An architecture for non-3GPP access to a 3GPP network based on quic

By adopting QUIC as a transport protocol for non-3GPP access in 3GPP networks, the architecture addresses IMSI spoofing and inflexibility issues, enhancing security and compatibility with cloud-native networks for advanced authentication and PDU session management.

WO2026093910A1PCT designated stage Publication Date: 2026-05-07TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2025-10-28
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

The existing 3GPP network architecture for non-3GPP access faces challenges such as IMSI spoofing risks due to clear transmission of UE identity, limited security options, and the inflexibility of IKE/IPSec protocol, along with a non-cloud-native Diameter interface, which hinders advanced authentication and network flexibility.

Method used

Implementing QUIC as a transport protocol between the UE and a non-3GPP gateway function (N3GW) for authentication and PDU session management, using HTTP/3 capsules for EAP payload and service-based interfaces to replace legacy protocols, enabling advanced security and cloud-native network architecture.

Benefits of technology

Enhances security, flexibility, and compatibility with cloud-native networks by utilizing QUIC's resilience and extensibility, reducing exposure to spoofing and improving authentication methods, while supporting seamless integration with 5G and future 6G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025060967_07052026_PF_FP_ABST
    Figure IB2025060967_07052026_PF_FP_ABST
Patent Text Reader

Abstract

A method and apparatus is provided for a wireless device for connecting to a core network via a non-third partnership project (3GPP) wireless access network wherein the method comprises after establishment of a QUIC connection over the non-3GPP wireless access network with a non-3GPP gateway function, the wireless device initiates a QUIC stream dialog with the non-3GPP gateway function for authentication of the wireless device over the QUIC connection, wherein the QUIC stream dialog includes a first QUIC stream that comprises a connect method to indicate EAP payload is to be carried over the QUIC stream dialog and the EAP payload is carried as an HTTP capsule or encapsulated in an HTTP based protocol.
Need to check novelty before this filing date? Find Prior Art

Description

An architecture for non-3GPP access to a 3 GPP network based on QUICRelated Application

[0001] This application claims the benefit of provisional patent application serial number 63 / 712782, filed on 10 / 28 / 2024, the disclosure of which is hereby incorporated herein by reference in its entirety.Technical Field

[0002] This disclosure relates generally to access to Third Generation Partnership Project, 3GPP, network over non-trusted access network.Background

[0003] An evolved Packet data gateway (ePDG) is introduced in the 3GPP 4G architecture and is used for connecting a User Equipment (UE) to the core network (Evolved Packet Core network) from an untrusted 3GPP access network such as a WLAN. The interface between UE and ePDG is based on IKE / IPsec protocol.Further, with advent of 3GPP 5G Core network, the existing ePDG is made to interwork with a Session Management Function (SMF+PGW-C) that supports interworking between 4G and 5G networks. Figure 1A shows the existing ePDG and 5G Core network (5GC) interworking network architecture.

[0004] The ePDG is connected with the 3GPP AAA / HSS which are the legacy EPC nodes. The interface between the ePDG and the AAA server is based on Diameter. The interface between the ePDG and the SMF (short for SMF+PGW-C) is based on GTP-C used in 4G networks, and the interface between the ePDG and the User Plane Function (UPF) in 5GC is based on GTP-U.

[0005] As the ePDG is connected with the AAA / HSS, the latter considered legacy EPC nodes defined within 4G scope, only EPC EAP-AKA authentication method is possible for a 5G UE connected to the interworking network via the ePDG over non-3GPP access. The UE connects to the ePDG using IKE / IPSec protocol. The UE identity, which is the IMSI, is transmitted to the ePDG in the first AUTH Request (over IKE). However the IMSI is sent in the clear which may have expose it to the risk of IMSI spoofing. The Diameter interface defined or specified between the ePDG and the 3GPP AAA / HSS is also considered a legacy standard protocol, which is not cloud native friendly.The IKE / IPSec protocol between UE and ePDG doesn't have the flexibility and advanced features such as QUIC (Quick UDP Internet Connection) .OUIC

[0006] QUIC is a UDP (User Datagram Protocol) based stream-multiplexed and secure transport protocol with integrity protected header and encrypted payload. Unlike the traditional transport protocol stack using Transmission Control Protocol (TCP), which resides in the operating system kernel, QUIC can easily be implemented in user space, i.e. in the application layer. Consequently, flexibility in terms of transport protocol evolution with implementation of new features, congestion control, deployability and adoption would be improved.QUIC is standardized by the IETF and officially published as standard IETF RFC 9000 incorporated herein by reference. QUIC is likely to become the main transport protocol in the Internet's for user plane traffic. It is expected that most applications running today over HTTP / HTTPS will migrate to QUIC, driven by latency improvements and stronger security. Notably, compared to HTTPS, encryption in QUIC covers both the transport protocol headers as well as the payload, as opposed to TLS over TCP, e.g. HTTPS, which protects only the payload, hence improving security over the traffic. Summary

[0007] The embodiments of the present disclosure propose a method performed by a wireless device for connecting to a core network via a non-third partnership project (3GPP) wireless access network, the method comprises the step of after establishing of a QUIC connection over the non-3GPP wireless access network with a non-3GPP gateway function, the wireless device initiates a QUIC stream dialog with the non-3GPP gateway function for authentication of the wireless device over the QUIC connection wherein the QUIC stream dialog includes a first QUIC stream that comprises a connect method to indicate Extended Authentication Protocol (EAP) payload is to be carried over the QUIC stream dialog where the EAP payload includes the authentication method to be carried out, such as EAP-AKA authentication and wherein the EAP payload is carried in a HyperText Transfer Protocol ( HTTP) capsule or the EAP payload is encapsulated in an HTTP based protocol.

[0008] For example, the connect method to indicate EAP payload is included in a protocol header.

[0009] In an embodiment, the wireless device selects the non-3GPP gateway function based on whether the N3GW supports QUIC and the wireless device selects it to be used to connect to the core network over the non-3GPP access network.When the UE want to establish a PDU session, the wireless device performs the step of transmitting in a QUIC stream an HTTP request or an HTTP capsule in a subsequent QUIC stream to the non-3GPP gateway function to request establishment of a Packet Data Unit (PDU) session with the core network, wherein the HTTP request or the HTTP capsule includes one or more parameters comprising at least one of: a Data network name, a network slice, a PDU session ID, a Domain name Server (DNS) configuration request, a proxy Call Session Control function (CSCF) configuration request, an IP address configuration request, an N1 mode and a 6G mode. Each of the one or more parameters may be carried in an HTTP capsule.

[0010] In one aspect, when the PDU session is successfully established in the core network, the method further comprises the step of receiving by the wireless device in a QUIC stream from the Non-3GPP gateway function in response to the request for establishment of the PDU session, at least one of an IP address assigned to wireless device, a PCSCF configuration information, a DNS configuration information and a User Plane IP proxy for uplink (UL) user plane (UP) traffic forwarding. The parameters may be included in an HTTP capsule.

[0011] For example, the wireless device further receives in a QUIC stream (either a new QUIC stream or the QUIC stream carrying the result of the PDU session establishment) one or more QoS flows to be setup for the PDU session including the QoS rules to be used for UL UP traffic mapping, and QFI identifying each of the QoS flow to be setup. The one or more QoS flows to be setup may be included in an HTTP Request or HTTP capsule. The wireless device then establishes a QUIC connection per QoS flow with the Non-3GPP gateway function. When UL UP traffic is to be transmitted, the wireless device maps the UL UP traffic to the QOS flow / QUIC connection based on the associated QoS rules.

[0012] For example, establishing a QUIC connection per QoS flow includes sending a connection identifier for each QUIC connection to be established to the Non-3GPP gateway function and may also include sending the QFI of the associated QoS flow.

[0013] In accordance with an embodiment, a wireless device adapted to perform any of the embodiments herein is provided.

[0014] In another embodiment, a wireless device comprising one or more processors and memory comprising instructions which when executed by the one or processors cause the wireless device to perform any of the embodiments herein is provided.In accordance with an embodiment, a method performed by a network function for connecting a wireless device to a core network via non- third partnership project (3GPP) wireless access network is provided. The method comprises the step of subsequent to establishment of a QUIC connection with the wireless device, establishing a QUIC stream dialog with the wireless device for performing authentication of the wireless device over the QUIC connection, wherein the QUIC stream dialog includes a first QUIC stream received from the wireless device which includes a connect method to indicate Extended Authentication Protocol (EAP) payload is to be carried over the QUIC stream dialog and wherein the EAP payload is carried in a Hypertext Transfer Protocol (HTTP) capsule or encapsulated in a new HTTP based protocol.The connect method to indicate EAP payload may be included in a protocol header of the QUIC protocol.

[0015] For example, the EAP payload comprises authentication methods to authenticate the wireless device such as EAP-AKA payload. But other EAP supported authentication method are not excluded. The network function performs authentication of the wireless device within the QUIC stream dialog by invoking authenticating service over a service based interface with an Authentication Service Function (AUSF).In one aspect, the method further comprises the step of receiving from the wireless device an HTTP request or an HTTP capsule in a subsequent QUIC stream requesting establishment of a Packet Data Unit (PDU) session with the core network, wherein the HTTP request or the HTTP capsule includes one or more parameters comprising at least one of: a Data network name, a network slice, a PDU session ID, a Domain name Server (DNS) configuration request, a proxy Call Session Control function (CSCF) configuration request, an IP address configuration request, an N1 mode and a 6G mode.

[0016] For example, each of the one or more parameters are carried in an HTTP capsule.

[0017] If the request is accepted, the method further comprises selecting a session management function (SMF) for the PDU session and requesting the selected SMF to establish the requested PDU session over a SBI interface using an HTTP request to allow the SMF to process the request to setup the PDU session and selects a user plane function. If the SMF accepts the request, it determines the parameters it needs to sendto the wireless device which it sends to the network function for transmission to the wireless device.

[0018] In one aspect, the method comprises transmitting to the wireless device in response to the request for establishment of the PDU session, in a QUIC stream at least one of an IP address assigned to wireless device, a PCSCF configuration information, a DNS configuration information and a User Plane IP proxy for uplink (UL) user plane (UP) traffic forwarding as obtained from the SMF.

[0019] In one aspect, the method comprises the step of transmitting in a QUIC stream one or more QoS flows to be setup for the PDU session, including QoS rules to be used for UL UP traffic mapping, and one or more QFIs identifying corresponding one or more QoS flows of the one or more QoS flows to be setup and establishing a QUIC connection per QoS flow with the wireless device as well as forwarding user plane traffic between the wireless device and a user plane function.For example, establishing a QUIC connection comprises receiving a request for a QUIC connection comprising a connection identifier and may comprise the QFI of the QoS flow.

[0020] In one aspect, a network node configured to perform the method of any one of the embodiments herein is provided.

[0021] In another aspect, a network node comprising one or more processors and memory comprising instructions which when executed by the one or more processors enable the network node to perform the method of any one of the embodiments herein is provided.

[0022] In yet another aspect, a computer readable memory comprising instructions which when executed by one or more processors of one or more servers configures the one or more servers of any one of the embodiments herein is provided.Brief Description of the Drawings

[0023] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.

[0024] Figure 1 illustrates one example of a cellular communications system 100 in which embodiments of the present disclosure may be implemented;

[0025] Figure 1A illustrates 5GC and ePDG interworking network architecture.

[0026] Figures 2 and 3 illustrate example embodiments of the cellular communication system of Figure 1 and 1A;

[0027] Figure 4 illustrates an architecture for non-3GPP access in accordance with the present disclosure;

[0028] Figure 5A is a sequence diagram of an access to the core network using the architecture in Figure 4 in accordance with the present disclosure;

[0029] Figure 5B illustrates different options for User plane connections between the wireless device and the User plane function.

[0030] Figure 6 is a flow chart of a method executed in a wireless device in accordance with embodiments of the present disclosure;

[0031] Figures 7, 8, and 9 are schematic block diagrams of example embodiments of a network node.

[0032] Figures 10, and 11 are schematic block diagrams of example embodiments of a wireless device.Technical Description

[0033] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.

[0034] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein, the disclosed subject matter should not be construed as limited to only the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0035] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step,etc., unless explicitly stated otherwise. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or where it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may apply to any other embodiments, and vice versa. Other objectives, features, and advantages of the enclosed embodiments will be apparent from the following description.

[0036] Radio Node: As used herein, a "radio node" is either a radio access node or a wireless communication device.

[0037] Radio Access Node: As used herein, a "radio access node" or "radio network node" or "radio access network node" is any node in a Radio Access Network (RAN) of a cellular communications network that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., a New Radio (NR) base station (gNB) in a Third Generation Partnership Project (3GPP) Fifth Generation (5G) NR network or an enhanced or evolved Node B (eNB) in a 3GPP Long Term Evolution (LTE) network), a 6G base station, a high- power or macro base station, a low-power base station (e.g., a micro base station, a pico base station, a home eNB, or the like), a relay node, a network node that implements part of the functionality of a base station (e.g., a network node that implements a gNB Central Unit (gNB-CU) or a network node that implements a gNB Distributed Unit (gNB-DU)) or a network node that implements part of the functionality of some other type of radio access node.

[0038] Core Network Node: As used herein, a "core network node" is any type of node in a core network or any node that implements a core network function. The node can be a server or system of distributed servers. Some examples of a core network node include, e.g., a User Plane Function (UPF), a Session Management Function (SMF), an interworking session management (SMF+PGW-C), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Function (NF) Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), an ePDG. The Core network functions may be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g., a cloud infrastructure.

[0039] Other future core network functions in future core networks such as 6G and beyond are also applicable for this invention.

[0040] Communication Device: As used herein, a "communication device" is any type of device that has access to an access network. Some examples of a communication device include, but are not limited to: mobile phone, smart phone, sensor device, meter, vehicle, household appliance, medical appliance, media player, camera, or any type of consumer electronic, for instance, but not limited to, a television, radio, lighting arrangement, tablet computer, laptop, or Personal Computer (PC). The communication device may be a portable, hand-held, computer-comprised, or vehiclemounted mobile device, enabled to communicate voice and / or data via a wireless or wireline connection.

[0041] Wireless Communication Device: One type of communication device is a wireless communication device, which may be any type of wireless device that has access to (i.e., is served by) a wireless network (e.g., a cellular network). Some examples of a wireless communication device include, but are not limited to: a User Equipment device (UE) in a 3GPP network supporting 3GPP radio (e.g., LTE, NR, 6G), and / or non-3GPP (e.g., WiFi). The wireless communication device may also be a Machine Type Communication (MTC) device, and an Internet of Things (loT) device. Such wireless communication devices may be, or may be integrated into, a mobile phone, smart phone, sensor device, meter, vehicle, household appliance, medical appliance, media player, camera, or any type of consumer electronic, for instance, but not limited to, a television, radio, lighting arrangement, tablet computer, laptop, or PC. The wireless communication device may be a portable, hand-held, computer-comprised, or vehicle-mounted mobile device, enabled to communicate voice and / or data via a wireless connection.

[0042] Network Node: As used herein, a "network node" is any node that is either part of the RAN or the core network of a cellular communications network / system.

[0043] Note that the description given herein focuses on a 3GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.

[0044] Note that, in the description herein, reference may be made to the term "cell"; however, particularly with respect to 5G NR concepts, beams may be usedinstead of cells and, as such, it is important to note that the concepts described herein are equally applicable to both cells and beams.

[0045] Figure 1 illustrates one example of a cellular communications system 100 in which embodiments of the present disclosure may be implemented. In the embodiments described herein, the cellular communications system 100 is a 5G system (5GS) including a Next Generation RAN (NG-RAN) and a 5G Core (5GC); however, the present disclosure is not limited thereto. The system may also be a 6G system connecting to 6G RAN and a core network supporting 6G UEs. In this example, the RAN includes base stations 102-1 and 102-2, which in the 5GS include NR base stations (gNBs) and optionally next generation eNBs (ng-eNBs) (e.g., LTE RAN nodes connected to the 5GC), controlling corresponding (macro) cells 104-1 and 104-2. The base stations 102-1 and 102-2 are generally referred to herein collectively as base stations 102 and individually as base station 102. Likewise, the (macro) cells 104-1 and 104-2 are generally referred to herein collectively as (macro) cells 104 and individually as (macro) cell 104. The RAN may also include a number of low power nodes 106-1 through 106-4 controlling corresponding small cells 108-1 through 108-4. The low power nodes 106-1 through 106-4 can be small base stations (such as pico or femto base stations) or RRHs, or the like. Notably, while not illustrated, one or more of the small cells 108-1 through 108-4 may alternatively be provided by the base stations 102. The low power nodes 106-1 through 106-4 are generally referred to herein collectively as low power nodes 106 and individually as low power node 106. Likewise, the small cells 108-1 through 108-4 are generally referred to herein collectively as small cells 108 and individually as small cell 108.

[0046] The cellular communications system 100 may in addition to including 3GPP base stations, also include some WiFi hotspots to provide UEs with access to the Core network using non-3GPP access networks such as WiFi access technology.

[0047] The base stations 102 and the low power nodes 106 provide service to wireless communication devices 112-1 through 112-5 in the corresponding cells 104 and 108. The wireless communication devices 112-1 through 112-5 are generally referred to herein collectively as wireless communication devices 112 and individually as wireless communication device 112. In the following description, the wireless communication devices 112 are oftentimes UEs and as such sometimes referred to herein as UEs 112, but the present disclosure is not limited thereto.

[0048] The ePDG in architecture 1A (prior art) includes control and User plane functionality.The functionality of the ePDG for supporting untrusted non-3GPP access is currently specified in 3GPP TS 23.402 as comprising the following functions:Functionality for transportation of a remote IP address as an IP address specific to a Packet Data Network, PDN, when S2b (S2b-c / S2b-u) interface is used;Routing of packets from / to PGW-U to / from UE;Routing of downlink packets towards the IPsec SA associated to the PDN connection.De-capsulation / Encapsulation of packets for IPSec and, if network based mobility (S2b (S2b-c / S2b-u)) is used;Tunnel authentication and authorization (termination of IKEv2 signalling and relay via Authentication, Authorization and Accounting, AAA messages);When the UE and the ePDG supports the establishment of a separate IPsec SA per s2b-u bearer:Establishing, where applicable, a new IPsec SA between ePDG and UE over SWu for every new dedicated bearer if the UE supports multiple IPsec SAs per PDN connection.Maintaining binding between EPC bearer ID and IPsec SA, where applicable. The default bearer maps to the initial IPsec SA.

[0049] Figure 2 illustrates a wireless communication system represented as a 5G network architecture or potentially a network architecture supporting not only 5G UEs but also 6G UEs where the core network is augmented with 6G functionality. The wireless system is also represented in the interworking architecture of Figure 1A. The wireless communication system of Figure 2 (partly represented in Figure 1A) is composed of core Network Functions (NFs), where interaction between any two NFs is represented by a point-to-point reference point / interface. Figure 2 can be viewed as one particular implementation of the system 100 of Figure 1. The embodiments in the reminder of these document are described within the context of the network architecture of Figure 2.

[0050] Reference point representations of the 5G network architecture are used to develop detailed call flows in the normative standardization. The N1 reference point is defined to carry signaling between the UE 112 and AMF 200. The reference points forconnecting between the AN 102 and AMF 200 and between the AN 102 and UPF 214 are defined as N2 and N3, respectively. There is a reference point, Nil, between the AMF 200 and SMF 208, which implies that the SMF 208 is at least partly controlled by the AMF 200. N4 is used by the SMF 208 and UPF 214 so that the UPF 214 can be set using the control signal generated by the SMF 208, and the UPF 214 can report its state to the SMF 208. N9 is the reference point for the connection between different UPFs 214. N15 and N7 are defined since the PCF 210 applies policy to the AMF 200 and SMF 208, respectively. N12 is required for the AMF 200 to perform authentication of the UE 112. N8 and N10 are defined because the subscription data of the UE 112 is required for the AMF 200 and SMF 208.

[0051] The network of Figure 2 aims at separating UP and CP. The UP carries user traffic while the CP carries signaling in the network. In Figure 2, the UPF 214 and UPF+PGW-U are UP functions. NFs, such as the AMF 200, SMF 208, PCF 210, NSSF 202, AUSF 204, SMF+PGW-C and UDM 206, are Control Plane (CP) function. Separating the UP and CP guarantees each plane resource to be scaled independently. It also allows UPFs to be deployed separately from CP functions in a distributed fashion. In this architecture, UPFs may be deployed very close to UEs to shorten the Round Trip Time (RTT) between UEs and data network for some applications requiring low latency.

[0052] The 5G core network architecture is composed of modularized functions. For example, the AMF 200, SMF 208 and for example SMSF 220 are independent functions in the CP. Separated AMF 200 and SMF 208 allow independent evolution and scaling. Other CP functions like the PCF 210 and AUSF 204 can be separated as shown in Figure 2. Modularized function design enables the 5GC network to support various services flexibly.

[0053] Each NF interacts with another NF directly. It is possible to use intermediate functions to route messages from one NF to another NF. In the CP, a set of interactions between two NFs is defined as service so that its reuse is possible. This service enables support for modularity. The UP supports interactions such as forwarding operations between different UPFs.

[0054] Figure 3 illustrates a network architecture of Figure 2 using service-based interfaces between the NFs in the CP, instead of the point-to-point reference points / interfaces used in the network architecture of Figure 2. However, the NFs described above with reference to Figure 2 correspond to the NFs shown in Figure 3.The service(s) etc. that a NF provides to other authorized NFs can be exposed to the authorized NFs through the service-based interface. In Figure 3 the service based interfaces are indicated by the letter "N" followed by the name of the NF, e.g. Namf for the service based interface of the AMF 200 and Nsmf for the service based interface of the SMF 208, etc. Any NFs depicted in Figure 2 can interact with the NEF 216 and / or NRF 218 of Figure 3 as necessary, though not explicitly indicated in Figure 2.

[0055] In 5G, 2 options are specified to access the core network via non-3GPP access (e.g., WLAN). In the first option, the standard specifies a common NAS layer that the 5G UE could use to access the core network via 3GPP access network and / or non-3GPP access network, i.e., a 5G UE could support and use NAS protocol to access the core network over 3GPP access and can also use NAS with IKE / IPSec over WiFi to access the same core network (where IKE / IPsec is setup between an N3IWF and the UE, and the UE uses NAS over IPsec to register with an AMF in the core network. For the second option, a UE that supports 3GPP radio (e.g., 5G and 4G) and WiFi would use NAS protocol to access the core network the 3GPP radio protocol over the 3GPP radio but uses IKE / IPSec over WiFi without NAS to access the core network as described 3GPP TS 23.402 or 3GPP TS 23.502.

[0056] Some properties of the NFs shown in Figures 1A, 2 and 3 may be described in the following manner. The AMF 200 provides UE-based authentication, authorization, mobility management, etc. SMF 208 is responsible for session management and allocates Internet Protocol (IP) addresses to UEs. The SMF 208 may also be an interworking SMF+PGW-C supporting session managements of UEs supporting 5G and 4G 3GPP radio access technology, but the SMF 208 is also used by UEs between 3GPP and non-3GPP radio access technology such WiFi when the UE does not use NAS over the non-3GPP radio access technology / WiFi. The SMF 208 or SMF+PGW-C also selects and controls the UPF 214 or UPF+PGW-U for data transfer. If a UE 112 has multiple sessions, different SMFs 208 may be allocated to each session to manage them individually and possibly provide different functionalities per session. The AUSF 204 supports authentication function for UEs or similar and thus stores data for authentication of UEs or similar while the UDM 206 stores subscription data of the UE 112. Many NFs including AMF 200, SMF 208 communicate with UDM 206 to obtain subscription data and / or notification of UE availability for reachability. The Data Network (DN) which is not part of the network of Figure 2 or 3, is either an Internet or anoperator data network providing services to UEs (e.g., voice services or other user services).

[0057] Currently, UEs deployed in the market do not support using NAS layer protocol over WiFi to access core network services on the non-3GPP access network. Support of NAS over non-3GPP networks is a new functionality added in 5G standards(3GPP TS 23.502). Prior to 5G, UEs do not use NAS over non-3GPP access networks to access the core network and with deployment of interworking 5G and 4G networks, UEs continue to use IKE / IPSec to connect to an evolved packet data gateway (ePDG) (specified in 4G standard), the later connects to a 4G PGW or to an interworking 5G / 4G entity, i.e., SMF+PGW-C (for control) and UPF+PGW-U (for User plane) using GTP-C protocol over S2b as illustrated in Figure 1A. The E-PDG connects to the SMF+PGW-C to enable IP connectivity service to the UE. As stated in the introduction, there currently exist certain challenges with the above architecture illustrated in Figure 1A, mainly the ePDG is connected to a AAA / HSS which is a legacy EPC node using Diameter protocols. Only EPC EAP-AKA authentication is possible for a 5G UE using WiFi to connect with an ePDG over non-3GPP access, hence limiting the security options / methods the operator can use to authenticate the UE. The UE identity, IMSI, is also transmitted to the ePDG in the first IKE AUTH Request (in the clear) which may expose the IMSI to spoofing. The Diameter interface between the ePDG and the AAA / HSS is a legacy protocol that is not cloud native friendly, which is based on services / microservices principles. Operators are upgrading their networks to a cloud friendlier architecture such as the service based architecture specified in 5G or 6G. Operators may prefer to upgrade their network and consolidate functionalities between 5G and 4G. Note that 5G is used as an example to explain the embodiments herein, but it is apparent that the embodiments herein can be applied to a 6G UE and a 6G service based interface network or beyond).

[0058] In addition, the IKE / IPSec protocol used between the UE 112 and the ePDG as described in 3GPP TS 23.402 or TS 24.402 doesn't have the flexibility and advanced features that a protocol such as QUIC provides.

[0059] Certain aspects of the present disclosure and their embodiments may provide solutions to the aforementioned or other challenges. Embodiments of the solutions described herein enable an interworking security gateway, referred herein as N3GW (non-3GPP gateway) which is an enhanced ePDG or an enhanced N3IWF (specified in5G) or a new network function to provide to a UE access to the core network using QUIC protocol.

[0060] According to the embodiments, QUIC is proposed to replace IKE / IPSec. QUIC is therefore used between the UE 112 and the N3GW, and the EAP payload for non- 3GPP access authentication will be carried by QUIC. In addition, the 3GPP PDU session management related parameters and the signaling procedures to setup or modify or terminate a PDU session between the UE and the core network will also be carried over QUIC.

[0061] With Diameter and GTP-C proposed to be replaced by the service based interface APIs as described in 5G service based architecture, the non-3GPP access authentication, authorization and the PDU Session management procedure signaling will be carried by HTTP protocol.

[0062] The embodiment in the present disclosure removes the dependency on legacy EPC components such as AAA and HSS. It enables more advanced security and authentication mechanism and provides a unified network architecture based on Service based interfaces, enabling a future proof network architecture for non-3GPP access for 5G or 6G UEs connecting to one core network over the non-3GPP access network (WLAN).

[0063] The use of a QUIC-based interface between the UE 112 and N3GW for non- 3GPP access has several advantages over legacy IKE / IPsec beyond just holding a great promise for the next generation Internet transport landscape:- QUIC operates on top of UDP and typically works seamlessly over existing network infrastructures.- QUIC is resilient to NAT rebinding and can survive changes to IP-addresses and ports.- QUIC is a highly extensible protocol and supports arbitrary application layer protocols. In particular, the use of HTTP3 allows for flexible additions of new functionality, including various types of tunnelling and proxy modes.- Access Traffic Steering-Switching-Splitting (ATSSS), in which both 3GPP access and non-3GPP access are used simultaneously, specifies steering modes that use QUIC end-to-end between UEs and UPFs, using aQUIC / HTTP3 based interface between UE and non-3GPP gateways enables optimizations for avoiding double encryption.- Obfuscation - It is possible to make QUIC over HTTP3 to look like any generic web traffic which makes it more difficult to track and target specific non-3GPP access traffic (e.g., mission critical).

[0064] Figure 4 illustrates a network architecture for non-3GPP interworking evolution in accordance with the present disclosure.Considering the long-term evolution for 6G, the standard may define a new name for the ePDG function. Herein, we use the name N3GW (non-3GPP Gateway) to refer to such an evolution so as to distinguish the GW from the legacy ePDG function.The Diameter interface between the ePDG and the AAA / HSS is replaced by a SB I protocol between the N3GW and the AUSF / UDM, which are NFs specified in 5G architecture (3GPP TS 23.501 ). The N3GW connects to the SMF based on a new SBI interface for PDU session management procedures.

[0065] To support roaming, the N3GW may be located either in the Visited PLMN (VPLMN) or the Home PLMN (HPLMN) based on operators' deployment. The SMF may be located in the VPLMN or the HPLMN depending on whether local breakout (LBO) or Home Routed (HR) deployment is used.Note that as 6G network evolution has not been defined completely, we use legacy names for NFs, such as AMF, SMF and so on. When 3GPP standard for 6G is defined, there may be new names defined for the relevant access management and session management functions. But the general principles still apply.Similarly to architectures that support core network access via the ePDG or the N3IWF, the UE which supports N3GW can be configured with an N3GW identifier by the HPLMN. The UE can also support the additional parameters as specified in 6.3.6 of TS 23.501 to build an N3GW FQDN for DNS discovery in order to select a N3GW.Similar to N3IWF configuration in current 3GPP 5G standard (TS 24.526, clause 4.3.3) it's assumed that the extended Home N3GW identifier and Slice-specific N3GW prefix configuration can be pre-configured in the UE or may be provisioned in the UE from a Policy Control Function (PCF).Figure 5A illustrates a sequence diagram of a UE initial access over non-3GPP access network (e.g., WLAN) in accordance with present disclosure.Step 1~4. After selecting the N3GW server or gateway, the UE establishes a QUIC connection with the N3GW. QUIC is specified in RFC9000. The UE starts by sending aQUIC packet of type Initial, comprising a DCID=Destination Connection ID, a SCID=Source Connection ID and containing a CRYPTO frame carrying the ClientHello. The N3IW server / gateway responds with an Initial packet comprising a DCID=Destination Connection ID, SCID=Source Connection ID and containing a CRYPTO frame carrying the ServerHello. Both the UE and the N3GW exchange a 1- RTT QUIC packet that includes the connection ID established during the handshake. Step 5~7. The UE opens a new QUIC stream with the payload of EAP- Response / ldentity including SUCI as the UE ID. A new connect method needs to be defined for QUIC protocol to carry EAP payload and other messages over non-3GPP access. The content of the QUIC Stream is illustrated in the Figure step 5. For example the content of the QUIC stream in step 5 includes: :method = CONNECT :Protocol=connect-xxx / 3GPP-xxx :scheme=https :authority=n3gw-proxy.org :path= / well-known / masque / ip / n3gw-proxy.org / portStep 8. the N3GW initiates the access authentication towards AUSF.Step 9~14. UE access authentication procedure with EAP payload over QUIC is carried out. The EAP payloads (EAP Request / EAP Response) can be carried as HTTP / 3 Capsule or encapsulated in a new HTTP based protocol over QUIC. Upon successful EAP authentication, the UE and the N3GW shall generate the credential for user plane QUIC connections based on the EAP authentication keying material.Step 15. the UE sends in a QUIC stream towards the N3GW an HTTP Request or an HTTP capsule to initiate a PDU session creation procedure in the core network with the UE over the non-3GPP access. The HTTP request or capsule includes any of the following parameters, such as UE ID, DNN, S-NSSAI, PDU Session ID, UE IP address type (IPv4 or IPv6), DNS and P-CSCF configuration request, N1_M0DE capability, 6G_M0DE capability, etc. These 3GPP parameters can be carried as HTTP / 3 Capsule or encapsulated in a new HTTP based protocol over QUIC.Step 16~23. The N3GW retrieves the UE subscription info from the User Data management function (UDM) where the UE subscription info includes subscribed network slices, Access-mobility subscription data (similar to what a 5G AMF obtains from the UDM as specified in TS 23.502), smf selection info to be used by the N3GW to select an appropriate SMF for the PDU session establishment.Step 24. The N3GW triggers an SM context creation request towards the selected SMF. The SM context creation request should include any of the following parameters: SUPI, DNN, PDU Session ID, S-NSSAI, UE IP address request, DNS and P-CSCF configuration request for UE and QUIC credential for UP (if the user plane QUIC connection bypass N3GW). This SM context create request may be a new service operation defined for the SMF or an update of the existing service operation specified in the current 5G standard, mainly 3GPP TS 23.502. In addition, the N3GW may select an SMF based on criteria such as support for access via QUIC protocol.Step 25. The SMF processes the request, and selects a UPF for the PDU session. The SMF may select a UPF that supports wireless device accessing the core network over QUIC. The selected UPF may further be selected based on whether it supports QUIC protocol to establish QUIC connections per QoS flow with the N3GW or to the wireless device. The SMF sends an SM context created to the N3GW comprising any one of the assigned UE IP address, DNS and P-CSCF configuration info and UP information (IP address, GTP tunnel ID(s) for the PDU session if user plane traffic between N3GW and UPF is carried over GTP-U, or QUIC credentials including connection IDs if user plane traffic is transmitted between the UPF and UE directly over QUIC or relayed over N3GW).Step 26. The N3GW sends to the UE over the QUIC Stream an HTTP capsule or HTTP Response based on the SM context created response received from the SMF. Example of parameters included and transmitted to the UE comprise one or more of the S-NSSAI of the PDU session, configuration information for DNS, PCSCF, UE IP address and a User plane IP proxy address to be used for user plane traffic towards the N3GW.Step 27~28. The N3GW registers itself with the UDM as an entity serving the UE over non-3GPP access. A new service operation on the SBI can be used. The registration of the N3GW may be used for Mobile terminating (MT) related procedures.Step 29~30. The N3GW may also subscribe to the UDM to receive UE subscription data update. The N3GW may use multiple subscriptions to UDM for different data sets. Step 31~36. To setup QoS flows for the established PDU session to support different applications of different QoS requirement, the SMF invokes an n3gw service to create one or more QoS flows for the PDU session. For example, the SMF transmits to the N3GW an n3gw message or information comprising an AMBR that the N3GW can enforce for the PDU session, User plane information so the N3GW can transfer the user plane traffic received at the UP IP address proxy transmitted to the UE for the PDUsession. Note that the AMBR and / or the UP IP address could be transmitted to the N3GW at step 25.The SMF may include a list of QoS flows to be setup when invoking the n3gw service (for example a service for a PDU session update). The SMF includes for each QoS flow to be setup a QFI and QoS parameters such as for example QoS rules for the QoS flow to be used by the UE for uplink traffic mapping. However the SMF may send a list of QFIs and QoS rules associated to each QFI. Once the N3GW receives the message comprising the list of QoS flow (where the list may include one or more QoS flows to be setup), the N3GW transmits the list of QoS flows to be setup list to the UE including the QFIs and the QoS parameters (e.g., QoS rules). The QoS rules include the packet filters and the QFI identifying the QoS flow over which the corresponding traffic should be mapped to. As indicated, different formatting option of the QoS flow list to be setup and the associated parameters (QFI, QoS parameters) can be used.After receiving the list of QoS flows to be setup, a single QUIC connection is established per QoS flow as illustrated in Figure 5A between steps 33 and 34. More specifically, for each QUIC connection to be established, the UE transmits to the N3GW a client Hello and receives a server Hello followed by a new connection ID being associated to the QUIC connection. The UE indicates to the N3GWfor each QUIC connection the corresponding QFI of the QoS flow. The UE repeats the process for each QoS flow in the list to be setup. Once all QUIC connections for the QoS flows are setup, the UE transmits to the N3GW at step 34 a QUIC Stream indicating the QoS flow setup is complete. The N3GW informs the SMF of the result of the PDU session update or of the establishment of the QoS flows as per the QoS flows setup request list. In one alternative, if one QoS flow of the list failed to be setup (for example, failed QUIC connection establishment), the UE may indicate the failed QoS flow to the N3GW as part of step 34, in which case it is possible for the UE to report partial success of QoS flow setup by indicating the QoS flow(s) setup successfully or the failed QoS flow(s). The N3GW informs the SMF accordingly. There is a one to one mapping between the QoS flow and the QUIC connection.When the UE has uplink data to transmit, the UE uses the obtained QoS rules to enable the UE to perform uplink data mapping to the corresponding QoS flow and to the corresponding QUIC connection and transmits the UL UP traffic to the N3GW using the UP IP address received at step 26. When the N3GW receives the UL traffic over a QUICconnection corresponding to a QoS flow, the N3GW transmits the UP traffic of the QoS flow to the UPF.Three user plane options are considered as illustrated in Figure 5B:

[0066] If GTP-U tunnel is used between the N3GW and the UPF, the N3GW marks the received UL packets in the GTP-U header with the QFI of the QoS flow based on the corresponding QUIC connection over which the UL user packets are received at the N3GW,. as the QUIC connection is dedicated to the the QoS flow. The tunnel information for the GTP-U are signaled at step 24 (for the N3GW tunnel endpoint information and step 26 (for the tunnel end point information of the UPF).For downlink traffic, the N3GW receives GTP-U packets from UPF marked with QFI, which the N3GW maps to the corresponding QUIC connection towards the UE.

[0067] If QUIC is used between the N3GW and the UPF for user plane, a QUIC connection for each QoS flow will be established in parallel to any of steps 33-34 of Figure 5A, between the N3GW and the UPF. The N3GW can trigger the establishment of each connection after receiving from the UE the request to establish the corresponding QUIC connection. It may also start establishment at step 25, however, the N3GW may need to release some or all of the connections if the UE fails to establish the corresponding QUIC connection for the QoS flow. In this option, where QUIC is used between UE-N3GW-UPF, the N3GW acts as a relay / proxy to relay traffic from one QUIC connection from the UE to the corresponding QUIC connection to the UPF. Alternatively, the N3GW can be bypassed for user plane traffic and the UE can forward the user plane traffic directly to the UPF using QUIC connections established between the UE and the UPF using a UP IP address that would be obtained by the UE from N3GW at step 26.For UL traffic, traffic for each QoS flow is transmitted over a QUIC connection all the way to the UPF either directly or proxied via the N3GW.Methods to carry 3GPP parameters between UE and N3GW

[0068] As indicated in step 15 of Figure 5A, the 3GPP parameters can be carried as HTTP / 3 Capsule extension or encapsulated in a new HTTP based protocol over QUIC between UE and N3GW. The following two methods are suggested:

[0069] Method (1) carry 3GPP parameters based on a new HTTP message, example as in the table below:

[0070] Method (2) carry 3GPP parameters based on HTTP / 3 Capsule extension. HTTP / 3 capsule mechanism is specified in RFC 9297. Examples of capsules are described below. Option 1 : The capsule extension may be defined as layer architecture with parent capsule to group the child capsules together and child capsule with detailed subparameters.Option 2: The capsule extension may be defined as flat architecture with all the parameters at the same level of capsule extensions.

[0071] Figure 6 illustrates a flow chart of a method performed by a wireless device for connecting to the core network over non-3GPP access network in accordance with the present disclosure.

[0072] The method comprises the step of after establishment of a QUIC connection with a non-3GPP gateway function, the wireless device initiating a QUIC stream dialog with the non-3GPP gateway function to perform authentication of the wireless device over the QUIC connection. The QUIC connection being established following steps 1-4 in Figure 5A. The QUIC stream dialog to perform authentication (e.g., wireless device authentication or mutual authentication) includes a first QUIC stream of the QUICK connection that comprises a connect method to indicate EAP payload to be carried over QUIC between the UE and the N3GW and where the EAP payload is carried in either an HTTP capsule or encapsulated in a new HTTP based protocol.

[0073] The connect method is a QUIC protocol header that indicates EAP payload is to be carried over QUIC.

[0074] In accordance with some embodiments, the EAP payload exchanged indicates different authentication methods carried out with the UE. An example of the EAP payload include EAP-AKA payload.

[0075] The method further comprises the step of selecting the non-3GPP gateway function (N3GW) based on QUIC capability of a gateway to connect to the core network. The UE selects the non-3GPP gateway function if one is available in the visited PLMN or home PLMN.

[0076] The method further comprises the step of transmitting in a QUIC stream an HTTP request or an HTTP capsule to the non-3GPP gateway function to request establishment of a PDU session with the core network, wherein the HTTP request or the HTTP capsule includes one or more parameters comprising at least one of: Data network name, network slice, PDU session ID, a DNS configuration request, a proxy CSCF configuration request, an IP address configuration request, an N1 mode and a 6G mode.

[0077] The one or more parameters may be carried in an HTTP capsule.

[0078] If the core network has accepted the request, the UE receives in a QUIC stream from the Non-3GPP gateway function parameters indicative of a successful PDU session establishment in the core network. The parameters include for example, the S- NSSAI, and configuration parameters such as DNS, PCSCF address, UE IP address and may include a User Plane IP proxy address or a UP IP address to be used for UL UP traffic. The parameters are included in an HTTP capsule or HTTP request.

[0079] In one example, the UE receives in a QUIC stream one or more QoS flows to be setup (e.g., a list of one or more QoS flows) for the PDU session with corresponding QoS parameters. The one or more QoS flows to be setup is included in an HTTP request or HTTP capsule. The corresponding parameters of the QoS flows to be setup include QFIs and QoS parameters such as QoS rules comprising packet filters to be used for uplink (UL) UP traffic mapping.

[0080] The wireless device may then perform the step of establishing a QUIC connection with the non-3GPP gateway function for each requested QoS flow to be setup. Each connection has a corresponding connection ID. Alternatively, the wireless device may instead receive a request, initiated by the non-3GPP gateway to setup a QUIC connection for each QoS flow the core network wants to establish for the PDU session. In other words, a QUIC connection for each QoS flow can be initiated by the wireless device as in Figure 5A or by the core network (non-3GPP gateway function).

[0081] When the UE initiates establishment of the QUIC connection for the QoS flow, it may also include the QFI in the request to identify the QoS flow for the QUIC connection, or the QFI can be included in the user plane packet header transmitted over the QUIC connection.

[0082] For example the UE establishes a QUIC connection for a QOS flow with the Non-3GPP gateway function or with the user plane function selected by the SMF.

[0083] When the UE has UL traffic to transmit towards the non-3GPP gateway function, it uses the QoS rules to map the UL user plane traffic from an application to the QoS flow, which is then mapped to the corresponding QUIC connection identified by a connection ID and optionally the QFI. The UP packets may be tagged with QFI as well to enable the Non-3GPP gateway function to perform proper routing to the UPF Further Description

[0084] Figure 7 is a schematic block diagram of a network node 1100 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The network node 1100 may be, for example, a core network node that implements a NF (e.g., one or more of the 5G network functions, or the like, as described herein). As illustrated, the network node 1100 includes a one or more processors 1104 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory 1106, and a network interface 1108. The one or more processors 1104 are also referred to herein as processing circuitry. The one or more processors 1104 operate to provide one or more functions of the network node 1100 as described herein (e.g., one or more functions of the e.g., one or more of the 5G network functions, or the like, as described herein. In some embodiments, the function(s) are implemented in software that is stored, e.g., in the memory 1106 and executed by the one or more processors 1104.

[0085] Figure 8 is a schematic block diagram of a network node corresponding to a radio access node 1100 according to some embodiments of the present disclosure. The network node being the radio access node 1100 may be, for example, a base station 302 or 306. As illustrated, the radio access node 1100 includes a control system 1102 that includes one or more processors 1104 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory 1106, and a network interface 1108. The one or more processors 1104 are also referred to herein as processing circuitry. In addition, the radio access node 1100 includes one or more radio units 1110 that each includes one or more transmitters 1112 and one or more receivers 1114 coupled to one or more antennas 1116. The radio units 1110 may be referred to or be part of radio interface circuitry. In some embodiments, the radio unit(s) 1110 is external to the control system 1102 and connected to the control system 1102 via, e.g., a wired connection (e.g., anoptical cable). However, in some other embodiments, the radio unit(s) 1110 and potentially the antenna(s) 1116 are integrated together with the control system 1102. The one or more processors 1104 operate to provide one or more functions of a radio access node 1100 as described herein. In some embodiments, the function(s) are implemented in software that is stored, e.g., in the memory 1106 and executed by the one or more processors 1104.

[0086] Figure 9 is a schematic block diagram that illustrates a virtualized embodiment of the network node 1100 according to some embodiments of the present disclosure. Again, optional features are represented by dashed boxes. As used herein, a "virtualized" network node is an implementation of the network node 1100 in which at least a portion of the functionality of the network node 1100 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). As illustrated, in this example, the network node 1100 includes one or more processing nodes 1200 coupled to or included as part of a network(s) 1202. Each processing node 1200 includes one or more processors 1204 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 1206, and a network interface 1208. In this example, functions 1210 of the network node 1100 described herein (e.g., one or more of the 5G network functions, or the like, as described herein) are implemented at the one or more processing nodes 1200 or distributed across the two or more processing nodes 1200 in any desired manner. In some particular embodiments, some or all of the functions 1210 of the network node 1100 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environ ment(s) hosted by the processing node(s) 1200.

[0087] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the network node 1100 or a node (e.g., a processing node 1200) implementing one or more of the functions 1210 of the network node 1100 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).

[0088] Figure 10 is a schematic block diagram of a UE 1000 according to some embodiments of the present disclosure. As illustrated, the UE 1000 includes one or more processors 1002 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 1004, and one or more transceivers 1006 each including one or more transmitters 1008 and one or more receivers 1010 coupled to one or more antennas 1012. The transceiver(s) 1006 includes radio-front end circuitry connected to the antenna(s) 1012 that is configured to condition signals communicated between the antenna(s) 1012 and the processor(s) 1002, as will be appreciated by on of ordinary skill in the art. The processors 1002 are also referred to herein as processing circuitry. The transceivers 1006 are also referred to herein as radio circuitry. In some embodiments, the functionality of the UE 1000 described above may be fully or partially implemented in software that is, e.g., stored in the memory 1004 and executed by the processor(s) 1002. Note that the UE 1000 may include additional components not illustrated in Figure 10 such as, e.g., one or more user interface components (e.g., an input / output interface including a display, buttons, a touch screen, a microphone, a speaker(s), and / or the like and / or any other components for allowing input of information into the UE 1000 and / or allowing output of information from the UE 1000), a power supply (e.g., a battery and associated power circuitry), etc.

[0089] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the UE 1000 according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).

[0090] Figure 11 is a schematic block diagram of the UE 1000 according to some other embodiments of the present disclosure. The UE 1000 includes one or more modules 1100, each of which is implemented in software. The module(s) 1100 provide the functionality of the UE 1000 described herein.

[0091] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry,which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according one or more embodiments of the present disclosure.

[0092] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).

[0093] While processes in the figures (flow charts, procedures) may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).

[0094] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.

[0095] Some example embodiments of the present disclosure are as follows: Embodiment 1. A method performed by a wireless device for connecting to a core network via non-3GPP wireless access network, the method comprising:- after establishment of a QUIC connection with a non-3GPP gateway function, initiating a QUIC stream dialog with the non-3GPP gateway function for authentication of the wireless device over the QUIC connection;- wherein the QUIC stream dialog includes a first QUIC stream that comprises a connect method to indicate carrying EAP payload over the QUIC stream dialog; and- wherein the EAP payload is carried in an HTTP capsule or encapsulated in a new HTTP based protocol.Embodiment 2. The method of embodiment 1 wherein the first QUIC stream that comprises a connect method to indicate carrying EAP payload over QUIC further comprises indicating the connect method of EAP in a protocol header.Embodiment 3. The method of embodiment 1 where in the EAP payload comprises EAP-AKA payload.Embodiment 4. The method of embodiment 1 further comprising selecting the non- 3GPP gateway function based on QUIC capability of a gateway to connect to the core network.Embodiment 5. The method of embodiment 1 further comprising transmitting an HTTP request or an HTTP capsule in a subsequent QUIC stream to the non-3GPP gateway function to request establishment of a PDU session with the core network, wherein the HTTP request or the HTTP capsule includes one or more parameters comprising at least one of: Data network name, network slice, PDU session ID, a DNS configuration request, a proxy CSCF configuration request, an IP address configuration request, an N1 mode and a 6G mode.Embodiment 6. The method of embodiment 5 wherein each of the one or more parameters are carried in an HTTP capsule.Embodiment 7. The method of embodiment 5 further comprising receiving a QUIC stream from the Non-3GPP gateway function which may indicate successful PDU session establishment, wherein the QUIC stream comprises one or more QoS flows to setup for the PDU session.Embodiment 8. The method of embodiment 7 further comprising establishing a QUIC connection for each requested QoS flow to be setup.Embodiment 9. The method of any of embodiments 7-8 wherein the received QUIC stream includes one or more QoS rules to map uplink traffic to the one or more QUIC connections / QoS flows.Embodiment 10. A wireless device adapted to perform any of the method embodiments 1 to 9.Embodiment 11. A wireless device comprising one or more processors and memory comprising instructions which when executed by the one or processors cause the wireless device to perform any of the method embodiments 1-9.Embodiment 12. A method performed by a network function for connecting a wireless device to a core network via non-3GPP wireless access network, the method comprising: after establishment of a QUIC connection with the wireless device, performing a QUIC stream dialog for authentication of the wireless device over the QUIC connection; wherein the QUIC stream dialog includes a first received QUIC stream from the wireless device comprises a connect method to indicate carrying EAP payload over the QUIC stream dialog; and wherein the EAP payload is carried in an HTTP capsule or encapsulated in a new HTTP based protocol.Embodiment 13. The method of embodiment 12 wherein the first received QUIC stream that comprises a connect method to indicate carrying EAP payload over QUIC further comprises indicating the connect method of EAP in a protocol header.Embodiment 14. The method of embodiment 12 where in the EAP payload comprises EAP-AKA payload.Embodiment 15. The method of embodiment 12 further comprising authenticating the wireless device as part of the QUIC stream dialog by invoking authenticating service over a service based interface with an AUSF.Embodiment 16. The method of embodiment 12 further comprising receiving an HTTP request or an HTTP capsule from the wireless in a subsequent QUIC stream requesting establishment of a PDU session with the core network, wherein the HTTP request or the HTTP capsule includes one or more parameters comprising at least one of: Data network name, network slice, PDU session ID, a DNS configuration request, a proxy CSCF configuration request, an IP address configuration request, an N1 mode and a 6G mode.Embodiment 17. The method of embodiment 16 further comprising selecting a session management function (SMF) and requesting the selected SMF to establish the requested PDU session over an SBI interface using an HTTP request.Embodiment 18. The method of embodiment 16 wherein each of the one or more parameters are carried in an HTTP capsule.Embodiment 19. The method of embodiment 12 further comprising transmitting a QUIC stream to the wireless device which may indicate successful PDU session establishment, wherein the QUIC stream comprises one or more QoS flows to setup for the PDU session.Embodiment 20. The method of embodiment 19 further comprising receiving or initiating a request for a QUIC connection for each QoS flow to be setup.Embodiment 21. The method of any of embodiments 19-21 wherein the transmitted QUIC stream includes one or more QoS rules to enable the wireless device to map uplink traffic to the one or more established QUIC connections / QoS flows.Embodiment 22. A network node configured to perform the method of any of embodiments 12-21.Embodiment 23. A network node comprising one or more processors and memory comprising instructions which when executed by the one or more processors enable the network node to perform the method of any of embodiments 12-21.Embodiment 24. A computer readable memory comprising instructions which when executed by one or more processors of one or more servers configures the one or more servers to perform any of the embodiments 12-21.

[0096] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.

Claims

Claims1. A method performed by a wireless device for connecting to a core network via a non-third partnership project (3GPP) wireless access network, the method comprising:- after establishment of a Quick UDP Internet Connections (QUIC) connection over the non-3GPP wireless access network with a non-3GPP gateway function, initiating a QUIC stream dialog with the non-3GPP gateway function for authentication of the wireless device over the QUIC connection;- wherein the QUIC stream dialog includes a first QUIC stream that comprises a connect method to indicate that Extended Authentication Protocol (EAP) payload is to be carried over the QUIC stream dialog; and- wherein the EAP payload is carried in a HyperText Transfer Protocol (HTTP) capsule or encapsulated in an HTTP based protocol.

2. The method of claim 1 wherein the connect method to indicate EAP payload is included in a protocol header.

3. The method of claim 1 wherein the EAP payload comprises EAP-AKA payload.

4. The method of claim 1 further comprising selecting the non-3GPP gateway function based on QUIC capability of a gateway to be used to connect to the core network over the non-3GPP access network.

5. The method of claim 1 further comprising transmitting in a QUIC stream an HTTP request or an HTTP capsule in a subsequent QUIC stream to the non-3GPP gateway function to request establishment of a Packet Data Unit (PDU) session with the core network, wherein the HTTP request or the HTTP capsule includes one or more parameters comprising at least one of: a Data network name, a network slice, a PDU session ID, a Domain name Server (DNS) configuration request, a proxy Call Session Control function (CSCF) configuration request, an IP address configuration request, an N1 mode and a 6G mode.

6. The method of claim 5 wherein each of the one or more parameters are carried in an HTTP capsule.

7. The method of claim 5 further comprising receiving from the Non-3GPP gateway function in response to the request for establishment of the PDU session, in a QUIC stream at least one of an IP address assigned to wireless device, a PCSCFconfiguration information, a DNS configuration information and a User Plane IP proxy for uplink (UL) user plane (UP) traffic forwarding.

8. The method of claim 1 or 5 further comprising:- receiving in a QUIC stream one or more QoS flows to be setup for the PDU session including QoS rules to be used for UL UP traffic mapping, and one or more QFIs identifying corresponding one or more QoS flows of the one or more QoS flows to be setup;- establishing a QUIC connection per QoS flow with the Non-3GPP gateway function; and- mapping UL UP traffic based on the QoS rules to the corresponding QoS flow.

9. The method of claim 8 wherein the step of establishing a QUIC connection per QoS flow comprises sending a connection identifier for each QUIC connection to be established to the Non-3GPP gateway function.

10. The method of claim 8 or 9 wherein the step of establishing a QUIC connection per QoS flow comprises transmitting the corresponding QFI of the QoS flow for each QUIC connection to be established to the Non-3GPP gateway function.

11. The method of claim 8 wherein the step of receiving comprises receiving in a QUIC stream an HTTP Request, wherein the HTTP Request comprises the one or more QoS flows to be setup including the QoS rules to be used for UL UP traffic mapping and the one or more QFIs identifying corresponding one or more QoS flows of the one or more QoS flows to be setup .

12. A wireless device adapted to perform any of the method claims 1 to 11.

13. A wireless device comprising one or more processors and memory comprising instructions which when executed by the one or processors cause the wireless device to perform any of the method claims 1-11.

14. A method performed by a network function for connecting a wireless device to a core network via non- third partnership project (3GPP) wireless access network, the method comprising:- subsequent to establishment of a Quick UDP Internet Connections (QUIC) connection with the wireless device, establishing a QUIC stream dialog with the wireless device for performing authentication of the wireless device over the QUIC connection;- wherein the QUIC stream dialog includes a first QUIC stream received from the wireless device including a connect method to indicate that Extended Authentication Protocol (EAP) payload is to be carried over the QUIC stream dialog; and- wherein the EAP payload is carried in a Hypertext Transfer Protocol (HTTP) capsule or encapsulated in a new HTTP based protocol.

15. The method of claim 14 wherein the connect method to indicate EAP payload is included in a protocol header.

16. The method of claim 14 where in the EAP payload comprises EAP-AKA payload.

17. The method of claim 14 further comprising authenticating the wireless device within the QUIC stream dialog by invoking authenticating service over a service based interface with an Authentication Service Function (AUSF).

18. The method of claim 14 further comprising receiving an HTTP request or an HTTP capsule from the wireless in a subsequent QUIC stream requesting establishment of a Packet Data Unit (PDU) session with the core network, wherein the HTTP request or the HTTP capsule includes one or more parameters comprising at least one of: a Data network name, a network slice, a PDU session ID, a Domain name Server (DNS) configuration request, a proxy Call Session Control function (CSCF) configuration request, an IP address configuration request, an N1 mode and a 6G mode.

19. The method of claim 18 wherein each of the one or more parameters are carried in an HTTP capsule.

20. The method of claim 18 further comprising selecting a session management function (SMF) for the PDU session and requesting the selected SMF to establish the requested PDU session over a SBI interface using an HTTP request.

21. The method of claim 16 further comprising transmitting to the wireless device in response to the request for establishment of the PDU session, in a QUIC stream at least one of an IP address assigned to wireless device, a PCSCF configuration information, a DNS configuration information and a User Plane IP proxy for uplink (UL) user plane (UP) traffic forwarding.

22. The method of claim 16 or 21 further comprising:- transmitting in a QUIC stream one or more QoS flows to be setup for the PDU session including QoS rules to be used for UL UP traffic mapping, andone or more QFIs identifying corresponding one or more QoS flows of the one or more QoS flows to be setup;- establishing a QUIC connection per QoS flow with the wireless device; and- forwarding user plane traffic between the wireless device and a user plane function.

23. The method of claim 22 wherein the step of establishing a QUIC connection comprises receiving a request for a QUIC connection comprising a connection identifier.

24. The method of claim 22 or 23 wherein the step of establishing a QUIC connection comprises receiving a request for a QUIC connection comprising the QFI of the QoS flow.

25. A network node configured to perform the method of any one of claims 16-24.

26. A network node comprising one or more processors and memory comprising instructions which when executed by the one or more processors enable the network node to perform the method of any one of claims 16-24.

27. A computer readable memory comprising instructions which when executed by one or more processors of one or more servers configures the one or more servers to perform any one of the claims 16-24.

Citation Information

Patent Citations

  • Service-based 5g core authentication endpoints

    US20210112409A1