IP Library › Granted Patent US 12,457,114
Granted Patent B2
US 12,457,114 · App. 18/031,183 · Granted Oct 28, 2025

Relay UE and remote UE authorization

Inventors: Zhang Fu (Stockholm, SE); Monica Wifvesson (Lund, SE); Shabnam Sultana (Montreal, CA); Juying Gan (Shanghai, CN)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L9/3247H04L9/3213H04W12/06H04W16/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,114
App. No.
18/031,183
Granted
Oct 28, 2025
Kind
B2
Abstract

A method performed by a relay UE for determining whether the relay UE may provide a relay service to a remote UE. The method includes the relay UE receiving from the remote UE a first message comprising a first authorization token and a first digital signature for verifying the authenticity of the first authorization token, wherein the first digital signature was generated by a first network function using the first authorization token and a first key, and the first authorization token indicates whether or not the remote UE is authorized to utilize a relay service provided by the relay UE. The method further includes the relay UE verifying the authenticity of the first authorization token.

Claims (51)

1. A method performed by a relay user equipment (UE) for determining whether the relay UE is authorized to provide a relay service to a remote UE, the method comprising:

the relay UE receiving from the remote UE a first message comprising a first authorization token and a first digital signature for verifying the authenticity of the first authorization token, wherein the first digital signature was generated by a first network function implemented in a network using the first authorization token and a first key, and the first authorization token indicates whether or not the remote UE is authorized to utilize a relay service provided by the relay UE;

the relay UE verifying the authenticity of the first authorization token; and

the relay UE transmitting to the remote UE a second message comprising a second authorization token and a second digital signature for verifying the authenticity of the second authorization token, wherein

the second digital signature was generated by a second network function implemented in the network or the first network function, and

the second authorization token indicates that the relay UE is authorized to provide a relay service to the remote UE.

2. The method of claim 1 , wherein the second digital signature was generated using the first key.

3. The method of claim 1 , further comprising:

prior to the relay UE transmitting to the remote UE the second message comprising the second authorization token, the relay UE receiving a third message comprising the second authorization token and the second digital signature.

4. The method of claim 1 , wherein the first authorization token further includes one or more of the following:

information specifying a time at which the first authorization token expires,

a UE identifier associated with the remote UE or with a group of UEs that includes the remote UE,

relay type information identifying a type of relay UE that the remote UE is authorized to utilize,

layer information indicating whether the remote UE supports layer-2 relaying and/or layer-3 relaying,

location information identifying one or more geographical areas, or

quality-of-service (QOS) information.

5. The method of claim 1 , wherein the step of verifying the authenticity of the first authorization token comprises the relay UE requesting a network function to verify the authenticity of the first authorization token.

6. The method of claim 1 , wherein

the first authorization token comprises a UE identifier that identifies a particular UE, and the method further comprises the relay UE determining whether the remote UE is the particular UE identified by the UE identifier, or

the first authorization token comprises a UE identifier that identifies a group of UEs, and the method further comprises the relay UE determining whether the remote UE is included in the group of UEs identified by the UE identifier.

7. A method performed by a remote user equipment (UE) for determining whether a relay UE is authorized to provide a relay service to the remote UE, the method comprising:

the remote UE receiving from the relay UE a first message comprising a first authorization token and a first digital signature for verifying the authenticity of the first authorization token, wherein the first digital signature was generated by a first network function implemented in a network using the first authorization token and a first key, and the first authorization token indicates whether or not the relay UE is authorized to provide a relay service to the remote UE; and

the remote UE verifying the authenticity of the first authorization token; and

the remote UE transmitting to the relay UE a second message comprising a second authorization token and a second digital signature for verifying the authenticity of the second authorization token, wherein

the second digital signature was generated by a second network function implemented in the network or the first network function, and

the second authorization token indicates that the remote UE is authorized to utilize a relay service provided by the relay UE.

8. The method of claim 7 , wherein the second digital signature was generated using the first key.

9. The method of claim 7 , further comprising:

prior to the remote UE transmitting to the relay UE the second message comprising the second authorization token, the remote UE receiving a third message comprising the second authorization token and the second digital signature.

10. The method of claim 7 , wherein the first authorization token further includes one or more of the following:

information specifying a time at which the first authorization token expires,

a UE identifier associated with the relay UE or with a group of UEs that includes the relay UE,

service types that the relay UE supports,

application types that the relay UE supports,

traffic types that the relay UE supports,

remote UE type information identifying a type of remote UE that the relay UE is authorized to serve,

layer information indicating whether the relay UE supports layer-2 relaying and/or layer-3 relaying,

a list of one or more Public Land Mobile Network (PLMN) identifies identifying PLMN that the relay is authorized to access,

location information identifying one or more geographical areas, or

quality-of-service information.

11. The method of claim 7 , wherein the step of verifying the authenticity of the first authorization token comprises the remote UE requesting a network function to verify the authenticity of the first authorization token.

12. The method of claim 7 , wherein

the first authorization token comprises a UE identifier that identifies a particular UE, and the method further comprises the remote UE determining whether the relay UE is the particular UE identified by the UE identifier, or

the first authorization token comprises a UE identifier that identifies a group of UEs, and the method further comprises the remote UE determining whether the relay UE is included in the group of UEs identified by the UE identifier.

13. A method performed by a first network node, the method comprising:

receiving a first request message; and

transmitting a first response message responsive to the first request message, wherein

the first response message comprises an authorization token and a digital signature for verifying the authenticity of the authorization token,

the digital signature was generated using a first key, and

the authorization token indicates at least one of: i) that a user equipment (UE) is authorized to utilize a relay service provided by one or more relay UEs or ii) that the UE is authorized to provide a relay service to one or more remote UEs.

14. The method of claim 13 , wherein the first response message further comprises a second key that is paired with the first key, which second key can be is used to verify the authenticity of the authorization token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2023
From: FU, ZHANG; WIFVESSON, MONICA; SULTANA, SHABNAM; GAN, JUYING
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064235/0945 →
Priority Claims (1)
WO PCT/CN2020/120324 · Oct 12, 2020 · international
Continuity (1)
Related Publication 20230379168A1 · Nov 23, 2023
References Cited (20)
US 8417949B2 · Zhang · 2013 [cited by examiner]
US 11678016B1 · Antony · 2023 [cited by examiner]
US 20170195407A1 · Miura · 2017 [cited by examiner]
US 20180375647A1 · Yan · 2018 [cited by examiner]
US 20200100088A1 · Kim et al. · 2020 [cited by applicant]
WO WO2015171750A1 · 2015 [cited by examiner]
WO WO2018031343A1 · 2018 [cited by examiner]
International Search Report and Written Opinion issued in International Application No. PCT/IB2021/059294 dated Dec. 22, 2021 (10 pages). [cited by applicant]
International Preliminary Report on Patentability issued in International Application No. PCT/IB2021/059294 dated Mar. 10, 2023 (26 pages). [cited by applicant]
Hardt, D., “The OAuth 2.0 Authorization Framework”, Internet Engineering Task Force (IETF), Request for Comments (RFC) 6749, Microsoft, Oct. 2012 (76 pages). [cited by applicant]
3GPP TS 23.303 V15.1.0 (Jun. 2018), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Proximity-based services (ProSe); Stage 2 (Release 15), Jun. 2018 (130 pages). [cited by applicant]
3GPP TS 23.287 V17.0.0 (Jun. 2021), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Architecture enhancements for 5G System (5GS) to support Vehicle-to-Everything (V2X) ser… [cited by applicant]
3GPP TR 23.752 V17.0.0 (Mar. 2021), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on system enhancement for Proximity based Services (ProSe) in the 5G System (5GS) … [cited by applicant]
3GPP TR 23.752 V0.5.0 (Sep. 2020), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on system enhancement for Proximity based Services (ProSe) in the 5G System (5GS) (… [cited by applicant]
3GPP TS 23.502 V0.6.0 (Aug. 2017), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G Stage 2 (Release 15), Aug. 2017 (148 pages). [cited by applicant]
ETSI TS 123 502 V16.5.1 (Sep. 2020), 5G; Procedures for the 5G System (5GS), (3GPP TS 23.502 version 16.5.1 Release 16), Sep. 2020 (597 pages). [cited by applicant]
ETSI TS 123 303 V16.0.0 (Jul. 2020), Universal Mobile Telecommunications System (UMTS); LTE; Proximity-based services (ProSe); Stage 2, (3GPP TS 23.303 version 16.0.0 Release 16), Jul. 2020 (133 pages). [cited by applicant]
ETSI TS 133 303 V16.0.0 (Aug. 2020), Universal Mobie Telecommunications System (UMTS); LTE; Proximity-based Services (ProSe); Security aspects (3GPP TS 33.303 version 16.0.0 Release 16), Aug. 2020 (92 pages). [cited by applicant]
ETSI TS 123 287 V16.4.0 (Oct. 2020), 5G; Architecture enhancements for 5G System (5GS) t support Vehicle-to-Everything (V2X) services (3GPP TS 23.287 version 16.4.0 Release 16), Aug. 2020 (60 pages). [cited by applicant]
3GPP TR 23.752 V0.3.0 (Jan. 2020), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on system enhancement for Proximity based Services (ProSe) in the 5G System (5GS) (… [cited by applicant]