IP Library › Granted Patent US 12,200,491
Granted Patent B2
US 12,200,491 · App. 16/619,268 · Granted Jan 14, 2025

Non-orthogonal signaling for radio access networks

Inventors: Noamen Ben Henda (Stockholm, SE); Peter Hedman (Helsingborg, SE); Paul Schliwa-Bertling (Ljungsbro, SE); Monica Wifvesson (Lund, SE)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04W12/102H04W76/10H04W76/30H04W92/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,200,491
App. No.
16/619,268
Granted
Jan 14, 2025
Kind
B2
Abstract

A method to operate a UE for handling security policy for user plane protection of communications in a communications system is provided. The method includes transmitting a packet data unit (PDU) session establishment request network access stratum (NAS) message toward an Access and Mobility Management Function (AMF) to establish a PDU session. The method further includes receiving an access network (AN) specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session.

Claims (75)

1. A user equipment (UE) for handling security policy for user plane protection of communications in a communications system, the UE comprising:

a transceiver configured to transmit and receive through a wireless air interface with an access node (AN) of the communications system; and

at least one processor connected to the transceiver and configured to perform operations comprising:

transmitting through the transceiver a packet data unit (PDU) session establishment request network access stratum (NAS) message toward an Access and Mobility Management Function (AMF) to establish a PDU session;

receiving through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session;

summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and

adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

2. The UE of claim 1 , wherein

generation of the session consumed DRB-IP rate comprises not including in the summing any DRB-IP rates that are allocated for DRBs of the PDU session that are not indicated by the AN specific resource setup message for the UE to activate integrity protection.

3. The UE of claim 1 , wherein:

when the PDU session will be the only active PDU session between the UE and the AN, the adjustment of the available DRB-IP rate of the UE comprises determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and the session consumed DRB-IP rate, wherein the maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

4. The UE of claim 1 , further comprising:

before transmitting the PDU session establishment request NAS message toward the AMF and when the UE does not have an active PDU session with the AN which has DRBs for which the UE provides integrity protection, adding an indication of a maximum DRB-IP rate of the UE to the PDU session establishment request NAS message that is transmitted toward the AMF to establish a PDU session.

5. The UE of claim 1 , wherein:

when the PDU session is one of a plurality of active PDU sessions between the UE and the AN, the adjustment of the available DRB-IP rate of the UE comprises determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and a summation of the session consumed DRB-IP rates that have been generated for each of the active PDU sessions, wherein the maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions.

6. The UE of claim 1 , further comprising:

following the adjustment of the available DRB-IP rate of the UE, adding the available DRB-IP rate of the UE to another PDU session establishment request NAS message that is transmitted toward the AMF to establish another PDU session;

receiving through the transceiver another AN specific resource setup message indicating whether the UE is to activate integrity protection for DRBs serving the another PDU session;

summing DRB-IP rates that are allocated for the DRBs of the another PDU session that are indicated by the another AN specific resource setup message for the UE to activate integrity protection, to generate another session consumed DRB-IP rate; and

further adjusting the available DRB-IP rate of the UE based on a difference between the available DRB-IP rate of the UE and the another session consumed DRB-IP rate.

7. The UE of claim 1 , further comprising:

responsive to releasing the PDU session, increasing the available DRB-IP rate of the UE based on the session consumed DRB-IP rate of the PDU session.

8. A method by a user equipment (UE) for handling security policy for user plane protection of communications in a communications system, the method comprising:

transmitting a packet data unit (PDU) session establishment request network access stratum (NAS) message toward an Access and Mobility Management Function (AMF) to establish a PDU session;

receiving an access node (AN) specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session;

summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and

adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

9. A communications system comprising:

an Access and Mobility Management Function (AMF) of the communications system, the AMF comprising:

a network interface configured to communicate with user equipments (UEs) via a network and an access node (AN) of the communications system, and to communicate with a Session Management Function (SMF) of the communications system; and

at least one processor configured to perform operations comprising:

receiving a packet data unit (PDU) session establishment request network access stratum (NAS) message from a UE requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established;

communicating toward the SMF a PDU session create message containing the indication of the available DRB-IP rate;

receiving a SMF message containing an indication of a user plane (UP) security policy for a PDU session being established; and

communicating a message containing the indication of the UP security policy to an access node (AN) that is communicating through a wireless air interface with the UE; and

the UE comprising:

a transceiver configured to transmit and receive through a wireless air interface with an access node (AN) of the communications system; and

at least one processor connected to the transceiver and configured to perform operations comprising:

receiving through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session;

summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and

adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

10. A method by a communications system, the method comprising:

at an Access and Mobility Management Function (AMF):

receiving a packet data unit (PDU) session establishment request network access stratum (NAS) message from a user equipment (UE) requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established;

communicating toward a Session Management Function (SMF) a PDU session create message containing the indication of the available DRB-IP rate of the UE;

receiving a SMF message containing an indication of a user plane (UP) security policy for a PDU session being established; and

communicating a message containing the indication of the UP security policy to an access node (AN) that is communicating through a wireless air interface with the UE; and

at the UE:

receiving an access node (AN) specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session;

summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and

adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

11. A communications system comprising:

a Session Management Function (SMF) of the communications system, the SMF comprising:

a network interface configured to communicate with an Access and Mobility Management Function (AMF) of the communications system; and

at least one processor configured to perform operations comprising:

receiving from the AMF a packet data unit (PDU) session create message for a user equipment (UE) that is requesting establishment of a PDU session, the PDU session create message containing an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established;

determining a user plane (UP) security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity; and

communicating to the AMF a message containing an indication of the UP security policy for the PDU session being established; and

the UE comprising:

a transceiver configured to transmit and receive through a wireless air interface with an access node (AN) of the communications system; and

at least one processor connected to the transceiver and configured to perform operations comprising:

receiving through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session;

summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and

adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

12. The SMF of claim 11 , wherein the determination of the UP security policy for the PDU session comprises determining whether the UE is to actively use integrity protection for at least some of the DRBs the UE will use for communication in the PDU session being established.

13. A method by a communications system, the method comprising:

a Session Management Function (SMF):

receiving from an Access and Mobility Management Function (AMF) a packet data unit (PDU) session create message for a user equipment (UE) that is requesting establishment of a PDU session, the PDU session create message containing an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available capacity for processing DRBs that are integrity protected for the PDU session being established;

determining a user plane (UP) security policy for the PDU session based on the indication of the available DRB-IP rate for which the UE presently has available capacity; and

communicating to the AMF a message containing an indication of the UP security policy for the PDU session being established; and

at the UE:

receiving an access node (AN) specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session;

summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and

adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate.

14. The method of claim 13 , wherein the determination of the UP security policy for the PDU session comprises determining whether the UE is to actively use integrity protection for at least some of the DRBs the UE will use for communication in the PDU session being established.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2024
From: BEN HENDA, NOAMEN; HEDMAN, PETER; SCHLIWA-BERTLING, PAUL; WIFVESSON, MONICA
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 068581/0168 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2019
From: BEN HENDA, NOAMEN; HEDMAN, PETER; SCHLIWA-BERTLING, PAUL; WIFVESSON, MONICA
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 051176/0608 →
Continuity (2)
Provisional Application 62653794 · Apr 6, 2018
Related Publication 20240284178A1 · Aug 22, 2024
References Cited (24)
US 11606682B2 · Ben Henda · 2023 [cited by examiner]
US 20110188408A1 · Yi et al. · 2011 [cited by applicant]
US 20200322804A1 · Vutukuri · 2020 [cited by examiner]
US 20210084130A1 · Dai · 2021 [cited by examiner]
US 20210127254A1 · Ben Henda · 2021 [cited by examiner]
US 20220038878A1 · Jung · 2022 [cited by examiner]
AU 2019249939B2 · 2019 [cited by applicant]
CN 105557062A · 2016 [cited by applicant]
CN 111149379A · 2020 [cited by examiner]
KR 1020170038096A · 2017 [cited by applicant]
KR 1020180030023A · 2018 [cited by applicant]
WO WO2019193147A1 · 2019 [cited by examiner]
ZTE, “Guarantee the UE Max Data Rate for Integrity Protection”, 3GPP TSG-RAN WG3 #99bis. R3-181691, Apr. 16-20, 2018, Sanya, China. [cited by applicant]
ZTE Corporation, 51342362A1, Consideration of UP Integrity Configuration, 3GPP TSG-RAN WG2 Meeting #99bis, R2-1710314, Prague, Czech Republic, Oct. 9-13, 2017, 3 pages. [cited by applicant]
Office Action, Including English Summary, for Argentinian Patent Application N° P190100916, mailed Nov. 4, 2022, 7 pages. [cited by applicant]
International Search Report and Written Opinion mailed May 31, 2019 for International Application No. PCT/SE2019/058622, 11 pages. [cited by applicant]
ZTE, 51416603A1, Guarantee the UE Max Data Rate for Integrity Protection, 3GPP TSG-RAN WG3 #99bis, R3-181691, Sanya, China, Apr. 16-20, 2018, 7 Pages. [cited by applicant]
ZTE Corporation, 51342362A1, Consideration of UP Integrity Configuration, 3GPP TSG-RAN WG2 Meeting #99bis, R2-1713014, Prague, Czech Republic, Oct. 9-13, 2017, 3 pages. [cited by applicant]
ZTE Corporation, Sanechips, 51399817A1, Framework for DRB Integrity Protection, 3GPP TSG-RAN WG2 Meeting #101, Athens, Greece, Feb. 26-Mar. 2, 2018, 3 pages. [cited by applicant]
3GPP TR 33.899 V1.3.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the security aspects of the next generation system (Release 14)”, 3GPP TR 33.899 V1.3.0, Au… [cited by applicant]
3GPP TS 33.501 V15.0.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15)”, 3GPP TS 33.501 V15.0.0, Mar. 2018. [cited by applicant]
ZTE Corporation, Sanechips. “Framework for DRB integrity protection.” 3GPP TSG RAN WG2 #101 R2-1802049, Mar. 2, 2018. [cited by applicant]
Japanese Notice of Reasons for Rejection, Japanese Application No. 2020-553544, mailed Oct. 26, 2021, 7 pages. [cited by applicant]
Korean Notice of Allowance, Korean Patent Application No. 2020-7029034, mailed Nov. 25, 2021, 5 pages. [cited by applicant]