Local routing
Patent Information
- Application Number
- PCT/EP2026/058188
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-26
- Filing Date
- 2026-03-23
- Publication Date
- 2026-10-01
Smart Images

Figure EP2026058188_01102026_PF_FP_ABST
Abstract
Description
LOCAL ROUTINGFIELD
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for local routing of data packets.BACKGROUND
[0002] A communication network may serve as a facility that enables communication between two or more communication devices or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.
[0003] The communication network may operate in accordance with standards such as those provided by Third Generation Partnership Project (3 GPP) or European Telecommunications Standards Institute (ETSI). Examples of standards provided by 3 GPP are the so-called 3 GPP standards for cellular technology generations, such as 3GPP standards for 4G technology, 5G technology, 6G technology, and so on.SUMMARY
[0004] In a first aspect of the present disclosure, there is provided an apparatus. The apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: transmit, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device; receive, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one target algorithm is at least determined based on the at least one preferred algorithm; and perform the local routing by using the at least one target algorithm.
[0005] i
[0006] In a second aspect of the present disclosure, there is provided a network device. The network device comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the network device at least to: receive capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device; receive further capability information indicating at least one preferred algorithm of the further apparatus associated with generating at least one key to be used in the local routing; determine at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus; and transmit, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
[0007] In a third aspect of the present disclosure, there is provided a method. The method comprises: transmitting, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device; receiving, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one target algorithm is at least determined based on the at least one preferred algorithm; and performing the local routing by using the at least one target algorithm.
[0008] In a fourth aspect of the present disclosure, there is provided a method. The method comprises: receiving capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device; receiving further capability information indicating at least one preferred algorithm of the further apparatus associated with generating at least one key to be used in the local routing; determining at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus; and transmitting, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
[0009] In a fifth aspect of the present disclosure, there is provided an apparatus. The apparatus comprises means for transmitting, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device; means for receiving, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one target algorithm is at least determined based on the at least one preferred algorithm; and means for performing the local routing by using the at least one target algorithm.
[0010] In a sixth aspect of the present disclosure, there is provided a network device. The network device comprises means for receiving capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device; means for receiving further capability information indicating at least one preferred algorithm of the further apparatus associated with generating at least one key to be used in the local routing; means for determining at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus; and means for transmitting, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
[0011] In a seventh aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the third aspect.
[0012] In an eighth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fourth aspect.
[0013] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to beused to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0015] FIG. 1 A illustrates an example communication scenario with a single satellite;
[0016] FIG. IB illustrates another example communication scenario with multiple satellites;
[0017] FIG. 2A illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0018] FIG. 2B illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0019] FIG. 3 illustrates a signaling flow for local routing in accordance with some example embodiments of the present disclosure;
[0020] FIG. 4 illustrates a signaling flow for local routing via a single satellite in accordance with some example embodiments of the present disclosure;
[0021] FIG. 5 illustrates a schematic diagram for common key generation in accordance with some example embodiments of the present disclosure;
[0022] FIG. 6 illustrates a signaling flow for local routing via multiple satellites in accordance with some example embodiments of the present disclosure;
[0023] FIG. 7 illustrates a schematic diagram for common key generation in accordance with some example embodiments of the present disclosure;
[0024] FIG. 8 illustrates a signaling flow for algorithm negotiation in accordance with some example embodiments of the present disclosure;
[0025] FIG. 9 illustrates a further signaling flow for algorithm negotiation via a single satellite in accordance with some example embodiments of the present disclosure;
[0026] FIG. 10 illustrates a signaling flow for local routing in accordance with someexample embodiments of the present disclosure;
[0027] FIG. 11 illustrates a further signaling flow for local routing in accordance with some example embodiments of the present disclosure;
[0028] FIG. 12A illustrates a signaling flow for local routing without end-to-end (E2E) encryption in accordance with some example embodiments of the present disclosure;
[0029] FIG. 12B illustrates a signaling flow for local routing without E2E encryption in accordance with some example embodiments of the present disclosure;
[0030] FIG. 13 illustrates a further signaling flow for local routing without E2E encryption in accordance with some example embodiments of the present disclosure;
[0031] FIG. 14 illustrates a schematic diagram of UE context for local routing without E2E encryption in accordance with some example embodiments of the present disclosure;
[0032] FIG. 15 illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;
[0033] FIG. 16 illustrates a flowchart of a method implemented at a network device in accordance with some example embodiments of the present disclosure;
[0034] FIG. 17 illustrates a flowchart of a method implemented at a network device in accordance with some example embodiments of the present disclosure;
[0035] FIG. 18 illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;
[0036] FIG. 19 illustrates a flowchart of a method implemented at a network device in accordance with some example embodiments of the present disclosure;
[0037] FIG. 20 illustrates a flowchart of a method implemented at an apparatus in accordance with some example embodiments of the present disclosure;
[0038] FIG. 21 illustrates a flowchart of a method implemented at a network device in accordance with some example embodiments of the present disclosure;
[0039] FIG. 22 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0040] FIG. 23 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.
[0041] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0042] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0043] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0044] References in the present disclosure to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0045] It shall be understood that although the terms “first,” “second,”..., etc. in front of noun(s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun(s). For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more ofthe listed terms.
[0046] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0047] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0048] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0049] As used in this application, the term “circuitry” may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and(b) combinations of hardware circuits and software, such as (as applicable):(i) a combination of analog and / or digital hardware circuit(s) with software / firmware and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) ora portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0050] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0051] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band Internet of Things (NB-loT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0052] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), aremote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non -terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0053] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user equipment” and “UE” may be used interchangeably.
[0054] As used herein, the term “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” may referto any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0055] A core network function as described herein may be implemented as a core network entity that includes a combination of hardware processing circuit and software and / or firmware comprising machine-readable instructions, or software comprising machine-readable instructions that are executable by at least one processor of hardware processing circuit of an apparatus. A hardware processing circuit includes at least one processor and at least one memory storing machine-readable instructions that are executable by the at least one processor of the hardware processing circuit. A processor includes any or some combination of an accelerator, a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digital signal processor, a central processing unit, a graphic processing unit, a tensor processing unit. Memory includes any or some combination of volatile or non-volatile memory (e.g., a flash memory, cache, a random-access memory (RAM), and / or a read-only memory (ROM)). The memory stores the machine-readable instructions of the software and / or firmware for execution by the at least one processor of the hardware processing circuit. The machine-readable instructions are executable by the at least one processor of the hardware processing circuit cause the hardware processing circuit to perform the actions or operations of the methods described herein. For example, the session management function described herein may be implemented as a session management entity and the session management policy control function described herein may be implemented as a session management policy control entity, respectively.
[0056] Information exchange in the maritime industry is very important. Information exchange allows for better coordination between ships, which is required regardless ofthe purpose for which ships are sailing. An effective information exchange system can better coordinate the ships and improve the safety of ships, such as resisting pirate attacks, avoiding accidents at sea, and rescuing.
[0057] At sea far from land, there is no terrestrial communication system. Ships can communicate directly with each other at short distance through various types of wireless technologies. At long distances, information can only be exchanged through satellites and then through remote data centers, which affects communication efficiency, especially in emergency situations. In addition, in some areas, the satellite has no available feeder link, which causes the communication interruption even though the communicating ships camp on the same satellite. In this scenario, communication between ships through satellites without going via remote data centers can improve communication efficiency and reduce losses caused by potential maritime accidents.
[0058] Satellite broadband can be suited to connecting remote areas which do not have reliable mobile or fixed broadband. There are new broadband satellites systems being developed, which use many satellites in a non-geostationary satellite orbit (NGSO) closer to the Earth than earlier satellites. Typically, the beam footprint size of Low-Earth Orbit (LEO) satellites and Medium-Earth Orbit (MEO) satellites is in the range of 100 - 1000 km.
[0059] There may be many ships operating all over the world. Satellites may be deployed to provide satellite communication services, which allows communication between ships via satellite(s) without going through the ground network, that is, devices on a ship may communicate directly with devices on another ship via satellite(s).
[0060] FIG. 1A illustrates an example communication scenario 100A with a single satellite. In the example shown in FIG. 1 A, a device A on ship #1 may register with the 5G network via a satellite #1, and device B on ship #2 (small) may also register with the 5G network via the satellite #1. The devices A and B may communicate with each other via the 5G network.
[0061] When the ship #1 and the ship #2 are under the same satellite coverage, the devices A and B may want to communicate with each other. A remote core network may authorize (direct) communications between the devices A and B based on e.g.,subscription, and location information. After getting authorized, the data traffic between the devices A and B is routed through only the satellite #1 and / or without passing / going through core network on land (i.e., ground network). During the data traffic communications between devices A and B without going through the ground network, if the feeder link between the satellite #1 and the ground network becomes unavailable, the device A still can communicate with the device B via the satellite#!.
[0062] FIG. IB illustrates another example communication scenario 100B with multiple satellites. In the example shown in FIG. IB, along a long journey, the ship #1 and the ship #2 move across coverage of different satellites, i.e. the ship #2 may move to the coverage of satellite #2 while ship #1 may remain in the coverage of satellite #1. Inter satellite link may be available between the satellite #1 and satellite #2. During the journey, the communication between the devices A and B via satellite(s) may continue without interruption. The charging information of the traffic data exchanged via the satellites may be collected in the satellites and reported to the remote core network.
[0063] In some cases, the ship #1 and the ship #2 may exchange information efficiently if the data traffic is not transferred via the remote core network (e.g., if the data traffic is transferred via only satellite(s)).
[0064] In some cases, a feeder link is available at least for the session establishment phase and the data traffic is transferred between the devices A and B without going through ground network. However, how the data traffic is locally routed or what could be the optimization done for the local routing of the data traffic remains unknown.
[0065] From service and system aspects, studies on which keys to be used between two UEs going via a local satellite (SAT)-gNB, and how to ensure that the communication is secured are needed. For UE-SAT-UE communications with the legacy signalling procedures, user plane (UP) data may need to go from UE1-SAT-Ground network-SAT-UE2. Embodiments of the present disclosure propose a method for the UP data path which includes enabling E2E encryption between UEs data path.
[0066] In some example embodiments of the present disclosure, it may be assumed that the feeder link is available at least for the initial session establishment and the user-plane communications between the UEs is ongoing, and the expectation may be that UEs are able to exchange data traffic without communicating to the remote corenetwork.
[0067] Example embodiments of the present disclosure propose a method of generation of one or more new keys, which is also referred to as common key(s), which may be shared by the common satellite to both UEs. These new keys may be used for encryption and integrity protection of all user-plane data packets getting exchanged between the UEs communicating (only) via the same satellite.
[0068] This new key may be shared in a radio resource control (RRC) reconfiguration message and secured using keys which were derived using AS security context procedures during call setup. This proposal ensures that even when UEs and / or satellites move, there is a secure communication between the UEs.
[0069] For the local routing of the packets between two UEs, the SAT-gNB MAY use both UEs’ keys to generate the common key and share it to two UEs in a RRC reconfiguration message in a secured way. For the provisioning of the common key(s), the (old) RRC keys of respective UEs may be used to deliver the common key(s). After a target algorithm (preferred by both UEs) is selected by the SAT-gNB, the target algorithm may be delivered / configured to the UEs. Thus, the packets may be just routed by the SAT-gNB and only the UEs can encrypt and decrypt the packets and also integrity protection may be verified by the UEs themselves.
[0070] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0071] FIG. 2A illustrates an example communication environment 200A in which example embodiments of the present disclosure can be implemented. The communication environment 200A involves two apparatuses 110-1 and 110-2, as well as a network device 120. Both apparatuses 110-1 and 110-2 may communicate with the network device 120 bidirectionally. The apparatuses 110-1 and 110-2 may be collectively referred to as the apparatus 110. In the example of FIG. 2A, either the apparatus 110-1 or the apparatus 110-2 may be or include a terminal device (e.g., a UE). The apparatus 110-1 may communicate with the apparatus 110-2 via the network device 120. In some example embodiments, the apparatus 110 may be implemented as a UE that may support 4G, 5G or 6G communications. The network device 120 may be a non-terrestrial network device, which may be a base station, e.g., a gNB, and whichmay include or may be included in or mounted on a non-terrestrial device (e.g., satellite or unmanned aerial vehicle). In some example embodiments, the network device 120 may be discussed with the example of SAT-gNB.
[0072] It is to be understood that the number of devices and their connections shown in FIG. 2A are only for the purpose of illustration without suggesting any limitation. The communication environment 200A may include any suitable number of apparatuses or network devices configured to implement example embodiments of the present disclosure. It is noted that although sometimes discussed as a network device, the network device 120 may be another device than a network device. Although illustrated as a terminal device, the apparatus 110 may be another device than a terminal device.
[0073] In the following, for the purpose of illustration, some example embodiments are described with the apparatusl 10 operating as a terminal device, e.g., a UE, and the network device 120 operating as a satellite or SAT-gNB. In this case, the example shown in FIG. 2 A corresponds to a UE-SAT-UE communication with a single satellite. That is, both the UEs are connected to the same SAT, so the context of both UEs will be on the same SAT.
[0074] The communication environment 200A may be implemented in the scenario 100 A. Specifically, the network device 120 may be implemented as the satellite #1, the apparatus 110-1 may be implemented as (terminal device on) the ship #1, and the apparatus 110-2 may be implemented as (terminal device on) the ship #2. It is to be understood that the above example implementation of the communication environment 200A is just discussed for example, rather than suggesting any limitations. The communication environment 200A may be implemented in various ways in other example embodiments of the present disclosure.
[0075] In some example embodiments, a transmission direction from the network device 120 to the apparatus 110 is referred to as a downlink (DL), while a transmission direction from the apparatus 110 to the network device 120 is referred to as an uplink (UL). In DL, the network device 120 is a transmitting (TX) device (or a transmitter) and the apparatus 110 is a receiving (RX) device (or a receiver). In UL, the apparatus 110 is a TX device (or a transmitter) and the network device 120 is a RX device (or areceiver).
[0076] Communications in the communication environment 200A may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0077] FIG. 2B illustrates an example communication environment 200B in which example embodiments of the present disclosure can be implemented. The communication environment 200A involves two apparatuses 110-1 and 110-2, as well as two network devices 120-1 and 120-2. Both apparatuses 110-1 and 110-2 may communicate with each other via the network devices 120-1 and 120-2. In the example of FIG. 2B, either the apparatus 110-1 or the apparatus 110-2 may include a terminal device (e.g., a UE), and may be collectively referred to as the apparatus 110. In some example embodiments, the apparatus 110 may be implemented as a UE that may support 4G, 5G or 6G communication.
[0078] Either the network device 120-1 or the network device 120-2 may communicate with each other directly or indirectly, for example, via one or more other nodes (e.g., satellites). The network device 120-1 and the network device 120-2 may be collectively referred to as the network device 120. The network device 120 may be a non-terrestrial network device, which may be a base station, e.g., a gNB, and which may include or may be included in a satellite. In some example embodiments, the network device 120 may be discussed with the example of SAT -gNB.
[0079] It is to be understood that the number of devices and their connections shown in FIG. 2B are only for the purpose of illustration without suggesting any limitation.The communication environment 200B may include any suitable number of apparatuses or network devices configured to implement example embodiments of the present disclosure. It is noted that although sometimes discussed as a network device, the network device 120 may be another device than a network device. Although illustrated as a terminal device, the terminal device 110 may be another device than a terminal device.
[0080] In the following, for the purpose of illustration, some example embodiments are described with the apparatus 110-1 or 110-2 operating as a terminal device, e.g., a UE, and the network device 120-1 or 120-2 operating as a satellite or SAT-gNB. In this case, the example shown in FIG. IB corresponds to a UE-SAT-UE communication with multiple satellites involved. That is, FIG. IB shows a multi-SAT routing architecture, where both the apparatuses 110-1 and 110-2 (e.g., two UEs) are connected to different network devices (e.g., different satellites). This means a routing satellite may need to know exactly where the other UE is connected to.
[0081] The communication environment 200B may be implemented in the scenario 100B. Specifically, the network device 120-1 may be implemented as the satellite #1, the network device 120-2 may be implemented as the satellite #2, the apparatus 110-1 may be implemented as (terminal device on) the ship #1, and the apparatus 110-2 may be implemented as (terminal device on) the ship #2. It is to be understood that the above example implementation of the communication environment 200B is just discussed for example, rather than suggesting any limitations. The communication environment 200B may be implemented in various ways in other example embodiments of the present disclosure.
[0082] Communications in the communication environment 200B may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access(TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0083] FIG. 3 illustrates a signaling flow 300 for local routing in accordance with some example embodiments of the present disclosure. For the purposes of discussion, the signaling flow 300 will be discussed with reference to FIGS. 2A and 2B, for example, by using the apparatus 110 and the network device 120.
[0084] In some example embodiments, the apparatus 110 may be discussed with a terminal device, e.g., a UE. The network device may be discussed with a non-terrestrial network device such as a satellite that operates as a base station, e.g., a gNB, which may be referred to as a SAT-gNB.
[0085] The local routing may include routing of data / information between the apparatus and the further apparatus via (only) at least one non-terrestrial network node including the network device 120. The local routing may be caused by a network entity in the core network (CN), for example, a CN network entity implementing a certain network function. Upon receiving, from the network entity, information indicating a possibility of the local routing, the network device 120 may enable the local routing based on the received information. In some example embodiments, the network device 120 may transmit, to the apparatus 110, an indication to enable the local routing. Upon receiving the indication, the apparatus 110 may be aware that the local routing is enabled. Thus, the apparatus 110 may perform related operations or acts of the local routing, for example, key generation, data encryption, integrity protection, data decryption, and / or integrity verification.
[0086] In the signaling flow 300, the network device 120 transmits (310), to the apparatus 110, configuration information about at least one common key for protecting the local routing between the apparatus and a further apparatus via the network device. In an example, the local routing may be the routing between the apparatus 110-1 and a further apparatus 110-2 (only) via the network device 120, as shown in FIG. 2A. In another example, the local routing may be the routing between the apparatus 110-1 and a further apparatus 110-2 via the network device 120-1 and the network device 120-2(e.g., (only) one or more non-terrestrial network devices), as shown in FIG. 2B.
[0087] The common key(s) may be generated at the network device 120 in various ways. In some example embodiments, the at least one common key may be generated based on at least one of: a first key associated with the apparatus 110-1, a second key associated with the further apparatus 110-2, or a random number. For example, the network device 120 may obtain a first key associated with the apparatus 110-1 from a context of the apparatus 110-1 and a second key associated with the further apparatus 110-2 from a context of the further apparatus 110-2. On the basis of the first key and the second key, as well as a random number, the network device 120 may generate the at least one common key.
[0088] After generation, the common key(s) may be protected with a key for control plane protection associated with the apparatus 110. In the case where the apparatus 110 may be a UE, the key for the control plane protection may be a RRC key for this UE. After the common key(s) is protected, the network device 120 may transmit, to the apparatus 110, the configuration information about the at least one protected common key.
[0089] In some example embodiments, the configuration information may be transmitted via a radio resource control (RRC) message. It is to be understood that, the RRC message is just an example for carrying the configuration information, rather than suggesting any limitations. Other suitable messages may be also application in further example embodiments of the present disclosure.
[0090] As for the apparatus 110, it receives (315), from the network device 120, configuration information about the at least one common key. Optionally, in the case where the network device 120 enables the local routing, the network device 120 may cause the apparatus 110 to enter an inactive state. After or in response to receiving (1015) the configuration information, the apparatus 110 may change from the inactive state, e.g., the RRC INACTIVE state, to a connected state, e.g., the RRC CONNECTED state.
[0091] Based on the received configuration information, the apparatus 110 performs (320) the local routing based on the at least one common key. Correspondingly, the network device 120 also performs (325) the local routing based on the same commonkey.
[0092] When performing (320) the local routing, the apparatus 110 may be a transmitter, e.g., the apparatus 110-1, which may transmit data to a further apparatus 110-2 via the network device 120. Before the transmission, the apparatus 110 may process data to be transmitted between the apparatus 110 and the network device 120 first. For example, the apparatus 110 may perform, based on the at least one common key, at least one of encryption or integrity protection on the data. Then, the apparatus 110 may transmit the processed data to the network device 120.
[0093] In some example embodiments, the encryption and / or the integrity protection may be performed by using the same common key. For example, the apparatus 110-1 may perform the encryption with a common key and perform the integrity protection with the same. Alternatively, the apparatus 110-1 may perform the encryption with a common key used for encryption and perform the integrity protection with a different common key used for the integrity protection.
[0094] As for the network device, it may receive, from the apparatus 110-1, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one common key. Then, the network device 120 may transmit the processed data to the further apparatus 110-2, as shown in the example environment 200A. Alternatively, in the example environment 200B, the network device 120-1 may transmit the processed data to the further network device 120-2 which is associated with the further apparatus 110-2.
[0095] As an alternative, when performing (320) the local routing, the apparatus 110 may be a receiver, e.g., the apparatus 110-1 which may receive data from the further apparatus 110-2 via the network device 120. Specifically, the apparatus 110-1 may receive, from the network device 120, processed data on which encryption and / or integrity protection is performed. Then, the apparatus 110-1 may perform decryption and / or integrity verification on the processed data based on the at least one common key. Likewise, the decryption and the integrity verification may be performed by using the same common key, or by using different common keys.
[0096] Regarding the network device 120, it may receive processed data, on which at least one of encryption or integrity protection on the data is performed, based on the atleast one common key. For example, the processed data may be from the further apparatus 110-2, as shown in the example environment 200 A. Alternatively, the processed data may be received from a further network device 120-2 associated with the further apparatus 110-2, as shown in the example environment 200B.
[0097] The network device 120 does not process the received processed data, e.g., does not decrypt the data, and may transmit the processed data to the apparatus 110-1 directly. That is, the network device 120 may forward the received processed data to the further apparatus 110-2 or the further network device 120-2.
[0098] Accordingly, the local routing which is a transparent forwarding of user plane (UP) data may be enabled, and E2E encryption of the UP data can be performed between apparatuses, e.g., UEs. Thus, the UP data can be efficiently exchanged between UEs connected via satellites without going through the ground network. This can also reduce lot of processing at SAT-gNBs in terms of integrity checks, decryption, etc. for all UP data packets exchanged between UEs connected via satellites. This can also be good for energy efficiency and sustainability.
[0099] More details of example embodiments discussed with respect to FIG. 3 will be further discussed with respect to FIGS. 4 to 7. In particular, FIGS. 4 and 5 are related to the scenario where the local routing is performed via a single satellite, and FIGS. 6 and 7 are related to the scenario where the local routing is performed via multiple satellites.
[0100] FIG. 4 illustrates a signaling flow 400 for local routing via a single satellite in accordance with some example embodiments of the present disclosure. The signaling flow 400 involves a UE1 401 which is an example of the apparatus 110-1, a UE2402 which is an example of the apparatus 110-2, a SAT-gNB 403 which is an example of the network device 120, a gateway (GW) 404, a CN 405 and a home network (HN) 406.
[0101] In the signaling flow 400, at step 411, after authentication of the UE1 401 and the UE2402 is successfully completed, the local routing, e.g., local SAT-gNB routing, is enabled or authorized for both the UE1 401 and the UE2402. The configuration may be also stored in SAT-gNB 403 in the UE context for future reference.
[0102] Subsequently, at 412a and 412b, the UE1 context may be available with UE1and SAT-gNB. Similarly, at 413a and 413b, UE2 context may be available with UE2 and SAT-gNB. Both the UE1 401 and the UE2 402 may use their respective keys (derived as per legacy procedures) for RRC control plane message and UP keys for data packets. As per legacy procedures, all packets would need to be routed via Core Network (via gateway) between the UE1 401 and the UE2402. Both the UE1 401 and the UE2402 may be connected via same SAT-gNB 403 in this scenario shown in FIG.4.
[0103] At 414. i-1 and 414. i-2, for UP Data transfer, protocol data unit (PDU) session establishment may be initiated for both the UE1 and the UE2.
[0104] At 414. ii, the core network (CN) 405 may identifies a possibility of E2E encrypted UE - SAT - UE communication and sees the possibility of local routing. This is possible based on the information about which satellite is covering which UE.
[0105] At 414. iii, if local routing is possible based on knowledge that both UEs are covered by the same satellite gNB, the CN 405, e.g., the access and mobility management function (AMF) may inform the SAT-gNB 403 about this, and subsequently, local routing may be enabled by SAT-gNB 403.
[0106] At 414. iv, the PDU session establishment may be initiated for both the UE1 401 and the UE2402.
[0107] After 414.iv, the UE1 401 and the UE2402 establish PDU sessions . Note that, at this point, the UP data may be routed via the core network on the ground.
[0108] At 415a, based on step 414. iii, the SAT-gNB 403 may decide to enable the local routing.
[0109] At 415b and 415c, the SAT-gNB 403 may (temporarily) move both the UE1 401 and the UE2 402 in the RRC_INACTIVE state. Steps 415b and 415c may be required to perform reconfiguration with new KsAT-gNB-iocai-route key(s), which are also referred to as the common key(s), in subsequent steps.
[0110] At 416, the SAT-gNB 403 may generate the common key KsAT-gNB-iocai-route. The common key may be generated based on a first key associated with the UE1 401, a second key associated with the UE2402, and / or a random number. FIG. 5 illustratesa schematic diagram 500 for the common key generation in accordance with some example embodiments of the present disclosure.[OHl] As shown in FIG. 5, the SAT-gNB 403 may generate a random number, denoted as RANDsAT-gNB, and use this parameter along with the first key, denoted as KgNB#i (UE1 gNB key) and the second key, denoted as KgNB#2 (UE2 gNB key), to generate a new common key for local routing KSAT -gNB-local-route.
[0112] At 417, the SAT-gNB 403 may use RRC keys for the UE1 to protect KSAT-§NB-local-route and prepares to reconfigure UE1.
[0113] At 418, the SAT-gNB 403 may use RRC keys for the UE2 to protect KSAT-§NB-local-route and prepare to reconfigure the UE2.
[0114] At 419a and 419b, the SAT-gNB 403 may perform RRC Reconfiguration with the UE1 401 and the UE2 402, respectively, to configure KsAT-gNB-iocai-route on both the UE1 401 and the UE2 402. After these steps, the UE1 401 and the UE2 402 may be back to the RRC CONNECTED state.
[0115] At 420, after successful RRC Reconfiguration of both UEs, the SAT-gNB 403 may enable its local configuration to start using the new keys KsAT-gNB-iocai-route to perform de-cyphering and integrity checks only for control plane (RRC) messages from UE1 and UE2. After this, the UP data or UP packets between these two UEs may be simply forwarded by SAT-gNB as shown in steps 421a to 42 le.
[0116] It is to be understood that there may be more than one common key. In some example embodiments, separate common keys may be derived for encryption and integrity protection, like KSAT -gNB-local-route-enc and KSAT -gNB-local-route-int-
[0117] At 421a, the UE1 401 may encrypt and integrity protect the data using common key(s), and at 421b, the UP data may be transferred from the UE1 401 towards the SAT-gNB 403. At 421c, the SAT-gNB 403 may determine to locally route / forward the UP data received from the UE1 401 forward, at 42 Id, the data packets to the UE2 402. At 42 le, the UE2 402 may check the integrity of received data and decrypt those using the common key(s). That is, in this case, decryption and integrity verification may be performed at the UE2 402.
[0118] Similar steps may be seen when data is sent from the UE2402 to the UE1 401, where the UE2402 may encrypt and integrity protect the data using common keys, and the UE1 401 may check the integrity of received packets and decrypt those using common keys.
[0119] In some example embodiments, for enabling the local routing (or local forwarding), the SAT-gNB 403 may also selectively enable “transparent mode” only for such UE-Satellite-UE communications. This may be done after providing new keys as described earlier and switching to local forwarding mode.
[0120] FIG. 6 illustrates a signaling flow 600 for local routing via multiple satellites in accordance with some example embodiments of the present disclosure. The signaling flow 600 involves a UE1 601 which is an example of the apparatus 110-1, a UE2602 which is an example of the apparatus 110-2, a SAT-gNBl 603 which is an example of the network device 120-1, a SAT-gNBl 604 which is an example of the network device 120-2, a GW 605, a CN 606 and a HN 607.
[0121] It is to be understood that although the signaling flow 600 shows only two satellite gNBs (SAT-gNB s) 603 and 604, they are shown for purpose of discussion, rather than suggesting any limitations. In other example embodiments of the present disclosure, there may be more than two enroute SAT-gNBs.
[0122] In the signaling flow 600, at step 611, after authentication of the UE1 601 and the UE2 602 is successfully completed, the local routing, e.g., local SAT-gNB routing, is enabled or authorized for both the UE1 601 and the UE2 602. The configuration may be also stored in SAT-gNBl 603 in the UE context for future reference.
[0123] Subsequently, at 612a and 612b, the UE1 context may be available with UE1 and SAT-gNB. Similarly, at 613a and 613b, UE2 context may be available with UE2 and SAT-gNB. Both the UE1 601 and the UE2 602 may use their respective keys (derived as per legacy procedures) for RRC control plane message and UP keys for data packets. As per legacy procedures, all packets would need to be routed via Core Network (via gateway) between the UE1 601 and the UE2 602. The UE1 601 may be connected via the SAT-gNBl 603 and the UE2 602 may be connected via the SAT-gNB2604.
[0124] At 614. i-1 and 614 i-2, for UP Data transfer, protocol data unit (PDU) session establishment may be initiated for both the UE1 601 and the UE2602.
[0125] At 614. ii, the CN 606 may determine the possibility of using local forwarding via multiple satellites using secure inter satellite link (ISL) links.
[0126] At 614. iii, the CN 606 may inform all enroute satellites about possible transparent forwarding of UP data between the UE1 601 and the UE2602. Also, at this step, the CN 606 may send a random number, RANDsAT-gNB, for subsequent common key generation. This key generation will be discussed with respect to FIG. 7 where this RANDsAT-gNB gets used.
[0127] FIG. 7 illustrates a schematic diagram 700 for common key generation for the example embodiments discussed in FIG. 6 in accordance with some example embodiments of the present disclosure. As shown FIG. 7, the CN 606 may generate a random number RANDsAT-gNB and share it to the SAT-gNBs 603 and 604. Alternatively, a CN selected master node may generate the RANDsAT-gNB and share it with the SAT-gNBs 603 and 604. The context of the UE1 601, denoted as UE1 context, may include various keys, including the KgNB#i (UE1 gNB key). The context of the UE2 602, denoted as UE2 context, may include various keys, including the KgNB#2 (UE2 gNB key). The SAT-gNBs may use this parameter along with KgNB#i (UE1 gNB key) and KgNB#2 (UE2 gNB key) to generate a new common key for local routing KsAT-gNB-iocai-route. In this multi SAT case, the SAT-gNBs may share the gNB keys of each other UE context to generate KsAT-gNB-iocai-route.
[0128] After 614.v, both the UE1 601 and the UE2602 may be in RRC CONNECTED state, and at this point, UEs can transfer UP data via the ground network (NOT in localrouting mode).
[0129] At 615a, when enroute SAT-gNBs 603 and 604 enable local routing based on core network’s information received in step 614. iii, subsequent steps 615b and 615c may be used to temporarily move the UE1 601 and the UE2 602 in RRC IN ACTIVE state. This may need to reconfigure the UEs for local-routing mode to use keys for end-to-end encryption.
[0130] At 616a and 616b, enroute SAT-gNBs 603 and 604 may share their respectiveKgNBs with each other for local-routing mode for UP data between UE1 and UE2.
[0131] At 617, the SAT-gNBl 603 may protect the newly generated KsAT-iocai-route key(s) using RRC keys for the UE1 601 (the UE1 601 is connected to SAT-gNBl 603).
[0132] At 618, the SAT-gNB2 604 may protect the newly generated KsAT-iocai-route key(s) using RRC keys for the UE2602 (the UE2602 is connected to SAT-gNB2604).
[0133] At 619a and 619b, the SAT-gNBl 603 may configure KsAT-iocai-route key(s) to the UE1 601 using an RRC Reconfiguration procedure, and the SAT-gNB2 604 may configure KsAT-iocai-route key(s) to the UE2 602 using an RRC_Reconfiguration procedure.
[0134] After successfully completing RRC Reconfiguration procedure at 619a and 619b, both UEs 601 and 602 may be back to the RRC CONNECTED state.
[0135] Also, at 620, all enroute SAT-gNBs 603 and 604 may set their configurations to allow transparent forwarding of UP data between UE1 and UE2. This step may ensure that every SAT-gNB maps a corresponding next-hop Satellite ID with this particular UE1-UE2 UP data connection channel.
[0136] Steps 621a - 621e show one path of UP data from the UE1 601 to the UE2602. Similar reverse path of UP data from the UE2602 to the UE1 601 may be envisioned. Specifically, at 621a, the UE1 601 may encrypt and integrity protect the data using common key(s), and at 621b, the UP data may be transferred from the UE1 601 towards the SAT-gNB 2 604 via the SAT-gNBl 603. At 621c, the SAT-gNB 2 604 may determine to locally route / forward the UP data received from the UE1 601 to the UE2 602 and forward, at 621d, the data (e.g., data packets) to the UE2 602. At 621e, the UE2 602 may check the integrity of received data and decrypt those using the common key(s).
[0137] Similar steps may be seen when data is sent from the UE2602 to the UE1 601, where the UE2602 may encrypt and integrity protect the data using common keys, and the UE1 601 may check the integrity of received packets and decrypt those using common keys.
[0138] FIG. 8 illustrates a signaling flow 800 for algorithm negotiation in accordancewith some example embodiments of the present disclosure. For the purposes of discussion, the signaling flow 800 will be discussed with reference to FIG. 2A, for example, by using the apparatus 110 (e.g., the apparatus 110-1) and the network device 120.
[0139] In some example embodiments, the apparatus 110 may be discussed with a terminal device, e.g., a UE. The network device may be discussed with a non-terrestrial network device such as a satellite that operates as a base station, e.g., a gNB, which may be referred to as a SAT-gNB.
[0140] The local routing may include routing of data / information between the apparatus and the further apparatus via (only) at least one non-terrestrial network node including the network device 120. The local routing may be caused by a network entity in the CN, for example, a CN network entity implementing a certain network function. Upon receiving, from the network entity, information indicating a possibility of the local routing, the network device 120 may enable the local routing based on the received information. In some example embodiments, the network device 120 may transmit, to the apparatus 110, an indication to enable the local routing. The apparatus 110 may receive the indication from the network device 120. Upon receiving the indication, the apparatus 110 may be aware that the local routing is enabled. Thus, the apparatus 110 may perform related operations or acts of the local routing, for example, key generation, data encryption, integrity protection, data decryption, and / or integrity verification.
[0141] In the signaling flow 300, the apparatus 110, e.g., the apparatus 110-1 transmits (810) capability information to a non-terrestrial network device. The capability information indicates one or more preferred algorithms associated with generating at least one key to be used in local routing between the apparatus 110-1 and a further apparatus 110-2 via the network device 120.
[0142] A preferred algorithm may include a variety of algorithms for generating keys for message(s) in the control plane or data in the user plane. The at least one preferred algorithm may include, for example, but not limited to, an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption ina data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane, and / or the like.
[0143] The network device 120 receives (815) the capability information from the apparatus 110-1. In the meanwhile, the network device 120 receives further capability information from the further apparatus 110-2, which indicates at least one preferred algorithm of the further apparatus 110-2 associated with generating at least one key to be used in the local routing.
[0144] Based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus, the network device 120 determines (820) at least one target algorithm for generating the at least one key. Then, the network device 120 transmits (825), to the apparatus 110-1 and the further apparatus 110-2, configuration information indicating the at least one target algorithm.
[0145] In some example embodiments, the configuration information may be transmitted via a radio resource control (RRC) message. It is to be understood that, the RRC message is just an example for carrying the configuration information, rather than suggesting any limitations. Other suitable messages may be also application in further example embodiments of the present disclosure.
[0146] Upon receiving (830) the configuration information, the apparatus 110 performs (835) the local routing by using the at least one target algorithm. Optionally, in the case where the network device 120 enables the local routing, the network device 120 may cause the apparatus 110 to enter an inactive state. After or in response to receiving (830) the configuration information, the apparatus 110 may change from the inactive state, e.g., the RRC INACTIVE state, to a connected state, e.g., the RRC CONNECTED state. The at least one target algorithm may include, but not limited to, an algorithm determined by the network device 120 for the apparatus 110-1 and the further apparatus 110-2 to generate a key for performing encryption in a control plane, an algorithm determined by the network device 120 for the apparatus 110-1 and the further apparatus 110-2 to generate a key for performing encryption in a data plane, an algorithm determined the network device 120 for the apparatus 110-1 and the furtherapparatus 110-2 to generate a key for performing integrity protection in a control plane, or an algorithm determined the network device 120 for the apparatus 110-1 and the further apparatus 110-2 to generate a key for performing integrity protection in a data plane.
[0147] Based on the at least one target algorithm, the apparatus 110, either the apparatus 110-1 or the apparatus 110-2, may generate one or more keys for performing at least one of encryption or integrity protection in the local routing.
[0148] Alternatively, based on at least one target algorithm, the apparatus 110, either the apparatus 110-1 or the apparatus 110-2, may generate at least one key for performing at least one of decryption or integrity verification.
[0149] With the above solutions, for the local routing of the packets between two UEs, the SAT-gNB may use the both UEs’ KgNB keys to generate a KSAT -gNB-local-route and share it to two UEs in a RRC reconfiguration message in a secured way. For the provisioning of this new keys, the old RRC keys of respective UEs will be used to deliver the key. After the new algorithm (preferred by both UE) is selected by the SAT-gNB, the selected algorithm (that is, the target algorithm) will be delivered to the UEs. So the packets will be just routed by the SAT-gNB and only the UEs can encrypt and decrypt the packets and also integrity protection can be verified by the UEs themselves. More details in this regard will be discussed with respect to FIG. 9 below.
[0150] FIG. 9 illustrates a further signaling flow 900 for algorithm negotiation via a single satellite in accordance with some example embodiments of the present disclosure. The signaling flow 900 involves a UE1 901 which is an example of the apparatus 110-1, a UE2902 which is an example of the apparatus 110-2, a SAT-gNB 903 which is an example of the network device 120, a GW 904, a CN 905 and a HN 906.
[0151] In the signaling flow 900, at step 911, after authentication of the UE1 901 and the UE2902 is successfully completed, the local routing, e.g., local SAT-gNB routing, is enabled or authorized for both the UE1 901 and the UE2902. The configuration may be also stored in SAT-gNB 903 in the UE context for future reference.
[0152] Subsequently, at 912a and 912c, the UE1 context may be available with UE1 and SAT-gNB. Similarly, at 912b and 912d, the UE2 context may be available withUE2 and SAT-gNB.
[0153] At 913, the SAT-gNB may be with Feeder link. So the UE1 901 and the UE2 902 use respective keys and data packets / control plan signal is protected with respective UE keys. Data or packets may be routed via the CN 905.
[0154] Optionally, at 914, the feeder link may be lost. That is there may be no connection between the SAT-gNB 903 and the GW 904 and / or the CN 905.
[0155] At 915a, the SAT-gNB 903 may decide to enable the local routing.
[0156] At 915b, the SAT-gNB 903 may decide to move both the UE1 901 and the UE2 902 to RRC INACTIVE mode till new configuration is updated.
[0157] At 916, optionally, the UE1 901 may send its UE capabilities with preferred algorithm(s).
[0158] At 917, optionally, the UE2 902 may send its UE capabilities with preferred algorithm(s).
[0159] At 918, the SAT-gNB 903 may decide target algorithm(s) to be used during the local routing based on the common preferred algorithm and indicate both UEs (the UE1 901 and the UE2 902) the decided target algorithm(s) to be used during the local routing.
[0160] At 919, both the UE1 901 and the UE2 902 may be moved to the RRC CONNECTED state.
[0161] At 920, both the UE1 901 and the UE2 902 may use the target algorithm(s) for local routing.
[0162] When deriving ciphering and / or integrity keys from the common key, denoted as KsAT-gNB-iocai-route, in the SAT-gNB 903 and UE (e.g., the UE1 901 and the UE2 902), the following parameters may be used to form a string S.- FC = 0x69- P0 = algorithm type distinguisher- L0 = length of algorithm type distinguisher (i.e. 0x000x01)- Pl = algorithm identity- LI = length of algorithm identity (i.e. 0x000x01)
[0163] The algorithm type distinguisher (also referred to as “algorithm distinguisher”) may be used to indicate the above discussed preferred algorithm, which may be N-RRC-enc-alg for RRC encryption algorithms, N-RRC-int-alg for RRC integrity protection algorithms, N-UP-enc-alg for UP encryption algorithms and N-UP-int-alg for UP integrity protection algorithms, as shown in Table 1. Each of the algorithm distinguisher corresponds to a value, such as 0x03, 0x04, 0x05, and 0x06. The values 0x00 and 0x07 to OxfO may be reserved for future use, and the values Oxfl to Oxff may be reserved for private use.Table 1Algorithm distinguisher ValueN-RRC-enc-alg 0x03N-RRC-int-alg 0x04N-UP-enc-alg 0x05N-UP-int-alg 0x06
[0164] The previously negotiated algorithms are used for UE#1 to SAT-gNB ciphering and integrity protection purposes. But the selected and so far, used algorithms could be completely different (the algorithm used between UE#1 901 & the SAT-gNB 903 and the algorithm used between the UE#2 902 & the SAT-gNB 903). As part of the suspend procedure, the SAT-gNB 903 may indicate both the UE1 901 and the UE2 902 about local routing using a flag.
[0165] This flag may be an additional (new) information element (IE) in existing message during one of the following: a RRC resume procedure if UE was in RRC INACTIVE mode, a successful AS security mode procedure if UE was in IDLE mode, or a RRC reconfiguration procedure if UE was in CONNECTED mode. It is to be understood that these examples are just discussed for illustration, rather than suggest any limitation. Various Implementations may be applicable in other example embodiments of the present disclosure.
[0166] Now for the local routing, the UE#1 901 and the UE#2 902 may have to renegotiate the algorithms (e.g., via a RRC resume procedure) via the SAT-gNB 903, so packets may be encrypted, and integrity protected using this new algorithm, which is also referred to as the target algorithm.
[0167] The algorithms for encryption and / or integrity protection may include, for example, but not limited to, Zu Chongzhi (ZUC) algorithm, advanced encryption standard (AES), secure and novel optical waveform (SNOW) for 128 bits and 256 bits separately.
[0168] FIG. 10 illustrates a signaling flow 1000 for local routing in accordance with some example embodiments of the present disclosure. For the purposes of discussion, the signaling flow 1000 will be discussed with reference to FIGS. 2A and 2B, for example, by using the apparatus 110 and the network device 120.
[0169] In example embodiments of FIG. 10, the apparatus 110 may be discussed with a terminal device, e.g., a UE. The network device may be discussed with a nonterrestrial network device such as a satellite that operates as a base station, e.g., a gNB, which may be referred to as a SAT-gNB.
[0170] The local routing may include routing of data / information between the apparatus and the further apparatus via (only) at least one non-terrestrial network node including the network device 120. The local routing may be caused by a network entity in the core network (CN), for example, a CN network entity implementing a certain network function. Upon receiving, from the network entity, information indicating a possibility of the local routing, the network device 120 may enable the local routing based on the received information. In some example embodiments, the network device 120 may transmit (1002), to the apparatus 110, an indication to enable the local routing. Upon receiving (1004) the indication, the apparatus 110 may be aware that the local routing is enabled. Thus, the apparatus 110 may perform related operations or acts of the local routing, for example, key generation, data encryption, integrity protection, data decryption, and / or integrity verification.
[0171] In some example embodiments, the apparatus 110, e.g., the apparatus 110-1 may transmit capability information to the network device 120. The capability information may indicate one or more preferred algorithms associated with generating at least one key. The preferred algorithm(s) may be algorithm(s) that is preferable for the apparatus 110-1 to use in generation of the at least one key.
[0172] A preferred algorithm may include a variety of algorithms for generating keys for message(s) in the control plane or data in the user plane. The at least one preferredalgorithm may include, for example, but not limited to, an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane, and / or the like.
[0173] In addition to receiving the capability information from the apparatus 110-1, the network device 120 may also receive further capability information from the apparatus 110-2. The further capability information may indicate at least one preferred algorithm of the further apparatus 110-2 associated with generating at least one key.
[0174] Based on the at least one preferred algorithm of the apparatus 110-1 and the at least one preferred algorithm of the further apparatus 110-2, the network device 120 may determine at least one target algorithm for generating the at least one key.
[0175] Additionally, the network device 120 may determine at least one common key for the apparatus 110-1 and the further apparats 110-2. In some example embodiments, the at least one common key may be generated based on at least one of: a first key associated with the apparatus 110-1, a second key associated with the further apparatus 110-2, or a random number. For example, the network device 120 may obtain the first key from a context of the apparatus 110-1 (UE1 context) and the second key from a context of the further apparatus 110-2 (UE2 context). On the basis of the first key and the second key, as well as a random number, the network device 120 may generate the at least one common key.
[0176] After generation, the at least one common key may be protected with a key for control plane protection associated with the apparatus 110. In the case where the apparatus 110 may be a UE, the key for the control plane protection may be a RRC key for this UE.
[0177] In the signaling flow 1000, the network device 120 transmits (1010), to the apparatus 110, configuration information indicating at least one common key and at least one target algorithm. The at least one common key is used for protecting local routing between the apparatus and a further apparatus via the network device. In someexample embodiments, the at least one common key may include, for example, a first common key for a control plane and a second common key for a data plane. The at least one target algorithm is used for generating at least one key to be used in the local routing based on the at least one common key. The at least one key may be, for example, one or more keys for performing at least one of encryption or integrity protection in the control plane, one or more keys for performing at least one of encryption or integrity protection in the data plane, and / or the like.
[0178] In an example, the local routing may be the routing between the apparatus 110-1 and a further apparatus 110-2 via the network device 120, as shown in FIG. 2A. In another example, the local routing may be the routing between the apparatus 110-1 and a further apparatus 110-2 via the network device 120-1 and the network device 120-2, as shown in FIG. 2B.
[0179] The at least one target algorithm may include, but not limited to, an algorithm determined by the network device 120 for the apparatus 110-1 and the further apparatus 110-2 to generate a key for performing encryption in a control plane, an algorithm determined by the network device 120 for the apparatus 110-1 and the further apparatus 110-2 to generate a key for performing encryption in a data plane, an algorithm determined the network device 120 for the apparatus 110-1 and the further apparatus 110-2 to generate a key for performing integrity protection in a control plane, or an algorithm determined the network device 120 for the apparatus 110-1 and the further apparatus 110-2 to generate a key for performing integrity protection in a data plane.
[0180] In some example embodiments, the configuration information may be transmitted via a radio resource control (RRC) message. It is to be understood that, the RRC message is just an example for carrying the configuration information, rather than suggesting any limitations. Other suitable messages may be also application in further example embodiments of the present disclosure.
[0181] As for the apparatus 110, it receives (1015) the configuration information from the network device 120. Optionally, in the case where the network device 120 enables the local routing, the network device 120 may cause the apparatus 110 to enter an inactive state. After or in response to receiving (1015) the configuration information, the apparatus 110 may change from the inactive state, e.g., the RRC INACTIVE state,to a connected state, e.g., the RRC CONNECTED state.
[0182] Based on the received configuration information, the apparatus 110 performs (1020) the local routing based on the at least one common key. Correspondingly, the network device 120 also performs (1025) the local routing based on the same configuration information.
[0183] When performing (1020) the local routing, the apparatus 110 may be a transmitter, e.g., the apparatus 110-1, which may transmit data to a further apparatus 110-2 via the network device 120. Before the transmission, the apparatus 110 may generate the at least one key based on the at least one common key and the at least one target algorithm. Then, the apparatus 110 may process data to be transmitted between the apparatus 110 and the network device 120, for example, by performing encryption and / or integrity protection on the data based on the at least one key. Afterwards, the apparatus 110 may transmit the processed data to the network device 120.
[0184] In some example embodiments, the encryption and / or the integrity protection may be performed based on the at least key determined from the same common key. Alternatively, the apparatus 110-1 may perform the encryption based on at least one key determined from a common key used for encryption and perform the integrity protection based on at least one key determined from a different common key used for the integrity protection.
[0185] As for the network device 120, it may receive, from the apparatus 110-1, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one key, which is generated based on the at least one common key and the at least one target algorithm. Then, the network device 120 may transmit the processed data to the further apparatus 110-2, as shown in the example environment 200A. Alternatively, in the example environment 200B, the network device 120-1 may transmit the processed data to the further network device 120-2 which is associated with the further apparatus 110-2.
[0186] As an alternative, when performing (1020) the local routing, the apparatus 110 may be a receiver, e.g., the apparatus 110-1 which may receive data to from the further apparatus 110-2 via the network device 120. Specifically, the apparatus 110-1 may receive, from the network device 120, processed data on which encryption and / orintegrity protection is performed. Then, the apparatus 110-1 may perform decryption and / or integrity verification on the processed data based on based on the at least one key, which is generated based on the at least one common key and the at least one target algorithm. Likewise, the decryption and the integrity verification may be performed by using the at least one key generated from the same common key, or from different common keys.
[0187] Regarding the network device 120, it may receive processed data from the further apparatus 110-2, where at least one of encryption or integrity protection on the data is performed on the data based on the at least one key, which is generated based on the at least one common key and the at least one target algorithm. This is shown in the example environment 200A. Alternatively, the processed data may be received from a further network device 120-2 associated with the further apparatus 110-2, as shown in the example environment 200B.
[0188] The network device 120 may not process the received processed data, e.g., does not decrypt the data, and may transmit the processed data to the apparatus 110-1 directly. That is, the network device 120 may forward the received processed data to the further apparatus 110-2 or the further network device 120-2.
[0189] Accordingly, the local routing which is a transparent forwarding of user plane (UP) data may be enabled, and E2E encryption of the UP data can be performed between apparatuses, e.g., UEs. Thus, the UP data can be efficiently exchanged between UEs connected via satellites without going through the ground network. This can also reduce lot of processing at SAT-gNBs in terms of integrity checks, decryption, etc. for all UP data packets exchanged between UEs connected via satellites. This can also be good for energy efficiency and sustainability.
[0190] FIG. 11 illustrates a further signaling flow 1100 for local routing in accordance with some example embodiments of the present disclosure. The signaling flow 1100 involves a UE1 1101 which is an example of the apparatus 110-1, a UE2 1102 which is an example of the apparatus 110-2, a SAT-gNB 1103 which is an example of the network device 120, a GW 1104, a CN 1105 and a HN 1106.
[0191] In the signaling flow 1100, at step 1111, after authentication of the UE1 1101 and the UE2 1102 is successfully completed, the local routing, e.g., local SAT-gNBrouting, is enabled or authorized for both the UE1 1101 and the UE2 1102. The configuration may be also stored in SAT-gNB 1103 in the UE context for future reference.
[0192] Subsequently, at 1112a and 1112b, the UE1 context may be available with UE1 and SAT-gNB. Similarly, at 1113a and 1113b, UE2 context may be available with UE2 and SAT-gNB. Both the UE1 1101 and the UE2 1102 may use their respective keys (derived as per legacy procedures) for RRC control plane message and UP keys for data packets. As per legacy procedures, all packets would need to be routed via Core Network (via gateway) between the UE1 1101 and the UE2 1102. Both the UE1 1101 and the UE2 1102 may be connected via same SAT-gNB 1103 in this scenario shown in FIG. 4.
[0193] At 1114.i-l and 1114.i-2, for UP Data transfer, protocol data unit (PDU) session establishment may be initiated for both the UE1 and the UE2.
[0194] At 1114.ii, the core network (CN) 1105 may identify a possibility of E2E encrypted UE - SAT - UE communication and sees the possibility of local routing. This is possible based on the information about which satellite is covering which UE.
[0195] At 1114.iii, if local routing is possible based on knowledge that both UEs are covered by the same satellite gNB, the CN 1105, e.g., the access and mobility management function (AMF) may inform the SAT-gNB 1103 about this, and subsequently, local routing may be enabled by SAT-gNB 1103.
[0196] At 1114.iv-l, the PDU session establishment may be initiated for both the UE1 1101 and the UE2 1102.
[0197] After 1114.iv-2, the UE1 1101 and the UE2 1102 are having PDU sessions established, but at this point the UP data may need to be routed via the core network on the ground as per legacy procedures.
[0198] At 1115a, based on step 1114.iii, the SAT-gNB 1103 may decide to enable the local routing.
[0199] At 1115b and 1115c, the SAT-gNB 1103 may temporarily move both the UE1 1101 and the UE2 1102 in the RRC INACTIVE state. This may be required to performreconfiguration with new KsAT-gNB-iocai-route key(s), which are also referred to as the common key(s), in subsequent steps.
[0200] At 1116, the SAT-gNB 1103 may generate the common key KsAT-gNB-iocai-route. The common key may be generated based on a first key associated with the UE1 1101, a second key associated with the UE2 1102, and / or a random number.
[0201] At 1117, the SAT-gNB 1103 may determine a target algorithm for key generation based on the capability information of the UE1 1101 and the capability information of the UE2 1102. The capability information of the UE1 1101 may indicate preferred algorithm of the UE1 1101, and the capability information of the UE2 1102 may indicate preferred algorithm of the UE2 1102.
[0202] At 1119a and 1119b, the SAT-gNB 1103 may perform RRC Reconfiguration with the UE1 1101 and the UE2 1102, respectively, to transmit configuration information including the common key and the target algorithm to both the UE1 1101 and the UE2 1102. After these steps, the UE1 1101 and the UE2 1102 may be back to the RRC CONNECTED state.
[0203] At 1120, the UE1 1101 may generate new keys based on the common key and the target algorithm. At 1121a, the UE1 1101 may perform the local routing packet integrity protected and ciphered using the new keys. For example, the UE1 1101 may perform encryption and integrity protection on data to be transmitted to the UE2 1102.
[0204] At 1121b, the UE1 1101 may transmit the processed data (which may be protected UP packets) to the SAT-gNB 1103.
[0205] At 1121c, the SAT-gNB 1103 may determine to locally route / forward the UP data received from the UE1 1101 to the UE2 1102 and forward, at 112 Id, the data packets to the UE2 1102.
[0206] At 112 le, the UE1 1102 may generate the new keys based on the common key and the target algorithm. At 1121g, the UE2 1102 may perform decryption and integrity verification on the received data packets. That is, the local routing packets are integrity protection verified and deciphered using the new keys.
[0207] In some other example embodiments of the present disclosure, for local routingvia multiple satellites, the respective satellites may maintain the UE contexts. In case there is no end-to-end encryption between UEs, the data encrypted by UE1 is sent to a gNB (SAT1), where it is decrypted. Then via local routing, the SAT1 will route the data to another gNB (SAT2). Here the data is encrypted using UE2 context keys and sent to UE2.
[0208] In this scenario, moving satellites may need to ensure that the UE contexts are transferred securely between satellites whenever one satellite leaves and another satellite comes up in the coverage of the same UE.
[0209] FIG. 12A and 12B illustrate signaling flows 1200 A and 1200B for local routing without end-to-end (E2E) encryption in accordance with some example embodiments of the present disclosure, respectively. For the purposes of discussion, the signaling flows 1200A and 1200B will be discussed with reference to FIG. 2B, for example, by using the apparatus 110-1, the network device 120-1 and the network device 120-2. The network device 120-1 and the network device 120-2 may be non-terrestrial network devices.
[0210] In some embodiments, the apparatus 110-1 may be or include a terminal device, and the further apparatus 110-2 may be or include a further terminal device. The network device 120-1 may be or may be included in a satellite, and the further network device 120-2 may be or may be included in a further satellite.
[0211] In the signaling flow 1200A, the network device 120-1 determines (1250), based on context information, a further network device 120-2 for local routing. The local routing is between an apparatus 110-1 served by the network device 120-1 and a further apparatus 110-2 served by the further network device 120-2 via the network device 120-1 and the further network device 120-2.
[0212] The apparatus 110-1 may transmit (1220) data to the network device 120-1. The network device 120-1, upon receiving (1225) the data from the apparatus 110-1, decrypts the data based on a key associated with the apparatus 110-1, and transmits (1230) the decrypted data to the further network device 120-2. The further network device 120-2, upon receiving (1235) the data, may encrypt the data based on the key associated with the further apparatus 110-2, and transmit the encrypted data to the further apparatus 110-2.
[0213] In this way, the local routing without E2E encryption can be achieved.
[0214] In the signaling flow 1200B, the network device 120-1 determines (1250) a further network device 120-2 for local routing based on context information. The local routing is between an apparatus 110-1 served by the network device 120-1 and a further apparatus 110-2 served by the further network device 120-2 via the network device 120-1 and the further network device 120-2.
[0215] In this case, the further network device 120-2 may transmit (1255) data to the network device 120-1. The network device 120-1, upon receiving (1260) the data from the further network device 120-2, encrypt the data based on the key associated with the apparatus 110-1, and transmit (1265) the encrypted data to the apparatus 110-1.
[0216] The apparatus 110-1, upon receiving (1270) the data, may decrypt the data based on the key associated with the apparatus 110-1. In this way, the local routing without E2E encryption can be also achieved.
[0217] In example embodiments shown with respect to FIG. 12A and FIG. 12B, the context information may be stored at the network device 120-1.
[0218] In some example embodiments, the context information discussed in example embodiments of FIG. 12A and FIG. 12B may include an identification of the further network device 120-2. In addition, the context information may further include, for example, but not limited to, the key associated with the apparatus, a list of algorithms for deriving the key, one or more configured parameters, and / or the like.
[0219] Optionally, in the example embodiments of FIG. 12A and FIG. 12B, during a connection establishment procedure of a protocol data unit (PDU) session between the apparatus and the further apparatus, an identification of the network device and an identification of the further network device may be exchanged between the network device 120-1 and further network device 120-2.
[0220] FIG. 14 illustrates a schematic diagram 1400 of UE context for local routing without E2E encryption in accordance with some example embodiments of the present disclosure. As shown, the context information stored on a network device, e.g., gNB (SAT1) is denoted as UE Context #1, and the context information stored on another network device, e.g., gNB (SAT2), is denoted as UE Context #2.
[0221] The UE Context #1 includes an identification of gNB (SAT2), that is, SAT_ID#2. Correspondingly, the UE Context #2 includes an identification of gNB (SAT1), that is, SAT_ID#1. In addition, the UE Context #1 may further include other information, such as KgNB#l, a list of algorithms (denoted as ALGO), configuration parameter(s) and so on. The UE Context #2 may further include other information, such as KgNB#2, a list of algorithms (denoted as ALGO), configuration parameter(s) and so on.
[0222] FIG. 13 illustrates a further signaling flow 1300 for local routing without E2E encryption in accordance with some example embodiments of the present disclosure. The signaling flow 1300 involves a UE1 1301 which is an example of the apparatus 110-1, a UE2 1302 which is an example of the apparatus 110-2, a SAT1 (which may implement as a gNB and / or User Plane Function (UPF)) 1303, which is an example of the network device 120-1, a SAT2 (which may implement as a gNB and / or UPF) 1304, which is an example of the network device 120-2, a network entity including Access and Mobility Management Function (AMF) / Session Management Function (SMF) 1305, and a network entity including Authentication Server Function (AUSF) / Unified Data Management (UDM) 1306.
[0223] In the signaling flow 1300, at 1311, primary authentication may be successful for the UE2 1302. The UE2 1302 may send DATA EXCHANGE AT SAT LEVEL support flag. A home network (HN) confirms if it is allowed or not.
[0224] At 1312, primary authentication may be successful fortheUEl 1301. TheUEl 1301 may send DATA EXCHANGE AT SAT LEVEL support flag. The HN may confirm if it is allowed or not.
[0225] At 1313, the SAT may be configured with DATA EXCHANGE AT SAT LEVEL.
[0226] At 1314, the UE1 1301 and the UE2 1302 may establish an individual RRC connection. SAT will enable the exchange via SAT ISL.
[0227] Thus, through steps 1311 to 1314, primary authentication may be successful for UE#2 and for UE#1. Satellite may be configured for local data routing between two or many satellites. Actual details of each routing will be performed during PDU sessionestablishment phase. The UE#1 1301 and UE#2 1302 may establish an individual RRC connection.
[0228] At 1315a, during PDU session establishment phase, both SAT IDs are exchanged and stored in UE context for local data routing. The Data packet may be encrypted and integrity protected using UE#1 context UP key. The encrypted-UP packet may be sent to SAT#l(gNB on board with UPF) 1303. The AMF / Core network may identify the en-route satellites which can enable routing of UP data from UE1 to UE2. The list of such SAT IDs may be communicated to each en-route satellite, with SAT ID of the next-hop satellites. As there is routing id (SAT ID) between two UE context (UE#1 and UE#2), then UP packet may be decrypted and directly send to SAT#2 which is the next-hop satellite. The same data packet may be encrypted in the SAT#2 and sent to UE#2.
[0229] This ensures that the UP data does not need to go to the ground network, and gets routed using the “routing ID” information, which is a combination of en-route SAT IDs.
[0230] As shown, at 1315a, during PDU session establishment, both SAT IDs are exchanged for local routing. AMF / Core Network may provide information about enroute satellite IDs (Next-hop SAT ID) for each satellite covering individual UEs. This information may enable the exchange of SAT IDs between satellites using ISL.
[0231] At 1315b, data packet is encrypted and integrity protected using UE1 context UP key.
[0232] At 1315c, the data packet is transmitted from the UE1 1301 to the SAT1 1303.
[0233] At 1315d, the data packet is decrypted and integrity protection checked using UE1 context UP key.
[0234] At 1315e, the data packet is transmitted from the SAT1 1303 to the SAT2 1304.
[0235] At 1315f, the data packet is encrypted and integrity protected by the SAT2 1304 using UE2 context UP key.
[0236] At 1315g, the data packet is transmitted from the SAT2 1304 to the UE2 1302.
[0237] At 1315h, the data packet is decrypted and integrity protected verified usingUE2 context UP key.
[0238] FIG. 15 shows a flowchart of an example method 1500 implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1500 will be described from the perspective of the apparatus 110 in FIGS. 2 A and 2B.
[0239] At block 1510, the apparatus 110 receives, from a non-terrestrial network device, configuration information about at least one common key for protecting local routing between the apparatus and a further apparatus via the network device.
[0240] At block 1520, the apparatus 110 performs the local routing based on the at least one common key.
[0241] In some example embodiments, the apparatus 110 is caused to perform the local routing based on the at least one common key by: processing data to be transmitted between the apparatus and the network device by performing, based on the at least one common key, at least one of encryption or integrity protection on the data; and transmitting the processed data to the network device.
[0242] In some example embodiments, the at least one of the encryption or the integrity protection is performed by using a same common key, or by using different common keys.
[0243] In some example embodiments, the apparatus is caused to perform the local routing based on the at least one common key by: receiving, from the network device, processed data on which at least one of encryption or integrity protection is performed; and performing at least one of decryption or integrity verification on the processed data based on the at least one common key.
[0244] In some example embodiments, the at least one of the decryption or the integrity verification is performed by using a same common key, or by using different common keys.
[0245] In some example embodiments, the method 1500 further comprises: receiving, from the network device, an indication to enable the local routing.
[0246] In some example embodiments, the at least one common key is protected witha key which was used for control plane protection associated with the apparatus.
[0247] In some example embodiments, the configuration information is received via a radio resource control (RRC) message.
[0248] In some example embodiments, the at least one common key is generated based on at least one of: a first key associated with the apparatus, a second key associated with the further apparatus, or a random number.
[0249] In some example embodiments, the apparatus changes from an inactive state to a connected state after or in response to receiving the configuration information.
[0250] In some example embodiments, the apparatus 110 comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0251] FIG. 16 shows a flowchart of an example method 1600 implemented at a network device in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1600 will be described from the perspective of the network device 120 in FIGS. 2A and 2B.
[0252] At block 1610, the network device 120 transmits, to an apparatus, configuration information about at least one common key for protecting local routing between the apparatus and a further apparatus via the network device, wherein the network device is a non-terrestrial network device.
[0253] At block 1620, the network device 120 performs the local routing based on the at least one common key.
[0254] In some example embodiments, the method 1600 further comprises: receiving, from a network entity, information indicating a possibility of the local routing; and enabling the local routing based on the received information.
[0255] In some example embodiments, the method 1600 further comprises: based on enabling the local routing, causing the apparatus to enter an inactive state, wherein the apparatus changes from the inactive state to a connected state after or in response to receiving the configuration information.
[0256] In some example embodiments, the method 1600 further comprises: obtaininga first key associated with the apparatus from a context of the apparatus and a second key associated with the further apparatus from a context of the further apparatus; and generating the at least one common key based on the first key, the second key and a random number.
[0257] In some example embodiments, the network device is caused to transmit the configuration information by: protecting the at least one common key with a key for control plane protection associated with the apparatus; and transmitting, to the apparatus, the configuration information about the at least one protected common key.
[0258] In some example embodiments, the network device is caused to perform the local routing based on the at least one common key by: receiving, from the apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one common key; and transmitting the processed data to the further apparatus or a further network device associated with the further apparatus.
[0259] In some example embodiments, the network device is caused to perform the local routing based on the at least one common key by: receiving, from the further apparatus or a further network device associated with the further apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one common key; and transmitting the processed data to the apparatus.
[0260] In some example embodiments, the at least one of the encryption or the integrity protection is performed by using a same common key, or by using different common keys.
[0261] In some example embodiments, the method 1600 further comprises: transmitting, to the apparatus, an indication to enable the local routing.
[0262] In some example embodiments, the configuration information is transmitted via a radio resource control (RRC) message.
[0263] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0264] FIG. 17 shows a flowchart of an example method 1700 implemented at a network device in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1700 will be described from the perspective of the network device 120 in FIGS. 2A and 2B.
[0265] At block 1710, the network device 120 determines, based on context information, a further network device for local routing between an apparatus served by the network device and a further apparatus served by the further network device via the network device and the further network device, wherein the network device is a nonterrestrial network device.
[0266] At block 1720, the network device 120, in response to receiving data from the apparatus, decrypts the data based on a key associated with the apparatus, and transmits the decrypted data to the further network device.
[0267] At block 1730, the network device 120, in response to receiving data from the further network device, encrypts the data based on the key associated with the apparatus, and transmits the encrypted data to the apparatus.
[0268] In some example embodiments, the context information is stored at the network device.
[0269] In some example embodiments, context information comprises an identification of the further network device and further comprises at least one of: the key associated with the apparatus, a list of algorithms for deriving the key, or one or more configured parameters.
[0270] In some example embodiments, during a connection establishment procedure of a protocol data unit (PDU) session between the apparatus and the further apparatus, an identification of the network device and an identification of the further network device are exchanged between the network device and further network device.
[0271] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, the network device comprises or is comprised in a satellite, and the further network device comprises or is comprised in a further satellite.
[0272] In some example embodiments, an apparatus capable of performing any of the method 1500 (for example, the apparatus 110 in FIGS. 2A and 2B) may comprise means for performing the respective operations of the method 1500. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the apparatus 110 in FIGS. 2 A and 2B.
[0273] In some example embodiments, the apparatus comprises means for receiving, from a non-terrestrial network device, configuration information about at least one common key for protecting local routing between the apparatus and a further apparatus via the network device; and means for performing the local routing based on the at least one common key.
[0274] In some example embodiments, the apparatus may further comprise means for processing data to be transmitted between the apparatus and the network device by performing, based on the at least one common key, at least one of encryption or integrity protection on the data; and means for transmitting the processed data to the network device.
[0275] In some example embodiments, the at least one of the encryption or the integrity protection is performed by using a same common key, or by using different common keys.
[0276] In some example embodiments, the apparatus may further comprise means for receiving, from the network device, processed data on which at least one of encryption or integrity protection is performed; and means for performing at least one of decryption or integrity verification on the processed data based on the at least one common key.
[0277] In some example embodiments, the at least one of the decryption or the integrity verification is performed by using a same common key, or by using different common keys.
[0278] In some example embodiments, the apparatus may further comprise: means for receiving, from the network device, an indication to enable the local routing.
[0279] In some example embodiments, the at least one common key is protected witha key which was used for control plane protection associated with the apparatus.
[0280] In some example embodiments, the configuration information is received via a radio resource control (RRC) message.
[0281] In some example embodiments, the at least one common key is generated based on at least one of: a first key associated with the apparatus, a second key associated with the further apparatus, or a random number.
[0282] In some example embodiments, the apparatus changes from an inactive state to a connected state after or in response to receiving the configuration information.
[0283] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0284] In some example embodiments, a network device capable of performing any of the method 1600 (for example, the network device 120 in FIGS. 2 A and 2B) may comprise means for performing the respective operations of the method 1600. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network device may be implemented as or included in the network device 120 in FIGS. 2A and 2B.
[0285] In some example embodiments, the network device comprises means for transmitting, to an apparatus, configuration information about at least one common key for protecting local routing between the apparatus and a further apparatus via the network device, wherein the network device is a non-terrestrial network device; and means for performing the local routing based on the at least one common key.
[0286] In some example embodiments, the network device further comprises: means for receiving, from a network entity, information indicating a possibility of the local routing; and means for enabling the local routing based on the received information.
[0287] In some example embodiments, the network device further comprises: means for based on enabling the local routing, causing the apparatus to enter an inactive state, wherein the apparatus changes from the inactive state to a connected state after or in response to receiving the configuration information.
[0288] In some example embodiments, the network device further comprises: means for obtaining a first key associated with the apparatus from a context of the apparatus and a second key associated with the further apparatus from a context of the further apparatus; and means for generating the at least one common key based on the first key, the second key and a random number.
[0289] In some example embodiments, the network device may further comprise means for protecting the at least one common key with a key for control plane protection associated with the apparatus; and means for transmitting, to the apparatus, the configuration information about the at least one protected common key.
[0290] In some example embodiments, the network device may further comprise means for receiving, from the apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one common key; and means for transmitting the processed data to the further apparatus or a further network device associated with the further apparatus.
[0291] In some example embodiments, the network device may further comprise means for receiving, from the further apparatus or a further network device associated with the further apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one common key; and means for transmitting the processed data to the apparatus.
[0292] In some example embodiments, the at least one of the encryption or the integrity protection is performed by using a same common key, or by using different common keys.
[0293] In some example embodiments, the network device further comprises: means for transmitting, to the apparatus, an indication to enable the local routing.
[0294] In some example embodiments, the configuration information is transmitted via a radio resource control (RRC) message.
[0295] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0296] In some example embodiments, a network device capable of performing any of the method 1700 (for example, the network device 120 in FIGS. 2A and 2B) may comprise means for performing the respective operations of the method 1700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network device may be implemented as or included in the network device 120.
[0297] In some example embodiments, the network device comprises means for determining, based on context information, a further network device for local routing between an apparatus served by the network device and a further apparatus served by the further network device via the network device and the further network device, wherein the network device is a non-terrestrial network device; means for in response to receiving data from the apparatus, decrypting the data based on a key associated with the apparatus, and transmit the decrypted data to the further network device; and means for in response to receiving data from the further network device, encrypting the data based on the key associated with the apparatus, and transmit the encrypted data to the apparatus.
[0298] In some example embodiments, the context information is stored at the network device.
[0299] In some example embodiments, context information comprises an identification of the further network device and further comprises at least one of: the key associated with the apparatus, a list of algorithms for deriving the key, or one or more configured parameters.
[0300] In some example embodiments, during a connection establishment procedure of a protocol data unit (PDU) session between the apparatus and the further apparatus, an identification of the network device and an identification of the further network device are exchanged between the network device and further network device.
[0301] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, the network device comprises or is comprised in a satellite, and the further network device comprises or is comprised in a further satellite.
[0302] FIG. 18 shows a flowchart of an example method 1800 implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1800 will be described from the perspective of the apparatus 110 in FIGS. 2 A and 2B.
[0303] At block 1810, the apparatus 110 transmits, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device.
[0304] At block 1820, the apparatus 110 receives, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one target algorithm is at least determined based on the at least one preferred algorithm.
[0305] At block 1830, the apparatus 110 performs the local routing by using the at least one target algorithm.
[0306] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0307] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
[0308] In some example embodiments, the method 1800 further comprises: generating, based on at least one target algorithm, the at least one key for performing at least one of encryption or integrity protection in the local routing.
[0309] In some example embodiments, the method 1800 further comprises: generating, based on at least one target algorithm, the at least one key for performing at least one of decryption or integrity verification.
[0310] In some example embodiments, the method 1800 further comprises: receiving, from the network device, an indication to enable the local routing.
[0311] In some example embodiments, the configuration information is received via a radio resource control (RRC) message.
[0312] In some example embodiments, the apparatus changes from an inactive state to a connected state in response to receiving the configuration information.
[0313] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0314] FIG. 19 shows a flowchart of an example method 1900 implemented at a network device in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1900 will be described from the perspective of the network device 120 in FIGS. 2 A and 2B.
[0315] At block 1910, the network device 120 receives capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device.
[0316] At block 1920, the network device 120 receives further capability information indicating at least one preferred algorithm of the further apparatus associated with generating at least one key to be used in the local routing.
[0317] At block 1930, the network device 120 determines at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of theapparatus and the at least one preferred algorithm of the further apparatus.
[0318] At block 1940, the network device 120 transmits, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
[0319] In some example embodiments, the method 1900 further comprises: receiving, from a network entity, information indicating a possibility of the local routing; and determining to enable the local routing based on the received information.
[0320] In some example embodiments, the method 1900 further comprises: causing the apparatus to enter an inactive state, wherein the apparatus changes from the inactive state to a connected state in response to receiving the configuration information.
[0321] In some example embodiments, the method 1900 further comprises: transmitting, to the apparatus, an indication to enable the local routing.
[0322] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0323] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
[0324] In some example embodiments, the configuration information is transmitted via a radio resource control (RRC) message.
[0325] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0326] In some example embodiments, an apparatus capable of performing any of the method 1800 (for example, the apparatus 110 in FIGS. 2A and 2B) may comprise means for performing the respective operations of the method 1800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the apparatus 110 in FIGS. 2 A and 2B.
[0327] In some example embodiments, the apparatus comprises means for transmitting, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device; means for receiving, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one target algorithm is at least determined based on the at least one preferred algorithm; and means for performing the local routing by using the at least one target algorithm.
[0328] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0329] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by thenetwork device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
[0330] In some example embodiments, the apparatus further comprises: means for generating, based on at least one target algorithm, the at least one key for performing at least one of encryption or integrity protection in the local routing.
[0331] In some example embodiments, the apparatus further comprises: means for generating, based on at least one target algorithm, the at least one key for performing at least one of decryption or integrity verification.
[0332] In some example embodiments, the apparatus further comprises: means for receiving, from the network device, an indication to enable the local routing.
[0333] In some example embodiments, the configuration information is received via a radio resource control (RRC) message.
[0334] In some example embodiments, the apparatus changes from an inactive state to a connected state in response to receiving the configuration information.
[0335] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0336] In some example embodiments, a network device capable of performing any of the method 1900 (for example, the network device 120 in FIGS. 2 A and 2B) may comprise means for performing the respective operations of the method 1900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network device may be implemented as or included in the network device 120 in FIGS. 2A and 2B.
[0337] In some example embodiments, the network device comprises means for receiving capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device; means for receiving further capability information indicating at least one preferred algorithm of the furtherapparatus associated with generating at least one key to be used in the local routing; means for determining at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus; and means for transmitting, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
[0338] In some example embodiments, the network device further comprises: means for receiving, from a network entity, information indicating a possibility of the local routing; and means for determining to enable the local routing based on the received information.
[0339] In some example embodiments, the network device further comprises: means for causing the apparatus to enter an inactive state, wherein the apparatus changes from the inactive state to a connected state in response to receiving the configuration information.
[0340] In some example embodiments, the network device further comprises: means for transmitting, to the apparatus, an indication to enable the local routing.
[0341] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0342] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key forperforming integrity protection in a data plane.
[0343] In some example embodiments, the configuration information is transmitted via a radio resource control (RRC) message.
[0344] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0345] FIG. 20 shows a flowchart of an example method 2000 implemented at an apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 2000 will be described from the perspective of the apparatus 110 in FIGS. 2 A and 2B.
[0346] At block 2010, the apparatus 110 receives, from a non-terrestrial network device, configuration information indicating at least one common key and at least one target algorithm, wherein the at least one common key is used for protecting local routing between the apparatus and a further apparatus via the network device, and the at least one target algorithm is used for generating at least one key to be used in the local routing based on the at least one common key.
[0347] At block 2020, the apparatus 110 performs the local routing based on the configuration information.
[0348] In some example embodiments, the apparatus is caused to perform the local routing based on the configuration information by: generating the at least one key based on the at least one common key and the at least one target algorithm; processing data to be transmitted between the apparatus and the network device by performing at least one of encryption or integrity protection on the data based on the at least one key; and transmitting the processed data to the network device.
[0349] In some example embodiments, the apparatus is caused to perform the local routing based on the configuration information by: generating the at least one key based on the at least one common key and the at least one target algorithm; receiving, from the network device, processed data on which at least one of encryption or integrity protection is performed; and performing at least one of decryption or integrity verification on the processed data based on the at least one key.
[0350] In some example embodiments, the at least one common key comprises a first common key for a control plane and a second common key for a data plane, and the at least one key comprises: one or more keys for performing at least one of encryption or integrity protection in the control plane, and / or one or more keys for performing at least one of encryption or integrity protection in the data plane.
[0351] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
[0352] In some example embodiments, the method 2000 further comprises: receiving, from the network device, an indication to enable the local routing.
[0353] In some example embodiments, the method 2000 further comprises: transmitting, to the network device, capability information indicating at least one preferred algorithm associated with generating the at least one key.
[0354] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0355] In some example embodiments, the configuration information is received via a radio resource control (RRC) message.
[0356] In some example embodiments, the at least one common key is generated based on at least one of: a first key associated with the apparatus, a second key associatedwith the further apparatus, or a random number.
[0357] In some example embodiments, the apparatus changes from an inactive state to a connected state after or in response to receiving the configuration information.
[0358] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0359] FIG. 21 shows a flowchart of an example method 2100 implemented at a network device in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 2100 will be described from the perspective of the network device 120 in FIGS. 2 A and 2B.
[0360] At block 2110, the network device 120 transmits, to an apparatus, configuration information indicating at least one common key and at least one target algorithm, wherein the at least one common key is used for protecting local routing between the apparatus and a further apparatus via the network device, and the at least one target algorithm is used for generating at least one key to be used in the local routing based on the at least one common key, wherein the network device is a nonterrestrial network device.
[0361] At block 2120, the network device 120 performs the local routing based on the configuration information.
[0362] In some example embodiments, the method 2100 further comprises: receiving, from a network entity, information indicating a possibility of the local routing; and enabling the local routing based on the received information.
[0363] In some example embodiments, the method 2100 further comprises: causing the apparatus to enter an inactive state, wherein the apparatus changes from the inactive state to a connected state after or in response to receiving the configuration information.
[0364] In some example embodiments, the method 2100 further comprises: obtaining a first key associated with the apparatus from a context of the apparatus and a second key associated with the further apparatus from a context of the further apparatus; and generating the at least one common key based on the first key, the second key and arandom number.
[0365] In some example embodiments, the network device is caused to perform the local routing based on the configuration information by: receiving, from the apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one key generated based on the at least one common key and the at least one target algorithm; and transmitting the processed data to the further apparatus or a further network device associated with the further apparatus.
[0366] In some example embodiments, the network device is caused to perform the local routing based on the configuration information by: receiving, from the further apparatus or a further network device associated with the further apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one key generated based on the at least one common key and the at least one target algorithm; and transmitting the processed data to the apparatus.
[0367] In some example embodiments, the at least one common key comprises a first common key for a control plane and a second common key for a data plane, and the at least one key comprises: one or more keys for performing at least one of encryption or integrity protection in the control plane, and / or one or more keys for performing at least one of encryption or integrity protection in the data plane.
[0368] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
[0369] In some example embodiments, the method 2100 further comprises: transmitting, to the apparatus, an indication to enable the local routing.
[0370] In some example embodiments, the method 2100 further comprises: receiving,from the apparatus, capability information indicating at least one preferred algorithm associated with generating the at least one key.
[0371] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0372] In some example embodiments, the configuration information is transmitted via a radio resource control (RRC) message.
[0373] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0374] In some example embodiments, an apparatus capable of performing any of the method 2000 (for example, the apparatus 110 in FIGS. 2A and 2B) may comprise means for performing the respective operations of the method 2000. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The apparatus may be implemented as or included in the apparatus 110 in FIGS. 2 A and 2B.
[0375] In some example embodiments, the apparatus comprises means for receiving, from a non -terrestrial network device, configuration information indicating at least one common key and at least one target algorithm, wherein the at least one common key is used for protecting local routing between the apparatus and a further apparatus via the network device, and the at least one target algorithm is used for generating at least one key to be used in the local routing based on the at least one common key; and means for performing the local routing based on the configuration information.
[0376] In some example embodiments, the apparatus is caused to perform the local routing based on the configuration information by: generating the at least one key based on the at least one common key and the at least one target algorithm; processing datato be transmitted between the apparatus and the network device by performing at least one of encryption or integrity protection on the data based on the at least one key; and transmitting the processed data to the network device.
[0377] In some example embodiments, the apparatus is caused to perform the local routing based on the configuration information by: generating the at least one key based on the at least one common key and the at least one target algorithm; receiving, from the network device, processed data on which at least one of encryption or integrity protection is performed; and performing at least one of decryption or integrity verification on the processed data based on the at least one key.
[0378] In some example embodiments, the at least one common key comprises a first common key for a control plane and a second common key for a data plane, and the at least one key comprises: one or more keys for performing at least one of encryption or integrity protection in the control plane, and / or one or more keys for performing at least one of encryption or integrity protection in the data plane.
[0379] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
[0380] In some example embodiments, the apparatus further comprises: means for receiving, from the network device, an indication to enable the local routing.
[0381] In some example embodiments, the apparatus further comprises: means for transmitting, to the network device, capability information indicating at least one preferred algorithm associated with generating the at least one key.
[0382] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key forperforming encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0383] In some example embodiments, the configuration information is received via a radio resource control (RRC) message.
[0384] In some example embodiments, the at least one common key is generated based on at least one of: a first key associated with the apparatus, a second key associated with the further apparatus, or a random number.
[0385] In some example embodiments, the apparatus changes from an inactive state to a connected state after or in response to receiving the configuration information.
[0386] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0387] In some example embodiments, a network device capable of performing any of the method 2100 (for example, the network device 120 in FIGS. 2 A and 2B) may comprise means for performing the respective operations of the method 2100. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The network device may be implemented as or included in the network device 120 in FIGS. 2A and 2B.
[0388] In some example embodiments, the network device comprises means for transmitting, to an apparatus, configuration information indicating at least one common key and at least one target algorithm, wherein the at least one common key is used for protecting local routing between the apparatus and a further apparatus via the network device, and the at least one target algorithm is used for generating at least one key to be used in the local routing based on the at least one common key, wherein the network device is a non-terrestrial network device; and means for performing the local routing based on the configuration information.
[0389] In some example embodiments, the network device further comprises: meansfor receiving, from a network entity, information indicating a possibility of the local routing; and means for enabling the local routing based on the received information.
[0390] In some example embodiments, the network device further comprises: means for causing the apparatus to enter an inactive state, wherein the apparatus changes from the inactive state to a connected state after or in response to receiving the configuration information.
[0391] In some example embodiments, the network device further comprises: means for obtaining a first key associated with the apparatus from a context of the apparatus and a second key associated with the further apparatus from a context of the further apparatus; and means for generating the at least one common key based on the first key, the second key and a random number.
[0392] In some example embodiments, the network device is caused to perform the local routing based on the configuration information by: receiving, from the apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one key generated based on the at least one common key and the at least one target algorithm; and transmitting the processed data to the further apparatus or a further network device associated with the further apparatus.
[0393] In some example embodiments, the network device is caused to perform the local routing based on the configuration information by: receiving, from the further apparatus or a further network device associated with the further apparatus, processed data on which at least one of encryption or integrity protection on the data is performed based on the at least one key generated based on the at least one common key and the at least one target algorithm; and transmitting the processed data to the apparatus.
[0394] In some example embodiments, the at least one common key comprises a first common key for a control plane and a second common key for a data plane, and the at least one key comprises: one or more keys for performing at least one of encryption or integrity protection in the control plane, and / or one or more keys for performing at least one of encryption or integrity protection in the data plane.
[0395] In some example embodiments, the at least one target algorithm comprises at least one of: an algorithm determined by the network device for the apparatus and thefurther apparatus to generate a key for performing encryption in a control plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane, an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
[0396] In some example embodiments, the network device further comprises: means for transmitting, to the apparatus, an indication to enable the local routing.
[0397] In some example embodiments, the network device further comprises: means for receiving, from the apparatus, capability information indicating at least one preferred algorithm associated with generating the at least one key.
[0398] In some example embodiments, the at least one preferred algorithm comprises at least one of: an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane, an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane, an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, or an algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
[0399] In some example embodiments, the configuration information is transmitted via a radio resource control (RRC) message.
[0400] In some example embodiments, the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
[0401] FIG. 22 is a simplified block diagram of a device 2200 that is suitable for implementing example embodiments of the present disclosure. The device 2200 may be provided to implement a communication device, for example, the apparatus 110 or the network device 120 as shown in FIGS. 2 A and 2B. As shown, the device 2200 includes one or more processors 2210, one or more memories 2220 coupled to the processor 2210, and one or more communication modules 2240 coupled to theprocessor 2210.
[0402] The communication module 2240 is for bidirectional communications. The communication module 2240 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 2240 may include at least one antenna.
[0403] The processor 2210 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 2200 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0404] The memory 2220 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 2224, an electrically programmable read only memory (EPROM), a flash memory, a hard disk, a compact disc (CD), a digital video disk (DVD), an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a randomaccess memory (RAM) 2222 and other volatile memories that will not last in the powerdown duration.
[0405] A computer program 2230 includes computer executable instructions that are executed by the associated processor 2210. The instructions of the program 2230 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 2230 may be stored in the memory, e.g., the ROM 2224. The processor 2210 may perform any suitable actions and processing by loading the program 2230 into the RAM 2222.
[0406] The example embodiments of the present disclosure may be implemented by means of the program 2230 so that the device 2200 may perform any process of the disclosure as discussed with reference to FIG. 3 to FIG. 21. The example embodiments of the present disclosure may also be implemented by hardware or by a combination ofsoftware and hardware.
[0407] In some example embodiments, the program 2230 may be tangibly contained in a computer readable medium which may be included in the device 2200 (such as in the memory 2220) or other storage devices that are accessible by the device 2200. The device 2200 may load the program 2230 from the computer readable medium to the RAM 2222 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0408] FIG. 23 shows an example of the computer readable medium 2300 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 2300 has the program 2230 stored thereon.
[0409] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0410] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non-transitory computer readable medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that performparticular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0411] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0412] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
[0413] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0414] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achievedesirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0415] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
WE CLAIM:
1. An apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:transmit, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device;receive, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one target algorithm is at least determined based on the at least one preferred algorithm; andperform the local routing by using the at least one target algorithm.
2. The apparatus of claim 1, wherein the at least one preferred algorithm comprises at least one of:an algorithm preferred by the apparatus for generating a key for performing encryption in a control plane,an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane,an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, oran algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
3. The apparatus of claim 1 or 2, wherein the at least one target algorithm comprises at least one of:an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane,69an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane,an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
4. The apparatus of any of claims 1 to 3, wherein the apparatus is further caused to: generate, based on at least one target algorithm, the at least one key for performing at least one of encryption or integrity protection in the local routing.
5. The apparatus of any of claims 1 to 3, wherein the apparatus is further caused to: generate, based on at least one target algorithm, the at least one key for performing at least one of decryption or integrity verification.
6. The apparatus of any of claims 1 to 5, wherein the apparatus is further caused to: receive, from the network device, an indication to enable the local routing.
7. The apparatus of any of claims 1 to 6, wherein the configuration information is received via a radio resource control (RRC) message.
8. The apparatus of any of claims 1 to 7, wherein the apparatus changes from an inactive state to a connected state in response to receiving the configuration information.
9. The apparatus of any of claims 1 to 8, wherein the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
10. A network device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the network device at least to:receive capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device;receive further capability information indicating at least one preferred algorithm of the further apparatus associated with generating at least one key to be used in the local routing;determine at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus; andtransmit, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
11. The network device of claim 10, wherein the network device is further caused to:receive, from a network entity, information indicating a possibility of the local routing; anddetermine to enable the local routing based on the received information.
12. The network device of claim 11, wherein the network device is further caused to:cause the apparatus to enter an inactive state, wherein the apparatus changes from the inactive state to a connected state in response to receiving the configuration information.
13. The network device of claim 11, wherein the network device is further caused to:transmit, to the apparatus, an indication to enable the local routing.
14. The network device of any of claims 11 to 13, wherein the at least one preferred algorithm comprises at least one of:an algorithm preferred by the apparatus for generating a key for performingencryption in a control plane,an algorithm preferred by the apparatus for generating a key for performing encryption in a data plane,an algorithm preferred by the apparatus for generating a key for performing integrity protection in a control plane, oran algorithm preferred by the apparatus for generating a key for performing integrity protection in a data plane.
15. The network device of any of claims 11 to 14, wherein the at least one target algorithm comprises at least one of:an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a control plane,an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing encryption in a data plane,an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a control plane, or an algorithm determined by the network device for the apparatus and the further apparatus to generate a key for performing integrity protection in a data plane.
16. The network device of any of claims 11 to 15, wherein the configuration information is transmitted via a radio resource control (RRC) message.
17. The network device of any of claims 11 to 16, wherein the apparatus comprises a terminal device, the further apparatus comprises a further terminal device, and the network device comprises or is comprised in a satellite.
18. A method comprising:transmitting, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device;receiving, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one targetalgorithm is at least determined based on the at least one preferred algorithm; and performing the local routing by using the at least one target algorithm.
19. A method comprising:receiving capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device;receiving further capability information indicating at least one preferred algorithm of the further apparatus associated with generating at least one key to be used in the local routing;determining at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus; andtransmitting, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
20. An apparatus comprising:means for transmitting, to a non-terrestrial network device, capability information indicating at least one preferred algorithm associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device;means for receiving, from the network device, configuration information indicating at least one target algorithm for generating the at least one key, wherein the at least one target algorithm is at least determined based on the at least one preferred algorithm; and means for performing the local routing by using the at least one target algorithm.
21. A network device comprising:means for receiving capability information indicating at least one preferred algorithm of an apparatus associated with generating at least one key to be used in local routing between the apparatus and a further apparatus via the network device, and wherein the network device is a non-terrestrial network device;means for receiving further capability information indicating at least one preferredalgorithm of the further apparatus associated with generating at least one key to be used in the local routing;means for determining at least one target algorithm for generating the at least one key based on the at least one preferred algorithm of the apparatus and the at least one preferred algorithm of the further apparatus; andmeans for transmitting, to the apparatus and the further apparatus, configuration information indicating the at least one target algorithm.
22. A computer readable medium comprising instructions stored thereon for causing an apparatus at least to perform the method of claim 18 or the method of claim 19.74