Authenticate user equipment through relay user equipment

By relaying the tunnel connection and temporary identity authentication between the user device and the application server, the problem of private identity leakage of remote user devices in the cellular network is solved, and the privacy protection of identity authentication and the security of network access are achieved.

CN116033420BActive Publication Date: 2025-10-03MALIKIE INNOVATIONS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211626533.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-10-05
Filing Date
2018-10-02
Publication Date
2025-10-03
Estimated Expiration
2038-10-02

AI Technical Summary

Technical Problem

When a remote user device accesses a wireless network through a relay user device, how can its private identity be protected from being leaked during the authentication process? Especially in cellular networks, existing technologies make it difficult to achieve effective identity authentication and privacy protection.

Method used

By relaying a tunneled connection between the user device and the application server, the remote user device uses a temporary identity for authentication. The relay device restricts initial access to the application server until the remote device is authenticated. The authentication process is performed using the EAP or OAuth 2.0 protocol to ensure that the private identity is not leaked.

Benefits of technology

This ensures that the remote user device protects the security of its private identity during the authentication process, avoids the leakage of the private identity, and ensures the privacy of identity authentication and the security of network access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116033420B_ABST
    Figure CN116033420B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to authenticating a user equipment (UE) via a relay UE. In some examples, a first user equipment (UE) sends an indication to an application server that the first UE will use a relay UE to access a network. The first UE receives a first identifier from the application server that is different from a second identifier of the first UE. The first UE registers with the network using the first identifier to authenticate the first UE.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related patent applications

[0002] This application is a divisional application of the invention patent application with international application number PCT / US2018 / 053913, international application date October 2, 2018, priority date October 5, 2017, entry into the Chinese national phase date April 7, 2020, and Chinese application number 201880065335.8. Background Art

[0003] Devices such as computers, handheld devices, vehicles, appliances, or other types of devices can communicate over wired or wireless networks. Wireless networks can include wireless local area networks (WLANs), which include wireless access points (APs) to which devices can wirelessly connect. Other types of wireless networks include cellular networks, which include wireless access network nodes to which devices can wirelessly connect. BRIEF DESCRIPTION OF THE DRAWINGS

[0004] Some implementations of the present disclosure are described with respect to the following figures.

[0005] Figure 1 is a flow diagram of a process for a remote user equipment (UE) according to some examples.

[0006] Figure 2 is a message flow diagram of interactions between various nodes according to another example.

[0007] Figure 3 is a message flow diagram of interactions between various nodes according to the first implementation of the present disclosure.

[0008] Figure 4 is a message flow diagram of interactions between various nodes according to the second implementation of the present disclosure.

[0009] Figure 5 is a message flow diagram of interactions between various nodes in which OAuth is used according to a first implementation of the present disclosure.

[0010] Figure 6 is a message flow diagram of the interaction between a relay UE and a network node according to the first implementation of the present disclosure.

[0011] Figure 7 is a message flow diagram of interactions between various nodes according to the first option of the second implementation of the present disclosure.

[0012] Figure 8 is a block diagram of protocol stacks in various nodes according to some examples.

[0013] Figure 9is a message flow diagram of interactions between various nodes according to a second option of the second implementation of the present disclosure.

[0014] Figure 10 is a block diagram of protocol stacks in various nodes according to further examples.

[0015] Figure 11 is a message flow diagram of interactions between various nodes according to the third option of the second implementation of the present disclosure.

[0016] Figure 12 is a block diagram of a network node according to some examples.

[0017] Throughout the drawings, the same reference numerals denote similar, but not necessarily identical, elements. The drawings are not necessarily drawn to scale, and the dimensions of certain parts may be exaggerated to more clearly illustrate the examples shown. Furthermore, the drawings provide examples and / or implementations consistent with the description. However, the description is not limited to the examples and / or implementations provided in the drawings. DETAILED DESCRIPTION

[0018] In this disclosure, the use of the terms "a", "an" or "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. Similarly, when used in this disclosure, the terms "includes", "including", "comprises", "comprising", "have" or "having" specify the presence of stated elements, but do not preclude the presence or addition of other elements.

[0019] In some examples, the wireless network is a cellular network operating according to a cellular protocol. Cellular protocols include protocols provided by the Third Generation Partnership Project (3GPP), such as the Long Term Evolution (LTE) standard. The LTE standard is also known as the Evolved Universal Terrestrial Radio Access (E-UTRA) standard. Cellular protocols may also include next-generation protocols, including fifth-generation (5G) and later protocols. Other cellular protocols may also be used in other examples.

[0020] Other examples of wireless networks include wireless local area networks (WLANs). WLANs may include, but are not limited to, wireless networks that operate according to Institute of Electrical and Electronics Engineers (IEEE) 802.11 or Wi-Fi Alliance specifications, among others.

[0021] Although some examples of wireless networks are provided, techniques or mechanisms according to some implementations of the present disclosure can be used with any of various types of wireless networks.

[0022] Examples of wireless devices capable of communicating in a wireless network include computers (e.g., tablet computers, laptops, desktop computers, etc.), handheld devices (e.g., smartphones, personal digital assistants, head-mounted devices, etc.), wearable devices (smart watches, electronic glasses, head-mounted devices, etc.), gaming devices, health monitors, vehicles (or devices in vehicles), cargo transport units (e.g., trailers, containers, etc.), Internet of Things (IoT) devices, or other types of endpoints or user devices capable of communicating wirelessly. Wireless devices may include mobile devices and / or fixed-location devices. More generally, a wireless device may refer to an electronic device capable of communicating wirelessly.

[0023] In the following discussion, a wireless device is referred to as a “User Equipment (UE)”. UE may refer to a UE with a UICC, a Mobile Equipment (ME) without a UICC, or any other type of wireless device.

[0024] As used herein, a "remote UE" may refer to a wireless device that may not be able to access a wireless network, such as a cellular network. A remote UE may use a relay UE to access a wireless network, such as a cellular network. A "relay UE" is a wireless device that allows another type of wireless device, such as a remote UE, to access the wireless network using the relay UE. An example of a relay UE is a layer 2 relay UE. The remote UE is a first type of UE, and the relay UE is a second type of UE that is different from the first type.

[0025] In some examples, the remote UE communicates with the relay UE using a first type of wireless technology, including any one or some combination of the following: Bluetooth, WLAN, device-to-device (D2D) (such as PC5, ProSe D2D, sidelink, direct short range communication (DSRC), IEEE 802.11p, etc.), near field communication (NFC), narrowband Internet of Things (NB-IoT), etc. The relay UE can communicate with the wireless network using a second type of wireless technology, such as Universal Terrestrial Radio Access Network (UTRAN), GSM EDGE Radio Access Network (GERAN), Enhanced Data Rates for GSM Evolution (EDGE), WLAN, LTE, 5G, etc.

[0026] In a more specific example, a Layer 2 relay UE allows a remote UE to access connectivity and services provided by a 3GPP network through the relay UE. In some examples, network access stratum (NAS) signaling transmitted by the remote UE can transparently pass through the relay function in the relay UE with the 3GPP network. The relay function can be provided as part of Layer 2 of the relay UE.

[0027] In an example where the wireless network is evolved UTRAN (e-UTRAN), the remote UE may be referred to as an eRemote UE, and the relay UE may be referred to as an eRelay UE.

[0028] In the context of public safety services such as Mission Critical Push to Talk (MCPTT) as defined by 3GPP, a relay UE may refer to an entity that may be deployed to extend 3GPP coverage to devices that may not have 3GPP coverage, such as in the event of a vehicle accident or emergency where a first responder group (such as the police) may establish one or more relay UEs to provide better coverage to other first responders attending the incident.

[0029] A problem that arises in the context of a remote UE accessing a wireless network using a relay UE, such as a Layer 2 relay UE, involves performing network authentication of the remote UE, where the remote UE does not wish to disclose its private identity. The private identity may also be referred to as a private user identity (ID). Typically, a property of the private identity is that it is known only to the wireless network and the remote UE.

[0030] Examples of a private user ID associated with a remote UE may include a Session Initiation Protocol (SIP) Uniform Resource Identifier (URI) or an IMSI. As another example, the private user ID may also be a temporary ID. The temporary ID may include any of the following: a globally unique temporary ID (GUTI), a temporary mobile subscriber identity (TMSI), a packet temporary mobile subscriber identity (P-TMSI), a 5G-GUTI, etc. A characteristic of a temporary ID is that the identity has a limited lifetime and can be assigned to another UE at a different time or at a different location.

[0031] Typically, the term "identity" refers to either a private identity or a public identity.

[0032] Figure 1 100 is a flow chart of a process 100 that may be performed by a remote UE to perform authentication. The remote UE sends (at 102) an indication to an application server (AS) that the remote UE will use a relay UE to access the network. The application server (also referred to as an "access server") is an entity that may perform any one or some combination of the following: protocol interworking between a first protocol and a second protocol; authentication functionality or proxy authentication functionality; functionality of a back-to-back user agent (B2BUA), which is a logical SIP network element; user identity mapping functionality, access and mobility management function (AMF); and the like.

[0033] The B2BUA is the logical entity that receives requests and processes them as a User Agent Server (UAS). To determine how to respond to a request, the B2BUA acts as a User Agent Client (UAC) and generates requests. Unlike a proxy server, the B2BUA maintains session state and participates in all requests sent over a session the B2BUA has established.

[0034] In some examples, it is assumed that the remote UE does not have cellular connectivity. However, it should be noted that techniques or mechanisms according to some implementations are also applicable to examples where the UE has cellular connectivity.

[0035] In process 100, the remote UE receives (at 104) a first identity different from a second identity of the remote UE from the application server. For example, the second identity can be the private identity of the remote UE discussed above. On the other hand, for example, the first identity can be a temporary ID.

[0036] The remote UE registers (at 106) with the network using the first identity, wherein the registration results in authentication of the remote UE.

[0037] In this way, the remote UE does not have to reveal its private identity when performing authentication.

[0038] Figure 2 FIG1 is a message flow diagram of an authentication process according to another example, which involves a remote UE, a relay UE, an application server labeled AS1, and various network nodes, including MMEa, MMEb, P-GW, and network node 1. MME stands for "Mobility Management Entity," which is an LTE core network node that performs various control tasks for access by UEs accessing the LTE access network. In other examples, different types of mobility management nodes may be used instead of the LTE MME, such as the Access and Mobility Management Function (AMF) of a 5G network.

[0039] exist Figure 2 In the MMEa and MMEb, two different MMEs are represented. Figure 2 Two MMEs are shown in FIG, but note that in other examples, only one MME may be employed.

[0040] P-GW stands for "Packet Data Network Gateway", which is an LTE core network node and is a gateway connected to a PDN (e.g., the Internet or another type of data network) to transmit service data packets between the UE and the PDN. In other examples, instead of P-GW, a different type of core network node can be used for service data communication, such as a user plane function (UPF) of a 5G network.

[0041] In a different example, AS1 can be replaced by a non-3GPP interworking function (N3IWF) for 5G networks. Alternatively, AS1 can be replaced by an evolved packet data gateway (ePDG). Therefore, the term "application server" can refer to an application server, N3IWF, ePDG, or any other entity designated to perform a specified task.

[0042] Figure 1 The network node 1 is shown as being configured to perform authentication services. In some examples, the network node 1 may include an Authentication Authorization Accounting (AAA) server, an Authentication Server Function (AUSF), or any other type of node that can provide authentication services.

[0043] Figure 2 Shows that it can be Figure 2 Various tasks are performed between the entities shown in .

[0044] Task 1: The remote UE registers with and / or associates with the relay UE. Registering with and / or associating with the relay UE allows the remote UE to exchange information with the relay UE, enabling the remote UE to obtain information about the relay UE, such as its configuration information. Once the remote UE and relay UE are associated, the remote UE can communicate with the wireless network using the relay UE.

[0045] Task 2: In response to the association between the remote UE and the relay UE, if the relay UE no longer exists and does not provide connectivity to AS1, the relay UE establishes a data connection with the P-GW. A key feature of the data connection is that it provides access to AS1. Another feature may be that the data connection only provides connectivity to AS1.

[0046] Task 3: The remote UE then establishes a secure connection with an application server AS1 in the network. The secure connection allows the remote UE to communicate with AS1 without another entity (such as a relay UE) being able to view the information exchanged between the remote UE and AS1. The relay UE includes functionality to restrict access to the remote UE upon receiving a request for an Internet Protocol (IP) address associated with application server AS1. Access restriction allows the remote UE to access only designated services of AS1 until the remote UE has been authenticated.

[0047] Task 4: The remote UE requests a temporary ID from AS 1 by sending the remote UE's private identity to AS 1. The temporary ID (or more generally, the remote UE's second identity, which is different from the remote UE's private identity) can be used by the remote UE for authentication purposes.

[0048] Task 5: The temporary ID or other second identifier can be obtained by AS1 in a variety of different ways. In some examples, the second identifier is assigned by AS1. In other examples, the second identifier is assigned by AS1. Figure 2 The mobility management node is allocated by a mobility management node such as an MMEb or another type of mobility management node.

[0049] In the example where the second identity is allocated by AS1, two options (Option A and Option C) can be implemented. In the alternative example where the second identity is allocated by the mobility management node, Option B is implemented.

[0050] Task 5: With option A, the second identity (assigned by AS1) and the private identity of the remote UE are sent in a message to the remote UE as Figure 2 The HSS responds to the message by creating a binding of the private identity of the remote UE and the second identity allocated by AS1.

[0051] Task 6: AS1 obtains a temporary ID or another second identity from MMEb or another mobility management node through option B. The second identity can be, for example, a GUTI. AS1 obtains the second identity by sending the private identity of the remote UE to MMEb or another mobility management node.

[0052] Task 7: AS1 sends a temporary ID or another second identity to the remote UE. The remote UE binds the temporary ID or another second identity provided by AS1 to the private identity of the remote UE.

[0053] Tasks 8 and 9: In response to receiving the temporary ID or another second identifier, the remote UE registers with the wireless network using the temporary ID or another second identifier. A registration message including the temporary ID or another second identifier may be sent by the remote UE to the relay UE (Task 8), and the relay UE may then forward the registration message (Task 9) to the MMEa (or another mobility management node).

[0054] Task 10: Through option A or B, the MMEa or another mobility management node sends a request (including a temporary ID or another second identifier) ​​to obtain an authentication vector from network node 1 (e.g., HSS). The authentication vector contains authentication information used to perform authentication of the remote UE. The HSS maps the received second identifier to the remote UE's private identifier, or the HSS does not perform the mapping.

[0055] Tasks 11, 12: With option C, the temporary ID or other second identifier has a format (e.g., IMSI, E.212, etc.) such that the entity (e.g., MMEa or another mobility management node) that receives the remote UE's registration request (Task 9) sends a request to AS1 (Task 11). AS1 then replaces the temporary ID or other second identifier with the private identifier of the remote UE received by AS1 in Task 4. After AS1 replaces the temporary ID or other second identifier with the private identifier of the remote UE, AS1 sends a request to network node 1 to obtain an authentication vector (Task 12).

[0056] Task 13: In an example where MMEa and MMEb are not the same entity, MMEa sends an identify request to MMEb to obtain identification and context information from MMEb.

[0057] Task 14: In response to the identification request, MMEb sends the identity and context information to MMEa. In other examples, MMEa and MMEb may refer to other types of mobility management nodes.

[0058] In the subsequent discussion, it is assumed that there is only one mobility management node. However, in general, the techniques or mechanisms discussed further below can be applied to the presence of multiple mobility management nodes (e.g., Figure 2 In the example of MMEa and MMEb).

[0059] The following describes more details about various different implementations (eg, Implementation 1, Implementation 2, etc.) according to some embodiments of the present disclosure, with reference to different sections such as Section 1.1, and subsections of these sections.

[0060] Section 1.1, Implementation 1

[0061] 1.1.0, Overview

[0062] In implementation 1, the remote UE is tunneled to AS1 in the network via the relay UE. AS1 allocates a second identity (e.g., a temporary ID or another token) to the remote UE so that the remote UE can then subsequently use the second identity, for example, when the remote UE performs registration via the relay UE using a layer 2 connectivity mechanism.

[0063] Tunneling is achieved via a relay UE that has established a Packet Data Protocol (PDP) connection that only allows the remote UE limited access to the application server (e.g., AS1) until the remote UE is authenticated. Note that the relay UE allows the remote UE limited access to a functional entity (AS1) that may be located in a completely different network (different from the network to which the relay UE is attached). In other words, the relay UE does not only restrict access to the application server of the relay UE's local area network.

[0064] Reference below Figure 3 .exist Figure 3 In , two or more entities are depicted in a vertical stack, which means that any entity in the vertical stack can perform Figure 3 The corresponding functions described in .

[0065] For example, in Figure 3 In the present invention, the MME or AMF can perform the tasks of the mobility management node. In addition, the P-GW or UPF (or alternatively, an entity including both the P-GW and the UPF) can perform the tasks of the data gateway. Similarly, any one of the AS1, ePDG, or N3IWF (or alternatively, any combination of AS1, ePDG, and N3IWF) can perform the tasks of the application server.

[0066] Figure 3 It is further shown that another application server can be implemented with AS2 or AMF2 (or alternatively, a combination of AS2 and AMF2). As another alternative, the other application server can be implemented as any one or some combination of AS1 and N3IWF. Figure 3 In the embodiment, the tasks of the network node 1 can be implemented by an AAA server or an AUSF (or alternatively, a combination thereof).

[0067] exist Figure 3 In

[0065] , tasks 3, 3b, and 6 can be implemented using the Extensible Authentication Protocol (EAP) or the OAuth 2.0 protocol to perform authentication.

[0068] It should also be noted that in Figure 3 There is no temporal relationship between tasks 7 and 8—these tasks can occur in any order and asynchronously.

[0069] 1.1.1, Remote UE Operation

[0070] The following references Figure 3 Various tasks performed by the remote UE through implementation 1.

[0071] Task 1: The remote UE associates with / registers with the relay UE and retrieves information about the relay UE, wherein the association allows data packets (e.g., IP packets) to be sent by the remote UE to the relay UE. The information retrieved by the remote UE from the relay UE may include any one, some, or none of the following: an identity of the relay UE, a network to which the relay UE is connected (e.g., a registered public land mobile network or RPLMN), a location of the relay UE, an address of AS1, etc. As used herein, "location" may refer to any one or some combination of a mobile country code (MCC), a mobile network code (MNC), a cell identity, GPS coordinates, waypoint details, a service set identifier (SSID), an operator code, a location area (LA), a routing area (RA), a tracking area (TA), etc.

[0072] Task not shown: The remote UE establishes a secure connection with AS1 using information retrieved from the relay UE or the remote UE's internal configuration information.

[0073] Task 3: The remote UE sends an indication to AS1 that the remote UE wishes to use the relay UE as a resource for accessing the core network (e.g., using EAP or OAuth). The remote UE may send one or more of the following information in or in association with the indication: an identity of the relay UE, a network to which the relay UE is attached, a location of the UE (remote UE and / or relay UE), an indication that the remote UE wishes to use the relay UE, etc.

[0074] Task 6: The remote UE receives a token from AS1, where the token is or contains a second identity to be used when registering for layer 2 access with the relay UE.

[0075] Task 8: The remote UE sends a NAS (e.g., Attach, Location Update, Routing Area Update, Tracking Area Update, etc.) message to the relay UE, including the second identity from the token. The NAS message is an example of a registration request used by the remote UE to register with the network so that the remote UE can be authenticated and the remote UE can obtain network services from the network.

[0076] Task 13: The remote UE receives an authentication challenge according to existing standards (currently published standards). The authentication challenge is initiated by the mobility management node (e.g., MME or AMF) in response to the authentication vector sent by network node 1 (or alternatively, AAA server or AUSF) in response to the remote UE's registration request (Task 11) (Task 12). The authentication challenge is forwarded to the remote UE by the relay UE (Task 12).

[0077] Task 14: The remote UE responds to the authentication challenge according to the existing standards

[0078] 1.1.2, Relay UE Operation

[0079] The following involves the relay UE performing the following steps by implementing 1: Figure 3 Various tasks in .

[0080] Task 1: The relay UE is associated with the remote UE and may provide any, some, or none of the following information to the remote UE: identity of the relay UE, the network to which the relay UE is connected, location of the relay UE, address of AS1, etc.

[0081] Task 2: The relay UE creates a PDP context to establish a data connection with the network. The PDP context has the following characteristics: the PDP context only provides a connection to the address of the application server (e.g., AS1) through the remote UE. If the PDP context already exists, this task is optional.

[0082] Task 3: The relay UE receives a data packet (eg, an IP packet) from the remote UE containing a destination address (eg, an IP address). The IP packet may include an indication sent by the remote UE to AS1 that the remote UE wishes to use the relay UE as a resource for accessing the core network.

[0083] Task 3b: The relay UE performs one of the following:

[0084] Check to see if the destination IP address received in the IP packet is "allowed" (e.g., the IP address is that of AS1); if the destination IP address is "allowed," the relay UE forwards the IP packet to AS1; or

[0085] Send the IP packet to the IP address pre-configured in the relay UE, where the pre-configured IP address is the IP address of AS1.

[0086] In some examples, the address of AS1 and the access point name (APN) used to create the PDP context can be obtained by the relay UE in one of the following ways:

[0087] 1. When the relay UE is communicating with the network (e.g., attaching), the relay UE receives the address and APN of AS1 from the network in a Protocol Configuration Option (PCO) information element in a NAS message; or

[0088] 2. The addresses of AS1 and APN are provided in the Universal Integrated Circuit Card (UICC) of the relay UE (in this case, the relay UE reads the addresses of AS1 and APN into memory); or

[0089] 3. The addresses of AS1 and APN are provided in the Mobile Equipment (ME), which is a UE without UICC

[0090] The PCO information element is defined in 3GPP TS 24.008 and allows the UE to indicate to the network the information it is requesting via an indicator sent to the network (where the indicator may comprise one or more bits or even one or more bits not present in the message). The network may respond to the UE with this information.

[0091] Task 8: The relay UE receives a NAS message (eg, Attach) sent by the remote UE.

[0092] Task 9: Relay UE sends NAS message (eg, Attach) or other registration request to the network.

[0093] Task 12: The relay UE receives an authentication challenge initiated by the mobility management node (e.g., MME or AMF) in response to the authentication vector sent (Task 11) by the network node 1 (or alternatively, the AAA server or AUSF) in response to the remote UE's registration request.

[0094] Task 13: The relay UE sends an authentication challenge to the remote UE.

[0095] Task 14: The relay UE receives a response to the authentication challenge according to existing standards.

[0096] Task 15: The relay UE sends a response to the authentication challenge to the network according to existing standards.

[0097] 1.1.3 AS1 Operation

[0098] The following involves the execution of AS1 by implementation 1 Figure 3 various tasks.

[0099] Task not shown: AS1 establishes a secure connection with the remote UE.

[0100] Task 3: AS1 receives an indication from the remote UE that the remote UE wishes to use the relay UE as a resource. The information sent by the remote UE to AS1 or sent together with the indication may include any one or some combination of the following: the identity of the relay UE, the network to which the relay UE is attached, the location of the UE (remote UE and / or relay UE), etc.

[0101] Task 4: If AS1 cannot complete the secure connection establishment, for example because AS1 is in the accessed network, AS1 sends the information received in Task 3 to AS2.

[0102] Task 5: If the remote UE is authorized to use the relay UE, AS2 creates the following indication: the indication is or includes the second identity of the remote UE, for example, the indication may include the above token.

[0103] Task 6: AS1 sends a token to the relay UE, where the token is or includes a second identifier.

[0104] Task 7: AS1 or AS2 sends a message to network node 1, where the message includes at least one of the following: a token, an identifier of a remote UE, an identifier of a relay UE, etc.

[0105] 1.1.4, Network Node 1 Operation

[0106] The following involves the execution by network node 1 through implementation 1 Figure 3 The network node 1 can be any of the following: HSS, Home Location Register (HLR) / Authentication Center (AuC), 5G AUSF, AAA server, etc.

[0107] Task 7: Network node 1 receives a message from AS 1, the message containing at least one of the following: a token, an identity of the remote UE, an identity of the relay UE, etc. In response, network node 1 creates a binding or mapping between at least two of the following: the identity of the remote UE, the identity of the relay UE, and the second identity in the token.

[0108] Task 10: Network node 1 receives a message from a mobility management node (e.g., MME or AMF) requesting an authentication vector for a second identity. The message optionally includes the identity of the relay UE. The message received at Task 10 may be in response to a registration request forwarded by the relay UE from the remote UE to the mobility management node. Network node 1 uses the second identity to determine the private identity of the remote UE so that the authentication vector can be retrieved. Optionally, network node 1 checks the identity of the relay UE against the identity of the relay UE created in the binding or mapping as part of Task 7 above.

[0109] Task 11: Network node 1 sends an authentication vector to the mobility management node.

[0110] Section 1.2, Implementation 2

[0111] 1.2.0, Overview

[0112] Implementation 2 Figure 4 Depicted in.

[0113] Implementation 2 is similar to Implementation 1, except that the mobility management node (e.g., MME or AMF) allocates a second identity to the remote UE and sends the allocated second identity back to AS1 so that AS1 can send the second identity to the remote UE to Figure 4 Used in Task 8.

[0114] As part of the allocation process, the MME authenticates the remote UE using standard procedures (those governed by current standards). The proposed differences between implementation 1 and implementation 2 are Figure 4 Indicated by dotted lines.

[0115] Section 2.2 Description Figure 4 Three different implementations of tasks 3-6 (optionally including tasks 4a, 4b and 5a-5e) in.

[0116] The first of the three different implementations involves sending a NAS message directly from the remote UE to the mobility management node via AS1.

[0117] The second of the three different implementations involves sending Internet Key Exchange (IKE) / EAP messages from the remote UE to AS1, where AS1 then interworks the IKE / EAP with NAS messages sent to the mobility management node.

[0118] The third of the three different implementations involves sending an IKE / EAP message from the remote UE to AS1, where AS1 assigns a private user ID (e.g., IMSI) to the remote UE, the IMSI having the following characteristics: routing in the network results in a Diameter or Mobility Application Part (MAP) message requesting an authentication vector to be sent to AS1.

[0119] 1.2.1 Remote UE Operation

[0120] The operation of the remote UE in Implementation 2 is similar to that in Implementation 1 except for the following additions.

[0121] Task 5c: The remote UE receives an authentication challenge from AS1 as part of the process of obtaining a second identity from AS1.

[0122] Task 5d: The remote UE sends a response to the authentication challenge back to AS1.

[0123] 1.2.2, Relay UE Operation

[0124] The operation of the relay UE in Implementation 2 is similar to that of the relay UE in Implementation 1.

[0125] 1.2.3, AS1 Operation

[0126] The operation of AS1 in Implementation 2 is similar to the operation of AS1 in Implementation 1 except for the following additions and / or modifications.

[0127] Task 3: AS1 receives, from the remote UE, an indication using a first protocol, that the remote UE wishes to use the relay UE as a resource for accessing a network. In some examples, the first protocol may include EAP or NAS over IP, or alternatively, may include a different protocol. Information received by AS1 from the remote UE as part of or associated with the indication includes one or more of the following: an identity of the relay UE, a network to which the relay UE is attached, a location of the UE (remote UE and / or relay UE), etc.

[0128] Task 4a: In response to the indication and associated information (sent by the remote UE at Task 3 and forwarded by the relay UE at Task 3b), AS1 sends a request for a second identity to the mobility management node using a second protocol. The request may include the identity of the remote UE received in Task 3. The second protocol may be different from the first protocol and may be a NAS protocol or other protocol.

[0129] Task 5b: AS1 receives an authentication challenge from the mobility management node using the second protocol.

[0130] Task 5c: AS1 sends an authentication challenge to the remote UE using the first protocol.

[0131] Task 5d: AS1 receives an authentication challenge response from the remote UE using the first protocol

[0132] Task 5e: AS1 sends an authentication challenge response to the mobility management node using the second protocol.

[0133] Task 4b: AS1 receives a response including a second identifier from the mobility management node using the second protocol.

[0134] Task 6: AS1 sends a token (including the second identifier of the remote UE) to the remote UE using the first protocol.

[0135] 1.2.4, Network Node 1 Operation

[0136] The operation of the network node 1 in Implementation 2 is similar to the operation of the network node 1 in Implementation 1 except for the following additions.

[0137] Task 5a: Network node 1 receives a request for an authentication vector from the mobility management node. The request for the authentication vector sent by the mobility management node is in response to the request for the second identity sent from AS1 to the mobility management node.

[0138] In response to the authentication vector received from network node 1, the mobility management node sends an authentication challenge to AS1 (task 5b).

[0139] Section 2.1, Implementation 1 Details

[0140] The following provides more details related to the various tasks of implementation 1 discussed above in Section 1.1.

[0141] 2.1.1, General Information Flow

[0142] The following involves Figure 3 , Figure 3 The message flow of implementation 1 is shown.

[0143] Task 1: The remote UE establishes a connection with the relay UE and can obtain any or some combination of the following:

[0144] a. Relay UE identification,

[0145] b. Relay the identity of the network to which the UE is connected (e.g., PLMN code, Service Set Identifier (SSID), etc.),

[0146] c. The location of the relay UE,

[0147] d. The address of AS1 (see Task 2 for possible ways in which the relay UE can obtain this address).

[0148] The remote UE stores the aforementioned information received from the relay UE.

[0149] If the address of AS1 is a fully qualified domain name (FQDN), one of the following situations may occur.

[0150] a) The relay UE appends its location information to the FQDN and sends the FQDN and location information to the remote UE.

[0151] b) The remote UE receives the FQDN and location information of the relay UE. The remote UE appends the location information to the FQDN.

[0152] Task 2: If the relay UE does not already have a data connection with the network, the relay UE creates a data connection with the network. An identifier (e.g., APN) for identifying the data network to be connected is configured on the relay ME or the relay UE's UICC, or is obtained from the network.

[0153] In implementations where the AS identifier is configured on the relay ME or UICC, Table 1 below lists example changes to 3GPP TS 31.102 or 3GPP TS 31.103 that can be made to allow the identifier to be configured on the relay ME or UICC. Underlined text in Table 1 below indicates example changes to either 3GPP TS 31.102 or 3GPP TS 31.103. While this specification includes proposed example changes to various standards, it should be noted that techniques or mechanisms according to some implementations of this disclosure can be implemented with other changes to the standards, or even with implementations that do not utilize changes to the standards. Furthermore, when the word "shall" appears in the text of a proposed change, it also covers other examples where "shall" is replaced with "should" or "may."

[0154] Table 1

[0155]

[0156]

[0157] Alternatively, the relay UE may obtain the address of AS1 from the network, which is described in Section 2.1.3 below.

[0158] The data connection established by the relay UE is characterized in that the data connection allows limited access for the remote UE to communicate only with the application server (AS1).

[0159] The relay UE creates a mapping between the remote UE and the established data connection.

[0160] If a data connection already exists, the relay UE creates a mapping between the remote UE and the existing data connection.

[0161] Task 3, 3b: The remote UE establishes a secure connection to AS1 in the network and may include any of the following in a security establishment message or a subsequent message (e.g., a registration message) during the security establishment process:

[0162] a. Any information stored by the relay UE in Task 1; or

[0163] b. a second identifier of the remote UE; or

[0164] c. Other information.

[0165] In response to receiving the IP packet from the remote UE, the relay UE sends the received IP packet from the relay UE over the data connection associated with the remote UE in Task 2 .

[0166] The address of the AS1 to be used is either obtained in Task 1 or provided in the remote UE (see Task 2 for possible implementation).

[0167] Another way to ensure that the remote UE is restricted to accessing only the target AS is for the remote UE to use an FQDN to reach the target AS. If the FQDN sent by the remote UE does not match the FQDN stored in the relay UE, the relay UE modifies the FQDN to the FQDN stored in the relay UE with the location of the relay UE appended thereto, and then the relay UE sends the FQDN in a request, such as a Domain Name System (DNS) request to a DNS server.

[0168] Matching of the FQDN involves comparing the location information of the relay UE included in the syntax of the FQDN received from the remote UE with the corresponding location information of the FQDN stored in the relay UE.

[0169] Task 4: If AS1 is unable to complete the secure connection establishment in response to the message from the relay UE, for example, because AS1 is in a visited network, AS1 sends the information received in Task 3 to AS2. AS2 is determined by using the second identity of the remote UE received in Task 3. This determination is made by using the domain portion of the second identity (for example, the second identity is in the format of Network Access Identifier (NAI) [username@domain]), where the domain identifies the network operator. If the received NAI domain portion is not processed by AS1, AS1 routes the message from the relay UE to AS2.

[0170] Task 5: If the remote UE is authorized to use the relay UE, AS2 creates an indication that is or contains the second identity of the remote UE to be sent back in Task 5 (e.g., in a token). The indication is stored for the second identity of the remote UE. AS2 sends the token or another message containing the indication to AS1.

[0171] In Task 5, if the remote UE is not authorized to use the relay UE or the specific relay UE, AS2 creates an indication that the remote UE has not been authorized. AS2 sends a message to AS1 containing an indication that may indicate any one or some combination of the following:

[0172] a. Remote UE authentication failed,

[0173] b. Remote UEs are not allowed to use Layer 2 relay UEs,

[0174] c. The remote UE is not allowed to use this particular Layer 2 relay UE,

[0175] d. Do not allow remote UE to use relay UE when roaming,

[0176] e. The remote UE is not allowed to use the relay UE connected to the RPLMN, or

[0177] f. Other instructions.

[0178] Note that AS2 and AS1 may be the same entity, or may be different entities.

[0179] Authorization to use the relay UE may be determined by using any or none of the following: the location of the remote UE, the identity of the relay UE, or the network to which the relay UE is connected (eg, RPLMN).

[0180] The indication sent by AS2 to AS1 may be based on any or none of the following: the location of the relay UE, the identity of the relay UE, or the network to which the relay UE is connected (eg, RPLMN).

[0181] Task 6: AS1 sends a message to the remote UE, the message including an indication including a second identity (eg, a token) of the remote UE, or an indication that the remote UE cannot use the relay UE as a layer-2 relay UE.

[0182] In response to receiving an indication that the remote UE cannot use the relay UE as a layer-2 relay UE, the remote UE may perform any of the following:

[0183] a. Displaying the indication on the remote UE display;

[0184] b. Play audible sound

[0185] c. If the received indication indicates that the remote UE is not allowed to use the particular Layer 2 relay UE, the remote UE may repeat the process of Task 1 if another relay UE is available;

[0186] d. If the received indication indicates that the remote UE is not allowed to use this particular Layer 2 relay UE, the remote UE may repeat the process of Task 1 if another relay UE is available, but if the relay UE indicates that the relay UE is connected to the same RPLMN, the remote UE does not proceed with any other tasks.

[0187] Task 7: AS2 sends a message to HSS, which includes any one or a combination of the following: an indication of the second identity of the remote UE, or other information.

[0188] The HSS receives the message from AS2 and stores, maps or creates a binding between the indication and the second identity of the remote UE received in the message from AS2.

[0189] Task 8: If an indication including the second identity of the remote UE is received in Task 7, the remote UE sends a message to the relay UE including the second identity of the remote UE as part of the token received in the message from AS1.

[0190] Task 9: The relay UE receives the message of Task 8 from the remote UE at a layer in the protocol stack so that the relay UE does not interact with the message. The relay UE passes the message received at Task 8 to the mobility management node.

[0191] Task 10: In response to the message of Task 9 from the relay UE, the mobility management node sends a message to the network node 1, the message including any one or some combination of the following: the second identity received in the message of Task 9, and the identity of the relay UE.

[0192] Network node 1 (e.g., an HSS) receives the message of Task 10. The HSS determines (e.g., based on the syntax of the second identity) that the second identity included in the message of Task 10 is a temporary ID and determines whether the second identity is assigned to a profile (e.g., the second identity profile of the remote UE). Alternatively, the HSS uses the received second identity to retrieve a subscriber profile associated with the second identity, such as in Task 7. As part of retrieving the profile, the HSS obtains or creates an authentication vector associated with the second identity of the remote UE.

[0193] The temporary ID can be determined by range. For example, if the temporary ID is in the format of an IMSI, a specific number within the IMSI structure can indicate that it is a temporary ID. An example can be that the Nth number in the IMSI structure (N is an integer between 0 and a non-zero value) indicates that the IMSI is temporary.

[0194] Task 11: In response to the message of Task 10, the HSS sends the authentication vector determined in Task 10 to the mobility management node.

[0195] Task 12: In response to the authentication vector from the HSS, the mobility management node sends the authentication vector to the relay UE.

[0196] Task 13: The relay UE sends the authentication vector received in Task 12 to the remote UE. The authentication vector constitutes an authentication challenge to the remote UE.

[0197] Task 14: In response to the authentication challenge, the remote UE sends an authentication challenge response to the relay UE.

[0198] Task 15: The relay UE sends the authentication challenge response received in Task 14 to the task management node.

[0199] Note that in tasks 12, 13, 14 and 15, the relay UE transparently receives and sends messages transmitted between the remote UE and the mobility management node.

[0200] 2.1.2, Communication with the Application Server

[0201] The following two subsections contain instructions on how to perform Figure 3 More details on tasks 3, 3b, and 6 of the . One mechanism uses OAuth and the other uses EAP.

[0202] 2.1.2.1, OAuth

[0203] Proposed example changes to 3GPP TS 33.180 (changes are underlined) to use OAuth are listed below in Table 2. For better clarity, the figures of 3GPP TS 33.180 are omitted.

[0204] Table 2

[0205]

[0206]

[0207]

[0208]

[0209]

[0210] Table 3 below describes an alternative example flow using OAuth.

[0211] Table 3

[0212]

[0213]

[0214] 2.1.2.2, EAP

[0215] Table 4 below shows example changes to 3GPP TS 24.302 for use of EAP (underlined text indicates changes).

[0216] Table 4

[0217]

[0218]

[0219]

[0220]

[0221]

[0222]

[0223] 2.1.3, Relay UE provides application server access identifier

[0224] The following describes an example of how to provide the identity of an application server (eg, AS1) to a relay UE.

[0225] 2.1.3.1 UE Operation

[0226] The following references Figure 6 .

[0227] Task 602: The relay UE sends a request (eg, attach, IMS method [eg, register, subscribe], etc.) to the network, the request including, for example, an indication in a PCO tag that the UE is a relay UE.

[0228] Task 604: The relay UE receives a response (to the request) from the network (eg, Attach Accept, 200 OK, Notification, etc.), the response including an indication of an address (eg, APN, IP address, etc.) to be used to access the application server identity.

[0229] The Attach Accept may include this indication in the PCO field.

[0230] The 200 OK or Notify message is an indication of the address of the application server, such as in the example format shown in Table 5.

[0231] Table 5

[0232]

[0233] Table 6 below lists example implementations of PCO, where proposed modifications to 3GPP TS 24.008 are indicated by underlined text (added text) and strikethrough text (deleted text).

[0234] Table 6

[0235]

[0236]

[0237] When 0012H is included, the coding of the provisioning service of the access server can be found in Table 7 (underlined text indicates additions to 3GPP TS 24.008).

[0238] Table 7

[0239]

[0240]

[0241] In Table 7, the encoding for the APN and access server address can be found in Table 1.

[0242] 2.1.3.2, Network Node Operation

[0243] Described below Figure 6 The operation of the network nodes in .

[0244] Task 602 - A network node (eg, MME, S-CSCF, P-GW, AMF, SMF, application server, etc.) receives a request from a relay UE with an indication that it is a relay UE.

[0245] Task 604 - If the message in task 602 includes an indication that the UE is a relay UE, and if the network node is configured with the address of the application server, the network node includes the address of the application server in a response to the request sent to the relay UE.

[0246] The address of the application server may be provided in an external database (e.g., HSS / HLR) and sent to a network node (e.g., Mobile Switching Center (MSC), MME, Serving Call State Control Function S-CSCF) via a message (e.g., Insert Subscriber Data compliant with 3GPP TS 29.002 or 3GPP TS 29.272)

[0247] Section 2.2, Details of Implementation 2

[0248] Various options that can be used with Implementation 2 are described below, including Options A, B, and C.

[0249] 2.2.1, Option A

[0250] Figure 7 Option A of Implementation 2 is shown.

[0251] Figure 7 The numbering of the arrows in the following descriptions is intentionally out of order, e.g., Task 4b appears after Task 5e. They are chosen to be consistent with the numbering in Section 1.2.

[0252] Task 1: See Task 1 in Section 2.1.1.

[0253] Task 2: See Task 2 of Section 2.1.1. The tasks of creating a PDP context and a PDN connection with the network include a registration (attachment) task.

[0254] Tasks 3, 3b: See Tasks 3) and 3b in Section 2.1.1, further explained below.

[0255] The remote UE sends a registration (eg, attach, etc.) message to AS1 containing any or some of the following: private user ID, first PDN address of the remote UE (such as in an Evolved Packet System Session Management (ESM) message), location of the relay UE, or other information.

[0256] Task 4a: If received, AS1 may remove or change the first PDN address in the message of Task 3b. If the first PDN address is included in the message from the remote UE, then when the Attach message is sent to the MME, the first PDN address may be replaced and set to the address configured in AS1 (the second PDN address).

[0257] Figure 8 A possible protocol stack in the remote UE, AS1 and MME is depicted, showing how task 3b may interwork with task 4a and the subsequent interaction between remote UE <-> AS1 <-> MME.

[0258] The protocol stack of the remote UE includes a Level 1 (L1) layer, a Level 2 (L2) layer, an IP layer, an IP Security (IPSec) layer, an application layer, and a NAS layer. AS1 includes a first protocol stack for communicating with the remote UE, wherein the first protocol stack includes an L1 layer, an L2 layer, an IP layer, an IPSec layer, and an application layer. AS1 also includes a second protocol stack for communicating with the MME, wherein the second protocol stack includes an L1 layer, an L2 layer, a Stream Control Transmission Protocol (SCTP) / IP layer, and an S1 Application Protocol (S1-AP) layer. AS1 also includes a relay function 802 for relaying between the first protocol stack and the second protocol stack of AS1.

[0259] The MME has a protocol stack including an L1 layer, an L2 layer, an SCTP / IP layer, an S1-AP layer, and a NAS layer.

[0260] The interaction between the remote UE and AS1 and the MME includes AS1 performing any of the following:

[0261] When AS1 receives a message from a remote UE, the relay function 802 of AS1 extracts the NAS message from the application layer and inserts the NAS message into an S1-AP message and sends the S1-AP message to the MME.

[0262] When AS1 receives the message from the MME, AS1 extracts the NAS message from the S1-AP message and sends the message to the remote UE.

[0263] Task 4a: Respond to Figure 7In the registration message of task 3b in Task 3b, AS1 sends a registration message (e.g., Attach, Location Update, Routing Area Update, Tracking Area Update, etc.) containing any one or some of the following: a private user ID, a second PDN address, or other information to MME 702. MME 702 is the "old" MME of the remote UE, i.e., the MME with which the remote UE would initially be associated based on the remote UE's location, for example.

[0264] The characteristics of the second PDN address are such that if the remote UE attempts to send data traffic using the PDN connection corresponding to the second PDN address, the traffic will fail.

[0265] The location of the relay UE may be used to determine the MME 702 to which AS1 will send the registration message. In AS1, there may be a mapping between locations and MMEs.

[0266] Task 5a) i): MME 702 requests an authentication vector from the HSS using the private user ID received in Task 3b.

[0267] Task 5a) ii): In response to the request of task 5a) i) from MME 702 , the HSS sends the authentication vector to MME 702 .

[0268] Task 5b: MME 702 sends an authentication challenge to AS1, for example in a NAS authentication request.

[0269] Task 5c: In response to the authentication challenge, AS1 sends an authentication challenge to the remote UE.

[0270] Task 5d: In response to the authentication challenge, the remote UE sends an authentication challenge response to AS1.

[0271] Task 5e: AS1 sends an authentication challenge response to MME 7702, for example in a NAS authentication response.

[0272] Task 4b: In response to the Authentication Challenge Response, MME 702 sends a Registration Accept (e.g., Attach Accept, Location Accept, Routing Area Update Accept, Tracking Area Update Accept, etc.) with a temporary ID (e.g., GUTI, TMSI, etc.) to AS1. In Option A, the temporary ID of the remote UE is assigned by MME 702.

[0273] Task 6: AS1 sends the temporary ID received from MME 702 at Task 4b to the remote UE.

[0274] Task 8: After receiving the temporary ID, the remote UE sends a registration message containing the temporary ID to the relay UE. The registration message may include attach, location update, routing area update, tracking area update, etc.

[0275] Task 9: Refer to 2.1.1 Task 9. Note that Figure 7 In the example, the registration message may be forwarded by the relay UE to a new MME 704 , which may be the same as or different from the old MME 702 .

[0276] Tasks 9a, 9b: The new MME 704 obtains context information associated with the remote UE from the old MME 702 using existing standards.

[0277] Tasks 10-15) Refer to Tasks 10-15 in Section 2.1.1 respectively.

[0278] 2.2.2, Option B

[0279] Figure 9 Option B of Implementation 2 is shown.

[0280] Note that in Figure 9 In this example, AS1 can be implemented using an ePDG and an AAA server. The ePDG and AAA server can be part of the same network node or included in separate network nodes. In addition, in some examples, the MME can also be combined with AS1 and P-GW.

[0281] Figure 10 Describes the possible protocol stack when ePDG and AAA server are combined. Figure 10 As shown, the remote UE has a protocol stack including an L1 layer, an L2 layer, an IP layer, and an IKEv2 / EAP layer. AS1 includes a first protocol stack for communicating with the remote UE. The first protocol stack includes an L1 layer, an L2 layer, an IP layer, and an IKEv2 / EAP layer.

[0282] The second protocol stack of AS1 communicating with MME includes L1 layer, L2 layer, SCTP / IP layer and NAS layer. The protocol stack of MME includes L1 layer, L2 layer, SCTP / IP layer and NAS layer.

[0283] exist Figure 10 In the example, when AS1 receives an IKE or EAP message, ASI interworks the contents of the IKE or EAP message with the NAS message. This interworking may involve any of the following:

[0284] a) AS1 can take parameters from the EAP message and convert the parameters into equivalent parameters, for example, the IMSI is encoded as NAI and converted into a numeric value where each digit is represented by 4 bits.

[0285] b) AS1 can take the parameters from the EAP message and map the parameters to equivalent parameters.

[0286] When AS1 receives a NAS message in the reverse direction, AS1 performs a reverse conversion or mapping to an EAP message.

[0287] The following involves Figure 9 task.

[0288] Task 1: See Task 1 in Section 2.1.1.

[0289] Task 2: See Task 2 in Section 2.1.1)

[0290] Task 2a: The remote UE and the ePDG exchange a first pair of messages, called IKE_SA_INIT, in which the ePDG and UE negotiate a cryptographic association, exchange one-time random numbers, and perform a Diffie-Hellman exchange of Diffie-Hellman values.

[0291] Task 3, 3b: The remote UE sends a user identity, such as a private user ID (in the IDi payload of the first message), APN information (in the IDr payload of the first message), and the remote UE location (encoded as part of the user identity), in the first message of the IKE_AUTH phase (the IKE_AUTH request message). The IKE_AUTH request message also includes security association information for the remote UE to begin negotiating child security associations. The remote UE sends a configuration payload (CFG_REQUEST) within the IKE_AUTH request message to obtain an IPv4 and / or IPv6 home IP address and / or home agent address. The remote UE ignores the AUTH parameter to indicate to the ePDG that the remote UE wishes to use EAP over IKEv2. The user identity conforms to the Network Access Identifier (NAI) format specified in TS 23.003 and contains an IMSI or pseudonym, as defined for EAP-AKA (Authentication and Key Agreement) in Request for Comments (RFC) 4187.

[0292] NOTE: For how the UE relay ensures that the messages of Tasks 2a, 3 and 3b are routed to the correct AS1, see the description of Tasks 3 and 3b elsewhere in this disclosure.

[0293] Task 3c: In response to the IKE_AUTH Request message, the ePDG sends an Authentication and Authorization Request message to the 3GPP AAA server (part of network node 1). The Authentication and Authorization Request message contains the user identity, the remote UE location, and the APN contained in the received IKE_AUTH Request message. The remote UE uses the NAI defined in accordance with clause 19.3 of 3GPP TS 23.003, and the 3GPP AAA server identifies, based on the realm portion of the NAI, that it is performing joint authentication and authorization to establish the tunnel through the ePDG, which only allows EAP-AKA.

[0294] Task 4a: The AAA server then performs interworking between the EAP message of Task 3c and the NAS message sent to MME 702. NAS messages may include Registration messages, Attach messages, Location Update messages, Routing Area Update messages, Tracking Area Update messages, etc. The 3GPP AAA server obtains the user identity in the Authentication and Authorization Request message received from the ePDG and generates a temporary ID (denoted as User ID 1). The AAA server also creates a mapping between the user identity and the temporary ID (User ID 1) and includes the temporary ID (User ID 1) in the NAS message sent from the AAA server to MME 702 in Task 4a. The NAS message may also contain the APN, which may be taken from Task 3c or modified as described in Task 4a of Section 2.2.1 (applicable to Option A above).

[0295] For other possible procedures, see Task 6 in Section 2.2.1.

[0296] Task 5a)i: MME 702 sends a request for an authentication vector for the temporary ID (User ID1) to the AAA server.

[0297] Task 5a) 1: The AAA server looks up the user identity using the received temporary ID (User ID 1) (see Task 4a above for how to create this mapping between the temporary ID (User ID 1) and the user identity). The AAA server sends a request for an authentication vector for the user identity to the HSS (part of network node 1).

[0298] Task 5a) 2: In response to the request for the authentication vector, the HSS sends a message containing the authentication vector to the AAA server. The AAA server receives the authentication vector and the authentication vector for the user identity.

[0299] Task 5a) ii: The AAA server sends a message to the MME 702 containing the received authentication vector.

[0300] Task 5b: MME 702 sends a NAS Authentication Request message (Authentication Challenge) to the AAA server in response to receiving the authentication vector from the AAA server.

[0301] Task 5b)1: The AAA server interworks the NAS Authentication Request message with the EAP Request / Challenge message. The AAA server initiates the authentication challenge by sending the authentication challenge in an Authentication and Authorization Reply message to the ePDG. The ePDG responds with the authentication and authorization messages sent by the ePDG to the AAA server. The AAA server also stores the authentication vectors used in the NAS Authentication Request message so that the AAA server can later determine which set of authentication vectors was used to challenge the remote UE. The information provided in Task 5b)1 and 4b)1 (discussed further below) is used to create the correct keying material.

[0302] Task 5c: The ePDG responds to the Authentication and Authorization Reply message by sending an IKE_AUTH Response message to the remote UE, where the IKE_AUTH Response message responds to the IKE_AUTH Request message of Tasks 3 and 3b. The IKE_AUTH Response message contains the ePDG's identity, credentials, and AUTH parameters to protect the previous message sent by the ePDG to the remote UE (in the IKE_SA_INIT exchange of Task 2a). The EAP message (EAP-Request / AKA-Challenge) received from the AAA server is included in the IKE_AUTH Response message to initiate the EAP process over IKEv2.

[0303] Task 5d: In response to the IKE_AUTH Response message, the remote UE checks the authentication parameters and responds to the authentication challenge by sending another IKE_AUTH Request message to the ePDG. The IKE_AUTH Request message of Task 5d includes an EAP message (EAP-Response / AKA-Challenge) containing the remote UE's response to the authentication challenge.

[0304] Task 5d)1: The ePDG forwards the EAP-Response / AKA-Challenge message to the AAA server in the Authentication and Authorization Request message.

[0305] Task 5e: The AAA server obtains the authentication challenge response from Task 5d) 1 and includes the authentication challenge response in the authentication response message to the MME 702.

[0306] Task 4b: Refer to Task 4b of 2.2.1.

[0307] Task 4b) 1: The AAA server receives the Attach Accept message from MME 702 (Task 4b) and interworks the Attach Accept message with an EAP Success message. The AAA server obtains the temporary ID (eg, GUTI) from Task 4b and includes it in the EAP Success message.

[0308] If all checks are successful, the AAA server sends a final authentication and authorization response (with a result code indicating success) to the ePDG, including the relevant service authorization information GUTI, EAP success, and key material. The key material includes the master session key (MSK) generated during the authentication process. When the Diameter protocol is used to implement the SWm and SWd interfaces between the ePDG and the AAA server, the MSK is encapsulated in the EAP-Master-Session-Key-AVP, as defined in RFC 4072.

[0309] Task 6: The ePDG sends an IKE_Auth Response message containing a temporary ID (eg, GUTI) to the remote UE. The IKE_Auth Response message responds to the IKE_Auth Request message of Task 5d.

[0310] Tasks 8, 9, 9a, 9b, 10-15: Refer to Tasks 8, 9, 9a, 9b, 10-15 in Section 2.2.1, respectively.

[0311] 2.2.3, Option C

[0312] Figure 11 Option C of Implementation 2 is shown.

[0313] In option C, the remote UE authenticates with the ePDG using non-3GPP S2b procedures. This authentication procedure provides an identity that the remote UE can use to register with the core network via the relay UE.

[0314] Tasks 1, 2, 2a, 3, 3c, 5a)1, 5a)2, 5b)1, 5c, 5d, 5d)1, 4b)1, refer to tasks 1, 2, 2a, 3, 3c, 5a)1, 5a)2, 5b)1, 5c, 5d, 5d)1, 4b)1 in Section 2.2.2, respectively.

[0315] Task 6: See Task 6 of Section 2.2.2. In addition, when the ePDG sends the IKE_AUTH Response message of Task 6, the ePDG also assigns or allocates a temporary ID (e.g., in the format of an IMSI, etc.). The ePDG creates a binding between the user identity received in Task 3 and the temporary ID (e.g., IMSI, etc.).

[0316] Task 8: Refer to Task 8 of 2.2.2. The UE sends a message to the relay UE, such as Attach, Tracking Area Update, Location Update, etc. The message includes the temporary ID received in Task 6.

[0317] Task 9: See Task 9 in 2.2.2.

[0318] Task 10: MME 702 sends a request to the AAA server for the authentication vector for the temporary ID received in Task 9.

[0319] Note that the value of the temporary ID is such that the routing of the request for the authentication vector terminates at the entity that assigned the temporary ID (in this case the AAA server).

[0320] Task 10a: After receiving the request for the authentication vector for the temporary ID in Task 10, the AAA server uses the temporary ID to determine if there is a mapping to another identity (e.g., the private identity of the remote UE). If there is another identity (i.e., the user identity received in Task 3), the AAA server uses the other identity to retrieve the authentication vector. The AAA server sends a request for the authentication vector for the other identity to the HSS.

[0321] Task 10b: The HSS sends the requested authentication vector to the AAA server.

[0322] Task 11: The AAA server sends the authentication vector to the MME 702.

[0323] System Example

[0324] Figure 12 is a block diagram of a communication node 1200, which may be any of the following: a remote UE, a relay UE, an application server, a mobility management node, a network node, or any other type of node that may be involved in methods according to the present disclosure.

[0325] Communications node 1200 includes a processor 1202 (or multiple processors). The processor may include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit.

[0326] The communications node 1200 also includes a non-transitory machine-readable or computer-readable storage medium 1204 storing machine-readable instructions 1206 executable on a processor (ie, one or more processors 1202 ) to perform various tasks discussed in this disclosure.

[0327] The communication node 1200 also includes a communication interface 1208 for performing wired or wireless communication. The communication interface 1208 may include a network interface controller, a radio transceiver, and the like.

[0328] Storage media 1204 may include any one or some combination of the following: semiconductor memory devices, such as dynamic or static random access memory (DRAM or SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory; magnetic disks, such as fixed, floppy, and removable disks; other magnetic media, including magnetic tape; optical media, such as compact discs (CDs) or digital video discs (DVDs); or other types of storage devices. Note that the instructions discussed above may be provided on one computer-readable or machine-readable storage medium, or alternatively, may be provided on multiple computer-readable or machine-readable storage media distributed across a large system, possibly with multiple nodes. Such computer-readable or machine-readable storage media are considered part of an article (or article of manufacture). An article or article of manufacture may refer to any manufactured single component or multiple components. One or more storage media may be located in the machine that runs the machine-readable instructions, or at a remote site from which the machine-readable instructions may be downloaded over a network for execution.

[0329] In the foregoing description, numerous details have been set forth to provide an understanding of the subject matter disclosed herein. However, implementations may be practiced without some of these details. Other implementations may include modifications and variations of the details discussed above. It is intended that the appended claims cover such modifications and variations.

Claims

1. A method for authentication, comprising: The remote user equipment UE sends an indication to the application server that the remote UE will use the wireless relay UE to access the wireless network; receiving, by the remote UE from the application server, a first identity that is different from a second identity associated with the remote UE, wherein the first identity is obtained by the application server from a mobility management function; and The remote UE uses the first identifier to authenticate and register with the wireless network, The first identifier is received by the remote UE from the application server, and the application server obtains the first identifier from the mobility management function using messaging according to a second protocol, and the second protocol is different from the first protocol used by the remote UE to send the indication to the application server.

2. The method according to claim 1, wherein the application server includes a non-3GPP interworking function N3IWF of a 5G network or an evolved packet data gateway ePDG.

3. The method according to claim 1, further comprising: The remote UE receives the information of the wireless relay UE from the wireless relay UE.

4. The method according to claim 3, wherein the information of the wireless relay UE is selected from an identification of the wireless relay UE, information of a network to which the wireless relay UE is attached, a location of the wireless relay UE, and an Internet Protocol (IP) address of the application server. 5 . The method of claim 1 , wherein the remote UE is tunneled to the application server via the wireless relay UE to perform the sending and the receiving. 6 . The method of claim 5 , wherein the tunneling is based on the wireless relay UE having a connection that only allows access to the application server and based on an Internet Protocol (IP) address of the application server.

7. The method of claim 1, wherein the first identity is allocated by an access and mobility function (AMF) for a 5G network.

8. The method according to claim 1, further comprising: A secure connection is established between the remote UE and the application server, wherein the sending and the receiving are performed in the secure connection. 9 . The method according to claim 1 , wherein the sending and the receiving use Extensible Authentication Protocol (EAP) or OAuth protocol.

10. The method according to claim 1, comprising: As part of registering with the wireless network: Sending, by the remote UE, an attach message including the first identifier to the wireless relay UE, wherein the attach message causes the wireless network to send a request for authentication information to a network node that has received the first identifier from the application server; receiving, by the remote UE, the authentication information from the network node; as well as The remote UE responds to the authentication information to perform authentication of the remote UE in the wireless network.

11. A user equipment (UE), comprising: A wireless interface for communicating wirelessly; as well as At least one processor configured to: Sending an indication to an application server that the UE will use a wireless relay UE to access a wireless network; receiving, from the application server, a first identity different from a second identity associated with the UE, wherein the first identity is obtained by the application server from a mobility management function; and authenticating and registering with the wireless network using the first identifier, The first identifier is received by the UE from the application server, and the application server obtains the first identifier from the mobility management function using messaging according to a second protocol, and the second protocol is different from the first protocol used by the UE to send the indication to the application server.

12. The UE according to claim 11, wherein the application server comprises a non-3GPP interworking function N3IWF of a 5G network or an evolved packet data gateway ePDG.

13. The UE according to claim 11, wherein the at least one processor is configured to receive information of the wireless relay UE from the wireless relay UE, wherein the information of the wireless relay UE is selected from an identification of the wireless relay UE, information of a network to which the wireless relay UE is attached, a location of the wireless relay UE, and an Internet Protocol (IP) address of the application server.

14. The UE according to claim 11, comprising: As part of registering with the wireless network: Sending an attach message including the first identifier to the wireless relay UE, wherein the attach message causes the wireless network to send a request for authentication information to a network node that has received the first identifier from the application server; receiving the authentication information from the network node; as well as The method further comprises performing authentication of the UE in the wireless network in response to the authentication information.

15. An application server comprising: Communication interface; as well as at least one processor coupled to the communication interface and configured to: receiving, from a remote user equipment (UE), an indication that the remote UE is to use a wireless relay UE to access a wireless network; obtaining, from a mobility management function, a first identity associated with the remote UE; as well as sending a first identifier different from a second identifier associated with the remote UE to the remote UE, the first identifier being used by the remote UE in authenticating and registering with the wireless network, The first identifier is received by the remote UE from the application server, and the application server obtains the first identifier from the mobility management function using messaging according to a second protocol, and the second protocol is different from the first protocol used by the remote UE to send the indication to the application server.

16. The application server according to claim 15, wherein the at least one processor is configured to: A request for the first identity of the remote UE is sent to the mobility management function, the request being sent in messaging according to a second protocol, the second protocol being different from the first protocol.

17. The application server according to claim 16, wherein the first protocol is one of Extensible Authentication Protocol (EAP) or Network Access Layer (NAS) over Internet Protocol (IP), and the second protocol is a NAS protocol.

18. The application server according to claim 16, wherein the at least one processor is configured to: receiving an authentication challenge from the wireless network in messaging according to the second protocol; sending the authentication challenge to the remote UE in messaging according to the first protocol; receiving an authentication challenge response from the remote UE in messaging according to the first protocol; sending the authentication challenge response to the wireless network in messaging according to the second protocol; receiving a response to the request from the wireless network, the response being in messaging according to the second protocol and including the first identification; as well as The first identity is sent to the remote UE in messaging according to the first protocol.

19. The application server of claim 15, wherein the application server is a first application server, and wherein the at least one processor is configured to: receiving, from the remote UE, a request to establish a secure connection between the remote UE and the first application server; In response to determining that the first application server cannot establish the secure connection, sending information associated with the request to a second application server; The first identifier is received from the second application server.

Citation Information

Patent Citations

  • Techniques for securely receiving critical communication content associated with a critical communication service

    CN106471834A

  • User equipment authentication via relay user equipment

    CN111183662B

  • Apparatus and method for sponsored connectivity to wireless networks using application-specific network access credentials

    WO2016148903A1