Communication and storage of aircraft system security information

The method and apparatus facilitate efficient communication and storage of aircraft system security information by transmitting and storing authentication results and security requirements, addressing the issue of unawareness of authentication completion in wireless networks and optimizing network resource utilization.

JP7838080B2Active Publication Date: 2026-03-31LENOVO (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-09
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In certain wireless communication networks, network devices are not aware of when authentication has been completed by another device, leading to wasted data transmission and time.

Method used

A method and apparatus for communicating and storing aerial system security information, involving the transmission and reception of messages between network functions to include aircraft identifiers, subscription identifiers, and security policy information, with the ability to store authentication results and security requirements information.

Benefits of technology

Enables efficient communication and storage of aircraft system security information, reducing unnecessary authentication processes and optimizing network resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007838080000001
    Figure 0007838080000001
  • Figure 0007838080000002
    Figure 0007838080000002
  • Figure 0007838080000003
    Figure 0007838080000003
Patent Text Reader

Abstract

Apparatus, methods, and systems for communicating and storing aircraft system security information are disclosed. One method (600) includes sending (602) a request message to an unmanned aircraft system network function, a network publishing function, or a combination thereof, where the request message includes an air vehicle identifier, a public subscription identifier, and security policy information. The method (600) includes receiving (604) a response message from the unmanned aircraft system network function, the network publishing function, or a combination thereof, where the response message includes the air vehicle identifier, the public subscription identifier, an air vehicle authentication result, an authorization result, or a combination thereof, and aircraft system security requirement information. The method (600) includes storing (606) the aircraft system security requirement information with the air vehicle identifier, the public subscription identifier, and the air vehicle authentication result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The subject matter disclosed herein generally relates to wireless communication, and more particularly to communicating and storing aerial system security information.

Background Art

[0002] In certain wireless communication networks, different network devices may not be aware of when authentication has been completed by another network device within the system. In such networks, data transmission and / or time may be wasted.

Summary of the Invention

Means for Solving the Problems

[0003] A method for communicating and storing aerial system security information is disclosed. Apparatus and systems also perform the functions of the method. One embodiment of the method includes transmitting a request message from an access and mobility management function to a unmanned aircraft system network function, a network exposure function, or a combination thereof, the request message including an aircraft identifier, a general public subscription identifier, and security policy information. In some embodiments, the method includes receiving a response message from a unmanned aircraft system network function, a network exposure function, or a combination thereof, the response message including an aircraft identifier, a general public subscription identifier, an aircraft authentication result, a permission result, or a combination thereof, and aerial system security requirement information. In certain embodiments, the method includes storing the aerial system security requirement information together with the aircraft identifier, the general public subscription identifier, and the aircraft authentication result.

[0004] A device for communicating and storing aircraft system security information includes access and mobility management functions. In some embodiments, the device includes a transmitter that sends a request message to an unmanned aircraft system network function, a network publishing function, or a combination thereof, wherein the request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In various embodiments, the device includes a receiver that receives a response message from an unmanned aircraft system network function, a network publishing function, or a combination thereof, wherein the response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, a authorization result, or a combination thereof, and aircraft system security requirements information. In certain embodiments, the device includes a processor that stores the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0005] Another embodiment of a method for communicating and storing aircraft system security information includes the step of receiving a first request message from an access and mobility management function in an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the first request message includes an aircraft vehicle identifier, a publicly available subscription identifier, and security policy information. In some embodiments, the method includes the step of sending a second request message to an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the second request message includes an aircraft vehicle identifier, a publicly available subscription identifier, and security policy information. In certain embodiments, the method includes the step of receiving a second response message from an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the second response message includes an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In various embodiments, the method includes the step of sending a first response message to an access and mobility management function, wherein the first response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In some embodiments, the method includes the step of storing the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0006] Another device for communicating and storing aircraft system security information includes an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof. In some embodiments, the device includes a receiver that receives a first request message from an access and mobility management function, wherein the first request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In various embodiments, the device includes a transmitter that sends a second request message to an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the second request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In certain embodiments, the device includes a processor. The receiver receives a second response message from an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, the second response message including an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; the transmitter sends a first response message to the access and mobility management function, the first response message including an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; and the processor stores the aircraft system security requirements information along with the aircraft vehicle identifier, the publicly available subscription identifier, and the aircraft vehicle authentication result.

[0007] Further embodiments of a method for communicating and storing aircraft system security information include the step of sending a third request message from a session management function to an unmanned aircraft system network function, a network publishing function, or a combination thereof, wherein the third request message includes an aircraft vehicle identifier, a public subscription identifier, and a data request instruction. In some embodiments, the method includes the step of receiving a third response message from an unmanned aircraft system network function, a network publishing function, or a combination thereof, wherein the third response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the method includes the step of deciding to establish a protocol data unit session in response to receiving an aircraft vehicle authentication result and skipping aircraft vehicle authentication. In various embodiments, the method includes the step of storing aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, the aircraft vehicle authentication result, and the aircraft system security requirements information. In some embodiments, the method includes the step of applying user plane security based on the aircraft system security requirements information.

[0008] Further devices for communicating and storing aircraft system security information include session management functions. In some embodiments, the device includes a transmitter that sends a third request message to an unmanned aircraft system network function, a network publishing function, or a combination thereof, wherein the third request message includes an aircraft vehicle identifier, a public subscription identifier, and a data request instruction. In various embodiments, the device includes a receiver that receives a third response message from an unmanned aircraft system network function, a network publishing function, or a combination thereof, wherein the third response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the device includes a processor that, in response to receiving an aircraft vehicle authentication result, decides to establish a protocol data unit session, skips aircraft vehicle authentication, stores aircraft system security requirements information together with the aircraft vehicle identifier, public subscription identifier, aircraft vehicle authentication result, and aircraft system security requirements information, and applies user plane security based on the aircraft system security requirements information.

[0009] Another embodiment of a method for communicating and storing aircraft system security information includes the step of receiving a request message from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, in an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In some embodiments, the method includes the step of sending a response message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the method includes the step of storing the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0010] Another device for communicating and storing aircraft system security information includes an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof. In some embodiments, the device includes a receiver that receives request messages from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In various embodiments, the device includes a transmitter that sends response messages to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the device includes a processor that stores the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0011] A more detailed description of the embodiments briefly described above is made by reference to specific embodiments shown in the accompanying drawings. Understanding that these drawings illustrate only a few embodiments and should therefore not be considered limiting in scope, embodiments are described and explained more specifically and in detail by using the accompanying drawings. [Brief explanation of the drawing]

[0012] [Figure 1] This is a schematic block diagram showing one embodiment of a wireless communication system for communicating and storing aircraft system security information. [Figure 2] This is a schematic block diagram showing one embodiment of a device that may be used to communicate and store aircraft system security information. [Figure 3] This is a schematic block diagram showing one embodiment of a device that may be used to communicate and store aircraft system security information. [Figure 4] This is a schematic block diagram illustrating one embodiment of a system for extracting user-plane security requirements from USS and / or UTM. [Figure 5] This is a schematic block diagram showing one embodiment of a system for providing UUAA results and UAS security requirements information to the SMF. [Figure 6] This is a flowchart illustrating one embodiment of a method for communicating and storing aircraft system security information. [Figure 7] This flowchart illustrates another embodiment of a method for communicating and storing aircraft system security information. [Figure 8] This flowchart illustrates a further embodiment of a method for communicating and storing aircraft system security information. [Figure 9] This flowchart illustrates yet another embodiment of a method for communicating and storing aircraft system security information. [Modes for carrying out the invention]

[0013] As will be understood by those skilled in the art, embodiments may be embodied as systems, apparatus, methods, or program products. Accordingly, embodiments may take the form of entirely hardware embodiments, entirely software embodiments (including firmware, resident software, microcode, etc.), or embodiments combining software and hardware embodiments, all of which may be commonly referred to herein as “circuits,” “modules,” or “systems.” Furthermore, embodiments may take the form of program products embodied in one or more computer-readable storage devices that store machine-readable code, computer-readable code, and / or program code, hereafter referred to as code. The storage devices may be tangible, non-temporary, and / or non-transmitting. The storage devices do not have to embody signals. In certain embodiments, the storage devices merely use signals to access the code.

[0014] Some of the functional units described herein may be labeled as modules to further emphasize their implementation independence. For example, modules may be implemented as custom very large-scale integrated circuits ("VLSI") or as hardware circuits comprising off-the-shelf semiconductors such as gate arrays, logic chips, transistors, or other individual components. Modules may also be implemented in programmable hardware devices such as field-programmable gate arrays, programmable array logic, or programmable logic devices.

[0015] Modules may also be implemented in code and / or software for execution by various types of processors. An identified module of code may, for example, contain one or more physical or logical blocks of executable code, which may be organized as, for example, objects, procedures, or functions. However, the executable files of an identified module do not need to be physically located together, but may contain different instructions stored in different locations, and these instructions, when logically combined, constitute the module and achieve the stated purpose of the module.

[0016] In practice, a module of code may be a single instruction or many instructions, and may even be distributed across several different code segments, between different programs, and across several memory devices. Similarly, operational data may be identified and indicated within a module as herein, embodied in any appropriate form, and organized within any appropriate type of data structure. Operational data may be collected as a single dataset or distributed across different locations, including across different computer-readable storage devices. If a module or part of a module is implemented in software, the software part is stored on one or more computer-readable storage devices.

[0017] Any combination of one or more computer-readable media may be used. The computer-readable media may be computer-readable storage media. The computer-readable storage media may be a storage device that stores code. The storage device may be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, holographic, micromechanical, or semiconductor systems, apparatus, or devices, or any suitable combination of the above.

[0018] More specific examples of storage devices (a non-exclusive list) would include electrical connections having one or more wires, portable computer diskettes, hard disks, random access memory ("RAM"), read-only memory ("ROM"), erasable programmable read-only memory ("EPROM" or Flash memory), portable compact disk read-only memory ("CD-ROM"), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the context of this document, computer-readable storage media may be any tangible media that contains or can store programs for use by or in connection with an instruction execution system, apparatus, or device.

[0019] The code for performing the actions for the embodiments may be of any number of lines and may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Python, Ruby, Java, Smalltalk, or C++, and traditional procedural programming languages ​​such as the "C" programming language, and / or machine languages ​​such as assembly language. The code may run entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network ("LAN") or a wide area network ("WAN"), or a connection to an external computer may be made (for example, via the Internet using an Internet service provider).

[0020] References throughout this specification to "one embodiment", "an embodiment", or similar language mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, appearances of the phrases "in one embodiment", "in an embodiment", and similar language throughout this specification are not necessarily all referring to the same embodiment, but "one or more embodiments" where not otherwise specified, unless stated otherwise. The terms "including", "comprising", "having", and variations thereof mean "including, without limitation" unless otherwise specified. A list of listed items does not imply that any or all of the items are mutually exclusive unless otherwise specified. The terms "a", "an", and "the" also refer to "one or more" unless otherwise specified.

[0021] Furthermore, the features, structures, or characteristics described for the embodiments may be combined in any suitable manner. In the following description, numerous specific details are provided, such as examples of programming, software modules, user selections, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., to provide a thorough understanding of the embodiments. However, one skilled in the art will recognize that the embodiments may be practiced without one or more of the specific details, or with other methods, components, materials, etc. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of an embodiment.

[0022] Aspects of the embodiments will be described below with reference to the schematic flowchart diagrams and / or schematic block diagrams of the method, apparatus, system, and program product according to the embodiments. It should be understood that each block of the schematic flowchart diagrams and / or schematic block diagrams, as well as combinations of blocks in the schematic flowchart diagrams and / or schematic block diagrams, can be implemented by code. The code can be provided to a processor of a general-purpose computer, a dedicated computer, or other programmable data processing apparatus to generate a machine, and as a result, the instructions executed via the computer or other programmable data processing apparatus' processor create means for implementing the functions / acts specified in one or more blocks of the schematic flowchart diagrams and / or schematic block diagrams.

[0023] Code that can instruct a computer, other programmable data processing apparatus, or other device to function in a specific way can also be stored in a memory device, and as a result, the instructions stored in the memory device generate a manufactured product that includes instructions for implementing the functions / acts specified in one or more blocks of the schematic flowchart diagrams and / or schematic block diagrams.

[0024] The code can also be loaded onto a computer, other programmable data processing apparatus, or other device to perform a series of operational steps on the computer, other programmable data processing apparatus, or other device to generate a computer-implemented process, and as a result, the code executed on the computer or other programmable data processing apparatus provides a process for implementing the functions / acts specified in one or more blocks of the flowchart diagrams and / or block diagrams.

[0025] The schematic flowcharts and / or schematic block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of devices, systems, methods, and program products according to various embodiments. In this regard, each block in the schematic flowcharts and / or schematic block diagrams may represent a module, segment, or portion of code containing one or more executable instructions of code for implementing a specified logical function.

[0026] It should also be noted that in some alternative implementations, the functions mentioned in a block may be performed in a different order than those shown in the diagram. For example, two blocks shown consecutively may actually be executed substantially simultaneously, or blocks may sometimes be executed in reverse order depending on the functions involved. Other steps and methods may be contemplated that are functionally, logically, or effectively equivalent to one or more blocks, or parts thereof, of the diagram shown.

[0027] Various arrow and line types may be used in flowcharts and / or block diagrams, but these are understood not to limit the scope of the corresponding embodiment. In fact, some arrows or other connectors may be used only to indicate the logical flow of the illustrated embodiment. For example, arrows may indicate waiting or monitoring periods of an unspecified duration between enumerated steps of the illustrated embodiment. It should also be noted that each block in a block diagram and / or flowchart, as well as combinations of blocks in a block diagram and / or flowchart, may be implemented by a dedicated hardware-based system or a combination of dedicated hardware and code to perform a specified function or action.

[0028] The descriptions of elements in each figure may refer to elements in preceding figures. Similar numbers refer to similar elements in all figures, including alternative embodiments of similar elements.

[0029] Figure 1 illustrates one embodiment of a wireless communication system 100 for communicating and storing aircraft system security information. In one embodiment, the wireless communication system 100 includes a remote unit 102 and a network unit 104. Although a specific number of remote units 102 and network units 104 are illustrated in Figure 1, those skilled in the art will recognize that any number of remote units 102 and network units 104 may be included in the wireless communication system 100.

[0030] In one embodiment, the remote unit 102 may include computing devices such as a desktop computer, laptop computer, personal digital assistant ("PDA"), tablet computer, smartphone, smart television (e.g., an internet-connected television), set-top box, game console, security system (including security camera), vehicle-mounted computer, network device (e.g., router, switch, modem), aerial vehicle, or drone. In some embodiments, the remote unit 102 includes wearable devices such as a smartwatch, fitness band, or optical head-mounted display. Furthermore, the remote unit 102 may be referred to as a subscriber unit, mobile, mobile station, user, terminal, mobile terminal, fixed terminal, subscriber station, UE, user terminal, device, or by other terms used in the art. The remote unit 102 may communicate directly with one or more of the network units 104 via UL communication signals. In certain embodiments, the remote unit 102 may communicate directly with other remote units 102 via side-link communication.

[0031] The network unit 104 may be distributed across geographical areas. In certain embodiments, the network unit 104 may include access points, access terminals, bases, base stations, location servers, core network ("CN"), radio network entities, node B, advanced node B ("eNB"), 5G node B ("gNB"), home node B, relay nodes, devices, core network, airborne servers, radio access nodes, access points ("AP"), new radio ("NR"), network entities, access and mobility management functions ("AMF"), integrated data management ("UDM"), integrated data repository The network unit 104 is generally part of a radio access network that includes one or more controllers communicably coupled to one or more corresponding network units 104. A wireless access network is generally commutably coupled to one or more core networks, and one or more core networks may be coupled to other networks within the network, such as the Internet and public switched telephone networks. These and other elements of the wireless access network and core networks are not shown but are generally well known to those skilled in the art.

[0032] In one implementation, the wireless communication system 100 conforms to the NR protocol standardized in the Third Generation Partnership Project ("3GPP®"), with the network unit 104 transmitting on the downlink ("DL") using OFDM modulation and the remote unit 102 transmitting on the uplink ("UL") using single-carrier frequency division multiple access ("SC-FDMA") or orthogonal frequency division multiplexing ("OFDM"). However, more generally, the wireless communication system 100 may implement any other open or proprietary communication protocol, such as WiMAX, the Institute of Electrical and Electronics Engineers ("IEEE") 802.11 variant, Global System for Mobile Communications ("GSM"), General-Purpose Packet Radio Service ("GPRS"), Universal Mobile Telecommunications System ("UMTS"), Long-Term Evolution ("LTE") variant, Code Division Multiple Access 2000 ("CDMA2000"), Bluetooth®, ZigBee, or Sigfox. This disclosure is not limited to any particular wireless communication system architecture or protocol implementation.

[0033] The network unit 104 may serve several remote units 102 within a serving area, for example, a cell or cell sector, via a wireless communication link. The network unit 104 transmits DL communication signals to serve the remote units 102 in the time domain, frequency domain, and / or spatial domain.

[0034] In various embodiments, the network unit 104 may send a request message to the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, the request message including an aircraft vehicle identifier, a public subscription identifier, and security policy information. In some embodiments, the network unit 104 may receive a response message from the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, the response message including an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, an authorization result, or a combination thereof, and aircraft system security requirements information. In certain embodiments, the network unit 104 may store the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result. Thus, the network unit 104 may be used to communicate and store aircraft system security information.

[0035] In certain embodiments, the network unit 104 may receive a first request message from an access and mobility management function in an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, the first request message including an aircraft vehicle identifier, a public subscription identifier, and security policy information. In some embodiments, the network unit 104 may send a second request message to an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, the second request message including an aircraft vehicle identifier, a public subscription identifier, and security policy information. In certain embodiments, the network unit 104 may receive a second response message from an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, the second response message including an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In various embodiments, the network unit 104 may transmit a first response message to the access and mobility management functions, the first response message including an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In some embodiments, the network unit 104 may store the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result. Thus, the network unit 104 may be used to communicate and store aircraft system security information.

[0036] In some embodiments, the network unit 104 may send a third request message to the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, the third request message including an aircraft vehicle identifier, a public subscription identifier, and a data request instruction. In some embodiments, the network unit 104 may receive a third response message from the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, the third response message including an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the network unit 104 may decide to establish a protocol data unit session in response to receiving the aircraft vehicle authentication result and skip aircraft vehicle authentication. In various embodiments, the network unit 104 may store aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, the aircraft vehicle authentication result, and the aircraft system security requirements information. In some embodiments, the network unit 104 may apply user plane security based on the aircraft system security requirements information. Therefore, the network unit 104 may be used to communicate and store aircraft system security information.

[0037] In various embodiments, the network unit 104 may receive request messages from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof in an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, and the request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In some embodiments, the network unit 104 may send response messages to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, and the response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the network unit 104 may store the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result. Thus, the network unit 104 may be used to communicate and store aircraft system security information.

[0038] Figure 2 illustrates one embodiment of a device 200 that may be used to communicate and store aircraft system security information. The device 200 includes one embodiment of a remote unit 102. Furthermore, the remote unit 102 may include a processor 202, memory 204, an input device 206, a display 208, a transmitter 210, and a receiver 212. In some embodiments, the input device 206 and the display 208 are combined into a single device such as a touchscreen. In certain embodiments, the remote unit 102 may not include any input device 206 and / or display 208. In various embodiments, the remote unit 102 may include one or more of the processor 202, memory 204, transmitter 210, and receiver 212, and may not include the input device 206 and / or display 208.

[0039] In one embodiment, the processor 202 may include any known controller capable of executing computer-readable instructions and / or performing logical operations. For example, the processor 202 may be a microcontroller, microprocessor, central processing unit ("CPU"), graphics processing unit ("GPU"), auxiliary processing unit, field-programmable gate array ("FPGA"), or similar programmable controller. In some embodiments, the processor 202 executes instructions stored in memory 204 to perform the methods and routines described herein. The processor 202 is communicatively coupled to memory 204, input device 206, display 208, transmitter 210, and receiver 212.

[0040] In one embodiment, memory 204 is a computer-readable storage medium. In some embodiments, memory 204 includes a volatile computer storage medium. For example, memory 204 may include RAM, including dynamic RAM ("DRAM"), synchronous dynamic RAM ("SDRAM"), and / or static RAM ("SRAM"). In some embodiments, memory 204 includes a non-volatile computer storage medium. For example, memory 204 may include a hard disk drive, flash memory, or any other suitable non-volatile computer storage device. In some embodiments, memory 204 includes both volatile and non-volatile computer storage mediums. In some embodiments, memory 204 also stores program code and associated data, such as an operating system or other controller algorithms running on the remote unit 102.

[0041] In one embodiment, the input device 206 may include any known computer input device, such as a touch panel, buttons, a keyboard, a stylus, or a microphone. In some embodiments, the input device 206 may be integrated with the display 208, for example, as a touchscreen or similar touch-sensitive display. In some embodiments, the input device 206 includes a touchscreen on which text can be entered using a virtual keyboard displayed on the touchscreen and / or by handwriting on the touchscreen. In some embodiments, the input device 206 includes two or more different devices, such as a keyboard and a touch panel.

[0042] In one embodiment, the display 208 may include any known electronically controllable display or display device. The display 208 may be designed to output visual signals, audible signals, and / or tactile signals. In some embodiments, the display 208 includes an electronic display capable of outputting visual data to a user. For example, the display 208 may include, but is not limited to, a liquid crystal display ("LCD"), a light-emitting diode ("LED") display, an organic light-emitting diode ("OLED") display, a projector, or a similar display device capable of outputting images or text to a user. In another non-limiting example, the display 208 may include a wearable display such as a smartwatch, smart glasses, or a head-up display. Furthermore, the display 208 may be a component of a smartphone, personal digital assistant, television, tablet computer, notebook (laptop) computer, personal computer, or vehicle dashboard.

[0043] In certain embodiments, the display 208 includes one or more speakers for generating sound. For example, the display 208 may generate audible alerts or notifications (e.g., beeps or chimes). In some embodiments, the display 208 includes one or more haptic devices for generating vibration, motion, or other tactile feedback. In some embodiments, all or part of the display 208 may be integrated with an input device 206. For example, the input device 206 and the display 208 may form a touchscreen or similar touch-sensitive display. In other embodiments, the display 208 may be located near the input device 206.

[0044] Although only one transmitter 210 and one receiver 212 are shown, the remote unit 102 may have any suitable number of transmitters 210 and receivers 212. The transmitters 210 and receivers 212 may be any suitable type of transmitter and receiver. In one embodiment, the transmitters 210 and receivers 212 may be part of a transceiver.

[0045] Figure 3 illustrates one embodiment of a device 300 that may be used to communicate and store aircraft system security information. The device 300 includes one embodiment of a network unit 104. Furthermore, the network unit 104 may include a processor 302, memory 304, input device 306, display 308, transmitter 310, and receiver 312. As can be understood, the processor 302, memory 304, input device 306, display 308, transmitter 310, and receiver 312 may be substantially the same as the processor 202, memory 204, input device 206, display 208, transmitter 210, and receiver 212 of a remote unit 102, respectively.

[0046] In certain embodiments, the transmitter 310 transmits a request message to the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, the request message including an aircraft vehicle identifier, a public subscription identifier, and security policy information. In various embodiments, the receiver 312 receives a response message from the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, the response message including an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, a authorization result, or a combination thereof, and aircraft system security requirements information. In certain embodiments, the processor 302 stores the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0047] In some embodiments, the receiver 312 receives a first request message from the access and mobility management function, the first request message including an aircraft vehicle identifier, a publicly available subscription identifier, and security policy information. In various embodiments, the transmitter 310 sends a second request message to the unmanned aerial vehicle system service supplier, the unmanned aerial vehicle system traffic management function, or a combination thereof, the second request message including an aircraft vehicle identifier, a publicly available subscription identifier, and security policy information. In certain embodiments, the device includes a processor 302. Receiver 312 receives a second response message from an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, the second response message including an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; Transmitter 310 sends a first response message to the access and mobility management function, the first response message including an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; and Processor 302 stores the aircraft system security requirements information together with the aircraft vehicle identifier, the publicly available subscription identifier, and the aircraft vehicle authentication result.

[0048] In various embodiments, the transmitter 310 transmits a third request message to the unmanned aerial vehicle system network function, the network exposure function, or a combination thereof, the third request message including an aircraft vehicle identifier, a public subscription identifier, and a data request instruction. In various embodiments, the receiver 312 receives a third response message from the unmanned aerial vehicle system network function, the network exposure function, or a combination thereof, the third response message including an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the processor 302, in response to receiving the aircraft vehicle authentication result, decides to establish a protocol data unit session, skips aircraft vehicle authentication, stores the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, the aircraft vehicle authentication result, and the aircraft system security requirements information, and applies user plane security based on the aircraft system security requirements information.

[0049] In certain embodiments, the receiver 312 receives a request message from the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, and the request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In various embodiments, the transmitter 310 sends a response message to the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, and the response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, the processor 302 stores the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0050] In certain embodiments, Unmanned Aerial System ("UAS") Service Supplier ("USS") Unmanned Aerial Vehicle ("UAV") authorization and / or certification ("UUAA") may be performed on the UAV during its registration to a fifth-generation ("5G") system or during the protocol data unit ("PDU") session establishment and / or modification procedure related to the UAS service. If UUAA is performed on the UAV during registration, it may not be necessary to perform UUAA during the subsequent PDU session establishment procedure. In such embodiments, it may not be clear how the session management function ("SMF") involved in the PDU session establishment procedure will know whether UUAA has been performed on the UAV, which can lead to various problems.

[0051] In some embodiments, the SMF may invoke additional UUAAs on the UAV during the PDU session establishment procedure (e.g., without prior knowledge of successful UUAAs), resulting in delayed UAS session setup and unnecessary overhead (e.g., inefficient resource utilization).

[0052] In various embodiments, the system may coordinate UUAA results and UUAA information (e.g., UAS and / or command and control ("C2") user plane security requirements information) between the 3GPP® network function ("NF") (e.g., AMF or UAS NF and / or network exposure function ("NEF")) and the SMF during PDU session establishment and / or modification procedures to enable the SMF to know whether UUAA has already been successfully performed on the UAV during the recent registration procedure.

[0053] In the first embodiment, there may be service-based user plane security enforcement in a 3GPP® 5G system ("5GS") during UUAA. In the first embodiment, the NF in the 3GPP® system may receive user plane security requirements information from the USS and / or Unmanned Aerial System Traffic Management ("UTM") following successful UAS service authentication and / or authorization (e.g., authorization of UUAA or UAV and / or UAV controller ("UAV-C") pairing).

[0054] Figure 4 is a schematic block diagram showing one embodiment of System 400 for extracting user plane security requirements from USS and / or UTM. System 400 includes User Equipment ("UE") 402, AMF 404, SMF 406, UAS 408 (e.g., UAS NF and / or NEF), and USS 410 (e.g., USS and / or UTM). Note that each communication in System 400 may contain one or more messages.

[0055] In a particular embodiment, UE402 requests service from any UAS408 by sending a message to AMF404 (for example, with its UAV identifier ("ID")). AMF404 decides to trigger UUAA based on its local policy, and / or decides to trigger UUAA following a request from USS410.

[0056] AMF404 calls UUAA (412).

[0057] In the first communication 414, AMF404 sends an authentication request (e.g., Nnef_Authentication_request) to UAS408 that includes a UAV ID (e.g., a Civil Aviation Administration ("CAA") level UAV ID) and an external identifier (e.g., a Publicly Available Subscription Identifier ("GPSI")). In certain embodiments, the authentication request includes UAS session security information (e.g., security policy information). Note that UAS session security information may be referred to as user plane security policy, UAS security policy, and / or external UAS security policy. UAS session security information and / or UAS security policy may also include policies specific to user plane confidentiality and user plane integrity protection.

[0058] In the second communication 416, UAS408 may send USS410 an authentication request (e.g., Naf_Authentication_request) including a UAV ID (e.g., a CAA-level UAV ID) and an external identifier (e.g., GPSI). In some embodiments, the authentication request may also include UAS session security information.

[0059] In various embodiments, the AMF404 may set session security information as "supported" based on either of the following conditions: 1) when an aviation subscription user plane security policy fetched from the UDM is "required", and / or 2) when a user plane security policy fetched from the UDM is "required".

[0060] In certain embodiments, the AMF404 may set the session security information to "unsupported, undesirable, and / or not required" based on either of the following conditions: 1) there is no aviation subscription, and / or 2) the user plane security policy fetched from the UDM is "not required and / or undesirable".

[0061] In the third communication 418, USS410 may send UAS408 an authentication response (e.g., Naf_Authentication_response) which includes an external identifier (e.g., GPSI) and an authentication and / or authorization message.

[0062] In an optional fourth communication 420, several round-trip messages required by the authentication method used by USS410 may be exchanged. Authentication and / or authentication response messages from USS410 may include GPSI and may include authentication messages based on the authentication method used, which are transparently transmitted to UE402 via transport messages (e.g., mobility management messages).

[0063] In the fifth communication 422, following the success of authentication and / or authorization, USS410 may send an authentication response (e.g., Naf_Authentication_response) to UAS408 that includes an external identifier (e.g., GPSI), a CAA-level UAV ID, the result, and UAS security requirements information (e.g., it may be user plane security requirements information).

[0064] In some embodiments, USS410 sets the UAS security requirement information as "required" based on at least one of the following conditions: 1) the session security information received by USS410 from UAS408 in step 416 is "supported," and / or 2) USS410 decides not to apply end-to-end security to the session and / or user plane data. In various embodiments, USS410 may send a causal value indicating that end-to-end security is not applicable and / or supported.

[0065] In certain embodiments, USS410 sets the UAS security requirements information as "not required" based on at least one of the following conditions: 1) if the session security information received by USS410 from UAS408 in step 416 is "not required and / or undesirable", 2) if USS410 does not receive UAS session security information in step 416, and / or 3) if USS410 decides to apply end-to-end security to the session and / or user plane data. In some embodiments, a causal value indicating that end-to-end security is applicable and / or supported may be sent from USS410.

[0066] In some embodiments, if USS410 receives session security information from UAS408 as “supported” in step 416, USS410 may decide to skip end-to-end security, set the UAS session security requirement information as “required,” and set the cause value as end-to-end security is not applicable and / or supported.

[0067] In various embodiments, if USS410 receives session security information from UAS408 as “unsupported, undesirable, and / or not required” in step 416, USS410 may decide to implement end-to-end security, setting the UAS session security requirements information as “not required” and setting the cause value as end-to-end security is applicable and / or supported.

[0068] The UAS408 may store received UAS security requirements information (for example, it may be user plane security requirements information) along with an external identifier (e.g., GPSI), a CAA-level UAV ID, and / or results (424).

[0069] In the sixth communication 426, UAS408 may send an authentication response message to AMF404 that includes an external identifier (e.g., GPSI), a CAA-level UAV ID, and / or results, along with UAS security requirements information (e.g., it may be user plane security requirements information).

[0070] The AMF404 may store received UAS security requirements information (for example, it may be user plane security requirements information) along with an external identifier (e.g., GPSI), a CAA-level UAV ID, and / or results (428).

[0071] In the seventh communication 430 and / or an optional eighth communication 432, the AMF 404 may provide the UE 402 with an authentication result and a CAA-level UAV ID in an Access Layer ("NAS") message (for example, a mobility management message or an optional UE configuration update message).

[0072] In a second embodiment, there may be UUAA status coordination in 3GPP® 5GS. In the second embodiment, UUAA may be performed on a UAV during its registration to the 5G system or during the PDU session establishment and / or modification procedure. If UUAA is performed on the UAV during registration, it is not necessary to perform UUAA during the subsequent PDU session establishment procedure. In some embodiments, the SMF involved in PDU session establishment may not have a means of knowing whether UUAA has been previously successfully performed on the corresponding UAV. The second embodiment includes information on how the SMF is notified of the successful UUAA result during the subsequent PDU session establishment procedure if UUAA has been previously successfully performed during registration.

[0073] Figure 5 is a schematic block diagram showing one embodiment of system 500 for providing UUAA results and UAS security requirements information to the SMF. System 500 includes UE 502, AMF 504, SMF 506, UAS 508 (e.g., UAS NF and / or NEF), and USS 510 (e.g., USS and / or UTM). Note that each communication in system 500 may contain one or more messages.

[0074] Figure 5 includes three options for providing the SMF506 with UUAA results and UUAA information (e.g., UAS and / or C2 user plane security requirements information) to enable the SMF to continue the PDU session establishment procedure without additional UUAA.

[0075] In the first communication 512, a successful UUAA is performed on the UAV during the 5GS registration procedure, and an NF (e.g., AMF504, UAS508) in the 3GPP® network stores the UUAA result (e.g., along with the UAV ID) and UAS security requirements information (or user plane security requirements information) in either local storage or in an unstructured data storage function ("UDSF") and / or UDM. Note that the storage of UAS security requirements information may be the same as that described in the first embodiment. The UAS security requirements information may indicate whether user plane security (or UAS session and / or C2 session security) needs to be enforced by 5GS.

[0076] UAS security requirements information may include the following information, namely: 1) 3GPP® user plane security is indicated as “required” and the cause value may indicate that end-to-end security is not applicable and / or supported as enforced by USS510; or 2) 3GPP® user plane security is indicated as “not required” and the cause value may indicate that end-to-end security is applicable and / or supported as enforced by USS510.

[0077] The first option includes steps 514, 516, 518, 520, 536, and 538.

[0078] Specifically, in the second communication 514, UE502 sends a PDU session establishment request to AMF504 in a NAS message that includes a service level device identity (e.g., the CAA-level UAV ID of the UAV) and optionally authentication data (e.g., UUAA aviation payload).

[0079] If AMF504 finds a UE context that has UUAA information, such as locally stored UUAA results and UAS security requirements information, based on the received CAA-level UAV ID, AMF504 decides to provide the UUAA information to SMF506 (516). AMF504 selects SMF506 and, in a third communication 518, sends an Nsmf_PDUSession_CreateSMContext request message along with the PDU session establishment request, the UUAA results (e.g., with a success indication), and / or UAS security requirements information. In certain embodiments, AMF504 may also send an Nsmf_PDUSession_UpdateSMContext request message to SMF506, which may include the UUAA results (e.g., with a success indication) and / or UAS security requirements information.

[0080] When SMF506 receives a CAA-level UAV ID along with the UUAA result (e.g., with a success indication) and / or UAS security requirements information, it decides to continue the PDU session establishment procedure without performing any additional UUAA with USS510, since the UUAA result (e.g., with a success indication) and / or UAS security requirements information from the registration procedure are available for SMF506 to continue establishing a PDU session related to the UAS service (520).

[0081] In the first option, steps 522-534 may be skipped. In the eighth communication 536, SMF506 continues with the PDU session establishment and / or modification procedure. In the ninth communication 538, if the UUAA result is not provided by AMF504, SMF506 triggers to perform a UUAA with USS510 for the PDU session establishment and / or modification procedure.

[0082] The second option includes steps 514, 518, 522, 524, 526, 534, 536, and 538, and therefore steps 516, 520, and 528-532 are skipped.

[0083] In the second communication 514, UE502 sends a PDU session establishment request to AMF504 in a NAS message that includes a service level device identity (e.g., the CAA-level UAV ID of the UAV) and optionally authentication data (e.g., UUAA aviation payload).

[0084] In the third communication 518, AMF504 selects SMF506 and sends an Nsmf_PDUSession_CreateSMContext request message to SMF506 along with a PDU session establishment request.

[0085] In the fourth communication 522, SMF506 decides to check for a CAA-level UAV ID and / or external identifier (e.g., GPSI) if any UUAA results from recent UUAAs exist. Furthermore, SMF506 sends a data request message (e.g., Nnef_Auth_Data Request or Nnef_UUAA_Data Request) to UAS508 that includes the CAA-level UAV ID and / or external identifier (e.g., GPSI).

[0086] If UAS508 finds a UE context that has UUAA information, such as locally stored UUAA results and UAS security requirements information, based on the received CAA-level UAV ID, UAS508 decides to provide the UUAA information to SMF506 (524).

[0087] In the fifth communication 526, UAS 508 sends SMF 506 a data response message (e.g., Nnef_Auth_Data Response or Nnef_UUAA_Data Response) containing the CAA-level UAV ID and / or external identifier (e.g., GPSI), the UUAA result (e.g., with a success indication), and / or UAS security requirements information. In some embodiments, if the UUAA result is not available, UAS 508 sends SMF 506 a data response message (e.g., Nnef_Auth_Data Response or Nnef_UUAA_Data Response) containing the CAA-level UAV ID and / or external identifier (e.g., GPSI), and / or a data unavailable indication.

[0088] When SMF506 receives a CAA-level UAV ID along with a UUAA result (e.g., with a success indication) and / or UAS security requirements information, it decides to continue the PDU session establishment procedure without performing any additional UUAA with USS510, since the UUAA result (e.g., with a success indication) and UAS security requirements information from the registration procedure are available for SMF506 to continue establishing a PDU session related to the UAS service (534).

[0089] In the eighth communication 536, SMF506 continues the PDU session establishment and / or modification procedure. In various embodiments, if no UUAA result is provided, a data unavailable instruction may be provided by UAS508, and then, in an optional ninth communication 538, SMF506 is triggered to perform a UUAA with USS510 for the PDU session establishment and / or modification procedure.

[0090] The third option includes steps 514, 518, 528, 530, 532, 534, 536, and 538, and therefore steps 516 and 520-526 are skipped.

[0091] In the second communication 514, UE502 sends a PDU session establishment request to AMF504 in a NAS message that includes a service level device identity (e.g., the CAA-level UAV ID of the UAV) and optionally authentication data (e.g., UUAA aviation payload).

[0092] In the third communication 518, AMF504 selects SMF506 and sends an Nsmf_PDUSession_CreateSMContext request message to SMF506 along with a PDU session establishment request.

[0093] In the sixth communication 528, SMF506 decides to invoke UUAA and sends an authentication request message (e.g., Nnef_Auth_Request) to UAS508 that includes the CAA-level UAV ID and an external identifier (e.g., GPSI).

[0094] If UAS508 finds a UE context that has UUAA information, such as locally stored UUAA results and UAS security requirements information, based on the received CAA-level UAV ID, UAS508 decides to provide the UUAA information to SMF506 (530).

[0095] In the seventh communication 532, UAS508 sends SMF506 an authentication response message (e.g., Nnef_Auth_Response) containing the CAA-level UAV ID and / or external identifier (e.g., GPSI), the UUAA result (e.g., with a success indication), and / or UAS security requirements information.

[0096] When SMF506 receives the CAA-level UAV ID and / or external identifier (e.g., GPSI) along with the UUAA result (e.g., with a success indication) and / or UAS security requirements information, it decides to continue the PDU session establishment procedure without performing any additional UUAA with USS510, since the UUAA result (e.g., with a success indication) and / or UAS security requirements information from the registration procedure are available for SMF506 to continue establishing a PDU session related to the UAS service (534).

[0097] In the eighth communication 536, SMF506 continues the PDU session establishment and / or modification procedure. In various embodiments, if no UUAA result is provided, a data unavailable instruction may be provided by UAS508, and then, in an optional ninth communication 538, SMF506 is triggered to perform a UUAA with USS510 for the PDU session establishment and / or modification procedure.

[0098] Figure 6 is a flowchart illustrating one embodiment of method 600 for communicating and storing aircraft system security information. In some embodiments, method 600 is implemented by a device such as a network unit 104. In certain embodiments, method 600 may be implemented by a processor that executes program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, or FPGA.

[0099] In various embodiments, Method 600 includes a step 602 of sending a request message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In some embodiments, Method 600 includes a step 604 of receiving a response message from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, a authorization result, or a combination thereof, and aircraft system security requirements information. In certain embodiments, Method 600 includes a step 606 of storing the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0100] In certain embodiments, Method 600 further comprises the step of setting security policy information to supported, enabled, or in combination thereof, in response to a need for an aviation subscription user plane security policy fetched from a management function (i.e., an integrated data management function (UDM)), in response to a need for a user plane security policy fetched from a management function (i.e., an integrated data management function (UDM)), or in combination thereof.

[0101] In some embodiments, Method 600 further comprises the step of setting security policy information to unsupported, disabled, undesirable, undesirable, undesirable, or a combination thereof, in response to the absence of an available aviation subscription for an aviation vehicle corresponding to an aviation vehicle identifier, in response to the preference, undesirability, or undesirability of a user plane security policy fetched from a management function (i.e., an integrated data management function (UDM)), or a combination thereof.

[0102] In various embodiments, the method 600 further comprises the step of providing the session management function with the aircraft vehicle authentication result and aircraft system security requirements information along with the aircraft vehicle identifier in response to receiving a protocol data unit session establishment request having an aircraft vehicle identifier from a user device.

[0103] Figure 7 is a flowchart illustrating another embodiment of method 700 for communicating and storing aircraft system security information. In some embodiments, method 700 is implemented by a device such as a network unit 104. In certain embodiments, method 700 may be implemented by a processor that executes program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, or FPGA.

[0104] In various embodiments, Method 700 includes step 702 of receiving a first request message from an access and mobility management function, wherein the first request message includes an aircraft vehicle identifier, a publicly available subscription identifier, and security policy information. In some embodiments, Method 700 includes step 704 of sending a second request message to an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the second request message includes an aircraft vehicle identifier, a publicly available subscription identifier, and security policy information. In certain embodiments, Method 700 includes step 706 of receiving a second response message from an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the second response message includes an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In various embodiments, Method 700 includes a step 708 of sending a first response message to an access and mobility management function, wherein the first response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In some embodiments, Method 700 includes a step 710 of storing the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0105] In certain embodiments, the method 700 further comprises the step of providing the session management function with the aircraft vehicle authentication result and aircraft system security requirements information, along with the aircraft vehicle identifier, in response to receiving an authentication request from the session management function.

[0106] Figure 8 is a flowchart illustrating further embodiments of method 800 for communicating and storing aircraft system security information. In some embodiments, method 800 is implemented by a device such as a network unit 104. In certain embodiments, method 800 may be implemented by a processor that executes program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, or FPGA.

[0107] In various embodiments, Method 800 includes step 802 of sending a third request message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the third request message includes an aircraft vehicle identifier, a public subscription identifier, and a data request instruction. In some embodiments, Method 800 includes step 804 of receiving a third response message from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the third response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, Method 800 includes step 806 of deciding to establish a protocol data unit session in response to receiving the aircraft vehicle authentication result and skipping aircraft vehicle authentication. In various embodiments, Method 800 includes step 808 of storing aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, the aircraft vehicle authentication result, and the aircraft system security requirements information. In some embodiments, method 800 includes step 810 of applying user plane security based on aircraft system security requirements information.

[0108] In certain embodiments, Method 800 further comprises the step of receiving a third response message without sending a third request message in response to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof comprising an access and mobility management function. In some embodiments, Method 800 further comprises the step of receiving a third response message in response to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof comprising an access and mobility management system, wherein the access and mobility management function receives a protocol data unit session establishment request having an aircraft vehicle identifier, and the access and mobility management system has an aircraft vehicle identifier with an aircraft vehicle authentication result and aircraft system security requirements information.

[0109] In various embodiments, the third request message is an authentication data request or authentication request message. In one embodiment, the third response message is an authentication data response or authentication response message. In certain embodiments, the third response message includes a data unavailable instruction. In some embodiments, method 800 further includes the step of deciding to invoke aviation vehicle authentication if a data unavailable instruction is received or if aviation vehicle authentication results and security requirements information are not received from the network function.

[0110] Figure 9 is a flowchart illustrating yet another embodiment of method 900 for communicating and storing aircraft system security information. In some embodiments, method 900 is implemented by a device such as a network unit 104. In certain embodiments, method 900 may be implemented by a processor that executes program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, or FPGA.

[0111] In various embodiments, Method 900 includes step 902 of receiving a request message from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof in an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the request message includes an aircraft vehicle identifier, a public subscription identifier, and security policy information. In some embodiments, Method 900 includes step 904 of sending a response message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message includes an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. In certain embodiments, Method 900 includes step 906 of storing the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0112] In certain embodiments, Method 900 further comprises the step of determining whether security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is supported, enabled, or a combination thereof, whether an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof decides not to apply end-to-end security to session data, user plane data, or a combination thereof, or setting aircraft system security requirement information as required based on such a combination. In some embodiments, Method 900 further comprises the step of sending a causal value indicating that end-to-end security is not applicable, not supported, or a combination thereof.

[0113] In various embodiments, Method 900 further comprises the step of setting aircraft system security requirements information as not required based on whether security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is unsupported, not enabled, not required, undesirable, or a combination thereof; whether an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof does not receive security policy information during aircraft vehicle authentication and / or authorization; whether an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof decides to apply end-to-end security to session data, user plane data, or a combination thereof; or any combination thereof.

[0114] In one embodiment, Method 900 further comprises the step of sending a cause value indicating that end-to-end security is applicable, supported, or a combination thereof. In a particular embodiment, if security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is supported, enabled, or a combination thereof, the unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to skip end-to-end security, sets the aircraft system security requirements information as required, and sets the cause value as end-to-end security is not applicable, not supported, or a combination thereof.

[0115] In some embodiments, if security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is unsupported, not enabled, not required, undesirable, or a combination thereof, the unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to activate end-to-end security, sets the aircraft system security requirements information as not required, and sets the cause value as end-to-end security is applicable, supported, or a combination thereof.

[0116] In one embodiment, the access and mobility management function method comprises the steps of: sending a request message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the request message comprises an aircraft vehicle identifier, a public subscription identifier, and security policy information; receiving a response message from the unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message comprises an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, a permission result, or a combination thereof, and aircraft system security requirement information; and storing the aircraft system security requirement information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0117] In certain embodiments, the method further comprises the step of setting security policy information to supported, enabled, or in combination thereof, in response to a need for an aviation subscription user plane security policy fetched from a management function (i.e., an integrated data management function (UDM)), in response to a need for a user plane security policy fetched from a management function (i.e., an integrated data management function (UDM)), or in combination thereof.

[0118] In some embodiments, the method further comprises the step of setting security policy information to unsupported, disabled, undesirable, undesirable, undesirable, or a combination thereof, in response to the absence of an available aviation subscription for an aviation vehicle corresponding to an aviation vehicle identifier, in response to the preference, undesirability, or undesirability of a user plane security policy fetched from a management function (i.e., an integrated data management function (UDM)), or in combination thereof.

[0119] In various embodiments, the method further comprises the step of providing the session management function with the aircraft vehicle authentication result and aircraft system security requirements information along with the aircraft vehicle identifier in response to receiving a protocol data unit session establishment request having an aircraft vehicle identifier from a user device.

[0120] In one embodiment, the device includes access and mobility management functions. The device further includes a transmitter that sends a request message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the request message comprises an aircraft vehicle identifier, a public subscription identifier, and security policy information; a receiver that receives a response message from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message comprises an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, a permission result, or a combination thereof, and aircraft system security requirement information; and a processor that stores the aircraft system security requirement information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0121] In certain embodiments, the processor sets security policy information to supported, enabled, or a combination thereof in response to a need for an aviation subscription user plane security policy fetched from a management function (i.e., an integrated data management function (UDM)), in response to a need for a user plane security policy fetched from a management function, or a combination thereof.

[0122] In some embodiments, the processor sets security policy information to unsupported, disabled, unsuitable, unsuitable, unsuitable, or a combination thereof, in response to the absence of available aviation subscriptions for an aviation vehicle corresponding to an aviation vehicle identifier, in response to whether user plane security policies fetched from a management function (i.e., an integrated data management function (UDM)) are preferred, unsuitable, or not, or a combination thereof.

[0123] In various embodiments, upon receiving a protocol data unit session establishment request from a user device having an aircraft vehicle identifier, the transmitter transmits the aircraft vehicle authentication result and aircraft system security requirements information along with the aircraft vehicle identifier to the session management function during the protocol data unit session establishment procedure.

[0124] In one embodiment, a method for an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, includes the steps of: receiving a first request message from an access and mobility management function, wherein the first request message comprises an aircraft vehicle identifier, a public subscription identifier, and security policy information; and sending a second request message to an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the second request message comprises an aircraft vehicle identifier, a public subscription identifier, and security policy information; and sending a second response message to the unmanned aerial vehicle system service supplier The process includes: receiving from an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein a second response message comprises an aerial vehicle identifier, a publicly available subscription identifier, an aerial vehicle authentication result, and aircraft system security requirements information; transmitting a first response message to an access and mobility management function, wherein the first response message comprises an aerial vehicle identifier, a publicly available subscription identifier, an aerial vehicle authentication result, and aircraft system security requirements information; and storing the aircraft system security requirements information together with the aerial vehicle identifier, the publicly available subscription identifier, and the aerial vehicle authentication result.

[0125] In certain embodiments, the method further comprises the step of providing the session management function with the aircraft vehicle authentication result and aircraft system security requirements information, along with the aircraft vehicle identifier, during the protocol data unit session establishment procedure, in response to receiving an authentication request from the session management function.

[0126] In one embodiment, the device comprises an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof. The device further comprises a receiver that receives a first request message from an access and mobility management function, wherein the first request message comprises an aircraft vehicle identifier, a public subscription identifier, and security policy information; a transmitter that transmits a second request message to an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, wherein the second request message comprises an aircraft vehicle identifier, a public subscription identifier, and security policy information; and a processor, wherein the receiver transmits a second response message to the unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function. The transmitter receives a first response message from the human-aircraft system traffic management function, or a combination thereof, and the second response message comprises an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. The transmitter then sends the first response message to the access and mobility management function, and the first response message comprises an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information. The processor stores the aircraft system security requirements information along with the aircraft vehicle identifier, the publicly available subscription identifier, and the aircraft vehicle authentication result.

[0127] In certain embodiments, the transmitter, in response to receiving an authentication request from the session management function, transmits the aircraft vehicle authentication result and aircraft system security requirements information during the protocol data unit session establishment procedure, along with the aircraft vehicle identifier, to the session management function.

[0128] In one embodiment, the session management function method comprises the steps of: sending a third request message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the third request message comprises an aircraft vehicle identifier, a public subscription identifier, and a data request instruction; receiving a third response message from the unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the third response message comprises an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; deciding to establish a protocol data unit session in response to receiving the aircraft vehicle authentication result and skipping aircraft vehicle authentication; storing aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, the aircraft vehicle authentication result, and the aircraft system security requirements information; and applying user plane security based on the aircraft system security requirements information.

[0129] In certain embodiments, the method further comprises the step of receiving a third response message without sending a third request message in response to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof having access and mobility management functions.

[0130] In some embodiments, the method includes the step of receiving a third response message in response to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof comprising an access and mobility management system, wherein the access and mobility management function receives a protocol data unit session establishment request having an aircraft vehicle identifier, and the access and mobility management system has an aircraft vehicle identifier with an aircraft vehicle authentication result and aircraft system security requirements information.

[0131] In various embodiments, the third request message is an authentication data request or an authentication request message.

[0132] In one embodiment, the third response message is an authentication data response or an authentication response message.

[0133] In certain embodiments, the third response message includes an indication that data is unavailable.

[0134] In some embodiments, the method further comprises the step of deciding to invoke aviation vehicle authentication if a data unavailable instruction is received or if aviation vehicle authentication results and security requirements information are not received from the network function.

[0135] In one embodiment, the device includes a session management function. The device further includes a transmitter that sends a third request message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the third request message comprises an aircraft vehicle identifier, a public subscription identifier, and a data request instruction; a receiver that receives a third response message from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the third response message comprises an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; and a processor that, in response to receiving the aircraft vehicle authentication result, decides to establish a protocol data unit session, skips aircraft vehicle authentication, stores the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, the aircraft vehicle authentication result, and the aircraft system security requirements information, and applies user plane security based on the aircraft system security requirements information.

[0136] In certain embodiments, the receiver receives a third response message without sending a third request message in response to the unmanned aerial vehicle system network function, network publishing function, or a combination thereof having access and mobility management functions.

[0137] In some embodiments, the receiver receives a third response message in response to the unmanned aerial vehicle system network function, network publishing function, or a combination thereof comprising an access and mobility management system, the access and mobility management function receives a protocol data unit session establishment request having an aircraft vehicle identifier, and the access and mobility management system has the aircraft vehicle identifier with an aircraft vehicle authentication result and aircraft system security requirements information.

[0138] In various embodiments, the third request message is an authentication data request or an authentication request message.

[0139] In one embodiment, the third response message is an authentication data response or an authentication response message.

[0140] In certain embodiments, the third response message includes an indication that data is unavailable.

[0141] In some embodiments, the processor decides to invoke aviation vehicle authentication if it receives a data unavailable instruction or if aviation vehicle authentication results and security requirements information are not received from the network function.

[0142] In one embodiment, a method for an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof, includes the steps of: receiving a request message from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the request message comprises an aircraft vehicle identifier, a public subscription identifier, and security policy information; sending a response message to the unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message comprises an aircraft vehicle identifier, a public subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; and storing the aircraft system security requirements information together with the aircraft vehicle identifier, the public subscription identifier, and the aircraft vehicle authentication result.

[0143] In certain embodiments, the method further comprises the steps of determining whether security policy information received from an unmanned aerial vehicle system network function, a network exposure function, or a combination thereof is supported, enabled, or a combination thereof, whether an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof decides not to apply end-to-end security to session data, user plane data, or a combination thereof, or setting aircraft system security requirements information as required based on such a combination.

[0144] In some embodiments, the method further comprises the step of sending a causal value indicating that end-to-end security is not applicable, unsupported, or a combination thereof.

[0145] In various embodiments, the method further comprises the step of setting aircraft system security requirements information as not required based on whether security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is unsupported, not enabled, not required, undesirable, or a combination thereof; whether an unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof does not receive security policy information during aircraft vehicle authentication and / or authorization; whether an unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to apply end-to-end security to session data, user plane data, or a combination thereof; or any combination thereof.

[0146] In one embodiment, the method further comprises the step of sending a causal value indicating that end-to-end security is applicable, supported, or a combination thereof.

[0147] In certain embodiments, if security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is supported, enabled, or a combination thereof, the unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to skip end-to-end security, sets the aircraft system security requirements information as required, and sets the cause value as end-to-end security is not applicable, not supported, or a combination thereof.

[0148] In some embodiments, if security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is unsupported, not enabled, not required, undesirable, or a combination thereof, the unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to activate end-to-end security, sets the aircraft system security requirements information as not required, and sets the cause value as end-to-end security is applicable, supported, or a combination thereof.

[0149] In one embodiment, the device comprises an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof. The device further comprises a receiver that receives request messages from an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the request message comprises an aircraft vehicle identifier, a publicly available subscription identifier, and security policy information; a transmitter that sends response messages to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the response message comprises an aircraft vehicle identifier, a publicly available subscription identifier, an aircraft vehicle authentication result, and aircraft system security requirements information; and a processor that stores the aircraft system security requirements information together with the aircraft vehicle identifier, the publicly available subscription identifier, and the aircraft vehicle authentication result.

[0150] In certain embodiments, the processor sets whether security policy information received from an unmanned aerial vehicle system network function, a network exposure function, or a combination thereof is supported, enabled, or a combination thereof, whether an unmanned aerial vehicle system service supplier, an unmanned aerial vehicle system traffic management function, or a combination thereof decides not to apply end-to-end security to session data, user plane data, or a combination thereof, or based on a combination thereof, aircraft system security requirements information is required.

[0151] In some embodiments, the transmitter transmits a causal value indicating that end-to-end security is not applicable, unsupported, or a combination thereof.

[0152] In various embodiments, the processor sets aircraft system security requirements information as not required based on whether security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is unsupported, not enabled, not required, undesirable, or a combination thereof; whether an unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof does not receive security policy information during aircraft vehicle authentication and / or authorization; whether an unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to apply end-to-end security to session data, user plane data, or a combination thereof; or any combination thereof.

[0153] In one embodiment, the transmitter transmits a causal value indicating that end-to-end security is applicable, supported, or a combination thereof.

[0154] In certain embodiments, if security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is supported, enabled, or a combination thereof, the unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to skip end-to-end security, sets the aircraft system security requirements information as required, and sets the cause value as end-to-end security is not applicable, not supported, or a combination thereof.

[0155] In some embodiments, if security policy information received from an unmanned aerial vehicle system network function, network exposure function, or a combination thereof is unsupported, not enabled, not required, undesirable, or a combination thereof, the unmanned aerial vehicle system service supplier, unmanned aerial vehicle system traffic management function, or a combination thereof decides to activate end-to-end security, sets the aircraft system security requirements information as not required, and sets the cause value as end-to-end security is applicable, supported, or a combination thereof.

[0156] The embodiments described may be practiced in other specific forms. The embodiments described should be considered in all respects to be illustrative and not limiting. Accordingly, the scope of the invention is indicated not by the above description but by the appended claims. All modifications that fall within the meaning and scope equivalent to the claims shall be encompassed within those scopes. [Explanation of Symbols]

[0157] 100 Wireless Communication Systems 102 Remote Unit 104 Network Units 200 equipment 202 processors 204 memory 206 Input Devices 208 displays 210 Transmitter 212 Receiver 300 equipment 302 Processors 304 memory 306 Input Devices 308 displays 310 Transmitter 312 Receiver 400 System 402 User Equipment, UE 404 AMF 406 SMF 408 UAS 410 USS 414 First communication 416 Second communication 418 Third Communication 420 Fourth Communication 422 Fifth Communication 426 The Sixth Communication 430 The 7th Communication 432 The 8th Communication 500 Systems 502 UE 504 AMF 506 SMF 508 UAS 510 USS 512 First Communication 514 Second communication 518 Third Communication 522 The fourth communication 526 Fifth Communication 528 The Sixth Communication 532 The 7th Communication 536 The 8th Communication 538 The 9th Communication 600 ways 700 methods 800 ways 900 ways

Claims

[Claim 1] A device equipped with access and mobility management functions, A transmitter that transmits a request message to an unmanned aerial vehicle system network function, a network publishing function, or a combination thereof, wherein the request message is Aircraft vehicle identifier and Publicly available subscription identifier and Security policy information and A transmitter equipped with, A receiver that receives a response message from the unmanned aerial vehicle system network function, the network publishing function, or a combination thereof, wherein the response message is The aforementioned aircraft vehicle identifier, The aforementioned publicly available subscription identifier and, Aviation vehicle certification results, approval results, or combination thereof, Aircraft system security requirements information and A receiver equipped with, A processor that stores the aircraft system security requirements information together with the aircraft vehicle identifier, the publicly available subscription identifier, and the aircraft vehicle authentication result. Furthermore, A device wherein, in response to the transmitter receiving a protocol data unit session establishment request having the aircraft vehicle identifier from a user device, the transmitter transmits the aircraft vehicle authentication result and the aircraft system security requirements information during the protocol data unit session establishment procedure, along with the aircraft vehicle identifier, to a session management function.