SYSTEM AND METHOD FOR PROVIDING SECURITY MECHANISMS TO UES IN A CORELESS RADIO ACCESS NETWORK - Patent application
The system addresses the inflexibility of 5G networks by enabling coreless RAN operations through local data management and lightweight AMF entities, enhancing QoS and network flexibility for UAVs in 6G networks.
Patent Information
- Application Number
- JP2025531267
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-11-30
- Filing Date
- 2023-11-30
- Publication Date
- 2026-01-06
AI Technical Summary
The existing 5G network architecture is inflexible and lacks the ability to support coreless radio access network (RAN) operations, particularly for unmanned aerial vehicles (UAVs), requiring improved security mechanisms for user equipment (UE) in 6G networks to enhance network flexibility, deployment, simplicity, efficiency, security, robustness, and automation.
A system and method for providing radio access node security mechanisms that enable coreless RAN operation by using a processor to determine the availability of user subscription data within mobile radio units, acquiring data from external sources if needed, and providing security mechanisms to UE, with features like local data management and lightweight AMF entities to support authentication and authorization independently from the core network.
Enables coreless RAN functionality, supports UAV-based operations, enhances QoS, and provides network programmability, deployment flexibility, simplicity, security, robustness, and automation in 6G networks.
Smart Images

Figure 2026500133000001_ABST
Abstract
Description
[Technical Field]
[0001] Reservation of Rights Portions of the disclosure of this patent document contain material that is subject to intellectual property rights, including but not limited to copyright, design, trademark, IC layout design, and / or trade dress protection, vested in Jio Platforms Limited (JPL) or its affiliates (hereinafter the "Owner"). The Owner has no objection to the facsimile reproduction of the patent document or patent disclosure as it appears in the Patent and Trademark Office patent file or records, but otherwise reserves all rights. All rights to such intellectual property are fully reserved by the Owner.
[0002] The present invention relates to the field of wireless communications, and more particularly to a system and method for providing security mechanisms, e.g., radio access node security mechanisms, to User Equipment (UE) to support coreless Radio Access Network (RAN) operation in cellular networks. [Background technology]
[0003] The following description of related art is intended to provide background information related to the field of the present disclosure. This section may include specific aspects of technology that may be related to various features of the present disclosure. However, it should be understood that this section is intended solely to enhance the reader's understanding of the present disclosure and is not intended as an admission of prior art.
[0004] As is well known, fifth-generation (5G) communication technology includes several upgraded features over those available in fourth-generation (4G) communication technology. Developed by the 3rd Generation Partnership Project (3GPP), 5G wireless communication technology aims to provide higher peak data rates of several Gbps, ultra-low latency, higher reliability and network capacity, improved availability, and a more uniform user experience for multiple users. The higher performance and improved efficiency provided by 5G technology will enable new user experiences and connect new industries. While the adoption of 5G technology has achieved some of the industry's goals, significant challenges remain, particularly with regard to addressing vertical industry integration, architectures supporting private networks, and support for flexible network deployment.
[0005] The 5G Core has a fully service-based architecture (SBA) with a new service-based interface (SBI), thus decoupling the service consumer from the service provider. The 5G Core supports new features such as improved session management that enables session and service continuity with a "make before break" option, which is essential for Ultra-Reliable Low Latency Communication (URLLC) use cases; a flow-based Quality of Service (QoS) framework that guarantees QoS at the application level; and flexible end-to-end and seamless network slicing across the RAN, core, and transport networks, which allows user equipment (UE) to access multiple slices simultaneously. As shown in Figure 1 at 100, the 5G network nodes include the Core Access and Mobility Management Function (AMF), which is responsible for terminating the UE, Next Generation Node Base station (gNB), Radio Access Network (RAN) control plane interface, the Non Access Stratum (NAS) for ciphering and integrity protection, mobility management, and access authentication and authorization, which serves as the Security Anchor Function (SEA). The AMF also interacts with the UE and Unified Data Management (UDM) as part of the UE's authentication process. The AMF is responsible for Security Context Management (SCM).Additionally, the core network User Plane Function (UPF) covers the functions of QoS processing, packet routing and forwarding, packet inspection and policy rule enforcement, traffic accounting and reporting, and acts as an anchor point for intra / inter-Radio Access Technology (RAT) mobility, where applicable.
[0006] Additionally, the architecture includes a Session Management Control Function (SMF) for session management, UE Internet Protocol (IP) address allocation and management (including optional authorization), user plane function selection and control, a termination interface for policy control, and a charging function that allows for policy enforcement and partial control of QoS. The architecture also handles roaming functions, local enforcement (i.e., Visited Public Land Mobile Network (VPLMN)) for applying QoS service level agreements (SLAs), charging data collection, and the charging interface (VPLMN). The Data Network (DN) handles operator services, Internet access, or other services. The Authentication Server Function (AUSF) handles authentication with the UE. The UDM supports an Authentication Credential Repository and Processing Function (ARPF). The ARPF function stores long-term security credentials used for AKA authentication and assists in the storage of subscription information. The Policy Control Function (PCF) provides support for a unified policy framework for controlling network behavior.
[0007] In the 5G network architecture described above, the close coupling of radio access nodes and core network functions results in multiple drawbacks at the functionality level. Therefore, there is a need in the art for an improved system and method for providing a sixth-generation (6G) network architecture that overcomes various drawbacks and addresses network flexibility issues. Summary of the Invention [Problem to be solved by the invention]
[0008] Some of the objectives of the present disclosure that are met by at least one embodiment herein are listed below.
[0009] An object of the present disclosure is to provide a system and method for providing radio access node security mechanisms to user equipment (UE) to support coreless radio access network (RAN) operation in cellular networks.
[0010] It is an object of the present invention to provide a system and method that enables a radio access node to operate in a coreless mode of operation for authorization / authentication of user equipment or UE.
[0011] An object of the present invention is to provide a system and method for supporting coreless RAN functionality to support unmanned aerial vehicle (UAV)-based radio access operations in sixth-generation (6G) network technologies.
[0012] It is an object of the present disclosure to provide systems and methods that facilitate providing better quality of service (QoS) to enhance end-user experience.
[0013] An objective of the present disclosure is to provide an enhanced network system with (a) network programmability, (b) deployment flexibility, (c) simplicity and efficiency, (d) security, robustness, and reliability, and (e) automation. [Means for solving the problem]
[0014] This section is provided to introduce in a simplified form certain objects and aspects of the disclosure that are described below in the Detailed Description. This Summary is not intended to identify key features or the scope of the claimed subject matter.
[0015] In one aspect, the present disclosure relates to a system for providing a security mechanism to a user equipment (UE) in a coreless radio access network (RAN). The system includes a processor and a memory operatively coupled to the processor. The memory stores instructions that, when executed by the processor, cause the processor to receive a registration request from the UE, the registration request including user subscription data. The processor determines whether the user subscription data is available within a mobile radio unit in a particular geographical area. Based on a positive determination, the processor provides the security mechanism to the UE. Based on a negative determination, the processor sends a data acquisition request to at least one data source. The processor receives data associated with the particular geographical area from the at least one data source and provides the security mechanism to the UE based on the received data.
[0016] In one embodiment, the memory includes processor-executable instructions that, when executed, may cause the processor to update the database based on the received data.
[0017] In one embodiment, the registration request may include one or more non-access stratum (NAS) messages.
[0018] In one embodiment, the memory includes processor-executable instructions that, when executed, may cause the processor to decode one or more NAS messages, authenticate the one or more NAS messages upon decoding, select a security mechanism based on the authentication, and provide the security mechanism to the UE.
[0019] In one aspect, the present disclosure relates to a method for providing a security mechanism to a user equipment (UE) in a coreless radio access network (RAN). The method includes receiving, by a processor associated with the system, a registration request from the UE, the registration request including user subscription data. The method includes determining, by the processor, whether the user subscription data is available within mobile radio units in a particular geographic region. Based on a positive determination, the method includes providing, by the processor, the security mechanism to the UE. Based on a negative determination, the method includes sending, by the processor, a data acquisition request to at least one data source. The method includes receiving, by the processor, data associated with the particular geographic region from the at least one data source, and providing, by the processor, the security mechanism to the UE based on the received data.
[0020] In one embodiment, the method may include updating, by the processor, a database based on the received data.
[0021] In one embodiment, the registration request may include one or more non-access stratum (NAS) messages.
[0022] In one embodiment, the method may include: decrypting, by the processor, one or more NAS messages; authenticating, by the processor, the one or more NAS messages upon decoding; selecting, by the processor, a security mechanism based on the authentication; and providing the security mechanism to the UE.
[0023] In one aspect, the present disclosure relates to a user equipment (UE). The UE includes a processor and a memory operatively coupled to the processor. The memory includes processor-executable instructions that, when executed, cause the processor to send a registration request to a system. The processor is communicatively coupled to the system, and the system is configured to receive the registration request from the UE, the registration request including user subscription data. The system is configured to determine whether the user subscription data is available within a mobile radio unit in a specific geographic region. Based on a positive determination, the system is configured to provide a security mechanism to the UE. Based on a negative determination, the system is configured to send a data acquisition request to at least one data source. The system is configured to receive data associated with the specific geographic region from the at least one data source and provide a security mechanism to the UE based on the received data.
[0024] In one aspect, the present disclosure relates to a non-transitory computer-readable medium including processor-executable instructions causing a processor to receive a registration request from a UE, the registration request including user subscription data, and determine whether the user subscription data is available within mobile radio units in a particular geographic region. Based on a positive determination, the processor provides a security mechanism to the UE. Based on a negative determination, the processor sends a data acquisition request to at least one data source, receives data associated with the particular geographic region from the at least one data source, and provides a security mechanism to the UE based on the received data. [Effects of the Invention]
[0025] The present disclosure provides systems and methods by which a radio access node may operate in a coreless mode of operation for authorization / authentication of user equipment (UE) or user terminals.
[0026] The present disclosure provides systems and methods for supporting coreless RAN functionality to support unmanned aerial vehicle (UAV)-based radio access operations in 6G network technologies.
[0027] The present disclosure provides systems and methods that facilitate better quality of service (QoS) to enhance end-user experience.
[0028] The present disclosure provides an enhanced network system with (a) network programmability, (b) deployment flexibility, (c) simplicity and efficiency, (d) security, robustness, and reliability, and (e) automation. [Brief explanation of the drawings]
[0029] The accompanying drawings are included to provide a further understanding of the present disclosure, and are incorporated in and constitute a part of this specification. The drawings illustrate exemplary embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure. The drawings are for purposes of illustration only and are therefore not intended to be limiting of the present disclosure.
[0030] In the figures, similar components and / or features may have the same reference label. Furthermore, various components of the same type may be distinguished by following the reference label with a second label that distinguishes among the similar components. When only a first reference label is used herein, the description applies to any one of the similar components having the same first reference label, regardless of the second reference label. [Figure 1] A block diagram of the fifth-generation (5G) core network architecture is shown. [Figure 2A] 1 illustrates an exemplary network architecture for implementing the proposed system, according to one embodiment of the present disclosure. [Figure 2B] 1 illustrates an exemplary block diagram of a proposed system, according to an embodiment of the present disclosure. [Figure 3]1 illustrates an exemplary architecture for implementing a coreless radio access network (RAN) security mechanism, according to one embodiment of the present disclosure. [Figure 4] 1 illustrates a sequential flow diagram for updating a Local Data Management (LDM) entity with relevant user subscription information, according to one embodiment of the present disclosure. [Figure 5] 1 illustrates an exemplary architecture for implementing a coreless RAN security mechanism according to another embodiment of the present disclosure. [Figure 6] 1 illustrates a sequential flow diagram for authentication of a user equipment (UE) by an LDM, according to one embodiment of the present disclosure. [Figure 7] 1 illustrates an exemplary computer system that may utilize or be utilized in conjunction with embodiments of the present invention in accordance with embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0031] In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. However, it will be apparent that embodiments of the present disclosure may be practiced without these specific details. Some features described below can be used independently of each other or in any combination with other features. Individual features may not address all of the problems described above, or may only address some of the problems described above. Some of the problems described above may not be completely addressed by any of the features described herein.
[0032] The following description provides exemplary embodiments only and is not intended to limit the scope, applicability, or configuration of the present disclosure. Rather, the following description of exemplary embodiments will provide those skilled in the art with an effective description for implementing the exemplary embodiments. It will be understood that various changes can be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as described.
[0033] In the following description, specific details are provided to provide a thorough understanding of the embodiments. However, it will be understood by those of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form so as not to obscure the embodiments in unnecessary detail. In other examples, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail so as not to obscure the embodiments.
[0034] Also, it should be noted that particular embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. While a flowchart may describe operations as a sequential process, many of the operations may be performed in parallel or simultaneously. Additionally, the order of operations may be rearranged. A process terminates when its operations are completed, but may have additional steps not included in the diagram. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination corresponds to the function returning to the calling function or to the main function.
[0035] The words "exemplary" and / or "demonstrative" are used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. Additionally, any aspect or design described herein as "exemplary" and / or "demonstrative" is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to exclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms "including," "having," "containing," and other similar terms are used in either the detailed description or the claims, such terms are intended to be inclusive in a manner similar to the open transitional term "comprising," without excluding additional or other elements.
[0036] Throughout this specification, references to "one embodiment" or "embodiment" or "example" or "one example" mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrase "in one embodiment" or "in an embodiment" in various places throughout this specification do not necessarily all refer to the same embodiment. Furthermore, particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0037] The terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting of the disclosure. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context indicates otherwise. It will be further understood that as used herein, the terms "comprises" and / or "comprising" specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0038] Sixth-generation (6G) networks are expected to provide radio and access architectures for both communications and sensing, including the co-design of artificial intelligence (AI)-optimized wide-area networks and data centers, and the dynamic orchestration of personalized services that revolutionize the long tail of niche consumer interests. While demand for mobile broadband is expected to continue to grow for consumers and businesses alike, ultra-reliable and low-latency deployments may be driven largely by specialized and local use cases in conjunction with non-public networks, often driven by augmented intelligence. This could occur as an integral part of an automated and secure network transformation, where objects ranging from automobiles, industrial machinery, and home appliances to watches and apparel are expected to learn and organize themselves to meet requirements by automatically adapting to user behavior, environments, and business processes.
[0039] Furthermore, achieving energy efficiency is also a key design criterion for 6G, as network performance may depend on the energy available in each architectural domain. One of the most challenging requirements for energy efficiency arises from the use of remote control devices for augmented reality and immersive media experiences. In such cases, ultra-high-speed data rates of 100 Gbit / s or more are required, enabling uncompressed transmission of high-quality 360-degree video, in addition to ultra-reliable and low-latency (URLLC) performance requirements. This results in demands for flexibility and specificity that exceed the capabilities of fifth-generation (5G) networks.
[0040] Therefore, it is appropriate to assume that 6G network design will likely be open service-driven. In short, business needs will drive the creation of 6G products and services. 6G networks will likely become an integral part of automated end-to-end (E2E) service workflows, steered and guided by policy and intent. In other words, use-case-driven means may be provided to meet the diverse needs and preferences of each user, whether they are a human, a physical machine, or a digital twin. In summary, the key requirements for designing a 6G architecture include (a) network programmability, (b) deployment flexibility, (c) simplicity and efficiency, (d) security, robustness, and reliability, and (e) automation.
[0041] For future technological advancements, a new paradigm in wireless communication technology, namely the 6G system, is proposed, which provides comprehensive support for devices supporting artificial intelligence (AI). The 6G system offers improved services compared to existing 5G systems, solving several fundamental problems by providing higher system capacity, higher data rates, lower latency, and improved quality of service (QoS). Furthermore, the proposed 6G architecture facilitates the solution of the problem of supporting a coreless mode of radio access network (RAN) operation.
[0042] As can be appreciated, one of the key requirements for radio base stations in 6G cellular networks that are expected to support mobility access nodes, such as access nodes for UAVs, is a coreless network concept, in which RAN nodes operate independently from the core network. To support such an independent RAN that operates independently from the core network, the existing security architecture needs to be reworked, as current security mechanisms available to user equipment (UE) are split across access network and core network entities and suffer from several drawbacks. This disclosure proposes systems and methods that provide an architecture with two-tiered security mechanisms in the RAN itself.
[0043] The proposed disclosure provides a system and method that addresses the problem of decoupling RAN access nodes from the core network and making device authentication / authorization independent from the core network. The system supports coreless RAN functionality that supports crewless / unmanned aerial vehicle (UAV)-based radio access operations and is used in 6G network architectures as a fundamental building block.
[0044] In the proposed embodiment, the core-independent radio access node is responsible for authenticating and authorizing devices, and the only dependency the radio access node has on the core network is for downloading a subscription profile from a user subscription entity in the core network.
[0045] Various embodiments throughout this disclosure are described in more detail with reference to FIGS. 2A-7.
[0046] FIG. 2A illustrates an exemplary network architecture (200A) for implementing the proposed system (210) according to one embodiment of the present disclosure.
[0047] Referring to FIG. 2A, the network architecture 200A may include a system 210. The system 210 may be connected to one or more computing devices 204-1, 204-2, ..., 204-N via a network 206. The one or more computing devices 204-1, 204-2, ..., 204-N may be interchangeably designated as user equipment (UE) 204 and operated by one or more users 202-1, 202-2, ..., 202-N. Additionally, the one or more users 202-1, 202-2, ..., 202-N may be interchangeably referred to as a user 202 or multiple users 202. The system 210 may include or be associated with a data lake 212 that includes multiple data sources. The multiple data sources may include, but are not limited to, a Local Data Management (LDM) entity, a Light weight Access and Mobility Management Function (AMF) entity, a Unified Data Management (UDM) entity, a Home Subscriber Server (HSS) entity, etc.
[0048] In one embodiment, the computing device 204 may include, but is not limited to, a mobile device, a laptop, etc. Furthermore, the computing device 204 may include a smartphone, a virtual reality (VR) device, an augmented reality (AR) device, a general-purpose computer, a desktop, a personal digital assistant, a tablet computer, and a mainframe computer. Furthermore, the computing device 204 may use an input device for receiving input from the user 202, such as a touchpad, a touch-enabled screen, or an electronic pen. A person of ordinary skill in the art will understand that the computing device 204 is not limited to the devices mentioned above, and various other devices may be used. The computing device 204 may be referred to as user equipment (UE).
[0049] In one embodiment, network 206 may include at least a portion of one or more networks having one or more nodes that, by way of example and not limitation, transmit, receive, forward, generate, buffer, store, route, switch, process, or any combination thereof, one or more messages, packets, signals, waves, voltage or current levels, any combination thereof, etc. Network 206 may also include, by way of example and not limitation, one or more of a wireless network, a wired network, the Internet, an intranet, a public network, a private network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a public-switched telephone network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or any combination thereof. Network 206 may include, by way of example and not limitation, a unicast network, a multicast network, or a broadcast network.
[0050] In one embodiment, the system 210 may receive a registration request from the UE 204. The registration request may include user subscription data. The system 210 may determine whether the user subscription data is available within the mobile radio unit in the specific geographic region. If the user subscription data is available within the mobile radio unit in the specific geographic region, the system 210 may provide a security mechanism to the UE. If the user subscription data is not available within the mobile radio unit in the specific geographic region, the system 210 may send a data acquisition request to at least one data source, such as a UDM entity. The system 210 may receive data associated with the specific geographic region from the at least one data source and provide a security mechanism to the UE 204 based on the received data.
[0051] Although Figure 2A illustrates example components of network architecture (200A), in other embodiments, network architecture (200A) may include fewer components, different components, components in a different arrangement, or components with additional functionality than those depicted in Figure 2. Additionally or alternatively, one or more components of network architecture (200A) may perform functions described as being performed by one or more other components of network architecture (200A).
[0052] FIG. 2B shows an exemplary block diagram of the proposed system (210) according to one embodiment of the present disclosure.
[0053] Referring to FIG. 2B , the system (210) may include one or more processors (222), which may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuits, and / or any device that processes data based on operational instructions. Among other functions, the one or more processors (222) may be configured to fetch and execute computer-readable instructions stored in the memory (224) of the system (210). The memory (224) may be configured to store one or more computer-readable instructions or routines on a non-transitory computer-readable storage medium, which may be fetched and executed to create or share data packets via a network service. The memory (224) may include any non-transitory storage device, including, for example, volatile memory such as random-access memory (RAM), or non-volatile memory such as erasable programmable read-only memory (EPROM), flash memory, etc.
[0054] In one embodiment, the system 210 may include an interface 226. The interface(s) 226 may include various interfaces, such as interfaces for data input / output (I / O) devices, storage devices, etc. The interface 226 may also provide a communication path for one or more components of the system 210. Examples of such components include, but are not limited to, a processing engine 228 and a database 240. The processing engine 228 may include, but is not limited to, a receiving engine 230, a decision engine 232, a data acquisition engine 234, a service provision engine 236, and other engines 238. The other engines 238 may include, but are not limited to, a monitoring engine, etc.
[0055] In one embodiment, the processing engine(s) (228) may be implemented as a combination of hardware and programming (e.g., programmable instructions) to implement one or more functionality of the processing engine(s) (228). In the examples described herein, such a combination of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine (228) may be processor-executable instructions stored on a non-transitory machine-readable storage medium, and the hardware for the processing engine (228) may include processing resources (e.g., one or more processors) for executing such instructions. In this example, the machine-readable storage medium may store instructions that, when executed by the processing resources, implement the processing engine (228). In such an example, the system (210) may include a machine-readable storage medium that stores instructions and a processing resource that executes the instructions, or the machine-readable storage medium may be separate but accessible to the system (210) and the processing resources. In other examples, the processing engine (228) may be implemented by electronic circuitry.
[0056] In one embodiment, the processor 222 may receive a registration request from the UE 204 via the receiving engine 230. The registration request may include user subscription data.
[0057] In one embodiment, the processor (222), via the decision engine (232), may determine whether user subscription data is available within mobile wireless units in a particular geographic region.
[0058] In one embodiment, based on a positive determination, the processor (222) may provide the security mechanism to the UE (204) via the service provisioning engine (236).
[0059] In one embodiment, based on a negative determination, the processor 222 may send a data acquisition request to at least one data source, such as a UDM entity, via the data acquisition engine 234. The processor 222 may receive data associated with a particular geographic region from the at least one data source via the data acquisition engine 234. Additionally, the processor 222 may provide a security mechanism to the UE 204 based on the received data via the service provision engine 236.
[0060] Although Figure 2B illustrates exemplary components of system 210, in other embodiments, system 210 may include fewer components, different components, components in a different arrangement, or components with additional functionality than those depicted in Figure 2B. Additionally or alternatively, one or more components of system 210 may perform functions described as being performed by one or more other components of system 210.
[0061] FIG. 3 illustrates an example architecture (300) for implementing a coreless RAN security mechanism, according to one embodiment of the present disclosure.
[0062] Referring to Figure 3, the architecture 300 may include a 6g NodeB (6gNB) distribution unit (DU) 302a and a 6gNB radio unit (RU) 302b. The architecture 300 may support local authentication of the radio access network node itself. An entity called a LDM entity 306 or LDM function may be deployed in the radio access node. The LDM entity 306 may store user subscription data related to the geography of operation of the mobile radio unit (i.e., base station on a UAV).
[0063] An additional entity that emulates core network security functions may be referred to as a lightweight AMF entity or function (LW-AMF / AuSF) 308. The LW-AMF / AuSF 308 may be introduced in the RAN domain to perform functions such as registration requests, including authentication and security for UEs 204 or users 202 supported by the LDM 306.
[0064] In another embodiment, both the LDM entity (306) and the LW-AMF / AuSF entity (308) present in the RAN domain may be implemented as application functions within the Central Unit Control Plane (CU-CP) (304a, 304b) of the radio access node. The CU-CP (304a, 304b) may be connected to the 6gNB-DU (302a) and the 6gNB-RU (302b). The CU-CP (304a, 304b) may establish connections with the LW-AMF / AuSF (308) and the User Plane Function (UPF) (310).
[0065] In some embodiments, the architecture (300) may include a 6G core network associated with a UDM entity (312) and an AMF / AuSF entity (314) to receive user subscription data of interest.
[0066] FIG. 4 illustrates a sequential flow diagram (400) for updating an LDM entity with relevant user subscription information according to one embodiment of the present disclosure.
[0067] Referring to Figure 4, the user subscription data may be applicable to a "mobile radio unit or entity." In one embodiment, a mechanism may be provided whereby the LDM and LW-AMF check whether user subscription data is available within the mobile radio unit for a given geographical area of the mobile radio unit's mobility of operation. If not, the LDM / LW-AMF may query any entity that has complete user subscription data, such as a UDM entity in the core network or a Home Subscriber Server (HSS) entity, to download the user profile information of interest. This may be the first step before authorization and authentication is performed for the user equipment by the mobile radio entity.
[0068] The download of user subscription data from the UDM or HSS entity by the mobile radio unit may occur via a secure connection via satellite or any other available connection mechanism before the mobile radio unit begins its travel trajectory or during the flight / travel trajectory.
[0069] As shown, at 402, when the LW-AMF determines to operate in a particular geographic area, the LW-AMF may send a preparation request to the LDM. At 404, the LDM may verify available user profile data for the new operating area. The LDM may then send a preparation response to the LW-AMF. At 406, the LW-AMF may next determine to obtain subscription data from the UDM. To this end, the LW-AMF may send a subscription data request to the UDM. At 408, the UDM may prepare the requested data, based on the area / Global Positioning System (GPS) coordinates, via the subscription data response to the LW-AMF. At 410, the LW-AMF may send an update data request to the LDM so that the local database is updated and an update data response is sent to the LW-AMF. At 412, the LW-AMF may signal that the system 210 is ready to provide service in the new operating area.
[0070] FIG. 5 illustrates an exemplary architecture for implementing a coreless RAN security mechanism according to another embodiment of the present disclosure.
[0071] Referring to Figure 5, another variation of the architecture is proposed to support independent RAN security mechanisms, where the Central Unit - Control Plane (CU-CP) (506a) itself may decode Non-Access Stratum (NAS) messages and authenticate the user (202) with the Radio Access Node / Mobile Radio Unit entity itself, as an alternative to the LW-AMF entity described in Figure 3. The CU-CP (506a) may support NAS encoder and decoder functionality (504), so that NAS messages can be decoded within the CU-CP (506a) and relevant actions can be initiated for specific service types.
[0072] FIG. 6 illustrates a sequential flow diagram (600) for authentication of a UE (204) by an LDM according to one embodiment of the present disclosure.
[0073] 6, for all other service types during non-mobile mode, the CU-CP entity of the mobile unit may forward the NAS message to the 6GC for further processing. When the RAN entity is in flight / mobile mode where core network connectivity is not available, the CU-CP itself may act as a substitute core network by processing the NAS message.
[0074] With respect to the disclosed sequence flow, at 602, once a Radio Resource Control (RRC) connection is successfully established between the UE (204) and the 6GNB-CU, the UE (204) may send an RRC Setup Complete (Registration Request) to the 6GNB-CU. The 6GNB-CU may send an Initial UE message (Registration Request) to the LW-AMF. The LW-AMF may send a NAS ID Request to the UE (204) and subsequently receive a NAS ID Response from the UE (204). At 604, the LW-AMF may select an Authentication Server Function (AUSF) based on a Subscription Concealed Identifier (SUCI) and send a UE Authentication Acquisition Request to the LDM. At 606, the LDM may generate an authentication vector and send a UE Authentication Acquisition Response to the LW-AMF. At 608, the LW-AMF may derive NAS security keys and other security keys. Further, the LW-AMF may obtain a subscription permanent identifier (SUPI) and send a NAS authentication request (NGKSI, RAND, AUTH) to the UE (204). The UE (204) may then send a NAS authentication response (response to the AUTH challenge) to the LW-AMF. At 610, the LW-AMF may verify the response and confirm the authentication. The LW-AMF may select a security mechanism and send a security mode request (security algorithm, IMEISV request) to the UE (204). At 612, the UE may send a NAS security mode complete (IMEISV) message to the LW-AMF to complete the NAS security procedure.
[0075] In one embodiment, the RAN nodes and the core network are connected via satellite.
[0076] In yet another embodiment, connectivity between the RAN node and the core entity may be intermittent and short-lived, and therefore a signaling mechanism between the RAN node and the core entity can be described that allows the core network to download a predefined or "on-demand" set of subscriber information from the HSS to the LW-AMF and AuSF entities in the core network before the connectivity between the RAN node and the core network is terminated.
[0077] To facilitate local data caching, a Packet Gateway (PGW) cache may be provided in a separate RAN node that can establish a data path between the UE (204) and the RAN node. Data may then be collected from the RAN node. If the requested data path is for another UE in the vicinity of the call initiating device, inter-RAN node communication may be established.
[0078] FIG. 7 illustrates an exemplary computer system (700) that may utilize or be utilized in conjunction with embodiments of the present invention in accordance with embodiments of the present disclosure.
[0079] As shown in FIG. 7 , the computer system (700) may include an external storage device (710), a bus (720), a main memory (730), a read-only memory (740), a mass storage device (750), a communications port (760), and a processor (770). Those skilled in the art will appreciate that the computer system (700) may include multiple processors and communications ports. The processor (770) may include various modules associated with embodiments of the present invention. The communications port (760) may be an RS-232 port for use with a modem-based dial-up connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or any other existing or future port. The communications port (760) may be selected depending on the network, such as a local area network (LAN), a wide area network (WAN), or any network to which the computer system is connected. The memory (730) may be a random access memory (RAM) or other dynamic storage device commonly known in the art. The read-only memory (740) may be any static storage device, such as, but not limited to, a programmable read-only memory (PROM) chip for storing static information, such as boot-up instructions or BIOS instructions for the processor (770). The mass storage device (750) may be any current or future mass storage solution that can be used to store information and / or instructions.Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid state drives (internal or external, e.g., with Universal Serial Bus (USB) and / or Firewire interfaces), one or more optical disks, and RAID (Redundant Array of Independent Disks) storage, e.g., an array of disks.
[0080] The bus (720) communicatively couples the processor(s) (770) to other memory, storage, and communication blocks. The bus (720) may be, for example, a Peripheral Component Interconnect (PCI) / PCI-Extension (PCI-X) bus, a Small Computer System Interface (SCSI), a USB, or other bus for connecting expansion cards, drives, and other subsystems, or a Front Side Bus (FSB) that connects the processor(s) (770) to a software system.
[0081] Optionally, operator and administrator interfaces, such as a display, keyboard, joystick, and cursor control device, may also be coupled to bus 720 to support direct operator interaction with computer system 700. Other operator and administrator interfaces may be provided through a network connection connected via communications port 760. The components described above are intended only to illustrate various possibilities. In no way should the foregoing exemplary computer system 700 limit the scope of this disclosure.
[0082] Various embodiments of the present disclosure enable the system 210 to decouple access nodes of the RAN from the core network to enable independent authentication / authorization of UEs 204 that are part of the core network. This decoupling can support coreless RAN functionality, thereby better supporting mobile access systems such as UAV-based radio access nodes, which can be used in 6G network architectures as fundamental building blocks.
[0083] Moreover, in interpreting this specification, all terms should be interpreted in the broadest possible manner consistent with the context. In particular, the terms "comprises" and "comprising" should be interpreted as referring to elements, components, or steps in a non-exclusive manner, indicating that a referenced element, component, or step can be present, utilized, or combined with other elements, components, or steps not expressly referenced. When a claim in this specification refers to at least one element selected from the group consisting of A, B, C, ..., N, the text should be interpreted as requiring only one element from the group, and not A+N, B+N, etc.
[0084] While considerable emphasis has been placed herein on preferred embodiments, it will be understood that many embodiments can be made and that many changes can be made to the preferred embodiments without departing from the principles of the present disclosure. While these and other changes in the preferred embodiments of the present disclosure will be apparent to those skilled in the art from the disclosure herein, it is hereby expressly understood that the foregoing illustrative matter is intended merely as an illustration of the present disclosure, and not as a limitation thereof.
Claims
1. 1. A system (210) for providing a security mechanism to a user equipment (UE) (204) in a coreless radio access network (RAN), the system (210) comprising: a processor (222); a memory (224) operatively coupled to the processor (222), the memory (224) storing instructions that, when executed by the processor (222), cause the processor (222) to: receiving a registration request from a UE (204), the registration request including user subscription data; determining whether said user subscription data is available within mobile radio units in a particular geographic region; providing a security mechanism to the UE (204) based on a positive determination; sending a data retrieval request to at least one data source based on a negative determination; receiving data associated with the particular geographic region from the at least one data source; providing the security mechanism to the UE (204) based on the received data; a memory (224) for causing the A system (210) comprising:
2. 2. The system of claim 1, wherein the memory includes processor-executable instructions that, when executed, cause the processor to update a database based on the received data.
3. The system (210) of claim 1, wherein the registration request comprises one or more non-access stratum (NAS) messages.
4. The memory (224) includes processor-executable instructions that, when executed, cause the processor (222) to: Decrypting one or more NAS messages; authenticating the one or more NAS messages upon decryption; selecting a security mechanism based on the authentication; providing the security mechanism to the UE (204); to carry out The system (210) of claim 3.
5. A method for providing a security mechanism to a user equipment (UE) (204) in a coreless radio access network (RAN), comprising: receiving, by a processor (222) associated with the system (210), a registration request from the UE (204), the registration request including user subscription data; determining, by said processor (222), whether said user subscription data is available within mobile radio units in a particular geographic region; providing, by the processor (222), a security mechanism for the UE (204) based on a positive determination; sending, by the processor (222) a data retrieval request to at least one data source based on a negative determination; receiving, by the processor (222), data associated with the particular geographic region from the at least one data source; providing, by the processor (222), the security mechanism to the UE (204) based on the received data; A method comprising:
6. The method of claim 5, further comprising updating, by the processor, a database based on the received data.
7. The method of claim 5 , wherein the registration request comprises one or more Non-Access Stratum (NAS) messages.
8. Decoding, by the processor (222), the one or more NAS messages; authenticating, by the processor (222), the one or more NAS messages upon decryption; selecting, by the processor (222), a security mechanism based on the authentication; providing, by the processor (222), the security mechanism to the UE (204); The method of claim 7, comprising:
9. A user equipment (UE) (204), a processor; a memory operatively coupled to the processor, the memory including processor-executable instructions, the processor-executable instructions, when executed, causing the processor to: sending a registration request to the system (210); Memory and Equipped with The processor is communicatively coupled to the system (210), the system (210) comprising: receiving the registration request from the UE (204), the registration request including user subscription data; determining whether said user subscription data is available within mobile radio units in a particular geographic region; providing a security mechanism to the UE (204) based on a positive determination; sending a data retrieval request to at least one data source based on a negative determination; receiving data associated with the particular geographic region from the at least one data source; providing the security mechanism to the UE (204) based on the received data; configured to: User Equipment (UE) (204).
10. A non-transitory computer-readable medium containing processor-executable instructions, the processor-executable instructions causing a processor to: receiving a registration request from a UE (204), the registration request including user subscription data; determining whether said user subscription data is available within mobile radio units in a particular geographic region; providing a security mechanism to the UE (204) based on a positive determination; sending a data retrieval request to at least one data source based on a negative determination; receiving data associated with the particular geographic region from the at least one data source; providing the security mechanism to the UE (204) based on the received data; to carry out Non-transitory computer-readable medium.
Citation Information
Patent Citations
Addressing failures that do not allow non-3GPP access to 5GCN
JP2021530896A
Detecting malicious small cells based on a connectivity schedule and cached entity profiles at network access nodes to re-authenticate network entities
WO2022026143A1