Enabling home network triggered master authentication in multi-registration scenario
By pre-configuring policies and selecting appropriate AMF/SEAFs at the UDM node, the service interruption problem of the main authentication process under the control of the service network in multi-registration scenarios is solved, thus achieving continuity and security of UE services.
Patent Information
- Application Number
- CN202380096428.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-07
- Publication Date
- 2025-11-11
AI Technical Summary
In multi-registration scenarios, the primary authentication process triggered by the home network in existing technologies is still under the control of the serving network, which may lead to the interruption of ongoing services by the UE.
By pre-configuring operator policies at the Unified Data Management (UDM) node, it is possible to determine when to trigger the primary authentication process and select the appropriate Access and Mobility Management Function (AMF) or Security Anchor Function (SEAF) to achieve primary authentication triggered by the home network and avoid service interruption.
In multi-registration scenarios, the main authentication process is controlled by the UDM node according to different connection management modes, ensuring the service continuity and security of the UE and avoiding service interruption.
Smart Images

Figure CN120937401A_ABST
Abstract
Description
Technical Field
[0001] This patent document generally relates to wireless communication. Background Technology
[0002] Mobile telecommunications technologies are propelling the world toward an increasingly interconnected and networked society. Compared to existing wireless networks, next-generation systems and wireless communication technologies will need to support a wider range of use case characteristics and provide more complex and sophisticated access requirements and flexibility.
[0003] Long-Term Evolution (LTE) is a wireless communication standard for mobile devices and data terminals developed by the 3rd Generation Partnership Project (3GPP). LTE Advanced (LTE-A) is a wireless communication standard that enhances the LTE standard. The fifth-generation (5G) wireless system advances further development based on the LTE and LTE-A wireless standards, aiming to support higher data rates, massive connectivity, ultra-low latency, high reliability, and other emerging service requirements. Summary of the Invention
[0004] A technique for triggering the primary authentication process from a unified data management (UDM) node is disclosed. The UDM node determines which access and mobility management function (AMF) or security anchor function (SEAF) to run the primary authentication process based on the mobile network registration corresponding to the AMF / SEAF. The AMF / SEAF then initiates the primary authentication process based on the user equipment (UE) mobility management state or authentication policy.
[0005] The first example wireless communication method includes a network node receiving multiple mobile network registrations. The method further includes the network node determining an Access and Mobility Management Function (AMF) or a Secure Anchor Function (SEAF) based on the multiple mobile network registrations. The method also includes the network node transmitting an authentication message to the AMF or SEAF.
[0006] The second example wireless communication method includes: receiving an authentication message by an Access and Mobility Management Function (AMF) or a Security Anchor Function (SEAF). The method further includes: determining, in response to the authentication message, the mobility management state of the User Equipment (UE) or a local authentication policy for the AMF or SEAF. The method also includes: determining, based on the UE's mobility management state or authentication policy, whether to run a primary authentication process.
[0007] In yet another exemplary embodiment, an apparatus configured or operable to perform the methods described above is disclosed. The apparatus may include a processor configured to implement the methods described above.
[0008] In yet another exemplary embodiment, the methods described above are implemented in the form of processor-executable code stored in a non-transitory computer-readable storage medium. When executed by a processor, the code included in the computer-readable storage medium causes the processor to implement the methods described in this patent document.
[0009] The above and other aspects and their embodiments are described in more detail in the accompanying drawings, specification and claims. Attached Figure Description
[0010] Figure 1 An exemplary authentication process is shown.
[0011] Figure 2 Another exemplary authentication process is shown.
[0012] Figure 3 This illustrates yet another exemplary authentication process.
[0013] Figure 4 An example authentication process triggered by the home network is shown.
[0014] Figure 5 This is an exemplary flowchart for transmitting authentication messages.
[0015] Figure 6 This is an exemplary flowchart for determining whether to run the main authentication process.
[0016] Figure 7 An exemplary block diagram of a hardware platform is shown, which may be part of a network device or a communication device.
[0017] Figure 8 Exemplary wireless communications, including a base station (BS) and user equipment (UE), are shown based on some implementations of the disclosed technology. Detailed Implementation
[0018] The example headings for the various sections below are used to facilitate understanding of the disclosed subject matter and do not limit the scope of the claimed subject matter in any way. Therefore, one or more features from one example section may be combined with one or more features from another example section. Furthermore, the term "5G" is used for clarity; however, the technologies disclosed in this document are not limited to 5G technology and can be used in wireless systems implementing other protocols.
[0019] I. Introduction
[0020] In fifth-generation (5G) systems, the home network's control over the security of user equipment (UE) has been strengthened compared to previous generations through many new mechanisms, such as Subscription Permanent Identifier (SUPI) privacy protection, termination of the authentication process in the home network, and providing increased home network control and links to subsequent processes. However, when authentication is triggered, it remains under the control of the serving network.
[0021] Home networks use Authentication Server Function (AUSF) keys (K) AUSF ) or from K AUSF Derived keys are used to provide protection for various services, such as interoperability from LTE to 5G, Steering of Roaming (SoR) / UE parameter update (UPU), and Authentication and Key Management for Application (AKMA) services. Therefore, the home network will benefit from having the ability to ensure the new key is obtained by triggering authentication. AUSF Available, especially to prevent counter wrap-around in SoR / UPU or the potential lack of available K after interoperability with LTE. AUSF .
[0022] The above describes the primary authentication requirement triggered by the home network in 3GPP TR 33.741.
[0023] Figure 1This illustrates the initiation of a primary authentication triggered by the UE, as described in 3GPP TS 33.501. The primary authentication is initiated by the UE and the serving network. The UDM in the home network then selects an authentication method from Extensible Authentication Protocol (EAP) Authentication and Key Agreement (EAP-AKA) and 5G AKA.
[0024] After the authentication is initiated by the UE, the UDM initiates the EAP-AKA' or 5GAKA authentication process based on the result of the authentication method selection.
[0025] Figure 2 and Figure 3 The EAP-AKA' and 5G AKA authentication processes described in 3GPP TS 33.501 are illustrated respectively. The EAP-AKA' and 5G AKA authentication processes achieve mutual authentication between the UE and the network and provide key material that can be used between the UE and the serving network in subsequent security processes. The key material generated by the main authentication and key negotiation processes produces what is known as K... SEAF The anchor key, the K SEAF It is provided by the AUSF of the home network to the SEAF of the serving network.
[0026] This patent document does not describe it in detail. Figures 1 to 3 The authentication process is shown below. However, the following is given: Figures 1 to 3 This section introduces some basic terms used to help understand these three certification processes.
[0027] UE: User Equipment
[0028] AMF: Access and Mobility Management Functions
[0029] SEAF: Safety Anchor Function
[0030] AUSF: Authentication Server Function
[0031] UDM: Unified Data Management
[0032] AKMA: Application Authentication and Key Management
[0033] SoR: Roaming Control
[0034] UPU: UE parameter update
[0035] SUPI: User Permanent Identifier
[0036] KAUSF Authentication intermediate key
[0037] K SEAF Security anchor key
[0038] K AKMA AKMA anchor key
[0039] exist Figures 1 to 3 In this process, the triggering of primary authentication remains under the control of the serving network. However, if re-authentication is triggered immediately after a Unified Data Management (UDM) authentication request, the UE's ongoing service may be interrupted.
[0040] This patent document proposes a mechanism for home network-triggered master authentication for UEs with different connection management modes in a multi-registration scenario. The proposed process is described in Example 1.
[0041] II. Example 1: Multiple Registration Scenarios
[0042] Figure 4 This paper illustrates a proposed mechanism for implementing home network-triggered master authentication for UEs with different connection management modes in a multi-registration scenario. The proposed process may include eight steps.
[0043] 1. UDM can be pre-configured with carrier policies to determine when to trigger the primary authentication process. Pre-configured carrier policies can include the following conditions:
[0044] a. UDM determines that the UE's previous master authentication is no longer secure;
[0045] b. UDM discovered that the UE supporting AKMA service does not have an AKMA indicator;
[0046] c. UDM discovered that UEs supporting SoR / UPU services do not have the corresponding K AUSF ;
[0047] d. When a UE first migrates from an Evolved Packet System (EPS) to a 5G System (5GS), there are no available K nodes maintained in the AUSF. AUSF UDM cannot find the AUSF identifier (ID) / address;
[0048] e. A network function (NF) or third-party application function (AF) sends a re-authentication request to the UDM. For example, in the AKMA service, a K-re-authentication refresh is required. AKMA or KAF .
[0049] 2. Based on the received event or local operator policy, if there is no primary authentication in progress for the UE, the UDM determines to trigger primary authentication.
[0050] 3. If the target UE has multiple registrations on different Public Land Mobile Networks (PLMNs), the UDM determines the following Service Access and Mobility Management Functions (AMF) / Security Anchor Functions (SEAF):
[0051] a. The UDM first selects the AMF / SEAF corresponding to the 3rd Generation Partnership Project (3GPP) registration. If recertification fails (as indicated in step 5), the UDM selects the AMF / SEAF corresponding to a non-3GPP registration; or
[0052] b. UDM first selects the AMF / SEAF corresponding to the latest registration (3GPP / non-3GPP). If re-authentication fails (as indicated in step 5), UDM selects the AMF / SEAF corresponding to another registration (non-3GPP / 3GPP).
[0053] 4. UDM uses UE's SUPI to send authentication messages to AMF / SEAF.
[0054] 5. After receiving the authentication message from the UDM, the AMF / SEAF should decide whether to run the main authentication process based on its own local authentication policy and the UE mobility management (MM) status.
[0055] If the UE cannot be contacted and the AMF / SEAF cannot perform primary authentication, the AMF / SEAF sends an authentication response message to the UDM, which indicates the reason for the failure. The policy in the response message can be a timer, after which authentication will be performed. If the UE accesses the network before the timer reaches zero, the AMF / SEAF will stop the timer and immediately trigger primary authentication.
[0056] If the UE is in 5G MM-CONNECTED mode and there is no ongoing service running on the UE, steps 6 to 7 will be skipped, and the AMF / SEAF will trigger the authentication process described in step 8 without sending an authentication response message to the UDM.
[0057] If the UE is in 5G MM-CONNECTED mode and an ongoing service is running on the UE, the AMF / SEAF sends an authentication response message back to the UDM. The response message includes the UE's mobility management mode and a policy for triggering authentication. This policy can be a timer after which authentication will be performed, or simply an indication that authentication will be triggered after a wait. The result in the message should indicate that primary authentication will be triggered after the ongoing service ends. Steps 6 and 7 are then skipped, and the AMF / SEAF triggers the authentication process as described in step 8 after the wait time.
[0058] If an ongoing primary authentication triggered by the UE exists, the AMF / SEAF sends an authentication response message back to the UDM. The result in the response message should indicate that an ongoing primary authentication triggered by the UE exists.
[0059] If the UE is in 5G MM-IDLE mode, the AMF / SEAF will trigger paging / notification and primary authentication as described in steps 6 through 8, and send an authentication response message back to the UDM. The response message includes the UE's mobility management mode and the policy used to trigger authentication. The policy in the response message can be a timer after which authentication will be performed, or simply an indication that authentication will be triggered after a wait. The result in the message should indicate that primary authentication will be triggered after the UE is connected.
[0060] 6. If the UE is in 5G MM-IDLE mode, the AMF / SEAF will send a paging message to the UE if the UE is registered with 3GPP, or a notification message to the UE if the UE is not registered with 3GPP.
[0061] After receiving a paging or notification message, the 7.5G MM-IDLE mode UE sends a service request to the AMF / SEAF to establish a service connection.
[0062] 8. When the UE is in 5G MM-CONNECTED mode, the AMF / SEAF initiates the main authentication process as described in Section 6.1.2 of TS 33.501.
[0063] This patent document proposes a mechanism for implementing home network-triggered master authentication for UEs with different connection management modes in a multi-registration scenario, as detailed below:
[0064] Provides a method for selecting AMF / SEAF in scenarios with multiple UE registrations;
[0065] AMF / SEAF instructs UDM on the results, UE mobility management modes, and policies for different UE conditions to avoid interrupting ongoing UE services.
[0066] Figure 5This is an exemplary flowchart of transmitting authentication messages. Operation 502 includes receiving multiple mobile network registrations by a network node. Operation 504 includes determining an Access and Mobility Management Function (AMF) or a Security Anchor Function (SEAF) by the network node based on the multiple mobile network registrations. Operation 506 includes transmitting an authentication message from the network node to the AMF or SEAF. In some embodiments, this method can be implemented according to Embodiment 1. In some embodiments, other steps of performing this method may be based on better system performance than conventional protocols.
[0067] In some embodiments, the network node includes a Unified Data Management (UDM) node, and the multiple mobile network registrations include multiple Public Land Mobile Network (PLMN) registrations associated with a target user equipment (UE). In some embodiments, determining an AMF or SEAF includes selecting an AMF or SEAF corresponding to a 3GPP registration among the multiple mobile network registrations. In some embodiments, the method further includes the network node receiving an authentication failure message, wherein determining an AMF or SEAF further includes selecting an AMF or SEAF corresponding to a non-3GPP registration among the multiple mobile network registrations.
[0068] In some embodiments, determining the AMF or SEAF includes selecting the AMF or SEAF corresponding to the latest registration among a plurality of mobile network registrations, wherein the latest registration is a 3GPP registration or a non-3GPP registration. In some embodiments, the method further includes receiving an authentication failure message by a network node, wherein determining the AMF or SEAF further includes selecting the AMF or SEAF corresponding to another registration among the plurality of mobile network registrations, wherein the other registration is different from the latest registration.
[0069] Figure 6 This is an exemplary flowchart for determining whether to run the main authentication process. Operation 602 includes receiving an authentication message by the Access and Mobility Management Function (AMF) or the Security Anchor Function (SEAF). Operation 604 includes the AMF or SEAF determining, in response to the authentication message, the mobility management state of the user equipment (UE) or a local authentication policy for the AMF or SEAF. Operation 606 includes the AMF or SEAF determining, based on the UE's mobility management state or authentication policy, whether to run the main authentication process. In some embodiments, this method can be implemented according to Embodiment 1. In some embodiments, other steps of performing this method can be based on better system performance than conventional protocols.
[0070] In some embodiments, if the UE cannot be contacted and the AMF or SEAF cannot run the main authentication process, the method further includes the AMF or SEAF sending an authentication response message, wherein the authentication response message includes the inability to contact the UE as the reason for the failure to run the main authentication process. In some embodiments, the authentication response message further includes a timer, wherein the AMF or SEAF initiates the main authentication process after the timer expires or immediately initiates the main authentication process if the UE is contacted before the timer expires.
[0071] In some embodiments, if the UE is in connected mode and no ongoing service is running on the UE, the AMF or SEAF runs the main authentication process.
[0072] In some embodiments, if the UE is in connected mode and an ongoing service is running on the UE, the method further includes sending an authentication response message by the AMF or SEAF, wherein the authentication response message includes the UE's mobility management state. In some embodiments, the authentication response message further includes a timer, wherein the AMF or SEAF initiates a main authentication process after the timer expires. In some embodiments, the authentication response message further includes an instruction to the AMF or SEAF to initiate a main authentication process after the ongoing service has completed.
[0073] In some embodiments, if there is an ongoing master authentication process triggered by the UE, the method further includes sending an authentication response message by the AMF or SEAF, wherein the authentication response message includes an indication of an ongoing master authentication process triggered by the UE.
[0074] In some embodiments, if the UE is in idle mode, the method further includes initiating a paging or notification procedure by the AMF or SEAF, and sending an authentication response message by the AMF or SEAF, wherein the authentication response message includes the UE's mobility management status. In some embodiments, the authentication response message further includes a timer, wherein the AMF or SEAF initiates a main authentication procedure after the timer expires. In some embodiments, the authentication response message further includes an indication from the AMF or SEAF to initiate a main authentication procedure after connecting to the UE.
[0075] Figure 7 An exemplary block diagram of a hardware platform 700 is shown. The hardware platform 700 may be part of a network device (e.g., a base station, UDM, AMF, or SEAF) or a communication device (e.g., a user equipment (UE)). The hardware platform 700 includes at least one processor 710 and a memory 705 storing instructions. These instructions, when executed by the processor 710, configure the hardware platform 700 to perform operations on... Figures 1 to 6The operations described in the various embodiments described in this patent document are as follows: Transmitter 715 transmits or sends information or data to another device. For example, a network device transmitter may send a message to a user equipment. Receiver 720 receives information or data transmitted or sent by another device. For example, a user equipment may receive a message from a network device. For example, the UE or network device described in this document may be implemented using hardware platform 700.
[0076] The implementation methods discussed above will be applied to wireless communication. Figure 8 An example of a wireless communication system (e.g., a 5G or NR (New Radio) cellular network) is illustrated, comprising a base station 820 and one or more user equipments (UEs) 811, 812, and 813. In some embodiments, the UE accesses the BS (e.g., the network) using a communication link to the network (sometimes referred to as the uplink direction, as depicted by dashed arrows 831, 832, and 833), followed by subsequent communication from the BS to the UE (e.g., shown in the direction from the network to the UE, sometimes referred to as the downlink direction, as shown by arrows 841, 842, and 843). In some embodiments, the BS sends information to the UE (sometimes referred to as the downlink direction, as depicted by arrows 841, 842, and 843), followed by subsequent communication from the UE to the BS (e.g., shown in the direction from the UE to the BS, sometimes referred to as the uplink direction, as shown by dashed arrows 831, 832, and 833). UE can be, for example, a smartphone, tablet, mobile computer, machine-to-machine (M2M) device, Internet of Things (IoT) device, etc. Figure 8 As depicted in this document, the UE can be communicatively coupled to the base station 820. The UE can also communicate with the BS for CSI (Channel State Information) communication.
[0077] In some embodiments, authentication messages can be transmitted from the UDM to the AMF / SEAF. In some embodiments, authentication messages can be transmitted from the UDM to the AFS. In some embodiments, authentication messages can be transmitted from the UDM to the UE. In some embodiments, authentication messages can be transmitted from the AFS to the AMF / SEAF. In some embodiments, authentication messages can be transmitted from the AFS to the UE. In some embodiments, authentication messages can be transmitted from the AMF / SEAF to the UE.
[0078] In some embodiments, the authentication response message can be transmitted from the AMF / SEAF to the UDM. In some embodiments, the authentication response message can be transmitted from the AMF / SEAF to the AUSF. In some embodiments, the authentication response message can be transmitted from the AUSF to the UDM. In some embodiments, the authentication response message can be transmitted from the UE to the UDM. In some embodiments, the authentication response message can be transmitted from the UE to the AMF / SEAF. In some embodiments, the authentication response message can be transmitted from the UE to the AUSF.
[0079] Those skilled in the art will understand that this document discloses a method for initiating a primary authentication process from a home network node (such as a Unified Data Management (UDM) node). The UDM node determines which Access and Mobility Management Function (AMF) or Security Anchor Function (SEAF) to run the primary authentication process based on the mobile network registration corresponding to the AMF / SEAF. The AMF / SEAF then initiates the primary authentication process based on the user equipment (UE)'s mobility management state or authentication policy.
[0080] Some embodiments described herein are described in the general context of methods or processes that may be implemented in one embodiment as a computer program product embodied in a computer-readable medium, which includes computer-executable instructions (such as program code) that are executed by a computer in a networked environment. The computer-readable medium may include removable and non-removable storage devices, including but not limited to read-only memory (ROM), random access memory (RAM), compact discs (CD), digital versatile discs (DVD), etc. Therefore, the computer-readable medium may include non-transitory storage media. Generally, program modules may include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. Computer- or processor-executable instructions, associated data structures, and program modules represent examples of program code for performing steps of the methods disclosed herein. Specific sequences of such executable instructions or associated data structures represent examples of corresponding actions for implementing the functionality described in such steps or processes.
[0081] Some embodiments of the disclosed examples may be implemented as devices or modules using hardware circuitry, software, or a combination thereof. For example, hardware circuitry implementations may include discrete analog and / or digital components, for instance, integrated as part of a printed circuit board. Alternatively or additionally, the disclosed components or modules may be implemented as application-specific integrated circuits (ASICs) and / or field-programmable gate arrays (FPGAs). Some implementations may additionally or alternatively include a digital signal processor (DSP), which is a dedicated microprocessor with an architecture optimized for the operational requirements of digital signal processing associated with the functions disclosed in this application. Similarly, various components or sub-components within each module may be implemented using software, hardware, or firmware. Connections between modules and / or components within modules may be provided using any of the connection methods and media known in the art, including but not limited to communication via the Internet, wired or wireless networks using suitable protocols.
[0082] While this document contains numerous details, these details should not be construed as limiting the scope of the claimed invention or the scope that may be claimed, but rather as descriptions of features specific to particular embodiments. Certain features described in the context of different embodiments in this document may also be implemented in a single embodiment in combination. Conversely, various features described in the context of a single embodiment may also be implemented separately in multiple embodiments, or in any suitable sub-combination. Furthermore, although features may be described above as functioning in certain combinations, and even initially claimed in this way, in some cases one or more features from the claimed combination may be removed from that combination, and the claimed combination may involve sub-combinations or variations thereof. Similarly, although operations are depicted in a specific order in the drawings, this should not be construed as requiring the operation to be performed in the specific order shown or sequentially, or requiring the performance of all shown operations to achieve the desired result.
[0083] Only a few implementations and examples have been described, and other implementations, enhancements and modifications can be made based on what is described and shown in this disclosure.
Claims
1. A method for wireless communication, comprising: The network node receives registrations from multiple mobile networks; The network nodes determine the Access and Mobility Management Function (AMF) or the Security Anchor Function (SEAF) based on the registration of the multiple mobile networks; as well as The network node transmits the authentication message to the AMF or the SEAF.
2. The method according to claim 1, wherein, The network nodes include a unified data management (UDM) node, and the plurality of mobile network registrations include a plurality of Public Land Mobile Network (PLMN) registrations associated with a target user equipment (UE).
3. The method according to any one of claims 1 or 2, wherein, Determining the AMF or the SEAF includes selecting the AMF or SEAF corresponding to the 3GPP registration in the plurality of mobile network registrations.
4. The method according to claim 3, further comprising: The network node receives an authentication failure message, wherein determining the AMF or the SEAF further includes selecting the AMF or SEAF corresponding to the non-3GPP registration among the plurality of mobile network registrations.
5. The method according to any one of claims 1 or 2, wherein, Determining the AMF or the SEAF includes selecting the AMF or SEAF corresponding to the latest registration among the plurality of mobile network registrations, wherein the latest registration is a 3GPP registration or a non-3GPP registration.
6. The method according to claim 5, further comprising: The network node receives an authentication failure message, wherein determining the AMF or the SEAF further includes selecting an AMF or SEAF corresponding to another registration among the plurality of mobile network registrations, and wherein the other registration is different from the latest registration.
7. A method for wireless communication, comprising: Authentication messages are received by the Access and Mobility Management Function (AMF) or the Security Anchor Function (SEAF); The AMF or the SEAF, in response to the authentication message, determines the mobility management status of the user equipment (UE) or the local authentication policy of the AMF or the SEAF. as well as The AMF or SEAF determines whether to run the main authentication process based on the UE's mobility management status or the authentication policy.
8. The method according to claim 7, wherein, The inability to contact the UE and the inability of the AMF or the SEAF to run the main authentication process further includes: the AMF or the SEAF sending an authentication response message, wherein the authentication response message includes the inability to contact the UE as the reason for the failure to run the main authentication process.
9. The method according to claim 8, wherein, The authentication response message also includes a timer, wherein the AMF or the SEAF initiates the main authentication process after the timer expires, or initiates the main authentication process immediately if the UE is contacted before the timer expires.
10. The method of claim 7, wherein, If the UE is in connected mode and no ongoing service is running on the UE, then the AMF or the SEAF runs the main authentication process.
11. The method according to claim 7, wherein, The UE is in connected mode and there is an ongoing service running on the UE, and the method further includes: sending an authentication response message by the AMF or the SEAF, wherein the authentication response message includes the mobility management status of the UE.
12. The method according to claim 11, wherein, The authentication response message also includes a timer, wherein the AMF or SEAF initiates the main authentication process after the timer expires.
13. The method according to claim 11, wherein, The authentication response message also includes an instruction to the AMF or the SEAF to initiate the main authentication process after the ongoing service is completed.
14. The method according to claim 7, wherein, The existence of an ongoing main authentication process triggered by the UE further includes: the AMF or the SEAF sending an authentication response message, wherein the authentication response message includes an indication of an ongoing main authentication process triggered by the UE.
15. The method according to claim 7, wherein, The UE being in idle mode also includes: The paging or notification process is initiated by the AMF or the SEAF; An authentication response message is sent by the AMF or the SEAF, wherein the authentication response message includes the mobility management status of the UE.
16. The method according to claim 15, wherein, The authentication response message also includes a timer, wherein the AMF or the SEAF initiates the main authentication process after the timer expires.
17. The method according to claim 15, wherein, The authentication response message also includes an instruction to the AMF or the SEAF to initiate the main authentication process after connecting to the UE.
18. An apparatus for wireless communication, comprising a processor, wherein, The processor is configured to implement the method according to any one or more of claims 1 to 17.
19. A computer-readable program storage medium having code stored thereon, the code, when executed by a processor, causing the processor to perform the method according to any one or more of claims 1 to 17.