Methods for secondary authentication of a user equipment, user equipment and network equipment
Patent Information
- Application Number
- BR112019014670
- Authority / Receiving Office
- BR · BR
- Patent Type
- Patents
- Current Assignee / Owner
- Publication Date
- 2026-08-11
Smart Images

Figure 00000041_0000 
Figure 00000042_0000 
Figure 00000043_0000
Abstract
Description
1 / 34 Methods for secondary authentication of a user device, user equipment, and network equipment. RELATED ORDERS
[001] This application claims priority to U.S. Provisional Patent Application Serial Number 62 / 451,645 filed January 27, 2017, the entire contents of which are incorporated herein by reference. FIELD OF TECHNIQUE
[002] This application generally relates to a wireless communication network, and specifically relates to the secondary authentication of a user device configured for use on a wireless communication network. FUNDAMENTALS
[003] A wireless communication network conventionally authenticates a user device based on credentials that are pre-provisioned by the network operator and securely stored with the user device. Support for alternative ways of authenticating a user device would allow the wireless communication network to, in turn, support a variety of potential use cases. For example, this would allow factory owners or enterprises to leverage their own credential and identity management systems for authentication and network security access.
[004] Supporting alternative authentication methods proves technically challenging, however. Many authentication methods have stringent recommendations and requirements on the transport network. Furthermore, relying on Internet Protocol (IP) connectivity to support alternative authentication methods proves inflexible and undermines the separation between the control plane and the user plane. Petition 870250017049, dated 28 / 02 / 2025, page 15 / 55 2 / 34 SUMMARY
[005] One or more embodiments herein exploit an Extensible Authentication Protocol (EAP) between a user device and a control plane function (e.g., a session management function, SMF) to provide authentication of the user device. Such authentication may be, for example, secondary authentication that is performed in addition to (e.g., after) primary authentication of the user device. Regardless, exploiting the EAP in this manner may be advantageous because it supports different types of authentication methods, does not depend on IP connectivity or a specific type of access network, and / or is control plane-based in order to maintain separation between the control plane and the user plane.
[006] More specifically, the embodiments included herein include a method for secondary authentication of a user device. The method may comprise receiving, by the user device, an Extensible Authentication Protocol (EAP) request from a Session Management Function (SMF) that serves as an EAP authenticator for secondary authentication of the user device, wherein secondary authentication is authentication of the user device in addition to the primary authentication of the user device. The method may also comprise, responsive to the EAP request, transmitting an EAP response from the user device to the SMF.
[007] The embodiments herein also include a method for secondary authentication of a user device. The method may comprise transmitting an Extensible Authentication Protocol (EAP) request from a Session Management Function (SMF) to a user device, wherein the SMF serves as an EAP authenticator for secondary authentication of the Petition 870250017049, dated 28 / 02 / 2025, page 16 / 55 3 / 34 user equipment, where secondary authentication is authentication of the user equipment in addition to the primary authentication of the user equipment. The method may also include, responsive to the EAP request, receiving an EAP response from the user equipment in the SMF.
[008] In some embodiments, the SMF also serves as an EAP server that executes an EAP authentication method for secondary authentication of the user device. In other embodiments, the SMF is configured to forward the EAP request and the EAP response between the user device and an EAP server that executes an EAP authentication method for the EAP authenticator.
[009] Still other embodiments here include a method for secondary authentication of a user device. The method may include transmitting an Extensible Authentication Protocol (EAP) request from an EAP server to a user device via a Session Management Function (SMF), wherein the SMF serves as a pass-through EAP authenticator for secondary authentication of the user device, wherein secondary authentication is authentication of the user device in addition to the primary authentication of the user device, and wherein the EAP server is configured to execute an EAP authentication method for the EAP authenticator. The method may further comprise, responsive to the EAP request, receiving on the EAP server via the SMF an EAP response from the user device.
[0010] In some embodiments, the user equipment and the SMF are configured for use on a wireless communication network, where the EAP server is on a data network with which the user equipment requests a user plane session, where the secondary authentication of the user equipment is authentication of the user equipment for Petition 870250017049, dated 28 / 02 / 2025, page 17 / 55 4 / 34 establish the user plan session, and in which secondary authentication is delegated by the wireless communication network to the data network.
[0011] In some embodiments, the EAP request and the EAP response are transmitted between the SMF and the EAP server via a user plane function selected by the SMF. In one embodiment, for example, the user plane function serves as a proxy for the EAP server. In another embodiment, the user plane function serves as a router through which the EAP request and the EAP response are transparently transmitted to the user plane function.
[0012] In any of these modes, the EAP request and the EAP response can be encapsulated within the respective non-access stratum protocol (NAS) messages between the SMF and the UE.
[0013] In some modes, transmission and reception are performed after primary authentication of the user equipment by a security anchor function in a core network.
[0014] In some embodiments, a core network comprises multiple different network slices respectively dedicated to different services, wherein secondary authentication of the user equipment comprises slice-specific authentication of the user equipment to access a specific network slice of the core network.
[0015] In some modalities, the method also includes, based on the successful secondary authentication of the user equipment, obtaining a security key shared between the user equipment and the SMF.
[0016] In some embodiments, a session establishment request transmitted from the user device triggers secondary authentication of the user device. In one such embodiment, the session establishment request includes a secondary identity of the device. Petition 870250017049, dated 28 / 02 / 2025, page 18 / 55 5 / 34 user used for secondary authentication. Alternatively or additionally, a session establishment response transmitted to the user's equipment includes an EAP success message indicating successful secondary authentication or an EAP failure message indicating failed secondary authentication.
[0017] In some embodiments, the method also involves linking the secondary authentication of the user's equipment to a channel through which the secondary authentication is performed.
[0018] In some embodiments, the method further comprises deriving, based on the successful secondary authentication of the user equipment, a security key shared between the user equipment and the SMF, wherein said derivation comprises deriving the security key as a function of link information associated with a channel over which secondary authentication is performed. In such an embodiment, said link information comprises one or more of: information identifying a type of access network through which the user equipment accesses a wireless communication network; information identifying a type of core network of the wireless communication network; information identifying a slice of core network to which the user equipment is requesting access; and information identifying a type of slice of core network to which the user equipment is requesting access.
[0019] In some modes, SMF is included in a 5G network.
[0020] The modalities also include devices, computer programs, and corresponding carriers.
[0021] Some modalities here may therefore utilize EAP (rfc3748) for authentication between a user device (UE) and a potentially external authentication, authorization, and accounting (AAA) server where Petition 870250017049, dated 28 / 02 / 2025, p. 19 / 55 6 / 34 The SMF, a session management function in the 5G core, endorses the role of the EAP authenticator. EAP payloads can be transported via the Non-Access Stratum (NAS) protocol between the UE and the SMF. The NAS protocol is the highest stratum of the control plane. The NAS protocol can be divided into NAS Mobility Management (NAS-MM) and NAS Session Management (NAS-SM), and NAS-SM messages are transported by NAS-MM in a transparent container. The SMF interacts with a backend AAA server possibly located in an external domain. EAP packets can be transported via AAA between the SMF and this external server in direct communication as per the Protocol Configuration Options (PCO) option or alternatively transparently over the User Plane Function (UPF). Another possibility would be that the EAP server is not used, and the SMF (i.e., the EAP authenticator) executes the EAP method.
[0022] Some modes therefore utilize EAP, which provides support for many authentication methods such as Transport Layer Security (EAP-TLS), EAP Authentication and Key Agreement (EAP-AKA), EAP Tunneled TLS (EAP-TTLS), and EAP Protected EAP (EAP-PEAP). One or more modes are based on encapsulating EAP messages in the NAS protocol and are therefore agnostic to the type of access network (AN). Some modes are based on the control plane and are therefore agnostic to the type of PDU session, i.e., Internet Protocol (IP), non-IP, etc. Using EAP, some modes support different types of credentials and authentication methods. EAP exchange would benefit from the protection of over-the-air interfaces provided by the NAS protocol. Furthermore, EAP exchange can result in the establishment of security keys to be used, for example, in protecting the user plane towards the established data network. BRIEF DESCRIPTION OF THE DRAWINGS Petition 870250017049, dated 28 / 02 / 2025, p. 20 / 55 7 / 34
[0023] Figure 1 is a block diagram of a wireless communication network according to one or more modes.
[0024] Figure 2 is a block diagram of a 5G network according to some modalities.
[0025] Figure 3 is a call flow diagram for secondary authentication of a UE according to some modalities.
[0026] Figure 4 is a block diagram of a protocol stack for exchanging EAP messages between a UE and AAA server according to some modes.
[0027] Figure 5 is a block diagram of a protocol stack for exchanging EAP messages between an SMF and an AAA server according to some modes.
[0028] Figure 6 is a logical flow diagram of a method performed by a user device according to some modalities.
[0029] Figure 7 is a logical flow diagram of a method performed by a control plane function (e.g., SMF) according to some embodiments.
[0030] Figure 8 is a logical flow diagram of a method performed by a WBS server according to some modalities.
[0031] Figure 9A is a block diagram of a user device according to some modalities.
[0032] Figure 9B is a block diagram of a user device according to other modalities.
[0033] Figure 10A is a block diagram of the control plane equipment according to some embodiments.
[0034] Figure 10B is a block diagram of the control plane equipment according to other embodiments. Petition 870250017049, dated 28 / 02 / 2025, page 21 / 55 8 / 34
[0035] Figure 11A is a block diagram of an EAP server according to some modalities.
[0036] Figure 11B is a block diagram of an EAP server according to other modalities. DETAILED DESCRIPTION
[0037] Figure 1 illustrates a wireless communication network (e.g., a 5G network) according to one or more modalities. The network includes an access network 12 and a core network. The core network includes one or more control plane functions, one of which is shown as control plane function 14. The core network may include, for example, a control plane function in the form of a session management function (SMF) responsible for session management and a separate control plane function in the form of an access and mobility management function (AMF) responsible for mobility management. In any case, the core network also includes a user plane function 16.
[0038] As shown in Figure 1, a user device 18 can request a session 20 (e.g., a user plane session or a packet data unit, PDU, session) with a data network 22 (e.g., providing network operator services, Internet access, or third-party services). The data network 22 can be internal or external to the wireless communication network. Regardless, the user plane function 16 is configured to forward user plane traffic for this session, while the control plane function(s) are configured to control this session (e.g., via control signaling for this session).
[0039] One or more modalities refer to the authentication of user equipment 18, for example, authentication of user equipment 18 to establish the session 20 with the data network 22. Authentication Petition 870250017049, dated 28 / 02 / 2025, page 22 / 55 9 / 34 may be of a secondary nature, in the sense that authentication occurs in addition to another so-called primary authentication of the user equipment (for example, which may use pre-provisioned credentials and / or be performed by a security anchor function). In some embodiments, for example, the user equipment 12 requesting the session 20 with the data network 22 triggers such secondary authentication, for example, after the primary authentication. This secondary authentication may even be performed by, controlled by, and / or delegated to this data network 16.
[0040] One or more embodiments herein exploit an Extensible Authentication Protocol (EAP) between user device 18 and a control plane function 14 (e.g., a session management function, SMF) in the core network in order to provide secondary authentication of user device 18. The control plane function 14 in this respect may serve as an EAP authenticator 24 for secondary authentication. User device 18 may in turn serve as a peer for EAP authentication.
[0041] In some embodiments, control plane function 14 also serves as an EAP server that actually executes an EAP authentication method for secondary authentication. In other embodiments, an EAP server 26 separate from control plane function 14 (as an EAP authenticator) executes an EAP authentication method for the EAP authenticator. The EAP server 26 may, for example, be located on data network 22 as shown in Figure 1. An EAP server 26 separate from the EAP authenticator may be referred to as a backend authentication server or simply an authentication server. Separating the EAP server from control plane function 14 means that, instead of requiring control plane function 14 to support every authentication method provided by Petition 870250017049, dated 28 / 02 / 2025, page 23 / 55 10 / 34 user equipment 18, for example, the EAP flexibly allows the control plane function 14 to act as a gateway for some or all of the authentication methods that are supported by the EAP server 26. This in turn allows secondary authentication to be delegated to the data network 22 in some modes. Consequently, user equipment 18 can perform an authentication method or procedure with the EAP server 26 through, or as established by, the control plane function 14. This EAP-based approach can prove advantageous insofar as it supports different types of authentication methods, does not depend on IP connectivity or a specific type of access network, and / or is control plane-based to maintain separation between the control plane and the user plane.
[0042] With control plane function 14 serving as EAP authenticator 24 for secondary authentication of user device 18, user device 18 and control plane function 14 can engage in an EAP authentication exchange. As shown in Figure 1, this exchange can involve control plane function 14 transmitting an EAP request 28 to user device 18, and user device 18 in turn receiving the EAP request 28 from control plane function 14. This EAP request 28 can request any of several different possible types of information requested from user device 18 (e.g., an identity, an MD5 challenge, etc.). The type of information requested can be indicated by a type field in the request 28.In any case, the EAP 28 request may request information as part of the negotiation of which authentication method should be used for secondary authentication of user equipment 18.
[0043] Responding to EAP request 28, user equipment 18 Petition 870250017049, dated 28 / 02 / 2025, page 24 / 55 11 / 34 (as an EAP pair) can transmit an EAP response 30 to control plane function 14 (as an EAP authenticator 24). The EAP response 30 can, for example, include the type of information indicated by the type field in the EAP request 28.
[0044] One or more additional sequences of requests and responses may continue in a similar manner. This may continue up to control plane function 14 as the EAP authenticator cannot authenticate user equipment 18 (for example, due to an unacceptable EAP response to one or more EAP requests), or up to control plane function 14 as the EAP authenticator determines that successful authentication has occurred.
[0045] In some modes, for example, the transmission from the user device of a request to establish session 20 triggers secondary authentication of the user device 18. In this case, a session establishment response may in turn be transmitted to the user device and include either an EAP success message indicating successful secondary authentication or an EAP failure message indicating failure of secondary authentication.
[0046] In these and other modalities, the EAP 28 request and the EAP 30 response can be encapsulated within the respective non-access stratum (NAS) protocol messages. NAS in this respect can be the highest stratum of the control plane. Thus encapsulated, the EAP 28 request and the EAP 30 response can be communicated between the user equipment 18 and the control plane function 14 independently of the type of access network 12.
[0047] In configurations involving EAP server 26 (for example, on data network 22 as shown in Figure 1) for secondary authentication, the Petition 870250017049, dated 28 / 02 / 2025, page 25 / 55 Control plane function 14 can forward EAP request 28 and EAP response 30 between user device 18 and EAP server 26. Control plane function 14 can, for example, inspect transmitted or received EAP messages in order to determine whether or where to forward these messages. In any case, EAP server 26 can transmit EAP request 28 to user device 18 through control plane function 14 as an EAP authenticator, and, responsive to the EAP request, can receive EAP response 30 from user device 18 through control plane function 14.
[0048] In some embodiments, the EAP request 28 and the EAP response 30 are transmitted between control plane function 14 and the EAP server 26 through the user plane function 16, for example, which can be selected by the control plane function 14. In some embodiments, the user plane function 16 can serve as a proxy for the EAP server 26. In other embodiments, the user plane function 16 serves as a router through which the EAP request 28 and the EAP response 30 are transparently transmitted to the user plane function 16.
[0049] These and other modalities may therefore allow the wireless communication network to delegate to the data network 22 the secondary authentication of the user equipment 18 (for example, to authenticate the establishment of the user equipment session 20 with the data network 22). Especially where the data network 22 implements the EAP server 26 which actually executes the authentication method used for such authentication, this may mean that the wireless communication network flexibly and generically supports different authentication methods.
[0050] Alternatively or additionally, the core network in some embodiments may comprise multiple different network slices. Petition 870250017049, dated 28 / 02 / 2025, p. 26 / 55 13 / 34 respectively dedicated to different services. In this case, the secondary authentication of user equipment 18 may comprise a slice-specific authentication of user equipment 18 to access a specific network slice of the core network. Similarly, then, the wireless communication network may generically and flexibly support different authentication methods (for example, which may be different for different network slices).
[0051] One or more modalities will now be described in the context of 5G (known as Next Generation, NG) as being developed by 3GPP. 5G aims (among other things) to separate the control plane from the user plane. The control plane is responsible for controlling and transmitting signaling information, while the user plane is responsible for routing user traffic. Separating the control plane involves extracting the control plane functions from a gateway to leave a simpler, user plane node. A gateway is thus divided into S / PGW-U and S / PGWC components that can scale independently, where SGW-U is the component of a server gateway (SGW) that handles user plane functions, PGW-U is the component of a packet gateway (PGW) that handles user plane functions, SGW-C is the component of an SGW that handles control plane functions, and PGW-C is the component of a PGW that handles control plane functions.In this way, the control plane, and all associated complex interactions, can be centralized, while the user plane is distributed across the IP service mesh and scaled as required by the traffic load.
[0052] In addition, 5G enables the virtualization of network functions and software-defined networking. The 5G system architecture should leverage service-based interactions between the network functions of the Plan. Petition 870250017049, dated 28 / 02 / 2025, page 27 / 55 14 / 34 Control (CP) when identified.
[0053] Furthermore, 5G aims to modularize the function design, for example, to allow for flexible and efficient network slicing. In addition, whenever applicable, procedures (i.e., the set of interactions between network functions) are defined as services, so that their reuse is possible.
[0054] Figure 2 in this regard describes a baseline architecture for the NG. The architecture includes several network functions. The control plane functions include a session management function (SMF), an access and mobility management function (AMF), a policy control function (PCF), an authentication server function (AUSF), and unified data management (UDM).
[0055] An SMF may include some or all of the following functionalities. Some or all of the SMF functions may be supported in a single instance of an SMF. SMF functionality includes session management (e.g., session establishment, modification, and release, including maintaining tunnel between UPF and access network node), allocation and management of UE IP addresses (including optional authorization), selection and control of the UP function, configuration of traffic routing on the UPF to route traffic to the appropriate destination, termination of interfaces towards policy control functions, control of part of the application of policy and quality of service (QoS), lawful interception (for SM events and interface to lawful interception system), termination of SM parts of NAS messages, notification of downlink data, initiation of AN-specific SM information, sent via AMF over N2 to AN,Determination of service continuity and session (SSC) mode for a session (per IP type PDU session), roaming functionality, local application handling to enforce QoS service level agreements (SLAs) (visited public terrestrial mobile network, Petition 870250017049, dated 28 / 02 / 2025, page 28 / 55 15 / 34 VPLMN), data collection and billing interface (VPLMN), lawful interception (in VPLMN for SM events and the interface for LI system), and support for interaction with external DN for transporting PDU session authorization / authentication signaling via external DN.
[0056] On the other hand, the Access and Mobility Management (AMF) function may include some or all of the following functionalities. Some or all of the AMF functions may be supported in a single instance of an AMF: radio access network (RAN) CP interface termination (N2), NAS termination (N1), NAS encryption and integrity protection, log management, connection management, accessibility management, mobility management, lawful interception (for AMF events and interface to LI System), transparent proxy for SM message routing, access authentication, access authorization, security anchor function (SEA or SEAF), and Security Context Management (SCM) which receives a key from the SEA that it uses to derive specific keys from the access network.With particular attention to SEA, it interacts with the Authentication Server Function (AUSF) and the UE, and receives the intermediate key that was established as a result of the UE authentication process. In the case of USIM-based authentication, the AMF retrieves the security material from the AUSF.
[0057] A User Plane Function (UPF) may include some or all of the following functionalities. Some or all of the UPF functions may be supported in a single UPF instance: an anchor point for Intra / Inter radio access technology (RAT) mobility (when applicable), external PDU session point for Data Network interconnection, packet routing and forwarding, packet inspection and part of the user plane policy rule enforcement, lawful interception (UP collection), traffic usage reports, uplink classifier for Petition 870250017049, dated 28 / 02 / 2025, page 29 / 55 16 / 34 support routing of traffic flows to a data network, branch point to support PDU session from multiple databases, QoS handling for the user plane, e.g. packet filtering, switching, application of uplink / downlink rate, uplink traffic verification (SDF for QoS flow mapping), transport layer packet marking on the uplink and downlink, and downlink packet buffering and downlink data notification triggering.
[0058] Any of these network functions can be applied either as a network element on dedicated hardware, or as a software instance running on dedicated hardware, or as a virtualized function instantiated on an appropriate platform, for example on a cloud infrastructure.
[0059] Among the new features of NG Systems is the concept of Network Slicing. A Network Slice (NS) is basically an instance of a core network dedicated to providing a specific service. This will allow operators to handle this wide variety of new use cases, each with different service requirements in terms of Quality of Service (QoS). For example, an operator could be running a slice for usual mobile broadband (MBB) services, in parallel with a mission-critical slice for public safety services (push to speak mission-critical, MCPTT) requiring very low latency, and in parallel with an Internet of Things (IoT) slice for electricity meters with very low bandwidth.
[0060] To support various types of services, operators will use multiple core networks implemented as network slices in a common IP services infrastructure. The idea, shown in Figure 2, is to create instances of networks of Petition 870250017049, dated 28 / 02 / 2025, page 30 / 55 17 / 34 virtual cores (or slices) dedicated to different services. Each slice can be optimized for the traffic profile and business context of the associated service, for example, IoT, public safety, mobile virtual network operator (MVNO), connected car, voice over WiFi, or enterprise services. Network slices can be two-dimensional in the sense that they can be service-specific and customer-specific.
[0061] 5G is expected to support many new scenarios and use cases and be an enabler for IoT. NG systems are expected to provide connectivity to a wide range of new devices such as sensors, smart wearables, vehicles, machines, etc. Flexibility would then be a key property in NG Systems. This is reflected in the security requirement for network access which requires support for alternative authentication methods and different types of credentials than the usual AKA credentials pre-provisioned by the operator and securely stored on the universal integrated circuit card (UICC). This would allow factory owners or enterprises to leverage their own identity and credential management systems for authentication and network security access.
[0062] 5G can decouple authentication and authorization procedures for accessing different network slices (NS). One possible scenario is as follows. For a NG-UE to access a particular NS, the operator can first perform primary (usual) authentication for initial network access towards AUSF / UDM via AMF, followed by NS-specific secondary authentication possibly under the control of a third party. This assumes trust between the third-party service provider and the mobile network operator (MNO) that, for example, is offering access and transport services to that third party on a dedicated network slice instance.
[0063] The so-called Encrypted Option Request and the use of an element of Petition 870250017049, dated 28 / 02 / 2025, page 31 / 55 18 / 34 Information referred to as Protocol Configuration Options (PCO) may be relevant to the scenario described above. The PCO can transfer Password Authentication Protocol (PAP) / Challenge Handshake Protocol (CHAP) usernames and passwords to the Packet Data Network Gateway (PDN-GW) which executes them via an AAA server (possibly located in an external domain) for access authorization. Since this information is sensitive and needs to be protected, if the UE intends to send PCO that requires encryption (e.g., PAP / CHAP usernames and passwords), the UE should set the Encrypted Options Transfer Flag in the Attachment Request message and send the PCO only after completing the authentication and security configuration of the NAS.
[0064] Among the limitations of this mechanism for use or extension in NG systems are the following.
[0065] First, the mechanism is very limited in terms of possible authentication methods. Currently, there is only support for PAP and CHAP. But since PAP is obsolete from a security standpoint, we are left with only CHAP.
[0066] Second, to support other methods and use the PCO information element for transporting authentication information, it would be necessary to specify special messages between the MME and the S-GW and the S-GW and the PDN-GW dedicated to this purpose. This is to handle authentication methods that require more than just a round trip.
[0067] Furthermore, it is difficult to see how this mechanism would fit into the Next Generation architecture that will be broken down further down the line. In fact, taking into account the new architectural features (TR 23.799), we can say that there will probably be more leaps along the way between UE and PDN-GW, for example in relation to the ongoing work on splitting the MME into an AM and an SM function (TR 23.799) and plane separation. Petition 870250017049, dated 28 / 02 / 2025, page 32 / 55 Control and User Planner (CUPS) 19 / 34 works for the Control and User Planner division (TR 23.714). This implies more overhead and signaling on the CN.
[0068] Finally, this mechanism is a workaround because there is no direct protocol between the UE and the PDN-GW. Making it generic enough to support other authentication methods would be technically challenging, especially since many methods have strict recommendations and requirements regarding transport.
[0069] One or more modalities address some of these and / or other challenges for secondary authentication through the use of EAP. EAP is specified in IETF RFC 3748. EAP is an authentication framework that supports multiple authentication methods.
[0070] One of the advantages of the EAP architecture is its flexibility. EAP is used to select a specific authentication mechanism, typically after the authenticator requests more information to determine the specific authentication method to be used. Instead of requiring the authenticator to be updated to support each new authentication method, EAP allows the use of a backend authentication server, which can implement some or all authentication methods, with the authenticator acting as a pass-through for some or all methods and peers. The EAP protocol can support multiple authentication mechanisms without having to pre-negotiate a particular one.
[0071] In EAP nomenclature, an EAP authenticator is the end of the link initiating EAP authentication. A peer is the end of the link that responds to the authenticator. A backend authentication server is an entity that provides an authentication service for an authenticator. When used, this server typically executes EAP methods for the authenticator. An EAP server is the entity that finalizes the EAP authentication method with the peer. In the case Petition 870250017049, dated 28 / 02 / 2025, page 33 / 55 In 20 / 34 mode, where no backend authentication server is used, the EAP server is part of the authenticator. In the case where the authenticator operates in pass-through mode, the EAP server is located on the backend authentication server. Successful authentication is an exchange of EAP messages, as a result of which the authenticator decides to allow access by the peer, and the peer decides to use that access. The authenticator's decision typically involves both authentication and authorization aspects; the peer may successfully authenticate the authenticator, but access may be denied by the authenticator due to policy recommendations.
[0072] The EAP authentication exchange proceeds as follows. The authenticator sends a request to authenticate the peer. The request has a Type field to indicate what is being requested. Examples of Request Types include Identity, MD5 Challenge, etc. Typically, the authenticator will send an initial Identity Request; however, an initial identity request is not required and can be skipped.
[0073] The pair sends a Response packet in reply to a valid Request. Just like the Request packet, the Response packet contains a Type field, which corresponds to the Type field of the Request.
[0074] The authenticator sends an additional request packet, and the peer responds with a reply.
[0075] The Request and Response sequence continues as long as necessary. The conversation continues until the authenticator cannot authenticate the peer (Unacceptable Responses to one or more Requests), in which case the authenticator implementation MUST transmit an EAP Failure (Code 4). Alternatively, the authentication conversation may continue until the authenticator determines that a successful authentication has occurred, in which case the authenticator MUST transmit an EAP success (Code 3). Petition 870250017049, dated 28 / 02 / 2025, p. 34 / 55 21 / 34
[0076] When operating as a pass-through authenticator, an authenticator performs checks on the Code, Identifier, and Length fields. It forwards EAP packets received from the peer and destined for its authenticator layer to the back-end authentication server; packets received from the back-end authentication server destined for the peer are forwarded to it.
[0077] Figure 3 illustrates the message flow involving primary and secondary authentication, using EAP, according to some modalities.
[0078] Step 1: The EU sends a registration request.
[0079] Step 2: The primary authentication procedure is performed between the EU and SEAF. After successful authentication, the primary identity (e.g., International Mobile Subscriber Identifier, IMSI) is verified and the next steps are executed.
[0080] Step 3: NAS security is configured, that is, CP security. From now on all NAS messages are confidentially and fully protected.
[0081] Step 4: The handling of the PDU session establishment request is done in two steps. In step 4a, the UE sends the PDU session establishment request to AMF. This message contains the primary identity and may optionally carry the secondary identity used later in the EAP secondary authentication. The request has integrity and optionally confidentiality protected between the UE and AMF. AMF verifies that the message originates from the UE that was authenticated in step 2, and forwards it including the verified identity information. In step 4b, the SMF receives a PDU session establishment request from AMF. If the SMF has not performed secondary authentication for the primary identity, and has a local policy to authenticate UEs, the SMF Petition 870250017049, dated 28 / 02 / 2025, page 35 / 55 22 / 34 should initiate the secondary authentication procedure. SMF also maintains a re-authentication policy, and if the primary identity received was authenticated by SMF a long time ago, it may be necessary to initiate a new re-authentication.
[0082] Step 5: The secondary authentication procedure is performed between the UE and the external AAA via the SMF. In this case, the SMF serves as the EAP authenticator and the external AAA serves as the EAP server. EAP messages are transported via the NAS-SM protocol, transparently to the AMF. This may require the specification of new NAS-SM messages that may contain SM-EAP packets, for example, SM authentication request and SM authentication response. If the PDU session establishment request carried the UE's secondary identity, the SMF can skip the EAP Identity request and initiate EAP authentication directly with the AAA server. EAP exchange over the air interface benefits from protection at the NAS layer.
[0083] Secondary EAP authentication may optionally need to be bound to the channel on which it was executed, otherwise there is a risk that a Man-in-the-Middle attack will tunnel EAP packets between channels (e.g., if the same EAP method and credentials are used on multiple channels). Channel binding can be done by retrieving channel-related information (e.g., the primary identity used in step 2, assuming it may include information related to the access type or core network type or network slice). Channel-related information is either used directly in cryptographic operations within secondary EAP authentication, or later when using the master key (i.e., master session key, MSK, or extended MSK, EMSK) created from secondary authentication for some purpose. Channel information can be one of Petition 870250017049, dated 28 / 02 / 2025, page 36 / 55 23 / 34 following: the type of access network (e.g. 5G radio, WLAN wireless local access network), the type of network core (e.g. 5G core network) or the type of network slice or identifier (e.g. Network Slice Selection Assistance Information NSAI, SM-NSAI or Data Network Name DNN).
[0084] In particular, most EAP authentication methods create a master key (MSK and EMSK) as a result of authentication. This key is used to create session keys, for example, integrity protection key or encryption key. Channel binding can be done in two places: a) within the EAP method when creating MSK / EMSK, and in this case the binding parameters are input values for key derivation: MSK = KDF (binding parameters, other parameters) and / or EMSK = KDF (binding parameters, other parameters); or b) after the MSK / EMSK has been created when creating some other key (master): Key = KDF (binding parameters, MSK) and / or Key = KDF (binding parameters, EMSK).
[0085] Step 6: As part of the AAA exchange, the external AAA server can indicate a re-authentication policy to the SMF. This could be, for example, the maximum time after which re-authentication is required.
[0086] After successful authentication, the AAA exchange may also include the exchange of service / session authorization information to the SMF. In this case, the AAA may provide the SMF with a service authorization profile (or service authorization profile identifier / token) from which the SMF will be able to determine whether the requested service is authorized for the user, and if authorized, in what manner the service should be offered in terms of, for example, Quality of Service, Quality of Experience, billing, etc.
[0087] Step 7: The SMF optionally links the primary identity and the secondary identity, and stores this locally. When the SMF sees a new request from the AMF carrying the primary identity, it can Petition 870250017049, dated 28 / 02 / 2025, p. 37 / 55 24 / 34 trust that the messages originate from the same EU that owns the secondary identity.
[0088] Step 8: After successful authentication and authorization, the SMF selects a user plan function, UPF, for the user plan related to the requested service.
[0089] Step 9: The SMF sends back a PDU session establishment response depending on the result of the secondary authentication. This message may carry the final EAP message, i.e., the accepted PDU session establishment may carry EAP Success or the failed PDU session establishment may carry EAP Failure.
[0090] In step 5, the SMF endorses the role of the EAP authenticator and can rely on a backend AAA server on the data network, possibly in another security domain, for example controlled by a third party. It is then left open how AAA messages are transported between the SMF and the AAA server. There are different possibilities. In one mode, AAA messages are transported through a direct interface between the SMF and the AAA, similarly to the EPC PCO solution. This interface is established based on commercial agreements when the AAA is controlled by a third party. Figure 4 shows the protocol architecture for supporting EAP-based secondary authentication with a direct interface between the SMF and the AAA server (called XX). On the UE side for the SMF, it shows one possibility of how EAP messages are transported over the NAS protocol.
[0091] In a second embodiment, AAA messages are transferred transparently over NG4-NG6 interfaces via UPF. UPF could act as an AAA proxy or, even more simply, an IP router. In this case, SMF will execute step 8 before the AAA exchange in Petition 870250017049, dated 28 / 02 / 2025, p. 38 / 55 25 / 34 step 5 of Figure 3 therefore it is possible to manipulate the AAA exchange through the selected UPF. Figure 5 shows support for secondary authentication based on EAP, where EAP messages are transported through the UPF via the NG4-NG6 interfaces. That is, the NG4-NG6 interfaces are used transparently to carry AAA messages between the SMF and the AAA server. In this specific case (Figure 5), the UPF could act as an IP router so that the AAA exchange between the SMF and the AAA server is transparent to the UPF.
[0092] In a third mode, UPF can actually act as a proxy for AAA.
[0093] In a fourth mode, the SMF can act as an EAP server and in this case there is no need for interaction with an external AAA server.
[0094] In a fifth mode, the primary identity and the secondary identity are the same or related to each other, for example, (a part of) the primary identity is encoded in the secondary identity. The credentials used for authentication may still be different.
[0095] Similar to the PCO-based mechanism, secondary authentication could be used for additional authorization controlled by an external party upon request from the UE for the establishment of specific or additional PDU sessions. Other use cases related to UP protection and slicing are described in the following clauses.
[0096] User plane protection: First, if UP traffic protection is terminated at a UPF, the following assumption is made. User plane protection between the UE and a UPF is implemented via an additional protocol layer independently of protection on the NGU interface between the UE and the access network.
[0097] In this case, secondary authentication can be used to Petition 870250017049, dated 28 / 02 / 2025, page 39 / 55 26 / 34 establish the necessary keys. In fact, after successful authentication, the resulting MSK key shared between the SMF (EAP authenticator) and the UE (peer) could be used for this specific purpose.
[0098] The mechanisms for distributing the protection keys, negotiating the algorithm, and activating the security mode would be generic and agnostic to the authentication method. All these operations can be performed in conjunction with establishing a PDU session (step 9 in Figure 3).
[0099] Network Slice Support: Secondary authentication could be used for Network Slice-specific authorization. In fact, after successful primary authentication through a given AMF, the UE could potentially be provided services through all Network Slices served by that particular AMF. It may be the case that the UE is automatically authorized to access all or some of the slices based on subscription information. Alternatively, authorization could be applied on a slice-specific basis using secondary authentication during the creation of a PDU session for a specific slice.
[00100] For the protection of UP traffic between the UE and a particular slice, the mechanism described in the previous clause could be used. However, the configuration of the slices in terms of who manages or owns which network function becomes relevant. From the point of view of the trust model, this would require that the UPF and SMF be slice-specific; otherwise, the protection would serve no purpose.
[00101] In view of the variations and modifications above, Figure 6 illustrates a method for secondary authentication of a user device 18 configured for use in a wireless communication network, for example, comprising an access network 12 and a core network, according to some Petition 870250017049, dated 28 / 02 / 2025, pages 40 / 55 27 / 34 modes. The method is performed by user equipment 18. The method may comprise receiving, by user equipment 18, an Extensible Authentication Protocol (EAP) request 28 from a control plane function 14 that is in the core network (e.g., an SMF) and that is serving as an EAP authenticator 24 for secondary authentication of user equipment 18 (Block 100). The secondary authentication may be authentication of user equipment 18 in addition to the primary authentication of user equipment 18. The method may also comprise, in response to the EAP request 28, transmitting an EAP response 30 from user equipment 18 to the control plane function 14 (e.g., SMF) (Block 110).
[00102] Figure 7 illustrates a corresponding method performed by control plane function 14 (Sf, SMF). The method may comprise transmitting an Extensible Authentication Protocol (EAP) request 28 from a control plane function 14 (e.g., SMF) to a user device 18, wherein the control plane function 14 is in the core network and is serving as an EAP authenticator 24 for secondary authentication of the user device 18 (Block 200). Again, secondary authentication may be authentication of the user device 18 in addition to the primary authentication of the user device 18. The method may also comprise, responsive to the EAP request 28, receiving in control plane function 14 an EAP response 30 from the user device 18 (block 210).
[00103] In some embodiments, control plane function 14 is also serving as an EAP server that executes an EAP authentication method for secondary authentication of user equipment 18. Alternatively, control plane function 14 may serve as a pass-through authenticator that forwards the EAP request 28 and the response. Petition 870250017049, dated 28 / 02 / 2025, page 41 / 55 28 / 34 of EAP 30 between user equipment 18 and an EAP server 26 (separate from the EAP authenticator) that runs an EAP authentication method for the EAP authenticator.
[00104] Figure 8 in this regard illustrates a method implemented by an EAP server 26 for secondary authentication of user equipment 18. The method may comprise transmitting an Extensible Authentication Protocol (EAP) request 28 from an EAP server 26 to user equipment 18 via a control plane function 14 (e.g., SMF) (Block 300). The control plane function in this regard is in the core network and is serving as a pass-through EAP authenticator for secondary authentication of user equipment 18. Secondary authentication may be authentication of user equipment 18 in addition to primary authentication of user equipment 18. The EAP server 26 may be configured to implement an EAP authentication method for EAP authenticator 24.The method may also include, in response to the EAP 28 request, receiving on the EAP 26 server via control plane function 14 an EAP 30 response from user equipment 18 (block 310).
[00105] In some embodiments, the EAP server 26 is on a data network 22 with which the user device 18 requests a user plane session. The secondary authentication of the user device 18 may be the authentication of the user device 18 to establish the user plane session 20. In some embodiments, the secondary authentication is delegated by the wireless communication network to the data network 22.
[00106] Note that a network node here is any type of node in AN 14 (e.g., a base station) or in the core network. Where the network node is a radio network node in AN, the node may be able to communicate with another node. Petition 870250017049, dated 28 / 02 / 2025, page 42 / 55 29 / 34 via radio signals. A wireless device is any type of device capable of communicating with a radio network node via radio signals. A wireless device can therefore refer to a machine-to-machine (M2M) device, a machine-to-communication (MTC) device, an NB-IoT device, etc. The wireless device can also be a UE, however it should be noted that the UE does not necessarily have a user in the sense of an individual person owning and / or operating the device.A wireless device may also be referred to as a radio device, a radio communication device, a wireless terminal, or simply a terminal – unless the context indicates otherwise, the use of any of these terms should include device-to-device UE or devices, machine-type devices or machine-to-machine communication capable devices, sensors equipped with a wireless device, wireless-enabled desktop computers, mobile terminals, smartphones, laptop embedded equipment (LEE), laptop mounted equipment (LME), USB dongles, wireless client premises equipment (CPE), etc. In the discussion here, the terms machine-to-machine (M2M) device, machine-type communication device (MTC), wireless sensor, and sensor may also be used. It should be understood that these devices may be UE, but are generally configured to transmit and / or receive data without direct human interaction.
[00107] In an IoT scenario, a wireless communication device as described herein may be, or may be comprised within, a machine or device that performs monitoring or measurements, and transmits the results of such monitoring measurements to another device or a network. Particular examples of such machines are energy meters, industrial machinery, or household appliances or personal devices, for example, Petition 870250017049, dated 28 / 02 / 2025, pp. 43 / 55 30 / 34 refrigerators, televisions, personal wearables such as watches, etc. In other scenarios, a wireless communication device as described herein may be included in a vehicle and may perform monitoring and / or communication of the vehicle's operational status or other vehicle-related functions.
[00108] User equipment 18 herein may perform the processing herein by implementing any means or functional units. In one embodiment, for example, user equipment 18 comprises respective circuits configured to perform the steps shown in Figure 6. The circuits in this respect may comprise circuits dedicated to performing a particular functional processing and / or one or more microprocessors in conjunction with memory. In embodiments employing memory, which may comprise one or more types of memory such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, etc., the memory stores program code which, when executed by one or more microprocessors, carries out the techniques described herein.That is, in some embodiments the memory of user equipment 18 contains instructions executable by the processing circuitry, so user equipment 18 is configured to carry out the processing described herein.
[00109] Figure 9A illustrates additional details of a user equipment 18 according to one or more embodiments. As shown, the user equipment 18 includes a processing circuit assembly 410 and a communication circuit assembly 420 (e.g., one or more radio circuits). The communication circuit assembly 420 can be configured to transmit through one or more antennas, which can be internal and / or external to the user equipment 18. The circuit assembly of Petition 870250017049, dated 28 / 02 / 2025, pp. 44 / 55 31 / 34 processing unit 410 is configured to perform the processing described above, for example, in Figure 6, such as by executing instructions stored in memory 430. The processing unit 410 in this respect may implement certain means or functional units.
[00110] Figure 9B in this regard illustrates further details of a user equipment 18 according to one or more other embodiments. As shown, the user equipment 18 may include a receiving unit or module 440 to receive the EAP request 28 and a transmitting unit or module 450 to transmit the EAP response 30. These units or modules may be implemented by the processing circuitry set 410 in Figure 9A.
[00111] Similarly, the control plane function 14 (e.g., SMF) can be provided or implemented by the control plane equipment in the control plane. The control plane equipment in this respect may include one or more control plane nodes. Multiple distributed control plane nodes may, for example, host or implement the control plane function 14 in a distributed manner. Alternatively, a single control plane node may host or implement the control plane function 14 in a centralized manner.
[00112] The control plane equipment herein can perform the processing of the control plane function 14 by implementing any means or functional units. In one embodiment, for example, the control plane equipment comprises respective circuits configured to perform the steps shown in Figure 7. The circuits in this sense may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. In embodiments employing memory, which may Petition 870250017049, dated 28 / 02 / 2025, pages 45 / 55 32 / 34 Understanding one or more types of memory such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, etc., the memory stores program code that, when executed by one or more microprocessors, carries the techniques described herein. That is, in some embodiments the memory of the control plane equipment contains instructions executable by the set of processing circuits, whereby the control plane equipment is configured to carry the processing described herein.
[00113] Figure 10A illustrates additional details of the control plane equipment 500 according to one or more embodiments. As shown, the control plane equipment 500 includes the processing circuitry 510 and the communication circuitry 520. The communication circuitry 520 can be configured to communicate with the user equipment 18, for example, through one or more defined interfaces. The processing circuitry 510 is configured to perform the processing described above, for example, in Figure 7, such as by executing instructions stored in memory 530. The processing circuitry 510 in this respect can implement certain means or functional units.
[00114] Figure 10B in this regard illustrates further details of the control plane equipment 500 according to one or more other embodiments. As shown, the control plane equipment 500 may include a receiving unit or module 540 to receive the EAP response 30 and a transmitting unit or module 5 to transmit the EAP request 28. These units or modules may be implemented by the processing circuitry set 510 in Figure 10A.
[00115] The EAP 26 server (also referred to as a server of Petition 870250017049, dated 28 / 02 / 2025, pages 46 / 55 33 / 34 authentication or backend authentication server) here can perform processing through the implementation of any means or functional units. In one embodiment, for example, the EAP server 26 comprises respective circuits configured to perform the steps shown in Figure 8. The circuits in this respect may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. In embodiments employing memory, which may comprise one or more types of memory such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, etc., the memory stores program code which, when executed by one or more microprocessors, carries out the techniques described herein.That is, in some modes the memory of the EAP 26 server contains instructions executable by the processing circuitry, so the authentication server 26 is configured to carry out the processing described here.
[00116] Figure 11A illustrates further details of an EAP server 26 according to one or more embodiments. As shown, the EAP server 26 includes the processing circuitry 610 and the communication circuitry 620. The communication circuitry 620 can be configured to communicate with the user equipment 18 and / or the control plane function 14, for example, through one or more defined interfaces. The processing circuitry 610 is configured to perform the processing described above, for example, in Figure 8, such as executing instructions stored in memory 630. The processing circuitry 610 in this respect can implement certain means or functional units.
[00117] Figure 11B in this regard illustrates additional details of a Petition 870250017049, dated 28 / 02 / 2025, pp. 47 / 55 34 / 34 EAP server 26 according to one or more other embodiments. As shown, the EAP server 26 may include a receiving unit or module 640 to receive the EAP response 30 and a transmitting unit or module 650 to transmit the EAP request 28. These units or modules may be implemented by the processing circuitry 610 in Figure 11A.
[00118] Those skilled in the art will also appreciate that the modalities included here include corresponding computer programs.
[00119] A computer program comprises instructions that, when executed on at least one processor (for example, of a user device 18, control plane device 500 or EAP server 26), cause the processor to perform a new processing described above. A computer program in this respect may comprise one or more code modules corresponding to the means or units described above.
[00120] Modalities also include a carrier containing such a computer program. This carrier may comprise an electronic signal, optical signal, radio signal, or computer-readable storage medium. Petition 870250017049, dated 28 / 02 / 2025, pages 48 / 55
Claims
1 / 6 CLAIMS 1. Method for secondary authentication of a user device, UE, (18), characterized in that the method comprises: receiving (100), by the user device (18), an Extensible Authentication Protocol request, EAP, (28) for a UE identity to be used in secondary authentication, the EAP request (28) being encapsulated within a Non-Access Stratum Protocol (NAS) message from a Session Management Function, SMF, (14) that serves as an EAP authenticator for secondary authentication of the user device (18), wherein the secondary authentication is authentication of the user device (18) to establish a packet data unit session with a data network (22) in addition to the primary authentication of the user device (18) performed between the user device (18) and a security anchor function;and responsive to the EAP request (28), transmit (110) an EAP reply (30) encapsulated within a NAS protocol message from the user equipment (18) to the SMF (14), wherein the EAP reply (30) includes the identity.; 2. Method according to claim 1, characterized in that the SMF (14) also serves as an EAP server that executes an EAP authentication method for secondary authentication of the user equipment (18).
3. Method according to claim 1, characterized in that the SMF (14) is configured to forward the EAP request (28) and the EAP response (30) between the user equipment (18) and an EAP server (26) that executes an EAP authentication method for the EAP authenticator. Petition 870250017049, dated 28 / 02 / 2025, p. 49 / 55 2 / 6 4. Method, according to any one of claims 1 to 3, characterized in that a core network comprises multiple different network slices respectively dedicated to different services, wherein the secondary authentication of the user equipment (18) comprises specific authentication of the user equipment slice (18) to access a specific network slice of the core network.
5. Method, according to any one of claims 1 to 4, characterized in that it further comprises, based on successful secondary authentication of the user equipment (18), obtaining a security key shared between the user equipment (18) and the SMF (14).
6. Method, according to any one of claims 1 to 5, characterized in that a session establishment request transmitted from the user equipment (18) triggers secondary authentication of the user equipment (18).
7. Method according to claim 6, characterized in that the session establishment request includes a secondary identity of the user equipment (18) used for secondary authentication.
8. Method according to claim 6 or 7, characterized in that a session establishment response transmitted to the user equipment (18) includes an EAP success message indicating secondary authentication success or an EAP failure message indicating secondary authentication failure.
9. Method, according to any one of claims 1 to 8, characterized in that it further comprises linking the secondary authentication of the user equipment (18) to a channel through which the secondary authentication is performed.
10. Method, according to any one of claims 1 to 9, characterized in that it further comprises deriving, based on successful secondary authentication of the user equipment (18), a security key shared between the user equipment (18) and the SMF (14), wherein said derivation comprises deriving the security key as a function of link information associated with a channel through which secondary authentication is performed.
11. Method for secondary authentication of a user device, UE, (18), characterized in that the method comprises: transmitting (200) an Extensible Authentication Protocol request, EAP, (28) for a UE identity to be used in secondary authentication, the EAP request (28) being encapsulated within a Non-Access Stratum Protocol (NAS) message from a Session Management Function, SMF, (14) to the user device (18), wherein the SMF (14) serves as an EAP authenticator for secondary authentication of the user device (18), wherein the secondary authentication is authentication of the user device (18) to establish a packet data unit session with a data network (22) in addition to the primary authentication of the user device (18) performed between the user device (18) and a security anchor function;and responsive to the EAP request (28), receive (210) in the SMF (14) an EAP response (30) encapsulated within a NAS protocol message from the user equipment (18), wherein the EAP response (30) includes the identity.; 12. Method according to claim 11, characterized in that the SMF (14) also serves as an EAP server that executes an EAP authentication method for secondary authentication of the user equipment (18).
13. Method according to claim 11, characterized in that the SMF (14) is configured to forward the EAP request (28) and the EAP response (30) between the user equipment (18) and an EAP server (26) that executes an EAP authentication method for the EAP authenticator.
14. Method, according to any one of claims 11 to 13, characterized in that a core network comprises multiple different network slices respectively dedicated to different services, wherein the secondary authentication of the user equipment (18) comprises specific authentication of the user equipment slice (18) to access a specific network slice of the core network.
15. Method, according to any one of claims 11 to 14, characterized in that it further comprises, based on successful secondary authentication of the user equipment (18), obtaining a security key shared between the user equipment (18) and the SMF (14).
16. Method, according to any one of claims 11 to 15, characterized in that a session establishment request transmitted from the user equipment (18) triggers secondary authentication of the user equipment (18).
17. Method according to claim 16, characterized in that the session establishment request includes a secondary identity of the user equipment (18) used for secondary authentication.
18. Method, according to claim 16 or 17, characterized Petition 870250017049, dated 2 / 28 / 2025, page 52 / 55 5 / 6 in that a session establishment response transmitted to the user equipment (18) includes an EAP success message indicating secondary authentication success or an EAP failure message indicating secondary authentication failure.
19. Method, according to any one of claims 11 to 18, characterized in that it further comprises linking the secondary authentication of the user equipment (18) to a channel through which the secondary authentication is performed.
20. Method, according to any one of claims 11 to 19, characterized in that it further comprises deriving, based on successful secondary authentication of the user equipment (18), a security key shared between the user equipment (18) and the SMF (14), wherein said derivation comprises deriving the security key as a function of link information associated with a channel through which secondary authentication is performed.
21. User Equipment, UE, (18) characterized in that it is configured to: receive an Extensible Authentication Protocol, EAP, request, (28) for a UE identity to be used in secondary authentication, the EAP request (28) being encapsulated within a Non-Access Stratum Protocol (NAS) message from a Session Management Function, SMF, (14) that serves as an EAP authenticator for secondary authentication of the user equipment (18) to establish a packet data unit session with a data network (22), wherein the secondary authentication is authentication of the user equipment (18) in addition to the primary authentication of the user equipment (18) performed between the user equipment (18) and a security anchor function; and Petition 870250017049, dated 28 / 02 / 2025, p.53 / 55 6 / 6 responsive to EAP request (28), transmit an EAP response (30) encapsulated within a NAS to SMF protocol message (14), where the EAP response (30) includes identity.
22. Network equipment configured to provide a session management function, SMF, (14), characterized in that the SMF (14) is configured to: transmit an Extensible Authentication Protocol request, EAP, (28) for a user equipment identity, UE, to be used in secondary authentication, the EAP request (28) being encapsulated within a Non-Access Stratum Protocol (NAS) message from the SMF (14) to a user equipment (18), wherein the SMF (14) serves as an EAP authenticator for secondary authentication of the user equipment (18) to establish a packet data unit session with a data network (22), wherein the secondary authentication is authentication of the user equipment (18) in addition to the primary authentication of the user equipment (18) performed between the user equipment (18) and a security anchor function;and responsive to the EAP request (28), receive in the SMF (14) an EAP response (30) encapsulated within a NAS protocol message from the user equipment (18), wherein the EAP response (30) includes the identity. Petition 870250017049, dated 28 / 02 / 2025, p. 54 / 55;