Method and apparatus for IP security child security association lifetime extention
The method extends the lifetime of IPsec child SAs by using a first lifetime and traffic threshold, addressing rekeying failures and preventing service disruptions, while ensuring secure operation through abnormal packet detection.
Patent Information
- Application Number
- PCT/CN2023/139049
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-19
AI Technical Summary
IPsec child Security Association (SA) rekeying failures due to routing changes or parameter configuration errors can lead to SA expiration, causing service disruption and traffic loss.
A method to extend the lifetime of IPsec child SAs based on a first lifetime and traffic threshold, allowing for continued operation beyond the initial local lifetime, with mechanisms to detect abnormal packets and trigger rekeying or deletion as necessary.
This solution extends the life cycle of IPsec child SAs, preventing service disruptions and traffic loss by giving users more time to handle rekey failures, while ensuring secure operation through abnormal packet detection.
Smart Images

Figure CN2023139049_19062025_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR IP SECURITY CHILD SECURITY ASSOCIATION LIFETIME EXTENTIONTECHNICAL FIELD
[0001] The non-limiting and exemplary embodiments of the present disclosure generally relate to the technical field of communications, and specifically to methods and apparatuses for Internet Protocol Security (IPsec) child Security Association (SA) lifetime extension.BACKGROUND
[0002] This section introduces aspects that may facilitate a better understanding of the disclosure. Accordingly, the statements of this section are to be read in this light and are not to be understood as admissions about what is in the prior art or what is not in the prior art.
[0003] Internet Protocol Security (IPsec) provides confidentiality, data integrity, access control, and data source authentication to IP datagrams. These services are provided by maintaining shared state between the source and the sink of an IP datagram. This state defines, among other things, the specific services provided to the datagram, which cryptographic algorithms will be used to provide the services, and the keys used as input to the cryptographic algorithms.
[0004] Internet Key Exchange Protocol Version 2 (IKEv2) Request For Comments (RFC) 7296 (Oct 2014) describes version 2 of the Internet Key Exchange (IKE) protocol. IKE is a component of IPsec used for performing mutual authentication and establishing and maintaining Security Associations (SAs) .
[0005] IKE performs mutual authentication between two parties and establishes an IKE SA that includes shared secret information that can be used to efficiently establish SAs for Encapsulating Security Payload (ESP) or Authentication Header (AH) and a set of cryptographic algorithms to be used by the SAs to protect the traffic that they carry. The SAs for ESP or AH that get set up through that IKE SA we call "Child SAs" .
[0006] IKE, ESP, and AH Security Associations use secret keys that should be used only for a limited amount of time and to protect a limited amount of data. This limits the lifetime of the entire Security Association. When the lifetime of a child SA expires, the child SA must not be used. If there is demand, new SA is established, Reestablishment of Security Associations to take the place of ones that expire is referred to as "rekeying" .SUMMARY
[0007] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0008] IPsec child SA rekeying may fail for a variety of reasons, such as routing changes in the forwarding plane, or parameter configuration errors in the child SA, etc., which are unpredictable and unavoidable. IPsec child SA rekeying failure may lead to IPsec child SA expire.
[0009] When the IPsec child SA expires, according to Internet Key Exchange Protocol Version 2 (IKEv2) Request For Comments (RFC) 7296 (Oct 2014) , all traffic encrypted or decrypted by the IPsec child SA must be stopped. However, if the IPsec child SA is deleted immediately, the customer's services will be seriously affected.
[0010] This issue causes service disruption for the customer in terms of the behavior defined by the current standard for the IPsec child SA expiration. For example, many customers use IPsec to protect Operations, Administration and Maintenance (OAM) traffic. If the IPsec child SA is deleted when the IPsec child SA expires, it causes traffic loss and network device lose connection. When a network device loses connection, the remote access to the network device is impossible. It is very costly to solve the problem onsite.
[0011] To overcome or mitigate at least one of above mentioned problems or other problems, the embodiments of the present disclosure propose an improved solution for IPsec child Security Association (SA) lifetime extension.
[0012] In a first aspect of the disclosure, there is provided a method performed by a first network node in Communication Network. The method comprises obtaining a first lifetime and a traffic threshold for a child Security Association (SA) . The method further comprises extending the lifetime of the child SA based on the first lifetime and the traffic threshold when a second lifetime of the child SA expires. The second lifetime is a local lifetime of the child SA created by the first network node. The first lifetime is an extended lifetime for the child SA after the second lifetime of child SA expires.
[0013] In an embodiment, the method further comprises detecting if the first lifetime expires or if the traffic encrypted or decrypted by the child SA exceeds the traffic threshold.
[0014] In an embodiment, when the first lifetime expires or when the traffic encrypted or decrypted by the child SA exceeds the traffic threshold, the method further comprises deleting the child SA.
[0015] In an embodiment, when the first lifetime doesn’ t expire or when the traffic encrypted or decrypted by the child SA doesn’ t exceed the traffic threshold, the method further comprises detecting if there is one or more abnormal packets, and deleting the child SA when there is detected abnormal packet.
[0016] In an embodiment, the method further comprises sending an alarm message to a third network node which comprises a Network Management System (NMS) .
[0017] In an embodiment, the method further comprises sending a child SA rekey message to a second network node.
[0018] In an embodiment, the first network node comprises an IPsec device or an IPsec function.
[0019] In an embodiment, the second network node comprises an IPsec device or an IPsec function.
[0020] In a second aspect of the disclosure, there is provided a first network node. The first network node comprises a processor, and a memory coupled to the processor. Said memory contains instructions executable by said processor. Said second network node is operative to obtain a first lifetime and a traffic threshold for a child Security Association (SA) . The method further comprises extending the lifetime of the child SA based on the first lifetime and the traffic threshold when a second lifetime of the child SA expires. The second lifetime is a local lifetime of the child SA created by the first network node. The first lifetime is an extended lifetime for the child SA after the second lifetime of the child SA expires.
[0021] In a third aspect of the disclosure, there is provided a computer-readable storage medium storing instructions which when executed by at least one processor, cause the at least one processor to perform the method according to any one of the first aspect.
[0022] Embodiments herein may provide many advantages, of which a non-exhaustive list of examples follows. It proposes a solution for IPsec child Security Association (SA) lifetime extension. Through the solution, the life cycle of the child SA is extended to give users more time to process the rekey failure, and avoids traffic loss and device lose connection.
[0023] The embodiments herein are not limited to the features and advantages mentioned above. A person skilled in the art will recognize additional features and advantages upon reading the following detailed description.BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more fully apparent, by way of example, from the following detailed description with reference to the accompanying drawings, in which like reference numerals or letters are used to designate like or equivalent elements. The drawings are illustrated for facilitating better understanding of the embodiments of the disclosure and not necessarily drawn to scale, in which:
[0025] FIG. 1a shows a basic IPsec device communication procedure;
[0026] FIG. 1b shows a flowchart of an IPsec child SA lifetime management procedure based on RFC 7296;
[0027] FIG. 2 shows a network architecture of the proposed solution;
[0028] FIG. 3 shows a flowchart of a method according to an embodiment of the presentdisclosure;
[0029] FIG. 4 shows a flowchart of the proposed solution procedure;
[0030] FIG. 5 shows a block diagram showing an apparatus suitable for practicing some embodiments of the disclosure;
[0031] FIG. 6 shows a block diagram showing a network function according to an embodiment of the disclosure;
[0032] FIG. 7 shows diagram illustrating an example of a communication system in accordance with some embodiments of the disclosure;
[0033] FIG. 8 shows a diagram illustrating a host in accordance with some embodiments of the disclosure;
[0034] FIG. 9 shows a diagram illustrating a host communicating via a network node with a UE over a partially wireless connection in accordance with some embodiments of the disclosure.DETAILED DESCRIPTION
[0035] The embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for the purpose of enabling those skilled persons in the art to better understand and thus implement the present disclosure, rather than suggesting any limitations on the scope of the present disclosure. Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present disclosure should be or are in any single embodiment of the disclosure. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present disclosure. Furthermore, the described features, advantages, and characteristics of the disclosure may be combined in any suitable manner in one or more embodiments. One skilled in the relevant art will recognize that the disclosure may be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the disclosure.
[0036] As used herein, the term “network” refers to a network following any suitable communication standards such as new radio (NR) , long term evolution (LTE) , LTE-Advanced, wideband code division multiple access (WCDMA) , high-speed packet access (HSPA) , Code Division Multiple Access (CDMA) , Time Division Multiple Address (TDMA) , Frequency Division Multiple Access (FDMA) , Orthogonal Frequency-Division Multiple Access (OFDMA) , Single carrier frequency division multiple access (SC-FDMA) and other wireless networks. A CDMA network may implement a radio technology such as Universal Terrestrial Radio Access (UTRA) , etc. UTRA includes WCDMA and other variants of CDMA. A TDMA network may implement a radio technology such as Global System for Mobile Communications (GSM) . An OFDMA network may implement a radio technology such as Evolved UTRA (E-UTRA) , Ultra Mobile Broadband (UMB) , IEEE 802.11 (Wi-Fi) , IEEE 802.16 (WiMAX) , IEEE 802.20, Flash-OFDMA, Ad-hoc network, wireless sensor network, etc. In the following description, the terms “network” and “system” can be used interchangeably. Furthermore, the communications between two devices in the network may be performed according to any suitable communication protocols, including, but not limited to, the communication protocols as defined by a standard organization such as 3GPP. For example, the communication protocols may comprise the first generation (1G) , 2G, 3G, 4G, 4.5G, 5G communication protocols, and / or any other protocols either currently known or to be developed in the future.
[0037] The term “network device” or “network node” refers to any suitable network function (NF) which can be implemented in a network function (physical or virtual) of a communication network. For example, the network function can be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g. on a cloud infrastructure. For example, the 5G system (5GS) may comprise a plurality of NFs such as AMF (Access and mobility Function) , SMF (Session Management Function) , AUSF (Authentication Service Function) , UDM (Unified Data Management) , PCF (Policy Control Function) , AF (Application Function) , NEF (Network Exposure Function) , UPF (User plane Function) and NRF (Network Repository Function) , RAN (radio access network) , SCP (service communication proxy) , NWDAF (network data analytics function) , NSSF (Network Slice Selection Function) , NSSAAF (Network Slice-Specific Authentication and Authorization Function) , etc. For example, the 4G system (such as LTE) may include MME (Mobile Management Entity) , HSS (home subscriber server) , Policy and Charging Rules Function (PCRF) , Packet Data Network Gateway (PGW) , PGW control plane (PGW-C) , Serving gateway (SGW) , SGW control plane (SGW-C) , E-UTRAN Node B (eNB) , etc. In other embodiments, the network node may comprise different types of NFs for example depending on a specific network.
[0038] The term “IPSec” or “IPsec” refers to Internet Protocol Security. The term “IPSec SA” , “child SA” or “IPsec child SA” refers to the secret keys used by ESP and AH Security Associations that used for a limited amount of time and to protect a limited amount of data. The term “terminal device” or “user equipment (UE) ” refers to any end device that can access a communication network and receive services therefrom. By way of example and not limitation, the terminal device refers to a mobile terminal or other suitable devices. The UE may be, for example, a Subscriber Station (SS) , a Portable Subscriber Station, a Mobile Station (MS) , or an Access Terminal (AT) . The terminal device may include, but not limited to, a portable computer, an image capture terminal device such as a digital camera, a gaming terminal device, a music storage and a playback appliance, a mobile phone, a cellular phone, a smart phone, a voice over IP (VoIP) phone, a wireless local loop phone, a tablet, a wearable device, a personal digital assistant (PDA) , a portable computer, a desktop computer, a wearable terminal device, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a Laptop-Embedded Equipment (LEE) , a Laptop-Mounted Equipment (LME) , a Universal Serial Bus (USB) dongle, a smart device, a wireless Customer-Premises Equipment (CPE) and the like. In the following description, the terms “terminal device” , “terminal” , “user equipment” and “UE” may be used interchangeably. As one example, a terminal device may represent a UE configured for communication in accordance with one or more communication standards promulgated by the 3GPP (3rd Generation Partnership Project) , such as 3GPP’ LTE standard or NR standard. As used herein, a “user equipment” or “UE” may not necessarily have a “user” in the sense of a human user who owns and / or operates the relevant device. In some embodiments, a terminal device may be configured to transmit and / or receive information without direct human interaction. For instance, a terminal device may be designed to transmit information to a network on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the communication network. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but that may not initially be associated with a specific human user.
[0039] As yet another example, in an Internet of Things (IoT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another terminal device and / or network equipment. The terminal device may in this case be a machine-to-machine (M2M) device, which may in a 3GPP context be referred to as a machine-type communication (MTC) device. As one particular example, the terminal device may be a UE implementing the 3GPP narrow band internet of things (NB-IoT) standard. Particular examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or home or personal appliances, for example refrigerators, televisions, personal wearables such as watches etc. In other scenarios, a terminal device may represent a vehicle or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0040] References in the specification to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0041] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.
[0042] As used herein, the phrase “at least one of A and B” or “at least one of A or B” should be understood to mean “only A, only B, or both A and B. ” The phrase “Aand / or B” should be understood to mean “only A, only B, or both A and B” .
[0043] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0044] It is noted that these terms as used in this document are used only for ease of description and differentiation among nodes, devices or networks etc. With the development of the technology, other terms with the similar / same meanings may also be used.
[0045] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0046] In communication / computer network, etc., Internet Protocol (IP) Security (IPsec) , provides confidentiality, data integrity, access control, and data source authentication to IP datagrams.
[0047] Fig. 1a is a typical IPsec device communication work flow. In the work flow, there are two IPsec devices, one is IPsec initiator, another one is IPsec responder. The IPsec initiator communicates with the IPsec responder through IKEv2 protocol. After the child SA is create, the IPsec session is established, then the traffic is transferred.
[0048] Communication using IKE always begins with IKE_SA_INIT and IKE_AUTH exchanges (known in IKEv1 as Phase 1) . These initial exchanges normally consist of four messages, though in some scenarios that number can grow. All communications using IKE consist of request / response pairs.
[0049] At Step 1, the IPsec initiator sends IKE_SA_INIT request to IPsec responder.
[0050] At Step 2, IPsec responder sends IKE_SA_INIT response to the IPsec initiator.
[0051] The first pair of messages (IKE_SA_INIT) negotiate cryptographic algorithms, exchange nonces, and do a Diffie-Hellman exchange.
[0052] At step 3, IPsec initiator sends IKE_AUTH request to IPsec responder.
[0053] At step 4, IPsec responder sends IKE_AUTH response to IPsec initiator.
[0054] The second pair of messages (IKE_AUTH) authenticate the previous messages, exchange identities and certificates, and establish the first Child SA. Parts of these messages are encrypted and integrity protected with keys established through the IKE_SA_INIT exchange, so the identities are hidden from eavesdroppers and all fields in all the messages are authenticated.
[0055] At step 5, IPsec initiator sends a CREATE_CHILD_SA request to IPsec responder to create a first child SA.
[0056] At step 6, IPsec responder sends a CREATE_CHILD_SA response to the IPsec initiator to notify the initiator if the first child SA is created successful or not.
[0057] Based on RFC 7296, IKE, ESP, and AH SAs use secret keys. The secret keys used only for a limited amount of time and to protect a limited amount of data. This limits the lifetime of the entire SA. When the lifetime of a child SA expires, the child SA is not allowed to be used. If there is demand, new Security Associations may be established. Reestablishment of Security Associations to take the place of ones that expire is referred to as "rekeying" .
[0058] In IKEv2, each end of the SA is responsible for enforcing its own lifetime policy on the SA and rekeying the SA when necessary. If the two ends have different lifetime policies, the end with the shorter lifetime will end up always being the one to request the rekeying.
[0059] At step 7, when the IPsec initiator’s lifetime of the child SA expires, the IPsec initiator sends a CREATE_CHILD_SA request to the IPsec responder, a rekey indicator is comprised in the CREATE_CHILD_SA request.
[0060] At step 8, the IPsec responder response to the CREATE_CHILD_SA request to confirm if the rekey is successful or not.
[0061] The detailed description of IKE_SA_INIT request and response, CREATE_CHILD_SA request and response are introduced in Internet Key Exchange Protocol Version 2 (IKEv2) Request For Comments (RFC) 7296 (Oct 2014) .
[0062] Fig. 1b is a workflow for an IPsec device to handle the lifetime of a child SA based on RFC 7296. The IPsec device may be an IPsec initiator or an IPsec responder.
[0063] At step 1, the IPsec device sets a local lifetime for child SA.
[0064] At step 2, the IPsec device monitors the local lifetime of child SA.
[0065] At step 3, the IPsec device checks if the local lifetime of the child SA expires. If the local lifetime is not expired, the process goes to step 2. If the local lifetime of the child SA expires, the process goes to step 4.
[0066] At step 4, the IPsec device deletes the child SA.
[0067] IPsec child SA rekeying may fail for a variety of reasons, such as routing changes in the forwarding plane, or parameter configuration errors in the child SA, etc., which are unpredictable and unavoidable. IPsec child SA rekeying failure may lead to IPsec child SA expire.
[0068] When the IPsec child SA expires, according to Internet Key Exchange Protocol Version 2 (IKEv2) Request For Comments (RFC) 7296 (Oct 2014) , all traffic encrypted or decrypted by the IPsec child SA must be stopped. However, if the IPsec SA is deleted immediately, the customer's services will be seriously affected.
[0069] This issue causes service disruption for the customer in terms of the behavior defined by the current standard for the child SA expiration. For example, many customers use IPsec to protect Operations, Administration and Maintenance (OAM) traffic. If the IPsec child SA is disabled when the IPsec child SA expires, it causes traffic loss and network device lose connection. When the network device loses connection, the remote access to the network device is impossible. It is very costly to solve the problem onsite.
[0070] To overcome or mitigate at least one of above mentioned problems or other problems, the embodiments of the present disclosure propose an improved solution for IPsec child Security Association (SA) lifetime extension.
[0071] Based on the extended lifetime of the child SA and the actual traffic encrypted or decrypted by the child SA, the present disclosure extends the life cycle of the child SA to give users more time to process the rekey failure, avoids traffic loss and device lose connection. Further, through detecting abnormal packets, it guarantees the safe use of the child SA during the life cycle extension period.
[0072] In this way, serious situations such as device disconnection are avoided. Users can handle suspicious situations more calmly, and IPsec security is promised.
[0073] In Fig. 2, it shows the network architecture of the present disclosure. There are three network nodes, first network node (10) , second network node (20) , and third network node (30) . The first network node and second network node communicate based on Internet Key Exchange Protocol Version 2 (IKEv2) protocol. But the proposed method is not limit to IKEv2, it may be compatible to further protocols. The first network node is the network node which initiates the IPsec rekey process, and the second network node is the network node which responds to the IPsec rekey process. The first network node may send a request to the second network node to rekey IPsec child SA. The request may be any suitable request. For example, it may be a Create_Child_SA request with a rekey indication “REKEY_SA” in it. The second network node may send a response back to the first network node. The response may be any suitable response. For example, it may be a Create_Child_SA response. The rekey result may be comprised in the response message. If the rekey is failure, the first network node may send alarm message to a third network node. If the rekey is failure, the second network node may also send alarm message to the third network node. The third network node may comprise Network Management System (NMS) in it.
[0074] Fig. 3 shows flowcharts of methods according to an embodiment of the present disclosure, which may be performed by an apparatus implemented in or at or as a first network node (30) , or communicatively coupled to the first network node. As such, the apparatus may provide means or modules for accomplishing various parts of the method 300 as well as means or modules for accomplishing other processes in conjunction with other components.
[0075] The first network node may be a physical entity or a virtualized network function. For example, the network node may be any suitable network device or node or entity or function (physical or virtual) which can provide a function for requesting an IKE session, or responding the requested IKE session. The first network node may support IKEv2. The first network node may communicate with the other network nodes through IKEv2 protocols, such as it may use a first pair of messages IKE_SA_INIT negotiate cryptographic algorithms, exchange nonces, and do a Diffie-Hellman exchange. It may use a second pair of messages IKE_AUTH authenticate the previous messages. It may use a third pair of messages Create_Child_SA to create Child SA.
[0076] In an embodiment, the first network node may comprise an IPsec device or an IPsec function.
[0077] At block 302, the first network node may obtain a first lifetime and a traffic threshold for a child Security Association (SA) .
[0078] The first lifetime is an extended lifetime for the child SA after the second lifetime of child SA expires. The second lifetime is a local lifetime of the child SA created by the first network node.
[0079] The traffic threshold may be used to control the traffic encrypted or decrypted by the child SA after the local lifetime of the child SA expires. Such as, the traffic threshold may be a maximum traffic number processed by the child SA.
[0080] There are many ways to obtain the child SA first lifetime and the traffic threshold. Such as it may be obtained by setting through the human-machine interface, or may be got from a local configuration script, or may be received from other network nodes.
[0081] At block 304, the first network node may extend the lifetime of the child SA based on the first lifetime and the traffic threshold obtained through block 302 when a second lifetime of the child SA expires.
[0082] In RFC 7296, an IPsec device deletes a child SA when the local lifetime of the child SA expires. However, in this disclosure, the first network node may not delete the child SA when the local lifetime of the child SA expires. The first network node may extend the lifetime of the child SA when a second lifetime of the child SA expires, until the traffic encrypted or decrypted by the child SA exceeds the traffic threshold or when the first lifetime expires.
[0083] In an embodiment, the first network node may further detect if the traffic encrypted or decrypted by the child SA exceeds the traffic threshold, or if the first lifetime expires.
[0084] There are many ways to detecting if the traffic encrypted or decrypted by the child SA exceeds the traffic threshold. For example, the first network node may detect the traffic through the packet counters of the child SA.
[0085] There are many ways to detect if the first lifetime of the child SA expires. For example, the first network node may set a timer, or may use a software program to count the time, or may use a computer interrupt to detect if the first lifetime of the child SA expires.
[0086] In an embodiment, when the traffic encrypted or decrypted by the child SA exceeds the traffic threshold or when the first lifetime expires, the first network node may further delete the child SA.
[0087] In an embodiment, when the traffic encrypted or decrypted by the child SA doesn’ t exceed the traffic threshold or when the first lifetime doesn’ t expire, the first network node may further detect if there is one or more abnormal packets, and delete the child SA when there is detected abnormal packet.
[0088] For example, the first network node may use a packet counter to static if there is packet belongs to No SA found packets, late packets, authentication error packets, etc. to detect if any suspicious or abnormal packets are detected.
[0089] In an embodiment, the first network node may further send an alarm message to a third network node. The third network node may comprise a Network Management System (NMS) . In an embodiment, the first network node may further send a child SA rekey message to a second network node.
[0090] In an embodiment, the first network node may comprise an IPsec device or an IPsec function. The second network node may comprise an IPsec device or an IPsec function. The first network node may initiate the IPsec rekey process, and the second network node may respond to the IPsec rekey process.
[0091] In an embodiment, the first network node may be a User Equipment, Router, physical server or virtual server which comprises an IPsec function in it.
[0092] FIG. 4 shows an example of the proposed solution.
[0093] At step 1, a first network node may obtain a first lifetime for a child SA. The first lifetime may also be named as grace lifetime. The first lifetime may be used to extend the local lifetime a child SA based on the first lifetime and the traffic threshold when a second lifetime of the child SA expires. Such as grace lifetime may be a maximum lifetime extends for the child SA. The second lifetime is a local lifetime of the child SA created by the first network node.
[0094] At step 2, the first network node may obtain a traffic threshold for the child SA. The traffic threshold may be used to control the traffic encrypted or decrypted by the child SA after the local lifetime of the child SA expires. Such as, the traffic threshold may be a maximum traffic number processed by the child SA.
[0095] There are many ways to obtain the child SA first lifetime and the traffic threshold. Such as it may be obtained by setting through the human-machine interface, or may be got through a local configuration script, or may be received from other network nodes.
[0096] At step 3, the first network node may monitor the second child SA lifetime. The second lifetime may be a local lifetime created by the first network node. When there is N seconds left for the local child SA lifetime, it may go to step 4, the parameter N may be set by the first network node.
[0097] At step4, the first network node may trigger child SA rekey process. The first network node may send rekey request to the second network node which communicate with it. The request may be any suitable request. For example, it may be a Create_Child_SA request with a rekey indication “REKEY_SA” in it. The second network node may send a response back to the first network node. The response may be any suitable response. For example, it may be a Create_Child_SA response. The rekey result may be comprised in the response message. If the child SA rekey failure, it may go to step 5. If the child SA rekey success, the first network node may receive rekey success response from the second network node, then the first network node may go to step 3, the process may be restarted to monitor the child SA lifetime.
[0098] At step 5, if the local lifetime of the child SA expires, the first network node may go to step 6; if the local lifetime of the child SA doesn’ t expire, it may go to step 3.
[0099] At step 6, the first network node may send alarm information, such as alarm message, alarm report etc., to a third network node. The third network node may comprise a Network Management System (NMS) in it. The first network node may create another thread periodically trigger the child SA rekey event. When the first network node receives child SA rekey success response from the second network node, it may restart a new child SA with a new local lifetime, and may go to step 3 to monitor the child SA lifetime.
[0100] At step 7, the first network node may monitor the child SA counter to count the detailed traffic encrypted or decrypted by the child SA. For example, the first network node may detect the traffic through monitoring the packet counters of the child SA.
[0101] At step 8, if the traffic encrypted or decrypted by the child SA exceeds the traffic threshold or if the first lifetime of the child SA expires, the IPsec device may go to step 10 to delete the child SA. If the encrypted or decrypted traffic processed by the child SA doesn’ t exceed the traffic threshold or the first lifetime of the child SA doesn’ t expire, the IPsec device may go to step 9.
[0102] There are many ways to detect if a first lifetime of the child SA expires. For example, the first network node may set a timer, or may use a software program to count the time, or may use a computer interrupt to detect if the first lifetime of the child SA expires.
[0103] At step 9, the first network node may detect if there is one or more abnormal packets to guarantee the safety during the extension lifetime period. For example, the first network node may use the packet counter to static if there is packet belongs to No SA found packets, late packets, authentication error packets, etc. to detect if there are any suspicious or abnormal packets. If any abnormal packet is detected, it may go to step 10 to delete the child SA. If no abnormal packet detected, it may go to step 7.
[0104] At step 10, the first network node may delete the child SA.
[0105] The above steps may not have a fixed sequence, these steps may be arranged by the network node or network function. The introduction of virtualization technology and network computing technology may improve the usage efficiency of the network resources and the flexibility of the network.
[0106] In the example, the first network node may comprise an IPsec device or an IPsec function. The second network node may comprise an IPsec device or an IPsec function. The first network node may initiate the IPsec rekey process, and the second network node may respond to the IPsec rekey process.
[0107] In above example, the first network node may be a User Equipment, Router, physical server or virtual server which comprises an IPsec function in it.
[0108] According to RFC7296, the present solution does not affect the compatibility with the existing standard, and the peer device (implementing the existing standard behavior) can delete the child SA at any time using the INFORMATION DELETE message, so it is fully compatible with the existing standard.
[0109] Embodiments herein afford many advantages, of which a non-exhaustive list of examples follows.
[0110] It extends the life cycle of the child SA to give users more time to process the abnormal event child SA expiration. Further, through detecting abnormal packets it can guarantee the safe use of the child SA during the life cycle extension period.
[0111] Based on the extended lifetime of the child SA and the actual traffic encrypted or decrypted by the child SA, the present disclosure extends the life cycle of the child SA to give users more time to process the rekey failure, avoids traffic loss and device lose connection. Further, through detecting abnormal packets, it guarantees the safe use of the child SA during the life cycle extension period.
[0112] In this way, serious situations such as device disconnection are avoided. Users can handle suspicious situations more calmly, and IPsec security is promised.
[0113] FIG. 5 is a block diagram showing an apparatus suitable for practicing some embodiments of the disclosure. For example, any one of the network nodes described above may be implemented as or through the apparatus 500.
[0114] The apparatus 500 comprises at least one processor 501, such as a digital processor (DP) , and at least one memory (MEM) 502 coupled to the processor 501. The apparatus 500 may further comprise a transmitter TX and receiver RX 503 coupled to the processor 501. The MEM 502 stores a program (PROG) 504. The PROG 504 may include instructions that, when executed on the associated processor 501, enable the apparatus 500 to operate in accordance with the embodiments of the present disclosure. A combination of the at least one processor 501 and the at least one MEM 502 may form processing means 505 adapted to implement various embodiments of the present disclosure.
[0115] Various embodiments of the present disclosure may be implemented by computer program executable by one or more of the processor 501, software, firmware, hardware or in a combination thereof.
[0116] The MEM 502 may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memories and removable memories, as non-limiting examples.
[0117] The processor 501 may be of any type suitable to the local technical environment, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples.
[0118] In an embodiment where the apparatus is implemented as or at the network node, the memory 502 contains instructions executable by the processor 501, whereby the network node operates according to any of the methods related to the network node as described above.
[0119] In an embodiment where the apparatus is implemented as or at the application node, the memory 502 contains instructions executable by the processor 501, whereby the application node operates according to any of the methods related to the application node as described above.
[0120] FIG. 6 is a block diagram showing a network node according to an embodiment of the disclosure.
[0121] As shown, a first network node 600 comprises an obtain module 601. The obtaining module 601 may be configured to obtain a first lifetime and a traffic threshold for a child Security Association (SA) . The first lifetime is an extended lifetime for the child SA after the second lifetime of child SA expires. The second lifetime is a local lifetime of the child SA created by the first network node.
[0122] In an embodiment, the first network node may further comprise an extending module 602. The extending module 602 may be configured to extend the lifetime of the child SA based on the first lifetime and the traffic threshold obtained by the obtain module 601 when a second lifetime of the child SA expires.
[0123] In an embodiment, the first network node may further comprise a first detecting module 603. The first detecting module 603 may be configured to detect if the traffic encrypted or decrypted by the child SA exceeds the traffic threshold or if the first lifetime expires.
[0124] In an embodiment, the first network node may further comprise a second detecting module 604. The second detecting module 604 may be configured to detect if there is one or more abnormal packets when the traffic encrypted or decrypted by the child SA doesn’ t exceed the traffic threshold or when the first lifetime doesn’ t expire.
[0125] In an embodiment, the first network node may further comprise a deleting module 605. The deleting module 605 may be configured to delete the child SA.
[0126] In an embodiment, the first network node may further comprise a first sending module 606. The first sending module 606 may be configured to send an alarm message to a third network node. The third network node may comprise a Network Management System (NMS) .
[0127] In an embodiment, the first network node may further comprise a second sending module 607. The second sending module 607 may be configured to send a child SA rekey message to a second network node.
[0128] FIG. 7 shows an example of a communication system QQ1000 in accordance with some embodiments.
[0129] In the example, the communication system QQ1000 includes a telecommunication network QQ1002 that includes an access network QQ1004, such as a radio access network (RAN) , a core network QQ1006, which includes one or more core network nodes QQ1008. The access network QQ1004 includes one or more access network nodes, such as network nodes QQ1010a and QQ1010b (one or more of which may be generally referred to as network nodes QQ1010) , or any other similar 3rd Generation Partnership Project (3GPP) access node or non-3GPP access point. The network nodes QQ1010 facilitate direct or indirect connection of user equipment (UE) , such as by connecting UEs QQ1012a, QQ1012b, QQ1012c, and QQ1012d (one or more of which may be generally referred to as UEs QQ1012) to the core network QQ1006 over one or more wireless connections.
[0130] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system QQ1000 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system QQ1000 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.
[0131] The UEs QQ1012 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes QQ1010 and other communication devices. Similarly, the network nodes QQ1010 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs QQ1012 and / or with other network nodes or equipment in the telecommunication network QQ1002 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network QQ1002.
[0132] In the depicted example, the core network QQ1006 connects the network nodes QQ1010 to one or more hosts, such as host QQ1016. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network QQ1006 includes one more core network nodes (e.g., core network node QQ1008) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node QQ1008. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC) , Mobility Management Entity (MME) , Home Subscriber Server (HSS) , Access and Mobility Management Function (AMF) , Session Management Function (SMF) , Authentication Server Function (AUSF) , Subscription Identifier De-concealing function (SIDF) , Unified Data Management (UDM) , Security Edge Protection Proxy (SEPP) , Network Exposure Function (NEF) , and / or a User Plane Function (UPF) , Control Function (PCF) , Unified Data Management (UDM) , etc.
[0133] The host QQ1016 may be under the ownership or control of a service provider other than an operator or provider of the access network QQ1004 and / or the telecommunication network QQ1002, and may be operated by the service provider or on behalf of the service provider. The host QQ1016 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.
[0134] As a whole, the communication system QQ1000 of FIG. 7 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM) ; Universal Mobile Telecommunications System (UMTS) ; Long Term Evolution (LTE) , and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G) ; wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi) ; and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax) , Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards.
[0135] In some examples, the telecommunication network QQ1002 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network QQ1002 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network QQ102. For example, the telecommunications network QQ1002 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive IoT services to yet further UEs.
[0136] In some examples, the first network nodemay run on HOST QQ1016, NETWORK NODE QQ1008, NETWORK NODE QQ1010, and UEs QQ1012.
[0137] In some examples, the second network node may run on HOST QQ1016, NETWORK NODE QQ1008, and NETWORK NODE QQ1010.
[0138] In some examples, the UEs QQ1012 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network QQ1004 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network QQ1004. Additionally, a UE may be configured for operating in single-or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC) , such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio –Dual Connectivity (EN-DC) .
[0139] In the example, the hub QQ1014 communicates with the access network QQ1004 to facilitate indirect communication between one or more UEs (e.g., UE QQ1012c and / or QQ1012d) and network nodes (e.g., network node QQ1010b) . In some examples, the hub QQ1014 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub QQ1014 may be a broadband router enabling access to the core network QQ1006 for the UEs. As another example, the hub QQ1014 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes QQ1010, or by executable code, script, process, or other instructions in the hub QQ1014. As another example, the hub QQ1014 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub QQ1014 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub QQ1014 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub QQ1014 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub QQ1014 acts as a proxy server or orchestrator for the UEs, in particular in if one or more of the UEs are low energy IoT devices.
[0140] The hub QQ1014 may have a constant / persistent or intermittent connection to the network node QQ1010b. The hub QQ1014 may also allow for a different communication scheme and / or schedule between the hub QQ1014 and UEs (e.g., UE QQ1012c and / or QQ1012d) , and between the hub QQ1014 and the core network QQ1006. In other examples, the hub QQ1014 is connected to the core network QQ1006 and / or one or more UEs via a wired connection. Moreover, the hub QQ1014 may be configured to connect to an M2M service provider over the access network QQ1004 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes QQ1010 while still connected via the hub QQ1014 via a wired or wireless connection. In some embodiments, the hub QQ1014 may be a dedicated hub –that is, a hub whose primary function is to route communications to / from the UEs from / to the network node QQ1010b. In other embodiments, the hub QQ1014 may be a non-dedicated hub –that is, a device which is capable of operating to route communications between the UEs and network node QQ1010b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.
[0141] FIG. 8 is a block diagram of a host QQ1100, which may be an embodiment of the host QQ1016 of FIG. 7, in accordance with various aspects described herein. As used herein, the host QQ1100 may be or comprise various combinations hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, container, or processing resources in a server farm. The host QQ1100 may provide one or more services to one or more UEs.
[0142] The host QQ1100 includes processing circuitry QQ1102 that is operatively coupled via a bus QQ1104 to an input / output interface QQ1106, a network interface QQ1108, a power source QQ1110, and a memory QQ1112.
[0143] The memory QQ1112 may include one or more computer programs including one or more host application programs QQ1114 and data QQ1116, which may include user data, e.g., data generated by a UE for the host QQ1100 or data generated by the host QQ1100 for a UE. Embodiments of the host QQ1100 may utilize only a subset or all of the components shown. The host application programs QQ1114 may be implemented in a container-based architecture and may provide support for edge applications, video codecs (e.g., Versatile Video Coding (VVC) , High Efficiency Video Coding (HEVC) , Advanced Video Coding (AVC) , Moving Pictures Experts Group (MPEG) ) and audio codecs (e.g., Free Lossless Audio Codec (FLAC) , Advanced Audio Coding (AAC) , MPEG, G. 711) , including transcoding for multiple different classes, types, or implementations of UEs (e.g., handsets, desktop computers, wearable display systems, heads-up display systems) . The host application programs QQ1114 may also provide for user authentication and licensing checks and may periodically report health, routes, and content availability to a central node, such as a device in or on the edge of a core network. Accordingly, the host QQ1100 may select and / or indicate a different host for over-the-top services for a UE. The host application programs QQ1114 may support various protocols, such as the HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP) , Real-Time Streaming Protocol (RTSP) , Dynamic Adaptive Streaming over HTTP (MPEG-DASH) , etc.
[0144] FIG. 9 shows a communication diagram of a host QQ1202 communicating via a network node QQ1204 with a UE QQ1206 over a partially wireless connection in accordance with some embodiments.
[0145] Like host QQ1100, embodiments of host QQ1202 include hardware, such as a communication interface, processing circuitry, and memory. The host QQ1202 also includes software, which is stored in or accessible by the host QQ1202 and executable by the processing circuitry. The software includes a host application that may be operable to provide a service to a remote user, such as the UE QQ1206 connecting via an over-the-top (OTT) connection QQ1250 extending between the UE QQ1206 and host QQ1202. In providing the service to the remote user, a host application may provide user data which is transmitted using the OTT connection QQ1250.
[0146] The network node QQ1204 includes hardware enabling it to communicate with the host QQ1202 and UE QQ1206. The connection QQ1260 may be direct or pass through a core network (like core network QQ1006 of FIG. 7) and / or one or more other intermediate networks, such as one or more public, private, or hosted networks. For example, an intermediate network may be a backbone network or the Internet.
[0147] The UE QQ1206 includes hardware and software, which is stored in or accessible by UE QQ1206 and executable by the UE’s processing circuitry. The software includes a client application, such as a web browser or operator-specific “app” that may be operable to provide a service to a human or non-human user via UE QQ1206 with the support of the host QQ1202. In the host QQ1202, an executing host application may communicate with the executing client application via the OTT connection QQ1250 terminating at the UE QQ1206 and host QQ1202. In providing the service to the user, the UE's client application may receive request data from the host's host application and provide user data in response to the request data. The OTT connection QQ1250 may transfer both the request data and the user data. The UE's client application may interact with the user to generate the user data that it provides to the host application through the OTT connection QQ1250.
[0148] The OTT connection QQ1250 may extend via a connection QQ1260 between the host QQ1202 and the network node QQ1204 and via a wireless connection QQ1270 between the network node QQ1204 and the UE QQ1206 to provide the connection between the host QQ1202 and the UE QQ1206. The connection QQ1260 and wireless connection QQ1270, over which the OTT connection QQ1250 may be provided, have been drawn abstractly to illustrate the communication between the host QQ1202 and the UE QQ1206 via the network node QQ1204, without explicit reference to any intermediary devices and the precise routing of messages via these devices.
[0149] As an example of transmitting data via the OTT connection QQ1250, in step QQ1208, the host QQ1202 provides user data, which may be performed by executing a host application. In some embodiments, the user data is associated with a particular human user interacting with the UE QQ1206. In other embodiments, the user data is associated with a UE QQ1206 that shares data with the host QQ1202 without explicit human interaction. In step QQ1210, the host QQ1202 initiates a transmission carrying the user data towards the UE QQ1206. The host QQ1202 may initiate the transmission responsive to a request transmitted by the UE QQ1206. The request may be caused by human interaction with the UE QQ1206 or by operation of the client application executing on the UE QQ1206. The transmission may pass via the network node QQ1204, in accordance with the teachings of the embodiments described throughout this disclosure. Accordingly, in step QQ1212, the network node QQ1204 transmits to the UE QQ1206 the user data that was carried in the transmission that the host QQ1202 initiated, in accordance with the teachings of the embodiments described throughout this disclosure. In step QQ1214, the UE QQ1206 receives the user data carried in the transmission, which may be performed by a client application executed on the UE QQ1206 associated with the host application executed by the host QQ1202.
[0150] In some examples, the UE QQ1206 executes a client application which provides user data to the host QQ1202. The user data may be provided in reaction or response to the data received from the host QQ1202. Accordingly, in step QQ1216, the UE QQ1206 may provide user data, which may be performed by executing the client application. In providing the user data, the client application may further consider user input received from the user via an input / output interface of the UE QQ1206. Regardless of the specific manner in which the user data was provided, the UE QQ1206 initiates, in step QQ1218, transmission of the user data towards the host QQ1202 via the network node QQ1204. In step QQ1220, in accordance with the teachings of the embodiments described throughout this disclosure, the network node QQ1204 receives user data from the UE QQ1206 and initiates transmission of the received user data towards the host QQ1202. In step QQ1222, the host QQ1202 receives the user data carried in the transmission initiated by the UE QQ1206.
[0151] One or more of the various embodiments improve the performance of OTT services provided to the UE QQ1206 using the OTT connection QQ1250, in which the wireless connection QQ1270 forms the last segment. More precisely, the teachings of these embodiments some embodiments herein can optimize the current solution. Some embodiments herein can consider two development cases. In some embodiments herein, it proposed a method to distribute the key of application function in case the VPLMN support or not support AKMA service in AKMA roaming scenario. In some embodiments herein, the key of application function is bound with SN ID, which can resist key leakage attack. In some embodiments herein, when the UE moves to another network, the key KAF used in VPLMN can be deleted both in the UE and VPLMN and cannot be used in HPLMN again, which can resist key leakage attack.
[0152] In an example scenario, factory status information may be collected and analyzed by the host QQ1202. As another example, the host QQ1202 may process audio and video data which may have been retrieved from a UE for use in creating maps. As another example, the host QQ1202 may collect and analyze real-time data to assist in controlling vehicle congestion (e.g., controlling traffic lights) . As another example, the host QQ1202 may store surveillance video uploaded by a UE. As another example, the host QQ1202 may store or control access to media content such as video, audio, VR or AR which it can broadcast, multicast or unicast to UEs. As other examples, the host QQ1202 may be used for energy pricing, remote control of non-time critical electrical load to balance power generation needs, location services, presentation services (such as compiling diagrams etc. from data collected from remote devices) , or any other function of collecting, retrieving, storing, analyzing and / or transmitting data.
[0153] In some examples, a measurement procedure may be provided for the purpose of monitoring data rate, latency and other factors on which the one or more embodiments improve. There may further be an optional network functionality for reconfiguring the OTT connection QQ1250 between the host QQ1202 and UE QQ1206, in response to variations in the measurement results. The measurement procedure and / or the network functionality for reconfiguring the OTT connection may be implemented in software and hardware of the host QQ1202 and / or UE QQ1206. In some embodiments, sensors (not shown) may be deployed in or in association with other devices through which the OTT connection QQ1250 passes; the sensors may participate in the measurement procedure by supplying values of the monitored quantities exemplified above, or supplying values of other physical quantities from which software may compute or estimate the monitored quantities. The reconfiguring of the OTT connection QQ1250 may include message format, retransmission settings, preferred routing etc.; the reconfiguring need not directly alter the operation of the network node QQ1204. Such procedures and functionalities may be known and practiced in the art. In certain embodiments, measurements may involve proprietary UE signaling that facilitates measurements of throughput, propagation times, latency and the like, by the host QQ1202. The measurements may be implemented in that software causes messages to be transmitted, in particular empty or ‘dummy’ messages, using the OTT connection QQ1250 while monitoring propagation times, errors, etc.
[0154] Embodiment 1. A host configured to operate in a communication system to provide an over-the-top (OTT) service, the host comprising: processing circuitry configured to provide user data; and a network interface configured to initiate transmission of the user data to a network node in a cellular network for transmission to a user equipment (UE) , the network node having a communication interface and processing circuitry, the processing circuitry of the network node configured to perform the operations related to the wireless device as described above to transmit the user data from the host to the UE.
[0155] Embodiment 2. The host of the previous embodiment, wherein: the processing circuitry of the host is configured to execute a host application that provides the user data; and the UE comprises processing circuitry configured to execute a client application associated with the host application to receive the transmission of user data from the host.
[0156] Embodiment 3. A method implemented in a host configured to operate in a communication system that further includes a network node and a user equipment (UE) , the method comprising: providing user data for the UE; and initiating a transmission carrying the user data to the UE via a cellular network comprising the network node, wherein the network node performs the operations related to the wireless device as described above to transmit the user data from the host to the UE.
[0157] Embodiment 4. The method of the previous embodiment, further comprising, at the network node, transmitting the user data provided by the host for the UE.
[0158] Embodiment 5. The method of any of the previous 2 embodiments, wherein the user data is provided at the host by executing a host application that interacts with a client application executing on the UE, the client application being associated with the host application.
[0159] Embodiment 6. Acommunication system configured to provide an over-the-top service, the communication system comprising: a host comprising: processing circuitry configured to provide user data for a user equipment (UE) , the user data being associated with the over-the-top service; and a network interface configured to initiate transmission of the user data toward a cellular network node for transmission to the UE, the network node having a communication interface and processing circuitry, the processing circuitry of the network node configured to perform the operations related to the wireless device as described above to transmit the user data from the host to the UE.
[0160] Embodiment 7. The communication system of the previous embodiment, further comprising: the network node; and / or the user equipment.
[0161] Embodiment 8. The communication system of the previous 2 embodiments, wherein: the processing circuitry of the host is configured to execute a host application, thereby providing the user data; and the host application is configured to interact with a client application executing on the UE, the client application being associated with the host application.
[0162] Embodiment 9. A host configured to operate in a communication system to provide an over-the-top (OTT) service, the host comprising: processing circuitry configured to initiate receipt of user data; and a network interface configured to receive the user data from a network node in a cellular network, the network node having a communication interface and processing circuitry, the processing circuitry of the network node configured to perform the operations related to the wireless device as described above to receive the user data from the UE for the host.
[0163] Embodiment 10. The host of the previous 2 embodiments, wherein: the processing circuitry of the host is configured to execute a host application, thereby providing the user data; and the host application is configured to interact with a client application executing on the UE, the client application being associated with the host application.
[0164] Embodiment 11. The host of the any of the previous 2 embodiments, wherein the initiating receipt of the user data comprises requesting the user data.
[0165] Embodiment 12. A method implemented by a host configured to operate in a communication system that further includes a network node and a user equipment (UE) , the method comprising: at the host, initiating receipt of user data from the UE, the user data originating from a transmission which the network node has received from the UE, wherein the network node performs the operations related to the wireless device as described above to receive the user data from the UE for the host.
[0166] Embodiment 13. The method of the previous embodiment, further comprising at the network node, transmitting the received user data to the host.
[0167] Embodiment 14. A host configured to operate in a communication system to provide an over-the-top (OTT) service, the host comprising: processing circuitry configured to provide user data; and a network interface configured to initiate transmission of the user data to a cellular network for transmission to a user equipment (UE) , wherein the UE comprises a communication interface and processing circuitry, the communication interface and processing circuitry of the UE being configured to perform the operations related to the wireless device as described above to receive the user data from the host.
[0168] Embodiment 15. The host of the previous embodiment, wherein the cellular network further includes a network node configured to communicate with the UE to transmit the user data to the UE from the host.
[0169] Embodiment 16. The host of the previous 2 embodiments, wherein: the processing circuitry of the host is configured to execute a host application, thereby providing the user data; and the host application is configured to interact with a client application executing on the UE, the client application being associated with the host application.
[0170] Embodiment 17. A method implemented by a host operating in a communication system that further includes a network node and a user equipment (UE) , the method comprising: providing user data for the UE; and initiating a transmission carrying the user data to the UE via a cellular network comprising the network node, wherein the UE performs the operations related to the wireless device as described above to receive the user data from the host.
[0171] Embodiment 18. The method of the previous embodiment, further comprising: at the host, executing a host application associated with a client application executing on the UE to receive the user data from the UE.
[0172] Embodiment 19. The method of the previous embodiment, further comprising: at the host, transmitting input data to the client application executing on the UE, the input data being provided by executing the host application, wherein the user data is provided by the client application in response to the input data from the host application.
[0173] Embodiment 20. A host configured to operate in a communication system to provide an over-the-top (OTT) service, the host comprising: processing circuitry configured to utilize user data; and a network interface configured to receipt of transmission of the user data to a cellular network for transmission to a user equipment (UE) , wherein the UE comprises a communication interface and processing circuitry, the communication interface and processing circuitry of the UE being configured to perform the operations related to the wireless device as described above to transmit the user data to the host.
[0174] Embodiment 21. The host of the previous embodiment, wherein the cellular network further includes a network node configured to communicate with the UE to transmit the user data from the UE to the host.
[0175] Embodiment 22. The host of the previous 2 embodiments, wherein: the processing circuitry of the host is configured to execute a host application, thereby providing the user data; and the host application is configured to interact with a client application executing on the UE, the client application being associated with the host application.
[0176] Embodiment 23. A method implemented by a host configured to operate in a communication system that further includes a network node and a user equipment (UE) , the method comprising: at the host, receiving user data transmitted to the host via the network node by the UE, wherein the UE performs the operations related to the wireless device as described above to transmit the user data to the host.
[0177] Embodiment 24. The method of the previous embodiment, further comprising: at the host, executing a host application associated with a client application executing on the UE to receive the user data from the UE.
[0178] Embodiment 25. The method of the previous embodiments, further comprising: at the host, transmitting input data to the client application executing on the UE, the input data being provided by executing the host application, wherein the user data is provided by the client application in response to the input data from the host application.
[0179] In addition, the present disclosure may also provide a carrier containing the computer program as mentioned above, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium. The computer readable storage medium can be, for example, an optical compact disk or an electronic memory device like a RAM (random access memory) , a ROM (read only memory) , Flash memory, magnetic tape, CD-ROM, DVD, Blue-ray disc and the like.
[0180] The techniques described herein may be implemented by various means so that an apparatus implementing one or more functions of a corresponding apparatus described with an embodiment comprises not only prior art means, but also means for implementing the one or more functions of the corresponding apparatus described with the embodiment and it may comprise separate means for each separate function, or means that may be configured to perform two or more functions. For example, these techniques may be implemented in hardware (one or more apparatuses) , firmware (one or more apparatuses) , software (one or more modules) , or combinations thereof. For a firmware or software, implementation may be made through modules (e.g., procedures, functions, and so on) that perform the functions described herein.
[0181] Exemplary embodiments herein have been described above with reference to block diagrams and flowchart illustrations of methods and apparatuses. It will be understood that each block of the block diagrams and flowchart illustrations, and combinations of blocks in the block diagrams and flowchart illustrations, respectively, can be implemented by various means including computer program instructions. These computer program instructions may be loaded onto a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions which execute on the computer or other programmable data processing apparatus create means for implementing the functions specified in the flowchart block or blocks.
[0182] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the subject matter described herein, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0183] While this specification contains many specific implementation details, these should not be construed as limitations on the scope of any implementation or of what may be claimed, but rather as descriptions of features that may be specific to particular embodiments of particular implementations. Certain features that are described in this specification in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a sub-combination or variation of a sub-combination.
[0184] It will be obvious to a person skilled in the art that, as the technology advances, the inventive concept can be implemented in various ways. The above described embodiments are given for describing rather than limiting the disclosure, and it is to be understood that modifications and variations may be resorted to without departing from the spirit and scope of the disclosure as those skilled in the art readily understand. Such modifications and variations are considered to be within the scope of the disclosure and the appended claims. The protection scope of the disclosure is defined by the accompanying claims.
Claims
1.A method (300) performed by a first network node (10) in Communication Network, comprising:obtaining (302) a first lifetime and a traffic threshold for a child Security Association (SA) ; andextending (304) the lifetime of the child SA based on the first lifetime and the traffic threshold when a second lifetime of the child SA expires;wherein the second lifetime is a local lifetime of the child SA created by the first network node;wherein the first lifetime is an extended lifetime for the child SA after the second lifetime of the child SA expires.2.The method according to claim 1, further comprising:detecting if the traffic encrypted or decrypted by the child SA exceeds the traffic threshold, or if the first lifetime expires.3.The method according to claim 2, when the first lifetime expires or the traffic encrypted or decrypted by the child SA exceeds the traffic threshold, further comprising:deleting the child SA.4.The method according to claims 2, when the first lifetime expires does not expire or the traffic encrypted or decrypted by the child SA does not exceed the traffic threshold, further comprising:detecting if there is one or more abnormal packets; anddeleting the child SA when there is detected abnormal packet.5.The method according to claim 1, further comprising:sending an alarm message to a third network node (30) ;wherein the third network node comprises a Network Management System (NMS) .6.The method according to claims 1or 5, further comprising:sending a child SA rekey message to a second network node (20) .7.The method according to any of claims 1-6, wherein the first network node comprises an Internet Protocol Security (IPsec) device or an IPsec function; andwherein the second network node comprises an IPsec device or an IPsec function.8.A first network node (500) , comprising:a processor (501) ; anda memory (502) coupled to the processor (501) , said memory (502) containing instructions executable by said processor (501) , whereby the first network node (500) is operative to:obtain a first lifetime and a traffic threshold for a child Security Association (SA) ; andextend the lifetime of the child SA based on the first lifetime and the traffic threshold when a second lifetime of the child SA expires;wherein the second lifetime is a local lifetime of the child SA created by the first network node;wherein the first lifetime is an extended lifetime for the child SA after the second lifetime of the child SA expires.9.The first network node according to claim 8, wherein the first network node is further operative to perform the method of any of claims 2 to 7.10.A computer-readable storage medium storing instructions which when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Methods and apparatuses for dynamic management of security associations in a wireless network
CN101971596A
Wireless device and method for rekeying with reduced packet loss for high-throughput wireless communications
CN102104870A
Rekeying security association SA
CN113169959A
Prioritized rekeying of security associations
WO2023060425A1