Security for traffic relay by wireless communication devices

A proximity service anchor node manages ProSe relay user keys for reuse in wireless networks, addressing inefficiencies in key reuse across sessions and maintaining secure communication without additional authentication, thus optimizing network operations.

JP7821892B2Active Publication Date: 2026-02-27TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024543060
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-01-21
Filing Date
2022-11-16
Publication Date
2026-02-27
Estimated Expiration
2042-11-16

AI Technical Summary

Technical Problem

Existing wireless communication networks face inefficiencies in reusing ProSe relay user keys across different sessions without re-executing primary authentication, which is burdensome for authentication servers and deviates from conventional design principles.

Method used

Introduce a proximity service anchor node to store and manage ProSe relay user keys, allowing their reuse without involving authentication servers in the management of key identifiers, and implement signaling for key reuse requests that do not specify the previous key's identity.

Benefits of technology

Enables efficient reuse of ProSe relay user keys compatible with existing network designs, reducing the burden on authentication servers and allowing secure communication without repeated authentication procedures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007821892000001
    Figure 0007821892000001
  • Figure 0007821892000002
    Figure 0007821892000002
  • Figure 0007821892000003
    Figure 0007821892000003
Patent Text Reader

Abstract

A method is provided that is performed by an authentication server, the method including receiving a request for authentication of a remote wireless communication device, the request requiring reuse of a proximity services relay user key to derive a shared key for protecting an interface between the remote wireless communication device and a relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD This application relates generally to the relaying of traffic by wireless communication devices, and more particularly to security for such traffic relaying. [Background technology]

[0002] Proximity services (ProSe) in wireless communication networks enable wireless communication devices in close proximity to each other to communicate directly via a path that does not traverse a network node. Proximity service relays leverage ProSe so that one wireless communication device can relay traffic for another wireless communication device in its vicinity. For example, a so-called ProSe device-network relay is a wireless communication device that relays unicast traffic between a remote wireless communication device and a wireless communication network. Through the ProSe device-network relay, the remote wireless communication device can then communicate with the network even when the remote wireless communication device is outside the network's coverage.

[0003] The interface between the remote wireless communication device and the relay wireless communication device may be protected based on a ProSe relay user key (PRUK), for example, called 5GPRUK in 5G networks. Generating a new ProSe relay user key each time the remote wireless communication device establishes an interface with the relay wireless communication device would sufficiently protect the interface, since any compromise of the ProSe relay user key would be limited to only one session of the interface. However, generating a new ProSe relay user key would inefficiently require performing primary authentication of the remote wireless communication device again. Therefore, reusing the ProSe relay user key across different sessions of the interface would prove more efficient. Nevertheless, challenges exist in reusing the ProSe relay user key, at least in a manner that is compatible with existing design principles for wireless communication networks. For example, the approach described in 3GPP TS33.503 v0.2.0 for securing 5G ProSe communications via 5G ProSe Layer-3 UE-to-Network Relay on the control plane will unconventionally place the burden on the Authentication Server (AUSF) to manage PRUK IDs for PRUKs, rather than just having to manage subscription IDs for remote wireless communication devices as is conventional. Summary of the Invention

[0004] Some embodiments herein introduce a new node, called a proximity service anchor node, to support proximity service relay user key reuse in a wireless communication network. In this regard, the proximity service anchor node may store a proximity service relay user key for a remote wireless communication device and bind an identifier to the key, so that the key can be later retrieved (for reuse) based on the identifier. With proximity service relay user key reuse supported by the proximity service anchor node in this manner, the proximity service anchor node effectively insulates other nodes in the communication network from the details of proximity service relay user key reuse. An authentication server, for example, would be insulated from having to manage identifiers bound to proximity service relay user keys and would therefore be able to simply manage subscription IDs of remote wireless communication devices, as is conventional.

[0005] Other embodiments herein introduce proximity service reuse signaling to request the reuse of proximity service relay user keys. Such signaling may, for example, simply request the reuse of a proximity service relay user key, regardless of which proximity service relay user key was last used, without specifying any identity bound to that last-used key. These embodiments thereby effectively relieve nodes in a wireless communication network from the burden of having to manage identifiers bound to proximity service relay user keys.

[0006] Whether via proximity service anchor nodes or proximity service reuse signaling, certain embodiments herein advantageously enable reuse of proximity service relay user keys in a manner that is compatible with existing design principles for wireless communication networks, e.g., so that the authentication server still only needs to rely on the subscription ID of the remote wireless communication device.

[0007] More particularly, embodiments herein include a method performed by a remote wireless communication device, the method including sending a request to a relay wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication, where the request requests reuse of a proximity services relay user key already associated with the remote wireless communication device.

[0008] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0009] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0010] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0011] In some embodiments, the method further includes receiving a response to the request from the relay wireless communication device indicating that the proximity services relay user key should be reused.

[0012] In some embodiments, the method further includes reusing the proximity service relay user key to generate a shared key for protecting an interface between the remote wireless communication device and the relay wireless communication device, and protecting the interface using the shared key. In one or more of these embodiments, the shared key is key K NR_ProSe In one or more of these embodiments, the interface is a PC5 interface.

[0013] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0014] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0015] Other embodiments herein include a method performed by a relay wireless communication device, the method including receiving a request from a remote wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication, where the request requests reuse of a proximity services relay user key already associated with the remote wireless communication device.

[0016] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0017] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0018] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0019] In some embodiments, the method further includes sending a response to the request to the remote wireless communication device indicating that the proximity services relay user key should be reused.

[0020] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0021] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0022] In some embodiments, the method further includes sending a request to a network node serving the relay wireless communication device for a shared key for protecting an interface between the remote wireless communication device and the relay wireless communication device. In this case, the request for the shared key requests reuse of a proximity service relay user key to derive the shared key. In one or more of these embodiments, the request for the shared key includes a proximity service relay user key reuse flag that requests reuse of the proximity service relay user key. In one or more of these embodiments, the method further includes receiving a response to the request for the shared key from the network node. In this case, the response to the request for the shared key includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0023] Other embodiments herein include a method performed by a relay wireless communication device, the method including sending a request for a shared key to protect an interface between a remote wireless communication device and the relay wireless communication device to a network node serving the relay wireless communication device, where the relay wireless communication device is configured to relay traffic for the remote wireless communication device, and the request for the shared key requires reuse of a proximity services relay user key to derive the shared key.

[0024] In some embodiments, the request for a shared key includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key.

[0025] In some embodiments, the method further includes receiving a response to the request for the shared key from the network node, where the response to the request for the shared key includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0026] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0027] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0028] In some embodiments, the method further includes receiving a request from the remote wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication, where the request requests reuse of a proximity services relay user key already associated with the remote wireless communication device. The method further includes sending a response to the request to the remote wireless communication device, where the response includes the shared key and indicates that the proximity services relay user key should be reused to derive the shared key.

[0029] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0030] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0031] In some embodiments, the shared key is key K NR_ProSe is.

[0032] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0033] In some embodiments, the interface is a PC5 interface.

[0034] Other embodiments herein include a method performed by a network node serving a relay wireless communication device, the method including receiving a request from the relay wireless communication device for a shared key for protecting an interface between a remote wireless communication device and the relay wireless communication device, where the relay wireless communication device is configured to relay traffic for the remote wireless communication device, and the request requires reuse of a proximity services relay user key to derive the shared key.

[0035] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0036] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0037] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0038] In some embodiments, the method further includes transmitting a response to the request to the relay wireless communication device, where the response includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0039] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0040] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0041] In some embodiments, the shared key is key K NR_ProSe is.

[0042] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0043] In some embodiments, the interface is a PC5 interface.

[0044] Other embodiments herein include a method performed by a network node serving a relay wireless communication device, the method including sending to an authentication server a request for authentication of a remote wireless communication device, where the request requires reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and the relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device.

[0045] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0046] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0047] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0048] In some embodiments, the method further includes receiving a response to the request from the authentication server, where the response includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0049] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0050] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0051] In some embodiments, the shared key is key K NR_ProSe is.

[0052] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0053] In some embodiments, the interface is a PC5 interface.

[0054] Other embodiments herein include a method performed by an authentication server, the method including receiving a request for authentication of a remote wireless communication device, where the request requires reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device.

[0055] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0056] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0057] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0058] In some embodiments, the method further includes sending a response to the request, where the response includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0059] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0060] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0061] In some embodiments, the shared key is key K NR_ProSe is.

[0062] In some embodiments, the request is received from an Access and Mobility Function (AMF).

[0063] In some embodiments, the interface is a PC5 interface.

[0064] In some embodiments, the method further includes sending a request for authentication credentials for the remote wireless communication device to the data management node. In this case, the request for authentication credentials requests reuse of a proximity services relay user key. In one or more of these embodiments, the method further includes receiving a response to the request for authentication credentials from the data management node. In this case, the response indicates whether the proximity services relay user key is available for reuse. In one or more of these embodiments, the response indicates that the proximity services relay user key is available for reuse. In some embodiments, the method further includes obtaining a shared key as derived from the proximity services relay user key and sending a response to the request for authentication. In this case, the response to the request for authentication includes the obtained shared key and indicates that the proximity services relay user key should be reused to derive the shared key. In one or more of these embodiments, obtaining the shared key includes retrieving the proximity services relay user key from local storage at the authentication server and deriving the shared key from the retrieved proximity services relay user key. In one or more of these embodiments, obtaining the shared key includes forwarding the request for authentication to another authentication server having a proximity service relay user key stored therein and receiving the shared key from the other authentication server as derived from the proximity service relay user key. In one or more of these embodiments, the response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials. In this case, the method further includes generating a proximity service relay user key based on keying material derived during authentication of the remote wireless communication device, where the authentication of the remote wireless communication device is based on the authentication credentials, deriving the shared key from the generated proximity service relay user key, and sending a response to the request for authentication. In this case, the response to the request for authentication includes the derived shared key.In one or more of these embodiments, the response to the request for authentication indicates that the proximity services relay user key should not be reused to derive the shared key. Alternatively or additionally, the method may further include, after generating the proximity services relay user key, sending signaling to the data management node indicating that the proximity services relay user key for the remote wireless communication device is available for reuse and indicating an identity of the authentication server on which the proximity services relay user key is stored.

[0065] Other embodiments herein include a method performed by an authentication server, the method including sending to a data management node a request for authentication credentials for a remote wireless communication device, where the request for authentication credentials requests reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device.

[0066] In some embodiments, the request is received from a network node that serves the relay wireless communications device, while in other embodiments, the request is received from another authentication server.

[0067] In some embodiments, the method further includes receiving a response to the request for authentication credentials from the data management node, where the response indicates whether the proximity service relay user key is available for reuse. In one or more of these embodiments, the response indicates that the proximity service relay user key is available for reuse. In this case, the method further includes obtaining a shared key as derived from the proximity service relay user key and sending a response to the request for authentication to the network node. In this case, the response to the request for authentication includes the obtained shared key and indicates that the proximity service relay user key should be reused to derive the shared key. In one or more of these embodiments, obtaining the shared key includes retrieving the proximity service relay user key from local storage at the authentication server and deriving the shared key from the retrieved proximity service relay user key. In one or more of these embodiments, obtaining the shared key includes forwarding the request for authentication to another authentication server having the proximity service relay user key stored therein and receiving the shared key from the other authentication server as derived from the proximity service relay user key.

[0068] In some embodiments, the response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials. In this case, the method further includes generating a proximity service relay user key based on keying material derived during authentication of the remote wireless communication device. In this case, authentication of the remote wireless communication device is based on the authentication credentials. The method further includes deriving a shared key from the generated proximity service relay user key and sending a response to the request for authentication to the network node. In this case, the response to the request for authentication includes the derived shared key. In one or more of these embodiments, the response to the request for authentication indicates that the proximity service relay user key should not be reused to derive the shared key.

[0069] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0070] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0071] In some embodiments, the shared key is key K NR_ProSe is.

[0072] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0073] In some embodiments, the interface is a PC5 interface.

[0074] Other embodiments herein include a method performed by a data management node, the method including receiving, from an authentication server, a request for authentication credentials for a remote wireless communication device, where the request for authentication credentials requires reuse of a proximity services relay user key to derive a shared key for protecting an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device.

[0075] In some embodiments, the method further includes sending a response to the request to the authentication server, where the response indicates whether the proximity services relay user key is available for reuse. In one or more of these embodiments, the response indicates that the proximity services relay user key is available for reuse. In one or more of these embodiments, the response indicates an identity of the authentication server on which the proximity services relay user key is stored. In one or more of these embodiments, the response indicates that the proximity services relay user key is not available for reuse and includes the requested authentication credentials. In one or more of these embodiments, the method further includes, after sending the response, receiving signaling indicating the identity of the authentication server on which the proximity services relay user key is stored, and storing information at the data management node indicating that the proximity services relay user key for the remote wireless communication device is available for reuse and indicating the identity of the authentication server on which the proximity services relay user key is stored.

[0076] In some embodiments, the method further includes determining whether a proximity services relay user key is available for reuse based on information at the data management node indicating whether a proximity services relay user key is stored for the remote wireless communication device.

[0077] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0078] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0079] In some embodiments, the shared key is key K NR_ProSe is.

[0080] In some embodiments, the interface is a PC5 interface.

[0081] Of course, the present disclosure is not limited to the above features and advantages. Indeed, those skilled in the art will recognize additional features and advantages upon reading the following detailed description, and upon viewing the accompanying drawings. [Brief explanation of the drawings]

[0082] [Figure 1] FIG. 1 is a block diagram of proximity service relay user key reuse, according to some embodiments. [Figure 2] FIG. 2 is a block diagram of a key hierarchy, according to some embodiments. [Figure 3A] FIG. 1 is a call flow diagram for proximity service relay user key reuse, according to some embodiments. [Figure 3B] FIG. 1 is a call flow diagram for proximity service relay user key reuse, according to some embodiments. [Figure 4A] FIG. 10 is a call flow diagram for proximity service relay user key reuse according to another embodiment. [Figure 4B] FIG. 10 is a call flow diagram for proximity service relay user key reuse according to another embodiment. [Figure 5A] FIG. 10 is a call flow diagram for proximity service relay user key reuse according to yet another embodiment. [Figure 5B] FIG. 10 is a call flow diagram for proximity service relay user key reuse according to yet another embodiment. [Figure 6A] FIG. 10 is a call flow diagram for proximity service relay user key reuse, according to yet another embodiment. [Figure 6B] FIG. 10 is a call flow diagram for proximity service relay user key reuse, according to yet another embodiment. [Figure 7] FIG. 10 is a block diagram of proximity service relay user key reuse according to another embodiment. [Figure 8A] FIG. 1 is a call flow diagram for proximity service relay user key reuse, according to some embodiments. [Figure 8B]FIG. 1 is a call flow diagram for proximity service relay user key reuse, according to some embodiments. [Figure 9] FIG. 1 is a logic flow diagram of a method performed by a proximity service anchor node, according to some embodiments. [Figure 10] FIG. 1 is a logic flow diagram of a method performed by an authentication server, according to some embodiments. [Figure 11] FIG. 1 is a logic flow diagram of a method performed by a network node, according to some embodiments. [Figure 12] 1 is a logic flow diagram of a method performed by a remote wireless communication device according to some embodiments. [Figure 13] 4 is a logic flow diagram of a method performed by a relay wireless communications device according to some embodiments. [Figure 14] 4 is a logic flow diagram of a method performed by a relay wireless communications device according to some embodiments. [Figure 15] FIG. 1 is a logic flow diagram of a method performed by a network node, according to some embodiments. [Figure 16] FIG. 1 is a logic flow diagram of a method performed by a network node, according to some embodiments. [Figure 17] FIG. 1 is a logic flow diagram of a method performed by an authentication server, according to some embodiments. [Figure 18] FIG. 1 is a logic flow diagram of a method performed by an authentication server, according to some embodiments. [Figure 19] FIG. 4 is a logic flow diagram of a method performed by a data management node, according to some embodiments. [Figure 20] 1 is a block diagram of a wireless communication device according to some embodiments. [Figure 21] FIG. 1 is a block diagram of a proximity service anchor node, according to some embodiments. [Figure 22] FIG. 2 is a block diagram of an authentication server, according to some embodiments. [Figure 23] FIG. 2 is a block diagram of a network node according to some embodiments. [Figure 24] FIG. 2 is a block diagram of a data management node, according to some embodiments. [Figure 25] 1 is a block diagram of a communication system according to some embodiments. [Figure 26] FIG. 2 is a block diagram of a user equipment according to some embodiments. [Figure 27] FIG. 2 is a block diagram of a network node according to some embodiments. [Figure 28] FIG. 2 is a block diagram of a host, according to some embodiments. [Figure 29] FIG. 1 is a block diagram of a virtualized environment, according to some embodiments. [Figure 30] FIG. 1 is a block diagram of a host communicating with a UE through a network node over a partial wireless connection, according to some embodiments. Modes for carrying out the invention

[0083] FIG. 1 illustrates proximity service (ProSe) relaying in accordance with some embodiments. As illustrated, wireless communication devices 12, 14 are in proximity to one another and communicate directly over interface 16, e.g., a PC5 interface defined in accordance with 3GPP standards. By communicating directly over interface 16, wireless communication devices 12, 14 communicate via a path that does not traverse a network node. Wireless communication devices 12, 14 utilize this proximity service direct communication, e.g., at layer 2 or layer 3 of their protocol stacks, such that wireless communication device 12 can relay traffic 18 for wireless communication device 14. Wireless communication device 12 is therefore referred to as a relay wireless communication device 12, while wireless communication device 14 is referred to as a remote wireless communication device 14. In one embodiment, as illustrated, for example, relay wireless communication device 12 relays traffic 18 between remote wireless communication device 14 and wireless communication network 20. Then, via the relay wireless communication device 12, the remote wireless communication device 14 can communicate with the network 20 even when the remote wireless communication device 14 is outside the network's coverage (i.e., remote with respect to the network's coverage).

[0084] The interface 16 between the wireless communication devices 12, 14 is protected based on a shared key 22, i.e., shared between the wireless communication devices 12, 14. The shared key 22 may be, for example, a root key from which cryptographic keys for confidentiality and / or integrity protection of the interface 16 are directly or indirectly derived. In some embodiments, the shared key 22 is shared between the wireless communication devices 12, 14 in that the shared key 22 is established at both the wireless communication devices 12, 14. For example, in one embodiment, the remote wireless communication device 14 generates the shared key 22 itself, while the relay wireless communication device 12 receives the same shared key 22 from a network node 24 in the wireless communication network 20 that implements, for example, an Access and Mobility Function (AMF). Once the shared key 22 is established at both the wireless communication devices 12, 14 in this manner, each wireless communication device 12, 14 can use the shared key 22 to derive cryptographic keys (not shown) for confidentiality and / or integrity protection of the interface 16. The wireless communication devices 12, 14 may then communicate securely over the interface 16 by applying confidentiality protection using a confidentiality key and / or integrity protection using an integrity key.

[0085] In embodiments herein, the shared key 22 is derived from a proximity service relay user key 26, also referred to as a PRUK key 26, where PRUK represents a ProSe relay user key. Figure 2 illustrates one exemplary implementation of the proximity service relay user key 26 in an embodiment where the wireless communication network 20 is a 5G network. As shown, an intermediate key K AUSF is established in the remote wireless communication device 14 and in the wireless communication network 10. This intermediate key K AUSF A key 5GPRUK is derived from the 5GPRUK, where 5GPRUK exemplifies the proximity service relay user key 26. In one embodiment, the 5GPRUK is the root of security for the PC5 unicast link between the wireless communication devices 12, 14. AUSF Next, we obtain the root certificate from the 5GPRUK.NR_ProSe is derived, where the key K NR_ProSe illustrates a shared key 22. In one embodiment, key K NR_ProSe is a root key (e.g., a 256-bit root key) established between wireless communication devices 12, 14 communicating using a New Radio (NR) PC5 unicast link. NR_ProSe is established in both the remote wireless communication device 14 and the relay wireless communication device 12. Each of the wireless communication devices 12, 14 has a key K NR_ProSe derive a key that protects the transfer of data between the devices 12, 14 over the interface 16. In this regard, each of the wireless communication devices 12, 14 has a key K NR_ProSe From key K relay-sess where the key K relay-sess is derived for each unicast link and / or each time a unicast communication session is activated between the devices 12, 14. Each of the wireless communication devices 12, 14 derives a key K that is to be used in a selected integrity algorithm and a selected encryption algorithm to protect PC5-S signaling, PC5 radio resource control (RRC) signaling, and PC5 user plane data, respectively. relay-int and key K relay-enc is derived.

[0086] That said, regardless of whether the wireless communication network 10 is a 5G network, generating a new proximity services relay user key 26 each time the remote wireless communication device 14 establishes an interface 16 with the same or a different relay wireless communication device would adequately protect the interface 16, since any compromise of the proximity services relay user key 26 would be limited to only one session of the interface 16. However, in some embodiments, the proximity services relay user key 26 is based on and / or unique to one execution of, for example, a primary authentication procedure 28 for primary authentication of the remote wireless communication device 14 to the wireless communication network 10. In these embodiments, then, generating a new proximity services relay user key 26 each time the remote wireless communication device 14 establishes an interface 16 with the same or a different relay wireless communication device would inefficiently require re-executing the primary authentication procedure 28 each time.

[0087] Some embodiments herein thus facilitate reusing proximity services relay user keys 26, for example, across different sessions of interface 16. Moreover, some embodiments herein facilitate reusing proximity services relay user keys 26 in a manner that is compatible with existing design principles for wireless communication network 10, for example, so that the authentication server still only needs to rely on the subscription ID of the remote wireless communication device.

[0088] Some embodiments, in this regard, introduce a new node called a proximity service anchor node 30 to support reuse of the proximity service relay user key 26. As shown, the proximity service anchor node 30 receives the proximity service relay user key 26 associated with the remote wireless communication device 14 from an authentication server 32. The proximity service anchor node 30 derives a shared key 22 from this proximity service relay user key 26 and transmits the shared key 22 to the network node 24 serving the relay wireless communication device 12. The proximity service anchor node 30 may transmit the shared key 22 to the network node 24, for example, in a response 34 to a shared key request 36 from the network node 24 requesting the shared key 22.

[0089] The proximity service anchor node 30, in some embodiments, stores the proximity service relay user key 26, for example, in storage at the proximity service anchor node 30, so that the key 26 can be later retrieved for reuse. With proximity service relay user key 26 reuse supported by the proximity service anchor node 30 in this manner, the proximity service anchor node 30 effectively insulates other nodes in the wireless communication network 10 from the details of proximity service relay user key reuse. The authentication server 32, for example, would be insulated from these details.

[0090] In one or more embodiments, as shown, for example, the proximity service anchor node 30 also receives from the authentication server 32 an identifier 38 that is bound to the proximity service relay user key 26. The identifier 38 may be referred to, for example, as a PRUK ID. After transmitting the identifier 38 to the proximity service anchor node 30, the authentication server 32 does not need to store or manage the identifier 38. Rather, the proximity service anchor node 30 stores the proximity service relay user key 26 in association with the identifier 38. The proximity service anchor node 30 may then later retrieve the proximity service relay user key 26 from storage using the identifier 38 bound to that key 26. This, correspondingly, allows the network node 24 to include the identifier 38 in its shared key request 36 as a way to request that the shared key 22 be derived from the reused proximity service relay user key bound to the identifier 38. These embodiments enable the reuse of proximity services relay user keys 26 in a manner that frees the authentication server 32 from having to manage or store identifiers 38 bound to proximity services relay user keys 26, i.e., according to existing paradigms.

[0091] 3A-3B illustrate an exemplary call flow according to some embodiments. As shown in FIG. 3A, a remote wireless communication device 14 sends a direct communication request to a relay wireless communication device 12 to establish a secure unicast link over an interface 16 (step 1). The direct communication request includes a subscription identifier (ID) that identifies a subscription to a wireless communication network 20. To establish the secure unicast link over the interface 16, the relay wireless communication device 12 correspondingly sends a shared key request to a network node 24 (e.g., an AMF), where the shared key request requests a shared key 22 to protect the interface 16 and includes the subscription identifier (step 2). The network node 24 then transmits a corresponding shared key request to a neighboring service anchor node 30 (step 3).

[0092] After the proximity service anchor node 30 receives the shared key request from the network node 24, the proximity service anchor node 30 sends a request for primary authentication of the remote wireless communication device 14 to the authentication server 32 (step 4). This request may include a subscription identifier for the remote wireless communication device 14. Based on the request, the authentication server 32 triggers the execution of a primary authentication procedure 28, during which the remote wireless communication device 14 and the authentication server generate a proximity service relay user key (PRUK) 26 and an identifier 38 (denoted as PRUK ID) bound to the proximity service relay user key (PRUK) 26 (step 5). After this, the authentication server 32 sends a response to the request for primary authentication to the proximity service anchor node 30, where the response includes the proximity service relay user key 26 and the identifier 38 (step 6). In some embodiments, although not shown, the response may also include a subscription identifier for the remote wireless communication device 14.

[0093] The proximity service anchor node 30 correspondingly receives a response from the authentication server 32, the response including the proximity service relay user key (PRUK) 26 and the identifier 38. Upon obtaining the proximity service relay user key (PRUK) 26, the proximity service anchor node 30 derives the shared key 22 from the PRUK 26 (step 7). The proximity service anchor node 30 also stores the PRUK 26 in association with the identifier 38, for example, such that the PRUK 26 is indexed by the identifier 38 (step 8). The proximity service anchor node 30 transmits a response to the shared key request, where the response includes the shared key 22 (step 9). The network node 24 receives the shared key 22 in the response and correspondingly transmits the shared key 22 to the relay wireless communication device 12, for example, in response to the shared key request from the relay wireless communication device 12 (step 10).

[0094] The relay wireless communication device 12 sends a direct security mode command (step 11) to the remote wireless communication device 14, as shown, including one or more other parameters, such as a nonce, from which the shared key 22 can be derived. The remote wireless communication device 14 ultimately derives the shared key 22 from the PRUK 26 generated in step 5 (step 12).

[0095] 3B shows a call flow diagram for reusing the PRUK 26 from FIG. 3A to protect a subsequent establishment of an interface 16 between, for example, a remote wireless communication device 14 and the same or a different relay wireless communication device 12. As shown, the remote wireless communication device 14 sends a direct communication request to the same or a different relay wireless communication device 12 (step 13). However, this time, rather than including a subscription identifier for the remote wireless communication device 14, the direct communication request includes an identifier (PRUK ID) 38 bound to the PRUK 26. The relay wireless communication device 12 correspondingly sends a shared key request to the network node 24 (step 14). Because this is a subsequent shared key request, the shared key request effectively requests a new shared key that is different from the previous shared key used in FIG. 3A. However, rather than including a subscription identifier, this new shared key request includes the identifier (PRUK ID) 38 bound to the PRUK 26. This means that the shared key request effectively requests that the PRUK 26 from FIG. 3A be reused to derive a new shared key. In either case, the network node 24 similarly sends a corresponding shared key request to the neighboring service anchor node 30 (step 15).

[0096] The proximity service anchor node 30 receives the new shared key request. Using the identifier 38 indicated in the new shared key request, the proximity service anchor node 30 retrieves the PRUK 26 from storage at the proximity service anchor node 30 (step 16). The proximity service anchor node 30 then reuses the retrieved PRUK 26 to derive the requested new shared key 22 (step 17). That is, rather than triggering primary authentication of the remote wireless communication device 14 via the authentication server 32 for generation of a new PRUK 26, the proximity service anchor node 30 reuses the PRUK 26 generated from a previous execution of the primary authentication procedure 28 in FIG. 3A . Moreover, once the PRUK 26 is stored at the proximity service anchor node 30 and the reuse of the PRUK 26 is accomplished by the proximity service anchor node 30, the authentication server 32 need not even be involved or affected by the reuse of the PRUK 26. In either case, the proximity service anchor node 30 then transmits the new shared key 22 to the network node 24 in response to the new shared key request (step 18).

[0097] 3A, the network node 24 receives the shared key 22 in response and correspondingly transmits the shared key 22 to the relay wireless communication device 12, for example in response to a shared key request from the relay wireless communication device 12 (step 19). The relay wireless communication device 12 again transmits a direct security mode command to the remote wireless communication device 14 (step 20), and the remote wireless communication device 14 derives the shared key 22 from the reused PRUK 26 generated in step 5 (step 21).

[0098] 4A-4B show a more detailed example of the embodiment from FIGS. 3A-3B in the context that the wireless communication network 20 is a 5G network. In this example, the remote wireless communication device 14 is exemplified as a remote user equipment (UE), the relay wireless communication device 12 is exemplified as a relay UE that is a 5G ProSe Layer 3 UE-to-network relay, the interface 16 is a PC5 interface, the network node 24 is exemplified as implementing an AMF, the proximity service anchor node 30 is exemplified as implementing a ProSe anchor network function (NF), and the authentication server 32 is exemplified as implementing an authentication server function (AUSF). In some embodiments, the Prose anchor function is hosted by an existing node, e.g., co-located with a node implementing a ProSe key management function (PKMF) or AAnF. Furthermore, the proximity service relay user key 26 is exemplified as PRUK, and the shared key 22 is exemplified as key K. NR_ProSe It is exemplified as follows.

[0099] In this context, the call flow in Figures 4A-4B describes security for 5G ProSe communication via a 5G ProSe Layer 3 (L3) UE-to-Network (U2N) relay on the control plane. The security mechanism for L3 U2N relay authentication, authorization, and key management uses primary authentication for PC5 key establishment. In this procedure, the remote UE establishes a PC5 link between the remote UE and the UE-to-Network Relay. The procedure includes how the remote UE is authenticated by the AUSF via the relay UE and the AMF of the relay UE during 5G ProSe PC5 establishment. The mechanism can be used by the remote UE while out of coverage. 0. The remote UE and relay UE shall be registered with the network. The UE-Network Relay shall be authenticated and authorized by the network to support as a relay UE. The remote UE shall be authenticated and authorized by the network to act as a remote UE. 1. The remote UE shall initiate the discovery procedure using either the Model A method or the Model B method as specified in clause 6.3.1.2 or clause 6.3.1.3 of TS 23.304 v.17.0.0, respectively. 2-4. After UE-Network Relay discovery, the remote UE shall send a Direct Communication Request (DCR) to the relay UE to establish a secure PC5 unicast link. The remote UE shall include its security capabilities and security policy in the DCR message as specified in TS33.536 v.16.4.0. The message shall also include the Subscription Confidentiality Identifier (SUCI) or PRUK ID, Relay Service Code (RSC), and Nonce_1. Upon receiving the DCR message, the relay UE shall send a Relay Key Request to the relay AMF, including the parameters received in the DCR message. The relay AMF shall verify whether the relay UE is authorized to act as a U2N relay. 5. The relay AMF shall select a Prose anchor function (PANF) based on the SUCI or PRUK ID and forward the key request to the PANF via an Npanf_ProseKey_Request message, which may include the SUCI or PRUK ID, RSC, and Nonce_1. The Prose Anchor Function (PANF) is located in the Home Public Land Mobile Network (HPLMN) of the remote UE (like the AUSF and UDM). 6. If a SUCI is received, the PANF shall select an AUSF based on the SUCI and forward the key request to the AUSF via a Nausf_UEAuthentication_ProseAuth request message, which may include the SUCI, RSC, and Nonce_1. If a PRUK ID is received, the PANF shall find the locally stored PRUK and proceed to step 13. If the PRUK ID is not valid or the PRUK cannot be found, the PANF returns an error message to the UE via the relay AMF, which may trigger the remote UE to repeat step 2 with the SUCI. 7~10. The AUSF shall retrieve the authentication vector from the UDM and trigger UE authentication of the remote UE. 11. Upon successful UE authentication, the AUSF and remote UE shall generate a 5GPRUK and a PRUK ID based on the keying material derived during UE authentication. 12. The AUSF shall return the SUPI of the remote UE, the 5G PRUK and the PRUK ID to the PANF via a Nausf_UEAuthentication_ProseAuth response message. 13. The PANF generates Nonce_2 and calculates K based on the 5G PRUK and Nonce_2. NR_ProSe The key shall be derived. The PANF (in the HPLMN of the remote UE) also NR_ProSe When deriving the key, Nonce_1 and RSC may be used as inputs. 14. The PANF returns the K in the Npanf_ProseKey_Response message. NR_ProSe , Nonce_2 shall be sent to the relay AMF. 15. Relay AMF is K NR_ProSe , Nonce_2 to the relay UE. 16. The Relay UE shall send the received Nonce_2 to the Remote UE in a Direct Security Mode Command message. 17-18. The remote UE shall determine the K to be used for remote access via the relay UE in the same manner as specified in step 13. NR_ProSe The remote UE shall send a direct security mode complete message to the UE-Network Relay.

[0100] Further communication between the remote UE and the network is performed securely via the UE-to-network relay.

[0101] 5A-5B show an exemplary call flow according to yet another embodiment.

[0102] 5A, the remote wireless communication device 14 sends a direct communication request to the relay wireless communication device 12 to establish a secure unicast link over the interface 16 (step 1). The direct communication request includes a subscription identifier (ID) that identifies the subscription to the wireless communication network 20. To establish the secure unicast link over the interface 16, the relay wireless communication device 12 correspondingly sends a shared key request to the network node 24 (e.g., AMF), where the shared key request requests a shared key 22 to protect the interface 16 and includes the subscription identifier (step 2). The network node 24, in these embodiments, sends a request for primary authentication of the remote wireless communication device 14 to the authentication server 32, where the authentication request includes the subscription ID (step 3).

[0103] Based on the request, the authentication server 32 triggers the execution of a primary authentication procedure 28, during which the remote wireless communication device 14 and the authentication server generate a proximity service relay user key (PRUK) 26 and an identifier 38 (denoted as PRUK ID) bound to the proximity service relay user key (PRUK) 26 (step 4). After this, the authentication server 32 registers the PRUK 26 and the identifier 38 bound to the PRUK 26 with the proximity service anchor node 30. In this regard, the authentication server 32 sends to the proximity service anchor node 30 a request to register the PRUK 26 with the proximity service anchor node 30, where the PRUK 26 is included in the request to register the PRUK 26 (step 5). The request to register the PRUK 26 also includes the identifier 38 bound to the PRUK 26 and / or may also include a subscription identifier. The proximity service anchor 30 node stores the PRUK 26 in accordance with the request in association with the identifier 38, e.g., stores the PRUK 26 indexed by the identifier 38 (step 6). Once the PRUK 26 has been registered with the proximity service anchor node 30, the authentication server 32 returns a response to the authentication request including the identifier 38 (PRUK ID) (step 7).

[0104] After registering the PRUK 26, the proximity service anchor node 30 receives a shared key request from the network node 24 indicating the identifier 38 bound to the PRUK 26 (step 8). Using the identifier 38 indicated in the shared key request, the proximity service anchor node 30 retrieves the PRUK 26 from storage at the proximity service anchor node 30 (step 9). The proximity service anchor node 30 then derives the shared key 22 from the PRUK 26 retrieved from storage (step 10) and sends the shared key 22 to the network node 24 in response to the shared key request (step 11).

[0105] The network node 24 receives the shared key 22 in response and correspondingly transmits the shared key 22 to the relay wireless communication device 12, for example in response to a shared key request from the relay wireless communication device 12 (step 12).

[0106] The relay wireless communication device 12 sends a direct security mode command (step 13) to the remote wireless communication device 14, as shown, including one or more other parameters, such as a nonce, from which the shared key 22 can be derived. The remote wireless communication device 14 ultimately derives the shared key 22 from the PRUK 26 generated in step 5 (step 14).

[0107] 5B shows a call flow diagram for reusing the PRUK 26 from FIG. 5A to protect a subsequent establishment of an interface 16 between, for example, a remote wireless communication device 14 and the same or a different relay wireless communication device 12. As shown, the remote wireless communication device 14 sends a direct communication request to the same or a different relay wireless communication device 12 (step 15). However, this time, rather than including a subscription identifier for the remote wireless communication device 14, the direct communication request includes an identifier (PRUK ID) 38 bound to the PRUK 26. The relay wireless communication device 12 correspondingly sends a shared key request to the network node 24 (step 16). Because this is a subsequent shared key request, the shared key request effectively requests a new shared key that is different from the previous shared key used in FIG. 5A. However, rather than including a subscription identifier, this new shared key request includes the identifier (PRUK ID) 38 bound to the PRUK 26. This means that the shared key request effectively requests that the PRUK 26 from FIG. 5A be reused to derive a new shared key. In either case, the network node 24 similarly sends a corresponding shared key request to the neighboring service anchor node 30 (step 17).

[0108] The proximity service anchor node 30 receives the new shared key request. Using the identifier 38 indicated in the new shared key request, the proximity service anchor node 30 retrieves the PRUK 26 from storage at the proximity service anchor node 30 (step 18). The proximity service anchor node 30 then reuses the retrieved PRUK 26 to derive the requested new shared key 22 (step 19). That is, rather than triggering primary authentication of the remote wireless communication device 14 via the authentication server 32 for generation of a new PRUK 26, the proximity service anchor node 30 reuses the PRUK 26 generated from a previous execution of the primary authentication procedure 28 in FIG. 5A . Moreover, once the PRUK 26 is stored at the proximity service anchor node 30 and the reuse of the PRUK 26 is accomplished by the proximity service anchor node 30, the authentication server 32 need not even be involved or affected by the reuse of the PRUK 26. In either case, the proximity service anchor node 30 then transmits the new shared key 22 to the network node 24 in response to the new shared key request (step 20).

[0109] 5A, the network node 24 receives the shared key 22 in response and correspondingly transmits the shared key 22 to the relay wireless communication device 12, for example in response to a shared key request from the relay wireless communication device 12 (step 21). The relay wireless communication device 12 again transmits a direct security mode command to the remote wireless communication device 14 (step 22), and the remote wireless communication device 14 derives the shared key 22 from the reused PRUK 26 generated in step 5 (step 23).

[0110] 6A-6B show a more detailed example of the embodiment from FIGS. 5A-5B in the context that the wireless communication network 20 is a 5G network. In this example, the remote wireless communication device 14 is exemplified as a remote user equipment (UE), the relay wireless communication device 12 is exemplified as a relay UE that is a 5G ProSe Layer 3 UE-to-network relay, the interface 16 is a PC5 interface, the network node 24 is exemplified as implementing an AMF, the proximity service anchor node 30 is exemplified as implementing a ProSe anchor network function (NF), and the authentication server 32 is exemplified as implementing an authentication server function (AUSF). In some embodiments, the Prose anchor function is hosted by an existing node, e.g., co-located with a node implementing a ProSe key management function (PKMF) or AAnF. Furthermore, the proximity service relay user key 26 is exemplified as PRUK, and the shared key 22 is exemplified as key K. NR_ProSe It is exemplified as follows.

[0111] In this context, the call flow in Figures 6A-6B describes security for 5G ProSe communication via a 5G ProSe Layer 3 (L3) UE-to-Network (U2N) relay on the control plane. The security mechanism for L3 U2N relay authentication, authorization, and key management uses primary authentication for PC5 key establishment. In this procedure, the remote UE establishes a PC5 link between the remote UE and the UE-to-Network Relay. The procedure includes how the remote UE is authenticated by the AUSF via the relay UE and the AMF of the relay UE during 5G ProSe PC5 establishment. The mechanism can be used by the remote UE while out of coverage.

[0112] Steps 1 to 4 in FIG. 6A are the same as steps 1 to 4 in FIG. 4A. 5. If the SUCI is received, the relay AMF shall select an AUSF based on the SUCI and forward the key request to the AUSF via a Nausf_UEAuthentication_ProseAuth request message. The message may include the SUCI, RSC, and Nonce_1. If the PRUK ID is received, the relay AMF shall discover the PANF (in the HPLMN of the remote UE) based on the PRUK ID and proceed to step 14. Steps 6 to 10 in FIG. 6A are the same as steps 7 to 11 in FIG. 4A. 11-12. The AUSF shall send the SUPI of the remote UE, the 5G PRUK and the PRUK ID to the PANF via Npanf_AnchorKey_Register request / response. 13. The AUSF shall return the PRUK ID to the relay AMF via the Nausf_UEAuthentication_ProseAuth response message. 14. The relay AMF shall send a Prose key request to the PANF via a Npanf_ProseKey_Request message, which may include the PRUK ID, RSC, and Nonce_1. Steps 15 to 20 in FIG. 6B are the same as steps 13 to 18 in FIG. 4B.

[0113] Generally, then, Figures 3A to 6B generally show an example in which a Prose anchor network function stores a remote UE's prose security context, which includes the UE's 5G PRUK and PRUK ID, and optionally the UE's Subscription Persistent Identifier (SUPI), so that the UE's prose security context and keying material can be managed entirely by this NF without any extra impact on existing NFs, e.g., AUSF / UDM, AMF, etc.

[0114] 7 illustrates another embodiment herein that utilizes signaling to request or indicate reuse of a last-used proximity service relay user key 26. Such signaling may advantageously enable reuse of a proximity service relay user key 26 without having to bind an identifier 28 to that key 26, and thus without requiring a node such as the authentication server 32 to store or maintain that identifier 28. Correspondingly, such signaling may avoid the introduction of a proximity service anchor node 30 in the previous embodiment.

[0115] The description of Figure 7 is similar to the description of Figure 1, except for the differences noted below. As shown in Figure 7, the remote wireless communication device 14 sends a request 42 to the relay wireless communication device 12 for the relay wireless communication device 12 to relay traffic 18 for the remote wireless communication 12. This relay request 42 requests reuse of a proximity services relay user key 26 already associated with the remote wireless communication device 14. The request 42 may, for example, request reuse of a proximity services relay user key 24 from a previous execution (e.g., last execution) of the primary authentication procedure 28 for primary authentication of the remote wireless communication device 14. The relay request 42 may, for example, include a proximity services relay user key reuse flag 44 requesting reuse of a proximity services relay user key 26 already (e.g., last) associated with the remote wireless communication device 14.

[0116] The relay wireless communication device 12 correspondingly receives such a request 42 from the remote wireless communication device 14. The relay wireless communication device 12 sends a request 46 to the network node 24 for a shared key 22 for protecting the interface 16, where the request 46 for the shared key 22 requests reuse of the proximity services relay user key 26 for deriving the shared key 22. For example, the request 46 for the shared key 22 may include a proximity services relay user key reuse flag 48 requesting reuse of the proximity services relay user key 26.

[0117] The network node 24 correspondingly receives a shared key request 42 from the relay wireless communication device 12. The network node 24 then sends a request 50 to the authentication server 32 for authentication of the remote wireless communication device 14, where the request 50 requests reuse of the proximity services relay user key 26 to derive the shared key 22. The request 50 may, for example, include a proximity services relay user key reuse flag 52 requesting reuse of a proximity services relay user key 26 already associated with the remote wireless communication device 14.

[0118] In response, the authentication server 32 receives the authentication request 50. The authentication server 32 then sends to the data management node 40 a request 58 for authentication credentials for the remote wireless communication device 14, where the request for authentication credentials 58 requests reuse of the proximity services relay user key 26 to derive the shared key 22. The authentication server 32 may receive a response 62 to the request for authentication credentials 58 from the data management node 40, where the response 62 indicates whether the proximity services relay user key 26 is available for reuse.

[0119] If the response 62 indicates that the proximity services relay user key 26 is available for reuse, the authentication server 32 may retrieve the proximity services relay user key 26 from local storage at the authentication server 32 and reuse the proximity services relay user key 26 to derive the shared key 22. Alternatively, the authentication server 32 may retrieve the shared key 22 from another authentication server (not shown) that has stored the proximity services relay user key 26 to be reused. In either case, after obtaining the derived shared key 22 through reuse of the proximity services relay user key 26, the authentication server 32 sends a response to the request for authentication 54 to the network node 24, where the response to the request for authentication 50 includes the derived shared key 22 and indicates that the proximity services relay user key 26 should be reused to derive the shared key 22. The network node 24 may, in response, send to the relay wireless communication device 12 a response to the shared key request 46, which response includes the shared key 22 and indicates (e.g., via flag 56) that the proximity services relay user key 26 should be reused to derive the shared key 22. The relay wireless communication device 12 may similarly signal to the remote wireless communication device 14 that the proximity services relay user key 26 should be reused to derive the shared key 22. The remote wireless communication device 14 may then reuse the proximity services relay user key 26 to derive the shared key 22.

[0120] 8A-8B show a more detailed example of the embodiment from FIG. 7 in the context that the wireless communication network 20 is a 5G network. In this example, the remote wireless communication device 14 is exemplified as a remote user equipment (UE), the relay wireless communication device 12 is exemplified as a relay UE that is a 5G ProSe Layer 3 UE-to-network relay, the interface 16 is a PC5 interface, the network node 24 is exemplified as implementing an AMF, the authentication server 32 is exemplified as implementing an Authentication Server Function (AUSF), and the data management node 40 is exemplified as implementing a User Data Management (UDM) function. Furthermore, the proximity services relay user key 26 is exemplified as PRUK, and the shared key 22 is exemplified as key K NR_ProSe It is exemplified as follows.

[0121] In this context, the call flow in Figures 8A-8B describes security for 5G ProSe communications via a 5G ProSe Layer 3 (L3) UE-to-Network (U2N) relay on the control plane. The security mechanism for L3 U2N relay authentication, authorization, and key management uses primary authentication for PC5 key establishment. In this procedure, the remote UE establishes a PC5 link between the remote UE and the UE-to-Network Relay. The procedure includes how the remote UE is authenticated by the AUSF via the relay UE and the AMF of the relay UE during 5G ProSe PC5 establishment. The mechanism can be used by the remote UE while out of coverage. 0. The remote UE and relay UE shall be registered with the network. The UE-Network Relay shall be authenticated and authorized by the network to support as a relay UE. The remote UE shall be authenticated and authorized by the network to act as a remote UE. 1. The remote UE shall initiate the discovery procedure. 2-4. After UE-Network Relay Discovery, the remote UE shall send a Direct Communication Request to the Relay UE to establish a secure PC5 unicast link. The remote UE shall include its security capabilities and security policy in the DCR message as specified in TS33.536 v.16.4.0. The message shall also include the SUCI, Relay Service Code (RSC), Nonce_1, and an indicator, referred to herein as PRUK_reuse_Flag, to indicate that the UE intends to reuse a PRUK obtained from a previous interaction with the network. Upon receiving the DCR message, the relay UE shall send a Relay Key Request to the Relay AMF, including the parameters received in the DCR message. The Relay AMF shall verify whether the relay UE is authorized to act as a U2N relay. 5. The relay AMF shall select an AUSF based on the SUCI and forward the key request to the AUSF via a Nausf_UEAuthentication_ProseAuth request message, which may include the SUCI, RSC, Nonce_1, and PRUK_reuse_Flag. 6. The AUSF shall send an authentication certificate request to the UDM, including the SUCI and PRUK_reuse_Flag in the message. 7. The UDM deciphers the SUCI to obtain the UE's SUPI. If the PRUK_reuse_Flag is received in the message, the UDM checks the PRUK storage status for the UE.

[0122] There are two alternatives on how the UDM proceeds, which are described below. Alternative 1: Step 8a, followed by steps 9a and 10a, as follows: 8a. If the PRUK storage status indicates that there is a PRUK stored for the UE and an AUSF instance storing the PRUK (referred to herein as AUSFpruk), the UDM sends an authentication certificate response to the AUSF with the AUSFpruk ID. 9a. If the AUSFpruk ID is the same instance of AUSF, the AUSF fetches the locally stored 5G PRUK. The AUSF generates Nonce_2 and calculates K based on the 5G PRUK. NR_ProSe Derive the key.

[0123] If the AUSFpruk ID is a different instance, the AUSF forwards the Nausf_UEAuthentication_ProseAuth request message to the AUSFpruk. The AUSFpruk fetches the locally stored 5G PRUK. The AUSFpruk generates Nonce_2 and calculates K based on the 5G PRUK, Nonce_1, Nonce_2, and RSC. NR_ProSe Derive the key and send it back to AUSF. 10a. The AUSF sends the K NR_ProSe and Nonce_2 and an indicator (referred to herein as PRUK_reuse_Ind) to indicate that the network has used the PRUK obtained from the previous interaction to the relay AMF. Alternative 2: Step 8b, followed by steps 9b, 10b, 11b and 12b below. 8b. If the PRUK storage status indicates that there is no PRUK stored for the UE or the UDM determines that the PRUK shall not be reused, the UDM sends an authentication certificate response to the AUSF along with the UE's SUPI and authentication vector. The AUSF proceeds with the UE authentication procedure. 9b. Upon successful UE authentication, the AUSF and remote UE shall generate a 5GPRUK based on the keying material derived during UE authentication. 10b. The AUSF stores the 5G PRUK and updates the PRUK storage status to the UDM via the message Nudm_UEAuthentication_ProseResult. The message may include the SUPI, RSC, PRUK storage status, and AUSF ID. 11b. The AUSF generates Nonce_2 and calculates K based on the 5G PRUK, Nonce_1, Nonce_2, and RSC. NR_ProSe Derive the key. 12b. The AUSF confirms the K via the Nausf_UEAuthentication_ProseAuth response message. NR_ProSe , Nonce_2 shall be returned to the relay AMF. 13. Relay AMF is K NR_ProSe , Nonce_2 to the relay UE. The message may contain PRUK_reuse_Ind. 14. The Relay UE shall send the received Nonce_2 to the Remote UE in a Direct Security Mode Command message, which may contain PRUK_reuse_Ind. 15-16. The remote UE determines the K to be used for remote access via the relay UE in the same manner as the AUSF in step 9a / step 11b. NR_ProSe The remote UE shall send a direct security mode complete message to the UE-Network Relay.

[0124] Further communication between the remote UE and the network is performed securely via the UE-to-network relay.

[0125] 2 may be derived using a key derivation function (KDF), such that the derived key is equal to the KDF calculated on string S using the key, as given by Derived Key = HMAC-SHA-256(Key, S). In one such embodiment, string S is constructed from n+1 input parameters as follows: S=FC||P0||L0||P1||L1||P2||L2||P3||L3||...||Pn||Ln where FC is used to distinguish different instances of the algorithm and is either a single octet or consists of two octets of the form FC1||FC2, where FC1=0xFF and FC2 is a single octet, where P0...Pn are the n+1 input parameter encodings and L0...Ln is a two-octet representation of the length of the corresponding input parameter encodings P0..Pn.

[0126] In some embodiments, when deriving the 5GPRUK from KAUSF, the following parameters are used to form the input S to the KDF: FC=0xXX, P0=Subscription Persistent Identifier (SUPI), L0=length of the SUPI, P1=Relay Service Code, and L1=Length of the Relay Service Code. The input key KEY is KAUSF.

[0127] Similarly, in some embodiments, when deriving KNR_ProSe from a 5GPRUK key, the following parameters are used to form the input S to the KDF: FC=0xZZ, P0=Nonce_2, L0=length of Nonce_2, P1=Nonce_1, and L1=length of Nonce_1. The input key KEY is the 5GPRUK key.

[0128] Furthermore, when deriving the 5GPRUK ID from KAUSF, the following parameters may be used to form the input S to the KDF: FC=0xAA, P0=“PRUK-ID”, L0=length of “PRUK-ID”, P1=relay service code, L1=length of relay service code, P2=SUPI, and L2=length of SUPI. The input key KEY is KAUSF.

[0129] For simplicity, the relay wireless communication device 12 is shown as if it were served by the home network of the remote wireless communication device, but this need not be the case. In other embodiments, for example, the relay wireless communication device 12 is served by a wireless communication network different from the home network of the remote wireless communication device.

[0130] In view of modifications and variations of this specification, Figure 9 illustrates a method performed by a proximity service anchor node according to a particular embodiment. The method includes receiving a proximity service relay user key associated with a remote wireless communication device from an authentication server (block 900). The method further includes deriving a shared key from the proximity service relay user key for protecting an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device (block 910). The method also includes transmitting the shared key to a network node serving the relay wireless communication device (block 920).

[0131] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0132] In some embodiments, the method further includes receiving, from the network node, a shared key request requesting a shared key from the proximity service anchor node; after receiving the shared key request, sending a request for primary authentication of the remote wireless communication device to an authentication server; and receiving a response to the request for primary authentication from the authentication server, where the response to the request for primary authentication includes the proximity service relay user key. In one or more of these embodiments, the shared key request includes a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device. In one or more of these embodiments, the method further includes sending a response to the shared key request to the network node, where the response to the shared key request includes the shared key.

[0133] In some embodiments, the method further includes storing the proximity service relay user key in storage at the proximity service anchor node in association with the identifier bound to the proximity service relay user key (block 930). In one or more of these embodiments, the method further includes receiving a new shared key request indicating the identifier bound to the proximity service relay user key (block 940). The method may further include retrieving the proximity service relay user key from storage at the proximity service anchor node using the identifier indicated in the new shared key request (block 950) and deriving a new shared key for the remote wireless communication device from the retrieved proximity service relay user key (block 960). The method may then include transmitting the new shared key in a response to the new shared key request (block 970).

[0134] For example, in some embodiments, the method further includes receiving, from the authentication server, an identifier bound to the proximity service relay user key. In one or more of these embodiments, the method further includes storing the proximity service relay user key in association with the received identifier in storage at the proximity service anchor node. In one or more of these embodiments, the method further includes receiving, from the requesting node, a new shared key request indicating the identifier bound to the proximity service relay user key, retrieving the proximity service relay user key from storage at the proximity service anchor node using the identifier indicated in the new shared key request, deriving a new shared key for the remote wireless communication device from the retrieved proximity service relay user key, and transmitting the new shared key to the requesting node in response to the new shared key request. In one or more of these embodiments, the method further includes storing the proximity service relay user key also in association with a subscription identifier identifying a subscription of the remote wireless communication device to the home network of the remote wireless communication device.

[0135] In some embodiments, the method further includes receiving, from the authentication server, a subscription identifier that identifies a subscription of the remote wireless communication device to a home network of the remote wireless communication device.

[0136] In some embodiments, the proximity service relay user key is received from the authentication server in a request to register the proximity service relay user key with the proximity service anchor node. In one or more of these embodiments, the request to register the proximity service relay user key also includes an identifier bound to the proximity service relay user key and / or a subscription identifier identifying a subscription of the remote wireless communication device to the home network of the remote wireless communication device. In one or more of these embodiments, the method further includes storing the proximity service relay user key in association with the received identifier in storage at the proximity service anchor node. In one or more of these embodiments, the method further includes, after receiving the request to register the proximity service relay user key, receiving a shared key request from the network node indicating the identifier bound to the proximity service relay user key, and retrieving the proximity service relay user key from storage at the proximity service anchor node using the identifier indicated in the shared key request. In this case, the shared key is derived from the proximity service relay user key retrieved from storage, and sending the shared key to the network node includes sending a response to the shared key request to the network node, the response including the shared key.

[0137] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0138] In some embodiments, the shared key is key K NR_ProSe is.

[0139] In some embodiments, the authentication server implements an authentication server function (AUSF).

[0140] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0141] In some embodiments, the interface is a PC5 interface.

[0142] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0143] 10 illustrates a method performed by an authentication server according to another specific embodiment. The method includes generating a proximity service relay user key associated with a remote wireless communication device (block 1000). The method also includes transmitting the proximity service relay user key to a proximity service anchor node (block 1010).

[0144] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0145] In some embodiments, the method further includes receiving, from a proximity service anchor node, a request for primary authentication of the remote wireless communication device, and transmitting a response to the request for primary authentication to the proximity service anchor node, the response to the request for primary authentication including the proximity service relay user key. In one or more of these embodiments, the response also includes a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device.

[0146] In some embodiments, the method further includes sending to the proximity service anchor node an identifier bound to the proximity service relay user key.

[0147] In some embodiments, the method further includes transmitting to the proximity service anchor node a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device.

[0148] In some embodiments, the method further includes sending a request to the proximity service anchor node to register a proximity service relay user key with the proximity service anchor node, where the proximity service relay user key is included in the request to register the proximity service relay user key. In one or more of these embodiments, the request to register the proximity service relay user key also includes an identifier bound to the proximity service relay user key and / or a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device.

[0149] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0150] In some embodiments, the authentication server implements an authentication server function (AUSF).

[0151] In some embodiments, the proximity services relay user key is a certificate from which a shared key for protecting an interface between a remote wireless communication device and a relay wireless communication device can be derived, where the relay wireless communication device is configured to relay traffic for the remote wireless communication device. In one or more of these embodiments, the interface is a PC5 interface. In one or more of these embodiments, the relay wireless communication device is a Layer 3 UE-to-network relay.

[0152] 11 illustrates a method performed by a network node serving a relay wireless communication device configured to relay traffic for a remote wireless communication device according to another specific embodiment. The method includes sending a request to a nearby service anchor node for a shared key for protecting an interface between the remote wireless communication device and the relay wireless communication device (block 1100). The method also includes receiving the shared key from the nearby service anchor node in response to the request (block 1110) and sending the shared key to the relay wireless communication device (block 1120).

[0153] In some embodiments, the shared key is derivable from a proximity service relay user key, where the proximity service relay user key is based on and / or unique to some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0154] In some embodiments, the shared key request includes an identifier bound to a proximity service relay user key. In this case, the received shared key is derived from the proximity service relay user key. In one or more of these embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0155] In some embodiments, the shared key request includes a subscription identifier that identifies the subscription of the remote wireless communication device to the home network of the remote wireless communication device.

[0156] In some embodiments, the shared key is key K NR_ProSe is.

[0157] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0158] In some embodiments, the interface is a PC5 interface.

[0159] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0160] 12 illustrates a method performed by a remote wireless communication device according to another specific embodiment, including transmitting a request to a relay wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication (block 1200), where the request requests reuse of a proximity services relay user key already associated with the remote wireless communication device.

[0161] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0162] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0163] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0164] In some embodiments, the method further includes receiving a response to the request from the relay wireless communication device indicating that the proximity services relay user key should be reused.

[0165] In some embodiments, the method further includes reusing the proximity service relay user key to generate a shared key for protecting an interface between the remote wireless communication device and the relay wireless communication device (block 1210), and protecting the interface using the shared key (block 1220). In one or more of these embodiments, the shared key is key K NR_ProSeIn one or more of these embodiments, the interface is a PC5 interface.

[0166] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0167] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0168] 13 illustrates a method performed by a relay wireless communication device, including receiving a request from a remote wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication (Block 1300), where the request requests reuse of a proximity services relay user key already associated with the remote wireless communication device.

[0169] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0170] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0171] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0172] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0173] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0174] In some embodiments, the method further includes sending a request for a shared key to a network node serving the relay wireless communication device for protecting an interface between the remote wireless communication device and the relay wireless communication device (block 1310). In this case, the request for the shared key requests reuse of a proximity service relay user key to derive the shared key. In one or more of these embodiments, the request for the shared key includes a proximity service relay user key reuse flag that requests reuse of the proximity service relay user key. In one or more of these embodiments, the method further includes receiving a response to the request for the shared key from the network node (block 1320). In this case, the response to the request for the shared key includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0175] In some embodiments, the method further includes sending a response to the request to the remote wireless communication device indicating that the proximity services relay user key should be reused (block 1330).

[0176] 14 illustrates a method performed by a relay wireless communications device. In some embodiments, the method includes sending a request to a network node serving the relay wireless communications device for a shared key for protecting an interface between the remote wireless communications device and the relay wireless communications device (block 1410). In this case, the relay wireless communications device is configured to relay traffic for the remote wireless communications device, and the request for the shared key requires reuse of a proximity services relay user key to derive the shared key.

[0177] In some embodiments, the request for a shared key includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key.

[0178] In some embodiments, the method includes receiving a response to the request for the shared key from the network node (block 1420), where the response to the request for the shared key includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0179] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0180] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0181] In some embodiments, the method includes receiving a request from a remote wireless communication device for a relay wireless communication device to relay traffic for the remote wireless communication (block 1400). In this case, the request requests reuse of a proximity services relay user key already associated with the remote wireless communication device. In some embodiments, the method further includes sending a response to the request to the remote wireless communication device (block 1430). In this case, the response includes a shared key and indicates that the proximity services relay user key should be reused to derive the shared key.

[0182] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0183] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0184] In some embodiments, the shared key is key K NR_ProSe is.

[0185] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0186] In some embodiments, the interface is a PC5 interface.

[0187] 15 illustrates a method performed by a network node serving a relay wireless communications device, the method including receiving a request from the relay wireless communications device for a shared key for protecting an interface between the relay wireless communications device and the remote wireless communications device (Block 1500), where the relay wireless communications device is configured to relay traffic for the remote wireless communications device, and the request requires reuse of a proximity services relay user key to derive the shared key.

[0188] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0189] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0190] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0191] In some embodiments, the method further includes transmitting a response to the request to the relay wireless communication device (block 1510), where the response includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0192] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0193] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0194] In some embodiments, the shared key is key K NR_ProSe is.

[0195] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0196] In some embodiments, the interface is a PC5 interface.

[0197] 16 illustrates a method performed by a network node serving a relay wireless communications device, the method including sending to an authentication server a request for authentication of a remote wireless communications device (block 1600), where the request requires reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communications device and the relay wireless communications device, the relay wireless communications device being configured to relay traffic for the remote wireless communications device.

[0198] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0199] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0200] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0201] In some embodiments, the method further includes receiving a response to the request from the authentication server (block 1610), where the response includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0202] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0203] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0204] In some embodiments, the shared key is key K NR_ProSe is.

[0205] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0206] In some embodiments, the interface is a PC5 interface.

[0207] 17 illustrates a method performed by an authentication server, including receiving (block 1700) a request for authentication of a remote wireless communication device, where the request requires reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device.

[0208] In some embodiments, the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0209] In some embodiments, the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

[0210] In some embodiments, the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

[0211] In some embodiments, the method further includes sending a response to the request (block 1710), where the response includes the shared key and indicates that the proximity service relay user key should be reused to derive the shared key.

[0212] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0213] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0214] In some embodiments, the shared key is key K NR_ProSe is.

[0215] In some embodiments, the request is received from an Access and Mobility Function (AMF).

[0216] In some embodiments, the interface is a PC5 interface.

[0217] In some embodiments, the method further includes sending a request for authentication credentials for the remote wireless communication device to the data management node. In this case, the request for authentication credentials requests reuse of a proximity services relay user key. In one or more of these embodiments, the method further includes receiving a response to the request for authentication credentials from the data management node. In this case, the response indicates whether the proximity services relay user key is available for reuse. In one or more of these embodiments, the response indicates that the proximity services relay user key is available for reuse. In some embodiments, the method further includes obtaining a shared key as derived from the proximity services relay user key and sending a response to the request for authentication. In this case, the response to the request for authentication includes the obtained shared key and indicates that the proximity services relay user key should be reused to derive the shared key. In one or more of these embodiments, obtaining the shared key includes retrieving the proximity services relay user key from local storage at the authentication server and deriving the shared key from the retrieved proximity services relay user key. In one or more of these embodiments, obtaining the shared key includes forwarding the request for authentication to another authentication server having a proximity service relay user key stored therein and receiving the shared key from the other authentication server as derived from the proximity service relay user key. In one or more of these embodiments, the response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials. In this case, the method further includes generating a proximity service relay user key based on keying material derived during authentication of the remote wireless communication device, where the authentication of the remote wireless communication device is based on the authentication credentials, deriving the shared key from the generated proximity service relay user key, and sending a response to the request for authentication. In this case, the response to the request for authentication includes the derived shared key.In one or more of these embodiments, the response to the request for authentication indicates that the proximity services relay user key should not be reused to derive the shared key. Alternatively or additionally, the method may further include, after generating the proximity services relay user key, sending signaling to the data management node indicating that the proximity services relay user key for the remote wireless communication device is available for reuse and indicating an identity of the authentication server on which the proximity services relay user key is stored.

[0218] 18 illustrates a method performed by an authentication server, including sending a request for authentication credentials for a remote wireless communication device to a data management node (block 1800), where the request for authentication credentials requests reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device.

[0219] In some embodiments, the request is received from a network node that serves the relay wireless communications device, while in other embodiments, the request is received from another authentication server.

[0220] In some embodiments, the method further includes receiving a response to the request for authentication credentials from the data management node (block 1810). In this case, the response indicates whether the proximity service relay user key is available for reuse. In one or more of these embodiments, the response indicates that the proximity service relay user key is available for reuse. In this case, the method further includes obtaining a shared key as derived from the proximity service relay user key and sending a response to the request for authentication to the network node. In this case, the response to the request for authentication includes the obtained shared key and indicates that the proximity service relay user key should be reused to derive the shared key. In one or more of these embodiments, obtaining the shared key includes retrieving the proximity service relay user key from local storage at the authentication server and deriving the shared key from the retrieved proximity service relay user key. In one or more of these embodiments, obtaining the shared key includes forwarding the request for authentication to another authentication server having the proximity service relay user key stored therein and receiving the shared key from the other authentication server as derived from the proximity service relay user key.

[0221] In some embodiments, the response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials. In this case, the method further includes generating a proximity service relay user key based on keying material derived during authentication of the remote wireless communication device. In this case, authentication of the remote wireless communication device is based on the authentication credentials. The method further includes deriving a shared key from the generated proximity service relay user key and sending a response to the request for authentication to the network node. In this case, the response to the request for authentication includes the derived shared key. In one or more of these embodiments, the response to the request for authentication indicates that the proximity service relay user key should not be reused to derive the shared key.

[0222] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0223] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0224] In some embodiments, the shared key is key K NR_ProSe is.

[0225] In some embodiments, the network node implements an Access and Mobility Function (AMF).

[0226] In some embodiments, the interface is a PC5 interface.

[0227] 19 illustrates a method performed by a data management node, including receiving a request for authentication credentials for a remote wireless communication device from an authentication server (block 1900), where the request for authentication credentials requests reuse of a proximity services relay user key to derive a shared key for protecting an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device.

[0228] In some embodiments, the method further includes sending a response to the request to the authentication server (block 1910). In this case, the response indicates whether the proximity service relay user key is available for reuse. In one or more of these embodiments, the response indicates that the proximity service relay user key is available for reuse. In one or more of these embodiments, the response indicates an identity of the authentication server on which the proximity service relay user key is stored. In one or more of these embodiments, the response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials. In one or more of these embodiments, the method further includes, after sending the response, receiving signaling indicating the identity of the authentication server on which the proximity service relay user key is stored, and storing information at the data management node indicating that the proximity service relay user key for the remote wireless communication device is available for reuse and indicating the identity of the authentication server on which the proximity service relay user key is stored.

[0229] In some embodiments, the method further includes determining whether a proximity services relay user key is available for reuse based on information at the data management node indicating whether a proximity services relay user key is stored for the remote wireless communication device.

[0230] In some embodiments, the proximity service relay user key is a 5G proximity service relay user key (5GPRUK).

[0231] In some embodiments, the relay wireless communications device is a Layer 3 UE-to-network relay.

[0232] In some embodiments, the shared key is key K NR_ProSe is.

[0233] In some embodiments, the interface is a PC5 interface.

[0234] Embodiments herein also include corresponding apparatus, for example, a wireless communication device configured to perform any of the steps of any of the embodiments described above for a remote wireless communication device or a relay wireless communication device.

[0235] Embodiments also include a wireless communication device comprising a processing circuit and a power supply circuit, the processing circuit configured to perform any of the steps of any of the embodiments described above for the remote wireless communication device or the relay wireless communication device, and the power supply circuit configured to supply power to the wireless communication device.

[0236] Embodiments further include a wireless communication device comprising a processing circuit configured to perform any of the steps of any of the embodiments described above for the remote wireless communication device or the relay wireless communication device. In some embodiments, the wireless communication device further comprises the communication circuit.

[0237] Embodiments further include a wireless communication device comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit to configure the wireless communication device to perform any of the steps of any of the embodiments described above for the remote wireless communication device or the relay wireless communication device.

[0238] Embodiments also include user equipment (UE). The UE comprises an antenna configured to send and receive wireless signals. The UE also comprises radio front-end circuitry connected to the antenna and processing circuitry and configured to condition signals communicated between the antenna and processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the remote wireless communication device or the relay wireless communication device. In some embodiments, the UE also comprises an input interface connected to the processing circuitry and configured to allow information input to the UE to be processed by the processing circuitry. The UE may also comprise an output interface connected to the processing circuitry and configured to output information from the UE processed by the processing circuitry. The UE may also comprise a battery connected to the processing circuitry and configured to provide power to the UE.

[0239] Embodiments herein also include a proximity service anchor node configured to perform any of the steps of any of the embodiments described above for the proximity service anchor node.

[0240] Embodiments also include a proximity service anchor node comprising a processing circuit and a power supply circuit, the processing circuit configured to perform any of the steps of any of the embodiments described above for the proximity service anchor node, and the power supply circuit configured to supply power to the proximity service anchor node.

[0241] Embodiments further include a proximity service anchor node comprising processing circuitry configured to perform any of the steps of any of the embodiments described above for the proximity service anchor node, hi some embodiments, the proximity service anchor node further comprises communications circuitry.

[0242] Embodiments further include a proximity service anchor node comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit whereby the proximity service anchor node is configured to perform any of the steps of any of the embodiments described above for the proximity service anchor node.

[0243] Embodiments herein also include an authentication server configured to perform any of the steps of any of the embodiments described above for the authentication server.

[0244] Embodiments also include an authentication server comprising a processing circuit and a power supply circuit, the processing circuit configured to perform any of the steps of any of the embodiments described above for the authentication server, and the power supply circuit configured to supply power to the authentication server.

[0245] Embodiments further include an authentication server comprising processing circuitry configured to perform any of the steps of any of the embodiments described above for the authentication server. In some embodiments, the authentication server further comprises communications circuitry.

[0246] An embodiment further includes an authentication server comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit to configure the authentication server to perform any of the steps of any of the embodiments described above for the authentication server.

[0247] Embodiments herein also include a network node 24 configured to perform any of the steps of any of the embodiments described above for the network node 24 .

[0248] Embodiments also include an authentication server comprising a processing circuit and a power supply circuit, the processing circuit configured to perform any of the steps of any of the embodiments described above for the network node 24. The power supply circuit is configured to supply power to the network node 24.

[0249] Embodiments further include a network node 24 comprising processing circuitry configured to perform any of the steps of any of the embodiments described above for the network node 24. In some embodiments, the network node 24 further comprises communications circuitry.

[0250] The embodiment further includes a network node 24 comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit to configure the network node 24 to perform any of the steps of any of the embodiments described above for the network node 24.

[0251] Embodiments herein also include a data management node 40 configured to perform any of the steps of any of the embodiments described above for the data management node 40 .

[0252] The embodiment also includes a data management node 40 comprising a processing circuit and a power supply circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the data management node 40. The power supply circuit is configured to supply power to the data management node 40.

[0253] Embodiments further include a data management node 40 comprising processing circuitry configured to perform any of the steps of any of the embodiments described above for the data management node 40. In some embodiments, the wireless data management node 40 further comprises communications circuitry.

[0254] The embodiment further includes a data management node 40 comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit to configure the data management node 40 to perform any of the steps of any of the embodiments described above for the data management node 40.

[0255] More specifically, the apparatus described above may perform the methods and any other processes herein by implementing any functional means, modules, units, or circuits. In one embodiment, for example, an apparatus comprises a respective circuit or circuitry configured to perform the steps illustrated in the method diagrams. The circuit or circuitry, in this regard, may comprise one or more microprocessors along with circuitry and / or memory dedicated to performing certain functional processes. For example, the circuitry may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), dedicated digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory, such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, and the like. The program code stored in memory may, in some embodiments, include program instructions for executing one or more communication and / or data communication protocols, as well as instructions for performing one or more of the techniques described herein. In embodiments that employ memory, the memory stores program code that, when executed by one or more processors, performs the techniques described herein.

[0256] FIG. 20 illustrates, for example, a wireless communication device 2000 implemented in accordance with one or more embodiments. The wireless communication device 2000 may be a remote wireless communication device or a relay wireless communication device. As shown, the wireless communication device 2000 includes a processing circuit 2010 and a communication circuit 2020. The communication circuit 2020 (e.g., a radio circuit) is configured to transmit information to and / or receive information from one or more other nodes, for example, via any communication technology. Such communication may occur via one or more antennas either internal or external to the wireless communication device 2000. The processing circuit 2010 is configured to perform the processing described above, for example, in FIG. 12, FIG. 13, and / or FIG. 14, such as by executing instructions stored in a memory 2030. The processing circuit 2010 may implement several functional means, units, or modules in this regard.

[0257] 21 illustrates a proximity service anchor node 30 implemented in accordance with one or more embodiments. As shown, the proximity service anchor node 30 includes a processing circuit 2110 and a communication circuit 2120. The communication circuit 2120 is configured to transmit information to and / or receive information from one or more other nodes, e.g., via any communication technology. The processing circuit 2110 is configured to perform the processes described above, e.g., in FIG. 9, such as by executing instructions stored in a memory 2130. The processing circuit 2110 may implement several functional means, units, or modules in this regard.

[0258] FIG. 22 illustrates an authentication server 32 implemented in accordance with one or more embodiments. As shown, the authentication server 32 includes a processing circuit 2210 and a communications circuit 2220. The communications circuit 2220 is configured to transmit information to and / or receive information from one or more other nodes, e.g., via any communications technology. The processing circuit 2210 is configured to perform the processes described above, e.g., in FIG. 10, FIG. 17, and / or FIG. 18, such as by executing instructions stored in a memory 2230. The processing circuit 2210 may implement several functional means, units, or modules in this regard.

[0259] FIG. 23 illustrates a network node 24 implemented in accordance with one or more embodiments. As shown, the network node 24 includes a processing circuit 2310 and a communications circuit 2320. The communications circuit 2320 is configured to transmit information to and / or receive information from one or more other nodes, e.g., via any communications technology. The processing circuit 2310 is configured to perform the processes described above, e.g., in FIG. 11 , FIG. 15 , and / or FIG. 16 , such as by executing instructions stored in a memory 2330. The processing circuit 2310 may implement several functional means, units, or modules in this regard.

[0260] 24 illustrates a data management node 40 implemented in accordance with one or more embodiments. As shown, the data management node 40 includes a processing circuit 2410 and a communication circuit 2420. The communication circuit 2420 is configured to transmit information to and / or receive information from one or more other nodes, e.g., via any communication technology. The processing circuit 2410 is configured to perform the processes described above, e.g., in FIG. 19 , such as by executing instructions stored in a memory 2430. The processing circuit 2410 may implement several functional means, units, or modules in this regard.

[0261] Those skilled in the art will also appreciate that the embodiments herein further include corresponding computer programs.

[0262] The computer program comprises instructions which, when executed on at least one processor of the apparatus, cause the apparatus to perform any of the respective operations described above. The computer program may in this regard comprise one or more code modules which correspond to the means or units described above.

[0263] Embodiments further include a carrier containing such a computer program, which may comprise one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.

[0264] In this regard, embodiments herein also include a computer program product comprising instructions stored on a non-transitory computer-readable (storage or recording) medium that, when executed by a processor of the device, cause the device to perform as described above.

[0265] Embodiments further include a computer program product, which may be stored on a computer-readable recording medium, comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by a computing device.

[0266] FIG. 25 illustrates an example of a communication system 2500, according to some embodiments.

[0267] In this example, communications system 2500 includes communications network 2502 including an access network 2504, such as a radio access network (RAN), and a core network 2506 including one or more core network nodes 2508. Access network 2504 includes one or more access network nodes (one or more of which may be generally referred to as network nodes 2510), such as network nodes 2510a and 2510b, or any other similar Third Generation Partnership Project (3GPP) access nodes or non-3GPP access points. Network node 2510 facilitates direct or indirect connectivity of user equipment (UE), such as by connecting UEs 2512a, 2512b, 2512c, and 2512d (one or more of which may be generally referred to as UEs 2512), to core network 2506 over one or more wireless connections.

[0268] Exemplary wireless communication over a wireless connection includes sending and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, communication system 2500 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals, whether via a wired or wireless connection. Communication system 2500 may include and / or interface with any type of communication, telecommunication, data, cellular, wireless network, and / or other similar type systems.

[0269] The UE 2512 may be any of a wide variety of communications devices, including a wireless device configured, configured, and / or operable to communicate wirelessly with the network node 2510 and other communications devices. Similarly, the network node 2510 is configured, capable of, configured, and / or operable to communicate, directly or indirectly, with the UE 2512 and / or with other network nodes or equipment in the communications network 2502 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration, in the communications network 2502.

[0270] In the illustrated example, the core network 2506 connects the network node 2510 to one or more hosts, such as the host 2516. These connections may be direct or indirect via one or more intermediate networks or devices. In other examples, the network node may be directly coupled to the host. The core network 2506 includes one or more core network nodes (e.g., the core network node 2508) structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, and therefore, those descriptions are generally applicable to the corresponding components of the core network node 2508. Exemplary core network nodes include one or more of a Mobile Switching Center (MSC), a Mobility Management Entity (MME), a Home Subscriber Server (HSS), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Subscription Identifier De-concealing Function (SIDF), a Unified Data Management (UDM), a Security Edge Protection Proxy (SEPP), a Network Publishing Function (NEF), and / or a User Plane Function (UPF).

[0271] The host 2516 may be owned or under the control of, and operated by or on behalf of, a service provider other than the operator or provider of the access network 2504 and / or the communications network 2502. The host 2516 may host various applications to provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data about various ambient conditions detected by multiple UEs, analytics functions, social media, functions for controlling or possibly interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0272] 25 enables connectivity between UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as a particular standard, including, but not limited to, Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G), a wireless local area network (WLAN) standard such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard (WiFi), and / or any other suitable wireless communication standard, such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communications (NFC) ZigBee, LiFi, and / or any low power wide area network (LPWAN) standard such as LoRa and Sigfox.

[0273] In some examples, communication network 2502 is a cellular network implementing 3GPP standardized features. Thus, communication network 2502 may support network slicing to provide different logical networks to different devices connected to communication network 2502. For example, communication network 2502 may provide Ultra-Reliable Low Latency Communication (URLLC) services to some UEs, while providing enhanced Mobile Broadband (eMBB) services to other UEs and / or providing Massive Machine-Based Communication (mMTC) / Massive IoT services to still further UEs.

[0274] In some examples, the UE 2512 is configured to transmit and / or receive information without direct human interaction. For example, the UE may be designed to transmit information to the access network 2504 on a predetermined schedule, when triggered by an internal or external event, or in response to a request from the access network 2504. Furthermore, the UE may be configured to operate in a single or multi-RAT or multi-standard mode. For example, the UE may operate in any one or a combination of Wi-Fi, NR (New Radio), and LTE, i.e., configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Enhanced UMTS Terrestrial Radio Access Network) New Radio-Dual Connectivity (EN-DC).

[0275] In this example, the hub 2514 communicates with the access network 2504 to facilitate indirect communication between one or more UEs (e.g., UEs 2512c and / or 2512d) and a network node (e.g., network node 2510b). In some examples, the hub 2514 may be a controller, a router, a content source, a content analyzer, or any of the other communication devices described herein with respect to UEs. For example, the hub 2514 may be a broadband router that enables access to the core network 2506 for the UE. As another example, the hub 2514 may be a controller that sends commands or instructions to one or more actuators in the UE. The commands or instructions may be received from the UE, the network node 2510, or may be due to executable code, scripts, processes, or other instructions in the hub 2514. As another example, the hub 2514 may be a data collector that serves as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 2514 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker, or other media distribution device, the hub 2514 may retrieve, via a network node, VR assets, video, audio, or other media or data related to sensory information, which the hub 2514 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In yet another example, the hub 2514 acts as a proxy server or orchestrator for the UEs, particularly in the case where one or more of the UEs are low-energy IoT devices.

[0276] The hub 2514 may have a constant / permanent or intermittent connection to the network node 2510b. The hub 2514 may also enable different communication schemes and / or schedules between the hub 2514 and the UEs (e.g., UEs 2512c and / or 2512d) and between the hub 2514 and the core network 2506. In other examples, the hub 2514 is connected to the core network 2506 and / or one or more UEs via a wired connection. Additionally, the hub 2514 may be configured to connect to an M2M service provider over the access network 2504 and / or to another UE over a direct connection. In some scenarios, a UE may establish a wireless connection with the network node 2510 while still connected via a wired or wireless connection through the hub 2514. In some embodiments, the hub 2514 may be a dedicated hub, i.e., a hub whose primary function is to route communications from / to the UE to / from the network node 2510b. In other embodiments, the hub 2514 may be a non-dedicated hub, i.e., a device that is capable of operating to route communications between the UE and the network node 2510b, but that is further capable of operating as a communication initiation and / or termination point for some data channels.

[0277] Figure 26 illustrates a UE 2600, according to some embodiments. As used herein, a UE refers to a device capable of, set up, configured, and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smartphone, a mobile phone, a cell phone, a voice-over-IP (VoIP) phone, a wireless local loop phone, a desktop computer, a personal digital assistant (PDA), a wireless camera, a gaming console or device, a music storage device, a playback appliance, a wearable terminal device, a wireless endpoint, a mobile station, a tablet, a laptop computer, a laptop embedded equipment (LEE), a laptop mounted equipment (LME), a smart device, a wireless customer premises equipment (CPE), a vehicle-mounted or vehicle-embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrowband Internet of Things (NB-IoT) UE, a machine-type communications (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0278] A UE may support device-to-device (D2D) communications, for example, by implementing 3GPP standards for sidelink communications, dedicated short-range communications (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE does not necessarily have a user in the sense of a human user who owns and / or operates an associated device. Instead, a UE may represent a device (e.g., a smart sprinkler controller) that is intended for sale to or operation by a human user, but may not be associated with or initially associated with a particular human user. Alternatively, a UE may represent a device (e.g., a smart power meter) that is not intended for sale to or operation by an end user, but may be associated with or operated for the user's benefit.

[0279] The UE 2600 includes a processing circuit 2602 operably coupled to an input / output interface 2606, a power source 2608, a memory 2610, a communication interface 2612, and / or any other components, or any combination thereof, via a bus 2604. Some UEs may utilize all or a subset of the components shown in FIG. 26. The level of integration between components may vary from UE to UE. Additionally, some UEs may include multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0280] The processing circuit 2602 is configured to process instructions and data and may be configured to implement any sequential state machine operable to execute instructions stored in memory 2610 as a machine-readable computer program. The processing circuit 2602 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, a field programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.), programmable logic together with appropriate firmware, one or more stored computer programs such as a microprocessor or digital signal processor (DSP) together with appropriate software, a general-purpose processor, or any combination of the above. For example, the processing circuit 2602 may include multiple central processing units (CPUs).

[0281] In this example, the input / output interface 2606 may be configured to provide one or more interfaces to an input device, an output device, or one or more input and / or output devices. Examples of output devices include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smart card, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 2600. Examples of input devices include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a webcam, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smart card, etc. A presence-sensitive display may include a capacitive or resistive touch sensor for detecting input from a user. The sensor may be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, a light sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as the input device. For example, a universal serial bus (USB) port may be used to accommodate input and output devices.

[0282] In some embodiments, the power source 2608 is structured as a battery or battery pack. Other types of power sources may be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or a battery. The power source 2608 may further include power circuitry for delivering power to various portions of the UE 2600 from the power source 2608 itself and / or from an external power source via an input circuit or an interface such as a power cable. Delivering power may be for charging the power source 2608, for example. The power circuitry may perform any formatting, conversion, or other modification on the power from the power source 2608 to make it suitable for each component of the UE 2600 being powered.

[0283] The memory 2610 may be or be configured to include memory, such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, hard disk, removable cartridge, flash drive, etc. In one example, the memory 2610 includes one or more application programs 2614, such as an operating system, a web browser application, a widget, a gadget engine, or other applications, and corresponding data 2616. The memory 2610 may store any of a variety of different operating systems or combinations of operating systems for use by the UE 2600.

[0284] The memory 2610 may be configured to include several physical drive units, such as a redundant array of independent disks (RAID), flash memory, a USB flash drive, an external hard disk drive, a thumb drive, a pen drive, a key drive, a high-density digital versatile disc (HD-DVD) optical disc drive, an internal hard disk drive, a Blu-ray optical disc drive, a holographic digital data storage (HDDS) optical disc drive, an external mini dual in-line memory module (DIMM), a synchronous dynamic random access memory (SDRAM), an external micro-DIMM SDRAM, a smart card memory, such as a tamper-resistant module in the form of a universal integrated circuit card (UICC) containing one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may be, for example, an embedded UICC (eUICC), an integrated UICC (iUICC), or a removable UICC, commonly known as a "SIM card." The memory 2610 may enable the UE 2600 to access, offload, or upload data, instructions, application programs, etc. stored on a temporary or non-transitory memory medium. An article of manufacture, such as an article of manufacture utilizing a communication system, may be tangibly embodied as or in the memory 2610, which may be or comprise a device-readable storage medium.

[0285] The processing circuit 2602 may be configured to communicate with an access network or other networks using a communication interface 2612. The communication interface 2612 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 2622. The communication interface 2612 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or network node in the access network). Each transceiver may include a transmitter 2618 and / or a receiver 2620 suitable for providing network communication (e.g., optical, electrical, frequency allocation, etc.). Moreover, the transmitter 2618 and receiver 2620 may be coupled to one or more antennas (e.g., antenna 2622) and may share circuit components, software, or firmware, or may alternatively be implemented separately.

[0286] In the illustrated embodiment, the communication capabilities of communication interface 2612 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication such as use of a Global Positioning System (GPS) to determine location, another similar communication capability, or any combination thereof. Communications may be implemented in accordance with one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, Transmission Control Protocol / Internet Protocol (TCP / IP), Synchronous Optical Networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), etc.

[0287] Regardless of the type of sensor, the UE may provide an output of data captured by the UE's sensors to a network node via a wireless connection through the UE's communications interface 2612. Data captured by the UE's sensors may be communicated to a network node via another UE over a wireless connection. The output may be periodic (e.g., once every 15 minutes when reporting detected temperature), in response to a triggering event (e.g., an alert is sent when humidity is detected), in response to a request (e.g., a user-initiated request), random (e.g., to even out the load from reporting from several sensors), or a continuous stream (e.g., a live video feed of a patient).

[0288] As another example, the UE may include an actuator, motor, or switch associated with a communications interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input, the actuator, motor, or switch may change state. For example, the UE may include a motor that adjusts a control surface or rotor of a drone in flight according to the received input, or a robotic arm that performs a medical procedure according to the received input.

[0289] When in the form of an Internet of Things (IoT) device, the UE may be a device for use in one or more application areas, including, but not limited to, urban wearable technology, augmented industrial applications, and healthcare. Non-limiting examples of such IoT devices are devices that are or are embedded in a connected refrigerator or freezer, a TV, a connected lighting device, an energy meter, a robotic vacuum cleaner, a voice-controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a water inundation / humidity sensor, an electronic door lock, a connected doorbell, an air conditioning system such as a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for augmented reality (AR) or virtual reality (VR), a wearable for haptic augmentation or sensory augmentation, a water sprinkler, an animal or product tracking device, a sensor for monitoring plants or animals, an industrial robot, an unmanned aerial vehicle (UAV), and any type of medical device such as a heart rate monitor or a remote-controlled surgical robot. A UE in the form of an IoT device comprises, in addition to the other components described with respect to UE 2600 shown in FIG. 26, circuitry and / or software depending on the intended application of the IoT device.

[0290] As yet another particular example, in an IoT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements and transmits results of such monitoring and / or measurements to another UE and / or network node. The UE, in this case, may be an M2M device, which may be referred to as an MTC device in a 3GPP context. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, bus, truck, ship, and airplane, or other equipment capable of monitoring and / or reporting on its operating status or other functionality associated with its operation.

[0291] In practice, any number of UEs may be used together for a single use case. For example, a first UE may be a drone or be integrated in a drone and provide the drone's speed information (obtained through a speed sensor) to a second UE that is a remote controller that operates the drone. When a user makes changes from the remote controller, the first UE may adjust a throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone's speed. The first and / or second UE may also include two or more of the functions described above. For example, a UE may include a sensor and an actuator and handle communication of data for both the speed sensor and the actuator.

[0292] 27 illustrates a network node 2700 according to some embodiments. As used herein, a network node refers to a device capable of, set up, configured, and / or operable to communicate, directly or indirectly, with UEs and / or other network nodes or devices in a communication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., wireless access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), and NR Node Bs (gNBs)).

[0293] Base stations may be categorized based on the amount of coverage they provide (or, stated another way, their transmit power level) and may therefore be referred to as femto, pico, micro, or macro base stations depending on the amount of coverage provided. A base station may be a relay node or a relay donor node that controls a relay. A network node may also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU), sometimes referred to as a remote radio head (RRH). Such remote radio units may or may not be integrated with an antenna, as in an antenna-integrated radio. Portions of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0294] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, MSR equipment such as a multi-standard radio (MSR) BS, a network controller such as a radio network controller (RNC) or base station controller (BSC), a base transceiver station (BTS), a transmission point, a transmitting node, a multi-cell / multicast coordination entity (MCE), an operation and maintenance (O&M) node, an operation support system (OSS) node, a self-organizing network (SON) node, a positioning node (e.g., an evolved serving mobile location center (E-SMLC)), and / or a minimization of drive test (MDT).

[0295] The network node 2700 includes a processing circuit 2702, a memory 2704, a communication interface 2706, and a power source 2708. The network node 2700 may be assembled from multiple physically separate components (e.g., a Node B component and an RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In some scenarios in which the network node 2700 comprises multiple separate components (e.g., a BTS component and a BSC component), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple Node Bs. In such scenarios, each unique Node B and RNC pair may, in some instances, be considered a single separate network node. In some embodiments, the network node 2700 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 2704 for different RATs) and some components may be reused (e.g., the same antenna 2710 may be shared by different RATs). Network node 2700 may also include multiple sets of the various shown components for different wireless technologies, e.g., GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, radio frequency identification (RFID), or Bluetooth wireless technologies, integrated into network node 2700. These wireless technologies may be integrated into the same or different chips or sets of chips and other components within network node 2700.

[0296] The processing circuit 2702 may comprise one or more combinations of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable to provide the network node 2700 functionality, either alone or in conjunction with other network node 2700 components such as memory 2704.

[0297] In some embodiments, the processing circuit 2702 comprises a system on a chip (SOC). In some embodiments, the processing circuit 2702 includes one or more of a radio frequency (RF) transceiver circuit 2712 and a baseband processing circuit 2714. In some embodiments, the radio frequency (RF) transceiver circuit 2712 and the baseband processing circuit 2714 may be on separate chips (or sets of chips), boards, or units, such as a radio unit and a digital unit. In alternative embodiments, some or all of the RF transceiver circuit 2712 and the baseband processing circuit 2714 may be on the same chip or set of chips, board, or unit.

[0298] The memory 2704 may comprise any form of volatile or non-volatile computer-readable memory, including, but not limited to, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disk), removable storage media (e.g., flash drive, compact disc (CD) or digital video disc (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions that may be used by the processing circuit 2702. The memory 2704 may store any suitable instructions, data, or information, including applications including one or more of computer programs, software, logic, rules, code, tables, and / or other instructions that can be executed by the processing circuit 2702 and utilized by the network node 2700. The memory 2704 may be used to store computations performed by the processing circuit 2702 and / or data received via the communications interface 2706. In some embodiments, the processing circuit 2702 and the memory 2704 are integrated.

[0299] The communications interface 2706 is used in wired or wireless communication of signaling and / or data between network nodes, access networks, and / or UEs. As shown, the communications interface 2706 comprises port(s) / terminal(s) 2716 for sending and receiving data to and from a network, e.g., over a wired connection. The communications interface 2706 also includes radio front-end circuitry 2718, which is coupled to an antenna 2710 or, in some embodiments, may be part of the antenna 2710. The radio front-end circuitry 2718 comprises a filter 2720 and an amplifier 2722. The radio front-end circuitry 2718 may be connected to the antenna 2710 and the processing circuit 2702. The radio front-end circuitry may be configured to condition signals communicated between the antenna 2710 and the processing circuit 2702. The radio front-end circuitry 2718 may receive digital data to be sent to other network nodes or UEs via a wireless connection. The radio front-end circuitry 2718 may convert the digital data into radio signals having appropriate channel and bandwidth parameters using a combination of filters 2720 and / or amplifiers 2722. The radio signals may then be transmitted via the antenna 2710. Similarly, when receiving data, the antenna 2710 may collect the radio signals, which are then converted into digital data by the radio front-end circuitry 2718. The digital data may be passed to the processing circuitry 2702. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0300] In some alternative embodiments, the network node 2700 does not include a separate radio front-end circuit 2718; instead, the processing circuit 2702 includes the radio front-end circuitry and is connected to the antenna 2710. Similarly, in some embodiments, all or a portion of the RF transceiver circuitry 2712 is part of the communications interface 2706. In still other embodiments, the communications interface 2706 includes one or more ports or terminals 2716, the radio front-end circuitry 2718, and the RF transceiver circuitry 2712 as part of a radio unit (not shown), and the communications interface 2706 communicates with baseband processing circuitry 2714 that is part of a digital unit (not shown).

[0301] The antenna 2710 may include one or more antennas or an antenna array configured to send and / or receive wireless signals. The antenna 2710 may be coupled to the radio front-end circuitry 2718 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, the antenna 2710 is separate from the network node 2700 and connectable to the network node 2700 through an interface or port.

[0302] The antenna 2710, the communication interface 2706, and / or the processing circuit 2702 may be configured to perform any receiving operation and / or some obtaining operation described herein as being performed by a network node. Any information, data, and / or signal may be received from a UE, another network node, and / or any other network equipment. Similarly, the antenna 2710, the communication interface 2706, and / or the processing circuit 2702 may be configured to perform any transmitting operation described herein as being performed by a network node. Any information, data, and / or signal may be transmitted to a UE, another network node, and / or any other network equipment.

[0303] The power supply 2708 provides power to the various components of the network node 2700 in a form suitable for each component (e.g., at the voltage and current levels required for each respective component). The power supply 2708 may further comprise, or be coupled to, power management circuitry for supplying power to the components of the network node 2700 for performing the functions described herein. For example, the network node 2700 may be connectable to an external power source (e.g., a power grid, an electrical outlet) via an input circuit or interface such as an electrical cable, whereby the external power source supplies power to the power circuitry of the power supply 2708. As a further example, the power supply 2708 may comprise a power source in the form of a battery or battery pack connected to or integrated in the power circuitry. The battery may provide backup power in the event that the external power source fails.

[0304] Embodiments of network node 2700 may include additional components other than those shown in Figure 27 to provide certain aspects of the network node's functionality, including any of the functionality described herein and / or functionality necessary to support the subject matter described herein. For example, network node 2700 may include user interface devices to enable input of information into network node 2700 and output of information from network node 2700. This may enable a user to perform diagnostic, maintenance, repair, and other administrative functions for network node 2700.

[0305] 28 is a block diagram of a host 2800, which may be an embodiment of the host 2516 of FIG. 25, in accordance with various aspects described herein. As used herein, the host 2800 may be or comprise various combinations of hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, a container, or processing resources in a server farm. The host 2800 may provide one or more services to one or more UEs.

[0306] Host 2800 includes a processing circuit 2802 operably coupled to an input / output interface 2806, a network interface 2808, a power supply 2810, and a memory 2812 via a bus 2804. In other embodiments, other components may be included. Features of these components may be substantially similar to those described with respect to the devices of previous figures, such as FIGS. 26 and 27, and therefore, those descriptions are generally applicable to the corresponding components of host 2800.

[0307] The memory 2812 may include one or more computer programs, including one or more host application programs 2814 and data 2816, which may include user data, e.g., data generated by the UE for the host 2800 or data generated by the host 2800 for the UE. An embodiment of the host 2800 may utilize only a subset or all of the shown components. The host application programs 2814 may be implemented in a container-based architecture and may provide support for video codecs (e.g., Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for multiple different classes, types, or implementations of UE (e.g., handsets, desktop computers, wearable display systems, heads-up display systems). The host application program 2814 may also provide user authentication and license checks, and may periodically report health, route, and content availability to a central node, such as a device in the core network or a device on the edge of the core network. Thus, the host 2800 may select and / or indicate a different host for over-the-top services for the UE. The host application program 2814 may support various protocols, such as HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP), Real-Time Streaming Protocol (RTSP), Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.

[0308] FIG. 29 is a block diagram illustrating a virtualization environment 2900 in which functionality implemented by some embodiments may be virtualized. In this context, virtualizing means creating a virtual version of an apparatus or device, which may include virtualizing a hardware platform, storage devices, and networking resources. Virtualization, as used herein, may apply to any device described herein, or components thereof, and relates to implementations in which at least a portion of functionality is implemented as one or more virtual components. Some or all of the functionality described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 2900 hosted by one or more of the hardware nodes, such as a network node, a UE, a core network node, or a hardware computing device acting as a host. Furthermore, in embodiments in which the virtual node does not require wireless connectivity (e.g., to a core network node or host), the node may be fully virtualized.

[0309] An application 2902 (which may alternatively be referred to as a software instance, a virtual appliance, a network function, a virtual node, a virtual network function, etc.) is run in the virtualized environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0310] Hardware 2904 includes processing circuitry, memory that stores software and / or instructions executable by the hardware processing circuitry, and / or other hardware devices described herein, such as network interfaces, input / output interfaces, etc. Software is executed by the processing circuitry to instantiate one or more virtualization layers 2906 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 2908a and 2908b (one or more of which may be referred to generically as VMs 2908), and / or perform any of the functions, features, and / or benefits described with respect to some embodiments described herein. Virtualization layer 2906 may present to VMs 2908 a virtual operating platform that appears to be networking hardware.

[0311] VMs 2908 may comprise virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and may be run by a corresponding virtualization layer 2906. Different embodiments of virtual appliance 2902 instances may be implemented on one or more of VMs 2908, and the implementations may be done in different ways. Hardware virtualization is referred to in some contexts as network functions virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry-standard high-volume server hardware, physical switches, and physical storage, which may be located in data centers and customer premises equipment.

[0312] In the context of NFV, VMs 2908 may be software implementations of physical machines that run programs as if they were running on a physical, non-virtualized machine. Each VM 2908 and the portion of hardware 2904 on which it runs, whether hardware dedicated to that VM and / or hardware shared by that VM with other VMs, form a separate virtual network element. Further in the context of NFV, a virtual network function is responsible for handling a particular network function running in one or more VMs 2908 on hardware 2904 and corresponds to application 2902.

[0313] The hardware 2904 may be implemented in a standalone network node with general or specific components. The hardware 2904 may implement some functions via virtualization. Alternatively, the hardware 2904 may be part of a larger cluster of hardware (e.g., as in a data center or CPE) where many hardware nodes cooperate and are managed via management and orchestration 2910, which, among other things, oversees the lifecycle management of the application 2902. In some embodiments, the hardware 2904 is coupled to one or more radio units, each including one or more transmitters and one or more receivers, which may be coupled to one or more antennas. The radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with virtual components to provide a virtual node with wireless capabilities, such as a wireless access node or base station. In some embodiments, some signaling may be provided using a control system 2912, which may alternatively be used for communication between the hardware nodes and the radio units.

[0314] 30 shows a communication diagram of a host 3002 communicating with a UE 3006 via a network node 3004 over a partial wireless connection, according to some embodiments. Exemplary implementations according to various embodiments of a UE (such as the UE 2512a of FIG. 25 and / or the UE 2600 of FIG. 26), a network node (such as the network node 2510a of FIG. 25 and / or the network node 2700 of FIG. 27), and a host (such as the host 2516 of FIG. 25 and / or the host 2800 of FIG. 28) described in the previous paragraphs will now be described with reference to FIG. 30.

[0315] Similar to the host 2800, an embodiment of the host 3002 includes hardware, such as a communications interface, processing circuitry, and memory. The host 3002 also includes software stored on or accessible by the host 3002 and executable by the processing circuitry. The software includes a host application that may be operable to provide services to a remote user, such as a UE 3006 connecting via an over-the-top (OTT) connection 3050 extending between the UE 3006 and the host 3002. In providing services to the remote user, the host application may provide user data that is transmitted using the OTT connection 3050.

[0316] The network node 3004 includes hardware that enables the network node 3004 to communicate with the host 3002 and the UE 3006. The connection 3060 may be direct or may pass through one or more other intermediate networks, such as a core network (similar to the core network 2506 of FIG. 25) and / or one or more public, private, or hosted networks. For example, the intermediate network may be a backbone network or the Internet.

[0317] The UE 3006 includes hardware and software stored on or accessible by the UE 3006 and executable by the UE's processing circuitry. The software includes a client application, such as a web browser or operator-specific "app," which, with the support of the host 3002, may be operable to provide services to a human or non-human user via the UE 3006. An executing host application on the host 3002 may communicate with an executing client application via an OTT connection 3050 that terminates at the UE 3006 and the host 3002. In providing services to the user, the UE's client application may receive request data from the host application and provide user data in response to the request data. The OTT connection 3050 may transfer both request data and user data. The UE's client application may interact with the user to generate user data that the UE's client application provides to the host application through the OTT connection 3050.

[0318] The OTT connection 3050 may extend via a connection 3060 between the host 3002 and the network node 3004 and via a wireless connection 3070 between the network node 3004 and the UE 3006 to provide connectivity between the host 3002 and the UE 3006. The connections 3060 and wireless connections 3070 over which the OTT connection 3050 may be provided are depicted abstractly to illustrate communication between the host 3002 and the UE 3006 via the network node 3004, without explicit reference to intermediary devices and the precise routing of messages through these devices.

[0319] As an example of transmitting data over the OTT connection 3050, in step 3008, the host 3002 provides user data, which may be performed by executing a host application. In some embodiments, the user data is associated with a particular human user interacting with the UE 3006. In other embodiments, the user data is associated with the UE 3006 sharing data with the host 3002 without explicit human interaction. In step 3010, the host 3002 initiates a transmission carrying the user data toward the UE 3006. The host 3002 may initiate the transmission in response to a request sent by the UE 3006. The request may be caused by human interaction with the UE 3006 or by the operation of a client application executing on the UE 3006. The transmission may proceed via the network node 3004 in accordance with the teachings of the embodiments described throughout this disclosure. Thus, in step 3012, the network node 3004 transmits the user data carried in the transmission initiated by the host 3002 to the UE 3006, in accordance with the teachings of the embodiments described throughout this disclosure. In step 3014, the UE 3006 receives the user data carried in the transmission, which may be executed by a client application executing on the UE 3006 associated with the host application executed by the host 3002.

[0320] In some examples, the UE 3006 executes a client application that provides user data to the host 3002. The user data may be provided in reaction or response to data received from the host 3002. Thus, in step 3016, the UE 3006 may provide the user data, which may be performed by executing the client application. In providing the user data, the client application may further consider user input received from a user via an input / output interface of the UE 3006. Regardless of the particular manner in which the user data is provided, the UE 3006 initiates transmission of the user data towards the host 3002 via the network node 3004 in step 3018. In step 3020, in accordance with the teachings of embodiments described throughout this disclosure, the network node 3004 receives the user data from the UE 3006 and initiates transmission of the received user data towards the host 3002. In step 3022, the host 3002 receives the user data carried in the transmission initiated by the UE 3006.

[0321] One or more of the various embodiments improve the performance of the OTT service provided to the UE 3006 using the OTT connection 3050 of which the wireless connection 3070 forms the final segment.

[0322] In an exemplary scenario, factory status information may be collected and analyzed by the host 3002. As another example, the host 3002 may process audio and video data that may have been retrieved from UEs for use in creating maps. As another example, the host 3002 may collect and analyze real-time data to assist in controlling vehicular congestion (e.g., controlling traffic signals). As another example, the host 3002 may store surveillance video uploaded by UEs. As another example, the host 3002 may store or control access to media content, such as video, audio, VR or AR, that the host 3002 may broadcast, multicast, or unicast to UEs. As other examples, the host 3002 may be used for energy pricing, remote control of non-time-critical electrical loads to balance power generation needs, location services, presentation services (such as compiling diagrams, etc. from data collected from remote devices), or any other function of collecting, retrieving, storing, analyzing, and / or transmitting data.

[0323] In some examples, measurement procedures may be provided for the purpose of monitoring data rates, latency, and other factors that one or more embodiments improve upon. There may further be optional network functionality for reconfiguring the OTT connection 3050 between the host 3002 and the UE 3006 in response to fluctuations in the measurement results. The measurement procedures and / or the network functionality for reconfiguring the OTT connection may be implemented in software and hardware of the host 3002 and / or the UE 3006. In some embodiments, sensors (not shown) may be deployed in or in association with other devices through which the OTT connection 3050 passes, and the sensors may participate in the measurement procedures by providing values ​​of the monitored quantities exemplified above, or other physical quantities from which software can calculate or estimate the monitored quantities. Reconfiguration of the OTT connection 3050 may include message formats, retransmission settings, preferred routing, etc., and the reconfiguration need not directly change the operation of the network node 3004. Such procedures and functionality may be known and practiced in the art. In some embodiments, the measurements may involve proprietary UE signaling that facilitates measurements of throughput, propagation time, latency, etc. by the host 3002. The measurements may be implemented in software causing messages, particularly empty or "dummy" messages, to be sent using the OTT connection 3050 while monitoring propagation time, errors, etc.

[0324] While the computing devices (e.g., UEs, network nodes, hosts) described herein may include the depicted combinations of hardware components, other embodiments may comprise computing devices with different combinations of components. It should be understood that these computing devices may comprise any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. The determining, calculating, obtaining, or similar operations described herein may be performed by processing circuitry, which may process information by, for example, transforming the obtained information to other information, comparing the obtained or transformed information to information stored in a network node, and / or performing one or more operations based on the obtained or transformed information and as a result of the processing making a decision. Moreover, while a component is illustrated as a single box located within a larger box or nested within multiple boxes, in reality the computing device may comprise multiple different physical components that make up the single depicted component, and functionality may be partitioned among the separate components. For example, a communications interface may be configured to include any of the components described herein, and / or the functionality of those components may be partitioned between the processing circuitry and the communications interface. In another example, non-computationally intensive functionality of any of such components may be implemented in software or firmware, and computationally intensive functionality may be implemented in hardware.

[0325] In some embodiments, some or all of the functionality described herein may be provided by a processing circuit executing instructions stored in a memory, which in some embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuit without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hardwired manner. In any of these particular embodiments, the processing circuit may be configured to perform the described functionality, regardless of whether or not it executes instructions stored on a non-transitory computer-readable storage medium. Benefits provided by such functionality are not limited to the processing circuit alone or to other components of the computing device, but are enjoyed by the computing device as a whole and / or by end users and wireless networks generally.

[0326] In particular, modifications and other embodiments of the present disclosure will come to mind to one skilled in the art having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the disclosure is not to be limited to the particular embodiments disclosed, and that modifications and other embodiments are intended to be included within the scope of the present disclosure. Although specific terms may be employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

[0327] Embodiment

[0328] Group A Embodiments A1. A method performed by a proximity service anchor node, the method comprising: receiving, from an authentication server, a proximity services relay user key associated with the remote wireless communication device; deriving a shared key from the proximity service relay user key for protecting an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device; transmitting the shared key to a network node serving the relay wireless communication device; A method comprising: A2. The method of embodiment A1, in which the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. A3. Receiving a shared key request from a network node requesting a shared key from a neighboring service anchor node; sending a request for primary authentication of the remote wireless communication device to an authentication server after receiving the shared key request; receiving a response to the request for primary authentication from the authentication server, the response to the request for primary authentication including the proximity service relay user key; The method of embodiment A1 or A2, further comprising: A4. The method of embodiment A3, wherein the shared key request includes a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device. A5. The method of embodiment A3 or A4, further comprising sending, to the network node, a response to the shared key request, the response to the shared key request including the shared key. A6. The method of any one of embodiments A1 to A5, further comprising receiving, from an authentication server, an identifier bound to a proximity service relay user key. A7. The method of embodiment A6, further comprising storing, in storage at the proximity service anchor node, a proximity service relay user key in association with the received identifier. A8. Receiving a new shared key request from a requesting node indicating an identifier bound to a proximity service relay user key; Retrieving a proximity service relay user key from storage at the proximity service anchor node using the identifier indicated in the new shared key request; deriving a new shared key for the remote wireless communication device from the retrieved proximity service relay user key; transmitting the new shared key to the requesting node in response to the new shared key request; The method of embodiment A7, further comprising: A9. The method of embodiment A7 or A8, further comprising storing the proximity services relay user key also in association with a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device. A10. The method of any one of embodiments A1 to A9, further comprising receiving, from the authentication server, a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device. A11. The method of any one of embodiments A1-A10, wherein the proximity service relay user key is received from the authentication server in a request to register the proximity service relay user key with the proximity service anchor node. A12. The method described in embodiment A11, wherein the request to register a proximity service relay user key also includes an identifier bound to the proximity service relay user key and / or a subscription identifier that identifies the subscription of the remote wireless communication device to the home network of the remote wireless communication device. A13. The method of embodiment A12, further comprising storing, in storage at the proximity service anchor node, a proximity service relay user key in association with the received identifier. A14. After receiving a request to register a proximity services relay user key, receiving a shared key request from the network node indicating an identifier bound to the proximity services relay user key; retrieving a proximity service relay user key from storage at the proximity service anchor node using the identifier indicated in the shared key request; further comprising a shared key is derived from the proximity service relay user key retrieved from storage; The method of embodiment A13, in which sending the shared key to the network node includes sending a response to the shared key request to the network node, the response including the shared key. A15. The method of any one of embodiments A1 to A14, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). A16. The shared key is key K NR_ProSe The method of any one of embodiments A1 to A15, wherein A17. The method of any one of embodiments A1 to A16, wherein the authentication server implements an authentication server function (AUSF). A18. The method of any one of embodiments A1 to A17, wherein the network node implements an Access and Mobility Function (AMF). A19. The method of any one of embodiments A1 to A18, wherein the interface is a PC5 interface. A20. The method of any one of embodiments A1 to A19, wherein the relay wireless communication device is a Layer 3 UE-network relay.

[0329] Group B Embodiments B1. A method performed by an authentication server, the method comprising: generating a proximity services relay user key associated with the remote wireless communication device; transmitting a proximity service relay user key to the proximity service anchor node; A method comprising: B2. The method of embodiment B1, in which the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. B3. Receiving a request for primary authentication of a remote wireless communication device from a nearby service anchor node; sending a response to the request for primary authentication to the proximity service anchor node, the response to the request for primary authentication including the proximity service relay user key; The method of embodiment B1 or B2, further comprising: B4. The method of embodiment B3, wherein the response also includes a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device. B5. The method of any one of embodiments B1-B4, further comprising sending, to the proximity service anchor node, an identifier bound to the proximity service relay user key. B6. The method of any one of embodiments B1 to B5, further comprising transmitting, to the proximity service anchor node, a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device. B7. The method of any one of embodiments B1 to B6, further comprising sending a request to a proximity service anchor node to register a proximity service relay user key with the proximity service anchor node, wherein the proximity service relay user key is included in the request to register the proximity service relay user key. B8. The method described in embodiment B7, wherein the request to register a proximity services relay user key also includes an identifier bound to the proximity services relay user key and / or a subscription identifier identifying the subscription of the remote wireless communication device to the home network of the remote wireless communication device. B9. The method of any one of embodiments B1 to B8, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). B10. The method of any one of embodiments B1 to B9, wherein the authentication server implements an authentication server function (AUSF). B11. A method according to any one of embodiments B1 to B10, wherein the proximity service relay user key is a certificate from which a shared key for protecting an interface between a remote wireless communication device and a relay wireless communication device can be derived, and the relay wireless communication device is configured to relay traffic for the remote wireless communication device. B12. The method of embodiment B11, wherein the interface is a PC5 interface. B13. The method of embodiment B11 or B12, wherein the relay wireless communication device is a Layer 3 UE-to-network relay.

[0330] Group C Embodiments C1. A method performed by a network node serving a relay wireless communication device configured to relay traffic for a remote wireless communication device, the method comprising: sending a request to a proximity service anchor node for a shared key for securing an interface between the remote wireless communication device and the relay wireless communication device; receiving a shared key from a neighboring service anchor node in response to the request; transmitting the shared key to the relay wireless communication device; A method comprising: C2. The method of embodiment C2, in which the shared key is derivable from a proximity service relay user key, and the proximity service relay user key is based on and / or unique to some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. C3. The method of embodiment C1 or C2, wherein the shared key request includes an identifier bound to a proximity service relay user key, and the received shared key is derived from the proximity service relay user key. C4. The method of embodiment C2 or C3, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). C5. The method of any one of embodiments C1 to C2, wherein the shared key request includes a subscription identifier that identifies a subscription of the remote wireless communication device to the home network of the remote wireless communication device. C6. The shared key is key K NR_ProSe The method of any one of embodiments C1 to C5, wherein C7. The method of any one of embodiments C1 to C6, wherein the network node implements an Access and Mobility Function (AMF). C8. The method of any one of embodiments C1 to C7, wherein the interface is a PC5 interface. C9. The method of any one of embodiments C1 to C8, wherein the relay wireless communication device is a Layer 3 UE-to-network relay.

[0331] Group D Embodiments D1. A method performed by a remote wireless communication device, the method comprising: transmitting a request to the relay wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication, the request requesting reuse of a proximity services relay user key already associated with the remote wireless communication device; A method comprising: D2. The method of embodiment D1, in which the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device. D3. The method of embodiment D1 or D2, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device. D4. The method of any one of embodiments D1 to D3, wherein the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. D5. The method of any one of embodiments D1 to D4, further comprising receiving a response to the request from the relay wireless communication device indicating that the proximity services relay user key should be reused. D6. Reusing the proximity service relay user key to generate a shared key for protecting an interface between the remote wireless communication device and the relay wireless communication device; Securing the interface with a shared key The method of any one of embodiments D1 to D5, further comprising: D7. The shared key is key K NR_ProSe The method of embodiment D6, wherein D8. The method of embodiment D6 or D7, wherein the interface is a PC5 interface. D9. The method of any one of embodiments D1 to D8, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). D10. The method of any one of embodiments D1 to D9, wherein the relay wireless communication device is a Layer 3 UE-to-network relay.

[0332] Group E Embodiments E1. A method performed by a relay wireless communication device, the method comprising: receiving a request from a remote wireless communication device for a relay wireless communication device to relay traffic for the remote wireless communication, the request requesting reuse of a proximity services relay user key already associated with the remote wireless communication device; A method comprising: E2. The method of embodiment E1, in which the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device. E3. The method of embodiment E1 or E2, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device. E4. The method of any one of embodiments E1 to E3, wherein the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. E5. The method of any one of embodiments E1 to E4, further comprising sending a response to the request to the remote wireless communication device indicating that the proximity services relay user key should be reused. E6. The method of any one of embodiments E1 to E5, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). E7. The method of any one of embodiments E1 to E6, wherein the relay wireless communication device is a Layer 3 UE-to-network relay. E8. The method of any one of embodiments E1 to E7, further comprising sending a request to a network node serving the relay wireless communication device for a shared key for protecting an interface between the remote wireless communication device and the relay wireless communication device, wherein the request for the shared key requests reuse of a proximity service relay user key to derive the shared key. E9. The method of embodiment E8, wherein the request for the shared key includes a proximity service relay user key reuse flag requesting reuse of the proximity service relay user key. E10. The method of embodiment E8 or E9, further comprising receiving a response to the request for the shared key from the network node, the response to the request for the shared key including the shared key and indicating that the proximity service relay user key should be reused to derive the shared key. EE1. A method performed by a relay wireless communication device, the method comprising: Sending a request for a shared key to protect an interface between a remote wireless communication device and the relay wireless communication device to a network node serving the relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device, the request for the shared key requesting reuse of a proximity services relay user key to derive the shared key. A method comprising: EE2. The method of embodiment EE1, wherein the request for the shared key includes a proximity service relay user key reuse flag requesting reuse of the proximity service relay user key. EE3. The method of embodiment EE1 or embodiment EE2, further comprising receiving a response to the request for the shared key from the network node, the response to the request for the shared key including the shared key and indicating that the proximity service relay user key should be reused to derive the shared key. EE4. The method of any one of embodiments EE1 to EE3, wherein the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device. EE5. The method of any one of embodiments EE1 to EE4, wherein the proximity service relay user key is based on and / or unique to some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. EE6. Receiving a request from a remote wireless communication device for a relay wireless communication device to relay traffic for the remote wireless communication, the request requesting reuse of a proximity service relay user key already associated with the remote wireless communication device; transmitting a response to the request to the remote wireless communication device, the response indicating that the proximity service relay user key should be reused to derive the shared key; The method of any one of embodiments EE1 to EE5, further comprising: EE7. The method of any one of embodiments EE1 to EE6, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). EE8. The method of any one of embodiments EE1 to EE7, wherein the relay wireless communication device is a Layer 3 UE-to-network relay. EE9. The shared key is key K NR_ProSe The method of any one of embodiments EE1 to EE8, wherein EE10. The method of any one of embodiments EE1 to EE9, wherein the network node implements an Access and Mobility Function (AMF). EE11. The method of any one of embodiments EE1 to EE10, wherein the interface is a PC5 interface.

[0333] Group F Implementation F1. A method performed by a network node serving a relay wireless communication device, the method comprising: receiving a request for a shared key from a relay wireless communication device for protecting an interface between the remote wireless communication device and the relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device, the request for the shared key requiring reuse of a proximity services relay user key to derive the shared key; A method comprising: F2. The method of embodiment F1, in which the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device. F3. The method of embodiment F1 or F2, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device. F4. The method of any one of embodiments F1 to F3, wherein the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. F5. The method of any one of embodiments F1 to F4, further comprising sending a response to the request to the relay wireless communication device, the response including the shared key and indicating that the proximity service relay user key should be reused to derive the shared key. F6. The method of any one of embodiments F1 to F5, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). F7. The method of any one of embodiments F1 to F6, wherein the relay wireless communication device is a Layer 3 UE-to-network relay. F8. The shared key is key K NR_ProSe The method of any one of embodiments F1 to F7, wherein F9. The method of any one of embodiments F1 to F8, wherein the network node implements an Access and Mobility Function (AMF). F10. The method of any one of embodiments F1 to F9, wherein the interface is a PC5 interface. FF1. A method performed by a network node serving a relay wireless communication device, the method comprising: Sending a request for authentication of the remote wireless communication device to an authentication server, the request requiring reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device. A method comprising: FF2. The method of embodiment FF1, wherein the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device. FF3. The method of embodiment FF1 or FF2, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device. FF4. The method of any one of embodiments FF1 to FF3, wherein the proximity service relay user key is based on and / or unique to some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. FF5. The method of any one of embodiments FF1 to FF4, further comprising receiving a response to the request from the authentication server, the response including the shared key and indicating that the proximity service relay user key should be reused to derive the shared key. FF6. The method of any one of embodiments FF1 to FF5, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). FF7. The method of any one of embodiments FF1 to FF6, wherein the relay wireless communication device is a Layer 3 UE-network relay. FF8. The shared key is key K NR_ProSe The method of any one of embodiments FF1 to FF7, wherein FF9. The method of any one of embodiments FF1 to FF8, wherein the network node implements an Access and Mobility Function (AMF). FF10. The method of any one of embodiments FF1 to FF9, wherein the interface is a PC5 interface.

[0334] Group G Embodiments G1. A method performed by an authentication server, the method comprising: receiving a request for authentication of a remote wireless communication device, the request requiring reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device; A method comprising: G2. The method of embodiment G1, in which the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device. G3. The method of embodiment G1 or G2, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device. G4. The method of any one of embodiments G1 to G3, wherein the proximity service relay user key is unique and / or based on some execution of a primary authentication procedure for primary authentication of the remote wireless communication device. G5. The method of any one of embodiments G1 to G4, further comprising sending a response to the request, the response including the shared key and indicating that the proximity service relay user key should be reused to derive the shared key. G6. The method of any one of embodiments G1 to G5, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). G7. The method of any one of embodiments G1 to G6, wherein the relay wireless communication device is a Layer 3 UE-network relay. G8. The shared key is key K NR_ProSe The method of any one of embodiments G1 to G7, wherein G9. The method of any one of embodiments G1 to G8, wherein the request is received from an Access and Mobility Function (AMF). G10. The method of any one of embodiments G1 to G9, wherein the interface is a PC5 interface. G11. A method according to any one of embodiments G1 to G10, further comprising sending to the data management node a request for authentication credentials for the remote wireless communication device, the request for authentication credentials requesting reuse of a proximity service relay user key. G12. The method of embodiment G11, further comprising receiving a response to the request for authentication credentials from the data management node, the response indicating whether the proximity service relay user key is available for reuse. G13. The response indicates that the proximity service relay user key is available for reuse, and the method obtaining a shared key as derived from a proximity service relay user key; transmitting a response to the request for authentication, the response to the request for authentication including the obtained shared key and indicating that the proximity service relay user key should be reused to derive the shared key; The method of embodiment G12, further comprising: G14. The method of embodiment G13, wherein obtaining the shared key includes retrieving a proximity service relay user key from local storage at the authentication server, and deriving the shared key from the retrieved proximity service relay user key. G15. Obtaining a shared key is forwarding the request for authentication to another authentication server having the proximity service relay user key stored therein; receiving a shared key from another authentication server as derived from the proximity service relay user key; The method of embodiment G13, comprising: G16. The response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials, and the method comprises: generating a proximity services relay user key based on keying material derived during authentication of the remote wireless communication device, the authentication of the remote wireless communication device being based on an authentication certificate; deriving a shared key from the generated proximity service relay user key; transmitting a response to the request for authentication, the response to the request for authentication including the derived shared key; The method of embodiment G12, further comprising: G17. The method of embodiment G16, wherein the response to the request for authentication indicates that the proximity service relay user key should not be reused to derive the shared key. G18. The method of embodiment G16 or G17, further comprising, after generating the proximity service relay user key, sending signaling to the data management node indicating that the proximity service relay user key for the remote wireless communication device is available for reuse and indicating the identity of the authentication server on which the proximity service relay user key is stored. G19. The method of any one of embodiments G1 to G18, wherein the request is received from a network node serving the relay wireless communication device. G20. The method of any one of embodiments G1 to G18, wherein the request is received from another authentication server. GG1. A method performed by an authentication server, the method comprising: sending, to the data management node, a request for authentication credentials for the remote wireless communication device, the request for authentication credentials requesting reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device; A method comprising: GG2. The method of embodiment GG1, further comprising receiving a response to the request for authentication credentials from the data management node, the response indicating whether the proximity service relay user key is available for reuse. GG3. The response indicates that the proximity service relay user key is available for reuse, and the method comprises: obtaining a shared key as derived from a proximity service relay user key; sending a response to the request for authentication to the network node, the response to the request for authentication including the obtained shared key and indicating that the proximity service relay user key should be reused to derive the shared key; The method of embodiment GG2, further comprising: GG4. The method of embodiment GG3, wherein obtaining the shared key includes retrieving a proximity service relay user key from local storage at the authentication server, and deriving the shared key from the retrieved proximity service relay user key. GG5. Obtaining a shared key is forwarding the request for authentication to another authentication server having the proximity service relay user key stored therein; receiving a shared key from another authentication server as derived from the proximity service relay user key; The method of embodiment GG3, comprising: GG6. The response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials, and the method comprises: generating a proximity services relay user key based on keying material derived during authentication of the remote wireless communication device, the authentication of the remote wireless communication device being based on an authentication certificate; deriving a shared key from the generated proximity service relay user key; transmitting a response to the request for authentication to the network node, the response to the request for authentication including the derived shared key; The method of embodiment GG2, further comprising: GG7. The method of embodiment GG6, wherein the response to the request for authentication indicates that the proximity service relay user key should not be reused to derive the shared key. GG8. The method of any one of embodiments GG1 to GG7, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). GG9. The method of any one of embodiments GG1 to GG8, wherein the relay wireless communication device is a Layer 3 UE-to-network relay. GG10. The shared key is key K NR_ProSe The method of any one of embodiments GG1 to GG9, wherein GG11. The method of any one of embodiments GG1 to GG10, wherein the network node implements an Access and Mobility Function (AMF). GG12. The method of any one of embodiments GG1 to GG11, wherein the interface is a PC5 interface.

[0335] Group H Embodiments H1. A method performed by a data management node, the method comprising: receiving, from an authentication server, a request for authentication credentials for a remote wireless communication device, the request for authentication credentials requesting reuse of a proximity services relay user key to derive a shared key for protecting an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device; A method comprising: H2. The method of embodiment H1 further including sending a response to the request to the authentication server, the response indicating whether the proximity service relay user key is available for reuse. H3. The method of embodiment H2, wherein the response indicates that the proximity service relay user key is available for reuse. H4. The method of embodiment H3, wherein the response indicates the identity of the authentication server on which the proximity service relay user key is stored. H5. The method of embodiment H2, wherein the response indicates that the proximity service relay user key is not available for reuse and includes the requested authentication credentials. H6. After sending the response, receiving signaling indicating an identity of an authentication server on which a proximity services relay user key is stored; storing information at the data management node indicating that a proximity services relay user key for the remote wireless communication device is available for reuse and indicating an identity of an authentication server on which the proximity services relay user key is stored; The method of embodiment H5, further comprising: H7. The method of any one of embodiments H1 to H6, further comprising determining whether a proximity service relay user key is available for reuse based on information in the data management node indicating whether a proximity service relay user key is stored for the remote wireless communication device. H8. The method of any one of embodiments H1 to H7, wherein the proximity service relay user key is a 5G proximity service relay user key (5GPRUK). H9. The method of any one of embodiments H1 to H8, wherein the relay wireless communication device is a Layer 3 UE-to-network relay. H10. The shared key is key K NR_ProSe The method of any one of embodiments H1 to H9, wherein H11. The method of any one of embodiments H1 to H10, wherein the interface is a PC5 interface.

[0336] Group J embodiment J1. A proximity service anchor node configured to perform any of the steps recited in any one of the embodiments of Group A. J2. A proximity service anchor node comprising processing circuitry configured to perform any of the steps recited in any one of the embodiments of Group A. J3. A neighborhood service anchor node, A communication circuit; a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group A; A proximity service anchor node comprising: J4. A neighborhood service anchor node, a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group A; and a power supply circuit configured to supply power to the proximity service anchor node; A proximity service anchor node comprising: J5. A neighborhood service anchor node, A proximity service anchor node comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit, whereby the proximity service anchor node is configured to perform any of the steps recited in any one of the embodiments of group A. J6. A computer program product comprising instructions that, when executed by at least one processor of a proximity service anchor node, cause the proximity service anchor node to perform the steps recited in any one of the embodiments of group A. J7. A carrier containing the computer program of embodiment J6, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. J8. An authentication server configured to perform any of the steps recited in any one of the Group B or Group G embodiments. J9. An authentication server comprising processing circuitry configured to perform any of the steps recited in any one of the Group B or Group G embodiments. J10. An authentication server, A communication circuit; a processing circuit configured to perform any of the steps recited in any one of the Group B or Group G embodiments; An authentication server comprising: J11. An authentication server, a processing circuit configured to perform any of the steps recited in any one of the Group B or Group G embodiments; a power supply circuit configured to supply power to the authentication server; An authentication server comprising: J12. An authentication server, An authentication server comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit, whereby the authentication server is configured to perform any of the steps recited in any one of the embodiments of Group B or Group G. J13. A computer program comprising instructions that, when executed by at least one processor of an authentication server, cause a proximity service anchor node to perform the steps recited in any one of the Group B or Group G embodiments. J14. A carrier containing the computer program of embodiment J13, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. J15. A network node configured to perform any of the steps recited in any one of the embodiments of Group C or Group F. J16. A network node comprising processing circuitry configured to perform any of the steps recited in any one of the embodiments of Group C or Group F. J17. A network node, A communication circuit; a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group C or Group F; A network node comprising: J18. A network node, a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group C or Group F; a power supply circuit configured to supply power to the network node; A network node comprising: J19. A network node, A network node comprising: a processing circuit and a memory, the memory including instructions executable by the processing circuit, whereby the network node is configured to perform any of the steps recited in any one of the embodiments of Group C or Group F. J20. A computer program comprising instructions that, when executed by at least one processor of a network node, cause the network node to perform the steps recited in any one of the embodiments of Group C or Group F. J21. A carrier containing the computer program of embodiment J20, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. J22. A wireless communication device configured to perform any of the steps recited in any one of the embodiments of Group D or Group E. J23. A wireless communication device comprising processing circuitry configured to perform any of the steps recited in any one of the embodiments of Group D or Group E. J24. A wireless communication device, A communication circuit; a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group D or Group E; A wireless communication device comprising: J25. A wireless communication device, a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group D or Group E; a power supply circuit configured to supply power to the wireless communication device; A wireless communication device comprising: J26. A wireless communication device, A wireless communication device comprising: a processing circuit and a memory, the memory including instructions executable by the processing circuit, whereby the wireless communication device is configured to perform any of the steps recited in any one of the embodiments of Group D or Group E. J27. A computer program product comprising instructions that, when executed by at least one processor of a wireless communication device, cause the wireless communication device to perform the steps recited in any one of the Group D or Group E embodiments. J28. A carrier containing the computer program of embodiment J27, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. J29. A user equipment (UE) comprising: an antenna configured to transmit and receive radio signals; a radio front-end circuit coupled to the antenna and the processing circuit and configured to condition signals communicated between the antenna and the processing circuit; a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group D or Group E; an input interface coupled to the processing circuitry and configured to allow input of information to the UE to be processed by the processing circuitry; an output interface coupled to the processing circuitry and configured to output information from the UE that has been processed by the processing circuitry; a battery connected to the processing circuit and configured to power the UE; A user equipment (UE) comprising: J30. A data management node configured to perform any of the steps recited in any one of the embodiments of Group H. J31. A data management node comprising processing circuitry configured to perform any of the steps recited in any one of the embodiments of Group H. J32. A data management node, A communication circuit; a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group H; A data management node comprising: J33. A data management node, a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group H; and a power supply circuit configured to supply power to the data management node; A data management node comprising: J34. A data management node, A data management node comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit, whereby the data management node is configured to perform any of the steps recited in any one of the embodiments of Group H. J35. A computer program comprising instructions that, when executed by at least one processor of a data management node, cause the data management node to perform the steps recited in any one of the embodiments of group H. J36. A carrier containing the computer program of embodiment J35, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.

[0337] Group K embodiments K9. A communication system including a host computer, the host computer: processing circuitry configured to provide user data; a communications interface configured to transfer user data to a cellular network for transmission to a user equipment (UE); Equipped with A communications system in which a UE comprises a radio interface and processing circuitry, the components of the UE configured to perform any of the steps recited in any one of the embodiments of Group D or Group E. K10. The communication system of embodiment K9, wherein the cellular network further includes a base station configured to communicate with the UE. K11. The processing circuitry of the host computer is configured to execute a host application and thereby provide user data; processing circuitry of the UE configured to execute a client application associated with the host application; The communication system of embodiment K9 or K10. K12. A method implemented in a communications system including a host computer, a base station, and a user equipment (UE), the method comprising: providing user data at a host computer; Initiating, at a host computer, a transmission carrying user data to a UE over a cellular network comprising a base station, wherein the UE performs any of the steps set forth in any one of the embodiments of Group D or Group E; A method comprising: K13. The method of embodiment K12, further comprising receiving, at the UE, user data from the base station. K14. A communication system including a host computer, the host computer: A communications interface configured to receive user data originating from transmissions from a user equipment (UE) to a base station. Equipped with A communications system in which a UE comprises a radio interface and processing circuitry, the processing circuitry of the UE configured to perform any of the steps recited in any one of the embodiments of Group D or Group E. K15. The communication system of embodiment K14, further comprising a UE. K16. The communications system of embodiment K14 or K15, further including a base station, the base station comprising a wireless interface configured to communicate with the UE and a communications interface configured to transfer user data carried by transmissions from the UE to the base station to a host computer. K17. processing circuitry of the host computer configured to execute a host application; processing circuitry of the UE configured to execute a client application associated with the host application and thereby provide user data; The communication system of any one of embodiments K14 to K16. K18. processing circuitry of the host computer configured to execute the host application and thereby provide the requested data; processing circuitry of the UE configured to execute a client application associated with the host application, thereby providing user data in response to the request data; A communication system according to any one of embodiments K14 to K17. K19. A method implemented in a communications system including a host computer, a base station, and user equipment (UE), the method comprising: receiving, at the host computer, user data transmitted from the UE to the base station, wherein the UE performs any of the steps set forth in any one of the embodiments of Group D or Group E. A method comprising: K20. The method of embodiment K19, further comprising, at the UE, providing user data to the base station. K21. running, at the UE, a client application thereby providing user data to be transmitted; executing, on the host computer, a host application associated with the client application; The method of embodiment K19 or K20, further comprising: K22. executing a client application at the UE; receiving, at the UE, input data for the client application, the input data being provided at the host computer by executing a host application associated with the client application; further comprising The method of any one of embodiments K19 to K21, wherein the user data to be transmitted is provided by a client application in response to input data. K27. A method implemented in a communication system including a host computer, a base station, and a user equipment (UE), the method comprising: receiving, at the host computer, from a base station, user data originating from a transmission received by the base station from the UE, wherein the UE performs any of the steps recited in any one of the embodiments of Group D or Group E. A method comprising: K28. The method of embodiment K27, further comprising receiving, at the base station, user data from the UE. K29. The method of embodiment K27 or K28, further comprising initiating, at the base station, transmission of the received user data to the host computer.

Claims

1. 1. A method performed by an authentication server, the method comprising: receiving a request for authentication of a remote wireless communication device, the request requiring reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and a relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device; Including, The method of claim 1, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

2. The method of claim 1 , wherein the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

3. The method of claim 1 , wherein the proximity service relay user key is based on and / or specific to a certain execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

4. 10. The method of claim 1, further comprising: transmitting a response to the request, the response including the shared key and indicating that the proximity service relay user key should be reused to derive the shared key.

5. 2. The method of claim 1, wherein the proximity services relay user key is a 5G proximity services relay user key (5GPRUK).

6. The method of claim 1 , wherein the relay wireless communication device is a Layer 3 UE-to-network relay.

7. The shared key is key K NR_ProSe The method of claim 1, wherein

8. 10. The method of claim 1, wherein the request is received from an Access and Mobility Function (AMF).

9. The method of claim 1 , wherein the interface is a PC5 interface.

10. 2. The method of claim 1, further comprising: sending a request for authentication credentials for the remote wireless communication device to a data management node, the request for authentication credentials requesting reuse of the proximity services relay user key.

11. 11. The method of claim 10, further comprising receiving a response to the request for authentication credentials from the data management node, the response indicating whether the proximity services relay user key is available for reuse.

12. The response indicates that the proximity service relay user key is available for reuse, and the method further comprises: obtaining the shared key as derived from the proximity service relay user key; transmitting a response to the request for authentication, the response to the request for authentication including the obtained shared key and indicating that the proximity service relay user key should be reused to derive the shared key; The method of claim 11 further comprising:

13. 13. The method of claim 12, wherein obtaining the shared key comprises retrieving the proximity services relay user key from local storage at the authentication server; and deriving the shared key from the retrieved proximity services relay user key.

14. Obtaining the shared key comprises: forwarding the request for authentication to another authentication server in which the proximity services relay user key is stored; receiving the shared key from the other authentication server as derived from the proximity service relay user key; 13. The method of claim 12, comprising:

15. the response indicates that the proximity services relay user key is not available for reuse and includes the requested authentication credentials, and the method further comprises: generating a proximity services relay user key based on keying material derived during authentication of the remote wireless communication device, the authentication of the remote wireless communication device being based on the authentication certificate; deriving the shared key from the generated proximity service relay user key; transmitting a response to the request for authentication, the response to the request for authentication including the derived shared key; The method of claim 11 further comprising:

16. 1. A method performed by an authentication server, the method comprising: sending, to a data management node, a request for authentication credentials for a remote wireless communication device, the request for authentication credentials requesting reuse of a proximity services relay user key to derive a shared key for protecting an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device; Including, The method of claim 1, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

17. 17. The method of claim 16, further comprising receiving a response to the request for authentication credentials from the data management node, the response indicating whether the proximity services relay user key is available for reuse.

18. The response indicates that the proximity service relay user key is available for reuse, and the method further comprises: obtaining the shared key as derived from the proximity service relay user key; sending a response to the request for authentication to a network node, the response to the request for authentication including the obtained shared key and indicating that the proximity service relay user key should be reused to derive the shared key; 20. The method of claim 17, further comprising:

19. 20. The method of claim 18, wherein obtaining the shared key comprises retrieving the proximity services relay user key from local storage at the authentication server; and deriving the shared key from the retrieved proximity services relay user key.

20. Obtaining the shared key comprises: forwarding the request for authentication to another authentication server in which the proximity services relay user key is stored; receiving the shared key from the other authentication server as derived from the proximity service relay user key; 20. The method of claim 19, comprising:

21. the response indicates that the proximity services relay user key is not available for reuse and includes the requested authentication credentials, and the method further comprises: generating a proximity services relay user key based on keying material derived during authentication of the remote wireless communication device, the authentication of the remote wireless communication device being based on the authentication certificate; deriving the shared key from the generated proximity service relay user key; transmitting a response to the request for authentication to a network node, the response to the request for authentication including the derived shared key; 21. The method of claim 20, further comprising:

22. 1. A method performed by a data management node, the method comprising: receiving, from an authentication server, a request for authentication credentials for a remote wireless communication device, the request for authentication credentials requesting reuse of a proximity services relay user key to derive a shared key for protecting an interface between the remote wireless communication device and a relay wireless communication device configured to relay traffic for the remote wireless communication device; Including, The method of claim 1, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

23. 23. The method of claim 22, further comprising sending a response to the request to the authentication server, the response indicating whether the proximity services relay user key is available for reuse.

24. 24. The method of claim 23, wherein the response indicates that the proximity services relay user key is available for reuse.

25. 25. The method of claim 24, wherein the response indicates the identity of an authentication server on which the proximity services relay user key is stored.

26. 24. The method of claim 23, wherein the response indicates that the proximity services relay user key is not available for reuse and includes the requested authentication credentials.

27. after sending the response, receiving signaling indicating an identity of an authentication server on which a proximity services relay user key is stored; storing information at the data management node indicating that a proximity services relay user key for the remote wireless communication device is available for reuse and indicating the identity of the authentication server on which the proximity services relay user key is stored; 27. The method of claim 26, further comprising:

28. 23. The method of claim 22, further comprising: verifying whether the proximity services relay user key is available for reuse based on information at the data management node indicating whether a proximity services relay user key is stored for the remote wireless communication device.

29. 1. A method performed by a remote wireless communication device, the method comprising: sending a request to a relay wireless communication device for the relay wireless communication device to relay traffic for a remote wireless communication, the request requesting reuse of a proximity services relay user key already associated with the remote wireless communication device; Including, The method of claim 1, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

30. 30. The method of claim 29, wherein the request requests reuse of a proximity services relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

31. 30. The method of claim 29, wherein the proximity service relay user key is based on and / or specific to a certain execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

32. 30. The method of claim 29, further comprising receiving a response to the request from the relay wireless communication device indicating that the proximity services relay user key should be reused.

33. reusing the proximity services relay user key to generate a shared key for securing an interface between the remote wireless communication device and the relay wireless communication device; securing said interface using said shared key; 30. The method of claim 29, further comprising:

34. 1. A method performed by a relay wireless communication device, the method comprising: receiving a request from a remote wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication, the request requesting reuse of a proximity services relay user key already associated with the remote wireless communication device; Including, The method of claim 1, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

35. 35. The method of claim 34, wherein the request requests reuse of a proximity service relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

36. 35. The method of claim 34, wherein the proximity service relay user key is based on and / or specific to a certain execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

37. 35. The method of claim 34, further comprising sending to the remote wireless communication device a response to the request indicating that the proximity services relay user key should be reused.

38. 1. A method performed by a relay wireless communication device, the method comprising: sending a request for a shared key to protect an interface between a remote wireless communication device and the relay wireless communication device to a network node serving the relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device, the request for the shared key requesting reuse of a proximity services relay user key to derive the shared key; Including, The method of claim 1, wherein the request for the shared key includes a proximity service relay user key reuse flag requesting reuse of the proximity service relay user key.

39. 39. The method of claim 38, further comprising receiving a response to the request for the shared key from the network node, the response to the request for the shared key including the shared key and indicating that the proximity services relay user key should be reused to derive the shared key.

40. 39. The method of claim 38, wherein the request requests reuse of a proximity services relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

41. receiving a request from the remote wireless communication device for the relay wireless communication device to relay traffic for the remote wireless communication, the request requesting reuse of a proximity services relay user key already associated with the remote wireless communication device; sending a response to the request to the remote wireless communication device, the response indicating that the proximity service relay user key should be reused to derive the shared key; 39. The method of claim 38, further comprising:

42. 1. A method performed by a network node serving a relay wireless communication device, the method comprising: receiving a request for a shared key from the relay wireless communication device for protecting an interface between a remote wireless communication device and the relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device, the request requiring reuse of a proximity services relay user key to derive the shared key; Including, The method of claim 1, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

43. 43. The method of claim 42, wherein the request requests reuse of a proximity services relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

44. 43. The method of claim 42, further comprising: transmitting a response to the request to the relay wireless communication device, the response including the shared key and indicating that the proximity services relay user key should be reused to derive the shared key.

45. 1. A method performed by a network node serving a relay wireless communication device, the method comprising: sending a request for authentication of a remote wireless communication device to an authentication server, the request requesting reuse of a proximity services relay user key to derive a shared key for securing an interface between the remote wireless communication device and the relay wireless communication device, the relay wireless communication device being configured to relay traffic for the remote wireless communication device; Including, The method of claim 1, wherein the request includes a proximity service relay user key reuse flag requesting reuse of a proximity service relay user key already associated with the remote wireless communication device.

46. 46. ​​The method of claim 45, wherein the request requests reuse of a proximity services relay user key from a previous execution of a primary authentication procedure for primary authentication of the remote wireless communication device.

47. 46. ​​The method of claim 45, further comprising receiving a response to the request from the authentication server, the response including the shared key and indicating that the proximity services relay user key should be reused to derive the shared key.

48. an authentication server, 22. An authentication server comprising a processing circuit and a memory, said memory containing instructions executable by said processing circuit, whereby said authentication server is configured to perform a method according to any one of claims 1 to 21.

49. 22. A computer program comprising instructions that, when executed by at least one processor of an authentication server, cause a proximity service anchor node to perform the method of any one of claims 1 to 21.

50. A communication circuit; a processing circuit configured to carry out the method of any one of claims 29 to 44; A wireless communication device comprising:

51. 45. A computer program comprising instructions which, when executed by at least one processor of a wireless communication device, cause the wireless communication device to perform the method of any one of claims 29 to 44.

52. A communication circuit; a processing circuit configured to carry out the method of any one of claims 22 to 28; A data management node comprising:

53. 29. A computer program comprising instructions which, when executed by at least one processor of a data management node, cause the data management node to perform the method of any one of claims 22 to 28.

54. a network node, a processing circuit configured to carry out the method of any one of claims 45 to 47; and a power supply circuit configured to supply power to the network node; A network node comprising:

55. 48. A computer program comprising instructions which, when executed by at least one processor of a network node, cause the network node to perform the method of any one of claims 45 to 47.

56. 48. A computer program comprising instructions which, when executed by at least one processor, cause said at least one processor to perform the method of any one of claims 1 to 47.

Citation Information

Patent Citations

  • Method and apparatus for direct communication key establishment

    JP2018523950A