Method for a user plane for handling a communication towards a ue

The method and network entities dynamically adjust User Plane security based on RAN type to address security and cost challenges in mobile networks, ensuring secure and cost-effective communication across varying radio access technologies.

WO2025247738A1PCT designated stage Publication Date: 2025-12-04TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/064078
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-31
Filing Date
2025-05-22
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

The varying architectural changes in User Plane security termination across different radio access network generations and core network components create challenges in handling encrypted and unencrypted user plane communications, leading to potential security vulnerabilities and increased costs due to the use of IPSec between Core and RAN.

Method used

A method and network entities that determine whether the User Plane should act as a security anchor based on the radio access technology, enabling flexible mobility and reducing the need for IPSec by allowing the User Plane to encrypt or decrypt communications accordingly, while supporting different RAN types, including 5G and 6G networks.

Benefits of technology

This approach enhances security by ensuring appropriate encryption/decryption based on RAN type, reduces overall solution costs, and maintains mobility flexibility, allowing seamless communication between different RAN generations without introducing security holes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025064078_04122025_PF_FP_ABST
    Figure EP2025064078_04122025_PF_FP_ABST
Patent Text Reader

Abstract

The invention refers to a method (100) for a User Plane (12) for handling a communication towards a user equipment, UE (21), wherein the first UE (21) is communicating with the User Plane (12) via a RAN (31). The method comprises receiving (101) a first message (3) that has been transmitted by a Control Plane (11), wherein the first message (3) comprises a first information, wherein the first information is indicating whether the User Plane (12) should act as a security anchor for a user plane communication between the UE (21) and the User Plane (12); determining (102) whether the User Plane (12) should act as a security anchor for the user plane communication of the UE (21) based on the first information; and acting (103) as the security anchor for the user plane communication based on a result of the determination.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method for a User Plane for handling a communication towards a UE

[0002] Technical field

[0003] The invention refers to handling a communication towards a user equipment.

[0004] Background

[0005] A User Plane security termination is provided in most mobile communication networks, wherein the User Plane security termination is provided by a so-called security anchor. However, User Plane security termination has changed over different radio access network (RAN) generations.

[0006] Figure 5 shows the location of User Plane security termination for existing radio access networks, wherein a security anchor SA for User Plane security termination is implemented in different ways.

[0007] That is:

[0008] • GSM CS terminates UP security on physical layer below channel coding.

[0009] • 2G GPRS terminates UP security in SGSN (LLC protocol) in the Core Network.

[0010] • 3G terminates UP security in RNC (common solution for CS / PS) in the RAN.

[0011] • In LTE / 4G UP security terminates in eNB in the RAN.

[0012] Note: Due to termination of UP security in eNB / gNB in LTE / NR, requirements were imposed having a “secure environment” for handling plaintext UP in the eNB (see 33.401 ch 5.3) as well as mandatory requirement to support IPsec.

[0013] • 5G: In NR UP security terminates in gNB, but gNB was split in DU, CU-CP and CU-UP enabling centralized deployment of CU-UP (terminating UP security). Security requirements are similar to eNB (see 33.501 ch 5.3).

[0014] Over the different generations, not only the RAN has undergone architectural changes but also the core network e.g., CUPS, Control User Plane Split which created an open interface in the defined GW products like SGW, Serving Gateway and PGW, PDN Gateway (see 3GPP TS 23.214). This change in EPC was also inherited to 5GC and the protocol specification for both EPC and 5GC are handled in 3GPP TS 29.244. Summary

[0015] According to an aspect of the invention, a method for a User Plane for handling a communication towards a user equipment (UE). The UE is communicating with the User Plane via a radio access network (RAN). The method comprises receiving a first message that has been transmitted by a Control Plane, wherein the first message comprises a first information, wherein the first information is indicating whether the User Plane should act as a security anchor for a user plane communication between the UE and the User Plane, determining whether the User Plane should act as a security anchor for the user plane communication of the UE based on the first information, and acting as the security anchor for the user plane communication based on a result of the determination.

[0016] According to an aspect of the invention, a first network entity is disclosed. The first network entity is configured to perform the method for the User Plane for handling a communication towards a user equipment (UE). The first network entity comprises a memory, a processing unit and a transceiver. The memory comprises a code, which when executed by the processing unit causes the first network entity to act as a User Plane and to handle a communication towards a user equipment (UE), wherein the first UE is communicating with the User Plane via a radio access network (RAN); receive a first message via the transceiver that has been transmitted by a Control Plane, wherein the first message comprises a first information, wherein the first information is indicating whether the User Plane should act as a security anchor for a user plane communication between the UE and the User Plane, determine whether the User Plane should act as a security anchor for the user plane communication of the UE based on the first information, and act as the security anchor for the user plane communication based on a result of the determination.

[0017] The User Plane is also referred to as UP. The Control Plane is also referred to as CP. The Control Plane is performing CP functions. The User Plane is performing UP functions. A CP function can interface multiple UP functions, and a UP function can be shared by multiple CP functions. Preferably, the User Plane is the User Plane of a core network and / or the Control Plane is the Control Plane of a core network.

[0018] Depending on the type of RAN that is used by the UE for connecting to the mobile communications network, the User Plane has to act as the security anchor or does not have to act as the security anchor. This means that the User Plane can either expect to receive an unencrypted user plane communication from the RAN, depending on the type of the RAN. Similarly, the User Plane has to decide whether encrypted or unencrypted user plane communication should be sent towards the RAN. In case the User Plane is acting as a security anchor, it will decrypt user plane communication that is received from the RAN and it will encrypt user plane communication that is sent to the RAN. In case the User Plane is not acting as a security anchor, it will not decrypt user plane communication that is received from the RAN and it will not encrypt user plane communication that is sent to the RAN.

[0019] In particular, the same method is performed by the User Plane for a further UE in a corresponding manner to determine whether the User Plane should act as a security anchor for a user plane communication between the further UE and the User Plane.

[0020] Aspects of the invention allow to open up for the possibility, with retained mobility flexibility, to move the UP security anchor in 6GS. This move allows to remove the IPSec that is used today between Core and RAN to secure the data which brings down the overall solution cost. If the UPF is RAT unaware then the solution won’t work as the RAN nodes may receive encrypted data when not expecting it or the other way around, receive unencrypted data when it expects encrypted data. The first issue can result in that the downlink payload isn’t properly understood by the receiver but the latter one is worse as it might open up a security / privacy hole in the solution by having no node encrypting the data.

[0021] The solution also enables that the same radio node, and especially the gNB, can be connected to a 5GC not supporting the enhancements and to an evolved 5GC supporting the enhancement, e.g., in a MOCN deployment where one operator has migrated to 6G while the other only supports 5G in 5GC.

[0022] In particular, the first information is indicating a radio access technology (RAT) type of the RAN. In particular, the RAT type of a RAN defines a standard that specifies the corresponding RAN. It is known for each RAT type whether the corresponding RAN comprises the security endpoint. Thus, it can be defined for the User Plane whether it should act as a security anchor for this RAT type and the UE that is connected via this RAT type.

[0023] In particular, it is determined that the User Plane should act as a security anchor for the user plane communication of the UE if the first information is indicating that the RAN is of a RAT type that is configured to terminate user plane security in a core network. In particular, it is it is determined that the User Plane should not act as a security anchor for the user plane communication of the UE if the first information is indicating that the RAN is of a RAT type that is configured to terminate user plane security in the RAN.

[0024] In particular, it is determined that the User Plane should act as a security anchor for the user plane communication of the UE if the first information is indicating that the RAN is a 6G RAN or an evolved 5G RAN, and / or it is determined that the User Plane should not act as a security anchor for the user plane communication of the UE if the first information is indicating that the RAN is a 5G RAN.

[0025] In particular, the first information is explicitly indicating if the User Plane should act as a security anchor for the user plane communication of the UE. Optionally, the Control Plane comprises a logic for determining whether the User Plane should act as a security anchor for the user plane communication between the UE and the User Plane to allow the communication between the fist UE and a further device, for example a further UE or a server. Upon this determination, the Control Plane can explicitly indicate to the User Plane on whether the User Plane should act as the security anchor for the user plane communication of the UE. Optionally, the User Plane acts as the security anchor for the user plane communication of the UE if the first information is received in the first message and the User Plane does not act as the security anchor for the user plane communication of the UE if the first information is not received in the first message.

[0026] In particular, the acting as the security anchor comprises encrypting and / or decrypting user data.

[0027] In particular, the first message is a Session Establishment request in particular a PFCP Session Establishment request. In particular, the first information is always sent in the Session Establishment request to ensure that the User Plane has sufficient information on whether it should act as the security anchor or not. In particular, the first information is sent in a RAT Type information element, wherein this information element is mandatory to provide the UP Function the current RAT Type for the PDN connection / PDU session. In the alternative, the first information is sent in a UP Security Anchor information element, wherein this information element is present if the CP has decided that the UP shall encrypt the user data over e.g., N3 or S1-U.

[0028] In particular, the User Plane is transmitting a User Plane capability indication to the Control plane prior to receiving the first message, wherein the User Plane capability indication is indicating that the User Plane is capable to act as a security anchor for the user plane communication between the UE and the User Plane. The User Plane capability indication is preferably sent as an Information Element (IE) in a PFCP Association Setup Response, wherein the information element is preferably the UP Function Features IE. For example, the UP Function Features IE comprises a Feature Octet for indicating UP security to indicate whether UP security anchor is supported by the UP function.

[0029] In particular, the first message is received over a N4 interface or an Sxa interface. In particular, the method further comprises receiving a second message that has been transmitted by the Control Plane, wherein the second message comprises a second information, wherein the second information is indicating whether the User Plane should act as the security anchor for the user plane communication between the UE and the User Plane, redetermining whether the User Plane should act as the security anchor for the user plane communication of the UE based on the second information, and acting as the security anchor for the user plane communication based on a result of the redetermination. This allows to handle scenarios in which the UE is switching from the RAN to a different RAN, wherein the different RAN is of a different RAT type than the initial RAN. That is, the User Plane can be updated to the actual scenario, for example after a handover between different RAT types.

[0030] In particular, the second message is a PFCP Session Modification Request.

[0031] According to an aspect of the invention, a method for a Control Plane for handling a communication towards a user equipment (UE), wherein the UE is communicating with a User Plane via a RAN. The method comprises transmitting a first message to the User Plane, wherein the first message comprises a first information, wherein the first information is indicating whether the User Plane should act as a security anchor for a user plane communication between the UE and the User Plane.

[0032] The method allows a Control Plane according to the invention to interact with a User Plane according to the invention. For this, the Control Plane is providing the necessary information to the User Plane to determine whether the User Plane should act as a security anchor for a user plane communication between the UE and the User Plane.

[0033] According to an aspect of the invention, a second network entity is disclosed. The second network entity is configured to perform the method for the Control Plane for handling a communication towards a user equipment. In particular, the second network entity comprises a memory, a processing unit and a transceiver, wherein the memory comprises a code, which when executed by the processing unit causes the second network entity to act as a Control Plane and to handle a communication towards a first UE, wherein the first UE is communicating with the User Plane via a RAN, transmit a first message to the User Plane, wherein the first message comprises a first information, wherein the first information is indicating whether the User Plane should act as a security anchor for a user plane communication between the UE and the User Plane.

[0034] In particular, the first information is indicating a type of the RAN. In particular, the first information is explicitly indicating if the User Plane should act as a security anchor for the user plane communication of the UE. It is preferable that the method for the Control Plane comprises a determination on whether the User Plane should act as the security anchor for the user plane communication between the UE and the User Plane and, depending on the outcome of the determination, the Control Plane is explicitly indicating if the User Plane should act as the security anchor for the user plane communication of the UE or not. In particular, the determination is performed by the Control Plane based on a type of the RAN. In particular, the first information is transmitted if it indicated that the User Plane should act as a security anchor for the user plane communication of the UE and the first information is not transmitted if it is indicated that the User Plane should not act as a security anchor for the user plane communication of the UE.

[0035] In particular, the first message is a Session Establishment request, in particular a PFCP Session Establishment request.

[0036] In particular the Control Plane is receiving a User Plane capability indication from the User Plane prior to transmitting the first message, wherein the User Plane capability indication is indicating that the User Plane is capable to act as a security anchor for the user plane communication between the UE and the User Plane. Optionally, the User Plane is transmitting a User Plane capability indication to the User Plane prior to transmitting the first message, wherein the User Plane capability indication is indicating that the Control Plane is capable to provide the necessary information to the User Plane that allows the User Plane to determine whether the User Plane should act as a security anchor for the user plane communication between the UE and the User Plane.

[0037] In particular, the first message is transmitted over a N4 interface or an Sxa interface.

[0038] In particular, the method further comprises determining if there is an ongoing HO procedure that will result in a RAT change for the UE, and transmitting a second message to the User Plane if a RAN change has been determined, wherein the second message comprises a second information, wherein the second information is indicating whether the User Plane should act as the security anchor for the user plane communication between the UE and the User Plane.

[0039] In particular, the second message is a PFCP Session Modification Request. Brief description of the drawings

[0040] Fig. 1 shows a mobile communications network that comprises network entities according to aspects of the invention, fig. 2 shows an exemplary signalling flow of a method according to an aspect of the invention, fig. 3 shows details in respect to a user plane communication in an mobile communication network that comprises network entities according to aspects of the invention, fig. 4 shows an exemplary structure of a first network entity or a second network entity according to aspects of the invention, and fig. 5 shows the location of a User Plane security termination for radio access networks according to the prior art.

[0041] Detailed

[0042] Figure 1 shows an exemplary mobile communications network that comprises network entities according to aspects of the invention. The mobile communications network comprises a first radio access network (RAN) 31 and a second RAN 32. The first RAN 31 and the second RAN are connected to a core network 40. A first user equipment (UE) 21 is communicating with the core network 40 via the first RAN 31. A second UE 22 is communicating with the core network 40 via the second RAN 32. A network entity can comprise one or more physical devices. A server 50 is connected to the core network 40. The first UE 21 is able to communicate with the second UE 22 and / or the server 50, wherein the communication towards the first UE 21 is handled by the core network 40.

[0043] As shown in Figure 2, the mobile communications network comprises a Control Plane (CP) 11 , wherein the Control Plane 11 is a plane of the mobile communications network that controls how data packets are forwarded and routed. The mobile communications network further comprises a User Plane (UP) 12, wherein the User Plane 12 is a plane of the mobile communications network that carries network user traffic. The Control Plane 11 is configured to perform CP functions. The User Plane 12 is configured to perform UP functions.

[0044] The first RAN 31 and the second RAN 32 can be different types of RAN, wherein it can be required that a security anchor is either provided in the respective RAN or in the core network 40. A security anchor is an entity that terminates a User Plane protection. The security anchor is provided by a software service that is configured for decrypting or encrypting data for the User Plane protection. The User Plane 12 is performing a method for handling a communication towards the first UE 21. Optionally, the User Plane 12 is performing a method for handling a communication towards the second UE 22 in a corresponding manner. The method is illustrated by example in Fig. 2, wherein the method for the User Plane 12 comprises the steps that are performed by the User Plane 12. The Control Plane 11 is performing a method for handling the communication towards the first UE 21. The method is illustrated by example in Fig. 2, wherein the method for the Control Plane 11 comprises the steps that are performed by the Control Plane 11.

[0045] In an initial phase the Control Plane 11 and the User Plane 12 are exchanging capability information. This is done in a PFCP (Packet Forwarding Control Protocol ) Association Establishment procedures that is performed between the Control Plane 11 and the User Plane 12. The Control Plane 11 is transmitting a PFCP Association Setup Request 1 to the User Plane 12, wherein the PFCP Association Setup Request 1 comprises an Information Element (IE) that is indicating that a UP security anchor is supported by the CP function.

[0046] Referring to this feature negotiation between the Control Plane 11 and the User plane 12 that occurs during the PFCP Association Establishment procedures, it is noted that information can be integrated into current 3GPP standards as follows:

[0047] Chapter 5.8.1 of 3GPP TS 29.244 cites:

[0048] 5.8.1 General

[0049] A PFCP Association shall be set up between the CP function and the UP function prior to establishing PFCP sessions on that UP function. Only one PFCP association shall be setup between a given pair of CP and UP functions, even if the CP and / or UP function exposes multiple IP addresses. A single PFCP association may also be setup between a SMF set and a UPF (see clause 5.22.2).

[0050] The CP function and the UP function shall support the PFCP Association Setup procedure initiated by the CP function (see clause 6.2.6.2). The CP function and the UP function may additionally support the PFCP Association Setup procedure initiated by the UP function (see clause 6.2.6.3).

[0051] A CP function may have PFCP Associations set up with multiple UP functions. A UP function may have PFCP Associations set up with multiple CP functions.

[0052] Skipping to next section in 3GPP TS 29.244, message content... (shortened list) Table 7.4.4. 1-1: Information Elements in a PFCP Association Setup Request

[0053] The underlined IE, CP Function Features, looks like this and can be adapted for indicating indi- eating that a UP security anchor is supported by the CP function (shortened list):

[0054] 8.2.58 CP Function Features

[0055] The CP Function Features IE indicates the features supported by the CP function. Only features having an impact on the (system-wide) UP function behaviour are signalled in this IE. It is coded as depicted in Figure 8.2.58-1.

[0056] Figure 8.2.58-1: CP Function Features

[0057] The CP Function Features IE takes the form of a bitmask where each bit set indicates that the corresponding feature is supported. Spare bits shall be ignored by the receiver. The same bitmask is defined for all PFCP interfaces.

[0058] The following table specifies the features defined on PFCP interfaces and the interfaces on which they apply. Table 8.2.58-1: CP Function Features

[0059] To allow an indication for the Control Plane 11 to indicate that UP security anchor is supported by the CP function, the following feature indication might be added to the CP Function Features:

[0060] In response to receiving the PFCP Association Setup Request 1 , the User Plane 12 is transmitting a PFCP Association Setup Response 2 to the Control Plane 11, wherein the PFCP Association Setup Response 2 comprises an Information Element (IE) that is indicating that the UP se- curity anchor is supported by the UP function, that is by the User Plane 12.

[0061] Consequently, the Control Plane 11 is receiving a User Plane capability indication from the User Plane 12 prior to transmitting a first message 3, wherein the User Plane capability indication is indicating that the User Plane is capable to act as a security anchor for the user plane commu- nication between the first UE 21 and the User Plane 12. Referring to this feature negotiation between the Control Plane 11 and the User plane 12 that occurs during the PFCP Association Establishment procedures, it is noted that information can be integrated into current 3GPP standards as follows: Ref 29.244 (shortened list)

[0062] Table 7.4.4.2-1: Information Elements in a PFCP Association Setup Response

[0063] The underlined IE, UP Function Features, looks like this and can be adapted for indicating that a UP security anchor is supported by the UP function (shortened list) as follows:

[0064] (shortened list)

[0065] 8.2.25 UP Function Features

[0066] The UP Function Features IE indicates the features supported by the UP function. It is coded as depicted in Figure 8.2.25-1.

[0067] Figure 8.2.25-1: UP Function Features The UP Function Features IE takes the form of a bitmask where each bit set indicates that the corresponding feature is supported. Spare bits shall be ignored by the receiver The same bitmask is defined for all PFCP interfaces.

[0068] The following table specifies the features defined on PFCP interfaces and the interfaces on which they apply.

[0069] Table 8.2.25-1: UP Function Features

[0070] To allow an indication for the User Plane 12 to indicate that UP security anchor is supported by the UP function, the following feature indication might be added to the CP Function Features:

[0071] If it is indicating that the User Plane 12 is capable to act as a security anchor for the user plane communication between the first UE 21 and the User Plane 12 and it is also indicated that the Control Plane 11 is capable to support this functionality, then it can be determined based on the following actions of the User Plane 12 and the Control Plane 11 whether the User Plane 12 should act as the security anchor for a user plane communication between the first UE 21 and the User Plane 12 or not.

[0072] To allow the User Plane 12 to determine whether it should act as a security anchor for the user plane communication of the first UE 21 or not, the Control Plane 12 is transmitting 110 the first message 3 to the User Plane 12, wherein the first message 3 comprises a first information, wherein the first information is indicating whether the User Plane 12 should act as the security anchor for a user plane communication between the first UE 21 and the User Plane 12. Accordingly, the User Plane 12 is receiving 101 the first message 3 that has been transmitted by the Control Plane 11 , wherein the first message 3 comprises the first information, wherein the first information is indicating whether the User Plane 12 should act as a security anchor for a user plane communication between the first UE 21 and the User Plane 12. In this example, the first message 3 is a PFCP Session Establishment Request. That is, the exchange of the first information can be integrated into a PFCP session establishment procedure, wherein the Control Plane is initiating the PFCP session establishment procedure.

[0073] The User Plane 12 is determining 102 whether the User Plane 12 should act as a security anchor for the user plane communication of the first UE 21 based on the received first information and is acting 103 as the security anchor for the user plane communication based on a result of the determination.

[0074] For transmitting the first information, it is noted that this can be integrated into current 3GPP standards as follows:

[0075] Referring to 3GPP 29.244 (shortened list), it is described:

[0076] 7.5.2 PFCP Session Establishment Request

[0077] 7.5.2.1 General

[0078] The PFCP Session Establishment Request shall be sent over the Sxa, Sxb, Sxc, N4 and N4mb interface by the CP function to establish a new PFCP session context in the UP function.

[0079] Table 7.5.2.1-1: Information Elements in a PFCP Session Establishment Request For indicating whether the User Plane 12 should act as the security anchor for a user plane communication between the first UE 21 and the User Plane 12, the above underlined RAT Type condition / comment needs to be updated to make the IE mandatory if the Control Plane 11 and User Plane 12 support the UP Security anchor feature.

[0080] With the above-described modification of the PFCP Session Establishment Request, the first information is indicating a radio access technology (RAT) type of the first RAN 31. The User Plane 12 determines that the User Plane 12 should act as the security anchor for the user plane communication of the first UE 21 if the first information is indicating that the first RAN 31 is of a RAT type that is configured to terminate user plane security in a core network, for example if if the first information is indicating that the first RAN 31 is a 6G RAN or an evolved 5G RAN. The User Plane 12 determines that the User Plane 12 should not act as the security anchor for the user plane communication of the first UE 21 if the first information is indicating that the first RAN 31 is of a RAT type that is configured to terminate user plane security in the first RAN 31 , for example if the first RAN 31 is a 5G RAN. That is, the User Plane is determining 102 whether the User Plane 12 should act as a security anchor for the user plane communication of the first UE 21 , and is acting 103 as the security anchor for the user plane communication based on a result of the determination.

[0081] In addition or in the alternative to communicating the RAT type, the first information is explicitly indicating if the User Plane 12 should act as a security anchor for the user plane communication of the first UE 21 . In this case, the Control Plane 11 determines that the User Plane 12 should act as the security anchor for the user plane communication of the first UE 21 and the following IE might be added to the PFCP Session Establishment Request:

[0082] With the above described modification of the PFCP Session Establishment Request, the first information is explicitly indicating if the User Plane 12 should act as a security anchor for the user plane communication of the first UE 21. Based on the explicit indication, the User Plane 12 determines if it should act as a security anchor for the user plane communication of the first UE 21. In particular, the User Plane 12 acts as the security anchor for the user plane communication of the first UE 21 if the first information is received in the first message 3 and the User Plane 12 does not act as the security anchor for the user plane communication of the first UE 21 if the first information is not received in the first message 3. When I RAT mobility occurs there is a need for the core network 40 to adapt to the different security requirement between the RATs once a UE, for example the first UE 21 , has been moved / relocated, hence the following message definition / comment can be updated / extended so that it makes sense that the UP security anchor logic builds on top of its presence.

[0083] In particular, upon determining 111 that there is an ongoing HO procedure that will result in a RAT change for the first UE 21 , the Control Plane 11 is transmitting a second message 4 to the User Plane 12, wherein the second message 4 comprises a second information, wherein the second information is indicating whether the User Plane 12 should act as the security anchor for the user plane communication between the first UE 21 and the User Plane 12. Accordingly, the User Plane 12 is receiving 104 the second message 4 that has been transmitted by the Control Plane 11, wherein the second message 4comprises the second information, wherein the second information is indicating whether the User Plane 12 should act as the security anchor for the user plane communication between the first UE 21 and the User Plane 12.

[0084] The User Plane 12 is redetermining 105 whether the User Plane 12 should act as the security anchor for the user plane communication of the first UE 21 based on the second information. Once the RAT change has been performed for the first UE 21, the User Plane 12 is acting 106 as the security anchor for the user plane communication based on a result of the redetermination. In case the User Plane 12 has already been acting as the security anchor for the user plane communication and the redetermination leads to the result that the User Plane 12 should not be acting as the security anchor for the user plane communication, the User Plane 12 will stop acting as the security anchor for the user plane communication. In case the User Plane 12 has not been acting as the security anchor for the user plane communication and the redetermination leads to the result that the User Plane 12 should be acting as the security anchor for the user plane communication, the User Plane 12 will start acting as the security anchor for the user plane communication.

[0085] In this example, the second message is a PFCP Session Modification Request.

[0086] For transmitting the second information, it is noted that this second information can be integrated into current 3GPP standard, for example by using of the following lEs, that is the IE named RAT Type or the UP Security Anchor, to the PFCP Session Modification Request as follows:

[0087] 3GPP 29.244 (shortened list) discloses: 7.5.4 PFCP Session Modification Request

[0088] 7.5.4. 1 General

[0089] The PFCP Session Modification Request is used over the Sxa, Sxb, Sxc, N4 and N4mb interface by the CP function to request the UP function to modify the PFCP session.

[0090] Table 7.5.4.1-1: Information Elements in a PFCP Session Modification Request

[0091] The RAT Type is already defined in 29.244 as an IE in the PFCP Session Modification Request. Thus, this information can be used as the second information and can be used as a basis for the re-determination.

[0092] As an alternative the UP Anchor Security IE can be added to the PFCP Session Modification Request for explicit logic, which may be beneficial many times as the features evolve over the years.

[0093] When I RAT connected mode mobility occurs there is a need for the CN to indirectly forward the user data between the RATs meaning that the User Plane function and therefore the User Plane 12 needs to know which target RAT the first UE 21 is about to be moved to, hence the PFCP Session Modification Request need to be updated to also include:

[0094] Figure 3 shows details in respect to a user plane communication in an mobile communication network that comprises network entities according to aspects of the invention.

[0095] In the scenario of Figure 3, three UEs 20 are connected to a Core Network, wherein the Core

[0096] Network comprises a Mobility Management Entity (MME), an enhanced Access and Mobility Management Function (eAMF). The core network further comprises an enhanced User Plane Function (eUPF) and / or Serving Gateway User plane function (SGW-U).

[0097] Three RAN systems 30 are connected to the core network. The RAN systems 30 are of different RAT types. All links for user plane communication between the different UEs 20 and the User Plane 12 of the Core Network, here the eUPF or SGW-U, are indicated by the use of bold lines. A user plane communication of the UEs 20 with an applied user plane protection are indicated by bold dotted lines and are terminated by an entity that is acting as a corresponding security anchor SA.

[0098] The first UE 21 is connected to the core network via the first RAN 31 , wherein the first RAN 31 is an NR RAN. The first RAN 31 comprises a gNodeB (gNB), the gNB comprising a gNB CU-CP (Central Unit Control Plane), a gNB CU-UP (Central Unit User Plane) and a gNB DU (Distributed Unit). The gNB CU-UP acts a security anchor for the first RAN 31 and a user plane protection of the first UE 21 is terminated at the gNB CU-UP. The further user plane communication towards the core network is either unencrypted or encrypted by using a different technology than the user plane protection, for example by IPsec.

[0099] The second UE 22 is connected to the core network via the second RAN 32, wherein the second RAN 32 is a 6G RAN. The second RAN 32 comprises a 6G-NB RAN and a 6G NB RU. The second RAN 32 does not act as a security anchor for the second RAN 32 and a user plane protection of the second UE 22 is terminated at the core network, in particular by the User Plane 12 (eUPF / SGW-U) of the core network.

[0100] The third UE 23 is connected to the core network via the third RAN 33, wherein the third RAN 33 is a LTE RAN. The third RAN 33 comprises eNodeB (eNB). The eNB acts a security anchor for the third RAN 33 and a user plane protection of the third UE 23 is terminated at the eNB. The further user plane communication towards the core network is either unencrypted or encrypted by using a different technology than the user plane protection, for example by IPsec.

[0101] The first UE 21 , the second UE 22 and the third UE 33 are illustrated together to show the different requirements for handling the user plane communication. However, the methods according to this disclosure allow a handover of one UE, such that a single UE can be handed over between different RAT types. For example, the second UE 22 of Figure 3 can be the same device as the first UE 21 but after handover from the first RAN 31 to the second RAN 32.

[0102] As can be seen from Figure 3, the first RAN 31 and the third RAN 33 are providing the security anchor for the user plane communication of the UEs 21 , 23 that are connected to these RAN systems. In this case, the methods according to the invention allow the User Plane 21 of the core network to determine that it should not act as the security anchor for the user plane communication between the UE 21, 23 and the User Plane 12. Contrary to this, the second RAN 32 is not providing the security anchor for the user plane communication of the second UE 22 that is connected to the second RAN 32. In this case, the methods according to the invention allow the User Plane 21 of the core network to determine that it should act as the security anchor for the user plane communication between the second UE 22 and the User Plane 12.

[0103] It is noted that any of the UEs 20 can be seen as the first UE 21 and that the User Plane 12 will act as the security anchor for this UE or will not act as the security anchor for this UE depending on whether the RAT type of the RAN that is used by the UE is already acting as the security anchor or nor.

[0104] For a handover from the first RAN 31 to the second RAN 32, that is from 5G to 6G mobility, a Source RAN, gNB, receives un-encrypted traffic from the core network 40 for the user plane communication and a Target RAN, 6G-NB RU, shall receive encrypted traffic from the core network 40 for the user plane communication.

[0105] For a handover from the second RAN 32 to the first RAN 31 , that is from 6G to 5G mobility, a Source RAN, 6G-NB RU receives encrypted traffic from the core network 40 for the user plane communication and a Target RAN, gNB, shall receive un-encrypted traffic from the core network 40 for the user plane communication.

[0106] For a handover between two RAN systems of the same type as the second RAN 32, this would lead to a scenario of Intra 6G mobility. In this case, both Source and Target RAN receive encrypted traffic from the core network 40 for the user plane communication.

[0107] Figure 4 shows a network entity that can be a first network entity 200 according to aspects of the invention or a second network entity 300 according to aspects of the invention.

[0108] Considering that Figure 4 is showing the first network entity 200 according to aspects of the invention, the first network entity 200 comprises a memory 201, a processing unit 202 and a transceiver 203, wherein the memory 201 comprises a code, which when executed by the processing unit 202 causes the first network entity 200 to act as the User Plane 12 and to handle a communication between the first UE 21 and the second UE 22. Further than that, the code causes the first network entity 200 to perform the actions of the User Plane 12 that are described for the method 100 as shown by example with Figure 2. Any transmission or reception of messages is performed via the transceiver 203. Considering that Figure 4 is showing the second network entity 300 according to aspects of the invention, the second network entity 300 comprises a memory 301 , a processing unit 302 and a transceiver 303, wherein the memory 301 comprises a code, which when executed by the pro- cessing unit 302 causes the second network entity 300 to act as the Control Plane 11 and to handle a communication between the first UE 21 and the second UE 22. Further than that, the code causes the second network entity 300 to perform the actions of the Control Plane 11 that are described for the method 100 as shown by example with Figure 2. Any transmission or reception of messages is performed via the transceiver 203.

[0109] The methods discussed above may alternatively be implemented by means of a system based on network functions virtualization.

Claims

Claims1. A method (100) for a User Plane (12) for handling a communication towards a user equipment, UE (21), wherein the UE (21) is communicating with the User Plane (12) via a RAN (31), the method comprising: receiving (101) a first message (3) that has been transmitted by a Control Plane (11), wherein the first message (3) comprises a first information, wherein the first information is indicating whether the User Plane (12) should act as a security anchor for a user plane communication between the UE (21) and the User Plane (12); determining (102) whether the User Plane (12) should act as a security anchor for the user plane communication of the UE (21) based on the first information; and acting (103) as the security anchor for the user plane communication based on a result of the determination.

2. The method according to claim 1, wherein the first information is indicating a radio access technology, RAT, type of the RAN (31).

3. The method according to claim 2, wherein it is determined that the User Plane (12) should act as a security anchor for the user plane communication of the UE (21) if the first information is indicating that the RAN (31) is of a RAT type that is configured to terminate user plane security in a core network; and / or it is determined that the User Plane (12) should not act as a security anchor for the user plane communication of the UE (21) if the first information is indicating that the RAN (31) is of a RAT type that is configured to terminate user plane security in the RAN (31).

4. The method according to any one of claims 2 and 3, wherein it is determined that the User Plane (12) should act as a security anchor for the user plane communication of the UE (21) if the first information is indicating that the RAN (31) is a 6G RAN or an evolved 5G RAN; and or it is determined that the User Plane (12) should not act as a security anchor for the user plane communication of the UE (21) if the first information is indicating that the RAN (31) is a 5G RAN.

5. The method according to claim 1, wherein the first information is explicitly indicating if the User Plane (12) should act as a security anchor for the user plane communication of the UE (21), wherein preferably the User Plane (12) acts as the security anchor for the user plane communication of the UE (21) if the first information is received in the first message (3) and the UserPlane (12) does not act as the security anchor for the user plane communication of the UE (21) if the first information is not received in the first message (3).

6. The method according to any one of claims 1 to 5, wherein acting as the security anchor comprises encrypting and / or decrypting user data.

7. The method according to any one of claims 1 to 6, wherein the first message is a Session Establishment request, in particular a PFCP Session Establishment request.

8. The method according to any one of claims 1 to 7, wherein the User Plane is transmitting a User Plane capability indication to the Control plane prior to receiving the first message (3), wherein the User Plane capability indication is indicating that the User Plane is capable to act as a security anchor for the user plane communication between the UE (21) and the User Plane (12).

9. The method according to any one of claims 1 to 8, wherein the first message is received over a N4 interface or an Sxa interface.

10. The method according to any one of claims 1 to 8, the method further comprising: receiving (104) a second message (4) that has been transmitted by the Control Plane (11), wherein the second message (4) comprises a second information, wherein the second information is indicating whether the User Plane (12) should act as the security anchor for the user plane communication between the UE (21) and the User Plane (12); redetermining (105) whether the User Plane (12) should act as the security anchor for the user plane communication of the UE (21) based on the second information; and acting (106) as the security anchor for the user plane communication based on a result of the redetermination.

11. The method according to claim 10, wherein the second message is a PFCP Session Modification Request.

12. A first network entity (200), the network entity comprising a memory (201), a processing unit (202) and a transceiver (203), wherein the memory (201) comprises a code, which when executed by the processing unit (202) causes the first network entity (200) to: act as a User Plane (12) and to handle a communication towards a user equipment, UE (21), wherein the UE (21) is communicating with the User Plane (12) via a RAN (31); receive (101) a first message (3) via the transceiver (203) that has been transmitted by a Control Plane (11), wherein the first message (3) comprises a first information, wherein thefirst information is indicating whether the User Plane (12) should act as a security anchor for a user plane communication between the UE (21) and the User Plane (12), and determine (102) whether the User Plane (12) should act as a security anchor for the user plane communication of the UE (21) based on the first information; and act (103) as the security anchor for the user plane communication based on a result of the determination.

13. The first network entity (200) according to claim 12, wherein the memory (201) comprises a code, which when executed by the processing unit (202) causes the first network entity (200) to perform the method according to any one of claims 2 to 11.

14. A method (100) for a Control Plane (11) for handling a communication towards a user equipment, UE (21), wherein the UE (21) is communicating with a User Plane (12) via a RAN (31), the method comprising: transmitting (101) a first message (3) to the User Plane (12), wherein the first message (3) comprises a first information, wherein the first information is indicating whether the User Plane (12) should act as a security anchor for a user plane communication between the UE (21) and the User Plane (12).

15. The method according to claim 14, wherein the first information is indicating a type of the RAN (31).

16. The method according to claim 14, wherein the first information is explicitly indicating if the User Plane (12) should act as a security anchor for the user plane communication of the UE (21), wherein preferably the first information is transmitted if it indicated that the User Plane (12) should act as a security anchor for the user plane communication of the UE (21) and the first information is not transmitted if it is indicated that the User Plane (12) should not act as a security anchor for the user plane communication of the UE (21).

17. The method according to any one of claims 14 to 16, wherein the first message (3) is a Session Establishment request, in particular a PFCP Session Establishment request.

18. The method according to any one of claims 14 to 17, wherein the Control Plane is receiving a User Plane capability indication from the User Plane (12) prior to transmitting the first message (3), wherein the User Plane capability indication is indicating that the User Plane is capable to act as a security anchor for the user plane communication between the UE (21) and the User Plane (12).

19. The method according to any one of claims 14 to 18, wherein the first message is transmitted over a N4 interface or an Sxa interface.

20. The method according to any one of claims 14 to 19, the method further comprising: determining if there is an ongoing HO procedure that will result in a RAT change for the UE(21), and transmitting (104) a second message (4) to the User Plane (12) if a RAN change has been determined, wherein the second message (4) comprises a second information, wherein the second information is indicating whether the User Plane (12) should act as the security anchor for the user plane communication between the UE (21) and the User Plane (12).

21. The method according to claim 20, wherein the second message is a PFCP Session Modification Request.

22. A second network entity (300), the network entity comprising a memory (301), a processing unit (302) and a transceiver (303), wherein the memory device comprises a code, which when executed by the processing unit (202) causes the second network entity (300) to: act as a Control Plane (11) and to handle a communication towards a user equipment, UE (21), wherein the UE (21) is communicating with the User Plane (12) via a RAN (31); and transmit (110) a first message (3) to the User Plane (12), wherein the first message (3) comprises a first information, wherein the first information is indicating whether the User Plane (12) should act as a security anchor for a user plane communication between the UE (21) and the User Plane (12).

23. The second first network entity (300) according to claim 22, wherein the memory (301) comprises a code, which when executed by the processing unit (302) causes the second network entity (300) to perform the method according to any one of claims 14 to 21.

Citation Information

Patent Citations

  • Secure Session Method And Apparatus

    US20210168594A1

  • Communication method and apparatus

    US20250024261A1

  • Security policy processing method and related device

    WO2018187961A1

  • Communication method and apparatus

    WO2023185558A1