Methods for enhancements on message coding in secured communication session over non-3GPP access
By using separate indications in EAP response/5G-NAS messages to signal the presence or absence of access network parameters, the proposed solution addresses decoding errors and repeated AMF selection, enhancing message coding efficiency in secured communication sessions over non-3GPP access.
Patent Information
- Application Number
- PCT/CN2025/087674
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-19
- Filing Date
- 2025-04-08
- Publication Date
- 2025-10-23
AI Technical Summary
Existing 3GPP standards require UE to include access network parameters in all EAP-Response/5G-NAS messages, leading to issues such as decoding errors or repeated AMF selection, even when these parameters are not needed, due to undefined optional fields.
Implementing schemes that use separate indications in EAP response/5G-NAS messages to signal the presence or absence of AN-parameters and extended-AN-parameters fields, using length fields set to zero for absence and non-zero for presence, to reduce unnecessary signaling and ensure proper decoding.
This approach reduces overheads and ensures normal UE and network operations by clearly indicating the absence of unnecessary parameters, preventing decoding errors and repeated AMF selection.
Smart Images

Figure CN2025087674_23102025_PF_FP_ABST
Abstract
Description
METHODS FOR ENHANCEMENTS ON MESSAGE CODING IN SECURED COMMUNICATION SESSION OVER NON-3GPP ACCESSCROSS REFERENCE TO RELATED PATENT APPLICATION (S)
[0001] The present disclosure is part of a non-provisional application claiming the priority benefit of U.S. Patent Application No. 63 / 636,162, filed 19 April 2024, the content of which herein being incorporated by reference in its entirety.TECHNICAL FIELD
[0002] The present disclosure is generally related to mobile communications and, more particularly, to enhancements on message coding in secured communication session over non-third generation partnership project (3GPP) access.BACKGROUND
[0003] Unless otherwise indicated herein, approaches described in this section are not prior art to the claims listed below and are not admitted as prior art by inclusion in this section.
[0004] A public land mobile network (PLMN) is a network established and operated by an administration or recognized operating agency (ROA) for the specific purpose of providing land mobile communication services to the public. As compared to PLMN, a non-public network (NPN) is a network for non-public use. An NPN is either a stand-alone NPN (SNPN) , i.e., operated by an NPN operator and not relying on network functions provided by a PLMN, or a public network integrated NPN (PNI-NPN) , i.e., an NPN deployed with the support of a PLMN. One PLMN / SNPN may include multiple radio access networks (RANs) utilizing different radio access technologies (RATs) for accessing mobile services. RAN is part of a mobile communication system, which implements a radio access technology. Conceptually, RAN resides between a mobile device and provides connection with its core network (CN) . Depending on the 3rd Generation Partnership Project (3GPP) standards, mobile phones and other mobile devices are varyingly known as user equipment (UE) , terminal equipment (TE) , mobile stations (MS) , or mobile termination (MT) , etc. Examples of different RATs include 2nd generation (2G) Global System for Mobile Communications (GSM) , 3rd generation (3G) Universal Mobile Telecommunications System (UMTS) , 4th generation (4G) Long Term Evolution (LTE) , 5th generation (5G) New Radio (NR) , and other non-3GPP access RAT including Wireless Fidelity (Wi-Fi) .
[0005] For access diversity, a 5G core (5GC) network may support the connectivity of the UE via non-3GPP access networks. These non-3GPP access networks may be trusted non-3GPP access networks, untrusted non-3GPP access networks, or wireline access networks. A trusted or untrusted non-3GPP access network may advertise the PLMNs / SNPNs for which it supports trusted connectivity and the type of supported trusted connectivity. Different types of trusted connectivity may be advertised so that the UE may discover the non-3GPP access networks that can provide trusted connectivity to one or more PLMNs / SNPNs. For example, a secured communication session may utilize a vendor-specific extensible authentication protocol (EAP) method (e.g., EAP-5G method) to encapsulate non-access stratum (NAS) messages between the UE and the non-3GPP interworking function (N3IWF) in the 5G network.
[0006] When a UE is trying to register with a 5G network via non-3GPP access, the UE would be asked to send certain parameters (e.g., access network (AN) -parameters, and / or extended-AN parameters) to the 5G network to assist with operations (e.g., access and mobility management function (AMF) selection) related to the registration. The messages containing these parameters will be encoded (by UE) and decoding (by 5G network) in the EAP-5G session over non-3GPP access. Since these parameters are used to establish connection with the 5G network, it may not be necessary to include these parameters in all the exchange messages after the UE has accessed the 5G network. However, in the 3GPP standards, these parameters are not defined as optional, causing the UE to always include them in the following EAP-Response / 5G-NAS messages even though they are actually not needed anymore. This may result in some issues in UE and network operations. For example, if the UE chooses to encode insignificant bits (e.g., all 0’s) for these parameters in the following EAP-Response / 5G-NAS messages, the N3IWF may consider the insignificant bits as an error when decoding these parameters. Otherwise, if the UE chooses to encode the same content as used in initial registration for these parameters in the following EAP-Response / 5G-NAS messages, receiving the same content of these parameters at the N3IWF may trigger repeated AMF selection, which would be detrimental to network operations. Furthermore, if the UE wishes to not include / encode these parameters in the following EAP-Response / 5G-NAS messages, it is unclear regarding how and when to indicate the absence of these parameters.
[0007] Therefore, there is a need to provide proper schemes to address these issues.SUMMARY
[0008] The following summary is illustrative only and is not intended to be limiting in any way. That is, the following summary is provided to introduce concepts, highlights, benefits and advantages of the novel and non-obvious techniques described herein. Select implementations are further described below in the detailed description. Thus, the following summary is not intended to identify essential features of the claimed subject matter, nor is it intended for use in determining the scope of the claimed subject matter.
[0009] One objective of the present disclosure is proposing schemes, concepts, designs, systems, methods and apparatus pertaining to enhancements on message coding in secured communication session over non-3GPP access. It is believed that the above-described issues would be avoided or otherwise alleviated by implementing one or more of the proposed schemes described herein.
[0010] In one aspect, a method may involve an apparatus connecting to a non-3GPP access network. The method may also involve the apparatus receiving an internet key exchange (IKE) authentication response message from a network node in a 3GPP network via the non-3GPP access network. The method may also involve the apparatus transmitting an IKE authentication request message to the network node in the 3GPP network via the non-3GPP access network. The IKE authentication request message may comprise an EAP response or a 5G NAS message which comprises a first indication of whether an AN-parameters field is absent or present in the EAP response or the 5G NAS message.
[0011] In one aspect, a method may involve a network node in a 3GPP network, transmitting an IKE authentication response message to an apparatus via a non-3GPP access network. The method may also involve the network node receiving an IKE authentication request message from the apparatus via the non-3GPP access network. The IKE authentication request message may comprise an EAP response or a 5G NAS message which comprises a first indication of whether an AN-parameters field is absent or present in the EAP response or the 5G NAS message. The method may also involve the network node decoding the EAP response or the 5G NAS message based on the first indication.
[0012] It is noteworthy that, although description provided herein may be in the context of certain radio access technologies, networks and network topologies such as LTE, LTE-Advanced, LTE-Advanced Pro, 5G, NR, Internet-of-Things (IoT) and Narrow Band Internet of Things (NB-IoT) , Industrial Internet of Things (IIoT) , beyond 5G (B5G) , and 6th Generation (6G) , the proposed concepts, schemes and any variation (s) / derivative (s) thereof may be implemented in, for and by other types of radio access technologies, networks and network topologies. Thus, the scope of the present disclosure is not limited to the examples described herein.BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The accompanying drawings are included to provide a further understanding of the disclosure and are incorporated in and constitute a part of the present disclosure. The drawings illustrate implementations of the disclosure and, together with the description, serve to explain the principles of the disclosure. It is appreciable that the drawings are not necessarily in scale as some components may be shown to be out of proportion than the size in actual implementation in order to clearly illustrate the concept of the present disclosure.
[0014] FIG. 1 is a diagram depicting an example scenario of a communication environment in which various solutions and schemes in accordance with the present disclosure may be implemented.
[0015] FIGs. 2A and 2B show a diagram depicting an example scenario of the registration procedure via an untrusted non-3GPP access network in accordance with an implementation of the present disclosure.
[0016] FIG. 3 is a diagram depicting an example scenario of the message format of an EAP-Response / 5G-NAS message in accordance with an implementation of the present disclosure.
[0017] FIG. 4 is a block diagram of an example communication system in accordance with an implementation of the present disclosure.
[0018] FIG. 5 is a flowchart of an example process in accordance with an implementation of the present disclosure.
[0019] FIG. 6 is a flowchart of another example process in accordance with an implementation of the present disclosure. DETAILED DESCRIPTION OF PREFERRED IMPLEMENTATIONS
[0020] Detailed embodiments and implementations of the claimed subject matters are disclosed herein. However, it shall be understood that the disclosed embodiments and implementations are merely illustrative of the claimed subject matters which may be embodied in various forms. The present disclosure may, however, be embodied in many different forms and should not be construed as limited to the exemplary embodiments and implementations set forth herein. Rather, these exemplary embodiments and implementations are provided so that description of the present disclosure is thorough and complete and will fully convey the scope of the present disclosure to those skilled in the art. In the description below, details of well-known features and techniques may be omitted to avoid unnecessarily obscuring the presented embodiments and implementations. Overview
[0021] Implementations in accordance with the present disclosure relate to various techniques, methods, schemes and / or solutions pertaining to enhancements on message coding in secured communication session over non-3GPP access. According to the present disclosure, a number of possible solutions may be implemented separately or jointly. That is, although these possible solutions may be described below separately, two or more of these possible solutions may be implemented in one combination or another.
[0022] In 3GPP Release 15 / 16 / 17 / 18, the AN-parameters field contains access network parameters used to establish connection. More specifically, the access network parameters contain information that is used by the N3IWF for selecting an AMF in the 5GC network, and the information includes a globally unique AMF identity (GUAMI) , a selected public land mobile network (PLMN) identity (ID) , a requested network slice selection assistance information (NSSAI) , an establishment cause, and a selected network identifier (NID) if the UE is accessing SNPN services via a PLMN. Additionally, or optionally, the extended-AN-parameters field is used after Release 17 only when at least one access network parameter is longer than 255 octets. However, both the AN-parameters field and the extended-AN-parameters field are not defined as optional, causing the UE to always include them in EAP-Response / 5G-NAS messages even though they are actually not needed (e.g., after the UE has accessed the 5G network) . This may result in some issues in UE and network operations. For example, if the UE chooses to encode insignificant bits (e.g., all 0’s) for these parameters in the following EAP-Response / 5G-NAS messages, the N3IWF in the 5G network may consider the insignificant bits as an error when decoding these parameters. Otherwise, if the UE chooses to encode the same content as used in initial registration for these parameters in the following EAP-Response / 5G-NAS messages, receiving the same content of these parameters at the N3IWF may trigger repeated AMF selection, which would be detrimental to network operations. Furthermore, if the UE chooses to not include / encode these parameters in the following EAP-Response / 5G-NAS messages, it is unclear regarding how and when to indicate that the absence of these parameters.
[0023] In view of the above, the present disclosure proposes a number of schemes pertaining to enhancements on message coding in secured communication session (e.g., EAP-5G session) over non-3GPP access. According to the schemes of the present disclosure, an EAP response / 5G-NAS message may include separate indications of whether the AN-parameters field is absent or present and whether the extended-AN-parameters field is absent or present in the EAP response or the 5G NAS message. In one example, the AN-parameters length field and the extended-AN-parameters length field are reused as such indications. Specifically, the AN-parameters length is set to a zero value to indicate that the AN-parameters field is absent, or is set to a non-zero value to indicate that the AN-parameters field is present. Similarly, the extended-AN-parameters length is set to a zero value to indicate that the extended-AN-parameters field is absent, or is set to a non-zero value to indicate that the extended-AN-parameters field is present. Accordingly, by applying the schemes of the present disclosure, the overheads related to signaling and encoding / decoding of unnecessary access network parameters in EAP-Response / 5G-NAS messages may be reduced, while ensuring normal UE and network operations.
[0024] FIG. 1 illustrates an example scenario 100 of a communication environment in which various solutions and schemes in accordance with the present disclosure may be implemented. Scenario 100 involves a UE 110 in wireless communication with a network 120 (e.g., a wireless network including a non-terrestrial network (NTN) and a TN) over a 3GPP access 122 and / or a non-3GPP access 130. The 3GPP access 122 may be provided by a base station (BS) (e.g., a Next Generation Node-B (gNB) and / or a transmission / reception point (TRP) ) or a satellite of the network 120. The non-3GPP access 130 may be provided by a Wi-Fi access point (AP) connected to the Internet. The network 120 may belong to a PLMN or an SNPN. In one example, interworking between the non-3GPP access 130 and the network 120 (e.g., a 5G system (5GS) ) may be supported through a Y2 interface connecting the non-3GPP access 130 to a network node (e.g., an N3IWF) in the network 120. In such communication environment, the UE 110, the network 120, and the network node (s) of the 3GPP access 122 and / or the non-3GPP access 130 may implement various schemes pertaining to enhancements on message coding in secured communication session (e.g., EAP-5G session) over non-3GPP access in accordance with the present disclosure, as described below. It is noteworthy that, while the various proposed schemes may be individually or separately described below, in actual implementations some or all of the proposed schemes may be utilized or otherwise implemented jointly. Of course, each of the proposed schemes may be utilized or otherwise implemented individually or separately.
[0025] FIGs. 2A and 2B illustrate an example scenario 200 of the registration procedure via an untrusted non-3GPP access network in accordance with an implementation of the present disclosure. In step 201a, the UE connects to an untrusted non-3GPP access network with any appropriate authentication procedure and it is assigned an IP address. For example, a non-3GPP authentication method can be used, e.g. no authentication (in the case of a free WLAN) , EAP with pre-shared key, username / password, etc. In step 201b, when the UE decides to attach to a 5GC network, the UE selects an N3IWF in a 5G PLMN or in an SNPN, depending on whether the UE is operating in SNPN access mode or not. For example, the UE not operating in SNPN access mode for NWu interface may select an N3IWF in a 5G PLMN, or the UE operating in SNPN access mode for NWu interface may select an N3IWF in an SNPN. In step 202, the UE proceeds with the establishment of an IPsec security association (SA) with the selected N3IWF by initiating an IKE initial exchange. It is noteworthy that after step 202, all subsequent IKE messages are encrypted and integrity protected by using the IKE SA established in step 202. In step 203, the UE initiates an IKE_AUTH exchange by sending an IKE_AUTH request message containing the UE ID to the N3IWF. Specifically, the authentication payload (denoted as AUTH in FIG. 2A) is not included in the IKE_AUTH request message, which indicates that the IKE_AUTH exchange shall use EAP signaling (i.e., EAP-5G signaling) . In step 204, the N3IWF responds with an IKE_AUTH response message, which includes an EAP-Request / 5G-Start packet. The EAP-Request / 5G-Start packet informs the UE to initiate an EAP-5G session, i.e. to start sending NAS messages encapsulated within EAP-5G packets. In step 205, the UE sends an IKE_AUTH request, which includes an EAP-Response / 5G-NAS packet that contains the AN parameters and a Registration Request message (encoded in a NAS-protocol data unit (PDU) ) . Specifically, the AN parameters contain information that is used by the N3IWF for selecting an AMF in the 5GC network, and this information may include at least one of the following: (i) the GUAMI, (ii) the selected PLMN ID (or PLMN ID and NID) , (iii) the requested NSSAI, and (iv) the establishment cause. The establishment cause provides the reason for requesting a signaling connection with 5GC. In step 206a, the N3IWF selects an AMF based on the received AN parameters and local policy. Then, in step 206b, the N3IWF forwards the Registration Request received from the UE to the selected AMF within an N2 message containing N2 parameters that include the selected PLMN ID and optionally the selected NID and the establishment cause.
[0026] Subsequently, and optionally, in steps 207a-207b, the selected AMF may decide to request the subscription concealed identifier (SUCI) or subscription permanent identifier (SUPI) by sending a NAS Identity Request message to the UE. This NAS message and all subsequent NAS messages are sent to UE encapsulated within EAP / 5G-NAS packets. Additionally, or optionally, in steps 208a-208h, the AMF may decide to authenticate the UE by invoking an authentication server function (AUSF) . Specifically, the AUSF may execute the authentication of the UE, e.g., by selecting a unified data management (UDM) and obtaining the authentication data from the UDM. The authentication packets may be encapsulated within NAS authentication messages, and the NAS authentication messages may be encapsulated within EAP / 5G-NAS packets. After the successful authentication, in step 208h, the AUSF may send the anchor key (denoted as SEAF key in FIG. 2B) to the AMF, which is used by the AMF to derive NAS security keys and a security key for N3IWF (or called N3IWF key) . The UE may also derive the anchor key (SEAF key) , and from that key, it may derive the NAS security keys and the N3IWF key. The N3IWF key is used by the UE and the N3IWF for establishing the IPsec SA.
[0027] Then, in step 209a, the AMF sends a NAS Security Mode Command to the UE to activate NAS security. In one example, if an EAP-AKA' authentication was successfully executed in steps 208a-208h, the AMF may encapsulate the EAP-Success received from the AUSF within the NAS Security Mode Command message. In step 209b, the N3IWF forwards the NAS Security Mode Command message to the UE within an EAP / 5G-NAS packet. In step 209c, the UE completes the EAP-AKA' authentication (if initiated in steps 208a-208h) , creates a NAS security context and an N3IWF key, and sends the NAS Security Mode Complete message within an EAP / 5G-NAS packet. In step 209d, the N3IWF relays the NAS Security Mode Complete message to the AMF. In step 210a, upon receiving the NAS Security Mode Complete, the AMF sends an Initial Context Setup Request message (using next generation application protocol (NGAP) ) that includes the N3IWF key to the N3IWF. In step 210b, the Initial Context Setup Request message triggers the N3IWF to send an EAP-Success to the UE, which completes the EAP-5G session. No further EAP-5G packets are exchanged. In steps 211a-211b, the IPsec SA is established between the UE and the N3IWF by using the common N3IWF key that was created in the UE in step 209c and received by the N3IWF in step 210a. This IPsec SA is referred to as the "signaling IPsec SA" . After the establishment of the signaling IPsec SA, the N3IWF notifies the AMF that the UE context (including AN security) was created by sending an Initial Context Setup Response (using NGAP) . All subsequent NAS messages exchanged between the UE and the N3IWF are sent via the signaling IPsec SA and carried over TCP / IP.
[0028] Next, in step 212, the AMF determines the allowed subset of the requested NSSAI that is allowed by the subscribed S-NSSAI (s) , and by doing so, the AMF may detect that the N3IWF used by the UE is not compatible with this allowed subset and based on operator's policy configured in the AMF, and then the AMF may determine whether a different N3IWF should be used. In step 213, the AMF sends the NAS Registration Accept / Reject message (depending on the determination result in step 212) in an N2 message to the N3IWF. If it’s the NAS Registration Accept message sent in an N2 message, this N2 message may include the Allowed NSSAI (i.e., a subset of the slices supported by the selected N3IWF) for the access type for the UE. Otherwise, if it’s the NAS Registration Reject message sent in an N2 message, the AMF may optionally provide target N3IWF information (e.g., fully-qualified domain name (FQDN) and / or IP address) to the UE within the Registration Reject message. In step 214, the N3IWF forwards the NAS Registration Accept / Reject message to the UE via the established signaling IPsec SA.
[0029] It is noteworthy that, in the signaling flow of the registration procedure shown in FIGs. 2A and 2B, only the EAP-Response / 5G-NAS in the IKE_AUTH request in step 205 includes the AN parameters, and the following EAP-Response / 5G-NAS messages do not include the AN parameters anymore.
[0030] FIG. 3 illustrates an example scenario 300 of the message format of an EAP-Response / 5G-NAS message in accordance with an implementation of the present disclosure. As shown in FIG. 3, an EAP-Response / 5G-NAS message may include multiple fields, including a code field, an identifier field, a length field, a type field, a vendor-Id field, a vendor-Type field, a message-Id field, a spare field, an AN-parameters length field, an AN-parameters field, a NAS-PDU length field, a NAS-PDU field, an extended-AN-parameters length field, an extended-AN-parameters field, and an extensions field. In particular, the octets of the AN-parameters field, the extended-AN-parameters length field, the extended-AN-parameters field, and the extensions field are marked with star signs, which means that these 4 fields are defined as optional. Specifically, the AN-parameters length field indicates the length of the AN-parameters field in octets. If the AN-parameters length field is set to a zero value, the AN-parameters field is absent. Otherwise, if the AN-parameters length field is set to a non-zero value, the AN-parameters field is present. The extended-AN-parameters length field indicates the length of the extended-AN-parameters field in octets. The extended-AN-parameters length field is present if the EAP-Response / 5G-NAS message is at least (y+n+1) octets long. If the extended-AN-parameters length field is set to a zero value, the extended-AN-parameters field is absent. Otherwise, if the extended-AN-parameters length field is set to a non-zero value, the extended-AN-parameters field is present. Lastly, the extensions field is an optional field and consists of spare bits. The sending entity shall not include the extensions field. Illustrative Implementations
[0031] FIG. 4 illustrates an example communication system 400 having an example communication apparatus 410 and an example network apparatus 420 in accordance with an implementation of the present disclosure. Each of communication apparatus 410 and network apparatus 420 may perform various functions to implement schemes, techniques, processes and methods described herein pertaining to enhancements on message coding in secured communication session over non-3GPP access, including scenarios / schemes described above as well as processes 500 and 600 described below.
[0032] Communication apparatus 410 may be a part of an electronic apparatus, which may be a UE such as a portable or mobile apparatus, a wearable apparatus, a wireless communication apparatus or a computing apparatus. For instance, communication apparatus 410 may be implemented in a smartphone, a smartwatch, a personal digital assistant, an electronic control unit (ECU) in a vehicle, a digital camera, or a computing equipment such as a tablet computer, a laptop computer or a notebook computer. Communication apparatus 410 may also be a part of a machine type apparatus, which may be an IoT, NB-IoT, IIoT, BL, or CE UE such as an immobile or a stationary apparatus, a home apparatus, a roadside unit (RSU) , a wire communication apparatus or a computing apparatus. For instance, communication apparatus 410 may be implemented in a smart thermostat, a smart fridge, a smart door lock, a wireless speaker or a home control center. Alternatively, communication apparatus 410 may be implemented in the form of one or more integrated-circuit (IC) chips such as, for example and without limitation, one or more single-core processors, one or more multi-core processors, one or more reduced-instruction set computing (RISC) processors, or one or more complex-instruction-set-computing (CISC) processors. Communication apparatus 410 may include at least some of those components shown in FIG. 4 such as a processor 412, for example. Communication apparatus 410 may further include one or more other components not pertinent to the proposed scheme of the present disclosure (e.g., internal power supply, display device and / or user interface device) , and, thus, such component (s) of communication apparatus 410 are neither shown in FIG. 4 nor described below in the interest of simplicity and brevity.
[0033] Network apparatus 420 may be a part of an electronic apparatus, which may be a network node such as a network node (e.g., an N3IWF) in a wireless network (e.g., a 5G / B5G / 6G, NR, IoT, NB-IoT, IIoT, or NTN network) , connecting communication apparatus 410 to the core network (e.g., a 5GC) of the wireless network. For instance, network apparatus 420 may be implemented in the form of one or more IC chips such as, for example and without limitation, one or more single-core processors, one or more multi-core processors, or one or more RISC or CISC processors. Network apparatus 420 may include at least some of those components shown in FIG. 4 such as a processor 422, for example. Network apparatus 420 may further include one or more other components not pertinent to the proposed scheme of the present disclosure (e.g., internal power supply, display device and / or user interface device) , and, thus, such component (s) of network apparatus 420 are neither shown in FIG. 4 nor described below in the interest of simplicity and brevity.
[0034] In one aspect, each of processor 412 and processor 422 may be implemented in the form of one or more single-core processors, one or more multi-core processors, or one or more CISC processors. That is, even though a singular term “aprocessor” is used herein to refer to processor 412 and processor 422, each of processor 412 and processor 422 may include multiple processors in some implementations and a single processor in other implementations in accordance with the present disclosure. In another aspect, each of processor 412 and processor 422 may be implemented in the form of hardware (and, optionally, firmware) with electronic components including, for example and without limitation, one or more transistors, one or more diodes, one or more capacitors, one or more resistors, one or more inductors, one or more memristors and / or one or more varactors that are configured and arranged to achieve specific purposes in accordance with the present disclosure. In other words, in at least some implementations, each of processor 412 and processor 422 is a special-purpose machine specifically designed, arranged and configured to perform specific tasks, including enhancements on message coding in secured communication session over non-3GPP access, in a UE (e.g., as represented by communication apparatus 410) and a network node (e.g., as represented by network apparatus 420) in accordance with various implementations of the present disclosure.
[0035] In some implementations, communication apparatus 410 may also include a transceiver 416 coupled to processor 412 and capable of wirelessly transmitting and receiving data. In some implementations, transceiver 416 may be capable of wirelessly communicating with different types of UEs and / or wireless networks of different RATs. In some implementations, transceiver 416 may be equipped with a plurality of antenna ports (not shown) such as, for example, four antenna ports. That is, transceiver 416 may be equipped with multiple transmit antennas and multiple receive antennas for multiple-input multiple-output (MIMO) wireless communications. In some implementations, network apparatus 420 may also include a transceiver 426 coupled to processor 422. Transceiver 426 may include a transceiver capable of wirelessly transmitting and receiving data. In some implementations, transceiver 426 may be capable of wirelessly communicating with different types of UEs of different RATs. In some implementations, transceiver 426 may be equipped with a plurality of antenna ports (not shown) such as, for example, four antenna ports. That is, transceiver 426 may be equipped with multiple transmit antennas and multiple receive antennas for MIMO wireless communications.
[0036] In some implementations, communication apparatus 410 may further include a memory 414 coupled to processor 412 and capable of being accessed by processor 412 and storing data therein. In some implementations, network apparatus 420 may further include a memory 424 coupled to processor 422 and capable of being accessed by processor 422 and storing data therein. Each of memory 414 and memory 424 may include a type of random-access memory (RAM) such as dynamic RAM (DRAM) , static RAM (SRAM) , thyristor RAM (T-RAM) and / or zero-capacitor RAM (Z-RAM) . Alternatively, or additionally, each of memory 414 and memory 424 may include a type of read-only memory (ROM) such as mask ROM, programmable ROM (PROM) , erasable programmable ROM (EPROM) and / or electrically erasable programmable ROM (EEPROM) . Alternatively, or additionally, each of memory 414 and memory 424 may include a type of non-volatile random-access memory (NVRAM) such as flash memory, solid-state memory, ferroelectric RAM (FeRAM) , magnetoresistive RAM (MRAM) and / or phase-change memory.
[0037] Each of communication apparatus 410 and network apparatus 420 may be a communication entity capable of communicating with each other using various proposed schemes in accordance with the present disclosure. For illustrative purposes and without limitation, a description of capabilities of communication apparatus 410, as a UE, and network apparatus 420, as a network node (e.g., N3IWF) , is provided below with processes 500 and 600. Illustrative Processes
[0038] FIG. 5 illustrates an example process 500 in accordance with an implementation of the present disclosure. Process 500 may be an example implementation of above scenarios / schemes, whether partially or completely, with respect to enhancements on message coding in secured communication session over non-3GPP access. Process 500 may represent an aspect of implementation of features of communication apparatus 410. Process 500 may include one or more operations, actions, or functions as illustrated by one or more of blocks 510 to 530. Although illustrated as discrete blocks, various blocks of process 500 may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the desired implementation. Moreover, the blocks of process 500 may be executed in the order shown in FIG. 5 or, alternatively, in a different order. Process 500 may be implemented by or in communication apparatus 410 or any suitable UE or machine type devices. Solely for illustrative purposes and without limitation, process 500 is described below in the context of communication apparatus 410, as a UE, and network apparatus 420, as a network node. Process 500 may begin at block 510.
[0039] At block 510, process 500 may involve processor 412 of communication apparatus 410, connecting, via transceiver 416, to a non-3GPP access network. Process 500 may proceed from block 510 to block 520.
[0040] At block 520, process 500 may involve processor 412 receiving, via transceiver 416, an IKE authentication response message from network apparatus 420 in a 3GPP network via the non-3GPP access network. Process 500 may proceed from block 520 to block 530.
[0041] At block 530, process 500 may involve processor 412 transmitting, via transceiver 416, an IKE authentication request message to network apparatus 420 in the 3GPP network via the non-3GPP access network, wherein the IKE authentication request message comprises an EAP response or a 5G NAS message which comprises a first indication of whether an AN-parameters field is absent or present in the EAP response or the 5G NAS message.
[0042] In some implementations, process 500 may further involve processor 412 determining not to encode the AN-parameters field in the EAP response or the 5G NAS message in an event that the first indication indicates that the AN-parameters field is absent, and encoding a field next to the AN-parameters field at an octet next to the first indication in the EAP response or the 5G NAS message.
[0043] In some implementations, the first indication may include an AN-parameters length which is set to a zero value to indicate that the AN-parameters field is absent, or is set to a non-zero value to indicate that the AN-parameters field is present.
[0044] In some implementations, the AN-parameters field may include at least one of the following access network parameters: (i) a GUAMI; (ii) a selected PLMN ID; (iii) a requested NSSAI; (iv) an establishment cause; and (v) a selected NID.
[0045] In some implementations, the EAP response or the 5G NAS message may further include a second indication of whether an extended-AN-parameters field is absent or present in the EAP response or the 5G NAS message.
[0046] In some implementations, the second indication may include an extended-AN-parameters length which is set to a zero value to indicate that the extended-AN-parameters field is absent, or is set to a non-zero value to indicate that the extended-AN-parameters field is present.
[0047] In some implementations, process 500 may further involve processor 412 determining not to encode the extended-AN-parameters field in the EAP response or the 5G NAS message in an event that the second indication indicates that the extended-AN-parameters field is absent, and encoding a field next to the extended-AN-parameters field at an octet next to the second indication in the EAP response or the 5G NAS message.
[0048] In some implementations, the IKE authentication request message may further include a NAS PDU, and the NAS PDU may include at least one of the following: (i) a registration request; (ii) an identity response; (iii) an authentication response; and (iv) a NAS security mode complete.
[0049] In some implementations, the IKE authentication response message may include at least one of an EAP request, an 5G NAS message, and an NAS PDU, and the NAS PDU may include at least one of the following: (i) an identity request; (ii) an authentication request; and (iii) a NAS security mode command.
[0050] In some implementations, network apparatus 420 may include an N3IWF.
[0051] FIG. 6 illustrates an example process 600 in accordance with an implementation of the present disclosure. Process 600 may be an example implementation of above scenarios / schemes, whether partially or completely, with respect to enhancements on message coding in secured communication session over non-3GPP access. Process 600 may represent an aspect of implementation of features of network apparatus 420. Process 600 may include one or more operations, actions, or functions as illustrated by one or more of blocks 610 to 630. Although illustrated as discrete blocks, various blocks of process 600 may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the desired implementation. Moreover, the blocks of process 600 may be executed in the order shown in FIG. 6 or, alternatively, in a different order. Process 600 may be implemented by or in network apparatus 420 as well as any variations thereof. Solely for illustrative purposes and without limitation, process 600 is described below in the context of communication apparatus 410, as a UE, and network apparatus 420, as a network node. Process 600 may begin at block 610.
[0052] At block 610, process 600 may involve processor 422 of network apparatus 420 in a 3GPP network, transmitting, via transceiver 426, an IKE authentication response message to communication apparatus 410 via a non-3GPP access network. Process 600 may proceed from block 610 to block 620.
[0053] At block 620, process 600 may involve processor 422 receiving, via transceiver 426, an IKE authentication request message from communication apparatus 410 via the non-3GPP access network, wherein the IKE authentication request message comprises an EAP response or a 5G NAS message which comprises a first indication of whether an AN-parameters field is absent or present in the EAP response or the 5G NAS message. Process 600 may proceed from block 620 to block 630.
[0054] At block 630, process 600 may involve processor 422 decoding the EAP response or the 5G NAS message based on the first indication.
[0055] In some implementations, the decoding of the EAP response or the 5G NAS message based on the first indication may include: determining not to decode the AN-parameters field in the EAP response or the 5G NAS message in an event that the first indication indicates that the AN-parameters field is absent, and decoding a field next to the AN-parameters field at an octet next to the first indication in the EAP response or the 5G NAS message.
[0056] In some implementations, the first indication may include an AN-parameters length which is set to a zero value to indicate that the AN-parameters field is absent, or is set to a non-zero value to indicate that the AN-parameters field is present.
[0057] In some implementations, the AN-parameters field may include at least one of the following access network parameters: (i) a GUAMI; (ii) a selected PLMN ID; (iii) a requested NSSAI; (iv) an establishment cause; and (v) a selected NID.
[0058] In some implementations, the EAP response or the 5G NAS message may further include a second indication of whether an extended-AN-parameters field is absent or present in the EAP response or the 5G NAS message.
[0059] In some implementations, the second indication may include an extended-AN-parameters length which is set to a zero value to indicate that the extended-AN-parameters field is absent, or is set to a non-zero value to indicate that the extended-AN-parameters field is present.
[0060] In some implementations, the decoding of the EAP response or the 5G NAS message may be performed based on the second indication.
[0061] In some implementations, the IKE authentication request message may further include a NAS PDU, and the NAS PDU may include at least one of the following: (i) a registration request; (ii) an identity response; (iii) an authentication response; and (iv) a NAS security mode complete.
[0062] In some implementations, the IKE authentication response message may include at least one of an EAP request, an 5G NAS message, and an NAS PDU, and the NAS PDU may include at least one of the following: (i) an identity request; (ii) an authentication request; and (iii) a NAS security mode command.
[0063] In some implementations, the network node may include an N3IWF. Additional Notes
[0064] The herein-described subject matter sometimes illustrates different components contained within, or connected with, different other components. It is to be understood that such depicted architectures are merely examples, and that in fact many other architectures can be implemented which achieve the same functionality. In a conceptual sense, any arrangement of components to achieve the same functionality is effectively "associated" such that the desired functionality is achieved. Hence, any two components herein combined to achieve a particular functionality can be seen as "associated with" each other such that the desired functionality is achieved, irrespective of architectures or intermedial components. Likewise, any two components so associated can also be viewed as being "operably connected" , or "operably coupled" , to each other to achieve the desired functionality, and any two components capable of being so associated can also be viewed as being "operably couplable" , to each other to achieve the desired functionality. Specific examples of operably couplable include but are not limited to physically mateable and / or physically interacting components and / or wirelessly interactable and / or wirelessly interacting components and / or logically interacting and / or logically interactable components.
[0065] Further, with respect to the use of substantially any plural and / or singular terms herein, those having skill in the art can translate from the plural to the singular and / or from the singular to the plural as is appropriate to the context and / or application. The various singular / plural permutations may be expressly set forth herein for sake of clarity.
[0066] Moreover, it will be understood by those skilled in the art that, in general, terms used herein, and especially in the appended claims, e.g., bodies of the appended claims, are generally intended as “open” terms, e.g., the term “including” should be interpreted as “including but not limited to, ” the term “having” should be interpreted as “having at least, ” the term “includes” should be interpreted as “includes but is not limited to, ” etc. It will be further understood by those within the art that if a specific number of an introduced claim recitation is intended, such an intent will be explicitly recited in the claim, and in the absence of such recitation no such intent is present. For example, as an aid to understanding, the following appended claims may contain usage of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed to imply that the introduction of a claim recitation by the indefinite articles "a" or "an" limits any particular claim containing such introduced claim recitation to implementations containing only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" and indefinite articles such as "a" or "an, " e.g., “a” and / or “an” should be interpreted to mean “at least one” or “one or more; ” the same holds true for the use of definite articles used to introduce claim recitations. In addition, even if a specific number of an introduced claim recitation is explicitly recited, those skilled in the art will recognize that such recitation should be interpreted to mean at least the recited number, e.g., the bare recitation of "two recitations, " without other modifiers, means at least two recitations, or two or more recitations. Furthermore, in those instances where a convention analogous to “at least one of A, B, and C, etc. ” is used, in general such a construction is intended in the sense one having skill in the art would understand the convention, e.g., “asystem having at least one of A, B, and C” would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. In those instances where a convention analogous to “at least one of A, B, or C, etc. ” is used, in general such a construction is intended in the sense one having skill in the art would understand the convention, e.g., “asystem having at least one of A, B, or C” would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. It will be further understood by those within the art that virtually any disjunctive word and / or phrase presenting two or more alternative terms, whether in the description, claims, or drawings, should be understood to contemplate the possibilities of including one of the terms, either of the terms, or both terms. For example, the phrase “A or B” will be understood to include the possibilities of “A” or “B” or “A and B. ”
[0067] From the foregoing, it will be appreciated that various implementations of the present disclosure have been described herein for purposes of illustration, and that various modifications may be made without departing from the scope and spirit of the present disclosure. Accordingly, the various implementations disclosed herein are not intended to be limiting, with the true scope and spirit being indicated by the following claims.
Claims
1.A method, comprising:connecting, by a processor of an apparatus, to a non-third generation partnership project (3GPP) access network;receiving, by the processor, an internet key exchange (IKE) authentication response message from a network node in a 3GPP network via the non-3GPP access network; andtransmitting, by the processor, an IKE authentication request message to the network node in the 3GPP network via the non-3GPP access network, wherein the IKE authentication request message comprises an extensible authentication protocol (EAP) response or a fifth generation (5G) non-access stratum (NAS) message which comprises a first indication of whether an access network (AN) -parameters field is absent or present in the EAP response or the 5G NAS message.2.The method of Claim 1, further comprising:determining, by the processor, not to encode the AN-parameters field in the EAP response or the 5G NAS message in an event that the first indication indicates that the AN-parameters field is absent; andencoding, by the processor, a field next to the AN-parameters field at an octet next to the first indication in the EAP response or the 5G NAS message.3.The method of Claim 1, wherein the first indication comprises an AN-parameters length which is set to a zero value to indicate that the AN-parameters field is absent, or is set to a non-zero value to indicate that the AN-parameters field is present.4.The method of Claim 1, wherein the AN-parameters field comprises at least one of the following access network parameters:a globally unique AMF identity (GUAMI) ;a selected public land mobile network (PLMN) identity (ID) ;a requested network slice selection assistance information (NSSAI) ;an establishment cause; anda selected network identifier (NID) .5.The method of Claim 1, wherein the EAP response or the 5G NAS message further comprises a second indication of whether an extended-AN-parameters field is absent or present in the EAP response or the 5G NAS message.6.The method of Claim 5, wherein the second indication comprises an extended-AN-parameters length which is set to a zero value to indicate that the extended-AN-parameters field is absent, or is set to a non-zero value to indicate that the extended-AN-parameters field is present.7.The method of Claim 5, further comprising:determining, by the processor, not to encode the extended-AN-parameters field in the EAP response or the 5G NAS message in an event that the second indication indicates that the extended-AN-parameters field is absent; andencoding, by the processor, a field next to the extended-AN-parameters field at an octet next to the second indication in the EAP response or the 5G NAS message.8.The method of Claim 1, wherein the IKE authentication request message further comprises a NAS protocol data unit (PDU) , and the NAS PDU comprises at least one of the following:a registration request;an identity response;an authentication response; anda NAS security mode complete.9.The method of Claim 1, wherein the IKE authentication response message comprises at least one of an EAP request, an 5G NAS message, and an NAS PDU, and the NAS PDU comprises at least one of the following:an identity request;an authentication request; anda NAS security mode command.10.The method of Claim 1, wherein the network node comprises a non-3GPP interworking function (N3IWF) .11.A method, comprising:transmitting, by a processor of a network node in a third generation partnership project (3GPP) network, an internet key exchange (IKE) authentication response message to an apparatus via a non-3GPP access network;receiving, by the processor, an IKE authentication request message from the apparatus via the non-3GPP access network, wherein the IKE authentication request message comprises an extensible authentication protocol (EAP) response or a fifth generation (5G) non-access stratum (NAS) message which comprises a first indication of whether an access network (AN) -parameters field is absent or present in the EAP response or the 5G NAS message; anddecoding, by the processor, the EAP response or the 5G NAS message based on the first indication.12.The method of Claim 11, wherein the decoding of the EAP response or the 5G NAS message based on the first indication comprises:determining not to decode the AN-parameters field in the EAP response or the 5G NAS message in an event that the first indication indicates that the AN-parameters field is absent; anddecoding a field next to the AN-parameters field at an octet next to the first indication in the EAP response or the 5G NAS message.13.The method of Claim 11, wherein the first indication comprises an AN-parameters length which is set to a zero value to indicate that the AN-parameters field is absent, or is set to a non-zero value to indicate that the AN-parameters field is present.14.The method of Claim 11, wherein the AN-parameters field comprises at least one of the following access network parameters:a globally unique AMF identity (GUAMI) ;a selected public land mobile network (PLMN) identity (ID) ;a requested network slice selection assistance information (NSSAI) ;an establishment cause; anda selected network identifier (NID) .15.The method of Claim 11, wherein the EAP response or the 5G NAS message further comprises a second indication of whether an extended-AN-parameters field is absent or present in the EAP response or the 5G NAS message.16.The method of Claim 15, wherein the second indication comprises an extended-AN-parameters length which is set to a zero value to indicate that the extended-AN-parameters field is absent, or is set to a non-zero value to indicate that the extended-AN-parameters field is present.17.The method of Claim 15, wherein the decoding of the EAP response or the 5G NAS message is performed based on the second indication.18.The method of Claim 11, wherein the IKE authentication request message further comprises a NAS protocol data unit (PDU) , and the NAS PDU comprises at least one of the following:a registration request;an identity response;an authentication response; anda NAS security mode complete.19.The method of Claim 11, wherein the IKE authentication response message comprises at least one of an EAP request, an 5G NAS message, and an NAS PDU, and the NAS PDU comprises at least one of the following:an identity request;an authentication request; anda NAS security mode command.20.The method of Claim 11, wherein the network node comprises a non-3GPP interworking function (N3IWF) .
Citation Information
Patent Citations
Method to authenticate with a mobile communication network
CN110603891A
Accessing a 5g network via a non-3gg access network
US20220039178A1
Network access authentication method based on non-3GPP network, and related device and system
WO2018170617A1
Notification in EAP procedure
WO2021204352A1