on the RSC and a first identity for the first group of target relay terminal devices based on determining that a first group of target relay terminal devices of the at least one group belongs to a first HPLMN, and means for obtaining a first set of security information associated with the first relay restriction ID.

[0287] In some exemplary embodiments, the means for obtaining at least one set of security information comprises: means for sending a third request for a second set of security information for the RSC to a second network device in the second HPLMN based on determining that a second group of the target relay terminal devices of the at least one group belongs to a second HPLMN different from the first HPLMN; and means for receiving a third response to the third request from the second network device, the third response including the second set of security information and a second relay restriction ID, the second relay restriction ID being associated with a second identity for the RSC and the second group.

[0288] In an exemplary embodiment, the third request includes the second identity.

[0289] In some exemplary embodiments, the means for obtaining at least one identity may comprise means for locally obtaining the at least one identity.

[0290] In some exemplary embodiments, each of the at least one target relay terminal equipment group belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.

[0291] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a single target relay terminal device, and each of the at least one identity includes a discovery relay ID.

[0292] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and each of the at least one identity includes one of a PLMN identity of a first HPLMN or a second HPLMN to which the plurality of target relay terminal devices belong, or a group identity of the plurality of target relay terminal devices.

[0293] In some exemplary embodiments, an apparatus (e.g., first terminal device 112) capable of performing any of the methods 1300 may comprise means for performing each operation of method 1300. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module. The apparatus may be implemented as or included in first terminal device 112. In some exemplary embodiments, the means may comprise a processor and a memory.

[0294] In some exemplary embodiments, the apparatus comprises means for transmitting a request for security information for relay discovery from a terminal device to a network device in a home public land mobile network (HPLMN), the request including at least a relay service code (RSC); means for receiving at least one set of security information from the network device, each of the at least one set of security information being associated with one of at least one target relay terminal device group that supports the RSC; and means for performing relay discovery based on the at least one set of security information.

[0295] In some exemplary embodiments, receiving the at least one set of security information may include receiving the set of security information in association with a relay restriction ID, the relay restriction ID being associated with an ID for one of the RSC and the at least one target relay terminal device group.

[0296] In an exemplary embodiment, each of the at least one target relay terminal equipment group belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.

[0297] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a single target relay terminal device, and each of the at least one identity includes a discovery relay ID.

[0298] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and each of the at least one identity includes one of a PLMN identity of a first or second HPLMN to which the plurality of target relay terminal devices belong, or a group identity of the plurality of target relay terminal devices.

[0299] In some exemplary embodiments, an apparatus (e.g., first PCF device 116) capable of performing any of methods 1400 may comprise means for performing each operation of method 1400. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module. The apparatus may be implemented as or included in first PCF device 116. In some exemplary embodiments, the means may comprise a processor and a memory.

[0300] In some exemplary embodiments, the apparatus comprises: means, in a first policy control function (PCF) device in a first home public land mobile network (HPLMN), for receiving a second request for at least one identity from a first network device in the first HPLMN, where each of the at least one identity is for one of at least one target relay terminal device group that supports a relay service code (RSC), the second request including at least the RSC; means for obtaining the at least one identity based on the second request; and means for sending a second response to the second request to the first network device, where the second response includes at least the at least one identity.

[0301] In some exemplary embodiments, each of the at least one target relay terminal equipment group belongs to a first HPLMN or a second HPLMN, the second HPLMN being different from the first HPLMN.

[0302] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a single target relay terminal device, and each of the at least one identity includes a discovery relay ID.

[0303] In some exemplary embodiments, the means for obtaining at least one identity may comprise means for locally obtaining a first identity of the first HPLMN based on the second request based on determining that the at least one target relay terminal device group belongs to the first HPLMN, and means for locally obtaining a relay ID for discovery for each of the at least one target relay terminal device group.

[0304] In some exemplary embodiments, the means for obtaining at least one identity may comprise: means for sending a fourth request of at least one relay ID for discovery for the at least one target relay terminal device group to a second PCF device of the second HPLMN based on determining that the at least one target relay terminal device group belongs to the second HPLMN; and means for receiving a fourth response to the fourth request from the second PCF device, the fourth response including the at least one relay ID.

[0305] In some exemplary embodiments, each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and the at least one identity includes one of a PLMN ID of a first or second HPLMN to which the plurality of target relay terminal devices belong, or a group ID of the plurality of target relay terminal devices.

[0306] In some exemplary embodiments, the means for obtaining at least one identity may comprise means for obtaining a PLMN identity or a group identity based on the second request.

[0307] In some exemplary embodiments, a device capable of performing any of the methods 1500 (e.g., the second network device 124) may include means for performing each operation of the method 1500. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module. The device may be implemented as the second network device 124 or may be included in the second network device 124. In some exemplary embodiments, the means may comprise a processor and a memory.

[0308] In some example embodiments, the apparatus comprises: means, at a second network device in a second home public land mobile network (HPLMN), for receiving from a first network device of a first HPLM a third request for a second set of at least one security information for a relay service code (RSC), the request including at least the RSC, the second HPLMN being different from the first HPLMN; means for obtaining the second set of at least one security information based on the third request; and means for sending a third response to the first network device, the third response including at least the second set of at least one security information.

[0309] In some exemplary embodiments, each set of at least one second security information is associated with a second group of target relay terminal devices belonging to a second HPLMN.

[0310] In some exemplary embodiments, the second group of target relay terminal devices comprises a single target relay terminal device, and the second identity of the second group includes a relay ID for discovery.

[0311] In some exemplary embodiments, the second group of target relay terminal devices comprises a plurality of target relay terminal devices, and the second identity for the second group includes one of a PLMN identity for a second HPLMN to which the plurality of target relay terminal devices belong, or a group identity for the plurality of target relay terminal devices.

[0312] In some exemplary embodiments, the means for obtaining the at least one second set of security information may comprise means for generating a second relay restriction ID based on the RSC and a second identity for the second group, and means for obtaining one of the at least one second set of security information associated with the second relay restriction ID.

[0313] In some demonstrative embodiments, the means for transmitting the at least one second set of security information may comprise means for transmitting one of the at least one second set of security information associated with the second relay restricted identity.

[0314] In some exemplary embodiments, the third request includes second identities for a second group of target relay terminal devices.

[0315] In some exemplary embodiments, an apparatus capable of executing any of the methods 1600 (e.g., second PCF device 126) may comprise means for performing each operation of method 1600. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module. The apparatus may be implemented as or included in second PCF device 126. In some exemplary embodiments, the means may comprise a processor and a memory.

[0316] In some exemplary embodiments, the apparatus comprises: means for receiving, at a second PCF device in a second home public land mobile network (HPLMN), a request for at least one identity, each of the at least one identity being for a target relay terminal device that supports a relay service code (RSC), the request including at least the RSC; means for obtaining the at least one identity based on the request; and means for transmitting a response to the request, the response including the at least one identity.

[0317] In some exemplary embodiments, the means for receiving a request for the at least one identity comprises means for receiving the request from either a first network device in a first HPLMN different from the second HPLMN or an SSNND in the second HPLMN.

[0318] It should be understood that the details of the exemplary embodiments of the present disclosure described with reference to FIGS. 7 to 11 also apply to methods 1200 to 1600.

[0319] 17 is a simplified block diagram of an apparatus 1700 suitable for implementing embodiments of the present disclosure. The apparatus 1700 may be provided to implement a communications apparatus such as the first terminal device 112, the first network device 114, the first PCF device 116, the second terminal device 122, the second network device 124, or the second PCF device 126 as shown in FIG. 1. As shown, the apparatus 1700 includes one or more processors 1710, one or more memories 1720 coupled to the processors 1710, and one or more communications modules 1740 coupled to the processors 1710.

[0320] The communication module 1740 is for two-way communication. The communication module 1740 has at least one antenna to facilitate communication. The communication interface may represent any interface necessary for communication with other network elements.

[0321] The processor 1710 may be of any type suitable for a local technology network and may include, by way of non-limiting example, one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. The device 1700 may have multiple processors, such as application-specific integrated circuit chips that are time-slaved to a clock that synchronizes a main processor.

[0322] The memory 1720 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memory include, but are not limited to, read-only memory (ROM) 1724, electronically programmable read-only memory (EPROM), flash memory, hard disks, compact disks (CDs), digital video disks (DVDs), and other magnetic and / or optical storage devices. Examples of volatile memory include, but are not limited to, random access memory (RAM) 1722 and other volatile memories that do not persist through power-down durations.

[0323] The computer program 1730 includes computer-executable instructions that are executed by the associated processor 1710. The program 1730 may be stored in the ROM 1724. The processor 1710 can load the program 1730 into the RAM 1722 to perform any suitable operations and processes.

[0324] 1 to 16, the embodiment of the present disclosure may be implemented by a program 1730 such that the device 1700 can execute any process of the present disclosure. The embodiment of the present disclosure may also be implemented by hardware or a combination of software and hardware.

[0325] In some exemplary embodiments, the program 1730 may be tangibly contained in a computer-readable medium, which may be included in the device 1700 (such as in memory 1720) or other storage accessible by the device 1700. The device 1700 may load the program 1730 from the computer-readable medium into RAM 1722 and execute it. The computer-readable medium may include any type of tangible non-volatile storage, such as ROM, EPROM, Flash memory, hard disk, CD, DVD, etc. Figure 18 shows an example of a computer-readable medium 1800 in the form of a CD or DVD. The computer-readable medium has the program 1730 stored on it.

[0326] In general, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device. While various aspects of embodiments of the present disclosure have been illustrated and described using block diagrams, flowcharts, or some other pictorial representations, it should be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller, or other computing device, or some combination thereof, in non-limiting, illustrative examples.

[0327] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, that execute on a target real or virtual processor device to perform methods 1200-1600, as described above with reference to Figures 12-16. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split among program modules as desired in various embodiments. The machine-executable instructions of the program modules may be executed in local or distributed devices. In a distributed device, the program modules may be located in both local and remote storage media.

[0328] Program code for carrying out the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus such that, when executed by the processor or controller, the functions / acts specified in the flowcharts and / or block diagrams are performed. The program code can run entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0329] In the context of the present disclosure, computer program code or associated data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations as described above. Examples of carriers include signals, computer-readable media, etc.

[0330] The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. Computer-readable media include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More specific examples of computer-readable storage media include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0331] Furthermore, although operations are depicted in a particular order, this should not be understood as requiring such operations to be performed in the particular order shown, or sequentially, or that all of the operations depicted be performed, to achieve desirable results. In certain situations, multitasking and parallel processing may be preferred. Similarly, while several specific implementation details are included in the above description, these should not be construed as limiting the scope of the disclosure, but rather as descriptions of features that may be unique to particular embodiments. Certain features that are described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable subcombination.

[0332] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the present disclosure, as defined by the appended claims, is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. a first network device, at least one processor; When executed by the at least one processor, the method provides the first network device in a first home public land mobile network (HPLMN) with at least: receiving a first request for security information for relay discovery from an end device served by the first network device, the first request including at least a Relay Service Code (RSC); Obtaining at least one identity based on the first request, each of the at least one identity being for one of at least one target relay terminal device group that supports the RSC; and Obtaining at least one set of security information based on the at least one identity and the RSC, each of the at least one set of security information being associated with one of the at least one target relay terminal device group; and transmitting said at least one set of security information to said terminal device; at least one memory storing instructions for executing the A first network device comprising:

2. the first network device, obtaining the at least one identity from a first Policy Control Function (PCF) device in the first HPLMN; to obtain the at least one identity by The first network device of claim 1 .

3. the first network device, sending a second request for the at least one identity to the first PCF device, the second request including at least the RSC; receiving a second response to the second request from the first PCF device, the second response including at least the at least one identity; and obtaining the at least one identity from the first PCF device by The first network device of claim 2 .

4. the first network device, Obtaining a set of security information associated with a relay restriction identity, the relay restriction identity being generated based on the RSC and an identity of one of the at least one target relay terminal device group; to obtain the at least one set of security information by the first network device, transmitting the set of security information in association with the relay restriction identity; to transmit the at least one set of security information by The first network device of claim 1 .

5. the first network device, Based on determining that a first group of target relay terminal devices among the at least one group belongs to the first HPLMN, generating a first relay restriction identity based on the RSC and a first identity of the first group of target relay terminal devices; obtaining a first set of security information associated with the first relay restriction identity; 5. The first network device of claim 4, adapted to obtain the at least one set of security information by:

6. the first network device, Based on determining that a second group of target relay terminal devices among the at least one group belongs to a second HPLMN different from the first HPLMN, sending a third request for a second set of security information for the RSC to a second network device in the second HPLMN; receiving a third response to the third request from the second network device, the third response including the second set of security information and a second relay restricted identity, the second relay restricted identity being associated with the RSC and a second identity of the second group; 5. The first network device according to claim 4, wherein the first network device is caused to obtain the at least one set of security information by:

7. The first network device of claim 6 , wherein the third request includes the second identity.

8. the first network device, obtaining the at least one identity locally; The first network device according to claim 1 , adapted to obtain the at least one identity by:

9. The first network device according to claim 1 , wherein each of the at least one target relay terminal device group belongs to the first HPLMN or a second HPLMN, and the second HPLMN is different from the first HPLMN.

10. The first network device of claim 9 , wherein each of the at least one target relay terminal device groups includes a single target relay terminal device, and each of the at least one identity includes a relay identity for discovery.

11. Each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and each of the at least one identity is: The PLMN identity of the first HPLMN or the second HPLMN to which the plurality of target relay terminal devices belong; or a group identity of the plurality of target relay terminal devices; 10. The first network device of claim 9, comprising one of:

12. A terminal device, at least one processor; When executed by the at least one processor, the terminal device is configured to: sending a request for security information for relay discovery to a network device in a Home Public Land Mobile Network (HPLMN), the request including at least a Relay Service Code (RSC); receiving at least one set of security information from the network device, each of the at least one set of security information being associated with one of at least one target relay terminal device group supporting the RSC; performing the relay discovery based on the at least one set of security information; at least one memory storing instructions for executing the A terminal device comprising:

13. The terminal device receiving a set of security information associated with a relay restriction identity, the relay restriction identity being associated with the RSC and an identity of one of the at least one target relay terminal device group; 13. The terminal device according to claim 12, wherein said terminal device is adapted to receive said at least one set of security information by:

14. The terminal device of claim 12 , wherein each of the at least one target relay terminal device group belongs to a first HPLMN or a second HPLMN, and the second HPLMN is different from the first HPLMN.

15. The terminal device of claim 14 , wherein each of the at least one target relay terminal device groups includes a single target relay terminal device, and each of the at least one identity includes a relay identity for discovery.

16. Each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and each of the at least one identity is: the PLMN identity of the first or second HPLMN to which the plurality of target relay terminal devices belong; or a group identity of the plurality of target relay terminal devices; 15. The terminal device of claim 14, comprising one of:

17. a first policy control function (PCF) device, at least one processor; When executed by the at least one processor, the method includes: receiving a second request for at least one identity from a first network device in the first HPLMN, each of the at least one identity being for one of at least one target relay terminal device group that supports a relay service code (RSC), the second request including at least the RSC; obtaining the at least one identity based on the second request; and receiving, to the first network device, a second response to the second request, the second response including at least the at least one identity; at least one memory storing instructions for executing the a first PCF device comprising:

18. 18. The first PCF device of claim 17, wherein each of the at least one target relay terminal device group belongs to the first HPLMN or the second HPLMN, and the second HPLMN is different from the first HPLMN.

19. 20. The first PCF device of claim 18, wherein each of the at least one target relay terminal device groups comprises a single target relay terminal device, and each of the at least one identity includes a relay identity for discovery.

20. The first PCF device Based on determining that the at least one target relay terminal device group belongs to the first HPLMN, locally obtaining a first identity of the first HPLMN based on the second request; Obtaining a relay identity for local discovery for each of the at least one target relay terminal device group; 20. The first PCF device of claim 19, adapted to obtain the at least one identity by:

21. The first PCF device Based on determining that the at least one target relay terminal device group belongs to the second HPLMN, sending a fourth request for at least one relay identity for discovery of the at least one target relay terminal device group to a second PCF device in the second HPLMN; receiving a fourth response to the fourth request from the second PCF device, the fourth response including the at least one relay identity; 20. The first PCF device of claim 19, adapted to obtain the at least one identity by:

22. Each of the at least one target relay terminal device group comprises a plurality of target relay terminal devices, and the at least one identity is: the PLMN identity of the first or second HPLMN to which the plurality of target relay terminal devices belong; or a group identity of the plurality of target relay terminal devices; 20. The first PCF device of claim 18, comprising one of:

23. The first PCF device obtaining the PLMN identity or the group identity based on the second request; 23. The first PCF device of claim 22, adapted to obtain the at least one identity by:

24. a second network device, at least one processor; When executed by the at least one processor, the method provides the second network device in a second home public land mobile network (HPLMN) with at least: receiving, from a first network device in a first HPLM, a third request for at least a second set of security information for a relay service code (RSC), the request including at least the RSC, the second HPLMN being different from the first HPLMN; obtaining the at least one second set of security information based on the third request; and transmitting a third response to the first network device, the third response including at least the at least one second set of security information; at least one memory storing instructions for executing the A second network device comprising:

25. 25. The second network device of claim 24, wherein each of the at least one second set of security information is associated with a second group of target relay terminal devices belonging to the second HPLMN.

26. 26. The second network device of claim 25, wherein the second group of target relay terminal devices comprises a single target relay terminal device, and the second identity of the second group includes a relay identity for discovery.

27. The second group of target relay terminal devices comprises a plurality of target relay terminal devices, and a second identity for the second group comprises: The PLMN identity of the second HPLMN to which the plurality of target relay terminal devices belong; or a group identity of the plurality of target relay terminal devices; 26. The second network device of claim 25, comprising one of:

28. the second network device, generating a second relay restriction identity based on the RSC and a second identity of the second group; obtaining one of the at least one second set of security information associated with the second relay restriction identity; to obtain a second set of the at least one security information by the second network device, transmitting one of the at least one second set of security information in association with the second relay restriction identity; to transmit the at least one second set of security information by 26. The second network device of claim 25.

29. The second network device of claim 24, wherein the third request includes a second identity of the target relay terminal device for the second group.

30. a second Policy Control Function (PCF) device, at least one processor; When executed by the at least one processor, the method causes the second PCF device in a second Home Public Land Mobile Network (HPLMN) to receive at least: receiving a request for at least one identity, each of the at least one identity being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; obtaining the at least one identity based on the request; and sending a response to the request, the response including the at least one identity; at least one memory storing instructions for executing the a second PCF device comprising:

31. The second PCF device a first network device in a first HPLMN different from the second HPLMN; or a second network device in the second HPLMN; and receiving the request for at least one identity from one of the 31. The second PCF device of claim 30.

32. 1. An apparatus comprising: means for receiving, in a first network device in a first home public land mobile network (HPLMN), a first request for security information for relay discovery from a terminal device served by the first network device, the first request including at least a relay service code (RSC); means for obtaining at least one identity based on the first request, each of the at least one identity being for one of at least one target relay terminal device group that supports the RSC; and means for obtaining at least one set of security information based on the at least one identity and the RSC, each of the at least one set of security information being associated with one of the at least one target relay terminal device group; means for transmitting said at least one set of security information to said terminal device; An apparatus comprising:

33. 1. An apparatus comprising: means for transmitting a request for security information for relay discovery from a terminal device to a network device in a Home Public Land Mobile Network (HPLMN), the request including at least a Relay Service Code (RSC); means for receiving at least one set of security information from the network device, each of the at least one set of security information being associated with one of at least one target relay terminal device group supporting the RSC; means for performing the relay discovery based on the at least one set of security information; An apparatus comprising:

34. 1. An apparatus comprising: means for receiving, in a first Policy Control Function (PCF) device in a first Home Public Land Mobile Network (HPLMN), a second request for at least one identity from a first network device in the first HPLMN, each of the at least one identity being for one of at least one target relay terminal device group supporting a Relay Service Code (RSC), the second request including at least the RSC; means for obtaining the at least one identity based on the second request; means for transmitting to the first network device a second response to the second request, the second response including at least the at least one identity; An apparatus comprising:

35. 1. An apparatus comprising: means for receiving, in a second network device in a second Home Public Land Mobile Network (HPLMN), from a first network device in a first HPLMN, a third request for at least a second set of security information for a Relay Service Code (RSC), the request including at least the RSC, the second HPLMN being different from the first HPLMN; means for obtaining the at least one second set of security information based on the third request; means for transmitting a third response to the first network device, the third response including at least the at least one second set of security information; An apparatus comprising:

36. 1. An apparatus comprising: means for receiving, in a second PCF device in a second home public land mobile network (HPLMN), a request for at least one identity, each of the at least one identity being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; means for obtaining the at least one identity based on the request; means for transmitting a response to the request, the response including the at least one identity; An apparatus comprising:

37. receiving, at a first network device in a first home public land mobile network (HPLMN), from a terminal device served by the first network device, a first request for security information for relay discovery, the first request including at least a relay service code (RSC); Obtaining at least one identity based on the first request, each of the at least one identity being for one of at least one target relay terminal device group that supports the RSC; and Obtaining at least one set of security information based on the at least one identity and the RSC, each of the at least one set of security information being associated with one of the at least one target relay terminal device group; transmitting said at least one set of security information to said terminal device; A method comprising:

38. sending a request for security information for relay discovery from a terminal device to a network device in a Home Public Land Mobile Network (HPLMN), the request including at least a Relay Service Code (RSC); receiving at least one set of security information from the network device, each of the at least one set of security information being associated with one of at least one target relay terminal device group supporting the RSC; performing the relay discovery based on the at least one set of security information; A method comprising:

39. receiving, at a first Policy Control Function (PCF) device in a first Home Public Land Mobile Network (HPLMN), from a first network device in the first HPLMN, a second request for at least one identity, each of the at least one identity being for one of at least one target relay terminal device group supporting a Relay Service Code (RSC), the second request including at least the RSC; obtaining the at least one identity based on the second request; and sending, to the first network device, a second response to the second request, the second response including at least the at least one identity; A method comprising:

40. receiving, at a second network device in a second Home Public Land Mobile Network (HPLMN), from a first network device in a first HPLMN, a third request for at least a second set of security information for a Relay Service Code (RSC), the request including at least the RSC, the second HPLMN being different from the first HPLMN; obtaining the at least one second set of security information based on the third request; and transmitting a third response to the first network device, the third response including at least the at least one second set of security information; A method comprising:

41. receiving, at a second PCF device in a second home public land mobile network (HPLMN), a request for at least one identity, each of the at least one identity being for a target relay terminal device supporting a relay service code (RSC), the request including at least the RSC; obtaining the at least one identity based on the request; and sending a response to the request, the response including the at least one identity; A method comprising:

42. A computer readable medium comprising program instructions for causing an apparatus to perform at least the method of any of claims 37 to 41.

Citation Information

Patent Citations

  • Relay communication method and device, communication equipment and storage medium

    CN115152254A

  • Secure link establishment

    US20220360966A1

  • Discovery key handling for UE-to-network relay discovery

    WO2022148622A1