AMF controlled handling of the security policy for user plane protection in 5G systems
US-11606682-B2 · Mar 14, 2023 · US
US12200491B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12200491-B2 |
| Application number | US-201916619268-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 4, 2019 |
| Priority date | Apr 6, 2018 |
| Publication date | Jan 14, 2025 |
| Grant date | Jan 14, 2025 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method to operate a UE for handling security policy for user plane protection of communications in a communications system is provided. The method includes transmitting a packet data unit (PDU) session establishment request network access stratum (NAS) message toward an Access and Mobility Management Function (AMF) to establish a PDU session. The method further includes receiving an access network (AN) specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session.
Opening claim text (preview).
The invention claimed is: 1. A user equipment (UE) for handling security policy for user plane protection of communications in a communications system, the UE comprising: a transceiver configured to transmit and receive through a wireless air interface with an access node (AN) of the communications system; and at least one processor connected to the transceiver and configured to perform operations comprising: transmitting through the transceiver a packet data unit (PDU) session establishment request network access stratum (NAS) message toward an Access and Mobility Management Function (AMF) to establish a PDU session; receiving through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session; summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate. 2. The UE of claim 1 , wherein generation of the session consumed DRB-IP rate comprises not including in the summing any DRB-IP rates that are allocated for DRBs of the PDU session that are not indicated by the AN specific resource setup message for the UE to activate integrity protection. 3. The UE of claim 1 , wherein: when the PDU session will be the only active PDU session between the UE and the AN, the adjustment of the available DRB-IP rate of the UE comprises determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and the session consumed DRB-IP rate, wherein the maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions. 4. The UE of claim 1 , further comprising: before transmitting the PDU session establishment request NAS message toward the AMF and when the UE does not have an active PDU session with the AN which has DRBs for which the UE provides integrity protection, adding an indication of a maximum DRB-IP rate of the UE to the PDU session establishment request NAS message that is transmitted toward the AMF to establish a PDU session. 5. The UE of claim 1 , wherein: when the PDU session is one of a plurality of active PDU sessions between the UE and the AN, the adjustment of the available DRB-IP rate of the UE comprises determining the available DRB-IP rate of the UE based on a difference between a maximum DRB-IP rate of the UE and a summation of the session consumed DRB-IP rates that have been generated for each of the active PDU sessions, wherein the maximum DRB-IP rate of the UE corresponds to a maximum computational capacity of the UE to process DRBs that are integrity protected during PDU sessions. 6. The UE of claim 1 , further comprising: following the adjustment of the available DRB-IP rate of the UE, adding the available DRB-IP rate of the UE to another PDU session establishment request NAS message that is transmitted toward the AMF to establish another PDU session; receiving through the transceiver another AN specific resource setup message indicating whether the UE is to activate integrity protection for DRBs serving the another PDU session; summing DRB-IP rates that are allocated for the DRBs of the another PDU session that are indicated by the another AN specific resource setup message for the UE to activate integrity protection, to generate another session consumed DRB-IP rate; and further adjusting the available DRB-IP rate of the UE based on a difference between the available DRB-IP rate of the UE and the another session consumed DRB-IP rate. 7. The UE of claim 1 , further comprising: responsive to releasing the PDU session, increasing the available DRB-IP rate of the UE based on the session consumed DRB-IP rate of the PDU session. 8. A method by a user equipment (UE) for handling security policy for user plane protection of communications in a communications system, the method comprising: transmitting a packet data unit (PDU) session establishment request network access stratum (NAS) message toward an Access and Mobility Management Function (AMF) to establish a PDU session; receiving an access node (AN) specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session; summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate. 9. A communications system comprising: an Access and Mobility Management Function (AMF) of the communications system, the AMF comprising: a network interface configured to communicate with user equipments (UEs) via a network and an access node (AN) of the communications system, and to communicate with a Session Management Function (SMF) of the communications system; and at least one processor configured to perform operations comprising: receiving a packet data unit (PDU) session establishment request network access stratum (NAS) message from a UE requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established; communicating toward the SMF a PDU session create message containing the indication of the available DRB-IP rate; receiving a SMF message containing an indication of a user plane (UP) security policy for a PDU session being established; and communicating a message containing the indication of the UP security policy to an access node (AN) that is communicating through a wireless air interface with the UE; and the UE comprising: a transceiver configured to transmit and receive through a wireless air interface with an access node (AN) of the communications system; and at least one processor connected to the transceiver and configured to perform operations comprising: receiving through the transceiver an AN specific resource setup message indicating whether the UE is to activate integrity protection for data radio bearers (DRBs) serving the PDU session; summing DRB Integrity Protected (DRB-IP) rates that are allocated for the DRBs of the PDU session that are indicated by the AN specific resource setup message for the UE to activate integrity protection, to generate a session consumed DRB-IP rate; and adjusting an available DRB-IP rate of the UE based on the session consumed DRB-IP rate. 10. A method by a communications system, the method comprising: at an Access and Mobility Management Function (AMF): receiving a packet data unit (PDU) session establishment request network access stratum (NAS) message from a user equipment (UE) requesting establishment of a PDU session, the PDU session establishment request NAS message comprising an indication of an available data radio bearer integrity protected (DRB-IP) rate for which the UE presently has available computational capacity for processing DRBs that are integrity protected for the PDU session being established; communicating toward a Session Management Function (SMF) a PDU session create message containing the indication of the available DRB-IP rate of the UE; receivin
between terminal device and access point, i.e. wireless air interface · CPC title
Connection setup · CPC title
Connection release · CPC title
of the user plane, e.g. user's traffic · CPC title
received data contents, e.g. message integrity · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.