Apparatuses and communication methods

A distributed NAS security policy in 5G networks addresses the limitations of centralized AMF by allowing flexible access rules, enhancing security and performance through optimized resource usage and secure direct signaling.

WO2026029844A1PCT designated stage Publication Date: 2026-02-05INNOPEAK TECHNOLOGY INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/031361
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-31
Filing Date
2025-05-29
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing 5G networks rely on a centralized Access and Mobility Management Function (AMF) for NAS security, leading to bottlenecks, inadequate security flexibility, and increased vulnerability due to a single NAS security policy that cannot meet diverse security requirements.

Method used

Implement a distributed Non-Access Stratum (NAS) security policy that allows for flexible access rules, including allowed, conditional, or denied access to network functions, enabling direct NAS signaling between the UE and specific network functions while maintaining security and performance.

Benefits of technology

Enhances network security and performance by optimizing resource usage, reducing AMF overload, and ensuring secure communication without compromising on flexibility and compatibility with existing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025031361_05022026_PF_FP_ABST
    Figure US2025031361_05022026_PF_FP_ABST
Patent Text Reader

Abstract

A wireless communication method performed by a user equipment (UE) includes performing an authentication procedure with a network device to establish a security context between the UE and a first network function of the network device and determining that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, comprising at least one of the following: allowed access, conditional access, or not allowed access to network functions.
Need to check novelty before this filing date? Find Prior Art

Description

APPARATUSES AND COMMUNICATION METHODSCROSS REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to U.S. Provisional Application No. 63 / 677,938, entitled “METHOD FOR DISTRIBUTED NAS SECURITY POLICY IN A COMMUNICATION SYSTEM,” filed on July 31, 2024, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication systems, and more particularly, to apparatuses and wireless communication methods.BACKGROUND

[0003] In wireless communication networks, security policies ensure secure communication between a user equipment (UE) and network functions. Existing 5G networks rely on a single non- access stratum (NAS) security policy managed by an access and mobility management function (AMF) to protect NAS signaling. However, this centralized approach has several limitations: AMF bottleneck: All UEs depend on the AMF for requesting and receiving services from other network functions, leading to potential overloading and performance degradation. Lack of security flexibility: A single NAS security policy cannot meet the diverse security requirements of different network functions, some of which may require higher security levels. Vulnerability of sensitive functions: Allowing NAS signaling to terminate in highly secure network functions without adequate protection increases the risk of unauthorized access.

[0004] These limitations highlight the need for a flexible NAS security policy that can adapt to different security requirements without overloading the AMF.SUMMARY

[0005] An object of the present disclosure is to propose apparatuses and wireless communication methods, which can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0006] In a first aspect of the present disclosure, a wireless communication method performed by a user equipment (UE) includes performing an authentication procedure with a network device to establish a security context between the UE and a first network function of the network device and determining that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. i

[0007] In a second aspect of the present disclosure, a wireless communication method performed by a network device includes performing an authentication procedure with a user equipment (UE) to establish a security context between the UE and a first network function of the network device and determining that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions.

[0008] In a third aspect of the present disclosure, a user equipment (UE), includes an executor configured to perform an authentication procedure with a network device to establish a security context between the UE and a first network function of the network device and a determiner configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions.

[0009] In a fourth aspect of the present disclosure, a user equipment (UE) includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The UE is configured to perform the above method.

[0010] In a fifth aspect of the present disclosure, a network device, includes an executor configured to perform an authentication procedure with a user equipment (UE) to establish a security context between the UE and a first network function of the network device and a determiner configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions.

[0011] In a sixth aspect of the present disclosure, a network device includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The network device is configured to perform the above method.

[0012] In a seventh aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.

[0013] In an eighth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.

[0014] In a ninth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.

[0015] In a tenth aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.

[0016] In an eleventh aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obvious that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.

[0018] FIG. 1 is a block diagram of a user equipment (UE) and a network device of communication in a communication system according to an embodiment of the present disclosure.

[0019] FIG. 2 is a block diagram of a UE according to an embodiment of the present disclosure.

[0020] FIG. 3 is a block diagram of a UE according to an embodiment of the present disclosure.

[0021] FIG. 4 is a flowchart illustrating a wireless communication method performed by a UE according to an embodiment of the present disclosure.

[0022] FIG. 5 is a block diagram of a network device according to an embodiment of the present disclosure.

[0023] FIG. 6 is a block diagram of a network device according to an embodiment of the present disclosure.

[0024] FIG. 7 is a flowchart illustrating a wireless communication method performed by a network device according to an embodiment of the present disclosure.

[0025] FIG. 8A is a schematic diagram illustrating a service-based architecture (SBA) architecture according to an embodiment of the present disclosure.

[0026] FIG. 8B is a schematic diagram illustrating a proposed SBA architecture enhancement according to an embodiment of the present disclosure.

[0027] FIG. 9 is a flowchart illustrating an example of using a distributed NAS security policy in 5G according to an embodiment of the present disclosure.

[0028] FIG. 10 is a flowchart illustrating an example of using a distributed NAS security policy in 5G according to an embodiment of the present disclosure.

[0029] FIG. 11 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.

[0030] FIG. 12 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS

[0031] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.

[0032] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, a LTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.

[0033] Optionally, a user equipment (UE) mentioned in the embodiments of the present application may refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal may be a cellular radio telephone, a cordless telephone, a session initiation protocol (SIP) telephone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device, other processing devices coupled with a wireless modem, an in- vehicle device, a wearable device, a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), etc.

[0034] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.

[0035] Distributed non-access stratum (NAS) is a new concept in 3rd generation partnership project (3GPP) architecture. Although security policies are not new, and many existing policies guide aspects such as when to apply user plane integrity protection, distributed NAS introduces unique security considerations.

[0036] Current security policies are not applicable to distributed NAS because the security requirements and motivations are fundamentally different. Moreover, the existing security architecture in 5G only supports a single NAS security policy for protecting NAS signaling. In this architecture, an access and mobility management function (AMF) serves as a bottleneck for a UE to access services from other network functions. Since all UEs rely on the AMF to request and receive services from other network functions, the AMF may become overburdened.

[0037] Another drawback is that a single NAS security policy cannot meet all security requirements in an enhanced architecture. For example, some network functions may require higher levels of security protection and more restricted access. Allowing NAS signaling to terminate in such highly restricted or security-critical network functions can expose those functions to unwarranted vulnerabilities.

[0038] Some embodiments of the present disclosure provide a mechanism for implementing a distributed NAS security policy in a communication system.

[0039] FIG. 1 illustrates that, in some embodiments, a UE 10 and a network device 20 of communication in a communication system 40. The communication system 40 includes the UE 10 and the network device 20. The UE 10 may include a memory 12, a transceiver 13, and a processor 11 coupled to the memory 12 and the transceiver 13. The network device 20 may include a memory 22, a transceiver 23, and a processor 21 coupled to the memory 22 and the transceiver 23. The processor 11 or 21 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 11 or 21. The memory 12 or 22 is operatively coupled with the processor 11 or 21 and stores a variety of information to operate the processor 11 or 21. The transceiver 13 or 23 is operatively coupled with the processor 11 or 21, and the transceiver 13 or 23 transmits and / or receives a radio signal.

[0040] The processor 11 or 21 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 12 or 22 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 13 or 23 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 12 or 22 and executed by the processor 11 or 21. The memory 12 or 22 can be implemented within the processor 11 or 21 or external to the processor 11 or 21 in which case those can be communicatively coupled to the processor 11 or 21 via various means as is known in the art.

[0041] In some embodiments, the processor 11 is configured to perform an authentication procedure with the network device 20 to establish a security context between the UE 10 and a first network function of the network device 20, and the processor 11 is configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE 10, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0042] In some embodiments, the processor 21 is configured to perform an authentication procedure with the UE 10 to establish a security context between the UE 10 and a first network function of the network device 20, and the processor 21 is configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE 10, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0043] FIG. 2 illustrates a UE 200 according to an embodiment of the present disclosure. The UE 200 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the UE 200 using any suitably configured hardware and / or software. The UE 200 includes an executor 201 and a determiner 202. The executor 201 is configured to perform an authentication procedure with a network device to establish a security context between the UE 200 and a first network function of the network device, and the determiner 202 is configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE 200, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0044] FIG. 3 illustrates a UE 300 according to an embodiment of the present disclosure. The UE 300 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the UE 300 using any suitably configured hardware and / or software. The UE 300 may include a memory 301, a transceiver 302, and a processor 303 coupled to the memory 301 and the transceiver 302. The processor 303 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 303. The memory 301 is operativelycoupled with the processor 303 and stores a variety of information to operate the processor 303. The transceiver 302 is operatively coupled with the processor 303, and the transceiver 302 transmits and / or receives a radio signal. The processor 303 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 301 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 302 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 301 and executed by the processor 303. The memory 301 can be implemented within the processor 303 or external to the processor 303 in which case those can be communicatively coupled to the processor 303 via various means as is known in the art.

[0045] In some embodiments, the processor 303 is configured to perform an authentication procedure with a network device to establish a security context between the UE 300 and a first network function of the network device, and the processor 303 is configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0046] FIG. 4 illustrates a wireless communication method 400 performed by a UE according to an embodiment of the present disclosure. The wireless communication method 400 performed by the UE is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the wireless communication method 400 performed by the UE using any suitably configured hardware and / or software. In some embodiments, the wireless communication method 400 performed by the UE includes: an operation 402, performing an authentication procedure with a network device to establish a security context between the UE and a first network function of the network device, and an operation 404, determining that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0047] In some embodiments, the distributed NAS security policy is received by the UE from a second network function of the network device through the first network function. In some embodiments, the distributed NAS security policy is maintained by the first network function. In some embodiments, the wireless communication method further includes making a service request to a third network function of the network node and establishing, based on the distributed NAS security policy, direct NAS security between the UE and the third network function by creating a NAS security context at the first network function. In some embodiments, the wireless communication method further includes receiving the NAS security context from the first network function and using the NAS security context for subsequent NAS signaling between the UE and the third network function. In some embodiments, the wireless communication method further includes making a service request to a fourth network function and using a current NAS security context between the UE and the first network function for NAS signaling between the UE and the fourth network function.

[0048] In some embodiments, the wireless communication method further includes determining a signaling, a service-related request, or a message exchange between the UE and the fourth network function using a service-based architecture (SBA) procedure, wherein the first network function acts as a relay between the UE and the fourth network function. In some embodiments, the first network function is an access and mobility management function (AMF), the second network function is a session management function (SMF), the third network function is NFx, and the fourth network function is NFy. In some embodiments, the distributed NAS security policy is sent to the UE after the UE successfully authenticates with the network device, and before the UE makes a service request to the network device. In some embodiments, the distributed NAS security policy is configured to allow the UE to establish direct NAS signaling with a network function if a security sensitivity of the network function is determined to be below a predetermined threshold. In some embodiments, the distributed NAS security policy prohibits the UE from directlyaccessing the network function if the security sensitivity of the network function is determined to exceed the predetermined threshold, and any service request to the network function is relayed through the first network function. In some embodiments, the distributed NAS security policy is dynamically updated by the network device based on network conditions or policy changes.

[0049] FIG. 5 illustrates a network device 500 according to an embodiment of the present disclosure. The network device 500 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the network device 500 using any suitably configured hardware and / or software. The network device 500 includes an executor 501 and a determiner 502. The executor 501 is configured to perform an authentication procedure with a user equipment (UE) to establish a security context between the UE and a first network function of the network device 500, and the determiner 502 is configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0050] FIG. 6 illustrates a network device 600 according to an embodiment of the present disclosure. The network device 600 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the network device 600 using any suitably configured hardware and / or software. The network device 600 may include a memory 601, a transceiver 602, and a processor 603 coupled to the memory 601 and the transceiver 602. The processor 603 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 603. The memory 601 is operatively coupled with the processor 603 and stores a variety of information to operate the processor 603. The transceiver 602 is operatively coupled with the processor 603, and the transceiver 602 transmits and / or receives a radio signal. The processor 603 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 601 may include read-only memory (ROM),random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 602 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 601 and executed by the processor 603. The memory 601 can be implemented within the processor 603 or external to the processor 603 in which case those can be communicatively coupled to the processor 603 via various means as is known in the art.

[0051] In some embodiments, the processor 603 is configured to perform an authentication procedure with a user equipment (UE) to establish a security context between the UE and a first network function of the network device 600, and the processor 603 is configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy and / or enhance network security and performance.

[0052] FIG. 7 illustrates a wireless communication method 700 performed by a network device according to an embodiment of the present disclosure. The wireless communication method 700 performed by the network device is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the wireless communication method 700 performed by the network device using any suitably configured hardware and / or software. In some embodiments, the wireless communication method 700 performed by the network device includes: an operation 702, performing an authentication procedure with a user equipment (UE) to establish a security context between the UE and a first network function of the network device, and an operation 704, determining that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, including at least one of the following: allowed access, conditional access, or not allowed access to network functions. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide a flexible distributed NAS security policy n and / or enhance network security and performance.

[0053] In some embodiments, the distributed NAS security policy is transmitted to the UE from a second network function of the network device through the first network function. In some embodiments, the distributed NAS security policy is maintained by the first network function. In some embodiments, the wireless communication method further includes receiving, by a third network function of the network node, a service request from the UE and establishing, based onthe distributed NAS security policy, direct NAS security between the UE and the third network function by creating a NAS security context at the first network function. In some embodiments, the wireless communication method further includes transmitting, by the first network function, the NAS security context to the UE and using the NAS security context for subsequent NAS signaling between the UE and the third network function. In some embodiments, the wireless communication method further includes receiving, by a fourth network function, a service request from the UE and using a current NAS security context between the UE and the first network function for NAS signaling between the UE and the fourth network function.

[0054] In some embodiments, the wireless communication method further includes performing a signaling, a service-related request, or a message exchange between the UE and the fourth network function using a service-based architecture (SBA) procedure, wherein the first network function acts as a relay between the UE and the fourth network function. In some embodiments, the first network function is an access and mobility management function (AMF), the second network function is a session management function (SMF), the third network function is NFx, and the fourth network function is NFy. In some embodiments, the distributed NAS security policy is sent to the UE after the network device successfully authenticates with the UE, and before the network device receives a service request from the UE. In some embodiments, the distributed NAS security policy is configured to allow the UE to establish direct NAS signaling with a network function if a security sensitivity of the network function is determined to be below a predetermined threshold. In some embodiments, the distributed NAS security policy prohibits the UE from directly accessing the network function if the security sensitivity of the network function is determined to exceed the predetermined threshold, and any service request to the network function is relayed through the first network function. In some embodiments, the distributed NAS security policy is dynamically updated by the network device based on network conditions or policy changes.

[0055] Examples:

[0056] NAS is defined in the 3GPP system for carrying signaling between a UE and a core network (e.g., mobility management entity (MME) or access and mobility management function (AMF)). All NAS signaling from the UE to the network must pass through the AMF, even when the signaling is intended for authenticating the UE with other network functions within the 3GPP network.

[0057] In 5G, 3GPP has adopted a service-based architecture (SBA) illustrated in FIG. 8A, where network functions communicate with each other through a service-based interface. However, the UE can only communicate with the AMF over the N1 interface, which is specifically designated for NAS signaling.

[0058] One of the limitations of the SBA is that when other network functions (NFs) need to provide a service to UE, for instance, when an application function (AF) such as a location management function (LMF) provides location services to the UE, there is no direct signaling path from the UE to the LMF. Instead, the signaling must first travel from the UE to the AMF via the N1 interface, after which the AMF forwards the signaling to the LMF. This process introduces unnecessary signaling delays and increases the AMF's overhead, particularly when the service being provided is time-sensitive (e.g., precision location services).

[0059] In future network upgrades (e.g., 6G), consideration is being given to allowing NAS signaling (e.g., a distributed NAS architecture) to be directly routed between the UE and another network function other than the AMF within the enhanced service-based network architecture, as illustrated in FIG. 8B.

[0060] Some embodiments of the present disclosure provide a mechanism for implementing a flexible distributed NAS security policy to support distributed NAS in a communication network.

[0061] In some examples, a flexible distributed NAS security policy supporting distributed NAS in an enhanced service-based architecture consists of rules that govern how UE can access network functions within the network. These rules can specify one of three access levels: allowed access, conditional access, or denied access.

[0062] In some examples, a distributed NAS security policy can be provided to the UE after the UE successfully authenticates with the network but before it accesses or requests services from any network function. The UE must comply with the distributed NAS security policy when making service requests to other network functions.

[0063] In some examples, a flexible distributed NAS security policy can also be applied at the network level, with the network acting as the enforcement entity. Subsequent service requests from the UE to network functions are guided by this distributed NAS security policy.

[0064] In a network that supports both distributed NAS signaling and hop-by-hop NAS signaling (such as the current NAS protocol used in both 4G and 5G), the UE must still register and authenticate with the network to establish NAS signaling protection. Upon successful authentication, a flexible security policy supporting distributed NAS is sent to the UE.

[0065] Depending on the security level of the network functions, the security policy may grant the UE unrestricted access to the network function, allow conditional access, or entirely prohibit access to the network function.

[0066] For example, a unified data management (UDM) is a highly protected network function that stores critical UE subscription data and must be safeguarded from direct UE access via NAS signaling. To protect the UDM, it is in the network operator's best interest to restrict access to theUDM, specifically, allowing access only through the AMF or another trusted network function within the core network, rather than directly from any UE in the network.

[0067] In this scenario, the security policy for UE access to the UDM is set to "NOT allowed." Although the UE may still request services involving the UDM (e.g., re-authentication), the NAS signaling would terminate at the AMF. This approach minimizes security exposure to the UDM by preventing direct access from the UE.

[0068] In another example, a UE that has subscribed to location services may need to access a LMF to request such services. Since the LMF is considered less critical compared to the UDM function, the security policy for accessing the LMF is set to "conditional." This means the network may establish NAS signaling security directly between the UE and the LMF.

[0069] In the same scenario, if the UE's requests for location services are infrequent, even though the security policy permits direct NAS signaling to the LMF, the network may choose not to establish a direct NAS signaling connection to the LMF due to performance considerations. Instead, access to the LMF is still routed through the AMF. This approach reduces the need for maintaining a dedicated security context between the UE and the LMF, optimizing resource usage.

[0070] Beyond security considerations, performance trade-offs are also a factor in determining whether the UE and the network function should establish a direct NAS connection (and the corresponding NAS security context).

[0071] An example of how a distributed NAS security policy is applied is illustrated in FIG. 9 below. FIG. 9 illustrates that, in some examples, the wireless communication method includes at least one of the following operations.

[0072] Operation 1 : When a UE requests access to the network, it must first undergo an authentication process with the network. Upon successful authentication, a security context is established between the UE and an AMF. At this point, all NAS signaling between the UE and the network is managed by the AMF, with the signaling terminating at the AMF as the central point for secure communication.

[0073] Operation 2: After successful authentication, a distributed NAS security policy is sent to the UE from a SMF or another network function via the AMF. Upon receiving this policy, the UE replaces any previously configured distributed NAS security policy with the newly received one. This policy defines the conditions under which distributed NAS security should be established and specifies the types of service requests that may trigger direct NAS security with specific network functions.

[0074] Operation 3 : When the UE initiates a service request to network function NFx, the process is guided by the distributed NAS security policy previously received by the UE. If this policyspecifies that a direct NAS security context should be established between the UE and NFx, the AMF takes action to create this dedicated security context. This UE-NFx NAS security context is specifically established to secure direct communication between the UE and NFx, ensuring that NAS signaling is protected according to the defined security rules.

[0075] Operations 4a and 4b: Once the AMF establishes the UE-NFx NAS security context, the AMF transmits this newly created security context to both the UE and network function NFx. The AMF also provides a signal to both the UE and NFx, instructing them to use this security context for all subsequent NAS signaling between them. This ensures that any further communication between the UE and NFx is securely protected under the established NAS security context.

[0076] Operation 5: Following the receipt of the NAS security context from the AMF, both the UE and NFx begin using this security context to protect their NAS signaling. This means that all NAS messages exchanged between the UE and NFx are now encrypted and authenticated according to the established security context, ensuring secure communication between the two entities.

[0077] Operation 6: Subsequently, the UE initiates a service request to another network function, NFy. This request is processed according to the distributed NAS security policy that the UE has received, which determines how the UE establishes a secure connection with NFy, whether through direct signaling or via a relay through the AMF.

[0078] Operation 7: Since the distributed NAS security policy specifies that the service request to Network Function NFy should reuse the existing UE-AMF NAS security context, the AMF does not create a new NAS security context. Instead, the UE continues to rely on the already established NAS security context between itself and the AMF for secure communication with NFy. This approach minimizes the overhead associated with creating multiple security contexts while maintaining secure communication.

[0079] Operation 8: Any signaling, service-related request, or message exchange between the UE and NFy is now managed by the AMF. The AMF forwards these communications using SBA procedures between itself and NFy. In this configuration, the AMF functions as a relay between the UE and NFy, ensuring that messages are securely exchanged without the need for a direct NAS security context between the UE and NFy.

[0080] In another example of a distributed NAS security policy, only the AMF is responsible for enforcing the distributed NAS security policy. In this configuration, the difference is that in operation 2, the distributed NAS security policy is retained within the network and is not transmitted to the UE. Specifically, the policy is sent only to the AMF, which uses it to manage and enforce security rules for NAS signaling between the UE and various network functions. Thisapproach maintains centralized control over NAS security while reducing the complexity of distributing and managing security policies directly on the UE. An example of this configuration is illustrated in FIG. 10.

[0081] In details, an example of how a distributed NAS security policy is applied is illustrated in FIG. 10 below. FIG. 10 illustrates that, in some examples, the wireless communication method includes at least one of the following operations.

[0082] Operation 1 : When a UE requests access to the network, it must first undergo an authentication process with the network. Upon successful authentication, a security context is established between the UE and an AMF. At this point, all NAS signaling between the UE and the network is managed by the AMF, with the signaling terminating at the AMF as the central point for secure communication.

[0083] Operation 2: After successful authentication, a distributed NAS security policy is sent to the AMF from a SMF or another network function. In some examples of a distributed NAS security policy, only the AMF is responsible for enforcing the distributed NAS security policy. In this configuration, the distributed NAS security policy is retained within the network and is not transmitted to the UE. Specifically, the policy is sent only to the AMF, which uses it to manage and enforce security rules for NAS signaling between the UE and various network functions. This approach maintains centralized control over NAS security while reducing the complexity of distributing and managing security policies directly on the UE.

[0084] Operation 3 : When the UE initiates a service request to network function NFx, the process is guided by the distributed NAS security policy previously received by the UE. If this policy specifies that a direct NAS security context should be established between the UE and NFx, the AMF takes action to create this dedicated security context. This UE-NFx NAS security context is specifically established to secure direct communication between the UE and NFx, ensuring that NAS signaling is protected according to the defined security rules.

[0085] Operations 4a and 4b: Once the AMF establishes the UE-NFx NAS security context, the AMF transmits this newly created security context to both the UE and network function NFx. The AMF also provides a signal to both the UE and NFx, instructing them to use this security context for all subsequent NAS signaling between them. This ensures that any further communication between the UE and NFx is securely protected under the established NAS security context.

[0086] Operation 5: Following the receipt of the NAS security context from the AMF, both the UE and NFx begin using this security context to protect their NAS signaling. This means that all NAS messages exchanged between the UE and NFx are now encrypted and authenticatedaccording to the established security context, ensuring secure communication between the two entities.

[0087] Operation 6: Subsequently, the UE initiates a service request to another network function, NFy. This request is processed according to the distributed NAS security policy that the UE has received, which determines how the UE establishes a secure connection with NFy, whether through direct signaling or via a relay through the AMF.

[0088] Operation 7: Since the distributed NAS security policy specifies that the service request to Network Function NFy should reuse the existing UE-AMF NAS security context, the AMF does not create a new NAS security context. Instead, the UE continues to rely on the already established NAS security context between itself and the AMF for secure communication with NFy. This approach minimizes the overhead associated with creating multiple security contexts while maintaining secure communication.

[0089] Operation 8: Any signaling, service-related request, or message exchange between the UE and NFy is now managed by the AMF. The AMF forwards these communications using SBA procedures between itself and NFy. In this configuration, the AMF functions as a relay between the UE and NFy, ensuring that messages are securely exchanged without the need for a direct NAS security context between the UE and NFy.

[0090] A flexible distributed NAS security policy for establishing NAS signaling in an enhanced service-based architecture offers significant benefits for network deployment and service offerings. By enabling a distributed NAS configuration, the network can adopt a fully service-based architecture where any service-providing network function can directly communicate with the UE via NAS signaling, without routing all communications through the AMF. However, this flexibility must be carefully managed because certain network functions may require a higher level of security protection. Allowing direct NAS signaling to these high-security functions can unnecessarily increase their exposure, potentially compromising their security. A flexible distributed NAS security policy mitigates this risk by restricting access to such functions, preserving the benefits of distributed NAS without compromising network security.

[0091] Furthermore, a flexible distributed NAS security policy is advantageous for services that are infrequently requested or provided to the UE. In such cases, establishing and maintaining a direct NAS security context between the UE and the network function may be resource-intensive and inefficient. By allowing conditional direct access, the network can optimize resource consumption and maintain high performance, avoiding the overhead of maintaining multiple security contexts.

[0092] Another benefit of a flexible distributed NAS security policy is that it maintains backward compatibility with existing NAS signaling procedures, where NAS signaling to the AMF is still required for initial UE network access and authentication. This ensures that existing network designs and UE implementations remain compatible with the enhanced distributed NAS model, reducing the need for extensive changes.

[0093] From a network management perspective, having the network enforce the flexible distributed NAS security policy simplifies UE design, as the UE does not need to independently decide when to request a direct NAS connection to a network function. This centralized enforcement model reduces complexity on the UE side while ensuring consistent application of security policies across the network. If the network enforces the policy, it can dynamically adjust security and access rules without requiring updates to UE configurations.

[0094] In contrast, a rigid pre-configured approach that statically defines the rules for distributed NAS connections lacks flexibility. It restricts the network's ability to adapt to changing conditions. For example, if the NAS anchor point (such as the AMF) becomes overloaded, a flexible distributed NAS security policy can redirect NAS signaling directly between the UE and another network function, reducing the AMF's load. Without such flexibility, the AMF would continue to be overloaded, potentially leading to network performance degradation.

[0095] In summary, a flexible distributed NAS security policy provides the network with the ability to balance security, performance, and resource optimization dynamically. It enhances service-based architecture capabilities, maintains backward compatibility, reduces complexity for UE design, and enables adaptive network management in response to real-time conditions.

[0096] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Provide a flexible distributed NAS security policy. 4. Enhance network security and performance. 5. Provide a good communication performance. 6. Provide high reliability. 7. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto- bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR device maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards to create an end product. Someembodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a network node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposed solution, method, system, and apparatus are widely used in an AIoT device, a network node (UE / BS), and / or a communication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.

[0097] FIG. 11 is an example of a computing device 1300 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 11 illustrates an example of the computing device 1300 that can implement apparatuses and methods of the above embodiments of FIGs. 1 to 10, using any suitably configured hardware and / or software. In some embodiments, the computing device 1300 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.

[0098] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer-readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other programcode. Non-limiting examples of a computer-readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random access memory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.

[0099] The computing device 1300 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1300. The computing device 1300 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1300 is illustrated with an input / output (“I / O”) interface 1418 that can receive input from one or more input devices 1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input events in response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.

[0100] The computing device 1300 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 10. The program code may be resident in the memory 1414 or anysuitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.

[0101] The computing device 1300 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1300 can transmit messages as electronic or optical signals via the network interface device 1424.

[0102] FIG. 12 is a block diagram of an example of a communication system 1400 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1400 using any suitably configured hardware and / or software. FIG. 12 illustrates the communication system 1400 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (VO) interface 1580, coupled with each other at least as illustrated.

[0103] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include any combination of general -purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable various applications and / or operating systems running on the system. The communication system 1400 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 10. The program code may be resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.

[0104] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wireless personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multimode baseband circuitry.

[0105] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, baseband circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.

[0106] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments of FIGs. 1 to10 may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, for system. The memory / storage for one embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.

[0107] In various embodiments, the I / O interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments, the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / or RF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.

[0108] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1400 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.

[0109] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware or combinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.

[0110] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative couplingoperate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.[oni] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units. Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.

[0112] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.

[0113] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.

Claims

What is claimed is:

1. A wireless communication method performed by a user equipment (UE), comprising: performing an authentication procedure with a network device to establish a security context between the UE and a first network function of the network device; and determining that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, comprising at least one of the following: allowed access, conditional access, or not allowed access to network functions.

2. The wireless communication method of claim 1, wherein the distributed NAS security policy is received by the UE from a second network function of the network device through the first network function.

3. The wireless communication method of claim 1, wherein the distributed NAS security policy is maintained by the first network function.

4. The wireless communication method of any one of claims 1 to 3, further comprising: making a service request to a third network function of the network node; and establishing, based on the distributed NAS security policy, direct NAS security between the UE and the third network function by creating a NAS security context at the first network function.

5. The wireless communication method of claim 4, further comprising: receiving the NAS security context from the first network function and using the NAS security context for subsequent NAS signaling between the UE and the third network function.

6. The wireless communication method of claim 5, further comprising: making a service request to a fourth network function; and using a current NAS security context between the UE and the first network function for NAS signaling between the UE and the fourth network function.

7. The wireless communication method of claim 6, further comprising: determining a signaling, a service-related request, or a message exchange between the UE and the fourth network function using a service-based architecture (SBA) procedure, wherein the first network function acts as a relay between the UE and the fourth network function.

8. The wireless communication method of claim 6 or 7, wherein the first network function is an access and mobility management function (AMF), the second network function is a session management function (SMF), the third network function is NFx, and the fourth network function is NFy.

9. The wireless communication method of any one of claims 1 to 8, wherein the distributed NAS security policy is sent to the UE after the UE successfully authenticates with the network device,and before the UE makes a service request to the network device.

10. The wireless communication method of any one of claims 1 to 9, wherein the distributed NAS security policy is configured to allow the UE to establish direct NAS signaling with a network function if a security sensitivity of the network function is determined to be below a predetermined threshold.

11. The wireless communication method of any one of claims 1 to 10, wherein the distributed NAS security policy prohibits the UE from directly accessing the network function if the security sensitivity of the network function is determined to exceed the predetermined threshold, and any service request to the network function is relayed through the first network function.

12. The wireless communication method of any one of claims 1 to 11, wherein the distributed NAS security policy is dynamically updated by the network device based on network conditions or policy changes.

13. A wireless communication method performed by a network device, comprising: performing an authentication procedure with a user equipment (UE) to establish a security context between the UE and a first network function of the network device; and determining that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, comprising at least one of the following: allowed access, conditional access, or not allowed access to network functions.

14. The wireless communication method of claim 13, wherein the distributed NAS security policy is transmitted to the UE from a second network function of the network device through the first network function.

15. The wireless communication method of claim 13, wherein the distributed NAS security policy is maintained by the first network function.

16. The wireless communication method of any one of claims 13 to 15, further comprising: receiving, by a third network function of the network node, a service request from the UE; and establishing, based on the distributed NAS security policy, direct NAS security between the UE and the third network function by creating a NAS security context at the first network function.

17. The wireless communication method of claim 16, further comprising: transmitting, by the first network function, the NAS security context to the UE and using the NAS security context for subsequent NAS signaling between the UE and the third network function.

18. The wireless communication method of claim 17, further comprising: receiving, by a fourth network function, a service request from the UE; and using a current NAS security context between the UE and the first network function for NAS signaling between the UE and the fourth network function.

19. The wireless communication method of claim 18, further comprising: performing a signaling, a service-related request, or a message exchange between the UE and the fourth network function using a service-based architecture (SBA) procedure, wherein the first network function acts as a relay between the UE and the fourth network function.

20. The wireless communication method of claim 18 or 19, wherein the first network function is an access and mobility management function (AMF), the second network function is a session management function (SMF), the third network function is NFx, and the fourth network function is NFy.

21. The wireless communication method of any one of claims 13 to 20, wherein the distributed NAS security policy is sent to the UE after the network device successfully authenticates with the UE, and before the network device receives a service request from the UE.

22. The wireless communication method of any one of claims 13 to 21, wherein the distributed NAS security policy is configured to allow the UE to establish direct NAS signaling with a network function if a security sensitivity of the network function is determined to be below a predetermined threshold.

23. The wireless communication method of any one of claims 13 to 22, wherein the distributed NAS security policy prohibits the UE from directly accessing the network function if the security sensitivity of the network function is determined to exceed the predetermined threshold, and any service request to the network function is relayed through the first network function.

24. The wireless communication method of any one of claims 13 to 23, wherein the distributed NAS security policy is dynamically updated by the network device based on network conditions or policy changes.

25. A user equipment (UE), comprising: an executor configured to perform an authentication procedure with a network device to establish a security context between the UE and a first network function of the network device; and a determiner configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, comprising at least one of the following: allowed access, conditional access, or not allowed access to network functions.

26. A network device, comprising: an executor configured to perform an authentication procedure with a user equipment (UE) to establish a security context between the UE and a first network function of the network device; and a determiner configured to determine that a distributed non-access stratum (NAS) security policy indicates access rules for the UE, comprising at least one of the following: allowed access,conditional access, or not allowed access to network functions.

27. A user equipment (UE), comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the UE is configured to perform the wireless communication method of any one of claims 1 to 12.

28. A network device, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the network device is configured to perform the wireless communication method of any one of claims 13 to 24.

Citation Information

Patent Citations

  • Access control method, user equipment, and network device

    US20180220302A1

  • Incorporating network policies in key generation

    US20190104134A1

  • 6g control plane network functions in service-based architecture

    WO2023220147A1

  • Security in a distributed NAS terminations architecture

    WO2024035434A1