Terminal device, network nodes, and methods therein for enhanced network access
Direct QUIC connections to a UPF over non-3GPP access, using IKE authentication, facilitate secure MA PDU session establishment, addressing the lack of TNGF/N3IWF support in 3GPP networks, enhancing network access efficiency and security.
Patent Information
- Application Number
- PCT/EP2025/053867
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-16
- Filing Date
- 2025-02-13
- Publication Date
- 2025-08-21
AI Technical Summary
Existing 3GPP network deployments lack support for non-integrated non-3GPP access without Trusted Non-3GPP Gateway Function (TNGF) or Non-3GPP InterWorking Function (N3IWF), complicating access traffic aggregation and steering, and requiring enhancements for secure connection establishment over non-3GPP access.
Implementing direct QUIC connections to a User Plane Function (UPF) without an IPsec tunnel over non-3GPP access, using Internet Key Exchange (IKE) based authentication and the QUIC protocol, along with network functions like non-3GPP gateways or proxies to manage secure connection establishment and packet forwarding.
Enables secure and efficient establishment of Multi-Access Packet Data Unit sessions over non-3GPP access, simplifying network operations and maintaining 5G network security without the need for TNGF/N3IWF.
Smart Images

Figure EP2025053867_21082025_PF_FP_ABST
Abstract
Description
[0001] TERMINAL DEVICE, NETWORK NODES, AND METHODS THEREIN FOR ENHANCED NETWORK ACCESS
[0002] TECHNICAL FIELD
[0003] The present disclosure relates to communication technology, and more particularly, to a terminal device, network nodes, and methods therein for enhanced network access.
[0004] BACKGROUND
[0005] Access Traffic Steering, Switching and Splitting (ATSSS) is a feature that was introduced in the 5thGeneration Core (5GC) in the 3rdGeneration Partnership Project (3GPP) Release 16 and has been further developed in Release 17 and Release 18. There are now ongoing 3GPP studies for further development in Release 19.
[0006] ATSSS allows a User Equipment (UE) to establish a Multi-Access Packet Data Unit (PDU) Session (MA PDU Session) that has active user plane connections via both 3GPP (e.g., 5G) and non-3GPP (e.g., Wireless Local Area Network, or WLAN) access simultaneously. Fig. 1 shows an ATSSS architecture. As shown, a UE has active user plane connections with a User Plane Function (UPF) via both a 3GPP Radio Access Network and a non-3GPP Access Network (AN) simultaneously.
[0007] In the Release 16 to Release 18 ATSSS feature, MA PDU Sessions require integrated trusted or untrusted non-3GPP accesses. This means that to enable ATSSS either a Trusted Non-3GPP Gateway Function (TNGF) or a Non-3GPP InterWorking Function (N3IWF) is deployed in a Public Land Mobile Network (PLMN). However, many network deployments do not have such nodes and it is therefore beneficial to study how to support a limited set of access traffic aggregation and steering features applicable to non-integrated non-3GPP access not based on TNGF / N3IWF.
[0008] Therefore 3GPP has agreed to work on the following Release 19 objectives:
[0009] WT#3: Study whether and how to define a functional architecture and procedures for steering, switching and splitting of traffic not based on current TNGF / N3IWF to simplify the operation over non-3GPP access without compromising the security of the 5G network. WT#3.1 : Study whether to keep the Non-Access Stratum (NAS) signaling connection on non-3GPP access or not, whether to eliminate Internet Protocol (IP) Security (IPSec) tunnel encapsulation on the user plane only or both on the control plane and the user plane, simplifying the protocol stack, reduce the user plane overhead.
[0010] WT#3.2: Study whether and how to support splitting, switching, steering between 3GPP access and "non-3GPP access without 5G NAS". Study whether and how to enhance registration and security aspects for supporting "non-3GPP access without 5G NAS".
[0011] SUMMARY
[0012] It is an object of the present disclosure to provide a terminal device, network nodes and methods therein, capable of enabling a terminal device to securely connect to a 3GPP network and establish an MA PDU session over a non-3GPP access without TNGF / N3IWF.
[0013] According to a first aspect of the present disclosure, a method in a terminal device is provided. The method includes transmitting an MA PDU session establishment request containing ATSSS capabilities indicating that the terminal device supports direct QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0014] In an embodiment, the method may further include receiving a PDU session establishment accept containing correlation information, and transmitting a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may contain the correlation information. The correlation information may correlate the QUIC connection establishment request with a PDU session context.
[0015] According to a second aspect of the present disclosure, a method in a UPF is provided. The method includes receiving a session establishment request for an MA PDU session. The method further includes transmitting a session establishment response containing correlation information for correlating a QUIC connection establishment request with a PDU session context.
[0016] In an embodiment, the method may further include receiving a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may contain the correlation information.
[0017] According to a third aspect of the present disclosure, a method in a terminal device is provided. The method includes transmitting, to a non-3GPP gateway or proxy, an Internet Key Exchange Authentication (IKE_AUTH) request containing ATSSS capabilities indicating that the terminal device supports direct QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0018] In an embodiment, the method may further include receiving, from the non-3GPP gateway or proxy, an IKE_AUTH response, deriving a TLS Pre-Shared Key (PSK) based on authentication key credential, and transmitting a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the derived TLS PSK.
[0019] According to a fourth aspect of the present disclosure, a method in a non-3GPP gateway or proxy is provided. The method includes receiving, from a terminal device, an IKE_AUTH request containing ATSSS capabilities indicating that the terminal device supports QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0020] In an embodiment, the method may further include deriving a TLS PSK based on authentication key credential, and transmitting, to an SMF, a request containing the derived TLS PSK.
[0021] In an embodiment, the request may further contain information on a General Packet Radio Service (GPRS) Tunneling Protocol - User Plane (GTP-U) tunnel of the non-3GPP gateway or proxy.
[0022] In an embodiment, the method may further include transmitting, to the terminal device, an IKE_AUTH response containing a QUIC proxy IP address that is set as an IP address of the non-3GPP gateway or proxy.
[0023] In an embodiment, the method may further include receiving a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the TLS PSK. The method may further include correlating the QUIC connection establishment request with the GTP-U tunnel for a PDU session of the terminal device.
[0024] In an embodiment, the method may further include receiving, from the terminal device, a QUIC packet, and changing a destination address of the QUIC packet into a QUIC Proxy address of the UPF, and forwarding the QUIC packet to the UPF via the correlated GTP-U tunnel.
[0025] According to a fifth aspect of the present disclosure, a method in an SMF is provided. The method includes receiving, from a non-3GPP gateway or proxy, a request containing a TLS PSK.
[0026] In an embodiment, the method may further include transmitting, to a UPF, a request containing the TLS PSK and ATSSS capabilities of a terminal device. The ATSSS capabilities may indicate that the terminal device supports direct QUIC connections to the UPF without IPsec tunnel over non-3GPP access.
[0027] According to a sixth aspect of the present disclosure, a method in a UPF is provided. The method includes receiving, from an SMF, a request containing a TLS PSK and ATSSS capabilities of a terminal device. The ATSSS capabilities indicate that the terminal device supports direct QUIC connections to the UPF without IPsec tunnel over non-3GPP access.
[0028] In an embodiment, the method may further include receiving a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the TLS PSK.
[0029] In an embodiment, the method may further include correlating the QUIC connection establishment request with a PDU session context for the terminal device, and handling the QUIC connection establishment request from the terminal device based on the TLS PSK.
[0030] According to a seventh aspect of the present disclosure, a terminal device is provided. The terminal device includes a communication interface, a processor, and a memory. The memory contains instructions executable by the processor whereby the terminal device is operative to perform the method according to the above first or third aspect.
[0031] According to an eighth aspect of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium has computer-readable instructions stored thereon. The computer-readable instructions, when executed by a processor of a terminal device, configure the terminal device to perform the method according to the above first or third aspect.
[0032] According to a ninth aspect of the present disclosure, a network node is provided. The network node includes a communication interface, a processor, and a memory. The memory contains instructions executable by the processor whereby the network node is operative to, when implementing a UPF, perform the method according to any of the above second or sixth aspect, or when implementing a non-3GPP gateway or proxy, perform the method according to the above fourth aspect, or when implementing an SMF, perform the method according to the above fifth aspect.
[0033] According to a tenth aspect of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium has computer-readable instructions stored thereon. The computer-readable instructions, when executed by a processor of a network node, configure the network node to, when implementing a UPF, perform the method according to any of the above second or sixth aspect, or when implementing a non-3GPP gateway or proxy, perform the method according to the above fourth aspect, or when implementing an SMF, perform the method according to the above fifth aspect.
[0034] With some embodiments of the present disclosure, a terminal device can securely connect to a 3GPP network and establish an MA PDU session over a non-3GPP access.
[0035] BRIEF DESCRIPTION OF THE DRAWINGS
[0036] The above and other objects, features and advantages will be more apparent from the following description of embodiments with reference to the figures, in which:
[0037] Fig. 1 is a schematic diagram showing an ATSSS architecture;
[0038] Fig. 2 is a schematic diagram showing a network architecture according to an embodiment of the present disclosure;
[0039] Fig. 3 is a flowchart illustrating a method in a terminal device according to an embodiment of the present disclosure;
[0040] Fig. 4 is a flowchart illustrating a method in a UPF according to an embodiment of the present disclosure;
[0041] Fig. 5 is a sequence diagram showing a process of MA PDU Session and QUIC connection establishment according to an embodiment of the present disclosure;
[0042] Figs. 6A and 6B are schematic diagrams each showing a network architecture according to another embodiment of the present disclosure; Fig. 7 is a flowchart illustrating a method in a terminal device according to another embodiment of the present disclosure;
[0043] Fig. 8 is a flowchart illustrating a method in a non-3GPP gateway or proxy according to another embodiment of the present disclosure;
[0044] Fig. 9 is a flowchart illustrating a method in an SMF according to an embodiment of the present disclosure;
[0045] Fig. 10 is a flowchart illustrating a method in a UPF according to an embodiment of the present disclosure;
[0046] Figs. 11 A and 11 B are sequence diagrams each showing a process of MA PDU Session and QUIC connection establishment over non-3GPP access according to an embodiment of the present disclosure;
[0047] Fig. 12 is a block diagram of a terminal device according to an embodiment of the present disclosure; and
[0048] Fig. 13 is a block diagram of a network node according to an embodiment of the present disclosure.
[0049] DETAILED DESCRIPTION
[0050] In the present disclosure, a network function, or NF, can be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g. on a cloud infrastructure. The term “network node” refers to any physical or virtual node configured to implement a network function.
[0051] The term "terminal device" or “UE” refers to any end device that can access a wireless communication network and receive services therefrom. By way of example and not limitation, the terminal device refers to a mobile terminal, user equipment (UE), or other suitable devices. The UE may be, for example, a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, portable computers, desktop computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, tablets, personal digital assistants (PDAs), wearable terminal devices, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE) and the like. In the following description, the terms "terminal device", "terminal", "user equipment" and "UE" may be used interchangeably. As one example, a terminal device may represent a UE configured for communication in accordance with one or more communication standards promulgated by the 3rd Generation Partnership Project (3GPP), such as 3GPP's Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or the 5th Generation (5G) standards. As used herein, a "user equipment" or "UE" may not necessarily have a "user" in the sense of a human user who owns and / or operates the relevant device. In some embodiments, a terminal device may be configured to transmit and / or receive information without direct human interaction. For instance, a terminal device may be designed to transmit information to a network on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the wireless communication network. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but that may not initially be associated with a specific human user.
[0052] References in the specification to "one / an / an example embodiment," and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, one skilled in the art may affect such feature, structure, or characteristic in connection with other embodiments.
[0053] It shall be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0054] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises", "comprising", "has", "having", "includes" and / or "including", when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0055] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0056] Quick User Datagram Protocol (UDP) Internet Connections (QUIC) is a UDP based stream-multiplexed and secure transport protocol with integrity protected header and encrypted payload. Unlike the traditional transport protocol stack with Transmission Control Protocol (TCP), which resides in the operating system kernel, QUIC can easily be implemented in user space, i.e., in the application layer. As a consequence, this improves flexibility in terms of transport protocol evolution with implementation of new features, congestion control, deploy ability and adoption.
[0057] QUIC is standardized in the Internet Engineering Task Force (IETF). QUIC is likely to become the main transport protocol in the Internet’s user plane. It is expected that most applications running today over Hypertext Transfer Protocol (HTTP) I HTTP Security (HTTPS) will migrate to QUIC, driven by latency improvements and stronger security. Notably, compared to HTTPS, encryption in QUIC covers both the transport protocol headers as well as the payload, as opposed to Transport Layer Security (TLS) over TCP, e.g. HTTPS, which protects only the payload.
[0058] Some embodiments of the present disclosure enable a terminal device to securely connect to a 3GPP network and establish an MA PDU session over a non-3GPP access, based on a combination of Internet Key Exchange (IKE) based authentication and the QUIC protocol.
[0059] Fig. 2 shows a network architecture according to an embodiment of the present disclosure. A UE, a UPF, an Access and Mobility Management Function (AMF), an SMF, a Policy Control Function (PCF), and a data network, as well as interfaces between the respective nodes, are shown in the figure. In this architecture, the UE communicates with the UPF via a 3GPP access and a non-3GPP access (via an Nx interface). The UPF exposes its Multi-Path QUIC (MPQUIC) Proxy address over the non-3GPP access. QUIC packets are exchanged between the UE and the UPF over non-3GPP access directly without an IPsec tunnel, and there is no control plane function over the non-3GPP access. Here, the UE is registered over the 3GPP access and the MA PDU session is to be established over the 3GPP access.
[0060] Fig. 3 is a flowchart illustrating a method 300 according to an embodiment of the present disclosure. The method 300 can be performed by a terminal device, e.g., a UE. The method 300 can be applied in the network architecture shown in Fig. 2.
[0061] At block 310, the terminal device transmits an MA PDU session establishment request, e.g., to an AMF. The MA PDU session establishment request contains ATSSS capabilities indicating that the terminal device supports direct QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0062] In an example, the terminal device may further receive, e.g., from the AMF, a PDU session establishment accept containing correlation information. The terminal device may further transmit a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may contain the correlation information. The correlation information may correlate the QUIC connection establishment request with a PDU session context.
[0063] Fig. 4 is a flowchart illustrating a method 400 according to an embodiment of the present disclosure. The method 400 can be performed by a UPF. The method 400 can be applied in the network architecture shown in Fig. 2.
[0064] At block 410, the UPF receives, e.g., from an SMF, a session establishment request for an MA PDU session.
[0065] At block 420, the UPF transmits, e.g., to an SMF, a session establishment response containing correlation information for correlating a QUIC connection establishment request with a PDU session context.
[0066] In an example, the UPF may further receive a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may contain the correlation information.
[0067] The above methods 300 and 400 will be further explained with reference to Fig. 5.
[0068] Fig. 5 shows a process of MA PDU Session and QUIC connection establishment according to an embodiment of the present disclosure. As shown, at Step 0, a UE performs a 3GPP access authentication procedure, which involves an AMF, an Authentication Server Function (AUSF), and a Unified Data Management (UDM).
[0069] At Step 1 , the UE initiates an MA PDU Session Establishment request, in a NAS message towards the AMF, with ATSSS capabilities indicating that the UE supports direct QUIC connections to UPF without IPsec tunnel over non-3GPP access.
[0070] At Step 2, the AMF obtains SMFSelection data and UeContextlnSmfData from the UDM.
[0071] At Steps 3 and 4, the AMF sends an Nsmf_PDUSession_CreateSMContext Request to an SMF, and receives an Nsmf_PDUSession_CreateSMContext Response from the SMF.
[0072] At Steps 5 and 6, the SMF sends an N4 session establishment request to a UPF, and receives an N4 session establishment response from the UPF in a Packet Forwarding Control Protocol (PFCP) session establishment procedure. The session establishment response contains correlation information for QUIC Connection, which will be used later by the UPF to correlate a QUIC connection request with a corresponding PDU session context if the UE initiates the QUIC connection request over non-3GPP access.
[0073] At Step 7, the SMF sends to the AMF an Namf_Communication_N1 N2MessageTransfer message containing the correlation information.
[0074] At Step 8, the AMF sends to the UE a PDU Session Establishment Accept (in a NAS message) containing the correlation information.
[0075] At Step 9, the procedure of PDU Session Establishment continues over 3GPP access. Then, a GTP-U Tunnel is established between the 3GPP RAN and the UPF.
[0076] At Step 10, the UE initiates an MPQUIC connection establishment procedure over 3GPP access or non-3GPP access. If the UE initiates the MPQUIC connection establishment over non-3GPP access, the UE includes the correlation information in a QUIC connection establishment request towards the UPF.
[0077] At Steps 11 and 12, stream data (e.g., QUIC packets) is exchanged between the UE and the UPF over non-3GPP access (e.g., WLAN) directly. For further details of some of the steps in Fig. 5, reference can be made to the 3GPP Technical Specification (TS) 23.502, V18.4.0, which is incorporated herein by reference in its entirety.
[0078] Figs. 6A and 6B each show a network architecture according to an embodiment of the present disclosure. Compared with the network architecture shown in Fig. 2, in each of Figs. 6A and 6B, a new network function, referred to herein as non-3GPP gateway (GW) / proxy, is introduced for non-3GPP access between a UE and a Core Network. The non-3GPP GW / proxy is connected with an AUSF / UDM via a Service Based Interface (SBI) for access authentication, and connected with an SMF via an SBI for PDU Session Management.
[0079] The non-3GPP GW / proxy performs access authentication for the UE over non-3GPP access based on an IKE procedure. The non-3GPP GW / proxy and UE derive a TLS PSK for QUIC connection based on authentication credentials. The non-3GPP GW / proxy send the derived TLS PSK to an UPF (MPQUIC proxy) via the SMF.
[0080] In the network architecture shown in Fig. 6A, the non-3GPP GW / proxy does not stay in the user plane path. The UPF exposes its MPQUIC Proxy address over non-3GPP access. The UE and the UPF establish direct MPQUIC connections without IPsec tunnel over non-3GPP access.
[0081] In the network architecture shown in Fig. 6B, the non-3GPP GW / proxy is connected with the UPF via a GTP-U tunnel and stays in the user plane path after access authentication and Session Management (SM) Context Creation for an MA PDU Session. The UPF does not need to expose its MPQUIC Proxy address over non-3GPP access in this case. The non-3GPP GW / proxy can act as a Network Address Translation (NAT) function by hiding the MPQUIC Proxy address of the UPF and relay QUIC packets between the UE and the UPF.
[0082] Fig. 7 is a flowchart illustrating a method 700 according to an embodiment of the present disclosure. The method 700 can be performed by a terminal device, e.g., a UE. The method 700 can be applied in the network architecture shown in Fig. 6A and / or the network architecture shown in Fig. 6B.
[0083] At block 710, the terminal device transmits, to a non-3GPP gateway or proxy, an IKE_AUTH request containing ATSSS capabilities indicating that the terminal device supports direct QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0084] In an example, the terminal device may receive, from the non-3GPP gateway or proxy, an IKE_AUTH response, derive a TLS PSK based on authentication key credential, and transmit a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the derived TLS PSK.
[0085] Fig. 8 is a flowchart illustrating a method 800 according to an embodiment of the present disclosure. The method 800 can be performed by a non-3GPP gateway or proxy. The method 800 can be applied in the network architecture shown in Fig. 6A and / or the network architecture shown in Fig. 6B.
[0086] At block 810, the non-3GPP gateway or proxy receives, from a terminal device, an IKE_AUTH request containing ATSSS capabilities indicating that the terminal device supports QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0087] In an example, the non-3GPP gateway or proxy may derive a TLS PSK based on authentication key credential, and transmit, to an SMF, a request containing the derived TLS PSK.
[0088] In an example, e.g., in the network architecture shown in Fig. 6B, the request may further contain information on a GTP-U tunnel of the non-3GPP gateway or proxy. The non-3GPP gateway or proxy may further transmit, to the terminal device, an IKE_AUTH response containing a QUIC proxy IP address that is set as an IP address of the non-3GPP gateway or proxy. The non-3GPP gateway or proxy may further receive a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the TLS PSK. The non-3GPP gateway or proxy may further correlate the QUIC connection establishment request with the GTP-U tunnel for a PDU session of the terminal device. Moreover, the non-3GPP gateway or proxy may further receive, from the terminal device, a QUIC packet, and change a destination address of the QUIC packet into a QUIC Proxy address of the UPF and forward the QUIC packet to the UPF via the correlated GTP-U tunnel.
[0089] Fig. 9 is a flowchart illustrating a method 900 according to an embodiment of the present disclosure. The method 900 can be performed by an SMF. The method 900 can be applied in the network architecture shown in Fig. 6A and / or the network architecture shown in Fig. 6B.
[0090] At block 910, the SMF receives, from a non-3GPP gateway or proxy, a request containing a TLS PSK.
[0091] In an example, the SMF may transmit, to a UPF, a request containing the TLS PSK and ATSSS, capabilities of a terminal device. The ATSSS capabilities may indicate that the terminal device supports direct QUIC connections to the UPF without IPsec tunnel over non-3GPP access.
[0092] Fig. 10 is a flowchart illustrating a method 1000 according to an embodiment of the present disclosure. The method 1000 can be performed by a UPF. The method 1000 can be applied in the network architecture shown in Fig. 6A and / or the network architecture shown in Fig. 6B.
[0093] At block 1010, the UPF receives, from an SMF, a request containing a TLS PSK and ATSSS capabilities of a terminal device. The ATSSS capabilities indicate that the terminal device supports direct QUIC connections to the UPF without IPsec tunnel over non-3GPP access.
[0094] In an example, the UPF may receive a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the TLS PSK.
[0095] In an example, the UPF may correlate the QUIC connection establishment request with a PDU session context for the terminal device, and handle the QUIC connection establishment request from the terminal device based on the TLS PSK.
[0096] The above methods 700-1000 will be further explained with reference to Figs. 11A and 11 B.
[0097] Figs. 11A and 11 B each show a process of MA PDU Session and QUIC connection establishment over non-3GPP access according to an embodiment of the present disclosure.
[0098] The process in Fig. 11 A may be performed in the network architecture of Fig. 6A; accordingly, entities mentioned with respect to Fig. 11 A may correspond to the respective entities of Fig. 6A. As shown in Fig. 11 A, at Step 1 , a UE connects to a non-3GPP access network (e.g., WLAN) and is allocated an IP address. When the UE decides to connect to a Core Network via non-3GPP access, the UE selects a non-3GPP GW / proxy, in a similar way as evolved Packet Data Gateway (ePDG) or N3IWF selection as per clause 6.3.6 of TS 23.501 , V18.4.0, which is incorporated herein by reference in its entirety.
[0099] At Step 2, the UE proceeds with establishment of an IPsec Security Association (SA) with the selected non-3GPP GW / proxy by initiating an IKE initial exchange.
[0100] At Step 3, the UE initiates IKE_AUTH exchange by sending an IKE_AUTH request message that includes parameters such as PDU Session Identifier (ID), Data Network Name (DNN), Single Network Slice Selection Assistance Information (S-NSSAI) and ATSSS capabilities. The ATSSS capabilities indicate that the UE supports the direct QUIC connection in the user plane without IPsec tunnel over non-3GPP access.
[0101] At Step 4, the non-3GPP GW / proxy decides to authenticate the UE and sends the key request to an AUSF. The AUSF may initiate an authentication procedure as described in clause 6.1.3 in TS 33.501 , V18.4.0, which is incorporated herein by reference in its entirety. The authentication payload is carried in IKE packets between the UE and the non-3GPP GW / proxy.
[0102] At Step 5, upon successful access authentication of the UE, if the UE indicates supporting the direct QUIC connection without IPsec tunnel over non-3GPP access, the non-3GPP GW / proxy derives a TLS PSK based on the authentication key credential.
[0103] At Step 6, the non-3GPP GW / proxy determines to create an SM Context corresponding to PDU Session Information contained in the IKE_AUTH request at Step 3. The non-3GPP GW / proxy gets SMF Selection Data and UeContextlnSmfData from a UDM, and performs SMF selection as per clause 4.3.2.2.3 in TS 23.502.
[0104] At Step 7, the non-3GPP GW / proxy sends an Nsmf_PDUSession_CreateSMContext Request to the selected SMF. The Nsmf_PDUSession_CreateSMContext Request may include the SM context information as described in clause 4.3.2.2 in TS 23.502, and also the TLS PSK derived at Step 5. At Step 8, the SMF replies to the non-3GPP GW / proxy with an Nsmf_PDUSession_Create Response.
[0105] At Step 9, the SMF selects a UPF that supports direct MPQUIC connection with UE over non-3GPP access and initiates a PFCP session establishment procedure. The PFCP session establishment request towards the UPF includes the TLS PSK and ATSSS capabilities of the UE. The UPF returns its MPQUIC proxy information in a PFCP session establishment response message. Note that the UPF does not allocate the UE “MPQUIC link specific multipath” addresses / prefixes for non-3GPP access in this case as the UE uses the non-3GPP access network allocated IP address to connect to the UPF MPQUIC proxy.
[0106] At Step 10, the SMF initiates an Namf_Communication_N1 N2MessageTransfer procedure to the non-3GPP GW / proxy with the MPQUIC proxy information of the UPF.
[0107] At Step 11 , the non-3GPP GW / proxy sends an IKE_AUTH_RSP message with EAP-Success and the MPQUIC proxy information to the UE.
[0108] At Step 12, the UE derives the TLS PSK based on the authentication key credential upon IKE_AUTH_RSP with EAP-Success. Note that the UE and the UPF only use the derived TLS PSK for the QUIC connections established over non-3GPP access. For QUIC connections which have been established over 3GPP access, the UE and the UPF can use the existing QUIC credential.
[0109] At Step 13, the UE initiates an MPQUIC connections establishment procedure over non-3GPP access protected by the PSK derived at Step 12. The UPF needs to correlate the MPQUIC connection request with the corresponding PDU session context for the UE and handles the MPQUIC connection requests from UE based on the TLS PSK received during the PFCP session establishment procedure at Step 9.
[0110] At Step 14, the UE sends an HTTP CONNECT request over the established QUIC connection to create a new stream for an uplink data packet. At Step 15, the UPF (MPQUIC proxy) responds with an HTTP 200 status, indicating that the request to proxy data packets to a remote host and destination port is accepted.
[0111] The process in Fig. 11 B may be performed in the network architecture of Fig. 6B; accordingly, entities mentioned with respect to Fig. 11 B may correspond to the respective entities of Fig. 6B. For the process in Fig. 11 B, only the difference from the process in Fig. 11 A will be described below. At Step 7, the non-3GPP GW / proxy provides its GTP-U Tunnel Information in an Nsmf_PDUSession_CreateSMContext Request.
[0112] At Step 9, the UPF allocates GTP-U Tunnel Information for the non-3GPP access.
[0113] At Step 11 , the non-3GPP GW / proxy changes the MPQUIC proxy IP address into the address of the non-3GPP GW / proxy so that the non-3GPP GW / proxy can relay QUIC packets between the UE and the UPF. The GTP-U tunnel between the non-3GPP GW / proxy and the UPF is established for the MA PDU Session of the UE at this step.
[0114] At Step 13, the UE initiates an MPQUIC connection establishment procedure over non-3GPP access protected by the PSK derived at Step 12. The non-3GPP GW / proxy correlates the MPQUIC connection establishment request with the GTP-U tunnel for the PDU session of the UE, and changes the destination address of the UE QUIC packet into the UPF QUIC Proxy address, then forwards QUIC packets to the UPF via the correlated GTP-U tunnel. The UPF handles the MPQUIC connection request from the UE based on the TLS PSK received during PFCP session establishment procedure at Step 9.
[0115] At Step 14, the UE sends an HTTP CONNECT request over the established QUIC connection to create a new stream for an uplink data packet, which is relayed to the UPF by the non-3GPP GW / proxy. At Step 15, the UPF (MPQUIC proxy) responds with an HTTP 200 status, indicating that the request to proxy data packets to a remote host and destination port is accepted. The HTTP 200 response is relayed to the UE by the non-3GPP GW proxy.
[0116] Fig. 12 is a block diagram of a terminal device 1200 according to an embodiment of the present disclosure.
[0117] The terminal device 1200 includes a communication interface 1210, a processor 1220 and a memory 1230.
[0118] The memory 1230 may contain instructions executable by the processor 1220 whereby the terminal device 1200 is operative to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 3. Particularly, the memory 1230 may contain instructions executable by the processor 1220 whereby the terminal device 1200 is operative to: transmit an MA PDU session establishment request containing ATSSS capabilities indicating that the terminal device supports direct QUIC connections to a UPF without IPsec tunnel over non-3GPP access. In an embodiment, the memory 1230 may further contain instructions executable by the processor 1220 whereby the terminal device 1200 is operative to: receive a PDU session establishment accept containing correlation information, and transmit a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may contain the correlation information. The correlation information may correlate the QUIC connection establishment request with a PDU session context.
[0119] Alternatively, the memory 1230 may contain instructions executable by the processor 1220 whereby the terminal device 1200 is operative to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 7. Particularly, the memory 1230 may contain instructions executable by the processor 1220 whereby the terminal device 1200 is operative to: transmit, to a non-3GPP gateway or proxy, an IKE_AUTH request containing ATSSS capabilities indicating that the terminal device supports direct QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0120] In an embodiment, the memory 1230 may further contain instructions executable by the processor 1220 whereby the terminal device 1200 is operative to: receive, from the non-3GPP gateway or proxy, an IKE_AUTH response, derive a TLS Pre-Shared Key (PSK) based on authentication key credential, and transmit a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the derived TLS PSK.
[0121] Fig. 13 is a block diagram of a network node 1300 according to an embodiment of the present disclosure.
[0122] The network node 1300 includes a communication interface 1310, a processor 1320 and a memory 1330.
[0123] The memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing a UPF, perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 4. Particularly, the memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing a UPF: receive a session establishment request for an MA PDU session; and transmit a session establishment response containing correlation information for correlating a QUIC connection establishment request with a PDU session context.
[0124] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the UPF: receive a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may contain the correlation information.
[0125] Alternatively, the memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing a non-3GPP gateway or proxy, perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 8. Particularly, the memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing a non-3GPP gateway or proxy: receive, from a terminal device, an IKE_AUTH request containing ATSSS capabilities indicating that the terminal device supports QUIC connections to a UPF without IPsec tunnel over non-3GPP access.
[0126] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the non-3GPP gateway or proxy: derive a TLS PSK based on authentication key credential, and transmit, to an SMF, a request containing the derived TLS PSK.
[0127] In an embodiment, the request may further contain information on a GTP-U tunnel of the non-3GPP gateway or proxy.
[0128] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the non-3GPP gateway or proxy: transmit, to the terminal device, an IKE_AUTH response containing a QUIC proxy IP address that is set as an IP address of the non-3GPP gateway or proxy.
[0129] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the non-3GPP gateway or proxy: receive a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the TLS PSK. The memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the non-3GPP gateway or proxy: correlate the QUIC connection establishment request with the GTP-U tunnel for a PDU session of the terminal device.
[0130] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the non-3GPP gateway or proxy: receive, from the terminal device, a QUIC packet, and change a destination address of the QUIC packet into a QUIC Proxy address of the UPF, and forward the QUIC packet to the UPF via the correlated GTP-U tunnel.
[0131] Alternatively, the memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing an SMF, perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 9. Particularly, the memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing an SMF: receive, from a non-3GPP gateway or proxy, a request containing a TLS PSK.
[0132] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing then SMF: transmit, to a UPF, a request containing the TLS PSK and ATSSS capabilities of a terminal device. The ATSSS capabilities may indicate that the terminal device supports direct QUIC connections to the UPF without IPsec tunnel over non-3GPP access.
[0133] Alternatively, the memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing a UPF, perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 10. Particularly, the memory 1330 may contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing a UPF: receive, from an SMF, a request containing a TLS PSK and ATSSS capabilities of a terminal device. The ATSSS capabilities indicate that the terminal device supports direct QUIC connections to the UPF without IPsec tunnel over non-3GPP access.
[0134] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the UPF: receive a QUIC connection establishment request for QUIC connection establishment over non-3GPP access. The QUIC connection establishment request may be protected by the TLS PSK.
[0135] In an embodiment, the memory 1330 may further contain instructions executable by the processor 1320 whereby the network node 1300 is operative to, when implementing the UPF: correlate the QUIC connection establishment request with a PDU session context for the terminal device, and handle the QUIC connection establishment request from the terminal device based on the TLS PSK.
[0136] The present disclosure also provides at least one computer program product in the form of a non-volatile or volatile memory, e.g., a non-transitory computer readable storage medium, an Electrically Erasable Programmable Read-Only Memory (EEPROM), a flash memory and a hard drive. The computer program product includes a computer program. The computer program includes: code / computer readable instructions, which when executed by the processor 1220 causes the terminal device 1200 to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 3 or 7; or code / computer readable instructions, which when executed by the processor 1320 causes the network node 1300 to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 4, 8, 9, or 10.
[0137] The computer program product may be configured as a computer program code structured in computer program modules. The computer program modules could essentially perform the actions of the flow illustrated in Fig. 3, 4, 7, 8, 9, or 10.
[0138] The processor may be a single CPU (Central Processing Unit), but could also comprise two or more processing units. For example, the processor may include general purpose microprocessors; instruction set processors and / or related chips sets and / or special purpose microprocessors such as Application Specific Integrated Circuits (ASICs). The processor may also comprise board memory for caching purposes. The computer program may be carried in a computer program product connected to the processor. The computer program product may comprise a non-transitory computer readable storage medium on which the computer program is stored. For example, the computer program product may be a flash memory, a Random Access Memory (RAM), a Read-Only Memory (ROM), or an EEPROM, and the computer program modules described above could in alternative embodiments be distributed on different computer program products in the form of memories.
Claims
CLAIMS1 . A method (300) in a terminal device, comprising: transmitting (310) a Multi-Access, MA, Packet Data Unit, PDU, session establishment request containing Access Traffic Steering, Switching and Splitting, ATSSS, capabilities indicating that the terminal device supports direct QUIC connections to a User Plane Function, UPF, without Internet Protocol, IP, Security, IPsec, tunnel over non 3rdGeneration Partnership Project, non-3GPP, access.
2. The method (300) of claim 1 , further comprising: receiving a PDU session establishment accept containing correlation information; and transmitting a QUIC connection establishment request for QUIC connection establishment over non-3GPP access, the QUIC connection establishment request containing the correlation information, the correlation information correlating the QUIC connection establishment request with a PDU session context.
3. A method (400) in a User Plane Function, UPF, comprising: receiving (410) a session establishment request for a Multi-Access, MA, Packet Data Unit, PDU, session; and transmitting (420) a session establishment response containing correlation information for correlating a QUIC connection establishment request with a PDU session context.
4. The method (400) of claim 3, further comprising: receiving a QUIC connection establishment request for QUIC connection establishment over non 3rdGeneration Partnership Project, non-3GPP, access, the QUIC connection establishment request containing the correlation information.
225. A method (700) in a terminal device, comprising: transmitting (710), to a non 3rdGeneration Partnership Project, non-3GPP, gateway or proxy, an Internet Key Exchange Authentication, IKE_AUTH, request containing Access Traffic Steering, Switching and Splitting, ATSSS, capabilities indicating that the terminal device supports direct QUIC connections to a User Plane Function, UPF, without Internet Protocol, IP, Security, IPsec, tunnel over non-3GPP access.
6. The method (700) of claim 5, further comprising: receiving, from the non-3GPP gateway or proxy, an IKE_AUTH response; deriving a Transport Layer Security, TLS, Pre-Shared Key, PSK, based on authentication key credential; and transmitting a QUIC connection establishment request for QUIC connection establishment over non-3GPP access, the QUIC connection establishment request being protected by the derived TLS PSK.
7. A method (800) in a non 3rdGeneration Partnership Project, non-3GPP, gateway or proxy, comprising: receiving (810), from a terminal device, an Internet Key Exchange Authentication, IKE_AUTH, request containing Access Traffic Steering, Switching and Splitting, ATSSS, capabilities indicating that the terminal device supports QUIC connections to a User Plane Function, UPF, without Internet Protocol ‘IP’ Security, IPsec, tunnel over non-3GPP access.
8. The method (800) of claim 7, further comprising: deriving a Transport Layer Security, TLS, Pre-Shared Key, PSK, based on authentication key credential; and transmitting, to a Session Management Function, SMF, a request containing the derived TLS PSK.
9. The method (800) of claim 8, wherein the request further contains information on a General Packet Radio Service ‘GPRS’ Tunneling Protocol - User Plane, GTP-U, tunnel of the non-3GPP gateway or proxy.
10. The method (800) of claim 9, further comprising: transmitting, to the terminal device, an IKE_AUTH response containing a QUIC proxy Internet Protocol, IP, address that is set as an IP address of the non-3GPP gateway or proxy.
11. The method (800) of claim 9 or 10, further comprising: receiving a QUIC connection establishment request for QUIC connection establishment over non-3GPP access, the QUIC connection establishment request being protected by the TLS PSK; and correlating the QUIC connection establishment request with the GTP-U tunnel for a Packet Data Unit, PDU, session of the terminal device.
12. The method (800) of claim 11 , further comprising: receiving, from the terminal device, a QUIC packet; and changing a destination address of the QUIC packet into a QUIC Proxy address of the UPF, and forwarding the QUIC packet to the UPF via the correlated GTP-U tunnel.
13. A method (900) in a Session Management Function, SMF, comprising: receiving (910), from a non 3rdGeneration Partnership Project, non-3GPP, gateway or proxy, a request containing a Transport Layer Security, TLS, Pre-Shared Key, PSK.
14. The method (900) of claim 13, further comprising: transmitting, to a User Plane Function, UPF, a request containing the TLS PSK and Access Traffic Steering, Switching and Splitting, ATSSS, capabilities of a terminal device, the ATSSS capabilities indicating that the terminal devicesupports direct QUIC connections to the UPF without Internet Protocol ‘IP’ Security, IPsec, tunnel over non-3GPP access.
15. A method (1000) in a User Plane Function, UPF, comprising: receiving (1010), from a Session Management Function, SMF, a request containing a Transport Layer Security, TLS, Pre-Shared Key, PSK, and Access Traffic Steering, Switching and Splitting, ATSSS, capabilities of a terminal device, the ATSSS capabilities indicating that the terminal device supports direct QUIC connections to the UPF without Internet Protocol ‘IP’ Security, IPsec, tunnel over non 3rdGeneration Partnership Project, non-3GPP, access.
16. The method (1000) of claim 15, further comprising: receiving a QUIC connection establishment request for QUIC connection establishment over non-3GPP access, the QUIC connection establishment request being protected by the TLS PSK.
17. The method (1000) of claim 16, further comprising: correlating the QUIC connection establishment request with a Packet Data Unit, PDU, session context for the terminal device; and handling the QUIC connection establishment request from the terminal device based on the TLS PSK.
18. A terminal device (1200), comprising a communication interface (1210), a processor (1220), and a memory (1230), the memory (1230) comprising instructions executable by the processor (1220) whereby the terminal device (1200) is operative to perform the method according to any of claims 1-2 or claims 5-6.
19. A computer-readable storage medium having computer-readable instructions stored thereon, the computer-readable instructions, when executed by a processor of a terminal device, configure the terminal device to perform the method according to any of claims 1-2 or claims 5-6.2520. A network node (1300), comprising a communication interface (1310), a processor (1320), and a memory (1330), the memory (1330) comprising instructions executable by the processor (1320) whereby the network node (1300) is operative to, when implementing a User Plane Function, UPF, perform the method according to any of claims 3-4 or claims 15-17, or when implementing a non 3rdGeneration Partnership Project, non-3GPP, gateway or proxy, perform the method according to any of claims 7-12, or when implementing a Session Management Function, SMF, perform the method according to claim 13 or 14.
21. A computer-readable storage medium having computer-readable instructions stored thereon, the computer-readable instructions, when executed by a processor of a network node, configure the network node to, when implementing a User Plane Function, UPF, perform the method according to any of claims 3-4 or claims 15-17, or when implementing a non 3rdGeneration Partnership Project, non-3GPP, gateway or proxy, perform the method according to any of claims 7-12, or when implementing a Session Management Function, SMF, perform the method according to claim 13 or 14.26