WO2021237391A1 - Cryptage d'identifiants d'application - Google Patents

Cryptage d'identifiants d'application Download PDF

Info

Publication number
WO2021237391A1
WO2021237391A1 PCT/CN2020/091987 CN2020091987W WO2021237391A1 WO 2021237391 A1 WO2021237391 A1 WO 2021237391A1 CN 2020091987 W CN2020091987 W CN 2020091987W WO 2021237391 A1 WO2021237391 A1 WO 2021237391A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
application identifier
data service
traffic
decryption key
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/091987
Other languages
English (en)
Inventor
Nan Zhang
Zhiguo Li
Chaofeng HUI
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Qualcomm Inc
Original Assignee
Qualcomm Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Qualcomm Inc filed Critical Qualcomm Inc
Priority to PCT/CN2020/091987 priority Critical patent/WO2021237391A1/fr
Publication of WO2021237391A1 publication Critical patent/WO2021237391A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/50Network service management, e.g. ensuring proper service fulfilment according to agreements
    • H04L41/5003Managing SLA; Interaction between SLA and QoS
    • H04L41/5009Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/50Network service management, e.g. ensuring proper service fulfilment according to agreements
    • H04L41/5041Network service management, e.g. ensuring proper service fulfilment according to agreements characterised by the time relationship between creation and deployment of a service
    • H04L41/5054Automatic deployment of services triggered by the service manager, e.g. service implementation by automatic configuration of network components
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0894Policy-based network configuration management

Definitions

  • the following relates generally to wireless communications and more specifically to encrypting application identifiers.
  • Wireless communications systems are widely deployed to provide various types of communication content such as voice, video, packet data, messaging, broadcast, and so on. These systems may be capable of supporting communication with multiple users by sharing the available system resources (e.g., time, frequency, and power) .
  • Examples of such multiple-access systems include fourth generation (4G) systems such as Long Term Evolution (LTE) systems, LTE-Advanced (LTE-A) systems, or LTE-A Pro systems, and fifth generation (5G) systems which may be referred to as New Radio (NR) systems.
  • 4G systems such as Long Term Evolution (LTE) systems, LTE-Advanced (LTE-A) systems, or LTE-A Pro systems
  • 5G systems which may be referred to as New Radio (NR) systems.
  • a wireless multiple-access communications system may include one or more base stations or one or more network access nodes, each simultaneously supporting communication for multiple communication devices, which may be otherwise known as user equipment (UE) .
  • UE user equipment
  • a wireless multiple-access communications system may include one or more base stations or one or more network access nodes, each simultaneously supporting communication for multiple communication devices, which may be otherwise known as user equipment (UE) .
  • UE user equipment
  • a UE may access a network slice for communicating with a base station. Improved techniques for managing communications between a base station and a UE via a network slice may be desirable.
  • the described techniques relate to improved methods, systems, devices, and apparatuses that support encrypting application identifiers.
  • the described techniques provide for a user equipment (UE) to receive a set of traffic descriptors each including an encrypted application identifier corresponding to an application.
  • Each traffic descriptor may additionally indicate, to the UE, a network slice (e.g., from a set of available network slices) that the UE is to use for establishing a data service for the associated application.
  • a network slice e.g., from a set of available network slices
  • the UE may in turn request for the application to provide its application identifier and a decryption key for the application identifier.
  • the UE may then identify the traffic descriptor associated with the application requesting the data service by decrypting the encrypted application identifier included in the traffic descriptor using the decryption key provided by the application to obtain the application identifier.
  • the UE may transmit (e.g., to a base station) a data service request for the application according to the traffic descriptor associated with the application.
  • the UE may receive data service traffic for the application.
  • the data service traffic may include the encrypted application identifier of the application.
  • the UE may decrypt the encrypted application identifier to obtain the application identifier of the application and route the data service traffic to the application based on decrypting the application identifier.
  • a method of wireless communication at a UE may include receiving a traffic descriptor that includes an encrypted application identifier corresponding to an application, receiving an application identifier of the application and a decryption key for the application identifier, transmitting, to a base station, a data service request that requests data service for the application according to the received traffic descriptor, receiving, from the base station, data service traffic for the data service that includes the encrypted application identifier, and routing the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the apparatus may include a processor, memory coupled with the processor, and instructions stored in the memory.
  • the instructions may be executable by the processor to cause the apparatus to receive a traffic descriptor that includes an encrypted application identifier corresponding to an application, receive an application identifier of the application and a decryption key for the application identifier, transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor, receive, from the base station, data service traffic for the data service that includes the encrypted application identifier, and route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the apparatus may include means for receiving a traffic descriptor that includes an encrypted application identifier corresponding to an application, receiving an application identifier of the application and a decryption key for the application identifier, transmitting, to a base station, a data service request that requests data service for the application according to the received traffic descriptor, receiving, from the base station, data service traffic for the data service that includes the encrypted application identifier, and routing the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • a non-transitory computer-readable medium storing code for wireless communication at a UE is described.
  • the code may include instructions executable by a processor to receive a traffic descriptor that includes an encrypted application identifier corresponding to an application, receive an application identifier of the application and a decryption key for the application identifier, transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor, receive, from the base station, data service traffic for the data service that includes the encrypted application identifier, and route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • transmitting the data service request may include operations, features, means, or instructions for transmitting the data service request according to the received traffic descriptor based on decrypting the application identifier within the received traffic descriptor using the decryption key.
  • receiving the traffic descriptor may include operations, features, means, or instructions for receiving a network slice selection policy indicating a first network slice from a set of available network slices associated with the application.
  • receiving the application identifier may include operations, features, means, or instructions for receiving the application identifier that may be an operating system application identifier.
  • Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for establishing a connection with a trusted environment, and receiving the decryption key for the application identifier from the trusted environment.
  • the trusted environment may be associated with a public land mobile network.
  • Some instances of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for receiving the traffic descriptor that includes the encrypted application identifier corresponding to the application from a public land mobile network.
  • Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for receiving, from the base station, a set of traffic descriptors that includes the received traffic descriptor.
  • each of the set of traffic descriptors include an encrypted application identifier corresponding to a unique application.
  • Some instances of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for identifying a first network slice from a set of available network slices based on the received traffic descriptor, and transmitting a registration request requesting to register with the first network slice of the set of available network slices, where transmitting the data service request may be based on transmitting the registration request.
  • Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for receiving a first request for the data service from the application, and transmitting, to the application, a second request for the application identifier and the decryption key, where receiving the application identifier and the decryption key for the application identifier may be based on transmitting the second request.
  • Some cases of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for matching a decrypted application identifier to the application identifier of the application based on decrypting the encrypted application identifier, where routing the data service traffic to the application may be based on matching the decrypted application identifier to the application identifier.
  • FIG. 1 illustrates an example of a system for wireless communications in accordance with aspects of the present disclosure.
  • FIG. 2 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
  • FIG. 3 illustrates an example of a process flow in accordance with aspects of the present disclosure.
  • FIGs. 4 and 5 show block diagrams of devices in accordance with aspects of the present disclosure.
  • FIG. 6 shows a block diagram of a communications manager in accordance with aspects of the present disclosure.
  • FIG. 7 shows a diagram of a system including a device in accordance with aspects of the present disclosure.
  • FIGs. 8 through 10 show flowcharts illustrating methods in accordance with aspects of the present disclosure.
  • a network slice may be a logical end-to-end network that can be dynamically created.
  • a user equipment UE
  • PDU protocol data unit
  • a UE may select a network slice based on an application or subscription service.
  • a UE may have an application that is an internet protocol (IP) multimedia systems (IMS) voice application, and the UE may select a network slice that is configured to support this mobile broadband application.
  • IP internet protocol
  • IMS internet protocol multimedia systems
  • a UE may, additionally or alternatively, have an application that is configured as an Internet of Everything (IoT) application; for example, the IoT application may configure the UE to operate as an IoT gateway device that compiles and transmits data to a remote server, periodically. As such, the UE may select a network slice that is configured to support massive IoT data traffic. By having different network slices serving different applications, subscriptions, etc., the UE may improve its resource utilization in a network, while also satisfying performance requirements of individual applications of the UE.
  • IoT Internet of Everything
  • Each network slice may be characterized by a set of parameters which may be defined based on a generic network slice template (GST) .
  • GST may indicate a quantity of protocol data unit (PDU) sessions per slice, the number of devices supported per slice, or a maximum uplink or downlink data rate per slice.
  • a public land mobile network (PLMN) may provide a UE with a list of traffic descriptors associated with each application of the UE, where each traffic descriptor indicates a network slice (e.g., from a set of available network slices) for providing data service to the corresponding application.
  • Each traffic descriptor may include an application identifier (e.g., an Operating System Application Identifier (OS APP ID) field) indicating a corresponding application.
  • OS APP ID Operating System Application Identifier
  • the UE may match the application identifier of the requesting application to the application identifier within a traffic descriptor. The UE may then transmit a data service request associated with the network slice indicated by the traffic descriptor.
  • the network slices may be served by different network functions (e.g., access and mobility management function (AMF) , session management function (SMF) , etc. ) .
  • the network may, in some cases, provide network slice selection assistance information (NSSAI) or a set of allowed NSSAIs (S-NSSAI) to the UE.
  • the NSSAI may include information indicating allowed or supported network slices for the UE to use, among other information.
  • a data network may be associated with an S-NSSAI.
  • a network operator may provide to a UE a network slice selection policy (NSSP) .
  • the NSSP may include one or more NSSP rules, each one associating an application with a certain S-NSSAI.
  • a default rule may match all applications to a S-NSSAI.
  • a UE application associated with an S-NSSAI may request data transmission.
  • an application may request a new data service using an application identifier other than its own application identifier.
  • the UE may match the application identifier (e.g., not associated with the requesting application) to the application identifier within a traffic descriptor that is not associated with the requesting application.
  • the UE may establish a data service associated with a network slice that is not associated with the requesting application. Enabling an application to access a network slice not associated with that application may decrease a security of communications associated with the network slice.
  • each traffic descriptor may include an encrypted application identifier (e.g., instead of an unencrypted application identifier) .
  • an application requests a data service
  • the UE may in turn request for the application to provide its application identifier and a decryption key for the application identifier.
  • an application vendor may apply for an application identifier (e.g., “OS App ID” ) from an operator and a secure decryption key at the same time.
  • the UE may then identify the traffic descriptor associated with the application requesting the data service by decrypting the encrypted application identifier included in the traffic descriptor using the decryption key provided by the application to obtain the application identifier.
  • the UE may transmit (e.g., to a base station) a data service request for the application according to the traffic descriptor associated with the application.
  • a data service for the application may be established (e.g., in response to the UE transmitting the data service request)
  • the UE may receive data service traffic for the application.
  • the data service traffic may include the encrypted application identifier of the application.
  • the UE may decrypt the encrypted application identifier to obtain the application identifier of the application and route the data service traffic to the application based on decrypting the application identifier.
  • an application may not request a data service using an application identifier other than its own because the application may not have access to the decryption key.
  • the UE may be unable to decrypt the application identifier included in the traffic descriptors. In some cases, this may increase a security associated with network slice instances.
  • aspects of the disclosure are initially described in the context of wireless communications systems. Aspects of the disclosure are further illustrated by and described with reference to a process flow, apparatus diagrams, system diagrams, and flowcharts that relate to encrypting application identifiers.
  • FIG. 1 illustrates an example of a wireless communications system 100 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the wireless communications system 100 may include one or more base stations 105, one or more UEs 115, and a core network 130.
  • the wireless communications system 100 may be a Long Term Evolution (LTE) network, an LTE-Advanced (LTE-A) network, an LTE-A Pro network, or a New Radio (NR) network.
  • LTE Long Term Evolution
  • LTE-A LTE-Advanced
  • LTE-A Pro LTE-A Pro
  • NR New Radio
  • the wireless communications system 100 may support enhanced broadband communications, ultra-reliable (e.g., mission critical) communications, low latency communications, communications with low-cost and low-complexity devices, or any combination thereof.
  • ultra-reliable e.g., mission critical
  • the base stations 105 may be dispersed throughout a geographic area to form the wireless communications system 100 and may be devices in different forms or having different capabilities.
  • the base stations 105 and the UEs 115 may wirelessly communicate via one or more communication links 125.
  • Each base station 105 may provide a coverage area 110 over which the UEs 115 and the base station 105 may establish one or more communication links 125.
  • the coverage area 110 may be an example of a geographic area over which a base station 105 and a UE 115 may support the communication of signals according to one or more radio access technologies.
  • the UEs 115 may be dispersed throughout a coverage area 110 of the wireless communications system 100, and each UE 115 may be stationary, or mobile, or both at different times.
  • the UEs 115 may be devices in different forms or having different capabilities. Some example UEs 115 are illustrated in FIG. 1.
  • the UEs 115 described herein may be able to communicate with various types of devices, such as other UEs 115, the base stations 105, or network equipment (e.g., core network nodes, relay devices, integrated access and backhaul (IAB) nodes, or other network equipment) , as shown in FIG. 1.
  • network equipment e.g., core network nodes, relay devices, integrated access and backhaul (IAB) nodes, or other network equipment
  • the base stations 105 may communicate with the core network 130, or with one another, or both.
  • the base stations 105 may interface with the core network 130 through one or more backhaul links 120 (e.g., via an S1, N2, N3, or other interface) .
  • the base stations 105 may communicate with one another over the backhaul links 120 (e.g., via an X2, Xn, or other interface) either directly (e.g., directly between base stations 105) , or indirectly (e.g., via core network 130) , or both.
  • the backhaul links 120 may be or include one or more wireless links.
  • One or more of the base stations 105 described herein may include or may be referred to by a person having ordinary skill in the art as a base transceiver station, a radio base station, an access point, a radio transceiver, a NodeB, an eNodeB (eNB) , a next-generation NodeB or a giga-NodeB (either of which may be referred to as a gNB) , a Home NodeB, a Home eNodeB, or other suitable terminology.
  • a base transceiver station a radio base station
  • an access point a radio transceiver
  • a NodeB an eNodeB (eNB)
  • eNB eNodeB
  • a next-generation NodeB or a giga-NodeB either of which may be referred to as a gNB
  • gNB giga-NodeB
  • a UE 115 may include or may be referred to as a mobile device, a wireless device, a remote device, a handheld device, or a subscriber device, or some other suitable terminology, where the “device” may also be referred to as a unit, a station, a terminal, or a client, among other examples.
  • a UE 115 may also include or may be referred to as a personal electronic device such as a cellular phone, a personal digital assistant (PDA) , a tablet computer, a laptop computer, or a personal computer.
  • PDA personal digital assistant
  • a UE 115 may include or be referred to as a wireless local loop (WLL) station, an Internet of Things (IoT) device, an Internet of Everything (IoE) device, or a machine type communications (MTC) device, among other examples, which may be implemented in various objects such as appliances, or vehicles, meters, among other examples.
  • WLL wireless local loop
  • IoT Internet of Things
  • IoE Internet of Everything
  • MTC machine type communications
  • the UEs 115 described herein may be able to communicate with various types of devices, such as other UEs 115 that may sometimes act as relays as well as the base stations 105 and the network equipment including macro eNBs or gNBs, small cell eNBs or gNBs, or relay base stations, among other examples, as shown in FIG. 1.
  • devices such as other UEs 115 that may sometimes act as relays as well as the base stations 105 and the network equipment including macro eNBs or gNBs, small cell eNBs or gNBs, or relay base stations, among other examples, as shown in FIG. 1.
  • the UEs 115 and the base stations 105 may wirelessly communicate with one another via one or more communication links 125 over one or more carriers.
  • the term “carrier” may refer to a set of radio frequency spectrum resources having a defined physical layer structure for supporting the communication links 125.
  • a carrier used for a communication link 125 may include a portion of a radio frequency spectrum band (e.g., a bandwidth part (BWP) ) that is operated according to one or more physical layer channels for a given radio access technology (e.g., LTE, LTE-A, LTE-A Pro, NR) .
  • BWP bandwidth part
  • Each physical layer channel may carry acquisition signaling (e.g., synchronization signals, system information) , control signaling that coordinates operation for the carrier, user data, or other signaling.
  • the wireless communications system 100 may support communication with a UE 115 using carrier aggregation or multi-carrier operation.
  • a UE 115 may be configured with multiple downlink component carriers and one or more uplink component carriers according to a carrier aggregation configuration.
  • Carrier aggregation may be used with both frequency division duplexing (FDD) and time division duplexing (TDD) component carriers.
  • FDD frequency division duplexing
  • TDD time division duplexing
  • a carrier may also have acquisition signaling or control signaling that coordinates operations for other carriers.
  • a carrier may be associated with a frequency channel (e.g., an evolved universal mobile telecommunication system terrestrial radio access (E-UTRA) absolute radio frequency channel number (EARFCN) ) and may be positioned according to a channel raster for discovery by the UEs 115.
  • E-UTRA evolved universal mobile telecommunication system terrestrial radio access
  • a carrier may be operated in a standalone mode where initial acquisition and connection may be conducted by the UEs 115 via the carrier, or the carrier may be operated in a non-standalone mode where a connection is anchored using a different carrier (e.g., of the same or a different radio access technology) .
  • the communication links 125 shown in the wireless communications system 100 may include uplink transmissions from a UE 115 to a base station 105, or downlink transmissions from a base station 105 to a UE 115.
  • Carriers may carry downlink or uplink communications (e.g., in an FDD mode) or may be configured to carry downlink and uplink communications (e.g., in a TDD mode) .
  • Signal waveforms transmitted over a carrier may be made up of multiple subcarriers (e.g., using multi-carrier modulation (MCM) techniques such as orthogonal frequency division multiplexing (OFDM) or discrete Fourier transform spread OFDM (DFT- S-OFDM) ) .
  • MCM multi-carrier modulation
  • OFDM orthogonal frequency division multiplexing
  • DFT- S-OFDM discrete Fourier transform spread OFDM
  • a resource element may consist of one symbol period (e.g., a duration of one modulation symbol) and one subcarrier, where the symbol period and subcarrier spacing are inversely related.
  • the number of bits carried by each resource element may depend on the modulation scheme (e.g., the order of the modulation scheme, the coding rate of the modulation scheme, or both) .
  • a wireless communications resource may refer to a combination of a radio frequency spectrum resource, a time resource, and a spatial resource (e.g., spatial layers or beams) , and the use of multiple spatial layers may further increase the data rate or data integrity for communications with a UE 115.
  • Time intervals of a communications resource may be organized according to radio frames each having a specified duration (e.g., 10 milliseconds (ms) ) .
  • Each radio frame may be identified by a system frame number (SFN) (e.g., ranging from 0 to 1023) .
  • SFN system frame number
  • Each frame may include multiple consecutively numbered subframes or slots, and each subframe or slot may have the same duration.
  • a frame may be divided (e.g., in the time domain) into subframes, and each subframe may be further divided into a number of slots.
  • each frame may include a variable number of slots, and the number of slots may depend on subcarrier spacing.
  • Each slot may include a number of symbol periods (e.g., depending on the length of the cyclic prefix prepended to each symbol period) .
  • a slot may further be divided into multiple mini-slots containing one or more symbols. Excluding the cyclic prefix, each symbol period may contain one or more (e.g., N f ) sampling periods. The duration of a symbol period may depend on the subcarrier spacing or frequency band of operation.
  • a subframe, a slot, a mini-slot, or a symbol may be the smallest scheduling unit (e.g., in the time domain) of the wireless communications system 100 and may be referred to as a transmission time interval (TTI) .
  • TTI duration e.g., the number of symbol periods in a TTI
  • the smallest scheduling unit of the wireless communications system 100 may be dynamically selected (e.g., in bursts of shortened TTIs (sTTIs) ) .
  • Physical channels may be multiplexed on a carrier according to various techniques.
  • a physical control channel and a physical data channel may be multiplexed on a downlink carrier, for example, using one or more of time division multiplexing (TDM) techniques, frequency division multiplexing (FDM) techniques, or hybrid TDM-FDM techniques.
  • a control region e.g., a control resource set (CORESET)
  • CORESET control resource set
  • a control region for a physical control channel may be defined by a number of symbol periods and may extend across the system bandwidth or a subset of the system bandwidth of the carrier.
  • One or more control regions (e.g., CORESETs) may be configured for a set of the UEs 115.
  • one or more of the UEs 115 may monitor or search control regions for control information according to one or more search space sets, and each search space set may include one or multiple control channel candidates in one or more aggregation levels arranged in a cascaded manner.
  • An aggregation level for a control channel candidate may refer to a number of control channel resources (e.g., control channel elements (CCEs) ) associated with encoded information for a control information format having a given payload size.
  • Search space sets may include common search space sets configured for sending control information to multiple UEs 115 and UE-specific search space sets for sending control information to a specific UE 115.
  • a base station 105 may be movable and therefore provide communication coverage for a moving geographic coverage area 110.
  • different geographic coverage areas 110 associated with different technologies may overlap, but the different geographic coverage areas 110 may be supported by the same base station 105.
  • the overlapping geographic coverage areas 110 associated with different technologies may be supported by different base stations 105.
  • the wireless communications system 100 may include, for example, a heterogeneous network in which different types of the base stations 105 provide coverage for various geographic coverage areas 110 using the same or different radio access technologies.
  • the wireless communications system 100 may be configured to support ultra-reliable communications or low-latency communications, or various combinations thereof.
  • the wireless communications system 100 may be configured to support ultra-reliable low-latency communications (URLLC) or mission critical communications.
  • the UEs 115 may be designed to support ultra-reliable, low-latency, or critical functions (e.g., mission critical functions) .
  • Ultra-reliable communications may include private communication or group communication and may be supported by one or more mission critical services such as mission critical push-to-talk (MCPTT) , mission critical video (MCVideo) , or mission critical data (MCData) .
  • MCPTT mission critical push-to-talk
  • MCVideo mission critical video
  • MCData mission critical data
  • Support for mission critical functions may include prioritization of services, and mission critical services may be used for public safety or general commercial applications.
  • the terms ultra-reliable, low-latency, mission critical, and ultra-reliable low-latency may be used interchangeably herein.
  • a UE 115 may also be able to communicate directly with other UEs 115 over a device-to-device (D2D) communication link 135 (e.g., using a peer-to-peer (P2P) or D2D protocol) .
  • D2D device-to-device
  • P2P peer-to-peer
  • One or more UEs 115 utilizing D2D communications may be within the geographic coverage area 110 of a base station 105.
  • Other UEs 115 in such a group may be outside the geographic coverage area 110 of a base station 105 or be otherwise unable to receive transmissions from a base station 105.
  • groups of the UEs 115 communicating via D2D communications may utilize a one-to-many (1: M) system in which each UE 115 transmits to every other UE 115 in the group.
  • a base station 105 facilitates the scheduling of resources for D2D communications. In other cases, D2D communications are carried out between the UEs 115 without the involvement of a base station 105.
  • the core network 130 may provide user authentication, access authorization, tracking, Internet Protocol (IP) connectivity, and other access, routing, or mobility functions.
  • the core network 130 may be an evolved packet core (EPC) or 5G core (5GC) , which may include at least one control plane entity that manages access and mobility (e.g., a mobility management entity (MME) , an access and mobility management function (AMF) ) and at least one user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW) , a Packet Data Network (PDN) gateway (P-GW) , or a user plane function (UPF) ) .
  • EPC evolved packet core
  • 5GC 5G core
  • MME mobility management entity
  • AMF access and mobility management function
  • S-GW serving gateway
  • PDN Packet Data Network gateway
  • UPF user plane function
  • the control plane entity may manage non-access stratum (NAS) functions such as mobility, authentication, and bearer management for the UEs 115 served by the base stations 105 associated with the core network 130.
  • NAS non-access stratum
  • User IP packets may be transferred through the user plane entity, which may provide IP address allocation as well as other functions.
  • the user plane entity may be connected to the network operators IP services 150.
  • the operators IP services 150 may include access to the Internet, Intranet (s) , an IP Multimedia Subsystem (IMS) , or a Packet-Switched Streaming Service.
  • Some of the network devices may include subcomponents such as an access network entity 140, which may be an example of an access node controller (ANC) .
  • Each access network entity 140 may communicate with the UEs 115 through one or more other access network transmission entities 145, which may be referred to as radio heads, smart radio heads, or transmission/reception points (TRPs) .
  • Each access network transmission entity 145 may include one or more antenna panels.
  • various functions of each access network entity 140 or base station 105 may be distributed across various network devices (e.g., radio heads and ANCs) or consolidated into a single network device (e.g., a base station 105) .
  • the wireless communications system 100 may operate using one or more frequency bands, typically in the range of 300 megahertz (MHz) to 300 gigahertz (GHz) .
  • the region from 300 MHz to 3 GHz is known as the ultra-high frequency (UHF) region or decimeter band because the wavelengths range from approximately one decimeter to one meter in length.
  • UHF waves may be blocked or redirected by buildings and environmental features, but the waves may penetrate structures sufficiently for a macro cell to provide service to the UEs 115 located indoors.
  • the transmission of UHF waves may be associated with smaller antennas and shorter ranges (e.g., less than 100 kilometers) compared to transmission using the smaller frequencies and longer waves of the high frequency (HF) or very high frequency (VHF) portion of the spectrum below 300 MHz.
  • HF high frequency
  • VHF very high frequency
  • the wireless communications system 100 may utilize both licensed and unlicensed radio frequency spectrum bands.
  • the wireless communications system 100 may employ License Assisted Access (LAA) , LTE-Unlicensed (LTE-U) radio access technology, or NR technology in an unlicensed band such as the 5 GHz industrial, scientific, and medical (ISM) band.
  • LAA License Assisted Access
  • LTE-U LTE-Unlicensed
  • NR NR technology
  • an unlicensed band such as the 5 GHz industrial, scientific, and medical (ISM) band.
  • devices such as the base stations 105 and the UEs 115 may employ carrier sensing for collision detection and avoidance.
  • operations in unlicensed bands may be based on a carrier aggregation configuration in conjunction with component carriers operating in a licensed band (e.g., LAA) .
  • Operations in unlicensed spectrum may include downlink transmissions, uplink transmissions, P2P transmissions, or D2D transmissions, among other examples.
  • a base station 105 or a UE 115 may be equipped with multiple antennas, which may be used to employ techniques such as transmit diversity, receive diversity, multiple-input multiple-output (MIMO) communications, or beamforming.
  • the antennas of a base station 105 or a UE 115 may be located within one or more antenna arrays or antenna panels, which may support MIMO operations or transmit or receive beamforming.
  • one or more base station antennas or antenna arrays may be co-located at an antenna assembly, such as an antenna tower.
  • antennas or antenna arrays associated with a base station 105 may be located in diverse geographic locations.
  • a base station 105 may have an antenna array with a number of rows and columns of antenna ports that the base station 105 may use to support beamforming of communications with a UE 115.
  • a UE 115 may have one or more antenna arrays that may support various MIMO or beamforming operations.
  • an antenna panel may support radio frequency beamforming for a signal transmitted via an antenna port.
  • Beamforming which may also be referred to as spatial filtering, directional transmission, or directional reception, is a signal processing technique that may be used at a transmitting device or a receiving device (e.g., a base station 105, a UE 115) to shape or steer an antenna beam (e.g., a transmit beam, a receive beam) along a spatial path between the transmitting device and the receiving device.
  • Beamforming may be achieved by combining the signals communicated via antenna elements of an antenna array such that some signals propagating at particular orientations with respect to an antenna array experience constructive interference while others experience destructive interference.
  • the adjustment of signals communicated via the antenna elements may include a transmitting device or a receiving device applying amplitude offsets, phase offsets, or both to signals carried via the antenna elements associated with the device.
  • the adjustments associated with each of the antenna elements may be defined by a beamforming weight set associated with a particular orientation (e.g., with respect to the antenna array of the transmitting device or receiving device, or with respect to some other orientation) .
  • the wireless communications system 100 may be a packet-based network that operates according to a layered protocol stack.
  • communications at the bearer or Packet Data Convergence Protocol (PDCP) layer may be IP-based.
  • a Radio Link Control (RLC) layer may perform packet segmentation and reassembly to communicate over logical channels.
  • RLC Radio Link Control
  • a Medium Access Control (MAC) layer may perform priority handling and multiplexing of logical channels into transport channels.
  • the MAC layer may also use error detection techniques, error correction techniques, or both to support retransmissions at the MAC layer to improve link efficiency.
  • the Radio Resource Control (RRC) protocol layer may provide establishment, configuration, and maintenance of an RRC connection between a UE 115 and a base station 105 or a core network 130 supporting radio bearers for user plane data.
  • RRC Radio Resource Control
  • transport channels may be mapped to physical channels.
  • Wireless communications system 100 may support the use of network slices to support additional features and network function optimizations.
  • a network slice may be a logical end-to-end network that can be dynamically created.
  • Each network slice may be characterized by a set of parameters which may be defined based on a GST.
  • the GST may indicate a quantity of PDU sessions per slice, the number of devices supported per slice, or a maximum uplink or downlink data rate per slice.
  • a PLMN may provide a UE 115 with a list of traffic descriptors associated with each application of the UE 115 (e.g., by a base station 105) , where each traffic descriptor indicates a network slice (e.g., from a set of available network slices) for providing data service to the corresponding application.
  • Each traffic descriptor may include an application identifier (e.g., an OS APP ID field) indicating a corresponding application.
  • an application identifier e.g., an OS APP ID field
  • the UE 115 may match the application identifier of the requesting application to the application identifier within a traffic descriptor. The UE 115 may then transmit a data service request associated with the network slice indicated by the traffic descriptor.
  • Each network slice may include an isolated end-to-end network tailored to meet different requirements (e.g., QoS, different application profiles, usage, etc. ) requested by a particular application.
  • different applications of a UE 115 may include services with different service level requirements.
  • the network slices may enable a flexible and scalable configuration on top of a common network infrastructure to meet the differing service level requirements for the different applications.
  • the different network slices may be administered by separate operators (e.g., mobile virtual network operators) , where an infrastructure provider leases physical resources to these operators that share the underlying physical network of the infrastructure provider. The operators may then deploy multiple network slices customized to the different applications provided to users associated with the operators.
  • network slicing may enable a mobile operator to create specific virtual networks that cater to particular clients and use cases.
  • certain applications e.g., such as eMBB communications, machine-to-machine (M2M) communications in manufacturing or logistics, smart cars, etc.
  • M2M machine-to-machine
  • a first application may use higher speeds
  • a second application may use low latency
  • a third application may use edge computing resources, etc.
  • a mobile operator may offer tailored solutions to particular industries. For example, different industries (e.g., marketing, augmented reality, mobile gaming, etc. ) may use these network slices for meeting corresponding requirements for the industries.
  • network slicing may also enhance service continuity via improved roaming across networks by creating a virtual network running on a physical infrastructure that spans multiple local or national networks, by allowing a host network to create an optimized virtual network which replicates the one offered by a home network for a roaming device (e.g., a UE 115) , etc.
  • a roaming device e.g., a UE 115
  • the network slices may be served by different network functions (e.g., AMF, SMF, etc. ) .
  • the network may, in some cases, provide NSSAI or an S-NSSAI to the UE 115.
  • the NSSAI may include information indicating allowed or supported network slices for the UE 115 to use, among other information.
  • a data network may be associated with an S-NSSAI.
  • a network operator may provide to a UE 115 an NSSP.
  • the NSSP may include one or more NSSP rules, each one associating an application with a certain S-NSSAI.
  • a default rule may match all applications to a S-NSSAI.
  • a UE application associated with an S-NSSAI may request data transmission.
  • each traffic descriptor may include an encrypted application identifier (e.g., instead of an unencrypted application identifier) .
  • the UE 115 may in turn request for the application to provide its application identifier and a decryption key for the application identifier.
  • the UE 115 may then identify the traffic descriptor associated with the application requesting the data service by decrypting the encrypted application identifier included in the traffic descriptor using the decryption key provided by the application to obtain the application identifier.
  • the UE 115 may transmit (e.g., to a base station 105) a data service request for the application according to the traffic descriptor associated with the application.
  • the UE 115 may receive data service traffic for the application.
  • the data service traffic may include the encrypted application identifier of the application.
  • the UE 115 may decrypt the encrypted application identifier to obtain the application identifier of the application and route the data service traffic to the application based on decrypting the application identifier.
  • an application may not request a data service using an application identifier other than its own because the application may not have access to the decryption key.
  • the UE 115 may be unable to decrypt the application identifier included in the traffic descriptors. In some cases, this may increase a security associated with network slice instances.
  • FIG. 2 illustrates an example of a wireless communications system 200 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the wireless communications system 200 may implement aspects of wireless communications system 100.
  • the base station 105-a and UE 115-a may be examples of base stations 105 and UEs 115, respectively, as described with reference to FIG. 1.
  • the UE 115-a may include a modem 215 and one or more applications, including application 220.
  • the modem 215 may enable the UE 115-a to communicate with the base station 105-a using one or more radio access technologies (RATs) .
  • RATs radio access technologies
  • the modem 215 may enable the UE 115-a to communicate with the base station 105-a by downlink channel 205 and uplink channel 210.
  • the application 220 may store an application identifier identifying the application 220 and a decryption key associated with the application identifier.
  • the application 220 may be provided to the U 115-a by an application vendor, which may supply the application identifier and secure decryption key to the application 220.
  • the UE 115-a may receive traffic descriptors 225 for each application 220 at the UE 115-a.
  • the base station 105-a may transmit the traffic descriptors 225 to the U 115-a by the downlink channel 205.
  • a PLMN e.g., associated with the base station 105-a
  • the traffic descriptors 225 may be network slice selection policy (NSSP) traffic descriptors 225. That is, each traffic descriptor 225 may associate an application with one or more network slices (e.g., from a set of available network slices) .
  • NSSP network slice selection policy
  • the traffic descriptors 225 may enable the UE 115-a to identify one or more network slices (e.g., one or more network slice instances) associated with the application 220.
  • Each traffic descriptor 225 may include an encrypted application identifier (e.g., an encrypted OSS APP ID field) . That is, one of the traffic descriptors 225 may include an encrypted application identifier associated with the application 220.
  • the application 220 may communicate a request for a new data service to the modem 215 of the UE 115-a.
  • the modem 215 may request the application identifier associated with the application 220 and a decryption key for the application identifier.
  • the application 220 may provide both the application identifier and the decryption key to the modem 215.
  • the modem 215 may establish a trusted environment (e.g., a secure trust zone environment) to receive the decryption key from the application 220
  • a trusted environment e.g., a secure trust zone environment
  • the UE 115-a may establish a connection to a trusted environment (e.g., associated with the PLMN) by the application 220 may receive its decryption key.
  • the modem 215 may then decrypt the encrypted application identifiers within the traffic descriptors 225 using the decryption key provided by the application 220.
  • the modem 215 may obtain a set of decrypted application identifiers, each associated with one of the traffic descriptors 225.
  • the modem 215 may then attempt to match one of the decrypted application identifiers associated with a traffic descriptor 225 to the application identifier supplied to the modem 215 by the application 220.
  • the modem 215 may identify the traffic descriptor 225 associated with the application 220 based on identifying a decrypted application identifier that matches the application identifier supplied by the application 220.
  • This traffic descriptor 225 may indicate a network slice (e.g., from a set of available network slices) associated with the application 220.
  • the UE 115-a may then transmit a data service request 230 to the base station 105-a (e.g., by the uplink channel 210) in accordance with the traffic descriptor 225 associated with the application 220.
  • the UE 115-a may transmit a registration request requesting to register with the network slice indicated by the traffic descriptor 225 associated with the application 220.
  • the data service request 230 may be a request to establish a PDU session for the network slice indicated by the traffic descriptor 225.
  • the base station 105-a may communicate a PDU session establishment accept message to the U 115-a. In either case, the UE 115-a may establish the data service in accordance with the traffic descriptor 225 associated with the application 220.
  • the UE 115-a may receive data service traffic 235 for the data service.
  • the data service traffic 235 may include the encrypted application identifier associated with the application 220.
  • the UE 115-a may decrypt the encrypted application identifier using the decryption key received from the application 220 to obtain the application identifier indicating the application 220.
  • the modem 215 may decrypt the encrypted application identifier in the trusted environment to prevent other applications 220 at the UE 115-a from identifying the decrypted application identifier.
  • the UE 115-a may match the decrypted application identifier to the application identifier associated with the application 220 and route the data service traffic 235 to the application 220 accordingly.
  • FIG. 3 illustrates an example of a process flow 300 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the process flow 300 may implement aspects of wireless communications system 100.
  • the base station 105-b and UE 115-b may be examples of base stations 105 and UEs 115, respectively, as described with reference to FIGs. 1 and 2.
  • UE 115-b may include a modem 215-a and an application 220-a, which may be respective examples of modem 215 and application 220 as described with reference to FIG. 2.
  • the base station 105-b may transmit a set of traffic descriptors to the UE 115-b (e.g., the modem 215-aof the UE 115-b) .
  • Each of the traffic descriptors may include an encrypted application identifier corresponding to a unique application 220 at the UE 115-a.
  • the set of traffic descriptors may indicate a network slice selection policy.
  • the UE 115-b may receive the network slice selection policy indicating a network slice from a set of available network slices associated with each application 220 of the UE 115-a.
  • the base station 105-b may be associated with a PLMN and may transmit the traffic descriptors 225 to the UE 115-b during a registration or updating of the UE 115-b. Additionally or alternatively, the UE 115-b may receive the traffic descriptors from a different network device associated with the PLMN.
  • the application 220-a may transmit a data service request to the modem 215-a.
  • the modem 215-a may communicate a second request (e.g., an application identifier request) to the application 220-a in response to receiving the data service request.
  • the second request may additionally request a decryption key associated with the application identifier.
  • the application 220-a may provide the application identifier of the application 220-a and the decryption key for the application identifier to the modem 215-a.
  • modem 215-a may identify a network slice from a set of available network slices based on the traffic descriptor associated with the application 220-a. That is, the modem 215-a may establish a trusted environment (e.g., to ensure that other applications 220 at the UE 115-b may not identify the application identifier associated with the application 220-a) and decrypt each of the application. The modem 215-a may then decrypt each of the application identifiers included in the set of traffic descriptors and identify the traffic descriptor associated with the application 220-a based on obtaining a decrypted application identifier that matches the application identifier of the application 220-a.
  • a trusted environment e.g., to ensure that other applications 220 at the UE 115-b may not identify the application identifier associated with the application 220-a
  • the modem 215-a may then decrypt each of the application identifiers included in the set of traffic descriptors and identify the traffic descriptor associated with the application 22
  • the modem 215-a may transmit, to the base station 105-b, a data service request that requests data service for the application 220-a according to the traffic descriptor associated with the application 220-a.
  • the UE 115-b may transmit a registration request to register with the network slice (e.g., identified at 325) .
  • the base station 105-b and the UE 115-b may establish the network slice connection for the data service for the application 220-a.
  • the UE 115-b may transmit a PDU establishment request message (e.g., to establish a PDU session associated with the identified network slice) to the base station 105-b and the base station 105-b may respond with as PDU establishment accept message.
  • the base station 105-b may transmit data service traffic to the UE 115-b.
  • the data service traffic may include an encrypted application identifier (e.g., corresponding to the application 220-a) .
  • the UE 115-b may route the data service traffic to the application 220-a based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the modem 215-a may establish a trusted environment to receive the decryption key from application 220-a, and decrypt the encrypted application identifier within the data service traffic using the received decryption key.
  • the modem 215-a may additionally match the decrypted application identifier to the application identifier of the application 220-a.
  • the UE 115-b may route the data service traffic to the application 220-a based on identifying a successful match.
  • the techniques described herein may enhance security for an application and a network slicing instance to reduce the likelihood of a cheating application being able to connect to the network slicing instance to which the cheating application is not authorized to connect.
  • FIG. 4 shows a block diagram 400 of a device 405 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the device 405 may be an example of aspects of a UE 115 as described herein.
  • the device 405 may include a receiver 410, a communications manager 415, and a transmitter 420.
  • the device 405 may also include a processor. Each of these components may be in communication with one another (e.g., via one or more buses) .
  • the receiver 410 may receive information such as packets, user data, or control information associated with various information channels (e.g., control channels, data channels, and information related to encrypting application identifiers, etc. ) . Information may be passed on to other components of the device 405.
  • the receiver 410 may be an example of aspects of the transceiver 720 described with reference to FIG. 7.
  • the receiver 410 may utilize a single antenna or a set of antennas.
  • the communications manager 415 may receive a traffic descriptor that includes an encrypted application identifier corresponding to an application, receive an application identifier of the application and a decryption key for the application identifier, transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor, receive, from the base station, data service traffic for the data service that includes the encrypted application identifier, and route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the communications manager 415 may be an example of aspects of the communications manager 710 described herein.
  • the communications manager 415 may be implemented in hardware, code (e.g., software or firmware) executed by a processor, or any combination thereof. If implemented in code executed by a processor, the functions of the communications manager 415, or its sub-components may be executed by a general-purpose processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described in the present disclosure.
  • DSP digital signal processor
  • ASIC application-specific integrated circuit
  • FPGA field programmable gate array
  • the communications manager 415 may be physically located at various positions, including being distributed such that portions of functions are implemented at different physical locations by one or more physical components.
  • the communications manager 415, or its sub-components may be a separate and distinct component in accordance with various aspects of the present disclosure.
  • the communications manager 415, or its sub-components may be combined with one or more other hardware components, including but not limited to an input/output (I/O) component, a transceiver, a network server, another computing device, one or more other components described in the present disclosure, or a combination thereof in accordance with various aspects of the present disclosure.
  • I/O input/output
  • the transmitter 420 may transmit signals generated by other components of the device 405.
  • the transmitter 420 may be collocated with a receiver 410 in a transceiver module.
  • the transmitter 420 may be an example of aspects of the transceiver 720 described with reference to FIG. 7.
  • the transmitter 420 may utilize a single antenna or a set of antennas.
  • FIG. 5 shows a block diagram 500 of a device 505 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the device 505 may be an example of aspects of a device 405, or a UE 115 as described herein.
  • the device 505 may include a receiver 510, a communications manager 515, and a transmitter 545.
  • the device 505 may also include a processor. Each of these components may be in communication with one another (e.g., via one or more buses) .
  • the receiver 510 may receive information such as packets, user data, or control information associated with various information channels (e.g., control channels, data channels, and information related to encrypting application identifiers, etc. ) . Information may be passed on to other components of the device 505.
  • the receiver 510 may be an example of aspects of the transceiver 720 described with reference to FIG. 7.
  • the receiver 510 may utilize a single antenna or a set of antennas.
  • the communications manager 515 may be an example of aspects of the communications manager 415 as described herein.
  • the communications manager 515 may include a traffic descriptor receiver 520, an application identifier manager 525, a data service request manager 530, a data service traffic receiver 535, and a routing manager 540.
  • the communications manager 515 may be an example of aspects of the communications manager 710 described herein.
  • the traffic descriptor receiver 520 may receive a traffic descriptor that includes an encrypted application identifier corresponding to an application.
  • the application identifier manager 525 may receive an application identifier of the application and a decryption key for the application identifier.
  • the data service request manager 530 may transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor.
  • the data service traffic receiver 535 may receive, from the base station, data service traffic for the data service that includes the encrypted application identifier.
  • the routing manager 540 may route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the transmitter 545 may transmit signals generated by other components of the device 505.
  • the transmitter 545 may be collocated with a receiver 510 in a transceiver module.
  • the transmitter 545 may be an example of aspects of the transceiver 720 described with reference to FIG. 7.
  • the transmitter 545 may utilize a single antenna or a set of antennas.
  • FIG. 6 shows a block diagram 600 of a communications manager 605 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the communications manager 605 may be an example of aspects of a communications manager 415, a communications manager 515, or a communications manager 710 described herein.
  • the communications manager 605 may include a traffic descriptor receiver 610, an application identifier manager 615, a data service request manager 620, a data service traffic receiver 625, a routing manager 630, and a network slice manager 635. Each of these modules may communicate, directly or indirectly, with one another (e.g., via one or more buses) .
  • the traffic descriptor receiver 610 may receive a traffic descriptor that includes an encrypted application identifier corresponding to an application.
  • the traffic descriptor receiver 610 may receive, from the base station, a set of traffic descriptors that includes the received traffic descriptor.
  • each of the set of traffic descriptors may include an encrypted application identifier corresponding to a unique application.
  • the traffic descriptor receiver 610 may receive the traffic descriptor that includes the encrypted application identifier corresponding to the application from a public land mobile network.
  • the traffic descriptor receiver 610 may receive a network slice selection policy indicating a first network slice from a set of available network slices associated with the application.
  • the application identifier manager 615 may receive an application identifier of the application and a decryption key for the application identifier.
  • the application identifier manager 615 may receive the application identifier that is an operating system application identifier.
  • the application identifier manager 615 may establish a connection with a trusted environment.
  • the application identifier manager 615 may receive the decryption key for the application identifier from the trusted environment.
  • the trusted environment is associated with a public land mobile network.
  • the application identifier manager 615 may transmit, to the application, a second request for the application identifier and the decryption key, where receiving the application identifier and the decryption key for the application identifier is based on transmitting the second request.
  • the data service request manager 620 may transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor. In some examples, the data service request manager 620 may transmit the data service request according to the received traffic descriptor based on decrypting the application identifier within the received traffic descriptor using the decryption key. In some cases, the data service request manager 620 may receive a first request for the data service from the application.
  • the data service traffic receiver 625 may receive, from the base station, data service traffic for the data service that includes the encrypted application identifier.
  • the routing manager 630 may route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application. In some examples, the routing manager 630 may match a decrypted application identifier to the application identifier of the application based on decrypting the encrypted application identifier, where routing the data service traffic to the application is based on matching the decrypted application identifier to the application identifier.
  • the network slice manager 635 may identify a first network slice from a set of available network slices based on the received traffic descriptor. In some examples, the network slice manager 635 may transmit a registration request requesting to register with the first network slice of the set of available network slices, where transmitting the data service request is based on transmitting the registration request.
  • FIG. 7 shows a diagram of a system 700 including a device 705 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the device 705 may be an example of or include the components of device 405, device 505, or a UE 115 as described herein.
  • the device 705 may include components for bi-directional voice and data communications including components for transmitting and receiving communications, including a communications manager 710, an I/O controller 715, a transceiver 720, an antenna 725, memory 730, and a processor 740. These components may be in electronic communication via one or more buses (e.g., bus 745) .
  • buses e.g., bus 745
  • the communications manager 710 may receive a traffic descriptor that includes an encrypted application identifier corresponding to an application, receive an application identifier of the application and a decryption key for the application identifier, transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor, receive, from the base station, data service traffic for the data service that includes the encrypted application identifier, and route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the I/O controller 715 may manage input and output signals for the device 705.
  • the I/O controller 715 may also manage peripherals not integrated into the device 705.
  • the I/O controller 715 may represent a physical connection or port to an external peripheral.
  • the I/O controller 715 may utilize an operating system such as or another known operating system.
  • the I/O controller 715 may represent or interact with a modem, a keyboard, a mouse, a touchscreen, or a similar device.
  • the I/O controller 715 may be implemented as part of a processor.
  • a user may interact with the device 705 via the I/O controller 715 or via hardware components controlled by the I/O controller 715.
  • the transceiver 720 may communicate bi-directionally, via one or more antennas, wired, or wireless links as described above.
  • the transceiver 720 may represent a wireless transceiver and may communicate bi-directionally with another wireless transceiver.
  • the transceiver 720 may also include a modem to modulate the packets and provide the modulated packets to the antennas for transmission, and to demodulate packets received from the antennas.
  • the wireless device may include a single antenna 725. However, in some cases the device may have more than one antenna 725, which may be capable of concurrently transmitting or receiving multiple wireless transmissions.
  • the memory 730 may include random-access memory (RAM) and read-only memory (ROM) .
  • the memory 730 may store computer-readable, computer-executable code 735 including instructions that, when executed, cause the processor to perform various functions described herein.
  • the memory 730 may contain, among other things, a basic input/output system (BIOS) which may control basic hardware or software operation such as the interaction with peripheral components or devices.
  • BIOS basic input/output system
  • the processor 740 may include an intelligent hardware device, (e.g., a general-purpose processor, a DSP, a CPU, a microcontroller, an ASIC, an FPGA, a programmable logic device, a discrete gate or transistor logic component, a discrete hardware component, or any combination thereof) .
  • the processor 740 may be configured to operate a memory array using a memory controller.
  • a memory controller may be integrated into the processor 740.
  • the processor 740 may be configured to execute computer-readable instructions stored in a memory (e.g., the memory 730) to cause the device 705 to perform various functions (e.g., functions or tasks supporting encrypting application identifiers) .
  • the code 735 may include instructions to implement aspects of the present disclosure, including instructions to support wireless communications.
  • the code 735 may be stored in a non-transitory computer-readable medium such as system memory or other type of memory. In some cases, the code 735 may not be directly executable by the processor 740 but may cause a computer (e.g., when compiled and executed) to perform functions described herein.
  • FIG. 8 shows a flowchart illustrating a method 800 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the operations of method 800 may be implemented by a UE 115 or its components as described herein.
  • the operations of method 800 may be performed by a communications manager as described with reference to FIGs. 4 through 7.
  • a UE may execute a set of instructions to control the functional elements of the UE to perform the functions described below. Additionally or alternatively, a UE may perform aspects of the functions described below using special-purpose hardware.
  • the UE may receive a traffic descriptor that includes an encrypted application identifier corresponding to an application.
  • the operations of 805 may be performed according to the methods described herein. In some examples, aspects of the operations of 805 may be performed by a traffic descriptor receiver as described with reference to FIGs. 4 through 7.
  • the UE may receive an application identifier of the application and a decryption key for the application identifier.
  • the operations of 810 may be performed according to the methods described herein. In some examples, aspects of the operations of 810 may be performed by an application identifier manager as described with reference to FIGs. 4 through 7.
  • the UE may transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor.
  • the operations of 815 may be performed according to the methods described herein. In some examples, aspects of the operations of 815 may be performed by a data service request manager as described with reference to FIGs. 4 through 7.
  • the UE may receive, from the base station, data service traffic for the data service that includes the encrypted application identifier.
  • the operations of 820 may be performed according to the methods described herein. In some examples, aspects of the operations of 820 may be performed by a data service traffic receiver as described with reference to FIGs. 4 through 7.
  • the UE may route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the operations of 825 may be performed according to the methods described herein. In some examples, aspects of the operations of 825 may be performed by a routing manager as described with reference to FIGs. 4 through 7.
  • FIG. 9 shows a flowchart illustrating a method 900 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the operations of method 900 may be implemented by a UE 115 or its components as described herein.
  • the operations of method 900 may be performed by a communications manager as described with reference to FIGs. 4 through 7.
  • a UE may execute a set of instructions to control the functional elements of the UE to perform the functions described below. Additionally or alternatively, a UE may perform aspects of the functions described below using special-purpose hardware.
  • the UE may receive a traffic descriptor that includes an encrypted application identifier corresponding to an application.
  • the operations of 905 may be performed according to the methods described herein. In some examples, aspects of the operations of 905 may be performed by a traffic descriptor receiver as described with reference to FIGs. 4 through 7.
  • the UE may receive an application identifier of the application and a decryption key for the application identifier.
  • the operations of 910 may be performed according to the methods described herein. In some examples, aspects of the operations of 910 may be performed by an application identifier manager as described with reference to FIGs. 4 through 7.
  • the UE may transmit, to a base station, a data service request according to the received traffic descriptor based on decrypting the application identifier within the received traffic descriptor using the decryption key, where the data service request requests data service for the application according to the received traffic descriptor.
  • the operations of 915 may be performed according to the methods described herein. In some examples, aspects of the operations of 915 may be performed by a data service request manager as described with reference to FIGs. 4 through 7.
  • the UE may receive, from the base station, data service traffic for the data service that includes the encrypted application identifier.
  • the operations of 920 may be performed according to the methods described herein. In some examples, aspects of the operations of 920 may be performed by a data service traffic receiver as described with reference to FIGs. 4 through 7.
  • the UE may route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the operations of 925 may be performed according to the methods described herein. In some examples, aspects of the operations of 925 may be performed by a routing manager as described with reference to FIGs. 4 through 7.
  • FIG. 10 shows a flowchart illustrating a method 1000 that supports encrypting application identifiers in accordance with aspects of the present disclosure.
  • the operations of method 1000 may be implemented by a UE 115 or its components as described herein.
  • the operations of method 1000 may be performed by a communications manager as described with reference to FIGs. 4 through 7.
  • a UE may execute a set of instructions to control the functional elements of the UE to perform the functions described below. Additionally or alternatively, a UE may perform aspects of the functions described below using special-purpose hardware.
  • the UE may receive a traffic descriptor that includes an encrypted application identifier corresponding to an application, where the traffic descriptor indicates a network slice selection policy indicating a first network slice from a set of available network slices associated with the application.
  • the operations of 1005 may be performed according to the methods described herein. In some examples, aspects of the operations of 1005 may be performed by a traffic descriptor receiver as described with reference to FIGs. 4 through 7.
  • the UE may receive an application identifier of the application and a decryption key for the application identifier.
  • the operations of 1010 may be performed according to the methods described herein. In some examples, aspects of the operations of 1010 may be performed by an application identifier manager as described with reference to FIGs. 4 through 7.
  • the UE may transmit, to a base station, a data service request that requests data service for the application according to the received traffic descriptor.
  • the operations of 1015 may be performed according to the methods described herein. In some examples, aspects of the operations of 1015 may be performed by a data service request manager as described with reference to FIGs. 4 through 7.
  • the UE may receive, from the base station, data service traffic for the data service that includes the encrypted application identifier.
  • the operations of 1020 may be performed according to the methods described herein. In some examples, aspects of the operations of 1020 may be performed by a data service traffic receiver as described with reference to FIGs. 4 through 7.
  • the UE may route the data service traffic to the application based on decrypting the encrypted application identifier using the decryption key to obtain the application identifier of the application.
  • the operations of 1025 may be performed according to the methods described herein. In some examples, aspects of the operations of 1025 may be performed by a routing manager as described with reference to FIGs. 4 through 7.
  • LTE, LTE-A, LTE-A Pro, or NR may be described for purposes of example, and LTE, LTE-A, LTE-A Pro, or NR terminology may be used in much of the description, the techniques described herein are applicable beyond LTE, LTE-A, LTE-A Pro, or NR networks.
  • the described techniques may be applicable to various other wireless communications systems such as Ultra Mobile Broadband (UMB) , Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi) , IEEE 802.16 (WiMAX) , IEEE 802.20, Flash-OFDM, as well as other systems and radio technologies not explicitly mentioned herein.
  • UMB Ultra Mobile Broadband
  • IEEE Institute of Electrical and Electronics Engineers
  • Wi-Fi Institute of Electrical and Electronics Engineers
  • WiMAX IEEE 802.16
  • IEEE 802.20 Flash-OFDM
  • Information and signals described herein may be represented using any of a variety of different technologies and techniques.
  • data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
  • a general-purpose processor may be a microprocessor, but in the alternative, the processor may be any processor, controller, microcontroller, or state machine.
  • a processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration) .
  • the functions described herein may be implemented in hardware, software executed by a processor, firmware, or any combination thereof. If implemented in software executed by a processor, the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Other examples and implementations are within the scope of the disclosure and appended claims. For example, due to the nature of software, functions described herein may be implemented using software executed by a processor, hardware, firmware, hardwiring, or combinations of any of these. Features implementing functions may also be physically located at various positions, including being distributed such that portions of functions are implemented at different physical locations.
  • Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another.
  • a non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special purpose computer.
  • non-transitory computer-readable media may include RAM, ROM, electrically erasable programmable ROM (EEPROM) , flash memory, compact disk (CD) ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that may be used to carry or store desired program code means in the form of instructions or data structures and that may be accessed by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor.
  • any connection is properly termed a computer-readable medium.
  • the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL) , or wireless technologies such as infrared, radio, and microwave
  • the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of computer-readable medium.
  • Disk and disc include CD, laser disc, optical disc, digital versatile disc (DVD) , floppy disk and Blu-ray disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above are also included within the scope of computer-readable media.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

L'invention concerne des procédés, des systèmes et des dispositifs pour des communications sans fil. Un équipement utilisateur (UE) peut recevoir un descripteur de trafic qui comprend un identifiant d'application crypté correspondant à une application. L'UE peut en outre recevoir un identifiant d'application de l'application et une clé de décryptage pour l'identifiant d'application. Par exemple, une application demandant un service de données peut fournir l'identifiant de l'application et la clé de décryptage pour l'identifiant d'application à l'UE. L'UE peut ensuite transmettre, à une station de base, une demande de service de données qui demande un service de données pour l'application selon le descripteur de trafic reçu. L'UE peut recevoir, de la station de base, un trafic de service de données pour le service de données qui comprend l'identifiant d'application crypté. L'UE peut acheminer le trafic de service de données vers l'application sur la base du décryptage de l'identifiant d'application crypté à l'aide de la clé de décryptage pour obtenir l'identifiant d'application de l'application.
PCT/CN2020/091987 2020-05-25 2020-05-25 Cryptage d'identifiants d'application Ceased WO2021237391A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2020/091987 WO2021237391A1 (fr) 2020-05-25 2020-05-25 Cryptage d'identifiants d'application

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2020/091987 WO2021237391A1 (fr) 2020-05-25 2020-05-25 Cryptage d'identifiants d'application

Publications (1)

Publication Number Publication Date
WO2021237391A1 true WO2021237391A1 (fr) 2021-12-02

Family

ID=78745381

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/091987 Ceased WO2021237391A1 (fr) 2020-05-25 2020-05-25 Cryptage d'identifiants d'application

Country Status (1)

Country Link
WO (1) WO2021237391A1 (fr)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114501593A (zh) * 2021-12-29 2022-05-13 西安广和通无线软件有限公司 网络切片接入方法、装置、系统和存储介质
CN116761168A (zh) * 2023-07-05 2023-09-15 中国电信股份有限公司技术创新中心 一种分配网络切片的方法、系统及电子设备
EP4173228A4 (fr) * 2020-06-28 2024-03-13 Qualcomm Incorporated Mise en évidence de découpage de réseau
WO2024065159A1 (fr) * 2022-09-27 2024-04-04 Qualcomm Incorporated Extension d'un identifiant d'application de canal de données avec une étiquette de canal de données

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150365227A1 (en) * 2014-06-11 2015-12-17 International Business Machines Corporation Shared security utility appliance for secure application and data processing
WO2019192672A1 (fr) * 2018-04-03 2019-10-10 Lenovo (Singapore) Pte. Ltd. Session pdu pour détection de trafic chiffrée
US20190386894A1 (en) * 2017-02-28 2019-12-19 Huawei Technologies Co., Ltd. Service management method and apparatus thereof
US20200146077A1 (en) * 2017-06-16 2020-05-07 Convida Wireless, Llc Small data transfer, data buffering, and data management as a service in a communications network

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150365227A1 (en) * 2014-06-11 2015-12-17 International Business Machines Corporation Shared security utility appliance for secure application and data processing
US20190386894A1 (en) * 2017-02-28 2019-12-19 Huawei Technologies Co., Ltd. Service management method and apparatus thereof
US20200146077A1 (en) * 2017-06-16 2020-05-07 Convida Wireless, Llc Small data transfer, data buffering, and data management as a service in a communications network
WO2019192672A1 (fr) * 2018-04-03 2019-10-10 Lenovo (Singapore) Pte. Ltd. Session pdu pour détection de trafic chiffrée

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
QUALCOMM INCORPORATED: "Clarifications and initial evaluation for Solution 7", 3GPP DRAFT; S2-185091_ENTRADE_SOLUTION, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. Newport Beach, USA; 20180528 - 20180601, 27 May 2018 (2018-05-27), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051448596 *

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4173228A4 (fr) * 2020-06-28 2024-03-13 Qualcomm Incorporated Mise en évidence de découpage de réseau
US12592857B2 (en) 2020-06-28 2026-03-31 Qualcomm Incorporated Network slicing enhancement
CN114501593A (zh) * 2021-12-29 2022-05-13 西安广和通无线软件有限公司 网络切片接入方法、装置、系统和存储介质
CN114501593B (zh) * 2021-12-29 2024-04-05 西安广和通无线软件有限公司 网络切片接入方法、装置、系统和存储介质
WO2024065159A1 (fr) * 2022-09-27 2024-04-04 Qualcomm Incorporated Extension d'un identifiant d'application de canal de données avec une étiquette de canal de données
CN116761168A (zh) * 2023-07-05 2023-09-15 中国电信股份有限公司技术创新中心 一种分配网络切片的方法、系统及电子设备

Similar Documents

Publication Publication Date Title
US20210345104A1 (en) Relay sidelink communications for secure link establishment
US11792812B2 (en) Search space configurations for multi-component carrier scheduling
US12457623B2 (en) Resource block set allocation for subband full duplex operation
US12615609B2 (en) Network slicing traffic descriptor encoding
US12446079B2 (en) Methods to establish a protocol data unit session
WO2021237391A1 (fr) Cryptage d'identifiants d'application
US20240260075A1 (en) Techniques for performing quality of service management for sidelink communications
TWI899212B (zh) 用於處置針對進化封包資料閘道wi-fi存取的切片化計費的方法
WO2021151223A1 (fr) Techniques de planification inter-porteuse pour systèmes de communication sans fil
US20240334320A1 (en) Techniques for switching between network slices
US20240340937A1 (en) Supplementary uplink switching for switching multiple radio frequency bands
US11690094B2 (en) Techniques for traffic steering between access links and sidelinks in wireless communications systems
CN117203910A (zh) 用于波束管理的参考信号模式
US12432799B2 (en) Techniques for data transmission management
US12356371B2 (en) Techniques for configuring component carriers for sidelink communications
US12047910B2 (en) Enhanced paging in wireless backhaul networks
US11870617B2 (en) Multilevel coding for physical layer security
WO2022052037A1 (fr) Configuration de politiques de sélection de route
WO2021232420A1 (fr) Désactivation de double connectivité au niveau d'un équipement d'utilisateur de module d'identité multi-abonné
US20250056602A1 (en) Channel occupancy time transmissions with a sidelink-synchronization signal block gap slot
WO2022032560A1 (fr) Procédure de sélection de tranche de réseau flexible
WO2022047690A1 (fr) Établissement d'une connexion de découpage en tranches de réseau
WO2021253283A1 (fr) Techniques de récupération de service pour systèmes de communication sans fil
WO2021203375A1 (fr) Connectivité avec des cellules non autonomes
WO2025038175A1 (fr) Transmissions de temps d'occupation de canal avec créneau d'espace de bloc de signal de synchronisation de liaison latérale

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20937818

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20937818

Country of ref document: EP

Kind code of ref document: A1