User equipment, non-public network authentication, authorization and accounting server, authentication server functional entity

By providing an authentication interface between user equipment and the authentication server functional entity, adopting a wired interface and encryption method, the problem of secure transmission of EMSK in non-public networks is solved, ensuring network security and flexibility, and is suitable for mobile communication systems deployed in non-independent NPNs.

CN115004638BActive Publication Date: 2025-09-23SONY GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180010240.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-01-31
Filing Date
2021-01-26
Publication Date
2025-09-23
Estimated Expiration
2041-01-26

AI Technical Summary

Technical Problem

In the existing technology, the authentication and key negotiation process between user equipment in non-public networks and authentication servers has security and interface transmission issues. In particular, in non-standalone NPN deployments, the challenge of securely transmitting the Extended Master Session Key (EMSK) from the NPN AAA server to the AUSF entity has not been effectively addressed.

Method used

By providing an authentication interface between the user device and the authentication server functional entity, a secure authentication and key negotiation process is implemented, the extended master session key is transmitted using a wired interface, and encryption and decryption are performed using methods based on pre-shared keys or public key infrastructure to ensure the secure transmission of EMSK.

Benefits of technology

It achieves the safe and efficient transmission of extended master session keys in non-public networks, protects network security, avoids the risk of Internet exposure of AUSF entities, supports the connection of multiple NPN AAA servers with AUSF entities, reduces the dependence on EAP-TTLS, and provides a flexible network architecture.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115004638B_ABST
    Figure CN115004638B_ABST
Patent Text Reader

Abstract

A user equipment for a mobile communication system includes a circuit configured to: communicate with a non-public network authentication authorization accounting server and start a registration process with the mobile communication system; and provide an authentication interface between the non-public network authentication authorization accounting server and an authentication server function entity in the mobile communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to a user equipment, a non-public network authentication, authorization and accounting server, and an authentication server function entity for a mobile communication system. Background Art

[0002] Several generations of mobile communication systems are known, such as the third generation ("3G"), which is based on the International Mobile Telecommunications-2000 (IMT-2000) specifications; the fourth generation ("4G"), which provides functionality defined in the International Mobile Telecommunications-Advanced standards (IMT-Advanced); and the fifth generation ("5G"), which is currently under development and may be put into service by 2020.

[0003] A candidate for meeting 5G requirements is Long Term Evolution (LTE), a wireless communication technology that allows high-speed data communication between mobile phones and data terminals and is already used in 4G mobile communication systems. Another candidate for meeting 5G requirements is a New Radio (NR) access technology system. NR can be based on LTE technology, just as some aspects of LTE are based on previous generations of mobile communication technology.

[0004] LTE is based on the second generation ("2G") GSM / EDGE ("Global System for Mobile communications" / "Enhanced Data rates for GSM Evolution", also known as EGPRS) and third generation ("3G") network technologies UMTS / HSPA ("Universal Mobile Telecommunications System" / "High Speed ​​Packet Access").

[0005] LTE is standardized under the control of 3GPP ("3rd Generation Partnership Project") and has a successor, LTE-A (LTE-Advanced), which allows higher data rates than basic LTE and is also standardized under the control of 3GPP.

[0006] For the future, 3GPP plans to further develop LTE-A so that LTE-A can meet the technical requirements of 5G.

[0007] Since 5G systems can be based on LTE-A or NR, respectively, it is believed that the specific requirements of 5G technology will basically be handled by the features and methods already defined in the LTE-A and NR standard documents.

[0008] Furthermore, 3GPP specifies support for non-public networks, for example, in 3GPP TS 22.261 (V 17.1.0), and addresses management aspects of non-public networks, for example, in 3GPP TS 28.807 (V 0.3.0). Non-public networks are intended for use only by private entities (such as enterprises) and can be deployed in various configurations utilizing both virtual and physical elements. Specifically, non-public networks can be deployed as completely independent networks, hosted by a public land mobile network ("PLMN"), or provided as part of a PLMN.

[0009] 3GPP TS 33.501 (V 16.1.0) specifies the authentication and authorization security procedures between user equipment and mobile communication systems, particularly the authentication procedures between user equipment and non-public networks.

[0010] While techniques exist for authenticating user devices in non-public networks, it is often desirable to improve upon existing techniques. Summary of the Invention

[0011] According to a first aspect, the present disclosure provides a user equipment for a mobile communication system, comprising a circuit configured to: communicate with a non-public network authentication, authorization and accounting server and initiate a registration process with the mobile communication system; and provide an authentication interface between the non-public network authentication, authorization and accounting server and an authentication server functional entity in the mobile communication system.

[0012] According to a second aspect, the present disclosure provides a non-public network authentication, authorization and billing server, comprising a circuit configured to: communicate with an associated user equipment of a mobile communication system; and receive information from the associated user equipment, wherein the associated user equipment receives a data packet from the mobile communication system via an authentication interface provided by the associated user equipment between the non-public network authentication, authorization and billing server and an authentication server function entity in the mobile communication system.

[0013] According to a third aspect, the present disclosure provides a non-public network authentication, authorization and accounting server, comprising a circuit configured to: generate and encrypt an extended master session key based on a pre-shared non-public network authentication, authorization and accounting server ID of the non-public network authentication, authorization and accounting server; and transmit the generated and encrypted extended master session key to an authentication server function entity via a wired interface.

[0014] According to a fourth aspect, the present disclosure provides a non-public network authentication, authorization and accounting server, comprising a circuit configured to: receive a public key from an authentication server functional entity; and generate and encrypt an extended master session key based on the received public key, and transmit the extended master session key to the authentication server functional entity via a wired interface.

[0015] According to a fifth aspect, the present disclosure provides a non-public network authentication, authorization and accounting server, comprising a circuit configured to: obtain a predetermined key pre-stored in a secure memory in the non-public network authentication, authorization and accounting server; generate and encrypt an extended master session key based on the predetermined key; and transmit the generated and encrypted extended master session key to an authentication server functional entity via a wired interface.

[0016] According to a sixth aspect, the present disclosure provides an authentication server functional entity for a mobile communication system, comprising a circuit configured to: register a user equipment associated with a non-public network authentication, authorization and billing server to the mobile communication system; and receive signaling from the user equipment indicating that the user equipment is associated with the non-public network authentication, authorization and billing server, wherein, when the user equipment is authenticated and authorized as a user equipment associated with the non-public network authentication, authorization and billing server in response to the signaling, an authentication interface is provided between the non-public network authentication, authorization and billing server and the authentication server functional entity.

[0017] According to the seventh aspect, the present disclosure provides an authentication server functional entity for a mobile communication system, including a circuit, which is configured to: receive an extended master session key generated and encrypted by a non-public network authentication authorization and billing server via a wired interface; and decrypt the encrypted extended master session key based on the pre-shared non-public network authentication authorization and billing server ID of the non-public network authentication authorization and billing server.

[0018] According to an eighth aspect, the present disclosure provides an authentication server functional entity for a mobile communication system, comprising a circuit configured to: generate a public key and a private key; and transmit the public key to a non-public network authentication, authorization and billing server via a wired interface, wherein the authentication server functional entity holds the private key.

[0019] According to the ninth aspect, the present disclosure provides an authentication server functional entity for a mobile communication system, including a circuit configured to: obtain a predetermined key pre-stored in a secure memory in the authentication server functional entity; receive an extended master session key generated and encrypted by a non-public network authentication authorization and billing server via a wired interface; and decrypt the encrypted extended master session key based on the predetermined key.

[0020] Additional aspects are set forth in the following description and accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The embodiments are explained by way of example with reference to the accompanying drawings, in which:

[0022] Figure 1 A first embodiment of a mobile communication system including a non-public network is schematically illustrated;

[0023] Figure 2 Schematically illustrates a first embodiment of a mobile communication system comprising a non-public network including a user equipment in a state where an authentication interface is established for the non-public network;

[0024] Figure 3 An embodiment for providing an authentication interface for a non-public network is shown as a state diagram;

[0025] Figure 4 Schematically illustrating a second embodiment of a mobile communication system comprising a non-public network, the non-public network comprising a user equipment for providing an authentication interface for the non-public network;

[0026] Figure 5 Schematically illustrates an embodiment of a mobile communication system including a non-public network, the non-public network including a wired interface between a non-public network authentication, authorization and accounting server and an authentication server functional entity;

[0027] Figure 6 A state diagram shows a first embodiment of transmitting an extended master session key from a non-public network authentication, authorization and accounting server to an authentication server function entity via a wired interface;

[0028] Figure 7 A state diagram shows a second embodiment of transmitting an extended master session key from a non-public network authentication, authorization and accounting server to an authentication server function entity via a wired interface;

[0029] Figure 8 An embodiment of a user equipment, a base station, an authentication authorization and accounting server, and an authentication server functional entity is shown in a block diagram; and

[0030] Figure 9 The block diagram shows a multi-purpose computer that can be used to implement user equipment, base stations, authentication, authorization and accounting servers, and authentication server functional entities. DETAILED DESCRIPTION

[0031] In giving reference Figure 2 Before describing the embodiments in detail, a general explanation is given.

[0032] As mentioned at the outset, several generations of mobile communication systems are generally known, such as the third generation ("3G") based on the International Mobile Telecommunications-2000 (IMT-2000) specifications; the fourth generation ("4G") providing functionality as defined in the International Mobile Telecommunications-Advanced standard (IMT-Advanced standard); and the current fifth generation ("5G"), which is under development and may be implemented this year.

[0033] One of the candidates for meeting the 5G requirements is called a New Radio ("NR") access technology system. In some embodiments, some aspects of NR can be based on LTE technology, just as some aspects of LTE are based on previous generations of mobile communication technology.

[0034] Furthermore, 3GPP specifies support for non-public networks, for example, in 3GPP TS 22.261 (V 17.1.0), and addresses management aspects of non-public networks, for example, in 3GPP TS 28.807 (V 0.3.0). Non-public networks are intended for use only by private entities (such as enterprises) and can be deployed in various configurations utilizing both virtual and physical elements. Specifically, non-public networks can be deployed as completely independent networks, hosted by a public land mobile network ("PLMN"), or provided as part of a PLMN.

[0035] In some embodiments, a non-public network is a network deployed outside of a mobile operator's network ("MNO"), and has two deployment options:

[0036] • The NPN is deployed as a Standalone NPN (“SNPN”); and

[0037] •NPN is deployed as part of the MNO as a non-standalone NPN (“NSNPN”).

[0038] In some embodiments, the NPN is hosted by a public network (NSNPN), i.e., a public mobile communications system. This can be achieved by implementing network slicing or access point names ("APNs") of the NPN within a public network ("PN"). In these embodiments, NPN deployment requires a cell-broadcast CAG ("Closed Access Group") ID, also known as a public network-integrated NPN ("PNI-NPN"). In some embodiments, the NPN and the public network share portions of the radio access network ("RAN"), control plane functions (e.g., authentication server function ("AUSF"), or user plane function ("UPF"). As previously described, this can be achieved by implementing network slicing, etc. In such embodiments, public network customers and corresponding user equipment ("UE") are allowed to use the NPN's RAN (e.g., the NPN's base stations) for the public network's control plane functions. In some embodiments, NPN customers are also public network customers and are allowed to register with both networks.

[0039] In the case of SNPN, in some embodiments, the cell broadcasts the PLMN ("Public Land Mobile Network") ID and NPN ID. In these embodiments, the PLMN ID and NPN ID may not be unique, as SNPN is intended to be a covert deployment and therefore no interaction between public networks is foreseen; however, cell resources may be shared between public and non-public networks.

[0040] It is foreseeable that in 3GPP Release-16, the cell selection and reselection behaviors in SNPN cell deployment and NSNPN cell deployment are specified, that is, sharing operator cells and also hosting NPN cell functions.

[0041] 3GPP TS 33.501 (V 16.1.0) specifies the authentication and authorization security procedures between user equipment and mobile communication systems, particularly the authentication procedures between user equipment and non-public networks.

[0042] Generally, in some embodiments, the authentication and key agreement process can achieve mutual authentication between the user device and the network and can be based on the Extensible Authentication Protocol ("EAP") framework. Generally, EAP-AKA is the baseline of 3GPP, but other methods such as EAP-AKA and TLS are also specified. The EAP framework includes roles such as EAP peers, EAP pass-through authenticators, and EAP servers (backend authentication servers). EAP pass-through authenticators may not inspect EAP packets and therefore may not need to implement any authentication methods (such as EAP-AKA ("EAP Authentication and Key Agreement Protocol") or EAP-TLS (EAP Transport Layer Security)). EAP peers and EAP servers must implement authentication methods.

[0043] In some embodiments, a non-public network authentication, authorization, and accounting ("NPN AAA") server participates in the authentication of user devices on the non-public network. Specifically, a user device authenticates with the NPN AAA server, for example, to access services provided by the NPN. Authentication, authorization, and accounting ("AAA") servers are generally known to those skilled in the art, and therefore a detailed description thereof is omitted. In such embodiments, the EAP server role may reside in an authentication server function ("AUSF") entity or the NPN AAA server.

[0044] It is recognized that, since different authentication methods generally require different credentials, the authentication method used to authenticate a user equipment at a (non-standalone) NPN may affect the EAP peer (i.e. UE) and the EAP server (i.e. AUSF entity or NPN AAA server) as well as the key hierarchy (e.g. specified in 3GPP TS 33.501 (V 16.1.0)).

[0045] Generally, in 3GPP Rel-16, the security framework specifies support for (5G-)AKA, EAP-AKA, and EAP-TLS methods. All of these options assume that the EAP server will be located in the core network of the mobile communication system. However, in some embodiments, NPN deployments may have two options: integrating the NPN AAA server with the AUSF entity in the mobile network operator's ("MNO") core network, or integrating the NPN and NPN AAA (EAP server) physically and logically residing within the NPN. In some embodiments, any UE credentials in the NPN deployment may be certificate-based or non-certificate-based.

[0046] It is recognized that in some embodiments, certificate-based credentials may be handled by existing specifications supporting EAP-TLS (a certificate-based approach utilizing an NPN AAA server may not offer any advantages), and that for non-certificate-based credentials that do not utilize an NPN AAA server, EAP-TTLS (EAP-Tunneled Transport Layer Security) may be a suitable authentication method (the changes required for 5G networks may be to encapsulate phase 1 and phase 2 EAP messages in NAS ("Non-Access Stratum") signaling).

[0047] Furthermore, for non-certificate based credentials utilizing an NPN AAA server, in some embodiments, the following issues have been recognized:

[0048] •Interface between 5G core network and NPN AAA server;

[0049] • If the EAP server is located on the NPN AAA server, the (Extended) Master Session Key (“E)MSK”) is transmitted from the NPN AAA server to the AUSF entity; and

[0050] • If the EAP server is located on AUSF, it supports RADIUS ("Remote Authentication Dial-In User Service") or DIAMETER protocols.

[0051] In some embodiments, the authentication method between the UE and the NPN AAA server is EAP-(T)TLS ("EAP-(Tunneled) Transport Layer Security"), and the UE with non-certificate based credentials initiates the authentication process on the NPN AAA server where the EAP server role resides.

[0052] In these embodiments, it is recognized that, as described above, the (Extended) Master Session Key (“E)MSK”) needs to be transferred in a secure manner to the AUSF entity for further key derivation, since the (E)MSK is derived by the UE and the NPN AAA server. Therefore, in these embodiments, an authenticated interface between the NPN AAA server and the AUSF entity is required.

[0053] Below is the reference Figure 1 Discuss example scenarios in the context of Figure 1 A first embodiment of a mobile communication system 1 comprising a non-public network 4 is schematically illustrated.

[0054] A mobile communication system 1 is provided by a mobile network operator (“MNO”) and includes an NR radio access network (RAN) including a cell 2 established by an NR eNodeB 3 (also known as a gNB (next generation eNodeB)).

[0055] In cell 2, for example, a non-public network (NPN) 4 is deployed in a factory. NPN 4 can be established, for example, by network slicing, as described above for the NSNPN case. NPN 4 hosts its own non-public network authentication, authorization, and accounting (NPN AAA) server 5 for authenticating non-public network user equipment (NPN UE) 6, which can be, for example, or installed on a machine. NPN UE 6 can communicate with gNB 3 to authenticate at NPN AAA server 5 via AUSF entity 7 in core network 8.

[0056] In an example scenario, a factory (i.e., NPN 4) holds credentials for the factory's machines (i.e., (machine) NPN UE 6) and wishes to use these credentials for security purposes. Assuming these credentials are similar to a "K" value, which can be stored in a SIM ("Subscriber Identity Module") card and an ARPF ("Authentication Credential Repository and Processing Function") / UDM ("Unified Data Management") in the core network 8, the (field) NPN AAA server 5 may not need to share any credentials with the MNO. (A trust relationship between the two business entities, i.e., the MNO and the factory owner, may not be easy to establish, and the factory owner may prefer to change MNO providers in the future without having to change the SIM card in every machine on the ground.)

[0057] For example, assume that a factory is located at location A where machines and an NPN AAA server 5 are housed, and the MNO HQ (“headquarters”) is located at location B, where the distance between locations A and B is non-contiguous (e.g., 50 km), and location B houses core network entities such as the UPF entity, the AUSF entity 7, and the ARPF / UDM entities (this is for illustration purposes only, the (5G) entities can be virtualized and virtually hosted anywhere).

[0058] Therefore, it has been recognised that an authentication interface is required between the NPN AAA server 5 and the AUSF entity 7 .

[0059] The AUSF entity 7 can be considered one of the most secure entities, and may therefore have to be exposed to each NPN 4 or factory NPN AAA server 5. The (5G) core network has an entity called NEF ("Network Exposure Function") for the purpose of exposing different network entities. However, it has been recognized that exposing the AUSF entity 7 may present security risks, and the above-mentioned issue of transmitting the EMSK from the NPN AAA server 5 to the AUSF entity 7 needs to be addressed.

[0060] Therefore, some embodiments relate to user equipment of a mobile communication system, including a circuit configured to: communicate with a non-public network authentication authorization accounting server and initiate a registration process with the mobile communication system; and provide an authentication interface between the non-public network authentication authorization accounting server and an authentication server functional entity in the mobile communication system.

[0061] The user equipment may be or may include an electronic device, a smartphone, a virtual reality (VR) device, a laptop computer, etc. The circuit may include at least one of the following: a processor, a microprocessor, a dedicated circuit, a memory, a storage device, a radio interface, a wireless interface, a network interface, etc., such as typical electronic components included in the user equipment to implement the functions described herein. The user equipment includes credentials for a mobile communication system, which may be based on a UMTS, LTE, LTE-A or NR, 5G system, etc.

[0062] The user device can communicate with the Non-Public Network Authentication Authorization Accounting (NPNAAA) server via a well-known wireless or network interface. In some embodiments, the user device is physically integrated into the NPN AAA server as an electronic component to implement the functions described herein.

[0063] The registration procedure may be any registration procedure commonly performed in a mobile communication system.

[0064] The authentication interface is logically located between the NPN AAA server and the AUSF entity in the core network and provides a secure logical and physical channel between the NPN AAA server and the AUSF entity. The user equipment is associated with the NPN AAA server in the mobile communication system, and any message or data packet for the NPN AAA server may be transmitted from the mobile communication system (i.e., the user equipment) via the authentication interface.

[0065] In some embodiments, a non-public network user equipment (NPN UE) located in an NPN transmits a data packet via an authentication interface for authenticating on an NPN AAA server. In some embodiments, the data packet comprises an EAP data packet.

[0066] When the NPN AAA server is started or powered on, or when the UE device is connected to the AAA server, the user equipment initiates a registration process with the mobile communication system and the ARPF / UDM and AUSF network entities. For example, during the registration process, the AUSF entity may be informed that the user equipment is a factory NPN AAA server.

[0067] Therefore, in some embodiments, the user equipment signals to the authentication server function entity during the registration process with the mobile communication system an indication that the user equipment is associated with a non-public network authentication, authorization and accounting server for providing an authentication interface.

[0068] In some embodiments, the user equipment includes a dedicated SIM card to identify the user equipment as being associated with the NPN AAA server.

[0069] In some embodiments, the signaling is based on access stratum signaling messages or non-access stratum signaling messages.

[0070] These messages may be any AS or NAS messages typically transmitted from a user equipment to an authentication server function entity and may include one or more bits indicating an association with an NPN AAA server.

[0071] In some embodiments, signaling is performed when the registration process is initiated.

[0072] In some embodiments, signaling is performed when a security context (security context) has been established between the user equipment and the authentication server function entity.

[0073] In some embodiments, signaling is performed when a secure environment is established on all nodes.

[0074] The establishment of the secure environment can be based on any authentication method supported in mobile communications for authenticating user devices, such as (5G-)AKA, EAP-AKA', or EAP-TLS. In some embodiments, the authentication method used during the registration process includes one of Authentication and Key Agreement Protocol, Extensible Authentication Protocol Authentication and Key Agreement Protocol, and Extensible Authentication Protocol Transport Layer Security.

[0075] When the security environment is established, the user equipment and the AUSF entity have authenticated each other, and the encryption keys and integrity protection keys of the AS and NAS are in place.

[0076] Therefore, in some embodiments, when the user equipment is authenticated and authorized as a user equipment associated with the non-public network authentication authorization accounting server in response to signaling, an authentication interface is provided between the non-public network authentication authorization accounting server and the authentication server function entity.

[0077] As mentioned above, in some embodiments, because the (E)MSK is derived by the UE and the NPN AAA server, the (Extended) Master Session Key (“(E)MSK”) needs to be transferred to the AUSF entity in a secure manner for further key derivation. Therefore, in such embodiments, an authenticated interface between the NPN AAA server and the AUSF entity is required for the transfer.

[0078] Furthermore, for the case of using a user device associated with an NPN AAA server and mobile communications and using a wired internet based connection, there remains the question of transferring the EMSK from the NPN AAA to the AUSF entity of EAP-(T)TLS (in a secure manner).

[0079] Therefore, the circuit of the user equipment is further configured to: transmit the extended master session key generated and encrypted by the non-public network authentication, authorization and accounting server to the authentication server function entity via the authentication interface.

[0080] In some embodiments, the physical path for transferring the EMSK from the NPN AAA server to the AUSF entity is: NPN AAA server->associated user equipment->gNB->UPF (or AMF (for control plane solution))->AUSF entity.

[0081] In these embodiments, the EMSK may be encrypted using the associated user device credentials. For example, the EMSK of a non-public network user device (note that this is not the user device associated with the NPN AAA server, but the user device that initiated authentication on the NPN AAA server) may be encrypted using the associated user device's Kausf or CK / IK or RRCint, UPciph key, or a new key derived from the CK / IK, specifically for this purpose and valid only for the associated user device.

[0082] Therefore, when the user device and the AUSF entity have established a secure environment, all keys are in place and the user device's credentials can be used to generate and encrypt the EMSK.

[0083] Thus, in some embodiments, the generated and encrypted extended master session key is encrypted based on the credentials of the user device, where the credentials are one of Kausf, CK / IK, RRCint, and UPciph.

[0084] In some embodiments, the generated and encrypted extended master session key is encrypted based on credentials of the user device, where the credentials are derived from the CK / IK.

[0085] The authentication interface can be provided by a solution based on user plane functions, where EAP signaling messages (EAP packets) can be treated as user plane packets. Since EAP signaling messages are likely small in size, existing network architectures can be maintained, with security functionality residing solely on the control plane ("CP") path. A potential risk with CP solutions is that some messages may be interpreted differently by different nodes, such as the AMF ("Access Mobility Management Function") / SMF ("Session Management Function") entities. Consequently, any EAP message encapsulated within a NAS message could be read by the AMF / SMF entity.

[0086] Therefore, in some embodiments, an authentication interface is provided via a user plane function of the mobile communication system.

[0087] In some embodiments, Extensible Authentication Protocol packets transmitted via the authentication interface are considered user plane packets.

[0088] Furthermore, in some embodiments, the circuitry of the user equipment is further configured to: prohibit access to any other data or other services provided by the mobile communication system.

[0089] The user equipment may pass the received information (eg, data packets or signaling messages) to the NPN AAA server, which may act as an application located above the AS / NAS layer of the user equipment.

[0090] In some embodiments, the circuitry of the user equipment is further configured to transmit any information received from the mobile communication system to an associated non-public network authentication, authorization and accounting server via the authentication interface.

[0091] In some embodiments, the received information includes an Extensible Authentication Protocol data packet from a non-public network user equipment located in a non-public network, for performing authentication on a non-public network authentication, authorization and accounting server.

[0092] In some embodiments, the circuit of the user equipment is further configured to: determine the access point name in the registration process as the authentication server function entity or the authentication credential repository and processing function entity or the unified data management entity.

[0093] In some embodiments, the authentication interface supports the RADIUS or DIAMETER protocols.

[0094] In general, RADIUS may be less secure than DIAMETER. However, given that many legacy systems may use RADIUS, it may be used due to the robustness provided by the inherent 3GPP security.

[0095] Additionally, there may be no need to support EAP-TTLS, as 3GPP provides the secure tunnel.

[0096] According to the embodiments described herein, some embodiments relate to a non-public network authentication, authorization and accounting server, comprising a circuit configured to: communicate with an associated user equipment of a mobile communication system; and receive information from the associated user equipment, wherein the associated user equipment receives a data packet from the mobile communication system via an authentication interface provided by the associated user equipment and located between the non-public network authentication, authorization and accounting server and an authentication server function entity in the mobile communication system.

[0097] Authentication, Authorization and Accounting ("AAA") servers are generally known to those skilled in the art, and thus a detailed description thereof is omitted. The circuitry may include at least one of the following: a processor, a microprocessor, a dedicated circuit, a memory, a storage device, a radio interface, a wireless interface, a network interface, etc., such as typical electronic components included in an AAA server to implement the functions described herein.

[0098] The association of the user equipment with the NPN AAA server may be based on a predetermined ID (identification) known to both the user equipment and the NPN AAA server, may be based on a (dedicated) SIM card of the user equipment known to the NPN AAA server, may be based on predetermined messages or keys exchanged during setup or operation or configuration of a predetermined communication path, etc., or the association of the user equipment with the NPN AAA server may be established by physically integrating the user equipment, etc.

[0099] As described above, in some embodiments, once the user equipment is authenticated and authorized by the mobile communication system, an authentication interface can be set up between the NPN AAA server and the AUSF entity via the user equipment function, and the data packet is transmitted to the NPN AAA server via the authentication interface and the user equipment.

[0100] In some embodiments, the information received from the associated user device includes an Extensible Authentication Protocol data packet from a non-public network user device located in a non-public network for authentication on a non-public network authentication and authorization computing server.

[0101] In some embodiments, the circuitry of the non-public network authentication, authorization, communication and billing server is further configured to generate and encrypt an extended master session key based on credentials of the associated user device.

[0102] In some embodiments, the non-public network authentication authorization accounting server transmits the generated and encrypted extended master session key to the associated user equipment for transmitting the generated and encrypted extended master session key to the authentication server function entity via the authentication interface.

[0103] As an example procedure for providing an authentication interface between a non-public network authentication authorization server and an authentication server functional entity:

[0104] The NPN AAA server is powered on and communicates with the associated user equipment to initiate provisioning of the authentication interface.

[0105] The associated user equipment then searches for the operator's network and camps on a suitable cell, which is shared between the NPN and the PLMN.

[0106] The associated user equipment initiates a registration procedure, namely an RRC ("Radio Resource Control") and NAS registration procedure, and signals to the core network that it is associated with the NPN AAA server.

[0107] A security process is initiated for a typical user device, and key derivation begins while assuming the user device with the K value as a typical user device.

[0108] The user equipment and the network (i.e., the mobile communication system) are then mutually authenticated, and the encryption and integrity protection keys for the AS and NAS are in place.

[0109] Once the 5G security context is established between the UE and the AUSF entity, a new authentication interface is established on the (5G) network. The physical node security responsibility for the NPN AAA server and the associated UE is within the factory (as an example).

[0110] Generally, in some embodiments, there are the following advantages:

[0111] •MNO can sell dedicated SIM cards for NPN AAA servers and charge fees based on factory business;

[0112] • The AUSF entity is not exposed to the Internet, and all services are carried over the operator network. The solution is scalable, allowing multiple NPN AAA servers to be connected to the AUSF entity;

[0113] • Factory owners (for example) do not expose machine credentials to the MNO, are not tied to a single operator, and are free to choose their market;

[0114] • Support for legacy protocols such as RADIUS or DIAMTER; and

[0115] • EAP-TTL support may not be required.

[0116] According to the embodiments described herein, some embodiments relate to an authentication server functional entity of a mobile communication system, comprising a circuit configured to: register a user equipment associated with a non-public network authentication, authorization and billing server to the mobile communication system; and receive signaling from the user equipment indicating that the user equipment is associated with the non-public network authentication, authorization and billing server, wherein, when the user equipment is authenticated and authorized as a user equipment associated with the non-public network authentication, authorization and billing server in response to the signaling, an authentication interface is provided between the non-public network authentication, authorization and billing server and the authentication server functional entity.

[0117] The authentication server functional entity is well known in mobile communication systems, and therefore, a detailed description thereof is omitted. The circuit may include at least one of the following: a processor, a microprocessor, a dedicated circuit, a memory, a storage device, a radio interface, a wireless interface, a network interface, etc., for example, typical electronic components included in the authentication server functional entity to implement the functions described herein.

[0118] In some embodiments, the circuit of the authentication server function entity is further configured to: receive, via the authentication interface, an extended master session key generated and encrypted by the non-public network authentication authorization accounting server, wherein the generated and encrypted extended master session key is encrypted based on the credentials of the user equipment associated with the non-public network authentication authorization accounting server.

[0119] As mentioned above, in case a wired (internet-based) connection (wired interface) is used, there still remains the issue of transferring the EMSK from the NPN AAA to the AUSF entity for EAP-(T)TLS (in a secure manner).

[0120] For wired interfaces, there may be two options:

[0121] In some embodiments, the NPN AAA server is assigned an ID, and both the NPN AAA server and the AUSF entity know the ID. In these embodiments, the EMSK is encrypted using the NPN AAA server ID, which may be the certificate of the NPN AAA server.

[0122] Alternatively, in some embodiments, in a PKI ("Public Key Infrastructure")-based solution, the AUSF entity sends a public key to the NPN AAA server, and the AUSF entity holds a private key (e.g., in memory, etc.). In the NPN AAA server, the EMSK is encrypted using the AUSF entity's public key. In the AUSF entity, the EMSK is decrypted using the private key.

[0123] Alternatively, in some embodiments, as a solution based on a pre-shared key (PSK), the MNO provides a key for this purpose, which can be stored separately on a dedicated SIM card in the NPN AAA server. The SIM card may have storage capacity for additional information, and only authorized users can access the card. Note that in some embodiments, this is different from the 3GPP pre-shared key (K) in the SIM. In the NPN AAA server, the EMSK is encrypted using the key. In the AUSF entity, the same key configured by the MNO is used for decryption. In another embodiment, the NPN operator issues the key and stores it in secure storage in the NPN AAA server. The NPN operator separately provides the key to the MNO, which then stores the key in the AUSF entity in advance.

[0124] Therefore, some embodiments relate to a non-public network authentication, authorization and accounting server, including a circuit configured to: generate and encrypt an extended master session key based on a pre-shared non-public network authentication, authorization and accounting server ID of the non-public network authentication, authorization and accounting server; and transmit the generated and encrypted extended master session key to an authentication server function entity via a wired interface.

[0125] Therefore, some embodiments relate to an authentication server functional entity for a mobile communication system, comprising a circuit configured to: receive an extended master session key generated and encrypted by a non-public network authentication, authorization and billing server via a wired interface; and decrypt the encrypted extended master session key based on a pre-shared non-public network authentication, authorization and billing server ID of the non-public network authentication, authorization and billing server.

[0126] In some embodiments, the pre-shared non-public network authentication authorization accounting server ID is one of a key, an ID, and a certificate of the non-public network authentication authorization accounting server.

[0127] In addition, some embodiments relate to an authentication server function entity for a mobile communication system, comprising a circuit configured to: generate a public key and a private key; and transmit the public key to a non-public network authentication authorization and accounting server via a wired interface, wherein the authentication server function entity holds the private key.

[0128] Therefore, some embodiments relate to a non-public network authentication, authorization and accounting server, comprising circuitry configured to: receive a public key from an authentication server functional entity; generate and encrypt an extended master session key based on the received public key; and transmit the extended master session key to the authentication server functional entity via a wired interface.

[0129] In some embodiments, the circuit of the authentication server function entity is further configured to: receive an extended master session key generated and encrypted by the non-public network authentication authorization and accounting server based on a public key via a wired interface; and decrypt the received extended master session key based on the retained private key.

[0130] In addition, some embodiments relate to a non-public network authentication, authorization and accounting server, including a circuit configured to: obtain a predetermined key pre-stored in a secure memory in the non-public network authentication, authorization and accounting server; generate and encrypt an extended master session key based on the predetermined key; and transmit the generated and encrypted master session key to an authentication server functional entity via a wired interface.

[0131] As described above, the keys can be provided by the MNO or NPN operator and can be pre-exchanged between the MNO or NPN operator. The keys can be stored in secure storage within the NPN AAA server and the AUSF entity. The secure storage can be a dedicated SIM card for the NPN AAA server. The SIM card can have storage capacity for additional information and can only be accessed by authorized users (e.g., the NPN AAA server). For the AUSF entity, the SIM card can be protected storage, particularly for storing keys for the NPN operator, etc.

[0132] According to the embodiments described herein, some embodiments relate to an authentication server function entity for a mobile communication system, comprising a circuit configured to: obtain a predetermined key pre-stored in a secure memory in the authentication server function entity; receive an extended master session key generated and encrypted by a non-public network authentication authorization and billing server via a wired interface; and decrypt the encrypted extended master session key based on the predetermined key.

[0133] return Figure 2 , Figure 2A first embodiment of a mobile communication system 1 comprising a non-public network 4 is schematically shown. The non-public network 4 comprises a user equipment 9 which is in a state of establishing an authentication interface for the non-public network 4 .

[0134] A mobile communication system 1 is provided by a mobile network operator (“MNO”) and includes an NR radio access network (RAN) including a cell 2 established by an NR eNodeB 3 (also known as a gNB (next generation eNodeB)).

[0135] In cell 2, for example, a non-public network (NPN) 4 is deployed in a factory. This non-public network (NPN) 4 can be established, for example, by network slicing, as described above for a non-standalone NPN. NPN 4 hosts its own non-public network authentication, authorization, and accounting (NPN AAA) server 5 for authenticating a non-public network user equipment (NPN UE) 6, which can be, for example, a machine. NPN UE 6 can communicate with gNB 3 to authenticate at NPN AAA server 5 via AUSF entity 7 in core network 8.

[0136] In addition, the NPN AAA server 5 communicates with an associated user equipment 9 (AAA UE). The AAA UE 9 communicates with the mobile communication system 1 via the gNB 3 and initiates a registration procedure with the mobile communication system 1 at the AUSF entity 7. During the registration procedure, the AAA UE 9 signals its association with the NPN AAA server 5 to the AUSF entity 7. As described herein, this is indicated by a dashed line carrying a message 10 (which may include one or more bits for signaling). Message 10 is an AS or NAS message and is transmitted when establishing a security context. In response to this signaling, an authentication interface is provided between the NPN AAA server 5 and the AUSF entity 7 via the AAA UE 9.

[0137] Figure 3 An embodiment for providing an authentication interface for a non-public network 4 is shown as a state diagram.

[0138] This embodiment is based on Figure 2 and Figure 4 Deployment of Non-Public Network (NPN) 4.

[0139] At 20, the non-public network authentication authorization accounting (NPN AAA) server 5 is powered on and communicates with the associated user equipment (AAA UE) 9 for initiating the authentication interface 11 between the NPN AAA server 5 and the authentication server function (AUSF) entity 7 (see Figure 4), the AAA UE 9 searches for the operator network and camps on a suitable cell, ie, the cell 2 shared between the NPN 4 and the PLMN.

[0140] In the following, for illustration purposes, the authentication interface 11 is divided into an internal authentication interface 11a (between the NPN AAA server 5 and the AAA UE 9, indicated by the dotted area between the NPN AAA server 5 and the AAA UE 9) and an external authentication interface 11b (between the AAA UE 9 and the AUSF entity 7, indicated by the dotted line from the AAA UE 9 to the AUSF entity 7).

[0141] At 21 , the AAA UE 9 initiates a registration procedure with the mobile communication system, ie the AUSF entity 7 , ie an RRC (“Radio Resource Control”) and NAS registration procedure.

[0142] At 22, the AAA UE 9 and the AUSF entity 7 establish a security context, i.e., perform a security procedure. This security context is established based on any authentication method supported in mobile communications for authenticating the AAA UE 9, such as (5G-)AKA, EAP-AKA', or EAP-TLS, as described herein. The security procedure is initiated for a typical user equipment of a mobile communications system, and key derivation begins, assuming that the AAA UE 9 has a K value typical of a typical user equipment. The AAA UE 9 and the AUSF entity 7 then mutually authenticate each other, and the encryption and integrity protection keys for the AS and NAS are in place.

[0143] At 23 , when the security context is established, the AAA UE 9 signals the AUSF entity 7 in an AS or NAS signalling message (which may be any message commonly exchanged including one or more bits for signalling associated with the AAA UE 9 and the NPN AAA server 5 ).

[0144] Then, at 24, in response to the signaling, an authentication interface 11 is provided between the NPN AAA server 5 and the AUSF entity 7 via the AAA UE 9. Furthermore, the authentication interface 11 is provided via the user plane function of the mobile communication system such that the EAP signaling messages are treated as user plane data packets.

[0145] At 25 , the AAA UE 9 sends credentials (one of Kausf, CK / IK, RRCint, and UPciph) to the NPN AAA server 5 via the internal authentication interface 11 a for generating and encrypting an extended master session key (EMSK) for a non-public network user equipment (NPN UE) 6 located in the NPN 4, the non-public network user equipment (NPN UE) 6 being, for example, a machine including user equipment for communicating with a mobile communication system and for authenticating at the NPN AAA server 5.

[0146] At 26a, the NPN UE 6 (EAP peer) sends an authentication request (a data packet of an EAP signaling message) for authentication at the NPN AAA server 5 via the user plane function over the network, which is transparently forwarded by the AUSF entity 7 (EAP pass-through authenticator) to the AAA UE 9 over the external authentication interface 11b at 26b.

[0147] At 26 c , the AAA UE 9 sends the received information (data packet) including the EAP data packet to the NPN AAA server 5 via the internal authentication interface 11 a for authenticating the NPN UE 6 at the NPN AAA server 5 .

[0148] At 27 , the NPN AAA server 5 generates and encrypts the EMSK based on the credentials of the AAA UE 9 (the NPN AAA server 5 holds the credentials of the NPN UE 6 for authentication).

[0149] The generated and encrypted EMS is transmitted to the AUSF entity 7 via the authentication interface 11 provided by the AAA UE 9 between the NPN AAA server 5 and the AUSF entity 7 at 28a and 28b.

[0150] Figure 4 A second embodiment of a mobile communication system 1 comprising a non-public network (NPN) 4 including a user equipment (AAA UE) 9 for providing an authentication interface 11 for the NPN 4 is schematically shown.

[0151] This embodiment is based on Figure 2, and shows a new logical and physical authentication interface 11 provided between the NPN AAA server 5 and the AUSF entity 7 via the AAA UE 9. The dashed arrow shows the logical authentication interface 11 and the solid arrow shows the actual (physical) path in the authentication interface 11. For illustration purposes, the authentication interface 11 is divided into an internal authentication interface 11a (between the NPN AAA server 5 and the AAA UE 9, shown by the dashed area between the NPN AAA server 5 and the AAA UE 9) and an external authentication interface 11b (between the AAA UE 9 and the AUSF entity 7, shown by the dashed line from the AAA UE 9 to the AUSF entity 7).

[0152] Figure 5 An embodiment of a mobile communication system 1a is schematically shown, which includes a non-public network (NPN) 4, which includes a wired interface 12 between a non-public network authentication, authorization and accounting (NPN AAA) server 5 and an authentication server function (AUSF) entity 7.

[0153] In addition to the NPN AAA server 5 being physically connected to the AUSF entity 7 via a wired interface 12 (eg an Internet-based connection), this embodiment is based on Figure 1 Embodiment of ,.

[0154] Figure 6 A first embodiment of the transmission of an extended master session key (EMSK) from a non-public network authentication authorization accounting (NPN AAA) server 5 to an authentication server function (AUSF) entity 7 via a wired interface 12 is shown in a state diagram.

[0155] This embodiment is based on Figure 5 Deployment of Non-Public Network (NPN) 4.

[0156] At 30 , the NPN AAA server 5 generates and encrypts the EMSK based on a pre-shared NPN AAA server ID of the NPN AAA server 5 , where the pre-shared NPN AAA ID is one of a key, an ID, and a certificate of the NPN AAA server 5 .

[0157] At 31 , the NPN AAA server 5 transmits the generated and encrypted EMSK to the AUSF entity 7 via the wired interface 12 .

[0158] At 32 , the AUSF entity 7 receives the EMSK via the wired interface 12 and decrypts the EMSK based on the pre-shared NPN AAA server ID of the NPN AAA server 5 .

[0159] In an alternative embodiment, at 30, the NPN AAA server 5 obtains a predetermined key pre-stored in a secure memory in the NPN AAA server 5 (eg, the key is loaded from a dedicated SIM card of the NPN AAA server 5). Furthermore, the NPN AAA server 5 generates and encrypts an EMSK based on the predetermined key.

[0160] At 31 , the NPN AAA server 5 transmits the generated and encrypted master session key to the AUSF entity 7 via the wired interface 12 .

[0161] At 32, the AUSF entity 7 obtains a predetermined key pre-stored in a secure memory in the AUSF entity 7 (e.g., loads the key from a protected memory in the AUSF entity 7). In addition, the AUSF entity 7 receives the EMSK generated and encrypted by the NPNAAA server 5 via the wired interface 12, and decrypts the EMSK based on the predetermined key.

[0162] Figure 7 A second embodiment of the transmission of an extended master session key (EMSK) from a non-public network authentication authorization accounting (NPN AAA) server 5 to an authentication server function (AUSF) entity 7 via a wired interface 12 is shown in a state diagram.

[0163] This embodiment is based on Figure 5 Deployment of Non-Public Network (NPN) 4.

[0164] At 40, the AUSF entity 7 generates a public key and a private key.

[0165] At 41 , the AUSF entity 7 transmits the public key to the NPN AAA server via the wired interface 12 , where the AUSF entity 7 holds the private key (in memory).

[0166] At 42, the NPN AAA server 5 receives the public key from the AUSF entity 7 and generates and encrypts the EMSK based on the received public key.

[0167] At 43 , the NPN AAA server 5 transmits the EMSK to the AUSF entity 7 via the wired interface 12 .

[0168] At 44, the AUSF entity 7 receives the EMSK via the wired interface 12 and decrypts the received EMSK based on the private key it holds.

[0169] refer to Figure 8An embodiment of a user equipment (AAA UE) 9, a base station (BS) 3 (e.g., NR eNB / gNB), a communication path 104 between the AAA UE 9 and the BS 3, an authentication server function (AUSF) entity 7, a communication path 108 between the BS 3 and the AUSF entity 7 (the BS 3 may not be directly connected to the AUSF entity, but for illustration purposes, the communication path 108 is illustrated as a direct connection), a non-public network authentication, authorization, and accounting (NPN AAA) server 5, a communication path 109 between the NPN AAA server 5 and the AAA UE 9 is discussed, which is used to implement an embodiment of the present disclosure.

[0170] The AAA UE 9 has a transmitter 101, a receiver 102 and a controller 103, wherein generally, those skilled in the art know the technical functions of the transmitter 101, the receiver 102 and the controller 103, and therefore, a more detailed description thereof is omitted.

[0171] The BS 3 has a transmitter 105, a receiver 106, and a controller 107, wherein here, generally, the functions of the transmitter 105, the receiver 106, and the controller 107 are known to those skilled in the art, and therefore, a more detailed description thereof is omitted.

[0172] The communication path 104 has an uplink path 104 a from the AAA UE 9 to the BS 3 and a downlink path 104 b from the BS 3 to the AAA UE 9 .

[0173] During operation, the controller 103 of the AAA UE 9 controls the reception of downlink signals at the receiver 102 over the downlink path 104b, and the controller 103 controls the transmission of uplink signals via the transmitter 101 over the uplink path 104a.

[0174] Similarly, during operation, the controller 107 of the BS 3 controls the transmission of downlink signals via the transmitter 105 over the downlink path 104b, and the controller 107 controls the reception of uplink signals at the receiver 106 over the uplink path 104a.

[0175] The BS 3 may communicate with the AUSF entity 7 via a communication path 108, which may be provided by a network interface commonly used for such communication. Since such communication via a network interface is known to the skilled person, a more detailed description thereof is omitted.

[0176] The NPN AAA server 5 may communicate with the AAA UE 9 via a communication path 109, which may be provided by a network interface typically used for such communication. Since such communication via a network interface is known to the skilled person, a more detailed description thereof will be omitted.

[0177] Figure 9 The block diagram shows a multi-purpose computer 130 that can be used to implement user equipment, base stations, non-public network authentication, authorization and accounting servers, and authentication server functional entities.

[0178] The computer 130 can be implemented so that the computer 130 can be used as essentially any type of user equipment, a base station or a new radio base station, a transmitting and receiving point, or a non-public network authentication, authorization and accounting server, or an authentication server functional entity as described herein. The computer has components 131 to 141, which can form circuits, such as any of the circuits of a base station and user equipment as described herein.

[0179] Embodiments of the methods described herein that utilize software, firmware, programs, etc., may be installed on the computer 130 and the computer 130 may then be configured as appropriate for the specific embodiment.

[0180] The computer 130 has a CPU 131 (central processing unit) that can execute the various types of processes and methods described herein, for example, according to a program stored in a read-only memory (ROM) 132 , stored in a storage device 137 and loaded into a random access memory (RAM) 133 , stored on a medium 140 that can be inserted into a corresponding drive 139 , or the like.

[0181] The CPU 131, ROM 132, and RAM 133 are connected to a bus 141, which in turn is connected to an input / output interface 134. The number of CPUs, memories, and storage devices is merely an illustrative example, and those skilled in the art will understand that when the computer 130 is used as a base station or user equipment, the computer 130 can be adjusted and configured accordingly to meet specific requirements that arise.

[0182] At the input / output interface 134 , several components are connected: input 135 , output 136 , storage 137 , communication interface 138 and drive 139 into which a medium 140 (compact disc, digital video disc, compact flash, etc.) can be inserted.

[0183] Input 135 may be a pointing device (mouse, tablet, etc.), keyboard, microphone, camera, touch screen, etc.

[0184] The output 136 may include a display (a liquid crystal display, a cathode ray tube display, a light emitting diode display, etc.), a speaker, and the like.

[0185] The storage device 137 may have a hard disk, a solid-state drive, or the like.

[0186] The communication interface 138 may be adapted for communication, for example, via a local area network (LAN), a wireless local area network (WLAN), a mobile communication system (GSM, UMTS, LTE, NR, etc.), Bluetooth, infrared, etc.

[0187] It should be noted that the above description relates only to an example configuration of the computer 130. Alternative configurations may be implemented with additional or other sensors, storage devices, interfaces, etc. For example, the communication interface 138 may support other radio access technologies besides the aforementioned UMTS, LTE, and NR.

[0188] In the case where computer 130 is used as a base station, communication interface 138 may also have separate air interfaces (providing, for example, E-UTRA protocols OFDMA (downlink) and SC-FDMA (uplink)) and network interfaces (implementing, for example, protocols such as S1-AP, GTP-U, S1-MME, X2-AP, etc.). Computer 130 may also be implemented to transmit data according to TCP. Furthermore, computer 130 may have one or more antennas and / or antenna arrays. The present disclosure is not limited to any particularity of such protocols.

[0189] If not stated otherwise, all units and entities described in this specification and claimed in the appended claims may be implemented as integrated circuit logic, for example, on a chip, and if not stated otherwise, the functions provided by these units and entities may be implemented by software.

[0190] Where the above disclosed embodiments are at least partially implemented using software controlled data processing apparatus, it will be appreciated that a computer program providing such software control and transmission, a memory or other medium providing such computer program are contemplated as aspects of the present disclosure.

[0191] Note that the present technology can also be configured as described below.

[0192] (1) A user equipment for a mobile communication system, comprising a circuit, wherein the circuit is configured to:

[0193] Communicate with the non-public network authentication authorization accounting server and initiate a registration process with the mobile communication system; and

[0194] An authentication interface is provided between a non-public network authentication, authorization and accounting server and an authentication server functional entity in a mobile communication system.

[0195] (2) The user equipment according to (1), wherein the user equipment signals to the authentication server function entity an indication that the user equipment is associated with a non-public network authentication, authorization and accounting server for providing an authentication interface during a registration process with the mobile communication system.

[0196] (3) The user equipment according to (2), wherein the signaling is based on an access stratum signaling message or a non-access stratum signaling message.

[0197] (4) The user equipment according to (2) or (3), wherein the signaling is performed when the user equipment and the authentication server function entity have established a secure environment.

[0198] (5) The user equipment according to (4), wherein when the user equipment is authenticated and authorized as a user equipment associated with the non-public network authentication authorization accounting server in response to the signaling, an authentication interface is provided between the non-public network authentication authorization accounting server and the authentication server function entity.

[0199] (6) The user equipment according to any one of (1) to (5), wherein the circuit is further configured to: transmit the extended master session key generated and encrypted by the non-public network authentication authorization accounting server to the authentication server function entity via the authentication interface.

[0200] (7) The user device of (6), wherein the generated and encrypted extended master session key is encrypted based on a credential of the user device, wherein the credential is one of Kausf, CK / IK, RRCint, and UPciph.

[0201] (8) The user device according to (6) or (7), wherein the generated and encrypted extended master key is encrypted based on credentials of the user device, wherein the credentials are derived from the CK / IK.

[0202] (9) The user equipment according to any one of (1) to (8), wherein the authentication interface is provided via a user plane function of the mobile communication system.

[0203] (10) The user equipment according to (9), wherein the Extensible Authentication Protocol data packets transmitted via the authentication interface are regarded as user plane data packets.

[0204] (11) The user equipment according to any one of (1) to (10), wherein the authentication interface supports RADIUS or DIAMETER protocol.

[0205] (12) The user equipment according to any one of (1) to (11), wherein the authentication method used in the registration process includes one of Authentication and Key Agreement Protocol (AKA), Extensible Authentication Protocol (EAP), and Extensible Authentication Protocol Transport Layer Security (EATLS).

[0206] (13) The user equipment according to any one of (1) to (12), wherein the circuit is further configured to: determine the access point name in the registration process as the authentication server function entity or the authentication credential repository and processing function entity or the unified data management entity.

[0207] (14) The user equipment according to any one of (1) to (13), wherein the circuit is further configured to: prohibit access to any other data or other services provided by the mobile communication system.

[0208] (15) The user equipment according to any one of (1) to (14), wherein the circuit is further configured to: transmit any information received from the mobile communication system to an associated non-public network authentication authorization and accounting server via the authentication interface.

[0209] (16) The user equipment according to (15), wherein the received information includes an Extensible Authentication Protocol data packet from a non-public network user equipment located in a non-public network, for performing authentication on a non-public network authentication, authorization and accounting server.

[0210] (17) The user equipment according to any one of (2) to (16), wherein the signaling is performed when a security context is established on all nodes.

[0211] (18) A non-public network authentication, authorization and accounting server comprising a circuit configured to:

[0212] communicating with user equipment associated with a mobile communications system; and

[0213] The information is received from an associated user equipment, wherein the associated user equipment receives a data packet from the mobile communication system via an authentication interface provided by the associated user equipment between a non-public network authentication authorization and accounting server and an authentication server function entity in the mobile communication system.

[0214] (19) The non-public network authentication authorization accounting server according to (18), wherein the information received from the associated user equipment includes an Extensible Authentication Protocol data packet from the non-public network user equipment located in the non-public network for authentication on the non-public network authentication authorization accounting server.

[0215] (20) The non-public network authentication, authorization and accounting server according to (18) or (19), wherein the circuit is further configured to:

[0216] Generates and encrypts an extended master session key based on the credentials of the associated user device.

[0217] (21) The non-public network authentication authorization accounting server according to (20), wherein the non-public network authentication authorization accounting server transmits the generated and encrypted extended master session key to the associated user equipment to transmit the generated and encrypted extended master session key to the authentication server function entity via the authentication interface.

[0218] (22) A non-public network authentication, authorization and accounting server comprising a circuit configured to:

[0219] Generate and encrypt an extended master session key based on the pre-shared non-public network authentication authorization accounting server ID of the non-public network authentication authorization accounting server; and

[0220] The generated and encrypted extended master session key is transmitted to the authentication server function entity via the wired interface.

[0221] (23) The non-public network authentication authorization accounting server according to (22), wherein the pre-shared non-public network authentication authorization accounting server ID is one of a key, an ID, and a certificate of the non-public network authentication authorization accounting server.

[0222] (24) A non-public network authentication, authorization and accounting server comprising a circuit configured to:

[0223] receiving a public key from an authentication server functional entity;

[0224] generating and encrypting an extended master session key based on the received public key; and

[0225] The extended master session key is transmitted to the authentication server function entity via the wired interface.

[0226] (25) A non-public network authentication, authorization and accounting server comprising a circuit configured to:

[0227] Obtaining a predetermined key pre-stored in a secure memory in a non-public network authentication, authorization and accounting server;

[0228] Generate and encrypt an extended master session key based on a predetermined key; and

[0229] The generated and encrypted extended master session key is transmitted to the authentication server function entity via the wired interface.

[0230] (26) An authentication server functional entity for a mobile communication system, comprising a circuit configured to:

[0231] registering a user equipment associated with the non-public network authentication, authorization and accounting server with the mobile communication system; and

[0232] Signaling is received from a user equipment, indicating that the user equipment is associated with a non-public network authentication, authorization and accounting server. When the user equipment is authenticated and authorized as a user equipment associated with the non-public network authentication, authorization and accounting server in response to the signaling, an authentication interface is provided between the non-public network authentication, authorization and accounting server and an authentication server function entity.

[0233] (27) The authentication server functional entity according to (26), wherein the circuit is further configured to:

[0234] An extended master session key generated and encrypted by the non-public network authentication authorization accounting server is received via the authentication interface, wherein the generated and encrypted extended master session key is encrypted based on credentials of a user device associated with the non-public network authentication authorization accounting server.

[0235] (28) An authentication server functional entity for a mobile communication system, comprising a circuit configured to:

[0236] receiving, via a wired interface, an extended master session key generated and encrypted by a non-public network authentication authorization accounting server; and

[0237] Decrypts the encrypted extended master session key based on the pre-shared non-public network authentication authorization accounting server ID of the non-public network authentication authorization accounting server.

[0238] (29) The authentication server functional entity according to (28), wherein the pre-shared non-public network authentication authorization accounting ID is one of a key, an ID, and a certificate of the non-public network authentication authorization accounting server.

[0239] (30) An authentication server functional entity for a mobile communication system, comprising a circuit configured to:

[0240] Generate public and private keys; and

[0241] The public key is transmitted to the non-public network authentication, authorization and accounting server via a wired interface, where the authentication server function entity holds the private key.

[0242] (31) The authentication server functional entity according to (30), wherein the circuit is further configured to:

[0243] receiving, via a wired interface, an extended master session key generated and encrypted by a non-public network authentication authorization accounting server based on a public key; and

[0244] Decrypt the received extended master session key based on the held private key.

[0245] (32) An authentication server functional entity for a mobile communication system, comprising a circuit configured to:

[0246] Obtaining a predetermined key pre-stored in a secure memory in the authentication server functional entity;

[0247] receiving, via a wired interface, an extended master session key generated and encrypted by a non-public network authentication authorization accounting server; and

[0248] The encrypted extended master session key is decrypted based on a predetermined key.

Claims

1. A user equipment for a mobile communication system, comprising a circuit, wherein the circuit is configured to: Communicating with a non-public network authentication, authorization and accounting server and initiating a registration process with the mobile communication system; and An authentication interface is provided between the non-public network authentication, authorization and accounting server and an authentication server function entity in the mobile communication system.

2. The user equipment according to claim 1, wherein During the registration process with the mobile communication system, the user equipment signals to the authentication server function entity an indication that the user equipment is associated with the non-public network authentication, authorization and accounting server to provide the authentication interface.

3. The user equipment according to claim 2, wherein: The signaling notification is based on an access layer signaling message or a non-access layer signaling message.

4. The user equipment according to claim 2, wherein: When the user equipment and the authentication server function entity have established a security environment, the signaling notification is performed.

5. The user equipment according to claim 4, wherein: When the user equipment is authenticated and authorized as the user equipment associated with the non-public network authentication, authorization and accounting server in response to the signaling notification, the authentication interface is provided between the non-public network authentication, authorization and accounting server and the authentication server function entity. The user equipment according to claim 1 , wherein: The circuit is further configured to transmit the extended master session key generated and encrypted by the non-public network authentication authorization accounting server to the authentication server function entity via the authentication interface.

7. The user equipment according to claim 6, wherein: The generated and encrypted extended master session key is encrypted based on the credential of the user equipment, wherein the credential is one of Kausf, CK / IK, RRCint and UPciph.

8. The user equipment according to claim 6, wherein: The generated and encrypted extended master session key is encrypted based on the credentials of the user device, wherein the credentials are derived from CK / IK.

9. The user equipment according to claim 1, wherein: The authentication interface is provided via a user plane function of the mobile communication system.

10. The user equipment according to claim 9, wherein: Extensible Authentication Protocol packets transmitted via the authentication interface are considered user plane packets.

11. The user equipment according to claim 1, wherein: The authentication interface supports RADIUS or DIAMETER protocols.

12. The user equipment according to claim 1, wherein: The authentication method used in the registration process includes one of Authentication and Key Agreement Protocol (AKA Protocol), Extensible Authentication Protocol (EAP) Authentication and Key Agreement Protocol (ECA Protocol), and Extensible Authentication Protocol Transport Layer Security (EAP-TLS).

13. The user equipment according to claim 1, wherein: The circuit is further configured to determine an access point name in the registration process as the authentication server function entity or the authentication credential repository and processing function entity or the unified data management entity.

14. The user equipment according to claim 1, wherein: The circuitry is further configured to disable access to any other data or other services provided by the mobile communication system.

15. The user equipment according to claim 1, wherein: The circuit is further configured to transmit any information received from the mobile communication system to the associated non-public network authentication, authorization and accounting server via the authentication interface.

16. The user equipment according to claim 15, wherein: The received information includes an extensible authentication protocol data packet from a non-public network user device located in a non-public network, so as to be authenticated at the non-public network authentication and authorization computing server.

17. The user equipment according to claim 2, wherein: The signaling is performed when a security environment is established on all nodes.

18. A non-public network authentication, authorization and accounting server, comprising a circuit, wherein the circuit is configured to: communicating with user equipment associated with a mobile communications system; and receiving information from the associated user equipment, wherein: The associated user equipment receives a data packet from the mobile communication system via an authentication interface provided by the associated user equipment between the non-public network authentication authorization accounting server and an authentication server function entity in the mobile communication system.

19. The non-public network authentication authorization accounting server according to claim 18, wherein: The information received from the associated user equipment includes an Extensible Authentication Protocol data packet from a non-public network user equipment located in a non-public network, used for authentication at the non-public network Authentication Authorization Accounting server.

20. The non-public network authentication authorization accounting server according to claim 18, wherein: The circuit is further configured to: An extended master session key is generated and encrypted based on the credentials of the associated user device.

21. The non-public network authentication authorization accounting server according to claim 20, wherein: The non-public network authentication authorization accounting server transmits the generated and encrypted extended master session key to the associated user equipment, so as to transmit the generated and encrypted extended master session key to the authentication server function entity via the authentication interface.

22. An authentication server function entity for a mobile communication system, comprising a circuit, wherein the circuit is configured to: registering a user equipment associated with a non-public network authentication, authorization and accounting server with the mobile communication system; and receiving a signaling from the user equipment indicating that the user equipment is associated with the non-public network authentication, authorization and accounting server, wherein: When the user equipment is authenticated and authorized as the user equipment associated with the non-public network authentication, authorization and accounting server in response to the signaling, an authentication interface is provided between the non-public network authentication, authorization and accounting server and the authentication server function entity.

23. The authentication server functional entity according to claim 22, wherein: The circuit is further configured to: An extended master session key generated and encrypted by the non-public network authentication authorization accounting server is received via the authentication interface, wherein the generated and encrypted extended master session key is encrypted based on the credentials of the user equipment associated with the non-public network authentication authorization accounting server.

Citation Information

Patent Citations

  • Secondary Authentication of a User Equipment

    US20180317086A1