IP Library › Granted Patent US 11,606,682
Granted Patent B2
US 11,606,682 · App. 17/041,710 · Granted Mar 14, 2023

AMF controlled handling of the security policy for user plane protection in 5G systems

Inventors: Noamen Ben Henda (Vällingby, SE); Peter Hedman (Helsingborg, SE); Paul Schliwa-Bertling (Ljungsbro, SE); Monica Wifvesson (Lund, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W8/08H04W12/106H04W48/16H04W60/00H04W76/25H04W92/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,606,682
App. No.
17/041,710
Granted
Mar 14, 2023
Kind
B2
Abstract

A method of operating an Access and Mobility Management Function (AMF) of a communications system that includes an access node (AN) configured to communicate through a wireless air interface with user equipments (UEs) and that has a Session Management Function (SMF), is provided. The method includes receiving an indication of a Max Data Radio Bearer Integrity Protection, DRB-IP, rate indicating a maximum computational capacity of the UE to process DRBs that have integrity protection during Packet Data Unit (PDU) sessions. A PDU session establishment request NAS message is received from the UE for establishing a PDU session. A PDU session create message is communicated toward the SMF. A SMF message is received that contains an indication of an allocated DRB-IP rate for DRBs that are to be integrity protected for a PDU session being established.

Claims (60)

1. An Access and Mobility Management Function, AMF, apparatus of a communications system that comprises an access node, AN, configured to communicate through a wireless air interface with user equipment, UEs, and that comprises a Session Management Function, SMF, the AMF comprising:

at least one processor configured to perform operations comprising:

receiving an indication of a Max Data Radio Bearer Integrity Protection, DRB-IP, rate indicating a maximum computational capacity of the UE to process DRBs that have integrity protection during protocol data unit, PDU, sessions;

receiving a protocol data unit, PDU, session establishment request non-access stratum, NAS, message from the UE for establishing a PDU session;

communicating a PDU session create message toward the SMF; and

receiving a SMF message containing an indication of an allocated DRB-IP rate for DRBs that are to be integrity protected for a PDU session being established,

wherein adjusting the available DRB-IP rate of the UE based on the Max DRB-IP rate and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established, comprises:

adjusting the available DRB-IP rate of the UE based on a determined difference between the Max DRB-IP rate of the UE and a summation of at least both the DRB-IP rates of flows in any existing PDU sessions that are to be integrity protected by the UE and which are known to the AMF and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established.

2. The AMF of claim 1 , wherein the at least one processor is configured to perform operations further comprising:

communicating a message toward the AN that is communicating with the UE, the message containing the indication of the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established; and

adjusting an available DRB-IP rate of the UE based on the Max DRB-IP rate and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established.

3. The AMF of claim 1 , wherein:

the Max DRB-IP rate is received from the UE as part of an initial UE registration procedure.

4. The AMF of claim 1 , wherein the at least one processor is configured to perform operations further comprising:

before the communication of the PDU session create message toward the SMF, determining the available DRB-IP rate for which the UE has available capacity for processing DRBs that are integrity protected for the PDU session being established, based on a determined difference between the Max DRB-IP rate of the UE and a summation of DRB-IP rates of flows in any existing PDU sessions that are to be integrity protected by the UE and which are known to the AMF; and

adding the available DRB-IP rate of the UE to the PDU session create message communicated toward the SMF.

5. The AMF of claim 1 , wherein:

the PDU session create message communicated toward the SMF comprises a Namf_PDUSession_CreateSMContext Request message containing the indication of the available DRB-IP rate of the UE; and

the received SMF message comprises a Namf_Communication_N1N2MessageTransfer Request message containing the indication of the allocated DRB-IP rate for the DRBs that are to be integrity protected for the PDU session being established.

6. The AMF of claim 1 , wherein the at least one processor is configured to perform operations further comprising:

subsequent to the adjustment of the available DRB-IP rate of the UE based on the determined difference, receiving another PDU session establishment request NAS message from the UE for establishing another PDU session;

communicating another PDU session create message toward the SMF for the another PDU session being established;

receiving another SMF message containing an indication of another allocated DRB-IP rate for DRBs that are to be integrity protected for the another PDU session being established;

adjusting the available DRB-IP rate of the UE based on a determined difference between the Max DRB-IP rate of the UE and a summation of at least the DRB-IP rates of flows in any existing PDU sessions that are to be integrity protected by the UE and which are known to the AMF and the another allocated DRB-IP rate for DRBs that are to be integrity protected for the another PDU session being established; and

communicating another message toward the AN that is communicating with the UE, the another message containing the indication of the another allocated DRB-IP rate for DRBs that are to be integrity protected for the another PDU session being established.

7. The AMF of claim 6 , wherein the at least one processor is configured to perform operations further comprising:

adding to the another PDU session create message communicated toward the SMF, the available DRB-IP rate of the UE that is adjusted based on the determined difference between the Max DRB-IP rate of the UE and the summation of at least both the DRB-IP rates of flows in any existing PDU sessions that are to be integrity protected by the UE and which are known to the AMF and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established.

8. The AMF of claim 1 , where the adjustment of the available DRB-IP rate of the UE is performed after communication of the message toward the AN, and comprises:

receiving from the AN a response message containing an indication of a consumed DRB-IP rate for DRBs that are assigned to the UE by the AN for the PDU session being established and which are to be integrity protected; and

adjusting the available DRB-IP rate of the UE based on a determined difference between the Max DRB-IP rate of the UE and a summation of at least both the DRB-IP rates of flows in any existing PDU sessions that are to be integrity protected by the UE and which are known to the AMF and the consumed DRB-IP rate.

9. The AMF of claim 1 , where the adjustment of the available DRB-IP rate of the UE is performed by operations occurring before and after communication of the message toward the AN, and comprises:

adjusting the available DRB-IP rate of the UE based on the Max DRB-IP rate and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established;

receiving from the AN a response message containing an indication of a consumed DRB-IP rate for DRBs that are assigned to the UE by the AN for the PDU session being established and which are to be integrity protected; and

further adjusting the available DRB-IP rate of the UE based on a difference between the allocated DRB-IP rate and the consumed DRB-IP rate.

10. The AMF of claim 1 , further comprising:

constraining the allocated DRB-IP rate that is indicated in the message communicated toward the AN to not exceed the available DRB-IP rate of the UE.

11. The AMF of claim 1 , wherein the at least one processor is configured to perform operations further comprising:

receiving a PDU session release request NAS message from the UE to release the PDU session that has been established; and

communicating with the SMF to receive an indication of the DRB-IP rate that was allocated to the PDU session.

12. The AMF of claim 11 , further comprising:

increasing the available DRB-IP rate of the UE based on the DRB-IP rate that was allocated to the PDU session.

13. The AMF of claim 11 , wherein the at least one processor is configured to perform operations further comprising:

responsive to receipt of the PDU session release request NAS message, communicating a N2 resource release request to release resources of the PDU session.

14. The AMF of claim 13 , wherein the at least one processor is configured to perform operations further comprising:

receiving from the AN, a resource release acknowledgement message containing an indication of a DRB-IP rate that was allocated to the PDU session that is being released.

15. A method for an Access and Mobility Management Function, AMF, of a communications system that comprises an access node, AN, configured to communicate through a wireless air interface with user equipments, UEs, and that comprises a Session Management Function, SMF, the method comprising:

receiving an indication of a Max Data Radio Bearer Integrity Protection, DRB-IP, rate indicating a maximum computational capacity of the UE to process DRBs that have integrity protection during protocol data unit, PDU, sessions;

receiving a protocol data unit, PDU, session establishment request non-access stratum, NAS, message from the UE for establishing a PDU session;

communicating a PDU session create message toward the SMF;

receiving a SMF message containing an indication of an allocated DRB-IP rate for DRBs that are to be integrity protected for a PDU session being established; and

before the communication of the PDU session create message toward the SMF, determining the available DRB-IP rate for which the UE has available capacity for processing DRBs that are integrity protected for the PDU session being established, based on a determined difference between the Max DRB-IP rate of the UE and a summation of DRB-IP rates of flows in any existing PDU sessions that are to be integrity protected by the UE and which are known to the AMF; and

adding the available DRB-IP rate of the UE to the PDU session create message communicated toward the SMF.

16. The method of claim 15 , further comprising:

communicating a message toward the AN that is communicating with the UE, the message containing the indication of the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established; and

adjusting an available DRB-IP rate of the UE based on the Max DRB-IP rate and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established.

17. The method of claim 15 , wherein:

the PDU session create message communicated toward the SMF comprises a Namf_PDUSession_CreateSMContext Request message containing the indication of the available DRB-IP rate of the UE; and

the received SMF message comprises a Namf_Communication_N1N2MessageTransfer Request message containing the indication of the allocated DRB-IP rate for the DRBs that are to be integrity protected for the PDU session being established,

wherein adjusting the available DRB-IP rate of the UE based on the Max DRB-IP rate and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established, comprises:

adjusting the available DRB-IP rate of the UE based on a determined difference between the Max DRB-IP rate of the UE and a summation of at least both the DRB-IP rates of flows in any existing PDU sessions that are to be integrity protected by the UE and which are known to the AMF and the allocated DRB-IP rate for DRBs that are to be integrity protected for the PDU session being established.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2020
From: BEN HENDA, NOAMEN; HEDMAN, PETER; SCHLIWA-BERTLING, PAUL; WIFVESSON, MONICA
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 054306/0541 →
Continuity (2)
Provisional Application 62654611 · Apr 9, 2018
Related Publication 20210127254A1 · Apr 29, 2021
Cited By (1)
US 12,200,491