User plane model for non-3gpp access to fifth generation core network
Abstract
Systems and methods relating to establishment of a Packet Data Unit, PDU, session over a Non 3GPP Access to a 3GPP network and transmitting IP data and non-IP data are provided. A method of operation of a wireless device is provided and comprises sending to an AMF over an N3IWF a PDU session request to establish a PDU session to transport one of IP data or non-IP data over an established first IPsec, Security Association, SA, establishing an IPSec Child SA, for the PDU session and associating the IPSec Child SA to a PDU session then encapsulating the data using ESP encapsulation or GRE encapsulation associated with the IPSec Child SA and indicating the type of data that is being transmitted (e.g., non-IP data that comprises raw application data). In this manner, an IoT device is able to securely transmit to the 3GPP network IP data/non-IP data/raw application data over an unsecure non 3GPP access network such as Wireless Local Area Network. Methods and apparatus describing the NAS signalling and the PDU session as each using their respective IPSec SA are provided. Similarly, methods and apparatus describing the NAS signalling and the PDU sessions sharing a common IPSec SA are provided. GRE encapsulation of the data within the ESP frame is described for both NAS signalling and PDU session in the case of multiple IPSec/Child SAs or common IPSec SA. Similarly, methods and apparatus are provided for the N3IWF which provides for the UE secure access to the network.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method of operation of a wireless device and of a network entity of a third partnership project, 3GPP, network over an established Internet Protocol Security, IPsec, Security Association, SA, the method comprising:
sending by the wireless device over the established IPsec SA to the network entity a Non-Access Stratum, NAS, Packet Data Unit, PDU, session request message to establish a PDU session for transporting PDUs of a particular type; establishing between the network entity and the wireless device an IPSec Child SA for the PDU session for transmitting the PDUs of the particular type; transmitting by the network entity to the wireless device a NAS PDU session response over the established IPsec SA; using by the network entity and the wireless device at least one of a security parameter Index, SPI, of the IPSec Child SA, an IP address assigned to the PDU session or a PDU session identifier to associate the IPSec Child SA to the established PDU session; and encapsulating the PDUs of the particular type in a Generic Routing Encapsulating, GRE, header prior to transmitting the PDUs in an Encapsulation Security Payload, ESP, packet associated to the IPSec child SA.
2 . The method of claim 1 wherein the PDU session request includes an application type or an application identifier of an application generating the data for the PDU session.
3 . The method of claim 1 wherein the step of establishing between the network entity and the wireless device the IPSec Child SA further comprises sending by the network entity to the wireless device an Internet Key Exchange Create_Child Security Association (IKE Create Child SA) request message and receiving by the network entity from the wireless device an IKE Create Child SA response message.
4 . The method of claim 1 wherein the method further comprises obtaining by the wireless device from the network entity the PDU session identifier assigned to the PDU session in the IKE Create Child SA request message.
5 . The method of claim 4 wherein said associating the IPSec Child SA to the PDU session further comprises correlating by the wireless device the PDU session identifier included in the IKE Child SA request message to the PDU session identifier in the PDU session response message.
6 . The method of claim 1 , wherein said associating the IPSec Child SA to the PDU session further comprises correlating the SPI of the IPsec child SA to an SPI included in the NAS PDU session response.
7 . The method of claim 1 , wherein sending the PDU session is initiated as a result of receiving the data from an Internet of Thing, IoT, device connected to the wireless device.
8 . The method of claim 1 , wherein the PDUs of the particular type comprises one of non-Internet Protocol PDUs, non-IP framed PDUs, non-IP raw PDUs and IP PDUs.
9 . The method of claim 1 wherein the said transmitting the PDUs in an ESP packet associated to the IPSec child SA comprises transmitting the PDUs encapsulated in an ESP header.
10 . A wireless device, comprising:
at least one transceiver; at least one processor; and a memory comprising instructions executable by the at least one processor whereby the wireless device is operable to:
send over an established Internet Protocol Security Association, IPsec SA to a network entity a Non-Access Stratum, NAS, Packet Data Unit, PDU, session request message to establish a PDU session for transporting PDUs of a particular type;
receiving from the network entity an Internet Key Exchange Create_Child Security Association (IKE Create Child SA) request message comprising an identifier of the PDU session to establish an IPSec child SA for the PDU session;
receiving from the network entity over the established IPsec SA a NAS PDU session response comprising the identifier of the PDU session;
using the identifier of the PDU session to associate the IPSec Child SA to the established PDU session; and
encapsulating the PDUs of the particular type in a Generic Routing Encapsulating, GRE, header prior to transmitting to the network entity the PDUs in an Encapsulation Security Payload, ESP, packet associated to the IPSec child SA.
11 . The wireless device of claim 10 , wherein the network entity corresponds to a non 3GPP Interworking function (N3IWF).
12 . The wireless device of claim 10 , wherein the PDUs of the particular type comprises one of non-Internet Protocol PDUs, non-IP framed PDUs, non-IP raw PDUs and IP PDUs.Join the waitlist — get patent alerts
Track US2022360634A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.