Method and system for mitigating denial of service (DOS) attacks in wireless networks
By validating UE access rights to CAG cells using SUPI and CAG ID before initial authentication, the method addresses network inefficiencies and reduces DoS attacks in 5G systems.
Patent Information
- Application Number
- CN202080017474.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-02-27
- Filing Date
- 2020-02-27
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2040-02-27
AI Technical Summary
The existing 5G communication systems are vulnerable to distributed denial-of-service (DoS) attacks due to the need for initial authentication processes to verify user equipment (UE) access rights to closed access group (CAG) cells, leading to network overhead and inefficiencies.
A method and system that verifies UE access rights to CAG cells before initial authentication by using the subscription permanent identifier (SUPI) and requested CAG identifier (ID) to validate UE permissions, reducing network overhead and DoS attacks.
This approach minimizes network overhead and reduces DoS attacks by validating UE access rights before initial authentication, maintaining network efficiency and security.
Smart Images

Figure CN116235525B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of wireless networks, and more particularly to mitigating denial of service (DoS) attacks in wireless networks. Background Art
[0002] In order to meet the demand for wireless data services that has increased since the deployment of the fourth generation (4G) communication system, efforts have been made to develop improved fifth generation (5G) or pre-5G communication systems. Therefore, 5G or pre-5G communication systems are also referred to as "beyond 4G networks" or "post-LTE systems."
[0003] 5G communication systems are considered to be implemented in higher frequency (mmWave) bands such as the 60 GHz band in order to achieve higher data rates. In order to reduce the propagation loss of radio waves and increase the transmission distance, beamforming, massive multiple-input multiple-output (MIMO), full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and massive antenna technology are discussed in 5G communication systems.
[0004] In addition, in the 5G communication system, development is being carried out for system network improvements based on advanced small cells, cloud radio access networks (RAN), ultra-dense networks, device-to-device (D2D) communications, wireless backhaul, mobile networks, collaborative communications, coordinated multi-point (CoMP), receiving-end interference cancellation, etc.
[0005] In 5G systems, hybrid FSK with QAM modulation (FQAM) and sliding window superposition coding (SWSC) as advanced coded modulation (ACM) and filter bank multi-carrier (FBMC), non-orthogonal multiple access (NOMA) and sparse code multiple access (SCMA) as advanced access technologies have been developed.
[0006] Currently, enterprises deploy private wireless networks / non-public networks (NPNs) to meet and optimize the coverage, performance, and security requirements of their business processes. NPNs can be deployed as non-standalone NPNs and standalone NPNs. Non-standalone NPNs are deployed in conjunction with public land mobile networks (PLMNs) (also known as public network integrated non-public networks) using closed access group (CAG) cells and / or network slices. When a non-standalone NPN is deployed with a PLMN, a user equipment (UE) can use a CAG cell to access the NPN via the PLMN and obtain services provided by the NPN. The CAG identifies a group of subscribers / UEs that are permitted to access one or more CAG cells / NPNs. The CAG can also prevent the UE from automatically selecting and registering from a location that does not provide access to the NPN or from a location that does not allow the UE to access the NPN. The CAG is identified by a CAG identifier (CAG ID), which is broadcast by the CAG cell / NPN. The CAG cell broadcasts one or more CAG identifiers per PLMN. The UE may have NPN authority / subscription / authorization to access the NPN via the PLMN. The UE may be further configured with an allowed list of CAG IDs / CAG cells based on its NPN authority / subscription / authorization (hereinafter referred to as authority to access the CAG cell / NPN). When the UE wants to access the CAG cell / NPN, the PLMN needs to verify whether the UE is allowed to access the CAG cell based on the UE's NPN authority / subscription and the allowed list of the UE's CAG cell. The embodiments herein may use terms such as "authorization", "subscription", "authorization", etc. interchangeably.
[0007] Standalone NPNs may be deployed without the support of a PLMN.Standalone NPNs may use CAG and / or non-public network identifiers to identify a set of subscribers / UEs that are permitted / authorized to access one or more CAG cells / NPNs.
[0008] According to the current 3GPP specification (TS 23.501), in order to access the NPN, the UE initiates a registration procedure by sending a Subscription Hidden Identifier (SUCI) to the serving network of the PLMN in an initial Non-Access Stratum (NAS) message (e.g., Registration message) or in any NAS message (e.g., Identity Response message). The serving network performs a primary authentication procedure to authenticate the UE based on the received SUCI of the UE (after de-hiding the SUCI and deriving the SUPI). Once the primary authentication is successful, the serving network verifies whether the UE has the authority to access the CAG cell / NPN or whether the UE is authorized to access the CAG cell / NPN and enables the UE to access the CAG cell / NPN based on the successful verification. However, the serving network needs to wait until the successful primary authentication procedure is completed to verify whether the UE has the authority to access the CAG cell / NPN cell, which may incur overhead on the serving network.
[0009] In addition, when there are a large number of UEs in the network, the registration process performed by rogue / malfunctioning / malicious UEs to access an NPN in a specific CAG cell or distributed at different CAG cells with / without valid NPN authority and without having to access a CAG cell causes a (distributed) denial of service ((D)DoS) attack on the serving network.
[0010] A (D)DoS attack may be possible when the UE performs a registration procedure with valid NPN authority and without authority to a CAG cell or when the UE performs a registration procedure without valid NPN authority and without authority to access a CAG cell.
[0011] Consider an example scenario where a UE can connect to a new radio (NR / 5G) network of a PLMN and the UE has valid NPN rights without access to a CAG cell. The 5G network includes an NG-Radio Access Network (RAN) and a 5G Core (5GC) network / service network. The 5GC includes elements such as, but not limited to, an Access and Mobility Management Function (AMF), a Unified Data Management (UDM), an Authentication Server Function (AUSF), etc.
[0012] In such a scenario, the UE initiates a registration procedure for accessing / obtaining services provided by a CAG cell / NPN. The UE initiates the registration procedure by sending a SUCI as its identity to the NG-RAN requesting access to the CAG cell / NPN. The NG-RAN forwards the received SUCI to the AMF together with the CAG ID of the requested CAG cell / NPN. The AMF inserts the CAG ID in the SUCI and forwards the UE's SUCI together with the CAG ID to the UDM. The UDM reveals the received SUCI and generates an authentication vector. Based on the authentication vector generated by the UDM, the AMF authenticates the UE. In the example herein, the primary authentication procedure is considered successful because the UE has valid NPN authority. Once the primary authentication procedure is successful, the AMF receives the UE's subscription permanent identifier (SUPI) from the AUSF and verifies whether the UE has authority to access the requested CAG cell / NPN based on the received SUPI. In the example herein, the AMF verifies that the UE is not authorized to access the CAG cell because the UE does not have authority. Thereafter, the AMF rejects the registration procedure initiated by the UE.
[0013] Consider another example scenario, where the UE is a rogue UE that does not have valid NPN authority and does not have authority to access a CAG cell / NPN. In such a scenario, the rogue UE sniffs the serving network and captures the SUCI (which may or may not have authority to a CAG cell). The rogue UE then initiates a registration procedure by sending the captured SUCI as its identity to the AMF via the NG-RAN, where the NG-RAN may add the CAG ID of the requested CAG cell / NPN to the SUCI. The AMF forwards the received SUCI along with the CAG ID to the UDM, where the UDM reveals the SUCI and generates an authentication vector. Based on the generated authentication vector, the AMF performs an authentication procedure. In the example herein, the AMF rejects the registration procedure of the UE because the authentication fails because the rogue UE does not have valid NPN authority.
[0014] Therefore, in both scenarios, regardless of whether the UE has valid NPN authority, the serving network needs to perform a primary authentication procedure to authorize the UE's CAG cell access. Such a procedure can cause overhead and (D)DoS attacks on the serving network. Summary of the invention
[0015] Technical issues
[0016] The primary objective of the embodiments herein is to disclose a method and system for mitigating (distributed) denial of service ((D)DoS) attacks in a wireless network, wherein the wireless network comprises at least one non-public network (NPN) coupled to a public land mobile network (PLMN).
[0017] Another object of embodiments herein is to disclose a method and system for mitigating (D)DoS attacks by verifying the authority of at least one user equipment (UE) to access at least one NPN before performing primary authentication of at least one UE.
[0018] Another object of embodiments herein is to disclose a method and system for verifying the authority of at least one user equipment (UE) to access at least one NPN using a subscription permanent identifier (SUPI) of at least one UE and a closed access group (CAG) identifier (ID) of the requested at least one NPN.
[0019] Solution to the problem
[0020] Therefore, embodiments of the present invention provide methods and systems for controlling the authority of at least one user equipment (UE) to access at least one non-public network (NPN) in a wireless network. The method disclosed herein includes requesting a public land mobile network (PLMN) by at least one UE to access at least one NPN through at least one closed access group (CAG) cell. The method also includes verifying, by a core network (CN) of the PLMN, the authority of at least one UE to access the requested at least one NPN through at least one CAG cell. The method also includes performing a primary authentication process by the CN to allow at least one UE to access the requested at least one NPN through at least one CAG cell if the authority of at least one UE to access the requested at least one NPN through at least one CAG cell is verified.
[0021] Therefore, embodiments of the present invention disclose a network including at least one user equipment, at least one non-public network (NPN), and a public land mobile network (PLMN) deployed in conjunction with at least one NPN. The PLMN includes at least one cellular network consisting of a radio access network and a core network (CN). At least one UE is configured to request the PLMN to access at least one NPN through at least one closed access group (CAG) cell. The CN of the PLMN is configured to verify the authority of at least one UE to access the requested at least one NPN via at least one CAG cell. The CN is further configured to perform a primary authentication process to allow at least one UE to access at least one NPN through at least one CAG cell if the authority of at least one UE to access the requested at least one NPN through at least one CAG cell is verified.
[0022] These and other aspects of the example embodiments herein will be better appreciated and understood when considered in conjunction with the following description and accompanying drawings. However, it should be understood that the following description, while indicating example embodiments and many of their specific details, is provided as an illustration and not as a limitation. Many changes and modifications may be made within the scope of the example embodiments herein without departing from their spirit, and the example embodiments herein include all such modifications.
[0023] Before embarking on the detailed description below, it may be helpful to set forth definitions of certain words and phrases used throughout this patent document: the terms "include" and "comprising" and their derivatives mean inclusion without limitation; the term "or" is inclusive, meaning and / or; the phrases "associated with" and "associated therewith" and their derivatives may mean including, being included, interconnected with, containing, being contained within, connected to or connected with, coupled to or coupled with, communicable with, cooperating with, interleaved, juxtaposed, proximate to, bound to or bound with, having, having the property of, etc.; and the term "controller" means any device, system, or portion thereof that controls at least one operation, such device may be implemented in hardware, firmware, or software, or some combination of at least two of these. It should be noted that the functionality associated with any particular controller may be centralized or distributed, whether locally or remotely.
[0024] In addition, the various functions described below can be implemented or supported by one or more computer programs, each of which is formed by a computer-readable program code and embodied in a computer-readable medium. The terms "application" and "program" refer to one or more computer programs, software components, instruction sets, processes, functions, objects, classes, instances, related data or a part thereof adapted to be implemented in a suitable computer-readable program code. The phrase "computer-readable program code" includes any type of computer code, including source code, object code and executable code. The phrase "computer-readable medium" includes any type of medium that can be accessed by a computer, such as a read-only memory (ROM), a random access memory (RAM), a hard drive, a compact disc (CD), a digital video disc (DVD), or any other type of memory. "Non-transitory" computer-readable media excludes wired, wireless, optical or other communication links that convey temporary electrical signals or other signals. Non-transitory computer-readable media include media that can permanently store data and media that can store data and overwrite later, such as rewritable optical discs or erasable memory devices.
[0025] Definitions for certain words and phrases are provided throughout this patent document. Those of ordinary skill in the art should understand that in many, but not most instances, such definitions apply to prior, as well as future uses of such defined words and phrases. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The embodiments of the present invention are illustrated in the accompanying drawings, and similar reference numerals indicate corresponding parts in the various figures throughout the accompanying drawings. The embodiments of the present invention will be better understood according to the following description with reference to the accompanying drawings, in which:
[0027] Figures 1A-1C Depicting a wireless communication system / wireless network according to embodiments as disclosed herein;
[0028] Figure 2 Depicts various elements of a wireless network 100 configured for mitigating (Distributed) Denial of Service (D)DoS attacks according to embodiments as disclosed herein;
[0029] Figure 3 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at a UDM of a 5GC according to an embodiment as disclosed herein;
[0030] Figure 4 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at a UDM of a 5GC by communicating directly with an AMF / SEAF according to an embodiment as disclosed herein;
[0031] Figure 5 is a sequence diagram depicting verification of the UE's authority to access a CAG cell at the UDM by communicating with the AMF / SEAF via a Get Request message and a Get Response message according to an embodiment as disclosed herein;
[0032] Figure 6 is a sequence diagram depicting verification of the UE's authority to access a CAG cell at the UDM 206 and / or AUSF of the 5GC according to an embodiment as disclosed herein;
[0033] Figure 7 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at an AUSF of a 5GC according to an embodiment as disclosed herein;
[0034] Figure 8 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at a CAG server upon receiving a request from a UDM according to an embodiment as disclosed herein;
[0035] Fig. 9 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at a CAG server upon receiving the UE's SUCI from an AMF / SEAF according to an embodiment as disclosed herein;
[0036] Fig.10 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at a CAG server upon receiving the UE's SUCI from an AUSF according to an embodiment as disclosed herein;
[0037] Fig.11 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at an AMF / SEAF according to an embodiment as disclosed herein;
[0038] Fig.12is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at an AMF / SEAF by communicating with the UDM via a service interface provided by the UDM according to an embodiment as disclosed herein;
[0039] Fig.13 is a sequence diagram depicting verification of the authority of a UE to access a CAG cell at a CAG server by communicating directly with an AMF / SEAF according to an embodiment as disclosed herein;
[0040] Fig.14 is a sequence diagram depicting verification of the UE's authority to access a CAG cell at the UDM upon receiving the UE's SUPI from the AMF / SEAF according to an embodiment as disclosed herein; and
[0041] Fig.15 is a flow chart depicting a method for controlling permission of at least one UE to access at least one NPN in a wireless network according to embodiments as disclosed herein. DETAILED DESCRIPTION
[0042] Discussed below Figures 1A to 15 The various embodiments used to describe the principles of the present disclosure in this patent document are only for illustration and should not be interpreted in any way as limiting the scope of the present disclosure. Those skilled in the art will understand that the principles of the present disclosure can be implemented in any suitably arranged system or device.
[0043] The example embodiments of this paper and their various features and advantageous details are more fully described with reference to the non-limiting embodiments illustrated in the accompanying drawings and described in detail in the following description. Descriptions of known components and processing techniques are omitted so as not to unnecessarily confuse the embodiments of this paper. The description of this paper is merely intended to promote an understanding of the way in which the example embodiments of this paper can be practiced and also to enable those skilled in the art to practice the example embodiments of this paper. Therefore, this disclosure should not be interpreted as limiting the scope of the example embodiments of this paper.
[0044] Embodiments herein disclose methods and systems for mitigating (distributed) denial of service ((D)DoS) attacks in a wireless network, wherein the wireless network system includes at least one non-public network (NPN) coupled to a public land mobile network (PLMN).
[0045] Embodiments herein disclose methods and systems for mitigating (D)DoS attacks by performing admission control to verify the authority of at least one user equipment (UE) to access at least one NPN through a closed access group (CAG) cell before performing primary authentication of at least one UE. The term "admission control of NPN" means verifying whether there is authority for the UE to access the CAG cell or whether there is authorization for the UE to access the CAG cell. In one embodiment, if the UE has authority or subscription or authorization to access the NPN, the corresponding CAG ID of the NPN is listed in the UE's allowed CAG list. The allowed CAG list is a list of CAG identifiers of the CAG cells that the UE is allowed to access.
[0046] Referring now to the drawings, and more particularly to Figures 1A to 15 , wherein like reference numerals consistently denote corresponding features throughout the drawings, example embodiments are shown.
[0047] Figures 1A-1C A wireless communication system / wireless network 100 is depicted according to an embodiment as disclosed herein. The wireless network 100 mentioned herein can be configured to mitigate (distributed) denial of service (D)DoS attacks on public network integrated non-public networks, which are generated by a large number of registration requests from users / UEs that are not allowed to access the non-public network.
[0048] The wireless network 100 includes a public land mobile network (PLMN) 102a, one or more non-public networks (NPNs) 102b, and a plurality of UEs 104.
[0049] PLMN 102a includes one or more different cellular networks, such as but not limited to Long Term Evolution (LTE) network, Advanced LTE network, New Radio (NR) / 5G network, Narrowband Internet of Things (NB-IoT) or any other next generation network. PLMN 102a can be operated by a mobile network operator (MNO). PLMN 102a can be configured to provide communication services provided by MNO to UE 104 in a specific area. Examples of communication services can be but not limited to streaming services (streaming of multimedia data such as audio, video, text, etc.), file download services, carousel services (services for combining file download services and streaming services), television (TV) services, Internet Protocol (IP) Multimedia Subsystem (IMS) services, non-3GPP services (e.g., firewalls, etc.), etc. The embodiments herein use terms such as "PLMN", "cellular network", "public network", "3GPP access network", etc. interchangeably to refer to networks that provide communication services to public use in a given area.
[0050] The NPN 102b may be configured to provide coverage and dedicated services to UEs 104 present in, for example, but not limited to, an organization, an enterprise, a factory, a campus, a room, a floor, etc. Dedicated services may include services defined by the premises. Examples of dedicated services may be, but not limited to, streaming services (streaming of multimedia data such as audio, video, text, etc.), file download services, etc.
[0051] In one embodiment, the NPN 102b may be deployed as a non-standalone NPN. The non-standalone NPN 102b may be deployed in conjunction with the PLMN 102a. The non-standalone NPN 102b may be deployed in conjunction with the PLMN 102a using network slicing and / or closed access group (CAG) cells (as specified in 3GPP TS 23.501). The network slice provides a dedicated data network name (DNN) network, or provides one or more network slice instances that may make the NPN 102b available to the UE 104 via the PLMN 102a. The CAG may be identified using a CAG identifier (CAG ID) broadcasted by the NPN / CAG cell 102b, where the CAG ID is unique relative to the PLMN ID. The CAG may be used by the NPN 102b to prevent users / UEs from automatically selecting and registering from locations / regions / areas that do not provide access to the NPN for the UE 104 or from locations that do not allow the UE 104 to access the NPN. Embodiments herein may use the terms "CAG identifier" and "non-public network identifier" interchangeably. CAG ID may refer to CAG-ID and / or NPN-ID. Embodiments herein may use terms such as, but not limited to, "NPN," "private network," "public network integrated NPN," "non-3GPP access network," "non-standalone NPN," "CAG cell," etc. interchangeably to refer to a network that limits communication services to within the boundaries of a premises defined for UE 104.
[0052] In one embodiment, the NPN 102b may be a standalone NPN. The standalone NPN 102b may be deployed without the support of a PLMN. The standalone NPN 102b may use a CAG and / or a non-public network identifier to identify a group of subscribers / UEs that are permitted to access one or more CAG cells / NPNs. The embodiments of this document are further illustrated by considering a non-standalone NPN 102b, but a standalone NPN may also be considered, where entities in the PLMN core network 102a are hosted by the NPN core network 102b.
[0053] The UE 104 mentioned herein may be a user device capable of supporting the PLMN 102a and the NPN 102b. Examples of the UE 104 may be, but are not limited to, a mobile phone, a smart phone, a tablet, a phone tablet, a personal digital assistant (PDA), a laptop, a computer, a wearable computing device, a vehicle infotainment device, an Internet of Things (IoT) device, a virtual reality (VR) device, a wireless fidelity (Wi-Fi) router, a USB dongle, a sensor, a robot, an automatic navigation vehicle, etc. The UE 104 may include one or more processors / central processing units (CPUs), memories, transceivers, etc., for performing at least one predetermined function / operation.
[0054] UE 104 may be configured to access PLMN 102a and / or NPN 102b to obtain communication services and / or dedicated services. In one embodiment, UE 104 may access PLMN 102a via NPN 102b. In one embodiment, UE 104 may access NPN and obtain dedicated network services provided by NPN 102b by subscribing to PLMN. UE's subscription to PLMN may include at least one of NPN authority / subscription and authority / subscription to access CAG cell / NPN 102b. NPN authority may indicate that UE 104 is authorized to access NPN / services provided by NPN 102b via PLMN 102a. The authority to access CAG cell / NPN102b may indicate an allowed list of CAG cell / CAG ID of UE 104. The authority to access CAG cell may be configured for UE 104 based on its NPN authority. Use existing 3GPP procedures (e.g., air mechanisms, UE configuration update procedures, etc.) to configure the permission / allowed CAG list for accessing the CAG cell for UE 104. The embodiments herein may use terms such as "permission to access a CAG cell," "CAG cell permission," "allowed list of CAG cells / CAG IDs," "allowed CAG cell permission," etc. interchangeably.
[0055] When UE 104 wants to access CAG cell / NPN 102b or access services provided by NPN 102b, UE 104 initiates a registration process. UE 104 sends a registration request to PLMN 102a by requesting access to CAG cell / NPN 102b. In the example herein, the requested PLMN 102a may be a home PLMN (HLPMN) to which UE 104 has subscribed. In one embodiment, upon receiving the registration request from UE 104, PLMN 102a verifies whether UE 104 has permission to access the requested CAG cell / NPN 102b (or whether UE 104 is authorized to access the requested CAG cell / NPN 102b). Upon verifying that the UE 104 is authorized to access the requested CAG cell / NPN 102a / or that the UE 104 has the authority to access the requested CAG cell / NPN 102a, the PLMN 102a performs a primary authentication procedure to check whether the UE 104 is an authenticated UE 104. Based on the successful authentication, the PLMN further proceeds with the UE's registration request procedure so that the UE accesses the NPN.
[0056] Upon verifying that the UE 104 does not have the authority to access the requested CAG cell / NPN 102b (or the UE 104 is not authorized to access the requested CAG cell / NPN 102b), the PLMN 102a rejects the registration request of the UE 104 and does not enable the UE 104 to access the requested CAG cell / NPN 102b. Therefore, the authority / authorization of the UE 104 to access the NPN 102b is verified by the PLMN 102a before performing the primary authentication process to mitigate the (D)DoS attack on the PLMN 102a, which is caused by the registration process initiated by the UE 104 without the valid authority to access the CAG cell / NPN 102b.
[0057] As depicted in FIG. 1b, NPN 102b includes a non-public radio access network (RAN) 106b and a non-public core network (CN) 108b. The non-public RAN 106b mentioned herein may be a 3GPP access node, a non-3GPP access node, etc. Examples of 3GPP access nodes may be, but are not limited to, an evolved node (eNB), a new radio node (gNB), etc. Examples of non-3GPP access nodes may be, but are not limited to, a local access network (LAN) node, a wireless LAN (WLAN) node, a Wi-Fi node, etc. The non-public RAN 106b of NPN 102b may be a RAN 106b of an auxiliary PLMN 102a including a CAG cell. PLMN 102a hosts RAN 106b to access NPN 102b. The non-public RAN 106b may be configured to connect at least one UE 104 to the non-public CN 108b. The non-public CN 108b may be configured to connect the UE 104 to an external data network / PLMN 102a. The non-public CN 108b may be at least one of an EPC network, a 5GC core network, etc. In one embodiment, the NPN 102b may share the non-public RAN 106b with the PLMN 102a. The NPN 102b and the PLMN 102a may have different identifiers (IDs), separate spectrum bands, and CN functionality (e.g., user plane and data plane functionality of the CN). In one embodiment, the NPN 102b may partially share the non-public RAN 106b with the PLMN 102a, so that one or more of the functions of the non-public RAN 106b serving the NPN 102b can be provided by the PLMN 102a. In one embodiment, the NPN 102b may share the non-public RAN 106b and spectrum bands with the PLMN 102a. In one embodiment, the NPN 102b may share the control plane functionality of the non-public RAN 106b and the non-public CN 108b with the PLMN 102a.
[0058] The PLMN 102a includes at least one cellular network 106 consisting of at least one RAN 106a and a CN 108a. The RAN 106a may be configured to connect at least one UE 104 to the CN 108a. The RAN 106a may include a node / base station (BS), such as but not limited to an evolved node (eNB), a new radio node (gNB), etc. The RAN 106a may include one or more processors / central processing units (CPUs), memories, transceivers, etc., for performing at least one predetermined function / operation.
[0059] The CN 108a mentioned herein may be at least one of an evolved packet core (EPC), a 5G core (5GC) network, etc. The CN 108a may be connected to the RAN 106a and an external data network. Examples of external data networks may be, but are not limited to, the Internet, a packet data network (PDN), an Internet Protocol (IP) multimedia core network subsystem, etc. In one embodiment, the CN 108a may be connected to a non-public CN 108b via an N3IWF interface. The embodiments herein may use terms such as "core network (CN)", "service network", etc. interchangeably.
[0060] The CN 108a may include one or more processors / central processing units (CPUs), memories, storages, transceivers, etc., for performing at least one predetermined function / operation. The CN 108a may be configured to maintain information about at least one of the NPN authority of the UE 104, the subscription permanent identifier (SUPI) of the UE 104, and the allowed list of CAG cells / CAG IDs configured for the UE 104, the mapping of the allowed list of CAG cells to the SUPI of the UE 104, etc. The allowed list of CAG cells may be configured for the UE 104 based on the effective NPN authority of the UE 104. The allowed list of CAG cells may include information about the CAG IDs of the CAG cells / NPN 102b that the UE 104 can access. The SUPI may be a unique identifier assigned to the UE 104 by the MNO during a universal subscriber identity module (USIM) registration process performed by the UE 104 to register with the network system 100. The SUPI may be an International Mobile Subscriber Identifier (IMSI) (as specified in TS 23.503) or a Network Access Identifier (NAI) (as specified in TS 23.0003), among others.
[0061] The CN 108a may be configured to connect at least one UE 104 (connected to at least one RAN node 106a) to an external data network. The CN 108a may also be configured to enable the UE 104 to access the NPN 102b. In one embodiment, the CN 108a may enable the UE 104 to access the NPN 102b by verifying the UE 104's authority to access the NPN 102b before performing a primary authentication process, thereby mitigating (D)DoS attacks and minimizing overhead on the PLMN 102a.
[0062] As depicted in FIG. 1b , in order to access the NPN 102b or obtain services provided by the NPN 102b, the UE 104 performs a registration procedure with the CN 108a of the PLMN 102a. The UE 104 performs a registration procedure by sending a registration request to the connected RAN 106a of the PLMN 102a requesting access to the NPN 102b or services provided by the NPN 102b. The registration request includes a subscription concealed identifier (SUCI) of the UE 104. The SUCI may be a privacy-preserving identifier containing a concealed SUPI. In one example, the UE 104 may generate the SUCI using a protection scheme based on an elliptic curve integrated encryption scheme (ECIES) together with a public key of the home network / HPLMN 102a that is securely provided to the UE 104 during USIM registration. The UE 104 may send the registration request including the SUCI to the NG-RAN 106a in an initial non-access stratum (NAS) message or any NAS message (e.g., an identity response message, etc.).
[0063] Upon receiving the SUCI from the UE 104, the RAN 106a identifies the CAG ID of the requested CAG cell / NPN 102b (based on the broadcast of the CAG ID by the CAG cell / NPN 102b). The RAN 106a forwards the received SUCI of the UE 104 and the identified CAG ID of the requested CAG cell / NPN 102b to the CN 108a. In one embodiment, the RAN 106a may also receive the CAG ID of the requested CAG cell / NPN 102b from the UE 104.
[0064] Upon receiving the SUCI of the UE 104 and the CAG ID of the requested CAG cell / NPN 102b, the CN 108a verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b before performing a primary authentication procedure. To verify the authority, the CN 108a exposes the received SUCI as a SUPI (as specified in 3GPP TS.23.501). The CN 108a retrieves the allowed list of CAG cells / CAG IDs of the UE 104 based on the exposed SUPI. The CN 108a uses the maintained mapping of the allowed list of CAG cells with the SUPI of the UE 104 and retrieves the allowed list of CAG cells for the exposed SUPI. The CN 108a checks whether the received CAG ID of the requested CAG cell / NPN 102a exists in the allowed list of cells / CAG IDs of the retrieved UE 104.
[0065] Upon checking that the received CAG ID of the requested CAG cell / NPN 102a exists in the allowed list of the retrieved cell / CAG ID of the UE 104, the CN 108a verifies that the UE 104 has the authority to access the CAG cell / NPN 102b (successful verification). Thereafter, the CN 108a performs a primary authentication procedure to authenticate whether the UE 104 has a valid NPN authority to access the requested NPN 102b via the PLMN 102a. In order to perform the primary authentication procedure, the CN 108a generates an authentication vector based on the received SUCI (as specified in 3GPP TS 23.501) and authenticates the UE 104 based on the generated authentication vector. Once the authentication procedure is successful, the CN 108a enables the UE 104 to access the requested CAG cell / NPN 102b by performing the procedure as specified in 3GPP TS 23.501.
[0066] Upon checking that the received CAG ID of the requested CAG cell / NPN 102a does not exist in the allowed list of the cell / CAG ID of the retrieved UE 104, the CN 108a verifies that the UE 104 does not have the authority to access the CAG cell / NPN 102b (unsuccessful verification). The CN 108a then rejects the registration request of the UE 104 without continuing the primary authentication process. Upon rejecting the registration request, the CN 108a sends a rejection message to the UE 104 through the RAN 106a indicating that the requested CAG cell / NPN 102b is not allowed to access. The CN 108a also sends an appropriate cause value to the UE 104 along with the rejection message. The cause value may be a value depicting the reason for the error that the UE 104 cannot access the requested CAG cell / NPN 102b or the service provided by the requested CAG cell / NPN 102b at the current location. Examples of cause values may be, but are not limited to, #12, #13, #15, #76, etc. In one example, cause value #15 indicates that there is no suitable CAG cell in the location / tracking area of HPLMN 102a (where UE 104 is present) or CAG cell access is not allowed for UE 104. In one example, cause value #12 indicates that CAG cell access is not allowed in the requested tracking area. In one example, cause value #13 indicates that roaming is not allowed for the requested tracking area.
[0067] Therefore, verifying the authority of the UE 104 to access the CAG cell before performing the primary authentication procedure mitigates (D)DoS on the CN 108a and reduces the overhead on the CN 108a for performing the primary authentication procedure.
[0068] In one embodiment, the PLMN 102a may deploy a CAG server 110, which may communicate with the CN 108a of at least one cellular network 106 as depicted in FIG. 1c. The CAG server 110 may perform at least one predetermined function of the CN 108a. The CAG server 110 may maintain information about at least one of the NPN authority of the UE 104, the SUPI of the UE 104, and the allowed list of CAG cells / CAG IDs configured for the UE 104, the mapping of the allowed list of CAG cells to the SUPI of the UE 104, etc. The CAG server 110 may verify the authority of the UE 104 to access the NPN 102b before performing a primary authentication procedure.
[0069] Figure 2 1 is a block diagram depicting various elements of a wireless network 100 configured for mitigating (D)DoS attacks according to an embodiment as disclosed herein. The embodiments herein are further illustrated by considering as an example a PLMN 102a including a 5G network 106 as a cellular network 106 and a non-public CN 108b as a 5GC 108b, but any other cellular network and any other CN may be considered.
[0070] like Figure 2 , the RAN 106a of the 5G network / PLMN 102a may be a NG-RAN / gNB 106a and the CN 108a may be a 5GC 108a. The 5GC 108a includes an access and mobility management function (AMF) / security anchor function (SEAF) 202, an authentication server function (AUSF) 204, and a unified data management (UDM) / authentication credential repository (ARPF) / subscription identifier disclosure function 206. The CN 108a also includes other elements such as, but not limited to, a session management function (SMF), a user plane functionality (UPF), a policy control function, an application function, a network exposure function (NEF), a NF repository function (NRF), a network slice selection function (NSSF), etc. (not shown). In one embodiment, the CAG server 110 may communicate with elements of the 5GC 108a via a service interface exposed by the CAG server 110. In one example, the service interface may be an Ncag_XXX interface. Similarly, non-public CN 108b / non-public 5GC 108a includes all elements of 5GC 108a (not shown).
[0071] In one embodiment, if SEAF and AMF 202 are not co-located, AMF 202 is connected to AUSF 204 via SEAF. In embodiments herein, if SEAF and AMF are co-located, the term "AMF" throughout this document means "AMF / SEAF" 202.
[0072] AMF / SEAF 202 may be configured to support functions such as, but not limited to, termination of NAS signaling, NAS encryption and integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management, etc. AUSF 204 may be an authentication server configured to authenticate UE 104 by maintaining information about UE 104.
[0073] UDM / ARPF / SIDF 206 may be configured to perform functions such as, but not limited to, generation of authentication and key agreement (AKA) credentials, user identity processing, access authorization, subscription management, etc. In embodiments herein, UDM, ARPF, and SIDF may or may not interoperate to perform at least one function.
[0074] Embodiments herein enable at least one of the UDM 206, UDM / ARPF / SIDF 206, AUSF 204, AMF / SEAF 202, and CAG server 110 to verify whether the UE 104 is authorized to access the CAG cell / NPN 102b (or whether the UE has permission to access the CAG cell / NPN 102b) before performing a primary authentication procedure.
[0075] Embodiments herein enable the UDM 206 of the 5GC 108a to verify the authority of the UE 104 to access the CAG cell / NPN 102b. As part of the registration process, in order to access the CAG cell / NPN 102b, the UE 104 sends a registration request including a SUCI to the NG-RAN 106a. In one embodiment, the UE 104 may send the registration request to the NG-RAN 106a in an initial NAS message. In one embodiment, the UE 104 may send the registration request to the NG-RAN 106a in a NAS message (e.g., in an identity response message). The NG-RAN 106a forwards the received SUCI of the UE 104 to the AMF / SEAF 202. In one embodiment, the NG-RAN 106a identifies the CAG ID broadcasted by the requested CAG cell / NPN 102b and adds the CAG ID to the SUCI for sending to the AMF / SEAF 202 via an N2 message. In one embodiment, the NG-RAN 106a receives the CAG ID (which is broadcast by the requested CAG cell / NPN 102a) and the SUCI from the UE 104. In such a case, the NG-RAN 106a forwards the SUCI to the AMF / SEAF 202 along with the CAG ID.
[0076] The AMF / SEAF 202 includes the received SUCI of the UE 104, the CAGID of the requested CAG cell / NPN 102b, and other parameters in an authentication request message (Nausf_UEAuthentication_Authenticate request message) and sends the authentication request message to the AUSF 204. Examples of other parameters may be, but are not limited to, SN names, etc. The AUSF 204 derives the SUCI of the UE 104, the CAGID of the requested CAG cell / NPN 102b, and other parameters from the received authentication request message. The AUSF 204 inserts the derived SUCI of the UE 104, the CAG ID of the requested CAG cell / NPN 102b, and other parameters into an authentication acquisition request message (Nudm_UEAuthentication_Get_Request message). The AUSF 204 sends the authentication acquisition request message to the UDM 206 of the 5GC 108a.
[0077] Upon receiving the authentication acquisition request message, the UDM 206 checks whether the CAG ID exists in the received message. If the CAG ID exists in the received message, the UDM 206 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b before performing the primary authentication procedure. To verify the authority, the UDM 206 exposes the received SUCI as a SUPI (as specified in 3GPP TS 23.501). The UDM 206 retrieves the allowed list of CAG cells / CAG IDs of the UE 104 based on the exposed SUPI. The UDM 206 uses the maintained mapping of the allowed list of CAG cells with the SUPI of the UE 104 to retrieve the allowed list of CAG cells for the exposed SUPI. The UDM 206 checks whether the received CAG ID of the requested CAG cell / NPN 102a exists in the allowed list of cells / CAG IDs of the retrieved UE 104.
[0078] Upon checking that the received CAG ID of the requested CAG cell / NPN 102a exists in the allowed list of the retrieved cell / CAG ID of the UE 104, the UDM 206 verifies that the UE 104 has the authority to access the CAG cell / NPN 102b. Upon verifying that the UE 104 has the authority to access the CAG cell, the UDM 206 selects an authentication method and generates an authentication vector (following the procedures specified in 3GPP TS 23.501). The UDM 206 sends the generated authentication vector to the AMF / SEAF 202 via the AUSF 204 to perform the primary authentication procedure. Upon receiving the authentication vector from the UDM 206, the AMF / SEAF 202 authenticates the UE 104 and enables the UE 104 to access the NPN 102b upon successful authentication.
[0079] If the received CAG ID of the requested CAG cell / NPN 102a does not exist in the allowed list of the retrieved cell / CAG ID of the UE 104, the UDM 206 verifies that the UE 104 does not have the authority to access the CAG cell / NPN 102b. After verifying that the UE 104 does not have the authority to access the CAG cell / NPN 102b, the UDM 206 does not continue with the primary authentication process. The UDM 206 inserts the SUPI and the CAG cell rejection message in a get response message (Nudm_UEAuthentication_Get_Response message) and sends the get response message to the AUSF 204.
[0080] Upon receiving the response message including the CAG cell rejection message, the AUSF 204 includes the received CAG cell rejection message in an authentication response message (Nausf_UEAUthentication_Authenticate response message) and forwards the authentication response message to the AMF / SEAF 202.
[0081] Upon receiving the authentication response message including the CAG cell reject message from the AUSF 204, the AMF / SEAF 202 rejects the received registration request of the UE 104. The AMF / SEAF 202 sends a registration reject message with an appropriate cause value to the UE 104. The cause value indicates that the UE 104 cannot access the requested CAG cell / NPN 102b or the service provided by the requested CAG cell / NPN 102b.
[0082] By performing the check at the UDM 206, (D)DoS attacks on the network are minimized without reducing the level of 5GS security, i.e., the SUPI is not revealed to the AMF 202 before primary authentication to maintain user privacy, but authorization is performed efficiently and without providing any information other than the cause value / error reason to the UE 104.
[0083] Embodiments herein enable the UDM 206 and / or the AUSF 204 to verify the authority of the UE 104 to access the CAG cell / NPN 102b. In order to access the CAG cell / NPN 102b or the services provided by the NPN 102b, the UE 104 sends a registration request together with the SUCI to the NG-RAN 106a. The NG-RAN 106 forwards the received SUCI of the UE 104 to the AMF / SEAF 202. The AMF / SEAF 202 may receive the SUCI from the NG-RAN 106 and the CAG cell ID from the NG-RAN 106a or from the UE 104 in the registration request message. The AMF / SEAF 202 includes the received SUCI of the UE 104, the CAG ID of the requested CAG cell / NPN 102b, and other parameters in at least one of a Nausf_XXX request message and a Nausf_UEAuthentication_Authenticate request message. The AMF / SEAF 202 sends at least one of a Nausf_XXX request message and a Nausf_UEAuthentication_Authenticate request message to the AUSF 204 .
[0084] The AUSF 204 includes the received SUCI of the UE 104 , the CAG ID of the requested CAG cell / NPN 102 b , and other parameters in at least one of a Nudm_XXX request message and a Nudm_UEAuthentication_Get_Request message for transmission to the UDM 206 .
[0085] In one embodiment, upon receiving the registration request message including the SUCI and the CAG ID from the AUSF 204, the UDM 206 exposes the SUCI as the SUPI (per 3GPP TS 33.501) and derives the allowed list of CAG cells of the UE 104 based on the SUPI. The UDM 206 verifies whether the UE 104 has the authority of the requested CAG cell / NPN 102b based on the allowed list of CAG cells of the UE 104 and the received CAG ID of the requested CAG cell / NPN 102b. Upon verifying that the UE 104 has the authority of the requested CAG cell / NPN 102b, the UDM 206 sends an acceptance message to the AUSF 204 in at least one of a Nudm_XXX response message and a Nudm_UEAuthentication_Get_Response message. The AUSF 204 also forwards the acceptance message in at least one of a Nausf_XXX response message and a Nausf_UEAuthentication_Authenticate response message to the AMF / SEAF 202. The AMF / SEAF 202 may further perform a primary authentication procedure to authenticate the UE 104 for accessing the CAG cell / NPN 102b.
[0086] Upon verifying that the UE 104 does not have the authority for the requested CAG cell / NPN 102b, the UDM 206 sends a CAG cell reject message together with the SUPI of the UE 104 in a Nausf_XXX response message and a Nausf_UEAuthentication_Authenticate response message to the AUSF 204. The AUSF 204 forwards the received CAG cell reject message to the AMF / SEAF 202 in at least one of the Nausf_XXX response message and the Nausf_UEAuthentication_Authenticate response message. The AMF / SEAF 202 rejects the registration request message of the UE 104 with an appropriate cause value.
[0087] In one embodiment, upon receiving the registration request message including the SUCI and the CAG ID from the AUSF 204, the UDM 206 reveals the SUCI as the SUPI and derives the allowed list of CAG cells of the UE 104 based on the SUPI. The UDM 206 may also send the allowed list of CAG cells of the UE 104 to the AUSF 204 in at least one of the Nausf_XXX response message and the Nausf_UEAuthentication_Authenticate response message for verifying the authority of the UE 104. Based on the received allowed list of CAG cells from the UDM 206 and the received CAG ID of the requested CAG cell from the AMF / SEAF 202, the AUSF 204 verifies whether the UE 104 has the authority to access the requested CAG cell / NPN 102b. Upon verifying that the UE 104 has the authority to access the requested CAG cell / NPN 102b, the AUSF 204 forwards an acceptance message in at least one of a Nausf_XXX response message and a Nausf_UEAuthentication_Authenticate response message to the AMF / SEAF 202. The AMF / SEAF 202 may further perform a primary authentication procedure to authenticate the UE 104 for accessing the CAG cell / NPN 102b.
[0088] When it is verified that the UE 104 does not have the authority for the requested CAG cell / NPN 102b or if the AUSF 204 does not receive the allowed list of CAG cells from the UDM 206, the AUSF 204 sends a CAG cell rejection message to the AMF / SEAF 202. The AUSF 204 may send the CAG cell rejection message in at least one of a Nausf_XXX response message and a Nausf_UEAuthentication_Authenticate response message to the AMF / SEAF 202. The AMF / SEAF 202 then rejects the registration request message of the UE 104 with an appropriate cause value.
[0089] Embodiments herein enable the UDM 206 of the 5GC 108a to verify the authority of the UE 104 to access the CAG cell / NPN 102b by communicating directly with the AMF / SEAF 202. In order to access the CAG cell / NPN 102b or the service provided by the NPN 102b, the UE 104 sends a registration request together with the SUCI to the NG-RAN 106a. The NG-RAN 106a forwards the received SUCI of the UE 104 to the AMF / SEAF 202. The AMF / SEAF 202 may receive the SUCI from the NG-RAN 106a and the CAG cell ID from the NG-RAN 106a or from the UE 104 in the registration request message. The AMF / SEAF 202 directly requests the UDM 206 to verify whether the UE 104 has the authority to access the CAG cell / NPN 102b. In one embodiment, the AMF / SEAF 202 may directly request the UDM 206 to verify the authority of the UE 104 through a service interface provided by the UDM 206, such as but not limited to a Nudm interface based on Nudm_XXX, an N8 interface, Nudm_UEVerifyCAGAccess_Get, etc. The AMF / SEAF 202 includes the received SUCI of the UE 104, the CAG ID of the requested CAG cell / NPN 102b, and other parameters in at least one of a Nudm_XXX request message and a Nudm_UEVerifyCAGAccess_Get request message and sends the message to the UDM 206.
[0090] In response to the request by the AMF / SEAF 202, the UDM 206 discloses the received SUCI as the SUPI and retrieves the allowed list of the CAG cell of the UE 104 based on the disclosed SUPI. The UDM 206 verifies whether the UE 104 has the authority to access the CAG cell / NPN 102b using the allowed list of the CAG cell of the UE 104 and the received CAG ID of the requested CAG cell / NPN 102b. After verifying that the UE 104 has the authority to access the CAG cell / NPN 102b, the UDM 206 may send an acceptance message to the AMF / SEAF 202, and the AMF / SEAF 202 may further perform a primary authentication procedure to authenticate the UE 104 for accessing the CAG cell / NPN 102b. The UDM 206 may send an acceptance message to the AMF / SEAF 202 in at least one of a Nudm_XXX response message and a Nudm_UEVerifyCAGAccess_Get response message.
[0091] Upon verifying that the UE 104 does not have the authority to access the CAG cell / NPN 102b, the UDM 206 may send a rejection message indicating that the UE 104 does not have the authority to access the CAG cell / NPN 102b to the AMF / SEAF 202. The UDM 206 may send the rejection message to the AMF / SEAF 202 in at least one of a Nudm_XXX response message and a Nudm_UEVerifyCAGAccess_Get response message. Upon receiving the rejection message from the UDM 206, the AMF / SEAF 202 rejects the registration request of the UE 104 and sends the rejection message to the UE 104 together with an appropriate cause value.
[0092] Embodiments herein enable the UDM to verify the authority of the UE 104 to access the CAG cell / NPN 102b upon receiving the SUPI from the AMF / SEAF 202. In one embodiment, the UE 104 initiates a service request procedure for accessing the CAG cell / NPN 102b by sending a service request message to the AMF / SEAF 202 via the NG-RAN 106a. In one embodiment, when the AMF / SEAF 202 may not be able to reveal the SUPI of the UE 104, the UE 104 may initiate a request procedure for accessing the CAG cell / NPN 102b by sending a registration request message including the SUCI of the UE 104 to the AMF / SEAF 202 via the NG-RAN 106a. The AMF / SEAF 202 may receive the CAG ID of the requested CAG cell / NPN 102b from the NG-RAN 106a or from the UE 104 in the service request message. Upon receiving the service request from the UE 104, the AMF / SEAF 202 may reveal the SUPI of the UE 104 (e.g., 5G-GUTI from the UE, etc.). If the AMF / SEAF 202 does not have the information (the allowed list of the CAG cells of the UE 104) to verify the authority of the UE 104 to access the CAG cell, the AMF / SEAF 202 provides the SUPI of the UE 104 and the CAG ID of the requested CAG cell to the UDM 206 through a Nudm_XXX message. The UDM 206 performs the verification of the UE's authority to the CAG cell. If the UDM 206 cannot verify the UE's authority to access the CAG cell, the AMF / SEAF 202 sends a NAS reject message with an appropriate cause value to the UE 104. If the UDM 206 is able to verify the UE's authority to access the CAG cell, the AMF / SEAF 202 should further proceed with the NAS / N2 procedure (registration request procedure or path switch procedure or N2 HO procedure).
[0093] Embodiments herein enable the AMF 202 to verify the authority of the UE 104 to access the CAG cell / NPN 102b. The UE 104 initiates a registration procedure for accessing the CAG cell / NPN 102b by sending a Registration Request message including a SUCI to the AMF 202 via the NG-RAN 106a. The AMF 202 may receive the CAG ID of the requested CAG cell / NPN 102b from the NG-RAN 106a or from the UE 104 in the Registration Request message. The AMF / SEAF 202 requests the UDM 206 for the SUPI and the allowed list of CAG cells by forwarding the SUCI of the UE 104 to the UDM 206. In one embodiment, the AMF / SEAF 202 may forward the SUCI of the UE 104 to the UDM 206 in at least one of a Nudm_XXX request message and a Nudm_SDM_Get request message.
[0094] Upon receiving the SUCI of UE 104 from AMF / SEAF 202, UDM 206 exposes the SUCI of UE 104 as the SUPI and retrieves the allowed list of CAG cells of UE 104 based on the exposed SUPI. In one embodiment, UDM may send the SUPI of UE 104 and the allowed list of CAG cells of UE 104 to AMF / SEAF 202 in at least one of a Nudm_XXX response message and a Nudm_SDM_Get response message.
[0095] Upon receiving the allowed list of CAG cells of UE 104 from UDM 206, AMF / SEAF 202 verifies whether the CAG ID of the requested CAG cell exists in the allowed list of CAG cells. If the CAG ID of the requested CAG cell exists in the allowed list, AMF / SEAF 202 determines that UE 104 has the authority of CAG cell / NPN 102b, and further proceeds with the primary authentication process to authenticate UE 104 for accessing NPN 102b. If the CAG ID of the requested CAG cell does not exist in the allowed list or if AMF / SEAF 202 does not receive the allowed list from UDM 206, AMF / SEAF 202 determines that UE does not have the authority of CAG cell / NPN 102b. Thereafter, AMF / SEAF 202 rejects the registration request of UE 104 with an appropriate cause value.
[0096] Embodiments herein enable the CAG server 110 to verify the authority of the UE 104 to access the CAG cell / NPN 102a upon receiving a request from the UDM 206. The UDM 206 receives a registration request message of the UE 104 including the SUCI and CAG ID of the UE 104 from the AMF / SEAF 202 or the AUSF 204. The UDM 206 checks whether the CAG ID is included in the registration request message. If the CAG ID is included in the registration request message, the UDM 206 exposes the SUCI of the UE 104 as the SUPI. The UDM 206 forwards the SUPI of the UE 104 and the CAG ID of the requested CAG cell / NPN 102b to the CAG server 110 through a service-based interface provided by the CAG server 110. In one example, the service-based interface may be Ncag_XXX, etc. The CAG server 110 retrieves the allowed list of CAG cells of the UE 104 based on the SUPI received from the UDM 206. Based on the retrieved allowed list of CAG cells and the CAG ID of the requested CAG cell, the CAG server 110 verifies whether the UE 104 has the authority to access the requested CAG cell. The CAG server 110 sends the result of the verification (acceptance / rejection) to the UDM 206. Based on the response from the CAG server 110, the UDM 206 can further proceed with the registration request of the UE 104 or reject the registration request of the UE 104.
[0097] Embodiments herein enable the CAG server 110 to verify the authority of the UE 104 to access the CAG cell / NPN 102a upon receiving a request from the AMF / SEAF 202. The CAG server 110 receives a registration request from the UE 104 from the AMF / SEAF 202, wherein the registration request includes the SUCI of the UE 104 and the CAG ID of the requested CAG cell / NPN 102b. Upon receiving the registration request from the UE 104, the CAG server 110 forwards the SUCI of the UE 104 to the UDM 206 by requesting the SUPI of the UE 104. The CAG server 110 may forward the SUCI of the UE 104 to the UDM 206 in a Nudm_XXX message.
[0098] Upon receiving the NUdm_XXX request message, the UDM 206 exposes the obtained SUCI as the SUPI. The UDM 206 provides the SUPI of the UE 104 to the CAG server in a Nudm_XXX response message. Upon receiving the SUPI from the UDM 206, the CAG server 110 retrieves the allowed list of the CAG cells of the UE 104. Based on the retrieved allowed list of the CAG cells and the CAG ID of the requested CAG cell, the CAG server 110 verifies whether the UE 104 has the authority to access the requested CAG cell. The CAG server 110 sends the result of the verification (acceptance / rejection) to the AMF / SEAF 202. Based on the response from the CAG server 110, the AMF / SEAF 202 may further proceed with the registration request of the UE 104 or reject the registration request of the UE 104.
[0099] Embodiments herein enable the CAG server 110 to verify whether the UE 104 has the authority to access the CAG cell / NPN 102b upon receiving a request from the AUSF 204. The AMF / SEAF 202 receives a registration request from the UE 104 through the NG-RAN 106a, wherein the registration request may include the SUCI of the UE 104 and the CAG ID of the requested CAG cell / NPN 102b. The AMF / SEAF 202 includes the SUCI of the UE 104, the CAG ID of the requested CAG cell, and other parameters in a Nausf_XXX request message and sends the Nausf_XXX request message to the AUSF 204. The AUSF 204 includes the SUCI of the UE 104, the CAG ID of the requested CAG cell, and other parameters in an Ncag_XXX request message and sends the Ncag_XXX request message to the CAG server 110.
[0100] Upon receiving the Ncag_XXX request message, the CAG server 110 discloses SUCI as SUPI and retrieves the allowed list of CAG cells / NPN 102b based on the disclosed SUPI. Based on the retrieved allowed list of CAG cells and the CAG ID of the requested CAG cell, the CAG server 110 verifies whether the UE 104 has the authority to access the requested CAG cell. If the UE 104 has the authority to access the requested CAG cell, the CAG server 110 includes an acceptance message to the AUSF 204 and the allowed list of CAG cells in the Ncag_XXX response message. Upon receiving the acceptance message from the CAG server 110, the AUSF 204 may further proceed with the registration request of the UE 104. If the UE 104 does not have the authority to access the requested CAG cell, the CAG server 110 includes a rejection message to the AUSF 204 and the allowed list of CAG cells in the Ncag_XXX response message. Upon receiving the rejection message from the CAG server 110, the AUSF 204 includes the CAG cell rejection message in a Nausf_XXX response message and sends the Nausf_XXX response message to the AMF / SEAF 202. The AMF / SEAF 202 may further reject the registration request of the UE 104.
[0101] Embodiments herein enable the CAG server 110 to verify the authority of the UE 104 to access the CAG cell / NPN 102b upon receiving the SUPI from the AMF / SEAF 202. The UE 104 initiates a request procedure for accessing the CAG cell / NPN 102b by sending a service request message to the AMF / SEAF 202 via the NG-RAN 106a. The AMF / SEAF 202 may receive the CAG ID of the requested CAG cell / NPN 102b from the NG-RAN 106a or from the UE 104 in a registration request message. Upon receiving the request from the UE 104, the AMF / SEAF 202 may reveal the SUPI of the UE 104 (e.g., 5G-GUTI from the UE, etc.). If the AMF / SEAF 202 does not have information to verify the authority of the UE 104 to access the CAG cell / NPN 102b, the AMF / SEAF 202 provides the SUPI of the UE 104 and the CAG ID of the requested CAG cell to the CAG server 110 in an Ncag_XXX request message. Upon receiving the SUPI from the AMF / SEAF 202, the CAG server 110 retrieves the allowed list of the CAG cell of the UE 104. Based on the retrieved allowed list of the CAG cell and the CAG ID of the requested CAG cell, the CAG server 110 verifies whether the UE 104 has the authority to access the requested CAG cell. The CAG server 110 sends the result of the verification (acceptance / rejection) to the AMF / SEAF 202 in an Ncag_XXX response message. Based on the response from the CAG server 110, the AMF / SEAF 202 may further proceed with the registration request of the UE 104 or reject the registration request of the UE 104.
[0102] Figure 1A , Figure 1B , Figure 1C and Figure 2 Various elements / nodes / components of wireless network 100 are shown, but it should be understood that other embodiments are not limited thereto. In other embodiments, wireless communication system 100 may include fewer or greater numbers of units. In addition, the labels or names of the units are used for illustrative purposes only and do not limit the scope of the embodiments herein. One or more units can be combined together to perform the same or substantially similar functions in wireless network 100.
[0103] 3GPP TS 23.501 specifies a public network integrated (non-standalone) non-public network as a non-public network (NPN) deployed with the support of a public PLMN using a closed access group (CAG) and / or network slicing. When a large number of UEs (especially in industrial / cellular / large-scale IoT) that are rogue or malfunctioning or malicious (compromised or introduced by an attacker) with or without a valid subscription and unauthorized to access a CAG cell perform a registration procedure to access the network via a CAG cell, then there is an overhead (signaling and computation) on the network and especially in the UDM, AMF and gNB, because the network needs to hide the SUCI and perform an authentication procedure and then check whether the UE has authorization for CAG cell access. Such attempts to access the NPN via a CAG cell in a specific CAG cell or distributed across different CAG cells will result in a (distributed) denial of service ((D)DoS) attack on the 5G system. The present disclosure provides a novel mechanism for the network to verify the registration request of a UE via a CAG cell without performing a primary authentication. This method enables the network (UDM / AUSF) to verify the subscription of the UE to access the CAG cell (where the UE is requesting access) based on the UE's subscription hidden identifier (SUCI) before performing primary authentication. The UDM receives the CAG identifier and the UE's subscription identity from the serving network AMF (via AUSF), and the UDM performs a CAG access check before further proceeding with the authentication process. By performing the check at the UDM (rather than performing the check at the serving network (AMF)), the overhead on the network is minimized and (D)DoS attacks on the network are mitigated without reducing the level of 5GS security. According to various embodiments, the UDM performs a check on the UE's access to the CAG cell and further proceeds with the primary authentication process based on the result of the CAG cell access check. The serving network (AMF) sends the CAG ID (the identifier of the CAG cell to which the UE is requesting access) to the UDM via the AUSF.
[0104] Figure 3 301 is a sequence diagram depicting verification of the authority of a UE 104 to access a CAG cell at a UDM of a 5GC 108a according to an embodiment as disclosed herein. In step 301, the UE 104 sends a registration request to the AMF / SEAF 202 via the NG-RAN 106a to access a CAG cell / NPN 102b. The registration request includes the SUCI of the UE 104. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b in the registration request. In one embodiment, the NG-RAN 106a may send all CAG IDs of the serving CAG ID to the AMF / SEAF 202 together with the registration request.
[0105] At step 302, AMF / SEAF 202 sends an authentication request message (Nudm_UEAuthentication_Authenticate request) to AUSF 204 by including the SUCI of UE 104, the CAG ID of the requested CAG cell and other parameters (eg, SN name, etc.) in the message.
[0106] In step 303 , the AUSF 204 includes the received SUCI of the UE 104 , the CAG ID of the requested CAG cell, and other parameters in an authentication get request (Nudm_UEAuthentication_Get_Request) message and sends the authentication get request message to the UDM / ARPF / SIDF 206 .
[0107] At step 304, the UDM / ARPF / SIDF 206 verifies the authority or authorization of the UE 104 to access the requested CAG cell / NPN 102b upon receiving the authentication acquisition request message from the AUSF 204. In one embodiment, the UDM / ARPF / SIDF 206 verifies the authority or authorization of the UE 104 to access the requested CAG cell / NPN 102b before performing a primary authentication procedure. The UDM / ARPF / SIDF 206 reveals the received SUCI as the SUPI and retrieves an allowed list of CAG cells based on the SUPI. The UDM / ARPF / SIDF 206 verifies whether the received CAG ID of the requested CAG cell exists in the allowed list of the CAG cell based on the SUPI. Upon verifying that the received CAG ID of the requested CAG cell exists in the allowed list of the CAG cell based on the SUPI, the UDM / ARPF / SIDF 206 determines that the UE has the authority or subscription or that the UE is a UE authorized to access the CAG cell / NPN 102b. Thereafter, the UDM / ARPF / SIDF 206 generates an authentication vector based on the SUPI of the UE 104 and performs a primary authentication procedure (as specified in 3GPP TS 33.501) for authenticating the UE 104 in order to allow the UE 104 to access the NPN 102b / services provided by the NPN 102b. Upon verifying that the received CAG ID of the requested CAG cell does not exist in the allowed list of CAG cells based on the SUPI, the UDM / ARPF / SIDF 206 determines that the UE does not have the authority or subscription or the UE is not authorized to access the CAG cell / NPN 102b. Then, the UDM / ARPF / SIDF 206 includes error information in the authentication get response message (Nudm_UEAuthentication_Get_Response).
[0108] In step 305, UDM / ARPF / SIDF 206 sends an authentication acquisition response message (e.g., 403 Prohibited, etc.) to AUSF. In step 306, AUSF 204 inserts a rejection message of the received authentication acquisition response message in the authentication response (Nausf_UEAUthentication_Authenticate response). AUSF 204 sends the authentication response (e.g., 403 Prohibited, etc.) to AMF / SEAF 202. In step 307, AMF / SEAF 202 rejects the registration request of UE 104 upon receiving the rejection message from AUSF 204. AMF / SEAF 202 sends a rejection message with an appropriate cause value (e.g., #12, #13, #15, #76, etc.) to UE 104, where the appropriate cause value indicates that CAG cell access is not allowed. Therefore, verifying the UE 104's authority / authorization to access the CAG cell at the UDM before performing primary authentication minimizes the signaling overhead on the 5GC 108a and mitigates DoS attacks.
[0109] According to various embodiments, a method for controlling the authority of at least one user equipment (UE) to access at least one non-public network (NPN) in a network, the method comprising: requesting, by at least one UE, a public land mobile network (PLMN) to access at least one NPN through at least one closed access group (CAG) cell; verifying, by a core network (CN) of the PLMN, the authority of at least one UE to access the requested at least one NPN through at least one CAG cell; and performing, by the CN, a primary authentication procedure to allow at least one UE to access the at least one NPN through at least one CAG cell based on the verification of the authority of at least one UE to access the requested at least one NPN through at least one CAG cell.
[0110] In some embodiments, at least one NPN is deployed in conjunction with a PLMN using at least one CAG cell.
[0111] In some embodiments, the at least one NPN includes at least one of a dependent NPN or an independent NPN.
[0112] In some embodiments, at least one of the unified data management (UDM), access and mobility management function (AMF), or authentication server function (AUSF) of the CN verifies the authority of at least one UE to access at least one NPN requested through at least one CAG cell.
[0113] In some embodiments, a CAG server coupled to the CN verifies the authority of at least one UE to access the requested at least one NPN.
[0114] In some embodiments, requesting access to at least one NPN by at least one UE includes sending a request including a Subscription Hidden Identifier (SUCI) of the at least one UE to a Radio Access Network (RAN) of the PLMN.
[0115] In some embodiments, the method further includes: adding, by a radio access network (RAN), at least one CAG identifier (CAG ID) of at least one NPN requested by at least one UE; and sending, by the RAN, a received subscription concealed identifier (SUCI) of the UE and the at least one CAG ID of the requested at least one NPN to the CN.
[0116] In some embodiments, requesting access to at least one NPN by at least one UE includes sending a request including a subscription concealed identifier (SUCI) of the at least one UE and at least one CAG identifier (CAG ID) of the requested at least one NPN to a radio access network (RAN) of the PLMN.
[0117] In some embodiments, the CN verifies the authority of at least one UE to access at least one NPN based on a received request message including at least one CAG ID.
[0118] In some embodiments, verifying, by the CN, the authority of the at least one UE includes: receiving a subscription concealed identifier (SUCI) of the at least one UE and at least one CAG identifier (CAGID) of the requested at least one NPN from a radio access network (RAN); deriving an allowed list of CAG cells of the at least one UE based on the received SUCI of the at least one UE; and verifying the authority of the at least one UE to access the requested at least one NPN using the derived allowed list of CAG cells and the received at least one CAG ID of the requested at least one NPN.
[0119] In some embodiments, deriving the allowed list of the CAG cell of the at least one UE includes: revealing the received SUCI of the at least one UE as a subscription permanent identifier (SUPI); mapping the revealed SUPI of the at least one UE with a mapping of the allowed list of the CAG cell and the SUPIs of the plurality of UEs; and deriving the allowed list of the CAG cell of the at least one UE based on the mapping of the relevant SUPI with the revealed SUPI of the at least one UE.
[0120] In some embodiments, verifying the authority of at least one UE using the derived CAG cell's allowed list and the received CAG ID of at least one requested NPN includes: determining whether the received at least one CAG ID of at least one requested NPN exists in the derived CAG cell's allowed list; verifying that at least one UE has authority to access the requested at least one NPN based on the presence of the received at least one CAG ID of at least one requested NPN in the derived CAG cell's allowed list; and verifying that at least one UE does not have authority to access the requested at least one NPN based on the presence of the received at least one CAG ID of at least one requested NPN not in the derived CAG cell's allowed list.
[0121] In some embodiments, the method also includes rejecting a request of at least one UE when it is verified that the at least one UE does not have authority to access the requested at least one NPN; and sending a rejection message to the at least one UE together with a cause value, wherein the cause value indicates at least one reason for the error in rejecting the request of the at least one UE.
[0122] In some embodiments, performing a primary authentication process includes: generating an authentication vector based on a revealed subscription permanent identifier (SUPI) of at least one UE based on verifying that the at least one UE has authority to access the requested at least one NPN; authenticating the at least one UE based on the generated authentication vector based on determining that the at least one UE has NPN authority to access the requested at least one NPN through a PLMN; and enabling the at least one UE to access the requested at least one NPN based on the at least one UE having NPN authority to access the requested at least one NPN through a PLMN.
[0123] According to various embodiments, a network includes at least one user equipment (UE); at least one non-public network (NPN); and a public land mobile network (PLMN). At least one NPN is deployed in conjunction with the PLMN, the PLMN includes at least one cellular network consisting of a radio access network (RAN) and a core network (CN), at least one UE is configured to request the PLMN to access the at least one NPN through at least one closed access group (CAG) cell, and the CN is configured to: verify the authority of the at least one UE to access the requested at least one NPN through the at least one CAG cell, and perform a primary authentication process to allow the at least one UE to access the at least one NPN through the at least one CAG cell based on the at least one UE's authority to access the requested at least one NPN through the at least one CAG cell being verified.
[0124] In some embodiments, at least one NPN is deployed in conjunction with a PLMN using at least one CAG cell.
[0125] In some embodiments, the at least one NPN includes at least one of a dependent NPN or an independent NPN.
[0126] In some embodiments, at least one of the unified data management (UDM), access and mobility management function (AMF), or authentication server function (AUSF) of the CN is further configured to verify the authority of at least one UE to access at least one NPN requested through at least one CAG cell.
[0127] In some embodiments, the PLMN further comprises a CAG server coupled to the CN, the CAG server being configured to verify the authority of the at least one UE to access the requested at least one NPN.
[0128] In some embodiments, the at least one UE is further configured to send a request including a Subscription Concealment Identifier (SUCI) of the at least one UE to the RAN requesting access to the PLMN of the at least one NPN.
[0129] In some embodiments, at least one RAN is further configured to: add at least one CAG identity (CAG ID) of at least one NPN requested by at least one UE; and send the received UE's subscription concealment identifier (SUCI) and the requested CAG ID of at least one NPN to the CN.
[0130] In some embodiments, the at least one UE is further configured to send a request including a Subscription Concealment Identifier (SUCI) of the at least one UE and a CAG Identifier (CAG ID) of the requested at least one NPN to the RAN of the PLMN.
[0131] In some embodiments, the CN is further configured to verify the authority of the at least one UE to access the at least one NPN based on the received request message including the at least one CAG ID.
[0132] In some embodiments, the CN is further configured to: receive a subscription concealed identifier (SUCI) of at least one UE and at least one CAG identifier (CAG ID) of the requested at least one NPN from the RAN; derive an allowed list of CAG cells of the at least one UE based on the received SUCI of the at least one UE; and verify the authority of the at least one UE to access the requested at least one NPN using the derived allowed list of CAG cells and the received at least one CAG ID of the requested at least one NPN.
[0133] In some embodiments, the CN is further configured to: disclose the received SUCI of at least one UE as a subscription permanent identifier (SUPI); map the disclosed SUPI of at least one UE with a mapping of an allowed list of CAG cells and SUPIs of multiple UEs; and derive an allowed list of CAG cells of at least one UE based on the mapping of the relevant SUPI with the disclosed SUPI of at least one UE.
[0134] In some embodiments, the CN is further configured to: determine that at least one CAG ID of at least one requested NPN that has been received exists in the allowed list of the derived CAG cell; verify that at least one UE has the authority to access the at least one requested NPN based on the fact that at least one CAG ID of at least one requested NPN that has been received exists in the allowed list of the derived CAG cell; and verify that at least one UE does not have the authority to access at least one CAG cell of at least one requested NPN based on the fact that the CAG ID of at least one requested NPN that has been received does not exist in the allowed list of the derived CAG cell.
[0135] In some embodiments, the CN is further configured to: reject the request of at least one UE upon verifying that the at least one UE does not have the authority to access at least one CAG ID of the requested at least one NPN; and send a rejection message to the at least one UE together with a cause value, wherein the cause value indicates at least one reason for the error in rejecting the request of the at least one UE.
[0136] In some embodiments, the CN is further configured to: generate an authentication vector based on a received subscription permanent identifier (SUPI) of at least one UE based on verifying that the at least one UE has authority to access the requested at least one NPN; authenticate the at least one UE based on the generated authentication vector based on determining that the at least one UE has NPN authority to access the requested at least one NPN through the PLMN; and enable the at least one UE to access the requested at least one NPN based on the at least one UE having NPN authority to access the requested at least one NPN through the PLMN.
[0137] According to various embodiments, a network includes at least one user equipment (UE); at least one non-public network (NPN); and a public land mobile network (PLMN). The at least one NPN is deployed in conjunction with the PLMN through at least one closed access group (CAG) cell, the PLMN includes at least one cellular network consisting of a radio access network (RAN) and a core network (CN), at least one UE is configured to request the PLMN for access to the at least one NPN, and the CN includes a unified data management (UDM) configured to: verify the authority of the at least one UE to access the requested at least one NPN, and initiate a primary authentication process based on the at least one UE's authority to access the requested at least one NPN being verified.
[0138] In some embodiments, at least one UE is further configured to send a request including a subscription concealment identifier (SUCI) of at least one UE to the RAN requesting access to the PLMN of at least one NPN, and the RAN is configured to: add a CAG identifier (CAG ID) of at least one NPN requested by the at least one UE, and send the received subscription concealment identifier (SUCI) of the UE and the requested CAG ID of at least one NPN to the CN.
[0139] In some embodiments, the at least one UE is further configured to send a request including a Subscription Concealment Identifier (SUCI) of the at least one UE and a CAG Identifier (CAG ID) of the requested at least one NPN to the RAN of the PLMN.
[0140] In some embodiments, the CN also includes an access and mobility management function (AMF) and an authentication server function (AUSF), the AMF being configured to: receive a SUCI of at least one UE and a CAG ID of at least one NPN requested from the RAN, insert the received SUCI of at least one UE and the CAG ID of at least one NPN requested into a first authentication request message, and send the first authentication request message to the AUSF, and the AUSF being further configured to: derive the SUCI of at least one UE and the CAG ID of at least one NPN requested based on the received first authentication request message, insert the derived SUCI of at least one UE and the CAG ID of at least one NPN requested into a first authentication acquisition request message, and send the authentication acquisition request message to the UDM.
[0141] In some embodiments, the UDM is further configured to: receive a SUCI of the at least one UE and a CAG ID of the requested at least one NPN from the AUSF, reveal the received SUCI of the at least one UE as a subscription permanent identifier (SUPI), map the revealed SUPI of the at least one UE with a mapping of an allowed list of a CAG cell and SUPIs of multiple UEs, retrieve the allowed list of the CAG cell of the at least one UE based on the mapping of the relevant SUPI with the revealed SUPI of the at least one UE, verify that the at least one UE has permission to access the requested at least one NPN based on the received CAG ID of the requested at least one NPN being present in the allowed list of the retrieved CAG cell, and verify that the at least one UE does not have permission to access the requested at least one NPN based on the received CAG ID of the requested at least one NPN not being present in the allowed list of the retrieved CAG cell.
[0142] In some embodiments, the UDM is further configured to: insert a rejection message and the SUPI of at least one UE in a second authentication acquisition request message based on verifying that the at least one UE does not have access to the requested at least one UE, and send an authentication acquisition response message to the AUSF, the AUSF is further configured to: derive a rejection message based on the received second authentication acquisition response message and insert the derived rejection message into the second authentication response message, and send the second authentication response message to the AMF, and the AMF is further configured to: reject the request of the at least one UE based on receiving the rejection message from the AUSF; and send a rejection message with an appropriate cause value to the at least one UE via the RAN, wherein the cause value indicates at least one cause of an error for rejecting the request of the at least one UE.
[0143] In some embodiments, the UDM is further configured to: generate an authentication vector based on the received SUCI of at least one UE based on verifying that the at least one UE has the authority to access the requested at least one NPN, and send the authentication vector to the AMF through the AUSF, and the AMF is further configured to: authenticate the at least one UE based on the received authentication vector to determine that the at least one UE has the NPN authority to access the requested at least one NPN through the PLMN; and enable the at least one UE to access the requested at least one NPN based on the at least one UE having the authority to access the requested at least one NPN through the PLMN.
[0144] According to various embodiments, a core network (CN) of a public land mobile network (PLMN), wherein the PLMN is combined with at least one non-public network (NPN) and connected to at least one user equipment (UE), wherein the CN is configured to: receive a request for access to at least one NPN from at least one UE through a radio access network (RAN); verify the authority of the at least one UE to access the requested at least one NPN; and perform a primary authentication procedure based on the at least one UE's authority to access the requested at least one NPN being verified.
[0145] In some embodiments, the request of the at least one UE includes a subscription concealment identifier (SUCI) of the at least one UE and a closed access group (CAG ID) of the at least one NPN requested by the at least one UE.
[0146] In some embodiments, the CN is further configured to: reveal a received subscription concealed identifier (SUCI) of the at least one UE as a subscription permanent identifier (SUPI), map the revealed SUPI of the at least one UE with a mapping of an allowed list of a CAG cell and SUPIs of multiple UEs, retrieve the allowed list of the CAG cell of the at least one UE based on the mapping of the relevant SUPI with the revealed SUPI of the at least one UE, verify that the at least one UE has the authority to access the requested at least one NPN based on the received closed access group identifier (CAG ID) of the requested at least one NPN being present in the allowed list of the retrieved CAG cell, and verify that the at least one UE does not have the authority to access the requested at least one NPN based on the received CAG ID of the requested at least one NPN not being present in the allowed list of the retrieved CAG cell.
[0147] In some embodiments, the CN is further configured to: reject the request of at least one UE based on verifying that the at least one UE does not have the authority to access the requested at least one NPN, and send a rejection message to the at least one UE through the RAN together with a cause value, wherein the cause value indicates at least one reason for the error used to reject the request of the at least one UE.
[0148] Figure 44 is a sequence diagram depicting verification of the authority of the UE 104 to access a CAG cell at the UDM 206 of the 5GC 108a by communicating directly with the AMF / SEAF 202 according to an embodiment as disclosed herein. In step 401, the UE 104 sends a registration request including a SUCI to the AMF / SEAF 202 through the NG-RAN 106a to access the CAG cell / NPN 102b. The NG-RAN 106a may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202, or the UE 104 may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a.
[0149] In step 402 , the AMF / SEAF 202 inserts the received SUCI, CAG ID and other parameters (eg, SN name) of the UE 104 into a Nudm_XXX request message and sends the Nudm_XXX request message to the UDM 206 .
[0150] In step 403, the UDM 206 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b upon receiving the authentication acquisition request message from the AMF / SEAF 202. In one embodiment, the UDM 206 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b before performing a primary authentication procedure. The UDM 206 reveals the received SUCI as the SUPI and retrieves the allowed list of the CAG cell based on the SUPI. The UDM 206 verifies whether the UE 104 has the authority to access the requested CAG cell / NPN 102b according to the allowed list of the CAG cell retrieved based on the SUPI of the UE 104 and the CAG ID of the requested CAG cell. Upon verifying that the UE 104 has the authority to access the requested CAG cell, the UDM 206 inserts an acceptance message, the allowed list of the CAG cell of the UE 104, etc. in the Nudm_XXX response message. At step 404a, UDM 206 sends a Nudm_XXX response message indicating successful verification to AMF / SEAF 202. At step 405a, upon receiving the Nudm_XXX response message, AMF / SEAF 202 further proceeds with the registration request of UE 104. At step 406a, AMF / SEAF 202 performs a primary authentication procedure (as specified in 3GPP TS 33.501) for authenticating UE 104 in order to allow UE 104 to access NPN 102b / services provided by NPN 102b.
[0151] Upon verifying that UE 104 does not have the authority to access CAG cell / NPN 102b, UDM 206 includes a rejection message and a cause value indicating that UE 104 is not permitted to use the CAG cell in a Nudm_XXX response message. In step 404b, UDM 206 sends a Nudm_XXX response message indicating unsuccessful verification to AMF / SEAF 202. In step 405b, AMF / SEAF 202 rejects the registration request of UE 104. In step 406b, AMF / SEAF 202 sends a response with a rejection message and an appropriate cause value to UE 104.
[0152] Figure 5 5 is a sequence diagram depicting verification of the authority of the UE 104 to access a CAG cell at the UDM 206 by communicating with the AMF / SEAF 202 through a Get Request message and a Get Response message according to an embodiment as disclosed herein. In step 501, the UE 104 sends a registration request including a SUCI to the AMF / SEAF 202 through the NG-RAN 106a in order to access the CAG cell / NPN 102b. The NG-RAN 106a may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202, or the UE 104 may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a.
[0153] At step 502 , the AMF / SEAF 202 inserts the received SUCI, CAG ID and other parameters (eg, SN name) of the UE 104 into a Nudm_UEVerifyCAGAccess_Get request message and sends the Nudm_UEVerifyCAGAccess_Get request message to the UDM 206 .
[0154] In step 503, the UDM 206 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b upon receiving the authentication acquisition request message from the AMF / SEAF 202. In one embodiment, the UDM 206 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b before performing a primary authentication procedure. The UDM 206 reveals the received SUCI as the SUPI and retrieves the allowed list of the CAG cell based on the SUPI. The UDM 206 verifies whether the UE 104 has the authority to access the requested CAG cell / NPN 102b according to the allowed list of the CAG cell retrieved based on the SUPI of the UE 104 and the CAG ID of the requested CAG cell. Upon verifying that the UE 104 has the authority to access the requested CAG cell, the UDM 206 inserts an acceptance message, the allowed list of the CAG cell of the UE 104, etc. in the Nudm_UEVerifyCAGAccess_Get response message. At step 504a, UDM 206 sends a Nudm_UEVerifyCAGAccess_Get response message indicating successful verification to AMF / SEAF 202. At step 505a, upon receiving the Nudm_XXX response message, AMF / SEAF 202 further proceeds with the registration request of UE 104.
[0155] Upon verifying that UE 104 does not have the authority to access CAG cell / NPN 102b, UDM 206 includes a rejection message and a cause value indicating that CAG cell is not allowed for UE 104 in a Nudm_XXX response message. In step 504b, UDM 206 sends a Nudm_XXX response message indicating unsuccessful verification to AMF / SEAF 202. In step 505b, AMF / SEAF 202 rejects the registration request of UE 104. In step 506, AMF / SEAF 202 sends a response with the rejection message and an appropriate cause value to UE 104.
[0156] Figure 66 is a sequence diagram depicting verification of the UE's authority to access a CAG cell at the UDM 206 and / or AUSF 204 of the 5GC 108a according to an embodiment as disclosed herein. In step 601, the UE 104 sends a registration request to access the CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a. The registration request includes the SUCI of the UE 104. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a in the registration request. In one embodiment, the NG-RAN 106a may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request.
[0157] In step 602, AMF / SEAF 202 inserts the received SUCI, CAG ID and other parameters of UE 104 into a Nausf_XXX request message and sends the Nausf_XXX request message to AUSF 204. In step 603, AUSF 204 inserts the received SUCI, CAG ID and other parameters of the Nausf_XXX message into a Nudm_XXX request message. AUSF 204 sends the Nudm_XXX request message to UDM 206.
[0158] At step 604, the UDM 206 exposes the received SUCI as the SUPI and retrieves the allowed list of CAG cells of the UE 104 based on the SUPI. In one embodiment, the UDM 206 uses the allowed list of CAG cells of the UE 104 retrieved based on the SUPI and the received CAG ID of the requested CAG cell / NPN 102b to verify the authority of the UE 104 to access the requested CAG cell / NPN 102b. Upon verifying that the UE has the authority to access the CAG cell / NPN 102b, the UDM 206 initiates a primary authentication procedure (as specified in 3GPP TS 33.501) for authenticating the UE 104 in order to allow the UE 104 to access the NPN 102b / services provided by the NPN 102b. When verifying that UE 104 does not have the authority to access CAG cell / NPN 102b, UDM 206 includes a CAG cell rejection message indicating that CAG cell is not allowed for UE 104 and the UE's SUPI in a Nudm_XXX response message. In step 605, UDM 206 sends a Nudm_XXX response message to AUSF 204 indicating that CAG cell is not allowed.
[0159] In one embodiment, UDM 206 may send the retrieved allowed list of CAG cells to AUSF 204 to perform verification of the authority of UE 104. In this case, at step 605, UDM 206 sends a Nudm_XXX response message including the allowed list of CAG cells to AUSF 204.
[0160] At step 606, the AUSF 204 verifies the authority of the UE 104 to access the CAG cell / NPN 102b using the received allowed list of CAG cells and the CAG ID of the requested CAG cell / NPN 102b.
[0161] In step 607, AUSF 204 sends a CAG cell rejection in a Nausf_XXX response message to AMF / SEAF 202 upon verifying that UE 104 does not have the authority to access the CAG cell or receiving a Nudm_XXX response indicating that CAG cell access is not allowed from UDM 206. In step 608, AMF / SEAF 202 rejects the registration request of UE 104 by sending a rejection message and an appropriate cause value to UE 104.
[0162] Figure 7 is a sequence diagram depicting verification of the authority of a UE 104 to access a CAG cell at the AUSF 204 of a 5GC 108a according to an embodiment as disclosed herein. In step 701, the UE 104 sends a registration request to access a CAG cell / NPN 102b to the AMF / SEAF 202 via the NG-RAN 106a. The registration request includes the SUCI of the UE 104. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF via the NG-RAN 106a in the registration request. In one embodiment, the NG-RAN may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request.
[0163] In step 702, AMF / SEAF 202 inserts the received SUCI, CAG ID and other parameters of UE 104 into a Nausf_UEAuthentication_Authenticate request message and sends the Nausf_UEAuthentication_Authenticate request message to AUSF 204. In step 703, AUSF 204 inserts the received SUCI, CAG ID and other parameters of the Nausf_UEAuthentication_Authenticate request into a Nudm_UEAuthentication_Get_Request message. AUSF 204 sends the Nudm_UEAuthentication_Get_Request message to UDM 206.
[0164] At step 704, UDM 206 exposes the received SUCI as SUPI and retrieves the allowed list of CAG cells of UE 104 based on the SUPI. At step 705, UDM 206 inserts the SUPI of UE 104 and the allowed list of CAG cells in Nudm_UEauthentication_Get_Response and sends Nudm_UEauthentication_Get_Response to AUSF 204.
[0165] In step 706, the AUSF 204 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b using the received allowed list of CAG cells of the UE 104 and the received CAG ID of the requested CAG cell / NPN 102b. Upon verifying that the UE 104 has the authority to access the CAG cell / NPN 102b, the AUSF 204 initiates a primary authentication procedure (as specified in 3GPP TS 33.501) for authenticating the UE 104 so as to allow the UE 104 to access the NPN 102b / services provided by the NPN 102b. Upon verifying that the UE 104 does not have the authority to access the CAG cell / NPN 102b, the AUSF 204 includes a CAG cell rejection message indicating that the CAG cell is not allowed for the UE 104 in the Nausf_UEAuthentication_Authenticate response message. In step 707, the AUSF 204 sends a Nausf_UEAuthentication_Authenticate response message to the AMF / SEAF 202 indicating that the CAG cell is not allowed.
[0166] At step 708, the AMF / SEAF 202 rejects the registration request of the UE 104 by sending a reject message with an appropriate cause value to the UE 104.
[0167] Figure 8 801 is a sequence diagram depicting verification of the authority of a UE 104 to access a CAG cell at a CAG server 110 upon receiving a request from a UDM 206 according to an embodiment as disclosed herein. In step 801, the UDM 206 receives a registration request of a UE 104 requesting access to a CAG cell / NPN 102b, wherein the registration request includes a SUCI of the UE 104 and a CAG ID of the requested CAG cell / NPN 102b. The UDM 206 derives a SUPI of the UE 104 based on the received SUCI. In step 802, the UDM 206 inserts the SUPI of the UE 104 and the CAG ID of the requested CAG cell / NPN 102b in an Ncag_XXX request message. In step 803, the UDM 206 sends the Ncag_XXX request message to the CAG server 110.
[0168] In step 804, the CAG server 110 obtains the allowed list of CAG cells of the UE 104 based on the SUPI of the UE 104 received from the UDM 206. The CAG server 110 verifies the authority of the UE 104 to access the CAG cell / NPN 102b based on the allowed list of CAG cells and the CAG ID of the requested CAG cell. Upon verifying that the UE 104 has the authority to verify the requested CAG cell / NPN 102b, the CAG server 110 inserts an acceptance message in the Ncag_XXX response message. In step 805, the CAG server 110 sends the Ncag-XXX response message including the acceptance message to the UDM 206. In step 806, the UDM 206 may further continue the request process.
[0169] When it is verified that the UE 104 does not have the authority to authenticate the requested CAG cell / NPN 102b, the CAG server inserts a rejection message in the Ncag_XXX response message. In step 805, the CAG server 110 sends the Ncag-XXX response message including the rejection message indicating that the CAG cell access is not allowed to the UDM 206. In step 806, the UDM 206 may reject the registration request of the UE 104 with an appropriate cause value.
[0170] Fig. 9is a sequence diagram depicting verification of the authority of the UE 104 to access a CAG cell at the CAG server 110 upon receiving the SUCI of the UE 104 from the AMF / SEAF 202 according to an embodiment as disclosed herein. At step 901, the UE 104 sends a registration request to the AMF / SEAF 202 through the NG-RAN 106a to access the CAG cell / NPN 102b. The registration request includes the SUCI of the UE 104. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a in the registration request. In one embodiment, the NG-RAN 106a may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request. The AMF / SEAF 202 sends the received SUCI of the UE 104 and the CAG ID of the requested CAG cell / NPN 102 b to the CAG server 110 .
[0171] In step 902, the CAG server 110 inserts the received SUCI into a Nudm_XXX request message and sends the Nudm_XXX request message to the UDM 206. In step 903, the UDM 206 exposes the SUCI as a SUPI. In step 904, the UDM 206 sends the exposed SUPI to the CAG server 110 through a Nudm_XXX response message.
[0172] In step 905, the CAG server 110 obtains the allowed list of CAG cells of the UE 104 based on the SUPI of the UE 104 received from the UDM 206. The CAG server 110 verifies the authority of the UE 104 to access the CAG cell / NPN 102b based on the allowed list of CAG cells and the CAG ID of the requested CAG cell. In step 906, the CAG server 110 sends the result of the verification (acceptance and / or rejection) to the AMF / SEAF 202. The AMF / SEAF 202 further proceeds with the registration request of the UE 104 if the result of the verification is accepted, or the AMF / SEAF 202 rejects the registration request of the UE 104 if the result of the verification is rejected.
[0173] Fig.101 is a sequence diagram depicting verification of the authority of the UE 104 to access a CAG cell at the CAG server 110 upon receiving the SUCI of the UE 104 from the AUSF 204 according to an embodiment as disclosed herein. At step 1001, the UE 104 sends a service request for access to the CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 in a registration request through the NG-RAN 106a. In one embodiment, the NG-RAN 106a may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request.
[0174] At step 1002 , the AMF / SEAF 202 inserts the SUPI of the UE 104 , the CAG ID of the requested CAG cell, and other parameters (eg, SN name) into a Nausf_XXX request message and sends the Nausf_XXX request message to the AUSF 204 .
[0175] In step 1003, the AUSF 204 derives the SUPI of the UE 104, the CAG ID of the requested CAG cell, and other parameters (e.g., SN name) from the received NCag_XXX request message. The AUSF 204 inserts the SUPI of the UE 104, the CAG ID of the requested CAG cell, and other parameters (e.g., SN name) into the NCag_XXX request message and sends the NCag_XXX request message to the CAG server 110.
[0176] At step 1004, the CAG server 110 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b upon receiving the NCag_XXX request message from the AUSF 204. In one embodiment, the CAG server 110 verifies the authority of the UE 104 to access the requested CAG cell / NPN. The CAG server 110 retrieves the allowed list of CAG cells based on the received SUPI. The CAG server 110 verifies whether the UE 104 has the authority to access the requested CAG cell / NPN 102b based on the allowed list of CAG cells retrieved based on the SUPI of the UE 104 and the CAG ID of the requested CAG cell. Upon verifying that the UE 104 has the authority to access the requested CAG cell, the CAG server 110 inserts an acceptance message, the allowed list of CAG cells of the UE 104, etc. in the NCag_XXX response message. At step 1005, the CAG server 110 sends an NCag_XXX response message to the AUSF 204 indicating successful verification. At step 1006 , the AUSF 204 may further proceed with the registration request of the UE 104 upon receiving an acceptance message from the CAG server 110 .
[0177] When verifying that UE 104 does not have the authority to access CAG cell / NPN 102b, CAG server 110 inserts a rejection message in NCag_XXX response message. In step 1005, CAG server 110 sends to AUSF 204 a NCag_XXX response message including a rejection message indicating that CAG cell is not allowed for UE 104.
[0178] In step 1006, the AUSF 204 rejects the service request of the UE 104 upon receiving the rejection message from the CAG server 110. In step 1007, the AUSF 204 sends a Nausf_XXX response message including CAG cell rejection to the AMF / SEAF 202 upon receiving the rejection message from the CAG server 110.
[0179] At step 1008, the AMF / SEAF 202 rejects the registration request of the UE 104 by sending a reject message and an appropriate cause value to the UE 104 upon receiving the reject message from the AUSF 204.
[0180] Fig.11is a sequence diagram depicting verification of the UE's authority to access a CAG cell at the AMF / SEAF 202 according to an embodiment as disclosed herein. At step 1101, the UE 104 sends a registration request to the AMF / SEAF 202 through the NG-RAN 106a requesting access to the CAG cell / NPN 102b. The registration request includes the SUCI of the UE 104. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a in the registration request. In one embodiment, the NG-RAN 106a may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request.
[0181] At step 1102 , the AMF / SEAF 202 inserts the received SUCI of the UE 104 into a Nudm_XXX request message and sends the Nudm_XXX request message to the UDM 206 .
[0182] At step 1103, UDM 206 exposes the received SUCI of UE 104 as SUPI and retrieves the allowed list of CAG cells of UE 104 based on SUPI. If the exposed SUPI is valid, UDM 206 stores the mapping of SUCI to SUPI that can be used during the primary authentication process. At step 1104, UDM 206 sends the SUPI of UE 104 and the allowed list of CAG cells to AMF / SEAF 202 through a Nudm_XXX response message.
[0183] At step 1105, the AMF / SEAF 202 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b based on the received allowed list of CAG cells and the CAG ID of the requested CAG cell / NPN 102b.
[0184] In step 1106, AMF / SEAF 202 further proceeds with the registration request of UE 104 when verifying that the UE has the authority to access the CAG cell.
[0185] At step 1107, AMF / SEAF 202 rejects the registration request of UE 104 by sending a rejection message with an appropriate cause value to UE 104 upon verifying that UE 104 does not have the authority to access the CAG cell.
[0186] Fig.12is a sequence diagram depicting the authorization of a UE to access a CAG cell at the AMF / SEAF 202 by communicating with the UDM 206 through a service interface provided by the UDM 206 according to an embodiment as disclosed herein. At step 1201, the UE 104 sends a registration request to the AMF / SEAF 202 through the NG-RAN 106a requesting access to the CAG cell / NPN 102b. The registration request includes the SUCI of the UE 104. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a in the registration request. In one embodiment, the NG-RAN 106a may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request.
[0187] At step 1202 , the AMF / SEAF 202 inserts the received SUCI of the UE 104 into a Nudm_SDM_Get_Request message and sends the Nudm_SDM_Get_Request message to the UDM 206 .
[0188] At step 1203, UDM 206 exposes the received SUCI of UE 104 as SUPI and retrieves the allowed list of CAG cells of UE 104 based on the SUPI. If the exposed SUPI is valid, UDM 206 stores the mapping of SUCI to SUPI that can be used during the primary authentication process. At step 1204, UDM sends the SUPI of UE 104 and the allowed list of CAG cells to AMF / SEAF 202 via a Nudm_SDM_Get_Response message.
[0189] At step 1205, the AMF / SEAF 202 verifies the authority of the UE 104 to access the requested CAG cell / NPN 102b based on the received allowed list of CAG cells and the CAG ID of the requested CAG cell / NPN 102b.
[0190] At step 1206, AMF / SEAF 202 further proceeds with the registration request of UE 104 upon verifying that the UE has the authority to access the CAG cell.
[0191] At step 1207, AMF / SEAF 202 rejects the registration request of UE 104 by sending a reject message with an appropriate cause value to UE 104 when it is verified that UE 104 does not have the authority to access the CAG cell or when AMF / SEAF 202 does not receive SUPI from UDM 206.
[0192] Fig.13 1301 is a sequence diagram depicting verification of the UE's authority to access a CAG cell at a CAG server by communicating directly with the AMF / SEAF 202 according to an embodiment as disclosed herein. In step 1302, the UE 104 sends a service request for access to a CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 in a request message through the NG-RAN 106a. In one embodiment, the NG-RAN 106a may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request.
[0193] At step 1302, the AMF / SEAF 202 reveals the SUPI of the UE 104. The AMF / SEAF 202 inserts the revealed SUPI of the UE 104, the CAG ID of the requested CAG cell / NPN 102b into a Nudm_XXX request message and sends the Nudm_XXX request message to the CAG server 110.
[0194] In step 1303, the CAG server 110 retrieves the allowed list of CAG cells based on the received SUPI. The CAG server 110 verifies whether the UE 104 has the authority to access the requested CAG cell / NPN 102b according to the allowed list of CAG cells retrieved based on the SUPI of the UE 104 and the CAG ID of the requested CAG cell. Upon verifying that the UE 104 has the authority to access the requested CAG cell, the CAG server 110 inserts an acceptance message and the allowed list of CAG cells of the UE 104 in the NCag_XXX response message. In step 1304, the CAG server 110 sends an NCag_XXX response message indicating successful verification to the AMF / SEAF 202. In step 1305, the AMF / SEAF 202 may further proceed with the registration request of the UE 104 upon receiving the acceptance message from the CAG server.
[0195] When verifying that UE 104 does not have the authority to access CAG cell / NPN 102b, CAG server 110 inserts a rejection message in NCag_XXX response message. In step 1304, CAG server 110 sends an NCag_XXX response message including a rejection message indicating that CAG cell is not allowed for UE 104 to AMF / SEAF.
[0196] In step 1305, AMF / SEAF 202 rejects the service request of UE 104 upon receiving the rejection message from CAG server 110. In step 1306, AMF / SEAF 202 sends the rejection message to UE 104 with an appropriate cause value.
[0197] Fig.14 14 is a sequence diagram depicting verification of the UE's authority to access a CAG cell at the UDM 206 upon receiving the SUPI of the UE 104 from the AMF / SEAF according to an embodiment as disclosed herein. At step 1401, the UE 104 sends a service request to the AMF / SEAF 202 through the NG-RAN 106a requesting access to the CAG cell / NPN 102b. In one embodiment, the UE 104 may also send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 through the NG-RAN 106a in the service request. In one embodiment, the NG-RAN 106a may send the CAG ID of the requested CAG cell / NPN 102b to the AMF / SEAF 202 together with the registration request.
[0198] At step 1402, the AMF / SEAF 202 reveals the SUPI of the UE 104. The AMF / SEAF 202 inserts the revealed SUPI of the UE 104, the CAG ID of the requested CAG cell / NPN 102b into a Nudm_XXX request message and sends the Nudm_XXXRequest message to the UDM 206.
[0199] In step 1403, the UDM 206 retrieves the allowed list of CAG cells based on the received SUPI. The UDM 206 verifies whether the UE 104 has the authority to access the requested CAG cell / NPN 102b according to the allowed list of CAG cells retrieved based on the SUPI of the UE 104 and the CAG ID of the requested CAG cell. Upon verifying that the UE 104 has the authority to access the requested CAG cell, the UDM 206 inserts an acceptance message and the allowed list of CAG cells of the UE 104 in the Nudm_XXX response message. In step 1404, the UDM 206 sends a Nudm_XXX response message indicating successful verification to the AMF / SEAF 202. In step 1405, the AMF / SEAF 202 may further proceed with the registration request of the UE 104 upon receiving the acceptance message from the UDM 206.
[0200] Upon verifying that UE 104 does not have the authority to access CAG cell / NPN 102b, UDM 206 inserts a rejection message in the Nudm_XXX response message. In step 1404, UDM 206 sends a Nudm_XXX response message including a rejection message indicating that CAG cell is not allowed for UE 104 to AMF / SEAF 202. In step 1405, AMF / SEAF 202 rejects the registration request of UE 104 upon receiving the rejection message from UDM 206. In step 1406, AMF / SEAF 202 sends the rejection message and an appropriate cause value to UE 104.
[0201] Fig.15 is a flow chart depicting a method 1500 for controlling the right of at least one UE 104 to access at least one NPN 102b in a wireless network 100 according to an embodiment as disclosed herein. At step 1502, the method includes requesting, by at least one UE 104, a PLMN 102a to access at least one NPN 102b through at least one CAG cell.
[0202] At step 1504, the method includes verifying, by the CN 108a of the PLMN 102a, authority for the at least one UE 104 to access the requested at least one NPN (102) through the at least one CAG cell.
[0203] At step 1506, the method includes performing, by the CN 108a, a primary authentication procedure to allow at least one UE 104 to access at least one NPN 102b through at least one cell if the authority of at least one UE 104 to access at least one NPN 102 through at least one CAG cell is verified. The various actions in the method 1500 may be performed in the order presented, in a different order, or simultaneously. In addition, in some embodiments, the steps of Fig.15 Some of the actions listed in .
[0204] According to various embodiments, a method for controlling the authority of at least one user equipment (UE) (104) to access at least one non-public network (NPN) (102b) in a network (100), the method comprising requesting, by at least one UE (104), a public land mobile network (PLMN) (102a) to access the at least one NPN (102b) through at least one closed access group (CAG) cell; verifying, by a core network (CN) (108a) of the PLMN (102b), the authority of the at least one UE (104) to access the requested at least one NPN (102) through the at least one CAG cell; and performing, by the CN (108a), a primary authentication procedure to allow the at least one UE (104) to access the at least one NPN (102b) through the at least one CAG cell if the authority of the at least one UE (104) to access the requested at least one NPN (102) through the at least one CAG cell is verified.
[0205] In some embodiments, at least one NPN (102b) is deployed in conjunction with a PLMN (102a) using at least one CAG cell.
[0206] In some embodiments, the at least one NPN (102b) includes at least one of a dependent NPN (102b) and an independent NPN (102b).
[0207] In some embodiments, at least one of the unified data management (UDM) (206), access and mobility management function (AMF) (202), and authentication server function (AUSF) 204 of the CN (108a) verifies the authority of at least one UE (104) to access at least one NPN (102) requested through at least one CAG cell.
[0208] In some embodiments, a CAG server (110) coupled to a CN (108a) verifies authority of at least one UE (104) to access the requested at least one NPN (102).
[0209] In some embodiments, requesting access to at least one NPN (102a) by at least one UE (102) includes sending a request including a subscription concealed identifier (SUCI) of the at least one UE (102) to a radio access network (RAN) (106a) of a PLMN (102b).
[0210] In some embodiments, the method includes: adding, by the RAN (106a), at least one CAG identifier (CAG ID) of at least one NPN (102b) requested by at least one UE (104); and sending, by the RAN (106b), the received SUCI of the UE (104) and the at least one CAG ID of the requested at least one NPN to the CN (108a).
[0211] In some embodiments, requesting access to at least one NPN (102a) by at least one UE (102) includes sending a request including a SUCI of the at least one UE (102) and a CAG ID of the requested at least one NPN to a RAN (106a) of a PLMN (102b).
[0212] In some embodiments, the CN (108a) verifies the authority of the at least one UE (104) to access the at least one NPN (102b) only if the received request message includes at least one CAG ID.
[0213] In some embodiments, verifying, by the CN (108a), the authority of the at least one UE (104) to access the requested at least one NPN (102b) includes: receiving a SUCI of the at least one UE (104) and at least one CAG ID of the requested at least one NPN (102a) from the RAN (106a); deriving an allowed list of CAG cells for the at least one UE (104) based on the received SUCI of the at least one UE (104); and verifying the authority of the at least one UE (104) to access the requested at least one NPN (102b) using the derived allowed list of CAG cells and the received at least one CAG ID of the requested at least one NPN (102b).
[0214] In some embodiments, deriving an allowed list of CAG cells for at least one UE (104) includes: revealing a received SUCI of the at least one UE (104) as a subscription permanent identifier (SUPI); mapping the revealed SUPI of the at least one UE (104) according to a mapping of the allowed list of CAG cells and SUPIs of a plurality of UEs; and deriving the allowed list of CAG cells for the at least one UE (104) if the relevant SUPI is mapped with the revealed SUPI of the at least one UE (104).
[0215] In some embodiments, verifying the authority of at least one UE (104) using the derived allowed list of the CAG cell and the received CAG ID of at least one requested NPN (102b) includes: determining whether the received at least one CAG ID of at least one requested NPN (102b) exists in the allowed list of the derived CAG cell; if the received at least one CAG ID of at least one requested NPN (102b) exists in the allowed list of the derived CAG cell, verifying that the at least one UE (104) has the authority to access the requested at least one NPN (102b); and if the received at least one CAG ID of at least one requested NPN (102b) does not exist in the allowed list of the derived CAG cell, verifying that the at least one UE (104) does not have the authority to access the requested at least one NPN (102b).
[0216] In some embodiments, the method includes rejecting a request of at least one UE (104) upon verifying that the at least one UE (104) does not have permission to access the requested at least one NPN (102b); and sending a rejection message to the at least one UE (104) together with a cause value, wherein the cause value indicates at least one reason for the error in rejecting the request of the at least one UE (104).
[0217] In some embodiments, performing a primary authentication process includes: generating an authentication vector based on the disclosed SUPI of the at least one UE (104) when verifying that the at least one UE (104) has authority to access the requested at least one NPN (102b); authenticating the at least one UE (104) based on the generated authentication vector when determining whether the at least one UE (104) has NPN authority to access the requested at least one NPN (102b) through the PLMN (102a); and enabling the at least one UE (104) to access the requested at least one NPN (102b) if the at least one UE (104) has NPN authority to access the requested at least one NPN (102b) through the PLMN (102a).
[0218] According to various embodiments, a network (100) includes at least one user equipment (UE) (104); at least one non-public network (NPN) (102a); and a public land mobile network (PLMN) (102a). At least one NPN (102b) is deployed in conjunction with the PLMN (102a), wherein the PLMN (102a) includes at least one cellular network (102a) consisting of a radio access network (106a) and a core network (CN) (108a). At least one UE (104) is configured to request the PLMN (102a) to access the at least one NPN (102a) through at least one closed access group (CAG) cell. The CN (108a) is configured to verify the authority of at least one UE (104) to access the requested at least one NPN (102) via at least one CAG cell; and perform a primary authentication procedure to allow at least one UE (104) to access the requested at least one NPN (102b) through at least one CAG cell if the authority of at least one UE (104) to access the requested at least one NPN (102b) through at least one CAG cell is verified.
[0219] In some embodiments, at least one NPN (102b) is deployed in conjunction with a PLMN (102a) using at least one CAG cell.
[0220] In some embodiments, the at least one NPN (102b) includes at least one of a dependent NPN (102b) and an independent NPN (102b).
[0221] In some embodiments, at least one of the unified data management (UDM) (206), access and mobility management function (AMF) (202), and authentication server function (AUSF) 204 of the CN (108a) is further configured to verify the authority of at least one UE (104) to access at least one NPN (102) requested through at least one CAG cell.
[0222] In some embodiments, the PLMN (102a) further includes a CAG server (110) coupled to the CN (108a), the CAG server being configured to verify the authority of the at least one UE (104) to access the requested at least one NPN (102).
[0223] In some embodiments, the at least one UE (102) is further configured to send a request including a subscription concealment identifier (SUCI) of the at least one UE (102) to a RAN (106a) requesting access to a PLMN (102b) of the at least one NPN (102b).
[0224] In some embodiments, at least one RAN (106a) is further configured to: add at least one CAG identifier (CAG ID) of at least one NPN (102b) requested by at least one UE (104); and send the received SUCI of the UE (104) and the CAG ID of the requested at least one NPN to the CN (108a).
[0225] In some embodiments, the at least one UE (102) is further configured to send a request including the SUCI of the at least one UE (102) and the CAG ID of the requested at least one NPN to the RAN (106a) of the PLMN (102b).
[0226] In some embodiments, the CN (108a) is further configured to verify the authority of the at least one UE (104) to access the at least one NPN (102b) only when the received request message includes at least one CAG ID.
[0227] In some embodiments, the CN (108a) is further configured to: receive a SUCI of the at least one UE (104) and at least one CAG ID of the requested at least one NPN (102a) from the RAN (106a); derive an allowed list of CAG cells of the at least one UE (104) based on the received SUCI of the at least one UE (104); and verify the authority of the at least one UE (104) to access the requested at least one NPN (102b) using the derived allowed list of CAG cells and the received at least one CAG ID of the requested at least one NPN (102b).
[0228] In some embodiments, the CN (108a) is further configured to: disclose the received SUCI of the at least one UE (104) as a subscription permanent identifier (SUPI); map the disclosed SUPI of the at least one UE (104) according to a mapping of an allowed list of CAG cells and SUPIs of a plurality of UEs; and derive an allowed list of CAG cells of the at least one UE (104) if the relevant SUPI is mapped with the disclosed SUPI of the at least one UE (104).
[0229] In some embodiments, the CN (108a) is further configured to: determine whether the at least one CAG ID of the at least one NPN (102b) requested that has been received exists in the allowed list of the derived CAG cell; if the at least one CAG ID of the at least one NPN (102b) requested that has been received exists in the allowed list of the derived CAG cell, verify that the at least one UE (104) has the authority to access the at least one NPN (102b) requested; and if the CAG ID of the at least one NPN (102b) requested that has been received does not exist in the allowed list of the derived CAG cell, verify that the at least one UE (104) does not have the authority to access the CAG cell of the at least one NPN (102b) requested.
[0230] In some embodiments, the CN (108a) is further configured to: upon verifying that the at least one UE (104) does not have authority for accessing at least one CAG ID of the requested at least one NPN (102b), reject the request of the at least one UE (104); and send a rejection message to the at least one UE (104) together with a cause value, wherein the cause value indicates at least one reason for the error in rejecting the request of the at least one UE (104).
[0231] In some embodiments, the CN (108a) is further configured to: generate an authentication vector based on the received SUPI of the at least one UE (104) when verifying that the at least one UE (104) has the authority to access the at least one NPN (102b) requested; authenticate the at least one UE (104) based on the generated authentication vector when determining whether the at least one UE (104) has the NPN authority to access the at least one NPN (102b) requested through the PLMN (102a); and enable the at least one UE (104) to access the at least one NPN (102b) requested if the at least one UE (104) has the NPN authority to access the at least one NPN (102b) requested through the PLMN (102a).
[0232] According to various embodiments, a network (100) includes at least one user equipment (UE) (104); at least one non-public network (NPN) (102a); and a public land mobile network (PLMN) (102a), wherein at least one NPN (102b) is deployed in conjunction with the PLMN (102a) through at least one closed access group (CAG) cell, wherein the PLMN (102a) includes at least one cellular network (102a) consisting of a radio access network (106a) and a core network (CN) (108a). At least one UE (104) is configured to request the PLMN (102a) for access to the at least one NPN (102a). The CN (108a) includes a unified data management (UDM) (206) configured to: verify the authority of the at least one UE (104) to access the requested at least one NPN (102); and initiate a primary authentication procedure if the authority of the at least one UE (104) to access the requested at least one NPN (102) is verified.
[0233] In some embodiments, the at least one UE (104) is further configured to: send a request (102b) including a subscription concealment identifier (SUCI) of the at least one UE (104) to a RAN (106a) requesting access to a PLMN of the at least one NPN (102b); wherein the RAN (106a) is configured to: add a CAG ID of the at least one NPN (102b) requested by the at least one UE (104); and send the received SUCI of the UE (104) and the requested CAG ID of the at least one NPN (102a) to the CN (108a).
[0234] In some embodiments, the at least one UE (104) is further configured to send a request including the SUCI of the at least one UE (102) and the CAG ID of the requested at least one NPN to the RAN (106a) of the PLMN (102b).
[0235] In some embodiments, the CN (108a) further comprises: an access and mobility management function (AMF) (202) and an authentication server function (AUSF) 204; wherein the AMF (202) is configured to: receive a SUCI of at least one UE (104) and a CAG ID of at least one NPN (102a) requested from the RAN (106a); insert the received SUCI of at least one UE (104) and the CAG ID of at least one NPN (102a) requested into an authentication request message (Nusf_UEAuthentication_Authenticate request message); and send the authentication request message to the AUSF (204). The AUSF (204) is further configured to derive the SUCI of the at least one UE (104) and the CAG ID of the requested at least one NPN (102a) according to the received authentication request message; insert the derived SUCI of the at least one UE (104) and the CAG ID of the requested at least one NPN (102a) into an authentication get request message (Nudm_UEAuthentication_Get_Request message); and send the authentication get request message to the UDM (206).
[0236] In some embodiments, the UDM (206) is further configured to: receive a SUCI of the at least one UE (104) and a CAG ID of the requested at least one NPN (102a) from the AUSF (204); disclose the received SUCI of the at least one UE (104) as a subscription permanent identifier (SUPI); map the disclosed SUPI of the at least one UE (104) according to a mapping of an allowed list of CAG cells and SUPIs of a plurality of UEs; retrieve the allowed list of the CAG cell of the at least one UE (104) if the relevant SUPI is mapped with the disclosed SUPI of the at least one UE (104); verify that the at least one UE (104) has permission to access the requested at least one NPN (102b) if the received CAG ID of the requested at least one NPN (102b) exists in the allowed list of the retrieved CAG cell; and verify that the at least one UE (104) has permission to access the requested at least one NPN (102b) if the received CAG ID of the requested at least one NPN (102b) exists in the allowed list of the retrieved CAG cell; and verify that the at least one UE (104) has permission to access the requested at least one NPN (102b) if the received CAG ID of the requested at least one NPN (102b) If the ID does not exist in the allowed list of the retrieved CAG cell, it is verified that the at least one UE (104) does not have the authority to access the requested at least one NPN (102b).
[0237] In some embodiments, the UDM (206) is further configured to: insert a rejection message and the SUPI of the at least one UE (204) in an authentication get request message (Nudm_UEAuthentication_Get_Response message) when it is verified that the at least one UE (204) does not have access to the requested at least one NPN (102b); send the authentication get response message to the AUSF (204). The AUSF (204) is further configured to: derive the rejection message from the received authentication get response message and insert the derived rejection message in an authentication response message (Nausf_UEAuthentication_Authenticate response message); send the authentication response message to the AMF (202). The AMF (202) is further configured to: reject the request of the at least one UE (104) when the rejection message is received from the AUSF (204); and send the rejection message to the at least one UE (104) through the RAN (106a) together with a cause value, wherein the cause value indicates at least one cause of error for rejecting the request of the at least one UE (104).
[0238] In some embodiments, the UDM (206) is further configured to: generate an authentication vector based on the received SUCI of the at least one UE (104) when verifying that the at least one UE (104) has the authority to access the requested at least one NPN (102b); send the authentication vector to the AMF (202) through the AUSF (204); the AMF (202) is further configured to: authenticate the at least one UE (104) based on the received authentication vector to determine whether the at least one UE (104) has the NPN authority to access the requested at least one NPN (102b) through the PLMN (102a); and if the at least one UE (104) has the NPN authority to access the requested at least one NPN (102b) through the PLMN (102a), enable the at least one UE (104) to access the requested at least one NPN (102b).
[0239] According to various embodiments, a core network CN (108a) of a public land mobile network (PLMN) (102a), wherein the PLMN (102a) is combined with at least one non-public network (NPN) (102a) and connected to at least one user equipment (UE) (104), wherein the CN (108a) is configured to: receive a request for access to at least one NPN (102a) from at least one UE (104) via a radio access network (RAN) (106a); verify the authority of the at least one UE (104) to access the requested at least one NPN (102); and if the authority of the at least one UE (104) to access the requested at least one NPN (102) is verified, perform a primary authentication procedure.
[0240] In some embodiments, the request of the at least one UE (104) includes a subscription concealment identifier (SUCI) of the at least one UE (102) and a closed access group (CAG ID) of the at least one NPN (102) requested by the at least one UE (104).
[0241] In some embodiments, the CN (108a) is further configured to: disclose the received SUCI of the at least one UE (104) as a subscription permanent identifier (SUPI); map the disclosed SUPI of the at least one UE (104) according to the mapping of the allowed list of the CAG cell and the SUPIs of the plurality of UEs; retrieve the allowed list of the CAG cell of the at least one UE (104) if the relevant SUPI is mapped with the disclosed SUPI of the at least one UE (104); verify that the at least one UE (104) has the authority to access the at least one NPN (102b) requested if the received CAG ID of the at least one NPN (102b) requested exists in the allowed list of the retrieved CAG cell; and verify that the at least one UE (104) does not have the authority to access the at least one NPN (102b) requested if the received CAG ID of the at least one NPN (102b) requested does not exist in the allowed list of the retrieved CAG cell.
[0242] In some embodiments, the CN (108a) is further configured to: reject the request of the at least one UE (104) when it is verified that the at least one UE (104) does not have the authority to access the requested at least one NPN (102b); and send a rejection message to the at least one UE (104) through the RAN (106a) together with a cause value, wherein the cause value indicates at least one reason for the error used to reject the request of the at least one UE (104).
[0243] The embodiments disclosed herein can be implemented by at least one software program running on at least one hardware device and performing network management functions to control the elements. Figure 1A-14 The elements shown in the figure may be at least one of hardware devices or a combination of hardware devices and software modules.
[0244] The embodiments disclosed herein describe methods and systems for mitigating denial of service (DoS) attacks in wireless networks. Therefore, it should be understood that the scope of protection is extended to such programs, and in addition to computer-readable devices having messages therein, such computer-readable storage devices also contain program code devices for implementing one or more steps of the method when the program is running on a server or a mobile device or any suitable programmable device. The method is implemented in one embodiment by or with a software program written in, for example, a very high speed integrated circuit hardware description language (VHDL), another programming language, or by executing one or more VHDL or several software modules on at least one hardware device. The hardware device can be any kind of portable device that can be programmed. The device can also include a device that may be, for example, a hardware device such as an ASIC, or a combination of hardware and software devices, such as an ASIC and an FPGA, or at least one memory in which at least one microprocessor and a software module are located. The method embodiments described herein can be implemented partially in hardware and partially in software. Alternatively, the present disclosure can be implemented on different hardware devices, for example, using multiple CPUs.
[0245] The foregoing description of specific embodiments will so fully reveal the general nature of the embodiments herein that others can easily modify and / or adapt such specific embodiments for various applications by applying current knowledge without departing from the general concept, and therefore, such adaptations and modifications should and are intended to be understood within the meaning and scope of equivalents of the disclosed embodiments. It should be understood that the wording or terminology employed herein is for descriptive and not limiting purposes. Therefore, although the embodiments herein have been described by example, those skilled in the art will recognize that the embodiments herein can be practiced by modification within the scope of the embodiments as described herein.
[0246] Although the present disclosure has been described with various embodiments, various changes and modifications may be suggested to one skilled in the art. The present disclosure is intended to encompass such changes and modifications as fall within the scope of the appended claims.
Claims
1. A method performed by a unified data management (UDM), the method comprising: receiving a request message from an authentication server function AUSF, the request message including a subscription concealment identifier SUCI of a user equipment UE and a CAG identifier of a closed access group CAG cell; identifying a subscription permanent identifier (SUPI) of the UE based on de-hiding the SUCI of the UE; Verifying, based on the SUPI of the UE, whether the UDM allows the UE to access the CAG cell; In a case where the UE is not allowed to access the CAG cell, sending a rejection message to the AUSF, the rejection message including information indicating the rejection of the CAG cell; as well as In a case where the UE is allowed to access the CAG cell, the UDM performs an authentication process between the UE and the network; The authentication process includes generating an authentication vector.
2. The method according to claim 1, further comprising: In a case where the UE is allowed to access the CAG cell, the UDM selects an authentication method for the authentication process.
3. The method according to claim 1, in, The SUPI of the UE is used to verify whether the UDM allows the UE to access the CAG cell.
4. The method according to claim 1, in, The UDM is associated with a subscription identifier de-hiding function SIDF, and The request message also includes the service network SN name.
5. A method performed by an authentication server function AUSF, the method comprising: receiving a first request message from a security anchor function SEAF, the first request message including a subscription concealment identifier SUCI of a user equipment UE and a CAG identifier of a closed access group CAG cell; Sending a second request message to a unified data management (UDM), where the second request message includes the SUCI of the UE and the CAG identifier of the CAG cell; In a case where the UE is not allowed to access the CAG cell, receiving a rejection message from the UDM, the rejection message including information indicating rejection of the CAG cell; as well as In case that the UE is allowed to access the CAG cell, a response message is received from the UDM according to an authentication process between the UE and a network, wherein the authentication process uses an authentication vector.
6. The method according to claim 5, in, The SUCI is used to obtain a subscription permanent identifier SUPI of the UE for verifying whether the UDM allows the UE to access the CAG cell.
7. The method according to claim 5, in, The first request message also includes the service network SN name, and The second request message also includes the SN name.
8. A method performed by an access and mobility management function (AMF), the method comprising: receiving a registration request from a user equipment UE via a base station, the registration request including a subscription concealment identifier SUCI of the UE; receiving a CAG identifier of a closed access group CAG cell from the base station; Sending a request message to a unified data management (UDM) via an authentication server function (AUSF), wherein the request message includes the SUCI of the UE and the CAG identifier of the CAG cell; In a case where the UE is not allowed to access the CAG cell, receiving a rejection message from the UDM via the AUSF indicating rejection of the CAG cell; as well as In a case where the UE is allowed to access the CAG cell, an authentication process of the UE is performed.
9. The method according to claim 8, in, The SUCI is used to obtain a subscription permanent identifier SUPI of the UE for verifying whether the UDM allows the UE to access the CAG cell.
10. A method performed by a user equipment UE, the method comprising: Sending, via a base station, to a security anchor function SEAF, a registration request for accessing a closed access group CAG cell, the registration request including a subscription concealed identifier SUCI of the UE, wherein the SEAF is associated with an access and mobility management function AMF that receives the CAG identifier of the CAG cell from the base station; In a case where the UE is not allowed to access the CAG cell, receiving a rejection message indicating rejection of the CAG cell from a unified data management (UDM) via an authentication server function (AUSF) and the SEAF; as well as In a case where the UE is allowed to access the CAG cell, an authentication process is performed between the network and the UE, wherein the authentication process uses an authentication vector.
11. The method according to claim 10, in, The SUCI is used to obtain a subscription permanent identifier SUPI of the UE for verifying whether the UDM allows the UE to access the CAG cell.
12. A unified data management (UDM), the UDM comprising: Transceiver; as well as A processor coupled to the transceiver and configured to implement one of claims 1 to 4.
13. An authentication server function AUSF, the AUSF comprising: Transceiver; as well as A processor coupled to the transceiver and configured to implement one of claims 5 to 7.
14. An access and mobility management function AMF, the AMF comprising: Transceiver; as well as A processor coupled to the transceiver and configured to implement one of claims 8 to 9.
15. A user equipment UE, the UE comprising: Transceiver; as well as A processor coupled to the transceiver and configured to implement one of claims 10 to 11.
Citation Information
Patent Citations
Authentication method and authentication device for secured communications between an ATM mobile terminal and an ATM access node of a wireless ATM radio communication network
CN1298620A
User equipment registration method for network slice selection and network controller and network communication system using the same
US20180227871A1