Security in a non-terrestrial communication network
By managing security associations based on predicted connectivity changes, the solution addresses the challenge of securing backhaul in NTN networks, ensuring continuous and secure communication.
Patent Information
- Application Number
- PCT/EP2025/060414
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-16
- Filing Date
- 2025-04-15
- Publication Date
- 2025-10-23
AI Technical Summary
Securing the backhaul in non-terrestrial communication networks (NTN) is challenging due to the dynamic environment caused by the movement of airborne or space-borne vehicles, which can disrupt IP connectivity and impact the lifetime and effectiveness of security associations.
A network node on-board the vehicle manages security associations proactively based on predicted availability or unavailability of network layer connectivity, using assistance information such as flight path and trajectory to anticipate and manage IKE and IPSec security associations.
This approach ensures graceful rekeying or tear down of security associations, maintaining secure communication despite changes in connectivity, thereby accommodating the dynamic environment of NTN deployments.
Smart Images

Figure EP2025060414_23102025_PF_FP_ABST
Abstract
Description
[0001] SECURITY IN A NON-TERRESTRIAL COMMUNICATION NETWORK
[0002] TECHNICAL FIELD
[0003] The present application relates generally to a non-terrestrial communication network, and relates more particularly to security in such a network.
[0004] BACKGROUND
[0005] Radio network nodes, such as eNodeB and gNodeB in 3GPP networks, are deployed in cell sites for terrestrial networks. Traditionally, the cell sites are in an untrusted domain from a security perspective. By contrast, the core network comprising data packet core, voice packet core, and circuit switched core is by design and deployment in a separate trust domain. These two domains communicate using protocols at the network layer, e.g., the two domains may be natively Internet Protocol (IP) based. The trust domains are logically and physically separated by means of security gateways (SEG), e.g., as specified by 3GPP TS 33.210 V18.0.0.
[0006] The communication and network management traffic between radio network node and the core network is transported over a logical connection called a 'backhaul'. The backhaul may be secured using one or more security associations between the radio network nodes and a SEG. The security association(s) may for example include Internet Key Exchanvge (IKE) Version 2 (IKEv2) and IP Security (IPSec) Security Associations (SAs). The security association(s) may provide mutual authentication, confidentiality, integrity, antireplay, and / or topology hiding (e.g., core network topology is hidden behind SEG from the access network point of view). In some cases, then, an IKEv2 and IPsec based tunnel may run on underlying IP connectivity.
[0007] The ground based terrestrial network nodes and the SEG benefit from wired fiber based physical connectivity. Initial installation and commissioning of this infrastructure remain in-situ. The logical connectivity and IP network design also do not meaningfully change for a foreseeable period. Therefore, network connectivity between radio network nodes and the SEG remains stable in traditional terrestrial deployments, e.g., the lifecycle, lifetime, IP connectivity, and key fresh phase of an IKEv2 / IPsec tunnel between radio network nodes and the SEG is not disrupted.
[0008] Challenges exist for securing the backhaul in non-terrestrial communication network (NTN) deployments, though. An NTN is a network that uses an airborne or space-borne vehicle to embark communication equipment. A satellite, for example, is a space-borne vehicle which may embark bent pipe payload communication equipment or regenerative payload communication equipment, e.g., placed into Low-Earth Orbit (LEO), Medium-Earth Orbit (MEO), or Geostationary Earth Orbit (GEO). Either way, communication equipment on- board the airborne or space-borne vehicle provides communication service to communication devices via a service link, and communicates with other nodes of the NTN via a feeder link. Using such an airborne or space-borne vehicle, an NTN can provide communication service over a wider area of Earth than a terrestrial network, e.g., so that service is more independent of location. When the airborne or space-borne vehicle embarks regenerative payload communication equipment, however, the backhaul traverses the feeder link. Contrasted with the stable environment provided by terrestrial deployments, this exposes the backhaul to a dynamic environment, e.g., due to movement of the hosting vehicle through air or space. Such a dynamic environment may cause interruption of IP connectivity between communication equipment on-board the airborne or space-borne vehicle and the ground-based SEG, which in turn impacts the lifetime and effectiveness of security associations needed for securing the backhaul.
[0009] SUMMARY
[0010] According to some embodiments herein, a network node that is hosted on-board an airborne or space-borne vehicle manages security association(s) with a ground-based security gateway based on predicted (un)availability of network layer connectivity with the security gateway. The network node may for instance trigger rekeying of, or tear down, of the security association(s) based on when the network layer connectivity is predicted to be unavailable. Predictions of network layer connectivity (un)availability may for instance be determined from assistance information, e.g., indicating a flight path and / or trajectory of the vehicle hosting the network node. Regardless, such proactive security association rekeying or tear down may for instance be performed in anticipation of and in advance of network layer connectivity becoming unavailable, e.g., so that security association tear down can be performed gracefully. Some embodiments may thereby prove advantageous for managing Internet Protocol (IP) Security (IPSec) Security Association(s) and / or Internet Key Exchange (IKE) Security Association(s) in such a way that accommodates and accounts for changes in IP connectivity between regenerative payload communication equipment and a ground- based security gateway.
[0011] More particularly, embodiments herein include a method performed by a network node of a non-terrestrial communication network, NTN, wherein the network node is hosted on-board a vehicle that is airborne or spaceborne. The method comprises receiving assistance information. The method also comprises determining, from the assistance information, predicted availability or unavailability of network layer connectivity between the network node and a ground-based security gateway for the NTN. The method also comprises managing one or more security associations between the network node and the ground-based security gateway based on the predicted availability or unavailability of network layer connectivity between the network node and the ground-based security gateway.
[0012] In some embodiments, the assistance information indicates a flight path of the vehicle and / or a flight trajectory of the vehicle.
[0013] In some embodiments, the assistance information indicates when and / or where the network node is predicted to perform a feeder link switch between ground-based NTN gateways.
[0014] In some embodiments, the assistance information indicates when and / or where the network layer connectivity between the network node and the ground-based security gateway is predicted to be available or unavailable.
[0015] In some embodiments, said managing comprises triggering establishment of the one or more security associations based on when the network layer connectivity is predicted to be available. In other embodiments, said managing alternatively or additionally comprises triggering rekeying of, or tear down of, the one or more security associations based on when the network layer connectivity is predicted to be unavailable.
[0016] In some embodiments, the network layer connectivity is Internet Protocol, IP, connectivity.
[0017] In some embodiments, the one or more security associations include one or more Internet Key Exchange, IKE, security associations. In other embodiments, the one or more security associations alternatively or additionally include one or more Internet Protocol, IP, Security, IPSec, security associations.
[0018] In some embodiments, the network node comprises a regenerative payload communication transmitter.
[0019] Other embodiments herein include a method performed by a node of a communication network that comprises a non-terrestrial communication network, NTN. The method comprises transmitting, to a network node of the NTN hosted on-board a vehicle that is airborne or spaceborne, assistance information configured to assist the network node to predict availability or unavailability of network layer connectivity between the network node and a ground-based security gateway for the NTN.
[0020] In some embodiments, the assistance information indicates a flight path of the vehicle and / or a flight trajectory of the vehicle.
[0021] In some embodiments, the assistance information indicates when and / or where the network node is predicted to perform a feeder link switch between ground-based NTN gateways.
[0022] In some embodiments, the assistance information indicates when and / or where the network layer connectivity between the network node and the ground-based security gateway is predicted to be available or unavailable. In some embodiments, the network layer connectivity is Internet Protocol, IP, connectivity.
[0023] In some embodiments, the network node comprises a regenerative payload communication transmitter.
[0024] Other embodiments herein include a network node of a non-terrestrial communication network, NTN, wherein the network node is configured to be hosted onboard a vehicle that is airborne or spaceborne. The network node is configured to receive assistance information. The network node is also configured to determine, from the assistance information, predicted availability or unavailability of network layer connectivity between the network node and a ground-based security gateway for the NTN. The network node is also configured to manage one or more security associations between the network node and the ground-based security gateway based on the predicted availability or unavailability of network layer connectivity between the network node and the ground-based security gateway.
[0025] In some embodiments, the network node is configured to perform the steps described above for a network node of a non-terrestrial communication network, NTN, wherein the network node is hosted on-board a vehicle that is airborne or spaceborne.
[0026] Other embodiments herein include a node of a communication network comprising a non-terrestrial communication network, NTN. The node is configured to transmit, to a network node of the NTN hosted on-board a vehicle that is airborne or spaceborne, assistance information configured to assist the network node to predict availability or unavailability of network layer connectivity between the network node and a ground-based security gateway for the NTN.
[0027] In some embodiments, the node is configured to perform the steps described above for a node of a communication network that comprises a non-terrestrial communication network, NTN.
[0028] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of a network node, causes the network node to perform the steps described above for a network node of a non-terrestrial communication network, NTN, wherein the network node is hosted on-board a vehicle that is airborne or spaceborne.
[0029] In some embodiments, a computer program comprising instructions which, when executed by at least one processor of a node, causes the node to perform the steps described above for a node of a communication network that comprises a non-terrestrial communication network, NTN.
[0030] In some embodiments, a carrier containing the computer program is one of an electronic signal, optical signal, radio signal, or computer readable storage medium. Other embodiments herein include a network node of a non-terrestrial communication network, NTN, wherein the network node is configured to be hosted onboard a vehicle that is airborne or spaceborne. The network node comprises communication circuitry and processing circuitry. The processing circuitry is configured to receive assistance information from the NTN. The processing circuitry is also configured to determine, from the assistance information, predicted availability or unavailability of network layer connectivity between the network node and a ground-based security gateway for the NTN. The processing circuitry is also configured to manage one or more security associations between the network node and the ground-based security gateway based on the predicted availability or unavailability of network layer connectivity between the network node and the ground- based security gateway.
[0031] In some embodiments, the processing circuitry is configured to perform the steps described above for a network node of a non-terrestrial communication network, NTN, wherein the network node is hosted on-board a vehicle that is airborne or spaceborne.
[0032] Other embodiments herein include a node of a communication network comprising a non-terrestrial communication network, NTN. The node comprises communication circuitry and processing circuitry. The processing circuitry is configured to transmit, to a network node of the NTN hosted on-board a vehicle that is airborne or spaceborne, assistance information configured to assist the network node to predict availability or unavailability of network layer connectivity between the network node and a ground-based security gateway for the NTN.
[0033] In some embodiments, the processing circuitry is configured to perform the steps described above for a node of a communication network that comprises a non-terrestrial communication network, NTN.
[0034] BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 is a block diagram of a communication network comprising a non-terrestrial communication network according to some embodiments.
[0036] Figure 2 is a block diagram of the logical architecture for the ‘backhaul’ connection over satellite feeder link according to some embodiments.
[0037] Figure 3 is a block diagram a dynamic link segment in the architecture of some embodiments.
[0038] Figure 4 is a logic flow diagram of a method performed by a network node of a nonterrestrial communication network, NTN, in accordance with particular embodiments.
[0039] Figure 5 is a logic flow diagram of a method performed by a node of a communication network that comprises a non-terrestrial communication network, NTN, in accordance with other particular embodiments.
[0040] Figure 6 is a block diagram of a network node of a non-terrestrial communication network, NTN, in accordance with particular embodiments. Figure 7 is a block diagram of a node of a communication network that comprises a non-terrestrial communication network, NTN, in accordance with other particular embodiments.
[0041] Figure 8 is a block diagram of a communication system according to some embodiments.
[0042] Figure 9 is a block diagram of user equipment according to some embodiments. Figure 10 is a block diagram of network node according to some embodiments. Figure 11 is a block diagram of a virtualization environment according to some embodiments.
[0043] DETAILED DESCRIPTION
[0044] Figure 1 shows a communication network 10 according to some embodiments. The communication network 10 comprises a non-terrestrial communication network (NTN) that exploits airborne or space-borne vehicle(s) to provide communication service to communication devices over a wider area of Earth than just a terrestrial network, e.g., so that service is more independent of location.
[0045] Figure 1 for example shows that the NTN includes an airborne or space-borne vehicle 14 in the form of a satellite, e.g., placed into Low-Earth Orbit (LEO), Medium-Earth Orbit (MEO), or Geostationary Earth Orbit (GEO). The airborne or space-borne vehicle 14 embarks a network node 22 such that the network node 22 is hosted on-board the vehicle 14. So deployed, the network node 22 is configured to provide communication service to a communication device 12, e.g., a user equipment (UE), within the coverage of a spatial beam 11 served by the network node 22. The network node 22 does so via a service link 13 with the communication device 12 and via a feeder link 15 with an earth-based gateway 16 (also referred to as an NTN gateway) that provides a connection towards a core network (CN) 20 of the communication network 10. With a regenerative payload architecture, the network node 22 includes regenerative payload communication equipment that performs on-board processing to demodulate and decode a received signal and regenerate the signal before forwarding it on. In this case, then, the network node 22 itself includes a base station (e.g., gNodeB).
[0046] A ground-based security gateway 18 for the NTN is deployed between the NTN gateway 16 and the core network 20 to secure the core network 20 as a separate security domain, e.g., as otherwise specified by 3GPP TS 33.210 v18.0.0. The network node 22 communicates with the security gateway 18 at the network layer, e.g., the Internet Protocol (IP) layer. Communication between the network node 22 and the security gateway 18 therefore relies upon network layer connectivity 24 (e.g., IP connectivity) between the network node 22 and the security gateway 18. Such network layer connectivity 24 may support a logical connection called a backhaul between the network node 22 and the core network 20, e.g., over which communication and network management traffic is transported. This backhaul may be secured using one or more security associations 26 between the network node 22 and the security gateway 18. The security association(s) 26 may for instance include one or more Internet Key Exchange (IKE) security associations (e.g., IKEv2 association(s)) and / or one or more IP Security (IPSec) security associations. The security association(s) 26 may provide mutual authentication, confidentiality, integrity, anti-replay, and / or topology hiding. In some cases, then, an IKEv2 and IPsec based tunnel may run on the underlying network layer connectivity 24.
[0047] According to embodiments herein, then, the backhaul and the underlying network layer connectivity 24 between the network node 22 and the security gateway 18 traverses the feeder link 15 between the network node 22 and the NTN gateway 16. This exposes the backhaul and the network layer connectivity 24 to a dynamic environment, e.g., due to movement of the vehicle 14 through air or space. Such a dynamic environment risks interruption of the network layer connectivity 24, which in turn threatens to impact the lifetime and effectiveness of the security association(s) 26 for securing the backhaul.
[0048] In this context, the network node 22 herein determines predicted availability or unavailability of the network layer connectivity 24 between the network node 22 and the security gateway 18. Such predicted availability or unavailability of the network layer connectivity 24 may generally indicate when and / or where the network layer connectivity 24 is predicted to be available or unavailable. The predicted availability or unavailability of the network layer connectivity 24 may for instance include predicted time(s) when the network layer connectivity 24 is expected to be available and / or predicted time(s) when the network layer connectivity 24 is expected to be unavailable. Alternatively or additionally, the predicted availability or unavailability of the network layer connectivity 24 may include predicted location(s) where the network layer connectivity 24 is expected to be available and / or predicted location(s) where the network layer connectivity 24 is expected to be unavailable.
[0049] In some embodiments, the network node 22 determines the predicted availability or unavailability of the network layer connectivity 24 from assistance information 30 that the network node 22 receives. In some embodiments, the assistance information 30 directly and / or explicitly indicates the predicted availability or unavailability of the network layer connectivity 24. The assistance information 30 may for example itself indicate when and / or where the network layer connectivity 24 is predicted to be available or unavailable, e.g., as predicted time periods of availability or unavailability. In other embodiments, the assistance information 30 includes information based on which the network node 22 calculates, derives, or otherwise determines the predicted availability or unavailability of the network layer connectivity 24. For example, the assistance information 30 may indicate a flight path of the vehicle 14 and / or a flight trajectory of the vehicle 14. In such a case, the network node 22 may predict when the network layer connectivity 24 will be available or unavailable, using the assistance information 30, e.g., in conjunction with other information such as a coverage map and / or flight telemetry of the vehicle 14. In these and other embodiments, the network node 22 may predict that network layer connectivity 24 will be unavailable when and / or where the network node 22 is predicted to perform a feeder link switch between ground- based NTN gateways. Correspondingly, in other embodiments, the assistance information 30 may itself indicate when and / or where the network node 22 is predicted to perform a feeder link switch between ground-based NTN gateways.
[0050] No matter the particular way in which the network node 22 determines the predicted availability or unavailability of network layer connectivity 24, the network node 22 notably exploits this predicted availability or unavailability of network layer connectivity 24 to manage the security association(s) 26. The network node 22 may for instance trigger rekeying of, or tear down, of the security association(s) 26 based on when the network layer connectivity 24 is predicted to be unavailable. For example, the network node 22 may trigger proactive rekeying of, or tear down, of the security association(s) 26 to occur before, in anticipation of, and / or in advance of when the network layer connectivity 24 is predicted to be unavailable. Such proactive measures may thereby facilitate graceful tear down of the security association(s) 26. Alternatively or additionally, the network node 22 may trigger establishment of the security association(s) 26 based on when the network layer connectivity 24 is predicted to be available. For example, the network node 22 may trigger proactive establishment of the security association(s) 26 to occur when the network layer connectivity 24 is predicted to be available. Such proactive measures may thereby facilitate more timely establishment or resumption of the security association(s) 26.
[0051] Some embodiments may thereby prove advantageous for managing security association(s) 26, such as IPSec Security Association(s) and / or IKE Security Association(s), in such a way that accommodates and accounts for changes in the network layer connectivity 24, e.g., due to movement of the vehicle 14 hosting the network node 22 on-board.
[0052] Some embodiments herein are applicable in the following context, wherein the security association(s) 26 are exemplified as IPSec Security Association(s) and / or IKEv2 Security Association(s), the NTN is exemplified as a 4G or 5G NTN with a regenerative architecture, the vehicle 14 is exemplified as a satellite, the security gateway 18 is exemplified as a SEG, and the network node 22 is exemplified as an eNodeB or gNodeB.
[0053] Some embodiments accommodate for the dynamic environment of a 5G NTN attributable to orbiting satellite movement from source NTN gateway to the target NTN gateway. By deployment of 5G NTN regenerative architecture, RAN node (e.g., eNodeB / gNodeB) are on-board an orbiting satellite. It results into the backhaul connection from orbiting 3GPP RAN infrastructure nodes passes through 5G NTN satellites' wireless links, such as a feeder link, to carry communication and management traffic towards ground based 3GPP core network and network management infrastructure.
[0054] The movement of orbiting satellite from source NTN gateway to target NTN gateway may be carried out by a feeder link switchover. There are two types of feeder link switchover:
[0055] 1. Hard switchover (aka break-before-make) - the orbiting satellite disconnects with its ground based current NTN gateway before connecting to target NTN gateway.
[0056] 2. Soft switchover (aka make-before-break) - the orbiting satellite connects to target NTN gateway in parallel to maintaining connection with the current NTN gateway, and then disconnects with current NTN gateway once connection with target NTN gateway is completed.
[0057] The NTN gateway 16 may be an IP transport network layer node. The feeder link switchover may result in interruption of IP connectivity from on-board RAN node 22 to ground based SEG. It impacts the lifetime and effectiveness of IKEv2 Security Association (SA) and IPsec SA because of potential interruption to underlying end-to-end IP connectivity. The movement of satellite from source NTN gateway to the target NTN gateway also could result in change to IP addresses of the outer IKEv2 tunnel of a peer.
[0058] To be able to reuse the backhaul security provided by security architecture, e.g., from TS 33.210 V18.0.0, and for it to remain effective, some embodiments automate IKEv2 / IPsec SA lifecycle to cater for dynamicity of 5G NTN backhaul over satellite wireless links.
[0059] More particularly, some embodiments provide a mechanism that enables 3GPP RAN node (for example 4G eNodeB / ng-eNodeB / 5G gNodeB) to be configured with satellite orbital information comprising time and location. Knowing the time-based ground connectivity of a satellite allows orbiting RAN nodes to know in advance exactly when the IP connectivity with ground based SEG is available or not. This information may be by configuration provided to orbiting RAN nodes via RAN node configuration automating the establishment, maintenance, and / or termination of IPsec over IP via satellite transport network according to feeder link switchover timetable. It may be a network management capability.
[0060] Such configuration may automate RAN nodes to gracefully automate the trigger of phases of IKEv2 / IPsec to establish, 'rekey', and / or tear down IKEv2 / IPsec SA with the ground based SEG, e.g., considering availability of end-to-end IP connectivity via satellite transport links.
[0061] Some embodiments provide preprogrammed logic in RAN nodes to set off a 'process trigger' in onboard RAN nodes for processing to initiate, 'rekey', or tear down IKEv2 / IPsec SA with ground based SEG. The automation logic that triggers IPsec establishment, ’rekey’, or termination may be made available by configuration of satellite's orbital 'flight path' trajectory-based availability and unavailability of IP connection information in RAN nodes. For example, some embodiments automatically establish IKEv2 / IPsec programmatically when IP connectivity establishes, and / or automatically gracefully tear down IKEv2 / IPsec programmatically when IP connectivity is about to be lost. Alternatively or additionally, some embodiments automatically gracefully complete 'rekeying' of IKEv2 / IPsec SA before the IP connectivity could potentially be lost.
[0062] Certain embodiments may provide one or more of the following technical advantage(s). Some embodiments provide preprogrammed automatic correlated IPsec lifecycle with lifecycle of IP connectivity from on-board RAN nodes to ground based SEG. The uptime and availability of IKEv2 / IPsec SA may be dependent on IP connectivity that is in turn impacted by frequent feeder link switchovers.
[0063] One benefit of some embodiments is that preprogrammed configuration information in on-board RAN nodes to be able to securely communicate with ground based SEG via IKEv2 / IPsec SA to secure 3GPP backhaul.
[0064] Figure 2 describes the logical architecture for the ‘backhaul’ connection over satellite feeder link according to some embodiments. This architecture assumes regenerative payload where RAN node, such as eNodeB / gNodeB, is on-board orbiting satellites. The 3GPP SEG is on the ground.
[0065] The rest of the 3GPP network functions (NFs) and network management systems are behind the SEG.
[0066] Figure 3 shows one problem solved by some embodiments herein. Figure 3 in this regard captures the dynamic link segment in the architecture. The following scenarios influence the dynamic properties associated with this link segment. The feeder link switchovers for satellite handovers could potentially cause a change in IP addresses of onboard RAN node and / or ground-based NTN gateway at the transport network layer. The state of IKEv2 / IPsec requires correlating with state of connect / disconnect of IP link itself due to impact of satellite movement on RAN nodes' backhaul IP connectivity with the ground.
[0067] For example, by operator policy and subject to regulation, satellite may only ever connect to ground stations allowed by policy. As a result, when the satellite moves out of ground station’s catchment location, it loses the ground connectivity via the feeder link and the IP transport during such period, and then reestablishes the IP connectivity. As another example, when the satellite orbit is passing over the earth surface (e.g., oceans, mountains, deserts, forests etc.) where there is no ground station and supporting infrastructure, the satellite may by-design route data over to Inter Satellite Link (ISL) to other satellites that may have connectivity with the ground infrastructure over a feeder link, but the ground infrastructure may reside in jurisdiction not permitted by regulations.
[0068] According to some embodiments, the feeder link switchovers and / or satellite handovers are known events upfront due to satellite’s known orbital 'flight path' trajectories, as an example of assistance information 30 herein. Therefore, this information is made available by the network management systems to the RAN nodes hosted on-board satellites for the RAN nodes to set off necessary process triggers for automating preprogrammed setting up IKEv2 and IPsec SA each time IP connectivity resumes. When the IP connection is about to disconnect, the RAN node gracefully tears down IKEv2 and / or IPsec SA. Alternatively or additionally, depending on predicted potential disruption to IP connectivity, timing of the 'rekeying' can be adjusted such that before potential disruption to IP connectivity, the 'rekeying' can complete gracefully.
[0069] Some embodiments are applicable for network domain IP based control planes, which shall be applied to NDS / IP-networks (i.e. 3GPP and fixed broadband networks).
[0070] In some embodiments, an IPsec Security Association is a unidirectional logical connection created for security purposes. All traffic traversing a SA is provided the same security protection. The SA itself is a set of parameters to define security protection between two entities. An IPsec Security Association includes the cryptographic algorithms, the keys, the duration of the keys, and other parameters.
[0071] In some embodiments, a security Domain includes network(s) that are managed by a single administrative authority. Within a security domain the same level of security and usage of security services will be typical.
[0072] In some embodiments, Security Gateways (SEGs) are entities on the borders of the IP security domains and will be used for securing native IP based protocols. The SEGs are defined to handle communication over the Za-interface, which is located between SEGs from different IP security domains.
[0073] All NDS / IP traffic shall pass through a SEG before entering or leaving the security domain. Each security domain can have one or more SEGs. Each SEG will be defined to handle NDS / IP traffic in or out of the security domain towards a well-defined set of reachable IP security domains.
[0074] SEGs are responsible for security sensitive operations and shall be physically secured. They shall offer capabilities for secure storage of long-term keys used for IKE authentication.
[0075] In some embodiments, the network domain control plane of an NDS / IP-network is sectioned into security domains and typically these coincide with operator borders. The border between the security domains is protected by Security Gateways (SEGs). The SEGs are responsible for enforcing the security policy of a security domain towards other SEGs in the destination security domain. The network operator may have more than one SEG in its network in order to avoid a single point of failure or for performance reasons. A SEG may be defined for interaction towards all reachable security domain destinations or it may be defined for only a subset of the reachable destinations. In some embodiments, IPsec is designed to provide interoperable, high quality, cryptographically-based security for IPv4 and IPv6. The set of security services offered includes access control, connectionless integrity, data origin authentication, detection and rejection of replays (a form of partial sequence integrity), confidentiality (via encryption), and limited traffic flow confidentiality. These services are provided at the IP layer, offering protection in a standard fashion for all protocols that may be carried over IP (including IP itself).
[0076] Because most of the security services provided by IPsec require the use of cryptographic keys, IPsec relies on a separate set of mechanisms for putting these keys in place. Some embodiments exploit a specific public-key based approach (IKEv2) for automated key management, but other automated key distribution techniques may be used. One function of IKE is the establishment and maintenance of SAs. In some embodiments, an SA is a simplex "connection" that affords security services to the traffic carried by it. To secure typical, bi-directional communication between two IPsec-enabled systems, a pair of SAs (one in each direction) is required.
[0077] In some embodiments, two types of SAs are defined: transport mode and tunnel mode. A transport mode SA is an SA typically employed between a pair of hosts to provide end-to-end security services. A tunnel mode SA is essentially an SA applied to an IP tunnel, with the access controls applied to the headers of the traffic inside the tunnel.
[0078] In some embodiments, IP Security (IPsec) provides confidentiality, data integrity, access control, and data source authentication to IP datagrams. These services are provided by maintaining shared state between the source and the sink of an IP datagram. This state defines, among other things, the specific services provided to the datagram, which cryptographic algorithms will be used to provide the services, and the keys used as input to the cryptographic algorithms.
[0079] IKE performs mutual authentication between two parties and establishes an IKE security association (SA) that includes shared secret information that can be used to efficiently establish SAs for Encapsulating Security Payload (ESP) [RFC4303] and / or Authentication Header (AH) [RFC4302] and a set of cryptographic algorithms to be used by the SAs to protect the traffic that they carry.
[0080] In some embodiments, IKE SA is established first between two devices (such as routers or gateways) that intend to communicate securely using IPsec. IKE SA is negotiated using either IKEv1 or IKEv2 protocols and involves the exchange of security attributes, authentication methods, and keying material. Once IKE SA has been established and security parameters have been agreed upon, IPsec SAs are then created. IPsec SA defines the specific security parameters (like algorithms, keys, and modes) that will be used for protecting the actual data traffic. IPsec SA is responsible for managing the security context for outbound and inbound IP packets. It determines how data is encrypted, authenticated, and decrypted.
[0081] Generally, then, IKE SA and IPsec SA are interdependent in the process of establishing secure communications. IKE SA is responsible for setting up the secure channel and negotiating parameters for subsequent IPsec SAs, which actually define how the data packets will be secured and transmitted.
[0082] Note that the earth-based gateway 16 (also referred to as NTN gateway) was exemplified in Figure 1 as being co-located with a ground station (e.g., dish). However, that need not be the case. The earth-based gateway 16 in other embodiments may be implemented separately from the ground station. The earth-based gateway 16 in these and other embodiments may for example be implemented as a Layer-3 router.
[0083] In view of the modifications and variations herein, Figure 4 depicts a method performed by a network node 22 of a non-terrestrial communication network, NTN, in accordance with particular embodiments, wherein the network node 22 is hosted on-board a vehicle 14 that is airborne or spaceborne. The method includes receiving assistance information 30 (Block 400). The method also comprises determining, from the assistance information 30, predicted availability or unavailability of network layer connectivity 24 between the network node 22 and a ground-based security gateway 18 for the NTN (Block 410). The method also comprises managing one or more security associations 26 between the network node 22 and the ground-based security gateway 18 based on the predicted availability or unavailability of network layer connectivity 24 between the network node 22 and the ground-based security gateway 18 (Block 420).
[0084] In some embodiments, the assistance information 30 indicates a flight path of the vehicle 14 and / or a flight trajectory of the vehicle 14.
[0085] In some embodiments, the assistance information 30 indicates when and / or where the network node 22 is predicted to perform a feeder link switch between ground-based NTN gateways 18.
[0086] In some embodiments, the assistance information 30 indicates when and / or where the network layer connectivity 24 between the network node 22 and the ground-based security gateway 18 is predicted to be available or unavailable.
[0087] In some embodiments, said managing comprises triggering establishment of the one or more security associations 26 based on when the network layer connectivity 24 is predicted to be available. In other embodiments, said managing alternatively or additionally comprises triggering rekeying of, or tear down of, the one or more security associations 26 based on when the network layer connectivity 24 is predicted to be unavailable.
[0088] In some embodiments, the network layer connectivity 24 is Internet Protocol, IP, connectivity. In some embodiments, the one or more security associations 26 include one or more Internet Key Exchange, IKE, security associations. In other embodiments, the one or more security associations 26 alternatively or additionally include one or more Internet Protocol, IP, Security, IPSec, security associations.
[0089] In some embodiments, the network node 22 comprises regenerative payload communication equipment.
[0090] Figure 5 depicts a method performed by a node 28 of a communication network 10 that comprises a non-terrestrial communication network, NTN, in accordance with other particular embodiments. The method includes transmitting, to a network node 22 of the NTN hosted on-board a vehicle 14 that is airborne or spaceborne, assistance information 30 configured to assist the network node 22 to predict availability or unavailability of network layer connectivity 24 between the network node 22 and a ground-based security gateway 18 for the NTN (Block 500).
[0091] In some embodiments, the assistance information 30 indicates a flight path of the vehicle 14 and / or a flight trajectory of the vehicle 14.
[0092] In some embodiments, the assistance information 30 indicates when and / or where the network node 22 is predicted to perform a feeder link switch between ground-based NTN gateways 18.
[0093] In some embodiments, the assistance information 30 indicates when and / or where the network layer connectivity 24 between the network node 22 and the ground-based security gateway 18 is predicted to be available or unavailable.
[0094] In some embodiments, the network layer connectivity 24 is Internet Protocol, IP, connectivity.
[0095] In some embodiments, the network node 22 comprises regenerative payload communication equipment.
[0096] Embodiments herein also include corresponding apparatuses. Embodiments herein for instance include a network node 22 configured to perform any of the steps of any of the embodiments described above for the network node 22.
[0097] Embodiments also include a network node 22 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the network node 22. The power supply circuitry is configured to supply power to the network node 22.
[0098] Embodiments further include a network node 22 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the network node 22. In some embodiments, the network node 22 further comprises communication circuitry. Embodiments further include a network node 22 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the network node 22 is configured to perform any of the steps of any of the embodiments described above for the network node 22.
[0099] Embodiments herein also include a node 28 configured to perform any of the steps of any of the embodiments described above for the node 28.
[0100] Embodiments also include a node 28 comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the node 28. The power supply circuitry is configured to supply power to the node 28.
[0101] Embodiments further include a node 28 comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the node 28. In some embodiments, the node 28 further comprises communication circuitry.
[0102] Embodiments further include a node 28 comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry whereby the node 28 is configured to perform any of the steps of any of the embodiments described above for the node 28.
[0103] More particularly, the apparatuses described above may perform the methods herein and any other processing by implementing any functional means, modules, units, or circuitry. In one embodiment, for example, the apparatuses comprise respective circuits or circuitry configured to perform the steps shown in the method figures. The circuits or circuitry in this regard may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. For instance, the circuitry may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory may include program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein, in several embodiments. In embodiments that employ memory, the memory stores program code that, when executed by the one or more processors, carries out the techniques described herein.
[0104] Figure 6 for example illustrates a network node 22 as implemented in accordance with one or more embodiments. As shown, the network node 22 includes processing circuitry 610 and communication circuitry 620. The communication circuitry 620 (e.g., radio circuitry) is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. Such communication may occur via one or more antennas that are either internal or external to the network node 22. The processing circuitry 610 is configured to perform processing described above, e.g., in Figure 4, such as by executing instructions stored in memory 630. The processing circuitry 610 in this regard may implement certain functional means, units, or modules.
[0105] Figure 7 illustrates a node 28 as implemented in accordance with one or more embodiments. As shown, the node 28 includes processing circuitry 710 and communication circuitry 720. The communication circuitry 720 is configured to transmit and / or receive information to and / or from one or more other nodes, e.g., via any communication technology. The processing circuitry 710 is configured to perform processing described above, e.g., in Figure 5, such as by executing instructions stored in memory 730. The processing circuitry 710 in this regard may implement certain functional means, units, or modules.
[0106] Those skilled in the art will also appreciate that embodiments herein further include corresponding computer programs.
[0107] A computer program comprises instructions which, when executed on at least one processor of an apparatus, cause the apparatus to carry out any of the respective processing described above. A computer program in this regard may comprise one or more code modules corresponding to the means or units described above.
[0108] Embodiments further include a carrier containing such a computer program. This carrier may comprise one of an electronic signal, optical signal, radio signal, or computer readable storage medium.
[0109] In this regard, embodiments herein also include a computer program product stored on a non-transitory computer readable (storage or recording) medium and comprising instructions that, when executed by a processor of an apparatus, cause the apparatus to perform as described above.
[0110] Embodiments further include a computer program product comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by a computing device. This computer program product may be stored on a computer readable recording medium.
[0111] Figure 8 shows an example of a communication system 800 in accordance with some embodiments.
[0112] In the example, the communication system 800 includes a telecommunication network 802 that includes an access network 804, such as a radio access network (RAN), and a core network 806, which includes one or more core network nodes 808. The access network 804 includes one or more access network nodes, such as network nodes 810a and 810b (one or more of which may be generally referred to as network nodes 810), or any other similar 3rdGeneration Partnership Project (3GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 802 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network 802 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network 802, including one or more network nodes 810 and / or core network nodes 808.
[0113] Examples of an ORAN network node include an open radio unit (0-Rll), an open distributed unit (0-Dll), an open central unit (O-CU), including an O-CU control plane (O- CLI-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an A1, F1, W1, E1 , E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an O-2 interface defined by the O-RAN Alliance or comparable technologies. The network nodes 810 facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs 812a, 812b, 812c, and 812d (one or more of which may be generally referred to as UEs 812) to the core network 806 over one or more wireless connections.
[0114] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 800 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 800 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.
[0115] The UEs 812 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 810 and other communication devices. Similarly, the network nodes 810 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 812 and / or with other network nodes or equipment in the telecommunication network 802 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 802.
[0116] In the depicted example, the core network 806 connects the network nodes 810 to one or more host computing systems, such as host 816. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 806 includes one more core network nodes (e.g., core network node 808) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 808. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).
[0117] The host 816 may be under the ownership or control of a service provider other than an operator or provider of the access network 804 and / or the telecommunication network 802. The host 816 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.
[0118] As a whole, the communication system 800 of Figure 8 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.
[0119] In some examples, the telecommunication network 802 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network 802 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 802. For example, the telecommunications network 802 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.
[0120] In some examples, the UEs 812 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 804 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 804. Additionally, a UE may be configured for operating in single- or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved- UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).
[0121] In the example, the hub 814 communicates with the access network 804 to facilitate indirect communication between one or more UEs (e.g., UE 812c and / or 812d) and network nodes (e.g., network node 810b). In some examples, the hub 814 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 814 may be a broadband router enabling access to the core network 806 for the UEs. As another example, the hub 814 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 810, or by executable code, script, process, or other instructions in the hub 814. As another example, the hub 814 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 814 may be a content source. For example, for a UE that is a VR device, display, loudspeaker, or other media delivery device, the hub 814 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 814 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 814 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.
[0122] The hub 814 may have a constant / persistent or intermittent connection to the network node 810b. The hub 814 may also allow for a different communication scheme and / or schedule between the hub 814 and UEs (e.g., UE 812c and / or 812d), and between the hub 814 and the core network 806. In other examples, the hub 814 is connected to the core network 806 and / or one or more UEs via a wired connection. Moreover, the hub 814 may be configured to connect to an M2M service provider over the access network 804 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 810 while still connected via the hub 814 via a wired or wireless connection. In some embodiments, the hub 814 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 810b. In other embodiments, the hub 814 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 810b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.
[0123] Figure 9 shows a UE 900 in accordance with some embodiments. The UE 900 presents additional details of some embodiments of the UE 812 of Figure 1. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage / playback device, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptopmounted equipment (LME), an Augmented Reality (AR) or Virtual Reality (VR) device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB- loT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.
[0124] A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle- to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).
[0125] The UE 900 includes processing circuitry 902 that is operatively coupled via a bus 904 to an input / output interface 906, a power source 908, a memory 910, a communication interface 912, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 9. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0126] The processing circuitry 902 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 910. The processing circuitry 902 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 902 may include multiple central processing units (CPUs).
[0127] In the example, the input / output interface 906 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 900. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.
[0128] In some embodiments, the power source 908 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source 908 may further include power circuitry for delivering power from the power source 908 itself, and / or an external power source, to the various parts of the UE 900 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source 908. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 908 to make the power suitable for the respective components of the UE 900 to which power is supplied.
[0129] The memory 910 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 910 includes one or more application programs 914, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 916. The memory 910 may store, for use by the UE 900, any of a variety of various operating systems or combinations of operating systems.
[0130] The memory 910 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD- DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUlCC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 910 may allow the UE 900 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 910, which may be or comprise a device-readable storage medium.
[0131] The processing circuitry 902 may be configured to communicate with an access network or other network using the communication interface 912. The communication interface 912 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 922. The communication interface 912 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 918 and / or a receiver 920 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 918 and receiver 920 may be coupled to one or more antennas (e.g., antenna 922) and may share circuit components, software or firmware, or alternatively be implemented separately.
[0132] In the illustrated embodiment, communication functions of the communication interface 912 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.
[0133] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 912, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).
[0134] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.
[0135] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE 900 shown in Figure 9.
[0136] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-loT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0137] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.
[0138] Figure 10 shows a network node 1000 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).
[0139] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O- RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).
[0140] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).
[0141] The network node 1000 includes a processing circuitry 1002, a memory 1004, a communication interface 1006, and a power source 1008. The network node 1000 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 1000 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 1000 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 1004 for different RATs) and some components may be reused (e.g., a same antenna 1010 may be shared by different RATs). The network node 1000 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 1000, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z- wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 1000.
[0142] The processing circuitry 1002 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 1000 components, such as the memory 1004, to provide network node 1000 functionality. In some embodiments, the processing circuitry 1002 includes a system on a chip (SOC). In some embodiments, the processing circuitry 1002 includes one or more of radio frequency (RF) transceiver circuitry 1012 and baseband processing circuitry 1014. In some embodiments, the radio frequency (RF) transceiver circuitry 1012 and the baseband processing circuitry 1014 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 1012 and baseband processing circuitry 1014 may be on the same chip or set of chips, boards, or units.
[0143] The memory 1004 may comprise any form of volatile or non-volatile computer- readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 1002. The memory 1004 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 1002 and utilized by the network node 1000. The memory 1004 may be used to store any calculations made by the processing circuitry 1002 and / or any data received via the communication interface 1006. In some embodiments, the processing circuitry 1002 and memory 1004 is integrated.
[0144] The communication interface 1006 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 1006 comprises port(s) / terminal(s) 1016 to send and receive data, for example to and from a network over a wired connection. The communication interface 1006 also includes radio front-end circuitry 1018 that may be coupled to, or in certain embodiments a part of, the antenna 1010. Radio front-end circuitry 1018 comprises filters 1020 and amplifiers 1022. The radio front-end circuitry 1018 may be connected to an antenna 1010 and processing circuitry 1002. The radio front-end circuitry may be configured to condition signals communicated between antenna 1010 and processing circuitry 1002. The radio front-end circuitry 1018 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 1018 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 1020 and / or amplifiers 1022. The radio signal may then be transmitted via the antenna 1010. Similarly, when receiving data, the antenna 1010 may collect radio signals which are then converted into digital data by the radio front-end circuitry 1018. The digital data may be passed to the processing circuitry 1002. In other embodiments, the communication interface may comprise different components and / or different combinations of components.
[0145] In certain alternative embodiments, the network node 1000 does not include separate radio front-end circuitry 1018, instead, the processing circuitry 1002 includes radio front-end circuitry and is connected to the antenna 1010. Similarly, in some embodiments, all or some of the RF transceiver circuitry 1012 is part of the communication interface 1006. In still other embodiments, the communication interface 1006 includes one or more ports or terminals 1016, the radio front-end circuitry 1018, and the RF transceiver circuitry 1012, as part of a radio unit (not shown), and the communication interface 1006 communicates with the baseband processing circuitry 1014, which is part of a digital unit (not shown).
[0146] The antenna 1010 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 1010 may be coupled to the radio front-end circuitry 1018 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 1010 is separate from the network node 1000 and connectable to the network node 1000 through an interface or port.
[0147] The antenna 1010, communication interface 1006, and / or the processing circuitry 1002 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 1010, the communication interface 1006, and / or the processing circuitry 1002 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.
[0148] The power source 1008 provides power to the various components of network node 1000 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 1008 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 1000 with power for performing the functionality described herein. For example, the network node 1000 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 1008. As a further example, the power source 1008 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail. Embodiments of the network node 1000 may include additional components beyond those shown in Figure 10 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 1000 may include user interface equipment to allow input of information into the network node 1000 and to allow output of information from the network node 1000. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 1000. In some embodiments providing a core network node, such as core network node 108 of FIG. 8, some components, such as the radio front-end circuitry 1018 and the RF transceiver circuitry 1012 may be omitted.
[0149] Figure 11 is a block diagram illustrating a virtualization environment 1100 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1100 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 1100 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface. Virtualization may facilitate distributed implementations of a network node, UE, core network node, or host.
[0150] Applications 1102 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.
[0151] Hardware 1104 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 1106 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 1108a and 1108b (one or more of which may be generally referred to as VMs 1108), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 1106 may present a virtual operating platform that appears like networking hardware to the VMs 1108.
[0152] The VMs 1108 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 1106. Different embodiments of the instance of a virtual appliance 1102 may be implemented on one or more of VMs 1108, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.
[0153] In the context of NFV, a VM 1108 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs 1108, and that part of hardware 1104 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 1108 on top of the hardware 1104 and corresponds to the application 1102.
[0154] Hardware 1104 may be implemented in a standalone network node with generic or specific components. Hardware 1104 may implement some functions via virtualization. Alternatively, hardware 1104 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 1110, which, among others, oversees lifecycle management of applications 1102. In some embodiments, hardware 1104 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 1112 which may alternatively be used for communication between hardware nodes and radio units.
[0155] Although the computing devices described herein (e.g., UEs, network nodes) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.
[0156] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.
Claims
CLAIMS1 . A method performed by a network node (22) of a non-terrestrial communication network, NTN, wherein the network node (22) is hosted on-board a vehicle (14) that is airborne or spaceborne, the method comprising: receiving (400) assistance information (30); determining (410), from the assistance information (30), predicted availability or unavailability of network layer connectivity (24) between the network node (22) and a ground-based security gateway (18) for the NTN; and managing (420) one or more security associations (26) between the network node (22) and the ground-based security gateway (18) based on the predicted availability or unavailability of network layer connectivity (24) between the network node (22) and the ground-based security gateway (18).
2. The method of claim 1 , wherein the assistance information (30) indicates a flight path of the vehicle (14) and / or a flight trajectory of the vehicle (14).
3. The method of any of claims 1-2, wherein the assistance information (30) indicates when and / or where the network node (22) is predicted to perform a feeder link switch between ground-based NTN gateways.
4. The method of any of claims 1-3, wherein the assistance information (30) indicates when and / or where the network layer connectivity (24) between the network node (22) and the ground-based security gateway (18) is predicted to be available or unavailable.
5. The method of any of claims 1-4, wherein said managing comprises: triggering establishment of the one or more security associations (26) based on when the network layer connectivity (24) is predicted to be available; and / or triggering rekeying of, or tear down of, the one or more security associations (26) based on when the network layer connectivity (24) is predicted to be unavailable.
6. The method of any of claims 1-5, wherein the network layer connectivity (24) is Internet Protocol, IP, connectivity.
7. The method of any of claims 1-6, wherein the one or more security associations (26) include:one or more Internet Key Exchange, IKE, security associations; and / or one or more Internet Protocol, IP, Security, IPSec, security associations.
8. The method of any of claims 1-7, wherein the network node (22) comprises regenerative payload communication equipment.
9. A method performed by a node (28) of a communication network (10) that comprises a non-terrestrial communication network, NTN, the method comprising: transmitting (500), to a network node (22) of the NTN hosted on-board a vehicle (14) that is airborne or spaceborne, assistance information (30) configured to assist the network node (22) to predict availability or unavailability of network layer connectivity (24) between the network node (22) and a ground-based security gateway (18) for the NTN.
10. The method of claim 9, wherein the assistance information (30) indicates a flight path of the vehicle (14) and / or a flight trajectory of the vehicle (14).
11. The method of any of claims 9-10, wherein the assistance information (30) indicates when and / or where the network node (22) is predicted to perform a feeder link switch between ground-based NTN gateways.
12. The method of any of claims 9-11 , wherein the assistance information (30) indicates when and / or where the network layer connectivity (24) between the network node (22) and the ground-based security gateway (18) is predicted to be available or unavailable.
13. The method of any of claims 9-12, wherein the network layer connectivity (24) is Internet Protocol, IP, connectivity.
14. The method of any of claims 9-13, wherein the network node (22) comprises regenerative payload communication equipment.
15. A network node (22) of a non-terrestrial communication network, NTN, wherein the network node (22) is configured to be hosted on-board a vehicle (14) that is airborne or spaceborne, the network node (22) configured to: receive assistance information (30);determine, from the assistance information (30), predicted availability or unavailability of network layer connectivity (24) between the network node (22) and a ground-based security gateway (18) for the NTN; and manage one or more security associations (26) between the network node (22) and the ground-based security gateway (18) based on the predicted availability or unavailability of network layer connectivity (24) between the network node (22) and the ground-based security gateway (18).
16. The network node (22) of claim 15, configured to perform the method of any of claims 2-8.
17. A node (28) of a communication network (10) comprising a non-terrestrial communication network, NTN, the node (28) configured to: transmit, to a network node (22) of the NTN hosted on-board a vehicle (14) that is airborne or spaceborne, assistance information (30) configured to assist the network node (22) to predict availability or unavailability of network layer connectivity (24) between the network node (22) and a ground-based security gateway (18) for the NTN.
18. The node (28) of claim 17, configured to perform the method of any of claims 10-14.
19. A computer program comprising instructions which, when executed by at least one processor of a network node (22), causes the network node (22) to perform the method of any of claims 1-8.
20. A computer program comprising instructions which, when executed by at least one processor of a node (28), causes the node (28) to perform the method of any of claims 9-14.
21. A carrier containing the computer program of any of claims 19-20, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.
22. A network node (22) of a non-terrestrial communication network, NTN, wherein the network node (22) is configured to be hosted on-board a vehicle (14) that is airborne or spaceborne, the network node (22) comprising: communication circuitry; and processing circuitry configured to:receive assistance information (30) from the NTN; determine, from the assistance information (30), predicted availability or unavailability of network layer connectivity (24) between the network node (22) and a ground-based security gateway (18) for the NTN; and manage one or more security associations (26) between the network node (22) and the ground-based security gateway (18) based on the predicted availability or unavailability of network layer connectivity (24) between the network node (22) and the ground-based security gateway (18).
23. The network node (22) of claim 22, the processing circuitry configured to perform the method of any of claims 2-8.
24. A node (28) of a communication network (10) comprising a non-terrestrial communication network, NTN, the node (28) comprising: communication circuitry; and processing circuitry configured to transmit, to a network node (22) of the NTN hosted on-board a vehicle (14) that is airborne or spaceborne, assistance information (30) configured to assist the network node (22) to predict availability or unavailability of network layer connectivity (24) between the network node (22) and a ground-based security gateway (18) for the NTN.
25. The node (28) of claim 24, the processing circuitry configured to perform the method of any of claims 10-14.
Citation Information
Patent Citations
Adapting mobility under discontinuous coverage
WO2023069508A1
Managing communications and out-of-coverage scenarios in a non-terrestrial network
WO2024035926A1