Protecting a registration or attach procedure using a certificate based cryptography
Certificate-based cryptography at UE and on-board network entities secures temporary identifiers and sensitive information in satellite communication networks, addressing NAS context vulnerabilities during feeder and service link unavailability.
Patent Information
- Application Number
- PCT/KR2025/099197
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-14
- Filing Date
- 2025-02-03
- Publication Date
- 2025-08-07
AI Technical Summary
In satellite-based communication networks, the unavailability of feeder and service links during store-and-forward scenarios poses challenges in securing Non-Access-Stratum (NAS) contexts, leading to potential threats from exposure of sensitive UE information, such as temporary identifiers, due to unprotected message transmission.
Implementing certificate-based cryptography at both the user equipment (UE) and on-board network entities, using pre-configured private keys and certificates to encrypt and decrypt partial registration or attach accept messages, ensuring secure transmission of temporary identifiers and sensitive information.
Enhances security and privacy by protecting sensitive UE information during feeder link unavailability, preventing unauthorized access and maintaining network integrity.
Smart Images

Figure KR2025099197_07082025_PF_FP_ABST
Abstract
Description
PROTECTING A REGISTRATION OR ATTACH PROCEDURE USING A CERTIFICATE BASED CRYPTOGRAPHY
[0001] The present disclosure is related to wireless communication networks. More particularly, the present disclosure is related to a method and system for protecting a registration or attach procedure using a certificate based cryptography.
[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.
[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.
[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE (User Equipment) Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.
[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.
[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.
[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.
[0008] In an embodiment, a method performed by a user equipment (UE) for protection of a partial registration or attach accept message using a certificate based cryptography is provided. The method may include pre-configuring a private key and a certificate at the UE based on an operator policy. The method may include transmitting a registration or attach request message including a public key of the UE in the certificate to an on-board network entity. The method may include receiving the partial registration or attach accept message from the on-board network entity, wherein the partial registration or attach accept message may be encrypted using the public key of the UE, and wherein the partial registration or attach accept message may include a temporary identifier for the UE. The method may include decrypting the received encrypted partial registration or attach accept message using the private key. The method may include storing the temporary identifier included in the decrypted partial registration or attach accept message.
[0009] In an embodiment, a method performed by an on-board network entity for protection of a partial registration or attach accept message using a certificate based cryptography is provided. The method may include receiving a registration or attach request message including a public key of a user equipment (UE) in a certificate from the UE. The method may include verifying the certificate of the UE. The method may include generating a temporary identifier for the UE. The method may include encrypting the partial registration or attach accept message using the public key of the UE, wherein the partial registration or attach accept message may include the generated temporary identifier. The method may include transmitting the encrypted partial registration or attach accept message to the UE.
[0010] In an embodiment, a user equipment (UE) for protection of a partial registration or attach accept message using a certificate based cryptography is provided. The UE may include memory, a processor coupled to the memory, and a registration protection controller communicatively coupled to the memory and the processor. The registration protection controller may pre-configure a private key and a certificate at the UE based on an operator policy. The registration protection controller may transmit a registration or attach request message including a public key of the UE in the certificate to an on-board network entity. The registration protection controller may receive the partial registration or attach accept message from the on-board network entity, wherein the partial registration or attach accept message may be encrypted using the public key of the UE, and wherein the partial registration or attach accept message may include a temporary identifier for the UE. The registration protection controller may decrypt the received encrypted partial registration or attach accept message using the private key. The registration protection controller may store the temporary identifier included in the decrypted partial registration or attach accept message.
[0011] In an embodiment, an on-board network entity for protection of a partial registration or attach accept message using a certificate based cryptography is provided. The on-board network entity may include memory, a processor coupled to the memory, and an on-board registration protection controller communicatively coupled to the memory and the processor. The on-board registration protection controller may receive a registration or attach request message including a public key of a user equipment (UE) in a certificate from the UE. The on-board registration protection controller may verify the certificate of the UE. The on-board registration protection controller may generate a temporary identifier for the UE. The on-board registration protection controller may encrypt the partial registration or attach accept message using the public key of the UE, wherein the partial registration or attach accept message may include the generated temporary identifier. The on-board registration protection controller may transmit the encrypted partial registration or attach accept message to the UE.
[0012] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating preferred embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications be made within the scope of the embodiments herein.
[0013] These and other features, aspects, and advantages of the present embodiments are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the drawings, in which:
[0014] Fig. 1 is a schematic diagram that illustrates a scenario of a serving satellite change during a feeder link disconnection while an IoT device is moving according to an embodiment as disclosed herein.
[0015] Fig. 2 is a schematic diagram that illustrates a scenario of the serving satellite change during the feeder link disconnection while the satellite is moving according to an embodiment as disclosed herein.
[0016] Fig. 3 is a sequence diagram that illustrates a scenario of initial registration and / or attach procedure between a UE, a single satellite and a network according to an embodiment as disclosed herein.
[0017] Fig. 4 is a sequence diagram that illustrates a scenario of initial registration and / or attach procedure between the UE, multiple satellites, and the network according to an embodiment as disclosed herein.
[0018] Fig. 5 is a block diagram that illustrates a schematic of the UE implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein.
[0019] Fig. 6 is a block diagram that illustrates a schematic of an on-board network apparatus implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein.
[0020] Fig. 7 is a sequence diagram that illustrates a protection of partial registration / attach accept message using public key cryptography while the UE is in possession of key pairs according to an embodiment as disclosed herein.
[0021] Fig. 8 is a sequence diagram that illustrates a protection of partial registration / attach accept message using certificate based cryptography while the UE in possession of certificates according to an embodiment as disclosed herein.
[0022] Fig. 9 is a sequence diagram that illustrates a protection of partial registration / attach accept message using a public key based cryptography while network functions (NFs) on-board are in possession of key pairs according to an embodiment as disclosed herein.
[0023] Fig. 10 is a sequence diagram that illustrates a protection of partial registration / attach accept message using a certificate based cryptography using NFs on-board in possession of certificates according to an embodiment as disclosed herein.
[0024] Fig. 11 is a sequence diagram that illustrates a protection of partial registration / attach accept message using a TLS Certificate based cryptography using the UE and the NFs-onboard according to an embodiment as disclosed herein.
[0025] Fig. 12 is a sequence diagram that illustrates KAMF-SATkey derivation per satellite according to an embodiment as disclosed herein.
[0026] Fig. 13 is a sequence diagram that illustrates NAS key derivation per satellite according to an embodiment as disclosed herein.
[0027] Fig. 14 is a schematic diagram that illustrates KAMF-SATderivation function according to an embodiment as disclosed herein.
[0028] Fig. 15 is a schematic diagram that illustrates the KAMF-SATderivation function according to an embodiment as disclosed herein.
[0029] Fig. 16 is a schematic diagram that illustrates KNASintderivation function according to an embodiment as disclosed herein.
[0030] Fig. 17 is a schematic diagram that illustrates KNASencderivation function according to an embodiment as disclosed herein.
[0031] Fig. 18 is a sequence diagram that illustrates a scenario where the UE selects another PDU session in case of satellite unavailability according to an embodiment as disclosed herein.
[0032] Figs. 19A and 19B are a sequence diagram that illustrates a scenario where the UE switches the PDU based on uplink unavailability according to an embodiment as disclosed herein.
[0033] Fig. 20 is a schematic diagram that illustrates a scenario where the same PDU session is maintained between both 3GPP and non-3GPP access according to an embodiment as disclosed herein.
[0034] Fig. 21 is a schematic diagram that illustrates a scenario where the same PDU session is maintained between both 3GPP and non-3GPP access according to an embodiment as disclosed herein.
[0035] Fig. 22 is a schematic diagram that illustrates a process of key derivation in dual connectivity according to an embodiment as disclosed herein.
[0036] Fig. 23 is a sequence diagram that illustrates key derivation and handling during dual connectivity in satellite communication according to an embodiment as disclosed herein.
[0037] Fig. 24 is a flow diagram that illustrates a method for protecting a registration or attach procedure using a certificate based cryptography by the UE according to an embodiment as disclosed herein.
[0038] Fig. 25 is a flow diagram that illustrates a method for protecting a registration or attach procedure using a certificate based cryptography by the on-board network apparatus according to an embodiment as disclosed herein.
[0039] It may be noted that to the extent possible, like reference numerals have been used to represent like elements in the drawing. Further, those of ordinary skill in the art will appreciate that elements in the drawing are illustrated for simplicity and may not have been necessarily drawn to scale. For example, the dimension of some of the elements in the drawing may be exaggerated relative to other elements to help to improve the understanding of aspects of the disclosure. Furthermore, the elements may have been represented in the drawing by conventional symbols, and the drawings may show only those specific details that are pertinent to the understanding the embodiments of the disclosure so as not to obscure the drawing with details that will be readily apparent to those of ordinary skill in the art having benefit of the description herein.
[0040] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. Also, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments can be combined with a plurality of other embodiments to form new embodiments. The term "or" as used herein, refers to a non-exclusive or, unless otherwise indicated. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein can be practiced and to further enable those skilled in the art to practice the embodiments herein. Accordingly, the examples are not be construed as limiting the scope of the embodiments herein.
[0041] As is traditional in the field, embodiments are described and illustrated in terms of blocks that carry out a described function or functions. These blocks, which referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, and the like, and optionally be driven by firmware and software. The circuits, for example, be embodied in a plurality of semiconductor chips, or on substrate supports such as printed circuit boards, and the like. The circuits constituting a block be implemented by dedicated hardware, or by a processor (e.g., a plurality of programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments be physically separated into two or more interacting and discrete blocks without departing from the scope of the proposed method. Likewise, the blocks of the embodiments be physically combined into more complex blocks without departing from the scope of the proposed method.
[0042] The accompanying drawings are used to help easily understand various technical features and it is understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the proposed method is construed to extend to any alterations, equivalents and substitutes in addition to those which are particularly set out in the accompanying drawings. Although the terms first, second, etc. used herein to describe various elements, these elements are not be limited by these terms. These terms are generally used to distinguish one element from another.
[0043] The various actions, acts, blocks, steps, or the like in the method is performed in the order presented, in a different order or simultaneously. Further, in an embodiment, some of the actions, acts, blocks, steps, or the like are omitted, added, modified, skipped, or the like without departing from the scope of the proposed method.
[0044] 3GPP is currently examining various use cases related to store and forward (S&F) scenarios where the service link (connecting the user equipment (UE) to the satellite) and the feeder link (linking the satellite to the non-terrestrial network (NTN) gateway) are not available simultaneously. When the satellite is linked to the ground network through the feeder link, messages are uploaded to the satellite. All accumulated and stored mobile terminated (MT) messages are transferred to the satellite via this feeder link. Concurrently, all accumulated and stored mobile originated (MO) messages are sent to the 5G Core (5GC) through the same feeder link, which may impact the performance of the feeder link, the satellite, and the 5GC.
[0045] In the S&F scenario, the handling of Non-Access-Stratum (NAS) contexts when the feeder link or service link is unavailable simultaneously remains an area that has not been thoroughly studied. To ensure NAS integrity and ciphering, it is essential that NAS keys are accessible to both the network and the user equipment (UE). Additionally, when multiple satellites are serving the UE through periodic switching, and there is no inter-satellite link available during the S&F scenario, further analysis or study is required to understand how NAS contexts are isolated and distributed among the satellites to safeguard NAS signaling.
[0046] In satellite S&F scenario, when a UE attaches or registers to the network (when a service link is available) via an on-board eNB / gNB and NFs, the satellite supporting S&F operation stores the registration request until the feeder link is available and sends an interim response message to the UE. Due to unavailability of the feeder link, the UE may not get authenticated (until the feeder link is available) and establish the security context to protect the response messages. In these situations, the on-board eNB / gNB and MME / AMF must prioritize the security and privacy of the (UE by safeguarding the response message, which may contain sensitive UE information, such as the assignment of a temporary ID. If any UE-related data is transmitted in clear text, it could expose the system to potential threats concerning UE traceability and linkability.
[0047] Hence, is desirable to address the above mentioned problems and disadvantages or at least provide a useful alternative.
[0048] Fig. 1 is a schematic diagram that illustrates a scenario of a serving satellite change during a feeder link disconnection while an IoT device (106) is moving according to an embodiment as disclosed herein. Fig. 2 is a schematic diagram that illustrates a scenario of the serving satellite change during the feeder link disconnection while the satellite is moving according to an embodiment as disclosed herein. As shown, Fig. 1 and Fig. 2 include the IoT device (106), a satellite A (102A), a satellite B (102B), and a gateway (104). The IoT device (106) is in communication with the satellite A (102A) via the service link. The satellite A (102A) and the satellite B (102B) are in communication with each other via an inter-satellite link. Further, the gateway (104) is in communication with the satellite A (102A) and the satellite B (102B) via the feeder link.
[0049] As shown in Fig. 1, the IoT device (106) may move from the coverage of one satellite to the other (e.g. containers tracing and tracking), or as shown in Fig. 2, a Non-Geostationary Satellite Orbit (NGSO) satellite may fly away and the other one will come and turn to serving a static IoT device. Under such circumstances, the serving satellite may forward the stored user plane data to the next serving satellite through Inter-Satellite Links, and the next serving satellite may help forward the data to the gateway.
[0050] Meanwhile, if the feeder link of the next satellite is also unavailable, it will continue the store operation until the recovery of its feeder link. In this way, for every single IoT device (106), there will be only one satellite for its data storage in the overall satellite system. Also, the mobile operators will be easier to manage and maintain the data rather than dealing with the separate data which is belong to one device but among different satellites.
[0051] Significantly, during the period that the feeder link is unavailable, the serving satellite only stores or forwards (Inter-satellite) the data received from the IoT device (106), which is already able to send data to the application server through the mobile network with satellite access. Since the disconnection separates the two parts of the mobile network temporarily, the part in the serving satellite will not be able to fulfill common communication procedures and it will refuse any access from an unregistered device. Furthermore, considering the limited data storage in satellite and the large amount of IoT devices, a maximum storage for the IoT device (106) should be pre-configured based on the application data characteristics, user subscriptions and overall performance of satellite communication system.
[0052] Considering the deployment options of at least one of an S&F for single satellite deployment and S&F for multiple satellite deployment, in which the gNB / eNB and MME / AMF are onboard in satellite. Fig. 3 and Fig. 4 show the potential solutions under consideration for initial registration and / or attach procedure without PDN connectivity. Whenever a procedure needs an interaction with a core network node in the ground, then AMF / MME-onboard stores the respective messages when feeder link is not available and progresses the procedure when feeder link is available. At step 3 in Fig. 3 and Fig. 4, the AMF / MME-onboard sends a NAS message e.g., Partial attach accept which is unprotected to the UE (502), indicating to the UE (502) that the sent REGISTRATION / ATTACH REQUEST message is partially stored by the AMF / MME-onboard. The Partial registration / attach accept message includes a temporary UE identifier (say 5G-GUTI / Globally Unique Temporary UE Identity (GUTI)) and other possible sensitive information such as parameters used for security mechanism which can lead to privacy attacks. Therefore, it is desired to address the risk of sending the UE temporary identifier in an unprotected message (e.g., partial registration / attach accept).
[0053] Referring now to the drawings, and more particularly to Figs. 5 through 24 where similar reference characters denote corresponding features consistently throughout the figures, there are shown preferred embodiments.
[0054] Fig. 5 is a block diagram that illustrates a schematic of a UE (502) implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein. For instance, the UE (502) may include, but not limited to a smartphone, a tablet, a laptop, a personal computer (PC), a television, automotive systems (such as connected cars, autonomous vehicles, vehicle-to-everything (V2X) communication devices, etc.), enterprise Devices such as robotics, specialized Equipment (such as medical devices, public safety devices, etc.), media Devices (such as gaming Consoles, streaming Devices, etc.), and the like. As shown, the UE (502) may include a first processor (504), first memory (506), a first Input / Output (I / O) Interface (508), and a registration protection controller (510). Each component is explained in further detail below.
[0055] The first processor (504) may communicates with the first memory (506), the first I / O Interface (508) and the registration protection controller (510). The first processor (504) may be configured to execute instructions stored in the first memory (506) and to perform various processes. The first processor (504) may include one or a plurality of processors, may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0056] The first memory (506) may include storage locations to be addressable through the first processor (504). The first memory (506) is not limited to a volatile memory and / or a non-volatile memory. Further, the first memory (506) may include a plurality of computer-readable storage media. The first memory (506) may include non-volatile storage elements. For example, non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories.
[0057] The first I / O Interface (508) may transmit the information between the first memory (506) and external peripheral devices. The peripheral devices may be the input-output devices associated with the UE (502). Further, the registration protection controller (510) may communicate with the first I / O Interface (508) and the first memory (506). The registration protection controller (510) may be communicatively coupled to the first memory (506) and the first processor (504). The registration protection controller (510) may be an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0058] In an embodiment, the registration protection controller (510) may pre-configure a private key and a certificate at the UE (502) based on an operator policy. The certificate may include a public key of the UE (502). The operator policy may outline the security protocols and standards that must be adhered to for the protection of user data and network integrity. The private key may be used to encrypt data and authenticate the identity of the UE (502) during communication sessions. The private key may remain confidential and may be stored securely within the UE (502), ensuring that only the authorized device can access and utilize it for secure transactions. Further, the certificate may act as an additional security layer and include the public key associated with the UE (502).
[0059] In an embodiment, the registration protection controller (510) may generate a registration or attach request message by adding the certificate including the public key of the UE (502). The registration or attach request message may be crucial for establishing a connection between the UE (502) and the network. To enhance the security and integrity of this communication, the registration protection controller (510) may incorporate the certificate into the registration or attach request message.
[0060] In an embodiment, the registration protection controller (510) may transmit the registration or attach request message to an on-board network apparatus (602). For instance, the on-board network apparatus (602) may include a next generation node B (gNB), an evolved node B (eNB), an access and mobility management function (AMF), and a mobility management entity (MME).
[0061] In an embodiment, the registration protection controller (510) may receive a partial attach registration or accept message from the on-board network apparatus (602) in response to the registration or attach request message. The partial attach registration or accept message may be received upon successful verification of the certificate by the on-board network apparatus (602). The partial attach registration or accept message may be encrypted using the public key of the UE (502). The partial attach registration or accept message may include a temporary identifier for the UE (502) and a security parameter. This temporary identifier may serve as a unique reference for the UE (502) during the ongoing session, allowing the on-board network apparatus (602) to manage and track the connection effectively. Further, the security parameter may include information related to encryption keys, authentication tokens, or other security-related data necessary for establishing a secure communication channel between the UE (502) and the on-board network apparatus (602).
[0062] In an embodiment, the registration protection controller (510) may decrypt the received encrypted partial registration or attach accept message using the private key preconfigured at the UE (502). The decryption process may involve using the private key to reverse the encryption applied to the message prior to its transmission. This ensures that only authorized entities, equipped with the correct private key, can interpret the contents of the message. The encrypted partial registration or attach accept message may contain vital information necessary for establishing or maintaining a connection between the UE (502) and the on-board network apparatus (602).
[0063] Fig. 6 is a block diagram that illustrates a schematic of the on-board network apparatus (602) implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein. For instance, the on-board network apparatus (602) may include a next generation node B (gNB), an evolved node B (eNB), an access and mobility management function (AMF), and a mobility management entity (MME) on-board a satellite. The gNB may be responsible for providing radio access to the UE (502). The gNB may facilitate high-speed data transmission, low latency, supports a large number of connected devices, manages user sessions, and ensure seamless connectivity. The eNB may be responsible for connecting user devices within the network. It may handle radio resource management, scheduling, and the transmission of data to and from the UE (502). The eNB may play a crucial role in maintaining the quality of service and managing handovers between cells.
[0064] The AMF may be responsible for managing user access and mobility. It may handle registration, connection management, and mobility procedures, ensuring that users maintain a stable connection as they move between different coverage areas. Further, the MME may be responsible for managing the signaling between the UE (502) and the core network. It may handle tasks such as user authentication, session management, and mobility management.
[0065] As shown, the on-board network apparatus (602) may include a second processor (604), second memory (606), a second I / O interface (608), and an on-board registration protection controller (610). The on-board registration protection controller (610) may communicate with the second I / O interface (608) and the second memory (606). The on-board registration protection controller (610) may be communicatively coupled to the second memory (606) and the second processor (604). The on-board registration protection controller (610) may be an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0066] In an embodiment, the on-board registration protection controller (610) may receive a registration or attach request message from the UE (502). The registration or attach request message may include a public key and a certificate associated with the UE (502). The certificate may include the public key of the UE (502). The public key may be used to encrypt data that can only be decrypted by the corresponding private key, ensuring that sensitive information remains secure during transmission. The certificate may be issued by a trusted certificate authority (CA). The certificate may include information such as the identity of the UE (502), the validity period of the certificate, the digital signature of the CA, which verifies the authenticity of the certificate, and the like.
[0067] In an embodiment, the on-board registration protection controller (610) may verify the certificate of the UE (502). The verification may be carried out by provisioning a root certificate of a root CA that issued the certificate of the UE (502) at the on-board network apparatus (602). The certificate of the UE (502) may be verified based on the provisioned root certificate of the root CA. The root certificate may serve as a trusted anchor for the entire authentication framework. The installation of the root certificate may be performed on the on-board network apparatus (602), which acts as a gateway for managing and verifying the certificates of the UE (502).
[0068] In an embodiment, the on-board registration protection controller (610) may generate a temporary identifier for the UE (502) upon successful verification of the certificate of the UE (502). The use of the temporary identifier may enhance privacy and security, as it minimizes the risk of unauthorized access and protects the actual identity of the UE (502) from potential threats.
[0069] In an embodiment, the on-board registration protection controller (610) may generate a partial attach registration or accept message to be transmitted to the UE (502) upon generation of the temporary identifier. The partial attach registration or accept message may include essential information that indicates the current status of the UE (502) in the network and may include details such as the temporary identifier itself, network capabilities, and any relevant parameters that the UE (502) needs to be aware of for further communication. The partial attach registration or accept message may be crucial for establishing a secure and efficient connection between the UE (502) and the on-board network apparatus (602). This may allow the UE (502) to proceed with its registration process while ensuring that it is duly recognized and authenticated.
[0070] In an embodiment, the on-board registration protection controller (610) may encrypt the partial registration or attach accept message using the public key of the UE (502). The partial registration or attach accept message may include the generated temporary identifier and security parameters. The security parameters may be critical for establishing a secure communication channel between the UE (502) and the on-board network apparatus (602). For instance, the security parameters may include encryption procedures, integrity protection mechanisms, and other security-related information that ensures the confidentiality and integrity of the data being transmitted.
[0071] Fig. 7 is a sequence diagram that illustrates a protection of partial registration / attach accept message using public key cryptography while the UE (502) is in possession of key pairs according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A) (including the eNB and MME-onboard), and a ground network (702) are in communication with each other. Each step is explained in further detail below.
[0072] At step 1, the UE (502) may be in possession of private-public key pair required for public key cryptography. In an embodiment, the UE (502) may be configured with the private-public key pair by the core network (ground network (702)) as part of UE configuration and / or in the Universal integrated circuit card (UICC). In an embodiment, the UE (502) may be configured with the private-public key pair by the NFs-onboarded (on the satellite A (102A)) as part of UE configuration and / or in the UICC. In an embodiment, the Key Management Server (KMS) (operator managed / third party provided) may configure the UE (502) with the private-public key pair as part of UE configuration and / or in the UICC. In an embodiment, the UE (502) (Universal Subscriber Identity Module (USIM) / UICC / Mobile Equipment (ME)) may generate asymmetric key pairs.
[0073] At step 2, when the service link is available (feeder link is not available), if the UE (502) identifies that current serving cell support S&F mode and the UE (502) is allowed to use S&F operation, then the UE (502) may send Registration or Attach Request message to the AMF or MME-onboard (in the satellite A (102A) (as in Fig. 7)). The UE (502) may include at least one of the UE identifier (International Mobile Subscriber Identity (IMSI) / Subscription Concealed Identifier (SUCI) and / or Generic Public Subscription Identifier (GPSI)), Message Authentication Code (MAC) of the message in the request message. The UE (502) may additionally include the public key in the registration or Attach Request message. This public key will be used to encrypt the partial registration or attach accept message.
[0074] In an embodiment, the GPSI may be included instead of IMSI to ensure the long term permanent identities are not exposed over the air and / or the certificate includes GPSI as the identity of the client (for example, if certificate / public key is issued by third party then long term permanent identities cannot be exposed to the 3rdparty).
[0075] In an embodiment, the UE (502) may include the security capability (for the protection of initial message exchanges) more specifically the asymmetric cryptographic information (at least one of the following parameters such as protection scheme like null-scheme or profiles, Elliptic Curve Integrated Encryption Scheme (ECIES), length of the cryptographic keys, size of the Message Authentication code (MAC), MAC algorithm, Digital Signature algorithm, Encryption algorithm, HASH algorithm, Key Derivation Function, Size of the scheme output, like so). In an embodiment, the certificates may be associated with validity to avoid any tracking issue due to using same certificate for longer period of time.
[0076] At step 3, in an embodiment, when the gNB or eNB and / or AMF or MME (onboard) receives the registration or Attach Request message, it may assign and / or generate a Temporary Identifier for the UE (502). In an embodiment, the gNB or eNB and / or AMF or MME (onboard) may associate or map the assigned Temporary Identifier with at least one of the received IMSI / SUCI and / or GPSI and the Public Key and further store the received Registration or Attach Request message until the feeder link is available as part of S&F operation.
[0077] In an embodiment, the temporary identifier may be of single usage or may be associated with a validity period.
[0078] In an embodiment, the gNB or eNB and / or AMF or MME (onboard) may check the legitimacy of the UE (502) and the request message by verifying the MAC.
[0079] At step 4, as the feeder link is not available, the gNB or eNB and / or AMF or MME-onboard may send a NAS message as Partial registration / attach accept message to the UE (502). The Partial registration / attach accept message may include the generated Temporary Identifier and other possible parameters encrypted and / or integrity protected using the public key of the UE (502), considering the received security capability of the UE (502). Further, the parameters / details of the used security mechanism may be included in the Partial registration / attach accept message.
[0080] In an embodiment, the partial registration / attach accept message may be the response NAS (N1) message for the received Registration or Attach Request message. In an embodiment, if asymmetric computation of keys is a significant overhead for the UE (502) and the satellite A (102A), then the response message may be encrypted and / or integrity protected by the random key generated by the on-board NF or the satellite A (102A). The on-board NF or the satellite A (102A) may encrypt the random key using the public key of the UE (502). The on-board NF or the satellite A (102A) may transmit encrypted and / or Internet Protocol (IP) response and also includes the encrypted random key to the UE (502) along with the message.
[0081] At step 5, the UE (502) may decrypt the received Partial registration / attach accept message using the private key and store the Temporary Identifier and the received security parameters / details if any in the Partial registration / attach accept message. The UE (502) shall not trigger the registration / attach request again until paging message is received or appropriate timer value elapses.
[0082] At step 6-7, when the onboard satellite A (102A) is connected to the ground network (702) but cannot connect to the UE (502) e.g., the service link connectivity is unavailable and feeder link connectivity is available, the AMF or MME-onboard may fetch the authentication vectors, subscription details and other possible required parameters from the Unified Data Management (UDM) or a Home Subscriber Server (HSS) (302) on the ground network (702) and indicate that it is pre-fetching the subscription data without authenticating the UE (502). The gNB or eNB and / or AMF or MME (onboard) may store the received authentication vectors, subscription details and other possible parameters received until the service link is available.
[0083] At step 8, when the service link is available and feeder link connectivity is not available, the onboard AMF or MME may enter UE serving area; it will start paging the UE (502) with the assigned temporary identifier in the partial registration or attach accept message. In an embodiment, the paging message will include a cause Information Element (IE) indicating to complete the registration or attach procedure for the UE (502).
[0084] At step 9, in response to receiving the paging message, the UE (502) may re-send the Registration or Attach request message including the IMSI / SUCI.
[0085] At step 10-11, the UE (502) and gNB / eNB or AMF / MME-onboard may perform the authentication and security procedure with the UE (502), once primary authentication procedure is successful remaining steps are performed to complete the Registration or Attach procedure with the UE (502). After successful authentication the UE and gNB / eNB and / or AMF / MME may establish the Access Stratum (AS), User Plane (UP) and Non-Access Stratum (NAS) security context.
[0086] At step 12, further message exchanges may be protected using AS, UP and NAS security context appropriately.
[0087] Fig. 8 is a sequence diagram that illustrates a protection of partial registration / attach accept message using certificate based cryptography while the UE (502) in possession of certificates according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A) (including the eNB and MME-onboard), and the ground network (702) are in communication with each other. Each step is explained in further detail below.
[0088] At step 1, the UE (502) may be in possession of certificate and private key. In an embodiment, the UE (502) may be configured with the certificate and private key by the Core Network (ground network (702)) as part of UE configuration and / or in the UICC. In an embodiment, the UE (502) may be configured with the certificate and private key by the NFs-onboarded (on the satellite A (102A)) as part of UE configuration and / or in the UICC. In an embodiment, the Certificate Authority (CA) / Registration Authority (RA) (operator managed / third party provided) may configure the UE (502) with the certificate and private key as part of UE pre-configuration and / or in the UICC.
[0089] At step 2, when the service link is available (feeder link is not available), if the UE (502) identifies that current serving cell support S&F mode and the UE (502) is allowed to use S&F operation then, the UE (502) may send Registration or Attach Request message to the AMF or MME-onboard (in the satellite A (102A)). The UE (502) may include at least one of the UE identifier IMSI / SUCI and / or GPSI in the request message. The UE (502) may additionally include the public key of the UE (502) in the certificate in the registration or Attach Request message. This Public key in the Certificate will be used to encrypt the partial registration or attach accept message.
[0090] In an embodiment, the GPSI may be included instead of IMSI to ensure the long term permanent identities are not exposed over the air and / or the certificate may include GPSI as the identity of the client (for example, if certificate / public key is issues by third party then long term permanent identities cannot be exposed to the 3rdparty). In an embodiment, the UE (502) may include the security capability (for the protection of initial message exchanges) more specifically the asymmetric cryptographic information (at least one of the following parameters such as protection scheme like null-scheme or profiles, ECIES, length of the cryptographic keys, size of the MAC, MAC algorithm, Digital Signature algorithm, Encryption algorithm, HASH algorithm, Key Derivation Function, Size of the scheme output, like so).
[0091] At step 3, in an embodiment, when the gNB or eNB and / or AMF or MME (onboard) receives the registration or Attach Request message, it may assign and / or generate a Temporary Identifier for the UE (502). In an embodiment, the gNB or eNB and / or AMF or MME (onboard) may associate or map the assigned Temporary Identifier with the received IMSI / SUCI and / or GPSI and the Public Key in the Certificate and further store the received Registration or Attach Request message until the feeder link is available as part of S&F operation. In an embodiment, in order to verify the certificate of the UE (502), the onboard NFs or an entity / module in the satellite A (102A) may be provisioned with the certificate of the root CA who issued the certificate. One example of the Root CA for this purpose is the GSMA CI, which is defined in SGP.02
[0092] At step 4, as the feeder link is not available, the gNB or eNB and / or AMF or MME-onboard may send a NAS message as Partial registration / attach accept message to the UE (502). The Partial attach registration / accept message may include the generated Temporary Identifier and other possible parameters encrypted using public key of the UE (502) in the certificate considering the received security capability of the UE (502). Further, the parameters / details of the used security mechanism may be included in the Partial registration / attach accept message.
[0093] In an embodiment, if asymmetric computation of keys is a significant overhead for the UE (502) and the satellite A (102A), then the response message may be encrypted and / or integrity protected by the random key generated by the Onboard NF or the satellite A (102A). The Onboard NF or the satellite A (102A) may encrypt the random key using the public key of the UE (502). The Onboard NF or the satellite A (102A) may transmit encrypted and / or IP response and also includes the encrypted random key to the UE (502) along with the message.
[0094] At step 5, the UE (502) may decrypt the received encrypted Partial registration / attach accept message using the private key and store the Temporary Identifier and the received security parameters / details if any in the Partial registration / attach accept message. The UE (502) shall not trigger the registration / attach request again until paging message is received or appropriate timer value elapses.
[0095] At step 6-7, when the onboard satellite A (102A) is connected to the ground network (702) but cannot connect to the UE (502) e.g., the service link connectivity is unavailable and feeder link connectivity is available, the AMF or MME-onboard may fetch the authentication vectors, subscription details and other possible required parameters from the UDM or the HSS (302) on the ground network (702) and indicate that it is pre-fetching the subscription data without authenticating the UE (502). The gNB or eNB and / or AMF or MME (onboard) may store the received authentication vectors, subscription details and other possible parameters received until the service link is available.
[0096] At step 8, when the service link is available and feeder link connectivity is not available, the on-board AMF or MME may enter UE serving area; it will start paging the UE (502) with the assigned temporary identifier in the partial registration or attach accept message. In an embodiment, the paging message will include a cause IE indicating to complete the registration or attach procedure for the UE (502).
[0097] At step 9, in response to receiving the paging message, the UE (502) may re-send the Registration or Attach request message including the IMSI / SUCI.
[0098] At step 10-11, the UE (502) and gNB / eNB or AMF / MME-onboard may perform the authentication and security procedure with the UE (502), once primary authentication procedure is successful remaining steps may be performed to complete the Registration or Attach procedure with the UE (502). After successful authentication the UE (502) and gNB / eNB and / or AMF / MME may establish the AS, UP, and NAS security context.
[0099] At step 12, further message exchanges may be protected using AS, UP and NAS security context appropriately.
[0100] Fig. 9 is a sequence diagram that illustrates a protection of partial registration / attach accept message using a public key based cryptography while NFs on-board are in possession of key pairs according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A) (including the eNB and MME-onboard), and the ground network (702) are in communication with each other. Each step is explained in further detail below.
[0101] At step 1, the Network on-board (in the satellite A (102A)) may be in possession of private-public key pair required for public key cryptography.
[0102] At step 2, in an embodiment, the UE (502) may receive the public key of the satellite A (102A) in a system information block (SIB) broadcasted by the eNB / gNB on-board. In an embodiment, the UE (502) may be configured with the public key by the NFs on-boarded in the satellite A (102A) as part of UE configuration and / or in the UICC. In an embodiment, the Key Management Server (operator managed / third party provided) may configure the UE (502) with the public key as part of UE configuration and / or in the UICC.
[0103] At step 3, the UE (502) may derive the Temporary Key pair from the public key of the satellite A (102A) and associate and / or map the temporary key with at least one of the gNB / eNB ID, Cell ID, PCI, ARFCN, Satellite ID and other possible parameters. In an embodiment, the UE (502) may encrypt the temporary key using the public key of the satellite A (102A).
[0104] At step 4, when the service link is available (feeder link is not available), if the UE (502) identifies that current serving cell support S&F mode and the UE (502) is allowed to use S&F operation, then the UE (502) may send Registration or Attach Request message to the AMF or MME-onboard (in the satellite A (102A) (as in Fig. 9)). The UE (502) may include at least one of the UE identifier IMSI / SUCI and / or GPSI if possible in the request message. The UE (502) may additionally include the encrypted Temporary key in the registration or Attach Request message. This temporary key will be used to encrypt the partial registration or attach accept message.
[0105] In an embodiment, the GPSI may be included instead of IMSI to ensure the long term permanent identities are not exposed over the air and / or the certificate may include GPSI as the identity of the client (for example, if certificate / public key is issues by third party then long term permanent identities cannot be exposed to the 3rdparty). In an embodiment, the UE (502) may include the security capability more specifically the asymmetric cryptographic information (at least one of the following parameters such as protection scheme like null-scheme or profiles, ECIES, length of the cryptographic keys, size of the MAC, MAC algorithm, Digital Signature algorithm, Encryption algorithm, HASH algorithm, Key Derivation Function, Size of the scheme output, and the like so).
[0106] At step 5, in an embodiment, when the gNB or eNB and / or AMF or MME (onboard) receives the registration or Attach Request message, it may assign a Temporary Identifier for the UE (502). In an embodiment, the gNB or eNB and / or AMF or MME (onboard) may associate or map the assigned Temporary Identifier with at least one of the received IMSI / SUCI and / or GPSI and the Temporary Key (decrypted using the private key of the satellite A (102A)) and store the Registration or Attach Request message until the feeder link is available as part of S&F operation.
[0107] At step 6, as the feeder link is not available, the gNB or eNB and / or AMF or MME-onboard may send a NAS message as Partial registration / attach accept message to the UE (502). The Partial attach accept message may include the Temporary Identifier and other possible parameters encrypted and / or integrity protected using the stored temporary key of the UE (502) (received in Registration / attach request message) considering the received security capability of the UE (502). Further, the parameters / details of the used security mechanism may be included in the Partial registration / attach accept message.
[0108] At step 7, the UE (502) may decrypt the received Partial registration / attach accept message using the temporary private key and store the Temporary Identifier and the received security parameters / details if any in the Partial registration / attach accept message. The UE (502) shall not trigger the registration / attach request again until paging message is received or appropriate timer value elapses.
[0109] At step 8-9, when the onboard satellite A (102A) is connected to the ground network (702) but cannot connect to the UE (502) e.g., the service link connectivity is unavailable and feeder link connectivity is available, the AMF or MME-onboard may fetch the authentication vectors, subscription details and other possible required parameters from the UDM or the HSS (302) on the ground network (702) and indicate that it is pre-fetching the subscription data without authenticating the UE (502). The gNB or eNB and / or AMF or MME (onboard) may store the received authentication vectors, subscription details and other possible parameters received until the service link is available.
[0110] At step 10, when the service link is available and feeder link connectivity is not available, the onboard AMF or MME may enter UE serving area; it will start paging the UE (502) with the assigned temporary identifier in the partial registration or attach accept message. In an embodiment, the paging message will include a cause IE indicating to complete the registration or attach procedure for the UE (502).
[0111] At step 11, in response to receiving the paging message, the UE (502) may re-send the Registration or Attach request message including the IMSI / SUCI.
[0112] At step 12-13, the UE (502) and gNB / eNB or AMF / MME-onboard may perform the authentication and security procedure with the UE (502), once primary authentication procedure is successful remaining steps may be performed to complete the Registration or Attach procedure with the UE (502). After successful authentication the UE (502) and gNB / eNB and / or AMF / MME may establish the AS, the UP, and NAS security context.
[0113] At step 14, further message exchanges may be protected using AS, UP and NAS security context appropriately.
[0114] Fig. 10 is a sequence diagram that illustrates a protection of partial registration / attach accept message using a certificate based cryptography using NFs on-board in possession of certificates according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A) (including the eNB and MME-onboard), and the ground network (702) are in communication with each other. Each step is explained in further detail below.
[0115] At step 1, the network on-board (in the satellite A (102A)) may be in possession of private key and the certificate.
[0116] At step 2, in an embodiment, the UE (502) may receive the public key certificate of the satellite A (102A) in the SIB broadcasted by the eNB / gNB on-board. In another embodiment, the UE (502) may be configured with the public key certificate of the satellite A (102A) by the NFs on-boarded in the satellite A (102A) as part of UE configuration and / or in the UICC. In an embodiment, the CA / RA (operator managed / third party provided) may configure the UE (502) with the certificate and private key as part of UE pre-configuration and / or in the UICC.
[0117] At step 3, the UE (502) may derive the Temporary Key pair from the public key certificate of the satellite A (102A) and associate and / or map the temporary key with at least one of the gNB / eNB ID, Cell ID, PCI, ARFCN, Satellite ID and other possible parameters. In an embodiment, the UE (502) may encrypt the temporary key using the public key certificate of the satellite A (102A).
[0118] At step 4, when the service link is available (feeder link is not available), if the UE (502) identifies that current serving cell support S&F mode and the UE (502) is allowed to use S&F operation, then the UE (502) may send Registration or Attach Request message to the AMF or MME-onboard (in the satellite A (102A) (as in Fig. 10)). The UE (502) may include the at least one of the UE identifier IMSI / SUCI and / or GPSI if possible in the request message. The UE (502) may additionally include the encrypted Temporary key in the registration or Attach Request message. This temporary key will be used to encrypt the partial registration or attach accept message.
[0119] In an embodiment, the GPSI may be included instead of IMSI to ensure the long term permanent identities are not exposed over the air and / or the certificate may include GPSI as the identity of the client (for example, if certificate / public key is issues by third party then long term permanent identities cannot be exposed to the 3rdparty). In an embodiment, the UE (502) may include the security capability more specifically the asymmetric cryptographic information (at least one of the following parameters such as protection scheme like null-scheme or profiles, ECIES, length of the cryptographic keys, size of the MAC, MAC algorithm, Digital Signature algorithm, Encryption algorithm, HASH algorithm, Key Derivation Function, Size of the scheme output, like so).
[0120] At step 5, in an embodiment, when the gNB or eNB and / or AMF or MME (onboard) receives the registration or Attach Request message, it may assign a Temporary Identifier for the UE (502). In an embodiment, the gNB or eNB and / or AMF or MME (onboard) may associate or map the assigned Temporary Identifier with the received IMSI / SUCI and / or GPSI and the Temporary Key (decrypted using the private key of the satellite A (102A)) and store the Registration or Attach Request message until the feeder link is available as part of S&F operation.
[0121] At step 6, as the feeder link is not available, the gNB or eNB and / or AMF or MME-onboard may send a NAS message as Partial registration / attach accept message to the UE (502). The Partial registration / attach accept message may include the generated Temporary Identifier and other possible parameters encrypted and / or integrity protected using the stored temporary key of the UE (502) (received in Registration / attach request message) considering the received security capability of the UE (502). Further, the parameters / details of the used security mechanism may be included in the Partial registration / attach accept message.
[0122] At step 7, the UE (502) may decrypt the received Partial registration / attach accept message using the temporary private key and store the Temporary Identifier and the received security parameters / details if any in the Partial registration / attach accept message. The UE (502) shall not trigger the registration / attach request again until paging message is received or appropriate timer value elapses.
[0123] In an embodiment, in order to verify the network's certificate, the onboard NFs or an entity / module in the satellite A (102A) may be provisioned with the certificate of the root CA who issued the certificate, and to verify the server certificate (certificate of onboard NF or the satellite A (102A)), the UE (502) may be provisioned with the certificate of the root CA who issued the server certificate. One example of the root CA for this purpose is the GSMA CI which is defined in SGP.02.
[0124] At step 8-9, when the onboard satellite A (102A) is connected to ground network (702) but cannot connect to the UE (502) e.g., the service link connectivity is unavailable and feeder link connectivity is available, the AMF or MME-onboard may fetch the authentication vectors, subscription details and other possible required parameters from the UDM or the HSS (302) on the ground network (702) and indicate that it is pre-fetching the subscription data without authenticating the UE (502). The gNB or eNB and / or AMF or MME (onboard) may store the received authentication vectors, subscription details and other possible parameters received until the service link is available.
[0125] At step 10, when the service link is available and feeder link connectivity is not available, the onboard AMF or MME may enter UE serving area; it will start paging the UE (502) with the assigned temporary identifier in the partial registration or attach accept message. In an embodiment, the paging message will include a cause IE indicating to complete the registration or attach procedure for the UE (502).
[0126] At step 11, in response to receiving the paging message, the UE (502) may re-send the Registration or Attach request message including the IMSI / SUCI.
[0127] At step 12-13, the UE (502) and gNB / eNB or AMF / MME may perform the authentication and security procedure with the UE (502), once primary authentication procedure is successful remaining steps may be performed to complete the Registration or Attach procedure with the UE (502). After successful authentication the UE (502) and gNB / eNB and / or AMF / MME may establish the AS, the UP, and NAS security context.
[0128] At step 14, further message exchanges may be protected using AS, UP and NAS security context appropriately.
[0129] Fig. 11 is a sequence diagram that illustrates a protection of partial registration / attach accept message using a TLS Certificate based cryptography using the UE (502) and the NFs-onboard according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A) (including the eNB and MME-onboard), and the ground network (702) are in communication with each other. Each step is explained in further detail below.
[0130] At step 1, the UE (502) and the NFs on-board the satellite A (102A) may be in possession of private key and certificate. In an embodiment, the UE (502) may be configured with the private key and certificates by the Core Network (ground network (702)) as part of UE configuration and / or in the UICC. In an embodiment, the UE (502) may be configured with the private key and certificate by the NFs-onboarded (on the satellite A (102A)) as part of UE configuration and / or in the UICC. In an embodiment, the key management server (operator managed / third party provided) may configure the UE (502) with the certificate and private key as part of UE configuration and / or in the UICC. In an embodiment, the CA / RA (operator managed / third party provided) may configure the UE (502) with the certificate and private key as part of UE pre-configuration and / or in the UICC. In an embodiment, a Security Gateway (SeGW) may be deployed in the satellite A (102A).
[0131] At step 2-3, the UE (502) and NFs onboard in the satellite A (102A) may establish a TLS connection using server side certificates over N1 interface. The further message exchanges may be protected using TLS security association. In an embodiment, in order to verify the certificate of the UE (502), the onboard NFs or an entity / module in the satellite A (102A) may be provisioned with the certificate of the root CA who issued the certificate, and to verify the server certificate (certificate of onboard NF or the satellite A (102A)), the UE (502) may be provisioned with the certificate of the root CA who issued the server certificate. One example of the Root CA for this purpose is the GSMA CI which is defined in SGP.02
[0132] At step 4, when the service link is available (feeder link is not available), if the UE (502) identifies that current serving cell support S&F mode and the UE (502) is allowed to use S&F operation, then the UE (502) may send Registration or Attach Request message to the AMF or MME-onboard (in the satellite A (102A) (as in Fig. 11)). The UE (502) may include the at least one of the UE identifier IMSI / SUCI and / or GPSI if possible in the request message.
[0133] In an embodiment, the GPSI may be included instead of IMSI to ensure the long term permanent identities are not exposed over the air and / or the certificate may include GPSI as the identity of the client (for example, if certificate / public key is issues by third party then long term permanent identities cannot be exposed to the 3rdparty).
[0134] At step 5, in an embodiment, when the gNB or eNB and / or AMF or MME (onboard) receives the registration or Attach Request message, it may assign a Temporary Identifier for the UE (502). In an embodiment, the gNB or eNB and / or AMF or MME (onboard) may associate or map the assigned Temporary Identifier with the received IMSI / SUCI and / or GPSI and store the Registration or Attach Request message until the feeder link is available as part of S&F operation.
[0135] At step 6, as the feeder link is not available, the gNB or eNB and / or AMF or MME-onboard may send a NAS message as Partial registration / attach accept message to the UE (502). The Partial registration / attach accept message may include the Temporary Identifier and other possible parameters.
[0136] At step 7, the UE (502) may store the Temporary Identifier received in the Partial registration / attach accept message. The UE (502) shall not trigger the registration / attach request again until paging message is received or appropriate timer value elapses.
[0137] At step 8-9, when the onboard satellite A (102A) is connected to the ground network (702) but cannot connect to the UE (502) e.g., the service link connectivity is unavailable and feeder link connectivity is available, the AMF or MME-onboard may fetch the authentication vectors, subscription details and other possible required parameters from the UDM or the HSS (302) on the ground network (702) and indicate that it is pre-fetching the subscription data without authenticating the UE (502). The gNB or eNB and / or AMF or MME (onboard) may store the received authentication vectors, subscription details and other possible parameters received until the service link is available.
[0138] At step 10, when the service link is available and feeder link connectivity is not available, the onboard AMF or MME may enter UE serving area; it will start paging the UE (502) with the assigned temporary identifier in the partial registration or attach accept message. This paging message will include a cause IE indicating to complete the registration or attach procedure for the UE (502).
[0139] At step 11, in response to receiving the paging message, the UE (502) may re-send the Registration or Attach request message including the IMSI / SUCI.
[0140] At step 12-13, the UE (502) and gNB / eNB or AMF / MME may perform the authentication and security procedure with the UE (502), once primary authentication procedure is successful remaining steps may be performed to complete the Registration or Attach procedure with the UE (502). After successful authentication the UE (502) and gNB / eNB and / or AMF / MME may establish the AS, UP, and NAS security context.
[0141] At step 14, further message exchanges may be protected using AS, UP and NAS security context appropriately.
[0142] Fig. 12 is a sequence diagram that illustrates KAMF-SATkey derivation per satellite according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A), the satellite B (102B), an AMF-ground (1202), an Authentication Server Function (AUSF) (1204), and a UDM (1206) are in communication with each other.
[0143] In a N1 message to the UE (502), the Security Anchor Function (SEAF) may include the authentication request indication and / or the ciphering and / or the integrity algorithm. Authentication request indication may be to indicate the UE (502) to perform authentication when performing next NAS procedure. The NAS procedure can be Registration procedure or Packet Data Unit (PDU) session establishment / modification procedure or Service request or UL NAS transport, like so. When initiating a NAS procedure, the UE (502) may select an unused sequence number (SQN) / authentication token (AUTN) and corresponding RAND from the stored values. Further the UE (502) may derive the RES* from the selected AUTN and RAND, if not derived when storing the received AUTN and RAND.
[0144] Based on the keys derived from the selected AUTN / SQN and RAND and the network indicated integrity algorithm (non-current 5G security context), the UE (502) may derive the MAC-I on the N1 request message. The UE (502) may then send an N1 message request to the SEAF. The message may include the SUCI or 5G-GUTI, RES*, AUTN and / or RAND and / or SQN, NAS MAC-I and other possible parameters. The NAS MAC-I may be used for integrity protection of the message.
[0145] Upon receiving the N1 message request from the UE (502), the SEAF may store the NAS MAC-I for the later integrity check and / or verification. The SEAF / the AMF-onboard may invoke the Authentication service by sending an Authenticate Request message to the AMF-ground (1202) whenever the SEAF wishes to initiate an authentication. This message may include SUCI or Subscription Permanent Identifier (SUPI), SN-name, AUTN and / or RAND and / or SQN, RES*.
[0146] The AMF-ground (1202) may invoke the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message to the AUSF (1204) whenever the AMF-onboard wishes to initiate an authentication. This message may include SUCI or SUPI, SN-name, AUTN and / or RAND and / or SQN, RES*.
[0147] Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF (1204) may send Nudm_UEAuthentication_Get Request to the UDM (1206), if there is no 5G Home Environment Authentication Vector (5G HE AV) available with the AUSF (1204) for the SUPI. If the AUSF (1204) is able to retrieve the 5G HE AV for the received SUPI and AUTN and / or RAND and / or SQN, then the AUSF (1204) may perform the step 9, skipping steps 6,7 & 8 (interaction with the UDM (1206)).
[0148] The Nudm_UEAuthentication_Get Request sent from the AUSF (1204) to the UDM (1206) may include the following information:
[0149] - SUCI or SUPI;
[0150] - the serving network name;
[0151] - if received from SEAF, Disaster Roaming service indication;
[0152] - AUTN and / or RAND and / or SQN
[0153] - AMF-onboard _ID
[0154] - SAT ID (Satellite ID)
[0155] Upon reception of the Nudm_UEAuthentication_Get Request, the UDM (1206) may invoke Subscription Identifier De-concealing (SIDF) if a SUCI is received. SIDF may de-conceal SUCI to gain SUPI before the UDM (1206) can process the request. The UDM (1206) / ARPF may generate the authentication vectors for the received AUTN and / or RAND and / or SQN and the SUPI. The UDM (1206) may subsequently send the 5G HE AV to the AUSF (1204) using a Nudm_UEAuthentication_Get Response message.
[0156] Upon receiving the Nudm_UEAuthentication_Get Response message from the UDM (1206), the AUSF (1204) may derive the KAUSF. The AUSF (1204) may send the Nausf_UEAuthentication_Authenticate Response message to the SEAF / AMF-ground (1202). Upon receiving the Nausf_UEAuthentication_Authenticate Response message from the AUSF (1204), the SEAF may then compute HRES* from RES* according to 3GPP TS 33.501, and the SEAF may compare HRES* and HXRES*. If they coincide, the SEAF may consider the authentication successful from the serving network point of view. The SEAF / AMF-ground (1202) may derive further keys to establish the NAS security context. In this alternative the SEAF / AMF-ground (1202) may derive the KAMF-SATkeys from the KAMF / KSEAFkey. The input parameters to the Key Derivation Function (KDF) for deriving the KAMF-SATkeys are as following:
[0157] When deriving a KAMF-SAT1from KSEAF / KAMFthe following parameters should be used to form the input S to the KDF.
[0158] - FC = 0xxx
[0159] - P0 = SAT1 ID
[0160] - L0 = length of SAT1 ID
[0161] - P1 = Freshness parameter / random number / index
[0162] - L1 = Length of Freshness parameter / random number / index
[0163] And other possible parameter
[0164] The input key KEY shall be the 256-bit KSEAF / KAMF.
[0165] In an embodiment, the KAMFand KAMF-SATmay be same and the input key for the derivation may be KSEAF. Upon successful key derivation, the AMF-ground (1202) may send the Authentication response message to the AMF-onboard of the satellite A (102A). This message may include the newly derived KAMF-SAT1key, 5G SE AV, Result and other possible parameters. The AMF-onboard may send the N1 message to the UE (502). This message may include ngKSI (either generated or the received ngKSI from the UE (502)), UE security capabilities, NAS MAC-I, Freshness parameter and other possible parameters.
[0166] In an embodiment, the freshness parameter may be provided to the UE (502) in the N1 message / Registration response / Authentication response. Upon receiving the N1 message from the SEAF, the UE (502) may derive the KAMF-SAT1and KAMF-SAT2for both the satellite A (102A) and the satellite B (102B). Soon after deriving the KAMF-SAT2key, the AMF-ground (1202) may push the KAMF-SAT2key to the AMF-onboard in the satellite B (102B). Upon receiving the KAMF-SAT2key from the AMF-ground (1202), the AMF-onboard may store the key for the later use.
[0167] When the satellite A (102A) goes out of coverage or if the connection is lost by any means, the UE (502) may connect via the satellite B (102B). The authentication and NAS Security Mode Command (SMC) procedure may follow as it is performed for the satellite A (102A) connection. In the N1 response message, the AMF-on board from the satellite B (102B) may send the key indication to the UE (502). Upon receiving the N1 response, the UE (502) checks if there is any key indication. If yes, the UE (502) may derive the KAMF-SAT2.
[0168] When deriving a KAMF-SAT2from KSEAF / KAMFthe following parameters should be used to form the input S to the KDF.
[0169] - FC = 0xxx
[0170] - P0 = SAT2 ID
[0171] - L0 = length of SAT2 ID
[0172] - P1 = Freshness parameter / random number / index
[0173] - L1 = Length of Freshness parameter / random number / index
[0174] And other possible parameter
[0175] The input key KEY shall be the 256-bit KSEAF / KAMF.
[0176] Fig. 13 is a sequence diagram that illustrates NAS key derivation per satellite according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A), the satellite B (102B), and the AMF-ground (1202) are in communication with each other.
[0177] Upon receiving the N1 response from the AMF-onboard (satellite A (102A)), the UE (502) may derive the KAMF-SAT1, and KAMF-SAT2from the KAMF / KSEAF. Once the KAMF-SATkeys are derived for the respective keys, the UE (502) may also derive the KNASintegrity and encryption keys. When deriving a KNASint1from KAMF-SAT1the following parameters should be used to form the input S to the KDF.
[0178] - FC = 0xxx
[0179] - P0 = N-NAS Integrity Algo
[0180] - L0 = length of N-NAS Integrity Algo
[0181] - P1 = Algo ID
[0182] - L1 = length of Algo ID
[0183] And other possible parameter
[0184] The input key KEY shall be the KAMF-SAT1.
[0185] When deriving a KNASenc1from KAMF-SAT1the following parameters should be used to form the input S to the KDF.
[0186] - FC = 0xxx
[0187] - P0 = N-NAS ciphering Algo
[0188] - L0 = length of N-NAS Ciphering Algo
[0189] - P1 = Algo ID
[0190] - L1 = length of Algo ID
[0191] And other possible parameter
[0192] The input key KEY shall be the KAMF-SAT1.
[0193] Upon successful Authentication at the network side, the AMF-ground (1202) may derive the KAMF-SATkeys and the KNASintand KNASenckeys for both the satellite A (102A) and the satellite B (102B) respectively. When deriving a KNASint1from KAMF-SAT1the following parameters should be used to form the input S to the KDF.
[0194] - FC = 0xxx
[0195] - P0 = N-NAS Integrity Algo
[0196] - L0 = length of N-NAS Integrity Algo
[0197] - P1 = Algo ID
[0198] - L1 = length of Algo ID
[0199] And other possible parameter
[0200] The input key KEY shall be the KAMF-SAT1.
[0201] When deriving a KNASenc1from KAMF-SAT1the following parameters should be used to form the input S to the KDF.
[0202] - FC = 0xxx
[0203] - P0 = N-NAS ciphering Algo
[0204] - L0 = length of N-NAS Ciphering Algo
[0205] - P1 = Algo ID
[0206] - L1 = length of Algo ID
[0207] And other possible parameter
[0208] The input key KEY shall be the KAMF-SAT1.
[0209] Similarly in an embodiment, the keys will be derived for the satellite B (102B) using the same input parameters except the respective satellite IDs. Once the KNASintand KNASenckeys are derived for the respective satellites, the AMF-ground (1202) may push the keys to the AMF-onboard in each respective satellites.
[0210] In an embodiment, instead of the AMF-ground (1202) deriving and pushing the KNASencand KNASintkeys to the AMF-onboard, the AMF-ground (1202) may only push the KAMF-SATkeys to the respective satellites including other possible parameters to derive the NAS integrity and encryption keys at the AMF-onboard.
[0211] In an embodiment, the AMF-onboard may derive the KNASencand KNASintkeys using the input parameters as detailed in the Alternative 1 of the solution. Upon receiving the KNASintand KNASenckeys,the AMF-onboard may store the keys and start the integrity protection / NAS SMC procedure as detailed in TS 33.501. Steps 4 to 6 may be performed as detailed in TS 33.501 for the NAS SMC procedure.
[0212] In an embodiment, the freshness parameter may be provided to the UE (502) in the NAS Security mode command message once the UE (502) is successfully authenticated with the core network to further derive the NAS keys. In an embodiment, the procedure for the key derivation and distribution to multiple satellites may be followed respectively for the EPS network.
[0213] Fig. 14 is a schematic diagram that illustrates KAMF-SATderivation function according to an embodiment as disclosed herein. It is assumed that the KAMFis the input key to the KDF (1402) for the KAMF-SATderivation.
[0214] Fig. 15 is a schematic diagram that illustrates the KAMF-SATderivation function according to an embodiment as disclosed herein. It is assumed that the KSEAFis the input key to the KDF (1402) for the KAMF-SATderivation. In an embodiment, it is assumed that the KAMF-SATand theKAMF-SATare same.
[0215] Fig. 16 is a schematic diagram that illustrates KNASintderivation function according to an embodiment as disclosed herein. It is assumed that the KAMF-SATis the input key to the KDF for the KNASintderivation.
[0216] Fig. 17 is a schematic diagram that illustrates KNASencderivation function according to an embodiment as disclosed herein. It is assumed that the KAMF-SATis the input key to the KDF for the KNASencderivation.
[0217] Fig. 18 is a sequence diagram that illustrates a scenario where the UE (502) selects another PDU session in case of satellite unavailability according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), the satellite A (102A) (including gNB-1 and UPF-1), the satellite B (102B) (including gNB-2 and UPF-2), an AMF (1802), a Session Management Function-1 (SMF-1) (1804A), a SMF-2 (1804B), a UPF (1806), and the UDM (1206) are in communication with each other.
[0218] Based on the local configuration, the AMF (1802) may identify the gNB ID associated with the satellite ID (e.g., the global Radio Access Network (RAN) node IDs associated with the satellite Backhaul). In an embodiment, the OAM may configure and / or provide the mapping and / or association of satellite ID with global RAN node ID. In an embodiment, the UE (502) may be preconfigured and / or may create the list of satellites available for the given location or the route. In an embodiment, the network may be preconfigured and / or may create the list of satellites available for the given location or the route of the UE (502).
[0219] In step 1, the UE (502) may decide to establish PDU session with the satellite A (102A) and the satellite B (102B). The UE (502) may be preconfigured or may determine the list of satellites that can serve the UE (502) for the given location and / or for the given path / route. The UE (502) may send the NAS message (PDU session establishment request) to the AMF (1802) as detailed in the TS 23.502. The UE (502) may include the NAS Message (Single - Network Slice Selection Assistance Information (S-NSSAI)(s), [Alternative S-NSSAI], UE Requested Data Network Name (DNN), PDU Session ID, Request type, Old PDU Session ID, N1 session management (SM) container (PDU Session Establishment Request, [Port Management Information Container])) and additionally the satellite ID (if available) and other possible parameters. In an embodiment, if the UE (502) determines redundant PDU sessions to be created (for example, based on the DNN and / or the configuration provided by the network via UE Route Selection Policy (USRP) or UE Configuration Update, like so), then the UE (502) may include the redundant PDU session indication to the AMF (1802).
[0220] In step 2, on receiving the request from the UE (502), the AMF (1802) may perform the SMF selection. Once the SMF is selected for the particular PDU session creation, the AMF (1802) may send the Nsmf_PDUsession_create context Request to the SMF.
[0221] In step 3, if Session Management Subscription data for corresponding SUPI, DNN and S-NSSAI of the Home Public Land Mobile Network (HPLMN) is not available, then SMF may retrieve the Session Management Subscription data using Nudm_SDM_Get (SUPI, Session Management Subscription data, selected DNN, S-NSSAI of the HPLMN, Serving PLMN ID, [NID]) and subscribe to be notified when this subscription data is modified as detailed in TS 23.502. On retrieving the subscription data from the UDM, the SMF may also select one or more UPFs as needed as detailed in clause 6.3.3 of TS 23.501. In the case of PDU Session Type IPv4 or IPv6 or IPv4v6, the SMF may allocate an IP address / prefix for the PDU Session (unless configured otherwise) as described in clause 5.8.2 of TS 23.501. For the PDU session type, the SMF will perform UPF selection to select the UPF (1806) as the anchor of this PDU Session as detailed in TS 23.502.
[0222] In step 4, the PDU session may be established between the UE (502), gNB-1 and the UPF-1. In addition, the PDU session may be established the redundant PDU sessions with the gNB-2 of the satellite B (102B) and gNB-3 of satellite 3. The PDU session may be established using the same PDU session ID and the tunnel ID for all the redundant connections. The list of satellites with which the PDU session has to be established may be either provided by the UE (502) or determined by the SMF.
[0223] Based on the PDU session establishment request, the SMF may establish the PDU session with multiple UPFs and also provide PDU session establishment accept message to the UE (502) appropriately via multiple AMFs, whenever the link (feeder link) is available with the UPF (1806) and / or the AMF (1802). The AMF (1802) may send the N2 PDU session request to the gNB to allocate resources and establish the session with the UPF (1806). The AMF (1802) may send the PDU session establishment accept message to the UE (502) whenever connectivity (service link) with the UE (502) is available. In an embodiment, the SMF may send the PDU Nsmf_PDUsession_create context Request message to the appropriate SMF(s), which have N4 connectivity with the determined UPFs.
[0224] In step 5, upon receiving the PDU session establishment accept message, the UE (502) may store the PDU contexts and send the uplink user plane data with the available satellite.
[0225] In step 6, the radio link between the UE (502) and the gNB-1 may be lost due to the connectivity issue and / or the UE (502) moved out of coverage and / or poor signal. In an embodiment, the satellite A (102A) may not be reachable for the UE (502). For example, if the RLF (Radio link failure) is detected for the SCG (NR cell) failure, the UE (502) may suspend the SCG transmission for all the radio bearers and report the SCG failure information to the gNB.
[0226] In step 7, the UE (502) may maintain the ongoing PDU session with the gNB-1 in the satellite A (102A) as the satellite may serve the UE (502) later once the connection is re-established.
[0227] In step 8, the UE (502) may determine that the satellite A (102A) is not reachable and decide to select another satellite in which it has already established the PDU session (based on the received PDU session establishment accept message). In an embodiment, the UE (502) may decide to send the indication to the gNB2 in the satellite B (102B). The message may include the SUPI, PDU session ID, Tunnel ID, redundant PDU indication, SN ID, Redundancy Sequence Number (RSN) and other possible parameters. In an embodiment, using the NAS message the UE (502) may also send an indication to the home network (AMF) about the change in the serving satellite.
[0228] In step 9, the UE (502) may move into the coverage of the satellite B (102B). Between the UE (502) and the gNB-2, the already created PDU session may be used with the same PDU session ID and the Tunnel ID as used by the UE (502) with the satellite A (102A). In an embodiment, the UE (502) may use the same user plane data between the satellite B (102B) using a Different PDU session ID and / or Tunnel ID different from the one used with the satellite A (102A). In this alternative, the SMF may indicate to the PSA UPF that one tunnel info is used as the redundancy tunnel of the PDU session. Upon receiving the request from the AMF (1802) for the PDU session establishment, the SMF may retrieve the subscription data from the UDM (1206) and select the UPF (1806) (SMF-1 (1804A) selects UPF 1 and the SMF-2 (1804B) selects UPF 2 respectively).
[0229] Figs. 19A and 19B are a sequence diagram that illustrates a scenario where the UE (502) switches the PDU based on uplink unavailability according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), a NG-RAN1 (1902A), a NG-RAN2 (1902B), the AMF (1802), a SMF (1804), a UPF-1 (1806A), a UPF-2 (1806B), and the UDM (1206) are in communication with each other.
[0230] In step 1, if the UE (502) is not registered via 3GPP access, the UE (502) may initiate Registration procedure via 3GPP access and send the NAS message over the RAN1. The UE (502) may send a PDU Session Establishment Request message with a new PDU Session ID and Request Type = "initial request". The UE (502) may also include an Multi-access Packet Data Unit (MA-PDU) Capability flag to indicate to the network that it can support MA-PDU sessions. The UE (502) may also include the PDU session ID, Request type which includes if the request is for MA PDU session or not, and the RSN and the PDU Session pair ID in the PDU session request message.
[0231] In step 2, the AMF (1802) may select the SMF (1804) as described in clause 4.3.2.2.3 of TS 23.502. In this step, the AMF (1802) may store Access Type of the PDU Session = "3GPP access". When the AMF (1802) received the MA-PDU Capability flag and it supports MA-PDU sessions, it may include an MA-PDU Capability flag in the Nsmf_PDUSession_CreateSMContext Request message sent to SMF. This message may additionally also include the PDU session ID, RSN, and the PDU session pair ID.
[0232] In step 3, the SMF (1804) may register with the UDM (1206) for the subscription data retrieval.
[0233] In step 4, the SMF (1804) may send the Create SM context Response message to the AMF (1802).
[0234] If needed, in step 5, the secondary authorization and / or authentication procedure may take place, as specified in TS 23.502, clause 4.3.2.3.
[0235] In step 6, the SMF (1804) may perform the UPF selection.
[0236] In step 7, the SMF (1804) may send the N4 session establishment request to the UPF-1 (1806A) as detailed in TS 23.502.
[0237] In step 8, the UPF-1 (1806A) may send the N4 session establishment response to the SMF (1804) as detailed in TS 23.502
[0238] In steps 9-12, if the PCF permits the use of MA-PDU procedures for the requested PDU session (e.g. to later establish another child PDU over non-3GPP access), the SMF (1804) may send a PDU Session Establishment Accept message with a MA-PDU Capability flag to inform the UE (502) that the network can support MA-PDU procedures for this PDU session. Otherwise, the SMF (1804) may accept the PDU Session establishment but does not include the MA-PDU Capability flag in the PDU Session Establishment Accept message. If the MA-PDU Capability flag is received by the UE (502), the UE (502) may later add another child PDU session to the existing PDU session with the steps below (steps 13-15).
[0239] In step 13, the UE (502) may send the first uplink data message to the Next Generation Radio Access Network (NGRAN) node over the 3GPP access. It is assumed that the uplink may be unavailable for the UE (502) that supports the MA PDU.
[0240] In step 14, the UE (502) may determine that the satellite is out of coverage and / or not reachable and therefore the PDU session is unavailable for the UE (502).
[0241] In such scenarios, in step 15, the UE (502) should not trigger the PDU session release procedure and the UE (502) shall retain the PDU session related info and store and forward info for the satellite A (102A). The UE (502) shall keep pinging the satellite A (102A) to check the availability of the satellite A (102A).
[0242] Similar steps may also be performed (steps 6 to step 13), if the MA PDU session type is "non-3GPP access". The UE (502) may determine that the PDU session is not available over the first 3GPP access and continue with uplink data transmission over 3GPP2 and / or non-3gpp access.
[0243] Fig. 20 is a schematic diagram that illustrates a scenario where the same PDU session is maintained between both 3GPP and non-3GPP access according to an embodiment as disclosed herein. In this alternative, the UE (502) may establish communication with the satellite A (102A) using the 3GPP access, whereas the UE (502) may establish communication with the satellite B (102B) using the non-3GPP access. Here for both the 3GPP access and the non-3GPP access, the gNB and the UPF (1806) may maintain the same PDU sessions (e.g., the PDU session ID, Tunnel ID and other parameters). In an embodiment, the AMF (1802) may be the same for both the 3GPP access and the non-3GPP access. Based on the local configuration, the AMF (1802) may have prior knowledge of the mapping of the gNB ID and the Satellite ID (SAT ID where the gNB is deployed).
[0244] Fig. 21 is a schematic diagram that illustrates a scenario where the same PDU session is maintained between both 3GPP and non-3GPP access according to an embodiment as disclosed herein. In this alternative, the UE (502) may be connected to both the satellites using the 3GPP access. Whenever there is a Radio link failure, the UE (502) may select the other satellite in its coverage and uses the same PDU session with the satellite B (102B). The gNB2 and the UPF (1806) may maintain the user plane data and establish the PDU session.
[0245] In an embodiment, the UE (502) may use the same PDU session ID for the PDU session establishment with multiple satellites (gNBs and UPFs) or alternatively, the UE (502) may maintain the mapping of the PDU Session IDs and Sat ID and / or TAI and / or gNB ID and / or Physical cell ID (PCI) and / or absolute radio-frequency channel number (ARFCN), like so) for the PDU session. The UE (502) may include multiple PDU session IDs in the PDU session establishment request, if determined that the PDU session to be established with multiple satellites (gNBs and UPFs). If the UPFs (1806A, 1806B) are located in the satellites respectively, and the gNB1 (from satellite A (102A)) and the gNB2 (from satellite B (102B)) connects to the UPF-1 (1806A) (I-UPF). Both the UPFs (1806A, 1806B) from the satellites may be connected to a PSA-UPF in the ground. Between the intermediate UPF (1806) and the gNBs (gNB1 and gNB2), the same PDU sessions may be maintained.
[0246] Fig. 22 is a schematic diagram that illustrates a process of key derivation in dual connectivity according to an embodiment as disclosed herein. In an embodiment, the satellite-ID / gNB-ID may be included as the input parameter to the key derivation of gNB and / or KSN. These derived KSNsmay be pushed to the satellites which can serve the UE (502) (list of allowed satellites which can serve the UE (502) and / or the satellite A (102A) has Inter-satellite link (ISL) with). In an embodiment, MN may derive the AS keys as well from the KSNand provide the AS context to each satellite.
[0247] Fig. 23 is a sequence diagram that illustrates key derivation and handling during dual connectivity in satellite communication according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (502), a MN (2302), a SN-1 (2304A), and a SN-2 (2304B) are in communication with each other. The MN (2302) may be configured with Sat-IDs based on Satellite backhaul category and the MN (2302) may derive corresponding KSN-SATfor each satellite in the list and pushes the keys when the MN (2302) triggers SN addition with the SN on-board.
[0248] In step 1, the UE (502) and the MN (2302) may establish the RRC connection.
[0249] In step 2, the MN (2302) may send SN Addition / Modification Request to the SN to negotiate the available resources, configuration, and algorithms at each SN (2304A, 2304B) at the satellites. The MN (2302) may compute and deliver the KSNfor each SN (2304A, 2304B). The UE security capabilities and the UP security policy received from the SMF may also be sent to each SN (2304A, 2304B). In an embodiment, the SMF may send the UP security policies associated with each SN (2304A, 2304B) to the MN (2302). When the MN (2302) decides to configure CPA or CPC, if there are more than one candidate SNs, for each SN (2304A, 2304B), the MN (2302) shall derive a different KSNand delivers the KSNto each SN separately.
[0250] In steps 3-7, the UE (502), MN (2302), and SN follow the same procedure as in dual connectivity. When the UE (502) determines that the satellite A (102A) serving it is not able to serve (UE / satellite moves out of coverage area) the UE (502) may establish RRC connection with SN-2 (2304B) (Sat-C) when SN-1 (2304A) (Sat-B) is unavailable (SN-2 (2304B) is indicated to use the context derived from KSN-SAT-2).
[0251] In an embodiment, the unique KSEAFmay be derived for each AMF (may be on-board) by the UE (502) and the AUSF from KAUSF. KSEAFmay be provided by AUSF to the SEAF. The following one or more parameters shall be used to form the input to the KDF along with other possible parameters: IMSI, Network Access Identifier (NAI), GCI, GLI, ABBA, Global Unique AMF ID (GUAMI), AMF Identifier (AMFI), SN name, NAS UL / DL Count. KAMFmay be a key derived by ME and SEAF from KSEAF.
[0252] In an embodiment, unique KAMFmay be derived for each SEAF / AMF (may be on-board) by the UE (502) and the SEAF from KSEAF. The following one or more parameters shall be used to form the input to the KDF along with other possible parameters: IMSI, Network Access Identifier (NAI), GCI, GLI, ABBA, Global Unique AMF ID (GUAMI), AMF Identifier (AMFI).
[0253] In an embodiment, the unique Access stratum key (KgNB) may be derived for each gNB (may be on-board). The following one or more parameters shall be used to form the input to the KDF along with other possible parameters: Uplink NAS COUNT, Access type distinguisher, gNB ID, Satellite ID, TAI, PCI, ARFCN.
[0254] In an embodiment, the UE (502) and the AMF may perform NAS Security Mode Command procedure when the registered UE connects with the AMF (on-board) upon re-establishing the service link with the Satellite to ensure that the security context in the UE and in the AMF are in synchronization.
[0255] In an embodiment, the UE (502) and the gNB may perform AS Security Mode Command procedure when the registered UE connects with the gNB (on-board) upon re-establishing the service link with the Satellite.
[0256] Fig. 24 is a flow diagram that illustrates a method for protecting a registration or attach procedure using a certificate based cryptography by the UE (502) according to an embodiment as disclosed herein. The method may include steps (2402-2412). Each step is explained in further detail below.
[0257] At step (2402), the UE (502) may pre-configure a private key and a certificate at the UE (502) based on an operator policy. The certificate may include a public key of the UE (502). The operator policy may outline the security measures and standards necessary for safeguarding user data and maintaining network integrity. The private key may be employed to encrypt information and verify the identity of the UE (502) during communication sessions. This private key may be kept confidential and securely stored within the UE (502), guaranteeing that only the authorized device can access and use it for secure transactions. Additionally, the certificate may serve as an extra layer of security and contain the public key linked to the UE (502).
[0258] At step (2404), the UE (502) may generate a registration or attach request message by adding the certificate including the public key of the UE (502). The registration or attach request message may be crucial for establishing a connection between the UE (502) and the network. To enhance the security and integrity of this communication, the UE (502) may incorporate the certificate into the registration or attach request message.
[0259] At step (2406), the UE (502) may transmit the registration or attach request message to an on-board network apparatus (602). For instance, the on-board network apparatus (602) may include a next generation node B (gNB), an evolved node B (eNB), an access and mobility management function (AMF), and a mobility management entity (MME).
[0260] At step (2408), the UE (502) may receive a partial attach registration or accept message from the on-board network apparatus (602) in response to the registration or attach request message. The partial attach registration or accept message may be received upon successful verification of the certificate by the on-board network apparatus (602). The partial attach registration or accept message may be encrypted using the public key of the UE (502). The partial attach registration or accept message may include a temporary identifier for the UE (502) and a security parameter. This temporary identifier may act as a distinct reference for the UE (502) throughout the current session, enabling the on-board network apparatus (602) to efficiently oversee and monitor the connection. Additionally, the security parameter may encompass details pertaining to encryption keys, authentication tokens, or other security-related information essential for creating a secure communication link between the UE (502) and the on-board network apparatus (602).
[0261] At step (2410), the UE (502) may decrypt the received encrypted partial registration or attach accept message using the private key preconfigured at the UE (502). The decryption procedure may include utilizing the private key to undo the encryption that was applied to the message before it was sent. This may guarantee that only those with the appropriate private key are able to understand the message's contents. The encrypted partial registration or attach accept message may hold essential information required for creating or sustaining a connection between the UE (502) and the on-board network apparatus (602).
[0262] At step (2412), the UE (502) may store the identifier and the security parameter decrypted from the partial registration or attach accept message.
[0263] Fig. 25 is a flow diagram that illustrates a method for protecting a registration or attach procedure using a certificate based cryptography by the on-board network apparatus (602) according to an embodiment as disclosed herein. The method may include steps (2502-2516). Each step is explained in further detail below.
[0264] At step (2502), the on-board network apparatus (602) may receive a registration or attach request message from the UE (502). The registration or attach request message may include a public key and a certificate associated with the UE (502). The certificate may include the public key of the UE (502). The public key may serve to encrypt data, which can only be decrypted by its associated private key, thereby safeguarding sensitive information throughout its transmission. A trusted certificate authority (CA) may issue the certificate. This certificate may contain details such as the identity of the UE (502), the certificate's validity period, and the CA's digital signature, which confirms the certificate's authenticity, among other information.
[0265] At step (2504), the on-board network apparatus (602) may verify the certificate of the UE (502).
[0266] At steps (2506-2508), the verification may be carried out by provisioning a root certificate of a root CA that issued the certificate of the UE (502) at the on-board network apparatus (602). The certificate of the UE (502) may be verified based on the provisioned root certificate of the root CA. The root certificate may serve as a trusted anchor for the entire authentication framework. The installation of the root certificate may be performed on the on-board network apparatus (602), which acts as a gateway for managing and verifying the certificates of the UE (502).
[0267] At step (2510), the on-board network apparatus (602) may generate a temporary identifier for the UE (502) upon successful verification of the certificate of the UE (502). The implementation of a temporary identifier may improve privacy and security by reducing the likelihood of unauthorized access and safeguarding the true identity of the UE (502) against potential threats.
[0268] At step (2512), the on-board network apparatus (602) may generate a partial attach registration or accept message to be transmitted to the UE (502) upon generation of the temporary identifier. The partial attach registration or accept message may include essential information that indicates the current status of the UE (502) in the network and may include details such as the temporary identifier itself, network capabilities, and any relevant parameters that the UE (502) needs to be aware of for further communication. The partial attach registration or accept message may be crucial for establishing a secure and efficient connection between the UE (502) and the on-board network apparatus (602). This may allow the UE (502) to proceed with its registration process while ensuring that it is duly recognized and authenticated.
[0269] At step (2514), the on-board network apparatus (602) may encrypt the partial registration or attach accept message using the public key of the UE (502). The partial registration or attach accept message may include the generated temporary identifier and security parameters. The security parameters may be critical for establishing a secure communication channel between the UE (502) and the on-board network apparatus (602). For instance, the security parameters may include encryption procedures, integrity protection mechanisms, and other security-related information that ensures the confidentiality and integrity of the data being transmitted.
[0270] At step (2516), the on-board network apparatus (602) may transmit the encrypted partial registration or attach accept message to the UE (502).
[0271] The principal object of an embodiment herein may be to protect a registration or attach procedure using a certificate based cryptography.
[0272] Another object of an embodiment herein may be to protect registration or attach procedure without public data network (PDN) connectivity in S&F operation.
[0273] Yet another object of an embodiment herein may be to protect partial registration / attach accept message using a public key cryptography.
[0274] Yet another object of an embodiment herein may be to protect partial registration / attach accept message using a transport layer security (TLS) certificate.
[0275] Yet another object of an embodiment herein may be to provide a system and method for isolation of non-access stratum (NAS) keys in S&F operating mode.
[0276] Another object of an embodiment herein may be to provide a method to derive the NAS security context for example, a KAMF-SATkey at the ground from the KAMFand distribute to the AMF-onboard when the feeder link is available.
[0277] Yet another object of an embodiment herein may be to provide a method to derive the NAS security context for example, KAMF-SATkey at the ground from the security anchor function key (KSEAF) and distribute to the AMF-onboard when the feeder link is available.
[0278] Yet another object of an embodiment herein may be to provide a method to derive a KNASintand KNASenckey at the ground and distribute it to the AMF-onboard when the feeder link is available.
[0279] Yet another object of an embodiment herein may be to provide a method to derive the KNASintand KNASencat the AMF-onboard using the KAMF-SATkey received from the AMF-ground after the successful authentication procedure.
[0280] Yet another object of an embodiment herein may be to provide a method to isolate the NAS keys for the satellites, in case multiple satellites are serving the UE.
[0281] Yet another object of an embodiment herein may be to disclose systems and methods for handling PDU sessions in S&F 5G satellite communication operations.
[0282] Yet another object of an embodiment herein may be to disclose systems and methods for establishing a PDU session of a UE across multiple gNBs and / or user plane functions (UPFs) in S&F 5G satellite communication operations.
[0283] Yet another object of an embodiment herein may be to disclose systems and methods for handling PDU sessions in S&F 5G satellite communication operations, where the same PDU session IDs is used between all gNBs and UPFs serving the UE.
[0284] Yet another object of an embodiment herein may be to disclose systems and methods for handling PDU sessions in S&F 5G satellite communication operations, wherein the same tunnel IDs is used between all the gNBs and UPF serving the UE.
[0285] Yet another object of an embodiment herein may be to disclose systems and methods for handling PDU sessions in S&F 5G satellite communication operations, wherein redundant (two or more than two) multi-access PDU sessions are maintained over two 3GPP access and / or 3GPP and non-3GPP access.
[0286] Yet another object of an embodiment herein may be to disclose systems and methods for handling PDU sessions in S&F 5G satellite communication operations, wherein the session related and S&F information are retained both at the UE and the satellite even when the UE goes out-of-coverage, or the satellite is unavailable.
[0287] Yet another object of an embodiment herein may be to disclose systems and methods for key derivation and handling in S&F 5G satellite communication operations.
[0288] Yet another object of an embodiment herein may be to disclose systems and methods for releasing PDU Session to release all the resources associated with a PDU Session in one or more than one gNB and / or UPF.
[0289] In an embodiment, the objectives are achieved by providing a method performed by a UE for protecting a registration or attach procedure using a certificate based cryptography. The method may include pre-configuring a private key and a certificate at the UE based on an operator policy. The method, wherein the certificate may include a public key of the UE. The method may include generating a registration or attach request message by adding the certificate including the public key of the UE. The method may include transmitting the registration or attach request message to an on-board network apparatus. The method may include receiving a partial attach registration or accept message from the network apparatus in response to the registration or attach request message. The method, wherein the partial attach registration or accept message may be encrypted using the public key of the UE. The method, wherein the partial attach registration or accept message may include a temporary identifier for the UE. The method may include decrypting the received encrypted partial registration or attach accept message using the private key preconfigured at the UE. The method may include storing the temporary identifier decrypted from the partial registration or attach accept message.
[0290] In an embodiment, the method, wherein the partial attach registration or accept message may be received upon successful verification of the certificate by the on-board network apparatus.
[0291] In an embodiment, the method, wherein the UE may be pre-configured with the private key and the certificate by a core network as part of at least one of a UE configuration and in a universal integrated circuit card (UICC).
[0292] In an embodiment, the method, wherein the partial attach registration or accept message comprises one or more parameters associated with a security capability of the UE.
[0293] In an embodiment, the method may include refraining, by the UE, from triggering another registration or attach request message to the on-board network apparatus until a paging message is received or a predetermined timer value elapses.
[0294] In an embodiment, the method may include receiving a paging message on the temporary identifier to complete registration of the UE with the on-board network apparatus. The method may include transmitting, by the UE, an attach or registration request message to the on-board network apparatus upon receiving the paging message, wherein the attach or registration request message comprises an IMSI and SUCI of the UE. The method may include establishing at least one of an AS security context, a UP security context and a NAS security context. The method may include transmitting communication with the on-board network apparatus using at least one of the AS security context, the UP security context and the NAS security context.
[0295] In an embodiment, the method may include determining whether at least one of a paging message has been received from the on-board network apparatus and a time value of a timer associated with the UE has elapsed. The method may include retransmitting the registration or attach request message to the on-board network apparatus only upon receiving the paging message or when the timer value of the timer associated with the UE has elapsed.
[0296] In an embodiment, the objectives are achieved by providing a method performed by an on-board network apparatus for protecting a registration or attach procedure using certificate based cryptography. The method may include receiving a registration or attach request message from a UE. The method, wherein the registration or attach request message may include a public key and a certificate associated with the UE. The method, wherein the certificate may include a public key of the UE. The method may include verifying the certificate of the UE. The method may include generating a temporary identifier for the UE upon successful verification of the certificate of the UE. The method may include generating a partial attach registration or accept message to be transmitted to the UE upon generation of the temporary identifier. The method may include encrypting the partial registration or attach accept message using the public key of the UE. The method, wherein the partial registration or attach accept message may include the generated temporary identifier. The method may include transmitting the encrypted partial registration or attach accept message to the UE.
[0297] In an embodiment, the method, wherein verifying the certificate of the UE may include provisioning a root certificate of a root certificate authority (CA) that issued the certificate of the UE at the on-board network apparatus. The method, wherein verifying the certificate of the UE may include verifying the certificate of the UE based on the provisioned root certificate of the root CA.
[0298] In an embodiment, the method may include receiving authentication vectors and subscription details from a UDM or a HSS on a ground network. The method may include storing the authentication vectors, the subscription details received until a service link is available. The method, wherein the service link may be unavailable when an onboard satellite A is connected to the ground network and is cannot connect to the UE and a feeder link connectivity is available at the on-board network apparatus.
[0299] In an embodiment, the method may include entering into a UE serving area when a service link is available and a feeder link connectivity is not available. The method may include generating a paging message to be transmitted to the UE upon entering into the UE serving area. The method may include receiving a re-transmission of the registration or attach request message from the UE upon receiving the paging message. The method, wherein the registration or attach request message may be retransmitted only upon transmission of the paging message to the UE or when a timer value of a timer associated with the UE has elapsed.
[0300] In an embodiment, the method, wherein the on-board network apparatus may include at least one of a next generation node B (gNB), an evolved node B (eNB), an access and mobility management function (AMF), and a mobility management entity (MME).
[0301] In an embodiment, the objectives are achieved by providing a UE for protecting a registration or attach procedure using a certificate based cryptography. The UE may include a memory, a processor coupled to the memory, and a registration protection controller communicatively coupled to the processor and the memory. The registration protection controller may pre-configure a private key and a certificate at the UE based on an operator policy. The certificate may include a public key of the UE. The registration protection controller may generate a registration or attach request message by adding the certificate including the public key of the UE. The registration protection controller may transmit the registration or attach request message to an on-board network apparatus. The registration protection controller may receive a partial attach registration or accept message from the network apparatus in response to the registration or attach request message. The partial attach registration or accept message may be received upon successful verification of the certificate by the on-board network apparatus. The partial attach registration or accept message may be encrypted using the public key of the UE. The partial attach registration or accept message may include a temporary identifier for the UE. The registration protection controller may decrypt the received encrypted partial registration or attach accept message using the private key preconfigured at the UE. The registration protection controller may store the temporary identifier decrypted from the partial registration or attach accept message.
[0302] In an embodiment, the UE, wherein the registration protection controller may refrain the UE from triggering another registration or attach request message to the on-board network apparatus (602) until a paging message is received or a predetermined timer value elapses.
[0303] In an embodiment, the UE, wherein the registration protection controller may receive a paging message on the temporary identifier to complete registration of the UE with the on-board network apparatus. The registration protection controller may transmit an attach or registration request message to the on-board network apparatus upon receiving the paging message, wherein the attach or registration request message comprises an IMSI and SUCI of the UE. The registration protection controller may establish at least one of an AS security context, an UP security context and a NAS security context. The registration protection controller may transmit a communication with the on-board network apparatus using at least one of the AS security context, the UP security context and the NAS security context.
[0304] In an embodiment, the UE, wherein the registration protection controller may determine whether at least one of a paging message has been received from the on-board network apparatus and a time value of a timer associated with the UE has elapsed. The registration protection controller may retransmit the registration or attach request message to the on-board network apparatus only upon receiving the paging message or when the timer value of the timer associated with the UE has elapsed.
[0305] In an embodiment, the objectives are achieved by providing an on-board network apparatus for protecting a registration or attach procedure using a certificate based cryptography. The on-board network apparatus may include a memory, a processor coupled to the memory, and an on-board registration protection controller communicatively coupled to the memory and the processor. The on-board registration protection controller may receive a registration or attach request message from a UE. The registration or attach request message may include a public key and a certificate associated with the UE. The certificate may include a public key of the UE. The on-board registration protection controller may verify the certificate of the UE. The on-board registration protection controller may generate a temporary identifier for the UE upon successful verification of the certificate of the UE. The on-board registration protection controller may generate a partial attach registration or accept message to be transmitted to the UE upon generation of the temporary identifier. The on-board registration protection controller may encrypt the partial registration or attach accept message using the public key of the UE. The partial registration or attach accept message may include the generated temporary identifier. The on-board registration protection controller may transmit the encrypted partial registration or attach accept message to the UE.
[0306] In an embodiment, the on-board network apparatus, wherein the on-board registration protection controller may provision a root certificate of a root CA that issued the certificate of the UE at the on-board network apparatus. The on-board registration protection controller may verify the certificate of the UE based on the provisioned root certificate of the root CA.
[0307] In an embodiment, the on-board network apparatus, wherein the on-board registration protection controller may receive authentication vectors and subscription details from a UDM or a HSS on a ground network. The on-board registration protection controller may store the authentication vectors, the subscription details received until a service link is available, wherein the service link may be unavailable when an onboard satellite A is connected to the ground network and cannot connect to the UE and a feeder link connectivity is available at the on-board network apparatus.
[0308] In an embodiment, the on-board network apparatus, wherein the on-board registration protection controller may enter into a UE serving area when a service link is available and a feeder link connectivity is not available. The on-board registration protection controller may generate a paging message to be transmitted to the UE upon entering into the UE serving area. The on-board registration protection controller may receive a re-transmission of the registration or attach request message from the UE upon receiving the paging message, wherein the registration or attach request message may be retransmitted only upon transmission of the paging message to the UE or when a timer value of a timer associated with the UE has elapsed.
[0309] In an embodiment, a method performed by a user equipment (UE) for protection of a partial registration or attach accept message using a certificate based cryptography is provided.
[0310] In an embodiment, the method, wherein the partial registration or attach accept message includes one or more parameters associated with a security capability of the UE.
[0311] In an embodiment, the method may include receiving a paging message with the temporary identifier to complete registration from the on-board network entity. The method may include retransmitting the registration or attach request message including an International Mobile Subscriber Identity (IMSI) or a Subscriber Concealed Identifier (SUCI) to the on-board network entity. The method may include establishing an Access Stratum (AS) security context, a User Plane (UP) security context and a Non-Access Stratum (NAS) security context. The method may include performing protection of a message exchange using the AS security context, the UP security context and the NAS security context.
[0312] In an embodiment, the method may include identifying whether a paging message is received or a timer value elapses. The method may include transmitting the registration or attach request message again to the on-board network entity in case that the paging message is received or the timer value elapses.
[0313] In an embodiment, a method performed by an on-board network entity for protection of a partial registration or attach accept message using a certificate based cryptography is provided.
[0314] In an embodiment, the method may include receiving authentication vectors and subscription details from a unified data management (UDM) or a home subscriber server (HSS) on a ground station. The method may include storing the authentication vectors and the subscription details received until a service link is available, wherein the service link connectivity is unavailable and a feeder link connectivity is available in case that an onboard satellite is connected to the ground station and cannot connect to the UE.
[0315] In an embodiment, the method may include entering a UE serving area in case that a service link is available and a feeder link connectivity is not available, wherein the registration or attach request message is re-transmitted at the UE in response to receiving a paging message, wherein the registration or attach request message is retransmitted in case that the UE receives the paging message or a timer value associated with the UE elapses.
[0316] In an embodiment, the method, wherein the on-board network entity may include at least one of a next generation node B (gNB), an evolved node B (eNB), an access and mobility management function (AMF), or a mobility management entity (MME).
[0317] In an embodiment, a user equipment (UE) for protection of a partial registration or attach accept message using a certificate based cryptography is provided.
[0318] In an embodiment, the UE, wherein the partial registration or attach accept message may include one or more parameters associated with a security capability of the UE.
[0319] In an embodiment, the UE, wherein the registration protection controller may receive a paging message with the temporary identifier to complete registration from the on-board network entity. The registration protection controller may retransmit the registration or attach request message including an International Mobile Subscriber Identity (IMSI) or a Subscriber Concealed Identifier (SUCI) to the on-board network entity. The registration protection controller may establish an Access Stratum (AS) security context, a User Plane (UP) security context and a Non-Access Stratum (NAS) security context. The registration protection controller may perform protection of a message exchange using the AS security context, the UP security context and the NAS security context.
[0320] In an embodiment, the UE, wherein the registration protection controller may identify whether a paging message is received or a timer value elapses. The registration protection controller may transmit the registration or attach request message again to the on-board network entity in case that the paging message is received or the timer value elapses.
[0321] In an embodiment, an on-board network entity for protection of a partial registration or attach accept message using a certificate based cryptography is provided.
[0322] In an embodiment, the on-board network entity, wherein the on-board registration protection controller may receive authentication vectors and subscription details from a unified data management (UDM) or a home subscriber server (HSS) on a ground station. The on-board registration protection controller may store the authentication vectors and the subscription details received until a service link is available, wherein the service link connectivity is unavailable and a feeder link connectivity is available in case that an onboard satellite is connected to the ground station and cannot connect to the UE.
[0323] In an embodiment, the on-board network entity, wherein the on-board registration protection controller may enter a UE serving area in case that a service link is available and a feeder link connectivity is not available, wherein the registration or attach request message is re-transmitted at the UE in response to receiving a paging message, wherein the registration or attach request message is retransmitted in case that the UE receives the paging message or a timer value associated with the UE elapses.
[0324] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of the embodiments as described herein.
Claims
1.A method performed by a user equipment (UE) for protection of a partial registration or attach accept message using a certificate based cryptography, the method comprising:pre-configuring a private key and a certificate at the UE based on an operator policy;transmitting a registration or attach request message including a public key of the UE in the certificate to an on-board network entity;receiving the partial registration or attach accept message from the on-board network entity, wherein the partial registration or attach accept message is encrypted using the public key of the UE, and wherein the partial registration or attach accept message includes a temporary identifier for the UE;decrypting the received encrypted partial registration or attach accept message using the private key; andstoring the temporary identifier included in the decrypted partial registration or attach accept message.2.The method of claim 1, wherein the partial registration or attach accept message includes one or more parameters associated with a security capability of the UE.3.The method of claim 1, the method comprising:receiving a paging message with the temporary identifier to complete registration from the on-board network entity;retransmitting the registration or attach request message including an International Mobile Subscriber Identity (IMSI) or a Subscriber Concealed Identifier (SUCI) to the on-board network entity;establishing an Access Stratum (AS) security context, a User Plane (UP) security context and a Non-Access Stratum (NAS) security context; andperforming protection of a message exchange using the AS security context, the UP security context and the NAS security context.4.The method of claim 1, the method comprising:identifying whether a paging message is received or a timer value elapses; andtransmitting the registration or attach request message again to the on-board network entity in case that the paging message is received or the timer value elapses.5.A method performed by an on-board network entity for protection of a partial registration or attach accept message using a certificate based cryptography, the method comprising:receiving a registration or attach request message including a public key of a user equipment (UE) in a certificate from the UE;verifying the certificate of the UE;generating a temporary identifier for the UE;encrypting the partial registration or attach accept message using the public key of the UE, wherein the partial registration or attach accept message includes the generated temporary identifier; andtransmitting the encrypted partial registration or attach accept message to the UE.6.The method of claim 5, the method comprising:receiving authentication vectors and subscription details from a unified data management (UDM) or a home subscriber server (HSS) on a ground station; andstoring the authentication vectors and the subscription details received until a service link is available,wherein the service link connectivity is unavailable and a feeder link connectivity is available in case that an onboard satellite is connected to the ground station and cannot connect to the UE.7.The method of claim 5, the method comprising:entering a UE serving area in case that a service link is available and a feeder link connectivity is not available,wherein the registration or attach request message is re-transmitted at the UE in response to receiving a paging message,wherein the registration or attach request message is retransmitted in case that the UE receives the paging message or a timer value associated with the UE elapses.8.The method of claim 5, wherein the on-board network entity comprises at least one of a next generation node B (gNB), an evolved node B (eNB), an access and mobility management function (AMF), or a mobility management entity (MME).9.A user equipment (UE) for protection of a partial registration or attach accept message using a certificate based cryptography, the UE comprising:memory;a processor coupled to the memory; anda registration protection controller communicatively coupled to the memory and the processor, wherein the registration protection controller:pre-configure a private key and a certificate at the UE based on an operator policy;transmit a registration or attach request message including a public key of the UE in the certificate to an on-board network entity;receive the partial registration or attach accept message from the on-board network entity, wherein the partial registration or attach accept message is encrypted using the public key of the UE, and wherein the partial registration or attach accept message includes a temporary identifier for the UE;decrypt the received encrypted partial registration or attach accept message using the private key; andstore the temporary identifier included in the decrypted partial registration or attach accept message.10.The UE of claim 9, wherein the partial registration or attach accept message includes one or more parameters associated with a security capability of the UE.11.The UE of claim 9, wherein the registration protection controller:receive a paging message with the temporary identifier to complete registration from the on-board network entity;retransmit the registration or attach request message including an International Mobile Subscriber Identity (IMSI) or a Subscriber Concealed Identifier (SUCI) to the on-board network entity;establish an Access Stratum (AS) security context, a User Plane (UP) security context and a Non-Access Stratum (NAS) security context; andperform protection of a message exchange using the AS security context, the UP security context and the NAS security context.12.The UE of claim 9, wherein the registration protection controller:identify whether a paging message is received or a timer value elapses; andtransmit the registration or attach request message again to the on-board network entity in case that the paging message is received or the timer value elapses.13.An on-board network entity for protection of a partial registration or attach accept message using a certificate based cryptography, the on-board network entity comprising:memory;a processor coupled to the memory; andan on-board registration protection controller communicatively coupled to the memory and the processor, wherein the on-board registration protection controller:receive a registration or attach request message including a public key of a user equipment (UE) in a certificate from the UE;verify the certificate of the UE;generate a temporary identifier for the UE;encrypt the partial registration or attach accept message using the public key of the UE, wherein the partial registration or attach accept message includes the generated temporary identifier; andtransmit the encrypted partial registration or attach accept message to the UE.14.The on-board network entity of claim 13, wherein the on-board registration protection controller:receive authentication vectors and subscription details from a unified data management (UDM) or a home subscriber server (HSS) on a ground station; andstore the authentication vectors and the subscription details received until a service link is available, wherein the service link connectivity is unavailable and a feeder link connectivity is available in case that an onboard satellite is connected to the ground station and cannot connect to the UE.15.The on-board network entity of claim 13, wherein the on-board registration protection controller:enter a UE serving area in case that a service link is available and a feeder link connectivity is not available,wherein the registration or attach request message is re-transmitted at the UE in response to receiving a paging message, wherein the registration or attach request message is retransmitted in case that the UE receives the paging message or a timer value associated with the UE elapses.
Citation Information
Patent Citations
Reaction passivator, method for forming thin film using the same, semiconductor substrate and semiconductor device prepared therefrom
KR1020230120970A
Multiple product meta data extracting method with artificial intelligence
KR1020250076843A
Automated provisioning of endpoint devices with management connectivity
US20230056321A1
Configuration of provisioning parameters for onboarding a device to a network
US20230137814A1
ECDHE Key Exchange for Mutual Authentication Using a Key Server
US20230231702A1