A method of supporting authentication of a user equipment

By leveraging the information exchange between UDM and HSS in a service-oriented architecture (SBA) telecommunications network, binding information is provided to support UE authentication, solving the problem that UEs cannot host UICC or IMSI authentication, and enabling simple and secure IMS domain access in 5G networks.

CN114667751BActive Publication Date: 2026-05-19TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2020-01-06
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In the fifth-generation core network, user equipment (UE) cannot host general integrated circuit cards (UICCs) or use security mechanisms based on International Mobile Subscriber Identity (IMSI), which makes existing IMS security solutions unable to effectively support user authentication in non-public network (NPN).

Method used

By leveraging the information exchange between the Unified Data Management (UDM) and Home Subscriber Server (HSS) in a Service-Based Architecture (SBA) telecommunications network, binding information is provided to support UE authentication, including the UE IP address and the timestamp of Protocol Data Unit (PDU) session registration, thus enabling a simple and secure authentication mechanism for the UE.

Benefits of technology

It provides UEs with a simple and secure authentication mechanism to access the IMS domain in 5G networks, reducing the complexity of UE configuration and making it suitable for non-public network NPN environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114667751B_ABST
    Figure CN114667751B_ABST
Patent Text Reader

Abstract

A method of supporting authentication of a user equipment, UE, in an Internet Protocol, IP, Multimedia Subsystem, IMS, telecommunication network by connecting a Service Based Architecture, SBA, telecommunication network, the method comprising the steps of: receiving, by a Unified Data Management, UDM, in the SBA telecommunication network, binding information from a Session Management Function, SMF, in the SBA telecommunication network, wherein the binding information is used to identify the UE in the IMS telecommunication network; receiving, by the UDM in the SBA telecommunication network, a request to provide the binding information from a Home Subscriber Server, HSS, in the IMS telecommunication network; and providing, by the UDM in the SBA telecommunication network, the binding information to the HSS in the IMS telecommunication network, thereby supporting authentication of the UE. Supplementary methods and corresponding nodes are also presented herein.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates primarily to the telecommunications field, and more specifically to methods for supporting the authentication of user equipment (UE) in a telecommunications network. Background Technology

[0002] The 3GPP technical standard TS 33.203, part of the 3rd Generation Partnership Project (3GPP), specifies the security functions and mechanisms for secure access to the Internet Protocol IP Multimedia Subsystem (IMS) when accessing it via 3GPP. Security functions within IMS are based on user authentication, which uses identifiers and credentials stored in the IMS User Identity Module (ISIM) application within the Universal Integrated Circuit Card (UICC). However, IMS also allows the use of credentials and identifiers stored in the Universal Mobile Telecommunications System (UMTS) User Identity Module (USIM) application within the UICC. These identifiers and credentials are primarily used for 3GPP access authentication, such as for General Packet Radio Service (GPRS) and Evolved Packet Core (EPC), for IMS-level authentication.

[0003] Furthermore, 3GPP TS 33.203 Annex T specifies a temporary security solution for early IMS implementations that do not fully comply with the IMS security architecture, namely the so-called GPRS IMS Bundled Authentication (GIBA). Although the GIBA security solution was initially conceived as a temporary step to facilitate early IMS deployments through 3GPP access, it has proven to provide sufficient security for most 3GPP IMS deployments. Therefore, it has been elevated and is no longer considered a temporary solution for early deployments, but rather a mainstream IMS security mechanism.

[0004] GIBA is an authentication mechanism, a temporary solution for devices that do not fully comply with IMS authentication and key protocol AKA. The IP address assigned to a user when establishing a Packet Data Protocol (PDP) context is passed to the Home Subscriber Server (HSS) and linked to their private / public ID. Future requests to IMS must originate from the same IP address in sequence.

[0005] 3GPP AKA is one of the authentication mechanisms currently defined in IMS. It utilizes the common 3GPP AKA mechanism also used in third-generation CS and GPRS networks. 3GPP AKA relies on a shared secret between the user stored in the UICC card and the network stored in the HSS, and it can be executed automatically without any user interaction.

[0006] GIBA, formerly known as Early IMS Security, is deployed in 3GPP-based networks where the infrastructure does not yet provide full IMS security, such as networks with early IMS deployments (which do not use IPsec and 3GPP AKA for IMS). GIBA relies on GPRS layer security and therefore does not require a specific IMS or SIP authentication process.

[0007] The GIBA security solution is intended for use prior to the availability of products (primarily User Equipment, UEs) that fully support the 3GPP IMS security features defined in TS 33.203. Therefore, it is necessary to ensure that a simple yet sufficiently secure mechanism is established to prevent the greatest security threats present in early IMS implementations.

[0008] The GIBA security solution works by creating a secure binding between the public / private user identity (i.e., Session Initiation Protocol (SIP) level identity) and the Internet Protocol (IP) address currently assigned to the user at the GPRS access level (such as a bearer / network level identity) within the HSS. Therefore, IMS-level signaling (especially the user-claimed IMS identity) can be securely bound to the packet-switched PS domain bearer-level security context. The signaling flow of GIBA using Gm is as follows: Figure 1 As shown.

[0009] Figure 1 This will be described in more detail in this disclosure.

[0010] Although GIBA is designed primarily for GPRS access, it can also be used in EPC with a packet data network gateway (PDN-GW) that acts as a RADIUS client, and supports Gi's interaction with an HSS that acts as a RADIUS server.

[0011] GIBA can also be used to authenticate user access to the IMS application server as an alternative to GAA / GBA. In this case, the IMS application server (IMS-AS) requests binding information from the HSS via the Sh UDR Diameter command to obtain IP address security binding information as defined in 3GPP TS 29.328. Currently, GIBA support has not been specified in 5GC.

[0012] 3GPP Release 16TS 23.501 defines the architecture and solutions for supporting Non-Public Networks (NPNs) in the 5G core (5GC). An NPN is a 5GS network deployed for non-public use. An NPN can be deployed as a standalone Non-Public Network (SNPN), operated by an NPN operator without relying on network functionality provided by a public terrestrial mobile network (PLMN).

[0013] Some PLMN operators are still experimenting with enabling the services and capabilities that PLMNs provide to SNPNs. In particular, IMS-based voice / video / messaging capabilities have become a focus.

[0014] In SNPN deployments, it is anticipated that UEs will not use authentication mechanisms based on the International Mobile Subscriber Identity (IMSI) and AKA mechanisms, primarily because UEs may not even be able to host UICCs. Identity and authentication management may be based on alternative identifiers and credentials, such as Subscription Persistent Identifiers (SUPIs) in Network Access Identifier (NAI) format, and certificate-based authentication using the Extensible Authentication Protocol – Transport Layer Security (EAP-TLS).

[0015] Therefore, support for the IMS security solution defined in 33.203 may not be in place in the UEs used in SNPN, and an alternative authentication mechanism should be used to enable IMS services for SNPN UEs.

[0016] Another popular authentication mechanism in IMS is SIP Digest Authentication, which is based on Hypertext Transfer Protocol (HTTP) digest authentication and uses a username and password as credentials. However, this requires configuring PLMN credentials for the SNPN UE.

[0017] An authentication solution is needed that enables IMS services for SNPN UEs while minimizing SNPN UE configuration. Summary of the Invention

[0018] In a first aspect of this disclosure, a method is proposed to support authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connection Service Architecture (SBA) telecommunications network. The method includes the following steps: a Unified Data Management (UDM) in the SBA telecommunications network receives binding information from a Session Management Function (SMF) in the SBA telecommunications network, wherein the binding information is used to identify the UE in the IMS telecommunications network; the UDM in the SBA telecommunications network receives a request from a Home Subscriber Server (HSS) in the IMS telecommunications network to provide the binding information; and the UDM in the SBA telecommunications network provides the binding information to the HSS in the IMS telecommunications network, thereby supporting authentication of the UE.

[0019] The inventors have discovered that if the UDM receives binding information, such as an IP address or subscription permanent identifier / globally unique personal identifier, from the Session Management Function (SMF), and during the authentication of the UE in the IMS domain, the Home Subscriber Server (HSS) is able to retrieve the binding information from the UDM.

[0020] Binding information can be provided to the UDM, for example, during the UE authentication process in a Service-Based Architecture (SBA) network. During such authentication, the SMF registers the corresponding PDU session with the UDM. Thus, the inventors found it potentially beneficial to introduce binding information into messages exchanged from the SMF to the UDM.

[0021] According to this disclosure, the IP Multimedia Subsystem (IMS) is a concept for integrated networks used by telecommunications operators, which will facilitate the use of IP for all known forms of packet communication, whether wireless or terrestrial. Examples of such communication include traditional telephone, fax, email, internet access, web services, Voice over IP (VoIP), instant messaging (IM), video conferencing sessions, and video on demand (VoD). IMS is part of the 3rd Generation Partnership Project (3GPP).

[0022] SBA telecommunications networks can be fifth-generation 5G networks. This disclosure provides a mechanism to support authentication mechanisms in the 5G core 5GC for devices that may not host Universal Integrated Circuit Cards (UICCs) or may not be able to use security mechanisms based on International Mobile Subscriber Identity (IMSI). This disclosure implements a simple yet secure authentication mechanism for those UEs accessing the IMS domain.

[0023] The Session Management Function (SMF) can be an element of a 5G service-based architecture. The SMF is primarily responsible for interacting with the decoupled data plane, creating, updating, and deleting Protocol Data Unit (PDU) sessions, and managing the session context using the User Plane Function (UPF).

[0024] SMF may involve a PDU session establishment request originating from the UE, in which the UE requests registration and authentication in the SBA (i.e., 5GC) telecommunications network.

[0025] According to an embodiment, binding information is provided through a Nudm service operation. For example, information is provided through the existing service operation Nudm_UEContextManagement_Registration. UDM can also provide binding information through Nudm_SDM_getservice. This service operation is provided through a standardized Nudm interface. To utilize existing service operations, the service operations may need to be extended to include additional information. Such modifications are presented in this disclosure.

[0026] According to the example embodiment, the binding information includes at least:

[0027] -UE IP address

[0028] - The timestamp of the Protocol Data Unit (PDU) session registration.

[0029] When the binding information includes a timestamp, this can be used to select the binding information to be provided to the HSS. The inventors believe that if the UDM keeps information about the old SMF of the DNN stagnant, the timestamp can help the UDM determine the latest SMF, which is advantageous.

[0030] According to an embodiment, the method further includes the following step: the UDM provides the SMF with information about the data network name (DNN), which will require reporting the UE IP address to the UDM.

[0031] According to the example, the steps for receiving the binding information include:

[0032] - The UDM requests the binding information from the SMF, the request being triggered by receiving a request from the HSS to provide the binding information.

[0033] - The binding information is received by the UDM from the SMF.

[0034] According to another example, the binding information includes a timestamp indicating the time when the binding information was generated.

[0035] Reference Figure 10 To best explain the two examples above, Figure 10 This will be explained in more detail later in this specific disclosure.

[0036] In a second aspect of this disclosure, a method is proposed to support authentication or actual authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network by connecting a Service-Based Architecture (SBA) telecommunications network. The method according to the second aspect includes the following steps: a Home Subscriber Server (HSS) in the IMS telecommunications network sends a request to a Unified Data Management Device (UDM) in the SBA telecommunications network to provide binding information, wherein the binding information is used to identify the UE in the IMS telecommunications network; the HSS in the IMS telecommunications network receives the requested binding information from the UDM in the SBA telecommunications network; and the HSS in the IMS telecommunications network sends the binding information to a Service Call / Session Control Function (S-CSCF) in the IMS telecommunications network, thereby supporting the authentication of the UE. The final sending step can be replaced or added by the following step: the HSS node in the IMS telecommunications network authenticates the UE based on the received binding information.

[0037] It is hereby noted that the advantages and features relating to the first aspect of this disclosure are also relevant to the second aspect of this disclosure if necessary.

[0038] As shown in the example, binding information is received through service operations of the Nudm service.

[0039] In the example of the second aspect, the binding information includes at least:

[0040] -UE IP address

[0041] - The timestamp of the Protocol Data Unit (PDU) session registration.

[0042] According to a third aspect of this disclosure, a method is provided for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connection Service Architecture (SBA) telecommunications network. The method includes the following steps: a Session Management Function (SMF) receiving a message from a Unified Data Management Device (UDM) requesting binding information for a Data Network Name (DNN); and the SMF sending the DNN binding information requested by the UDM to the UDM.

[0043] It is hereby noted that the advantages and features relating to the first aspect of this disclosure may also relate to the third aspect of this disclosure if necessary.

[0044] In the example of the third aspect, the binding information includes at least:

[0045] -UE IP address

[0046] - The timestamp of the Protocol Data Unit (PDU) session registration.

[0047] According to a fourth aspect of this disclosure, a unified data management UDM node is provided in a Service-Based Architecture (SBA) telecommunications network for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network by connecting to the SBA telecommunications network. The UDM node includes: a receiving device for receiving binding information from a Session Management Function (SMF) in the SBA telecommunications network, wherein the binding information is used to identify the UE in the IMS telecommunications network, wherein the receiving device is further configured to receive a request from a Home Subscriber Server (HSS) in the IMS telecommunications network for providing the binding information; and a transmitting device for providing the binding information to an HSS in the IMS telecommunications network.

[0048] The features and advantages associated with the first aspect of this disclosure (as a method for supporting authentication of user equipment) are also related to the fourth aspect (i.e., UDM nodes that support authentication of UEs).

[0049] According to an embodiment, the binding information is used to provide operations through the Nudm service, such as Nudm_UECM_Registration or Nudm_SDM_getservice.

[0050] According to the example embodiment, the binding information includes at least:

[0051] -UE IP address

[0052] - The timestamp of the Protocol Data Unit (PDU) session registration.

[0053] According to an embodiment, the UDM also includes a selection device for selecting binding information to be provided to the HSS based on the timestamp.

[0054] In this embodiment, the transmitting device of the UDM is also used to provide the SMF with information about the data network name (DNN), which will require reporting the UE IP address to the UDM.

[0055] In another example, the sending device is also configured to request the binding information from the SMF, the request being triggered by receiving a request from the HSS for providing the binding information, and wherein the receiving device is also configured to receive the binding information from the SMF by the UDM.

[0056] Here, the binding information may include a timestamp indicating the time when the binding information was generated.

[0057] The above example can be about Figure 10 To obtain the best explanation Figure 10 This will be explained in more detail later in this specific disclosure.

[0058] In a fifth aspect of this disclosure, a Home Subscriber Server (HSS) node is provided in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network for supporting authentication of User Equipment (UE) in the IMS telecommunications network via a Service-Oriented Architecture (SBA) telecommunications network. The HSS node includes: a transmitting device for sending a request to a Unified Data Management Device (UDM) in the SBA telecommunications network to provide binding information, wherein the binding information is used to identify the UE in the IMS telecommunications network; and a receiving device for receiving the requested binding information from the UDM in the SBA telecommunications network.

[0059] According to a sixth aspect of this disclosure, a Session Management Function (SMF) node is provided in a Service-Based Architecture (SBA) telecommunications network for supporting authentication of User Equipment (UE) in an Internet Protocol (IP) Multimedia Subsystem (IMS) telecommunications network by connecting to the SBA telecommunications network. The SMF node includes: a receiving device for receiving a message from a Unified Data Management Device (UDM) requesting binding information for a Data Network Name (DNN); and a sending device for sending the DNN binding information requested by the UDM to the UDM via the SMF.

[0060] In a seventh aspect of this disclosure, a computer-readable storage medium including instructions, when loaded onto one or more nodes in a communication network, are provided, the instructions being configured to perform any of the methods according to this disclosure. Those skilled in the art will understand that a computer program product for performing the methods according to a first aspect of this disclosure can be loaded onto a UDM node and executed by the UDM node. Similarly, a computer program product for performing the methods according to a second aspect of this disclosure can be loaded onto an HSS node and executed by the HSS node. Finally, a computer program product for performing the methods according to a third aspect of this disclosure can be loaded onto an SMF node and executed by the SMF node.

[0061] Within the scope of this disclosure, the steps performed by the User Data Management (UDM) node can be performed by any other data management node in the telecommunications network. The steps performed by the Session Management Function (SMF) can be performed by any other node in the telecommunications network designed to manage sessions.

[0062] The above and other features and advantages of this disclosure will be better understood from the following description with reference to the accompanying drawings. In the drawings, similar reference numerals denote identical parts or parts performing identical or similar functions or operations. Attached Figure Description

[0063] Figure 1 The diagram schematically illustrates a message sequence secure according to the early Internet Protocol Multimedia Subsystem (IMS) of the prior art.

[0064] Figure 2 The signaling sequence for GPRS IMS bundled authentication GIBA support in a fifth-generation core 5GC network is illustrated schematically.

[0065] Figure 3 The signaling sequence used to support 5GIBA for UE authentication in the IMS Application Server IMS-AS is illustrated schematically.

[0066] Figures 4 to 6 The method according to this disclosure is illustrated schematically.

[0067] Figure 7 The Uniform Data Management (UDM) according to this disclosure is illustrated schematically.

[0068] Figure 8 The Home Subscriber Server (HSS) according to this disclosure is illustrated schematically.

[0069] Figure 9 The Session Management Function (SMF) according to this disclosure is illustrated schematically.

[0070] Figure 10The method according to this disclosure is illustrated schematically. Detailed Implementation

[0071] Some examples contemplated herein will now be described more fully with reference to the accompanying drawings. However, other examples are included within the scope of the subject matter disclosed herein, and the disclosed subject matter should not be construed as being limited to the examples set forth herein; rather, these examples are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0072] In the context of this disclosure, some possible steps of the GIBA process are highlighted below:

[0073] UE 2 first sets up the PDP context, as shown in steps 10 to 15. When the Packet Data Protocol (PDP) context is activated for the IP Multimedia Subsystem (IMS), the GPRS gateway support node GGSN 4, acting as a RADIUS client, provides the user IP address, IMSI, and MSISDN assigned to UE 2 to the RADIUS server in HSS 7 via the Gi interface.

[0074] Upon successful establishment of the PDP context, UE 2 sends Session Initiation Protocol (SIP) registration requests 16 and 17. The registration request includes the IP address assigned to UE 2 and UE 2's IMS Public Identifier (IMPU).

[0075] GGSN 4 verifies that the IP address assigned to UE 2 during PDP context establishment matches the IP address provided in the registration request. Once the IP address has been verified, GGSN 4 forwards the registration request to the Proxy Call Session Control Function (P-CSCF) 5.

[0076] P-CSCF 5 verifies the source IP address based on the IP address in the Via header of the registration request. If the source IP address differs from the IP address in the Via header, P-CSCF 5 adds the source IP address to the parameters received in the Via header. P-CSCF 5 then forwards the registration request to the Inquiry CSCF (I-CSCF) in the home network.

[0077] I-CSCF 6 contacts HSS 7 at 24 to authorize UE 2 to access IMS. HSS 7 responds at 25 UE 2 is authorized, and I-CSCF 6 forwards the SIP registration request at 27 to the service CSCF (S-CSCF) at 8 selected to serve UE 2.

[0078] S-CSCF 8 contacts HSS 7 and instructs it to use GIBA for UE authentication. HSS 7 returns the stored IP address to S-CSCF 8. S-CSCF 8 then verifies whether the IP address returned by HSS 7 matches the IP address obtained in the registration request. If they match, the received parameters should be used. If they match, the user is authenticated and authorized to register in IMS.

[0079] S-CSCF 8 sends message 32 to HSS 7, notifying S-CSCF 8 that it will serve UE 2, and HSS 7 responds with a message providing S-CSCF 8 with the information required to serve UE 2.

[0080] S-CSCF 8 returns a 34SIP 200OK response to UE 2, indicating that registration was successfully completed.

[0081] Based on the principles used in GIBA, an authentication mechanism is implemented for UEs (which do not support AKA-based identifiers and credentials when accessing using 5GC) to access the IMS domain, hereinafter referred to as 5G IMS Bundled Authentication 5GIBA.

[0082] The concept of this disclosure revolves around the SMF providing binding information, such as IP address and SUPI / GPSI, to the UDM through existing Nudm_UEContextManagement_Registration service operations, so that the HSS can retrieve the binding information from the UDM during the authentication process of IMS registration.

[0083] To register binding information in 5GC, the existing Nudm_UEContextManagement_Registration service operation is extended via the standardized Nudm interface defined in 3GPP TS 29.503. Therefore, the information registered by the SMF in the UDM is extended using the SMF registration timestamp and UE IP address in the UE context from the following SMF data:

[0084]

[0085] This invention proposes that the UE context in SMF may also be filtered by SUPI / DNN requests, as described below.

[0086]

[0087] Figure 2 The signaling sequence 40 used to support General Packet Radio Service (GPRSIMS) Bundled Authentication (GIBA) is illustrated schematically in a fifth-generation core 5GC network.

[0088] UE 2 authenticates and registers in 5GC 51. This authentication process is known in the prior art. The SUPI and credentials used by UE 2 may not be based on the International Mobile Subscriber Identity / Authentication and Key Protocol IMSI / AKA.

[0089] In step 52, UE 2 establishes a PDU session for the data network name DNN IMS. An SMF 41 suitable for establishing a PDU session for DNN IMS is selected.

[0090] In steps 53 and 54, SMF 41 registers a PDU session in UDM 42 using the existing Nudm_UEContextManagement_Registration service operation defined in 3GPP TS 23.502 and 3GPP TS 29.503. SMF 41 includes the IP address assigned to UE 2, and UDM 42 stores it as the "UE context in SMF data". Additionally, SMF 41 may include a timestamp for PDU session registration. This timestamp can help UDM 42 determine the latest SMF 41 in the DNN if UDM 42 retains stagnant information about older SMFs.

[0091] SMF 41 can be configured to include only the UE IP address used for the IMS DNN, or to do so for all DNNs. In another embodiment, when the SMF requests subscription data for the SUPI / DNN from the UDM using Nudm_SDM_Get, UDM 42 can notify the SMF 41 which DNNs will need to report their UE IP addresses to the UDM, such as... Figure 2 Step 53 is shown.

[0092] The DNN IMS PDU session establishment is completed in step 55. In the subsequent step 56, UE 2 sends a SIP registration request to the IMS. The SIP registration request includes the UE's IMPI / IMPU and the IP address assigned to UE 2 in 5GC. The IMPI / IMPU used by UE 2 for registration in IMS is based on the SUPI used by the UE for registration in 5GC. It is worth noting that the SUPI may include the NAI used as the IMPI.

[0093] In step 57, the S-CSCF in IMS core 43 contacts HSS 7 and instructs that GIBA be used to authenticate UE 2. HSS 7 can attempt to find the binding information provided to HSS by GGSN / PDN-GW using Gi. In the event of a lack of binding information from the GPRS / EPS domain, or in addition, HSS-IMS 7 will also check the binding information from 5GC.

[0094] In the UDICOM context defined in 3GPP TS 23.632, and with HSS and UDM deployed as separate NFs, HSS-IMS uses the existing Nudm_SDM_Get service operation to request binding information from UDM (i.e., “UE context in SMF data” for SUPI and IMS DNN).

[0095] HSS 7 creates a SUPI based on the IMPI received in the authentication request from the S-CSCF in step 7. UDM 42 provides HSS 7 with the "UE context in SMF data".

[0096] In another embodiment, in the presence of multiple SMFs managing DNN IMS, the UDM can use the timestamp included in the "UE context in SMF data" to select the latest binding information from the 5GC domain to provide to the HSS.

[0097] In step 59, HSS 7 returns the stored IP address to S-CSCF 43. If binding information from the 5GC and GPRS / EPC domains exists, HSS 7 also determines, for example, which IP address to provide to S-CSCF based on the timestamp of the binding information from GPRS / EPC. S-CSCF 43 then matches the IP address returned by HSS with the IP address obtained in the SIP registration request.

[0098] In step 60, the IMS registration process is performed accordingly. For example, if the IP address provided by the HSS is the same as the IP address provided by the UE to the S-CSCF in the SIP registration message, the IMS registration process is successful.

[0099] The same principle can be used to support 5GIBA for UE authentication in IMS-AS, such as... Figure 3 The signaling diagram in Figure 70 is shown below:

[0100] In this scenario, in steps 77-79, when HSS 7 receives a request for IP address security binding information normally from the authentication / aggregation agent or IMS AS 44, it requests the security binding information stored in the UDM during UE registration in 5GC in steps 73-74. If the security binding information provided by HSS 7 is the same as the security binding information provided by the UE in step 76, the IMS service continues or stops. 80. The remaining steps are combined with... Figure 2 The steps for presentation and description are the same, namely Figure 3 Step 71 in the text corresponds to Figure 2 Step 51 in the text, and so on.

[0101] A mechanism is proposed to authenticate UEs accessing the IMS domain that do not support AKA-based identifiers and credentials when using 5GC. The proposed mechanism is based on principles used in GIBA. This will provide a simple authentication mechanism for UEs that do not support AKA-based identifiers and credentials to access the IMS domain.

[0102] Figure 4 A method 100 is illustrated for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connection Service Architecture (SBA) telecommunications network. The method includes the following steps: a Unified Data Management (UDM) in the SBA telecommunications network receives 101 binding information from a Session Management Function (SMF) in the SBA telecommunications network, wherein the binding information is used to identify the UE in the IMS telecommunications network. In a subsequent step 102, the UDM receives a request from a Home Subscriber Server (HSS) in the IMS telecommunications network to provide the binding information, and subsequently provides 103 the binding information to the Home Subscriber Server (HSS) in the IMS telecommunications network, thereby supporting authentication of the user.

[0103] Method 100 may also include an additional step of the UDM providing the SMF with 104 information about the data network name (DNN), which will require reporting the UE IP address to the UDM.

[0104] Figure 5 A method 110 is illustrated for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connection Service-Based Architecture (SBA) telecommunications network. The method includes the following steps: 111 The Home Subscriber Server (HSS) in the IMS telecommunications network sends a request 111 to the Unified Data Management Device (UDM) in the SBA telecommunications network to provide binding information, wherein the binding information is used to identify the UE in the IMS telecommunications network. 112 The HSS receives the requested binding information from the UDM in the SBA telecommunications network and sends the binding information 113 to the Service Call / Session Control Function (S-CSCF) in the IMS telecommunications network, thereby supporting authentication of the UE.

[0105] Figure 6 A method 120 is schematically illustrated for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connectivity Service-Based Architecture (SBA) telecommunications network. Method 120 includes the following steps: a Session Management Function (SMF) receiving a message 121 requesting binding information for a Data Network Name (DNN) from a Unified Data Management Device (UDM); and the SMF sending the DNN binding information requested by the UDM to the UDM.

[0106] Figure 7 A Unified Data Management (UDM) node 42 in a Service-Based Architecture (SBA) telecommunications network is schematically illustrated, used to support authentication of User Equipment (UE) in an Internet Protocol (IP) Multimedia Subsystem (IMS) telecommunications network by connecting to the SBA network. The UDM node 42 includes receiving devices 131 and 132, which are used to receive binding information from the Session Management Function (SMF) in the SBA network, wherein the binding information is used to identify the UE in the IMS network. The receiving devices 131 and 132 are also used to receive requests from the Home Subscriber Server (MSS) in the IMS network for providing the binding information.

[0107] UDM node 42 further includes transmitting devices 133 and 134 for providing the binding information to the HSS in the IMS telecommunications network. The UDM node may also include a selection device 135 for selecting binding information to be provided to the HSS based on the timestamp.

[0108] UDM node 42 also includes memory 137 for storing a set of computer-readable instructions that, when executed by processor 136, cause UDM node 42 to perform methods according to this disclosure. Internal components communicate with each other using internal bus 138.

[0109] Figure 8 The illustration schematically depicts a Home Subscriber Server (HSS) node 7 in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network, used to support authentication of User Equipment (UE) in the IMS telecommunications network via a Connectivity Service Architecture (SBA) telecommunications network. HSS node 7 includes: transmitting devices 143 and 144 for sending a request to the Unified Data Management (UDM) in the SBA telecommunications network to provide binding information, wherein the binding information is used to identify the UE in the IMS telecommunications network; and receiving devices 141 and 142 for receiving the requested binding information from the UDM in the SBA telecommunications network.

[0110] HSS node 7 also includes memory 146 for storing a set of computer-readable instructions that, when executed by processor 145, cause the HSS node to perform methods according to this disclosure. Internal components communicate with each other using internal bus 147.

[0111] Figure 9The illustration schematically depicts a Session Management Function (SMF) node 41 in a Service-Based Architecture (SBA) telecommunications network, used to support authentication of User Equipment (UE) in an Internet Protocol (IP) Multimedia Subsystem (IMS) telecommunications network by connecting to the SBA telecommunications network. The SMF node 41 includes: receiving devices 151 and 152 for receiving messages from a Unified Data Management Device (UDM) requesting binding information for a Data Network Name (DNN); and sending devices 153 and 154 for transmitting the DNN binding information requested by the UDM to the UDM via the SMF.

[0112] SMF node 41 also includes memory 156 for storing a set of computer-readable instructions that, when executed by processor 155, cause SMF node 41 to perform methods according to this disclosure. Internal components communicate with each other using internal bus 157.

[0113] Figure 10 The method according to this disclosure is illustrated schematically.

[0114] This method illustrates signaling sequence 201 for supporting General Packet Radio Service GPRS IMS Bundled Authentication GIBA in a 5G core 5GC network.

[0115] UE 2 authenticates and registers 51 in 5GC, just like the reference. Figure 2 The scenario described is the same. In step 52, UE 2 establishes a PDU session for the data network name DNN IMS. An SMF 41 suitable for establishing a PDU session for DNN IMS is selected.

[0116] In steps 202 and 203, for example, SMF 41 registers a PDU session in UDM 42 using the existing Nudm_UEContextManagement_Registration service operation defined in 3GPP TS 23.502 and 3GPP TS 29.503. Here, with reference to... Figure 2 Compared to the described scenario, SMF 41 does not include an IP address assigned to UE 2.

[0117] The DNN IMS PDU session establishment is completed in step 55. In the subsequent step 56, UE 2 sends a SIP registration request to the IMS. The SIP registration request includes the UE's IMPI / IMPU and the IP address assigned to UE 2 in 5GC. The IMPI / IMPU used by UE 2 for registration in IMS is based on the SUPI used by the UE for registration in 5GC. It is worth noting that the SUPI may include the NAI used as the IMPI.

[0118] In step 204, the S-CSCF in IMS core 43 contacts HSS 7 and instructs that GIBA be used to authenticate UE 2. HSS 7 can attempt to use Gi to find the binding information provided to HSS by GGSN / PDN-GW. In the absence of binding information from the GPRS / EPS domain, or in addition, HSS-IMS will also check the binding information from 5GC.

[0119] In the UDICOM context defined by 3GPP in TS 23.632, where HSS and UDM are deployed as separate NFs, HSS-IMS uses the existing Nudm_SDM_Get service operation to request binding information from UDM (i.e., “UE context in SMF data” for SUPI and IMSDNN).

[0120] In this specific case, HSS 7 requests 205UDM 42 to provide the IP address of UE 2. This can be achieved using an event, for example, called Nudm_Event_Exposure_Notifyservice, which notifies the UE of the IP address once and reports it immediately.

[0121] In step 206, UDM 42 uses, for example, the service Nsmf_EventExposure with immediate response to obtain the UE IP address. Then, SMF 41 provides the UE IP address to UDM 42 in an Nsmf_Event_Exposure_Notify operation. The existing service operations provided by the defined SMF do not include the ability of SMF 41 to include a timestamp of the time when the UE IP address was generated in the notification.

[0122] In step 207, UDM 42 returns the UE IP address along with a timestamp to HSS 7 in the Nudm_EventExposure_Notify operation. Finally, in step 208, HSS 7 returns the IP address to S-CSCF 43. If binding information from the 5GC and GPRS / EPC domains exists, HSS 7, for example, also determines which IP address to provide to S-CSCF based on the timestamp of the binding information from GPRS / EPC. S-CSCF 43 then matches the IP address returned by HSS with the IP address obtained in the SIP registration request.

[0123] In step 60, the IMS registration process is performed accordingly. For example, if the IP address provided by the HSS is the same as the IP address provided by the UE to the S-CSCF in the SIP registration message, the IMS registration process is successful.

[0124] Within the scope of this disclosure, the steps performed by the User Data Management (UDM) node can be performed by any other data management node in the telecommunications network. The steps performed by the Session Management Function (SMF) can be performed by any other node in the telecommunications network designed to manage sessions.

[0125] Those skilled in the art, in practicing this claimed disclosure, can understand and implement other modifications to the examples of the above disclosure based on a study of the drawings, description, and appended claims. In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite articles "a" or "an" do not exclude a plurality. A single processor or other unit can perform the functions of several items referenced in the claims. The fact that certain measures are recited only in mutually different dependent claims does not mean that a combination of these measures cannot be used advantageously. Computer programs can be stored / distributed on suitable media, such as optical storage media or solid-state media provided together with or as part of other hardware, but can also be distributed in other forms, such as via the Internet or wired or wireless telecommunications systems. Any reference numerals in the claims should not be construed as limiting their scope.

[0126] This disclosure is not limited to the examples disclosed above, and those skilled in the art can modify and enhance this invention without departing from the scope of this disclosure as disclosed in the appended claims, without needing to apply inventive techniques.

Claims

1. A method for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connection Service-Based Architecture (SBA) telecommunications network, wherein, When the UE accesses the SBA telecommunications network, it does not support AKA-based identifiers and credentials. The method includes the following steps: - The Unified Data Management (UDM) in the SBA telecommunications network receives binding information from the Session Management Function (SMF) in the SBA telecommunications network, wherein the binding information is used to identify the UE in the IMS telecommunications network; - The UDM in the SBA telecommunications network receives a request from the Home Subscriber Server (HSS) in the IMS telecommunications network to provide the binding information, and - The binding information is provided by the UDM in the SBA telecommunications network to the HSS in the IMS telecommunications network, thereby supporting the authentication of the UE in the IMS telecommunications network.

2. The method according to claim 1, wherein, The binding information is provided through the service operation of the Nudm service.

3. The method according to claim 1 or 2, wherein, The binding information includes at least one of the following: - UE IP address - The timestamp of the Protocol Data Unit (PDU) session registration.

4. The method according to claim 3, wherein, The UDM uses the timestamp to select the binding information to be provided to the HSS.

5. The method according to claim 1 or 2, further comprising the following step: - The UDM provides the SMF with information about the data network name (DNN), which will require the UE IP address to be reported to the UDM.

6. The method according to claim 1 or 2, wherein, The steps for receiving the binding information include: - The UDM requests the binding information from the SMF, the request being triggered by receiving a request from the HSS to provide the binding information. - The binding information is received by the UDM from the SMF.

7. The method according to claim 6, wherein, The binding information includes a timestamp indicating the time when the binding information was generated.

8. A method for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connection Service-Based Architecture (SBA) telecommunications network, wherein, When the UE accesses the SBA telecommunications network, it does not support AKA-based identifiers and credentials. The method includes the following steps: - The Home Subscriber Server (HSS) in the IMS telecommunications network sends a request to the Unified Data Management Device (UDM) in the SBA telecommunications network to provide binding information, wherein the binding information is used to identify the UE in the IMS telecommunications network; - The HSS in the IMS telecommunications network receives the requested binding information from the UDM in the SBA telecommunications network; - The binding information is sent from the HSS in the IMS telecommunications network to the Service Call / Session Control Function (S-CSCF) in the IMS telecommunications network to support the authentication of the UE.

9. The method according to claim 8, wherein, The binding information is received through the service operation of the Nudm service.

10. The method according to claim 8 or 9, wherein, The binding information includes at least: - UE IP address - The timestamp of the Protocol Data Unit (PDU) session registration.

11. A method for supporting authentication of User Equipment (UE) in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network via a Connection Service-Based Architecture (SBA) telecommunications network, wherein, When the UE accesses the SBA telecommunications network, it does not support AKA-based identifiers and credentials. The method includes the following steps: - The Session Management Function (SMF) receives a message from the Unified Data Management Function (UDM) requesting binding information for a Data Network Name (DNN), wherein the binding information is used to identify the UE in the IMS telecommunications network; - The SMF sends the binding information of the DNN requested by the UDM to the UDM.

12. The method according to claim 11, wherein, The binding information includes at least: - UE IP address - The timestamp of the Protocol Data Unit (PDU) session registration.

13. A unified data management UDM node in a service-oriented architecture (SBA) telecommunications network, used to support authentication of user equipment (UE) in an Internet Protocol (IP) Multimedia Subsystem (IMS) telecommunications network by connecting to the SBA telecommunications network, wherein, The UE does not support AKA-based identifiers and credentials when accessing the SBA telecommunications network, and the UDM node includes: - A receiving device, configured to receive binding information from a Session Management Function (SMF) in the SBA telecommunications network, wherein the binding information is used to identify the UE in the IMS telecommunications network, and wherein the receiving device is further configured to receive a request from a Home Subscriber Server (HSS) in the IMS telecommunications network to provide the binding information; and - A transmitting device for providing the binding information to the HSS in the IMS telecommunications network.

14. The UDM node according to claim 13, wherein, The binding information is configured to be provided through operations of the Nudm service.

15. The UDM node according to claim 13 or 14, wherein, The binding information includes at least: - UE IP address - The timestamp of the Protocol Data Unit (PDU) session registration.

16. The UDM node according to claim 15, wherein, The UDM also includes a selection device for selecting the binding information to be provided to the HSS based on the timestamp.

17. The UDM node according to claim 13 or 14, wherein, The transmitting device is also used to provide the SMF with information about the data network name (DNN), which will require the UE IP address to be reported to the UDM.

18. The UDM node according to claim 13 or 14, wherein, The transmitting device is further configured to request the binding information from the SMF, the request being triggered by receiving a request from the HSS to provide the binding information, and wherein the receiving device is further configured to receive the binding information from the SMF by the UDM.

19. The UDM node according to claim 18, wherein, The binding information includes a timestamp indicating the time when the binding information was generated.

20. A Home Subscriber Server (HSS) node in an Internet Protocol IP Multimedia Subsystem (IMS) telecommunications network, used to support authentication of User Equipment (UE) in the IMS telecommunications network by connecting to a Service-Based Architecture (SBA) telecommunications network, wherein... The UE does not support AKA-based identifiers and credentials when accessing the SBA telecommunications network, and the HSS node includes: - A transmitting device for sending a request to the Unified Data Management (UDM) in the SBA telecommunications network to provide binding information, wherein the binding information is used to identify the UE in the IMS telecommunications network; - A receiving device for receiving requested binding information from the UDM in the SBA telecommunications network.

21. The HSS node according to claim 20, in the IMS telecommunications network, wherein, The binding information includes at least: - UE IP address - The timestamp of the Protocol Data Unit (PDU) session registration.

22. A Session Management Function (SMF) node in a Service-Based Architecture (SBA) telecommunications network, used to support authentication of User Equipment (UE) in an Internet Protocol (IP) Multimedia Subsystem (IMS) telecommunications network by connecting to the SBA telecommunications network, wherein... The UE does not support AKA-based identifiers and credentials when accessing the SBA telecommunications network, and the SMF node includes: - A receiving device for receiving a message from a unified data management unit (UDM) requesting binding information for a data network name (DNN), wherein the binding information is used to identify the UE in the IMS telecommunications network; - A transmitting device for transmitting the binding information of the DNN requested by the UDM to the UDM via the SMF.

23. The SMF node according to claim 22, wherein, The binding information includes at least: - UE IP address - The timestamp of the Protocol Data Unit (PDU) session registration.

24. A computer-readable storage medium including instructions, which, when loaded onto one or more nodes in a communication network, are configured to perform the method according to any one of claims 1 to 7 or 8 to 10 or 11.