Method and device for establishing session for using network slice
A zero-trust architecture with remote attestation for network slices addresses security gaps in mobile communication systems, ensuring secure and reliable network slice usage by dynamically verifying network functions.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2025-09-29
- Publication Date
- 2026-04-23
AI Technical Summary
Existing network slices in mobile communication systems lack design considerations for security aspects, particularly in environments where multiple operators' network functions are deployed on a single server, leading to potential security breaches that can spread across entities.
Implement a zero-trust architecture (ZTA) based security scheme for network slices, utilizing remote attestation (RA) to dynamically verify the integrity of network functions and ensure secure session management through secure-access and mobility management functions (sAMF), secure-session management functions (sSMF), and secure-user plane functions (sUPF).
Enhances security by ensuring reliable and secure network slice usage, preventing the spread of attacks across entities and maintaining system integrity through continuous integrity checks.
Smart Images

Figure KR2025015309_23042026_PF_FP_ABST
Abstract
Description
Method and device for establishing a session for using network slices
[0001] The present disclosure relates to a method and apparatus for establishing a session for using network slices.
[0002] Looking back at the evolution of wireless communication through successive generations, technologies have been developed primarily for human-oriented services, such as voice, multimedia, and data. Following the commercialization of 5G (5th-generation) communication systems, connected devices, which have been increasing explosively, are expected to be connected to communication networks. Examples of networked objects include vehicles, robots, drones, home appliances, displays, smart sensors installed in various infrastructures, construction machinery, and factory equipment. Mobile devices are expected to evolve into various form factors, such as augmented reality glasses, virtual reality headsets, and holographic devices. In the 6G (6th-generation) era, efforts are underway to develop improved 6G communication systems to connect hundreds of billions of devices and objects to provide diverse services. For this reason, 6G communication systems are being referred to as "beyond 5G" systems.
[0003] In the 6G communication system predicted to be realized around 2030, the maximum transmission speed is tera (i.e., 1,000 gigabit) bps, and the wireless latency is 100 microseconds (μsec). In other words, compared to the 5G communication system, the transmission speed in the 6G communication system is 50 times faster, and the wireless latency is reduced to one-tenth.
[0004] To achieve such high data transmission speeds and ultra-low latency, 6G communication systems are being considered for implementation in the terahertz band (e.g., the 95 GHz to 3 terahertz (3 THz) band). In the terahertz band, due to more severe path loss and atmospheric absorption compared to the millimeter wave (mmWave) band introduced in 5G, the importance of technology capable of guaranteeing signal reach, or coverage, is expected to increase. As key technologies to ensure coverage, radio frequency (RF) devices, antennas, new waveforms that offer better coverage than orthogonal frequency division multiplexing (OFDM), beamforming, and multi-antenna transmission technologies such as massive multiple-input and multiple-output (massive MIMO), full-dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas must be developed. In addition, new technologies such as metamaterial-based lenses and antennas, high-dimensional spatial multiplexing technology using orbital angular momentum (OAM), and reconfigurable intelligent surface (RIS) are being discussed to improve coverage of terahertz band signals.
[0005] In addition, to improve frequency efficiency and system network, development is underway in 6G communication systems for full duplex technology, in which uplink and downlink simultaneously utilize the same frequency resources at the same time; network technology that integrates satellites and HAPS (high-altitude platform stations); network structure innovation technology that supports mobile base stations and enables network operation optimization and automation; dynamic spectrum sharing technology through collision avoidance based on spectrum usage prediction; AI-based communication technology that utilizes AI (artificial intelligence) from the design stage and internalizes end-to-end AI support functions to realize system optimization; and next-generation distributed computing technology that realizes services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high performance communication and computing resources (mobile edge computing (MEC), cloud, etc.). In addition, attempts are continuing to further strengthen connectivity between devices, further optimize networks, promote the softwareization of network entities, and increase the openness of wireless communication through the design of new protocols to be used in 6G communication systems, the implementation of hardware-based security environments, the development of mechanisms for the safe utilization of data, and the development of technologies regarding privacy maintenance methods.
[0006] Due to the research and development of such 6G communication systems, it is expected that a new dimension of hyper-connected experience will become possible through the hyper-connectivity of 6G communication systems, which encompasses not only connections between objects but also connections between people and objects. Specifically, it is projected that 6G communication systems will enable the provision of services such as truly immersive extended reality (truly immersive XR), high-fidelity mobile holograms, and digital replicas. Furthermore, services such as remote surgery, industrial automation, and emergency response, which are provided through 6G communication systems with enhanced security and reliability, will be applied in various fields including industry, healthcare, automotive, and home appliances.
[0007] Meanwhile, due to the full-scale adoption of cloud and virtualization technologies, mobile communication systems may consider existing boundary-based security frameworks, such as firewalls, IPSec (Internet Protocol Security), and TLS (Transport Layer Security), for their components. Alternatively, mobile communication systems may consider applying a Zero Trust security framework. With the introduction of virtualization technology, various Network Functions (NFs) can be distributed across commercial off-the-shelf (COTS) servers in remote locations in the form of virtualized Virtual Network Functions (VNFs) and Cloud-Native Network Functions (CNFs). In environments where NFs from multiple operators are deployed on a single COTS server or where third-party applications coexist, a breach of a single entity can cause attacks to spread to various entities sharing the COTS server. Remote locations can include edge environments, cloud environments, and private networks. To address this issue, communication systems can utilize technologies such as Remote Attestation (RA) to continuously perform integrity checks on distributed entities even in remote locations. Through these continuous integrity checks of entities, communication systems can ensure system reliability. The communication system can support technology that can remotely verify the integrity of execution to apply a zero-trust security system.
[0008] At least one device included in the communication system can produce network slices based on requirements for throughput or latency. At least one device included in the communication system may lack a design that considers security aspects regarding network slices.
[0009] The present disclosure provides a method and apparatus for establishing a session for using network slices.
[0010] A method for a secure-access and mobility management function (sAMF) for using a network slice according to one embodiment of the present disclosure for achieving the above objective may include: receiving a packet data unit (PDU) session establishment request message transmitted by a user equipment (UE); determining whether to perform remote attestation (RA) using the PDU session establishment request message; selecting a secure-session management function (sSMF) authenticated through the RA based on the PDU session establishment request message and the determination of whether to perform the RA; transmitting a context request message to the sSMF that includes information indicating whether the selected sSMF performs additional RA; receiving a context response message from the sSMF; and performing a PDU session authentication / authorization procedure using the context response message.
[0011] A method of a secure-session management function (sSMF) for using a network slice according to one embodiment of the present disclosure for achieving the above objective may include the steps of: receiving a context request message from a secure-access and mobility management function (sAMF) containing information indicating whether the sSMF performs additional remote attestation (RA); transmitting a context response message to the sAMF; performing a PDU session authentication / authorization procedure using the context response message; selecting a secure-point coordination function (sPCF) using the context request message; and selecting a secure-user plane function (sUPF) using the context request message.
[0012] A method of a UE (user equipment) for using a network slice according to one embodiment of the present disclosure for achieving the above objective may include the step of determining whether a URSP (UE route selection policy) rule is set, and if it is determined that the URSP rule is set, the step of transmitting a PDU (packet data unit) session establishment request message to a sAMF (secure-access and mobility management function) using the URSP rule.
[0013] An apparatus for a secure-access and mobility management function (sAMF) for using a network slice according to one embodiment of the present disclosure for achieving the above objective comprises a transceiver and a control unit, wherein the control unit receives a packet data unit (PDU) session establishment request message transmitted by a user equipment (UE), determines whether to perform remote attestation (RA) using the PDU session establishment request message, selects a secure-session management function (sSMF) authenticated through the RA based on the PDU session establishment request message and the determination of whether to perform the RA, transmits a context request message to the sSMF including information indicating whether the selected sSMF performs additional RA, receives a context response message from the sSMF, and is configured to perform a PDU session authentication / authorization procedure using the context response message.
[0014] It may include a device of sAMF.
[0015] An apparatus for a secure-session management function (sSMF) for using a network slice according to one embodiment of the present disclosure for achieving the above objective may include a transceiver; and a control unit, wherein the control unit receives a context request message from a secure-access and mobility management function (sAMF) containing information indicating whether the sSMF performs additional remote attestation (RA), transmits a context response message to the sAMF, performs a PDU session authentication / authorization procedure using the context response message, selects a secure-point coordination function (sPCF) using the context request message, and selects a secure-user plane function (sUPF) using the context request message.
[0016] A device of a UE (user equipment) for using a network slice according to one embodiment of the present disclosure for achieving the above objective may include a transmitting and receiving unit; and a control unit, wherein the control unit determines whether a URSP (UE route selection policy) rule is set, and if it is determined that the URSP rule is set, the device of the UE is configured to transmit a PDU (packet data unit) session establishment request message to a sAMF (secure-access and mobility management function) using the URSP rule.
[0017] Devices supporting 6G (6th-generation) communication can utilize quantum security algorithms to provide communication services for application fields requiring special security, such as government applications, military communications, medical services, and financial services.
[0018] A method and apparatus according to one embodiment of the present disclosure can dynamically perform reliability verification for network functions (NFs) that constitute a secure network slice using a zero-trust architecture (ZTA) based security scheme.
[0019] A method and apparatus according to one embodiment of the present disclosure can provide a secure network slice by dynamically performing reliability verification on NFs constituting a secure network slice using a ZTA-based security system.
[0020] When a URSP (UE Route Selection Policy) is not configured on a UE (user equipment), the method and device according to one embodiment of the present disclosure may assign a network slice with security applied by default, rather than assigning a network slice based on a Default NSSAI (network slice selection assistance information) value for using a network slice with enhanced security.
[0021] A method and apparatus according to one embodiment of the present disclosure can provide a policy setting method that enables a UE to dynamically check the reliability of a network slice based on RA (remote attestation) in a URSP.
[0022] A method and apparatus according to one embodiment of the present disclosure can provide a PDU (packet data unit) session establishment procedure that enables the UE to dynamically perform reliability assurance based on RA when the UE uses a security-enhanced network slice.
[0023] A method and apparatus according to one embodiment of the present disclosure can enhance security for network slices by dynamically performing reliability verification for NFs constituting a next-generation communication system through RA execution.
[0024] FIG. 1 is a block diagram illustrating a network slice of a mobile communication system according to one embodiment of the present disclosure.
[0025] FIG. 2 is a block diagram illustrating network slice identifiers according to one embodiment of the present disclosure.
[0026] FIG. 3 is a conceptual diagram illustrating the types of NSSAI (network slice selection assistance information) according to one embodiment of the present disclosure.
[0027] FIG. 4 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure.
[0028] FIG. 5 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure.
[0029] FIG. 6 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure.
[0030] FIG. 7 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure.
[0031] FIG. 8 is a conceptual diagram illustrating a zero-trust architecture (ZTA) based procedure according to one embodiment of the present disclosure.
[0032] FIG. 9 is a conceptual diagram illustrating a remote attestation (RA) based procedure according to one embodiment of the present disclosure.
[0033] FIG. 10 is a block diagram illustrating a network function (NF) service registration procedure according to one embodiment of the present disclosure.
[0034] FIG. 11 is a block diagram illustrating a network function (NF) service registration procedure according to one embodiment of the present disclosure.
[0035] FIG. 12 is a conceptual diagram illustrating a network function for distributing a cloud according to one embodiment of the present disclosure.
[0036] FIG. 13 is a conceptual diagram illustrating a security-enhanced network slice (SE-NS) according to one embodiment of the present disclosure.
[0037] FIG. 14 is a conceptual diagram illustrating an SE-NS policy and session establishment procedure for user equipment (UE) according to one embodiment of the present disclosure.
[0038] FIG. 15 is a flowchart illustrating a procedure for generating sNF (secure-NF) of a RAN (radio access network) and a Core Network that constitutes an SE-NS according to one embodiment of the present disclosure.
[0039] FIG. 16 is a flowchart illustrating a procedure for generating sNFs of a RAN and a Core Network constituting an SE-NS according to one embodiment of the present disclosure.
[0040] FIG. 17a is a conceptual diagram illustrating an NF registration procedure using RA according to one embodiment of the present disclosure.
[0041] FIG. 17b is a conceptual diagram illustrating an NF registration procedure using RA according to one embodiment of the present disclosure.
[0042] FIG. 17c is a conceptual diagram illustrating an NF registration procedure using RA according to one embodiment of the present disclosure.
[0043] FIG. 18 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0044] FIG. 19 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0045] FIG. 20 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0046] FIG. 21 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0047] FIG. 22 is a conceptual diagram illustrating a security-enhanced network slice service according to one embodiment of the present disclosure.
[0048] FIG. 23 is a conceptual diagram illustrating a virtual network function (VNF) / cloud-native network function (CNF) remote proof according to one embodiment of the present disclosure.
[0049] FIG. 24 is a block diagram illustrating a UE device according to one embodiment of the present disclosure.
[0050] FIG. 25 is a block diagram illustrating an entity device according to one embodiment of the present disclosure.
[0051] The operating principles of the present disclosure will be described in detail below with reference to the attached drawings. In describing the present disclosure below, specific descriptions of related known functions or configurations will be omitted if it is determined that such detailed descriptions would unnecessarily obscure the essence of the present disclosure. Furthermore, the terms described below are defined in consideration of their functions in the present disclosure, and these may vary depending on the intentions or practices of the user or operator. Therefore, their definitions should be based on the content throughout this specification.
[0052] For the same reason, some components in the attached drawings have been omitted or depicted schematically. Additionally, the dimensions of each component do not fully reflect their actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.
[0053] The advantages and features of the present disclosure and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms. Various embodiments are provided to make the present disclosure complete and to fully inform those skilled in the art of the scope of the present disclosure, and the present disclosure is defined only by the scope of the claims. Throughout the specification, like reference numerals refer to like components.
[0054] At this time, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored in computer-available or computer-readable memory that can be directed toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored in computer-available or computer-readable memory can also produce a manufactured item containing the means of instruction to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).
[0055] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specific logical function(s). It should also be noted that in some alternative execution examples, the functions mentioned in the blocks may occur out of order. For instance, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may be executed in reverse order according to their corresponding functions.
[0056] In various embodiments of the present disclosure, the term “part” as used refers to a software or hardware component, and the “part” performs certain roles. However, the “part” is not limited to software or hardware. The “part” may be configured to reside in an addressable storage medium or may be configured to operate one or more processors. Thus, by example, the “part” includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and “parts” may be combined into a smaller number of components and “parts” or further separated into additional components and “parts.” Furthermore, the components and “parts” may be implemented to operate one or more CPUs within a device or secure multimedia card. In addition, in various embodiments of the present disclosure, the '~part' may include one or more processors.
[0057] In the present disclosure, each of the phrases such as “A and / or B,” “A or B,” “at least one of A and B,” “at least one of A or B,” “A, B or C,” “at least one of A, B and C,” and “at least one of A, B, or C” may include any one of the items listed together in the corresponding phrase, or all possible combinations thereof. Terms such as “first,” “second,” or “first” or “second” may be used simply to distinguish a component from another component and do not limit the components in any other aspect (e.g., importance or order).
[0058] In the embodiments of the present disclosure, user equipment (UE) may be a terminal, a mobile station (MS), a cellular phone, a smartphone, a computer, or various electronic devices capable of performing communication functions. Additionally, a base station (BS) is a network entity that performs resource allocation to a terminal and may be a Node B, an eNB (eNode B), a gNB (gNode B), a wireless access unit, a base station controller, or a node on a network.
[0059] Furthermore, various embodiments of the present disclosure may be applied to other communication systems having a technical background or channel type similar to the various embodiments of the present disclosure described below. Additionally, various embodiments of the present disclosure may be applied to other communication systems with some modifications made at the discretion of a person with skilled technical knowledge, provided that they do not deviate significantly from the scope of the present disclosure.
[0060] The present invention is capable of various modifications and may have various embodiments, and specific embodiments are illustrated in the drawings and described in detail. However, this is not intended to limit the invention to specific embodiments, and it should be understood that the invention includes all modifications, equivalents, and substitutions that fall within the spirit and scope of the invention.
[0061] Terms such as "first," "second," etc., may be used to describe various components, but said components should not be limited by said terms. These terms are used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of the present invention, the first component may be named the second component, and similarly, the second component may be named the first component.
[0062] When it is stated that one component is "connected" or "connected" to another component, it should be understood that while it may be directly connected or connected to that other component, there may also be other components in between. On the other hand, when it is stated that one component is "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between.
[0063] The terms used in this application are used merely to describe specific embodiments and are not intended to limit the invention. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this application, terms such as "comprising" or "having" are intended to indicate the presence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0064] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as generally understood by those skilled in the art to which the present invention pertains. Terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an ideal or overly formal sense unless explicitly defined in this application.
[0065] Hereinafter, preferred embodiments of the present invention will be described clearly and in detail with reference to the attached drawings so that a person skilled in the art can easily practice the present invention.
[0066] 5G wireless communication technology can define wide frequency bands to enable fast transmission speeds and new services. 5G wireless communication technology can be implemented in frequency bands below 6 GHz ('Sub 6 GHz'), such as 3.5 gigahertz (3.5 GHz). 5G wireless communication technology can also be implemented in ultra-high frequency bands ('Above 6 GHz'), known as millimeter wave (mmWave), such as 28 GHz and 39 GHz. 6G wireless communication technology, referred to as a system beyond 5G, can be implemented in terahertz bands (e.g., the 3 terahertz (3 THz) band at 95 GHz) to achieve transmission speeds 50 times faster and ultra-low latency reduced to one-tenth compared to 5G wireless communication technology.
[0067] 5G wireless communication technology may include technologies aimed at supporting services and satisfying performance requirements for enhanced mobile broadband (eMBB), ultra-reliable low-latency communications (URLLC), and massive machine-type communications (mMTC). 5G wireless communication technology may include beamforming and Massive MIMO (multiple-input and multiple-output) to mitigate path loss of radio waves in the ultra-high frequency band and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple subcarrier spacing) and dynamic operation of slot formats for efficient utilization of ultra-high frequency resources, initial access technology to support multi-beam transmission and broadband, definition and operation of BWP (band-width part), new channel coding methods such as LDPC (low density parity check) codes for high-volume data transmission and polar codes for reliable transmission of control information, L2 pre-processing, and network slicing to provide dedicated networks specialized for specific services.
[0068] 5G wireless communication technology can be used for the improvement and performance enhancement of initial 5G wireless communication technology, taking into account the services intended to be supported. 5G wireless communication technology can be used in the physical layer for technologies such as V2X (vehicle-to-everything), which helps autonomous vehicles make driving decisions based on their own location and status information transmitted by the vehicle and enhances user convenience; NR-U (new radio unlicensed), which aims for system operation in unlicensed bands to comply with various regulatory requirements; NR (new radio) terminal low power consumption technology (UE Power Saving); non-terrestrial network (NTN), which is terminal-satellite direct communication to secure coverage in areas where communication with the terrestrial network is impossible; and positioning.
[0069] 5G wireless communication technology may include technologies in the field of wireless interface architecture / protocols, such as industrial internet of things (IIoT) for supporting new services through linkage and convergence with other industries, integrated access and backhaul (IAB) that provides nodes for expanding network service areas by integrating wireless backhaul links and access links, mobility enhancement technologies including conditional handover and dual active protocol stack (DAPS) handover, and 2-step random access (2-step RACH (random access channel) for NR) that simplifies random access procedures. It may also include technologies in the field of system architecture / services, such as 5G baseline architecture for incorporating network functions virtualization (NFV) and software-defined networking (SDN) technologies (e.g., service-based architecture, service-based interface), and mobile edge computing (MEC) that provides services based on the location of the terminal.
[0070] When technology for 5G wireless communication systems is commercialized, connected devices, which are increasing explosively, can be connected to communication networks. It may be necessary to enhance the functionality and performance of 5G wireless communication systems and to integrate the operation of connected devices. 5G wireless communication systems may include technologies for 5G performance improvement and complexity reduction using artificial intelligence (AI) and machine learning (ML), as well as technologies for supporting AI services, metaverse services, and drone communication, in order to efficiently support augmented reality (AR), virtual reality (VR), mixed reality (MR), etc., and extended reality (XR).
[0071] The advancement of 5G wireless communication systems can serve as a foundation for the development of new waveforms for ensuring coverage in the terahertz band of 6G wireless communication technology, multi-antenna transmission technologies such as full-dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas, metamaterial-based lenses and antennas, high-dimensional spatial multiplexing technology using OAM (orbital angular momentum), and reconfigurable intelligent surface (RIS) technology to improve coverage of terahertz band signals, as well as full-duplex technology for improving frequency efficiency and system networks of 6G wireless communication technology, AI-based communication technology that realizes system optimization by utilizing satellites and artificial intelligence (AI) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology that realizes services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high-performance communication and computing resources.
[0072] Network slicing technology defined in mobile communication systems can provide hardware infrastructure resources tailored to the requirements of various services through virtualization technology. The GSMA and 3GPP may define network slices such as eMBB (enhanced mobile broadband), URLLC (ultra-reliable low latency communications), and mMTC (massive machine type communications) as standards. Network slicing technology can create network slice services according to the operator's requirements. Network slicing technology can be standardized to provide services according to the operator's requirements. Network slicing technology can provide services for eMBB, URLLC, mMTC, and various verticals based on SLA (service level agreement) requirements. At least one device included in the mobile communication system can receive requirements defined based on GST (generic network slice template) / NEST (network slice type) and apply them to the system. A generic network slice template (GST) may include attributes for providing specific network slices required by eMBB, URLLC, mMTC, and various verticals. A network slice template (NEST) may refer to a template form in which appropriate values are filled into the attributes defined in the generic network slice template to provide specific network slice services. GST / NEST can be used by a network slice provider (NSP) to prepare a network slice instance (NSI) that satisfies a specific SLA for a network slice consumer (NSC).
[0073] To address the problems arising from network slices that lack design consideration for security aspects, the present disclosure may propose a policy and session establishment method that enables a user device (UE) to use a network slice with enhanced security.
[0074] FIG. 1 is a block diagram illustrating a network slice of a mobile communication system according to one embodiment of the present disclosure.
[0075] Referring to FIG. 1, at least one device included in the communication system may include technology for a security-enhanced network slice service in a mobile communication system.
[0076] An NSC (network slice customer) (101) may refer to an entity or organization that uses a network slice within a 5G network to meet specific service requirements. An NSC (network slice customer) (101) may provide requirements (103) for at least one device included in a communication system to a network operator. An NSC (101) may provide a use case (102) to a network operator. In other words, an NSC (101) may provide a UE's use case to a network operator (NOP) or a network slice provider (NSP). An NSC (101) may provide service requirements and technical requirements for a network slice of a network entity associated with an NOP. An NSC (101) may provide service requirements and technical requirements for a network slice of a network entity associated with an NSP. A UE may request a network slice based on the use case (102). A generic network slice template (GST) (104) containing a set of attributes characterizing a network slice type (NEST) (105) can be used to convert service requirements and / or technical requirements into a set of attributes. The GST (104) may include a coverage area, a maximum number of terminals (maxNumberofUEs), an uplink data transmission rate (uLThptPerUE), or a downlink data transmission rate slice subnet (dLThptPerSliceSubnet). The uplink data transmission rate (uLThptPerUE) may refer to the data transmission rate supported by the network slice subnet for each UE.The downlink data transmission rate slice subnet (dLThptPerSliceSubnet) may refer to the achievable data transmission rate of a network slice subnet in the downlink that is available ubiquitously across the coverage area of the slice subnet. The set of attributes may be represented using a service profile. At least one device included in the communication system may have a network slice type (NEST) (105) created that includes a GST (104) filled with values. Values may be assigned to represent a defined set of service requirements and / or technical requirements to support the use case (102) of the NSC (101). The NEST (105) may be used as an input for network slice preparation.
[0077] Network slice management and orchestration (106) may include at least one of a CSC (commun. service consumer, CSC) (107), a CSP (commun. service provider, CSP) (108), or a NOP (network operator, NOP) (109). The CSC (107) may include a CSMF (commun. Service management function, CSMF). The CSP (108) may include a NSMF (network slice management function). The NOP (109) may include at least one of a CN (core network) NSSMF (network slice subnet management function), an AN (access network) NSSMF, or a TN (transport network) NSSMF.
[0078] The communications service management function (CSFM) can receive GST / NEST. The CSFM can convert GST / NEST into a service profile. The CSFM can transmit the service profile to the network slice management function (NSMF). GST / NEST can be defined by the GSMA. The service profile can be defined by 3GPP. The service profile associated with the network slice can be obtained from the NEST (105).
[0079] The CSP (108) can generate one or more subnet slice profiles from the slice profile. One or more subnet slice profiles can be associated with one or more corresponding network domains of the 5G network. The CSP (108) can generate a top slice subnet profile (TSSP) using the slice profile. Based on the TSSP, the CSP (108) can generate a radio access network (RAN) slice subnet profile, a transport network (TN) slice subnet profile, or a core network (CN) slice subnet profile. In other words, the NSMF can receive a service profile. The NSMF can convert the received service profile into a Top Slice Subnet Profile. NSMF can be converted into at least one of the domain-specific profiles of each mobile communication system: a RAN (radio access network) Slice Subnet Profile, a CN (core network Slice Subnet Profile), or a TN (transport network) Slice Subnet Profile. The CSP (108) can generate one or more subnet slice profiles to correspond to one or more network domains of the 5G network. For example, a core slice subnet profile can be used to convey core network domain requirements. A radio access network subnet slice profile can be used to convey radio access network domain requirements. A transport network slice subnet profile can be used to convey transport domain requirements.
[0080] According to each domain-specific profile, the network operator (NOP) (109) can set the characteristics defined in the corresponding profile for each domain network component. The network operator (NOP) (109) can create network slices using the defined characteristics. One or more subnet slice profiles may be configured to classify one or more attributes into configurable attributes. Configurable attributes may include at least one of performance attributes and quality attributes. Performance attributes may be related to key performance indications (KPIs), such as downlink or uplink throughput. Quality attributes may be related to quality of service parameters, such as packet loss, packet delay variation, and jitter. Non-configurable attributes may include at least one of coverage attributes and feature attributes. Coverage attributes may be related to attributes that limit service accessibility. Feature attributes may indicate the supportability of various functions in the network slice. Configurable attributes may be converted into configuration parameters (i.e., values). Configurable attributes may be enforced by one or more network entities at runtime. Unconfigurable attributes remain at the NSMF or NSSMF level as necessary slice functions and can be enforced by the NSMF or NSSMF during slice provisioning.
[0081] The profile attributes that map to the GSMA attributes defined for GST / NEST can be represented as follows.
[0082]
[0083] FIG. 2 is a block diagram illustrating network slice identifiers according to one embodiment of the present disclosure.
[0084] Referring to FIG. 2, the network slice identifier may include at least one of NSSAI (201), S-NSSAIs (203), or S-NSSAI (single-network slice selection assistance Information) (205). At least one device included in the communication system to use a network slice created according to a service level agreement (SLA) may include at least one of NSSAI (network slice selection assistance information) (201), S-NSSAIs (single-network slice selection assistance Information) (203), SST (slice / service type), or SD (service differentiator). In other words, at least one device included in the communication system may include at least one of NSSAI (201), S-NSSAIs (203), or S-NSSAI (205).
[0085] NSSAI (201) may include at least one of configured NSSAI, Requested NSSAI, or Allowed NSSAI. Configured NSSAI may refer to an NSSAI configured for the UE. Requested NSSAI may refer to an NSSAI for the UE to check whether a specific network slice is available to the NW. Allowed NSSAI may refer to an NSSAI (201) for the NW to inform the UE whether a specific network slice is available.
[0086] S-NSSAIs (203) may include at least one of S-NSSAIs#1, S-NSSAIs#2, S-NSSAIs#3, S-NSSAIs#4, S-NSSAIs#5, S-NSSAIs#6, S-NSSAIs#7, or S-NSSAIs#8. S-NSSAI (205) may include at least one of SST or SD. At least one device included in the communication system can identify various network slices by a combination of SST and SD values. At least one device included in the communication system can define five types of network slices by SST values. At least one device included in the communication system can distinguish network slices through SD values. In other words, at least one device included in the communication system can distinguish each network slice for various operators and service providers for the same network slice through SD values. User equipment (UE) can use network slices provided by the network (network, NW) through the value of S-NSSAI. S-NSSAI (205) can be composed of a combination of SST and SD values. A combination of S-NSSAIs (203) can be defined as an NSSAI. A combination of S-NSSAIs can be represented by four NSSAIs.
[0087] FIG. 3 is a conceptual diagram illustrating the types of NSSAI according to one embodiment of the present disclosure.
[0088] Referring to FIG. 3, the four NSSAIs may include at least one of Configured NSSAI, Subscribed NSSAI, Requested NSSAI, or Allowed NSSAI. At least one device included in the communication system may include at least one of UE (301), AMF (303), or UDM (305).
[0089] Configured NSSAI may refer to an NSSAI configured in the UE (301). Subscribed NSSAI may refer to an NSSAI configured in the unified data management (UDM). Requested NSSAI may refer to an NSSAI for the UE (301) to check whether a specific network slice is available to the NW. Allowed NSSAI may refer to an NSSAI for the NW to inform the UE whether a specific network slice is available.
[0090] The UE (301) can configure the Configured NSSAI. The UE (301) can create a Requested NSSAI using the Configured NSSAI. The UE (301) can transmit the Requested NSSAI to the Access and Mobility Management Function (AMF) (303). The AMF (303) can transmit information about the NSSAI to the Unified Data Management (UDM) (305) using the Requested NSSAI received from the UE. The Unified Data Management (UDM) (305) can configure the Subscribed NSSAI. The UDM (305) can transmit the Subscribed NSSAI to the AMF (303). The AMF (303) can receive the Subscribed NSSAI transmitted by the UDM (305). The AMF (303) can create an Allowed NSSAI using the Subscribed NSSAI. The AMF (303) can send the Allowed NSSAI to the UE (301). The UE (301) can receive the Allowed NSSAI.
[0091] FIG. 4 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure.
[0092] Referring to FIGS. 4 and 5, FIGS. 4 and 5 illustrate a procedure in which a UE obtains an Allowed S-NSSAI through an initial registration procedure. At least one device included in the communication system may include at least one of a UE (user equipment) (401), a RAN (radio access network) (403), an AMF (access and mobility management function) (405), an SMF (session management function) (407), a UPF (user plane function) (409), a PCF (point coordination function) (411), a UDM (unified data management) (413), a UDR (uniFi dream router) (415), or an AUSF (authentication server function) (417).
[0093] The UE (401) can determine whether the URSP (UE route selection policy) is configured. The UE (401) can use network slices created according to the SLA of the NW (network). The UE (401) can perform application-specific traffic classification using network slices. The rules of the URSP (UE route selection policy) for performing application-specific traffic classification can be defined as shown in Tables 2 and 3.
[0094]
[0095] Table 2 may represent a table of URSP policies (URSP rules). The NW can set URSP policies for the UE (401). The UE (401) can send traffic for a specific application to a specific network slice through the URSP policies set by the NW. A URSP may include at least one of a Rule Precedence, a Traffic Descriptor, or a List of Route Selection Descriptor that specifies the priority of the policy. The UE (401) can identify a specific application through Application Descriptors, which are sub-items of the Traffic Descriptor. The UE (401) can identify a specific network slice through Network Slice Selection, which is a sub-item of the List of Route Selection Descriptors. OSAppId(s) and S-NSSAI(s) can be used to identify a specific application and a network slice, respectively, in the UE (401). Route Selection Descriptors can be represented as shown in Table 3.
[0096]
[0097] The UE (401) can create a Configured NSSAI. The Configured NSSAI may include an S-NSSAI. The S-NSSAI may include an SST or an SD. The SST of the Configured NSSAI may include a value of 1. The SD of the Configured NSSAI may include a value of 0 or NULL. If a URSP is configured, the UE (401) can select a value for the S-NSSAI. If a URSP is not configured, the UE (401) cannot select a value for the S-NSSAI, so it may request the AMF (405) to establish a PDU session with a NULL value. If the S-NSSAI is NULL, the AMF (405) can map the PDU session to the Default network slice based on the Default S-NSSAI value stored in the UDM (413).
[0098] In other words, if NW has set a URSP for UE (401), UE (401) can specify an S-NSSAI value according to the policy set in the URSP. UE (401) can request AMF (405) to establish a PDU session for a network slice by specifying an S-NSSAI value. If UE (401) has a URSP policy, when UE (401) sends a PDU session establishment request message, it can establish a session with an S-NSSAI value in Allowed NSSAI that is not NULL.
[0099] UDM (413) may serve as a frontend that stores user subscription data in the Unified Data Repository (UDR). UDM (413) may execute required functions in response to requests from other Network Functions (NFs). UDM (413) may be paired with a UDR that stores subscriber profile information, policies, structures, and application data. UDM (413) may generate a Default S-NSSA#1 for Business to Customer (B2C).
[0100] The UE (401) can generate a Requested NSSAI using the Configured NSSAI. The UE (401) can generate a registration request message. The registration request message may include the Requested NSSAI. The UE (401) can transmit the registration request message to the AMF (405) via the RAN (403) (S401). The UE (401) can transmit the Requested NSSAI to the AMF (405) by including it in the registration request message. In other words, the UE (401) can request initial registration from the NW for the use of a specific network slice through the S-NSSAI value included in the Requested NSSAI.
[0101] The NW can check whether the S-NSSAI value included in the Requested NSSAI requested by the UE (401) is available and transmit to the UE (401) the S-NSSAI value, which is an identifier of the available network slices in the Allowed NSSAI. The specific procedure may be as follows.
[0102] The AMF (405) can receive a registration request message sent by the UE (401). The AMF (405) can receive a Requested NSSAI sent by the UE (401). The AMF (405) can create a Nausf_UE_Authentication_Authenticate_Request message using the Requested NSSAI. The AMF (405) can send the Nausf_UE_Authentication_Authenticate_Request message to the AUSF (authentication server function) (417) using the Requested NSSAI (S402).
[0103] AUSF (417) can receive the Nausf_UE_Authentication_Authenticate_Request message sent by AMF (405). AUSF (417) can create a Nudm_Authentication_Get_Request message using the Nausf_UE_Authentication_Authenticate_Request message. AUSF (417) can send the Nudm_Authentication_Get_Request message to UDM (413) (S403).
[0104] UDM (413) can receive the Nudm_Authentication_Get_Request message sent by AUSF (417). UDM (413) can create a Nudm_Authentication_Get_Response message using the Nudm_Authentication_Get_Request message sent by AUSF (417). UDM (413) can send the Nudm_Authentication_Get_Response message to AUSF (417) (S404).
[0105] AUSF (417) can receive the Nudm_Authentication_Get_Response message sent by UDM (413). AUSF (417) can use the Nudm_Authentication_Get_Response message to generate the Nausf_UE_Authentication_Authenticate_Response message (S405).
[0106] AMF (405) can receive the Nausf_UE_Authentication_Authenticate_Response message sent by AUSF (417). AMF (405) can create an Authentication Request message using the Nausf_UE_Authentication_Authenticate_Response message sent by AUSF (417). AMF (405) can send the Authentication Request message to UE (401) (S406).
[0107] The UE (401) can receive an Authentication Request message sent by the AMF (405). The UE (401) can generate an Authentication Response message using the Authentication Request message sent by the AMF (405). The UE (401) can send the Authentication Response message to the AMF (405) (S407).
[0108] AMF (405) can receive an Authentication Response message sent by UE (401). AMF (405) can use the Authentication Response message to send a Nausf_UE_Authentication_Authenticate_Request message to AUSF (417) (S408).
[0109] AUSF (417) can receive the Nausf_UE_Authentication_Authenticate_Request message sent by AMF (405). AUSF (417) can generate a Nausf_UE_Authentication_Authenticate_Response message using the Nausf_UE_Authentication_Authenticate_Request message sent by AMF (405). AUSF (417) can send the Nausf_UE_Authentication_Authenticate_Response message to AMF (405) (S409).
[0110] AUSF (417) can generate a Nudm_UE_Authentication_Result_Confirmation_Request message using the Nausf_UE_Authentication_Authenticate_Request message. AUSF (417) can send the Nudm_UE_Authentication_Result_Confirmation_Request message to UDM (413) (S410).
[0111] UDM (413) can receive the Nudm_UE_Authentication_Result_Confirmation_Request message sent by AUSF (417). UDM (413) can create a Nudm_UE_Authentication_Result_Confirmation_Response message using the Nudm_UE_Authentication_Result_Confirmation_Request message. UDM (413) can send the Nudm_UE_Authentication_Result_Confirmation_Response message to AUSF (417) (S411).
[0112] AMF (405) can receive the Nausf_UE_Authentication_Authenticate_Response message transmitted by AUSF (417). AMF (405) can generate a Security Mode Command message using the Nausf_UE_Authentication_Authenticate_Response message. AMF (405) can transmit the Security Mode Command message to the UE (401) (S412).
[0113] The UE (401) can receive a Security Mode Command message transmitted by the AMF (405). The UE (401) can generate a Security Mode Complete message using the Security Mode Command message. The UE (401) can transmit the Security Mode Complete message to the AMF (405) using the Security Mode Complete message (S413).
[0114] FIG. 5 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure. FIG. 5 is a flowchart illustrating one embodiment of an initial registration procedure.
[0115] Referring to FIGS. 4 and 5, at least one device included in the communication system may include at least one of UE (501), RAN (503), AMF (505), SMF (507), UPF (509), PCF (511), UDM (513), UDR (515), or AUSF (517).
[0116] The AMF (505) can receive a Security Mode Complete message sent by the UE (501). The AMF (505) can generate a Nudm_SDM_Get message using the Security Mode Complete message sent by the UE (501). The Nudm_SDM_Get message may include Slice Selection Subscription Date data. The AMF (505) can send the Nudm_SDM_Get message to the UDM (513) (S514).
[0117] UDM (513) can receive a Nudm_SDM_Get message sent by AMF (505). UDM (513) can generate a Nudm_SDM_Get_Response message corresponding to the Nudm_SDM_Get message. The Nudm_SDM_Get_Response message may include a Subscribed S-NSSAI. UDM (513) can send the Nudm_SDM_Get_Response message to AMF (505) (S515).
[0118] AMF (505) can receive the Nudm_SDM_Get_Response message sent by UDM (513). AMF (505) can create a Nudm_UECM_Registration message using the Nudm_SDM_Get_Response message. AMF (505) can send the Nudm_UECM_Registration message to UDM (513) (S516).
[0119] UDM (513) can receive the Nudm_UECM_Registration message sent by AMF (505). UDM (513) can create a Nudm_UECM_Registration_Response message using the Nudm_UECM_Registration message. UDM (513) can send the Nudm_UECM_Registration_Response message to AMF (505) (S517).
[0120] AMF (505) can receive the Nudm_UECM_Registration_Response message sent by UDM (513). AMF (505) can create a Nudm_SDM_Subscribe message using the Nudm_UECM_Registration_Response message. AMF (505) can send the Nudm_SDM_Subscribe message to UDM (513) (S518).
[0121] UDM (513) can receive the Nudm_SDM_Subscribe message sent by AMF (505). UDM (513) can create a Nudm_SDM_Subscribe_Response message using the Nudm_SDM_Subscribe message. UDM (513) can send the Nudm_SDM_Subscribe_Response message to AMF (505) (S519).
[0122] AMF (505) can receive the Nudm_SDM_Subscribe_Response message sent by UDM (513). AMF (505) can use the Nudm_SDM_Subscribe_Response message to generate an Initial Context Setup Request message. AMF (505) can send the Initial Context Setup Request message to RAN (503) (S520).
[0123] The AMF (505) can generate a Registration Accept message using the Nudm_SDM_Subscribe_Response message. The Registration Accept message may include an Allowed NSSAI. The Allowed NSSAI may include a Default S-NSSAI#1. The Default S-NSSAI#1 may include a value where SST is 1. The Default S-NSSAI#1 may include a value where SD is NULL. The AMF (505) can send the Registration Accept message to the UE (501) (S521).
[0124] The AMF (505) can transmit a terminal radio capability information indicator (UE Radio Capability info Indication) to the RAN (503) (S522).
[0125] The RAN (503) can receive the UE Radio Capability info Indication transmitted by the AMF (505). Using the RAN UE Radio Capability info Indication, it can transmit an Initial Context Setup Response message to the AMF (505) (S523).
[0126] The UE (501) can generate a Registration Complete message. The UE (501) can transmit the Registration Complete message to the AMF (505) (S524). The AMF (505) can receive a UE Radio Capability info Indication from the RAN (503). The AMF (505) can receive the Registration Complete message from the AMF (505).
[0127] The UE (501) can receive a Registration Accept message from the AMF (505).
[0128] The UE (501) can perform a PDU session establishment procedure for a specific network slice using the S-NSSAI value included in the Allowed NSSAI.
[0129] FIG. 6 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure. FIG. 6 is a flowchart illustrating one embodiment of the initial registration procedure.
[0130] Referring to FIGS. 6 and 7, FIGS. 6 and 7 may illustrate a procedure for establishing a PDU session when a URSP policy is not set after the UE is initially registered. At least one device included in the communication system may include at least one of a UE (601), RAN (603), AMF (605), SMF (607), UPF (609), PCF (611), UDM (613), UDR (615), or AUSF (617).
[0131] The UE (601) may not have a URSP policy set. The UE (601) may generate a PDU Session Establishment Request message. The PDU Session Establishment Request message may include S-NSSAI. S-NSSAI may include a NULL value. The PDU Session Establishment Request message may include DNN (data network name) information. DNN may include information called Internet. The PDU Session Establishment Request message may include information that the UE does not have a URSP policy set. The UE (601) may send the PDU Session Establishment Request message to the AMF (605) (S601).
[0132] The AMF (605) can receive a PDU Session Establishment Request message sent by the UE (601). The AMF (605) can receive Default S-NSSAI#1 from the UDM (613). The AMF (605) can select an SMF (607) using Default S-NSSAI#1. In other words, the AMF (605) can perform the SMF (607) selection procedure using S-NSSAI. The AMF (605) can create an Nsmf_PDUSession_CreatSMContextRequest message. The Nsmf_PDUSession_CreatSMContextRequest message can be sent to the SMF (607) selected by the AMF (605). In other words, AMF (605) can send the Nsmf_PDUSession_CreatSMContextRequest message to the SMF (607) selected by AMF (605) (S602).
[0133] SMF (607) can receive the Nsmf_PDUSession_CreatSMContextRequest message sent by AMF (605). SMF (607) can create a Nudm_UECM_Registration message using the Nsmf_PDUSession_CreatSMContextRequest message. SMF (607) can send the Nudm_UECM_Registration message to UDM (613) (S603).
[0134] UDM (613) can receive the Nudm_UECM_Registration message sent by SMF (607). UDM (613) can create a Nudm_UECM_Registration_Response message using the Nudm_UECM_Registration message. UDM (613) can send the Nudm_UECM_Registration_Response message to SMF (607) (S604).
[0135] SMF (607) can receive the Nudm_UECM_Registration_Response message sent by AMF (605). SMF (607) can create a Nudm_SDM_Get message using the Nudm_UECM_Registration_Response message. SMF (607) can send the Nudm_SDM_Get message to UDM (613) (S605).
[0136] UDM (613) can receive the Nudm_SDM_Get message sent by SMF (607). UDM (613) can create a Nudm_SDM_Get_Response message using the Nudm_SDM_Get message. UDM (613) can send the Nudm_SDM_Get_Response message to SMF (607) (S606).
[0137] AMF (605) can generate a Nudm_SDM_Subscribe message. AMF (605) can send the Nudm_SDM_Subscribe message to UDM (613) (S607).
[0138] UDM (613) can receive the Nudm_SDM_Subscribe message sent by AMF (605). UDM (613) can generate a Nudm_SDM_Subscribe_Response message using the Nudm_SDM_Subscribe message. UDM (613) can send the Nudm_SDM_Subscribe_Response message to AMF (605) (S608). AMF (605) can receive the Nudm_SDM_Subscribe_Response message sent by UDM (613).
[0139] SMF (607) can use a dynamic PCC (primary component carrier) to establish a PDU session. SMF (607) can perform a PCF selection procedure using S-NSSAI. SMF (607) can create an Npcf_SMPolicyControl_Create_Request message using message information received from UDM (613). SMF (607) can send the Npcf_SMPolicyControl_Create_Request message to UDR (uniFi dream router) (615) (S609).
[0140] PCF (611) can receive the Npcf_SMPolicyControl_Create_Request message sent by SMF (607). PCF (611) can create a Nudr_DataRepository_Query_Request message using the Npcf_SMPolicyControl_Create_Request message. PCF (611) can send the Nudr_DataRepository_Query_Request message to UDR (615) (S610).
[0141] UDR (615) can receive the Nudr_DataRepository_Query_Request message sent by PCF (611). UDR (615) can create a Nudr_DataRepository_Query_Response message using the Nudr_DataRepository_Query_Request message. PCF (611) can send the Nudr_DataRepository_Query_Response message to UDR (615) (S611).
[0142] PCF (611) can receive the Nudr_DataRepository_Query_Response message sent by UDR (615). PCF (611) can create a Nudr_DataRepository_Subscribe_Request message using the Nudr_DataRepository_Query_Response message. PCF (611) can send the Nudr_DataRepository_Subscribe_Request message to UDR (615) (S612).
[0143] UDR (615) can receive the Nudr_DataRepository_Subscribe_Request message sent by PCF (611). UDR (615) can create a Nudr_DataRepository_Subscribe_Response message using the Nudr_DataRepository_Subscribe_Request message. PCF (611) can send the Nudr_DataRepository_Subscribe_Response message to UDR (615) (S613).
[0144] PCF (611) can generate an Npcf_SMPolicyControl_Create_Response message. PCF (611) can send the Npcf_SMPolicyControl_Create_Response message to SMF (607) (S614).
[0145] FIG. 7 is a flowchart illustrating an initial registration procedure according to one embodiment of the present disclosure. FIG. 7 is a flowchart illustrating one embodiment of the initial registration procedure.
[0146] Referring to FIGS. 6 and 7, at least one device included in the communication system may include at least one of UE (701), RAN (703), AMF (705), SMF (707), UPF (709), PCF (711), UDM (713), UDR (715), or AUSF (717).
[0147] SMF (707) can receive the Npcf_SMPolicyControl_Create_Response message transmitted by PCF (711). SMF (707) can select UPF (709) using S-NSSAI (UPF selection w / S-NSSAI). SMF can create an N4_Session_Establishment_Request message using the Npcf_SMPolicyControl_Create_Response message. SMF (707) can transmit the N4_Session_Establishment_Request message to UPF (S715).
[0148] UPF (709) can receive the N4_Session_Establishment_Request message sent by SMF (707). UPF (709) can generate an N4_Session_Establishment_Response message corresponding to the N4_Session_Establishment_Request message. UPF (709) can send the N4_Session_Establishment_Response message to SMF (707) (S716).
[0149] SMF (707) can receive the N4_Session_Establishment_Response message transmitted by UPF (709). SMF (707) can generate the Nsmf_PDUSession_Establishment_Response message based on the N4_Session_Establishment_Response message. SMF (707) can transmit the Nsmf_PDUSession_Establishment_Response message to AMF (705) (S717).
[0150] SMF (707) can generate an Nsmf_PDUSession_Establishment_Response message. SMF (707) can send the Nsmf_PDUSession_Establishment_Response message to AMF (705) (S718).
[0151] AMF (705) can receive the Nsmf_PDUSession_Establishment_Response message sent by SMF (707). AMF (705) can receive the Namf_Communication_N1N2MessageTransfer_Request message sent by SMF (707). AMF (705) can send the Namf_Communication_N1N2MessageTransfer_Response message corresponding to the Namf_Communication_N1N2MessageTransfer_Request message to SMF (707) (S719).
[0152] AMF (705) can generate a PDU Session Resource Setup Request message. AMF (705) can send the PDU Session Resource Setup Request message to RAN (703) (S720).
[0153] The AMF (705) can generate a PDU Session Establishment Accept message. The AMF (705) can send the PDU Session Establishment Accept message to the UE (701) (S721).
[0154] The UE (701) can perform a Public PDU Session Establishment uplink procedure based on a PDU Session Establishment Accept message. At least one of the UE, RAN, AMF, SMF, or UPF can perform a Public PDU Session Establishment uplink procedure.
[0155] RAN (703) can generate a PDU Session Resource Setup Response message based on the PDU Session Resource Setup Request message transmitted by AMF. RAN (703) can transmit the PDU Session Resource Setup Response message to AMF (705) (S722).
[0156] AMF (705) can receive a PDU Session Resource Setup Response message sent by RAN (703). AMF (705) can generate an Nsmf_PDUSession_UpdataSMContext_Request message based on the PDU Session Resource Setup Response message. AMF (705) can send the Nsmf_PDUSession_UpdataSMContext_Request message to SMF (707) (S723).
[0157] SMF (707) can receive the Nsmf_PDUSession_UpdataSMContext_Request message sent by AMF (705). SMF (707) can generate an N4 Session Establishment Request message based on the Nsmf_PDUSession_UpdataSMContext_Request message. SMF (707) can send the N4 Session Establishment Request message to UPF (709) (S724).
[0158] UPF (709) can receive an N4 Session Establishment Request message transmitted by SMF (707). UPF (709) can perform a Public PDU Session Establishment downlink procedure based on the N4 Session Establishment Request message. At least one of UE, RAN, AMF, SMF, or UPF can perform a Public PDU Session Establishment downlink procedure.
[0159] UPF (709) can generate an N4 Session Establishment Response message based on an N4 Session Establishment Request message. UPF (709) can send the N4 Session Establishment Response message to SMF (S725).
[0160] SMF (707) can receive an N4 Session Establishment Response message sent by UPF (709). SMF (707) can generate an Nsmf_PDUSession_UpdataSMContext_Response message based on the N4 Session Establishment Response message. SMF (707) can send the Nsmf_PDUSession_UpdataSMContext_Response message to AMF (705) (S726).
[0161] FIG. 8 is a conceptual diagram illustrating a zero-trust architecture (ZTA) based procedure according to one embodiment of the present disclosure.
[0162] Referring to Fig. 8, security technology for network slicing may be applied to at least one of URLLC, eMBB, and mMTC. Security technology for network slicing may be applied to NSSAA (network slice specific authentication and authorization) for additional authentication regarding network slice services provided by a third party. Security technology for network slicing may include interoperability technology for devices providing security functions, such as firewalls, at the N6 interface connecting the network slice and the DN (data network). Security technology for network slicing may include NSAC (network slice admission control) functions to prevent attacks such as DDoS (distributed denial of service) by providing access control for a specific network slice. From an SLA perspective, GSMA may provide attributes that allow setting availability and isolation levels for providing network slice security.
[0163] With the increase in terminals and equipment, the complexity of security management systems, and the rise in various cyber security threats such as insider breaches, Zero-Trust Architecture (ZTA) can be proposed to overcome the limitations of existing perimeter-based security systems. The Zero-Trust Architecture of NIST (National Institute of Standards and Technology) assumes that the network can always be considered compromised. ZTA can refer to a collection of ideas and concepts that grant precise and least privileges to requests for access to data and computing services that need to be protected. NIST defines tenets for ZTA. All data resources and computing services may be resources. Communications may be protected regardless of location. At least one device included in the communication system may access individual resources granted on a session basis. At least one device included in the communication system may access resources determined by dynamic policies, behaviors, and environmental attributes. At least one device included in the communication system may monitor and measure the integrity and security status of owned assets and associated assets. At least one device included in the communication system can strictly apply dynamic resource authentication and authorization before access is permitted. At least one device included in the communication system can collect information regarding assets, network infrastructure, and the current state of communications. At least one device included in the communication system can improve the security system through ZTA.
[0164] A boundary-based security system allows an attacker to access various servers, databases, storage devices, etc., within an organization or enterprise based on implicit trust once they have bypassed security systems such as firewalls, IDS, IPS, or VPNs installed at the network boundary. A Zero Trust security system may include a security system design based on the principle of fundamental trustlessness for all components constituting a system or network. At least one device included in the communication system may utilize remote attestation technology to use the ZTA security system. Remote attestation technology can be represented as follows.
[0165] FIG. 9 is a conceptual diagram illustrating a remote attestation (RA) based procedure according to one embodiment of the present disclosure.
[0166] Referring to FIG. 9, at least one device included in the communication system may include at least one of a verification device (901), a transmission device (Sender) (903), a receiving device (Receiver) (905), or a verification device (907). The verification device (901) may include at least one cloud server (909). The cloud server (909) may be implemented by hardware.
[0167] Remote attestation (RA) technology is one of the technologies used to provide a ZTA security system and refers to a technology for verifying the integrity of an execution remotely. For example, if a server performing a specific function in response to a remote request is infected by an attacker and causes it to perform an incorrect function, there may be a problem where the remote location uses the incorrect response from the server as is.
[0168] For authenticated communication between the sender (903) and the receiver (905), the sender (903) may transmit hardware-based evidence from the cloud server to the receiver (905). In other words, the attestation device (901) may include a cloud server (909). The attestation device (901) may generate evidence through hardware on the cloud server. The attestation device (901) may transmit the evidence to the sender (903). The sender (903) may receive the evidence transmitted by the attestation device (901). The sender (903) may communicate with the receiver (905). Communication between the sender (903) and the receiver (905) may refer to communication needing attestation. To prove communication between the transmitting device (903) and the receiving device (905), the transmitting device (903) may transmit evidence to the receiving device (905). The receiving device (905) may receive the evidence transmitted by the transmitting device (903). The receiving device (905) may transmit the evidence transmitted by the transmitting device (903) to the verification device (907). The verification device (907) may receive the evidence transmitted by the receiving device (905). The verification device (907) may verify the evidence. The verification device (907) may transmit an attestation result to the receiving device (905) through the verified evidence. The receiving device (905) may receive the attestation result transmitted by the verification device (907). The receiving device (905) can check the reliability between the sending device (Sender) (903) and the receiving device (Receiver) (905) based on the attestation result of verifying the evidence received from the sending device (Sender) (903) through the verifier (907).
[0169] FIG. 10 is a block diagram illustrating a network function (NF) service registration procedure according to one embodiment of the present disclosure.
[0170] Referring to FIG. 10, at least one device included in a communication system may use RA for NF service registration. At least one device included in a communication system may include a Network Function Virtualization Infrastructure (NFVI) (1001) and an NFV Management and Orchestration (NFV MANO) (1003) each containing an Attestator and a Verifier for RA application. The present disclosure may define a new NF called a Profile and Attestation Check Function (PACF). New VNFs (1005) may include a PACF. When registering new VNFs (VNF service) (1005), at least one device included in a communication system may perform RA (Remote Attestation). At least one device included in a communication system may perform procedures, such as performing RA to verify the reliability of VNFs (1005).
[0171] NFVI (1001) may include at least one of virtual resources, an attester, a virtualization layer, or hardware resources. The attester may perform a measure procedure. The attester may transmit the measure value to VNFs (1005). The attester may transmit the measure value to a virtual instance. The attester may generate evidence. The attester may transmit the evidence to an NFV MANO (1003). In other words, the attester may transmit the evidence to a verifier.
[0172] The NFV MANO (1003) may include an attestation device. The NFV MANO (1003) may receive attestation transmitted by the attestation device. In other words, the attestation device may receive attestation transmitted by the attestation device. The attestation device may generate attestation results. The attestation device may transmit the attestation results to VNFs (network function virtualization service) (1005). The attestation device may transmit the attestation results to PACF.
[0173] VNFs (1005) can receive attestation results transmitted by the verification device. VNFs (1005) may include at least one of a virtual instance, a relying party VNF, or a PACF. The PACF can receive attestation results transmitted by the verification device. The PACF can transmit a policy to the verification device. The verification device can receive the policy transmitted by the PACF. The PACF can transmit attestation results to the relying party VNF. The relying party VNF can receive attestation results transmitted by the PACF. The relying party VNF and the untrusted VNF can perform communication depending on attestation. The virtual instance may include an untrusted VNF. The trusted party VNF and the untrusted VNF can communicate through a procedure that compares measurements and verification results.
[0174] FIG. 11 is a block diagram illustrating a network function (NF) service registration procedure according to one embodiment of the present disclosure.
[0175] Referring to FIG. 11, at least one device included in the communication system may include at least one of an NF service consumer (1101), an NRF (1103), or a PACF (1105).
[0176] An NF service consumer (1101) can generate an Nnrf_Management_NFReister_request message. An NF service consumer (1101) can send the Nnrf_Management_NFReister_request message to a network repository function (NRF) (S1101). The Nnrf_Management_NFReister_request message may include an NF profile.
[0177] NRF (1103) can receive an Nnrf_Management_NFReister_request message transmitted by an NF service consumer (1101). NRF (1103) can generate an Attestation_request message. NRF (1103) can transmit the Attestation_request message to PACF (1105) (S1102). The Attestation_request message may include an NF profile.
[0178] PACF (1105) can receive an Attestation_request message transmitted by NRF (1103). PACF (1105) can perform a verify signature procedure based on the Attestation_request message (S1103). PACF (1105) can perform a retrieve attestation results procedure based on the Attestation_request message (S1103).
[0179] PACF (1105) can generate an Attestation_response message. The Attestation_request message may include at least one signature result. The Attestation_request message may include at least one attestation result. PACF (1105) can transmit the Attestation_response message to NRF (S1104). NRF (1103) can receive the Attestation_response message transmitted by PACF (1105).
[0180] NRF (1103) can validate the NF profile based on the Attestation_response message (S1105). NRF (1103) can store the NF profile based on the Attestation_response message.
[0181] NRF (1103) can generate an Nnrf_Management_NFReister_response message. NRF (1103) can send the Nnrf_Management_NFReister_response message to an NF service consumer (S1106).
[0182] FIG. 12 is a conceptual diagram illustrating a network function for distributing a cloud according to one embodiment of the present disclosure.
[0183] Referring to Fig. 12, network slicing technology in 6G may include technology capable of providing customized services according to the requirements of various applications. 5G and Beyond 5G may be designed primarily based on requirements for throughput, delay, and admission control. An SLA may not define attributes that can provide security in a specific network slice. An SLA may lack methods to prevent security threats between slices when a UE uses multiple network slices simultaneously. When utilizing network slices, such as providing network slices to prevent new security threats in the era of quantum computing, an SLA may lack methods to provide enhanced security network slices to offer various necessary security services.
[0184] Key requirements for network slicing security may include isolation levels and availability. The isolation level attribute may not be defined in detail. This disclosure may propose a definition of a security-native network slice. This disclosure may propose a method for solving problems arising from sharing a security context for a network slice.
[0185] At least one device included in the mobile communication system may consider existing boundary-based security systems, such as existing firewalls, IPSec, and TLS, for the communication system components due to the full-scale introduction of cloud and virtualization technologies. At least one device included in the mobile communication system may consider the application of a zero-trust security system. Due to the introduction of virtualization technologies, various NFs may be distributed in the form of virtualized VNFs and CNFs on commercial off-the-shelf (COTS) servers at remote locations. The remote location (S1201) may include an edge, a cloud, or a private network. The remote location (S1201) may include a shared COTS A, a shared COTS B, a private network, an edge C, or a cloud D.
[0186] COTS may contain NFs from multiple operators or include 3rd Party Apps. In other words, COTS may include at least one of a vCU (vehicle control unit), O-CU (operator-control unit), Apps (Applications), or shared hardware. Private networks and / or edge environments may include at least one of a UPF or untrusted hardware. Cloud environments may include at least one of NFs or untrusted hardware. In an environment where NFs from multiple operators are deployed on a single COTS server or where 3rd Party Apps are mixed, if one entity is compromised, a problem may arise where the attack can spread to various entities sharing the COTS server. In other words, an attacker's attack can propagate between individual NFs. An attack propagated between NFs can then spread to the SMO (service management and orchestration) and / or AO (automation orchestrator). The AO may include at least one of a BO (bare-metal orchestrator), a CO (cloud orchestrator), or a USM (unified system manager). The SMO can perform VNF / CNF deployment and operation for life cycle management (LCM).
[0187] To solve the problem, at least one device included in the communication system can utilize a technology such as RA to continuously perform integrity checks on distributed entities even at a remote location. At least one device included in the communication system can ensure the reliability of the system through continuous integrity checks on entities. The present disclosure may propose a technology capable of verifying the integrity of execution remotely for the application of a zero-trust security system. In other words, the present disclosure may propose a technology for RA.
[0188] Network slices based on requirements for throughput or latency, which are included in at least one device of a communication system, may lack design considerations regarding security aspects. To address problems arising from network slices lacking design considerations regarding security aspects, the present disclosure may propose a policy and session establishment method that enables a User Equipment (UE) to use a security-enhanced network slice. 6G may use a ZTA-based security system that includes a boundary-based security system. The present disclosure may include a method for dynamically performing reliability verification on NFs constituting a security-enhanced network slice using a ZTA-based security system. The present disclosure may provide a security-enhanced network slice by dynamically performing reliability verification on NFs constituting a security-enhanced network slice using a ZTA-based security system. If a URSP is not configured on the UE, the present disclosure may use a method for assigning a network slice with security applied by default, rather than assigning a network slice based on a Default NSSAI value, for the use of a security-enhanced network slice. The present disclosure may propose a policy configuration method that enables a UE to dynamically check the reliability of a network slice based on RA in a URSP. The present disclosure may propose a PDU session establishment procedure that enables a UE to dynamically secure reliability based on RA when the UE uses a secure network slice.
[0189] FIG. 13 is a conceptual diagram illustrating a security-enhanced network slice (SE-NS) according to one embodiment of the present disclosure.
[0190] Referring to FIG. 13, at least one device included in the communication system may include at least one of an NSC (1301) or a security-enhanced network slice management and orchestration (1306).
[0191] In a next-generation communication system, when providing a service with security requirements (1303) by providing a security-enhanced network slice, the present disclosure may generate and provide a security-enhanced network slice (SE-NS). At least one device included in the communication system may generate a security-enhanced network slice SE-NS by reflecting quantum security requirements, security key separation per network slice, and reliability provision requirements.
[0192] A network slice customer (NSC) (1301) can provide requirements (1303). The NSC can provide a use case (1302). In other words, the NSC (1301) can provide service requirements and technical requirements for a network slice to a network entity associated with a network operator (NOP) or network slice provider (NSP) for the UE's use case (1302). The UE can request a network slice based on the use case. A generic network slice template (GST) (1304) containing a set of attributes characterizing a network slice type (NEST) (1305) can be used to convert service requirements and / or technical requirements into a set of attributes.
[0193] The present disclosure may propose high-level security requirements for network slices. High-level security requirements may include at least one of qauntumProtection, securityNativeSlice, N3Protection, securityPerformance, or trustLevel. In other words, high-level security requirements may include at least one of attributes, intent, and GST (1304).
[0194] The GST (1304) may include a coverage area, a maximum number of terminals (maxNumberofUEs), an uplink data transmission rate (uLThptPerUE), or a downlink data transmission rate slice subnet (dLThptPerSliceSubnet). The set of attributes may be represented using a service profile. A network slice type (NEST) (1305) containing the GST (1304) filled with values may be created. Values may be assigned to represent a defined set of service requirements and / or technical requirements to support NSC use cases. The NEST may be used as an input for network slice preparation.
[0195] Security-enhanced network slice management and orchestration (1306) may include at least one of a commun service consumer (CSC) (1307), a commun service provider (CSP) (1308), or a network operator (NOP) (1309). The CSC (1307) may include a commun service management function (CSMF). The CSP (1308) may include a network slice management function (NSMF). The NOP (1309) may include at least one of a core network (CN) subnet slice management function (NSSMF), an NSSMF, or a TN NSSMF.
[0196] The communications service management function (CSFM) can receive GST / NEST. The CSFM can convert GST / NEST into a security-enhanced (SE) service profile. The CSFM can transmit the service profile to the network slice management function (NSMF). GST / NEST may be defined by the GSMA. The service profile may be defined by 3GPP. The service profile associated with the network slice may be obtained from NEST (1305).
[0197] The CSP (1308) can generate one or more subnet slice profiles from the slice profile. One or more subnet slice profiles can be associated with one or more corresponding network domains of the 5G network. The CSP (1308) can generate a security-enhanced (SE) top slice subnet profile (TSSP) using the slice profile. Based on the SE-TSSP, the CSP (1308) can generate a security-enhanced (SE) radio access network (RAN) slice subnet profile, a security-enhanced (SE) transport network (TN) slice subnet profile, or a security-enhanced (SE) core network (CN) slice subnet profile. In other words, the NSMF can receive a security-enhanced (SE) service profile. The NSMF can convert the received security-enhanced (SE) service profile into a security-enhanced (SE) Top Slice Subnet Profile. NSMF can be converted into at least one of the domain-specific profiles of each mobile communication system: a secure (SE) RAN (radio access network) Slice Subnet Profile, a secure (SE) CN (core network Slice Subnet Profile), or a secure (SE) TN (transport network) Slice Subnet Profile. The CSP (1308) can generate one or more secure (SE) subnet slice profiles to correspond to one or more network domains of the 5G network. For example, a secure (SE) core slice subnet profile can be used to convey core network domain requirements.Security-enhanced (SE) wireless access network subnet slice profiles can be used to convey wireless access network domain requirements. Security-enhanced (SE) transport network slice subnet profiles can be used to convey transport domain requirements.
[0198] According to each domain profile, the network operator (NOP) (1309) can set the characteristics defined in the corresponding profile for each domain network component. The network operator (NOP) (1309) can create network slices using the defined characteristics. One or more security-enhanced (SE) subnet slice profiles can be configured to classify one or more attributes into configurable attributes. Configurable attributes may include at least one of performance attributes and quality attributes. Performance attributes may be related to Key Performance Indications (KPIs), such as downlink or uplink throughput. Quality attributes may be related to quality of service parameters, such as packet loss, packet delay variation, and jitter. Non-configurable attributes may include at least one of coverage attributes and feature attributes. Coverage attributes may be related to attributes that limit service accessibility. Feature attributes may indicate the supportability of various functions in the network slice. Configurable attributes can be converted into configuration parameters (i.e., values). Configurable attributes may be enforced by one or more network entities at runtime. Unconfigurable attributes remain at the NSMF or NSSMF level as necessary slice functions and can be enforced by the NSMF or NSSMF during slice provisioning.
[0199] FIG. 14 is a conceptual diagram illustrating an SE-NS policy and session establishment procedure for a UE (user equipment) according to one embodiment of the present disclosure.
[0200] Referring to FIG. 14, at least one device included in the communication system may include at least one of a CN (1401), a RAN (1403), a UE (1405), a SE-NS (1407), or a service provider (1409).
[0201] The present disclosure may propose a method for configuring a URSP policy and a method for establishing a PDU session for a UE (1405) to use an SE-NS (1407). A core network (CN) (1401) may transmit a URSP configuration to a RAN (1403). The URSP configuration transmitted by the core network (1401) may be intended to create a security-enhanced network slice (SE-NS) (1407) that includes an RA. The RAN (1403) may receive the URSP configuration information transmitted by the core network (1401). The RAN (1403) may transmit the URSP configuration information to the UE (1405). The UE (1405) may receive the URSP configuration information transmitted by the RAN (1403). The UE (1405) may perform a PDU Session Establishment procedure using the URSP configuration information. The PDU session establishment procedure performed by the UE (1405) may include a procedure for creating an SE-NS (1407) that includes an RA. The SE-NS (1407) may be composed of a sCU (secure central unit), a sAMF (secure-access and mobility management function), a sSMF (secure-session management function), a sPCF (secure-point coordination function) and / or a sUPF (secure-user plane function), etc. The SE-NS (1407) may be used in URLLC, V2X, etc.
[0202] When creating an SE-NS (1407), the NFs constituting the SE-NS can check their reliability through the execution of an RA procedure. The NFs can provide a secure network slice by verifying their reliability. NFs that have undergone a reliability check through RA can be referred to as sNFs (secure-NFs). The NW can set a URSP policy based on the UE's subscription information. The UE (1405) can establish a session for the SE-NS (1407) based on the set URSP policy. The UE (1405) can use the SE-NS by utilizing the established session for the SE-NS. The UE (1405) can provide network slice instances (NSIs) to a service provider (1409). The service provider (1409) can receive NSIs from the UE (1405). The service provider (1409) may include the government, finance, extended reality (XR), V2X (vehicle to everything), etc. The service provider (1409) may transmit requirements to the UE (1405). The UE (1405) may receive the requirements transmitted by the service provider (1409). The UE (1405) may generate an SE-NS (1407) in consideration of the requirements transmitted by the service provider (1409).
[0203] Allowed S-NSSAI may refer to an NSSAI for the NW to inform the UE whether a specific network slice is available. The UE (1405) may perform various procedures by considering whether a URSP is configured. The UE (1405) may perform various procedures by considering whether an Allowed S-NSSAI for SE-NS generation is included in the UE. Various procedures can be represented as shown in Table 4 below.
[0204]
[0205] It can be assumed that URSP is not configured on the UE and Allowed S-NSSAI for SE-NS is not configured on the UE. At least one device included in the communication system may perform a PDU session establishment procedure using Default S-NSSAI. During the PDU session establishment procedure, the AMF may regard SE-NS as Default S-NSSAI. The UE may regard SE-NS as Default S-NSSAI and apply it. During the PDU session establishment procedure, the network may not perform additional RA for NFs of SE-NS.
[0206] It can be assumed that URSP is not configured in the UE, and Allowed S-NSSAI for SE-NS is configured in the UE. At least one device included in the communication system can perform a PDU session establishment procedure using Default S-NSSAI.
[0207] It can be assumed that URSP is configured on the UE and Allowed S-NSSAI for SE-NS is not configured on the UE. Procedures for the communication system may not be defined.
[0208] It can be assumed that URSP is configured on the UE and Allowed S-NSSAI for SE-NS is configured on the UE. At least one device included in the communication system can perform a PDU session establishment procedure using Allowed S-NSSAI. The UE can perform additional RA for NFs of SE-NS by URSP. During the PDU session establishment procedure, the network can perform additional RA for NFs of SE-NS.
[0209] NF can set RA indication parameters in Route selection components to set URSP policies. Setting RA indication parameters in Route selection components can be represented as shown in Table 5.
[0210]
[0211] When a UE uses SE-NS, the NF can set a URSP policy to dynamically instruct the execution of RA. During the step of establishing a PDU session for SE-NS usage, if the UE selects the NFs that constitute the SE-NS, the UE can generate an RA Enforcement factor that enables dynamic reliability assurance for the SE-NS by executing RA. When performing the sSMF selection procedure, the UE can add and transmit the RA Enforcement. The setting of RA Enforcement by the UE can be represented as shown in Table 6.
[0212]
[0213] When the SMF performs the sPCF selection procedure, the SMF can transmit with added RA Enforcement. The SMF setting up RA Enforcement can be represented as shown in Table 7.
[0214]
[0215] When the SMF performs the sUPF selection procedure, the SMF may transmit with added RA Enforcement. The SMF setting up RA Enforcement can be represented as shown in Table 8.
[0216]
[0217] FIG. 15 is a flowchart illustrating a procedure for generating sNF (secure-NF) of a RAN (radio access network) and a Core Network that constitutes an SE-NS according to one embodiment of the present disclosure.
[0218] Referring to FIG. 15, at least one device included in the communication system may include at least one of a RAN NSSMF (1501), NFMF (EMS) (1503), NFVO / CNFO (1505), VNFM / CNFM (1507), DC-SDN (data center software defined network) (1509), Leaf / Spine Switch (1511), Border GW (1513), sCU-CP (1515), sCU-UP (1517), or sDU (1519).
[0219] The UE can assign a network slice subnet instance (NSSI) profile to a network slice subnet management function (RAN NSSMF) (1501) (S1501). In other words, the UE can transmit the NSSI profile to the RAN NSSMF (1501). The NSSI profile may include a RAN slice profile. The RAN slice profile may include the proposed items.
[0220] The RAN NSSMF (1501) can receive the NSSI profile transmitted by the UE. The RAN NSSMF (1501) can verify the feasibility of requirements related to the NSS (S1502). The RAN NSSMF (1501) can decide whether to create a new NSSI or use an existing NSSI (S1503). The RAN NSSMF (1501) can derive terrestrial network (TN) requirements from the RAN slice profile (S1504). The RAN NSSMF (1501) can derive network slice (NS) requirements from the RAN slice profile. The RAN NSSMF (1501) can derive network function virtualization (VNF) requirements from the RAN slice profile. The RAN NSSMF (1501) can derive cloud-native function (CNF) requirements from the RAN slice profile.
[0221] The RAN NSSMF (1501) can send and receive data with the NFVO (network function virtualization orchestrator) / CNFO (cloud-native network function virtualization orchestrator) (1505). The RAN NSSMF and the NFVO / CNFO can perform an NS instantiation procedure (S1505). The instantiation procedure may include a procedure for generating an NS ID. The instantiation procedure may include a procedure for instantiating an NS. The instantiation procedure may include a notification procedure. The RAN NSSMF can perform an NSSI allocation procedure (S1506).
[0222] The RAN NSSMF (1501) can generate an NF request message. The NF request message may include information about the MOI (managed object instance) operation. The RAN NSSMF can transmit the NF request message to the NFMF (network function management function) (EMS (element management system)) (1503) (S1507).
[0223] The NFMF (EMS) (1503) can receive an NF request message transmitted by the RAN NSSMF (1501). The NFMF (EMS) (1503) and the VNFM (network function virtualization manager) / CNFM (cloud-native function manager) (1507) can perform a V / CNF instantiation procedure (S1508). The NFMF (EMS) (1503) and the VNFM / CNFM (1507) can perform a procedure to generate a V / CNF ID. The NFMF (EMS) (1503) and the VNFM / CNFM (1507) can perform a notification procedure. The NFMF (EMS) (1503) can set an NF MOI (S1509).
[0224] The NFMF (EMS) (1503) can generate a slice associated with configuration data. The slice associated with configuration data may include at least one of quantumProtection, securityNativeSlice, N3Protection, securityPerformance, or trustLevel information. The NFMF (EMS) (1503) can transmit the slice associated with configuration data to the sCU-CP (control plane) (1515) (S1510). The NFMF (EMS) (1503) can transmit the slice associated with configuration data to the sCU-UP (user plane) (1517) (S1510). The NFMF (EMS) can transmit the slice associated with configuration data to the sDU (1519) (S1510).
[0225] When generating SE-NS, the RAN and core network can generate sNFs containing SE-NS based on the RA Enforcement factor. When generating SE-NS, the RAN and core network can generate NSIs using the sNFs. NFs that have performed remote integrity verification based on the RA Enforcement factor may be referred to as sNFs. For example, NFs that have performed RA in the RAN may be represented as sCUs and sDUs (secure distributed units).
[0226] The NFMF (EMS) (1503) can generate an NF response message. The NFMF (EMS) (1503) can transmit the NF response message to the RAN NSSMF (1501) (S1511). At least one of the RAN NSSMF, NFMF (EMS), NFVO / CNFO (1505), VNFM / CNFM (1507), DC-SDN (1509), Leaf / Spine Switch (1511), or Border GW (gateway) (1513) can perform a terrestrial network (TN) setup procedure.
[0227] The RAN NSSMF can assign an NSSI response message to the UE (S1512). In other words, the RAN NSSMF can send an NSSI response message to the UE.
[0228] FIG. 16 is a flowchart illustrating a procedure for generating sNFs of a RAN and a Core Network that constitute an SE-NS according to one embodiment of the present disclosure.
[0229] Referring to FIG. 16, the NFs that performed RA in the core network may include at least one of sPCF, sAMF, sSMF, or sUPF.
[0230] The UE can assign an NSSI profile to the CN NSSMF (1601) (S1601). In other words, the UE can transmit an NSSI profile to the CN NSSMF (1601). The NSSI profile may include a CN slice profile. The CN slice profile may include the proposed items.
[0231] The CN NSSMF (1601) can receive the NSSI profile transmitted by the UE. The CN NSSMF (1601) can verify the feasibility of requirements related to the NSS (S1602). The CN NSSMF (1601) can decide whether to create a new NSSI or use an existing NSSI (S1603). The CN NSSMF (1601) can derive terrestrial network (TN) requirements from the CN slice profile (S1604). The CN NSSMF (1601) can derive network slice (NS) requirements from the CN slice profile. The CN NSSMF (1601) can derive network function virtualization (VNF) requirements from the CN slice profile. The CN NSSMF (1601) can derive cloud-native function (CNF) requirements from the CN slice profile.
[0232] The CN NSSMF (1601) can send and receive data with the NFVO / CNFO (1605). The CN NSSMF (1601) and the NFVO / CNFO (1605) can perform an NS instantiation procedure (S1605). The instantiation procedure may include a procedure for generating an NS ID. The instantiation procedure may include a procedure for instantiating an NS. The instantiation procedure may include a notification procedure. The CN NSSMF (1601) can perform an NSSI allocation procedure (S1606).
[0233] CN NSSMF (1601) can generate an NF request message. The NF request message may include information about a managed object instance (MOI) operation. CN NSSMF (1601) can send the NF request message to an NFMF (element management system (EMS)) (1603) (S1607).
[0234] The NFMF (EMS) (1603) can receive an NF request message transmitted by the CN NSSMF (1601). The NFMF (EMS) (1603) and the VNFM (network function virtualization manager) / CNFM (cloud-native function manager) (1607) can perform a V / CNF instantiation procedure (S1608). The NFMF (EMS) (1603) and the VNFM / CNFM (1607) can perform a procedure to generate a V / CNF ID. The NFMF (EMS) (1603) and the VNFM / CNFM (1607) can perform a notification procedure. The NFMF (EMS) (1603) can set an NF MOI (S1609).
[0235] The NFMF (EMS) (1603) can generate a slice associated with configuration data. The slice associated with configuration data may include at least one of quantumProtection, securityNativeSlice, N3Protection, securityPerformance, or trustLevel information. The NFMF (EMS) (1603) can transmit the slice associated with configuration data to the UDM (1615) (S1610). The NFMF (EMS) (1603) can transmit the slice associated with configuration data to the sPCF (1617) (S1610). The NFMF (EMS) (1603) can transmit the slice associated with configuration data to the NSSF (1619) (S1610). The NFMF (EMS) (1603) can transmit the slice associated with configuration data to the sAMF (1621) (S1610). NFMF(EMS) (1603) can transmit a slice related to the configuration data to sSMF (1623) (S1610). NFMF(EMS) (1603) can transmit a slice related to the configuration data to sUPF (1625) (S1610).
[0236] When generating SE-NS, the CN and core network can generate sNFs containing SE-NS based on the RA Enforcement factor. When generating SE-NS, the CN and core network can generate NSIs using the sNFs.
[0237] The NFMF (EMS) (1603) can generate an NF response message. The NFMF (EMS) can send the NF response message to the CN NSSMF (S1611). At least one of the CN NSSMF (1601), NFMF (EMS) (1603), NFVO / CNFO (1605), VNFM / CNFM (1607), DC (data center)-SDN (1609), Leaf / Spine Switch (1611), or Border GW (1613) can perform the terrestrial network (TN) setup procedure.
[0238] CN NSSMF (1601) can assign an NSSI response message to the UE (S1612). In other words, CN NSSMF (1601) can send an NSSI response message to the UE.
[0239] FIG. 17a is a conceptual diagram illustrating an NF registration procedure using RA according to one embodiment of the present disclosure.
[0240] FIG. 17b is a conceptual diagram illustrating an NF registration procedure using RA according to one embodiment of the present disclosure.
[0241] FIG. 17c is a conceptual diagram illustrating an NF registration procedure using RA according to one embodiment of the present disclosure.
[0242] Referring to FIGS. 17a, 17b, and 17c, FIGS. 17a through 17c may include a procedure for applying RA implemented by the Keylime open-source project to apply RA to existing NF registration and NF discovery procedures. An RA registration procedure (Registration protocol) based on the Root of Trust stored in the TPM between the Keylime agent, Keylime register, and Keylime verifier for RA can be applied to the NF Service Registration procedure defined by 3GPP. FIGS. 17a through 17c may include a procedure for applying an attestation procedure (Attestation protocol) that performs RA between actual entities to the NF Service Discovery procedure defined by 3GPP.
[0243] An NF service consumer can send an Nnrf_NFManagement_NFRegister_request message to an NRF. An NRF can receive the Nnrf_NFManagement_NFRegister_request message sent by the NF service consumer.
[0244] The NRF can store an NF profile using the Nnrf_NFManagement_NFRegister_request message. The NRF can perform the RA registration protocol. The NRF can generate the Nnrf_NFManagement_NFRegister_response message. The NRF can send the Nnrf_NFManagement_NFRegister_response message to an NF service consumer. The NF service consumer can receive the Nnrf_NFManagement_NFRegister_response message sent by the NRF. The RA registration protocol can be represented as follows.
[0245] The RA registration protocol may include at least one of hardware (hardwary, HW), secure NFs, SMO, or trust NFs or secure NF consumers.
[0246] An NF Service consumer can send an Nnrf_NFDiscovery_Request message to an NRF. An NRF can receive the Nnrf_NFDiscovery_Request message sent by the NF Service consumer.
[0247] An NRF can authorize NF service discovery using the Nnrf_NFDiscovery_Request message. An NRF can perform an RA attestation protocol. An NRF can generate an Nnrf_NFDiscovery_Request Response message. An NRF can send the Nnrf_NFDiscovery_Request Response message to an NF service consumer. An NF service consumer can receive the Nnrf_NFDiscovery_Request Response message sent by the NRF. The RA attestation protocol can be represented as follows.
[0248] The RA proof protocol may include at least one of hardware (hardwary, HW), secure NFs, SMO, or trust NFs or secure NF consumers.
[0249] FIG. 17b may represent a diagram illustrating an implementation method for implementing a specific procedure of an RA registration procedure or an authentication protocol. The present disclosure may utilize open source software such as Keylime. The present disclosure may add an RA registration procedure to an existing NF service registration procedure. FIG. 17b may include a procedure in which an RA authentication protocol is added to an NF service discovery procedure.
[0250] FIG. 18 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0251] Referring to FIG. 18, at least one device included in the communication system may include at least one of UE (1801), sRAN (1803), sAMF (1805), sSMF (1807), sUPF (1809), sPCF (1811), UDM (1813) or DN (1815).
[0252] If the URSP policy is not set on the UE (1801), the UE (1801) may set an S-NSSAI representing SE-NS in the UE (1801)'s Allowed NSSAI to use SE-NS. If the UE (1801) sets an S-NSSAI representing SE-NS in the UE (1801)'s Allowed NSSAI, the NW may consider the Default S-NSSAI as SE-NS and proceed with the PDU session establishment procedure.
[0253] The UE (1801) can generate a configured NSSAI. The configured NSSAI may include an S-NSSAI. The S-NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a NULL value. The configured NSSAI may include an S-NSSAI#2. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a NULL value.
[0254] UDM (1813) may be configured with subscribed S-NSSAIs. UDM may store subscribed S-NSSAIs indicating whether a specific UE can use a specific network slice according to the enterprise subscription policy. To use a specific network slice, the UE may select the requested S-NSSAI of the network slice it wishes to use from the configured NSSAIs configured according to the enterprise subscription policy and send it to the network. The network may use the subscribed S-NSSAIs stored in the UDM to inform the UE of the Allowed NSSAIs currently available to the UE in the Tracking Arear (TA). In other words, the UE may send the Requested NSSAI among the Configured NSSAIs to the network. The network may compare the Subscribed S-NSSAIs with the Requested NSSAI and send the Allowed NSSAI to the UE. The UE may receive the Allowed NSSAI from the network. The UE can establish a PDU session by requesting a specific PDU session from the NW for network slice usage using Allowed NSSAI.
[0255] A subscribed S-NSSAI may include at least one of Default S-NSSAI#1 or S-NSSAI#2. Default S-NSSAI#1 may include at least one of SST or SD. The SST of Default S-NSSAI#1 may contain a value of 1. The SD of Default S-NSSAI#1 may contain a NULL value. Default S-NSSAI#1 may be an S-NSSAI for B2C. Default S-NSSAI#1 may be an identifier referring to URLLC, eMTC (enhanced Machine-Type Communication), mIoT (media-centric internet of things), etc. Default S-NSSAI#1 may be a separate network slice for a specific service.
[0256] Default S-NSSAI#1 may be an S-NSSAI for B2C. Default S-NSSAI#1 may be an identifier referring to URLLC, eMTC (enhanced Machine-Type Communication), mIoT (media-centric internet of things), etc. Default S-NSSAI#1 may be a separate network slice for a specific service.
[0257] S-NSSAI for B2C may refer to the S-NSSAI used when a UE, such as a general smartphone user, wants to use the Internet by using a URLLC network slice.
[0258] S-NSSAI#2 may include at least one of SST or SD. The SST of S-NSSAI#2 may include a value of 128. The SD of S-NSSAI#2 may include a value of NULL. S-NSSAI#2 may be an S-NSSAI for a security slice.
[0259] At least one of UE (1801), sRAN (1803), sAMF (1805), sSMF (1807), sUPF (1809), sPCF (1811), UDM (1813) or DN (1815) can perform an initial registration procedure.
[0260] The UE (1801) can generate an Allowed NSSAI. The Allowed NSSAI may include at least one of an S-NSSAI or an S-NSSAI#2. The S-NSSAI of the Allowed NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a NULL value. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a NULL value.
[0261] The UE (1801) can generate a PDU session establishment request message. The PDU session establishment request message may include at least one of S-NSSAI or DNN. The PDU session establishment request message may include information on whether a URSP policy is set on the terminal. The S-NSSAI of the PDU session establishment request message may include a NULL value. The DNN of the PDU session establishment request message may include information that it is the internet. The UE (1801) can transmit the PDU session establishment request message to the sAMF (1805) (S1801).
[0262] sAMF (1805) can receive a PDU session establishment request message transmitted by UE (1801). sAMF (1805) can determine whether URSP is set on the UE through the PDU session establishment request message. sAMF (1805) can determine whether there is an SE-NS NSSAI among the UE's Allowed NSSAIs. If URSP is not set on sAMF (1805) and there is an SE-NS NSSAI among the UE's (1801) Allowed NSSAIs, sAMF (1805) can select the SE-NS NSSAI as the Default S-NSSAI. sAMF (1805) can perform an sSMF selection procedure (S1802). In other words, sAMF (1805) can perform an sSMF selection procedure using the selected SE-NS NSSAI. sAMF (1805) may not perform the RA addition procedure in NF Discovery because UE (1801) does not have a URSP.
[0263] sAMF (1805) can create an Nsmf_PDUSession_CreateSMContextRequest message. sAMF (1805) can send an Nsmf_PDUSession_CreateSMContextRequest message to sSMF (1807) (S1803).
[0264] sSMF (1807) can receive the Nsmf_PDUSession_CreateSMContextRequest message sent by sAMF (1805). sSMF (1807) can perform a subscription retrieval / subscription for updates procedure with UDM (1813) (S1804).
[0265] sSMF (1807) can generate an Nsmf_PDUSession_CreateSMContextResponse message. sSMF (1807) can send the Nsmf_PDUSession_CreateSMContextResponse message to sAMF (1805) (S1805). sAMF (1805) can receive the Nsmf_PDUSession_CreateSMContextResponse message sent by sSMF (1807).
[0266] At least one of UE (1801), sRAN (1803), sAMF (1805), sSMF (1807), sUPF (1809), sPCF (1811), UDM (1813) or DN (1815) can perform a PDU session authentication / authorization procedure (S1806).
[0267] sSMF (1807) can perform the sPCF selection procedure (S1807). sSMF (1807) and sPCF (1809) can perform the SM policy association establishment procedure (S1808). sPCF (1809) can perform the SM policy association modification procedure initiated by SMF. sSMF (1807) can perform the sUPF selection procedure (S1809).
[0268] FIG. 19 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0269] Referring to FIG. 19, at least one device included in the communication system may include at least one of UE (1901), sRAN (1903), sAMF (1905), sSMF (1907), sUPF (1909), sPCF (1911), UDM (1913) or DN (1915).
[0270] If the URSP policy is not set on the UE (1901), the UE (1901) may set an S-NSSAI representing SE-NS in the UE (1901)'s Allowed NSSAI to use SE-NS. If the UE (1901) sets an S-NSSAI representing SE-NS in the UE (1901)'s Allowed NSSAI, the UE (1901) may proceed with the PDU session establishment procedure based on the S-NSSAI representing SE-NS that is not NULL as the Default S-NSSAI. In other words, if the URSP is not set on the UE (1901) and there is SE-NS among the UE (1901)'s Allowed NSSAI, the procedure of the communication system may be as follows.
[0271] The UE (1901) can generate a configured NSSAI. The configured NSSAI may include an S-NSSAI. The S-NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a NULL value. The configured NSSAI may include an S-NSSAI#2. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a NULL value.
[0272] UDM (1913) may have subscribed S-NSSAIs configured. UDM may store subscribed S-NSSAIs indicating whether a specific UE can use a specific network slice according to an enterprise subscription policy. A subscribed S-NSSAI may include at least one of Default S-NSSAI#1 or S-NSSAI#2. Default S-NSSAI#1 may include at least one of SST or SD. The SST of Default S-NSSAI#1 may contain a value of 1. The SD of Default S-NSSAI#1 may contain a NULL value. Default S-NSSAI#1 may be an S-NSSAI for B2C. Default S-NSSAI#1 may be an identifier referring to URLLC, eMTC (enhanced Machine-Type Communication), mIoT (media-centric internet of things), etc. Default S-NSSAI#1 may be a separate network slice for a specific service.
[0273] S-NSSAI#2 may include at least one of SST or SD. The SST of S-NSSAI#2 may include a value of 128. The SD of S-NSSAI#2 may include a value of NULL. S-NSSAI#2 may be an S-NSSAI for a security slice.
[0274] At least one of UE (1901), sRAN (1903), sAMF (1905), sSMF (1907), sUPF (1909), sPCF (1911), UDM (1913) or DN (1915) can perform an initial registration procedure.
[0275] The UE (1901) can generate an Allowed NSSAI. The Allowed NSSAI may include at least one of an S-NSSAI or an S-NSSAI#2. The S-NSSAI of the Allowed NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a NULL value. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a NULL value.
[0276] The UE (1901) can generate a PDU session establishment request message. The PDU session establishment request message may include at least one of S-NSSAI or DNN. The PDU session establishment request message may include information on whether a URSP policy is set on the terminal. The S-NSSAI of the PDU session establishment request message may include the value S-NSSAI#2. The DNN of the PDU session establishment request message may include information that it is internet. The UE (1901) can transmit the PDU session establishment request message to sAMF (1905) (S1901).
[0277] sAMF (1905) can receive a PDU session establishment request message transmitted by UE (1901). sAMF (1905) can determine whether URSP is set on UE (1901) through the PDU session establishment request message. sAMF (1905) can determine whether there is an SE-NS NSSAI among the Allowed NSSAIs of UE (1901). If URSP is not set on UE (1901) and there is an SE-NS NSSAI among the Allowed NSSAIs of UE (1901), sAMF (1905) can use the SE-NS NSSAI as the Default S-NSSAI. sAMF (1905) can perform an sSMF selection procedure (S1802). In other words, sAMF (1905) can perform an sSMF selection procedure using the selected SE-NS NSSAI. sAMF (1905) may not perform the RA addition procedure in NF Discovery because UE (1901) does not have a URSP.
[0278] sAMF (1905) can create an Nsmf_PDUSession_CreateSMContextRequest message. sAMF (1905) can send an Nsmf_PDUSession_CreateSMContextRequest message to sSMF (1907) (S1903).
[0279] sSMF (1907) can receive the Nsmf_PDUSession_CreateSMContextRequest message sent by sAMF (1905). sSMF (1907) can perform a subscription retrieval / subscription for updates procedure with UDM (1913) (S1904).
[0280] sSMF (1907) can generate an Nsmf_PDUSession_CreateSMContextResponse message. sSMF (1907) can send the Nsmf_PDUSession_CreateSMContextResponse message to sAMF (1905) (S1905). sAMF (1905) can receive the Nsmf_PDUSession_CreateSMContextResponse message sent by sSMF (1907).
[0281] At least one of UE (1901), sRAN (1903), sAMF (1905), sSMF (1907), sUPF (1909), sPCF (1911), UDM (1913) or DN (1915) can perform a PDU session authentication / authorization procedure (S1906).
[0282] sSMF (1907) can perform the sPCF selection procedure (S1907). sSMF (1907) and sPCF (1911) can perform the SM policy association establishment procedure (S1908). sPCF (1911) can perform the SM policy association modification procedure initiated by SMF. sSMF (1907) can perform the sUPF selection procedure (S1909).
[0283] FIG. 20 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0284] Referring to FIG. 20, at least one device included in the communication system may include at least one of UE (2001), sRAN (2003), sAMF (2005), sSMF (2007), sUPF (2009), sPCF (2011), UDM (2013) or DN (2015).
[0285] If a URSP policy is set in the UE (2001), and for SE-NS usage, the Allowed NSSAI of the UE (2001) contains an S-NSSAI indicating SE-NS, and the RA Indicator of the URSP is set to N, then at least one device included in the communication system can perform a PDU session establishment procedure. Since the policy is that the UE (2001) does not perform an additional RA, when the NW generates SE-NS, it can perform an RA. When the UE (2001) establishes a PDU session for SE-NS usage, at least one device included in the communication system may not perform a reliability verification by not performing an additional RA during the NF selection process. The procedure of the communication system may be as follows.
[0286] The UE (2001) can generate a configured NSSAI. The configured NSSAI may include an S-NSSAI. The S-NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a NULL value. The configured NSSAI may include an S-NSSAI#2. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a NULL value.
[0287] UDM (2013) may have subscribed S-NSSAIs configured. UDM (2013) may store subscribed S-NSSAIs indicating whether a specific UE can use a specific network slice according to an enterprise subscription policy. A subscribed S-NSSAI may include at least one of Default S-NSSAI#1 or S-NSSAI#2. Default S-NSSAI#1 may include at least one of SST or SD. The SST of Default S-NSSAI#1 may include a value of 1. The SD of Default S-NSSAI#1 may include a NULL value. Default S-NSSAI#1 may be an S-NSSAI for B2C. Default S-NSSAI#1 may be an identifier referring to URLLC, eMTC (enhanced Machine-Type Communication), mIoT (media-centric internet of things), etc. Default S-NSSAI#1 can be a separate network slice for specific services.
[0288] S-NSSAI#2 may include at least one of SST or SD. The SST of S-NSSAI#2 may include a value of 128. The SD of S-NSSAI#2 may include a value of NULL. S-NSSAI#2 may be an S-NSSAI for a security slice.
[0289] At least one of UE (2001), sRAN (2003), sAMF (2005), sSMF (2007), sUPF (2009), sPCF (2011), UDM (2013) or DN (2015) can perform an initial registration procedure.
[0290] The UE (2001) can generate an Allowed NSSAI. The Allowed NSSAI may include at least one of an S-NSSAI or an S-NSSAI#2. The S-NSSAI of the Allowed NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a NULL value. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a NULL value.
[0291] The UE (2001) can generate a PDU session establishment request message. The PDU session establishment request message may include at least one of S-NSSAI, DNN, or RA indication. The PDU session establishment request message may include information regarding whether a URSP policy is set on the terminal. The S-NSSAI of the PDU session establishment request message may include the value S-NSSAI#2. The DNN of the PDU session establishment request message may include information that it is "internet". The RA indication may include information indicating Y or N. Y of the RA indication may mean information indicating the execution of an RA procedure. N of the RA indication may mean information not indicating the execution of an RA procedure. The RA indication of the PDU session establishment request message may include N information. The UE (2001) can transmit the PDU session establishment request message to sAMF (2005) (S2001).
[0292] sAMF (2005) can receive a PDU session establishment request message transmitted by UE (2001). sAMF (2005) can determine whether URSP is set on UE (2001) through the PDU session establishment request message. sAMF (2005) can determine whether there is an SE-NS NSSAI among the Allowed NSSAIs of UE (2001). sAMF (2005) can determine whether to apply the RA procedure through the PDU session establishment request message. If URSP is set on UE (2001) and there is an SE-NS NSSAI among the Allowed NSSAIs of UE (2001), sAMF (2005) can select whether to apply the RA.
[0293] sAMF (2005) can perform the sAMF selection procedure (S2002). sAMF (2005) may not perform the RA addition procedure in NF Discovery if RA is not applied to the URSP of UE (2001). In other words, sAMF (2005) may not perform the RA addition procedure in NF Discovery if the RA indicator in the URSP of UE (2001) is N.
[0294] sAMF (2005) can create an Nsmf_PDUSession_CreateSMContextRequest message. sAMF (2005) can send an Nsmf_PDUSession_CreateSMContextRequest message to sSMF (2007) (S2003).
[0295] sSMF (2007) can receive the Nsmf_PDUSession_CreateSMContextRequest message sent by sAMF (2005). sSMF (2007) can perform subscription retrieval / subscription for updates procedure with UDM (2013) (S2004).
[0296] sSMF (2007) can generate an Nsmf_PDUSession_CreateSMContextResponse message. sSMF (2007) can send the Nsmf_PDUSession_CreateSMContextResponse message to sAMF (2005) (S2005). sAMF (2005) can receive the Nsmf_PDUSession_CreateSMContextResponse message sent by sSMF (2007).
[0297] At least one of UE (2001), sRAN (2003), sAMF (2005), sSMF (2007), sUPF (2009), sPCF (2011), UDM (2013) or DN (2015) can perform a PDU session authentication / authorization procedure (S2006).
[0298] sSMF (2007) can perform an sPCF selection procedure (S2007). sSMF (2007) and sPCF (2011) can perform an SM policy association establishment procedure (S2008). sPCF (2011) can perform an SM policy association modification procedure initiated by sSMF (2007). sSMF (2007) can perform an sUPF selection procedure (S2009).
[0299] FIG. 21 is a flowchart illustrating a session establishment procedure for SE-NS according to one embodiment of the present disclosure.
[0300] Referring to FIG. 21, at least one device included in the communication system may include at least one of UE (2101), sRAN (2103), sAMF (2105), sSMF (2107), sUPF (2109), sPCF (2111), UDM (2113) or DN (2115).
[0301] If a URSP policy is set in the UE (2101), and for SE-NS usage, the Allowed NSSAI of the UE (2101) contains an S-NSSAI indicating SE-NS, and the RA Indicator of the URSP is set to Y, then at least one device included in the communication system can perform a PDU session establishment procedure. Since the policy allows the UE (2101) to additionally perform RA, when the NW generates SE-NS, at least one device included in the communication system can perform RA. When the UE (2101) establishes a PDU session for SE-NS usage, at least one device included in the communication system can perform reliability verification by additionally performing RA during the NF selection process. The procedure of the communication system may be as follows.
[0302] The UE (2101) can generate a configured NSSAI. The configured NSSAI may include an S-NSSAI. The S-NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a NULL value. The configured NSSAI may include an S-NSSAI#2. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a NULL value.
[0303] The UDM (2113) may be configured with subscribed S-NSSAIs. The UDM (2113) may store subscribed S-NSSAIs indicating whether a specific UE can use a specific network slice according to the enterprise subscription policy. A subscribed S-NSSAI may include at least one of Default S-NSSAI#1 or S-NSSAI#2. Default S-NSSAI#1 may include at least one of SST or SD. The SST of Default S-NSSAI#1 may include a value of 1. The SD of Default S-NSSAI#1 may include a NULL value. Default S-NSSAI#1 may be an S-NSSAI for B2C. Default S-NSSAI#1 may be an identifier referring to URLLC, eMTC (enhanced Machine-Type Communication), mIoT (media-centric internet of things), etc. Default S-NSSAI#1 may be a separate network slice for a specific service. S-NSSAI#2 may include at least one of SST or SD. The SST of S-NSSAI#2 may include a value of 128. The SD of S-NSSAI#2 may include a value of NULL. S-NSSAI#2 may be an S-NSSAI for a security slice.
[0304] At least one of UE (2101), sRAN (2103), sAMF (2105), sSMF (2107), sUPF (2109), sPCF (2111), UDM (2113) or DN (2115) can perform an initial registration procedure.
[0305] The UE (2101) can generate an Allowed NSSAI. The Allowed NSSAI may include at least one of an S-NSSAI or an S-NSSAI#2. The S-NSSAI of the Allowed NSSAI may include at least one of an SST or an SD. The SST of the S-NSSAI may include a value of 1. The SD of the S-NSSAI may include a value of NULL. The S-NSSAI#2 may include at least one of an SST or an SD. The SST of the S-NSSAI#2 may include a value of 128. The SD of the S-NSSAI#2 may include a value of NULL.
[0306] The UE (2101) can generate a PDU session establishment request message. The PDU session establishment request message may include at least one of S-NSSAI, DNN, or RA indication. The PDU session establishment request message may include information regarding whether a URSP policy is set on the UE (2101). The S-NSSAI of the PDU session establishment request message may include the value S-NSSAI#2. The DNN of the PDU session establishment request message may include information that it is "internet". The RA indication may include information indicating Y or N. Y of the RA indication may mean information indicating the execution of an RA procedure. The RA indication of the PDU session establishment request message may include Y information. N of the RA indication may mean information indicating that it does not indicate the execution of an RA procedure. The UE (2101) can transmit the PDU session establishment request message to sAMF (2105) (S2101).
[0307] sAMF (2105) can receive a PDU session establishment request message transmitted by UE (2101). sAMF (2105) can determine whether URSP is set on UE (2101) through the PDU session establishment request message. sAMF (2105) can determine whether there is an SE-NS NSSAI among the Allowed NSSAIs of UE (2101). sAMF (2105) can determine whether to apply the RA procedure through the PDU session establishment request message. If URSP is set on UE (2101) and there is an SE-NS NSSAI among the Allowed NSSAIs of UE (2101), sAMF (2105) can select whether to apply the RA.
[0308] sAMF (2105) can perform an sSMF selection procedure (S2102). When sAMF (2105) performs an sSMF selection procedure, sAMF (2105) can perform an RA enforcement procedure. sAMF (2105) can enforce the execution of an RA addition procedure in NF Discovery if the RA indicator in the URSP of UE (2101) is Y. In other words, if the RA indicator in the URSP of UE (2101) is Y, sAMF (2105) can enforce the execution of an RA addition procedure in NF Discovery.
[0309] sAMF (2105) can create an Nsmf_PDUSession_CreateSMContextRequest message. sAMF (2105) can send an Nsmf_PDUSession_CreateSMContextRequest message to sSMF (2107) (S2103).
[0310] sSMF (2107) can receive the Nsmf_PDUSession_CreateSMContextRequest message sent by sAMF (2105). sSMF (2107) can perform a subscription retrieval / subscription for updates procedure with UDM (2113) (S2104).
[0311] sSMF (2107) can generate an Nsmf_PDUSession_CreateSMContextResponse message. sSMF (2107) can send the Nsmf_PDUSession_CreateSMContextResponse message to sAMF (2105) (S2105). sAMF (2105) can receive the Nsmf_PDUSession_CreateSMContextResponse message sent by sSMF (2107).
[0312] At least one of UE (2101), sRAN (2103), sAMF (2105), sSMF (2107), sUPF (2109), sPCF (2111), UDM (2113) or DN (2115) can perform a PDU session authentication / authorization procedure (S2106).
[0313] sSMF (2107) can perform an sPCF selection procedure (S2107). If sSMF (2107) performs an sPCF selection procedure, sSMF (2107) can perform an RA enforcement procedure. sSMF (2107) and sPCF (2111) can perform an SM policy association establishment procedure (S2108). sPCF (2111) can perform an SM policy association modification procedure initiated by SMF. sSMF (2107) can perform an sUPF selection procedure (S2109). If sSMF (2107) performs an sUPF selection procedure, sSMF (2107) can perform an RA enforcement procedure.
[0314] sNF may include at least one sRAN among sSMF, sPCF, sAMF, sAF, sNEF, and sUPF. sNFs may refer to NFs authenticated through RA. In other words, NFs registered by applying the RA registration protocol to the NF service registration procedure may be referred to as sNFs. sNFs may refer to NFs to which the RA authentication protocol has been applied in the NF service discovery procedure. For example, if a RAN constitutes an SE-NS, the SE-NS may be composed of NFs authenticated by performing RA.
[0315] FIG. 22 is a conceptual diagram illustrating a security-enhanced network slice service according to one embodiment of the present disclosure.
[0316] Referring to FIG. 22, at least one device included in the communication system can provide communication services for applications requiring special security by utilizing a quantum security algorithm in 6G. Applications requiring special security may include government applications, military communications, medical services, financial services, etc. At least one device included in the communication system may include at least one of a network infrastructure (2201) or an automation orchestrator (AO) (2203).
[0317] The network infrastructure (2201) may include at least one of a security slice or an eMBB slice. The security slice may be transmitted to a radio unit (RU). The RU may receive the security slice. The RU may transmit the security slice to a digital unit (DU). The RU may transmit the security slice to the DU via a fronthaul TN. The DU may receive the security slice transmitted by the RU. The DU may transmit the security slice to a central unit (CU)-user plane (PDCP). The DU may transmit the security slice to a CU-UP (PDCP) via a midhaul TN. The CU-UP (PDCP) may receive the security slice transmitted by the DU. The CU-UP (PDCP) may transmit the security slice to a security PF (UPF). CU-UP (PDCP) can transmit security slices to UPF via the backhaul TN. In other words, CU-UP (PDCP) can transmit security slices to UPF via N3. UPF can receive security slices transmitted by CU-UP (PDCP). UPF can transmit security slices to DN using PCF and / or SMF. UPF can transmit security slices to DN via the backbone. UPF can transmit security slices to DN via N6. DN can receive security slices transmitted by UPF. DN may include security-enhanced applications.
[0318] An eMBB slice can be transmitted to an RU. The RU can receive an eMBB slice. The RU can transmit an eMBB slice to a DU. The DU can receive an eMBB slice transmitted by the RU. The DU can transmit an eMBB slice to a CU-UP (PDCP). The CU-UP (PDCP) can receive an eMBB slice transmitted by the DU. The CU-UP (PDCP) can transmit an eMBB slice to a UPF (security). The UPF can receive an eMBB slice transmitted by the CU-UP (PDCP). The UPF can transmit an eMBB slice to a DN using an SMF. The UPF can transmit an eMBB slice to a DN via N6. The DN can receive an eMBB slice transmitted by the UPF. The DN may include eMBB applications (eMBB apps).
[0319] AO(2203) may include at least one of an end-to-end (E2E) service orchestration, a RAN NSSMF, a core NSSMF, or a TN NSSMF. The E2E service orchestration may include at least one of a CSMF or an NSMF. The RAN NSSMF may include at least one of a quantum-safe (QS) or a trust. The core NSSMF may include at least one of a QS or a trust. The TN NSSMF may include a QS.
[0320] FIG. 23 is a conceptual diagram illustrating a virtual network function (VNF) / cloud-native network function (CNF) remote proof according to one embodiment of the present disclosure.
[0321] Referring to FIG. 23, at least one device included in a next-generation communication system performing RA can dynamically perform reliability verification for NFs constituting the communication system. At least one device included in a communication system that dynamically performs reliability verification for NFs can enhance security for network slices.
[0322] An external attester can provide evidence to a communication system. At least one device included in the communication system may include at least one of a base station, a terminal, a server, a private network, an edge, a cloud, or a shared COTS server. The attester may include at least one of a shared COTS server, a private network, an edge, or a cloud. A shared COTS server may include at least one of a vCU, an O-CU, applications, or shared hardware. A private network and / or edge may include at least one of a UPF or untrusted hardware. A cloud may include at least one of CNFs or untrusted hardware.
[0323] The attestation device can receive attestation from an external attestation device. The attestation device can transmit the attestation to the AO and / or MO. The AO and / or MO may refer to a verifier. The AO may include at least one of a BO, CO, or USM. The AO and / or SMO can perform a remote attestation service. Remote attestation can secure credibility in an untrusted zone. An untrusted zone may include shared COTS, edge, or cloud. The AO and / or SMO can verify the attestation. In other words, the AO and / or SMO can verify the attestation through the remote attestation service. Remote attestation can prevent cyber attacks. Remote attestation can prevent data leakage in a cloud environment. The AO and / or SMO can generate attestation results by performing verification on the attestation.
[0324] The verification device, the AO and / or SMO, can transmit the verification results to a terminal and / or base station. The terminal or base station may include NF or trusted hardware. In other words, the verification device, the AO and / or SMO, can transmit the verification results to a terminal or base station having trusted hardware.
[0325] A terminal or base station having trusted hardware may be referred to as a relying party. The relying party may receive attestation results from the AO and / or SMO. The relying party may include at least one of an NF or trusted hardware. The relying party may transmit the trust result to an attestation device.
[0326] Trusted devices and / or verification devices can detect attack propagation. Trusted devices and / or verification devices can block attack propagation.
[0327] FIG. 24 is a block diagram illustrating a UE device according to one embodiment of the present disclosure.
[0328] Referring to FIG. 24, the UE (2401) illustrated in FIG. 24 may be a UE device illustrated in the present disclosure. The UE (2401) may include at least one of a transceiver (2402), a processor (2403), or a memory (2404). The transceiver (2402) of the UE may refer to a transceiver that performs signal transmission and reception with other UEs or network entities. The transceiver (2402) may support 5G networks following 4G networks and next-generation communication technologies, for example, new radio access technology (NR access technology). NR access technology may support high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and connection of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low-latency communications (URLLC)). The transceiver (2402) may support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The transceiver (2402) may support various technologies for securing performance in the high-frequency band, for example, beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beamforming, or large-scale antenna. The transceiver (2402) may also be referred to as a transceiver or a communication module.
[0329] The processor (2403) of the UE may also be referred to as a control unit or a controller. The processor (2403) of the UE may include at least one processor that controls at least one operation of the UE (2401). All operations or methods in the UE described above in this disclosure may be understood as being performed under the control of said processor (2403).
[0330] The memory (2403) may store various data used by at least one component of the UE (2401) (e.g., processor (2403) or transceiver (2402)). The data may include, for example, input data or output data for software and related commands. The memory (2403) may include volatile memory and / or non-volatile memory.
[0331] The processor (2403), the transceiver (2402), and the memory (2404) do not necessarily have to be implemented as separate devices, and can, of course, be implemented as a single component in the form of a single chip. The control unit can be implemented as a single processor within the UE (2401).
[0332] FIG. 25 is a block diagram illustrating an entity device according to one embodiment of the present disclosure.
[0333] Referring to FIG. 25, the network entity may include at least one of a transceiver, a processor, and a memory. The network entity device illustrated in FIG. 25 may be a core network entity device (SMF, PCF, AMF, AF, NEF (network exposure function), UPF, RAN, etc.) illustrated in the present disclosure. The network entity device illustrated in FIG. 25 may be a core network entity device (sSMF, sPCF, sAMF, sAF (secure application function), sNEF (secure Network Exposure Function), sUPF, sRAN, etc.) illustrated in the present disclosure.
[0334] A network entity (2500) may include a transceiver (2502) that performs signal transmission and reception with other network entities or UEs, and a processor (2503) that controls all operations of the network entity (2501). In the present disclosure, all methods performed by entities such as SMF, PCF, AMF, AF, NEF, UPF, RAN, etc., may be understood as being performed under the control of the processor (2503). In the present disclosure, all methods performed by entities such as sSMF, sPCF, sAMF, sAF, sNEF, sUPF, sRAN, etc., may be understood as being performed under the control of the processor (2503).
[0335] The transceiver (2502) can support 5G networks and next-generation communication technologies following 4G networks, for example, new radio access technology. NR access technology can support high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and connection of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low-latency communications (URLLC)). The transceiver (2502) can support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The transceiver (2502) can support various technologies for securing performance in the high-frequency band, such as beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large-scale antenna. The transceiver (2502) may also be referred to as a transceiver or a communication module.
[0336] The processor (2503) of the network entity may also be referred to as a control unit or a controller. The processor (2503) of the network entity may include at least one processor that controls at least one operation of the network entity (2501). All operations or methods in the UE described above in this disclosure may be understood as being performed under the control of said processor (2503).
[0337] The memory (2503) may store various data used by at least one component of the UE (2501) (e.g., processor (2503) or transceiver (2502)). The data may include, for example, input data or output data for software and related commands. The memory (2503) may include volatile memory and / or non-volatile memory.
[0338] The processor (2503), the transceiver (2502), and the memory (2504) do not necessarily have to be implemented as separate devices, and can, of course, be implemented as a single component in the form of a single chip. The control unit can be implemented as a single processor within the network entity (2501).
[0339] It should be noted that the system configuration diagrams, method example diagrams, device configuration diagrams, etc., illustrated in FIGS. 1 to 25 above are not intended to limit the scope of the rights of the present disclosure. That is, all configurations or operations described in FIGS. 1 to 12 above should not be interpreted as essential components for the implementation of the present disclosure, and may be implemented within a scope that does not impair the essence of the present disclosure even if only some components are included.
[0340] Methods according to the claims or embodiments described in the specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.
[0341] When implemented in software, a computer-readable storage medium may be provided for storing one or more programs (software modules). One or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. One or more programs may include instructions that cause the electronic device to execute methods according to the claims or embodiments described in the specification of this disclosure.
[0342] Such programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), magnetic disc storage devices, CD-ROM (Compact Disc-ROM), Digital Versatile Discs (DVDs), or other forms of optical storage devices, magnetic cassettes. Alternatively, they may be stored in memory composed of some or all of these. Additionally, each constituent memory may include multiple units.
[0343] Additionally, the program may be stored on an attachable storage device accessible via a communication network such as the Internet, Intranet, Local Area Network (LAN), Wide LAN (WLAN), or Storage Area Network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure through an external port. Additionally, a separate storage device on a communication network may be connected to a device performing an embodiment of the present disclosure.
[0344] In the specific embodiments of the present disclosure described above, the components included in the present disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.
Claims
1. In a method of sAMF (secure-access and mobility management function) authenticated through RA (remote attestation) for network slice usage, A step of receiving a session establishment request message, a PDU (packet data unit), transmitted by the UE (user equipment); A step of determining whether to perform RA using the above PDU session establishment request message; A step of selecting an sSMF (secure-session management function) authenticated through the RA based on the above PDU session establishment request message and whether the above RA is performed; A step of transmitting to the sSMF a context request message containing information indicating whether the sSMF performs additional RA; A step of receiving a context response message from the above sSMF; and A step comprising performing a PDU session authentication / authorization procedure using the above context response message, sAMF method.
2. In Paragraph 1, The step of selecting an sSMF authenticated through RA based on the above PDU session establishment request message and whether the above RA is performed is: A step of performing RA by determining whether URSP is configured in the above UE and whether SE-NS (security-enhanced network slice) NSSAI (network slice selection assistance information) is present in the PDU session establishment request message; and A step comprising selecting an sSMF by performing the above RA, sAMF method.
3. In Paragraph 1, The step of selecting an sSMF authenticated through RA based on the above PDU session establishment request message and whether the above RA is performed is: A step of determining whether URSP is configured in the above UE and whether SE-NS NSSAI is present in the PDU session establishment request message, and selecting SE-NS NSSAI as the default S-NSSAI (single-network slice selection assistance Information); and A step including selecting an sSMF using the default S-NSSAI above, sAMF method.
4. In the method of sSMF (secure-session management function) for using network slices, A step of receiving a context request message from a secure-access and mobility management function (sAMF) containing information indicating whether the above sSMF performs additional remote attestation (RA); A step of sending a context response message to the above sAMF; A step of performing a PDU session authentication / authorization procedure using the above context response message; A step of selecting a secure-point coordination function (sPCF) using a context request message; and A method including the step of selecting a secure-user plane function (sUPF) using a context request message, sSMF method.
5. In Paragraph 4, The step of selecting sPCF using a context request message is, A step for determining whether to apply RA; and A step including selecting sPCF by forcibly performing the RA procedure considering whether the above RA is applied, sSMF method.
6. In Paragraph 4, The step of selecting sUPF using a context request message is, A step for determining whether to apply RA; and A step including selecting sUPF by forcibly performing the RA procedure considering whether the above RA is applied, sSMF method.
7. In Paragraph 4, The above sSMF method is, A step of determining whether there is a URSP in the context request message transmitted by the above sAMF; A step of determining whether SE-NS NSSAI is present in the context request message transmitted by the sAMF; and A step further comprising selecting the SE-NS NSSAI as the Default S-NSSAI (single-network slice selection assistance information) by considering the presence or absence of the above URSP and SE-NS (security-enhanced network slice) NSSAI (network slice selection assistance information), sSMF method.
8. In the method of a UE (user equipment) for using network slices, A step of determining whether a URSP (UE route selection policy) rule is set; If it is determined that the above URSP policy is set, the method includes the step of transmitting a PDU (packet data unit) session establishment request message to the sAMF (secure-access and mobility management function) using the above URSP policy. UE's method.
9. In Paragraph 8, A step of determining whether there is an S-NSSAI (single-network slice selection assistance Information) representing a SE-NS (security-enhanced network slice) in the Allowed NSSAI (network slice selection assistance information); and If the above S-NSSAI exists, the UE further includes the step of transmitting an S-NSAAI representing a non-NULL SE-NS Default S-NSSAI included in the above PDU session establishment request message. UE's method.
10. In Paragraph 8, The above PDU session establishment request message is, including RA (remote attestation) factors, UE's method.
11. In a device of sAMF (secure-access and mobility management function) authenticated through RA (remote attestation) for network slice usage, Transmitter / receiver; and It includes a control unit, and the control unit, said control unit Receives a session establishment request message, a PDU (packet data unit) transmitted by the UE (user equipment), and Determine whether to perform RA using the above PDU session establishment request message, and Based on the above PDU session establishment request message and whether the above RA is performed, select an sSMF (secure-session management function) authenticated through the RA, and Sending a context request message to the sSMF that includes information indicating whether the sSMF performs additional RA, and Receive a context response message from the above sSMF, and Configured to perform a PDU session authentication / authorization procedure using the above context response message, sAMF device.
12. In Paragraph 11, The operation of selecting an sSMF authenticated via RA based on the above PDU session establishment request message and whether the above RA is performed is: Perform RA by determining whether URSP is configured on the above UE and whether SE-NS (security-enhanced network slice) NSSAI (network slice selection assistance information) is present in the PDU session establishment request message, and Configured to select sSMF by performing the above RA, sAMF device.
13. In Paragraph 11, The operation of selecting an sSMF authenticated via RA based on the above PDU session establishment request message and whether the above RA is performed is: Determine whether URSP is configured in the above UE and the presence of SE-NS NSSAI in the PDU session establishment request message, select SE-NS NSSAI as the default S-NSSAI (single-network slice selection assistance Information), and Configured to select sSMF using the above default S-NSSAI, sAMF device.
14. In a device of sSMF (secure-session management function) for network slicing, Transmitter / receiver; and It includes a control unit, and the control unit, said control unit The above sSMF receives a context request message from the sAMF (secure-access and mobility management function) containing information indicating whether to additionally perform RA (remote attestation), and Send a context response message to the above sAMF, and Using the above context response message, perform the PDU session authentication / authorization procedure, and Select the sPCF (secure-point coordination function) using the context request message, and Configured to select the sUPF (secure-user plane function) using context request messages, sSMF device.
15. In Paragraph 14, The operation of selecting an sPCF using a context request message is: Determine whether to apply RA, and Configured to select sPCF by forcibly performing the RA procedure considering whether the above RA is applied, sSMF device.
Citation Information
Patent Citations
Communication method and device
CN116847331A
LED lighting device for outdoor with surge protection and pest prevention function
KR1020210119172A
Polarizing Plate and Display Device Comprising the Same
KR1020260050775A
Ball Type Base Isolation device
KR102396446B1
Methods, architectures, apparatuses and systems for assertion of wireless transmit / receive unit (WTRU) trustworthiness
WO2023212152A1