Methods and apparatus for non-access stratum security
Patent Information
- Application Number
- PCT/EP2026/053545
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-26
- Filing Date
- 2026-02-10
- Publication Date
- 2026-09-03
Smart Images

Figure EP2026053545_03092026_PF_FP_ABST
Abstract
Description
[0001] METHODS AND APPARATUS FOR NON-ACCESS STRATUM SECURITY
[0002] TECHNICAL FIELD
[0003] [1] Various example embodiments relate generally to wireless communication technology, and more particularly, to methods and apparatus for non-access stratum (NAS) security.
[0004] BACKGROUND
[0005] [2] The development of future communication technologies, such as the six generation (6G) mobile communication technology, will bring significant changes to communication modes. For example, an increasing variety of data (such as data for industrial Internet of Things (loT), data for artificial intelligence, and the like) are being collected from a terminal side and then transmitted to the network side. This requires changes and developments for NAS security, so as to meet requirements of various new business scenarios.
[0006] SUMMARY
[0007] [3] This summary is provided to introduce simplified concepts of the present disclosure. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0008] [4] According to a first aspect of the disclosure, there is provided a method performed at a terminal device. The method comprises transmitting to a core network, first information indicating one or more modes of non-access stratum (NAS) security supported by the terminal device; receiving from the core network, second information indicating an accepted mode of NAS security; and establishing a NAS connection with a network function based on the accepted mode of NAS security.
[0009] [5] According to some embodiments, the first information may be transmitted via a message of registration request to a first network function for mobility management.
[0010] [6] According to some embodiments, the first information is transmitted via an uplink NAS message after a primary authentication for the terminal device.
[0011] [7] According to some embodiments, the second information may be received in a message of registration response, or a message of authentication response.
[0012] [8] According to some embodiments, the method may further comprise receiving third information indicating modes of NAS security supported by a plurality of network functions. The third information may be received from at leastone of the following: a first network function for mobility management, a third network function in a home network of the terminal device, or a network function for policy control.
[0013] [9] According to some embodiments, the method may further comprise, utilizing at least one of the first information, the second information and the third information as input parameters to verify an authentication challenge in the message of authentication response, in case that the second information is received in a message of authentication response. The authentication challenge may be an authentication token (AUTN). The method may further comprise, in case that a verification of the authentication challenge is successful, utilizing at least one of the first information, the second information and the third information as input parameters for key generation. The at least one of the second information and the third information may be utilized for generation of a key KAUSF.
[0014]
[0010] According to some embodiments, the method may further comprise, determining whether distributed NAS is supported by a second network function, in case that the accepted mode of NAS security is hybrid NAS.
[0015]
[0011] According to some embodiments, the method may further comprise establishing a NAS connection with a second network function by using a separate security association dedicated for the second network function, in case that the accepted mode of NAS security is distributed NAS, or in case that the accepted mode of NAS security is hybrid NAS while the second network function supports distributed NAS.
[0016]
[0012] According to a second aspect of the disclosure, there is provided a method performed at a first network function for mobility management. The method comprises determining an accepted mode of non-access stratum (NAS) security to be used for the terminal device; and transmitting to the terminal device, second information indicating the accepted mode of NAS security.
[0017]
[0013] According to some embodiments, the method may further comprise receiving from the terminal device, a message of registration request which comprises first information indicating one or more modes of NAS security supported by the terminal device.
[0018]
[0014] According to some embodiments, the method may further comprise receiving an uplink NAS message from a terminal device after a primary authentication for the terminal device. The uplink NAS message comprises first information indicating one or more modes of NAS security supported by the terminal device.
[0015] According to some embodiments, the second information may be transmitted to the terminal device via a message of registration response, or a message of authentication response.
[0019]
[0016] According to some embodiments, the method may further comprise determining whether the one or more modes of NAS security is supported by the first network function.
[0020]
[0017] According to some embodiments, the method may further comprise transmitting the first information to a third network function; and receive the second information from the third network function. The third network function is a network function for authentication and unified data management in a home network of the terminal device. The method may further comprise receiving from the third network function, third information indicating modes of NAS security supported by a plurality of network functions. The method may further comprise transmitting the received third information to the terminal device.
[0021]
[0018] According to some embodiments, the method may further comprise obtaining information on modes of NAS security supported by a plurality of network functions; and determining the accepted mode of NAS security based on the obtained information.
[0022]
[0019] According to some embodiments, the method may further comprise retrieveing from a network repository function, respective modes of NAS security supported by each of the plurality of network functions.
[0023]
[0020] According to some embodiments, the method may further comprise receiving from at least one network function of the plurality of network functions, a subscription request for NAS security support for the at least one network function; and determining according to the subscription request, that the at least one network function do not support distributed NAS, and the other network functions of the plurality of network functions support distributed NAS.
[0024]
[0021] According to some embodiments, the method may further comprise receiving a message of policy configuration from a network function for policy control. The message of policy configuration comprises information on modes of NAS security supported by a plurality of network functions.
[0025]
[0022] According to some embodiments, the method may further comprise determining third information indicating modes of NAS security supported by the plurality of network functions based on the obtained information on modes of NAS security supported by a plurality of network functions; and transmit the determined third information to the terminal device.
[0026]
[0023] According to some embodiments, the method may further comprise, in case that the accepted mode of NAS security is hybrid NAS, transmitting to a secondnetwork function, a service request from the terminal device which comprises fourth information indicating that hybrid NAS is supported by the terminal device; and in response to the service request, receiving from the second network function, a fifth information indicating whether distributed NAS security is supported by the second network function or not. The method may further comprise notifying the terminal device that distributed NAS is supported by the second network function, in case that the fifth information indicates that distributed NSA is supported by the second network function. The method may further comprise providing NAS security for data transfer between the terminal device and the second network function, in case that the fifth information indicates that distributed NSA is not supported by the second network function.
[0027]
[0024] According to a third aspect of the disclosure, there is provided a method performed at a second network function in a core network, the method comprising: transmitting information indicating a mode of non-access stratum (NAS) security supported by the second network function, to a network repository function or a first network function for mobility management.
[0028]
[0025] According to some embodiments, the method may further comprise establishing a NAS connection with a terminal device by using a separate security association dedicated for the second network function, in case that the second network function supports distributed NAS.
[0029]
[0026] According to some embodiments, the method may further comprise receiving a service request from a terminal device which comprises fourth formation indicating that hybrid NAS is supported by the terminal device; and in response to the service request, transmitting to the first network function, fifth information indicating whether distributed NAS is supported by the second network function or not.
[0030]
[0027] According to some embodiments, the method may further comprise transmitting to the first network function, a subscription request for NAS security support for the second network function. The method may further comprise transmitting to the first network function, a request for NAS security; and receiving from the first network function, information related to NAS security.
[0031]
[0028] According to a fourth aspect of the disclosure, there is provided a method performed at a network repository function in a core network. The method comprises: receiving from each of one or more network functions, information indicating modes of non-access stratum (NAS) supported by respective network functions; and storing the received information for each of the one or more network functions.
[0029] According to some embodiments, the method may further comprise: receiving a request for a mode of NAS security supported by a particular network function; and in response to the retrieve request, retrieving and transmit the mode of NAS security supported by the particular network function. The request may be received from a first network function for mobility management, or from a network function for unified data management.
[0032]
[0030] According to a fifth aspect of the disclosure, there is provided a method performed at a third network function in a core network. The method comprises: obtaining information indicating respective modes of non-access stratum (NAS) security supported by each of one or more network functions; obtaining first information indicating one or more modes of NAS security supported by a terminal device; determining an accepted mode of NAS security to be used for the terminal device; and transmitting to the terminal device, second information indicating the accepted mode of NAS security.
[0033]
[0031] According to some embodiments, the first information may be received in an authentication request from a first network function for mobility management.
[0034]
[0032] According to some embodiments, the first information may be retrieved from subscriber data of the terminal device which is stored in the third network function.
[0035]
[0033] According to some embodiments, the second information may be transmitted to the terminal device via a message of authentication response.
[0036]
[0034] According to some embodiments, the first information is received in an uplink NAS message from the terminal device after primary authentication for the terminal device.
[0037]
[0035] According to some embodiments, the method may further comprise transmitting third information indicating modes of NAS security supported by the plurality of network functions.
[0038]
[0036] According to some embodiments, the method may further comprise: in case that the first information is received in a message of authentication request, calculating an authentication challenge by utilizing at least one of the second information and the third information as inputs parameter; and transmit the authentication challenge to the terminal device in the message of authentication response. The authentication challenge may be an authentication token (AUTN). The method may further comprise utilizing the at least one of the second information and the third information as input parameters for key generation. The at least one of the second information and the third information may be utilized for generation of a key KAUSF.
[0037] According to a sixth aspect of the disclosure, there is provided an apparatus at a terminal device. The apparatus comprises at least one processor, and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods according to the first aspect of the disclosure.
[0039]
[0038] According to a seventh aspect of the disclosure, there is provided an apparatus at a first network function for mobility management. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods according to the second aspect of the disclosure.
[0040]
[0039] According to an eighth aspect of the disclosure, there is provided an apparatus at a second network function in a core network. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods according to the third aspect of the disclosure.
[0041]
[0040] According to a ninth aspect of the disclosure, there is provided an apparatus at a network repository function in a core network. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods according to the fourth aspect of the disclosure.
[0042]
[0041] According to a tenth aspect of the disclosure, there is provided an apparatus at a third network function in a core network. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods according to the fifth aspect of the disclosure.
[0043]
[0042] According to an eleventh aspect of the disclosure, there is provided a computer-readable medium having computer program codes embodied thereon which, when executed by a processor, cause the processor to perform any of the methods according to the first, second, third, fourth, and fifth aspects of the disclosure.
[0044]
[0043] According to a twelfth aspect of the disclosure, there is provided a computer program product comprising computer programs or instructions which, when executed by a processor, cause the processor to perform any of the methods according to the first, second, third, fourth, and fifth aspects of the disclosure.
[0045]
[0044] In some embodiments of the above aspects, at least one of the following features would be further comprised:• The one or more modes of NAS security may comprise at least one of following modes of NAS security: distributed NAS; single NAS; or hybrid NAS;
[0046] • The accepted mode of NAS security is one of following modes of NAS security: distributed NAS; single NAS; or hybrid NAS.
[0047] • The first information may be indicated by a predefined parameter or is comprised in a concealed part of a subscription concealed identifier of the terminal device;
[0048] • The third information may indicate a bit map indicating whether the mode of distributed NAS is supported or not per network function;
[0049] • The mode of NAS security supported by the second network function may comprise any of following modes ofNAS security: distributed NAS; or single NAS.
[0050]
[0045] It is to be understood that the summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.
[0051] BRIEF DESCRIPTION OF THE DRAWINGS
[0052]
[0046] Some examples will now be described with reference to the accompanying drawings in which:
[0053]
[0047] FIG. 1 illustrates exemplary network architecture of modular NAS;
[0054]
[0048] FIG. 2 illustrates exemplary protocol architecture of modular NAS;
[0055]
[0049] FIG. 3 illustrates an exemplary security architecture of modular NAS;
[0056]
[0050] FIG. 4 illustrates exemplary network architectures of three modes ofNAS security;
[0057]
[0051] FIG. 5 illustrates an exemplary signaling procedure for NAS security according to an example of the present disclosure;
[0058]
[0052] FIG. 6 illustrates another exemplary signaling procedure for NAS security according to an example of the present disclosure;
[0059]
[0053] FIG. 7 illustrates an exemplary signaling procedure for NAS security according to an example of the present disclosure;
[0060]
[0054] FIG. 8 illustrates another exemplary signaling procedure for serving network-controlled NAS security according to an example of the present disclosure;
[0061]
[0055] FIG. 9 illustrates an exemplary format of bit map for a per module indication ofNAS support according to examples of the present disclosure;
[0056] FIG. 10 is a flow chart depicting a method performed at a terminal device (such as UE) for serving network-controlled NAS security according to examples of the present disclosure;
[0062]
[0057] FIG. 11 is a flow chart depicting a method performed at a network function (such as MM NF) for serving network-controlled NAS security according to examples of the present disclosure;
[0063]
[0058] FIG. 12 illustrates an exemplary signaling procedure for home network-controlled NAS security according to an example of the present disclosure;
[0064]
[0059] FIG. 13 illustrates an exemplary generation procedure for SUCI according to examples of the present disclosure;
[0065]
[0060] FIG. 14 illustrates an exemplary generation procedure for security keys according to examples of the present disclosure;
[0066]
[0061] FIG. 15 is a flow chart depicting a method performed at a terminal device (such as UE) for home network-controlled NAS security according to examples of the present disclosure;
[0067]
[0062] FIG. 16 is a flow chart depicting a method performed at a network function (such as MM NF in 6G core network) for home network-controlled NAS security according to examples of the present disclosure;
[0068]
[0063] FIG. 17 is a flow chart depicting a method performed at another network function (such as AUSF / UDM) for home network-controlled NAS security according to examples of the present disclosure;
[0069]
[0064] FIG. 18 illustrates an exemplary signaling procedure for policy -based NAS security according to an example of the present disclosure;
[0070]
[0065] FIG. 19A illustrates an exemplary signaling procedure for UE parameter update (UPU)-based NAS security according to an example of the present disclosure;
[0071]
[0066] FIGs. 19B-19D illustrate exemplary formats of UPU data according to an example of the present disclosure;
[0072]
[0067] FIG. 20 is a flow chart depicting a method performed at a terminal device (such as UE) for UPU based NAS security according to examples of the present disclosure;
[0073]
[0068] FIG. 21 is a flow chart depicting a method performed at a network function (such as UDM) for UPU based NAS security according to examples of the present disclosure;
[0074]
[0069] FIG. 22 is a flow chart depicting a method performed at a terminal device (such as UE) for NAS security according to examples of the present disclosure;
[0070] FIG. 23 is a flow chart depicting a method performed at a first network function (such as MM NF in 6G core network or AMF in 5G core network) for NAS security according to examples of the present disclosure;
[0075]
[0071] FIG. 24 is a flow chart depicting a method performed at a second network function for NAS security according to examples of the present disclosure;
[0076]
[0072] FIG. 25 is a flow chart depicting a method performed at a network repository function (such as NRF) for NAS security according to examples of the present disclosure;
[0077]
[0073] FIG. 26 is a flow chart depicting a method performed at a third network function in for NAS security according to examples of the present disclosure; and
[0074] FIG. 27 is a block diagram showing an apparatus suitable for practicing some examples of the disclosure.
[0078] DETAILED DESCRIPTION
[0079]
[0075] The following embodiments are exemplary. Although the specification may refer to “an”, “one”, or “some” example(s) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment(s), or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is de-scribed in connection of an embodiment, it is within the knowledge of one skilled in the art to apply such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described. It shall be understood that although the terms “first,” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.
[0080]
[0076] For the purposes of the present disclosure, the phrases “at least one of A or B”, “at least one of A and B”, and “A and / or B” means (A), (B), or (A and B). For the purposes of the present disclosure, the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).
[0081]
[0077] Embodiments described may be implemented in a communication network, such as any of the following radio access technologies (RATs): World-wide Interoperability for Micro-wave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGE radio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W-CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, and enhanced LTE (eLTE), 5G (also called NR), or any future RATsuch as 6G. Moreover, communication within the communication network may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), and / or Discrete Fourier Transform spread OFDM (DFT-s-OFDM).
[0082]
[0078] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0083]
[0079] As used herein, the term “terminal device” refers to any end device that may be capable of wireless communication. By way of example, a terminal device may be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), or a Mobile Station (MS). The terminal device may include a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, USB dongles, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless net-works, and the like.
[0084]
[0080] The term “network node” or “network function” refers to a network entity in a core network. Each NF provides functions by independent functions (services) and can be called from each other.
[0085]
[0081] As used herein, the terms “data,” “content,” “information,” and similar terms may be used interchangeably to refer to data capable of being transmitted, received and / or stored in accordance with embodiments of the present invention. Thus, use of any such terms should not be taken to limit the spirit and scope of embodiments of the present invention.
[0086]
[0082] As defined herein, a “computer-readable storage medium,” which refers to a non-transitory physical storage medium (e.g., volatile or non-volatile memory device), may be differentiated from a “computer-readable transmission medium,” which refers to an electromagnetic signal. Such a medium may take many forms, including, but not limited to a non-transitory computer-readable storage medium(e.g., non-volatile media, volatile media), and transmission media. Transmission media include, for example, coaxial cables, copper wire, fiber optic cables, and carrier waves that travel through space without wires or cables, such as acoustic waves and electromagnetic waves, including radio, optical and infrared waves. Signals include man-made transient variations in amplitude, frequency, phase, polarization or other physical properties transmitted through the transmission media. Examples of non-transitory computer-readable media include a magnetic computer readable medium (e.g., a floppy disk, hard disk, magnetic tape, any other magnetic medium), an optical computer readable medium (e.g., a compact disc read only memory (CD-ROM), a digital versatile disc (DVD), a Blu-Ray disc, or the like), a random access memory (RAM), a programmable read only memory (PROM), an erasable programmable read only memory (EPROM), a FLASH-EPROM, or any other non-transitory medium from which a computer may read. The term computer-readable storage medium is used herein to refer to any computer-readable medium except transmission media. However, it will be appreciated that where embodiments are described to use a computer-readable storage medium, other types of computer-readable mediums may be substituted for or used in addition to the computer-readable storage medium in alternative embodiments.
[0087]
[0083] As mentioned above, NAS security is required to be enhanced and developed, to meet requirements of various new business scenarios. For example, motivations for enhancement of NAS security may comprise the following points.
[0088] • Current NAS protocol is monolithic (which is also called as “one size fits all” approach). In this regard, devices must support all basic NAS modules. As such, only a single protocol is supported by a UE with a single NAS security termination in the core network.
[0089] • Modular NAS or distributed NAS is proposed to apply distributed NAS security termination. It enables a high degree of orthogonality in a terminal device and network functions. Synergies with modular 6G RRC design are easier to become possible.
[0090] • Independent design of NAS modules in respective network functions, e.g., in MM and SM, leads to a high flexibility when introducing new functions, and allows independent testing of NAS modules. This independent design also supports easier market take off.
[0091] • NAS security should allow optimal and tailored support of future use cases for a variety of different types of terminal device, such as terminal devices for enterprise, internet of things (loT), public safety, timing, positioning, ambient intelligence & internet of things (AIoT), or sensing, or terminaldevices with high capabilities, e.g., with extended reality (XR) or artificial intelligence (Al) capabilities.
[0092]
[0084] Embodiments of the present invention mainly focus on network architecture of modular NAS. Modular NAS is a proposed architectural change for 6G related to exchange of messages between a UE and the core network (so-called NAS messages). In network architecture of legacy NAS, e.g., NAS of a 5G core network, the NAS messages are terminated by a single NAS module located in an AMF. A NAS module in the AMF packs and unpacks contents of all NAS messages. There is no NAS module deployed in other NFs. If the contents of the NAS messages relate to another NF, SBI may be used for sending or receiving the contents between the AMF and another NF. In contrast, in the network architecture of modular NAS, other NFs may be deployed with NAS modules. A NAS module may be a part of a NF and is responsible for terminating NAS messages related to the functionality of this NF. NAS messages may be terminated by several different NAS modules in different NFs in the core network.
[0093]
[0085] In a variant of modular NAS, e.g., NAS of a 6G core network, NAS messages are exchanged between UE and NAS modules in NFs by using a mobility management network function (MM NF) for transport of the messages. That is, the MM NF transparently forwards complete NAS messages between the UE and a terminating NAS module in another NF, using service-based interfaces without consuming or modifying contents of the NAS messages.
[0094]
[0086] FIG. 1 illustrates an example of such network architecture 100 with point to point (P2P) NAS between a MM NF 130 in a 6G core network and UE 110 via a RAN node. As shown in FIG. 1, the MM NF 130 has a NAS module 131. Besides the MM NF 130, other NFs in the core network such as session management (SM) NF 140 and XX NF (referred to any other NF, e.g., location management (LM) NF or short message service (SMS) NF) 150 also have respective NAS modules 142 and 153. The UE 110 may have separate NAS modules (e.g., denoted as 111, 112, and 113) corresponding to NAS modules 131, 142, 153 of different NFs in the 6G core network, respectively. These NFs 140 and 150 may have their respective end-to-end NAS connections with UE 110 via the MM NF 130.
[0095]
[0087] FIG. 2 illustrates exemplary protocol architecture of modular NAS with P2P interface between RAN and core network. In the protocol stack, NAS protocol layers for NAS modules in respective NFs are called NAS-MM (for NAS module in MM NF), NAS-SM (for NAS module in SM NF), NAS-XX (for NAS module in XX NF), etc. UE may be configured with corresponding NAS protocol layers for associated NAS modules. These separate NAS modules enable distributed security termination of NAS connections in respective NFs. As shown in FIG. 2, a NASconnection between UE1 210 and MM NF 230 is terminated by NAS-MM 211 of the UE1 and NAS-MM 231 of the MM NF 230. A NAS connection between UE1 210 and SM NF 240 is terminated by NAS-SM 212 of the UE1 and NAS-SM 242 of the SM NF 240. A NAS connection between UE1 210 and XX NF 250 (referred to any other NF e.g., LM NF or SMS NF) is terminated by NAS-XX 213 of the UE1 and NAS-XX 253 of the XX NF 250. The respective NAS connections between UE1 210 and SM NF 240 and XX NF 250 may enable UE1 210 to perform bi-directional direct communication with respective NFs which is transparent to the MM NF 230 or the NAS module in the MM NF 230. In this regard, MM NF 230 may be responsible for purely relaying for the NAS connections between UE1 210 and SM NF 240 and XX NF 250.
[0096]
[0088] Independent UE temporary identifier (e.g., different GUTI) may be used for each of NAS terminations of an independent NAS connection. For example, UE1 210 and MM NF 230 can route NAS messages over a NAS connection 201 between UE1 210 and MM NF 230 by using a UE temporary identifier, e.g., MM-6G-GUTI. Similarly, UE1 210 and SM NF 240 can route the NAS messages over a NAS connection 202 between UE1 210 and SM NF 240 by using another different UE temporary identifier, e.g., SM-6G-GUTI. Between another NF (e.g., XX NF 250) and UE1 210, a UE temporary identifier “XX-6G-GUTI” can be used to route NAS messages over a NAS connection 203.
[0097]
[0089] Independent key set identities (KSIs) and parent keys are distributed for different NAS modules. A unique parent key may be distributed per NAS connection or per NAS module. This enables independent security associations to be used for different NAS connections. FIG. 3 illustrates exemplary security architecture of modular NAS which can provide distributed NAS security. It is noteworthy that the security architecture shown here is only used as an illustrative example, and it can take any suitable form. Currently, the specification in 3GPP of the security architecture of modular NAS is not settled.
[0098]
[0090] During a primary authentication and key agreement (AKA) procedure 301 (e.g., 5G AKA method or EAP method), UE 310 and a security key management function (SKMF) 350 in a core network can derive a parent key (denoted as Kp) from an anchor key (denoted as Ka). As shown at 301a and 301a’, different parent keys, such as Kpl and Kp2, may be derived from the Ka. SKMF 350 generates a set of key set identifiers (KSIs) and assigns each parent key with a unique KSI. For example, Ka may be KSEAF (security anchor function Key) or equivalent key in 6G communication system. SKMF 350 may be deployed or comprised in authentication server function (AUSF), security anchor function (SEAF), andaccess and mobility management function (AMF) of 5G core network or MM NF of 6G core network.
[0099]
[0091] In a message from the SKMF 350 to the UE 310 during the primary AKA procedure 301, the SKMF 350 provides the set of KSIs to the UE 310, as shown at 301b. The UE 310 associates the received set of KSIs with respective Kps. Each of the KSIs is associated with a specific NF.
[0100]
[0092] Meanwhile, inside the core network, the SKMF 350 distributes to an NF, a Kp and a KSI for the NF. For example, the SKMF 350 provides {Kp, KSI1} and {Kp, KSI2} to NF1 330 and NF2340, respectively.
[0101]
[0093] A NF (such as NF1 330) which terminates a direct interface with RAN 320 initiates a security mode control (SMC) procedure 302. The NF1 may be the AMF or equivalent NF in 6G communication system (e.g., MM NF). In this SMC procedure 302, the UE 310 and NF1 330 agree on KSI and security algorithms to be used for secure NAS connection between the UE 310 and NF1 330. As shown at 302a, in this SMC procedure 302, the UE 310 receives aKSIl from the NF1 330, and then identifies or derives an associated Kp (such as Kpl) according to the aKSIl . A NAS connection 360 may be established between NAS module 311 (e.g., MM-NAS module) of UE 310 and NAS module of NF1 330 (e.g., MM NF). An access stratum (AS)-level SMC also takes place to secure AS connection between the UE 310 and RAN 320.
[0102]
[0094] As another NAS connection becomes necessary, the UE 310 and a corresponding NF may perform another SMC procedure. For example, the UE 310 may need to establish a new PDU session, and then the UE 310 and an NF2 340 (e.g., an SM NF) perform a SMC procedure and agree on KSI and security algorithms to be used for securing a NAS connection between the UE 310 and the NF2340. As shown at 303a, in this SMC procedure 303, the UE 310 receives aKSI2 from the NF2 340, and then identifies or derives an associated Kp (such as Kp2) according to the aKSI2. Hence a new NAS connection 370 between the UE 310 and the NF2340 is established.
[0103]
[0095] In the architectures of modular NAS shown in FIGs. 1 to 3, each NF in the core network has a NAS module. Dedicated NAS security can be used between UE and respective NAS modules of each NFs. The situation in real network may be complex. In some scenarios, not all NFs can support dedicated NAS security. In some scenarios, not all terminal devices can support dedicated NAS security with each NAS module of different NFs in a core network. For example, constraint devices (e.g., a device terminal of IOT) might not have multiple separate NAS modules for supporting multiple NAS connections with respective NFs in the core network. In another example, some NFs do not want to provide or create separateNAS with UEs, no matter whether these NFs have a capability to support dedicated NAS security. In this case, dedicated NAS security association cannot be established between UE and these NFs, and traditional approach of NAS security can be used. In this regard, data transmission between UE and these NFs can reuse NAS security established at MM NF. There may occur a scenario in which some NFs in a core network could use dedicated NAS security, and some NFs (such as SMS NF) could still use traditional approaches.
[0104]
[0096] How UE and NFs can know which type of NAS security is to be utilized for data transmission between them is a problem. The present disclosure proposes some solutions to this problem. With examples of the present disclosure, NAS connection between UE and NF can be established based on modes of NAS security supported by the UE and the NF. The modes of NAS security may comprise the following three modes: distributed NAS security (also called as DNAS), single NAS security NAS (also called as SNAS), and hybrid NAS security (also called as HNAS).
[0105]
[0097] DNAS is a variant of modular NAS, in which dedicated security associations are used between UE and each NAS module in a core network. That is, NAS messages exchanged between the UE and an NAS module of a NF are encrypted / decrypted and integrity protected by the NAS module with security keys specific for this NAS module. FIG. 4 illustrates exemplary network architecture 402 of DNAS. In this mode, UE 410 is supporting dedicated security associations with each NAS modules (e.g., NAS modules 431, 442, 453, 464) in a network side, and all NFs in the core network are supporting dedicated NAS security associations per NF module towards UE. As shown FIG. 4, in this example, SM NF 440 has its dedicated security association with NAS module 412 in the UE 410, MM NF 430 has its dedicated security association with NAS module 411 in UE, LM NF 450 has its dedicated security association with NAS module 413 in UE, etc.
[0106]
[0098] In a mode of SNAS, the core network is supporting a single security association (terminated by MM NF or AMF) for all NAS modules of NFs. In the context of modular NAS, the term single NAS refers to a variant, in which the MM NF or AMF terminates the security associations for all NAS modules. All NAS modules would use one common NAS security. This approach is similar to that of the legacy 5G architecture, with the difference that also in this variant of modular NAS the MM NF does not terminate NAS containers itself. That is the MM NF does not pack or unpack the NAS messages for other NAS modules of the other NFs, but merely exchanges unprotected NAS messages with these NAS modules. FIG. 4 illustrates exemplary network architecture 401 of SNAS.
[0107]
[0099] Hybrid NAS (HNAS) is another variant of the modular NAS, in which for some of NAS modules of NFs in a core network dedicated security associations areused, and for some of the NAS modules of other NFs in the core network, a common security association (i.e., NAS security for connection between UE and MM NF) are used. In the latter case, the MM NF exchanges unprotected NAS messages with respective NAS modules of other NFs. For packets received from a NAS module without dedicated security, the MM NF adds encryption and integrity protection to the NAS message before sending to the UE. For packets received from the UE and intended for a NAS module without dedicated security, the MM NF decrypts the message and verifies integrity before sending the unprotected message to the NAS module. FIG. 4 illustrates exemplary network architecture 403 of HNAS. The Network is supporting usage of dedicated security associations on a per NAS module basis. MM NF 430 has its security association with NAS module 411 in UE 410, SM NF 440 has its dedicated security association with NAS module 402 in UE 412. All other NFs, such as LM NF 450 and SMS NF 460, could use security keys of the security association terminated in NAS module 431 to protect NAS messages, and don’t have security keys dedicated for LM NF 450 or SMS NF 460. The NAS modules (which do not support dedicated NAS security) of LM NF 450 and SMS NF 460 may not be shown in FIG. 4.
[0108]
[0100] UE and NFs may support at least one of the above three modes of NAS security. From the point of view of MM NF, it may work in a similar way in the modes of HNAS and SNAS. In both modes, MM NF would provide NAS security to NAS messages towards or from other NFs. For any other NF, what is considered is whether it supports DNAS or not.
[0109]
[0101] To at least partially tackle at least one of the above problems or other problems, there are proposed solutions to establish a NAS connection between UE and a NF based on modes of NAS security supported by the UE and the NF.
[0110]
[0102] FIG. 5 illustrates an exemplary signaling procedure for NAS security according to an example of the present disclosure. In the exemplary signaling procedure, a mode of NAS security to be used for NAS connection establishment may be negotiated on per NF via network repository function (NRF).
[0111]
[0103] At step 500, NFs in a core network transmit to NRF, an indication indicating their support for modes of NAS security. In an example, all NFs (except MM NF) supporting NAS will register with NRF for whether they support DNAS or not. But MM NF doesn’t do this, because the DNAS is expected to be supported by the MM NF by default. In an example, it may be determined that SM NF 530 does not support DNAS as shown at 500a, SMS NF 540 does not support DNAS as shown at 500b, and LM NF 560 supports DNAS as shown at 500c. The mode of NAS security supported by these NFs may be configured by a network operator of the core network. These register with the NRF 550 about their support for DNAS viaSBI interface. The SM NF 530 transmits to NRF 550, a message of Nnrf_NFManagement_Register with a “supportMultiNAS” flag set to False, as shown at 500d. The SMS NF 540 transmits to NRF 550, a message of Nnrf_NFManagement_Register with a “supportMultiNAS” flag set to False, as shown at 500e. The LM NF 560 transmits to NRF 550, a message of Nnrf_NFManagement_Register with a “supportMultiNAS” flag set to True, as shown at 500f. The MM NF 520 supports DNAS by default and thus does not need to further notify the NRF 550 about its support for DNAS.
[0112]
[0104] At step 501, UE 510 registers with the MM NF 520 and transmits an indication indicating its capabilities of support for one or more modes of NAS security. A message of registration request is sent from the UE 510 to the MM NF 520. The message of registration request comprises subscription concealed identifier (SUCI) of the UE 510 and UE capabilities with information of the one or more modes of NAS security supported by the UE 510. In an example, the one or more modes of NAS security supported by the UE 510 may be sent as enumeration. The one or more modes of NAS security may comprise at least one of DNAS, SNAS, and HNAS. In an example, there could be three possibilities which UE could propose as candidate mode of NAS security: only SNAS; only DNAS; or HNAS.
[0113]
[0105] At step 502, the MM NF 520 may store the UE capabilities with the information of the one or more modes of NAS security received at step 501. The MM NF 520 may determine an accepted mode of NAS security for the UE 510. In this regard, the MM NF 520 may determine whether it can support the one or more modes of NAS security. In some examples, the MM NF 520 can select a mode of NAS security from the one or more modes of NAS security, as the accepted mode of NAS security. For example, the selection at the MM NF 520 could be done if all the three modes of NAS security are supported by the UE510 and the MM NF 510. The selection may be performed based on network configuration, e.g., configured by a network operator. For example, a list of priorities for respective modes of NAS security may be pre-configured at the MM NF 520. These priorities may dynamically change, e.g., based on network conditions. The MM NF 520 may pass or notify information of the selected mode of NAS security in step 504.
[0114]
[0106] If none of the proposed modes of NAS security from UE, i.e., the one or more modes of NAS security received by the MM NF 520 at step 501, is supported by the MM NF 520, then by default single NAS (SNAS) is supported by both of the UE 510 and the MM NF 520.
[0115]
[0107] At step 503, a NAS security mode command (SMC) procedure is completed between the UE 510 and the MM NF 520. Then, a NAS connection (e.g., referredto as UE-MM NAS connection) may be established between the UE 510 and the MM NF 520.
[0116]
[0108] At step 504, a message of registration response is transmitted from the MM NF 520 to the UE 510. The message of registration response comprises a UE temporary identifier e.g., “6G MM GUTI”, which is distributed by the MM NF 520 to identify termination of the UE-MM NAS connection, and an indication indicating the accepted mode of NAS security to be used by the UE 510. For example, the indication is a flag set to True or False to indicate whether the one or more supported modes of NAS security sent in step 501 is accepted or not, or information of which of the one or more supported modes of NAS security is accepted.
[0117]
[0109] Then, the UE 510 can establish NAS connections or security association with NFs (e.g., SM NF 530, SMS NF 540, LM NF 560, and other NFs) in the core network based on the accepted mode of NAS security.
[0118]
[0110] In an example, a PDU session needs to be triggered. The UE 510 transmits to the MM NF 520, a PDU session or service request targeted for the SM NF 530, as shown at step 505.
[0119]
[0111] At step 506a, in response to the request, the MM NF 520 discovers supported modes of NAS security of the SM NF 530 from the NRF 550. For example, SBI communication request and response may be used at step 506a. In this regard, the MM NF 520 may send a message of discovery or a message of service request to the NRF 550, and in response receive information of modes of NAS security supported by the SM NF 530 in a NF profile or service response from the NRF 550. In this example, the MM NF 520 can determine that the SM NF 530 doesn’t support DNAS according to the discovered information.
[0120]
[0112] In case that the accepted mode of NAS security for the UE 510 is only DNAS, the establishment of PDU session with the SM NF 530 may fail if it is discovered that the SM NF 530 doesn’t support DNAS. In an example, it is always proposed to have the UE 510 to support SNAS as mandatory. So DNAS and HNAS will be an addition to that default one. In that case, UE PDU session establishment will not fail.
[0121]
[0113] In case that the accepted mode of NAS security for the UE 510 is HNAS, a PDU session may be established with utilizing security of the UE-MM NAS connection. There will be SBI communication request and response between the MM NF 520 and the SM NF 530 for the establishment of PDU session, as shown at step 506b and 506c. The MM NF 520 utilizes the security keys of the UE-MM NAS connection to transfer data of the PDU session. No separate SMC runs between the SM NF 530 and the UE 510. The MM NF 520 may transfer in a NAScontainer of the UE-MM NAS connection, the contents towards or from the SM NF 530 as well.
[0122]
[0114] In an example, NAS packets towards the SMS NF 540 need to be sent. At step 507, a discovery procedure is used by the MM NF 520 to detect that the SMS NF 540 doesn’t support DNAS, in a similar way to step 506a. So there are no separate runs between the SMS NF 540 and the UE 510. Instead, security keys of the UE-MM NAS connection are utilized to secure data transfer of the SMS NF 540. The MM NF 520 may inform the UE 510 in one of downlink packets to the UE 510 of this discovery result, when the MM NF 520 sends a packet for the SMS NF 540. The MM NF 520 may transfer in a NAS container of the UE-MM NAS connection, the contents towards or from the SMS NF 540 as well.
[0123]
[0115] During a location management session at step 508, the LM NF 560 runs an SMC procedure with the UE 510 directly. The MM NF 520 would know that the LM NF 560 is able to support DNAS by running a discovery procedure from the NRF 550 as described in step 506a. As the LM NF 560 runs the SMC procedure with the UE 510, this separate SMC indicates a support of DNAS for corresponding NAS module in the LM NF 560.
[0124]
[0116] FIG. 6 illustrates another exemplary signaling procedure for NAS security according to an example of the present disclosure. In the exemplary signaling procedure, a mode of NAS security to be used for NAS connection establishment may be negotiated on per NF without a NRF.
[0125]
[0117] At step 600, supported modes of NAS security of each NF in a core network are configured. In an example, SM NF 630 is configured to not support DNAS as shown at 600a, SMS NF 640 is configured to not support DNAS as shown at 600b, and LM NF 660 is configured to support DNAS as shown at 600c.
[0126]
[0118] Steps 601, 602, 603, and 604 may be performed in a similar way as the steps 501, 502, 503, and 504 described above, respectively. For some parts which have been described in the above examples, the description thereof is omitted here for brevity.
[0127]
[0119] At step 601, UE 610 registers with the MM NF 620 and transmits an indication indicating its capabilities for supporting one or more modes of NAS security. A message of registration request is sent from the UE 610 to the MM NF 620 with SUCI of the UE 610 and UE capabilities with information of the one or more modes of NAS security.
[0128]
[0120] At step 602, the MM NF 620 may store the UE capabilities with the information of the one or more supported modes of NAS security received at step 601. The MM NF 620 may determine an accepted mode of NAS security for the UE 610. In this regard, the MM NF 620 may determine whether it can support atleast one of the one or more modes of NAS security. A mode of NAS security can be selected from the one or more modes of NAS security, as the accepted mode of NAS security to be used by the UE 610.
[0129]
[0121] At step 603, a NAS SMC procedure is completed between the UE 610 and the MM NF 620. Then, a NAS connection (e.g., referred to as UE-MM NAS connection) may be established between the UE 610 and the MM NF 620.
[0130]
[0122] At step 604, a message of registration response is transmitted from the MM NF 620 to the UE 610. The message of registration response comprises a MM GUTI and an indication indicating the accepted mode of NAS security to be used by the UE 510. Then, the UE 610 can establish NAS connections with NFs (e.g., SM NF 630, SMS NF 640, LM NF 660, and other NFs) in the core network based on the accepted mode of NAS security.
[0131]
[0123] In an example, a PDU session needs to be triggered. The UE 610 transmits to the MM NF 620, a PDU session or service request targeted for the SM NF 630, as shown at step 605.
[0132]
[0124] In response to the request, the MM NF 620 would negotiate with the SM NF 630 for establishment of NAS connection for the PDU session. At step 606a, the MM NF 620 sends a message of SBI communication or request to the SM NF 630. The message comprises information of UE capability, which may contain information of algorithms supported by the UE 610 and the UE’s capability for supporting a mode of NAS security (i.e., the mode of NAS security accepted by the MM NF 620 previously).
[0133]
[0125] At step 606b, the SM NF 630 determines whether a dedicated NAS connection or security association can be created for the PDU session based on the UE’s capability and other information, such as policy and required encryption algorithms. In an example, the information of UE capability indicates support of DNAS. Based on this UE capability and related information, the SM NF 630 may find that a required encryption algorithm is not supported and then decides not to create a dedicated NAS connection for the PDU session between the UE 610 and the SM NF 630. That is, no separate SMC runs between the SM NF 630 and the UE 610. The PDU session may be established with utilizing security of the UE-MM NAS connection.
[0134]
[0126] Then, at step 606c, a SBI communication or response can be transmitted from the SM NF 630 to the MM NF 620, with an indication indicating that DNAS is not allowed (e.g., a flag “DNAS Not Allowed” set to True).
[0135]
[0127] At step 606d, MM NF 620 utilizes security keys of the UE-MM NAS connection to transfer data of the PDU session, based on the SBI communication orresponse at step 606c. The MM NF 620 may transfer in a NAS container of the UE-MM NAS connection, the contents towards or from the SM NF 630 as well.
[0136]
[0128] In an example, NAS packets towards the SMS NF 640 need to be sent. At step 607, a negotiation procedure for establishment of NAS connection for transfer of SMS packets would be performed between the MM NF 620 and the SMS NF 640 in a similar way as steps 606a, 606b, 606c. In an example, the SMS NF 640 may decide not to establish a dedicated NAS connection or security association as it doesn’t support DNAS. So no separate SMC runs between the SMS NF 640 and the UE 610. Instead, security keys of the UE-MM NAS connection are utilized to secure data transfer of the SMS NF 640.
[0137]
[0129] During a location management session at step 608, the LM NF 660 runs a SMC procedure with the UE 610 directly. A negotiation procedure for establishment of an NAS connection would be performed between the MM NF 620 and the LM NF 660 in a similar way as steps 606a, 606b, 606c. As the LM NF 660 runs the SMC procedure with the UE 610, this separate SMC indicates support of DNAS for corresponding NAS module in the LM NF 660.
[0138]
[0130] FIGs. 7 and 8 illustrate exemplary signaling procedures for serving network-controlled NAS security according to an example of the present disclosure. In these exemplary signaling procedures, MM NF in a serving network of a UE can obtain information related to a UE’s capabilities for support one or more modes of NAS security and information related to respective support for NAS security modes of other NFs, and accordingly make a comprehensive decision on an accepted mode of NAS security to be used by the UE based on the obtained information.
[0139]
[0131] In FIG. 7, NRF is involved in the signaling procedure. At step 700, NFs (except MM NF) in a core network transmit to NRF, an indication indicating their support for modes of NAS security. In an example, SM NF, SMS NF, and LMF NF register with the NRF 750 about their support for DNAS via SBI interface. For example, SM NF 730 and LM NF 760 use a message of Nnrf_NFManagement_Register with a “supportMultiNAS” flag set to True to indicate that they can support DNAS. SMS NF 740 uses a message of Nnrf_NFManagement_Register with a “supportMultiNAS” flag set to False to indicate that it doesn’t support DNAS.
[0140]
[0132] At step 701, UE 710 transmits a message of registration request to the MM NF 720, with SUCI of the UE 710 and UE capabilities. The UE capabilities comprise information of one or more modes of NAS security supported by the UE 710. In an example, the one or more modes of NAS security proposed by the UE 710 is HNAS.
[0133] At step 702, the MM NF 720 may store the UE capabilities with the information of the one or more supported modes of NAS security received at step 701. The MM NF 720 may determine whether it can support the one or more modes of NAS security proposed by the UE 710. If none of the proposed modes of NAS security from the UE 710 is supported by the MM NF 720, then by default single NAS (SNAS) is supported by both of the UE 710 and the MM NF 720.
[0141]
[0134] At step 703a, the MM NF 720 fetches information about the supported mode of NAS security of different NFs from the NRF 750. For example, An SBI communication request and response may be used at step 703a. In this regard, the MM NF 720 may send a message of service request to the NRF 750, and in response receive information about respective supported modes of NAS security of each NF in a service response from the NRF 750. As discussed above, what is considered for these NFs is whether it supports DNAS or not. Then, the received information may be about respective support for DNAS by each NF, such as, SM NF 730 supports DNAS, LM NF 760 supports DNAS, SMS NF 740 doesn’t support DNAS.
[0142]
[0135] At step 703b, the MM NF 720 may determine or select an accepted mode of NAS security for the UE 710, at least based on the one or more modes of NAS security proposed by UE 710 and the fetched information about supported mode of NAS security of different NFs. For example, if all of the NFs (except MM NF) do not support DNAS, SNAS may be determined as the accepted mode.
[0143]
[0136] At step 703c, a NAS SMC procedure is completed between the UE 710 and the MM NF 720. Then, a NAS connection (e.g., referred to as UE-MM NAS connection) may be established between the UE 710 and the MM NF 720.
[0144]
[0137] At step 704a, a message of registration response is transmitted from the MM NF 720 to the UE 710. The message of registration response comprises a temporary identifier, e.g., “6G MM GUTI”, to identify termination of the UE-MM NAS connection and an indication indicating the accepted mode of NAS security to be used by the UE 710.
[0145]
[0138] In an example, the message of registration response further comprises information indicating respective supported mode of NAS security of NFs in the core network. This information may be a value generated based on the fetched information about supported mode of NAS security of different NFs which is received from NRF 750 at step 703a. In an example, the information is a per module (or per-NF) indication of NAS mode support, e.g., a bitmap in which one bit is used to mark a value corresponding to a supported mode of NAS security of an associated NF. For example, value “0” of a bit means that a particular NF (or NAS module of the NF) associated with the bit does not support DNAS. Value “1” of a bit means that a particular NF (or NAS module of the NF) associated with the bit supportsDNAS. In some examples, the bitmap is not directly transmitted from the MM NF. The MM NF may encode the bitmap into an integer value, and then transmit the integer value.
[0146]
[0139] FIG. 9 illustrates an exemplary format of bitmap of a per-module (or per NF) indication of NAS support. As shown in FIG.9, each of 8 bits of the bitmap is associated with a NF. The value of Bit #7 is set to “0” to indicate that the SMS NF does not support DNAS. The value of Bit #6 is set to “1” to indicate that the SM NF supports DNAS. The other bits of the bitmap are also set to corresponding values according to whether associated NFs support DNAS or not. In an example, the bitmap may consist of more than 8 bits to indicate the supported mode of NAS security of more NFs. In an example, NFs which are not associated with bits in the bitmap may be assumed to always not support DNAS. For example, it is assumed that the SMS NF is a traditional SMS NF and would always not support DNAS. Thus, there is no need to occupy a bit in the bitmap for indicating the SMS NF’s supported mode of NAS security.
[0147]
[0140] At step 704b, the UE 710 may store the per-module indication of NAS security support received at step 704a. As such, both the MM NF 720 and the UE 710 know which NF can support DNAS and which NF cannot support DNAS, and thus know how to establish NAS connection for respective NFs.
[0148]
[0141] For example, according to this per module indication of fixed support of NAS security mode, the SM NF 730 may run a SMC procedure with the UE 710 during a PDU session establishment phase as shown at step 705, the LM NF 760 may run another SMC procedure with the UE 710 during location management session as shown at step 706, and no separate SMC runs between the SMS NF 740 and the UE 710.
[0149]
[0142] At step 707, when NAS packets towards SMS NF need to be sent, the MM NF 720 may use security keys of a UE-MM NAS connection to secure data transfer of the SMS NF 740. The MM NF 720 may transfer in a NAS container of the UE-MM NAS connection, the contents towards or from the SMS NF 740 as well.
[0150]
[0143] FIG. 8 illustrates another exemplary signaling procedure for serving network-controlled NAS security, in which NRF is not involved. Steps 801, 802, 803f, 804a, 804b, 805, 806, and 807 may be performed in a similar way as the steps 701, 702, 703c, 704a, 704b, 705, 706, and 707 described above, respectively. For some parts which have been described in the above examples, the description thereof is omitted here for brevity.
[0151]
[0144] The difference between this signaling procedure of FIG. 8 and the previous signaling procedure of FIG. 7 is that NFs in the core network may subscribe to MM NF for NAS security support for respective NFs. The subscription may beimplemented by using SBI service of the MM NF. The NFs which support DNAS, would not subscribe to the MM NF for NAS security support.
[0152]
[0145] In an example, SM NF 830 supports DNAS. Thus, as shown at step 803c, the SM NF 830 would not reach out to MM NF (e.g., send SBI request) for NAS security support, because SM NF can run a SMC procedure with UE by itself. The same case will occur for a LM NF 860 as the LM NF 860 also supports DNAS. Whereas the SMS NF 840 doesn’t support DNAS, so it would reach out to the MM NF 820 via a SBI interface to request for NAS security support. Then, the MM NF can know that SMS NF 840 doesn’t support DNAS. In this regard, the MM NF 820 may make a determination for DNAS support of respective NFs based on subscription data from these NFs.
[0153]
[0146] Accordingly, the MM NF 820 may determine or select an accepted mode of NAS security for the UE 810, at least based on one or more modes of NAS security proposed by UE 810 and a determination of whether respective NF s support DNAS, at step 803f.
[0154]
[0147] At step 804a, the MM NF 820 may notify the UE 810 of which mode of NAS security is accepted to be used, e.g., HNAS is this example. Meanwhile, the MM NF 820 may notify the UE 810 of respective support of DNAS of NFs in the core network, e.g., a per-module (per-NF) indication of NAS security support. For example, a bitmap in a format as shown in FIG. 9 may be set according to whether a subscription for NAS security is requested from respective NFs at step 803a. In this example, the MM NF 820 may set a bit in the bitmap for the SMS NF 840 to “0”. Bits for other NFs (such as SM NF 830, LM NF 860) may be set to “1”. In some examples, the bitmap is not directly transmitted from the MM NF 820 to the UE 810. The MM NF 820 may encode the bitmap into an integer value, and then transmit the integer value in a registration response towards the UE 810.
[0155]
[0148] At step 804b, the UE 810 may store the received bitmap. Alternatively, the UE may determine or derive the bitmap from the received information which indicates the bitmap. As such, the UE 810 also know which NF can support DNAS and which NF cannot support DNAS, and thus know how to establish NAS connection with respective NFs based on the bitmap.
[0156]
[0149] FIG. 10 is a flow chart depicting a method 1000 performed at a terminal device (such as UE) for serving network-controlled NAS security according to examples of the present disclosure.
[0157]
[0150] At block 1010, a terminal device (e.g., UE 710 or UE 810 shown in FIGs. 7 and 8) transmits a message of registration request to a first network function for mobility management, such as MM NF or AMF, e.g., MM NF 720 or MM NF 820. The message may be an initial registration request for the terminal device. Themessage of registration request comprises first information indicating one or more modes of NAS security supported by the terminal device. The one or more modes of NAS security may comprise at least one of DNAS, SNAS and HNAS. In an example, the first information may indicate that HNAS is supported and proposed by the terminal device.
[0158]
[0151] At block 1020, in response to the registration request, the terminal device (such as UE) receives a message of registration response from the first network function (such as MM NF or AMF).The message of registration response comprises second information (e.g., a flag) indicating an accepted mode of NAS security and third information (e.g., information indicating a bitmap shown at FIG. 9) indicating modes of NAS security supported by a plurality of network functions. Although not shown, in some examples, the terminal device may store the third information (e.g., the received bitmap) or respective modes of NAS security supported by the plurality of network functions which are determined from the third information.
[0159]
[0152] At block 1030, the terminal device (such as UE) establishes a NAS connection with a second network function (such as SM NF, SMS NF, LM NF, and the like) based on the accepted mode of NAS security and a mode of NAS security supported by the second network function. The accepted mode of NAS security can be determined from the second information. A mode of NAS security supported by the second network function can be determined from the third information. The second network function may be one of the plurality of network functions. In case that the accepted mode of NAS security is HNAS, the terminal device may determine whether DNAS is supported by the second network function, according to the third information.
[0160]
[0153] FIG. 11 is a flow chart depicting a method performed at a network function (such as MM NF or AMF) for serving network-controlled NAS security according to examples of the present disclosure.
[0161]
[0154] At block 1110, a first network function, e.g., MM NF 720 or MM NF 820, receives a message of registration request from a terminal device (such as a UE). The message may be an initial registration request for the terminal device. The message of registration request comprises first information indicating one or more modes of NAS security supported by the terminal device. The one or more modes of NAS security may comprise at least one of DNAS, SNAS and HNAS. In an example, the first information may indicate that HNAS is supported and proposed by the terminal device.
[0162]
[0155] At block 1120, the first network function obtains information of respective modes of NAS supported by each of a plurality of network functions. In an example, respective modes of NAS supported by each of the plurality of network functionsmay be retrieved from a network repository function (e.g., NRF 750). In another example, respective modes of NAS supported by each of the plurality of network functions may be determined from subscription requests, which are received from at least one network function of the plurality of network functions for NAS security support for the at least one network function. In an example, the at least one network function may be determined to not support DNAS, whereas the other network functions of the plurality of network functions may be determined to support DNAS.
[0163]
[0156] At block 1130, the first network function determines an accepted mode of NAS to be used for the terminal device at least based on the one or more modes of NAS supported by the terminal device, the respective modes of NAS supported by each of the plurality of network functions obtained at block 1120, and modes of NAS supported by the first network function.
[0164]
[0157] At block 1140, the first network function transmits a message of registration response to the terminal device in response to the registration request received at block 1110. The message of registration response comprises second information (e.g., a flag) indicating the accepted mode of NAS and third information (e.g., information indicating a bitmap shown at FIG. 9) indicating modes of NAS supported by a plurality of network functions.
[0165]
[0158] In some examples, the decision for accepted mode of NAS to be applied by a UE is made by a NF (e.g., authentication server function (AUSF) or unified data management (UDM)) in a home network of the UE. FIGs. 12, 15, and 16 depict some of these examples. The AUSF or UDM in the home network can obtain information of a UE’s capabilities for support one or more modes of NAS security and information of respective support for NAS security modes of other NFs, and accordingly make a decision on an accepted mode of NAS security to be used by the UE based on the obtained information. This NAS security approach may be called home network-controlled NAS security in the present disclosure.
[0166]
[0159] In an example, UE capabilities with an indication (e.g., a flag) of modes of NAS security supported by a UE can be transmitted from the UE to a MM NF which in a serving network (which may be a visited network or a home network of the terminal device). Then, the MM NF transmits the received UE’s capabilities with the indication to AUSF or UDM in the home network of the terminal device.
[0167]
[0160] In an example, the AUSF or UDM can include the UE capabilities (e.g., a flag) in an AKA challenge, e.g., by using information of the UE capabilities received from the UE as an input for calculation of an authentication token, AUTN). Key generation for communication with the UE may also be affected because of the UE capabilities (e.g., a flag) received from the UE. For example, the AUSF or UDMcan utilize information of the UE capabilities for generations of security keys (e.g., KAUSF). In case the MM NF would have modified the UE capabilities (e.g., when forwarding the flag), then AKA challenge between USIM of the UE and the AUSF or UDM will fail.
[0168]
[0161] In an example, alternative to including the UE capabilities in the registration request, UE capabilities of a UE might also be stored in the UDM as a part of subscriber data of the UE.
[0169]
[0162] In an example, the AUSF or UDM can protect the decision of the accepted mode of NAS security by an AKA challenge (e.g., using information of the decision as an input for calculation of an authentication token, AUTN). The AUSF or UDM can further utilize information of the decision for generation of security keys (e.g., KAUSF) for communication with the UE.
[0170]
[0163] FIG. 12 illustrates an exemplary signaling procedure for home network-controlled NAS security according to an example of the present disclosure.
[0171]
[0164] At step 1200, the AUSF or UDM 1270 may obtain information indicating respective modes of NAS security supported by NFs (e.g., SMNF 1230, SMS NF 1240, LM NF 1260) in a core network. NFs in a core network may indicate their capabilities related to support for modes of NAS security during registration with a NRF (not shown), and the AUSF or UDM 1270 may query the capabilities from the NRF through a mechanism of service-based architecture. In an example, SM NF 1230, SMS NF 1240, and LMF NF 1260 register with the NRF 750 about their support for DNAS via an SBI interface. As an example, in this signaling procedure, it is assumed that the SM NF 1230 and the LM NF 1260 support DNAS, whereas the SMS NF 1240 does not support DNAS.
[0172]
[0165] At step 1201, UE 1210 transmits a message of initial registration request to MM NF 1220. In response to the initial registration request, the MM NF 1220 may send a primary authentication request to the AUSF or UDM 1270 in a home network of the UE 1210, as shown at step 1203 a.
[0173]
[0166] In an example, the initial registration request may contain UE capabilities with an indication of one or more modes of NAS security supported by the UE 1210. For example, the UE capabilities may comprise an indication of at least one of DNAS, SNAS, or HNAS. As an example, in this signaling procedure, it is assumed that the UE 1210 is supporting HNAS. The UE capabilities with the indication would be forwarded to the AUSF or UDM 1270 in the authentication request at step 1203 a.
[0174]
[0167] In examples of the present disclosure, a UE may use one of the following ways to convey the indication of modes of NAS security supported by the UE to the AUSF or UDM. One way is to convey the indication in UE capabilities directlyas a new parameter in the registration request. Another way is to use a SUCI which is generated by concealing both SUPI of the UE and information (e.g., a flag) of modes of NAS security supported by the UE. Another way is to use any other methods of cryptographic mechanism for integrity protection between the UE and the home network to convey the indication to the AUSF or UDM.
[0175]
[0168] FIG. 13 is a detailed overview illustrating an exemplary generation procedure for SUCI according to examples of the present disclosure. As shown at block 1301, at UE, the information of modes of NAS security supported by the UE, e.g., HNAS mode, is encrypted together with SUPI to form a concealed part (i.e., part B shown in FIG.13) of a SUCI. At the home network side, e.g., at the AUSF or UDM 1270, the information on modes of NAS security supported by the UE may be obtained by decrypt the UE’s SUCI as shown at block 1302. In this way, the information of modes of NAS security supported by the UE is concealed, and integrity protected, and thus cannot be modified by any intermediary, e.g. the MM NF. The cryptographic mechanism for SUCI could be easily extended to other methods of cryptographic mechanism for integrity protection between the UE and the home network for conveying the information of modes of NAS security supported by the UE, e.g., via a separate message.
[0176]
[0169] In an example, the MM NF 1220 may store at step 1202, the UE capabilities with the information of the one or more supported modes of NAS security received at step 1201. The MM NF 1220 may determine whether it can support the one or more modes of NAS security proposed by the UE 1210. For example, if none of the proposed modes of NAS security from the UE 1210 is supported by the MM NF 1220, then by default SNAS is supported by both of the UE 1210 and the MM NF 1220.
[0177]
[0170] At block 1203b, the UDM or AUSF 1270 make a decision which mode of NAS security is to be used for the UE 1210. The decision is made based on the UE capabilities of support for mode of NAS security and on the capabilities of support for mode of NAS security of NFs. The capabilities of support for mode of NAS security of the NFs are obtained through a mechanism of the service-based architecture as shown at step 1200. The UDM or AUSF 1270 may learn the UE capabilities from the previous authentication request (at step 1203a). If the capabilities are a part of the SUCI of the UE 1210, the UDM or AUSF 1270 learns the capabilities after de-concealment of the SUCI (as shown at step 1302 in FIG.
[0178] 13). If other method for integrity protection of the UE capability information is applied, the AUSF or UDM 1270 learns the capabilities after a verification of the integrity of the UE capability using this cryptographic method. Alternatively, or inaddition, the AUSF or UDM 1270 may learn the UE capabilities from the UE’s subscriber data stored in the UDM.
[0179]
[0171] Depending on the capabilities of the UE 1210 and the NFs, and optionally considering other conditions (such as operator policies), the AUSF or UDM 1270 finally decide an accepted mode of NAS security to be applied for the UE 1210. The accepted mode of NAS security may be any of DNAS, SNAS, or HNAS. As an example, in this signaling procedure, it is assumed that the accepted mode of NAS security is HNAS.
[0180]
[0172] At step 1203c, the decision of the accepted mode ofNAS security is encoded into a single integer value, e.g., called “NAS security decision parameter”. In case that the decision is HNAS, an indication indicating the supported mode of NAS security on per NF (i.e., per NAS module) basis may also be encoded into the “NAS security decision parameter”. For example, the indication may be a per-module indication in the form of bitmap as shown in FIG.9.
[0181]
[0173] In an example, the AUSF or UDM 1270 may use the “NAS security decision parameter” as an input value for generating AKA challenge (AUTN). The “NAS security decision parameter” may be further used as an input value for key generation (e.g., for generating KAUSF) during the primary authentication. In this way, a successful completion of the primary authentication and the creation of all keys derived from the key hierarchy are bound to the UE’s correct knowledge of the “NAS security decision parameter”.
[0182]
[0174] In an example, the AUSF or UDM 1270 may use UE capability with supported mode ofNAS security (e.g., a flag) received from UE 1210 via the MM NF 1220 an input value for generating AKA challenge (AUTN). The received UE capability may be further used as an input value for key generation (e.g., for generating KAUSF) during the primary authentication. In this way, a successful completion of the primary authentication and the creation of all keys derived from the key KAUSF are bound to the AUSF / UDM’s correct knowledge of the “UE capability with supported mode ofNAS security”.
[0183]
[0175] At step 1203d, the AUSF or UDM 1270 includes the “NAS security decision parameter” into a response for the UE 1210 as a part of the primary authentication. In this regard, the AUSF or UDM 1270 transmits to the MM NF 1220, an authentication response comprising an AUTN and information of the “NAS security decision parameter”. The MM NF 1220 forwards the authentication response to the UE 1210, as shown at step 1203e. In this way, the MM NF 1220 also learns about the decision of accepted mode ofNAS security and then may take appropriate actions.
[0176] At step 1203f, the UE 1210 uses the “NAS security decision parameter” received at step 1203e as an input for calculating the authentication challenge (AUTN) and verify if the calculated AUTN matches the AUTN received at step 1302d. If the “NAS security decision parameter” has been tampered with, e.g. by the MM NF 1220, the primary authentication will fail. Then, the UE 1210 can alert a user and / or terminate the communication with the network.
[0184]
[0177] Alternatively or additionally, at step 1203f, the UE 1210 may include the UE capabilities with supported modes of NAS security into verification for authentication challenge (AUTN). In this regard, the UE 1210 may use “the UE capabilities with supported modes of NAS security” as an input for calculating the authentication challenge (AUTN) and verify if the calculated AUTN matches the AUTN received at step 1302d. If the “the UE capabilities with supported modes of NAS security” has been tampered with, e.g. by the MM NF 1220, the primary authentication will fail.
[0185]
[0178] In case that the verification of the AUTN is success, the UE 1210 may store the “NAS security decision parameter” received at step 1203e. The UE 1210 may further use the received “NAS security decision parameter” as an input for subsequent key generation. In an example, the “NAS security decision parameter” may be used for generating RES* and KAUSF in a similar way as shown in FIG. 14. In another example, in case that the verification of the AUTN is success, the UE 1210 may use the “UE capabilities with supported modes of NAS security” as an input for subsequent key generation. In an example, the “UE capabilities with supported modes of NAS security” may be used for generating RES* and KAUSF.
[0186]
[0179] At step 1203f, a NAS SMC procedure is completed between the UE 1210 and the MM NF 1220. Then, a NAS connection (e.g., referred to as UE-MM NAS connection) may be established between the UE 1210 and the MM NF 1220. At step 1204, a message of registration response is transmitted from the MM NF 1220 to the UE 1210. The message of registration response comprises a UE temporary identifier, e.g., “6G MM GUTI”, to identify termination of the UE-MM NAS connection.
[0187]
[0180] Then, the UE 1210 is able to conduct communication with NAS modules of NFs in the core network based on the accepted mode of NAS. As part of communication with NAS modules in the network, the UE ensures that the NAS modules in the core network comply with the decision for the accepted mode of NAS security received at step 1203e. For instance, if the accepted mode of NAS security is DNAS, the UE 1210 does not communicate with a NAS module of a NF before receiving a SMC command from this NAS module.
[0181] In another example, if the accepted mode of NAS security is HNAS and the “NAS security decision parameter” contains a determination of supported mode of NAS security on a per NF basis, the UE 1210 can control communication with NAS modules per NF. That is, if a NF (e.g., SMNF 1230, LMNF 1260) supports DNAS, the UE 1210 do not communicate with a NAS module of the NF before receiving a SMC from this NF. As shown at step 1205, the SM NF 1230 may run a SMC procedure with the UE 1210 during a PDU session establishment phase. As shown at step 1206, the LM NF 1260 may run another SMC procedure with the UE 1210 during location management session. No separate SMC runs between the SMS NF 1240 and the UE 1210 for SMS communication at step 1207.
[0188]
[0182] FIG. 15 is a flow chart depicting a method 1500 performed at a terminal device (such as UE) for home network-controlled NAS security according to examples of the present disclosure.
[0189]
[0183] At block 1510, a terminal device (e.g., UE 1210 shown in FIG. 12) transmits a message of initial registration request to a first network function (e.g., MM NF 1220). The massage of initial registration request may comprise first information indicating one or more modes of NAS security supported by the terminal device.
[0190]
[0184] The first information may be indicated by a predefined parameter, e.g., a flag in UE capabilities indicating supported modes of NAS security of a UE. Alternatively, the first information may be comprised in an identifier such as SUCI (e.g., in a concealed part of SUCI), of the terminal device.
[0191]
[0185] At block 1520, the terminal device receives a message of authentication response from a home network, such as a network function for authentication (e.g., AUSF) or a network function for unified data management (e.g., UDM). The authentication response comprises second information indicating an accepted mode of NAS to be used for the terminal device.
[0192]
[0186] In some examples, the message of authentication response may further comprise third information indicating modes of NAS supported by a plurality of NFs. The third information may indicate a bitmap indicating whether the mode of DNAS is supported or not per NF, e.g., a bitmap in a format as shown in FIG. 9. The third information may be comprised in the authentication response in case that the accepted mode of NAS is HNAS. In this case, the terminal device may determine whether DNAS is supported by a second network function, according to the third information.
[0193]
[0187] At block 1530, the terminal device establishes an NAS connection with a NF based on the accepted mode of NAS. The NF may be one of the plurality of NFs. In case that the accepted mode of NAS is HNAS, the terminal device maydetermine whether DNAS is supported by the second network function, according to the third information.
[0194]
[0188] In some examples, although not shown in FIG. 15, the terminal device may utilize of at least one of the first information, the second information and the third information as input parameters to verify an authentication challenge (e.g., AUTN) in the message of authentication response in a primary authentication for the terminal device, e.g., for verification in AKA as shown at step 1203f. Additionally, the terminal device may further utilize the at least one of the first information, the second information and the third information for key generation after a success of the primary authentication, e.g., for generating KAUSF as shown in FIG. 14.
[0195]
[0189] FIG. 16 is a flow chart depicting a method 1600 performed at a network function (such as AMF or MM NF) for home network-controlled NAS security according to examples of the present disclosure.
[0196]
[0190] At block 1610, a network function (e.g., MM NF 1220) receives an initial registration request from a terminal device (such as a UE). At block 1620, in response to the initial registration request, the network function transmits an authentication request to a home network of the terminal device, e.g., to a network function for authentication (e.g., AUSF) or a network function for unified data management (e.g., UDM).
[0197]
[0191] In some examples, the initial registration request comprises first information indicating one or more modes of NAS supported by the terminal device, e.g., as described above with referent to step 1201. The first information may be indicated by a predefined parameter, e.g., a flag in UE capabilities indicating supported modes of NAS security of a UE. Alternatively, the first information may be comprised in a concealed part of a SUCI of a UE.
[0198]
[0192] At block 1630, the network function receives a message of authentication response from the home network of the terminal device. The message of authentication response comprises second information indicating an accepted mode of NAS security to be used by the terminal device. In some examples, the authentication response further comprises third information indicating modes of NAS supported by a plurality of network functions, e.g., information indicating a bitmap in a format as shown in FIG. 9. Then, the network function forwards the message of authentication response to the terminal device.
[0199]
[0193] FIG. 17 is a flow chart depicting a method 1700 performed at another network function (such as AUSF or UDM) for home network-controlled NAS security according to examples of the present disclosure.
[0200]
[0194] At block 1710, a network function (e.g., AUSF or UDM 1270) obtains information indicating respective modes of NAS security supported by each of aplurality of NFs. For example, the network function may request NRF for supported modes of NAS security of several NFs, e.g., as described above with reference to step 1200 of FIG. 12.
[0201]
[0195] At block 1720, the network function receives a message of authentication request for a primary authentication for a terminal device (such as a UE, e.g., UE 1210).
[0202]
[0196] At block 1730, in response to the message of authentication request, the network function obtains first information indicating one or more modes of NAS supported by the terminal device. In an example, the first information may be received in the authentication request received at block 1720. The first information is indicated by a predefined parameter (a flag in UE capabilities) or is comprised in a concealed part of a SUCI of the terminal device, which is comprised in the message of authentication request. In another example, the network function may retrieve the first information from subscriber data of the terminal device which is stored in a network function for unified data management (e.g., UDM 1270).
[0203]
[0197] At block 1740, the network function determines an accepted mode of NAS security to be used for the terminal device. In this regard, the network function may decide the accepted mode of NAS security based on the one or more modes of NAS supported by the terminal device as indicated by the first information and respective supported modes of NAS security of the plurality of NFs.
[0204]
[0198] At block 1750, the network function transmits a message of authentication response to the terminal device. The message of authentication response comprises second information indicating the accepted mode of NAS security. In an example, the network function may further transmit to the terminal device a third information indicating modes of NAS supported by the plurality of network functions. For example, the third information may be also transmitted in the message of authentication response in case that the accepted mode of NAS security is HNAS.
[0205]
[0199] In some examples, although not shown in FIG. 17, the network function may calculate an authentication challenge (e.g., AUTN) by utilizing at least one of the first information, the second information and the third information as input parameters. The authentication challenge may be transmitted to the terminal device in the message of authentication response.
[0206]
[0200] In some examples, although not shown in FIG. 17, the network function may utilize at least one of the first information, second information and the third information as input parameters for key generation, e.g., for generating KAUSF.
[0207]
[0201] FIG. 18 illustrates an exemplary signaling procedure for policy -based NAS security according to an example of the present disclosure. In this approach, a MM NF and a UE are configured by policies related to NAS security from a networkfunction for policy control (such as, PCF). In this example, the UE would perform communication with NFs based on the configured policies.
[0208]
[0202] At step 1801, UE 1810 transmits to the MM NF 1820, a message of registration request which comprises an SUCI of the UE 1810 and an indication indicating its capabilities of support for one or more modes of NAS security.
[0209]
[0203] At step 1802, the MM NF 1820 may store the UE capabilities with the information of the one or more modes of NAS security received at step 1801. The MM NF 1820 may determine an accepted mode of NAS security for the UE 1810. In this regard, the MM NF 1820 may determine whether it can support the one or more modes of NAS security proposed by the UE 1810. In some examples, the MM NF 1820 can select a mode of NAS security from the one or more modes of NAS security, as the accepted mode of NAS security.
[0210]
[0204] At step 1803, a NAS SMC procedure is completed between the UE 1810 and the MM NF 1820. Then, at step 1804, a message of registration response is transmitted from the MM NF 1820 to the UE 1810. The message of registration response comprises a 6G MM GUTI to identify termination of the UE-MM NAS connection established previously between the UE 1810 and the MM NF 1820, and an indication indicating the accepted mode of NAS security.
[0211]
[0205] At step 1804, PCF 1830 may transmit a message for policy control to the UE 1810 and the MM NF 1820. The message comprises an indication indicating support of modes of NAS security of respective NFs. In an example, the PCF 1830 may transmit a UE policy create message (e.g., MANAGE UE policy command) to the MM NF 1820, and then the message is forwarded to the UE 1810. A field of “UePolicy” in the message indicates which NF support DNAS and which NF doesn’t support DNAS. As such, both the MM NF 1820 and the UE 1810 can learn which NF supports DNAS and which NF doesn’t support DNAS, and can perform NAS communication according to the accepted mode and NAS security and the received policy.
[0212]
[0206] FIG. 19A illustrates an exemplary signaling procedure for UE parameters update (UPU) based NAS security according to an example of the present disclosure. In this procedure, a security procedure for UPU is utilized to negotiate mode of NAS security for a UE, and UDM can make a decision on which mode of NAS security is to be applied.
[0213]
[0207] The UDM may decide to perform UPU anytime after the UE has been successfully authenticated and registered to a cellular communication system. In an example, as shown at step 1901, UE 510 is registered with the AMF NF 1920 and completes a NAS SMC procedure with the AMF 1920. In this regard, a NAS connection between the UE 1910 and the AMF NF 1920 is established.
[0208] At step 1902, the UDM 1940 may obtain information indicating respective modes of NAS security supported by NFs (e.g., SM NF, SMS NF, LM NF) in a core network. NFs in a core network may indicate their capabilities related to support for modes of NAS security during registration with a NRF (not shown), and the UDM 1940 may query the capabilities from the NRF through a mechanism of service based architecture.
[0214]
[0209] The UDM 1940 can send the obtained information indicating respective modes of NAS security supported by NFs to the UE 1910 via a UPU procedure. At step 1903, the UDM 1940 decides to perform the UPU using a control plane procedure. In an example, the UDM 1940 may include information of support for modes of NAS security for respective NFs (which is obtained at step 1902) in UPU data. The information may be a Per-module indication, e.g., a bitmap as described with reference to FIG.9. If the UDM 1940 requests an acknowledgement, it shall temporarily store an expected UPU-XMAC-IUE, which is obtained from AUSF 1930.
[0215]
[0210] At step 1904a, the UDM 1940 transmits a Nudm_SDM_Notification message to the AMF 1920. In an example, the Nudm_SDM_Notification message may comprise UPU data comprising the information of support for modes of NAS security for respective NFs. At step 1904b, upon receiving the Nudm_SDM_Notification message, the AMF 1920 forwards the information of support for modes of NAS security for respective NFs (e.g., received in UPU data) to the UE1920 in downlink NAS transport message, as shown at step 1904b.
[0216]
[0211] In another example, the UDM 1940 may further include the information of support for modes of NAS security (e.g., a value encoded from a bitmap of per-NF indication of the support for DNAS) for respective NFs in calculation of UPU-MAC-IAUSF. The Nudm_SDM_Notification message may comprise the calculated UPU-MAC-IAUSF. The UPU-MAC-IAUSF is used for integrity protection. That is, the UE can verify that the UPU data is indeed from the home network. At step 1904b, the AMF 1920 forwards the received UPU data containing the relevant information of support for modes of NAS security and the UPU-MAC-IAUSF to the UE 1910 in a downlink NAS transport message.
[0217]
[0212] At step 1905, the UE 1910 can obtain the information of support for modes of NAS security for respective NFs from the received downlink NAS transport message. In an example, on receiving the downlink NAS transport message, the UE 1910 can calculate a UPU-MAC-IAUSF, based on the received information of support for modes of NAS security for respective NFs, and verify whether it matches the UPU-MAC-IAUSF value received in the downlink NAS transport message. If the verification of UPU-MAC-IAUSF is successful, and the UE 1910stores the received information of support for modes of NAS security for respective NFs, or update its stored parameters with the received information of support for modes of NAS security for respective NFs.
[0218]
[0213] After the successful verification, the UE 1910 may send an acknowledgement (e.g., ACK). An indication of one or more modes of NAS security supported by the UE 1910, is sent to the UDM 1940. UPU-MAC-IUE is generated by the UE 1910 and included in the uplink NAS transport message, so as to ensure the indication of one or more modes of NAS security cannot be modified or altered by any intermediary NF (e.g., the AMF 1920). In an example, the UE 1910 is supporting HNAS. The uplink NAS transport message comprises UE capabilities with an indication of support for HNAS. As shown at step 1906a, the UE 1910 transmits the uplink NAS transport message to the AMF 1920. The uplink NAS transport message may further comprise (e.g., in UE parameter update header) an indication indicating the presence of the indication of support for HNAS in the UPU data. The AMF 1920 may forward the ACK with the UPU-MAC-IUE and the indication of the one or more modes of NAS security to the UDM 1940, via a Nudm SDM Info request message to the UDM, as shown at step 1906b.
[0219]
[0214] UPU transparent container can be used to convey UPU data, including UPU-MAC-IUE and the indication of the one or more modes of NAS security supported by a UE. In some examples, a format of UPU transparent container may be adjusted to support transmission of an indication of the one or more modes of NAS security supported by a UE, e.g., in the uplink NAS transport message of step 1906a and in the Nudm SDM Info request message of step 1906b. The UPU transparent container may be a type 6 information element (IE) with a minimum length of 20 octets.
[0220]
[0215] In an example, the UPU transparent container may be of a format as shown in FIG. 19B. The “UE capability fixed hybrid support bitmap” IE is used to indicate of the one or more modes of NAS security supported by a UE.
[0221]
[0216] The UE parameters update header may be in a format as shown in FIG. 19C. The bit of “UPU data type” is of a value “1” to indicate that the UPU transparent container is used for the UE to reply with ACK to the UDM. The bit of “Fixed hybrid flag” may be set to a value “1” to indicate that UPU transparent container includes an indication of one or more modes of NAS security supported by the UE.
[0222]
[0217] In an example, a new UPU data set type, e.g., called “Fixed hybrid support data”, may be defined as shown in FIG. 19D to indicate the presence of the indication of the one or more modes of NAS security supported by a UE in UPU data, i.e., in UDP transparent container.
[0218] In an example, if a UE parameters update list include a UE parameters update data set with a UE parameters update data set type indicating “Fixed hybrid support data”, i.e., with a value “0101”, it can be determined that a UE parameters update data set in the UE parameters update list comprises an indication of the one or more modes of NAS security supported by a UE.
[0223]
[0219] The UDM 1940 validates the ACK received from the UE 1010, as shown at step 1907a. In this regard, the UDM 1940 may compare the UPU-MAC-IUE received from the UE 1920 with the expected UPU-XMAC-IUE that the UDM 1940 stored temporarily at step 1903. If the validation is successful, the UDM 1940 stores the indication of the one or more modes of NAS security received at step 1906b. If ACK is not received or the validation is not successful, the UDM 1940 can mark the AMF 1920 or a visited public land mobile network (VPLMN) of the AMF 1920 as a low trusted network.
[0224]
[0220] If the validation at step 1907a is successful, the UDM 1940 may determine at step 1907b, an accepted mode of NAS security for the UE 1910, at least based on the one or more modes of NAS security proposed by UE 1910 and the supported mode of NAS security of respected NFs (e.g., a bitmap determined at step 1902). For example, the UDM 1940 may determine that HNAS can be the accepted mode of NAS security.
[0225]
[0221] The decision of the accepted mode of NAS security may be notified to the UE 1910, as shown at step 1908.
[0226]
[0222] Then, the UE 1910 can establish NAS connection with NFs based on the accepted mode of NAS security and the supported mode of NAS security of respected NFs (e.g., the fixed bitmap stored at step 1905). For example, at step 1908, the UE 1920 may know whether SMS NF supports or not, and utilizes security keys of the NAS connection between the UE 1910 and the AMF 1920 to secure data transfer to or from the SMS NF.
[0227]
[0223] FIG. 20 is a flow chart depicting a method 2000 performed at a terminal device (such as UE) for UPU based NAS security according to examples of the present disclosure.
[0228]
[0224] At block 2010, a terminal device (e.g., UE 1910) transmits to a network function (e.g., UDM 1940) in a home network of the terminal device an uplink NAS message after a primary authentication for the terminal device. The uplink NAS message comprises first information indicating one or more modes of NAS supported by the terminal device. The uplink NAS message may be a message for UPU. The first information may be comprised in UPU data with a UPU header indicating a presence of the first information.
[0225] At block 2020, the terminal device receives a first downlink NAS message from the network function (e.g., UDM 1940). The first downlink NAS message comprises second information indicating an accepted mode of NAS security to be used for the terminal device.
[0229]
[0226] At block 2030, the terminal device establishes a NAS connection with a second network function based on the accepted mode of NAS security.
[0230]
[0227] In an example, although not shown, the terminal device may receive from the network function (e.g., UDM 1940), third information indicating modes of NAS supported by a plurality of network functions. The third information may be received in a second downlink NAS for UPU. The third information may be comprised in UPU data. For example, the third information may indicate a bit map indicating whether the mode of distributed NAS is supported or not per network function (e.g., in a format shown in FIG. 9).
[0231]
[0228] In an example, the third information may be received together with a UPU ACIAUSF which is calculated from the third information, and the terminal device (e.g., UE 1910) may verify the UPU-MAC-IAUSF based on the received third information. In this regard, the terminal device may calculate the UPU-MAC-IAUSF based on the received third information, and verify whether the UPU-MAC-IAUSF comprised in the second downlink message matches the calculated UPU-MAC-IAUSF. In case that the verification of the UPU-MAC-IAUSF is successful, the terminal device (e.g., UE 1910) may store the third information or the modes of NAS supported by the plurality of network functions as indicated by the third information.
[0232]
[0229] In case that the accepted mode of NAS is HNAS, the terminal device may determine whether DNAS is supported by the second network function based on the third information. The second network function may be one of the plurality of network functions.
[0233]
[0230] FIG. 21 is a flow chart depicting a method 2100 performed at a network function (such as UDM) for UPU based NAS security according to examples of the present disclosure.
[0234]
[0231] At block 2110, the network function (e.g., UDM 1940) obtains information indicating respective modes of NAS security supported by each of a plurality of network functions. In an example, the information may be obtained as described with reference to step 1902 in FIG. 19 A.
[0235]
[0232] At block 2120, the network function (e.g., UDM 1940) receives an uplink NAS message after a primary authentication for a terminal device (e.g., UE 1910). The uplink NAS message comprises first information indicating one or more modes of NAS supported by the terminal device. The uplink NAS message may be amessage for UPU, e.g., in a UPU data for acknowledgment. The network function may store the one or more modes of NAS supported by the terminal device received at block 2120.
[0236]
[0233] At block 2130, the network function (e.g., UDM 1940) determines an accepted mode of NAS security to be used for the terminal device based on the information obtained at block 2110 and the one or more modes of NAS supported by the terminal device.
[0237]
[0234] At block 2140, the network function (e.g., UDM 1940) transmits to the terminal device (e.g., UE 1910), a first downlink NAS message comprising second information indicating the accepted mode of NAS security.
[0238]
[0235] In an example, although not shown in FIG. 21, the network function (e.g., UDM 1940) may transmit to the terminal device (e.g., UE 1910), third information indicating modes of NAS supported by a plurality of network functions. For example, the third information may indicate a bitmap indicating whether DNAS is supported or not per network function (e.g., in a format shown in FIG. 9). The third information may be transmitted via a second downlink NAS message for UPU.
[0239]
[0236] In an example, although not shown in FIG. 21, the network function (e.g., UDM 1940) may calculate UPU-MAC-IAUSF based on the third information, and transmit the calculated UPU-MAC-IAUSF to the UE 1910 together with the third information.
[0240]
[0237] FIG. 22 is a flow chart depicting a method 2200 performed at a terminal device (such as UE) for NAS security according to examples of the present disclosure.
[0241]
[0238] At block 2210, a terminal device (such as UE) transmits to a core network, first information indicating one or more modes of NAS security supported by the terminal device. In an example, the first information may be transmitted in a message of registration request, e.g., to a network function (e.g., AMF or MM NF) for mobility management in a visited network. In another example, the first information may be transmitted in a message of authentication request of a message for UPU, e.g., to a network function for authentication or unified data management (such as AUSF or UDM) in a home network of the terminal device. The one or more modes of NAS security may comprise at least one of DNAS, SNAS, or HNAS.
[0242]
[0239] At block 2220, the terminal device (such as UE) receives from the core network, second information indicating an accepted mode of NAS security to be used for the terminal device. The accepted mode of NAS security may be one of the one or more modes of NAS security proposed by the terminal device at block 2210. In an example, the second information may be received in a message ofregistration response, e.g., from the network function (e.g., AMF or MM NF) for mobility management in the visited network. In another example, the second information may be received in a message of authentication response or a downlink NAS message, e.g., from the network function for authentication or unified data management (such as AUSF or UDM) in the home network.
[0243]
[0240] At block 2230, the terminal device (such as UE) establishes a NAS connection with a second network function based on the accepted mode of NAS. The terminal device may establish a NAS connection with the second network function by using a separate security association dedicated for the second network function, in case that the accepted mode of NAS security is distributed NAS, or in case that the accepted mode of NAS security is hybrid NAS while the second network function supports distributed NAS.
[0244]
[0241] Although not shown, the terminal device (such as UE) may further receive third information indicating modes of NAS supported by a plurality of network functions. The third information may indicate a bit map indicating whether the mode of distributed NAS is supported or not per network function, e.g., the bitmap indicated in FIG.9. The third information may be received together with the second information, or may be received separately from the second information. In an example, the third information may be received in a message of registration response, e.g., from the network function (e.g., AMF or MM NF) for mobility management in the visited network. In an example, the third information may be received in a message of authentication response or a downlink NAS message, e.g., from the network function for authentication or unified data management (such as AUSF or UDM) in the home network. In yet another example, the indication may be received in a message for policy control, e.g., from a network for policy control (e.g., PCF).
[0245]
[0242] In some examples, in case that the accepted mode of NAS is HNAS, the terminal device (e.g., UE) may determine whether DNAS is supported by a particular network function, e.g., based on the received third information.
[0246]
[0243] FIG. 23 is a flow chart depicting a method performed at a first network function (such as MM or AMF) for NAS security according to examples of the present disclosure.
[0247]
[0244] At block 2310, the first network function (such as MM or AMF) determines an accepted mode of NAS security to be used for a terminal device (such as UE). At block 2320, the first network function transmits to the terminal device, second information indicating the accepted mode of NAS security. The accepted mode of NAS security is one of DNAS, SNAS, or HNAS. The second information may betransmitted to the terminal device via a message of registration response, or a message of authentication response.
[0248]
[0245] In an example, the accepted mode of NAS security may be determined based on modes of NAS security supported by at least one of the terminal device, the first network function and network functions in a core network. In another example, the accepted mode of NAS security may be determined from information (e.g., a flag) indicating the accepted mode of NAS security received from a third network function (such as AUSF or UDM) of a home network of the terminal device.
[0249]
[0246] In some examples, although not shown in FIG. 23, the first network function may receive from the terminal device (such as UE), a message of registration request which comprises first information indicating one or more modes of NAS security supported by the terminal device. In some examples, the first network function may receive an uplink NAS message from the terminal device after a primary authentication for the terminal device. The uplink NAS message comprises the first information. The one or more modes of NAS security comprise at least one of DNAS, SNAS, or HNAS. The first information may be indicated by a predefined parameter or is comprised in a concealed part of a subscription concealed identifier (SUCI) of the terminal device. The first network function may determine whether the one or more modes of NAS security is supported by the first network function.
[0250]
[0247] In some examples, the first network function may transmit the first information to a third network function (such as AUSF or UDM); and receive the second information from the third network function. The first network function may further receive from the third network function, third information indicating modes of NAS security supported by a plurality of network functions. The third information indicates a bit map indicating whether the mode of DNAS is supported or not per network function. The first network function may further transmit the third information to the terminal device, e.g., together with the second information.
[0251]
[0248] In some examples, the first network function may obtain information on modes of NAS security supported by a plurality of network functions; and determine the accepted mode of NAS security based on the obtained information. In an example, the first network function may retrieve from a network repository function (such as NRF), respective modes of NAS security supported by each of the plurality of network functions. In another example, the first network function may receive from at least one network function of the plurality of network functions, a subscription request for NAS security support for the at least one network function; and determine according to the subscription request, that the at least one network function do not support DNAS; and the other network functions of the plurality of network functions support distributed NAS. In another example,the first network function may receive from a network function (e.g., PCF) for policy control, a message of policy configuration comprising information on modes of NAS security supported by the plurality of network functions. The first network function may determine third information indicating modes of NAS security supported by the plurality of network functions based on the obtained information; and transmit the determined third information to the terminal device. The third information may be transmitted to the terminal device, e.g., together with the second information.
[0252]
[0249] In some examples, in case that the accepted mode of NAS security is hybrid NAS, the first network function may transmit to a second network function, a service request from the terminal device which comprises fourth information (e.g., a flag) indicating that HNAS is supported by the terminal device. In response to the service request, the first network function may receive from the second network function, a fifth information (e.g., another flag) indicating whether distributed NAS security is supported by the second network function or not. The first network function may notify the terminal device that DNAS is supported by the second network function, in case that the fifth information indicates that DNSA is supported by the second network function. In case that the fifth information indicates that distributed NSA is not supported by the second network function, the first network function may provide NAS security for data transfer between the terminal device and the second network function.
[0253]
[0250] FIG. 24 is a flow chart depicting a method performed at a second network function (such as SM NF, LM NF, SMS NF, or any other NF) for NAS security according to examples of the present disclosure. At block 2410, the second network function transmits information indicating a mode of NAS security supported by the second network function, to a network repository function (such as NRF) or a first network function (such as AMF or MM NF) for mobility management. The mode of NAS security supported by the second network function may be DNAS or SNAS.
[0254]
[0251] In some examples, the second network function may receive a service request from a terminal device which comprises fourth formation (e.g., a flag) indicating that HNAS is supported by the terminal device. In response to the service request, the second network function may transmit to the first network function, fifth information (e.g., another flag) indicating whether DNAS is supported by the second network function or not.
[0255]
[0252] In some examples, the second network function may transmit to the first network function, a subscription request for NAS security support for the second network function, as shown at block 2420. It means that the second network does not support DNAS. The second network function may transmit to the first networkfunction, a request for NAS security; and receive from the first network function, information related to NAS security.
[0256]
[0253] In some examples, the second network function may establish a NAS connection with a terminal device by using a separate security association dedicated for the second network function, in case that the second network function supports DNAS, as shown at block 2430.
[0257]
[0254] FIG. 25 is a flow chart depicting a method performed at a network repository function (such as NRF) for NAS security according to examples of the present disclosure. At block 2510, the network repository function receives from each of one or more network functions (such as SM NF, LM NF, SMS NF, or any other NF), information indicating modes of NAS security supported by respective network functions. At block 2510, the network repository function stores the received information for each of the one or more network functions. The modes of NAS security may comprise at least one of DNAS or SNAS.
[0258]
[0255] In some example, the network repository function may receive a request for a mode of NAS security supported by a particular network function. In response to the retrieve request, the network repository function may retrieve and transmit the mode of NAS security supported by the particular network function, as shown at block 2530. The request may be received from a first network function for mobility management (such as AMF or MM NF), or from a network function for unified data management (UDM).
[0259]
[0256] FIG. 26 is a flow chart depicting a method performed at a third network function (such as AUSF or UDM) for NAS security according to examples of the present disclosure.
[0260]
[0257] At block 2610, a third network function (such as AUSF or UDM) obtains information indicating respective modes of NAS security supported by each of a plurality of network functions. A mode of NAS security supported by a network function may be DNAS or SNAS.
[0261]
[0258] At block 2620, the third network function obtains first information indicating one or more modes of NAS security supported by a terminal device. The one or more modes of NAS security may comprise at least one of DNAS, SNAS, or HNAS. In some examples, the first information is received in an authentication request from a first network function (such as AMF or MM NF) for mobility management. In some examples, the first information may be retrieved from subscriber data of the terminal device which is stored in the third network function. In another example, the first information may be received in an uplink NAS message (e.g., a message for UPU) from the terminal device after a primary authentication for the terminal device. The first information may be indicated by apredefined parameter, or may be comprised in a concealed part of a subscription concealed identifier of the terminal device.
[0262]
[0259] At block 2630, the third network function determines an accepted mode of NAS security to be used for the terminal device. The accepted mode of NAS security may be selected or determined based on the respective modes of NAS security supported by each of a plurality of network functions, and / or the one or more modes of NAS security supported by a terminal device.
[0263]
[0260] At block 2640, the third network function transmits to the terminal device, second information indicating the accepted mode of NAS security. The second information may be transmitted to the terminal device via a message of authentication response.
[0264]
[0261] In some examples, the third network function may further transmit third information indicating modes of NAS security supported by the plurality of network functions. The third information may indicate a bit map indicating whether the mode of distributed NAS is supported or not per network function. The third information may be transmitted to the terminal device and / or the first network function (such as AMF or MM NF).
[0265]
[0262] In some examples, in case that the first information is received in a message of authentication request, the third network function may calculate an authentication challenge (e.g., authentication token, AUTN) by utilizing at least one of the second information and the third information as input parameters; and transmit the authentication challenge to the terminal device in the message of authentication response. The third network function may further utilize the at least one of the second information and the third information as input parameters for key generation (e.g., for a key KAUSF) for subsequent communication of the terminal device.
[0266]
[0263] FIG. 27 shows, by way of example, a block diagram of an apparatus 10, that may be embodied in / as the terminal device, or the network node. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods as disclosed herein, and any of the embodiments thereof. In an example, the at least one memory and the instructions (e.g. a computer program code, software), are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods as disclosed herein, and any of the embodiments thereof.
[0267]
[0264] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with example embodiments described herein. As used inthis application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0268]
[0265] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may be at least in part external to apparatus 10 but accessible to apparatus 10.
[0269]
[0266] The instructions 15 may be comprised in a computer readable medium or a non-transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM).
[0270]
[0267] For example, the apparatus 10 is a terminal device, such as the UE of FIGs.
[0271] 5-8, 10, 12, 15, 18, 19A, 20, or 22. As another example, the apparatus is comprised in such a terminal device, e.g. as a chipset configured to control the terminal device. The apparatus 10 may be caused or configured to perform at least the method of FIGs. 5-8, 10, 12, 15, 18, 19A, 20, or 22 and / or any one or more of the embodiments described.
[0272]
[0268] As another example, the apparatus 10 is a network function, e.g. the MM NF or AMF of FIGs. 5-8, 11, 12, 15, 16, 18, 19A, or 23, the NRF of FIGs. 5, 7, or 25, the SM NF or SMS NF or LM NF of FIG. 5-8, 12, 15, 18, 19A, or 24, the AUSF or UDM of FIG. 12, 17, 19A, 21, or 26. In another embodiment, the apparatus is comprised in such a network node, e.g. as a chipset configured to control thenetwork node. The apparatus 10 may be caused or configured to perform at least a method ofFIGs. 5-12, 15-19A, or 23-26 and / or any one ormoreofthe embodiments described.
[0273]
[0269] The apparatus may comprise one or more entities of any of protocol layers, such as a MAC entity, an RRC entity, an RLC entity, a PDCP entity or a PHY entity. In some embodiments, the entity is configured to perform at least the methods ofFIGs. 2-18, and / or any one or more of the embodiments described.
[0274]
[0270] The apparatus 10 comprises a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellular standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than one transceiver.
[0275]
[0271] The apparatus 10 may comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10. For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.
[0276]
[0272] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components of the apparatus 10. For example, the at least one processor 12, the memory 14, and the computer program code form means for carrying out the method or methods as disclosed herein, and any of the embodiments thereof. As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C]”, is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only onemeans for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.
[0277]
[0273] It should be appreciated that at least some aspects of the exemplary embodiments of the disclosures may be embodied in computer-executable instructions, such as in one or more program modules, executed by one or more computers or other devices. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types when executed by a processor in a computer or other device. The computer executable instructions may be stored on a computer readable medium, for example, non-transitory computer readable medium, such as a hard disk, optical disk, removable storage media, solid state memory, RAM, etc. As will be appreciated by one of skills in the art, the function of the program modules may be combined or distributed as desired in various embodiments. In addition, the function may be embodied in whole or in part in firmware or hardware equivalents such as integrated circuits, field programmable gate arrays (FPGA), and the like.
[0278]
[0274] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0279]
[0275] Even though the invention has been described above with reference to an example according to the accompanying drawings, it is clear that the invention is not restricted thereto but may be modified in several ways within the scope of the appended claims. Therefore, all words and expressions should be interpreted broadly and they are intended to illustrate, not to restrict, the embodiment. It will be obvious to a person skilled in the art that, as technology advances, the inventive concept may be implemented in various ways. Further, it is clear to a person skilled in the art that the described embodiments may, but are not required to, be combined with other embodiments in various ways.
Claims
48I / We Claim:
1. An apparatus at a terminal device, the apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:transmit to a core network, first information indicating one or more modes of non-access stratum (NAS) security supported by the terminal device;receive from the core network, second information indicating an accepted mode of NAS security; andestablish a NAS connection with a network function based on the accepted mode of NAS security.
2. The apparatus according to claim 1, wherein the one or more modes of NAS security comprise at least one of following modes of NAS security, distributed NAS; single NAS; or hybrid NAS.
3. The apparatus according to claim 1 or 2, wherein the first information is transmitted via a message of registration request to a first network function for mobility management.
4. The apparatus according to claim 3, wherein the first information is indicated by a predefined parameter or is comprised in a concealed part of a subscription concealed identifier of the terminal device.
5. The apparatus according to claim 1 or 2, wherein the first information is transmitted via an uplink NAS message after a primary authentication for the terminal device.
6. The apparatus according to any of claims 1 to 5, wherein the second information is received in a message of registration response, or a message of authentication response.
7. The apparatus according to any of claims 1 to 6, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,receive third information indicating modes of NAS security supported by a plurality of network functions.
8. The apparatus according to claim 7, wherein the third information indicates a bit map indicating whether the mode of distributed NAS is supported or not per network function.
9. The apparatus according to claim 7 or 8, wherein the third information is received from at least one of,a first network function for mobility management,49a third network function in a home network of the terminal device, or a network function for policy control.
10. The apparatus according to any of claims 7 to 9, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,in case that the second information is received in a message of authentication response,utilize at least one of the first information, the second information and the third information as input parameters to verify an authentication challenge in the message of authentication response.
11. The apparatus according to claim 10, wherein the authentication challenge is an authentication token (AUTN).
12. The apparatus according to claim 10 or 11, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,in case that a verification of the authentication challenge is successful, utilize at least one of the first information, the second information and the third information as input parameters for key generation.
13. The apparatus according to claim 12, wherein the at least one of the second information and the third information is utilized for generation of a key KAUSF.
14. The apparatus according to any of claims 1 to 13, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,in case that the accepted mode of NAS security is hybrid NAS, determine whether distributed NAS is supported by a second network function.
15. The apparatus according to claim 1 to 14, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,establish a NAS connection with a second network function by using a separate security association dedicated for the second network function, in case that the accepted mode of NAS security is distributed NAS, or in case that the accepted mode of NAS security is hybrid NAS while the second network function supports distributed NAS.
16. An apparatus at a first network function for mobility management, the apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:50determine an accepted mode of non-access stratum (NAS) security to be used for a terminal device; andtransmit to the terminal device, second information indicating the accepted mode of NAS security.
17. The apparatus according to claim 16, wherein the accepted mode of NAS security is one of following modes of NAS security: distributed NAS ; single NAS; or hybrid NAS.
18. The apparatus according to claim 16 or 17, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,receive from the terminal device, a message of registration request which comprises first information indicating one or more modes of NAS security supported by the terminal device.
19. The apparatus according to claim 18, wherein the first information is indicated by a predefined parameter or is comprised in a concealed part of a subscription concealed identifier of the terminal device.
20. The apparatus according to claim 16 or 19, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least toreceive an uplink NAS message from a terminal device after a primary authentication for the terminal device, wherein the uplink NAS message comprise first information indicating one or more modes of NAS security supported by the terminal device.
21. The apparatus according to any of claim 16 to 20, wherein the second information is transmitted to the terminal device via a message of registration response, or a message of authentication response.
22. The apparatus according to any of claims 18 to 21, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,determine whether the one or more modes of NAS security is supported by the first network function.
23. The apparatus according to any of claims 18 to 22, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,transmit the first information to a third network function; andreceive the second information from the third network function, wherein the third network function is a network function for authentication and unified data management in a home network of the terminal device.5124. The apparatus according to claim 23, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,receive from the third network function, third information indicating modes of NAS security supported by a plurality of network functions.
25. The apparatus according to claim 24, wherein the third information indicates a bit map indicating whether the mode of distributed NAS is supported or not per network function.
26. The apparatus according to any of claim 24 to 25, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,transmit the received third information to the terminal device.
27. The apparatus according to any of claims 16 to 21, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,obtain information on modes of NAS security supported by a plurality of network functions; anddetermine the accepted mode of NAS security based on the obtained information.
28. The apparatus according to claim 27, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to obtain the information by,retrieving from a network repository function, respective modes of NAS security supported by each of the plurality of network functions.
29. The apparatus according to claim 27, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to obtain the information by,receiving from at least one network function of the plurality of network functions, a subscription request for NAS security support for the at least one network function; andaccording to the subscription request, determining that the at least one network function do not support distributed NAS, and the other network functions of the plurality of network functions support distributed NAS.
30. The apparatus according to any of claims 16 to 23, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to obtain the information by,receiving a message of policy configuration from a network function for policy control, wherein the message of policy configuration comprises information onmodes of NAS security supported by a plurality of network functions.
31. The apparatus according to any of claims 27 to 30, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,determine third information indicating modes of NAS security supported by the plurality of network functions based on the obtained information; and transmit the determined third information to the terminal device.
32. The apparatus according to any of claims 16 to 23, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,in case that the accepted mode of NAS security is hybrid NAS,transmit to a second network function, a service request from the terminal device which comprises fourth information indicating that hybrid NAS is supported by the terminal device; andin response to the service request, receive from the second network function, a fifth information indicating whether distributed NAS security is supported by the second network function or not.
33. The apparatus according to claim 32, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,notify the terminal device that distributed NAS is supported by the second network function, in case that the fifth information indicates that distributed NSA is supported by the second network function.
34. The apparatus according to claim 33, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,provide NAS security for data transfer between the terminal device and the second network function, in case that the fifth information indicates that distributed NSA is not supported by the second network function.
35. The apparatus according to any of claims 16 to 34, wherein the first network function is an access and mobility management function (AMF) or a mobility management (MM) network function.
36. An apparatus at a second network function in a core network, the apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:transmit information indicating a mode of non-access stratum (NAS) securitysupported by the second network function, to a network repository function or a first network function for mobility management.
37. The apparatus according to claim 36, wherein the mode of NAS security supported by the second network function comprises any of following modes of NAS security: distributed NAS; or single NAS.
38. The apparatus according to claim 36 or 37, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,establish a NAS connection with a terminal device by using a separate security association dedicated for the second network function, in case that the second network function supports distributed NAS.
39. The apparatus according to any of claims 36 to 38, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,receive a service request from a terminal device which comprises fourth formation indicating that hybrid NAS is supported by the terminal device; and in response to the service request, transmit to the first network function, fifth information indicating whether distributed NAS is supported by the second network function or not.
40. The apparatus according to any of claims 36 to 39, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,transmit to the first network function, a subscription request for NAS security support for the second network function.
41. The apparatus according to claim 40, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,transmit to the first network function, a request for NAS security; and receive from the first network function, information related to NAS security.
42. An apparatus at a network repository function in a core network, the apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive from each of one or more network functions, information indicating modes of non-access stratum (NAS) security supported by respective network functions; andstore the received information for each of the one or more network functions.5443. The apparatus according to claim 42, wherein the modes of NAS security comprise at least one of following modes of NAS security: distributed NAS ; or single NAS.
44. The apparatus according to any of claims 42 to 43, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,receive a request for a mode of NAS security supported by a particular network function; andin response to the retrieve request, retrieve and transmit the mode of NAS security supported by the particular network function.
45. The apparatus according to claim 44, wherein the request is received from a first network function for mobility management, or from a network function for unified data management.
46. An apparatus at a third network function in a core network, the apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:obtain information indicating respective modes of non-access stratum (NAS) security supported by each of a plurality of network functions;obtain first information indicating one or more modes of NAS security supported by a terminal device;determine an accepted mode of NAS security to be used for the terminal device; andtransmit to the terminal device, second information indicating the accepted mode of NAS security.
47. The apparatus according to claim 46, wherein the one or more modes of NAS security comprise at least one of following modes of NAS security: distributed NAS; single NAS; or hybrid NAS48. The apparatus according to claim 46 or 47, wherein the first information is received in an authentication request from a first network function for mobility management.
49. The apparatus according to claim 48, wherein the first information is indicated by a predefined parameter or is comprised in a concealed part of a subscription concealed identifier of the terminal device.
50. The apparatus according to claim 46 or 47, wherein the first information is retrieved from subscriber data of the terminal device which is stored in the third network function.5551. The apparatus according to any of claims 48 to 50, wherein the second information is transmitted to the terminal device via a message of authentication response.
52. The apparatus according to claim 46 or 47, wherein the first information is received in an uplink NAS message from the terminal device after a primary authentication for the terminal device.
53. The apparatus according to any of claims 46 to 52, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,transmit third information indicating modes of NAS security supported by the plurality of network functions.
54. The apparatus according to claim 53, wherein the third information indicates a bit map indicating whether the mode of distributed NAS is supported or not per network function.
55. The apparatus according to any of claims 46 to 54, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,in case that the first information is received in a message of authentication request,calculate an authentication challenge by utilizing at least one of the second information and the third information as input parameters; andtransmit the authentication challenge to the terminal device in the message of authentication response.
56. The apparatus according to claim 55, wherein the authentication challenge is an authentication token (AUTN).
57. The apparatus according to claim 55 or 56, wherein when the instructions are executed by the at least one processor, the instructions further cause the apparatus at least to,utilize the at least one of the second information and the third information as input parameters for key generation.
58. The apparatus according to claim 57, wherein the at least one of the second information and the third information is utilized for generation of a key KAUSF.
59. The apparatus according to any of claims 46 to 58, wherein the third network function is a network function for authentication and unified data management in a home network of the terminal device.
60. A method performed at a terminal device, the method comprising:transmitting to a core network, first information indicating one or more modes of non-access stratum (NAS) security supported by the terminal device;56receiving from the core network, second information indicating an accepted mode of NAS security; andestablishing a NAS connection with a network function based on the accepted mode of NAS security.
61. The method according to claim 60, further comprising:receiving third information indicating modes of NAS security supported by a plurality of network functions.
62. The method according to claim 60 or 61, further comprising:determining whether distributed NAS is supported by a second network function, in case that the accepted mode of NAS security is hybrid NAS.
63. The method according to any of claims 60 to 62, further comprising:establishing a NAS connection with a second network function by using a separate security association dedicated for the second network function, in case that the accepted mode of NAS security is distributed NAS, or in case that the accepted mode of NAS security is hybrid NAS while the second network function supports distributed NAS.
64. A method performed at a first network function for mobility management, the method comprising:determining an accepted mode of non-access stratum (NAS) security to be used for the terminal device; andtransmitting to the terminal device, second information indicating the accepted mode of NAS security.
65. The method according to claim 64, further comprising:receiving from the terminal device, a message of registration request which comprises first information indicating one or more modes of NAS security supported by the terminal device.
66. The method according to claim 64 or 65, further comprising:receiving an uplink NAS message from a terminal device after a primary authentication for the terminal device, wherein the uplink NAS message comprise first information indicating one or more modes of NAS security supported by the terminal device.
67. The method according to any of claims 64 to 66, further comprising:determining whether the one or more modes of NAS security is supported by the first network function.
68. The method according to any of claims 64 to 67, further comprising:transmitting the first information to a third network function; and receiving the second information from the third network function, wherein the third network function is a network function for authentication and57unified data management in a home network of the terminal device.
69. The method according to claim 68, further comprising:receiving from the third network function, third information indicating modes of NAS security supported by a plurality of network functions.
70. The method according to claim 69, further comprising:transmitting the received third information to the terminal device.
71. The method according to any of claims 64 to 70, further comprising:in case that the accepted mode of NAS security is hybrid NAS, transmitting to a second network function, a service request from the terminal device which comprises fourth information indicating that hybrid NAS is supported by the terminal device; andin response to the service request, receiving from the second network function, a fifth information indicating whether distributed NAS security is supported by the second network function or not.
72. The method according to claim 71, further comprising:notifying the terminal device that distributed NAS is supported by the second network function, in case that the fifth information indicates that distributed NSA is supported by the second network function.
73. The method according to any of claims 64 to 72, further comprising:providing NAS security for data transfer between the terminal device and the second network function, in case that the fifth information indicates that distributed NSA is not supported by the second network function.
74. A method performed at a second network function in a core network, the method comprising:transmitting information indicating a mode of non-access stratum (NAS) security supported by the second network function, to a network repository function or a first network function for mobility management.
75. The method according to claim 74, further comprising:establishing a NAS connection with a terminal device by using a separate security association dedicated for the second network function, in case that the second network function supports distributed NAS.
76. A method performed at a network repository function in a core network, the method comprising:receiving from each of one or more network functions, information indicating modes of non-access stratum (NAS) supported by respective network functions; andstoring the received information for each of the one or more network functions.
77. A method performed at a third network function in a core network, the methodcomprising:obtaining information indicating respective modes of non-access stratum (NAS) security supported by each of one or more network functions;obtaining first information indicating one or more modes of NAS security supported by a terminal device;determining an accepted mode of NAS security to be used for the terminal device; andtransmitting to the terminal device, second information indicating the accepted mode of NAS security.
78. A computer-readable medium having computer program codes embodied thereon which, when executed by a processor, cause the processor to perform the method according to any one of claims 60 to 77.
79. A computer program product comprising computer programs or instructions which, when executed by a processor, cause the processor to perform the method according to any one of claims 60 to 77.