PC5 Remote UE Relay Access Via IWF for Secure NAS Continuity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing L3 UE-to-NW relay schemes in 5G wireless communication systems face issues such as the lack of a network access stratum (NAS) connection for remote UEs, insufficient end-to-end security, and IP session continuity when switching data paths between radio and relay links, which hinder efficient UE-to-network relay access.
Innovation Solution
Implementing a PC5 remote UE with UE-to-network relay access via an Interworking Function (IWF) to establish a NAS connection, utilize IPsec security associations, and enable Access Traffic Steering, Switching, and Splitting (ATSSS) to ensure secure and continuous data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If L3 UE-to-NW relay schemes are implemented to enable remote UE connectivity, then transmission speed and flexibility are improved, but transmission complexity and security risks increase
Solution Approach 1:
The patent introduces an Interworking Function (IWF) as an intermediary component between the remote UE and the 5G core network. The IWF establishes a NAS connection on behalf of the remote UE, manages IPsec security associations, and coordinates with the relay UE to provide end-to-end security. This intermediary approach enables the remote UE to access network services through the relay UE while maintaining security boundaries and reducing the complexity burden on the remote UE itself.
2Reliability
If relay access is used to extend network coverage to remote UEs, then connectivity is improved, but end-to-end security is compromised
Solution Approach 1:
The patent segments the communication path into distinct secured segments: the relay UE establishes its own secure connection to the network, while the remote UE communicates with the relay UE over PC5 interface. The IWF creates separate NAS connections and IPsec security associations for each UE, ensuring that security contexts are isolated and compromised security in one segment does not affect the other.
Solution Approach 2:
The IWF acts as a security intermediary that establishes end-to-end IPsec security associations between the remote UE and the network. It manages security contexts separately for relay and remote UEs, ensuring that the relay UE cannot access the remote UE's data plane traffic, thus maintaining security boundaries while enabling connectivity.
3Adaptability or versatility
If data path switching between radio and relay links is enabled for service continuity, then service availability is improved, but IP session continuity becomes difficult to maintain
Solution Approach 1:
The patent establishes a persistent NAS connection between the remote UE and the IWF before actual data transmission begins. This preliminary connection setup includes pre-configuring IPsec security associations and maintaining the NAS context even when data paths switch between radio access and relay access, ensuring that IP sessions remain continuous without requiring re-establishment during path switching.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to wireless communications and in particular to providing connectivity (2, 3, 4, 5) of a PCS remote user equipment, UE, with UE-to-network, NW, relay access to the 5G core, 5GC, via an IWF, e.g., N3IWF. A remote UE is provided (5) support for a network access stratum, NAS, connection with 5GC via an IWF. Access Traffic Steering, Switching and Splitting, ATSSS, support may be provided for a remote UE.