Dual registration of user equipment

By assigning different access network identifiers to user equipment to generate unique encryption keys, the security vulnerability caused by key reuse in multi-access network environments is solved, and communication security and reliability are improved.

CN121128205APending Publication Date: 2025-12-12NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480032650.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-05-15
Filing Date
2024-05-08
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In multi-access network environments, the registration process of user equipment in existing technologies has security vulnerabilities caused by the reuse of keys. In particular, when the same encryption key is shared between different access networks, it is susceptible to replay attacks, which affect communication security.

Method used

By assigning different access network identifiers (AN_ID) to user equipment, a unique encryption key based on the access network identifier is generated during the registration process, ensuring that each access network uses a unique encryption key and preventing key reuse.

Benefits of technology

It improves the security of user equipment in multi-access network environments, prevents replay attacks, ensures the encryption and integrity of communication, and enhances network security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121128205A_ABST
    Figure CN121128205A_ABST
Patent Text Reader

Abstract

According to one example aspect of the present disclosure, there is provided an apparatus configured to: receive a first access network identifier from a first access network, and receive a second access network identifier from a second access network; establishing a radio resource control (RRC) connection with the first access network and the second access network; and responsive to a first encrypted challenge from the core network node via the first access network based on the first access network identifier, and responsive to a second encrypted challenge from the core network node via the second access network based on the second access network identifier.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to registering a communication network user equipment over more than one access. BACKGROUND

[0002] A communication network can be seen as a facility that enables communication sessions between two or more entities, such as communication devices, base stations and / or other nodes, by providing carriers between the various entities involved in the communication path.

[0003] A communication system can be a wireless communication system. Examples of wireless systems include public land mobile networks, PLMN, operating based on a radio standard, such as the standards provided by the Third Generation Partnership Project, 3GPP, satellite based communication systems and different wireless local area networks, e.g. wireless local area networks, WLAN. Wireless systems can typically be divided into cells and are thus often referred to as cellular systems.

[0004] Communication systems and related devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are allowed to do and how that should be implemented. Communication protocols and / or parameters used for the connections are typically also defined. Examples of standards are the so-called 5G and Long Term Evolution, LTE, standards. SUMMARY

[0005] According to some aspects, the subject matter of the independent claims is provided. Some embodiments are defined in the dependent claims. The independent claims define the scope of the invention for which various embodiments are claimed. Embodiments, examples and features described in this specification that are not within the scope of the independent claims are to be interpreted as examples useful for understanding the invention various embodiments.

[0006] According to a first aspect of the disclosure, there is provided an apparatus comprising at least one processing core and at least one memory storing instructions that, when executed by the at least one processing core, cause the apparatus at least to: receive a first access network identifier from a first access network and a second access network identifier from a second access network; establish a radio resource control, RRC, connection with the first access network and the second access network; and respond to a first cryptographic challenge from a core network node via the first access network based on the first access network identifier and to a second cryptographic challenge from the core network node via the second access network based on the second access network identifier.

[0007] According to a second aspect of the disclosure, there is provided an apparatus comprising at least one processing core and at least one memory storing instructions that, when executed by the at least one processing core, cause the apparatus at least to: transmit a first access network identifier in a coverage area of a cell controlled by the apparatus; establish a radio resource control, RRC, connection with a user equipment; and transmit a registration request to a core network node regarding the user equipment, the registration request comprising the first access network identifier.

[0008] According to a third aspect of the disclosure, there is provided an apparatus comprising at least one processing core and at least one memory storing instructions that, when executed by the at least one processing core, cause the apparatus at least to: receive a first authentication request regarding a user equipment, the first authentication request comprising a first access network identifier, and receive a second authentication request regarding the user equipment, the second authentication request comprising a second access network identifier; based on the first access network identifier and issue a first encryption challenge in response to the first authentication request, and issue a second encryption challenge in response to the second authentication request based on the second access network identifier; generate a first set of encryption keys based at least in part on the first access network identifier for use between the user equipment and a first access network identified by the first access network identifier; and generate a second set of encryption keys based at least in part on the second access network identifier for use between the user equipment and a second access network identified by the second access network identifier, wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

[0009] According to a fourth aspect of the disclosure, there is provided an apparatus comprising at least one processing core and at least one memory storing instructions that, when executed by the at least one processing core, cause the apparatus at least to: receive a registration request from an access network regarding a user equipment connected to the access network, the registration request comprising an access network identifier identifying the access network; and in response to the registration request, transmit an authentication request to a core network node regarding the user equipment, the authentication request comprising the access network identifier.

[0010] According to a fifth aspect of the disclosure, there is provided a method comprising, in an apparatus: receiving a first access network identifier from a first access network and a second access network identifier from a second access network; establishing a radio resource control, RRC, connection with the first access network and the second access network; and responding to a first encryption challenge from a core network node via the first access network based on the first access network identifier, and responding to a second encryption challenge from the core network node via the second access network based on the second access network identifier.

[0011] According to a sixth aspect of the disclosure, there is provided a method comprising: transmitting a first access network identifier in a coverage area of a cell controlled by an apparatus; establishing a radio resource control, RRC, connection with a user equipment; and transmitting a registration request to a core network node regarding the user equipment, the registration request comprising the first access network identifier.

[0012] According to a seventh aspect of the disclosure, there is provided a method comprising: receiving a first authentication request regarding a user equipment, the first authentication request comprising a first access network identifier, and receiving a second authentication request regarding the user equipment, the second authentication request comprising a second access network identifier; issuing a first encryption challenge based on the first access network identifier and in response to the first authentication request, and issuing a second encryption challenge based on the second access network identifier and in response to the second authentication request; generating a first set of encryption keys based at least in part on the first access network identifier for use by the user equipment with a first access network identified by the first access network identifier; and generating a second set of encryption keys based at least in part on the second access network identifier for use by the user equipment with a second access network identified by the second access network identifier, wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

[0013] According to an eighth aspect of the disclosure, there is provided a method comprising: receiving a registration request from an access network regarding a user equipment connected to the access network, the registration request comprising an access network identifier identifying the access network; and in response to the registration request, transmitting an authentication request to a core network node regarding the user equipment, the authentication request comprising the access network identifier.

[0014] According to a ninth aspect of the disclosure, there is provided an apparatus comprising means for: in the apparatus, receiving a first access network identifier from a first access network and a second access network identifier from a second access network; establishing a radio resource control, RRC, connection with the first access network and the second access network; and responding to a first encryption challenge from a core network node via the first access network based on the first access network identifier, and responding to a second encryption challenge from the core network node via the second access network based on the second access network identifier.

[0015] According to a tenth aspect of the disclosure, there is provided an apparatus comprising means for: transmitting a first access network identifier in a coverage area of a cell controlled by the apparatus; establishing a radio resource control, RRC, connection with a user equipment; and transmitting a registration request to a core network node regarding the user equipment, the registration request comprising the first access network identifier.

[0016] According to an eleventh aspect of the disclosure, there is provided an apparatus comprising means for: receiving a first authentication request for a user equipment, the first authentication request comprising a first access network identifier, and receiving a second authentication request for the user equipment, the second authentication request comprising a second access network identifier; issuing a first encryption challenge based on the first access network identifier and in response to the first authentication request, and issuing a second encryption challenge based on the second access network identifier and in response to the second authentication request; generating a first set of encryption keys based at least partly on the first access network identifier for use between the user equipment and a first access network identified by the first access network identifier, and generating a second set of encryption keys based at least partly on the second access network identifier for use between the user equipment and a second access network identified by the second access network identifier, wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

[0017] According to a twelfth aspect of the disclosure, there is provided an apparatus comprising means for: receiving, from an access network, a registration request for a user equipment connected to the access network, the registration request comprising an access network identifier identifying the access network; and in response to the registration request, sending an authentication request for the user equipment to a core network node, the authentication request comprising the access network identifier.

[0018] According to a thirteenth aspect of the disclosure, there is provided a computer- readable medium having stored thereon a computer-readable instruction set that, when executed by an apparatus, causes the apparatus to perform at least the following: receiving a first access network identifier from a first access network and a second access network identifier from a second access network; establishing a radio resource control, RRC, connection with the first access network and the second access network; and responding to a first encryption challenge from a core network node via the first access network based on the first access network identifier, and responding to a second encryption challenge from the core network node via the second access network based on the second access network identifier.

[0019] According to a fourteenth aspect of the disclosure, there is provided a computer- readable medium having stored thereon a computer-readable instruction set that, when executed by an apparatus, causes the apparatus to perform at least the following: transmitting a first access network identifier in a coverage area of a cell controlled by the apparatus; establishing a radio resource control, RRC, connection with a user equipment; and sending a registration request for the user equipment to a core network node, the registration request comprising the first access network identifier.

[0020] According to a fifteenth aspect of the disclosure, there is provided a computer- readable medium having stored thereon a set of computer readable instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receive a first authentication request for a user equipment, the first authentication request comprising a first access network identifier, and receive a second authentication request for the user equipment, the second authentication request comprising a second access network identifier; issue a first encryption challenge based on the first access network identifier and in response to the first authentication request, and issue a second encryption challenge based on the second access network identifier and in response to the second authentication request; generate a first set of encryption keys based at least in part on the first access network identifier for use between the user equipment and a first access network identified by the first access network identifier, and generate a second set of encryption keys based at least in part on the second access network identifier for use between the user equipment and a second access network identified by the second access network identifier, wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

[0021] According to a sixteenth aspect of the disclosure, there is provided a computer- readable medium having stored thereon a set of computer readable instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receive, from an access network, a registration request for a user equipment connected to the access network, the registration request comprising an access network identifier identifying the access network; and in response to the registration request, send, to a core network node, an authentication request for the user equipment, the authentication request comprising the access network identifier. BRIEF DESCRIPTION OF DRAWINGS

[0022] Figure 1 FIGURE 1 illustrates an example system in accordance with at least some embodiments of the application;

[0023] Figure 2 is a signaling diagram of an example procedure;

[0024] Figure 3 FIGURE 1 illustrates an example system in accordance with at least some embodiments of the application;

[0025] Figure 4 FIGURE 1 illustrates an example system in accordance with at least some embodiments of the application; and

[0026] Figure 5 is a flow diagram of a method in accordance with at least some embodiments of the application. DETAILED DESCRIPTION

[0027] Described herein is a procedure enabling a user device, such as a user equipment, to register via two or more access networks such that these registrations are active at the same time or sequentially. Furthermore, the user device is provided with different encryption keys to use via each of the two or more access networks to avoid re-use of keys on multiple access networks and thereby enhance security. This is achieved using an access network identifier in the authentication and / or key generation procedure. The access network identifier can be a cell identifier or an identifier of the entire access network comprising multiple cells.

[0028] Figure 1 An example system is illustrated in accordance with at least some embodiments. In the following, different exemplary embodiments will be described using as an example of an access architecture to which the embodiments can be applied a radio access architecture based on Long Term Evolution Advanced (LTE-A) or New Radio (NR) (also known as Fifth Generation (5G)), without limiting the embodiments to such an architecture. Some examples of other options of suitable systems are Universal Mobile Telecommunication System (UMTS) radio access network (UTRAN or E-UTRAN), Long Term Evolution (LTE, same as E-UTRA), Wireless Local Area Network (WLAN or WiFi), Worldwide Interoperability for Microwave Access (WiMAX), Bluetooth®, Personal Communications Service (PCS), ZigBee®, Wideband Code Division Multiple Access (WCDMA), systems using Ultra- Wideband (UWB) technology, sensor networks, Mobile Ad hoc Networking (MANET) and Internet Protocol Multimedia Subsystem (IMS) or any combination thereof.

[0029] Figure 1 An example of a simplified system architecture is depicted, showing only some elements and functional entities, all being logical units whose implementation can differ from what is shown. Figure 1 The connections shown are logical connections; actual physical connections can be different. The system can also comprise other functions and structures than those shown. Figure 1 The connections shown are logical connections; actual physical connections can be different. The system can also comprise other functions and structures than those shown.

[0030] Figure 1 The example shows a part of a radio access network, which is an example of an access network. As an alternative to a radio access network RAN, the access network can be based on wired connections. Figure 1User equipments 100 and 102 are shown, which are configured to make a wireless connection on one or more communication channels in a cell with an access node providing the cell, such as (e / g)NodeB 104, 105. The physical link from the user equipment to the (e / g)NodeB is called uplink or reverse link, while the physical link from the (e / g)NodeB to the user equipment is called downlink or forward link. It should be appreciated that the (e / g)NodeB or its functionalities can be implemented using any node, host, server or access point etc. entity adapted for such a use. The communication system typically comprises more than one (e / g)NodeB, in which case the (e / g)NodeBs can also be configured to communicate with one another over links designed for the purpose, which can be wired or wireless. These links can be used for signalling purposes. The (e / g)NodeB is a computing device configured to control the radio resources of one or more cells it controls. The NodeB can also be referred to as a base station, access point or an access node. The (e / g)NodeB comprises or is coupled to a transceiver. From the transceiver of the (e / g)NodeB, there is provided a connection to an antenna unit, which establishes the bi-directional radio link to the user equipment. The (e / g)NodeB is further connected to a core network 110. Depending on the system, the counterpart on the CN side can be a serving gateway (S-GW, for routing and forwarding user data packets), a packet data network gateway (P-GW) for providing connectivity to external packet data networks for a user equipment (UE), or a mobility management entity (MME). In detail, the core network can comprise one or more access and mobility management function AMF, one or more authentication server function AUSF and unified data management UDM node. The UDM is configured to issue authentication challenges and derive encryption keys in the network. Multiple core networks can be connected to each other through a gateway to enable data exchange.

[0031] The user equipment (also known as user equipment UE) is the device to which resources on the air interface are allocated and assigned, and thus any features of the user equipment described herein can be implemented with a corresponding device.

[0032] The user equipment can comprise a portable computing device, such as a wireless mobile communication device operating with or without a subscriber identification module SIM, including, but not limited to, the following types of devices: a mobile station, a mobile phone, a smartphone, a personal digital assistant, a device using a wireless modem, a laptop, a tablet, and a connected car connectivity module.

[0033] 5G mobile communications support a wide range of use cases and related applications, including video streaming, augmented reality, different ways of sharing data, and various forms of machine type applications. 5G is expected to have multiple radio interfaces, i.e. below 6GHz, cmWave and mmWave, and can also be integrated with existing legacy radio access technologies, such as LTE. At least in the early phase, the integration with LTE can be implemented as one system, where macro coverage is provided by LTE and 5G radio interface access comes from small cells by aggregating to LTE. In other words, 5G plans to support inter-RAT operability, such as LTE-5G, and inter-RI operability, i.e. inter-radio interface operability, such as below 6GHz-cmWave, below 6GHz-cmWave-mmWave. One of the concepts considered for use in 5G networks is network slicing, where multiple independent and dedicated virtual sub-networks (network instances) can be created within the same infrastructure to run services with different requirements on latency, reliability, throughput, and mobility.

[0034] 5G can also utilize satellite communication to enhance or complement the coverage of 5G services, for example by providing backhauling. Possible use cases are providing service continuity for machine-to-machine (M2M) or Internet of Things (IoT) devices or passengers on board of vehicles, or ensuring service availability for critical communications, and future railway / maritime / aeronautical communications. When satellite communication is used, a satellite 106 or a corresponding constellation of satellites acts as an access network.

[0035] Figure 1 Of interest is that the UE 102 is connected with two access nodes 104, 105. These can be included in different access networks, and the UE 102 can have a radio resource control, RRC, state towards both access networks simultaneously. For example, the RRC state can be connected or inactive, or the UE 102 can be in RRC connected state with one of the access networks and in RRC inactive state with the other of the access networks. In RRC connected, an active connection is ongoing with the UE, including storing the context of the UE. Likewise, in RRC inactive state, the context of the UE is stored in both the UE and the access network. This context stores access layer information related to the UE, which can be used to maintain or restore the connection with the UE, such as one or more of UE capability information, UE status information, security information, and identification of UE related logical S1 connection.

[0036] Simultaneous registration via two access networks can enable a UE to simultaneously access services of two networks, such as a PLMN or SNPN. Different networks can provide different sets of services. Moreover, simultaneous registration via two access networks can direct, split, and / or handover data access across the two access networks. This is useful in improving throughput and in hiding a portion of traffic of a first access network by routing via another access network. Furthermore, a railway mobile communication system can benefit from dual simultaneous registration via two or more access networks. In some cases, by having two access networks participate in positioning, a location of the UE can be determined more accurately. For example, data collected by the two access networks can be provided to a positioning algorithm, or more simply, location estimates independently acquired by the two access networks can be averaged to obtain an average location estimate, which can be more accurate than a single estimate.

[0037] This document describes mechanisms for enabling a UE to be connected through at least two access networks in, for example, the following configurations. First, a UE can register to a 5G core network, a PLMN, or a SNPN via two New Radio, NR, access networks. NR is another term for 5G in the 3GPP context. Second, a UE can register to a 5G core network via a 5G access network while being attached to an Evolved Packet Core (EPC) network via a LTE access network. Third, a UE can attach to an EPC network via one LTE access network while registering to a 5G core network via two NR access networks. Furthermore, a UE can connect to a 5G core network via a satellite access network while connecting to the same 5G core network via a terrestrial NR access network. Moreover, a UE can also simultaneously connect to a PLMN and a standalone non-public network, SNPN, using different access networks. For example, the PLMN and the SNPN each can have its own access network, which can be based on the same radio access technology, RAT, such as 5G, or on different RATs, such as LTE and 5G. Still further, a UE can register in two standalone PLMNs or SNPNs via two different access networks. Thus, in general, a UE can simultaneously connect to one or two core networks via two access networks. The two access networks can have the same RAT or be based on different RATs. In each of the above cases, a UE can use a single subscription when registering via the two access networks.

[0038] When registering via a first access network, the UE can undergo an authentication procedure to ensure the identity of the UE or its subscription. The UE can also perform a key generation procedure with the network to establish one or more encryption keys to protect communications. Authentication can be based on a cryptographic challenge, where a core network node such as a UDM issues a challenge and the UE responds to the challenge based on secret information it has. The core network node such as the UDM can then determine whether the UE possesses the correct secret information based on determining whether the response it receives from the UE is correct. One particular type of cryptographic challenge is an authentication and key agreement, AKA, challenge.

[0039] In the case where network selection reuses authentication performed on a first access network in both access networks, when the UE registers with a second access network in the two access networks, a security challenge is generated. In this case, the UE will eventually use the same encryption key on both access networks through which it registers and maintains RRC state. This credential sharing between different access networks can lead to security vulnerabilities. A malicious actor can attempt to perform a replay attack on the air interface based on the shared key, which can lead to data compromise.

[0040] To prevent this credential sharing, a dual registration procedure is described herein, where each access network is assigned a different access network identifier, AN ID. The AN ID can be assigned by, for example, an AMF or an operations, administration, and maintenance, OAM. In the case where the OAM assigns the AN ID, the AMF would be aware of it. The AMF can be allocated a range of AN IDs that identify access networks controlled by the respective AMF. The access network can include the AN ID in system information broadcast in cells controlled by the access network to expose the AN ID to the UE before the UE attaches to the access network. Alternatively, the AN ID can be conveyed to the UE in an initial random access procedure. The access network can also provide the UE with other identifiers such as a PLMN identity, a tracking area identifier, a cell identifier, and a service area identifier, which are different from the access network identifier.

[0041] When processing an initial registration request related to a UE, the access network includes its AN_ID in the registration request it sends to its core network (e.g., to the AMF node in the core network). The AMF may also include the AN_ID in the authentication request it sends to the UDM in the UE's home network. For example, the AMF may concatenate the AN_ID with the identifier SN_ID of the serving network of the network in which the AMF is included. When the AMF is in an SNPN, the AMF may concatenate the AN_ID with the non-public network identifier NID of the SNPN. The concatenated identifier can be considered as the serving network identifier SNN. Subsequently, the encryption challenge and encryption key generation processes used to authenticate the UE will be based on the AN_ID and the serving network identifier. When the concatenated SNN is used, the encryption key generation process is based on the SNN. Therefore, different encryption keys will be generated for the UE through different access networks it is connected to, because these access networks have different AN_IDs even if the subscriber credentials used by the UE are the same. An example of this process is... Figure 2 The diagram in the middle is shown.

[0042] Figure 2 This is a signaling diagram of an example procedure. The vertical axis, from left to right, corresponds to the User Equipment (UE), First Radio Access Network (RAN2), Second Radio Access Network (RAN2), AMF, and UDM. Figure 2 Prior to the process shown, RAN1 and RAN2 have been assigned their access network identifiers AN1_ID and AN2_ID. Time progresses from top to bottom.

[0043] In phases 410 and 420, RAN1 and RAN2 respectively transmit their system information, which includes their respective access network identifiers AN1_ID and AN2_ID. These transmissions may be broadcast radio transmissions, meaning they are not sent to any specific receiver.

[0044] In phase 430, an RRC connection is established between the UE and RAN1. This can be initiated, for example, using a random access procedure. Phase 440 includes the UE sending a registration request to RAN1. The registration request may include a subscription hidden identifier (SUCI), which may include an encrypted version of the subscription permanent identifier (SUPI) of the active subscription in the UE. In phase 450, RAN1 sends a registration request to the AMF, which includes the SUCI received in RAN1 in phase 440 and RAN1's ​​access network identifier (AN1_ID). Alternatively, if the AMF is configured to determine the AN1_ID based on signaling received in phase 450, RAN1 may omit the AN1_ID.

[0045] The AMF responds to phase 450 by sending an authentication request to the UDM (e.g., the UDM in the UE's home network) in phase 460. Phase 460 can proceed via AMF. The authentication request includes SUCI, SSN, and AN1_ID. Finally, the UDM responds to the authentication request in phase 470 by generating an encrypted challenge based on the subscription-related secret information, SSN, and AN1_ID. For example, the challenge could be a request to hash the subscription-related secret information, SSN, and AN1_ID together, and the correct response to the challenge is the requested hash value. Phase 480 represents the exchange of encrypted challenge responses leading to the UE's authentication. Furthermore, the encryption key can be generated as a result of the challenge-response pair or via a separate key generation process. After key generation, the UE can use RAN1 and register there via RRC status (such as RRC connected or RRC inactive as described above). The encryption key can include an encryption key, an integrity protection key, and / or an intermediate key. The intermediate key (such as K...) SEAF or K AMF It is derived from another encryption key and used to derive other encryption keys, as described in Clause 6.2 of 3GPP Technical Specification TS 33.501 V18.1.0.

[0046] Subsequently, without releasing the registration to RAN1, the UE establishes an RRC connection with RAN2 in phase 490. This can be a similar process to phase 430 of RAN1. Similar to phase 440, the UE sends a registration request to RAN2 in phase 4100, which includes the SUCI. Since the subscription is the same, the SUPI encrypted in the SUCI is the same as in phase 440. In phase 4110, RAN2 sends a registration request to AMF, which includes the SUCI from phase 4100 and RAN2's access network identifier AN2_ID. Alternatively, if AMF is configured to determine AN2_ID based on the signaling it receives in phase 4110, RAN2 can omit AN2_ID. In response, AMF sends an authentication request to UDM in phase 4120, which includes the SUCI, SSN, and AN2_ID. UDM responds in phase 4130 by generating an encrypted challenge based on the subscription-related secret information SSN and AN2_ID. Because the access network identifier differs from the identifier used in phase 470, this challenge is different from the challenge generated for RAN1. Subsequently, an encryption challenge response and key generation are performed in phase 4140. After phase 4140, the UE registers with the core network via RAN1 and RAN1, using different encryption keys to register data through these access networks. Key generation is performed in either the UE or the UDM, or in other core network nodes responsible for key generation and / or authentication.

[0047] althoughFigure 2 The process of using AN1_ID and AN2_ID is described, but in other embodiments, instead of using separate access network identifiers, the Cell_ID of the cell to which the UE is attached is used. The Cell_ID is expected to differ between cells in different access networks, resulting in different encryption challenges and key derivations, which are therefore based on the corresponding Cell_ID to which the UE is connected.

[0048] Figure 3 Example apparatuses capable of supporting at least some embodiments of the present invention are illustrated. The illustrated device is 300, which may include, for example, user equipment, or, in applicable portions, fixed network nodes such as access nodes, base stations, or core network nodes such as AMFs or UDMs. Device 300 includes a processor 310, which may include, for example, a single-core or multi-core processor, wherein a single-core processor includes one processing core, and a multi-core processor includes more than one processing core. Processor 310 typically includes a control device. Processor 310 may include more than one processor. When processor 310 includes more than one processor, device 300 may be a distributed device, wherein processing of tasks occurs in more than one physical unit. Processor 310 may be a control device. For example, the processing core may include, for example, a Cortex-A8 processing core manufactured by ARM Holdings or a Zen processing core designed by Advanced Micro Devices Corporation. Processor 310 may include at least one Qualcomm Snapdragon and / or Intel Atom processor. Processor 310 may include at least one application-specific integrated circuit (ASIC). Processor 310 may include at least one field-programmable gate array (FPGA). Processor 310 may be a component for performing method steps in device 300, such as receiving, building, responding, exporting, adopting, maintaining, executing, sending, including, publishing, and generating. Processor 310 may be configured, at least in part, by computer instructions to perform actions.

[0049] A processor may include, or be configured as, one or more circuit systems configured to perform stages of the methods according to embodiments described herein. As used herein, the term “circuit system” may refer to one or more or all of the following: (a) a purely hardware circuit implementation, such as an implementation solely in analog and / or digital circuit systems; and (b) a combination of hardware circuitry and software, such as, where applicable: (i) a combination of (multiple) analog and / or digital hardware circuitry with software / firmware; and (ii) any portion of (multiple) hardware processors having software (including (multiple) digital signal processors), software, and (multiple) memories that work together to enable a device such as a user equipment or network node to perform various functions; and (c) (multiple) hardware circuitry and / or (multiple) processors, such as (multiple) microprocessors or portions thereof, which require software (e.g., firmware) to operate, but may be absent when the software is not required to operate.

[0050] This definition of "circuit system" applies to all uses of the term in this application, including in any claim. As another example, as used herein, the term "circuit system" also covers implementations of hardware circuitry or processors (or processors) or portions thereof, and their accompanying software and / or firmware. For instance, if applicable to a particular claim element, the term "circuit system" also covers baseband integrated circuits or processor integrated circuits for mobile devices, or similar integrated circuits in servers, cellular network devices, or other computing or network devices.

[0051] Device 300 may include memory 320. Memory 320 may include random access memory and / or permanent memory. Memory 320 may include at least one RAM chip. Memory 320 may be a computer-readable medium. Memory 320 may include, for example, solid-state, magnetic, optical, and / or holographic memory. Memory 320 may be at least partially accessible by processor 310. Memory 320 may be at least partially included in processor 310. Memory 320 may be a component for storing information. Memory 320 may include computer instructions configured to be executed by processor 310. When computer instructions configured to cause processor 310 to perform certain actions are stored in memory 320, and device 300 is configured as a whole to run using computer instructions from memory 320 under the guidance of processor 310, processor 310 and / or at least one of its processing cores may be considered to be configured to perform some of the aforementioned actions. Memory 320 may be at least partially included in processor 310. Memory 320 may be at least partially located outside device 300, but device 300 may access the memory. The memory 320 can be transient or non-transient. The term “non-transient” as used herein refers to a limitation on the medium itself (i.e., tangible, not signaling), rather than a limitation on the persistence of data storage (e.g., RAM vs. ROM).

[0052] Device 300 may include a transmitter 330. Device 300 may include a receiver 340. Transmitter 330 and receiver 340 may be configured to transmit and receive information according to at least one cellular or non-cellular standard. Transmitter 330 may include more than one transmitter. Receiver 340 may include more than one receiver. Transmitter 330 and / or receiver 340 may be configured to operate according to standards such as GSM, WCDMA, 5G, LTE, IS-95, WLAN, Ethernet, and / or WiMAX.

[0053] Device 300 may include a near-field communication (NFC) transceiver 350. The NFC transceiver 350 may support at least one NFC technology, such as NFC, Bluetooth, Wibree, or similar technologies.

[0054] Device 300 may include a user interface (UI) 360. UI 360 may include at least one of a display, keyboard, touchscreen, vibrator arranged to signal to the user by causing device 300 to vibrate, speaker, or microphone. The user can operate device 300 via UI 360, for example, by receiving incoming calls, initiating phone or video calls, browsing the internet, managing digital files stored in memory 320 or accessible in the cloud via transmitter 330 and receiver 340 or via NFC transceiver 350, and / or playing games.

[0055] Device 300 may include or be arranged to accept a subscriber identification module 370. Subscriber identification module 370 may include, for example, a subscriber identification module SIM card that can be installed in device 300. Subscriber identification module 370 may include subscription information identifying a user of device 300. Subscriber identification module 370 may include encryption information that can be used to verify the identity of the user of device 300 and / or facilitate the encryption of communication information and billing of the user of device 300 for communications performed via device 300.

[0056] Processor 310 may be equipped with a transmitter arranged to output information from processor 310 to other devices included in device 300 via electrical wires within device 300. Such a transmitter may include a serial bus transmitter arranged to output information to memory 320 for storage, for example, via at least one electrical wire. Alternatively, the transmitter may include a parallel bus transmitter. Similarly, processor 310 may include a receiver arranged to receive information from other devices included in device 300 via electrical wires within device 300. Such a receiver may include a serial bus receiver arranged to receive information from receiver 340, for processing within processor 310, for example, via at least one electrical wire. Alternatively, the receiver may include a parallel bus receiver.

[0057] Device 300 may include Figure 3 Other devices not shown. For example, in the case where device 300 includes a smartphone, it may include at least one digital camera. Some devices 300 may include a rear camera and a front camera, wherein the rear camera may be used for digital photography, while the front camera is used for video calling. Device 300 may include a fingerprint sensor arranged to at least partially authenticate the user of device 300. In some embodiments, device 300 lacks at least one of the devices described above. For example, some devices 300 (such as fixed network nodes and satellite nodes) may lack an NFC transceiver 350 and / or a user identification module 370.

[0058] Processor 310, memory 320, transmitter 330, receiver 340, NFC transceiver 350, UI 360, and / or user identification module 370 can be interconnected in various ways via electrical wires within device 300. For example, each of the above-described devices can be individually connected to the main bus within device 300 to allow the devices to exchange information. However, those skilled in the art will understand that this is merely an example, and depending on the embodiment, various ways of interconnecting at least two of the above-described devices may be chosen without departing from the scope of the invention.

[0059] Figure 4 The illustration shows an example of simultaneous dual registration via two access networks. UE 405 connects via radio links to each of RAN1 410 of PLMN 401 and RAN2 420 of SNPN 402, which are UE 405's home networks. PLMN 401 and SNPN 402 can operate on different frequency bands. Each network has AMFs 412 and 422 coupled to the corresponding RANs 410 and 420. Furthermore, each network 401 and 402 has Session Management Functions (SMFs) 416 and 426. Additionally, each network 401 and 402 has User Plane Functions (UPFs) 418 and 428. Each UPF can be coupled to a separate Data Network (DN). For clarity, the DN is not shown in the diagram. Figure 4 The diagram shows that PLMN 401 and SNPN 402 can be registered simultaneously or sequentially.

[0060] As a result of the dual registration process described herein, UE 405 registers simultaneously via two RANs, 410 and 420, using different encryption keys.

[0061] Figure 5 This is a flowchart of a method according to at least some embodiments of the present invention. The stages of the method shown can be performed, for example, in a user equipment or in a control device configured to control the functions of the UE when installed in the UE.

[0062] Phase 510 includes receiving a first access network identifier from a first access network and a second access network identifier from a second access network within the apparatus. Phase 520 includes establishing Radio Resource Control (RRC) connections with the first and second access networks. The RRC connections with the first and second access networks can be concurrent or sequential. Finally, Phase 530 includes responding to a first encrypted challenge from a core network node via the first access network identifier, and responding to a second encrypted challenge from a core network node via the second access network identifier.

[0063] It should be understood that the embodiments of the present invention disclosed herein are not limited to the specific structures, process steps, or materials disclosed herein, but can be extended to equivalents that will be recognized by those skilled in the art. It should also be understood that the terminology used herein is for describing particular embodiments only and is not intended to be limiting.

[0064] References to an embodiment or an embodiment in this specification indicate that a particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment of the invention. Therefore, the phrases "in one embodiment" or "in an embodiment" appearing in various places in this specification do not necessarily refer to the same embodiment. When numerical values ​​are referenced using terms such as approximately or substantially, exact numerical values ​​are also disclosed.

[0065] As used herein, for convenience, multiple items, structural elements, constituent elements, and / or materials may be presented in a public list. However, these lists should be interpreted as each member being individually identified as a separate and unique member. Therefore, no individual member in such a list should be construed as a de facto equivalent of any other member in the same list solely based on its presentation in the common group (without any indication to the contrary). Furthermore, various embodiments and examples of the invention, as well as alternatives to its various components, may be referenced herein. It should be understood that these embodiments, examples, and alternatives should not be construed as de facto equivalents of each other, but should be considered as separate and autonomous representations of the invention.

[0066] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details, such as examples of length, width, shape, etc., have been provided in the foregoing description to provide a thorough understanding of embodiments of the invention. However, those skilled in the art will recognize that the invention can be practiced without one or more specific details, or using other methods, components, materials, etc. In other instances, well-known structures, materials, or operations have not been shown or described in detail to avoid obscuring aspects of the invention.

[0067] While the foregoing examples illustrate the principles of the invention in one or more specific applications, those skilled in the art will understand that many modifications can be made to the form, use, and details of the implementation without inventive effort and without departing from the principles and concept of the invention. Therefore, the invention is not intended to be limited except by the following claims.

[0068] In this document, the verbs “to comprise” and “to include” are used as disclosure restrictions, neither excluding nor requiring the presence of unreferenced features. Unless otherwise expressly stated, the features recited in the dependent claims may be freely combined with each other. Furthermore, it should be understood that the use of “an” or “a” (i.e., the singular form) in this document does not exclude the plural.

[0069] As used herein, “at least one of the following: ” and “at least one of ” and similar wording (where a list of two or more elements is connected by “and” or “or”) means at least any one of these elements, or at least any two or more of these elements, or at least all of these elements. Industrial applicability

[0070] At least some embodiments of the present invention have industrial applications in managing communication networks. List of abbreviations 3GPP: Third Generation Partnership Project 5G: Fifth Generation AMF: Access and Mobility Management Functions AUSF: Authentication Server Function PLMN: Public Land Mobile Network LTE: Long Term Evolution OAM: Operations, Management and Maintenance SNPN: Independent Non-Public Network UDM: Unified Data Management Node

Claims

1. An apparatus comprising at least one processing core and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor core, cause the apparatus to at least: - Receive a first access network identifier from a first access network, and receive a second access network identifier from a second access network; - Establish Radio Resource Control (RRC) connections with the first access network and the second access network; as well as - Respond to a first encrypted challenge from a core network node based on the first access network identifier and via the first access network, and respond to a second encrypted challenge from the core network node based on the second access network identifier and via the second access network.

2. The apparatus of claim 1, wherein the apparatus is further configured to: derive a first encryption key and use the first encryption key when transmitting data via the first access network, and derive a second encryption key and use the second encryption key when transmitting data via the second access network.

3. The apparatus of claim 2, wherein the apparatus is configured to: employ the first access network identifier when the first encryption key is derived, and employ the second access network identifier when the second encryption key is derived.

4. The apparatus according to any one of claims 1 to 3, wherein the apparatus is configured to simultaneously maintain user equipment context for the first access network and the second access network.

5. The apparatus according to any one of claims 1 to 4, wherein the apparatus is configured to perform the reception of the first access network identifier and the second access network identifier by receiving broadcast system information from the first access network and the second access network, respectively.

6. The apparatus according to any one of claims 1 to 5, wherein the apparatus is further configured to: receive a first public land mobile network identifier, a first tracking area identifier, a first cell identifier, and a first service area identifier from the first access network, and receive a second public land mobile network identifier, a second tracking area identifier, a second cell identifier, and a second service area identifier from the second access network.

7. An apparatus comprising at least one processing core and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor core, cause the apparatus to at least: - Transmit a first access network identifier within the coverage area of ​​the cell controlled by the device; - Establish a Radio Resource Control (RRC) connection with the user equipment; and - Send a registration request for the user equipment to the core network node, the registration request including the first access network identifier.

8. The apparatus of claim 7, wherein the apparatus is configured to: perform the transmission of the first access network identifier in broadcast system information.

9. The apparatus according to any one of claims 7 to 8, wherein the apparatus is configured to include the first access network identifier in the registration request in the form of a concatenation of the first access network identifier and the service network identifier of the apparatus.

10. The apparatus according to any one of claims 7-9, further configured to: transmit at least one of the following in the coverage area of ​​the cell: a first public land mobile network identifier, a first tracking area identifier, a first cell identifier, or a first service area identifier.

11. The apparatus according to any one of claims 7 to 10, wherein the apparatus is configured to receive the first access network identifier from the core network node, the second core network node, or the operation, management, and maintenance node.

12. An apparatus comprising at least one processing core and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor core, cause the apparatus to at least: - Receive a first authentication request for a user equipment, the first authentication request including a first access network identifier, and receive a second authentication request for the user equipment, the second authentication request including a second access network identifier; - Issue a first encryption challenge based on the first access network identifier and in response to the first authentication request, and issue a second encryption challenge based on the second access network identifier and in response to the second authentication request; - Generate a first set of encryption keys based at least in part on the first access network identifier for use between the user equipment and the first access network identified by the first access network identifier; as well as - A second set of encryption keys is generated, at least in part, based on the second access network identifier, for use between the user equipment and the second access network identified by the second access network identifier. - wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

13. An apparatus comprising at least one processing core and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor core, cause the apparatus to at least: - Receive a registration request from the access network for a user equipment connected to the access network, the registration request including an access network identifier that identifies the access network; and - In response to the registration request, an authentication request for the user equipment is sent to the core network node, the authentication request including the access network identifier.

14. The apparatus of claim 13, configured to include an access network identifier in the authentication request, the access network identifier being concatenated with a non-public network identifier of the network in which the apparatus is included.

15. The apparatus of claim 13 or 14 is further configured to: assign the access network identifier to the access network.

16. A method comprising: - In the device, a first access network identifier is received from a first access network, and a second access network identifier is received from a second access network; - Establish Radio Resource Control (RRC) connections with the first access network and the second access network; as well as - Respond to a first encrypted challenge from a core network node based on the first access network identifier and via the first access network, and respond to a second encrypted challenge from the core network node based on the second access network identifier and via the second access network.

17. The method of claim 16, further comprising: A first encryption key is derived and used when transmitting data via the first access network, and a second encryption key is derived and used when transmitting data via the second access network.

18. The method according to any one of claims 16 to 17, comprising: In the device, user equipment context is maintained for both the first access network and the second access network.

19. The method according to any one of claims 16 to 18, wherein the method comprises: The reception of the first access network identifier and the second access network identifier is performed by receiving broadcast system information from the first access network and the second access network, respectively.

20. The method according to any one of claims 16 to 19, wherein the method further comprises: The system receives a first public land mobile network identifier, a first tracking area identifier, a first cell identifier, and a first service area identifier from the first access network, and receives a second public land mobile network identifier, a second tracking area identifier, a second cell identifier, and a second service area identifier from the second access network.

21. A method comprising: - Transmit the first access network identifier within the coverage area of ​​the cell controlled by the device; - Establish a Radio Resource Control (RRC) connection with the user equipment; as well as - Send a registration request for the user equipment to the core network node, the registration request including the first access network identifier.

22. The method of claim 21, wherein the method comprises: The transmission of the first access network identifier is performed in the broadcast system information.

23. The method according to any one of claims 21 to 22, wherein the method comprises: The registration request includes the first access network identifier in the form of a concatenation of the first access network identifier and the service network identifier of the device.

24. The method according to any one of claims 21 to 23, further comprising: In the coverage area of ​​the cell, transmit at least one or each of the following: a first public land mobile network identifier, a first tracking area identifier, a first cell identifier, or a first service area identifier.

25. The method according to any one of claims 21 to 24, wherein the method comprises: The first access network identifier is received from the core network node, the second core network node, or the operation, management, and maintenance node.

26. A method comprising: - Receive a first authentication request for a user equipment, the first authentication request including a first access network identifier, and receive a second authentication request for the user equipment, the second authentication request including a second access network identifier; - Issue a first encryption challenge based on the first access network identifier and in response to the first authentication request, and issue a second encryption challenge based on the second access network identifier and in response to the second authentication request; - Generate a first set of encryption keys based at least in part on the first access network identifier for use between the user equipment and the first access network identified by the first access network identifier; as well as - A second set of encryption keys is generated, at least in part, based on the second access network identifier, for use between the user equipment and the second access network identified by the second access network identifier. - wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

27. A method comprising: - Receive a registration request from the access network for a user equipment connected to the access network, the registration request including an access network identifier that identifies the access network; as well as - In response to the registration request, an authentication request for the user equipment is sent to the core network node, the authentication request including the access network identifier.

28. An apparatus comprising components for: - In the device, a first access network identifier is received from a first access network, and a second access network identifier is received from a second access network; - Establish Radio Resource Control (RRC) connections with the first access network and the second access network; as well as - Respond to a first encrypted challenge from a core network node based on the first access network identifier and via the first access network, and respond to a second encrypted challenge from the core network node based on the second access network identifier and via the second access network.

29. An apparatus comprising components for: - Transmit a first access network identifier within the coverage area of ​​the cell controlled by the device; - Establish a Radio Resource Control (RRC) connection with the user equipment; and - Send a registration request for the user equipment to the core network node, the registration request including the first access network identifier.

30. An apparatus comprising components for: - Receive a first authentication request for a user equipment, the first authentication request including a first access network identifier, and receive a second authentication request for the user equipment, the second authentication request including a second access network identifier; - Issue a first encryption challenge based on the first access network identifier and in response to the first authentication request, and issue a second encryption challenge based on the second access network identifier and in response to the second authentication request; - Generate a first set of encryption keys based at least in part on the first access network identifier for use between the user equipment and the first access network identified by the first access network identifier; as well as - A second set of encryption keys is generated, at least in part, based on the second access network identifier, for use between the user equipment and the second access network identified by the second access network identifier. - wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

31. An apparatus comprising components for: - Receive a registration request from a first access network regarding a user equipment connected to the first access network, the registration request including a first access network identifier identifying the first access network, and - In response to the registration request, an authentication request for the user equipment is sent to the core network node, the authentication request including the first access network identifier.

32. A computer-readable medium having stored thereon a computer-readable instruction set, which, when executed by a device, causes the device to perform at least the following: - Receive a first access network identifier from a first access network, and receive a second access network identifier from a second access network; - Establish Radio Resource Control (RRC) connections with the first access network and the second access network; and - Respond to a first encrypted challenge from a core network node based on the first access network identifier and via the first access network, and respond to a second encrypted challenge from the core network node based on the second access network identifier and via the second access network.

33. A computer-readable medium having stored thereon a computer-readable instruction set, which, when executed by a device, causes the device to perform at least the following: - Transmit a first access network identifier within the coverage area of ​​the cell controlled by the device; - Establish a Radio Resource Control (RRC) connection with the user equipment; and - Send a registration request for the user equipment to the core network node, the registration request including the first access network identifier.

34. A computer-readable medium having stored thereon a computer-readable instruction set, which, when executed by a device, causes the device to perform at least the following: - Receive a first authentication request for a user equipment, the first authentication request including a first access network identifier, and receive a second authentication request for the user equipment, the second authentication request including a second access network identifier; - Issue a first encryption challenge based on the first access network identifier and in response to the first authentication request, and issue a second encryption challenge based on the second access network identifier and in response to the second authentication request; - Generate a first set of encryption keys based at least in part on the first access network identifier for use between the user equipment and the first access network identified by the first access network identifier; as well as - A second set of encryption keys is generated, at least in part, based on the second access network identifier, for use between the user equipment and the second access network identified by the second access network identifier. - wherein the user equipment is authenticated for concurrent encrypted radio resource connections with the first access network and the second access network.

35. A computer-readable medium having stored thereon a computer-readable instruction set, which, when executed by a device, causes the device to perform at least the following: - Receive a registration request from the access network for a user equipment connected to the access network, the registration request including an access network identifier that identifies the access network; and - In response to the registration request, an authentication request for the user equipment is sent to the core network node, the authentication request including the access network identifier.