Securing communications between user equipment and home network via a security anchor

WO2026175601A1PCT designated stage Publication Date: 2026-08-27NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/051861
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-21
Filing Date
2026-01-26
Publication Date
2026-08-27

Smart Images

  • Figure 00000039_0000
    Figure 00000039_0000
  • Figure 00000040_0000
    Figure 00000040_0000
  • Figure 00000041_0000
    Figure 00000041_0000
Patent Text Reader

Abstract

A method in a user equipment (UE) includes: transmitting, towards a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), a first message including: a second message destined for a destination network function of the H-PLMN, and an indication regarding the destination network function.
Need to check novelty before this filing date? Find Prior Art

Description

SECURING COMMUNICATIONS BETWEEN USER EQUIPMENT AND HOME NETWORK VIA A SECURITY ANCHORFIELD

[0001] Various example embodiments relate to secure communications and, more particularly, to securing communications between user equipment and network functions in a home network via a security anchor.BACKGROUND

[0002] Wireless networking provides significant advantages for user mobility. A user’s ability to remain connected while on the move provides advantages not only for the user, but also provides greater efficiency and productivity for society as a whole. As expectations for connection reliability, data speed, and lower power consumption, become more demanding, technology for wireless networking must also keep pace with such expectations. For example, such expectations may relate to greater efficiency and security in communications. Accordingly, there is continuing interest in improving wireless networking technology.SUMMARY

[0003] In aspects of the present disclosure, a method in a user equipment (UE) includes: transmitting, towards a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), a first message including: a second message destined for a destination network function of the H-PLMN, and an indication regarding the destination network function.

[0004] In an aspect, the indication regarding the destination network function may indicate a network function type of the destination network function.

[0005] In an aspect, the indication regarding the destination network function may indicate a service provided by the destination network function.

[0006] In an aspect, the first message may be encrypted and integrity protected.

[0007] In an aspect, the first message may be encrypted and integrity protected using at least one of the following: a key (KH-SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrityprotection. The KSI and the identities of the security algorithms for encryption and integrity protection may be received via a third message from the network function configured to serve as the security anchor for the H-PLMN.

[0008] In an aspect, the method may further include determining whether replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0009] In an aspect, the method may further include generating a fourth message in response to the third message; encrypting and integrity protecting the fourth message based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message; and transmitting the encrypted and integrity protected fourth message to the network function configured to serve as the security anchor for the H-PLMN.

[0010] In an aspect, the fourth message may be encrypted and integrity protected if a result of the determining indicates that the replayed information, in the third message, regarding the security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0011] In an aspect, the third message may be a home network (HN) security mode command, and the fourth message may be a HN security mode complete message.

[0012] In aspects of the present disclosure, an apparatus includes: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform any one of the preceding methods.

[0013] In aspects of the present disclosure, a non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform any one of the preceding methods.

[0014] In aspects of the present disclosure, a method in a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN) includes: receiving, from a user equipment (UE), a first message including: a second message destined for a destination network function of the PLMN, and an indication regarding the destination network function.

[0015] In an aspect, the indication regarding the destination network function may indicate a network function type of the destination network function.

[0016] In an aspect, the indication regarding the destination network function may indicate a service provided by the destination network function.

[0017] In an aspect, the first message may be encrypted and integrity protected.

[0018] In an aspect, the method may further include identifying the destination network function based on the indication regarding the destination network; and transmitting the second message to the destination network function.

[0019] In an aspect, the method may further include decrypting the first message; and performing integrity check for the first message.

[0020] In an aspect, the decrypting and the performing the integrity check may be based on at least one of the following: a key (KH-SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrity protection. The KSI and the identities of the security algorithms for encryption and integrity protection may be sent via a third message to the UE.

[0021] In an aspect, the method may further include receiving, from the UE, an encrypted fourth message responding to the third message. The fourth message may be encrypted and integrity protected based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message.

[0022] In an aspect, the fourth message may indicate that replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0023] In an aspect, the third message may be a home network (HN) security mode command, and the fourth message may be a HN security mode complete message.

[0024] In aspects of the present disclosure, an apparatus includes: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform any one of the preceding methods.

[0025] In aspects of the present disclosure, a non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform any one of the preceding methods.

[0026] Further aspects are shown in the Examples section, which is incorporated by reference into this section.

[0027] According to some aspects, there is provided the subject matter of the independent claims and of the Examples. Some further aspects are defined in the dependent claims and in the Examples.BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Some example embodiments will now be described with reference to the accompanying drawings.

[0029] FIG. l is a diagram of an example embodiment of wireless networking between a network system and a user equipment (UE), according to one illustrated aspect of the disclosure;

[0030] FIG. 2 is a diagram of example components of a network system, according to one illustrated aspect of the disclosure;

[0031] FIG. 3 is a diagram of an example embodiment of a network function which serves as a security anchor in a home public land mobile network (H-PLMN), according to one illustrated aspect of the disclosure;

[0032] FIG. 4 is a diagram of an example embodiment of a key hierarchy of a wireless network, according to one illustrated aspect of the disclosure;

[0033] FIG. 5 is a diagram of an example embodiment of operations for generating a security key for a network function which serves as a security anchor, according to one illustrated aspect of the disclosure;

[0034] FIG. 6 is a diagram of an example embodiment of an uplink communication using a network function which serves as a security anchor, according to one illustrated aspect of the disclosure;

[0035] FIG. 7 is a diagram of an example embodiment of a downlink communication using a network function which serves as a security anchor, according to one illustrated aspect of the disclosure;

[0036] FIG. 8 is a diagram of an example embodiment of security mode control between a user equipment and a network function which serves as a security anchor, according to one illustrated aspect of the disclosure; and

[0037] FIG. 9 is a diagram of an example of components of a user equipment or of a network apparatus, according to one illustrated aspect of the present disclosure.DETAILED DESCRIPTION

[0038] The present disclosure relates to securing communications between user equipment and network functions in a home network via a security anchor. In aspects, a network function is introduced which provides functionality of a security anchor in a home public land mobile network (H-PLMN). As used herein, functionality of a security anchor refers to functionality which routes information securely between a user equipment (UE) and other network functions in a core network through a central / anchor network function. In embodiments, such functionality may be implemented in a new network function, which may be referred to herein as a home security anchor function (H-SEAF). In embodiments, such functionality may be implemented in a network function which provides other known functionality, such as, for example, implemented in an authentication server function (AUSF), among other possible network functions. In aspects, a security key is generated for the network function. Such a security key may be denoted herein as KH-SEAF. However, it will be understood that the notation is merely an example, and any notation may be used to refer to such a security key.

[0039] By implementing functionality of a security anchor, routing of communications between a UE and any network function in a core network may be secured by routing communications through the security anchor. Without a security anchor, communications between a UE and network functions in a core network may involve a myriad of interface / reference points, which are as specified in 3rd Generation Partnership Project (3GPP) Technical Specification (TS) 23.501, section 4.2.7. A reference point is a point of interaction between two network functions or components. Examples of interfaces / reference points include:N1 : Reference point between the UE and the AMF.N2: Reference point between the (R)AN and the AMF.N3: Reference point between the (R)AN and the UPF.N4: Reference point between the SMF and the UPF.N6: Reference point between the UPF and a Data Network.N9: Reference point between two UPFs.N5: Reference point between the PCF and an AF.N7: Reference point between the SMF and the PCF.N8: Reference point between the UDM and the AMF.N10: Reference point between the UDM and the SMF.Nil: Reference point between the AMF and the SMF.N12: Reference point between AMF and AUSF.N13: Reference point between the UDM and AUSF.N14: Reference point between two AMFs.N18: Reference point between any NF and UDSF.N22: Reference point between AMF and NSSF.N23 : Reference point between PCF and NWDAF.N28: Reference point between PCF and CHF.N29: Reference point between NEF and SMF.N30: Reference point between PCF and NEF.N33: Reference point between NEF and AF.N34: Reference point between NSSF and NWDAF.N35: Reference point between UDM and UDR.N36: Reference point between PCF and UDR.N37: Reference point between NEF and UDR.N40: Reference point between SMF and the CHF.N50: Reference point between AMF and the CBCF.N51 : Reference point between AMF and NEF.N52: Reference point between NEF and UDM.N55: Reference point between AMF and the UCMF.N56: Reference point between NEF and the UCMF.N57: Reference point between AF and the UCMF.N41 : Reference point between AMF and the CHF in HPLMN. N58: Reference point between AMF and the NSSAAF.N59: Reference point between UDM and the NSSAAF.Some of the routes use reference points / interfaces that have no security / integrity protection. Using functionality of a security anchor, the disclosed technology secures the routing of communications between a UE and any network function in a core network by routing communications through the security anchor.

[0040] In the following description, certain specific details are set forth in order to provide a thorough understanding of disclosed aspects. However, one skilled in the relevant art will recognize that aspects may be practiced without one or more of these specific details or with other methods, components, materials, etc. In other instances, well-known structures associated with transmitters, receivers, or transceivers have not been shown or described in detail to avoid unnecessarily obscuring descriptions of the aspects.

[0041] Reference throughout this specification to “one aspect” or “an aspect” means that a particular feature, structure, or characteristic described in connection with the aspect is included in at least one aspect. Thus, the appearances of the phrases “in one aspect” or “in an aspect” in various places throughout this specification are not necessarily all referring to the same aspect. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.

[0042] Embodiments described in the present disclosure may be implemented in wireless networking apparatuses, such as, without limitation, apparatuses utilizing Worldwide Interoperability for Microwave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGE radio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W-CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, enhanced LTE (eLTE), 5GNew Radio (5GNR), 5G Advance, 6G (and beyond) and 802.1 lax (Wi-Fi 6), among other wireless networking systems. The term ‘eLTE’ here denotes the LTE evolution that connects to a 5G core. LTE is also known as evolved UMTS terrestrial radio access (EUTRA) or as evolved UMTS terrestrial radio access network (EUTRAN).

[0043] The present disclosure may use the term “serving network device” to refer to a network node or network device (or a portion thereof) that services a UE. As used herein, the terms “transmit toward,” “transmit to,” “receive from,” and“cooperate with,” (and their variations) include communications that may or may not involve communications through one or more intermediate devices or nodes. The term “acquire” (and its variations) includes acquiring in the first instance or reacquiring after the first instance. The term “connection” may mean a physical connection or a logical connection.

[0044] The present disclosure uses 5GNR as an example of a wireless network and may use smartphones and / or extended reality headsets as an example of UEs. It is intended and shall be understood that such examples are merely illustrative, and the present disclosure is applicable to other wireless networks and user equipment.

[0045] FIG. 1 is a diagram depicting an example of wireless networking between a network system 100 and a user equipment (UE) 150. The network system 100 may include one or more network nodes 120, one or more servers 110, and / or one or more network equipment 130 (e.g., test equipment). The network nodes 120 will be described in more detail below. As used herein, the term “network apparatus” may refer to any component of the network system 100, such as the server 110, the network node 120, the network equipment 130, any component(s) of the foregoing, and / or any other component(s) of the network system 100. Examples of network apparatuses include, without limitation, apparatuses implementing aspects of 5G NR, among others. The present disclosure describes embodiments related to 5G NR and embodiments that involve aspects defined by 3rd Generation Partnership Project (3GPP). However, it is contemplated that embodiments relating to other wireless networking technologies are encompassed within the scope of the present disclosure.

[0046] The following description provides further details of examples of network nodes. In a 5G NR network, a gNodeB (also known as gNB) may include, e.g., a node that provides new radio (NR) user plane and control plane protocol terminations towards the UE and that is connected via a NG interface to the 5G core (5GC), e.g., according to 3GPP TS 38.300 V16.6.0 (2021-06) section 3.2, which is hereby incorporated by reference herein.

[0047] A gNB supports various protocol layers, e.g., Layer 1 (LI) - physical layer, Layer 2 (L2), and Layer 3 (L3).

[0048] The layer 2 (L2) of NR is split into the following sublayers: Medium Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP) and Service Data Adaptation Protocol (SDAP), where, e.g.:o The physical layer offers to the MAC sublayer transport channels; o The MAC sublayer offers to the RLC sublayer logical channels; o The RLC sublayer offers to the PDCP sublayer RLC channels; o The PDCP sublayer offers to the SDAP sublayer radio bearers; o The SDAP sublayer offers to 5GC quality of service (QoS) flows; o Control channels include broadcast control channel (BCCH) and physical control channel (PCCH).

[0049] Layer 3 (L3) includes, e.g., radio resource control (RRC), e.g., according to 3GPP TS 38.300 V16.6.0 (2021-06) section 6, which is hereby incorporated by reference herein.

[0050] A gNB central unit (gNB-CU) includes, e.g., a logical node hosting, e.g., radio resource control (RRC), service data adaptation protocol (SDAP), and packet data convergence protocol (PDCP) protocols of the gNB or RRC and PDCP protocols of the en-gNB, that controls the operation of one or more gNB distributed units (gNB-DUs). The gNB-CU terminates the Fl interface connected with the gNB-DU. A gNB-CU may also be referred to herein as a CU, a central unit, a centralized unit, or a control unit.

[0051] A gNB Distributed Unit (gNB-DU) includes, e.g., a logical node hosting, e.g., radio link control (RLC), media access control (MAC), and physical (PHY) layers of the gNB or en-gNB, and its operation is partly controlled by the gNB-CU. One gNB-DU supports one or multiple cells. One cell is supported by only one gNB-DU. The gNB-DU terminates the Fl interface connected with the gNB-CU. A gNB-DU may also be referred to herein as DU or a distributed unit.

[0052] A gNB-CU-Control Plane (gNB-CU-CP) includes, e.g., a logical node, the RRC and the control plane part of the PDCP protocol of the gNB-CU for an en-gNB or a gNB. The gNB-CU-CP terminates the El interface connected with the gNB-CU-User Plane (gNB-CU-UP) and the Fl-C interface connected with the gNB-DU.

[0053] A gNB-CU-User Plane (gNB-CU-UP) includes, e.g., a logical node hosting, e.g., the user plane part of the PDCP protocol of the gNB-CU for an en-gNB, and the user plane part of the PDCP protocol and the SDAP protocol of the gNB-CU for a gNB. The gNB-CU-UP terminates the El interface connected with the gNB-CU-CP and the Fl-U interface connected with the gNB-DU, e.g., according to 3GPP TS 38.401 V16.6.0 (2021-07) section 3.1, which is hereby incorporated by reference herein.

[0054] As used herein, the term “network node” may refer to any of a gNB, a gNB-CU, a gNB-DU, a gNB-CU-CP, or a gNB-CU-UP, or any combination of them.

[0055] A RAN (radio access network) node or network node such as, e.g., a gNB, gNB-CU, or gNB-DU, or parts thereof, may be implemented using, e.g., an apparatus with at least one processor and / or at least one memory with processor-readable instructions (“program”) configured to support and / or provision and / or process CU and / or DU related functionality and / or features, and / or at least one protocol (sub-)layer of a RAN (radio access network), e.g., layer 2 and / or layer 3. An example of such an apparatus and components will be described in connection with FIG. 11 below.

[0056] The gNB-CU and gNB-DU parts may, e.g., be co-located or physically separated. The gNB-DU may even be split further, e.g., into two parts, e.g., one including processing equipment and one including an antenna. A central unit (CU) may also be called baseband unit / radio equipment controller / cloud-RAN / virtual-RAN (BBU / REC / C-RAN / V-RAN), open-RAN (0-RAN), or part thereof. A distributed unit (DU) may also be called remote radio head / remote radio unit / radio equipment / radio unit (RRH / RRU / RE / RU), or part thereof. Hereinafter, in various example embodiments of the present disclosure, a network node, which supports at least one of central unit functionality or a layer 3 protocol of a radio access network, may be, e.g., a gNB-CU. Similarly, a network node, which supports at least one of distributed unit functionality or a layer 2 protocol of the radio access network, may be, e.g., a gNB-DU.

[0057] A gNB-CU may support one or multiple gNB-DUs. A gNB-DU may support one or multiple cells and, thus, could support a serving cell for a user equipment (UE) or support a candidate cell for handover, dual connectivity, and / or carrier aggregation, among other procedures.

[0058] The user equipment (UE) 150 may be or include a wireless or mobile device, an apparatus with a radio interface to interact with a RAN (radio access network), a smartphone, an in-vehicle apparatus, an loT device, or a M2M device, among other types of user equipment. Such UE 150 may include: at least one processor; and at least one memory including program code; where the at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus at least to perform certain operations, such as, e.g., RRC connection to the RAN. An example of components of a UE will be described in connection with FIG. 11. In embodiments, the UE 150 may be configured to generate a message (e.g., including a cell ID) to be transmitted via radio towards a RAN (e.g., to reach and communicate with a serving cell). In embodiments, the UE 150 may generate and transmit and receive RRC messages containing one or more RRC PDUs (packet data units). Persons skilled in the art will understand RRC protocol as well as other procedures a UE may perform.

[0059] With continuing reference to FIG. 1, in the example of a 5G NR network, the network system 100 provides one or more cells, which define a coverage area of the network system 100. As described above, the network system 100 may include a gNB of a 5G NR network or may include any other apparatus configured to control radio communication and manage radio resources within a cell. As used herein, the term “resource” may refer to radio resources, such as a resource block (RB), a physical resource block (PRB), a radio frame, a subframe, a time slot, a sub-band, a frequency region, a sub-carrier, a beam, etc. In embodiments, the network node 120 may be called a base station.

[0060] FIG. 1 provides an example and is merely illustrative of a network system 100 and a UE 150. Persons skilled in the art will understand that the network system 100 includes components not illustrated in FIG. 1 and will understand that other user equipment may be in communication with the network system 100.

[0061] FIG. 2 is a block diagram of example components of the network system 100 of FIG. 1. A 5G NR network may be described as an example of the network system 100, and it is intended that aspects of the following description shall be applicable to other types of network systems, as well. The network system may operate in accordance with the signals and connections shown in FIG. 1 such that the UE 150 is in communication with the network system 100 through the radioaccess network 225. Additionally, the network system may be divided into user plane components and functions and control plane components and functions, as shown and described herein. Unless indicated otherwise, the terms “component”, “function”, and “service” may be used interchangeably herein, and they may refer to and be implemented by instructions executed by one or more processors.

[0062] Example functions of the components are described below. The example functions are merely illustrative, and it shall be understood that additional operations and functions may be performed by the components described herein. Additionally, the connections between components may be virtual connections over service-based interfaces such that any component may communicate with any other component. In this manner, any component may act as a service “producer,” for any other component that is a service “consumer,” to provide services for network functions.

[0063] For example, a core network 210 is described in the control plane of the network system. The core network 210 may include an authentication server function (AUSF) 211, an access and mobility management function (AMF) 212, and a session management function (SMF) 213. The core network 210 may also include a network slice selection function (NSSF) 214, a network exposure function (NEF) 215, a network repository function (NRF) 216, and a unified data management function (UDM) 217, which may include a uniform data repository (UDR) 224.

[0064] Additional components and functions of the core network 210 may include an application function 218, policy control function (PCF) 219, network data analytics function (NWDAF) 220, analytics data repository function (ADRF) 221, management data analytics function (MDAF) 222, and operations and management function (0AM) 223.

[0065] The user plane includes the UE 150, a radio access network (RAN) 225, a user plane function (UPF) 226, and a data network (DN) 227. The RAN 225 may include one or more components described in connection with FIG. 1, such as one or more network nodes. However, the RAN 225 may not be limited to such components. The UPF 226 provides connection for data being transmitted over the RAN 225. The DN 226 identifies services from service providers, Internet access, and third party services, for example.

[0066] The AMF 212 processes connection and mobility tasks. The AUSF 211 receives authentication requests from the AMF 212 and interacts with UDM 217 to authenticate and validate network responses for determination of successful authentication. The SMF 213 conducts packet data unit (PDU) session management, as well as manages session context with the UPF 226.

[0067] The NSSF 214 may select a network slicing instance (NSI) and determine the allowed network slice selection assistance information (NSSAI). This selection and determination is utilized to set the AMF 212 to provide service to the UE 150. The NEF 215 secures access to network services for third parties to create specialized network services. The NRF 216 acts as a repository to store network functions to allow the functions to register with and discover each other.

[0068] The UDM 217 generates authentication vectors for use by the AUSF 211 and ADM 212 and provides user identification handling. The UDM 217 may be connected to the UDR 224 which stores data associated with authentication, applications, or the like. The AF 218 provides application services to a user (e.g., streaming services, etc.). The PCF 219 provides policy control functionality. For example, the PCF 219 may assist in network slicing and mobility management, as well as provide quality of service (QoS) and charging functionality.

[0069] The NWDAF 220 collects data (e.g., from the UE 150 and the network system) to perform network analytics and provide insight to functions that utilize the analytics in the providing of services. The ADRF 221 allows the storage, retrieval, and removal of data and analytics by consumers. The MDAF 222 provides additional data analytics services for network functions. The 0AM 223 provides provisioning and management processing functions to manage elements in or connected to the network (e.g., UE 150, network nodes, etc.).

[0070] FIG. 2 is merely an example of components of a network system, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the network system may include other components not illustrated in FIG. 2. In embodiments, the network system may not include every component illustrated in FIG. 2. In embodiments, the components and connections may be implemented with different connections than those illustrated in FIG. 2. Such and other embodiments are contemplated to be within the scope of the present disclosure.

[0071] As mentioned above, the present disclosure relates to securing communications between user equipment and network functions in a home network via a security anchor.

[0072] FIG. 3 shows an example of a security anchor located in a home public land mobile network (H-PLMN). The diagram includes a user equipment 305, a mobility management network function 310 (MM NF) (e.g., AMF), a network function 320 which serves as a security anchor in a H-PLMN, and various network functions 332-336 (e.g., PCF, UDM, etc.).

[0073] The UE 305 and the network function 320 providing the security anchor in a H-PLMN (which may be, e.g., H-SEAF, AUSF, or another network function) activate security, e.g., during the primary authentication and key agreement procedure. In the illustration of FIG. 3, communications between the UE 305 and various network functions 332-336 of the H-PLMN are routed through a mobility management network function (MM NF) 310 and the network function 320 providing the security anchor. The MM NF 310 may be, e.g., an AMF. As mentioned above, the network function 320 providing the security anchor may be a new network function (e.g., designated as H-SEAF) or may be an already defined network function, such as AUSF or another network function.

[0074] In FIG. 3, the various illustrated flows represent distinct data flows and do not necessarily represent different communication paths. Various communications between the network function 320 providing the security anchor and other network functions may utilize a service-based architecture (SB A), such as 5G SBA.

[0075] FIG. 3 and the description above are merely examples, and variations are contemplated to be within the scope of the present disclosure.

[0076] Referring now to FIG. 4, there is shown security keys for a wireless architecture which may be employed in accordance with the present disclosure. Aspects of security keys and security architecture are described in 3GPP TS 33.501, which is incorporated by reference herein in its entirety. As persons skilled in the art will understand, security keys may be used for, e.g., authentication, encryption, and decryption. As used herein, security keys will generally be denoted by the symbol K.

[0077] In accordance with aspects of the present disclosure, a key 410 (KH-SEAF) is generated for a network function serving as a security anchor in a H-PLMN, and a key 420 (KV-SEAF) may be generated for a network function serving as a security anchor in a visited public land mobile network (V-PLMN).

[0078] In aspects, as shown in FIG. 4, the key 410 (KH-SEAF) can be generated based on a key derivation function and a key (KAUSF) for an AUSF. Aspects of a key derivation function are described in 3GPP TS 33.501, which was incorporated above. The key (KH-SEAF) 410 may be generated independently by a UE (e.g., 305, FIG. 3) and by a network apparatus, e.g., of a core network, e.g., by AUSF in the H-PLMN. The AUSF may provide the KH-SEAF 410 to the H-SEAF network function in the H-PLMN, and the H-SEAF may receive the key KH-SEAF 410 from the AUSF.

[0079] In aspects, the key 420 (KV-SEAF) can be generated based on a key derivation function and the key 410 (KH-SEAF). The (KV-SEAF) 420 may be generated independently by a UE (e.g., 305, FIG. 3) and by a network apparatus, e.g., of a core network, e.g., by H-SEAF in the H-PLMN. The H-SEAF may provide the key KV-SEAF 420 to the V-SEAF in the V-PLMN, and the V-SEAF may receive the key KV-SEAF 420 from the H-SEAF.

[0080] In aspects, the key 420 KV-SEAF can be generated independently by the UE and by an AUSF of a H-PLMN based on KAUSF. The AUSF of the H-PLMN can transmit the key 420 KV-SEAF to the V-SEAF in the V-PLMN, and the V-SEAF can receive the key 420 KV-SEAF from the AUSF of the H-PLMN.

[0081] In aspects, a key (KAMF) for an AMF can be generated independently by the user equipment and by a V-SEAF from KV-SEAF. In aspects, the key KAMF is further generated by the UE and by a source AMF when performing horizontal key derivation, which persons skilled in the art will understand.

[0082] When deriving a key 420 (KV-SEAF) from Optionl: KH-SEAF or Option2: KAUSF, the following parameters may be used to form the input S to the key derivation function (KDF):FC = 0x6C,P0 = <serving network name>,L0 = length of <serving network name>.The input key KEY shall be KH -SEAF (Optionl) or KAUSF (Option2).

[0083] The serving network name is used in the derivation of the anchor key. It serves three purposes, namely:It binds the anchor key to the serving network by including the serving network identifier (SN Id).It makes sure that the anchor key is specific for authentication between a 5G core network and a UE by including a service code set to "6G".Optionally, Access type for which the VPLMN anchor key is derived. This means for each access type, there could be different V-SEAF keys.

[0084] The serving network name is the concatenation of a service code and the SN Id and access type with a separation character such that the service code prepends the SN Id and access type. Examples of format could be “6G:SN ID: Access type” or “6G:SN ID”.

[0085] The illustration of FIG. 4 is merely an example, and variations are contemplated to be within the scope of the present disclosure.

[0086] FIG. 5 is a diagram of an example embodiment of operations for generating a security key for a network function which serves as a security anchor. The operations are performed by the blocks shown at the top of FIG. 5, which include a UE, a MM NF (e.g., AMF), a network function serving as a security anchor in a H-PLMN (e.g., H-SEAF or AUSF, etc.), an AUSF, and a UDM. The network function serving as a security anchor in a H-PLMN will be referred to below a H-SEAF, but it will be understood that another network function serving as a security anchor may be used, instead. The services described below utilize a service-based architecture (SBA).

[0087] At operation 501, the UE transmits a registration request message to the MM NF, and the MM NF receives the registration request message from the UE. The communication occurs through a RAN node (e.g., as described in connection with FIG. 2). In the registration request, the UE indicates its security capabilities for the H-PLMN to the MM NF.

[0088] At operation 502, the MM NF invokes a Nausf_UEAuthentication_Authenticate service toward the AUSF, and the AUSF receives the service request from the MM NF. In theNausf UEAuthentication Authenticate request, the MM NF includes the UE’s security capabilities for the H-PLMN while also triggering primary authentication procedure.

[0089] At operation 503, the AUSF invokes a Nudm UEAuthentication Get service towards the UDM, and the UDM receives the service request from the AUSF. The AUSF obtains an authentication vector from the UDM. During the authentication vector generation, the AUSF / UDM generates a key (KAUSF) for the AUSF. Using the KAUSF (or any other key derived in the AUSF), the AUSF creates a key (KH -SEAF) for the network function providing the security anchor, and assigns a key set identifier (H-KSI) for the H-PLMN to the KH-SEAF.

[0090] At operation 504, the AUSF transmits a Nausf_UEAuthentication_Authenticate response to the MM NF, and the MM NF receives the Nausf UEAuthentication Authenticate response from the AUSF. The AUSF includes the H-KSI in the response.

[0091] At operation 505, the MM NF transmits an authentication request message to the UE, and the UE receives the authentication request message from MM NF. The authentication request message can include the H-KSI. For example, the authentication request message can be an authentication request for both a H-PLMN and a V-PLMN. The UE authenticates the network upon receiving the authentication request message.

[0092] At operation 506, the UE generates a key KH-SEAF from a key (e.g., KAUSF) for the AUSF and associates the KH-SEAF with the received H-KSI. In embodiments, they UE may have previously generated the KAUSF.

[0093] At operation 507, the UE constructs and transmits an authentication response message for both a V-PLMN and a H-PLMN to the MM NF, and the MM NF receives the authentication response message from the UE.

[0094] At operation 508, the MM NF invokes a Nausf_UEAuthentication_Authenticate service to the AUSF, and the AUSF receives the service request from the MM NF. The AUSF selects an H-SEAF (or alternatively, the UDM can perform the H-SEAF selection and provide the AUSF with addressing information of the selected H-SEAF, e.g. at operation 503). The AUSF transmits addressing information of the selected H-SEAF to the MM NF,and the MM NF receives the addressing information of the selected H-SEAF from the AUSF.

[0095] At operation 509, the AUSF invokes a Nh-seaf service to the selected H-SEAF, and the H-SEAF receives the service request from the AUSF. The service may be based on the service-based architecture (SB A). In the request used to invoke the Nh-seaf service, the AUSF includes the UE’ s security capabilities (e.g., received at operation 502), the KH-SEAF associated with the H-KSI (KH-SEAF / H-KSI made available at operation 503), and MM NF addressing information. In addition, the H-SEAF generates keys for encryption and integrity protection (e.g., as shown in FIG. 4).

[0096] At operation 510, the H-SEAF stores the received information and transmits a response to the AUSF. The AUSF receives the response from the H-SEAF.

[0097] The following will describe various operations of FIG. 5 from various perspectives.

[0098] From the perspective of a UE, the operations include: accessing at least one key derivation parameter (e.g., operation 506); and generating a first key (KH-SEAF) for a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), where the first key is generated based on a key derivation function and the at least one key derivation parameter (e.g., operation 506).

[0099] From the perspective an AUSF, the operations include: accessing at least one key derivation parameter (e.g., operation 503); and generating a first key (KH-SEAF) for a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), where the first key is generated based on a key derivation function and the at least one key derivation parameter (e.g., operation 503).

[0100] From the perspective a H-SEAF, the operations include: receiving, from an authentication server function (AUSF), information comprising at least one of the following: information regarding UE security capabilities for a home public land mobile network (H-PLMN), a first key (KH-SEAF) for a network function configured to serve as a security anchor for the H-PLMN, a key set identifier (KSI),and mobility management network function (MM NF) addressing information (e.g., operation 509); and storing the received information (e.g., operation 509).

[0101] FIG. 5 and the description above are merely examples, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the operations may include other operations not illustrated in FIG. 5. In embodiments, the operations may not include every operation illustrated in FIG. 5. In embodiments, operations illustrated as separate operations may be performed by a combined operation. In embodiments, operations illustrated as a single operation may be performed by separate operations. Such and other embodiments are contemplated to be within the scope of the present disclosure.

[0102] FIG. 6 is a diagram of an example embodiment of an uplink communication using a network function which serves as a security anchor. The operations are performed by the blocks shown at the top of FIG. 6, which include a UE, a network function serving as a security anchor in a H-PLMN (e.g., H-SEAF or AUSF, etc.), and a network function of the H-PLMN (H-PLMN NF). The network function serving as a security anchor in a H-PLMN will be referred to below a H-SEAF, but it will be understood that another network function serving as a security anchor may be used, instead. Communications between the UE and the H-SEAF are routed through a RAN node (e.g., as described in connection with FIG. 2) and through a MM NF (e.g., 310, FIG. 3), which are not shown to provide clearer illustration.

[0103] At operation 601, when a UE needs to transmit a message to a H-PLMN NF (denoted as MESSAGE X), the UE creates a message to be sent to the H-SEAF (denoted as MESSAGE A). In MESSAGE A, the UE includes:MESSAGE X; andan indicator identifying the type of the H-PLMN NF (e.g., PCF, etc.) or indicating a service provided by the H-PLMN NF (e.g., UE policy, etc.). For example, if MESSAGE X is for UE policy, the indicator can be set to “H-PCF” or “UE policy.”The UE encrypts and integrity protects MESSAGE A. The UE transmits the encrypted and integrity protected MESSAGE A to the H-SEAF, and the H-SEAF receives the encrypted and integrity protected MESSAGE A from the UE.

[0104] At operation 602, the H-SEAF decrypts MESSAGE A and performs integrity check for MESSAGE A. Based on the indicator identifying the type of the H-PLMN NF (e.g., PCF, etc.) or indicating a service provided by the H-PLMN NF (e.g., UE policy, etc.), the H-SEAF determines that MESSAGE X should be transmitted to the particular H-PLMN NF.

[0105] If the H-SEAF does not have stored addressing information for the H-PLMN NF, the H-SEAF can obtain addressing information for the H-PLMN NF. In order to obtain addressing information for the H-PLMN NF, the H-SEAF can perform H-PLMN NF selection or the H-SEAF can contact another network function in the H-PLMN, e.g., UDM, and receive the addressing information for the H-PLMN NF from the UDM.

[0106] The H-SEAF transmits MESSAGE X to the H-PLMN NF, which is reachable using the addressing information, and the H-PLMN NF receives the MESSAGE X from the H-SEAF.

[0107] The following will describe various operations of FIG. 6 from various perspectives.

[0108] From the perspective of a UE, the operations include: transmitting, towards a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), a first message comprising: a second message destined for a destination network function of the H-PLMN, and an indication regarding the destination network function (e.g., operation 601).

[0109] From the perspective an H-SEAF, the operations include: receiving, from a user equipment (UE), a first message comprising: a second message destined for a destination network function of the PLMN, and an indication regarding the destination network function (e.g., operation 601).

[0110] FIG. 6 and the description above are merely examples, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the operations may include other operations not illustrated in FIG. 6. In embodiments, the operations may not include every operation described in connection with FIG. 6. In embodiments, operations described as separate operations may be performed by a combined operation. In embodiments, operations illustrated or described as a single operation may be performed by separateoperations. Such and other embodiments are contemplated to be within the scope of the present disclosure.[OHl] FIG. 7 is a diagram of an example embodiment of a downlink communication using a network function which serves as a security anchor. The operations are performed by the blocks shown at the top of FIG. 7, which include a UE, a network function serving as a security anchor in a H-PLMN (e.g., H-SEAF or AUSF, etc.), and a network function of a H-PLMN (H-PLMN NF). The network function serving as a security anchor in a H-PLMN will be referred to below a H-SEAF, but it will be understood that another network function serving as a security anchor may be used, instead. Communications between the UE and the H-SEAF are routed through a RAN node (e.g., as described in connection with FIG. 2) and through a MM NF (e.g., 310, FIG. 3), which are not shown to provide clearer illustration.

[0112] At operation 701, when a H-PLMN NF needs to transmit a message to the UE (denoted as MESSAGE Y), the H-PLMN NF invokes a Nh-seaf service to the H-SEAF, and the H-SEAF receives the service request from the H-PLMN NF. The service request may utilize the service-based architecture (SB A). In the request invoking the Nh-seaf service, the H-PLMN NF includes MESSAGE Y.

[0113] If addressing information for the H-SEAF is not available in the H-PLMN NF, the H-PLMN NF obtains addressing information for the H-SEAF. In order to obtain addressing information for the H-SEAF, the H-PLMN NF can contact another network function in the HPLMN, e.g., UDM, and receive addressing information for the H-SEAF from the UDM.

[0114] At operation 702, the H-SEAF creates a message to be sent to the UE (denoted as MESSAGE B). In MESSAGE B, the H-SEAF includes:MESSAGE Y; andan indicator identifying the type of the H-PLMN NF (e.g., PCF, etc.) or indicating a service provided by the H-PLMN NF (e.g., UE policy, etc.) For example, if MESSAGE Y is for UE policy, the indicator can be set to “H-PCF” or “UE policy.”

[0115] The H-SEAF encrypts and integrity protects MESSAGE B (if AEAD mode is used, then only one key is enough to both integrity protect and cipher). TheH-SEAF transmits the encrypted and integrity protected MESSAGE B to the UE, and the UE receives the MESSAGE B from the H-SEAF.

[0116] At operation 702, the UE decrypts MESSAGE B and performs integrity check for MESSAGE B. Based on the indicator identifying the type of the H-PLMN NF (e.g., PCF, etc.) or indicating a service provided by the H-PLMN NF (e.g., UE Policy, etc.), the UE determines that MESSAGE Y is transmitted from the particular H-PLMN NF.

[0117] The following will describe various operations of FIG. 7 from various perspectives.

[0118] From the perspective of a UE, the operations include: receiving, from a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), a first message comprising: a second message for the UE, and an indication regarding an initiating network function which transmitted the second message (e.g., operation 702).

[0119] From the perspective a H-SEAF, the operations include: transmitting, to a user equipment (UE), a first message comprising: a second message initiated by a network function and destined for the UE, and an indication regarding the initiating network function.

[0120] FIG. 7 and the description above are merely examples, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the operations may include other operations not illustrated in FIG. 7. In embodiments, the operations may not include every operation described in connection with FIG. 7. In embodiments, operations described as separate operations may be performed by a combined operation. In embodiments, operations illustrated or described as a single operation may be performed by separate operations. Such and other embodiments are contemplated to be within the scope of the present disclosure.

[0121] FIG. 8 is a diagram of an example embodiment of security mode control between a user equipment and a network function which serves as a security anchor. The operations are performed by the blocks shown at the top of FIG. 8, which include a UE and a network function serving as a security anchor in a H-PLMN (e.g., H-SEAF or AUSF, etc.). The network function serving as a security anchor in a H-PLMN will be referred to below a H-SEAF, but it will be understood thatanother network function serving as a security anchor may be used, instead. Communications between the UE and the H-SEAF are routed through a RAN node (e.g., as described in connection with FIG. 2) and through a MM NF (e.g., 310, FIG.3), which are not shown to provide clearer illustration.

[0122] At operation 801, the H-SEAF creates a SECURITY MODE COMMAND message. In the message, the H-SEAF includes the UE’s security capabilities (received in operation 509 of FIG. 5) and the H-KSI (received in operation 509 of FIG. 5). The H-SEAF selects security algorithms for encryption and integrity protection and includes identities for the selected security algorithms in the SECURITY MODE COMMAND message. Using the integrity protection key derived from the KH-SEAF identified by the H-KSI and the selected integrity protection algorithm, the H-SEAF integrity protects the SECURITY MODE COMMAND message.

[0123] The H-SEAF transmits the integrity protected home network (HN) SECURITY MODE COMMAND message to the MM NF, which can be reached using the addressing information, e.g., received in operation 509 of FIG. 5, and the MM NF receives the message from the H-SEAF. The MM NF forwards the HN SECURITY MODE COMMAND message by transmitting a mobility management (MM) message including the HN SECURITY MODE COMMAND message to the UE, and the UE receives the message from the MM NF. The MM message can be a REGISTRATION ACCEPT message or a DL NAS TRANSPORT message, among other possibilities.

[0124] At operation 802, upon receiving the HN SECURITY MODE COMMAND message, the UE (i) checks if the received security capabilities match the UE’s own security capabilities and (ii) performs the integrity protection check.

[0125] The UE stores the H-KSI and selected security algorithms. The UE creates a HN SECURITY MODE COMPLETE message. The HN SECURITY MODE COMPLETE message is integrity protected and encrypted using the selected security algorithms and integrity protection / encryption keys derived from the KH-SEAF identified by the H-KSI. The UE transmits the integrity protected / encrypted HN SECURITY MODE COMPLETE message to the MM NF, and the MM NF receives the message from the UE. The MM NF forwards the message to the H-SEAF, and the H-SEAF receives the message from the MM NF.

[0126] From then on, messages exchanged between the UE and the H-SEAF are integrity protected and encrypted using the integrity protection / encry ption keys and the security algorithms.

[0127] If the check in (i) or in (ii) fails, the UE transmits a HN SECURITY MODE REJECT message to the H-SEAF via the MM NF, and the H-SEAF receives the message from the UE via the MM NF. The reject message can include a cause value indicating why the command was rejected.

[0128] FIG. 8 and the description above are merely examples, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the operations may include other operations not illustrated in FIG. 8. In embodiments, the operations may not include every operation described in connection with FIG. 8. In embodiments, operations described as separate operations may be performed by a combined operation. In embodiments, operations illustrated or described as a single operation may be performed by separate operations. Such and other embodiments are contemplated to be within the scope of the present disclosure.

[0129] Referring now to FIG. 9, there is shown a block diagram of example components of a UE or a network apparatus. The apparatus includes an electronic storage (e.g., non-transitory processor-readable medium) 910, a processor 920, a memory 950, and a network interface 940. The various components may be communicatively coupled with each other. The processor 920 may be and may include any type of processor, such as a single-core central processing unit (CPU), a multi-core CPU, a microprocessor, a digital signal processor (DSP), a System-on-Chip (SoC), or any other type of processor. The memory 950 may be a volatile type of memory, e.g., RAM, or a non-volatile type of memory, e.g., NAND flash memory. The memory 950 includes processor-readable instructions that are executable by the processor 920 to cause the apparatus to perform various operations, including those mentioned herein, such as the operations described in connection with FIGS. 3-8.

[0130] The electronic storage 910 may be and include any type of electronic storage used for storing data, such as hard disk drive, solid state drive, and / or optical disc, among other types of electronic storage. The electronic storage 910 stores processor-readable instructions for causing the apparatus to perform its operationsand stores data associated with such operations, such as storing data relating to 5G NR standards, among other data. The network interface 940 may implement wireless networking technologies such as 5G NR and / or other wireless networking technologies.

[0131] The components shown in FIG. 9 are merely examples, and persons skilled in the art will understand that an apparatus includes other components not illustrated and may include multiples of any of the illustrated components. Such and other embodiments are contemplated to be within the scope of the present disclosure.

[0132] Further embodiments of the present disclosure include the following examples. In the following, any “means” may be implemented by at least one processor and processor-executable instructions, unless the context indicates otherwise. Any “means” for receiving or transmitting may be implemented by a transceiver. The notation Example n.x refers to any Example having a value for n and a value for x.

[0133] Example 1.1. A method in a user equipment (UE), comprising: transmitting, towards a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), a first message comprising:a second message destined for a destination network function of the H-PLMN, andan indication regarding the destination network function.

[0134] Example 1.2. The method of Example 1.1, wherein the indication regarding the destination network function indicates a network function type of the destination network function.

[0135] Example 1.3. The method of Example 1.1, wherein the indication regarding the destination network function indicates a service provided by the destination network function.

[0136] Example 1.4. The method of any one of Examples 1.1-1.3, wherein the first message is encrypted and integrity protected.

[0137] Example 1.5. The method of any one of Examples 1.1-1.4, wherein the first message is encrypted and integrity protected using at least one of the following:a key (KH -SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrity protection, wherein the KSI and the identities of the security algorithms for encryption and integrity protection are received via a third message from the network function configured to serve as the security anchor for the H-PLMN.

[0138] Example 1.6. The method of Example 1.5, further comprising: determining whether replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0139] Example 1.7. The method of Example 1.5 or Example 1.6, further comprising:generating a fourth message in response to the third message; encrypting and integrity protecting the fourth message based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message; andtransmitting the encrypted and integrity protected fourth message to the network function configured to serve as the security anchor for the H-PLMN.

[0140] Example 1.8. The method of Example 1.7, wherein the fourth message is encrypted and integrity protected if a result of the determining indicates that the replayed information, in the third message, regarding the security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0141] Example 1.9. The method of Example 1.8,wherein the third message is a home network (HN) security mode command, andwherein the fourth message is a HN security mode complete message.

[0142] Example 1.10. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of Examples 1.1-1.9.

[0143] Example 1.11. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of Examples 1.1-1.9.

[0144] Example 2.1. An apparatus comprising:means for transmitting, towards a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), a first message comprising:a second message destined for a destination network function of the H-PLMN, andan indication regarding the destination network function.

[0145] Example 2.2. The apparatus of Example 2.1, wherein the indication regarding the destination network function indicates a network function type of the destination network function.

[0146] Example 2.3. The apparatus of Example 2.1, wherein the indication regarding the destination network function indicates a service provided by the destination network function.

[0147] Example 2.4. The apparatus of any one of Examples 2.1-2.3, wherein the first message is encrypted and integrity protected.

[0148] Example 2.5. The apparatus of any one of Examples 2.1-2.4, wherein the first message is encrypted and integrity protected using at least one of the following:a key (KH -SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrity protection, wherein the KSI and the identities of the security algorithms for encryption and integrity protection are received via a third message from the network function configured to serve as the security anchor for the H-PLMN.

[0149] Example 2.6. The apparatus of Example 2.5, further comprising:means for determining whether replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0150] Example 2.7. The apparatus of Example 2.5 or Example 2.6, further comprising:means for generating a fourth message in response to the third message; means for encrypting and integrity protecting the fourth message based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message; andmeans for transmitting the encrypted and integrity protected fourth message to the network function configured to serve as the security anchor for the H-PLMN.

[0151] Example 2.8. The apparatus of Example 2.7, wherein the fourth message is encrypted and integrity protected if a result of the determining indicates that the replayed information, in the third message, regarding the security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0152] Example 2.9. The apparatus of Example 2.8,wherein the third message is a home network (HN) security mode command, andwherein the fourth message is a HN security mode complete message.

[0153] Example 3.1. A method in a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), comprising:receiving, from a user equipment (UE), a first message comprising:a second message destined for a destination network function of the PLMN, andan indication regarding the destination network function.

[0154] Example 3.2. The method of Example 3.1, wherein the indication regarding the destination network function indicates a network function type of the destination network function.

[0155] Example 3.3. The method of Example 3.1, wherein the indication regarding the destination network function indicates a service provided by the destination network function.

[0156] Example 3.4. The method of any one of Examples 3.1-3.3, wherein the first message is encrypted and integrity protected.

[0157] Example 3.5. The method of any one of Examples 3.1-3.4, further comprising:identifying the destination network function based on the indication regarding the destination network; andtransmitting the second message to the destination network function.

[0158] Example 3.6. The method of any one of Examples 3.1-3.5, further comprising:decrypting the first message; andperforming integrity check for the first message.

[0159] Example 3.7. The method of Example 3.6, wherein the decrypting and the performing the integrity check are based on at least one of the following:a key (Ku -SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrity protection, wherein the KSI and the identities of the security algorithms for encryption and integrity protection are sent via a third message to the UE.

[0160] Example 3.8. The method of Example 3.7, further comprising: receiving, from the UE, an encrypted fourth message responding to the third message,wherein the fourth message is encrypted and integrity protected based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message.

[0161] Example 3.9. The method of Example 3.7, wherein the fourth message indicates that replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0162] Example 3.10. The method of Example 3.8,wherein the third message is a home network (HN) security mode command, andwherein the fourth message is a HN security mode complete message.

[0163] Example 3.11. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of Examples 3.1-3.10.

[0164] Example 3.12. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of Examples 3.1-3.10.

[0165] Example 4.1. An apparatus providing a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), the apparatus comprising:means for receiving, from a user equipment (UE), a first message comprising:a second message destined for a destination network function of the PLMN, andan indication regarding the destination network function.

[0166] Example 4.2. The apparatus of Example 4.1, wherein the indication regarding the destination network function indicates a network function type of the destination network function.

[0167] Example 4.3. The apparatus of Example 4.1, wherein the indication regarding the destination network function indicates a service provided by the destination network function.

[0168] Example 4.4. The apparatus of any one of Examples 4.1-4.3, wherein the first message is encrypted and integrity protected.

[0169] Example 4.5. The apparatus of any one of Examples 4.1-4.4, further comprising:means for identifying the destination network function based on the indication regarding the destination network; andmeans for transmitting the second message to the destination network function.

[0170] Example 4.6. The apparatus of any one of Examples 4.1-4.5, further comprising:means for decrypting the first message; andmeans for performing integrity check for the first message.

[0171] Example 4.7. The apparatus of Example 4.6, wherein the decrypting and the performing the integrity check are based on at least one of the following:a key (KH -SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrity protection, wherein the KSI and the identities of the security algorithms for encryption and integrity protection are sent via a third message to the UE.

[0172] Example 4.8. The apparatus of Example 4.7, further comprising:means for receiving, from the UE, an encrypted fourth message responding to the third message,wherein the fourth message is encrypted and integrity protected based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message.

[0173] Example 4.9. The apparatus of Example 4.7, wherein the fourth message indicates that replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

[0174] Example 4.10. The apparatus of Example 4.8,wherein the third message is a home network (HN) security mode command, andwherein the fourth message is a HN security mode complete message.

[0175] The embodiments and aspects disclosed herein are examples of the present disclosure and may be embodied in various forms. For instance, although certain embodiments herein are described as separate embodiments, each of theembodiments herein may be combined with one or more of the other embodiments herein. Specific structural and functional details disclosed herein are not to be interpreted as limiting, but as a basis for the claims and as a representative basis for teaching one skilled in the art to variously employ the present disclosure in virtually any appropriately detailed structure. Like reference numerals may refer to similar or identical elements throughout the description of the figures.

[0176] The phrases “in an aspect,” “in aspects,” “in various aspects,” “in some aspects,” or “in other aspects” may each refer to one or more of the same or different aspects in accordance with this present disclosure. The phrase “a plurality of’ may refer to two or more.

[0177] The phrases “in an embodiment,” “in embodiments,” “in various embodiments,” “in some embodiments,” or “in other embodiments” may each refer to one or more of the same or different embodiments in accordance with the present disclosure. A phrase in the form “A or B” means “(A), (B), or (A and B) ” A phrase in the form “at least one of A, B, or C” means “(A); (B); (C); (A and B); (A and C); (B and C); or (A, B, and C) .”

[0178] Any of the herein described methods, programs, algorithms or codes may be converted to, or expressed in, a programming language or computer program. The terms “programming language” and “computer program,” as used herein, each include any language used to specify instructions to a computer, and include (but is not limited to) the following languages and their derivatives: Assembler, Basic, Batch files, BCPL, C, C+, C++, Delphi, Fortran, Java, JavaScript, machine code, operating system command languages, Pascal, Perl, PL1, Python, scripting languages, Visual Basic, metalanguages which themselves specify programs, and all first, second, third, fourth, fifth, or further generation computer languages. Also included are database and other data schemas, and any other meta-languages. No distinction is made between languages which are interpreted, compiled, or use both compiled and interpreted approaches. No distinction is made between compiled and source versions of a program. Thus, reference to a program, where the programming language could exist in more than one state (such as source, compiled, object, or linked) is a reference to any and all such states. Reference to a program may encompass the actual instructions and / or the intent of those instructions.

[0179] While aspects of the present disclosure have been shown in the drawings, it is not intended that the present disclosure be limited thereto, as it is intended that the present disclosure be as broad in scope as the art will allow and that the specification be read likewise. Therefore, the above description should not be construed as limiting, but merely as exemplifications of particular aspects. Those skilled in the art will envision other modifications within the scope and spirit of the claims appended hereto.

Claims

34I / We Claim:

1. A method in a user equipment (UE), comprising:transmitting, towards a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), a first message comprising:a second message destined for a destination network function of the H-PLMN, andan indication regarding the destination network function.

2. The method of claim 1, wherein the indication regarding the destination network function indicates a network function type of the destination network function.

3. The method of claim 1, wherein the indication regarding the destination network function indicates a service provided by the destination network function.

4. The method of any one of claims 1-3, wherein the first message is encrypted and integrity protected.

5. The method of any one of claims 1-4, wherein the first message is encrypted and integrity protected using at least one of the following:a key (Ku -SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrity protection,wherein the KSI and the identities of the security algorithms for encryption and integrity protection are received via a third message from the network function configured to serve as the security anchor for the H-PLMN.

6. The method of claim 5, further comprising:35determining whether replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

7. The method of claim 5 or claim 6, further comprising:generating a fourth message in response to the third message; encrypting and integrity protecting the fourth message based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message; andtransmitting the encrypted and integrity protected fourth message to the network function configured to serve as the security anchor for the H-PLMN.

8. The method of claim 7, wherein the fourth message is encrypted and integrity protected if a result of the determining indicates that the replayed information, in the third message, regarding the security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

9. The method of claim 8,wherein the third message is a home network (HN) security mode command, andwherein the fourth message is a HN security mode complete message.

10. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of claims 1-9.

11. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of claims 1-9.

12. A method in a network function configured to serve as a security anchor for a home public land mobile network (H-PLMN), comprising:receiving, from a user equipment (UE), a first message comprising: a second message destined for a destination network function of the PLMN, andan indication regarding the destination network function.

13. The method of claim 12, wherein the indication regarding the destination network function indicates a network function type of the destination network function.

14. The method of claim 12, wherein the indication regarding the destination network function indicates a service provided by the destination network function.

15. The method of any one of claims 12-14, wherein the first message is encrypted and integrity protected.

16. The method of any one of claims 12-15, further comprising: identifying the destination network function based on the indication regarding the destination network; andtransmitting the second message to the destination network function.

17. The method of any one of claims 12-16, further comprising: decrypting the first message; andperforming integrity check for the first message.

18. The method of claim 17, wherein the decrypting and the performing the integrity check are based on at least one of the following:a key (KH -SEAF) for the network function configured to serve as a security anchor for the H-PLMN associated with a key set identifier (KSI), and identities of security algorithms for encryption and integrity protection,wherein the KSI and the identities of the security algorithms for encryption and integrity protection are sent via a third message to the UE.

19. The method of claim 18, further comprising:receiving, from the UE, an encrypted fourth message responding to the third message,wherein the fourth message is encrypted and integrity protected based on the security algorithms for encryption and integrity protection and the key (KH-SEAF) for the network function configured to serve as the security anchor for the H-PLMN associated with the key set identifier (KSI) to provide an encrypted and integrity protected fourth message.

20. The method of claim 18, wherein the fourth message indicates that replayed information, in the third message, regarding security capabilities of the UE matches native information in the UE regarding the security capabilities of the UE.

21. The method of claim 19,wherein the third message is a home network (HN) security mode command, andwherein the fourth message is a HN security mode complete message.

22. An apparatus comprising:at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus to perform a method as in any one of claims 12-21.3823. A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus to perform a method as in any one of claims 12-21.