User equipment, core network element and non-terrestrial network including a plurality of satellites for store and forward authentication of the user

The NTN system with multiple satellites effectively manages authentication processes through wait times and status checks, ensuring secure and reliable authentication in non-continuous coverage scenarios.

GB2641366APending Publication Date: 2025-12-03THALES DIS AIS DEUT GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
GB2024007520
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-28
Publication Date
2025-12-03

AI Technical Summary

Technical Problem

Authentication of user equipment (UE) in non-terrestrial networks (NTN) with non-continuous coverage poses challenges due to the need for reliable security measures, which existing store and forward authentication processes may not adequately address.

Method used

A non-terrestrial network (NTN) system utilizing a plurality of satellites to manage store and forward authentication, where each satellite handles authentication requests and responses, including wait times, status checks, and data forwarding via feeder links, ensuring secure and reliable authentication even in non-continuous coverage scenarios.

Benefits of technology

The system ensures secure and reliable authentication of UE by managing authentication processes across multiple satellites, maintaining network security and efficiency even in areas with intermittent connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A non-terrestrial network (NTN) for store and forward authentication of a user equipment 110 (UE) to a network 90, which may include a plurality of satellites 121, 122, wherein a first satellite of th
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to the field of store and forward authentication of a user equipment to a network, and more particularly, to store and forward authentication of a user equipment by a non-terrestrial network including a plurality of satellites. BACKGROUND OF THE INVENTION

[0002] Authentication of a user equipment (UE) to a network is fundamental to the security of the network. If the authentication is performed by a network with non-continuous coverage, e.g. by a non-terrestrial network (NTN), store and forward authentication process is usually used. The store and forward authentication process usually includes temporarily storing an authentication request at an intermediate node on a satellite of the NTN before forwarding the authentication request to authentication servers located on the ground within the core network infrastructure. The store and forward authentication process may ensure that the authentication process proceeds reliably even in scenarios of non-continuous network coverage, thereby ensuring the security of the network. SUMMARY OF THE INVENTION

[0003] Embodiments of the present invention may provide a non-terrestrial network (NTN) for store and forward authentication of a user equipment (UE) to a network, which may include: one or more feeder links; and a plurality of satellites; wherein a first satellite of the plurality of satellites is configured to: receive, from the UE, an authentication request as part of an authentication process initiated by the UE, the authentication request including an authentication transaction code (ATAC), the ATAC including an identifier indicative of an identity of the UE and an identifier of the authentication process; calculate a wait time for the UE to wait since the initiation of the authentication process before initiating a new authentication process; transmit, to the UE, a notification indicating the wait time; and forward, via one of the one or more feeder links, the authentication request to a core network element of a core network; and wherein each satellite of the plurality of satellites is configured to receive, from the core network element via one of the one or more feeder links, an authentication response, the authentication response including the AT AC, and one of an authentication vector if the UE is authorized to access the network or an authentication rejection if the UE is not authorized to access the network.

[0004] In some embodiments, the wait time is smaller than a time in which the first satellite reappears and becomes visible to the UE.

[0005] In some embodiments, a second satellite of the plurality of satellites is configured to: receive, from the UE, an authentication status request, the authentication status request including the ATAC; and based on the ATAC, determine whether or not the authentication response for the authentication process of the UE has been received.

[0006] In some embodiments, upon determination that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network, the second satellite is configured to complete the authentication process of the UE using the authentication vector included in the authentication response.

[0007] In some embodiments, upon determination that at least one identifier included in the ATAC of the authentication status request is not identical to the corresponding at least one identifier included in the ATAC of the authentication response, the second satellite is configured to: reject the authentication process; and transmit, to the UE, a notification that the authentication process is rejected.

[0008] In some embodiments, the second satellite is configured to transmit, to the core network element, via one of the one or more feeder links, a notification that the authentication process of the UE has been successfully completed, the notification including the ATAC.

[0009] In some embodiments, each of the plurality of satellites is configured to receive, from the core network element, via one of the one or more feeder links, the notification that the authentication process of the UE has been successfully completed.

[0010] In some embodiments, upon determination that the authentication response for the authentication process of the UE has been received but the UE is not authorized to access the network, the second satellite is configured to transmit, to the UE, the authentication rejection.

[0011] In some embodiments, upon determination that no authentication response for the authentication process of the UE has been received, the second satellite is configured to transmit, to the UE, a notification that the status the authentication request of the UE is unknown.

[0012] In some embodiments, the next satellite of the plurality of satellites that reaches the UE is configured to: receive, from the UE, the authentication status request; based on the AT AC included in the authentication status request, verify that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network; and upon verification, complete the authentication process of the UE using the authentication vector included in the authentication response.

[0013] In some embodiments, a second satellite of the plurality of satellites is configured to: receive, from the UE, an attach request, the attach request including the ATAC; and based on the AT AC included in the attach request, determine whether or not a notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites has been received.

[0014] In some embodiments, upon determination that the notification has been received, the second satellite is configured to: approve the attach request; and transmit, to the UE, a notification that the attach request is approved.

[0015] In some embodiments, upon determination that the notification has not been received, the second satellite is configured to: reject the attach request; and transmit, to the UE, a notification that the attach request is rejected.

[0016] In some embodiments, the second satellite is configured to: receive, from the UE, the attach request, the notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites, and user data; store the user data; and forward the user data and the ATAC to one of the one or more feeder links.

[0017] In some embodiments, the second satellite is configured to: receive, from the UE, the attach request and the notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites; based on the ATAC included in the attach request, determine whether or not the authentication response for the authentication process of the UE has been received; and upon determination that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network, complete the authentication process of the UE using the authentication vector included in the authentication response.

[0018] In some embodiments, each of the satellites of the plurality of satellites includes: a base station of the NTN; a core network authentication module; and an authentication repository including: a list of ongoing authentication processes of UEs; and a list of successfully completed authentication processes of UEs.

[0019] Embodiments of the present invention may provide a user equipment (UE) for store and forward authentication to a network by a non-terrestrial network (NTN) including a plurality of satellites, wherein the UE is configured to: initiate an authentication process by transmitting, to a first satellite of the plurality of satellites of the NTN, an authentication request, the authentication request including an authentication transaction code (ATAC), the ATAC including an identifier indicative of an identity of the UE and an identifier of the authentication process; receive, from the first satellite, a notification indicating a wait time for the UE to wait since the initiation of the authentication process with the first satellite before initiating a new authentication process; monitor a time that has elapsed since the initiation of the authentication process with the first satellite; and initiate a new authentication process only if the authentication process is unsuccessful or the time that has elapsed since the initiation of the authentication process with the first satellite exceeds the wait time.

[0020] In some embodiments, the UE is configured to: transmit, to a second satellite of the plurality of satellites of the NTN, an authentication status request, the authentication status request including the ATAC; receive, from the second satellite, a notification that the status of the authentication process of the UE is unknown; and upon determination that the wait time since the initiation of the authentication process with the first satellite has not elapsed, transmit the authentication status request to the next satellite of the plurality of satellites when the satellite reaches the UE.

[0021] In some embodiments, the UE is configured to: transmit, to a second satellite of the plurality of satellites of the NTN, an authentication status request, the authentication status request including the ATAC; receive, from the second satellite, an authentication vector; and complete the authentication process with the second satellite using the authentication vector.

[0022] In some embodiments, the UE is configured to: transmit, to a second satellite of the plurality of satellites of the NTN, an attach request, the attach request including the ATAC; and receive, from the second satellite, a notification that the attach request is rejected.

[0023] In some embodiments, the UE is configured to: retransmit, to the second satellite, the attach request, a notification that the authentication process of the UE has been successfully completed with one of satellites of the NTN, and user data.

[0024] In some embodiments, the UE is configured to: retransmit, to the second satellite, the attach request and a notification that the authentication process of the UE has been successfully completed with one of satellites of the NTN; receive, from the second satellite, an authentication vector; and complete the authentication process with the second satellite using the authentication vector.

[0025] Embodiments of the present invention may provide a core network element for store and forward authentication of a user equipment (UE) to a network by a non-network network (NTN) including a plurality of satellites, wherein the core network element is configured to: receive, from a first satellite of the plurality of satellites of the NTN, via one of one or more feeder links of the NTN, an authentication request received by the first satellite from the UE as part of an authentication process initiated by the UE, the authentication request including an authentication transaction code (ATAC), the ATAC including an identifier indicative of an identity of the UE and an identifier of the authentication process; and generate an authentication response, the authentication response including the ATAC, and one of an authentication vector if the UE is authorized to access the network or an authentication rejection if the UE is not authorized to access the network; and transmit the authentication response to at least one satellite of the plurality of satellites of the NTN via at least one of the one or more feeder links of the NTN.

[0026] In some embodiments, if the UE is authorized to access the network, the core network element is configured to transmit the authentication response to all satellites of the plurality of satellites of the NTN via at least one of the one or more feeder links of the NTN.

[0027] In some embodiments, if the UE is not authorized to access the network, the core network element is configured to transmit the authentication response only to one satellite of the plurality of satellites of the NTN via one of the one or more feeder links of the NTN, said satellite being the first satellite or the next satellite of the plurality of satellites to become visible to the UE. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] For a better understanding of embodiments of the invention and to show how the same can be carried into effect, reference will now be made, purely by way of example, to the accompanying drawings in which like numerals designate corresponding elements or sections throughout. In the accompanying drawings:

[0029] Fig. 1 shows schematic illustrations of operations performed by a user equipment, a first and second satellites of a non-terrestrial network and a core network element for store and forward authentication of the user equipment to a network, according to some embodiments of the invention;

[0030] Fig. 2 shows schematic illustrations of operations performed by the user equipment, the first and second satellites of the non-terrestrial network and the core network element for store and forward authentication of the user equipment to the network in various scenarios of distribution of authentication-related notifications in the non-terrestrial network, according to some embodiments of the invention; [0031 ] Fig. 3 is an example of store and forward authentication process of the UE to the network by satellites of the NTN, according to some embodiments of the invention;

[0032] Fig. 4 is an example of store and forward authentication process of UE to the network by satellites of the NTN including the wait time of the UE upon receipt of an unknown authentication notification, according to some embodiments of the invention;

[0033] Fig. 5 is a flowchart of a method of operating the NTN for store and forward authentication of the UE to the network, according to some embodiment of the invention;

[0034] Fig. 6 is a flowchart of a method of operating the UE for store and forward authentication of the UE to the network by the NTN including a plurality of satellites, according to some embodiment of the invention;

[0035] Fig. 7 is a flowchart of a method of operating the core network element for store and forward authentication of the UE to the network by the NTN including a plurality of satellites, according to some embodiment of the invention;

[0036] Fig. 8 is a block diagram of an exemplary computing device which may be used with embodiments of the present invention;

[0037] Fig. 9 is a block diagram of an exemplary user equipment which may be used with embodiments of the present invention;

[0038] Fig. 10 is a block diagram of an exemplary base station which may be used with embodiments of the present invention; and

[0039] Fig. 11 is a block diagram of an exemplary satellite which may be used with embodiments of the present invention.

[0040] It will be appreciated that, for simplicity and clarity of illustration, elements shown in the figures have not necessarily been drawn to scale. For example, the dimensions of some of the elements may be exaggerated relative to other elements for clarity. Further, where considered appropriate, reference numerals may be repeated among the figures to indicate corresponding or analogous elements. DETAILED DESCRIPTION OF THE INVENTION

[0041] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be understood by those skilled in the art that the present invention can be practiced without these specific details. In other instances, well-known methods, procedures, and components, modules, units and / or circuits have not been described in detail so as not to obscure the invention.

[0042] Embodiments of the present invention may improve store and forward authentication of a user equipment (UE) to a network by a non-terrestrial network (NTN) including a plurality of satellites.

[0043] Reference is made to Fig. 1, which shows schematic illustrations of operations 101 to 105 performed by a user equipment (UE) 110, a first and second satellites 121, 122 of a non-terrestrial network (NTN) 120 and a core network element 130 for store and forward authentication of UE 110 to a network 90, according to some embodiments of the invention.

[0044] UE 110 (e.g., such as UE 900 described below with respect to Fig. 9) may be an end-user device that may be used to access and use telecommunications services.

[0045] NTN 120 may include a plurality of satellites (e.g., such as satellite 1100 described below with respect to Fig. 11). NTN 120 may include one or more Low Earth Orbit (LEO) satellites, one or more Geosynchronous Orbit (GEO) satellites, one or more Very Low Earth Orbit (VLEO) satellites and / or any suitable combination thereof. For example, NTN 120 may include first satellite 121 and second satellite 122 (e.g., as shown in Fig. 1). While two satellites 121, 122 are shown in Fig. 1, NTN 120 may include more than two satellites. Each of satellites of NTN 120 (e.g., satellites 121, 122) may include abase station ofNTN 120 (e.g., such as abase station 1125 described below with respect to Fig. 11). Each of the satellites of NTN 120 (e.g., satellites 121, 122) may include a core network authentication module (e.g., such as core network authentication module 1130 described below with respect to Fig. 11). The core network authentication module may perform at least a portion of operations of a core network for authentication of UE 110 to network 90. Each of the satellites ofNTN 120 (e.g., satellites 121, 122) may include an authentication repository (e.g., such as authentication repository 1135 described below with respect to Fig. 11). The authentication repository may store a list of ongoing authentication processes of UEs (e.g., such as a list 1137 described above with respect to Fig. 11), a list of successfully completed authentication processes of UEs (e.g., such as a list 1139 described above with respect to Fig. 11) and / or any other suitable information related to authentication of UEs to network 90.

[0046] Core network element 130 may include an authentication server of a core network (or a proxy thereof) and / or any other suitable components of the core network required to perform authentication of UEs to network 90. Network 90 may be a public switched telephone network (PSTN), an internet network or any other suitable telecommunication or Internet Protocol (IP) based network.

[0047] In operation 101, UE 110 may initiate an authentication process 110a to get access to network 90. As part of authentication process 110a, UE 110 may transmit an authentication request 110b to first satellite 121 of NTN 120 when first satellite 121 reaches (e.g., becomes visible to) UE 110. Authentication request 110b may include an authentication transaction code (ATAC). The ATAC may include an identifier indicative of an identity of UE 110. For example, the identifier indicative of the identity of the UE may include an International Mobile Subscriber Identity (I MSI) or a temporary version of the IMS1, a Subscription Concealed Identifier (SUCI) and / or any other suitable information that can identify this particular UE. The ATAC may include an identifier of the authentication process initiated by UE 110. For example, the identifier of the authentication process may include a time stamp and / or any other suitable information that can distinguish or identify this particular authentication process initiated earlier or later than this particular authentication process.

[0048] First satellite 121 may receive authentication request 110b from UE 110. First satellite 121 may store authentication request 110b.

[0049] First satellite 121 may calculate a wait time for which UE 110 may wait since the initiation of authentication process 110a with first satellite 121 before initiating any new authentication process. For example, the wait time (e.g., maximal wait time) may be a time in which first satellite 121 may reach (e.g., reappear or become visible again to) UE 110. In another example, the wait time (e.g., minimal wait time) may be a time in which the next satellite of the plurality of satellites of NTN 120 may reach (e.g., appear or become visible to) UE 110. In another example, the wait time (e.g., minimal wait time) may be a time in which first satellite 121 may reach one of the feeder link(s) of NTN 120 (e.g., such as feeder links 124, 125 show in Fig. 1) plus a time in which the next satellite of the plurality of satellites of NTN 120 may reach one of the feeder link(s) of NTN 120 and reach UE 110 In example, the wait time may be greater than a time in which first satellite 121 may reach (e.g., become visible to) one of the feeder link(s) of NTN 120 (e.g., such as feeder links 124, 125 show in Fig. 1) plus a time in which the next satellite of the plurality of satellites of NTN 120 may reach one of the feeder link(s) of NTN 120 and reach UE 110 and / or smaller than a time in which first satellite 121 may reach (e.g., reappear or become visible again to) UE 110.

[0050] First satellite 121 may transmit, to UE 110, a notification 111. Notification 111 may indicate that UE 110 is unknown. Notification 111 may include an indication of the wait time.

[0051] UE 110 may receive indication 111 from first satellite 121. UE 110 may monitor a time that has elapsed since the initiation of authentication process 110a. UE 110 may not initiate any new authentication process until the time elapsed since the initiation of authentication process 110a exceeds the wait time.

[0052] In operation 102, first satellite 121 may reach (e.g., become visible to) one of the feeder link(s) of NTN 120 (e.g., feeder link 124). First satellite 121 may forward (e.g., transmit) authentication request 110b to core network element 130 via the feeder link (e.g., feeder link 124).

[0053] Core network element 130 may receive authentication request 110b from first satellite 121. Based on authentication request 110b, core network element 130 may determine whether or not UE 110 is authorized to access network 90. Core network element 130 may generate an authentication response 131. Authentication response 131 may include the ATAC (e.g., the identifier indicative of the identity of the UE and the identifier of the authentication process), and one of (i) an authentication vector if it is determined that the UE is authorized to access the network or (ii) an authentication rejection if it is determined that the UE is not authorized to access the network. The authentication vector may include a random number (RAND), an authentication token (AUTN), an expected response (XRES), optionally a key for access security management entity (KASME) and / or any other suitable data elements required to complete authentication process 110a of UE 110 to network 90.

[0054] Core network element may transmit (e.g., distribute) authentication response 131 to at least one satellite of the plurality of satellites of NTN 120 via at least one of the feeder link(s) of NTN 120. For example, if it is determined that UE 110 is authorized to access network 90, core network element 130 may forward (e.g., transmit or distribute) authentication response 131 at least to the satellite with which the authentication process has been initiated (e.g., first satellite 121) and the next satellite of the plurality of satellites to reach UE 110. In another example, core network element 130 may forward (e.g., transmit or distribute) authentication response 131 to a subset of satellites (e.g., three or more satellites) of the plurality of satellites of NTN 120. In another example, core network element 130 may forward (e.g., transmit or distribute) authentication response 131 to all satellites of the plurality of satellites of NTN 120.

[0055] If it is determined that UE 110 is not authorized to access network 90, core network element 130 may forward (e.g., transmit or distribute) authentication response 131 to one satellite only, for example to first satellite 121 (e.g., with which the authentication process has been initiated) or the next satellite of the plurality of satellites to reach (e.g., become visible to) UE 110.

[0056] Each of the feeder link(s) (e.g., feeder links 124, 125) may store authentication response 131 and transmit authentication response 131 to any satellite of the plurality of satellites of NTN 120 when the respective satellite reaches the respective feeder link. In the example of Fig. 1, first satellite 121 may receive authentication response 131 for authentication process 110a of UE 110 via feeder link 125 when first satellite 121 reaches feeder link 125 and second satellite 122 may receive authentication response 131 for authentication process 110a of UE 110 via feeder link 124 when second satellite 122 reaches feeder link 124 (e.g., as shown in operation 102 in Fig. 1

[0057] Upon receipt of authentication response 131, each of the plurality of satellites of the NTN (e.g., satellites 121, 122) may update its authentication repository to include authentication process 110a of UE 110 in the list of ongoing authentication processes of UEs.

[0058] In operation 103, second satellite 122 of the plurality of satellites of NTN 120 may reach (e.g., become visible to) UE 110. In the example of Fig. I. second satellite 122 may receive authentication response 131 for authentication process 110a of UE 110 before reaching (e.g., becoming visible to) UE 110 (e.g., in operation 102 as described hereinabove).

[0059] When second satellite 122 reaches UE 110, UE 110 may transmit an authentication status request 110c to second satellite 122. Authentication status request 110c may include the ATAC. Based on the ATAC included in authentication status request 110c, second satellite 122 may determine (e.g., check in the list of ongoing authentication processes stored in its authentication repository) whether or not authentication response 131 for authentication process 110a of UE 110 has been received.

[0060] If it is determined by second satellite 122 that that authentication response 131 for authentication process 110a of UE 110 has been received and that UE 110 is authorized to access network 90 (e.g., if authentication response 131 includes the authentication vector), second satellite 122 may perform a series of operations 1 lOd to complete authentication process 110a of UE 110. For example, in order to complete authentication process 110a of UE 110, second satellite 122 may transmit, to UE 110, the authentication vector included in authentication response 131. UE 110 may receive the authentication vector from second satellite 122. Based on the authentication vector, UE 110 may generate a UE response. UE 110 may transmit the UE response to second satellite 122. Second satellite 122 may receive the UE response. Based on the UE response and the authentication vector, second satellite 122 may complete authentication process 110a of UE 110 (e.g., by its core network authentication module). Second satellite 122 may update its authentication repository to include authentication process 110a of UE 110 in the list of successfully completed authentication processes.

[0061] Once authentication process 110a of UE 110 has been completed, UE 110 may transmit user data to second satellite 122. Second satellite 122 may store and forward the user data received from UE 110 to network 90 via one of the feeder link(s) of NTN 120 when second satellite 122 reaches (e.g., becomes visible to) the feeder link.

[0062] Second satellite 122 may complete authentication process 110a of UE 110 only if the AT AC of authentication status request 110c is identical to the ATAC of authentication response 131. For example, if the identifiers indicative of the identity of UE 110 and / or the identifiers of authentication process 110a are not identical in the ATACs of authentication status request 110c and authentication response 131, second satellite 122 may reject the authentication process of UE 110. Second satellite 122 may transmit to UE 110 a notification that authentication process 110a is rejected (e.g., due to the mismatch in the identifiers).

[0063] If it is determined by second satellite 122 that authentication response 131 for UE 110 and authentication process 110 has been received, but UE 110 is not authorized to access network 90 (e.g., if authentication response 131 includes the authentication rejection), second satellite 122 may transmit, to UE 110, the authentication rejection. UE 110 may receive the authentication rejection. Upon receipt of the authentication rejection, UE 110 may initiate a new authentication process. For example, if UE 110 receives the authentication rejection, UE 110 may initiate a new authentication process even before the wait time since the initiation of authentication process 110a has elapsed.

[0064] In operation 104, after completing authentication process 110a of UE 110, second satellite 122 may forward (e.g., transmit) to core network element 130 a notification 123 that authentication process 110a of UE 110 has been successfully completed. Notification 123 may include the AT AC. Second satellite 122 may forward notification 123 to core network element 130 via one of the feeder link(s) of NTN 120 when second satellite 122 reaches (e.g., becomes visible to) the feeder link (e.g., feeder link 124 in the example of Fig. 1). Core network element 130 may receive notification 123.

[0065] Core network element 130 may forward (e.g., distribute) notification 123 indicating that authentication process 110a of UE 110 has been successfully completed to at least one satellite of the plurality of satellites of NTN 120. For example, core network element 130 may transmit notification 123 at least to the next satellite of the plurality of satellites of NTN 120 to reach (e.g., become visible to) UE 110. In another example, core network element 130 may transmit notification 123 to a subset of satellites (e.g., three or more satellites) of the plurality of satellites of NTN 120. In another example, core network element 130 may forward notification 123 to all satellites of the plurality of satellites of NTN 120. Each of the feeder link(s) (e.g., feeder links 124, 125) may store notification 123 and transmit notification 123 to any satellite of the plurality of satellites of NTN 120 when the respective satellite reaches the respective feeder link. In the example of Fig. 1, first satellite 121 may receive notification 123 via feeder link 124 when first satellite 121 reaches feeder link 124 and second satellite 122 may receive notification 123 via feeder link 124 when second satellite 122 reaches feeder link 124 (e.g., as shown in operation 104 in Fig. 1).

[0066] Each satellite of the plurality of satellites of NTN 120 (e.g., satellites 121,122) may receive notification 123 and update its authentication repository to include authentication process 110a of UE 110 in the list of successfully completed authentication processes.

[0067] In operation 105, first satellite 121 may reach (e.g., become visible to) UE 110. UE 110 may transmit an attach request HOe to first satellite 121. Attach request HOe may include the ATAC and / or notification 223 indicating that authentication process 110a of UE 110 has been successfully completed with one of the plurality of satellites of NTN 120 (e.g., with second satellite 121 in the example of Fig. 1). First satellite 121 may receive attach request 1 lOe. First satellite 121 may verify (e.g., in the list of successfully completed authentication processes stored in its authentication repository) that authentication request 110a of UE 110 has been successfully completed. Upon the verification, first satellite 121 may transmit to UE 110 a notification 121a that attach request 1 lOe is approved. UE 110 may transmit user data 11 Of to first satellite 121. First satellite 121 may store and forward user data 11 Of received from UE 110 to network 90 via one of the feeder link(s) of NTN 120 when second satellite 122 reaches (e.g., becomes visible to) the feeder link.

[0068] Reference is made to Fig. 2, which shows schematic illustrations of operations 201 to 207 performed by UE 210 (e.g., such as UE 210), first and second satellites 221, 222 (e.g., such as satellites 121, 122) of NTN 220 (e.g., such as NTN 120) and core network element 230 (e.g., such as core network element 130) for store and forward authentication of UE 210 to network 90 in various scenarios of distribution of authentication-related notifications in NTN 220, according to some embodiments of the invention.

[0069] In operation 201, UE 210 may initiate an authentication process 210a by transmitting an authentication request 210b with the ATAC to first satellite 221 of NTN 220 when first satellite 221 reaches (e.g., becomes visible to) UE 210. First satellite 221 may receive authentication request 210b from UE 210. First satellite 221 may store authentication request 210b. First satellite 221 may calculate the wait time for which UE 210 may wait since the initiation of authentication process 210a with first satellite 221 before initiating any new authentication process. First satellite 221 may transmit, to UE 210, notification 211 indicating that UE 210 is unknown and / or indicating the wait time. UE 210 may receive indication 211 from first satellite 221. UE 210 may monitor a time that has elapsed since the initiation of authentication process 210a. UE 210 may not initiate any new authentication process until the time that has elapsed since the initiation of authentication process 110a exceeds the wait time.

[0070] In operation 202, when first satellite 221 reaches (e.g., becomes visible to) one of the feeder link(s) of NTN 220, first satellite 221 may forward (e.g., transmit) authentication request 210b to core network element 230 via the feeder link (e.g., a feeder link 224). Core network element 230 may receive authentication request 210b. Based on authentication request 210b, core network element 230 may determine whether or not UE 210 is authorized to access network 90, generate an authentication response 231 and forward (e.g., transmit or distribute) authentication response 231 to at least one satellite of the plurality of satellites of NTN 220 via at least one of the feeder link(s) of NTN 220 (e.g., as described above with respect to Fig. 1). Authentication response 231 may include the ATAC, and of (i) the authentication vector if UE 210 is authorized to access network 90 or (ii) if UE 210 is not authorized to access network 90 (e.g., as described above with respect to Fig. 1). In the example of Fig. 2, first satellite 221 (e.g., with which the authentication process has been initiated) may receive authentication response 231 for authentication process 210a of UE 210 in operation 202.

[0071] In operation 203, second satellite 222 may reach (e.g., become visible to) UE 210. Unlike in the example of Fig. 1, in the example of Fig. 2, second satellite 222 may reach UE 210 before receiving authentication response 231 for authentication process 210a of UE 210 from core network element 230 (e.g., see operations 201 and 202 in Fig. 2).

[0072] When second satellite 222 reaches UE 210, UE 210 may transmit an authentication status request 210c with the ATAC to second satellite 222. Upon determination that no authentication response 231 for authentication process 210a of UE 210 has been received, second satellite 222 may transmit to UE 210 a notification 222a indicating that the status of authentication request 210a of UE 210 is unknown. UE 210 may receive notification 222a. UE 210 may not initiate any new authentication process unless the time that elapsed since the initiation of authentication process 110a exceeds the wait time. This is unlike prior art UE that would typically initiate a new authentication process upon receipt of notification 222a. Instead, UE 210 may transmit authentication status request 210c to the next satellite that reaches (e.g., becomes visible to) UE 210.

[0073] Each of the feeder link(s) of NTN 220 may store authentication response 231 for authentication process 210a of UE 210 and transmit authentication response 231 to any satellite of the plurality of satellites of NTN 220 when the respective satellite reaches the respective feeder link. In operation 204, second satellite 222 may reach (e.g., become visible to) one of the feeder link(s) of NTN 220. Second satellite 222 may receive authentication response 231, e.g. from the feeder link (e.g., feeder link 224). Second satellite 222 may update its authentication repository to include authentication process 210a of UE 210 in the list of ongoing authentication processes.

[0074] In operation 205, first satellite 221 may reach (e.g., become visible to) UE 210. UE 210 may transmit authentication status request 210c to first satellite 221. Upon verification (e.g., in the list of ongoing authentication processes in the authentication repository of first satellite 221) that authentication response 231 for authentication process 210a of UE 210 has been received and that UE 210 is authorized to access network 90, first satellite 221 may perform a series of actions 210d complete authentication process 210a of UE 210 (e.g., as described above with respect to Fig. 1). While in the example of Fig. 2 first satellite 221 completes authentication process 210a of UE 210, any other satellite of the plurality of satellites of NTN 220 that has successfully received authentication response 231 before reaching UE 210 may complete authentication process 210a of UE 210.

[0075] In operation 206, first satellite 221 (or any other satellite of the plurality of satellites of NTN 220 that has completed authentication process 210a of UE 210) may reach (e.g., become visible to) one of the feeder link(s) of NTN 220 (e.g., feeder link 224 in the example of Fig. 2). First satellite 221 may transmit to core network element 230 via the feeder link notification 223 that authentication process 210a of UE 210 has been successfully completed. Core network element 230 may receive notification 223 from second satellite 222. Core network element 230 may transmit (e.g., distribute) notification 223 indicating that authentication process 210a of UE 210 has been successfully completed to at least one satellite of the plurality of satellites of NTN 220 (e.g., as described above with respect to Fig. 1).

[0076] Each satellite of the plurality of satellites of NTN 220 (e.g., satellites 221,222) may receive notification 223 and update its authentication repository to include authentication process 210a of UE 210 in the list of successfully completed authentication processes.

[0077] In operation 207, second satellite 222 may reach (e.g., become visible to) UE 210. Unlike in the example of Fig. 1, in the example of Fig. 2, second satellite 222 reaches UE 210 before receiving notification 1223 indicating that authentication process 210a of UE 210 has been successfully completed (e.g., see operations 205, 206 in Fig. 2). When second satellite 222 reaches UE 210, UE 210 may transmit to second satellite 222 attach request 210e. Attach request 210e may include the AT AC. Since second satellite 222 has not received notification 223 indicating that authentication process 210a of UE 210 has been successfully completed, second satellite 222 may reject attach request 210e and transmit to UE 210 a notification 222b that attach request 210e is rejected. Unlike prior art UE that would typically initiate a new authentication process upon receipt of notification 222b, UE 210 may not initiate any new authentication process. Instead, UE 210 may retransmit to second satellite 222 attach request 210e with the AT AC and notification 223 indicating that authentication process 210a of UE 210 has been successfully completed with one of the plurality of satellites of NTN 220 (e.g., with first satellite 221 in the example of Fig. 2). Second satellite 222 may receive attach request 210e with the ATAC and notification 223. Since in the example of Fig. 2 second satellite 222 has already received authentication response 231 for authentication process 210a of UE 210 before reaching UE 210 (e.g., in operation 204 in the example of Fig. 2), second satellite 222 may, based on the AT AC included in the attached request 210e, verify (e.g., in the list of ongoing authentication processes stored in the authentication repository) that authentication response 231 for authentication process 210a of UE 210 has been received and that UE 210 is authorized to access network 90. Upon verification, second satellite 222 may perform the series of operations 21 Od to complete authentication process 210a of UE 210 (e.g., as described above with respect to Fig. 1). Once authentication process 210a of UE 210 has been completed, UE 210 may transmit user data 210f to second satellite 222. Second satellite 222 may store and forward user data 21 Of to network 90 via one of the feeder link(s) of NTN 220 when second satellite 222 reaches (e.g., becomes visible to) the feeder link.

[0078] Second satellite 222 may forward (e.g., transmit) to core network element 230 notification 223 that authentication process 210a of UE 210 has been successfully completed via one of the feeder link(s) of NTN 220 when second satellite 222 reaches the feeder link, and core network element 230 may distribute notification 223 to at least one satellite of the plurality of satellites of NTN 220 (e.g., as described above with respect to Fig. 1).

[0079] As mentioned above, in the example of Fig. 2, second satellite 222 receives authentication response 231 for authentication process 210a of UE 210 before reaching UE 210 (e.g., in operation 204 in the example of Fig. 2), which allows second satellite 222 to successfully complete authentication process 210a of UE 210. In another example, second satellite 222 may reach (e.g., become visible to) UE 210 before receiving authentication response 231 for authentication process 210a of UE 210. In this example, upon receipt of notification 222b indicating that attach request 2 lOe is rejected, UE 210 may wait the wait time since the initiation of the authentication request 210a of UE 210 before initiating a new authentication process. UE 210 may not initiate any new authentication process until the time that has elapse since the initiation of the authentication request 210a of UE 210 exceeds the wait time. This is in contrast to prior art UE which would typically initiate a new authentication process with second satellite 222 upon receipt of notification 222b.

[0080] In another example, upon receipt of notification 222b indicating that attach request 210e has been rejected, UE 210 may retransmit to second satellite 222 attach request 210e with the ATAC, notification 223 indicating that authentication process 210a of UE 210 has been successfully completed with one of the plurality of satellites of NTN 220 (e.g., with first satellite 221 in the example of Fig. 2) and user data 210f. Second satellite 222 may store user data 210f and forward user data 210f to one the feeder link(s) of NTN 220 when the second satellite reaches the feeder link. If UE 210 is authorized to access network 90, the feeder link may forward user data 21 Of network 90. If the UE is not authorized to access network 90, the feeder link may drop user data 21 Of and not forward it to network 90.

[0081] Reference is made to Fig. 3, which is an example of store and forward authentication process 300 of UE 310 (e.g., such as UE 110, 210) to the network (e.g., such as network 90) by satellites 321, 322 (e.g., such as satellites 121, 122 and 221, 222, respectively) of the NTN 320 (e.g., such as NTN 120, 220), according to some embodiments of the invention.

[0082] In operation 341, UE 310 may initiate authentication process 300 by transmitting to first satellite 310 an authentication request with the AT AC (e.g., with the identifier indicative of the identity of UE 310 and the identifier of authentication process 300). In operation 342, first satellite 321 may transmit to UE 310 a notification indicating that UE 310 is unknown and / or indicating the wait time for UE 310 to wait since the initiation of authentication process 300 with first satellite 321 before initiating any new authentication process with one of satellites of NTN 320.

[0083] In operation 343, first satellite 321 may forward the authentication request with the ATAC to feeder link 324 (e.g., such as feeder link 124). In operation 344, feeder link 324 may forward the authentication request with the ATAC to core network element 330.

[0084] In operation 345, core network element 330 may forward an authentication response for authentication process 300 of UE 310 to feeder link 324. The authentication response may include the ATAC (e.g., with the identifier indicative of the identity of UE 310 and the identifier of authentication process 300) and the authentication vector if UE 310 is authorized to access the network (e.g., as described above with respect to Figs. 1 and 2). In operation 346, core network element 130 may forward the authentication response (with the ATAC and the authentication vector) to feeder link 325 (e.g., such as feeder link 125).

[0085] In operation 347, feeder link 324 may forward the authentication response (with the ATAC and the authentication vector) to first satellite 321. In operation 348, feeder link 325 may forward the authentication response (with the ATAC and the authentication vector) to second satellite 322.

[0086] In operation 349, UE 310 may transmit an authentication status request to second satellite 322. The authentication status request may include the ATAC (e.g., with the identifier indicative of the identity of UE 310 and the identifier of authentication process 300). In operation 350, second satellite 322 may complete authentication process 300 with UE using the authentication vector included in the authentication response received from core network element 330 (e.g., as described above with respect to Figs. 1 and 2).

[0087] Authentication process 300 may include operations that are not shown in Fig. 3 (e.g., such as operations described above with respect to Figs. 1 and 2).

[0088] Reference is made to Fig. 4, which is an example of store and forward authentication process 400 of UE 410 (e.g., such as UE 110, 210) to the network (e.g., such as network 90) by satellites 421, 422 (e.g., such as satellites 121, 122 and 221, 222, respectively) of the NTN 420 (e.g., such as NTN 120, 220) including the wait time of UE 410 upon receipt of an unknown authentication notification, according to some embodiments of the invention.

[0089] In operation 441, UE 410 may initiate authentication process 400 by transmitting to first satellite 410 an authentication request with the ATAC (e.g., with the identifier indicative of the identity of UE 410 and the identifier of authentication process 400). In operation 442, first satellite 421 may transmit to UE 410 a notification indicating that UE 410 is unknown and / or indicating the wait time for UE 410 to wait since the initiation of authentication process 400 with first satellite 421 before initiating any new authentication process with one of satellites of NTN 420 (e.g., as described above with respect to Figs. 1 and 2).

[0090] In operation 443, first satellite 421 may forward the authentication request with the ATAC to feeder link 424 (e.g., such as feeder link 124). In operation 444, feeder link 424 may forward the authentication request with the ATAC to core network element 430.

[0091] In operation 445, core network element 430 may forward an authentication response for authentication process 400 of UE 410 to feeder link 424. The authentication response may include the ATAC (e.g., with the identifier indicative of the identity of UE 410 and the identifier of authentication process 400) and the authentication vector if UE 410 is authorized to access the network (e.g., as described above with respect to Figs. 1 and 2).

[0092] In operation 346, feeder link 424 may forward the authentication response (with the ATAC and the authentication vector) to first satellite 421.

[0093] In operation 447, UE 310 may transmit an authentication status request to second satellite 422. The authentication status request may include the ATAC (e.g., with the identifier indicative of the identity of UE 410 and the identifier of authentication process 300). In operation 448, second satellite 422 may transmit to UE 410 a notification indicating that the status authentication process 400 is unknown (e.g., since second satellite 422 has not yet received the authentication response for authentication process 400 of UE 410).

[0094] In operation 449, UE 410 may wait the wait time since the initiation of authentication process 400 with first satellite 421 before initiating any new authentication process with one of satellites of NTN 420. UE 410 may not initiate any new authentication process with one of satellites of NTN 420 before the time that has elapsed since the initiation of authentication process 400 with first satellite 421 exceeds the wait time.

[0095] In operation 450, feeder link 424 may forward the authentication response with the AT AC and the authentication vector to second satellite 422.

[0096] Authentication process 400 may include operations that are not shown in Fig. 4 (e.g., such as operations described above with respect to Figs. 1 and 2).

[0097] Reference is made to Fig. 5, which is a flowchart of a method of operating a NTN (e.g., such as NTN 120, 220) for store and forward authentication of a UE (e.g., such as UE 110, 310) to a network (e.g., such as network 90), according to some embodiment of the invention.

[0098] The method may be performed using equipment described above with respect to Figs. 1 and 2 and / or any other suitable equipment.

[0099] In operation 501, an authentication request may be received by a first satellite (e.g., such as first satellite 121, 221) of a plurality of satellites of the NTN (e.g., such as NTN 120, 220) from the UE (e.g., such as UE 110, 210) as part of an authentication process initiated by the UE (e.g., as described above with respect to Figs. 1 and 2). The authentication request may include an authentication transaction code (ATAC). The ATAC may include an identifier indicative of an identity of the UE and an identifier of the authentication process (e.g., as described above with respect to Figs. 1 and 2).

[00100] In operation 502, a wait time for the UE to wait since the initiation of the authentication process before initiating a new authentication process may be calculated by the first satellite (e.g., as described above with respect to Figs. 1 and 2). The wait time may range between a time in which the first satellite becomes visible to one of the one or more feeder links and a time in which the first satellite reappears and becomes visible to the UE (e.g., as described above with respect to Figs. 1 and 2).

[00101] In operation 503, a notification indicating that the UE is unknown and / or indicating the wait time may be transmitted to the UE by the first satellite (e.g., as described above with respect to Figs. 1 and 2).

[00102] In operation 504, the authentication request may be forwarded to a core network element (e.g., such as core network element 130, 230) of a core network by the first satellite via one of one or more feeder links of the NTN (e.g., as described above with respect to Figs. 1 and 2).

[00103] In operation 505, an authentication response from the core network element may be received by at least one satellite of the plurality of satellites of the NTN via one of the one or more feeder links, (e.g., as described above with respect to Figs. 1 and 2). The authentication response including the ATAC, and one of an authentication vector if the UE is authorized to access the network or an authentication rejection if the UE is not authorized to access the network (e.g., as described above with respect to Figs. 1 and 2).

[00104] An authentication status request may be received from the UE by a second satellite (e.g., such as satellite 122, 222) of the plurality of satellites. The authentication status request may include the ATAC. Based on the ATAC, it may be determined by the second satellite whether or not the authentication response for the authentication process of the UE has been received (e.g., as described above with respect to Figs. 1 and 2).

[00105] Upon determination that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network, the authentication process of the UE may be completed using the authentication vector included in the authentication response (e.g., as described above with respect to Fig. 1). A notification that the authentication process of the UE has been successfully completed may be transmitted by the second satellite to the core network element via one of the one or more feeder links (e.g., as described above with respect to Fig. 1). The notification may include the ATAC.

[00106] Upon determination that at least one identifier included in the AT AC of the authentication status request is not identical to the corresponding at least one identifier included in the ATAC of the authentication response, the authentication process may be rejected by the second satellite (e.g., as described above with respect to Fig. 1). A notification that the authentication process is rejected may be transmitted to the UE by the second satellite (e.g., as described above with respect to Fig. 1).

[00107] Upon determination that the authentication response for the authentication process of the UE has been received but the UE is not authorized to access the network, the authentication rejection may be transmitted to the UE by the second satellite (e.g., as described above with respect to Fig. 2).

[00108] Upon determination that no authentication response for the authentication process of the UE has been received, a notification that the status the authentication request of the UE is unknown may be transmitted to the UE by the second satellite (e.g., as described above with respect to Fig. 2). The authentication status request may be then received from the UE by the next satellite (e.g., the first satellite as in the example of Fig. 2) of the plurality of satellites of the NTN that reaches the UE (e.g., as described above with respect to Fig. 2). Based on the ATAC included in the authentication status request, it may be verified by that satellite that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network (e.g., as described above with respect to Fig. 2). Upon verification, the authentication process of the UE may be completed by that satellite (e.g., as described above with respect to Fig. 2).

[00109] An attach request may be received from the UE by the second satellite of the plurality of satellites of the NTN (e.g., as described above with respect to Figs. 1 and 2). The attach request may include the ATAC. Based on the ATAC included in the attach request, it may be determined by the second satellite whether or not a notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites has been received (e.g., as described above with respect to Figs. 1 and 2). Upon determination that the notification has been received, the attach request may be approved by the second satellite. A notification that the attach request is approved may be transmitted to the UE by the second satellite (e.g., as described above with respect to Figs. 1 and 2).

[00110] Upon determination that no notification that the authentication process of the UE has been successfully completed has been received, the attach request may be rejected by the second satellite (e.g., as described above with respect to Fig. 2). A notification that the attach request is rejected may be transmitted to the UE by the second satellite (e.g., as described above with respect to Fig. 2).

[00111] In one response example, the attach request, the notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites and user data may be received by the second satellite from the UE (e.g., as described above with respect to Fig. 2). The user data may be stored by the second satellite (e.g., as described above with respect to Fig. 2). The user data may be then forwarded by the second satellite to one of the one or more feeder links (e.g., as described above with respect to Fig. 2).

[00112] In another response example, the attach request and the notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites may be received by the second satellite from the UE (e.g., as described above with respect to Fig. 2). Based on the ATAC included in the attach request, it may be determined by the second satellite whether or not the authentication response for the authentication process of the UE has been received (e.g., as described above with respect to Fig. 2). Upon determination that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network, the authentication process of the UE may be completed by the second satellite using the authentication vector included in the authentication response (e.g., as described above with respect to Fig. 2).

[00113] Reference is made to Fig. 6, which is a flowchart of a method of operating a UE (e.g., such as UE 110, 210) for store and forward authentication of the UE to the network (e.g., such as network 90) by a NTN (e.g., such as NTN 120, 220) including a plurality of satellites (e.g., such as satellites 121, 122 and 221, 222), according to some embodiment of the invention.

[00114] The method may be performed using equipment described above with respect to Figs. 1 and 2 and / or any other suitable equipment.

[00115] In operation 601, an authentication process may be initiated by the UE by transmitting an authentication request to a first satellite (e.g., first satellite 121, 221) of the plurality of satellites of the NTN (e.g., as described above with respect to Figs. 1 and 2). The authentication request may include the ATAC (e.g., as described above with respect to Figs. 1 and 2). The ATAC may include the identifier indicative of the identity of the UE and the identifier of the authentication process (e.g., as described above with respect to Figs. 1 and 2).

[00116] In operation 602, a notification indicating of a wait time for the UE to wait since the initiation of the authentication process with the first satellite before initiating a new authentication process may be received by the UE from the first satellite (e.g., as described above with respect to Figs. 1 and 2).

[00117] In operation 603, a time that has elapsed since the initiation of the authentication process with the first satellite may be monitored by the UE (e.g., as described above with respect to Figs. 1 and 2).

[00118] In operation 604, a new authentication process may be initiated by the UE only if the authentication process is unsuccessful (e.g., rejected) or the time that has elapsed since the initiation of the authentication process with the first satellite exceeds the wait time (e.g., as described above with respect to Figs. 1 and 2).

[00119] An authentication status request may be transmitted by the UE to a second satellite (e.g., such as second satellite 122, 222) of the plurality of satellites of the NTN. The authentication status request may include the ATAC (e.g., as described above with respect to Fig. 2). In one example response, a notification that the status of the authentication process of the UE is unknown may be received by the UE from the second satellite (e.g., as described above with respect to Fig. 2). Upon determination that the wait time since the initiation of the authentication process with the first satellite has not elapsed, the authentication status request may be transmitted by the UE to the next satellite of the plurality of satellites when that satellite reaches the UE (e.g., as described above with respect to Fig. 2). In another response example, an authentication vector may be received by the UE from the second satellite (e.g., as described above with respect to Fig. 1). The authentication process may be completed by the UE with the second satellite using the authentication vector (e.g., as described above with respect to Fig. I).

[00120] An attach request may be transmitted by the UE to the second satellite of the plurality of satellites of the NTN. In response, a notification that the attach request is rejected may be received by the UE from the second satellite. In one response example, the attach request may be retransmitted by the UE to the second satellite with a notification that the authentication process of the UE has been successfully completed with one of satellites of the NTN (e.g., as described above with respect to Fig. 2). The authentication vector may be then received by the UE from the second satellite (e.g., as described above with respect to Fig. 2). The authentication process may be then completed by the UE with the second satellite using the authentication vector (e.g., as described above with respect to Fig. 2). In another response example, the attach request may be retransmitted by the UE to the second satellite with the notification that the authentication process of the UE has been successfully completed with one of satellites of the NTN and the user data (e.g., as described above with respect to Fig. 2).

[00121] Reference is made to Fig. 7, which is a flowchart of a method of operating a core network element (e.g., such as core network element 130, 230) for store and forward authentication of the UE (e.g., such as UE 110, 210) to the network (e.g., such as network 90) by a NTN (e.g., such as NTN 120, 220) including a plurality of satellites (e.g., such as satellites 121, 122 and 221, 222), according to some embodiment of the invention.

[00122] The method may be performed using equipment described above with respect to Figs. 1 and 2 and / or any other suitable equipment.

[00123] In operation 701, an authentication request of a UE generated by the UE as part of an authentication process may be received by the core network element from a first satellite of the plurality of satellites of the NTN (e.g., as described above with respect to Figs. 1 and 2). The authentication request may include the ATAC (e.g., as described above with respect to Figs. 1 and 2). The ATAC may include the identifier indicative of the identity of the UE and the identifier of the authentication process (e.g., as described above with respect to Figs. 1 and 2).

[00124] In operation 702, an authentication response may be generated by the core network element. The authentication response may include the ATAC, and one of an authentication vector if the UE is authorized to access the network or an authentication rejection if the UE is not authorized to access the network (e.g., as described above with respect to Figs. 1 and 2).

[00125] In operation 703, the authentication response may be distributed by the core network element to at least one satellite of the plurality of satellites of the NTN via at least one of the one or more feeder links of the NTN (e.g., as described above with respect to Figs. 1 and 2).

[00126] If the UE is authorized to access the network, the authentication response may be distributed by the core network element to all satellites of the plurality of satellites of the NTN via at least one of the one or more feeder links of the NTN.

[00127] If the UE is not authorized to access the network, the authentication response may be forwarded by the core network element only to one satellite of the plurality of satellites of the NTN via one of the one or more feeder links of the NTN (e.g., to the first satellite or the next satellite of the plurality of satellites to become visible to the UE).

[00128] Embodiments of the present invention may improve store and forward authentication of the UE to the network by the NTN including a plurality of satellites.

[00129] In one example, embodiments of the present invention may ensure that at each point of time only one authentication process initiated by the UE may exist and / or prevent the UE from initiating multiple parallel authentication processes. Having two or more pending authentication processes of the UE to the network may cause a problem since the challenge response of the UE is different for each authentication process. During an authentication process, the core network element may transmit a unique challenge to the UE, which then generates a response based on this challenge using cryptographic algorithms and secret keys (e.g., as described hereinabove). If multiple authentication processes are initiated simultaneously, the UE may receive different challenges for each process. The responses generated by the UE will be different for each challenge because they are based on different inputs. When the core network element tries to verify the responses, it may need to match each response with the corresponding challenge. However, if there are multiple pending authentication processes, the network might confuse which response corresponds to which challenge, leading to authentication failures. By ensuring that at each point of time only one authentication process initiated by the UE may exist and / or prevent the UE from initiating multiple parallel authentication processes, embodiments of the present invention may improve the store and forward authentication of the UE to the network by the NTN including the plurality of satellites.

[00130] In another example, embodiments of the present invention may shorten the time required to complete authentication process of the UE to the network. For example, the UE may initiate the authentication process with the satellite and complete the authentication process with another satellite of the plurality of satellites of the NTN which may reach the UE before the first satellite reappears and becomes visible again to the UE, thereby shortening the time required to complete authentication process of the UE to the network. By shortening the time required to complete authentication process of the UE to the network, embodiments of the present invention may improve the store and forward authentication of the UE to the network by the NTN including the plurality of satellites.

[00131] Reference is now made to Fig. 8, which is a block diagram of an exemplary computing device 800 which may be used with embodiments of the present invention.

[00132] Computing device 800 may include a controller or processor 805 that may be, for example, a central processing unit processor (CPU), a chip or any suitable computing or computational device, an operating system 815, a memory 820, a storage 830, input devices 835 and output devices 840.

[00133] Operating system 815 may be or may include any code segment designed and / or configured to perform tasks involving coordination, scheduling, arbitration, supervising, controlling or otherwise managing operation of computing device 800, for example, scheduling execution of programs. Memory 820 may be or may include, for example, a Random Access Memory (RAM), a read only memory (ROM), a Dynamic RAM (DRAM), a Synchronous DRAM (SD-RAM), a double data rate (DDR) memory chip, a Flash memory, a volatile memory, a non volatile memory, a cache memory, a buffer, a short term memory unit, a long term memory unit, or other suitable memory units or storage units. Memory 820 may be or may include a plurality of, possibly different, memory units. Memory 820 may store for example, instructions to carry out a method (e.g., code 825), and / or data such as user responses, interruptions, etc.

[00134] Executable code 825 may be any executable code, e.g., an application, a program, a process, task or script. Executable code 825 may be executed by controller 805 possibly under control of operating system 815. In some embodiments, more than one computing device 800 or components of device 800 may be used for multiple functions described herein. For the various modules and functions described herein, one or more computing devices 800 or components of computing device 800 may be used. Devices that include components similar or different to those included in computing device 800 may be used, and may be connected to a network and used as a system. One or more processor(s) 805 may be configured to carry out embodiments of the present invention by for example executing software or code. Storage 830 may be or may include, for example, a hard disk drive, a floppy disk drive, a Compact Disk (CD) drive, a CD-Recordable (CD-R) drive, a universal serial bus (USB) device or other suitable removable and / or fixed storage unit. In some embodiments, some of the components shown in Fig. 1 may be omitted.

[00135] Input devices 835 may be or may include a mouse, a keyboard, a touch screen or pad or any suitable input device. It will be recognized that any suitable number of input devices may be operatively connected to computing device 800 as shown by block 835. Output devices 840 may include one or more displays, speakers and / or any other suitable output devices. It will be recognized that any suitable number of output devices may be operatively connected to computing device 800 as shown by block 840. Any applicable input / output (I / O) devices may be connected to computing device 800, for example, a wired or wireless network interface card (NIC), a modem, printer or facsimile machine, a universal serial bus (USB) device or external hard drive may be included in input devices 835 and / or output devices 840.

[00136] Embodiments of the invention may include one or more article(s) (e.g., memory 820 or storage 830) such as a computer or processor non-transitory readable medium, or a computer or processor non-transitory storage medium, such as for example a memory, a disk drive, or a USB flash memory, encoding, including or storing instructions, e.g., computer-executable instructions, which, when executed by a processor or controller, carry out methods disclosed herein.

[00137] Reference is made to Fig. 9, which is a block diagram of an exemplary user equipment (UE) 900 which may be used with embodiments of the present invention.

[00138] UE 900 may include a radio interface 905. Radio interface 905 may include an antenna, a transceiver and / or any other suitable component to allow communication between UE 900 and a telecommunications network.

[00139] UE 900 may include a user identity module 910. User identity module 910 may store user-specific information such as the International Mobile Subscriber Identity (IMSI) and may be used for authentication and authorization on the telecommunications network.

[00140] UE 900 may include connectivity module 915. Connectivity module 915 may support various connectivity options, including cellular networks (e.g., 4G / LTE, 5G), Wi-Fi, Bluetooth, and NFC (Near Field Communication), allowing UE 900 to connect to other devices and telecommunications networks.

[00141] UE 900 may include a computing device 920 (e.g., such as computing device 800 described above with respect to Fig. 8). Computing device 920 may include components of computing device 800 (e.g., as described above with respect to Fig. 8). Computing device 920 may include at least one of a processor, an operating system, a memory, an executable code, a storage, input devices and / or output devices (e.g., as described above with respect to Fig. 8). In some embodiments, some of the components of computing device 800 may be omitted in computing device 920. Computing device 920 may manage operation of UE 900. For example, computing device 920 may perform operations for store and forward authentication of UE 900 to network 90 as described above with respect to Figs. 1, 2, 3 and 4.

[00142] UE 900 may include sensors 925. Sensors 925 may include accelerometers, gyroscopes, GPS, and ambient light sensors, cameras and / or any other suitable sensors known in the art. Sensors 925 may allow features such as orientation detection, location-based services, and any other suitable features known in the art.

[00143] UE 900 may include security components 930. Security components 930 may be responsible for ensuring the security and privacy of user data and communications. Security components 930 may include encryption / decryption hardware and software, as well as security features to protect against malware and unauthorized access.

[00144] UE 900 may include a battery 935. Battery 935 may provide power to UE 900, allowing it to operate without being connected to an external power source. UE 900 may include a charging port 940 for recharging battery 935.

[00145] In some embodiments, some of the components shown in Fig. 9 may be omitted. In some embodiments, UE 900 may include additional components in accordance with standards specifications (e.g., 3GPP specifications) that are not shown in Fig. 9.

[00146] Reference is now made to Fig. 10, which is a block diagram of an exemplary base station (BS) 1000 which may be used with embodiments of the present invention.

[00147] BS 1000 may include a radio transceiver 1005. Radio transceiver 1005 may transmit and receive radio signals.

[00148] BS 1000 may include an antenna system 1010. Antenna system 1010 may include one or more antennas that may transmit and receive signals via the air in specific directions and patterns. For example, antenna system 1010 may include advanced antenna technologies such as Multiple-Input Multiple-Output (MIMO) and beamforming that may improve network performance and coverage.

[00149] BS 1000 may include baseband processing unit 1015. Baseband processing unit 1015 may handle the baseband processing of communication signals. Baseband processing unit 1015 may perform tasks such as modulation / demodulation, encoding / decoding, error correction, and channel allocation.

[00150] BS 1000 may include a digital signal processing unit 1020. Digital signal processing unit 1020 may process and manipulate digital signals within baseband processing unit 1015. Digital signal processing unit 1020 may perform tasks such as signal processing, beamforming, interference cancellation, and MIMO processing.

[00151] BS 1000 may include a backhaul connection 1025. Backhaul connection 1025 may provide a high-capacity backhaul connection to connect BS 1000 to the core network. Backhaul connection 1025 may include wired connections such as optical fiber or microwave links.

[00152] BS 1000 may include a power supply unit 1030. Power supply unit 1030 may provide electrical power to BS’s 1000 components to ensure continuous operation.

[00153] BS 1000 may include a computing device 1035 (e.g., such as computing device 800 described above with respect to Fig. 8). Computing device 1035 may include components of computing device 800 (e.g., as described above with respect to Fig. 8). Computing device 1035 may include at least one of a processor, an operating system, a memory, an executable code, a storage, input devices and / or output devices (e.g., as described above with respect to Fig. 8). In some embodiments, some of the components of computing device 800 may be omitted in computing device 1035. Computing device 1035 may manage operation of BS 1000. Computing device 1035 may handle tasks such as network configuration, software updates, and fault management.

[00154] BS 1000 may include a cooling system 1040. Cooling system 1040 may fans, heat sinks, and / or liquid cooling systems that may maintain the equipment of BS 1000 within its operating temperature range.

[00155] BS 1000 may include a timing and synchronization unit 1045. Timing and synchronization unit 1045 may perform timing and synchronization for maintaining the integrity of the communication network, e.g., to ensure that all base stations in the network are synchronized with a common timing reference.

[00156] BS 1000 may include a security and encryption unit 1050. Security and encryption unit 1050 may perform tasks such as encryption of user data and authentication of UEs for protecting the network from unauthorized access and malicious attacks.

[00157] BS 1000 may include a fault detection and alarming unit 1055. Fault detection and alarming unit 1055 may monitoring equipment health and raising alarms in case of hardware or software issues are critical for maintaining network reliability and availability.

[00158] In some embodiments, some of the components shown in Fig. 10 may be omitted. In some embodiments, BS 1000 may include additional components in accordance with standards specifications (e.g., 3GPP specifications) that are not shown in Fig. 10.

[00159] Reference is now made to Fig. 11, which is a block diagram of an exemplary satellite 1100 which may be used with embodiments of the present invention.

[00160] Satellite 1100 may include transponders 1105. Transponders 1105 may receive signals from base stations and / or user equipment. Transponders 1105 may transmit signals to base stations and / or user equipment. Transponders 1105 may be configured for different frequency bands and services. Transponders 1105 may include modulation and demodulation equipment to encode and decode the transmitted data. Satellite 1100 may include antennas 1110 for receiving and transmitting signals.

[00161] Satellite 1100 may include a computing device 1115 (e.g., such as computing device 800 described above with respect to Fig. 8). Computing device 1115 may include components of computing device 800 (e.g., as described above with respect to Fig. 8). Computing device 1115 may include at least one of a processor, an operating system, a memory, an executable code, a storage, input devices and / or output devices (e.g., as described above with respect to Fig. 8). In some embodiments, some of the components of computing device 800 may be omitted in computing device 1115. Computing device 1115 may manage operation of satellite 1100. For example, computing device 1115 may maintain satellite's 1100 orbital position, attitude, and health. Computing device 1115 may handle adjustments to the satellite's 1100 transponders 1105, power levels, and other settings. Computing device 1115 may manage communication protocols, routing of signals, process and relay data efficiently between the uplink and downlink and other data-related functions.

[00162] Satellite 1100 may include a power system 1120. Powe system 1120 may, for example, include solar panels to generate electrical power from sunlight. This power may be stored in onboard batteries and used to operate the satellite's systems, including the communication payload (e.g., transponders 1105). Power system 1120 may include regulators and converters to ensure a stable power supply.

[00163] Satellite 1100 may include a base station (BS) 1125 (e.g., such as BS 1000 described above with respect to Fig. 10). BS 1125 may include components of BS 1000 as described above with respect to Fig. 10. In some embodiments, some of the components of BS 1000 may be omitted in BS 1125. For example, BS 1125 may be a base station of a NTN (e.g., as described above with respect to Figs. 1, 2, 3 and 4).

[00164] Satellite 1100 may include a core network authentication module 1130. Core network authentication module 1130 may perform at least a portion of operations of a core network for authentication of a UE (e.g., such as UE 110, 210) to a network. Core network authentication module 1130 (or its proxy) may perform operations for store and forward authentication of a UE (e.g., such as UE 110, 600) to network 90 (e.g., as described above with respect to Figs. 1, 2, 3 and 4). Satellite 1100 may include an authentication repository 1135. Authentication repository 1135 may store a list 1137 of ongoing authentication processes of UEs, a list 1139 of successfully completed authentication processes of UEs and / or any other suitable information related to authentication of UEs to a network. In various embodiments, core network authentication module 11303 and / or authentication repository 1135 may be included in BS 1125 of satellite 1100.

[00165] In some embodiments, satellite 1100 may act as relay of radio signals.

[00166] In some embodiments, some of the components shown in Fig. 11 may be omitted. In some embodiments, satellite 1100 may include additional components that are not shown in Fig. 11 and that may be required for supporting the communication of the satellite with base stations and / or user equipment.

[00167] One skilled in the art will realize the invention may be embodied in other specific forms without departing from the spirit or essential characteristics thereof. The foregoing embodiments are therefore to be considered in all respects illustrative rather than limiting of the invention described herein. Scope of the invention is thus indicated by the appended claims, rather than by the foregoing description, and all changes that come within the meaning and range of equivalency of the claims are therefore intended to be embraced therein.

[00168] In the foregoing detailed description, numerous specific details are set forth in order to provide an understanding of the invention. However, it will be understood by those skilled in the art that the invention can be practiced without these specific details. In other instances, well-known methods, procedures, and components, modules, units and / or circuits have not been described in detail so as not to obscure the invention. Some features or elements described with respect to one embodiment can be combined with features or elements described with respect to other embodiments.

[00169] Although embodiments of the invention are not limited in this regard, discussions utilizing terms such as, for example, “processing,” “computing,” “calculating,” “determining,” “establishing”, “analyzing”, “checking”, or the like, can refer to operation(s) and / or process(es) of a computer, a computing platform, a computing system, or other electronic computing device, that manipulates and / or transforms data represented as physical (e.g., electronic) quantities within the computer’s registers and / or memories into other data similarly represented as physical quantities within the computer’s registers and / or memories or other information non-transitory storage medium that can store instructions to perform operations and / or processes.

[00170] Although embodiments of the invention are not limited in this regard, the terms “plurality” and “a plurality” as used herein can include, for example, “multiple” or “two or more”. The terms “plurality” or “a plurality” can be used throughout the specification to describe two or more components, devices, elements, units, parameters, or the like. The term set when used herein can include one or more items. Unless explicitly stated, the method embodiments described herein are not constrained to a particular order or sequence. Additionally, some of the described method embodiments or elements thereof can occur or be performed simultaneously, at the same point in time, or concurrently.

Claims

1. A non-terrestrial network (NTN) for store and forward authentication of a user equipment (UE) to a network, the NTN comprising:one or more feeder links; anda plurality of satellites;wherein a first satellite of the plurality of satellites is configured to:receive, from the UE, an authentication request as part of an authentication process initiated by the UE, the authentication request comprising an authentication transaction code (ATAC), the ATAC comprising an identifier indicative of an identity of the UE and an identifier of the authentication process;calculate a wait time for the UE to wait since the initiation of the authentication process before initiating a new authentication process;transmit, to the UE, a notification indicating the wait time; andforward, via one of the one or more feeder links, the authentication request to a core network element of a core network; andwherein each satellite of the plurality of satellites is configured to receive, from the core network element via one of the one or more feeder links, an authentication response, the authentication response comprising the ATAC, and one of an authentication vector if the UE is authorized to access the network or an authentication rejection if the UE is not authorized to access the network.

2. The NTN of claim 1, wherein the wait time is smaller than a time in which the first satellite reappears and becomes visible to the UE.

3. The NTN of claim i, wherein a second satellite of the plurality of satellites is configured to:receive, from the UE, an authentication status request, the authentication status request comprising the ATAC; andbased on the ATAC, determine whether or not the authentication response for the authentication process of the UE has been received.

4. The NTN of claim 3, wherein upon determination that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network, the second satellite is configured to complete the authentication process of the UE using the authentication vector comprised in the authentication response.

5. The NTN of claim 3, wherein upon determination that at least one identifier comprised in the ATAC of the authentication status request is not identical to the corresponding at least one identifier comprised in the ATAC of the authentication response, the second satellite is configured to:reject the authentication process; andtransmit, to the UE, a notification that the authentication process is rejected.

6. The NTN of claim 4, wherein the second satellite is configured to transmit, to the core network element, via one of the one or more feeder links, a notification that the authentication process of the UE has been successfully completed, the notification comprising the ATAC.

7. The NTN of claim 6, wherein each of the plurality of satellites is configured to receive, from the core network element, via one of the one or more feeder links, the notification that the authentication process of the UE has been successfully completed.

8. The NTN of claim 3, wherein upon determination that the authentication response for the authentication process of the UE has been received but the UE is not authorized to access the network, the second satellite is configured to transmit, to the UE, the authentication rejection.

9. The NTN of claim 3, wherein upon determination that no authentication response for the authentication process of the UE has been received, the second satellite is configured to transmit, to the UE, a notification that the status the authentication request of the UE is unknown.

10. The NTN of claim 9, wherein the next satellite of the plurality of satellites that reaches the UE is configured to:receive, from the UE, the authentication status request;based on the AT AC comprised in the authentication status request, verify that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network; andupon verification, complete the authentication process of the UE using the authentication vector comprised in the authentication response.

11. The NTN ofclaim 1, wherein a second satellite of the plurality of satellites is configured to: receive, from the UE, an attach request, the attach request comprising the AT AC; and based on the AT AC comprised in the attach request, determine whether or not a notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites has been received.

12. The NTN of claim 11, wherein upon determination that the notification has been received, the second satellite is configured to:approve the attach request; andtransmit, to the UE, a notification that the attach request is approved.

13. The NTN of claim 11, wherein upon determination that the notification has not been received, the second satellite is configured to:reject the attach request; andtransmit, to the UE, a notification that the attach request is rejected.

14. The NTN of claim 13, wherein the second satellite is configured to:receive, from the UE, the attach request, the notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites, and user data;store the user data; andforward the user data and the AT AC to one of the one or more feeder links.

15. The NTN of claim 13, wherein the second satellite is configured to:receive, from the UE, the attach request and the notification that the authentication process of the UE has been successfully completed by one of the plurality of satellites;based on the AT AC included in the attach request, determine whether or not the authentication response for the authentication process of the UE has been received; andupon determination that the authentication response for the authentication process of the UE has been received and that the UE is authorized to access the network, complete the authentication process of the UE using the authentication vector comprised in the authentication response.

16. The NTN of any one of claims 1-15, wherein each of the satellites of the plurality of satellites comprises:a base station of the NTN;a core network authentication module; andan authentication repository comprising:a list of ongoing authentication processes of UEs; anda list of successfully completed authentication processes of UEs.

17. A user equipment (UE) for store and forward authentication to a network by a non-terrestrial network (NTN) comprising a plurality of satellites, the UE is configured to:initiate an authentication process by transmitting, to a first satellite of the plurality of satellites of the NTN, an authentication request, the authentication request comprising an authentication transaction code (ATAC), the ATAC comprising an identifier indicative of an identity of the UE and an identifier of the authentication process;receive, from the first satellite, a notification indicating a wait time for the UE to wait since the initiation of the authentication process with the first satellite before initiating a new authentication process;monitor a time that has elapsed since the initiation of the authentication process with the first satellite; andinitiate a new authentication process only if the authentication process is unsuccessful or the time that has elapsed since the initiation of the authentication process with the first satellite exceeds the wait time.

18. The UE of claim 17, wherein the UE is configured to:transmit, to a second satellite of the plurality of satellites of the NTN, an authentication status request, the authentication status request comprising the ATAC;receive, from the second satellite, a notification that the status of the authentication process of the UE is unknown; andupon determination that the wait time since the initiation of the authentication process with the first satellite has not elapsed, transmit the authentication status request to the next satellite of the plurality of satellites when the satellite reaches the UE.

19. The UE of claim 17, wherein the UE is configured to:transmit, to a second satellite of the plurality of satellites of the NTN, an authentication status request, the authentication status request comprising the ATAC;receive, from the second satellite, an authentication vector; andcomplete the authentication process with the second satellite using the authentication vector.

20. The UE of claim 17, wherein the UE is configured to:transmit, to a second satellite of the plurality of satellites of the NTN, an attach request, the attach request comprising the ATAC; andreceive, from the second satellite, a notification that the attach request is rejected.

21. The UE of claim 20, wherein the UE is configured to:retransmit, to the second satellite, the attach request, a notification that the authentication process of the UE has been successfully completed with one of satellites of the NTN, and user data.

22. The UE of claim 20, wherein the UE is configured to:retransmit, to the second satellite, the attach request and a notification that the authentication process of the UE has been successfully completed with one of satellites of the NTN;receive, from the second satellite, an authentication vector; andcomplete the authentication process with the second satellite using the authentication vector.

23. A core network element for store and forward authentication of a user equipment (UE) to a network by a non-network network (NTN) comprising a plurality of satellites, the core network element is configured to:receive, from a first satellite of the plurality of satellites of the NTN, via one of one or more feeder links of the NTN, an authentication request received by the first satellite from the UE as part of an authentication process initiated by the UE, the authentication request comprising an authentication transaction code (ATAC), the ATAC comprising an identifier indicative of an identity of the UE and an identifier of the authentication process; andgenerate an authentication response, the authentication response comprising the ATAC, and one of an authentication vector if the UE is authorized to access the network or an authentication rejection if the UE is not authorized to access the network; andtransmit the authentication response to at least one satellite of the plurality of satellites of the NTN via at least one of the one or more feeder links of the NTN.

24. The core network element of claim 23, wherein if the UE is authorized to access the network, the core network element is configured to transmit the authentication response to all satellites of the plurality of satellites of the NTN via at least one of the one or more feeder links of the NTN.

25. The core network element of claim 23, wherein if the UE is not authorized to access the network, the core network element is configured to transmit the authentication response only to one satellite of the plurality of satellites of the NTN via one of the one or more feeder links of the NTN, said satellite being the first satellite or the next satellite of the plurality of satellites to become visible to the UE.