Apparatus and method for assigning a temporary identity to a device for use in a wireless network
Patent Information
- Application Number
- CN202580013660.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-03-15
- Filing Date
- 2025-03-07
- Publication Date
- 2026-09-04
Smart Images

Figure CN122700535A_ABST
Abstract
Description
[0001] Related applications
[0002] This application claims priority to U.S. Patent Application No. 63 / 565,984, filed March 15, 2024, entitled “Apparatus and Method for Assigning a Temporary Identity to a Device for Use in a Wireless Network,” the entire disclosure of which is incorporated herein by reference. Technical Field
[0003] This disclosure relates to wireless communication, and more specifically, to apparatus and methods for assigning temporary identities to devices for use in wireless networks. Background Technology
[0004] A wireless communication system may include one or more network communication devices, which may otherwise be referred to as network equipment (NE), supporting wireless communication for one or more user communication devices, which may also be referred to as user equipment (UE), user facility, or other suitable terms. The wireless communication system can support wireless communication with one or more user communication devices by utilizing the resources of the wireless communication system (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers, etc.)). Furthermore, the wireless communication system can support wireless communication across various radio access technologies, including third-generation (3G), fourth-generation (4G), fifth-generation (5G), and other suitable radio access technologies beyond 5G (e.g., sixth-generation (6G)). Summary of the Invention
[0005] In some embodiments of the methods and apparatus described herein, an access request message may be sent indirectly to a first-type network via a wireless access point associated with a second-type network. The access request message may include a subscription identity for use with the first-type network and an indication that the apparatus supports the assignment of a temporary identifier for use with the first-type network. The assignment of the temporary identifier for use with the first-type network may be received via the wireless access point associated with the second-type network.
[0006] This describes an apparatus for wireless communication (e.g., a non-5th generation capability (N5CW) device based on a wireless local area network). The apparatus may be configured, capable, or operable to perform one or more operations as described herein. For example, the apparatus may be configured, capable, or operable to indirectly send an access request message to a first type of network via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network and an indication that the apparatus supports the assignment of a temporary identifier for use with the first type of network; and to receive the assignment of the temporary identifier for use with the first type of network via the wireless access point associated with the second type of network.
[0007] This document describes a processor (e.g., a component of a standalone processor chipset or an N5CW device) for wireless communication. The processor may be configured, capable, or operable to perform one or more operations as described herein. For example, the processor may be configured, capable, or operable to indirectly send an access request message to a first type of network via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network and an indication that the processor supports the assignment of a temporary identifier for use with the first type of network; and to receive the assignment of the temporary identifier for use with the first type of network via the wireless access point associated with the second type of network.
[0008] A method is described that is performed or can be performed by a device for wireless communication (e.g., an N5CW device). The method may include indirectly sending an access request message to a first type of network via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network and an indication that the device supports the assignment of a temporary identifier for use with the first type of network; and receiving the assignment of the temporary identifier for use with the first type of network via the wireless access point associated with the second type of network.
[0009] In some embodiments of the apparatus, processor, and methods described herein, the wireless access point associated with the second type of network has an interoperability (IF) function for communicating with the access and mobility management function (AMF) of the first type of network.
[0010] In some embodiments of the apparatus, processor, and method described herein, the assignment of the temporary identifier for use with the first type of network is received from the AMF via the wireless access point associated with the second type of network, based on the indication of support by the apparatus for the assignment of the temporary identifier for use with the first type of network, as part of the N2 Initial Context Establishment Request.
[0011] In some embodiments of the apparatus, processor, and method described herein, the N2 Initial Context Establishment Request sent by the AMF of the first type of network includes an encryption key to support communication between the AMF and the IF of the wireless access point associated with the second type of network, in addition to the assignment of the temporary identifier for use by the apparatus with the first type of network.
[0012] In some embodiments of the apparatus, processor, and method described herein, the wireless access point associated with the second type of network receives from the AMF the assignment of the temporary identifier for use with the first type of network, as part of an N2 message indicating registration acceptance, based on the indication of support by the apparatus for the assignment of the temporary identifier for use with the first type of network.
[0013] In some embodiments of the apparatus, processor, and method described herein, the apparatus receives, as part of an IP configuration response message, the assignment of the temporary identifier for use with the first type of network from the wireless access point associated with the second type of network.
[0014] In some embodiments of the apparatus, processor, and method described herein, the apparatus receives, from the wireless access point associated with the second type of network, the assignment of the temporary identifier for use with the first type of network as part of an Extensible Authentication Protocol (EAP) request message.
[0015] In some embodiments of the apparatus, processor, and method described herein, the apparatus receives, from the wireless access point associated with the second type of network, the assignment of the temporary identifier for use with the first type of network as part of an EAP success message.
[0016] A network element (NE) for wireless communication (e.g., a base station) is described. The NE can be configured, enabled, or operable to perform one or more operations as described herein. For example, the NE can be configured, enabled, or operable to receive an access request message from a device that does not support direct communication with a first type of network compatible with the NE, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network, and an indication that the device supports the assignment of a temporary identifier for use with the first type of network; generating a temporary identifier for use with the first type of network for the device; and transmitting the assignment of the temporary identifier via the wireless access point associated with the second type of network for use by the device with the first type of network.
[0017] This describes a processor (e.g., a standalone processor chipset or a component of an NE (e.g., a base station)) for wireless communication. The processor may be configured, capable, or operable to perform one or more operations as described herein. For example, the processor may be configured, capable, or operable to receive an access request message from a device that does not support direct communication with a first type of network compatible with the processor, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network and an indication that the device supports the assignment of a temporary identifier for use with the first type of network; generating a temporary identifier for use with the first type of network for the device; and transmitting the assignment of the temporary identifier via the wireless access point associated with the second type of network for use by the device with the first type of network.
[0018] A method is described that is performed by or can be performed by a network-interface (NE) for wireless communication. The method may include receiving an access request message from a device, wherein the device does not support direct communication with a first type of network compatible with the NE, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network, and an indication that the device supports the assignment of a temporary identifier for use with the first type of network; generating a temporary identifier for use with the first type of network for the device; and transmitting the assignment of the temporary identifier via the wireless access point associated with the second type of network for use by the device with the first type of network.
[0019] In some embodiments of the NE, processor, and method described herein, the wireless access point associated with the second type of network has an IF for communicating with the NE via an AMF.
[0020] In some implementations of the NE, processor, and method described herein, the assignment of the temporary identifier for use with the first type of network is sent from the AMF via the wireless access point associated with the second type of network, based on the indication of support by the device for the assignment of the temporary identifier for use with the first type of network, as part of the N2 Initial Context Establishment Request.
[0021] In some implementations of the NE, processor, and method described herein, the N2 Initial Context Establishment Request sent by the AMF of the first type of network includes an encryption key to support communication between the AMF and the IF of the wireless access point associated with the second type of network, in addition to the assignment of the temporary identifier for use by the device with the first type of network.
[0022] In some embodiments of the NE, processor, and method described herein, the wireless access point associated with the second type of network receives from the AMF the assignment of the temporary identifier for use with the first type of network, based on the indication of support by the device for the assignment of the temporary identifier for use with the first type of network, as part of an N2 message indicating registration acceptance.
[0023] In some embodiments of the NE, processor, and method described herein, the device receives, as part of an IP configuration response message, the assignment of the temporary identifier for use with the first type of network from the wireless access point associated with the second type of network.
[0024] In some embodiments of the NE, processor, and method described herein, the device receives, as part of an EAP request message, the assignment of the temporary identifier for use with the first type of network from the wireless access point associated with the second type of network.
[0025] In some embodiments of the NE, processor, and method described herein, the device receives, as part of an EAP success message, the assignment of the temporary identifier for use with the first type of network from the wireless access point associated with the second type of network. Attached Figure Description
[0026] Figure 1 Examples of wireless communication systems according to aspects of this disclosure are provided;
[0027] Figure 2A and 2B An example of a signal flow diagram illustrating an aspect of this disclosure for assigning a temporary identity to a device for use in a network;
[0028] Figure 3 Examples of apparatus according to aspects of this disclosure are provided;
[0029] Figure 4 Examples of processors according to aspects of this disclosure are described;
[0030] Figure 5 Examples of NEs according to aspects of this disclosure;
[0031] Figure 6 A flowchart illustrating a method performed by an apparatus according to aspects of this disclosure; and
[0032] Figure 7 A flowchart illustrating the method performed by NE according to aspects of this disclosure. Detailed Implementation
[0033] According to 3GPP Technical Specifications (TS) 33.501 and 3GPP TS 23.502, non-5G capability (N5CW) devices based on Wireless Local Area Networks (WLANs) can register to the 5G Core Network (5GC) using 3GPP credentials, such as using a Universal Subscriber Identity Module (USIM), and can establish 5GC connections via trusted WLAN access networks. Example N5CW devices can be laptops, tablets, or other devices with SIM cards for 5G carriers. N5CW devices may not have a 5G modem but may have a 5G subscription identity for authentication. N5CW devices may not support Non-Access Stratum (NAS) protocols; interoperability is achieved on behalf of the N5CW device by a Trusted WLAN Interoperability Function (TWIF).
[0034] In cases where the N5CW device does not support NAS, a 5G-GUTI (Globally Unique Temporary UE Identity) is typically not assigned as part of the NAS registration acceptance message. NAS protocols usually assign a 5G-GUTI. If the N5CW device supports 3GPP access to the 5GC network and correspondingly supports NAS based on 3GPP access, then it can receive a 5G-GUTI. However, it is more likely that a device supporting both 3GPP access and NAS protocols will also support NAS protocols based on non-3GPP access, for example, for trusted or untrusted access. Therefore, suppose the N5CW device does not have a 5G modem with 3GPP access capabilities, but is instead a simpler device, such as a laptop computer, that may only have USIM and WLAN access capabilities. In this case, the 5GC will not assign a 5G-GUTI, and the N5CW device must use a Subscription Hidden Identifier (SUCI) when attempting to attach to a trusted WLAN access point (TWAP).
[0035] However, SUCI is not intended to be used continuously for authentication in 5GC and should be used only once during initial registration. 5G-GUTI should be used thereafter. SUCI freshness and encryption level depend on the scheme used by the mobile operator, and in the worst case, such as cases involving NULL schemes, encryption may be disabled. N5CW is vulnerable to privacy attacks such as tracking, impersonation, or other attacks, especially when the Subscription Permanent Identifier (SUPI) is not encrypted (NULL scheme).
[0036] Furthermore, neither 3GPP TS 33.501 nor 3GPP TS 23.502 describes the allocation of 5G-GUTI to N5CW devices. Assuming that 5G-GUTI is assigned as part of 3GPP access:
[0037] If the N5CW device has already registered with the 5GC via 3GPP access when the above process begins, then the Network Access Identifier (NAI) contains the 5G-GUTI assigned to the N5CW device via 3GPP access. This allows TWIF to select the same AMF as the Access and Mobility Management Function (AMF) serving the N5CW device via 3GPP access.
[0038] For N5CW devices that only support non-3GPP access, it may be impossible to retrieve 5G-GUTI. The device will have to use SUCI in every case, which is not intended for this purpose, especially when the protection profile of the SUPI used to generate the SUCI is weak and / or not used.
[0039] At least some embodiments of this application may introduce one or more of at least three possible options for alternatively providing 5G-GUTI to an N5CW device. Since N5CW devices typically do not support the NAS protocol, they generally cannot directly receive registration acceptance messages from the AMF, and the 5G-GUTI will typically be conveyed within those messages. Correspondingly, the N5CW may need to indicate its ability to receive 5G-GUTI through alternative means (e.g., using flags), so that the AMF will allocate 5G-GUTI to the device.
[0040] In the first of at least three possible options (Option A), the AMF assigns a 5G-GUTI to the N5CW device and combines it with the TWIF key (K). TWIF Together, they are sent to TWIF. TWIF includes the 5G-GUTI in the Extensible Authentication Protocol (EAP) success message to the N5CW device. In such cases, the EAP success message via the air interface may be unprotected.
[0041] In the second of at least three possible options (Option B), the AMF assigns a 5G-GUTI to the N5CW device and sends it to the TWIF in a NAS registration accept message. The TWIF then provides the N5CW with the new 5G-GUTI and Internet Protocol (IP) configuration (DHCP response) via a protected air interface.
[0042] In the third of at least three possible options (Option C), the AMF assigns a 5G-GUTI to the N5CW device and sends it to the TWIF in a NAS registration accept message. The TWIF initiates a new EAP message exchange, such as an identity request, and provides the new 5G-GUTI in an EAP success message via a protected air interface.
[0043] This document refers to sending or receiving data or information. It should be understood that other terms are used interchangeably with "sending," such as communication, signaling, transmission, output, forwarding, etc. It should also be understood that other terms are used interchangeably with "receiving," such as communication, signaling, retrieval, obtaining, etc.
[0044] The aspects of this disclosure are described in the context of wireless communication systems.
[0045] Figure 1This describes an example of a wireless communication system 100 according to aspects of this disclosure. The wireless communication system 100 may include one or more NEs 102, one or more devices 104, and a network 106. The wireless communication system 100 may support various radio access technologies. In some embodiments, the wireless communication system 100 may be a 4G network, such as an LTE network or an LTE-A network. In some other embodiments, the wireless communication system 100 may be an NR network, such as a 5G network, a 5G-A network, or a 5G Ultra Wideband (5G-UWB) network. In other embodiments, the wireless communication system 100 may be a combination of 4G and 5G networks, or other suitable radio access technologies, including IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and / or IEEE 802.20. The wireless communication system 100 may support radio access technologies beyond 5G, such as 6G. In addition, the wireless communication system 100 can support technologies such as Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), or Code Division Multiple Access (CDMA).
[0046] One or more NEs 102 may be distributed across a geographical area to form a wireless communication system 100. One or more of the NEs 102 described herein may be, include, or be referred to as a network node, base station, network element, network function, network entity, radio access network (RAN), NodeB, eNodeB (eNB), next-generation NodeB (gNB), access point, transmit-receive point (TRP), or other suitable terms. The NEs 102 and device 104 may communicate via a communication link, which may be a wireless or wired connection. For example, the NEs 102 and device 104 may perform wireless communication (e.g., receiving signaling, transmitting signaling) via a Uu interface.
[0047] NE 102 can provide a geographic coverage area that supports services for one or more devices 104 within that geographic coverage area. For example, NE 102 and device 104 can support wireless communication of signals associated with services (e.g., voice, video, packet data, messaging, broadcasting, etc.) according to one or more radio access technologies. In some embodiments, NE 102 can be mobile, for example, a satellite associated with a non-terrestrial network (NTN). In some embodiments, different geographic coverage areas associated with the same or different radio access technologies may overlap, but different geographic coverage areas may be associated with different NE 102s.
[0048] One or more devices 104 may be distributed throughout a geographical area of the wireless communication system 100. Device 104 may include or be referred to as a remote unit, mobile device, wireless device, remote device, subscriber device, transmitter device, receiver device, or some other suitable term. In some embodiments, device 104 may be referred to as a UE, unit, station, terminal, or client, and other instances. Additionally or alternatively, device 104 may be referred to as an Internet of Things (IoT) device, an Internet of Everything (IoE) device, or a Machine Type Communication (MTC) device, and other instances.
[0049] Device 104 may be able to support direct wireless communication with other devices 104 via a communication link. For example, device 104 may support direct wireless communication with another device 104 via a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a side link. For example, device 104 may support direct wireless communication with another device 104 via a PC5 interface.
[0050] Network 106 may include a core network, a wireless communication network, a cellular telephone network, a WLAN, a TDMA-based network, a CDMA-based network, an FDMA-based network, an Orthogonal Frequency Division Multiple Access (OFDMA)-based network, a Long Term Evolution (LTE) network, a New Radio (NR) network, a 3rd Generation Partnership Project (3GPP)-based network, a 5G network, a satellite communication network, a high-altitude platform network, the Internet and / or other communication networks.
[0051] NE 102 may support communication with network 106 or with another NE 102 or both. For example, NE 102 may interface with other NE 102 or network 106 via one or more backhaul links (e.g., S1, N2, N2, or network interfaces). In some embodiments, NE 102 may communicate directly with each other. In some other embodiments, NE 102 may communicate with each other or indirectly (e.g., via network 106). In some embodiments, one or more NE 102 may include sub-components, such as access network entities, which may be instances of access node controllers (ANCs). The ANC may communicate with one or more devices 104 via one or more other access network transmitting entities (which may be referred to as radio heads, smart radio heads, or TRPs).
[0052] Network 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. Network 106 may be an Evolved Packet Core (EPC) or a 5GC, and may include control plane entities that manage access and mobility (e.g., a Mobility Management Entity (MME), Access and Mobility Management Function (AMF)) and user plane entities that route packets or interconnect to external networks (e.g., a Serving Gateway (S-GW), Packet Data Network (PDN) Gateway (P-GW), or User Plane Function (UPF)). In some embodiments, the control plane entities may manage non-access stratum (NAS) functions of one or more devices 104 served by one or more NEs 102 associated with network 106, such as mobility, authentication, and bearer management (e.g., data bearers, signaling bearers, etc.).
[0053] Network 106 can communicate with a packet data network via one or more backhaul links (e.g., via S1, N2, N2, or another network interface). The packet data network may include an application server. In some embodiments, one or more devices 104 may communicate with the application server. Device 104 may establish a session (e.g., a Protocol Data Unit (PDU) session, etc.) with network 106 via NE 102. Network 106 may use the established session (e.g., an established PDU session) to route traffic (e.g., control information, data, etc.) between device 104 and the application server. A PDU session may be an instance of a logical connection between device 104 and network 106 (e.g., one or more network functions of network 106).
[0054] In the wireless communication system 100, NE 102 and device 104 can use the resources of the wireless communication system 100 (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communication). In some embodiments, NE 102 and device 104 can support different resource structures. For example, NE 102 and device 104 can support different frame structures. In some embodiments, such as in 4G, NE 102 and device 104 can support a single frame structure. In some other embodiments, such as in 5G and other suitable radio access technologies, NE 102 and device 104 can support various frame structures (i.e., multiple frame structures). NE 102 and device 104 can support various frame structures based on one or more parameter sets.
[0055] The wireless communication system 100 may support one or more parameter sets, and the parameter sets may include subcarrier spacing and cyclic prefixes. A first parameter set (e.g., μ=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a regular cyclic prefix. In some embodiments, the first parameter set (e.g., μ=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one time slot per subframe. A second parameter set (e.g., μ=1) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a regular cyclic prefix. A third parameter set (e.g., μ=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a regular cyclic prefix or an extended cyclic prefix. A fourth parameter set (e.g., μ=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a regular cyclic prefix. A fifth parameter set (e.g., μ=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a regular cyclic prefix.
[0056] The time intervals of resources (e.g., communication resources) can be organized according to frames (also called radio frames). Each frame may have a duration, for example, 10 milliseconds (ms). In some embodiments, each frame may contain multiple subframes. For example, each frame may contain 10 subframes, and each subframe may have a duration, for example, 1 ms. In some embodiments, each frame may have the same duration. In some embodiments, each subframe of a frame may have the same duration.
[0057] Alternatively, the time intervals of resources (e.g., communication resources) can be organized according to time slots. For example, a subframe may contain a certain number (e.g., quantity) of time slots. The number of time slots in each subframe may also depend on one or more parameter sets supported in the wireless communication system 100. For example, the first, second, third, fourth, and fifth parameter sets (i.e., μ=0, μ=1, μ=2, μ=3, μ=4) associated with corresponding subcarrier intervals of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single time slot per subframe, two time slots per subframe, four time slots per subframe, eight time slots per subframe, and 16 time slots per subframe, respectively. Each time slot may contain a certain number (e.g., quantity) of symbols (e.g., OFDM symbols). In some embodiments, the number (e.g., quantity) of time slots in a subframe may depend on the parameter set. For a conventional cyclic prefix, a time slot may contain 14 symbols. For an extended cyclic prefix (e.g., applicable to a 60 kHz subcarrier spacing), a time slot may contain 12 symbols. The relationship between the number of symbols per time slot for the regular cyclic prefix and the extended cyclic prefix, the number of time slots per subframe, and the number of time slots per frame may depend on the parameter set. It should be understood that references to the first parameter set (e.g., μ=0) associated with the first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and time slots.
[0058] In the wireless communication system 100, the electromagnetic (EM) spectrum can be divided into various categories, frequency bands, channels, etc., based on frequency or wavelength. For example, the wireless communication system 100 may support one or more operating frequency bands, such as frequency range names FR1 (410 MHz to 7.125 GHz), FR2 (24.25 GHz to 52.6 GHz), FR3 (7.125 GHz to 24.25 GHz), FR4 (52.6 GHz to 114.25 GHz), FR4a or FR4-1 (52.6 GHz to 71 GHz), and FR5 (114.25 GHz to 300 GHz). In some embodiments, NE 102 and device 104 may perform wireless communication on one or more of the operating frequency bands. In some embodiments, FR1 may be used by NE 102 and device 104, as well as other equipment or devices, for cellular communication services (e.g., control information, data). In some implementations, FR2 can be used by NE 102 and device 104, as well as other equipment or devices, for short-range, high data rate capabilities.
[0059] FR1 may be associated with one or more parameter sets (e.g., at least three parameter sets). For example, FR1 may be associated with a first parameter set containing a 15 kHz subcarrier spacing (e.g., μ=0); a second parameter set containing a 30 kHz subcarrier spacing (e.g., μ=1); and a third parameter set containing a 60 kHz subcarrier spacing (e.g., μ=2). FR2 may be associated with one or more parameter sets (e.g., at least two parameter sets). For example, FR2 may be associated with a third parameter set containing a 60 kHz subcarrier spacing (e.g., μ=2); and a fourth parameter set containing a 120 kHz subcarrier spacing (e.g., μ=3).
[0060] Figure 2A and 2B This is an example of a signaling flow diagram 200 that illustrates, as part of the authentication process, assigning a temporary identity to a device (e.g., an N5CW device) for use in a network. According to at least one embodiment, the flowchart describes exemplary messaging that can occur between an N5CW device, a trusted WLAN access network (which may include trusted WLAN access points and TWIF), an AMF / Security Anchor Function (SEAF), an Authentication Server Function (AUSF), and a Unified Data Management (UDM) entity.
[0061] As part of the illustrated embodiment, the authentication process includes the following steps:
[0062] 1. Initial registration and PDU session establishment, in which the N5CW device associates with a trusted WLAN network and initiates the EAP authentication and key negotiation (AKA) authentication process.
[0063] 2. The N5CW device provides its Network Access Identity (NAI). A Trusted WLAN Access Point (TWAP) selects a Trusted WLAN Interoperability Function (TWIF) based on the received domain and sends an Authentication, Authorization, and Accounting (AAA) request to the selected TWIF. If the N5CW device is registering with the 5GC for the first time via 3GPP access at the start of the above process, then the NAI should include the SUCI. If the N5CW device has already registered with the 5GC via 3GPP access at the start of the above process, then the NAI includes the 5G-GUTI assigned to the N5CW device via 3GPP access. This allows the TWIF to select the same AMF as the AMF serving the N5CW device via 3GPP access in step 4a. The N5CW may include an indication that it supports the allocation of 5G-GUTI, for example, via the use of a 5G-GUTI support flag.
[0064] 3. TWIF creates a 5GC registration request message on behalf of the N5CW device. TWIF fills the parameters in the registration request message with default values, which can be the same for all N5CW devices that do not support 5G NAS. The registration type indicates "Initial Registration".
[0065] 4. TWIF selects an AMF (e.g., by using a 5G-GUTI in the NAI, if provided by an N5CW device) and sends an N2 message to the AMF. The N2 message contains a registration request, user location, and access network (AN) type, as well as an indication that it supports the allocation of 5G-GUTI (a 5G-GUTI support flag). Based on this indication, TWIF recognizes that it needs to include the 5G-GUTI in a later message to the N5CW device (e.g., steps 12, 16, and / or 17).
[0066] 5. If the AMF triggers the authentication process, the AMF sends a request to the ASF by sending a Nausf_UEAuthentication_Authenticate request message. The Nausf_UEAuthentication_Authenticate request message contains either SUCI or SUPI (if a valid 5G-GUTI is received by the AMF). The request message also contains an indication that the request originated from an N5CW device. Even if the AMF already has a security context identified via the 5G-GUTI, the AMF initiates primary authentication. Note: To avoid issues arising from K... AMF Export K TWIF When reusing the key stream, the K should be refreshed through the updated master authentication. AMF .
[0067] 6. AUSF sends a Nudm_UEAuthentication_Get request to UDM containing SUCI or SUPI and N5CW indications.
[0068] 7. Upon receiving a Nudm_UEAuthentication_Get request, if a SUCI is received, the UDM invokes the Subscription Identifier De-hiding Function (SIDF). SIDF de-hids the SUCI to obtain a SUPI before the UDM can process the request. The UDM can select the authentication method based on the "domain" portion of the SUPI, the N5CW device indicator, a combination of the "domain" portion and the N5CW device indicator, or a UDM-local policy.
[0069] 8. The EAP-AKA procedure will be triggered to perform mutual authentication between the N5CW device and its home network. EAP-AKA occurs between the N5CW device and AUSF. Through the N2 interface, the EAP message is encapsulated within a NAS authentication message. EAP-AKA messages exchanged between the N5CW device and TWIF are encapsulated in Layer 2 packets, such as IEEE 802.3 / 802.1x packets, IEEE 802.11 / 802.1x packets, or Point-to-Point Protocol (PPP) packets.
[0070] 9. NAS security context is not required in this scenario. AMF receives K from the received K AMF Key export K TWIF Key. NAS security between AMF and TWIF is established similarly to an unauthenticated emergency call, i.e., with NULL encryption and NULL integrity protection. Note: N5CW devices typically do not support NAS; therefore, NAS counters may not be usable in N5CW devices.
[0071] 10a. AMF sends a NAS secure mode command to TWIF. The NAS secure mode command contains an EAP-success message and a NULL-safe algorithm.
[0072] 10c. TWIF does not directly forward the EAP-success message to N5CW. Instead, TWIF stores the EAP-success message and waits for K. TWIF .
[0073] 10d. TWIF sends a NAS security mode completion message to AMF.
[0074] In the example where option A is selected, step 202, which includes steps 10e, 11, 12a, 12b, and 12c, is executed.
[0075] 10e. The AMF assigns a 5G-GUTI [Option A] to the N5CW device based on the instruction received in step 4.
[0076] 11. AMF sends an N2 Initial Context Establishment Request to TWIF and provides K TWIF Key and 5G-GUTI [Option A].
[0077] 12. TWIF derives a trusted non-3GPP access point (TNAP) key K from K trusted non-3GPP gateway function (TNGF) keys. TNAPThe TNAP key and an EAP-success message with 5G-GUTI [Option A] are sent to a trusted WLAN access point, which forwards the EAP-success message with 5G-GUTI [Option A] to the N5CW device. The TNAP key corresponds to a pair master key (PMK), which is used to protect WLAN air interface communications according to IEEE 802.11. A Layer 2 or Layer 3 connection is established between the trusted WLAN access point and the TWIF to deliver all user plane services of the N5CW device to the TWIF. This connection is later bound to an N3 connection created for this N5CW device.
[0078] 13. TWIF sends an N2 Initial Context Establishment Response Message to AMF.
[0079] In the example where options B and / or C are selected, step 204, which includes steps 14 and 15, is executed.
[0080] 14. AMF assigns 5G-GUTI [Options B, C] to the N5CW device based on the instruction received in step 4.
[0081] 15. The AMF sends a registration acceptance message with 5G-GUTI [options B, C] to the TWIF. At this time, the N5CW device connects to the WLAN access network and registers with the 5GC.
[0082] In the example where option B is selected, step 206, which includes steps 16a and 16b, is executed.
[0083] 16a. TWIF receives IP configuration requests (e.g., Dynamic Host Configuration Protocol (DHCP) offer / request) from the N5CW device [Option B].
[0084] 16b. TWIF (e.g., using DHCP) assigns IP configuration data with 5G-GUTI [Option B] to the N5CW device. The IP address assigned to the N5CW device is the IP address assigned to the PDU session.
[0085] In the example where option C is selected, step 208, which includes 17a, 17b, and 17c, is executed.
[0086] 17a. TWIF sends an EAP request (e.g., an EAP identity request) to the N5CW device. This request may already contain the new 5G-GUTI [Alternative #1].
[0087] 17b. The N5CW responds to the TWIF request. If it is an EAP identity request, the N5CW sends the identity (SUCI, "old" 5G-GUTI) as used previously in step 2b. If the TWIF has already assigned a new 5G-GUTI in step 17a, the N5CW may simply acknowledge receipt of the request.
[0088] 17c. TWIF successfully sends EAP to the N5CW device. If the new 5G-GUTI was not included in step 17a, then TWIF includes the new 5G-GUTI in the message to the N5CW device [Alternative 2].
[0089] Figure 3 An example of an apparatus 300 (e.g., an N5CW device) according to aspects of this disclosure is described. Apparatus 300 may include at least one processor 302, at least one memory 304, at least one controller 306, and at least one transceiver 308. The processor 302, memory 304, controller 306, or transceiver 308, or various combinations thereof, or various components thereof, may be examples of components for performing the various aspects of this disclosure as described herein. These components may be coupled via one or more interfaces (e.g., operatively ground, communicative ground, functional ground, electronic ground, electrical ground).
[0090] Processor 302, memory 304, controller 306, or transceiver 308, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured or otherwise supporting components for performing the functions described in this disclosure.
[0091] Processor 302 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some embodiments, processor 302 may be configured to operate memory 304. In some other embodiments, memory 304 may be integrated into processor 302. Processor 302 may be configured to execute computer-readable instructions stored in memory 304 to cause device 300 to perform various functions of this disclosure.
[0092] Memory 304 may comprise volatile or non-volatile memory. Memory 304 may store computer-readable, computer-executable code containing instructions that, when executed by processor 302, cause device 300 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as memory 304 or another type of memory. Computer-readable medium includes both non-transitory computer storage media and communication media, wherein the communication media includes any media that facilitates the transfer of a computer program from one place to another. Non-transitory storage media may be any available media accessible by a general-purpose or special-purpose computer.
[0093] Controller 306 manages the input and output signals of device 300. Controller 306 can also manage peripheral devices not integrated into device 300. In some embodiments, controller 306 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some embodiments, controller 306 may be implemented as part of processor 302.
[0094] In some embodiments, device 300 may include at least one transceiver 308. In other embodiments, device 300 may have more than one transceiver 308. Transceiver 308 may represent a wireless transceiver. Transceiver 308 may include one or more receiver chains 310, one or more transmitter chains 312, or a combination thereof.
[0095] Receiver chain 310 may be configured to receive signals (e.g., control information, data, packets) via wireless media. For example, receiver chain 310 may include one or more antennas for receiving signals over the air or wireless media. Receiver chain 310 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 310 may include at least one demodulator configured to demodulate the received signal and obtain transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 310 may include at least one decoder for decoding the demodulated signal to receive transmitted data.
[0096] Transmitter chain 312 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 312 may include at least one modulator for modulating data onto a carrier signal in preparation for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 312 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 312 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0097] In some embodiments, processor 302 and memory 304 coupled to processor 302 may be configured to cause device 300 to perform one or more of the functions described herein (e.g., instructions stored in memory 304 are executed by processor 302). For example, processor 302 may support wireless communication at device 300 according to the examples disclosed herein. Device 300 may be configured to support components for assigning temporary identities to the device for use in a wireless network.
[0098] The device 300 may be configured or operable to support a component for: indirectly sending an access request message to a first type of network via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network and an indication that the device supports the assignment of a temporary identifier for use with the first type of network; and receiving the assignment of a temporary identifier for use with the first type of network via a wireless access point associated with the second type of network.
[0099] According to possible embodiments, device 300 may be an N5CW device because it may have 5G credentials, but may not support NAS. At least one processor 302 may be configured or operable to cause device 300 to indirectly send an access request message to a first-type network via a wireless access point associated with a second-type network. The access request message includes a subscription identity for use with the first-type network and an indication that the device supports the assignment of a temporary identifier for use with the first-type network, such as a 5G-GUTI support flag. The assignment of the temporary identifier for use with the first-type network is received via the wireless access point associated with the second-type network.
[0100] According to possible embodiments, the radio access point associated with the second type of network has an interworking function (IF) for communicating with the Access and Mobility Management Function (AMF) of the first type of network. In some of these examples, the assignment of a temporary identifier for use with the first type of network may be received from the AMF via the radio access point associated with the second type of network, as part of the N2 Initial Context Establishment Request, based on support indicated by the device for assigning a temporary identifier for use with the first type of network. Furthermore, the N2 Initial Context Establishment Request sent by the AMF of the first type of network may include an encryption key to support communication between the AMF and the IF of the radio access point associated with the second type of network, in addition to the assignment of the temporary identifier for use with the first type of network.
[0101] In some examples, the assignment of a temporary identifier for use with the first type of network may be received by the radio access point associated with the second type of network from the AMF, as part of an N2 message indicating registration acceptance, based on the indication of support by the device for the assignment of a temporary identifier for use with the first type of network. In some of these examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an IP configuration response message. In others of these examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) request message. In further other examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) success message.
[0102] Figure 4 An example of a processor 400 according to aspects of this disclosure is described. Processor 400 may be an example of a processor configured to perform various operations according to the examples described herein. Processor 400 may include at least one controller 402 configured to perform various operations according to the examples described herein. Processor 400 may optionally include at least one memory 404, which may be, for example, an L1 / L2 / L3 cache. Additionally or alternatively, processor 400 may optionally include one or more arithmetic logic units (ALUs) 406. One or more of these components may be electronically communicated or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0103] Processor 400 may be a processor chipset and includes a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receive, acquire, retrieve, transmit, output, forward, store, determine, identify, access, write, read) according to the examples described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to the processor chipset (e.g., processor 400) or contained within the processor chipset), or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), and others).
[0104] Controller 402 can be configured to manage and coordinate various operations of processor 400 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, and reading) to enable processor 400 to support various operations according to the examples described herein. For example, controller 402 can operate as a control unit of processor 400, generating control signals that manage the operation of various components of processor 400. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating operation timing.
[0105] Controller 402 may be configured to fetch (e.g., fetch, retrieve, receive) instructions from memory 404 and determine subsequent instructions to be executed to enable processor 400 to support various operations according to the examples described herein. Controller 402 may be configured to track the memory addresses of instructions associated with memory 404. Controller 402 may be configured to decode instructions to determine the operations to be performed and the operands involved. For example, controller 402 may be configured to interpret instructions and determine control signals to be output to other components of processor 400 to enable processor 400 to support various operations according to the examples described herein. Additionally or alternatively, controller 402 may be configured to manage data flow within processor 400. Controller 402 may be configured to control data transfers between registers, arithmetic logic unit (ALU), and other functional units of processor 400.
[0106] Memory 404 may include one or more caches (e.g., memory local to processor 400 or included in processor 400), or other memories such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some embodiments, memory 404 may reside within or on the processor chipset (e.g., locally to processor 400). In some other embodiments, memory 404 may reside outside the processor chipset (e.g., remotely from processor 400).
[0107] Memory 404 may store computer-readable, computer-executable code containing instructions that, when executed by processor 400, cause processor 400 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. Controller 402 and / or processor 400 may be configured to execute computer-readable instructions stored in memory 404 to cause processor 400 to perform various functions. For example, processor 400 and / or controller 402 may be coupled to or coupled to memory 404, and processor 400 and controller 402 may be configured to perform the various functions described herein. In some instances, processor 400 may include multiple processors, and memory 404 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, which may be individually or collectively configured to perform the various functions described herein.
[0108] One or more ALUs 406 may be configured to support various operations according to the examples described herein. In some embodiments, one or more ALUs 406 may reside within or on a processor chipset (e.g., processor 400). In some other embodiments, one or more ALUs 406 may reside outside the processor chipset (e.g., processor 400). One or more ALUs 406 may perform one or more calculations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALUs 406 may receive input operands and an opcode that determines the operation to be performed. One or more ALUs 406 may be configured with various logic and arithmetic circuitry, including adders, subtractors, shifters, and logic gates, to process and manipulate data according to the operation. Alternatively, one or more ALU 406s may support logical operations such as AND, OR, XOR, NOR, and NAND, enabling one or more ALU 406s to handle conditional operations, comparisons, and bitwise operations.
[0109] In operation according to possible embodiments, at least one controller 402 may be configured or operable to cause processor 400 to receive an access request message from a device, wherein the device does not support direct communication with a first type of network compatible with NE, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network. The access request message may include a subscription identity for use with the first type of network and an indication that the device supports the assignment of a temporary identifier for use with the first type of network. At least one controller 402 may cause processor 400 to generate a temporary identifier for the device for use with the first type of network and to send the assignment of the temporary identifier via a wireless access point associated with the second type of network for use with the first type of network.
[0110] Processor 400 may support wireless communication according to examples disclosed herein. According to possible embodiments associated with the device (e.g., an N5CW device), at least one controller 402 may be configured or operable to cause processor 400 to indirectly send an access request message to a first-type network via a wireless access point associated with a second-type network. The access request message includes a subscription identity for use with the first-type network and an indication that the processor supports the assignment of a temporary identifier for use with the first-type network, such as a 5G-GUTI support flag. The assignment of the temporary identifier for use with the first-type network is received via the wireless access point associated with the second-type network.
[0111] According to possible embodiments, the radio access point associated with the second type of network may have an interworking function (IF) for communicating with the Access and Mobility Management Function (AMF) of the first type of network. In some of these examples, the assignment of a temporary identifier for use with the first type of network may be received from the AMF via the radio access point associated with the second type of network as part of the N2 Initial Context Establishment Request, based on support indicated by the processor for the assignment of a temporary identifier for use with the first type of network. Furthermore, the N2 Initial Context Establishment Request sent by the AMF of the first type of network may include an encryption key to support communication between the AMF and the IF of the radio access point associated with the second type of network, in addition to the assignment of the temporary identifier for use with the first type of network by the processor.
[0112] In some examples, the assignment of a temporary identifier for use with the first type of network may be received by the radio access point associated with the second type of network from the AMF, as part of an N2 message indicating registration acceptance, based on the processor's indication of support for the assignment of a temporary identifier for use with the first type of network. In some of these examples, the processor may receive the assignment of a temporary identifier for use with the first type of network from the radio access point associated with the second type of network, as part of an IP configuration response message. In others of these examples, the processor may receive the assignment of a temporary identifier for use with the first type of network from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) request message. In further other examples, the processor may receive the assignment of a temporary identifier for use with the first type of network from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) success message.
[0113] Figure 5 An example of NE 500 according to aspects of this disclosure is described. NE 500 may include a processor 502, a memory 504, a controller 506, and a transceiver 508. The processor 502, memory 504, controller 506, or transceiver 508, or various combinations thereof, or various components thereof, may be examples of components for performing the various aspects of this disclosure as described herein. These components may be coupled via one or more interfaces (e.g., operatively ground, communicatively ground, functional ground, electronic ground, electrical ground).
[0114] Processor 502, memory 504, controller 506, or transceiver 508, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured to or otherwise support components for performing the functions described in this disclosure.
[0115] Processor 502 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some embodiments, processor 502 may be configured to operate memory 504. In some other embodiments, memory 504 may be integrated into processor 502. Processor 502 may be configured to execute computer-readable instructions stored in memory 504 to cause NE 500 to perform various functions of this disclosure.
[0116] Memory 504 may comprise volatile or non-volatile memory. Memory 504 may store computer-readable, computer-executable code containing instructions that, when executed by processor 502, cause NE 500 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as memory 504 or another type of memory. Computer-readable medium includes both non-transitory computer storage media and communication media, wherein the communication media includes any media that facilitates the transfer of a computer program from one place to another. Non-transitory storage media may be any available media accessible by a general-purpose or special-purpose computer.
[0117] In some implementations, processor 502 and memory 504 coupled to processor 502 may be configured to cause NE 500 to perform one or more of the functions described herein (e.g., processor 502 executing instructions stored in memory 504). For example, processor 502 may support wireless communication at NE 500 according to the examples disclosed herein.
[0118] Controller 506 manages the input and output signals of NE 500. Controller 506 can also manage peripheral devices not integrated into NE 500. In some embodiments, controller 506 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some embodiments, controller 506 may be implemented as part of processor 502.
[0119] In some embodiments, the NE 500 may include at least one transceiver 508. In other embodiments, the NE 500 may have more than one transceiver 508. The transceiver 508 may represent a wireless transceiver. The transceiver 508 may include one or more receiver chains 510, one or more transmitter chains 512, or a combination thereof.
[0120] Receiver chain 510 may be configured to receive signals (e.g., control information, data, packets) via wireless media. For example, receiver chain 510 may include one or more antennas for receiving signals over the air or wireless media. Receiver chain 510 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 510 may include at least one demodulator configured to demodulate the received signal and obtain transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 510 may include at least one decoder for decoding the demodulated signal to receive transmitted data.
[0121] Transmitter chain 512 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 512 may include at least one modulator for modulating data onto a carrier signal in preparation for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 512 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 512 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0122] The NE 500 can be configured or operated to support a component for: receiving an access request message from a device, wherein the device does not support direct communication with a first type of network compatible with the NE, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network and an indication that the device supports the assignment of a temporary identifier for use with the first type of network; generating a temporary identifier for use with the first type of network for the device; and transmitting the assignment of the temporary identifier via a wireless access point associated with the second type of network for use with the first type of network.
[0123] In operation according to possible embodiments, at least one processor 502 may be configured or operable to cause NE 500 to receive an access request message from a device, wherein the device does not support direct communication with a first type of network compatible with the NE, and wherein the access request message is received indirectly via a radio access point associated with a second type of network. The access request message may include a subscription identity for use with the first type of network and an indication that the device supports the assignment of a temporary identifier for use with the first type of network. At least one processor 502 may generate a temporary identifier for use with the first type of network for the device. Transmitter chain 512 and / or transceiver 508 may transmit the assignment of the temporary identifier via a radio access point associated with the second type of network for use with the first type of network.
[0124] According to possible embodiments, the radio access point associated with the second type of network may have an interworking function (IF) for communicating with the Access and Mobility Management Function (AMF) of the NE. In some of these examples, the assignment of a temporary identifier for use with the first type of network may be sent from the AMF via the radio access point associated with the second type of network as part of the N2 Initial Context Establishment Request, based on support indicated by the device for the assignment of a temporary identifier for use with the first type of network. Furthermore, the N2 Initial Context Establishment Request sent by the AMF of the first type of network may include an encryption key to support communication between the AMF and the IF of the radio access point associated with the second type of network, in addition to the assignment of the temporary identifier for use with the first type of network.
[0125] In some examples, the assignment of a temporary identifier for use with the first type of network may be received by the radio access point associated with the second type of network from the AMF, as part of an N2 message indicating registration acceptance, based on the indication of support by the device for the assignment of a temporary identifier for use with the first type of network. In some of these examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an IP configuration response message. In others of these examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) request message. In further other examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) success message.
[0126] Figure 6 A flowchart 600 illustrates an example of a method according to an aspect of this disclosure. The operation of the method can be implemented by an apparatus as described herein (e.g., an N5CW device). In some embodiments, the apparatus may execute a set of instructions to control the functional elements of the apparatus to perform the described functions.
[0127] At 602, the method may include indirectly sending an access request message to a first-type network via a wireless access point associated with a second-type network, the access request message including a subscription identity for use with the first-type network and an indication that the device supports the assignment of a temporary identifier for use with the first-type network. At 604, the method may include receiving an assignment of a temporary identifier for use with the first-type network via a wireless access point associated with the second-type network.
[0128] According to possible embodiments, the radio access point associated with the second type of network may have an interworking function (IF) for communicating with the Access and Mobility Management Function (AMF) of the first type of network. In some of these examples, the assignment of a temporary identifier for use with the first type of network may be received from the AMF via the radio access point associated with the second type of network as part of the N2 Initial Context Establishment Request, based on support indicated by the device for the assignment of a temporary identifier for use with the first type of network. Furthermore, the N2 Initial Context Establishment Request sent by the AMF of the first type of network may include an encryption key to support communication between the AMF and the IF of the radio access point associated with the second type of network, in addition to the assignment of the temporary identifier for use with the first type of network.
[0129] In some examples, the assignment of a temporary identifier for use with the first type of network may be received by the radio access point associated with the second type of network from the AMF, as part of an N2 message indicating registration acceptance, based on the indication of support by the device for the assignment of a temporary identifier for use with the first type of network. In some of these examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an IP configuration response message. In others of these examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) request message. In further other examples, the assignment of a temporary identifier for use with the first type of network may be received by the device from the radio access point associated with the second type of network, as part of an Extensible Authentication Protocol (EAP) success message.
[0130] It should be noted that the method described herein describes one possible implementation, and the operation and steps may be rearranged or modified in other ways, and other implementations are possible.
[0131] Figure 7 Flowchart 700 illustrates an example of a method according to aspects of this disclosure. The operation of the method can be performed by an NE (e.g., implementing...). Figure 2A and 2B At least one NE of the TWIF is implemented. In some implementations, the NE can execute a set of instructions to control the functional elements of the NE to perform the described functions.
[0132] At 702, the method may include receiving an access request message from a device, wherein the device does not support direct communication with a first type of network compatible with NE, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network. The access request message may include a subscription identity for use with the first type of network and an indication that the device supports the assignment of a temporary identifier for use with the first type of network.
[0133] At 704, the method may include generating a temporary identifier for the device to be used in conjunction with a first type of network.
[0134] At 706, the method may include sending an assignment of a temporary identifier via a wireless access point associated with a second type of network for use by the device with a first type of network.
[0135] It should be noted that the method described herein describes one possible implementation, and the operation and steps may be rearranged or modified in other ways, and other implementations are possible.
[0136] The description herein is provided to enable those skilled in the art to make or use this disclosure. Various modifications to this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of this disclosure. Therefore, this disclosure is not limited to the examples and designs described herein, but should be given the widest scope consistent with the principles and novel features disclosed herein.
[0137] At least some of the methods disclosed herein can be implemented on a programmable processor. However, the controller, flowchart, and module can also be implemented on a general-purpose or special-purpose computer, a programmable microprocessor or microcontroller and peripheral integrated circuit elements, integrated circuits, hardware electronics or logic circuits (e.g., discrete element circuits), programmable logic devices, etc. Generally, any device on which resides a finite state machine capable of implementing the flowcharts shown in the figures can be used to implement the processor functions of this disclosure.
[0138] At least some embodiments may improve the operation of the disclosed apparatus. Various components of the embodiments may be interchanged, added, or replaced in other embodiments. Furthermore, not all elements in each figure are essential for the operation of the disclosed embodiments. For example, those skilled in the art to which the disclosed embodiments pertain will be able to make and use the teachings of this disclosure by simply employing the elements of the independent claims. Therefore, the embodiments of this disclosure as described herein are intended to be illustrative and not restrictive. Various changes may be made without departing from the spirit and scope of this disclosure.
[0139] The article “a” preceding an element is unrestricted and should be understood to mean “at least one” or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” are interchangeable. For example, without further constraints, an element beginning with “a (a / an)” or similar does not exclude the presence of additional identical elements in a process, method, article, or apparatus that includes said element. As used herein, the word “or” included in the claims, as used in a list of items (e.g., a list of items beginning with phrases such as “at least one of,” “one or more of,” or “one or two”) indicates an inclusive list such that a list of at least one of, for example, A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). For example, the phrase “at least one of,” “at least one selected from a set,” or “at least one selected from…” followed by a list is defined as indicating one, some, or all of the elements in the list, but not necessarily all of them. Furthermore, as used herein, the phrase “based on” should not be construed as referring to a closed set of conditions. For example, without departing from the scope of this disclosure, an example step described as “based on condition A” may be based on both condition A and condition B. In other words, as used herein, the phrase “based on” should be interpreted in the same manner as the phrase “at least partially based on.” Additionally, as used herein, encompassed in the claims, “set” may include one or more elements.
[0140] The terms “comprises / comprising,” “including,” or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements may include not only those elements but also other elements not expressly listed or inherent to such a process, method, article, or apparatus. Furthermore, the term “another” is defined as at least a second or more. The terms “having” and similar terms as used herein are defined as “comprising.” Unless otherwise defined, approximation terms, such as “approximate,” “close to,” “substantially,” and / or other related terms, are defined as a range within + / - 5% of an approximate element, a range within + / - 10% of an approximate element, and / or a range sufficiently close to the approximate element to achieve the desired result. All elements of the disclosed embodiments can be modified using such terms. In this document, relational terms such as “first,” “second,” etc., may be used only to distinguish one entity or action from another entity or action, and do not necessarily require or imply any actual such relationship or order between such entities or actions.
[0141] The background section is not considered prior art, but is written at the time of application as the inventor's own understanding of the context of some embodiments, and includes the inventor's own awareness of any problems with the prior art and / or problems experienced by the inventor in their own work.
Claims
1. An apparatus for wireless communication, comprising: At least one memory; and At least one processor, coupled to and operable to cause the device to: The device indirectly sends an access request message to a first-type network via a wireless access point associated with a second-type network. The access request message includes a subscription identity for use with the first-type network and an indication that the device supports the assignment of a temporary identifier for use with the first-type network. and The assignment of the temporary identifier for use with the network of the first type is received via the wireless access point associated with the network of the second type.
2. The apparatus of claim 1, wherein the wireless access point associated with the network of the second type has an interoperability function (IF) for communicating with the access and mobility management function (AMF) of the network of the first type.
3. The apparatus of claim 2, wherein the assignment of the temporary identifier for use with the first type of network is received from the AMF via the wireless access point associated with the second type of network, based on the indicated support of the assignment by the apparatus for the use of the temporary identifier for use with the first type of network, as part of the N2 initial context establishment request.
4. The apparatus of claim 3, wherein the N2 Initial Context Establishment Request sent by the AMF of the first type of network includes an encryption key to support communication between the AMF and the IF of the wireless access point associated with the second type of network, in addition to the assignment of the temporary identifier for use by the apparatus with the first type of network.
5. The apparatus of claim 2, wherein the wireless access point associated with the second type of network receives from the AMF, based on the indicated support of the assignment of the temporary identifier for use with the first type of network, as part of an N2 message indicating registration acceptance, the assignment of the temporary identifier for use with the first type of network.
6. The apparatus of claim 5, wherein the apparatus receives the assignment of the temporary identifier for use with the network of the first type from the wireless access point associated with the network of the second type as part of an IP configuration response message.
7. The apparatus of claim 5, wherein the apparatus receives, from the wireless access point associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type as part of an Extensible Authentication Protocol (EAP) request message.
8. The apparatus of claim 5, wherein the assignment of the temporary identifier for use with the network of the first type is received by the apparatus from the wireless access point associated with the network of the second type as part of an Extensible Authentication Protocol (EAP) success message.
9. A method performed by an apparatus, the method comprising: The device indirectly sends an access request message to a first-type network via a wireless access point associated with a second-type network. The access request message includes a subscription identity for use with the first-type network and an indication that the device supports the assignment of a temporary identifier for use with the first-type network. and The assignment of the temporary identifier for use with the network of the first type is received via the wireless access point associated with the network of the second type.
10. The method of claim 9, wherein the wireless access point associated with the network of the second type has an interoperability function (IF) for communicating with the access and mobility management function (AMF) of the network of the first type.
11. The method of claim 10, wherein the assignment of the temporary identifier for use with the first type of network is received from the AMF via the wireless access point associated with the second type of network, based on the indicated support of the device for the assignment of the temporary identifier for use with the first type of network, as part of the N2 initial context establishment request.
12. A network device, comprising: At least one memory; and At least one processor coupled to the at least one memory and operable to equip the network: The device receives an access request message, wherein the device does not support direct communication with a first type of network compatible with the network equipment, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network, and an indication that the device supports the assignment of a temporary identifier for use with the first type of network. Generate a temporary identifier for the device to be used in conjunction with the network of the first type; and The assignment of the temporary identifier is sent via the wireless access point associated with the network of the second type for use by the device with the network of the first type.
13. The network equipment of claim 12, wherein the wireless access point associated with the network of the second type has an interoperability function IF for communicating with the access and mobility management function AMF of the network equipment.
14. The network apparatus of claim 13, wherein, based on the indicated support of the device for the assignment of a temporary identifier for use with the first type of network, the assignment of the temporary identifier for use with the first type of network is sent from the AMF via the wireless access point associated with the second type of network as part of an N2 initial context establishment request.
15. The network apparatus of claim 14, wherein the N2 Initial Context Establishment Request sent by the AMF of the first type of network includes an encryption key to support communication between the AMF and the IF of the wireless access point associated with the second type of network, in addition to the assignment of the temporary identifier for use by the apparatus with the first type of network.
16. The network apparatus of claim 13, wherein, based on the indicated support for the assignment of a temporary identifier for use with the first type of network by the device, the wireless access point associated with the second type of network receives from the AMF the assignment of the temporary identifier for use with the first type of network as part of an N2 message indicating registration acceptance.
17. The network apparatus of claim 16, wherein the device receives, as part of an IP configuration response message, the assignment of the temporary identifier for use with the network of the first type from the wireless access point associated with the network of the second type.
18. The network apparatus of claim 16, wherein the device receives, from the wireless access point associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type as part of an Extensible Authentication Protocol (EAP) request message.
19. The network apparatus of claim 16, wherein the device receives, from the wireless access point associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type as part of an Extensible Authentication Protocol (EAP) success message.
20. A method performed by a network device, the method comprising: The device receives an access request message, wherein the device does not support direct communication with a first type of network compatible with the network equipment, and wherein the access request message is received indirectly via a wireless access point associated with a second type of network, the access request message including a subscription identity for use with the first type of network, and an indication that the device supports the assignment of a temporary identifier for use with the first type of network. Generate a temporary identifier for the device to be used in conjunction with the network of the first type; and The assignment of the temporary identifier is sent via the wireless access point associated with the network of the second type for use by the device with the network of the first type.