Method and apparatus for authentication
By enhancing the AUSF interface and using AMF's network access indicator, the problem that AUSF cannot determine whether authentication is used for network access is solved, unnecessary signaling is avoided, system performance is improved, and access denial reasons are accurately notified.
Patent Information
- Application Number
- CN202380073935.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-21
- Filing Date
- 2023-10-17
- Publication Date
- 2025-05-30
AI Technical Summary
Prior Art In the 3GPP specification, AUSF cannot determine whether authentication is used for UE's network access, resulting in unnecessary signaling waste or increase.
Enhance the AUSF interface so that the AMF indicates to the AUSF whether the authentication is used for network access in signaling, thereby deciding whether to query the UDM for authentication method selection or notify the authentication result.
By determining whether authentication is used for network access, unnecessary signaling is avoided, the system performance of AUSF and UDM is improved, and the user can be correctly notified of the real reason for access denial.
Smart Images

Figure CN120077691A_ABST
Abstract
Description
Technical Field
[0001] The non - limiting and exemplary embodiments of the present disclosure generally relate to the field of communication technologies, and more particularly to methods and apparatuses for authentication. Background Art
[0002] This section introduces various aspects that can help better understand the present disclosure. Therefore, the statements in this section should be read from this perspective and should not be construed as an admission of what is in the prior art or what is not in the prior art.
[0003] Authentication and key negotiation processes can be supported in various networks. For example, in communication networks such as LTE (Long - Term Evolution) or NR (New Radio) defined by the 3rd Generation Partnership Project (3GPP), various authentication and key negotiation processes are supported.
[0004] The purpose of the primary authentication and key negotiation process can be to enable mutual authentication between a user equipment (UE) and a network, and to provide key material that can be used between the UE and the serving network in subsequent security processes.
[0005] A Stand - Alone Non - Public Network (SNPN) can support UE access using credentials owned by a credential holder independent of the SNPN. The onboarding of the UE to the SNPN allows the UE to access the Onboarding Network (ONN) for the purpose of providing the UE with SNPN credentials and other information for primary authentication, enabling access to the desired SNPN, i.e., (re)selecting the SNPN and (re)registering with the SNPN.
[0006] Figure 1 A flowchart showing the primary authentication using an external domain is the same as FIG. I.2.2.2.2 - 1 of 3GPP TS 33.501 V17.7.0, the disclosure of which is incorporated herein by reference in its entirety.
[0007] This process enables the UE to access the SNPN, where the SNPN uses a credential management system managed by a credential provider outside the SNPN.
[0008] In this scenario, the authentication server role is assumed by an AAA (Authentication, Authorization, and Accounting) server. The AUSF (Authentication Service Function) acts as an EAP (Extensible Authentication Protocol) authenticator and interacts with the AAA server to perform the primary authentication process.
[0009] The architecture for SNPN access using credentials from a credential holder using an AAA server is described in clause 5.30.2.9.2 of 3GPP TS23.501 V17.5.0, the disclosure of which is incorporated herein by reference in its entirety.
[0010] Section I.2.2.2.2 of 3GPP TS 33.501 V17.7.0 describes the following steps.
[0011] 0. The UE shall be configured with credentials from the credential holder, such as the SUPI containing the network-specific identifier and the credentials used for the key generation EAP method. As part of the credential configuration, the UE shall also be configured with an indication that, after successful primary authentication, the UE shall use the MSK for deriving KAUSF. The exact process for configuring the UE is not specified in this document.
[0012] It is further assumed that there is a trust relationship between the SNPN and the credential holder AAA server. These entities need to authenticate each other, and the information transmitted on the interface needs confidentiality protection, integrity protection, and replay protection. When the procedures in this section are used for network access purposes, the network access-specific adaptations include, respectively: the 'credentials' used are 'default credentials', the 'SUPI' used is 'network access SUPI', and the 'SUCI' used is 'network access SUCI'.
[0013] 1. The UE shall select an SNPN and initiate UE registration in the SNPN.
[0014] For the construction of the SUCI, the existing methods in Section 6.12 can be used. Otherwise, if the EAP method supports SUPI privacy, the UE may send the anonymous value SUCI based on the configuration.
[0015] 2. The AMF within the SNPN shall initiate primary authentication for the UE with the AUSF using the Nausf_UEAuthentication_Authenticate service operation. The AMF shall discover and select the AUSF based on the criteria specified in clause 5.30.2.9.2 of TS23.501 [2].
[0016] 3. In the case of network access, steps 3 - 5 are omitted. If steps 3 - 5 are not omitted, the AUSF shall initiate the Nudm_UEAuthentication_Get service operation. The AUSF shall discover and select the UDM based on the criteria specified in clause 5.30.2.9 of TS23.501 [2].
[0017] Note 1: In the case of re-authentication, the SUPI shall be used instead of the SUCI.
[0018] 4. In the case where the UDM receives the SUCI, the UDM shall resolve the SUCI to the SUPI before checking the authentication method applicable to the SUPI. The UDM decides to run primary authentication with an external entity based on the subscription data.
[0019] In the case where the UDM receives an anonymous SUCI, the UDM determines to perform the primary authentication with an external entity based on the realm part of the SUPI in the NAI format.
[0020] Note 1a: The UDM needs to be configured with a list of realms and the expected authentication servers (external or internal)
[0021] In the case where the UDM receives an anonymous SUCI that does not contain a realm part, the UDM shall abort the process. Otherwise, the UDM authorizes the UE based on the realm part of the SUCI and sends the anonymous SUPI and the indicator to the AUSF as described in step 5.
[0022] The anonymous SUPI shall be in the NAI format.
[0023] 5. In the case where the UDM receives a SUCI in the previous step, the UDM shall provide the SUPI or the anonymous SUPI to the AUSF and shall indicate to the AUSF to perform the primary authentication with the AAA server in the external credential holder.
[0024] When using the credential holder of the AAA server for the primary authentication, the AUSF uses the MSK to derive the KAUSF. It is strongly recommended that the same credential used for the authentication between the UE and the 5G SNPN should not be used for the authentication between the UE and the non-5G network, assuming that the 5G SNPN and the non-5G network are in different security domains.
[0025] Note 2: The MSK obtained from the non-5G network can be used to simulate the 5G SNPN to the UE.
[0026] 6. Based on the indication from the UDM, the AUSF shall select the NSSAAF as defined in TS23.501 [2] and initiate the Nnssaaf_AIWF_Authenticate service operation to the NSSAAF as defined in clause 14.4.2.
[0027] 7. The N4SSAAF shall select the AAA server based on the domain name corresponding to the realm part of the SUPI. The NSSAAF shall perform the relevant protocol conversion and relay the EAP message to the AAA server.
[0028] Note 3: The interface and protocol between the NSSAAF and the AAA are outside the scope of this document and existing AAA protocols such as RADIUS or Diameter can be used.
[0029] 8. The UE and the AAA server shall perform mutual authentication. The AAA server shall act as an EAP server for the purpose of primary authentication. The EAP identifier received by the AAA server in the EAP-Response / Identity message in step 7 may contain an anonymous SUPI. In this case, the AAA server uses the EAP method-specific EAP identifier request / response message to obtain the UE identifier as part of the EAP authentication between the UE and the AAA server.
[0030] 9. After successful authentication, the MSK and the SUPI (i.e., the UE identifier for successful EAP authentication) shall be provided from the AAA server to the NSSAAF.
[0031] 10. The NSSAAF uses the Nnssaaf_AIWF_Authenticate service operation response message to return the MSK and the SUPI to the AUSF. When deriving a 5G key (e.g., KAMF) that requires the SUPI as an input for key derivation, the SUPI received from the AAA shall be used.
[0032] 11 - 13. When the SUCI received during network access or in step 2 is not anonymous, steps 11 - 13 are omitted. Otherwise, the AUSF notifies the UDM of the authentication result for the received SUPI by using the Nudm_UEAuthentication_ResultConfirmation service operation, verifying that the SUPI corresponds to a valid subscription in the SNPN. The UDM stores the authentication status for the SUPI, and if there is no subscription corresponding to the SUPI, the UDM shall return an error.
[0033] If the SUPI verification is unsuccessful, the AUSF rejects the UE's access to the SNPN.
[0034] Note 4: If the above failure occurs, the error is not a failed authentication but a lack of subscription in the SNPN.
[0035] 14. The AUSF shall use the highest 256 bits of the MSK as the KAUSF. The AUSF shall also derive the KSEAF from the KAUSF according to the definition in Annex A.6.
[0036] 15. The AUSF shall send a success indication together with the UE's SUPI and the obtained KSEAF to the AMF.
[0037] 16. The AMF shall send EAP success in the NAS message.
[0038] 17. The UE shall derive the KAUSF from the MSK according to the pre - configured indication described in step 0, as described in step 11.
[0039] 3GPP TS 29.509 V17.7.0, the disclosure of which is incorporated herein by reference in its entirety, describes the definition of type AuthenticationInfo as follows. Table 6.1.6.2.2-1: Definition of type AuthenticationInfo SUMMARY OF THE INVENTION
[0040] The present invention is provided in simplified form to introduce selected concepts, which are further described below in the detailed description. The present invention is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0041] There are some problems with existing solutions for authentication.
[0042] Problem 1: As described in step 3 of Figure 1 , in the case of network access, steps 3-5 are skipped. The problem is that based on 3GPP TS 29.509 V17.7.0 (e.g., AuthenticationInfo), from the existing signaling, the AUSF does not know whether the authentication is for network access. Therefore, the AUSF can rely on itself to infer whether the authentication is for network access. If the AUSF wrongly or blindly queries the UDM for authentication method selection, there will be waste or increase in unnecessary signaling.
[0043] Problem 2: As described in steps 11-13 of Figure 1 , it requires the AUSF to notify the UDM of the authentication result for the received SUPI (Subscription Permanent Identifier) by using the Nudm_UEAuthentication_ResultConfirmation service operation to verify that the SUPI corresponds to a valid subscription in the SNPN. It also requires that in the case of network access, steps 11-13 be omitted, but the problem is that based on 3GPP TS 29.509 V17.7.0 (e.g., AuthenticationInfo), the AUSF does not know whether the authentication is for network access. If the AUSF wrongly or blindly uses the Nudm_UEAuthentication_ResultConfirmation service operation to notify the UDM of the authentication result for the received SUPI, there will be waste or increase in unnecessary signaling.
[0044] Question 3: In the existing 3GPP specifications (such as 3GPP TS 33.501 V17.7.0), the AUSF notifies the UE of the authentication result independently of the result of the Nudm_UEAuthentication_ResultConfirmation service operation because the authentication result is always returned. The question is whether notifying the UE of a successful authentication result depends on the subscription verification result from the UDM if the authentication is not for network access.
[0045] As Figure 1 stated in steps 11 - 13 of, if the verification of the SUPI is unsuccessful, the error is not a failed authentication but a lack of subscription in the SNPN. However, based on 3GPP TS 29.509 V17.7.0, whether to notify the UE of the authentication result does not depend on the subscription verification result from the UDM. If the verification of the SUPI is unsuccessful, the AUSF still accepts the UE's access to the SNPN. Additionally, there is no corresponding cause code to indicate that the user's SNPN access rejection is not due to authentication reasons because the authentication is actually successful but due to a lack of SNPN subscription. Therefore, the subscriber does not know the real problem, or it may be very time - consuming for troubleshooting.
[0046] To overcome or mitigate at least one of the above - mentioned problems or other problems, embodiments of the present disclosure propose an improved solution for authentication.
[0047] In an embodiment, to solve Problem 1, the AUSF interface is enhanced such that when an authentication request is requested from the AMF, the AMF shall indicate in the signaling to the AUSF whether the authentication is for network access. Using the enabled creative step, the AUSF knows whether the authentication is for network access and decides whether to query the UDM for authentication method selection based on this indication. Thus, if the authentication is for network access, unnecessary signaling to the UDM is avoided.
[0048] In an embodiment, to solve Problem 2, the AUSF interface is enhanced such that when an authentication request is requested from the AMF, the AMF shall indicate in the signaling to the AUSF whether the authentication is for network access. Using the enabled creative step, the AUSF knows whether the authentication is for network access and decides whether to notify the UDM of the authentication result for the received SUPI using the Nudm_UEAuthentication_ResultConfirmation service operation based on this indication. Thus, if the authentication is for network access, unnecessary signaling to the UDM is avoided.
[0049] In an embodiment, to solve Problem 3, when the AUSF hands over the authentication result, it will update the service logic processing based on whether the authentication is for network access. If it is not for network access and fromFigure 1 In step 2 of Figure 1 , the SUPI is not anonymous. It will first use the Nudm_UEAuthentication_ResultConfirmation service operation to notify the UDM of the authentication result for the received SUPI and wait for the result from the UDM. If the result is OK, the AUSF will notify the AMF of the successful authentication result. However, if the result from the UDM is failure, even if the authentication result is successful, the AUSF will reject the UE's access to this SNPN. The AUSF interface is enhanced to indicate the reason for the lack of SNPN subscription. Although the authentication is successful, when the UE receives this indication, it can show the user the real reason for the lack of SNPN subscription, and the user can contact the SNPN operator support to solve this problem.
[0050] In a first aspect of the present disclosure, a method performed by an authentication service node is provided. The method includes receiving a first authentication request sent by an access and mobility node. The first authentication request includes a subscription hidden identifier and a first piece of information indicating whether the primary authentication is for the terminal device to access the network. The method further includes processing the first authentication request based on the first piece of information.
[0051] In an embodiment, the first piece of information is an indicator.
[0052] In an embodiment, when the indicator is set to true, the indicator indicates that the primary authentication is for the terminal device to access the network.
[0053] In an embodiment, when the indicator is set to false or the indicator does not exist, the indicator indicates that the primary authentication is not for the terminal device to access the network.
[0054] In an embodiment, processing the first authentication request based on the first piece of information includes: when the first piece of information indicates that the primary authentication is for the terminal device to access the network, skipping the selection of the data management node and skipping sending a request for authentication method selection to the data management node; when the first piece of information indicates that the primary authentication is not for the terminal device to access the network, selecting the data management node and sending a request for authentication method selection to the data management node.
[0055] In an embodiment, the method further includes sending a second authentication request to an independent non-public network (SNPN) authentication and authorization node. The method further includes receiving, from the SNPN authentication and authorization node, a second authentication response including authentication success, a master session key, and a subscription permanent identifier. The method further includes skipping sending an authentication result confirmation request to a data management node when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier received in the first authentication request is not anonymous. The method further includes sending an authentication result confirmation request to the data management node and receiving an authentication result confirmation response from the data management node when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous. The authentication result confirmation request is used to verify that the subscription permanent identifier corresponds to a valid subscription in the SNPN.
[0056] In an embodiment, when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier received in the first authentication request is not anonymous, the method further includes generating a key for the authentication service node and a key for the security anchor function. The method further includes sending a first authentication response including authentication success, the key for the security anchor function, and the subscription permanent identifier to an access and mobility node.
[0057] In an embodiment, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous, the method further includes rejecting the terminal device's access to the SNPN and sending a first authentication response including the second information to the access and mobility node when the authentication result confirmation response includes second information indicating that user subscription verification has failed, or the user was not found, or the SNPN subscription is missing.
[0058] In an embodiment, the SNPN authentication and authorization node includes a network slice specific and SNPN authentication and authorization function (NSSAAF).
[0059] In an embodiment, the data management node includes a unified data management (UDM).
[0060] In an embodiment, the access and mobility node includes an access and mobility management function (AMF).
[0061] In an embodiment, the authentication service node includes an authentication server function (AUSF).
[0062] In a second aspect of the present disclosure, a method performed by an access and mobility node is provided. The method includes receiving, from a terminal device, a registration request for registration in a Standalone Non-Public Network (SNPN). The registration request includes a subscription hidden identifier. The method further includes sending a first authentication request to an authentication service node. The first authentication request includes the subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network.
[0063] In an embodiment, the first information is an indicator.
[0064] In an embodiment, when the indicator is set to true, the indicator indicates that the primary authentication is for the terminal device to access the network.
[0065] In an embodiment, when the indicator is set to false or the indicator does not exist, the indicator indicates that the primary authentication is not for the terminal device to access the network.
[0066] In an embodiment, when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier is not anonymous, the method further includes receiving, from the authentication service node, a first authentication response including authentication success, a key for a security anchor function, and a subscription permanent identifier. The method further includes sending authentication success to the terminal device.
[0067] In an embodiment, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier is anonymous, the method further includes receiving, from the authentication service node, a first authentication response including second information indicating that user subscription verification has failed or the user has not been found or there is a lack of SNPN subscription. The method further includes sending the second information to the terminal device.
[0068] In an embodiment, the access and mobility node includes an Access and Mobility Management Function (AMF).
[0069] In an embodiment, the authentication service node includes an Authentication Server Function (AUSF).
[0070] In a third aspect of the present disclosure, a method performed by a terminal device is provided. The method includes sending, to an access and mobility node, a registration request for registration in a Standalone Non-Public Network (SNPN). The registration request includes a subscription hidden identifier. The method further includes receiving, from the access and mobility node, authentication success or second information. The second information indicates that user subscription verification has failed or the user has not been found or there is a lack of SNPN subscription.
[0071] In an embodiment, the access and mobility node includes an Access and Mobility Management Function (AMF).
[0072] In an embodiment, the method further includes providing the second information to a user of the terminal device.
[0073] In a fourth aspect of the present disclosure, an authentication service node is provided. The authentication service node includes a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The authentication service node is operable to receive a first authentication request sent by an access and mobility node. The first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network. The authentication service node is further operable to process the first authentication request based on the first information.
[0074] In a fifth aspect of the present disclosure, an access and mobility node is provided. The access and mobility node includes a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The access and mobility node is operable to receive a registration request from a terminal device for registration in an independent non-public network (SNPN). The registration request includes a subscription hidden identifier. The access and mobility node is further operable to send a first authentication request to an authentication service node. The first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network.
[0075] In a sixth aspect of the present disclosure, a terminal device is provided. The terminal device includes a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The terminal device is operable to send a registration request for registration in an independent non-public network (SNPN) to an access and mobility node. The registration request includes a subscription hidden identifier. The terminal device is further operable to receive an authentication success or second information from the access and mobility node. The second information indicates that the user subscription verification fails, or the user is not found, or the SNPN subscription is missing.
[0076] In another aspect of the present disclosure, an authentication service node is provided. The authentication service node includes a first receiving module configured to receive a first authentication request sent by an access and mobility node. The first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network. The authentication service node further includes a processing module configured to process the first authentication request based on the first information.
[0077] In an embodiment, the authentication service node further includes a first sending module configured to send a second authentication request to an independent non-public network (SNPN) authentication and authorization node.
[0078] In an embodiment, the authentication service node further includes a second receiving module configured to receive a second authentication response from the SNPN authentication and authorization node, the second authentication response including authentication success, a master session key, and a subscription permanent identifier.
[0079] In an embodiment, the authentication service node further includes a skip module configured to skip sending an authentication result confirmation request to the data management node when the first information indicates that the primary authentication is for the access of a terminal device to the network or the subscription hidden identifier received in the first authentication request is not anonymous.
[0080] In an embodiment, when the first information indicates that the primary authentication is not for the access of a terminal device to the network and / or the subscription hidden identifier received in the first authentication request is anonymous, the authentication service node further includes a second sending module configured to send an authentication result confirmation request to the data management node; and a third receiving module configured to receive an authentication result confirmation response from the data management node. The authentication result confirmation request is used to verify that the subscription permanent identifier corresponds to a valid subscription in the SNPN.
[0081] In an embodiment, when the first information indicates that the primary authentication is for the access of a terminal device to the network or the subscription hidden identifier received in the first authentication request is not anonymous, the authentication service node further includes a generation module configured to generate a key of the authentication service node and a key of the security anchor function, and a third sending module configured to send a first authentication response including authentication success, the key of the security anchor function, and the subscription permanent identifier to the access and mobility node.
[0082] In an embodiment, when the first information indicates that the primary authentication is not for the access of a terminal device to the network and / or the subscription hidden identifier received in the first authentication request is anonymous, and when the authentication result confirmation response includes second information indicating that the user subscription verification fails, the user is not found, or the SNPN subscription is missing, the authentication service node further includes a rejection module configured to reject the access of the terminal device to the SNPN, and a fourth sending module configured to send a first authentication response including the second information to the access and mobility node.
[0083] In another aspect of the present disclosure, an access and mobility node is provided. The access and mobility node includes a first receiving module configured to receive a registration request for registration in a Standalone Non-Public Network (SNPN) from a terminal device. The registration request includes a subscription hidden identifier. The access and mobility node further includes a first sending module configured to send a first authentication request to an authentication service node. The first authentication request includes the subscription hidden identifier and first information indicating whether the primary authentication is for the access of the terminal device to the network.
[0084] In an embodiment, when the first information indicates that the primary authentication is for the terminal device to access the network or the subscribed hidden identifier is not anonymous, the access and mobility node further includes a second receiving module configured to receive, from an authentication service node, a first authentication response including authentication success, a key for a security anchor function, and a subscribed permanent identifier, and a second sending module configured to send authentication success to the terminal device.
[0085] In an embodiment, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscribed hidden identifier is anonymous, the access and mobility node further includes a third receiving module configured to receive, from the authentication service node, a first authentication response including second information, where the second information indicates that user subscription verification fails, or the user is not found, or there is a lack of SNPN subscription, and a third sending module configured to send the second information to the terminal device.
[0086] In another aspect of the present disclosure, a terminal device is provided. The terminal device includes a sending module configured to send a registration request for registering in a Standalone Non-Public Network (SNPN) to an access and mobility node. The registration request includes a subscribed hidden identifier. The terminal device further includes a receiving module configured to receive authentication success or second information from the access and mobility node. The second information indicates that user subscription verification fails, or the user is not found, or there is a lack of SNPN subscription.
[0087] In an embodiment, the terminal device further includes a providing module configured to provide the second information to a user of the terminal device.
[0088] In another aspect of the present disclosure, a computer program product including instructions is provided. When the instructions are executed by at least one processor, the instructions cause the at least one processor to execute the method according to any one of the first, second, or third aspects.
[0089] In another aspect of the present disclosure, a computer-readable storage medium storing instructions is provided. When the instructions are executed by at least one processor, the instructions cause the at least one processor to execute the method according to any one of the first, second, or third aspects.
[0090] The embodiments in this document can offer many advantages, and the following is a non-exhaustive list of examples of the advantages. In some embodiments in this document, if authentication is used for network access, unnecessary signaling to a data management node (such as a UDM) can be avoided. This can improve the system performance of both the authentication service node AUSF and the data management node (such as a UDM). In some embodiments in this document, network access services can be treated differently from non-network access services, so communication service providers (CSPs) can monetize their networks based on meeting different service requirements. In some embodiments in this document, since the real cause of the SNPN access rejection situation can be detected and users can correctly find the corresponding support, user satisfaction is improved. This can help CSPs reduce operating expenses (OPEX) and at the same time retain subscriber royalties. The embodiments in this document are not limited to the above features and advantages. Those skilled in the art will recognize additional features and advantages after reading the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0091] From the following detailed description with reference to the accompanying drawings, by way of example, the above and other aspects, features, and benefits of various embodiments of the present disclosure will become more fully apparent, in which like reference numerals or letters are used to refer to like or equivalent elements. The drawings are shown to facilitate a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale, where:
[0092] Figure 1 A flowchart of the primary authentication with an external domain is shown;
[0093] Figure 2 A 5G system architecture for accessing an SNPN using credentials from a credential holder using an AAA server is schematically shown;
[0094] Figure 3 A flowchart of a method according to an embodiment of the present disclosure is shown;
[0095] Figure 4 A flowchart of a method according to another embodiment of the present disclosure is shown;
[0096] Figure 5 A flowchart of a method according to another embodiment of the present disclosure is shown;
[0097] Figure 6a A flowchart of a method according to another embodiment of the present disclosure is shown;
[0098] Figure 6b A flowchart of a method according to another embodiment of the present disclosure is shown;
[0099] Figure 6cFlowchart showing a method according to another embodiment of the present disclosure;
[0100] Figure 6d Flowchart showing a method according to another embodiment of the present disclosure;
[0101] Figure 6e Flowchart showing a method according to another embodiment of the present disclosure;
[0102] Figure 7a Flowchart showing a method according to another embodiment of the present disclosure;
[0103] Figure 7b Flowchart showing primary authentication with UE access network indication according to another embodiment of the present disclosure;
[0104] Figure 8a Block diagram showing an apparatus suitable for practicing some embodiments of the present disclosure;
[0105] Figure 8b Block diagram showing an authentication service node according to an embodiment of the present disclosure;
[0106] Figure 8c Block diagram showing an access and mobility node according to an embodiment of the present disclosure;
[0107] Figure 9 Block diagram showing a terminal device according to an embodiment of the present disclosure;
[0108] Figure 10 Illustration of an example of a communication system according to an embodiment of the present disclosure;
[0109] Figure 11 Block diagram of a host according to an embodiment of the present disclosure; and
[0110] Figure 12 Communication diagram showing a host communicating with a UE over a partial wireless connection via a network node according to an embodiment of the present disclosure. Detailed Description
[0111] Embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for the purpose of enabling those skilled in the art to better understand and thus implement the present disclosure, rather than suggesting any limitation to the scope of the present disclosure. References throughout the specification to features, advantages, or similar language do not imply that all features and advantages that can be realized with the present disclosure should be in or in any single embodiment of the present disclosure. On the contrary, language referring to features and advantages should be understood to mean that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present disclosure. In addition, the features, advantages, and characteristics described in the present disclosure may be combined in any suitable manner in one or more embodiments. Those skilled in the relevant art will recognize that the present disclosure may be practiced without one or more specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments, and the additional features and advantages may not be present in all embodiments of the present disclosure.
[0112] As used herein, the term "network" refers to a network that follows any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced, Wideband Code Division Multiple Access (WCDMA), High Speed Packet Access (HSPA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single Carrier Frequency Division Multiple Access (SC-FDMA), and other wireless networks. CDMA networks may implement radio technologies such as Universal Terrestrial Radio Access (UTRA). UTRA includes WCDMA and other variants of CDMA. TDMA networks may implement radio technologies such as Global System for Mobile Communications (GSM). OFDMA networks may implement radio technologies such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, Ad-hoc networks, wireless sensor networks, etc. In the following description, the terms "network" and "system" may be used interchangeably. In addition, communication between two devices in a network may be performed according to any suitable communication protocol, including but not limited to communication protocols defined by standard organizations such as 3GPP. For example, the communication protocol may include first generation (1G), 2G, 3G, 4G, 4.5G, 5G communication protocols and / or any other protocol known currently or developed in the future.
[0113] The term "network device" or "network node" refers to any suitable network function (NF) that can be implemented in a (physical or virtual) network entity of a communication network. For example, the network function can be implemented as a network element on dedicated hardware, as a software instance running on dedicated hardware, or as a virtualized function instantiated on a suitable platform (e.g., on a cloud infrastructure). For example, a 5G system (5GS) can include multiple NFs, such as an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management (UDM), a policy control function (PCF), an application function (AF), a network exposure function (NEF), a user plane function (UPF), and a network repository function (NRF), a radio access network (RAN), a service communication proxy (SCP), a network data analytics function (NWDAF), a network slice selection function (NSSF), a network slice specific authentication and authorization function (NSSAAF), etc. For example, a 4G system (e.g., LTE (Long-Term Evolution)) can include a mobility management entity (MME), a home subscriber server (HSS), a PCRF (policy and charging rules function), a packet data network gateway (PGW), a PGW control plane (PGW-C), a serving gateway (SGW), an SGW control plane (SGW-C), an E-UTRAN node B (eNB), etc. In other embodiments, depending on the specific network, the network function can include different types of NFs.
[0114] The term "terminal device" refers to any terminal device that can access a communication network and receive services therefrom. By way of example and not limitation, terminal devices refer to mobile terminals, user equipment (UE), or other suitable devices. A UE can be, for example, a subscriber station (SS), a portable subscriber station, a mobile station (MS), or an access terminal (AT). Terminal devices can include, but are not limited to, portable computers, image capture terminal devices such as digital cameras, game terminal devices, music storage and playback devices, mobile phones, cellular phones, smart phones, Internet Protocol voice (VoIP) phones, wireless local loop phones, tablet computers, wearable devices, personal digital assistants (PDA), portable computers, desktop computers, wearable terminal devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop mounted devices (LME), USB dongles, smart devices, wireless customer premises equipment (CPE), etc. In the following description, the terms "terminal device", "terminal", "user equipment", and "UE" may be used interchangeably. As an example, a terminal device can represent a UE configured to communicate according to one or more communication standards (such as the LTE standard or NR standard of 3GPP) released by 3GPP (Third Generation Partnership Project). As used herein, a "user equipment" or "UE" may not necessarily have a "user" in terms of a human user who owns and / or operates the relevant device. In some embodiments, a terminal device can be configured to send and / or receive information without direct human interaction. For example, when triggered by an internal or external event, or in response to a request from a communication network, a terminal device can be designed to send information to the network according to a predetermined schedule. Alternatively, a UE can represent a device intended for sale to or operated by a human user but that may not initially be associated with a particular human user.
[0115] As yet another example, in an Internet of Things (IoT) scenario, a terminal device can represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or network device. In such a case, the terminal device can be a machine-to-machine (M2M) device, which can be referred to as a machine type communication (MTC) device in the context of 3GPP. As a specific example, a terminal device can be a UE that implements the 3GPP narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (such as electricity meters), industrial machinery, or household or personal appliances such as refrigerators, televisions, personal wearable devices (such as watches), etc. In other scenarios, a terminal device can represent a vehicle or other device capable of monitoring and / or reporting its operating status or other functions related to its operation.
[0116] References in the specification to "one embodiment", "an embodiment", "an exemplary embodiment", etc., indicate that the described embodiments may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes the particular feature, structure, or characteristic. Moreover, these phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that, whether or not explicitly described, the feature, structure, or characteristic is within the knowledge of those skilled in the art in connection with other embodiments to affect the same.
[0117] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0118] As used herein, the phrase "at least one of A and B" or "at least one of A or B" should be understood to mean "only A, only B, or both A and B". The phrase "A and / or B" should be understood to mean "only A, only B, or both A and B".
[0119] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the exemplary embodiments. Unless the context clearly indicates otherwise, as used herein, the singular forms "a", "an", and "the" are also intended to include the plural forms. It will be further understood that when used herein, the terms "comprises", "comprising", "has", "owns", "contains", and / or "covers" specify the presence of the described features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0120] Note that the terms used herein are only for convenience of description and for distinction between nodes, devices, or networks, etc. As technology develops, other terms with similar / same meanings may also be used.
[0121] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.
[0122] Although the subject matter described herein may be implemented in any suitable type of system using any suitable components, the embodiments disclosed herein are with respect to Figure 2The communication system with the exemplary system architecture shown is described. For simplicity, Figure 2 the system architecture only depicts some exemplary elements. In practice, the communication system may further include any additional elements suitable for supporting communication between terminal devices or between a wireless device and another communication device (such as a landline phone, a service provider, or any other network node or terminal device). The communication system may provide communication and various types of services to one or more terminal devices to facilitate the access and / or use of services provided by or via the communication system.
[0123] Figure 2 A 5G system architecture for accessing an SNPN using credentials from a credential holder of an AAA server is schematically shown, which is the same as that described in 3GPP TS23.501 V17.5.0 Figure 5 .30.2.9.2-1. Figure 2 The system architecture may include some exemplary elements such as AUSF, AMF, DN (data network), NEF, NRF, NSSF, PCF, SMF, UDM, UPF, AF, UE, (R)AN, NSSAAF (network slice specific authentication and authorization function), NSACF (network slice admission control function), AAA server, etc.
[0124] The AUSF and UDM in the SNPN may use credentials from the AAA server in the credential holder (CH) to support the primary authentication and authorization of the UE.
[0125] If the UDM decides, based on the UE's SUPI and subscription data, that the primary authentication is to be performed by the AAA server in the CH. The home network identifier is derived from the SUCI (subscription concealed identifier) received by the UDM from the AUSF. Then, the UDM instructs the AUSF: to request the primary authentication by the AAA server in the CH, the AUSF shall discover and select the NSSAAF, and then forward the EAP message to the NSSAAF. The NSSAAF selects the AAA server based on the domain name corresponding to the realm part of the SUPI, relays the EAP message between the AUSF and the AAA server (or AAA proxy), and performs the relevant protocol conversion. The AAA server acts as an EAP server for the purpose of primary authentication.
[0126] The UDM in the SNPN is pre-configured with information indicating whether the UE requires primary authentication from the AAA server based on the SLA (service level agreement) between the credential holder and the SNPN.
[0127] The SUPI is used to identify the UE during the primary authentication and authorization towards the AAA server. SUPI privacy is achieved according to the method in clause I.5 of 3GPP TS 33.501 V17.7.0.
[0128] The AMF uses the home network identifier (realm part) and the routing indicator present in the configured SUCI provided by the UE as described in clause 6.3.4 of 3GPP TS 23.501 V17.5.0 to discover and select the AUSF.
[0129] The AMF and the SMF shall use the SUPI to retrieve the UE subscription data from the UDM.
[0130] The NSSAAF deployed in the SNPN can use the credentials from the credential holder using the AAA server (as shown) to support the primary authentication in the SNPN, and / or the NSSAAF can use a network slice-specific AAA server (not shown) to support network slice-specific authentication and authorization.
[0131] Figure 3 A flowchart showing a method according to an embodiment of the present disclosure, the method may be executed by a device implemented in an authentication service node, or a device implemented at an authentication service node, or a device implemented as an authentication service node, or a device communicatively coupled to the authentication service node. Thus, the device may provide components or modules for implementing various parts of method 300, as well as components or modules for implementing other processes in combination with other components.
[0132] At block 302, the authentication service node may receive a first authentication request sent by an access and mobility node. The first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network (scenario).
[0133] The authentication service node may be any suitable network device or node or entity or function. In an embodiment, the authentication service node may include an authentication server function (AUSF). In another embodiment, the authentication service node may include an authentication center (AUC).
[0134] The access and mobility node may be any suitable network device or node or entity or function. In an embodiment, the access and mobility node may include an access and mobility management function (AMF). For example, the AMF may have a security anchor function (SEAF). In another embodiment, the access and mobility node may include a mobility management entity (MME).
[0135] The first authentication request can be any suitable message, such as an existing message or a new message. In an embodiment, the first authentication request can be the Nausf_UEAuthentication_Authenticate request as described in 3GPP TS 33.501 V17.7.0.
[0136] The subscription hidden identifier can be any suitable subscription hidden identifier. In an embodiment, the subscription hidden identifier can be the SUCI as described in 3GPP TS 33.501 V17.7.0. For example, the SUCI can be the SUCI in the NAI format (i.e., in the username@realm format as specified in Clause 28.7.3 of 3GPP TS 23.003).
[0137] The first information indicating whether the primary authentication is for the terminal device to access the network can be any suitable information, such as a bit, a flag, an indicator, etc. In an embodiment, the first information can be an indicator.
[0138] In an embodiment, when the indicator is set to true, the indicator indicates that the primary authentication is for the terminal device to access the network.
[0139] In an embodiment, when the indicator is set to false or the indicator does not exist, the indicator indicates that the primary authentication is not for the terminal device to access the network.
[0140] At block 304, the authentication service node can process the first authentication request based on the first information. For example, when the primary authentication is not for the terminal device to access the network, the authentication service node can perform corresponding operations. When the primary authentication is for the terminal device to access the network, the authentication service node can perform another corresponding operation.
[0141] Figure 4 A flowchart illustrating a method according to another embodiment of the present disclosure, which can be executed by a device implemented in an authentication service node, or a device implemented at an authentication service node, or a device implemented as an authentication service node, or a device communicatively coupled to the authentication service node. Thus, the device can provide components or modules for implementing various parts of method 400, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, their descriptions are omitted here.
[0142] At block 402, the authentication service node can receive a first authentication request sent by an access and mobility node. The first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network.
[0143] At block 404, when the first information indicates that the primary authentication is for the access of the terminal device to the network, the authentication service node may skip the selection of the data management node and skip sending a request for authentication method selection to the data management node.
[0144] For example, when the first information indicates that the primary authentication is for the access of the terminal device to the network, steps 3-5 Figure 1 are omitted.
[0145] At block 406, when the first information indicates that the primary authentication is not for the access of the terminal device to the network, the authentication service node may select the data management node and send a request for authentication method selection to the data management node.
[0146] The data management node can be any suitable network device or node or entity or function. In an embodiment, the data management node may include a Unified Data Management (UDM). In an embodiment, the data management node may include a Home Subscriber Server (HSS) or a Home Location Register (HLR).
[0147] For example, when the first information indicates that the primary authentication is not for the access of the terminal device to the network, Figure 1 steps 3-5 are executed.
[0148] Figure 5 A flowchart showing a method according to another embodiment of the present disclosure, which may be executed by a device implemented in an authentication service node, or a device implemented at an authentication service node, or a device implemented as an authentication service node, or a device communicatively coupled to the authentication service node. Thus, the device may provide components or modules for implementing various parts of method 500, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, their descriptions are omitted here for the sake of brevity.
[0149] At block 502, the authentication service node may send a second authentication request to an Independent Non-Public Network (SNPN) authentication and authorization node.
[0150] The SNPN authentication and authorization node can be any suitable network device or node or entity or function. In an embodiment, the SNPN authentication and authorization node may include a Network Slice Specific and SNPN Authentication and Authorization Function (NSSAAF).
[0151] The second authentication request can be any suitable message, such as an existing message or a new message. In an embodiment, the second authentication request may be an Nnssaaf_AIW_Authenticate request as described in 3GPP TS 33.501 V17.7.0.
[0152] In an embodiment, block 502 is related to Figure 1is the same as step 6.
[0153] At block 504, the authentication service node may receive a second authentication response from the SNPN authentication and authorization node, including authentication success, a master session key, and a subscription permanent identifier.
[0154] The second authentication response may be any suitable message, such as an existing message or a new message. In an embodiment, the second authentication response may be an Nnssaaf_AIW_Authenticate response as described in 3GPP TS 33.501 V17.7.0.
[0155] For example, when the NSSAAF receives an Nnssaaf_AIW_Authenticate request from the AUSF, steps 7-9 in Figure 1 may be performed.
[0156] In an embodiment, block 504 is the same as step 10 in Figure 1
[0157] At block 506, when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier received in the first authentication request is not anonymous, the authentication service node may skip sending an authentication result confirmation request to the data management node.
[0158] The authentication result confirmation request may be any suitable message, such as an existing message or a new message. In an embodiment, the authentication result confirmation request may be an Nudm_UEAU_ResultConfirmation request as described in 3GPP TS 33.501 V17.7.0.
[0159] At block 508, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous, the authentication service node may send an authentication result confirmation request to the data management node and receive an authentication result confirmation response from the data management node. The authentication result confirmation request is used to verify that the subscription permanent identifier corresponds to a valid subscription in the SNPN.
[0160] For example, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous, steps 11-13 in Figure 1 may be performed.
[0161] Figure 6a A flowchart of a method according to another embodiment of the present disclosure is shown. The method may be performed by a device implemented in an authentication service node, or a device implemented at an authentication service node, or a device implemented as an authentication service node, or a device communicatively coupled to the authentication service node. Thus, the device may provide components or modules for implementing various parts of method 600, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, their descriptions are omitted here.
[0162] In this embodiment, the first information indicates that the primary authentication is for the terminal device to access the network, or the subscription hidden identifier received in the first authentication request is not anonymous.
[0163] At block 602, the authentication service node may generate a key for the authentication service node and a key for the security anchor function.
[0164] In an embodiment, block 602 is the same as Figure 1 step 14.
[0165] At block 604, the authentication service node may send a first authentication response including authentication success, the key of the security anchor function, and the subscription permanent identifier to the access and mobility node.
[0166] In an embodiment, block 604 is the same as Figure 1 step 15.
[0167] Figure 6b A flowchart of a method according to another embodiment of the present disclosure is shown. The method may be performed by a device implemented in an authentication service node, or a device implemented at an authentication service node, or a device implemented as an authentication service node, or a device communicatively coupled to the authentication service node. Thus, the device may provide components or modules for implementing various parts of method 610, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, their descriptions are omitted here.
[0168] In this embodiment, the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous.
[0169] At block 612, when the authentication result confirmation response includes second information indicating that the user subscription verification fails, or the user is not found, or the SNPN subscription is missing, the authentication service node may reject the terminal device from accessing the SNPN and send a first authentication response including the second information to the access and mobility node.
[0170] Figure 6cA flowchart showing a method according to another embodiment of the present disclosure, which may be executed by a device implemented in an access and mobility node, or a device implemented at an access and mobility node, or a device implemented as an access and mobility node, or a device communicatively coupled to an access and mobility node. Thus, the device may provide components or modules for implementing various parts of method 620, as well as components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, for the sake of brevity, their descriptions are omitted here.
[0171] At block 622, the access and mobility node may receive a registration request for registration in a Standalone Non-Public Network (SNPN) from a terminal device. The registration request includes a subscription hidden identifier.
[0172] In an embodiment, block 622 is the same as Figure 1 step 1 of
[0173] At block 624, the access and mobility node may send a first authentication request to an authentication service node. The first authentication request includes a subscription hidden identifier and a first piece of information indicating whether the primary authentication is for the terminal device to access the network.
[0174] In an embodiment, the first piece of information may be an indicator.
[0175] In an embodiment, when the indicator is set to true, it may indicate that the primary authentication is for the terminal device to access the network.
[0176] In an embodiment, when the indicator is set to false or the indicator does not exist, it may indicate that the primary authentication is not for the terminal device to access the network.
[0177] In an embodiment, the access and mobility node includes an Access and Mobility Management Function (AMF).
[0178] In an embodiment, the authentication service node includes an Authentication Server Function (AUSF).
[0179] Figure 6d A flowchart showing a method according to another embodiment of the present disclosure, which may be executed by a device implemented in an access and mobility node, or a device implemented at an access and mobility node, or a device implemented as an access and mobility node, or a device communicatively coupled to an access and mobility node. Thus, the device may provide components or modules for implementing various parts of method 630, as well as components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, for the sake of brevity, their descriptions are omitted here.
[0180] In this embodiment, the first information indicates that the primary authentication is for the terminal device to access the network or subscribe to a hidden identifier that is not anonymous.
[0181] At block 632, the access and mobility node may receive a first authentication response from the authentication service node, including authentication success, the key of the security anchor function, and the subscribed permanent identifier.
[0182] In an embodiment, block 632 is the same as Figure 1 step 15 in
[0183] At block 634, the access and mobility node may send authentication success to the terminal device.
[0184] In an embodiment, block 634 is the same as Figure 1 step 16 in
[0185] Figure 6e A flowchart showing a method according to another embodiment of the present disclosure, which may be executed by a device implemented in an access and mobility node, or a device implemented at an access and mobility node, or a device implemented as an access and mobility node, or a device communicatively coupled to an access and mobility node. Therefore, the device may provide components or modules for implementing various parts of method 640, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, their descriptions are omitted here.
[0186] In this embodiment, the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscribed hidden identifier is anonymous.
[0187] At block 642, the access and mobility node may receive a first authentication response from the authentication service node, the first authentication response including second information indicating that the user subscription verification fails, or the user is not found, or the SNPN subscription is missing.
[0188] At block 644, the access and mobility node may send the second information to the terminal device. For example, the second information may be sent in an N1 message.
[0189] Figure 7a A flowchart showing a method according to another embodiment of the present disclosure, which may be executed by a device implemented in a terminal device, or a device implemented at a terminal device, or a device implemented as a terminal device, or a device communicatively coupled to a terminal device. Therefore, the device may provide components or modules for implementing various parts of method 700, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, their descriptions are omitted here.
[0190] At block 702, the terminal device may send a registration request for registration in a Standalone Non-Public Network (SNPN) to an access and mobility node. The registration request includes a subscription hidden identifier.
[0191] In an embodiment, the access and mobility node may include an Access and Mobility Management Function (AMF).
[0192] At block 704, the terminal device may receive authentication success or second information from the access and mobility node. The second information indicates that the user subscription verification has failed or the user has not been found or the SNPN subscription is missing.
[0193] At block 706, optionally, the terminal device may provide the second information to the user of the terminal device.
[0194] Figure 7b A flowchart showing primary authentication with UE network access indication according to another embodiment of the present disclosure.
[0195] The flowchart shows the changes for primary authentication with a UE network access indication in a signaling message from the AMF to the AUSF, and how the AUSF further uses this information during the process for primary authentication.
[0196] Compared with Figure 1 the existing process, the changes are as follows:
[0197] Step 2: The AMF within the SNPN shall initiate primary authentication for the UE with the AUSF using the Nausf_UEAuthentication_Authenticate service operation. The AMF shall discover and select the AUSF based on the criteria specified in clause 5.30.2.9.2 of 3GPP TS23.501 V17.5.0.
[0198] This step is updated as follows: The AMF shall indicate to the AUSF in the signaling whether the primary authentication is for a UE network access situation using a network access indicator. If the indicator is set to true, it indicates to the AUSF that the authentication is for network access, and if the indicator is set to false or this attribute does not exist, it implicitly indicates that the authentication is not for network access (situation). The AUSF shall internally store this value for future use (e.g., in step 10-a and step 13-a).
[0199] As described in 3GPP TS29.509 V17.7.0, the Nausf_UEAuthentication_Authenticate service operation request payload does not yet support this possibility.
[0200] In an embodiment, Table 6.1.6.2.2-1 of 3GPP TS29.509 V17.7.0 can be modified as follows. Table 6.1.6.2.2-1: Definition of type AuthenticationInfo
[0201] Step 2-a: A new step for the AUSF to check the access indication in the signaling message from the AMF. If the AMF indicates access (true) in the signaling, the AUSF may skip the UDM selection and not perform steps 3-5. If access is not indicated (false or absent) in the signaling, it may continue with steps 3-5.
[0202] Step 10-a: A new step for the AUSF to check when receiving EAP-Success from step 10, where EAP-Success means the authentication has been successful, i.e., the UE and the network have mutually authenticated using the negotiated EAP authentication method. In step 10, the SUPI is also returned as the UE identifier. Based on the access indication from the signaling message in step 2 and the SUPI in step 2, the AUSF may perform at least one of the following:
[0203] - If the access is indicated from the signaling message in step 2, skip steps 11-13.
[0204] - If the access is not indicated from the signaling message in step 2 and the SUPI from step 2 is anonymous, continue with steps 11-13.
[0205] Step 13-a: A new step for the AUSF to check when receiving a response for the Nudm_UEAU_ResultConfirmation service operation from the UDM in step 13. Based on the access indication in the signaling message from step 2 and the response returned from step 13, the AUSF may perform at least one of the following:
[0206] - If the access is indicated from the signaling message in step 2, continue with branch 1: steps 14-17
[0207] - If the access is not indicated from the signaling message in step 2 and a USER_NOT_FOUND error is returned from step 13, continue with new branch 2: steps 15-a, step 16-a, step 17-a (skipping step 14, so there is no corresponding alternative step).
[0208] Step 15-a: Although the authentication is successful, the response code in Step 13 indicates that the user subscription verification fails. The AUSF shall return a new cause code to the AMF. An example cause code is LACKING_SNPN_SUBSCRIPTION.
[0209] Step 16-a: The AMF may notify the UE of the cause of LACKING_SNPN_SUBSCRIPTION so that the UE knows the real reason for the access rejection: Although the authentication is successful, the SNPN subscription is missing.
[0210] Step 17-a: The UE shows the user that the real reason for the SNPN access rejection is LACKING_SNPN_SUBSCRIPTION, rather than authentication failure (in fact, the authentication is successful). Therefore, the user can contact the SNPN operator support to solve the problem.
[0211] The remaining steps are the same as Figure 1 the corresponding steps of
[0212] In the embodiment, new steps are introduced between the AMF and the AUSF. When the AMF sends an authentication request for the UE, it indicates in the signaling whether the authentication is for network access.
[0213] In the embodiment, new steps for the AUSF are introduced. Based on the new indication from the above signaling, the AUSF decides whether to query the UDM for the authentication method.
[0214] In the embodiment, new steps for the AUSF are introduced. Based on the new indication from the above signaling, the AUSF decides whether to verify the SNPN subscription by notifying the UDM of the authentication result.
[0215] In the embodiment, new steps for the AUSF are introduced. Based on the absence of the new indication from the signaling and other information, the AUSF decides whether to reject the access to the SNPN through the result of the subscription verification by notifying the UDM of the authentication result.
[0216] In the embodiment, the AUSF may notify the AMF, and the AMF further notifies the UE that the real reason for the rejection of access to the SNPN is the lack of SNPN subscription, rather than authentication failure (in fact, the authentication result is successful).
[0217] In the embodiment, new steps for the UE are introduced to indicate to the user that the real reason for the SNPN access rejection is the lack of SNPN subscription rather than authentication failure. Therefore, the user can contact the SNPN operator support service based on the real reason to solve the problem.
[0218] The embodiments in this document can provide many advantages, and the following is a non-exhaustive list of examples of advantages. In some embodiments in this document, if authentication is used for network access, unnecessary signaling to a data management node (such as the UDM) can be avoided. This can improve the system performance of both the authentication service node AUSF and the data management node (such as the UDM). In some embodiments in this document, network access services can be treated differently from non-network access services, so the CSP can monetize their networks based on meeting different service requirements. In some embodiments in this document, since the real reason for the SNPN access rejection situation can be detected and the user can correctly find the corresponding support, user satisfaction is improved. This can help the CSP reduce OPEX and at the same time retain subscriber royalties. The embodiments in this document are not limited to the above features and advantages. Those skilled in the art will recognize additional features and advantages after reading the following detailed description.
[0219] Figure 8a is a block diagram showing an apparatus suitable for practicing some embodiments of the present disclosure. For example, any one of the above authentication service nodes, access and mobility nodes, or terminal devices can be implemented as or by the apparatus 800.
[0220] The apparatus 800 includes at least one processor 821, such as a digital processor (DP), and at least one memory (MEM) 822 coupled to the processor 821. The apparatus 800 may further include a transmitter TX and a receiver RX 823 coupled to the processor 821. The MEM 822 stores a program (PROG) 824. The PROG 824 may include instructions that, when executed on the relevant processor 821, cause the apparatus 800 to operate according to the embodiments of the present disclosure. The combination of at least one processor 821 and at least one MEM 822 may form a processing device 825 suitable for implementing various embodiments of the present disclosure.
[0221] Various embodiments of the present disclosure can be implemented by a computer program that can be executed by one or more of the processor 821, software, firmware, hardware, or a combination thereof.
[0222] The MEM 822 can be of any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory, as non-limiting examples.
[0223] The processor 821 can be of any type suitable for the local technical environment and can include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture, as non-limiting examples.
[0224] In an embodiment where the apparatus is implemented as an authentication service node or implemented at an authentication service node, the memory 822 stores instructions that can be executed by the processor 821, whereby the authentication service node operates according to any method related to the authentication service node as described above.
[0225] In an embodiment where the apparatus is implemented as an access and mobility node or implemented at an access and mobility node, the memory 822 stores instructions that can be executed by the processor 821, whereby the access and mobility node operates according to any method related to the access and mobility node as described above.
[0226] In an embodiment where the apparatus is implemented as a terminal device or implemented at a terminal device, the memory 822 stores instructions that can be executed by the processor 821, whereby the terminal device operates according to any method related to the terminal device as described above.
[0227] Figure 8b is a block diagram showing an authentication service node according to an embodiment of the present disclosure. As shown, the authentication service node 830 includes a first receiving module 831 configured to receive a first authentication request sent by an access and mobility node. The first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network. The authentication service node 830 further includes a processing module 832 configured to process the first authentication request based on the first information.
[0228] In an embodiment, the authentication service node 830 further includes a first sending module 833 configured to send a second authentication request to an independent non-public network (SNPN) authentication and authorization node.
[0229] In an embodiment, the authentication service node 830 further includes a second receiving module 834 configured to receive a second authentication response including authentication success, a master session key, and a subscription permanent identifier from the SNPN authentication and authorization node.
[0230] In an embodiment, the authentication service node 830 further includes a skip module 835 configured to skip sending an authentication result confirmation request to the data management node when the first information indicates that the primary authentication is for the terminal device to access the network or when the subscription hidden identifier received in the first authentication request is not anonymous.
[0231] In an embodiment, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous, the authentication service node 830 further includes a second sending module 836 configured to send an authentication result confirmation request to the data management node, and a third receiving module 837 configured to receive an authentication result confirmation response from the data management node. The authentication result confirmation request is used to verify that the subscription permanent identifier corresponds to a valid subscription in the SNPN.
[0232] In an embodiment, when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier received in the first authentication request is not anonymous, the authentication service node 830 further includes a generating module 838-1 configured to generate a key for the authentication service node and a key for the security anchor function, and a third sending module 838-2 configured to send a first authentication response including authentication success, the key for the security anchor function, and the subscription permanent identifier to the access and mobility node.
[0233] In an embodiment, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous, and when the authentication result confirmation response includes second information indicating that the user subscription verification fails, or the user is not found, or the SNPN subscription is missing, the authentication service node 830 further includes: a rejecting module 839-1 configured to reject the terminal device from accessing the SNPN, and a fourth sending module 839-2 configured to send a first authentication response including the second information to the access and mobility node.
[0234] Figure 8c FIG. is a block diagram of an access and mobility node according to an embodiment of the present disclosure. As shown, the access and mobility node 840 includes a first receiving module 841 configured to receive a registration request for registering in a Standalone Non-Public Network (SNPN) from a terminal device. The registration request includes a subscription hidden identifier. The access and mobility node 840 further includes a first sending module 842 configured to send a first authentication request to the authentication service node. The first authentication request includes the subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network.
[0235] In an embodiment, when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier is not anonymous, the access and mobility node 840 further includes a second receiving module 843 configured to receive a first authentication response including authentication success, the key for the security anchor function, and the subscription permanent identifier from the authentication service node, and a second sending module 844 configured to send authentication success to the terminal device.
[0236] In an embodiment, when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscribed hidden identifier is anonymous, the access and mobility node 840 further includes a third receiving module 845 configured to receive, from the authentication service node, a first authentication response including second information indicating a failure in user subscription verification or that the user is not found or a lack of SNPN subscription, and a third sending module 846 configured to send the second information to the terminal device.
[0237] Figure 9 FIG. is a block diagram of a terminal device according to an embodiment of the present disclosure. As shown, the terminal device 900 includes a sending module 901 configured to send a registration request for registration in a Standalone Non-Public Network (SNPN) to an access and mobility node. The registration request includes a subscribed hidden identifier. The terminal device 900 further includes a receiving module 902 configured to receive, from the access and mobility node, an authentication success or second information, where the second information indicates a failure in user subscription verification or that the user is not found or a lack of SNPN subscription.
[0238] In an embodiment, the terminal device 900 further includes a providing module 903 configured to provide the second information to a user of the terminal device.
[0239] The term unit or module may have a conventional meaning in the field of electronic devices, electrical equipment, and / or electronic equipment, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, output, and / or display functions, etc., such as those described herein.
[0240] By using functional units, the authentication service node, the access and mobility node, or the terminal device may not require a fixed processor or memory, and any computing resources and storage resources may be arranged from the authentication service node, the access and mobility node, or the terminal device in the communication system. The introduction of virtualization technology and network computing technology can improve the utilization efficiency of network resources and the flexibility of the network.
[0241] In one aspect of the present disclosure, there is provided a computer program product tangibly stored on a computer-readable storage medium and including instructions that, when executed on at least one processor, cause the at least one processor to perform any of the above methods.
[0242] In one aspect of the present disclosure, there is provided a computer-readable storage medium storing instructions that, when executed on at least one processor, cause the at least one processor to perform any of the above methods.
[0243] In addition, an exemplary overall communication system including a terminal device and a network node will be described below.
[0243] In addition, an exemplary overall communication system including a terminal device and a network node will be described below.
[0244] In addition, an exemplary overall communication system including a terminal device and a network node (such as the above-mentioned authentication service node and access and mobility node) will be described below.
[0245] Figure 10 An example of a communication system QQ100 according to some embodiments is shown.
[0246] In this example, the communication system QQ100 includes a telecommunications network QQ102, which includes an access network QQ104 (such as a radio access network (RAN)) and a core network QQ106, and the core network includes one or more core network nodes QQ108. The access network QQ104 includes one or more access network nodes, such as network nodes QQ110a and QQ110b (one or more of which are generally referred to as network node QQ110), or any other similar 3rd Generation Partnership Project (3GPP) access node or non-3GPP access point. The network node QQ110 facilitates the direct or indirect connection of user equipment (UE), such as connecting UEs QQ112a, QQ112b, QQ112c, and QQ112d (one or more of which are generally referred to as UE QQ112) to the core network QQ106 through one or more wireless connections.
[0247] Example wireless communications via wireless connections include using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for transmitting information without using wires, cables, or other material conductors to send and / or receive wireless signals. In addition, in different embodiments, the communication system QQ100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that can facilitate or participate in the communication of data and / or signals, whether through wired or wireless connections. The communication system QQ100 may include any type of communication, telecommunications, data, cellular, radio network, and / or other similar types of systems and / or interface therewith.
[0248] The UE QQ112 can be any one of a variety of communication devices, including wireless devices that are arranged, configured, and / or operable to communicate wirelessly with the network node QQ110 and other communication devices. Similarly, the network node QQ110 is arranged, capable, configured, and / or operable to communicate directly or indirectly with the UE QQ112 and / or with other network nodes or devices in the telecommunication network QQ102 to enable and / or provide network access (e.g., wireless network access) and / or perform other functions (e.g., management in the telecommunication network QQ102).
[0249] In the depicted example, the core network QQ106 connects the network node QQ110 to one or more hosts (e.g., host QQ116). These connections can be direct or indirect through one or more intermediate networks or devices. In other examples, the network node can be directly coupled to the host. The core network QQ106 includes one or more core network nodes (e.g., core network node QQ108), which are composed of hardware and software components. The characteristics of these components can be substantially similar to those described for the UE, network node, and / or host, such that the description generally applies to the corresponding components of the core network node QQ108. Example core network nodes include one or more of the following: Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-hiding Function (SIDF), Unified Data Management (UDM), Secure Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or User Plane Function (UPF).
[0250] The host QQ116 can be owned or controlled by a service provider other than the operator or provider of the access network QQ104 and / or the telecommunication network QQ102, and can be operated by the service provider or on behalf of the service provider. The host QQ116 can host various applications to provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data collection services (e.g., retrieving and compiling data on various environmental conditions detected by multiple UEs), analytical functions, social media, functions for controlling or otherwise interacting with remote devices, functions for alarm and monitoring centers, or any other such functions performed by a server.
[0251] Generally speaking, Figure 10The communication system QQ100 enables connections between UEs, network nodes, and hosts. In this sense, the communication system QQ100 can be configured to operate according to predefined rules or procedures, such as specific standards, which include but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long-Term Evolution (LTE) and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future-generation standards (e.g., 6G); Wireless Local Area Network (WLAN) standards, such as Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standards, such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC), ZigBee, LiFi, and / or any Low-Power Wide-Area Network (LPWAN) standards, such as LoRa and Sigfox.
[0252] In some examples, the telecommunication network QQ102 is a cellular network implementing 3GPP standardized features. Thus, the telecommunication network QQ102 can support network slicing to provide different logical networks to different devices connected to the telecommunication network QQ102. For example, the telecommunication network QQ102 can provide ultra-reliable low-latency communication (URLLC) services to some UEs, while providing enhanced mobile broadband (eMBB) services to other UEs, and / or providing massive machine-type communication (mMTC) / massive IoT services to more UEs.
[0253] In some examples, the UE QQ112 is configured to send and / or receive information without direct human interaction. For example, the UE can be designed to transmit information to the access network QQ104 according to a predefined timeline, when triggered by an internal or external event, or in response to a request from the access network QQ104. In addition, the UE can be configured to operate in single or multi-RAT or multi-standard mode. For example, the UE can operate using any one or a combination of Wi-Fi, NR (New Radio), and LTE, i.e., be configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved UMTS Terrestrial Radio Access Network)-New Radio-dual connectivity (EN-DC).
[0254] In this example, the hub QQ114 communicates with the access network QQ104 to facilitate indirect communication between one or more UEs (e.g., UEs QQ112c and / or QQ112d) and a network node (e.g., network node QQ110b). In some examples, the hub QQ114 can be a controller, router, content source and analyzer, or any other communication device described herein with respect to the UE. For example, the hub QQ114 can be a broadband router that enables the UE to access the core network QQ106. As another example, the hub QQ114 can be a controller that sends commands or instructions to one or more actuators in the UE. The commands or instructions can be received from the UE, the network node QQ110, or be received by executable code, scripts, procedures, or other instructions in the hub QQ114. As another example, the hub QQ114 can be a data collector that acts as a temporary storage for UE data and, in some embodiments, can perform analysis or other processing of the data. As another example, the hub QQ114 can be a content source. For example, for a UE that is a VR headset, display, speaker, or other media delivery device, the hub QQ114 can retrieve VR assets, videos, audio, or other media or data related to sensing information via the network node, and then the hub QQ114 provides it directly, after performing local processing, and / or after adding additional local content to the UE. In yet another example, the hub QQ114 acts as a proxy server or coordinator for the UE, especially when one or more of the UEs are low-power IoT devices.
[0255] The hub QQ114 can have a constant / persistent or intermittent connection to the network node QQ110b. The hub QQ114 can also allow for different communication schemes and / or scheduling between the hub QQ114 and the UEs (e.g., UEs QQ112c and / or QQ112d) and between the hub QQ114 and the core network QQ106. In other examples, the hub QQ114 is connected to the core network QQ106 and / or one or more UEs via a wired connection. Additionally, the hub QQ114 can be configured to connect to an M2M service provider via the access network QQ104 and / or to another UE via a direct connection. In some scenarios, a UE can establish a wireless connection to the network node QQ110 while still being connected via the hub QQ114 via a wired or wireless connection. In some embodiments, the hub QQ114 can be a dedicated hub, i.e., a hub whose main function is to route communications from the UEs to the network node QQ110b and / or from the network node QQ110b to the UEs. In other embodiments, the hub QQ114 can be a non-dedicated hub, i.e., a device that is capable of operating to route communications between the UEs and the network node QQ110b but that is additionally capable of operating as a communication origin and / or destination for certain data channels.
[0256] Figure 11 is a block diagram of a host QQ400 according to various aspects described herein, which can be Figure 10 an embodiment of the host QQ116. As used herein, the host QQ400 can be or include a combination of various hardware and / or software, including a stand-alone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, a container, or processing resources in a server farm. The host QQ400 can provide one or more services to one or more UEs.
[0257] The host QQ400 includes a processing circuit QQ402 that is operatively coupled via a bus QQ404 to an input / output interface QQ406, a network interface QQ408, a power supply QQ410, and a memory QQ412. Other components can be included in other embodiments. The characteristics of these components can be substantially similar to those described with respect to the devices in the previous figures (e.g., Figures QQ2 and QQ3) such that their description generally applies to the corresponding components of the host QQ400.
[0258] The memory QQ412 can store one or more computer programs (including one or more host applications QQ414) and data QQ416, which can include user data, such as data generated by the UE for the host QQ400 or data generated by the host QQ400 for the UE. Embodiments of the host QQ400 can utilize a subset or all of only the components shown. The host application QQ414 can be implemented in a container-based architecture and can provide support for video codecs (e.g., Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for a variety of different classes, types, or implementations of UEs (e.g., mobile phones, desktop computers, wearable display systems, heads-up display systems). The host application QQ414 can also provide user authentication and license checking and can periodically report health status, routing, and content availability to a central node (e.g., a device in the core network or at the edge). Thus, the host QQ400 can select and / or indicate different hosts for over-the-top services for the UE. The host application QQ414 can support various protocols, such as the HTTP Live Streaming (HLS) protocol, the Real-Time Messaging Protocol (RTMP), the Real-Time Streaming Protocol (RTSP), the Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.
[0259] Figure 12 A communication diagram is shown of a host QQ602 communicating with a UE QQ606 over a partial wireless connection via a network node QQ604, according to some embodiments. According to various embodiments, the UE (e.g., Figure 12 discussed in the previous paragraphs will now be described with reference to Figure 10 the UE QQ112a of Figure 10 and / or the UE QQ200 of FIG. QQ2), the network node (e.g., Figure 10 the network node QQ110a of Figure 11 and / or the network node QQ300 of FIG. QQ3), and the host (e.g.,
[0260] Similar to host QQ400, embodiments of host QQ602 include hardware, such as a communication interface, processing circuitry, and a memory. Host QQ602 also includes software that is stored in or accessible by host QQ602 and executable by the processing circuitry. The software includes a host application that is operable to provide services to remote users, such as UE QQ606 connected via an over-the-top (OTT) connection QQ650 extending between UE QQ606 and host QQ602. In providing services to remote users, the host application may provide user data transmitted using OTT connection QQ650.
[0261] Network node QQ604 includes hardware that enables network node QQ604 to communicate with host QQ602 and UE QQ606. Connection QQ660 may be direct or through a core network (such as Figure 10 core network QQ106) and / or one or more other intermediate networks (such as one or more public, private, or managed networks). For example, the intermediate network may be a backbone network or the Internet.
[0262] UE QQ606 includes hardware and software that is stored in or accessible by UE QQ606 and executable by the processing circuitry of the UE. The software includes a client application, such as a web browser or an operator-specific "app", that is operable to provide services to a human or non-human user via UE QQ606 with the support of host QQ602. In host QQ602, the executing host application may communicate with the executing client application via OTT connection QQ650 terminating at UE QQ606 and host QQ602. When providing services to a user, the client application of the UE may receive request data from the host application of the host and provide user data in response to the request data. OTT connection QQ650 may transmit both request data and user data. The client application of the UE may interact with the user to generate user data that is provided to the host application via OTT connection QQ650.
[0263] OTT connection QQ650 may extend via connection QQ660 between host QQ602 and network node QQ604 and via wireless connection QQ670 between network node QQ604 and UE QQ606 to provide a connection between host QQ602 and UE QQ606. Connection QQ660 and wireless connection QQ670 (through which OTT connection QQ650 may be provided) have been drawn abstractly to illustrate communication between host QQ602 and UE QQ606 via network node QQ604 without explicitly referring to any intermediate devices and the exact routing of messages through these devices.
[0264] As an example of transmitting data via OTT connection to QQ650, in step QQ608, the host QQ602 provides user data, which can be performed by running a host application. In some embodiments, the user data is associated with a specific human user interacting with the UE QQ606. In other embodiments, the user data is associated with the UE QQ606 that shares data with the host QQ602 without explicit human interaction. In step QQ610, the host QQ602 initiates a transmission carrying the user data to the UE QQ606. The host QQ602 can initiate the transmission in response to a request sent by the UE QQ606. The request can be caused by a human interaction with the UE QQ606 or by an operation of a client application running on the UE QQ606. According to the teachings of the embodiments described in the present disclosure, the transmission can be relayed via the network node QQ604. Thus, in step QQ612, according to the teachings of the embodiments described throughout the present disclosure, the network node QQ604 transmits the user data carried in the transmission initiated by the host QQ602 to the UE QQ606. In step QQ614, the UE QQ606 receives the user data carried in the transmission, and this reception can be performed by a client application running on the UE QQ606, which is associated with the host application running on the host QQ602.
[0265] In some examples, the UE QQ606 runs a client application that provides user data to the host QQ602. The user data can be provided as a reaction or response to the data received from the host QQ602. Thus, in step QQ616, the UE QQ606 can provide user data, which can be performed by running the client application. When providing the user data, the client application can also consider user input received from the user via the input / output interface of the UE QQ606. Regardless of the specific manner of providing the user data, the UE QQ606 initiates, in step QQ618, a transmission of the user data to the host QQ602 via the network node QQ604. In step QQ620, according to the teachings of the embodiments described in the present disclosure, the network node QQ604 receives the user data from the UE QQ606 and initiates a transmission of the received user data to the host QQ602. In step QQ622, the host QQ602 receives the user data carried in the transmission initiated by the UE QQ606.
[0266] One or more of the various embodiments improve the performance of the OTT service provided to UE QQ606 using the OTT connection QQ650, where the wireless connection QQ670 forms the last segment. More precisely, in some embodiments herein, if authentication is used for network access, unnecessary signaling to a data management node (e.g., UDM) can be avoided. This can improve the system performance of both the authentication service node AUSF and the data management node (e.g., UDM). In some embodiments herein, network access services can be treated differently than non-network access services, so the CSP can monetize their network based on meeting different service requirements. In some embodiments herein, since the true cause of the SNPN access rejection situation can be detected and the user can correctly find the corresponding support, user satisfaction is improved. This can help the CSP reduce OPEX and at the same time retain subscriber royalties.
[0267] In an example scenario, the host QQ602 can collect and analyze factory status information. As another example, the host QQ602 can process audio and video data that may have been retrieved from the UE for map creation. As another example, the host QQ602 can collect and analyze real-time data to assist in controlling vehicle congestion (e.g., controlling traffic lights). As another example, the host QQ602 can store the surveillance videos uploaded by the UE. As another example, the host QQ602 can store or control access to media content such as video, audio, VR, or AR that can be broadcast, multicast, or unicast to the UE. As other examples, the host QQ602 can be used for energy pricing, remote control of non-time-critical electrical loads to balance power generation demand, location services, demonstration services (compiling graphs of data collected from remote devices, etc.), or any other function of collecting, retrieving, storing, analyzing, and / or transmitting data.
[0268] In some examples, a measurement process can be provided for monitoring data rate, latency, and other factors that one or more embodiments improve upon. There can also be optional network functions for reconfiguring the over-the-top (OTT) connection QQ650 between the host QQ602 and the UE QQ606 in response to changes in the measurement results. The measurement process and / or the network functions for reconfiguring the OTT connection can be implemented in the software and hardware of the host QQ602 and / or the UE QQ606. In some embodiments, sensors (not shown) can be deployed in or associated with other devices through which the OTT connection QQ650 passes; the sensors can participate in the measurement process by providing values of the exemplified monitored quantities or by providing values of other physical quantities, and the software can calculate or estimate the monitored quantities based on the values of the other physical quantities. The reconfiguration of the OTT connection QQ650 can include message format, retransmission settings, preferred routing, etc.; the reconfiguration does not need to directly change the operation of the network node QQ604. Such processes and functions are known and practiced in the art. In certain embodiments, the measurement can involve proprietary UE signaling that helps the host QQ602 measure throughput, propagation time, latency, etc. The measurement can be achieved by software causing messages (especially empty messages or "virtual" messages) to be transmitted using the OTT connection QQ650 while monitoring propagation time, errors, etc.
[0269] Embodiment 1. A host configured to operate in a communication system to provide over-the-top (OTT) services, the host comprising:
[0270] Processing circuitry configured to provide user data; and
[0271] A network interface configured to initiate transmission of the user data to a network node in a cellular network for transmission to a user equipment (UE), the network node having a communication interface and processing circuitry, the processing circuitry of the network node being configured to perform the operations associated with the network node as described above to send or facilitate sending of the user data from the host to the UE.
[0272] Embodiment 2. The host of the preceding embodiment, wherein:
[0273] The processing circuitry of the host is configured to run a host application that provides the user data; and
[0274] The UE includes processing circuitry configured to run a client application associated with the host application to receive transmission of the user data from the host.
[0275] Embodiment 3. A method implemented in a host configured to operate in a communication system further comprising a network node and a user equipment (UE), the method comprising:
[0276] Provide user data for the UE; and
[0277] Initiate a transmission of user data to the UE via a cellular network including a network node, where the network node performs the operations related to the network node as described above to send or facilitate sending user data from the host to the UE.
[0278] Example 4. The method of the foregoing example further includes sending, at the network node, user data provided by the host for the UE.
[0279] Example 5. The method of any of the previous 2 examples, where user data is provided at the host by running a host application that interacts with a client application running on the UE, and the client application is associated with the host application.
[0280] Example 6. A communication system configured to provide an over-the-top service, the communication system including:
[0281] A host, including:
[0282] Processing circuitry configured to provide user data for a user equipment (UE), the user data being associated with an over-the-top service; and
[0283] A network interface configured to initiate a transmission of user data to a cellular network node for transmission to the UE, the network node having a communication interface and processing circuitry, and the processing circuitry of the network node being configured to perform the operations related to the network node as described above to send or facilitate sending user data from the host to the UE.
[0284] Example 7. The communication system of the foregoing example further includes:
[0285] A network node; and / or
[0286] A user equipment.
[0287] Example 8. The communication system of the previous 2 examples, where:
[0288] The processing circuitry of the host is configured to run a host application to provide user data; and
[0289] The host application is configured to interact with a client application running on the UE, and the client application is associated with the host application.
[0290] Example 9. A host configured to operate in a communication system to provide an over-the-top (OTT) service, the host including:
[0291] Processing circuitry configured to initiate reception of user data; and
[0292] A network interface configured to receive user data from a network node in a cellular network, the network node having a communication interface and a processing circuit, the processing circuit of the network node being configured to perform the operations associated with the network node as described above to receive or facilitate the reception of user data from a UE for a host.
[0293] Example 10. The host in the previous 2 examples, wherein:
[0294] The processing circuit of the host is configured to run a host application to provide user data; and
[0295] The host application is configured to interact with a client application running on a UE, the client application being associated with the host application.
[0296] Example 11. The host in any of the previous 2 examples, wherein initiating the reception of user data includes requesting user data.
[0297] Example 12. A method implemented by a host, the host being configured to operate in a communication system further including a network node and a user equipment (UE), the method including:
[0298] At the host, initiating the reception of user data from the UE, the user data originating from a transmission that the network node has received from the UE, wherein the network node performs the operations associated with the network node as described above to receive or facilitate the reception of user data from the UE for the host.
[0299] Example 13. The method of the previous example, further including, at the network node, sending the received user data to the host.
[0300] Example 14. A host configured to operate in a communication system to provide an over-the-top (OTT) service, the host including:
[0301] A processing circuit configured to provide user data; and
[0302] A network interface configured to initiate the transmission of user data to a cellular network for transmission to a user equipment (UE), wherein the UE includes a communication interface and a processing circuit, the communication interface and processing circuit of the UE being configured to perform the operations associated with a terminal device as described above to receive or facilitate the reception of user data from the host.
[0303] Example 15. The host of the previous example, wherein the cellular network further includes a network node configured to communicate with the UE to send user data from the host to the UE.
[0304] Example 16. The host of the previous 2 examples, wherein:
[0305] The processing circuitry of the host is configured to run a host application to provide user data; and
[0306] The host application is configured to interact with a client application running on a UE, and the client application is associated with the host application.
[0307] Example 17. A method implemented by a host, the host operating in a communication system further including a network node and a user equipment (UE), the method comprising:
[0308] Providing user data for the UE; and
[0309] Initiating a transmission carrying the user data to the UE via a cellular network including a network node, wherein the UE performs operations related to the terminal device as described above to receive or facilitate the reception of user data from the host.
[0310] Example 18. The method of the foregoing example, further comprising:
[0311] At the host, running a host application associated with a client application running on the UE to receive user data from the UE.
[0312] Example 19. The method of the foregoing example, further comprising:
[0313] At the host, sending input data to a client application running on the UE, the input data being provided by running the host application,
[0314] wherein the user data is provided by the client application in response to the input data from the host application.
[0315] Example 20. A host configured to operate in a communication system to provide an over-the-top (OTT) service, the host comprising:
[0316] Processing circuitry configured to utilize user data; and
[0317] A network interface configured to receive a transmission of user data of a transmission of the user equipment (UE) to the cellular network,
[0318] wherein the UE includes a communication interface and processing circuitry, and the communication interface and processing circuitry of the UE are configured to perform operations related to the terminal device as described above to send or facilitate the sending of user data to the host.
[0319] Example 21. The host of the foregoing example, wherein the cellular network further includes a network node configured to communicate with the UE to send user data from the UE to the host.
[0320] Example 22. The host of the previous 2 examples, wherein:
[0321] The processing circuitry of the host is configured to run a host application to provide user data; and
[0322] The host application is configured to interact with a client application running on the UE, and the client application is associated with the host application.
[0323] Example 23. A method implemented by a host, where the host is configured to operate in a communication system further including a network node and a user equipment (UE), the method comprising:
[0324] At the host, receiving user data sent by the UE to the host via the network node, where the UE performs the operations related to the terminal device as described above to send or initially send user data to the host:
[0325] Example 24. The method of the foregoing example, further comprising:
[0326] At the host, running a host application associated with a client application running on the UE to receive user data from the UE.
[0327] Example 25. The method of the foregoing example, further comprising:
[0328] At the host, sending input data to a client application running on the UE, where the input data is provided by running the host application,
[0329] where the user data is provided by the client application in response to the input data from the host application.
[0330] In addition, the present disclosure may also provide a carrier containing the above computer program, where the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. The computer-readable storage medium may be, for example, an optical disc or an electronic storage device such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, magnetic tape, CD-ROM, DVD, Blu-ray Disc, etc.
[0331] The technologies described herein may be implemented in various ways, such that a device for implementing one or more functions of the corresponding device described in the examples includes not only components of the prior art, but also components for implementing one or more functions of the corresponding device described in the examples, and it may include separate components for each individual function, or may be configured to execute two or more functions. For example, these technologies may be implemented in hardware (one or more devices), firmware (one or more devices), software (one or more modules), or a combination thereof. For firmware or software, the implementation may be completed by executing modules (e.g., procedures, functions, etc.) that perform the functions described herein.
[0332] Exemplary embodiments herein have been described with reference to block diagrams and flowcharts of methods and apparatuses. It will be understood that each block of the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, can be implemented by various means including computer program instructions. These computer program instructions can be loaded onto a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed on the computer or other programmable data processing apparatus create means for implementing the functions specified in the flowchart block or blocks.
[0333] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve the desired results. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limitations on the scope of the subject matter described herein, but rather as descriptions of features that may be specific to particular embodiments. Certain features described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination.
[0334] Although this specification contains many specific implementation details, these should not be construed as limitations on the scope of any implementation or of what may be claimed, but rather as descriptions of features that may be specific to particular embodiments of a particular implementation. Certain features described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. Additionally, although the above features may be described as acting in certain combinations and even initially claimed as such, in some cases one or more features from a claimed combination may be excluded from the combination, and the claimed combination may be directed to a sub-combination or variation of a sub-combination.
[0335] It will be apparent to those skilled in the art that, as technology progresses, the inventive concept can be implemented in various ways. The above embodiments are given for the purpose of description and not limitation of the disclosure, and it should be understood that modifications and variations can be made without departing from the spirit and scope of the disclosure as would be readily understood by those skilled in the art. Such modifications and variations are considered to be within the scope of the disclosure and the appended claims. The scope of protection of the disclosure is defined by the appended claims.
Claims
1. A method (300) performed by an authentication service node, comprising: receiving (302) a first authentication request sent by an access and mobility node, wherein the first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network; and processing (304) the first authentication request based on the first information.
2. The method according to claim 1, wherein, the first information is an indicator.
3. The method according to claim 2, wherein, when the indicator is set to true, the indicator indicates that the primary authentication is for the terminal device to access the network, and when the indicator is set to false or the indicator does not exist, the indicator indicates that the primary authentication is not for the terminal device to access the network.
4. The method according to any one of claims 1 - 3, wherein, processing the first authentication request based on the first information includes: when the first information indicates that the primary authentication is for the terminal device to access the network, skipping (404) the selection of the data management node and skipping sending a request for authentication method selection to the data management node; and when the first information indicates that the primary authentication is not for the terminal device to access the network, selecting (406) the data management node and sending the request for authentication method selection to the data management node.
5. The method according to any one of claims 1 - 4, further comprising: sending (502) a second authentication request to an independent non - public network SNPN authentication and authorization node; and receiving (504) a second authentication response from the SNPN authentication and authorization node, the second authentication response including authentication success, a master session key, and a subscription permanent identifier; when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier received in the first authentication request is not anonymous, skipping (506) sending a request to confirm the authentication result to the data management node; and when the first information indicates that the primary authentication is not for the terminal device to access the network and / or the subscription hidden identifier received in the first authentication request is anonymous, sending (508) the request to confirm the authentication result to the data management node and receiving an authentication result confirmation response from the data management node, wherein the request to confirm the authentication result is used to verify that the subscription permanent identifier corresponds to a valid subscription in the SNPN.
6. The method according to claim 5, wherein, when the first information indicates that the primary authentication is for the terminal device to access the network or the subscription hidden identifier received in the first authentication request is not anonymous, the method further includes: generating (602) a key for the authentication service node and a key for the security anchor function; and sending (604) a first authentication response including the authentication success, the key for the security anchor function, and the subscription permanent identifier to the access and mobility node.
7. The method according to claim 5 or 6, wherein, When the first information indicates that the primary authentication is not for the access of the terminal device to the network and / or the subscription hidden identifier received in the first authentication request is anonymous, the method further includes: When the authentication result confirmation response includes second information indicating that the user subscription verification fails, or the user is not found, or the SNPN subscription is missing, reject (612) the access of the terminal device to the SNPN, and send a first authentication response including the second information to the access and mobility node.
8. The method according to any one of claims 5-7, wherein, the SNPN authentication and authorization node includes a network slice specific and SNPN authentication and authorization function NSSAAF.
9. The method according to any one of claims 4-8, wherein, the data management node includes a unified data management UDM.
10. The method according to any one of claims 1-9, wherein, the access and mobility node includes an access and mobility management function AMF.
11. The method according to any one of claims 1-10, wherein, the authentication service node includes an authentication server function AUSF.
12. A method (620) performed by an access and mobility node, comprising: receiving (622) from a terminal device a registration request for registration in a Standalone Non-Public Network (SNPN), wherein the registration request includes a subscription hidden identifier; and sending (624) a first authentication request to an authentication service node, wherein the first authentication request includes the subscription hidden identifier and first information indicating whether the primary authentication is for the access of the terminal device to the network.
13. The method according to claim 12, wherein, the first information is an indicator.
14. The method according to claim 13, wherein, when the indicator is set to true, the indicator indicates that the primary authentication is for the access of the terminal device to the network, and when the indicator is set to false or the indicator does not exist, the indicator indicates that the primary authentication is not for the access of the terminal device to the network.
15. The method according to any one of claims 12-14, wherein, when the first information indicates that the primary authentication is for the access of the terminal device to the network or the subscription hidden identifier is not anonymous, the method further includes: receiving (632) from the authentication service node a first authentication response including authentication success, a key of the security anchor function, and a subscription permanent identifier; and sending (634) the authentication success to the terminal device.
16. The method according to any one of claims 12-15, wherein, when the first information indicates that the primary authentication is not for the access of the terminal device to the network and / or the subscription hidden identifier is anonymous, the method further includes: receiving (642) from the authentication service node a first authentication response including second information indicating that the user subscription verification fails, or the user is not found, or the SNPN subscription is missing; and sending (644) the second information to the terminal device.
17. The method according to any one of claims 12-16, Wherein, the access and mobility node includes an access and mobility management function AMF.
18. The method according to any one of claims 12-17, wherein, the authentication service node includes an authentication server function AUSF.
19. A method (700) performed by a terminal device, comprising: sending (702) a registration request for registration in a Standalone Non-Public Network SNPN to an access and mobility node, wherein the registration request includes a subscription hidden identifier; and receiving (704) authentication success or second information from the access and mobility node, wherein the second information indicates that user subscription verification fails or the user is not found or there is a lack of SNPN subscription.
20. The method according to claim 19, wherein, the access and mobility node includes an access and mobility management function AMF.
21. The method according to claim 19 or 20, further comprising: providing (706) the second information to a user of the terminal device.
22. An authentication service node (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the authentication service node (800) is operable to: receive a first authentication request sent by an access and mobility node, wherein the first authentication request includes a subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network; and process the first authentication request based on the first information.
23. The authentication service node according to claim 22, wherein, the authentication service node is further operable to perform the method according to any one of claims 2 to 11.
24. An access and mobility node (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the access and mobility node (800) is operable to: receive a registration request for registration in a Standalone Non-Public Network SNPN from a terminal device, wherein the registration request includes a subscription hidden identifier; and send a first authentication request to an authentication service node, wherein the first authentication request includes the subscription hidden identifier and first information indicating whether the primary authentication is for the terminal device to access the network.
25. The access and mobility node according to claim 24, wherein, the access and mobility node is further operable to perform the method according to any one of claims 13 to 18.
26. A terminal device (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the terminal device (800) is operable to: Send a registration request for registration in a Standalone Non-Public Network (SNPN) to an access and mobility node, where the registration request includes a subscription hidden identifier; and Receive authentication success or second information from the access and mobility node, where the second information indicates that user subscription verification fails, or the user is not found, or there is a lack of SNPN subscription.
27. The terminal device according to claim 26,[[]]END]] wherein,[[]]END]] the terminal device is further operable to perform the method according to any one of claims 20 to 21.
28. A computer-readable storage medium storing instructions, which when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 21.
29. A computer program product comprising instructions, which when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 21.