Authentication based on visited network

By generating and using the root key of the accessed network between user equipment and network equipment, the authentication problem of user equipment when it cannot access the home network is solved, and secure access and efficient authentication within the accessed network are achieved.

CN122640152APending Publication Date: 2026-08-25NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610221263.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-02-24
Filing Date
2026-02-24
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

In existing technologies, when user equipment cannot access its home network, it is difficult to achieve secure and efficient authentication based on the accessed network, resulting in reduced communication security and reliability.

Method used

User equipment and network devices implement the authentication process of user equipment by generating and using root keys based on the accessed network. This includes generating and using root keys in the accessed network, reducing dependence on the home network, and ensuring secure access for user equipment within the accessed network.

Benefits of technology

Even when the home network is unavailable, user equipment can securely access network services, improving communication security and the efficiency and reliability of the authentication process based on the accessed network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122640152A_ABST
    Figure CN122640152A_ABST
Patent Text Reader

Abstract

Methods, apparatuses, and computer readable storage media for visited network based authentication are provided. In one method, a user device sends, to a first network device in a visited network of the user device, a registration request including an indication that the user device supports visited network based authentication; and generates a root key to be used for visited network based authentication for the user device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various exemplary embodiments of this disclosure generally relate to the telecommunications field, and more specifically to devices, methods, apparatuses, and computer-readable storage media for authentication based on an accessed network. Background Technology

[0002] In communication systems, authentication plays a crucial role in ensuring secure and trusted interaction between user equipment (UE) and network devices. As UEs connect to different networks, verifying identity and seamlessly managing access can be critical. An effective authentication mechanism may need to support secure and efficient methods for verifying UEs across diverse network environments, enabling UEs to access services without compromising security. Summary of the Invention

[0003] In a first aspect of this disclosure, a user equipment is provided. The user equipment includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to at least: send a registration request to a first network device in an accessed network of the user equipment, the registration request including an indication that the user equipment supports accessed network-based authentication; and generate a root key to be used for accessed network-based authentication of the user equipment.

[0004] In a second aspect of this disclosure, a first network device is provided in an accessed network of a user equipment. The first network device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first network device to at least: receive a registration request from a user equipment, the registration request including an indication that the user equipment supports accessed network-based authentication; send a request for accessed network-based authentication for the user equipment to a second network device in the user equipment's home network; receive a response to the request from the second network device, the response including a root key for accessed network-based authentication for the user equipment; send a registration response to the registration request to the user equipment, the registration response including an indication that accessed network-specific authentication is enabled for the user equipment; and, in response to the commencement of communication by the user equipment, authenticate the user equipment via the accessed network using the root key.

[0005] In a third aspect of this disclosure, a second network device is provided in the home network of a user equipment. The second network device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second network device to at least: receive a request for accessed network-based authentication for the user equipment from a first network device in an accessed network of the user equipment; generate a root key for accessed network-based authentication of the user equipment; and send a response to the request to the first network device, the response including the root key.

[0006] In a fourth aspect of this disclosure, a method is provided at a user equipment. The method includes: the user equipment sending a registration request to a first network device in an accessed network of the user equipment, the registration request including an indication that the user equipment supports accessed network-based authentication; and the user equipment generating a root key to be used for accessed network-based authentication of the user equipment.

[0007] In a fifth aspect of this disclosure, a method is provided at a first network device in an accessed network of a user equipment. The method includes: the first network device receiving a registration request from the user equipment, the registration request including an indication that the user equipment supports accessed network-based authentication; the first network device sending a request for accessed network-based authentication of the user equipment to a second network device in the user equipment's home network; the first network device receiving a response to the request from the second network device, the response including a root key for accessed network-based authentication of the user equipment; the first network device sending a registration response to the registration request to the user equipment, the registration response including an indication that accessed network-specific authentication is enabled for the user equipment; and in response to the commencement of communication by the user equipment, the first network device authenticating the user equipment via the accessed network using the root key.

[0008] In a sixth aspect of this disclosure, a method is provided at a second network device in the home network of a user equipment. The method includes: the second network device receiving a request for access-based authentication of the user equipment from a first network device in an accessed network of the user equipment; the second network device generating a root key for access-based authentication of the user equipment; and the second network device sending a response to the request to the first network device, the response including the root key.

[0009] In a seventh aspect of this disclosure, a user equipment is provided. The user equipment includes: components for sending a registration request to a first network device in an accessed network of the user equipment, the registration request including an indication that the user equipment supports accessed network-based authentication; and components for generating a root key for use by the user equipment in accessed network-based authentication.

[0010] In an eighth aspect of this disclosure, a first network device is provided in an accessed network of a user equipment. The first network device includes: means for receiving a registration request from the user equipment, the registration request including an indication that the user equipment supports accessed network-based authentication; means for sending a request for accessed network-based authentication of the user equipment to a second network device in the user equipment's home network; means for receiving a response to the request from the second network device, the response including a root key for accessed network-based authentication of the user equipment; means for sending a registration response to the registration request to the user equipment, the registration response including an indication that accessed network-specific authentication is enabled for the user equipment; and means for authenticating the user equipment via the accessed network using the root key in response to the commencement of communication by the user equipment.

[0011] In a ninth aspect of this disclosure, a second network device is provided in the home network of a user equipment. The second network device includes: components for receiving a request for authentication of the user equipment based on the accessed network from a first network device in an accessed network of the user equipment; components for generating a root key for authentication of the user equipment based on the accessed network; and components for sending a response to the request to the first network device, the response including the root key.

[0012] In a tenth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing an apparatus to perform at least the methods according to the fourth, fifth, and sixth aspects.

[0013] It should be understood that the summary portion is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0014] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which: Figure 1 An example communication environment in which example embodiments of the present disclosure may be implemented is shown; Figure 2 Example diagrams are shown illustrating an authentication process between a user equipment and a network device in a communication system, according to some example embodiments of the present disclosure; Figure 3 An exemplary signaling flow for an authentication process based on an accessed network, according to some exemplary embodiments of this disclosure, is shown; Figures 4A to 4C Example signaling flows for some processes of authentication based on an accessed network according to some example embodiments of this disclosure are shown; Figure 5AAnother example signaling flow for an authentication process based on an accessed network, according to some example embodiments of this disclosure, is shown; Figure 5B Example diagrams for deriving a root key are shown according to some example embodiments of this disclosure; Figure 5C Example diagrams are shown for the range of serial numbers according to some example embodiments of the present disclosure; Figure 5D Example diagrams for deriving authentication vectors according to some example embodiments of this disclosure are shown; Figure 5E An exemplary signaling flow for another process of authentication based on an accessed network, according to some exemplary embodiments of this disclosure, is shown; Figures 6A to 6C Example signaling flows for some other processes for authentication based on an accessed network, according to some example embodiments of this disclosure, are shown; Figure 7 A flowchart is shown illustrating a method implemented at a user equipment according to some example embodiments of the present disclosure; Figure 8 A flowchart is shown illustrating a method implemented at a first network device in an accessed network of a user equipment according to some example embodiments of the present disclosure; Figure 9 A flowchart is shown illustrating a method implemented at a second network device in an accessed network of a user equipment according to some example embodiments of the present disclosure; Figure 10 A flowchart is shown illustrating a method implemented at a user equipment according to some example embodiments of the present disclosure; Figure 11 A flowchart is shown illustrating a method implemented at a first network device in an accessed network of a user equipment according to some example embodiments of the present disclosure; Figure 12 A flowchart is shown illustrating a method implemented at a second network device in the home network of a user equipment according to some example embodiments of the present disclosure; Figure 13 A flowchart is shown illustrating a method implemented at a user equipment according to some example embodiments of the present disclosure; Figure 14 A flowchart is shown illustrating a method implemented at a first network device in an accessed network of a user equipment according to some example embodiments of the present disclosure; Figure 15 A flowchart is shown illustrating a method implemented at a second network device in the home network of a user equipment according to some example embodiments of the present disclosure; Figure 16A flowchart is shown illustrating a method implemented at a user equipment according to some example embodiments of the present disclosure; Figure 17 A flowchart is shown illustrating a method implemented at a first network device in an accessed network of a user equipment according to some example embodiments of the present disclosure; Figure 18 A flowchart is shown illustrating a method implemented at a second network device in the home network of a user equipment according to some example embodiments of the present disclosure; Figure 19 A simplified block diagram of a device suitable for implementing example embodiments of the present disclosure is shown; and Figure 20 A block diagram of an example computer-readable medium according to some example embodiments of the present disclosure is shown.

[0015] Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0016] The principles of this disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described for illustrative purposes only and to help those skilled in the art to understand and implement this disclosure, without implying any limitation on the scope of this disclosure. The embodiments described herein can be implemented in various ways other than those described below.

[0017] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0018] References to "an embodiment," "an embodiment," "an example embodiment," etc., in this disclosure indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment includes that particular feature, structure, or characteristic. Furthermore, these phrases do not necessarily refer to the same embodiment. In addition, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is to be noted that those skilled in the art will recognize, whether explicitly described or not, that such features, structures, or characteristics apply in conjunction with other embodiments.

[0019] It should be understood that although terms such as "first," "second," etc., may be used before names (or similar designations) to describe various elements herein, these elements should not be limited by these terms. These terms are used only to distinguish one element from another, and they do not restrict the order of the nouns (or similar designations). For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0020] As used herein, “at least one of the following: ” and “at least one of ” and similar expressions, wherein the list of two or more elements is connected by “and” or “or”, means at least any one of these elements, or at least any two or more of these elements, or at least all of these elements.

[0021] As used herein, unless explicitly stated otherwise, the action “in response to A” does not indicate that the action is performed immediately after “A” occurs and may include one or more intervention steps.

[0022] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. As used herein, the singular forms “a,” “an,” and “the” are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the terms “comprising,” “including,” “having,” “possessing,” “containing,” and / or “covering,” as used herein, specify the presence of the stated features, elements, and / or components, but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0023] As used in this application, the term "circuit" may refer to one or more or all of the following: (a) Hardware circuit implementation only (e.g., implemented with purely analog and / or digital circuits) and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of (multiple) analog and / or digital hardware circuits and software / firmware, and (ii) Any part of a hardware processor having software (including (multiple) digital signal processors, software, and (multiple) memories, which work together to enable a device (such as a mobile phone or server) to perform various functions) and (c) The operation requires software (e.g., firmware) for the operation of (multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or parts thereof, but the software may be absent when the operation does not require the software.

[0024] This definition of "circuit" applies to all uses of the term in this application. As a further example, as used in this application, the term "circuit" also covers only hardware circuitry or processors (or processors), or portions of hardware circuitry or servers and their accompanying software and / or firmware implementations. For example, where applicable to certain claim elements, the term "circuit" also covers baseband integrated circuits or processor integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices, or other computing or networking devices.

[0025] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-A Advanced, Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in a communication network can be performed according to any suitable generation of communication protocol, including but not limited to, first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G), 5G Advanced, sixth-generation (6G) communication protocols, wireless LAN communication protocols (such as IEEE 802.11), and / or any other currently known or future protocols. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple Input Multiple Output (MIMO), Orthogonal Frequency Division Multiple Access (OFDM), Discrete Fourier Transform Extended OFDM (DFT-s-OFDM), and / or any other currently known or future-developed technology. Embodiments of this disclosure can be applied to a variety of communication systems. Given the rapid development of communication, future types of communication technologies and systems capable of implementing this disclosure will inevitably emerge. The scope of this disclosure should not be considered limited to the systems described above.

[0026] As used herein, the term "network device" refers to a node in a communications network through which a user equipment (UE) accesses the network and receives services. A network device can refer to a base station (BS) or access point (AP), such as a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), an NR NB (also known as a gNB), a Remote Radio Unit (RRU), a Radio Head (RH), a Remote Radio Head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low-power node (such as a femtosecond, picosecond, non-terrestrial network (NTN), or non-terrestrial network equipment (such as satellite network equipment, low Earth orbit (LEO) satellites and geostationary Earth orbit (GEO) satellites, spacecraft network equipment, etc.), depending on the terminology and technology applied. In some example embodiments, the Radio Access Network (RAN) separation architecture includes a centralized unit (CU) and a distributed unit (DU) at the IAB donor node. The IAB node includes a mobile terminal (IAB-MT) portion that behaves similarly to a UE toward its parent node, and the DU portion of the IAB node behaves similarly to a base station toward the next-hop IAB node.

[0027] The term "user equipment" refers to any terminal device capable of wireless communication. By way of example and not limitation, user equipment may also be referred to as user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). User equipment can include, but is not limited to, mobile phones, cellular phones, smartphones, Voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable user devices, personal digital assistants (PDAs), portable computers, desktop computers, image acquisition user equipment (such as digital cameras), gaming user devices, music storage and playback devices, in-vehicle wireless user equipment, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop installed devices (LME), Universal Serial Bus (USB) dongles, smart devices, wireless customer premises equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronics devices, devices operating on commercial and / or industrial wireless networks, etc. User equipment may also correspond to the mobile terminal (MT) portion of an IAB node (e.g., a relay node). In the following description, the terms "user equipment," "terminal equipment," "terminal," "user equipment," and "UE" are used interchangeably.

[0028] As used herein, the terms “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” can refer to any resource used to perform communication, such as communication between a user equipment and a network device, including resources in the time domain, frequency domain, spatial domain, code domain, or any other combination of time-domain, frequency-domain, spatial-domain, and / or code-domain resources used to implement communication. In the following, unless explicitly stated otherwise, resources in both the frequency and time domains will be used as examples of transmission resources used to describe some exemplary embodiments of this disclosure. It should be noted that the exemplary embodiments of this disclosure are equally applicable to other resources in other domains.

[0029] Figure 1 An example communication environment 100 in which example embodiments of the present disclosure may be implemented is shown. For example... Figure 1 As shown, the communication environment 100 may include an accessed network 125 and a home network 135. A user equipment 110 located within the accessed network 125 can operate as a UE. The accessed network 125 may also include a first network device 120, which can function as a Mobility Management Network Function (MM NF) or Access Management Function (AMF), where the AMF is responsible for handling user registration and session management tasks. The home network 135 may also include a second network device 130, which can function as an Authentication Server Function (AUSF), responsible for authenticating the user equipment 110 and ensuring secure communication.

[0030] In some example embodiments, the link from network device 120 (e.g., AMF) to user equipment 110 is referred to as a downlink (DL), and the link from user equipment 110 to network device 120 is referred to as an uplink (UL). In the DL, network device 120 is a transmitting (TX) device (or transmitter), and user equipment 110 is a receiving (RX) device (or receiver). In the UL, user equipment 110 is a TX device (or transmitter), and network device 120 is an RX device (or receiver).

[0031] It should be understood that Figure 1 The number or type of networks, user equipment, and network devices and their connections shown are for illustrative purposes only and do not impose any limitations. Communication environment 100 may include any suitable number or type of networks, user equipment, and network devices configured to implement some example embodiments.

[0032] In some cases, authentication based on the visited network 125 (i.e., authentication based on the visited network) may be necessary, without involving the home network 135. For example, in the event of a disaster where user equipment 110 has already been authenticated by the home network 135, the visited network 125 may need to re-authenticate user equipment 110 to provide a basic service level, independent of the home network 135. Alternatively, when user equipment 110 is not authenticated by the home network or is connecting to the visited network 125 for the first time, the visited network 125 may decide to authenticate user equipment 110 independently of the home network 135. In such cases, a service level agreement (SLA) between operators (e.g., between the visited network and the home network) may be necessary. Such examples could involve operators (such as Operator A) that operate in multiple countries and can choose to avoid home network authentication, opting instead for local authentication within the same country where roaming takes place. Furthermore, in satellite communication systems, for example as in a non-disaster scenario, each low Earth orbit (LEO) satellite can authenticate user equipment 110 without requiring any terrestrial gateway or home network connection. These use cases demonstrate the need for access-based authentication when home network participation may be impractical or unnecessary.

[0033] Figure 2 A communication process 200 involving a UE (e.g., user equipment 110) and various network elements (including a serving network (represented by an SN, e.g., an accessed network 125) and a home network (represented by an HE) 135) is illustrated. In this system, the UE (represented by a mobile device ME) can interact with both 3GPP and non-3GPP access networks (ANs) via a User Subscription Identity Module (USIM). The two “K” symbols “K” 201 and “K” 202 can represent long-term subscriber keys used in authentication and security processes. “K” 201 corresponds to a key that can be used to protect communication between the user equipment and the SN. “K” 202 represents a different key that can be used to protect communication between the SN and the HE. When the HE becomes unavailable or unreachable, the authentication process relying on “K” 202 may be impossible. In this case, accessed network-based authentication may be required, where the SN can take over the authentication responsibility without involving the HE.

[0034] According to some example embodiments, a solution for accessed network-based authentication is provided. In one solution, user equipment 110 sends a registration request to a first network device 120 in an accessed network 125 of user equipment 110. The registration request includes an indication that user equipment 110 supports accessed network-based authentication. The first network device 120 in the accessed network then sends a request for accessed network-based authentication for user equipment 110 to a second network device 130 in the home network 135 of user equipment 110 and receives a response to the request. The first network device 120 obtains a root key for accessed network-based authentication and uses the root key to authenticate user equipment 110 through the accessed network 120.

[0035] In this way, user equipment (UE) can obtain secure authentication within the visited network even when the home network may be unavailable. This ensures that UE can still access network services even when the UE's home network is temporarily inaccessible (such as during roaming or in disaster recovery). Using root keys for authentication enhances communication security, ensuring secure communication between UE and the visited network, while improving the overall efficiency and reliability of the authentication process based on the visited network.

[0036] Now for reference Figure 3 This illustrates an example signaling flow 300 of an authentication process based on an accessed network according to some example embodiments. The signaling flow 300 relates to a user equipment 110, a first network device 120 in an accessed network 125, and a second network device 130 in a home network 135.

[0037] like Figure 3 As shown, User Equipment 110 sends a (302) registration request to First Network Device 120, the registration request including an indication that the User Equipment supports accessed network-based authentication. Accordingly, First Network Device 120 receives a (304) registration request. In some examples, User Equipment 110 may send the registration request to First Network Device 120 via a Non-Access Stratum (NAS) message. In some example embodiments, in addition to the indication that User Equipment 110 supports accessed network-based authentication, the registration request may also include an indication of one or more accessed network-based authentication modes supported by User Equipment 110. The supported authentication method, which may be specified in the UE Capability field, may include the conventional Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) method or a new authentication method described in detail below.

[0038] First network device 120 sends (306) a request for accessed network-based authentication for the user equipment to second network device 130. Accordingly, second network device 130 receives (308) the request. In some examples, first network device 120 may identify second network device 130 based on, for example, subscription information of user equipment 110. First network device 120 may decide to use accessed network-based optimized authentication, depending on the service level agreement (SLA) between first network device 120 and second network device 130.

[0039] In some example embodiments, the first network device 120 may perform authentication of the user equipment 110 during registration or in response to the start of communication by the user equipment. For authentication performed by the first network device 120 during user equipment registration, the first network device 120 may send an authentication vector request to a second network device (e.g., MM NF or AUSF). The authentication vector may contain a set of parameters used to verify the identity of the user equipment 110 during the registration authentication process. In the request sent to the second network device 130, the first network device 120 may include an indication requesting authentication based on the accessed network. The second network device 130 may provide the authentication vector to the first network device 120 and wait for the completion of the full authentication process.

[0040] If user equipment 110 is authenticated and responds to receiving the request, the second network device 130 sends (310) a response to the request to the first network device 120. Accordingly, the first network device 120 receives (312) the response.

[0041] First network device 120 obtains (314) a root key for authentication of the user equipment based on the accessed network. In some example embodiments, the root key may be associated with the accessed network and user equipment 110. First network device 120 may obtain the accessed network-specific root key (K) via any suitable means. RT In some example embodiments, K RT It can be generated by the first network device 120. In some example embodiments, K RT This can be generated by the second network device 130 and sent from the second network device 130 to the first network device 110. In some examples, the second network device 130 can send K to the first network device 120. RT And anchor keys (e.g., secure anchor keys, K) SEAF Despite K SEAF and K RT They can be similar to each other, but they can serve different aspects of authentication. SEAFIt can be used as a long-term key for protecting communication between user equipment 110 and the home network, and can be used without being used to generate a root key associated with authentication based on the accessed network. On the other hand, K RT It can be used for key generation based on authentication of the accessed network. Security can be improved by limiting the long-term key K. SEAF Enhanced by exposure during subsequent key transfers.

[0042] K RT The root key can be derived using any suitable function. In some example embodiments, the root key may be specific to the accessed network. In some example embodiments, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key. In some example embodiments, the reference key may be an AUSF key, an AMF key, or a long-term key. Three example derivation methods / functions are described below, and K... RT From K AUSF Alternatively, it can be derived from a long-term key. It should be understood that the following methods are for illustrative purposes only and do not imply any limitations.

[0043] Using K AUSF Export K RK In the first method, the following parameters can be used to form the input S to the key derivation function (KDF): FC=0xXX; P0=<service network name>; L0=length of <service network name>; P1=<constant>; L1=length of <constant>.

[0044] The parameter FC can be set to a fixed value, 0xXX, which represents the function code. FC can also indicate the type of operation to be performed during cryptographic processing, such as key derivation or encryption. P0 can refer to the accessed network name, specifying the network that user equipment 110 can currently register with, and L0 can be the length of the accessed network name. P1 can be a constant, and L1 can be the length of the constant P1. The input key used for this derivation can be K. AUSF A long-term key for authentication purposes is shared between the second network device 130 (i.e., AUSF) and the user equipment 110. If a constant value is used, it can be a predefined fixed value between the user equipment 110 and the second network device 130 (i.e., AUSF), thereby ensuring consistent and secure authentication.

[0045] Using K AUSF Export K RK In the second method, the following parameters can be used to form the input S to the KDF: FC=0xXX; P0=<service network name>; L0=length of <service network name>; P1= <rand> ;L1= <rand>The length.

[0046] In this method, a random value can be used for P1 and L1. In some example embodiments, user equipment 110 may receive a constant used in the first method or a random value used in the method from the AUSF. The random value RAND may be sent to user equipment 110 via a User Plane Update (UPU) procedure or via normal signaling from the second network device 130 (i.e., the AUSF). The first network device 120 sends (316) a registration response to the registration request, and the registration response includes an indication to enable network-based authentication for user equipment 110. Accordingly, user equipment 110 receives (318) a registration response.

[0047] Exporting K using a long-term key that can be stored in a unified data management (UDM) RK In the third method, the following parameters can be used to form the input S to the KDF: FC=0xXX; P0=<service network name>; L0=length of <service network name>; P1= <rand>Or <constant>; L1= <rand>Or the length of a <constant>.

[0048] In some examples, the first network device 120 may store a root key for future use within the UE security context. If the user equipment 110 moves between areas within the same accessed network managed by different network functions (which may be referred to as mobility MM NFs), the stored root key may also be used by a target MM NF in the first network device 120 to ensure the continuity of authentication processes and secure communications based on the accessed network, despite the mobility of the user equipment 110 within the accessed network.

[0049] Return to reference Figure 3 The first network device 120 sends (316) a registration response to the registration request to the user equipment 110, and the registration response includes an indication that authentication based on the accessed network is enabled. Accordingly, the user equipment 110 receives (318) a registration response.

[0050] In some example embodiments, user equipment 110 may subsequently generate a root key K. RT This is used for user equipment authentication. In some example embodiments, user equipment 110 authentication may include authentication based on the accessed network. User equipment 110 may generate a root key by following any of the three key derivation functions described in detail above. In some example embodiments, the root key may be generated based on the name of the accessed network, the identifier of user equipment 110a, and a long-term key.

[0051] In some example embodiments, the first network device 120 may perform authentication of the user equipment 110 in response to the start of communication between the user equipment and the first network device 120. In response to the start of communication between the user equipment 110 and the first network device 120, the first network device 120 authenticates the user equipment 110 via the accessed network (320) using a root key, without involving the second network device 130.

[0052] In some examples, if user equipment 110 indicates in its registration request that it only supports the traditional EAP AKA authentication mode, then the first network device 120 can use the EAP method to authenticate user equipment 110. The first network device 120 can generate an authentication vector based on the root key and perform subsequent accessed network-based authentication for user equipment 110 based on the root key.

[0053] If authentication based on the accessed network is successful, to ensure the security of ongoing communication, a new key that may be shared between user equipment 110 and the first network device 120 can be generated and applied to encrypt and protect the communication. For example, user equipment 110 and the first network device 120 can generate a key named, for example, K. VPLMN The public key. The public key can be derived using any of the key derivation functions mentioned above, taking the root key as input. This public key can be used in secure command mode to refresh encryption and integrity protections during subsequent data exchange processes, thus ensuring that ongoing communication remains secure.

[0054] In some other examples, if user equipment 110 indicates that it supports a new authentication mode, which will be described in detail below, the new mode can be used to perform subsequent authentication based on the accessed network.

[0055] For new authentication modes based on the accessed network, in some example embodiments, the first network device 120 may send a new authentication message to the user equipment 110 via a NAS message. This message may contain temporary data or a string protected by root key integrity. The first network device 120 may also include a random value in the message to enhance security.

[0056] In some example embodiments, User Equipment 110 may use a root key to verify the integrity protection of the authentication message; and in response to successful verification, User Equipment 110 may generate an authentication response. In some example embodiments, the authentication message may contain temporary data that is integrity protected using the root key. In some examples, upon receiving an authentication message, User Equipment 110 may use the root key to verify the integrity of the temporary data. If the integrity check is successful, User Equipment 110 may authenticate the first network device 120. In some example embodiments, the authentication response prepared by User Equipment 110 may contain temporary data, and the temporary data is integrity protected and encrypted using the root key. In some examples, User Equipment 110 may subsequently prepare its response by encrypting the integrity of the same temporary data or by replaying the registration message initially sent in step 302. User Equipment 110 may deliver the authentication response to the first network device 120 via a NAS message.

[0057] Once the first network device 120 successfully verifies encryption and integrity protection, the user equipment 110 can be considered to have been authenticated by the accessed network.

[0058] One potentially advantageous option is that, after successful network-based authentication of user equipment 110 by the first network device 120, user equipment 110 and the first network device 120 can generate a public key, for example, named K. VPLMN The public key. This public key can be used in secure command mode to refresh encryption and integrity protection, thereby ensuring secure communication between user equipment 110 and the first network device 120.

[0059] In another solution for authentication based on the accessed network, on the network side, the root key can be generated by a second network device 130 in the home network 135 of user equipment 110. For example, after a registration request from user equipment 110 is authenticated, the second network device 130 in the home network 135 generates a root key and sends the generated root key to a first network device 120 in the accessed network 125. User equipment 110 also generates a root key. The first network device 120 uses the root key to authenticate user equipment 110 through the accessed network.

[0060] This solution reduces reliance on the home network, enabling the first network device 120 to locally authenticate user equipment (UE) within the accessed network, even when the UE's home network is temporarily inaccessible, such as during roaming or in disaster recovery situations. Using a root key for authentication enhances communication security, ensuring secure communication between the UE and the accessed network, while improving the overall efficiency and reliability of the accessed network-based authentication process.

[0061] Now for reference Figure 4A This illustrates an example signaling flow 400 A for an authentication process based on an accessed network according to some example embodiments. Signaling flow 400 A relates to user equipment 110, a first network device 120 in the accessed network 125, and a second network device 130 in the home network 135.

[0062] like Figure 4A As shown, user equipment 110 sends a (402) registration request to first network device 120, the registration request including an indication that the user equipment supports accessed network-based authentication. Accordingly, first network device 120 receives a (404) registration request. In some example embodiments, the registration request may include an indication of one or more authentication modes supported by user equipment 110. In some example embodiments, in addition to the indication that user equipment 110 supports accessed network-based authentication, the registration request may also include an indication of one or more accessed network-based authentication modes supported by user equipment 110.

[0063] First network device 120 sends (406) a request for authentication of the user equipment based on the accessed network to second network device 130. Accordingly, second network device 130 receives (408) the request.

[0064] The second network device 130 generates (410) a root key for authentication of the user equipment based on the accessed network. In some example embodiments, the root key may be specific to the accessed network. In some example embodiments, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key. In some example embodiments, the reference key may be an authentication server function (i.e., K...). AUSF The key or long-term key. (Already referenced) Figure 3 The root key generation process and related key derivation functions have been described in detail, and will not be repeated here.

[0065] The second network device 130 sends (412) a response to the request to the first network device 120, and the response includes a root key generated for authentication of the user equipment 110 based on the accessed network. Accordingly, the first network device 120 receives (414) the response. In some example embodiments, the first network device 120 may store the root key so that the root key can be used for further authentication of the user equipment 110. The user equipment 110 also generates (419) a root key for authentication of the user equipment 110 based on the accessed network.

[0066] The first network device 120 sends (416) a registration response to the registration request to the user equipment 110, and the registration response includes an instruction to enable network-based authentication for the user equipment 110. Accordingly, the user equipment 110 receives (418) a registration response.

[0067] In response to the commencement of communication by user equipment 110, first network device 120 authenticates user equipment 110 via the accessed network using a root key (420). In some example embodiments, first network device 120 may send an authentication message to user equipment 110, and correspondingly, user equipment 110 may receive the authentication message. In some example embodiments, the authentication message may be integrity protected using the root key. In some example embodiments, the authentication message may contain temporary data, and the temporary data may be integrity protected using the root key.

[0068] In some example embodiments, user equipment 110 may send an authentication response to the authentication message to first network device 120, and first network device 120 may receive the authentication response. In some example embodiments, the authentication response may be integrity-protected and encrypted using a root key. In some example embodiments, the authentication response may contain the same temporary data, and the temporary data may be integrity-protected using the root key.

[0069] In some example embodiments, the first network device 120 can verify the integrity protection and encryption of the authentication response by authenticating the user equipment 110 using a root key. In some example embodiments, if the authentication is successful, the first network device 120 can determine that the user equipment 110 has been authenticated.

[0070] Authentication messages and responses can be delivered in any suitable manner. In some example embodiments, authentication messages and responses may be delivered via NAS messages.

[0071] It should be understood, as referenced above Figure 3 The features and operations described in relation to user equipment 110, first network device 120, and second network device 130 also apply to Figure 4A The process described above has a similar effect. For the sake of simplicity, its details will not be repeated.

[0072] The following will refer to Figure 4B Example procedure 400 B for authentication based on the accessed network is described. In this example, UE 401 is an example of user equipment 110, VPLMN 403 is an example of a first network device 120 in the accessed network of the user equipment, and HPLMN 404 is an example of a second network device 130 in the home network of the user equipment.

[0073] UE 401 may send a (421) registration request to VPLMN 403, indicating that it supports VPLMN-based authentication methods, such as EAP AKA or a new authentication method. Upon receiving this request, VPLMN 403 may send a (422) authentication vector request to HPLMN 404, also indicating a request for VPLMN-based authentication. In response, HPLMN 404 may send (423) the requested authentication vector to VPLMN 403.

[0074] Upon receiving the authentication vector, VPLMN 403 can perform the (424) registration authentication process. VPLMN 404 can generate (424A) a VPLMN-specific root key (i.e., K). RT HPLMN 404 can send (425A) the VPLMN-specific root key and anchor key K to VPLMN 403. SEAF .

[0075] VPLMN 403 may send a registration response (425B) to UE 401, and the response may include an instruction to enable VPLMN-specific authentication for UE 401. Following this, VPLMN 403 may initiate (427) communication with UE 401 and decide (428) to perform further authentication steps. In response to the initiation of communication between UE 401 and VPLMN 403, VPLMN 403 may perform (429) EPA authentication to authenticate UE 401 for subsequent EPA authentication; the authentication vector may be generated based on the root key.

[0076] The following will refer to Figure 4C Describes an example process for authentication based on the accessed network 400 C.

[0077] UE 401 may send a (451) registration request to VPLMN 403, indicating its support for VPLMN-based authentication methods, such as EAP AKA or a new authentication method. Upon receiving this request, VPLMN 403 may send a (452) authentication vector request to HPLMN 404, also indicating a request for VPLMN-based authentication. In response, HPLMN 404 may send (453) the requested authentication vector to VPLMN 403.

[0078] Upon receiving the authentication vector, VPLMN 403 can perform the (454) registration authentication process. VPLMN 403 can perform the (454) registration authentication process. HPLMN 404 can generate (454A) a VPLMN-specific root key (i.e., K). RT The HPLMN404 can send (455A) the VPLMN-specific root key and anchor key K to the VPLMN 403. SEAF .

[0079] VPLMN 403 may send a (455B) registration response to UE 401, and the response may include an instruction to enable VPLMN-specific authentication for UE 401. UE 401 may generate (455C) a VPLMN-specific root key. VPLMN 403 may store (456) the VPLMN-specific root key.

[0080] Following this, VPLMN 403 may begin (457) communication with UE 401. VPLMN 403 may decide (458) to perform further authentication steps, and VPLMN 403 may decide (459) to use SMC-based implicit authentication. In this case, VPLMN 403 sends (460) a new authentication message to UE 401, which includes temporary data that is integrity protected and encrypted using a new key.

[0081] UE 401 can use the new key to verify (461) the received message. If the verification is successful, UE 401 can respond by encrypting the same data and sending it back. UE 401 can send (462) a new authentication response to VPLMN 403, which includes temporary data that is again protected with integrity and encrypted using the new key.

[0082] VPLMN 403 can check whether the (464) integrity protection and encryption checks are successful. If these checks pass, the UE 401 can be considered certified.

[0083] In another solution for authentication based on the accessed network, authentication for user equipment 110 registration is performed by a first network device 120 in the accessed network 125, rather than a second network device 130 in the home network 135. For example, the second network device 130 sends both the generated root key and the obtained sequence number range to the first network device 120 in the accessed network. The first network device 120 in the accessed network then generates an authentication vector based on the root key and the sequence number range, and authenticates user equipment 110 through the accessed network using the authentication vector.

[0084] Similar to other solutions, this solution also provides an efficient and flexible method for authenticating user equipment (UEs) within the accessed network, reducing reliance on the home network used for the authentication process. This can be advantageous when the local network is temporarily inaccessible, as the first network device can independently authenticate UEs, ensuring continuous service. The solution grants the first network device in the accessed network greater autonomy by enabling it to perform both registration authentication and authentication for subsequent communication between the UE and the accessed network. From a security perspective, by utilizing sequence number ranges along with the root key used for authentication, the solution ensures the correct ordering of authentication messages, preventing replay attacks. This further enhances the security of accessed network-based authentication.

[0085] Now for reference Figure 5A This illustrates an example signaling flow 500 A for an authentication process based on an accessed network according to some example embodiments. Signaling flow 500 A relates to user equipment 110, a first network device 120 in the accessed network 125, and a second network device 130 in the home network 135.

[0086] like Figure 5A As shown, user equipment 110 transmits a registration request (502) to first network device 120, the registration request including an indication that the user equipment supports accessed network-based authentication. Accordingly, first network device 120 receives the registration request (504). In some example embodiments, the registration request may include an indication of one or more authentication modes supported by user equipment 110. In some example embodiments, in addition to the indication that user equipment 110 supports accessed network-based authentication, the registration request may also include an indication of one or more accessed network-based authentication modes supported by user equipment 110.

[0087] First network device 120 sends (506) a request for authentication of the user equipment based on the accessed network to second network device 130. Accordingly, second network device 130 receives (508) the request.

[0088] The second network device 130 generates (510) a root key for authentication of the user equipment based on the accessed network. In some example embodiments, the root key may be specific to the accessed network. In some example embodiments, the root key may be generated based on the name of the accessed network, the identifier of the user equipment 110, and a long-term key.

[0089] Figure 5B Example procedure 500 B for generating the root key of a service network (SN) is shown. Figure 5B As shown, generation may involve using three key inputs: a long-term key, a serving network name (SNN), and a subscription persistent identifier (SUPI). These three inputs can be provided to the KDF. The KDF can be defined in any suitable manner, and the KDF can combine these input elements in a defined way to derive the SN root key, which can be used in subsequent authentication processes. The long-term key can serve as the basic security element, while the SNN and SUPI can be used to identify the serving network (e.g., the accessed network) and the user equipment (e.g., user equipment 110), respectively.

[0090] The second network device 130 obtains (512) a range of serial numbers for authentication based on the accessed network from the user equipment 110. In some example embodiments, the range may be specific to the accessed network. Figure 5C Figure 500C shows a series of sequence numbers (SQNs) ranging from SQN[0] to SQN

[47] for network authentication across different generations. SQNs can be divided into segments corresponding to various network generations, such as 6G, 5G, 4G, 3G, and 2G. Each range can represent the allocation of sequence numbers for authentication purposes associated with different network generations.

[0091] Figure 500 C shows an example of a range for an SN, where a specific SQN range is assigned to each SN authentication. Even for HN authentication (Home Network Authentication), a dedicated SQN range is assigned. This range is pre-agreed between the USIM (User Subscription Identity Module) and the UDM. The MM NF receives its assigned SQN range and root key from the HN, enabling the network to securely perform the necessary authentication process. Authentication can be triggered for different networks using specific SQN ranges, such as SQN

[25] -SQN

[29] for SN#1 authentication. Additionally, SQN

[20] -SQN

[24] can be assigned for HN authentication. The sequence number within each range can be used to manage the authentication process and prevent replay attacks by ensuring that each authentication message is uniquely identified and processed in sequence.

[0092] The second network device 130 sends (514) a response to the request to the first network device 120, and the response includes a generated root key and a range of authentication numbers for the user equipment 110 based on the accessed network. Accordingly, the first network device 120 receives (516) the response.

[0093] The first network device 120 generates an authentication vector (518) based on the root key and a range of numbers. The authentication vector can be generated in any suitable manner. As an example, Figure 5D Example procedure 500 D for authentication vector generation is shown. The received root key (from the home network's KRT) and sequence number range can be two input elements used for generation. The SQN value can increment with each user equipment authentication to ensure a unique sequence for each authentication, thus preventing replay attacks and maintaining security. This sequence number range is essential for SN-triggered authentication, providing secure and ordered processing for each SN.

[0094] The authentication generation process can use other input elements, including RAND (random number), AMF, SQN, etc., such as MAC (Message Authentication Code), XRES (Expected Response), CK (Encryption Key), and IK (Integrity Key), as input to the cryptographic functions (F1-F5). These inputs can be used to generate an authentication vector, which can be sent to user equipment 110 as part of an AKA challenge. User equipment 110 responds to the challenge, and MM NF verifies the response used to authenticate the device.

[0095] As can be seen, it is possible to base it on the root key instead of using the HN key (such as K). AUSF This option allows the first network device 120 in the accessed network to independently authenticate the user equipment 110 for limited services, such as when the accessed network does not require or supports the UPU or SoR (signaling for re-authentication) process. By bypassing the need for an HN key, this process simplifies authentication and can make it more efficient for specific service use cases.

[0096] Furthermore, SEAF can be deployed within a VPLMN as a potential network function responsible for generating AKA challenges. In some embodiments, SEAF can be co-located with MM NF or AMF to further enhance the authentication process and maintain robust security within the accessed network.

[0097] The first network device 120 authenticates the accessed network (520) user device 110 by using an authentication vector.

[0098] In response to user equipment 110 being authenticated, first network device 120 sends (522) a registration response to user equipment 110 for the registration request, the registration response including an indication that authentication specific to the accessed network is enabled for the user equipment. Accordingly, user equipment 110 receives (524) a registration response.

[0099] In some example embodiments, the first network device 120 may store a root key. In some example embodiments, the user equipment 110 may generate a root key for further authentication of the user equipment 110.

[0100] In response to the commencement of communication between user equipment 110 and first network device 120, first network device 120 sends an authentication message (526) to user equipment 110, and user equipment 110 receives an authentication message (528) accordingly. In some example embodiments, the authentication message may be integrity protected using a root key. In some example embodiments, the authentication message may contain temporary data, and the temporary data may be integrity protected using a root key.

[0101] User equipment 110 sends (530) an authentication response to the authentication message to first network device 120, and first network device 120 receives (532) the authentication response. In some example embodiments, the authentication response may be integrity protected and encrypted using a root key. In some example embodiments, the authentication response may contain the same temporary data, and the temporary data may be integrity protected using a root key.

[0102] It should be understood, as referenced above Figure 3 The features and operations described in relation to user equipment 110, first network device 120, and second network device 130 also apply to Figure 5A The process described above has a similar effect. For the sake of simplicity, its details will not be repeated.

[0103] The following will refer to Figure 5E A sample process 500E for authentication based on the accessed network is described. In this example, UE 401 is an example of user equipment 110, VPLMN 403 is an example of a first network device 120 in the accessed network of the user equipment, and HPLMN 404 is an example of a second network device 130 in the home network of the user equipment.

[0104] UE 401 may send a (571) registration request to VPLMN 403, indicating that it supports VPLMN-based authentication methods, such as EAP AKA or a new authentication method. Upon receiving this request, VPLMN 403 may send a (572) authentication vector request to HPLMN 404, also indicating a request for VPLMN-based authentication. HPLMN 404 may generate (573) a VPLMN-specific root key. HPLMN 404 may send a (574) response to VPLMN 403, and the response may include the generated root key and a range of numbers associated with VPLMN 403.

[0105] VPLMN 403 can generate an authentication vector using a root key and a range of numbers. VPLMN 403 can use the authentication vector to perform (575A) authentication. After successful authentication, VPLMN 403 can send a (575B) registration acceptance instruction to UE 401, signaling that VPLMN-specific authentication has been enabled.

[0106] UE 401 can generate (575C) a VPLMN-specific root key, and VPLMN 403 can store the VPLMN-specific root key for future use. After this, VPLMN 403 can begin (577) communication with UE 401.

[0107] In another solution for accessed network-based authentication, the root key is generated by a first network device 120 in accessed network 125. For example, after a registration request from user equipment 110 is authenticated, a second network device 130 in home network 135 sends an instruction to the first network device 120 in accessed network 125 allowing accessed network-based authentication.

[0108] After receiving the instruction, the first network device 120 generates a root key and uses the root key to authenticate the user equipment 110 through the accessed network for subsequent communication between the user equipment 110 and the first network device 120 in the accessed network.

[0109] This solution enhances authentication efficiency by enabling the first network device in the accessed network to autonomously handle network-based authentication. By allowing the first network device to generate the root key, the solution reduces reliance on the home network used for authentication.

[0110] Now for reference Figure 6A This illustrates an example signaling flow 600 A for an authentication process based on an accessed network according to some example embodiments. Signaling flow 600 A relates to user equipment 110, a first network device 120 in an accessed network 125, and a second network device 130 in a home network 135.

[0111] like Figure 6A As shown, user equipment 110 transmits a registration request (602) to first network device 120, the registration request including an indication that the user equipment supports accessed network-based authentication. Accordingly, first network device 120 receives the registration request (604). In some example embodiments, the registration request may include an indication of one or more authentication modes supported by user equipment 110. In some example embodiments, in addition to the indication that user equipment 110 supports accessed network-based authentication, the registration request may also include an indication of one or more accessed network-based authentication modes supported by user equipment 110.

[0112] First network device 120 sends (606) a request for authentication of the user equipment based on the accessed network to second network device 130. Accordingly, second network device 130 receives (608) the request.

[0113] The second network device 130 sends (610) a response to the request to the first network device 120, and the response includes an indication allowing accessed network-based authentication for user equipment 110. Accordingly, the first network device 120 receives (612) the response. In some examples, if user equipment 110 is authenticated and if the SLA between the first network device 120 and the second network device 130 allows accessed network-based authentication, the second network device 130 may send an indication to the first network device 120 to perform accessed network-based authentication along with an anchor key.

[0114] The second network device 130 generates (614) a root key for authentication of the user equipment 110 based on the accessed network. In some example embodiments, the root key may be specific to the accessed network. In some example embodiments, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key. In some example embodiments, the reference key may be an AMF key. K can be derived using any suitable function. RT The following are example methods for generating the root key. It should be understood that the methods listed below are for illustrative purposes only and do not imply any limitations.

[0115] Using K AMF Export K RK In the first method, the following parameters can be used to form the input S to the key derivation function (KDF): FC = 0xXX; P1 = <constant>; L1 = length of <constant>. The input key used for derivation can be K. AMF If a constant value is used, it can be a predefined fixed value between user equipment 110 and the first network device 120 (i.e., AMF), thereby ensuring consistent and secure authentication.

[0116] Using K AMF Export K RK In the second method, the following parameters can be used to form the input S to the KDF: FC=0xXX; P1= <rand> ;L1= <rand>The length.

[0117] The random value RAND can be sent from the first network device 120 (i.e., AMF) to the user equipment 110 via the user plane update (UPU) process or through normal signaling.

[0118] The first network device 120 sends (616) a registration response to the registration request to the user equipment 110, and the registration response includes an instruction to enable network-based authentication for the user equipment 110.

[0119] In some example embodiments, the first network device 120 may store a root key.

[0120] In response to the commencement of communication by user equipment 110, first network device 120 authenticates user equipment 110 via the accessed network using a root key (620). First network device 120 sends (622) an authentication message, and user equipment 110 receives (624) the authentication message. In some example embodiments, the authentication message may be integrity protected using the root key. In some example embodiments, the authentication message may contain temporary data, and the temporary data may be integrity protected using the root key.

[0121] User equipment 110 sends an authentication response (626) to first network device 120, and first network device 120 receives an authentication response (628). In some example embodiments, the authentication response may be integrity protected and encrypted using a root key. In some example embodiments, the authentication response may contain the same temporary data, and the temporary data may be integrity protected using a root key.

[0122] In some example embodiments, the first network device 120 may authenticate the user equipment 110 by using a root key to verify the integrity protection and encryption of the authentication response. In some example embodiments, if the verification is successful, the first network device 120 may determine that the user equipment 110 has been authenticated.

[0123] Authentication messages and responses can be delivered in any suitable manner. In some example embodiments, authentication messages and responses may be delivered via NAS messages.

[0124] It should be understood, as referenced above Figure 3 The features and operations described in relation to user equipment 110, first network device 120, and second network device 130 also apply to Figure 6A The process described above has a similar effect. For the sake of simplicity, its details will not be repeated.

[0125] The following will refer to Figure 6B A sample process 600 B is described for authentication based on the accessed network. In this example, UE 401 is an example of user equipment 110, VPLMN 403 is an example of a first network device 120 in the accessed network of the user equipment, and HPLMN 404 is an example of a second network device 130 in the home network of the user equipment.

[0126] UE 401 may send a (631) registration request to VPLMN 403, indicating its support for VPLMN-based authentication methods, such as EAP AKA or a new authentication method. Upon receiving the registration request, VPLMN 403 may send a (632) authentication vector request to HPLMN 404, requesting VPLMN-based authentication. In response to this request, HPLMN 404 may then provide an (633) authentication vector.

[0127] Once the authentication vector is received, VPLMN 403 can use the provided vector to perform (634) authentication. HPLMN 404 can send a (635A) response to VPLMN 403, which may include the anchor key and an indication that VPLMN-specific authentication is allowed. VPLMN 403 can send a (635B) registration acceptance indication to UE 401, confirming that VPLMN-specific authentication is enabled.

[0128] UE 401 can generate (635C) a VPLMN-specific root key. VPLMN 403 can store (636) the VPLMN-specific root key. VPLMN 403 can initiate (637) communication with UE 401.

[0129] In response to the commencement of communication, VPLMN 403 may decide (638) to perform authentication. VPLMN 403 may send an authentication message to UE 401, and UE 401 may send a new authentication response (639) to VPLMN 403. The new authentication message may include temporary data, which may be integrity protected and encrypted using a newly generated key.

[0130] The following will refer to Figure 6C A sample process 600C for authentication based on the accessed network is described. In this example, UE401 is an example of user equipment 110, VPLMN 403 is an example of a first network device 120 in the accessed network of the user equipment, and HPLMN 404 is an example of a second network device 130 in the home network of the user equipment.

[0131] UE 401 may send a (651) registration request to VPLMN 403, indicating that it supports VPLMN-based authentication methods, such as EAP AKA or a new authentication method. Upon receiving the registration request, VPLMN 403 may send a (652) authentication vector request to HPLMN 404, requesting VPLMN-based authentication. In response to this request, HPLMN 404 may then provide an (653) authentication vector.

[0132] Once the authentication vector is received, VPLMN 403 can use the provided vector to perform (654) authentication. HPLMN 404 can send a response to VPLMN 403, which may include the anchor key and an indication that VPLMN-specific authentication is allowed. VPLMN 403 can send a (655B) registration acceptance indication to UE 401, confirming that VPLMN-specific authentication is enabled.

[0133] UE 401 can generate (655C) a VPLMN-specific root key. VPLMN 403 can store (656) the VPLMN-specific root key. VPLMN 403 can initiate (657) communication with UE 401.

[0134] In response to the commencement of communication, VPLMN 403 may decide (658) to perform authentication. VPLMN 403 may decide (959) to use SMC-based implicit authentication. VPLMN 403 may send an authentication message (660) to UE 401. UE 401 may use the new key to verify (661) the received message. If the verification is successful, UE 401 responds by encrypting the same data and sending it back to VPLMN 403. VPLMN 403 then sends a new authentication response (662) to UE 401, which includes temporary data that is again protected for integrity and encrypted with the new key.

[0135] VPLMN 403 can check whether the integrity protection and encryption checks (664) are successful. If these checks pass, UE 401 can be considered authenticated, and the authentication process can be completed.

[0136] Figure 7 A flowchart of an example method 700 implemented at a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 700 is described from the perspective of user equipment 110.

[0137] At box 710, user equipment 110 sends a registration request to a first network device in the network accessed by the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0138] At box 720, user equipment 110 receives a registration response from a first network device in response to a registration request, the registration response including an indication that network-specific authentication has been enabled for the user equipment.

[0139] In some example embodiments, user equipment 110 may generate a root key to be used for authentication of the user equipment.

[0140] In some example embodiments, authentication of a user equipment may include authentication of the user equipment based on the accessed network.

[0141] In some example embodiments, the registration request may also include an indication of one or more authentication modes based on the accessed network, supported by the user equipment.

[0142] In some example embodiments, user equipment 110 may receive authentication messages from network devices; and user equipment 110 may send authentication responses to network devices in response to authentication messages, wherein the authentication responses are protected for integrity and encrypted by a root key.

[0143] In some example embodiments, user equipment 110 may use a root key to verify the integrity protection of authentication messages; and in response to successful verification, user equipment 110 may generate an authentication response.

[0144] In some example implementations, the authentication message may contain temporary data, and the temporary data may be protected for integrity using the root key.

[0145] In some example implementations, the authentication response may contain temporary data, and the temporary data may be protected for integrity and encrypted using the root key.

[0146] In some example implementations, authentication messages and authentication responses may be delivered via Non-Access Stratum (NAS) messages.

[0147] In some example implementations, the root key may be specific to the accessed network.

[0148] In some example implementations, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key.

[0149] In some example embodiments, user equipment 110 may receive constant or random values ​​from the authentication server function.

[0150] In some example implementations, the reference key may be a key for authentication server functions, a key for access management functions, or a long-term key.

[0151] In some example implementations, the root key may be generated based on the name of the accessed network, the identifier of the user equipment, and a long-term key.

[0152] In some example embodiments, a user device capable of performing any of the methods in method 700 (e.g., Figure 1 The user equipment 110 may include components for performing corresponding operations of method 700 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The user equipment may be implemented as or included in Figure 1 In user equipment 110.

[0153] Figure 8 A flowchart of an example method 800 implemented at a first network device according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 800 is described from the perspective of the first network device 120 in the middle.

[0154] At box 810, the first network device 120 receives a registration request from the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0155] At box 820, the first network device 120 sends a request for authentication of the user equipment based on the accessed network to the second network device in the home network of the user equipment.

[0156] At box 830, the first network device 120 receives a response to the request from the second network device.

[0157] At box 840, the first network device 120 obtains a root key for authentication based on the accessed network for the user equipment.

[0158] At box 850, the first network device 120 authenticates the user device through the accessed network by using a root key.

[0159] In some example embodiments, the root key may be received from a second network device or generated by a first network device.

[0160] In some example implementations, the root key may be associated with the accessed network and user equipment.

[0161] In some example embodiments, authentication may be performed during the registration of the user equipment or in response to the start of communication by the user equipment.

[0162] In some example embodiments, a first network device in the accessed network of any user device capable of performing method 800 (e.g., Figure 1 The first network device 120 may include components for performing corresponding operations of method 800 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The first network device may be implemented as or included in Figure 1 The first network device in the network is 120.

[0163] Figure 9 A flowchart illustrating an example method 900 implemented at a second network device in an accessed network of a user equipment, according to some example embodiments of the present disclosure, is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 900 is described from the perspective of the second network device 130 in the middle.

[0164] At box 910, the second network device 130 receives a request for authentication of the user equipment based on the accessed network from the first network device in the user equipment's home network.

[0165] At box 920, the second network device 130 sends a response to the first network device in response to the request.

[0166] In some example embodiments, a second network device in the accessed network of any user device capable of performing method 900 (e.g., Figure 1 The second network device 130 may include components for performing corresponding operations of method 900 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The second network device may be implemented as or included in... Figure 1 The second network device 130 in the system.

[0167] Figure 10 A flowchart of an example method 1000 implemented at a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1000 is described from the perspective of user equipment 110.

[0168] At box 1010, user equipment 110 sends a registration request to a first network device in the network accessed by the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0169] At box 1020, user equipment 110 generates a root key to be used for authentication based on the accessed network for the user equipment.

[0170] In some example embodiments, the registration request may also include an indication of one or more authentication modes based on the accessed network, supported by the user equipment.

[0171] In some example embodiments, user equipment 110 may receive authentication messages from network devices; and user equipment 110 may send authentication responses to network devices in response to authentication messages, wherein the authentication responses are protected for integrity and encrypted using a root key.

[0172] In some example embodiments, user equipment 110 may use a root key to verify the integrity protection of authentication messages; and in response to successful verification, user equipment 110 may generate an authentication response.

[0173] In some example implementations, the authentication message may contain temporary data, and the temporary data is protected for integrity using the root key.

[0174] In some example implementations, the authentication response may contain temporary data, and the temporary data is protected for integrity and encrypted using the root key.

[0175] In some example implementations, authentication messages and authentication responses may be delivered via Non-Access Stratum (NAS) messages.

[0176] In some example implementations, the root key may be specific to the accessed network.

[0177] In some example implementations, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key.

[0178] In some example embodiments, user equipment 110 may receive constant or random values ​​from the authentication server function.

[0179] In some example implementations, the reference key may be a key for the authentication server function or a long-term key.

[0180] In some example embodiments, a user device capable of performing any of the methods in method 1000 (e.g., Figure 1 The user equipment 110 may include components for performing corresponding operations of method 1000 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The user equipment may be implemented as or included in Figure 1 In user equipment 110.

[0181] Figure 11 A flowchart illustrating an example method 1100 implemented at a first network device in an accessed network of a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1100 is described from the perspective of the first network device 120 in the middle.

[0182] At box 1110, the first network device 120 receives a registration request from the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0183] At box 1120, the first network device 120 sends a request for authentication of the user equipment based on the accessed network to the second network device in the home network of the user equipment.

[0184] At box 1130, the first network device 120 receives a response to the request from the second network device, the response including a root key for authentication of the user equipment based on the accessed network.

[0185] At box 1140, the first network device 120 sends a registration response to the user equipment in response to the registration request, the registration response including an indication that network-specific authentication has been enabled for the user equipment.

[0186] At box 1150, in response to the start of communication by the user equipment, the first network device 120 authenticates the user equipment through the accessed network by using a root key.

[0187] In some example embodiments, the registration request may also include an indication of one or more authentication modes supported by the user equipment.

[0188] In some example implementations, the root key may be specific to the accessed network.

[0189] In some example embodiments, the first network device 120 may also be configured to store a root key.

[0190] In some example embodiments, the first network device 120 can send authentication messages to the user equipment; can receive authentication responses to the authentication messages from the user equipment; and can use a root key to verify the integrity protection and encryption of the authentication responses to authenticate the user equipment.

[0191] In some example embodiments, the authentication response may be protected for integrity and encrypted using the root key, and in response to successful authentication, the first network device 120 may determine that the user equipment has been authenticated.

[0192] In some example implementations, authentication messages can be protected for integrity using a root key.

[0193] In some example implementations, the authentication message may contain temporary data, and the temporary data is protected for integrity using the root key.

[0194] In some example implementations, the authentication response may contain temporary data, and the temporary data is protected for integrity and encrypted using the root key.

[0195] In some example implementations, authentication messages and authentication responses may be delivered via Non-Access Stratum (NAS) messages.

[0196] In some example embodiments, a first network device in the accessed network of any user device capable of performing method 1100 (e.g., Figure 1 The first network device 120 in the accessed network of the user equipment may include components for performing corresponding operations of method 1100 and any embodiment thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The first network device in the accessed network of the user equipment may be implemented as or included in Figure 1 The first network device in the network is 120.

[0197] Figure 12 A flowchart illustrating an example method 1200 implemented at a second network device in the home network of a user equipment, according to some example embodiments of the present disclosure, is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1200 is described from the perspective of the second network device 130 in the middle.

[0198] At box 1210, the second network device 130 receives a request for network-based authentication of the user equipment from the first network device in the accessed network of the user equipment.

[0199] At box 1220, the second network device 130 generates a root key for authentication of the user equipment based on the accessed network.

[0200] At box 1230, the second network device 130 sends a response to the first network device in response to the request, the response including the root key.

[0201] In some example implementations, the root key may be specific to the accessed network.

[0202] In some example implementations, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key.

[0203] In some example implementations, the reference key may be a key for the authentication server function or a long-term key.

[0204] In some example embodiments, a second network device in the home network of any user equipment capable of performing method 1200 (e.g., Figure 1 The second network device 130 in the user equipment's home network may include components for performing corresponding operations of method 1200 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The second network device in the user equipment's home network may be implemented as or included in... Figure 1 The second network device 130 in the system.

[0205] Figure 13 A flowchart of an example method 1300 implemented at a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1300 is described from the perspective of user equipment 110.

[0206] At box 1310, user equipment 110 sends a registration request to a first network device in the network accessed by the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0207] At frame 1320, user equipment 110 receives an authentication message from the first network device.

[0208] At box 1330, user equipment 110 sends an authentication response to the authentication message to the first network device.

[0209] At box 1340, user equipment 110 receives a registration response from a first network device in response to a registration request, the registration response including an indication that network-specific authentication has been enabled for the accessed network.

[0210] In some example embodiments, the registration request may also include an indication of one or more authentication modes based on the accessed network, supported by the user equipment.

[0211] In some example embodiments, user equipment 110 may generate a root key to be used for further authentication of the user equipment.

[0212] In some example implementations, the root key may be specific to the accessed network.

[0213] In some example implementations, the root key may be generated based on the name of the accessed network, the identifier of the user equipment, and a long-term key.

[0214] In some example embodiments, a user device capable of performing any of the methods in method 1300 (e.g., Figure 1 The user equipment 110 may include components for performing corresponding operations of method 1300 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The user equipment may be implemented as or included in Figure 1 In user equipment 110.

[0215] Figure 14 A flowchart illustrating an example method 1400 implemented at a first network device in an accessed network of a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1400 is described from the perspective of the first network device 120 in the middle.

[0216] At box 1410, the first network device 120 receives a registration request from the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0217] At box 1420, the first network device 120 sends a request for authentication of the user equipment based on the accessed network to the second network device in the home network of the user equipment.

[0218] At box 1430, the first network device 120 receives a response to the request from the second network device, the response including a root key for the user equipment’s access network-based authentication and a range of serial numbers for the user equipment’s access network-based authentication.

[0219] At box 1440, the first network device 120 generates an authentication vector based on the root key and the number range.

[0220] At box 1450, the first network device 120 authenticates the user device through the accessed network by using an authentication vector.

[0221] At box 1460, in response to the user equipment being authenticated, the first network device 120 sends a registration response to the user equipment in response to the registration request, the registration response including an indication that network-specific authentication has been enabled for the user equipment.

[0222] In some example embodiments, the registration request may also include an indication of one or more authentication modes supported by the user equipment.

[0223] In some example implementations, the root key may be specific to the accessed network.

[0224] In some example embodiments, the number range may be specific to the accessed network.

[0225] In some example embodiments, the first network device may store the root key.

[0226] In some example embodiments, a first network device in the accessed network of any user device capable of performing method 1400 (e.g., Figure 1 The first network device 120 in the network may include components for performing corresponding operations of method 1400 and any embodiment thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The first network device in the accessed network of the user equipment may be implemented as or included in Figure 1 The first network device in the network is 120.

[0227] Figure 15 A flowchart illustrating an example method 1500 implemented at a second network device in the home network of a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1500 is described from the perspective of the second network device 130 in the middle.

[0228] At box 1510, the second network device 130 receives a request for network-based authentication for the user equipment from the first network device in the accessed network of the user equipment.

[0229] At box 1520, the second network device 130 generates a root key for authentication of the user equipment based on the accessed network.

[0230] At box 1530, the second network device 130 obtains a range of serial numbers for authentication of the user equipment based on the accessed network.

[0231] In box 1540, the second network device 130 sends a response to the first network device in response to the request, the response including a root key and a range of numbers.

[0232] In some example implementations, the root key may be specific to the accessed network.

[0233] In some example embodiments, the number range may be specific to the accessed network.

[0234] In some example implementations, the root key may be generated based on the name of the accessed network, the identifier of the user equipment, and a long-term key.

[0235] In some example embodiments, a second network device in the home network of any user equipment capable of performing method 1500 (e.g., Figure 1 The second network device 130 in the user equipment's home network may include components for performing corresponding operations of method 1500 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The second network device in the user equipment's home network may be implemented as or included in... Figure 1 The second network device 130 in the system.

[0236] Figure 16 A flowchart of an example method 1600 implemented at a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1600 is described from the perspective of user equipment 110.

[0237] At box 1610, user equipment 110 sends a registration request to a first network device in the network accessed by the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0238] At box 1620, user equipment 110 receives a registration response from a first network device in response to a registration request, the registration response including an indication that network-specific authentication has been enabled for the user equipment.

[0239] At box 1630, user equipment 110 generates a root key for authentication based on the accessed network for the user equipment.

[0240] At box 1640, user equipment 110 receives an authentication message from the first network device in response to the start of communication by the user equipment.

[0241] At box 1650, user equipment 110 sends an authentication response to the authentication message to the first network device using the root key.

[0242] In some example embodiments, the registration request may also include an indication of one or more authentication modes based on the accessed network, supported by the user equipment.

[0243] In some example implementations, the root key may be specific to the accessed network.

[0244] In some example implementations, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key.

[0245] In some example embodiments, user equipment 110 may receive constant or random values ​​from the authentication server function.

[0246] In some example implementations, the reference key may be a key for accessing management functions.

[0247] In some example embodiments, user equipment 110 may use a root key to verify the integrity protection of authentication messages; and in response to successful verification, user equipment 110 may generate an authentication response.

[0248] In some example implementations, the authentication message may contain temporary data, and the temporary data is protected for integrity using the root key.

[0249] In some example implementations, the authentication response may contain temporary data, and the temporary data is protected for integrity and encrypted using the root key.

[0250] In some example implementations, authentication messages and authentication responses may be delivered via Non-Access Stratum (NAS) messages.

[0251] In some example embodiments, a user device capable of performing any of the methods in method 1600 (e.g., Figure 1 The user equipment 110 may include components for performing corresponding operations of method 1600 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The user equipment may be implemented as or included in Figure 1 In user equipment 110.

[0252] Figure 17 A flowchart illustrating an example method 1700 implemented at a first network device in an accessed network of a user equipment according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1700 is described from the perspective of the first network device 120 in the middle.

[0253] At box 1710, the first network device 120 receives a registration request from the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network.

[0254] At box 1720, the first network device 120 sends a request for authentication of the user equipment based on the accessed network to the second network device in the home network of the user equipment.

[0255] At box 1730, the first network device 120 receives a response to the request from the second network device, the response including an indication that the user device's authentication based on the accessed network is permitted.

[0256] At box 1740, the first network device 120 generates a root key for authentication of user equipment based on the accessed network.

[0257] At box 1750, the first network device 120 sends a registration response to the user equipment in response to the registration request, the registration response including an indication that network-specific authentication has been enabled for the user equipment.

[0258] At box 1760, in response to the start of communication by the user equipment, the first network device 120 authenticates the user equipment through the accessed network by using a root key.

[0259] In some example embodiments, the registration request may also include an indication of one or more authentication modes supported by the user equipment.

[0260] In some example implementations, the root key may be specific to the accessed network.

[0261] In some example implementations, the root key may be generated based on the name of the accessed network, a constant or random value, and a reference key.

[0262] In some example implementations, the reference key may be a key for accessing management functions.

[0263] In some example embodiments, the first network device 120 may store a root key.

[0264] In some example embodiments, the first network device 120 may send an authentication message that is integrity protected using a root key to a user equipment; the first network device 120 may receive an authentication response to the authentication message from the user equipment; and the first network device 120 may use the root key to verify the integrity protection and encryption of the authentication response to authenticate the user equipment.

[0265] In some example embodiments, the authentication response may be protected for integrity and encrypted using the root key, and in response to successful authentication, the first network device 120 may determine that the user equipment has been authenticated.

[0266] In some example implementations, the authentication message may contain temporary data, and the temporary data is protected for integrity using the root key.

[0267] In some example implementations, the authentication response may contain temporary data, and the temporary data is protected for integrity and encrypted using the root key.

[0268] In some example implementations, authentication messages and authentication responses may be delivered via Non-Access Stratum (NAS) messages.

[0269] In some example embodiments, a first network device in the accessed network of any user device capable of performing method 1700 (e.g., Figure 1 The first network device 120 in the network may include components for performing corresponding operations of method 1700 and any embodiment thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The first network device in the accessed network of the user equipment may be implemented as or included in Figure 1 The first network device in the network is 120.

[0270] Figure 18 A flowchart illustrating an example method 1800 implemented at a second network device in the home network of a user equipment, according to some example embodiments of the present disclosure, is shown. For discussion purposes, [the following will be discussed]. Figure 1 Method 1800 is described from the perspective of the second network device 120 in the middle.

[0271] At box 1810, the second network device 120 receives a request for network-based authentication for the user equipment from the first network device in the accessed network of the user equipment.

[0272] At box 1820, the second network device 120 sends a response to the first network device, the response including an indication that the user equipment's authentication based on the accessed network is allowed.

[0273] In some example embodiments, a second network device in the home network of any user equipment capable of performing method 1800 (e.g., Figure 1 The second network (130) may include components for performing corresponding operations of method 1800 and any embodiments thereof. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit or software module. The second network device in the home network of the user equipment may be implemented as or included in... Figure 1 The second network device 130 in the system.

[0274] Figure 19 This is a simplified block diagram of a device 1900 suitable for implementing an example embodiment of the present disclosure. The device 1900 can be provided to implement a communication device, such as... Figure 1 The user equipment 110, the first network device 120, or the second network device 130 are shown. As shown, device 1900 includes one or more processors 1910, one or more memories 1920 coupled to processor 1910, and one or more communication modules 1940 coupled to processor 1910.

[0275] Communication module 1940 is used for bidirectional communication. Communication module 1940 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface can represent any interface necessary for communication with other network elements. In some example embodiments, communication module 1940 may include at least one antenna.

[0276] As a non-limiting example, processor 1910 can be any type suitable for a local technology network and can include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), and processor based on a multi-core processor architecture. Device 1900 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock synchronized with the main processor.

[0277] Memory 1920 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1924, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disc (DVD), optical disc, laser disc, and other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1922 and other volatile memories that will not be maintained during power outages.

[0278] Computer program 1930 includes computer-executable instructions that are executed by an associated processor 1910. The instructions of program 1930 may include instructions for performing operations / actions of some example embodiments of this disclosure. Program 1930 may be stored in memory (e.g., ROM 1924). Processor 1910 can perform any suitable actions and processes by loading program 1930 into RAM 1922.

[0279] Example embodiments of this disclosure can be implemented by means of program 1930, such that device 1900 can perform as described in the reference. Figures 2 to 18 Any process discussed in this disclosure. Exemplary embodiments of this disclosure may also be implemented by hardware or by a combination of software and hardware.

[0280] In some example embodiments, program 1930 may be tangibly included in a computer-readable medium, which may be included in device 1900 (such as in memory 1920) or in other storage devices accessible by device 1900. Device 1900 may load program 1930 from the computer-readable medium into RAM 1922 for execution. In some example embodiments, the computer-readable medium may include any type of non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. As used herein, the term "non-transitory" is a limitation of the medium itself (i.e., tangible, not tactile), rather than a limitation of the persistence of data storage (e.g., RAM versus ROM).

[0281] Figure 20 An example of a computer-readable medium 2000 is shown, which may be in the form of a CD, DVD, or other optical storage disc. The computer-readable medium 2000 has a program 1930 stored thereon.

[0282] In general, the various embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, and others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof, as non-limiting examples.

[0283] Some exemplary embodiments of this disclosure also provide at least one computer program product tangibly stored on a computer-readable medium, such as a non-transitory computer-readable medium. The computer program product includes computer-executable instructions, such as those included in a program module, which are executed in a device on a target physical or virtual processor to perform any of the methods described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., that perform a particular task or implement a particular abstract data type. In various embodiments, the functionality of a program module can be combined or split among program modules as needed. The machine-executable instructions for a program module can execute within a local or distributed device. In a distributed device, the program module can reside on both local and remote storage media.

[0284] Program code for performing the methods of this disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be performed. The program code may be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0285] In the context of this disclosure, computer program code or related data may be carried by any suitable carrier wave to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carrier waves include signals, computer-readable media, etc.

[0286] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More specific examples of computer-readable storage media will include electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0287] Furthermore, although operations are described in a specific order, this should not be construed as requiring that such operations be performed in the specific order shown or sequentially, or requiring that all shown operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this disclosure, but rather as a description of features that may be specific to particular embodiments. Unless explicitly stated otherwise, certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated otherwise, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0288] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms for implementing the claims.< / rand> < / rand> < / rand> < / rand> < / rand> < / rand>

Claims

1. A user equipment, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to at least: Send a registration request to a first network device in the accessed network of the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network; as well as Generate a root key for network-based authentication of the user equipment.

2. The user equipment of claim 1, wherein the registration request further includes an indication of one or more authentication modes based on the accessed network supported by the user equipment.

3. The user equipment according to any one of claims 1 to 2, wherein the user equipment is further configured to: Receive authentication messages from the network device; and Send an authentication response to the authentication message to the network device, wherein the authentication response is protected for integrity and encrypted using the root key.

4. The user equipment of claim 3, wherein the authentication message is protected for integrity using the root key, and wherein the user equipment is further configured to: The root key is used to verify the integrity protection of the authentication message; and In response to the successful verification, the authentication response is generated.

5. The user equipment of claim 4, wherein the authentication message includes temporary data, and the temporary data is protected for integrity using the root key.

6. The user equipment of claim 5, wherein the authentication response includes the temporary data, and the temporary data is integrity protected and encrypted using the root key.

7. The user equipment of claim 3, wherein the authentication message and the authentication response are delivered via a Non-Access Stratum (NAS) message.

8. The user equipment according to any one of claims 1 to 2, wherein the root key is specific to the accessed network.

9. The user equipment according to any one of claims 1 to 2, wherein the root key is generated based on the name of the accessed network, a constant or random value, and a reference key.

10. The user equipment of claim 9, wherein the user equipment is further configured to: Receive the constant or random value from the authentication server function.

11. The user equipment according to claim 9, wherein the reference key is a key for the authentication server function or a long-term key.

12. A first network device in an accessed network of a user equipment, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the first network device to at least: Receive a registration request from the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network; Send a request for authentication of the user equipment based on the accessed network to a second network device in the home network of the user equipment; Receive a response to the request from the second network device, the response including the root key for the accessed network-based authentication of the user equipment; Send a registration response to the registration request to the user equipment, the registration response including an indication that network-specific authentication has been enabled for the user equipment; as well as In response to the commencement of communication by the user equipment, the user equipment is authenticated through the accessed network using the root key.

13. The first network device of claim 12, wherein the registration request further includes an indication of one or more authentication modes supported by the user equipment.

14. The first network device according to claim 12 or claim 13, wherein the root key is specific to the accessed network.

15. The first network device according to claim 12 or claim 13, wherein the first network device is further configured to store the root key.

16. The first network device according to claim 12 or claim 13, wherein the first network device that is caused to authenticate the user equipment is caused to: Send an authentication message to the user equipment; Receive an authentication response from the user equipment in response to the authentication message; and The root key is used to verify the integrity protection and encryption of the authentication response in order to authenticate the user equipment.

17. The first network device of claim 16, wherein the authentication response is integrity protected and encrypted using the root key, and wherein the first network device that is caused to authenticate the user equipment is further caused to: In response to the successful verification, it is determined that the user equipment has been authenticated.

18. The first network device of claim 16, wherein the authentication message is protected for integrity using the root key.

19. The first network device of claim 18, wherein the authentication message includes temporary data, and the temporary data is protected for integrity using the root key.

20. The first network device of claim 19, wherein the authentication response includes the temporary data, and the temporary data is integrity protected and encrypted using the root key.

21. The first network device of claim 16, wherein the authentication message and the authentication response are delivered via a Non-Access Stratum (NAS) message.

22. A second network device in the home network of a user equipment, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the second network device to at least: Receive a network-based authentication request for the user equipment from a first network device in the accessed network of the user equipment; Generate a root key for the network-based authentication of the user equipment; as well as Send a response to the request to the first network device, the response including the root key.

23. The second network device of claim 22, wherein the root key is specific to the accessed network.

24. The second network device according to claim 22 or claim 23, wherein the root key is generated based on the name of the accessed network, a constant or random value, and a reference key.

25. The second network device according to claim 24, wherein the reference key is a key for the authentication server function or a long-term key.

26. A method for communication, comprising: At the user equipment, Send a registration request to a first network device in the accessed network of the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network; as well as Generate a root key for network-based authentication of the user equipment.

27. A method for communication, comprising: At the first network device. Receive a registration request from the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network; Send a request for authentication of the user equipment based on the accessed network to a second network device in the home network of the user equipment; Receive a response to the request from the second network device, the response including the root key for the accessed network-based authentication of the user equipment; Send a registration response to the registration request to the user equipment, the registration response including an indication that network-specific authentication has been enabled for the user equipment; as well as In response to the commencement of communication by the user equipment, the user equipment is authenticated through the accessed network using the root key.

28. A method for communication, comprising: At the second network device Receive a network-based authentication request for the user equipment from a first network device in the accessed network of the user equipment; Generate a root key for the network-based authentication of the user equipment; as well as Send a response to the request to the first network device, the response including the root key.

29. A user equipment, comprising: A component for sending a registration request to a first network device in an accessed network of the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network; as well as A component for generating a root key for authentication based on the accessed network to be used by the user equipment.

30. A first network device, comprising: A component for receiving a registration request from the user equipment, the registration request including an indication that the user equipment supports authentication based on the accessed network; A component for sending a request for authentication of the user equipment based on the accessed network to a second network device in the home network of the user equipment; A component for receiving a response to the request from the second network device, the response including a root key for the user equipment based on the accessed network authentication; A component for sending a registration response to the registration request to the user equipment, the registration response including an indication that network-specific authentication has been enabled for the user equipment; as well as A component for authenticating the user equipment via the accessed network using the root key in response to the commencement of communication with the user equipment.

31. A second network device, comprising: A component for receiving a network-based authentication request for the user equipment from a first network device in the accessed network of the user equipment; A component for generating the root key for authentication based on the accessed network of the user equipment; as well as A component for sending a response to the request to the first network device, the response including the root key.

32. A computer-readable medium comprising instructions stored thereon, the instructions being configured to cause a device to perform at least the method of claim 26, the method of claim 27, or the method of claim 28.