Method for providing 5GC service access through non-integrated non-3GPP network and related device

By generating an NSW0F key and a temporary UE identifier by the UE, a secure communication channel is established directly with the 5GC network NF entity, which solves the challenges of secure registration and connection without TNGF and N3IWF, and realizes secure UE registration and service access.

CN121128138APending Publication Date: 2025-12-12NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480032908.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-08
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

When the Trusted Non-3GPP Gateway Function (TNGF) and Non-3GPP Interoperability Function (N3IWF) are unavailable, user equipment (UE) faces challenges in securely registering and connecting to fifth-generation core network (5GC) services through non-integrated, non-3GPP access networks.

Method used

The User Equipment (UE) generates a Non-Seamless Radio Offloading (NSWOF) key and establishes a secure communication channel directly with the first Network Function (NF) entity of the 5GC network. It performs primary authentication through a pre-configured fully qualified domain name address, generates a temporary UE identifier and an NSWOF key, and completes the secure registration process.

Benefits of technology

It enables secure UE registration and connection to the 5GC network in the absence of TNGF and N3IWF, ensuring the security of communication channels and service access permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

When accessing services via a non-integrated, non-3rd generation partnership project access network, secure registration and connectivity of user equipment to a limited range of services provided by a 5th generation core network is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of mobile communication networks, and in particular to the provision of fifth-generation core network (5GC) services to users and their associated devices through non-integrated, non-3GPP networks.

[0002] introduction The information presented in this section helps to better understand the invention disclosure. Therefore, the statements in this section should be understood in this context and should not be construed as an admission of prior art or non-prior art.

[0003] Given the high demand for wireless communication and 5GC services, 5GC cellular networks have found it necessary to "offload" some traffic (e.g., data). To this end, both user equipment (UE) and cellular networks need to be able to perform this offloading through non-integrated, non-3GPP access networks (e.g., wireless LANs, abbreviated as "WLAN").

[0004] However, when neither the Trusted Non-3GPP Gateway Function (TNGF) nor the Non-3GPP Interoperability Function (N3IWF) is available (i.e., the 5G Non-Access Stratum (NAS) registration procedure via a non-3GPP access network is not used), there are challenges in providing secure registration and connectivity to 5GC services for UEs via non-integrated, non-3GPP access networks.

[0005] Therefore, it is hoped that innovative solutions can be provided to alleviate the challenges outlined in this article. Summary of the Invention

[0006] This disclosure describes exemplary methods and related devices for providing 5GC service access through non-integrated, non-3GPP networks.

[0007] In one embodiment, a method for providing 5GC services through a non-integrated, non-3GPP access network may include: a user equipment (UE) generating a non-seamless radio offloading (NSWOF) key after completing primary authentication; and sending an initialization message containing the NSWOF key directly to a first network function (NF) entity of the 5GC network to establish a secure communication channel (e.g., an IP sec tunnel) directly between the UE and the first NF entity using the NSWOF key.

[0008] This exemplary method may also include forming a secure communication channel, including generating or receiving a temporary UE identifier by the UE, and generating an NSWOF key by the UE.

[0009] In one embodiment, generating an NSWOWF key may include completing a first encryption process, wherein completing the first encryption process may further include receiving a CONSTANT value or RAND value, an FC value, and an MSK value.

[0010] Alternatively, generating the NSWOF key may include completing a second encryption process, which may further include receiving a temporary UE identifier, an FC value, and an MSK value.

[0011] In one embodiment, generating a temporary UE identifier may further include completing a third encryption process, wherein completing the third encryption process may further include receiving a CONSTANT value or RAND value, an FC value, and an MSK value.

[0012] In addition to the steps described above (and elsewhere in this document), this method may also include the UE generating an additional initialization message containing the generated temporary UE identifier, and sending the additional initialization message and the temporary UE identifier to the first NF entity within the formed secure communication channel.

[0013] In addition, this exemplary method may also include performing primary authentication by pre-configuring the fully qualified domain name address of the first NF entity of the UE having a 5GC network.

[0014] A second exemplary method for providing fifth-generation core network (5GC) services via a non-integrated, non-3GPP access network may include: generating an electronic indicator by an NF entity of the 5GC network and sending it to a second NF entity of the 5GC network, indicating permission for the UE to register via non-integrated, non-3GPP access; sending an indicator by a first NF entity to the UE, indicating permission for non-integrated, non-3GPP network registration; receiving an Internet key exchange security association initialization message ("initialization message") containing an NSWOWF key directly from the UE by the first NF entity; and establishing a secure communication channel (e.g., an IPsec tunnel) directly between the UE and the first NF entity.

[0015] The second method may further include having the first NF entity compare the received temporary UE identifier with the stored temporary UE identifier; and when the comparison results match, directly establishing a secure communication channel between the UE and the first NF entity.

[0016] Furthermore, the second exemplary method may also include: (i) the first NF entity completing a comparison process to authenticate the first communication session before continuing to register the UE with the 5GC network; and / or (ii) the first NF entity sending a registration message to a third NF entity of the 5GC network, the registration message including a non-access stratum, user data management, UE configuration management value, a previously generated subscription permanent identifier (SUPI) value, and an NSWOF address; and / or (iii) the first NF entity sending a registration message to the third NF entity, wherein the registration message contains a request for the third NF entity to forward NSWOF-specific data to the first NF entity, wherein the requested NSWOF data may include an identifier of an allowed 5GC service, which may include a service selected from data service, call service, or short message service.

[0017] In addition, this second exemplary method may also include sending a restricted service indication message from the first NF entity to the UE, which allows the UE to access a limited range and number of 5GC services provided by the 5GC network.

[0018] A third exemplary method for providing fifth-generation core network (5GC) services through a non-integrated, non-3GPP access network may include: generating an NSW0F key and a temporary UE identifier by a first NF entity of the 5GC network; and sending the generated NSW0F key, temporary UE identifier, and SUPI by the first NF entity to a second NF entity of the 5GC network.

[0019] A third exemplary method may further include completing a first encryption process to generate an NSWOF key, wherein the first encryption process may include receiving a RAND value or CONSTANT value, an FC value, and an MSK value.

[0020] Alternatively, generating the NSWOF key may include completing a second encryption process, which may include receiving a temporary UE identifier value, an FC value, and an MSK value.

[0021] In one embodiment, generating a temporary UE identifier may include completing a third encryption process, wherein completing the third encryption process may include receiving a CONSTANT value or RAND value, an FC value, and an MSK value.

[0022] The fourth method for providing fifth-generation core network (5GC) services through a non-integrated, non-3GPP access network may include: generating an electronic indicator from a third NF entity of the 5GC network and sending it to a second NF entity of the core 5G network, indicating that the UE is permitted to register through the non-integrated, non-3GPP access network; receiving a non-seamless unified data management, subscription user data management "get" message ("get message") from a first NF entity of the 5GC network, the get message containing a request to send non-seamless radio offloading network function (NSWOF) specific data to the first NF entity; and sending NSWOF data to the first NF entity.

[0023] The method of claim 28, wherein the NSWOF specific data identifier indicates the 5GC service that the UE is allowed to access.

[0024] In addition to the exemplary methods, this disclosure also provides related apparatus for providing 5GC services through a non-integrated, non-3GPP access network. Such apparatus (e.g., UE) may include components for generating an Internet Key Exchange Security Association initialization message ("initialization message") containing the generated NSWOWF key; and components for sending the initialization message directly to a first NF entity of the 5GC network to directly establish a secure communication channel (e.g., IP sec tunnel) between the apparatus and the first NF entity.

[0025] In one embodiment, such an apparatus may further include a component for pre-configuring the fully qualified domain name address of a first NF entity in the 5GC network.

[0026] A second exemplary apparatus (e.g., an NSWOF entity in a 5GC network) may include means for providing 5GC services in a 5GC network via a non-integrated, non-3GPP access network. Such means may include components for generating and sending a first indicator to a second NF entity in the 5GC network, the first indicator indicating permission for a UE to register via a non-integrated, non-3GPP access network; components for sending a second indicator to the UE, the second indicator indicating permission for non-integrated, non-3GPP network registration; components for directly receiving an Internet Key Exchange Security Association Initialization Message ("Initialization Message") containing an NSWOF key from the UE; and components for directly establishing a secure communication channel (e.g., an IP sec tunnel) between the UE and the apparatus.

[0027] A third exemplary device (e.g., an Authentication Server Function (AUSF) entity for a 5GC network) may also be included in a 5GC network. This device can provide 5GC services through a non-integrated, non-3GPP access network, wherein the device may include components for generating an NSWOWF key and a temporary UE identifier; and components for sending the generated NSWOWF key, temporary UE identifier, and subscription permanent identifier (SUPI) to a first NF entity of the 5GC network.

[0028] A fourth exemplary device (e.g., a unified data management entity) may also be present in a 5GC network. Such a device can provide 5GC services via a non-integrated, non-3GPP access network, wherein the device may include: components for generating and sending an electronic indicator to a second NF entity of the 5GC network, the electronic indicator indicating permission for a UE to register via a non-integrated, non-3GPP access network; components for receiving a non-seamless unified data management, subscriber data management "get" message ("get message") from a first NF entity of the 5GC network, the get message including a request to send non-seamless radio offloading network function (NSWOF) specific data to the first NF entity; and components for sending NSWOF data to the first NF entity.

[0029] In one embodiment, NSWOF specific data can identify the 5GC services that the UE is allowed to access.

[0030] Brief description of the attached figures The present invention is illustrated by way of example and is not limited to the accompanying drawings, wherein the same reference numerals denote similar elements, and wherein: Figure 1 An exemplary mobile communication network according to this disclosure is depicted.

[0031] Figure 2A and 2B An exemplary message flow is depicted according to the exemplary methods provided in this disclosure.

[0032] Figure 3A and 3B An exemplary block diagram is depicted illustrating the generation of a Non-Seamless Wireless Offloading Network Function (NSWOF) key according to an exemplary method provided in this disclosure.

[0033] Figure 4 An exemplary block diagram is depicted illustrating an exemplary method for generating a temporary UE ID according to the present disclosure.

[0034] Figure 5 Simplified block diagrams of devices are depicted, such as electronic components of a 5GC network or electronic components of a non-integrated, non-3GPP access network.

[0035] Figure 6 A simplified block diagram of a device, such as a UE, is depicted.

[0036] Specific embodiments of the present invention are disclosed below with reference to various accompanying drawings and sketches. The descriptions and illustrations are provided to enhance understanding. For example, Figure 1 The networks and block diagrams in Figures 3 and 4 do not represent actual networks, devices, or apparatuses; rather, they are provided to explain the features of the methods and apparatus of the present invention.

[0037] Simplicity and clarity are sought in the description and illustrations to effectively enable those skilled in the art to make, use, and best practice the exemplary embodiments described herein based on knowledge known in the art. Those skilled in the art will understand that various modifications and variations can be made to the specific embodiments described herein without departing from the spirit and scope of this disclosure. Therefore, the text and drawings should be considered illustrative and exemplary, not restrictive or all-encompassing, and all such modifications to the specific embodiments described herein are intended to be included within the scope of this disclosure.

[0038] Detailed description of exemplary embodiments The following detailed description describes exemplary embodiments and is not intended to limit it to the explicitly disclosed combinations. Therefore, unless otherwise stated, the features disclosed herein may be combined to form additional combinations that are not shown separately for the sake of brevity.

[0039] As used herein and in the appended claims, the terms "comprising," "including," or variations thereof are intended to mean a non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements may include not only those elements in the list but also other elements not expressly listed or inherent to such a process, method, article, or apparatus.

[0040] As used herein, the term "an" or "a kind" is defined as one or more. As used herein, the term "a plurality of" is defined as two or more. As used herein, the term "another" is defined as at least a second or more.

[0041] Unless otherwise stated herein, the use of relational terms (if any), such as "first" and "second," is solely for distinguishing one function, process, or set of executable instructions from another, and does not necessarily require or imply any actual such relationship, order, or importance between such functions, processes, or sets of executable instructions.

[0042] As used herein, the terms "including" and / or "having" are defined as including (i.e., open language).

[0043] In the accompanying drawings, similar reference numerals always indicate similar features in all drawings.

[0044] The term "or" as used in this document is used for both selection and connection, unless otherwise stated.

[0045] The terms "illustrative" and "exemplary" are used as examples and do not indicate a level of quality.

[0046] As used herein, the term "data" and similar terms refer to information that can be transmitted, received, and / or stored according to certain embodiments of this disclosure.

[0047] As used herein, the term "user equipment" or "UE" refers to an apparatus, among other things, including electronic components (e.g., modems) that act as radio frequency transceivers, wirelessly (i) transmit signals, messages, and data to one or more elements (e.g., devices, apparatuses) of a mobile telecommunications network using an air interface, and (ii) receive signals, messages, and data from one or more elements of the network using an air interface.

[0048] As used herein, where applicable, the use of the letters "a" and "n" in a phrase indicates the first and last element or step in a group of elements or steps, such as one or more UEs 2a to 2n.

[0049] As used herein, the terms "telecommunications entity," "entity," or the plural forms "telecommunications entity" and "entity" mean: (a) an implementation of electronic hardware circuitry alone (e.g., an implementation in analog and / or digital circuitry) capable of performing one or more functions, such as network functions (NF) or user-defined functions (UE); and / or (b) a combination of electronic circuitry and computer program products, including software and / or firmware instructions stored on one or more electronic memories, which work together to cause a device to perform one or more NF, UE functions, or process steps described herein; and / or (c) an electronic circuitry, such as an electronic microprocessor, a portion of a microprocessor, a processor, a portion of a processor, an electronic integrated circuit, or an electronic application processor (collectively referred to herein as a "processor"), executing stored instructions (e.g., software or firmware) retrieved from at least one electronic memory, which, when executed by the processor, cause the device or element itself to perform one or more features, NF, UE functions, or steps of a process or method. As used herein, the terms "telecommunications entity" and "entity" may be used interchangeably herein.

[0050] As used herein, the names "first," "second," "third," and other relational terms (if any) are used only to distinguish one network function (NF), entity, process, or action from another NF, view, entity, or action, and / or to distinguish one UE function, entity, process, or action from another UE function, view, entity, action, or process, without requiring or implying any actual such relationship, order, or importance between such functions, views, entities, actions, or processes.

[0051] As used herein, the phrase "electronic memory" (referred to herein as "memory") refers to a non-transitory electronic storage medium (e.g., a volatile or non-volatile memory device). Examples of non-transitory electronic storage media include, but are not limited to: random access memory (RAM); programmable read-only memory (PROM); erasable programmable read-only memory (EPROM); FLASH-EPROM; magnetic computer-readable media (e.g., floppy disk, hard disk, magnetic tape, any other magnetic medium); optical computer-readable media (e.g., read-only optical disc memory (CD-ROM); digital versatile optical disc (DVD); Blu-ray disc (BD), the like, or combinations thereof); or any other non-transitory medium from which an electronic processor may retrieve stored instructions, which, when executed, cause the device to perform one or more functions or steps in the process.

[0052] As used herein, the phrase "non-integrated" refers to a telecommunications network that is not seamlessly connected to or interoperable with cellular networks defined by 3GPP, while the phrase "non-3GPP" refers to a telecommunications network that does not comply with 3GPP mobile communication standards. An example of a "non-integrated, non-3GPP network" is a private wireless network or WLAN built using technologies such as Wi-Fi, LoRa (Low Power Wide Area Network), or other proprietary wireless solutions. Such networks can be used for specific applications, such as industrial Internet of Things (IoT) deployments.

[0053] Now for reference Figure 1 The document depicts an exemplary mobile communication network 1 (e.g., a 5GC wireless network). In one embodiment, network 1 may include one or more UEs 2a to 2n configured to perform the innovative functions and steps described herein and to wirelessly communicate and couple with one or more wireless access points (APs) 3a to 3n of an exemplary non-integrated, non-3GPP access network 4 (e.g., a WLAN) via one or more telecommunications channels 5a to 5n. In one embodiment, each of the one or more wireless APs 3a to 3n may be configured to perform the innovative functions and steps described herein. Furthermore, the non-integrated, non-3GPP access network 4 may further communicate with a core wireless network 6 (e.g., a 5GC wireless network).

[0054] In one embodiment, the core wireless network 6 may include multiple Telecommunication Network Function (NF) entities, such as a Non-Seamless Wireless Offloading (NSWOF) entity 8 (sometimes referred to as a "second NF entity" for simplicity), configured to perform known Non-Seamless Wireless Offloading Network Functions and Procedures (NSWOFs), innovative functions and procedures described herein (e.g., innovative NSWOF functions and procedures), and support NSWO authentication. Furthermore, in one embodiment, the NSWOF entity 8 may be wirelessly connected to one or more non-integrated, non-3GPP access networks (e.g., network 4) and connected via wired or wireless connection 10 to an Authentication Server Function (AUSF) entity 9 (sometimes referred to as a "first NF entity" for simplicity), which is also part of the core network 6. The AUSF entity 9 may be referred to as an Extensible Authentication Protocol (EAP) authenticator and may be further configured to perform known network functions and procedures, innovative functions and procedures described herein, and perform authentication for one or more UEs 2a to 2n, such as UE 2a, and store data for UE 2a to 2n authentication.

[0055] Figure 1 The document also describes how AUSF entity 9 connects to Unified Data Management (UDM) entity 10 (sometimes referred to as the "third NF entity" for simplicity) via wired or wireless means. UDM entity 10 can be configured to perform known network functions and procedures, innovative functions and procedures described herein, and to store user subscription data, decrypt subscription hidden identifiers (SUCI), etc.

[0056] Although Figure 1 Telecommunication entities 8 to 10 are depicted as three separate and distinct elements, but it should be understood that this is merely exemplary. Alternatively, one or more of entities 8 to 10 may be combined together, or further, may be separated into additional elements.

[0057] As will be explained in more detail herein, embodiments of this disclosure innovatively modify and / or extend the features, functions, and procedures of entities 8 to 10 and UEs 2a to 2n and APs 3a to 3n of the non-integrated, non-3GPP access network 4 to allow UEs 2a to 2n to securely register and connect to the 5GC network 6 to access 5GC services when neither TNGF nor N3IWF is available (i.e., without using the 5G non-access stratum (NAS) registration procedure via the non-3GPP access network).

[0058] For simplicity, we assume the reader is familiar with the disclosures regarding NSWO-based authentication in Appendix S of Technical Specification TS 33.501. Furthermore, the disclosures regarding NSWO-based authentication in Appendix S of Technical Specification TS 33.501 are incorporated herein by reference. Additionally, to illustrate the innovative features, functions, and steps provided in this disclosure, we will (temporarily) discuss a single UE2a and a single non-integrated non-3GPP access network 4 (e.g., WLAN), but this is merely exemplary. It should be understood that our discussion applies to each UE 2a to 2n seeking secure registration and connection to the 5GC network 6 to access 5GC services when neither TNGF nor N3IWF is available, and may also apply to multiple non-integrated non-3GPP access networks. Furthermore, for simplicity, we may refer to communications (e.g., messages, signaling) exchanged between the non-integrated non-3GPP access network 4 and UE 2a and / or network 6, although it should be understood that these communications involve one or more wireless APs 3a to 3n of network 4.

[0059] In embodiments, UE 2a may include Internet of Things (IoT) compatible devices, such as mobile phones, laptops, personal computers, electronic servers, home appliances, and industrial equipment, which are just a few non-limiting examples of UE 2a.

[0060] Now for reference Figure 2A and Figure 2B It describes an exemplary communication flow involving elements and entities of mobile network 1, which provide secure registration and connectivity to 5GC services for UE 2a via a non-integrated non-3GPP access network 4 when neither TNGF nor N3IWF is available (i.e., the 5G NAS registration procedure via a non-3GPP access network is not used).

[0061] In this embodiment, our discussion will first describe the innovative features, functions, and steps that one or more network entities 8 to 10 of the 5GC network 6 can accomplish in conjunction with the non-integrated non-3GPP access network 4, and then describe the innovative features, functions, and steps that the UE 2a can accomplish in conjunction with the non-integrated non-3GPP access network 4 and the core network 6.

[0062] In one embodiment, UE 2a may be pre-configured with the fully qualified domain name ("fqdn") address of NSWOWF entity 8 (i.e., to complete primary authentication). Thereafter, steps 101 to 106 shown in Figure 2 (as described in Appendix S of TS 33.501 regarding NSWO-based authentication) can be performed by a combination of element 2a, elements and corresponding entities of network 4 (e.g., WLAN), and elements and corresponding entities 8, 9, and 10 of 5GC network 6.

[0063] Subsequently, during innovation step 107, UDM entity 10 can be configured to innovatively generate and send a "flag" (e.g., an electronic value, referred to herein as a "first" indicator) to AUSF entity 9 (e.g., an EAP authentication server) indicating permission for the UE to register via a non-integrated, non-3GPP access network (such as network 4), provided that subscription data allows the UE (e.g., UE 2a) to register via a non-integrated, non-3GPP network (such as network 4). In one embodiment, such a flag can be configured and stored in a unified data repository (UDR) (e.g., a database). Figure 1 (Not shown in the image), this repository can be managed by UDM entity 10.

[0064] Innovatively and as an alternative, NSWOF entity 8 can be configured to provide an indicator (e.g., an electronic message) to AUSF entity 9 and UDM entity 10, indicating that core network 6 is connected via... Figure 1 Connections 11 and 12 in the configuration support non-integrated non-3GPP network registration (hereinafter referred to as the "second" indicator). For example, this indicator may be provided during step 105.

[0065] After completing innovation step 107, you can complete... Figure 2A Steps 108 to 115 are shown (as per the provisions regarding NSWO-based certification in Appendix S of TS 33.501).

[0066] After completing step 115, in one embodiment, innovative step 116 can be performed. More specifically, assuming (i) NSWOF entity 8 has sent a "second" indicator to AUSF entity 9 and UDM entity 10 (i.e., core network 6 supports non-integrated non-3GPP network registration) or (ii) UDM entity 10 has sent a first indicator to AUSF entity 9 in step 107 (i.e., core network 6 allows non-integrated non-3GPP network registration), AUSF entity 9 can be configured to generate an NSWOF key and a temporary UE identifier. As further described herein, UE 2a should also generate the same NSWOF key and temporary UE identifier (i.e., any UE 2a to 2n wishing to register with core 5G network 6 via non-integrated non-3GPP access network 4). In an alternative embodiment, AUSF 9 may send the generated NSWOF key and temporary UE identifier to UE 2a, or, as described below, UE 2a may generate these same keys and identifiers to form a secure communication channel (e.g., IPsec tunnel).

[0067] Continuing, after generating the NSWOF key and / or temporary UE identifier, AUSF entity 9 may, for example, send the generated NSWOF key, temporary UE identifier, and subscription permanent identifier (SUPI) to NSWO entity 8 via connection 11 during step 116.

[0068] More specifically, we first turn to discuss an exemplary embodiment of generating NSWOF keys from elements and corresponding entities (e.g., AUSF entity 9) of the 5GC network 6.

[0069] Now for reference Figure 3A In one embodiment, the AUSF entity 9 may include at least one processor 502 configured to execute and retrieve electronic instructions stored in and from at least one memory (e.g., see...). Figure 5 The memory 503) is used to generate the NSWOF key 16 to complete the first cryptographic key derivation function (KDF) process for generating the NSWOF key 16. For example, as Figure 3A As shown, processor 502 can receive RAND value 13, fixed constant (FC) value 15, and master session key (MSK) value 14, and then, based on the received values ​​13, 14, and 15 and a first KDF procedure, execute a first KDF procedure during step 116 to generate NSWOF key 16. In one embodiment, the FC value may be a value determined by a telecommunications standard or adopted by a telecommunications provider. In a further embodiment, AUSF entity 9 may use the same FC value to generate NSWOF key 16 for each UE 2a to 2n. Regarding the MSK value, in one embodiment, the MSK value may be generated by AUSF entity 9 independently of UEs 2a to 2n using a known procedure.

[0070] Alternatively, processor 502 may receive CONSTANT value 13 instead of RAND value, FC value 15, and MSK value 14, and then execute the first cryptographic KDF procedure to generate NSWOF key 16 during step 116. In one embodiment, similar to the FC value, the CONSTANT value may be determined by telecommunications standards or adopted by a telecommunications provider. In a further embodiment, AUSF entity 9 may use the same CONSTANT value to generate NSWOF key 16 for each UE 2a to 2n.

[0071] In another alternative embodiment, reference Figure 3B The processor 502 may receive the temporary UE identifier value 17 instead of the CONSTANT or RAND value, FC value 19 and MSK value 18, and then perform a "second" cipher KDF procedure to generate the NSWOF key 20 during step 116.

[0072] We now turn to an exemplary embodiment of generating a temporary UE identifier from elements and corresponding entities of the core 5G network 6 (e.g., AUSF entity 9).

[0073] Now for reference Figure 4 In one embodiment, upon receiving CONSTANT value 21 (or RAND value), FC value 23 and MSK value 22, processor 502 (e.g., a processor of AUSF 9) may be configured to complete a third cipher KDF process to generate a temporary UE identifier 24 during step 116.

[0074] As previously mentioned, after generating the NSWOF key and / or temporary UE identifier, AUSF entity 9 (or another entity of the core 5G network 6) may, for example, send the generated NSWOF key, temporary UE identifier and SUPI to NSWOF entity 8 via connection 11 during step 116.

[0075] Next, during step 117a, NSWOF entity 8 can be configured to receive and store the NSWOF key and / or temporary UE identifier, as well as SUPI, from AUSF entity 9. Furthermore, NSWOF entity 8 can be configured, for example, to send an indication allowing registration with the non-integrated non-3GPP access network 4 via connection 7 (hereinafter referred to as the "third" indication). Additionally, NSWOF entity 8 can be configured to complete the additional steps regarding NSWO-based authentication as described in Annex S of TS 33.501.

[0076] Upon receiving the third indicator, the non-integrated non-3GPP access network 4 (e.g., one or more of APs 3a to 3n) can be configured to send a similar indicator to UE 2a, for example via connection 5, during step 117b, indicating permission for the non-integrated non-3GPP network to register (hereinafter referred to as the "fourth indicator"). Thereafter, the non-integrated non-3GPP access network 4 (e.g., one or more of APs 3a to 3n) can complete the steps specified in Annex S of TS 33.501 regarding NSWO-based authentication.

[0077] We now turn our attention to the role of UE 2a, for example, in innovative approaches to secure registration and connectivity of UE 2a to 5GC services via a non-integrated non-3GPP access network 4 when neither TNGF nor N3IWF functionality is available (i.e., without using the 5G non-access stratum (NAS) registration procedure via a non-3GPP access network), as described herein.

[0078] First, we will describe an innovative implementation whereby UE 2a generates an NWSOF key and a temporary UE identifier based on stored values ​​(e.g., values ​​stored by UE 2a). Then, we will describe an implementation whereby UE 2a generates an NWSOF key and a temporary UE identifier based at least in part on values ​​received from elements and corresponding entities of the core 5G network 6.

[0079] To recap, based on the fourth indicator that allows registration with the non-integrated non-3GPP network as discussed above, UE 2a can be configured to complete the registration process with the 5GC network 6 via the non-integrated non-3GPP access network 4 when neither TNGF nor N3IWF is available (i.e., without using the 5G NAS registration procedure).

[0080] Recall that UE 2a may be pre-configured with the fully qualified domain name ("fqdn") address of NSWOWF entity 8. Therefore, in order to establish an IPSec tunnel between UE 2a and NSWOWF entity 8 of core network 6 to ensure secure registration and communication between UE 2a and core network 6, in one embodiment, UE 2a needs to export the same NSWOWF key and UE temporary identifier generated by an entity of 5GC network 6 (e.g., AUSF entity 9).

[0081] Refer again Figure 3A UE 2a's processor 604 (see also) Figure 6 It can receive CONSTANT value 13, FC value 15, and MSK value 14, and then execute electronic instructions stored in and retrieved from at least one memory (e.g., see...). Figure 6 During step 119, the first cryptographic KDF process discussed above is completed (memory 605) to generate the NSWOF key 16. As previously mentioned, in one embodiment, the FC value may be determined by a telecommunications standard or adopted by a telecommunications provider. In a further embodiment, each UE 2a to 2n may use the same FC value to generate the NSWOF key 16. Regarding the MSK value, in one embodiment, each UE 2a to 2n may use a known process to generate the MSK value independently of AUSF entity 9.

[0082] Alternatively, processor 604 may receive RAND value 13 instead of CONSTANT value, FC value 15, and MSK value 14, and then perform the first cryptographic KDF process during step 119 to generate NSWOF key 16.

[0083] In another alternative embodiment, reference Figure 3BThe processor 604 may receive the temporary UE identifier value 17 instead of the CONSTANT or RAND value, the FC value 19, and the MSK value 18, and then execute the second cryptographic KDF process discussed above to generate the NSWOF key 20 during step 119.

[0084] We now turn to discuss an exemplary embodiment of UE 2a generating a temporary UE identifier.

[0085] Refer again Figure 4 In one embodiment, upon receiving the CONSTANT value 21 (or RAND value), FC value 23, and MSK value 22, the processor 604 may be configured to complete the third cryptographic KDF process discussed above in order to generate a temporary UE identifier 24 during step 119.

[0086] As mentioned earlier, UE 2a can generate NSWOF and temporary UE identifier values ​​based on stored CONSTANT, RAND, FC and MSK values.

[0087] One or more of these values ​​can be sent from elements and corresponding entities in 5GC network 6 (e.g., from AUSF entity 9) to UE 2a. For example, Figure 3A and Figure 4 The RAND values ​​13 and 21 can be sent from elements and corresponding entities in core network 6 (e.g., from AUSF entity 9) to UE 2a. Furthermore, Figure 3B The temporary UE identifier 17 in the 5GC network 6 can be sent to UE 2a from entities in the 5GC network 6 (e.g., from AUSF entity 9). In contrast, the FC and CONSTANT values ​​are not sent to UE 2a from elements and corresponding entities in the 5GC network 6.

[0088] After generating the NSWOF key using the embodiments described herein, UE 2a then generates and directly sends an Internet Key Exchange Security Association Initialization Message (referred to as the "First Initialization Message", abbreviated as "IKE_SA_INIT") containing the NSWOF key to NSWOF entity 8 during step 119a.

[0089] Upon receiving the initialization message from UE 2a, NSWOF entity 8 can be further configured to directly establish a secure communication channel (e.g., an IPsec tunnel) between UE 2a and NSWO entity 8 of 5GC network 6. Therefore, the non-integrated, non-3GPP access network 4 cannot access the established secure communication channel.

[0090] As an alternative embodiment, UE 2a may include the generated temporary UE identifier in the initialization message (referred to as the "second initialization message") and then send the second initialization message to NSWO entity 8 during alternative step 119b.

[0091] Upon receiving the second initialization message, NSWOF entity 8 is configured to compare the received temporary UE identifier with its stored temporary UE identifier. If the comparison matches, NSWOF entity 8 is further configured to establish a secure communication channel (e.g., an IPsec tunnel) between UE 2a and NSWO entity 8 of 5GC network 6 during step 119b.

[0092] After establishing a secure communication channel with NSWOF entity 8, UE 2a and NSWOF entity 8 can now begin the innovative process of registering UE 2a with core network 6.

[0093] refer to Figure 2B In one embodiment, during step 120, UE 2a may send a first registration message, which may contain a temporary UE identifier, to NSWOF entity 8 (referred to as the "first communication session") within an established secure communication channel. Upon receiving the registration message containing the temporary UE identifier, NSWOF entity 8 completes a comparison process to authenticate the first communication session before proceeding with UE 2a's registration in 5GC network 6.

[0094] Subsequently, during steps 121 and 122, NSWOF entity 8 and UDM entity 10 exchange messages to register UE 2a within core network 6.

[0095] More specifically, during step 121, NSWOF entity 8 may send a second registration message, which includes NAS user data management ("Nudm"), UE configuration management (UECM) value, previously generated subscription permanent identifier (SUPI) value, and the address of NSWOF entity 8 ("NSWOF address") to UDM entity 10.

[0096] In one embodiment, the SUPI value may have been previously stored and is available at AUSF entity 9 before being sent to NSWOF entity 8.

[0097] Upon receiving the second registration message, UDM entity 10 generates and sends a confirmation message to NSWO entity 8 during step 122.

[0098] Upon receiving an acknowledgment message from UDM entity 10, NSWOF entity 8 may be configured to send a third registration message (e.g., a Non-Seamless Unified Data Management, Subscriber Data Management "get" message, i.e., a "Nudm_SDM_get operation" message or simply a "get message") to UDM entity 10 during step 123. In one embodiment, the third registration message may include a request for UDM entity 10 to forward NSWOF-specific data to NSWOF entity 8. In response, upon receiving the get message, UDM entity 10 may send the requested NSWOF data to NSWOF entity 8 during step 124. In one embodiment, the NSWOF-specific data may identify which 5GC services (e.g., limited services) UE 2a may be allowed to access after completing the security authentication and registration process described herein.

[0099] Subsequently, during step 125, upon receiving the NSWOF data, NSWOF entity 8 may send a limited service indication message to UE 2a, which allows UE 2a (and its corresponding user) to access a limited range and number of 5GC services provided by 5GC network 6. For example, an exemplary limited service may allow data services but not call and / or short message (SMS) services. Alternatively, another exemplary limited service may allow call services but not data and / or short message (SMS) services. Furthermore, yet another exemplary limited service may allow SMS services but not data and / or call services; these are just a few examples among the types of limited services that can be allowed and / or disallowed.

[0100] Now for reference Figure 5 It describes a simplified block diagram of a network device 500 according to an exemplary embodiment, which includes entities of a 5GC network 6 (e.g., NSWO entity 8, AUSF entity 9, or UDM entity 10) or entities of a non-integrated non-3GPP access network 4 (e.g., APs 3a to 3n of a WLAN).

[0101] For clarity, as described herein, the phrase "network device" refers to an element of a 5GC network 6 or a non-integrated non-3GPP access network 4 (e.g., WLAN) and its corresponding NF, while the phrase "UE device" (or UE) refers to UE 2a to 2n and their corresponding UE functions.

[0102] In one embodiment, network device 500 may be configured to provide one or more network-based operations and features, and to perform related steps within a 5GC network 6 or a non-integrated non-3GPP access network 4. Furthermore, network device 500 may be configured to perform multiple core network functions (NFs). For example, device 500 may be incorporated into one or more network entities 8, 9, and 10 described above and herein.

[0103] In one embodiment, network device 500 may include components for performing one or more innovative NFs, features, and steps. In embodiments, these devices may include combinations of electronic components, such as network interface 501, at least one electronic processor 502, and electronic memory 503. Network interface 501 may include wired and / or wireless transceivers to enable access to other elements, nodes, and / or functions, including base stations, elements 3a to 3n, 8, 9, and 10, the Internet, functions, and / or other elements. Memory 503 may include volatile and / or non-volatile memory containing program code that, when executed by at least one processor 502, provides, among other things, the processes disclosed herein, including, but not limited to, NSWOWF key generation and UE temporary ID generation.

[0104] Now for reference Figure 6 The diagram illustrates a simplified block diagram of user equipment 600, which may include user equipment 2a (or 2b to 2n). User equipment 600 or portions thereof may be implemented in other network devices or elements, including base stations / WLAN APs 3a to 3n, and other network elements.

[0105] In one embodiment, user equipment 600 may include components for performing one or more innovative UE functions, features, and steps. In embodiments, these components may include combinations of electronic elements, such as at least one antenna 601 communicating with an electronic transmitter 602 and an electronic receiver 603. Alternatively, component 600 may include separate transmit and receive antennas (not shown for simplicity). User equipment 600 may also include additional means, such as at least one electronic processor 604, configured to provide and receive communication signals to and from the transmitter and receiver, and to control the functions of the means. Processor 604 may be configured to control the functions of the transmitter and receiver by sending control signals to the transmitter and receiver via electrical leads or wirelessly. Similarly, processor 604 may be configured to control other elements of user equipment 600 by connecting processor 604 via electrical leads or wirelessly to other components, such as a display (not shown for simplicity) or electronic memory 605.

[0106] Processors 502 and 604 may, for example, be embodied in various ways, including electronic circuitry, at least one electronic processing core, one or more microprocessors with digital signal processors, one or more electronic processors without digital signal processors, one or more coprocessors, one or more multi-core processors, one or more electronic controllers, electronic processing circuitry, one or more computers, various other electronic processing elements, including integrated circuits (e.g., application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), and / or the like), or some combination thereof. Therefore, although in Figure 5 and6 The processor is shown as a single processor, but in some example embodiments, processors 502 and 604 may include multiple electronic processors or processing cores.

[0107] Continuing, again regarding user equipment 600, in one embodiment, user equipment 600 may be configured to operate using one or more air interface standards, communication protocols, modulation types, access types, and / or the like. Signals transmitted and received by processor 604 may include signaling information according to the air interface standard of the applicable cellular system, and / or any number of different wired or wireless network technologies, including but not limited to Wi-Fi, WLAN technologies such as IEEE 802.11, 802.16, 802.3, ADSL, DOCSIS, and / or the like. Furthermore, these signals may include voice data, user-generated data, user-requested data, and / or the like. One or more storage elements 605 may be used to store information such as NSWOWF keys, temporary UE identifiers, and UE context information, and interact with processor 604 as is known in the art.

[0108] For example, the user equipment 600 and / or its cellular modem may be able to operate according to various communication protocols, such as first-generation (1G) communication protocols, second-generation (2G or 2.5G) communication protocols, third-generation (3G) communication protocols, fourth-generation (4G) communication protocols, fifth-generation (5G) communication protocols, and IP Multimedia Subsystem (IMS) communication protocols (e.g., Session Initiation Protocol (SIP) and / or the like). For example, the user equipment 600 may be able to operate according to 2G wireless communication protocols IS-136, Time Division Multiple Access (TDMA), Global System for Mobile Communications (GSM), IS-95, Code Division Multiple Access (CDMA), and / or the like. Furthermore, for example, the user equipment 600 may be able to operate according to 2.5G wireless communication protocols General Packet Radio Service (GPRS), Enhanced Data GSM Environment (EDGE), and / or the like. Furthermore, for example, device 600 may be able to operate according to 3G wireless communication protocols, such as Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), Wideband Code Division Multiple Access (WCDMA), Time Division Synchronous Code Division Multiple Access (TD-SCDMA) and / or the like.

[0109] User equipment 600 may also be able to operate according to (i) 3.9G wireless communication protocols, such as Long Term Evolution (LTE), Evolved Universal Terrestrial Radio Access Network (E-UTRAN) and / or similar, and (ii) 4G wireless communication protocols, such as LTE Advanced, 5G and / or similar, and similar wireless communication protocols that may be developed subsequently.

[0110] It should be understood that processors 502 and 604 may include additional means, such as circuitry for implementing the audio / video and logic functions of devices 500 and 600. As a non-limiting example, processor 604 may include a digital signal processor device, a microprocessor device, an analog-to-digital converter, a digital-to-analog converter, and / or the like. The control and signal processing functions of user device 600 may be distributed among these devices according to their respective capabilities.

[0111] Typically, processors 502 and 604 can retrieve and access software or firmware stored as electronic instructions to cause their respective devices 500 and 600 to perform at least certain functions, features, and / or steps.

[0112] For example, processors 502 and 604 may include components for performing authentication and registration processes, such as generating NSWOF keys and temporary UE identifiers through one or more cryptographic KDF processes, secure handshakes, etc.

[0113] Furthermore, the processor 604 can be configured to complete a connection process that allows the user device 600 to transmit and receive network content, such as location-based content, according to protocols such as Wireless Application Protocol (WAP), Hypertext Transfer Protocol (HTTP), and / or similar protocols.

[0114] It should be understood that Figure 5 and 6 Each of the devices 500, 600 shown includes components for performing one or more innovative functions, features, and steps, including but not limited to the UE functions, features, and steps or network-side functions (e.g., NF) features and steps set forth in the following claims. In embodiments, these devices may include combinations of electronic components, such as one or more electronic transmitters, receivers, electronic comparator circuits, electronic input / output (I / O) circuits, electronic conductors (e.g., electronic buses), at least one electronic processor 502, 604, and at least one electronic memory 503, 605 containing stored electronic instructions (i.e., computer program code), wherein each at least one processor 502, 604, in conjunction with each at least one memory 503, 605 and each computer program code, is executed and / or arranged to cause each device 500, 600 to perform at least the functions, features, and steps described herein, including but not limited to… Figures 1 to 6 The functions, features, and steps are shown.

[0115] While the foregoing description and related figures depict certain exemplary embodiments in the context of combinations of certain exemplary elements, functions, or steps, it should be understood that alternative embodiments may provide different combinations of elements, functions, and / or steps without departing from the scope of the appended claims. In this regard, for example, combinations of elements, functions, and / or steps different from those explicitly described above are also contemplated, as may be set forth in some of the appended claims. Although specific terms may have been used herein, they are used only in a general and descriptive sense and not for limiting purposes.

[0116] The following claims language is incorporated herein by reference in an expanded form, i.e., a hierarchical structure from widest to narrowest, where each possible combination indicated by multiple dependent claims is described as a unique, independent embodiment.

[0117] The benefits, other advantages, and solutions to challenges have been described above with reference to specific embodiments of the invention. However, the benefits, advantages, solutions to challenges, and any elements, functions, and / or steps that may lead to or produce such benefits, advantages, or solutions, or that make such benefits, advantages, or solutions more apparent, should not be construed as key, essential, or fundamental features or elements of any or all claims.

Claims

1. A method for providing fifth-generation core network (5GC) services through a non-3GPP access network, comprising: The Non-Seamless Radio Offload (NSWOF) key is generated by the User Equipment (UE) after completing the primary authentication. as well as An initialization message including the generated NSWOF key is sent directly to the first network function (NF) entity of the 5GC network to establish a secure communication channel directly between the UE and the first NF entity using the NSWOF key.

2. The method of claim 1, wherein forming the secure communication channel further includes generating a temporary UE identifier by the UE or receiving the temporary UE identifier.

3. The method of claim 1, wherein generating the NSWOF key includes completing a first encryption process.

4. The method of claim 3, wherein completing the first encryption process further includes receiving a CONSTANT value or a RAND value, an FC value, and an MSK value.

5. The method of claim 1, wherein generating the NSWOF key includes completing a second encryption process.

6. The method of claim 5, wherein completing the second encryption process further includes receiving the temporary UE identifier, FC value, and MSK value.

7. The method of claim 2, wherein generating the temporary UE identifier further includes completing a third encryption process.

8. The method of claim 7, wherein completing the third encryption process further includes receiving a CONSTANT value or a RAND value, an FC value, and an MSK value.

9. The method of claim 1, further comprising: The UE generates an additional initialization message including the generated temporary UE identifier; as well as The additional initialization message is sent to the first NF entity within the established secure communication channel.

10. The method of claim 1, wherein the formed secure communication channel comprises an IP sec tunnel.

11. The method of claim 1, further comprising performing the primary authentication by pre-configuring the fully qualified domain name address of the first NF entity of the 5GC network to the UE.

12. A method for providing fifth-generation core network (5GC) services via a non-integrated, non-3GPP access network, comprising: An electronic indicator is generated by the first network function (NF) entity of the 5GC network and sent to the second NF entity of the 5GC network, the indicator indicating that a user equipment (UE) is allowed to register via non-integrated non-3GPP access; The first NF entity sends an indicator to the UE, indicating that registration with a non-integrated non-3GPP network is permitted. The first NF entity directly receives from the UE an Internet key exchange security association initialization message ("initialization message") including a non-seamless wireless offloading (NSWOF) key; and A secure communication channel is directly established between the UE and the first NF entity.

13. The method of claim 12, wherein the secure communication channel includes an IP sec tunnel.

14. The method of claim 12, further comprising: The first NF entity compares the received temporary UE identifier with the stored temporary UE identifier; as well as When the comparison results match, the secure communication channel is directly established between the UE and the first NF entity.

15. The method of claim 12, further comprising authenticating the first communication session before the first NF entity completes the comparison process to continue the UE's registration with the 5GC network.

16. The method of claim 12, further comprising sending a registration message from the first NF entity to a third NF entity of the 5GC network, the registration message including a non-access stratum user data management UE configuration management value, a previously generated subscription permanent identifier (SUPI) value, and an NSWOF address.

17. The method of claim 12, further comprising sending a registration message from the first NF entity to the third NF entity, wherein the registration message includes a request from the third NF entity to forward NSWOWF specific data to the first NF entity.

18. The method of claim 17, wherein the requested NSWOF data includes an identifier of an authorized 5GC service.

19. The method of claim 18, wherein the permitted 5GC service includes a service selected from data service, call service, or short message service.

20. The method of claim 12, further comprising sending a limited service indication message from the first NF entity to the UE, the message allowing the UE to access a limited range and number of 5GC services provided by the 5GC network.

21. A method for providing fifth-generation core network (5GC) services via a non-integrated, non-3GPP access network, comprising: The first network function (NF) entity of the 5GC network generates the non-seamless radio offloading network function (NSWOF) key and temporary UE identifier; as well as The first NF entity sends the generated NSWOWF key, the temporary UE identifier, and the subscription permanent identifier (SUPI) to the second NF entity of the 5GC network.

22. The method of claim 21, wherein the generation of the NSWOF key includes performing a first encryption process.

23. The method of claim 22, wherein completing the first encryption process includes receiving a randomly generated (RAND) value or a CONSTANT value, a fixed constant (FC) value, and a master session key (MSK) value.

24. The method of claim 21, wherein the generation of the NSWOF key includes performing a second encryption process.

25. The method of claim 24, wherein completing the second encryption process includes receiving the temporary UE identifier value, FC value, and MSK value.

26. The method of claim 21, wherein the generation of the temporary UE identifier includes completing a third encryption process.

27. The method of claim 26, wherein completing the third encryption process includes receiving a CONSTANT value or a RAND value, an FC value, and an MSK value.

28. An apparatus for providing core fifth-generation (5GC) services via a non-integrated non-3GPP access network, the apparatus comprising: Components for generating an Internet Key Exchange Security Association initialization message ("initialization message"), the initialization message including a generated Non-Seamless Radio Offload Network Function (NSWOF) key; and A component for sending the initialization message directly to a first network function (NF) entity of the 5GC network to establish a secure communication channel directly between the device and the first NF entity.

29. The apparatus of claim 28, wherein the apparatus includes user equipment.

30. The apparatus of claim 28, wherein the formed secure communication channel comprises an IP sec tunnel.

31. The apparatus of claim 28, further comprising a component for pre-configuring the fully qualified domain name address of the first NF entity of the 5GC network.

32. An apparatus for providing 5GC services via a non-integrated, non-3GPP access network in a core fifth-generation (5GC) network, the apparatus comprising: A component for generating and sending a first indicator to a second network function (NF) entity of the 5GC network, the first indicator indicating that a user equipment (UE) is allowed to register via the non-integrated non-3GPP access network; A component for sending a second indicator to the UE, indicating permission to register with a non-integrated, non-3GPP network; Components for directly receiving an Internet Key Exchange Security Association initialization message ("initialization message") from the UE, the initialization message including a Non-Seamless Radio Offload Network Function (NSWOF) key; and A component for directly establishing a secure communication channel between the UE and the device.

33. The apparatus of claim 32, wherein the apparatus includes the NSWOF entity of the 5GC network.

34. The apparatus of claim 32, wherein the secure communication channel comprises an IP sec tunnel.

35. An apparatus for providing 5GC services via a non-integrated, non-3GPP access network in a core fifth-generation (5GC) network, the apparatus comprising: Components used to generate Non-Seamless Radio Offload Network Function (NSWOF) keys and temporary UE identifiers; as well as A component for sending the generated NSWOWF key, the temporary UE identifier, and the subscription permanent identifier (SUPI) to the first network function (NF) entity of the 5GC network.

36. The apparatus of claim 35, wherein the apparatus includes an Authentication Server Function (AUSF) entity for the 5GC network.