Security for non-3GPP access to 3GPP-based non-public networks
The method and device for authentication entities and data management entities between a non-3GPP access network and an independent non-public network based on 3GPP solve the security issues of the non-3GPP access network, achieve secure authentication and protection of communications, prevent attacks, and improve system security.
Patent Information
- Application Number
- CN202480011199.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-02-09
- Filing Date
- 2024-02-09
- Publication Date
- 2025-09-12
AI Technical Summary
In the prior art, the connection between the non-3GPP access network and the 3GPP-based non-public network lacks effective security protection, resulting in the possibility that the communication between the UE and the NPN/SNPN may be subject to impersonation, leakage, tampering or replay attacks.
Provided are a method and apparatus for an authentication entity and a data management entity. By obtaining an authentication request message and performing a network check based on the network identity, an appropriate authentication method is selected. The authentication server function and a unified data manager are used to implement secure authentication between a UE and an independent non-public network based on 3GPP, including the use of extensible authentication protocol methods such as EAP-AKA Enhanced, EAP TLS, and 5G-AKA.
It achieves secure authentication and communication protection between non-3GPP access networks and independent non-public networks based on 3GPP, prevents impersonation, leakage, tampering and replay attacks in communications, and improves the security of the system.
Smart Images

Figure CN120642384A_ABST
Abstract
Description
Technical Field
[0001] Various example embodiments relate to security for non-3GPP access to non-public networks based on 3GPP. More specifically, measures / mechanisms (including methods, apparatus (i.e., devices, entities, elements, instances, and / or functions), and computer program products) for enabling / implementing security for non-3GPP access to non-public networks based on 3GPP are described. Background Art
[0002] Various example embodiments relate to security considerations in (e.g., mobile / wireless) communication systems, such as 5G / NR systems and next-generation systems beyond 5G. For example, various example embodiments are applicable to 3GPP standardized mobile / wireless communication systems from Release 18 onwards.
[0003] Such security considerations may involve the security of a connection from a UE via a non-standardized or non-standards-based access network to a standardized or standards-based non-public network (NPN), including a standalone non-public network (SNPN) and a public network integrated non-public network (PNI-NPN). Thus, one example use case may involve the security of a connection from a UE via a non-3GPP access network (such as, for example, a WLAN access network that may conform to any IEEE 802.11 standard) to a 3GPP-based NPN (such as a 3GPP-based SNPN or PNI-NPN). Summary of the Invention
[0004] Various example embodiments address at least some of the problems, issues, and / or deficiencies described herein or recognized by those skilled in the art.
[0005] Various exemplary embodiments are set forth in the claims.
[0006] According to an example embodiment, a method is provided for an authentication entity of a communication system (or in other words, operable or used therein / by it), the method comprising: obtaining an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the authentication request message comprising a subscription hiding identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP and the interface type of the interface entity; and issuing a request message to a data management entity, the request message comprising the subscription hiding identifier of the communication entity, an indication of the requested authentication type, and the network identity.
[0007] According to an example embodiment, a device is provided for an authentication entity of a communication system (or in other words, operable or usable in / by it), the device comprising: at least one processor; and at least one memory storing instructions, which instructions, when executed by the at least one processor, cause the device to at least: obtain an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the authentication request message comprising a subscription hiding identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity; and issue a request message to a data management entity, the request message comprising a subscription hiding identifier of the communication entity, an indication of the requested authentication type, and the network identity.
[0008] According to an example embodiment, there is provided an apparatus for an authentication entity of a communication system (or in other words, operable or usable therein / by it), the apparatus comprising: a component for obtaining an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the authentication request message comprising a subscription hiding identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP and the interface type of the interface entity; and a component for issuing a request message to a data management entity, the request message comprising the subscription hiding identifier of the communication entity, an indication of the requested authentication type, and the network identity.
[0009] According to an example embodiment, there is provided an apparatus for an authentication entity of a communication system (or in other words, operable or usable therein / by it), the apparatus comprising: a circuit system configured to obtain an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the authentication request message comprising a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity; and a circuit system configured to issue a request message to a data management entity, the request message comprising a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and the network identity.
[0010] According to various developments / modifications, any of the above method-related and / or apparatus-related example embodiments may include one or more of the following features:
[0011] The method, functionality, operability or configuration includes or enables: performing a network inspection based on the network identity, wherein the request message is issued based on the result of the network inspection,
[0012] The method, function, operability or configuration includes or enables: registering a subscription permanent identifier of the communication entity corresponding to the subscription hidden identifier of the communication entity; and issuing an authentication message including the subscription permanent identifier of the communication entity to the data management entity,
[0013] The subscription permanent identifier is registered during, or as a result of, an authentication process for authenticating the communicating entity using an authentication method based on the requested authentication type,
[0014] Registration includes: obtaining an authentication message including the subscription permanent identifier,
[0015] The requested authentication type includes at least one authentication method supported by the 3GPP-based standalone non-public network,
[0016] the authentication method is an Extensible Authentication Protocol method and / or an authentication and key agreement method, includes at least one type of an Extensible Authentication Protocol method and / or an authentication and key agreement method, or is based on an Extensible Authentication Protocol method and / or an authentication and key agreement method, such as EAP-AKA Enhanced, EAP-TLS, 5G-AKA, or any key generating EAP method,
[0017] The authentication entity is, includes or involves an authentication server function AUSF,
[0018] The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO,
[0019] The data management entity is, includes or involves the unified data management (UDM) entity.
[0020] Non-3GPP access network is, includes or involves wireless local area network WLAN access network,
[0021] The communicating entity is, includes or involves a user equipment,
[0022] Network identity is, includes or relates to access network identity,
[0023] The communication system is, includes or relates to a 5G system.
[0024] According to an example embodiment, a method of a data management entity of a communication system (or in other words, operable or used therein / by thereof) is provided, the method comprising: obtaining a request message from an authentication entity, the request message comprising a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based independent non-public network, and an interface type of an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network; and selecting an authentication method for authenticating the communication entity based on the requested authentication type and the network identity.
[0025] According to an example embodiment, there is provided an apparatus of a data management entity of a communication system (or in other words, operable or usable therein / by it), the apparatus comprising: at least one processor; and at least one memory storing instructions, which instructions, when executed by the at least one processor, cause the apparatus to at least: obtain a request message from an authentication entity, the request message comprising a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based independent non-public network, and an interface type of an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network; and select an authentication method for authenticating the communication entity based on the requested authentication type and the network identity.
[0026] According to an example embodiment, there is provided an apparatus of a data management entity of a communication system (or in other words, operable or usable therein / by it), the apparatus comprising: a component for obtaining a request message from an authentication entity, the request message comprising a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based independent non-public network, and an interface type of an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network; and a component for selecting an authentication method for authenticating the communication entity based on the requested authentication type and the network identity.
[0027] According to an example embodiment, there is provided an apparatus of a data management entity of a communication system (or in other words, operable or usable therein / by it), the apparatus comprising: a circuit system configured to obtain a request message from an authentication entity, the request message comprising a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying an independent non-public network based on 3GPP, and an interface type of an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP; and a circuit system configured to select an authentication method for authenticating the communication entity based on the requested authentication type and the network identity.
[0028] According to various developments / modifications, any of the above method-related and / or apparatus-related example embodiments may include one or more of the following features:
[0029] The selection includes: triggering authentication of the communicating entity using the selected authentication method, or rejecting authentication of the communicating entity,
[0030] The method, functionality, operability or configuration comprises or enables: obtaining an authentication message from an authentication entity, the authentication message comprising a subscription permanent identifier of the communication entity corresponding to a subscription hidden identifier of the communication entity,
[0031] The method, functionality, operability or configuration comprises or enables: performing authorization of the communicating entity using a subscription permanent identifier of the communicating entity based on at least one of subscription data configured at the data management entity or a policy stored at the data management entity,
[0032] The requested authentication type includes: at least one authentication method supported by the 3GPP independent non-public network,
[0033] the authentication method is an Extensible Authentication Protocol method and / or an authentication and key agreement method, includes at least one type of an Extensible Authentication Protocol method and / or an authentication and key agreement method, or is based on an Extensible Authentication Protocol method and / or an authentication and key agreement method, such as EAP-AKA Enhanced, EAP-TLS, 5G-AKA, or any key generating EAP method,
[0034] The data management entity is, includes or involves the unified data management (UDM) entity.
[0035] The authentication entity is, includes or involves an authentication server function AUSF,
[0036] The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO,
[0037] Non-3GPP access network is, includes or involves wireless local area network WLAN access network,
[0038] The communicating entity is, includes or involves a user equipment,
[0039] Network identity is, includes or relates to access network identity,
[0040] The communication system is, includes or relates to a 5G system.
[0041] According to an example embodiment, a method is provided for an interface entity of a communication system (or in other words, operable or used therein / by thereof), the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the method comprising: obtaining a message including a subscription hidden identifier of the communication entity from the non-3GPP access network; and issuing an authentication request message to an authentication entity, the authentication request message including the subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity.
[0042] According to an example embodiment, there is provided an apparatus of an interface entity of a communication system (or in other words, operable or usable in / by it), the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the apparatus comprising: at least one processor; and at least one memory storing instructions, which instructions, when executed by the at least one processor, cause the apparatus to at least: obtain a message including a subscription hidden identifier of the communication entity from the non-3GPP access network; and issue an authentication request message to an authentication entity, the authentication request message including the subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity.
[0043] According to an example embodiment, there is provided an apparatus of an interface entity of a communication system (or in other words, operable or usable in / by it), the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the apparatus comprising: a component for obtaining a message including a subscription hidden identifier of the communication entity from the non-3GPP access network; and a component for issuing an authentication request message to an authentication entity, the authentication request message including the subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity.
[0044] According to an example embodiment, there is provided an apparatus of an interface entity of a communication system (or in other words, operable or usable in / by it), the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the apparatus comprising: a circuit system configured to obtain a message including a subscription hidden identifier of the communication entity from the non-3GPP access network; and a circuit system configured to issue an authentication request message to an authentication entity, the authentication request message including the subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity.
[0045] According to various developments / modifications, any of the above method-related and / or apparatus-related example embodiments may include one or more of the following features:
[0046] The requested authentication type includes: at least one authentication method supported by the 3GPP independent non-public network,
[0047] the authentication method is an Extensible Authentication Protocol method and / or an authentication and key agreement method, includes at least one type of an Extensible Authentication Protocol method and / or an authentication and key agreement method, or is based on an Extensible Authentication Protocol method and / or an authentication and key agreement method, such as EAP-AKA Enhanced, EAP-TLS, 5G-AKA, or any key generating EAP method,
[0048] The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO, and / or
[0049] The non-3GPP access network is, includes or relates to a wireless local area network (WLAN) access network, and / or
[0050] The authentication entity is, includes or involves an authentication server function AUSF, and / or
[0051] The communicating entity is, includes or involves a user equipment, and / or
[0052] The network identity is, includes or relates to the access network identity, and / or
[0053] The communication system is, includes or relates to a 5G system.
[0054] According to an example embodiment, a device is provided, which includes components for performing a method of any one of the above-mentioned example embodiments (or any development / modification thereof) and / or a circuit system configured to perform a method of any one of the above-mentioned example embodiments (or any development / modification thereof).
[0055] According to an example embodiment, a system is provided, the system comprising: at least one processor and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the system to at least perform one or more of the following:
[0056] For example, obtaining an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the authentication request message including a subscription hiding identifier of a communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and an interface type of the interface entity,
[0057] For example, a request message is sent to the data management entity, the request message including the subscription hiding identifier of the communication entity, an indication of the requested authentication type, and the network identity,
[0058] For example, obtaining a request message from an authentication entity, the request message including a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based independent non-public network, and an interface type of an interface entity, the interface entity being configured to provide an interface between the non-3GPP access network and the 3GPP-based independent non-public network,
[0059] Selecting an authentication method for authenticating the communicating entity based on the requested authentication type and the network identity,
[0060] For example, obtaining a message including a subscription hidden identifier of a communication entity from a non-3GPP access network, and
[0061] For example, an authentication request message is sent to the authentication entity, which includes a subscription hidden identifier of the communication entity, an indication of the requested authentication type, a network identity, which identifies an independent non-public network based on 3GPP, and an interface type of the interface entity.
[0062] According to an example embodiment, there is provided a system comprising one or more of the following:
[0063] means (or corresponding circuitry) for obtaining, for example, an authentication request message from an interface entity configured to provide an interface between a non-3GPP access network and a 3GPP-based standalone non-public network, the authentication request message comprising a subscription hiding identifier of the communicating entity, an indication of a requested authentication type, and a network identity identifying the 3GPP-based standalone non-public network and an interface type of the interface entity,
[0064] means (or corresponding circuitry) for issuing a request message, e.g. towards a data management entity, the request message comprising a subscription hiding identifier of the communicating entity, an indication of the requested authentication type, and a network identity,
[0065] means (or corresponding circuitry) for obtaining, for example, from an authentication entity, a request message including a subscription hiding identifier of a communicating entity, an indication of a requested authentication type, and a network identity identifying a 3GPP-based standalone non-public network, and an interface type of an interface entity configured to provide an interface between a non-3GPP access network and a 3GPP-based standalone non-public network,
[0066] means (or corresponding circuitry) for selecting an authentication method for authenticating a communicating entity based on the requested authentication type and the network identity,
[0067] means (or corresponding circuitry) for obtaining a message comprising a subscription concealment identifier of a communicating entity, for example from a non-3GPP access network, and
[0068] A component (or corresponding circuit system) for issuing an authentication request message, for example, to an authentication entity, the authentication request message including a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, which identifies an independent non-public network based on 3GPP, and an interface type of the interface entity.
[0069] According to an example embodiment, there is provided a computer-readable medium comprising program instructions for causing an apparatus to at least perform the method of any one of the above example embodiments (or any development / modification thereof).
[0070] According to an example embodiment, a computer program product is provided comprising (computer-executable) computer program code, which, when the program code is executed (or run) on a computer or the program is run on a computer (e.g., a computer of an apparatus according to any one of the above-mentioned apparatus-related example embodiments (or any development / modification thereof)), is configured to cause the computer to perform a method according to the above-mentioned method-related example embodiments (or any development / modification thereof).
[0071] The computer program product may include or be embodied as a (tangible / non-transitory) computer-readable (storage) medium or the like having computer-executable computer program code stored thereon, and / or the program may be directly loadable into the internal memory of a computer or its processor.
[0072] The term "non-transitory" as used herein is a restriction on the medium itself (eg, tangible media, not signals), not on the persistence of data storage (eg, RAM versus ROM).
[0073] Further developments and / or modifications of the exemplary embodiments described above are set out below.
[0074] As an example embodiment, for example, a technique for (eg, enabling / implementing) security for non-3GPP access to a 3GPP-based non-public network. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] Hereinafter, various example embodiments will be described with reference to the accompanying drawings, in which:
[0076] Figure 1 shows a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment,
[0077] Figure 2 shows a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment,
[0078] Figure 3 shows a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment,
[0079] Figure 4 shows a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment,
[0080] Figure 5 shows a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment,
[0081] Figure 6 shows a sequence diagram of a security procedure in a use case of WLAN accessing a Standalone Non-Public Network (SNPN) according to at least one example embodiment,
[0082] Figure 7 shows a schematic block diagram illustrating the structure of an apparatus according to at least one example embodiment, and
[0083] Figure 8 A schematic block diagram illustrating the structure of an apparatus according to at least one example embodiment is shown. DETAILED DESCRIPTION
[0084] Various exemplary embodiments are described herein with reference to specific non-limiting and illustrative examples. It will be understood by those skilled in the art that these various exemplary embodiments are by no means limited to these non-limiting and illustrative examples, but may be applied more broadly.
[0085] It should be noted that the detailed description sometimes refers to one or more specifications that serve as non-limiting and illustrative examples of certain network configurations and system deployments. More specifically, the detailed description references 3GPP standards as non-limiting and illustrative examples. Therefore, the example embodiments provided herein may specifically employ terminology directly related thereto. Such terminology is used solely in the context of non-limiting and illustrative examples and is not intended to limit the example embodiments in any way. Rather, any other system configuration or deployment may be utilized while maintaining the applicability of the content and / or example embodiments described herein to the present application.
[0086] For example, the various exemplary embodiments are applicable to any (e.g., mobile / wireless) communication system, such as a 5G / NR system and next-generation systems after 5G. For example, the various exemplary embodiments are applicable to 3GPP standardized mobile / wireless communication systems after Release 18.
[0087] In the following, various example embodiments are described using several variations and / or alternatives. It should generally be noted that, depending on certain implementations or constraints, all described variations and / or alternatives may be provided individually or in any possible combination (e.g., also including combinations of individual features of these various variations and / or alternatives).
[0088] As used herein, the terms “comprising” and “including” should be understood as not limiting example embodiments to consist of only those features that have been mentioned, but example embodiments may also include features, structures, units, modules, etc. that are not specifically mentioned.
[0089] As used herein, “at least one of: ” and “at least one of ” and similar expressions (where a list of two or more elements is connected by “and” or “or”) refer to at least any one of these elements, or at least any two or more of these elements, or at least all of these elements.
[0090] As used herein, according to various example embodiments, any operation of issuing or receiving may include actual transmission or communication operations, i.e., sending or receiving associated commands or signals, but may also additionally or alternatively include related processing operations, i.e., preparing / generating associated commands and signals before sending, and / or handling / processing associated commands or signals after receiving. For example, issuing a command at / by an entity may include generating and / or sending / transmitting the command in / at / by the entity, and receiving a command at / by an entity may include obtaining and / or processing the command in / at / by the entity. As used herein, a command may refer to and / or encompass any type of corresponding message, signal, etc.
[0091] In the accompanying drawings, it should be noted that the lines / arrows interconnecting individual blocks or entities are generally intended to illustrate operational couplings therebetween, which may be physical and / or logical couplings that are implementation-independent (e.g., wired or wireless) on the one hand and may also include any number of intermediate functional blocks or entities not shown on the other hand. In flowcharts or sequence diagrams, the order of operations or actions shown is generally non-limiting and illustrative, and any other order of the corresponding operations or actions may be envisioned, if feasible.
[0092] In this document, a non-public network (NPN) is a network (intended) for non-public purposes, including the concept of a private network, which is an isolated network deployment that does not interact with a public network. Therefore, a non-public network can also be referred to as or understood as a private network. In the context of 3GPP (standardization), a distinction is made between a standalone non-public network (SNPN) and a public network integrated non-public network (PNI-NPN). A standalone non-public network (also referred to herein as a (3GPP-based) SNPN) involves an NPN that does not rely on a public land mobile network (PLMN) (the network functions (or infrastructure) provided by it) as a 3GPP-based public network. A public network integrated non-public network (which may also be referred to herein as a (3GPP-based) PNI-NPN) involves an NPN deployed as a 3GPP-based public network with the support of a public land mobile network (PLMN) (network functions (or infrastructure) provided by it), where the PNI-NPN can be deployed as a private slice (a dedicated network slice used only by the owner of the PLMN), or it may involve a portion of a network, network element or network function deployed by the PLMN and a portion of other networks, network elements or network functions deployed by the owner.
[0093] However, there are issues regarding supporting non-3GPP access to (3GPP-based) NPNs, in particular (3GPP-based) SNPNs, as the 3GPP specification currently does not support (direct) connection to SNPNs via non-3GPP access networks, thus making it currently impossible for 5GS to support (direct) connection of non-3GPP access networks to (3GPP-based) NPNs, in particular (3GPP-based) SNPNs, such as its core network part.
[0094] If the non-3GPP access in the NPN (such as SNPN) does not provide mutual authentication between the UE and the NPN / SNPN, it is possible to impersonate the UE or NPN / SNPN. If the communication between the UE and the NPN / SNPN via the non-3GPP access is not protected by confidentiality, integrity or replay, it is possible to leak, tamper with or replay the communication. In terms of potential security requirements, if non-3GPP access is used, the 5GS should therefore provide means for mutual authentication between the UE and the NPN / SNPN, and if non-3GPP access is used, the 5GS should also provide means for confidentiality, integrity and replay protection for the communication between the UE and the NPN / SNPN.
[0095] Therefore, there are problems, difficulties and / or deficiencies in the security of non-3GPP access to (3GPP-based) NPNs, or in other words, in the security of a (direct) connection from a UE to a (3GPP-based) NPN (e.g., its core network part) via a non-3GPP access network.
[0096] Therefore, techniques for (e.g., enabling / realizing) security of non-3GPP access to a (3GPP-based) NPN, or in other words, for security of a (direct) connection from a UE to a (3GPP-based) NPN (e.g., its core network portion) via a non-3GPP access network, may be advantageous.
[0097] According to various example embodiments, measures / mechanisms are provided for (e.g., enabling / implementing) security of a connection from a UE via a non-standardized or non-standards-based access network to a standardized or standards-based non-public network (NPN), including a standalone non-public network (SNPN) and a public network integrated non-public network (PNI-NPN). More specifically, for example, various example embodiments provide measures / mechanisms for (e.g., enabling / implementing) security of a non-3GPP access to a 3GPP-based non-public network.
[0098] In the following, example embodiments are described with reference to a use case or scenario of non-3GPP accessing a 3GPP based Standalone Non-Public Network (SNPN).
[0099] However, it should be noted that this is to facilitate understanding / illustration of the underlying concepts and techniques and does not limit the scope or applicability of the example embodiments accordingly. For example, any type of standardization may be used as a basis, with 3GPP standardization being used as a non-limiting example, such that the example embodiments are generally applicable to / with any type of non-standard access standard-based non-public network. For example, any type of non-public network (as a target for connection via an access network) may be used, including any configured or deployed non-public network, such that the example embodiments are applicable to / with any public network integrated non-public network (PNI-NPN) and / or any stand-alone non-public network (SNPN). In other words, any reference to a stand-alone non-public network may be replaced with a reference to a non-public network (such as, for example, a stand-alone non-public network and / or a public network integrated non-public network).
[0100] Figure 1 and Figure 2 Each of the diagrams illustrates an example method or process performed at / by an apparatus according to various example embodiments. In this regard, the apparatus is, or in other words, the method or process is, an authentication entity in / of a (mobile / wireless) communication system, or an element, function or entity having similar / comparable functionality or operability (or in other words, a method or process operable or used therein / by it). Such an authentication entity may, for example, be or relate to an authentication server function (AUSF), for example acting as an EAP authentication server. In this case, at least in the case of a WLAN access network as an example of a non-3GPP access network, the interface entity mentioned may be or relate to a non-seamless WLAN offload function (NSWOF), and / or the data management entity mentioned may be or relate to a unified data manager (UDM), without being subject to corresponding limitations. In this document, the interface entity should be configured to provide an interface between a non-3GPP access network and a (3GPP-based) independent non-public network.
[0101] Figure 1 Shown is a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment.
[0102] like Figure 1As shown, the method or process includes an operation (S110) of obtaining an authentication request message (e.g., from an interface entity), the authentication request message including a subscription concealment identifier (SUCI) of a communication entity (e.g., a UE), an indication of a requested authentication type, and a network identity, the network identity identifying a standalone non-public network (SNPN) based on 3GPP and an interface type of the interface entity (e.g., the interface type of the NSWOF (entity) is NSWO); and an operation (S120) of issuing a request message (e.g., for or in other words, directed to or addressed to a data management entity), the request message including a subscription concealment identifier (SUCI) of a communication entity (e.g., a UE), an indication of a requested authentication type, and the network identity.
[0103] Figure 2 Shown is a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment.
[0104] like Figure 2 As shown, the method or process includes Figure 1 The acquisition operation (S210) corresponding to the acquisition operation S110 and the Figure 1 The issuing operation (S230) corresponding to the issuing operation S120 is described in detail. Figure 1 Description.
[0105] As indicated by the dashed box, the method or process may include an operation (S220) of performing a network check based on the network identity. In an issuing operation (S230), a request message may then be issued based on the results of the network check. Through the network check, a base scenario may be identified, i.e., by checking or verifying the network identity. For example, when the network identity identifies a (3GPP-based) Standalone Non-Public Network (SNPN) and NSWO as interface types, it may be identified that the authentication request message relates to a scenario where a non-3GPP network accesses the SNPN via NSWO. As another example, when the network identity identifies a (3GPP-based) Public Land Mobile Network (PLMN) and NSWO as interface types, it may be identified that the authentication request message relates to a scenario where a non-3GPP network accesses the PLMN via NSWO. In this regard, the apparatus performing the method or process may store / pre-store (datasets of) network identities (e.g., associated with corresponding scenarios and / or related operations to be performed) and compare or verify the network identity included in the authentication request message with these stored / pre-stored network identities.
[0106] As indicated by the dashed box, the method or process may include an operation (S240) of registering a subscription permanent identifier (SUPI) of a communication entity (such as a UE) corresponding to a subscription concealed identifier (SUCI) of the communication entity (such as a UE); and an operation (S250) of issuing an authentication message (e.g., for a data management entity, or in other words, directed to or addressed to the data management entity) including the subscription permanent identifier (SUPI) of the communication entity (such as a UE). In this regard, the subscription permanent identifier (SUPI) may be registered during or as a result of an authentication process for authenticating the communication entity (such as a UE) using an authentication method based on the requested authentication type, and / or the registration operation (S240) may include obtaining an authentication message including the subscription permanent identifier (SUPI). In this regard, the device performing the method or process may participate in an authentication method based on the requested authentication type and may obtain the subscription permanent identifier (SUPI) in the context of such an authentication method.
[0107] It should be noted that operation S220 and operations S240 and S250 are independent of each other. Therefore, operation S220 and any one or both of operations S240 and S250 may be included in the method or process.
[0108] Figure 3 and Figure 4 Each of the diagrams illustrates an example method or process performed at / by an apparatus according to various example embodiments. In this regard, the apparatus is, or in other words, the method or process is, a method or process of / a data management entity in a (mobile / wireless) communication system, or an element, function or entity having similar / comparable functionality or operability (or in other words, operable or used therein / by it). Such a data management entity may be, for example, or relate to, a unified data manager (UDM). In this case, at least in the case of a WLAN access network as an example of a non-3GPP access network, the authentication entity mentioned may be, for example, or relate to, an authentication server function (AUSF), for example, acting as an EAP authentication server, and / or the interface entity mentioned may be, for example, or relate to, a non-seamless WLAN offload function (NSWOF), without corresponding limitations. In this document, the interface entity should be configured to provide an interface between a non-3GPP access network and a (3GPP-based) independent non-public network.
[0109] Figure 3 Shown is a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment.
[0110] like Figure 3As shown, the method or process includes an operation (S310) of obtaining a request message (e.g., from an authentication entity), the request message including a subscription concealment identifier (SUCI) of a communication entity (e.g., a UE), an indication of a requested authentication type, and a network identity, the network identity identifying a standalone non-public network (SNPN) based on 3GPP and an interface type of an interface entity (e.g., the interface type of an NSWOF (entity) is NSWO); and an operation (S320) of selecting an authentication method for authenticating a communication entity (e.g., a UE) based on the requested authentication type and the network identity.
[0111] According to at least one example embodiment, the selection operation S320 may trigger authentication of the communication entity (such as a UE) using the selected authentication method, or reject authentication of the communication entity. In this regard, the device performing the method or process may make a decision (i.e., decide) based on or with respect to the request message to accept / initiate or reject authentication of the communication entity (such as a UE), wherein in the former case, an authentication method based on the requested authentication type may be used.
[0112] According to at least one example embodiment, the selection operation S320 may also be based on a local policy, such as an operator policy. Thus, the authentication method used to authenticate the communication entity (such as a UE) may be based on one or more of the requested authentication type, the access network identity, or a local policy (such as, for example, an operator policy).
[0113] Figure 4 Shown is a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment.
[0114] like Figure 4 As shown, the method or process includes Figure 3 The acquisition operation (S410) corresponding to the acquisition operation S310 and the Figure 3 The selection operation S320 corresponds to the selection operation (S420), for details, please refer to Figure 3 Description.
[0115] As indicated by the dotted box, the method or process may include an operation (S430) of obtaining an authentication message (e.g., from an authentication entity), the authentication message including a subscription permanent identifier (SUPI) of a communication entity (such as a UE) corresponding to a subscription concealed identifier (SUCI) of the communication entity (such as a UE).
[0116] As indicated by the dotted box, the method or process may include an operation (S440) of performing authorization of a communication entity (such as a UE) using a subscription permanent identifier (SUPI) of the communication entity (such as a UE) based on at least one of subscription data configured at the device performing the method or process or the connected / linked device (i.e., local subscription data) or a policy stored at the device performing the method or process or the connected / linked device (i.e., local policy).
[0117] Figure 5 The diagram illustrates an example method or process performed at / by an apparatus according to various example embodiments. In this regard, the apparatus is, or in other words, the method or process is, an interface entity in / of a (mobile / wireless) communication system, or an element, function, or entity having similar / comparable functionality or operability (or in other words, a method or process operable or used therein / by it). In this document, the interface entity should be configured to provide an interface between a non-3GPP access network and a (3GPP-based) independent non-public network. For example, at least in the case of a WLAN access network as an example of a non-3GPP access network, such an interface entity may be or relate to a non-seamless WLAN offload function (NSWOF). In this case, the non-3GPP access network mentioned may be, for example, or relate to a WLAN access network (at least one node, element, or entity thereof), and / or the authentication entity mentioned may be, for example, or relate to an authentication server function (AUSF), for example, acting as an EAP authentication server, without corresponding limitations.
[0118] Figure 5 Shown is a flowchart illustrating a method or process at / performed by an apparatus according to at least one example embodiment.
[0119] like Figure 5 As shown, the method or process includes an operation (S510) of obtaining (e.g., from a non-3GPP access network, i.e., a node, element, or entity thereof) a message including a subscription concealment identifier (SUCI) of a communication entity (such as a UE); and an operation (S520) of issuing (e.g., for an authentication entity, or in other words, directed to or addressed to an authentication entity) an authentication request message including a subscription concealment identifier (SUCI) of the communication entity (such as a UE), an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based Standalone Non-Public Network (SNPN) and an interface type of the interface entity (e.g., the interface type of the NSWOF (entity) is NSWO).
[0120] According to various example embodiments, for example, Figures 1 to 5The requested authentication type mentioned in any one of the descriptions of may include at least one authentication method supported by a 3GPP-based Standalone Non-Public Network (SNPN). The authentication method may be, include, or be based on at least one of an Extensible Authentication Protocol (EAP) method and / or an Authentication and Key Agreement (AKA) method, such as, for example, EAP-AKA Enhanced, EAP TLS, 5G-AKA, or any key generation EAP method.
[0121] According to various example embodiments, for example, Figures 1 to 5 The network identity mentioned in any one of the descriptions may be, include or relate to an access network identity. For example, when NSWOF (entity) represents an interface entity, an access network identity (AN ID) that identifies SNPN and NSWO may be used.
[0122] According to various example embodiments, for example, Figures 1 to 5 The Subscription Hidden Identifier (SUCI) mentioned in any of the descriptions of is an illustrative but non-limiting example of a privacy-preserving identifier (e.g., an encrypted or transcoded identifier) of a communication entity (e.g., a UE) that makes the communication entity (e.g., a UE) anonymous. Therefore, SUCI may also be referred to as anonymous SUCI. In addition, as in, for example, Figures 1 to 5 As described in any of the foregoing, a Subscription Permanent Identifier (SUPI) is an illustrative but non-limiting example of a (public or plaintext) (i.e., non-privacy-preserving) identifier of a communicating entity (such as a UE) that reveals the communicating entity (such as a UE) and fails to maintain anonymity. Through the correspondence / relationship between the SUCI and the SUPI of a communicating entity (such as a UE), the SUPI can be dehidden or determined from the SUCI, for example, by a Subscription Identifier Dehiding Function (SIDF).
[0123] like Figures 1 to 5 As shown, any of the above methods or processes can be part of an authentication procedure or process for security of non-3GPP access to a (3GPP-based) NPN (such as SNPN or PNI-NPN), or in other words, can be part of an authentication procedure or process for security of a (direct) connection from a UE to a (3GPP-based) NPN (such as SNPN or PNI-NPN) (e.g., its core network part) via a non-3GPP access network (e.g., in a 5G communication system).
[0124] In the following, an illustrative but non-limiting example scenario of non-3GPP access to a non-public network (NPN) in a 5GS communication system is described. More specifically, the use case described thus relates to WLAN access to a SNPN via NSWO / NSWOF.
[0125] Figure 6 A sequence diagram illustrating a security procedure in a use case of a WLAN accessing a Standalone Non-Public Network (SNPN) according to at least one example embodiment is shown. Figure 6 The sequence diagram relates to the authentication procedure for mutual authentication between the UE and the SNPN.
[0126] exist Figure 6 In the sequence / process, UE represents an example of a communication entity, WLAN AN represents an example of a non-3GPP access network (e.g., at least one node, element, or entity thereof), NSWOF represents an example of an interface entity, AUSF represents an example of an authentication entity, and UDM represents an example of a data management entity. Configuration / connection of (at least) NSWOF, AUSF, and UDM may be based on or in accordance with a service-based architecture (SBA) or service-based interface (SBI) concept.
[0127] In step 1, the UE establishes a WLAN connection with the WLAN access network (AN), for example, using procedures specified in any IEEE 802.11 standard. In step 2, the WLAN AN sends an EAP Identity / Request message to the UE. In step 3, the UE sends an EAP Response / Identity message. If the UE determines to use NSWO services, it may use the SUCI in the NAI format (e.g., username@realm format) as its identity. In step 4, based on the realm portion of the SUCI, the EAP Response / Identity message is routed from the WLAN AN to the NSWOF via the SWa interface. Here, the NSWOF may act as an SBI / AAA proxy between the AUSF and the WLAN AN.
[0128] In step 5, the NSWOF sends an authentication request message, such as a Nausf_UEAuthentication_Authenticate request, to the AUSF. The message contains / includes (at least) the SUCI, the access network identity, and the requested authentication type. The access network identity identifies the SNPN and NSWO as the interface type of the NSWOF, and the requested authentication type includes or indicates at least one authentication method supported by the SNPN.
[0129] According to various example embodiments, the access network identity may be (illustratively) constructed from 5G:SNPN:NSWO (or in a similar manner). Since the NSWO / NSWOF knows the SNPNs it serves or supports, the access network identity of the independent non-public network (which may be used as input for various key / parameter derivations) identifies the (serving) SNPN. In the case of a WLAN accessing a public land mobile network (PLMN), as an example of a public network, the access network identity may be (illustratively) constructed from / as 5G:NSWO:PLMNID:NID (or in a similar manner). Therefore, the NSWOF may use the corresponding (access) network identity to trigger the authentication process for the UE for both scenarios or use cases: a normal PLMN case and an NPN (e.g., SNPN or PNI-NPN) case.
[0130] According to various example embodiments, the requested authentication type (or an indication thereof) provides the AUSF with an indication of the requested authentication type / method as an authentication method supported by the SNPN. Since the NSWO / NSWOF is aware of the authentication methods supported by the SNPN it serves or supports, the requested authentication type (or an indication thereof) may indicate, request, identify, or specify an applicable (requested) authentication method. For a standalone non-public network, the requested authentication type (or an indication thereof) may indicate, request, identify, or specify (as an authentication method) such as EAP AKA Enhanced, EAP TLS, 5G-AKA, or any key generation EAP method.
[0131] In step 6-0, the AUSF (acting as an EAP authentication server) performs a (serving) network check based on the access network identity. To this end, the AUSF is configured with the access network identity (AN ID) as described above, and performs a (serving) network check on the access network identity (AN ID) as described above. In the case of WLAN access to SNPN via NSWO / NSWOF (which can be simply referred to as the NSWO+SNPN use case), the AUSF performs a (serving) network check by constructing 5G:SNPN:NSWO (etc.) with the AN ID.
[0132] When the (serving) network check is successful, in step 6a, the AUSF forwards a message, such as a request message, e.g., a Nudm_UEAuthentication_Get request, to the UDM, whose content is (at least in part) the same as the received authentication request message (e.g., a Nausf_UEAuthentication_Authenticate request). That is, the message (such as the request message, e.g., the Nudm_UEAuthentication_Get request) includes (at least) the SUCI, the access network identity, and the requested authentication type. Based on the access network identity, i.e., the AN ID, constructing 5G:SNPN:NSWO (etc.), the UDM can identify the underlying or related scenario as an NSWO+SNPN use case. As a result, the UDM will know that the received authentication request relates to an SNPN case (but not a normal PLMN case), which helps to correctly handle the requested authentication type / method, i.e., the selection of the authentication method.
[0133] Then, in step 6b, the UDM selects an authentication method for authenticating the UE (e.g., for establishing mutual authentication between the UE and the SNPN) in order to enable a (direct) connection from the UE to the SNPN (e.g., its core network part) via the WLAN access network. When selecting the authentication method, the UDM takes into account the requested authentication type, i.e., the authentication method indicated or requested thereby. Thus, the decision of the authentication method to be used / performed by / at the UDM is enabled or assisted by the NSWO / NSWOF, in particular the requested authentication type (or an indication thereof) in the authentication request message from the NSWOF. Furthermore, the decision of the authentication method to be used / performed by / at the UDM may be assisted by or based on the use of local policies (such as, for example, operator policies) or made using local policies. In this regard, the UDM may decide to use the indicated or requested authentication method, or to reject the request for authentication of the UE.
[0134] In step 7, the selected authentication method is executed. That is, the AUSF interacts with the NSSAAF / AAA-S (as an AAA server) to authenticate the UE and obtain the UE's SUPI, i.e., the SUPI corresponding to the SUCI. That is, the AUSF participates in an authentication method based on the requested authentication type, such as EAP authentication, and thereby obtains the SUPI in the context of such an authentication method. In this regard, several EAP messages, for example, may be exchanged between the UE and the credential holder.
[0135] Since the initial step only shares an anonymous SUCI, the real SUPI is only known by / at the AUSF during or after the EAP authentication in step 8, or in other words, registered or obtained by / at the AUSF.
[0136] Then, in steps 8b / 8c, the real SUPI is shared from the AUSF to the UDM in an authentication message. Using the SUPI, in step 8c, the UDM can perform authorization of the UE based on the (local) UE subscription data configured in the UDM and / or based on the (local) policies stored in the UDM.
[0137] In step 8a, the AUSF sends an authentication response message, such as Nausf_UEAuthentication_Authenticate response, with EAP success and the MSK key to the NSWOF. The AUSF may optionally provide the SUPI to the NSWOF. In step 9a, the NSWOF sends the EAP success and the MSK to the WLAN AN via the SWa interface, and in step 9b, the EAP success message is forwarded from the WLAN AN to the UE.
[0138] In steps 10a / 10b, after receiving the EAP success message, the WLAN AN and the UE derive a WLAN key from the PMK, for example, the first 256 bits of the MSK are used as the PMK. Then, in steps 10c / 10d, the UE and the WLAN AN perform a 4-way handshake to establish a secure connection with local IP configuration.
[0139] It should be noted that Figure 6 The sequence / process of FIG. 1 illustrates an example, including the operations of UE, WLAN AN and NSWOF and the operations between them, and the operations of NSWOF, AUSF and UDM and the operations between them. The operations of NSWOF, AUSF and UDM and the operations between them are represented accordingly. Figures 1 to 5 Illustrative and non-limiting examples of methods / processes.
[0140] As described above, various example embodiments provide a technique for (e.g., enabling / realizing) security of non-3GPP access to a (3GPP-based) NPN, or in other words, a technique for security of a (direct) connection from a UE to a (3GPP-based) NPN (e.g., its core network portion) via a non-3GPP access network.
[0141] According to various embodiments, various features (one or more) may be achieved / provided, including for example
[0142] - use the requested authentication type (or an indication thereof), which is for example included in messages from the interfacing entity to the authenticating entity and from the authenticating entity to the data management entity,
[0143] - using a network identity (which may also be referred to as an access network identity, at least in certain scenarios or use cases), which network identity identifies the non-public network and the interface type of the interfacing entity, for example included in messages from the interfacing entity to the authentication entity and from the authentication entity to the data management entity,
[0144] - using the subscription hidden identifier of the communicating entity as an example of a privacy-preserving identifier or an anonymous SUPI / identifier at an initial stage (e.g. before authentication of the communicating entity), and using the subscription permanent identifier of the communicating entity as an example of a non-privacy-preserving identifier or a real SUPI / identifier at a subsequent stage (e.g. during and / or after authentication of the communicating entity), such that, for example, the subscription permanent identifier is used at the authentication entity and / or provided from the authentication entity to the data management entity.
[0145] Through various exemplary embodiments, various effects and / or benefits (one or more) may be achieved, including, for example,
[0146] - enables the data management entity to know the purpose of the authentication request or authentication procedure, i.e. whether the authentication request or procedure relates to an NPN (e.g. SNPN or PNI-NPN) case or a normal PLMN case; thus, the data management entity can select an appropriate authentication method supported by the associated network, e.g. NPN (e.g. SNPN or PNI-NPN), such as e.g. EAP / AKA method for the SNPN case,
[0147] - In terms of security considerations, different scenarios or use cases can be covered / enabled, including NPN (e.g., SNPN or PNI-NPN) scenarios or use cases; for example, scenarios where the credential holder uses an AAA server (e.g., NSSAAF / AAA-S) for NSWO authentication, and scenarios where the credential holder uses AUSF and UDM for NSWO authentication,
[0148] - an (access) network identity identifying the non-public network (such as e.g. SNPN) and the interface type of the interfacing entity (such as e.g. NSWO / NSWOF) may be used to identify underlying / relevant scenarios or use cases, may be used by the authentication entity to perform (appropriate) network checks, and / or may be used to enable (appropriate) billing and charging,
[0149] - Authorization of the communicating entity may be enabled by / at the data management entity, even for different scenarios or use cases, such as for example SNPN+NSWO / NSWOF scenarios or use cases,
[0150] - (standardized or public) credentials (such as e.g. 5G credentials defined in / for 5G communication systems) may be re-used / used for authentication in the context of non-3GPP access to a (3GPP-based) NPN or in other words in the context of security of a (direct) connection from a UE to a (3GPP-based) NPN (e.g. a core network part thereof) via a non-3GPP access network,
[0151] - Means may be provided for mutual authentication between a communicating entity and a non-public network (based on 3GPP) even when using non-3GPP access, and means may be provided for enabling confidentiality, integrity and replay protected communications between a communicating entity and a non-public network (based on 3GPP) even when using non-3GPP access.
[0152] As described above, the above functions and their related operations, procedures, methods, and processes may be implemented by corresponding functional elements, entities, modules, units, processors, etc. These functional elements, entities, modules, units, processors, etc. (i.e., implementations of one or more example embodiments) may be implemented in a cloud environment through SDN, NFV / NFVI, etc.
[0153] Although various example embodiments are described with reference to operations, procedures, methods, and processes, these example embodiments also cover corresponding apparatuses, entities, modules, units, network nodes, and / or systems, including software and / or hardware thereof.
[0154] Reference below Figure 7 and Figure 8 Describe the corresponding example embodiments, and for the sake of brevity, refer to Figures 1 to 6 A detailed description of the corresponding configuration / settings, schemes, processes, sequences, methods, and functions, principles and operations.
[0155] exist Figure 7 and Figure 8 In the embodiment, these blocks are basically configured to perform the corresponding methods, procedures and / or functions as described above. These blocks as a whole are basically configured to perform the methods, procedures and / or functions as described above. Figure 7 and Figure 8 It should be noted that the individual blocks are intended to illustrate corresponding functional blocks that implement corresponding functions, processes or procedures. Such functional blocks are implementation-independent, i.e., they can be implemented by any type of hardware or software or a combination thereof.
[0156] In addition, Figure 7 and Figure 8In the figure, only those functional blocks that are relevant to any of the above-mentioned methods, procedures and / or functions are illustrated. A person skilled in the art will recognize that there are any other conventional functional blocks required for the operation of the corresponding structural arrangement, such as, for example, a power supply, a central processing unit, corresponding memories, etc. Among them, one or more memories are provided, which are used to store programs or program instructions for controlling or enabling individual functional entities or any combination thereof to operate as described herein with respect to the example embodiments.
[0157] Figure 7 A schematic diagram illustrating the structure of an apparatus according to at least one example embodiment is shown. Here, an apparatus may refer to a physical entity or component, such as a structural device that implements a particular network element, entity, or function or its functionality, or a functional or logical entity or component. For example, the apparatus shown may be implemented in or by a server or the like in a cloud environment, such as through a cloud-based implementation.
[0158] like Figure 7 As shown, according to at least one example embodiment, the apparatus 700 may include or implement at least one processor 710 and at least one memory 720 (and possibly at least one interface 730 ), which may be operatively connected or coupled, respectively, via, for example, a bus 740 .
[0159] The processor 710 and / or the interface 730 of the apparatus 700 may also include a modem or the like to facilitate communication via a (hardwired or wireless) link, respectively. The interface 730 of the apparatus 700 may include a transmitter, a receiver, or a transceiver, which is connected or coupled to one or more antennas, antenna elements (such as an antenna array), or a communication facility or component for (hardwired or wireless) communication with the linked, coupled, or connected device(s). The interface 730 of the apparatus 700 is typically configured to communicate with at least one other apparatus, device, node, or entity (particularly an interface thereof).
[0160] The memory 720 of the device 700 may represent a (non-transitory / tangible) storage medium (e.g., RAM, ROM, EPROM, EEPROM, etc.) and store corresponding software, programs, program products, macros or applets, etc., or portions thereof, which may be assumed to include program instructions or computer program codes that, when executed by a corresponding processor, enable the corresponding electronic device or device to operate according to the example embodiments described herein. In addition, the memory 720 of the device 700 may store (including databases) any data, information, etc. used in the operation of the device.
[0161] According to various example embodiments, the corresponding apparatus (and / or part thereof) may represent a component for performing the corresponding operation and / or presenting the corresponding function, and / or the corresponding device (and / or part thereof) may have a function for performing the corresponding operation and / or presenting the corresponding function.
[0162] In view of the foregoing, the illustrated apparatus 700 may be used to practice one or more example embodiments described herein.
[0163] When it is stated in the subsequent description that a processor (or some other component) is configured to perform a certain function, this should be interpreted as being equivalent to or corresponding to such a description statement that (i.e., at least one) processor or corresponding circuit system (potentially in cooperation with computer program code stored in a memory of the corresponding device or otherwise available (it should be understood that the memory may also be an external memory or provided / implemented by a cloud service, etc.)) is configured to cause the device to perform at least the aforementioned function. It should be understood that the processor or more generally the processing part in this document should not be regarded as merely a physical part representing one or more processors, but may also be regarded as a logical division of the referred processing tasks performed by one or more processors.
[0164] According to at least one example embodiment, the illustrated apparatus 700 may represent or implement / embody (a portion of) an authentication entity in / of a (mobile / wireless) communication system, or an element, function or entity having similar / comparable functionality or operability. Such an authentication entity may, for example, be or relate to an authentication server function (AUSF), for example acting as an EAP authentication server. Thus, as (for an authentication entity or AUSF) in Figure 1 、 Figure 2 and Figure 6 As described in any one of the above, the device 700 can be configured to execute programs and / or present functions and / or implement mechanisms.
[0165] Thus, the apparatus 700 may be caused, or the apparatus 700 or at least one of its processors 710 (possibly together with computer program code stored in at least one memory 720 thereof) may be configured to, for example, obtain an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the authentication request message comprising a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity; and to, for example, issue a request message to a data management entity, the request message comprising a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and the network identity.
[0166] Furthermore, the apparatus 700 may be caused, or the apparatus 700 or its at least one processor 710 (possibly together with computer program code stored in its at least one memory 720) may be configured to perform a network check based on the network identity; register a subscription permanent identifier of the communication entity corresponding to the subscription hidden identifier of the communication entity; and / or issue an authentication message including the subscription permanent identifier of the communication entity, for example to the data management entity.
[0167] According to at least one example embodiment, the illustrated apparatus 700 may represent or implement / embody (a portion of) a data management entity in / of a (mobile / wireless) communication system, or an element, function, or entity having similar / comparable functionality or operability. Such a data management entity may, for example, be or relate to a unified data manager (UDM). Thus, as (for a data management entity or UDM) in Figure 3 、 Figure 4 and Figure 6 As described in any one of the above, the device 700 can be configured to execute programs and / or present functions and / or implement mechanisms.
[0168] Thus, the apparatus 700 may be caused, or the apparatus 700 or at least one of its processors 710 (possibly together with computer program code stored in at least one memory 720 thereof) may be configured to, for example, obtain a request message from an authentication entity, the request message including a subscription hiding identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying an independent non-public network based on 3GPP, and an interface type of an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP; and select an authentication method for authenticating the communication entity based on the requested authentication type and the network identity.
[0169] In addition, the device 700 can be caused, or the device 700 or at least one of its processors 710 (possibly together with computer program code stored in its at least one memory 720) can be configured to trigger authentication of the communication entity using the selected authentication method; deny authentication of the communication entity; for example, obtain an authentication message from the authentication entity, the authentication message including the subscription permanent identifier of the communication entity corresponding to the subscription hidden identifier of the communication entity; and / or perform authorization of the communication entity using the subscription permanent identifier of the communication entity based on at least one of the subscription data configured at the data management entity or the policies stored at the data management entity.
[0170] According to at least one example embodiment, the illustrated apparatus 700 may represent or implement / embody an interface entity (a portion thereof) in / of a (mobile / wireless) communication system, or an element, function or entity having similar / comparable functionality or operability. In this document, the interface entity shall be configured to provide an interface between a non-3GPP access network and a (3GPP-based) independent non-public network. For example, at least in the case of a WLAN access network as an example of a non-3GPP access network, such an interface entity may be or relate to a non-seamless WLAN offload function (NSWOF). Thus, as (for the interface entity or NSWOF) in Figure 5 and Figure 6 As described in any of the above, the device 700 can be configured to execute programs and / or present functions and / or implement mechanisms.
[0171] Thus, the apparatus 700 may be caused, or the apparatus 700 or at least one of its processors 710 (possibly together with computer program code stored in at least one memory 720 thereof) may be configured to, for example, obtain a message comprising a subscription hidden identifier of a communication entity from a non-3GPP access network; and, for example, issue an authentication request message to an authentication entity, the authentication request message comprising a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying an interface type of an independent non-public network and interface entity based on 3GPP.
[0172] As described above, the apparatus according to at least one example embodiment may be constructed by including one or more units or components or circuit systems for performing corresponding operations, procedures and / or functions. For example, such one or more units or components or circuit systems may be based on Figure 7 The illustrated apparatus structure is realized / implemented, for example, by one or more processors 710 , one or more memories 720 , one or more interfaces 730 , or any combination thereof.
[0173] Figure 8 A schematic diagram illustrating the structure of an apparatus according to at least one example embodiment is shown.
[0174] like Figure 8 As shown, the apparatus 810 according to at least one example embodiment may represent or implement / embody (a portion of) an authentication entity in / of a (mobile / wireless) communication system, or an element, function or entity with similar / comparable functionality or operability. Such an authentication entity may, for example, be or relate to an authentication server function (AUSF), for example acting as an EAP authentication server. Thus, as (for the authentication entity or AUSF) in Figure 1 、 Figure 2 and Figure 6As described in any one of the above, the device 700 can be configured to execute programs and / or present functions and / or implement mechanisms.
[0175] The apparatus 810 may include (at least) one or more units / components / circuitry systems represented by an acquisition portion 811, which represents any implementation for (or is configured to) obtain, for example, an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP, the authentication request message including a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and the interface type of the interface entity; and one or more units / components / circuitry systems represented by an issuance portion 812, which represents any implementation for (or is configured to) issue a request message, for example, to a data management entity, the request message including a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity.
[0176] In addition, the device 810 may include (at least) one or more units / components / circuitry systems represented by an execution part 813, which represents any implementation for (or is configured to) perform network inspection based on network identity; and / or one or more units / components / circuitry systems represented by a registration part 814, which represents any implementation for (or is configured to) register a subscription permanent identifier of a communication entity corresponding to a subscription hidden identifier of the communication entity; and / or one or more units / components / circuitry systems represented by an issuance part 815, which represents any implementation for (or is configured to) issue an authentication message including the subscription permanent identifier of the communication entity, for example to a data management entity.
[0177] like Figure 8 As shown, the apparatus 820 according to at least one example embodiment may represent or implement / embody (a portion of) a data management entity in / of a (mobile / wireless) communication system, or an element, function or entity with similar / comparable functionality or operability. Such a data management entity may be or relate to a unified data manager (UDM), for example. Thus, as (for a data management entity or UDM) in Figure 3 、 Figure 4 and Figure 6 As described in any one of the above, the device 700 can be configured to execute programs and / or present functions and / or implement mechanisms.
[0178] The apparatus 820 may include (at least) one or more units / components / circuitry systems represented by an acquisition portion 821, which represents any implementation for (or is configured to) obtain, for example, a request message from an authentication entity, the request message including a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, which network identity identifies an independent non-public network based on 3GPP, and an interface type of an interface entity, which interface entity is configured to provide an interface between a non-3GPP access network and an independent non-public network based on 3GPP; and one or more units / components / circuitry systems represented by a selection portion 822, which represents any implementation for (or is configured to) select an authentication method for authenticating the communication entity based on the requested authentication type and the network identity.
[0179] In addition, the device 820 may include (at least) one or more units / components / circuitry systems represented by an acquisition part 823, which represents any implementation for (or is configured to) obtain an authentication message, for example, from an authentication entity, the authentication message including a subscription permanent identifier of the communication entity corresponding to the subscription hidden identifier of the communication entity; and / or one or more units / components / circuitry systems represented by an execution part 824, which represents any implementation for (or is configured to) perform authorization of the communication entity using the subscription permanent identifier of the communication entity based on at least one of the subscription data configured at the data management entity or the policies stored at the data management entity.
[0180] like Figure 8 As shown, the apparatus 830 according to at least one example embodiment may represent or implement / embody an interface entity (a portion thereof) in / of a (mobile / wireless) communication system, or an element, function or entity having similar / comparable functionality or operability. In this document, the interface entity shall be configured to provide an interface between a non-3GPP access network and a (3GPP-based) independent non-public network. For example, at least in the case of a WLAN access network as an example of a non-3GPP access network, such an interface entity may be or relate to a non-seamless WLAN offload function (NSWOF). Therefore, as (for the interface entity or NSWOF) in Figure 5 and Figure 6 As described in any of the above, the device 700 can be configured to execute programs and / or present functions and / or implement mechanisms.
[0181] The apparatus 830 may include (at least) one or more units / components / circuitry systems represented by an acquisition portion 831, which represents any implementation for (or configured to) acquire a message including a subscription hidden identifier of a communication entity, for example, from a non-3GPP access network; and one or more units / components / circuitry systems represented by an issuance portion 832, which represents any implementation for (or configured to) issue an authentication request message, for example, to an authentication entity, the authentication request message including a subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, which network identity identifies an independent non-public network based on 3GPP, and an interface type of the interface entity.
[0182] For further details on the operability / functionality of the apparatus (or its units / components) according to example embodiments, reference is accordingly made to the above references in conjunction with Figures 1 to 6 Description of any one of .
[0183] According to various example embodiments, various functions, operations, parts, units, components, circuit systems, etc. may be implemented in (or integrated into) one or more devices or systems, and / or may be distributed across one or more devices or systems. Therefore, depending on a requirement, constraint, specification, implementation, etc., at least one device and / or at least one system may be provided according to various example embodiments, which includes one or more or even all of the above-mentioned functions, operations, parts, units, components, circuit systems, etc.
[0184] According to example embodiments, any one of the (at least one) processor, (at least one) memory, and (at least one) interface, and any one of the units / components shown may be implemented as individual modules, chips, chipsets, circuit systems, etc., or one or more of them may accordingly be implemented as a common module, chip, chipset, circuit system, etc.
[0185] As used herein, the term "circuitry" may refer to one or more or all of the following: (a) a pure hardware circuit implementation (such as an implementation using only analog and / or digital circuitry), and (b) a combination of hardware circuitry and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuitry and software / firmware, and (ii) any portion of hardware processor(s) (including digital signal processor(s)), software, and memory(s) with software that work together to enable a device (such as a mobile phone or server) to perform various functions, and (c) hardware circuit(s) and / or processor(s), such as microprocessor(s) or portion(s) of microprocessor(s), that requires software (e.g., firmware) to operate, but which may not be present when not required for operation.
[0186] This definition of "circuitry" applies to all uses of the term herein, including in any claims. As a further example, as used herein, the term "circuitry" also covers an implementation of merely a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its accompanying software and / or firmware. For example, if applicable to the particular claim element, the term "circuitry" also covers a baseband integrated circuit or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or networking device.
[0187] According to example embodiments, a system may include any conceivable combination of any depicted or described apparatuses and other network elements or functional entities configured to cooperate as described above.
[0188] In general, it should be noted that the corresponding functional blocks or elements according to the various embodiments described herein may be implemented by any known components in hardware and / or software, if only suitable for performing the functions of the corresponding parts. The above method steps may be implemented in individual functional blocks or by individual devices, or one or more of the above method steps may be implemented in a single functional block or by a single device.
[0189] In general, a basic system architecture of a (long-range) communication network including a mobile communication system (in which some examples of the example embodiments are applicable) may include the architecture of one or more communication networks, including (one or more) radio access network subsystems / systems and possibly (one or more) core networks. Such an architecture may include one or more communication network control elements or functions, such as, for example, an access network element, a radio access network element, an access service network gateway or a base transceiver station (such as a base station, access point, NodeB (NB), eNB or gNB), a distributed or centralized unit, which controls a corresponding coverage area or (one or more) cells, and one or more communication stations are able to communicate with it via one or more channels via one or more communication beams to send several types of data in multiple access domains, the above-mentioned communication station is such as a communication element or function, such as a user equipment or terminal device, such as UE, or another device with similar functionality, such as a modem chipset, chip, module, etc., which may also be part of a station, element, function or application capable of communication, such as a UE, element or function that can be used for a machine-to-machine communication architecture, or as a separate element attached to such an element, function or application capable of communication, etc. Furthermore, core network elements or network functions may be included, such as gateway network elements / functions, mobility management entities, mobile switching centers, servers, databases, etc.
[0190] The general functionality and interconnection of the described elements and functions (which also depends on the actual network type) are known to those skilled in the art and are described in the corresponding specifications, so a detailed description thereof is omitted here. It should be understood that in addition to those described in detail below, several additional network elements and signaling links may be employed to communicate with elements, functions or applications (such as communication endpoints), communication network control elements (such as servers, gateways, radio network controllers) and other elements of the same or other communication networks.
[0191] The communication network architecture considered in the examples of the exemplary embodiments may also be capable of communicating with other networks, such as the public switched telephone network or the Internet, including the Internet of Things. The communication network may also be capable of supporting cloud services for virtual network elements or their functions, wherein it should be noted that the virtual network part of the (remote) communication network may also be provided by non-cloud resources, such as an intranet, etc. It should be understood that the network elements and / or corresponding functions of the access system, core network, etc. may be implemented by using any node, host, server, access node or entity, etc. suitable for such purpose. In general, the network functions may be implemented as network elements on dedicated hardware, as software instances running on dedicated hardware, or as virtualized functions instantiated on an appropriate platform (e.g., a cloud infrastructure).
[0192] Without changing the spirit or scope of the various exemplary embodiments, any method step is suitable for implementation as software or by hardware. Such software can be independent of the software code and can be specified using any known or future developed programming language, such as Java, C++, C, and assembly language, as long as the functionality defined by the method step is retained. Such hardware can be independent of the hardware type and can be implemented using any known or future developed hardware technology or any mixture of these technologies, such as MOS (metal oxide semiconductor), CMOS (complementary MOS), BiMOS (bipolar MOS), BiCMOS (bipolar CMOS), ECL (emitter coupled logic), TTL (transistor-transistor logic), etc., using, for example, ASIC (application specific IC (integrated circuit)) components, FPGA (field programmable gate array) components, CPLD (complex programmable logic device) components, or DSP (digital signal processor) components. The device / apparatus can be represented by a semiconductor chip, a chipset, or a (hardware) module including such a chip or chipset; however, this does not exclude the possibility that the functionality of the device / apparatus or module is not implemented in hardware but is implemented as software in a (software) module, such as a computer program or computer program product including an executable software code portion for execution / running on a processor. For example, a device may be considered as one device / apparatus, or a component of more than one device / apparatus, whether they cooperate in function or are independent in function but located in the same device housing.
[0193] Means and / or units / components or parts thereof may be implemented as individual devices, but this does not exclude that they may be implemented in a distributed manner throughout the system, as long as the functionality of the device is retained. Such and similar principles are considered to be known to those skilled in the art.
[0194] Software in the sense of this specification comprises software code, which itself comprises code means or parts or a computer program or computer program product for performing the corresponding functions, as well as software (or computer program, computer program product) embodied on a tangible medium (such as a computer-readable (storage) medium) having the corresponding data structures or code means / parts stored thereon, or embodied in a signal or a chip, potentially during processing.
[0195] The various example embodiments also cover any conceivable combination of the above method steps and operations, and any conceivable combination of the above nodes, devices, modules, or elements, as long as the concepts of the above methods and structural arrangements are applicable.
[0196] In view of the above situation, measures for (enabling / implementing) security of non-3GPP access to a 3GPP-based non-public network are provided. Such measures may exemplarily include: an authentication entity of a communication system obtains an authentication request message from an interface entity, the interface entity being configured to provide an interface between the non-3GPP access network and a 3GPP-based independent non-public network, the authentication request message including a subscription concealment identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying the 3GPP-based independent non-public network and the interface type of the interface entity, and sends a request message to or for a data management entity, the request message including the subscription concealment identifier of the communication entity, an indication of a requested authentication type, and the network identity.
[0197] Although various exemplary embodiments have been described above with reference to the accompanying drawings, it should be understood that the various exemplary embodiments are not limited thereto. Instead, it is obvious to those skilled in the art that the various exemplary embodiments may be modified in various ways without departing from the intended scope.
[0198] List of abbreviations
[0199] 3GPP: Third Generation Partnership Project
[0200] 5G(S): fifth generation (system)
[0201] AAA: Authentication, Authorization, and Accounting
[0202] AAA-S: Authentication, Authorization, and Accounting Server
[0203] AKA: Authentication and Key Agreement
[0204] AMF: Access and Mobility Management Function
[0205] AN: Access Network
[0206] AUSF: Authentication Server Function
[0207] EAP: Extensible Authentication Protocol
[0208] ID: Identifier / Identity
[0209] IEEE: Institute of Electrical and Electronics Engineers
[0210] IP: Internet Protocol
[0211] MBMS: Multimedia Broadcast / Multicast Service
[0212] MSK: MBMS service key
[0213] NAI: Network Access Identifier
[0214] NID: Network Identifier
[0215] NPN: Non-Public Network
[0216] NR: New Radio
[0217] PLMN: Public Land Mobile Network
[0218] PMK: Pairwise Master Key
[0219] PNI-NPN: Public Network Integrated Non-Public Network
[0220] NFV: Network Function Virtualization
[0221] NFVI: Network Function Virtualization Infrastructure
[0222] NSSAAF: Network Slice Specific Authentication and Authorization Function
[0223] NSWO: Non-Seamless WLAN Offload
[0224] NSWOF: Non-Seamless WLAN Offload Function
[0225] SBA / SBI: Service-Based Architecture / Interface
[0226] SDN: Software Defined Networking
[0227] SIDF: Subscription Identifier Decryption Function
[0228] SNPN: Standalone Non-Public Network
[0229] SUCI: Subscription Hidden Identifier
[0230] SUPI: Subscription Persistent Identifier
[0231] TLS: Transport Layer Security
[0232] UDM: Unified Data Manager / Management
[0233] WLAN: Wireless Local Area Network
[0234] UE: User Equipment
Claims
1. A method for authenticating an entity of a communication system, the method comprising: obtaining an authentication request message from an interface entity configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network, the authentication request message comprising: a subscription concealment identifier of a communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying the 3GPP-based independent non-public network and an interface type of the interface entity; and A request message is issued to a data management entity, the request message including: the subscription hiding identifier of the communication entity, the indication of the requested authentication type, and the network identity.
2. The method according to claim 1, further comprising: performing a network inspection based on the network identity, The request message is sent based on a result of the network inspection.
3. The method according to claim 1 or 2, further comprising: registering a subscription permanent identifier of said communicating entity corresponding to said subscription hidden identifier of said communicating entity, and An authentication message including the subscription permanent identifier of the communication entity is issued to the data management entity.
4. The method according to claim 3, wherein: The subscription permanent identifier is registered during, or as a result of, an authentication process for authenticating the communication entity using an authentication method based on the requested authentication type, and / or The registering includes obtaining an authentication message including the subscription permanent identifier.
5. The method according to any one of claims 1 to 4, wherein: The requested authentication type includes: at least one authentication method supported by the independent non-public network based on 3GPP.
6. The method according to claim 5, wherein: The authentication method is an extensible authentication protocol method and / or an authentication and key agreement method, includes at least one type of an extensible authentication protocol method and / or an authentication and key agreement method, or is based on an extensible authentication protocol method and / or an authentication and key agreement method, such as EAP-AKA enhanced version, EAP TLS, 5G-AKA or any key generation EAP method.
7. The method according to any one of claims 1 to 6, wherein: The authentication entity is, includes or involves an authentication server function AUSF, and / or The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO, and / or The data management entity is, includes or relates to a unified data management (UDM) entity, and / or The non-3GPP access network is, includes or relates to a wireless local area network (WLAN) access network, and / or The communication entity is, includes or involves a user equipment, and / or The network identity is, includes or relates to an access network identity, and / or The communication system is, includes or involves a 5G system.
8. A method for a data management entity of a communication system, the method comprising: obtaining a request message from an authentication entity, the request message including: a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based standalone non-public network, and an interface type of an interface entity configured to provide an interface between a non-3GPP access network and the 3GPP-based standalone non-public network, and An authentication method for authenticating the communicating entity is selected based on the requested authentication type and the network identity.
9. The method of claim 8, wherein the selecting comprises: triggering authentication of the communication entity using the selected authentication method, or Authentication of the communicating entity is denied.
10. The method according to claim 8 or 9, further comprising: An authentication message is obtained from the authentication entity, the authentication message including a subscription permanent identifier of the communication entity corresponding to the subscription hidden identifier of the communication entity.
11. The method according to claim 10, further comprising: Authorization of the communicating entity is performed using the subscription permanent identifier of the communicating entity based on at least one of subscription data configured at the data management entity or a policy stored at the data management entity.
12. The method according to any one of claims 8 to 11, wherein: The requested authentication type includes: at least one authentication method supported by the independent non-public network based on 3GPP.
13. The method according to claim 12, wherein: The authentication method is an extensible authentication protocol method and / or an authentication and key agreement method, includes at least one type of an extensible authentication protocol method and / or an authentication and key agreement method, or is based on an extensible authentication protocol method and / or an authentication and key agreement method, such as EAP-AKA enhanced version, EAP TLS, 5G-AKA or any key generation EAP method.
14. The method according to any one of claims 8 to 13, wherein: The data management entity is, includes or relates to a unified data management (UDM) entity, and / or The authentication entity is, includes or involves an authentication server function AUSF, and / or The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO, and / or The non-3GPP access network is, includes or relates to a wireless local area network (WLAN) access network, and / or The communication entity is, includes or involves a user equipment, and / or The network identity is, includes or relates to an access network identity, and / or The communication system is, includes or involves a 5G system.
15. A method for an interface entity of a communication system, the interface entity being configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network, the method comprising: obtaining a message including a subscription concealment identifier of a communication entity from the non-3GPP access network, and An authentication request message is sent to an authentication entity, the authentication request message including: the subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the 3GPP-based independent non-public network and the interface type of the interface entity.
16. The method according to claim 15, wherein: The requested authentication type includes: at least one authentication method supported by the independent non-public network based on 3GPP.
17. The method according to claim 16, wherein: The authentication method is an extensible authentication protocol method and / or an authentication and key agreement method, includes at least one type of an extensible authentication protocol method and / or an authentication and key agreement method, or is based on an extensible authentication protocol method and / or an authentication and key agreement method, such as EAP-AKA enhanced version, EAP TLS, 5G-AKA or any key generation EAP method.
18. The method according to any one of claims 15 to 17, wherein: The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO, and / or The non-3GPP access network is, includes or relates to a wireless local area network (WLAN) access network, and / or The authentication entity is, includes or involves an authentication server function AUSF, and / or The communication entity is, includes or involves a user equipment, and / or The network identity is, includes or relates to an access network identity, and / or The communication system is, includes or involves a 5G system.
19. A device for an authentication entity of a communication system, the device comprising: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: obtaining an authentication request message from an interface entity configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network, the authentication request message comprising: a subscription concealment identifier of a communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying the 3GPP-based independent non-public network and an interface type of the interface entity; and A request message is issued to a data management entity, the request message including: the subscription hiding identifier of the communication entity, the indication of the requested authentication type, and the network identity.
20. The apparatus of claim 19, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: performing a network inspection based on the network identity, The request message is sent based on a result of the network inspection.
21. The apparatus of claim 19 or 20, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: registering a subscription permanent identifier of said communicating entity corresponding to said subscription hidden identifier of said communicating entity, and An authentication message including the subscription permanent identifier of the communication entity is issued to the data management entity.
22. The apparatus of claim 21, wherein: The subscription permanent identifier is registered during, or as a result of, an authentication process for authenticating the communication entity using an authentication method based on the requested authentication type, and / or The registering includes obtaining an authentication message including the subscription permanent identifier.
23. The device according to any one of claims 19 to 22, wherein: The requested authentication type includes: at least one authentication method supported by the independent non-public network based on 3GPP.
24. The apparatus of claim 23, wherein: The authentication method is an extensible authentication protocol method and / or an authentication and key agreement method, includes at least one type of an extensible authentication protocol method and / or an authentication and key agreement method, or is based on an extensible authentication protocol method and / or an authentication and key agreement method, such as EAP-AKA enhanced version, EAP TLS, 5G-AKA or any key generation EAP method.
25. The device according to any one of claims 19 to 24, wherein: The authentication entity is, includes or involves an authentication server function AUSF, and / or The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO, and / or The data management entity is, includes or relates to a unified data management (UDM) entity, and / or The non-3GPP access network is, includes or relates to a wireless local area network (WLAN) access network, and / or The communication entity is, includes or involves a user equipment, and / or The network identity is, includes or relates to an access network identity, and / or The communication system is, includes or involves a 5G system.
26. An apparatus of a data management entity of a communication system, the apparatus comprising: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: obtaining a request message from an authentication entity, the request message including: a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based standalone non-public network, and an interface type of an interface entity configured to provide an interface between a non-3GPP access network and the 3GPP-based standalone non-public network, and An authentication method for authenticating the communicating entity is selected based on the requested authentication type and the network identity.
27. The apparatus of claim 26, wherein the selecting comprises: triggering authentication of the communication entity using the selected authentication method, or Authentication of the communicating entity is denied.
28. The apparatus of claim 26 or 27, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: Acquire an authentication message from the authentication entity, the authentication message including: a subscription permanent identifier of the communicating entity corresponding to the subscription hidden identifier of the communicating entity.
29. The apparatus of claim 28, wherein the instructions, when executed by the at least one processor, further cause the apparatus to: Authorization of the communicating entity is performed using the subscription permanent identifier of the communicating entity based on at least one of subscription data configured at the data management entity or a policy stored at the data management entity.
30. The device according to any one of claims 26 to 29, wherein: The requested authentication type includes: at least one authentication method supported by the independent non-public network based on 3GPP.
31. The apparatus of claim 30, wherein: The authentication method is an extensible authentication protocol method and / or an authentication and key agreement method, includes at least one type of an extensible authentication protocol method and / or an authentication and key agreement method, or is based on an extensible authentication protocol method and / or an authentication and key agreement method, such as EAP-AKA enhanced version, EAP TLS, 5G-AKA or any key generation EAP method.
32. The apparatus according to any one of claims 26 to 31, wherein: The data management entity is, includes or relates to a unified data management (UDM) entity, and / or The authentication entity is, includes or involves an authentication server function AUSF, and / or The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO, and / or The non-3GPP access network is, includes or relates to a wireless local area network (WLAN) access network, and / or The communication entity is, includes or involves a user equipment, and / or The network identity is, includes or relates to an access network identity, and / or The communication system is, includes or involves a 5G system.
33. A device for an interface entity of a communication system, the device comprising: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: obtaining a message including a subscription concealment identifier of a communication entity from the non-3GPP access network, and An authentication request message is sent to an authentication entity, the authentication request message including: the subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and an interface type of the interface entity.
34. The apparatus of claim 33, wherein: The requested authentication type includes: at least one authentication method supported by the independent non-public network based on 3GPP.
35. The apparatus of claim 34, wherein: The authentication method is an extensible authentication protocol method and / or an authentication and key agreement method, includes at least one type of an extensible authentication protocol method and / or an authentication and key agreement method, or is based on an extensible authentication protocol method and / or an authentication and key agreement method, such as EAP-AKA enhanced version, EAP TLS, 5G-AKA or any key generation EAP method.
36. The apparatus according to any one of claims 33 to 35, wherein: The interface entity is, includes or relates to a non-seamless wireless LAN offload function NSWOF, and the interface type is, includes or relates to a non-seamless wireless LAN offload NSWO, and / or The non-3GPP access network is, includes or relates to a wireless local area network (WLAN) access network, and / or The authentication entity is, includes or involves an authentication server function AUSF, and / or The communication entity is, includes or involves a user equipment, and / or The network identity is, includes or relates to an access network identity, and / or The communication system is, includes or involves a 5G system.
37. An apparatus comprising means for performing the method of any one of claims 1 to 7, 8 to 14, or 15 to 18.
38. A computer-readable medium comprising program instructions for causing an apparatus to perform the method of any one of claims 1 to 7, 8 to 14, or 15 to 18.
39. A system comprising: at least one processor and at least one memory storing instructions, wherein the instructions, when executed by the at least one processor, cause the system to perform at least one or more of the following: Obtaining an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network, the authentication request message comprising: a subscription hiding identifier of a communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying the 3GPP-based independent non-public network and an interface type of the interface entity, issuing a request message to a data management entity, the request message comprising: the subscription hiding identifier of the communication entity, the indication of the requested authentication type, and the network identity, Obtaining a request message from an authentication entity, the request message including: a subscription hiding identifier of the communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based standalone non-public network, and an interface type of an interface entity configured to provide an interface between a non-3GPP access network and the 3GPP-based standalone non-public network, selecting an authentication method for authenticating the communication entity based on the requested authentication type and the network identity, obtaining a message including a subscription concealment identifier of a communication entity from the non-3GPP access network, and An authentication request message is sent to an authentication entity, the authentication request message including: the subscription hidden identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the independent non-public network based on 3GPP, and an interface type of the interface entity.
40. A system comprising one or more of the following: A component for obtaining an authentication request message from an interface entity, the interface entity being configured to provide an interface between a non-3GPP access network and a 3GPP-based independent non-public network, the authentication request message comprising: a subscription hiding identifier of the communicating entity, an indication of the requested authentication type, and a network identity identifying the 3GPP-based independent non-public network and an interface type of the interface entity, means for issuing a request message to a data management entity, said request message comprising: said subscription hiding identifier of said communicating entity, said indication of said requested authentication type, and said network identity, means for obtaining a request message from an authentication entity, the request message comprising: a subscription hiding identifier of a communication entity, an indication of a requested authentication type, and a network identity, the network identity identifying a 3GPP-based standalone non-public network, and an interface type of an interface entity configured to provide an interface between a non-3GPP access network and the 3GPP-based standalone non-public network, means for selecting an authentication method for authenticating said communicating entity based on said requested authentication type and said network identity, means for obtaining a message comprising a subscription concealment identifier of a communicating entity from said non-3GPP access network, and A component for issuing an authentication request message to an authentication entity, the authentication request message comprising: the subscription hiding identifier of the communication entity, an indication of the requested authentication type, and a network identity, the network identity identifying the 3GPP-based independent non-public network and an interface type of the interface entity.