U2N RELAY (UP) PC5 LINK SETUP SECURITY WHEN USING GBA PUSH
A relay WTRU may receive, from a remote WTRU, a request for connection that includes a PRUK ID. The relay WTRU may transmit, to a PKMF associated with the relay WTRU, a key request message that includes the PRUK ID. The relay WTRU may receive, from the PKMF associated with the relay WTRU, a key response message that includes a GPI. The relay WTRU may transmit, to the remote WTRU, a direct security mode command message that includes the GPI. The relay WTRU may receive, from the remote WTRU, a direct security mode complete message. The relay WTRU may transmit, to the PKMF associated with the relay WTRU, a PRUK confirmation message. The relay WTRU, may receive, from the PKMF associated with the relay WTRU, an acknowledgement that the PRUK confirmation message was received, and transmit, to the second WTRU, an acceptance of the request for connection.
1 . A method performed by a first wireless transmit/receive unit (WTRU), the method comprising:
receiving, from a second WTRU, a request for connection, wherein the request for connection includes a proximity service (ProSe) remote user key (PRUK) ID;
transmitting, to a ProSe Key Management Function (PKMF) associated with the first WTRU, a key request message that includes the PRUK ID received from the second WTRU;
receiving, from the PKMF associated with the first WTRU, a key response message that includes generic bootstrapping architecture (GBA) push information (GPI);
if the GPI is received from the PKMF associated with the first WTRU, transmitting, to the second WTRU, a direct security mode command message that includes the GPI;
receiving, from the second WTRU, a direct security mode complete message; and
if the direct security mode complete message is received from the second WTRU, transmitting, to the PKMF associated with the first WTRU, a PRUK confirmation message, wherein the PRUK confirmation message includes the PRUK ID.
2 . The method of claim 1 , further comprising:
validating the direct security mode complete message.
3 . The method of claim 1 , further comprising:
receiving, from the PKMF associated with the first WTRU, an acknowledgement that the PRUK confirmation message was received; and
transmitting, to the second WTRU, an acceptance of the request for connection.
4 . The method of claim 1 , wherein the request for connection is a Direct Communication Request message.
5 . The method of claim 1 , wherein the key request message includes a relay service code (RSC) and K NRP freshness parameter 1.
6 . The method of claim 1 , wherein the direct security mode command message includes a K NRP freshness parameter 2.
7 . A first wireless transmit receive unit (WTRU), comprising:
a transceiver; and
a processor;
wherein the transceiver and processor are configured to:
receiving, from a second WTRU, a request for connection, wherein the request for connection includes a proximity service (ProSe) remote user key (PRUK) ID;
transmit, to a ProSe Key Management Function (PKMF) associated with the first WTRU, a key request message that includes the PRUK ID received from the second WTRU;
receive, from the PKMF associated with the first WTRU, a key response message that includes generic bootstrapping architecture (GBA) push information (GPI);
if the GPI is received from the PKMF associated with the first WTRU, transmit, to the second WTRU, a direct security mode command message that includes the GPI;
receive, from the second WTRU, a direct security mode complete message; and
if the direct security mode complete message is received from the second WTRU, transmit, to the PKMF associated with the first WTRU, a PRUK confirmation message, wherein the PRUK confirmation message includes the PRUK ID.
8 . The first WTRU of claim 7 , wherein the transceiver and processor are further configured to:
validate the direct security mode complete message.
9 . The first WTRU of claim 7 , wherein the transceiver and processor are further configured to:
receive, from the PKMF associated with the first WTRU, an acknowledgement that the PRUK confirmation message was received; and
transmit, to the second WTRU, an acceptance of the request for connection.
10 . The first WTRU of claim 7 , wherein the request for connection is a Direct Communication Request message.
11 . The first WTRU of claim 7 , wherein the key request message includes a relay service code (RSC) and K NRP freshness parameter 1.
12 . The first WTRU of claim 7 , wherein the direct security mode command message includes a K NRP freshness parameter 2.
13 . A first wireless transmit/receive unit (WTRU), comprising:
a transceiver; and
a processor;
wherein the transceiver and processor are configured to:
transmit, to a second WTRU, a request for connection that includes a first proximity service (ProSe) remote user key (PRUK) ID associated with a PRUK;
receive, from the second WTRU, a connection reject message that includes a cause code;
determine, based on the cause code, that the PRUK is out of sync with a proximity service (ProSe) Key Management Function (PKMF) associated with the first WTRU;
transmit, to the second WTRU, a connection request message that includes a subscription concealed identifier (SUCI).
14 . The first WTRU of claim 13 , wherein the cause code indicates that the PRUK ID is invalid.
15 . The first WTRU of claim 13 , wherein the request for connection is a Direct Communication Request message.