Establishing a secure connection
By implementing AKMA-based pre-shared key generation and TLS 1.3 with PSK authentication, the 5G system architecture establishes secure connections between UE and AFs, addressing the lack of universal AKMA support and enhancing network security and service access reliability.
Patent Information
- Application Number
- JP2023520287
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-10-02
- Filing Date
- 2021-08-18
- Publication Date
- 2025-07-16
- Estimated Expiration
- 2041-08-18
AI Technical Summary
The existing 5G system architecture lacks a robust mechanism for establishing secure connections between user equipment (UE) and application functions (AF) using the Authentication and Key Management for Applications (AKMA) procedure, as not all AFs support this protocol, leading to potential security vulnerabilities and service access issues.
A method is introduced to dynamically generate a pre-shared key (K AF) using the AKMA procedure, ensuring both the UE and the AF support AKMA capabilities, and utilize Transport Layer Security (TLS) 1.3 with Pre-Shared Key (PSK) authentication to establish a secure connection, leveraging the 5G system architecture's existing authentication procedures.
This approach ensures secure and reliable communication services by verifying UE and AF capabilities, enabling secure connections and service access while adhering to 5G system architecture standards, thus enhancing network security and service availability.
Smart Images

Figure 0007709520000001 
Figure 0007709520000002 
Figure 0007709520000003
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to communications, and more particularly to communication methods and related devices and nodes that support wireless communications.
Background Art
[0002] In 3GPP TR 23.752, SA2 is developing an architecture option called the "user plane-based architecture". This architecture proposes to adopt the functions for the proximity service (ProSe) function defined in TS 23.303 into the 5G system architecture. According to 3GPP TS 23.303, the direct discovery naming management function (DDNMF) and the direct provisioning function (DPF) of the ProSe function are necessary to support ProSe in the 5G system architecture. The DPF is used to provision the necessary parameters to the UE for using 5G ProSe direct discovery and 5G ProSe direct communication, which can be replaced by the policy control function (PCF). The DDNMF is used to provide the following procedures on the PC3 interface. - A discovery request / response procedure for providing an ID and a filter for direct discovery. - A match report procedure for confirming direct discovery and providing mapping information for direct discovery. - An alert notification procedure for supporting "on-demand" ProSe direct discovery in the case of the ProSe restricted discovery model A. - A discovery update procedure for updating / canceling the previously assigned ID and filter.
[0003] 5GS supports a service-based architecture, and the DDNMF can not only interact with 5G NFs (e.g., to consume Nudm service operations), but can also connect to the UE via user plane connectivity to support procedures on the PC3 interface and can be a network function (NF). In the architecture, as shown in Figure 1, it is proposed to introduce 5G DDNMF. The 5G DDNMF illustrated in Figure 1 is managed by a mobile network operator (MNO). 5G DDNMF can consume service operations from other NFs in 5GC (e.g., Nudm or Npcf).
[0004] The PC3 interface supports discovery request / response, match report procedure, alert notification procedure, and discovery update procedure as the following basic functions defined in 3GPP TS 23.303. Which network slice selection assistance information (NSSAI) or data network name (DNN) should be used for the user plane connectivity for the PC3 interface depends on the MNO's configuration (e.g., it can be controlled by the UE route selection policy (URSP) or local configuration in the UE). The authentication and key management for applications (AKMA) function is defined in 3GPP TS 33.535.
[0005] Figure 2 illustrates the network model of AKMA and the interfaces between them. There is no separate authentication of the UE to support the AKMA function. Instead, it reuses, for example, the 5G primary authentication procedure performed during UE registration to authenticate the UE. Successful 5G primary authentication results in K AUSF being stored in the authentication server function (AUSF) and the UE.
[0006] During the first authentication procedure, the AUSF interacts with the Unified Data Management (UDM) to fetch authentication information such as subscription credentials (e.g., AKA authentication vectors) and authentication methods using the Nudm_UEAuthentication_Get request service operation. In the response, the UDM may also indicate to the AUSF whether an AKMA key needs to be generated for the UE. If the AUSF receives an AKMA instruction from the UDM, after the first authentication procedure is successfully completed, the AUSF stores K AUSF and generates the AKMA anchor key (K AUSF ) and the AKMA key identifier (A-KID) from K AKMA . After the AKMA key material is generated, the AUSF sends the A-KID and K AKMA generated for the AKMA anchor function (AAnF) together with the UE Subscriber Permanent Identifier (SUPI) to the AAnF using the Naanf_AKMA_KeyRegistration request service operation as shown in Figure 2. The AAnF stores the latest information sent by the AUSF.
[0007] Before starting communication with the AKMA application function, the UE generates the AKMA anchor key (K AUSF ) and the A-KID from K AKMA . The A-KID identifies the UE's K AKMA key from which other AKMA keys are derived. The A-KID is in the network access identifier (NAI) format specified in Section 2.2 of IETF RFC 7542, i.e., of the form username@realm. The username part includes the routing identifier and the A-TID (AKMA temporary UE identifier), and the realm part includes the home network identifier.
[0008] The A-TID is derived from K AUSF as defined in Annex A.3. The key derivation of K AKMA is performed using the key derivation function (KDF) specified in TS 33.220 [5]. K AKMA is K AKMA=KDF(K AUSF 、 "AKMA", SUPI) as (in Attachment A, in two ways), where the key derivation parameter consists of the static string "AKMA" and SUPI. The AKMA key is based on K from the first authentication operation AUSF , so the AKMA key can only be refreshed by operating a fresh first authentication. Figure 3 illustrates the procedure used by the Application Function (AF) to directly request the Application Function Specific AKMA key from the 5G Core (5GC) when the AF is located in the operator's network.
[0009] Figure 3 illustrates that after the first authentication is performed, the UE generates AUSF from the K key and generates an A-KID. The UE requests the AF to establish a secure connection with the UE. The UE includes the A-KID for the AF in the application establishment request message to the AF. The AF contacts the AAnF using the A-KID and the AF ID. The AAnF generates the KAF key from the AF key using the AF ID as input. The AAnF provides the AUSF key to the AF along with the expiration time. AF
[0010] In ProSe in the 4G system, the PC3 interface was protected by establishing a shared key between the UE and the ProSe function through the use of the GBA (Generic Bootstrapping Architecture) procedure in the evolved packet system (EPS) system. GBA is defined in TS 33.220 [5]. In ProSe in the 5G system, one option could be to generate a shared key (K AF ) by using the AKMA procedure. However, the current solution assumes that the AF providing the ProSe service supports the AKMA procedure and the UE is permitted to utilize the AKMA procedure, but this may not always be the case.
Summary of the Invention
[0011] In some embodiments, the method is performed by a control network node to establish a secure connection in a wireless communication network. The method comprises receiving a request to use a communication service provided by the wireless communication network, the request including an indication that the communication device is capable of supporting the requested communication service and an AKMA service provided by the wireless communication network, determining whether the requested communication service and AKMA service can be provided to the communication device, and communicating to the communication device information indicating whether the requested communication service and AKMA service can be provided to the communication device to establish a secure connection in the wireless communication network.
[0012] In some embodiments, the method is performed by a communication device to establish a secure connection in a wireless communication network. The method comprises communicating a request to use a communication service provided by the wireless communication network, the request including an indication that the communication device is capable of supporting the requested communication service and an AKMA service provided by the wireless communication network, and receiving, in response to communicating the request, a communication comprising information indicating whether the requested communication service and AKMA service can be provided to the communication device to establish a secure connection in the wireless communication network.
[0013] In some embodiments, a network node implements a method for establishing a secure connection in a wireless communication network. The method includes the network node receiving, from a core network node, a request for AKMA service availability information indicating whether the network node can provide an AKMA service to establish a secure connection for a requested communication service between a communication device operating in the wireless communication network and the network node, and the network node communicating, to the core network node, AKMA service availability information indicating whether the network node can provide an AKMA service to establish a secure connection for the requested communication service.
[0014] Included to provide a further understanding of the present disclosure, incorporated in and constituting a part of this application, the accompanying drawings illustrate some non-limiting embodiments of the inventive concept.
Brief Description of the Drawings
[0015]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9A
Figure 9B
Figure 9C
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
[0016] Next, the inventive concept will be described in more detail below with reference to the accompanying drawings that show examples of embodiments of the inventive concept. However, the inventive concept may be embodied in many different forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the scope of the inventive concept to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment may be implicitly assumed to be present / used in another embodiment.
[0017] The following description presents various embodiments of the disclosed subject matter. These embodiments are presented as illustrative examples and should not be construed as limiting the scope of the disclosed subject matter. For example, some details of the described embodiments may be modified, omitted, or extended without departing from the scope of the described subject matter.
[0018] FIG. 5 is a block diagram illustrating elements of a communication device UE300 (also referred to as a mobile terminal, mobile communication terminal, wireless device, wireless communication device, wireless terminal, mobile device, wireless communication terminal, user equipment (UE), user equipment node / terminal / device, etc.) configured to provide wireless communication according to the claims of the inventive concept. (The communication device 300 may be provided, for example, as discussed below with respect to the wireless device 4110 of FIG. 18.) As shown, the communication device UE includes an antenna 307 (corresponding to, for example, the antenna 4111 of FIG. 18) and a transmitter and receiver configured to provide uplink wireless communication and downlink wireless communication with a base station of a wireless access network (corresponding to, for example, the network node 4160 of FIG. 18, also referred to as a RAN node), a wireless transceiver circuit 301 (also referred to as a transceiver corresponding to, for example, the interface 4114 of FIG. 18). The communication device UE may also include a processing circuit 303 (also referred to as a processor corresponding to, for example, the processing circuit 4120 of FIG. 18) coupled to the transceiver circuit and a memory circuit 305 (also referred to as a memory corresponding to, for example, the device-readable medium 4130 of FIG. 18) coupled to the processing circuit. The memory circuit 305 may include computer-readable program code that, when executed by the processing circuit 303, causes the processing circuit to perform operations according to the claims disclosed herein. According to other embodiments, the processing circuit 303 may be defined to include memory such that a separate memory circuit is not required. The communication device UE may also include an interface (such as a user interface) coupled to the processing circuit 303, and / or the communication device UE may be incorporated into a vehicle.
[0019] As discussed herein, the operations of the communication device UE may be performed by the processing circuitry 303 and / or the transceiver circuitry 301. For example, the processing circuitry 303 may control the transceiver circuitry 301 to transmit communications over the radio interface to a radio access network node (also called a base station) through the transceiver circuitry 301 and / or to receive communications from the RAN node over the radio interface through the transceiver circuitry 301. Moreover, modules may be stored in the memory circuitry 305, and these modules may provide instructions such that when the instructions of the modules are executed by the processing circuitry 303, the processing circuitry 303 performs respective operations (e.g., the operations discussed below with respect to an exemplary embodiment related to a wireless communication device).
[0020] FIG. 6 is a block diagram illustrating elements of a radio access network (RAN) node 400 of a radio access network (RAN) configured to provide cellular communications (also referred to as a network node, base station, eNodeB / eNB, gNodeB / gNB, etc.). (RAN node 400 can be provided, for example, as discussed below with respect to network node 4160 of FIG. 18.) As shown, the RAN node can include a radio transceiver circuit 401 (also referred to as a transceiver) configured to provide uplink and downlink radio communications with a mobile terminal (for example, corresponding to the portion of interface 4190 of FIG. 18). The RAN node can include a network interface circuit 407 (also referred to as a network interface) configured to provide communications with other nodes of the RAN and / or core network CN (for example, with other base stations). The network node can also include a processing circuit 403 (also referred to as a processor) coupled to the transceiver circuit (for example, corresponding to processing circuit 4170) and a memory circuit 405 (also referred to as a memory) coupled to the processing circuit. The memory circuit 405 can include computer-readable program code that, when executed by the processing circuit 403, causes the processing circuit to perform operations according to the claims disclosed herein. According to other embodiments, the processing circuit 403 can be defined to include memory such that a separate memory circuit is not required.
[0021] As discussed herein, the operation of the RAN node may be implemented by the processing circuit 403, the network interface 407, and / or the transceiver 401. For example, the processing circuit 403 may control the transceiver 401 to transmit downlink communication to one or more mobile terminals UE over the wireless interface through the transceiver 401, and / or to receive uplink communication from one or more mobile terminals UE over the wireless interface through the transceiver 401. Similarly, the processing circuit 403 may control the network interface 407 to transmit communication to one or more other network nodes through the network interface 407, and / or to receive communication from one or more other network nodes through the network interface. Additionally, modules may be stored in the memory 405, and these modules may provide instructions such that when the instructions of the modules are executed by the processing circuit 403, the processing circuit 403 performs respective operations (e.g., the operations discussed below with respect to exemplary embodiments related to the RAN node).
[0022] According to some other embodiments, the network node may be implemented as a core network CN node without a radio transceiver. In such embodiments, the transmission to the wireless communication device UE may be initiated by the network node such that the transmission to the wireless communication device UE is provided through a network node including a radio transceiver (e.g., through a base station or a RAN node). According to the claims where the network node is a RAN node including a transceiver, initiating the transmission may include transmitting through the transceiver.
[0023] FIG. 7 is a block diagram illustrating elements of a core network CN node (e.g., an SMF node, an AMF node, a PCF node, etc.) of a communication network configured to provide cellular communication according to the claims of the inventive concept. As shown, the CN node may include a network interface circuit 507 (also referred to as a network interface) configured to provide communication with other nodes of the core network and / or the radio access network RAN. The CN node may also include a processing circuit 503 (also referred to as a processor) coupled to the network interface circuit and a memory circuit 505 (also referred to as a memory) coupled to the processing circuit. The memory circuit 505 may include computer-readable program code that, when executed by the processing circuit 503, causes the processing circuit to perform operations according to the claims disclosed herein. According to other embodiments, the processing circuit 503 may be defined to include memory such that a separate memory circuit is not required.
[0024] As discussed herein, the operations of the CN node may be performed by the processing circuit 503 and / or the network interface circuit 507. For example, the processing circuit 503 may control the network interface circuit 507 to transmit communications through the network interface circuit 507 to one or more other network nodes and / or receive communications through the network interface circuit from one or more other network nodes. Additionally, modules may be stored in the memory 505, and these modules may provide instructions such that when the instructions of the modules are executed by the processing circuit 503, the processing circuit 503 performs respective operations (e.g., the operations discussed below with respect to exemplary embodiments related to core network nodes).
[0025] The methods and devices described herein are such that the AKMA procedure dynamically generates a new pre-shared key (K AF) is based on the understanding that it is used to establish. This implies that the 3GPP network and the AF need to support AKMA. The AF needs to support the connection to the AAnF in the AKMA described in TS 33.535 [6]. It should be understood that the methods and devices described herein can be mapped to any Application Function (AF) used for any service. As an example of how the service helps the Policy Control Function (PCF) determine which AF the UE needs to contact, the ProSe service is used throughout this disclosure.
[0026] This disclosure assumes that TLS v1.3 with Pre-Shared Key (PSK) authentication defined in RFC 8446 is used to set up a secure connection between the UE and the AF. The UE needs to include the A-KID (K AKMA key identifier) in the client hello message to the AF and needs to include a hint that the UE supports and wishes to use AKMA by including the "3GPP-akma" hint. The AF can be any application function that supports TLS v1.3 with PSK authentication. In the ProSe service, the AF can be mapped to any application function used for the ProSe service. For example, the 5G DDNMF and PC3 interfaces defined in TS 23.502
[88] , or the new key management function used by the ProSe service in 5G. Another option can be for using IPsec with PSK authentication in IKEv2 in RFC 5996.
[0027] The UE and the network can perform secure negotiation to use the AKMA procedure to establish a pre-shared key in the UE and the AF (Application Function). A secure connection can be established between the UE and the AF using the pre-shared key established from the AKMA procedure. The UE and the network need to securely negotiate that the AKMA procedure is used. This implies the following. - The home PLMN has AKMA capabilities. - The UE has AKMA capabilities. - The AF has AKMA capabilities and an interface to the AAnF.
[0028] The UE includes its UE capabilities for supporting the AKMA procedure in the registration request message. Whether the UE is allowed to use the AKMA service and whether the UE is allowed to use the ProSe service are set in the subscription in the UDM. The capabilities of the AF that supports AKMA can be as follows. a) Provisioned to the PCF, or b) The PCF can query the AF about the capabilities of the AF for supporting AKMA.
[0029] Figure 8 illustrates the PCF requesting AKMA capability support. In case a), this step is performed before the UE accesses the 3GPP network and can indicate its capabilities for supporting AKMA. In case b), this step is performed when the UE is accessing the 3GPP core network and can indicate its capabilities for supporting AKMA. When the PCF queries the AF, it includes the capabilities of the UE for supporting AKMA.
[0030] When the UE wishes to use the ProSe service, the UE sends a UE policy provisioning request to the 3GPP network, as shown in Figure 9A, provides its UE capabilities for supporting both the ProSe service and the AKMA service to the 3GPP network, and provides a request for using the ProSe service. If the UE subscription enables the UE to use AKMA, and the 3GPP network supports the AKMA procedure and the AF supports AKMA, the PCF in the network provides the AF address to the UE. If the AF does not support AKMA, the PCF still indicates the AF address along with an instruction to the UE not to use AKMA with this AF.
[0031] The PCF decision to provide the AF address to the UE can be combined with additional UE capabilities included by the UE to the network for supporting a particular service, e.g., the proximity service (ProSe). This UE capability for ProSe support helps the PCF determine which AF the UE needs to access to support the requested service. For example, if the UE requests the ProSe service and indicates the UE's capabilities for using the ProSe service, the AF can be mapped to the 5GDDNMF in ProSe, which can perform key management for ProServices, or any other ProSe function in the network. Note that the use of 5GDDNMF assumes that 5GDDNMF is a separate entity and not a function of the PCF.
[0032] This solution proposes to use Transport Layer Security (TLS) 1.3 with Pre-Shared Key (PSK) authentication as a security mechanism to establish a secure connection between the UE and the AF, as described in RFC 8446
[10] . The following signaling flow describes the establishment of TLS 1.3 with PSK authentication. The PSK authentication can be combined with Diffie-Hellman key exchange (pk_dhe_ke) or without Diffie-Hellman (psk_ke). The TLS client and server may use an interface (draft-ietf-tls-external-psk-importer) to import external PSK identification information into TLS 1.3. The UE sends a ClientHello, where the ClientHello includes a pre_shared_key extension containing PSK identification information formatted from the A-KID, a psk_key_exchange_modes extension indicating, for example, psk_dhe_ke, and a "3GPP-akma" hint.
[0033] There is no separate authentication of the UE to support the AKMA function as described in TS 33.535 [6]. Instead, it re-uses, for example, the 5G primary authentication procedure performed during UE registration to authenticate the UE. Successful 5G primary authentication results in K AUSF being stored at the AUSF and the UE. The AUSF generates K AUSF from K AKMA and generates an A-KID mapped to the newly generated K AKMA and pushes K AKMA and the A-KID to the AAnF. According to some embodiments, whether the UE is allowed to use the AKMA service is set in the subscription at the UDM. Whether the UE is allowed to use the ProSe service is set in the subscription at the UDM. In some embodiments, the capabilities of the AF that support AKMA are provisioned to the PCF.
[0034] It is assumed that the 3GPP core network authenticates the UE by starting the primary authentication either before step 1(a) or after step 1(a) as illustrated in Figure 9A. In step 1(a), when the UE 902 wishes to use the ProSe service, the UE 902 sends a request to use the ProSe service and a UE policy provisioning request to the 3GPP network, and provides its UE capabilities to support both the ProSe service and the AKMA service to the 3GPP network. In step 1(b) illustrated in Figure 9A, the AMF 906 sends an Npcf_UEpolicycontrol_update request on the service-based interface to discover the corresponding PCF 900 and sends a request for the AF 904 address required for the ProSe service. The AMF 906 forwards the UE 902 request to use the ProSe service and the UE capabilities to support both the ProSe service and the AKMA service to the PCF 900.
[0035] Figure 9A also illustrates that in step 1(c), the PCF 900 checks with the UDM 908 whether the UE 902 is allowed to use AKMA. The PCF 900 contacts the UDM using the subscription concealment identifier (SUCI) or 5G global unique temporary identifier (5G-GUTI) to the UDM 908 in the Nudm_UEAuthentication_request, and the UE's capabilities to support both ProSe services and AKMA services. The UDM 908 maintains an indicator in the UE subscription as to whether the UE 902 is allowed to use AKMA. In other words, the UE 902 may support AKMA, but the UE 902 may not be allowed to use AKMA. The UDM 908 maintains an indicator in the UE subscription as to whether the UE 902 is allowed to use ProSe services. In other words, the UE 902 may support ProSe services, but the UE 902 may not be allowed to use ProSe services.
[0036] Figure 9A also illustrates that in step 1(d), UDM908 responds in Nudm_UEAuthentication_response with the SUPI, whether UE902 is allowed to use the AKMA service, and whether UE902 is allowed to use the ProSe service. Step 1(e) in Figure 9B is an optional step where PCF900 contacts AF904 that supports the ProSe service and asks whether AF904 supports AKMA, together with the UE capabilities for supporting AKMA. This step 1(e) is not required if the PCF has provisioned the capabilities of the AF for supporting the AKMA service. Step 1(f) in Figure 9B is an optional step where AF904 that supports the ProSe service responds to PCF900 whether AF904 supports AKMA, which is based on the AKMA capabilities of the AF and whether UE902 supports AKMA. Next, PCF900 can determine whether UE902 is allowed to use AKMA according to the Public Land Mobile Network (PLMN) policy using AF904 for the ProSe service.
[0037] UE 902 is enabled to use the AKMA service and the ProSe service. When the AF 904 for the ProSe service supports AKMA, FIG. 9B illustrates a first option, step 1(g)-option 1, in which the PCF 900 returns the AF address of the AF 904 that supports the ProSe service to the UE 902, along with an indication that the UE 902 is enabled to use AKMA using the AF 904 for the ProSe service. When the UE 902 is not enabled to use the AKMA service, but the UE 902 is enabled to use the ProSe service, and the AF 904 for the ProSe service supports AKMA, FIG. 9B illustrates a second option, step 1(g)-option 2, in which the PCF 900 does not provide the AF 904 address to the UE 902. In another embodiment, when the UE 902 is enabled to use the AKMA service and the UE 902 is enabled to use the ProSe service, but the AF 904 for the ProSe service does not support AKMA, the PCF 900 returns the AF address of the AF 904 that supports the ProSe service to the UE 902, along with an indication that the UE 902 is not enabled to use AKMA using the AF 904 for the ProSe service.
[0038] Steps 2(a) to 2(c) illustrated in FIG. 9B are part of the AKMA procedure in TS 33.535 [6]. FIG. 9B illustrates that the AUSF 912 generates K AUSF from K AKMA and generates an A-KID. As illustrated in steps 2(b) to 2(c) illustrated in FIG. 9B, the AUSF 912 pushes the K AKMA key and the A-KID to the AAnF 914. Step 3 illustrated in FIG. 9C is an optional step in which the UE 902 generates K AUSF from K AKMA and generates an A-KID. The UE 902 generates K AKMA from K AFGenerate. In some embodiments, this step can also be performed in step 4(e) after the UE 902 receives the server hello message. FIG. 9C illustrates that the UE 902 initiates TLS 1.3 with PSK authentication using the AF server 904 using the address to the AF 904 in step 4.
[0039] Step 4(a) in FIG. 9C shows that the UE 902 sends a client hello, where the ClientHello includes a psk_key_exchange_modes extension indicating, for example, psk_dhe_ke, a pre_shared_key extension including PSK identification information formatted from the A-KID, and a 3GPP-akma hint. For example, when an interface such as draft-ietf-tls-external-psk-importer is used to import an external PSK into TLS 1.3, the PSK identification information in the pre_shared_key extension is the imported identification information. The ClientHello may also include other extensions. The following steps in FIG. 9C are part of the AKMA procedure defined in TS33.535 [6]. 4(b). The AF server 904 contacts the AAnF 914 using the A-KID. 4(c). The AAnF 914 uses the A-KID to search for the K AKMA key and generates the K AKMA key from the K AF key. 4(d). The AAnF server 914 responds to the AF with the K AF key and the expiration time for the K AF key. 4(e). The AF server 914 responds with a server hello with a pre_shared_key extension indicating the selected PSK identification information. The server hello may include other extensions. Along with the server hello, the server sends other handshake messages such as, for example, EncryptedExtensions and Finished. Optional step: The UE 902 derives the K AUSF from the KAKMA Generate it and generate A-KID. The UE generates K AKMA from K AF Generate it. This step may be performed in step 3 as the first option. 4(f). UE902 responds with a Finished message. 5. UE902 and the AF server 904 can exchange data over a secure link.
[0040] Next, with reference to the flowcharts of FIGS. 11-13, according to some embodiments of the present disclosure, the operation of the core network CN node 500 (implemented using the structure of FIG. 7) will be discussed. It should be understood that the PCF 900 described above may include the CN node 500 according to some embodiments described herein. For example, the modules may be stored in the memory 505 of FIG. 7, and these modules may provide instructions such that when the module instructions are executed by their respective CN node processing circuits 503, the processing circuit 503 performs the respective operations of the flowchart.
[0041] Figure 10 illustrates a method for establishing a secure connection in a wireless communication network according to the claims of the present disclosure. In this embodiment, the method is performed by a control network node of the wireless communication network. Figure 10 illustrates that the method includes receiving 1000 a request to use a communication service provided by the wireless communication network. In some embodiments, the request includes an indication that the communication device is capable of supporting the requested communication service and an authentication and key management (AKMA) service for applications provided by the wireless communication network. Figure 10 also illustrates that the method includes determining 1002 whether the requested communication service and AKMA service can be provided to the communication device. The method also includes communicating 1004 to the communication device information indicating whether the requested communication service and AKMA service can be provided to the communication device to establish a secure connection in the wireless communication network.
[0042] In some embodiments, the control network node comprises a policy control function (PCF) network node of a wireless communication network, such as the PCF900 described above with respect to FIGS. 8 and 9A-9C. In some embodiments, the requested communication service is provided by an application function (AF) of the wireless communication network. For example, the AF904 described above with respect to FIGS. 8 and 9A-9C. The requested communication service comprises, in some embodiments, a proximity service (ProSe) provided by the AF. In some embodiments, the method comprises the communication device obtaining information indicating whether it is permitted to utilize the AKMA service. For example, FIGS. 9A-9C illustrate the PCF900 (such as) obtaining information indicating whether the communication device 902 is permitted to utilize the AKMA service in steps 1c-1d of FIG. 9A. In some embodiments, the method comprises the AF obtaining AKMA service availability information indicating whether it can provide the AKMA service. For example, FIGS. 8 and 9A-9C illustrate the PCF (such as the PCF900) obtaining AKMA service availability information indicating whether the AF can provide the AKMA service in steps 1e-1f of FIG. 9B.
[0043] According to some embodiments, the method includes 1100 determining that the AF can provide the AKMA service based on the AKMA service availability information, as illustrated in FIG. 11. In this embodiment, the method also includes 1102 determining that the communication device is permitted to use the AKMA service based on information indicating whether the communication device is permitted to use the AKMA service. In this embodiment, the method further includes 1104 communicating to the communication device information indicating that the communication device is permitted to use the AKMA service using the AF to establish a secure connection to receive the requested communication service. In this embodiment, the information includes an address associated with the AF that can provide the AKMA service and the requested communication service. For example, FIG. 9B illustrates that the PCF 900 communicates information indicating that the UE 902 is permitted to use the AKMA service using the AF 904 and that the AF supports the AKMA service, and the address of the AF 904, in steps 1g and 1g-option 1 of FIG. 9B.
[0044] FIG. 12 illustrates that, according to an embodiment, the method includes (1200) determining that the AF cannot provide the AKMA service based on the AKMA service availability information. FIG. 12 also illustrates that, in this embodiment, the method includes (1202) determining that the communication device is permitted to use the AKMA service based on information indicating whether the communication device is permitted to use the AKMA service. FIG. 12 further illustrates that, in this embodiment, the method further includes communicating (1204) to the communication device information indicating that the communication device cannot use the AKMA service using the AF (904) to establish a secure connection to receive the requested communication service. In this embodiment, the information includes an address associated with the AF that can provide the AKMA service and the requested communication service. For example, FIG. 9B illustrates that the PCF 900 communicates, in steps 1g and 1g - option 1 of FIG. 9B, information indicating that the UE 902 is not permitted to use the AKMA service using the AF 904 and that the AF does not support the AKMA service, and the address of the AF 904.
[0045] FIG. 13 illustrates that the method, according to an embodiment, includes 1300 determining that the AF can provide the AKMA service based on the AKMA service availability information. FIG. 13 also illustrates that in this embodiment, the method includes 1302 determining that the communication device is not permitted to use the AKMA service based on information indicating whether the communication device is permitted to use the AKMA service. FIG. 13 also illustrates that according to this embodiment, the method includes 1304 determining that the requested communication service and the AKMA service cannot be provided to the communication device based on information indicating that the communication device is not permitted to use the AKMA service and information indicating that the AF providing the requested communication service supports the AKMA service. FIG. 13 further illustrates that the method includes 1306 communicating to the communication device information indicating that the requested communication service and the AKMA service cannot be provided to the communication device. In this embodiment, the information does not include the address of the AF that can provide the requested communication service. For example, FIG. 9B illustrates that the PCF 900 communicates information indicating that the requested communication service and the AKMA service cannot be provided in steps 1g and 1g-option 2 of FIG. 9B.
[0046] Next, with reference to the flowcharts of FIGS. 14-15, according to some embodiments of the inventive concept, the operation of the communication device 300 (implemented using the block diagram structure of FIG. 5) is discussed. For example, modules may be stored in the memory 305 of FIG. 5, and these modules may provide instructions such that when the instructions of the modules are executed by their respective communication device processing circuits 303, the processing circuit 303 performs the respective operations of the flowchart.
[0047] The various operations from the flowchart of FIG. 14 may be optional with respect to some embodiments of the communication device and related methods. For example, with respect to the method of an exemplary embodiment of establishing a secure connection (described below), the operation of block 1404 in FIG. 14 may be optional.
[0048] FIG. 14 illustrates a method for establishing a secure connection in a wireless communication network according to some embodiments of the present disclosure. In this embodiment, the method is implemented by a communication device operating in a wireless communication network. FIG. 14 illustrates that the method includes communicating 1400 a request to use a communication service provided by the wireless communication network. In some embodiments, the method includes communicating the request towards a policy control function (PCF) network node of the wireless communication network. For example, FIG. 9A illustrates an exemplary UE902 communicating a request towards a PCF900 in step 1a of FIG. 9A.
[0049] FIG. 14 also illustrates that the method includes receiving 1402 a communication comprising information indicating whether the requested communication service and AKMA service can be provided to the communication device to establish a secure connection in the wireless communication network in response to communicating the request. In some embodiments, the method includes receiving the information from a PCF network node. For example, FIG. 9B illustrates an exemplary UE902 receiving information from a PCF900 in step 1g (options 1 and 2) of FIG. 9B. In some embodiments, the requested communication service is provided by an application function (AF) of the wireless communication network. The requested communication service comprises, in some embodiments, a proximity service (ProSe) provided by the AF.
[0050] Returning to FIG. 14, the method, according to some embodiments, indicates that the address of the AF included in the communication, the requested communication service, and the AKMA service can be provided to the communication device based on the information for establishing a secure connection in the wireless communication network. To use the requested communication service from the AF, it includes establishing a secure connection with the AF using the AKMA service at 1404. In some embodiments, FIG. 15 illustrates that the method includes generating pre-shared key (PSK) identification information based on the AKMA key identifier (A-KID) associated with the AKMA service at 1500. FIG. 15 also illustrates that the method includes communicating a message comprising a pre-shared key (PSK) extension including the PSK identification information, the A-KID, and the AKMA hint towards the AF at 1502. The AKMA hint indicates to the AF that the communication device supports the AKMA service and desires to use the AKMA service to establish a secure connection.
[0051] FIG. 15 also illustrates that the method includes receiving a communication comprising the PSK identification information for the secure connection from the AF at 1504. The method, according to some embodiments, further includes establishing a secure connection with the AF based on the PSK identification information at 1506. For example, FIG. 9C illustrates that the exemplary UE 902 establishes a secure connection with the AF 904 based on the PSK identification information in steps 3-5 of FIG. 9C. Alternatively, in some other embodiments, the method includes establishing a secure connection with the AF to receive the requested communication service from the AF based on the address of the AF included in the communication and the information indicating that the requested communication service can be provided to the communication device without using the AKMA service to establish a secure connection in the wireless communication network.
[0052] Next, with reference to the flowcharts of FIGS. 16-17, according to some embodiments of the present disclosure, the operation of a network node (implemented using the structure of FIG. 7) will be discussed. It should be understood that the AF904 described above may include a network node, or a core network node such as the CN node 500, according to some embodiments described herein. For example, modules may be stored in the memory 505 of FIG. 7, and these modules may provide instructions such that when the instructions of the modules are executed by their respective CN node processing circuits 503, the processing circuits 503 perform the respective operations of the flowchart.
[0053] FIG. 16 illustrates a method for establishing a secure connection in a wireless communication network according to some embodiments. The method is implemented by a network node of the wireless communication network. FIG. 16 illustrates that the method includes receiving 1600 at the network node a request for AKMA service availability information indicating whether the network node can provide an AKMA service to establish a secure connection for a requested communication service between a communication device operating in the wireless communication network and the network node. In some embodiments, the network node includes an application function (AF) of the wireless communication network configured to provide the requested communication service. The core network node includes, according to some embodiments, a policy control function (PCF) network node of the wireless communication network. In some embodiments, the requested communication service includes a proximity service (ProSe) provided by the AF.
[0054] FIG. 16 also illustrates that the method further includes communicating 1602 to the core network node AKMA service availability information indicating whether the network node can provide an AKMA service to establish a secure connection for the requested communication service. For example, FIG. 9B illustrates that exemplary AF 904 communicates service availability information indicating whether the network node can provide an AKMA service in steps 1e-1f of FIG. 9B. In some embodiments, the AKMA service availability information indicates that the network node can provide an AKMA service.
[0055] FIG. 17 illustrates that the method, according to some embodiments, includes receiving 1700 from a communication device a message comprising a pre-shared key (PSK) extension, an A-KID, and an AKMA hint based on an AKMA key identifier (A-KID) associated with the AKMA service. The AKMA hint indicates to the AF that the communication device wishes to support the AKMA service and use the AKMA service to establish a secure connection. For example, FIG. 9C illustrates that exemplary AF 904 receives in steps 3-4a of FIG. 9C a ClientHello message comprising a PSK extension, an A-KID, and an AKMA hint based on the A-KID. FIG. 17 also illustrates that the method includes communicating 1702 towards the communication device a communication comprising PSK identification information for the secure connection and establishing 1704 a secure connection with the communication device based on the PSK identification information. For example, FIG. 9C illustrates that exemplary AF 904 establishes a secure connection with exemplary UE 902 in steps 4b-5 of FIG. 9C.
[0056] In some other embodiments, the AKMA service availability information indicates that the network node is unable to provide the AKMA service. In this embodiment, the method includes providing the communication service requested by the communication device without using the AKMA service. For example, the AF904 illustrated in FIGS. 8 and 9 may not be configured to provide the AKMA service and provides the requested communication service to the UE902 without using the AKMA service.
[0057] Generally, all terms used herein should be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or implied from the context in which the term is used. All references to an element, apparatus, component, means, step, etc. should be construed openly as referring to at least one instance of that element, apparatus, component, means, step, etc., unless otherwise explicitly stated. None of the steps of any method disclosed herein need to be performed in the exact order disclosed, unless the step is explicitly described as following or preceding another step and / or it is implicit that the step must follow or precede another step. Any feature of any of the embodiments disclosed herein may, where appropriate, be applied to any other embodiment. Similarly, any advantage of any of the embodiments may be applied to any other embodiment, and vice versa. Other objects, features, and advantages of the enclosed embodiments will become apparent from the following description.
[0058] Next, with reference to the accompanying drawings, some of the embodiments contemplated herein are more fully described. However, other embodiments are within the scope of the subject matter disclosed herein and the disclosed subject matter should not be construed as limited to only the embodiments described herein. Rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.
[0059] FIG. 18 illustrates a wireless network according to some embodiments.
[0060] The subject matter described herein can be implemented in any suitable type of system using any suitable components, but the embodiments disclosed herein are described with respect to wireless networks such as the exemplary wireless network illustrated in FIG. 18. For simplicity, the wireless network of FIG. 18 depicts only network 4106, network nodes 4160 and 4160b, and WDs (also called mobile terminals) 4110, 4110b, and 4110c. In reality, a wireless network can further include any additional elements suitable for supporting communication between wireless devices or between a wireless device and another communication device such as a landline phone, a service provider, or any other network node or end device. Of the components shown, network node 4160 and wireless device (WD) 4110 are depicted with additional detail. A wireless network can provide communication and other types of services to one or more wireless devices to facilitate access of the wireless devices to the wireless network and / or use of services provided by or through the wireless network.
[0061] A wireless network may comprise any type of communication, telecommunication, data, cellular, and / or wireless network, or other similar type of system, and / or interface with them. In some embodiments, the wireless network may be configured to operate according to a particular standard or other type of predefined rules or procedures. Thereby, certain embodiments of the wireless network may implement communication standards such as the Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, or 5G standards, wireless local area network (WLAN) standards such as the IEEE 802.11 standard, and / or any other appropriate wireless communication standards such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, and / or ZigBee standards.
[0062] Network 4106 may comprise one or more backhaul networks, core networks, IP networks, public switched telephone networks (PSTN), packet data networks, optical networks, wide area networks (WAN), local area networks (LAN), wireless local area networks (WLAN), wired networks, wireless networks, metropolitan area networks, and other networks for enabling communication between devices.
[0063] Network nodes 4160 and WD4110 include various components that are described in more detail below. These components cooperate to provide network node and / or wireless device functionality, such as providing a wireless connection in a wireless network. In different embodiments, the wireless network may include any number of wired or wireless networks, network nodes, base stations, controllers, wireless devices, relays, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals, whether via a wired connection or a wireless connection.
[0064] As used herein, a network node refers to a device that is configured, constructed, and / or operable to communicate directly or indirectly with a wireless device and / or other network nodes or devices in a wireless network to enable and / or provide wireless access to the wireless device and / or perform other functions (e.g., administration) in the wireless network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., wireless access points), base stations (BSs) (e.g., wireless base stations, Node B, evolved Node B (eNB), and NR Node B (gNB)). Base stations can be categorized based on the amount of coverage provided by the base station (or, alternatively, the transmission power level of the base station), in which case they may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station can be a relay node or a relay donor node that controls relays. A network node can also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU), which may sometimes be referred to as a remote radio head (RRH). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may sometimes be referred to as nodes in a distributed antenna system (DAS). Further examples of network nodes include multi-standard radio (MSR) devices such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), core network nodes (e.g., MSC, MME), O&M nodes, OSS nodes, SON nodes, positioning nodes (e.g., E-SMLC), and / or MDTs. As another example, a network node can be a virtual network node, as described in more detail below.However, more generally, a network node may represent any suitable device (or group of devices) that is configured, constructed, and / or operable to enable access to and / or provide access to a wireless network and / or provide some service to a wireless device that has accessed the wireless network.
[0065] In FIG. 18, network node 4160 includes a processing circuit 4170, a device-readable medium 4180, an interface 4190, auxiliary equipment 4184, a power source 4186, a power circuit 4187, and an antenna 4162. The network node 4160 illustrated in the exemplary wireless network of FIG. 18 may represent a device that includes the illustrated combination of hardware components, although other embodiments may include network nodes with different combinations of components. It should be understood that a network node comprises any suitable combination of hardware and / or software required to implement the tasks, features, functions, and methods disclosed herein. Moreover, although the components of network node 4160 are depicted as a single box located within a larger box or as a single box nested within multiple boxes, in reality, a network node may comprise multiple different physical components that make up a single illustrated component (e.g., device-readable medium 4180 may comprise multiple separate hard drives as well as multiple RAM modules).
[0066] Similarly, network node 4160 can be assembled from a plurality of physically distinct components (e.g., a Node B component and an RNC component, or a BTS component and a BSC component, etc.), each of which can have its own respective components. In some scenarios where network node 4160 comprises a plurality of distinct components (e.g., a BTS component and a BSC component), one or more of the distinct components can be shared among several network nodes. For example, a single RNC can control a plurality of Node Bs. In such scenarios, each unique pair of Node B and RNC can, in some cases, be regarded as a single distinct network node. In some embodiments, network node 4160 can be configured to support a plurality of radio access technologies (RATs). In such embodiments, some components can be replicated (e.g., separate device-readable media 4180 for different RATs), and some components can be reused (e.g., the same antenna 4162 can be shared by RATs). Network node 4160 can also include a plurality of sets of various illustrated components for different radio technologies, such as, for example, GSM, WCDMA, LTE, NR, WiFi, or Bluetooth radio technologies, integrated into network node 4160. These radio technologies can be integrated with the same or different chips or sets of chips, and other components within network node 4160.
[0067] The processing circuit 4170 is configured to perform any decision-making operation, computing operation, or similar operation (e.g., some acquisition operation) as described herein as provided by a network node. These operations performed by the processing circuit 4170 may include processing the information obtained by the processing circuit 4170, for example, by converting the obtained information into other information, comparing the obtained information or the converted information with the information stored in the network node, and / or performing one or more operations based on the obtained information or the converted information and as a result of the processing having made a decision.
[0068] The processing circuit 4170 may comprise a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or any other suitable computing device, one or more combinations of resources, or a combination of hardware, software and / or encoded logic, operable to provide the network node 4160 functionality, either alone or in combination with other network node 4160 components such as the device-readable medium 4180. For example, the processing circuit 4170 may execute instructions stored in the device-readable medium 4180 or instructions stored in memory within the processing circuit 4170. Such functionality may include providing any of the various wireless features, functions, or benefits discussed herein. In some embodiments, the processing circuit 4170 may include a system on chip (SOC).
[0069] In some embodiments, the processing circuit 4170 may include one or more of a radio frequency (RF) transceiver circuit 4172 and a baseband processing circuit 4174. In some embodiments, the radio frequency (RF) transceiver circuit 4172 and the baseband processing circuit 4174 may be on separate chips (or sets of chips), boards, or units such as a radio unit and a digital unit. In alternative embodiments, some or all of the RF transceiver circuit 4172 and the baseband processing circuit 4174 may be on the same chip or set of chips, board, or unit.
[0070] In some embodiments, some or all of the functions described herein as provided by a network node, base station, eNB, or other such network device may be implemented by a processing circuit 4170 that executes instructions stored in a device-readable medium 4180, or in memory within the processing circuit 4170. In alternative embodiments, some or all of the functions may be provided by the processing circuit 4170 without executing instructions stored in a separate or discrete device-readable medium, such as in a hardwired manner. In any of those embodiments, whether or not executing instructions stored in a device-readable storage medium, the processing circuit 4170 may be configured to implement the described functions. The benefits provided by such functions are not limited to the processing circuit 4170 alone or to other components of the network node 4160, but are enjoyed generally by the network node 4160 as a whole, and / or by end users and the wireless network.
[0071] The device-readable medium 4180 can comprise any form of volatile or non-volatile computer-readable memory, including but not limited to persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disk), removable storage media (e.g., flash drive, compact disk (CD) or digital video disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that can store information, data, and / or instructions used by the processing circuit 4170. The device-readable medium 4180 can store any suitable instructions, data, or information, including an application that includes one or more of a computer program, software, logic, rules, code, tables, etc., and / or other instructions that can be executed by the processing circuit 4170 and utilized by the network node 4160. The device-readable medium 4180 can be used to store calculations performed by the processing circuit 4170 and / or data received via the interface 4190. In some embodiments, the processing circuit 4170 and the device-readable medium 4180 can be considered integrated.
[0072] Interface 4190 is used in the wired or wireless communication of signaling and / or data between network node 4160, network 4106, and / or WD 4110. As shown, interface 4190 includes, for example, port / terminal 4194 for sending and receiving data with network 4106 over a wired connection. Interface 4190 also includes a radio front-end circuit 4192 that may be coupled to antenna 4162 or, in some embodiments, may be part of antenna 4162. The radio front-end circuit 4192 includes a filter 4198 and an amplifier 4196. The radio front-end circuit 4192 may be connected to antenna 4162 and processing circuit 4170. The radio front-end circuit may be configured to condition signals communicated between antenna 4162 and processing circuit 4170. The radio front-end circuit 4192 may receive digital data to be sent to other network nodes or WDs via a wireless connection. The radio front-end circuit 4192 may convert the digital data into a radio signal having appropriate channel and bandwidth parameters using a combination of filter 4198 and / or amplifier 4196. The radio signal may then be transmitted via antenna 4162. Similarly, when receiving data, antenna 4162 may collect a radio signal, which is then converted into digital data by radio front-end circuit 4192. The digital data may be passed to processing circuit 4170. In other embodiments, the interface may comprise different components and / or different combinations of components.
[0073] In some alternative embodiments, network node 4160 may not include a separate radio front-end circuit 4192. Instead, processing circuit 4170 may comprise a radio front-end circuit and may be connected to antenna 4162 without a separate radio front-end circuit 4192. Similarly, in some embodiments, all or part of RF transceiver circuit 4172 may be regarded as part of interface 4190. In yet other embodiments, interface 4190 may include one or more ports or terminals 4194, radio front-end circuit 4192, and RF transceiver circuit 4172 as part of a wireless unit (not shown), and interface 4190 may communicate with baseband processing circuit 4174, which is part of a digital unit (not shown).
[0074] Antenna 4162 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals. Antenna 4162 may be coupled to radio front-end circuit 4192 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, antenna 4162 may comprise one or more omnidirectional, sector, or panel antennas operable to transmit / receive wireless signals, for example, between 2 GHz and 66 GHz. Omnidirectional antennas may be used to transmit / receive wireless signals in any direction, sector antennas may be used to transmit / receive wireless signals from devices within a particular area, and panel antennas may be line-of-sight antennas used to transmit / receive wireless signals in a relatively straight line. In some cases, the use of two or more antennas may be referred to as MIMO. In some embodiments, antenna 4162 may be separate from network node 4160 and may be connectable to network node 4160 through an interface or port.
[0075] Antenna 4162, interface 4190, and / or processing circuit 4170 may be configured to perform any receiving operations and / or some acquisition operations described herein as being performed by a network node. Any information, data, and / or signals may be received from a wireless device, another network node, and / or any other network equipment. Similarly, antenna 4162, interface 4190, and / or processing circuit 4170 may be configured to perform any transmission operations described herein as being performed by a network node. Any information, data, and / or signals may be transmitted to a wireless device, another network node, and / or any other network equipment.
[0076] Power circuit 4187 may comprise a power management circuit or be coupled to a power management circuit and is configured to supply power for performing the functions described herein to the components of network node 4160. Power circuit 4187 may receive power from power source 4186. Power source 4186 and / or power circuit 4187 may be configured to provide power to the various components of network node 4160 in a form suitable for each respective component (e.g., at the voltage and current levels required for each respective component). Power source 4186 may be either included in power circuit 4187 and / or network node 4160 or external to power circuit 4187 and / or network node 4160. For example, network node 4160 may be connectable to an external power source (e.g., an electrical outlet) via an input circuit or interface such as an electrical cable, whereby the external power source supplies power to power circuit 4187. As a further example, power source 4186 may comprise a power source in the form of a battery or battery pack connected to or integrated in power circuit 4187. The battery may provide backup power in the event that the external power source fails. Other types of power sources such as photovoltaic devices may also be used.
[0077] An alternative embodiment of network node 4160 may be responsible for providing some aspect of the functionality of a network node, including any of the functionality described herein, and / or any of the functionality necessary to support the subject matter described herein, and may include additional components other than those shown in FIG. 18. For example, network node 4160 may include user interface equipment to enable the input of information to network node 4160 and to enable the output of information from network node 4160. This may enable a user to perform diagnostic, maintenance, repair, and other administrative functions for network node 4160.
[0078] As used herein, a wireless device (WD) refers to a device that is capable of wirelessly communicating with a network node and / or another wireless device, and is configured, arranged, and / or operable to do so. Unless otherwise stated, the term WD may be used interchangeably with user equipment (UE) in this document. Wireless communication may involve transmitting and / or receiving a wireless signal using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for transmitting information through the air. In some embodiments, the WD may be configured to transmit and / or receive information without direct human interaction. For example, the WD may be designed to transmit information to the network at a predetermined schedule when triggered by an internal or external event, or in response to a request from the network. Examples of WDs include, but are not limited to, smartphones, mobile phones, cell phones, voice over IP (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, gaming consoles or devices, music storage devices, playback appliances, wearable terminal devices, wireless endpoints, mobile stations, tablets, laptop computers, laptop embedded equipment (LEE), laptop-mounted equipment (LME), smart devices, wireless customer premises equipment (CPE), in-vehicle wireless terminal devices, etc. The WD may support device-to-device (D2D) communication, for example, by implementing 3GPP standards for sidelink communication, vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-everything (V2X), in which case it may be referred to as a D2D communication device. As another specific example, in an Internet of Things (IoT) scenario, the WD may represent a machine or other device that performs monitoring and / or measurement and transmits the results of such monitoring and / or measurement to another WD and / or network node. The WD may, in this case, be a machine-to-machine (M2M) device, and M2M devices may sometimes be referred to as machine type communication (MTC) devices in a 3GPP context.As one specific example, the WD may be a UE implementing the 3GPP narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or household or personal electrical appliances (such as refrigerators, televisions, etc.), personal wearables (such as watches, fitness trackers, etc.). In other scenarios, the WD may represent a vehicle or other equipment, and the vehicle or other equipment is capable of monitoring its operating status and / or reporting on its operating status, or other functions related to its operation. The WD described above may represent an endpoint of a wireless connection, in which case the device may be referred to as a wireless terminal. Moreover, the WD described above may be mobile, in which case the device may also be referred to as a mobile device or a mobile terminal.
[0079] As illustrated, the wireless device 4110 includes an antenna 4111, an interface 4114, a processing circuit 4120, a device-readable medium 4130, a user interface device 4132, an auxiliary device 4134, a power source 4136, and a power circuit 4137. The WD 4110 may include one or more sets of one or more of the illustrated components for different wireless technologies supported by the WD 4110, for example, to name just a few, GSM, WCDMA, LTE, NR, WiFi, WiMAX, or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chips or sets of chips as other components within the WD 4110.
[0080] Antenna 4111 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals and is connected to interface 4114. In some alternative embodiments, antenna 4111 is separate from WD 4110 and may be connectable to WD 4110 through an interface or port. Antenna 4111, interface 4114, and / or processing circuit 4120 may be configured to perform any of the receiving or transmitting operations described herein as being performed by the WD. Any information, data, and / or signals may be received from a network node and / or another WD. In some embodiments, the radio front-end circuitry and / or antenna 4111 may be regarded as an interface.
[0081] As shown, interface 4114 includes a radio front-end circuit 4112 and an antenna 4111. The radio front-end circuit 4112 includes one or more filters 4118 and an amplifier 4116. The radio front-end circuit 4112 is connected to the antenna 4111 and the processing circuit 4120 and is configured to condition signals communicated between the antenna 4111 and the processing circuit 4120. The radio front-end circuit 4112 may be coupled to the antenna 4111 or may be part of the antenna 4111. In some embodiments, WD 4110 may not include a separate radio front-end circuit 4112; rather, the processing circuit 4120 may include a radio front-end circuit and may be connected to the antenna 4111. Similarly, in some embodiments, some or all of the RF transceiver circuit 4122 may be considered part of the interface 4114. The radio front-end circuit 4112 may receive digital data to be transmitted to other network nodes or WDs via a wireless connection. The radio front-end circuit 4112 may convert the digital data into a wireless signal having appropriate channel and bandwidth parameters using a combination of the filters 4118 and / or the amplifier 4116. The wireless signal may then be transmitted via the antenna 4111. Similarly, when receiving data, the antenna 4111 may collect a wireless signal, which may then be converted into digital data by the radio front-end circuit 4112. The digital data may be passed to the processing circuit 4120. In other embodiments, the interface may include different components and / or different combinations of components.
[0082] The processing circuit 4120 may comprise a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or any other suitable computing device, resource, one or a combination of multiple ones thereof, or a combination of hardware, software and / or encoded logic, operable to provide the WD4110 functionality, either alone or in conjunction with other WD4110 components such as the device-readable medium 4130. Such functionality may include providing any of the various wireless features or benefits discussed herein. For example, the processing circuit 4120 may execute instructions stored on the device-readable medium 4130 or instructions stored in memory within the processing circuit 4120 to provide the functionality disclosed herein.
[0083] As illustrated, processing circuitry 4120 includes one or more of RF transceiver circuitry 4122, baseband processing circuitry 4124, and application processing circuitry 4126. In other embodiments, the processing circuitry may comprise different components and / or different combinations of components. In some embodiments, the processing circuitry 4120 of WD 4110 may comprise a system-on-a-chip (SOC). In some embodiments, the RF transceiver circuitry 4122, baseband processing circuitry 4124, and application processing circuitry 4126 may be on separate chips or a set of chips. In an alternative embodiment, some or all of the baseband processing circuitry 4124 and application processing circuitry 4126 may be combined to form one chip or a set of chips, and the RF transceiver circuitry 4122 may be on a separate chip or a set of chips. In a further alternative embodiment, some or all of the RF transceiver circuitry 4122 and baseband processing circuitry 4124 may be on the same chip or a set of chips, and the application processing circuitry 4126 may be on a separate chip or a set of chips. In yet another alternative embodiment, some or all of the RF transceiver circuitry 4122, baseband processing circuitry 4124, and application processing circuitry 4126 may be combined within the same chip or a set of chips. In some embodiments, the RF transceiver circuitry 4122 may be part of interface 4114. The RF transceiver circuitry 4122 may condition RF signals for the processing circuitry 4120.
[0084] In some embodiments, some or all of the functions described herein as being performed by the WD may be provided by a processing circuit 4120 that executes instructions stored on a device-readable medium 4130, which in some embodiments may be a computer-readable storage medium. In alternative embodiments, some or all of the functions may be provided by the processing circuit 4120 without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether or not executing instructions stored on a device-readable storage medium, the processing circuit 4120 may be configured to perform the described functions. The benefits provided by such functions are not limited to the processing circuit 4120 alone or to other components of the WD4110, but are enjoyed by the WD4110 as a whole, and / or generally by the end user and the wireless network.
[0085] The processing circuit 4120 may be configured to perform any decision-making operation, computational operation, or similar operation (e.g., some acquisition operations) described herein as being performed by the WD. These operations as performed by the processing circuit 4120 may include processing the information obtained by the processing circuit 4120, e.g., by converting the obtained information into other information, comparing the obtained information or the converted information with information stored by the WD4110, and / or performing one or more operations based on the obtained information or the converted information and as a result of the processing having made a decision.
[0086] The device-readable medium 4130 may be operable to store an application including one or more of a computer program, software, logic, rules, code, tables, etc., and / or other instructions executable by the processing circuitry 4120. The device-readable medium 4130 may include a computer memory (e.g., random access memory (RAM) or read-only memory (ROM)), a mass storage medium (e.g., hard disk), a removable storage medium (e.g., compact disk (CD) or digital video disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that can store information, data, and / or instructions used by the processing circuitry 4120. In some embodiments, the processing circuitry 4120 and the device-readable medium 4130 may be considered integrated.
[0087] The user interface device 4132 may provide components that enable a human user to interact with the WD4110. Such interactions can be in many forms, such as visual, auditory, tactile, etc. The user interface device 4132 may be operable to create outputs to the user and to enable the user to provide inputs to the WD4110. The type of interaction may vary depending on the type of user interface device 4132 installed on the WD4110. For example, if the WD4110 is a smartphone, the interaction may be via a touch screen, and if the WD4110 is a smart meter, the interaction may be through a screen that provides usage amounts (e.g., the number of gallons used) or a speaker that provides an audible alarm (e.g., if smoke is detected). The user interface device 4132 may include an input interface, devices and circuits, as well as an output interface, devices and circuits. The user interface device 4132 is configured to enable the input of information to the WD4110 and is connected to the processing circuit 4120 to enable the processing circuit 4120 to process the input information. The user interface device 4132 may include, for example, a microphone, a proximity or other sensor, a key / button, a touch display, one or more cameras, a USB port, or other input circuits. The user interface device 4132 is also configured to enable the output of information from the WD4110 and to enable the processing circuit 4120 to output information from the WD4110. The user interface device 4132 may include, for example, a speaker, a display, a vibration circuit, a USB port, a headphone interface, or other output circuits. Using one or more input and output interfaces, devices, and circuits of the user interface device 4132, the WD4110 may communicate with an end user and / or a wireless network, enabling the end user and / or the wireless network to benefit from the functions described herein.
[0088] Auxiliary device 4134 is operable to provide more specific functions that may not generally be performed by the WD. This can include special sensors for making measurements for various purposes, interfaces for additional types of communication such as wired communication, etc. The components included and types of the auxiliary device 4134 can vary depending on the embodiment and / or scenario.
[0089] Power source 4136 can, in some embodiments, be in the form of a battery or battery pack. Other types of power sources can also be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or a battery. The WD 4110 can further include a power circuit 4137 for distributing power from the power source 4136 to various parts of the WD 4110 that require power to perform any of the functions described or indicated herein. The power circuit 4137 can, in some embodiments, include a power management circuit. The power circuit 4137 can alternatively or additionally be operable to receive power from an external power source, in which case the WD 4110 can be connectable to an external power source (such as an electrical outlet) via an input circuit or interface such as a power cable. The power circuit 4137 can also, in some embodiments, be operable to distribute power from an external power source to the power source 4136. This can be for, example, charging the power source 4136. The power circuit 4137 can perform any formatting, conversion, or other modification to the power from the power source 4136 to make it suitable for each component of the WD 4110 to which the power is supplied.
[0090] FIG. 19 illustrates a user device according to some embodiments.
[0091] FIG. 19 illustrates one embodiment of a UE according to various aspects described herein. A user equipment or UE as used herein may not necessarily have a user in the sense of a human user who owns and / or operates the associated device. Instead, a UE may represent a device (e.g., a smart sprinkler controller) that is intended for sale to, or operation by, a human user, but may not be associated with a particular human user, or may not initially be associated with a particular human user. Alternatively, a UE may represent a device (e.g., a smart power meter) that is not intended for sale to, or operation by, an end user, but may be associated with a user, or may be operated for the benefit of a user. UE42200 can be any UE identified by the Third Generation Partnership Project (3GPP), including an NB-IoT UE, a Machine Type Communication (MTC) UE, and / or an Extended MTC (eMTC) UE. The UE4200 illustrated in FIG. 19 is an example of a WD configured for communication according to one or more communication standards published by 3GPP, such as the GSM, UMTS, LTE, and / or 5G standards of the Third Generation Partnership Project (3GPP). As described above, the terms WD and UE may be used interchangeably. Thus, FIG. 19 is of a UE, but the components discussed herein are equally applicable to a WD, and vice versa.
[0092] In FIG. 19, the UE 4200 includes a processing circuit 4201 operably coupled to an input / output interface 4205, a radio frequency (RF) interface 4209, a network connection interface 4211, a memory 4215 including a random access memory (RAM) 4217, a read-only memory (ROM) 4219, a storage medium 4221, etc., a communication subsystem 4231, a power supply 4213, and / or other components, or any combination thereof. The storage medium 4221 includes an operating system 4223, an application program 4225, and data 4227. In other embodiments, the storage medium 4221 may include other similar types of information. Some UEs may utilize all of the components shown in FIG. 19 or only a subset of those components. The level of integration between components may vary from UE to UE. Additionally, some UEs may include multiple instances of components such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0093] In FIG. 19, the processing circuit 4201 may be configured to process computer instructions and data. The processing circuit 4201 may be any sequential state machine operable to execute machine instructions stored in memory as a machine-readable computer program, such as one or more hardware-implemented state machines (e.g., in discrete logic, FPGA, ASIC, etc.), programmable logic together with appropriate firmware, a microprocessor or digital signal processor (DSP) together with appropriate software, one or more program embedded, general-purpose processors, or any combination of the above. For example, the processing circuit 4201 may include two central processing units (CPUs). The data may be information in a form suitable for use by a computer.
[0094] In the described embodiment, the input / output interface 4205 can be configured to provide a communication interface to an input device, an output device, or an input / output device. The UE 4200 can be configured to use an output device via the input / output interface 4205. The output device can use the same type of interface port as the input device. For example, a USB port can be used to provide input to and output from the UE 4200. The output device can be a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smart card, another output device, or any combination thereof. The UE 4200 can be configured to use an input device via the input / output interface 4205 to enable a user to capture information to the UE 4200. The input device can include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smart card, etc. The presence-sensitive display can include a capacitive or resistive touch sensor for detecting input from a user. The sensor can be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, another similar sensor, or any combination thereof. For example, the input device can be an accelerometer, a magnetometer, a digital camera, a microphone, and an optical sensor.
[0095] In FIG. 19, the RF interface 4209 can be configured to provide a communication interface to RF components such as a transmitter, a receiver, and an antenna. The network connection interface 4211 can be configured to provide a communication interface to the network 4243a. The network 4243a can include wired and / or wireless networks such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a communication network, another similar network, or any combination thereof. For example, the network 4243a can include a Wi-Fi network. The network connection interface 4211 can be configured to include a receiver and a transmitter interface used to communicate with one or more other devices on the communication network according to one or more communication protocols such as Ethernet, TCP / IP, SONET, ATM, etc. The network connection interface 4211 can implement receiver and transmitter functions suitable for a communication network link (e.g., optical, electrical, etc.). The transmitter and receiver functions can share circuit components, software, or firmware, or alternatively, can be implemented separately.
[0096] RAM 4217 can be configured to interface with the processing circuit 4201 via the bus 4202 to provide storage or caching of data or computer instructions during the execution of software programs such as an operating system, application programs, and device drivers. ROM 4219 can be configured to provide computer instructions or data to the processing circuit 4201. For example, ROM 4219 can be configured to store invariant low-level system code or data for basic system functions such as basic input / output (I / O), startup, or reception of keystrokes from a keyboard, which are stored in non-volatile memory. The storage medium 4221 can be configured to include memory such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, floppy disk, hard disk, removable cartridge, or flash drive. In one example, the storage medium 4221 can be configured to include an operating system 4223, an application program 4225 such as a web browser application, widget or gadget engine, or another application, and a data file 4227. The storage medium 4221 can store any of a variety of operating systems or combinations of operating systems for use by the UE 4200.
[0097] The memory medium 4221 can be configured to include several physical drive units, such as a redundant array of independent disks (RAID), a floppy disk drive, a flash memory, a USB flash drive, an external hard disk drive, a thumb drive, a pen drive, a key drive, a high-definition digital versatile disc (HD-DVD) optical disc drive, an internal hard disk drive, a Blu-Ray optical disc drive, a holographic digital data storage (HDDS) optical disc drive, an external mini dual in-line memory module (DIMM), a synchronous dynamic random access memory (SDRAM), an external micro DIMM SDRAM, a subscriber identification information module or a removable user identification information (SIM / RUIM) module such as a smart card memory, other memories, or any combination thereof. The memory medium 4221 can enable the UE4200 to access computer-executable instructions, application programs, etc. stored in a temporary or non-temporary memory medium, offload data, or upload data. A manufactured product such as a manufactured product using a communication system can be tangibly embodied in the memory medium 4221, and the memory medium 4221 can comprise a device-readable medium.
[0098] In FIG. 19, the processing circuit 4201 can be configured to communicate with the network 4243b using the communication subsystem 4231. The network 4243a and the network 4243b can be the same one or more networks or different one or more networks. The communication subsystem 4231 can be configured to include one or more transceivers used to communicate with the network 4243b. For example, the communication subsystem 4231 can be configured to include one or more transceivers for communicating with one or more remote transceivers of another WD, UE, or base station, etc., capable of wireless communication, such as another device on a radio access network (RAN) according to one or more communication protocols, such as IEEE802.11, CDMA, WCDMA, GSM, LTE, UTRAN, WiMax, etc. Each transceiver can include a transmitter 4233 and / or a receiver 4235 for implementing a transmitter function or a receiver function suitable for a RAN link (such as frequency allocation, etc.), respectively. Further, the transmitter 4233 and the receiver 4235 of each transceiver can share circuit components, software, or firmware, or alternatively, can be implemented separately.
[0099] In the illustrated embodiment, the communication functions of the communication subsystem 4231 may include data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication such as the use of the Global Positioning System (GPS) for determining location, other similar communication functions, or any combination thereof. For example, the communication subsystem 4231 may include cellular communication, Wi-Fi communication, Bluetooth communication, and GPS communication. The network 4243b may include wired and / or wireless networks such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a communication network, other similar networks, or any combination thereof. For example, the network 4243b may be a cellular network, a Wi-Fi network, and / or a near-field network. The power supply 4213 may be configured to provide alternating current (AC) or direct current (DC) power to the components of the UE 4200.
[0100] The features, benefits, and / or functions described herein may be implemented in one of the components of the UE 4200 or may be distributed across multiple components of the UE 4200. Further, the features, benefits, and / or functions described herein may be implemented in any combination of hardware, software, or firmware. In one example, the communication subsystem 4231 may be configured to include any of the components described herein. Further, the processing circuit 4201 may be configured to communicate with any of such components over the bus 4202. In another example, any of such components may be represented by program instructions stored in a memory that, when executed by the processing circuit 4201, perform the corresponding functions described herein. In another example, the functions of any of such components may be divided between the processing circuit 4201 and the communication subsystem 4231. In another example, the non-computation-intensive functions of any of such components may be implemented in software or firmware, and the computation-intensive functions may be implemented in hardware.
[0101] FIG. 20 illustrates a virtualized environment according to some embodiments.
[0102] FIG. 20 is a schematic block diagram illustrating a virtualized environment 4300 in which functions implemented according to some embodiments can be virtualized. In this context, virtualizing means creating a virtual version of a device or apparatus that may include virtualizing a hardware platform, memory device, and networking resources. As used herein, virtualization can be applied to a node (e.g., a virtualized base station or a virtualized radio access node), or to a device (e.g., a UE, a wireless device, or any other type of communication device) or a component of that device, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components (e.g., via one or more applications, components, functions, virtual machines, or containers executing on one or more physical processing nodes in one or more networks).
[0103] In some embodiments, some or all of the functions described herein can be implemented as virtual components executed by one or more virtual machines hosted in one or more virtual environments 4300 hosted by one or more of the hardware nodes 4330. Further, in embodiments where the virtual node is not a radio access node or does not require wireless connectivity (e.g., a core network node), the network node can be fully virtualized.
[0104] The functionality can be implemented by one or more applications 4320 (alternatively, sometimes referred to as software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) that are operable to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. The application 4320 is operated in a virtualization environment 4300 that provides hardware 4330 comprising a processing circuit 4360 and a memory 4390. The memory 4390 includes instructions 4395 executable by the processing circuit 4360, whereby the application 4320 is operable to provide one or more of the features, benefits, and / or functions disclosed herein.
[0105] The virtualized environment 4300 comprises a general-purpose or dedicated network hardware device 4330 that includes a set of one or more processors or a processing circuit 4360, where the set of one or more processors or the processing circuit 4360 can be a commercial off-the-shelf (COTS) processor, a dedicated application-specific integrated circuit (ASIC), or any other type of processing circuit including digital or analog hardware components or dedicated processors. Each hardware device can include a memory 4390-1, which can be a non-persistent memory for temporarily storing instructions 4395 or software executed by the processing circuit 4360. Each hardware device can include one or more network interface controllers (NICs) 4370, also known as network interface cards, where the network interface controller (NIC) 4370 includes a physical network interface 4380. Each hardware device can also include a non-transitory, persistent, machine-readable storage medium 4390-2 storing software 4395 and / or instructions executable by the processing circuit 4360. The software 4395 can include any type of software including software for instantiating one or more virtualization layers (also called hypervisors) 4350, software for executing virtual machines 4340, and software enabling it to perform the functions, features, and / or benefits described in relation to some of the embodiments described herein.
[0106] The virtual machine 4340 comprises virtual processing, virtual memory, virtual networking or interfaces, and virtual storage and can be operated by a corresponding virtualization layer 4350 or hypervisor. Different embodiments of instances of virtual appliances 4320 can be implemented on one or more of the virtual machines 4340 and the implementation can be done in different ways.
[0107] During operation, the processing circuit 4360 executes software 4395 to instantiate a hypervisor or virtualization layer 4350, which may sometimes be referred to as a virtual machine monitor (VMM). The virtualization layer 4350 may present a virtual operating platform to the virtual machines 4340 that appears as networking hardware.
[0108] As shown in FIG. 20, the hardware 4330 can be a stand-alone network node with general or specific components. The hardware 4330 can include an antenna 43225 and can implement some functions through virtualization. Alternatively, the hardware 4330 can be part of a larger class of hardware (such as in the case of a data center or customer premise equipment (CPE)) that is managed through a management and orchestration (MANO) 43100 where multiple hardware nodes cooperate and in particular oversee the lifecycle management of the application 4320.
[0109] The virtualization of hardware is called network function virtualization (NFV) in some contexts. NFV can be used to consolidate many network equipment types onto industry-standard high-volume server hardware, physical switches, and physical storage that can be located within data centers and customer premise equipment.
[0110] In the context of NFV, the virtual machines 4340 can be software implementations of physical machines that run programs as if those programs were running on non-virtualized physical machines. Each of the virtual machines 4340 forms a separate virtual network element (VNE) with that part of the hardware 4330 that executes it, whether that hardware is dedicated to that virtual machine and / or shared by that virtual machine with other virtual machines among the virtual machines 4340.
[0111] Furthermore, in the context of NFV, a virtual network function (VNF) is responsible for handling a specific network function operating in one or more virtual machines 4340 on a hardware networking infrastructure 4330, corresponding to the application 4320 in FIG. 20.
[0112] In some embodiments, one or more radio units 43200, each including one or more transmitters 43220 and one or more receivers 43210, may be coupled to one or more antennas 43225. The radio unit 43200 may communicate directly with the hardware node 4330 via one or more suitable network interfaces and may be used in combination with virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station.
[0113] In some embodiments, some signaling may be implemented using a control system 43230 that may alternatively be used for communication between the hardware node 4330 and the radio unit 43200.
[0114] FIG. 21 illustrates a communication network connected to a host computer via an intermediate network according to some embodiments.
[0115] Referring to FIG. 21, according to an embodiment, a communication network 4410, such as a 3GPP type cellular network, includes an access network 4411, such as a radio access network, and a core network 4414. The access network 4411 includes a plurality of base stations 4412a, 4412b, 4412c, such as NB, eNB, gNB, or other types of radio access points, each defining a corresponding coverage area 4413a, 4413b, 4413c. Each base station 4412a, 4412b, 4412c is connectable to the core network 4414 over a wired or wireless connection 4415. A first UE 4491 located in the coverage area 4413c is configured to wirelessly connect to the corresponding base station 4412c or be paged by the corresponding base station 4412c. A second UE 4492 in the coverage area 4413a is wirelessly connectable to the corresponding base station 4412a. Although a plurality of UEs 4491, 4492 are illustrated in this example, the disclosed embodiments are equally applicable to situations where only one UE is in the coverage area or only one UE is connected to the corresponding base station 4412.
[0116] The communication network 4410 is itself connected to a host computer 4430, which may be embodied in the hardware and / or software of a stand-alone server, a cloud-implemented server, a distributed server, or as processing resources in a server farm. The host computer 4430 may be under the ownership or control of a service provider or may be operated by or on behalf of a service provider. The connections 4421 and 4422 between the communication network 4410 and the host computer 4430 may extend directly from the core network 4414 to the host computer 4430 or may proceed via an optional intermediate network 4420. The intermediate network 4420 may be one of a public network, a private network, or a hosted network, or a combination of two or more of them. The intermediate network 4420 may, if any, be a backbone network or the Internet. In particular, the intermediate network 4420 may comprise two or more sub-networks (not shown).
[0117] The communication system of FIG. 21 enables connectivity between the connected UEs 4491, 4492 and the host computer 4430. The connectivity can be described as an over-the-top (OTT) connection 4450. The host computer 4430 and the connected UEs 4491, 4492 are configured to communicate data and / or signaling via the OTT connection 4450, using the access network 4411, the core network 4414, any intermediate network 4420, and any additional infrastructure (not shown) as a medium. The OTT connection 4450 can be transparent in the sense that the participating communication devices through which the OTT connection 4450 passes are unaware of the routing of uplink and downlink communications. For example, the base station 4412 may not be informed or need to be informed about the past routing of incoming downlink communications with data originating from the host computer 4430 that is to be forwarded (e.g., handed over) to the connected UE 4491. Similarly, the base station 4412 does not need to be aware of the future routing of outgoing uplink communications originating from the UE 4491 and directed towards the host computer 4430.
[0118] FIG. 22 illustrates a host computer communicating with a user equipment via a base station over a partial wireless connection, according to some embodiments.
[0119] Next, an exemplary implementation of the UE, base station, and host computer discussed in the previous paragraph according to the embodiment will be described with reference to FIG. 22. In a communication system 4500, a host computer 4510 includes hardware 4515 including a communication interface 4516 configured to set up and maintain a wired or wireless connection with interfaces of different communication devices of the communication system 4500. The host computer 4510 further includes a processing circuit 4518 that may have a storage capacity and / or a processing capacity. In particular, the processing circuit 4518 may include one or more programmable processors, application specific integrated circuits, field programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The host computer 4510 further includes software 4511 stored in or accessible by the host computer 4510 and executable by the processing circuit 4518. The software 4511 includes a host application 4512. The host application 4512 may be operable to provide services to a remote user, such as a UE 4530, that connects via an OTT connection 4550 that terminates at the UE 4530 and the host computer 4510. When providing services to a remote user, the host application 4512 may provide user data transmitted using the OTT connection 4550.
[0120] The communication system 4500 further includes a base station 4520 provided in the communication system, and the base station 4520 includes hardware 4525 that enables the base station 4520 to communicate with the host computer 4510 and the UE 4530. The hardware 4525 includes a communication interface 4526 for setting up and maintaining a wired or wireless connection with an interface of different communication devices of the communication system 4500, and a wireless interface 4527 for setting up and maintaining at least a wireless connection 4570 with a UE 4530 located in a coverage area (not shown in FIG. 22) served by the base station 4520. The communication interface 4526 can be set to facilitate the connection 4560 to the host computer 4510. The connection 4560 can be direct, or the connection 4560 can pass through a core network (not shown in FIG. 22) of the communication system and / or one or more intermediate networks outside the communication system. In the illustrated embodiment, the hardware 4525 of the base station 4520 further includes a processing circuit 4528, and the processing circuit 4528 can include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The base station 4520 further has software 4521 stored internally or accessible via an external connection.
[0121] The communication system 4500 further includes the UE 4530 already mentioned. The hardware 4535 of the UE 4530 may include a radio interface 4537 configured to set up and maintain a radio connection 4570 with a base station serving the coverage area where the UE 4530 is currently located. The hardware 4535 of the UE 4530 further includes a processing circuit 4538, which may comprise one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The UE 4530 further comprises software 4531 stored in or accessible by the UE 4530 and executable by the processing circuit 4538. The software 4531 includes a client application 4532. The client application 4532 may be operable to provide services to a human or non-human user via the UE 4530 under the support of the host computer 4510. In the host computer 4510, the running host application 4512 may communicate with the running client application 4532 via an OTT connection 4550 terminating at the UE 4530 and the host computer 4510. When providing services to the user, the client application 4532 may receive request data from the host application 4512 and provide user data in response to the request data. The OTT connection 4550 may transfer both the request data and the user data. The client application 4532 may interact with the user to generate the user data provided by the client application 4532.
[0122] Note that the host computer 4510, base station 4520, and UE 4530 illustrated in FIG. 22 may be the same as or equivalent to one of the host computer 4430, base stations 4412a, 4412b, 4412c in FIG. 21, and one of the UEs 4491, 4492, respectively. That is, the operation inside these entities may be as shown in FIG. 22, and separately, the surrounding network topology may be the same as that in FIG. 21.
[0123] In FIG. 22, the OTT connection 4550 is abstractly drawn to illustrate the communication between the host computer 4510 and the UE 4530 via the base station 4520 without explicit mention of the intermediary device and the exact routing of messages through these devices. The network infrastructure may determine the routing, and the network infrastructure may be configured to hide the routing from the UE 4530, from the service provider operating the host computer 4510, or from both. While the OTT connection 4550 is active, the network infrastructure may further make a determination to dynamically change the routing (e.g., based on network load distribution considerations or reconfiguration).
[0124] The radio connection 4570 between the UE 4530 and the base station 4520 follows the teachings of the embodiments described throughout this disclosure. One or more of the various embodiments may use the OTT connection 4550 of which the radio connection 4570 forms the last segment to improve the performance of the OTT service provided to the UE 4530. More precisely, the teachings of these embodiments may improve the random access speed and / or reduce the random access failure rate, thereby providing benefits such as faster and / or more reliable random access.
[0125] A measurement procedure can be provided for the purpose of monitoring data rate, latency, and other factors that one or more embodiments improve. There can further be an optional network function for reconfiguring the OTT connection 4550 between the host computer 4510 and the UE 4530 in response to variations in the measurement results. The measurement procedure and / or the network function for reconfiguring the OTT connection 4550 can be implemented in the software 4511 and hardware 4515 of the host computer 4510 or in the software 4531 and hardware 4535 of the UE 4530, or both. In an embodiment, a sensor (not shown) can be deployed in or associated with the communication device through which the OTT connection 4550 passes, and the sensor can participate in the measurement procedure by supplying values of the monitored quantities exemplified above or by supplying values of other physical quantities that the software 4511, 4531 can calculate or estimate the monitored quantities. The reconfiguration of the OTT connection 4550 can include message format, retransmission settings, preferred routing, etc., and the reconfiguration need not affect the base station 4520 and can be unknown or imperceptible to the base station 4520. Such procedures and functions are known and can be practiced in the art. In some embodiments, the measurement can involve proprietary UE signaling that facilitates measurements at the host computer 4510 such as throughput, propagation time, latency, etc. The measurement can be implemented in that the software 4511 and 4531 cause messages, particularly empty or "dummy" messages, to be transmitted using the OTT connection 4550 while the software 4511 and 4531 monitor propagation time, errors, etc.
[0126] FIG. 23 illustrates a method implemented in a communication system including a host computer, a base station, and a user equipment, according to some embodiments.
[0127] FIG. 23 is a flowchart illustrating a method implemented in a communication system according to an embodiment. The communication system may include a host computer, a base station, and a UE, as described with reference to FIGS. 21 and 22. For simplicity of the present disclosure, only the drawing reference to FIG. 23 is included in this section. At step 4610, the host computer provides user data. At optional sub-step 4611 of step 4610, the host computer provides user data by executing a host application. At step 4620, the host computer initiates a transmission to carry the user data to the UE. At optional step 4630, the base station transmits the user data carried in the transmission initiated by the host computer to the UE according to the teachings of the embodiments described throughout the present disclosure. At optional step 4640, the UE executes a client application related to the host application executed by the host computer.
[0128] FIG. 24 illustrates a method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments.
[0129] FIG. 24 is a flowchart illustrating a method implemented in a communication system according to an embodiment. The communication system may include a host computer, a base station, and a UE as described with reference to FIGS. 21 and 22. For simplicity of the present disclosure, only the drawing reference to FIG. 24 is included in this section. In step 4710 of the method, the host computer provides user data. In an optional sub-step (not shown), the host computer provides user data by executing a host application. In step 4720, the host computer initiates a transmission that conveys the user data to the UE. The transmission may proceed via the base station in accordance with the teachings of the embodiments described throughout the present disclosure. In step 4730 (which may be optional), the UE receives the user data conveyed in the transmission.
[0130] FIG. 25 illustrates a method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments.
[0131] FIG. 25 is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system may include a host computer, a base station, and a UE as described with reference to FIGS. 21 and 22. For simplicity of the present disclosure, only the reference to FIG. 25 is included in this section. In optional step 4810, the UE receives input data provided by the host computer. Additionally or alternatively, in step 4820, the UE provides user data. In optional sub-step 4821 of step 4820, the UE provides user data by executing a client application. In optional sub-step 4811 of step 4810, the UE executes a client application that provides user data in response to the received input data provided by the host computer. When providing user data, the executed client application may further consider user input received from the user. Regardless of the particular manner in which the user data is provided, the UE starts transmitting the user data to the host computer in optional sub-step 4830. In step 4840 of the method, the host computer receives the user data transmitted from the UE according to the teachings of the embodiments described throughout the present disclosure.
[0132] FIG. 26 illustrates a method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments.
[0133] FIG. 26 is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system can include a host computer, a base station, and a UE as described with reference to FIGS. 21 and 22. For simplicity of the present disclosure, only the drawing reference to FIG. 26 is included in this section. In optional step 4910, according to the teachings of the embodiments described throughout the present disclosure, the base station receives user data from the UE. In optional step 4920, the base station initiates transmission of the received user data to the host computer. In optional step 4930, the host computer receives the user data carried in the transmission initiated by the base station.
[0134] Any suitable steps, methods, features, functions, or benefits disclosed herein may be implemented through one or more functional units or modules of one or more virtual devices. Each virtual device may comprise several of these functional units. These functional units may be implemented via a processing circuit, which may include one or more microprocessors or microcontrollers, and other digital hardware, which may include a digital signal processor (DSP), dedicated digital logic, etc. The processing circuit may be configured to execute program code stored in a memory, which may include one or several types of memory, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory devices, optical storage devices, etc. The program code stored in the memory includes program instructions for executing one or more communication and / or data communication protocols, and instructions for performing one or more of the techniques described herein. In some implementations, the processing circuit may be used to cause each functional unit to perform a corresponding function according to one or more embodiments of the present disclosure.
[0135] The term "unit" may have its ordinary meaning in the field of electronics, electrical devices, and / or electronic devices, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solids and / or discrete devices, computer programs or instructions, etc. for performing respective task, procedure, calculation, output, and / or display functions such as those described herein.
[0136] Further provisions and embodiments are discussed below.
[0137] In the above description of various embodiments of the inventive concept, it should be understood that the technical terms used herein are for the purpose of describing specific embodiments only and do not limit the inventive concept. Unless otherwise defined, all terms (including technical and scientific terms) used herein shall have the same meaning as commonly understood by one of ordinary skill in the art to which the inventive concept pertains. Terms such as those defined in commonly used dictionaries shall be interpreted as having a meaning conforming to their meaning in the context of this specification and the relevant art, and shall not be interpreted in an idealized or overly formal sense unless expressly so defined herein.
[0138] When an element is said to be "connected to", "coupled to", "responsive to", or a variation thereof, with respect to another element, the element can be directly connected to, coupled to, or responsive to the other element, or intervening elements may be present. In contrast, when an element is said to be "directly connected to", "directly coupled to", "directly responsive to", or a variation thereof, with respect to another element, no intervening elements are present. Like reference numerals refer to like elements throughout. Moreover, as used herein, "coupled", "connected", "responsive", or variations thereof can include wirelessly coupled, wirelessly connected, or wirelessly responsive. As used herein, the singular forms "a", "an", and "the" are to be construed to include the plural forms as well, unless the context clearly dictates otherwise. For brevity and / or clarity, well-known functions or constructions may not be described in detail. The term "and / or" (abbreviated " / ") includes any and all combinations of one or more of the associated listed items.
[0139] To describe various elements / acts, the terms first, second, third, etc. may be used herein, but it should be understood that these elements / acts are not to be limited by these terms. These terms are only used to distinguish one element / act from another. Thus, a first element / act in some embodiments may be referred to as a second element / act in other embodiments without departing from the teachings of the inventive concept. The same reference numeral or the same reference sign indicates the same or similar elements throughout this specification.
[0140] As used herein, the terms "comprise," "comprising," "comprises," "include," "including," "includes," "have," "has," "having," or variations thereof are open-ended and include one or more recited features, integers, elements, steps, components, or functions, but do not preclude the presence or addition of one or more other features, integers, elements, steps, components, functions, or groups thereof. Moreover, as used herein, the common abbreviation "e.g.", which is derived from the Latin phrase "exempli gratia," may be used to introduce or specifically recite one or more general examples of the foregoing items and is not limiting of such items. The common abbreviation "i.e.", which is derived from the Latin phrase "id est," may be used to specifically recite a particular item from a more general recitation.
[0141] Exemplary embodiments are described herein with reference to block diagrams and / or flowchart illustrations of a computer-implemented method, an apparatus (system and / or device), and / or a computer program product. It should be understood that the blocks of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by computer program instructions executed by one or more computer circuits. These computer program instructions can be provided to the processor circuits of a general-purpose computer circuit, a dedicated computer circuit, and / or other programmable data processing circuits for creating machines, and thus, the instructions executed via the processor of a computer and / or other programmable data processing apparatus transform and control transistors, values stored in memory locations, and other hardware components within such circuits to implement the functions / acts specified in one or more blocks of the block diagrams and / or flowcharts, and thereby, create means (functions) and / or structures for implementing the functions / acts specified in the blocks of the block diagrams and / or flowcharts.
[0142] These computer program instructions can also be stored in a tangible computer-readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, and thus, the instructions stored in the computer-readable medium produce a manufacture including instructions for implementing the functions / acts specified in one or more blocks of the block diagrams and / or flowcharts. Accordingly, embodiments of the inventive concept can be embodied in hardware and / or software (including firmware, resident software, microcode, etc.) running on a processor such as a digital signal processor, which may sometimes be generically referred to as a "circuit", a "module", or a variation thereof.
[0143] Also, in some alternative implementations, it should be noted that the functions / acts recited in a block may occur out of the order recited in the flowchart. For example, depending on the functions / acts involved, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order. Additionally, the functionality of a given block in a flowchart and / or block diagram may be split into multiple blocks, and / or the functionality of two or more blocks in a flowchart and / or block diagram may be at least partially integrated. Finally, without departing from the scope of the inventive concept, other blocks may be added / inserted between the blocks shown, and / or blocks / acts may be omitted. Additionally, although some of the figures include arrows on communication paths to indicate a primary direction of communication, it should be understood that communication may occur in the direction opposite to that shown by the drawn arrows.
[0144] Many variations and modifications can be made to the embodiments without substantially departing from the principles of the inventive concept. All such variations and modifications are intended to be included herein within the scope of the inventive concept. Accordingly, the subject matter disclosed above should be regarded as illustrative and not restrictive, and the examples of embodiments are intended to cover all such modifications, extensions, and other embodiments that fall within the spirit and scope of the inventive concept. Thereby, to the maximum extent permitted by law, the scope of the inventive concept should be determined by the broadest permissible interpretation of this disclosure, including examples of embodiments and their equivalents, and should not be limited or restricted by the above detailed description.
Claims
1. A method for establishing a secure connection in a wireless communication network, the method being executed by a control network node (500, 900) of the wireless communication network, the method comprising: Receiving (1000) a request to use a communication service provided by the wireless communication network, the request including an indication that a communication device (300, 902) can support authentication and key management (AKMA) services for the requested communication service and applications provided by the wireless communication network; Determining (1002) whether the requested communication service and the AKMA service can be provided to the communication device (300, 902); Communicating (1004) information indicating whether the requested communication service and the AKMA service can be provided to the communication device for establishing the secure connection in the wireless communication network, to the communication device (300, 902); comprising: Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) includes: Obtaining AKMA service availability information indicating whether an application function (AF) (904) of the wireless communication network can provide the AKMA service; A method.
2. The method according to claim 1, wherein the control network node (500, 900) includes a policy control function (PCF) network node (900) of the wireless communication network.
3. The method according to claim 1 or 2, wherein the requested communication service is provided by the AF (904).
4. The method according to any one of claims 1 to 3, wherein the requested communication service includes a proximity service (ProSe) provided by the AF (904).
5. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) includes: Obtaining information indicating whether the communication device (300, 902) is permitted to use the AKMA service. including the method according to any one of claims 1 to 4.
6. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) is based on the AKMA service availability information, the AF (904) determines (1100) that it can provide the AKMA service; and based on the information indicating whether the communication device (300, 902) is permitted to use the AKMA service, the communication device (300, 902) determines (1102) that it is permitted to use the AKMA service including communicating the information indicating whether the requested communication service and the AKMA service can be provided to the communication device is that the communication device (300, 902) communicates (1104) to the communication device (300, 902) information indicating that it is permitted to use the AKMA service using the AF (904) to establish the secure connection to receive the requested communication service including the method according to claim 5.
7. The method according to any one of claims 1 to 6, wherein the information indicating whether the requested communication service and the AKMA service can be provided to the communication device includes an address associated with the AF (904) that can provide the AKMA service and the requested communication service.
8. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) is based on the AKMA service availability information, the AF (904) determines (1200) that it cannot provide the AKMA service; and based on the information indicating whether the communication device (300, 902) is permitted to use the AKMA service, the communication device (300, 902) determines (1202) that it is permitted to use the AKMA service including communicating the information indicating whether the requested communication service and the AKMA service can be provided to the communication device communicating (1204) to the communication device (300, 902) information indicating that the communication device (300, 902) cannot use the AKMA service using the AF (904) to establish the secure connection to receive the requested communication service comprising The method according to claim 5
9. The method according to any one of claims 1 to 5 and 8, wherein the information indicating whether the requested communication service and the AKMA service can be provided to the communication device includes an address associated with the AF (904) that can provide the requested communication service
10. Determining whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) includes determining (1300) based on the AKMA service availability information that the AF (904) can provide the AKMA service determining (1302) based on the information indicating whether the communication device (300, 902) is permitted to use the AKMA service that the communication device (300, 902) is not permitted to use the AKMA service determining (1304) that the requested communication service and the AKMA service cannot be provided to the communication device (300, 902) based on the information indicating that the communication device (300, 902) is not permitted to use the AKMA service and the information indicating that the AF (904) providing the requested communication service supports the AKMA service comprising The method according to claim 5
11. communicating the information indicating whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) to the communication device (300, 902) Communicating (1306) information indicating that the requested communication service and the AKMA service cannot be provided to the communication device (300, 902), wherein the information indicating whether the requested communication service and the AKMA service can be provided to the communication device does not include the address of the AF (904) that can provide the requested communication service including The method according to any one of claims 1 to 5 and 10 **Claim 12** A method for establishing a secure connection in a wireless communication network, the method being executed by a communication device (300, 902) operating in the wireless communication network, the method comprising communicating (1400) a request to a control network node in the wireless communication network and for using a communication service provided by the wireless communication network, the request including an indication that the communication device (300, 902) can support authentication and key management (AKMA) services for the requested communication service and an application provided by the wireless communication network in response to communicating the request, receiving (1402) a communication from the control network node comprising information indicating whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) to establish the secure connection in the wireless communication network including Whether the requested communication service and the AKMA service can be provided to the communication device (300, 902) is determined by the control network node obtaining AKMA service availability information indicating whether the application function (AF) (904) of the wireless communication network can provide the AKMA service, a method **Claim 13** Communicating the request includes communicating the request towards a policy control function (PCF) network node (500, 900) as the control network node of the wireless communication network Receiving, from the PCF network node (500, 900), the communication comprising the information indicating whether the requested communication service and the AKMA service can be provided to the communication device (300, 902). The method according to claim 12.
14. The method according to claim 12 or 13, wherein the requested communication service is provided by the AF (904).
15. The method according to any one of claims 12 to 14, wherein the requested communication service comprises a proximity service (ProSe) provided by the AF (904).
16. Based on the address of the AF (904) included in the communication and the information indicating that the requested communication service and the AKMA service can be provided to the communication device (300, 902) to establish the secure connection in the wireless communication network, establishing (1404) the secure connection with the AF (904) using the AKMA service to use the requested communication service from the AF (904). The method according to any one of claims 12 to 15, further comprising.
17. Establishing the secure connection includes generating (1500) pre-shared key (PSK) identification information based on an AKMA key identifier (A-KID) associated with the AKMA service; communicating (1502) a message comprising a pre-shared key (PSK) extension comprising the PSK identification information, the A-KID, and an AKMA hint, towards the AF (904), wherein the AKMA hint indicates to the AF (904) that the communication device (300, 902) supports the AKMA service and desires to use the AKMA service to establish the secure connection; receiving (1504) a communication comprising PSK identification information for the secure connection from the AF (904); and establishing (1506) the secure connection with the AF (904) based on the PSK identification information including The method according to any one of claims 12 to 16.
18. Based on the address of the AF (904) included in the communication and information indicating that the requested communication service can be provided to the communication device (300, 902) without using the AKMA service to establish the secure connection in the wireless communication network, establishing the secure connection with the AF (904) to receive the requested communication service from the AF (904). The method according to any one of claims 12 to 15, further comprising the above.
19. A method for establishing a secure connection in a wireless communication network, the method being executed by a network node (500, 904) of the wireless communication network, the method comprising: The network node receiving (1600) a request for AKMA service availability information indicating whether the AKMA service can be provided to establish a secure connection for the requested communication service between a communication device (300, 902) operating in the wireless communication network and the network node (500, 904) from a core network node (500, 902); The network node (500, 904) communicating (1602) the AKMA service availability information indicating whether the AKMA service can be provided to establish the secure connection for the requested communication service to the core network node (500, 902). A method comprising the above.
20. The network node (500, 904) includes an application function (AF) of the wireless communication network configured to provide the requested communication service. The core network node (500, 902) includes a policy control function (PCF) network node (902) of the wireless communication network. The method according to claim 19.
21. The method according to claim 19 or 20, wherein the requested communication service includes a proximity service (ProSe) provided by the AF (904).
22. The AKMA service availability information indicates that the network node (500, 904) can provide the AKMA service, and the method receiving (1700) from the communication device (300, 902) a message comprising a pre-shared key (PSK) extension based on an AKMA key identifier (A-KID) associated with the AKMA service, the A-KID, and an AKMA hint, wherein the AKMA hint indicates to the AF (904) that the communication device (300, 902) supports the AKMA service and desires to use the AKMA service to establish the secure connection, communicating (1702) a communication comprising PSK identification information for the secure connection towards the communication device (300, 902), establishing (1704) the secure connection with the communication device (300, 902) based on the PSK identification information further comprising The method according to any one of claims 19 to 21.
23. The AKMA service availability information indicates that the network node cannot provide the AKMA service, and the method providing the requested communication service to the communication device (300, 902) without using the AKMA service further comprising The method according to any one of claims 19 to 21.
24. A communication device (300), a processing circuit (303), a memory (305) coupled to the processing circuit comprising, wherein the memory contains instructions which, when executed by the processing circuit, cause the communication device to perform the operations according to any one of claims 12 to 18. Communication device (300).
25. A communication device (300) adapted to perform according to any one of claims 12 to 18.
26. A computer program comprising program code to be executed by a processing circuit (303) of a communication device (300), whereby execution of the program code causes the communication device (300) to perform the operations according to any one of claims 12 to 18.
27. A core network (CN) node (500, 900), a processing circuit (503), A memory (505) coupled to the processing circuit and comprising the memory includes instructions that, when executed by the processing circuit, cause the CN node (500, 900) to perform the operation according to any one of claims 1 to 11 a core network (CN) node (500, 900).
28. A core network (CN) node (500, 900) adapted to perform according to any one of claims 1 to 11
29. A computer program comprising program code to be executed by a processing circuit (403) of a core network (CN) node (500, 900), whereby execution of the program code causes the CN node (500, 900) to perform the operation according to any one of claims 1 to 11
30. A network node (500, 904), comprising a processing circuit (503), a memory (505) coupled to the processing circuit and comprising the memory includes instructions that, when executed by the processing circuit, cause the network node (500, 904) to perform the operation according to any one of claims 19 to 23 a network node (500, 904).
31. A network node (500, 904) adapted to perform according to any one of claims 19 to 23
32. A computer program comprising program code to be executed by a processing circuit (403) of a network node (500, 904), whereby execution of the program code causes the network node (500, 904) to perform the operation according to any one of claims 19 to 23
Citation Information
Patent Citations
Method and apparatus for interworking between networks in a wireless communication system
JP2019525690A
Privacy protection and extensible authentication protocol authentication and autorization in cellular networks
US20200068391A1