One-time password (OTP) delivery method

By using encrypted access codes and expiration timers for direct application communication in wireless networks, the problems of manual intervention and susceptibility to interception in SMS-based OTP transmission are solved, achieving a more secure and automated OTP transmission process.

CN121128206APending Publication Date: 2025-12-12NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480032525.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-10-19
Filing Date
2024-10-15
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

One-time password (OTP) transmission based on SMS has problems in wireless communication systems, such as requiring multiple manual interventions and the message being easily intercepted.

Method used

By enabling direct communication between the user equipment (UE) and a dedicated application, and utilizing encrypted access codes and expiration timers, OTP delivery in the wireless network is achieved, avoiding direct SMS delivery and enhancing security and automation.

Benefits of technology

It simplifies the use of OTP, reduces manual intervention, improves security, and lowers the risk of OTP being intercepted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121128206A_ABST
    Figure CN121128206A_ABST
Patent Text Reader

Abstract

A method includes connecting, by a user equipment (UE), to an access site or application. The UE receives, from a first device, a first message including an access code for accessing an access site or application through a dedicated application available on the UE, and extracts the access code from the first message to the dedicated application. The UE transmits an access code to an access site or application via a dedicated application for authentication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Various example embodiments relate generally to wireless networks, and more particularly, to one-time password (OTP) delivery methods. BACKGROUND

[0002] Short Message Service (SMS) is used for messaging in wireless communication systems, but its use in certain applications and websites can be limited to authorization through, for example, one-time password (OTP) delivery. However, there are some drawbacks to SMS-based OTPs. First, since the OTP is delivered through SMS, multiple manual interventions can be required (e.g., the user needs to read the SMS and copy the OTP for third-party authentication). Second, the SMS message can be intercepted. SUMMARY

[0003] In one aspect of the disclosure, a method includes connecting, by a user equipment (UE), to an access site or application. The UE receives, from a first device, a first message including an access code for accessing the access site or application through a dedicated application available on the UE, and extracts the access code from the first message to the dedicated application. The UE sends the access code to the access site or application via the dedicated application for authentication.

[0004] In one aspect of the method, the first message is a downlink (DL) non-access stratum (NAS) transport message.

[0005] In one aspect of the method, the first message includes a UE parameter configuration message encrypted by the first device and decrypted by the UE.

[0006] In one aspect of the method, the first message includes an application identifier identifying the dedicated application and an expiration timing of the access code.

[0007] In one aspect of the disclosure, a method includes providing, by a first device, a user equipment (UE) with an application for authentication. The first device receives, from a second device, a first message including an access code for the UE to access an access site and additional attributes, and sends, to the UE, a second message including the access code and the additional attributes.

[0008] In one aspect of the method, the first message includes one or more of: a data delivery request message, a subscription message, a protection message, or a notification message.

[0009] In one aspect of the method, the first message includes an application identifier identifying the dedicated application and an expiration timing of the access code.

[0010] In one aspect of the method, the second message includes an application identifier identifying the dedicated application and an expiration timing of the access code.

[0011] In one aspect of the method, the first or second message includes an encrypted access code that can be decrypted by a dedicated application and is recognizable by the application identifier.

[0012] In one aspect of the method, if the UE is unreachable or unavailable, the first device buffers the message and retransmits the second message when the UE becomes available.

[0013] In one aspect of the method, the first device caches the second message until the expiration timer expires.

[0014] In one aspect of this disclosure, a method includes a first device providing an application for authentication to a user equipment (UE). The first device receives a first message from a second device, the first message including an indication that the first message is an authentication message. The first device receives a second message from the second device, the second message including an access code for the UE to access an access site, and sends a third message to the UE, the third message including the access code and an application identifier.

[0015] In one aspect of the method, the first message includes one or more of the following: non-IP data transmission, NIDD transmission request message, PDU session transmission message, or communication transmission message.

[0016] In one aspect of the method, the first message includes an application identifier that identifies the dedicated application and an expiration time for the access code.

[0017] In one aspect of the method, the third message includes an application identifier that identifies the dedicated application and an expiration time for the access code.

[0018] In one aspect of the method, the first or second message includes an encrypted access code that can be decrypted by a dedicated application and is recognizable by the application identifier.

[0019] In one aspect of the method, if the UE is unreachable or unavailable, the first device buffers the message and retransmits the second message when the UE becomes available.

[0020] In one aspect of the method, the first device caches the second message until the expiration timer expires.

[0021] In one aspect of this disclosure, a user equipment (UE) includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least any of the foregoing methods.

[0022] In one aspect of this disclosure, the apparatus includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform at least any of the foregoing methods.

[0023] In one aspect of this disclosure, a processor-readable medium stores instructions that, when executed by at least one processor of the device, cause the device to perform at least any of the foregoing methods.

[0024] The subject matter of the independent claims is provided for some aspects. Other aspects are defined in the dependent claims. Attached Figure Description

[0025] Some exemplary embodiments will now be described with reference to the accompanying drawings.

[0026] Figure 1 This is a schematic diagram of an example embodiment of a wireless network between a network system and a user equipment (UE) according to one aspect of this disclosure; Figure 2 This is a schematic diagram of an example component of a network system according to one aspect of this disclosure; Figure 3 This is a diagram of an example embodiment of signals and operations between a UE, AMF, AUSF, UDM, NEF, and AF according to one aspect of this disclosure; Figure 4 This is a diagram of an example embodiment of signals and operations between the UE, AMF, V-SMF, H-SMF, NEF, and AF according to one aspect of this disclosure; and Figure 5 This is a diagram of an example embodiment of a component of a UE or network device according to one aspect of this disclosure. Detailed Implementation

[0027] In the following description, certain specific details are set forth in order to provide a thorough understanding of the disclosed aspects. However, those skilled in the art will recognize that these aspects can be practiced without one or more of these specific details or using other methods, components, materials, etc. In other instances, well-known structures associated with transmitters, receivers, or transceivers have not been shown or described to avoid unnecessarily obscuring the description of the aspects.

[0028] The reference to "an aspect" or "one aspect" in this specification means that a particular feature, structure, or characteristic described in connection with that aspect is included in at least one aspect. Therefore, the phrases "in one aspect" or "in one aspect" appearing throughout this specification do not necessarily refer to the same aspect. Furthermore, a particular feature, structure, or characteristic may be combined in one or more aspects in any suitable manner.

[0029] The embodiments described in this disclosure can be implemented in wireless networking devices, such as, but not limited to, devices utilizing wireless networking systems such as Global Microwave Access Interoperability (WiMAX), Global System for Mobile Communications (GSM, 2G), GSM EDGE Radio Access Network (GERAN), General Packet Radio Service (GPRS), Universal Mobile Telecommunications System based on Basic Wideband Code Division Multiple Access (W-CDMA) (UMTS, 3G), High-Speed ​​Packet Access (HSPA), Long Term Evolution (LTE), LTE-Advanced, Enhanced LTE (eLTE), 5G New Radio (5GNR), 5G Advance, 6G (and later), and 802.11ax (Wi-Fi 6). The term "eLTE" herein refers to LTE evolution connected to a 5G core. LTE is also referred to as Evolved UMTS Terrestrial Radio Access (EUTRA) or Evolved UMTS Terrestrial Radio Access Network (EUTRAN).

[0030] This disclosure may use the term "serving network device" to refer to a network node or network device (or part thereof) that provides services to a UE. As used herein, the terms "sent to," "received from," and "cooperate" (and variations thereof) include communications that may or may not involve communication through one or more intermediate devices or nodes. The term "acquire" (and variations thereof) includes an initial acquisition or a subsequent acquisition. The term "connection" may refer to a physical connection or a logical connection.

[0031] This disclosure uses 5G NR as an example of a wireless network, and may use smartphones and / or extended reality headsets as examples of UEs. It should be understood that these examples are illustrative only, and this disclosure applies to other wireless networks and user equipment.

[0032] Figure 1 This is a diagram depicting an example of wireless networking between network system 100 and user equipment (UE) 150. Network system 100 may include one or more network nodes 120, one or more servers 110, and / or one or more network devices 130 (e.g., test devices). Network node 120 will be described in more detail below. As used herein, the term "network device" may refer to any component of network system 100, such as server 110, network node 120, network device 130, any of the foregoing components, and / or any other component of network system 100. Examples of network devices include, but are not limited to, devices for implementing 5G NR, etc. This disclosure describes embodiments related to 5G NR and embodiments relating to aspects defined by the 3rd Generation Partnership Project (3GPP). However, embodiments related to other wireless networking technologies are contemplated to be included within the scope of this disclosure.

[0033] The following description provides further details of examples of network nodes. In a 5G NR network, a gNodeB (also known as a gNB) may include, for example, a node that provides the UE with New Radio (NR) user plane and control plane protocol termination and connects to the 5G core (5GC) via an NG interface, such as according to Section 3.2 of 3GPP TS 38.300 V16.6.0 (2021-06), which is incorporated herein by reference.

[0034] gNB supports various protocol layers, such as Layer 1 (L1) - the physical layer, Layer 2 (L2) and Layer 3 (L3).

[0035] NR's Layer 2 (L2) is divided into the following sublayers: Media Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP), and Service Data Adaptation Protocol (SDAP), among which, for example: The physical layer provides a transmission channel to the MAC sublayer; The MAC sublayer provides logical channels to the RLC sublayer; The RLC sublayer provides RLC channels to the PDCP sublayer; The PDCP sublayer provides radio bearers to the SDAP sublayer; The SDAP sublayer provides Quality of Service (QoS) flows to 5GC; The control channels include the Broadcast Control Channel (BCCH) and the Physical Control Channel (PCCH).

[0036] Layer 3 (L3) includes, for example, Radio Resource Control (RRC), as per Section 6 of 3GPP TS 38.300 V16.6.0 (2021-06), which is incorporated herein by reference.

[0037] The gNB Central Unit (gNB-CU) includes, for example, a logical node that hosts, the radio resource control (RRC), serving data adaptation protocol (SDAP), and packet data convergence protocol (PDCP) of the gNB, or the RRC and PDCP protocols of the en-gNB, and controls the operation of one or more gNB Distributed Units (gNB-DUs). The gNB-CU terminates the F1 interface connected to the gNB-DU. The gNB-CU may also be referred to herein as a CU, central unit, centralized unit, or control unit.

[0038] A gNB Distributed Unit (gNB-DU) comprises a logical node that hosts, for example, the Radio Link Control (RLC), Media Access Control (MAC), and Physical (PHY) layers of a gNB or en-gNB, and its operation is partially controlled by the gNB-CU. One gNB-DU supports one or more cells. A cell is supported by only one gNB-DU. The gNB-DU terminates the F1 interface connected to the gNB-CU. The gNB-DU may also be referred to herein as a DU or Distributed Unit.

[0039] As used herein, the term "network node" may refer to any one of a gNB, gNB-CU, or gNB-DU, or any combination thereof. RAN (Radio Access Network) nodes or network nodes, such as gNBs, gNB-CUs, or gNB-DUs, or portions thereof, may be implemented using means, for example, having at least one processor and / or at least one memory having processor-readable instructions ("program"), configured to support and / or provide and / or process CU and / or DU-related functions and / or features, and / or at least one protocol (sub) layer of the RAN (Radio Access Network), such as Layer 2 and / or Layer 3. Different functional divisions may exist between central and distributed units. Examples of such means and components will be provided in conjunction with the following... Figure 4 Describe it.

[0040] The gNB-CU and gNB-DU portions can be, for example, co-located or physically separated. The gNB-DU can even be further divided, for example, into two parts, such as one part including processing equipment and the other including antennas. The Central Unit (CU) can also be referred to as a Baseband Unit / Radio Device Controller / Cloud RAN / Virtual RAN (BBU / REC / C-RAN / V-RAN), Open RAN (O-RAN), or a portion thereof. The Distributed Unit (DU) can also be referred to as a Remote Radio Head / Remote Radio Unit / Radio Device / Radio Unit (RRH / RRU / RE / RU), or a portion thereof. In the various exemplary embodiments of this disclosure below, a network node supporting at least one of the Layer 3 protocols of the Central Unit function or the Radio Access Network can be, for example, a gNB-CU. Similarly, a network node supporting at least one of the Layer 2 protocols of the Distributed Unit function or the Radio Access Network can be, for example, a gNB-DU.

[0041] A gNB-CU can support one or more gNB-DUs. A gNB-DU can support one or more cells, and therefore can support the serving cell of a user equipment (UE) or a candidate cell that supports processes such as handover, dual connectivity, and / or carrier aggregation.

[0042] User equipment (UE) 150 may be or include user equipment of the following types: wireless or mobile device, device with a wireless interface for interacting with RAN (Radio Access Network), smartphone, vehicle-mounted device, IoT device, or M2M device. Such UE 150 may include: at least one processor; and at least one memory including program code; wherein the at least one memory and computer program code are configured, together with the at least one processor, to enable the device to perform at least certain operations, such as an RRC connection with the RAN. Component examples of the UE will be combined... Figure 5 The following description is provided. In an embodiment, UE 150 may be configured to generate messages (e.g., including a cell ID) to be transmitted wirelessly to the RAN (e.g., to reach and communicate with the serving cell). In an embodiment, UE 150 may generate, transmit, and receive RRC messages containing one or more RRC PDUs (Packet Data Units). Those skilled in the art will understand the RRC protocol and other processes that the UE may perform.

[0043] Continue to refer to Figure 1 In the example of a 5G NR network, network system 100 provides one or more cells that define the coverage area of ​​network system 100. As described above, network system 100 may include a gNB of the 5G NR network or may include any other means configured to control wireless communications and manage radio resources within the cell. As used herein, the term "resource" may refer to radio resources such as resource blocks (RBs), physical resource blocks (PRBs), radio frames, subframes, time slots, subbands, frequency regions, subcarriers, beams, etc. In embodiments, network node 120 may be referred to as a base station.

[0044] Figure 1 An example is provided, which is merely an illustration of network system 100 and UE 150. Those skilled in the art will understand that network system 100 includes... Figure 1 The components not shown in the diagram will be understood, and other user equipment can communicate with network system 100.

[0045] Figure 2 yes Figure 1 A block diagram of example components of network system 100. A 5G NR network can be described as an example of network system 100, and it is anticipated that the aspects described below will also apply to other types of network systems. The network system can be configured according to... Figure 1The signals and connections shown operate to enable UE 150 to communicate with network system 100 via radio access network 225. Furthermore, the network system can be divided into user plane components and functions and control plane components and functions, as shown and described herein. Unless otherwise stated, the terms "component," "function," and "service" are used interchangeably herein and can refer to and be implemented by instructions executed by one or more processors.

[0046] The following describes example functionality of the components. This example functionality is illustrative only, and it should be understood that the components described herein can perform additional operations and functions. Furthermore, connections between components can be virtual connections based on service interfaces, allowing any component to communicate with any other component. In this way, any component can act as a service "producer" for any other component acting as a service "consumer," providing services for network functions.

[0047] For example, core network 210 is described in the control plane of the network system. Core network 210 may include Authentication Server Function (AUSF) 211, Access and Mobility Function (AMF) 212, and Session Management Function (SMF) 213. Core network 210 may also include Network Slice Selection Function (NSSF) 214, Network Open Function (NEF) 215, Network Repository Function (NRF) 216, and Unified Data Management Function (UDM) 217, which may include Unified Data Repository (UDR) 224.

[0048] Additional components and functions of the core network 210 may include application functions 218, policy control functions (PCF) 219, network data analysis functions (NWDAF) 220, analytical data repository functions (ADRF) 221, management data analysis functions (MDAF) 222, and operation and management functions (OAM) 223.

[0049] The user plane includes UE 150, Radio Access Network (RAN) 225, User Plane Function (UPF) 226, and Data Network (DN) 227. RAN 225 may include a combination of Figure 1 The RAN 225 describes one or more components, such as one or more network nodes. However, the RAN 225 may not be limited to these components. The UPF 226 provides connectivity for data transmitted through the RAN 225. The DN 226 identifies services from service providers, such as internet access and third-party services.

[0050] AMF 212 handles connectivity and mobility tasks. AUSF 211 receives authentication requests from AMF 212 and interacts with UDM 217 to authenticate and verify network responses to determine successful authentication. SMF 213 performs Packet Data Unit (PDU) session management and manages session context with UPF 226.

[0051] NSSF 214 can select a Network Slice Instance (NSI) and determine the allowed Network Slice Selection Auxiliary Information (NSSAI). This selection and determination are used to configure AMF 212 to provide services to UE 150. NEF 215 enables third parties to securely access network services to create specialized network services. NRF 216 acts as a repository to store network functions, allowing these functions to register and discover each other.

[0052] UDM 217 generates authentication vectors for use by AUSF 211 and ADM 212 and provides user identification processing. UDM 217 can connect to UDR 224, which stores data related to authentication, applications, etc. AF 218 provides application services (such as streaming media services) to users. PCF 219 provides policy control functions. For example, PCF 219 can assist with network slicing and mobility management, as well as provide Quality of Service (QoS) and accounting functions.

[0053] NWDAF 220 collects data (e.g., from UE 150 and network systems) to perform network analytics and provide insights to functions that leverage analytics in providing services. ADRF 221 allows consumers to store, retrieve, and delete data and analytics. MDAF 222 provides additional data analytics services for network functions. OAM 223 provides configuration and management processing functions to manage elements in or connected to the network (e.g., UE 150, network nodes, etc.).

[0054] Figure 2 These are merely examples of network system components, and variations are considered within the scope of this disclosure. In embodiments, the network system may include... Figure 2 Other components not shown. In embodiments, the network system may not include... Figure 2 Each component is shown in the diagram. In embodiments, components and connections can be used with... Figure 2 The different connections shown are used to implement this. These and other embodiments are considered to be within the scope of this disclosure.

[0055] As mentioned above, Short Message Service (SMS) is used for messaging in wireless communication systems, but its use in some applications and websites may be limited to authorization via, for example, a One-Time Password (OTP). However, SMS-based OTPs have some drawbacks. First, because OTPs are delivered via SMS, multiple manual interventions may be required (e.g., the user needs to read the SMS and copy the OTP for third-party authentication). Furthermore, SMS messages can be intercepted.

[0056] In SMS-based authentication, the UE triggers a procedure where the user enters their mobile phone number in the application to request verification via SMS. The application server sends an SMS message containing an access code via the 5G core network (CN). This code is delivered to the UE as an SMS message. The user reads the code and uses it to log in to the application. The application server verifies the code and allows login. As mentioned above, due to the potential drawbacks of SMS authentication, more secure methods can be provided.

[0057] While more details are provided below, in short, an authentication method using OTP delivery is described where an access code is provided to a dedicated application or access site to which the user seeks access, without using SMS messages. By utilizing this method, the message or OTP can be delivered directly to the application only by providing the application's application identifier (ID) when the application invokes authentication, instead of exposing the OTP and making it vulnerable to potential attacks by malicious applications.

[0058] As used herein, communication with the Radio Access Network (RAN) can refer to and mean communication with a portion of the RAN, such as communication with network nodes (e.g., DU and / or CU) or another portion of the RAN. As used herein, communication with the core network can refer to and mean communication with one or more services / applications of the core network, such as AMF or another service of the core network.

[0059] Based on the above brief explanation, Figure 3 This is a diagram illustrating an example embodiment of signals and operations between a UE, AMF, AUSF, UDM, NEF, and AF, according to one aspect of this disclosure. The following paragraphs will describe various signals and operations. It should be understood that the described signals may have associated operations, and the described operations may have associated signals.

[0060] exist Figure 3 In various example embodiments, the UE may include Figure 1 The UE 150 described herein may include AMF 212, AUSF 211, UDM 217, NEF 215, and AF 215. Figure 2AF 218 as described in the text.

[0061] Prior to operation 301a, the UE may be attempting to access a site or application. In various embodiments, the site or application may be accessed via a dedicated application provided on the UE.

[0062] In operation 301a, the AF sends an Nnef_datadelivery_request message to the NEF, and the NEF receives the Nnef_datadelivery_request message. In various embodiments, the AF may be the AF associated with the application that the UE is trying to access. The Nnef_datadelivery_request message may include an access code, an application identifier (ID), and an expiration time for the access code (e.g., (OTP) validity period = 30 seconds, application ID). Those skilled in the art will understand that although a 30-second expiration time is used for the access code for illustrative purposes, other time periods may also be used.

[0063] In operation 302, the NEF performs authorization and load control, as understood by those skilled in the art, and may include determining that the UE has been authenticated. In operation 303, the NEF sends a Nudm_EE_subscribe message to the UDM, which receives the Nudm_EE_subscribe message. In various embodiments, the Nudm_EE_subscribe message may include an access code, an application ID, and an expiration time for the access code. In operation 304a, the UDM sends a Nausf_UPU protection message to the AUSF, which receives the Nausf_UPU protection message. In various embodiments, the Nausf_UPU protection message includes a SUPI, an access code, authentication (authenticate = true), and an application ID, as well as an acknowledgment indication.

[0064] In operation 304b, AUSF sends a Nausf_UPU protection response message to UDM, and UDM receives the Nausf_UPU protection message. In various embodiments, the Nausf_UPU protection message will be understood by those skilled in the art. In operation 305, the UDM sends a Nudm_SDM_Notification message to the AMF, and the AMF receives the Nudm_SDM_Notification message. In various embodiments, the Nudm_SDM_Notification message includes UPU data containing the access code, application ID, code expiration time, and authentication information. In various embodiments, the Nudm_SDM_Notification message may include UPU-MAC-IAUSF and counterUPU, as will be understood by those skilled in the art.

[0065] In operation 306, the AMF sends a downlink (DL) non-access stratum (NAS) transport message to the UE, and the UE receives the DL NAS transport message. In various embodiments, the DL NAS transport message includes UPU data, UPU-MAC-IAUSF, and counterUPU, containing access code, application ID, code expiration time, and authentication information.

[0066] In operation 307a, the UE verifies the UPU-MAC-IAUSF. In various embodiments, the access code is provided to the application that matches the application ID. That is, the dedicated application performing authentication is directly provided with the access code for authentication. In various embodiments, the UE verifies that the UPU header is valid. In various embodiments, in operation 307b, the AMF can perform buffering on the time available in the OTP.

[0067] In operation 308, the UE sends an uplink (UL) NAS transmission message to the AUSF, and the AUSF receives the UL NAS transmission message. In various embodiments, the UL NAS transmission message includes UPU-MAC-IUE. In operation 309, the AUSF sends a Nudm_SDM_Info message to the UDM, and the UDM receives the Nudm_SDM_Info message. In various embodiments, the Nudm_SDM_Info message includes UPU-MAC-IUE.

[0068] In operation 310, the UDM compares the UPU-MAC-IUE with the stored UPU-XMAC-IUE to determine if a match exists for authentication.

[0069] Figure 3 The operations described are merely illustrative, and variations are considered within the scope of this disclosure. In embodiments, the operations may include... Figure 3 Other operations not shown. In embodiments, operations may not include... Figure 3 Each operation is shown in the diagram. In an embodiment, the operation can be performed in conjunction with... Figure 3 The different sequences of implementations shown are illustrated. These and other embodiments are considered to be within the scope of this disclosure. Those skilled in the art will understand that while various example components are described to perform various functions, other components may perform those functions described in FIG. 300. In various embodiments, FIG. 300 may depict a Non-Internet Protocol Data Transfer (NIDD) scheme.

[0070] Figure 4 This is a diagram illustrating an example embodiment of signaling and operation 400 between a UE, AMF, Access (V)-SMF, Home (H)-SMF, NEF, and AF, according to this disclosure. In various embodiments, Figure 4The components shown can be used with Figure 1 and Figure 2 The similar components shown are related to those described above for example embodiment 300.

[0071] As described above, prior to operation 401a, the UE may be attempting to access a site or application. In various embodiments, the site or application may be accessed via a dedicated application provided on the UE.

[0072] In operation 401a, the AF sends an Nnef_NIDD_delivery request message to the NEF, and the NEF receives the Nnef_NIDD_delivery request message. In various embodiments, the Nnef_NIDD_delivery request message includes a flag indicating that authentication is in progress (flag = authentication), as well as an application ID and access code.

[0073] In operation 401b, the AMF can send a Namf_eventexposure_notify message to the NEF, and the NEF receives the Namf_eventexposure_notify message. Therefore, in operation 402, the NEF can perform authorization and load control. Those skilled in the art will understand the operations performed in operations 401b and 402.

[0074] In operation 403, the NEF sends an Nsmf_NIDD_delivery request message to the H-SMF, and the H-SMF receives the Nsmf_NIDD_delivery request message. In various embodiments, the Nsmf_NIDD_delivery request message may include an authentication flag, an access code, and an application ID.

[0075] In the event of Operation 404, the H-SMF can send an Nsmf_PDUsession_TransferMT data message to the V-SMF, and the V-SMF receives the Nsmf_PDUsession_TransferMT data message. In various embodiments, the Nsmf_PDUsession_TransferMT data message includes an authentication flag, an access code, and an application ID.

[0076] In operation 405, the V-SMF sends a Namf_communication_N1N2message to the AMF, and the AMF receives the Namf_communication_N1N2message. In various embodiments, the Namf_communication_N1N2message includes a PDU session ID, data, authentication flag, access code, and application ID.

[0077] Those skilled in the art will understand and comprehend the operations performed in operations 406-414. For example, in operation 406, the AMF may send a Namf_communication_N1N2message transmission response message to the V-SMF, and the V-SMF may receive the Namf_communication_N1N2message transmission response message.

[0078] In operation 407, the V-SMF can send an Nsmf_PDUsession_message transmission response message to the H-SMF, and the H-SMF receives the Nsmf_PDUsession_message transmission response message. After receiving the Nsmf_PDUsession_message transmission response message, in operation 408, the H-SMF can send an Nsmf_NIDD_delivery response message to the NEF, and the NEF receives the Nsmf_NIDD_delivery response message.

[0079] In operation 409, steps of the mobile termination data transmission process anchored to the UPF in control plane optimization can be performed (e.g., 3-6). In operation 410, a UE confirmation update process for access and mobility management related parameters can be performed.

[0080] In operation 411, the AMF can send a `Namf_communication_N1N2messagetransferfailure` notification message to the V-SMF, and the V-SMF receives this message. In operation 412, the V-SMF can send an `Nsmf_PDUseession_transferMTdata` response message to the H-SMF, and the H-SMF receives this message. In operation 413, the H-SMF can send an `Nsmf_NIDD_delivery` response message to the NEF, and the NEF receives this message.

[0081] In operation 414, steps (e.g., 9-11) of the UPF anchoring mobile terminal data transmission process during the control plane optimization procedure can be performed. In various embodiments, the access code and application ID may be included in the payload of the message sent to the UE.

[0082] In operation 414a, the access code can be provided to the application requesting authentication, identified by the application ID. In operation 415, the AMF can send a `Namf_communication_N1N2message transfer` response message to the V-SMF, which is received by the V-SMF. In operation 416, the V-SMF can send an `Nsmf_PDUsession_transferMTdata` response message to the H-SMF, which is received by the H-SMF. In operation 417, the H-SMF can send an `Nsmf_NIDD_delivery` response message to the NEF, which is received by the NEF.

[0083] In operation 418, NEF sends an Nnef_NIDD_delivery response message to AF, and AF receives the Nnef_NIDD_delivery response message. Those skilled in the art will understand and comprehend the operations performed in operations 415-418.

[0084] Figure 4 The operations described are merely exemplary and variations can be considered within the scope of this disclosure. In embodiments, these operations may include... Figure 4 Other operations not shown. In embodiments, these operations may not include... Figure 4 Each operation is shown in the diagram. In an embodiment, these operations can be performed in conjunction with... Figure 4 The different sequences of implementation are shown. These and other embodiments are considered within the scope of this disclosure. Those skilled in the art will understand that although various example components are described to perform various functions, other components can perform those functions described in FIG. 400. In various embodiments, FIG. 400 may depict an NIDD scheme. That is, messages can be transmitted according to the NIDD protocol.

[0085] The operation is described below from the perspective of the UE in various embodiments. From such a perspective, the method may include: a user equipment (UE) connecting to an access site or application. The UE receives from a first device a first message including an access code for accessing the access site or application through a dedicated application available on the UE, and extracts the access code from the first message to the dedicated application. The UE sends the access code to the access site or application for authentication through the dedicated application.

[0086] The operation is described below from the perspective of a network device (apparatus) in various embodiments. From such a perspective, the method may include: a first apparatus providing an application for authentication to a user equipment (UE). The first apparatus receives a first message from a second apparatus, the first message including an access code and additional attributes for the UE to access an access site, and sends a second message to the UE, the second message including the access code and additional attributes.

[0087] The operation is described below from the perspective of a network device (apparatus) in various embodiments. From such a perspective, the method may include: a first apparatus providing an application for authentication to a user equipment (UE). The first apparatus receives a first message from a second apparatus, the first message including an indication that the first message is an authentication message. The first apparatus receives a second message from the second apparatus, the second message including an access code for the UE to access an access site, and sends a third message to the UE, the third message including the access code and an application identifier.

[0088] Now for reference Figure 5 This diagram illustrates a block diagram of example components of a UE or network device (e.g., a RAN or core network). The device includes electronic memory 510, a processor 520, a network interface 540, and memory 550. The various components can be communicatively coupled to each other. The processor 520 can be and may include any type of processor, such as a single-core central processing unit (CPU), a multi-core CPU, a microprocessor, a digital signal processor (DSP), a system-on-a-chip (SoC), or any other type of processor. The memory 550 can be volatile memory, such as RAM, or non-volatile memory, such as NAND flash memory. The memory 550 includes processor-readable instructions executable by the processor 520 to cause the device to perform various operations, including those mentioned herein, such as... Figure 3 and 4 The operation.

[0089] Electronic memory 510 can be and includes any type of electronic memory for storing data, such as hard disk drives, solid-state drives, optical disks and / or other non-transitory computer-readable media, as well as other types of electronic memory. Electronic memory 510 stores processor-readable instructions for causing or configuring the device to perform its operations, and also stores data related to such operations, such as data related to the 5G NR standard and other data. Network interface 540 can implement wireless network technologies, such as 5G NR and / or other wireless network technologies.

[0090] Figure 5 The components shown are merely examples, and those skilled in the art will understand that the apparatus includes other components not shown, and may include multiples of any of the components shown. These and other embodiments are considered within the scope of this disclosure.

[0091] Other embodiments of this disclosure include the following examples.

[0092] Example 1.1. User Equipment (UE), including: A means for a user equipment (UE) to connect to an access site or application; A means for receiving, by the UE, a first message from a first device including an access code for accessing an access site or application via a dedicated application available on the UE; A means for the UE to extract an access code from a first message to a dedicated application; and A device for authenticating a UE by sending an access code to an access site or application via a dedicated application.

[0093] Example 1.2. The UE of Example 1.1, where the first message is a downlink (DL) non-access stratum (NAS) transport message.

[0094] Example 1.3. The UE of Example 1.1, wherein the first message includes a UE parameter configuration message encrypted by the first device and decrypted by the UE.

[0095] Example 1.4. The UE of Example 1.1, wherein the first message includes an application identifier that identifies the dedicated application and the expiration time of the access code.

[0096] Example 2.1. An apparatus comprising: A means for providing an application for authentication to a user equipment (UE) by a first means; A means for receiving a first message from a second device by a first device, the first message including an access code and additional attributes for the UE to access an access site; and A means for sending a second message from a first means to a UE, the second message including an access code and additional attributes.

[0097] Example 2.2. The apparatus of Example 2.1, wherein the first message includes one or more of the following: a data delivery request message, a subscription message, a protection message, or a notification message.

[0098] Example 2.3. An apparatus as in any of Examples 2.1-2.2, wherein the first message includes an application identifier identifying the dedicated application and an expiration time for the access code.

[0099] Example 2.4. An apparatus as in any of Examples 2.1-2.3, wherein the second message includes an application identifier identifying the dedicated application and an expiration time for the access code.

[0100] Example 2.5. An apparatus as in any of Examples 2.1-2.4, wherein the first or second message includes an encrypted access code that can be decrypted by a dedicated application and identified by an application identifier.

[0101] Example 2.6. An apparatus as described in any of Examples 2.1-2.5, wherein if the UE is unreachable or unavailable, the first apparatus buffers the message and retransmits the second message when the UE becomes available.

[0102] Example 2.7. The apparatus of Example 2.4, wherein the first apparatus caches the second message until the expiration time expires.

[0103] Example 3.1. An apparatus comprising: A means for providing an application for authentication to a user equipment (UE) by a first means; A means for receiving a first message from a second device by a first device, the first message including an indication that the first message is an authentication message; A means for receiving a second message from a second device by a first device, the second message including an access code for a UE to access an access site; and A means for sending a third message from a first means to a UE, the third message including the access code and the application identifier.

[0104] Example 3.2. The apparatus of Example 3.1, wherein the first message includes one or more of the following: a non-IP data transfer (NIDD) transfer request message, a PDU session transfer message, or a communication transfer message.

[0105] Example 3.3. The apparatus as described in any one of Examples 3.1-3.2, wherein the first message includes an application identifier identifying the dedicated application and an expiration time of the access code.

[0106] Example 3.4. The apparatus as described in any one of Examples 3.1-3.3, wherein the third message includes an application identifier identifying the dedicated application and an expiration time of the access code.

[0107] Example 3.5. An apparatus as described in any one of Examples 3.1-3.4, wherein the first or second message includes an encrypted access code that can be decrypted by a dedicated application recognized by the application identifier.

[0108] Example 3.6. The apparatus of any one of Examples 3.1-3.5, wherein if the UE is unreachable or unavailable, the first apparatus buffers the message and retransmits the second message when the UE becomes available.

[0109] Example 3.7. The apparatus of Example 3.4, wherein the first apparatus caches the second message until the expiration time expires.

[0110] Example 4.1. A user equipment (UE) comprising: At least one processor; and At least one memory stores instructions that, when executed by the at least one processor, cause the UE to at least: Connect to the access site or application; Receive a first message from the first device, the first message including an access code for accessing the access site or application via a dedicated application available on the UE; Extract the access code from the first message and assign it to the dedicated application; and The access code is sent to the access site or application for authentication via the dedicated application.

[0111] Example 5.1. A first device comprising: At least one processor; and At least one memory stores instructions that, when executed by the at least one processor, cause the first device to at least: Provides applications for authentication for user equipment (UE); Receive a first message from the second device, the first message including an access code and additional attributes for the UE to access the access site; and A second message is sent to the UE, the second message including the access code and additional attributes.

[0112] Example 6.1. A first device comprising: At least one processor; and At least one memory stores instructions that, when executed by the at least one processor, cause the first device to at least: Provides applications for authentication for user equipment (UE); Receive a first message from the second device, the first message including an indication that the first message is an authentication message; Receive a second message from the second device, the second message including an access code for the UE to access the access site; and A third message is sent to the UE, the third message including the access code and the application identifier.

[0113] The embodiments and aspects disclosed herein are examples of this disclosure and can be implemented in various forms. For example, although some embodiments herein are described as separate embodiments, each embodiment herein may be combined with one or more other embodiments herein. The specific structural and functional details disclosed herein should not be construed as limiting, but should serve as the basis for the claims and as a representative basis for teaching those skilled in the art to adopt this disclosure in various ways with virtually any suitably detailed structure. The same reference numerals may refer to similar or identical elements depicted in the figures.

[0114] For example, as described above, in NIDD operation, the NEF can expose an enhanced API to the AF, where the AF can request the UE to authenticate via an Nnef_NIDD_Delivery request. Therefore, in various embodiments, a flag can be defined in the Nnef_NIDD_Delivery request to indicate that it is for authentication. The UE can connect to a third-party site (access site or application) via the Internet or through an application and provide an MSISDN. The third-party site can send an OTP to authenticate the UE or to verify that the user authenticating the UE is the actual owner of the device identified by the MSISDN.

[0115] In various embodiments, a third-party site invokes the NEF Nnef_NIDD_Delivery API to authenticate the UE and provide an access (key) code / OTP and application ID or application details. The NEF can provide the access code and application details to the SMF and transmit them to the UE via, for example, the NIDD procedure defined in Section 4.25.5 of TS 23.502. The authentication flag in the DL NAS transport (NAS message (PDU Session ID, Data, Authentication)) helps the UE determine how to handle the message.

[0116] In various embodiments, the UE receives a NAS message flag or indication for authentication, along with an application ID / details. The UE can then obtain an access code (text payload information from the NAS payload) and deliver it to the application (upper layer) that matches the application ID. The application delivers the access code to a third-party site, and if the access code matches on the third-party site, the UE is authenticated.

[0117] Additionally, for example, in non-NIDD operations, the NEF can expose an API for the AF, where the AF can request authentication from the UE. Similarly, the UE can connect to a third-party site via the internet or an application and provide an MSISDN. The third-party site will also want to send an OTP or confirm whether the connected device is indeed an authorized UE.

[0118] In various embodiments, a third-party site invokes the NEF API to authenticate the UE and provide an access code and application ID or application details. The NEF provides the access code, application ID / details to the UDM, the UDM pushes this information to the AMF, and the AMF delivers it to the UE via a NAS message or UPU. In various embodiments, the AMF or UDM may support buffering in case the UE is unreachable. The UPU message is encrypted by the network in a manner that only the UE can decrypt, as defined, for example, in TS 33.501.

[0119] In various embodiments, the UE receives a NAS message flag or indication for authentication, along with an application ID / details, extracts a secret code (text payload information from the NAS payload), and delivers it to the application (upper layer) matching the application ID. The application delivers the access code to a third-party site, and if the access code matches at the third party, the UE is authenticated. If the message is delivered to the UE via a UPU process, the UE verifies and decrypts the UPU. If verification is successful, only the UE delivers the access code to the dedicated application identified by the application ID. In various embodiments, the application / site may encrypt the code, and only applications available on the UE can decrypt it to ensure confidentiality.

[0120] Therefore, based on the above, messages or OTPs can be directly provided to dedicated applications for authentication.

[0121] In various embodiments, the above message may be encrypted for transmission and decrypted by the receiving component or device.

[0122] The phrases “in one aspect,” “in all aspects,” “in various aspects,” “in some aspects,” or “in other aspects” may each refer to one or more of the same or different aspects according to this disclosure. The phrase “multiple” may refer to two or more.

[0123] In various embodiments, the terms "first message" and "second message" as well as any subsequent messages may refer to any messages transmitted or received in a certain order, and are not necessarily limited to any particular message.

[0124] The phrases "in one embodiment," "in an embodiment," "in various embodiments," "in some embodiments," or "in other embodiments" may each refer to one or more of the same or different embodiments according to this disclosure. A phrase of the form "A or B" means "(A), (B), or (A and B)." A phrase of the form "at least one of A, B, or C" means "(A); (B); (C); (A and B); (A and C); (B and C); or (A, B, and C)."

[0125] Any method, program, algorithm, or code described herein can be translated into or expressed in a programming language or computer program. As used herein, the terms "programming language" and "computer program" each include any language used to specify instructions to a computer, and include (but are not limited to) the following languages ​​and their derivatives: assembler, Basic, batch file, BCPL, C, C+, C++, Delphi, Fortran, Java, JavaScript, machine code, operating system command languages, Pascal, Perl, PL1, Python, scripting languages, Visual Basic, meta-languages ​​that specify programs themselves, and all first, second, third, fourth, fifth, or higher generation computer languages. Databases and other data schemas, and any other meta-languages, are also included. No distinction is made between interpreted, compiled, or languages ​​that use both compilation and interpretation methods. No distinction is made between compiled and source versions of a program. Therefore, a reference to a program, where a programming language can exist in multiple states (e.g., source, compiled, target, or linked), is a reference to any and all such states. References to a program can include the actual instructions and / or intent of those instructions.

[0126] While various aspects of this disclosure have been shown in the accompanying drawings, it is not intended to limit this disclosure, as it is intended to be as extensive as permitted by the art, and the specification is read accordingly. Therefore, the foregoing description should not be construed as restrictive, but merely as examples of particular aspects. Other modifications within the scope and spirit of the appended claims will be contemplated by those skilled in the art.

Claims

1. A method comprising: Connected to an access site or application by a user equipment (UE); The UE receives a first message from the first device, the first message including an access code for accessing the access site or the application through a dedicated application available on the UE; The UE extracts the access code from the first message to the dedicated application; as well as The UE transmits the access code to the access site or the application via the dedicated application for authentication.

2. The method according to claim 1, wherein the first message is a downlink (DL) non-access stratum (NAS) transmission message.

3. The method according to claim 1, wherein the first message includes a UE parameter configuration message encrypted by the first device and decrypted by the UE.

4. The method of claim 1, wherein the first message includes an application identifier identifying the dedicated application and an expiration time for the access code.

5. A method comprising: The first device provides the application for authentication to the user equipment (UE); The first device receives a first message from the second device, the first message including an access code and additional attributes for the UE to access the access site; as well as The first device transmits a second message to the UE, the second message including the access code and the additional attributes.

6. The method of claim 5, wherein the first message includes one or more of the following: a data delivery request message, a subscription message, a protection message, or a notification message.

7. The method according to any one of claims 5 to 6, wherein the first message includes an application identifier identifying the dedicated application and an expiration time for the access code.

8. The method according to any one of claims 5 to 7, wherein the second message includes an application identifier identifying the dedicated application and an expiration time for the access code.

9. The method according to any one of claims 5 to 8, wherein the first message or the second message includes an encrypted access code, the encrypted access code being decryptable by the dedicated application identified by the application identifier.

10. The method according to any one of claims 5 to 9, wherein if the UE is unreachable or unavailable, the first device buffers the message and retransmits the second message when the UE becomes available.

11. The method of claim 8, wherein the first device buffers the second message until the expiration timer expires.

12. A method comprising: The first device provides the application for authentication to the user equipment (UE); The first device receives a first message from the second device, the first message including an indication that the first message is an authentication message; The first device receives a second message from the second device, the second message including an access code for the UE to access the access site; as well as The first device transmits a third message to the UE, the third message including the access code and the application identifier.

13. The method of claim 12, wherein the first message includes one or more of the following: a non-IP data delivery (NIDD) delivery request message, a PDU session transmission message, or a communication transmission message.

14. The method according to any one of claims 12 to 13, wherein the first message includes an application identifier identifying the dedicated application and an expiration time for the access code.

15. The method according to any one of claims 12 to 14, wherein the third message includes an application identifier identifying the dedicated application and an expiration time for the access code.

16. The method according to any one of claims 12 to 15, wherein the first message or the second message includes an encrypted access code, the encrypted access code being decryptable by the dedicated application identified by the application identifier.

17. The method according to any one of claims 12 to 16, wherein if the UE is unreachable or unavailable, the first device buffers the message and retransmits the second message when the UE becomes available.

18. The method of claim 15, wherein the first device buffers the second message until the expiration timer expires.

19. A user equipment (UE), comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least the method as described in any one of claims 1 to 4.

20. A processor-readable medium storing instructions that, when executed by at least one processor of a device, cause the device to perform at least the method as claimed in any one of claims 1 to 4.

21. An apparatus comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the device to perform at least the method as claimed in any one of claims 5 to 18.

22. A processor-readable medium storing instructions that, when executed by at least one processor of a device, cause the device to perform at least the method as claimed in any one of claims 5 to 18.