IP Library › Granted Patent US 12,432,552
Granted Patent B2
US 12,432,552 · App. 18/030,895 · Granted Sep 30, 2025

Handling application functions for key management in communication device-network relay scenarios

Inventors: Monica Wifvesson (Lund, SE); Zhang Fu (Stockholm, SE); Vesa Lehtovirta (Espoo, FI)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/0433H04L9/0819H04W12/037
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,552
App. No.
18/030,895
Granted
Sep 30, 2025
Kind
B2
Abstract

A remote communication device can receive a discovery key; receive a communication key and a key identifier, ID, for the communication key; and discover a relay communication device. Discovering the relay communication device can include receiving an encrypted discovery message from the relay communication device and decrypting the encrypted discovery message using the discovery key. The remote communication device can further transmit a direct communication request to the relay communication device responsive to receiving and decrypting the encrypted discovery message from the relay communication device. The direct communication request can include the key ID for the communication key. The remote communication device can further receive an encrypted direct communication response from the relay communication device. Receiving the encrypted direct communication response can include decrypting the encrypted direct communication response.

Claims (82)

1. A method of operating a remote communication device, the method comprising:

fetching an address of an Application Function node (AF- 1 ) associated with the remote communication device from a Direct Discovery Name Management Function, DDNMF, node associated with the remote communication device;

transmitting a key request message for discovery to the Application Function node (AF- 1 ) associated with the remote communication device based on the address of the Application Function node (AF- 1 ) associated with the remote communication device, the key request message for discovery including a relay service code;

receiving a key response message for discovery including a discovery key from the Application Function node (AF- 1 ) associated with the remote communication device, the key response message for discovery being associated with the key request message for discovery;

transmitting a key request message for communication to the Application Function node (AF- 1 ) associated with the remote communication device based on the address of the Application Function node (AF- 1 ) associated with the remote communication device, the key request message for communication including the relay service code;

receiving a key response message for communication including a communication key and a key identifier, ID, for the communication key, the key response message for communication being associated with the key request message for communication;

discovering a relay communication device, wherein discovering the relay communication device includes receiving an encrypted discovery message from the relay communication device and decrypting the encrypted discovery message using the discovery key;

transmitting a direct communication request to the relay communication device responsive to receiving and decrypting the encrypted discovery message from the relay communication device, wherein the direct communication request includes the key ID for the communication key; and

receiving an encrypted direct communication response from the relay communication device, wherein receiving the encrypted direct communication response includes decrypting the encrypted direct communication response.

2. The method of claim 1 , wherein transmitting the direct communication request comprises:

encrypting the direct communication request using the discovery key to provide an encrypted direct communication request; and

transmitting the encrypted direct communication request.

3. The method of claim 1 , wherein the direct communication request includes the address of the Application Function node (AF- 1 ) associated with the remote communication device.

4. The method of claim 1 , wherein the direct communication request includes the relay service code.

5. The method of claim 1 , wherein the AF- 1 comprises a proximity service key management function, PKMF.

6. The method of claim 1 , wherein the encrypted discovery message comprises an encrypted discovery announcement message that is broadcast by the relay communication device.

7. The method of claim 1 , wherein discovering the relay communication device comprises transmitting an encrypted discovery request message that is encrypted based on the discovery key, the encrypted discovery message comprising an encrypted discovery response message corresponding to the encrypted discovery request message and the encrypted discovery response message being decrypted using the discovery key.

8. The method of claim 1 further comprising providing communication with a Radio Access Network, RAN, node using the communication key, the communication with the RAN node being relayed through the relay communication device.

9. The method of claim 8 , wherein providing the communication comprises:

encrypting the communication using the communication key to provide an encrypted communication; and

transmitting the encrypted communication to the relay communication device.

10. The method of claim 8 , wherein providing the communication comprises:

receiving an encrypted communication from the relay communication device; and

decrypting the encrypted communication using the communication key to provide the communication that is from the RAN node.

11. A method of operating a relay communication device, the method comprising:

fetching an address of an Application Function node (AF- 2 ) associated with the relay communication device from a Direct Discovery Name Management Function, DDNMF, node associated with the relay communication device;

transmitting a key request message for discovery to the Application Function node (AF- 2 ) associated with the relay communication device based on the address of the Application Function node (AF- 2 ) associated with the relay communication device, the key request message including a relay service code;

receiving a key response message for discovery including a discovery key from the Application Function node (AF- 2 ) associated with the relay communication device, the key response message for discovery being associated with the key request message for discovery;

transmitting an encrypted discovery message, the encrypted discovery message being encrypted using the discovery key;

receiving a direct communication request from a remote communication device, the direct communication request including a key identifier, ID;

obtaining a communication key corresponding to the key ID from the direct communication request; and

transmitting an encrypted direct communication response to the remote communication device, the encrypted direct communication response is encrypted using the communication key corresponding to the key ID.

12. The method of claim 11 , wherein receiving the direct communication request comprises:

receiving an encrypted direct communication request; and

decrypting the encrypted direct communication request using the discovery key to provide the direct communication request.

13. The method of claim 11 , wherein the direct communication request includes the relay service code.

14. The method of claim 11 , wherein the direct communication request includes an address of an Application Function node (AF- 1 ) associated with the remote communication device.

15. The method of claim 14 , wherein obtaining the communication key comprises:

transmitting a key request message for communication to the Application Function node (AF- 2 ) associated with the relay communication device in response to receiving the direct communication message, the key request message for communication including the key ID and the address of the Application Function node (AF- 1 ) associated with the remote communication device; and

receiving a key response message for communication from the Application Function node (AF- 2 ) associated with the relay communication device, the key response message including the communication key corresponding to the key ID.

16. The method of claim 14 , wherein obtaining the communication key comprises:

transmitting a key request message for communication to the Application Function node (AF- 1 ) associated with the remote communication device using the address of the Application Function node (AF- 1 ) associated with the remote communication device in response to receiving the direct communication message, the key request message for communication including the key ID; and

receiving a key response message for communication from the Application Function node (AF- 1 ) associated with the remote communication device, the key response message including the communication key corresponding to the key ID.

17. The method of claim 11 , wherein the Application Function node (AF- 2 ) comprises a proximity service key management function, PKMF.

18. The method of claim 11 , wherein the encrypted discovery message comprises an encrypted discovery announcement message that is broadcast by the relay communication device.

19. The method of claim 11 , further comprising receiving an encrypted discovery request message,

wherein receiving the encrypted discovery request message includes decrypting the encrypted discovery request message using discovery key,

wherein the encrypted discovery message comprises an encrypted discovery response message that is transmitted responsive to the encrypted discovery request message, and

wherein the encrypted discovery response message is encrypted using the discovery key.

20. The method of claim 11 further comprising:

relaying communication between the remote communication device and a Radio Access Network, RAN, node using the communication key for encryption between the remote communication device and the relay communication device,

wherein relaying the communication comprises at least one of:

receiving the communication as an encrypted communication from the remote communication device, decrypting the encrypted communication using the communication key, and transmitting the communication to the RAN node; and

receiving the communication from the RAN node, encrypting the communication using the communication key to provide an encrypted communication, and transmitting the encrypted communication to the remote communication device.

21. A method of operating an Application Function node (AF- 1 ) associated with a remote communication device, the method comprising:

receiving a key request message for discovery from the remote communication device, wherein the key request message for discovery includes a relay service code;

obtaining a discovery key based on the relay service code included in the key request message for discovery;

transmitting a key response message for discovery including the discovery key to the remote communication device;

receiving a key request message for communication from the remote communication device, the key request message for communication including the relay service code;

obtaining a communication key and a key identifier, ID, for the communication key based on the relay service code;

transmitting a key response message for communication to the remote communication device, the key response message including the communication key and the key ID for the communication key;

receiving a key request message, the key request message including the key ID from an Application Function node (AF- 2 ) associated with a relay communication device; and

transmitting a key response message including the communication key responsive to receiving the key request message including the key ID to the Application Function node (AF- 2 ) associated with the relay communication device responsive to receiving the key request message including the key ID.

22. The method of claim 21 , wherein obtaining the discovery key comprises deriving the discovery key internally based on the relay service code.

23. The method of claim 21 , wherein obtaining the discovery key comprises,

transmitting a key request message to the Application Function node (AF- 2 ) associated with the relay communication device responsive to receiving the key request message for discovery, the key request message including the relay service code; and

receiving a key response message from the Application Function node (AF- 2 ) associated with the relay communication device, the key response message including the discovery key,

wherein transmitting the key request message comprises forwarding the key request message for discovery, and

wherein transmitting the key response message for discovery comprises forwarding the key response message.

24. A method of operating an Application Function node (AF- 2 ) associated with a relay communication device, the method comprising:

receiving a key request message for discovery from the relay communication device, the key request message including a relay service code;

obtaining a discovery key based on the relay service code included in the key request message for discovery;

transmitting a key response message for discovery including the discovery key to the relay communication device

receiving a key request message for communication from the relay communication device, the key request message for communication including a key identifier, ID;

transmitting a key request message including the key ID to an Application Function (AF- 1 ) associated with a remote communication device;

receiving a key response message including a communication key corresponding to the key ID from the Application Function (AF- 1 ) associated with the remote communication device, the key response message corresponding to the key request message; and

transmitting a key response message for communication including the communication key to the relay communication device responsive to receiving the key response message.

25. The method of claim 24 , wherein obtaining the discovery key comprises deriving the discovery key internally based on the relay service code.

26. The method of claim 24 , further comprising:

receiving a key request message from an Application Function node (AF- 1 ) associated with the remote communication device, the key request message including the relay service code;

obtaining the discovery key based on the relay service code included in the key request message from the Application Function node (AF- 1 ) associated with the remote communication device;

transmitting a key response message including the discovery key to the Application Function node (AF- 1 ) associated with the remote communication device.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE RECEIVING PARTY IS TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) PREVIOUSLY RECORDED ON REEL 063261 FRAME 0048. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 11, 2023
From: WIFVESSON, MONICA; FU, ZHANG
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064569/0421 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE RECEIVING PARTY IS TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) PREVIOUSLY RECORDED ON REEL 063261 FRAME 0099. ASSIGNOR(S) HEREBY CONFIRMS THE LMF TO LME ASSIGNMENT. Recorded Aug 11, 2023
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064569/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: LEHTOVIRTA, VESA
To: OY L M ERICSSON AB
Reel/Frame 063260/0954 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: WIFVESSON, MONICA; FU, ZHANG
To: TELEFONAKTIEBOLAGET ERICSSON LM (PUBL)
Reel/Frame 063261/0048 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET ERICSSON LM (PUBL)
Reel/Frame 063261/0099 →
Continuity (2)
Provisional Application 63108082 · Oct 30, 2020
Related Publication 20230397000A1 · Dec 7, 2023
References Cited (13)
US 20220303254A1 · Guo · 2022 [cited by examiner]
3rd Generation Partnership Project (3GPP), TR 33.847 V0.2.0: Study on Security Aspects of Enhancement for Proximity Based Services in 5GS, Oct. 2020. 3GPP, Version 0.2.0, pp. 1-18 (Year: 2020). [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority, PCT/EP2021/079700, mailed Jan. 25, 2022, 10 pages. [cited by applicant]
3GPP TR 33.847 v0.2.0 (Oct. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enhancements for proximity based services in the 5G System (… [cited by applicant]
3GPP TS 33.303 v16.0.0 (Jul. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Proximity-based Services (ProSe); Security aspects (Release 16); 90 pages. [cited by applicant]
International Preliminary Report on Patentability of the International Preliminary Examining Authority, PCT/EP2021/079700, mailed Oct. 4, 2022, 10 pages. [cited by applicant]
3GPP TS 23.401 v16.8.0 (Sep. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; General Packet Radio Service (GPRS) enhancements for Evolved Universal Terrestrial Radio… [cited by applicant]
3GPP TS 23.501 v16.6.0 (Sep. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16); 447 pages. [cited by applicant]
3GPP TR 23.752 v0.5.0 (Sep. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on system enhancements for Proximity based Services (ProSe) in the 5G System (5GS) … [cited by applicant]
3GPP TS 33.220 v16.2.0 (Sep. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Generic Bootstrapping Architecture (GBA) (Rel… [cited by applicant]
3GPP TS 33.501 v16.4.0 (Sep. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16); 250 pages. [cited by applicant]
3GPP TS 33.535 v16.1.0 (Sep. 2020); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in t… [cited by applicant]
Ericsson, “ProSe: Key management server(s) in UE-to-network relay scenarios,” 3GPP TSG-SA-3 Meeting #101-e, S3-203373, e-meeting, Nov. 9-20, 2020, 3 pages. [cited by applicant]