A method for protecting confidentiality and / or integrity of a data communication channel of a slice

The method generates shared secret keys at the secure element and AAA-S to secure data communication channels using VPNs, addressing the lack of end-to-end security in 5G network slicing, particularly for private networks, ensuring confidentiality and integrity.

WO2025172233A1PCT designated stage Publication Date: 2025-08-21THALES DIS FRANCE SA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/053453
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-15
Filing Date
2025-02-10
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing 5G network slicing technologies lack end-to-end security solutions, particularly for private network use cases, which are critical for ensuring confidentiality and integrity of data communication channels in applications like aircraft and military communications.

Method used

A method is proposed to protect the confidentiality and integrity of data communication channels by generating a shared secret key at the secure element and AAA-S, establishing interfaces between UPFs, and using VPNs to secure data exchanges between user equipment and VPN servers, leveraging existing 5G interfaces like N3, N9, and N6.

Benefits of technology

Ensures end-to-end protection of data communication channels by providing encryption and integrity, ensuring secure communication between user equipment and VPN servers, even in roaming scenarios, without the need for additional applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025053453_21082025_PF_FP_ABST
    Figure EP2025053453_21082025_PF_FP_ABST
Patent Text Reader

Abstract

The invention proposes a method 800 for protecting confidentiality and / or integrity of a data communication channel of a slice established between a user equipment 100 comprising a secure element 110 and a VPN server 117 cooperating with an Authentication, Authorization and Accounting Server, AAA-S 104. The method comprises, after an EAP Authentication procedure is completed between the mobile equipment 111 and the AAA-S 104, generating 802, at the secure element 110 and at the AAA-S 104, at least one secret key, identical at the secure element 110 and the AAA-S 104. The method further comprises establishing 804 an interface between a user plane function (UPF) 115 of the HPLMN 300 and a UPF 114 of the VPLMN and exchanging 806 messages between the user equipment 100 cooperating with a VPN client 112 and the VPN server 117 by using VPNs using the at least one secret key.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A method for protecting confidentiality and / or integrity of a data communication channel of a slice

[0002] FIELD OF THE INVENTION

[0003] The present invention concerns telecommunications and in particular 5G network slicing.

[0004] BACKGROUND

[0005] 5G network slicing is a network architecture that provides a way to divide a network to provide independent logical networks over physical network resources and functionality. This can help operators (MNOs) to provide differentiated services and quickly deploy new cases.

[0006] An operator can use network slicing to logically allocate physical resources across one or more slices, where each slice may have a different Quality of Service (QoS) and other performance characteristics, as well as configurations and policies, to meet a variety of use cases and possible Service Level Agreements (SLAs).

[0007] For example, a slice supporting mobile broadband users may require high data rates and traffic volumes, a slice supporting Internet of Things (loT) devices may optimize high-density devices and power consumption, and a slice supporting autonomous driving may provide high-reliability and low-latency communications.

[0008] Currently, 3GPP only defines slice authentication (see, for example, 5G; 5G System; Network Slice-Specific Authentication and Authorization (NSSAA) services; Stage 3 (3GPP TS 29.526 version 16.2.0 Release 16)).

[0009] Figure 1 represents an extract of the European Telecommunications Standards Institute (ETSI) standard TS 133501 V16.3.0 (2020-08) entitled “5G; Security architecture and procedures for 5G System (3GPP TS 33.501 version 16.3.0 Release 16)” that represents figure 16.3-1 describing the “Network Slice-Specific Authentication and Authorization procedure”.

[0010] In this figure, five entities are represented: A user equipment (UE) 100, constituted by a secure element like a Universal Integrated Circuit Card (UICC) cooperating with a mobile equipment (ME), an AMF (Access and Mobility Management Function) 101 , a NSSAAF (Network Slice Specific Authentication and Authorization Function) 102, an AAA-P (Authentication, Authorization and Accounting Proxy) 103 and an AAA-S (Authentication, Authorization and Accounting Server) 104.

[0011] In figure 1 , the following steps are performed (according to the above-mentioned standard):

[0012] At step (1), for single - Network Slice Selection Assistance Information (S-NSSAIs) that require Network Slice-Specific Authentication and Authorization, based on a change of subscription information, or triggered by the AAA-S 104, the AMF 101 may trigger the start of the Network Slice Specific Authentication and Authorization procedure.

[0013] For example, if Network Slice Specific Authentication and Authorization is triggered as a result of the Registration procedure, the AMF 101 may determine, based on UE 100 Context in the AMF 101 , that for some or all S-NSSAI(s) subject to Network Slice Specific Authentication and Authorization, the UE 100 has already been authenticated following a Registration procedure on a first access. Depending on the result of Network Slice Specific Authentication and Authorization procedure (e.g. success / failure) from the previous Registration, the AMF 101 may determine, based on Network policies, whether to skip Network Slice Specific Authentication and Authorization for these S-NSSAIs during the Registration on a second access. If the Network Slice Specific Authentication and Authorization procedure corresponds to a re-authentication and re-authorization procedure triggered as a result of AAA Server-triggered UE 100 for reauthentication and reauthorization for one or more S-NSSAIs, as described in clause 4.2.9.2 of TS 23.502, or triggered by the AMF 101 based on operator policy or a subscription change and if S-NSSAIs that are requiring Network Slice-Specific Authentication and Authorization are comprised in the Allowed NSSAI for each Access Type, the AMF 101 selects an Access Type to be used to perform the Network Slice Specific Authentication and Authorization procedure based on network policies.

[0014] At step 2, the AMF 101 may request the UE 100 for User ID for Extensible Authentication Protocol (EAP) authentication (interchangeably referred to as “EAP ID”) for the S-NSSAI in a Non-Access Stratum mobility management (NAS-MM) Transport message comprising the S-NSSAI.

[0015] At step 3, the UE 100 provides the EAP ID for the S-NSSAI alongside the S-NSSAI in an NAS- MM transport message towards the AMF 101 . At step 4, the AMF 101 sends the EAP ID to the NSSAAF 102 which provides an interface with the AAA, in an NSSAAF 102_NSSAA_Authenticate Request. The request can comprise EAP ID Response, Generic Public Subscription Identifier (GPSI), and S-NSSAI.

[0016] At step 5, if the AAA-P 103 is present (e.g. when the AAA-S 104 belongs to a third party and the operator deploys a proxy towards third parties), the NSSAAF 102 forwards the EAP ID Response message to the AAA-P 103, otherwise i.e. when AAA-P is absent, according to the ETSI 3GPP TS 33.501 version 16.3.0 Release 16 189 ETSI TS 133 501 V16.3.0 (2020-08), the NSSAAF 102 forwards the message directly to the AAA-S 104. The NSSAAF 102 routes to the AAA-S 104 based on the S-NSSAI. The NSSAAF 102 / AAA-P 103 forwards the EAP Identity message to the AAA-S 104 together with S-NSSAI and GPSI. The AAA-S 104 stores the GPSI to create an association with the EAP ID in the EAP ID response message so that the AAA-S 104 can later use it to revoke authorization or to trigger reauthentication. The AAA-S 104 uses the EAP-ID and S-NSSAI to identify for which UE 100, slice authorization is requested.

[0017] At steps 6 -11 , EAP-messages are exchanged with the UE 100. One or more iterations of these steps may occur.

[0018] At step 12, EAP authentication is completed. An EAP-Success / Failure message is delivered to the NSSAAF 102 / AAA-P 103 along with GPSI and S-NSSAI.

[0019] At step 13, the NSSAAF 102 sends the NSSAAF 102_NSSAA_Authenticate Response to the AMF 101. The authenticate response can comprise EAP-Success / Failure message, S-NSSAI, and GPSI.

[0020] At step 14, the AMF 101 transmits a NAS-MM Transport message to the UE 100. The NAS-MM Transport message can comprise EAP-Success / Failure message.

[0021] At step 15, based on the result of Slice specific authentication (EAP-Success / Failure), if a new allowed NSSAI or new rejected NSSAI needs to be delivered to the UE 100, or if the re-allocation of AMF 101 is required, the AMF 101 initiates the UE 100 Configuration Update procedure, for each Access Type, as described in clause 4.2.4.2 of TS 23.502. However, this standardized solution does not provide any security, especially for private network use cases:

[0022] For enterprises, security and privacy are two mandatory points for selecting a private network;

[0023] In the aircraft domain, for example, LAS (Landing Assist Sensor) secure communications have to be deployed for ensuring privacy and security of the communications (commands) between the cockpit and the control tower; and

[0024] In the military domain, several tactical bubbles (e.g. IOPS - Isolated E-UTRAN Operation for Public Safety) use their own security system within a bubble but cannot communicate outside of this bubble (e.g. to the headquarter or another bubble). In case of compromising of the bubble, previous communication to the headquarter or to another bubble could be decrypted (stored and decrypted later). To avoid this risk, the communications external to the bubble must be protected with a key not known by the bubble Core Network (CN).

[0025] It is therefore desired to provide a solution for providing end-to-end protection (encryption, and / or integrity) of the data exchanged between a user equipment (UE) comprising a secure element, like a USIM (Universal SIM), a UICC (Universal Integrated Circuit Card), an eUlCC (embedded UICC) or an iUICC (integrated UICC) and an end-point.

[0026] International Patent Application Publication No. WO2022067654A1 describes apparatuses, methods, and systems for key-based authentication for a mobile edge computing network.

[0027] International Patent Application Publication No. WO2022262975A1 describes methods for enabling end-to-end security for a communication session between a user equipment and a gateway.

[0028] Summary

[0029] The proposed invention proposes a solution to this problem.

[0030] More precisely, the invention proposes a method for protecting confidentiality and / or integrity of a data communication channel of a slice established between a user equipment and VPN (Virtual Private Network) server. The user equipment comprises a secure element cooperating with a mobile equipment and the VPN server cooperates with an Authentication, Authorization and Accounting Server (AAA-S). The user equipment is roaming through a Visited Public Land Mobile Network (VPLMN) and connected to Home Public Land Mobile Network (HPLMN) through the VPLMN. The method comprises, after an EAP Authentication procedure is completed between the mobile equipment and the AAA-S, generating, at the secure element and at the AAA-S, at least one secret key, identical at the secure element and the AAA-S. The method further comprises establishing an interface between a user plane function (UPF) of the HPLMN and a UPF of the VPLMN. The method further comprises upon establishing the interface between the UPF of the HPLMN and the UPF of the VPLMN, exchanging messages between the user equipment cooperating with a VPN client and the VPN server by using VPNs using the at least one secret key to protect the confidentiality and / or integrity of the data communication channel.

[0031] According to some example embodiments, the secret key is generated for confidentiality by deriving a session key (SKSiice_enc) derived from a master key (MK).

[0032] According to some example embodiments, the secret key is generated for integrity by deriving a session key (SKsiicejnt) derived from a master key (MK).

[0033] According to some example embodiments, the data communication channel is in a user plane.

[0034] According to some example embodiments, a plurality of parameters allowing to establish the protection in confidentiality and / or integrity are either pre-configured in the user equipment (100) or the secure element or configured by an UDM (Unified Data Management). The UDM sends the plurality of parameters to the user equipment or the secure element.

[0035] According to some example embodiments, the method further comprises configuring at least one of: interface between the UPF and the VPN, and interface between a base station (gNB) and the UPF of the VPLMN.

[0036] According to some example embodiments, the method further comprises configuring a radio interface between the ME and the gNB.

[0037] BRIEF DESCRIPTION OF THE DRAWINGS The invention will be better understood by reading the description below of a preferred embodiment of the invention, given as a non-exhaustive example, in view of the figures that represent:

[0038] Figure 1 an extract of the ETSI standard TS 133 501 V16.3.0 (2020-08) entitled “5G; Security architecture and procedures for 5G System (3GPP TS 33.501 version 16.3.0 Release 16)” represents a figure (16.3-1) describing the “Network Slice-Specific Authentication and Authorization procedure”;

[0039] Figure 2 a signal flow diagram of the method according to the invention, based on figure 1 ;

[0040] Figure 3 a signal flow diagram of the method according to the invention, for generating a shared secret between the ME and the AAA-S of figure 2;

[0041] Figure 4 a signal flow diagram of the method according to the invention, representing an example for configuring security parameters in a mobile equipment from an UDM; and Figure 5 a method for protecting confidentiality and / or integrity of a data communication channel of a slice established between a user equipment and a Virtual Private network.

[0042] The present invention will be better understood by reading the following description of these figures.

[0043] DETAILED DESCRIPTION

[0044] The term “Network Slice-Specific Authentication and Authorization” refers to a process in 5G networks where a user's access to a specific network slice is verified and authorized based on their identity and the requirements of that slice. This procedure is typically managed by a dedicated function called the “Network Slice-Specific Authentication and Authorization Function (NSSAAF)” within the network infrastructure.

[0045] The term “private network” used in this disclosure refers to a Non-Public Network (or NPN in 3GPP specifications) or is also referred to as a Mobile Private Network (MPN).

[0046] In figure 2, the same entities as those of figure 1 are represented (100 to 104). Steps 2 and 3 in figure 2 are identical to steps 2 and 3 as illustrated in figure 1 (i.e., the AMF 101 requests the UE 100 for an User ID for EAP authentication for the S-NSSAI and the UE 100 provides the EAP ID for the Single - Network Slice Selection Assistance Information (S-NSSAI) alongside the S-NSSAI towards the AMF 101 , through the ME 111). The S-NSSAI is used in support of network slicing to uniquely identify a network slice.

[0047] In this figure, a complete system is represented, by assuming that the UE 100 is not directly connected to his Home Public Land Mobile Network (HPLMN) 300, but through a Visited Public Land Mobile Network (VPLMN) 200. The configuration here is that the UE 100 wants to connect to a private network managed by an enterprise 400 through a VPLMN 200.

[0048] The entities represented in this figure are:

[0049] - In the VPLMN 200: a UICC 110 cooperating with a ME 111 , both constituting the UE 100 of figure 1 ; a VPN 112 connected or integrated into the ME 111 ; a base station (gNB) 113;

[0050] - the AMF 101 of figure 1 ; a user plane function (UPF) 114;

[0051] - In the HPLMN 300:

[0052] - the NSSAAF 102 of figure 1 ; the AAA-P 103 of figure 1 ;

[0053] - an UPF 115; a data network (DN) 116;

[0054] In the enterprise 400: a VPN 117 connected to the AAA-S 104 of figure 1 .

[0055] The gNB refers to a base station or a Next Generation Node B of the 5G mobile communication standard. It serves as the radio access network for 5G devices, responsible for transmitting and receiving data between the 5G device and the core network.

[0056] As will be detailed below, the invention comprises adding VPN servers 112 and 117 between the UE 100 and the AAA-S 104 in order to secure all the communications between them. The method of the invention provides a method for protecting in confidentiality or integrity (or both) of a data communication channel of a slice established between:

[0057] - a user equipment 100 comprising a secure element 110 cooperating with a mobile equipment 111 and,

[0058] - a VPN (Virtual Private Network) server 117 cooperating with an Authentication, Authorization and Accounting Server (AAA-S) 104.

[0059] The invention particularly concerns the protection of a User Plane (U-Plane), which is the process of sending and receiving user data, which are the main signals for communication.

[0060] The data communication channel is preferably in a user plane.

[0061] The secret keys can be generated or known in advance at step 500, after execution of the steps 2 and 3 previously described, at the level of the UICC 110 and the AAA-S 104.

[0062] The secret keys are, at step 501 , transmitted from the UICC 110 to the ME 111.

[0063] Then, standardized exchanges are performed between the ME 111 and the VPN 117:

[0064] - a radio interface is established between the ME 111 and the gNB 113,

[0065] - a N3 5G interface is established between the gNB 113 and the UPF 114,

[0066] - a N9 5G interface is established between the UPF 114 and the UPF 115,

[0067] - a N6 5G interface is established between the UPF 115 and the VPN 117.

[0068] The 5G N3 interface performs the role of conveying user data from the RAN to the User Plane

[0069] Function, making it possible to create both low- and high-latency services. It replaces the S1-U interface from the 4G Evolved Packet Core (EPC) and is key for supporting the new Control and User Plane Separation (CUPS) architecture, with distributed user data processing. Testing and validation of these interfaces is essential, but a challenge.

[0070] The N9 interface is a special feature of the 5G Core UPF that two UPFs can be deployed in series and connected via an interface referred to as N9.

[0071] In 4G networks, the SGi interface (defined by the 3GPP) is the interface between the EPC and the Public IP network. Importantly, traffic through the interface can be identified by user IP, making user and service differentiation a reality. As such, the SGi interface can be perceived as a service gateway, and is a key enabler for new services, particularly when combined with functions such as deep packet inspection and policy-based service selection.

[0072] The N6 interface plays the same role in the 5G network, providing connectivity between the UPF and any other external (or internal) networks or service platforms, such as the Internet, the public cloud or private clouds.

[0073] Once this protocol has been established, the invention proposes to protect (steps 502 and 503) all the data exchanged between the ME 111 and the VPN server 117, through a secured VPN link 504.

[0074] The master key generation and the session key derivations can be performed either in the ME 111 or in the UICC 110.

[0075] The ME 111 protects the data to be communicated to the AAA-S 104 with the secret keys SKsiice_enc for confidentiality and / or SKsiice_int for integrity, and the AAA-S 104 protects the data to be communicated to the ME 111 with the same secret keys SKsiice_enc and / or SKsiice_int.

[0076] Confidentiality and integrity of communication are therefore ensured, in the scope of a user plane communication channel of a slice established between these two entities.

[0077] This solution was based on at least single shared secret key (SKsiice_enc and / or SKsiice_int).

[0078] For going forward, the invention also proposes to generate, at the secure element 110 (or at the ME 111) and at the AAA-S 104 same secret keys generated by deriving session keys (SKsiice_enc key and / or SKsiice_int) derived from a master key MK and a list of parameters. The list of parameters can comprise one or more of:

[0079] • a label e.g. “Slice-Enc”;

[0080] • a session ID;

[0081] • an EAP-ID;

[0082] • a key type (e.g. encryption, integrity);

[0083] • a key size; and

[0084] • an algorithm type.

[0085] The master key MK is the Master Session Key (MSK) or the Extended Master Session Key (EMSK) as defined in the RFC 3748 of the EAP (Extensible Authentication Protocol). This is disclosed in figure 3 where:

[0086] - at step 600, a master key is generated at the AAA-S 104 and at the secure element 110;

[0087] - at step 601 , the AAA-S 104 and the secure element 110 derive the secret keys SKSiice_enc and / or SKsiice_int;

[0088] - the step 501 is identical to step 501 of figure 2;

[0089] - at steps 502 to 504, a VPN link is established between the VPNs 112 and 117.

[0090] Alternatively, a master session key (MSK) can be derived from the master key (MK), then the SKsiice_enc and SKsiice_int are derived from this master session key (MSK).

[0091] The VPNs 112 and 117 can be native VPNs. This has the advantage that the encryption of the user plane communication channel of a slice is “plug and play”: There is no need to install an over-the-top application.

[0092] Also, the credentials can be securely secured outside of the serving network and user credentials can be managed remotely by the credential manager.

[0093] Figure 4 represents a signal flow diagram for configuring the security parameters in the ME from the UDM (Unified Data Management).

[0094] The AMF is in the serving network (VPLMN or HPLMN).

[0095] At step 700, the AMF sends a request to the UDM according to TS 29.503, TS 23.501 and TS 23.502 to obtain the subscriber data information (in the command Nudm_SubscriberDataManagement).

[0096] As described above, these parameters can be one of several of:

[0097] • a label e.g. “Slice-Enc” ;

[0098] • a session Id;

[0099] • an EAP-ID;

[0100] • a key type (e.g. encryption, integrity);

[0101] • a key size; and

[0102] • an algorithm type. These parameters can be either pre-configured in the UE (UICC 110 or ME 111) or configured by the UDM 120.

[0103] At step 701 , the UDM answers with security parameters such as key lengths, parameters, encryption algorithms, security encryption required, etc. to be used by the ME for the protection of the data exchanged between the VPNs 112 and 117.

[0104] At step 702, these security parameters are transmitted to the ME 111 (UE Parameter Update) in a NAS-MM message that sends them to the user equipment 100 or secure element 110.

[0105] Figure 5 illustrates a method 800 for protecting confidentiality and / or integrity of a data communication channel of a slice established between a user equipment 100 and VPN (Virtual Private network) server 117. The user equipment 100 comprises a secure element 110 cooperating with a mobile equipment 111 and the VPN server 117 cooperates with an Authentication, Authorization and Accounting Server (AAA-S) 104. The user equipment 100 is roaming through a Visited Public Land Mobile Network (VPLMN) 200 and connected to Home Public Land Mobile Network (HPLMN) 300 through the VPLMN 200.

[0106] At step 802, after an EAP Authentication procedure is completed between the mobile equipment 111 and the AAA-S 104, at the secure element 110 and at the AAA-S 104, at least one secret key is generated identical at the secure element 110 and the AAA-S 104. The secret key is generated for confidentiality by deriving a session key (SKsiice_enc) derived from a master key (MK). The secret key is generated for integrity by deriving a session key (SKsiicejnt) derived from a master key (MK).

[0107] At step 804, an interface between a user plane function (UPF) 115 of the HPLMN 300 and a UPF 114 of the VPLMN is established.

[0108] At step 806, upon establishing the interface between the UPF 115 and the UPF 114, messages between the user equipment 100 cooperating with a VPN client 112 and the VPN server 117 are exchanged by using VPNs using the at least one secret key to protect the confidentiality and / or integrity of the data communication channel.

[0109] In some embodiments, the data communication channel is in a user plane. In some embodiments, a plurality of parameters allowing them to establish the protection in confidentiality and / or integrity are either pre-configured in the user equipment or the secure element 110 or configured by an UDM 120. The UDM 120 sends the plurality of parameters to the user equipment 100 or to the secure element 110.

[0110] In some embodiments, the method further comprises configuring at least one of: interface between the UPF 115 and the VPN 117, and interface between a base station gNB 113 and the UPF 114 of the VPLMN 200.

[0111] In some embodiments, the method further comprises configuring a radio interface between the ME 111 and the gNB 113.

[0112] Various embodiments of the invention may comprise one or more computer programs stored or otherwise embodied on a computer-readable medium, wherein the computer programs are configured to cause a processor or the computer to perform one or more operations. A computer- readable medium storing, embodying, or encoded with a computer program, or similar language may be embodied as a tangible data storage device storing one or more software programs that are configured to cause a processor or computer to perform one or more operations. Such operations may be, for example, any of the steps or operations described herein. In some embodiments, the computer programs may be stored and provided to a computer using any type of non-transitory computer-readable media.

Claims

CLAIMS1 . A method (800) for protecting confidentiality and / or integrity of a data communication channel of a slice established between:- a user equipment (100) comprising a secure element (110) cooperating with a mobile equipment (111), and- a VPN, Virtual Private Network, server (117) cooperating with an Authentication, Authorization and Accounting Server, AAA-S (104), said user equipment (100) roaming through a Visited Public Land Mobile Network (200), VPLMN, and connected to a Home Public Land Mobile Network (300), HPLMN, through said VPLMN (200), said method (800) comprising:- after an Extensible Authentication Protocol, EAP, Authentication procedure is completed between said mobile equipment (111) and said AAA-S (104), generating (802), at said secure element (110) and at said AAA-S (104), at least one secret key, identical at said secure element (110) and said AAA-S (104);- establishing (804) an interface between a user plane function (115), UPF, of said HPLMN (300) and a UPF (114) of said VPLMN (200); and upon establishing said interface, exchanging (806) messages between said user equipment (100) cooperating with a VPN client (112) and said VPN server (117) by using VPNs using said at least one secret key to protect the confidentiality and / or integrity of said data communication channel.

2. The method (800) according to claim 1 , wherein said secret key is generated for confidentiality by deriving a session key (SKsiice_enc) derived from a master key (MK).

3. The method (800) according to claim 1 , wherein said secret key is generated for integrity by deriving a session key (SKsiicejnt) derived from a master key (MK).

4. The method (800) according to any of the claims 1 to 3, wherein said data communication channel is in a user plane.

5. The method (800) according to any of the claims 1 to 4, wherein a plurality of parameters allowing to establish said protection in confidentiality and / or integrity are either pre-configured in said user equipment (100) or said secure element (110) or configured by an UDM (120), wherein said UDM (120) sends said plurality of parameters to said user equipment (100) or said secure element (110).

6. The method (800) according to any of the claims 1 to 5, the method (800) further comprising: configuring at least one of: interface between said UPF (115) and said VPN (117), and - interface between a base station (113), gNB, and said UPF (114) of said VPLMN (200).

7. The method (800) according to claim 6, the method (800) further comprising configuring a radio interface between said ME (111) and said gNB (113).

Citation Information

Patent Citations

  • Key-based authentication for a mobile edge computing network

    WO2022067654A1

  • Methods and entites for end-to-end security in communication sessions

    WO2022262975A1