Secure store and forward non-terrestrial network communication

A provisional registration and authentication process for non-terrestrial networks enables secure small data transmission by deriving provisional NAS keys, addressing inefficiencies in existing systems and improving connectivity in intermittent conditions.

WO2025150020A1PCT designated stage Publication Date: 2025-07-17LENOVO (SINGAPORE) PTE LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/052139
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-28
Filing Date
2025-02-27
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in securely transmitting small data via non-terrestrial networks due to intermittent connectivity and the need for full registration and authentication procedures, which can result in time-outs and inefficiencies.

Method used

A provisional one-round-trip registration and authentication process is implemented using a store and forward access network, allowing UEs to derive provisional NAS security keys without a full NAS SMC procedure, enabling secure transmission of small data.

Benefits of technology

This approach enhances data security and system efficiency by allowing protected data transmission even in scenarios where full network registration is not available, reducing the need for multiple round trips and time-sensitive procedures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025052139_17072025_PF_FP_ABST
    Figure IB2025052139_17072025_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to secure store and forward non-terrestrial network communication. An apparatus, such as a user equipment (UE), transmits a registration request message to request a registration, the registration request message including an indication that the registration is via a store and forward (SF) access network. The UE receives a registration accept response message including an indication that a registration is provisional and a first authentication token, and computes a first authentication result based at least in part on the first authentication token. The UE can derive, based at least in part on information in the first authentication token, a first security context including one or more first provisional non access stratum (NAS) security keys. The security context can be used to securely transmit data such as via the SF access network.
Need to check novelty before this filing date? Find Prior Art

Description

SECURE STORE AND FORWARD NON-TERRESTRIAL NETWORK COMMUNICATIONRELATED APPLICATION

[0001] This application claims priority to U.S. Provisional Application Serial No. 63 / 558,899, filed 28 February 2024 entitled “Secure Store and Forward Non-Terrestrial Network Communication,” the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD

[0002] The present disclosure relates to wireless communications, and more specifically to non-terrestrial network (NTN) communication.BACKGROUND

[0003] A wireless communications system may include one or multiple network communication devices, which may be otherwise known as network equipment (NE), supporting wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like)). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY

[0004] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or“one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on”. Further, as used herein, including in the claims, a “set” may include one or more elements.

[0005] A UE for wireless communication is described. The UE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the UE may be configured to, capable of, or operable to transmit a registration request message to request a registration, the registration request message including an indication that the registration is via a store and forward (SF) access network; receive a registration accept response message including an indication that a registration is provisional and a first authentication token; compute a first authentication result based at least in part on the first authentication token; and derive, based at least in part on information in the first authentication token, a first security context including one or more first provisional Non Access Stratum (NAS) security keys.

[0006] A processor (e.g., a standalone processor chipset, or a component of a UE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to transmit a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; receive a registration accept response message including an indication that a registration is provisional and a first authentication token; compute a first authentication result based at least in part on the first authentication token; and derive, based at least in part on information in the first authentication token, a first security context including one or more first provisional NAS security keys.

[0007] A method performed or performable by a UE for wireless communication is described. The method may include transmitting a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network;receiving a registration accept response message including an indication that a registration is provisional and a first authentication token; computing a first authentication result based at least in part on the first authentication token; and deriving, based at least in part on information in the first authentication token, a first security context including one or more first provisional NAS security keys.

[0008] In some implementations of the UE, the processor, and the method described herein, the SF access network includes one or more satellites.

[0009] In some implementations of the UE, the processor, and the method described herein, registration accept response message is unprotected.

[0010] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit the registration request message to a first network function at a first NE, and receive the registration accept response message from a second network function at a second NE.

[0011] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to derive the first security context based at least in part on a preconfigured configuration.

[0012] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to derive the first security context without performing a NAS security mode command (SMC) procedure.

[0013] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and the first authentication result; receive a protected NAS response message including an acknowledgement for the data and a second authentication token; unprotect the NAS response message using the first provisional NAS security keys; compute a second authentication result based at least in part on the secondauthentication token; and derive, based at least in part on information in the second authentication token, a second security context including second provisional NAS security keys.

[0014] In some implementations of the UE, the processor, and the method described herein, the first authentication result and the data are protected via NAS security.

[0015] In some implementations of the UE, the processor, and the method described herein, the data includes small data.

[0016] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit the NAS request message to a first network function at a first NE, and receive the protected NAS response message from a second network function at a second NE.

[0017] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to derive the second security context based at least in part on a preconfigured configuration.

[0018] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to derive the second security context without performing a NAS SMC procedure.

[0019] In some implementations of the UE, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to delete the first security context including the one or more first provisional NAS security keys.

[0020] An NE (e.g., a base station) for wireless communication is described. The NE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the NE may be configured to, capable of, or operable to receive, from a UE and at a first network function at the NE, a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; transmit a registration accept response message including an indication that the registration is provisional and a first authentication token, and derive one or more provisional NAS security keys from the firstauthentication token; receive a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and an authentication result generated via the first authentication token; and transmit, to the UE, a protected NAS response message including an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

[0021] A processor (e.g., a standalone processor chipset, or a component of a NE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to receive, from a UE and at a first network function at the NE, a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; transmit a registration accept response message including an indication that the registration is provisional and a first authentication token, and derive one or more provisional NAS security keys from the first authentication token; receive a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and an authentication result generated via the first authentication token; and transmit, to the UE, a protected NAS response message including an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

[0022] A method performed or performable by an NE (e.g., a base station) for wireless communication is described. The method may include receiving, from a UE and at a first network function at the NE, a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; transmitting a registration accept response message including an indication that the registration is provisional and a first authentication token, and derive one or more provisional NAS security keys from the first authentication token; receiving a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and an authentication result generated via the first authentication token; and transmitting, to the UE, a protected NAS response message including an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

[0023] In some implementations of the NE, the processor, and the method described herein, the network function includes an access and mobility management function (AMF).

[0024] In some implementations of the NE, the processor, and the method described herein, the SF access network includes one or more satellites.

[0025] In some implementations of the NE, the processor, and the method described herein, the data includes small data.

[0026] In some implementations of the NE, the processor, and the method described herein, the NE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to derive the one or more provisional NAS keys without performing a NAS SMC procedure.

[0027] In some implementations of the NE, the processor, and the method described herein, the NE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit, to a second network function, an authentication request message for the UE including the indication that the registration is via the SF access network; and receive, from the second network function, an authentication response message including the first authentication token.

[0028] In some implementations of the NE, the processor, and the method described herein, the NE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit, to a second network function, an authentication request message for the UE including the authentication result; and receive, from the second network function, an authentication response message including the second authentication token.BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.

[0030] Figure 2 illustrates an example of SF satellite operation mode, in accordance with aspects of the present disclosure.

[0031] Figure 3a and Figure 3b illustrate different aspects of an example of a signaling diagram for a provisional registration procedure in accordance with aspects of the present disclosure.

[0032] Figure 4a and Figure 4b illustrate different aspects of an example of a signaling diagram for a protected small data transmission procedure in accordance with aspects of the present disclosure.

[0033] Figure 5 illustrates an example of a UE in accordance with aspects of the present disclosure.

[0034] Figure 6 illustrates an example of a processor in accordance with aspects of the present disclosure.

[0035] Figure 7 illustrates an example of a NE in accordance with aspects of the present disclosure.

[0036] Figure 8 illustrates a flowchart of a method in accordance with aspects of the present disclosure.

[0037] Figure 9 illustrates a flowchart of a method in accordance with aspects of the present disclosure.

[0038] Figure 10 illustrates a flowchart of a method in accordance with aspects of the present disclosure.DETAILED DESCRIPTION

[0039] A wireless communications system may support wireless communications for one or more wireless devices, such as UEs, satellites, and / or other NEs, among other devices, that transmit and / or receive signaling. A wireless communication scenario may include UE to satellite communication, with SF communication to the 5G core network (5GC) and to an application server (AS) and / or application function (AF). The availability and stability of the communication link between the UE and the 5GC may raise the issue of the feeder link being intermittently unavailable. Another issue may include assuming that the registration procedure may not be executed. For example, the UE may determine partial availability and use the SF mechanism to send small data. Thus, a consideration is how the UE can send a protected message including small data tofunctionality of the 5GC via the SF link between one or more satellites without a successful registration and / or without running a full registration and authentication procedure. Currently the registration authentication and key agreement procedure may involve several round trips, which may fail due to time outs because of the unavailability to the connections.

[0040] Accordingly, aspects of the present disclosure include techniques for enabling a UE and a 5GC to perform, via a SF access network, a provisional one -round-trip procedure for a provisional registration. For instance, the UE is not fully registered at this point in time and thus may not be eligible to receive terminating data or establish a PDU session. In implementations, for example, a normal 5GC registration procedure is not able to be performed due to time outs of the different registration protocols. Thus, the UE and the network may generate a provisional NAS key for the NAS signalling, and the UE and satellite may use also a provisional NAS key for the Radio Resource Control (RRC) signalling. The UE can receive a token from the 5GC to compute a result from a challenge to authenticate itself when the UE subsequently sends the small data in a NAS message, which may be protected by a provisional NAS key. In implementations the provisional NAS key can be derived without an NAS SMC procedure such as to save one round trip of messages. The network may assign a new token in the acknowledgement of the NAS message for the next time usage.

[0041] Thus, in implementations a provisional security context including NAS keys (e.g., without NAS SMC procedure) and provisional registration can be achieved within one round trip and optionally extended NAS timers to avoid timeouts. A UE achieve authentication when sending the protected small data with the provisional security context. For each NAS transmission, the UE can have an updated security context and can get re-authenticated every time.

[0042] In this way, the small data is protected via the SF network (e.g., depending on the validity time of the token) and the process may be less time sensitive such that a procedure may not need to be carried out within a specific time window. In at least some implementations the described solutions can be split into two parts, the provisional registration procedure and the small data transmission within a NAS message, including the authentication response token.

[0043] By performing implementing the described techniques, UE can be enabled to send protected data in scenarios where full network registration may not be available, thus increasing data security and system efficiency.

[0044] Aspects of the present disclosure are described in the context of a wireless communications system.

[0045] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.

[0046] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a nextgeneration NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.

[0047] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 anda UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.

[0048] The one or more UEs 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of- Everything (loE) device, or machine-type communication (MTC) device, among other examples.

[0049] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0050] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N6, or other network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other indirectly (e.g., via the CN 106). In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).

[0051] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.

[0052] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N6, or other network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).

[0053] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0054] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A firstnumerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.

[0055] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0056] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, jU=l , / r=2, / r=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., Orthogonal Frequency Division Multiplexing (OFDM) symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understoodthat reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0057] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0058] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.

[0059] According to implementations, one or more of the NEs 102 and the UEs 104 are operable to implement various aspects of the techniques described with reference to the present disclosure. For example, a UE 104 and different NEs 102 (e.g., satellites, network functions, CN, etc.) can interact to provide the UE 104 with a provisional registration that the UE 104 can utilize to securely transmit small data, such as detailed throughout this disclosure.

[0060] Figure 2 illustrates an example of SF satellite operation mode 200, in accordance with aspects of the present disclosure. In one or more implementations, the SF satellite operation in a wireless communications system with satellite access provides a communication service for UEsunder satellite coverage with intermittent or temporary satellite connectivity (e.g. when the satellite is not connected via a feeder link or via inter satellite links (ISL) to the ground network) for a delay- tolerant communication service. In this example of SF satellite operation mode 200, the end-to-end exchange of signaling and / or data traffic can be handled as a combination of two steps, indicated as step A and step B, not concurrent in time.

[0061] For example, at step A 202, a signaling and / or data exchange between UE 104 and a satellite 204 takes place, without the satellite being simultaneously connected to the ground network (i.e. the satellite 204 operates the service link without an active feeder link connection). At step B 206, connectivity between a satellite 208 and the ground network 210 is established so that communication between the satellite and the ground network can take place. So, the satellite moves from being connected to the UE 104 in step A to being connected to the ground network 210 in step B. The concept of SF (also referred to as S&F) service is used in communicate scenarios for delay-tolerant networking and disruption-tolerant networking. In a 3 GPP context, a similar service is short message service (SMS), for which there is no need to have an end-to-end connectivity between the endpoints (e.g. an endpoint can be a UE and the other an application server) but only between the endpoints a message service center that operates as an intermediate node for storing and relaying data.

[0062] Aspects of the present disclosure include techniques for enabling a UE and a 5GC to perform, via a SF access network, a provisional one-round-trip procedure for a provisional registration which can enable the UE to send data (e.g., small data) in a protected way. In at least some implementations the described solutions can be split into two parts, the provisional registration procedure and the small data transmission within a NAS message, including the authentication response token.

[0063] Figure 3a and Figure 3b illustrate different aspects of an example of a signaling diagram 300 for a provisional registration procedure in accordance with aspects of the present disclosure. The example signaling diagram 300 includes a UE 104, a first satellite 302 (e.g., satellite A), a second satellite 304 (e.g., satellite B), an AMF 306, an Authentication Server Function (AUSF) 308, and a Unified Data Management (UDM) 310. While the signaling diagram 300 is discussed with reference to the AMF 306, the AMF 306 may additionally or alternatively be implemented as a SEcurity Anchor Function (SEAF). The example signaling diagram 300 alsoincludes several communication links, such as a service link 312 between the UE 104 and the first satellite 302; a SF link 314 between the first satellite 302 and the second satellite 304; a feeder link control plane 316 between the second satellite 304 and the AMF 306; and a feeder link user plane 318 between the second satellite 304 and the AUSF 308.

[0064] In one or more implementations, the UE 104 (at step 1) sends a NAS Registration Request to the SF satellite network. The UE 104 includes an indication for the AMF 306 that the registration is via SF and not a normal registration procedure. The NAS timer for the Registration message is longer than usual for normal registrations to ensure the timer does not expire until the response message it received later. The satellite 302 (at step 2) forwards the NAS message to one or more satellites with SF functionality (e.g., until a link becomes available) and the satellite 304 (at step 3) forwards the NAS message to the AMF 306. The AMF 306 (at step 4) sends an Nausf_UEAuthentication_Authenticate Request message to the AUSF 308 including the indication that the registration is via SF network. The AUSF 308 (at step 5) sends the Nudm_UEAuthentication_Get Request to the UDM 310 including the indication that the registration is via SF network.

[0065] The UDM 310 (at step 6) selects the authentication mode and creates an authentication token for the UE 104. The authentication token, for instance, may be the form of the authentication challenge of EAP-AKA’ (Extensible Authentication Protocol, Authentication and Key Agreement), 5G-AKA, or any other token that can be computed by the UE 104 to produce an expected result in a similar way as in the UDM 310. The UDM 310 derives the key KAUSF based on the selected authentication token and computes an expected authentication result. The UDM 310 (at step 7) sends an Nudm_UEAuthentication_Get Response to the AUSF 308, including the authentication token and the authentication result. The AUSF 308 (at step 8) marks the UE 104 as provisional authentication based on the indication that the registration is via SF network and the authentication token. The AUSF derives the SEAF from the KAUSF.

[0066] Proceeding to the discussion of the signaling diagram 300 at Figure 3b, the AUSF 308 (at step 9) sends a Nausf_UEAuthentication_Authenticate Response to the AMF 306 including the authentication token. The AMF 306 (at step 10) derives the KAMF and the provisional NAS keys, such as without performing a NAS SMC procedure. The default algorithms for integrity and confidentiality maybe preconfigured in the AMF 306 and the UE 104. The UE 104 is marked in theAMF 306 as provisional registered. The UE 104, for instance, can send small data in protected NAS messages but cannot receive terminating services since the UE 104 does not have a PDU Session and would not get paged by the AMF 306. The AMF 306 (at step 11) sends a Registration Accept to the UE 104 via the SF satellite including an indication that the registration is provisional and the authentication token. The satellite 304 (at step 12) forwards the Registration Accept to the UE 104 via the SF satellite including an indication that the registration is provisional and the authentication token. The serving satellite 302 (at step 13) sends a Registration Accept to the UE 104 including an indication that the registration is provisional and the authentication token. The UE 104 (at step 14) computes the authentication result from the authentication token. The UE 104, for instance, computes the keys in the same way as the 5GC including the provisional NAS keys with the same default configuration. The NAS keys are then used to protect the NAS message sent via the SF links including the embedded small data.

[0067] Figure 4a and Figure 4b illustrate different aspects of an example of a signaling diagram 400 for a protected small data transmission procedure in accordance with aspects of the present disclosure. The procedure depicted in the signaling diagram 400, for instance, occurs after the procedure depicted in the signaling diagram 300. The example signaling diagram 300 includes various apparatus, entities, and communication links such as introduced in the signaling diagram 300.

[0068] In one or more implementations, the UE 104 (at step 1) sends a NAS Request to the SF satellite network. The UE 104 includes the authentication result, computed from the authentication token, and small data. The NAS message is protected with the provisional NAS keys. The NAS timer for the Registration message can be longer than usual for normal registrations to ensure the timer does not expire until the response message it received later. The satellite 302 (at step 2) forwards the NAS message to one or more satellites with SFs functionality until a link becomes available. The satellite 304 (at step 3) forwards the NAS message to the AMF 306. The AMF 306 (at step 4) sends an Nausf_UEAuthentication_Authenticate Request message to the AUSF 308 including the authentication result. The AUSF 308 (at step 5) verifies the received authentication result with the one received from the UDM 310 in the provisional registration procedure. If the verification is successful, the AUSF 308 maintains the UE 104 as provisional authenticated and requests a fresh authentication token from the UDM 310.

[0069] The AUSF 308 (at step 6) sends the Nudm_UEAuthentication_Get Request to the UDM 310 including the indication that the registration is via SF network to request a new authentication token. The AUSF 308 may include the verification result. The UDM 310 (at step 7) selects the authentication mode and creates a new authentication token for the UE 104. The authentication token, for instance, may be the form of the authentication challenge of EAP-AKA’, 5G-AKA, or any other token that can be computed by the UE 104 to produce an expected result in a similar way as in the UDM 310. The UDM 310 derives the new key KAUSF based on the selected authentication token and computes an expected authentication result. The UDM 310 (at step 8) sends an Nudm_UEAuthentication_Get Response to the AUSF 308, including the new authentication token and the new authentication result. The AUSF 308 (at step 9) maintains the UE 104 marked as provisional authentication based on the indication that the registration is via SF network and the new authentication token. The AUSF 308 derives the new KSEAF from the KAUSF.

[0070] Proceeding to the discussion of the signaling diagram 400 at Figure 4b, the AUSF 308 (at step 10) sends a Nausf_UEAuthentication_Authenticate Response to the AMF 306 including the new authentication token and the verification result. The AMF 306 (at step 11) forwards the small data to the respective network function if the verification result is successful. The AMF 306 derives the new KAMF and the new provisional NAS keys, such as without performing a NAS SMC procedure. The default algorithms for integrity and confidentiality maybe preconfigured in the AMF 306 and UE 104. The UE 104 is marked in the AMF 306 as provisional registered. For instance, the UE 104 can send small data in the protected NAS messages but cannot receive any terminating services since it does not have a PDU Session and would not get paged by the AMF 306. The AMF 306 (at step 12) sends a NAS Response message to the UE 104 protected with the old provisional NAS keys via the SF satellite including an acknowledgement for the small data and the new authentication token. The AMF 306 may delete the old NAS keys after the protection of this message, also considering the NAS retransmission timers.

[0071] The satellite 304 (at step 13) forwards the NAS Response message to the UE 104 via the SF satellite including an acknowledgement for the small data and the new authentication token. The serving satellite 302 (at step 14) sends a NAS Response message to the UE 104 including an acknowledgement for the small data and the new authentication token. The UE 104 (at step 15) computes the new authentication result from the new authentication token. The UE 104 computesthe new keys, such as in the same way as the 5GC including the provisional NAS keys with the same default configuration. The new NAS keys can then be used to protect the next NAS message sent via the SF links including the embedded small data. The UE 104 may delete the old NAS keys after the successful reception of the NAS Response message.

[0072] Figure 5 illustrates an example of a UE 500 in accordance with aspects of the present disclosure. The UE 500 may include a processor 502, a memory 504, a controller 506, and a transceiver 508. The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0073] The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0074] The processor 502 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 502 may be configured to operate the memory 504. In some other implementations, the memory 504 may be integrated into the processor 502. The processor 502 may be configured to execute computer-readable instructions stored in the memory 504 to cause the UE 500 to perform various functions of the present disclosure.

[0075] The memory 504 may include volatile or non-volatile memory. The memory 504 may store computer-readable, computer-executable code including instructions when executed by the processor 502 cause the UE 500 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 504 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program fromone place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0076] In some implementations, the processor 502 and the memory 504 coupled with the processor 502 may be configured to cause the UE 500 to perform one or more of the functions described herein (e.g., executing, by the processor 502, instructions stored in the memory 504). For example, the processor 502 may support wireless communication at the UE 500 in accordance with examples as disclosed herein. The UE 500 may be configured to or operable to support a means for transmitting a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; receiving a registration accept response message including an indication that a registration is provisional and a first authentication token; computing a first authentication result based at least in part on the first authentication token; and deriving, based at least in part on information in the first authentication token, a first security context including one or more first provisional NAS security keys.

[0077] Additionally, the UE 500 may be configured to support any one or combination of where the SF access network includes one or more satellites; registration accept response message is unprotected; transmitting the registration request message to a first network function at a first NE, and receiving the registration accept response message from a second network function at a second NE; deriving the first security context based at least in part on a preconfigured configuration; deriving the first security context without performing a NAS SMC procedure; transmitting a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and the first authentication result; receiving a protected NAS response message including an acknowledgement for the data and a second authentication token; unprotecting the NAS response message using the first provisional NAS security keys; computing a second authentication result based at least in part on the second authentication token; and deriving, based at least in part on information in the second authentication token, a second security context including second provisional NAS security keys; the first authentication result and the data are protected via NAS security; the data includes small data; transmitting the NAS request message to a first network function at a first NE, and receiving the protected NAS response message from a second network function at a second NE; deriving the second security context based at least in part on a preconfigured configuration; deriving the second security context without performing a NASSMC procedure; deleting the first security context including the one or more first provisional NAS security keys.

[0078] Additionally, or alternatively, the UE 500 may support at least one memory (e.g., the memory 504) and at least one processor (e.g., the processor 502) coupled with the at least one memory and configured to cause the UE to transmit a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; receive a registration accept response message including an indication that a registration is provisional and a first authentication token; compute a first authentication result based at least in part on the first authentication token; and derive, based at least in part on information in the first authentication token, a first security context including one or more first provisional NAS security keys.

[0079] Additionally, the UE 500 may be configured to support any one or combination of where the SF access network includes one or more satellites; registration accept response message is unprotected; the at least one processor is configured to cause the UE to transmit the registration request message to a first network function at a first NE, and receive the registration accept response message from a second network function at a second NE; the at least one processor is configured to cause the UE to derive the first security context based at least in part on a preconfigured configuration; the at least one processor is configured to cause the UE to derive the first security context without performing a NAS SMC procedure; the at least one processor is configured to cause the UE to: transmit a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and the first authentication result; receive a protected NAS response message including an acknowledgement for the data and a second authentication token; unprotect the NAS response message using the first provisional NAS security keys; compute a second authentication result based at least in part on the second authentication token; and derive, based at least in part on information in the second authentication token, a second security context including second provisional NAS security keys.

[0080] Additionally, the UE 500 may be configured to support any one or combination of where the first authentication result and the data are protected via NAS security; the data includes small data; the at least one processor is configured to cause the UE to transmit the NAS request message to a first network function at a first NE, and receive the protected NAS response message from asecond network function at a second NE; the at least one processor is configured to cause the UE to derive the second security context based at least in part on a preconfigured configuration; the at least one processor is configured to cause the UE to derive the second security context without performing a NAS SMC procedure; the at least one processor is configured to cause the UE to delete the first security context including the one or more first provisional NAS security keys.

[0081] The controller 506 may manage input and output signals for the UE 500. The controller 506 may also manage peripherals not integrated into the UE 500. In some implementations, the controller 506 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 506 may be implemented as part of the processor 502.

[0082] In some implementations, the UE 500 may include at least one transceiver 508. In some other implementations, the UE 500 may have more than one transceiver 508. The transceiver 508 may represent a wireless transceiver. The transceiver 508 may include one or more receiver chains 510, one or more transmitter chains 512, or a combination thereof.

[0083] A receiver chain 510 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 510 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 510 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 510 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 510 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0084] A transmitter chain 512 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 512 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 512 may also include at least one power amplifier configured to amplify the modulated signal to an appropriatepower level suitable for transmission over the wireless medium. The transmitter chain 512 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0085] Figure 6 illustrates an example of a processor 600 in accordance with aspects of the present disclosure. The processor 600 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 600 may include a controller 602 configured to perform various operations in accordance with examples as described herein. The processor 600 may optionally include at least one memory 604, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 600 may optionally include one or more arithmetic-logic units (ALUs) 606. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).

[0086] The processor 600 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 600) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).

[0087] The controller 602 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 600 to cause the processor 600 to support various operations in accordance with examples as described herein. For example, the controller 602 may operate as a control unit of the processor 600, generating control signals that manage the operation of various components of the processor 600. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.

[0088] The controller 602 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 604 and determine subsequent instruction(s) to be executed to cause the processor 600 to support various operations in accordance with examples as described herein. The controller 602 may be configured to track memory addresses of instructions associated with the memory 604. The controller 602 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 602 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 600 to cause the processor 600 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 602 may be configured to manage flow of data within the processor 600. The controller 602 may be configured to control transfer of data between registers, ALUs 606, and other functional units of the processor 600.

[0089] The memory 604 may include one or more caches (e.g., memory local to or included in the processor 600 or other memory, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 604 may reside within or on a processor chipset (e.g., local to the processor 600). In some other implementations, the memory 604 may reside external to the processor chipset (e.g., remote to the processor 600).

[0090] The memory 604 may store computer-readable, computer-executable code including instructions that, when executed by the processor 600, cause the processor 600 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 602 and / or the processor 600 may be configured to execute computer-readable instructions stored in the memory 604 to cause the processor 600 to perform various functions. For example, the processor 600 and / or the controller 602 may be coupled with or to the memory 604, the processor 600, and the controller 602, and may be configured to perform various functions described herein. In some examples, the processor 600 may include multiple processors and the memory 604 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.

[0091] The one or more ALUs 606 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 606 may reside within or on a processor chipset (e.g., the processor 600). In some otherimplementations, the one or more ALUs 606 may reside external to the processor chipset (e.g., the processor 600). One or more ALUs 606 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 606 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 606 may be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 606 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 606 to handle conditional operations, comparisons, and bitwise operations.

[0092] The processor 600 may support wireless communication in accordance with examples as disclosed herein. The processor 600 may be configured to or operable to support at least one controller (e.g., the controller 602) coupled with at least one memory (e.g., the memory 604) and configured to cause the processor to transmit a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; receive a registration accept response message including an indication that a registration is provisional and a first authentication token; compute a first authentication result based at least in part on the first authentication token; and derive, based at least in part on information in the first authentication token, a first security context including one or more first provisional NAS security keys.

[0093] Additionally, the processor 600 may be configured to or operable to support any one or combination of where the SF access network includes one or more satellites; registration accept response message is unprotected; the at least one controller is configured to cause the processor to transmit the registration request message to a first network function at a first NE, and receive the registration accept response message from a second network function at a second NE; the at least one controller is configured to cause the processor to derive the first security context based at least in part on a preconfigured configuration; the at least one controller is configured to cause the processor to derive the first security context without performing a NAS SMC procedure; the at least one controller is configured to cause the processor to: transmit a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and the first authentication result; receive a protected NAS response message including anacknowledgement for the data and a second authentication token; unprotect the NAS response message using the first provisional NAS security keys; compute a second authentication result based at least in part on the second authentication token; and derive, based at least in part on information in the second authentication token, a second security context including second provisional NAS security keys.

[0094] Additionally, the processor 600 may be configured to or operable to support any one or combination of where the first authentication result and the data are protected via NAS security; the data includes small data; the at least one controller is configured to cause the processor to transmit the NAS request message to a first network function at a first NE, and receive the protected NAS response message from a second network function at a second NE; the at least one controller is configured to cause the processor to derive the second security context based at least in part on a preconfigured configuration; the at least one controller is configured to cause the processor to derive the second security context without performing a NAS SMC procedure; the at least one controller is configured to cause the processor to delete the first security context including the one or more first provisional NAS security keys.

[0095] The processor 600 may support wireless communication in accordance with examples as disclosed herein. The processor 600 may be configured to or operable to support at least one controller (e.g., the controller 602) coupled with at least one memory (e.g., the memory 604) and configured to cause the processor to receive, from a UE and at a first network function at the NE, a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; transmit a registration accept response message including an indication that the registration is provisional and a first authentication token, and derive one or more provisional NAS security keys from the first authentication token; receive a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and an authentication result generated via the first authentication token; and transmit, to the UE, a protected NAS response message including an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

[0096] Additionally, the processor 600 may be configured to or operable to support any one or combination of where the network function includes an AMF; the SF access network includes oneor more satellites; the data includes small data; the at least one processor is configured to cause the NE to derive the one or more provisional NAS keys without performing a NAS SMC procedure; the at least one controller is configured to cause the processor to: transmit, to a second network function, an authentication request message for the UE including the indication that the registration is via the SF access network; and receive, from the second network function, an authentication response message including the first authentication token; the at least one controller is configured to cause the processor to: transmit, to a second network function, an authentication request message for the UE including the authentication result; and receive, from the second network function, an authentication response message including the second authentication token.

[0097] Figure 7 illustrates an example of a NE 700 in accordance with aspects of the present disclosure. The NE 700 may include a processor 702, a memory 704, a controller 706, and a transceiver 708. The processor 702, the memory 704, the controller 706, or the transceiver 708, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0098] The processor 702, the memory 704, the controller 706, or the transceiver 708, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0099] The processor 702 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 702 may be configured to operate the memory 704. In some other implementations, the memory 704 may be integrated into the processor 702. The processor 702 may be configured to execute computer-readable instructions stored in the memory 704 to cause the NE 700 to perform various functions of the present disclosure.

[0100] The memory 704 may include volatile or non-volatile memory. The memory 704 may store computer-readable, computer-executable code including instructions when executed by the processor 702 cause the NE 700 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 704 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0101] In some implementations, the processor 702 and the memory 704 coupled with the processor 702 may be configured to cause the NE 700 to perform one or more of the functions described herein (e.g., executing, by the processor 702, instructions stored in the memory 704). For example, the processor 702 may support wireless communication at the NE 700 in accordance with examples as disclosed herein. The NE 700 may be configured to or operable to support a means for receiving, from a UE and at a first network function at the NE, a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; transmitting a registration accept response message including an indication that the registration is provisional and a first authentication token, and deriving one or more provisional NAS security keys from the first authentication token; receiving a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and an authentication result generated via the first authentication token; and transmitting, to the UE, a protected NAS response message including an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

[0102] Additionally, the NE 700 may be configured to or operable to support any one or combination of the where the network function includes an AMF; the SF access network includes one or more satellites; the data includes small data; deriving the one or more provisional NAS keys without performing a NAS SMC procedure; transmitting, to a second network function, an authentication request message for the UE including the indication that the registration is via the SF access network; and receiving, from the second network function, an authentication response message including the first authentication token; transmitting, to a second network function, anauthentication request message for the UE including the authentication result; and receiving, from the second network function, an authentication response message including the second authentication token.

[0103] Additionally, or alternatively, the NE 700 may support at least one memory (e.g., the memory 704) and at least one processor (e.g., the processor 702) coupled with the at least one memory and configured to cause the NE to receive, from a UE and at a first network function at the NE, a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network; transmit a registration accept response message including an indication that the registration is provisional and a first authentication token, and derive one or more provisional NAS security keys from the first authentication token; receive a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and an authentication result generated via the first authentication token; and transmit, to the UE, a protected NAS response message including an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

[0104] Additionally, the NE 700 may be configured to support any one or combination of where the network function includes an AMF; the SF access network includes one or more satellites; the data includes small data; the at least one processor is configured to cause the NE to derive the one or more provisional NAS keys without performing a NAS SMC procedure; the at least one processor is configured to cause the NE to: transmit, to a second network function, an authentication request message for the UE including the indication that the registration is via the SF access network; and receive, from the second network function, an authentication response message including the first authentication token; the at least one processor is configured to cause the NE to: transmit, to a second network function, an authentication request message for the UE including the authentication result; and receive, from the second network function, an authentication response message including the second authentication token.

[0105] The controller 706 may manage input and output signals for the NE 700. The controller 706 may also manage peripherals not integrated into the NE 700. In some implementations, the controller 706 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or otheroperating systems. In some implementations, the controller 706 may be implemented as part of the processor 702.

[0106] In some implementations, the NE 700 may include at least one transceiver 708. In some other implementations, the NE 700 may have more than one transceiver 708. The transceiver 708 may represent a wireless transceiver. The transceiver 708 may include one or more receiver chains 710, one or more transmitter chains 712, or a combination thereof.

[0107] A receiver chain 710 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 710 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 710 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 710 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 710 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0108] A transmitter chain 712 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 712 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 712 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 712 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0109] Figure 8 illustrates a flowchart of a method 800 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0110] At 802, the method may include transmitting a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network. The operations of 802 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 802 may be performed by a UE as described with reference to Figure 5.

[0111] At 804, the method may include receiving a registration accept response message including an indication that a registration is provisional and a first authentication token. The operations of 804 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 804 may be performed by a UE as described with reference to Figure 5.

[0112] At 806, the method may include computing a first authentication result based at least in part on the first authentication token. The operations of 806 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 806 may be performed a UE as described with reference to Figure 5.

[0113] At 808, the method may include deriving, based at least in part on information in the first authentication token, a first security context including one or more first provisional NAS security keys. The operations of 808 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 808 may be performed a UE as described with reference to Figure 5.

[0114] Figure 9 illustrates a flowchart of a method 900 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0115] At 902, the method may include transmitting a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and the first authentication result. The operations of 902 may be performed in accordance with examples asdescribed herein. In some implementations, aspects of the operations of 902 may be performed by a UE as described with reference to Figure 5.

[0116] At 904, the method may include receiving a protected NAS response message including an acknowledgement for the data and a second authentication token. The operations of 904 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 904 may be performed by a UE as described with reference to Figure 5.

[0117] At 906, the method may include unprotecting the NAS response message using the first provisional NAS security keys. The operations of 906 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 906 may be performed a UE as described with reference to Figure 5.

[0118] At 908, the method may include computing a second authentication result based at least in part on the second authentication token. The operations of 908 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 908 may be performed a UE as described with reference to Figure 5.

[0119] At 910, the method may include deriving, based at least in part on information in the second authentication token, a second security context including second provisional NAS security keys. The operations of 910 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 910 may be performed a UE as described with reference to Figure 5.

[0120] Figure 10 illustrates a flowchart of a method 1000 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0121] At 1002, the method may include receiving, from a UE and at a first network function at the NE, a registration request message to request a registration, the registration request message including an indication that the registration is via a SF access network. The operations of 1002 maybe performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1002 may be performed by a NE as described with reference to Figure 7.

[0122] At 1004, the method may include transmitting a registration accept response message including an indication that the registration is provisional and a first authentication token, and deriving one or more provisional NAS security keys from the first authentication token. The operations of 1004 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1004 may be performed by a NE as described with reference to Figure 7.

[0123] At 1006, the method may include receiving a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message including data and an authentication result generated via the first authentication token. The operations of 1006 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1006 may be performed a NE as described with reference to Figure 7.

[0124] At 1008, the method may include transmitting, to the UE, a protected NAS response message including an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys. The operations of 1008 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1008 may be performed a NE as described with reference to Figure 7.

[0125] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

CLAIMSWhat is claimed is:

1. A user equipment (UE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the UE to: transmit a registration request message to request a registration, the registration request message comprising an indication that the registration is via a store and forward (SF) access network; receive a registration accept response message comprising an indication that a registration is provisional and a first authentication token; compute a first authentication result based at least in part on the first authentication token; and derive, based at least in part on information in the first authentication token, a first security context comprising one or more first provisional non access stratum (NAS) security keys.

2. The UE of claim 1, wherein the SF access network comprises one or more satellites.

3. The UE of claim 1 , wherein registration accept response message is unprotected.

4. The UE of claim 1 , wherein the at least one processor is operable to cause the UE to transmit the registration request message to a first network function at a first network equipment (NE), and receive the registration accept response message from a second network function at a second NE.

5. The UE of claim 1 , wherein the at least one processor is operable to cause the UE to derive the first security context based at least in part on a preconfigured configuration.

6. The UE of claim 1 , wherein the at least one processor is operable to cause the UE to derive the first security context without performing a NAS security mode command (SMC) procedure.

7. The UE of claim 1, wherein the at least one processor is operable to cause the UE to: transmit a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message comprising data and the first authentication result; receive a protected NAS response message comprising an acknowledgement for the data and a second authentication token; unprotect the NAS response message using the first provisional NAS security keys; compute a second authentication result based at least in part on the second authentication token; and derive, based at least in part on information in the second authentication token, a second security context comprising second provisional NAS security keys.

8. The UE of claim 7, wherein the first authentication result and the data are protected via NAS security, and wherein the data comprises small data.

9. The UE of claim 7, wherein the at least one processor is operable to cause the UE to transmit the NAS request message to a first network function at a first network equipment (NE), and receive the protected NAS response message from a second network function at a second NE.

10. The UE of claim 7, wherein the at least one processor is operable to cause the UE to derive the second security context based at least in part on a preconfigured configuration.

11. The UE of claim 7, wherein the at least one processor is operable to cause the UE to derive the second security context without performing a NAS security mode command (SMC) procedure.

12. The UE of claim 7, wherein the at least one processor is operable to cause the UE to delete the first security context including the one or more first provisional NAS security keys.

13. A network equipment (NE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the NE to: receive, from a user equipment (UE) and at a first network function at the NE, a registration request message to request a registration, the registration request message comprising an indication that the registration is via a store and forward (SF) access network; transmit a registration accept response message comprising an indication that the registration is provisional and a first authentication token, and derive one or more provisional non access stratum (NAS) security keys from the first authentication token; receive a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message comprising data and an authentication result generated via the first authentication token; and transmit, to the UE, a protected NAS response message comprising an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

14. The NE of claim 13, wherein the network function comprises an access and mobility management function (AMF), and wherein the SF access network comprises one or more satellites.

15. The NE of claim 13, wherein the data comprises small data.

16. The NE of claim 13, wherein the at least one processor is operable to cause the NE to derive the one or more provisional NAS keys without performing a NAS security mode command (SMC) procedure.

17. The NE of claim 13, wherein the at least one processor is operable to cause the NE to: transmit, to a second network function, an authentication request message for the UE comprising the indication that the registration is via the SF access network; and receive, from the second network function, an authentication response message comprising the first authentication token.

18. The NE of claim 13, wherein the at least one processor is operable to cause the NE to: transmit, to a second network function, an authentication request message for the UE comprising the authentication result; and receive, from the second network function, an authentication response message comprising the second authentication token.

19. A method performed by a user equipment (UE), the method comprising: transmitting a registration request message to request a registration, the registration request message comprising an indication that the registration is via a store and forward (SF) access network; receiving a registration accept response message comprising an indication that a registration is provisional and a first authentication token; computing a first authentication result based at least in part on the first authentication token; and deriving, based at least in part on information in the first authentication token, a first security context comprising one or more first provisional non access stratum (NAS) security keys.

20. A method performed by a network equipment (NE), the method comprising: receiving, from a user equipment (UE) and at a first network function at the NE, a registration request message to request a registration, the registration request message comprising an indication that the registration is via a store and forward (SF) access network; transmitting a registration accept response message comprising an indication that the registration is provisional and a first authentication token, and deriving one or more provisional non access stratum (NAS) security keys from the first authentication token; receiving a NAS request message protected with the one or more first provisional NAS security keys, the NAS request message comprising data and an authentication result generated via the first authentication token; and transmitting, to the UE, a protected NAS response message comprising an acknowledgement for the data and a second authentication token, the protected NAS response message protected with the one or more provisional NAS security keys.

Citation Information

Patent Citations

  • Systems and methods to authenticate a non-fifth generation capable device on a residential gateway

    US11902779B1

  • System and method for security protection of NAS messages

    US20230292121A1