Apparatus and method for establishing multi-access protocol data unit session in wireless communication system

By co-locating the ePDG with the UPF and employing MPQUIC, the solution addresses the challenge of establishing multi-access PDU sessions in wireless communication systems, simplifying network operations and enhancing security in non-3GPP access scenarios.

WO2025173896A1PCT designated stage Publication Date: 2025-08-21LG ELECTRONICS INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/021279
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2024-12-27
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in establishing multi-access PDU sessions without relying on network nodes like N3IWF and TNGF, particularly in non-3GPP access scenarios, which complicates network operations and security.

Method used

The proposed solution involves co-locating an evolved packet data gateway (ePDG) with the user plane function (UPF) to enable multi-access PDU sessions, allowing for simplified access traffic steering, switching, and splitting, and utilizing null encryption based on the activation of multipath quick UDP internet connections (MPQUIC) for authentication.

Benefits of technology

This approach supports ATSSS without the need for N3IWF and TNGF, simplifying network operations and enhancing security in non-3GPP access scenarios, while enabling efficient multi-access PDU session establishment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024021279_21082025_PF_FP_ABST
    Figure KR2024021279_21082025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to establishment of a multi-access (MA) protocol data unit (PDU) session in a wireless communication system, wherein a method performed by user equipment comprises the steps of: transmitting, through a first access, a first message related to establishment of a protocol data unit (PDU) session; receiving, by the user equipment, a second message related to establishment of a PDU session; and establishing, on the basis of the second message, an MA PDU session having a first access leg and a second access leg, wherein the first message may include a message requesting the establishment of the MA PDU session, and the second message may include information related to a second access.
Need to check novelty before this filing date? Find Prior Art

Description

Device and method for establishing a multiple access protocol data unit session in a wireless communication system

[0001] The following description relates to a wireless communication system, and to a device and method for establishing a multi-access (MA) protocol data unit (PDU) session.

[0002] Wireless access systems are widely deployed to provide various types of communication services, such as voice and data. Typically, wireless access systems are multiple access systems that support communications with multiple users by sharing available system resources (e.g., bandwidth, transmission power). Examples of multiple access systems include code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), orthogonal frequency division multiple access (OFDMA), and single-carrier frequency division multiple access (SC-FDMA).

[0003] In particular, as numerous communication devices demand greater communication capacity, enhanced mobile broadband (eMBB) communication technologies are being proposed, improving upon existing radio access technology (RAT). Furthermore, massive machine type communications (mMTC), which connects numerous devices and objects to provide diverse services anytime and anywhere, as well as communication systems that consider reliability and latency-sensitive services / user equipment (UE), are being proposed. Various technological configurations are being proposed for these purposes.

[0004] The present disclosure relates to a device and method for establishing a multi-access (MA) PDU session in a wireless communication system.

[0005] The present disclosure relates to a device and method for supporting a simplified access traffic steering, switching, splitting (ATSS) architecture in a wireless communication system.

[0006] The present disclosure relates to a device and method for establishing a MA PDU session based on an evolved packet data gateway (ePDG) co-located in a user plane function (UPF) in a wireless communication system.

[0007] The present disclosure relates to a device and method for obtaining information related to non-3GPP access through 3GPP access in a wireless communication system.

[0008] The present disclosure relates to a device and method for obtaining address information of an ePDG from a UPF via 3GPP access in a wireless communication system.

[0009] The present disclosure relates to a device and method for accessing non-3GPP access based on address information of an ePDG obtained through 3GPP access in a wireless communication system.

[0010] The present disclosure relates to a device and method for adding a non-3GPP access path to a MA PDU session based on address information of an ePDG acquired through 3GPP access in a wireless communication system.

[0011] The present disclosure relates to a device and method for providing information indicating null encryption in a wireless communication system.

[0012] The present disclosure relates to a device and method for determining the use of null encryption based on the activation of a multipath quick UDP internet connections (MPQUIC) steering function in a wireless communication system.

[0013] The present disclosure relates to a device and method for performing authentication on a terminal for establishing a MA PDU session in a wireless communication system.

[0014] The technical objectives to be achieved in the present disclosure are not limited to those mentioned above, and other technical tasks not mentioned can be considered by a person having ordinary skill in the technical field to which the technical configuration of the present disclosure is applied from the embodiments of the present disclosure described below.

[0015] As an example of the present disclosure, a method includes a step of a terminal transmitting a first message related to establishing a protocol data unit (PDU) session through a first access, a step of the terminal receiving a second message related to establishing the PDU session, and a step of establishing a multi-access (MA) PDU session having a first access path and a second access path based on the second message, wherein the first message may include a message requesting establishment of the MA PDU session, and the second message may include information related to the second access.

[0016] As an example of the present disclosure, the method includes a step of a first network node receiving a first message related to establishing a protocol data unit (PDU) session from a terminal through a first access, a step of the first network node obtaining information related to a second access, and a step of the first network node transmitting a second message related to establishing a PDU session, wherein the first message includes a message requesting establishment of the multi-access (MA) PDU session, and the second message may include information related to the second access.

[0017] As an example of the present disclosure, the method includes a step of a second network node requesting information related to a second access from a first network node, and a step of the second network node transmitting the information related to the second access to the first network node, wherein the information related to the second access may include address information of an evolved packet data gateway (ePDG) co-located with the second network node.

[0018] As an example of the present disclosure, a device includes a transceiver and a processor connected to the transceiver, wherein the processor controls to transmit a first message related to establishing a protocol data unit (PDU) session through a first access, receive a second message related to establishing the PDU session, and establish a multi-access (MA) PDU session having a first access path and a second access path based on the second message, wherein the first message includes a message requesting establishment of the MA PDU session, and the second message includes information related to the second access.

[0019] As an example of the present disclosure, a device includes a transceiver and a processor connected to the transceiver, wherein the processor receives a first message related to establishing a protocol data unit (PDU) session from a terminal through a first access, obtains information related to a second access, and controls transmission of a second message related to establishing a PDU session, wherein the first message includes a message requesting establishment of the multi-access (MA) PDU session, and the second message includes information related to the second access.

[0020] As an example of the present disclosure, a device includes a transceiver and a processor connected to the transceiver, wherein the processor is configured to receive information related to a second access from a first network node and control the first network node to transmit the information related to the second access, wherein the information related to the second access may include address information of an evolved packet data gateway (ePDG) co-located with the second network node.

[0021] As an example of the present disclosure, a communication device includes at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, direct operations, the operations including: a step of a terminal transmitting a first message related to establishing a protocol data unit (PDU) session through a first access; a step of the terminal receiving a second message related to establishing the PDU session; and a step of establishing a multi-access (MA) PDU session having a first access path and a second access path based on the second message, wherein the first message may include a message requesting establishment of the MA PDU session, and the second message may include information related to the second access.

[0022] As an example of the present disclosure, a non-transitory computer-readable medium stores at least one instruction executable by a processor, the at least one instruction controlling to transmit a first message related to establishing a protocol data unit (PDU) session through a first access, receive a second message related to establishing the PDU session, and establish a multi-access (MA) PDU session having a first access path and a second access path based on the second message, wherein the first message may include a message requesting establishment of the MA PDU session, and the second message may include information related to the second access.

[0023] The above-described aspects of the present disclosure are only some of the preferred embodiments of the present disclosure, and various embodiments reflecting the technical features of the present disclosure can be derived and understood by a person having ordinary skill in the art based on the detailed description of the present disclosure to be described below.

[0024] The following effects may be achieved by embodiments based on the present disclosure.

[0025] The present disclosure can support ATSSS (access traffic steering, switching, splitting) without support of network nodes such as existing N3IWF (non-3GPP interworking function) and / or TNGF (trusted non-3GPP gateway function) in a wireless communication system.

[0026] The effects that can be obtained from the embodiments of the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned can be clearly derived and understood by those skilled in the art to which the technical configuration of the present disclosure is applied, from the description of the embodiments of the present disclosure below. In other words, unintended effects that result from implementing the configuration described in the present disclosure can also be derived by those skilled in the art from the embodiments of the present disclosure.

[0027] The accompanying drawings are intended to aid in understanding the present disclosure and, together with detailed descriptions, may provide embodiments of the present disclosure. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form new embodiments. Reference numerals in each drawing may indicate structural elements.

[0028] Figure 1 illustrates an example of a communication system applicable to the present disclosure.

[0029] FIG. 2 illustrates an example of a user equipment (UE) applicable to the present disclosure.

[0030] FIG. 3 illustrates an example of functional separation of a next generation radio access network (NG-RAN) and a 5th generation core (5GC) applicable to the present disclosure.

[0031] FIG. 4 illustrates an example of a general architecture of a 5G (5th generation) system applicable to the present disclosure.

[0032] FIG. 5a and FIG. 5b illustrate examples of the overall architecture according to embodiments of the present disclosure.

[0033] FIG. 6 illustrates an example of a MA PDU session establishment procedure according to an embodiment of the present disclosure.

[0034] FIG. 7a and FIG. 7b illustrate examples of a MA PDU session establishment procedure according to an embodiment of the present disclosure.

[0035] FIG. 8 illustrates an example of a procedure for establishing an MA PDU session according to an embodiment of the present disclosure.

[0036] FIG. 9 illustrates an example of a procedure for obtaining information related to a second access according to an embodiment of the present disclosure.

[0037] FIG. 10 illustrates an example of a procedure for transmitting information related to a second access according to an embodiment of the present disclosure.

[0038] The following embodiments combine components and features of the present disclosure in a predetermined form. Each component or feature may be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, some components and / or features may be combined to form embodiments of the present disclosure. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment.

[0039] In the description of the drawings, procedures or steps that may obscure the gist of the present disclosure are not described, and procedures or steps that can be understood by a person skilled in the art are also not described.

[0040] Throughout the specification, when a part is said to "comprising" or "including" a component, this does not mean that other components may be included, but rather that other components may be excluded, unless otherwise specifically stated. In addition, terms such as "...part," "...unit," and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware, software, or a combination of hardware and software. In addition, the words "a" or "an," "one," "the," and similar related words may be used in the context of describing the present disclosure (especially in the context of the claims below) to include both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context.

[0041] Embodiments of the present disclosure described herein focus on the data transmission and reception relationship between a base station and a mobile station. Here, the base station is understood as a terminal node of a network that directly communicates with the mobile station. Certain operations described herein as being performed by the base station may, in some cases, be performed by an upper node of the base station.

[0042] That is, in a network consisting of multiple network nodes including a base station, various operations performed for communication with a mobile station may be performed by the base station or other network nodes other than the base station. In this case, the term 'base station' may be replaced by terms such as fixed station, Node B, eNB (eNode B), gNB (gNode B), ng-eNB, advanced base station (ABS), or access point.

[0043] Additionally, in embodiments of the present disclosure, the term terminal may be replaced with terms such as user equipment (UE), mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, or advanced mobile station (AMS).

[0044] Additionally, a transmitter refers to a fixed and / or mobile node that provides data or voice services, and a receiver refers to a fixed and / or mobile node that receives data or voice services. Therefore, for uplink, a mobile station can be the transmitter, and a base station can be the receiver. Similarly, for downlink, a mobile station can be the receiver, and a base station can be the transmitter.

[0045] Embodiments of the present disclosure are wireless access systems such as IEEE 802.xx system, 3rd Generation Partnership Project (3GPP) system, 3GPP Long Term Evolution (LTE) system, 3GPP 5G (5 th generation) NR (New Radio) system and 3GPP2 system, and in particular, embodiments of the present disclosure may be supported by 3GPP TS (technical specification) 38.211, 3GPP TS 38.212, 3GPP TS 38.213, 3GPP TS 38.321 and 3GPP TS 38.331 documents.

[0046] Furthermore, the embodiments of the present disclosure can be applied to other wireless access systems and are not limited to the aforementioned systems. For example, they can also be applied to systems implemented after the 3GPP 5G NR system, and are not limited to a specific system.

[0047] That is, obvious steps or parts not described in the embodiments of the present disclosure can be explained by referring to the above documents. In addition, all terms disclosed in this document can be explained by the above standard documents.

[0048] Hereinafter, preferred embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to illustrate exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the technical configurations of the present disclosure may be implemented.

[0049] Additionally, specific terms used in the embodiments of the present disclosure are provided to aid in understanding the present disclosure, and the use of such specific terms may be changed to other forms without departing from the technical spirit of the present disclosure.

[0050] The following technology can be applied to various wireless access systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access).

[0051] For clarity, the following description is based on a 3GPP communication system (e.g., LTE, NR, etc.), but the technical spirit of the present invention is not limited thereto. LTE may refer to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 may be referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 may be referred to as LTE-A pro. 3GPP NR may refer to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. "xxx" refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system.

[0052] For background information, terms, abbreviations, etc. used in this disclosure, reference may be made to standard documents published prior to the present invention. For example, reference may be made to the 36.xxx and 38.xxx standard documents.

[0053] For terms, abbreviations, and other background technologies that may be used in this document, please refer to the following standard documents published prior to this document. In particular, terms, abbreviations, and other background technologies related to LTE / EPS (Evolved Packet System) can refer to the 36.xxx series, 23.xxx series, and 24.xxx series, and terms, abbreviations, and other background technologies related to NR (new radio) / 5GS (5G system) can refer to the 38.xxx series, 23.xxx series, and 24.xxx series.

[0054] Hereinafter, this specification is described based on the terms defined above.

[0055] The three key requirement areas for 5G include (1) Enhanced Mobile Broadband (eMBB), (2) Massive Machine Type Communication (mMTC), and (3) Ultra-reliable and Low Latency Communications (URLLC).

[0056] Some use cases may require optimization across multiple domains, while others may focus on just one Key Performance Indicator (KPI). 5G supports these diverse use cases in a flexible and reliable manner.

[0057]

[0058] Communication system applicable to the present disclosure

[0059] Although not limited thereto, the various descriptions, functions, procedures, proposals, methods and / or operational flowcharts of the present disclosure disclosed in this document may be applied to various fields requiring wireless communication / connectivity (e.g., 5G) between devices.

[0060] Hereinafter, more specific examples will be provided with reference to the drawings. In the drawings / descriptions below, the same drawing reference numerals may represent identical or corresponding hardware blocks, software blocks, or functional blocks, unless otherwise described.

[0061] Figure 1 illustrates an example of a communication system applied to the present disclosure.

[0062] Referring to FIG. 1, a communication system (100) applied to the present disclosure includes a wireless device, a base station, and a network. Here, the wireless device refers to a device that performs communication using a wireless access technology (e.g., 5G NR, LTE) and may be referred to as a communication / wireless / 5G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (extended reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Things) device (100f), and an AI (artificial intelligence) device / server (100g). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicles (100b-1, 100b-2) may include unmanned aerial vehicles (UAVs) (e.g., drones). The XR devices (100c) include augmented reality (AR) / virtual reality (VR) / mixed reality (MR) devices, and may be implemented in the form of head-mounted devices (HMDs), head-up displays (HUDs) installed in vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signage, vehicles, robots, etc. The portable devices (100d) may include smartphones, smart pads, wearable devices (e.g., smartwatches, smart glasses), computers (e.g., laptops, etc.), etc. The home appliances (100e) may include TVs, refrigerators, washing machines, etc. The IoT devices (100f) may include sensors, smart meters, etc. For example, the base station (120) and the network (130) may also be implemented as wireless devices, and a specific wireless device (120a) may act as a base station / network node to other wireless devices.

[0063] Wireless devices (100a to 100f) can be connected to a network (130) via a base station (120). AI technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (100g) via a network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, etc. The wireless devices (100a to 100f) can communicate with each other via the base station (120) / network (130), but can also communicate directly (e.g., sidelink communication) without going through the base station (120) / network (130). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). In addition, IoT devices (100f) (e.g., sensors) can communicate directly with other IoT devices (e.g., sensors) or other wireless devices (100a to 100f).

[0064] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a to 100f) / base stations (120), and base stations (120) / base stations (120). Here, the wireless communication / connection can be established through various wireless access technologies (e.g., 5G NR) such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and communication between base stations (150c) (e.g., relay, IAB (integrated access backhaul)). Through the wireless communication / connection (150a, 150b, 150c), the wireless device and base station / wireless device, and base stations and base stations can transmit / receive wireless signals to / from each other. For example, the wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, based on various proposals of the present disclosure, at least some of various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), resource allocation processes, etc. may be performed.

[0065] Figure 2 illustrates an example of a UE applicable to the present disclosure.

[0066] Referring to FIG. 2, the UE (200) may include a processor (102), memory (104), a transceiver (106), one or more antennas (108), a power management module (141), a battery (142), a display (143), a keypad (144), a SIM (Subscriber Identification Module) card (145), a speaker (146), and a microphone (147).

[0067] The processor (102) may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed herein. The processor (102) may be configured to control one or more other components of the UE (200) to implement the descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed herein. A layer of a radio interface protocol may be implemented in the processor (102). The processor (102) may include an ASIC, other chipset, logic circuit, and / or data processing device. The processor (102) may be an application processor. The processor (102) may include at least one of a DSP, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a modem (modulator and demodulator).

[0068] The memory (104) is operatively coupled to the processor (102) and can store various information for operating the processor (102). The memory (104) may include ROM, RAM, flash memory, a memory card, a storage medium, and / or other storage devices. When the implementation is implemented in software, the techniques described herein may be implemented using modules (e.g., procedures, functions, etc.) that perform the descriptions, functions, procedures, suggestions, methods, and / or operational flowcharts disclosed herein. The modules may be stored in the memory (14) and executed by the processor (102). The memory (104) may be implemented within the processor (102) or external to the processor (102), in which case it may be communicatively coupled to the processor (102) via various methods known in the art.

[0069] A transceiver (106) is operably coupled to the processor (102) and is capable of transmitting and / or receiving radio signals. The transceiver (106) may include a transmitter and a receiver. The transceiver (106) may include baseband circuitry for processing radio frequency signals. The transceiver (106) may control one or more antennas (108) to transmit and / or receive radio signals.

[0070] The power management module (141) can manage the power of the processor (102) and / or the transceiver (106). The battery (142) can supply power to the power management module (141).

[0071] The display (143) can output the results processed by the processor (102). The keypad (144) can receive input to be used by the processor (102). The keypad (144) can be displayed on the display (143).

[0072] A SIM card (145) is an integrated circuit that securely stores an International Mobile Subscriber Identity (IMSI) and associated keys, and can be used to identify and authenticate subscribers in mobile devices such as mobile phones and computers. Additionally, contact information can be stored on many SIM cards.

[0073] The speaker (146) can output sound-related results processed by the processor (102). The microphone (147) can receive sound-related input to be used by the processor (102).

[0074] In implementations of this specification, a UE may operate as a transmitter in the uplink and as a receiver in the downlink. In implementations of this specification, a base station may operate as a receiver in the uplink and as a transmitter in the downlink. In this specification, a base station may be referred to as a Node B (Node B), an eNode B (eNB), or a gNB, and may not be limited to a specific form.

[0075] In addition, for example, the UE may be implemented in various forms depending on the use case / service. The UE may be composed of various components, devices / parts, and / or modules. For example, each UE may include a communication device, a control device, a memory device, and additional components. The communication device may include a communication circuit and a transceiver. For example, the communication circuit may include one or more processors and / or one or more memories. For example, the transceiver may include one or more transceivers and / or one or more antennas. The control device is electrically connected to the communication device, the memory device, and the additional components, and may control the overall operation of each UE. For example, the control device may control the electrical / mechanical operation of each UE based on a program / code / command / information stored in the memory device. The control device may transmit information stored in the memory device to an external device (e.g., another communication device) via the communication device via a wireless / wired interface, or may store information received from an external device (e.g., another communication device) via the communication device via a wireless / wired interface in the memory device.

[0076] Additional components may be configured in various ways depending on the type of UE. For example, the additional components may include at least one of a power unit / battery, an input / output (I / O) device (e.g., an audio I / O port, a video I / O port), a driving device, and a computing device. In addition, the UE is not limited thereto, and may be implemented in the form of a robot (100a in FIG. 1), a vehicle (100b-1 and 100b-2 in FIG. 1), an XR device (100c in FIG. 1), a portable device (100d in FIG. 1), a home appliance (100e in FIG. 1), an IoT device (100f in FIG. 1), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (100g in FIG. 1), a base station (120 in FIG. 1), or a network node. UE can be used in mobile or fixed locations depending on the use case / service.

[0077] The various components, devices / parts, and / or modules of the UE may all be connected to each other via a wired interface, or at least some of them may be connected wirelessly via a communication device. In addition, each component, device / part, and / or module of the UE may further include one or more elements. For example, the control device may be configured by a set of one or more processors. For example, the control device may be configured by a set of a communication control processor, an application processor (AP), an electronic control unit (ECU), a graphics processing unit, and a memory control processor. As another example, the memory device may be configured by a random access memory (RAM), a dynamic random access memory (DRAM), a read-only memory (ROM), a flash memory, a volatile memory, a non-volatile memory, and / or a combination thereof.

[0078] 5G system architecture applicable to the present disclosure

[0079] The 5G system is an advanced technology from the 4th generation LTE mobile communication technology. It supports new radio access technology (RAT: Radio Access Technology), extended LTE (eLTE) as an extended technology of LTE (Long Term Evolution), and non-3GPP (e.g., WLAN) access through the evolution or clean-state structure of the existing mobile communication network structure.

[0080] 5G systems are defined as service-based, and the interactions between network functions (NFs) within the architecture for 5G systems can be expressed in two ways as follows.

[0081] - Reference point representation: Represents the interaction between NF services within NFs described by a point-to-point reference point (e.g., N11) between two NFs (e.g., AMF and SMF).

[0082] Service-based representation: Network functions (e.g., AMF) within the control plane (CP) allow other authorized network functions to access their services. This representation also includes point-to-point reference points, if necessary.

[0083] 5GC (5G Core) can include various components, some of which include access and mobility management function (AMF), session management function (SMF), policy control function (PCF), user plane function (UPF), application function (AF), unified data management (UDM), and non-3GPP interworking function (N3IWF).

[0084] The UE connects to the data network via the UPF via the next-generation radio access network (NG-RAN) that includes the gNB. The UE can receive data services via untrusted non-3GPP access points, such as wireless local area networks (WLANs). To connect non-3GPP access points to the core network, an N3IWF may be deployed.

[0085] The N3IWF manages interworking between non-3GPP access and 5G systems. When a UE is connected to a non-3GPP access (e.g., WiFi, also known as IEEE 802.11), it can connect to a 5G system via the N3IWF. The N3IWF performs control signaling with the AMF and connects to the UPF via the N3 interface for data transmission.

[0086] AMF can manage access and mobility in 5G systems. It can also manage non-access stratum (NAS) security. It can also handle mobility in idle states.

[0087] The UPF functions as a gateway for transmitting and receiving user data. A UPF node can perform all or part of the user plane functions of a 4G mobile communications S-GW (serving gateway) and P-GW (packet data network gateway).

[0088] The UPF acts as a boundary point between the next generation RAN (NG-RAN) and the core network, and is an element that maintains the data path between the gNB and the SMF. In addition, the UPF acts as a mobility anchor point when the UE moves across the area served by the gNB. The UPF can perform the function of handling PDUs. For mobility within the NG-RAN (e.g., NG-RAN defined after 3GPP Release-15), the UPF can route packets. In addition, the UPF can also act as an anchor point for mobility with other 3GPP networks (e.g., RAN defined before 3GPP Release-15), such as UTRAN (UMTS (universal mobile telecommunications system) terrestrial radio access network), E-UTRAN (evolved-UTRAN), or GERAN (GSM (global system for mobile communication) / EDGE (enhanced data rates for global evolution) radio access network). A UPF may correspond to the termination point of a data interface toward a data network.

[0089] The PCF is a node that controls the operator's policies. The AF is a server that provides various services to UEs. The UDM is a server that manages subscriber information, similar to the HSS (home subscriber server) of 4G mobile communications. The UDM (460) stores and manages subscriber information in a unified data repository (UDR).

[0090] The SMF can perform the function of assigning an IP (Internet protocol) address to the UE. In addition, the SMF can control the PDU (protocol data unit) session.

[0091] For convenience of explanation below, the drawing symbols for AMF, SMF, PCF, UPF, AF, UDM, N3IWF, gNB, or UE may be omitted, and operation may be performed by referring to the matters described in standard documents published prior to this document.

[0092] Figure 3 illustrates an example of functional separation of NG-RAN and 5GC (5th generation core) applicable to the present disclosure.

[0093] Referring to Figure 3, the UE connects to a data network (DN) via a next-generation RAN. The control plane function (CPF) node performs all or part of the functions of the mobility management entity (MME) of 4G mobile communications, and all or part of the control plane functions of the serving gateway (S-GW) and the PDN gateway (P-GW). The CPF node includes the AMF and the SMF.

[0094] The UPF node functions as a gateway through which user data is transmitted and received.

[0095] The authentication server function (AUSF) authenticates and manages UEs. The Network Slice Selection Function (NSSF) is a node for network slicing, as described below.

[0096] The network exposure function (NEF) provides a mechanism to securely expose the services and functions of the 5G core.

[0097]

[0098] The reference points shown in Fig. 3 are as follows. N1 represents a reference point between the UE and the AMF. N2 represents a reference point between the (R)AN and the AMF. N3 represents a reference point between the (R)AN and the UPF. N4 represents a reference point between the SMF and the UPF. N5 represents a reference point between the PCF and the AF. N6 represents a reference point between the UPF and the DN. N7 represents a reference point between the SMF and the PCF. N8 represents a reference point between the UDM and the AMF. N9 represents a reference point between the UPFs. N10 represents a reference point between the UDM and the SMF. N11 represents a reference point between the AMF and the SMF. N12 represents a reference point between the AMF and the AUSF. N13 represents a reference point between the UDM and the AUSF. N14 represents a reference point between the AMFs. N15 represents a reference point between a PCF and an AMF in a non-roaming scenario, and a reference point between an AMF and a PCF of a visited network in a roaming scenario. N16 represents a reference point between SMFs. N22 represents a reference point between an AMF and an NSSF. N30 represents a reference point between a PCF and an NEF. N33 may represent a reference point between an AF and an NEF, and the entities and interfaces described above may be configured with reference to those described in standard documents published before this document. N58 represents a reference point between an AMF and an NSSAAF. N59 represents a reference point between a UDM and an NSSAAF. N80 represents a reference point between an AMF and an NSACF. N81 represents a reference point between an SMF and an NSACF.

[0099] The radio interface protocol is based on the 3GPP radio access network standard. Horizontally, the radio interface protocol consists of the physical layer, data link layer, and network layer. Vertically, it is divided into the user plane for data information transmission and the control plane for control signaling.

[0100] Protocol layers can be divided into L1 (layer-1), L2 (layer-2), and L3 (layer-3) based on the three lower layers of the open systems interconnection (OSI) standard model, which is widely known in communication systems.

[0101] Below, the present disclosure describes each layer of the wireless protocol. Figure 4 illustrates an example of a general architecture of a 5G (5th generation) system applicable to the present disclosure.

[0102] Referring to FIG. 4, the AS (access stratum) layer may include a physical (PHY) layer, a medium access control layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, and a radio resource control (RRC) layer, and operations based on each layer may be performed by referring to matters described in standard documents published prior to this document.

[0103]

[0104] Specific embodiments of the present disclosure

[0105] The present disclosure relates to a device and method for establishing a multi-access (MA) PDU session in a wireless communication system. Specifically, the present disclosure relates to a device and method for establishing an MA PDU session based on a simplified access traffic steering, switching, and splitting (ATSS) architecture in which an evolved packet data gateway (ePDG) is co-located with a user plane function (UPF) in a wireless communication system.

[0106]

[0107] 3GPP is developing solutions for DualSteer and ATSSS_Ph4 (access traffic steering, switching, and splitting, phase 4) as part of its research on multi-access in Rel-19. That is, 3GPP is developing solutions for steering, switching, and splitting terminal traffic over two 3GPP access links. Specifically, research is being conducted for the following goals. Use cases and service requirements are described in TR 22.841, "Study on Upper Layer Traffic Steer, Switch, and Split over Dual 3GPP Access."

[0108] ----------------------------------------------------------------------

[0109] 4. Goal

[0110] The following aspects will be studied:

[0111] ATSSS_Ph4 Work Assignment:

[0112] WT#2: Investigate ways to extend MPQUIC steering capabilities to allow steering, switching, and segmentation of non-UDP traffic (TCP, IP, Ethernet traffic).

[0113] WT#3: Study whether and how to define a functional architecture and procedures for steering, switching, and segmenting of traffic that is not currently based on TNGF / N3IWF to simplify operations in non-3GPP access without compromising the security of 5G networks.

[0114] WT#3.1: Investigate whether to maintain NAS signaling connections in non-3GPP accesses, and whether to remove IPSec tunnel encapsulation only in the user plane or in both the control plane and the user plane, to simplify the protocol stack and reduce user plane overhead.

[0115] WT#3.2: Investigate whether and how to support segmentation, switching, and steering between 3GPP access and "non-3GPP access without 5G NAS." Investigate whether and how to improve registration and security aspects to support "non-3GPP access without 5G NAS."

[0116] Note 10: This WT requires coordination with SA3 to handle security aspects.

[0117] ----------------------------------------------------------------------

[0118] Among the WTs mentioned above, the key issues for WT#3.1 and WT#3.2 were approved as follows and reflected in TR 23.700-54.

[0119] ----------------------------------------------------------------------

[0120] 5.2.2 Key Issue #2.2: Simplified ATSSS Architecture with Non-3GPP Access

[0121] 5.2.2.1 Description

[0122] The current ATSSS architecture requires non-3GPP access to be provided via either trusted or untrusted non-3GPP access procedures. This means that TNGF or N3IWF must be deployed to enable ATSSS. This core issue explores whether and how to define the functional architecture and procedures for steering, switching, and segmenting traffic that does not utilize TNGF / N3IWF, as specified in Rel-18 and previous releases (TS 23.501), to simplify network operations via non-3GPP access without compromising the security of 5G networks. In particular, this core issue explores the following issues:

[0123] 1) Simplification of the protocol stack

[0124] - Whether and how to remove NAS signal connections via non-3GPP access.

[0125] - Whether and how to remove IPSec tunnel encapsulation only in the user plane or in both the control plane and the user plane to simplify the UE protocol stack and reduce user plane overhead.

[0126] 2) “Non-3GPP access without 5G NAS via non-3GPP”.

[0127] - Whether and how to support segmentation, switching, and steering between 3GPP access and “non-3GPP access without 5G NAS via non-3GPP”.

[0128] - Whether and how to enhance registration and security aspects to support "non-3GPP access without 5G NAS via non-3GPP." This may also include investigating whether registration can be used over non-3GPP access.

[0129] NOTE: During the study of this KI, SA WG3 should be consulted to address security aspects.

[0130] ----------------------------------------------------------------------

[0131] The present disclosure proposes a solution to the aforementioned core issues. In the present disclosure, a terminal may include a UE, and a user may include a subscriber. In addition, an application server (AS) may include an application function (AF). A multi-access (MA) PDU session may include at least one of a dual-access (DA) session, a dual steer (DS) PDU session, a dual steering PDU session, a dual 3GPP access PDU session, and a multi-3GPP PDU session. This refers to a PDU session that provides a PDU connection service that can use one 3GPP access network at a time or two 3GPP access networks simultaneously. In the present disclosure, a public land mobile network (PLMN) may be understood to be replaceable with a standalone non-public network (SNPN), an equivalent PLMN, etc., and an SNPN may be understood to be replaceable with a PLMN.

[0132] The present disclosure fundamentally reuses the existing evolved packet data gateway (ePDG) architecture and / or functionality. The ePDG is a network node that performs functions to support the secure connection of a terminal to a non-3GPP access network. For example, it can encrypt and protect data transmission by establishing an IPsec tunnel between the terminal and the non-3GPP access network. In the present disclosure, the ePDG is co-located with the PSA (PDU session anchor) UPF. The present disclosure proposes two options for supporting authentication of a UE via the ePDG. Option 1 utilizes the existing architecture for interaction between the ePDG / EPC and the 5GS, as illustrated in FIG. 5a. Option 2 introduces a new interface between the SMF and the AUSF, as illustrated in FIG. 5b, thereby eliminating the use of a legacy interface in the UPF.

[0133] FIG. 5A and FIG. 5B illustrate examples of the overall architecture according to an embodiment of the present disclosure. FIG. 5A is an example of an architecture for a case where an AAA server is used for authentication, and FIG. 5B is an example of an architecture for a case where an AUSF is used for authentication.

[0134] Referring to FIGS. 5A and 5B, a UE (510) can establish a MA PDU session via a 3GPP access (520). When the UE (510) establishes a MA PDU session via a 3GPP access (520), a session management function (SMF) + packet gateway control plane (PGW-C) (540) provides the UE (510) with information on an ePDG (552) to be used via a non-3GPP (N3GPP) access (580) based on interaction with a PSA UPF (550). When the UE (510) receives the information on the ePDG (552), the UE (510) triggers a connection procedure to the ePDG and / or 5GC using existing procedures, through which authentication for the UE is performed and a non-3GPP access path is added to the established MA PDU session. During this procedure, the UE (510) and / or the ePDG (552) may use null encryption to prevent duplicate encryption.

[0135]

[0136] FIG. 6 illustrates an example of a multi-access PDU session establishment procedure according to an embodiment of the present disclosure. In FIG. 6, the ePDG is co-located with the PSA UPF. FIG. 6 illustrates an example of a MA PDU session establishment procedure when using an AAA server for authentication, as in Option 1.

[0137] Referring to FIG. 6, in step 1, UE (610) performs registration via 3GPP access. For example, UE (610) may perform the registration procedure via NG-RAN (620) and AMF (630).

[0138] In step 2, the UE (610) transmits a PDU Session Establishment Request message to establish an MA PDU session. The PDU Session Establishment Request message may include first information indicating that the UE supports the simplified ATSSS architecture via non-3GPP access. The PDU Session Establishment Request message is transmitted to the SMF and PGW-C (640) via the NG-RAN (620) and the AMF (630).

[0139] In step 3, the SMF and PGW-C (640) and the PSA UPF (650) establish an N4 session. Here, the PSA UPF (650) may include a co-located ePDG (652). Based on information indicating that the UE supports the simplified ATSSS architecture via non-3GPP access, the SMF and PGW-C (640) requests the PSA UPF (650) to allocate an ePDG address to be used for the MA PDU session. The PSA UPF (650) provides the SMF and PGW-C (640) with information about the ePDG address to be used for the MA PDU session.

[0140] According to one embodiment, when the SMF and PGW-C (640) decide to use the MPQUIC (multipath quick UDP internet connections, multipath QUIC) function, the SMF and PGW-C (640) may instruct the UPF (650) to use null encryption to prevent double encryption in the MPQUIC layer and the IPsec layer. Null encryption may mean an encryption method that transmits the corresponding data as is without performing encryption.

[0141] In one embodiment, instead of the SMF and PGW-C (640) or the SMF directly providing information indicating the use of null encryption, the PSA UPF (650) recognizing that the MPQUIC steering function should be used may determine the use of null encryption. For example, the PSA UPF (650) may determine the use of null encryption if it detects that the MPQUIC function has been enabled by the SMF and PGW-C (640).

[0142] In step 4, the SMF and PGW-C (640) transmit a PDU Session Establishment Acceptance message to the UE (610). The PDU Session Establishment Acceptance message may include ePDG address information obtained from the PSA UPF / ePDG (650).

[0143] In step 5, the SMF and PGW-C (640) register an MA PDU session with the HSS / UDM (670). For example, the SMF and PGW-C (640) can register an MA PDU session of the UE (610) by providing the context of the UE to the HSS / UDM (670).

[0144] In step 6, the UE (610) connects to the ePDG (652) based on the ePDG address information received from the SMF and PGW-C (640) through step 4 and triggers an initial attach procedure. During the initial attach procedure, the UE provides the ePDG (652) with at least one of information required for the MA PDU session through internet key exchange (IKE) signaling, or a PDU session ID and IP address of an MA PDU session established through 3GPP access, as described in section 4.22.2.4.2 of TS 23.502. For example, the information required for the MA PDU session may include at least one of information indicating that a PDN connection is requested to be associated with the MA PDU session, or information related to the ATSSS capability of the UE. Information related to the ATSSS capability of the UE may include at least one of information indicating whether the UE can support a combination of the ATSSS-LL function, the MPTCP function, and the MPQUIC function, or information indicating that the UE supports a simplified ATSSS architecture. The UE (610) and the ePDG (652) may establish a secure connection by negotiating an encryption algorithm using IKE signaling.

[0145] In one embodiment, when negotiating an encryption algorithm between the UE (610) and the ePDG (652), the ePDG (652) may instruct the UE (610) to use null encryption via IKE signaling. Accordingly, the UE (610) may select null encryption.

[0146] In one embodiment, when the use of null encryption for an IPsec tunnel is indicated by the SMF and PGW-C (640), the ePDG (652) may select the null encryption algorithm during encryption algorithm negotiation between the UE (610) and the ePDG (652).

[0147] In step 7, if authentication is successful, the ePDG (652) sends a session creation request message to the SMF and PGW-C (640), and the SMF and PGW-C (640) send a session creation response message to the ePDG (652). Accordingly, an internal tunnel (e.g., a GTP tunnel) may be created between the ePDG (652) and the PSA UPF (650). The manner in which the internal tunnel is created is not within the scope of this disclosure and may vary depending on the implementation.

[0148] In step 8, the PSA UPF / ePDG (650) may transmit an IKEv2 signal to the UE (610) to notify that an access path (leg) has been successfully added to the existing MA PDU session.

[0149] In the embodiments described with reference to FIGS. 5A and 6, the UE (510, 610) may include the capability of a simplified ATSSS architecture over non-3GPP access during the PDU session establishment request procedure. In addition, the UE (510, 610) connects to an ePDG (522) and triggers an initial connection procedure based on the ePDG information received during the multi-access PDU session establishment.

[0150] Additionally, the SMF and PGW-C (540, 640) request the PSA UPF (550) to allocate an ePDG address based on the UE capability, and provide the ePDG address information to the UE (510, 610) using the PDU Session Establishment Accept message. The SMF and PGW-C (540, 640) instruct the use of null encryption for the IPsec tunnel based on the MPQUIC steering function.

[0151] The PSA UPF (550, 650) allocates ePDG addresses to be used for the simplified ATSSS architecture via non-3GPP access (580, 680) based on requests from the SMF and PGW-C (540, 640).

[0152]

[0153] Figures 7a and 7b illustrate examples of a multi-access PDU session establishment procedure according to an embodiment of the present disclosure. In Figures 7a and 7b, the ePDG is co-located with the PSA UPF. Figures 7a and 7b illustrate examples of a MA PDU session establishment procedure when using an AUSF server for authentication, as in Option 2.

[0154] First, referring to FIG. 7A, the following operations are performed when the UE (710) is registered through 3GPP access. Specifically, in step 1, the UE (710) transmits a PDU session establishment request message to the AMF (730) requesting establishment of an MA PDU session based on the current specification. The UE (710) indicates that it supports a simplified ATSSS architecture through non-3GPP access. For example, the PDU session establishment request message may include indication information indicating that the UE (710) supports a simplified ATSSS architecture through non-3GPP access.

[0155] In step 2, AMF (730) transmits a session management context creation request message of UE (710) to SMF (740). For example, the session management context creation request message may include a CreateSMContext Request message.

[0156] In step 3, SMF (740) retrieves SM (session management) subscription data of UE (710) from UDM (770).

[0157] In step 4, if dynamic PCC (policy and charging control) is used in the MA PDU session, the SMF (740) sends the MA PDU request indication and ATSSS capabilities in the SM policy control generated message PDU session to the PCF (760). The PCF (760) provides PCC rules including MA PDU session control information as specified in TS 23.503.

[0158] In step 5, SMF (740) selects UPF (750) and initiates N4 session establishment procedure with the selected UPF (750).

[0159] In step 6, the SMF (740) transmits an N4 Session Establishment Request message to the UPF (750), separately from the existing operation, requesting activation of the function of the ePDG (752) within the UPF (750). For example, as defined in TS 23.502, the SMF (740) requests the UPF (750) to activate the MPTCP (multipath TCP) function and / or the MPQUIC function. Based on the request of the SMF (740), the UPF (750) assigns an ePDG address for the MA PDU session. If the SMF (740) decides to utilize the MPQUIC function, the SMF (740) may instruct the UPF (750) to utilize null encryption to prevent double encryption at the MPQUIC layer and the IPsec layer.

[0160] In step 7, the UPF (750) transmits an N4 Session Establishment Accept message including the ePDG address to be used by the UE (710) to the SMF (740). That is, the UPF (750) transmits the N4 Session Establishment Accept message including the ePDG address as a response message to the M4 Session Establishment Request message. According to one embodiment, the ePDG address may include the ePDG IP address.

[0161] In step 8, the SMF (740) transmits a message including a PDU Session Establishment Accept message to the AMF (730). The PDU Session Establishment Accept message includes the ATSSS rules for the MA PDU session. In addition, when the ATSSS-LL function and / or the MPTCP function and / or the MPQUIC function are applied, the PDU Session Establishment Accept message may include UE measurement support information and / or MPTCP link-specific multipath and / or MPQUIC link-specific multipath addresses / prefixes. In addition, the PDU Session Establishment Accept message may further include the ePDG address received from the UPF (750) in step 7.

[0162] In steps 9 and 10, the AMF (730) transmits a PDU session establishment acceptance message to the UE (710) via the RAN (720). The UE (710) receives ePDG address information from the SMF (740). In other words, the PDU session establishment acceptance message may include ePDG address information to be used by the UE (710).

[0163] Through steps 1 to 10 as described above, the UE (710) can establish an MA PDU session with one leg, i.e., one user plane path, via 3GPP access.

[0164] Referring to FIG. 7b, after the UE (710) establishes an MA PDU session with one connection path through 3GPP access, the following IPSec (IP security) establishment procedure is performed through non-3GPP access.

[0165] Specifically, in step 1, a data link layer L2 is connected between the UE (710) and the N3G WLAN (780). The UE (710) obtains the IP address of the UE (710) from the WLAN access for IPsec tunnel establishment using the ePDG (752) in the UPF (750). The ePDG (752) in the UPF (750) can be obtained from a PDU session establishment accept message received through the 3GPP access.

[0166] In step 2, the UE (710) initiates an IPSec tunnel setup procedure for the ePDG (752) within the UPF (750) and exchanges the first pair of IKE_SA_INIT messages. The IKE_SA_INIT message may be an initialization message for establishing a security association (SA) in the IKE (Internet Key Exchange) protocol.

[0167] In step 3, the UE (710) transmits an IKE authentication request (IKE_AUTH_request) message including the UE network access identifier (NAI) and the UE IP address to the ePDG (752) of the UPF (750). The UE IP address can be obtained from the PDU session setup accept message received via 3GPP access.

[0168] In step 4, the UPF (750) determines a relevant N4 session based on the UE IP address and sends the UE NAI to the SMF (740) through the determined relevant N4 session. If the UPF (750) cannot find an N4 session based on the UE IP address, the UPF (750) may reject the IKE authentication request of the UE.

[0169] In step 5, SMF (740) triggers an authentication procedure based on the received UE NAI. SMF (740) constructs an EAP Response / Identity message including the UE NAI and sends a Nausf_SMauthentication_Authenticate request message including the constructed EAP Response / Identity message to AUSF (780).

[0170] In step 6, AUSF (780) selects UDM (770) and obtains authentication data for UE (710) from the selected UDM (750) as described in section 6.3.8 of TS 23.501.

[0171] In step 7, the AUSF (780) generates an EAP-Request / AKA'-Challenge message based on the authentication data for the UE, and sends a Nausf_SMAuthentication_Authenticate response message including the EAP-Request / AKA'-Challenge message to the SMF (740). In step 8, the SMF (740) transparently sends the EAP-Request / AKA'-Challenge message to the ePDG (752) of the UPF (750) through the relevant PFCF session. In step 9, the ePDG (752) of the UPF (750) sends an IKE_AUTH Answer message including the EAP-Request / AKA'-Challenge message to the UE (710). Here, the IKEv2 messages exchanged between the ePDG (752) of the UPF (750) and the UE may be configured identically to the IKEv2 messages exchanged between the UE and the ePDG as defined in TS 33.402 Section 8.2.2. If the SMF (740) instructs to use null encryption for the IPsec tunnel, the ePDG (752) in the UPF (750) selects the null encryption algorithm. In addition, the UE (710) includes information required for the MA PDU session as described in TS 23.502 Section 4.22.2.4.2. For example, the information required for the MA PDU session may include at least one of information indicating that a PDN connection has been requested to be associated with the MA PDU session, or information related to the ATSSS capability of the UE. Information related to the ATSSS capability of the UE may include at least one of information indicating whether the UE can support a combination of the ATSSS-LL function, the MPTCP function, and the MPQUIC function, or information indicating that the UE supports a simplified ATSSS architecture.

[0172] In one embodiment, if the UPF (750) recognizes that the MPQUIC steering functionality should be utilized instead of the SMF (740) or the SMF and PGW-C directly providing information indicating the utilization of null encryption, the UPF (750) may determine the utilization of null encryption based on this. For example, if the SMF (740) has enabled the MPQUIC steering functionality, the UPF (750) may determine the utilization of null encryption upon detecting that the MPQUIC functionality has been enabled by the SMF (740).

[0173] In step 10, the AUSF (780) and the UE (710) can exchange EAP-Request / Response messages through the SMF (740) and the UPF (750). The SMF (740) and the UPF (750) transparently forward the messages.

[0174] In step 11, if the UE (710) is successfully authenticated, the AUSF (780) transmits an authentication success message and an authentication response message including a security key to the SMF (740). The authentication success message may be an EAP-Success message, and the authentication response message may be a Nausf_SMAuthentication_Authenticate Response message.

[0175] In step 12, SMF (740) transmits an authentication success message and a security key to ePDG (752) of UPF (750) through N4 session.

[0176] In step 13, UPF (750) transmits an authentication success message to UE (710) and completes the IPSec tunnel establishment procedure based on the security key received from SMF (740). The authentication success message may be transmitted via an IKE_AUTH_Answer message.

[0177] In step 14, the UE (710) responds to the UPF (750) with an IKE_AUTH_Req / Answer message.

[0178] The UE can establish a MA PDU session with two legs on 3GPP and non-3GPP access through the procedure described above, and perform traffic steering, switching, and splitting based on ATSSS rules following the current mechanism. In addition, the UE can transmit uplink data encapsulated in an IPsec tunnel by setting the UE's MPTCP link-specific multipath addresses / prefixes and the UE's MPQUIC link-specific multipath addresses / prefixes as internal source IP addresses based on the steering function to be applied.

[0179] In the embodiment described with reference to FIG. 7, UPF (750) supports ATSSS-Lite functionality, i.e., simplified ATSSS functionality. For example, UPF (750) may support ePDG address allocation for the ATSSS-Lite functionality, establishment of an IPSec tunnel with the UE, and UE NAI and EAP message transfer to the SMF via an N4 session.

[0180] Additionally, SMF (740) supports a new interface with AUSF (780) to exchange new Nausf_SMAuthentication_Authenticate request / response messages. Additionally, the N4 interface supported by SMF (740) may be enhanced to transport UE NAI, EAP messages, and security keys.

[0181] AUSF (780) supports a new interface with SMF (740) to exchange new Nausf_SMAuthentication_Authenticate request / response messages.

[0182] UE (710) includes the functionality of a simplified ATSSS architecture via non-3GPP access during the PDU session establishment request procedure. Based on the ePDG information received during MA PDU session establishment, it connects to the ePDG and triggers the initial connection procedure.

[0183]

[0184] As mentioned above, the present disclosure assumes that the ePDG is co-located with the UPF. However, instead of the ePDG, only some of the functions of the ePDG may be co-located with the UPF, or a new NF that performs functions similar to the ePDG may be introduced. If a new NF is introduced, the interface with the new NF and other network nodes (e.g., SMF, AAA server, etc.) may be newly defined. In addition, the existing N4 interface may be extended to perform procedures similar to the create session request and create session response of S2b through the N4 procedure without using the S2b interface.

[0185] As described above, according to an embodiment of the present disclosure, a UE may transmit a PDU Session Establishment Request message to an SMF, which includes information indicating that the UE supports a simplified ATSSS architecture via non-3GPP, and the SMF may request ePDG address information to be used by the UE from the UPF based on the PDU Session Establishment Request message. Accordingly, the UPF may transmit ePDG address information to be used by the UE to the SMF, and the SMF may transmit a PDU Session Establishment Accept message to the UE, which includes the ePDG address information received from the UPF. The UE may perform an initial attachment procedure based on the ePDG address information included in the PDU Session Establishment Accept message.

[0186] The present disclosure can support ATSSS without the support of network nodes such as existing N3IWF and / or TNGF by operating as described above, and can solve the problem of duplicated encryption that occurs when encryption is performed at a higher layer (e.g., MP-QUIC) by not performing encryption.

[0187]

[0188] FIG. 8 illustrates an example of a procedure for establishing an MA PDU session according to an embodiment of the present disclosure. FIG. 8 illustrates a method performed by a terminal.

[0189] Referring to FIG. 8, in step S801, the terminal transmits a first message related to PDU session establishment. The terminal may transmit a first message requesting MA PDU session establishment in a registered state through a first access. The first access may include a 3GPP access, and the first message may include a PDU session establishment request message. For example, the first message may be delivered to a first network node through a 3GPP access (e.g., NG-RAN). The first network node is a node that performs PDU session management and user traffic flow control functions, and may include, for example, an SMF, or an SMF and a PGW-C. According to one embodiment, the first message may include first information indicating that the terminal supports a simplified ATSSS architecture through a second access. The second access may include a non-3GPP access.

[0190] In step S803, the terminal receives a second message related to PDU session establishment. The terminal may receive a second message from the first network node accepting the MA PDU session establishment. By the terminal receiving the second message accepting the MA PDU session establishment, an MA PDU session having a first access path may be established. The second message may include a PDU session establishment acceptance message. The second message may include information related to the second access. The information related to the second access may include address information of an ePDG to be used for the MA PDU session having a first user plane path through the first access and a second user plane path through the second access. The address information of the ePDG may be assigned by a second network node with which the ePDG is co-located. The second network node may include a node that performs a function for processing data traffic in the user plane. For example, the second network node may include a UPF or a PSA UPF.

[0191] In step S805, the terminal establishes a MA PDU session having a first access path and a second access path. Based on the second message, the terminal can add a second access path to the MA PDU session having the first access path. To add the second access path, the terminal can connect to the corresponding ePDG based on the second message accepting the MA PDU session establishment and trigger an initial connection procedure for the second access. At this time, the terminal can connect to the corresponding ePDG based on the address information of the ePDG included in the second message. According to one embodiment, the terminal and the ePDG can establish a secure connection by negotiating an encryption algorithm using IKE signaling. For example, the terminal can obtain information indicating the use of null encryption from the ePDG and select a null encryption algorithm based on the obtained information. This can prevent double encryption from being performed at the MPQUIC layer and the IPsec layer.

[0192] According to one embodiment, the terminal may further perform at least one operation of the UE (610) of FIG. 6 and the UE (710) of FIGS. 7A and 7B.

[0193]

[0194] FIG. 9 illustrates an example of a procedure for obtaining information related to a second access according to an embodiment of the present disclosure. FIG. 9 illustrates a method performed by a first network node. The first network node may include an SMF, or an SMF and a PGW-C. The first access may include a 3GPP access, and the second access may include a non-3GPP access.

[0195] Referring to FIG. 9, in step S901, a first network node receives a first message related to a PDU session. The first network node may receive a first message requesting MA PDU session establishment from a terminal registered in the first access network. The first message may include a PDU session establishment request message. According to one embodiment, the first message may include first information indicating that the terminal supports a simplified ATSSS architecture via the second access.

[0196] In step S903, the first network node obtains information related to the second access. Based on the first information, the first network node may request information related to the second access for the MA PDU session from the second network node. The second network node may include a UPF or a PSA UPF. In response to the request, the first network node may obtain information related to the second access for the MA PDU session from the second network node. The information related to the second access for the MA PDU session may include address information of an ePDG to be used for the MA PDU session. According to one embodiment, the first network node may instruct the second network node to use null encryption.

[0197] In step S905, the first network node transmits a second message related to PDU session establishment. The first network node may transmit a second message including information related to the second access to the terminal. The second message is a message accepting MA PDU session establishment and may include a PDU session establishment acceptance message. The information related to the second access may include address information of an ePDG to be used for an MA PDU session having a first user plane path through the first access and a second user plane path through the second access.

[0198] According to one embodiment, the first network node may further perform at least one operation of the SMF and PGW-C (640) of FIG. 6 and the SMF and PGW-C (740) of FIGS. 7a and 7b.

[0199]

[0200] FIG. 10 illustrates an example of a procedure for transmitting information related to a second access according to an embodiment of the present disclosure. FIG. 10 illustrates a method performed by a second network node. The second network node may include a UPF with an ePDG co-located therein. The first access may include a 3GPP access, and the second access may include a non-3GPP access.

[0201] Referring to FIG. 10, in step S1001, the second network node receives a message requesting information related to the second access. The second network node may receive a message requesting information related to the second access for the MA PDU session of the terminal from the first network node.

[0202] In step S1003, the second network node transmits information related to the second access. The second network node determines an ePDG to be used for the MA PDU session of the terminal and may transmit address information of the determined ePDG to the first network as information related to the second access.

[0203] In one embodiment, the second network node may detect or determine that null encryption should be used. The use of null encryption may be detected or determined by a directive from the first network node, or based on the first network node activating the MPQUIC steering function. When negotiating an encryption algorithm with the terminal, the second network node may select a null encryption algorithm and instruct the terminal to use null encryption.

[0204] According to one embodiment, the second network node may further perform at least one operation of the PSA UPF (650) of FIG. 6 and the PSA UPF (750) of FIGS. 7A and 7B.

[0205]

[0206] It is clear that the examples of the proposed methods described above can also be considered as a type of proposed methods, as they can be included as one of the implementation methods of the present disclosure. Furthermore, the proposed methods described above can be implemented independently, but they can also be implemented in the form of a combination (or merge) of some of the proposed methods. Information regarding the applicability of the proposed methods (or information regarding the rules of the proposed methods) can be defined by a rule such that the base station notifies the terminal of the application of the proposed methods through a predefined signal (e.g., a physical layer signal or a higher layer signal).

[0207] The present disclosure may be embodied in other specific forms without departing from the technical ideas and essential features described herein. Therefore, the above detailed description should not be construed as limiting in all respects but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the present disclosure are intended to be included within the scope of the present disclosure. Furthermore, claims that do not explicitly cite each other in the claims may be combined to form embodiments or incorporated into new claims through post-filing amendments.

[0208] Embodiments of the present disclosure can be applied to various wireless access systems. Examples of various wireless access systems include the 3rd Generation Partnership Project (3GPP) or 3GPP2 systems.

[0209] The embodiments of the present disclosure can be applied not only to the various wireless access systems described above, but also to all technical fields that utilize these various wireless access systems. Furthermore, the proposed method can also be applied to mmWave and THz communication systems utilizing ultra-high frequency bands.

[0210] Additionally, embodiments of the present disclosure can be applied to various applications such as autonomous vehicles and drones.

Claims

1. In the method, A step in which a terminal transmits a first message related to establishing a PDU (protocol data unit) session through a first access; A step in which the terminal receives a second message related to establishing a PDU session; and A step of establishing a MA (multi-access) PDU session having a first access path (access leg) and a second access path based on the second message, The first message includes a message requesting establishment of the MA PDU session, A method wherein the second message includes information related to the second access.

2. In claim 1, A method wherein the first message includes information indicating that the terminal supports a simplified ATSSS (access traffic steering, switching, splitting) architecture via the second access.

3. In claim 1, Information related to the second access includes address information of an ePDG (evolved packet data gateway) to be used for the MA PDU session, The above ePDG is co-located with a second network node that performs a data traffic processing function of the user plane.

4. In claim 3, The steps for establishing the above MA PDU session are: A method comprising a step of triggering an initial connection procedure based on address information of the above ePDG.

5. In claim 4, Further comprising a step of negotiating an encryption algorithm with the ePDG, A method in which null encryption is selected based on the above encryption algorithm negotiation.

6. In claim 1, The above first access includes 3GPP access, The second access is a method including non-3GPP access.

7. In the method, A step in which a first network node receives a first message related to establishing a PDU (protocol data unit) session from a terminal through a first access; A step in which the first network node obtains information related to the second access; and A step in which the first network node transmits a second message related to establishing a PDU session, The first message includes a message requesting establishment of the MA (multi-access) PDU session, A method wherein the second message includes information related to the second access.

8. In claim 7, The step of obtaining information related to the second access is: A step of requesting information related to the second access from a second network node; A method comprising the step of obtaining address information of an evolved packet data gateway (ePDG) co-located in the second network node from the second network node.

9. In claim 8, A method further comprising the step of instructing the ePDG to use null encryption.

10. In the method, A step in which a second network node requests information related to a second access from a first network node; and A step in which the second network node transmits information related to the second access to the first network node, A method in which information related to the second access includes address information of an evolved packet data gateway (ePDG) co-located in the second network node.

11. In claim 10, A method further comprising a step of instructing a terminal, for which an initial connection procedure is triggered based on the above ePDG, to use null encryption.

12. In the device, Transmitter and receiver; and A processor connected to the above transceiver, the processor comprising: Transmitting the first message related to establishing a PDU (protocol data unit) session through the first access, Receive a second message related to PDU session establishment, Control to establish a MA (multi-access) PDU session having a first access path and a second access path based on the second message, The first message includes a message requesting establishment of the MA PDU session, The second message is a device including information related to the second access.

13. In the device, Transmitter and receiver; and A processor connected to the above transceiver, the processor comprising: Receive a first message related to establishing a PDU (protocol data unit) session from the terminal through the first access, Obtain information related to the second access, Controls the transmission of a second message related to the establishment of a PDU session, The first message includes a message requesting establishment of the MA (multi-access) PDU session, The second message is a device including information related to the second access.

14. In the device, Transmitter and receiver; and A processor connected to the above transceiver, the processor comprising: Requesting information related to the second access from the first network node, Control to transmit information related to the second access to the first network node, A device including information related to the second access, the address information of an evolved packet data gateway (ePDG) co-located in the second network node.

15. In communication devices, At least one processor; At least one memory storing instructions that direct operations when executed by at least one processor, The above actions are, A step in which a terminal transmits a first message related to establishing a PDU (protocol data unit) session through a first access; A step in which the terminal receives a second message related to establishing a PDU session; and A step of establishing a MA (multi-access) PDU session having a first access path and a second access path based on the second message, The first message includes a message requesting establishment of the MA PDU session, The second message is a communication device including information related to the second access.

16. In a non-transitory computer-readable medium storing at least one instruction, At least one instruction executable by the processor, Transmitting the first message related to establishing a PDU (protocol data unit) session through the first access, Receive a second message related to PDU session establishment, Control to establish a MA (multi-access) PDU session having a first access path and a second access path based on the second message, The first message includes a message requesting establishment of the MA PDU session, The second message is a computer-readable medium containing information related to the second access.

Citation Information

Patent Citations

  • Umbrella type air conditioner

    KR102865780B1

  • UE and smf

    US20220361272A1

  • Method and apparatus for registration data retrieval

    US20230075951A1

  • Method for adding 3GPP PDN leg to an ma PDU session with non-3GPP leg

    US20230217508A1