Subscription retrieval for anonymous identity

By generating a second SUCI or SUPI, the problem of protecting the privacy of subscription identifiers during anonymous SUCI authentication in 5G systems is solved, enabling legitimate access and successful authentication for anonymous UEs.

CN115885531BActive Publication Date: 2026-01-09TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180045393.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-06-26
Filing Date
2021-06-25
Publication Date
2026-01-09
Estimated Expiration
2041-06-25

AI Technical Summary

Technical Problem

In 5G systems, when using anonymous SUCI for authentication, existing technologies cannot effectively protect the privacy of subscription identifiers, leading to authentication failures.

Method used

By mapping the information transmitted by EAP TLS, a second SUCI or SUPI is generated. The AUSF node is then used to retrieve the UE's authentication subscription data and real SUPI from the UDM, thereby enabling the subscription retrieval of the anonymous identifier.

Benefits of technology

It effectively protects the privacy of subscription identifiers, ensures the successful execution of the authentication process, and supports legitimate access for anonymous UEs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115885531B_ABST
    Figure CN115885531B_ABST
Patent Text Reader

Abstract

A first network node operating in a telecommunications network can receive an authentication request associated with a communication device requesting registration with the telecommunications network. The authentication request can include first subscriber information. The first network node can determine that the first subscriber information includes an anonymous identifier. In response to determining that the first subscriber information includes an anonymous identifier, the network node can determine an authentication procedure to perform. The network node can receive information associated with the communication device as part of the authentication procedure. The network node can generate second subscriber information based on the information associated with the communication device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates generally to communications, and more particularly to communication methods and related devices and nodes that support wireless communications. BACKGROUND

[0002] Figure 1 An example of a Fifth Generation (“5G”) network is illustrated that includes a 5G base station (“gNB”) and a plurality of communication devices 104 (also referred to as user equipment (“UE”)).

[0003] In addition to 5G Authentication and Key Agreement (“AKA”) or Extensible Authentication Protocol Authentication and Key Agreement (“EAP-AKA”) (e.g., Extensible Authentication Protocol Transport Layer Security (“EAP-TLS”)), the Third Generation Partnership Project (“3GPP”) introduced the use of alternative authentication methods for primary authentication and access to the 5G system.

[0004] The alternative authentication methods can be used with Internet of Things devices in private networks or in isolated deployment scenarios. Further, as part of the Wireless and Wireline Convergence (“WWC”) for 5G systems, it enables Non-5G Capable (“N5GC”) devices (e.g., devices that lack 5G functionality, including Non-Access Stratum (“NAS”) and 5G key hierarchy derivation) behind residential gateways in private or isolated scenarios with wireline access to use alternative EAP methods for authentication and access to the 5G system. SUMMARY

[0005] According to some embodiments, a method of operating a first network node in a telecommunications network is provided. The method can include receiving an authentication request associated with a communication device requesting registration with the telecommunications network. The authentication request can include first subscriber information. The method can further include determining that the first subscriber information includes an anonymous identifier. The method can further include determining an authentication procedure to perform in response to determining that the first subscriber information includes an anonymous identifier. The method can include receiving information associated with the communication device as part of the authentication procedure in response to determining the authentication procedure to perform. The method can further include generating second subscriber information based on the information associated with the communication device.

[0006] According to other embodiments, a method of operating a second network node in a telecommunications network is provided. The method can include receiving, from a first network node, an authentication request associated with a communication device requesting registration with the telecommunications network. The authentication request can include first subscriber information. The method can further include determining, in response to receiving the authentication request, that the first subscriber information includes an anonymous identifier. The method can further include determining, in response to determining that the first subscriber information includes an anonymous identifier, an authentication procedure to perform. The method can further include sending, to the first network node, an authentication response in response to determining the authentication procedure to perform. The authentication response can include an indicator indicating the authentication procedure and an indicator indicating that the subscriber information includes an anonymous identifier.

[0007] According to other embodiments, a first network node, a second network node, a computer program, and / or a computer program product for performing the above-described methods are provided.

[0008] In various embodiments described herein, in response to an anonymous SUCI provided during initial registration of a UE, a predetermined authentication procedure is selected and triggered by the network. In some embodiments, the AUSF node generates a second SUCI or SUPI based on information retrieved through the predetermined authentication procedure and retrieves the actual authentication subscription data and SUPI for the anonymous UE. Thus, subscription retrieval is available when any anonymous SUCI is sent over 5G system control signaling. BRIEF DESCRIPTION OF DRAWINGS

[0009] The accompanying drawings, included to provide a further understanding of the disclosure and are incorporated in and constitute a part of this application, illustrate certain non-limiting embodiments of the inventive concepts. In the drawings:

[0010] Figure 1 is a schematic diagram illustrating an example of a Fifth Generation (“5G”) network;

[0011] Figure 2 is a signal flow diagram illustrating an example of using an Extensible Authentication Protocol Transport Layer Security (“EAP-TLS”) authentication procedure for initial authentication over a 5G network;

[0012] Figure 3 is a signal flow diagram illustrating an example of subscription retrieval for an anonymous identity (“ID”) according to some embodiments;

[0013] Figure 4 is a signal flow diagram illustrating another example of subscription retrieval for an anonymous identity (“ID”) according to some embodiments;

[0014] Figure 5 is a block diagram illustrating an example of a communication device according to some embodiments;

[0015] Figure 6 is a block diagram illustrating an example of a radio access network (“RAN”) node according to some embodiments;

[0016] Figure 7 is a block diagram illustrating an example of a core network (“CN”) node according to some embodiments;

[0017] Figure 8 is a block diagram illustrating an example of an authentication server function (“AUSF”) node according to some embodiments;

[0018] Figure 9 is a block diagram illustrating an example of a unified data management (“UDM”) node according to some embodiments;

[0019] Figures 10-11 is a flow diagram illustrating an example of a process performed by a first network node (e.g., an AUSF node) according to some embodiments; and

[0020] Figures 12-13 is a flow diagram illustrating an example of a process performed by a second network node (e.g., a UDM node) according to some embodiments. DETAILED DESCRIPTION

[0021] The present inventive concepts will now be described more fully with reference to the accompanying drawings, in which examples of embodiments of the present inventive concepts are shown. The present inventive concepts may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the present inventive concepts to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment can be assumed by default to be present / used in another embodiment.

[0022] Figure 2 An example of an alternative authentication procedure is illustrated. In this example, an Extensible Authentication Protocol Transport Layer Security (“EAP-TLS”) authentication procedure is shown for initial authentication with a 5G network. Similarly, other EAP methods can be supported.

[0023] In 5G systems, subscriber privacy is significantly improved, for example, by the introduction of a Subscription Concealed Identifier (“SUCI”), which is intended to be used in initial access to a 5G system. The SUCI protects a Subscription Permanent Identifier (“SUPI”) (e.g., from being exposed over the air). The SUCI includes a concealed SUPI by encrypting the SUPI using a public key (e.g., a home network public key) and a protection scheme that is securely provided in a Universal Subscriber Identity Module (“USIM”) under control of the home network.

[0024] Blocks 205, 210, 215, and 220 can be part of an initial registration procedure of the UE 202 with a network including the SEAF 204, the AUSF 206, and the UDM 208. At block 205, the UE 202 sends a registration request including a SUCI to the SEAF 204. At block 210, the SEAF 204 sends an authentication request (e.g., Nausf_UEAuthentication_AuthenticateRequest (SUCI, SN Name)) to the AUSF 206. At block 215, the AUSF 206 sends an authentication request (e.g., Nudm_UEAuthenticate_Get Request (SUCI, SN Name)) to the UDM 208. At block 220, the UDM 208 performs an authentication method selection. In this example, the UDM 208 selects an EAP-TLS procedure for authenticating the UE 202.

[0025] At block 225, the UDM 208 sends an authentication response (e.g., Nudm_UEAuthentication_Get Response (SUPI, Indicator (EAP-TLS))) to the AUSF 206.

[0026] Blocks 230, 235, 240, 245, 250, 255, 260, 265, 270, 275, 280, 285, 290, 292, 294, and 296 illustrate an example of an EAP-TLS authentication procedure. At block 230, the AUSF 206 sends an authentication response to the SEAF 204 (e.g., Nausf_UEAuthentication_Authenticate Response (EAP Request / EAP Type = EAP-TLS (TLS Start))). At block 235, the SEAF 204 sends an authentication request to the UE 202 (e.g., Auth-Req. (EAP Request / EAP Type = EAP-TLS (TLS Start), ngKSI, ABBA)). At block 240, the UE 202 sends an authentication response to the SEAF 204 (e.g., Auth-Resp. (EAP Response / EAP Type = EAP-TLS (TLS client_hello))). At block 245, the SEAF 204 sends an authentication request to the AUSF 206 (e.g., Nausf_UEAuthentication_Authenticate Request (EAP Response / EAP Type = EAP-TLS (TLS client_hello))). At block 250, the AUSF 206 sends an authentication response to the SEAF 204 (e.g., Nausf_UEAuthentication_Authenticate Response (EAP Request / EAP Type = EAP-TLS (TLS server_hello, TLS certificate, TLS server_key_exchange, TLS certificate_request, TLS server_hello_done))). At block 255, the SEAF 204 sends an authentication request to the UE 202 (e.g., Auth-Req. (EAP Request / EAP Type = EAP-TLS (TLS server_hello, TLS certificate, TLS server_key_exchange, TLS certificate_request, TLS server_hello_done), ngKSI, ABBA)). At block 260, the UE 202 authenticates the network.

[0027] At block 265, the UE 202 sends an authentication response (e.g., Auth-Resp. (EAP Request / EAP Type = EAP-TLS (TLS certificate, TLS client_key_exchange, TLS certificate_verify, TLS change_cipher_spec, TLS finish))) to the SEAF 204. At block 270, the SEAF 204 forwards the authentication request (e.g., Nausf_UEAuthentication_Authenticate Request (EAP Request / EAP Type = EAP-TLS (TLS certificate, TLS client_key_exchange, TLS certificate_verify, TLS change_cipher_spec, TLS finish))) to the AUSF 206. At block 275, the AUSF 206 authenticates the UE.

[0028] At block 280, the AUSF 206 sends an authentication response (e.g., Nausf_UEAuthentication_Authenticate Response (EAP Response / EAP Type = EAP-TLS (TLS change_cipher_spec, TLS finish))) to the SEAF 204. At block 285, the SEAF 204 sends an authentication request (e.g., Auth-Req. (EAP Request / EAP Type = EAP-TLS (TLS change_cipher_spec, TLS finish), ngKSI, ABBA)) to the UE 202. At block 290, the UE 202 sends an authentication response (e.g., Auth-Resp. (EAP Response / EAP Type = EAP-TLS)) to the SEAF 204. At block 292, the SEAF 204 sends an authentication request (e.g., Nausf_UEAuthentication_Authenticate Request (EAP Response / EAP Type = EAP-TLS)) to the AUSF 206. At block 294, the AUSF 206 sends an authentication response (e.g., Nausf_UEAuthentication_Authenticate Response (EAP Success, AnchorKey, SUPI)) to the SEAF 204. At block 296, the SEAF 204 sends an N1 message (e.g., N1 (EAP Success, ngKSI, ABBA)) to the UE 202.

[0029] The "null scheme" is a dummy scheme that does not conceal the SUPI but provides the SUPI in clear text. By using the "null scheme", a device or UE equipped with a legacy USIM (without the capability to conceal the SUPI) can also access the 5G system but without the need for the capability to conceal the SUPI.

[0030] In addition to the subscription privacy features provided by the 5G system, some authentication methods can support inherent identifier privacy mechanisms. For example, for EAP TLS, subscription identifier privacy is supported inherently in TLS 1.3 or via a separate privacy option in TLS 1.2.

[0031] Attention to subscription identifier protection is needed in both 5G system control signaling and EAP transactions (e.g., blocks 205 and 265 in Figure 2 When EAP TLS is used as the alternative authentication method and the "null scheme" is used for 5G system control signaling (e.g., over NAS), subscription identifier privacy can be ineffective because even though EAP TLS can provide its own privacy protection, the SUCI with the "null scheme" will expose the SUPI in clear text.

[0032] Accordingly, it is proposed in 3GPP that the "null scheme" can be used while still preserving subscription identifier privacy by omitting the username part from the Network Access Identifier ("NAI") of the SUPI or setting the username to "anonymous". This would be similar to using an anonymous identifier in EAP, meaning that only the realm part from the NAI is included in the SUCI. A SUCI constructed in this way can be referred to as an anonymous SUCI.

[0033] However, a fundamental step in the primary authentication procedure is that the Authentication Server Function ("AUSF") node can retrieve the UE's authentication subscription data and de-concealed SUPI from the Unified Data Management ("UDM") node based on the SUCI. With an anonymous SUCI (e.g., a SUCI without a username or with the username set to "anonymous"), it can not be feasible for the UDM to locate the UE's subscription or provide the correct SUPI back to the AUSF. This can result in a failed authentication procedure.

[0034] Various embodiments described herein provide an AUSF node that can map information conveyed over EAP TLS (e.g., a user's credentials or a UE's ID sent over a TLS tunnel such as according to EAP Tunneled Transport Layer Security ("TTLS")) to a second SUCI or SUPI. The AUSF in turn can use the second SUCI or SUPI to retrieve the UE's authentication subscription data and / or the true SUPI from the UDM.

[0035] In some embodiments, mapping information communicated over EAP TLS to a second SUCI or SUPI can enable subscription retrieval when sending an anonymous SUCI over 5G system control signaling.

[0036] Figure 5 is a block diagram illustrating units of a communication device 500 (also referred to as a mobile terminal, mobile communication terminal, wireless device, wireless communication device, wireless terminal, mobile device, wireless communication terminal, user equipment, UE, user equipment node / terminal / device, etc.) configured to provide wireless communication according to embodiments of inventive concepts. (The communication device 500 can be provided.) As shown, the communication device 500 can include an antenna 507 and a transceiver circuit 501 (also referred to as a transceiver) including a transmitter and a receiver configured to provide uplink and downlink radio communications with a base station of a radio access network (also referred to as a RAN node). The communication device 500 can also include a processing circuit 503 (also referred to as a processor) coupled to the transceiver circuit, and a memory circuit 505 (also referred to as a memory) coupled to the processing circuit. The memory circuit 505 can include computer readable program code that, when executed by the processing circuit 503, causes the processing circuit to perform operations according to embodiments disclosed herein. According to other embodiments, the processing circuit 503 can be defined to include the memory such that a separate memory circuit is not needed. The communication device 500 can also include an interface (such as a user interface) coupled to the processing circuit 503, and / or the communication device UE can be incorporated into a vehicle.

[0037] As discussed herein, operations of the communication device 500 can be performed by the processing circuit 503 and / or the transceiver circuit 501. For example, the processing circuit 503 can control the transceiver circuit 501 to transmit communications over a radio interface to a radio access network node (also referred to as a base station) by the transceiver circuit 501 and / or to receive communications over the radio interface from the RAN node by the transceiver circuit 501. Moreover, modules can be stored in the memory circuit 505, and these modules can provide instructions to cause the processing circuit 503 to perform respective operations when the instructions of the modules are executed by the processing circuit 503.

[0038] Figure 6is a block diagram illustrating elements of a radio access network ("RAN") node 600 (also referred to as a network node, base station, eNodeB / eNB, gNodeB / gNB, etc.) configured to provide cellular communications according to embodiments of inventive concepts. (The RAN node 600 can be provided.) As shown, the RAN node 600 can include transceiver circuitry 601 (also referred to as a transceiver) including a transmitter and a receiver configured to provide uplink and downlink wireless communications with mobile terminals. The RAN node 600 can include network interface circuitry 607 (also referred to as a network interface) configured to provide communications with other nodes of the RAN and / or core network CN (e.g., with other base stations). The RAN node 600 can also include processing circuitry 603 (also referred to as a processor) coupled to the transceiver circuitry, and memory circuitry 605 (also referred to as a memory) coupled to the processing circuitry. The memory circuitry 605 can include computer readable program code that, when executed by the processing circuitry 603, causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, the processing circuitry 603 can be defined to include the memory such that a separate memory circuitry is not needed.

[0039] As discussed herein, the operations of the RAN node 600 can be performed by the processing circuitry 603, the network interface 607, and / or the transceiver 601. For example, the processing circuitry 603 can control the transceiver 601 to transmit downlink communications to one or more mobile terminals UEs over a radio interface via the transceiver 601 and / or to receive uplink communications from one or more mobile terminals UEs over a radio interface via the transceiver 601. Similarly, the processing circuitry 603 can control the network interface 607 to transmit communications to and / or receive communications from one or more other network nodes via the network interface 607. Moreover, modules can be stored in the memory 605, and these modules can provide instructions so that when the instructions of the modules are executed by the processing circuitry 603, the processing circuitry 603 performs corresponding operations (e.g., operations discussed below with respect to example embodiments related to network nodes).

[0040] According to some other embodiments, a network node can be implemented as a core network CN node without a transceiver. In such embodiments, transmissions to wireless communication devices UEs can be initiated by the network node such that the transmissions to wireless communication devices UEs are provided by a network node that includes a transceiver (e.g., by a base station or RAN node). According to embodiments in which the network node is a RAN node that includes a transceiver, initiating transmissions can include transmitting via the transceiver.

[0041] Figure 7is a block diagram illustrating elements of a core network ("CN") node 700 (e.g., an SMF node, an AMF node, an AUSF node, a UDM node, etc.) of a communication network configured to provide cellular communications according to embodiments of the inventive concepts. As shown, the CN node 700 can include network interface circuitry 707 (also referred to as a network interface) configured to provide communications with other nodes of the core network and / or RAN. The CN node 700 can also include processing circuitry 703 (also referred to as a processor) coupled to the network interface circuitry, as well as memory circuitry 705 (also referred to as a memory) coupled to the processing circuitry. The memory circuitry 705 can include computer-readable program code that, when executed by the processing circuitry 703, causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, the processing circuitry 703 can be defined to include the memory, such that a separate memory circuitry is not needed.

[0042] As discussed herein, the operations of the CN node 700 can be performed by the processing circuitry 703 and / or the network interface circuitry 707. For example, the processing circuitry 703 can control the network interface circuitry 707 to transmit communications through the network interface circuitry 707 to one or more other network nodes and / or to receive communications through the network interface circuitry from one or more other network nodes. Moreover, modules can be stored in the memory 705, and these modules can provide instructions to cause the processing circuitry 703 to perform respective operations when the instructions of the modules are executed by the processing circuitry 703.

[0043] Figure 8 is a block diagram illustrating elements of an authentication server function ("AUSF") node 800 of a communication network configured to provide cellular communications according to embodiments of the inventive concepts. As shown, the AUSF node 800 can include network interface circuitry 807 (also referred to as a network interface) configured to provide communications with other nodes of the core network and / or RAN. The AUSF node 800 can also include processing circuitry 803 (also referred to as a processor) coupled to the network interface circuitry, as well as memory circuitry 805 (also referred to as a memory) coupled to the processing circuitry. The memory circuitry 805 can include computer-readable program code that, when executed by the processing circuitry 803, causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, the processing circuitry 803 can be defined to include the memory, such that a separate memory circuitry is not needed.

[0044] As discussed herein, the operations of the AUSF node 800 can be performed by the processing circuitry 803 and / or the network interface circuitry 807. For example, the processing circuitry 803 can control the network interface circuitry 807 to transmit communications through the network interface circuitry 807 to one or more other network nodes and / or to receive communications through the network interface circuitry from one or more other network nodes. Also, modules can be stored in the memory 805, and these modules can provide instructions so that when the instructions of the modules are executed by the processing circuitry 803, the processing circuitry 803 performs corresponding operations.

[0045] Figure 9 is a block diagram illustrating elements of a Unified Data Management (“UDM”) node 900 configured to provide cellular communications according to embodiments of the inventive concepts. As shown, the UDM node 900 can include network interface circuitry 907 (also referred to as a network interface) configured to provide communications with other nodes of a core network and / or RAN. The UDM node 900 can also include processing circuitry 903 (also referred to as a processor) coupled to the network interface circuitry, as well as memory circuitry 905 (also referred to as a memory) coupled to the processing circuitry. The memory circuitry 905 can include computer-readable program code that, when executed by the processing circuitry 903, causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, the processing circuitry 903 can be defined to include the memory, such that a separate memory circuitry is not needed.

[0046] As discussed herein, the operations of the UDM node 900 can be performed by the processing circuitry 903 and / or the network interface circuitry 907. For example, the processing circuitry 903 can control the network interface circuitry 907 to transmit communications through the network interface circuitry 907 to one or more other network nodes and / or to receive communications through the network interface circuitry from one or more other network nodes. Also, modules can be stored in the memory 905, and these modules can provide instructions so that when the instructions of the modules are executed by the processing circuitry 903, the processing circuitry 903 performs corresponding operations.

[0047] Although Figures 8-9 While separate AUSF node 800 and UDM node 900 are illustrated, in some embodiments, a CN node can include both an AUSF layer and a UDM layer, which share one or more components including processing circuitry, memory, and network interface.

[0048] Figures 3-4 Two different procedures for subscription retrieval for anonymous ID are illustrated. Figures 3-4 Both include blocks 305, 310, 335, 340, 345, 350, 355, 360, and 365. Figure 3including blocks 315, 320, and 325, which illustrate a procedure in which the AUSF 206 sends the SUCI to the UDM 208 (e.g., the UDM node 900) (the UDM 208 determines that the SUCI includes an anonymous ID, generates a dummy SUPI, and sends the dummy SUPI to the AUSF 206). Figure 4 including block 430, which illustrates a procedure in which the AUSF 206 (e.g., the AUSF node 800 in Figure 8 determines that the SUCI includes an anonymous ID.

[0049] At block 305, the UE 202 triggers an initial registration procedure to the 5G system and sends an anonymous SUCI as a subscriber identifier. The UE 202 can be a 3GPP UE or an N5GC. If the UE 202 is an N5GC, the authentication request can arrive at the SEAF 204 from a wireline access network via intermediate nodes such as a residential gateway (“RG”) and a wireline access gateway function (“W-AGF”). In some examples, the anonymous SUCI can be generated by the W-AGF on behalf of the N5GC.

[0050] At block 310, the SEAF 204 (or an authentication management function (“AMF”) node) selects the AUSF 206 based on a home network identifier of the SUCI in the received registration request and sends an authentication request message (e.g., a Nausf_UEAuthentication_Authenticate Request message) to the AUSF 206 to trigger an authentication procedure. In some examples, if the UE is an N5GC, the authentication request message can also include an indicator that the request is on behalf of an N5GC device.

[0051] At block 315, the AUSF 206 sends an authentication request (e.g., a Nudm_UEAuthentication_Get Request) to the UDM 208 to request authentication subscription data and a de- hidden SUPI for the UE 202. The authentication request can include the anonymous SUCI for an N5GC device or a 3GPP UE.

[0052] At block 320, the UDM 208 invokes a subscriber identity de-hiding function (“SIDF”) to map the anonymous SUCI to a SUPI and determine that it is an anonymous SUCI. The UDM 208 generates a dummy SUPI and selects a default authentication method (e.g., EAP-TLS) for the dummy SUPI.

[0053] At block 325, the UDM 208 sends an authentication response (e.g., Nudm_UEAuthentication_Get Response) to the AUSF 206 that includes the virtual SUPI and / or an indicator of the virtual authentication subscription.

[0054] Instead of blocks 315, 320, and 325, Figure 4 Block 430 is included. At block 430, the AUSF 206 determines, on its own, that the received SUCI is an anonymous SUCI based on the information received from the SEAF 204 in block 310. For example, the AUSF 206 can detect the N5GC indicator in the information received from the SEAF 204. In some embodiments, the procedure can include some of blocks 315, 320, 325, and 430 such that the AUSF 206 determines that the received SUCI is an anonymous SUCI based on the information received from the UDM 208. For example, the AUSF 206 can receive an error code from the UDM 208 in block 325. The AUSF 206 can in turn select a default authentication method (e.g., EAP-TLS) for anonymous SUCIs based on a mobile network operator (“MNO”) policy.

[0055] At block 335, the authentication procedure continues (e.g., as shown in the EAP TLS flow in Figure 2

[0056] At block 340, once the AUSF 206 receives the UE identifier information (e.g., a client certificate or an identifier sent through the TLS tunnel), the AUSF 206 generates a 3GPP identifier based on the UE identifier information used during the EAP authentication method. Depending on whether the UE identifier information is a 3GPP permanent identifier (e.g., SUPI) or an identifier that can be used as a pseudonym ID for a 3GPP subscription, the AUSF uses the empty scheme or the SUPI to construct a second SUCI. For example, the second SUCI or SUPI can include an identifier that is part of or mapped from a client certificate or a username sent through the TLS tunnel.

[0057] At block 345, the AUSF 206 sends an authentication request (e.g., Nudm_UEAuthentication_Get Request) to the UDM 208 to request authentication subscription data and / or a de- hidden SUPI for the UE 202. The authentication request includes the second SUCI or SUPI and, optionally, an indicator indicating that a default authentication method (e.g., EAP TLS) has been performed for the UE 202.

[0058] ​At box 350, if a second SUCI is received, UDM 208 invokes SIDF to map the second SUCI to a SUPI. UDM 208 then selects an authentication method (e.g., EAP-TLS) based on the subscription data corresponding to that SUPI (mapped from the second SUCI or received from AUSF 206). Considering the indicator indicating that a default authentication method (e.g., EAP-TLS) has been performed for UE 202, UDM 208 can select the actual authentication method for the SUPI.

[0059] At box 355, UDM 208 sends an authentication response (e.g., Nudm_UEAuthentication_Get Response) to AUSF 206, which includes SUPI and an indicator of the selected authentication method (e.g., EAP-TLS).

[0060] At box 360, AUSF 206 verifies that the information received from UDM 208 and the authentication method actually selected by UDM 208 match the authentication method performed in the previous operation.

[0061] If UDM 208 selects a different authentication method, AUSF 206 can close the existing authentication transaction and trigger a new authentication process based on the actual authentication method selected. Otherwise, at box 365, the remainder of the authentication process continues (e.g., Figure 2 (The remainder of the EAP TLS process is shown). In some examples, AUSF 206 sends the authentication result and / or the actual SUPI back to SEAF 204.

[0062] Reference will now be made to some embodiments based on the concept of the present invention. Figures 10-11 The flowchart is used to discuss the operation of AUSF nodes. Figures 10-11 This will be described below as being executed by AUSF node 800 (using...) Figure 8 (This is implemented using a block diagram structure). For example, modules can be stored in... Figure 8 The memory 805 contains these modules, and these modules can provide instructions such that when the instructions of the modules are executed by the corresponding AUSF processing circuit 803, the processing circuit 803 performs the corresponding operation of the flowchart. However, Figures 10-11 The operations within can be performed by any suitable network node.

[0063] Figure 10 The illustration shows an example of the process by which a first network node generates second subscriber information (without an anonymous identifier) ​​when the first subscriber information includes an anonymous identifier.

[0064] At block 1010, processing circuitry 803 receives, via network interface 807, an authentication request associated with a communication device including first subscriber information. In some embodiments, the authentication request is part of a request by the communication device to register with a telecommunication network, which is a 5G network. In additional or alternative embodiments, the first subscriber information includes a subscriber concealed identifier, SUCI. In additional or alternative embodiments, the authentication request further includes an indicator indicating that the communication device is an N5GC device.

[0065] At block 1020, processing circuitry 803 sends, via network interface 807, a first message including the first subscriber information to a second network node. In some embodiments, the second network node is a UDM node (e.g., UDM node 900 in Figure 9 .

[0066] At block 1030, processing circuitry 803 receives, via network interface 807, a second message from the second network node. In some embodiments, the second message includes an indicator indicating that the first subscriber information includes an anonymous identifier. In additional or alternative embodiments, the second message includes an indicator indicating an authentication procedure to be performed.

[0067] At block 1040, processing circuitry 803 determines that the first subscriber information includes an anonymous identifier. In some embodiments, processing circuitry 803 determines that the first subscriber information includes an anonymous identifier based on the indicator in the second message. In additional or alternative embodiments, processing circuitry 803 determines that the first subscriber information includes an anonymous identifier based on the authentication request including an indicator indicating that the communication device is an N5GC device.

[0068] At block 1050, processing circuitry 803 determines an authentication procedure to be performed. In some embodiments, the authentication procedure is a predetermined or default authentication procedure selected in response to the first subscriber information including an anonymous identifier. In additional or alternative embodiments, the authentication procedure includes EAP-TLS.

[0069] At block 1060, processing circuitry 803 receives, via network interface 807, information associated with the communication device as part of the authentication procedure.

[0070] At block 1070, processing circuitry 803 generates second subscriber information based on the information associated with the communication device. In some embodiments, the second subscriber information includes a SUCI or a SUPI.

[0071] Figure 11 FIGURE 13 illustrates an example of additional procedures performed by a first network node to verify authentication subscription data associated with second subscriber information.

[0072] At frame 1175, the processing circuit 803 sends a third message, including second subscriber information, to the second network node via the network interface 807.

[0073] At block 1180, processing circuitry 803 receives a fourth message, including authentication subscription data associated with the communication device, from a second network node via network interface 807.

[0074] At block 1190, processing circuitry 803 verifies the authenticated subscription data. In some embodiments, the fourth message includes a second authentication process associated with the authenticated subscription data. If the second authentication process differs from a predetermined / default authentication process, processing circuitry 803 may execute the second authentication process and regenerate the second subscriber information based on information received as part of the second authentication process. In additional or alternative embodiments, verifying the authenticated subscription data may include determining that third subscriber information associated with the authenticated subscription data matches the second subscriber information.

[0075] Figures 10-11 Various operations may be optional in some embodiments of the communication device and related methods. For example, regarding the method of Example Embodiment 1 below, Figure 10 The frames 1020, 1030, 1050, and 1060, and Figure 11 The operations in boxes 1175, 1180, and 1190 can be optional.

[0076] Reference will now be made to some embodiments based on the concept of the present invention. Figures 12-13 The flowchart is used to discuss the operation of UDM nodes. Figures 12-13 This will be described below as being executed by UDM node 900 (using...) Figure 9 (This is implemented using a block diagram structure). For example, modules can be stored in... Figure 9 The memory 905 contains these modules, and these modules can provide instructions such that when the instructions of the modules are executed by the corresponding UDM processing circuit 903, the processing circuit 903 performs the corresponding operation of the flowchart. However, Figures 12-13 The operation can be performed by any suitable network node.

[0077] Figure 12 The illustration shows an example of the process performed by a second network node to obtain and verify second subscriber information (without an anonymous identifier) ​​when the first subscriber information includes an anonymous identifier.

[0078] At block 1210, processing circuitry 903 receives, via network interface 907, an authentication request associated with a communication device including first subscriber information. In some embodiments, the authentication request is part of a request by the communication device to register with a telecommunication network, which is a 5G network. In additional or alternative embodiments, the first subscriber information includes a subscriber concealed identifier, SUCI. In additional or alternative embodiments, the authentication request further includes an indicator indicating that the communication device is a N5GC device.

[0079] At block 1220, processing circuitry 903 determines that the first subscriber information includes an anonymous identifier. In some embodiments, determining that the first subscriber information includes an anonymous identifier includes attempting to de-conceal the first subscriber information. In additional or alternative embodiments, determining that the first subscriber information includes an anonymous identifier includes detecting an indicator indicating that the communication device is a N5GC device.

[0080] At block 1230, processing circuitry 903 determines an authentication procedure to perform. In some embodiments, the authentication procedure is a predetermined or default authentication procedure selected in response to the first subscriber information including an anonymous identifier. In additional or alternative embodiments, the authentication procedure includes EAP-TLS.

[0081] At block 1240, processing circuitry 903 sends, via network interface 907, an authentication response including an indicator indicating the authentication procedure and an indicator indicating that the first subscriber information includes an anonymous identifier. In some embodiments, the indicator indicating that the first user information includes an anonymous identifier can include virtual subscriber information.

[0082] At block 1250, processing circuitry 903 receives, via network interface 907, a second authentication request associated with the communication device including second subscriber information. In some embodiments, the second authentication request can further include an indicator indicating that the authentication procedure has been performed.

[0083] At block 1270, processing circuitry 903 determines a second authentication procedure associated with the second subscriber information.

[0084] At block 1280, processing circuitry 903 sends, via network interface 907, a second authentication response including an indicator indicating the second authentication procedure.

[0085] Figure 13 Figure illustrates an example of additional operations performed by the second network node in response to the second subscriber information including a concealed identifier (e.g., SUCI). At block 1360, processing circuitry 903 determines a de-concealed version of the second subscriber information, e.g., SUPI. At block 1380, processing circuitry 903 sends, via network interface 907, a second authentication response including the de-concealed version of the second subscriber information.

[0086] Figures 12-13 Various operations may be optional in some embodiments of the communication device and related methods. For example, regarding the method of Example Embodiment 9 below, Figure 12 The frames 1250, 1270, and 1280 and Figure 13 The operations in boxes 1360 and 1380 can be optional.

[0087] Example embodiments are included below.

[0088] Example 1. A method for operating a first network node in a telecommunications network, the method comprising:

[0089] Receive (1010) an authentication request associated with a communication device requesting to register with the telecommunications network, the authentication request including first subscriber information;

[0090] It is determined (1040) that the first subscriber information includes an anonymous identifier;

[0091] In response to determining that the first subscriber information includes an anonymous identifier, determine (1050) the authentication process to be performed;

[0092] In response to determining the authentication process to be performed, information associated with the communication device is received (1060) as part of the authentication process; and

[0093] Based on the information associated with the communication device, (1070) second subscriber information is generated.

[0094] Example 2. According to the method described in Example 1, wherein the first network node is an Authentication Server Function (AUSF) node, and

[0095] The telecommunications network in question is a 5G network.

[0096] Example 3. The method according to any one of Examples 1-2, wherein the first subscriber information includes a first subscriber hidden identifier SUCI.

[0097] The second subscriber information includes the second SUCI or subscription perpetual identifier SUPI.

[0098] Example 4. The method according to any one of Examples 1-3, wherein the authentication request further includes an indicator indicating that the communication device does not support 5G N5GC devices, and

[0099] Specifically, determining that the first subscriber information includes an anonymous identifier includes: determining that the first subscriber information includes an anonymous identifier based on the authentication request including an indicator indicating that the communication device is an N5GC device.

[0100] Example 5. The method of any of Examples 1-4, further comprising:

[0101] in response to receiving the authentication request, sending (1020) a first message to the second network node, the first message comprising the first subscriber information; and

[0102] in response to sending the first message to the second network node, receiving (1030) a second message from the second network node, the second message comprising a first indicator indicating that the first subscriber information comprises an anonymous identifier and a second indicator indicating the authentication, and

[0103] wherein determining that the first subscriber information comprises an anonymous identifier comprises determining, based on the first indicator, that the first subscriber information comprises an anonymous identifier, and

[0104] wherein determining the authentication procedure to be performed comprises determining, based on the second indicator, the authentication procedure to be performed.

[0105] Example 6. The method of any of Examples 1-5, further comprising:

[0106] in response to generating the second subscriber information, sending (1175) a third message to the second network node, the third message comprising the second subscriber information and an indicator indicating that the authentication method has been performed; and

[0107] in response to sending the third message, receiving (1180) a fourth message from the second network node, the fourth message comprising authentication subscription data associated with the communication device; and

[0108] in response to receiving the fourth message, verifying (1190) the authentication subscription data.

[0109] Example 7. The method of Example 6, wherein the fourth message further comprises a second authentication procedure associated with the authentication subscription data,

[0110] wherein verifying the authentication subscription data comprises:

[0111] determining that third subscriber information associated with the authentication subscription data matches the second subscriber information; and

[0112] determining that the second authentication procedure matches the authentication procedure.

[0113] Example 8. The method of any of Examples 5-7, wherein the second network node is a unified data management, UDM, node.

[0114] Embodiment 9. The method of any one of claims 1-8, wherein the authentication procedure comprises at least one of: Extensible Authentication Protocol, EAP, Transport Layer Security, TLS, and EAP Tunneled Transport Layer Security, TTLS,

[0115] wherein the information comprises at least one of: a client certificate, and a username, and

[0116] wherein receiving the information associated with the communication device as part of the authentication procedure comprises at least one of:

[0117] receiving a client certificate via the EAP-TLS; and

[0118] receiving a username via the EAP-TTLS.

[0119] Embodiment 10. A method of operating a second network node in a telecommunication network, the method comprising:

[0120] receiving (1210), from a first network node, an authentication request associated with a communication device requesting registration with the telecommunication network, the authentication request comprising first subscriber information;

[0121] in response to receiving the authentication request, determining (1220) that the first subscriber information comprises an anonymous identifier;

[0122] in response to determining that the first subscriber information comprises an anonymous identifier, determining (1230) an authentication procedure to be performed; and

[0123] in response to determining the authentication procedure to be performed, sending (1240), to the first network node, an authentication response comprising an indicator indicating the authentication procedure and an indicator indicating that the subscriber information comprises an anonymous identifier.

[0124] Embodiment 11. The method of embodiment 10, further comprising:

[0125] in response to sending the authentication response, receiving (1250) a second authentication request associated with the communication device requesting registration with the telecommunication network, the second authentication request comprising second subscriber information and an indicator indicating that the authentication procedure has been performed;

[0126] in response to receiving the second authentication request, determining (1270) a second authentication procedure associated with the second subscriber information; and

[0127] in response to determining the second authentication procedure, sending (1280), to the first network node, a second authentication response comprising an indicator indicating the second authentication procedure.

[0128] Embodiment 12. The method of embodiment 11, wherein the first subscriber information comprises a first subscriber concealed identifier, SUCI,

[0129] wherein the second subscriber information comprises a second SUCI or a subscription permanent identifier, SUPI.

[0130] Embodiment 13. The method of embodiment 12, wherein the second subscriber information comprises a second SUCI,

[0131] The method further comprises, in response to receiving the second authentication request, determining (1360) the SUPI based on the SUCI using a subscriber identity de-concealing function, SIDF, and

[0132] wherein the second authentication response further comprises the SUPI.

[0133] Embodiment 14. The method of any of embodiments 10-13, wherein the second network node is a unified data management, UDM, node,

[0134] wherein the first network node is an authentication server function, AUSF, node, and

[0135] wherein the telecommunication network is a 5thgeneration, 5G, network.

[0136] Embodiment 15. A first network node (700, 800) operating in a telecommunication network, the first network node comprising:

[0137] processing circuitry (703, 803);

[0138] a memory (705, 805) coupled to the processing circuitry and having instructions stored therein that are executable by the processing circuitry to cause the first network node to perform operations comprising:

[0139] receiving (1010) an authentication request associated with a communication device requesting to register with the telecommunication network, the authentication request comprising first subscriber information;

[0140] determining (1040) that the first subscriber information comprises an anonymous identifier;

[0141] in response to determining that the first subscriber information comprises an anonymous identifier, determining (1050) an authentication procedure to be performed;

[0142] in response to determining the authentication procedure to be performed, receiving (1060) information associated with the communication device as part of the authentication procedure; and

[0143] generating (1070) second subscriber information based on the information associated with the communication device.

[0144] Embodiment 16. The first network node of embodiment 15, wherein the first network node is an Authentication Server Function, AUSF, node, and

[0145] wherein the telecommunication network is a 5th Generation, 5G, network.

[0146] Embodiment 17. The first network node of any of embodiments 15-16, wherein the first subscriber information comprises a first Subscriber Concealed Identifier, SUCI,

[0147] wherein the second subscriber information comprises a second SUCI or a Subscription Permanent Identifier, SUPI.

[0148] Embodiment 18. The first network node of any of embodiments 15-17, wherein the authentication request further comprises an indicator indicating that the communication device is a non-5G N5GC device, and

[0149] wherein determining that the first subscriber information comprises an anonymous identifier comprises determining that the first subscriber information comprises an anonymous identifier based on the authentication request comprising the indicator indicating that the communication device is a N5GC device.

[0150] Embodiment 19. The first network node of any of embodiments 15-18, the operations further comprising:

[0151] in response to receiving the authentication request, sending (1020) a first message to a second network node, the first message comprising the first subscriber information; and

[0152] in response to sending the first message to the second network node, receiving (1030) a second message from the second network node, the second message comprising a first indicator indicating that the first subscriber information comprises an anonymous identifier and a second indicator indicating the authentication, and

[0153] wherein determining that the first subscriber information comprises an anonymous identifier comprises determining that the first subscriber information comprises an anonymous identifier based on the first indicator, and

[0154] wherein determining the authentication procedure to be performed comprises determining the authentication procedure to be performed based on the second indicator.

[0155] Embodiment 20. The first network node of any of embodiments 15-19, the operations further comprising:

[0156] in response to generating the second subscriber information, sending (1175) a third message to the second network node, the third message comprising the second subscriber information and an indicator indicating that the authentication method has been performed; and

[0157] receiving (1180), from the second network node, a fourth message in response to sending the third message, the fourth message comprising authentication subscription data associated with the communication device; and

[0158] verifying (1190) the authentication subscription data in response to receiving the fourth message.

[0159] Embodiment 21. The first network node of embodiment 20, wherein the fourth message further comprises a second authentication procedure associated with the authentication subscription data,

[0160] wherein verifying the authentication subscription data comprises:

[0161] determining that third subscriber information associated with the authentication subscription data matches the second subscriber information; and

[0162] determining that the second authentication procedure matches the authentication procedure.

[0163] Embodiment 22. The first network node of any of embodiments 19-21, wherein the second network node is a unified data management, UDM, node.

[0164] Embodiment 23. The first network node of any of claims 15-22, wherein the authentication procedure comprises at least one of: an Extensible Authentication Protocol, EAP, Transport Layer Security, TLS, and an EAP Tunneled Transport Layer Security, TTLS,

[0165] wherein the information comprises at least one of: a client certificate, and a username, and

[0166] wherein receiving the information associated with the communication device as part of the authentication procedure comprises at least one of:

[0167] receiving a client certificate via the EAP-TLS; and

[0168] receiving a username via the EAP-TTLS.

[0169] Embodiment 24. A first network node (700, 800) operative in a telecommunication network, the first network node adapted to perform operations comprising:

[0170] receiving (1010) an authentication request associated with a communication device requesting to register with the telecommunication network, the authentication request comprising first subscriber information;

[0171] determining (1040) that the first subscriber information comprises an anonymous identifier;

[0172] determining (1050) an authentication procedure to be performed in response to determining that the first subscriber information comprises an anonymous identifier;

[0173] receiving (1060) information associated with the communication device as part of the authentication procedure in response to determining the authentication procedure to be performed; and

[0174] generating (1070) second subscriber information based on the information associated with the communication device.

[0175] Embodiment 25. The first network node of embodiment 24, the operations further comprising any of the operations of embodiments 2-9.

[0176] Embodiment 26. A computer program comprising program code to be executed by a processing circuit (703, 803) of a first network node (700, 800) operating in a telecommunication network, whereby execution of the program code causes the first network node to perform operations comprising:

[0177] receiving (1010) an authentication request associated with a communication device requesting to register with the telecommunication network, the authentication request comprising first subscriber information;

[0178] determining (1040) that the first subscriber information comprises an anonymous identifier;

[0179] determining (1050) an authentication procedure to be performed in response to determining that the first subscriber information comprises an anonymous identifier;

[0180] receiving (1060) information associated with the communication device as part of the authentication procedure in response to determining the authentication procedure to be performed; and

[0181] generating (1070) second subscriber information based on the information associated with the communication device.

[0182] Embodiment 27. The computer program of embodiment 26, the operations further comprising any of the operations of embodiments 2-9.

[0183] Embodiment 28. A computer program product comprising a non-transitory storage medium (705, 805) comprising program code to be executed by a processing circuit (703, 803) of a first network node (700, 800) operating in a telecommunication network, whereby execution of the program code causes the first network node to perform operations comprising:

[0184] receiving (1010) an authentication request associated with a communication device requesting to register with the telecommunication network, the authentication request comprising first subscriber information;

[0185] determining (1040) that the first subscriber information comprises an anonymous identifier;

[0186] in response to determining that the first subscriber information comprises an anonymous identifier, determining (1050) an authentication procedure to be performed;

[0187] in response to determining the authentication procedure to be performed, receiving (1060) information associated with the communication device as part of the authentication procedure; and

[0188] based on the information associated with the communication device, generating (1070) second subscriber information.

[0189] Embodiment 29. The computer program product of embodiment 26, the operations further according to any of the operations of embodiments 2-9.

[0190] Embodiment 30. A second network node (700, 900) operative in a telecommunication network, the second network node comprising:

[0191] processing circuitry (703, 903);

[0192] memory (705, 905) coupled to the processing circuitry and having instructions stored therein executable by the processing circuitry to cause the second network node to perform operations comprising:

[0193] receiving (1210), from a first network node, an authentication request associated with a communication device requesting registration with the telecommunication network, the authentication request comprising first subscriber information;

[0194] in response to receiving the authentication request, determining (1220) that the first subscriber information comprises an anonymous identifier;

[0195] in response to determining that the first subscriber information comprises an anonymous identifier, determining (1230) an authentication procedure to be performed; and

[0196] in response to determining the authentication procedure to be performed, sending (1240), to the first network node, an authentication response comprising an indicator indicating the authentication procedure and an indicator indicating that the subscriber information comprises an anonymous identifier.

[0197] Embodiment 31. The second network node of embodiment 30, the operations further comprising:

[0198] in response to sending the authentication response, receiving (1250) a second authentication request associated with the communication device requesting registration with the telecommunication network, the second authentication request comprising second subscriber information and an indicator indicating that the authentication procedure has been performed;

[0199] In response to receiving the second authentication request, determining (1270) a second authentication procedure associated with the second subscriber information; and

[0200] In response to determining the second authentication procedure, sending (1280) a second authentication response to the first network node, the second authentication response including an indicator indicating the second authentication procedure.

[0201] Embodiment 32. The second network node of Embodiment 31, wherein the first subscriber information comprises a first subscriber concealed identifier, SUCI,

[0202] wherein the second subscriber information comprises a second SUCI or a subscription permanent identifier, SUPI.

[0203] Embodiment 33. The second network node of Embodiment 32, wherein the second subscriber information comprises a second SUCI,

[0204] The operations further comprise, in response to receiving the second authentication request, determining (1360) the SUPI based on the SUCI using a subscriber identity de-concealing function, SIDF, and

[0205] wherein the second authentication response further comprises the SUPI.

[0206] Embodiment 34. The second network node of any of Embodiments 30-33, wherein the second network node is a unified data management, UDM, node,

[0207] wherein the first network node is an authentication server function, AUSF, node, and

[0208] wherein the telecommunication network is a 5thGeneration, 5G, network.

[0209] Embodiment 35. A second network node (700, 900) operative in a telecommunication network, the second network node adapted to perform operations comprising:

[0210] receiving (1210) an authentication request from a first network node associated with a communication device requesting registration with the telecommunication network, the authentication request including first subscriber information;

[0211] In response to receiving the authentication request, determining (1220) that the first subscriber information comprises an anonymous identifier;

[0212] In response to determining that the first subscriber information comprises an anonymous identifier, determining (1230) an authentication procedure to perform; and

[0213] in response to determining the authentication procedure to be performed, sending (1240) an authentication response to the first network node, the authentication response comprising an indicator indicative of the authentication procedure and an indicator indicative of the subscriber information comprising an anonymous identifier.

[0214] Embodiment 36. The second network node of embodiment 33, the operations further comprising any of the operations of embodiments 11-14.

[0215] Embodiment 37. A computer program comprising program code to be executed by a processing circuit (703, 903) of a second network node (700, 900) operating in a telecommunication network, whereby execution of the program code causes the second network node to perform operations comprising:

[0216] receiving (1210), from a first network node, an authentication request associated with a communication device requesting registration with the telecommunication network, the authentication request comprising first subscriber information;

[0217] in response to receiving the authentication request, determining (1220) that the first subscriber information comprises an anonymous identifier;

[0218] in response to determining that the first subscriber information comprises an anonymous identifier, determining (1230) an authentication procedure to be performed; and

[0219] in response to determining the authentication procedure to be performed, sending (1240) an authentication response to the first network node, the authentication response comprising an indicator indicative of the authentication procedure and an indicator indicative of the subscriber information comprising an anonymous identifier.

[0220] Embodiment 38. The computer program of embodiment 37, the operations further comprising any of the operations of embodiments 11-14.

[0221] Embodiment 39. A computer program product comprising a non-transitory storage medium (705, 905) comprising program code to be executed by a processing circuit (703, 903) of a second network node (700, 900) operating in a telecommunication network, whereby execution of the program code causes the second network node to perform operations comprising:

[0222] receiving (1210), from a first network node, an authentication request associated with a communication device requesting registration with the telecommunication network, the authentication request comprising first subscriber information;

[0223] in response to receiving the authentication request, determining (1220) that the first subscriber information comprises an anonymous identifier;

[0224] In response to determining that the first subscriber information includes an anonymous identifier, determine (1230) the authentication process to be performed; and

[0225] In response to determining the authentication process to be performed, an authentication response (1240) is sent to the first network node, the authentication response including an indicator indicating the authentication process and an indicator indicating that the subscriber information includes an anonymous identifier.

[0226] Example 40. The computer program product according to Example 39, wherein these operations further include any operations according to Examples 11-14.

[0227] Additional references are included below.

[0228] "Security architecture and processes for 5G systems", 3GPP 33.501 16.2.0.

[0229] "EAP-TLS Authentication Protocol", IETF RFC 5216.

[0230] Additional notes are provided below.

[0231] Generally, all terms used herein should be interpreted according to their ordinary meaning in the relevant art, unless a different meaning is explicitly given and / or implied from the context of their use. Unless explicitly stated otherwise, all references to "a / an / element, device, component, part, step, etc." should be openly interpreted as referring to at least one instance of the element, device, component, part, step, etc. The steps of any method disclosed herein need not be performed in the exact order disclosed, unless a step is explicitly described as occurring after or before another step and / or it is implied that a step must occur after or before another step. Where applicable, any feature of any embodiment disclosed herein may be applied to any other embodiment. Similarly, any advantage of any embodiment may be applied to any other embodiment, and vice versa.

[0232] Any appropriate steps, methods, features, functions, or benefits disclosed herein can be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus can comprise a number of these functional units. These functional units can be implemented via processing circuitry, which can include one or more microprocessor or microcontroller, other digital hardware, and / or can include digital

[0233] The term unit can have the conventional meaning in the field of electronic, electrical, and / or electronic devices and can include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for executing the corresponding tasks, processes, calculations, outputs, and / or display functions, etc., as described herein.

[0234] At least some of the following abbreviations can be used in this disclosure. If there is a discrepancy between an abbreviation listed here and an abbreviation used in the foregoing disclosure, the discrepancy should be resolved in favor of the abbreviation used in the foregoing disclosure. If an abbreviation is listed multiple times, the first listing should be controlling.

[0235] 1xRTT CDMA2000 1x Radio Transmission Technology

[0236] 3GPP Third Generation Partnership Project

[0237] 5G Fifth Generation

[0238] ABS Almost Blank Subframe

[0239] ARQ Automatic Repeat reQuest

[0240] AWGN Additive White Gaussian Noise

[0241] BCCH Broadcast Control Channel

[0242] BCH Broadcast Channel

[0243] CA Carrier Aggregation

[0244] CC Carrier Component

[0245] CCCHSDU common control channel SDU

[0246] CDMA code division multiple access

[0247] CGI cell global identifier

[0248] CIR channel impulse response

[0249] CP cyclic prefix

[0250] CPICH common pilot channel

[0251] CPICH Ec / No CPICH received energy per chip divided by power density in the frequency band

[0252] CQI channel quality information

[0253] C-RNTI cell RNTI

[0254] CSI channel state information

[0255] DCCH dedicated control channel

[0256] DL downlink

[0257] DM demodulation

[0258] DM-RS demodulation reference signal DRX discontinuous reception DTX discontinuous transmission DTCH dedicated traffic channel DUT device under test

[0259] E-CID enhanced cell ID (positioning method) E-SMLC evolved serving mobile location center ECGI evolved CGI eNB E-UTRAN NodeB ePDCCH enhanced physical downlink control channel E-SMLC evolved serving mobile location center E-UTRA evolved UTRA E-UTRAN evolved UTRAN FDD frequency division duplex

[0260] FFS for further study GERAN GSM EDGE radio access network gNB base station in NR GNSS global navigation satellite system GSM Global System for Mobile Communications HARQ Hybrid Automatic Repeat reQuest HO Handover

[0261] HSPA High Speed Packet Access HRPD High Rate Packet Data LOS Line of Sight

[0262] LPP LTE Positioning Protocol LTE Long Term Evolution

[0263] MAC Medium Access Control

[0264] MBMS Multimedia Broadcast Multicast Service

[0265] MBSFN Multimedia Broadcast Multicast Service Single Frequency Network

[0266] MBSFN ABS MBSFN Almost Blank Subframe

[0267] MDT Minimization of Drive Testing

[0268] MIB Master Information Block

[0269] MME Mobility Management Entity

[0270] MSC Mobile Switching Center

[0271] NPDCCH Narrowband Physical Downlink Control Channel

[0272] NR New Radio

[0273] OCNG OFDMA Channel Noise Generator

[0274] OFDM Orthogonal Frequency Division Multiplexing

[0275] OFDMA Orthogonal Frequency Division Multiple Access

[0276] OSS Operation Support System

[0277] OTDOA Observed Time Difference of Arrival

[0278] O&M Operation and Maintenance

[0279] PBCH Physical Broadcast Channel

[0280] P-CCPCH Primary Common Control Physical Channel

[0281] PCell Primary Cell

[0282] PCFICH Physical Control Format Indicator Channel

[0283] PDCCH Physical Downlink Control Channel

[0284] PDP Configuration Delay Profile

[0285] PDSCH Physical Downlink Shared Channel

[0286] PGW Packet Gateway

[0287] PHICH Physical Hybrid-ARQ Indicator Channel

[0288] PLMN Public Land Mobile Network

[0289] PMI Precoder Matrix Indicator

[0290] PRACH Physical Random Access Channel

[0291] PRS Positioning Reference Signal

[0292] PSS Primary Synchronization Signal

[0293] PUCCH Physical Uplink Control Channel

[0294] PUSCH Physical Uplink Shared Channel

[0295] RACH Random Access Channel

[0296] QAM Quadrature Amplitude Modulation

[0297] RAN Radio Access Network

[0298] RAT Radio Access Technology

[0299] RLM Radio Link Management

[0300] RNC Radio Network Controller

[0301] RNTI Radio Network Temporary Identifier

[0302] RRC Radio Resource Control

[0303] RRM Radio Resource Management

[0304] RS Reference Signal

[0305] RSCP Received Signal Code Power

[0306] RSRP Reference Symbol Received Power or Reference Signal Received Power

[0307] RSRQ Reference Signal Received Quality or Reference Symbol Received Quality

[0308] RSSI Received Signal Strength Indicator

[0309] RSTD Reference Signal Time Difference

[0310] SCH Synchronization Channel

[0311] SCell Secondary Cell

[0312] SDU Service Data Unit

[0313] SFN System Frame Number

[0314] SGW Serving Gateway

[0315] SI System Information

[0316] SIB System Information Block

[0317] SNR Signal to Noise Ratio

[0318] SON Self-Optimizing Network

[0319] SS Synchronization Signal

[0320] SSS Secondary Synchronization Signal

[0321] TDD Time Division Duplex

[0322] TDOA Time Difference of Arrival

[0323] TOA Time of Arrival

[0324] TSS Terrestrial Synchronization Signal

[0325] TTI Transmission Time Interval

[0326] UE User Equipment

[0327] UL Uplink

[0328] UMTS Universal Mobile Telecommunications System

[0329] USIM Universal Subscriber Identity Module

[0330] UTDOA Uplink Time Difference of Arrival

[0331] UTRA Universal Terrestrial Radio Access

[0332] UTRAN Universal Terrestrial Radio Access Network

[0333] WCDMA Wideband CDMA

[0334] WLAN Wireless Local Area Network

[0335] Further definitions and embodiments are discussed below.

[0336] In the above description of various embodiments of the inventive concepts, it is to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the inventive concepts. Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the inventive concepts belong. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an overly formal or overly literal sense unless expressly so defined herein.

[0337] When an element A is said to be “connected”, “coupled”, “responsive”, or variations thereof, to another element B, it can be directly connected, coupled, or responsive to the other element B or intervening elements can be present. In contrast, when an element A is said to be “directly connected”, “directly coupled”, “directly responsive”, or variations thereof, to another element B, then there are no intervening elements present. Like numbers refer to like elements throughout. Also, “coupled”, “connected”, “responsive”, or variations thereof, as used herein can include wireless coupling, connection, or response. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. Well-known functions or constructions can not be described in detail for brevity and / or clarity. The term “and / or” (abbreviated as “ / ”) includes any and all combinations of one or more of the associated listed items.

[0338] It will be understood that, although the terms first, second, third, etc. can be used herein to describe various elements / operations, these elements / operations should not be limited by these terms. These terms are only used to distinguish one element / operation from another. Thus, a first element / operation in some embodiments could be termed a second element / operation in other embodiments without departing from the teachings of the inventive concepts. In the description, identical reference numbers or reference labels can indicate identical or similar elements.

[0339] As used herein, the terms “comprise”, “comprising”, “have”, “having”, “include”, “including”, “contain”, “containing”, or variations thereof, are open-ended and include one or more stated features, integers, elements, steps, components, or functions but do not preclude the presence or addition of one or more other features, integers, elements, steps, components, functions, or groups thereof. Also, as used herein, the common abbreviation “e.g.” (which derives from the Latin phrase “exempli gratia”), can be used to introduce or specify a general example or examples of a previously recited item, and is not intended to be limiting of such item to the specific example(s) set forth. The common abbreviation “i.e.” (which derives from the Latin phrase “id est”), can be used to specify a particular item from a more general recitation.

[0340] The exemplary embodiments are described herein with reference to the accompanying drawings, which are figures of example embodiments and illustrate the best modes presently contemplated by the inventors of the present disclosure. The agent should understand that the drawings are not necessarily to scale and that, unless otherwise specifically indicated herein, the drawings are merely intended to depict the general structure of the exemplary embodiments. Wherever possible, like reference numerals are used across the drawings to refer to like elements. The exemplary embodiments are described herein with reference to block diagrams and / or flowchart illustrations of the computer implemented methods, apparatus (systems and / or devices) and / or computer program products according to the present disclosure. It will be understood that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by computer program instructions that are executed by one or more computer circuits. These computer program instructions can be provided to a processor circuit of a general purpose computer, special purpose computer, and / or other programmable data processing circuit to produce a machine, such that the instructions, which execute via the processor of the computer and / or other programmable data processing apparatus, transform and control transistors, values stored in memory locations, and other hardware components within such circuitry to implement the functions / acts specified in the block diagrams and / or flowchart block or blocks, thereby creating means for implementing the functions / acts specified in the block diagrams and / or flowchart block or blocks. Embodiments of the present disclosure can be implemented in hardware and / or in software (including firmware, resident software, micro-code, etc.) that runs on a processor such as a digital signal processor, which can collectively be referred to as "circuitry," "module" or variants thereof.

[0341] These computer program instructions can also be stored in a tangible computer-readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable medium produce an article of manufacture including instructions that implement the functions / acts specified in the block diagrams and / or flowchart block or blocks. Accordingly, embodiments of the present disclosure can be embodied in hardware and / or in software (including firmware, resident software, micro-code, etc.) that runs on a processor such as a digital signal processor, which can collectively be referred to as "circuitry," "module" or variants thereof.

[0342] It should also be noted that in some alternative implementations, the functions / acts described in the blocks can occur out of the order described in the flowcharts. For example, two blocks shown in succession can in fact be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality / acts involved. Also, the functionality of a given block can be separated into multiple blocks and / or the functionality of two or more blocks can be combined into a single block. Finally, additional blocks can be added / inserted between the blocks shown in the flowcharts and / or blocks / operations can be omitted from the flowcharts. In addition, while some of the diagrams include arrows on communication paths to show a primary direction of communication, it is to be understood that communication can occur in the opposite direction to the arrows. For example, if the top of a block has an arrow pointing downward, communication can be sent from the top toward the bottom with or without the block below communicating back to the block above. Likewise, if the bottom of a block has an arrow pointing upward, it can be understood that communication can be sent from the bottom toward the top with or without the block above communicating back to the block below.

[0343] Many modifications and variations of the embodiments described herein can be made without departing from the spirit and scope of the inventive concept. All such modifications and variations are intended to be included herein. Thus, the above disclosed subject matter is to be considered illustrative, and not restrictive, and the examples of embodiments are intended to cover all such modifications, enhancements, and other embodiments, which fall within the spirit and scope of the inventive concept. Accordingly, the scope of the inventive concept is to be determined only by the broadest permissible interpretation of the present disclosure, including the examples of embodiments and their equivalents, and will not be restricted by the foregoing detailed description of the embodiments.

Claims

1. A method of operating a first network node in a telecommunications network, the first network node being an authentication server function, AUSF, node, the method comprising: receiving (1010) an authentication request associated with a communication device requesting to register with the telecommunications network, the authentication request comprising first subscriber information; in response to receiving the authentication request, sending (1020) a first message to a second network node, the first message comprising the first subscriber information, wherein the second network node is a unified data management, UDM, node; and in response to sending the first message to the second network node, receiving (1030) a second message from the second network node, the second message comprising a first indicator indicating that the first subscriber information comprises an anonymous identifier and a second indicator indicating an authentication procedure; determining (1040) that the first subscriber information comprises the anonymous identifier; and generating (1070) second subscriber information based on the anonymous identifier; wherein determining that the first subscriber information comprises the anonymous identifier comprises determining, based on the first indicator, that the first subscriber information comprises the anonymous identifier, the method further comprising: in response to generating the second subscriber information, sending (1175) a third message to a second network node, the third message comprising the second subscriber information and an indicator indicating that the authentication procedure has been performed; in response to sending the third message, receiving (1180) a fourth message from the second network node, the fourth message comprising authentication subscription data associated with the communication device; and in response to receiving the fourth message, verifying (1190) the authentication subscription data.

2. The method of claim 1, wherein, the first subscriber information comprises a first subscription concealed identifier, SUCI, wherein the second subscriber information comprises a second SUCI or a subscription permanent identifier, SUPI.

3. The method of any one of claims 1-2, wherein, the authentication request further comprises an indicator indicating that the communication device is a non-5G N5GC capable device, and wherein determining that the first subscriber information comprises the anonymous identifier comprises determining, based on the authentication request comprising the indicator indicating that the communication device is a N5GC capable device, that the first subscriber information comprises the anonymous identifier.

4. The method of any one of claims 1-2, wherein, the fourth message further comprises a second authentication procedure associated with the authentication subscription data, wherein verifying the authentication subscription data comprises: determining that third subscriber information associated with the authentication subscription data matches the second subscriber information; and determining that the second authentication procedure matches the authentication procedure.

5. The method of any of claims 1-2, further comprising: in response to determining that the first subscriber information comprises the anonymous identifier, determining (1050) an authentication procedure to be performed; in response to determining the authentication procedure to be performed, receiving (1060) information associated with the communication device as part of the authentication procedure; and wherein generating the second subscriber information comprises generating the second subscriber information based on the information associated with the communication device. ​ 6. The method of claim 5, wherein, determining, based on the second indicator, an authentication procedure to be performed.

7. The method of claim 5, wherein, the authentication procedure comprises at least one of: Extensible Authentication Protocol Transport Layer Security, EAP-TLS, and EAP Tunneled Transport Layer Security, EAP-TTLS, wherein the information comprises at least one of: a client certificate, and a username, and wherein receiving the information associated with the communication device as part of the authentication procedure comprises at least one of: receiving the client certificate via the EAP-TLS; and receiving the username via the EAP-TTLS.

8. A method of operating a second network node in a telecommunications network, wherein, the second network node is a Unified Data Management, UDM, node, the method comprising: receiving (1210), from a first network node, an authentication request associated with a communication device requesting registration with the telecommunication network, the authentication request comprising first subscriber information, the first network node being an Authentication Server Function, AUSF, node; in response to receiving the authentication request, determining (1220) that the first subscriber information comprises an anonymous identifier; in response to determining that the first subscriber information comprises the anonymous identifier, determining (1230) an authentication procedure to be performed; in response to determining the authentication procedure to be performed, sending (1240), to the first network node, an authentication response comprising an indicator indicating the authentication procedure and an indicator indicating that the subscriber information comprises the anonymous identifier; in response to sending the authentication response, receiving (1250) a second authentication request associated with the communication device requesting registration with the telecommunication network, the second authentication request comprising second subscriber information and an indicator indicating that the authentication procedure has been performed; in response to receiving the second authentication request, determining (1270) a second authentication procedure associated with the second subscriber information; and in response to determining the second authentication procedure, sending (1280), to the first network node, a second authentication response comprising an indicator indicating the second authentication procedure.

9. The method of claim 8, wherein, the first subscriber information comprises a first Subscription Concealed Identifier, SUCI, wherein the second subscriber information comprises a second SUCI or a Subscription Permanent Identifier, SUPI.

10. The method of claim 9, wherein, the second subscriber information comprises a second SUCI, the method further comprising, in response to receiving the second authentication request, determining (1360), using a Subscriber Identity De-concealing Function, SIDF, the SUPI based on the SUCI, and wherein the second authentication response further comprises the SUPI.

11. A first network node (700, 800) operating in a telecommunication network, the first network node comprising: processing circuitry (703, 803); memory (705, 805) coupled to the processing circuitry and having instructions stored therein that are executable by the processing circuitry to cause the first network node to perform the method of any of claims 1-7.

12. A computer program product comprising a non-transitory storage medium (705, 805) having program code to be executed by a processing circuit (703, 803) of a first network node (700, 800) operating in a telecommunications network, whereby execution of the program code causes the first network node to perform the method according to any one of claims 1-7.

13. A second network node (700, 900) operating in a telecommunications network, the second network node comprising: a processing circuit (703, 903); a memory (705, 905) coupled to the processing circuit and having instructions stored therein that are executable by the processing circuit to cause the second network node to perform the method according to any one of claims 8-10.

14. A computer program product comprising a non-transitory storage medium (705, 905) having program code to be executed by a processing circuit (703, 903) of a second network node (700, 900) operating in a telecommunications network, whereby execution of the program code causes the second network node to perform the method according to any one of claims 8-10.

Citation Information

Patent Citations

  • Subscription concealed identifier

    US20190098502A1