Unified User Identifier Management in Communication Systems
By introducing a unified user identifier data structure into the 5G network, the challenge of user equipment switching user identifiers in different formats in different authentication scenarios is solved, and the flexibility of user identifier management and the efficiency of authentication process are achieved.
Patent Information
- Application Number
- CN202210556457.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-04-05
- Filing Date
- 2019-04-04
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2039-04-04
AI Technical Summary
In 5G networks, user equipment needs to switch user identifiers of different formats (such as SUCI, SUPI, or IMSI) in different authentication scenarios, and the prior art has failed to effectively solve the challenge of this unified representation.
A unified user identifier data structure is proposed, containing multiple fields to support the representation of different user identifier types, including MCC, MNC, UDM selection parameters, encryption switches, KDF, identifier type, encryption curve, temporary public key pair, encrypted MSIN length, MSIN or encrypted MSIN, MSIN MAC and encryption algorithm identifiers. This structure allows the user equipment to dynamically select the appropriate user identifier representation according to the authentication scenario.
Through a unified user identifier data structure, user equipment can flexibly select appropriate user identifier formats in different authentication scenarios, simplifying user identifier management and improving the flexibility and efficiency of the authentication process.
Smart Images

Figure CN115022875B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application is a divisional application of the invention patent application with international application number PCT / EP2019 / 058530, international application date April 4, 2019, priority date April 5, 2018, date of entry into the Chinese national phase October 9, 2020, Chinese national application number 201980024618.2, and invention name “Uniform subscription identifier management in communication systems”. Technical Field
[0003] The field relates generally to communication systems and, more particularly, but not exclusively, to the management of user identifiers of users within such systems. Background Art
[0004] This section introduces aspects that may help promote a better understanding of the present invention. Therefore, the statements in this section should be read from this perspective and should not be understood as an admission that there is something in the prior art or something that does not exist in the prior art.
[0005] The fourth generation (4G) of wireless mobile telecommunication technology, also known as Long Term Evolution (LTE) technology, is designed to provide high capacity mobile multimedia at high data rates, particularly for human interaction. The next or fifth generation (5G) technology is intended not only for human interaction, but also for machine-type communications in so-called Internet of Things (IoT) networks.
[0006] While 5G networks are intended to enable large-scale IoT services (e.g., a very large number of limited-capacity devices) and mission-critical IoT services (e.g., requiring high reliability), they support improvements to traditional mobile communication services in the form of enhanced mobile broadband (eMBB) services, providing improved wireless Internet access to mobile devices.
[0007] In an exemplary communication system, a user equipment (5G UE in a 5G network, or more broadly, UE), such as a mobile terminal (user), communicates via an air interface with a base station or access point, referred to as a gNB in a 5G network. An access point (e.g., a gNB) is illustratively part of an access network of the communication system. For example, in a 5G network, the access network is referred to as a 5G system and is described in 3GPP Technical Specification (TS) 23.501, V15.0.0 entitled "Technical Specification Group Services and System Aspects; System Architecture for the 5G System", the disclosure of which is incorporated herein by reference in its entirety. In general, an access point (e.g., a gNB) enables a UE to access a core network (CN), which in turn enables the UE to access other UEs and / or data networks, such as a packet data network (e.g., the Internet). In addition, 5G network access procedures are described in 3GPP Technical Specification (TS) 23.502, V15.1.0, entitled "Technical Specification Group Services and System Aspects; Procedures for the 5G System", the disclosure of which is incorporated herein by reference in its entirety. In addition, 3GPP Technical Specification (TS) 33.501, V0.7.0, entitled "Technical Specification Group Services and System Aspects; Security Architecture and Procedures for the 5G System" further describes security management details associated with 5G networks, the disclosure of which is incorporated herein by reference in its entirety.
[0008] In 5G networks, during the registration request procedure described in 3GPP TS23.502, a 5G compatible UE may include a User Suppressed Identifier (SUCI) as described in 3GPP TS 33.501. SUCI is a hidden (encrypted) form of the User Permanent Identifier (SUPI). In traditional 4G (LTE) networks, the user identifier used is the International Mobile Station Identity (IMSI) as defined in 3GPP Technical Specification (TS) 23.003, V15.3.0 entitled "Technical Specification Group Core Network and Terminals; Numbering, Addressing and Identification", the disclosure of which is incorporated herein by reference in its entirety. The management of such user identifiers can present significant challenges.
[0009] 3GPP; Technical Specification Group Core Network and Terminals; Non-Access Stratum (NAS) Protocol for 5G System (5GS); Stage 3 (Release 15) discloses a method for a user equipment to request and obtain a specific type of mobile identity among existing identity types.
[0010] WO 2014 / 053197 A1 discloses a policy control method and also discloses an enhanced device that enables support for user community profiles applied to multiple users. In addition, the generation and enforcement of community policies and charging rules are disclosed, the community policies and charging rules are obtained from the user community profile and are preferably installed when a session is established for a first user. In the case where the community policies and charging rules can be enabled, sessions to be established for subsequent users of the multiple users can be enforced without having to process them separately.
[0011] 3GPP; 23.501: SUPI terminology correction; The 3GPP draft discloses a "User Permanent Identifier" so that a globally unique 5G User Permanent Identifier (SUPI) can be assigned to each user in a 5G system.
[0012] 3GPP; SA WG3; LS Security Aspects of ECIES for Hiding IMSI or SUPI discloses the next generation mobile network (referred to as 5G). A new and generic term called SUPI (Subscriber Permanent Identifier) is disclosed, which is intended to be used to represent the globally unique 5G Subscriber Permanent Identifier. It is also proposed to hide the IMSI or SUPI over the air in 5G through ECIES (Elliptic Curve Integrated Cryptography Scheme). Summary of the invention
[0013] The illustrative embodiments provide improved techniques for managing user identifiers in a communication system.
[0014] For example, in an illustrative embodiment, a method includes the following steps. At a given user equipment in a wireless communication system, a unified user identifier data structure is constructed. The unified user identifier data structure is stored. The unified user identifier data structure includes a plurality of fields, the plurality of fields specifying a selected one of two or more user identifier fields associated with a selected user identifier type. The selected one of the two or more user identifier fields in the unified user identifier data structure is used to access one or more networks associated with the wireless communication system based on an authentication scenario corresponding to the selected user identifier type.
[0015] Other illustrative embodiments are provided in the form of a non-transitory computer-readable storage medium having executable program code embodied therein, which, when executed by a processor, causes the processor to perform the above steps. Other illustrative embodiments include a device having a processor and a memory configured to perform the above steps.
[0016] Advantageously, during different authentication scenarios, the given user equipment utilizes the unified user identifier data structure to provide an appropriate user identifier (eg, SUPI, SUCI or IMSI) and associated parameters for a given authentication scenario.
[0017] These and other features and advantages of the embodiments described herein will become more apparent from the accompanying drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 A communication system is shown that can be used to implement one or more illustrative embodiments.
[0019] Figure 2 User equipment and network elements / functions for providing user identifier management during an authentication procedure are shown that may be used to implement one or more illustrative embodiments.
[0020] Figure 3A An IMSI format is shown that may be used to implement one or more illustrative embodiments.
[0021] Figure 3B A SUPI format is shown that may be used to implement one or more illustrative embodiments.
[0022] Figure 3C A SUCI format is shown that may be used to implement one or more illustrative embodiments.
[0023] Figure 4 A unified user identifier format is shown according to an illustrative embodiment.
[0024] Figure 5 Exemplary field lengths for a unified user identifier format are shown in accordance with an illustrative embodiment.
[0025] Figure 6 A unified user identifier format according to another illustrative embodiment is shown.
[0026] Figure 7 A user device method for utilizing a unified user identifier format is shown in accordance with an illustrative embodiment.
[0027] Figure 8 A network entity method for utilizing a unified user identifier format is shown in accordance with an illustrative embodiment. DETAILED DESCRIPTION
[0028] Embodiments will be described herein in conjunction with communication systems and associated technologies for providing user identifier management during authentication and other procedures in an exemplary communication system. However, it should be understood that the scope of the claims is not limited to the specific type of communication system and / or process disclosed. Optional processes and operations may be used to implement embodiments in various other types of communication systems. For example, although described in the context of a wireless cellular system utilizing 3GPP system elements (such as 3GPP Next Generation System (5G)), the disclosed embodiments may be used in a straightforward manner for various other types of communication systems.
[0029] According to an illustrative embodiment implemented in a 5G communication system environment, one or more 3GPP technical specifications (TS) and technical reports (TR) may provide further explanation of network elements / functions and / or operations that may interact with portions of the inventive solution, such as 3GPP TS 23.00323.501, 23.502, and 33.501 cited above. Other 3GPP TS / TR documents may provide other routine details that a person of ordinary skill will recognize. However, while well suited to 5G-related 3GPP standards, the embodiments are not necessarily intended to be limited to any particular standard.
[0030] The illustrative embodiments relate to user identifier management associated with a 5G network. Figure 1 and Figure 2 A general description of the main components of a 5G network is described in the background.
[0031] Figure 1A communication system 100 is shown within which an illustrative embodiment is implemented. It should be understood that the elements shown in the communication system 100 are intended to represent the main functions provided within the system, such as UE access functions, mobility management functions, authentication functions, serving gateway functions, etc. Thus, Figure 1 The boxes shown in refer to specific elements in the 5G network that provide these main functions. However, other network elements may be used to implement some or all of the main functions represented. In addition, it will be understood that in Figure 1 Not all functions of a 5G network are depicted in the figure. Rather, functions that facilitate explanation of the illustrative implementation are presented. Subsequent figures may depict some additional elements / functions.
[0032] Thus, as shown, the communication system 100 includes a user equipment (UE) 102 that communicates with an access point (gNB) 104 via an air interface 103. The UE 102 may be a mobile station, and such a mobile station may include, for example, a mobile phone, a computer, or any other type of communication device. Thus, the term "user equipment" as used herein is intended to be understood in a broad sense so as to encompass a variety of different types of mobile stations, user stations, or more generally communication devices, including multiple examples such as a combination of data cards inserted into a laptop or other device such as a smart phone. Such communication devices are also intended to include devices commonly referred to as access terminals.
[0033] In one embodiment, UE 102 includes a Universal Integrated Circuit Card (UICC) part and a Mobile Equipment (ME) part. UICC is the user-related part of UE and contains at least one Universal User Identity Module (USIM) and appropriate application software. USIM securely stores permanent user identifiers and their associated keys, which are used to identify and authenticate users who want to access the network. ME is the user-independent part of UE and contains terminal equipment (TE) functions and various mobile terminal (MT) functions.
[0034] Access point 104 is illustratively part of an access network of communication system 100. Such an access network may include, for example, a 5G system having a plurality of base stations and one or more associated radio network control functions. The base stations and radio network control functions may be logically separate entities, but in a given embodiment may be implemented in the same physical network element (such as, for example, a base station router or a femtocell access point).
[0035] In this illustrative embodiment, the access point 104 is operatively coupled to the mobility management function 106. In a 5G network, the mobility management function is implemented by an access and mobility management function (AMF). A security anchor function (SEAF) may also be implemented with the AMF to allow the UE to securely connect to the mobility management function. As used herein, a mobility management function is an element or function (i.e., an entity) in the core network (CN) portion of a communication system that manages or otherwise participates in the access and mobility (including authentication / authorization) operations of the UE (through the access point 104) in addition to other network operations. The AMF may also be more generally referred to herein as an access and mobility management entity.
[0036] In this illustrative embodiment, the AMF 106 is operatively coupled to a home subscriber function 108, i.e., one or more functions resident in the user's home network. As shown, some of these functions include a unified data management (UDM) function and an authentication server function (AUSF). The AUSF and UDM (alone or together with a 4G home subscriber server or HSS) may also be more generally referred to herein as authentication entities. In addition, the home subscriber function may include, but is not limited to, a network slice selection function (NSSF), a network exposure function (NEF), a network storage function (NRF), a policy control function (PCF), and an application function (AF).
[0037] Access point 104 is also operatively coupled to a serving gateway function, session management function (SMF) 110, which is operatively coupled to a user plane function (UPF) 112. UPF 112 is operatively coupled to a packet data network, such as the Internet 114. Other typical operations and functions of such network elements are not described here as they are not of interest to the illustrative embodiments and may be found in appropriate 3GPP 5G documents.
[0038] It should be appreciated that this particular arrangement of system elements is merely an example, and that additional or optional elements of other types and arrangements may be used to implement the communication system in other embodiments. For example, in other embodiments, system 100 may include other elements / functions not explicitly shown herein.
[0039] therefore, Figure 1 The arrangement of is only one exemplary configuration of a wireless cellular system, and many alternative configurations of system elements may be used. Figure 1 Only a single element / function is shown in the embodiment, but this is only for simplicity and clarity of description. A given alternative embodiment may of course include more such system elements, as well as additional or optional elements of the type normally associated with conventional system implementations.
[0040] It should also be noted that although Figure 1 The system elements are shown as single functional blocks, but the various subnetworks that make up the 5G network are divided into so-called network slices. A network slice (network partition) includes a series of network function (NF) sets (i.e., function chains) for each corresponding service type using network function virtualization (NFV) on a common physical infrastructure. Network slices are instantiated on demand for given services, such as eMBB services, large-scale IoT services, and mission-critical IoT services. Therefore, a network slice or function is instantiated when an instance of the network slice or function is created. In some embodiments, this involves installing or otherwise running the network slice or function on one or more host devices of the underlying physical infrastructure. UE 102 is configured to access one or more of these services via gNB 104.
[0041] Figure 2 2 is a block diagram of a portion of a communication system 200 that, in an illustrative embodiment, includes a user device 202 and a network element / function 204 for providing user identifier management as part of an authentication procedure. In one embodiment, the network element / function 204 may be a UDM (as described above). However, it should be appreciated that the network element / function 204 may represent any network element / function that may be configured to provide user identifier management and other authentication techniques described herein.
[0042] The user device 202 includes a processor 212 coupled to a memory 216 and an interface circuit 210. The processor 212 of the user device 202 includes an authentication processing module 214, which can be implemented at least in part in the form of software executed by the processor. The processing module 214 performs user identifier management and other related technologies described in this document in conjunction with subsequent figures and in other ways. The memory 216 of the user device 202 includes a user identifier management data storage module 218, which stores data generated or otherwise used during user identifier management and other operations.
[0043] The network element / function 204 includes a processor 222 coupled to a memory 226 and the interface circuit 220. The processor 222 of the network element / function 204 includes an authentication processing module 224, which may be implemented at least in part in the form of software executed by the processor 222. The processing module 224 performs authentication techniques using a user identifier provided by the UE 202 and other techniques described herein in conjunction with subsequent figures and otherwise. The memory 226 of the network element / function 204 includes an authentication processing data storage module 228, which stores data generated or otherwise used during authentication and other operations.
[0044] The processors 212 and 222 of the respective user equipment 202 and network element / function 204 may include, for example, a microprocessor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a digital signal processor (DSP), or other type of processing device or integrated circuit, and portions or combinations of such elements. Such integrated circuit devices, and portions or combinations thereof, are examples of "circuits," as the term is used herein. Various other arrangements of hardware and associated software or firmware may be used when implementing the illustrative embodiments.
[0045] The memories 216 and 226 of the respective user equipment 202 and network element / function 204 may be used to store one or more software programs that are executed by the respective processors 212 and 222 to implement at least a portion of the functionality described herein. For example, user identifier management operations and other authentication functionality as described herein in conjunction with subsequent figures and otherwise may be implemented in a straightforward manner using software code executed by the processors 212 and 222.
[0046] A given one of memory 216 or 226 may therefore be considered an example of what is more generally referred to herein as a computer program product or, still more generally, as a processor-readable storage medium having executable program code embodied therein. Other examples of processor-readable storage media may include disks or other types of magnetic or optical media (in any combination). Illustrative embodiments may include an article of manufacture that includes such a computer program product or other processor-readable storage medium.
[0047] More specifically, memory 216 or 226 may include, for example, electronic random access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memory, such as flash memory, magnetic RAM (MRAM), phase change RAM (PC-RAM), or ferroelectric RAM (FRAM). The term "memory" as used herein is intended to be understood in a broad sense and may additionally or alternatively include, for example, read-only memory (ROM), disk-based memory, or other types of storage devices, as well as portions or combinations of such devices.
[0048] The interface circuits 210 and 220 of the respective user equipment 202 and network element / function 204 illustratively include transceivers or other communication hardware or firmware that allow the associated system elements to communicate with each other in the manner described herein.
[0049] from Figure 2 It is apparent from the diagram that the user equipment 202 is configured to communicate with the network element / function 204 via respective interface circuits 210 and 220, and vice versa. In the case where the network element / function 204 is a UDM, the user equipment and the UDM are operatively coupled through the gNB 104 and the AMF 106 and communicate via the gNB 104 and the AMF 106 (e.g. Figure 1 ). This communication involves user equipment 202 sending data to network element / function 204 and network element / function 204 sending data to user equipment 202. However, in alternative embodiments, more or fewer network elements (in addition to or in lieu of gNB and AMF) may be operatively coupled between network elements / functions 202 and 204. The term "data" as used herein is intended to be understood in a broad sense so as to include any type of information that may be sent between a user equipment and one or more network elements / functions, including but not limited to messages, identifiers, keys, indicators, user data, control data, etc.
[0050] It should be understood that Figure 2 The specific component arrangements shown in are examples only, and many alternative configurations may be used in other embodiments. For example, any given network element / function may be configured to incorporate additional or optional components and support other communication protocols.
[0051] Other system components (such as but not limited to Figure 1 Other elements shown in ) can also be configured to include multiple components, such as processors, memories, and network interfaces. These elements do not need to be implemented on separate independent processing platforms, but can instead represent different functional parts of a single common processing platform, for example.
[0052] Given the general concepts described above, an illustrative implementation that addresses the user identifier management problem will now be described.
[0053] As mentioned above, in a conventional 4G (LTE) communication system, the permanent user identifier is typically the International Mobile Station Identity or IMSI of the UE. As defined in the 3GPP TS23.003 cited above, the IMSI consists of a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Mobile Station Identification Number (MSIN). Typically, if the user identifier needs to be protected, only the MSIN portion of the IMSI needs to be encrypted. The MNC and MCC portions provide routing information that is used by the serving network to route to the correct home network. In a 5G communication system, the permanent user identifier is referred to as a User Permanent Identifier or SUPI. Like the IMSI, the SUPI can uniquely identify a user using the MSIN. When the MSIN of the SUPI is encrypted, it is referred to as a User Hidden Identifier or SUCI.
[0054] However, it is recognized herein that in different operating scenarios, the UE may need to represent the user identifier as a SUCI, SUPI, or IMSI.To address these and other user identifier management issues, the illustrative embodiments propose a unified representation structure for user identifiers.
[0055] More specifically, the illustrative embodiments address the challenge of using an appropriate user identifier representation (i.e., SUPI or its encrypted form SUCI or even IMSI) in a registration request message sent by a UE to the network and UE authentication procedures in a 5G network (note that the same or similar unified data structures may be exchanged between network entities). For example, a UE may need to present a user identifier in three different formats, SUCI, SUPI, or IMSI, when performing a 5G authentication and key agreement (AKA) procedure (e.g., see 3GPP TS 33.501 cited above). If the authentication procedure uses the Extensible Authentication Protocol (EAP) AKA' procedure (e.g., see 3GPP TS 33.501 cited above), the representation uses the Network Access Identifier (NAI) format, i.e., "joe@example.com" as defined in Internet Engineering Task Force (IETF) Request for Comments (RFC) 7542, "The Network Access Identifier" (May 2015), the disclosure of which is incorporated herein by reference in its entirety.
[0056] The challenge of different user identifier formats is not addressed in the TS 33.501 cited above, or in any other Stage 3 specification. In the 3GPP Technical Specification (TS) 33.401, V15.3.0 entitled "Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); System architecture", the disclosure of which is incorporated herein by reference in its entirety, only the use of IMSI is defined.
[0057] Figure 3A An IMSI format 300 that can be used to implement one or more illustrative embodiments is shown. As shown, the format 300 includes a fixed length of 15 digits and consists of a 3-digit mobile country code (MCC), a 3-digit mobile network code (MNC), and a 9-digit mobile station identification number (MSIN). In some cases, the MNC can be 2 digits, while the MSIN is 10 digits. Other details about the IMSI are defined in the 3GPP TS23.003 referenced above.
[0058] As explained above, if the authentication procedure uses the EAP-AKA' procedure or the EAP Transport Layer Security (TLS) procedure (each defined in the 3GPP TS 33.501 cited above), then the user identifier is represented using the NAI format. RFC 7542 specifies that for 3GPP, the "user name" part is a unique identifier derived from device-specific information, and the "realm" part includes information about the home network, followed by the base string "3gppnetwork.org". For example, a user identifier in the NAI format may be represented as follows:
[0059] 2341509999999999@ims.mnc015.mcc234.3gppnetwork.org
[0060] Therefore, for the EAP-AKA' procedure, the UE shall encode its user identifier SUPI or SUCI in the NAI format as specified in RFC 7542, for example,
[0061] MSIN@mnc.mcc.3gppnetwork.org.
[0062] Figure 3B and Figure 3CSUPI format 310 and SUCI format 320 are shown, respectively, which may be used to implement one or more illustrative embodiments. In this example, SUPI format 310 includes an MCC field (3 digits), and an MNC field (3 digits), an MSIN, and a UDM selector (8 bits). SUCI format 320 is an encrypted form of SUPI format 310, and as shown includes an MCC field (3 digits), and an MNC field (3 digits), a UDM selector field, an encrypted MSIN, and parameters for decrypting the encrypted MSIN.
[0063] It has been agreed in 3GPP SA3 to support at least two elliptic curves (Elliptic Curve Integrated Cryptography Scheme (ECIES) curve A and curve B) to encrypt the MSIN part of the SUPI while the encrypted identifier is used as the SUCI. In future releases, 3GPP may specify more or fewer curves from the Elliptic Curve Cryptography (ECC) curve family, or may allow the use of dedicated curves to encrypt the MSIN. However, it should be recognized that while the use of a standardized scheme is preferred, a network operator may also decide to use its own specific encryption method. In addition, especially in a transition phase, a network operator may configure the device to use only the null scheme for the SUCI. The null scheme is implemented so that the output it returns is the same as the input, which applies to both encryption and decryption (i.e., the MSIN is not encrypted). The null scheme is indicated by the scheme identifier in the SUCI and can therefore be presented in the same way by the unified user identifier format.
[0064] Since in the core network, in the UE ( Figure 1 102) and UDM( Figure 1 The hidden user identifier SUCI is exchanged between the UE and the UDM (part 108 in ), so the UDM should be configured to understand how the UE encodes the MSIN. Therefore, the encoding method should be part of the format exchanged as well as the encoding output itself, because no other messages are exchanged between the UE and the UDM during the authentication process. Therefore, it should be recognized that the scheme for representing SUCI should support a flexible representation to accommodate multiple fields, each field being flexible enough to support multiple options.
[0065] The illustrative embodiments address the above and other challenges by providing a unified structure to represent user identifiers. For example, the unified structure in one illustrative embodiment can represent user identifiers such as SUCI, SUPI, and IMSI, as well as various options associated with the use of each identifier during authentication and other operations.
[0066] Figure 4 A unified user identifier format (data structure) 400 is shown according to an illustrative embodiment. In addition, Figure 5 Shown in Figure 4Example field length 500 for each field shown in uniform user identifier format 400 .
[0067] As shown, the uniform user identifier format 400 includes the following fields (with exemplary field lengths in parentheses):
[0068] MCC field 402 (24 bits / 3 digits);
[0069] MNC field 404 (24 bits / 3 digits);
[0070] UDM selection parameter field 406 (8 bits);
[0071] Encryption on / off field 408 (1 bit);
[0072] KDF (Key Derivation Function) field 410 (3 bits);
[0073] KDF optional parameter field 412 (n bits / depends on optional parameters);
[0074] Identifier type SUPI / SUCI / IMSI field 414 (2 bits);
[0075] Encryption uses ECIES curve field 416 (4 bits);
[0076] Temporary public key pair field 418 (256 bits);
[0077] Encrypted MSIN length field 420 (4 bits / 128, 192, 256, 512 bits / depending on the MSIN format);
[0078] MSIN or encrypted MSIN field 422 (length as specified in field 420);
[0079] MSIN MAC (Message Authentication Code of the MSIN field calculated using the selected ECIES curve) field 424 (256 bits); and
[0080] Encryption algorithm identifier field 426 (4 bits).
[0081] It should be appreciated that the field lengths described herein are illustrative in nature and are therefore not intended to be limiting. Depending on the operating scenario in which the UE and the 5G network function, the field lengths may be set to different values. It should also be appreciated that in alternative embodiments, one or more additional fields may be added to the data structure, and / or some of the above fields may be deleted and / or not used at all. In addition, Figure 4The arrangement of fields within the structure format 400 in is exemplary in nature, and thus, alternative field arrangements are contemplated in other embodiments. By way of example only, one additional field that may be part of the data structure (or indicated in a UDM selection or other field) is a Network Slice Selection Assistance Information (NSSAI) field.
[0082] Although some demonstrative embodiments enable the UE to store the complete unified user identifier data structure (i.e., Figure 4 400) is sent to a given UDM (or one or more other network entities), but an optional illustrative embodiment avoids transmitting many indicative parameters, such as, for example, KDF, KDF optional parameters, selected elliptic curve, encryption algorithm identifier, etc., to minimize transmission overhead. Figure 6 An optional illustrative unified user identifier data structure 600 is depicted in FIG. As shown, the unified user identifier format 600 includes the following fields (with exemplary field lengths in parentheses):
[0083] MCC field 602 (24 bits / 3 digits);
[0084] MNC field 604 (24 bits / 3 digits);
[0085] UDM selection parameter field 606 (8 bits);
[0086] Identifier type SUPI / SUCI / IMSI field 608 (2 bits);
[0087] Encrypted MSIN length field 610 (4 bits / 128, 192, 256, 512 bits / depending on the MSIN format);
[0088] MSIN or encrypted MSIN field 612 (length as specified in field 610);
[0089] MSIN MAC (Message Authentication Code of the MSIN field calculated using the selected ECIES curve) field 614 (256 bits); and
[0090] Profile selection field 616 (4 bits).
[0091] It should be appreciated that the field lengths described herein are illustrative in nature and are therefore not intended to be limiting. Depending on the operating scenario in which the UE and the 5G network function, the field lengths may be set to different values. It should also be appreciated that in alternative embodiments, one or more additional fields may be added to the data structure, and / or some of the above fields may be deleted and / or not used at all. In addition, Figure 6The arrangement of fields within the structure format 600 in is exemplary in nature, and thus, alternative field arrangements are contemplated in other embodiments. By way of example only, one additional field that may be part of the data structure (or indicated in a UDM selection or other field) is a Network Slice Selection Assistance Information (NSSAI) field.
[0092] Fields 602 to 614 provide the same information as the corresponding fields of the same name in data structure 400. However, data structure 600 includes a profile selection field 616. It will be appreciated that it may be advantageous to pre-establish certain standard profiles between the UE and the UDM for use in the unified user identifier representation format. These agreed profiles may be defined as preset values (by way of example only, the 4-bit Encryption Selected ECIES Curve field). In such a case, the agreed values from the profiles will be used by the sending UE and UDM, thereby avoiding actually exchanging values for these parameters.
[0093] For example, in such a profile-based reduced field version of the unified user identifier data structure, the UDM would be configured to know that a given profile selection field of "0011" (if 4 bits) corresponds to Figure 6 The reduced field version of Figure 4 The UE may specify certain predetermined settings for the fields in the format, while a profile selection field of "1010" would mean a different predetermined setting, etc. Thus, the UDM may pre-store (or obtain in real time) the data structure of each possible profile that the UE may send (as the UE is configured to select different authentication scenarios).
[0094] The illustrative embodiment enables all UEs (e.g. Figure 1 102) and network elements / functions such as but not limited to gNB ( Figure 1 104), AMF( Figure 1 106 in the ), SEAF ( Figure 1 106 of the ), AUSF( Figure 1 108 in) and UDM ( Figure 1 108) is capable of supporting unified user identifier formats 400 and 600 and optional variations.
[0095] Figure 7 A method for utilizing a unified user identifier format (eg, Figure 4 Data structure 400 or Figure 6 Method 700 of data structure 600).
[0096] At step 702, the UE maintains a permanent user identifier (SUPI) or IMSI.
[0097] At step 704, the UE maintains the UDM's public key and its own private / public key pair.
[0098] At step 706, the UE selects parameters (algorithm, curve, etc.) for encrypting the MSIN.
[0099] In step 708, the UE constructs a unified user identifier data structure (e.g., Figure 4 of 400).
[0100] At step 710, the UE sends a unified user identifier data structure to the selected UDM during a network access request (e.g., a registration request). In one embodiment, the unified user identifier data structure may be Figure 4 400 (i.e., a version with all fields filled in), while in an alternative embodiment, the unified user identifier data structure may be Figure 6 The unified user identifier data structure 600 (based on a simplified field version of the configuration file) may be sent in other optional embodiments. The network entity (e.g., UDM) is also configured to construct or otherwise obtain / maintain such a unified user identifier data structure.
[0101] Figure 8 A method for utilizing a unified user identifier format (e.g., Figure 4 Data structure 400 or Figure 6 Method 800 of data structure 600).
[0102] At step 802, the network entity receives a unified user identifier data structure.
[0103] At step 804, the network entity decrypts the unified user identifier data structure as needed.
[0104] At step 806, the network element performs authentication of the sender UE based on the authentication scenario corresponding to the selected user identifier type in the received data structure.
[0105] Therefore, it should be emphasized again that the various embodiments described herein are presented by way of example only and should not be construed as limiting the scope of the claims. For example, alternative embodiments may utilize different communication system configurations, user equipment configurations, base station configurations, key pair provision and use processes, messaging protocols, and message formats than those described above in the context of the illustrative embodiments. These and numerous other alternative embodiments within the scope of the appended claims will be readily apparent to those skilled in the art.
Claims
1. A user equipment (102, 202) for a wireless communication system (100, 200), the user equipment (102, 202) comprising a processor (212) and a memory (216), the processor (212) and the memory (216) being configured to execute: At the user equipment (102, 202) in the wireless communication system (100, 200), constructing a unified user identifier data structure; wherein the unified user identifier data structure (400, 600) includes a plurality of fields (402-426, 602-616), the plurality of fields including at least one field specifying a selected user identifier type from among two or more user identifier types; as well as using the unified user identifier data structure (400, 600) to access one or more networks associated with the wireless communication system (100, 200) based on an authentication scenario corresponding to the selected user identifier type; wherein the plurality of fields (402-426, 602-616) include a user identifier type field (414, 608); The plurality of fields (402-426, 602-616) include a network entity selection parameter field (406, 606), wherein the network entity (104, 204) performs one or more of a unified data management (UDM) function and an authentication server function (AUSF).
2. The user equipment (102, 202) of claim 1, wherein the user identifier type is selectable from the group consisting of a Subscriber Suppressed Identifier (SUCI), a Subscriber Permanent Identifier (SUPI), and an International Mobile Station Identity (IMSI).
3. The user equipment (102, 202) of claim 1, wherein the plurality of fields (402-426) includes an encryption on / off field (408).
4. The user equipment (102, 202) of claim 3, wherein the plurality of fields (402-426) includes an encryption algorithm identifier field (426).
5. The user equipment (102, 202) of claim 1, wherein the plurality of fields (402-426) includes a key derivation function field (410).
6. The user equipment (102, 202) of claim 5, wherein the plurality of fields (402-426) includes a key derivation function parameter field (412).
7. The user equipment (102, 202) of claim 1, wherein the plurality of fields (402-426, 602-616) includes a Mobile Country Code field (402, 602).
8. The user equipment (102, 202) of claim 1, wherein the plurality of fields (402-426, 602-616) includes a Mobile Network Code field (404, 604).
9. The user device (102, 202) of claim 1, wherein the plurality of fields (402-426) includes a field (416) that specifies a selected curve from an elliptic curve integrated cryptographic scheme.
10. The user device (102, 202) of claim 1, wherein the plurality of fields (402-426) includes a temporary public key pair field (418).
11. The user equipment (102, 202) of claim 1, wherein the plurality of fields (402-426, 602-616) includes a field (420, 610) that specifies a length of an encrypted Mobile Station Identity (MSIN) field.
12. The user device (102, 202) of claim 11, wherein the plurality of fields (402-426, 602-616) includes an encrypted MSIN field (422, 612).
13. The user equipment (102, 202) of claim 11, wherein the plurality of fields (402-426, 602-616) includes a MSIN message authentication code field (424, 614).
14. The user equipment (102, 202) of claim 1, wherein the wireless communication system (100, 200) comprises a 5G system.
15. The user equipment (102, 202) of claim 1, wherein the processor and the memory are further configured to send the unified user identifier data structure (400, 600) to at least one network entity (104, 204) in the wireless communication system (100, 200) in order to access the one or more networks associated with the wireless communication system (100, 200).
16. The user device (102, 202) of claim 1, wherein the plurality of fields (602-616) includes a profile selection field (616).
17. The user equipment (102, 202) of claim 16, wherein the profile selection field (616) enables the user equipment (102, 202) to notify one or more network entities in the one or more networks associated with the wireless communication system (100, 200) to use predetermined values of one or more optional parameters associated with the selected user identifier type.
18. The user equipment (102, 202) of claim 17, wherein the processor (212) and the memory (216) are further configured to send the unified user identifier data structure (600) having the profile selection field (616) and the reduced field set to at least one of the one or more network entities in the wireless communication system (100, 200) in order to access the one or more networks associated with the wireless communication system (100, 200).
19. A communication method, include: At a user equipment (102, 202) in a wireless communication system (100, 200), constructing a unified user identifier data structure (400, 600); wherein the unified user identifier data structure (400, 600) includes a plurality of fields (402-426, 602-616), the plurality of fields including at least one field specifying a selected user identifier type of two or more user identifier types; as well as using the unified user identifier data structure (400, 600) to access one or more networks associated with the wireless communication system (100, 200) based on an authentication scenario corresponding to the selected user identifier type; wherein the plurality of fields includes a user identifier type field; The plurality of fields comprises a network entity selection parameter field, wherein the network entity performs one or more of a unified data management (UDM) function and an authentication server function (AUSF).
20. A non-transitory computer readable storage medium having executable program code stored thereon, the executable program code, when executed by a processor (212), causing the processor (212) to: At a user equipment (102, 202) in a wireless communication system (100, 200), constructing a unified user identifier data structure (400, 600); wherein the unified user identifier data structure (400, 600) includes a plurality of fields (402-426, 602-616), the plurality of fields including at least one field specifying a selected user identifier type of two or more user identifier types; as well as using the unified user identifier data structure (400, 600) to access one or more networks associated with the wireless communication system (100, 200) based on an authentication scenario corresponding to the selected user identifier type; wherein the plurality of fields includes a user identifier type field; The plurality of fields comprises a network entity selection parameter field, wherein the network entity performs one or more of a unified data management (UDM) function and an authentication server function (AUSF).
Citation Information
Patent Citations
Method and apparatuses for policy and charging control of machine-to-machine type communications
WO2014053197A1
Apparatus and method for enriching data records in a telecommunications network
US20070171856A1
Authentication with privacy identity
US20180020351A1