Method and apparatus for secure access of a core network through non-3GPP access

WO2026167171A1PCT designated stage Publication Date: 2026-08-13KONINKLIJKE PHILIPS NV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-06
Publication Date
2026-08-13

Smart Images

  • Figure EP2026053189_13082026_PF_FP_ABST
    Figure EP2026053189_13082026_PF_FP_ABST
Patent Text Reader

Abstract

This invention describes a method and apparatus for secure access of a core network through non-3GPP access, wherein the method comprises: establishing a secure connection with the core network through 3GPP access, receiving a first configuration from the core network, receiving from the core network and / or determining a second configuration, sending a connection request message to a network function based on and / or using the first configuration and the second configuration to establish the connection, and setting up the connection with the core network through non-3GPP access.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method and apparatus for secure access of a core network through non-3GPP access

[0002] FIELD OF THE INVENTION

[0003] This invention relates to a method, apparatus, and system for providing a wireless device such as a user equipment with secure access to a core network through non-3GPP access in a wireless system such as a cellular system, a WiFi network or the like.

[0004] BACKGROUND OF THE INVENTION

[0005] In conventional cellular networks, a primary station serves a plurality of secondary stations located within a cell served by this primary station. In the context of cellular networks as standardized by 3GPP, the primary station is referred to a base station, or a gNodeB (or gNB) in 5G (NR) or an eNodeB (or eNB) in 4G (LTE). The eNB / gNB is part of the Radio Access Network RAN, which interfaces to functions in the Core Network (CN), e.g. a 4G Evolved Packet Core (EPC) or a 5G Core Network (5GC). In the same context, the secondary station corresponds to a mobile station, or a User Equipment (or a UE) in 4G / 5G, which is a wireless client device or a specific role played by such device. The term "node" is also used to denote either a UE or a gNB / eNB. In a cellular network, the wireless link between the primary station and the secondary station typically involves a cellular Radio Access Technology (RAT) such as 4G Long Term Evolution (LTE) or 5G New Radio (5G NR).

[0006] Cellular networks also can incorporate means to integrate with other wireless technologies, i.e. different Radio Access Technologies, such as Wi-Fi. For example, to enable support of IMS voice calls over Wi-Fi (non-3GPP access) when a UE is connected to EPC / 5GC. In 4G this integration involves an Evolved Packet Data Gateway deployed by the EPC. In 5G this integration involves a Non-3GPP InterWorking Function (N3IWF). However, the N3IWF is considered to be more complex. It would be beneficial to make use of the widespread ePDG deployment for non-3GPP access, not only to 4G EPC, but also 5GC or possibly even a 6G Core Network. However, it is challenging to ensure a high security level / good performance when using legacy procedures in the 5GC.

[0007] SUMMARY OF THE INVENTION

[0008] An aim of the invention is to address above problem by means of the methods in claims 1 to 13, the apparatus of claim 14, and the computer program of claim 15.It shall be understood that a preferred embodiment of the invention can also be any combination of the dependent claims or below embodiments with the respective independent claim.

[0009] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiments described hereinafter.

[0010] BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In the following drawings:

[0012] Fig. 1 schematically represents the overall cellular system including UEs, RAN, and core network;

[0013] Fig. 2 provides a schematic representation of a UE and its components; and

[0014] Fig. 3 schematically represents different entities involved in a non-terrestrial network; Fig. 4 schematically represents a random-access procedure in a wireless network; Fig. 5 schematically represents a signalling procedure by an access device; and Fig. 6 schematically represents the periodic transmission of SSB bursts; and

[0015] Fig. 7 schematically represents examples of wireless devices according to some embodiments.

[0016] DETAILED DESCRIPTION OF EMBODIMENTS

[0017] Embodiments of the present invention are now described based on a cellular communication network environment, such as 5G or 6G. However, the present invention may also be used in connection with other wireless technologies.

[0018] Throughout the present disclosure, the abbreviation "gNB" (5G terminology) or " BS" (base station) or the term "access device" is intended to mean a wireless access device such as a cellular base station or a WiFi access point or a ultrawide band (UWB) personal area network (PAN) coordinator. The gNB may consist of a centralized control plane unit (gNB-CU-CP), multiple centralized user plane units (gNB-CU-UPs) and / or multiple distributed units (gNB-DUs). The gNB is part of a radio access network (RAN), which provides an interface to functions in the core network (CN). The RAN is part of a wireless communication network. It implements a radio access technology (RAT). Conceptually, it resides between a communication device such as a mobile phone, a computer, or any remotely controlled machine and provides connection with its CN. The CN is the communication network's core part, which offers numerous services to customers who are interconnected via theRAN. More specifically, it directs communication streams over the communication network and possibly other networks.

[0019] Furthermore, the terms "base station" (BS) and "network" may be used as synonyms in this disclosure. This means for example that when it is written that the "network" performs a certain operation it may be performed by a CN function of a wireless communication network, or by one or more base stations that are part of such a wireless communication network, and vice versa. It can also mean that part of the functionality is performed by a CN function of the wireless communication network and part of the functionality by the base station.

[0020] It is further noted that throughout the present disclosure only those blocks, components and / or devices that are relevant are shown in the accompanying drawings. Other blocks have been omitted for reasons of brevity. Furthermore, blocks designated by same reference numbers are intended to have the same or at least a similar function, so that their function is not described again later.

[0021] A cellular system is a wireless communication system that consists of three main components: user equipment (UE), radio access network (RAN), and core network (CN). These components work together to provide voice and data services to mobile users over a large geographic area.

[0022] In conventional cellular networks, a primary station serves a plurality of secondary stations located within a cell served by this primary station. Wireless communication from the primary station towards each secondary station is done on downlink channels. Conversely, wireless communication from each secondary towards the primary station is done on uplink channels. The wireless communication can include data traffic (sometimes referred to User Data), and control information (also referred sometimes as signalling). This control information typically comprises information to assist the primary station and / or the secondary station to exchange data traffic (e.g. resource allocation / requests, physical transmission parameters, information on the state of the respective stations). In the context of cellular networks as standardized by 3GPP, the primary station is referred to a base station, or a gNodeB (or gNB) in 5G (NR) or an eNodeB (or eNB) in 4G (LTE). The eNB / gNB is part of the Radio Access Network RAN, which interfaces to functions in the Core Network (CN). In the same context, the secondary station corresponds to a mobile station, or a User Equipment (or a UE) in 4G / 5G / 6G, which is a wireless client device or a specific role played by such device. The term "node" is also used to denote either a UE or a gNB / eNB.

[0023] Additionally, for example, in the case of PC5 interface or Sidelink communication, it is possible to have Direct communication between secondary stations, here UEs. It is then also possiblefor UEs to operate as Relays to allow for example out of coverage UEs to get an inter-mediate (or indirect) connection to the eNB or gNB. To be able to work as a relay, a UE may use discovery messages to establish new connections with other UEs. Certain UEs may communicate with each other by using device-to-device communication, also known as sidelink communication using the PC5 interface that may rely on physical sidelink (PS) broadcast channel, PS shared channel, PS control, etc. Furthermore, the role of a relay node has been introduced in 3GPP. This relay node is a wireless communication station that includes functionalities for relaying communication between a primary station, e.g. a gNB and a secondary station, e.g. a UE. This relay function for example allows to extend the coverage of a cell to an out-of-coverage (OoC) secondary station. This relay node may be a mobile station or could be a different type of device. In the specifications for 4G, the Proximity Services (ProSe) functions are defined inter alia in TS 23.303, and TS 24.334 to enable - amongst others -connectivity for the cellular User Equipment (UE) that is temporarily not in coverage of the cellular network base station (eNB) serving the cell. This particular function is called ProSe UE-to-network relay, or Relay UE for short. The Relay UE relays application and network traffic in two directions between the OoC UE and the eNB. The local communication between the Relay UE and the OoC UE is called device-to-device (D2D) communication or Sidelink (also known as PC5) communication in TS 23.303 and TS 24.334. Once the relaying relation is established, the OoC-UE is, e.g., IP-connected via the Relay UE and acts in a role of " Remote UE". This situation means the Remote UE has an indirect network connection to selected functions of the Core Network as opposed to a direct network connection to all Core Network functions that is the normal case. Furthermore, it has been introduced the role of a UE-to-UE relay node, i.e., a relay node re-laying the communication between two UE devices. The relay node relays the communications between UE devices. UEs may connect to the core network through a base station when in-coverage. In such relay scenarios, the relay devices may receive and store some information for some time before forwarding it towards the target device. This information that may be stored and forwarded may be discovery messages received from a source UE whereby the relay UE may release them at some point of time later. This information that may be stored and forwarded may be a SIB that may contain a timestamp.

[0024] User equipment (UE) is the device that a user uses to access the cellular system, such as a smartphone, a tablet, a laptop, loT device, or a wearable device. A UE typically may contain the following components:

[0025] - A universal integrated circuit card (UICC), which stores the user's identification and authentication information, such as the subscription permanent identifier (SUPI) or credentials.- A transceiver, which converts the digital signals from the processor into analog signals for transmission and reception over the air interface. The transceiver also performs modulation, demodulation, coding, decoding, and other signal processing functions.

[0026] - A processor, which controls the operation of the UE and executes the applications and services that the user requests. The processor also communicates with the RAN and the CN using various protocols.

[0027] - A display, which shows the user the information and feedback from the UE, such as the signal strength, the battery level, the call status, the messages, the contacts, the menu, etc.

[0028] - A microphone and a speaker, which enable the user to make and receive voice calls, as well as use other audio features, such as voice mail, voice recognition, etc.

[0029] - A keyboard and / or a touch screen, which allow the user to enter and select commands, text, numbers, etc.

[0030] - A camera and / or a video recorder, which enable the user to capture and send images and videos, as well as use other multimedia features, such as video calling, video streaming, etc.

[0031] - A memory, which stores the data and programs that the user needs, such as the phone book, the messages, the photos, the videos, the applications, etc as well as a computer program to perform the operations of the RAN and CN protocols.

[0032] - A battery, which provides the power supply for the UE.

[0033] Fig. 2 provides a schematic representation of a UE and its components, e.g., UICC (201), processor (202), transceiver (203), memory (204), input devices (205) such as camera, microphone, etc and output devices (206) such as display, speaker, etc. Fig. 7 schematically represents wireless devices that may include the capabilities of a UE and / or a STA. Fig. 7a) represents AR / VR glasses; Fig. 7b) represents a connected vehicle; and Fig. 7c) represents a mobile phone. In these devices, a reflective intelligent surface (RIS) may be embedded, e.g., by covering and / or under the whole a part of the UE surface. This may be used, e.g., to better deal with interferences or improve wireless sensing.

[0034] A UE access the cellular network via the radio access network, as described below. Certain UEs may communicate with each other by using device-to-device communication, also known as sidelink communication using the PC5 interface that may rely on physical sidelink (PS) broadcast channel, PS shared channel, PS control, etc.

[0035] A UE may receive a configuration by means of different procedures:

[0036] Downlink control information (DCI) is a type of control information that is sent from the BS to the UE on the physical downlink control channel (PDCCH). DCI contains various parameters2025P00098WQ 6

[0037] that instruct the UE how / when to decode and transmit data on the physical downlink shared channel (PDSCH) and the physical uplink shared channel (PUSCH), such as the resource allocation, the modulation and coding scheme. The UE needs to monitor the PDCCH in each subframe to detect and decode the DCI that is addressed to it.

[0038] Uplink control information (UCI) is a type of control information that is sent from the UE to the BS on the physical uplink control channel (PUCCH) or the physical uplink shared channel (PUSCH). UCI contains various feedback signals that inform the BS about the status and quality of the downlink transmission, such as the HARQ. acknowledgments (ACKs), the channel state information (CSI), and the scheduling requests (SRs). The UE needs to encode and transmit the UCI according to the configuration and timing indicated by the BS.

[0039] Sidelink control information (SCI) is a type of control information that is sent from the UE to another UE on the physical sidelink control channel (PSCCH) in device-to-device (D2D) communication scenarios. The main functions of SCI include resource allocation, synchronization, channel quality reporting,.

[0040] Medium access control (MAC) control element (MAC CE) is a type of control information that is sent from the BS to the UE or vice versa on the MAC layer. MAC CE contains various commands or indications that regulate the MAC layer functions, such as the buffer status report (BSR), the timing advance command (TAC), the discontinuous reception (DRX) command, etc. The UE needs to process the MAC CE according to the MAC protocol and the configuration provided by the BS.

[0041] Radio resource control (RRC) command is a type of control information that is exchanged between the BS and the UE on the RRC layer. RRC Command contains various messages that modify / configure RRC parameters and / or initiate, modify, or release the RRC connection or the radio bearers between the UE and the BS, such as the RRC connection setup, the RRC connection reconfiguration, the RRC connection release, the security mode command, the mobility from E-UTRA command, the handover from E-UTRA preparation request, etc. The UE needs to respond to the RRC Command according to the RRC protocol and the configuration provided by the BS.

[0042] Non-access stratum (NAS) messages are used for signalling between UE and core network (CN) on the non-access stratum (NAS) layer. NAS messages enable functionality such as registration, session establishment, security, and mobility management. The UE needs to respond to the NAS Command according to the NAS protocol and the configuration provided by the CN.

[0043] UE parameter update (UPU) is a procedure between the UE and the home network that enables the home network to update configuration parameters in mobile phones and / or USIM using tthe UDM control plane procedure (TS 23.502). The UE can receive Parameters Update Data from the UDM after the UE has registered in the 5G network.Steering of Roaming (SoR) enables the home network to guide the user equipment (UE) when registering on a visited network. For detailed information about the interfaces and registration in the 5G System, refer to 3GPP TS.23.501 (Release 15)

[0017] and 3GPP TS 24.501 (Release 15)

[0018] , The 5G CP-SOR is activated during or after registration to update the UE's " Operator Controlled PLMN Selector with Access Technology" list via secure NAS messages, as directed by the home PLMN based on specific operator policies, such as preferred networks or UE location.

[0044] UE configuration update (UCU) is used to update configuration parameters as per TS 23.502 that may include Access and Mobility Management related parameters decided and provided by the AMF, UE Policy provided by the PCF. When AMF wants to change the UE configuration for access and mobility management related parameters the AMF initiates the procedure defined in clause 4.2.4.2. When the PCF wants to change or provide new UE Policies in the UE, the PCF initiates the procedure defined in clause 4.2.4.3. If the UE Configuration Update procedure requires the UE to initiate a Registration procedure, the AMF indicates this to the UE explicitly. The procedure in clause 4.2.4.2 may be triggered also when the AAA Server that performed Network Slice-Specific Authentication and Authorization for an S-NSSAI revokes the authorization.

[0045] Radio access network (RAN) is the part of the cellular system that connects the UEs to the CN via the air interface. The RAN consists of base stations (BSs). A base station (BS) is a fixed or mobile transceiver that covers a certain geographic area, called a cell. In 5G, a BS is also called a gNB (next generation node B). A BS can serve multiple UEs simultaneously within its cell, by using different frequencies, time slots, codes, or beams. A BS also performs functions such as power control, handover control, channel allocation, interference management, etc. A base station can be divided into two units: a central unit (CU) and a distributed unit (DU). The CU performs the higher layer functions, such as RLC, PDCP, RRC, etc. The DU performs the lower layer functions, such as PHY and MAC. The CU and the DU can be co-located or separated, depending on the network architecture and deployment. In cellular systems, a base station may be denoted, based on context, as a cell, or gNB.

[0046] The cell may also refer to the coverage area of a base station. A BS may have different coverage areas such as a macro cell (e.g. several kilometres wide), a pico cell (e.g., for a given location such as a stadium) or a femto cell for a small location (e.g., a home or part of it).

[0047] A base station may communicate with the core network. Since there can be base stations for different cellular systems, different interfaces are required. For instance, a base station, eNB, in a 4G Long Term Evolution (LTE) system (also known as Evolved Universal Mobile Telecommunications Systems (UMTS) Terrestrial Radio Access Network (E-UTRAN)) may interface with the 4G CN known as EPC through the corresponding interface. For instance, a base station, gNB, in a 5G system (i.e., 5G New Radio or Next Generation RAN) may communicate with the 5GC through a2025P00098WQ 8

[0048] different interface. 4G and 5G base stations may communicate with each other directly or through their corresponding core networks. Similar architecture is expected in 6G.

[0049] The main protocols used between the UEs and the RAN are:

[0050] - The physical layer (PHY), which defines the characteristics of the air interface, such as the frequency bands, the modulation schemes, the coding rates, the frame structure, the synchronization, etc.

[0051] - The medium access control (MAC) layer, which regulates the access of the UEs to the shared radio channel, by using techniques such as orthogonal frequency division multiple access (OFDMA), time division duplex (TDD), frequency division duplex (FDD), etc.

[0052] - The radio link control (RLC) layer, which provides reliable data transmission over the radio channel, by using techniques such as segmentation, reassembly, error detection, error correction, retransmission, etc.

[0053] - The packet data convergence protocol (PDCP) layer, which compresses and decompresses the headers of the data packets, encrypts and decrypts the data, and performs data integrity protection.

[0054] - The radio resource control (RRC) layer, which establishes, maintains, and releases the radio bearers between the UEs and the RAN, as well as exchanges the signaling messages for functions such as connection setup, handover, measurement reporting, security activation, etc.

[0055] A transmission / reception communication unit or transceiver may be used by BS and UE to transmit / receive data. Control data may be required for a physical broadcast channel, physical downlink control channel, etc. Data may be for the physical downlink shared channel.

[0056] Data may be encoded by the UE and / or BS to obtain data symbols and / or control symbols that may be exchanged over the wireless interface. The conversion from digital data into analog symbols may be done by the transmission / reception communication unit

[0057] A medium access control control-element (MAC-CE) is a MAC layer communication element that is used to control the communication between wireless devices. A MAC-CE may be exchanged in a shared channel, e.g., the physical downlink / uplink / sidelink shared channel.

[0058] The communication between a UE and a base station or the communication between UEs (when sidelink is used) may involve the exchange of reference signals. Reference signals may include primary synchronization signal (PSS), a secondary synchronization signal (SSS), a physical broadcast channel demodulation reference signal (DMRS), a channel state information reference signal (CSI-RS). Core network (CN) is the part of the cellular system that connects the RAN to other networks, such as the Internet, or other cellular systems. The CN consists of two main (control / user) domains. The control domain is responsible for providing signalling and control functions for the UEs,2025P00098WQ 9

[0059] such as authentication, authorization, mobility management, session management, etc. The control plane consists of several network functions (NFs), such as the access and mobility management function (AMF), the session management function (SMF), the unified data management (UDM), the policy control function (PCF), the network exposure function (NEF), and the authentication server function (AUSF). The access and mobility management function (AMF) is a NF that handles the registration, deregistration, connection management, and mobility management for the UEs. The session management function (SMF) is a NF that handles the establishment, modification, and release of the sessions for the UEs. The SMF also communicates with the user plane devices to perform functions such as IP address allocation, tunneling, QoS, etc. The unified data management (UDM) is a NF that stores and manages the user data, such as the SUPI, the service profile, the subscription status, etc. The policy control function (PCF) is a NF that provides the policy rules and charging information for the UEs, such as the access type, the service level, the data rate, the quota, etc. The network exposure function (NEF) is a NF that exposes the network capabilities and services to external applications and devices, such as the IMS, the Internet of Things (loT), etc. The authentication server function (AUSF) is a NF that performs the primary authentication with the by using credentials and the SUPI. The user domain is responsible for providing data and multimedia services to the UEs, by using packets and IP addresses. The user plane consists of two main functions: the user plane function (UPF) and the data network (DN). The user plane function (UPF) is a device that forwards the data packets between the UEs and the DNs, as well as performs functions such as tunneling, firewall, QoS, charging, etc. The data network (DN) is a network that provides access to the services and applications that the UEs request, such as the Internet, the IMS, etc.

[0060] A residential gateway (RG) is a device that connects a home network to an external network, such as the Internet or a cellular system. An RG typically provides functions such as routing, switching, firewall, NAT, DHCP, DNS, VPN, etc. An RG can also support various types of interfaces, such as Ethernet, Wi-Fi, Bluetooth, USB, etc. A cellular-capable RG is an RG that has a cellular interface, such as a UICC slot, a cellular modem, or an antenna, that enables it to access the cellular system as a backup or an alternative to the wired or wireless broadband connection. A cellular-capable RG can provide benefits such as: (1) Enhanced reliability, by switching to the cellular connection in case of a failure or a degradation of the broadband connection; (2) Increased bandwidth, by aggregating the cellular connection and the broadband connection to achieve higher data rates or QoS.

[0061] A multi-SIM subscription is a subscription that allows a user to have multiple SIMs (or eSIMs) that are linked to the same account and service profile. A user can use the multi-SIM subscription to access the cellular system from different devices, such as a smartphone, a tablet, a laptop, or a wearable device, without having to switch the SIM card or the device.Overall system: Fig. 1 provides an overall description of a wireless system wherein devices 100, 102, and 128 can play the role of UEs. Device 102 is part of a cellular-capable RG providing connectivity to a home network 129 e.g., by means of a local area network and / or wireless local area network. Device 102 is served by base station 104.

[0062] The RAN 127 comprises base station 103 and serves UE 128. UE 128 may also be a UE to Network relay given access to remote UE 136 that is out of coverage of base station 103. UEs 134 and 136 also communicate with each other via a UE-to-UE relay 135. UE to UE communication via relays is enabled by means of sidelink communication / PC5 interface.

[0063] Within the RAN, the range of base station 103 is extended via smart repeater 137 and reflective intelligent surface (RIS) 138. Smart repeater 137 and RIS 138 give access to UE 142.

[0064] The RAN 143 includes base station 104 tand serves as wireless access infrastructure for the home network. Base station 104 also serves a mobile access device and / or UE as a UAV 139. UAV 139 may provide connectivity to remote UE 136.

[0065] Furthermore, a satellite gateway 141 is shown that connects to satellite 140 and may provide connectivity services to remote UE 136 or UE 100.

[0066] In Fig. 1, the 5G core network 133 may include one or more an AMF 121, SMF 123, UPF 122, AUSF 124, UDM 125, PCF 131, NEF 132 and allows the connection to a data network 130.

[0067] In Fig. 1, a second core network 142, e.g., a legacy core network as a 4G core network, is also shown that may interface with the 5G core network 133, interface with base stations denoted eNB in 4G, and provide a connection to the data network 130. The legacy 4G core network is denoted EPC and may include one or more mobility management entities (MME), a serving gateway, a multimedia broadcast multicast service gateway, a broadcast multicast service center, a packet data network gateway, etc. The mobility management entity may handle the signalling between UE and the 4G CN and may interact with the home subscriber server (HSS) in charge of the storage and management of subscriber data and secrets. The MME may provide connection management, similar to the AMF in 5G. The serving gateway may be used to exchange user internet protocol messages whereby the serving gateway may interact with the packet data network gateway that is connected to IP services. Multiple protocols in 4G and 5G have similar features. For example, the 5G network registration and 4G attach registration message are initially sent by the UE to establish a connection between the UE and the CN, which involves sending an initial request from the UE with its identity and capabilities, receiving an authentication request from the CN with a challenge, sending an authentication response from the UE with a response, receiving an authentication result from the CN with an indication of success or failure, and sending a security mode command from the CN with the selected security algorithms. As a result of this connection establishment procedure, NAS and AS keys2025P00098WQ 11

[0068] are derived from the K_AMF (5G) and K_ASME (4G) where K_AMF is managed by the AM F and K_ASME is managed by the MME. A UE may connect to a serving network or serving Public Land Mobile Network (PLMN). A UE may have a subscription with a home PLMN, and during the registration procedure, the (AMF of the) serving PLMN may forward the registration request to the (AUSF of the) home PLMN that may perform an initial authentication procedure between home PLMN and UE. If the authentication procedure is successful, keys are derived and the home PLMN may share derived credentials with the serving PLMN, including K_SEAF, that may be used to derive K_AMF, from which NAS keys and AS keys are derived. The registration request sent by the UE includes an identifier that can be used by the home PLMN to identify the UE. To prevent privacy vulnerabilities, the long-term subscriber's identifier known as Subscriber Permanent Identifier (SUPI) may not be exchanged in the clear, but instead, either a Subscription Concealed Identifier (SUCI) or a pseudonym known as GUTI are exchanged with the AMF of the serving PLMN. The AMF of the PLMN may then forward the SUCI to the home PLMN so that the home PLMN decrypts / verifies it.

[0069] Satellite access: Fig. 1 depicts satellite 140 providing access to one or more UEs. Satellite access can be performed by means of non-terrestrial devices at different altitudes such as Low Earth Orbit (LEO), Medium Earth Orbit (MEO) or Geosynchronous Equatorial Orbit (GEO) satellites. Other types of non-terrestrial devices may include high-altitude platform station (HAPS) or unmanned aerial vehicle (UAVs) that may comprise a base station. Fig. 3 illustrates different elements including a GEO satellite 302, a MEO satellite 303, a LEO satellites 304 and 304', a UAV 305, all of them potential non-terrestrial mobile access devices giving coverage to wireless device (e.g., a UE) 301. GEO satellite 302 remains static over a given earth position while MEO and LEO satellites move. MEO satellites 303 have a slower moving vector 306 in relation to the earth compared with LEO satellites 304 / 304' that have a faster moving vector 307 / 307'. A non-terrestrial gateway 308 is included that provides connectivity to the mobile access device via a feeder link 310. A mobile access device provides service to the wireless device via a service link 311. Two mobile access devices in the same orbit may communicate with each other via an intra-orbit-satellite link 312 while two mobile access devices in different orbits may communicate with each other via an inter-orbit-satellite link 313. Fig. 3 finally also includes a terrestrial access device 309 that may also provide connectivity to wireless device 301. The terrestrial access device 309, the wireless device 301, and non-terrestrial gateway are on the earth surface 314.

[0070] Non-terrestrial devices such as satellites distribute system information in specific SIBs, in particular, SIB31 in 4G and SIB19 in 5G. S19 information element as defined in TS 38.331 18.2.0.

[0071] -- TAG-SIB19-START

[0072]

[0073] 2025P00098WQ 12

[0074] FIE19-rl7:: = SEQHEHGE (

[0075] ntn-Conf ig-r!7 IITII-Conf iq-117

[0076] OPTIOHAL, -- llqqb R

[0077] t-Sqrviqq-rl7 IHTEGER ( 0.. 549755813887 )

[0078] OPTIOHAL, — Hqpd R

[0079] lAArenceLuCatiun-rP Ref ereneeLc q at iari-rl"

[0080] OPTIOHAL, -- llAd R

[0081] Gist anqqThrqsh-rl7 IHTEGER ( U.. 65525 )

[0082] OPTIOHAL, — Ile ed R

[0083] ritn-lIqiqhOqllOqnf iqLiqt -rl" lITH-lIeiqhOellOorif IqList-rl7

[0084] OPTIOHAL, — Heed R

[0085] let elleeidrit ic al Eat erisiuri OCTET STRIHG

[0086] OPTIOHAL,

[0087] ritri-lIaighCellCanf igLiatE::t ---l~ 2'j HTn-HeighOellOC nf iqLiat -rl"

[0088] OPTIOHAL — Heed R

[0089] iiiii niiCl-i'iiiniqoRef ereneeLC cat ie H-rl S Ref ereneeLoc at laii-Ll"

[0090] OPTIOHAL, -- Heed R

[0091] ritri0avEnh-rl 8 lITlI-CovEnh-rl 8

[0092] OPTIOHAL, — Heed R

[0093] e at P rit chTTit HReEyne-rl 7 17 at Sit qhTiit LReGyne-rl t:

[0094] OPTIOHAL -- Heed R

[0095] iiiiliiM

[0096] HTH-HeighOellOanfiqLiat -rl":: = CEQUEHCE ( SILE f l.. nia:: OellHTH-rl~ ) ) OF 1TT1I- Ileigh0ell0onfiq-rl7

[0097] lITlI-HeighCellCorif iq-r!7:: = FEQUEHCE (

[0098] ntri-Oonf ig-r!7 HTH-Conf iq-1’17

[0099] OPTIOHAL, -- Heed R

[0100] carrierFreq-rl7 ARFCH-ValiaellR

[0101] OPTIOHAL, -- Heed R

[0102] phys0ellId-rl7 PhpsOellld

[0103] OPTIOHAL -- Heed R

[0104] HTH-CovEiih-rl 8:: = FEQUEHCE {

[0105] nuniberOfl laqJHA. RQ-A. OH-Repet it iona-rlS BIT GTRIHG ( FILE ( 4 ) ),

[0106] rarp-Threaholdl Iaq4H. ARQ-. ACH- 1'1 S RFRP-Ranqa

[0107] OPTIOHAL — Heed R

[0108] Eat Si ritehnithReEpne-rl t::: = FEQUEHCE (

[0109] nt ri-Ocoif iq-rl 8 HTH-Oonfig-rl7,

[0110] t-Service3tart -rl 8 IHTEGER ( Li.. 549" 5581388" )

[0111] OPTIOHAL, — Heed R

[0112] ssb-TimeOf f set -rl8 IHTEGER ( 'J.. 159 )

[0113] OPTIOHAL -- Heed R

[0114] -- TAG-SIB19-STOP

[0115]

[0116] -- ASN1STOP

[0117] SIB19 field descriptions

[0118] distanceThresh

[0119] Distance from the serving cell reference location and is used in location-based measurement initiation in RRC_IDLE and RRC_INACTIVE, as defined in TS 38.304

[0020] , Each step represents 50m. This field is only present in an NTN cell.

[0120] movingReferenceLocation

[0121] Reference location of the serving cell of an NTN Earth-moving cell at a time reference. It is used in the evaluation of eventD2 and condEventD2 criteria for the serving cell in RRC_CONNECTED, and locationbased measurement initiation in RRC_IDLE and RRC_INACTIVE when distanceThresh is also configured, as defined in TS 38.304

[0020] , The time reference of this field is indicated by epochTime in ntn-Config of the serving cell. This field is excluded when determining changes in system information, i.e., changes to movingReferenceLocation should neither result in system information change notifications nor in a modification of valueTag in SIB1. This field is only present in an NTN cell.

[0122] ntn-Config

[0123]

[0124] 2025P00098WQ 13

[0125] Provides parameters needed for the UE to access NR via NTN access such as Ephemeris data, common TA parameters, k_offset, validity duration for UL sync information and epoch. In a TN cell, this field is only present in ntn-NeighCellConfigList and ntn-NeighCellConfigListExt.

[0126] ntn-Neigh Cell Config Lis t, n tn-Neigh Cell Config Lis tExt

[0127] Provides a list of NTN neighbour cells including their ntn-Config, carrier frequency and PhysCellld. This set includes all elements of ntn-NeighCellConfigList and all elements of ntn-NeighCellConfigListExt. If ntn-Config is absent for an entry in ntn-NeighCellConfigListExt, the ntn-Config provided in the entry at the same position in ntn-NeighCellConfigList applies. Network provides ntn-Config for the first entry of ntn-NeighCellConfigList. If the ntn-Config is absent for any other entry in ntn-NeighCellConfigList, the ntn-Config provided in the previous entry in ntn-NeighCellConfigList applies.

[0128] referenceLocation

[0129] Reference location of the serving cell provided via NTN (quasi)-Earth fixed cell and is used in location-based measurement initiation in RRC_IDLE and RRC_INACTIVE, as defined in TS 38.304

[0020] , This field is only present in an NTN cell.

[0130] satSwitchWithReSync

[0131] Provides parameters for the target satellite required to perform satellite switch with resynchronization. This field is only present in an NTN cell and its presence indicates that satellite switch without PCI change is supported in the cell.

[0132] t-Service

[0133] Indicates the time information on when a cell provided via NTN is going to stop serving the area it is currently covering. This field applies for both service link switches in NTN quasi-Earth fixed cell and feeder link switches for both NTN quasi-Earth fixed and Earth-moving cell. The field indicates a time in multiples of 10 ms after 00:00:00 on Gregorian calendar date 1 January, 1900 (midnight between Sunday, December 31, 1899 and Monday, January 1, 1900). The exact stop time is between the time indicated by the value of this field minus 1 and the time indicated by the value of this field. The reference point for t-Service is the uplink time

[0134]

[0135] synchronization reference point of the cell. This field is only present in an NTN cell.

[0136] NTN-CovEnh field descriptions

[0137] numberOfMsg4HARQ-ACK-Repetitions

[0138] The number of repetition slots for PUCCH transmission with HARQ-ACK information for Msg4, see clause 9.2.6 in TS 38.213

[0013] , The first / leftmost bit corresponds to the repetition factor 1, the second bit corresponds to repetition factor 2, the third bit corresponds to the repetition factor 4, and the last / rightmost bit corresponds to the repetition factor 8. The repetition factor 1 shall be indicated together with at least one other repetition factor. _

[0139] rsrp- ThresholdMsg4HARQ-A CK

[0140] This threshold is used by the UE for determining the configuration of the MAC entity for PUCCH repetition for

[0141]

[0142] Msg4 HARQ-ACK, as specified in clause 6.2.1 in TS 38.321 [3].

[0143] SatSwitchWithReSync field descriptions

[0144] ssb- TimeOffset

[0145] Indicates the time offset between the SSB from source and target satellite at the uplink time synchronization reference point. It is given in number of subframes.

[0146] t-ServiceStart

[0147] Indicates the time information on when the target satellite is going to start serving the area currently covered by the serving satellite. The field indicates a time in multiples of 10 ms after 00:00:00 on Gregorian calendar date 1stJanuary 1900 (midnight between Sunday, December 31, 1899, and Monday, January 1, 1900). The exact start time is between the time indicated by the value of this field minus 1 and the time indicated by the value of this field. The reference point for t-ServiceStart is the uplink time synchronization reference point of

[0148]

[0149] the serving satellite.

[0150] A UE in a cellular system performs an initial random-access procedure to connect an access device. The 5G random access procedure is illustrated by means of Fig. 4 wherein 401 represents a user equipment and 402 represents an access device. The access device distributes signals 402. Signals 402 can be distributed periodically or on demand. Signals 402 may comprise the Master Information Block (MIB) transmitted together with / in the physical broadcast channel (PBCH) and the synchronization signals. The MIB comprises:2025P00098WQ 14

[0151] MIB::= SEQUENCE {

[0152] system FrameNumber BIT STRING (SIZE (6)), subCarrierSpacingCommon ENUMERATED {scsl5or60, scs30orl20}, ssb-SubcarrierOffset INTEGER (0..15),

[0153] dmrs-TypeA-Position ENUMERATED {pos2, pos3},

[0154] pdcch-ConfigSIBl INTEGER (0..255),

[0155] cellBarred ENUMERATED {barred, notBarred}, IntraFreqReselection ENUMERATED {allowed, notAllowed}, spare BIT STRING (SIZE (1))

[0156] }

[0157] MIB and PBCH are transmitted as part of a Synchronization Signal Block, and the access device may transmit multiple SSBs through different beams, allowing the user equipment to determine the preferred beam, and once the preferred beam is obtained, retrieve the MIB, and use the information in the MIB to attempt to retrieve System Information Block 1 (SIB1) that may also be distributed periodically. The UE can the use the information in SIB1 to perform the random-access procedure selecting a preamble to indicate its intention to access the cell by means of message 404, e.g., preamble transmission. This message may use a random-access radio network temporary identifier (RA-RNTI). Upon reception of message 404, access device 402 replies with message 405, e.g., a random access response. This message may include a time advance field to adapt the transmission timing, a value matching the preamble used by wireless device 401, and a grant (communication resources) for the wireless device. The access device also assigns a temporary cell radio network temporary identifier (TC-RNTI). Prior to this message 405, the access device may send a PDCCH DCI message assigning resources (a communication grant). This message may be addressed using the RA-RNTI. Upon reception of message 405, wireless device uses the initial grant received in the previous message and the RA-RNTI to transmit a subsequent message 406, e.g, an RRCSetupRequest or PHY layer. This message may include a Contention Resolution Identifier (CRI). This message may be sent in the PUSCH. As a response, access device replies with message 407, e.g., RRCSetup, that includes / repeats the received CRI confirming that the access device has identified the access device. This message includes a Cell RNTI (C-RNTI). Next, wireless device replies with message 408, e.g., an RRCSetupComplete that includes the RegistrationRequest message, and UE capabilities.

[0158] MIB and PBCH are transmitted as part of a Synchronization Signal Block, and the access device may transmit multiple SSBs through different beams. Multiple SSBs transmitted through multiple beams2025P00098WQ 15

[0159] form an SSB burst. The multiple SSBs in an SSB burst are transmitted sequentially in the first part of a frame. SSB bursts are transmitted periodically, typically every 20 ms, or more.

[0160] Fig. 5 schematically illustrates an access device 500 transmitting four beams, each of them transmitting an SSB, namely 501, 502, 503, and 504. A wireless device 505 can measure the signal strength, i.e., RSRP (Reference Signal Received Power), of the beams. This is illustrated by means of the graph in Fig. 5 where 501', 502', 503', and 504' represent the RSRP of beams 501, 502, 503, and 504, respectively, as measured by wireless device 505. Wireless device 505 can use this information to determine which one of the beams is the preferred beam for further communication, e.g., to perform the random access procedure.

[0161] Fig. 6 further schematically illustrates SSB bursts transmitted periodically. In this case, each SSB burst comprises four SSBs transmitted in the first part / half of every second frame. In this figure, frames are denoted as f, f+1, f+2, f+3,... A frame has a typical duration of 10 ms.

[0162] Resource grid: in a cellular network, such as a 5G network, the resource grid is a structured framework used to allocate and manage communication resources efficiently. It is characterized by a time-frequency matrix where each element, known as a resource element, is defined by its position in both time and frequency domains. The vertical axis represents frequency, segmented into subcarriers, which are spaced at intervals. The subcarrier spacing can vary depending on the deployment scenario, with common spacings being 15 kHz, 30 kHz, 60 kHz, 120 kHz, 240 kHz, and 480 kHz (corresponding to mu equal to 0, 1, 2, 3, 4, and 5, respectively). The horizontal axis of the grid represents time and is divided into frames, subframes, and slots, each frame has a duration of 10 ms and each subframe has a duration of 1 millisecond. Within these subframes, the time is further divided into slots. For mu, there are 2Amu symbols per subframe. Each slot typically spans 14 OFDM symbols. Each resource element in the grid, defined by the intersection of a time symbol and a frequency subcarrier, can carry a small portion of data, control information, or reference signals. These resource elements are grouped into larger units called Resource Blocks (RBs), which span 12 subcarriers in frequency and one slot in time. The allocation of these RBs is dynamically managed.

[0163] Reflective intelligent surfaces (RIS): may be used as part of the wireless infrastructure or as part of the wireless devices. RIS, often referred to as metasurfaces, are advanced materials engineered with sub-wavelength structures that can manipulate electromagnetic waves in a controlled manner. These surfaces consist of an array of unit cells, each capable of adjusting its electromagnetic response through electronic control, thus enabling dynamic alteration of the2025P00098WQ 16

[0164] wavefront of the incident signal. The wireless device can utilize the RIS to fine-tune the reflection properties of the wireless sensing signal, such as phase, amplitude, and polarization. By dynamically adjusting these parameters, the RIS can enhance signal strength, directivity, and overall signal quality. For instance, the RIS can focus the reflected signal towards the transmitter, significantly improving signal reception. This capability is particularly advantageous in urban environments where obstacles and interference are prevalent. Technical details of the RIS involve the implementation of tunable elements, such as varactor diodes or microelectromechanical systems (MEMS), in each unit cell. These elements allow real-time reconfiguration of the surface's electromagnetic properties in response to control signals from the wireless device. The control signals can be generated based on real-time analysis of the received signal's quality and contextual parameters, ensuring optimal reflection under varying conditions. The RIS can operate in various frequency bands, including sub-6 GHz and millimeter-wave (mmWave) frequencies, making it versatile for different wireless applications. Additionally, the RIS can incorporate sensing capabilities to monitor the environment and further refine the reflection parameters. For example, integrated sensors can detect changes in temperature, humidity, or the presence of obstacles, and adjust the reflection properties accordingly to maintain high signal quality.

[0165] Quality of Service: a wireless system may be used to transport data belonging to different types of applications such as Machine Type Communication (MTC), Critical Machine Type Communication (CMTC), Enhanced Mobile Broadband (EMB), or Fixed Wireless Access (FWA). MTC (e.g., smart meters, tracking,...) requires low bandwidth and non-latency critical, CMTC (e.g., industrial applications) has strict throughput, latency, and availability needs, EMB (VR / AR, 4K UDH,...) and FWA (e.g., in the home) require high data rate, with low latency, and low end-to-end response time. In wireless network such as 5G the Quality of Service has to accommodate different applications such as EMB, MTC, ultra-reliable low latency communications. QoS is influenced by the entities involved in the communication, UE, RAN, UPF, and DN. Data exchanges between UE and DN are mapped to QoS flows, and each QoS flow is mapped to a 5G QoS Identifier (5QI) in TS 23.501 (Table 5.7.4-1) that describes resource types, priority, packet delay budget, packet error rate, maximum data burst volume. Network is configured to configure RAN and core network interfaces to achieve the requirements of a 5QI. QoS is applied to a data stream from the wireless physical layer to the core network. Between RAN and UPF, QoS is applied in terms of a QoS flow. QoS in the RAN is managed by means of Data Radio Bearers (DRB). A QoS flow on core network side is created by means of a PDU session establishment accept. The mapping between a QoS flow and a DRM is done by means of SDAP configuration in an RRC message (RRCSetup or RRCReconfiguration) The indication or identifier that connects the whole QoS2025P00098WQ 17

[0166] pipe is called QoS flow identifier. Downlink traffic requires mapping IP messages and the QoS pipe, and this is done by the UPF. For each IP message or packet, the UPF checks (by means of a packet QoS assignment / detection rule) the packet information (source / destination / protocol / type of service / ...) and directs the IP packet to a QoS flow. The packet QoS assignment / detection rule is provided by SMF interacting with PCF. In the uplink, the UE performs a similar task by applying QoS rules provided in NAS messages (e.g., PDU session establishment) by the SMF or are pre-configured / derived by the UE.

[0167] Discontinuous reception (DRX) in cellular networks such as 5G is in two types, Idle mode DRX and Connected mode DRX. In Idle mode DRX, the UE wakes up to monitor for paging messages. If no paging message is detected, it sleeps further. In Connected DRX mode, the UE enters in sleep mode periodically and during the sleep period the UE is not required to monitor the Physical Download Control Channel. The access device configures the UE device with C-DRX parameters. Connected DRX approach reduces energy consumption of the device because it does not require monitoring the PDCCH periodically and it also reduces the transmissions of CSI or SRS signals, that also has a positive effect in the network / access devices load. There are two types of DRX cycles, long and short. A long DRX cycle consists of an on period and an off period. The on duration is in terms of milliseconds. The long DRC cycle may be configured or the long DRX cycle and short DRX cycles may be configured. The access device can configure the time (drx-onDurationTimer) during which the UE is awake and goes back to sleep if there is no PDCCH received. The access device can also configure a given drx-LongCycleStartOffiset to start to awake period at a subframe boundary and / or drx-SlotOffset relative to the subframe boundary. If there is activity in an awake period, the UE may remain awake some more time determined by the drx-lnactivityTimer. Furthermore, the access device can configure long DRX cycle together with additional DRX cycle which is shorter than long DRX cycle. Configurable parameters include the drx-ShortCycle (duration of the short cycle) and drx-ShortCycleTImer that determines how many short cycles before the device should apply.

[0168] Data scheduling in a cellular network such as a 5G cellular network may be performed by means of a scheduler wherein the scheduler takes as input information such as measurements of UE / network, buffer status report, QoS requirements, associated radio bearers, or a scheduling request. In the downlink, data scheduling may be performed by means of dynamic scheduling and semi persistent scheduling (SPS). In dynamic scheduling, every data exchange in the Physical Downlink Shared Channel (PDSCH) is scheduled by means of a downlink control information (DCI) message in the Physical Downlink Control Channel (PDCCH). In SPS, the scheduling is done by means of an RRC message. In the uplink, scheduling can be performed by means of dynamic scheduling and configured2025P00098WQ 18

[0169] scheduling (CS). In dynamic scheduling each Physical Uplink Shared Channel (PUSCH) is scheduled over DCI. In CS, the PUSCH transmission is scheduled via RRC message. Furthermore, a Scheduling Request message may be sent over the PUCCH (Physical Uplink Control Channel) or in an Uplink Control Information (UCI) in the PUSCH (Physical Uplink Shared Channel). An SR may be sent by a UE device when it has data to transmit. Upon reception, the access device can allocate resources (Uplink Grant by means of the Physical Downlink Control Channel. Upon resource allocation, the UE device can transmit data in the Physical Uplink Shared Channel.

[0170] Wireless sensing and integrated wireless sensing and communication: wireless systems are evolving to include wireless sensing capabilities. These wireless sensing capabilities may be implemented e.g. by a radar functionality in wireless communication involving one or more access devices (e.g., base stations (BS)) and / or one or more terminal devices (e.g., UEs). As an example, Frequency Modulated Continuous Wave (FMCW) mmWave radar systems can measure range, velocity, and angle of arrival (if two receivers are available) of objects in the scene which reflect radio waves. Such radar systems emit a chirp signal, e.g., a sine wave that increases in frequency over time. The chirp signal (e.g., a continuous wave pulse) has a bandwidth and a frequency increase rate. Generally, a continuous series of such chirps are emitted. The transmitted and received analogue chirp signals are mixed to generate an intermediate frequency (IF) signal which corresponds to the difference in frequencies of the two signals (outbound and inbound) and whose output phase corresponds to the difference in the phases of the two signals. Each surface of a scene or environment will therefore produce a constant frequency IF signal whose frequency relates to the distance to the surface (i.e., a first distance from the transmitter of the chirp signal to the surface plus a second distance from the surface to the receiver of the chirp signal). To resolve two surfaces at different distances, the two IF signals can be frequency resolved. A longer time window of the IF signal results in greater resolution. As the chirp time is related to its bandwidth (with constant chirp frequency change) the resolution of the radar is related to the chirp bandwidth. The IF signal may then be band pass filtered (to remove signals below some minimal range and frequencies above the maximum frequency for a subsequent analogue-to-digital converter (ADC)) and digitized prior to further processing. The upper frequency sensing range of the bandpass filter and ADC sets the maximum range that can be detected (i.e., IF frequencies increase with range). To detect vibrations, the phase of the IF signal is important, since the phase (i.e., the difference in phases of the transmitted and received chirp signals) is a sensitive measure of small changes in the distance of a surface. Small distance changes can be detected in the phase signal but may be indiscernible in the frequency signal. Moreover, phase difference measures between two consecutive chirp signals can be used to determine the velocity of the surface. As an example, a fast Fourier transform (FFT)2025P00098WQ 19

[0171] processing can be performed across multiple chirp signals to enable separation of objects with the same range but moving at different velocities. A Fourier transform converts a signal from a space or time domain into the frequency domain. In the frequency domain the signal is represented by a weighted sum of sine and cosine waves. A discrete digital signal with N samples can be represented exactly by a sum of N waves. FFT provides a faster way of computing a discrete Fourier transform by using the symmetry and repetition of waves to combine samples and reuse partial results. This method can save a huge amount of processing time, especially with real-world signals that can have many thousands or even millions of samples. As a further example, angle estimation can be performed by using the phase difference between the received chirp signal at two separated receivers.

[0172] As another option, a channel state information (CSI) can be used, which is a measure of the phases and amplitudes of many frequencies detected at a receiver, thereby forming a complex 'map' of the radio environment, including effects of objects within that environment. CSI characterizes how wireless signals propagate from the transmitter to the receiver at certain carrier frequencies. CSI amplitude and phase are impacted by multi-path effects including amplitude attenuation and phase shift, e.g., by the displacements and movements of the transmitter, receiver, and surrounding objects and humans. In other words, CSI captures the wireless characteristics of the nearby environment. These characteristics, assisted by mathematical modeling or machine learning algorithms, can be used for different sensing applications. A radio channel may be divided into multiple subcarriers, as is done e.g. in 5G communication systems (using e.g. orthogonal frequency division multiplexing (OFDM)). To measure CSI, the transmitter may send long training symbols (LTFs), which contain pre-defined symbols for each subcarrier, e.g., in a packet preamble. When those LTFs are received, the receiver can estimate a CSI matrix using the received signals and the original LTFs. For each subcarrier, the channel can be modeled by y = Hx + n, where y is the received signal, x is the transmitted signal, H is the CSI matrix, and n is the noise vector. The receiver estimates the CSI matrix H using a pre-defined signal x and the received signal y after signal processing such as removing cyclic prefix, de-mapping and demodulation. The estimated CSI is then a three-dimensional matrix of complex values and this matrix represents an 'image' of the radio environment at that time. By processing a time series of such 'images' information on movements, locations and vibrations of objects can be extracted. Such a processing of a CSI matrix can be used for vital signs monitoring, presence detection, and human movement recognition. As an example, neural network like recognition techniques can be used to process the CSI matrix to perform such kinds of recognition.

[0173] It is noted that systems using channel state information (CSI) are somehow related to systems with FMCW mmWave radar. In a CSI-based system, the input signal X may be defined and the receiver2025P00098WQ 20

[0174] may use the received signal Y to obtain H, i.e., as H = (Y - N) / X. In a FMCW mmWave radar, the transmitted signal Chirp X may also be predefined, and the receiver may uses the received signal Y to obtain a transfer function as H = Y / X. This last step is in fact somehow related to multiplying the locally computed chirp signal and the received chirp signal and applying a bandpass filter. According to various embodiments in this invention, the above-described wireless sensing techniques are implemented in a mobile communication system (e.g. 5G or 6G or other cellular or WiFi communication systems), while the functional coexistence of radar and communication operating in the same frequency bands is configured to avoid interference bandwidths. Thereby, radio sensing can be integrated into large-scale mobile networks to create perceptive mobile networks.

[0175] As another example, the sensing signal may consist of a number of pulses sent, e.g., at specific frequencies and timing (sensing signal parameter information) by a sensing transmitter. The sensing receiver may include a number of bandpass filters that allow identifying the sensing signal parameter information, e.g, timing and frequency of the received pulses. In particular, if the transmitter determines a given pseudo-random sequence of frequency / timing pulses and beams it, e.g., by means of beamforming, in a specific direction, and if the transmitter communicates to the receiver the timing / frequency, in general, the sensing signal parameter information, of the transmitted sensing signal, the receiver can use its bandpass filters to identify the reception of the same transmitted pulses, i.e., sensing signal, based on the received sensing signal parameter information.

[0176] The wireless sensing signal may be part of the synchronization signal block. For instance, the wireless sensing signal may be a reference signal included in the primary synchronization signal or in the secondary synchronization signal. It may consist of a number of reference signals and / or it may be a wide band signal. This wireless sensing signal can allow the access devices to determine the presence of a wireless device. The wireless device may also use this wireless sensing signal to determine the access device that is more suitable to (re-)select.

[0177] Wireless local area network technologies such as Wi-Fi allow devices to connect to the Internet or to each other without using cables. Wi-Fi is based on radio waves that are transmitted and received by a device called a wireless access point (AP). The AP acts as a hub that connects Wi-Fi enabled devices, such as laptops, smartphones, tablets, smart TVs, etc., to a wired network, such as a local area network (LAN) or the Internet.

[0178] The term Wi-Fi is a trademark of the Wi-Fi Alliance, an industry association that certifies products that comply with the IEEE 802.11 standards for wireless local area networks (WLANs). These standards define the physical and data link layers of the communication protocol, such as the frequency bands, modulation schemes, encryption methods, authentication mechanisms,2025P00098WQ 21

[0179] and data rates used by Wi-Fi devices. The most common Wi-Fi standards are 802.11a, 802.11b, 802.11g, 802.11n, 802.11ac, and 802.11ax, which operate in different frequency bands (2.4 GHz, 5 GHz, or both) and offer different levels of performance and compatibility.

[0180] To use Wi-Fi, a device needs to have a wireless network interface card (NIC) that can send and receive radio signals. The NIC scans the available wireless channels and detects the presence of nearby APs. The device then selects an AP to connect to, based on factors such as signal strength, security settings, and network name (SSID). The device and the AP exchange information, such as the MAC address, IP address, encryption key, and password, to establish a connection. This process is called association. After the connection is established, the device can communicate with the AP and other devices on the same network, or access the Internet through the AP.

[0181] IEEE 802.11n (Wi-Fi 4) provided new features such as MIMO and frame aggregation to increase throughput. IEEE 802.11ac (Wi-Fi 5) introduced wider bandwidth and MU-MIMO. IEEE 802.11ax (WIFI-6) included OFDMA and BSS color or spatial reuse to use spectrum resources more efficiently. IEEE 802.11ah introduced target wake time (TWT) to support low power loT applications by allowing STAs to go into sleep when not in a wake period after negotiation with AP. IEEE 802.11be (Wi-Fi 7) aims at improving throughput and latency operating in unlicensed bands between 1GHz and 7.125 GHz. Wi-Fi 7. Increases bandwidths up to 320 MHz, 4096 QAM modulation, and supporting up to 16 spatial streams in MU-MIMO with an improved sounding procedure. Wi-FI 7 also enables multiple resource units to be assigned to a single device. Furthermore, it includes an enhanced preamble with a universal SIG filed indicating the PHY version. It also extends the negotiated ack buffer size to 1024 bits. It also enables multilink operation (MLO) enabling multiple links between a station and an access point, for instance an AP can have two radios 2.4 and 5 GHz and use both of them for simultaneous transmission and / or reception with a multi-link capable device (MLD) capable station. Wi-Fi 7 also includes a restricted TWT providing predictable latency by assigning STAs to different rTWT types and making sure that other STAs do not transmit if they do not belong to a given rTWT type. Wi-Fi 7 also include multi-AP coordination performing, e.g., coordinated transmission, beamforming, or joint transmission.

[0182] For instance, in references to Fig. 1, devices 100, 101 and 102 can be Wi-FI access points and device 106 can be a wireless station. Station 106 and access point 101 are MLD and communicate with two links 126. Device 102 is a cellular capable residential gateway.

[0183] This invention is illustrated in the context of IMS voice over Wi-Fi connected to 5GC in standalone deployments (see S2-2411498) via a modernized evolved Packet Data Gateway (ePDG) connecting to the 5GC via SBI (S2-2411655; S2-2411656), in order to continue to make use of the widespread ePDG deployment for non-3GPP access, not only to 4G EPC, but also 5GC. This includes2025P00098WQ 22

[0184] enabling support for IMS Voice over Wi-Fi connected to 5GC in standalone deployments without relying on N3IWF, including architecture to support ePDG connected to AUSF, UDM and NRF, without intermediate 3GPP AAA Server. Similarly, in 6G it may be beneficial to use an ePDG, or particular an "enhanced" ePDG for enabling non-3GPP access to a 6G Core Network. Hence, in all instances in this description where 5G is used, the term may be replaced by 6G and 5G specific terms such as N3IWF may be replaced with a 6G network function responsible for enabling UEs to access the 6G network via non-3GPP access. The term AUSF may be replaced with a 6G network function responsible for authentication of UEs similar to a 5G AUSF.

[0185] One of the issues is how to deal with the different authentication mechanisms needed for connecting to a traditional 4G ePDG to access EPC versus authenticating via N3IWF to access 5GC. For example, a 5G UE would authenticate via N3IWF using 5G-AKA or EAP-AKA' / EAP-5G related mechanisms in a transparent manner via the AMF (i.e. similar as access through 3GPP RAT) to the AUSF (whereby the subscription is managed by UDM to which the AUSF is connected), in order to gain access to the 5GC (e.g. UPF). A 4G UE would authenticate via ePDG using EAP-AKA (RFC 4187 [7]) or on EAP-AKA' (RFC 5448

[0023] ) related mechanisms to an AAA server (whereby the subscription is managed by HSS to which the AAA server is connected), in order to gain access to the 4G EPC (e.g. PDN Gateway).

[0186] With ePDG, for every mobility between 3GPP and Non-3GPP access there is need to re-authenticate the UE, whereas in the N3IWF based architecture this is not needed as the AMF has the UE's security context. Which means with ePDG based architecture there will be more signalling required, more time required for mobility between 3GPP and Non-3GPP access. Moreover, the additional signalling will impact dimensioning of AUSF / UDM, specially in scenarios where there is frequent toggle between 3GPP and Non-3GPP access.

[0187] For N3IWF, the mobility is much more streamlined given the overlap between 3GPP and non-3GPP access in terms of authentication via AMF and AUSF. The UE may even be authenticated by reusing the existing UE NAS security context in AMF when switching between 3GPP and non-3GPP access.

[0188] An initial architecture for interworking between ePDG and 5GC has been defined in clause 4.3.4 of 3GPP TS 23.501, primarily for the purpose of handover between 4G and 5G, e.g. as further specified in clause 4.11.4 of 3GPP TS 23.502.2025P00098WQ 23

[0189] The following embodiments focus on enabling a UE to access the 5GC over non-3GPP access by deploying an ePDG in an efficient manner with minimal changes to existing NFs such as ePDG.

[0190] In an embodiment that may be combined with other embodiments or implemented independently, a UE may register to 5GC via 3GPP access using a first PDU session establishment procedure. During the first PDU session establishment procedure or afterwards over the established PDU session or through a previous PDU session or through pre-configured information (e.g. N3IWF / ePDG selection information and / or related policies), the UE may be provided with information and / or configuration about an "enhanced" ePDG.

[0191] The information and / or configuration may comprise parameters such as, e.g., IP address / FQDN or ePDG, list of capabilities. Such ePDG may be capable of allowing the UE to connect to 5GC via the ePDG. This may be denoted a first configuration and may comprise non-security parameters that are required to setup the connection with the ePDG through non-3GPP access. In an example, the information about a set of "enhanced" ePDGs may be configured at the UE and used as in clause 6.3.6 of 3GPP TS 23.501. In order for the UE to select an "enhanced" ePDG (e.g. instead or with higher or lower priority over e.g. an N3IWF or a legacy ePDG), the configuration information may include additional rules and / or conditions (in general, connection conditions) when the "enhanced" ePDG can / should or should not be used, for example depending on whether an N3IWF is available in the respective 5GC, or on whether certain capabilities (e.g. AKMA based ePDG access or token validation with AUSF) are supported by the 5GC / ePDG, or on which countries or geographical areas the UE resides, and / or based on QoS requirements (e.g. whether or not certain interruptions are

[0192]

[0193] In addition, the UE may be provided with information and / or configuration on credential information and / or identity information to be provided during an authentication procedure via that "enhanced" ePDG, and / or information on which authentication procedure to use for PDU session / PDN connection establishment via non-3GPP access via the "enhanced" ePDG. This may include security token, a symmetric key, cryptographic challenges, information related to the security context, information used to verify a network function such as ePDG (e.g., a digital certificate / public key used to verify a certificate provided by the ePDG at a later stage). This may be denoted a second configuration and may comprise security and identification parameters that are required to setup the connection with the ePDG through non-3GPP access.In an example, during the first PDU session establishment procedure via 3GPP access, the UE may receive (e.g. using a NAS message) a first and / or second configuration that may include one or more of the following parameters:

[0194] IP address and port number of an ePDG accessible for non-3GPP access and / or an identity to be used by the UE and / or

[0195] credentials to communicate with the network via non-3GPP access and / or a security token and / or a symmetric key and / or cryptographic challenge and / or information related to the security context of the UE (as stored by the AUSF) for validation of the UE with AUSF via the "enhanced" ePDG.

[0196] an indication about a protocol to use to connect with the ePDG and / or parameters used to derive a key.

[0197] Additionally or alternatively, the UE may be provided with credentials to derive security materials to establish a link with the network via non-3GPP access. Additionally or alternatively, said credentials may be derived from the current security context handled by the UE, e.g., the current root key derived from the primary authentication, e.g., K_AUSF in 5G.

[0198] The UE may use the received information (or a subset thereof) when the UE registers and / or connects to the network via non-3GPP access or sets up a PDU session or PDN connection with the network via non-3GPP access via the "enhanced" ePDG. In some examples, the connection (e.g. PDU session) between the UE and the network over 3GPP access may be closed prior to establishing connection to the ePDG and / or the UE may be out-of-coverage of 3GPP access. To this end the configuration information, e.g. the credentials may be provided together with a maximum lifetime and / or conditions in which cases these can be used (e.g. only for "enhanced" ePDGs and not when connecting to legacy ePDG or only for specific ePDGs matching certain IP address / FQDN, or only when the UE is connected to the 5GC over 3GPP access, or only when in certain countries or geographical areas).

[0199] For example, it may use the information and / or configuration above, e.g., a security token and / or cryptographic challenge and / or other security related information that it has received and / or an identity of the UE (e.g. SUCI protected using 5GC credentials, GUTI, or GPSI) in a message M (e.g. registration message or PDU session establishment request message or PDN connection request message or authentication related message) to the "enhanced" ePDG over non-3GPP accessand / or it may use credentials received from the 5GC (e.g. received during the first PDU session establishment or pre-configured on the UE) and / or credentials derived from an existing security context to protect / encrypt message M (or part of the message's payload) and / or include a Message Authentication / Integrity Code (MAC / MIC) in message M to the "enhanced" ePDG over non-3GPP access.

[0200] Based on message M received by the "enhanced" ePDG, the "enhanced" ePDG may use the information received in message M to authenticate and / or to verify the authentication of the UE with the AUSF to which the "enhanced" ePDG may be directly connected (e.g. using SBI) or indirectly connected (e.g. via AAA server or AMF). If the authentication or authentication verification of the UE is successful, the ePDG may receive the necessary information (e.g. part of the security context information of the UE) or may be preconfigured to allow the UE access to the 5GC, e.g. to the UPF (e.g. the one for which IP address and port number may be provided during the first PDU session establishment procedure).

[0201] It can also be envisioned that a similar issue as described for ePDG may apply to vendors that have already deployed an N3IWF in 5G, and may wish to continue to do so in 6G going forward. Therefore in an embodiment that may be be combined with other embodiments or used independently, the term "ePDG" in the previous embodiment may be replaced with " N3IWF", and N3IWF may be replaced with a 6G network function responsible for enabling UEs to access the 6G network via non-3GPP access, and the AUSF may be replaced with a 6G network function responsible for authentication of UEs similar to a 5G AUSF. Additionally or alternatively, the UE may be configured (through the first configuration) to communicate with an authentication function (e.g. a 6G AUSF equivalent or an AAA server) deployed in the 6G network or accessible through the 6G network (e.g. via IP / User Plane, possibly "directly" or relayed / forwarded via a user plane related function to transmit / receive IP packets to / from the UE), whereby the second configuration may be used by the UE to authenticate with the authentication function and / or to enable the authentication function to authenticate the UE.

[0202] It can also be envisioned that a similar issue as described for ePDG may apply to vendors that have an N3IWF in 5G, and wish to continue to do so in 6G forward. Therefore, in an embodiment that may be be combined with other embodiments or used

[0203]

[0204] the term "ePDG" in the previous embodiment may be replaced with " N3IWF", and N3IWF may be replaced with a 6G network function responsible for enabling UEs to access the 6Gnetwork via non-3GPP access, the term AUSF be with a 6G network function

[0205] for authentication of UEs similar to a 5G AUSF.

[0206] In 6G, a decentralized architecture may be envisioned for the 6G Core Network. In such architecture, a UE connect via IP with a set of 6G Core Network Functions. Therefore, in an embodiment that

[0207]

[0208] be combined with other embodiments or used i

[0209]

[0210] a 6G Core Network

[0211]

[0212] be with a 6G authentication function

[0213]

[0214] such 6G authentication function enable access to the 6G core network via non-3GPP access. Such authentication function be an authentication function dedicated to non-3GPP access (e.g. AAA server or

[0215]

[0216] similar) or shared between UEs

[0217]

[0218] the authentication function via 3GPP access as well as via non-3GPP access (e.g. a 5G AUSF

[0219]

[0220] for

[0221] In an example, the UE may be configured to connect "directly" (e.g., via IP) with such 6G authentication function or "i via e.g. a user plane related function to ive IP

[0222]

[0223] m a UE) to the 6G authentication function.

[0224] In an example, the UE may be configured with information to enable the UE to set up a connection with the 6G authentication function non-3GPP access. This be denoted as a first

[0225]

[0226] and non-:

[0227]

[0228] such as, e.g., I

[0229]

[0230] P a of the 6G authentication function, list of ca

[0231]

[0232] etc.

[0233] In an example, the UE may also be configured with credential information and / or information to be an authentication via that 6G authentication function, a information on which authentication

[0234]

[0235] to use for

[0236]

[0237] sessio

[0238]

[0239] establishment via non-3GPP access via the 6G authentication function. This

[0240]

[0241] include

[0242]

[0243] token, a

[0244]

[0245] ic information related to the

[0246]

[0247] context information used to

[0248]

[0249] a network function such as the 6G authentication function (e.g., a

[0250]

[0251] certificate ic key used to

[0252]

[0253] a certificate

[0254]

[0255] the 6G authentication function at a later. This be denoted a second

[0256]

[0257] and and identification

[0258]

[0259] that are to the connection with the 6G authentication function

[0260]

[0261] non-3GPP access.

[0262] In an example, the UE may use the first and second configuration to perform an authentication with the 6G authentication function in order to access (e.g. set up a PDU session) with the 6G Core Network.

[0263] In an example, the first or second configuration may also include security information related to a secure tunnel (e.g. IPSec or other to the 6G authenticationfunction and / or information about one or more intermediate network functions for the UE to connect to (e.g. in case the 6G authentication function is not to entities outside the 6G core

[0264] In an example, an intermediate network function may be a user plane function or data ei ever or a trusted access wireless access device that a UE is allowed to connect to (e.g. after an initial

[0265]

[0266] authentication, e.g. an IPSec based

[0267]

[0268] verification or a 4-’ and which

[0269]

[0270] have a direct" connection with the 6G authentication function.

[0271] In an example, this intermediate network function may be configured with credentials a identities of UEs that are authorized to connect to the intermediate network function a the su to reach the 6G authentication function, a

[0272]

[0273] r be with IP

[0274]

[0275] addresses header and / or other information related to the 6G authentication function to be able to

[0276]

[0277] that are meant for the 6G authentication function from other

[0278] In an example, the intermediate function may relay an incoming / outgoing first set of

[0279]

[0280] the UE via non-3GPP m the 6G authentication function (e.g. based on destination IP address or other information in the

[0281]

[0282] and block other

[0283]

[0284] from forwarded or further

[0285]

[0286] the intermediate network function until the UE has com

[0287]

[0288] the authentication

[0289]

[0290] with the 6G authentication function.

[0291] Additionally or alternatively, the intermediate function may transmit the incomi the first set of as a second set of e.g. enca in a different

[0292]

[0293] . The intermediate function a

[0294]

[0295] the 6G authentication function

[0296]

[0297] be

[0298]

[0299] to throttle that are UEs via non-3GPP e.g. to avoid

[0300]

[0301] malicious or devices.

[0302] In a similar manner as for the above mentioned 6G authentication function, the UE

[0303]

[0304] be to connect or " to other 6G core network functions (e.g. a 6G session function

[0305]

[0306] or 6G control function

[0307]

[0308] via IP.

[0309] In another example, the ePDG may also be provided with (related) information and / or configuration, so that the ePDG can authenticate the UE directly, and / or the UE can also authenticate the ePDG. For instance, in an embodiment that may be combined with other embodiments or used independently, the ePDG may act as an AF in the AKMA context and the UE and ePDG may rely on AKMA to agree / derive / obtain a shared secret K_AF denoted in this context K_ePDG. This key may be used to authenticate and setup a secure connection between UE and ePDG. The ePDG and UE can be mutually authenticated and the communication can be protected. In a related embodiment thatmay be combined with other embodiments or used independent, the UE and ePDG rely on SBA to setup / agree on common secrets / or credentials.

[0310] Performing the procedure in such manner would allow quick access to the 5GC via an "enhanced" ePDG without having to run 4G EAP-AKA authentication protocol (in addition), by making use of the security context that the UE already has in the 5GC, and with minimal changes to the existing ePDG (e.g., it just needs to "forward" the information received from the UE to perform a check with the AUSF). Note that message M may be received only once a secure connection has been established, e.g., a TLS connection or an IPSec connection has been established so that message M can be exchanged in the TLS connection and it cannot be eavesdropped and resent by an attacker. When setting up the TLS connection or an IPSec connection, the wireless device, i.e., UE may also be required to verify the authenticity of the ePDG, e.g., by verifying a digital certificate issued by the 5GS to the ePDG. The UE may be able to verify it, and only if verified, the UE may transmit message M.

[0311] For instance, IPSec rfc7619 specifies the NULL Authentication method and the ID_NULL Identification Payload ID Type for Internet Key Exchange Protocol version 2 (IKEv2). This allows two IKE peers to establish single-side authenticated or mutual unauthenticated IKE sessions for those use cases where a peer is unwilling or unable to authenticate or identify itself. This ensures IKEv2 can be used for Opportunistic Security (also known as Opportunistic Encryption) to defend against Pervasive Monitoring attacks without the need to sacrifice anonymity. Such an IPSec protocol may be used to setup the connection first, the UE may be able to verify the identity of the network function (e.g., ePDG) based on a digital certificate. The UE may then send message M through the secure IPsec tunnel. This approach may allow reusing legacy protocols in a network function, while using keying materials of a newer generation core network.

[0312] In some cases, if message M does not contain any of the above-mentioned information or the authentication / authentication verification with AUSF fails, the ePDG may be configured, to request a 4G EAP-AKA authentication procedure to be executed and / or to block the connection and / or inform the UE of the authentication failure. The ePDG may also inform other NF in the 5GS about the failure.

[0313] Note also that after the non-3GPP connection via the "enhanced" ePDG is established, the first 3GPP connection may be torn down.In some cases, the "enhanced" ePDF or AUSF may request (or offer) an additional verification or authentication check with (or for) the UE via the first PDU session via 3GPP access, e.g., when the message includes an indication of the establishment of a multipath communication. To this end, the "enhanced" ePDG or AUSF may send a message N to / via the AUSF, SM F and / or AM F, whereby message N may include information from the "enhanced" ePDG (e.g. a 4G EPC related credential or identity) and / or from the information received from the UE in message M in order to request the AUSF, SMF and / or AMF to trigger a verification or authentication check with the UE via the first PDU session via 3GPP access. This message N may also allow the UE to verify / confirm that it is using a valid ePDG.

[0314] In some cases, the AUSF, SMF and / or AMF may do this if the UE is configured and / or is establishing a multipath communication, e.g., the SMF may have been notified about the intention of establishing a multipath connection over 3GPP and non-3GPP access. This further verification may be triggered / done by sending a message N' (e.g. NAS message) that includes a verification or authentication check to the UE and / or the "enhanced" ePDG may send a message O (e.g. NAS message or other type of message) that needs to be (transparently) forwarded by the AUSF / SMF / AMF to the UE to perform the verification or authorization check. The message N' or message O may include identity information of the UE (e.g. identity information received in message M) and / or a cryptographic challenge (e.g. based on credential from the "enhanced" ePDG and / or 4G network) and / or information about incoming traffic via non-3GPP access (e.g. question for device or user of the device to confirm that it has requested access to the network via non-3GPP access, possibly including timestamp information of when the "enhanced" ePDG received the incoming message M), and / or may request to send a token / authentication value through the non-3GPP access, if the UE intends to establish, is establishing or has established that connection. Upon receiving such message N' or O, the UE may perform the requested verification or authentication check and / or requested action and respond with message P that may be transmitted via the first PDU session (or via the non-3GPP access to the "enhanced" ePDG).

[0315] Additionally or alternatively, message N' or O or subsequent message (e.g. before or after successful verification or authentication check e.g. as indicated by message P) may include credentials for the UE (e.g., in addition or instead of credentials that may have been transmitted upon establishing the first PDU session) to use in subsequent messages to the "enhanced" ePDG via non-3GPP access (e.g. use for encryption or integrity protection). For instance, the core network may assigncommunication parameters (e.g., credentials such as keys or certificates or IP address) to establish the communication via non-3GPP access e.g. to the 5GC.

[0316] Additionally or alternatively, the "enhanced" ePDG may verify if the message M is protected, e.g., encrypted, using credentials that it knows / trusts (e.g. because these have been supplied to the UE using the first PDU session (during initial session establishment or in message N' or O or subsequent message) and may have been shared with the "enhanced" ePDG as well). If not, the "enhanced" ePDG may discard the message and / or communication / connection establishment.

[0317] In some embodiments that may be combined with other embodiments or used independently, a UE may perform traditional / standard primary authentication over the 3GPP access, and the UE may obtain through the 3GPP access some credentials, e.g., explicitly or implicitly (e.g., deriving from some root secrets) to use for connecting with the "enhanced" ePDG or legarcy ePDG. The UE may indicate then its intention to use / access the "enhanced" ePDG or a legacy ePDG. Credentials / parameters may be provided to the UE to access the "enhanced" or legacy ePDG. In some examples, the connection (e.g. PDU session) between the UE and the network over 3GPP access may be closed prior to establishing connection to the ePDG and / or the UE may be out-of-coverage of 3GPP access. To this end the credentials may be provided together with a maximum lifetime and / or conditions in which cases these can be used (e.g. only for "enhanced" ePDGs and not when connecting to legacy ePDG, or only for specific ePDGs matching certain IP address / FQDN, or only when the UE is connected to the 5GC over 3GPP access or only when in certain countries or geographical areas).

[0318] The credentials / security parameters may be updated periodically by the network (e.g. every time the UE connects via 3GPP access or every time the UE connects via non-3GPP access). If the credentials / security parameters are not valid anymore (e.g. their configured lifetime expired), the UE may request new / updated credentials / security parameters when it is connected via 3GPP access.

[0319] Additionally or alternatively, the UE may connect via non-3GPP access whereby it may include an indication that the credentials / security parameters to connect via non-3GPP (as obtained via the second configuration) have expired, upon which the "enhanced" ePDG may

[0320] - provide updated credential / security parameters via 3GPP access, if the UE is connected or may be able to connect via 3GPP access. The UE may be requested (e.g. through an error response message or a redirection response) to disconnect the non-3GPP access and / or to connect via 3GPP access to obtain the updated credential / security parameters, and / or - trigger a legacy ePDG authentication procedure over non-3GPP access, and / or- trigger an adapted authentication procedure whereby the UE may need to use and / or provide (proof of possession of) the expired credentials / security parameters (e.g. by the network providing a seed / nonce that the UE should use together with the expired credentials / security parameters to derive a secret or key to use) in the adapted authentication procedure over non-3GPP with the "enhanced" ePDG, and / or

[0321] - trigger an adapted authentication procedure whereby the UE may need to use and / or provide (proof of possession of) a previously configured shared secret (e.g. Wi-Fi-related passphrase or a recovery password that may have been shared beforehand between the UE and the core network (e.g. "enhanced" ePDG)) in the adapted authentication procedure over non-3GPP with the "enhanced" ePDG.

[0322] The provided / derived credentials / parameters may be used by the UE to authenticate itself against the ePDG. For instance, the credentials / parameters may be an authorization token or a key or a one-time password. These credentials may be exchanged when establishing an IP connection between UE and ePDG and / or when establishing a secure connection between UE and ePDG. In an example, they may be used prior to the establishment of a secure channel (e.g., in the header of a security protocol such as TLS or IPSec when the secure channel is being established). In some examples, they may be exchanged once the secure channel has been established. If the credentials are exchanged prior to the establishment, the system / ePDG is more resilient to DoS attacks. If the credentials are exchanged after establishment of the secure channel, the system is more resilient to spoofing. It is to be noted that the UE may also send credentials to the ePDG so that the ePDG verifies the UE, but also the ePDG may send credentials to the UE so that the UE verifies the ePDG. Credentials such as keys, certificates, etc can be considered as a type of token.

[0323] In an embodiment that may be combined with other embodiments or used independently, it is considered that the ePDG may be capable of performing a legacy authentication / security protocol, e.g., as detailed in TS 33.402, Clause 8.2.2. A legacy authentication protocol may rely on IPSec and / or EAP-AKA. While such protocols may be available at the ePDG, relevant keying materials and / or NF may not be available in a 5GC. Thus, it is important to reuse such protocols of a legacy authentication / security protocol with keys that are available in the 5GC. This may require adapting legacy authentication / security protocols, e.g., using a specific mode X instead of mode Y. For instance, IPSec may be used with both public key cryptography (e.g., Mode Y) and symmetric keys (e.g., Mode X). In an option, e.g., the IPSec protocol may be executed between UE and ePDG, but using keys / credentials associated to the 5GS, e.g., AKMA keys. This may allow adapting an2025P00098WQ 32

[0324] ePDG in such a manner that legacy security protocols as they are, or part of them, or adapted (in general, adapted legacy security protocols) can be used, but relying on keys delivered by other NFs available in a modern 5GC. This may be advantageous because ePDG may be reused with minimal changes (e.g., using adapted legacy security protocols).

[0325] For instance, AKMA may be used to derive keys (e.g., a K_AF) for both UE and the ePDG. K_AF may then be used with IPSec using symmetric keys (adapted legacy security protocol). IKE, part of IPSec, may be used to setup the connection. For instance, one of the initial IKEv2 protocol messages (e.g., IKEA_SA_INIT_Request) may carry a hint indicating that the UE is accessing an ePDG in the 5GS. The hint may also indicate the credentials used, e.g., credentials of the second configuration. For instance, AKMA credentials. ePDG may be adapted to request keys from another NF, e.g., AKMA Anchor Function (AAnF) or AUSF. This may allow reusing and / or adapting legacy security procedures (e.g., IPSec protocols) in ePDG. In this example, it would eliminate the need of EAP-AKA (improving performance and / or need of accessing legacy NFs such as HSS), and it would provide means to allow mutual authentication between UE and ePDG. In other examples, EAP-AKA may also be reused / adapted.

[0326] Furthermore, this invention can be applied to various types of UEs or terminal devices, such as mobile phone, vital signs monitoring / telemetry devices, smartwatches, detectors, vehicles (for vehicle-to-vehicle (V2V) communication or more general vehicle-to-everything (V2X) communication), V2X devices, Internet of Things (IoT) hubs, IoT devices, including low-power medical sensors for health monitoring, medical (emergency) diagnosis and treatment devices, for hospital use or first-responder use, virtual reality (VR) headsets, etc.

[0327] Other variations to the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed invention, from a study of the drawings, the disclosure and the appended claims. In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. A single processor or other unit may fulfil the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage. The foregoing de-scription details certain embodiments of the invention. It will be appreciated, however, that no matter how detailed the foregoing appears in the text, the invention may be practiced in many ways, and is therefore not limited to the embodiments disclosed. It should be noted that the use of particular terminology when describing certain features or aspects of the invention should not be taken to imply that the terminology is being re-defined herein to be restricted to include any specific characteristics of the features or aspects ofthe invention with which that terminology is associated. Additionally, the expression "at least one of A, B, and C" is to be understood as disjunctive, i.e., as " A and / or B and / or C". The same applies to the expressions " A or B" and "at least one of A or B", i.e., they may indicate all possible combinations of the listed items.

[0328] A single unit or device may fulfil the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.

[0329] The described operations like those indicated in the above embodiments may be implemented as program code means of a computer program and / or as dedicated hardware of the related network device or function, respectively. The computer program may be stored and / or distributed on a suitable medium, such as an optical storage medium or a solid-state medium, supplied together with or as part of other hardware, but may also be distributed in other forms, such as via the Internet or other wired or wireless telecommunication systems.

Claims

Claims1. A method for secure access of a core network through non-3GPP access, comprising, by a wireless device:- establishing a secure connection with a core network through 3GPP access,- receiving from the core network a first configuration and / or determining the first configuration,- receiving from the core network a second configuration and / or determining the second configuration,- sending a connection request message to a network function based on and / or using the first configuration and the second configuration to establish the connection, - setting up the connection with the core network through non-3GPP access.

2. The method of claim 1, wherein the connection is set up upon verifying the network function.

3. The method of any previous claims, wherein the network function is an evolved Packet Data Gateway, ePDG or an Non-3GPP InterWorking Function (N3IWF) or a 6G authentication function, and the core network is a 5G or 6G core network.

4. The method of any previous claims, wherein the first configuration comprises one or more of:an IP address / FQDN,a port number,a list of capabilities,connection conditions,of the network function.

5. The method of any previous claims, wherein the second configuration comprises one or more of:- a configuration to determine a temporal identifier,- an authorization token,- a symmetric key,- a digital certificate and / or public key to verify the network function,- a digital certificate and / or public key to authenticate against a network function,- parameters / configuration to derive a symmetric key from a root secret.

6. The method of any previous claims, wherein the connection request message is addressed to the network function identified by the first configuration, and includes at least one value derived from or comprised in the second configuration.

7. The method of any of claims 2 to 6, wherein setting up the connection upon verifying the network function comprises receiving a confirmation message from the core network through 3GPP access or non-3GPP access.

8. The method of any of claims 2 to 7, wherein setting up the connection upon verifying the network function comprises performing a mutual authentication handshake with the network function based on at least one value derived from the second configuration.

9. The method of any previous claims, wherein the connection request message to the network function based on and / or using the first configuration and the second configuration to establish the connection is transmitted after setting up a secure connection with the network function or with another network function that forwards or transmits (an adapted set of) messages between the wireless device and the network function.

10. The method of any previous claims, wherein at least a value in the second configuration is derived from a root secret derived from the last successful primary authentication performed with the core network through 3GPP access.

11. The method of any previous claims, wherein the connection request message is an AKMA application session establishment request or an authentication and / or key management request message for a NF.

12. The method of any previous claims, wherein sending the connection request message to the network function based on and / or using the first configuration and the second configuration to establish the connection and setting up the connection, comprisesexecuting an adapted legacy security protocol with the network function using at least one value of / in / derived from the second configuration and setting up the connection upon successful execution of the legacy security protocol.

13. The method of claim 12, wherein the adapted legacy security protocol is IPSec and / or EAP-AKA.

14. An apparatus for secure access to a core network through non-3GPP access, wherein the apparatus comprises:- a processor,- a 3GPP transceiver,- a non-3GPP transceiver,and the apparatus is adapted to- establish a secure connection with the core network through 3GPP access via its 3GPP transceiver,- receiving from the core network via its 3GPP transceiver and / or determining a first configuration,- receiving from the core network via its 3GPP transceiver, and / or determining a second configuration,- sending a connection request message to a network function based on and / or using the first configuration and the second configuration to establish the connection via its non-3GPP transceiver,- setting up the connection with the core network through non-3GPP access.

15. A computer program for secure access of a core network through non-3GPP access, wherein the program comprises instructions implementing the steps of the methods of any of claims 1 to 13.