System and method for authorizing connection of IAB nodes based on IAB node identification information

By storing and using the mapping information of IAB-UE nodes in network entities for authentication, the problem that IAB nodes are easily impersonated by attackers in open environments is solved, and the stability of core network services is ensured.

CN115136663BActive Publication Date: 2025-05-30ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202080097366.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-02-26
Publication Date
2025-05-30
Estimated Expiration
2040-02-26

AI Technical Summary

Technical Problem

In the prior art, when deployed in an open environment, IAB nodes are vulnerable to threats of attackers impersonating them, resulting in interruption of core network services.

Method used

By storing mapping information, including pre-authorized IAB-UE's UICC certificate, IAB-ME identification, location information and cell identification information, network entities such as UDM, AMF, EIR, HSS, MME, etc. are used for authentication to determine the authorized connection of the IAB-UE node.

Benefits of technology

It effectively prevents the risk of IAB nodes being impersonated by attackers, ensures the legal connection of IAB nodes, and stabilizes the core network services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115136663B_ABST
    Figure CN115136663B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a system and method for wireless communication. In one embodiment, the wireless communication method includes: storing mapping information by a first network entity, and determining, by the first network entity, that a first node is authorized to connect to the network based on identification information and the mapping information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to wireless communication, and more particularly, to a system and method for authorizing an integrated access backhaul (IAB) node to connect based on IAB node identification information. Background Art

[0002] The new radio (NR) of the new generation mobile communication system allows for more flexible network deployment than 2G, 3G, and 4G systems. Currently, the integrated access backhaul (IAB) node integrates the backhaul link and the normal access link, providing flexible coverage and network deployment without laying a large number of optical fibers, saving network deployment costs.

[0003] A universal integrated circuit card (UICC) is a physical card that includes a processor, non-volatile memory, random access memory, and read-only memory. The UICC supports multiple applications, making the card recognizable on several different networks (e.g., the universal subscriber identity module (USIM) application for the global system for mobile communications (GSM) network and the code division multiple access (CDMA) subscriber identity module (CSIM) application for the CDMA network). Summary of the Invention

[0004] The example embodiments disclosed herein are intended to solve problems related to one or more challenges presented in the prior art, and to provide additional features that will become apparent upon reference to the following detailed description when taken in conjunction with the accompanying drawings. According to various embodiments, example systems, methods, devices, and computer program products are disclosed herein. However, it should be understood that these embodiments are presented by way of example and not limitation, and it will be apparent to those of ordinary skill in the art who read this disclosure that various modifications can be made to the disclosed embodiments while remaining within the scope of this disclosure.

[0005] In some embodiments, a wireless communication method includes: storing mapping information by a first network entity, and determining by the first network entity that a first node is authorized to connect to a network based on identification information received from the first node and the mapping information.

[0006] The above and other aspects and their implementations will be described in more detail in the drawings, the specification, and the claims. Brief Description of the Drawings

[0007] The various example embodiments of the present solution are described in detail below with reference to the following diagrams or drawings. The drawings are provided for illustrative purposes only and describe only the example embodiments of the present solution to facilitate the reader's understanding of the present solution. Therefore, the drawings should not be regarded as limiting the breadth, scope, or applicability of the present solution. It should be noted that, for clarity and ease of illustration, these drawings are not necessarily drawn to scale.

[0008] Figure 1 is a block diagram showing an example network system architecture according to an embodiment of the present disclosure.

[0009] Figure 2 is a signaling diagram showing an example process of authenticating an IAB-UE via a Unified Data Management (UDM) according to some embodiments of the present disclosure.

[0010] Figure 3 is a signaling diagram showing an example process of authenticating an IAB-UE via an Access and Mobility Management Function (AMF) according to some embodiments of the present disclosure.

[0011] Figure 4 is a signaling diagram showing an example process of authenticating an IAB-UE via an Equipment Identity Register (EIR) according to some embodiments of the present disclosure.

[0012] Figure 5 is a signaling diagram showing an example process of authenticating an IAB-UE via a Home Subscriber Server (HSS) according to some embodiments of the present disclosure.

[0013] Figure 6 is a signaling diagram showing an example process of authenticating an IAB-UE via a Mobility Management Entity (MME) according to some embodiments of the present disclosure.

[0014] Figure 7 is a signaling diagram showing an example process for authenticating an IAB-UE via an EIR according to some embodiments of the present disclosure.

[0015] Figure 8 is a flowchart showing an example method for determining a node's authentication and access to a network according to an embodiment of the present disclosure.

[0016] Figure 9A shows a block diagram of an example base station according to some embodiments of the present disclosure.

[0017] Figure 9B shows a block diagram of an example User Equipment (UE) according to some embodiments of the present disclosure. Detailed Description

[0018] Various example embodiments of the present solution will be described below with reference to the accompanying drawings so that those of ordinary skill in the art can make and use the present solution. It will be apparent to those of ordinary skill in the art that various changes or modifications can be made to the examples described herein without departing from the scope of the present solution after reading this disclosure. Therefore, the present solution is not limited to the example embodiments and applications described and illustrated herein. In addition, the specific order or hierarchy of steps in the methods disclosed herein is merely an example method. Based on design preferences, the specific order or hierarchy of steps of the disclosed method or process can be rearranged while remaining within the scope of the present solution. Therefore, those of ordinary skill in the art should understand that the methods and techniques disclosed herein present various steps or acts in a sample order, and the present solution is not limited to the specific order or hierarchy presented unless otherwise expressly stated.

[0019] For a new generation of mobile communication systems, a node having a wired backhaul link to the core network is an anchor (donor) IAB (IAB-anchor). The IAB-anchor includes a central unit (CU) and one or more distributed units (DUs), which can obtain downlink data or send uplink data to the core network. A node wirelessly connected to the anchor IAB (or an upper-layer IAB node) is an IAB node. There is no direct connection between the IAB node and the core network. The IAB nodes in the radio access network (RAN) can achieve simpler deployment and incremental deployment by reducing the dependence on the availability of the wired backhaul at each access node location. The IAB node interacts with the core network by forwarding the IAB node message one or more times via the IAB-anchor. That is, the IAB node can send and receive messages from the IAB-anchor, and the IAB-anchor can send and receive messages from the core network. Alternatively, the IAB node can send and receive messages from a second IAB node, the second IAB node can send and receive messages from a third IAB node, and so on, where one of the IAB nodes communicates with the IAB-anchor. Both the anchor IAB and the IAB node support terminal access.

[0020] The IAB node has two functions. The first function is the DU function and the CU function. The IAB node operating in its DU function acts as a base station and can be considered an IAB-anchor. That is, during the IAB-DU function, the IAB node can provide wireless access to the core network for child nodes or terminals. The IAB node can provide wireless access to the core network by providing NR Uu access to the UE, where Uu is the interface between the UE and the 5G-RAN. Before providing Uu access to the UE, the IAB node can request a certificate to authenticate the UE. The corresponding CU function can control the IAB node operating as a DU via the F1 interface, where it may also be necessary to authenticate the IAB node using the F1 interface.

[0021] The second function is the mobile terminal (MT, mobile-terminal) function. The IAB node operating in its MT function acts as a terminal or UE, where the UE can be a wireless communication device (e.g., a mobile phone). That is, during the IAB-MT function, the IAB node acts as an IAB-UE and is controlled and scheduled by the IAB-anchor.

[0022] The IAB node can be considered to include both software components and hardware components. Generally, the hardware component of the IAB node can be considered a mobile device (ME). The ME of the IAB node is configured such that the IAB node can act as a DU or a UE. In one instance, the software component can utilize a removable UICC. The removable UICC of the IAB node can store the USIM certificate required for authenticating / authorizing the device on the cellular network.

[0023] In some embodiments, the integration of the IAB into the network can include three phases: 1) IAB-UE setup; 2) backhaul RLC channel establishment and routing update; and 3) IAB-DU setup. During the IAB-UE setup, the IAB node performs network registration as a UE. That is, the IAB node establishes a secure connection between the IAB-anchor and the IAB-UE. The IAB node configured as a UE is authenticated using the same or a similar authentication process as a traditional UE. In one embodiment, to support the authentication key agreement (AKA) authentication method, the USIM in the IAB node can reside on a removable UICC.

[0024] Although the authentication certificates in the IAB node can be protected, in the case where one or more certificates of the IAB node are transferred from the IAB node to the attacker's device without authorization, the attacker's device can "impersonate" the IAB node. When the IAB node is deployed in an open environment, the threat of an attacker impersonating the IAB node increases. The IAB node can be deployed at a specific location and accessed by a specific IAB anchor. Therefore, an impersonated IAB node, an IAB node used in an unexpected location, or an IAB node used by an unexpected IAB anchor may interrupt the services in the core network.

[0025] Figure 1 is a block diagram showing an exemplary network system architecture 100 according to an embodiment of the present disclosure. Referring to Figure 1 , an example of the network system architecture 100 is the 5GS architecture. The network system architecture 100 includes various network entities such as, but not limited to, AMF 102, Session Management Function (SMF) 106, User Plane Function (UPF) 108, UDM 112, PCF 114, Application Function (AF) 116, and the like.

[0026] AMF 102 includes functions such as, but not limited to, UE mobility management, reachability management, connection management, etc. For example, where AMF 102 is determined by the communication protocol (CP) interface N2 of the RAN and the non-access stratum (NAS) CP interface N1. The CP interface N2 is used for the communication link between the RAN (e.g., 5G access network (AN) 104) and AMF 102. The NAS CP interface N1 is used for the communication link between the UE 101 (e.g., wireless communication device) and AMF 102. AMF 102 also performs NAS encryption and integrity protection. The UE 101 is connected to the 5G-AN 104.

[0027] In addition, AMF 102 allocates session management (SM) NAS to the appropriate SMF (e.g., SMF106) via the CP interface N11. SMF 106 includes functions such as, but not limited to, UE Internet Protocol (IP) address allocation and management, selection and control of the user plane (UP) function, PDU connection management, etc.

[0028] In some embodiments, the UPF 108 is an anchor point for mobility within a Radio Access Technology (RAT) or for inter-RAT mobility. The UPF 108 can also be an external PDU session point interconnected with a data network 110 connected to the UPF 108. In this regard, the UPF 108 is connected to the SMF 106 via the CP interface N4. The UPF 108 can route and forward data packets as an indication from the SMF 106. When the UE 101 is in the idle mode, the UPF 108 can cache downlink (DL) data. The UPF 108 is connected to the 5G-AN 104.

[0029] The UDM 112 can store the subscription profiles of UEs (including but not limited to the UE 101). The UDM 112 is connected to the AMF 102 via the CP interface N8. The UDM 112 is connected to the SMF 106 via the CP interface N10. Both the UDM and the Authentication Credential Repository and Processing Function (ARPF) belong to the core network and are implemented together. The UDM can save (e.g., store in local memory) mapping information that includes but is not limited to the UICC certificates of pre-authorized IAB-UEs, the pre-authorized identification of mobile devices (IAB-ME), and the pre-authorized location information and cell identification information for cells.

[0030] The PCF 114 can generate policies (e.g., policy and enforcement elements) based on subscriptions and indications from the AF 116 to manage network behavior. The PCF 114 is connected to the AF 116 via an appropriate communication link. The PCF 114 can also provide policy rules to CP functions (e.g., the AMF 102 and the SMF 106), which are configured to enforce these policy rules. For example, the PCF 114 can provide policy rules to the SMF 106 via the CP interface N7.

[0031] Each of the communication links, CP interfaces, connections, etc. shown as a wire between two elements 101 - 116 can be any suitable wired or wireless connection.

[0032] Traditionally, in 5GS, the AMF is responsible for authenticating the UICC certificates and the IAB-ME of IAB nodes. The AMF can communicate with the UDM. The communication with the UDM indicates whether the IAB-UE attempting to register is properly authenticated.

[0033] The present disclosure relates to storing mapping information, which is used for authentication. The mapping information may include UICC certificates of pre-authorized IAB-UEs, pre-authorized IAB-ME identifications, and pre-authorized location information and cell information of cells. The mapping information may be stored in a network entity such as, but not limited to, a UDM, an AMF, an EIR, an HSS, an MME, or other suitable network entities or functions. In addition, network entities such as, but not limited to, a UDM, an AMF, an EIR, an HSS, or an MME may authorize an IAB-UE node attempting to register. Authorization of the IAB-UE node may be determined by performing a check using the stored mapping information and identification information associated with the IAB-UE node attempting to register with the network.

[0034] Figure 2 is a signaling diagram showing an example process 200 for authenticating an IAB-UE 201 via a UDM 210 according to some embodiments of the present disclosure. Referring Figure 2 , the IAB-UE 201 is performing a registration process for the IAB network (e.g., process 200), which includes connecting to an IAB-anchor 203, an AMF 205, a Equipment Identity Register (EIR) 401, an Authentication Server Function (AUSF) 213, and a UDM 210. The EIR is a register used to authenticate mobile devices in the network. The AUSF manages user authentication during registration or re-registration by obtaining authentication information from the UDM. Process 200 includes the UDM 210 authorizing whether the IAB-UE 201 can connect to the IAB network.

[0035] At 202, the IAB-UE 201 may send a Registration Request to the IAB-anchor 203. The Registration Request may include a certificate in the UICC such as, but not limited to, a Subscription Hidden Identifier (SUCI), a 5G Globally Unique Temporary Identity (5G-GUTI), etc. At 204, the IAB-anchor 203 may send an N2 message to the AMF 205. The N2 message may include both the certificate in the UICC and location information and cell identification information related to the cell in which the IAB-UE 201 resides. At 206, the AMF 205 may authenticate the certificate that has been received from the IAB-anchor 203, for example, in a manner similar to step 9 in clause 4.2.2.2.2 of TS 23.502. In some embodiments, at 207, in response to AMF 205 determining that AMF 205 does not save (e.g., not stored in the local memory of AMF 205) the PEI of IAB-UE 201, AMF 205 may send an identification request message to IAB-UE 201 in a manner similar to step 11 of clause 4.2.2.2.2 of TS 23.502. IAB-UE 201 may respond to the AMF 205 identification request message with an identification response, which includes the PEI of IAB-UE 201. In other embodiments, AMF 205 saves (e.g., stores in the local memory of AMF 205) the PEI of IAB-UE 201.

[0036] In some embodiments, at 208, the AMF 205 may initiate an IAB-ME identification check using an identification response message from the IAB-UE 201, for example in a manner similar to step 12 in TS 23.502 clause 4.2.2.2.2.

[0037] At 209, the AMF 205 may send a Nudm_SDM_Request to the UDM 210, where the Nudm_SDM_Request may contain information related to the following: certificates in the UICC, IAB-ME identification, and both location information and cell identification information related to the cell in which the IAB-UE 201 resides. Based on the operator policy, the UDM 210 may check one or more IAB-UE 201 identification information received from the AMF 205 at 209 against the mapping information stored in the UDM 210. In some embodiments, the UDM 210 may check the received certificates in the UICC and IAB-ME identification (e.g., received from the AMF 205 at 209) against the stored mapping of the certificates in the UICC and IAB-ME identification. In some embodiments, the UDM 210 may check the received certificates in the UICC, IAB-ME identification, and location information related to the cells in which the IAB-UE 201 can reside against the mapping information stored in the UDM 210 for the certificates in the UICC, IAB-ME identification, and location information related to the cell in which the IAB-UE 201 resides (e.g., received from the AMF 205 at 209). In some embodiments, the UDM 210 may check the received certificates in the UICC, IAB-ME identification, and both location information and cell identification information related to the cell in which the IAB-UE 201 resides against the mapping information stored in the UDM 210 for the certificates in the UICC, IAB-ME identification, and both location information and cell identification information related to the cell in which the IAB-UE 201 resides (e.g., received from the AMF 205 at 209).

[0038] In one embodiment, when the UDM 210 checks the mapping information against the IAB-UE 201 identification information (e.g., the information received from the AMF 205 at 209), the UDM 210 determines whether the stored information matches the IAB-UE 201 identification information received from the AMF 205 at 209.

[0039] In one embodiment, the UDM 210 may match the certificates and IAB-ME identification information in the stored UICC with the IAB-UE 201 identity information received from the AMF 205 at 209, such as the certificates and IAB-ME identification information in the UICC. In one embodiment, the UDM 210 may match the certificates, IAB-ME identification information, and location information in the stored UICC with the IAB-UE 201 identification information received from the AMF 205 at 209, such as the certificates, IAB-ME identification information, and location information related to the cell where the IAB-UE 201 resides in the UICC. In one embodiment, the UDM 210 may match both the certificates, IAB-ME identification information, and location information related to the cell where the IAB-UE 201 resides and the cell identification information in the stored UICC with the IAB-UE 201 identification information received from the AMF 205 at 209, such as the certificates, IAB-ME identification information, and both the location information and cell identification information related to the cell where the IAB-UE 201 resides in the UICC.

[0040] In response to the IAB-UE 201 identification information matching the stored mapping information, the UDM 210 may determine that the mapping is successful and the IAB-UE 201 is authorized to connect to the network. In response to the IAB-UE 201 identification information not matching the stored mapping information, the UDM 210 may determine that the mapping is unsuccessful and the IAB-UE 201 is not authorized to connect to the network.

[0041] At 211, the UDM 210 may send a Nudm_SDM_Response to the AMF 205, which indicates the success or failure of the mapping of the IAB-UE information. In some embodiments, in response to the UDM 210 determining that the mapping is successful, at 212, the AMF 205 may send a Registration Accept to the IAB-anchor 203, and the IAB-anchor 203 relays the UDM 210 response to the IAB-UE 201. Upon receiving the Registration Accept, the IAB-UE 201 is authorized to connect to the network. In other embodiments, in response to the UDM 210 determining that the mapping is not successful, the AMF 205 may send a rejection response to the IAB-anchor 203, and the IAB-anchor 203 relays the UDM 210 response to the IAB-UE 201. When receiving the rejection response to the RegistrationRequest at 202, the IAB-UE 201 is not authorized to connect to the network.

[0042] Figure 3 is a signaling diagram showing an example process 300 for authenticating an IAB-UE 201 via the AMF 205 according to some embodiments of the present disclosure. Refer to Figure 3 , the IAB-UE 201 is performing a registration process (e.g., process 300) for the IAB network, which includes connecting to the IAB-anchor 203, the AMF 205, the EIR 401, the AUSF 213, and the UDM 210. The process 300 includes the AMF 205 authorizing whether the IAB-UE 201 can connect to the IAB network.

[0043] In this embodiment, the AMF 205 determines whether the IAB-UE 201 is authorized to connect to the IAB network by checking the stored authentication information and the IAB nodes allowed by the authentication information mapping. At 301, the AMF may be preconfigured with mapping information, which includes but is not limited to the UICC certificate of the pre-authorized IAB-UE, the pre-authorized IAB-ME identification, and the pre-authorized location information and cell identification information related to the cell where the IAB-UE 201 resides. The mapping information may be preconfigured via operation, administration, and maintenance (OAM) or provided by the UDM 210.

[0044] At 302, the IAB-UE 201 may send a Registration Request to the IAB-anchor 203. The Registration Request may include a certificate in the UICC such as, but not limited to, SUCI, 5G-GUTI, etc. At 304, the IAB-anchor 203 may send an N2 message to the AMF 205. The N2 message may include both the certificate in the UICC and location information and cell identification information related to the cell in which the IAB-UE 201 resides. At 306, the AMF 205 may authenticate the certificate that has been received from the IAB-anchor 203, for example, in a manner similar to step 9 in clause 4.2.2.2.2 of TS 23.502. In some embodiments, at 307, in response to the AMF 205 determining that the AMF 205 does not save (e.g., not stored in the local memory of the AMF 205) the PEI of the IAB-UE 201, the AMF 205 may send an identification request message to the IAB-UE 201 in a manner similar to step 11 of clause 4.2.2.2.2 of TS 23.502. The IAB-UE 201 may respond to the AMF 205 identification request message with an identification response, the identification response including the PEI of the IAB-UE 201. In other embodiments, the AMF 205 saves (e.g., stores in the local memory of the AMF 205) the PEI of the IAB-UE 201.

[0045] In some embodiments, at 308, the AMF 205 may initiate an IAB-ME identification check using an identification response message from the IAB-UE 201, for example in a manner similar to step 12 in TS 23.502 clause 4.2.2.2.2.

[0046] At 309, based on the operator's policy, the AMF 205 can check one or more IAB-UE 201 identification information against the mapping information stored in the AMF 205. In some embodiments, the AMF 205 can check the certificate in the received UICC (e.g., received from the IAB-donor 203 in the N2 message at 304) and the IAB-ME identification against the mapping of the certificate and the IAB-ME identification stored in the UICC. In some embodiments, the AMF 205 can check the certificate in the received UICC, the IAB-ME identification, and the location information related to the cell where the IAB-UE 201 resides (e.g., received from the IAB-anchor 203 in the N2 message at 304) against the stored mapping information of the certificate, the IAB-ME identification, and the location information related to the cell where the IAB-UE 201 resides in the stored UICC. In some embodiments, the AMF 205 can check the certificate in the received UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell where the IAB-UE 201 resides (e.g., received from the IAB-anchor 203 in the N2 message at 304) against the mapping information of the certificate, the IAB-ME identification, and both the location information and the cell identification information related to the cell where the IAB-UE 201 resides in the stored UICC.

[0047] In some embodiments, the AMF 205 can check the certificate in the received UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell where the IAB-UE 201 resides against the mapping information of the certificate, the IAB-ME identification, and both the location information and the cell identification information related to the cell where the IAB-UE 201 resides in the stored UICC (e.g., received from the IAB-anchor 203 in the N2 message at 304).

[0048] In one embodiment, when the AMF 205 checks the mapping information against the IAB-UE 201 identification information (e.g., the information received from the IAB-anchor 203 in the N2 message at 304), the AMF 205 determines whether the stored information matches the IAB-UE 201 identification information received from the IAB-anchor in the N2 message at 304.

[0049] In one embodiment, the AMF 205 may match the certificates and IAB-ME identification information in the stored UICC with the IAB-UE 201 identification information received from the IAB-anchor 203 in the N2 message at 304, where the received IAB-UE 201 identification information is such as the certificates and IAB-ME identification information in the UICC. In one embodiment, the AMF 205 may match the certificates, IAB-ME identification information, and location information in the stored UICC with the IAB-UE 201 identification information received from the IAB-anchor 203 in the N2 message at 304, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and location information related to the cell where the IAB-UE 201 resides. In one embodiment, the AMF 205 may match both the certificates, IAB-ME identification information, and location information related to the cell where the IAB-UE 201 resides and the cell identification information with the IAB-UE 201 identification information received from the IAB-anchor in the N2 message at 304, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and both the location information related to the cell where the IAB-UE 201 resides and the cell identification information.

[0050] In response to the IAB-UE 201 identification information matching the stored mapping information, the AMF 205 may determine that the mapping is successful and the IAB-UE 201 is authorized to connect to the network. In response to the IAB-UE 201 identification information not matching the stored mapping information, the AMF 205 may determine that the mapping is unsuccessful and the IAB-UE 201 is not authorized to connect to the network.

[0051] In response to the AMF 205 determining that the mapping is successful, at 310, the AMF 205 may send a Registration Accept to the IAB-anchor 203, and the IAB-anchor 203 relays the AMF 205 response to the IAB-UE 201. Upon receiving the Registration Accept, the IAB-UE 201 is authorized to connect to the network. In other embodiments, in response to the AMF 205 determining that the mapping is unsuccessful, the AMF 205 may send a rejection response to the IAB-anchor 203, and the IAB-anchor 203 relays the AMF 205 response to the IAB-UE 201. When receiving a rejection response to the Registration Request at 302, the IAB-UE 201 is not authorized to connect to the network.

[0052] Figure 4is a signaling diagram showing an example process 400 for authenticating an IAB-UE 201 via an EIR 401 according to some embodiments of the present disclosure. Referring to Figure 4 , the IAB-UE 201 is performing a registration process (e.g., process 400) with respect to the IAB network, and the registration process includes connecting to the IAB-anchor 203, the AMF 205, the EIR 401, the AUSF 213, and the UDM 210. Process 300 includes the EIR 401 authorizing whether the IAB-UE 201 can connect to the IAB network.

[0053] In this embodiment, the EIR 401 determines whether the IAB-UE 201 is authorized to connect to the IAB network by checking the stored authentication information and the IAB nodes permitted by the authentication information mapping. At 402, the EIR 401 may be preconfigured with mapping information, which includes but is not limited to the UICC certificate of the pre-authorized IAB-UE, the pre-authorized IAB-ME identification, and the pre-authorized location information and cell identification information related to the cell where the IAB-UE 201 resides. The mapping information may be preconfigured via OAM or provided by the UDM 210.

[0054] At 403, the IAB-UE 201 may send a Registration Request to the IAB-anchor 203. The Registration Request may contain certificates in the UICC such as but not limited to SUCI, 5G-GUTI, etc. At 405, the IAB-anchor 203 may send an N2 message to the AMF 205. The N2 message may include both the certificate in the UICC and the location information and cell identification information related to the cell where the IAB-UE 201 resides. At 407, the AMF 205 may authenticate the certificate received from the IAB-anchor 203, for example, in a manner similar to step 9 in clause 4.2.2.2.2 of TS 23.502. In some embodiments, at 408, in response to the AMF 205 determining that the AMF 205 does not save (e.g., does not store in the local memory of the AMF 205) the PEI of the IAB-UE 201, the AMF 205 may send an identification request message to the IAB-UE 201 in a manner similar to step 11 in clause 4.2.2.2.2 of TS 23.502. The IAB-UE 201 may respond to the AMF 205 identification request message with an identification response that includes the PEI of the IAB-UE 201. In other embodiments, the AMF 205 saves (e.g., stores in the local memory of the AMF 205) the PEI of the IAB-UE 201.

[0055] At 409, the AMF 205 may send an N5g-eir_EquipmentIdentityCheck request to the EIR 401, where the N5g-eir_EquipmentIdentityCheck request may include information related to the following: the certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 is resident. At 410, the EIR 401 may check the IAB-ME identification according to its own register, and, based on the operator policy, the EIR 401 may additionally check the authentication information of the IAB-UE 201.

[0056] The EIR 401 may check one or more IAB-UE 201 identification information received from the AMF 205 at 409 against the mapping information stored in the EIR 401. In some embodiments, the EIR 401 may check the received certificate in the UICC and the IAB-ME identification against the stored mapping of the certificate and the IAB-ME identification in the UICC (e.g., received from the AMF 205 at 409). In some embodiments, the EIR 401 may check the received certificate in the UICC, the IAB-ME identification, and the location information related to the cell in which the IAB-UE 201 is resident against the stored mapping information of the certificate in the UICC, the IAB-ME identification, and the location information related to the cell in which the IAB-UE 201 is resident (e.g., received from the AMF 205 at 409). In some embodiments, the EIR 401 may check the received certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 is resident against the stored mapping information of the certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 is resident (e.g., received from the AMF 205 at 409).

[0057] In one embodiment, when the EIR 401 checks the mapping information against the IAB-UE 201 identification information (e.g., the information received from the AMF 205 at 409), the EIR 401 determines whether the stored information matches the IAB-UE 201 identification information received from the AMF 205 at 409.

[0058] In one embodiment, the EIR 401 may match the certificates and IAB-ME identification information in the stored UICC with the IAB-UE 201 identification information received from the AMF 205 at 409, where the received IAB-UE 201 identification information is such as the certificates and IAB-ME identification information in the UICC. In one embodiment, the EIR 401 may match the certificates, IAB-ME identification information, and location information in the stored UICC with the IAB-UE 201 identification information received from the AMF 205 at 409, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and location information related to the cell in which the IAB-UE 201 resides. In one embodiment, the EIR 401 may match both the certificates, IAB-ME identification information, and the location information and cell identification information related to the cell in which the IAB-UE 201 resides in the stored UICC with the IAB-UE 201 identification information received from the AMF 205 at 409, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and both the location information and cell identification information related to the cell in which the IAB-UE 201 resides.

[0059] In response to the IAB-UE 201 identification information matching the stored mapping information, the EIR 401 may determine that the mapping is successful and the IAB-UE 201 is authorized to connect to the network. In response to the IAB-UE 201 identification information not matching the stored mapping information, the EIR 401 may determine that the mapping is unsuccessful and the IAB-UE 201 is not authorized to connect to the network.

[0060] At 411, the EIR 401 may send an N5g-EIR_EqiupmentIdentityCheck response to the AMF 205, which indicates the success or failure of the IAB-UE information mapping. In some embodiments, in response to the EIR 401 determining that the mapping is successful, at 412, the AMF 205 may send a RegistrationAccept to the IAB-anchor 203, and the IAB-anchor 203 relays the EIR 401 response to the IAB-UE 201. Upon receiving the Registration Accept, the IAB-UE 201 is authorized to connect to the network. In other embodiments, in response to the EIR 401 determining that the mapping is not successful, the AMF 205 may send a rejection response to the IAB-anchor 203, and the IAB-anchor 203 relays the EIR 401 response to the IAB-UE 201. When receiving a rejection response to the Registration Request at 403, the IAB-UE 201 is not authorized to connect to the network.

[0061] Figure 5 is a signaling diagram showing an example process 500 for authenticating an IAB-UE via a Home Subscriber Server (HSS) according to some embodiments of the present disclosure. The HSS stores user and subscription information for accessing a network such as an EPS network. Referring to Figure 5 , the IAB-UE 201 is performing a registration process (e.g., process 500) for the IAB network, which includes connecting to the IAB-anchor 203, a Mobility Management Entity (MME) 503, an EIR 701, and an HSS 508. Among other functions, the MME may select a Serving Gateway protocol for each UE when initially connecting to the network, or, when a node relocates to or from the network, the MME may authenticate the UE by interacting with the HSS. Process 500 includes the HSS 508 authorizing whether the IAB-UE 201 can connect to the IAB network.

[0062] At 501, the IAB-UE 201 sends an Attach Request to the IAB-anchor 203. The Attach Request may include credentials in the UICC such as, but not limited to, the International Mobile Subscriber Identity (IMSI), the Globally Unique Temporary Identity (GUTI), etc. At 502, the IAB-anchor 203 may send an S1-MME message to the MME 503. The S1-MME message may include both the credentials in the UICC and location information and cell identification information related to the cell in which the IAB-UE 201 is camped. At 504, the MME 503 may authenticate the credentials received from the IAB-anchor 203, for example, in a manner similar to step 5a in clause 5.3.2.1 of TS 23.401. In some embodiments, at 505, in response to the MME determining that the MME 503 does not save (e.g., does not store in the local memory of the MME 503) the IAB-ME identity (International Mobile Equipment Identity (IMEI)) of the IAB-UE 201, the MME 503 may send an identification request message to the IAB-UE 201 in a manner similar to step 5b in clause 5.3.2.1 of TS 23.401. The IAB-UE 201 may respond to the MME 503 identification request message with an identification response that includes the IMEI of the IAB-UE 201. In other embodiments, the MME 503 saves (e.g., stores in the local memory of the MME 503) the IMEI of the IAB-ME 201.

[0063] In some embodiments, at 506, the MME 503 may use the identification response message from the IAB-UE 201 to start the IAB-ME identification check, for example, in a manner similar to step 5b in clause 5.3.2.1 of TS 23.401. At 507, the MME 503 may send a Notify Request to the HSS 508, where the Notify Request may contain information related to the following: the certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 is resident. Based on the operator's policy, the HSS 508 may check one or more IAB-UE 201 identification information received from the MME 503 at 507 against the mapping information stored in the HSS 508. In some embodiments, the HSS 508 may check the received certificate in the UICC and the IAB-ME identification (e.g., received from the MME 503 at 507) against the stored mapping of the certificate in the UICC and the IAB-ME identification. In some embodiments, the HSS 508 may check the received certificate in the UICC, the IAB-ME identification, and the location information related to the cell in which the IAB-UE 201 is resident (e.g., received from the MME 503 at 507) against the stored mapping information of the certificate in the UICC, the IAB-ME identification, and the location information related to the cell in which the IAB-UE 201 is resident. In some embodiments, the HSS 508 may check the received certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 is resident (e.g., received from the MME 503 at 507) against the stored mapping information of the certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 is resident.

[0064] In one embodiment, when the HSS 508 checks the mapping information against the IAB-UE 201 identification information (e.g., the information received from the MME 503 at 507), the HSS 508 determines whether the stored information matches the IAB-UE 201 identification information received from the MME 503 at 507.

[0065] In one embodiment, the HSS 508 may match the certificates and IAB-ME identification information in the stored UICC with the IAB-UE 201 identification information received from the MME 503 at 507, where the received IAB-UE 201 identification information is such as the certificates and IAB-ME identification information in the UICC. In one embodiment, the HSS 508 may match the certificates, IAB-ME identification information, and location information in the stored UICC with the IAB-UE 201 identification information received from the MME 503 at 507, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and location information related to the cell where the IAB-UE 201 resides. In one embodiment, the HSS 508 may match both the certificates, IAB-ME identification information, and location information related to the cell where the IAB-UE 201 resides and the cell identification information in the stored UICC with the IAB-UE 201 identification information received from the MME 503 at 507, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and both the location information and cell identification information related to the cell where the IAB-UE 201 resides.

[0066] In response to the IAB-UE 201 identification information matching the stored mapping information, the HSS 508 may determine that the mapping is successful and the IAB-UE 201 is authorized to connect to the network. In response to the IAB-UE 201 identification information not matching the stored mapping information, the HSS 508 may determine that the mapping is unsuccessful and the IAB-UE 201 is not authorized to connect to the network.

[0067] At 509, the HSS 508 may send a Notify Response to the MME 503, which indicates the success or failure of the mapping of the IAB-UE information. In some embodiments, in response to the HSS 508 determining that the mapping is successful, at 509, the MME 503 may send an Attach Accept to the IAB-anchor 203, and the IAB-anchor 203 relays the HSS 508 response to the IAB-UE 201. Upon receiving the Attach Accept, the IAB-UE 201 is authorized to connect to the network. In other embodiments, in response to the HSS 508 determining that the mapping is unsuccessful, the MME 503 may send a rejection response to the IAB-anchor 203, and the IAB-anchor 203 relays the HSS 508 response to the IAB-UE 201. When receiving a rejection response to the Attach Request at 501, the IAB-UE 201 is not authorized to connect to the network.

[0068] Figure 6 is a signaling diagram showing an example process 600 for authenticating an IAB-UE 201 via an MME 503 according to some embodiments of the present disclosure. Referring to Figure 6 , the IAB-UE is performing a registration process with respect to the IAB network (e.g., process 600), which includes connecting to an IAB-anchor 203, an MME 503, an EIR 701, and an HSS 508. Process 600 includes the MME 503 authorizing whether the IAB-UE 201 can connect to the IAB network.

[0069] In this embodiment, the MME 503 determines whether the IAB-UE 201 is authorized to connect to the IAB network by checking the stored authentication information and mapping the authentication information of the IAB node. At 601, the MME 503 may be preconfigured with mapping information, which includes but is not limited to the UICC certificate of a pre-authorized IAB-UE, the pre-authorized IAB-ME identification, and the pre-authorized location information and cell identification information related to the cell in which the IAB-UE 201 resides. The mapping information may be preconfigured via OAM or provided by the HSS 508.

[0070] At 602, the IAB-UE 201 sends an Attach Request to the IAB-anchor 203. The Attach Request may contain certificates in the UICC such as but not limited to IMSI, GUTI, etc. At 603, the IAB-anchor 203 may send an S1-MME message to the MME 503. The S1-MME message may include both the certificate in the UICC and the location information and cell identification information related to the cell in which the IAB-UE 201 resides. At 604, the MME 503 may authenticate the certificate received from the IAB-anchor 203 in a manner similar to step 5a in clause 5.3.2.1 of TS 23.401, for example. In some embodiments, at 605, in response to the MME 503 determining that the MME 503 does not save (e.g., does not store in the local memory of the MME 503) the IMEI of the IAB-UE 201, the MME 503 may send an identification request message to the IAB-UE 201 in a manner similar to step 5b in clause 5.3.2.1 of TS 23.401. The IAB-UE 201 may respond to the MME 503 identification request message with an identification response that includes the IMEI of the IAB-UE 201. In other embodiments, the MME 503 saves (e.g., stores in the local memory of the MME 503) the IMEI of the IAB-UE 201.

[0071] In some embodiments, at 606, the MME 503 may use the identification response message from the IAB-UE 201 to start the IAB-ME identification check, for example, in a manner similar to step 5b in clause 5.3.2.1 of TS 23.401.

[0072] At 607, based on the operator policy, the MME 503 may check one or more IAB-UE 201 identification information against the mapping information stored in the MME 503. In some embodiments, the MME 503 may check the certificate in the received UICC (e.g., received from the IAB-anchor 203 in the S1-MME message at 603) and the IAB-ME identification against the mapping of the certificate in the stored UICC and the IAB-ME identification. In some embodiments, the MME 503 may check the certificate in the received UICC, the IAB-ME identification, and the location information related to the cell where the IAB-UE 201 resides (e.g., received from the IAB-anchor 203 in the S1-MME message at 603) against the mapping information of the certificate, the IAB-ME identification, and the location information related to the cell where the IAB-UE 201 resides stored in the UICC. In some embodiments, the MME 503 may check the certificate in the received UICC, the IAB-ME identification, and both the location information related to the cell where the IAB-UE 201 resides and the cell identification information against the mapping information of the certificate, the IAB-ME identification, and both the location information related to the cell where the IAB-UE 201 resides and the cell identification information stored in the UICC (e.g., received from the IAB-anchor 203 in the S1-MME message at 603).

[0073] In some embodiments, the MME 503 may check the certificate in the received UICC, the IAB-ME identification, and both the location information related to the cell where the IAB-UE 201 resides and the cell identification information against the mapping information of the certificate, the IAB-ME identification, and both the location information related to the cell where the IAB-UE 201 resides and the cell identification information stored in the UICC (e.g., received from the IAB-anchor 203 in the S1-MME message at 603).

[0074] In one embodiment, when the MME 503 checks the mapping information against the IAB-UE 201 identification information (e.g., the information received from the IAB-anchor 203 in the S1-MME message at 603), the MME 503 determines whether the stored information matches the IAB-UE 201 identification information received from the IAB-anchor in the S1-MME message at 603.

[0075] In one embodiment, the MME 503 may match the certificate and IAB-ME identification information in the stored UICC with the IAB-UE 201 identification information received from the IAB-anchor 203 in the S1-MME message at 603, where the received IAB-UE 201 identification information is such as the certificate and IAB-ME identification information in the UICC. In one embodiment, the MME 503 may match the certificate, IAB-ME identification information, and location information in the stored UICC with the IAB-UE 201 identification information received from the IAB-anchor 203 in the S1-MME message at 603, where the received IAB-UE 201 identification information is such as the certificate, IAB-ME identification information, and location information related to the cell in which the IAB-UE 201 resides. In one embodiment, the MME 503 may match both the certificate, IAB-ME identification information, and location information related to the cell in which the IAB-UE 201 resides and the cell identification information in the stored UICC with the IAB-UE 201 identification information received from the IAB-anchor in the S1-MME message at 603, where the received IAB-UE 201 identification information is such as the certificate, IAB-ME identification information, and both the location information and cell identification information related to the cell in which the IAB-UE 201 resides.

[0076] In response to the IAB-UE 201 identification information matching the stored mapping information, the MME 503 may determine that the mapping is successful and the IAB-UE 201 is authorized to connect to the network. In response to the IAB-UE 201 identification information not matching the stored mapping information, the MME 503 may determine that the mapping is unsuccessful and the IAB-UE 201 is not authorized to connect to the network.

[0077] In response to the MME 503 determining that the mapping is successful, at 608, the MME 503 may send an AttachAccept to the IAB-anchor 203, and the IAB-anchor 203 relays the MME 503 response to the IAB-UE 201. Upon receiving the Attach Accept, the IAB-UE 201 is authorized to connect to the network. In other embodiments, in response to the MME 503 determining that the mapping is not successful, the MME 503 may send a rejection response to the IAB-anchor 203, and the IAB-anchor 203 relays the MME 503 response to the IAB-UE 201. When receiving a rejection response to the Attach Request at 602, the IAB-UE 201 is not authorized to connect to the network.

[0078] Figure 7is a signaling diagram showing an example process 700 for authenticating an IAB-UE 201 via an EIR 701 according to some embodiments of the present disclosure. Referring to Figure 7 , the IAB-UE is performing a registration process (e.g., process 400) for the IAB network, which includes connecting to the IAB-anchor 203, MME 503, EIR 701, and HSS 508. Process 700 includes the EIR 701 authenticating whether the IAB-UE can connect to the IAB network.

[0079] In this embodiment, the EIR 701 determines whether the IAB-UE 201 is authorized to connect to the IAB network by checking the stored authentication information and the IAB nodes allowed by the authentication information mapping. At 702, the EIR 701 may be preconfigured with mapping information, which includes but is not limited to the UICC certificate of the pre-authorized IAB-UE, the pre-authorized IAB-ME identification, and the pre-authorized location information and cell identification information related to the cell where the IAB-UE 201 resides. This mapping information may be preconfigured via OAM or provided by the HSS 508.

[0080] At 703, the IAB-UE 201 may send an Attach Request to the IAB-anchor 203. The Attach Request may contain certificates in the UICC such as but not limited to IMSI, GUTI, etc. At 704, the IAB-anchor 203 may send an S1-MME message to the MME 503. The S1-MME message may include both the certificate in the UICC and the location information and cell identification information related to the cell where the IAB-UE 201 resides. At 705, the MME 503 may authenticate the certificate received from the IAB anchor-203 in a manner similar to step 5a in clause 5.3.2.1 of TS 23.401. In some embodiments, at 706, in response to the MME 503 determining that the MME 503 does not save (e.g., is not stored in the local memory of the MME 503) the IMEI of the IAB-UE 201, the MME 503 may send an identification request message to the IAB-UE 201 in a manner similar to step 5b in clause 5.3.2.1 of TS 23.401. The IAB-UE 201 may respond to the MME 503 identification request message with an identification response including the IMEI of the IAB-UE 201. In other embodiments, the MME 503 saves (e.g., stores in the local memory of the MME 503) the IMEI of the IAB-UE 201.

[0081] At 707, the MME 503 may send a ME Identity Check request to the EIR 701, where the ME Identity Check request may include information related to the following: the certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 resides. At 708, the EIR 701 may check the IAB-ME identification against its own register, and, based on the operator policy, the EIR 701 may additionally check the authentication information of the IAB-UE 201.

[0082] The EIR 701 may check one or more IAB-UE 201 identification information received from the MME 503 at 707 against the mapping information stored in the EIR 401. In some embodiments, the EIR 701 may check the received certificate in the UICC and the IAB-ME identification (e.g., received from the MME 503 at 707) against the stored mapping of the certificate and the IAB-ME identification in the UICC. In some embodiments, the EIR 701 may check the received certificate in the UICC, the IAB-ME identification, and the location information related to the cell in which the IAB-UE 201 resides (e.g., received from the MME 503 at 707) against the stored mapping information of the certificate in the UICC, the IAB-ME identification, and the location information related to the cell in which the IAB-UE 201 resides. In some embodiments, the EIR 701 may check the received certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 resides (e.g., received from the MME 503 at 707) against the stored mapping information of the certificate in the UICC, the IAB-ME identification, and both the location information and the cell identification information related to the cell in which the IAB-UE 201 resides.

[0083] In one embodiment, when the EIR 701 checks the mapping information against the IAB-UE 201 identification information (e.g., the information received from the MME 503 at 707), the EIR 701 determines whether the stored information matches the IAB-UE 201 identification information received from the MME 503 at 707.

[0084] In one embodiment, the EIR 701 may match the certificates and IAB-ME identification information in the stored UICC with the IAB-UE 201 identification information received from the MME 503 at 707, where the received IAB-UE 201 identification information is such as the certificates and IAB-ME identification information in the UICC. In one embodiment, the EIR 701 may match the certificates, IAB-ME identification information, and location information in the stored UICC with the IAB-UE 201 identification information received from the MME 503 at 707, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and location information related to the cell in which the IAB-UE 201 resides. In one embodiment, the EIR 701 may match both the stored certificates, IAB-ME identification information, and location information related to the cell in which the IAB-UE 201 resides and the cell identification information in the UICC with the IAB-UE 201 identification information received from the MME 503 at 707, where the received IAB-UE 201 identification information is such as the certificates, IAB-ME identification information, and both the location information and cell identification information related to the cell in which the IAB-UE 201 resides.

[0085] In response to the IAB-UE 201 identification information matching the stored mapping information, the EIR 701 may determine that the mapping is successful and the IAB-UE 201 is authorized to connect to the network. In response to the IAB-UE 201 identification information not matching the stored mapping information, the EIR 701 may determine that the mapping is unsuccessful and the IAB-UE 201 is not authorized to connect to the network.

[0086] At 709, the EIR 701 may send a ME Identity Check response to the MME 503, where the ME Identity Check response indicates the success or failure of the mapping of the IAB-UE information. In some embodiments, in response to the EIR 701 determining that the mapping is successful, at 710, the MME 503 may send an Attach Accept to the IAB-anchor 203, and the IAB-anchor 203 relays the EIR 701 response to the IAB-UE 201. Upon receiving the Attach Accept, the IAB-UE 201 is authorized to connect to the network. In other embodiments, in response to the EIR 701 determining that the mapping is not successful, the MME 503 may send a rejection response to the IAB-anchor 203, and the IAB-anchor 203 relays the EIR 701 response to the IAB-UE 201. When receiving a rejection response to the Attach Request at 703, the IAB-UE 201 is not authorized to connect to the network.

[0087] Figure 8 is a flowchart showing an example method for determining the authentication and access of a node to a network according to an embodiment of the present disclosure. Referring to Figures 1-7 , method 800 may be performed by different network entities, including but not limited to the UDM 210 (as Figure 2 shown), the AMF 503 (as Figure 3 shown), the EIR 401 / 701 (as Figure 4 and 7 shown), the HSS 508 (as Figure 5 shown), and the MME503 (as Figure 6 shown).

[0088] At 810, a wireless communication method includes storing mapping information by a first network entity.

[0089] In some examples, as Figure 2 , 4 , 5, and 7 shown, the second network entity receives a certificate of the first node, location information of the cell, and a cell identification of the cell from the second node, and the first network entity receives the certificate of the first node, identification information of the first node, location information of the cell, and a cell identification of the cell from the second network entity.

[0090] In some examples, as Figure 2 shown, the first network entity is the UDM 210, the second network entity is the AMF 305, the first node is the IAB-UE 201, and the second node is the IAB-anchor 203.

[0091] In some examples, as Figure 4 shown, the first network entity is the EIR 401, the second network entity is the AMF 205, the first node is the IAB-UE 201, and the second node is the IAB-anchor 203. The mapping information may be pre-configured via OAM or received from the UDM 210.

[0092] In some examples, as Figure 5 shown, the first network entity is the HSS 508, the second network entity is the MME 503, the first node is the IAB-UE 201, and the second node is the IAB-anchor 203.

[0093] In some examples, as Figure 7 shown, the first network entity is the EIR 701, the second network entity is the MME 503, the first node is the IAB-UE 201, and the second node is the IAB-anchor 203. The mapping information may be pre-configured via OAM or received from the HSS 508.

[0094] In some examples, such as Figure 3 and 6 shown, the first network entity may receive the certificate of the first node, the location information of the cell, and the cell identification of the cell from the second node.

[0095] In some examples, such as Figure 3 shown, the mapping information may be pre-configured by the OAM or received from the second network entity. The first network entity is the AMF 205, the second network entity is the UDM 210, the first node is the IAB-UE 201, and the second node is the IAB-anchor 203.

[0096] In some examples, such as Figure 6 shown, the first network entity is the MME 503, the IAB-UE is 201, and the second node is the IAB-anchor 203. The mapping information may be pre-configured via the OAM or received from the HS508.

[0097] At 820, the wireless communication method determines, by the first network entity based on the identification information and the mapping information, that the first node is authorized to connect to the network. The identification information includes one or more of the certificate of the first node, the identification information of the first node, the location information of the cell where the first node resides, or the cell identification of the cell. The certificate of the first node includes the certificate in the UICC of the first node, and the identification information of the first node includes the IAB-ME identification of the first node. In some examples, the mapping information maps the certificates of multiple nodes to the identification information of multiple nodes. In some examples, the mapping information maps the certificates of multiple nodes, the identification information of multiple nodes, and the location information of multiple cells to each other. In some examples, the mapping information maps the certificates of multiple nodes, the identification information of multiple nodes, the location information of multiple cells, and the cell identification of multiple cells to each other.

[0098] Figure 9A A block diagram of an example base station 902 in accordance with some embodiments of the present disclosure is shown. Figure 9B A block diagram of an example UE 101 in accordance with some embodiments of the present disclosure is shown. For example, the UE may be an IAB node configured as an IAB-UE. Refer to Figures 1-9B, the base station 902 and the UE 101 may include components and elements configured to support known or conventional operating features that are not detailed herein. In an illustrative embodiment, the base station 902 and the UE 101 can be used to transmit (e.g., send and receive) data symbols in a wireless communication environment such as the network system architecture 100 and the registration processes 200, 300, 400, 500, 600, 700 described above. For example, the base station 902 can be a base station (e.g., gNodeB (gNB), an IAB node configured as a base station, or an IAB-DU, etc.), a server, a node, or any suitable computing device for implementing NFs (e.g., AMF 102, SMF 106, UPF 108, UDM 112, PCF 114, AF 116, etc.), and providing the networks 104 and 110.

[0099] The base station 902 includes a transceiver module 910, an antenna 912, a processor module 914, a memory module 916, and a network communication module 918. The modules 910, 912, 914, 916, and 918 are operably coupled and interconnected with each other via a data communication bus 920. The UE 101 includes a UE transceiver module 930, a UE antenna 932, a UE memory module 934, and a UE processor module 936. The modules 930, 932, 934, and 936 are operably coupled and interconnected with each other via a data communication bus 940. The base station 902 communicates with the UE 101 or another base station via a communication channel, which can be any wireless channel or other medium suitable for data transmission as described herein.

[0100] As will be understood by those of ordinary skill in the art, the base station 902 and the UE 101 may also include any number of modules other than Figure 9A and 9B the modules shown. The various illustrative blocks, modules, circuits, and processing logics described in connection with the embodiments disclosed herein can be implemented in hardware, computer-readable software, firmware, or any practical combination thereof. To illustrate this interchangeability and compatibility of hardware, firmware, and software, the various illustrative components, blocks, modules, circuits, and steps are generally described in terms of their functionality. Whether this functionality is implemented as hardware, firmware, or software depends on the particular application and the design constraints imposed on the overall system. The embodiments described herein can be implemented in a suitable manner for each particular application, but the decision of any implementation should not be construed as limiting the scope of the present disclosure.

[0101] According to some embodiments, the UE transceiver 930 includes a radio frequency (RF) transmitter and an RF receiver, each of which includes circuitry coupled to an antenna 932. A duplexer switch (not shown) may alternatively couple the RF transmitter or receiver to the antenna in a time-division duplexing manner. Similarly, according to some embodiments, the transceiver 910 includes an RF transmitter and an RF receiver, each of which has circuitry coupled to an antenna 912 or an antenna of another base station. The duplexer switch alternatively couples the RF transmitter or receiver to the antenna 912 in a time-division duplexing manner. The operations of the two transceiver modules 910 and 930 may be coordinated in time such that while the transmitter is coupled to the antenna 912, the receiver circuitry is coupled to the antenna 932 to receive transmissions over a wireless transmission link. In some embodiments, there is tight time synchronization with a minimum guard time between changes in the duplexing direction.

[0102] The UE transceiver 930 and the transceiver 910 are configured to communicate via a wireless data communication link and cooperate with a suitably configured RF antenna arrangement 912 / 932 capable of supporting a particular wireless communication protocol and modulation scheme. In some illustrative embodiments, the UE transceiver 910 and the transceiver 910 are configured to support industry standards such as Long-Term Evolution (LTE) and emerging 5G standards. However, it should be understood that the present disclosure is not necessarily limited in application to specific standards and related protocols. Instead, the UE transceiver 930 and the base station transceiver 910 may be configured to support alternative or additional wireless data communication protocols, including future standards or variants thereof.

[0103] The transceiver 910 and the transceiver of another base station (such as but not limited to the transceiver 910) are configured to communicate via a wireless data communication link and cooperate with a suitably configured RF antenna arrangement capable of supporting a particular wireless communication protocol and modulation scheme. In some illustrative embodiments, the transceiver 910 and the transceiver of another base station are configured to support industry standards such as LTE and emerging 5G standards. However, it should be understood that the present disclosure is not necessarily limited in application to specific standards and related protocols. Instead, the transceiver 910 and the transceiver of another base station may be configured to support alternative or additional wireless data communication protocols, including future standards or variants thereof.

[0104] According to various embodiments, base station 902 may be a base station such as, but not limited to, an eNB, serving eNB, target eNB, IAB-DU, femto cell, or pico cell. Base station 902 may be an RN, conventional, DeNB, gNB, or IAB anchor. In some embodiments, UE 101 may be embodied in various types of user equipment such as, for example, a mobile phone, smartphone, personal digital assistant (PDA), tablet computer, laptop computer, wearable computing device, etc. Processor modules 914 and 936 may be implemented or realized using a general-purpose processor, content addressable memory, digital signal processor, application specific integrated circuit, field programmable gate array, any suitable programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. In this manner, the processor may be implemented as a microprocessor, controller, microcontroller, state machine, etc. The processor may also be implemented as a combination of computing devices, e.g., a combination of a digital signal processor and a microprocessor, multiple microprocessors, one or more digital signal processor cores in conjunction with a microprocessor, or any other such configuration.

[0105] In addition, the methods or algorithms disclosed herein may be directly embodied in hardware, firmware, software modules executed respectively by processor modules 914 and 936, or in any practical combination thereof. Memory modules 916 and 934 may be implemented as RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art. In this regard, memory modules 916 and 934 may be coupled respectively to processor modules 910 and 930 such that processor modules 910 and 930 may read information from and write information to memory modules 916 and 934 respectively. Memory modules 916 and 934 may also be integrated into their respective processor modules 910 and 930. In some embodiments, memory modules 916 and 934 may each include a cache for storing temporary variables or other intermediate information during the execution of instructions to be executed respectively by processor modules 910 and 930. Memory modules 916 and 934 may also each include non-volatile memory for storing instructions to be executed respectively by processor modules 910 and 930.

[0106] The network communication module 918 generally represents the hardware, software, firmware, processing logic, and / or other components of the base station 902, and its implementation enables two-way communication between the transceiver 910 and other network components and communication nodes communicating with the base station 902. For example, the network communication module 918 can be configured to support Internet or WiMAX traffic. In a non-limiting deployment, the network communication module 918 provides an 802.3 Ethernet interface, enabling the transceiver 910 to communicate with a traditional Ethernet-based computer network. In this way, the network communication module 918 can include a physical interface for connecting to a computer network (e.g., a mobile switching center (MSC)). In some embodiments where the base station 902 is an IAB anchor, the network communication module 918 includes an optical fiber transmission connection configured to connect the base station 902 to the core network. The terms "configured to", "configured for", and their conjugates, as used herein with respect to a specified operation or function, refer to a device, component, circuit, structure, machine, signal, etc., that is physically constructed, programmed, formatted, and / or arranged to perform the specified operation or function.

[0107] Although the UICC has been described, the certificate can also be stored in other suitable storage devices of the IAB-UE, and examples of such other suitable storage devices can include, but are not limited to, a virtual subscriber identity module (SIM), internal memory, external memory (e.g., any externally connectable storage device such as a memory card, flash device, circuit containing memory, etc.), and a SIM stored in the cloud.

[0108] Although various embodiments of the present solution have been described above, it should be understood that they are presented by way of example rather than limitation. Similarly, the various figures may depict example architectures or configurations, and the provided example architectures or configurations enable those of ordinary skill in the art to understand the example features and functions of the present solution. However, these persons should understand that the solution is not limited to the example architectures or configurations shown, but can be implemented using various alternative architectures and configurations. Additionally, as should be understood by those of ordinary skill in the art, one or more features of one embodiment can be combined with one or more features of another embodiment described herein. Therefore, the breadth and scope of the present disclosure should not be limited by any of the illustrative embodiments described above.

[0109] It should also be understood that any reference to elements using names such as "first", "second", etc. generally does not limit the number or order of these elements. Instead, these names are used herein as a convenient means of distinguishing between two or more elements or element instances. Thus, the reference to a first element and a second element does not mean that only two elements can be employed, or that the first element must be located before the second element in some manner.

[0110] In addition, those of ordinary skill in the art should understand that any of a variety of different technologies and processes can be used to represent information and signals. For example, data, instructions, commands, information, signals, bits, and symbols, as may be referred to in the above description, can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0111] Those of ordinary skill in the art should also understand that any of the various illustrative logical blocks, modules, processors, means, circuits, methods, and functions described in connection with the aspects disclosed herein can be implemented by electronic hardware (e.g., digital implementations, analog implementations, or a combination of both), firmware, various forms of programs or design code containing instructions (which may be referred to herein, for convenience, as "software" or "software modules"), or any combination of these technologies. To clearly illustrate this interchangeability of hardware, firmware, and software, the various illustrative components, blocks, modules, circuits, and steps have been generally described above in terms of their functionality. Whether such functionality is implemented as hardware, firmware, software, or a combination of these technologies depends on the particular application and the design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in various ways for each particular application, but such implementation decisions do not result in a departure from the scope of the present disclosure.

[0112] Furthermore, those of ordinary skill in the art should understand that the various illustrative logical blocks, modules, devices, components, and circuits described herein can be implemented within or performed by an integrated circuit (IC) that includes a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, or any combination thereof. The logical blocks, modules, and circuits can also include antennas and / or transceivers to communicate with various components within a network or within a device. The general-purpose processor can be a microprocessor, but in an alternative, the processor can be any conventional processor, controller, or state machine. The processor can also be implemented as a combination of computing devices, such as, for example, a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other suitable configuration for performing the functions described herein.

[0113] If implemented in software, the functions can be stored as one or more instructions or codes on a computer-readable medium. Thus, the steps of the methods or algorithms disclosed herein can be implemented as software stored on a computer-readable medium. Computer-readable media include computer storage media and communication media, and the communication media includes any medium that enables a computer program or code to be transferred from one place to another. The storage media can be any available medium accessible by a computer. By way of example and not limitation, such computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code in the form of instructions or data structures and is accessible by a computer.

[0114] In this application, the term "module" as used herein refers to software, firmware, hardware, and any combination of these components for performing the related functions described herein. Additionally, for purposes of facilitating discussion, the various modules are described as discrete modules; however, it will be apparent to those of ordinary skill in the art that two or more modules can be combined to form a single module that performs the related functions according to embodiments of the present solution.

[0115] Furthermore, in embodiments of the present solution, a memory or other memory and communication components can be employed. It should be understood that, for clarity, the above description has described embodiments of the present solution with reference to different functional units and processors. However, it is apparent that, without affecting the present solution, any suitable functional distribution between different functional units, processing logic elements, or domains can be used. For example, functions shown to be performed by different processing logic elements or controllers can be performed by the same processing logic element or controller. Thus, the reference to a particular functional unit is only a reference to the appropriate means for providing the described function, and not an indication of a strict logical or physical structure or organization.

[0116] Various modifications to the embodiments described in this disclosure will be apparent to those skilled in the art, and the general principles defined herein can be applied to other embodiments without departing from the scope of the disclosure. Therefore, this disclosure is not intended to be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the novel features and principles disclosed herein, as set forth in the following claims.

Claims

1. A wireless communication method, comprising: storing, by a first network entity, mapping information, the mapping information including certificates and identification information of a plurality of nodes, wherein the identification information includes: certificates of the corresponding plurality of nodes, mobile equipment (ME) identification information of the corresponding plurality of nodes, pre-authorized location information of one or more cells associated with the corresponding plurality of nodes, and cell identifications of the one or more cells; receiving, by the first network entity, the identification information of the first node from the first node, the identification information of the first node including: a certificate of the first node, ME identification information of the first node, location information of a cell where the first node resides, and a cell identification of the cell; and determining, by the first network entity: based on a match between the identification information of the first node and the stored mapping information, the first node is authorized to connect to the network, wherein the mapping information maps the certificates of the plurality of nodes to the identification information of the plurality of nodes; or based on at least a part of the identification information of the first node not matching the stored mapping information, the first node is not authorized to connect to the network.

2. The method according to claim 1, wherein: the certificate of the first node includes a certificate in a universal integrated circuit card (UICC) of the first node, the pre-authorized location information includes locations of the one or more cells where each of the plurality of nodes is authorized to reside, and to determine whether the first node is authorized: the first network entity compares the following two: the identification information of the first node including a certificate of the first node, ME identification information of the first node, location information of a cell where the first node resides, and a cell identification of the cell, and the stored identification information including certificates of the corresponding plurality of nodes, ME identification information of the corresponding plurality of nodes, pre-authorized location information of one or more cells associated with the corresponding plurality of nodes, and cell identifications of the one or more cells; and determining, by the first network entity, based on a match between the identification information of the first node and the stored identification information, that the first node is authorized to connect to the network; or determining, by the first network entity, based on at least a part of the identification information of the first node not matching the stored identification information, that the first node is not authorized to connect to the network.

3. The method according to claim 1, the method further comprising: receiving, by the first network entity, the certificate of the first node, the identification information of the first node, the location information of the cell, and the cell identification of the cell from a second network entity, wherein the second network entity receives the certificate of the first node, the location information of the cell, and the cell identification of the cell from a second node.

4. The method according to claim 3, wherein: the first network entity is a unified data management (UDM); the second network entity is an access and mobility management function (AMF); the first node is an integrated access and backhaul (IAB)-user equipment (UE); and the second node is an IAB-anchor.

5. The method according to claim 3, wherein: The first network entity is an Equipment Identity Register (EIR); The second network entity is an Access and Mobility Management Function (AMF); The first node is an Integrated Access and Backhaul (IAB)-User Equipment (UE); and The second node is an IAB-anchor point.

6. The method according to claim 5, wherein, the mapping information is pre-configured via Operations, Administration, and Maintenance (OAM), or received from a Unified Data Management (UDM).

7. The method according to claim 3, wherein: The first network entity is a Home Subscriber Server (HSS); The second network entity is a Mobility Management Entity (MME); The first node is an Integrated Access and Backhaul (IAB)-User Equipment (UE); and The second node is an IAB-anchor point.

8. The method according to claim 3, wherein: The first network entity is an Equipment Identity Register (EIR); The second network entity is a Mobility Management Entity (MME); The first node is an Integrated Access and Backhaul (IAB)-User Equipment (UE); and The second node is an IAB-anchor point.

9. The method according to claim 8, wherein, the mapping information is pre-configured via Operations, Administration, and Maintenance (OAM), or received from a Home Subscriber Server (HSS).

10. The method according to claim 1, wherein, the mapping information is pre-configured via Operations, Administration, and Maintenance (OAM), or received from the second network entity.

11. The method according to claim 10, wherein: The first network entity is an Access and Mobility Management Function (AMF); The second network entity is a Unified Data Management (UDM); The first node is an Integrated Access and Backhaul (IAB)-User Equipment (UE).

12. The method according to claim 8, wherein: The first network entity is a Mobility Management Entity (MME); The first node is an Integrated Access and Backhaul (IAB)-User Equipment (UE); and The second node is an IAB-anchor point.

13. The method according to claim 12, wherein, the mapping information is pre-configured via Operations, Administration, and Maintenance (OAM), or received from a Home Subscriber Server (HSS).

14. The method according to claim 1, wherein, the mapping information maps the certificates of the multiple nodes, the identification information of the multiple nodes, and the location information of multiple cells to each other.

15. The method according to claim 1, wherein, the mapping information maps the certificates of the multiple nodes, the identification information of the multiple nodes, the location information of multiple cells, and the cell identification of the multiple cells to each other.

16. A wireless communication device includes at least one processor and a memory, wherein the at least one processor is configured to read code from the memory and implement the method according to any one of claims 1-15.

17. A computer program product comprising computer-readable program media code stored thereon, which when executed by at least one processor causes the at least one processor to implement the method according to any one of claims 1-15.