Secure store and forward non-terrestrial network communication

By generating security keys within the network and at user equipment for satellite communication, secure transmission of small data packets is achieved in non-terrestrial networks, addressing the intermittently unavailable feeder link challenge.

WO2025181699A1PCT designated stage Publication Date: 2025-09-04LENOVO (SINGAPORE) PTE LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/052071
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-27
Filing Date
2025-02-26
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

The intermittently unavailable feeder link in non-terrestrial network communication systems poses challenges for secure communication between user equipment and application servers, particularly in scenarios where small data packets need to be transmitted securely.

Method used

A security key is generated within the network and at the user equipment, using 3GPP credentials, to protect store and forward communication via satellite links, employing key derivation from AMF and/or SEAF with direct provisioning to application servers, or through AKMA variations with KAF push or pull mechanisms.

Benefits of technology

Ensures secure and reliable transmission of small data packets over satellite links by protecting the communication with derived security keys, maintaining communication integrity and security in non-terrestrial network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025052071_04092025_PF_FP_ABST
    Figure IB2025052071_04092025_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to secure store and forward (SF) non-terrestrial network (NTN) communication. An apparatus, such as a UE, performs registration including an authentication procedure using a store and forward (SF) access network. The UE derives a security key based on a key generated from the authentication procedure. The UE transmits, to an application server (AS) via the SF access network, an application SF request message that includes a user plane (UP) protocol data unit (PDU) with SF data protected with the security key. The UE receives, from the AS via the SF access network, a response message as an acknowledgement.
Need to check novelty before this filing date? Find Prior Art

Description

SECURE STORE AND FORWARD NON-TERRESTRIAL NETWORK COMMUNICATIONRELATED APPLICATION

[0001] This application claims priority to U.S. Provisional Application Serial No. 63 / 558,426 filed February 27, 2024 entitled “Secure Store and Forward Non-Terrestrial Network Communication,” the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD

[0002] The present disclosure relates to wireless communications, and more specifically to non-terrestrial network (NTN) communication.BACKGROUND

[0003] A wireless communications system may include one or multiple network communication devices, which may be otherwise known as network equipment (NE), supporting wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like)) or frequency resources (e.g., subcarriers, carriers, or the like). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).

[0004] The wireless communications system may support wireless device communications, and may include one or more wireless devices, such as UEs, satellites, and / or network equipment (NE), among other devices, that transmit and / or receive signaling. The wireless communications may include a scenario for UE to satellite communication, with store and forward (SF) communication to the 5G core network (5GC) and to an application server and / or application function.SUMMARY

[0005] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on.” Further, as used herein, including in the claims, a “set” may include one or more elements.

[0006] A UE for wireless communication is described. The UE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the UE may be configured to, capable of, or operable to perform registration including an authentication procedure using a store and forward (SF) access network; derive a security key based on a key generated from the authentication procedure; transmit, to an application server (AS) via the SF access network, an application SF request message that includes a user plane (UP) protocol data unit (PDU) with SF data protected with the security key; and receive, from the AS via the SF access network, a response message as an acknowledgement.

[0007] A processor (e.g., a standalone processor chipset, or a component of a UE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to perform registration including an authentication procedure using a SF access network; derive a security key based on a key generated from the authentication procedure; transmit, to an AS via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; and receive, from the AS via the SF access network, a response message as an acknowledgement.

[0008] A method performed or performable by a UE for wireless communication is described. The method may include performing registration including an authentication procedure using a SF access network; deriving a security key based on a key generated from the authentication procedure; transmitting, to an AS via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; and receiving, from the AS via the SF access network, a response message as an acknowledgement.

[0009] In some implementations of the UE, the processor, and the method described herein, the registration that includes the authentication procedure is performed with a NE via the SF access network. In some implementations of the UE, the processor, and the method described herein, the SF access network includes one or more satellites. In some implementations of the UE, the processor, and the method described herein, a security context of the key comprises at least one of a security anchor function (SEAF) or an access and mobility management function (AMF). In some implementations of the UE, the processor, and the method described herein, a security context of the key comprises at least one of an authentication server function (AUSF) or authentication and key management for applications (AKMA). In some implementations of the UE, the processor, and the method described herein, the application SF request message includes an AS identifier (ID) and a generic public subscription identifier (GPSI).

[0010] An application server (AS) for wireless communication is described. The AS may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the AS may be configured to, capable of, or operable to receive, from a NE, a SF service security context push request message that includes a security key, a key expiration time, and a UE identifier; transmit, to the NE, a response message as an acknowledgement; receive, from the UE via a SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; select the security key based on the UE identifier; and unprotect the UP PDU with the SF data using the security key.

[0011] A processor (e.g., a standalone processor chipset, or a component of an AS) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to receive, from a NE, a SF service security context push request message that includes a security key, a key expiration time, and a UE identifier; transmit, to the NE,a response message as an acknowledgement; receive, from the UE via a SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; select the security key based on the UE identifier; and unprotect the UP PDU with the SF data using the security key.

[0012] A method performed or performable by an AS for wireless communication is described. The method may include receiving, from a NE, a SF service security context push request message that includes a security key, a key expiration time, and a UE identifier; transmitting, to the NE, a response message as an acknowledgement; receiving, from the UE via a SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; selecting the security key based on the UE identifier; and unprotecting the UP PDU with the SF data using the security key.

[0013] In some implementations of the AS, the processor, and the method described herein, the AS, the processor, and the method may be configured to, capable of, or operable to derive the security key in a security context that comprises at least one of a SEAF or an AMF. In some implementations of the AS, the processor, and the method described herein, the application SF request message includes an AS ID and a GPSI. In some implementations of the AS, the processor, and the method described herein, the security key is selected based on the GPSI of the UE. In some implementations of the AS, the processor, and the method described herein, the AS, the processor, and the method may be configured to, capable of, or operable to transmit, to the UE via the SF access network, an acknowledgement response message.BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.

[0015] Figure 2 illustrates an example of SF satellite operation mode, in accordance with aspects of the present disclosure.

[0016] Figure 3 illustrates an example of a signaling diagram for key derivation from a key in the AMF and / or SEAF, with direct provisioning to an AS, in accordance with aspects of the present disclosure.

[0017] Figure 4 illustrates an example of a signaling diagram for AKMA variation with KAF push to an AS, with protected packet transmission via a SF link, in accordance with aspects of the present disclosure.

[0018] Figure 5 illustrates an example of a signaling diagram 500 for AKMA variation with KAF pull to an AS, with protected packet transmission via a SF link, in accordance with aspects of the present disclosure.

[0019] Figure 6 illustrates an example of a UE in accordance with aspects of the present disclosure.

[0020] Figure 7 illustrates an example of a processor in accordance with aspects of the present disclosure.

[0021] Figure 8 illustrates an example of a network equipment (NE) in accordance with aspects of the present disclosure.

[0022] Figure 9 illustrates an example of an AS in accordance with aspects of the present disclosure.

[0023] Figure 10 illustrates a flowchart of a method performed by a UE in accordance with aspects of the present disclosure.

[0024] Figure 11 illustrates a flowchart of a method performed by an AS in accordance with aspects of the present disclosure.DETAILED DESCRIPTION

[0025] A wireless communications system may support wireless communications for one or more wireless devices, such as UEs, satellites, and / or NEs, among other devices, that transmit and / or receive signaling. A wireless communication scenario may include UE to satellite communication, with store and forward (SF) communication to the 5G core network (5GC) and to an application server (AS) and / or application function (AF). The availability and stability of the communication link between the UE and the 5GC may raise the issue of the feeder link being intermittently unavailable. Another issue may include assuming that the registration procedure may not be executed. However, this is likely a non-issue given that the procedure itself is not timeintensive, and the respective UE can usually be registered in the system. For example, the UE may determine partially availability and use the SF mechanism to send small data.

[0026] In aspects of this present disclosure, one or more techniques are provided for the UE to communicate a protected message to the application server in the 5GC via the SF link between one or more satellites, after a successful registration. Aspects of the disclosure are directed to securing wireless communications for the SF service with respect to security of a communication, such as security for SF satellite operation. Small data transmission for machine type communication (MTC), or Internet of things (loT) devices is standardized for the evolved packet system (EPS), where a UE can transmit a small data packet inside the protected non-access stratum (NAS) signaling message. This type of small data packet has a very small data size and is restricted by the NAS message size. However, a satellite may be able to store larger packets and directly transmit a larger packet as an Internet protocol (IP) packet to an application server.

[0027] Aspects of the present disclosure include a solution to generate a security key in the network and at a UE, and the security key may then be used to protect a SF IP packet that is directed to the application server. In one or more various implementations, the procedures for AKMA based on 3GPP credentials in the 5G system (5GS) may be utilized (i.e., the key generation is based on KAUSF and pulled or pushed to the AS or to an AF). As described herein, the terms application server and application function may be used interchangeably. The one or more implementations include key derivation from a key in the AMF and / or SEAF, with direct provisioning to an AS. The one or more implementations also include AKMA variation with KAF push to an AS, with protected packet transmission via a SF link. The one or more implementations also include AKMA variation with KAF pull to an AS, with protected packet transmission via a SF link.

[0028] Aspects of the present disclosure are described in the context of a wireless communications system. Reference is made herein to communicating data or information, such as signaling communication resources and / or communications that are transmitted or received between devices. It is to be appreciated that other terms may be used interchangeably with communicating, such as signaling, transmitting, receiving, outputting, forwarding, retrieving, obtaining, and so forth.

[0029] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.

[0030] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, network infrastructure (or infrastructure), a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.

[0031] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.

[0032] The one or more UEs 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of- Everything (loE) device, or machine-type communication (MTC) device, among other examples.

[0033] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0034] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N6, or other network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other indirectly (e.g., via the CN 106). In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).

[0035] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an AMF) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility,authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.

[0036] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N6, or other network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).

[0037] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0038] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifthnumerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.

[0039] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0040] Additionally, or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, jU=l , / r=2, / r=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0041] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one ormore of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0042] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.

[0043] According to implementations, one or more of the NEs 102 and the UEs 104 are operable to implement various aspects of the techniques described with reference to the present disclosure. For example, a UE 104 performs a registration procedure, which includes an authentication procedure, using a SF access network, such as communications via one or more satellites. In implementations, the registration that includes the authentication procedure is performed with a NE 102 via the SF access network. In one or more implementations, the UE 104 can derive a security key based on a key that is generated from the authentication procedure. For example, a security context of the key may include a SEAF, an AMF, an AUSF, or AKMA. The UE 104 can transmit, to an application server via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key. The application SF request message may also include an AS ID and a GPSI. The UE 104 may then receive, from the AS via the SF access network, a response message as an acknowledgement.

[0044] According to implementations, an application server (or application function) may receive, from a NE 102, a SF service security context push request message that includes a security key, a key expiration time, and a UE identifier of a UE 104. The AS transmits, to the NE 102, a response message as an acknowledgement. In one or more implementations, the AS can then receive, from the UE 104 via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key. The AS can then select thesecurity key based on the UE identifier, and unprotect the UP PDU with the SF data using the security key.

[0045] Figure 2 illustrates an example of SF satellite operation mode 200, in accordance with aspects of the present disclosure. In one or more implementations, the SF satellite operation in a wireless communications system with satellite access provides a communication service for UEs under satellite coverage with intermittent or temporary satellite connectivity (e.g. when the satellite is not connected via a feeder link or via inter satellite links (ISE) to the ground network) for a delay- tolerant communication service. In this example of SF satellite operation mode 200, the end-to-end exchange of signaling and / or data traffic can be handled as a combination of two steps, indicated as step A and step B, not concurrent in time.

[0046] For example, at step A 202, a signaling and / or data exchange between UE 104 and a satellite 204 takes place, without the satellite being simultaneously connected to the ground network (i.e. the satellite 204 operates the service link without an active feeder link connection). At step B 206, connectivity between a satellite 208 and the ground network 210 is established so that communication between the satellite and the ground network can take place. So, the satellite moves from being connected to the UE 104 in step A to being connected to the ground network 210 in step B. The concept of SF (also referred to as S&F) service is used in communicate scenarios for delay-tolerant networking and disruption-tolerant networking. In a 3 GPP context, a similar service is short message service (SMS), for which there is no need to have an end-to-end connectivity between the end-points (e.g. an end-point can be a UE and the other an application server) but only between the end-points a message service center that operates as an intermediate node for storing and relaying data.

[0047] Aspects of the present disclosure include an implementation for key derivation from a key in the AMF and / or SEAF, with direct provisioning to an AS. In this implementation, the SF key KSF is derived from the KSEAF or the KAMF. The UE performs the same operation independently from the AMF after the registration procedure. When the UE transmits the SF data, it protects the SF data with the key KSF and sends it via the SF satellite link(s). The receiving AS of the IP packet has already been pushed the KSF from the AMF (via network exposure function (NEF) or SMF) after its generation, and can unprotect the SF data packet again. For the KSF derivation, the AS identity may be used as additional input.

[0048] Figure 3 illustrates an example of a signaling diagram 300 for key derivation from a key in the AMF and / or SEAF, with direct provisioning to an AS, in accordance with aspects of the present disclosure. This example signaling diagram 300 includes a UE 104, a first satellite 302 (e.g., satellite A), a second satellite 304 (e.g., satellite B), an AMF 306, and an application server (AS 308). The example signaling diagram 300 also includes several communication links, such as a service link 310 between the UE 104 and the first satellite 302; a SF link 312 between the first satellite 302 and the second satellite 304; a feeder link control plane 314 between the second satellite 304 and the AMF 306; and a feeder link user plane 316 between the second satellite 304 and the AS 308.

[0049] In one or more implementations, the UE 104 (at step 1) performs a registration procedure and establishes the security context. It is assumed that no interruption has occurred during this registration procedure. The AMF 306 (at step 2) retrieves the subscription profile with the subscribed SF service, as well as the AS ID and AS address. The UE 104 and the AMF 306 (both at step 3) derive the SF key KSF either from the KSEAF or the KAMF. For the KSF derivation, the AS identity may be used as additional input. The UE 104 is preconfigured with the AS ID and the AS Address. The AMF 306 (at step 4) sends a SF service security context push request to the AS 308, including the KSF, a KSF expiration time, and the GPSI or subscription permanent identifier (SUPI) of the UE. The AS 308 (at step 5) acknowledges the storage of the SF service security context with a response message.

[0050] The UE 104 can then send data to the AS 308, and the UE (at step 6) creates an application SF request message with the AS ID, GPSI, and the protected UP PDU with the SF data. The UP PDU with the SF data is protected with the key KSF (i.e., the KSF is used as input for the encryption and / or integrity protection algorithm). The UE transmits the application SF request message to the SF satellite link. The application SF request message (at step 7) is forwarded and stored at the next SF satellite link, if needed. There may be several satellite links with SF in the transmission chain. The SF satellite (at step 8) forwards the application SF request message to the ground network where it is delivered to the AS. The AS 308 selects (at step 9) the KSF based on the GPSI in the request message and unprotects the UP PDU. The AS 308 acknowledges (at step 10) the receipt of the request message, the acknowledgement is forwarded between the SF satellite links (at step 11), and (at step 12) the SF satellite serving the UE sends the acknowledgement to the UE.

[0051] Aspects of the present disclosure include an implementation for AKMA variation with KAF push to an AS, with protected packet transmission via a SF link. In this embodiment, the SF key is the application function (AF) key KAF according to AKMA specification. The KAF is derived from the KAKMA after the registration and authentication procedure. When the UE transmits the SF data, it protects the SF data with the key KAF and sends it via the SF satellite link(s). The receiving AS (or AF in AKMA) of the IP packet has already been pushed the KAF from the AKMA anchor function (AAnF) (e.g., via NEF) after its generation, and the AS can unprotect the SF data packet.

[0052] Figure 4 illustrates an example of a signaling diagram 400 for AKMA variation with KAF push to an AS, with protected packet transmission via a SF link, in accordance with aspects of the present disclosure. This example signaling diagram 400 includes a UE 104, a first satellite 402 (e.g., satellite A), a second satellite 404 (e.g., satellite B), an AAnF 406, and an application server (AS 408). The example signaling diagram 400 also includes several communication links, such as a service link 410 between the UE 104 and the first satellite 402; a SF link 412 between the first satellite 402 and the second satellite 404; a feeder link control plane 414 between the second satellite 404 and the AAnF 406; and a feeder link user plane 416 between the second satellite 404 and the AS 408.

[0053] In one or more implementations, the UE 104 (at step 1) the UE 104 performs the registration procedure and establishes the security context. It is assumed that no interruption occurred during this registration procedure. The AAnF 406 (at step 2) retrieves from the AUSF the generated AKMA key material, the generated A-KID, and KAKMA together with the SUPI of the UE. The UE also the generates the A-KID and KAKMA. The AUSF also provides the subscribed SF service, the AS ID, and the AS address to the AAnF. The AAnF 406 (at step 3) sends a SF service security context push request to the AS 408, including the KAF, a KAF expiration time, and the GPSI or SUPI of the UE. The AS 408 (at step 4) acknowledges the storage of the AF service security context with a response message.

[0054] The UE 104 (at step 5) sends data to the AS 408 and creates an application SF request message with the AS ID, GPSI, and the protected UP PDU with the SF data. The UP PDU with the SF data is protected with the key KAF (i.e., the KAF is used as input for the encryption and / or integrity protection algorithm). The UE 104 sends the application SF request message to the SF satellite link. The application SF request message (at step 6) is forwarded and stored at the next SFsatellite link, if needed. There may be several satellite links with SF in the transmission chain. The SF satellite (at step 7) forwards the application SF request message to the ground network where it is delivered to the AS. The AS 408 (at step 8) selects the KAF based on the GPSI in the request message and unprotects the UP PDU. The AS 408 (at step 9) acknowledges the receipt of the request message. The acknowledgement is forwarded between the SF satellite links (at step 10), and (at step 11), the SF satellite serving the UE sends the acknowledgement to the UE.

[0055] Aspects of the present disclosure include an implementation for AKMA variation with KAF pull to an AS, with protected packet transmission via a SF link. In this embodiment, the SF key is the application function (AF) key KAF according to the AKMA specification. The KAF is derived from the KAKMA after the AS requests the key according to the AKMA procedure. When the UE transmits the SF data, it protects the SF data with the key KAF and sends it via the SF satellite link(s). The receiving AS (or AF in AKMA) of the IP packet requests the KAF from the AAnF (e.g., via NEF) and can unprotect the SF data packet.

[0056] Figure 5 illustrates an example of a signaling diagram 500 for AKMA variation with KAF pull to an AS, with protected packet transmission via a SF link, in accordance with aspects of the present disclosure. This example signaling diagram includes a UE 104, a first satellite 502 (e.g., satellite A), a second satellite 504 (e.g., satellite B), an AAnF 506, and an application server (AS 508). The example signaling diagram 500 also includes several communication links, such as a service link 510 between the UE 104 and the first satellite 502; a SF link 512 between the first satellite 502 and the second satellite 504; a feeder link control plane 514 between the second satellite 504 and the AAnF 506; and a feeder link user plane 516 between the second satellite 504 and the AS 508.

[0057] In one or more implementations, the UE 104 (at step 1) performs the registration procedure and establishes the security context. It is assumed that no interruption occurred during this registration procedure. The AAnF 506 (at step 2) retrieves from the AUSF the generated AKMA key material, the generated A-KID, and KAKMA together with the SUPI of the UE. The UE 104 also the generates the A-KID and KAKMA. The AUSF also provides the subscribed SF service, the AS ID, and the AS address to the AAnF.

[0058] The UE 104 (at step 3) sends data to the AS 508 and creates an application SF request message with the AS ID, GPSI, and the protected UP PDU with the SF data. The UP PDU with the SF data is protected with the key KAF (i.e., the KAF is used as input for the encryption and / or integrity protection algorithm). The UE 104 sends the application SF request message to the SF satellite link. The application SF request message (at step 4) is forwarded and stored at the next SF satellite link, if needed. There may be several satellite links with SF in the transmission chain. The SF satellite (at step 5) forwards the application SF request message to the ground network where it is delivered to the AS.

[0059] The AS 508 (at step 6) sends a Naanf_AKMA_ApplicationKey_Get request to AAnF with the A-KID to request the KAF for the UE. The AF also includes its identity (AF_ID) in the request. The AAnF 506 (at step 7) derives the AKMA Application Key (KAF) from KAKMA if it does not already have KAF. The AAnF 506 (at step 8) sends Naanf_AKMA_ApplicationKey_Get response to the AF with SUPI or GPSI, the KAF, and the KAF expiration time. The AS 508 (at step 9) selects the received KAF and unprotects the UP PDU. The AS 508 (at step 10) acknowledges the receipt of the request message. The acknowledgement is forwarded between the SF satellite links (at step 11), and (at step 12), the SF satellite serving the UE sends the acknowledgement to the UE.

[0060] Figure 6 illustrates an example of a UE 600 in accordance with aspects of the present disclosure. The UE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608. The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0061] The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0062] The processor 602 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 602 may be configured to operate the memory 604. In some other implementations, the memory 604 may be integrated into the processor 602. The processor 602 may be configured to execute computer-readable instructions stored in the memory 604 to cause the UE 600 to perform various functions of the present disclosure.

[0063] The memory 604 may include volatile or non-volatile memory. The memory 604 may store computer-readable, computer-executable code including instructions when executed by the processor 602 cause the UE 600 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 604 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0064] In some implementations, the processor 602 and the memory 604 coupled with the processor 602 may be configured to cause the UE 600 to perform one or more of the functions described herein (e.g., executing, by the processor 602, instructions stored in the memory 604). For example, the processor 602 may support wireless communication at the UE 600 in accordance with examples as disclosed herein. The UE 600 may be configured to or operable to support a means for performing registration including an authentication procedure using a SF access network; deriving a security key based on a key generated from the authentication procedure; transmitting, to an AS via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; and receiving, from the AS via the SF access network, a response message as an acknowledgement.

[0065] Additionally, the UE 600 may be configured to support any one or combination of the registration that includes the authentication procedure is performed with a NE via the SF access network. The SF access network includes one or more satellites. A security context of the key comprises at least one of a SEAF or an AMF. A security context of the key comprises at least one of an AUSF or AKMA. The application SF request message includes an AS ID and a GPSI.

[0066] Additionally, or alternatively, the UE 600 may support at least one memory (e.g., the memory 604) and at least one processor (e.g., the processor 602) coupled with the at least one memory and configured to cause the UE to perform registration including an authentication procedure using a SF access network; derive a security key based on a key generated from the authentication procedure; transmit, to an AS via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; and receive, from the AS via the SF access network, a response message as an acknowledgement.

[0067] Additionally, the UE 600 may be configured to support any one or combination of the registration that includes the authentication procedure is performed with a NE via the SF access network. The SF access network includes one or more satellites. A security context of the key comprises at least one of a SEAF or an AMF. A security context of the key comprises at least one of an AUSF or AKMA. The application SF request message includes an AS ID and a GPSI.

[0068] The controller 606 may manage input and output signals for the UE 600. The controller 606 may also manage peripherals not integrated into the UE 600. In some implementations, the controller 606 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 606 may be implemented as part of the processor 602.

[0069] In some implementations, the UE 600 may include at least one transceiver 608. In some other implementations, the UE 600 may have more than one transceiver 608. The transceiver 608 may represent a wireless transceiver. The transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.

[0070] A receiver chain 610 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 610 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (ENA)) configured to amplify the received signal. The receiver chain 610 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 610 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0071] A transmitter chain 612 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0072] Figure 7 illustrates an example of a processor 700 in accordance with aspects of the present disclosure. The processor 700 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 700 may include a controller 702 configured to perform various operations in accordance with examples as described herein. The processor 700 may optionally include at least one memory 704, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 700 may optionally include one or more arithmetic-logic units (ALUs) 706. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).

[0073] The processor 700 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 700) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).

[0074] The controller 702 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 700 to cause the processor700 to support various operations in accordance with examples as described herein. For example, the controller 702 may operate as a control unit of the processor 700, generating control signals that manage the operation of various components of the processor 700. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.

[0075] The controller 702 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 704 and determine subsequent instruction(s) to be executed to cause the processor 700 to support various operations in accordance with examples as described herein. The controller 702 may be configured to track memory addresses of instructions associated with the memory 704. The controller 702 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 702 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 702 may be configured to manage flow of data within the processor 700. The controller 702 may be configured to control transfer of data between registers, ALUs 706, and other functional units of the processor 700.

[0076] The memory 704 may include one or more caches (e.g., memory local to or included in the processor 700 or other memory, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 704 may reside within or on a processor chipset (e.g., local to the processor 700). In some other implementations, the memory 704 may reside external to the processor chipset (e.g., remote to the processor 700).

[0077] The memory 704 may store computer-readable, computer-executable code including instructions that, when executed by the processor 700, cause the processor 700 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 702 and / or the processor 700 may be configured to execute computer-readable instructions stored in the memory 704 to cause the processor 700 to perform various functions. For example, the processor 700 and / or the controller 702 may be coupled with or to the memory 704, the processor 700, and the controller 702, and may be configured to perform various functions described herein. In some examples, the processor 700 may include multiple processors and the memory 704 may include multiple memories. One or moreof the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.

[0078] The one or more ALUs 706 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 706 may reside within or on a processor chipset (e.g., the processor 700). In some other implementations, the one or more ALUs 706 may reside external to the processor chipset (e.g., the processor 700). One or more ALUs 706 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 706 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 706 may be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 706 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 706 to handle conditional operations, comparisons, and bitwise operations.

[0079] The processor 700 may support wireless communication in accordance with examples as disclosed herein. The processor 700 may be configured to or operable to support at least one controller (e.g., the controller 702) coupled with at least one memory (e.g., the memory 704) and configured to cause the processor to perform registration including an authentication procedure using a SF access network; derive a security key based on a key generated from the authentication procedure; transmit, to an AS via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; and receive, from the AS via the SF access network, a response message as an acknowledgement.

[0080] Additionally, the processor 700 may be configured to or operable to support any one or combination of the registration that includes the authentication procedure is performed with a NE via the SF access network. The SF access network includes one or more satellites. A security context of the key comprises at least one of a SEAF or an AMF. A security context of the key comprises at least one of an AUSF or AKMA. The application SF request message includes an AS ID and a GPSI.

[0081] Figure 8 illustrates an example of a NE 800 in accordance with aspects of the present disclosure. The NE 800 may include a processor 802, a memory 804, a controller 806, and a transceiver 808. The processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0082] The processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0083] The processor 802 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 802 may be configured to operate the memory 804. In some other implementations, the memory 804 may be integrated into the processor 802. The processor 802 may be configured to execute computer-readable instructions stored in the memory 804 to cause the NE 800 to perform various functions of the present disclosure.

[0084] The memory 804 may include volatile or non-volatile memory. The memory 804 may store computer-readable, computer-executable code including instructions when executed by the processor 802 cause the NE 800 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 804 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0085] In some implementations, the processor 802 and the memory 804 coupled with the processor 802 may be configured to cause the NE 800 to perform one or more of the functionsdescribed herein (e.g., executing, by the processor 802, instructions stored in the memory 804). For example, the processor 802 may support wireless communication at the NE 800 in accordance with examples as disclosed herein.

[0086] The controller 806 may manage input and output signals for the NE 800. The controller 806 may also manage peripherals not integrated into the NE 800. In some implementations, the controller 806 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 806 may be implemented as part of the processor 802.

[0087] In some implementations, the NE 800 may include at least one transceiver 808. In some other implementations, the NE 800 may have more than one transceiver 808. The transceiver 808 may represent a wireless transceiver. The transceiver 808 may include one or more receiver chains 810, one or more transmitter chains 812, or a combination thereof.

[0088] A receiver chain 810 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 810 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 810 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 810 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 810 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0089] A transmitter chain 812 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 812 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 812 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 812 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0090] Figure 9 illustrates an example of a AS 900 in accordance with aspects of the present disclosure. The AS 900 may include a processor 902, a memory 904, a controller 906, and a transceiver 908. The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0091] The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0092] The processor 902 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 902 may be configured to operate the memory 904. In some other implementations, the memory 904 may be integrated into the processor 902. The processor 902 may be configured to execute computer-readable instructions stored in the memory 904 to cause the AS 900 to perform various functions of the present disclosure.

[0093] The memory 904 may include volatile or non-volatile memory. The memory 904 may store computer-readable, computer-executable code including instructions when executed by the processor 902 cause the AS 900 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 904 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0094] In some implementations, the processor 902 and the memory 904 coupled with the processor 902 may be configured to cause the AS 900 to perform one or more of the functionsdescribed herein (e.g., executing, by the processor 902, instructions stored in the memory 904). For example, the processor 902 may support wireless communication at the AS 900 in accordance with examples as disclosed herein. The AS 900 may be configured to or operable to support a means for receiving, from a NE, a SF service security context push request message that includes a security key, a key expiration time, and a UE identifier; transmitting, to the NE, a response message as an acknowledgement; receiving, from the UE via a SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; selecting the security key based on the UE identifier; and unprotecting the UP PDU with the SF data using the security key.

[0095] Additionally, the AS 900 may be configured to or operable to support any one or combination of the method further including deriving the security key in a security context that comprises at least one of a SEAF or an AMF. The application SF request message includes an AS ID and a GPSI. The security key is selected based on the GPSI of the UE. The method further including transmitting, to the UE via the SF access network, an acknowledgement response message.

[0096] Additionally, or alternatively, the AS 900 may support at least one memory (e.g., the memory 904) and at least one processor (e.g., the processor 902) coupled with the at least one memory and configured to cause the AS to receive, from a NE, a SF service security context push request message that includes a security key, a key expiration time, and a UE identifier; transmit, to the NE, a response message as an acknowledgement; receive, from the UE via a SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key; select the security key based on the UE identifier; and unprotect the UP PDU with the SF data using the security key.

[0097] Additionally, the AS 900 may be configured to support any one or combination of the at least one processor is configured to cause the AS to derive the security key in a security context that comprises at least one of a SEAF or an AMF. The application SF request message includes an AS ID and a GPSI. The security key is selected based on the GPSI of the UE. The at least one processor is configured to cause the AS to transmit, to the UE via the SF access network, an acknowledgement response message.

[0098] The controller 906 may manage input and output signals for the AS 900. The controller 906 may also manage peripherals not integrated into the AS 900. In some implementations, the controller 906 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 906 may be implemented as part of the processor 902.

[0099] In some implementations, the AS 900 may include at least one transceiver 908. In some other implementations, the AS 900 may have more than one transceiver 908. The transceiver 908 may represent a wireless transceiver. The transceiver 908 may include one or more receiver chains 910, one or more transmitter chains 912, or a combination thereof.

[0100] A receiver chain 910 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 910 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 910 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 910 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 910 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0101] A transmitter chain 912 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 912 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 912 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 912 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0102] Figure 10 illustrates a flowchart of a method 1000 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elementsof the UE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0103] At 1002, the method may include performing registration including an authentication procedure using a SF access network. The operations of 1002 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1002 may be performed by a UE as described with reference to Figure 6.

[0104] At 1004, the method may include deriving a security key based on a key generated from the authentication procedure. The operations of 1004 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1004 may be performed by a UE as described with reference to Figure 6.

[0105] At 1006, the method may include transmitting, to an AS via the SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key. The operations of 1006 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1006 may be performed a UE as described with reference to Figure 6.

[0106] At 1008, the method may include receiving, from the AS via the SF access network, a response message as an acknowledgement. The operations of 1008 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1008 may be performed a UE as described with reference to Figure 6.

[0107] Figure 11 illustrates a flowchart of a method 1100 in accordance with aspects of the present disclosure. The operations of the method may be implemented by an AS as described herein. In some implementations, the AS may execute a set of instructions to control the function elements of the AS to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0108] At 1102, the method may include receiving, from a NE, a SF service security context push request message that includes a security key, a key expiration time, and a UE identifier. The operations of 1102 may be performed in accordance with examples as described herein. In someimplementations, aspects of the operations of 1102 may be performed by an AS as described with reference to Figure 9.

[0109] At 1104, the method may include transmitting, to the NE, a response message as an acknowledgement. The operations of 1104 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1104 may be performed by an AS as described with reference to Figure 9.

[0110] At 1106, the method may include receiving, from the UE via a SF access network, an application SF request message that includes a UP PDU with SF data protected with the security key. The operations of 1106 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1106 may be performed by an AS as described with reference to Figure 9.

[0111] At 1108, the method may include selecting the security key based on the UE identifier. The operations of 1108 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1108 may be performed by an AS as described with reference to Figure 9.

[0112] At 1110, the method may include unprotecting the UP PDU with the SF data using the security key. The operations of 1110 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1110 may be performed by an AS as described with reference to Figure 9.

[0113] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

CLAIMSWhat is claimed is:

1. A user equipment (UE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the UE to: perform registration including an authentication procedure using a store and forward (SF) access network; derive a security key based at least in part on a key generated from the authentication procedure; transmit, to an application server (AS) via the SF access network, an application SF request message that includes a user plane (UP) protocol data unit (PDU) with SF data protected with the security key; and receive, from the AS via the SF access network, a response message as an acknowledgement.

2. The UE of claim 1 , wherein the registration that includes the authentication procedure is performed with a network equipment (NE) via the SF access network.

3. The UE of claim 1, wherein the SF access network includes one or more satellites.

4. The UE of claim 1 , wherein a security context of the key comprises at least one of a security anchor function (SEAF) or an access and mobility management function (AMF).

5. The UE of claim 1, wherein a security context of the key comprises at least one of an authentication server function (AUSF) or authentication and key management for applications (AKMA).

6. The UE of claim 1, wherein the application SF request message includes an AS identifier (ID) and a generic public subscription identifier (GPSI).

7. A method performed by a user equipment (UE), the method comprising: performing registration including an authentication procedure using a store and forward (SF) access network; deriving a security key based at least in part on a key generated from the authentication procedure; transmitting, to an application server (AS) via the SF access network, an application SF request message that includes a user plane (UP) protocol data unit (PDU) with SF data protected with the security key; and receiving, from the AS via the SF access network, a response message as an acknowledgement.

8. The method of claim 7, wherein the registration that includes the authentication procedure is performed with a network equipment (NE) via the SF access network.

9. The method of claim 7, wherein the SF access network includes one or more satellites.

10. The method of claim 7, wherein a security context of the key comprises at least one of a security anchor function (SEAF) or an access and mobility management function (AMF).

11. The method of claim 7, wherein a security context of the key comprises at least one of an authentication server function (AUSF) or authentication and key management for applications (AKMA).

12. The method of claim 7, wherein the application SF request message includes an AS identifier (ID) and a generic public subscription identifier (GPSI).

13. An application server (AS) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause theAS to: receive, from a network entity (NE), a store and forward (SF) service security context push request message that includes a security key, a key expiration time, and a user equipment (UE) identifier; transmit, to the NE, a response message as an acknowledgement; receive, from the UE via a SF access network, an application SF request message that includes a user plane (UP) protocol data unit (PDU) with SF data protected with the security key; select the security key based at least in part on the UE identifier; and unprotect the UP PDU with the SF data using the security key.

14. The AS of claim 13, wherein the at least one processor is operable to cause the AS to derive the security key in a security context that comprises at least one of a security anchor function (SEAF) or an access and mobility management function (AMF).

15. The AS of claim 13, wherein the application SF request message includes an AS identifier (ID) and a generic public subscription identifier (GPSI), and the security key is selected based at least in part on the GPSI of the UE.

16. The AS of claim 13, wherein the at least one processor is operable to cause the AS to transmit, to the UE via the SF access network, an acknowledgement response message.

17. A method performed by an application server (AS), the method comprising: receiving, from a network entity (NE), a store and forward (SF) service security context push request message that includes a security key, a key expiration time, and a user equipment (UE) identifier; transmitting, to the NE, a response message as an acknowledgement; receiving, from the UE via a SF access network, an application SF request message that includes a user plane (UP) protocol data unit (PDU) with SF data protected with the security key; selecting the security key based at least in part on the UE identifier; and unprotecting the UP PDU with the SF data using the security key.

18. The method of claim 17, further comprising deriving the security key in a security context that comprises at least one of a security anchor function (SEAF) or an access and mobility management function (AMF).

19. The method of claim 17, wherein the application SF request message includes an AS identifier (ID) and a generic public subscription identifier (GPSI), and the security key is selected based at least in part on the GPSI of the UE.

20. The method of claim 17, further comprising transmitting, to the UE via the SF access network, an acknowledgement response message.

Citation Information

Patent Citations

  • Satellite communication method and system based on broadband store-and-forward mode

    CN112332898A

  • Mobile phone client application authentication through media access gateway (MAG)

    US10757089B1