IP Library › Granted Patent US 12,425,845
Granted Patent B2
US 12,425,845 · App. 18/576,625 · Granted Sep 23, 2025

Security communication in ProSe U2N relay

Inventors: Jing Ping (Chengdu, CN); Suresh Nair (Estero, FL)
Assignee: Nokia Technologies Oy
H04W12/03H04W12/08H04W40/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,845
App. No.
18/576,625
Granted
Sep 23, 2025
Kind
B2
Abstract

Embodiments of the present disclosure relate to security communication in ProSe U2N relay. According to one aspect of the present disclosure, remote UE and relay UE receive a configuration comprising at least a set of indicators of a CP based security procedure or a UP based security procedure for a set of relay services. Based on an indicator for a relay service in the set of indicators, the remote UE and relay UE performs one of the CP based security procedure or the UP based security procedure for a communication between the remote UE and the relay UE for the relay service. In this way, remote UE and remote UE may correctly trigger a security procedure for U2N relay communication.

Claims (44)

1. A first device comprising:

at least one processor; and

at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the first device to:

perform service authorization and provisioning with a network to be authorized by the network to receive a relay service, and to receive security policies provisioned by the network including a control plane based security indicator to perform a control plane based security procedure for the relay service;

perform a discovery procedure for the relay service to select a second device for the relay service that supports the control plane based security procedure according to authorization information of the first device provisioned by the network, and a security procedure indicator of relay services announced by the second device indicating that the second device supports the control plane based security procedure; and

perform, based on the control plane based security indicator for the relay service, the control plane based security procedure to protect direct communications between the first device and the second device for the relay service;

wherein the first device is remote user equipment, the second device is relay user equipment, and the first device is provisioned with the control plane based security indicator by a core network element or a proximity-based service application server.

2. The first device of claim 1 , wherein:

the control plane based security indicator is provisioned by the network in a relay service code of the relay service.

3. The first device of claim 2 , wherein:

the control plane based security indicator is included in security parameters of the relay service code.

4. The first device of claim 1 , wherein the core network element is a policy control function or a proximity-based service key management function for the remote user equipment.

5. A second device comprising:

at least one processor; and

at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the second device to:

perform service authorization and provisioning with a network to be authorized by the network to provide a relay service, and to receive security policies provisioned by the network including a control plane based security indicator to perform a control plane based security procedure for the relay service;

perform a discovery procedure for the relay service by announcing the relay service and the control plane based security indicator indicating that the second device supports the control plane based security procedure for the relay service; and

in response to receiving a communication request from a first device for the relay service, perform, based on the control plane based security indicator for the relay service, the control plane based security procedure to protect direct communications between the first device and the second device for the relay service;

wherein the first device is remote user equipment, the second device is relay user equipment, and the second device is provisioned with the control plane based security indicator by a core network element or a proximity-based service application server.

6. The second device of claim 5 , wherein:

the control plane based security indicator is provisioned by the network in a relay service code of the relay service.

7. The second device of claim 6 , wherein:

the control plane based security indicator is included in security parameters of the relay service code.

8. The second device of claim 5 , wherein the core network element is a policy control function or a proximity-based service key management function for the relay user equipment.

9. A method of communication, comprising:

performing, at a first device, service authorization and provisioning with a network to be authorized by the network to receive a relay service, and to receive security policies provisioned by the network including a control plane based security indicator to perform a control plane based security procedure for the relay service;

performing, at the first device, a discovery procedure for the relay service to select a second device for the relay service that supports the control plane based security procedure according to authorization information of the first device provisioned by the network, and a security procedure indicator of relay services announced by the second device indicating that the second device supports the control plane based security procedure; and

performing, based on the control plane based security indicator for the relay service, the control plane based security procedure at the first device to protect direct communications between the first device and the second device for the relay service;

wherein the first device is remote user equipment, the second device is relay user equipment, and the first device is provisioned with the control plane based security indicator by a core network element or a proximity-based service application server.

10. The method of claim 9 , wherein:

the control plane based security indicator is provisioned by the network in a relay service code of the relay service.

11. The method of claim 10 , wherein:

the control plane based security indicator is included in security parameters of the relay service code.

12. The method of claim 9 , wherein the core network element is a policy control function or a proximity-based service key management function for the remote user equipment.

13. A method of communication, comprising:

performing, at a second device, service authorization and provisioning with a network to be authorized by the network to provide a relay service, and to receive security policies provisioned by the network including a control plane based security indicator to perform a control plane based security procedure for the relay service;

performing, at the second device, a discovery procedure for the relay service by announcing the relay service and the control plane based security indicator indicating that the second device supports the control plane based security procedure for the relay service; and

in response to receiving a communication request from a first device for the relay service, performing, based on the control plane based security indicator for the relay service, the control plane based security procedure at the second device to protect direct communications between the first device and the second device for the relay service;

wherein the first device is a remote user equipment, the second device is a relay user equipment, and the second device is provisioned with the control plane based security indicator by a core network element or a proximity-based service application server.

14. The method of claim 13 , wherein:

the control plane based security indicator is provisioned by the network in a relay service code of the relay service.

15. The method of claim 14 , wherein:

the control plane based security indicator is included in security parameters of the relay service code.

16. The method of claim 13 , wherein the core network element is a policy control function or a proximity-based service key management function for the relay user equipment.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2024
From: NAIR, SURESH
To: NOKIA OF AMERICA CORPORATION
Reel/Frame 066292/0701 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2024
From: PING, JING
To: NOKIA SOLUTIONS AND NETWORKS SYSTEM TECHNOLOGY (BEIJING) CO., LTD.
Reel/Frame 066292/0855 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2024
From: NOKIA OF AMERICA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 066292/0924 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2024
From: NOKIA SOLUTIONS AND NETWORKS SYSTEM TECHNOLOGY (BEIJING) CO., LTD.
To: NOKIA TECHNOLOGIES OY
Reel/Frame 066292/0985 →
Continuity (1)
Related Publication 20240314551A1 · Sep 19, 2024
References Cited (9)
US 20210345104A1 · Cheng · 2021 [cited by examiner]
US 20220109996A1 · Lee · 2022 [cited by examiner]
CN 113748619A · 2021 [cited by applicant]
WO 2021212260A1 · 2021 [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security Aspects of Proximity based Services (ProSe) in the 5G System (5GS (Release 17)”, 3GPP TS 33.503, V0.3.0, Mar. 2022… [cited by applicant]
“IEEE 802.11”, Wikipedia, Retrieved on Feb. 26, 2024, Webpage available at : https://en.wikipedia.org/wiki/IEEE_802.11. [cited by applicant]
International Search Report and Written Opinion received for corresponding Patent Cooperation Treaty Application No. PCT/CN2022/091498, dated Dec. 16, 2022, 9 pages. [cited by applicant]
“ProSe: New Solution for Key Issue #3”, 3GPP TSG-SA3 Meeting #104-e, S3-212967, Agenda: 5.9, Xiaomi, Aug. 16-27, 2021, 4 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Proximity based Services (ProSe) in the 5G System (5GS) (Release 17)”, 3GPP TS 23.304, V17.3.0, Jun. 2022, pp. 1-105. [cited by applicant]