User plane connection establishment for providing location services
A dedicated TCP port number for LCS-UPP is introduced, allowing the UE to correctly set up a secure connection with the LMF, addressing the uncertainty in port selection and ensuring efficient message routing.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
- Filing Date
- 2025-10-08
- Publication Date
- 2026-05-07
AI Technical Summary
The existing Location Services User Plane Protocol (LCS-UPP) does not provide a reserved TCP port number for the UE to establish a secure connection with the Location Management Function (LMF), leading to uncertainty in setting the destination TCP port for the TLS connection, as the LMF can be used for multiple services.
A dedicated TCP port number is allocated for LCS-UPP, either by registration with IANA or 3GPP, or included in the connection establishment request message, enabling the UE to set up an LCS secure connection by including the port number in the TCP connection request.
Enables the UE to establish a secure connection with the LMF by specifying the correct TCP port, ensuring proper routing of LCS-UPP messages.
Smart Images

Figure EP2025078954_07052026_PF_FP_ABST
Abstract
Description
USER PLANE LOCATION SERVICESTECHNICAL FIELD
[0001] Disclosed are embodiments related to user plane location services.BACKGROUND
[0002] The Location Services User Plane Protocol (LCS-UPP), which was introduced in 3GG Release 18 (Rell8) (see, e.g., 3GPP Technical Specification (TS) 24.572 V18.2.1 (2024- 09), provides transport of Long Term Evolution (LTE) Positioning Protocol (LPP) messages and Location Service (LCS) supplementary services messages via a user plane connection between a user equipment (UE) and a Location Management Function (LMF). As used herein a UE can be embodied in any type of device with wireless communication capabilities, such as, for example, a phone, an appliance, a vehicle, a sensor, a camera, a computer, a tablet, a gateway, a router, an access point, etc.
[0003] To utilize the user plane positioning via LCS-UPP, the UE and LMF establish what is known as an LCS secured user plane connection, the LCS secured user plane connection is typically a Transport Layer Security (TLS) connection established over a Transmission Control Protocol (TCP) connection that is established between the UE and the LMF.
[0004] To trigger the UE to establish the LCS secured user plane connection towards the LMF, the LMF transmits to the UE a connection establishment request message, such as, for example, a USER PLANE CONNECTION ESTABLISHMENT COMMAND message as defined in 3GPP TS 24.572 VI 8.2.1 (hereinafter “TS 24.572”). This connection establishment request includes the LMF’s user plane (UP) positioning address (a.k.a., the LMF LCS UP address), which consists essentially of an Internet Protocol (IP) address or a fully qualified domain name (FQDN) assigned to the LMF.SUMMARY
[0005] Certain challenges presently exist. For instance, while the LMF LCS UP address provided in the connection establishment request includes a network address (e.g., an IP address or a FQDN), the connection establishment request does not include the LMF's TCP port numberto be used as destination port when the UE establishes the TCP connection for the secure connection (e.g., TLS connection) for LCS-UPP. Moreover, there is no TCP port number reserved for LCS-UPP.
[0006] Because a TCP port number is not included in the connection establishment request and there is no TCP port number reserved for LCS-UPP, the UE does not know how to set the destination TCP port when establishing the TCP connection for the TLS connection for the LCS-UPP. Also, the LMF is not dedicated to being used for LCS-UPP; the LMF can be used for user plane positioning using SUPL (Secure User Plane Location), or other services as well, which means that the LMF may be running multiple services (e.g., applications) each associated with a different TCP port number.
[0007] Accordingly, in one aspect there is provided a method performed by a UE for use in establishing a connection with an LMF. The method includes receiving from the LMF a connection establishment request message, wherein the connection establishment request message carries a port number. The method also includes obtaining the port number from the received connection establishment request message. In another aspect there is provided a computer program comprising instructions which when executed by processing circuitry of a UE causes the UE to perform the method. In one embodiment, there is provided a carrier containing the computer program wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer readable storage medium. In another aspect there is provided a UE that is configured to perform the method. The UE may include memory and processing circuitry coupled to the memory.
[0008] In another aspect there is provided a method performed by a UE for use in establishing a connection with an LMF. The method includes generating a connection establishment request message, wherein the connection establishment request message carries a port number. The method also includes transmitting the connection establishment request message to the UE. In another aspect there is provided a computer program comprising instructions which when executed by processing circuitry of a network node causes the network node to perform the method. In one embodiment, there is provided a carrier containing the computer program wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer readable storage medium. In another aspect there is provided a networknode that is configured to perform the method. The network node may include memory and processing circuitry coupled to the memory.
[0009] An advantage of the embodiments disclosed herein is that they enable the UE 102 to set up an LCS secure connection.BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The accompanying drawings, which are incorporated herein and form part of the specification, illustrate various embodiments.
[0011] FIG. 1 illustrates a system according to an embodiment.
[0012] FIG. 2 is a message flow diagram according to an embodiment.
[0013] FIG. 3 is a flowchart illustrating a process according to an embodiment.
[0014] FIG. 4 is a flowchart illustrating a process according to an embodiment.
[0015] FIG. 5 is a block diagram of a UE according to an embodiment.
[0016] FIG. 6 is a block diagram of a network node according to an embodiment.DETAILED DESCRIPTION
[0017] FIG. 1 illustrates an exemplifying wireless communication system 100 represented as a 3GPP Fifth Generation (5G) network architecture comprising an Access Network (AN) 190 (e.g., a Radio AN (RAN)) and a Core network (CN) comprising network entities in the form of Network Functions (NFs). Typically, the AN comprises base stations, e.g., such as evolved Node Bs (eNBs) or 5G base stations (gNBs) or similar. As shown in FIG. 1, a user equipment (UE) 102 establishes a connection with the AN 190 and is able to communicate with an Access and Mobility Management Function (AMF) 106 via AN 190. As further shown in FIG. 1, the 5G CN NFs include: a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a Network Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), an Application Function (AF), an Authentication Server Function (AUSF), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), a User Plane Function (UPF), and an LMF 104.
[0018] A number of 5G core network NFs of different types are typically instantiated per default in the 5G core network, e.g., such as an AMF, a NRF, a PCF, a SMF, an LMF etc. Other5G core network NFs may be instantiated as needed and several NFs of the same type can also be instantiated if required, e.g., to distribute load to additional NF(s) of the same type. Thus, an NF instance may be seen as an example or a specimen of a certain NF. Herein, the terms NF and NF instance are used interchangeably, unless otherwise expressly stated or is apparent from the context in which the terms are used. An NF instance exposes one or more NF Service Instances.
[0019] FIG. 2 is a message flow diagram illustrating a message flow according to an embodiment. In some embodiments, LMF 104 may trigger UE 102 to establish an LCS secure connection with LMF 104 by transmitting to UE 102 a connection establishment request message m202. Message m202 may be modified version of the USER PLANE CONNECTION ESTABLISHMENT COMMAND message defined in TS 24.572.
[0020] Assuming UE 102 can accept the connection establishment request, UE may establish a secure connection (e.g., an LCS secure connection) with LMF 104. In some embodiments, establishing the secure connection may include: 1) establishing a PDU session for providing connectivity service between UE 102 and LMF 104 if such a PDU session is not already available; 2) using the established or previously established PDU session to establish a TCP connection between UE 102 and LMF 104; 3) using the established TCP connection to establish a TLS connection between UE 102 and LMF 104; and 5) performing a location services user plane (LCS-UP) binding procedure as described in TS 24.572 (e.g., the UE initiates the LCS-UP connection binding procedure by sending, over the secure connection, the LCS-UP CONNECTION BINDING REQUEST message to the LMF, where the UE generates the LCS- UP CONNECTION BINDING REQUEST message according to clause 10.2.3 of TS 24.572, and includes the LCS-UP binding ID included int the connection establishment request message m202).
[0021] Once the secure connection (e.g. LCS secure connection) is established between UE 102 and LMF 104, UE 102 can use the secure connection to send LCS-UPP messages to LMF 104, and, likewise, LMF 104 can use the secure connection to send LCS-UPP messages to UE 102, as illustrated in FIG. 2.
[0022] Also, after receiving connection establishment request message m202, UE 102 transmits to LMF 104 a response message m204. This response message may be 1) the USER PLANE CONNECTION ESTABLISHMENT COMPLETE message defined in TS 24.572 if theconnection establishment request can be accepted or 2) the USER PLANE CONNECTION ESTABLISHMENT FAILURE message defined in TS 24.572 if the connection establishment request cannot be accepted.
[0023] As noted above, UE 102 establishes a TCP connection with LMF 104. For example, UE 102 establishes a TCP connection with an LCS-UPP service 290 (e.g., an LCS-UPP server application) provided by LMF 104. The LMF 104 (e.g., the LCS-UPP service 290 of LMF 104) is configured to listen for TCP packets (e.g., TCP connection requests, which are also known as TCP SYN packets) comprising a particular TCP port number in the destination port field of the TCP packet. Accordingly, to establish the TCP connection, UE 102 must obtain the particular TCP port number on which the LMF 104 is listening and include this TCP port number in the TCP connection request. More specifically, the TCP connection request includes a TCP header and UE 104 must include the particular TCP port number in the destination port field of the TCP header or otherwise the TCP packet will not be able to be routed to the correct service. Indeed, for all TCP packets transmitted by UE 102 over the TCP connection, the TCP packet must include the particular TCP port number in the destination port filed of the TCP packet.
[0024] This disclosure introduces different mechanisms to provide UE 102 with the particular TCP port number of the LMF, to be used as destination TCP port when the UE establishes TCP connection for TLS connection for LCS-UPP. For example, a dedicated TCP port number can be allocated to the LSC-UPP service or LMF 104 can provide the UE with the particular TCP port number, thereby enabling the UE 102 to set up the LCS secure connection. As another example, the TCP port number for the LCS-UPP can be pre-configured in the LMF and the UE, however, there may be a mis-matched configuration between the UE and LMF for the roaming scenario.
[0025] In one embodiment, to allocate a dedicated TCP port number for TCP connection of TLS connection of LCS-UPP, the port number can be registered and assigned by the Internet Assigned Numbers Authority (IANA) or by 3GPP. For 3GPP assigned TCP port number, the assigned dedicated TCP port number for TCP connection for TLS connection of LCS-UPP should be documented in a 3GPP TS technical such as 3GPP TS 29.641 or a 3GPP technical report (TR) such as 3GPP TR 29.941.
[0026] In another embodiment, the LMF sends the TCP port number to be used as destination TCP port when the UE establishes TCP connection for the TLS connection of LCS- UPP, to the UE in the connection establishment request message m202. In one embodiment, the connection establishment request message m202 is modified version of the USER PLANE CONNECTION ESTABLISHMENT COMMAND defined in TS 24.572.
[0027] For example, in one embodiment, the USER PLANE CONNECTION ESTABLISHMENT COMMAND message defined in TS 24.572 is extended to include a fourth Information Element (IE), which may be named LMF LCS-UP port, as illustrated in TABLE 1 below. In one embodiment, this new LMF LC-UP port IE includes at least one TCP port number of two octets. In one embodiment, if the LMF LCS-UP address IE includes an two network addresses (e.g., an IPv4 address and an IPv6 address), then LMF LC-UP port IE includes a first TCP port number associated with the first network address and a second TCP port number associated with the second network address.TABLE 1
[0028] In another embodiment, the LMF LCS-UP port IE is not added to the USER PLANE CONNECTION ESTABLISHMENT COMMAND message, but rather the existing LMF LCS-UP address IE is used to carry the TCP port number(s) as shown below in Table 2 and Table 3 below.TABLE 24-zTABLE 3
[0029] Table 2 shows the structure of the LMF LCS-UP address IE as defined in TS 24.572 and Table 3 illustrates the semantics of the LMF LCS-UP address type field of the LMF LCS-UP address IE. As illustrated in Table 3, four new address types are defined.
[0030] FIG. 5 is a block diagram of UE 102, according to some embodiments. As shown in FIG. 5, UE 102 may comprise: processing circuitry (PC) 502, which comprises one or more processors (P) 555 (e.g., one or more general purpose microprocessors and / or one or more otherprocessors, such as an application specific integrated circuit (ASIC), field-programmable gate arrays (FPGAs), and the like); communication circuitry 548, which is coupled to an antenna arrangement 549 comprising one or more antennas and which comprises a transmitter (Tx) 545 and a receiver (Rx) 547 for enabling UE 102 to transmit data and receive data (e.g., wirelessly transmit / receive data); and a storage unit (a.k.a., “data storage system”) 508, which may include one or more non-volatile storage devices and / or one or more volatile storage devices. In embodiments where PC 502 includes a programmable processor, a computer readable storage medium (CRSM) 542 may be provided. CRSM 542 may store a computer program (CP) 543 comprising computer readable instructions (CRI) 544. CRSM 542 may be a non-transitory computer readable medium, such as, magnetic media (e.g., a hard disk), optical media, memory devices (e.g., random access memory, flash memory), and the like. In some embodiments, the CRI 544 of computer program 543 is configured such that when executed by PC 502, the CRI causes UE 102 to perform steps described herein (e.g., steps described herein with reference to the flow charts). In other embodiments, UE 102 may be configured to perform steps described herein without the need for code. That is, for example, PC 502 may consist merely of one or more ASICs. Hence, the features of the embodiments described herein may be implemented in hardware and / or software.
[0031] FIG. 6 is a block diagram of a network node 600, according to some embodiments, which can be used to implement the LMF described herein. In embodiments where LMF consists of software, network node 600 may run (or execute a virtual machine that runs) the LMF. As shown in FIG. 6, network node 600 may comprise: processing circuitry (PC) 602, which comprises one or more processors (P) 655 (e.g., one or more general purpose microprocessors and / or one or more other processors, such as an application specific integrated circuit (ASIC), field-programmable gate arrays (FPGAs), and the like), which processors may be co-located in a single housing or in a single data center or may be geographically distributed (e.g., network node 600 may be a distributed, cloud computing system comprising two or more computers or a monolithic computing system consisting of a single computer); at least one network interface 648 (e.g., a physical interface or air interface) comprising a transmitter (Tx) 645 and a receiver (Rx) 647 for enabling network node 600 to transmit data to and receive data from other nodes connected to network 110 (e.g., an Internet Protocol (IP) network) to which network interface 648 is connected (physically or wirelessly) (e.g., network interface 648 may becoupled to an antenna arrangement comprising one or more antennas for enabling network node 600 to wirelessly transmit / receive data); and a storage unit (a.k.a., “data storage system”) 608, which may include one or more non-volatile storage devices and / or one or more volatile storage devices. In embodiments where PC 602 includes a programmable processor, a computer readable storage medium (CRSM) 642 may be provided. CRSM 642 may store a computer program (CP) 643 comprising computer readable instructions (CRI) 644. CRSM 642 may be a non-transitory computer readable medium, such as, magnetic media (e.g., a hard disk), optical media, memory devices (e.g., random access memory, flash memory), and the like. In some embodiments, the CRI 644 of computer program 643 is configured such that when executed by PC 602, the CRI causes network node 600 to perform steps described herein (e.g., steps described herein with reference to the flow charts). In other embodiments, network node 600 may be configured to perform steps described herein without the need for code. That is, for example, PC 602 may consist merely of one or more ASICs. Hence, the features of the embodiments described herein may be implemented in hardware and / or software.
[0032] Summary of Various EmbodimentsAl. A method (300) performed by a user equipment, UE, for use establishing a connection with a location management function, LMF, the method comprising: receiving (s302) from the LMF a connection establishment request message, wherein the connection establishment request message carries a port number; and obtaining (s304) the port number from the received connection establishment request message.A2. The method of embodiment Al, wherein the method further comprises using (s306) the obtained port number to establish a transport layer connection (e.g., a TCP connection) with the LMF.A3. The method of embodiment Al or A2, wherein receiving the connection establishment request message comprises receiving a downlink (DL) non-access stratum (NAS) transport message comprising a header portion and a payload portion, andthe connection establishment request message is contained within the payload portion of the DL NAS transport message.A4. The method of any one of embodiments A1-A3, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; a second IE of type LMF LCS-UP address; and a third IE comprising the port number.A5. The method of any one of embodiments A1-A3, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; a second IE comprising i) a first IP address or ii) a domain name; and a third IE comprising the port number.A6. The method of any one of embodiments A1-A3, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; and a second IE comprising the port number and i) a first IP address or ii) a domain name.A7. The method of embodiment A6, wherein the second IE comprises the first IP address (e.g. an IPv4 address), the second IE further comprises a second IP address (e.g. an IPv6 address), and the second IE further comprises a second port number associated with the second IP address.Bl. A computer program (543) comprising instructions (544) which when executed by processing circuitry (502) of a UE causes the UE to perform the method of any one of the above embodiments.B2. A carrier containing the computer program of embodiment Bl, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer readable storage medium (542).Cl. A method (400) performed by an LMF for enabling a UE to initiate the establishment of a connection with the LMF, the method comprising: generating (s402) a connection establishment request message, wherein the connection establishment request message carries a port number; and transmitting (s404) the connection establishment request message to the UE.C2. The method of embodiment Cl, wherein transmitting the connection establishment request message to the UE comprises transmitting to the UE a downlink (DL) non-access stratum (NAS) transport message comprising a header portion and a payload portion, and the connection establishment request message is contained within the payload portion of the DL NAS transport message.C3. The method of embodiment C2, wherein transmitting to the UE the DL NAS transport message comprises transmitting the DL NAS transport message to a management function (e.g., AMF) serving the UE, wherein the management function is configured to forward the DL NAS transport message to the UE.C4. The method of any one of embodiments C1-C4, wherein the method further comprises receiving (s406) from the UE a connection establishment request, wherein the connection establishment request comprises a header comprising a destination port field, and the port number is within the destination port field.C5. The method of any one of embodiments C1-C4, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; a second IE comprising i) a first IP address or ii) a domain name; and a third IE comprising the port number.C6. The method of any one of embodiments C1-C4, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; and a second IE comprising the port number and i) a first IP address or ii) a domain name.C7. The method of embodiment C6, wherein the second IE comprises the first IP address (e.g. an IPv4 address), the port number is associated with the first IP address, the second IE further comprises a second IP address (e.g. an IPv6 address), and the second IE further comprises a second port number associated with the second IP address.DI. A computer program (643) comprising instructions (644) which when executed by processing circuitry (602) of a network node causes the network node to perform the method of any one of the embodiments C1-C7.D2. A carrier containing the computer program of embodiment DI, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer readable storage medium (642).
[0033] While various embodiments are described herein, it should be understood that they have been presented by way of example only, and not limitation. Thus, the breadth andscope of this disclosure should not be limited by any of the above-described exemplary embodiments. Moreover, any combination of the above-described elements in all possible variations thereof is encompassed by the disclosure unless otherwise indicated herein or otherwise clearly contradicted by context.
[0034] As used herein transmitting a message “to” or “toward” an intended recipient encompasses transmitting the message directly to the intended recipient or transmitting the message indirectly to the intended recipient (i.e., one or more other nodes (e.g., an AMF) are used to relay the message from the source node (e.g., UE) to the intended recipient (e.g., LMF). Likewise, as used herein receiving a message “from” a sender encompasses receiving the message directly from the sender or indirectly from the sender (i.e., one or more nodes are used to relay the message from the sender to the receiving node). Further, as used herein “a” means “at least one” or “one or more.”
[0035] Additionally, while the processes described above and illustrated in the drawings are shown as a sequence of steps, this was done solely for the sake of illustration. Accordingly, it is contemplated that some steps may be added, some steps may be omitted, the order of the steps may be re-arranged, and some steps may be performed in parallel.
Claims
Claims1. A method (300) performed by a user equipment, UE, for use establishing a connection with a location management function, LMF, the method comprising: receiving (s302) from the LMF a connection establishment request message, wherein the connection establishment request message carries a port number; and obtaining (s304) the port number from the received connection establishment request message.
2. The method of claim 1, wherein the method further comprises using (s306) the obtained port number to establish a transport layer connection with the LMF.
3. The method of claim 1 or 2, wherein receiving the connection establishment request message comprises receiving a downlink (DL) non-access stratum (NAS) transport message comprising a header portion and a payload portion, and the connection establishment request message is contained within the payload portion of the DL NAS transport message.
4. The method of any one of claims 1-3, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; a second IE of type LMF LCS-UP address; and a third IE comprising the port number.
5. The method of any one of claims 1-3, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; a second IE comprising i) a first IP address or ii) a domain name; and a third IE comprising the port number.
6. The method of any one of claims 1-3, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; and a second IE comprising the port number and i) a first IP address or ii) a domain name.
7. The method of claim 6, wherein the second IE comprises the first IP address, the second IE further comprises a second IP address, and the second IE further comprises a second port number associated with the second IP address.
8. A computer program (543) comprising instructions (544) which when executed by processing circuitry (502) of a UE causes the UE to perform the method of any one of the above claims.
9. A carrier containing the computer program of claim 8, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer readable storage medium (542).
10. A method (400) performed by an LMF for enabling a UE to initiate the establishment of a connection with the LMF, the method comprising: generating (s402) a connection establishment request message, wherein the connection establishment request message carries a port number; and transmitting (s404) the connection establishment request message to the UE.
11. The method of claim 10, wherein transmitting the connection establishment request message to the UE comprises transmitting to the UE a downlink (DL) non-access stratum (NAS) transport message comprising a header portion and a payload portion, andthe connection establishment request message is contained within the payload portion of the DL NAS transport message.
12. The method of claim 11, wherein transmitting to the UE the DL NAS transport message comprises transmitting the DL NAS transport message to a management function serving the UE, wherein the management function is configured to forward the DL NAS transport message to the UE.
13. The method of any one of claims 10-12, wherein the method further comprises receiving (s406) from the UE a connection establishment request, wherein the connection establishment request comprises a header comprising a destination port field, and the port number is within the destination port field.
14. The method of any one of claims 10-12, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; a second IE comprising i) a first IP address or ii) a domain name; and a third IE comprising the port number.
15. The method of any one of claims 10-12, wherein the connection establishment request message comprises: a first information element, IE, indicating that the connection establishment request message is a connection establishment request message; and a second IE comprising the port number and i) a first IP address or ii) a domain name.
16. The method of claim 15, wherein the second IE comprises the first IP address, the port number is associated with the first IP address, the second IE further comprises a second IP address, andthe second IE further comprises a second port number associated with the second IP address.
17. A computer program (643) comprising instructions (644) which when executed by processing circuitry (602) of a network node causes the network node to perform the method of any one of the claims 10-16.
18. A carrier containing the computer program of claim 17, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer readable storage medium (642).
Citation Information
Patent Citations
Apparatus, method, and computer program
WO2024068542A1