Security gateway selection in hybrid 4G and 5G networks

US11889298B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11889298-B2
Application numberUS-201816765634-A
CountryUS
Kind codeB2
Filing dateNov 20, 2018
Priority dateNov 20, 2017
Publication dateJan 30, 2024
Grant dateJan 30, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Method and apparatus relating to a wireless device supporting 3GPP 4G and 5G radio interfaces and also supporting non-3GPP access, i.e., WiFi, for selecting a security gateway of a first type e.g., ePDG or a security gateway of a second type, e.g., N3IWF for accessing to the core network of first type, e.g., EPC or of a second type e.g., SGC. As the access methods via ePDG and N3IWF are not the same, the wireless device has to determine based on information obtained by a function in the network and its capabilities whether to use an ePDG or an N3IWF for untrusted non-3GPP access. The wireless device may take into account in the selection whether it is connected to the Core network over 3GPP 4G or 5G radio access network. A corresponding apparatus claim is provided.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method performed at a wireless device for selecting a security gateway for access over a non-third Generation Partnership Project, Non-3GPP, access network, the method comprising: obtaining information comprising security gateway of a first type information and security gateway of a second type information for enabling the wireless device to select the security gateway of a first type or the security gateway of a second type in a public land mobile network (PLMN), the information further comprising a service type and a PLMN preference for the security gateway of the first type or of the second type; selecting, based on a requested service type and the PLMN preference, one of the security gateway of the first type or the security gateway of the second type that supports the requested service type for establishing a connection over the non-3GPP access network, wherein the security gateway of the first type provides access for the wireless device to a first type of 3GPP core network and the security gateway of the second type provides access for the wireless device to a second type of 3GPP core network; and establishing a connection to the selected security gateway. 2. The method of claim 1 further comprising selecting one of the security gateway of the first type or the security gateway of the second type based on determining that a connection over a 3GPP radio access network to the first type of 3GPP core network or the second type of 3GPP core network exists. 3. The method of claim 1 wherein the obtained information comprises a priority list for one or more public land mobile networks, PLMNs, that provide at least one the security gateway of the first type and the security gateway of the second type. 4. The method of claim 1 , wherein the method further comprises selecting a first PLMN that is the same PLMN selected for access over the 3GPP radio access network. 5. The method of claim 1 , wherein the method further comprises selecting the security gateway of the first type for access to the first type of 3GPP core network while the wireless device is connected to the second type of 3GPP core network over the 3GPP radio access network, wherein the first type of 3GPP core network and the second type of 3GPP core network are in the first PLMN. 6. The method of claim 1 wherein the step of selecting further comprises selecting in a second PLMN the security gateway of the first type for access to the first type of 3GPP core network while connected to the second type of 3GPP core network in a first PLMN over the 3GPP radio access network. 7. The method of claim 6 wherein the method further comprises moving existing connection over the 3GPP radio access network from the second type of 3GPP core network to the first type of 3GPP core network. 8. The method of claim 1 , wherein the information comprises instruction for moving the existing connection over the 3GPP radio access network from the second type of 3GPP core network to the first type of 3GPP core network. 9. The method of claim 1 , wherein the information further comprises for one or more PLMNs, an identifier of the security gateway of the first type or the identifier of the security gateway of the second type associated to a network slice. 10. The method of claim 1 , wherein the information further comprises for one or more PLMNs, an identifier of the security gateway of the first type or the identifier of the security gateway of the second type associated to a data network name, DNN. 11. The method of claim 1 , wherein the information further comprises for one or more PLMNs, an identifier of the security gateway of the first type or the identifier of the security gateway of the second type corresponding to the service type. 12. The method of claim 1 , wherein the information is obtained over the 3GPP radio access network using Non-Access Stratum, NAS, protocol layer. 13. The method of claim 1 , wherein the information is obtained during local authentication in the non-3GPP access network. 14. The method of claim 13 , wherein the information is obtained from an Authentication, Authorization and Accounting, AAA, server in the non-3GPP access network. 15. The method of claim 1 , wherein the information is obtained via Domain Name Server, DNS. 16. The method of claim 1 , wherein the selected security gateway is based on at least one of capability of the wireless device to connect to the first type of 3GPP core network and the second type of 3GPP core network, and a preference of the wireless device. 17. The method of claim 1 wherein when the step of selecting, based on a requested service type and the PLMN preference, one of the security gateway of the first type or the security gateway of the second type that supports the requested service type for establishing a connection over the non-3GPP access network, fails, selecting the other one of the security gateway of the first type or the security gateway of the second type. 18. A method in a network entity for enabling a wireless device to select a security gateway for connecting to a core network over a Non-third Generation Partnership Project, Non-3GPP access network, the method comprising the steps of: obtaining an indication to provide information comprising security gateway of a first type information and security gateway of a second type information for enabling a wireless device to select a security gateway of a first type or a security gateway of a second type for a service type in a public land mobile network (PLMN); and transmitting the information to the wireless device, wherein the information comprises a prioritized list of one or more PLMN, a PLMN preference for the security gateway of a first type or the security gateway of a second type and information for identifying the security gateway of the first type and the security gateway of the second type supporting the service type; and wherein the security gateway of the first type provides access for the wireless device to a first type of 3GPP core network and the security gateway of the second type provides access for the wireless device to a second type of 3GPP core network. 19. The method of claim 18 , wherein the indication comprises one of a requested network slice or a data network name. 20. The method of claim 18 wherein the security gateway of the first type is an evolved Packet Data Gateway, ePDG, and the security gateway of the second type is a Non-3GPP Interworking Function, N3IWF.

Assignees

Inventors

Classifications

  • Reselecting a network or an air interface · CPC title

  • H04W12/009Primary

    specially adapted for networks, e.g. wireless sensor networks, ad-hoc networks, RFID networks or cloud networks · CPC title

  • using domain name system [DNS] · CPC title

  • by using authentication-authorization-accounting [AAA] servers or protocols · CPC title

  • Gateway arrangements · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11889298B2 cover?
Method and apparatus relating to a wireless device supporting 3GPP 4G and 5G radio interfaces and also supporting non-3GPP access, i.e., WiFi, for selecting a security gateway of a first type e.g., ePDG or a security gateway of a second type, e.g., N3IWF for accessing to the core network of first type, e.g., EPC or of a second type e.g., SGC. As the access methods via ePDG and N3IWF are not the…
Who is the assignee on this patent?
Foti George, Madour Lila, Ericsson Telefon Ab L M
What technology area does this patent fall under?
Primary CPC classification H04W12/009. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 30 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).