Apparatuses and communication methods

A direct NAS connection between UE and NF through AMF-assisted security context establishment addresses signaling bottlenecks, reducing AMF load and enhancing system efficiency and scalability.

WO2026054895A1PCT designated stage Publication Date: 2026-03-12INNOPEAK TECHNOLOGY INC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Current 3GPP systems face signaling bottlenecks and latency issues due to the dual-connection model between user equipment (UE) and network functions (NFs) via the access and mobility management function (AMF, especially for time-critical services, leading to increased signaling overhead and AMF load.

Method used

Establish a direct, secure non-access stratum (NAS) connection between UE and NF by creating a security context via the AMF, allowing direct NAS signaling without relying on AMF as a relay, using key derivation functions to generate ciphering and integrity protection keys, and enabling seamless handoff without requiring UE knowledge of network topology.

Benefits of technology

Reduces AMF load, improves system efficiency, and enhances scalability by allowing direct secure communication between UE and NF, minimizing signaling overhead and latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025039044_12032026_PF_FP_ABST
    Figure US2025039044_12032026_PF_FP_ABST
Patent Text Reader

Abstract

A wireless communication method performed by a user equipment (UE) includes establishing, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF) and performing secure NAS signaling between the UE and the NF using the security context.
Need to check novelty before this filing date? Find Prior Art

Description

Atty. Dkt. No. 10085-01-0170-PCTAPPARATUSES AND COMMUNICATION METHODSCROSS REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to U.S. Provisional Application No. 63 / 690,162, entitled “METHOD AND SYSTEM FOR ESTABLISHING SECURE NON-ACCESS STRATUM (NAS) CONNECTION BETWEEN UE AND A NETWORK FUNCTION IN A COMMUNICATION SYSTEM,” filed on September 3, 2024, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication systems, and more particularly, to apparatuses and wireless communication methods such as a user equipment (UE), a network function (NF), and wireless communication methods for establishing secure non-access stratum (NAS) connection between the UE and the NF in a communication system.BACKGROUND

[0003] In current 3rd generation partnership project (3GPP) systems, a non-access stratum (NAS) protocol is used to carry signaling between a user equipment (UE) and a core network, typically via an access and mobility management function (AMF). All NAS signaling between the UE and the network must pass through the AMF, even when a service or authentication involves other network functions (NFs) such as a location management function (LMF). With the introduction of a service-based architecture (SB A) in 5G, NFs communicate through service-based interfaces (SBI), while the UE can only interact with the AMF over N1 interface. This design creates a signaling bottleneck and unnecessary latency, especially for time-critical services such as precise positioning.

[0004] Currently, if the UE requests services from an NF, the AMF relays the NAS messages hop-by-hop, maintaining both a NAS connection with the UE and an SBI connection with the NF. This dual-connection model increases signaling overhead and requires the AMF to manage multiple security associations, creating scalability and performance challenges as UE numbers grow. Although handover mechanisms exist in 3GPP, they address cell mobility, not the dynamic reassignment of service termination points between the AMF and other NFs. Existing solutions lack a mechanism to establish a direct, secure NAS connection between the UE and an NF other than the AMF.

[0005] Therefore, there is a need for apparatuses and wireless communication methods such as a user equipment (UE), a network function (NF), and wireless communication methods forAtty. Dkt. No. 10085-01-0170-PCT establishing secure non-access stratum (NAS) connection between the UE and the NF in a communication system.SUMMARY

[0006] An object of the present disclosure is to propose apparatuses and wireless communication methods such as a user equipment (UE), a network function (NF), and wireless communication methods for establishing secure non-access stratum (NAS) connection between the UE and the NF in a communication system, which can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0007] In a first aspect of the present disclosure, a wireless communication method by a user equipment (UE), includes establishing, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF); and performing secure NAS signaling between the UE and the NF using the security context.

[0008] In a second aspect of the present disclosure, a user equipment includes an establisher and an executor. The establisher is configured to establish, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF). The executer is configured to perform secure NAS signaling between the UE and the NF using the security context.

[0009] In a third aspect of the present disclosure, a user equipment includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The user equipment is configured to perform the above method.

[0010] In a fourth aspect of the present disclosure, a wireless communication method by a network function (NF), includes receiving, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with a user equipment (UE) and performing secure NAS signaling with the UE using the security context.

[0011] In a fifth aspect of the present disclosure, a network function (NF) includes a receiver and an executor. The receiver is configured to receive, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with a user equipment (UE). The executer is configured to perform secure NAS signaling with the UE using the security context.

[0012] In a sixth aspect of the present disclosure, a network function (NF) includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The NF is configured to perform the above method.Atty. Dkt. No. 10085-01-0170-PCT

[0013] In a seventh aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.

[0014] In an eighth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.

[0015] In a ninth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.

[0016] In a tenth aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.

[0017] In an eleventh aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obvious that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.

[0019] FIG. 1 A is a block diagram of an example of a 5G SBA architecture.

[0020] FIG. IB is a flowchart of an example of a NAS connection in 5G.

[0021] FIG. 2 is a block diagram of a user equipment (UE) and a network function (NF) of communication in a communication system according to an embodiment of the present disclosure.

[0022] FIG. 3 is a block diagram of a UE according to an embodiment of the present disclosure.

[0023] FIG. 4 is a block diagram of a UE according to an embodiment of the present disclosure.

[0024] FIG. 5 is a flowchart illustrating a wireless communication method performed by a UE according to an embodiment of the present disclosure.

[0025] FIG. 6 is a block diagram of a NF according to an embodiment of the present disclosure.

[0026] FIG. 7 is a block diagram of a NF according to an embodiment of the present disclosure.

[0027] FIG. 8 is a flowchart illustrating a wireless communication method performed by a NF according to an embodiment of the present disclosure.

[0028] FIG. 9 is a block diagram of a proposed SBA architecture enhancement according to an embodiment of the present disclosure.

[0029] FIG. 10 is a flowchart illustrating an example of UE secure NAS transfer to NF according to an embodiment of the present disclosure.Atty. Dkt. No. 10085-01-0170-PCT

[0030] FIG. 11 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.

[0031] FIG. 12 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS

[0032] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.

[0033] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, a LTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.

[0034] Optionally, a user equipment (UE) mentioned in the embodiments of the present application may refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal may be a cellular radio telephone, a cordless telephone, a session initiation protocol (SIP) telephone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device, other processing devices coupled with a wireless modem, an in- vehicle device, a wearable device, a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), etc.

[0035] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.Atty. Dkt. No. 10085-01-0170-PCT

[0036] The non-access stratum (NAS) protocol is defined in a 3GPP system to carry signaling between a user equipment (UE) and a core network (e.g., MME or AMF). All NAS signaling from the UE to the network must go through the AMF, even when the signaling is for authenticating the UE by other network functions within the 3GPP system. 3GPP has adopted a service-based architecture (SBA) in 5G, as illustrated in FIG. 1A, where network functions communicate with each other over service-based interfaces (SBI), while the UE communicates only with the AMF over the N1 interface (i.e., the NAS signaling interface).

[0037] One of the limitations of the SBA architecture is that when other network functions (NFs) need to provide a service to the UE, for example, when a network function such as the location management function (LMF) provides location services, there is no direct signaling path from the UE to the LMF. Instead, the signaling must first go from the UE to the AMF over the N 1 interface, and then the AMF forwards the signaling to the LMF over the service-based interface (SBI). This creates unnecessary signaling delays and imposes additional overhead on the AMF, especially for time-critical services such as precise location. Furthermore, using the AMF as a relay to reach other NFs can create a signaling bottleneck at the AMF, particularly when a large number of UEs are requesting services from NFs other than the AMF.

[0038] Distributed NAS is a new concept in the 3GPP architecture. Existing solutions do not allow a NAS connection to be established directly between the UE and a network function (NF) other than the AMF. However, handovers in 3GPP are designed only for situations where the UE moves from one serving cell to another. In some embodiments of the present disclosure, the UE does not physically move (i.e., it is not a traditional mobility event), but the service request termination point shifts from the AMF to another NF that is designated to provide the requested service to the UE.

[0039] Current NAS connections and procedures operate in a hop-by-hop manner. For example, if the UE needs to access a location service provided by the location management function (LMF), a NAS connection is established between the UE and the AMF, and the AMF relays any service requests or signaling exchanges between the UE and the LMF, as illustrated in FIG. IB. A drawback of the existing NAS procedure is that the AMF must maintain two separate connections, one NAS connection toward the UE and another service-based interface (SBI) connection toward the network function. Given the large number of UEs served by the network, this can overburden the AMF and create a significant performance bottleneck.

[0040] Another drawback is that the AMF must maintain two separate security associations and security contexts, one between the UE and the AMF, and another between the AMF and the other NF. Although the AMF may continue to maintain a separate NAS connection with the UE evenAtty. Dkt. No. 10085-01-0170-PCT after transferring the secure NAS connection to the NF serving the UE, this UE-AMF NAS connection is used solely for other NAS signaling between the UE and the AMF and is not associated with the newly established NAS connection between the UE and the NF.

[0041] In future network upgrades (e.g., 6G), consideration may be given to enabling NAS signaling (e.g., using a distributed NAS architecture) to be routed directly between the UE and a network function (NF) other than the AMF within the enhanced service-based network architecture. Some embodiments of the present disclosure provide a mechanism for establishing a secure NAS connection between the UE and an NF in a communication system, where the AMF serves as an anchor to create the security context between the UE and the NF and then transfers (e.g., hands off) the security context along with the UE’s service request to the NF.

[0042] FIG. 2 illustrates that, in some embodiments, a UE 10 and a NF 20 of communication in a communication system 40. The communication system 40 includes the UE 10 and the NF 20. The UE 10 may include a memory 12, a transceiver 13, and a processor 11 coupled to the memory 12 and the transceiver 13. The NF 20 may include a memory 22, a transceiver 23, and a processor 21 coupled to the memory 22 and the transceiver 23. The processor 11 or 21 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 11 or 21. The memory 12 or 22 is operatively coupled with the processor 11 or 21 and stores a variety of information to operate the processor 11 or 21. The transceiver 13 or 23 is operatively coupled with the processor 11 or 21, and the transceiver 13 or 23 transmits and / or receives a radio signal.

[0043] The processor 11 or 21 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 12 or 22 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 13 or 23 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 12 or 22 and executed by the processor 11 or 21. The memory 12 or 22 can be implemented within the processor 11 or 21 or external to the processor 11 or 21 in which case those can be communicatively coupled to the processor 11 or 21 via various means as is known in the art.

[0044] In some embodiments, the processor 11 is configured to establish, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE 10 and the NF 20, and the processor 11 is configured to perform secure NAS signaling between the UE 10 and the NF 20 using the security context. This can solveAtty. Dkt. No. 10085-01-0170-PCT issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0045] In some embodiments, the transceiver 23 is configured to receive, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with the UE 10; and the processor 21 is configured to perform secure NAS signaling with the UE 10 using the security context. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0046] FIG. 3 illustrates a UE 300 according to an embodiment of the present disclosure. The UE 300 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the UE 300 using any suitably configured hardware and / or software. The UE 300 includes an establisher 301 and an executor 302. The establisher 301 is configured to establish, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF), and the executer 302 is configured to perform secure NAS signaling between the UE and the NF using the security context. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0047] FIG. 4 illustrates a UE 400 according to an embodiment of the present disclosure. The UE400 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the UE 400 using any suitably configured hardware and / or software. The UE 400 may include a memory 401, a transceiver 402, and a processor 403 coupled to the memory 401 and the transceiver 402. The processor 403 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 403. The memory 401 is operatively coupled with the processor 403 and stores a variety of information to operate the processor 403. The transceiver 402 is operatively coupled with the processor 403, and the transceiver 402 transmits and / or receives a radio signal. The processor 403 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory401 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 402 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures,Atty. Dkt. No. 10085-01-0170-PCT functions, and so on) that perform the functions described herein. The modules can be stored in the memory 401 and executed by the processor 403. The memory 401 can be implemented within the processor 403 or external to the processor 403 in which case those can be communicatively coupled to the processor 403 via various means as is known in the art.

[0048] In some embodiments, the processor 403 is configured to is establish, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF), and the processor 403 is configured to perform secure NAS signaling between the UE and the NF using the security context. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0049] FIG. 5 illustrates a wireless communication method 500 performed by a UE according to an embodiment of the present disclosure. The wireless communication method 500 performed by the UE is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the wireless communication method 500 performed by the UE using any suitably configured hardware and / or software. In some embodiments, the wireless communication method 500 performed by the UE includes: an operation 502, establishing, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF); and an operation 504, performing secure NAS signaling between the UE and the NF using the security context. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0050] In some embodiments, the wireless communication method further includes performing registration and authentication with the AMF, wherein a first security context between the UE and the AMF is established during the authentication; transmitting, to the AMF, a service request indicating the NF; and receiving, from the AMF, the security context for communication between the UE and the NF. In some embodiments, the UE receives the security context derived by the AMF using a key derivation function (KDF) with a key shared between the UE and the AMF. In some embodiments, the security context includes a ciphering key and an integrity protection key derived based on an identifier of the NF and one or more functional parameters. In some embodiments, the wireless communication method further includes generating, at the UE, a semi-Atty. Dkt. No. 10085-01-0170-PCT permanent session key in coordination with the AMF, wherein the semi-permanent session key is usable to derive refreshed ciphering and integrity protection keys for NAS signaling with the NF based on an operator key refresh policy. This approach enables the UE to securely and efficiently communicate with the NF while reducing AMF load and supporting dynamic key updates according to operator policies.

[0051] In some embodiments, the method includes UE registration and authentication with the AMF, receiving a security context (with ciphering and integrity keys) derived via KDF, and optionally generating a semi-permanent session key to support key refresh for secure NAS communication with the NF. This method enables efficient and secure NAS communication with the NF, supporting dynamic key updates while reducing AMF processing burden.

[0052] In some embodiments, after sending the service request, the UE receives an indication from the AMF that the security context has been transmitted to the NF along with a NAS handoff request. In some embodiments, the UE is notified by the AMF that the security context has been received by the NF. In some embodiments, the UE performs a NAS security command procedure with the NF to negotiate and activate one or more security algorithms for ciphering and integrity protection. In some embodiments, the UE operates without prior knowledge of a topology or capability of the NF, and relies on the AMF to determine the NF to handle the service request. In some embodiments, the UE operates under a distributed NAS security policy enforced by the AMF, without exposure of the distributed NAS security policy to the UE.

[0053] In some embodiments, after sending the service request, the UE receives an indication from the AMF that the security context has been transmitted to the NF along with a NAS handoff request, and the UE is notified once the NF has received it. The UE then performs a NAS security command procedure with the NF to negotiate and activate security algorithms for ciphering and integrity protection. The UE operates without prior knowledge of the NF’ s topology or capabilities and relies on the AMF to select the appropriate NF, following a distributed NAS security policy managed entirely by the AMF. This approach enables seamless and secure NAS handoff to the NF without requiring the UE to be aware of network topology or security policies, simplifying UE operations and enhancing system scalability.

[0054] FIG. 6 illustrates a NF 600 according to an embodiment of the present disclosure. The NF 600 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the NF 600 using any suitably configured hardware and / or software. The NF 600 includes a receiver 601 and an executor 602. The receiver 601 is configured to receive, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with a user equipment (UE), and the executer 602 isAtty. Dkt. No. 10085-01-0170-PCT configured to perform secure NAS signaling with the UE using the security context. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0055] FIG. 7 illustrates a NF 700 according to an embodiment of the present disclosure. The NF700 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the NF 700 using any suitably configured hardware and / or software. The NF 700 may include a memory 701, a transceiver 702, and a processor 703 coupled to the memory 701 and the transceiver 702. The processor 703 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 703. The memory 701 is operatively coupled with the processor 703 and stores a variety of information to operate the processor 703. The transceiver 702 is operatively coupled with the processor 703, and the transceiver 702 transmits and / or receives a radio signal. The processor 703 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory701 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 702 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 701 and executed by the processor 703. The memory 701 can be implemented within the processor 703 or external to the processor 703 in which case those can be communicatively coupled to the processor 703 via various means as is known in the art.

[0056] In some embodiments, a transceiver 702 is configured to receive, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with a user equipment (UE), and the processor 703 is configured to perform secure NAS signaling with the UE using the security context. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0057] FIG. 8 illustrates a wireless communication method 800 performed by a NF according to an embodiment of the present disclosure. The wireless communication method 800 performed by the NF is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the wireless communication method 800 performed by the NF using any suitably configured hardware and / or software. In some embodiments, theAtty. Dkt. No. 10085-01-0170-PCT wireless communication method 800 performed by the NF includes: an operation 802, receiving, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with a user equipment (UE); and an operation 804, performing secure NAS signaling with the UE using the security context. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency.

[0058] In some embodiments, the wireless communication method further includes receiving, from the AMF, a NAS handoff request along with the security context after the AMF receives a service request from the UE. In some embodiments, the wireless communication method further includes sending, to the AMF, an acknowledgment indicating receipt of the NAS handoff request and the security context. In some embodiments, the security context includes a ciphering key and an integrity protection key derived by the AMF using a key derivation function (KDF) based on a key shared between the UE and the AMF. In some embodiments, the NF performs a NAS security command procedure with the UE to negotiate and activate one or more security algorithms for ciphering and integrity protection. In some embodiments, the NF uses refreshed ciphering and integrity protection keys derived from a semi-permanent session key generated by the UE and the AMF, based on an operator key refresh policy. In some embodiments, the NF operates without receiving prior capability information of the UE, and the AMF determines the NF to handle the service request based on UE registration and authentication information. In some embodiments, the NF operates under a distributed NAS security policy enforced by the AMF, without direct exposure of the security policy to the UE.

[0059] In some embodiments, after receiving a service request from the UE, the AMF sends a NAS handoff request and security context to the NF, and the UE sends an acknowledgment upon receipt. The security context includes ciphering and integrity protection keys derived by the AMF using a key derivation function (KDF) based on a shared key. The NF then performs a NAS security command procedure with the UE to negotiate and activate security algorithms, optionally using refreshed keys derived from a semi-permanent session key generated by the UE and AMF under an operator key refresh policy. The NF operates without prior knowledge of the UE’s capabilities, relying on the AMF to determine service assignments, and functions under a distributed NAS security policy managed by the AMF, with no direct exposure to the UE. This approach enables secure and dynamic UE-NF communication with minimal signaling overhead and without requiring UE-specific configuration at the NF.

[0060] Some embodiments of the present disclosure describe network function (NF) architectures and methods that allow an NF to establish secure non-access stratum (NAS) communicationAtty. Dkt. No. 10085-01-0170-PCT directly with a user equipment (UE) using a security context received from the access and mobility management function (AMF). The NF includes components such as a receiver, processor, memory, and transceiver configured to handle NAS signaling securely with the UE. After the UE sends a service request, the AMF delivers a NAS handoff request and the derived security context — containing ciphering and integrity protection keys — to the NF, which then performs a NAS security command procedure with the UE to negotiate and activate security algorithms. The NF can optionally use refreshed keys derived from a semi-permanent session key shared between the UE and AMF. Importantly, the NF operates without needing prior knowledge of UE capabilities, as the AMF selects and assigns the appropriate NF and enforces the distributed NAS security policy without exposing it to the UE. This approach enables secure, efficient, and scalable direct communication between the UE and NF, reducing AMF load while eliminating the need for preconfiguration or capability exchange at the NF.

[0061] FIG. 9 is a proposed SBA architecture enhancement according to an embodiment of the present disclosure. FIG. 9 illustrates that, in some embodiments, an AMF serves as an anchor function and transfers (e.g., hands off) the UE’s NAS connection to the NF from which the UE requests service, similar to how a UE transitions from one serving base station to another. At the same time, the AMF creates a dedicated security context (e.g., keys used for ciphering and integrity protection) between the UE and the target NF. The AMF then transfers this security context to the NF. The NF and the UE may execute a procedure (e.g., the NAS Security Command procedure currently defined in 5G) to agree on the security algorithms (e.g., ciphering and integrity algorithms) and activate the security context for use.

[0062] Since the UE does not know the network topology (i.e., the services and capabilities of the NFs providing services are not directly visible to the UE in 5G), the UE is unable to directly request services from NFs located in the network. For example, if the UE needs to request a service from a Location Management Function (LMF), it would first need to be made aware of the existence and capabilities of the LMF within the network. Alternatively, the LMF would need to expose its availability to the UE.

[0063] Every UE registration goes through the AMF. After the AMF registers and authenticates the UE (using credentials shared between the UE and the UDM), the AMF becomes aware that the UE is actually requesting a service from another NF. The AMF then uses the security credentials shared between the UE and the UDM to create a UE-NF security context (in addition to the existing access stratum (AS) security context and NAS security context used between the UE and the gNB, and between the UE and the AMF, respectively). This newly created UE-NF security context is transferred to the target NF from which the UE is requesting service. Using this context, the UE and the NF can then establish a secure NAS connection.Atty. Dkt. No. 10085-01-0170-PCT

[0064] The UE needs to access a service offered by the NF. As part of the normal procedure for accessing the network, the UE registers with and authenticates to the network via the AMF.

[0065] As an extension of the authentication and key agreement procedure, establishing NAS security between the UE and the AMF not only produces a set of keys for AS security between the UE and the gNB, and a set of keys for NAS security between the UE and the AMF, but also generates an additional key to be used for NAS security between the UE and another network function.

[0066] The AMF requests the NF to provide the service requested by the UE and transfers the newly established security (e.g., the additional set of keys generated as an extension of the AKA procedure) to the NF. The NF and the UE then establish NAS security using a procedure similar to the NAS Security Mode Command procedure used between the UE and the AMF.

[0067] FIG. 10 illustrates an example of UE secure NAS transfer to NF according to an embodiment of the present disclosure. An example of how a UE and NFx establish a secure NAS connection, with the AMF securely transferring the NAS security context to NFx, is illustrated in FIG. 10 below. The procedure illustrated in FIG. 10 includes at least one of the following operations:

[0068] Operation 1 : The UE and the network perform authentication when the UE requests access to the network. As part of the successful authentication, a security context is established between the UE and the AMF. At this stage, NAS signaling between the UE and the network terminates at the AMF.

[0069] Operation 2: The UE wishes to request a service from NFx (e.g., a location service), and since the UE is only aware of the AMF, it sends the request to the AMF.

[0070] Operation 3: The AMF creates a security context (e.g., a ciphering key and an integrity protection key) between the UE and NFx, for example, using the KAMF shared between the UE and the AMF, such as KNFx NASenc = KDF(KAMF, NFID, FC, PARAM) and KNFx NASint = KDF(KAMF, NFID, FC, PARAM), where NFID denotes the identifier of the NF from which the UE is requesting service, FC denotes the function code for the key derivation function, and PARAM represents other parameters associated with this key generation instance. Alternatively, a semi-permanent session key KNFx_NAS may be generated by the UE and the AMF, allowing the UE and NFx to derive KNFx_NASenc and KNFx_NASint for securing the UE-NFx NAS signaling. This semi-permanent session key can also be reused to refresh or update KNFx NASenc and KNFx_NASint according to the operator’s key refresh security policy if the NAS session between the UE and NFx extends over a long period of time. In Operation 3, the AMF creates a security context between the UE and NFx by deriving ciphering and integrity keys (e.g.,Atty. Dkt. No. 10085-01-0170-PCTKNFx_NASenc and KNFx_NASint) using the shared KAMF or, alternatively, by generating a semi-permanent session key (KNFx_NAS) that allows ongoing key derivation and refresh for long-duration UE-NFx NAS communication.

[0071] Operation 4: The AMF sends a request to NFx to hand off the NAS connection, i.e., it transfers the newly created UE-NFx NAS security context to NFx.

[0072] Operation 5: NFx acknowledges the NAS handoff request from the AMF.

[0073] Operation 6: The AMF informs the UE that the UE-NFx NAS security context has been received by NFx and that the UE’s service request to NFx has been processed.

[0074] Operation 7: The UE and NFx perform a UE-NFx NAS Security Command procedure (similar to the NAS Security Command procedure between the UE and AMF) to agree on the security algorithms to be used and to activate security protection over the UE-NFx NAS layer.

[0075] Operation 8: NAS signaling exchanges between the UE and NFx continue and are protected using the security context activated in Operation 7.

[0076] In another example of a distributed NAS security policy, only the AMF is involved in enforcing the policy. In this case, the only difference is in Operation 2, where the distributed NAS security policy is kept within the network (i.e., sent only to the AMF) and is not shared with the UE. An example is illustrated below in FIG. 10.

[0077] In some embodiments, technical benefits may include at least one of the following. Distributed NAS in an enhanced architecture enables the network to operate as a fully servicebased system, where any service-producing network function (NF) can connect directly to the UE via NAS signaling, without needing to route through the AMF. The proposed solution provides a secure way to establish a NAS connection between the UE and another NF via the AMF. One benefit of this solution is that it allows security to be established between the UE and NFx using the existing security credentials provisioned between the UE and the UDM, eliminating the need to separately provision security credentials between the UE and the NF from which it requests service. The security establishment between the UE and NFx can be incorporated into or integrated with the existing Authentication and Key Agreement (AKA) procedure by extending key derivation to generate new keys specifically for UE-NFx communication (e.g., KNFx_NASenc for ciphering and KNFx NASint for integrity protection, or semi-permanent keys that can later be used to derive KNFx_NASenc and KNFx_NASint). If semi-permanent keys (e.g., KNFx_NAS) are generated at the AMF and UE, protection keys such as KNFx_NASenc and KNFx_NASint can be derived from them. Moreover, if the NAS session between the UE and NFx lasts for an extended period, protection keys can be refreshed using the semi-permanent key without needing to return to the AMF. Further, by eliminating the need for the AMF to act as a relay between theAtty. Dkt. No. 10085-01-0170-PCTUE and NF, the solution improves AMF load capacity and contributes to better load balancing across the network.

[0078] An alternative to using secure transfer of NAS from the AMF to an NF requested by the UE is to allow the UE to directly request service from that NF. However, this would require the UE and the serving NF to share common credentials in order to establish a security context for protecting the NAS connection between the UE and the NF. If there are many NFs capable of providing services to the UE, the UE would need to maintain shared credentials with each of those NFs. Allowing the UE to directly request service from an NF may also require the services or capabilities of the NF to be exposed (i.e., made known) to the UE through a service or capability exposure procedure involving a network entity such as the Network Exposure Function (NEF). However, since the UE must already register and authenticate with the network via the AMF, using the AMF as a secure NAS transfer anchor reduces the need for an additional exposure function to make the services and capabilities of the NF visible to the UE.

[0079] In summary, some embodiments of the present disclosure describe a method for securely establishing a NAS connection between a UE and a network function (NFx) through the assistance of the AMF. As outlined in FIG. 10, the procedure includes key operations such as UE registration and authentication with the AMF, the UE’s service request to the AMF, the AMF’s creation and transfer of a UE-NFx security context, and the activation of secure NAS signaling between the UE and NFx. The AMF generates security keys (e.g., ciphering and integrity protection keys) using key derivation based on shared credentials between the UE and UDM, or through semi-permanent session keys that allow ongoing key refreshes without requiring additional AMF involvement. Once the NAS security context is handed off and acknowledged, the UE and NFx negotiate security algorithms and establish protected NAS communication. This distributed NAS architecture offers several technical benefits: it enables a fully service-based network where any NF can communicate securely with the UE without relaying through the AMF, reduces the need for individual UE-NF credential provisioning, integrates smoothly with existing AKA procedures, supports long-lived sessions with dynamic key updates, and improves network scalability and AMF load balancing by removing unnecessary signaling bottlenecks.

[0080] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Allow the UE to maintain secure NAS communication directly with the serving NF, thereby reducing AMF load and improving system efficiency. 4. Provide a good communication performance. 5. Provide high reliability. 6. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto-bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR deviceAtty. Dkt. No. 10085-01-0170-PCT maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards to create an end product. Some embodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposed solution, method, system, and apparatus are widely used in an AIoT device, a node (UE / BS), and / or a communication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.

[0081] FIG. 11 is an example of a computing device 1400 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 11 illustrates an example of the computing device 1400 that can implement apparatuses and methods of the above embodiments of FIGs. 1A to 10, using any suitably configured hardware and / or software. In some embodiments, the computing device 1400 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.

[0082] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer-readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other program code. Non-limiting examples of a computer-readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random access memory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.

[0083] The computing device 1400 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1400. The computing device 1400 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1400 is illustrated with an input / output (“VO”)Atty. Dkt. No. 10085-01-0170-PCT interface 1418 that can receive input from one or more input devices 1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input events in response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.

[0084] The computing device 1400 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1A to 10. The program code may be resident in the memory 1414 or any suitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.

[0085] The computing device 1400 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1400 can transmit messages as electronic or optical signals via the network interface device 1424.

[0086] FIG. 12 is a block diagram of an example of a communication system 1500 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1500 using any suitably configured hardware and / or software. FIG. 12 illustrates the communication system 1500 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (I / O) interface 1580, coupled with each other at least as illustrated.

[0087] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include any combination of general -purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable various applications and / or operating systems running on the system. The communication system 1500 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1A to 10. The program code may beAtty. Dkt. No. 10085-01-0170-PCT resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.

[0088] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wireless personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multimode baseband circuitry.

[0089] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, baseband circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.

[0090] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments of FIGs. 1A to 10 may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, for system. The memory / storage for oneAtty. Dkt. No. 10085-01-0170-PCT embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.

[0091] In various embodiments, the I / O interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments, the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / or RF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.

[0092] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1500 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.

[0093] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware or combinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.

[0094] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative couplingAtty. Dkt. No. 10085-01-0170-PCT operate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.

[0095] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units. Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.

[0096] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.

[0097] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.

Claims

Atty. Dkt. No. 10085-01-0170-PCTWhat is claimed is:

1. A wireless communication method performed by a user equipment (UE), comprising: establishing, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF); and performing secure NAS signaling between the UE and the NF using the security context.

2. The wireless communication method of claim 1, further comprising: performing registration and authentication with the AMF, wherein a first security context between the UE and the AMF is established during the authentication; transmitting, to the AMF, a service request indicating the NF; and receiving, from the AMF, the security context for communication between the UE and the NF.

3. The wireless communication method of claim 2, wherein the UE receives the security context derived by the AMF using a key derivation function (KDF) with a key shared between the UE and the AMF.

4. The wireless communication method of claim 3, wherein the security context comprises a ciphering key and an integrity protection key derived based on an identifier of the NF and one or more functional parameters.

5. The wireless communication method of claim 1, wherein further comprising: generating, at the UE, a semi-permanent session key in coordination with the AMF, wherein the semi-permanent session key is usable to derive refreshed ciphering and integrity protection keys for NAS signaling with the NF based on an operator key refresh policy.

6. The wireless communication method of claim 1, wherein after sending the service request, the UE receives an indication from the AMF that the security context has been transmitted to the NF along with a NAS handoff request.

7. The wireless communication method of claim 6, wherein the UE is notified by the AMF that the security context has been received by the NF.

8. The wireless communication method of claim 1, wherein the UE performs a NAS security command procedure with the NF to negotiate and activate one or more security algorithms for ciphering and integrity protection.

9. The wireless communication method of claim 1, wherein the UE operates without prior knowledge of a topology or capability of the NF, and relies on the AMF to determine the NF to handle the service request.

10. The wireless communication method of claim 1, wherein the UE operates under a distributed NAS security policy enforced by the AMF, without exposure of the distributed NAS security policy to the UE.Atty. Dkt. No. 10085-01-0170-PCT11. A wireless communication method performed by a network function (NF), comprising: receiving, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with a user equipment (UE); and performing secure NAS signaling with the UE using the security context.

12. The wireless communication method of claim 11, further comprising: receiving, from the AMF, a NAS handoff request along with the security context after the AMF receives a service request from the UE.

13. The wireless communication method of claim 12, further comprising: sending, to the AMF, an acknowledgment indicating receipt of the NAS handoff request and the security context.

14. The wireless communication method of claim 11, wherein the security context comprises a ciphering key and an integrity protection key derived by the AMF using a key derivation function (KDF) based on a key shared between the UE and the AMF.

15. The wireless communication method of claim 11, wherein the NF performs a NAS security command procedure with the UE to negotiate and activate one or more security algorithms for ciphering and integrity protection.

16. The wireless communication method of claim 11, wherein the NF uses refreshed ciphering and integrity protection keys derived from a semi-permanent session key generated by the UE and the AMF, based on an operator key refresh policy.

17. The wireless communication method of claim 1, wherein the NF operates without receiving prior capability information of the UE, and the AMF determines the NF to handle the service request based on UE registration and authentication information.

18. The method of claim 11, wherein the NF operates under a distributed NAS security policy enforced by the AMF, without direct exposure of the security policy to the UE.

19. A user equipment (UE), comprising: an establisher configured to establish, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF); and an executer configured to perform secure NAS signaling between the UE and the NF using the security context.

20. A user equipment (UE), comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the UE is configured to perform the wireless communication method of any one of claimsAtty. Dkt. No. 10085-01-0170-PCTI to 10.

21. A network function (NF), comprising: a receiver configured to receive, from an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication with a user equipment (UE); and an executer configured to perform secure NAS signaling with the UE using the security context.

22. A network function (NF), comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the NF is configured to perform the wireless communication method of any one of claimsII to 18.

Citation Information

Patent Citations

  • First and Second Connections with an Authentication Management Function

    US20200413258A1

  • Security context for target amf

    US20230262453A1

  • Security Context Obtaining Method and Apparatus, and Communications System

    US20240040380A1

  • Communication apparatus, first communication apparatus, method of communication apparatus, and method of first communication apparatus

    WO2023068118A1

  • Security in a distributed NAS terminations architecture

    WO2024035434A1