Methods for securely transmitting downlink encrypted XRM traffic with PDU set handling
By securing metadata transmission through a UDP tunnel and applying encryption algorithms, the challenge of PDU Set identification for end-to-end encrypted XRM traffic is addressed, ensuring effective QoS handling in 5G networks.
Patent Information
- Application Number
- PCT/US2025/042299
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-16
- Filing Date
- 2025-08-15
- Publication Date
- 2026-02-19
AI Technical Summary
Current 5G networks struggle with PDU Set identification for end-to-end encrypted XRM traffic due to metadata being transmitted without secure delivery mechanisms, hindering effective PDU Set based QoS handling.
Establishing a secure UDP tunnel between the UE and the UPF using a Connect-UDP upgrade token, and employing encryption and integrity protection algorithms for metadata transmission, enabling PDU Set identification and QoS handling through transformed QUIC packets or UDP options.
Ensures secure and effective PDU Set identification and QoS handling for end-to-end encrypted XRM traffic, enhancing network performance and security in 5G communication systems.
Smart Images

Figure US2025042299_19022026_PF_FP_ABST
Abstract
Description
Patent Application Attorney Docket Number 0683-104-WO METHODS FOR SECURELY TRANSMITTING DOWNLINK ENCRYPTED XRM TRAFFIC WITH PDU SET HANDLING FIELD OF THE DISCLOSURE
[0001] This document generally describes methods and devices (e.g., user equipment (UE) and network entity (NE) performing network core functions) operating in wireless communication systems such as (but not limited to) the ones described in 3rd Generation Partnership Project (3GPP) technical specifications, for example, the Fifth Generation (5G) or Long Term Evolution (LTE) communication systems. More particularly, the methods and devices employ techniques for securely transmitting downlink extended reality and media (XRM) traffic with protocol data unit (PDU) set handling. BACKGROUND
[0002] A PDU Set includes one or more PDUs carrying an application layer payload. In case of XRM traffic, a PDU packet payload may be a video frame, or a video slice formatted as real time protocol (RTP) packets. One or more RTP packets may be encapsulated in a QUIC packet transported by a logical QUIC stream. Here, QUIC stands for Quick UDP Internet Connections, with UDP meaning User Datagram Protocol. When a PDU Set is transmitted from an application server (AS) to a UE via a PDU session anchor (PSA) user plane function (UPF), the PDU Set based quality of service (QoS) handling of the packets by a radio access network (RAN) node (e.g., by a next generation (NG) radio access network (NG-RAN) node), which delivers the packets to the UE, depends on (i) the PDU Set QoS profile associated with a respective QoS Flow to which the QUIC packets pertain, and (ii) PDU Set information carried by metadata associated with each packet. The PDU Set QoS profile includes parameters such as, PDU Set Delay Budget (PSDB), PDU Set Error Rate (PSER), and PDU Set Integrated Handling Information (PSIHI). The PDU Set information may include: a PDU Set Sequence Number, an indication of End (last) PDU of the PDU Set, a PDUPatent Application Attorney Docket Number 0683-104-WO Sequence Number within a PDU Set, a PDU Set Size in bytes, and a PDU Set Importance (PSI), which identifies the relative importance of a PDU Set compared to other PDU Sets within the QoS flow. The PDU Set information may be extended to cover more information for the PDU Set identification in a wireless network.
[0003] Ongoing efforts for architecture enhancement for XRM service aim to enhance PDU Set based QoS handling, enhance support of XRM based on non-3GPP access, expose XR related network capability / information towards the application layer, etc. The current 3GPP Technical Report (TR) 23.700-70 defines a Fully Encrypted Media Flow (FEMF) and a Partially Encrypted Media Flow (PEMF) as follows. The FEMF is a media flow where both the media header and media payload are encrypted from end-to-end and are not visible in the network. The PEMF is a media flow where at least some media headers (e.g., the base header) are not encrypted. Other media headers (e.g., extension headers) and media payload, however, are encrypted from end-to-end and, thus, not visible in the network.
[0004] Current versions of 3GPP TSs 23.501, 23.502, 23.503, and 26.522 describe 5G network cores that support PDU Set based QoS handling. In this context, the Policy and Control Function (PCF) determines a Policy Charge and Control (PCC) Rule based on PDU Set QoS Parameters provided by the application function (AF) and Protocol Description(s). The PCC rule provides information that enables identifying Internet Protocol (IP) traffic flows, applying QoS parameters, filtering, and charging for such flows. Upon receiving the PCC rule, the Session Management Function (SMF) binds (i.e., associates) the PCC rule to a QoS Flow within a PDU Session. The SMF also adds these PDU Set QoS parameters to the QoS Profile of the QoS Flow and then provides the QoS Profile to the NG-RAN node. If the PCC rule contains one or more PDU Set QoS Parameters (PSER, PSDB, and PSIHI), the PSA UPF may use the Protocol Description(s) for identifying the PDU Set information included in an XRM packet header of the XRM packet transmitted over N6 interface between a 5G core network and a data network.
[0005] The PSA UPF identifies PDUs that belong to PDU Sets and retrieves the PDU Set Information (specified above) based on the RTP extension header. The PSA UPF then sends the PDU Set Information to the NG-RAN node in a GTP-U headerPatent Application Attorney Docket Number 0683-104-WO (here, GTP-U stands for GPRS Tunneling Protocol User, and GPRS for General Packet Radio Service). The NG-RAN node uses the PDU Set information for PDU Set based QoS handling.
[0006] The current networks generally use end-to-end encryption to provide security, which is expected also for XRM applications. The PSA UPF in 5G network can not perform PDU Set Identification for end-to-end encrypted traffic when the media packet header information necessary for PDU Set identification is partially or fully encrypted. It has been proposed to deliver metadata containing PDU Set Information via an UDP-Option which is transmitted along with the encrypted QUIC packet containing the XRM packets. This approach is tunnel-less but the AS / AF needs to provide information of a specific media stream correlation ID (MSC-ID) to correlate a QUIC connection and / or QUIC stream with a specific set of QoS requirements. Based on the MSC-ID information, the UPF may perform PDU Set Identification for the packets marked with an MSC-ID received from the AS and then enforce QoS rules accordingly.
[0007] Conventionally, the metadata transmitted from the AS to the PSA UPF over N6 reference point in the user plane is not securely delivered (e.g., not encrypted and / or integrity protected). In other words, the AS does not have a secure delivery mechanism to protect the metadata associated with XRM packets transmitted to UEs. SUMMARY
[0008] A UE establishes a PDU session and connection with an AS via a wireless network, a UDP tunnel for transporting encrypted traffic and security-protected metadata with an UPF of the wireless network’s core, and an end-to-end QUIC connection with the AS. That is, the UE and the AS establish a security mechanism (e.g., security keys and other parameters) for protecting metadata that enables PDU Set based QoS handling of packets pertaining to the PDU session. The UE may establish the UDP tunnel with the UPF using a Connect-UDP upgrade token in forwarded mode. In some embodiments, the AS conveys the security-protected metadata using the UDP option of a UDP datagram. In other embodiments, the AS conveys the metadata within a transformed QUIC payload.Patent Application Attorney Docket Number 0683-104-WO BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate one or more embodiments and, together with the description, explain these embodiments.
[0010] Fig.1 is a schematic representation of a wireless communication system including a UE and an NE configured to perform methods according to various embodiments.
[0011] Fig.2 illustrates a 5G system architecture in reference point representation.
[0012] Fig.3 is a flowchart of a method performed by a UE for enabling delivery of encrypted traffic pertaining to a PDU Set handled with a specific QoS according to an embodiment.
[0013] Fig.4 is a flowchart of a method performed by a NE forwarding encrypted traffic pertaining to a PDU Set handled with a specific QoS according to an embodiment.
[0014] Fig.5 illustrates a UDP datagram transporting XRM traffic.
[0015] Fig.6 illustrates a UDP datagram with a QUIC packet in the UDP payload and the XRM metadata in the QUIC payload according to an embodiment.
[0016] Fig.7 is a diagram illustrating XRM traffic over N6 interface for a logical media session for QUIC connection / stream for transporting a QUIC packet along with metadata in UDP-Option between UE and AS.
[0017] Fig.8 is a signal diagram detailing a procedure initiated by an application function (AF) or AS requesting QoS handling of encrypted XRM traffic according to an embodiment.
[0018] Fig.9 is a signal diagram illustrating details of establishing a PDU session and connection between a UE and an AS according to an embodiment.
[0019] Fig.10 is a signal diagram illustrating an efficient transport of encrypted XRM traffic for PDU Set handling according to an embodiment.
[0020] Fig.11 is a flowchart of a method performed by an AS for transmitting encrypted XRM traffic with PDU Set handling according to an embodiment.Patent Application Attorney Docket Number 0683-104-WO DETAILED DESCRIPTION
[0021] Methods and devices described in this section embody techniques related to securely transmit downlink XRM traffic with PDU Set handling. The downlink XRM traffic is securely transmitted when a packet’s payload and corresponding metadata are both securely protected when the AS applies an encryption algorithm and / or an integrity protection algorithm to the packets (payload and metadata). A challenge in securely transmitting XRM traffic is that, while the XRM payload can be encrypted end-to- end between the AS and the UE, the PSA UPF, which is located on the path, needs access to the corresponding metadata to perform PDU Set based QoS handling. In some embodiments, the UE and the AS set up a security mechanism (including but not limited to secure keys) when the PDU session is established and provides the security information needed to decrypt the metadata to the PSA UPF.
[0022] The embodiment descriptions in this section refer to the accompanying drawings. The same reference numbers in different drawings identify the same or similar elements. The detailed descriptions do not preclude other embodiments within the scope of the appended claims. The embodiments are not limited to the configurations described hereinafter but may be extended to other arrangements.
[0023] Methods and devices embodying techniques for secured metadata delivery according to various embodiments operate within the framework of a wireless communication system 100 as illustrated in Fig.1. The wireless communication system 100 includes a UE 102, an NG-RAN 104, and an NE 120 on which one or more 5G CN functions are performed. The UE 102 uses services provided by the 5GC 110 via the NG-RAN 104 that serves UEs within a cell 124. For the sake of simplicity and clarity, the following description refers mostly to 5G radio access technology (RAT), but this RAT is an illustration and should not be interpreted as a limitation; other RATs such as a sixth generation (6G) RAT may be employed.
[0024] As illustrated in Fig.1, the NG-RAN 104 serves (i.e., intermediates communication with UEs located within) a cell 125 but it may serve plural cells (not shown) in the same Radio Access Network Notification Areas (RNA) or different RNAs. In general, a network operator owning a core network 110 provides services to end users (i.e., UEs) via any number of nodes (NG-RANs), and each of the NG-RANs mayPatent Application Attorney Docket Number 0683-104-WO serve one, two, three, or any other suitable number of cells. A NG-RAN (e.g., 104) connect to 5GC NEs such as NE 120 (i.e., physical devices hosting 5G CN function(s)) via a 5G CN interface (e.g., N2 or N3 interface). The NG-RANs may be interconnected via other specific interfaces (e.g., an Xn interface).
[0025] The 5G CN includes many functions but only a few, which are relevant to the claimed methods, are illustrated in Fig.1. Fig.2 provides a more complete illustration (as presented in 3GPP TS 23.501) of 5G CN functions and their inter- relationships in reference point representation. The NE 120 hosts one or more of the 5G CN functions. The NE 120’s processing hardware includes a processor 122 (or more processors of various types), a transmitter 124 configured to transmit signals wirelessly, and a receiver 126 configured to receive signals wirelessly (the transmitter and the receiver functionality may be provided by a single transceiver). The NE 120 typically also includes a memory (not shown) storing executable instructions for the processor 122 to perform various methods described hereinafter, and other data.
[0026] The 5G CN 110 illustrated in Fig.1 includes an access and mobility management function (AMF) 112, a session management function (SMF) 114, a user plane function (UPF) 116, a policy control function (PCF) 118, and a network exposure function (NEF) 119. The same NE may execute one or more 5GC functions or instances of 5GC functions. For example, the 5GC 110 may have a plurality of UPF instances running on the same NE or on different NEs.
[0027] The AMF 112 is configured to manage authentication, registration, paging, and other related functions. The SMF 114 is configured to manage PDU sessions, and the UPF 116 is configured to transfer user-plane packets related to audio calls, video calls, XRM, etc., between the UE and a data network 108 (which is the AS for XRM applications). The PCF 118 is a network function that provides policy control and charging rules for 5G services and applications thereby facilitating network behavior control, network slicing, UE activities, and communication with other 5GC functions. The NEF 119 is a function that allows third-party applications to securely access the 5G network's services and capabilities. The application function (AF) 115 may be located on the same physical device 123 as the AS. This device’s processing hardware includes at least one processor 127, a transmitter 128, and a receiver 129 (or aPatent Application Attorney Docket Number 0683-104-WO transceiver) that enable wireless communication of data packets with function of the 5G CN 110.
[0028] The UE 102 is equipped with processing hardware 130 that includes one or more general-purpose processors and / or special-purpose processing units. The processing hardware 130 illustrated in Fig.1 includes a processor 132 configured to process uplink (UL) data that the UE 102 transmits to the NG-RAN 104, and / or downlink (DL) data the UE receives from the NG-RAN 104. The processing hardware 130 also includes a transmitter 134 configured to transmit the UL data and a receiver 136 configured to receive the DL data (or, alternatively, a transceiver performing both transmitting and receiving data). The UE 102 may also include (although not shown) transmission / reception hardware for other 3GPP RAT(s) besides 5G (e.g., LTE, 6G) and / or for non-3GPP RAT(s) (e.g., WiFi, Bluetooth). The processing hardware 130 typically also includes a non-transitory computer-readable medium (e.g., a memory, not shown) storing machine-readable instructions executable by the processor to perform various techniques for securely downloading encrypted XRM traffic with PDU Set handling.
[0029] The NG-RAN 104 is similarly equipped with processing hardware (not shown) including one or more general-purpose processors and / or special-purpose processing units, a transmitter, a receiver and a non-transitory computer-readable medium.
[0030] Fig.2 illustrates a 5G system architecture in reference point representation. Reference points (e.g., N1, N2, N4, N6) are interfaces when end points (functions) on either side of these points are hosted by different physical devices. Control plane 211 functions manage communication sessions and control communications and include AMF 112, SMF 114, AF 115, PCF 118, and NEF 119 that transmit messages Namf, Nsmf, Naf, Npcf, and Nnef respectively. The UE 102, NG-RAN 104, UPF 116, and DN 108 handle user plane 221 traffic. The UE 102 and the NG-RAN 104 communicate with the AMF 112 via interfaces N1 and N2, respectively. The UPF 116 communicates with the NG-RAN 104 via an N3 interface, with the SMF 114 via an N4 interface (or reference point in case the UPF and the SMF are hosted on the same physical device), and with DN (AS) 108 via an N6 interface. The UPF 116 as a PSA UPF may communicate with an IntermediatePatent Application Attorney Docket Number 0683-104-WO UPF (I-UPF, not shown) via an N9 interface (or reference point if the communicating UPFs are hosted by the same physical device). This interface is critical for handling user plane data, especially during handover procedures, and ensures traffic routing and QoS consistency.
[0031] The embodiments described hereinafter enable PDU Set handling of encrypted XRM traffic via an UDP tunnel between the UE and the UPF established using an Connect-UDP upgrade token in forwarded mode.
[0032] Without going into many details revealed later, in a high level (general) view, Fig.3 is a flowchart of a method 300 performed by a UE (e.g., UE 102) for enabling delivery of encrypted traffic pertaining to a PDU Set handled with a specific QoS according to some embodiments. The method 300 includes establishing 352 a PDU session and connecting with an AS (e.g., 108) via a wireless network including a NE (e.g., 130) that executes an UPF (e.g., 116). The method 300 further includes establishing 354 a UDP connection using an encapsulation protocol with the UPF, and negotiating 355 security keys for applying a security algorithm to metadata associated with a UDP datagram transmitted from the AS to the UE. The metadata indicates to the NE (UPF) that the UDP datagram carries a PDU that pertains to a PDU Set to be handled with a specific QoS. When the encapsulation protocol is Internet Protocol (IP), the UE is a http client, and the UPF is an http proxy (here http stands for hypertext transfer protocol). Note that http and IP are different, but related, protocols that work together to enable communications over the internet: IP is responsible for routing data packets, while HTTP is a higher-level protocol that defines the manner in which web browsers and servers communicate with each other to transfer content. The method 300 then includes providing 357 the security keys to the application server, and receiving 366 the UDP datagram carrying the PDU of the PDU session.
[0033] In the same high level (general) view, Fig.4 is a flowchart of a method 400 performed by a NE (e.g., 120) executing an UPF (e.g., 116) that forwards, to a UE (e.g., 102), encrypted traffic according to a PDU Set handled with a specific QoS. The method 400 includes the NE (hosting the UPF) facilitating 452 establishment of a PDU session between a UE and an AS. The method 400 then includes establishing 454 a UDP connection using an encapsulation protocol with the UE and negotiating 455Patent Application Attorney Docket Number 0683-104-WO security keys for applying a security algorithm to metadata associated with a UDP datagram transmitted from the AS to the UE. As already mentioned, the metadata indicates that the UDP datagram carries a PDU that pertains to a PDU Set to be handled with a specific QoS, and, when the encapsulation protocol is Internet Protocol (IP), the UE is an http client, and the UPF is an http proxy. After step 455, the method 400 then includes forwarding 466 the UDP datagram received from the AS to the UE.
[0034] Fig.5 illustrates a UDP datagram transporting XRM traffic. The UDP datagram 500 includes an IP header 501 and UDP header 502, a UDP payload 510, and an UDP option 520. The UDP payload 510 carries a QUIC packet 511 including a QUIC header 512 and QUIC payload 514. The QUIC payload 514 carries one or more RTP packets 516. The UDP option 520 has a minimum length of two bytes and includes a Kind field 522 (always one byte), a Length field 524, and a Remainder of option field 526. The Length field 524 is one byte for all lengths below 255 but a Length of 255 indicates use of an UDP option extended format. The extended Length field is then a 16-bit field in network standard byte order. The UDP option 520 has typically a minimum of two bytes except for the one-byte option "No Operation." The Remainder of option field 526 is used in some of the embodiments described below to transmit encrypted metadata including PDU Set information enabling PDU Set identification as pertaining to a PDU Set / flow and therefore handling the packet 510 according to the specific QoS based on PDU Set based QoS handling. The metadata is protected by applying an encryption algorithm and / or an integrity protection algorithm using pre-negotiated security keys which may have a limited validity period.
[0035] Internet Assigned Numbers Authority (IANA) manages standardized (i.e., publicly known and used) UDP options, consisting of UDP option Kind field values and UDP Option Experimental IDs (ExIDs). Initial values of the UDP Option Kind registry are as reproduced below, including those both assigned and reserved. Additional values in this registry are to be assigned from the UNASSIGNED values by Internet Engineering Steering Group (IESG) Approval or Standards Action. An end point supporting UDP option must support at least the Kind marked with * in the following table.Patent Application Attorney Docket Number 0683-104-WO Kind Length Meaning ---------------------------------------------- 0* - End of Options List (EOL) 1* - No operation (NOP) 2* 6 Additional payload checksum (APC) 3* 10 / 12 Fragmentation (FRAG) 4* 4 Maximum datagram size (MDS) 5* 4 Maximum reassembled datagram size (MRDS) 6* 6 Request (REQ) 7* 6 Response (RES) 8 10 Timestamps (TIME) 9 (varies) RESERVED for Authentication (AUTH) 10-126 (varies) UNASSIGNED (assignable by IANA) 127 (varies) RFC 3692-style experiments (EXP) 128-191 RESERVED 192 (varies) RESERVED for Compression (UCMP) 193 (varies) RESERVED for Encryption (UENC) 194-253 UNASSIGNED-UNSAFE (assignable by IANA) 254 (varies) RFC 3692-style experiments (UEXP) 255 RESERVED-UNSAFE
[0036] The embodiments described below start from the following assumptions: (a) RTP is used; (b) RTP over QUIC is based on IETF draft-ietf-avtcore-rtp-over-quic-07: RTP over QUIC, whereby the end-to-end connection between the UE and the Application Server is based on QUIC; and (c) the http / 3 is assumed for http client and http client for solutions that apply Proxy-UDP-in HTTP / 3 and QUIC aware proxy.
[0037] The embodiments described hereinafter enable PDU Set handling of encrypted XRM traffic by the UE as http client that establishes UDP tunnel with UPF as http proxy using Connect-UDP upgrade token in forwarded mode. Two options may be used for encryption / integrity protection of the metadata based on the protocol methods that the AS applies to transport the XRM metadata. A first option uses UDP-Option containingPatent Application Attorney Docket Number 0683-104-WO XRM metadata, which has been discussed above. A second option uses transformed QUIC that includes security-protected metadata in the QUIC payload.
[0038] Fig.6 illustrates a UDP datagram 600, in which a UDP payload 610 contains transformed QUIC packet 611 including QUIC header 512, original QUIC payload, and XRM metadata (Option2). Unlike in Fig.5, the UDP payload 610 carries the transformed QUIC packet 611. The transformed QUIC packet 611 includes QUIC header 512 and a QUIC payload 614 that includes metadata in addition to one or more RTP header(s) and RTP payload(s).
[0039] As illustrated in Fig.7 end-to-end encrypted XRM traffic and security- protected metadata are transported using a UDP datagram 706 from the AS 108 to the UPF 116 over an N6 interface. Note that both the XRM data (payload) and the metadata are encrypted as suggested by the two lock icons. The UPF decrypts the metadata (as suggested by the open lock to perform PDU Identification and then forwards the UDP datagram encapsulated using the IP according to the specific QoS. The UE 102 as http client receives the encapsulated UDP datagram 704 via an UDP-tunnel using Connect- UDP upgrade token in forwarded mode from the PSA UPF as http proxy for the AS. The UPF may proxy UDP in encapsulated http datagram and perform QUIC aware proxy functionality to forward the UDP datagram between the UE and the application server in the cloud. This method avoids re-encapsulation and re-encryption, all XRM packets are forwarded using the Forwarded Mode in QUIC-Aware Proxying using HTTP.
[0040] Fig.8 is a diagram illustrating a high-level procedure for enabling PDU Set Identification by proxying UDP in http datagram and QUIC-Aware Proxying in a 5G communication system. The UE and the AS first establish 852 a PDU Session and connection between the UE 102 and the AS 108 via the PSA UPF 116. This procedure is followed by an AF-initiated procedure 853 requesting a specific QoS handling of encrypted downlink XRM traffic transmitted from the AS to the UE.
[0041] Upon receiving an upper layer request, or a downlink IP packet with a configured destination IP address of the AS, the UE 102, as the http client, triggers a procedure 854 for establishing a UDP connection using encapsulation protocol (i.e., a UDP-tunnel with PSA UPF as http proxy) by sending a Connect-UDP upgrade token in forwarded mode. Based on operator’s policies, the PSA UPF 116 may use the same UDPPatent Application Attorney Docket Number 0683-104-WO tunnel for transporting the XRM traffic from application servers managed by the same http proxy in the cloud (e.g., for one or more XRM application of one or more UEs). The UE and the UPF 116 then negotiate 855 security keys for applying a security algorithm to metadata associated with a UDP datagram transmitted from the AS to the UE The UE 102 and the AS 108 also establish 856 an end-to-end QUIC connection via the network. The UE initiated QUIC connection may be established, for example, as described in IEFT RFC 9000. The UE 102 provides 857 the security keys to the AS via an application layer communication.
[0042] Procedure 870 illustrates a downlink XRM packet being transmitted (i.e., transported from the AS 108 to the UE 102) in this context. The AS 108 obtains, via application layer signaling, security keys from the UE for applying an encryption and / or integrity protection algorithm to the packet’s metadata. The security keys are negotiated based on the http protocol (i.e., IP) between the UE / http client and the PSA UPF / http proxy. The AS 108 performs 858 encryption and / or integrity protection of the XRM metadata using the security keys obtained from the UE (as suggested by the lock icon). In this scenario, the AS 108 then transforms the original QUIC packet by including security- protected metadata to the transformed QUIC packet that contains XRM traffic. In an alternative embodiment, the security-protected metadata is transmitted using the UDP option. The AS 108 generates 860 the UDP datagram including the QUIC packet and security-protected metadata and transmits 862 the UDP datagram including transformed QUIC packet to the PSA UPF 116.
[0043] Upon receiving the UDP datagram from the AS 108, the PSA UPF 116 extracts 864 the XRM metadata from the transformed QUIC packet in the UDP payload of the UDP datagram, decrypts 865 the XRM metadata and performs PDU Set Identification accordingly, reconstructs the original QUIC packet, and transmits 866 the reconstructed QUIC packet within an http datagram in the downlink direction to the UE 102 (via the NG- RAN not shown).
[0044] The UE 102 then extracts 868 the QUIC packet from UDP payload in the http datagram and forwards 869 the QUIC packet to UE’s upper layers (e.g., application layer).Patent Application Attorney Docket Number 0683-104-WO
[0045] Looking now in more detail at the procedure for establishing a PDU session and connection between a UE and an AS (i.e., step 852), the procedure may be initiated by the UE 102 sending 970 a non-access stratum (NAS) message to AMF 112 requesting PDU session establishment and indicating an initial request. This NAS message is transmitted over an N1 reference point (i.e., in an N1 session management container). The AMF 112 then selects 972 an SMF instance and sends 974 an Nsmf_PDUSession_CreateSMContext Request message to the selected SMF instance (SMF 114). The SMF 114 may (i.e., optionally) retrieve 976 the UE’s subscription information from united data management (UDM) 113 and then replies 977 to the Nsmf_PDUSession_CreateSMContext Request message with an Nsmf_PDUSession_CreateSMContext Response message. A PDU Session authentication / authorization procedure 978 follows. The steps following the ones illustrated in Fig.9 are described in 3GPP TS 23.502.
[0046] Fig.10 illustrates the message flow for enabling a PDU Set Identification for end-to-end encrypted XRM traffic according to an embodiment. Here, the PDU Session Establishment procedure 852 may include the following enhancements relative to the above description related to Fig.9: (a) the PDU Session Establishment / Modification Request message (see step 970) indicates capability of http client for UDP tunnel in forwarded mode for handling encrypted XRM traffic, and (b) the PDU Session Establishment Accept message or PDU Session Modification Command message (transmitted to the UE later in a step not illustrated in Fig.9) includes http proxy address information at PSA UPF 116, for example, in a protocol configuration option (PCO) information element (IE) or an extended PCO (ePCO) IE.
[0047] The AF (here illustrated as collocated with the AS) initiates an AF session with QoS by invoking Nnef_AFSessionWithQoS Create service operation as described in TS 23.502 procedure that includes the following steps. Based on information from AS, the AF sends 1082 an AF request to the PCF / NEF 118 / 119 over N33 (reference point or interface depending on the physical device(s) hosting AF and PCF / NEF) to enable the PDU Set Identification for the end-to-end encrypted XRM traffic. The AF request includes one or more of the following pieces of information: (a) a protocol description that includesPatent Application Attorney Docket Number 0683-104-WO information related to the use of the UDP-tunnel over N6, and (b) security requirements for metadata encryption / integrity protection.
[0048] The information related to the use of the UDP-tunnel over N6 includes one or more of: (i) an indication of using Connect-UDP upgrade token in forwarded mode; (ii) configuration information of UDP tunnel, including indication of PSA UPF role as http proxy, (iii) IP address of the UE as http client, and addresses of one or more application server(s) that may use the N6 tunnel managed by the PSA / UPF http proxy; and (iv) Context Type ID information represents the type of protocol packets (e.g., transformed QUIC or UDP-Option) used by the XRM metadata which is included in the UDP datagram over N6. The Context type ID may indicate UDP-Option for XRM metadata in the UDP datagram, and a Kind value may be indicated to represent the content is for XRM metadata carrying PDU Set information. The Context type ID may additionally or alternatively indicate Transformed QUIC packet with a specific format that extends QUIC payload with XRM metadata such as: Option 1 - one or two bits of length information defined for the metadata of the XRM packet; Option 2: the metadata of the XRM packet appended in the front of original QUIC payload of the XRM packet or in the tail of the original QUIC payload of the XRM packet; Option 3: the extended QUIC payload includes fixed length metadata of the XRM packet appended in the front of original QUIC payload of the XRM packet or in the tail of the original QUIC payload of the XRM packet.
[0049] Security requirements for metadata encryption / integrity protection indicates: (i) the method of security keys negotiation based on http protocol between the UE and PSA UPF / http proxy, and (ii) validity criteria for the encryption / integrity keys. The encryption / integrity protection of the XRM metadata is done by the AS which obtains the security keys information from the UE in the application layer signaling. The validity criteria for the encryption / integrity keys may be for example a validity timer or start / end time or renewal timer, or a Max. number of packets that used the exiting security keys.
[0050] Based on information of the AF request (sent to the PCF via NEF or directly), the PCF 118 generates and sends 1084 a PCC rule to instruct the UPF to identify PDU Set information based on XRM metadata included in UDP option or the transformed QUIC packet. The PCC rule includes the information obtained from AF included in the AFPatent Application Attorney Docket Number 0683-104-WO request. The SMF 114 provides 1086 a QoS profile to the NG-RAN 104, and QoS rules to the UE 102 (e.g., using a PDU Session Establishment / Modification procedure).
[0051] The PSA UPF 116 configured with N4 rules supports the http proxy functionality in order to manage a UDP tunnel with the UE as http client using connect- UDP upgrade token in forwarded mode and enables 1088 PDU Set Handling for encrypted XRM traffic according to the required QoS. That is, the PSA UPF 116 is enabled to extract the XRM metadata from the transformed QUIC packet in the UDP datagram based on a specific Context ID or Context ID with Kind value for the use of UDP- Option for XRM metadata (as illustrated in step 864). The PSA UPF 116 then decrypts the XRM metadata and performs PDU Set Identification accordingly (as illustrated in step 865), marks the PDU Set Information into GTP-U header (as described in TS 23.501 subsection 5.37.5) and forwards the QUIC packet in the downlink direction to the NG-RAN (as in step 866). The PSA UPF 116 manages the UDP tunnel with the UE as http client, for transporting the downlink XRM traffic.
[0052] As discussed in Fig.8 description, upon receiving an uplink packet from an upper (e.g., application) layer and configuration information of http proxy / PSA UPF 116 address, the UE 102 establishes 1057 a UDP tunnel towards http proxy and an end-to-end QUIC connection. A procedure 870 may then be performed for the packets pertaining to the PDU Session via the UPF / http proxy forwarding the original QUIC packet with XRM traffic to the UE and vice-versa uplink traffic from the UE to the AS.
[0053] Before expiration of a validity criteria for the existing security keys for XRM metadata, the UE 102 and the PSA UPF 116 may negotiate 1090 new security keys over the UDP tunnel based on the http protocol. The UE 102 then provides the new security keys to the AS 108. The UPF 116 and AS 108 then stop using the invalid security keys for protecting the XRM metadata.
[0054] Fig.11 is a flowchart of a method 1100 performed by an AS (i.e., a network device hosting the AS) for transmitting encrypted XRM traffic with PDU Set handling according to an embodiment. The method 1100 includes establishing 1152 a PDU session and connecting to a UE via a wireless network (step corresponding to procedure 852). The method 1100 further includes transmitting 1182 (corresponding to 1082) a request for providing a specific quality of service, QoS, to PDUs related to the PDUPatent Application Attorney Docket Number 0683-104-WO session. The request includes (A) a protocol description and (B) security requirements. The protocol description includes (A1) configuration information for a UDP tunnel, (A2) an indication of using a Connect-UDP upgrade token in forwarded mode, and (A3) a context type identifier. The security requirements include (B1) security keys negotiated by the network with the UE and (B2) optionally, a validity criterion for the security keys.
[0055] The method 1100 further includes receiving 1157, from the UE, the security keys for applying a security algorithm to metadata associated with a UDP datagram, and transmitting 1162 PDU UDP datagram to the UE with PDU UDP metadata secured by applying the security algorithm using the security keys (steps corresponding to 857 and 862 in Fig.8).
[0056] Reference throughout this section to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout the specification are not necessarily all referring to the same embodiment. Further, the particular features, structures or characteristics may be combined in any suitable manner in one or more embodiments.
[0057] Numerical adjectives “first”, “second”, and “third” do not imply any order (are not ordinals) but are markers to distinguish separate instances of similar elements. References to the singular (e.g., “a” or “an”, “the”) should include the plural unless clearly indicated otherwise.
[0058] As used herein, a phrase referring to “at least one of” or “one or more of” a list of items refers to any combination of those items, including single members. For example, “at least one of: a, b, or c” is intended to cover the possibilities of: a only, b only, c only, a combination of a and b, a combination of a and c, a combination of b and c, and a combination of a and b and c.
[0059] Although the features and elements of the present embodiments are described in the embodiments in particular combinations, each feature or element may be used alone without the other features and elements of the embodiments or in various combinations with or without other features and elements disclosed herein. The methods or flowcharts may be implemented in a computer program, software or firmware tangiblyPatent Application Attorney Docket Number 0683-104-WO embodied in a computer-readable storage medium for execution by a specifically programmed computer or processor.
Claims
Patent Application Attorney Docket Number 0683-104-WO WHAT IS CLAIMED IS:
1. A wireless communication method (300) performed by a user equipment, UE, (102), the method comprising: establishing (352) a packet data unit, PDU, session and connection with an application server (108) via a wireless network including a network entity, NE, (120) that executes a user plane function, UPF, (116); establishing (354) a User Datagram Protocol, UDP, connection using an encapsulation protocol with the UPF; negotiating (355) security keys for applying a security algorithm to metadata associated with a UDP datagram transmitted from the application server to the UE, the metadata indicating to the NE that the UDP datagram carries a PDU that pertains to a PDU Set to be handled with a specific quality of service, QoS; providing (357) the security keys to the application server; and receiving (366) the UDP datagram carrying the PDU of the PDU session.
2. The wireless communication method of claim 1, further comprising: establishing a Quick UDP Internet Connections, QUIC, connection with the application server, with a payload of the UDP datagram including a QUIC packet whose payload carries the PDU, wherein the receiving of the UDP datagram includes extracting the QUIC packet from the UDP datagram payload and forwarding the QUIC packet to an upper layer.
3. The wireless communication method of claim 2, wherein the establishing of the UDP connection includes indicating that the UDP datagram transmitted by the application server includes security-protected metadata in a QUIC payload.
4. The wireless communication method of claim 1 or 2, wherein the establishing of the UDP connection includes indicating that the UDP datagram transmitted by the application server includes security-protected metadata in an UDP option.Patent Application Attorney Docket Number 0683-104-WO 5. The wireless communication method of any of claims 1 to 4, wherein the establishing the PDU session comprises: transmitting a message initiating or modifying the PDU session including an indication of UE’s capability to support UDP tunnels in forwarded mode as the UDP connection and of using Internet Protocol, IP, as the encapsulation protocol; and receiving an IP address of the UPF in response to the message initiating or modifying the PDU session, wherein the UE establishes the UDP connection as a UDP tunnel by sending a Connect-UDP upgrade token in forwarded mode.
6. The wireless communication method of any of claims 1 to 5, further comprising: renewing the security keys after a predetermined time interval.
7. The wireless communication method of any of claims 1 to 6, wherein the UE receives, from the application server, extended reality and media, XRM, traffic included in the PDU.
8. A wireless communication method (400) performed by network entity, NE, (130) that executes a user plane function, UPF, (116), the method comprising: facilitating (452) establishment of a packet data unit, PDU, session between a user equipment, UE, and an application server (108); establishing (454) with the UE a User Datagram Protocol, UDP, connection using an encapsulation protocol with the UE; negotiating (455) security keys for applying a security algorithm to metadata associated with a UDP datagram transmitted from the application server to the UE, the metadata indicating to the NE that the UDP datagram carries a PDU that pertains to a PDU Set to be handled with a specific quality of service, QoS; and forwarding (466) the UDP datagram received from the application server to the UE according to the metadata decrypted using the security keys.Patent Application Attorney Docket Number 0683-104-WO 9. The wireless communication method of claim 8, further comprising: facilitating establishment of a Quick UDP Internet Connections, QUIC, connection between the application server and the UE, a payload of the UDP datagram including a QUIC packet whose payload carries the PDU, wherein forwarding the UDP datagram includes: extracting and decrypting the metadata from the UDP datagram payload using the security keys, and transmitting, to the UE and according to the specific QoS, a QUIC packet carried by payload of the UDP datagram and encapsulated using Internet Protocol as the encapsulation protocol.
10. The wireless communication method of claim 8, wherein the UDP datagram received from the application server carries security-protected metadata in a payload of the QUIC packet.
11. The wireless communication method of claim 8, wherein the UDP datagram received from the application server includes security-protected metadata in an UDP option.
12. The wireless communication method of any of claims 8 to 11, further comprising: renewing the security keys based on a validity criterion.
13. A wireless communication method (1100) performed by a network device (135) that hosts an application server (108) and / or an application function, AF, (115), the method comprising: establishing (1152) a packet data unit, PDU, session and connection with a user equipment, UE, (102) via a wireless network (104, 110);Patent Application Attorney Docket Number 0683-104-WO transmitting (1182), to the wireless network, a request for providing a specific quality of service, QoS, to PDUs related to the PDU session, the request including a protocol description and security requirements, wherein the protocol description includes configuration information for a User Datagram Protocol, UDP, tunnel, an indication of using a Connect-UDP upgrade token in forwarded mode, and a context type identifier indicating whether the application server transmits security-protected metadata related to a PDU in an UDP option or in a payload of a Quick UDP Internet Connections, QUIC, packet included in payload of the UDP, and the security requirements include security keys negotiated by the network with the UE, and optionally, a validity criterion associated with the security keys; receiving (1157), from the UE, the security keys for applying a security algorithm to metadata associated with a UDP datagram; and transmitting (1162) a PDU UDP datagram to the UE with security-protected metadata secured by applying the security algorithm using the security keys.
14. The wireless communication method of claim 13, further comprising: establishing a Quick UDP Internet Connections, QUIC, connection between the with the UE, wherein a payload of the UDP datagram includes a QUIC packet whose payload carries the PDU and the security-protected metadata, or a UDP option field of the PDUUPD datagram carries the security-protected metadata secured by applying the security algorithm using the security keys 15. A wireless communication device (120, 123, 130) comprising a processor (122, 132, 127) and a transceiver (124, 126, 128, 129, 134, 136) configured to cooperatively execute the methods of claims 1 to 14.