Secure handling of network QOE configuration parameters
A separate framework using a mobility management node to manage key material distribution secures network QoE configuration parameters during UE transitions, addressing the challenge of securing these parameters in transit and maintaining integrity and confidentiality.
Patent Information
- Application Number
- PCT/SE2024/051089
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-26
- Filing Date
- 2024-12-17
- Publication Date
- 2025-09-04
AI Technical Summary
The deletion of UE context in RRC IDLE mode hinders the ability of UEs to continue logging QoE measurements, and existing encryption frameworks for network communication are insufficient for securing network QoE configuration parameters during UE transitions.
A separate framework for securing network QoE configuration parameters is introduced, utilizing a mobility management node to manage key material distribution based on policy conditions, ensuring only eligible access network nodes receive decryption keys, thereby decoupling security protection from common communication frameworks.
This approach secures network QoE configuration parameters in transit, reduces the risk of Man-in-the-Middle attacks, and maintains confidentiality and integrity, while accommodating UE mobility.
Smart Images

Figure SE2024051089_04092025_PF_FP_ABST
Abstract
Description
[0001] SECURE HANDLING OF
[0002] NETWORK QOE CONFIGURATION PARAMETERS
[0003] TECHNICAL FIELD
[0004] Embodiments presented herein relate to methods, a mobility management node, access network nodes, computer programs, and a computer program product for secure handling of network Quality of Experience configuration parameters in a network.
[0005] BACKGROUND
[0006] In general terms, 3GPP (short for 3rd Generation Partnership Project) defines various standards for mobile telecommunications, for example specifications for network Quality of Experience (QoE) configuration parameters. In general terms, QoE in the context of 3GPP involves parameters that affect the user's perception of the network's performance, such as service accessibility, retainability, integrity, and the overall user experience.
[0007] In general terms, the specific QoE configuration parameters can be detailed and technical, and they may vary depending on the particular 3GPP release and the technology in question (e.g., long term evolution (LTE), fifth generation new radio (5G NR), etc.). Some examples of common QoE configuration parameters are QoS Class Identifier (QCI), Allocation and Retention Priority (ARP), Bit rates, Traffic Flow Templates (TFTs), 5G Quality of Service (QoS) Identifier (5QI), Measurement Thresholds, Handover Parameters, etc.
[0008] QoE measurement gathering is an application-layer concept that can be used for gathering information at the user equipment (UE). The information gathering provides an end-user perspective of the QoE to the network operator. That in turn enables the network operator to improve end-user experience of using the telecommunication network services offered by the operator. The QoE measurement gathering at the UE is initiated by the network operator via a management system, which triggers the network to activate the function in the UE. The QoE measurement gathering is carried out for UEs in an area of scope for a specified service type (e.g., streaming) or for a specific UE. If a UE can log QoE information and report the information to the network, then the reported QoE measurement can be transported to a Measurement Collection Entity (MCE) of the operator in the network.
[0009] In a 5G NR network, the gNB plays a crucial role in delivering high-quality network services and ensuring a satisfactory QoE for the users. The gNB is the primary base station component in the 5G network architecture, responsible for managing radio communications with devices, orchestrating network resources, and implementing various network policies, including those related to QoE.
[0010] A UE capable of logging and reporting QoE measurements is configured for QoE by its serving gNB. The UE has its own set of QoE configuration parameters, and the network has its own set of QoE configuration parameters. These two sets are not the same. When a UE transitions from radio resource control (RRC) CONNECTED mode to RRC IDLE mode (or RRC INACTIVE mode), the entire Access Stratum (AS) UE context is deleted - both in the UE and in the gNB. Hereinafter, the three aforementioned RRC modes (sometimes also referred to as RRC states) will simply be referred to as CONNECTED mode, IDLE mode, and INACTIVE mode. On the UE- side, the AS UE Context contains the QoE configuration parameters for the UE. Correspondingly, on the gNB-side, the AS UE contexts contains the networks’ QoE parameters. Therefore, deletion of the AS UE context when going to IDLE mode hinders the UE’s ability to continue logging QoE for services (e.g., Multicast Broadcast, etc.).
[0011] Hence, there is still a need for secure handling of the network QoE configuration parameters.
[0012] SUMMARY
[0013] An object of embodiments herein is to address the above issues.
[0014] One possibility is that a UE in IDLE mode is utilized for temporarily storing the network QoE configuration parameters. It could then be possible for one gNB (hereinafter referred to as source gNB or first access network node) to provide the network QoE configuration parameters to the UE and for one gNB (hereinafter referred to as target gNB or second access network node) to at some later point in time fetch the network QoE configuration parameters from the UE.
[0015] However, if the network QoE configuration parameters are stored in the UE, the network QoE configuration parameters are exposed in a potentially hostile environment, and a mechanism to protect the network QoE configuration parameters is therefore required.
[0016] A particular object is therefore to secure the network QoE configuration parameters when stored at the UE.
[0017] In this respect, one option could be to utilize some encryption scheme, where the network QoE configuration parameters are encrypted before being provided to the UE. However, there are many such encryption schemes to choose from. One example could be to utilize the same, or at least a similar, framework for encryption as for common communication in the network (e.g., the communication between a gNB and a UE, or the communication between two gNBs).
[0018] However, utilizing such an existing framework for a new purpose (i.e., for security protecting the network QoE configuration parameters in transit) still makes the network QoE configuration parameters vulnerable to security attacks. This is since knowledge of the framework for encrypting common communication in the network can be used by an adversary in an effort to gain access to the network QoE configuration parameters.
[0019] A further particular object is therefore to provide a separate framework for security protecting the network QoE configuration parameters in transit, where this separate framework is decoupled from existing frameworks for security protection of common communication in a network.
[0020] A further particular object is to take into consideration the possible mobility of the UE.
[0021] According to a first aspect there is presented a method for secure handling of network QoE configuration parameters in a network. The method is performed by a mobility management node. The method comprises receiving a request from a second access network node for key material for the second access network node to process security protected network QoE configuration parameters. The method comprises verifying whether the second access network node fulfils a policy condition or not. The method comprises transmitting the key material to the second access network node only when the second access network node fulfils the policy condition.
[0022] According to a second aspect there is presented a mobility management node for secure handling of network QoE configuration parameters in a network. The mobility management node comprises processing circuitry. The processing circuitry is configured to cause the mobility management node to receive a request from a second access network node for key material for the second access network node to process security protected network QoE configuration parameters. The processing circuitry is configured to cause the mobility management node to verify whether the second access network node fulfils a policy condition or not. The processing circuitry is configured to cause the mobility management node to transmit the key material to the second access network node only when the second access network node fulfils the policy condition.
[0023] According to a third aspect there is presented a computer program for secure handling of network QoE configuration parameters in a network, the computer program comprising computer program code which, when run on processing circuitry of a mobility management node, causes the mobility management node to perform actions. One action comprises the mobility management node to receive a request from a second access network node for key material for the second access network node to process security protected network QoE configuration parameters. One action comprises the mobility management node to verify whether the second access network node fulfils a policy condition or not. One action comprises the mobility management node to transmit the key material to the second access network node only when the second access network node fulfils the policy condition.
[0024] According to a fourth aspect there is presented a method for secure handling of network QoE configuration parameters in a network. The method is performed by a first access network node. The method comprises obtaining key material. The method comprises obtaining network QoE configuration parameters. The method comprises security protecting the network QoE configuration parameters using the key material. The method comprises transmitting the security protected network QoE configuration parameters to one of the UEs served by the first access network node.
[0025] According to a fifth aspect there is presented a first access network node for secure handling of network QoE configuration parameters in a network. The first access network node comprises processing circuitry. The processing circuitry is configured to cause the first access network node to obtain key material. The processing circuitry is configured to cause the first access network node to obtain network QoE configuration parameters. The processing circuitry is configured to cause the first access network node to security protect the network QoE configuration parameters using the key material. The processing circuitry is configured to cause the first access network node to transmit the security protected network QoE configuration parameters to one of the UEs served by the first access network node.
[0026] According to a sixth aspect there is presented a computer program for secure handling of network QoE configuration parameters in a network, the computer program comprising computer program code which, when run on processing circuitry of a first access network node, causes the first access network node to perform actions. One action comprises the first access network node to obtain key material. One action comprises the first access network node to obtain network QoE configuration parameters. One action comprises the first access network node to security protect the network QoE configuration parameters using the key material. One action comprises the first access network node to transmit the security protected network QoE configuration parameters to one of the UEs served by the first access network node.
[0027] According to a seventh aspect there is presented a method for secure handling of network QoE configuration parameters in a network. The method is performed by a second access network node. The method comprises obtaining key material. The method comprises obtaining security protected network QoE configuration parameters from a UE served by the second access network node. The method comprises obtaining the network QoE configuration parameters by processing the security protected network QoE configuration parameters using the key material.
[0028] According to an eighth aspect there is presented a second access network node for secure handling of network QoE configuration parameters in a network. The second access network node comprises processing circuitry. The processing circuitry is configured to cause the second access network node to obtain key material. The processing circuitry is configured to cause the second access network node to obtain security protected network QoE configuration parameters from a UE served by the second access network node. The processing circuitry is configured to cause the second access network node to obtain the network QoE configuration parameters by processing the security protected network QoE configuration parameters using the key material.
[0029] According to a ninth aspect there is presented a computer program for secure handling of network QoE configuration parameters in a network, the computer program comprising computer program code which, when run on processing circuitry of a second access network node, causes the second access network node to perform actions. One action comprises the second access network node to obtain key material. One action comprises the second access network node to obtain security protected network QoE configuration parameters from a UE served by the second access network node. One action comprises the second access network node to obtain the network QoE configuration parameters by processing the security protected network QoE configuration parameters using the key material.
[0030] According to a tenth aspect there is presented a computer program product comprising a computer program according to at least one of the third aspect, the sixth aspect, and the ninth aspect and a computer readable storage medium on which the computer program is stored. The computer readable storage medium can be a non- transitory computer readable storage medium.
[0031] Advantageously, these aspects provide for secure handling of the network QoE configuration parameters in transit. Advantageously, according to these aspects, the network QoE configuration parameters are secured when stored at the UE.
[0032] Advantageously, these aspects provide a separate framework for security protecting the network QoE configuration parameters in transit, where this separate framework is decoupled from existing frameworks for security protection of common communication in a network.
[0033] Advantageously, these aspects reduce the risk of Man-in-the-Middle attacks being successful.
[0034] Advantageously, these aspects take into consideration the possible mobility of the UE.
[0035] Advantageously, these aspects enable the mobility management node, responsible for managing mobility events in the network, to act as policy definition point while the access network nodes act as policy enforcement points. In this way, the mobility management node can provide key material to only those access network nodes that, for example, are in the area of scope for a particular set of network QoE configuration parameters.
[0036] Advantageously, these aspects enable the network QoE configuration parameters to get confidentiality and integrity protection when received by the second access network node, and only if the mobility management node verifies the second access network node, this second access network node obtains key material usable for decrypting the security protected network QoE configuration parameters.
[0037] Advantageously, some aspects enable vendors to protect their proprietary configuration parameters and metrics (hereinafter referred to as vendor-specific parameters) from access network nodes and mobility management nodes vendors that do not belong to the same vendor.
[0038] Advantageously, some aspects enable public configuration parameters (such as standardized parameters) and metrics (hereinafter referred to as public parameters) to be accessible to all access network nodes that can be verified by the mobility management node, irrespective of vendor.
[0039] Other objectives, features and advantages of the enclosed embodiments will be apparent from the following detailed disclosure, from the attached list of claims as well as from the drawings.
[0040] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, module, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, module, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.
[0041] BRIEF DESCRIPTION OF THE DRAWINGS
[0042] The inventive concept is now described, by way of example, with reference to the accompanying drawings, in which:
[0043] Fig. 1 is a schematic diagram illustrating a network according to embodiments;
[0044] Figs. 2, 3, and 4 are flowcharts of methods according to embodiments;
[0045] Figs. 5 and 6 are signaling diagrams according to embodiments;
[0046] Fig. 7 is a schematic diagram showing structural units of a mobility management node according to an embodiment;
[0047] Fig. 8 is a schematic diagram showing structural units of a first access network node according to an embodiment;
[0048] Fig. 9 is a schematic diagram showing structural units of a second access network node according to an embodiment; and
[0049] Fig. 10 shows one example of a computer program product comprising computer readable means according to an embodiment. DETAILED DESCRIPTION
[0050] The inventive concept will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the inventive concept are shown. This inventive concept may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concept to those skilled in the art. Like numbers refer to like elements throughout the description. Any step or feature illustrated by dashed lines should be regarded as optional.
[0051] Fig. i is a schematic diagram illustrating a network too where embodiments presented herein can be applied. The network too comprises access network nodes 140a, 140b, 140c, i4od. In some non-limiting examples each access network node 140a: i4od is any of: a radio access network node, a radio base station, a base transceiver station, a node B, an evolved node B, a gNB, and access node, an access point, a transmission and reception point, an integrated access and backhaul node. The access network nodes 140a: i4od are configured to provide network access to, and thus serve, UEs. For ease of description only one single UE 150 is illustrated in Fig. 1. In some non-limiting examples the UE is any of: a portable wireless device, a mobile station, a mobile phone, a handset, a wireless local loop phone, a smartphone, a laptop computer, a tablet computer, a network-connectible vehicle, or the like.
[0052] The access network nodes 140a: i4od are provided in different scopes 130a, 130b. Examples of scopes will be provided below. The access network nodes 140a: i4od are operatively connected to a mobility management node 110. In some non-limiting examples the mobility management node implements the functionality of an Access and Mobility Management Function (AMF) or another network function with similar purpose. In turn, the mobility management node 110 is operatively connected to an MCE 120.
[0053] It is hereinafter that one access network node 140a (called the source gNB, or first access network node) stores security protected network QoE configuration parameters on a UE 150 and another access network node 140b (called the target gNB, or second access network node) retrieves the security protected network QoE configuration parameters from the same UE 150. However, it is understood that the source gNB and the target gNB can be one and the same gNB and thus that the security protected network QoE configuration parameters is retrieved by the very same access network node that stored the security protected network QoE configuration parameters on the UE 150.
[0054] In some aspects, the network QoE configuration parameters are valid for an area of scope. This area of scope, or scope for short, could be a tracking area (TA), a list of access network nodes, or corresponding cells, or be another way of identifying a set of access network nodes. The scope could also be a domain, such as a logical address space, a logical collection of identifiers for access network nodes or collection of access network nodes. The scope could also be a property (possibly in combination with a domain or other addressing, or location, based grouping). A property could here be one or more certain capabilities of the access network nodes, for example, the ability to orchestrate QoE measurements of the UE.
[0055] The mobility management node 110 is connectible to the access network nodes in one or more scopes, and is configured (e.g., from the MCE 120) with which access network nodes belong to a given scope. The mobility management node 110 also has access to an identifier for that scope, referred to as the scope ID. The mobility management node 110 could construct the identifier itself, or it could have been obtained by other means, e.g., via configuration.
[0056] Further, the mobility management node 110 is configured to generate key material, identifying the cryptographic secrets, such as encryption keys. For this purpose, the mobility management node 110 might be provided with a hardware or software random number generator. The key material generation may be performed using a true random number generator (TRNG) or a pseudorandom number generator (PRNG). An example of a pseudorandom generator is a key derivation function (KDF) applied to a secret value and a label, where a different label result in a different input with high probability. An example of a KDF is the HMAC-SHA256 function. A method for secure handling of network QoE configuration parameters in a network IOO can be summarized as follows. Particular details of the mobility management node and the access network nodes will be disclosed below with reference to Fig. 2, Fig. 2, and Fig. 3, respectively.
[0057] When the UE goes to CONNECTED mode for the first time, the access network node that the UE is operatively connected to obtains key material from the mobility management node. This access network node is referred to as the first access network node. The key material is separate from the key material in the UE’s key hierarchy, e.g., KgNB and K_SEAF.
[0058] The first access network node may choose to store its network QoE configuration parameters in the UE for later retrieval by the same or other access network node (being the second access network node) in the same area of scope. The area of scope is defined by a policy in the mobility management node. The access network nodes might not even be aware of the scope.
[0059] Before storing the network QoE configuration parameters, the first access network node encrypts and integrity protects the network QoE configuration parameters using the key material. Optionally, the first access network node adds a timestamp, or a counter value, to the network QoE configuration parameters before encryption which can later be used to verify the freshness of the network QoE configuration parameters.
[0060] Examples of network QoE configuration parameters will be disclosed below. In some aspects, the network QoE configuration parameters have two parts; a public part and a private part. The private part might comprise vendor-specific parameters and metrics that a given vendor does not want to share with other vendors. Therefore, in some examples, part of the network QoE configuration parameters, if considered sensitive by a given vendor, will get additional confidentiality first by encryption using key material only known to the access network nodes (and mobility management nodes) of that given vendor, before the entire network QoE configuration parameters are encrypted. Hence, even if a second access network node from another vendor decrypts the encrypted network QoE configuration parameters from UE, sensitive part still remains encrypted since the key material of the given vendor is not known to the vendor of the second access network node. Hence, in this way, the vendor-specific parameters and metric might first be encrypted using vendor-specific key material only known to access network node of a given vendor. Then the resultant data, together with the remaining network QoE configuration parameters, is further encrypted and integrity protected using another key material supplied by the mobility management node.
[0061] Upon reception, the UE 150 stores the security protected network QoE configuration parameters.
[0062] The second access network node retrieves the security protected network QoE configuration parameters from the UE. For this purpose, the UE might signal to the second access network node the UE’s capability to perform QoE measurements, or at least to store network related information, and the second access network node might then query the UE for the security protected network QoE configuration parameters.
[0063] The second access network node then obtains key material from the mobility management node for second access network node to decrypt the security protected network QoE configuration parameters.
[0064] Based on locally maintained policies, the mobility management node verifies that the second access network node is eligible to receive the requested key material and then sends the key material to the second access network node. Here, the locally maintained policies by the mobility management node identify the corresponding key material for the second access network node in the same scope as that of the first access network node. For example, the mobility management node might maintain a mapping of symmetric security keys for each defined scope such that all access network nodes in the same scope will receive the same key material for performing data security protection operations (e.g., encrypt / decrypt / integrity protect-validate). This means that the mobility management node, for example, may send the key material for a certain scope to any access network node in that scope. The sending of the key material maybe conditioned on various parameters. For example, the network QoE configuration parameters may contain a key index, which the access network node provides to the mobility management node. Here, different indexes may map to different key material. The network node providing the access network nodes with the network context in the first place may provide the access network nodes with that index and the access network nodes can attach it to the network QoE configuration parameters before encryption.
[0065] Upon reception of the key material from the mobility management node, the second access network node decrypts and validates integrity of the network QoE configuration parameters received from the UE and can then take it into use.
[0066] Reference is now made to Fig. 2 illustrating a method for secure handling of network QoE configuration parameters in a network 100 as performed by the mobility management node no according to an embodiment.
[0067] S102: The mobility management node no receives a request from a second access network node 140b for key material for the second access network node 140b to process security protected network QoE configuration parameters.
[0068] S106: The mobility management node no verifies whether the second access network node 140b fulfils a policy condition or not.
[0069] S108: The mobility management node no transmits the key material to the second access network node 140b only when the second access network node 140b fulfils the policy condition.
[0070] Hence, step S108 is not performed in case the second access network node 140b does not fulfil the policy condition. That is, no key material is sent to the second access network node 140b. Instead, the mobility management node 110, for example, may send a reject message, or error message, to the second access network node 140b.
[0071] In this way the mobility management node 110 can be utilized for generating and storing key material, as well as for providing access control to the key material based on a policy defining which access network nodes that may retrieve key material.
[0072] This method maintains a consistent security protection level of the network QoE configuration parameters when stored at the UE and retrieved from the UE by an access network node that fulfils the policy condition for scenarios with mobility as well as for scenarios without mobility.
[0073] This method provides a level of separation between security protecting the network QoE configuration parameters in transit and security protecting common communication (between the access network nodes and the UEs as well as between the access network nodes themselves) in the network. This is achieved by having separate key material for these two purposes.
[0074] Embodiments relating to further details of secure handling of network QoE configuration parameters in a network 100 as performed by the mobility management node no will now be disclosed with continued reference to Fig. 2.
[0075] The provision of key material from the mobility management node to the access network nodes (such as to the second access network node 140b in step S108) could be carried over NGAP Initial Context Setup Request / Response messaging. Hence, in some embodiments, the key material is transmitted using NGAP Initial Context Setup Request / Response messaging. However, also, other NGAP procedures for NG-c interface management could be utilized for this purpose.
[0076] There can be different examples of requests received by the mobility management node 110 from the second access network node 140b in step S102. For example, the request might comprise one or more identifiers. In some embodiments, the request comprises an identifier of, or for, one or more of: the second access network node 140b, a first access network node 140a, a UE 150.
[0077] As disclosed in step S108, the mobility management node 110 transmits the key material to the second access network node 140b. this implicitly implies that the mobility management node 110 has access to the key material. In this respect, the mobility management node 110 might either receive the key material from a key material generating function or the mobility management node 110 might generate the key material itself. Therefore, in some embodiments, the mobility management node 110 is configured to perform (optional) step S104.
[0078] S104: The mobility management node 110 generates the key material. There can be different ways for the mobility management node no to generate the key material in step S104. The key material might for example be generated with respect to some identifier. In particular, in some embodiments, the key material is generated in dependence of an identifier of, or for, one or more of: a UE 150, the second access network node 140b, a first access network node 140a. For example, the mobility management node 110 might have access to a mapping between key material and scopes, such as tracking areas (TAs), where each of the scopes is associated with its own key material. This method provides confidentiality and integrity protection of the network QoE configuration parameters while stored at the UE in an area of scope. This could, for example, be the case where there are different network QoE configurations, and thus different network QoE configuration parameters, for different scopes. Therefore, in some embodiments, the network QoE configuration parameters are associated with one or more of the scopes.
[0079] In some aspects, it is ensured that only access network nodes belonging to the domain defined by the MCE get access to the network QoE configuration parameters. This can be achieved by the mobility management node providing access network nodes with the key material at UE mobility events, allowing only those access network nodes that should have access to the network QoE configuration parameters to retrieve it from the UE. For this purpose, in some embodiments, the second access network node 140b is regarded as fulfilling the policy condition in case the second access network node 140b belongs to said one or more of the scopes.
[0080] In some aspects, and as will be further disclosed below, the network QoE configuration parameters are security protected by a first access network node 140a. The key material and / or the network QoE configuration parameters (either security protected or not) might therefore be provided by the mobility management node 110 to the first access network node 140a. In particular, in some embodiments, the mobility management node 110 is configured to perform (optional) step S110.
[0081] S110: The mobility management node 110 transmits the key material and / or the (for example, security protected) network QoE configuration parameters to a first access network node 140a belonging to said one of the scopes. In some aspects, and as will be further disclosed below, the mobility management node no might receive the security protected network QoE configuration parameters from an access network node 140a, 140b and / or from a UE 150. Therefore, in some embodiments, the mobility management node 110 is configured to perform (optional) step S112.
[0082] S112: The mobility management node 110 receives the security protected network QoE configuration parameters from a UE 150.
[0083] There can be different examples of network QoE configuration parameters, in some non-limiting examples, the network QoE configuration parameters at least pertain to any, or any combination of: measurement collector entity information (e.g., MCE ID, or MCE Internet protocol (IP) address), Trace Collector Entity (TCE) ID, Minimization of Drive Tests (MDT) alignment information, QoE measurement type. Further examples of network QoE configuration parameters will be disclosed below.
[0084] Reference is now made to Fig. 3 illustrating a method for secure handling of network QoE configuration parameters in a network 100 as performed by the first access network node 140a according to an embodiment.
[0085] S202: The first access network node 140a obtains key material.
[0086] S204: The first access network node 140a obtains network QoE configuration parameters.
[0087] S208: The first access network node 140a security protects the network QoE configuration parameters using the key material.
[0088] S210: The first access network node 140a transmits the security protected network QoE configuration parameters to one of the UEs 150 served by the first access network node 140a.
[0089] This method enables the network QoE configuration parameters to be security protected while stored at the UE. Embodiments relating to further details of secure handling of network QoE configuration parameters in a network 100 as performed by the first access network node 140a will now be disclosed with continued reference to Fig. 3.
[0090] In some embodiments, both the key material and the network QoE configuration parameters are obtained from the mobility management node 110. The case where an access network node receives the network QoE configuration parameters from a UE will be disclosed below. This access network node is then referred to as a second access network node 140b.
[0091] There might be different actions taken by the first access network node 140a upon having obtained the network QoE configuration parameters. In some aspects, the first access network node 140a utilizes the network QoE configuration parameters for traffic management purposes. Hence, in some embodiments, the first access network node 140a is configured to perform (optional) step S206.
[0092] S206: The first access network node 140a enforces, using the network QoE configuration parameters, traffic management of a UE 150 served by the first access network node 140a.
[0093] It is here noted that the first access network node 140a could utilize the network QoE configuration parameters also for other purposes. Some non-limiting purposes are: scheduling and resource allocation, traffic flow management, load balancing, traffic off-loading, adaptive quality-of-service (QoS) management, mobility management, QoE measurements and reporting.
[0094] As disclosed above, in some embodiments, the first access network node 140a adds a timestamp, or a counter value, to the network QoE configuration parameters before encryption which can later be used to verify the freshness of the network QoE configuration parameters.
[0095] In some aspects, the first access network node 140a distinguishes between a first type of parameters and a second type of parameters in the network QoE configuration parameters. For example, the first access network node 140a might apply an extra layer of security protection to one of these types of parameters. Particularly, the network QoE configuration parameters might comprise at least some first type of parameters and at least some second type of parameters, and where the first access network node 140a is configured to perform (optional) step S208-2 as part of security protecting the network QoE configuration parameters using the key material in step S208.
[0096] S208-2: The first access network node 140a separately security protects only one of the first type and the second type of parameters using a separate key material before security protecting the network QoE configuration parameters using the key material.
[0097] Here, the first type of parameters might be the aforementioned vendor-specific parameters. Likewise, the second type of parameters might be the aforementioned public parameters. The separate key material might thus be vendor-specific key material.
[0098] The first access network node might transmit the security protected network QoE configuration parameters to the UE using RRC Reconfiguration signaling. That is, in some embodiments, the security protected network QoE configuration parameters are in step S210 transmitted using RRC reconfiguration signaling.
[0099] Reference is now made to Fig. 4 illustrating a method for secure handling of network QoE configuration parameters in a network 100 as performed by the second access network node 140b according to an embodiment.
[0100] S302: The second access network node 140b obtains key material.
[0101] S304: The second access network node 140b obtains security protected network QoE configuration parameters from a UE 150 served by the second access network node 140b.
[0102] S306: The second access network node 140b obtains the network QoE configuration parameters by processing the security protected network QoE configuration parameters using the key material. Embodiments relating to further details of secure handling of network QoE configuration parameters in a network 100 as performed by the second access network node 140b will now be disclosed with continued reference to Fig. 4.
[0103] In some embodiments, the key material from the mobility management node 110. In some examples, the second access network node 140b also receives network QoE configuration parameters from the mobility management node 110 (in a step separated from step S304).
[0104] The second access network node 140b might in step S304 obtain the security protected network QoE configuration parameters from the UE over RRC Reconfiguration signaling.
[0105] As disclosed above, the first access network node 140a might distinguish between a first type of parameters and a second type of parameters in the network QoE configuration parameters. Hence, in some embodiments, the security protected network QoE configuration parameters comprise at least some first type parameters and at least some second type parameters. In some embodiments, the second access network node 140b is therefore configured to perform (optional) step S306-2 as part of obtaining the network QoE configuration parameters in step S306.
[0106] S306-2: The second access network node 140b separately processes one of the first type and the second type of parameters using a separate key material to obtain the first type or the second type of parameters after having processed the security protected network QoE configuration parameters using the key material.
[0107] As above, the first type of parameters might be the aforementioned vendor-specific parameters. Likewise, the second type of parameters might be the aforementioned public parameters. The separate key material might thus be vendor-specific key material.
[0108] As disclosed above, in some embodiments, the first access network node 140a adds a timestamp, or a counter value, to the network QoE configuration parameters before encryption. This timestamp, or a counter value can be used by the second access network node 140b to verify the freshness of the network QoE configuration parameters. Hence, in some embodiments, the second access network node 140b verifies the freshness of the timestamp, or the counter value, after having processed the security protected network QoE configuration parameters using the key material. In this way, by comparing the timestamp, or counter value, to some reference value, the second access network node 140b can verify that the received network QoE configuration parameters are not outdated.
[0109] There might be different actions taken by the second access network node 140b upon having obtained the network QoE configuration parameters.
[0110] In some aspects, the second access network node 140b utilizes the network QoE configuration parameters for traffic management purposes. Hence, in some embodiments, the second access network node 140b is configured to perform (optional) step S308.
[0111] S308: The second access network node 140b enforces, using the network QoE configuration parameters, traffic management of a UE 150 served by the second access network node 140b.
[0112] As above, the second access network node 140b could utilizes the network QoE configuration parameters also for other purposes. Some non-limiting purposes (as also listed above) are: scheduling and resource allocation, traffic flow management, load balancing, traffic off-loading, adaptive quality-of-service (QoS) management, mobility management, QoE measurements and reporting.
[0113] In some aspects, the second access network node 140b forwards the network QoE configuration parameters (security protected or not) to the mobility management node 110. Hence, in some embodiments, the second access network node 140b is configured to perform (optional) step S310.
[0114] S310: The second access network node 140b forwards the (for example, security protected) network QoE configuration parameters to the mobility management node
[0115] 110. The second access network node might pass the (for example, security protected) network QoE configuration parameters to the mobility management node by using NGAP Initial Context Setup Request / Response messaging. Hence, in some embodiments, the (security protected) network QoE configuration parameters are forwarded using NGAP Initial Context Setup Request / Response messaging. However, also other NGAP procedures could be used for this purpose.
[0116] Some non-limiting examples of network QoE configuration parameters will be disclosed next. A QoE reference represents the ID of the QoE measurement configuration. An RRC ID can be used on the air interface to refer to the network QoE configuration parameters instead of the QoE reference. Measurement Collector Entity Information represents the ID or the IP address of the entity to which the QoE measurement reports are to be sent. Service Type Information represents the service type (e.g., streaming service, voice over NR (VoNR), extended reality (XR) service, etc.) for which the QoE measurements are done. A Container for Application Layer Measurement Configuration indicates what metrics the UE should measure and how often the UE should send QoE measurement reports. Minimization of Drive Tests Alignment Information represents instructions of whether the QoE measurement should be performed in an aligned manner with radio related measurements or not. Area Scope of measurements is a list of cells or Tracking Areas or public land mobile networks (PLMNs) in which the UE is to perform the QoE measurements. Single Network Slice Selection Assistance Information (S-NSSAIs) provides information of the network slice on which the UE is to perform the QoE measurements. RAN visible QoE Information informs which of the QoE measurements that should be exposed to the access network nodes. QoE measurement type defines the measurement type of the QoE measurements, for example whether the QoE measurements should be signaling based, or management based.
[0117] One embodiment of a method for secure handling of network QoE configuration parameters in a network too for a mobility scenario will be disclosed next. In this embodiment, the mobility management node is represented by an AMF, the second access network node is represented by a target gNB, and the first access network node is represented by a source gNB. The AMF generates key material Kb_i using a Ture Random Number Generator (TRNG) or a Pseudorandom Number Generator (PRNG) from a seed only known to the AMF. The key material Kb_i could be a single encryption key or multiple encryption keys used for different purposes, for example for confidentiality protection, and integrity protection.
[0118] The AMF transmits, using NGAP signaling, network QoE configuration parameters together with the key material Kb_i to the source gNB that holds the UE context and already has established an AS security context with the UE.
[0119] The source gNB integrity protects and encrypts the network QoE configuration parameters using a suitable algorithm, such as authenticated encryption with associated data (AEAD). As above, the source gNB might first separately security protecting only the vendor-specific parameters of the network QoE configuration parameters.
[0120] The source gNB transmits, using RRC signaling, the security protected network QoE configuration parameters to the UE. The RRC signaling is protected in the usual way using the AS security context. Specifically, that transfer is integrity protected so that the UE does not accept data from a third party (such as a false base station).
[0121] The UE stores the security protected network QoE configuration parameters (either in application layer, in baseband or some other part of the Mobile Equipment (ME) part of the UE).
[0122] A network operator policy might trigger the target gNB to retrieve, using RRC signaling, the security protected network QoE configuration parameters from the UE. Alternatively, the UE might unsolicited provide the security protected network QoE configuration parameters to the target gNB. The UE, when in CONNTECTED mode, transmits the security protected network QoE configuration parameters over RRC signaling to the target gNB.
[0123] The target gNB decrypts the security protected network QoE configuration parameters and validates the integrity thereof. This decryption is possibly only if the target gNB has received the corresponding key material Kb j from the AMF. For this purpose the target gNB queries the AMF for the key material and the AMF provides the key material Kb j after having verified that the target gNB is in same scope as the source gNB.
[0124] Upon decryption, the target gNB forwards, over NGAP signaling, the thus decrypted network QoE configuration parameters to the AMF.
[0125] The UE may transition from CONNECTED to IDLE or INACTIVE modes and may camp on another target gNB during mobility. In IDLE mode, the UE may send the security protected network QoE configuration parameters over NAS signaling to the AMF via an access network node, where the transmission of the security protected network QoE configuration parameters thus is transparent to this access network node. Decryption of the protected network QoE configuration parameters and integrity validation is then carried out by the AMF.
[0126] One embodiment of a method for secure handling of network QoE configuration parameters in a network loo for a mobility scenario where the UE is in INACTIVE or IDLE mode will be disclosed next with reference to Fig. 5. In this embodiment, the mobility management node is represented by an AMF, the second access network node is represented by a target gNB, and the first access network node is represented by a source gNB.
[0127] S401: The target gNB, using a NGAP procedure, requests the key material from the AMF.
[0128] S402: The AMF checks a locally configured policy for gNB-eligibility and identifies the key material for the target gNB.
[0129] S403: The AMF, using a NGAP procedure, provides the key material, possibly in combination with identification of an encryption algorithm for which the key material is to be used.
[0130] The UE is in RRC INACTIVE / IDLE mode and is camping on the target gNB by cell (re-)selection.
[0131] S404: The source gNB transfers the UE context to the target gNB. The UE transitions to CONNECTED mode.
[0132] S405: The target gNB requests security protected network QoE configuration parameters from the UE.
[0133] S406: The UE provides the security protected network QoE configuration parameters to the target gNB.
[0134] S407: The target gNB decrypts and validates the integrity of the received security protected network QoE configuration parameters using the information received in step S403. The target gNB holds a preconfigured local mapping table of MCE IDs and MCE IP addresses. This is how the target gNB gets knowledge of the MCE IP address. The target gNB can then forward QoE reports as received from the UE to the MCE with the identified MCE IP address.
[0135] One embodiment of a method for secure handling of network QoE configuration parameters in a network 100 for a mobility scenario where the UE is in CONNECTED mode will be disclosed next with reference to Fig. 6. In this embodiment, the mobility management node is represented by an AMF, the second access network node is represented by a target gNB, and the first access network node is represented by a source gNB.
[0136] 8501a, 8501b: Both the source gNB and the target gNB request, using a NGAP procedure, key material from the AMF.
[0137] S502: The AMF checks a locally configured policy for gNB-eligibility and identifies the key material for the source gNB and the target gNB.
[0138] 8503a, 8503b: The AMF, using a NGAP procedure, provides the key material, possibly in combination with identification of an encryption algorithm for which the key material is to be used to the source gNB and the target gNB.
[0139] S504: The AMF provides network QoE configuration parameters, as received from a management entity, to the source gNB. S505: The source gNB has a preconfigured local mapping of MCE IP addresses to MCE IDs. The source gNB replaces the MCE IP address in the network QoE configuration parameters with the MCE ID. The source gNB security protects the network QoE configuration parameters using the information received in step 8503a.
[0140] The UE is in CONNECTED mode.
[0141] S506: The source gNB transmits the security protected network QoE configuration parameters to the UE using an RRC procedure.
[0142] S507: The UE stores the security protected network QoE configuration parameters.
[0143] S508: A handover procedure takes place for the UE from the source gNB to the target gNB whereby the source gNB hands over the UE context to the target gNB.
[0144] S509: The target gNB requests security protected network QoE configuration parameters from the UE.
[0145] S510: The UE provides the security protected network QoE configuration parameters to the target gNB.
[0146] S511: The target gNB decrypts and validates the integrity of the received security protected network QoE configuration parameters using the information received in step 8503b. The target gNB holds a preconfigured local mapping table of MCE IDs and MCE IP addresses. This is how the target gNB gets knowledge of the MCE IP address. The target gNB can then forward QoE reports as received from the UE to the MCE with the identified MCE IP address.
[0147] Fig. 7 schematically illustrates, in terms of a number of structural units, the components of a mobility management node 700 according to an embodiment. Processing circuitry 710 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1010a (as in Fig. 10), e.g. in the form of a storage medium 730. The processing circuitry 710 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA). Particularly, the processing circuitry 710 is configured to cause the mobility management node 700 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 730 may store the set of operations, and the processing circuitry 710 may be configured to retrieve the set of operations from the storage medium 730 to cause the mobility management node 700 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus the processing circuitry 710 is thereby arranged to execute methods as herein disclosed.
[0148] The storage medium 730 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.
[0149] The mobility management node 700 may further comprise a communications (comm.) interface 720 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 720 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0150] The processing circuitry 710 controls the general operation of the mobility management node 700 e.g. by sending data and control signals to the communications interface 720 and the storage medium 730, by receiving data and reports from the communications interface 720, and by retrieving data and instructions from the storage medium 730. Other components, as well as the related functionality, of the mobility management node 700 are omitted in order not to obscure the concepts presented herein.
[0151] The mobility management node 700 may be provided as a standalone device or as a part of at least one further device. For example, the mobility management node 700 may be provided in a node of the core network. Alternatively, functionality of the mobility management node 700 may be distributed between at least two devices, or nodes. These at least two nodes, or devices, may either be part of the same network part (such as the core network) or may be spread between at least two such network parts. In general terms, instructions that are required to be performed in real time may be performed in a device, or node, operatively closer to the cell than instructions "2-1 that are not required to be performed in real time. Thus, a first portion of the instructions performed by the mobility management node 700 may be executed in a first device, and a second portion of the of the instructions performed by the mobility management node 700 may be executed in a second device; the herein disclosed embodiments are not limited to any particular number of devices on which the instructions performed by the mobility management node 700 may be executed. Hence, the methods according to the herein disclosed embodiments are suitable to be performed by a mobility management node 700 residing in a cloud computational environment. Therefore, although a single processing circuitry 710 is illustrated in Fig. 7, the processing circuitry 710 may be distributed among a plurality of devices, or nodes. The same applies to the computer program 1020a of Fig. 10.
[0152] Fig. 8 schematically illustrates, in terms of a number of structural units, the components of a first access network node 800 according to an embodiment. Processing circuitry 810 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1010b (as in Fig. 10), e.g. in the form of a storage medium 830. The processing circuitry 810 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0153] Particularly, the processing circuitry 810 is configured to cause the first access network node 800 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 830 may store the set of operations, and the processing circuitry 810 may be configured to retrieve the set of operations from the storage medium 830 to cause the first access network node 800 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus the processing circuitry 810 is thereby arranged to execute methods as herein disclosed.
[0154] The storage medium 830 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory. The first access network node 8oo may further comprise a communications interface 820 for communications with other entities, functions, nodes, and devices, as in Fig.
[0155] 1. As such the communications interface 820 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0156] The processing circuitry 810 controls the general operation of the first access network node 800 e.g. by sending data and control signals to the communications interface 820 and the storage medium 830, by receiving data and reports from the communications interface 820, and by retrieving data and instructions from the storage medium 830. Other components, as well as the related functionality, of the first access network node 800 are omitted in order not to obscure the concepts presented herein.
[0157] Fig. 9 schematically illustrates, in terms of a number of structural units, the components of a second access network node 900 according to an embodiment. Processing circuitry 910 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1010c (as in Fig. 10), e.g. in the form of a storage medium 930. The processing circuitry 910 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0158] Particularly, the processing circuitry 910 is configured to cause the second access network node 900 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 930 may store the set of operations, and the processing circuitry 910 may be configured to retrieve the set of operations from the storage medium 930 to cause the second access network node 900 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus the processing circuitry 910 is thereby arranged to execute methods as herein disclosed.
[0159] The storage medium 930 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory. The second access network node 900 may further comprise a communications interface 920 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 920 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0160] The processing circuitry 910 controls the general operation of the second access network node 900 e.g. by sending data and control signals to the communications interface 920 and the storage medium 930, by receiving data and reports from the communications interface 920, and by retrieving data and instructions from the storage medium 930. Other components, as well as the related functionality, of the second access network node 900 are omitted in order not to obscure the concepts presented herein.
[0161] Some (radio) access network architectures define access network nodes (or gNBs) comprising multiple component parts or nodes: a central unit (CU), one or more distributed units (DUs), and one or more radio units (RUs). The protocol layer stack of the network node is divided between the CU, the DUs and the RUs, with one or more lower layers of the stack implemented in the RUs, and one or more higher layers of the stack implemented in the CU and / or DUs. The CU is coupled to the DUs via a fronthaul higher layer split (HLS) network; the CU / DUs are connected to the RUs via a fronthaul lower-layer split (LLS) network. The DU may be combined with the CU in some embodiments, where a combined DU / CU may be referred to as a CU or simply a baseband unit. A communication link for communication of user data messages or packets between the RU and the baseband unit, CU, or DU is referred to as a fronthaul network or interface. Messages or packets may be transmitted from the access network node in the downlink (i.e., from the CU to the RU) or received by the access network node in the uplink (i.e., from the RU to the CU).
[0162] Fig. 10 shows one example of a computer program product 1010a, 1010b, 1010c comprising computer readable means 1030. On this computer readable means 1030, a computer program 1020a can be stored, which computer program 1020a can cause the processing circuitry 710 and thereto operatively coupled entities and devices, such as the communications interface 720 and the storage medium 730, to execute methods according to embodiments described herein. The computer program 1020a and / or computer program product 1010a may thus provide means for performing any steps of the mobility management node no, 700 as herein disclosed. On this computer readable means 1030, a computer program 1020b can be stored, which computer program 1020b can cause the processing circuitry 810 and thereto operatively coupled entities and devices, such as the communications interface 820 and the storage medium 830, to execute methods according to embodiments described herein. The computer program 1020b and / or computer program product 1010b may thus provide means for performing any steps of the first access network node 140a, 800 as herein disclosed. On this computer readable means 1030, a computer program 1020c can be stored, which computer program 1020c can cause the processing circuitry 910 and thereto operatively coupled entities and devices, such as the communications interface 920 and the storage medium 930, to execute methods according to embodiments described herein. The computer program 1020c and / or computer program product 1010c may thus provide means for performing any steps of the second access network node 140b, 900 as herein disclosed.
[0163] In the example of Fig. 10, the computer program product 1010a, 1010b, 1010c is illustrated as an optical disc, such as a CD (compact disc) or a DVD (digital versatile disc) or a Blu-Ray disc. The computer program product 1010a, 1010b, 1010c could also be embodied as a memory, such as a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or an electrically erasable programmable read-only memory (EEPROM) and more particularly as a non-volatile storage medium of a device in an external memory such as a USB (Universal Serial Bus) memory or a Flash memory, such as a compact Flash memory. Thus, while the computer program 1020a, 1020b, 1020c is here schematically shown as a track on the depicted optical disk, the computer program 1020a, 1020b, 1020c can be stored in any way which is suitable for the computer program product 1010a, 1010b, 1010c.
[0164] The inventive concept has mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the inventive concept, as defined by the appended patent claims.
Claims
Claims1. A method for secure handling of network Quality of Experience, QoE, configuration parameters in a network (too), wherein the method is performed by a mobility management node (no, 700), and wherein the method comprises: receiving (S102) a request from a second access network node (140b, 900) for key material for the second access network node (140b, 900) to process security protected network QoE configuration parameters; verifying (S106) whether the second access network node (140b, 900) fulfils a policy condition or not; and transmitting (S108) the key material to the second access network node (140b, 900) only when the second access network node (140b, 900) fulfils the policy condition.
2. The method according to claim 1, wherein the request comprises an identifier of, or for, one or more of: the second access network node (140b, 900), a first access network node (140a, 800), a user equipment, UE (150).
3. The method according to claim 1 or 2, wherein the method further comprises: generating (S104) the key material.
4. The method according to claim 3, wherein the key material is generated in dependence of an identifier of, or for, one or more of: a user equipment, UE (150), the second access network node (140b, 900), a first access network node (140a, 800).
5. The method according to any of claims 1-4, wherein the mobility management node (110, 700) has access to a mapping between key material and scopes, where each of the scopes is associated with its own key material.
6. The method according to claim 5, wherein the network QoE configuration parameters are associated with one or more of the scopes.
7. The method according to claim 6, wherein the second access network node (140b, 900) fulfils the policy condition in case the second access network node (140b, 900) belongs to said one or more of the scopes.
8. The method according to claim 6 or 7, wherein the method further comprises: transmitting (S110) the key material and / or the security protected network QoE configuration parameters to a first access network node (140a, 800) belonging to said one of the scopes.
9. The method according to any of claims 1-8, wherein the key material is transmitted using NGAP Initial Context Setup Request / Response messaging.
10. The method according to any of claims 1-9, wherein the method further comprises: receiving (S112) the security protected network QoE configuration parameters from a user equipment, UE (150).
11. The method according to any of claims 1-10, wherein the network QoE configuration parameters at least pertain to any, or any combination of: measurement collector entity information, Minimization of Drive Tests, MDT, alignment information, QoE measurement type.
12. A method for secure handling of network Quality of Experience, QoE, configuration parameters in a network (100), wherein the method is performed by a first access network node (140a, 800), and wherein the method comprises: obtaining (S202) key material; obtaining (S204) network QoE configuration parameters; security protecting (S208) the network QoE configuration parameters using the key material; andtransmitting (S210) the security protected network QoE configuration parameters to one of the UEs (150) served by the first access network node (140a, 800).
13. The method according to claim 12, wherein the method further comprises: enforcing (S206), using the network QoE configuration parameters, traffic management of a user equipment, UE (150), served by the first access network node (140a, 800).
14. The method according to claim 12 or 13, wherein the key material and the network QoE configuration parameters are obtained from a mobility management node (110, 700).
15. The method according to any of claims 12-14, wherein the network QoE configuration parameters comprise at least some first type of parameters and at least some second type of parameters, and wherein the method further comprises: separately (S208-2) security protecting only one of the first type and the second type of parameters using a separate key material before security protecting the network QoE configuration parameters using the key material.
16. The method according to any of claims 12-15, wherein the security protected network QoE configuration parameters are transmitted using RRC reconfiguration signaling.
17. The method according to any of claims 12-15, wherein the first access network node (140a) adds a timestamp, or a counter value, to the network QoE configuration parameters before encryption.
18. A method for secure handling of network Quality of Experience, QoE, configuration parameters in a network (100), wherein the method is performed by a second access network node (140b, 900), and wherein the method comprises: obtaining (S302) key material;obtaining (S304) security protected network QoE configuration parameters from a user equipment, UE (150), served by the second access network node (140b, 900); and obtaining (S306) the network QoE configuration parameters by processing the security protected network QoE configuration parameters using the key material.
19. The method according to claim 18, wherein the method further comprises: enforcing (S308), using the network QoE configuration parameters, traffic management of a UE (150) served by the second access network node (140b, 900).
20. The method according to claim 18 or 19, wherein the key material is obtained from a mobility management node (110, 700).
21. The method according to claim 20, wherein the method further comprises: forwarding (S310) the security protected network QoE configuration parameters to the mobility management node (110, 700).
22. The method according to claim 21, wherein the security protected network QoE configuration parameters are forwarded using NGAP Initial Context Setup Request / Response messaging.
23. The method according to any of claims 18-22, wherein the security protected network QoE configuration parameters are obtained from the UE using RRC reconfiguration signaling.
24. The method according to any of claims 18-23, wherein the security protected network QoE configuration parameters comprise at least some first type parameters and at least some second type parameters, and wherein the method further comprises: separately (S306-2) processing one of the first type and the second type of parameters using a separate key material to obtain the first type or the second type ofparameters after having processed the security protected network QoE configuration parameters using the key material.
25. The method according to any of claims 18-24, wherein the security protected network QoE configuration parameters comprise a timestamp, or a counter value, and wherein the second access network node (140b) verifies freshness of the timestamp, or the counter value, after having processed the security protected network QoE configuration parameters using the key material.
26. A mobility management node (110, 700) for secure handling of network QoE configuration parameters in a network (100), the mobility management node (110, 700) comprising processing circuitry (710), the processing circuitry being configured to cause the mobility management node (110, 700) to: receive a request from a second access network node (140b, 900) for key material for the second access network node (140b, 900) to process security protected network QoE configuration parameters; verify whether the second access network node (140b, 900) fulfils a policy condition or not; and transmit the key material to the second access network node (140b, 900) only when the second access network node (140b, 900) fulfils the policy condition.
27. A first access network node (140a, 800) for secure handling of network QoE configuration parameters in a network (100), the first access network node (140a, 800) comprising processing circuitry (810), the processing circuitry being configured to cause the first access network node (140a, 800) to: obtain key material; obtain network QoE configuration parameters; security protect the network QoE configuration parameters using the key material; andtransmit the security protected network QoE configuration parameters to one of the UEs (150) served by the first access network node (140a, 800).
28. A second access network node (140b, 900) for secure handling of network QoE configuration parameters in a network (100), the second access network node (140b, 900) comprising processing circuitry (910), the processing circuitry being configured to cause the second access network node (140b, 900) to: obtain key material; obtain security protected network QoE configuration parameters from a user equipment, UE (150), served by the second access network node (140b, 900); and obtain the network QoE configuration parameters by processing the security protected network QoE configuration parameters using the key material.
29. A computer program (1020a) for secure handling of network QoE configuration parameters in a network (100), the computer program comprising computer code which, when run on processing circuitry (710) of a mobility management node (110, 700), causes the mobility management node (110, 700) to: receive (S102) a request from a second access network node (140b, 900) for key material for the second access network node (140b, 900) to process security protected network QoE configuration parameters; verify (S104) whether the second access network node (140b, 900) fulfils a policy condition or not; and transmit (S108) the key material to the second access network node (140b, 900) only when the second access network node (140b, 900) fulfils the policy condition.
30. A computer program (1020b) for secure handling of network QoE configuration parameters in a network (100), the computer program comprising computer code which, when run on processing circuitry (810) of a first access network node (140a, 800), causes the first access network node (140a, 800) to:obtain (S202) key material; obtain (S204) network QoE configuration parameters; security protect (S208) the network QoE configuration parameters using the key material; and transmit (S210) the security protected network QoE configuration parameters to one of the UEs (150) served by the first access network node (140a, 800).
31. A computer program (1020c) for secure handling of network QoE configuration parameters in a network (100), the computer program comprising computer code which, when run on processing circuitry (910) of a second access network node (140b, 900), causes the second access network node (140b, 900) to: obtain (S302) key material; obtain (S304) security protected network QoE configuration parameters from a user equipment, UE (150), served by the second access network node (140b, 900); and obtain (S306) the network QoE configuration parameters by processing the security protected network QoE configuration parameters using the key material.
32. A computer program product (1010a, 1010b, 1010c) comprising a computer program (1020a, 1020b, 1020c) according to at least one of claims 29, 30, and 31, and a computer readable storage medium (1030) on which the computer program is stored.
Citation Information
Patent Citations
Systems and method for secure updates of configuration parameters provisioned in user equipment
US20210160691A1
Configuring quality of experience measurements
WO2023156915A1