Pure authentication and key management for applications (AKMA) based two-factor authentication
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
- Filing Date
- 2023-06-20
- Publication Date
- 2026-04-29
AI Technical Summary
Current two-factor authentication methods, such as SMS-based one-time passwords, lack security and privacy, being vulnerable to attacks and not providing adequate protection for users.
The implementation of Authentication and Key Management for Applications (AKMA) based two-factor authentication, which generates a root key and session key for user equipment, performing multiple authentication steps with an operator two-factor authentication service to verify user identity and session integrity, ensuring secure access to services without revealing the accessed application to the operator.
Enhances security and privacy by providing a robust two-factor authentication mechanism that is resistant to attacks, ensuring secure access to services while maintaining user privacy and reducing the need for trust relationships between service providers and operators.
Smart Images

Figure IB2023056378_26122024_PF_FP_ABST
Abstract
Description
PURE AUTHENTICATION AND KEY MANAGEMENT FOR APPLICATIONS (AKMA) BASED TWO-FACTOR AUTHENTICATIONTechnical Field
[0001] The present disclosure relates to methods, apparatuses, and systems for two- factor authentication.Background
[0002] User authentication is typically done with a username and a password. To enhance security, a 2ndfactor authentication (2FA) is often used. One way of doing 2FA is via a short message service (SMS) based one-time codes, i.e. SMS-based one-time passwords (OTPs). With the addition of an SMS OTP, the user is showing she possesses the mobile phone / subscription receiving the SMS OTP (a 2ndfactor) in addition to knowledge of the username and password. SMS OTP is widely used, affordable, carries the benefits of SMS being a globally available technology that people are used to using. New techniques are needed for 2FA that provide better security and privacy to the user.Summary
[0003] Disclosed are methods, apparatuses, systems, and computer readable media for two-factor authentication. In one aspect, a method performed at a user equipment (UE), for two-factor authentication at an application function (AF) is disclosed. The method includes generating a root key for the UE and a root key identifier corresponding to the root key. The method further includes performing a first authentication of the UE for a service provided by the AF, where the performing the first authentication includes: obtaining a session ID (SID); generating a first authentication response based on an authentication challenge received from the AF; and transmitting the first authentication response to the AF over a first session. The method further includes performing a second authentication of the UE for the service provided by the AF, where the performing the second authentication includes: generating a session key based on the root key; generating a second authentication response based on the session key; transmitting the root key identifier and the second authentication response to an operator two-factor authentication service (2FAS); transmitting the SID to the 2FAS; receiving, from the operator 2FAS, an attestation including an attested SID and an attested user identifier; verifying the SID obtained in the first authentication matches theattested SID in the attestation; and transmitting, to the AF over the first session, the attestation including the SID and the user identifier. Advantages of the disclosed subject matter include providing 2FA with better security and privacy compared to short message service (SMS) based one-time codes, i.e. SMS based one-time passwords (OTPs). For example, the disclosed subject matter provides for hiding the AF used by the UE from the operator as well has providing improved 2FA for the UE and the AF.
[0004] In some embodiments, the performing the second authentication further includes verifying a user identifier matches the attested user identifier in the attestation. In some embodiments, the generating the first authentication response includes operating on the received authentication challenge using credentials of the UE to generate the first authentication response.
[0005] In some embodiments, the user identifier includes a phone number, Mobile Station Integrated Services Digital Network (MSISDN), a personal identification number (PIN), a location, other user information in possession of a Mobile Network Operator (MNO) including an age of a subscriber, an address of the subscriber, biometric information, or other subscriber information.
[0006] In some embodiments, the method further includes operating in accordance with a first authentication result of the first authentication and a second authentication result of the second authentication. In some embodiments, the first authentication result is a successful first authentication and the second authentication result is a successful second authentication, and wherein the operating includes accessing the service provided by the AF. In some embodiments, the first authentication result or the second authentication result is unsuccessful, and wherein the operating includes receiving a denial of access to the service provided by the AF.
[0007] In some embodiments, the root key is an Authentication and Key Management for Applications (AKMA) root key (K AKMA), the root key identifier is an AKMA key identifier (A-KID), the SID is a session identifier for a secure session of the first authentication, and the session key is an AKMA session key (K 2FAS).
[0008] In some embodiments, the root key is a General Bootstrapping Architecture (GBA) key (Ks), the root key identifier is a Bootstrap Transaction Identifier (BTID), the SID is a session identifier for a secure session of the first authentication, and the session key is a Network Application Function (NAF) session key (Ks_NAF). In some embodiments, the SID and the user identifier are signed by the MNO.
[0009] In another aspect, a UE apparatus for two-factor authentication at an AF isdisclosed. The UE apparatus includes receiver circuitry and processing circuitry associated with the receiver circuitry. The processing circuitry is configured to cause the UE to at least: generate a root key for the UE and a root key identifier corresponding to the root key; perform a first authentication of the UE for a service provided by the AF. The performing the first authentication includes: obtaining a SID; generating a first authentication response based on an authentication challenge received from the AF; and transmitting the first authentication response to the AF over a first session. The processing circuitry is further configured to perform a second authentication of the UE for the service provided by the AF. The performing the second authentication includes: generating a session key based on the root key; generating a second authentication response based on the session key; transmitting the root key identifier and the second authentication response to a 2FAS; transmitting the SID to the 2FAS; receiving, from the 2FAS, an attestation including an attested SID and optionally an attested user identifier; and verifying the SID obtained in the first authentication matches the attested SID in the attestation and optionally that optionally a user identifier matches an attested user identifier in the attestation; and transmitting, after the verifying, to the AF over the first session, the attestation including the SID and the user identifier.
[0010] In another aspect, a method for providing two-factor authentication of a UE, for a service provided by an AF is disclosed. The method includes performing a second authentication of the UE at the AF after a first authentication of the UE for the service provided by the AF. The performing the second authentication includes at a first network node: performing a cellular authentication of the UE and generating a root key for the UE and a root key identifier associated with the root key for the UE. The performing the second authentication includes at a third network node: receiving, from the UE, the root key identifier and a second authentication response based on a session key; authenticating the UE based on the session key; receiving a SID, from the UE related to the first authentication; and transmitting to the UE an attestation including an attested SID and an attested user identifier.
[0011] In some embodiments, the method further includes at the first network node: transmitting to a second network node the root key, the root key identifier, and an identifier of the UE. The method further includes at the second network node: receiving, from the first network node, the root key, the root key identifier, and the identifier of the UE. The method further includes at the third network node: sending the root key identifier to the second network node. The method further includes at the secondnetwork node: receiving the root key identifier from the third network node; generating the session key based on the root key associated to the root key identifier; and sending the session key to the third network node.
[0012] In some embodiments, the first network node is a Bootstrapping Server Function (BSF) of a GBA. In some embodiments, the method further includes performing, by the BSF, a bootstrapping of the UE. In some embodiments, the method further includes at the third network node sending the root key identifier to the first network node. In some embodiments, the method further includes at the first network node: receiving the root key identifier from the third network node; generating the session key based on the root key associated with the root key identifier; and sending the session key to the third network node.
[0013] In some embodiments, the identifier of the UE is a Subscription Permanent Identifier (SUPI). In some embodiments the method further includes transmitting, from the first network node to the third network node, the identifier.
[0014] In some embodiments, the user identifier includes a phone number, a MSISDN, a PIN, a location, other user information in possession of a MNO, including an age of a subscriber, an address of the subscriber, biometric information, or other subscriber information.
[0015] In some embodiments, the second network node is an AKMA anchor function (AAnF). In some embodiments, the first network node is a 3GPP network node. In some embodiments, the third network node is an operator AKMA Two-Factor Authentication Service (2FAS). In some embodiments, the first network node is a BSF of a GBA. In some embodiments, the method further includes performing the second authentication of the UE at the BSF.
[0016] In some embodiments, a first result of the first authentication is a successful first authentication and a second result of the second authentication result is a successful second authentication resulting in allowing the UE to access the service provided bv the AF. In some embodiments, a first result of the first authentication result or a second result of the second authentication is unsuccessful resulting in denying the UE access to the service provided by the AF.
[0017] In some embodiments, the SID and the user identifier are signed by an MNO. In some embodiments, the service provided by the AF is identified by a Fully Qualified Domain Name (FQDN).
[0018] In some embodiments, the root key is an AKMA root key (K AKMA),the root key identifier is an AKMA key identifier (A-KID), the SID is a session identifier for a secure session of the first authentication, and the session key is an AKMA session key (K 2FAS).
[0019] In some embodiments, the root key is a GBA master key (Ks), the root key identifier is a BTID, the SID is a session identifier for a secure session of the first authentication, and the session key is a NAF session key (Ks_NAF).
[0020] In another aspect, a method performed at an AF for performing two-factor authentication of a UE at the AF is disclosed. The method includes performing a first authentication of the UE for a service at the AF. The performing the first authentication includes: receiving, from the UE, a first authentication response over a first session; and obtaining a SID. The method further includes performing a second authentication of the UE for the service at the AF. The performing the second authentication includes: receiving, from the UE, an attestation including the SID and a user identifier; and verifying an identity of the user by comparing the attestation including the SID and a user identifier to stored user identity information associated with the SID. The method further includes operating in accordance with a first authentication result of the first authentication and a second authentication result of the second authentication.
[0021] In some embodiments, the receiving the first authentication response includes: transmitting an authentication challenge to the UE; and receiving, a first authentication response in response to the authentication challenge. In some embodiments, the method further includes receiving, at an operator authentication service, the user identifier from a 3GPP network node.
[0022] In some embodiments, the first authentication result is a successful first authentication and the second authentication result is a successful second authentication, and wherein the operating includes accessing the service at the AF. In some embodiments, the first authentication result and / or the second authentication result is unsuccessful, and wherein the operating includes receiving a denial of access to the service at the AF.
[0023] In some embodiments, the SID is a session identifier for a secure session of the first authentication. In some embodiments, the user identifier includes: a phone number, a MSISDN, a PIN, a location, other user information in possession of an MNO, including an age of a subscriber, an address of the subscriber, biometric information, or other subscriber information.
[0024] In another aspect, a network node apparatus for implementing an AFconfigured for two-factor authentication of a UE is disclosed. The apparatus includes receiver circuitry and processing circuitry associated with the receiver circuitry. The processing circuitry is configured to cause the network node apparatus to at least: perform a first authentication of the UE for a service at the AF. The performing the first authentication includes receiving, from the UE, a first authentication response over a first session; and obtaining a SID, based on the received first authentication response. The processing circuitry is further configured to cause the network node apparatus to perform a second authentication of the UE for the service at the AF. The performing the second authentication includes: receiving, from the UE, an attestation including the SID and a user identifier; verifying an identity of the user by comparing the attestation including the SID and the user identifier to stored user identity information associated with the SID; and operating in accordance with a first authentication result of the first authentication and a second authentication result of the second authentication.Brief Description of the Drawings
[0025] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.
[0026] Figure 1 shows an example of a signaling diagram for two-factor authentication, according to some example embodiments;
[0027] Figure 2 shows an example of a signaling diagram for authentication and key management for applications (AKMA) based two-factor authentication, according to some example embodiments;
[0028] Figure 3 shows one example of a cellular communications system, according to some example embodiments;
[0029] Figure 4 shows a schematic block diagram of a network node, according to some example embodiments;
[0030] Figure 5 shows a schematic block diagram that illustrates a virtualized embodiment of the network node of Figure 4, according to some example embodiments;
[0031] Figure 6 shows a schematic block diagram of the network node of Figure 4, according to some other example embodiments;
[0032] Figure 7 shows a schematic block diagram of a User Equipment device (UE), according to some example embodiments; and
[0033] Figure 8 shows a schematic block diagram of the UE of Figure 7, according tosome other example embodiments.Detailed Description
[0034] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.
[0035] Radio Node: As used herein, a “radio node” is either a radio access node or a communication device.
[0036] Radio Access Node: As used herein, a “radio access node” or “radio network node” or “radio access network node” is any node in a Radio Access Network (RAN) of a cellular communications network that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., a New Radio (NR) base station (gNB) in a Third Generation Partnership Project (3GPP) Fifth Generation (5G) NR network or an enhanced or evolved Node B (eNB) in a 3GPP Long Term Evolution (LTE) network), a high-power or macro base station, a low-power base station (e.g., a micro base station, a pico base station, a home eNB, or the like), a relay node, a network node that implements part of the functionality of a base station or a network node that implements a gNB Distributed Unit (gNB-DU)) or a network node that implements part of the functionality of some other type of radio access node.
[0037] Core Network Node: As used herein, a “core network node” is any type of node in a core network or any node that implements a core network function. Some examples of a core network node include, e.g., a Mobility Management Entity (MME), a Packet Data Network Gateway (P-GW), a Service Capability Exposure Function (SCEF), a Home Subscriber Server (HSS), or the like. Some other examples of a core network node include a node implementing an Access and Mobility Function (AMF), a User Plane Function (UPF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a Network Function (NF) Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), or the like.
[0038] Communication Device: As used herein a communication device can be a wireless communication device or a wired communication device. Both are communication devices for transmitting and / or receiving signals such as the signals carrying information as described in this patent document. A wireless communication device may be any type of wireless device that has access to (i.e. , is served by) a wireless network (e.g., a cellular network). Some examples of a wireless communication device include but are not limited to: a User Equipment device (UE) in a 3GPP network, a Machine Type Communication (MTC) device, and an Internet of Things (loT) device. Such wireless communication devices may be, or may be integrated into, a mobile phone, smart phone, sensor device, meter, vehicle, household appliance, medical appliance, media player, camera, or any type of consumer electronic, for instance, but not limited to, a television, radio, lighting arrangement, tablet computer, laptop, or PC. The wireless communication device may be a portable, handheld, computer-comprised, or vehicle-mounted mobile device, enabled to communicate voice and / or data via a wireless connection. A wired communication device may be similar to the wireless communication device described above except that the signals carrying information are passed over one or more wires, fiber optic cables, or otherwise directly connecting a transmitter to a receiver or connecting one transceiver to another over a cable or wire instead of being communicated via propagating electromagnetic waves as is the case for wireless communication devices.
[0039] Network Node: As used herein, a “network node” is any node that is either part of the RAN or the core network of a cellular communications network / system. "Network node" is also used to refer to nodes that may be external to the cellular communications network / system. Disclosed examples of network nodes include a key anchor function (e.g., an Authentication and Key management for Applications (AKMA) Anchor Function (AAnF)), and a Bootstrapping Server Function (BSF), an Operator Two- factor Authentication (2FA) Service (2FAS), and an Application Function (AF).
[0040] Note that the description given herein focuses on a 3GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.
[0041] Fast Identity Online 2 (FIDO2) is an emerging solution where username / password credentials are replaced with asymmetric keys; one key pair per service, where a private key is stored and operated on a FIDO authenticator in a userdevice or as a separate FIDO authenticator device. This is typically a hardware-based solution for securely storing and operating on data. In some examples, access to the key in the authenticator can be controlled by requiring the user to provide biometric verification before the key can be used, thus resulting in 2FA based on a first factor being the key on the authenticator and a second factor being biometric information of the user.
[0042] Authentication and Key management for Applications (AKMA) is a Third Generation Partnership Project (3GPP) solution developed for the 3GPP Fifth Generation (5G). AKMA is similar to the General Bootstrapping Architecture (GBA). In both solutions, the subscription credentials are used for generating session credentials for an application. In AKMA, the User Equipment (UE) and 5G core network derive an AKMA root key (K AKMA) and an identifier (A-KID) for the AKMA root key as part of the Authentication and Key Agreement (AKA) run during cellular authentication. K AKMA is derived from an Authentication Server Function (AUSF) key, K AUSF. K AKMA, A-KID and the Subscription Permanent Identifier (SUPI) of the subscription are provided to the AKMA Anchor Function (AAnF), which is the AKMA network function in the 5G core. When the UE wants to use AKMA for generating credentials for a service at an Application Function (AF), it derives an AKMA-based session key, K_AF from K AKMA. K_AF is bound to the specific service / application function. The UE can then use the credentials, where the A-KID is similar to a username and the K_AF is similar to password, to authenticate to the specific service / AF. The AF queries the (trusted) AAnF for the corresponding K_AF by providing the A-KID to the AAnF. The AAnF, after authenticating and verifying the identity of the AF, generates the corresponding AF specific key K_AF and provides it to the AF. The AF can now use the key K_AF to authenticate the UE. GBA works similarly, with the exception that the root key is a GBA root key (K BSF) which is derived with a dedicated authentication run between the UE and the Bootstrapping Server Function (BSF) in the GBA. The UE can then derive Network Application Function (NAF) session key (Ks_NAF) from the root key and authenticate to the service at the NAF using the NAF session key (Ks_NAF) and the root key identifier (Bootstrap key Identifier (B-TID) in GBA). The NAF can query the BSF for the corresponding NAF session key.
[0043] A secure and authenticated connection should be used in AKMA when the AF fetches the AKMA session key, K-AF, from the AAnF, and in GBA when the NAF fetches the NAF session key, Ks_NAF from the BSF. In some embodiments, the AKMAsession key that the AF fetches from the AAnF can be the AKMA session key, K 2FAS. In practice, having a secure and authenticated connection means that the AF and NAF need to have an existing trust relationship with the home operator of the UE. For a service serving customers globally, this would mean that the service would need to have a trust relationship with more or less all operators, which is not feasible. However, a Zn- proxy can be used allowing the AF / NAF to interact with operators via roaming agreements. For example, if a NAF has a trust relationship with operator A but not with operator B, but operators A and B have a roaming agreement, then the NAF can fetch NAF specific keys for subscribers of operator B, via operator A and the Zn-proxy utilizing the roaming agreement. This reduces the need for trust relationships between NAFs and operators and makes the solution scalable.
[0044] While AKMA / GBA can operate silently, where the user is unaware that authentication is being done and key material is being generated, the 3GPP has been discussing that the GBA / AKMA client in the UE might require user consent before doing GBA / AKMA operations. This could be implemented by before the GBA / AKMA client generates a NAF / AF specific session key by requesting user input such as biometric data (e.g., fingerprint), pin code, or just clicking an OK button agreeing to the use of GBA / AKMA. This would prevent a malicious application in the UE fetching GBA / AKMA credentials at will without the user being aware of it. Furthermore, since the GBA / AKMA client in the UE gets the request for generating keys from an application in the UE, it can identify the application and also indicate the application in the user consent request discussed above. This means that the user would be able to identify if an unexpected (possibly malicious) application wants consent to use GBA / AKMA.
[0045] There are ways of attacking SMS OTP so that an attacker gets the OTP and can use it to take over the account of the victim, e.g., via social engineering attacks, SMS hijacking via SS7, phishing, SIM swap etc. Also, the ease of use of SMS OTP is not ideal as the user needs to get the OTP from the SMS and transfer it to the application requiring 2FA. Further, SMS does not provide security and the content is sent in clear text so any system in the message transmission path can read it including the operators and possibly 3PP SMS Firewall (FW) vendors used by the operators.
[0046] FIDO2 is something that is fully uncoupled from 3GPP. If it replaces SMS OTP operators are losing part of their relevance in the area.
[0047] When using AKMA / GBA, the mobile operator is made aware of the service the UE is accessing, since the operator generates the session key based on the serviceidentity / Fully Qualified Domain Name (FQDN), which could be a privacy concern.
[0048] AKMA or GBA can be used to perform 2FA without revealing the service to the operator. The 2ndpart of the 2FA is based on information registered at the service, such as a user identifier, i.e. available at the application function (AF of NAF), and available to the operator, so that the operator can assert the information. The Mobile Station Integrated Services Digital Network phone number (MSISDN) can be used as a user identifier or other information may be used as well as detailed below.
[0049] Disclosed is a 2FAS in the operator network. For example, the user can be registered with the AF service with first authentication information such as a username, password, and MSISDN for 2FA. As detailed below, different or additional first authentication information can be used to register the user with the service at the AF.
[0050] A first authentication is performed at the AF using the first authentication information provided by the UE. To do 2FA, the UE requests an AKMA session key (K 2FAS) for the operator AKMA 2FA service (2FAS). The UE does AKMA-based authentication towards the 2FAS which acts as an AKMA AF and based on the received A-KID requests the AKMA session key from the AAnF in the operator network. Once 2FAS receives K 2FAS, it can authenticate the UE.
[0051] The UE then provides a Session Identifier (SID) for the session over which the UE has been authenticated to the AF. This could be the Transport Security Layer (TLS) client and / or server random values from the TLS Hello messages or a hash of the unencrypted “Finished” message which would be a SID that an attacker would not be able to learn from looking at the TLS handshake. The 2FAS obtains the user identifier (e.g. MSISDN) associated with the subscription of the UE from the operator network through existing AKMA information exchange or a new interface. The 2FAS signs the user identifier (e.g., MSISDN) and UE provided SID using a certificate of the operator. The 2FAS does not learn which AF the SID belongs to. The signed data is provided back to the UE, which forwards it to the AF. The AF can now verify that the received data is fresh and associated to the UE based on the SID being included. It can further find the user identifier (e.g., MSISDN) of the UE from the information provided by the UE and verify it matches the user identifier (e.g., MSISDN) stored for the authenticated user for 2FA, and can verify that the data has been signed by a trusted operator.
[0052] In this way, the AF has confirmation from a trusted operator of information about the subscription used by the user / UE at the AF, the information has been authenticated by the signature used to sign the information, and the user identifier (e.g.MSISDN) in the information is the same user identifier (e.g. MSISDN) as that registered at the AF as a 2FA control parameter. At the same time, the operator does not know which service / AF the user / subscription is accessing. By binding the user identifier (e.g., MSISDN) to the SID it also makes the combined information usable only for the session associated with the SID. If either the UE or AF notices that the included SID does not match the currently active session it can discard the information.
[0053] An example of 2FAS in accordance with the disclosed subject matter includes:(a) Using AKMA for 2FA to in a way that avoids UE OS (Android, iPhone) impacts;(b) Binding first factor authentication (username / password) session to subscription using AKMA; and(c) Keeping operator out of loop of which AF the UE is accessing.
[0054] Disclosed is AKMA based 2FA towards a service, where the second factor is the verification of the user identifier (e.g., MSISDN) of the subscription of the UE. Although the description below verifies the phone number, other information about the subscription / subscriber can be verified as an alternative to the phone number, or in addition to the phone number. The user identifier can include one or more of: the MSISDN, biometric information, facial recognition, a fingerprint scan, an iris scan, a location, other user information in possession of a Mobile Network Operator, MNO, including an age of a subscriber, an address of the subscriber or other subscriber information. For example, a service having an age restriction, could get verification of the owner of subscriber’s age via the solution. The operator knows many things about the subscriber / subscription and any piece of information it has could potentially be provided via the presented solution in a verifiable way to the service. Below, the MSISDN is used as the user identifier, but as noted above, the user identifier can be or include other information.
[0055] Figure 1 shows an example of a signaling diagram for two-factor authentication, in accordance with some example embodiments. Figure 1 as optional features, aspects that differ between AKMA and GBA.
[0056] At 112, in the case of AKMA, the UE 110 attaches to the 3GPP network node 130 (or a Network Function (NF) in the 3GPP core network node 130 of a 3GPP network) and performs a cellular authentication with the 3GPP network node 130. In the case of GBA, instead of 112, the UE 110 performs a GBA bootstrapping andauthentication with the BSF (3GPP network node 130). The details of the cellular authentication are well-known to those of skill in the art and as such are not repeated here. However, in general, cellular authentication includes registering the UE 110 with the 3GPP network node 130 to establish basic cellular service.
[0057] At 114, the UE 110 obtains a root key (e.g., K AKMA in the case of AKMA; GBA master key, Ks, in the case of GBA) and a root key identifier (e.g., A-KID in the case of AKMA; B-TID in the case of GBA).
[0058] At 132, the 3GPP network node 130 also generates a root key (e.g., K AKMA in the case of AKMA; GBA master key, Ks, in the case of GBA) and a root key identifier (e.g., A-KID for AKMA; B-TID for GBA). In the case of GBA, the root key identifier, B- TID, is sent from the BSF (3GPP network node 130) to the UE 110. The root key and the root key identifier generated by the 3GPP network node 130 match those generated by the UE 110 at 114.
[0059] At 134, for an AKMA solution, the A-KID and K AKMA are provided to the key anchor function 120 from the 3GPP network node 130. For AKMA, the key anchor function is referred to as the AKMA Anchor Function (AAnF).
[0060] At 116, the application 115 in the UE 110 accesses the AF 160, and the user associated to the UE 110 is authenticated with first authentication information (e.g., a username and a password, a Personal Identification Number (PIN) code, an asymmetric key pair, a one-time password (OTP), biometric information, facial recognition, fingerprint scan, or iris scan, or a combination of the foregoing). As part of the first authentication a session is established between the UE and the AF, e.g. TLS. The session has a session identifier (SID) such as a TLS session ID, or TLS finished message which can be sent in encrypted format and can be used to uniquely identify the session. As used herein, SID can include any type of session identifier such as a TLS 1 .2 session ID, a TLS 1 .3 session ticket / session identifier, or other session identifier.Although not shown in Figures 1 and 2, 2FAS 140 can alternatively be an AKMA AF or a GBA NAF.
[0061] At 117, if the application is configured for 2FA or the AF requests 2FA from the UE as part of the first authentication, it obtains a session key including K 2FAS for AKMA or Ks_NAF for GBA. Note that if the UE 110 is not already registered with the 3GPP network node 130 (112 above), the UE 110 is triggered to perform 112, 132, and 134. The application obtains the session key (AKMA: K 2FAS; GBA: KS_NAF) by requesting session key, which is derived (e.g., by the AKMA or GBA client in the UE110) from the root key (e.g., K AKMA in the case of AKMA; Ks in the case of GBA). In one embodiment, the 2FAS 140 is a pre-configured service in the client for which any application requiring 2FA can request a service specific key.
[0062] At 118, the UE 110 authenticates to 2FAS 140 using the root key identifier (A- KID in the case of AKMA or B-TID in the case of GBA) and the session key (K 2FAS in the case of AKMA and Ks_NAF in the case of GBA).
[0063] At 142, for AKMA, the 2FAS 140 requests the session key K_2FAS from the key anchor function 120 (e.g., AAnF) based on root key identifier, A-KID.
[0064] At 142A for GBA, the 2FAS 140 requests the session key Ks_NAF from the 3GPP network node 130 (e.g., BSF) based on the root key identifier (e.g., B-TID).
[0065] At 122, for AKMA, the AAnF derives a session key (e.g., K 2FAS) from the root key (e.g., K AKMA) associated to the received A-KID.
[0066] At 122A, for GBA, the 3GPP network node 130 (e.g., 5G CN node) derives the session key from the root key Ks associated with the received B-TID.
[0067] At 124, for AKMA, the AAnF provides the session key (e.g., K 2FAS) to the 2FAS 140. Optionally, the AAnF 120 provides a user identifier (e.g., MSISDN) from the subscription associated to the A KID to the 2FAS 140. The user identifier can include one or more of: the MSISDN, biometric information, facial recognition, a fingerprint scan, an iris scan, a location, other user information in possession of a Mobile Network Operator, MNO, including an age of a subscriber, an address of the subscriber or other subscriber information.
[0068] At 124A, for GBA, the 3GPP network node 130 provides the session key Ks_NAF to the 2FAS 140. In some embodiments, BSF 120 can provide the user identifier to the 2FAS 140 (not shown in Figure 1 ).
[0069] At 144, the 2FAS 140 authenticates the UE 110 based on the received session key.
[0070] At 113, the UE 110 provides the SID from to the 2FAS 140.
[0071] At 136, if the 2FAS 140 did not get the user identifier (e.g., MSISDN) from the AAnF, it can obtain the user identifier (e.g., MSISDN) from the 3GPP network node 130 over an existing interface or a new interface. The user identifier (e.g., MSISDN) is optionally signed with an operator certificate, either by the 2FAS 140 or by an entity providing the user identifier (e.g., MSISDN) to the 2FAS 140.
[0072] At 146, the 2FAS 140 generates and sends to the UE an attestation indicating that the received SID belongs to the user identifier (e.g., MSISDN). For example, theattestation could be generated by the 2FAS signing the SID and user identifier (e.g., MSISDN) using a Mobile Network Operator (MNO) certificate. That the combination of the SID and the user identifier is signed by the MNO proves that the signed identifier is for the session identified by the SID.
[0073] At 111 , the UE verifies that the information in the received attestation (SID and user identifier) is correct which includes: the attested SID matches the SID the UE 110 sent in 116, and that the information is signed by a trusted MNO. Optionally, verification that the attested user identifier (e.g. MSISDN) matches the user identifier (e.g., MSISDN) at the UE 110 of the user can be performed. A trusted MNO is one that the UE 110 has information confirming that the MNO is trustworthy.
[0074] At 119, the UE 110 provides the attestation including the attested SID and optionally the attested user identifier (e.g. MSISDN) signed by the MNO to the AF 160.
[0075] At 168, the AF 160 verifies the information in the attestation (similar to the verification performed by the UE at 111). The AF 160 verifies that the SID matches the SID of the session with the UE 110 sent in 116, and the user identifier (e.g. MSISDN) matches the MSISDN registered for the user at the AF 160, and that the information is signed by a trusted MNO. If the AF 160 is not able to verify trustworthiness of an MNO (i.e. the AF 160 does not know the operator from before), the AF 160 can use an external service to get a second opinion of the MNO's certificate, without revealing the data signed by it.
[0076] At 169, the AF 160 service is operated in accordance with the first authentication and the second authentication. In other words, if both the first authentication and the second authentication are successful (i.e., 2FA is successful), then the AF 160 provides the requested service to the UE 110. Otherwise, the AF 160 performs some action(s) related to failure of 2FA such as, e.g., notifying the UE 110 of the failure and denying access to the service.
[0077] Figure 2 shows an example of a signaling diagram for authentication and key management for applications (AKMA) based two-factor authentication, in accordance with some example embodiments.
[0078] At 202, the UE 110 attaches to the network and performs cellular authentication at the 3GPP network node 130.
[0079] At 204, the UE 110 and 3GPP network node 130 each generate A-KID and K AKMA.
[0080] At 206, the A-KID and K AKMA are provided to the AAnF 120.
[0081] At 208, the Application in the UE 110 accesses the AF 160 and the user is authenticated in a first authentication with a username and password, or other first authentication information as describe above. As part of the first authentication, a session (e.g. TLS) is established between the UE 110 and the AF 160. The session has an identifier such as a TLS session ID, or TLS finished message, which is sent in encrypted format and uniquely identifies the session.
[0082] At 210, if the application is configured for 2FA, or the AF 160 requests 2FA from the UE 110 (e.g. as part of username / password authentication process), it obtains an AKMA-based session key for the 2FAS 140. If the UE 110 is not registered with a 3GPP network node 130, the UE 110 is triggered to perform 202, 204, and 206. The application requests a session key (K 2FAS) for the 2FAS service, which the AKMA client in the UE 110 derives from K AKMA. In some embodiment, 2FAS 140 is preconfigured for 2FA service in the UE 110, i.e. when an application needs 2FA, it requests a 2FAS key.
[0083] At 212, the UE 110 authenticates to 2FAS 140 using the AKMA credentials including A-KID and K 2FAS.
[0084] At 214, 2FAS 140 requests the K 2FAS key from AAnF 120 based on A-KID.
[0085] At 216, the AAnF 120 derives K_2FAS from K AKMA.
[0086] At 218, AAnF 120 provides K 2FAS to 2FAS 140. Optionally, the AAnF 120 provides the user identifier (e.g., MSISDN) of the service subscription to 2FAS 140.
[0087] At 220, 2FAS 140 authenticates UE 110 based on the received K 2FAS.
[0088] At 222, UE 110 provides the SID from 208 to 2FAS 140.
[0089] At 224, if 2FAS 140 did not get user identifier (e.g., MSISDN) from AAnF 120, it obtains the user identifier (e.g., MSISDN) from 3GPP network node 130 over an existing or a new interface.
[0090] At 226, 2FAS 140 generates and sends to UE 110 an attestation indicating that the received SID belongs to the user identifier (e.g., MSISDN). This could be by the 2FAS 140 signing the SID and MSISDN using an operator certificate.
[0091] At 228, the UE 110 verifies that the received information is correct; that the attested SID matches SID it sent in 222, and optionally that the attested user identifier (e.g., MSISDN) matches its own MSISDN, and that the information is signed by the trusted MNO.
[0092] At 230, the UE 110 provides the attestation including the attested SID and attested user identifier (e.g., MSISDN) signed by the MNO to the AF 160.
[0093] At 232, the AF 160 verifies the information in the attestation (similar to the verification performed by the UE at 230). The AF 160 verifies that the attested SID matches the SID of the session with the UE 110 sent in 222, and optionally that the attested user identifier (e.g., MSISDN) matches the user identifier (e.g., MSISDN) registered for the user at the AF 160, and that the information is signed by a trusted MNO. If the AF 160 is not able to verify trustworthiness of an MNO (i.e. the AF 160 does not know the operator from before), the AF 160 can use an external service to get a second opinion of the MNO's certificate, without revealing the data signed by it.
[0094] At 169, the AF 160 service is operated in accordance with the first authentication and the second authentication. In other words, if both the first authentication and the second authentication are successful (i.e., 2FA is successful), then the AF 160 provides the requested service to the UE 110. Otherwise, the AF 160 performs some action(s) related to failure of 2FA such as, e.g., notifying the UE 110 of the failure and denying access to the service.
[0095] Advantages of the disclosed subject matter include providing 3GPP based 2FA with better security and privacy compared to short message service (SMS) based onetime codes, i.e. SMS based one-time passwords (OTPs). In some embodiments, the service needs to be able to trust the operator of the UE.
[0096] If the AF can verify that the attested information was bound to the session of the user (authentication with username / password) via the SID, contains the same MSISDN as is registered for the user in the AF, and that the attested information was generated by a trusted operator (e.g., MNO), the AF 160 has a 2ndfactor of authentication for the UE / user. In this way, the MNO does not have information indicating which AF the user / UE is accessing.
[0097] To further add security to the solution, the 2FAS can be configured to only provide one attestation for one set of session credentials (identified by A-KID / B-TID), i.e. if A-KID / B-TID has been recorded at the 2FAS as being already used, then the 2FAS will not provide attestation if requested with the same A-KID / B-TID. This will prevent an attacker from trying to via a malicious application to capture and re-use GBA / AKMA credentials for interacting with the 2FAS on behalf of the attacker. The 2FAS service is operated by the MNO which also issues the B-TID / A-KID, so it knows how long the validity time is for GBA / AKMA credentials. Thus, the 2FAS can store A-KID / B-TIDs and keep them stored for the maximum lifetime of GBA / AKMA credentials after which it is safe to delete them as the BSF / AAnF will no longer be able to provide credentials basedon them. If an attempt is made to re-use an A-KID / B-TID, 2FAS can signal an error to the UE, indicating that A-KID / B-TID is being re-used.
[0098] By applying single-use, requiring user consent for generating GBA / AKMA credentials, and by indicating the requesting application in the consent request, it would be difficult for an attacker to be able to abuse valid GBA / AKMA credentials; the attacker would have to request them at the same time as the user is requesting them, have the request come from an application whose identity matches the application ID of the application the user is actively using, and use the GBA / AKMA credentials towards 2FAS before the user’s application has had time to do that. And still, if the attacker somehow could manage that, the user would be alerted that the credentials have already been used, so the attacker’s actions would not go undetected.
[0099] The foregoing description has the 2FAS 140 providing attestation of the user identifier (e.g., MSISDN) of the subscription. The solution could be extended to verifying additional attributes of the subscription or subscriber. Example use cases include an AF 160having age restriction for its users, location restrictions of the user, etc.
[0100] The AF 160 can indicate to the UE110 what it needs to know about the UE / user before it provides access. This indication can be part of the user authentication (e.g., Figure 1 at 116 and Figure 2 at 208), or the AF 160 can signal this after successful authentication based on the first authentication information (e.g., username and password). In some embodiments, the user can be made aware of what the AF160 is requesting (e.g. pop-up) and make a decision whether the user wants to proceed (and reveal that information via the attested information from 2FAS), or abort accessing the service, or try to access it without the information and possibly end up with erroneous or limited service from AF 160.
[0101] When the UE 110 sends the SID to the 2FAS 140 (Figure 1 at 116 and Figure 2 at 222), the UE 110 can further indicate what attributes are requested by the 2FAS 140 for attestation in case user does not want to provide all the information that the AF 160 requests. Alternatively, the MNO has multiple GBA / AKMA enabled services, one for 2FA which provides Mobile Subscription Identification Number (MSIN) information in attestation, but it could have also a service for location attestation, age attestation, etc. Then, the UE 110 would request attestation from the service providing the requested type of attestation. If 2FAS 140 (or whatever attestation service the UE is using) has not obtained the necessary information in Figure 1 at 124 / 124A or Figure 2 at 218, the 2FAS 140 requests the information from the CN at Figure 1 at 134 or Figure 2 at 224.When 2FAS 140 generates the attestation, it includes the information in the attested data that was requested by the UE 110. The UE 110 and AF160 can verify the additional information in a similar way to how the user identifier (e.g., MSISDN) is verified and described above.
[0102] In GBA, the network maintains a GBA User Security Settings (GUSS) record for the subscription. The GUSS includes information about the subscriber / subscription, and it can be provided to the GBA enabled service the UE authenticates to using GBA. This information could be directly utilized as received by the 2FAS 140 at Figure 1 at 124 / 124A or Figure 2 at 218 for GBA and possibly AKMA. Some information might not be available through GUSS and in such case the 2FAS would have to request it specifically at Figure 1 at 134 of Figure 2 at 224. Instead of requesting very specific information such as age or date of birth the AF 160 could request verification that user is over 18 years old. Based on date of birth information available to the operator, the 2FAS could deduce the users age and provide an attestation that the user is over 18, without revealing the actual date of birth.
[0103] Figure 3 illustrates one example of a cellular communications system 300 in which embodiments of the present disclosure may be implemented. Some or all of the features detailed with respect to Figures 1 and 2 can be implemented in the core network 310, communications devices 312-1 to 312-5, and / or base stations 302-1 and / or 302-2.
[0104] In the embodiments described herein, the cellular communications system 300 is a 5G system (5GS) including a Next Generation RAN (NG-RAN) and a 5G Core (5GC). In this example, the RAN includes base stations 302-1 and 302-2, which in the 5GS include NR base stations (gNBs) and optionally next generation eNBs (ng-eNBs) (e.g., LTE RAN nodes connected to the 5GC), controlling corresponding (macro) cells 304-1 and 304-2. The base stations 302-1 and 302-2 are generally referred to herein collectively as base stations 302 and individually as base station 302. Base stations 302 can communicate wirelessly to wireless communications devices 312, can communicate via a wired interface to wired communications devices 312, or to a mixture of wireless and wired communication devices 312. To assist clarity, base stations 302 and communication devices 312 described below are wireless devices although they could be wired devices as well. Likewise, the (macro) cells 304-1 and 304-2 are generally referred to herein collectively as (macro) cells 304 and individually as (macro) cell 304. The RAN may also include a number of low power nodes 306-1 through 306-4controlling corresponding small cells 308-1 through 308-4. The low power nodes 306-1 through 306-4 can be small base stations (such as pico or femto base stations) or RRHs, or the like. Notably, while not illustrated, one or more of the small cells 308-1 through 308-4 may alternatively be provided by the base stations 302. The low power nodes 306-1 through 306-4 are generally referred to herein collectively as low power nodes 306 and individually as low power node 306. Likewise, the small cells 308-1 through 308-4 are generally referred to herein collectively as small cells 308 and individually as small cell 308. The cellular communications system 300 also includes a core network 310, which in the 5G System (5GS) is referred to as the 5GC. The base stations 302 (and optionally the low power nodes 306) are connected to the core network 310.
[0105] The base stations 302 and the low power nodes 306 provide service to communication devices 312-1 through 312-5 in the corresponding cells 304 and 308. The communication devices 312-1 through 312-5 are generally referred to herein collectively as communication devices 312 and individually as communication device 312. Communication devices 312 can be wireless communication devices or wired communication devices, or a mixture of wireless and wired communication devices. In the following description, the wireless communication devices 312 are oftentimes UEs, but the present disclosure is not limited thereto.
[0106] Figure 4 is a schematic block diagram of a network node 400 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. For example, the network node 400 may be a network node that implements the functionality of the 3GPP network 130 described above with respect to Figure 1 or Figure 2, a network node that implements the functionality of the key anchor function 120 described above with respect to Figure 1 and the AAnF 120 described with respect to Figure 2, a network node that implements the functionality of the 2FAS 140 in Figures 1 and 2, or a network node that implements the functionality of the AF 160 described above with respect to Figures 1 and 2.
[0107] As illustrated, the network node 400 includes a control system 402 that includes one or more processors 404 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory 406, and a network interface 408. The one or more processors 404 are also referred to herein as processing circuitry. In addition, if the network node 400 is a radio access node, the network node 400 may include one ormore radio units 410 that each includes one or more transmitters 412 and one or more receivers 414 coupled to one or more antennas 416. In the case that network node communicated with wired communication devices, one or more antennas are replaced with wired interfaces. The radio units 410 may be referred to or be part of radio interface circuitry. In some embodiments, the radio unit(s) 410 is external to the control system 402 and connected to the control system 402 via, e.g., a wired connection (e.g., an optical cable). However, in some other embodiments, the radio unit(s) 410 and potentially the antenna(s) 416 are integrated together with the control system 402. The one or more processors 404 operate to provide one or more functions of the network node 400 as described herein (e.g., one or more functions of the 3GPP network 130, one or more functions of the key anchor function 120 or AAnF 120, one or more functions of the 2FAS 140, or one or more functions of the AF 160 as described herein). In some embodiments, the function(s) are implemented in software that is stored, e.g., in the memory 406 and executed by the one or more processors 404.
[0108] Figure 5 is a schematic block diagram that illustrates a virtualized embodiment of the network node 400 according to some embodiments of the present disclosure. Again, optional features are represented by dashed boxes.
[0109] As used herein, a “virtualized” network node is an implementation of the network node 400 in which at least a portion of the functionality of the network node 400 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). As illustrated, in this example, if the network node 400 is a radio access node, the network node 400 may include the control system 402 and / or the one or more radio units 410, as described above. The control system 402 may be connected to the radio unit(s) 410 via, for example, an optical cable or the like. The network node 400 includes one or more processing nodes 500 coupled to or included as part of a network(s) 502. If present, the control system 402 or the radio unit(s) are connected to the processing node(s) 500 via the network 502. Each processing node 500 includes one or more processors 504 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 506, and a network interface 508.
[0110] In this example, functions 510 of the network node 400 described herein (e.g., one or more functions of the 3GPP network 130, one or more functions of the key anchor function 120 or AAnF 120, one or more functions of the 2FAS 140, or one or more functions of the AF 160 as described herein) are implemented at the one or more processing nodes 500 or distributed across the one or more processing nodes 500 andthe control system 402 and / or the radio unit(s) 410 in any desired manner. In some particular embodiments, some or all of the functions 510 of the network node 400 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environment(s) hosted by the processing node(s) 500. As will be appreciated by one of ordinary skill in the art, additional signaling or communication between the processing node(s) 500 and the control system 402 may be used in order to carry out at least some of the desired functions 510. Notably, in some embodiments, the control system 402 may not be included, in which case the radio unit(s) 410 communicates directly with the processing node(s) 500 via an appropriate network interface(s).
[0111] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the network node 400 or a node (e.g., a processing node 500) implementing one or more of the functions 510 of the network node 400 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).
[0112] Figure 6 is a schematic block diagram of the network node 400 according to some other embodiments of the present disclosure. The network node 400 includes one or more modules 600, each of which is implemented in software. The module(s) 600 provide the functionality of the network node 400 described herein (e.g., one or more functions of the 3GPP network 130, one or more functions of the key anchor function 120 or AAnF 120, one or more functions of the 2FAS 140, or one or more functions of the AF 160 as described herein). This discussion is equally applicable to the processing node 500 of Figure 5 where the modules 600 may be implemented at one of the processing nodes 500 or distributed across multiple processing nodes 500 and / or distributed across the processing node(s) 500 and the control system 402.
[0113] Figure 7 is a schematic block diagram of a communication device 700 according to some embodiments of the present disclosure. Some or all of the features detailed with respect to Figures 1 and 2 can be implemented in wireless communications device 700, particularly with respect to UE 110.
[0114] As illustrated, the communication device 700 includes one or moreprocessors 702 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 704, and one or more transceivers 706 each including one or more transmitters 708 and one or more receivers 710. In the case of a wireless communication device 700, the one or more transmitters 708 and one or more receivers 710 are coupled to one or more antennas 712. In this case, the transceiver(s) 706 includes radio-front end circuitry connected to the antenna(s) 712 that is configured to condition signals communicated between the antenna(s) 712 and the processor(s) 702, as will be appreciated by one of ordinary skill in the art. In the case of a wired communication device 700, the antennas can be replaced by a wired or optical interface. The processors 702 are also referred to herein as processing circuitry. The transceivers 706 are also referred to herein as radio circuitry. In some embodiments, the functionality of the communication device 700 described above may be fully or partially implemented in software that is, e.g., stored in the memory 704 and executed by the processor(s) 702. Note that the communication device 700 may include additional components not illustrated in Figure 7 such as, e.g., one or more user interface components (e.g., an input / output interface including a display, buttons, a touch screen, a microphone, a speaker(s), and / or the like and / or any other components for allowing input of information into the communication device 700 and / or allowing output of information from the communication device 700), a power supply (e.g., a battery and associated power circuitry), etc.
[0115] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the communication device 700 according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).
[0116] Figure 8 is a schematic block diagram of the communication device 700 according to some other embodiments of the present disclosure. The communication device 700 includes one or more modules 800, each of which is implemented in software. The module(s) 800 provides the functionality of the communication device 700 described herein.
[0117] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of thesefunctional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.
[0118] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).
[0119] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.
Claims
Claims1 . A method performed at a User Equipment, UE (110), for two-factor authentication at an Application Function, AF (160), the method comprising:• generating (114) a root key for the UE and a root key identifier corresponding to the root key;• performing a first authentication of the UE for a service provided by the AF, wherein the performing the first authentication comprises: o obtaining (116) a Session ID, SID; o generating (116) a first authentication response based on an authentication challenge received from the AF; and o transmitting (116) the first authentication response to the AF over a first session; and• performing a second authentication of the UE for the service provided by the AF, wherein the performing the second authentication comprises: o generating (117) a session key based on the root key; o generating (117) a second authentication response based on the session key; o transmitting (118) the root key identifier and the second authentication response to an operator two-factor authentication service, 2FAS; o transmitting (113) the SID to the 2FAS; o receiving (146), from the operator 2FAS, an attestation comprising an attested SID and an attested user identifier; o verifying (122) the SID obtained in the first authentication matches the attested SI Din the attestation; and o transmitting (119), to the AF over the first session, the attestation comprising the SID and the user identifier.
2. The method of claim 1 , wherein the performing the second authentication further comprises: verifying (122) a user identifier matches the attested user identifier in the attestation.
3. The method of claim 1 , wherein the generating the first authentication response comprises:operating on the received authentication challenge using credentials of the UE to generate the first authentication response.
4. The method of claim 1 , wherein the user identifier comprises: a phone number, Mobile Station Integrated Services Digital Network, MSISDN, a Personal Identification Number, PIN, a location, other user information in possession of a Mobile Network Operator, MNO, including an age of a subscriber, an address of the subscriber, biometric information, or other subscriber information.
5. The method of claim 1 , further comprising: operating (169) in accordance with a first authentication result of the first authentication and a second authentication result of the second authentication.
6. The method of claim 5, wherein the first authentication result is a successful first authentication and the second authentication result is a successful second authentication, and wherein the operating comprises accessing the service provided by the AF.
7. The method of claim 5, wherein the first authentication result or the second authentication result is unsuccessful, and wherein the operating comprises receiving a denial of access to the service provided by the AF.
8. The method of any of claims 1 to 7, wherein: the root key is an Authentication and Key Management for Applications, AKMA, root key, K AKMA, the root key identifier is an AKMA key identifier, A-KID, the SID is a session identifier for a secure session of the first authentication, and the session key is an AKMA session key, K 2FAS.
9. The method of any of claims 1 to 7, wherein: the root key is a General Bootstrapping Architecture, GBA, key, Ks, the root key identifier is a Bootstrap Transaction Identifier, BTID, the SID is a session identifier for a secure session of the first authentication, and the session key is a Network Application Function, NAF, session key, Ks_NAF.
10. The method of claim 9, wherein the SID and the user identifier are signed by the Mobile Network Operator, MNO.
11. A User Equipment, UE (110), adapted to perform the method of any of claims 1 to 10.
12. A User Equipment, UE (110), apparatus configured for two-factor authentication at an Application Function, AF (160), the UE apparatus comprising: receiver circuitry; and processing circuitry associated with the receiver circuitry, the processing circuitry configured to cause the UE to at least: o generate (114) a root key for the UE and a root key identifier corresponding to the root key; o perform a first authentication of the UE for a service provided by the AF, wherein the performing the first authentication comprises: o obtaining (116) a Session ID, SID; o generating (116) a first authentication response based on an authentication challenge received from the AF; and o transmitting (116) the first authentication response to the AF over a first session; and o perform a second authentication of the UE for the service provided by the AF, wherein the performing the second authentication comprises: o generating (117) a session key based on the root key; o generating (117) a second authentication response based on the session key; o transmitting (118) the root key identifier and the second authentication response to an operator two-factor authentication service, 2FAS; o transmitting (116) the SID to the 2FAS; o receiving (146), from the 2FAS, an attestation comprising an attested SID and an attested user identifier; ando verifying (122) the SID obtained in the first authentication matches the attested SID and a user identifier matches an attested user identifier in the attestation; and o transmitting (119), after the verifying (122), to the AF over the first session, the attestation comprising the SID and the user identifier.
13. A non-transitory computer readable medium having code stored thereon, the code, when executed by a processor, causing the processor to perform the method recited in any of claims 1 to 10.
14. A method for providing two-factor authentication of a User Equipment, UE (110), for a service provided by an Application Function, AF (160), the method comprising:• performing a second authentication of the UE (110) at the AF (160), after a first authentication of the UE (110) for the service provided by the AF (160), wherein the performing the second authentication comprises: o at a first network node:■ performing a cellular authentication (112) of the UE (110); and■ generating (132) a root key for the UE (110) and a root key identifier associated with the root key for the UE (110); and o at a third network node:■ receiving (118), from the UE (110), the root key identifier and a second authentication response based on a session key;■ authenticating (144) the UE (110) based on the session key;■ receiving (113) a Session ID, SID, from the UE (110) related to the first authentication; and■ transmitting (146) to the UE (110) an attestation comprising an attested SID and an attested user identifier.
15. (AKMA specific) The method of claim 14, further comprising: o at the first network node (130):■ transmitting (134), to a second network node (120), the root key, the root key identifier, and an identifier of the UE (110); o at the second network node (120):■ receiving (134), from the first network node (130), the root key, the root key identifier, and the identifier of the UE (110); o at the third network node (140):■ sending (142) the root key identifier to the second network node (120); and o at the second network node (120):■ receiving (142) the root key identifier from the third network node (140);■ generating (122) the session key based on the root key associated to the root key identifier; and■ sending (124) the session key to the third network node (140).
16. The method of claim 14, wherein the first network node is a Bootstrapping Server Function, BSF, of a General Bootstrapping Architecture, GBA.
17. The method of claim 16, further comprising: performing, by the BSF, a bootstrapping of the UE.
18. (GBA) The method of claim 17, further comprising: o at the third network node (140):■ sending (142) the root key identifier to the first network node (130); and o at the first network node (130):■ receiving (142A) the root key identifier from the third network node (140);■ generating (122A) the session key based on the root key associated with the root key identifier; and■ sending (124A) the session key to the third network node (140).
19. The method of claim 14, wherein the identifier of the UE is a Subscription Permanent Identifier, SUPL20. The method of claim 14, further comprising:transmitting (136), from the first network node to the third network node, the user identifier.21 . The method of any of claims 14 to 20, wherein the user identifier comprises: a phone number, Mobile Station Integrated Services Digital Network, MSISDN, a Personal Identification Number, PIN, a location, other user information in possession of a Mobile Network Operator, MNO, including an age of a subscriber, an address of the subscriber, biometric information, or other subscriber information.
22. The method of claim 14, wherein the second network node is an Authentication and Key Management for Applications, AKMA, anchor function, AAnF.
23. The method of claim 14, wherein the first network node is a 3GPP network node.
24. The method of claim 14, wherein the third network node is an operator Key Management for Applications, AKMA, Two-Factor Authentication Service, 2FAS.
25. The method of claim 14, wherein the first network node is a Bootstrapping Server Function, BSF, of a General Bootstrapping Architecture, GBA.
26. The method of claim 25, further comprising: performing the second authentication of the UE at the BSF.
27. The method of claim 14, wherein a first result of the first authentication is a successful first authentication and a second result of the second authentication result is a successful second authentication resulting in allowing the UE to access the service provided bv the AF.
28. The method of claim 14, wherein a first result of the first authentication result or a second result of the second authentication is unsuccessful resulting in denying the UE access to the service provided by the AF.
29. The method of claim 14, wherein the SID and the user identifier are signed by a Mobile Network Operator, MNO.
30. The method of claim 14, wherein the service provided by the AF (160) is identified by a Fully Qualified Domain Name, FQDN.31 . The method of any of claims 14 to 30, wherein: the root key is an AKMA root key, K AKMA, the root key identifier is an AKMA key identifier, A-KID, the SID is a session identifier for a secure session of the first authentication, and the session key is an AKMA session key, K 2FAS.
32. The method of any of claims 13 to 29, wherein: the root key is a GBA key, Ks, the root key identifier is a Bootstrap Transaction Identifier, BTID, the SID is a session identifier for a secure session of the first authentication, and the session key is a Network Application Function, NAF, session key, Ks_NAF.
33. A method performed at an Application Function, AF, for performing two-factor authentication of a User Equipment, UE, at the AF, the method comprising:• performing a first authentication of the UE for a service at the AF, wherein performing the first authentication comprises: o receiving (116), from the UE, a first authentication response over a first session; and o obtaining (116) a session ID, SID;• performing a second authentication of the UE for the service at the AF, wherein performing the second authentication comprises: o receiving (119), from the UE, an attestation comprising the SID and a user identifier; and o verifying (168) an identity of the user by comparing the attestation comprising the SID and a user identifier to stored user identity information associated with the SID; and• operating (169) in accordance with a first authentication result of the first authentication and a second authentication result of the second authentication.
34. The method of claim 33, wherein the receiving the first authentication response comprises: transmitting an authentication challenge to the UE; and receiving, a first authentication response in response to the authentication challenge.
35. The method of claim 33, further comprising: receiving, at an operator authentication service, the user identifier from a 3GPP network node.
36. The method of claim 33, wherein the first authentication result is a successful first authentication and the second authentication result is a successful second authentication, and wherein the operating comprises accessing the service at the AF.
37. The method of claim 33, wherein the first authentication result and / or the second authentication result is unsuccessful, and wherein the operating comprises receiving a denial of access to the service at the AF.
38. The method of any of claims 33 to 37, wherein the SID is a session identifier for a secure session of the first authentication.
39. The method of any of claims 33 to 38, wherein the user identifier comprises: a phone number, Mobile Station Integrated Services Digital Network, MSISDN, a Personal Identification Number, PIN, a location, other user information in possession of a Mobile Network Operator, MNO, including an age of a subscriber, an address of the subscriber, biometric information, or other subscriber information.
40. A network node apparatus for implementing an Application Function, AF (160), adapted to perform the method of any of claims 32 to 39.41 . A network node apparatus for implementing an Application Function, AF (160), configured for two-factor authentication of a User Equipment, UE (110), the network node apparatus comprising: receiver circuitry; andprocessing circuitry associated with the receiver circuitry, the processing circuitry configured to cause the network node apparatus to at least: o perform a first authentication of the UE for a service at the AF, wherein performing the first authentication comprises:■ receiving (116), from the UE, a first authentication response over a first session; and■ obtaining (116) a session ID, SID, based on the received first authentication response; o perform a second authentication of the UE for the service at the AF, wherein performing the second authentication comprises:■ receiving (119), from the UE, an attestation comprising the SID and a user identifier;■ verifying (168) an identity of the user by comparing the attestation comprising the SID and the user identifier to stored user identity information associated with the SID; and o operate (169) in accordance with a first authentication result of the first authentication and a second authentication result of the second authentication.
42. A non-transitory computer readable medium having code stored thereon, the code, when executed by a processor, causing the processor to perform the method recited in any of claims 32 to 39.