Supporting remote user equipment authentication via relay user equipment

The implementation of a U2N connection mapping ID in relay UE authentication systems clarifies message routing between relay UE, relay AMF, and AUSF, addressing ambiguity and enhancing authentication efficiency for remote UEs.

JP7807554B2Active Publication Date: 2026-01-27TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024539667
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-12-30
Filing Date
2022-08-23
Publication Date
2026-01-27
Estimated Expiration
2042-08-23

AI Technical Summary

Technical Problem

Existing authentication methods for remote user equipment (UE) via relay UE in 3GPP specifications lack clarity in identifying and routing authentication messages between the relay UE, the relay AMF, and the AUSF, leading to ambiguity and inefficiencies in the authentication process.

Method used

Implementing a UE-to-network (U2N) connection mapping identity (ID) to identify and route authentication messages, allowing the relay UE and relay AMF to distinguish between relay UE and remote UE communications, and maintain mappings for accurate authentication message handling.

Benefits of technology

Enhances the ability to authenticate remote UEs via relay UEs with improved clarity and efficiency, enabling concurrent authentication of multiple remote UEs and minimizing impact on existing standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007807554000006
    Figure 0007807554000006
  • Figure 0007807554000007
    Figure 0007807554000007
  • Figure 0007807554000008
    Figure 0007807554000008
Patent Text Reader

Abstract

A system and method for supporting remote UE authentication via a relay user equipment (UE) is disclosed. In one embodiment, the method implemented by the relay UE includes receiving a first message communicated by the remote UE and sending a second message to a relay access and mobility function (AMF), the second message including a UE-to-network (U2N) connection mapping identity (ID) that identifies the remote UE. In this manner, the relay UE and the relay AMF are able to identify that the second message (e.g., an authentication-related message) is for the remote UE. Also disclosed are embodiments of a relay UE, an embodiment of a relay AMF, and an embodiment of a method of operation thereof.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Related Applications This application claims the benefit of Provisional Patent Application No. 63 / 294,920, filed December 30, 2021, the entire disclosure of which is incorporated herein by reference.

[0002] Embodiments relating to functionality for supporting authentication of a remote user equipment (UE) via a relay UE are disclosed. [Background technology]

[0003] Background on Control Plane-Based Solutions for Remote UE Authorization

[0004] The 3rd Generation Partnership Project (3GPP) Technical Specification (TS) 33.503 v0.2.0 section 6.3.3.3, reproduced below, specifies a control plane-based solution for remote user equipment (UE) authorization. In 3GPP TS33.503 v0.2.0 section 6.3.3.3, PC5 is the reference point where a UE communicates directly with another UE, ID stands for identification, AMF stands for Access and Mobility Function, AUSF stands for Authentication Server Function, UDM stands for Unified Data Management, 5G stands for Next Generation, PCF stands for Policy Control Function, DCR stands for Direct Communication Request, SUCI stands for Subscription Privacy Identifier, U2N stands for UE-to-Network, NAS stands for Non-Access Stratum, SMC stands for Security Mode Command, and FFS stands for Further Considerations. Figure 1 shows Figure 6.3.3.3.2-1 of 3GPP TS33.503 v0.2.0. *****BEGIN EXCERPT FROM 3GPP TS33.503***** 6.3.3.3 Security procedures on the control plane Editor's note: This section describes security procedures that rely on primary authentication procedures to authenticate / authorize a UE during 5G ProSe UE-to-network relay communication. 6.3.3.3.1 Overview This subclause describes the security mechanisms for L3 U2N relay authentication, authorization, and key management using primary authentication for PC5 key establishment. The network entities AMF, AUSF, and UDM are responsible for the key derivation and distribution used for UE-network relay communication. The UE shall be provisioned with the necessary policies and parameters for using 5G ProSe services as part of the UE ProSe policy information, as specified in TS 23.503... clause 4.2.2. The PCF shall provision the authorization policies and parameters for 5G UE-network relay discovery and communication, as specified in TS 23.304... clause 5.1.4. 6.3.3.3.2 UE-Network Relay Connection with Network Prose Security Context Setup During PC5 Link Establishment This subclause describes the procedure for a remote UE to establish a PC5 link between the remote UE and the UE-network relay. The procedure includes how the remote UE is authenticated by the AUSF via the relay UE and the AMF of the relay UE during 5G ProSe PC5 establishment. The mechanism can be used by the remote UE while out of coverage. [Figure 6.3.3.3.2-1 of 3GPP TS33.503 v0.2.0 is shown in Figure 1] Figure 6.3.3.3.2-1: UE-Network Relay Security Procedure with Network Prose Security Context Setup during PC5 Link Establishment 0. The remote UE and relay UE shall be registered with the network. The UE-Network Relay shall be authenticated and authorized by the network to support as a relay UE. The remote UE shall be authenticated and authorized by the network to act as a remote UE. 1. The remote UE shall initiate the discovery procedure using either the Model A method or the Model B method as specified in clause 6.3.1.2 or clause 6.3.1.3 of TS 23.304... respectively. 2-5. After UE-Network Relay discovery, the remote UE shall send a Direct Communication Request to the relay UE to establish a secure PC5 unicast link. The remote UE shall include its security capabilities and security policy in the DCR message as specified in TS33.536.... The message shall also include the SUCI, Relay Service Code, and Nonce_1. Upon receiving the DCR message, the relay UE shall send a Relay Key Request to the Relay AMF, including the parameters received in the DCR message. The Relay AMF shall verify whether the Relay UE is authorized to act as a U2N relay. The Relay AMF shall select an AUSF based on the SUCI and forward the Key Request to the AUSF in a Nausf_UEAuthentication_Authenticate request message. 6-7. The AUSF shall retrieve the authentication vector from the UDM and trigger the primary authentication of the remote UE using existing procedures as specified in TS33.501.... This authentication is performed between the AUSF and the remote UE via the relay AMF and the relay UE. The AUSF shall not make the newly derived KAUSF the latest KAUSF. In the remote UE, the newly derived KAUSF shall not be taken as the latest KAUSF since no NAS SMC procedure is performed between the remote UE and the relay AMF. Editor's note: Further details on authentication message handling in the UE, AMF and AUSF of the relay UE are available in the FFS. Editor's note: There are essentially two different KAUSF keys. To avoid confusion and misunderstanding, different key names should be used. This is FFS. Editor's Note: To separate different functions and service logic, a new service behavior should be used for Prose authentication to distinguish it from the primary authentication specified in 33.501. This is FFS. 8. Upon successful primary authentication, the AUSF and remote UE shall use the newly derived KAUSF to generate a 5GPRUK (as specified in Annex A.2) and a 5GPRUK ID as specified in Annex A.3. 9. The AUSF shall generate KNR_ProSe keys as specified in Annex A.4. 10-11. The AUSF shall send the PC5 GPRUK ID, KNR_ProSe, and Nonce_2 in the Nausf_UEAuthentication_Authenticate response message to the UE-Network Relay via the Relay AMF. Upon receiving KNR_ProSe from the AUSF, the AMF shall not attempt to trigger a NAS SMC procedure with the remote UE. The Relay UE shall derive the PC5 session key Krelay-sess and confidentiality and integrity keys from KNR_ProSe using the KDF specified in section 6.3.3.3.4 of this document. The KNR_ProSe ID and Krelay-sess ID are established in the same way as the KNRP ID and KNRP-sess ID in TS 33.536 [6]. 12. The UE-Network Relay shall send the received 5GPRUK ID, Nonce_2, to the remote UE in a Direct Security Mode Command message. 13-14. The remote UE shall use the 5GPRUK ID to find the KAUSF / 5GPRUK to be used for PC5 link security. The remote UE shall generate the KNR_ProSe key to be used for remote access via the relay UE in the same manner as specified in step 9. The remote UE shall derive the PC5 session key Krelay-sess and confidentiality and integrity keys from KNR_ProSe in the same manner as specified in step 11. The remote UE shall send a Security Mode Complete message directly to the UE-Network Relay. Further communication between the remote UE and the network is performed securely via a UE-to-network relay. Editor's note: Further details regarding the need for and use of the 5GPRUK ID are available at FFS. *****End excerpt from 3GPP TS33.503*****

[0005] Background on UE Certification

[0006] 3GPP TS24.501 v17.4.0 clause 5.4.1.2 specifies the Extensible Authentication Protocol (EAP) based primary authentication and key agreement procedure and is reproduced below. In 3GPP TS24.501, ngKSI stands for Key Set Identifier for Next Generation Radio Access Networks and 5GMM stands for 5G System Mobility Management. Figure 2 shows Figure 5.4.1.2.1.1 of 3GPP TS24.501. *****BEGIN EXCERPT FROM 3GPP TS24.501***** 5.4.1.2 EAP-based Primary Authentication and Key Agreement Procedure 5.4.1.2.1 Overview The purpose of the EAP-based primary authentication and key agreement procedure is to provide mutual authentication between the UE and the network and to agree on the keys KAUSF, KSEAF and KAMF (see 3GPP TS33.501...). The Extensible Authentication Protocol (EAP), as specified in IETF RFC3748..., allows authentication using a variety of EAP methods. EAP defines four types of EAP messages. a) an EAP request message; b) an EAP response message; c) an EAP success message, and d) EAP failure message. Several rounds of exchanges of EAP request messages and associated EAP response messages may be required to achieve authentication (see example in Figure 5.4.1.2.1.1). The EAP-based primary authentication and key agreement procedure is always initiated and controlled by the network. The EAP request message, ngKSI and ABBA are transported from the network to the UE using the Authentication Request message of the EAP Message Reliable Transport procedure. The EAP Response message is transported from the UE to the network using the Authentication Response message of the EAP Message Reliable Transport procedure. If the UE has been successfully authenticated and the serving AMF intends to initiate a security mode control procedure after the EAP-based primary authentication and key agreement procedure, and the security mode control procedure intends to start using the partial native 5G NAS security context created by the EAP-based primary authentication and key agreement procedure, the EAP success message and the ngKSI are transported from the network to the UE using the security mode command message of the security mode control procedure (see subclause 5.4.2). If the UE authentication is completed successfully and the serving AMF does not intend to initiate a security mode control procedure and start using the partial native 5G NAS security context created by the EAP-based primary authentication and key agreement procedure, the EAP success message and ngKSI are transported from the network to the UE using the authentication result message of the EAP result message transport procedure. NOTE 1: The serving AMF shall not initiate the security mode control procedure after the EAP-based primary authentication and key agreement procedure, e.g. in case of AMF relocation during the registration procedure. If the UE authentication is not completed successfully, an EAP Failure message is transported from the network to the UE using the Authentication Result message or the Authentication Reject message of the EAP Result Message Transport procedure or in response to an initial 5GMM procedure of which the EAP-based primary authentication and key agreement procedure is performed. The AMF shall set the authenticator retransmission timer specified in IETF RFC3748

[34] subclause 4.3 to an infinite value. NOTE 2: The EAP message reliable transport procedure provides reliable transport of EAP messages, so that no retransmissions are performed at the EAP layer. The AUSF and AMF support the exchange of EAP messages using N12. The UE shall detect and handle duplicate EAP messages as specified in IETF RFC3748... [Figure 5.4.1.2.1.1 of 3GPP TS24.501 is shown in Figure 2.] Figure 5.4.1.2.1.1: EAP-based primary authentication and key agreement procedure *****End excerpt from 3GPP TS24.501*****

[0007] 3GPP TS24.501 clauses 8.2.1 to 8.2.5 specify the messages used for UE authentication. Those clauses are reproduced below: *****BEGIN EXCERPT FROM 3GPP TS24.501***** 8.2.1 Authentication Request 8.2.1.1 Message Conventions The authentication request message is sent by the AMF to the UE to initiate authentication of the UE identity. See Table 8.2.1.1.1. Message Type: Authentication Request Efficacy: Dual Direction: Network to UE TIFF0007807554000001.tif1241708.2.2 Authentication Response 8.2.2.1 Message Conventions The authentication response message is sent by the UE to the AMF to deliver the calculated authentication response to the network. See Table 8.2.2.1.1. Message Type: Authentication Response Efficacy: Dual Direction: UE to network TIFF0007807554000002.tif831708.2.3 Authentication result 8.2.3.1 Message Conventions The Authentication Result message is sent by the AMF to the UE to provide the result of EAP authentication of the UE identity. See Table 8.2.3.1.1. Message Type: Authentication Result Efficacy: Dual Direction: Network to UE TIFF0007807554000003.tif1031708.2.4 Authentication failed 8.2.4.1 Message Conventions The authentication failure message is sent by the UE to the AMF to indicate that network authentication has failed. See Table 8.2.4.1.1. Message Type: Authentication Failure Efficacy: Dual Direction: UE to network TIFF0007807554000004.tif731708.2.5 Authentication denied 8.2.5.1 Message Conventions The Authentication Reject message is sent by the AMF to the UE to indicate that the authentication procedure has failed and that the UE shall abort all activities, see Table 8.2.5.1.1. Message Type: Authentication Rejection Efficacy: Dual Direction: Network to UE TIFF0007807554000005.tif72170*****END EXCERPT FROM 3GPP TS24.501***** Summary of the Invention

[0008] A system and method for supporting remote UE authentication via a relay user equipment (UE) is disclosed. In one embodiment, the method performed by the relay UE includes receiving a first message communicated by the remote UE and sending a second message to a relay access and mobility function (AMF), the second message including a UE-to-network (U2N) connection mapping identity (ID) that identifies the remote UE. In this manner, the relay UE and the relay AMF can identify that the second message (e.g., an authentication-related message) is intended for the remote UE.

[0009] In one embodiment, the second message further includes a subscription concealment ID of the remote UE. In one embodiment, the second message further includes the relay service code received in the first message, the nonce received in the first message, or both the relay service code received in the first message and the nonce received in the first message.

[0010] In one embodiment, the second message is a relay key request.

[0011] In one embodiment, the first message is a direct communication request (DCR) message.

[0012] In one embodiment, the method further includes receiving a first authentication message communicated by the relay AMF, the authentication message including a U2N connection mapping ID that identifies a remote UE, and sending a second authentication message to the remote UE identified by the U2N connection mapping ID included in the first authentication message. In one embodiment, the first authentication message further includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the second authentication message includes the EAP message and / or one or more parameters. In one embodiment, the second authentication message is a PC5-S message. In one embodiment, the first authentication message is a relay authentication request.

[0013] In one embodiment, the method further includes receiving a third authentication message communicated by the remote UE and sending a fourth authentication message to the relay AMF, where the fourth authentication message includes a U2N connection mapping ID that identifies the remote UE. In one embodiment, the third authentication message includes an EAP message and / or one or more parameters, and the fourth authentication message includes an EAP message and / or one or more parameters. In one embodiment, the third authentication message is a PC5-S message.

[0014] In one embodiment, the method further includes receiving a Relay Key Response message conveyed by the Relay AMF, where the Relay Key Response message includes a U2N Connection Mapping ID that identifies a remote UE, and sending a message to the remote UE identified by the U2N Connection Mapping ID included in the Relay Key Response message. In one embodiment, the Relay Key Response message includes a 5GPRUK ID, K NR_ProSe , and / or Nonce_2, and the sent message includes the 5GPRUK ID and / or Nonce_2. NR_ProSe deriving a PC5 session key Krelay-sess and / or confidentiality and integrity keys from the message. In one embodiment, the sent message is a Direct Security Mode command.

[0015] In one embodiment, the method further includes receiving a direct security completion message communicated by the remote UE.

[0016] In one embodiment, the method further includes allocating a U2N connection mapping ID to the remote UE.

[0017] In one embodiment, the U2N connection mapping ID is a temporary ID.

[0018] In one embodiment, the method further includes storing a mapping between a U2N connection mapping ID and an ID of the remote UE. In one embodiment, the ID of the remote UE is a Layer 2 ID of the remote UE.

[0019] In one embodiment, the U2N connection mapping ID is the Layer 2 ID of the remote UE.

[0020] In one embodiment, the U2N connection mapping ID is the publicly available subscription identifier (GPSI) of the remote UE.

[0021] In one embodiment, the U2N connection mapping ID is the user information ID of the remote UE.

[0022] Corresponding embodiments of a relay UE are also disclosed. In one embodiment, the relay UE is adapted to receive a first message communicated by a remote UE and to send a second message to the relay AMF, where the second message includes a U2N connection mapping ID that identifies the remote UE.

[0023] In one embodiment, a relay UE comprises a communication circuit and a processing circuit associated with the communication circuit, the processing circuit configured to cause the relay UE to receive a first message communicated by a remote UE and to send a second message to the relay AMF, the second message including a U2N connection mapping ID that identifies the remote UE.

[0024] An embodiment of a method implemented by a relay AMF is also disclosed. In one embodiment, the method implemented by the relay AMF includes receiving a first message communicated by a relay UE, the first message including a U2N connection mapping ID that identifies a remote UE. The method further includes selecting an Authentication Server Function (AUSF), storing a mapping between the U2N connection mapping ID and an ID of the selected AUSF, and sending a second message to the selected AUSF.

[0025] In one embodiment, the first message further includes a subscription concealment identifier of the remote UE. In one embodiment, the first message further includes a relay service code, a nonce, or both a relay service code and a nonce.

[0026] In one embodiment, the first message is a relay key request.

[0027] In one embodiment, the second message sent to the selected AUSF includes (a) a subscription concealment identifier of the remote UE, (b) a relay service code, (c) a nonce, or (d) a combination of any two or more of (a)-(d).

[0028] In one embodiment, the second message sent to the selected AUSF includes a subscription masking identifier of the remote UE, and selecting the AUSF includes selecting the AUSF based on the subscription masking identifier of the remote UE.

[0029] In one embodiment, the message sent to the selected AUSF is a Nausf_UEAuthentication_Authenticate request message.

[0030] In one embodiment, the method further includes verifying that the relay UE is authorized to act as a U2N relay.

[0031] In one embodiment, the method further includes sending a first authentication message to the relay UE, the first authentication message including the U2N connection mapping ID. In one embodiment, the first authentication message further includes an EAP message and / or one or more parameters.

[0032] In one embodiment, the method further includes receiving a second authentication message communicated by the relay UE, the second authentication message including a U2N connection mapping ID, and sending a third authentication message to the AUSF mapped to the USN connection mapping ID included in the second authentication message. In one embodiment, the second authentication message further includes an EAP message and / or one or more parameters, and the third authentication message includes the EAP message and / or one or more parameters included in the second authentication message. In one embodiment, sending the third authentication message to the AUSF includes calling a Nausf_UEAuthentication service of the AUSF. In one embodiment, the method further includes receiving an authentication response message communicated by the AUSF, the authentication response message including one or more parameters, and sending an authentication response message to the relay UE, the authentication response message including the U2N connection mapping ID and one or more parameters included in the received authentication response. In one embodiment, the sent authentication response message is a Relay Key Response. In one embodiment, the one or more parameters included in the received authentication response include: a 5GPRUK ID, a K NR_ProSe , and / or Nonce_2.

[0033] In one embodiment, the U2N connection mapping ID is a temporary ID.

[0034] In one embodiment, the U2N connection mapping ID is the Layer 2 ID of the remote UE.

[0035] In one embodiment, the U2N connection mapping ID is the GPSI of the remote UE.

[0036] In one embodiment, the U2N connection mapping ID is the user information ID of the remote UE (302).

[0037] Corresponding embodiments of a relay AMF are also disclosed. In one embodiment, the relay AMF is adapted to receive a first message communicated by a relay UE, the first message including a U2N connection mapping ID that identifies a remote UE. The relay AMF is further adapted to select an AUSF, store a mapping between the U2N connection mapping ID and an ID of the selected AUSF, and send the second message to the selected AUSF.

[0038] In one embodiment, the relay AMF comprises a network interface and a processing circuit associated with the network interface. The processing circuit is configured to cause the relay AMF to receive a first message communicated by a relay UE, the first message including a U2N connection mapping ID that identifies a remote UE. The processing circuit is further configured to cause the relay AMF to select an AUSF, store a mapping between the U2N connection mapping ID and an ID of the selected AUSF, and send the second message to the selected AUSF.

[0039] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate various aspects. [Brief explanation of the drawings]

[0040] [Figure 1] A diagram showing the UE-network relay security procedure involving the setup of a network Prose security context during PC5 link establishment. [Figure 2] FIG. 1 illustrates an EAP-based primary authentication and key agreement procedure. [Figure 3] FIG. 1 illustrates a system and flowchart according to some aspects. [Figure 4A] 1 is a flowchart illustrating a process, according to some embodiments. [Figure 4B]1 is a flowchart illustrating a process, according to some embodiments. [Figure 5] 1 is a flowchart illustrating a process, according to some embodiments. [Figure 6] FIG. 1 illustrates a user equipment, according to some aspects. [Figure 7] FIG. 1 illustrates an apparatus, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0041] In this application, the term "node" can be a network node or a user equipment (UE). Examples of network nodes include, but are not limited to, a Node B, a base station (BS), a MSR radio node such as a Multi-Standard Radio (MSR) BS, an eNodeB, a gNodeB, a master eNB (MeNB), a secondary eNB (SeNB), an integrated access backhaul (IAB) node, a network controller, a radio network controller (RNC), a base station controller (BSC), a relay, a donor node control relay, a base transceiver station (BTS), a central unit (e.g., in a gNB), a distributed unit (e.g., in a gNB), a base station controller (BSC), a UE, ... The network includes a baseband unit, a centralized baseband, a C-RAN, an access point (AP), a transmission point, a transmitting node, a remote radio unit (RRU), a remote radio head (RRH), a node in a distributed antenna system (DAS), a core network node (e.g., a mobile switching center (MSC), a mobility management entity (MME), etc.), an operation and management (O&M), an operation support system (OSS), a self-organizing network (SON), and a positioning node (e.g., an evolved serving mobile location center (E-SMLC)).

[0042] In this application, the term "user equipment" or "UE" is a non-limiting term that refers to any type of wireless device that communicates with network nodes and / or other UEs in a cellular or mobile communication system. Examples of UEs include, but are not limited to, target devices, device to device (D2D) UEs, vehicle to vehicle (V2V) UEs, machine type UEs, machine type communication (MTC) UEs, machine-to-machine (M2M) communication capable UEs, PDAs, tablets, mobile terminal(s), smartphones, laptop embedded equipment (LEEs), laptop mounted equipment (LMEs), and USB dongles.

[0043] In this application, the terms "radio network node," "network node," and "NW node" are general terms that refer to any type of network node, including, but not limited to, a base station, a radio base station, a base transceiver station, a base station controller, a network controller, an evolved Node B (eNB), a Node B, a gNode B (gNB), a relay node, an access point (AP), a radio access point, a remote radio unit (RRU), a remote radio head (RRH), a central unit (e.g., in a gNB), a distributed unit (e.g., in a gNB), a baseband unit, a centralized baseband, and a C-RAN.

[0044] In this application, the term "radio access technology" or "RAT" may refer to any RAT, including, for example and without limitation, UTRA, E-UTRA, Narrowband Internet of Things (NB-IoT), WiFi, Bluetooth, Next Generation RAT, New Radio (NR), 4G, and 5G. Any of the equipment denoted by the term "node," "network node," or "radio network node" may be capable of supporting a single RAT or multiple RATs.

[0045] 3rd Generation Partnership Project (3GPP) Technical Specification (TS) 33.503 v0.2.0, section 6.3.3.3.2, mentions that further details regarding authentication message handling in the UE, the Access and Mobility Function (AMF) of the relay UE, and the Authentication Server Function (AUSF) require further study. That is, 3GPP TS 33.503 v0.2.0 does not provide details of step 7 in Figure 6.3.3.3.2-1, which is reproduced in Figure 1 herein.

[0046] The existing authentication procedure is between a UE and a network (e.g., an AMF). If the same authentication message specified in 3GPP TS24.501 is used, when a relay UE receives an authentication message from an AMF, the relay UE cannot distinguish whether the message is (a) for itself or (b) for a remote UE. Furthermore, if the message is for a remote UE, the relay UE cannot distinguish which remote UE the message is for. Similarly, when a relay UE forwards an authentication message from a remote UE to an AMF, the AMF does not know whether the message is (a) for the relay UE or (b) for a remote UE. Furthermore, if the message is for a remote UE, the AMF does not know which remote UE the message is for. Therefore, the AMF does not know which AMF it needs to contact to proceed with the authentication procedure.

[0047] Aspects of the solution(s) disclosed herein may overcome one or more of the problems with existing solutions by having a relay UE use a UE-to-network (U2N) connection mapping identity (ID) (e.g., a temporary ID) to identify a remote UE by an AMF. In some aspects, the relay UE may provide the U2N connection mapping ID to the AMF. In some aspects where the U2N connection mapping ID is a temporary ID, the relay UE may allocate a temporary ID for the remote UE and provide the temporary ID to the AMF. In some aspects, the relay UE may maintain a mapping between the remote UE L2 ID and the temporary ID. In some aspects, when the AMF sends an authentication message for the remote UE to the relay UE, the AMF may include the U2N connection mapping ID (e.g., the temporary ID) in the authentication message. In some aspects, the relay UE may use the U2N connection mapping ID in the message from the AMF to know which remote UE the authentication message is for. In some aspects, the AMF may maintain a mapping between the U2N connection mapping ID and the AUSF ID of the remote UE. In some aspects, the AMF may use the mapping to forward Extensible Authentication Protocol (EAP) messages to the correct AUSF.

[0048] In one embodiment, the relay UE may use the U2N connection mapping ID in the authentication message to identify the remote UE for which the authentication message is intended. The relay UE may include the U2N connection mapping ID in a message to the relay AMF (e.g., an authentication and / or relay key request message). The relay AMF may store the mapping, the U2N connection mapping ID, and the ID of the authentication server function (AUSF). The relay AMF may receive a message from the AUSF (e.g., an authentication message and / or an authentication response message), use the mapping to select a U2N connection mapping ID, and include the U2N connection mapping ID in a message forwarded to the relay UE. The relay UE may receive the authentication message including the U2N connection mapping ID, use the U2N connection mapping ID to identify the remote UE, and send a PC5-S message to the remote UE.

[0049] Aspects of the solution(s) disclosed herein may provide the advantage of providing details regarding authentication message handling in the UE, the AMF of the relay UE, and the AUSF, with little impact on current standards. Aspects of the solution(s) disclosed herein may additionally or alternatively provide the advantage of the relay UE and the AMF being able to identify that an authentication is for a remote UE. In some aspects, in this way, the remote UE may be enabled to authenticate itself to the network via the relay UE. Aspects of the solution(s) disclosed herein may additionally or alternatively provide the advantage of enabling concurrent authentication of multiple remote UEs via the same relay UE.

[0050] One aspect of the solution(s) disclosed herein may provide a method implemented by a relay UE. The method may include receiving a message communicated by a remote UE. The method may include sending the message to a relay AMF. The sent message may include a U2N connection mapping ID that identifies the remote UE.

[0051] In some aspects, the message communicated by the remote UE may be a Direct Communication Request (DCR) message. In some aspects, the message communicated by the remote UE may include the security capabilities of the remote UE, the security policy of the remote UE, a Subscription Confidentiality Identifier (SUCI), a Relay Service Code, and / or Nonce_1. In some aspects, the sent message including the U2N Connection Mapping ID may further include the ID of the remote UE, a SUCI, a Relay Service Code, and / or Nonce_1. In some aspects, the sent message including the U2N Connection Mapping ID may be a Relay Key Request.

[0052] In some aspects, the method may further include receiving an authentication message conveyed by the relay AMF. The received authentication message may include a U2N connection mapping ID. In some aspects, the method may further include using the received U2N connection mapping ID to identify the remote UE. In some aspects, the method may further include sending the authentication message to the identified remote UE. In some aspects, the received authentication message may further include an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the sent authentication message may include the EAP message and / or one or more parameters. In some aspects, the sent authentication message may be a PC5-S message (e.g., a dedicated PC5-S message). In some aspects, the sent authentication message may include the U2N connection mapping ID. In some alternative aspects, the sent authentication message does not include the U2N connection mapping ID.

[0053] In some aspects, the method may further include receiving an authentication message communicated by the remote UE, where the received authentication message may include a U2N connection mapping ID. In some aspects, the method may further include sending an authentication message to the relay AMF, where the sent authentication message may include a U2N connection mapping ID.

[0054] In some aspects, the method may further include receiving an authentication message communicated by the remote UE, wherein the received authentication message does not include a U2N connection mapping ID. In some aspects, the method may further include sending an authentication message to the relay AMF, wherein the sent authentication message may include a U2N connection mapping ID.

[0055] In some aspects, the authentication message conveyed by the remote UE may include an EAP message and / or one or more parameters, and the authentication message sent to the relay AMF may include an EAP message and / or one or more parameters. In some aspects, the received authentication message is a PC5-S message (e.g., a dedicated PC5-S message).

[0056] In some aspects, the method may further include receiving a Relay Key Response message conveyed by the Relay AMF, where the Relay Key Response may include a U2N Connection Mapping ID. In some aspects, the method may further include using the received U2N Connection Mapping ID to identify the remote UE. In some aspects, the method may further include sending a message to the identified remote UE. In some aspects, the received Relay Key Response message may further include a 5GPRUK ID, a KNR_ProSe, and / or a Nonce_2, where the sent message may include the 5GPRUK ID and / or Nonce_2. In some aspects, the method may further include deriving a PC5 session key Krelay-sess and / or confidentiality and integrity keys from the KNR_ProSe. In some aspects, the sent message may be a Direct Security Mode Command.

[0057] In some aspects, the method may further include receiving a direct security completion message communicated by the remote UE.

[0058] In some aspects, the method may further include allocating a U2N connection mapping ID to the remote UE. In some aspects, the U2N connection mapping ID may be a temporary ID. In some aspects, the method may further include storing a mapping between the U2N connection mapping ID and an ID of the remote UE. In some aspects, the ID of the remote UE may be a Layer 2 ID of the remote UE.

[0059] In some aspects, the U2N connection mapping ID may be a Layer 2 ID of the remote UE. In some alternative aspects, the U2N connection mapping ID may be a Public Subscription Identifier (GPSI) of the remote UE. In some alternative aspects, the U2N connection mapping ID may be a User Info ID of the remote UE.

[0060] Another aspect of the solution(s) disclosed herein may provide a relay user UE. The relay UE may be configured to receive a message communicated by a remote UE. The relay UE may be configured to send a message to the relay AMF, and the sent message may include a U2N connection mapping ID that identifies the remote UE.

[0061] Yet another aspect of the solution(s) disclosed herein may provide a method implemented by a relay AMF. The method may include receiving a message communicated by a relay UE, where the message may include a U2N connection mapping ID. The method may include selecting an AUSF. The method may include storing a mapping between the U2N connection mapping ID and an ID of the selected AUSF. The method may include sending a message to the selected AUSF.

[0062] In some aspects, the message communicated by the relay UE may be a relay key request.

[0063] In some aspects, the message conveyed by the relay UE may further include the ID of the remote UE, the SUCI of the remote UE, a relay service code, and / or Nonce_1. In some aspects, the ID of the remote UE may be the Layer 2 ID of the remote UE. In some aspects, the message sent to the selected AUSF may include the SUCI of the remote UE, the relay service code, and / or Nonce_1. In some aspects, the AUSF may be selected based on the SUCI of the remote UE.

[0064] In some aspects, the message sent to the selected AUSF may be a Nausf_UEAuthentication_Authenticate request message. In some aspects, the method may further include verifying that the relay UE is authorized to act as a U2N relay.

[0065] In some aspects, the method may further include sending an authentication message to the relay UE, where the authentication message may include the U2N connection mapping ID. In some aspects, the authentication message may further include an Extensible Authentication Protocol (EAP) message and / or one or more parameters.

[0066] In some aspects, the method may further include receiving an authentication message communicated by the relay UE, where the received authentication message may include a U2N connection mapping ID. In some aspects, the method may further include using the received U2N connection mapping ID and the mapping to identify a selected AUSF. In some aspects, the method may further include sending the authentication message to the identified AUSF. In some aspects, the received authentication message may further include an EAP message and / or one or more parameters, where the sent authentication message may include the EAP message and / or one or more parameters. In some aspects, sending the authentication message to the identified AUSF may include calling a Nausf_UEAuthentication service of the identified AUSF.

[0067] In some aspects, the method may further include receiving an authentication response message communicated by the AUSF, where the authentication response message may include one or more parameters. In some aspects, the method may further include using the mapping to select a U2N connection mapping ID. In some aspects, the method may further include sending an authentication response message to the relay UE, where the authentication response message may include the one or more parameters and the selected U2N connection mapping ID. In some aspects, the sent authentication response message may be a Relay Key Response. In some aspects, the one or more parameters may include a 5GPRUK ID, a KNR_ProSe, and / or a Nonce_2.

[0068] In some aspects, the U2N connection mapping ID may be a temporary ID. In some alternative aspects, the U2N connection mapping ID may be a Layer 2 ID of the remote UE. In some alternative aspects, the U2N connection mapping ID may be a GPSI of the remote UE. In some alternative aspects, the U2N connection mapping ID may be a User Info ID of the remote UE.

[0069] Another aspect of the present invention may provide a relay AMF. The relay AMF may be configured to receive a message transmitted by a relay UE, where the message may include a U2N connection mapping ID. The relay AMF may be configured to select an AUSF. The relay AMF may be configured to store a mapping between the U2N connection mapping ID and an ID of the selected AUSF. The relay AMF may be configured to send a message to the selected AUSF.

[0070] Yet another aspect of the solution(s) described herein may provide a method implemented by a relay UE. The method may include receiving an authentication message conveyed by the relay AMF, where the received authentication message may include an EAP message and / or one or more parameters. The method may include sending a PC5-S message to the remote UE, where the PC5-S message may include the EAP message and / or one or more parameters.

[0071] In some aspects, the received authentication message may include a U2N connection mapping ID, and the method may further include using the U2N connection mapping ID to identify the remote UE. In some aspects, the sent authentication message may include the U2N connection mapping ID. In some alternative aspects, the sent authentication message does not include the U2N connection mapping ID.

[0072] In some aspects, the method may further include receiving a DCR message communicated by the remote UE.

[0073] In some aspects, the method may further include sending a relay key request including a U2N connection mapping ID. In some aspects, the DCR message may include the security capabilities of the remote UE, the security policy of the remote UE, a SUCI, a relay service code, and / or Nonce_1. In some aspects, the relay key request may further include the ID of the remote UE, a SUCI, a relay service code, and / or Nonce_1.

[0074] In some aspects, the method may further include allocating a U2N connection mapping ID to the remote UE. In some aspects, the method may further include storing a mapping between the U2N connection mapping ID and an ID of the remote UE. In some aspects, using the U2N connection mapping ID to identify the remote UE may include using the U2N connection mapping ID and the mapping to identify the remote UE. In some aspects, the ID of the remote UE may be a Layer 2 ID of the remote UE.

[0075] In some aspects, the method may further include receiving an authentication message communicated by the remote UE, wherein the received authentication message may include a U2N connection mapping ID. In some aspects, the method may further include sending an authentication message to a relay AMF, wherein the sent authentication message may include the U2N connection mapping ID. In some alternative aspects, the method may further include receiving an authentication message communicated by the remote UE, wherein the received authentication message does not include the U2N connection mapping ID. In some aspects, the method may further include identifying a U2N connection mapping ID and sending an authentication message to the relay AMF, wherein the sent authentication message may include the identified U2N connection mapping ID.

[0076] In some aspects, the authentication message conveyed by the remote UE may include an EAP message and / or one or more parameters, and the authentication message sent to the relay AMF may include an EAP message and / or one or more parameters. In some aspects, the received authentication message may be a PC5-S message (e.g., a dedicated PC5-S message).

[0077] In some aspects, the method may further include receiving a Relay Key Response message conveyed by the Relay AMF, where the Relay Key Response may include a U2N Connection Mapping ID. In some aspects, the method may further include using the received U2N Connection Mapping ID to identify the remote UE. In some aspects, the method may further include sending a Direct Security Mode Command to the identified remote UE. In some aspects, the received Relay Key Response message may further include a 5GPRUK ID, a KNR_ProSe, and / or a Nonce_2, where the Direct Security Mode Command may include the 5GPRUK ID and / or Nonce_2. In some aspects, the method may further include deriving a PC5 session key Krelay-sess and / or a confidentiality and integrity key from the KNR_ProSe.

[0078] In some aspects, the U2N connection mapping ID may be a temporary ID. In some alternative aspects, the U2N connection mapping ID may be a Layer 2 ID of the remote UE. In some alternative aspects, the U2N connection mapping ID may be a GPSI of the remote UE. In some alternative aspects, the U2N connection mapping ID may be a User Info ID of the remote UE.

[0079] In some aspects, the method may further include receiving a direct security completion message communicated by the remote UE. In some aspects, the PC5-S message is a dedicated PC5-S message.

[0080] Another aspect of the solution(s) described herein may provide a relay UE. The relay UE may be configured to receive an authentication message conveyed by the relay AMF. The relay UE may be configured to send the authentication message to the remote UE, where the sent authentication message may be a PC5-S message.

[0081]

[0010] Yet another aspect of the solution(s) described herein may provide a computer program comprising instructions for adapting an apparatus to perform any of the methods described above. Yet another aspect of the invention may provide a carrier containing the computer program, the carrier being one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.

[0082] Yet another aspect of the solution(s) described herein may provide an apparatus including a processing circuit and a memory, the memory including instructions executable by the processing circuit such that the apparatus is operable to perform any of the methods described above.

[0083] Yet another aspect of the solution(s) described herein may provide an apparatus adapted to any of the methods described above.

[0084] Yet another aspect of the solution(s) described herein may provide any combination of the aspects described above.

[0085] 3 illustrates a system 300 according to some aspects. In some aspects, the system 300 may include one or more nodes, as illustrated in FIG. 3. In some aspects, the nodes of the system 300 may include a remote UE 302, a relay UE 304, a remote AMF 306, a relay AMF 308, an AUSF 310 (e.g., a remote AUSF), and / or a unified data management (UDM) 310. In some aspects, the system 300 may implement a process 350.

[0086] In some aspects, process 350 may include step 1, which may include one or more of steps 0-2 as shown in FIG. 1 and described in 3GPP TS33.503 v0.2.0 section 6.3.3.3.2. That is, in some aspects, step 1 of process 350 may include the remote UE 302 and / or relay UE 304 registering with the network as shown in steps 0a and / or 0b of FIG. 1 and / or described in step 0 of 3GPP TS33.503 v0.2.0 section 6.3.3.3.2. In some aspects, the UE-network relay (e.g., the relay UE 304) may be authenticated and authorized by the network to support as a relay UE. In some aspects, the remote UE 302 shall be authenticated and authorized by the network to act as a remote UE. In some aspects, step 1 of process 350 may additionally or alternatively include the remote UE 302 initiating a discovery procedure (e.g., using either the Model A method or the Model B method, as specified in TS 23.304 subsections 6.3.1.2 or 6.3.1.3, respectively) as shown in step 1 of FIG. 1 and / or described in step 1 of 3GPP TS 33.503 v0.2.0 section 6.3.3.3.2. In some aspects, step 1 of process 350 may include the remote UE 302 sending a Direct Communication Request (DCR) message to the relay UE 304 after UE-to-network relay discovery to establish a secure PC5 unicast link, as shown in step 2 of FIG. 1 and / or described in steps 2-5 of 3GPP TS 33.503 v0.2.0 section 6.3.3.3.2. In some aspects, the remote UE 302 may include its security capabilities and / or security policy in the DCR message (e.g., as specified in 3GPP TS33.536). In some aspects, the DCR message may additionally or alternatively include a subscription concealment identifier (SUCI), a relay service code, and / or a Nonce_1.

[0087] In some aspects, the process 350 may include step 2, in which the relay UE 304, upon receiving the DCR message, allocates a temporary ID for the remote UE 302. In some aspects, the relay UE 102 may keep a mapping between the temporary ID and the ID of the remote UE 302 (e.g., the Layer 2 ID of the remote UE 302).

[0088] In some aspects, the process 350 may include step 3, in which the relay UE 304 sends a relay key request to the relay AMF 308, and the relay AMF 308 receives the relay key request. In some aspects, the relay key request may include a temporary ID, an ID of the remote UE 302 (e.g., a Layer 2 ID of the remote UE 302), and / or one or more of the parameters received in the DCR message (e.g., a SUCI of the remote UE 302, a relay service code, and / or Nonce_1).

[0089] In some aspects, the process 350 may include step 4, in which the relay AMF 308 verifies whether the relay UE 304 is authorized to act as a UE-to-network (U2N) relay. In some aspects, in step 4, the relay AMF 308 may select the AUSF 310 based on the SUCI of the remote UE 302, which may be received in the relay key request in step 3. For example, in some aspects, the relay AMF 308 may select the AUSF 310 based on a routing indicator in the SUCI of the remote UE 302. In some aspects, the relay AMF 308 may maintain a mapping between a temporary ID (e.g., the temporary ID received in the relay key request in step 3) and the ID of the AUSF 310 selected for the remote UE 302. In some aspects, in step 4, the relay AMF 308 may forward the relay key request to the selected AUSF 310 in a Nausf_UEAuthentication_Authenticate request message. In some aspects, the Nausf_UEAuthentication_Authenticate request message may include the ID of the remote UE 302 (e.g., the Layer 2 ID of the remote UE 302) and / or one or more of the parameters that the relay UE 304 received in the DCR message (e.g., the SUCI of the remote UE 302, the relay service code, and / or Nonce_1).

[0090] In some aspects, in step 4, the AUSF 310 may receive the forwarded relay key request. In some aspects, in step 4, the AUSF 310 may retrieve the authentication vector from the UDM 312 (e.g., using a Nudm_UEAuthentication_Get message). In some aspects, in step 4, the AUSF 310 may trigger primary authentication of the remote UE 302 (e.g., using existing procedures as specified in 3GPP TS33.501).

[0091] 1 and described in 3GPP TS33.503 v0.2.0 section 6.3.3.3.2, the relay AMF 308 further maintains a mapping between the temporary ID and the AUSF ID. In some aspects, the relay AMF 308 may then use the mapping to forward the EAP message to the correct AUSF 310.

[0092] In some aspects, the process 350 may include steps 5 and 6, where the remote UE 302 and the relay AMF 308 exchange authentication messages via the relay UE 304. That is, in some aspects, the process 350 may include step 5, where the relay AMF 308 sends an authentication message to the remote UE 302 via the relay UE 304. In some aspects, the authentication message may be, for example, an authentication request, a rejection, a failure, or a result message. In some aspects, the authentication message sent by the relay AMF 308 in step 5 and received by the relay UE 304 may include a temporary ID, an EAP message, and / or one or more parameters. In some aspects, the relay UE 304 may use the temporary ID and the mapping to identify the remote UE 302 to which the authentication message should be forwarded.

[0093] In some aspects, step 5 may include step 5a, in which the relay UE 304 forwards an authentication message to the remote UE 302 identified by the temporary ID and the mapping. In some aspects, the relay UE 304 may use a PC5-S message (e.g., a dedicated PC5-S message) to forward the authentication message to the remote UE 302. In some aspects, the relay UE 304 may determine a destination Layer 2 ID of the PC5-S message according to the mapping between the Layer 2 ID of the remote UE 302 and the temporary ID. In some aspects, the authentication message forwarded by the relay UE 304 to the remote UE 302 may include an EAP message and / or one or more parameters. In some aspects, the authentication message forwarded by the relay UE 304 to the remote UE 302 may further include the temporary ID. In some alternative aspects, the relay UE 304 may remove the temporary ID from the authentication message forwarded by the relay UE 304 to the remote UE 302. In some aspects, in step 5, the remote UE 302 may receive the authentication message forwarded by the relay UE 304.

[0094] In some aspects, the process 350 may include step 6, in which the remote UE 302 sends an authentication message to the relay AMF 308 via the relay UE 304. In some aspects, the authentication message may be, for example, an authentication request, rejection, failure, or result message. In some aspects, step 6 may include step 6a, in which the remote UE 302 sends the authentication message and the relay UE 304 receives the authentication message. In some aspects, the remote UE 302 may use a PC5-S message (e.g., a dedicated PC5-S message) to send the authentication message to the relay 304. In some aspects, the authentication message sent by the remote UE 302 and received by the relay UE 304 in step 6a may include an EAP message and / or one or more parameters. In some aspects, if the authentication message received by the remote UE 302 in step 5a includes a temporary ID, the remote UE 302 may include the temporary ID in the authentication message sent by the remote UE 302 and received by the relay UE 304 in step 6a.

[0095] In some aspects, step 6 may include the relay UE 304 forwarding the authentication message to the relay AMF 308. In some aspects, the authentication message forwarded by the relay UE 304 to the relay AMF 308 may include an EAP message and / or one or more parameters. In some aspects, the authentication message forwarded by the relay UE 304 to the remote UE 302 may further include a temporary ID. In some aspects, if the authentication message sent by the remote UE 302 and received by the relay UE 304 in step 6 includes a temporary ID (e.g., the temporary ID included in the authentication message received by the remote UE 302 in step 5), the authentication message forwarded by the relay UE 304 to the relay AMF 308 may include the temporary ID in the authentication message sent by the remote UE 302 and received by the relay UE 304 in step 6. In some aspects, if the authentication message sent by the remote UE 302 and received by the relay UE 304 in step 6 does not include a temporary ID (e.g., because the relay UE 304 removed the temporary ID from the authentication message forwarded to the remote UE 302 in step 5), the relay UE 304 may add the temporary ID allocated for the remote UE 302 (e.g., the temporary ID allocated for the remote UE 302 in step 2). In an aspect, in step 6, the relay AMF 308 may receive the authentication message forwarded by the relay UE 304.

[0096] In some aspects, the authentication messages exchanged in steps 5 and 6 may be messages specified in 3GPP TS24.501 (e.g., authentication request, authentication response, authentication rejection, authentication failure, or authentication result). In some alternative aspects, the authentication messages exchanged in steps 5 and 6 may be new types of messages (e.g., remote UE authentication request, response, rejection, failure, or result).

[0097] In some aspects, the process 350 may include step 7, in which the relay AMF 308 forwards the EAP message (e.g., the EAP message of the authentication message received by the relay AMF 308 in step 6) to the AUSF 310. In some aspects, the relay AMF 308 may use the temporary ID in the authentication message received in step 6 and the mapping between the temporary ID and the AUSF ID to identify the correct AUSF 310 to which the EAP message should be forwarded. In some aspects, the relay AMF 308 may call a Nausf_UEAuthentication service of the AUSF 310 to forward the EAP message (e.g., based on the mapping between the temporary ID and the ID of the AUSF 310 selected for the remote UE 302). In some aspects, in step 7, the AUSF 310 may receive the EAP message.

[0098] 1 and described in 3GPP TS33.503 v0.2.0 section 6.3.3.3.2, where the relay AMF 308 includes the temporary ID in a relay key response message sent to the relay UE 304. That is, in some aspects, step 8 of process 350 may include, upon successful primary authentication (e.g., in steps 5-7 of process 350), the AUSF 310 and the remote UE 102 may use the newly derived KAUSF to generate a 5GPRUK (e.g., as specified in Annex A.2 of 3GPP TS33.503) and generate a 5GPRUK ID (e.g., as specified in Annex A.3 of 3GPP TS33.503). In some aspects, step 8 of process 350 may be implemented by determining whether AUSF 310 is a K NR_ProSeIn some aspects, step 8 of the process 350 may include the AUSF 310 transmitting the GPRUK ID, K in a Nausf_UEAuthentication_Authenticate response message to the UE-to-network relay via the relay AMF 308. NR_ProSe , and / or sending Nonce_2.

[0099] In some aspects, the relay AMF 308 may include (e.g., in a Nausf_UEAuthentication_Authenticate response message) the 5GPRUK ID, K NR_ProSe , and / or Nonce_2 and send a Relay Key Response to the Relay UE 304. In some aspects, the Relay AMF 308 may include a Temporary ID in the Relay Key Response. In some aspects, the Relay AMF 308 may select a Temporary ID to include in the Relay Key Response based on a mapping between the Temporary ID and the ID of the AUSF 310, which may then select the 5GPRUK ID, K, selected for the remote UE 302. NR_ProSe , and / or Nonce_2. NR_ProSe When receiving K, the relay AMF 308 may not attempt to trigger a NAS SMC procedure with the remote UE 302. In some aspects, the relay UE 304 may use a KDF (e.g., as specified in clause 6.3.3.3.4 of 3GPP TS33.503) to NR_ProSe In some embodiments, the PC5 session key Krelay-sess and confidentiality and integrity keys may be derived from K NR_ProSe The ID and Krelay-sess ID can be established in the same manner as the KNRP ID and KNRP-sess ID in TS33.536.

[0100] In some aspects, step 8 of the process 350 may involve the relay UE 304 receiving a GPRUK ID, K NR_ProSe, Nonce_2, and / or a temporary ID. In some aspects, the UE-network relay (e.g., the relay UE 304) may send the received 5GPRUK ID and / or Nonce_2 (e.g., in the direct security mode command message) to the remote UE 302. In some aspects, the relay UE 304 may use the received temporary ID and a mapping between the temporary ID and the remote UE ID to identify the remote UE 302 for sending the 5GPRUK ID and / or Nonce_2. In some aspects, the relay UE 304 may include the received temporary ID in the direct security mode command message to the remote UE 302. However, this is not required, and in some alternative aspects, the relay UE 304 may include the received temporary ID in the direct security mode command message to the remote UE 302.

[0101] In some aspects, step 8 of process 350 may include the remote UE 302 using the 5GPRUK ID (e.g., received in the Direct Security Mode Command message) to find the KAUSF and / or 5GPRUK to be used for PC5 link security. In some aspects, the remote UE 302 finds the KAUSF and / or 5GPRUK to be used for remote access via the relay UE 304 in the same manner as described above. NR_ProSe In some aspects, the remote UE 302 may generate the key K in the same manner as defined above. NR_ProSe The remote UE 302 may derive a PC5 session key Krelay-sess and confidentiality and integrity keys from the UE. In some aspects, the remote UE 302 may send a security mode complete message directly to the UE-to-network relay.

[0102] In some aspects, the process 350 may include the relay UE 304 deleting or discarding the temporary ID after the remote UE 302 completes the authentication procedure for the remote UE 302.

[0103] In some aspects, the temporary ID may be used as a UE-to-Network (U2N) connection mapping identity (ID). In some alternative aspects, an existing ID of the remote UE 302 (e.g., a Layer 2 ID of the remote UE 302, a Publicly-Public Subscription Identifier (GPSI) of the remote UE 302, a User Info ID of the remote UE 302 from the application layer) may be used instead of the temporary ID allocated by the relay UE 304 in step 2 of process 350.

[0104] 4A illustrates a process 400 performed by the relay UE 302, according to some aspects. In some aspects, as shown in FIG. 4A, the process 400 may include step 402, in which the relay UE 304 receives a message communicated by the remote UE 302.

[0105] 4A, the process 400 may include step 408, in which the relay UE 304 sends a message to the relay access and mobility function (AMF) 308. The sent message may include a UE-to-network (U2N) connection mapping identity (ID) that identifies the remote UE 302.

[0106] In some aspects, as shown in FIG. 4A , process 400 may include optional step 404, in which the relay UE 304 assigns a U2N connection mapping ID to the remote UE 302. In some aspects, the U2N connection mapping ID may be a temporary ID. In some aspects, as shown in FIG. 4A , process 400 may include optional step 406, in which the relay UE 304 stores a mapping between the U2N connection mapping ID and the ID of the remote UE 302. In some aspects, the ID of the remote UE 302 may be the Layer 2 ID of the remote UE 302. In some alternative aspects, the U2N connection mapping ID may be a Public Subscription Identifier (GPSI) of the remote UE 302. In some further alternative aspects, the U2N connection mapping ID may be a user information ID of the remote UE 302 (e.g., from an application layer). In some aspects (e.g., in some aspects where the U2N connection mapping ID is the Layer 2 ID of the remote UE 302), process 400 may not include step 404 and step 406. In some alternative aspects (e.g., in some aspects where the U2N connection mapping ID is the GPSI or user information ID of the remote UE 302), process 450 may not include step 404 but may include step 406, and the mapping may be between the GPSI or user information ID of the remote UE 302 and the Layer 2 ID of the remote UE 302.

[0107] In some aspects, the message communicated by the remote UE 302 and received by the relay UE 304 in step 408 may be a Direct Communication Request (DCR) message. In some aspects, the message communicated by the remote UE 302 and received by the relay UE 304 in step 408 may include the security capabilities of the remote UE 302, the security policy of the remote UE 302, a Subscription Concealment Identifier (SUCI), a Relay Service Code, and / or Nonce_1. In some aspects, the message including the U2N Connection Mapping ID sent to the relay AMF 308 in step 408 may further include the ID of the remote UE 302, a SUCI, a Relay Service Code, and / or Nonce_1. In some aspects, the message including the U2N Connection Mapping ID sent to the relay AMF 308 in step 408 may be a Relay Key Request.

[0108] 4A , the process 400 may include an optional step 410 in which the relay UE 304 receives an authentication message communicated by the relay AMF 308. In some aspects, the received authentication message may include a U2N connection mapping ID. In some aspects, the optional step 410 may further include using the received U2N connection mapping ID to identify the remote UE 302. In some aspects, the remote UE 302 may be identified using a stored mapping between the U2N connection mapping ID and the ID of the remote UE 302 (e.g., if the relay UE 304 allocates a temporary ID to the remote UE 302) or using the U2N connection mapping ID itself (e.g., if the U2N connection mapping ID is the Layer 2 ID, GPSI, or user information ID of the remote UE 302).

[0109] 4A , process 400 may include optional step 412, in which the relay UE 304 sends an authentication message to the remote UE 302 identified in step 410. In some aspects, the authentication message received in step 410 may further include an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the authentication message sent in step 412 may include the EAP message and / or one or more parameters. In some aspects, the authentication message sent in step 412 may be a PC5-S message (e.g., a dedicated PC5-S message). In some aspects, the authentication message sent in step 412 may include a U2N connection mapping ID. In some alternative aspects, the authentication message sent in step 412 does not include a U2N connection mapping ID.

[0110] In some aspects, as shown in FIG. 4A , process 400 may include optional step 414, in which the relay UE 304 receives an authentication message communicated by the remote UE 302. In some aspects, the authentication message received in step 414 may include a U2N connection mapping ID. In some alternative aspects, the authentication message received in step 414 does not include a U2N connection mapping ID. In some aspects in which the authentication message received in step 414 does not include a U2N connection mapping ID, step 414 may include identifying the U2N connection mapping ID (e.g., using a stored mapping between the U2N connection mapping ID and the ID of the remote UE 302). In some aspects, as shown in FIG. 4A , process 400 may include optional step 416, in which the relay UE 304 sends an authentication message to the relay access and mobility function (AMF) 308, and the authentication message sent in step 416 may include the U2N connection mapping ID. In some aspects, the authentication message communicated by the remote UE 302 and received by the relay UE 304 in step 414 may include an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the authentication message sent to the relay AMF 308 in step 416 may include the EAP message and / or one or more parameters. In some aspects, the authentication message received in step 414 may include a PC5-S message (e.g., a dedicated PC5-S message).

[0111] 4A , the process 400 may include an optional step 418 in which the relay UE 304 receives a relay key response message communicated by the relay AMF 308, where the relay key response may include a U2N connection mapping ID. In some aspects, the step 418 may further include using the received U2N connection mapping ID to identify the remote UE 302. In some aspects, the relay UE 308 may identify the remote UE 302 using a stored mapping between the U2N connection mapping ID and the ID of the remote UE 302 (e.g., if the relay UE 304 allocates a temporary ID to the remote UE 302) or using the U2N connection mapping ID itself (e.g., if the U2N connection mapping ID is the Layer 2 ID, GPSI, or user information ID of the remote UE 302).

[0112] 4A , process 400 may include optional step 420, in which the relay UE 304 sends a message to the identified remote UE 302. In some aspects, the relay key response message received in step 418 may further include a 5GPRUK ID, a KNR_ProSe, and / or a Nonce_2, and the message sent in step 420 may include the 5GPRUK ID and / or a Nonce_2. In some aspects, process 400 further includes deriving a PC5 session key Krelay-sess and / or confidentiality and integrity keys from the KNR_ProSe. In some aspects, the message sent in step 420 may be a direct security mode command.

[0113] In some aspects, as shown in FIG. 4A, the process 400 may include an optional step 422 in which the relay UE 304 receives a direct security completion message communicated by the remote UE 302.

[0114] 4B illustrates a process 450 performed by the relay UE 302, according to some aspects. In some aspects, as shown in FIG. 4B, the process 450 may include an optional step 452 in which the relay UE 304 receives a direct communication request (DCR) message communicated by the remote UE 302.

[0115] 4B , process 450 may include optional step 458, in which the relay UE 304 sends a relay key request including the U2N connection mapping ID. In some aspects, the DCR message received in step 452 may include the security capabilities of the remote UE 302, the security policy of the remote UE 302, a subscription concealment identifier (SUCI), a relay service code, and / or Nonce_1. In some aspects, the relay key request sent in step 458 may further include the ID of the remote UE 302, the SUCI, the relay service code, and / or Nonce_1.

[0116] In some aspects, as shown in FIG. 4B , process 450 may include optional step 454, in which the relay UE 304 assigns a U2N connection mapping ID to the remote UE 302. In some aspects, the U2N connection mapping ID may be a temporary ID. In some aspects, as shown in FIG. 4B , process 450 may include optional step 456, in which the relay UE 304 stores a mapping between the U2N connection mapping ID and the ID of the remote UE 302. In some aspects, the ID of the remote UE 302 may be the Layer 2 ID of the remote UE 302. In some alternative aspects, the U2N connection mapping ID may be a Public Subscription Identifier (GPSI) of the remote UE 302. In some further alternative aspects, the U2N connection mapping ID may be a user information ID of the remote UE 302 (e.g., from an application layer). In some aspects (e.g., in some aspects where the U2N connection mapping ID is the Layer 2 ID of the remote UE 302), process 450 may not include step 454 and step 456. In some alternative aspects (e.g., in some aspects where the U2N connection mapping ID is the GPSI or user info ID of the remote UE 302), process 450 may not include step 454 but may include step 456, and the stored mapping may be, for example, between the GPSI or user info ID of the remote UE 302 and the Layer 2 ID of the remote UE 302.

[0117] 4B , process 450 may include step 460, in which the relay UE 304 receives an authentication message communicated by the relay AMF 308, where the received authentication message may include an EAP message and / or one or more parameters. In some aspects, the authentication message received in step 460 may include a UE-to-Network (U2N) connection mapping identity (ID), where step 460 may further include using the U2N connection mapping ID to identify the remote UE 302. In some aspects, the relay UE 304 may identify the remote UE 302 in step 460 using a stored mapping between the U2N connection mapping ID and the ID of the remote UE 302 (e.g., if the relay UE 304 allocates a temporary ID to the remote UE 302) or using the U2N connection mapping ID itself (e.g., if the U2N connection mapping ID is the Layer 2 ID, GPSI, or user information ID of the remote UE 302).

[0118] 4B, process 450 may include step 462, in which relay UE 304 sends a PC5-S message to remote UE 302, where the PC5-S message may include an EAP message and / or one or more parameters. In some aspects, the PC5-S message is a dedicated PC5-S message. In some aspects, the authentication message sent in step 462 may include a U2N connection mapping ID. In some alternative aspects, the authentication message sent in step 462 does not include a U2N connection mapping ID.

[0119] 4B , process 450 may include optional step 464, in which relay UE 304 receives an authentication message communicated by remote UE 302. In some aspects, the received authentication message may include a U2N connection mapping ID. In some alternative aspects, the received authentication message does not include a U2N connection mapping ID. In some aspects where the authentication message received in step 414 does not include a U2N connection mapping ID, step 414 may include identifying the U2N connection mapping ID (e.g., using a stored mapping between the U2N connection mapping ID and the ID of the remote UE 302).

[0120] 4B , process 450 may include optional step 466, in which the relay UE 304 sends an authentication message to the relay AMF 308, where the sent authentication message may include a U2N connection mapping ID. In some aspects, the authentication message communicated by the remote UE 302 and received by the relay UE 304 in step 464 may include an EAP message and / or one or more parameters, and the authentication message sent to the relay AMF 308 in step 466 may include an EAP message and / or one or more parameters. In some aspects, the authentication message received in step 464 may be a PC5-S message (e.g., a dedicated PC5-S message).

[0121] 4B , the process 450 may include an optional step 468 in which the relay UE 304 receives a relay key response message communicated by the relay AMF 308, where the relay key response may include a U2N connection mapping ID. In some aspects, the step 468 may further include using the received U2N connection mapping ID to identify the remote UE 302. In some aspects, the relay UE 308 may identify the remote UE 302 using a stored mapping between the U2N connection mapping ID and the ID of the remote UE 302 (e.g., if the relay UE 304 allocates a temporary ID to the remote UE 302) or using the U2N connection mapping ID itself (e.g., if the U2N connection mapping ID is the Layer 2 ID, GPSI, or user information ID of the remote UE 302).

[0122] 4B , process 450 may include optional step 470, in which the relay UE 304 sends a direct security mode command to the identified remote UE 302. In some aspects, the relay key response received in step 468 may further include a 5GPRUK ID, a KNR_ProSe, and / or a Nonce_2, and the direct security mode command sent in step 470 may include the 5GPRUK ID and / or a Nonce_2. In some aspects, process 450 may further include the relay UE 304 deriving a PC5 session key Krelay-sess and / or confidentiality and integrity keys from the KNR_ProSe.

[0123] In some aspects, as shown in FIG. 4B, the process 450 may include an optional step 472 in which the relay UE 304 receives a direct security completion message communicated by the remote UE 302.

[0124] FIG. 5 shows a process 500 performed by the relay access and mobility function (AMF) 308.

[0125] In some aspects, process 500 may include step 502, in which relay AMF 308 receives a message communicated by relay user equipment (UE) 303, the message may include a UE-to-network (U2N) connection mapping identity (ID). In some aspects, the U2N connection mapping ID may be a temporary ID. In some alternative aspects, the U2N connection mapping ID may be a Layer 2 ID of the remote UE 302. In some other alternative aspects, the U2N connection mapping ID may be a publicly available subscription identifier (GPSI) of the remote UE 302. In some further alternative aspects, the U2N connection mapping ID may be a user information ID of the remote UE 302.

[0126] In some aspects, the message communicated by the relay UE 304 and received by the relay AMF 308 in step 502 may be a relay key request. In some aspects, the message communicated by the relay UE 304 and received by the relay AMF 308 in step 502 may further include an ID of the remote UE 302, a subscription concealment identifier (SUCI) of the remote UE 302, a relay service code, and / or Nonce_1. In some aspects, the ID of the remote UE 302 may be a Layer 2 ID of the remote UE 302.

[0127] In some aspects, the process 500 may include an optional step 504 in which the relay AMF 308 verifies that the relay UE 304 is authorized to act as a U2N relay.

[0128] In some aspects, the process 500 may include step 506, in which the relay AMF 308 selects an authentication server function (AUSF) 310. In some aspects, the AUSF may be selected based on the SUCI of the remote UE 302.

[0129] In some aspects, the process 500 may include step 508, in which the relay AMF 308 stores a mapping between the U2N connection mapping ID and the ID of the selected AUSF 310.

[0130] In some aspects, process 500 may include step 510, in which the relay AMF 308 sends a message to the selected AUSF 310. In some aspects, the message sent to the selected AUSF 310 in step 510 may include the SUCI, a relay service code, and / or Nonce_1 of the remote UE 302. In some aspects, the message sent to the selected AUSF 310 in step 510 may be a Nausf_UEAuthentication_Authenticate request message.

[0131] In some aspects, process 500 may include optional step 512, in which the relay AMF 308 sends an authentication message to the relay UE 304, where the authentication message may include a U2N connection mapping ID. In some aspects, the authentication message may further include an EAP message and / or one or more parameters.

[0132] In some aspects, process 500 may include optional step 514, in which the relay AMF 308 receives an authentication message communicated by the relay UE 304, where the received authentication message may include a U2N connection mapping ID. In some aspects, step 514 may further include using the received U2N connection mapping ID and the mapping to identify the selected AUSF 310.

[0133] In some aspects, process 500 may include optional step 516, in which the relay AMF 308 sends an authentication message to the identified AUSF 310. In some aspects, the authentication message received in step 514 may further include an EAP message and / or one or more parameters, and the authentication message sent in step 516 may include the EAP message and / or one or more parameters. In some aspects, sending the authentication message to the identified AUSF 310 in step 516 may include calling a Nausf_UEAuthentication service of the identified AUSF 310.

[0134] In some aspects, process 500 may include optional step 518, in which the relay AMF 308 receives an authentication response message communicated by the AUSF 310, where the authentication response message may include one or more parameters. In some aspects, step 518 may further include using the mapping to select a U2N connection mapping ID. In some aspects, process 500 may include optional step 520, in which the relay AMF 308 sends an authentication response message to the relay UE 304, where the authentication response message may include one or more parameters and the selected U2N connection mapping ID. In some aspects, the authentication response message sent in step 520 may be a Relay Key Response. In some aspects, the one or more parameters may include a 5GPRUK ID, a KNR_ProSe, and / or a Nonce_2.

[0135] 6 is a block diagram of a UE 600 (e.g., a UE 302 or a UE 304) according to some aspects. As shown in FIG. 6, the UE 600 may comprise a processing circuit (PC) 602, which may include one or more processors (P) 655 (e.g., one or more general-purpose microprocessors and / or one or more other processors, such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), etc.); a communication circuit 648, which may include a transmitter (Tx) 645 and a receiver (Rx) 647, coupled to an antenna arrangement 649 comprising one or more antennas to enable the UE 600 to transmit data and receive data (e.g., transmit / receive data wirelessly); and a local storage unit (a.k.a., a “data storage system”) 608, which may include one or more non-volatile storage devices and / or one or more volatile storage devices. In some aspects in which the PC 602 comprises a programmable processor, a computer program product (CPP) 641 may be provided. The CPP 641 includes a computer-readable medium (CRM) 642, which stores a computer program (CP) 643 comprising computer-readable instructions (CRI) 644. The CRM 1142 may be a non-transitory computer-readable medium, such as a magnetic medium (e.g., a hard disk), an optical medium, a memory device (e.g., a random access memory, a flash memory), or the like. In some aspects, the CRI 644 of the computer program 643, when executed by the PC 602, is configured such that the CRI causes the UE 600 to perform steps described herein (e.g., steps described herein with reference to flowcharts FIG. 3, FIG. 4A, and / or FIG. 4B). In other aspects, the UE 600 may be configured to perform steps described herein without the need for code. That is, for example, the PC 602 may simply consist of one or more ASICs. Thus, features of aspects described herein may be implemented in hardware and / or software.

[0136] 7 is a block diagram of a network node 700 (e.g., AMF 306, AMF 308, AUSF 310, and / or AUSF 312) according to some aspects. As shown in FIG. 7, the network node 700 includes a processing circuit (PC) 702 that may include one or more processors (P) 755 (e.g., one or more general-purpose microprocessors and / or one or more other processors, such as application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), etc.), which may be co-sited in a single housing or in a single data center or may be geographically distributed (i.e., the network node 704 may be a distributed computing device); and a network interface 768 that enables the network node 700 to communicate with the network to which the network interface 768 is connected. The network node 700 may comprise a network interface 768 having a transmitter (Tx) 765 and a receiver (Rx) 767 for enabling the network node 700 to transmit data to and receive data from other nodes connected to the network 110 (e.g., an Internet Protocol (IP) network); a communication circuit 748 having a transmitter (Tx) 745 and a receiver (Rx) 747 coupled to an antenna arrangement 749 having one or more antennas for enabling the network node 700 to transmit data and receive data (e.g., transmit / receive data wirelessly); and a local storage unit (a.k.a. "data storage system") 708, which may include one or more non-volatile storage devices and / or one or more volatile storage devices. In aspects in which the PC 702 includes a programmable processor, a computer program product (CPP) 741 may be provided. The CPP 741 includes a computer-readable medium (CRM) 742, which stores a computer program (CP) 743 comprising computer-readable instructions (CRI) 744. The CRM 742 may be a non-transitory computer-readable medium, such as a magnetic medium (eg, a hard disk), an optical medium, or a memory device (eg, a random access memory, a flash memory).In some aspects, the CRI 744 of the computer program 743, when executed by the PC 702, is configured such that the CRI causes the network node 700 to perform the steps described herein (e.g., steps described herein with reference to FIG. 5). In other aspects, the network node 700 may be configured to perform the steps described herein without the need for code. That is, for example, the PC 702 may simply consist of one or more ASICs. Thus, features of aspects described herein may be implemented in hardware and / or software.

[0137] Some exemplary embodiments of the present disclosure are as follows.

[0138] Embodiment A1: A method (400) implemented by a relay user equipment (UE) (304), the method including: receiving a message transmitted by a remote UE (302); and sending a message to a relay access and mobility function (AMF) (308), the sent message including a UE-to-network (U2N) connection mapping identity (ID) that identifies the remote UE.

[0139] Embodiment A2: The method of embodiment A1, wherein the message communicated by the remote UE is a direct communication request (DCR) message.

[0140] Embodiment A3: The method of embodiment A1 or A2, wherein the message transmitted by the remote UE includes the security capabilities of the remote UE, the security policy of the remote UE, a subscription concealment identifier (SUCI), a relay service code, and / or Nonce_1.

[0141] Embodiment A4: The method of embodiment A3, wherein the sent message including the U2N connection mapping ID further includes the ID of the remote UE, a SUCI, a relay service code, and / or Nonce_1.

[0142] Embodiment A5: The method of any one of embodiments A1 to A4, wherein the sent message including the U2N connection mapping ID is a relay key request.

[0143] Embodiment A6: The method of any one of embodiments A1 to A5, further comprising: receiving an authentication message communicated by a relay access and mobility function (AMF) (308), wherein the received authentication message includes a U2N connection mapping ID; using the received U2N connection mapping ID to identify a remote UE; and sending the authentication message to the identified remote UE.

[0144] Embodiment A7: The method described in embodiment A6, wherein the received authentication message further includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the sent authentication message includes an EAP message and / or one or more parameters.

[0145] Embodiment A8: The method of embodiment A6 or A7, wherein the sent authentication message is a PC5-S message (eg, a dedicated PC5-S message).

[0146] Embodiment A9: The method of any one of embodiments A6 to A8, wherein the sent authentication message includes a U2N connection mapping ID.

[0147] Embodiment A10: The method of any one of embodiments A6 to A8, wherein the sent authentication message does not include a U2N connection mapping ID.

[0148] Embodiment A11: The method of any one of embodiments A1 to A10, further comprising: receiving an authentication message transmitted by a remote UE, wherein the received authentication message includes a U2N connection mapping ID; and sending the authentication message to a relay access and mobility function (AMF) (308), wherein the sent authentication message includes a U2N connection mapping ID.

[0149] Embodiment A12: The method of any one of embodiments A1 to A10, further comprising: receiving an authentication message transmitted by a remote UE, wherein the received authentication message does not include a U2N connection mapping ID; and sending an authentication message to a relay access and mobility function (AMF) (308), wherein the sent authentication message includes a U2N connection mapping ID.

[0150] Embodiment A13: The method of embodiment A11 or A12, wherein the authentication message conveyed by the remote UE includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the authentication message sent to the relay AMF includes an EAP message and / or one or more parameters.

[0151] Embodiment A14: The method of any one of embodiments A11 to A13, wherein the received authentication message is a PC5-S message (eg, a dedicated PC5-S message).

[0152] Embodiment A15: The method of any one of embodiments A1 to A14, further comprising receiving a Relay Key Response message conveyed by a Relay Access and Mobility Function (AMF) (308), the Relay Key Response including a U2N Connection Mapping ID; using the received U2N Connection Mapping ID to identify a remote UE; and sending a message to the identified remote UE.

[0153] Embodiment A16: The received relay key response message includes the 5GPRUK ID, K NR_ProSe The method of embodiment A15, further comprising: a 5GPRUK ID and / or Nonce_2; and wherein the sent message includes the 5GPRUK ID and / or Nonce_2.

[0154] Embodiment A17:K NR_ProSe The method of embodiment A16, further comprising deriving a PC5 session key Krelay-sess and / or a confidentiality and integrity key from

[0155] Embodiment A18: The method of any one of embodiments A15 to A17, wherein the sent message is a direct security mode command.

[0156] Embodiment A19: The method of any one of embodiments A1 to A18, further comprising receiving a direct security completion message communicated by the remote UE.

[0157] Embodiment A20: The method of any one of embodiments A1 to A19, further comprising allocating a U2N connection mapping ID to the remote UE.

[0158] Embodiment A21: The method of embodiment A20, wherein the U2N connection mapping ID is a temporary ID.

[0159] Embodiment A22: The method of any one of embodiments A1 to A21, further comprising storing a mapping between a U2N connection mapping ID and an ID of the remote UE.

[0160] Embodiment A23: The method of embodiment A22, wherein the ID of the remote UE is a Layer 2 ID of the remote UE.

[0161] Embodiment A24: The method of any one of embodiments A1 to A19, wherein the U2N connection mapping ID is the Layer 2 ID of the remote UE.

[0162] Embodiment A25: The method of any one of embodiments A1 to A19, A22, and A23, wherein the U2N connection mapping ID is a publicly available subscription identifier (GPSI) of the remote UE.

[0163] Embodiment A26: The method of any one of embodiments A1 to A19, A22, and A23, wherein the U2N connection mapping ID is a user information ID of the remote UE.

[0164] Embodiment B1: A relay user equipment (UE) (304) configured to receive a message communicated by a remote UE (302) and to send a message to a relay access and mobility function (AMF) (308), the sent message including a UE-to-network (U2N) connection mapping identity (ID) that identifies the remote UE.

[0165] Embodiment C1: A method (500) performed by a relay access and mobility function (AMF) (308), the method including: receiving a message communicated by a relay user equipment (UE) (304), the message including a UE-to-network (U2N) connection mapping identification (ID); selecting an authentication server function (AUSF) (310); storing a mapping between the U2N connection mapping ID and the ID of the selected AUSF; and sending the message to the selected AUSF.

[0166] Embodiment C2: The method of embodiment C1, wherein the message communicated by the relay UE is a relay key request.

[0167] Embodiment C3: The method of embodiment C1 or C2, wherein the message conveyed by the relay UE further includes an ID of the remote UE (302), a subscription concealment identifier (SUCI) of the remote UE, a relay service code, and / or Nonce_1.

[0168] Embodiment C4: The method of embodiment C3, wherein the ID of the remote UE is a Layer 2 ID of the remote UE.

[0169] Embodiment C5: The method of embodiment C3 or C4, wherein the message sent to the selected AUSF includes the SUCI of the remote UE, a relay service code, and / or Nonce_1.

[0170] Embodiment C6: The method of any one of embodiments C3 to C5, wherein the AUSF is selected based on the SUCI of the remote UE.

[0171] Embodiment C7: The method of any one of embodiments C1 to C6, wherein the message sent to the selected AUSF is a Nausf_UEAuthentication_Authenticate request message.

[0172] Embodiment C8: The method of any one of embodiments C1 to C7, further comprising verifying that the relay UE is authorized to act as a U2N relay.

[0173] Embodiment C9: The method of any one of embodiments C1 to C8, further comprising sending an authentication message to the relay UE, the authentication message including a U2N connection mapping ID.

[0174] Embodiment C10: The method of embodiment C9, wherein the authentication message further includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters.

[0175] Embodiment C11: The method of any one of embodiments C1 to C11, further including: receiving an authentication message communicated by a relay UE, wherein the received authentication message includes a U2N connection mapping ID; using the received U2N connection mapping ID and the mapping to identify a selected AUSF; and sending the authentication message to the identified AUSF.

[0176] Embodiment C12: The method described in embodiment C11, wherein the received authentication message further includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the sent authentication message includes an EAP message and / or one or more parameters.

[0177] Embodiment C13: The method of embodiment C11 or C12, wherein sending the authentication message to the identified AUSF includes calling a Nausf_UEAuthentication service of the identified AUSF.

[0178] Embodiment C14: The method of any one of embodiments C1 to C13, further including: receiving an authentication response message communicated by the AUSF, the authentication response message including one or more parameters; using the mapping to select a U2N connection mapping ID; and sending an authentication response message to the relay UE, the authentication response message including the one or more parameters and the selected U2N connection mapping ID.

[0179] Embodiment C15: The method of embodiment C14, wherein the sent authentication response message is a relay key response.

[0180] Embodiment C16: The one or more parameters include a 5GPRUK ID, K NR_ProSe and / or Nonce_2.

[0181] Embodiment C17: The method of any one of embodiments C1 to C16, wherein the U2N connection mapping ID is a temporary ID.

[0182]

[0033] Embodiment C18: The method of any one of embodiments C1 to C16, wherein the U2N connection mapping ID is the Layer 2 ID of the remote UE (302).

[0183] Embodiment C19: The method of any one of embodiments C1 to C16, wherein the U2N connection mapping ID is a publicly available subscription identifier (GPSI) of the remote UE (302).

[0184]

[0033] Embodiment C20: The method of any one of embodiments C1 to C16, wherein the U2N connection mapping ID is a user information ID of the remote UE (302).

[0185] Embodiment D1: A relay access and mobility function (AMF) (308) configured to receive a message communicated by a relay user equipment (UE) (304), the message including a UE-to-network (U2N) connection mapping identification (ID), select an authentication server function (AUSF) (310), store a mapping between the U2N connection mapping ID and the ID of the selected AUSF, and send the message to the selected AUSF.

[0186] Embodiment E1: A method (450) performed by a relay user equipment (UE) (304), the method including: receiving an authentication message communicated by a relay access and mobility function (AMF) (308), the received authentication message including an Extensible Authentication Protocol (EAP) message and / or one or more parameters; and sending a PC5-S message to a remote UE (302), the PC5-S message including the EAP message and / or one or more parameters.

[0187] Embodiment E2: The method of embodiment E1, wherein the received authentication message includes a UE-to-network (U2N) connection mapping identification (ID), and the method further includes using the U2N connection mapping ID to identify the remote UE.

[0188] Embodiment E3: The method of embodiment E2, wherein the sent authentication message includes a U2N connection mapping ID.

[0189] Embodiment E4: The method of embodiment E2, wherein the sent authentication message does not include a U2N connection mapping ID.

[0190] Embodiment E5: The method of any one of embodiments E2 to E4, further comprising receiving a direct communication request (DCR) message communicated by a remote UE and sending a relay key request including a U2N connection mapping ID.

[0191]

[0033] Embodiment E6: The method of embodiment E5, wherein the DCR message includes the security capabilities of the remote UE, the security policy of the remote UE, a subscription concealment identifier (SUCI), a relay service code, and / or Nonce_1.

[0192]

[0033] Embodiment E7: The method of embodiment E6, wherein the relay key request further includes the ID of the remote UE, a SUCI, a relay service code, and / or Nonce_1.

[0193] Embodiment E8: The method of any one of embodiments E5 to E7, further comprising allocating a U2N connection mapping ID to the remote UE and storing a mapping between the U2N connection mapping ID and the ID of the remote UE.

[0194]

[0023] Embodiment E9: The method of embodiment E8, wherein using a U2N connection mapping ID to identify the remote UE includes using a U2N connection mapping ID and the mapping to identify the remote UE.

[0195]

[0033] Embodiment E10: The method of embodiment E9 or E10, wherein the ID of the remote UE is a Layer 2 ID of the remote UE.

[0196] Embodiment E11: The method of any one of embodiments E2 to E10, further comprising: receiving an authentication message communicated by a remote UE, wherein the received authentication message includes a U2N connection mapping ID; and sending an authentication message to a relay AMF, wherein the sent authentication message includes a U2N connection mapping ID.

[0197] Embodiment E12: The method of any one of embodiments E2 to E10, further comprising: receiving an authentication message communicated by a remote UE, wherein the received authentication message does not include a U2N connection mapping ID; and sending an authentication message to a relay AMF, wherein the sent authentication message includes a U2N connection mapping ID.

[0198] Embodiment E13: The method of embodiment E11 or E12, wherein the authentication message conveyed by the remote UE includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the authentication message sent to the relay AMF includes an EAP message and / or one or more parameters.

[0199] Embodiment E14: The method of any one of embodiments E11 to E13, wherein the received authentication message is a PC5-S message (eg, a dedicated PC5-S message).

[0200] Embodiment E15: The method of any one of embodiments E2 to E14, further comprising: receiving a relay key response message conveyed by a relay AMF, the relay key response including a U2N connection mapping ID; using the received U2N connection mapping ID to identify a remote UE; and sending a security mode command directly to the identified remote UE.

[0201] Embodiment E16: The received relay key response message includes the 5GPRUK ID, K NR_ProSe The method of embodiment E15, further comprising: a 5GPRUK ID and / or Nonce_2; and wherein the direct security mode command includes the 5GPRUK ID and / or Nonce_2.

[0202] Embodiment E17:K NR_ProSe The method of embodiment E16, further comprising deriving a PC5 session key Krelay-sess and / or a confidentiality and integrity key from

[0203] Embodiment E18: The method of any one of embodiments E2 to E17, wherein the U2N connection mapping ID is a temporary ID.

[0204]

[0032] Embodiment E19: The method of any one of embodiments E2 to E17, wherein the U2N connection mapping ID is the Layer 2 ID of the remote UE.

[0205]

[0023] Embodiment E20: The method of any one of embodiments E2 to E17, wherein the U2N connection mapping ID is a publicly available subscription identifier (GPSI) of the remote UE.

[0206] Embodiment E21: The method of any one of embodiments E2 to E17, wherein the U2N connection mapping ID is a user information ID of the remote UE.

[0207]

[0032] Embodiment E22: The method of any one of embodiments E1 to E21, further comprising receiving a direct security completion message communicated by the remote UE.

[0208] Embodiment E23: The method of any one of embodiments E1 to E22, wherein the PC5-S message is a dedicated PC5-S message.

[0209] Embodiment F1: A relay user equipment (UE) (304) configured to receive an authentication message communicated by a relay access and mobility function (AMF) (308) and to send an authentication message to a remote UE (302), wherein the sent authentication message is a PC5-S message.

[0210] Embodiment G1: A computer program comprising instructions for adapting an apparatus to carry out the method according to any one of embodiments A1 to A26, C1 to C20, and E1 to E23.

[0211] Embodiment H1: A carrier containing the computer program of embodiment G1, the carrier being one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.

[0212] Embodiment I1: An apparatus (304 or 308) comprising a processing circuit (602 or 702) and a memory (642 or 742), the memory including instructions (644 or 744) executable by the processing circuit, whereby the apparatus is operable to perform a method according to any one of embodiments A1 to A26, C1 to C20, and E1 to E23.

[0213] Embodiment J1: An apparatus (304 or 308) adapted to perform the method of any one of embodiments A1 to A26, C1 to C20, and E1 to E23.

[0214] Embodiment K1: Any combination of the above-described embodiments.

[0215] While various aspects and embodiments have been described herein, it should be understood that these aspects and embodiments have been presented by way of example only, and not limitation. Thus, the breadth and scope of the present disclosure should not be limited by any of the exemplary aspects and embodiments described above. Moreover, unless otherwise indicated herein or clearly contradicted by context, any combination of the above-described elements in all possible variations thereof is encompassed by the present disclosure.

[0216] Additionally, while the processes described above and illustrated in the figures have been shown as a sequence of steps, this has been done for purposes of illustration only, and it is therefore contemplated that some steps may be added, some steps may be omitted, the order of steps may be rearranged, and some steps may be performed in parallel.

Claims

1. A method (400) implemented by a relay user equipment (UE) (304), the method comprising: Receiving a first message communicated by a remote UE (302) (FIG. 3, step 1; 402; 452); sending a second message to a Relay Access and Mobility Function (AMF) (308) (FIG. 3, step 3; 408; 458), wherein the second message includes a UE-to-Network (U2N) connection mapping identity (ID) that identifies the remote UE (302); and Including, The method (400), wherein the U2N connection mapping ID is an ID temporarily assigned to the remote UE by the relay UE (304) or a Layer 2 ID of the remote UE.

2. The method of claim 1 , wherein the second message further includes a subscription concealment identifier (ID) of the remote UE (302).

3. 3. The method of claim 2, wherein the second message further includes a relay service code received in the first message, a nonce received in the first message, or both the relay service code received in the first message and a nonce received in the first message.

4. the second message is a relay key request; and / or The method of claim 1 , wherein the first message is a direct communication request (DCR) message.

5. receiving a first authentication message conveyed by the Relay AMF (308) (FIG. 3, step 5; 410; 460), the authentication message including the U2N connection mapping ID identifying the remote UE (302); sending a second authentication message to the remote UE identified by the U2N connection mapping ID included in the first authentication message (FIGS. 3 and 5a); The method of claim 1 further comprising:

6. the first authentication message further includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the second authentication message includes the EAP message and / or the one or more parameters; the second authentication message is a PC5-S message; and / or The method of claim 5 , wherein the first authentication message is a relay authentication request.

7. receiving a third authentication message communicated by the remote UE (FIG. 3, step 6a; 414; 464); sending a fourth authentication message to the Relay AMF (308) (FIG. 3, step 6b; 416; 466), wherein the fourth authentication message includes the U2N connection mapping ID identifying the remote UE (302); and The method of claim 1 further comprising:

8. the third authentication message includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the fourth authentication message includes the EAP message and / or the one or more parameters; and / or The method of claim 7, wherein the third authentication message is a PC5-S message.

9. receiving a Relay Key Response message conveyed by the Relay AMF (308) (FIG. 3, step 8; 418; 468), wherein the Relay Key Response message includes the U2N Connection Mapping ID that identifies the remote UE (302); and Sending a message to the remote UE (302) identified by the U2N Connection Mapping ID included in the Relay Key Response message (FIG. 3, step 8; 420; 470); The method of claim 1 further comprising:

10. The relay key response message includes a 5GPR UK ID, K NR_ProSe , and / or Nonce_2, wherein the sent message includes the 5GPRUK ID and / or the Nonce_2, the method further comprising deriving a PC5 session key Krelay-sess and / or confidentiality and integrity keys from K NR_ProSe ; and / or 10. The method of claim 9, wherein the sent message is a direct security mode command.

11. receiving a direct security completion message transmitted by the remote UE (302) (FIG. 3, step 8; 422; 472); The method of claim 1.

12. Allocating the U2N Connection Mapping ID to the remote UE (FIG. 3, step 2; 404; 454); and / or 2. The method of claim 1, further comprising: storing a mapping between the U2N connection mapping ID and the ID of the remote UE (FIG. 3, step 2; 406; 456).

13. A relay user equipment (UE) (304), A relay user equipment (UE) (304) adapted to perform the method of any one of claims 1 to 12.

14. A method (500) performed by a Relay Access and Mobility Function (AMF) (308), the method comprising: Receiving a first message (FIG. 3, step 3; 502) conveyed by a relay user equipment (UE) (304), the first message including a UE-to-network (U2N) connection mapping identity (ID) identifying a remote UE (302); Selecting an Authentication Server Function (AUSF) (310) (FIG. 3, step 4; 506); Storing the mapping between the U2N connection mapping ID and the selected AUSF ID (FIG. 3, step 4; 508); sending a second message to the selected AUSF (FIG. 3, step 4; 510); and Including, The method (500), wherein the U2N connection mapping ID is an ID temporarily assigned to the remote UE by the relay user equipment (UE) (304) or a Layer 2 ID of the remote UE.

15. The method of claim 14, wherein the first message further includes a subscription concealment identifier (ID) of the remote UE (302).

16. 16. The method of claim 15, wherein the first message further includes a relay service code, a nonce, or both a relay service code and a nonce.

17. The method of claim 14 , wherein the first message is a relay key request.

18. the second message sent to the selected AUSF includes: (a) a subscription concealment identifier (ID) of the remote UE (302); (b) a relay service code; (c) a nonce; or (d) a combination of any two or more of (a)-(d); the second message sent to the selected AUSF includes a subscription privacy identifier (ID) of the remote UE (302), and selecting the AUSF includes selecting the AUSF based on the subscription privacy identifier (ID) of the remote UE (302); and / or 15. The method of claim 14, wherein the second message sent to the selected AUSF is a Nausf_UEAuthentication_Authenticate request message.

19. 15. The method of claim 14, further comprising verifying (504) that the relay UE is authorized to act as a U2N relay.

20. 15. The method of claim 14, further comprising sending a first authentication message to the relay UE (FIG. 3, step 5; 512), wherein the first authentication message includes the U2N connection mapping ID (FIG. 3, step 5; 512).

21. 21. The method of claim 20, wherein the first authentication message further comprises an Extensible Authentication Protocol (EAP) message and / or one or more parameters.

22. receiving a second authentication message transmitted by the relay UE (302) (FIG. 3, step 6; 514), wherein the second authentication message includes the U2N connection mapping ID; and sending a third authentication message to the AUSF mapped to the U2N connection mapping ID included in the second authentication message (FIG. 3, step 7; 516); 15. The method of claim 14, further comprising:

23. the second authentication message further includes an Extensible Authentication Protocol (EAP) message and / or one or more parameters, and the third authentication message includes the EAP message and / or the one or more parameters included in the second authentication message; and / or 23. The method of claim 22, wherein sending the third authentication message to the AUSF (FIG. 3, step 7; 516) comprises calling a Nausf_UEAuthentication service of the AUSF (FIG. 3, step 7; 516).

24. receiving an authentication response message communicated by the AUSF (FIG. 3, step 8; 518), the authentication response message including one or more parameters; sending an authentication response message to the relay UE (FIG. 3, step 8; 520), the authentication response message including the one or more parameters included in the received authentication response and the U2N connection mapping ID (FIG. 3, step 8; 520); 23. The method of claim 22, further comprising:

25. the sent authentication response message is a Relay Key Response; and / or The method of claim 24 , wherein the one or more parameters included in the received authentication response include a 5GPRUK ID, a K NR_ProSe , and / or a Nonce_2.

26. A Relay Access and Mobility Function (AMF) (308), A Relay Access and Mobility Function (AMF) (308) adapted to perform the method of any one of claims 14 to 25.

Citation Information

Patent Citations

  • Authentication for relay

    WO2021034093A1

  • Authentication and authorization for user equipment (UE)-to-network relaying

    WO2021230867A1