Multiple network layer registration and authentication

WO2026195335A1PCT designated stage Publication Date: 2026-09-24NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/055768
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-21
Filing Date
2026-03-03
Publication Date
2026-09-24

Smart Images

  • Figure EP2026055768_24092026_PF_FP_ABST
    Figure EP2026055768_24092026_PF_FP_ABST
Patent Text Reader

Abstract

Example embodiments of the present disclosure are directed to multiple network layer registration and authentication. A method comprises obtaining, from a device, a user plane function, UPF, key; determining at least one network specific key of at least one network with which the apparatus is successfully authenticated; and transmitting, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] MULTIPLE NETWORK LAYER REGISTRATION AND AUTHENTICATION

[0002] FIELD

[0003] [1] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to method, apparatus, system, and computer program for multiple network layer registration and authentication.

[0004] BACKGROUND

[0005] [2] A communication network may serve as a facility that enables communications between two or more communication devices or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.

[0006] [3] The communication network may operate in accordance with standards such as those provided by Third Generation Partnership Project (3GPP) or European Telecommunications Standards Institute (ETSI). Examples of standards provided by 3GPP are the so-called 3GPP standards for cellular technology generations, such as 3GPP standards for 4G technology, 5G technology, 6G technology, and so on.

[0007] SUMMARY

[0008] [4] In a first aspect of the present disclosure, there is provided an apparatus. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: obtain, from a device, a user plane function (UPF) key; determine at least one network specific key of at least one network with which the apparatus is successfully authenticated; and transmit, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

[0009] [5] In a second aspect of the present disclosure, there is provided a network entity. The network entity comprises at least one processor; and at least one memory storinginstructions that, when executed by the at least one processor, cause the network entity at least to: obtain, from a further network entity, a UPF key; receive, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key corresponding to the network; and determine second decrypted data using the UPF key.

[0010] [6] In a third aspect of the present disclosure, there is provided a method. The method comprises: obtaining, by the apparatus from a device, a UPF key; determining at least one network specific key of at least one network with which the apparatus is successfully authenticated; and transmitting, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

[0011] [7] In a fourth aspect of the present disclosure, there is provided a method. The method comprises: obtaining, by the network entity from a further network entity, a UPF key; receiving, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key corresponding to the network; and determining second decrypted data using the UPF key.

[0012] [8] In a fifth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for obtaining, from a device, a UPF key; means for determining at least one network specific key of at least one network with which the apparatus is successfully authenticated; and means for transmitting, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

[0013] [9] In a sixth aspect of the present disclosure, there is provided a network entity. The network entity comprises means for obtaining, from a further network entity, a UPF key; means for receiving, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key corresponding to the network; and means for determining second decrypted data using the UPF key.

[0010] In a seventh aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the third aspect.

[0014]

[0011] In an eighth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fourth aspect.

[0015]

[0012] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.

[0016] BRIEF DESCRIPTION OF THE DRAWINGS

[0017]

[0013] Some example embodiments will now be described with reference to the accompanying drawings, where:

[0018]

[0014] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;

[0019]

[0015] FIG. 2 illustrates an example diagram of a multiple network layer network;

[0020]

[0016] FIG. 3 illustrates a signaling chart according to some example embodiments of the present disclosure;

[0021]

[0017] FIG. 4 illustrates a signaling chart according to some example embodiments of the present disclosure;

[0022]

[0018] FIG. 5 illustrates a signaling chart according to some example embodiments of the present disclosure;

[0023]

[0019] FIGS. 6A-6C illustrate key generation processes and a key template according to some example embodiments of the present disclosure;

[0024]

[0020] FIG. 7 illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;

[0025]

[0021] FIG. 8 illustrates a flowchart of a method implemented at a network entity in accordance with some example embodiments of the present disclosure;

[0026]

[0022] FIG. 9 illustrates a flowchart of a method implemented at an apparatus in accordancewith some example embodiments of the present disclosure;

[0027]

[0023] FIG. 10 illustrates a flowchart of a method implemented at a network entity in accordance with some example embodiments of the present disclosure;

[0028]

[0024] FIG. 11 illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;

[0029]

[0025] FIG. 12 illustrates a flowchart of a method implemented at a network entity in accordance with some example embodiments of the present disclosure;

[0030]

[0026] FIG. 13 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and

[0031]

[0027] FIG. 14 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.

[0032]

[0028] Throughout the drawings, the same or similar reference numerals represent the same or similar element.

[0033] DETAILED DESCRIPTION

[0034]

[0029] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.

[0035]

[0030] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same mean as commonly understood by one of ordinary skills in the art to which this disclosure belongs.

[0036]

[0031] References in the present disclosure to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature,structure, or characteristic in connection with other embodiments whether or not explicitly described.

[0037]

[0032] It shall be understood that although the terms “first,” “second,”... , etc. in front of noun(s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun(s). For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0038]

[0033] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0039]

[0034] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.

[0040]

[0035] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.

[0041]

[0036] As used in this application, the term “circuitry” may refer to one or more or all of the following:

[0042] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and

[0043] (b) combinations of hardware circuits and software, such as (as applicable):

[0044] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0045] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0046]

[0037] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0047]

[0038] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.

[0048]

[0039] As used herein, the term “network device” refers to a node in a communicationnetwork via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.

[0049]

[0040] As used herein, the term “network device” also may refer to a core network (CN) entity / node / function / apparatus / device. Example core network nodes may such as include functions of one or more of a location management function (LMF), mobile switching center (MSC), mobility management entity (MME), home subscriber server (HSS), access and mobility management function (AMF), session management function (SMF), authentication server function (AUSF), subscription identifier de-concealing function (SIDF), unified data management (UDM), security edge protection proxy (SEPP), network exposure function (NEF), and / or a user plane function (UPF) and so on.

[0050]

[0041] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounteddisplay (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user equipment” and “UE” may be used interchangeably.

[0051]

[0042] As used herein, the term “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.

[0052]

[0043] FIG. 1 shows an example communication environment 100 in which example embodiments of the present disclosure may be implemented. The communication environment 100 includes a plurality of apparatuses or devices, such as an apparatus 110, a device 120 and a network entity 130.

[0053]

[0044] The apparatus 110 may comprise or implemented as a terminal device that can communicate with the device 120 and the network entity 130 via a wireless channel.

[0054]

[0045] As shown in FIG. 1, the device 120 may comprise a plurality of devices capable of performing communication with the apparatus 110 or the network entity 130. The device 120 may comprise a device 120-1 in terrestrial network, and the device 120-1 in terrestrial network may comprise a network node, for example, the gNB, the eNB and a 6G node.

[0055]

[0046] The device 120 may comprise a device 120-2 in space network, and the device 120-2 in space network may comprise a plurality of satellites. For example, the device 120-2 in space network may comprise a geostationary earth orbit (GEO) satellite, a mediumearth orbit (MEO) satellite and a low earth orbit (LEO) satellite.

[0056]

[0047] The device 120 may also comprise a device 120-3 in aerial network, and the device 120-3 in arial network may comprise a device in a high-altitude platform system (HAPS) that can be implemented at an aerial vehicle. The aerial vehicle may comprise or implemented as, for example, a high altitude air ship, higher altitude with long range unmanned aerial vehicle (UAV) and a drone.

[0057]

[0048] The apparatus 110 and / or the device 120 may communicate with the network entity 130. In some examples, the network entity 130 may include or implement the UPF. The UPF may handle user data traffic, including packet routing, forwarding, and quality of service (QoS) enforcement, or the like. The network entity 130 may also include or implement a mobility management (MM) network function (NF). The MM NF may handle the mobility -related tasks of user devices within a mobile network.

[0058]

[0049] For example, the network entity 130 may also include or implement a home network (HN) that supports the AUSF for handling an authentication request and the UDM function for managing related data of a user.

[0059]

[0050] In some other examples, the network entity 130 may also include or implement the SMF for managing a session between the user and the network device.

[0060]

[0051] In addition, the network entity 130 may also include or implement the AMF, the SMF, a session management (SM) NF, and the like (other NFs). The AMF may manage device connectivity and mobility, such as registration, authentication and tracking location changes. The SMF may control user sessions, including setup, modification and termination of the user sessions. The SM NF may manage sessions for the network.

[0061]

[0052] A core network function as described herein may be implemented as a core network entity that includes a combination of hardware processing circuit and software and / or firmware comprising machine-readable instructions, or software comprising machine-readable instructions that are executable by at least one processor of hardware processing circuit of an apparatus. A hardware processing circuit includes at least one processor and at least one memory storing machine-readable instructions that are executable by the at least one processor of the hardware processing circuit. A processor includes any or some combination of an accelerator, a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digitalsignal processor, a central processing unit, a graphic processing unit, a tensor processing unit.

[0062]

[0053] Memory includes any or some combination of volatile or non-volatile memory (e.g., a flash memory, cache, a random-access memory (RAM), and / or a read-only memory (ROM)). The memory stores the machine-readable instructions of the software and / or firmware for execution by the at least one processor of the hardware processing circuit. The machine-readable instructions are executable by the at least one processor of the hardware processing circuit cause the hardware processing circuit to perform the actions or operations of the methods described herein. For example, the session management function described herein may be implemented as a session management entity and the session management policy control function described herein may be implemented as a session management policy control entity, respectively.

[0063]

[0054] In some example embodiments, a direction from the device 120 or network entity 130 to the apparatus 110 is referred to as a downlink (DL), while a direction from the apparatus 110 to the device 120 or network entity 130 is referred to as an uplink (UL). In DL, the device 120 or network entity 130 is a transmitting (TX) device (or a transmitter) and the apparatus 110 is a receiving (RX) device (or a receiver). In UL, the apparatus 110 is a TX device (or a transmitter) and the device 120 or network entity 130 is a RX device (or a receiver).

[0064]

[0055] It is to be understood that the number of devices and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of devices configured to implement example embodiments of the present disclosure. Although not shown, it would be appreciated that one or more additional devices may be located in the cell provided by the device 120, and one or more additional cells may be deployed in the communication environment 100. It is noted that although illustrated as a network node or entity, the device 120 or network entity 130 may be another device than a network node or entity. Although illustrated as a terminal device, the apparatus 110 may be another device than a terminal apparatus.

[0065]

[0056] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols, wireless local network communication protocols suchas Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.

[0066]

[0057] In some discussed schemes, an efficient interconnection and integration between the NTN and a future 6G system on a multiple network layer basis is required to support new use cases and services.

[0067]

[0058] Reference is now made to FIG. 2, which shows a multi-layer network. A multilayered infrastructure shown in FIG. 2 consists of satellites 210, 220, 230 including GEO / non-geostationary earth orbit (NGEO), high altitude platforms (HAPs) 240, ground network 250 including ground stations (such as a base station 251), gateways (such as a gateway 252) and terminals (such as a terminal device 253) showcasing the integration of various spaceborne, airborne, and ground-based communication layers.

[0068]

[0059] The space segment is categorized into GEO satellites 210, MEO satellites 220, and LEO satellites 230, forming a hierarchical structure for data transmission and relay. Each orbital layer has distinct characteristics: GEO satellites 210 provide wide coverage with higher latency, MEO satellites 220 balance coverage and latency, and LEO satellites 230 offer low latency with more localized coverage. These layers are interconnected through inter-satellite links (ISL), service link (SL) and feeder link (FL), creating a robust and flexible communication framework that supports efficient resource allocation and enhanced connectivity.

[0069]

[0060] In addition to the spaceborne elements, an example diagram shown in FIG. 2 integrates the HAPS 240 and the aerial vehicles, such as the drones 242 and aircrafts 241, to bridge an aerial and ground network 250. These aerial platforms provide complementary coverage in regions where ground infrastructure may be sparse or infeasible. A ground network 250, represented by ground stations 252, terminal devices 253, interacts seamlessly with aerial and spaceborne components, leveraging NTN’smulti-layered design to ensure ubiquitous coverage.

[0070]

[0061] This layered architecture is important for 6G communication systems, which aims to deliver reliable, low-latency connectivity for diverse applications, including the loT, vehicular communication, and remote area services. An interplay of these layers facilitates resilience, scalability, and enhanced service continuity in challenging scenarios.

[0071]

[0062] The multi-layer architecture of NTNs (as shown in FIG. 2) presents unique opportunities for diverse use cases but also introduces significant challenges, particularly in the areas of registration and authentication. For instance, in disaster response scenarios, emergency services can leverage the LEO satellites 230 for low-latency communication, while the GEO satellites 210 ensure broad coverage for coordination across affected regions.

[0072]

[0063] Similarly, the HAPS 240 and drones 242 can provide localized, high-capacity connectivity for loT devices in precision agriculture or enable seamless communication for autonomous vehicles in remote areas.

[0073]

[0064] However, these dynamic and distributed environments necessitate robust mechanisms for user registration and authentication. Devices and users frequently move across different layers, such as transitioning from an aerial network (e.g., the drones 242 / the UAV 244, the airships 243) to the satellite network or a space network (e.g., LEO satellites 230 or GEO satellites 210 or MEO satellite 220). This mobility complicates the assignment and verification of unique identities, session continuity, and the prevention of unauthorized access.

[0074]

[0065] Addressing these challenges requires developing an adaptive authentication framework that incorporate satellite-specific attributes, manage cross-layer handovers efficiently, and maintain security without compromising latency or resource constraints.

[0075]

[0066] In order to solve at least part of the above problems or other potential problems, several solutions for multi-layer registration and authentication are proposed in accordance with some embodiments of the present disclosure. The solutions proposed in the preset disclosure provide a multi-layer registration and authentication process for a 6G system.

[0076]

[0067] In a solution, the apparatus 110 transmits a registration request to a device 120. The registration request at least comprising an indication indicative of at least one of acapability and a requirement of the apparatus 110 for accessing at least one network comprising a terrestrial network and at least one non-terrestrial network. If an authentication procedure is triggered associated with the registration request, the apparatus 110 performs an authentication procedure between the apparatus 110 and one or more networks that are allowed to be accessed by the apparatus 110. The apparatus 110 receives, from the device 120, a registration response indicating a result of the authentication procedure.

[0077]

[0068] In this manner, the authentication procedure for the apparatus can be performed based on the capability of the apparatus 110 and the requirement for accessing the network. Thus, the efficiency of the multi-layer registration and authentication process can be improved by reducing redundant authentication steps.

[0078]

[0069] FIG. 3 illustrates a signaling flow 300 for the multiple network layer registration and authentication in accordance with some example embodiments of the present disclosure. The signaling flow 300 involves the apparatus 110, the device 120 and the network entity 130. By way of example, the apparatus 110 may be referred to as the terminal device, and the device 120 may be referred to as the device 120-1 in terrestrial network (comprising a 6G NB 302), the device 120-2 in space network (comprising the LEO satellite 304, the MEO satellite 306 and the GEO satellite 308) and the device 120-3 in aerial network (comprising the HAPS 310). The network entity 130 may be referred to a 6G MM NF 312 or aHN 314.

[0079]

[0070] In the scenario shown in FIG. 3, the 6G MM NF 312 may be referred to as a network entity, and the HN 314 may be referred to as a further network entity.

[0080]

[0071] In operation, the apparatus 110 transmits (330) a registration request to the device 120. Correspondingly, the device 120 receives (330) the registration request.

[0081]

[0072] In some embodiments, the registration request may be received by the 6G NB 302, which may serve as the device in the terrestrial network.

[0082]

[0073] Based on the registration request from the apparatus 110, the device 120 transmits (335) the registration request to the network entity 130. For example, the device 120 may forward the registration request to the 6G MM NF 312 which handles an authorization procedure for an authentication of the at least one network.

[0083]

[0074] In some embodiments, the registration request may at least comprise the indicationindicative of at least one of a capability and a requirement of the apparatus 110 for accessing at least one network.

[0084]

[0075] In some embodiments, the indication sent from the apparatus 110 in registration request may be referred to as a multi-network layer indication or a multi-layer indication. The capability of the apparatus 110 may indicate which network layer or network layers that the apparatus 110 may be capable of accessing. The requirement may indicate that the apparatus 110 requires access for one or more networks among all types of networks. For example, the requirement may indicate that the apparatus 110 requires access for an aerial network.

[0085]

[0076] As an example, the multi-layer indication may indicate the capability of the apparatus 110 or the multi-layer indication may indicate the requirement of the apparatus 110 for accessing the network separately. Alternatively, or in addition, the multi-layer indication may indicate both the capability and the requirement.

[0086]

[0077] In some embodiments, the at least one network mentioned above may be referred to as one or more network layers. The at least one network may comprise the terrestrial network and at least one non-terrestrial network. In some examples, the at least one nonterrestrial network may comprise the aerial network which may be operated by the device 120-3 in aerial network in FIG. 3. The at least one non-terrestrial network may also comprise the satellite network (or the space network device) which may be operated by the device 120-2 in space network in FIG. 3.

[0087]

[0078] In this way, the apparatus 110 may perform a registration and authentication process with multiple different network layers, which expands an access capability of the apparatus 110.

[0088]

[0079] In some embodiments, the registration request may comprise a 6G subscription concealed identifier (SUCI) which is an identifier obtained through encrypting a subscription permanent identifier (SUPI) of the apparatus 110.

[0089]

[0080] In some scenarios, the registration request may comprise some additional information related to a registration and authentication procedure. For example, the registration request may further comprise at least one identifier of at least one component associated with the at least one network supported by the capability of the apparatus 110.

[0090]

[0081] For example, if the apparatus 110 is capable of accessing the satellite network, theregistration request may further comprise an identifier of a satellite in this satellite network that the apparatus 110 may be capable of accessing. As another example, if the apparatus 110 is capable of accessing the terrestrial network, the registration request may further comprise an identifier of a terrestrial cell in this terrestrial network that the apparatus 110 may be capable of accessing. As yet another example, if the apparatus 110 is capable of accessing the aerial network, the registration request may further comprise an identifier of a HAPS in this aerial network that the apparatus 110 may be capable of accessing.

[0091]

[0082] In this way, the registration request may comprise various information related to the registration and authentication procedure, which reduces a number of unnecessary request sent by the apparatus 110 during the registration and authentication procedure. Thereby, the efficiency of the registration and authentication procedure can be improved, and a finer control of the whole procedure can also be realized.

[0092]

[0083] Alternatively or in addition, the registration request may further comprise a further indication indicative of at least one component level to which the at least one component belongs.

[0093]

[0084] In some embodiments, a component level of a satellite may indicate an earth orbit to which the satellite belongs. For example, the component level of the LEO satellite 304 may indicate that the LEO satellite 304 belongs to the LEO.

[0094]

[0085] In some embodiments, a component level of a HAPS may indicate a serving type associated with the HAPS. For example, the component level of the HAPS 310 may indicate that the HAPS 310 is serving as the airship.

[0095]

[0086] In some embodiments, a component level of a terrestrial cell may indicate a characteristic of the terrestrial cell. For example, the component level of the terrestrial cell may indicate a type of a cell provided by the 6G NB 302.

[0096]

[0087] As mentioned above, by transmitting the further indication indicating the component level of the device 120, a component level registration is enabled. With the component level registration, the apparatus 110 may directly register with individual components (e.g., specific satellites, HAPS, or ground stations) within the network layer (or the network). This can add more granularity with specifying the components within each network layer. Hence the user can particularly register for one specific component(with its identifier) in the network layer or across network layers (or in the network or across networks).

[0097]

[0088] In this way, the component level registration approach can offer high granularity, and allow tailored authentication and fault isolation at the component level. Furthermore, the component level registration within a network layer in Non-Terrestrial Networks can offer significant advantages by enabling fine-grained management of devices and resources. It can enhance scalability by distributing the registration workload across individual components, such as specific satellites or terrestrial nodes, and allows for network layer-specific optimization through tailored authentication mechanisms suited to the characteristics of each component.

[0098]

[0089] The component level registration approach can also improve fault isolation, as issues within a single component can be contained without affecting the entire network layer and facilitate seamless mobility management by localizing registrations to the serving component, thereby reducing latency during handovers.

[0099]

[0090] Additionally, the component level registration can strengthen security by enforcing granular access control and mitigates risks of unauthorized access or misuse. By maintaining a localized understanding of registered devices, the component level registration approach can also optimize resource allocation within the network layer, ensuring efficient use of bandwidth, power, and spectrum resources while maintaining overall network resilience.

[0100]

[0091] As shown in FIG. 3, if the registration request from the apparatus 110 comprises the at least one identifier of the at least one component, the network entity 130 may store (340) the at least one identifier at the network entity 130. For example, the at least one identifier may be stored at the 6G MM NF 312. With the stored identifier(s), the network entity 130 may not need to obtain them from the apparatus 110, e.g., when the apparatus 110 moves to a new cell.

[0101]

[0092] In this manner, a network layer-specific authentication can be enabled while reducing the need for repeated exchanges of credentials, thereby enhancing both efficiency and security of the registration and authentication procedure.

[0102]

[0093] In some embodiments, the network entity 130 may generate an authentication request based on the received registration request from the apparatus 110. Theauthentication request may comprise the SUCI indicated by the registration request for the network entity 130 to identify a source of the registration request.

[0103]

[0094] In some embodiments, as an option, if the at least one identifier is present in the registration request, the network entity 130 may obtain, via the registration request, the at least one identifier of at least one component associated with one or more networks supported by the capability of the apparatus 110. Based on the obtained at least one identifier, the network entity 130 may generate the authentication request indicating the indication (i.e., the multi-layer indication) and the at least one identifier.

[0104]

[0095] In some embodiments, as another option, if a further indication (i.e., the component level indication) is also present in the registration request, the network entity 130 may obtain, via the registration request, a further indication indicative of at least one component level to which the at least one component belongs. Based on the obtained component level indication, the network entity 130 may generate the authentication request indicating the indication (i.e., the multi-layer indication), the at least one identifier and the at least one component level.

[0105]

[0096] In this way, the authentication request can be generated based on the registration request, thereby increasing the efficiency and accuracy of generating the authentication request.

[0106]

[0097] As shown in FIG. 3, the network entity 130 transmits (345) the authentication request indicating the indication (i.e., the multi-layer indication) to the further network entity. For example, the 6G MM NF 312 may transmit the authentication request to the HN 314.

[0107]

[0098] In some embodiments, the network entity 130 may perform an authorization procedure for a multi-layer authentication procedure. For example, the HN 314 may collaborate with the 6G MM NF 312 to verify the authentication request and authorize (350) the multiple network layer authentication procedure.

[0108]

[0099] In some embodiments, the network entity 130 may generate an authentication response based on the authorization result. The authentication response may comprise the SUPI decrypted from the SUCI. Furthermore, the authentication response may also comprise an indication indicating allowed network layer (or network) for the apparatus 110.

[0100] For example, as an option, the HN 314 may determine which network layers or networks the apparatus 110 is allowed to access based on its subscription (derived using the capability of the apparatus 110 and the SUCI) and network capabilities and responds with the authentication response including the list of allowed network layers for the apparatus 110.

[0109]

[0101] In some embodiments, as another option, if the registration request comprises the at least one identifier, the authentication response may also comprise at least one component (e.g., at least one device within certain network layer or networks) corresponding to the at least one identifier that is allowed to be accessed by the apparatus 110.

[0110]

[0102] In some embodiments, as yet another option, if the registration request comprises the further indication indicative of at least one component level to which the at least one component belongs, the authentication response may further comprise an indication indicating at least one allowed component level for the apparatus 110.

[0111]

[0103] As shown in FIG. 3, the further network entity (i.e., the HN 314) transmits (355) the authentication response to the network entity (i.e., the 6G MM NF 312).

[0112]

[0104] In some embodiments, if the network entity (e.g., the 6G MM NF 312 or the HN 314) determines that the authentication response, received from the further network entity (e.g., the HN 314) indicates the one or more networks allowed to be accessed by the apparatus 110, the network entity 130 may trigger the authentication procedure between the apparatus 110 and the at least one network.

[0113]

[0105] For example, if the HN 314 confirms the subscription and eligibility of the apparatus 110, the authentication procedure may be triggered between apparatus 110 and each network types.

[0114]

[0106] In some embodiments, the authentication procedure may comprise separate authentication procedures between the apparatus 110 and each network layer or network (e.g., the terrestrial network, the aerial network, and the satellite network (or the space network)).

[0115]

[0107] In some embodiments, if the apparatus 110 determines that the authentication procedure is triggered associated with the registration request, the apparatus 110 may perform the authentication procedure between the apparatus 110 and one or more networks that is allowed to be accessed by the apparatus 110.

[0108] As shown in FIG. 3, the first apparatus 110 performs (360) the authentication procedure with the terrestrial network using a subscriber identity module (SIM) card. In some examples, the authentication procedure between the apparatus 110 and the terrestrial network may also be performed using an authentication vector.

[0116]

[0109] In some embodiments, if the authentication procedure is successful, the apparatus 110 may be granted access to the terrestrial network.

[0117] [HO] In some embodiments, different authentication mechanisms may be used for the authentication procedure on the at least one non-terrestrial network in the network. For example, the non-terrestrial network may be authenticated based on a certificate-based authentication. The certificate-based authentication may use digital certificates to verify an identity of a user (i.e., the apparatus 110).

[0118] [Hl] In some other examples, the non-terrestrial network may be authenticated based on a multi -factor authentication. The multi-factor authentication requires a user (i.e., the apparatus 110) to provide two or more forms of identification, such as a password and a one-time code, in order to log in.

[0119]

[0112] In some examples, as shown in FIG. 3, the apparatus 110 performs (365) the authentication procedure with the aerial network (e.g., HAPS 310) using a certificatebased authentication method. If authentication procedure is successful, the apparatus 110 may access the aerial network.

[0120]

[0113] In some other examples, as shown in FIG. 3, the apparatus 110 performs (370) the authentication procedure with the space network (or the satellite network) using a multifactor authentication method. If successful, the apparatus 110 may access the space network (or the satellite network).

[0121]

[0114] Through the above process, secure and distinct authentication for each network layer or network can be ensured while maintaining centralized control.

[0122]

[0115] In some embodiments, the network entity 130 may transmit, to the apparatus 110, the registration response indicating a result of the authentication procedure. The registration response may be transmitted to the device in terrestrial network 120 first, then the device 120 may forward the registration response to the apparatus 110.

[0123]

[0116] As shown in FIG. 3, the 6G MM NF 312 transmits (375) the registration response to the 6GNB 302. As an example, once the apparatus 110 has successfully authenticatedwith all desired networks, the 6G MM NF 312 may send the registration response to the apparatus 110 (via the device 120), providing its 6G temporary mobile subscriber identity (6G-TMSI) and confirming a successful authentication across all network layers.

[0124]

[0117] Upon receiving the registration response, the 6G NB 302 may forward the registration response to the apparatus 110. As shown in FIG. 3, the apparatus 110 receives (380), from the device 120, the registration response indicating the result of the authentication procedure.

[0125]

[0118] In this way, an efficient and secure registration and authentication procedure can be achieved. The apparatus 110 can provide different information for the authentication process based on the configuration (e.g., whether the component level registration is enabled), thereby increasing processing speed of the authentication procedure and ensuring authentication success rate.

[0126]

[0119] In some other scenarios, the apparatus 110 may update its registration request according to a modification of the at least one network that is desired to be accessed by the apparatus 110.

[0127]

[0120] In this case, the apparatus 110 receives, from the device 120, the registration response indicative of the successful authentication between the apparatus 110 and at least one network comprising the terrestrial network and the at least one non-terrestrial network. If the apparatus 110 determines that the at least one network is to be modified, the apparatus 110 transmits, to the device 120, the registration request for updating the at least network currently serving the apparatus 110. The apparatus 110 performs the authentication procedure between the apparatus 110 and one or more networks to be updated associated with the registration request. The apparatus 110 receives, from the device 120, a further registration response indicating the result of the authentication procedure. With this solution, a high efficiency updating procedure can be achieved.

[0128]

[0121] FIG. 4 illustrates a signaling flow 400 for multiple network layer registration and authentication in accordance with some example embodiments of the present disclosure. The signaling flow 400 involves the apparatus 110, the device 120 and the network entity 130 in FIG. 1.

[0129]

[0122] In operation, the apparatus 110 may transmit (430) the registration request to the 6G NB 302. Upon receiving the registration request, the 6G NB 302 may transmit (435)the registration request to the 6G MM NF 312.

[0130]

[0123] Based on the received registration request, the 6G MM NF 312 may generate and transmit (440) the authentication request to the HN 314. The HN 314 may perform the authorization procedure and transmit (445) the authentication response to the 6G MM NF 312. The authentication procedure may also be triggered once the authorization procedure is completed.

[0131]

[0124] If the authentication procedure is triggered, the apparatus 110 may perform (450) the authentication procedure with the terrestrial network (referred to as an initial registration as well). Based on the performed authentication procedure, the 6G MM NF 312 may generate and transmit (455) the registration response to the 6G NB 302 (i.e., the device 120).

[0132]

[0125] As shown in FIG. 4, the apparatus 110 receives (460) the registration response from the device 120. The registration response may be indicative of the successful authentication between the apparatus 110 and at least one network comprising the terrestrial network and the at least one non-terrestrial network.

[0133]

[0126] The steps 430-460 shown in FIG. 4 are similar to the step described in connection with FIG. 3. These steps may be referred to as a previous round of the registration and authentication procedure.

[0134]

[0127] In some embodiments, the apparatus 110 may update (465) the registration request to indicate an update of the at least one network currently serving the apparatus 110.

[0135]

[0128] As shown in FIG. 4, if the apparatus 110 determines that the at least one network is to be modified, the apparatus 110 transmits (470), to the device 120, the registration request for updating the at least one network currently serving the apparatus 110. For example, the apparatus 110 may transmit the updated registration request to the 6G NB 302.

[0136]

[0129] In some embodiments, the registration request for updating the at least one network currently serving the apparatus 110 may comprise an indication indicative of an updated capability and requirement of the apparatus 110 for accessing the network. The network may comprise the terrestrial network and at least one non-terrestrial network.

[0137]

[0130] In some examples, if the apparatus 110 determines to remove some of the serving networks, the registration request may comprise one or more networks to be removed fromthe at least one network caused by the updated capability and requirement.

[0138]

[0131] In some other examples, if the apparatus 110 requires some additional serving networks, the registration request may comprise one or more networks to be added to the at least one network caused by the updated capability and requirement.

[0139]

[0132] In some embodiments, the registration request may also comprise at least one identifier of at least one component associated with the one or more networks to be updated. For example, based on a demand of the apparatus 110, an existing registration request may be modified with identifiers of other network layer components.

[0140]

[0133] Furthermore, if the component level is indicated by the apparatus 110, the registration request may further comprise at least one component level to which the at least one component belongs. Alternatively or in addition, the registration request may also comprise the SUCI associated with the apparatus 110.

[0141]

[0134] In this way, the registration request may indicate the update of the capability, the requirement and the networks in an agile manner, thereby increasing the efficiency of updating the registration request.

[0142]

[0135] Upon receiving the registration request, the 6G NB 302 may forward the registration request to the network entity 130. For example, the network entity 130 receives (475), from the apparatus 110, a registration request for updating the at least one network currently serving the apparatus 110.

[0143]

[0136] As shown in FIG. 4, the network entity transmits (480), to a further network entity (i.e., the HN 314), an authentication request indicating one or more networks to be updated that are required by the apparatus 110 in the registration request. For example, the 6G MM NF 312 may generate the authentication request based on the registration request of the apparatus 110, and transmit the authentication request to the HN 314.

[0144]

[0137] In some embodiments, the authentication request may further indicate at least one identifier of at least one component associated with the one or more networks to be updated. If the component level is indicated by the apparatus 110, the authentication request may also indicate at least one component level to which the at least one component belongs.

[0145]

[0138] Alternatively or in addition, the authentication request may further indicate the SUCI associated with the apparatus 110.

[0139] In some embodiments, the network entity 130 may perform (485) the authorization procedure for the multiple network layer authentication based on the authentication request.

[0146]

[0140] In some embodiments, the HN 314 may generate the authentication response and transmit (490) the authentication response to the 6G MM NF 312. If the authentication response received from the further network entity (i.e., the HN 314), indicates the one or more networks are allowed to be accessed by the apparatus 110, the authentication procedure between the apparatus 110 and the one or more networks may be triggered.

[0147]

[0141] As shown in FIG. 4, the apparatus 110 performs (492 and 494) the authentication procedure between the apparatus 110 and one or more networks to be updated associated with the registration request.

[0148]

[0142] For example, the apparatus 110 performs (492) the authentication procedure with the aerial network. As another example, the apparatus 110 performs (494) the authentication procedure with the space network (or satellite network).

[0149]

[0143] Upon finishing the authentication procedure, the network entity 130 transmits, to the apparatus 110, the registration response indicating the result of the authentication procedure. The registration response may be transmitted to the device 120 first, then the device 120 may forward the registration response to the apparatus 110.

[0150]

[0144] For example, the 6G MM NF 312 transmits (496) the registration response to the 6G NB 302. Upon receiving the registration response, the 6G NB 302 may forward the registration response to the apparatus 110. As an example, the apparatus 110 may receive (498), from the device 120, a further registration response indicating the result of the authentication procedure.

[0151]

[0145] In this way, an on-demand registration model is realized which ensures that resources and authentication efforts are allocated only when necessary, optimizing resource usage.

[0152]

[0146] The present disclosure also provides a solution for key distribution during the registration and authentication process. In the solution for key distribution, the apparatus 110 obtains a UPF key from the device 120. The apparatus 110 determines at least one network specific key of at least one network with which the apparatus 110 is successfully authenticated. The apparatus 110 transmits, to a component in the at least one network,data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

[0153]

[0147] In this way, a double encryption of the data to be transmitted can be achieved, thereby increasing the security of a transmission procedure of the data.

[0154]

[0148] FIG. 5 illustrates a signaling flow 500 for key distribution in accordance with some example embodiments of the present disclosure. The signaling flow 500 involves the apparatus 110, the device 120 and the network entity 130 in FIG. 1. The network entity 130 shown in FIG. 5 further comprises a UPF 505 and a 6G MM NF / SM NF 510

[0155]

[0149] In operation, at block 520, the multiple network layer authentication is determined to be successful. The multiple network layer authentication may comprise the authentication procedure described in connection with FIG. 3 and FIG. 4.

[0156]

[0150] In some embodiments, once the authentication procedure is completed and the apparatus 110 is authorized to use components across network layers, key provisioning (or key distribution) may be performed.

[0157]

[0151] As shown in FIG. 5, at steps 525, 530 and 535, the apparatus 110 determines at least one network specific key of at least one network with which the apparatus 110 is successfully authenticated.

[0158]

[0152] In some embodiments, the key distribution may be performed between the apparatus 110 and corresponding network network layer. As an example, the network specific key may be obtained through executing a security mode command (SMC) at the component.

[0159]

[0153] For example, at step 525, between the apparatus 110 and aerial network, a HAPS SMC is run and the network specific key corresponding to the aerial network is derived independently in HAPS and the apparatus 110.

[0160]

[0154] Reference is now made to FIG. 6A, which shows an example process for generating the network specific key (referred to as a HAPS key for discussion) corresponding to the aerial network.

[0161]

[0155] At step 610, the HAPS 310 may collect the root credentials associated with the apparatus 110. At step 615, the HAPS 310 may perform the authentication with the apparatus 110, and if the authentication is successful, the HAPS 310 may generate the HAPS key corresponding to the aerial network.

[0156] At step 620, the HAPS 310 may generate the HAPS key via master session key (MSK). At step 625, the HAPS key is generated and may be utilized to encrypt data from the apparatus 110.

[0162]

[0157] Referring back to FIG. 5, at step 530, a satellite SMC (also referred to as SAT SMC) is run and the network specific key corresponding to the space network (or satellite network) is derived independently in satellites (i.e., LEO satellite 304, MEO satellite 306 or GEO satellite 308) and the apparatus 110.

[0163]

[0158] Reference is now made to FIG. 6B, which shows an example process for generating the network specific key (referred to as a SAT key for discussion) corresponding to the space network or satellite network.

[0164]

[0159] At step 630, the device 120-2 in space network (e.g., the LEO satellite 304, the MEO satellite 306 and the GEO satellite 308) may collect the root credentials associated with the apparatus 110. At step 635, the device 120-2 in space network may perform the authentication with the apparatus 110, and if the authentication is successful, the device 120-2 in space network may generate the SAT key corresponding to the space network (or satellite network).

[0165]

[0160] At step 640, the device 120-2 in space network may generate the SAT key based on a multi-party computation key. At step 645, the SAT key is generated and may be utilized to encrypt the data from the apparatus 110.

[0166]

[0161] Referring back to FIG. 5, at step 535, a terrestrial SMC may be run and the network specific key corresponding to the terrestrial network is derived independently in 6G NB 302 and the apparatus 110.

[0167]

[0162] In some embodiments, the above-mentioned key generation process may be independent of AMF key hierarchy, and the at least one network specific key may be generated associated with a root credential between the corresponding network and the apparatus 110. For example, for the network specific key corresponding to the terrestrial network, it may be generated depending on the root credentials between the 6G NB 302 and the apparatus 110 without depending on the AMF key.

[0168]

[0163] At step 540, a protocol data unit (PDU) session is triggered. After the PDU session is triggered, the network entity 130 obtains (545) the UPF key from a further network entity. For example, the UPF 505 may obtain the UPF key from the 6G MM NF / SM NF510.

[0169]

[0164] In some embodiments, the UPF key may be derived via the AMF key. In some other embodiments, the UPF key may be obtained via the SMF. For example, the UPF 505 may fetch the UPF key from the 6G MM NF / SM NF 510 via the SMF.

[0170]

[0165] Reference is now made to FIG. 6C, which shows an example template for UPF key. As shown in block 660, the UPF key may comprise a UPF session identifier. The UPF session identifier may be a unique identifier assigned by the SMF to manage and control the user plane traffic flows handled by the UPF. The UPF key may also comprise a UPF length of the session identifier.

[0171]

[0166] Referring back to FIG .5, after the PDU session is triggered, the apparatus 110 obtains (550) the UPF key from the device 120. In some embodiments, the UPF key may be transmitted, from the network entity 130, to the device 120 first and then forwarded from the device 120 to the apparatus 110.

[0172]

[0167] In this solution, the double encryption for the data packets is implemented. Thus the data packets will be encrypted first with UPF keys and then with the network specific key in UE, and the details of the double encryption will be described in the following.

[0173]

[0168] In some embodiments, based on the obtained UPF key, the apparatus 110 may encrypt data packet to be transmitted using the UPF key. Furthermore, the apparatus 110 may also encrypt the data packet using the network specific key corresponding to the network that the data packet is to be transmitted to.

[0174]

[0169] As shown in FIG. 5, at step 555, 560 and 565, the apparatus 110 transmits, to a component in the at least one network, data encrypted by the UPF key and the network specific key, associated with a network to which the component belongs, among the at least one network specific key.

[0175]

[0170] For example, as shown in IFG. 5, if the data is to be transmitted to the device 120-1 in terrestrial network, the apparatus 110 encrypts the data with the UPF key and the terrestrial network key, and the apparatus 110 transmits (555) the encrypted data to the device 120-1 in terrestrial network.

[0176]

[0171] For another example, as shown in FIG. 5, if the data is to be transmitted to the device 120-3 in aerial network, the apparatus 110 encrypts the data with the UPF key and the HAPS key, and the apparatus 110 transmits (560) the encrypted data to the device 120-3in aerial network.

[0177]

[0172] For yet another example, as shown in FIG. 5, if the data is to be transmitted to the device 120-2 in space network (or the satellite device), the apparatus 110 encrypts the data with the UPF key and the SAT key, and the apparatus 110 transmits (565) the encrypted data to the device 120-2 in space network.

[0178]

[0173] In some embodiments, in the above data transmission process, the data encrypted by using the UPF key and the network specific key may be transmitted to the component via a user plane (UP) packet. The component herein may be referred to as the device within a network.

[0179]

[0174] In this way, through the above-described double encryption process, the security of the data packet can be ensured no matter whether links between the apparatus 110 and various network devices are secured or not. Moreover, the above-described double encryption process can also ensure that the UP packet transmitted over an air transmission is secured and cannot be decrypted with the network specific key or the UPF key only, thereby reducing the possibility of malicious packet sniffing.

[0180]

[0175] In some embodiments, the component in the network may receive the data encrypted by both the UPF key and the network specific key, and decrypt the encrypted data with the network specific key. Upon decrypting the encrypted data with the network specific key, the component in the network may further forward or transmit the encrypted data (with the UPF encryption only) to the network entity 130.

[0181]

[0176] In some embodiments, the network entity 130 may receive, from a component in the network with which the apparatus 110 is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus 110 by using a network specific key corresponding to the network. For example, the UPF 505 may receive the first decrypted data encrypted only with the UPF key.

[0182]

[0177] As shown in FIG. 5, the network entity 130 determines (570) second decrypted data using the UPF key. For example, the UPF 505 may decrypt the data packet with the UPF key and obtain original data.

[0183]

[0178] In this way, data packets can be routed via any network layer, while keeping the underlying encryption between apparatus 110 and the UPF 505 remaining the same. Through this procedure only the network specific keys and encryption will change(depending upon a routing entity). This encryption and decryption scheme can enable a de-centralized network structure and improve the effectiveness of the data encryption.

[0184]

[0179] Furthermore, the embodiment of the present disclosure can also enhance scalability through distributed registration processes and improve efficiency by reducing redundant authentication step. On the other hand, the above-described procedures can also strengthen security with tailored, network layer-specific protocols and optimize resource allocation through dynamic or component level registration.

[0185]

[0180] FIG. 7 shows a flowchart of an example method 700 implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 700 will be described from the perspective of the apparatus 110 in FIG. 1.

[0186]

[0181] At block 710, the apparatus 110 transmits, to a device, a registration request at least comprising an indication indicative of at least one of a capability and a requirement of the apparatus for accessing at least one network comprising a terrestrial network and at least one non-terrestrial network.

[0187]

[0182] At block 720, in accordance with a determination that an authentication procedure is triggered associated with the registration request, at block 730 the apparatus 110 performs an authentication procedure between the apparatus and one or more networks that is allowed to be accessed by the apparatus.

[0188]

[0183] At block 740, the apparatus 110 receives, from the device, a registration response indicating a result of the authentication procedure.

[0189]

[0184] In some example embodiments, the method 700 further comprises: transmitting, to the device via the registration request, at least one identifier of at least one component associated with the at least one network supported by the capability of the apparatus.

[0190]

[0185] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0191]

[0186] In some example embodiments, the method 700 further comprises: transmitting, to the device via the registration request, a further indication indicative of at least onecomponent level to which the at least one component belongs.

[0192]

[0187] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0193]

[0188] In some example embodiments, a component level of a HAPS indicates a serving type associated with the HAPS.

[0194]

[0189] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0195]

[0190] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0196]

[0191] In some example embodiments, the method 700 further comprises: performing the authentication procedure with the terrestrial network using a SIM card.

[0197]

[0192] In some example embodiments, different authentication mechanisms are used for the authentication procedure on the at least one non-terrestrial network in the network, and wherein a non-terrestrial network is authenticated based on a certificate-based authentication or a multi-factor authentication.

[0198]

[0193] In some example embodiments, the apparatus comprises a terminal device.

[0199]

[0194] FIG. 8 shows a flowchart of an example method 800 implemented at a network entity in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 800 will be described from the perspective of the network entity 130 in FIG. 1.

[0200]

[0195] At block 810, the network entity 130 receives, from an apparatus, a registration request at least comprising an indication indicative of at least one of a capability and a requirement of the apparatus for accessing at least one network comprising a terrestrial network and at least one non-terrestrial network.

[0201]

[0196] At block 820, the network entity 130 transmits, to a further network entity, an authentication request indicating the indication.

[0202]

[0197] At block 830, in accordance with a determination that an authentication response, received from the further network entity, indicating the one or more networks allowed to be accessed by the apparatus, at block 840, the network entity 130 triggers an authentication procedure between the apparatus and the at least one network.

[0198] At block 850, the network entity 130 transmits, to the apparatus, a registration response indicating a result of the authentication procedure.

[0203]

[0199] In some example embodiments, the method 800 further comprises: obtaining, via the registration request, the at least one identifier of at least one component associated with one or more networks supported by the capability of the apparatus; generating the authentication request indicating the indication and the at least one identifier; and transmitting the authentication request to the further network entity.

[0204]

[0200] In some example embodiments, the method 800 further comprises: storing the at least one identifier at the network entity.

[0205]

[0201] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0206]

[0202] In some example embodiments, the method 800 further comprises: obtaining, via the registration request, a further indication indicative of at least one component level to which the at least one component belongs; generating the authentication request indicating the indication, the at least one identifier and the at least one component level; and transmitting the authentication request to the further network entity.

[0207]

[0203] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0208]

[0204] In some example embodiments, a component level of a HAPS indicates a serving type associated with the HAPS.

[0209]

[0205] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0210]

[0206] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0211]

[0207] In some example embodiments, the apparatus comprises a terminal device and the device comprises a network entity.

[0212]

[0208] FIG. 9 shows a flowchart of an example method 900 implemented at an apparatusin accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 900 will be described from the perspective of the apparatus 110 in FIG. 1.

[0213]

[0209] At block 910, the apparatus 110 receives, from a device, a registration response indicative of a successful authentication between the apparatus and at least one network comprising a terrestrial network and at least one non-terrestrial network.

[0214]

[0210] At block 920, in accordance with a determination that the at least one network is to be modified, at block 930, the apparatus 110 transmits to the device, a registration request for updating the at least one network currently serving the apparatus.

[0215]

[0211] At block 940, the apparatus 110 performs an authentication procedure between the apparatus and one or more networks to be updated associated with the registration request.

[0216]

[0212] At block 950, the apparatus 110 receives, from the device, a further registration response indicating a result of the authentication procedure.

[0217]

[0213] In some example embodiments, the registration request for updating the at least one network currently serving the apparatus indicates at least one of the following: an indication indicative of an updated capability and requirement of the apparatus for accessing the at least one network comprising the terrestrial network and the at least one non-terrestrial network, the one or more networks to be removed from the at least one network caused by the updated capability and requirement, the one or more networks to be added to the at least one network caused by the updated capability and requirement, at least one identifier of at least one component associated with the one or more networks to be updated, at least one component level to which the at least one component belongs, or a SUCI associated with the apparatus.

[0218]

[0214] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0219]

[0215] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0220]

[0216] In some example embodiments, a component level of a HAPS indicates a servingtype associated with the HAPS.

[0221]

[0217] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0222]

[0218] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0223]

[0219] In some example embodiments, the method 900 further comprises: performing the authentication procedure with the terrestrial network using a SIM card.

[0224]

[0220] In some example embodiments, different authentication mechanisms are used for the authentication procedure on the at least one non-terrestrial network in the network, and wherein a non-terrestrial network is authenticated based on a certificate-based authentication or a multi-factor authentication.

[0225]

[0221] In some example embodiments, the apparatus comprises a terminal device.

[0226]

[0222] FIG. 10 shows a flowchart of an example method 1000 implemented at a network entity in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1000 will be described from the perspective of the network entity 130 in FIG. 1.

[0227]

[0223] At block 1010, the network entity 130 receives, from the apparatus, a registration request for updating the at least one network currently serving the apparatus, wherein the at least one network comprises a terrestrial network and at least one non-terrestrial network.

[0228]

[0224] At block 1020, the network entity 130 transmits, to a further network entity, an authentication request indicating one or more networks to be updated that are required by the apparatus in the registration request.

[0229]

[0225] At block 1030, in accordance with a determination that an authentication response, received from the further network entity, indicating the one or more networks are allowed to be accessed by the apparatus, at block 1040, the network entity 130 triggers an authentication procedure between the apparatus and the one or more networks.

[0230]

[0226] At block 1050, the network entity 130 transmits, to the apparatus, a registration response indicating a result of the authentication procedure.

[0231]

[0227] In some example embodiments, the registration request for updating the at least onenetwork currently serving the apparatus indicates at least one of the following: an indication indicative of an updated capability and requirement of the apparatus for accessing the at least one network comprising the terrestrial network and the at least one non-terrestrial network, the one or more networks to be removed from the at least one network caused by the updated capability and requirement, the one or more networks to be added to the at least one network caused by the updated capability and requirement, at least one identifier of at least one component associated with the one or more networks to be updated, at least one component level to which the at least one component belongs, or a SUCI associated with the apparatus.

[0232]

[0228] In some example embodiments, the authentication request further indicates at least one of the following: at least one identifier of at least one component associated with the one or more networks to be updated, at least one component level to which the at least one component belongs, or a SUCI associated with the apparatus.

[0233]

[0229] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0234]

[0230] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0235]

[0231] In some example embodiments, a component level of a HAPS indicates a serving type associated with the HAPS.

[0236]

[0232] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0237]

[0233] In some example embodiments, the method 1000 further comprises: storing the at least one identifier at the network entity.

[0238]

[0234] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0239]

[0235] In some example embodiments, the apparatus comprises a terminal device and the device comprises a network entity.

[0236] FIG. 11 shows a flowchart of an example method 1100 implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1100 will be described from the perspective of the apparatus 110 in FIG. 1.

[0240]

[0237] At block 1110, the apparatus 110 obtains, from a device, a user plane function, UPF, key.

[0241]

[0238] At block 1120, the apparatus 110 determines at least one network specific key of at least one network with which the apparatus is successfully authenticated.

[0242]

[0239] At block 1130, the apparatus 110 transmits, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

[0243]

[0240] In some example embodiments, the method 1100 further comprises: obtaining the UPF key from the device after a PDU session is triggered.

[0244]

[0241] In some example embodiments, the UPF key is derived via an AMF key.

[0245]

[0242] In some example embodiments, the at least one network specific key is generated associated with a root credential between the corresponding network and the apparatus.

[0246]

[0243] In some example embodiments, the data encrypted by using the UPF key and the network specific key is transmitted to the component via a UP packet.

[0247]

[0244] In some example embodiments, the network specific key is obtained through executing a SMC at the component.

[0248]

[0245] In some example embodiments, the at least one network comprises at least one of the following: a non-terrestrial network, an aerial network, or a satellite network.

[0249]

[0246] In some example embodiments, the network specific key comprises a HAPS key corresponding to the aerial network, and the HAPS key is generated via a MSK.

[0250]

[0247] In some example embodiments, the network specific key comprises a SAT key corresponding to the satellite network, and the SAT key is generated based on a multiparty computation key.

[0251]

[0248] In some example embodiments, the apparatus comprises a terminal device.

[0252]

[0249] FIG. 12 shows a flowchart of an example method 1200 implemented at a networkentity in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1200 will be described from the perspective of the network entity 130 in FIG. 1.

[0253]

[0250] At block 1210, the network entity 130 obtains, from a further network entity, a user plane function, UPF, key.

[0254]

[0251] At block 1220, the network entity 130 receives, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key corresponding to the network.

[0255]

[0252] At block 1230, the network entity 130 determines second decrypted data using the UPF key.

[0256]

[0253] In some example embodiments, the method 1200 further comprises: obtaining the UPF key after a PDU session is triggered.

[0257]

[0254] In some example embodiments, the UPF key is obtained via a SMF.

[0258]

[0255] In some example embodiments, the UPF key is derived via an AMF key.

[0259]

[0256] In some example embodiments, the network specific key is generated associated with a root credential between the network and the apparatus.

[0260]

[0257] In some example embodiments, the network comprises one of the following: a nonterrestrial network, an aerial network, a satellite network.

[0261]

[0258] In some example embodiments, the network specific key comprises a HAPS key corresponding to the aerial network, and the HAPS key is generated via a MSK.

[0262]

[0259] In some example embodiments, the network specific key comprises a SAT key corresponding to the satellite network, and the SAT key is generated based on a multiparty computation key.

[0263]

[0260] In some example embodiments, the apparatus comprises a terminal device.

[0264]

[0261] In some example embodiments, an apparatus capable of performing any of the method 700 (for example, the apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry orsoftware module. The apparatus may be implemented as or included in the apparatus 110 in FIG. 1.

[0265]

[0262] In some example embodiments, the apparatus comprises means for transmitting, to a device, a registration request at least comprising an indication indicative of at least one of a capability and a requirement of the apparatus for accessing at least one network comprising a terrestrial network and at least one non-terrestrial network; means for in accordance with a determination that an authentication procedure is triggered associated with the registration request, performing an authentication procedure between the apparatus and one or more networks that are allowed to be accessed by the apparatus; and means for receiving, from the device, a registration response indicating a result of the authentication procedure.

[0266]

[0263] In some example embodiments, the apparatus further comprises: means for transmitting, to the device via the registration request, at least one identifier of at least one component associated with the at least one network supported by the capability of the apparatus.

[0267]

[0264] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0268]

[0265] In some example embodiments, the apparatus further comprises: means for transmitting, to the device via the registration request, a further indication indicative of at least one component level to which the at least one component belongs.

[0269]

[0266] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0270]

[0267] In some example embodiments, a component level of a HAPS indicates a serving type associated with the HAPS.

[0271]

[0268] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0272]

[0269] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0270] In some example embodiments, the apparatus further comprises: means for performing the authentication procedure with the terrestrial network using a SIM card.

[0273]

[0271] In some example embodiments, different authentication mechanisms are used for the authentication procedure on the at least one non-terrestrial network in the network, and wherein a non-terrestrial network is authenticated based on a certificate-based authentication or a multi-factor authentication.

[0274]

[0272] In some example embodiments, the apparatus comprises a terminal device.

[0275]

[0273] In some example embodiments, a network entity capable of performing any of the method 800 (for example, the network entity 130 in FIG. 1) may comprise means for performing the respective operations of the method 800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network entity may be implemented as or included in the network entity 130 in FIG. 1.

[0276]

[0274] In some example embodiments, the network entity comprises means for receiving, from an apparatus, a registration request at least comprising an indication indicative of at least one of a capability and a requirement of the apparatus for accessing at least one network comprising a terrestrial network and at least one non-terrestrial network; means for transmitting, to a further network entity, an authentication request indicating the indication; means for in accordance with a determination that an authentication response, received from the further network entity, indicating the one or more networks allowed to be accessed by the apparatus, triggering an authentication procedure between the apparatus and the at least one network; and means for transmitting, to the apparatus, a registration response indicating a result of the authentication procedure.

[0277]

[0275] In some example embodiments, the network entity further comprises: means for obtaining, via the registration request, the at least one identifier of at least one component associated with one or more networks supported by the capability of the apparatus; means for generating the authentication request indicating the indication and the at least one identifier; and means for transmitting the authentication request to the further network entity.

[0278]

[0276] In some example embodiments, the network entity further comprises: means for storing the at least one identifier at the network entity.

[0277] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0279]

[0278] In some example embodiments, the network entity further comprises: means for obtaining, via the registration request, a further indication indicative of at least one component level to which the at least one component belongs; means for generating the authentication request indicating the indication, the at least one identifier and the at least one component level; and means for transmitting the authentication request to the further network entity.

[0280]

[0279] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0281]

[0280] In some example embodiments, a component level of a HAPS indicates a serving type associated with the HAPS.

[0282]

[0281] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0283]

[0282] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0284]

[0283] In some example embodiments, the apparatus comprises a terminal device and the device comprises a network entity.

[0285]

[0284] In some example embodiments, an apparatus capable of performing any of the method 900 (for example, the apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the apparatus 110 in FIG. 1.

[0286]

[0285] In some example embodiments, the apparatus comprises means for receiving, from a device, a registration response indicative of a successful authentication between the apparatus and at least one network comprising a terrestrial network and at least one nonterrestrial network; means for in accordance with a determination that the at least onenetwork is to be modified, transmitting to the device, a registration request for updating the at least one network currently serving the apparatus; means for performing an authentication procedure between the apparatus and one or more networks to be updated associated with the registration request; and means for receiving, from the device, a further registration response indicating a result of the authentication procedure.

[0287]

[0286] In some example embodiments, the registration request for updating the at least one network currently serving the apparatus indicates at least one of the following: an indication indicative of an updated capability and requirement of the apparatus for accessing the at least one network comprising the terrestrial network and the at least one non-terrestrial network, the one or more networks to be removed from the at least one network caused by the updated capability and requirement, the one or more networks to be added to the at least one network caused by the updated capability and requirement, at least one identifier of at least one component associated with the one or more networks to be updated, at least one component level to which the at least one component belongs, or a SUCI associated with the apparatus.

[0288]

[0287] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0289]

[0288] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0290]

[0289] In some example embodiments, a component level of a HAPS indicates a serving type associated with the HAPS.

[0291]

[0290] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0292]

[0291] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0293]

[0292] In some example embodiments, the apparatus further comprises: means for performing the authentication procedure with the terrestrial network using a SIM card.

[0294]

[0293] In some example embodiments, different authentication mechanisms are used forthe authentication procedure on the at least one non-terrestrial network in the network, and wherein a non-terrestrial network is authenticated based on a certificate-based authentication or a multi-factor authentication.

[0295]

[0294] In some example embodiments, the apparatus comprises a terminal device.

[0296]

[0295] In some example embodiments, a network entity capable of performing any of the method 1000 (for example, the network entity 130 in FIG. 1) may comprise means for performing the respective operations of the method 1000. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network entity may be implemented as or included in the network entity 130 in FIG. 1.

[0297]

[0296] In some example embodiments, the network entity comprises means for receiving, from the apparatus, a registration request for updating the at least one network currently serving the apparatus, wherein the at least one network comprises a terrestrial network and at least one non -terrestrial network; means for transmitting, to a further network entity, an authentication request indicating one or more networks to be updated that are required by the apparatus in the registration request; means for in accordance with a determination that an authentication response, received from the further network entity, indicating the one or more networks are allowed to be accessed by the apparatus, triggering an authentication procedure between the apparatus and the one or more networks; and means for transmitting, to the apparatus, a registration response indicating a result of the authentication procedure.

[0298]

[0297] In some example embodiments, the registration request for updating the at least one network currently serving the apparatus indicates at least one of the following: an indication indicative of an updated capability and requirement of the apparatus for accessing the at least one network comprising the terrestrial network and the at least one non-terrestrial network, the one or more networks to be removed from the at least one network caused by the updated capability and requirement, the one or more networks to be added to the at least one network caused by the updated capability and requirement, at least one identifier of at least one component associated with the one or more networks to be updated, at least one component level to which the at least one component belongs, or a SUCI associated with the apparatus.

[0299]

[0298] In some example embodiments, the authentication request further indicates at leastone of the following: at least one identifier of at least one component associated with the one or more networks to be updated, at least one component level to which the at least one component belongs, or a SUCI associated with the apparatus.

[0300]

[0299] In some example embodiments, the at least one identifier of the at least one component comprises at least one of the following: a terrestrial cell identifier associated with the terrestrial network, a satellite identifier associated with the at least one nonterrestrial network, or a HAPS identifier associated with the at least one non-terrestrial network.

[0301]

[0300] In some example embodiments, a component level of a satellite indicates an earth orbit to which the satellite belongs.

[0302]

[0301] In some example embodiments, a component level of a HAPS indicates a serving type associated with the HAPS.

[0303]

[0302] In some example embodiments, a component level of a terrestrial cell indicates a characteristic of the terrestrial cell.

[0304]

[0303] In some example embodiments, the network entity further comprises: means for storing the at least one identifier at the network entity.

[0305]

[0304] In some example embodiments, the at least one non-terrestrial network comprises at least one of the following: an aerial network, or a satellite network.

[0306]

[0305] In some example embodiments, the apparatus comprises a terminal device and the device comprises a network entity.

[0307]

[0306] In some example embodiments, an apparatus capable of performing any of the method 1100 (for example, the apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 1100. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the apparatus 110 in FIG. 1.

[0308]

[0307] In some example embodiments, the apparatus comprises means for obtaining, from a device, a UPF key; means for determining at least one network specific key of at least one network with which the apparatus is successfully authenticated; and means for transmitting, to a component in the at least one network, data encrypted by the UPF keyand a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

[0309]

[0308] In some example embodiments, the apparatus further comprises: means for obtaining the UPF key from the device after a PDU session is triggered.

[0310]

[0309] In some example embodiments, the UPF key is derived via an AMF key.

[0311]

[0310] In some example embodiments, the at least one network specific key is generated associated with a root credential between the corresponding network and the apparatus.

[0312]

[0311] In some example embodiments, the data encrypted by using the UPF key and the network specific key is transmitted to the component via a UP packet.

[0313]

[0312] In some example embodiments, the network specific key is obtained through executing a SMC at the component.

[0314]

[0313] In some example embodiments, the at least one network comprises at least one of the following: a non-terrestrial network, an aerial network, or a satellite network.

[0315]

[0314] In some example embodiments, the network specific key comprises a HAPS key corresponding to the aerial network, and the HAPS key is generated via a MSK.

[0316]

[0315] In some example embodiments, the network specific key comprises a SAT key corresponding to the satellite network, and the SAT key is generated based on a multiparty computation key.

[0317]

[0316] In some example embodiments, the apparatus comprises a terminal device.

[0318]

[0317] In some example embodiments, a network entity capable of performing any of the method 1200 (for example, the network entity 130 in FIG. 1) may comprise means for performing the respective operations of the method 1200. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network entity may be implemented as or included in the network entity 130 in FIG. 1.

[0319]

[0318] In some example embodiments, the network entity comprises means for obtaining, from a further network entity, a UPF key; means for receiving, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key corresponding to the network; and means for determiningsecond decrypted data using the UPF key.

[0320]

[0319] In some example embodiments, the network entity further comprises: means for obtaining the UPF key after a PDU session is triggered.

[0321]

[0320] In some example embodiments, the UPF key is obtained via a SMF.

[0322]

[0321] In some example embodiments, the UPF key is derived via an AMF key.

[0323]

[0322] In some example embodiments, the network specific key is generated associated with a root credential between the network and the apparatus.

[0324]

[0323] In some example embodiments, the network comprises one of the following: a nonterrestrial network, an aerial network, a satellite network.

[0325]

[0324] In some example embodiments, the network specific key comprises a HAPS key corresponding to the aerial network, and the HAPS key is generated via a MSK.

[0326]

[0325] In some example embodiments, the network specific key comprises a SAT key corresponding to the satellite network, and the SAT key is generated based on a multiparty computation key.

[0327]

[0326] In some example embodiments, the apparatus comprises a terminal device.

[0328]

[0327] FIG. 13 is a simplified block diagram of a device 1300 that is suitable for implementing example embodiments of the present disclosure. The device 1300 may be provided to implement a communication device, for example, the apparatus 110 or the device 120 or the network entity 130 as shown in FIG. 1. As shown, the device 1300 includes one or more processors 1310, one or more memories 1320 coupled to the processor 1310, and one or more communication modules 1340 coupled to the processor 1310.

[0329]

[0328] The communication module 1340 is for bidirectional communications. The communication module 1340 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 1340 may include at least one antenna.

[0330]

[0329] The processor 1310 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purposecomputers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1300 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.

[0331]

[0330] The memory 1320 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1324, an electrically programmable read only memory (EPROM), a flash memory, a hard disk, a compact disc (CD), a digital video disk (DVD), an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random-access memory (RAM) 1322 and other volatile memories that will not last in the power-down duration.

[0332]

[0331] A computer program 1330 includes computer executable instructions that are executed by the associated processor 1310. The instructions of the program 1330 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 1330 may be stored in the memory, e.g., the ROM 1324. The processor 1310 may perform any suitable actions and processing by loading the program 1330 into the RAM 1322.

[0333]

[0332] The example embodiments of the present disclosure may be implemented by means of the program 1330 so that the device 1300 may perform any process of the disclosure as discussed with reference to FIG. 2 to FIG. 12. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.

[0334]

[0333] In some example embodiments, the program 1330 may be tangibly contained in a computer readable medium which may be included in the device 1300 (such as in the memory 1320) or other storage devices that are accessible by the device 1300. The device 1300 may load the program 1330 from the computer readable medium to the RAM 1322 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0335]

[0334] FIG. 14 shows an example of the computer readable medium 1400 which may be inform of CD, DVD or other optical storage disk. The computer readable medium 1400 has the program 1330 stored thereon.

[0336]

[0335] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0337]

[0336] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as anon-transitory computer readable medium. The computer program product includes computerexecutable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.

[0338]

[0337] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.

[0338] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.

[0339]

[0339] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0340]

[0340] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.

[0341]

[0341] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

47WE CLAIM:

1. An apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:obtain, from a device, a user plane function, UPF, key;determine at least one network specific key of at least one network with which the apparatus is successfully authenticated; andtransmit, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

2. The apparatus of claim 1, wherein the apparatus is caused to:obtain the UPF key from the device after a protocol data unit, PDU, session is triggered.

3. The apparatus of claim 1, wherein the UPF key is derived via an access and mobility management function, AMF, key.

4. The apparatus of claim 1, wherein the at least one network specific key is generated associated with a root credential between the corresponding network and the apparatus.

5. The apparatus of claim 1, wherein the data encrypted by using the UPF key and the network specific key is transmitted to the component via a user plane, UP, packet.

6. The apparatus of claim 1, wherein the network specific key is obtained through executing a security mode command, SMC, at the component.

7. The apparatus of claim 1, wherein the at least one network comprises at least one of the following:a non-terrestrial network,48an aerial network, ora satellite network.

8. The apparatus of claim 7, wherein the network specific key comprises a high-altitude platform station, HAPS, key corresponding to the aerial network, and the HAPS key is generated via a master session key, MSK.

9. The apparatus of claim 7, wherein the network specific key comprises a satellite, SAT, key corresponding to the satellite network, and the SAT key is generated based on a multi-party computation key.

10. The apparatus of any of claims 1-9, wherein the apparatus comprises a terminal device.

11. A network entity comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the network entity at least to:obtain, from a further network entity, a user plane function, UPF, key; receive, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key corresponding to the network; anddetermine second decrypted data using the UPF key.

12. The network entity of claim 11, wherein the network entity is caused to: obtain the UPF key after a protocol data unit, PDU, session is triggered.

13. The network entity of claim 11, wherein the UPF key is obtained via a session management function, SMF.

14. The network entity of claim 11, wherein the UPF key is derived via an access and mobility management function, AMF, key.4915. The network entity of claim 11, wherein the network specific key is generated associated with a root credential between the network and the apparatus.

16. The network entity of any of claims 11-15, wherein the at least one network comprises one of the following:a non-terrestrial network,an aerial network,a satellite network.

17. The network entity of claim 16, wherein the network specific key comprises a high-altitude platform station, HAPS, key corresponding to the aerial network, and the HAPS key is generated via a master session key, MSK.

18. The network entity of claim 16, wherein the network specific key comprises a satellite, SAT, key corresponding to the satellite network, and the SAT key is generated based on a multi-party computation key.

19. The network entity of any of claims 11-18, wherein the apparatus comprises a terminal device.

20. A method comprising:obtaining, by an apparatus from a device, a user plane function, UPF, key; determining at least one network specific key of at least one network with which the apparatus is successfully authenticated; andtransmitting, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

21. A method comprising:obtaining, by a network entity from a further network entity, a user plane function, UPF, key;receiving, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key50corresponding to the network; anddetermining second decrypted data using the UPF key.

22. An apparatus comprising:means for obtaining, from a device, a user plane function, UPF, key; means for determining at least one network specific key of at least one network with which the apparatus is successfully authenticated; andmeans for transmitting, to a component in the at least one network, data encrypted by the UPF key and a network specific key, associated with a network to which the component belongs, among the at least one network specific key.

23. A network entity comprising:means for obtaining, from a further network entity, a user plane function, UPF, key;means for receiving, from a component in a network among at least one network with which an apparatus is successfully authenticated, first decrypted data decrypted by the component from encrypted data of the apparatus by using a network specific key corresponding to the network; andmeans for determining second decrypted data using the UPF key.

24. A computer readable medium comprising instructions stored thereon for causing an apparatus at least to perform the method of claim 20 or the method of claim 21.