5G Non-seamless Wireless Local Area Network Offload
Patent Information
- Application Number
- JP2024502147
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-04
- Filing Date
- 2022-08-05
- Publication Date
- 2025-08-04
AI Technical Summary
Existing 4G non-seamless wireless local area network (WLAN) offloading protocols expose user equipment (UE) identifiers in clear text, making them vulnerable to interception and misuse, leading to unauthorized tracking and network attacks.
Implementing 5G NR communication systems with enhanced security features, using 5G core network capabilities to encrypt UE identifiers as Subscription Concealed Identifiers (SUCI) in Network Access Identifier (NAI) format for secure authentication on non-3GPP access networks.
Enhances security by encrypting UE identifiers, preventing unauthorized access and misuse, thus improving the integrity and efficiency of wireless communications.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] Related Applications This application claims the benefit of priority to U.S. Provisional Application No. 63 / 230,784, entitled "5G Non-Seamless Wireless Local Area Network Offload," filed August 8, 2021, the entire contents of which are incorporated herein by reference for all purposes. [Background technology]
[0002] Non-seamless Wireless Local Area Network (WLAN) Offload (NSWO) enables authentication of a User Equipment (UE) by its home network for access to another access network, such as a Wi-Fi network. In an NSWO procedure for a fourth generation (4G) communication system, the UE transmits a UE identifier in an unencrypted form (i.e., in the clear) to the access network over a wireless communication link. If subscriber identity privacy is not provided during the authentication procedure, the UE may be vulnerable to capture and misuse of the UE identifier (e.g., by an "IMSI catcher"), which may enable unauthorized tracking of UE activity or misuse of the UE identifier for attacks or other malicious activity against the network. Summary of the Invention
[0003] Various aspects include systems and methods for performing authentication of a user equipment (UE) using non-seamless wireless local area network (WLAN) offload (NSWO) facilitated by network elements and functions of a 5G NR (fifth generation new radio) communication system. Various aspects may include a system for performing authentication of a user equipment (UE), the system including: a non-3GPP access network; a UE including a processor configured with processor-executable instructions for obtaining a Mobile Subscriber Identity (MSIN) from an International Mobile Subscriber Identity (IMSI) of the UE, encrypting the MSIN to generate a Subscription Masking Identifier (SUCI) in a Network Access Identifier (NAI) format, and transmitting the SUCI to the non-3GPP access network for authentication of the UE; and a network element of a home 3GPP network including a processor configured with processor-executable instructions for receiving, by a 5G non-seamless WLAN offload (NSWO) function, an authentication request including the SUCI from the non-3GPP access network, determining, by the 5G NSWO function based on the SUCI, that the UE should be authenticated by an authentication function of the home 3GPP network, and providing the authentication request including the SUCI to an authentication function of the home 3GPP network for processing based on a determination by the authentication function that the UE should be authenticated.
[0004] In some aspects, the processor of the UE may be further configured to receive an identity request from the non-3GPP access network and, in response to the identity request, determine whether the UE is configured to perform 5G NSWO based on an indicator stored in the UE. In some aspects, the processor of the network element of the home 3GPP network may be further configured to determine, by the 5G NSWO function, whether the SUCI is in an NAI format. In some aspects, the authentication function may process the authentication request including the SUCI in response to determining that the SUCI is in an NAI format. In some aspects, the authentication function may include an authentication server function (AUSF).
[0005] In some aspects, the non-3GPP access network may be further configured to establish a communication link with the UE and, in response to establishing the communication link with the UE, send an identity request to the UE. In some aspects, the processor of the network element of the home 3GPP network may be further configured to receive, by a 5G NSWO function, from the authentication function an authentication response based on processing the authentication request including the SUCI, and, in response to receiving the authentication response from the authentication function, send, by the 5G NSWO function, an authentication challenge to the non-3GPP access network.
[0006] In some aspects, the processor of the UE may be further configured to receive an authentication challenge from the non-3GPP access network, generate an authentication response in response to the authentication challenge, and transmit the authentication response to the non-3GPP access network. In some aspects, the processor of the UE may be further configured to generate the key using an arbitrary value for a serving network name of the non-3GPP access network.
[0007] In some aspects, the processor of the network element of the home 3GPP network may be further configured to receive, via a 5G NSWO function, from the UE via the non-3GPP access network, an authentication response in response to the authentication challenge, provide the authentication response to an authentication function of the home 3GPP network, and receive, via the 5G NSWO function, from the authentication function of the home 3GPP network, a Master Session Key (MSK) in response to the authentication response. In some aspects, the processor of the network element of the home 3GPP network may be further configured to send the MSK to the non-3GPP access network to authenticate the UE for access to the non-3GPP access network. In some aspects, the MSK may be derived using any value for a serving network name of the non-3GPP access network.
[0008] Various aspects include a method for performing authentication of a UE for 5G network authentication to support 5G non-seamless WLAN offload over a non-3GPP access network (5G NSWO). Various aspects may include obtaining, by a processor of the UE, a Mobile Subscriber Identity (MSIN) from an International Mobile Subscriber Identity (IMSI) of the UE; encrypting, by a processor of the UE, the MSIN to generate a Subscription Unmasking Identifier (SUCI) in a Network Access Identifier (NAI) format; sending, by a processor of the UE, the SUCI to the non-3GPP access network for authentication of the UE; receiving, by a 5G NSWO function of a network element of the home 3GPP network, an authentication request including the SUCI from the non-3GPP access network; determining, by the 5G NSWO function, based on the SUCI, that the UE should be authenticated by an authentication function of the home 3GPP network; providing, based on a determination by the authentication function that the UE should be authenticated, an authentication request including the SUCI to an authentication function of the home 3GPP network for processing; and completing authentication of the UE in accordance with an Extensible Authentication Protocol (EAP) protocol.
[0009] In some aspects, determining, by the 5G NSWO function, based on the SUCI that the UE should be authenticated by an authentication function of the home 3GPP network may include determining, by the 5G NSWO function, that the SUCI is in an NAI format. Some aspects may include processing, by the authentication function, an authentication request including the SUCI in response to determining that the SUCI is in the NAI format. In some aspects, the authentication function may include an authentication server function (AUSF).
[0010] Various aspects include a method performed by a processor of a user equipment (UE) for 5G network authentication to support 5G non-seamless WLAN offload (NSWO). Various aspects may include obtaining a Mobile Subscriber Identity (MSIN) from an International Mobile Subscriber Identity (IMSI) of the UE, encrypting the MSIN to generate a Subscription Masking Identifier (SUCI) in a Network Access Identifier (NAI) format, and transmitting the SUCI to a network element of the non-3GPP access network for authentication of the UE by a home 3GPP network for access to the non-3GPP access network.
[0011] Some aspects may include checking a Universal Subscriber Identity Module (USIM) or Mobile Equipment (ME) configuration for an indication that the UE should use the 5G NSWO, where encrypting the MSIN to generate an SUCI in an NAI format and sending the SUCI to a network element of the non-3GPP access network for authentication of the UE by the home 3GPP network for access to the non-3GPP access network are performed in response to the USIM or ME configuration indicating that the UE should use the 5G NSWO. In some aspects, obtaining the MSIN from the UE's IMSI may include obtaining, by an ME function of the UE, the encrypted MSIN from the UE's USIM and generating, by the ME, the SUCI in the NAI format using the encrypted MSIN. Some aspects may include receiving an Extensible Authentication Protocol and Key Agreement Prime (EAP-AKA') challenge from a network element of the non-3GPP access network, computing an EAP response via an authentication and key agreement (AKA) algorithm, deriving one or more keys using an optional value for a serving network name of the non-3GPP access network, sending the EAP response to the network element of the non-3GPP access network, receiving an EAP success from the network element of the non-3GPP access network, and initiating communication on the non-3GPP access network via the network element of the non-3GPP access network in response to receiving the EAP success.
[0012] Various aspects include systems and methods for performing authentication to support 5G non-seamless NSWO on a non-3GPP access network. Various aspects may include checking, by a processor of the UE, a USIM or ME configuration for an indication that the UE should use 5G NSWO, generating, by the processor of the UE, a SUCI in an NAI format in response to the USIM or ME configuration indicating that the UE should use 5G NSWO, and transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE.
[0013] In some aspects, transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE may include receiving, by the UE, an identity request from the non-3GPP access network, where transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE is performed in response to the identity request from the non-3GPP access network.
[0014] In some aspects, generating, by the processor of the UE, the NAI-formatted SUCI may include encrypting, by the processor of the UE, an MSIN obtained from the IMSI of the UE and including the encrypted MSIN in the SUCI. In some aspects, generating, by the processor of the UE, the NAI-formatted SUCI may include obtaining, by an ME function of the UE, an encrypted MSIN from a USIM of the UE, where the ME function uses the encrypted MSIN to generate the NAI-formatted SUCI.
[0015] In some aspects, to generate the NAI-formatted SUCI, the processor of the UE can encrypt a username portion of the NAI and incorporate the encrypted username portion into the SUCI. In some aspects, the NAI-formatted SUCI can include an indication of whether the SUCI is derived from the UE's IMSI or the NAI. In some aspects, generating the NAI-formatted SUCI by the processor of the UE can include converting digits of the UE's IMSI to a domain name.
[0016] Some aspects may include receiving an Extensible Authentication Protocol and Key Agreement Prime (EAP-AKA') challenge from a network element of the non-3GPP access network, deriving one or more keys using an arbitrary value for a serving network name of the non-3GPP access network, sending an EAP response to the network element of the non-3GPP access network, and initiating communication over the non-3GPP access network via the network element of the non-3GPP access network using the one or more derived keys. In some aspects, initiating communication over the non-3GPP access network via the network element of the non-3GPP access network may include receiving an EAP success from the network element of the non-3GPP access network, and initiating communication over the non-3GPP access network via the network element of the non-3GPP access network in response to receiving the EAP success.
[0017] Further aspects may include a UE or network element having a processor configured to perform one or more operations of any of the methods summarized above. Further aspects may include a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of a wireless device or UE or network element to perform operations of any of the methods summarized above. Further aspects include a UE or network element having means for performing functions of any of the methods summarized above. Further aspects include a system-on-chip for use in a UE or network element including a processor configured to perform one or more operations of any of the methods summarized above. [Brief description of the drawings]
[0018] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate exemplary embodiments of the claims and, together with the general description given above and the detailed description below, serve to explain the features of the claims. [Figure 1A] FIG. 1 is a system block diagram illustrating an exemplary communication system suitable for implementing any of the various embodiments. [Figure 1B] FIG. 1 is a system block diagram illustrating an exemplary split base station architecture suitable for implementing various embodiments. [Diagram 2] FIG. 1 is a component block diagram illustrating an exemplary computing and wireless modem system suitable for implementing any of the various embodiments. [Diagram 3] FIG. 2 is a component block diagram illustrating a software architecture including radio protocol stacks for user and control planes in wireless communications suitable for implementing any of the various embodiments. [Figure 4-1] FIG. 4 is a message flow diagram illustrating a method for performing authentication of a user equipment according to various embodiments. [Figure 4-2] FIG. 4 is a message flow diagram illustrating a method for performing authentication of a user equipment according to various embodiments. [Figure 5A] FIG. 1 is a method flow diagram illustrating a method for performing authentication of a user equipment, according to various embodiments. [Figure 5B] FIG. 1 is a method flow diagram illustrating a method for performing authentication of a user equipment, according to various embodiments. [Figure 6A] FIG. 11 is a process flow diagram illustrating a method that may be performed by a processor of a UE for 5G network authentication to support 5G NSWO, according to various embodiments. [Figure 6B] FIG. 11 is a process flow diagram illustrating a method that may be performed by a processor of a UE for 5G network authentication to support 5G NSWO, according to various embodiments. [Figure 7] FIG. 1 is a component block diagram of a networked computing device suitable for use in the various embodiments. [Figure 8] FIG. 1 is a component block diagram of a wireless device suitable for use in the various embodiments. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0019] Various embodiments will now be described in detail with reference to the accompanying drawings. Whenever possible, the same reference numbers will be used throughout the drawings to refer to the same or like parts. References made to specific examples and embodiments are for illustrative purposes only and are not intended to limit the scope of the claims.
[0020] Various embodiments include systems and methods for performing non-seamless wireless local area network (WLAN) offload (NSWO) authentication for a UE attempting to access a non-3GPP access network (e.g., an Institute of Electrical and Electronics Engineers (IEEE) 802.11 WLAN access network). Various embodiments can improve the efficiency and accuracy of wireless communications between wireless devices and communications networks by providing enhanced security features provided by 5G systems to NSWO communications.
[0021] The term "wireless device" is used herein to refer to any one or all of the following: wireless router devices, wireless appliances, cellular telephones, smartphones, portable computing devices, personal or mobile multimedia players, laptop computers, tablet computers, smartbooks, ultrabooks, palmtop computers, wireless email receivers, multimedia Internet-enabled cellular telephones, medical devices and equipment, biometric sensors / devices, wearable devices including smart watches, smart clothing, smart glasses, smart wristbands, and smart jewelry (e.g., smart rings, smart bracelets, etc.), entertainment devices (e.g., wireless game controllers, music and video players, satellite radio, etc.), wireless network-enabled Internet of Things (IoT) devices including smart meters / sensors, industrial manufacturing equipment, and large and small machines and appliances for home and business use, wireless communication elements in autonomous and semi-autonomous vehicles, wireless devices fixed or embedded in various mobile platforms, global positioning system devices, and similar electronic devices including memory, wireless communication components, and programmable processors.
[0022] The term "system on chip" (SOC) is used herein to refer to a single integrated circuit (IC) chip that includes multiple resources and / or processors integrated on a single substrate. A single SOC may include circuits for digital, analog, mixed signal, and radio frequency functions. A single SOC may also include any number of general purpose and / or special purpose processors (such as digital signal processors, modem processors, video processors, etc.), memory blocks (e.g., ROM, RAM, Flash, etc.), and resources (e.g., timers, voltage regulators, oscillators, etc.). A SOC may also include software for controlling the integrated resources and processors and for controlling peripheral devices.
[0023] The term "system in package" (SIP) may be used herein to refer to a single module or package that includes multiple resources, computing units, cores, and / or processors on two or more IC chips, substrates, or SOCs. For example, a SIP may include a single substrate on which multiple IC chips or semiconductor dies are stacked in a vertical configuration. Similarly, a SIP may include one or more multi-chip modules (MCMs) on which multiple ICs or semiconductor dies are packaged in a unified substrate. A SIP may also include multiple independent SOCs that are coupled together via high-speed communication circuits and packaged in close proximity, such as on a single motherboard or in a single wireless device. The proximity of the SOCs facilitates high-speed communication and sharing of memory and resources.
[0024] As used herein, the terms "network," "system," "wireless network," "cellular network," and "wireless communications network" may interchangeably refer to a portion or all of a wireless network of a carrier associated with a wireless device and / or a subscription on a wireless device. The techniques described herein may be used in connection with various wireless communications networks, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), FDMA, Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA), and other networks. In general, any number of wireless networks may be deployed within a given geographic area. Each wireless network may support at least one radio access technology capable of operating on one or more frequencies or frequency ranges. For example, a CDMA network may implement Universal Terrestrial Radio Access (UTRA) (including the Wideband Code Division Multiple Access (WCDMA) standard), CDMA2000 (including the IS-2000, IS-95, and / or IS-856 standards), and the like. In another example, the TDMA network may implement Enhanced Data Rates for GSM Evolution (EDGE). In another example, the OFDMA network may implement Evolved UTRA (E-UTRA) (including the LTE standard), Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash OFDM, etc. Reference may be made to wireless networks using the LTE standard, and thus the terms "Evolved Universal Terrestrial Radio Access," "E-UTRAN," and "eNodeB" may also be used interchangeably herein to refer to wireless networks. However, such references are provided merely as examples and are not intended to exclude wireless networks using other communication standards.For example, although various third generation (3G), fourth generation (4G), and fifth generation (5G) systems are described herein, these systems are mentioned by way of example only and, in various embodiments, may be replaced by future generation systems (e.g., sixth generation (6G) or higher systems).
[0025] Most UEs require authentication to access a communication network. NSWO, using 4G protocols, enables authentication of a UE attempting to connect to a non-3GPP access network (e.g., WLAN) via network elements, capabilities, and credentials provided by the UE's home network, such as a cellular network employing 3rd Generation Partnership Project (3GPP®) protocols and systems.
[0026] One issue with current NSWO using 4G protocols is that the UE's identity is transmitted in the clear, resulting in a risk that the UE's identity may be intercepted and used for unauthorized purposes. Providing network access to unauthorized UEs may allow unauthorized UEs to misuse network access via NSWO. For example, unauthorized UEs accessing an enterprise WLAN without authentication may consume WLAN resources and reduce the availability of NSWO for legitimate UEs (e.g., through a distributed denial of service (DDoS) attack). 5G communication systems and protocols provide higher security by providing communication of UE identities in a confidential (or encrypted) format. The deployment and use of NSWO using 5G NR communication networks will enable the use of such enhanced security capabilities of 5G systems using NSWO.
[0027] Various embodiments include systems and methods that enable the deployment and use of NSWO (sometimes referred to herein as "5G NSWO") using 5G NR communication networks. Various embodiments leverage the enhanced security capabilities of 5G protocols by performing the NSWO authentication procedure supported by elements of the 5G core network using credentials provided by functions of the 5G core network, such as a Unified Data Management (UDM) function, an Authentication Credentials Repository and Processing Function (ARPF), and a Subscriber Identifier Deciphering Function (SIDF). Various embodiments provide a 5G NSWO process with enhanced UE identity security by avoiding sending an unencrypted form (i.e., in the clear) of the UE identity (e.g., a Subscription Permanent Identifier (SUPI) or an International Mobile Subscriber Identity (IMSI)). Although the UE can be provisioned to use an authentication protocol such as an Extensible Authentication Protocol (e.g., Extensible Authentication Protocol and Key Agreement Prime (EAP-AKA'), the UE and network elements or network functions must be adapted to implement NSWO for the 5G communication system.
[0028] In various embodiments, the UE may be configured by a home network operator to use 5G NSWO to offload traffic to a non-3GPP access network, such as a WLAN. The UE may establish a communication link with an access point of the non-3GPP access network (e.g., a WLAN network employing Wi-Fi or another suitable wireless communication protocol) via a WLAN access point or another suitable device. As part of establishing such communication, the access point of the non-3GPP access network may transmit an identity request to the UE. At any time prior to receiving the identity request, or in response to receiving the identity request, the UE may determine whether it is configured to perform (use, perform operations of, etc.) 5G NSWO with respect to authentication to access the non-3GPP access network. In some embodiments, the UE may check (determine, obtain) a Universal Subscriber Identity Module (USIM) or Mobile Equipment (ME) setting for an indication of whether the UE should use 5G NSWO. In response to determining that the UE is configured to use 5G NSWO for authentication, the UE may generate a subscription masking identifier (SUCI) in a network access identifier (NAI) format (i.e., a masked version of the SUPI).
[0029] The SUPI may be configured as a SUPI type, such as SUPI type 0 for an International Mobile Subscriber Identity (IMSI) type, or SUPI type 1 for an NAI type. If the SUPI configured on the UE is an IMSI type identifier, the UE may obtain a Mobile Subscriber Identity (MSIN) from the UE's IMSI. In some embodiments, the UE may encrypt the MSIN to generate a SUCI in an NAI format. In some implementations, the SUPI may include a 15-digit decimal string with the first three digits representing an Operational Region Code (MCC) and the next two or three digits representing a Telecommunication Carrier Identity Code (MNC) that identifies the network operator. In some embodiments, using the encrypted MSIN, a mobile equipment (ME) function of the UE may derive a SUCI in an NAI format (e.g., username@realm format) by incorporating the encrypted MSIN into the username portion of the NAI and incorporating the MCC and MNC values of the IMSI into the realm portion of the NAI.
[0030] If the SUPI configured on the UE is an NAI type identifier, the UE may encrypt the username portion of the NAI and incorporate the encrypted username into the username portion of the SUCI to form an NAI-formatted SUCI. In some embodiments, either the ME or the USIM may perform the encryption of the MSIN or username using procedures defined in 3GPP Technical Specification (TS) 33.501.
[0031] The UE may send the SUCI in the derived NAI format to a network element of the non-3GPP access network for authentication of the UE by the home 3GPP network for access to the non-3GPP access network. In some embodiments, the SUCI in the NAI format may incorporate a type of SUPI to indicate whether the SUCI is derived from an IMSI or an NAI.
[0032] One or more network elements of the non-3GPP access network may send an access request (which may be or may include a request to authenticate the UE) associated with the UE to a home 3GPP network (e.g., a 5G NR communication network) of the UE via a standard 3GPP communication network. In some embodiments, the non-3GPP access network may send an authentication, authorization, and accounting (AAA) request to the home 3GPP network with a username set to the SUCI in NAI format. A network element of the home 3GPP network may receive the access (authentication) request including the SUCI from the non-3GPP access network. In some embodiments, a 5G NSWO function implemented in a network element of the home 3GPP network may receive the authentication request. In some embodiments, the 5G NSWO function may be implemented in a new network element or in an enhanced or upgraded 3GPP AAA server in an existing 4G network. In some embodiments, the 5G NSWO function may determine based on the SUCI that the UE should be authenticated using a 5G NSWO procedure (e.g., rather than a 4G NSWO procedure) and may forward the authentication request to an authentication function in the 5G core network, such as an authentication server function (AUSF). For example, the 5G NSWO function of the home 3GPP network may determine that the NAI is a 5G SUCI. In response to determining that the NAI is a 5G SUCI, a network element of the home 3GPP network may provide an authentication request including the SUCI to an authentication function of the home 3GPP network implemented in the network element of the home 3GPP network. In some embodiments, the 5G NSWO network function may set the serving network name to an arbitrary string value (e.g., "5G:NSWO") to indicate that the authentication request is for 5G NSWO over a non-3GPP access network, such as a WLAN access network.
[0033] In some embodiments, an authentication function (e.g., AUSF) of the home 3GPP network of the 5G NSWO function can send the SUCI in an authentication acquisition request to a repository (e.g., UDM / ARPF / SIDF) of UE secure identifiers and credentials to receive authentication information that the authentication function (e.g., AUSF) can use to generate an authentication challenge message according to an EAP-AKA' protocol or the like. The UDM / ARPF / SIDF can use the SUPI to decipher the SUCI into a SUPI and select EAP-AKA' as the authentication protocol. The authentication function (e.g., AUSF) can send an authentication challenge message to the non-3GPP access network, such as via the 5G NSWO function, and the non-3GPP access network can send the authentication challenge to the UE. Upon receiving the authentication challenge from the non-3GPP access network, the UE can generate an authentication response to the authentication challenge, such as according to an EAP-AKA' protocol, and send the authentication response to the non-3GPP access network. The 5G NSWO function can receive the authentication response from the UE via the non-3GPP access network. The 5G NSWO function may provide an authentication response to an authentication function (e.g., AUSF) of the home 3GPP home network. The authentication function (e.g., AUSF) of the home 3GPP network may verify the UE authentication response. In response to verifying the UE authentication response, the authentication function may generate a Master Session Key (MSK) and send the MSK to the 5G NSWO function. The AUSF may include a SUPI (e.g., IMSI or NAI based on the type of SUPI) as identification information for key derivation of the MK (master key). The MSK (master session key) derivation may also include an arbitrary value for the serving network name. The 5G NSWO function may send the MSK to the non-3GPP access network to authenticate the UE for access to the non-3GPP access network.In response, a message (e.g., an EAP success message) may be sent to the UE indicating that the authentication was successful or that the UE is authenticated and may begin 5G NSWO communications.
[0034] In some embodiments, the UE may use any value for the serving network name to derive (e.g., determine or calculate) the key. In some embodiments, the actual serving network name (i.e., serving network identifier or non-3GPP access network identifier) may be unavailable to the UE and / or the home 3GPP network (e.g., to an authentication function of the home 3GPP network). In some embodiments, the authentication function (e.g., AUSF) may use any value for the serving network name of the non-3GPP access network to derive (determine, calculate) the MSK.
[0035] Various embodiments improve the operation of a communications network by enabling NSWO operations with elements of a 5G communications system to authenticate a UE for access to a non-3GPP access network. Various embodiments improve the operation of a UE by providing an efficient process for authenticating the UE to a non-3GPP access network using credentials and authentication processes provided by the home 3GPP network.
[0036] FIG. 1 is a system block diagram illustrating an exemplary communication system 100 suitable for implementing any of the various embodiments. The communication system 100 may be a 5G New Radio (NR) network or any other suitable network, such as a Long Term Evolution (LTE) network. Although FIG. 1 illustrates a 5G network, later generation networks may include the same or similar elements. Therefore, references to 5G networks and 5G network elements in the following description are for illustrative purposes and are not intended to be limiting.
[0037] The communication system 100 may include a heterogeneous network architecture including a core network 140 and various mobile devices (shown in FIG. 1 as wireless devices 120a-120e). The communication system 100 may also include several base stations (shown as BS 110a, BS 110b, BS 110c, and BS 110d) and other network entities. A base station is an entity that communicates with wireless devices (mobile devices) and may also be referred to as a Node B, an LTE evolved Node B (eNode B, or eNB), an access point (AP), a radio head, a transmit / receive point (TRP), a new radio base station (NR BS), a 5G Node B (NB), a next generation Node B (gNode B, or gNB), etc. Each base station may provide communication coverage for a particular geographic area. In 3GPP, the term "cell" may refer to a coverage area of a base station, a base station subsystem serving this coverage area, or a combination thereof, depending on the context in which the term is used. The core network 140 may be any type of core network, such as an LTE core network (e.g., an EPC network), a 5G core network, etc.
[0038] Communications system 100 may include a non-3GPP access network 150. Elements of core network 140 and non-3GPP access network 150 may communicate via communications link 152. Non-3GPP access network 150 may include one or more access points 154 that facilitate wireless communications with wireless devices (e.g., 120d) via communications link 156. In some embodiments, core network 140 may function as a home 3GPP network to, among other things, provide authentication functionality for wireless device access to non-3GPP access network 150, as described further below.
[0039] The base stations 110a-110d may provide communication coverage for a macro cell, a pico cell, a femto cell, another type of cell, or a combination thereof. A macro cell may cover a relatively large geographic area (e.g., a few kilometers in radius) and may allow unrestricted access by mobile devices with service subscriptions. A pico cell may cover a relatively small geographic area and may allow unrestricted access by mobile devices with service subscriptions. A femto cell may cover a relatively small geographic area (e.g., a home) and may allow restricted access by mobile devices associated with the femto cell (e.g., mobile devices in a Closed Subscriber Group (CSG)). A base station for a macro cell may be referred to as a Macro BS. A base station for a pico cell may be referred to as a Pico BS. A base station for a femto cell may be referred to as a Femto BS or a Home BS. In the embodiment shown in Figure 1, base station 110a may be a macro BS for macro cell 102a, base station 110b may be a pico BS for pico cell 102b, and base station 110c may be a femto BS for femto cell 102c. Base stations 110a-110d may support one or more (e.g., three) cells. The terms "eNB", "base station", "NR BS", "gNB", "TRP", "AP", "Node B", "5G NB", and "cell" may be used interchangeably herein.
[0040] In some embodiments, the cells may not be stationary and the geographic area of the cells may move according to the location of the mobile base station. In some embodiments, the base stations 110a-110d may be interconnected to each other and to one or more other base stations or network nodes (not shown) within the communication system 100 through various types of backhaul interfaces, such as direct physical connections, virtual networks, or combinations thereof, using any suitable transport network.
[0041] The base stations 110a-110d may communicate with the core network 140 via wired or wireless communication links 126. The wireless devices 120a-120e may communicate with the base stations 110a-110d via wireless communication links 122.
[0042] The wired communication link 126 may use a variety of wired networks (e.g., Ethernet, TV cable, telephony, optical fiber, and other forms of physical network connections) that may use one or more wired communication protocols, such as Ethernet, Point-to-Point Protocol, High-Level Data Link Control (HDLC), Advanced Data Communications Control Protocol (ADCCP), and Transmission Control Protocol / Internet Protocol (TCP / IP).
[0043] The communication system 100 may also include a relay station (e.g., relay BS 110d). A relay station is an entity capable of receiving a transmission of data from an upstream station (e.g., a base station or a mobile device) and transmitting a transmission of data to a downstream station (e.g., a wireless device or a base station). A relay station may also be a mobile device capable of relaying a transmission for another wireless device. In the embodiment shown in FIG. 1, the relay station 110d may communicate with the macro base station 110a and the wireless device 120d to facilitate communication between the base station 110a and the wireless device 120d. A relay station may also be referred to as a relay base station, a relay base station, a repeater, etc.
[0044] The communications system 100 may be a heterogeneous network including different types of base stations, e.g., macro base stations, pico base stations, femto base stations, relay base stations, etc. These different types of base stations may have different transmit power levels, different coverage areas, and different impacts on interference within the communications system 100. For example, macro base stations may have high transmit power levels (e.g., 5-40 watts), while pico base stations, femto base stations, and relay base stations may have lower transmit power levels (e.g., 0.1-2 watts).
[0045] A network controller 130 may be coupled to a set of base stations and may provide coordination and control for these base stations. Network controller 130 may communicate with the base stations via a backhaul. The base stations may also communicate with each other, e.g., directly or indirectly, via wireless or wired backhaul.
[0046] The wireless devices 120a, 120b, 120c may be dispersed throughout the communication system 100, and each wireless device may be fixed or mobile. The wireless devices may also be referred to as access terminals, terminals, mobile stations, subscriber units, stations, user equipment (UE), etc.
[0047] The macro base station 110a may communicate with the communications network 140 via a wired or wireless communications link 126. The wireless devices 120a, 120b, 120c may communicate with the base stations 110a-110d via wireless communications links 122.
[0048] The wireless communication links 122, 124, and 156 may include multiple carrier signals, frequencies, or frequency bands, each of which may include multiple logical channels. The wireless communication links 122 and 124 may utilize one or more radio access technologies (RATs). Examples of RATs that may be used in the wireless communication links include 3GPP LTE, 3G, 4G, 5G (e.g., NR), GSM, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Worldwide Interoperable Microwave Access (WiMAX), Time Division Multiple Access (TDMA), and other mobile telephony technology cellular RATs. Further examples of RATs that may be used in one or more of the various wireless communication links in the communication system 100 include medium-range protocols such as Wi-Fi, LTE-U, LTE-Direct, LAA, MuLTEfire, and relatively short-range RATs such as ZigBee, Bluetooth, and Bluetooth Low Energy (LE).
[0049] Certain wireless networks (e.g., LTE) utilize orthogonal frequency division multiplexing (OFDM) on the downlink and single-carrier frequency division multiplexing (SC-FDM) on the uplink. OFDM and SC-FDM partition the system bandwidth into multiple (K) orthogonal subcarriers, also commonly referred to as tones, bins, etc. Each subcarrier may be modulated with data. In general, modulation symbols are sent in the frequency domain with OFDM and in the time domain with SC-FDM. The spacing between adjacent subcarriers may be fixed, and the total number of subcarriers (K) may be dependent on the system bandwidth. For example, the subcarrier spacing may be 15 kHz, and the minimum resource allocation (called a "resource block") may be 12 subcarriers (or 180 kHz). Thus, the nominal fast file transfer (FFT) size may be equal to 128, 256, 512, 1024, or 2048 for a system bandwidth of 1.25, 2.5, 5, 10, or 20 megahertz (MHz), respectively. The system bandwidth may also be partitioned into subbands. For example, a subband may cover 1.08 MHz (i.e., 6 resource blocks), and there may be 1, 2, 4, 8, or 16 subbands for a system bandwidth of 1.25, 2.5, 5, 10, or 20 MHz, respectively.
[0050] Although the description of some embodiments may use terminology and examples associated with LTE technology, various embodiments may be applicable to other wireless communication systems, such as New Radio (NR) or 5G networks. NR may utilize OFDM with cyclic prefix (CP) on the uplink (UL) and downlink (DL) and may include support for half-duplex operation using time division duplex (TDD). A single component carrier bandwidth of 100 MHz may be supported. An NR resource block may span 12 subcarriers with a subcarrier bandwidth of 75 kHz over a duration of 0.1 milliseconds (ms). Each radio frame may consist of 50 subframes having a length of 10 ms. Thus, each subframe may have a length of 0.2 ms. Each subframe may indicate a link direction (i.e., DL or UL) for data transmission, and the link direction for each subframe may be dynamically switched. Each subframe may include DL / UL data as well as DL / UL control data. Beamforming may be supported, and the beam direction may be dynamically configured. Multiple-input multiple-output (MIMO) transmission using precoding may also be supported. MIMO configurations in the DL may support up to eight transmit antennas using multi-layer DL transmission with up to eight streams and up to two streams per wireless device. Multi-layer transmission using up to two streams per wireless device may be supported. Multiple cell aggregation may be supported using up to eight serving cells. Alternatively, NR may support a different air interface other than an OFDM-based air interface.
[0051] Some mobile devices may be considered machine type communication (MTC) or evolved or extended machine type communication (eMTC) mobile devices. MTC and eMTC mobile devices may include, for example, a robot, a drone, a remote device, a sensor, a meter, a monitor, a location tag, etc., capable of communicating with a base station, another device (e.g., a remote device), or some other entity. A wireless computing platform may provide connectivity to or to a network (e.g., a wide area network such as the Internet or a cellular network), for example, via a wired or wireless communication link. Some mobile devices may be considered Internet of Things (IoT) devices or may be implemented as NB-IoT (narrowband Internet of Things) devices. The wireless devices 120a-120e may be included within a housing that houses components of the wireless devices 120a-120e, such as a processor component, a memory component, similar components, or a combination thereof.
[0052] In general, any number of communication systems and any number of wireless networks may be deployed within a given geographic area. Each communication system and wireless network may support a particular radio access technology (RAT) and may operate at one or more frequencies. The RAT may also be referred to as a radio technology, an air interface, etc. The frequencies may also be referred to as a carrier, a frequency channel, etc. To avoid interference between communication systems of different RATs, each frequency may support a single RAT within a given geographic area. In some cases, a 4G / LTE network and / or a 5G / NR RAT network may be deployed. For example, a 5G non-standalone (NSA) network may utilize both a 4G / LTE RAT on the 4G / LTE RAN side of a 5G NSA network and a 5G / NR RAT on the 5G / NR RAN side of a 5G NSA network. The 4G / LTE RAN and the 5G / NR RAN may be connected to each other and to a 4G / LTE core network (e.g., an evolved packet core (EPC) network) in the 5G NSA network. Another example network configuration may include a 5G Standalone (SA) network, in which a 5G / NR RAN connects to a 5G core network.
[0053] In some embodiments, two or more mobile devices 120a-120e (e.g., depicted as wireless device 120a and wireless device 120e) may communicate directly (e.g., without using base station 110a-110d as an intermediary to communicate with each other) using one or more sidelink channels 124. For example, wireless devices 120a-120e may communicate using peer-to-peer (P2P) communication, end-to-end (D2D) communication, vehicle-to-everything (V2X) protocols (which may include vehicle-to-vehicle (V2V) protocols, vehicle-to-infrastructure (V2I) protocols, or similar protocols), mesh networks, or similar networks, or combinations thereof. In this case, wireless devices 120a-120e may perform scheduling operations, resource selection operations, and other operations described elsewhere herein as being performed by base station 110a.
[0054] FIG. 1B is a system block diagram illustrating an example separated base station 160 architecture that may be part of a V2X and / or 5G network (e.g., communication system 100) according to any of the various embodiments. With reference to FIGS. 1A and 1B, the separated base station 160 architecture may include one or more central units (CUs) 162 that may communicate directly with a core network 180 via a backhaul link or indirectly with the core network 180 through one or more separated base station units, such as a near real-time (near RT) RAN intelligent controller (RIC) 164 via an E2 link or a non-real-time (non-RT) RIC 168 associated with a service management and orchestration (SMO) framework 166, or both. The CUs 162 may communicate with one or more distributed units (DUs) 170 via corresponding midhaul links, such as an F1 interface. The DUs 170 may communicate with one or more radio units (RUs) 172 via corresponding fronthaul links. The RUs 172 can communicate with corresponding UEs 120 over one or more radio frequency (RF) access links. In some implementations, a user equipment (UE), such as a V2X processing system 104, can be served by multiple RUs 172 simultaneously.
[0055] Each of the units (i.e., CU 162, DU 170, RU 172), as well as quasi-RT RIC 164, non-RT RIC 168, and SMO framework 166, may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) over a wired or wireless transmission medium. Each of the units, or an associated processor or controller that provides instructions to the unit's communication interfaces, may be configured to communicate with one or more of the other units over a transmission medium. For example, the units may include a wired interface configured to receive or transmit signals over a wired transmission medium to one or more of the other units. Furthermore, the units may include a wireless interface, which may include a receiver, transmitter, or transceiver (such as a radio frequency (RF) transceiver) configured to receive or transmit or transmit signals over a wireless transmission medium to one or more of the other units.
[0056] In some aspects, the CU 162 may host one or more higher layer control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Service Data Adaptation Protocol (SDAP), etc. Each control function may implement an interface configured to communicate signals with other control functions hosted by the CU 162. The CU 162 may be configured to handle user plane functions (i.e., Central Unit-User Plane (CU-UP)), control plane functions (i.e., Central Unit-Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU 162 may be logically divided into one or more CU-UP units and one or more CU-CP units. The CU-UP units may bidirectionally communicate with the CU-CP units over an interface such as an E1 interface when implemented in an O-RAN configuration. The CU 162 may be implemented to communicate with the DU 170 as needed for network control and signaling.
[0057] The DU 170 may correspond to a logical unit including one or more base station functions for controlling the operation of one or more RUs 172. In some aspects, the DU 170 may host one or more of a Radio Link Control (RLC) layer, a Medium Access Control (MAC) layer, and one or more upper physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation and demodulation, etc.) at least in part according to a functional division such as that defined by the 3rd Generation Partnership Project (3GPP). In some aspects, the DU 170 may further host one or more lower PHY layers. Each layer (or module) may implement an interface configured to communicate signals with other layers (and modules) hosted by the DU 170 or to communicate signals with control functions hosted by the CU 162.
[0058] The lower layer functions may be implemented by one or more RUs 172. In some deployments, the RUs 172 controlled by the DUs 170 may correspond to logical nodes hosting RF processing functions, or lower PHY layer functions (such as performing Fast Fourier Transform (FFT), inverse FFT (iFFT), digital beamforming, physical random access channel (PRACH) extraction and filtering, etc.), or both, based at least in part on a functional division, such as a lower layer functional division. In such an architecture, the RUs 172 may be implemented to handle over-the-air (OTA) communications with one or more UEs 120. In some implementations, real-time and non-real-time aspects of control plane and user plane communications with the RUs 172 may be controlled by the corresponding DUs 170. In some scenarios, this configuration may enable the DUs 170 and CUs 162 to be implemented in a cloud-based radio access network (RAN) architecture, such as a vRAN architecture.
[0059] The SMO framework 166 can be configured to support RAN deployment and provisioning of non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 166 can be configured to support deployment of dedicated physical resources for RAN coverage requirements, which can be managed via an operation and maintenance interface (such as an O1 interface). For virtualized network elements, the SMO framework 166 can be configured to interact with a cloud computing platform (such as an open cloud (O-cloud) 176) to perform life cycle management of the network elements (such as for instantiating virtualized network elements) via a cloud computing platform interface (such as an O2 interface). Such virtualized network elements can include, but are not limited to, the CU 162, the DU 170, the RU 172, and the quasi-RT RIC 164. In some implementations, the SMO framework 166 can communicate with hardware aspects of a 4G RAN, such as an open eNB (O-eNB) 174, via an O1 interface. Moreover, in some implementations, the SMO framework 166 can communicate directly with one or more RUs 172 over the O1 interface. The SMO framework 166 may also include a non-RT RIC 168 configured to support the functionality of the SMO framework 166.
[0060] The non-RT RIC 168 can be configured to include logic functions that enable non-real-time control and optimization of RAN elements and resources, artificial intelligence / machine learning (AI / ML) workflows including model training and updates, or policy-based guidance of applications / functions in the quasi-RT RIC 164. The non-RT RIC 168 can be coupled to the quasi-RT RIC 164 or can communicate with it (e.g., via an A1 interface). The quasi-RT RIC 164 can be configured to include logic functions that enable near real-time control and optimization of RAN elements and resources through data collection and action via interfaces that connect one or more CUs 162, one or more DUs 170, or both, and the O-eNB to the quasi-RT RIC 164 (e.g., via an E2 interface).
[0061] In some implementations, the non-RT RIC 168 can receive parameters or external enrichment information from an external server to generate an AI / ML model for deployment in the quasi-RT RIC 164. Such information can be utilized by the quasi-RT RIC 164 and can be received in the SMO framework 166 or the non-RT RIC 168 from a non-network data source or from a network function. In some embodiments, the non-RT RIC 168 or the quasi-RT RIC 164 can be configured to adjust the behavior or performance of the RAN. For example, the non-RT RIC 168 can employ the AI / ML model to monitor long-term trends and patterns regarding performance and take corrective action through the SMO framework 166 (e.g., reconfiguration via O1) or through the creation of a RAN management policy (e.g., A1 policy).
[0062] 2 is a component block diagram illustrating an exemplary computing and wireless modem system 200 suitable for implementing any of the various embodiments. The various embodiments can be implemented on any number of single-processor and multi-processor computer systems, including systems on a chip (SOC) or systems in a package (SIP).
[0063] 1A-2, the illustrated exemplary computing system 200 (which in some embodiments may be a SIP) includes two SOCs 202, 204 coupled to a clock 206, a voltage regulator 208, and a wireless transceiver 266 configured to transmit and receive wireless communications to and from a wireless device (e.g., 120a-120e) or a base station (e.g., 110a-110d) via an antenna (not shown). In some embodiments, the first SOC 202 may operate as a central processing unit (CPU) of the wireless device, implementing instructions of a software application program by performing arithmetic, logical, control, and input / output (I / O) operations specified by the instructions. In some embodiments, the second SOC 204 may operate as a dedicated processing unit. For example, the second SOC 204 may operate as a dedicated 5G processing unit responsible for managing high-capacity, high-speed (e.g., 5 Gbps, etc.), and / or extremely high frequency short wavelength (e.g., 28 GHz mmWave spectrum, etc.) communications.
[0064] The first SOC 202 may include a digital signal processor (DSP) 210, a modem processor 212, a graphics processor 214, an application processor 216, one or more coprocessors 218 (e.g., vector coprocessors) connected to one or more of these processors, memory 220, custom circuitry 222, system components and resources 224, an interconnect / bus module 226, one or more temperature sensors 230, a thermal management unit 232, and a thermal power envelope (TPE) component 234. The second SOC 204 may include a 5G modem processor 252, a power management unit 254, an interconnect / bus module 264, multiple mmWave transceivers 256, memory 258, and various additional processors 260, such as application processors, packet processors, etc.
[0065] Each processor 210, 212, 214, 216, 218, 252, 260 may include one or more cores, and each processor / core may perform operations independent of the other processors / cores. For example, the first SOC 202 may include a processor that executes a first type of operating system (e.g., FreeBSD, LINUX, OS X, etc.) and a processor that executes a second type of operating system (e.g., MICROSOFT WINDOWS 10 ("WINDOWS" is a registered trademark)). Furthermore, any or all of the processors 210, 212, 214, 216, 218, 252, 260 may be included as part of a processor cluster architecture (e.g., a synchronous processor cluster architecture, an asynchronous or heterogeneous processor cluster architecture, etc.).
[0066] The first SOC 202 and the second SOC 204 may include various system components, resources, and custom circuits for managing sensor data, analog-to-digital conversion, wireless data transmission, and performing other specialized operations, such as decoding data packets and processing encoded audio and video signals for rendering in a web browser. For example, the system components and resources 224 of the first SOC 202 may include power amplifiers, voltage regulators, oscillators, phase-locked loops, peripheral bridges, data controllers, memory controllers, system controllers, access ports, timers, and other similar components used to support processors and software clients running on the wireless device. The system components and resources 224 and / or custom circuits 222 may also include circuits for interfacing with peripheral devices, such as cameras, electronic displays, wireless communication devices, external memory chips, etc.
[0067] The first SOC 202 and the second SOC 204 can communicate via an interconnect / bus module 250. The various processors 210, 212, 214, 216, 218 can be interconnected to one or more memory elements 220, system components and resources 224, and custom circuitry 222, as well as a thermal management unit 232, via an interconnect / bus module 226. Similarly, the processor 252 can be interconnected to a power management unit 254, a mmWave transceiver 256, memory 258, and various additional processors 260 via an interconnect / bus module 264. The interconnect / bus modules 226, 250, 264 can include arrays of reconfigurable logic gates and / or implement bus architectures (e.g., CoreConnect, AMBA, etc.). Communications can be provided by advanced interconnects, such as high-performance networks on chips (NoCs).
[0068] The first SOC 202 and / or the second SOC 204 may further include an input / output module (not shown) for communicating with resources external to the SOC, such as a clock 206 and a voltage regulator 208. Resources external to the SOC (e.g., clock 206, voltage regulator 208) may be shared by two or more of the internal SOC processors / cores.
[0069] In addition to the exemplary SIP 200 described above, various embodiments may be implemented in a wide variety of computing systems, which may include a single processor, multiple processors, multi-core processors, or any combination thereof.
[0070] 3 is a component block diagram illustrating a software architecture 300 including radio protocol stacks for user and control planes in wireless communications suitable for implementing any of the various embodiments. With reference to FIGS. 1A-3, a wireless device 320 may implement the software architecture 300 to facilitate communication between the wireless device 320 (e.g., wireless devices 120a-120e, 200) and a base station 350 (e.g., base stations 110a-110d) of a communication system (e.g., 100). In various embodiments, layers in the software architecture 300 may form logical connections with corresponding layers in the software of the base station 350. The software architecture 300 may be distributed among one or more processors (e.g., processors 212, 214, 216, 218, 252, 260, etc.). Although illustrated with respect to one over-the-air protocol stack, in a multi-SIM (Subscriber Identity Module) wireless device, software architecture 300 may include multiple protocol stacks, each of which may be associated with a different SIM (e.g., in a dual-SIM wireless communication device, two protocol stacks, each of which is associated with two SIMs). Although described below with reference to LTE communication layers, software architecture 300 may support any of a variety of standards and protocols for wireless communication and / or may include additional protocol stacks supporting any of a variety of standards and protocols for wireless communication.
[0071] The software architecture 300 may include a non-access stratum (NAS) 302 and an access stratum (AS) 304. The NAS 302 may include functions and protocols for packet filtering, security management, mobility control, session management, and supporting traffic and signaling between a wireless device's SIM (e.g., SIM 204) and its core network 140. The AS 304 may include functions and protocols for supporting communication between a SIM (e.g., SIM 204) and a supported access network entity (e.g., a base station). Specifically, the AS 304 may include at least three layers (Layer 1, Layer 2, and Layer 3), each of which may include various sublayers.
[0072] In the user and control planes, Layer 1 (L1) of the AS 304 may be a physical layer (PHY) 306 that may oversee functions that enable transmission and / or reception over the air interface via a wireless transceiver (e.g., 266). Examples of such physical layer 306 functions may include cyclic redundancy check (CRC) attachment, coding blocks, scrambling and descrambling, modulation and demodulation, signal measurement, MIMO, etc. This physical layer may include various logical channels, including a physical downlink control channel (PDCCH) and a physical downlink shared channel (PDSCH).
[0073] In the user and control planes, Layer 2 (L2) of the AS 304 may be responsible for the link between the wireless device 320 and the base station 350 via the physical layer 306. In various embodiments, Layer 2 may include a Medium Access Control (MAC) sublayer 308, a Radio Link Control (RLC) sublayer 310, and a Packet Data Convergence Protocol (PDCP) sublayer 312, each of which forms a logical connection that terminates at the base station 350.
[0074] In the control plane, Layer 3 (L3) of the AS 304 may include a Radio Resource Control (RRC) sublayer 3. Although not shown, the software architecture 300 may include additional sublayers of Layer 3, as well as various upper layers above Layer 3. In various embodiments, the RRC sublayer 313 may provide functions including broadcasting system information, paging, and establishing and releasing RRC signaling connections between the wireless device 320 and the base station 350.
[0075] In various embodiments, the PDCP sublayer 312 can provide uplink functions including multiplexing between different radio bearers and logical channels, sequence numbering, handover data handling, integrity protection, ciphering, and header compression. In the downlink, the PDCP sublayer 312 can provide functions including in-order delivery of data packets, detection of duplicate data packets, integrity verification, decryption, and header decompression.
[0076] In the uplink, the RLC sublayer 310 can provide segmentation and concatenation of upper layer data packets, retransmission of lost data packets, and automatic repeat request (ARQ). In the downlink, the functions of the RLC sublayer 310 can include reordering of data packets to compensate for out-of-order reception, reassembly of upper layer data packets, and ARQ.
[0077] In the uplink, the MAC sublayer 308 can provide functions including multiplexing between logical and transport channels, random access procedures, logical channel priorities, and operation of Hybrid ARQ (HARQ). In the downlink, the MAC layer functions can include channel mapping within a cell, demultiplexing, discontinuous reception (DRX), and operation of HARQ.
[0078] While the software architecture 300 may provide functionality for transmitting data over a physical medium, the software architecture 300 may further include at least one host layer 314 for providing data transfer services to various applications within the wireless device 320. In some embodiments, the application-specific functionality provided by the at least one host layer 314 may provide an interface between the software architecture and the general-purpose processor 206.
[0079] In other embodiments, software architecture 300 may include one or more higher logical layers (e.g., transport, session, presentation, application, etc.) that provide host layer functionality. For example, in some embodiments, software architecture 300 may include a network layer (e.g., Internet Protocol (IP) layer) with logical connections terminating at a Packet Data Network (PDN) Gateway (PGW). In some embodiments, software architecture 300 may include an application layer with logical connections terminating at another device (e.g., an end user device, a server, etc.). In some embodiments, software architecture 300 may further include a hardware interface 316 between physical layer 306 and communications hardware (e.g., one or more radio frequency (RF) transceivers) within AS 304.
[0080] Figure 4 is a message flow diagram illustrating wireless communications 400 that may be exchanged between various elements in a communications system including a UE, a non-3GPP network, and a home 3GPP network for performing authentication of the UE to the non-3GPP network for purposes of performing 5G NSWO, according to various embodiments. Figures 5A and 5B are method flow diagrams illustrating a method 500 that may be performed by a processor of a UE as part of authenticating the UE to the non-3GPP network for purposes of performing 5G NSWO, according to various embodiments. For ease of explanation, the communications illustrated in Figure 4 and the operations illustrated in Figures 5A and 5B are labeled with corresponding reference numbers, and Figures 4-5B are described together in the following description.
[0081] 1-5B, methods 400 and 500 may be performed by processors (e.g., 210, 212, 214, 216, 218, 252, 260) of a wireless device 402 (e.g., wireless devices 120a-120e, 350), processors (e.g., 210, 212, 214, 216, 218, 252, 260) of elements of a non-3GPP access network 404 (e.g., 150), and processors (e.g., 210, 212, 214, 216, 218, 252, 260) of elements of a core network (e.g., 140), which may provide functions such as a 5G NSWO function 406 and an authentication function (e.g., AUSF) 408. In various embodiments, the core network 140 may be referred to as a home 3GPP network of the UE and may provide various functions and perform various operations as further described herein.
[0082] In operation 0, the processor of the UE 402 may determine whether the UE is configured to perform operations related to 5G NSWO. In some embodiments, the processor of the UE 402 may check a Universal Subscriber Identity Module (USIM) or Mobile Equipment (ME) configuration for an indication that the UE should use 5G NSWO, and the encrypting of the MSIN to generate a SUCI in NAI format and the sending of the SUCI to a network element of the non-3GPP access network for authentication of the UE by the home 3GPP network for access to the non-3GPP access network are performed in response to the USIM or ME configuration indicating that the UE should use 5G NSWO. In some embodiments, such a configuration indication may be present on the USIM (e.g., a new USIM service or stored in a basic file on the USIM) or on the ME. Such a configuration on the USIM may take precedence over any configuration on the ME in some embodiments. In some embodiments, the processor of the UE 402 can obtain an encrypted MSIN from the USIM via an ME function and can generate (e.g., by the ME) an NAI-formatted SUCI using the encrypted MSIN. In various embodiments, the processor of the UE 402 can perform the operations of Block 0 prior to establishment of a communication link with the non-3GPP access network 404 (as shown in FIG. 4), after establishment of a communication link with the non-3GPP access network 404, or during establishment of such communication link. In some embodiments, the UE 402 can determine whether the UE is configured to perform an operation related to 5G NSWO in response to receiving an identity request from the non-3GPP access network 404 (Action and Communication 2).
[0083] In Operation and Communications 1, the UE 402 and the non-3GPP access network 404 may establish a communications link (eg, wireless communications link 156).
[0084] In Operation and Communications 2, the non-3GPP access network 404 may send an identity request to the UE 402 in response to establishing a communications link with the UE 402. As mentioned above, in some embodiments, the UE 402 may determine whether the UE is configured to perform operations related to 5G NSWO in response to receiving the identity request from the non-3GPP access network 404.
[0085] In Operation and Communications 3, the UE 402 can obtain a Mobile Subscriber Identity (MSIN) from the UE's International Mobile Subscriber Identity (IMSI), encrypt the MSIN to generate a Subscription Security Identifier (SUCI) in a Network Access Identifier (NAI) format, and send the SUCI to the non-3GPP access network 404.
[0086] In operation and communication 4, the non-3GPP access network 404 can send an authentication request to the 5G NSWO function 406. In some embodiments, this authentication request can include an authentication, authorization, and accounting (AAA) request over the SWa communication interface with the username set to the SUCI in NAI format. In some embodiments, if an AAA proxy is used in the network (e.g., when the UE is roaming), the AAA proxy can forward the AAA request to the 5G NSWO function 406 over the SWd communication interface.
[0087] In operation 5, the 5G NSWO function 406 may receive an authentication request including the SUCI. The 5G NSWO function 406 may determine that the UE should be authenticated by the home 3GPP network authentication function 408 based on the SUCI. In some embodiments, the 5G NSWO function 406 may determine that the SUCI is in an NAI format. In such an embodiment, the 5G NSWO function 406 may determine that the UE should be authenticated by the home 3GPP network authentication function 408 in response to determining that the SUCI is in an NAI format. In some embodiments, the 5G NSWO function 406 may convert the AAA message to a service-based interface (SBI) message, e.g., for network transport.
[0088] In operations and communications 6, the 5G NSWO function 406 may provide an authentication request including the SUCI to an authentication function 408 of the home 3GPP network for processing based on a determination that the UE should be authenticated by the authentication function. In some embodiments, the authentication function 408 processes the authentication request including the SUCI in response to determining that the SUCI is in NAI format. In some embodiments, the 5G NSWO function 406 may provide the authentication request including the SUCI with a "Serving Network Name" associated with or provided to the non-3GPP access network set to any value, such as "5G:NSWO". In some embodiments, the 5G NSWO function 406 may provide the authentication request to the authentication function 408 as a Nausf_UEAuthentication_Authenticate request message with the Serving Network Name set to any value.
[0089] In operation and communication 7, the authentication function 408 can send an authentication get request (e.g., Nudm_UEAuthentication_Get request) to a network authentication infrastructure element 410 (e.g., UDM / ARPF / SIDF). The UDM (Unified Data Management) network element or function can process network user data in a 5G communication network, for example for the authentication function 408. The ARPF (Authentication Credentials Repository and Processing Function) can select an authentication method based on the subscriber identity and can calculate authentication data and keying material for the authentication function 408. The SIDF (Subscriber Identifier Deciphering Function) can decrypt the SUCI to obtain a persistent UE identity (e.g., the UE's SUPI or IMSI).
[0090] In operation 8, the network authentication infrastructure element 410 can decipher (e.g., decrypt) the SUCI, select an authentication method, such as an authentication protocol such as EAP-AKA' for use with the UE 402 (e.g., based on the SUPI and / or serving network name), and generate an initial authentication vector (AV).
[0091] In Operation and Communication 9, the network authentication infrastructure element 410 may send an authentication get response (eg, a Nudm_UEAuthentication_Get response message) to the authentication function 408.
[0092] In operation and communication 10, the authentication function 408 may send an authentication challenge message (e.g., an EAP-Request / AKA' challenge message) to the 5G NSWO function 406.
[0093] In operation and communications 11, the 5G NSWO function 406 may send an authentication challenge message (e.g., an EAP-Request / AKA' challenge message) to the non-3GPP access network 404. In some embodiments, the 5G NSWO function 406 may send the authentication challenge message as an AAA message.
[0094] In operation and communication 12, the non-3GPP access network 404 may send an authentication challenge message (eg, an EAP-Request / AKA′ challenge message) to the UE 402.
[0095] In operation 13, the UE 402 may receive an authentication challenge message (e.g., an EAP Request / AKA' challenge message). The UE 402 may calculate an authentication response message (e.g., an EAP Response) via an AKA algorithm. In some embodiments, the UE 402 may determine one or more EAP keys (e.g., a Master Session Key (MSK), an Extended MSK (EMSK), etc.) as part of operation 13 or at any time after operation 13. In some embodiments, the UE 402 may set a serving network name (SN name) to any value and may use any value of the serving network name to derive keys. For example, the UE 402 may set the SN name to "5G:NSWO" to derive keys if a serving network name is required. In some embodiments, the actual network name may not be available to the UE. By using an arbitrary value for the serving network name, it becomes unnecessary to define or adopt procedures to enable the UE 402 and authentication function 406 to obtain and use the actual value of the serving network or non-3GPP access network identifier when deriving such keys.
[0096] In operation and communication 14, the UE 402 may send an authentication response (eg, an EAP response, such as an EAP-Response / AKA′ Challenge message) to the non-3GPP access network 404.
[0097] In operation and communication 15, the non-3GPP access network 404 may forward the EAP response to the 5G NSWO function 406 (e.g., in an AAA message).
[0098] At communication 16, the 5G NSWO function 406 may send an EAP response / AKA' challenge message to the authentication function 408 (e.g., within a Nausf_UEAuthentication_Authenticate request message).
[0099] In operation 17, authentication function 408 may verify the authentication response. In response to determining that the authentication response verification is successful, authentication function 408 may send an authentication failure message (e.g., an EAP failure message) to 5G NSWO function 406. In response to determining that the authentication response verification is successful, authentication function 408 may perform operations as described further below.
[0100] In optional operations and communications 18, the UE 402 and the authentication function 408 may exchange further EAP messages. Such EAP messages may include, for example, EAP Request / AKA' notification messages and EAP Response / AKA' notification messages via the NSWO function. In various embodiments, the 5G NSWO function 406 may forward such messages between the UE 402 and the authentication function 408.
[0101] In operations and communications 19, the authentication function 408 can derive (generate, calculate) a Master Session Key (MSK) and send the MSK to the 5G NSWO function 406. In some embodiments, the authentication function 408 can derive the MSK from an integrity key (e.g., IK') and an encryption key (e.g., CK'), as well as optional values for the serving network name (SN name) if necessary.
[0102] In operation and communications 20, the 5G NSWO function 406 may send the MSK to the non-3GPP access network 404. In some embodiments, the 5G NSWO function 406 may send an authentication success message (e.g., an EAP success message) that may include the MSK.
[0103] In operations and communications 21, the non-3GPP access network 404 may send an authentication success message to the UE 402. In some embodiments, this completes the 5G NSWO authentication operation.
[0104] In operation and communication 22, the UE 402 and the non-3GPP access network 404 may carry out communications via an established communications link.
[0105] 6A is a process flow diagram illustrating a method 600a that may be performed by a processor of a UE for 5G network authentication to support 5G NSWO, according to various embodiments. With reference to FIGS. 1A-6A, means for performing operations of the method 600a may include a processor (e.g., 210, 212, 214, 216, 218, 252, 260) of a UE (e.g., UE 120a-120e, 350, 402).
[0106] At block 602, the processor may check a Universal Subscriber Identity Module (USIM) or Mobile Equipment (ME) configuration for an indication that the UE should use 5G NSWO. For example, the processor may determine that the UE should use the 5G NSWO procedure in response to a bit or flag value set in the USIM or in a memory register of the ME. In some embodiments, the configuration for using the 5G NSWO procedure may be part of an ME firmware configuration that may be preloaded into the UE as part of configuring the device for service with a home network.
[0107] At block 604, the processor may obtain a Mobile Subscriber Identity (MSIN) from an International Mobile Subscriber Identity (IMSI) of the UE. In some embodiments, the processor may obtain an encrypted MSIN from a USIM of the UE and use the encrypted MSIN to generate a SUCI in the NAI format.
[0108] At block 606, the processor may encrypt the MSIN to generate a subscription security identifier (SUCI) in a network access identifier (NAI) format. In some embodiments, in response to the USIM or ME configuration indicating that the UE should use 5G NSWO, the processor may encrypt the MSIN to generate a SUCI in an NAI format and transmit the SUCI to a network element of the non-3GPP access network for authentication of the UE by the home 3GPP network for access to the non-3GPP access network.
[0109] At block 608, the processor may transmit the SUCI to a network element of the non-3GPP access network for authentication of the UE by the home 3GPP network for access to the non-3GPP access network. In some embodiments, transmitting the SUCI to the network element of the non-3GPP access network may be accomplished in response to an identity request received from the non-3GPP access network.
[0110] At block 610, the processor may receive an Extensible Authentication Protocol and Key Agreement Prime (EAP-AKA') challenge from a network element of a non-3GPP access network. Such an EAP-AKA' challenge message may be consistent with conventional EAP-AKA' protocol procedures.
[0111] In block 612, the processor may calculate an EAP response via the AKA algorithm. The generation of the EAP response via the AKA algorithm may follow conventional EAP-AKA' protocol procedures.
[0112] The processor may derive or generate one or more keys using any value for the serving network name of the non-3GPP access network in block 614. In various embodiments, the derivation / generation of the one or more keys may be accomplished at any time after receiving the EAP-AKA' challenge message.
[0113] In block 616, the processor may send an EAP response to a network element of the non-3GPP access network. The sending of the EAP-AKA' response may be consistent with conventional EAP-AKA' protocol procedures.
[0114] At block 618, the processor may receive an EAP success message from a network element of the non-3GPP access network. Receipt of the EAP success message indicates to the UE processor that the device has been successfully authenticated to the home network and therefore may continue communications over the non-3GPP access network using 5G security procedures.
[0115] At block 620, the processor may initiate communication with the Internet via a network element of the non-3GPP access network in response to receiving the EAP success.
[0116] 6B is a process flow diagram illustrating a method 600b that may be performed by a processor of a UE for 5G network authentication to support 5G NSWO, according to various embodiments. With reference to FIGS. 1A-6B, means for performing operations of method 600b may include a processor (e.g., 210, 212, 214, 216, 218, 252, 260) of a UE (e.g., UE 120a-120e, 350, 402).
[0117] In block 602, the processor may check the USIM or ME configuration for an indication that the UE should use 5G NSWO, as described.
[0118] In block 630, in response to the USIM or ME configuration indicating that the UE should use 5G NSWO, a processor of the UE may generate an NAI-formatted SUCI. In some embodiments, the processor may obtain an MSIN from the IMSI of the UE. In some embodiments, the processor may obtain an encrypted MSIN from the USIM of the UE and generate the NAI-formatted SUCI using the encrypted MSIN. In some embodiments, the processor may encrypt the MSIN to generate the NAI-formatted SUCI.
[0119] At block 632, the processor may send the NAI-formatted SUCI to the non-3GPP access network (e.g., to a network element of the non-3GPP access network) for authentication of the UE. In some embodiments, sending the NAI-formatted SUCI to the non-3GPP access network may enable a network element of the UE's home 3GPP network to perform authentication of the UE for access to the non-3GPP access network. In some embodiments, sending the NAI-formatted SUCI to the network element of the non-3GPP access network may be performed in response to receiving an identity request received from the non-3GPP access network.
[0120] In various embodiments, the operations of methods 500-600b may be performed in various network computing devices (e.g., in network elements), an example of which is shown in FIG. 7, which is a component block diagram of a network computing device 700 suitable for use in various embodiments. Such a network computing device may include at least the components shown in FIG. 7. With reference to FIGS. 1-7, the network computing device 700 may include a processor 701 coupled to a volatile memory 702 and a large capacity non-volatile memory, such as a disk drive 703. The network computing device 700 may also include a peripheral memory access device, such as a floppy disk drive, compact disk (CD) or digital video disk (DVD) drive 706, coupled to the processor 701. The network computing device 700 may also include a network access port 704 (or interface) coupled to the processor 701 for establishing a data connection with a network, such as the Internet and / or a local area network coupled to other system computers and servers. The network computing device 700 may be connected to one or more antennas for transmitting and receiving electromagnetic radiation, which may be connected to a wireless communications link. The network computing device 700 may include additional access ports, such as USB, Firewire, Thunderbolt, etc., for coupling to peripherals, external memory, or other devices.
[0121] In various embodiments, operations of methods 500-600b may be performed in various wireless devices (e.g., wireless devices 120a-120e, 200, 320, 402), an example of which is shown in FIG. 8, which is a component block diagram of a wireless device 800 suitable for use in various embodiments. With reference to FIGS. 1-8, wireless device 800 may include a first SOC 202 (e.g., SOC-CPU) coupled to a second SOC 204 (e.g., a 5G-enabled SOC). The first SOC 202 and second SOC 204 may be coupled to an internal memory 816, a display 812, and a speaker 814. Additionally, wireless device 800 may include an antenna 804 for transmitting and receiving electromagnetic radiation that may be coupled to a wireless data link and / or a cellular telephone transceiver 266, which is coupled to one or more processors in the first SOC 202 and / or second SOC 204. The wireless device 800 may also include menu selection buttons or rocker switches 820 for receiving user input.
[0122] The wireless device 800 may also include a voice encoding / decoding (CODEC) circuit 810 that digitizes sound received from the microphone into data packets suitable for wireless transmission and decodes the received voice data packets to generate analog signals that are provided to a speaker to generate voice. One or more of the processors in the first SOC 202 and second SOC 204, the wireless transceiver 266, and the CODEC 810 may also include digital signal processor (DSP) circuitry (not separately shown).
[0123] The processors of the network computing device 800 and the wireless device 800 may be any programmable microprocessor, microcomputer, or multiprocessor chip that may be configured by software instructions (applications) to perform various functions, including those of the various embodiments described below. In some mobile devices, there may be multiple processors, such as one processor in SOC 204 dedicated to wireless communication functions and one processor in SOC 202 dedicated to running other applications. Software applications may be stored in memory 816 before they are accessed and loaded into the processor. The processor may include sufficient internal memory to store application software instructions.
[0124] As used in this application, terms such as "component," "module," "system," and the like are intended to include computer-related entities, such as, but not limited to, hardware, firmware, a combination of hardware and software, software, or software in execution, configured to perform certain operations or functions. For example, a component may be, but is not limited to, a process running on a processor, a processor, an object, an executable, a thread of execution, a program, and / or a computer. By way of example, both an application running on a wireless device and the wireless device may be referred to as a component. One or more components may reside within a process and / or thread of execution, and a component may be localized on one processor or core and / or distributed among two or more processors or cores. Furthermore, these components may execute from various non-transitory computer-readable media on which various instructions and / or data structures are stored. Components may communicate by way of local and / or remote processes, function or procedure calls, electronic signals, data packets, memory reads / writes, and other known network, computer, processor, and / or process related communication methods.
[0125] A number of different cellular and mobile communication services and standards are available or are contemplated in the future, all of which may implement and benefit from the various embodiments. Such services and standards include, for example, 3rd Generation Partnership Project (3GPP), Long Term Evolution (LTE) systems, third generation wireless mobile communication technologies (3G), fourth generation wireless mobile communication technologies (4G), fifth generation wireless mobile communication technologies (5G), Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), 3GSM, General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA) systems (e.g., cdmaOne, CDMA1020™), Enhanced Data Rates for GSM Evolution (EDGE), Advanced Mobile Phone System (AMPS), Digital AMPS (IS-136 / TDMA), Evolution Data Optimized (EV-DO), Digital Enhanced Cordless Telecommunications (DECT), Worldwide Interoperable Microwave Access (WiMAX), Wireless Local Area Networks (WLAN), Wi-Fi Protected Access I & II (WPA, WPA2), and Integrated Digital Enhanced Network (iDEN). Each of these technologies involves, for example, the sending and receiving of voice, data, signaling, and / or content messages. It should be understood that any reference to terminology and / or technical details relating to particular telecommunications standards or technologies is for illustrative purposes only and is not intended to limit the claims to a particular communications system or technology unless specifically recited in the claim language.
[0126] The various embodiments shown and described are provided merely as examples to illustrate various features of the claims. However, features shown and described with respect to any given embodiment are not necessarily limited to the associated embodiment, but may be used with or combined with other embodiments shown and described. Moreover, the claims are not intended to be limited by any one exemplary embodiment. For example, one or more of the operations of method 500 may be replaced or combined with one or more operations of method 600a and / or method 600b.
[0127] Implementation examples are described in the following paragraphs. Although some of the implementation examples below are described in terms of example systems and methods, further example implementations may include the following: the example operations discussed in the following paragraphs may be performed by various devices of a system for performing authentication of a UE, the example methods discussed in the following paragraphs may be performed by a UE or a network element including a processor configured with processor-executable instructions for performing the operations of the method of the following implementations, the example methods discussed in the following paragraphs may be performed by a UE or a network element including means for performing the functions of the method of the following implementations, and the example methods discussed in the following paragraphs may be implemented as a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of a UE or a network element to perform the operations of the method of the following implementations.
[0128] Example 1. A system for performing authentication of a user equipment (UE), comprising: a non-3GPP access network; a UE including a processor configured with processor-executable instructions for obtaining a Mobile Subscriber Identity (MSIN) from an International Mobile Subscriber Identity (IMSI) of the UE, encrypting the MSIN to generate a Subscription Masking Identifier (SUCI) in a Network Access Identifier (NAI) format, and sending the SUCI to the non-3GPP access network for authentication of the UE; and a network element of a home 3GPP network including a processor configured with processor-executable instructions for receiving, by a 5G non-seamless WLAN offload (NSWO) function, an authentication request including the SUCI from the non-3GPP access network, determining, by the 5G NSWO function based on the SUCI, that the UE should be authenticated by an authentication function of the home 3GPP network, and providing the authentication request including the SUCI to an authentication function of the home 3GPP network for processing based on a determination by the authentication function that the UE should be authenticated.
[0129] Example 2. The system of example 1, wherein the processor of the UE is further configured to receive an identity request from the non-3GPP access network and, in response to the identity request, determine whether the UE is configured to perform 5G NSWO based on an indicator stored within the UE.
[0130] Example 3. The system of any of Examples 1 and 2, wherein the processor of the network element of the home 3GPP network is further configured to determine, via a 5G NSWO function, that the SUCI is in NAI format.
[0131] Example 4. The system of example 3, wherein the authentication function processes the authentication request including the SUCI in response to determining that the SUCI is in NAI format.
[0132] Example 5. The system of any one of Examples 1 to 3, wherein the authentication function includes an authentication server function (AUSF).
[0133] Example 6. The system of any of Examples 1 to 5, wherein the non-3GPP access network is further configured to establish a communication link with the UE and, in response to establishing the communication link with the UE, send an identification information request to the UE.
[0134] Example 7. The system of any of Examples 1 to 6, wherein the processor of the network element of the home 3GPP network is further configured to receive, by the 5G NSWO function, from the authentication function an authentication response based on processing the authentication request including the SUCI, and in response to receiving the authentication response from the authentication function, send, by the 5G NSWO function, an authentication challenge to the non-3GPP access network.
[0135] Example 8. The system of any of Examples 1-7, wherein the processor of the UE is further configured to receive an authentication challenge from the non-3GPP access network, generate an authentication response in response to the authentication challenge, and transmit the authentication response to the non-3GPP access network.
[0136] Example 9. The system of example 8, wherein the processor of the UE is further configured to generate the key using an arbitrary value for a serving network name of the non-3GPP access network.
[0137] Example 10. The system of Example 8, wherein the processor of the network element of the home 3GPP network is further configured to receive, via a 5G NSWO function, an authentication response from the UE via the non-3GPP access network in response to the authentication challenge, provide the authentication response to an authentication function of the home 3GPP network, and receive, via the 5G NSWO function, a master session key (MSK) in response to the authentication response from the authentication function of the home 3GPP network.
[0138] Example 11. The system of example 10, wherein the processor of the network element of the home 3GPP network is further configured to send the MSK to the non-3GPP access network to authenticate the UE for access to the non-3GPP access network.
[0139] Example 12. The system of example 10, wherein the MSK is derived using an arbitrary value for the serving network name of the non-3GPP access network.
[0140] Example 13. A method for performing authentication of a user equipment (UE) for 5G network authentication to support 5G non-seamless WLAN offload (5G NSWO) over a non-3GPP access network, comprising: obtaining, by a processor of the UE, a mobile subscriber identity (MSIN) from an international mobile subscriber identity (IMSI) of the UE; encrypting, by a processor of the UE, the MSIN to generate a subscription masking identifier (SUCI) in a network access identifier (NAI) format; transmitting, by the processor of the UE, the SUCI to the non-3GPP access network for authentication of the UE; receiving, by a 5G NSWO function of a network element of a home 3GPP network, an authentication request including the SUCI from the non-3GPP access network; The method includes determining, by an NSWO function, based on the SUCI, that the UE should be authenticated by an authentication function of the home 3GPP network; providing an authentication request including the SUCI to the authentication function of the home 3GPP network for processing based on the determination by the authentication function that the UE should be authenticated; and completing authentication of the UE in accordance with an Extensible Authentication Protocol (EAP) protocol.
[0141] Example 14. The method of example 13, wherein determining, by the 5G NSWO function, that the UE should be authenticated by an authentication function of the home 3GPP network based on the SUCI includes determining, by the 5G NSWO function, that the SUCI is in NAI format.
[0142] Example 15. The method of example 14, further comprising, in response to determining that the SUCI is in NAI format, processing, by the authentication function, an authentication request including the SUCI.
[0143] Example 16. The method of example 13, wherein the authentication function includes an authentication server function (AUSF).
[0144] Example 17. A method executed by a processor of a user equipment (UE) for 5G network authentication to support 5G non-seamless WLAN offload (NSWO), comprising: obtaining a mobile subscriber identity (MSIN) from an international mobile subscriber identity (IMSI) of the UE; encrypting the MSIN to generate a subscription concealment identifier (SUCI) in a network access identifier (NAI) format; and transmitting the SUCI to a network element of the non-3GPP access network for authentication of the UE by a home 3GPP network for access to the non-3GPP access network.
[0145] Example 18. The method of Example 17, further comprising checking a Universal Subscriber Identity Module (USIM) or Mobile Equipment (ME) configuration for an indication that the UE should use 5G NSWO, and wherein encrypting the MSIN to generate a SUCI in NAI format and sending the SUCI to a network element of the non-3GPP access network for authentication of the UE by the home 3GPP network for access to the non-3GPP access network are performed in response to the USIM or ME configuration indicating that the UE should use 5G NSWO.
[0146] Example 19. The method of any of Examples 17 or 18, wherein obtaining an MSIN from the IMSI of the UE includes obtaining, by an ME function of the UE, an encrypted MSIN from a USIM of the UE, and generating, by the ME, a SUCI in an NAI format using the encrypted MSIN.
[0147] Example 20. The method of any of Examples 17-19, further comprising receiving an Extensible Authentication Protocol and Key Agreement Prime (EAP-AKA') challenge from a network element of the non-3GPP access network, calculating an EAP response via an AKA algorithm, deriving one or more keys using an arbitrary value for a serving network name of the non-3GPP access network, sending an EAP response to the network element of the non-3GPP access network, receiving an EAP success from the network element of the non-3GPP access network, and initiating communication on the non-3GPP access network via the network element of the non-3GPP access network in response to receiving the EAP success.
[0148] Example 21. A method for 5G network authentication to support 5G non-seamless WLAN offload (NSWO) over a non-3GPP access network, comprising: checking, by a processor of a UE, a universal subscriber identity module (USIM) or mobile equipment (ME) setting for an indication that the UE should use 5G NSWO; generating, by a processor of the UE, a subscription concealment identifier (SUCI) in a network access identifier (NAI) format in response to the USIM or ME setting indicating that the UE should use 5G NSWO; and transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE.
[0149] Example 22. The method of example 21, wherein transmitting, by the processor of the UE, a SUCI in an NAI format to the non-3GPP access network for authentication of the UE, includes receiving, by the UE, an identity request from the non-3GPP access network, and transmitting, by the processor of the UE, a SUCI in an NAI format to the non-3GPP access network for authentication of the UE in response to the identity request from the non-3GPP access network.
[0150] Example 23. The method of any of Examples 21 or 22, wherein generating an SUCI in an NAI format by the processor of the UE includes encrypting, by the processor of the UE, a mobile subscriber identity number (MSIN) obtained from an international mobile subscriber identity (IMSI) of the UE to generate an SUCI in the NAI format.
[0151] Example 24. The method of any of Examples 21 or 22, wherein generating an SUCI in an NAI format by the processor of the UE includes obtaining, by an ME function of the UE, an encrypted MSIN from the UE's USIM, and generating, by the ME function, an SUCI in an NAI format using the encrypted MSIN.
[0152] Example 25. The method of any of Examples 21-24, wherein transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE includes transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE in response to an identity request received by the UE from the non-3GPP access network.
[0153] Example 26. Any of the methods of Examples 21-25, wherein generating an NAI-formatted SUCI by the UE's processor includes encrypting a username portion of the NAI and incorporating the encrypted username in the NAI to form an NAI-formatted SUCI.
[0154] Example 27. The method of any of Examples 21-26, wherein the SUCI in the NAI format includes an indication of whether the SUCI is derived from the UE's IMSI or the NAI.
[0155] Example 28. The method of any of Examples 21-27, wherein generating, by the processor of the UE, the SUCI in the NAI format includes converting IMSI digits of the UE into a domain name.
[0156] Example 29. The method of any of Examples 21-28, further comprising receiving an Extensible Authentication Protocol and Key Agreement Prime (EAP-AKA') challenge from a network element of the non-3GPP access network, deriving one or more keys using an arbitrary value for a serving network name of the non-3GPP access network, sending an EAP response to the network element of the non-3GPP access network, and initiating communication on the non-3GPP access network via the network element of the non-3GPP access network using the one or more derived keys.
[0157] Example 30. The method of example 29, wherein initiating communication over the non-3GPP access network via a network element of the non-3GPP access network includes receiving an EAP success from the network element of the non-3GPP access network, and in response to receiving the EAP success, initiating communication over the non-3GPP access network via the network element of the non-3GPP access network.
[0158] Example 31. A method for 5G network authentication to support 5G NSWO on a non-3GPP access network, comprising: checking, by a processor of a UE, a USIM or ME setting for an indication that the UE should use 5G NSWO; generating, by a processor of the UE, a SUCI in an NAI format in response to the USIM or ME setting indicating that the UE should use 5G NSWO; and transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE.
[0159] Example 32. The method of example 31, wherein sending an NAI-formatted SUCI to the non-3GPP access network for authentication of the UE is performed by the processor of the UE in response to receiving an identity request from the non-3GPP access network by the UE.
[0160] Example 33. The method of any of Examples 31 and 32, wherein generating the SUCI in the NAI format by the UE processor includes encrypting, by the UE processor, a Mobile Subscriber Identity Number (MSIN) obtained from the UE's International Mobile Subscriber Identity (IMSI), and including the encrypted MSIN within the SUCI.
[0161] Example 34. The method of any of Examples 31 to 33, wherein generating an SUCI in an NAI format by the processor of the UE includes obtaining, by an ME function of the UE, an encrypted MSIN from a USIM of the UE, and using, by the ME function, the encrypted MSIN to generate an SUCI in an NAI format.
[0162] Example 35. Any of the methods of Examples 31-34, wherein generating an NAI-formatted SUCI by the UE's processor includes encrypting a username portion of the NAI and incorporating the encrypted username portion of the NAI into the SUCI.
[0163] Example 36. The method of any of Examples 31 to 35, wherein the SUCI in the NAI format includes an indication of whether the SUCI is derived from the UE's IMSI or the NAI.
[0164] Example 37. The method of any of Examples 31-36, wherein generating, by the processor of the UE, the SUCI in the NAI format includes converting IMSI digits of the UE into a domain name.
[0165] Example 38. The method of any of Examples 31 to 37, further comprising receiving an Extensible Authentication Protocol and Key Agreement Prime (EAP-AKA') challenge from a network element of the non-3GPP access network, deriving one or more keys using an arbitrary value for a serving network name of the non-3GPP access network, sending an EAP response to the network element of the non-3GPP access network, and initiating communication on the non-3GPP access network via the network element of the non-3GPP access network using the one or more derived keys.
[0166] Example 39. The method of example 38, wherein initiating communication over the non-3GPP access network via a network element of the non-3GPP access network includes receiving an EAP success from the network element of the non-3GPP access network, and in response to receiving the EAP success, initiating communication over the non-3GPP access network via the network element of the non-3GPP access network.
[0167] The method descriptions and process flow diagrams set forth above are provided merely as illustrative examples and are not intended to require or imply that the operations of the various embodiments must be performed in the order presented. As will be appreciated by one of ordinary skill in the art, the order of operations in the above-described embodiments may be performed in any order. Terms such as "thereafter," "then," and "next" are not intended to limit the order of operations, but rather, these terms are used to guide the reader through the method description. Furthermore, any reference to a claim element in the singular, for example, using the articles "a," "an," or "the," should not be construed as limiting the element to the singular.
[0168] The various exemplary logic blocks, modules, components, circuits, and algorithmic operations described in connection with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, the various exemplary components, blocks, modules, circuits, and operations have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in various ways for each specific application, but such implementation decisions should not be interpreted as causing a departure from the scope of the claims.
[0169] The hardware used to implement the various example logic, logic blocks, modules, and circuits described in connection with the embodiments disclosed herein may be implemented or performed using a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, designed to perform the functions described herein. A general purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of receiver smart objects, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Alternatively, some operations or methods may be performed by circuits that are specialized for a given function.
[0170] In one or more embodiments, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored as one or more instructions or code on a non-transitory computer-readable storage medium or a non-transitory processor-readable storage medium. The operations of the methods or algorithms disclosed herein may be embodied in a processor-executable software module or processor-executable instructions that may reside on a non-transitory computer-readable storage medium or a non-transitory processor-readable storage medium. A non-transitory computer-readable storage medium or a non-transitory processor-readable storage medium may be any storage medium that can be accessed by a computer or a processor. By way of example and without limitation, such a non-transitory computer-readable storage medium or a non-transitory processor-readable storage medium may include RAM, ROM, EEPROM, FLASH memory, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage smart objects, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. Disk and disc, as used herein, include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc, where disks typically reproduce data magnetically while discs reproduce data optically using a laser. Combinations of the above are also included within the scope of non-transitory computer-readable media and processor-readable media. Furthermore, operations of a method or algorithm may reside as one or any combination or set of code and / or instructions on a non-transitory processor-readable storage medium and / or a non-transitory computer-readable storage medium, which may be incorporated into a computer program product.
[0171] The foregoing description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the claims. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the claims. Thus, the present disclosure is not intended to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the following claims and the principles and novel features disclosed herein. [Explanation of symbols]
[0172] 100 Communication Systems 102 Macrocell 110 base station 120 Wireless Devices 122 Wireless Communication Links 124 Wireless Communication Links 126 Wired / Wireless Communication Links 130 Network Controller 140 Core Network 150 Non-GPP Access Networks 152 Communication Links 154 Access Points 156 Communication Links
Claims
1. A user equipment (UE), comprising: a processor, wherein the processor: checks a Universal Subscriber Identity Module (USIM) or Mobile Equipment (ME) setting regarding an instruction that the UE should use 5G Non-Seamless WLAN Offloading (NSWO); in response to the USIM or the ME setting indicating that the UE should use 5G NSWO, generates a Subscriber Concealed Identifier (SUCI) in Network Access Identifier (NAI) format; transmits the SUCI in NAI format to a non-3GPP access network for authentication of the UE. The UE is configured as such.
2. The UE according to claim 1, wherein, to generate the SUCI in NAI format, the processor is further configured to encrypt a Mobile Subscriber Identification Number (MSIN) obtained from the International Mobile Subscriber Identity (IMSI) of the UE and include the encrypted MSIN in the SUCI.
3. The processor is further configured to obtain an encrypted MSIN from the USIM of the UE by the ME function of the UE, and the ME function uses the encrypted MSIN to generate the SUCI in NAI format. The UE according to claim 1.
4. The UE according to claim 1, wherein, to generate the SUCI in NAI format, the processor is further configured to encrypt a username part of the NAI and incorporate the encrypted username part into the SUCI.
5. The UE according to claim 1, wherein the SUCI in NAI format includes an indication of whether the SUCI is derived from the IMSI of the UE or from the NAI.
6. The UE according to claim 1, wherein the processor is further configured to convert the digits of the IMSI of the UE into a domain name.
7. Receiving an identification information request from the non-3GPP access network, and transmitting the SUCI in NAI format to the non-3GPP access network for authentication of the UE is performed in response to the identification information request from the non-3GPP access network. Receiving an Extensible Authentication Protocol and Key Sharing Prime (EAP-AKA’) challenge from a network element of the non-3GPP access network; Deriving one or more keys using any value related to the serving network name of the non-3GPP access network; Transmitting an EAP response to the network element of the non-3GPP access network; Receiving EAP success from the network element of the non-3GPP access network; The UE according to claim 1, further configured to start communication on the non-3GPP access network via the network element of the non-3GPP access network using the one or more derived keys in response to receiving the EAP success.
8. A method for 5G network authentication for supporting 5G non-seamless WLAN offload (NSWO) on a non-3GPP access network, comprising: Checking, by a processor of a user equipment (UE), a Universal Subscriber Identity Module (USIM) or mobile equipment (ME) setting regarding an indication that the UE should use 5G NSWO; In response to the USIM or the ME setting indicating that the UE should use 5G NSWO, Generating, by the processor of the UE, a Subscriber Concealed Identifier (SUCI) in a Network Access Identifier (NAI) format; Transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE.
9. The method according to claim 8, wherein generating, by the processor of the UE, the SUCI in the NAI format comprises encrypting a Mobile Subscriber Identification Number (MSIN) obtained from the International Mobile Subscriber Identity (IMSI) of the UE by the processor of the UE and including the encrypted MSIN in the SUCI.
10. Generating, by the processor of the UE, the SUCI in the NAI format comprises Obtaining, by the ME function of the UE, an encrypted MSIN from the USIM of the UE; The method according to claim 8, comprising: using the encrypted MSIN to generate the SUCI in the NAI format by the ME function.
11. The method according to claim 8, wherein generating the SUCI in the NAI format by the processor of the UE includes encrypting the username part of the NAI and incorporating the encrypted username part in the NAI into the SUCI.
12. The method according to claim 8, wherein the SUCI in the NAI format includes an indication of whether the SUCI is derived from the IMSI of the UE or from the NAI.
13. The method according to claim 8, wherein generating the SUCI in the NAI format by the processor of the UE includes converting the digits of the IMSI of the UE into a domain name.
14. Transmitting, by the processor of the UE, the SUCI in the NAI format to the non-3GPP access network for authentication of the UE is performed in response to receiving, by the UE, an identification information request from the non-3GPP access network. The method is receiving an Extensible Authentication Protocol and Key Sharing Prime (EAP-aka') challenge from a network element of the non-3GPP access network; deriving one or more keys using any value related to the serving network name of the non-3GPP access network; transmitting an EAP response to the network element of the non-3GPP access network; starting communication on the non-3GPP access network via the network element of the non-3GPP access network using the one or more derived keys; further comprising starting communication on the non-3GPP access network via the network element of the non-3GPP access network is receiving EAP success from the network element of the non-3GPP access network; starting communication on the non-3GPP access network via the network element of the non-3GPP access network in response to receiving the EAP success, the method according to claim 8. A computer program comprising processor-executable instructions which, when executed by a processing device within a user equipment (UE), cause the processing device to perform the method according to claim 8.