Enabling cellular-based zero-trust network access
The integration of SASE and GBA/AKMA platforms in VPN systems addresses the visibility and control issues in remote access, providing enhanced security and management for enterprise networks.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
- Filing Date
- 2023-01-28
- Publication Date
- 2026-05-11
AI Technical Summary
Existing VPN technologies for remote employees lack the necessary visibility and control over user devices, making it difficult for IT departments to manage access and security effectively.
Implementing a Secure Access Service Edge (SASE) entity and General-Purpose Bootstrapping Architecture/Application Authentication Key Management (GBA/AKMA) platform to establish secure connections between user devices and enterprise networks, allowing dynamic control and visibility through session key sharing.
Enhances IT department visibility and control over remote user devices, enabling secure and managed access to enterprise resources.
Smart Images

Figure 0007856793000001 
Figure 0007856793000002 
Figure 0007856793000003
Abstract
Description
Technical Field
[0001] Cross - Reference to Related Applications This application claims priority under 35 U.S.C.§119(e) to U.S. Provisional Patent Application No. 63 / 344,538, filed on May 21, 2022, entitled "Enabling Zero - Trust Networks Based on 4G and 5G". The entirety of the content of this application is incorporated here by reference for all purposes.
[0002] This disclosure relates to in general a communication system, and more particularly, to methods and apparatuses for establishing a secure connection between a user device and an application entity in an enterprise network.
Background Art
[0003] Remote employees company rely on virtual private network (VPN) technology to access information technology (IT) services. For this purpose, a VPN tunnel is set up between an employee's device such as a laptop, tablet, and a remote dedicated VPN gateway (GW).
[0004] The VPN GW company is placed behind a firewall. In such a setup, it is difficult for the IT department to obtain the desired visibility of the activities of remote user devices. For example, it cannot have the same level of visibility as when the user is working in the office.
[0005] In fact, to improve the visibility of the activities of user devices, the IT department often collects logs from various company applications, which may not be an easy task. Furthermore, the IT department desires to dynamically and finely control user devices and what can be accessed, as well as the location and time of access.
Summary of the Invention
[0006] Various computer implementations, methods, and products for establishing secure connections to enterprise application entities within an enterprise network are described herein.
[0007] According to several embodiments, a method is disclosed for a user device (UE) to establish a secure connection with an application entity in an enterprise network. This method involves sending an establishment request to a Secure Access Secure Edge (SASE) entity, and the SASE entity authorizing the establishment request and the General Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform. Fo If the system decides to allow the application entity to share a session key, it will receive an establishment response from the application entity and establish a connection with the application entity based on the session key. In the following description, the user device will also be referred to as the end-user device.
[0008] According to several embodiments, a method is disclosed that is performed by a Secure Access Secure Edge (SASE) entity to establish a secure connection between a user device and an application entity in an enterprise network. The method includes receiving an establishment request from the user device, deciding whether to allow the establishment request, and if the SASE entity decides to allow the establishment request, sending an initiation message to a General-Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform, receiving an acknowledgment (ACK) response from the GBA / AKMA platform, and sending a session establishment request message to the application entity. The initiation message includes permission to share the session key with the application entity.
[0009] According to several embodiments, a method is disclosed that is performed by a computer implementation controller for establishing a secure connection between a user device and an application entity within an enterprise network. The method includes receiving an establishment request from the user device, deciding whether to allow the establishment request, and if the computer implementation controller decides to allow the establishment request, sending an initiation message to the GBA / AKMA platform, receiving an acknowledgment (ACK) response from the GBA / AKMA platform, and sending a session establishment request message to the application entity. The initiation message includes permission to share a session key with the application entity.
[0010] Embodiments of the UE and computer-implemented controller are also provided according to embodiments of the method described above. [Brief explanation of the drawing]
[0011] To better understand the various embodiments described, the following detailed descriptions should be referred to in conjunction with the following drawings, where similar reference numbers throughout the drawings refer to corresponding parts.
[0012] [Figure 1] This shows exemplary communication systems according to several embodiments.
[0013] [Figure 2] This shows exemplary user devices according to several embodiments.
[0014] [Figure 3] This shows exemplary network nodes according to several embodiments.
[0015] [Figure 4] This shows block diagrams of the host according to several embodiments.
[0016] [Figure 5] shows a block diagram illustrating a virtualized environment according to some embodiments.
[0017] [Figure 6] shows a communication diagram of a host communicating with a user device via a network node through a partial wireless connection according to some embodiments.
[0018] [Figure 7] shows a communication diagram of an end-user device communicating with an enterprise application entity via a Secure Access Service Edge (SASE) entity using a virtual private network (VPN) between the end-user device and the SASE entity.
[0019] [Figure 8] shows an exemplary communication diagram of an end-user device communicating with an enterprise application entity via an Extended User Plane Function (E-UPF) having a SASE entity that uses a VPN between the end-user device and the enterprise application entity.
[0020] [Figure 9] shows an exemplary signal sequence diagram illustrating a process for establishing a secure connection between an end-user device and an enterprise application entity in an enterprise network according to an embodiment of the present disclosure.
[0021] [Figure 10] shows an exemplary flowchart illustrating an exemplary method executed by a user device to establish a secure connection with an enterprise application entity in an enterprise network according to some embodiments of the present disclosure.
[0022] [Figure 11]This section presents an exemplary flowchart illustrating exemplary methods performed by a SASE entity to establish a secure connection between a user device and an enterprise application entity in an enterprise network, according to some embodiments of the present disclosure. [Modes for carrying out the invention]
[0023] To provide a more complete understanding of this disclosure, the following description will elaborate on numerous specific details, such as specific configurations, parameters, and examples. However, it should be noted that such descriptions are not intended to limit the scope of this disclosure, but rather to provide a better description of exemplary embodiments.
[0024] Throughout the specification and claims, the following terms have the meanings expressly relating to this specification unless the context clearly indicates otherwise.
[0025] The phrase "according to some embodiments" does not necessarily refer to the same embodiments as used herein, but may do so. Therefore, various embodiments of this disclosure can be readily combined without departing from the scope or spirit of this disclosure, as described below.
[0026] As used herein, the term "or" is an inclusive "or" operator and is equivalent to the term "and / or" unless the context clearly indicates otherwise.
[0027] The term "based on" is not exclusive and allows for the use of additional factors not explicitly stated, unless the context clearly indicates otherwise.
[0028] As used herein, unless the context indicates otherwise, the term “to be coupled to” is intended to include both direct coupling (where the two elements being coupled are in contact with each other) and indirect coupling (where at least one additional element is located between the two elements). Thus, the terms “to be coupled to” and “to be joined to” are used synonymously. In the context of a networked environment in which two or more components or devices can exchange data, the terms “coupled to” and “joined to” are also used to mean “communicatively coupled to” via one or more intermediate devices, depending on the context.
[0029] In addition, throughout this specification, the meanings of “a,” “an,” and “the” include multiple references, and the meaning of “in” includes “in” and “on.”
[0030] While some of the various embodiments presented herein constitute a single combination of the elements of the Disclosure, it should be understood that the subject matter of the Disclosure is to be considered to include all possible combinations of the elements disclosed. Therefore, if one embodiment includes elements A, B, and C, and another embodiment includes elements B and D, the subject matter of the Disclosure is to be considered to include other remaining combinations of A, B, C, or D, even if not expressly discussed herein. Furthermore, the transitional term “including” means having as a part or component, or being a part or component of them. As used herein, the transitional term “including” is inclusive or non-exclusive and does not exclude additional, unquoted elements or method steps.
[0031] This disclosure relates to a method for establishing secure connections with application entities in an enterprise network. The exemplary embodiments described below primarily relate to 4G and / or 5G communication networks, but this disclosure is also applicable to existing technologies such as GSM and 3G, and other future technologies such as 6G networks and beyond.
[0032] Figure 1 shows examples of communication systems 100 according to several embodiments.
[0033] In this example, the communication system 100 includes a telecommunications network 102, which includes an access network 104 such as a radio access network (RAN), and a core network 106, which includes one or more core network nodes 108. The access network 104 includes one or more access network nodes, such as network nodes 110a and 110b (one or more of which may generally be referred to as network node 110), or any other similar Third Generation Partnership Project (3GPP®) access node or non-3GPP® access point. Network node 110 includes one or more radio connection Direct or indirect connections of user equipment (UEs) are enabled, for example, by connecting UE112a, 112b, 112c, and 112d (one or more of which may generally be referred to as UE112) to the core network 106 via the .
[0034] wireless Example of connection wireless Communication may use electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for carrying information without using wires, cables, or other physical conductors. wireless This includes transmitting and / or receiving signals. Furthermore, in various embodiments, the communication system 100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that can facilitate or participate in the communication of data and / or signals, whether wired or wireless. The communication system 100 may include and / or interface with any type of communication, telecommunications, data, cellular, wireless network, and / or other similar types of systems.
[0035] UE112 connects with network node 110 and other communication devices. Wireless Arranged, configured, and / or operable to communicate wireless It may be any of the broad range of communication devices, including devices. Similarly, network node 110, wireless The UE 112 and / or other network nodes or devices within the telecommunications network 102 are configured, capable of, and / or capable of operating in such a way as to enable and / or provide network access, and / or to perform other functions, such as management within the telecommunications network 102, by communicating directly or indirectly with the UE 112 and / or other network nodes or devices within the telecommunications network 102.
[0036] In the illustrated example, the core network 106 connects network nodes 110 to one or more hosts, such as host 116. These connections may be direct or indirect, via one or more intermediate networks or devices. In other examples, network nodes may be directly connected to hosts. The core network 106 includes one or more core network nodes (e.g., core network node 108) structured with hardware and software components. The functions of these components may be substantially the same as those described for the UE, network nodes, and / or hosts, and therefore those descriptions are generally applicable to the corresponding components of core network node 108. An exemplary core network node is a mobile switching center. - (MSC) includes one or more of the following functions: Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier Decryption Function (SIDF), Unified Data Management (UDM), Security Edge Protected Proxy (SEPP), Network Exposure Function (NEF), and / or User Plane Function (UPF).
[0037] Host 116 is, Operator Host 116 may be owned by or under the control of other service providers, or providers of access network 104 and / or telecommunications network 102, and may be operated by or for such service providers. Host 116 may host a variety of applications and provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data acquisition services such as acquisition and editing of data on various ambient conditions detected by multiple UEs, analytical functionality, social media, functions for controlling or otherwise interacting with remote devices, alarm and monitoring centers. - This includes functions for that purpose, or any other such functions performed by the server.
[0038] Overall, the communication system 100 in Figure 1 enables connectivity between the UE, network nodes, and hosts. In this sense, the communication system may be configured to operate according to predefined rules or procedures, such as certain standards, including, but not limited to, the following: GSM (Global System for Mobile Communications), UMTS (Universal Mobile Telecommunications System), LTE (Long Term Evolution), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standards (e.g., 6G), WLAN (wireless local area network) standards such as the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard (WiFi), and / or any other suitable LPWAN (low-power wide-area network) standards such as WiMAX (Worldwide Interoperability for Microwave Access), Bluetooth, Z-Wave, NFC (Near Field Communication), ZigBee, LiFi, and / or LoRa and Sigfox. wireless Communication standard.
[0039] In some examples, the telecommunications network 102 is a cellular network implementing functions standardized by 3GPP®. Therefore, the telecommunications network 102 may support network slicing to provide various logical networks to various devices connected to the telecommunications network 102. For example, the telecommunications network 102 may provide ultra-high reliability low latency communication (URLLC) services to some UEs while providing extended mobile broadband (eMBB) services to other UEs, and may also provide massive machine type communication (mMTC) / massive IoT services to further UEs.
[0040] In some examples, UE112 is configured to transmit and / or receive information without direct human interaction. For example, the UE may be designed to transmit information to access network 104 on a predetermined schedule, triggered by internal or external events, or in response to a request from access network 104. Additionally, the UE may be configured to operate in single or multi-RAT, or multi-standards mode. For example, the UE may be configured to operate in any one or a combination of Wi-Fi, NR (New Radio), and LTE, i.e., for multi-radio dual connectivity (MR-DC) such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio-Dual Connectivity (EN-DC).
[0041] In the above example, hub 114 communicates with access network 104 to facilitate indirect communication between one or more UEs (e.g., UE112c and / or 112d) and network nodes (e.g., network node 110b). In some examples, hub 114 is a controller, router, content source and analysis, or any other communication device described herein with respect to the UE. For example, hub 114 may be a broadband router that enables the UE to access the core network 106. In another example, hub 114 may be a controller that sends commands or instructions to one or more actuators in the UE. Commands or instructions may be received from the UE or network node 110, or accepted by executable code, scripts, processes, or other instructions within hub 114. In yet another example, hub 114 may be a data collector that acts as temporary storage for the UE's data, and in some embodiments may perform analysis or other processing on that data. In yet another example, hub 114 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker, or other media delivery device, hub 114 may acquire media or data related to VR assets, images, audio, or other sensory information via network nodes, in which case hub 114 provides it to the UE either directly, after performing local processing, and / or after adding additional local content. In another example, Hub 114 acts as a proxy server or orchestrator for the UE, particularly when one or more of the UEs are low-energy IoT devices.
[0042] Hub 114 may have a steady / permanent or intermittent connection to network node 110b. Furthermore, Hub 114 may enable different communication methods and / or schedules between Hub 114 and UEs (UE 112c and / or 112d), and between Hub 114 and the core network 106. In another example, Hub 114 is connected to the core network 106 and / or one or more UEs via a wired connection. Additionally, Hub 114 may be configured to connect to an M2M service provider on the access network 104 and / or to other UEs via a direct connection. In some scenarios, a UE may establish a wireless connection with network node 110 while still being connected via Hub 114 via a wired or wireless connection. In some embodiments, Hub 114 may be a dedicated hub, i.e., a hub whose primary function is to route communication between UEs and network node 110b. In other embodiments, the hub 114 may be a non-dedicated hub, i.e., a device capable of routing communication between the UE and the network node 110b, but also capable of acting as the source and / or destination of communication for some data channel.
[0043] Figure 2 shows UE200 according to several embodiments. Where used here, the UE is connected to a network node and / or other UEs. Wireless A UE is a device that is capable of communicating, configured, arranged, and / or operating in such a manner. Examples of UEs include, but are not limited to, smartphones, mobile phones, cell phones, VoIP (Voice over IP) phones, wireless Local loop phones, desktop computers, personal digital assistants (PDAs), wireless Cameras, game consoles or devices, music storage devices, playback appliances, wearable devices, wireless Endpoints, mobile stations, tablets, laptops, laptop embedded devices (LEE), laptop-based devices (LME), smart devices, wirelessCustomer premises equipment (CPE), vehicles, in-vehicle or vehicle embedded / integrated wireless This includes devices, etc. Other examples include any UE identified by 3GPP®, including Narrowband Internet of Things (NB-IoT) UEs, Machine Type Communications (MTC) UEs, and / or Enhanced MTC (eMTC) UEs.
[0044] The UE may support device-to-device (D2D) communication, for example, by implementing 3GPP® standards for side-link communication, dedicated short-range communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2E). In other examples, the UE does not necessarily have a user in the sense of a human user who owns and / or operates the device in question. Instead, the UE may represent a device (e.g., a smart sprinkler controller) that is intended to be sold to or operated by a human user, but may not be associated with a specific human user, at least initially. Alternatively, the UE may represent a device (e.g., a smart power meter) that is not intended to be sold to or operated by an end user, but may be associated with or operated for the benefit of a user.
[0045] The UE200 includes a processing circuit 202, a power supply 208, a memory 210, a communication interface 212, and / or any other components, or any combination thereof, which are operablely connected to an input / output interface 206 via a bus 204. A given UE may utilize all or a subset of the components shown in Figure 2. The level of integration between components may vary between one UE and another. Furthermore, a given UE may include multiple instances of a component, such as multiple processors, memory, transceivers, transmitters, receivers, etc.
[0046] The processing circuit 202 is configured to process instruction sets and data, and may be configured to implement some sequential state machine capable of operating to execute instruction sets stored in memory 210 as machine-readable computer programs. The processing circuit 202 may be implemented as one or more hardware-implemented state machines (e.g., discrete logic, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), etc.), programmable logic with appropriate firmware, one or more stored computer programs, general-purpose processors such as microprocessors or digital signal processors (DSPs) with appropriate software, or any combination of the above. For example, the processing circuit 202 may be multiple central processing units process It may include a device (CPU).
[0047] In the above example, the input / output interface 206 may be configured to provide an input device, an output device, or one or more interfaces to one or more input / output devices. Examples of output devices include speakers, sound cards, video cards, displays, monitors, printers, actuators, emitters, smart cards, other output devices, or any combination thereof. Input devices may allow a user to capture information to the UE200. Examples of input devices include touch-sensitive or presence-sensitive displays, cameras (e.g., digital cameras, digital video cameras, webcams, etc.), microphones, sensors, mice, trackballs, directional pads, trackpads, scroll wheels, and smart cards. Presence-sensitive displays may include capacitive or resistive touch sensors for sensing user input. Sensors may include, for example, accelerometers, gyroscopes, tilt sensors, force sensors, magnetic sensors, optical sensors, proximity sensors, biosensors, or any combination thereof. Output devices may use the same type of interface port as input devices. For example, a Universal Serial Bus (USB) port may be used to provide input and output devices.
[0048] In some embodiments, the power supply 208 is structured as a battery or battery pack. External electric Other types of power sources, such as a power source (e.g., an electrical outlet), a solar power generation device, or a battery, may also be used. Power source 208 may further include power circuits for transmitting power from power source 208 itself and / or an external power source to various parts of UE200 via interfaces such as input circuits or power cables. Power transmission may, for example, be for charging power source 208. The power circuits may perform some shaping, conversion, or other modification of the power from power source 208 to suit the power of each component of UE200 to which the power is supplied.
[0049] Memory 210 may be random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electroerasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, and flash drives, or may be configured to include such memory. In one example, memory 210 includes one or more application programs QQ214, such as an operating system, a web browser application, a widget, a gadget engine, or other application, and corresponding data QQ216. Memory 210 may store any of a wide variety of operating systems or combinations of multiple operating systems for use by UE100.
[0050] Memory 210 may be configured to include multiple physical drive units such as RAID (Redundant Array of Independent Disks), flash memory, USB flash drives, external hard disk drives, thumb drives, pen drives, key drives, HD-DVD (High-Density Digital Versatile Disc), optical disc drives, internal hard disk drives, Blu-ray optical disc drives, HDDS (Holographic Digital Data Storage) optical disc drives, external mini DI MM (Dual In-Line Memory Module), SDRAM (Synchronous Dynamic Random Access Memory), external micro DIMM SDRAM, smart card memory such as a UICC (universal integrated circuit card) containing one or more SIMs (subscriber Identity Modules) such as USIM and / or ISIM, other memories, or any combination thereof. The UICC may be, for example, an embedded UICC (eUICC), an integrated UICC (iUICC), or a removable UICC commonly known as a "SIM card". Memory 210 may enable UE200 to access instruction sets and application programs stored in temporary or non-temporary storage media to offload or upload data. Product items, such as those utilizing communication systems, may be tangibly embodied as or within memory 210, which is a device-readable storage medium or may include one.
[0051] The processing circuit 202 may be configured to communicate with an access network or other network using a communication interface 212. The communication interface 212 may include one or more communication subsystems, and may include or be communicatively connected to an antenna 222. The communication interface 212 is, wirelessThe system may include one or more transceivers used to communicate, for example, by communicating with one or more remote transceivers of other communicable devices (e.g., other UEs or network nodes in the access network). Each transceiver may include a transmitter 218 and / or receiver 220 appropriate for providing network communication (e.g., optical, electrical, frequency-allocated, etc.). Furthermore, the transmitters 218 and receivers 220 may be coupled to one or more antennas (e.g., antenna 222), which may share circuit components, software, or firmware, or may be implemented separately.
[0052] In the illustrated embodiment, the communication functions of the communication interface 212 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, near-field communication such as Bluetooth, location-based communication such as the use of GPS (Global Positioning System) for location determination, other similar communication functions, or any combination thereof. The communication may be implemented in accordance with one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA®), GSM, LTE, New Radio (NR), UMTS, WiMAX, Ethernet, Transmission Control Protocol / Internet Protocol (TCP / IP), Synchronous Optical Networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, and Hypertext Transfer Protocol (HTTP).
[0053] Regardless of the sensor type, the UE communicates through its communication interface 212 wireless The UE may provide the network node with the output of the data captured by its own sensors via the connection. The data captured by the UE's sensors is wirelessCommunication to network nodes via other UEs may be made through the connection. Output may be periodic (e.g., once every 15 minutes if reporting sensed temperature), random (e.g., to equalize the load from notifications from multiple sensors), in response to triggering events (e.g., humidity is detected and an alert is sent), in response to requests (e.g., user-initiated requests), or a continuous stream (e.g., a live video feed of a patient).
[0054] As another example, UE is from network nodes wireless via connection wireless Includes actuators, motors, or switches associated with a communication interface configured to receive input. wireless The state of actuators, motors, or switches may change in response to input. For example, the UE may include a motor that adjusts the control surface or rotor of a drone in flight according to the received input, or a robotic arm that performs a medical procedure according to the received input.
[0055] If a UE is in the form of an IoT (Internet of Things) device, it may be a device for use in one or more application domains, which include, but are not limited to, wearable technology in urban environments, augmented industrial applications, and healthcare. Non-exclusive examples of such IoT devices include, or are incorporated into, devices such as connected refrigerators or freezers, TVs, connected lighting devices, electric meters, robotic vacuum cleaners, voice-controlled smart speakers, home security cameras, motion detectors, thermostats, smoke detectors, door / window sensors, moisture detectors (flood / moisture sensors), electric door locks, connected doorbells, air conditioning systems such as heat pumps, autonomous vehicles, surveillance systems, weather monitoring devices, vehicle parking monitoring devices, electric vehicle charging stations, smartwatches, fitness trackers, head-mounted displays for augmented reality (AR) or virtual reality (VR), wearables for haptic enhancement or sensory enhancement, water sprinklers, animal or object tracking devices, sensors for monitoring plants or animals, industrial robots, unmanned aerial vehicles (UAVs), and any type of medical device such as heart rate monitors or remotely controlled surgical robots. The UE in the form of an IoT device comprises other components, such as those described in relation to the UE200 shown in Figure 2, in addition to circuitry and / or software that depends on the intended application of the IoT device.
[0056] In another specific example, in an IoT scenario, the UE may represent a machine or other device that performs monitoring and / or measurement and transmits the results of such monitoring and / or measurement to other UEs and / or network nodes. In this case, the UE may be an M2M device and may be referred to as an MTC device in the context of 3GPP®. As one example, the UE may implement the 3GPP® NB-IoT standard. In other scenarios, the UE may represent a passenger car, truck, ship or aircraft or other equipment capable of monitoring and / or reporting its operational status or other functions associated with its operation.
[0057] In practice, any number of UEs may be used together for a single use case. For example, the first UE may be a drone or integrated into a drone and provide speed information of the drone (obtained through a speed sensor) to a second UE, which is a remote controller operating the drone. When the user makes a change from the remote controller, the first UE may adjust the drone's throttle (for example, by controlling an actuator) to increase or decrease the drone's speed. The first and / or second UE may include more than one of the functionalities described above. For example, the UE may include sensors and actuators and handle data communication for both the speed sensor and the actuator.
[0058] Figure 3 shows network node 300 according to several embodiments. As used herein, network node means equipment that is capable of communicating directly or indirectly with the UE and / or other network nodes or equipment in the telecommunications network, and is configured, positioned and / or operational in such a manner. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points) and base stations (BSs) (e.g., radio base stations, node Bs, evolved node Bs (eNBs), and NR node Bs (gNBs)), O-RAN nodes, and components of O-RAN nodes (e.g., O-RUs, O-DUs, O-CUs).
[0059] Base stations may be categorized based on the amount of coverage they provide (or, in other words, their transmit power level), and therefore may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations, depending on the amount of coverage they provide. A base station may also be a relay node or a relay donor node controlling a relay device. A network node may include one or all of the parts of a distributed radio base station, such as a centralized digital unit, a distributed unit (e.g., in an O-RAN access node), and / or a remote radio unit (RRU), sometimes called a remote radio head (RRH). Such remote radio units may or may not be integrated with an antenna, such as an antenna-integrated radio. Some of the distributed radio base stations may be referred to as nodes in a distributed antenna system (DAS).
[0060] Other examples of network nodes include multi-transmitting point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BS, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base stations (BTSs), transmit points, transmit nodes, multi-cell / multicast cooperative entities (MCEs), operations, and maintenance(O&M) nodes, Operation Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Advanced Serving Mobile Location Center) - (E-SMLC) and / or Drive Test Minimization (MDT) are included.
[0061] The network node 300 includes a processing circuit 302, memory 304, a communication interface 306, and a power supply 308. The network node 300 may consist of multiple physically separate components (e.g., an NB component and an RNC component, or a BTS component and a BSC component), each of which may have its own respective components. In a scenario in which the network node 300 has multiple separate components (e.g., BTS and BSC components), one or more of these separate components may be shared among several network nodes. For example, a single RNC may control multiple NBs. In such a scenario, each unique pair of NBs and RNCs may, in some examples, be considered a single separate network node. In some embodiments, the network node 300 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be redundant (e.g., separate memories 304 for different RATs), and some components may be reused (e.g., the same antenna 310 may be shared by multiple different RATs). Furthermore, the network node 300 supports technologies such as GSM, WCDMA®, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, RFID (Radio Frequency Identification), or Bluetooth. wireless Various technologies and other elements will be integrated into the Network Node 300. wireless It may include multiple sets of diverse exemplary components for the technology. wirelessThe technology may be integrated into the same or different chips or sets of chips and other components within the network node 300.
[0062] The processing circuit 302 is a microprocessor, controller, microcontroller, central, capable of operating independently or in conjunction with other network node 300 components such as memory 304 to provide the functionality of the network node 300. Arithmetic processing unit This may include one or more combinations of digital signal processors, application-specific integrated circuits, field-programmable gate arrays, or other suitable computing devices, resources, or hardware, software, and / or coding logic.
[0063] In some embodiments, the processing circuit 302 includes a system-on-a-chip (SOC). In some embodiments, the processing circuit 302 includes one or more of the radio frequency (RF) transceiver circuit 312 and the baseband processing circuit 314. In some embodiments, the radio frequency (RF) transceiver circuit 312 and the baseband processing circuit 314 may be on separate chips (or sets of chips), substrates, or units, such as a radio unit and a digital unit. In alternative embodiments, some or all of the RF transceiver circuit 312 and the baseband processing circuit 314 may be on the same chip or set of chips, substrate, or unit.
[0064] Memory 304 may include, but is not limited to, any form of volatile or non-volatile computer-readable memory, including persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random-access memory (RAM), read-only memory (ROM), large storage media (e.g., hard disk), removable storage media (e.g., flash drive, compact disc (CD) or digital video disc (DVD)), and / or any other volatile or non-volatile non-temporary device-readable and / or computer-executable memory device, for storing information, data and / or instructions that can be used by the processing circuit 302. Memory 304 may store any suitable instructions, data or information, including applications, and / or other instructions, which are executable by the processing circuit 302 and available to the network node 300, including one or more computer programs, software, logic, rules, code, and tables. Memory 304 may also be used to store any calculation results produced by the processing circuit 302 and / or any data received via interface 306. In some embodiments, the processing circuit 302 and the memory 304 are integrated.
[0065] The communication interface 306 is used in wired or wireless signaling and / or data between network nodes, access networks, and / or UEs. As illustrated, the communication interface 306 includes, for example, a port / terminal 316 for sending and receiving data to and from the network over a wired connection. The communication interface 306 also includes a wireless front-end circuit 318, which is connected to or, in some embodiments, part of the antenna 310. The wireless front-end circuit 318 includes a filter 320 and an amplifier 322. The wireless front-end circuit 318 may be connected to the antenna 310 and the processing circuit 302. The wireless front-end circuit may be configured to adjust signals communicated between the antenna 310 and the processing circuit 302. The wireless front-end circuit 318 can receive digital data to be sent to other network nodes or UEs via the wireless connection. The wireless front-end circuit 318 can convert its digital data into a wireless signal with appropriate channel and bandwidth parameters using a combination of the filter 320 and / or the amplifier 322. The radio signal can then be transmitted via the antenna 310. Similarly, when data is received, the antenna 310 collects the radio signal, which can then be converted into digital data by the radio front-end circuit 318. The digital data can then be passed to the processing circuit 302. In other embodiments, the communication interface may include different components and / or different combinations of components.
[0066] In one alternative embodiment, the network node 300 does not have to include a separate wireless front-end circuit 318; rather, the processing circuit 302 may include the wireless front-end circuit and be connected to the antenna 310. Similarly, in some embodiments, all or some of the RF transceiver circuits 312 are part of the communication interface 306. In yet another embodiment, the communication interface 306, as part of a wireless unit (not shown), includes one or more ports or terminals 316, a wireless front-end circuit 318, and RF transceiver circuits 312, and the communication interface 306 communicates with a baseband processing circuit 314, which is part of a digital unit (not shown).
[0067] Antenna 310 is, wireless It may include one or more antennas or antenna arrays configured to transmit and / or receive signals. Antenna 310 may be connected to the wireless front-end circuit 318 to transmit and / or receive data and / or signals. Wireless It may be any type of antenna capable of transmitting and receiving. In one embodiment, the antenna 310 is separate from the network node 300 and can be connected to the network node 300 through an interface or port.
[0068] The antenna 310, communication interface 306, and / or processing circuit 302 may be configured to perform any receiving operations and / or acquisition operations described herein as being performed by a network node. Any information, data, and / or signals may be received from the UE, other network nodes, and / or any other network equipment. Similarly, the antenna 310, communication interface 306, and / or processing circuit 302 may be configured to perform any transmitting operations described herein as being performed by a network node. Any information, data, and / or signals may be transmitted to the UE, other network nodes, and / or any other network equipment.
[0069] Power supply 308 provides power to the various components of the network node 300 in a format suitable for each component (for example, at the voltage and current levels required for each component). Power supply 308 may include, or be connected to, a power management circuit for supplying power to the components of the network node 300 to perform the functions described herein. For example, the network node 300 may have external input circuits or interfaces such as electrical cables. electric It may also be connectable to a power source (e.g., power grid, electrical outlet), thereby enabling external access electric The power source supplies power to the power circuit of power supply 308. As a further example, power supply 308 may include a power source in the form of a battery or battery pack connected to or integrated into the power circuit. The battery is external electric Backup power may be provided in case of a source failure.
[0070] Embodiments of network node 300 may include additional components other than those shown in Figure 3 to provide a functional view of the network node, including any functionality necessary to support any and / or the subject matter described herein. For example, network node 300 may include user interface equipment that enables input of information to and output of information from network node 300. This would allow a user to diagnose network node 300, maintenance This may enable the execution of repair and other management functions.
[0071] Figure 4 is a block diagram of a host 400 that may be an embodiment of host 116 in Figure 1, relating to the various perspectives described herein. Where used here, host 400 is a hardware of various combinations including standalone servers, blade servers, cloud-implemented servers, distributed servers, virtual machines, containers, or processing resources within a server farm. cormorantIt may be, or include, software and / or assets. Host 400 may provide one or more services to one or more UEs.
[0072] The host 400 includes a processing circuit 402 operably connected to an input / output interface 406 via a bus 404, a network interface 408, a power supply 410, and memory 412. In other embodiments, other components may be included. The functions of these components may be substantially the same as those described for the devices in previous drawings such as Figures 2 and 3, and thus those descriptions are generally applicable to the corresponding components of the host 400.
[0073] Memory 412 may include one or more computer programs, including one or more host application programs 414, and data 416, which may include user data, such as data generated by the UE for the host 400 or data generated by the host 400 for the UE. Embodiments of the host 400 may utilize only a subset or all of the illustrated components. The host application program 414 may be implemented in a container-based architecture and may provide support for video codecs (VVC (Versatile Video Coding), HEVC (High Efficiency Video Coding), AVC (Advanced Video Coding), MPEG, VP9) and audio codecs (e.g., FLAC, AAC (Advanced Audio Coding), MPEG, G.711), including transcoding for multiple different classes, types, or implementations of UEs (e.g., handsets, desktop computers, wearable display systems, head-up display systems). Furthermore, the host application program 414 may provide user authentication and license checks, and may periodically report health, route, and content availability to central nodes such as devices within or at the edge of the core network. Thus, host 400 may select and / or point to different hosts for over-the-top services for the UE. The host application program 414 may support a variety of protocols, such as HLS (HTTP Live Streaming), RTMP (Real-Time Messaging Protocol), RTSP (Real-Time Streaming Protocol), and MPEG-DASH (Dynamic Adaptive Streaming over HTTP).
[0074] Figure 5 is a block diagram showing a virtualization environment 500 in which functions implemented by several embodiments can be virtualized. In this context, virtualization means for generating virtual versions of devices or equipment may include a virtualization hardware platform, storage devices, and networking resources. As used herein, virtualization can be applied to any of the devices or components thereof described herein and relates to implementation examples in which at least a portion of its functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented within one or more virtual environments 500 hosted by one or more hardware nodes, such as network nodes, UEs, core network nodes, or hardware computing devices acting as hosts. Furthermore, in embodiments in which the virtual nodes do not require radio connectivity (e.g., core network nodes or hosts), the nodes as a whole may be virtualized. In some embodiments, the virtualization environment 500 includes a set of components defined by the O-RAN Alliance, such as an O-Cloud environment organized by a service management and orchestration framework via an O-2 interface.
[0075] Application 502 (which may alternatively be called a software instance, virtual appliance, network function, virtual node, virtual network function, etc.) runs in a virtualized environment 500 to implement some of the features, functions and / or benefits of some of the embodiments disclosed herein.
[0076] Hardware 504 includes a processing circuit, memory for storing software and / or instruction sets executable by the hardware processing circuit, and / or hardware devices as described herein, such as network interfaces and input / output interfaces. The software is executed by the processing circuit to instantiate one or more virtualization layers 506 (also referred to as a hypervisor or virtual machine monitor (VMM)), provide VM508a and VM508b (one or more of which may be referred to collectively as VM508), and / or perform any of the functions, features and / or benefits described herein in relation to some of the embodiments described herein. The virtualization layer 506 may present a virtual operating platform that appears to the virtual machine 508 as networking hardware.
[0077] VM508 includes virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and may be run by the corresponding virtualization layer 506. Various embodiments of instances of the virtual appliance 502 may be implemented in one or more of the VM508, and the implementation may be done in various ways. Hardware virtualization is referred to as network function virtualization (NFV) in some contexts. NFV is used in data centers. - It can also be used to consolidate many types of network equipment into industry-standard, high-capacity server hardware, physical switches, and physical storage that can be located within the customer's premises.
[0078] In the context of NFV, VM508 may be a software implementation of a physical machine that runs a program as if it were running on a physical, non-virtualized machine. Each VM508, and the portion of hardware 504 on which the VM runs, whether dedicated hardware for that VM and / or hardware shared by that VM with other VMs, forms a separate virtual network element. Also in the context of NFV, the virtual network function is responsible for handling the specific network functions running in one or more VM508s at the top level of hardware 504 and corresponds to application 502.
[0079] Hardware 504 may be implemented in a standalone network node with common or specific components. Hardware 504 may implement some functions through virtualization. Alternatively, hardware 504 may be managed through a management and orchestration 510 in which multiple hardware nodes cooperate (e.g., in a data center). - It may also be part of a larger hardware cluster (such as one within a CPE), which oversees, among other things, the lifecycle management of application 502. In some embodiments, hardware 504 is connected to one or more radio units, each including one or more transmitters and one or more receivers, which can be connected to one or more antennas. The radio units may communicate directly with other hardware nodes via one or more suitable network interfaces, or they may be used in combination with virtual components to provide radio capabilities to virtual nodes, such as radio access nodes or base stations. In some embodiments, some signaling can be provided along with the use of a control system 512, which may alternatively be used for communication between hardware nodes and radio units.
[0080] Figure 6 shows some partial embodiments wireless A host that communicates with UE606 via network node 604 on the connection. 6The communication diagram for 02 is shown. Exemplary implementations of various embodiments of the UE (UE112a in Figure 1 and / or UE200 in Figure 2), network nodes (network node 110a in Figure 1 and / or network node 300 in Figure 3), and hosts (host 116 in Figure 1 and / or host 400 in Figure 4) discussed in the preceding paragraphs will now be described with reference to Figure 6.
[0081] Similar to host 400, an embodiment of host 602 includes hardware such as a communication interface, processing circuitry, and memory. Host 602 also includes software stored within or accessible by host 602, which is executable by the processing circuitry. This software is used by UE6060 and host 6 This includes a host application that may be capable of operating to provide services to remote users, such as a UE606 connected via an over-the-top (OTT) connection 650 extending between 02. While providing services to remote users, the host application may provide user data transmitted using the OTT connection 650.
[0082] Network node 604 includes hardware that enables communication with host 602 and UE606. Connection 660 is direct or can pass through a core network (such as core network 106 in Figure 1) and / or one or more other intermediate networks, such as one or more public, private, or hosted networks. For example, the intermediate network may be a backbone network or the internet.
[0083] UE606 also includes software stored within or accessible by UE606, which is executable by the UE's processing circuitry. This software may, with the support of host 602, operate to provide services to human or non-human users via UE606, such as a web browser or OperatorThis includes client applications such as unique "apps". On host 602, the host application to be executed can communicate with the client application to be executed via UE606 and an OTT connection 650 that terminates on host 602. While providing services to the user, the UE's client application may receive request data from the host's host application and provide user data in response to that request data. The OTT connection 650 handles both the request data and the user data. Turn The UE's client application can interact with the user to generate user data that it provides to the host application via OTT connection 650.
[0084] The OTT connection 650 extends via connection 660 between host 602 and network node 604, and via wireless connection 670 between network node 604 and UE 606, and may provide connectivity between host 602 and UE 606. The connections 660 and wireless connection 670, which may be provided by the OTT connection 650, are abstractly depicted to illustrate communication between host 602 and UE 606 via network node 604 without any explicit reference to any intermediate devices and the precise routing of messages through those devices.
[0085] As an example of transmitting data via the OTT connection 650, in step 608, host 602 provides user data, which may be done by running a host application. In some embodiments, the user data is associated with a specific human user interacting with UE 606. In other embodiments, the user data is associated with UE 606 sharing data with host 602 without explicit human interaction. In step 610, host 602 initiates a transmission to UE 606 that carries the user data. Host 602 may initiate such a transmission in response to a request transmitted by UE 606. Such a request may be triggered by human interaction with UE 606 or by the operation of a client application running on UE 606. The transmission may pass through network node 604 in accordance with the teachings of the embodiments described through this disclosure. Accordingly, in step 612, network node 604 transmits the user data carried in the transmission initiated by host 602 to UE 606 in accordance with the teachings of the embodiments described through this disclosure. In step 614, UE606 receives the user data carried in the above transmission, which may be done by a client application running on UE606 associated with a host application running on host 602.
[0086] In some examples, UE606 runs a client application, thereby providing user data destined for host 602. User data may be provided in reaction to or in response to receiving data from host 602. Accordingly, in step 616, UE606 may provide user data, which may be done by running a client application. While providing user data, the client application may further consider user input received from the user via the input / output interface of UE606. Regardless of the specific way in which the user data is provided, in step 618, UE606 initiates transmission of the user data to host 602 via network node 604. In step 620, in accordance with the teachings of the embodiments described through this disclosure, network node 604 receives user data from UE606 and initiates transmission of the received user data to host 602. In step 622, host 602 receives the user data carried in the transmission initiated by UE606.
[0087] One or more of the various embodiments improve the performance of OTT services provided to the UE606 using the OTT connection 650, with the wireless connection 670 forming the final segment. More precisely, the teachings of these embodiments may improve the power consumption of the UE606, thereby providing benefits such as extended battery life.
[0088] In an exemplary scenario, Host 602 may collect and analyze factory status information. In another example, Host 602 may process audio and video data, which may be acquired from the UE, for use in generating maps. In yet another example, Host 602 may collect and analyze real-time data to assist in controlling vehicle congestion (e.g., traffic light control). In yet another example, Host 602 may store surveillance video uploaded by the UE. In yet another example, Host 602 may store or control access to media content such as video, audio, VR, or AR that can be broadcast, multicast, or unicast to the UE. In yet another example, Host 602 may be used for energy pricing, remote control of non-time-critical power loads for balancing power generation needs, location services, presentation services (such as editing diagrams from data collected from remote devices), or any other function of collecting, acquiring, storing, analyzing, and / or transmitting data.
[0089] In some examples, measurement procedures may be provided for the purpose of monitoring data rate, latency, and other factors that are improved by one or more embodiments. Network as an option for reconfiguring the OTT connection 650 between host 602 and UE606 in response to variations in measurement results. machineFurther possibilities may exist. The above measurement procedures and / or network functionality for reconfiguring the OTT connection may be implemented in the software and hardware of host 602 and / or UE 606. In some embodiments, sensors (not shown) through which the OTT connection 650 passes may be deployed in or associated with other devices, and these sensors may participate in the measurement procedures by supplying numerical values of the monitoring results exemplified above or values of other physical quantities, from which the software may calculate or estimate the monitored quantities. Reconfiguration of the OTT connection 650 may include message formatting, retransmission settings, preferred routing, etc., and such reconfiguration does not need to directly change the operation of network node 604. Such procedures and functionality may be known or in practice in the art. In some embodiments, the measurement may include proprietary UE signaling that facilitates the measurement of throughput, propagation time, and latency, etc., by host 602. The measurement may be implemented by software monitoring propagation time, errors, etc., while sending messages that are specifically empty or "dummy" messages using the OTT connection 650.
[0090] While the computing devices described herein (e.g., UE, network node, host) may include combinations of illustrated hardware components, other embodiments may include computing devices with different combinations of components. It should be understood that these computing devices may include any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. The decisions, calculations, acquisitions, or similar operations described herein may be performed by processing circuits, which may process information by, for example, converting acquired information to other information, comparing acquired or converted information with information stored in the network node, and / or performing one or more operations based on the acquired or converted information, and making decisions as a result of the processing. Furthermore, while components are depicted as single boxes located within larger boxes or nested within multiple boxes, in practice, computing devices may include multiple different physical components that make up the illustrated single component, and functionality may be separated between distinct components. For example, a communication interface may be configured to include any of the components described herein. and / or, The functionality of these components may be divided between processing circuits and communication interfaces. In other examples, computationally intensive functions of any of these components may be implemented in software or firmware, while computationally intensive functions may be implemented in hardware.
[0091] In some embodiments, some or all of the functionalities described herein may be provided by a processing circuit executing a set of instructions stored in memory, and in some embodiments, this may be a computer program product in the form of a non-temporary computer-readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuit, such as in a hardwired manner, without executing instructions stored in separate or discrete device-readable storage mediums. In any of these specific embodiments, the processing circuit can be configured to perform the functionalities described, regardless of whether or not it executes instructions stored in a non-temporary computer-readable storage medium. The benefits provided by such functionalities are not limited to the processing circuit alone or other components of the computing device, but are provided by the computing device as a whole, and / or to the end user and wireless This is enjoyed by the network in general.
[0092] As mentioned above, IT departments often struggle to gain the desired visibility into the activity of remote user devices. To improve visibility into user device activity, IT departments often collect logs from various enterprise applications, but this can be a cumbersome task. Furthermore, IT departments desire dynamic and granular control over user devices and what they can access, as well as the location and time of access. To solve or mitigate these problems, SASE can be used to combine multiple functions into a single entity. For example, SASE would incorporate virtual private network (VPN) gateway (GW), firewall, and software-defined wide area network (SD-WAN) capabilities. In such a scenario, any encrypted tunnel originating from an end-user device (e.g., laptop, tablet, etc.) is terminated at the SASE level, regardless of the user's location. Another encrypted tunnel is then established between the SASE and the target application. An embodiment shown in Figure 7 illustrates such a scenario. This type of technology does not, for example, utilize 4G / 5G embedded security, which eliminates the need to break the VPN tunnel at the SASE level, where data can be decrypted and re-encrypted.
[0093] Figure 7 shows a communication diagram of an end-user device 701 communicating with enterprise application entities 703A-C via Secure Access Secure Edge (SASE) entity 702 using VPN 704 between the end-user device 701 and SASE entity 702. As shown in Figure 7, VPN 704 may be established between the end-user device (e.g., laptop, tablet, etc.) 701 and SASE entity 702 using a pre-shared key generated by Generic Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA). Other encrypted tunnels 705A-C may then be established between SASE entity 702 and target applications 703A-C, respectively.
[0094] According to embodiments of the present disclosure, an end-user device (also known as a UE) 701 may establish a VPN tunnel 704 with a SASE entity 702. A pre-shared key may be used to establish the VPN tunnel 704. Such a pre-shared key may be computed via a GBA and / or AKMA platform (not shown in Figure 7). According to one embodiment, the end-user device 701 first communicates with the GBA / AKMA platform to compute a session key, which the GBA / AKMA platform can then share with the SASE entity 702. The goal behind deriving such a session key via the GBA / AKMA platform is to give the SASE entity 702 confidence in the identifier of the end-user device 701. The pre-shared key computed via the GBA / AKMA platform is used to secure any communication between the end-user device 701 and applications 703A-C authorized by the SASE entity 702.
[0095] According to some embodiments, the end-user device 701 may have a 4G / 5GeSIM (embedded SIM) profile installed. However, according to some embodiments of this disclosure, it is not essential that the end-user device 701 is connected to a 4G / 5G network. However, 5G connectivity may be required if GBA technology becomes obsolete. GBA technology is currently available for 4G and may be extended to support 5G. The GBA platform enables user authentication and requires that the end-user device 701 has a valid identity (identifier) stored on the GBA platform. According to some embodiments, the home network of the end-user device 701 can act as an identifier provider to provide the GBA platform with the necessary and valid identifier.
[0096] The GBA platform does not necessarily require a cellular connection and can operate via a Wi-Fi connection. According to some embodiments, the GBA platform and the end-user device 701 mutually authenticate and agree on a session key to be applied between the end-user device 701 and the GBA platform. The derived key material is used by the GBA user to It may be assigned. After VPN 704 is established between end-user device 701 and SASE entity 702 using a pre-shared key generated by the GBA platform, encrypted tunnels 705A-C may be established between SASE 702 and target applications 703A-C. End-user device 701 and applications 703A-C can communicate securely using session keys generated during mutual authentication between end-user device 701 and the GBA platform.
[0097] Application Key Management (AKMA) is the successor to GBA in 5G technology. The AKMA service aims to establish authenticated communication between end-user devices, such as end-user device 701, and application functions, such as applications 703A-C. Similar to GBA, AKMA leverages operator authentication infrastructure to secure communication between end-user device 701 and applications 703A-C. Therefore, the above description of the GBA platform can also be applied to the AKMA platform. In this disclosure, the GBA platform and the AKMA platform are sometimes used interchangeably and sometimes referred to as the GBA / AKMA platform.
[0098] As described above, the configuration type shown in Figure 7 may not leverage 4G / 5G embedded security, for example, and therefore the VPN tunnel must be broken at the SASE level, where data is decrypted and re-encrypted. Figure 8 shows an exemplary communication diagram of a user device (UE) 801 communicating with enterprise application entities 806A-B via an Enhanced User Plane Function (E-UPF) 803 using a GBA / AKMA-based VPN between the end-user device 801 and enterprise application entities 806A-B. The Enhanced User Plane Function (E-UPF) 803 may include a Secure Access Secure Edge (SASE) entity 804. Enterprise application entities 806A and 806B may operate on enterprise networks 807A and 807B, respectively. Enterprise application entities 806A and 806B can communicate with a GBA / AKMA platform (e.g., platform 802) and may comply with the GBA / AKMA 3GPP® specification. In most cases, such a GBA / AKMA platform may reside within the telecommunications infrastructure. According to some embodiments, a SASE entity 804 can securely communicate with a GBA / AKMA platform 802. Further details of the general-purpose bootstrapping architecture can be found in the documents, namely, European Telecommunications Standards Institute (ETSI) Technical Specifications (TS) 133 220, ETSI TS 133 535, and ETSI TS 133 501, which are incorporated herein in their entirety.
[0099] As shown in Figure 8, the Extended User Plane Function (E-UPF) 803 can combine the user plane functions with the functions of the SASE entity 804. According to some embodiments, the user plane function (UPF) can support minimal security functions (e.g., deep packet inspection) but does not have to have advanced firewall or virtual private network (VPN) gateway (GW) functions. By combining the functions of the SASE entity 804 with the UPF, these additional security functions can become part of the "Extended UPF (E-UPF) 803" as shown in Figure 8. Furthermore, the GBA / AKMA platform 802 can be integrated with the SASE functionality. According to some embodiments, a computer implementation controller can be used to implement the SASE entity 804. The controller can combine at least some of the functions of the SASE entity 804 with the functions of the UPF. The SASE entity 804 may use key exchange with the UE 801 and / or enterprise application entities 806A and 806B to establish secure communication. According to some embodiments of this disclosure, the GBA / AKMA platform 802 may be used to compute and distribute shared keys.
[0100] Specifically, referring to Figure 8, a user device (UE) 801 can communicate with an E-UPF 803 having a SASE entity 804 via the General-Purpose Packet Radio Service (GPRS) Tunneling Protocol (GTP). The E-UPF 803 having the SASE entity 804 may be part of a private or public network 805. The UE 801 may initiate communication with a GBA / AKMA platform 802, which may then compute a session key based on its communication with the UE 801. The GBA / AKMA platform 802 may then share the session key with the E-UPF 803 having the SASE entity 804, thereby giving the SASE entity 804 confidence in the device identifier of the UE 801. For example, according to some embodiments, the pre-shared key computed via the GBA / AKMA platform 802 may be used to secure any communication between the UE 801 and an application authorized by the SASE entity 804. Subsequently, GBA / AKMK-based VPNs 808A between UE801 and SASE entity 804, GBA / AKMK-based VPNs 808B between SASE entity 804 and enterprise application entity 806B, and GBA / AKMK-based VPNs 808C between SASE entity 804 and enterprise application entity 806A can be established using a pre-shared key generated by the GBA / AKMK platform 802.
[0101] After a GBA / AKMA-based VPN is established between UE801 and E-UPF803, and between E-UPF803 and enterprise application entities 806A and 806B, UE801 may, according to one embodiment of this disclosure, send an establishment request, for example, an "App Session Establishment Request" message, to SASE entity 804. According to some embodiments, the establishment request may include requesting or attempting to establish a connection with enterprise application entities 806A or 806B. SASE entity 804 may determine whether UE801's request to connect to enterprise application entities 806A or 806B can be permitted. If SASE entity 804 decides to permit the establishment request, it may permit the GBA / AKMA platform 802 to share the session key with enterprise application entities 806A or 806B. According to some embodiments, if SASE entity 804 determines that UE801's request cannot be permitted, an error message may be sent to UE801. Therefore, the connection between UE801 and enterprise application entity 806A or 806B is terminated. Completed It is possible.
[0102] According to some embodiments, if SASE entity 804 determines that the UE801's request may be permitted, SASE entity 804 proceeds to communicate with GBA / AKMA platform 802. For example, during one such communication, SASE entity 804 may send an "App_Bootstrap_Initiate" ("AB_Init") message to GBA / AKMA platform 802 to permit the sharing of a session key with enterprise application entities 806A or 806B.
[0103] Upon receiving an AB_Init message from SASE entity 804, GBA / AKMA platform 802 may send an acknowledgment (ACK) to SASE entity 804. After receiving an acknowledgment from GBA / AKMA platform 802, SASE entity 804 may forward an "app session establishment request" message to enterprise application entity 806A or 806B. Upon receiving the "app session establishment request" message from SASE entity 804, enterprise application entity 806A or 806B may query for the associated session key by sending a key request message to GBA / AKMA platform 802.
[0104] Upon receiving a valid key request message from enterprise application entity 806A or 806B, the GBA / AKMA platform 802 may respond by sending a key response message carrying the session key along with the relevant parameters. After receiving the key response message from the GBA / AKMA platform 802, enterprise application entity 806A or 806B may respond to UE801 by sending an establishment response message. After sending the establishment response message, a secure end-to-end communication channel can be established between UE801 and enterprise application entity 806A or 806B using the pre-shared session key generated by the GBA / AKMA platform 802. Specifically, the data plane for GBA / AKMA-based VPN809A may be established between UE801 and enterprise application entity 806A, and / or the data plane for GBA / AKMA-based VPN809B may be established between UE801 and enterprise application entity 806B.
[0105] Figure 9 shows an enterprise network according to one embodiment of the present disclosure. to UE901 and Enterprise a Exemplary signals for the process of establishing a secure connection with application entity 904 Sequence A diagram is shown. Referring to Figure 9, UE901 (also called an end-user device) can communicate with SASE entity 903 over uplink (UL) and downlink (DL) channels. UE901 and SASE entity 903 may be part of a cellular communication network, such as a 4G or 5G network.
[0106] In operation 905, UE901 may initiate communication with the GBA / AKMA platform 902. According to some embodiments, the GBA / AKMA platform 902 may compute a session key based on the communication with UE901. The GBA / AKMA platform 902 may then share the session key with the SASE entity 903, thereby giving the SASE entity 903 confidence in the device identifier of UE901. For example, according to some embodiments, a pre-shared key computed via the GBA / AKMA platform 902 may be used to secure any communication between UE901 and an application authorized by the SASE entity 903. The SASE entity 903 may use key exchange with UE901 or the enterprise application entity 904 to establish secure communication. According to some embodiments of this disclosure, the GBA / AKMA platform 902 may be used to compute and distribute shared keys. A VPN may then be established between UE901 and the SASE entity 903 using the pre-shared key generated by the GBA / AKMA platform 902.
[0107] In operation 906, UE901 may send an establishment request (for example, an “App Session Establishment Request” message, as shown in Figure 9) to SASE entity 903 after the VPN has been established between UE901 and SASE entity 903, using a pre-shared key generated by the GBA / AKMK platform 902. According to some embodiments, the establishment request may include requesting or attempting to connect to an enterprise application entity ("App(A)") 904. SASE entity 903 may then determine whether UE901's request or attempt to connect to application A ("app(A)") can be permitted. If SASE entity 903 decides to permit the establishment request, it may permit the GBA / AKMK platform 902 to share the session key with the application entity. According to some embodiments, if SASE entity 903 determines that UE901's request or attempt to connect to application A ("app(A)") cannot be permitted, an error message may be sent to UE901. Therefore, the connection between UE901 and enterprise application entity 904 may be terminated.
[0108] According to some embodiments, if SASE entity 903 determines that the UE 901's request may be permitted, SASE entity 903 proceeds in operation 907 to communicate with the GBA / AKMA platform 902. For example, during one such communication, SASE entity 903 may send an “App_Bootstrap_Initiate” (“AB_Init”) message to the GBA / AKMA (i.e., the Bootstrapping Server Function (BSF) of the GBA platform, or the AKMA Anchor Function (AAnF) of the AKMA platform) 902 to authorize sharing the session key with App(A) 904. According to some embodiments, the message may further include several specific properties and / or parameters assigned to the session key based on the UE 901’s credentials. The AB_Init message may carry the session key identifier (A-KID) sent by UE 901 to App(A) 904 in the “app session establishment request” message, as shown in Figure 9. According to some embodiments, additional properties / parameters included and sent within the AB_Init message may include an App(A) identifier, session key lifetime, nonce, and the like.
[0109] Upon receiving an AB_Init message carrying a valid A-KID from SASE entity 903, the GBA / AKMA platform 902 can store any additional properties and / or parameters included in the AB_Init message. Then, in operation 908, the GBA / AKMA platform 902 may send an acknowledgment (ACK) response to SASE entity 903. According to some embodiments, if it is in a 4G network scenario and the GBA platform is used, the AKMA anchor function (AAnF) included in the GBA platform may store any additional properties and / or parameters included in the AB_Init message and send an ACK message to SASE 903. On the other hand, in a 5G network scenario, the AKMA platform can be used instead of the GBA platform, and then the bootstrapping server function (BSF) can be used to store any additional properties and / or parameters in the AB_Init message and send an ACK message to SASE entity 903.
[0110] After receiving an acknowledgment (ACK) from the GBA / AKMA platform 902, in operation 909, the SASE entity 903 can forward an "app session establishment request" message to App(A) 904. Upon receiving the "app session establishment request" message from the SASE entity 903, App(A) 904 can query for the associated session key in operation 910 by sending an "AKMA AFKey Request" message to AAnF (or a similar request to BSF for the GBA).
[0111] Upon receiving a valid "AKMA AFKey Request" message from App(A)904, the AAnF on the AKMA platform may respond in operation 911 by sending an "AKMA AFKey Response" message that carries the session key along with the relevant parameters. According to some embodiments, when GBA is used instead of AKMA, the AAnF node may be replaced by a BSF that receives a request similar to an "AKMA AFKey Request" and sends a response similar to an "AKMA AFKey Response".
[0112] After receiving an "AKMA AFKey Response" message from AAnF (or a similar response from BSF for GBA), App(A)904 may respond to UE901 in operation 912 by sending an "AKMA AFKey Response" (or a similar response if the GBA platform is used). After sending the "AKMA AFKey Response" (or a similar response if the GBA platform is used), in operation 913, secure end-to-end communication may be established between UE901 and App(A)904 using a pre-shared session key computed by the GBA / AKMA platform 902.
[0113] Embodiments of this disclosure are based on Zero Trust Network Access (ZTNA) that leverage 4G / 5G embedded security to provide access only to user equipment (UE) and explicitly authorized end-user devices inside or outside the enterprise network. company It provides both VPN capabilities and fine-grained control over end-to-end encryption between IT services (e.g., applications within an enterprise network) and other IT services.
[0114] In addition to enabling embedded VPNs, embodiments of the Disclosure integrate SASE features (such as cryptographic tables, artificial intelligence (AI), firewalls, and proxies) into an enhanced UPF, bringing such nodes closer to IT services running on-premises and / or in the public cloud. Furthermore, the granularity of VPN encryption can be tailored per application, per user device, and / or per user by SASE. Devices and applications do not require additional keys, as with traditional VPN certificates; they only require 4G / 5G (or any future cellular generation) keys, such as eSIM profile keys. Any communication to or from devices supporting embodiments of the Disclosure passes through the SASE firewall (FW). Embodiments of the Disclosure enable a provisioned SASE entity 903 to determine whether packets should be snooped whenever necessary, taking into account initiator identifiers, states, times, locations, application types, etc., between an end-user device (e.g., UE) and a target application, or to enable full end-to-end secure communication between the two entities.
[0115] Strong security requires end-to-end security (i.e., encryption). In fact, each time a middlebox, such as SASE entity 903, terminates and restarts an encrypted VPN tunnel, a weakness / vulnerability is introduced because the data packets are decrypted until they are encrypted again. On the other hand, establishing end-to-end encryption is coordinated by ensuring that the two endpoints trust each other. Embodiments of this disclosure establish such trust by using a GBA / AKMA platform (e.g., platform 902). Furthermore, according to some embodiments of this disclosure, end-to-end (e2e) encryption may be the default configuration. This limits the role of the anchor node (e.g., SASE entity) to address exceptional cases where constraints are needed to implement tighter real-time monitoring.
[0116] For example, "inside" company Hackers are no longer uncommon and are even a significant threat today. Therefore, while applications in enterprise networks can use the GBA / AKMA platform (e.g., platform 902), the ability to collect additional data related to the identifier of the user attempting to connect to the application can be beneficial in making decisions. For example, if a contractor / intern is attempting to connect to a “sensitive” application late at night or on a weekend, or if their location is unreliable, a SASE entity might not allow default end-to-end encryption between the two entities. On the other hand, such restrictions are unnecessary if, for example, an executive is attempting to connect to the application.
[0117] Figure 10 shows an exemplary flowchart illustrating exemplary methods 1000 performed by a UE (e.g., UE 901 or any other UE described above) to establish a secure connection with an application entity (e.g., enterprise application entity 904 or any other application entity described above) in an enterprise network, according to some embodiments of the present disclosure. In step 1010, the UE may be configured to send an establishment request (e.g., an "App Session Establishment Request" message, as described above) to a Secure Access Secure Edge (SASE) entity (e.g., entity 903). The SASE entity may then decide whether to authorize the establishment request and authorize a GBA / AKMA platform (e.g., platform 902 or any other GBA / AKMA platform described above) to share a session key with the application entity.
[0118] If the SASE entity decides to allow the establishment request and permit the GBA / AKMA platform to share the session key with the application entity, method 1000 proceeds to step 1020. In step 1020, if the SASE entity decides to allow the establishment request and permit the GBA / AKMA platform to share the session key with the application entity, the UE may be configured to receive an establishment response from the application entity (for example, an "AKMA AFKey Response" message from the BSF for the GBA or a similar response, as described above). On the other hand, according to some embodiments, if the SASE entity decides not to allow the establishment request, the UE receives an error message from the SASE entity and terminates the connection between the user device 901 and the application entity. Completed It can be configured to do so.
[0119] According to some embodiments, the UE may be configured to generate a session key with the GBA / AKMA platform before sending an establishment request to the SASE entity in step 1010. According to some embodiments, the UE may be configured to generate a session key with the GBA / AKMA platform and establish a virtual private network (VPN) tunnel with the SASE entity before sending an establishment request to the SASE entity in step 1010. According to some embodiments, the session key may be computed by the GBA / AKMA platform.
[0120] After the UE receives an establishment response from the application entity 904, method 1000 proceeds to step 1030, where the UE may be configured to establish a connection with the application entity based on a session key calculated by the GBA / AKMA platform.
[0121] Figure 11 shows an exemplary flowchart illustrating exemplary method 1100 performed by a SASE entity (e.g., entity 903 or any other SASE entity) to establish a secure connection between a UE (e.g., UE901 or any other UE described above) and an application entity (e.g., enterprise application entity 904 or any other application entity described above) in an enterprise network, according to some embodiments of the present disclosure. In step 1110, the SASE entity may be configured to receive an establishment request (e.g., an "App Session Establishment Request" message as described above) from the UE. According to some embodiments, the establishment request may include a session key identifier. Then, in step 1120, the SASE entity may be configured to decide whether to allow the establishment request. If the SASE entity decides to allow the establishment request, method 1100 proceeds to step 1130.
[0122] In step 1130, the SASE entity may be configured to send an initiation message (e.g., an "App_Bootstrap_Initiate" message or "AB_Init" message, as described above) to the GBA / AKMA platform (e.g., platform 902 or any other GBA / AKMA platform) if the SASE entity decides to authorize the establishment request. According to some embodiments, the initiation message may include authorization to share the session key with the application entity. The initiation message may carry the session key identifier (e.g., an A-KID, as described above) sent to the application entity by the UE in the establishment request.
[0123] On the other hand, according to some embodiments, if in step 1120 the SASE entity decides not to allow the establishment request, the SASE entity terminates the connection between the UE and the application entity. Completed To that end, it may be configured to send an error message to the UE. According to some embodiments, the start message may further include at least one of one or more properties assigned to the session key based on the user device credentials, or a session key identifier. According to some embodiments, after receiving the start message from the SASE entity, the GBA / AKMA platform stores at least one of the following parameters: namely, an application identifier, or a session key lifetime.
[0124] In step 1140, the SASE entity may be configured to receive an acknowledgment (ACK) response from the GBA / AKMA platform. In step 1150, the SASE entity may be configured to send a session establishment request message to the application entity. For example, the SASE entity may forward an "App Session Establishment Request" message to the application entity.
[0125] The foregoing specification should be understood in all respects to be illustrative and illustrative, and not restrictive, and the scope of the disclosure disclosed herein should not be determined by the specification alone, but rather by the claims, interpreted in accordance with the full scope permitted by patent law. The embodiments shown and described herein are merely illustrative of the principles of the disclosure, and various modifications can be implemented by those skilled in the art without departing from the scope and spirit of the disclosure. Those skilled in the art can implement various other combinations of features without departing from the scope and spirit of the disclosure.
[0126] Abbreviation SASE: Secure Access Secure Edge GBA: General-Purpose Bootstrapping Architecture AKMA: For applications recognition proof key management VPN: Virtual Private Network AAnF: AKMA anchoring function BSF: Bootstrapping Server Function GW: Gateway SD-WAN: Software-Defined Wide Area Network NAF: Network Access Function HSS: Home Subscriber Services GUSS: GBA user Setting fixed AKA: Authentication and Key Agreement TLS: Transport Layer Security AF: Application Function AUSF: Authentication Server Function A-KID: AKMA Key Identifier 1xRTT:CDMA2000 1xWireless Transmission Technology 3GPP®: Third Generation Partnership Project 5G: Fifth Generation DL: Downlink DM: Recovery DMRS: Recovery reference signal DRX: Intermittent reception DTX: Intermittent transmission DTCH: Dedicated Traffic Channel DUT: Device under test E-CID: Extended Cell ID (Positioning Method) eMBMS: Advanced Multimedia Broadcast Multicast Service E-SMLC: Evolution type Serving Mobile Location Center ECGI: Evolution type CGI eNB:NodeB of E-UTRAN ePDCCH: Extended Physical Downlink Control Channel E-SMLC: Evolution type Serving Mobile Location Center E-UTRA: Evolution type UTRA E-UTRAN: Evolved UTRAN FDD: Frequency Division Duplex FFS: Future research topics gNB:NR base station GNSS: Global Navigation Satellite System HARQ: Hybrid Automated Resend Request HO: Handover HSPA: High-Speed Packet Access HRPD: High-Rate Packet Data LOS: line of sight LPP: LTE Positioning Protocol LTE: Long-Term Evolution MAC: Media Access Control MBSFN: Multimedia Broadcast Multicast Service Single Frequency Network MBSFN ABS: MBSFN's mostly blank subframes MDT: Minimizing Drive Tests MIB: Master Information Block MME: Mobility Management Entity MSC: Mobile switching Center NPDCCH: Narrowband Physical Downlink Control Channel NR: New Radio OCNG: OFDMA Channel Noise Generator OFDM: Orthogonal Frequency Division Multiplexing OFDMA: Orthogonal Frequency Division Multiple Access OSS: Operations support system OTDOA: Observed difference in arrival time O&M: Operation and maintenance PBCH: Physical Broadcast Channel P-CCPCH: Primary Common Control Physical Channel PCell: Primary Cell PCFICH: Physical Control Format Indicator Channel PDCCH: Physical Downlink Control Channel PDCP: Packet Data Convergence Protocol PDP: Profile Delay Profile PDSCH: Physical Downlink Shared Channel PGW: Packet Gateway PHICH: Physical Hybrid ARQ Indicator Channel PLMN: Public Land Mobile Communications Network PMI: Precoder Matrix Indicator PRACH: Physical Random Access Channel PRS: Positioning reference signal PSS: Primary Sync Signal PUCCH: Physical uplink control channel PUSCH: Physical uplink shared channel RACH: Random Access Channel QAM: Quadrature Amplitude Modulation RAN: Wireless Access Network RAT: Wireless Access Technology RLC: Wireless Link Control RLM: Wireless Link Management RNC: Wireless Network Controller RNTI: Temporary Wireless Network Identifier RRC: Wireless Resource Control RRM: Wireless Resource Management RS: three light signal RSCP: Received Signal Code Power RSRP: Reference Symbol Received Power, or reference Signal reception power RSRQ: reference Signal reception quality, or Reference symbol reception quality RSSI: Received Signal Strength Indicator RSTD: reference Signal time difference SCH: Synchronization Channel SCell: Secondary Cell SDAP: Service Data Adaptive Protocol SDU: Service Data Unit SFN: System Frame Number SGW: Serving Gateway SI: System Information SIB: System Information Block SNR: Signal-to-Noise Ratio SON: Self-Optimizing Network SS: Synchronization signal SSS: Secondary Sync Signal TDD: Time division duplex TDOA: arrival time difference TOA: Arrival Timing TSS: Third-order synchronous signal TTI: Transmission Time Interval UE: User Device UL: Uplink USIM: Universal Subscriber ID Module UTDOA: Uplink arrival time difference WCDMA (registered trademark): Wide CDMA WLAN: Wide Area Local Network
Claims
1. A method performed by a user device (901) to establish a secure connection with an application entity (904) in an enterprise network, wherein the method is: Sending an establishment request to a Secure Access Secure Edge (SASE) entity (903), The process involves receiving an establishment response from the application entity (904), the establishment response indicating that the SASE entity (903) has authorized the establishment request and decided to allow the General Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform (902) to share a session key with the application entity (904), and Establishing a connection with the application entity (904) based on the session key, A method of having.
2. The method according to claim 1, further, If the SASE entity (903) decides not to allow the establishment request, an error message is received from the SASE entity (903), Upon receiving the aforementioned error message, the connection between the user device (901) and the application entity (904) is terminated, A method of having.
3. A method according to claim 1 or 2, further, Before sending the establishment request to the SASE entity (903), generate a session key with the GBA / AKMA platform (902), A method of having.
4. A method according to claim 1 or 2, further, Before sending the establishment request to the SASE entity (903), establish a virtual private network (VPN) tunnel with the SASE entity (903). A method of having.
5. A method according to claim 1 or 2, wherein the session key is calculated by the GBA / AKMA platform (902).
6. A method according to claim 1 or 2, further, Providing user data, Transferring the user data to the host via transmission to the application entity (904), A method of having.
7. A method performed by a Secure Access Secure Edge (SASE) entity (903) for establishing a secure connection between a user device (901) and an application entity (904) in an enterprise network, wherein the method is: Receiving an establishment request from the user device (901), To decide whether to permit the aforementioned establishment request, If the SASE entity (903) decides to grant the establishment request, it sends a start message to the General Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform (902), Receiving an acknowledgment (ACK) response from the GBA / AKMA platform (902), The process includes sending a session establishment request message to the application entity (904), The method for the commencement message includes permission to share the session key with the application entity (904).
8. The method according to claim 7, further, If the SASE entity (903) decides not to allow the establishment request, it sends an error message to the user device (901) in order to terminate the connection between the user device (901) and the application entity (904). A method of having.
9. A method according to claim 7 or 8, wherein the establishment request includes a session key identifier.
10. The method according to claim 9, wherein the start message is One or more properties assigned to the session key based on the credentials of the user device (901), or The aforementioned session key identifier, A method that includes at least one of the following.
11. A method performed by a computer implementation controller for establishing a secure connection between a user device (901) and an application entity (904) in an enterprise network, wherein the method is: Receiving an establishment request from the user device, To decide whether to permit the aforementioned establishment request, If the computer implementation controller decides to allow the establishment request, it sends a start message to the General Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform (902), Receiving an acknowledgment (ACK) response from the GBA / AKMA platform (902), The process includes sending a session establishment request message to the application entity (904), The method for the commencement message includes permission to share the session key with the application entity (904).
12. The method according to claim 11, further, If the computer implementation controller decides not to allow the establishment request, it sends an error message to the user device to terminate the connection between the user device and the application entity (904). A method of having.
13. A method according to claim 11 or 12, wherein the establishment request includes a session key identifier.
14. The method according to claim 13, wherein the start message is One or more properties assigned to the session key based on the user device credentials, or The aforementioned session key identifier, A method that includes at least one of the following.
15. A user device for establishing a secure connection with an application entity (904) in an enterprise network, A processing circuit, Sending an establishment request to a Secure Access Secure Edge (SASE) entity (903), The process involves receiving an establishment response from the application entity (904), the establishment response indicating that the SASE entity (903) has authorized the establishment request and decided to allow the General-Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform (902) to share the session key with the application entity (904), and Establishing a connection with the application entity (904) based on the session key, The processing circuit is configured to perform the following: A power supply circuit configured to supply power to the aforementioned processing circuit, A user device having the following features.
16. A computer implementation controller for establishing a secure connection between a user device and an application entity (904) within an enterprise network, wherein the computer implementation controller is: A processing circuit, Receiving an establishment request from the user device, To decide whether to permit the aforementioned establishment request, If the processing circuit decides to grant the establishment request, it sends a start message to the General Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform (902), Receiving an acknowledgment (ACK) response from the GBA / AKMA platform (902), The processing circuit is configured to perform the following actions: sending a session establishment request message to the application entity (904); Here, the start message includes permission to share the session key with the application entity (904), A power supply circuit configured to supply power to the aforementioned processing circuit, A computer-implemented controller having
17. In an enterprise network, a user device is used to establish a secure connection with an application entity (904). Sending an establishment request to a Secure Access Secure Edge (SASE) entity (903), The process involves receiving an establishment response from the application entity (904), the establishment response indicating that the SASE entity (903) has authorized the establishment request and decided to allow the General-Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform (902) to share the session key with the application entity (904), and Establishing a connection with the application entity (904) based on the session key, A computer program that executes an action.
18. A computer implementation controller for establishing a secure connection between user devices and application entities (904) within an enterprise network, Receiving an establishment request from the user device, To decide whether to permit the aforementioned establishment request, If it is decided to grant the aforementioned establishment request, a start message is sent to the General Purpose Bootstrapping Architecture / Application Authentication Key Management (GBA / AKMA) platform (902), Receiving an acknowledgment (ACK) response from the GBA / AKMA platform (902), Send a session establishment request message to the application entity (904) and perform the following actions: Here, the start message includes permission to share the session key with the application entity (904), a computer program.