Methods, apparatuses, and systems for su pi protection in a communication network

CN122893318APending Publication Date: 2026-10-09ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480089271.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-03
Publication Date
2026-10-09

AI Technical Summary

Technical Problem

公共无线网络与私有无线网络之间的互联在安全方面带来了重大挑战

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122893318A_ABST
    Figure CN122893318A_ABST
Patent Text Reader

Abstract

The present disclosure relates generally to protecting sensitive user subscription data in wireless communications. The method is performed by a first network element and comprises receiving, from a wireless device, a first message for a service request for a wireless network, the first message carrying at least one of: a SUCI of the wireless device; or a first 5G-GUTI of the wireless device; and sending, to a second network element, a second message for an authentication request, the second message carrying at least one of: a SN name of a SN serving the wireless device; the SUCI of the wireless device; a UE identifier of the wireless device associated with a SUPI of the wireless device; a service indicator indicating that a security domain of a service initiated in association with the second message is different from a security domain of the second network element; or an identifier of the first network element.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to wireless communications, and more particularly to protecting sensitive user subscription data in communication networks such as 4G, 5G and 6G wireless communication networks. Background Technology

[0002] With the proliferation of mobile devices and the ever-increasing demand for data, mobile operators are widely deploying public wireless networks, while enterprises are widely deploying private wireless networks. Private wireless networks are typically deployed within defined geographical areas, such as campuses, factories, or facilities. Interconnection between public and private wireless networks presents significant security challenges. Establishing secure inter-network operations is crucial for achieving seamless and secure communication between these two different network environments. Implementing robust security measures at the interface between public and private wireless networks is essential for ensuring the privacy and integrity of wireless communications. Summary of the Invention

[0003] This disclosure discloses methods, systems, apparatuses, and storage media relating to wireless communication, and particularly relates to protecting sensitive user subscription data in wireless communication networks such as 4G, 5G, and 6G wireless communication networks.

[0004] In one embodiment, this disclosure describes a method for wireless communication. The method is performed by a first network element and includes: receiving a first message from a wireless device for a service request for a wireless network, the first message carrying at least one of the following: a Subscription Concealed Identifier (SUCI) of the wireless device; or a first 5G Global Unique Temporary Identifier (5G-GUTI) of the wireless device; and sending a second message to a second network element for an authentication request, the second message carrying at least one of the following: the SN name of the Serving Network (SN) serving the wireless device; the SUCI of the wireless device; a User Equipment (UE) identifier of the wireless device associated with its Subscription Permanent Identifier (SUPI); a service indicator indicating that the security domain initiating the service associated with the second message is different from the security domain of the second network element; or an identifier of the first network element.

[0005] In another embodiment, a method for wireless communication is disclosed. The method is executed by a first network element and includes: receiving a first message from a wireless device for a service request for a wireless network, the first message carrying at least one of the following: a Subscription Hidden Identifier (SUCI) of the wireless device; or a first 5G Globally Unique Temporary Identifier (5G-GUTI) of the wireless device; and sending a second message to a second network element for an authentication request, the second message carrying at least one of the following: the SN name of the serving network (SN) serving the wireless device; a Subscription Permanent Identifier (SUPI) of the wireless device; a User Equipment (UE) identifier of the wireless device associated with the Subscription Permanent Identifier (SUPI); a service indicator indicating that the security domain initiating the service associated with the second message is different from the security domain of the first network element; or an identifier of the first network element.

[0006] In another embodiment, a method for wireless communication is disclosed. The method is executed by a first network element and includes: receiving a first message from a second network element, the first message being an authentication request initiated by a wireless device, the first message carrying at least one of the following: the SN name of the serving network (SN) serving the wireless device; the SUCI of the wireless device; the user equipment (UE) identifier of the wireless device associated with its subscription permanent identifier (SUPI); the identifier of the second network element; a service indicator indicating that the security domain initiating the service associated with the first message is different from the security domain of the first network element; or an indicator indicating that the first security domain initiating the authentication request of the wireless device is different from the second security domain to which the first network element belongs; and sending a second message for the authentication request of the wireless device to a third network element, the second message carrying at least one of the following: the SN name of the SN serving the wireless device; the SUCI of the wireless device; the UE identifier of the wireless device associated with its SUPI; the identifier of the second network element; or an indicator indicating that the first security domain initiating the authentication request of the wireless device is different from the second security domain to which the first network element belongs.

[0007] In another embodiment, a network element or wireless device including a processor and memory is disclosed. The processor may be configured to read computer code from memory to implement any of the methods described above.

[0008] In yet another embodiment, a computer program product is disclosed, comprising a non-transitory computer-readable program medium having computer code stored thereon. When the computer code is executed by a processor, the processor may perform any of the methods described above.

[0009] The above embodiments and other implementation methods and alternatives are explained in more detail in the following drawings, description and claims. Attached Figure Description

[0010] Figure 1 An exemplary communication network is shown, including various terminal devices, carrier networks, data networks, and service applications.

[0011] Figure 2 This illustrates exemplary network functions or network nodes in a communication network.

[0012] Figure 3 This illustrates exemplary network functions or network nodes in a wireless communication network.

[0013] Figure 4 An exemplary network model of a non-public network (NPN) carried by a Public Land Mobile Network (PLMN) is shown.

[0014] Figure 5 Example wireless network node (or network element, network function, network entity, entity, application function) is shown.

[0015] Figure 6 Example user equipment is shown.

[0016] Figure 7 An exemplary logic flow for interaction between an NPN and a PLMN with SUPI protection is shown.

[0017] Figure 8 This illustrates another exemplary logic flow for interaction between an NPN and a PLMN with SUPI protection. Detailed Implementation

[0018] Figure 1An exemplary communication network, shown as 100, may include terminal devices 110 and 112, a carrier network 102, various service applications 140, and other data networks 150. For example, carrier network 102 may include access network 120 and core network 130. Carrier network 102 may be configured to transmit voice, data, and other information (collectively, data communications) between terminal devices 110 and 112, between terminal devices 110 and 112 and service applications 140, or between terminal devices 110 and 112 and other data networks 150. Communication sessions and corresponding data paths may be established and configured for such data transmission. Access network 120 may be configured to provide network access to core network 130 to terminal devices 110 and 112. Access network 120 may, for example, support wireless access via radio resources or wired access. Core network 130 may include various network nodes or network functions configured to control communication sessions and perform network access management and data communication routing. Service application 140 can be hosted by various application servers, which can be accessed by terminal devices 110 and 112 through the core network 130 of operator network 102. Service application 140 can be deployed as a data network outside the core network 130. Similarly, terminal devices 110 and 112 can access other data networks 150 through the core network 130, and these other data networks can be presented as data destinations or data sources for specific communication sessions instantiated in operator network 102.

[0019] Figure 1 The core network 130 may include various geographically distributed and interconnected network nodes or functions to provide network coverage for the service area of ​​the operator network 102. These network nodes or functions may be implemented as dedicated hardware network units. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or software entities. Various network nodes may be configured with one or more types of network functions. These network nodes or network functions may collectively provide provisioning and routing functions for the core network 130. The terms "network node" and "network function" are used interchangeably in this disclosure.

[0020] Figure 2 This further illustrates an exemplary division of network functions within the core network 130 of the communication network 200. Although in Figure 2 Only a single instance of a network node or function is shown, but those skilled in the art will understand that each of these network nodes can be instantiated as multiple instances of network nodes distributed throughout the core network 130. Figure 2As shown, the core network 130 may include, but is not limited to, network nodes such as access management network node (AMNN) 230, authentication network node (AUNN) 260, network data management network node (NDMNN) 270, session management network node (SMNN) 240, data routing network node (DRNN) 250, policy control network node (PCNN) 220, and application data management network node (ADMNN) 210. Figure 2 In the diagram, the solid lines connecting the nodes represent exemplary signaling and data exchanges between various types of network nodes through various communication interfaces. Such signaling and data exchanges can be carried by signaling or data information that follows a predetermined format or protocol.

[0021] The above Figure 1 and Figure 2 The implementation methods described herein can be applied to wireless and wired communication systems. Figure 3 Showing based on Figure 2 An exemplary cellular wireless communication network 300 is a general implementation of the communication network 200. Figure 3 A wireless communication network 300 is shown, which may include a user equipment (UE) 310 (used as...) Figure 2 Terminal equipment 110), radio access network (RAN) 320 (used as terminal equipment 110), radio access network (RAN) 320 Figure 2 The network comprises an access network 120, a data network (DN) 150, and a core network 130, the core network including an access management function (AMF) 330 (used as...). Figure 2 AMNN230), session management function (SMF) 340 (used as AMNN230), session management function (SMF) 340 Figure 2 SMNN 240), application function (AF) 390 (used as Figure 2 ADMNN 210), user plane function (UPF) 350 (used as Figure 2 DRNN 250), policy control function (PCF) 322 (used as Figure 2 PCNN 220), authentication server function (AUSF) 360 (used as Figure 2 AUNN 260) and Universal Data Management (UDM) functionality 370 (used as Figure 2 UDMNN 270). Similarly, although Figure 3 Only a single instance of some network functions or nodes of the wireless communication network 300 (particularly the core network 130) is shown; however, those skilled in the art will understand that each of these network nodes or functions can have multiple instances distributed throughout the wireless communication network 300. While AF 390 is... Figure 3 While depicted as part of the core network 130, these functions may be considered associated with specific service applications 140 and may be considered located outside the core network 140. In this disclosure, the various functions deployed in the wireless network as described above may also be referred to as functional entities, which may be implemented via hardware, software, or a combination thereof as network nodes, network elements, or logical functions.

[0022] exist Figure 3 In this configuration, UE 310 can be implemented as various types of mobile devices configured to access core network 130 via RAN 320. UE 310 can include, but is not limited to, mobile phones, laptops, tablets, Internet of Things (IoT) devices, distributed sensor network nodes, wearable devices, etc. The UE can also be a UE with multi-access edge computing (MEC) capabilities that support edge computing. For example, RAN 320 can include multiple radio base stations distributed throughout the service area of ​​the operator's network. Communication between UE 310 and RAN 320 can be achieved through methods such as... Figure 3 The over-the-air (OTA) wireless interface shown in 311 is used.

[0023] Continue to refer to Figure 3 The UDM 370 can form a persistent storage or database for user contracts and contractual data. The UDM can also include an authentication credential repository and processing function (ARPF, such as...) Figure 3As shown in UDM / ARPF 370, it stores a long-term security certificate used for user authentication and uses this long-term security certificate as input to perform calculations of the encryption key, as described in more detail below. To prevent unauthorized exposure of UDM / ARPF data, UDM / ARPF 370 can be located in a secure network environment of a network operator or a third party.

[0024] The AMF / SEAF 330 can communicate with RAN 320, SMF 340, AUSF 360, UDM / ARPF 370, and Policy Control Function (PCF) 322 through various communication interfaces indicated by solid lines connecting these network nodes or functions. The AMF / SEAF 330 can handle signaling management from the UE to the Non-access stratum (NAS), and is responsible for providing UE 310 registration and access to the core network 130, as well as SMF 340 allocation to support the communication needs of specific UEs. The AMF / SEAF 330 can also handle UE mobility management. The AMF may also include a security anchor function (SEAF, such as...) Figure 3 As shown in AMF / SEAF 330 (and described in more detail below), this security anchor function interacts with AUSF 360 and UE 310 for user authentication and various levels of encryption / decryption key management. AUSF 360 can terminate user registration / authentication / key generation requests from AMF / SEAF 330 and interact with UDM / ARPF 370 to complete such user registration / authentication / key generation.

[0025] The SMF 340 can be assigned by the AMF / SEAF 330 to a specific communication session instantiated in the wireless communication network 300. The SMF 340 can be responsible for allocating the UPF 350 to support the communication session and data flow within the user data platform, and for provisioning / regulating the allocated UPF 350 (e.g., for developing packet detection and forwarding rules for the allocated UPF 350). In addition to allocation by the SMF 340, the UPF 350 can be allocated by the AMF / SEAF 330 for specific communication sessions and data flows. The UPF 350 allocated and provided by the SMF 340 and AMF / SEAF 330 can be responsible for data routing and forwarding, as well as reporting network usage for specific communication sessions. For example, the UPF 350 can be responsible for routing end-to-end data flows between UE 310 and DN 150, and between UE 310 and serving application 140. DN 150 and service application 140 may include, but are not limited to, data networks and services provided by the operator of wireless communication network 300 or by third-party data network and service providers.

[0026] PCF 322 can manage and provide AMF / SEAF 330 and SMF 340 with policies and rules at various levels applicable to communication sessions associated with UE 310. Thus, for example, AMF / SEAF 330 can assign SMF 340 to a communication session based on the policies and rules associated with UE 310 and obtained from PCF 322. Similarly, SMF 340 can assign UPF 350 to handle data routing and forwarding for the communication session based on the policies and rules obtained from PCF 322.

[0027] although Figures 1-3 The exemplary embodiments described below are based on cellular wireless communication networks, but the scope of this disclosure is not limited thereto, and the basic principles are applicable to other types of wireless and wired communication networks.

[0028] Figure 3 Network identity and data security in the wireless communication network 300 can be managed through the user authentication process provided by AMF / SEAF 330, AUSF360, and UDM / ARPF 370. Specifically, UE 310 can first communicate with AMF / SEAF330 to register with the network, and then be authenticated by AUSF 360 based on the user contract and subscription data in UDM / ARPF 370. After user authentication with the wireless communication network 300, the communication session established for UE 310 can be protected by encryption / decryption keys at various levels. The generation and management of various keys can be coordinated by AUSF 360 and other network functions in the communication network 300.

[0029] Security Domains - Carrier Premises and Customer Premises Figure 4 An exemplary network model 400 is shown, including carrier premises and customer premises. The carrier premises may include, for example, a Unified Data Management (UDM) entity, a Network Exposure Function (NEF) entity, a Network Repository Function (NRF) entity, a Policy Control Function (PCF) entity, a User Plane Function (UPF) entity, an Authentication Server Function (AUSF) entity, an AMF entity, a Session Management Function (SMF) entity, and may also include an Application Function (AF) entity. The customer premises may include, for example, an AMF entity, an SMF entity, a UPF entity, and a data network (DN).

[0030] In network model 400, operator premises may include a Public Land Mobile Network (PLMN), which is managed and operated by a public operator. Customer premises may include private networks, such as Non-Public Networks (NPNs) of the 3rd Generation Partnership Project (3GPP). NPNs may be operated or managed by, for example, private entities (such as private enterprises or private operators). NPNs may be deployed as Stand-alone NPNs (SNPNs), which do not depend on services or applications provided by the PLMN. NPNs may also be deployed as Public Network Integrated NPNs (PNI-NPNs), which interconnect with the PLMN. In some example implementations, a PNI-NPN may share a Radio Access Network (RAN) with the PLMN. In some example implementations, a PNI-NPN may share at least a portion of the Control Plane (CP) and / or User Plane (UP) functions with the PLMN.

[0031] In wireless networks such as 5G, a Service Based Architecture (SBA) framework has been implemented to expose the functionality of various network elements to each other. The SBA framework enhances network deployment flexibility by providing rich configuration options. Through SBA implementation, various components and functions within a wireless network (including PLMNs and private networks) can seamlessly interact and leverage each other's capabilities, promoting more flexible and modular network deployments that can adapt to diverse operational requirements.

[0032] In such Figure 4 In some of the network deployments shown, dedicated UPFs and some CP functions are deployed at the customer premises. The dedicated network functions (NFs) at the customer premises can communicate with the NFs at the operator premises via SBA interfaces. In this example deployment, the CP functions carried by the NPNs at the customer premises include AMF and SMF entities.

[0033] In some other network deployments, a dedicated UPF is deployed at the customer premises, which can interact with the operator premises via, for example, an N4 interface (not an SBA interface).

[0034] Figure 5Examples of electronic devices 500 are shown for implementing various network nodes, network elements, and network entities, such as network base stations (e.g., radio access network nodes), core networks (CNs), core network components / entities (e.g., AMFs, UDMs, AAnFs, etc.), operations and maintenance (OAM), etc. Optionally, in one embodiment, the example electronic device 500 may include radio transmit / receive (Tx / Rx) circuitry 508 for transmitting / receiving communication with a UE and / or other base stations. Optionally, in one embodiment, the electronic device 500 may also include network interface circuitry 509 for communicating with other base stations and / or the core network, such as optical or wired interconnects, Ethernet, and / or other data transmission media / protocols. The electronic device 500 may optionally include input / output (I / O) interfaces 506 for communicating with operators, etc.

[0035] The electronic device 500 may also include system circuitry 504. System circuitry 504 may include a processor 521 and / or memory 522. Memory 522 may include an operating system 524, instructions 526, and parameters 528. Instructions 526 may be configured for use by one or more processors 521 to perform functions of the network node. Parameters 528 may include parameters to support the execution of instructions 526. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping allocation, and / or other parameters.

[0036] In this disclosure, network functions / network entities / entities, such as AMF, AUSF, UDM, AAnF, NEF, and AF, can be implemented in hardware, software, or a combination of hardware and software, and can be implemented or integrated in electronic device 500. They can also be implemented as logical entities carried by electronic device 500.

[0037] Figure 6An example of an electronic device for implementing a terminal device 600 (e.g., a UE) is shown. The UE 600 may be a mobile device, such as a smartphone or a mobile communication module installed in a vehicle. The UE 600 may include some or all of the following: a communication interface 602, system circuitry 604, input / output interfaces (I / O) 606, display circuitry 608, and memory 609. The display circuitry may include a user interface 610. The system circuitry 604 may include any combination of hardware, software, firmware, or other logic / circuit. The system circuitry 604 may be implemented, for example, using one or more system-on-chip (SoC), application-specific integrated circuits (ASICs), discrete analog and digital circuits, and other circuits. The system circuitry 604 may be part of an implementation of any desired functionality in the UE 600. In this respect, system circuitry 604 may include logic that facilitates, for example, decoding and playing music and video, such as MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user input; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections, such as for internet connections; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on user interface 610. User interface 610 and input / output (I / O) interface 606 may include a graphical user interface, a touch-sensitive display, haptic feedback or other haptic outputs, voice or facial recognition inputs, buttons, switches, speakers, and other user interface elements. Other examples of I / O interface 606 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headphone and microphone input / output jacks, universal serial bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors), and other types of inputs.

[0038] refer to Figure 6The communication interface 602 may include radio frequency (RF) transmit (Tx) and receive (Rx) circuitry 616, which processes the transmission and reception of signals via one or more antennas 614. The communication interface 602 may include one or more transceivers. The transceiver may be a wireless transceiver, including modulation / demodulation circuitry, a digital-to-analog converter (DAC), a shaping table, an analog-to-digital converter (ADC), a filter, a waveform shaper, a preamplifier, a power amplifier, and / or other logic for transmission and reception via one or more antennas or (for some devices) via a physical (e.g., wired) medium. The transmitted and received signals may follow any of a variety of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM), frequency channels, bit rates, and encodings. As a specific example, the communication interface 602 may include a transceiver supporting transmission and reception under 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS), High-Speed ​​Packet Access (HSPA)+, 4G / LTE, 5G, and 6G standards. However, the techniques described below are applicable to other wireless communication technologies, regardless of whether they originate from the 3rd Generation Partnership Project (3GPP), the GSM Association, 3GPP2, IEEE, or other partners or standards bodies.

[0039] refer to Figure 6 System circuitry 604 may include one or more processors 621 and memory 622. Memory 622 stores, for example, an operating system 624, instructions 626, and parameters 628. Processor 621 is configured to execute instructions 626 to perform the desired functions of UE 600. Parameters 628 can provide and specify configuration and operational options for instructions 626. Memory 622 may also store any BT, WiFi, 3G, 4G, 5G, 6G, or other data that UE 600 will send or has received via communication interface 602. In various embodiments, the system power of UE 600 may be provided by power storage devices such as batteries or transformers.

[0040] UE Identification Protection in Wireless Networks In wireless communication networks, if the UE identifier (such as the Subscription Permanent Identifier (SUPI)) is available to the network function (NF) in plaintext at the customer’s premises during the primary authentication and authorization process, it may potentially lead to security threats, privacy breaches, UE location tracking, and targeted attacks.

[0041] Furthermore, with the evolution of roaming architectures (such as roaming hubs) and core networks (NPN, edge computing), distributed CNs (multi-site CNs), there is no direct trust relationship between the Home Network (HN) and various other networks (such as Serving Network (SN), Visiting PLMN (VPLMN), and Edge Network) (i.e., between different security domains). Therefore, for the HN, there are serious security concerns about opening permanent and / or sensitive information (such as UE identifiers and other parameters) to NFs that are not in the HN.

[0042] In this disclosure, the term "security domain" is used to refer to different domains encompassing entities involved in network infrastructure, physical premises, or the network ecosystem. Different security domains exist in wireless networks (PLMNs and NPNs) for various reasons. Security domains can be categorized by network owner / operator. For example, a PLMN may be owned and / or operated by a communications service provider, while an NPN may be owned and / or operated by a private enterprise, private entity, etc. Security domains can also be categorized by regulatory compliance and risk management. For example, a PLMN may be classified as relatively low-risk compared to an NPN. The embodiments described below may use the terms "customer domain" and "carrier domain" to represent different security domains. Regardless of the specific terminology used, the basic concepts and principles apply to all other types of security domains.

[0043] Privacy-sensitive SUPIs are identifiers provided by the home network operator specifically for identifying its users and associated subscription information for processing related services. Robust mechanisms are needed to address the potential risks associated with sharing sensitive user data between different security domains. Such mechanisms are crucial for protecting sensitive information (e.g., SUPIs) to address the risks arising when PLMNs carry NPNs or NPNs carry PLMNs.

[0044] In this disclosure, the UE's SUPI, as sensitive information associated with the user's identity within a PLMN (whether a Home PLMN, HPLMN, or VPLMN), should be protected to safeguard user privacy and prevent security vulnerabilities. Transmission of the UE's SUPI across security domains is not permitted, or the transmission of SUPI between different security domains is not permitted without appropriate protection mechanisms.

[0045] To accommodate interconnection between two security domains, an alternative UE identifier is introduced. First, this newly introduced alternative UE identifier differs from various existing UE identifiers in the wireless standard, such as SUCI, SUPI, or 5G-GUTI (5G Globally Unique Temporary Identifier). Second, the alternative UE identifier can be specifically used for information exchange between the two security domains. Third, the alternative UE identifier can be derived from or generated from the UE's SUPI, but it can undergo a secure conversion process to ensure its confidentiality and integrity. For example, it can include encrypting the SUPI using one or more secure keys. Specifically, the conversion process differs from the process used to generate existing UE identifiers (such as SUCI). This ensures that even if the alternative UE identifier is compromised in one security domain, other UE identifiers remain secure and protected. In this disclosure, this newly introduced alternative UE identifier may be referred to as the PLMN-NPN UE ID or PLMNNPN UE ID, as it can be used across the PLMN and NPN domains. This name is for illustrative purposes only, and other names may be chosen to represent the alternative UE identifier.

[0046] There are several solutions for generating PLMN-NPN UE IDs. In some example implementations, encryption techniques can be used to generate the PLMN-NPN UE ID from the UE's SUPI. In some example implementations, a unique random number can be obtained and mapped to each SUPI, so the random number is a representation of the SUPI through the mapping relationship. When a random number is received, it can be mapped back to the SUPI. As an additional security layer, the random number can be further encrypted before being transmitted between security domains. In some example implementations, the PLMN-NPN UE ID is generated in one security domain and can be transmitted to different security domains for future use.

[0047] Example 1: In the case of SPNF and UDM being co-located, UE authentication at the customer premises is performed via AMF. In this embodiment, the network deployment includes two security domains. For example, such as Figure 4 As shown, one security domain is the customer's premises and the other security domain is the operator's premises.

[0048] In this embodiment, the UE is located in a customer premises and can initiate service requests using the AMF1 deployed in the customer premises. UE authentication can be initiated from the AMF1. See below for reference. Figure 7 This document describes in detail exemplary steps of a UE registration / authentication process initiated by AMF1. Exemplary methods may include some or all of these steps. In this disclosure, SEAF and AMF may co-locate, and the terms SEAF and AMF are used interchangeably. In some example implementations, the same entity within the network performs the functions associated with both SEAF and AMF. Figure 7In this context, AMF1 is located in the first security domain, such as a customer's premises. AMF2 is located in the second security domain, such as an operator's premises.

[0049] Step 1: The UE sends a registration request message to AMF1. The registration request message may carry the UE's SUCI or 5G-GUTI. AMF1 may execute a local policy such that if the registration request message carries a 5G-GUTI and that 5G-GUTI points to an AMF that is not in the same premises (or security domain) as AMF1 (e.g., AMF1 is in the customer premises, while the 5G-GUTI points to an AMF in the operator's premises), then AMF1 may initiate the UE's identity request procedure to obtain the UE's SUCI.

[0050] Step 2: AMF1 can initiate the UE authentication process. For example, AMF1 can invoke the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate request message to AUSF. The Nausf_UEAuthentication_Authenticate request message can carry the SUCI or the newly introduced alternative UE ID, namely the PLMNNPN UE ID. The Nausf_UEAuthentication_Authenticate request message can also carry the UE's serving network (SN) name. The SN can be the network in which the UE initiated the registration request. The Nausf_UEAuthentication_Authenticate request message can also carry the PLMNNPN service indication.

[0051] In this disclosure, the PLMNNPN service indication can indicate that a service request (or more broadly, a message / signaling) is cross-security domain. For example, the source of the message / request / signaling may be in one security domain, while its destination may be in another. Figure 7 As shown, the PLMNNPN service indication is used to indicate that the message originates from a customer premises location different from the operator's premises. In network deployment scenarios where both customer premises and operator premises are deployed, the PLMNNPN service indication is used to indicate to network elements in the operator premises that the corresponding message / request / signaling originates from the customer premises.

[0052] In this disclosure, the PLMNNPN service instruction may include at least one of the following: • SN name (indicating the SN that initiated the message); • PLMNNPN UE ID; • AMF ID (indicating the AMF that initiated the message); • PLMNNPN service indicator (e.g., represented as an Information Element (IE), bit, parameter, etc.); or • The name and / or type of the message / signaling (e.g., keywords, specific strings in the message name). As an example, the Nausf_UEAuthentication_Authenticate request message can be renamed to "Nausf_PLMNNPN_UEAuthentication_Authenticate request".

[0053] Step 3: Upon receiving the Nausf_UEAuthentication_Authenticate request message, AUSF sends a Nudm_UEAuthentication_Get request to the UDM. The Nudm_UEAuthentication_Get request may carry at least one of the following: the UE's SUCI; the PLMNNPN UE ID used in the customer's premises; the UE's serving network name; and the PLMNNPN service indication (if any) carried in the Nausf_UEAuthentication_Authenticate request message in Step 2.

[0054] Step 4: After receiving the Nudm_UEAuthentication_Get request, if a SUCI is received, the UDM can call the Subscription Identifier De-concealing Function (SIDF) to de-conceal the SUCI before the UDM can process the request, thereby obtaining the SUPI.

[0055] If a PLMNNPN UE ID is received, the newly introduced function, Security for PLMNNPN Network Function (SPNF), will be invoked to obtain the UE's SUPI. SPNF can decrypt the PLMNNPN UE ID to obtain the UE's SUPI. For example, SPNF can decrypt the PLMNNPN UE ID to obtain the UE's SUPI. Alternatively, SPNF can use a (SUPI, PLMNNPN UE ID) mapping to obtain the UE's SUPI.

[0056] In response, the UDM can, for example, respond to the AUSF with a Nudm_UEAuthentication_Get response message. The response message may carry the authentication vector (AV) created by the UDM (or ARPF). If a SUCI is received in step 3, the Nudm_Authenticate_Get response may also include the newly created PLMNNPN UE ID. Alternatively, if a PLMNNPN UE ID is received in step 3, there are two options based on the operator's policy. In the first option, the UDM can refresh / update the PLMNNPN UE ID, and the response message may carry the refreshed PLMNNPN UE ID. In the second option, it is not necessary to refresh the received PLMNNPN UE ID; the PLMNNPN UE ID received in step 3 is carried in the response message.

[0057] Step 5: AUSF can send a Nausf_UEAuthentication_UEAuthentication response message carrying AV to AMF1.

[0058] Step 6: AMF1 can send an authentication request message to the UE, and the UE can use a message carrying the authentication challenge result (RES). The system responds to the authentication response message.

[0059] Step 7: AMF1 can send a message carrying RES to AUSF The Nausf_UEAuthentication_Authenticate request message.

[0060] Step 8: AUSF can indicate to AMF1 in the Nausf_UEAuthentication_Authenticate response message whether authentication was successful from the home network's perspective. If authentication is successful, the anchor key (K) will be included in the Nausf_UEAuthentication_Authenticate response message. SEAF Send to AMF1.

[0061] If AUSF receives a SUCI or PLMNNPN UE ID from AMF1 in the authentication request (in step 2) and authentication is successful, AUSF may also include the PLMNNPN UE ID in the Nausf_UEAuthentication_Authenticate response message. If AUSF receives a SUCI in step 2, the PLMNNPN UE ID can be a newly created PLMNNPN UE ID. If AUSF receives a PLMNNPN UE ID in step 2, the PLMNNPN UE ID can be a refreshed PLMNNPN UE ID or the original PLMNNPN UE ID sent in step 2.

[0062] After receiving the Nausf_UEAuthentication_Authenticate response message, AMF1 can use the Key Deviation Function (KDF) to extract the key from the K... SEAF Derive its key K AMF K SEAF It can be 256 bits, and is the input key for the KDF. The following equation can be used to form the input string S of the KDF: S = FC || P0 || L0 || P1 || L1 || P2 || L2 || P3 || L3 ||... || Pn ||Ln in: "||" is the concatenation operator, and n is an integer.

[0063] FC is used to distinguish different instances of the algorithm. FC can be a single octet or two octets in the form FC1||FC2. For example, FC1 = 0xFF and FC2 is a single octet.

[0064] P0 ... Pn are n+1 input parameters, and L0 ... Ln is a two-octet representation of the length of the corresponding input parameter encoding P0 ... Pn.

[0065] In some example implementations, P0 is a predefined ASCII encoded string.

[0066] The final output, the derived key, is equal to the KDF computed on the string S using the input key. For example, the derived key = HMAC-SHA-256(key, S). As an example, the input can be set as follows: FC = 0x6D (for illustrative purposes only, other values ​​may be set).

[0067] P0 = PLMNNPN UE ID (for illustrative purposes only, depending on what UE identifier is used in the customer’s premises).

[0068] L0 = P0 length, the number of octets in P0.

[0069] P1 = ABBA parameter.

[0070] L1 = P1 length (e.g., the number of octets in P1).

[0071] The input key KEY is a 256-bit K SEAF .

[0072] Note further that for P0, the PLMNNPN UE ID is used as an example. It can be any other UE identifier used in the PLMN bearer NPN. P0 can be set to the PLMNNPN UE ID in Network Access Identifier (NAI) format, i.e., username@realm.

[0073] Step 9: If authentication is successful, AMF1 can send a registration acceptance message to the UE. AMF1 can then assign a new 5G-GUTI to the UE.

[0074] In some scenarios, AMF1 in the customer's premises needs to transfer the UE context to AMF2 in the operator's premises. For example, AMF1 can be the UE's old AMF, and AMF2 can be the UE's new AMF. There are two cases, described below.

[0075] Scenario 1: UE context transfer during mobile registration (e.g.) Figure 7 (As shown) Step 10: The UE can send a registration request message carrying 5G-GUTI (received from step 9) to AMF2 in the operator's premises.

[0076] Step 11: AMF2 sends a Namf_Communication_UEContextTransfer message to AMF1 at the customer's premises.

[0077] Step 12: AMF1 in the customer premises responds to AMF2 in the operator premises with the UE context. The UE context may include PLMNNPN UE ID.

[0078] Step 13: AMF2 can decide to trigger master authentication between the UE and AMF2. AMF2 can send an identity request to the UE to request the UE's SUCI. Alternatively, AMF2 can use the PLMNNPN UE ID as input to request the UE's SUPI from the UDM.

[0079] Step 14: AMF2 can send a registration acceptance message to the UE carrying the newly assigned 5G-GUTI. The new 5G-GUTI points to AMF2 (i.e., the new AMF serving the UE).

[0080] Scenario 2: UE context transfer during N2 handover (not in Figure 7 (as shown in the image) In this scenario, AMF1 at the customer's premises is the source AMF, and AMF2 at the operator's premises is the target AMF.

[0081] Upon receiving the NGAPHANDOVER REQUIRED message, AMF1 can send a Namf_Communication_CreateUEContext request message to AMF2. AMF2, located in the operator's premises, can then decide to trigger master authentication between the UE and AMF2. AMF2 can send an identity request to the UE to request its SUCI. Alternatively, AMF2 can use the PLMNNPN UE ID as input to request the UE's SUPI from the UDM.

[0082] Example 2: UE authentication via AMF at the operator's premises when SPNF and UDM are co-located. In this embodiment, the network deployment includes two security domains. For example, one security domain is the customer premises and the other is the operator premises. The UE is located in the operator premises and can initiate service requests using the AMF2 deployed in the operator premises. UE authentication can be initiated from the AMF2. See below for reference. Figure 8 The exemplary steps of the UE registration / authentication process initiated by AMF2 are described in detail. The exemplary method may include some or all of the following steps.

[0083] Step 1: The UE sends a registration request message to AMF2. The registration request message may carry the UE's SUCI or 5G-GUTI. AMF2 may execute a local policy such that if the registration request message carries a 5G-GUTI and that 5G-GUTI points to an AMF that is not in the same premises (or security domain) as AMF2 (e.g., AMF2 is in the operator's premises, while the 5G-GUTI points to an AMF in the customer's premises), then AMF2 may initiate the UE's identity request procedure to obtain the UE's SUCI.

[0084] Step 2: AMF2 can initiate the UE authentication process. For example, AMF2 can invoke the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate request message, such as Nausf_UEAuthentication_Authenticate, to AUSF. The Nausf_UEAuthentication_Authenticate request message can carry the UE's SUCI or SUPI. The Nausf_UEAuthentication_Authenticate request message can also carry the UE's serving network (SN) name. The SN can be the network in which the UE initiated the registration request. In this case, the SN is the customer premises network. The Nausf_UEAuthentication_Authenticate request message can also carry a PLMNNPN service indication. In this scenario, the PLMNNPN service indication can be used to indicate that the service request originated from the customer premises and / or that the service request originated from a different security domain. A detailed description of the PLMNNPN service indication can be found in Example 1 and is omitted here for simplicity.

[0085] Step 3: Upon receiving the Nausf_UEAuthentication_Authenticate request message, AUSF sends a Nudm_UEAuthentication_Get request to the UDM. The Nudm_UEAuthentication_Get request may carry at least one of the following: the UE's SUCI; the UE's serving network name; and the PLMNNPN service indication (if any) carried in the Nausf_UEAuthentication_Authenticate request message in Step 2.

[0086] Step 4: After receiving the Nudm_UEAuthentication_Get request, if SUCI is received, UDM can call SIDF to remove SUCI before UDM can process the request, thereby obtaining SUPI.

[0087] In response, the UDM can, for example, respond to the AUSF with a Nudm_UEAuthentication_Get response message. The response message may carry an authentication vector (AV) created by the UDM (or ARPF).

[0088] The UDM can check the UE's subscription and generate a new PLMNNPN UE ID, which can be carried in the Nudm_Authenticate_Get response message. If a SUCI is received in step 3, the UDM can create a new PLMNNPN UE ID for the UE, which can also be carried in the Nudm_Authenticate_Get response message. Alternatively, if a PLMNNPN UE ID is received in step 3, there are two options based on the operator's policy. In the first option, the UDM can refresh / update the PLMNNPN UE ID, and the response message can carry the refreshed PLMNNPN UE ID. In the second option, it is not necessary to refresh the received PLMNNPN UE ID, and the PLMNNPN UE ID received in step 3 is carried in the response message.

[0089] Step 5: AUSF can send a Nausf_UEAuthentication_UEAuthentication response message carrying AV to AMF2.

[0090] Step 6: AMF2 can send an authentication request message to the UE, and the UE can use a message carrying the authentication challenge result (RES). The system responds to the authentication response message.

[0091] Step 7: AMF2 can send a message carrying RES to AUSF The Nausf_UEAuthentication_Authenticate request message.

[0092] Step 8: AUSF can indicate to AMF2 in the Nausf_UEAuthentication_Authenticate response message whether authentication was successful from the home network's perspective. If authentication is successful, the anchor key (K) will be included in the Nausf_UEAuthentication_Authenticate response message. SEAF Send to AMF2.

[0093] If AUSF receives the SUCI or PLMNNPN UE ID from AMF2 in the authentication request (in step 2) and authentication is successful, AUSF may also include the PLMNNPN UE in the Nausf_UEAuthentication_Authenticate response message (if received from UDM in step 4).

[0094] After receiving the Nausf_UEAuthentication_Authenticate response message, AMF2 can use the key derivation function (KDF) to extract the key from the K key. SEAF Derive its key K AMF Details regarding the key derivation process can be found in Example 1 and are omitted here.

[0095] Steps 9-11: AMF2 can register with UDM using messages such as Nudm_UECM_Registration to register for access. After AMF2 successfully completes the Nudm_UECM_Registration operation, and if AMF2 does not have UE subscription data, AMF2 can retrieve subscription data using Nudm_SDM_Get, such as access and mobility subscription data, SMF selection subscription data, UE context in SMF data, Location Service (LCS) mobility initiation, etc. UDM can send the newly generated PLMNNPN UEID in the Nudm_UECM_Registration response message or the Nudm_SDM_Get response message. Upon receiving a successful response, AMF2 can subscribe using Nudm_SDM_Subscribe to be notified when the requested data is modified. If a new PLMNNPN UE ID is generated, UDM can send a notification to AMF2. For example, the PLMNNPN UE ID can be configured with a lifecycle, and must be updated / refreshed once the lifecycle is reached.

[0096] Step 12: If authentication is successful, AMF2 can send a registration acceptance message to the UE. The registration acceptance message may include the 5G-GUTI pointing to the AMF2 in the operator's premises.

[0097] In some scenarios, AMF2 in the operator's premises needs to transfer the UE context to AMF1 in the customer's premises. For example, AMF2 can be the UE's old AMF, and AMF1 can be the UE's new AMF. There are two cases, described below.

[0098] Scenario 1: UE context transfer during mobile registration (e.g.) Figure 8 (As shown) Step 13: The UE can send a registration request message to AMF1 in the customer's premises. The registration request message can carry a 5G-GUTI pointing to AMF2 in the operator's premises (received by the UE in step 12).

[0099] Step 14: AMF1 in the customer's premises sends a Namf_Communication_UEContextTransfer message to AMF2 in the operator's premises.

[0100] Step 15: AMF2 in the operator's premises responds to AMF1 in the customer's premises with the UE context. The response message may include a Namf_Communication_UEContextTransfer response message. In the UE context transferred to AMF1, AMF2 may replace the UE's SUPI with the UE's PLMNNPN UE ID.

[0101] The AMF1 at the customer's premises can decide to trigger primary authentication. AMF1 can send an identity request to the UE to request the UE's SUCI. Alternatively, AMF2 can use the PLMNNPN UE ID as input to request the UE's SUPI from the UDM.

[0102] Step 16: AMF1 can send a registration acceptance message to the UE carrying the newly assigned 5G-GUTI. The new 5G-GUTI points to AMF1 (i.e., the new AMF serving the UE).

[0103] Scenario 2: UE context transfer during N2 handover (not in Figure 8 (as shown in the image) In this scenario, AMF2 at the operator's premises is the source AMF, and AMF1 at the customer's premises is the target AMF.

[0104] Upon receiving the NGAP handover request message, AMF2 can send a Namf_Communication_CreateUEContext request message to AMF1. In the UE context transferred to AMF1, AMF2 can replace the UE's SUPI with the UE's PLMNNPN UE ID.

[0105] The AMF1 at the customer's premises can decide to trigger master authentication between the UE and AMF1. AMF1 can send an identity request to the UE to request the UE's SUCI. Alternatively, AMF2 can use the PLMNNPN UE ID as input to request the UE's SUPI from the UDM.

[0106] In this disclosure, message type and / or message name (e.g., such as Figures 7-8 (As shown) are for illustrative purposes only. Different message types and / or message names may be selected in implementations, and should still be covered by this disclosure as long as the basic principles are the same, for example, if the messages are used for the same purpose.

[0107] In this disclosure, a single information element in a message can be divided into multiple information elements. Multiple information elements can also be combined into a single information element.

[0108] In this disclosure, the steps in each embodiment are for illustrative purposes only, and other alternatives may be derived as needed based on the disclosed embodiments. For example, only some steps may need to be performed. As another example, the order of the steps may be adjusted. For yet another example, several steps may be combined (e.g., several messages may be combined into one message). Furthermore, a single step may be split (e.g., one message may be sent via two sub-messages).

[0109] The embodiments described in this disclosure are for illustrative purposes only. Multiple embodiments may be combined to form new embodiments.

[0110] The accompanying drawings and description provide specific example embodiments and implementations. However, the described subject matter can be embodied in a variety of different forms, and therefore, the covered or claimed subject matter is intended to be construed as not being limited to any of the example embodiments set forth herein. A reasonably broad scope is intended for the claimed or covered subject matter. Furthermore, for example, the subject matter can be embodied as a method, apparatus, component, system, or non-transitory computer-readable medium for storing computer code. Therefore, embodiments can take the form of, for example, hardware, software, firmware, storage media, or any combination thereof. For example, the above-described method embodiments can be implemented by a component, apparatus, or system including a memory and a processor by executing computer code stored in the memory.

[0111] Throughout this specification and claims, the meanings of terms suggested or implied in the context may have subtle differences, in addition to their expressly stated meanings. Similarly, the phrase "in one embodiment / implementation" as used herein does not necessarily refer to the same embodiment, and the phrase "in another embodiment / implementation" as used herein does not necessarily refer to a different embodiment. For example, the subject matter intended to be claimed includes combinations of all or some of the exemplary embodiments.

[0112] Generally, terms can be understood at least in part by their use in context. For example, terms such as “and,” “or,” and “and / or” as used herein may include multiple meanings that may depend at least in part on the context in which such terms are used. Generally, if “or” is used with an associative list, such as A, B, or C, it is intended to mean A, B, and C, used herein in an inclusive sense, and A, B, or C, used herein in an exclusive sense. Furthermore, the term “one or more” as used herein depends at least in part on the context and can be used to describe any feature, structure, or characteristic in a singular sense, or a combination of features, structures, or characteristics in a plural sense. Similarly, terms such as “a,” “an,” or “described” depend at least in part on the context and can be understood to convey either a singular or a plural usage. Moreover, also depending at least in part on the context, the term “based on” can be understood to not necessarily convey an exclusive set of factors, but may allow for the presence of additional factors that are not necessarily explicitly described.

[0113] Throughout this specification, references to features, advantages, or similar language do not imply that all features and advantages implemented using this solution should be attributed to or included in any single implementation thereof. Rather, language relating to features and advantages is understood to mean that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of this solution. Therefore, throughout this specification, discussions of features and advantages, as well as similar language, may, but do not necessarily refer to the same embodiment.

[0114] Furthermore, the features, advantages, and characteristics described herein can be combined in any suitable manner in one or more embodiments. Those skilled in the art will recognize that, based on the description herein, this solution can be implemented without one or more specific features or advantages of a particular embodiment. In other instances, additional features and advantages that may not be present in all embodiments of this solution may be recognized in certain embodiments.

Claims

1. A method for wireless communication, performed by a first network element, comprising: A first message is received from a wireless device for a service request for a wireless network, the first message carrying at least one of the following: The wireless device's Subscribed Hidden Identifier (SUCI); or The first 5G globally unique temporary identifier (5G-GUTI) of the wireless device; and Send a second message for authentication request to the second network element, the second message carrying at least one of the following: The SN name of the service network (SN) serving the wireless device; The wireless device SUCI; The user equipment (UE) identifier of the wireless device associated with the subscription permanent identifier (SUPI) of the wireless device; A service indicator is used to indicate that the security domain of the service associated with the second message is different from the security domain of the second network element; or The identifier of the first network element.

2. The method as described in claim 1, wherein, The first network element includes an access and mobility management function (AMF), and the second network element includes an authentication server function (AUSF).

3. The method as described in claim 1, wherein, The UE identifier of the wireless device does not belong to any of the following: SUCI; SUPI; and 5G-GUTI.

4. The method of claim 1, wherein, The first network element is located in the first security domain, and the second network element is located in the second security domain, which is different from the first security domain.

5. The method of claim 1, wherein, The service indicator indicates that the service associated with the second message was initiated or triggered from the customer's premises.

6. The method of claim 1, wherein, The service indicator includes at least one of the following: The SN name of the SN serving the wireless device; The UE identifier of the wireless device; The identifier of the first network element; An indicator that the service associated with the second message was initiated or triggered from the customer's premises; or The name of the second message or the type of the second message.

7. The method of claim 1, wherein, The first message includes a Nausf_UEAuthentication_Authenticate request message, and the second message includes a Nausf_UEAuthentication_Authenticate response message.

8. The method according to any one of claims 1-7, further comprising: The third message, which carries an authentication vector (AV), is received from the second network element as a response to the second message.

9. The method of claim 8, further comprising: Send a fourth message to the second network element, the fourth message carrying the authentication challenge result from the wireless device; as well as Receive a fifth message from the second network element as a response to the fourth message, the fifth message including at least one of the following: Anchor key (KSEAF); The UE identifier of the wireless device; or The refreshed UE identifier of the wireless device.

10. The method of claim 9, wherein, The fourth message includes a Nausf_UEAuthentication_Authenticate request message, and the fifth message includes a Nausf_UEAuthentication_Authenticate response message.

11. The method of claim 9, further comprising: The AMF key KAMF is derived based on at least one of the following: the UE identifier of the radio device; the refreshed UE identifier of the radio device; Or the anchor key.

12. The method of claim 9, further comprising: A sixth message is sent to the wireless device as a response to the first message, the sixth message indicating acceptance of the service request from the wireless device, the sixth message including a second 5G-GUTI assigned to the wireless device, the second 5G-GUTI pointing to an AMF located in the same security domain as the second network element.

13. The method of claim 12, wherein, The sixth message includes a registration acceptance message.

14. The method of any one of claims 1-7, further comprising: In response to the fact that the AMF identified by the first 5G-GUTI and the first network element belong to different security domains, the wireless device triggers an identity request to obtain the SUCI of the wireless device.

15. The method of any one of claims 1-7, further comprising: A seventh message is received from a third network element, the seventh message requesting that the UE context of the wireless device be transferred from the first network element to the third network element; as well as An eighth message is sent to the third network element, the eighth message carrying the UE context of the radio device, wherein the SUPI of the radio device is replaced with the UE identifier of the radio device.

16. The method of claim 15, wherein: The third network element includes AMF; and The security domain of the third network element is different from the security domain of the first network element.

17. A method for wireless communication, performed by a first network element, comprising: A first message is received from a wireless device for a service request for a wireless network, the first message carrying at least one of the following: The Subscription Hidden Identifier (SUCI) of the wireless device; The first 5G globally unique temporary identifier (5G-GUTI) of the wireless device; and Send a second message for authentication request to the second network element, the second message carrying at least one of the following: The SN name of the service network (SN) serving the wireless device; The wireless device SUCI; The Subscription Permanent Identifier (SUPI) of the wireless device. The user equipment (UE) identifier of the wireless device associated with the subscription permanent identifier (SUPI) of the wireless device; A service indicator is used to indicate that the security domain of the service associated with the second message is different from the security domain of the first network element; or The identifier of the first network element.

18. The method of claim 17, wherein, The first network element includes an access and mobility management function (AMF), and the second network element includes an authentication server function (AUSF).

19. The method according to any one of claims 17-18, wherein, The wireless device is located in a first security domain, and the first network element and the second network element are located in a second security domain, which is different from the first security domain.

20. The method of claim 19, wherein, The service indicator indicates that the service associated with the second message was initiated from the customer's location.

21. The method of claim 20, wherein, The service indicator includes at least one of the following: The SN name of the SN serving the wireless device; The identifier of the first network element; or An indicator used to indicate whether the service associated with the second message was initiated or triggered from the customer's premises; or The name of the second message or the type of the second message.

22. The method of claim 17, wherein, The first message includes a registration request message, and the second message includes a Nausf_UEAuthentication_Authenticate request message.

23. The method of any one of claims 17-22, further comprising: The third message, which carries an authentication vector (AV), is received from the second network element as a response to the second message.

24. The method of claim 23, wherein, The third message includes the Nausf_UEAuthentication_Authenticate response message.

25. The method of claim 24, further comprising: Send a fourth message to the second network element, the fourth message carrying the authentication challenge result from the wireless device; as well as Receive a fifth message from the second network element as a response to the fourth message, the fifth message including at least one of the following: Anchor key (KSEAF); or The user equipment (UE) identifier of the wireless device associated with the SUPI of the wireless device.

26. The method of claim 25, wherein, The UE identifier of the wireless device does not belong to any of the following: SUCI; SUPI; and 5G-GUTI.

27. The method of claim 25, wherein, The fourth message includes a Nausf_UEAuthentication_Authenticate request message, and the fifth message includes a Nausf_UEAuthentication_Authenticate response message.

28. The method of any one of claims 25-27, further comprising: Send a sixth message to a third network element to register the wireless device with the third network element or to retrieve the subscription data of the wireless device from the third network element; as well as The third network element receives a seventh message in response to the sixth message, the seventh message carrying an updated UE identifier of the radio device.

29. The method of claim 28, wherein, The sixth message includes at least one of the following: a Nudm_UECM_Registration message; or a Nudm_SDM_Get message.

30. The method of any one of claims 25-27, further comprising: The eighth message is received from the fourth network element, and the eighth message requests that the UE context of the wireless device be transferred from the first network element to the fourth network element. as well as A ninth message is sent to the fourth network element, the ninth message carrying the UE context of the radio device, wherein the SUPI of the radio device is replaced with the UE identifier of the radio device.

31. The method of claim 30, wherein: The fourth network element includes AMF; and The security domain of the fourth network element is different from the security domain of the first network element.

32. A method for wireless communication, performed by a first network element, comprising: The first message is received from the second network element. The first message is used for an authentication request initiated by the wireless device. The first message carries at least one of the following: The SN name of the service network (SN) serving the wireless device; The wireless device SUCI; The user equipment (UE) identifier of the wireless device associated with the subscription permanent identifier (SUPI) of the wireless device; The identifier of the second network element; or A service indicator is used to indicate that the security domain of the service associated with the first message is different from the security domain of the first network element; and The instruction is used to indicate that the first security domain that initiates the authentication request of the wireless device is different from the second security domain to which the first network element belongs; as well as A second message is sent to a third network element for an authentication request for the wireless device, the second message carrying at least one of the following: The SN name of the SN serving the wireless device; The wireless device SUCI; The UE identifier of the radio device associated with the SUPI; The identifier of the second network element; or The instruction is used to indicate that the first security domain that initiates the authentication request of the wireless device is different from the second security domain to which the first network element belongs.

33. The method of claim 32, wherein: The first network element includes an authentication server function (AUSF). The second network element includes Access and Mobility Management Function (AMF); and The third network element includes Unified Data Management (UDM).

34. The method of claim 33, wherein, The UDM is able to derive the SUPI of the wireless device from the UE identifier of the wireless device.

35. The method of claim 32, wherein, The first network element is located in the first security domain, and the second network element is located in the second security domain, which is different from the first security domain.

36. The method of claim 32, wherein, The first network element and the second network element are in the same security domain.

37. The method of claim 32, wherein, The UE identifier of the wireless device does not belong to any of the following: SUCI; SUPI; and 5G-GUTI.

38. The method of claim 32, wherein, The first security domain includes the customer's premises, and the second security domain includes the operator's premises.

39. The method of claim 32, wherein, The service indicator indicates that the service associated with the first message was initiated or triggered from the customer's premises.

40. The method of claim 32, wherein, The service indicator includes at least one of the following: The SN name of the SN serving the wireless device; The UE identifier of the wireless device; The identifier of the second network element; or An indicator used to indicate whether the service associated with the first message was initiated or triggered from the customer's premises; or The name of the first message or the type of the first message.

41. The method of claim 32, wherein, The first message includes a Nausf_UEAuthentication_Authenticate request message, and the second message includes a Nudm_UEAuthentication_Get response message.

42. The method of any one of claims 32 to 39, further comprising receiving from the third network element a third message as a response to the second message, the third message carrying at least one of the following: Authentication Vector (AV); The SUCI-based UE identifier of the wireless device, wherein the SUCI-based UE identifier is derived based on the SUCI of the wireless device; The UE identifier of the wireless device; or The refreshed UE identifier of the wireless device, wherein the refreshed UE identifier is a refreshed version of the UE identifier of the wireless device.

43. The method of claim 42, wherein, The third message includes the Nudm_Authenticate_Get response message.

44. The method of claim 42, further comprising: A fourth message, which is a response to the first message, is sent to the second network element, and the fourth message includes the AV.

45. The method of claim 44, further comprising: The fifth message is received from the second network element, the fifth message carrying the authentication challenge result generated by the wireless device; as well as Send a sixth message to the second network element as a response to the fifth message, the sixth message including at least one of the following: The anchor key (KSEAF) used to generate the AMF key KAMF of the second network element; or The refreshed UE identifier of the wireless device.

46. ​​The method of claim 45, wherein, The fifth message includes a Nausf_UEAuthentication_Authenticate request message, and the sixth message includes a Nausf_UEAuthentication_Authenticate response message.

47. A method for wireless communication, performed by a first network element, comprising: The first message is received from the second network element. The first message is used for wireless device authentication and carries at least one of the following: The Subscription Hidden Identifier (SUCI) of the wireless device; The user equipment (UE) identifier of the wireless device associated with the subscription permanent identifier (SUPI) of the wireless device; or The SN name of the service network (SN) serving the wireless device; and Send a second message to the second network element as a response to the first message, the second message carrying at least one of the following: The wireless device SUPI; The UE identifier of the wireless device; or The updated UE identifier of the wireless device.

48. The method of claim 47, wherein, The wireless device is located in a first security domain, and the first network element and the second network element are located in a second security domain that is different from the first security domain.

49. The method of claim 47, wherein, The first message includes a Nudm_Authenticate_Get message, and the second message includes a Nudm_Authenticate_Get response message.

50. The method according to any one of claims 47-49, wherein, The first message indicates the attributes of a first security domain, the attributes of which include at least one of the following: The first security domain is located at the customer's premises; The name of the first security domain; or The type of the first security domain.

51. The method of claim 50, wherein, The second message indicates the attribute of the first security domain by at least one of the following: The SN name of the SN serving the wireless device; An indicator that the service request associated with the second message was initiated or triggered from the first security domain; or The name of the second message or the type of the second message.

52. The method according to any one of claims 47-51, wherein, The first message carries the SUCI of the wireless device, and the method further includes: The SUPI of the wireless device is obtained based on the SUCI; and The UE identifier of the wireless device is generated based on the SUPI.

53. The method of claim 52, wherein, The UE identifier for generating the wireless device includes: Encrypt the SUPI to obtain the UE identifier of the wireless device; or Map the SUPI to the UE identifier of the wireless device.

54. The method according to any one of claims 47-51, wherein, The first message carries the UE identifier of the wireless device, and the method further includes updating the UE identifier of the wireless device to obtain an updated UE identifier of the wireless device.

55. An apparatus or network element comprising a memory for storing computer instructions and a processor in communication with the memory, wherein the processor is configured to perform the method as described in any one of claims 1-54 when executing the computer instructions.

56. A computer program product comprising a non-transitory computer-readable program medium having computer code stored thereon, which, when executed by one or more processors, causes the one or more processors to perform the method as described in any one of claims 1-54.