Authentication for devices with non-cellular access
The method addresses the challenge of authenticating non-3GPP devices by establishing secure connections using a registration and authentication process, ensuring secure network access for non-cellular devices.
Patent Information
- Application Number
- JP2025507296
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-08
- Filing Date
- 2023-08-07
- Publication Date
- 2025-09-09
AI Technical Summary
Existing communication systems face challenges in authenticating and securing data communications for terminal devices accessing networks via non-cellular mechanisms, particularly non-3GPP devices, as existing certification processes do not adequately cover these devices.
A method and apparatus for authenticating devices with non-cellular access, involving a registration request and authentication process to establish secure connections using security information, ensuring devices like AUN3 devices are identified and authorized, and protecting network slice information.
Ensures secure connections for non-cellular devices, protecting network and device security by authenticating and establishing connections using authentication credentials, thus addressing the authentication gap for non-3GPP devices.
Smart Images

Figure 2025529729000001_ABST
Abstract
Description
[Technical Field]
[0001] Various exemplary embodiments of the present disclosure relate generally to the field of telecommunications, and more particularly to authentication methods, devices, apparatus, and computer-readable storage media for devices with non-cellular access. [Background technology]
[0002] With the rapid development of communication technology, communication systems can accommodate various types of access technologies for terminal devices. For example, the terminal devices can be connected to the 3rd Generation Partnership Project (3GPP) rd A terminal device may connect to a communication network via a cellular access mechanism, such as a 3GPP (3GPP Generation Partnership Project) access mechanism. Alternatively, in some scenarios, the terminal device may connect to the communication network via a non-cellular access mechanism, such as a non-3GPP access mechanism. Recent communication technologies have proposed that terminal devices accessing a network via a non-cellular mechanism must be authenticated or registered with the network before communicating. Such an authentication or registration process can ensure the security of data communications. Work is underway to introduce authentication for devices with non-cellular access. Summary of the Invention
[0003] In a first aspect of the present disclosure, a first device is provided, the first device comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first device to at least: send to a second device a registration request for a third device, the registration request indicating at least that the third device is accessing a network via a non-cellular mechanism; receive from the second device a first message indicating that the third device has been authenticated; and, based on the receipt of the first message, send to the fourth device security information for establishing a connection between the third device and a fourth device.
[0004] In a second aspect of the present disclosure, a second device is provided, the second device comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second device to at least: receive from the first device a registration request for a third device, the registration request at least indicating that the third device is accessing the network via a non-cellular mechanism; send to the fifth device an authentication request for the third device, the authentication request at least indicating that the third device is accessing the network via a non-cellular mechanism; and send to the first device a first message indicating that the third device has been authenticated.
[0005] In a third aspect of the present disclosure, a third device is provided, the third device comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third device to at least: send a message to at least one of the first device or the fourth device indicating that the third device is accessing a network via a non-cellular mechanism; determine security information for establishing a connection between the third device and the fourth device; and perform procedures for establishing a connection with the fourth device based on the security information.
[0006] In a fourth aspect of the present disclosure, a fourth apparatus is provided, the fourth apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the fourth apparatus to at least receive, from the first apparatus, security information for establishing a connection between a third apparatus and the fourth apparatus, and perform a procedure for establishing a connection with the third apparatus based on the security information.
[0007] In a fifth aspect of the present disclosure, a fifth apparatus is provided, the fifth apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fifth apparatus to at least: receive, from the second device, a first authentication request for a third device, the first authentication request indicating at least that the third device is accessing the network via a non-cellular mechanism; and send, to a sixth device, a second authentication request for the third device.
[0008] In a sixth aspect of the present disclosure, a method is provided, the method including: sending, from a first device to a second device, a registration request for a third device, the registration request indicating at least that the third device is accessing a network via a non-cellular mechanism; receiving, from the second device, a first message indicating that the third device has been authenticated; and, based on the receipt of the first message, sending, to the fourth device, security information for establishing a connection between the third device and the fourth device.
[0009] In a seventh aspect of the present disclosure, a method is provided, the method including: a second device receiving, from a first device, a registration request for a third device, the registration request indicating at least that the third device is accessing a network via a non-cellular mechanism; sending, to a fifth device, an authentication request for the third device, the authentication request indicating at least that the third device is accessing the network via the non-cellular mechanism; and sending a first message to the first device indicating that the third device has been authenticated.
[0010] In an eighth aspect of the present disclosure, a method is provided, the method including: sending a message from the third device to at least one of the first device or the fourth device, the message at least indicating that the third device is accessing a network via a non-cellular mechanism; determining security information for establishing a connection between the third device and the fourth device; and performing a procedure for establishing a connection with the fourth device based on the security information.
[0011] In a ninth aspect of the present disclosure, there is provided a method, the method including: a fourth device receiving, from a first device, security information for establishing a connection between a third device and the fourth device; and performing, based on the security information, a procedure for establishing the connection with the third device.
[0012] In a tenth aspect of the present disclosure, a method is provided, the method including: a fifth device receiving, from a second device, at least a first authentication request for a third device, the first authentication request indicating that the third device is accessing the network via a non-cellular mechanism; and sending, to a sixth device, a second authentication request for the third device.
[0013] In an eleventh aspect of the present disclosure, there is provided a computer-readable medium having stored thereon instructions for causing an apparatus to perform at least a method according to the sixth, seventh, eighth, ninth or tenth aspects.
[0014] It should be understood that the summary section is not intended to identify key or essential features of the embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become readily apparent through the following description.
[0015] Some example embodiments will now be described with reference to the accompanying drawings. [Brief explanation of the drawings]
[0016] [Figure 1] 1 illustrates an exemplary communication environment in which exemplary embodiments of the present disclosure may be practiced. [Figure 2] 1 is a signaling chart for authenticating a device according to some example embodiments of the present disclosure. [Figure 3] 10 is another signaling chart for authenticating a device according to some example embodiments of the present disclosure. [Figure 4] 1 is a flowchart of a method performed in a first device according to some exemplary embodiments of the present disclosure. [Figure 5] 10 is a flowchart of a method performed on a second device according to some exemplary embodiments of the present disclosure. [Figure 6] 10 is a flowchart of a method implemented in a third device according to some exemplary embodiments of the present disclosure. [Figure 7] 10 is a flowchart of a method implemented in a fourth apparatus according to some exemplary embodiments of the present disclosure. [Figure 8] 5 is a flowchart of a method implemented in a fifth apparatus according to some exemplary embodiments of the present disclosure. [Figure 9] FIG. 1 is a simplified block diagram of a device suitable for practicing exemplary embodiments of the present disclosure. [Figure 10] 1 is a block diagram of an exemplary computer-readable medium according to some exemplary embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0017] Throughout the drawings, the same or similar reference numbers represent the same or similar elements.
[0018] The principles of the present disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are set forth for illustrative purposes only to aid those skilled in the art in understanding and practicing the present disclosure, without implying any limitation on the scope of the present disclosure. The embodiments described herein can be implemented in a variety of ways other than those described below.
[0019] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0020] References in this disclosure to "one embodiment," "an embodiment," "an exemplary embodiment," etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but do not require that all embodiments include the particular feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with one embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments, whether or not explicitly stated.
[0021] Terms such as "first," "second," and the like may be used herein to describe various elements, but it should be understood that these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, a first element can be referred to as a second element, and similarly, a second element can be referred to as a first element without departing from the scope of the exemplary embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.
[0022] As used herein, unless expressly stated, performing a step "in response to A" does not indicate that the step is performed immediately after "A" occurs, and may include one or more intervening steps.
[0023] The terms used herein are used only for the purpose of describing particular embodiments and are not intended to limit example embodiments. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly dictates otherwise. It is further understood that the terms "comprise," "comprising," "having," "having," "including," and / or "including," as used herein, specify the presence of stated features, elements, and / or components, etc., but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0024] As used herein, the term "circuitry" may refer to one or more or all of the following: (a) hardware-only circuit implementations (e.g., implementations using only analog and / or digital circuitry); and (b) A combination of hardware circuitry and software, such as (where applicable): (i) A combination of analog and / or digital hardware circuitry(s) and software / firmware. (ii) any portion of a hardware processor(s) comprising software (including a digital signal processor), software, and memory(s) that work together to cause a device, such as a mobile phone or server, to perform various functions; (c) Hardware circuit(s) and / or processor(s), such as microprocessor(s) or portions of microprocessors, that require software (e.g., firmware) to operate but that the software may not be present when not required for operation.
[0025] This definition of circuit applies to all uses of the term in this application, including all claims. As a further example, when used in this application, the term circuit also covers simply a hardware circuit or processor (or processors), or a portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware implementation. The term circuit, when applied to certain claim elements, also covers, for example, similar integrated circuits in mobile devices or servers, baseband integrated circuits or processor integrated circuits for cellular network devices, or other computing or network devices.
[0026] As used herein, the term "communication network" refers to a network conforming to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), or Narrow Band Internet of Things (NB-IoT). Furthermore, communication between terminal devices and network devices within a communication network may be performed via any suitable generation communication protocol, including, but not limited to, first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G) communication protocols, and / or any other protocols currently known or developed in the future. Embodiments of the present disclosure may be applied to various communication systems. Given the rapid development in communications, there will naturally be future types of communication technologies and systems in which the present disclosure may be embodied. The scope of the present disclosure should not be considered limited to only the above-mentioned systems.
[0027] As used herein, the term "network device" refers to a node in a communication network through which a terminal device accesses the network and receives services therefrom. A network device may refer to a base station (BS) or an access point (AP), and may include a variety of network devices, such as a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a repeater, an Integrated Access and Backhaul (IAB) node, a low-power node such as a femto or pico node, a non-terrestrial network (NIN) or non-terrestrial network device such as a satellite network device, a low Earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an airborne network device, etc., depending on the terminology and technology applied. In some exemplary embodiments, a radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node, where the IAB node comprises a Mobile Terminal (IAB-MT) portion that acts like a UE with respect to the parent node, and a DU portion of the IAB node that acts like a base station with respect to the next-hop IAB node.
[0028] The term "terminal device" refers to any end device that may be capable of wireless communication. By way of example and not limitation, a terminal device may be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices include, but are not limited to, mobile phones, cellular phones, smartphones, voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), Internet of Things (loT) devices, watches or other wearables, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, and the like. A terminal device may correspond to a Mobile Termination (MT) portion of an IAB node (e.g., a relay node). In the following description, the terms "terminal device," "communication device," "terminal," "user equipment," and "UE" may be used interchangeably.
[0029] Example Environment 1 illustrates an exemplary communication environment 100 in which exemplary embodiments of the present disclosure can be implemented. In the communication environment 100, a terminal device 110 accesses a communication network, such as a 5G Core (5GC) network or any other suitable network. The communication environment 100 can accommodate different types of access technologies, such as cellular access or non-cellular access.
[0030] Terminal device 110 may access a communication network via a non-cellular mechanism or non-cellular access. As used herein, a terminal device that accesses a communication network via a non-cellular mechanism may be referred to as a non-cellular device or a device with non-cellular access. Non-cellular access may include non-3GPP access. Terminal device 110 with non-3GPP access may connect to a communication network using a non-3GPP access technology but does not support a non-access stratum (NAS) above the non-3GPP access. Such a terminal device may be referred to as a non-3GPP device or a device with non-3GPP access. It will be understood that terminal device 110 also supports cellular access or 3GPP access in some circumstances. Unless explicitly stated, in some exemplary embodiments, terminal device 110 accesses a communication network via a non-cellular mechanism.
[0031] In some exemplary embodiments, a non-3GPP device may include an authenticable non-3GPP (AUN3) device. As used herein, the term “AUN3 device” may refer to a device that a communication network, such as a 5GC network, can authenticate or identify. An AUN3 device may not support NAS over non-3GPP access but may possess network authentication credentials, such as 5G authentication credentials or other suitable authentication credentials. For example, an AUN3 device may have a universal subscriber identity module (USIM) but no protocol stack or NAS. In some exemplary embodiments, an AUN3 device may support a network authentication method, such as a 5GC authentication method. Alternatively, or in addition, an AUN3 device may have a contract with a network, such as a 5GC network.
[0032] Terminal device 110 may access the communication network through a network device such as a residential gateway (RG) 120 (also referred to as a Wireless Local Area Network (WLAN) Access Point (AP)) or any other suitable network device. For example, terminal device 110 may access the communication network by connecting to RG 120 via a WLAN or a wired line. Terminal device 110 using non-3GPP mechanisms or devices may connect to RG 120 using non-3GPP access technologies but are not capable of NAS over non-3GPP access.
[0033] The communication environment 100 includes a wireline access gateway function (W-AGF) 130 connected to an RG 120. The RG 120 may connect to a communication network via a 3GPP access or W-AGF 130. The communication environment 100 may include an access and mobility management function (AMF) 140 and a security anchor function (SEAF) 145 connected to the W-AGF 130, an authentication server function (AUSF) 150 connected to the AMF 140 and the SEAF 145, and a unified data management (UDM) 160 connected to the AUSF 150.
[0034] The AMF 140 may include registration and connection management, as well as other suitable functions. For example, the AMF 140 may support authentication of the terminal device 110. The SEAF 145 may support authentication of the terminal device 110. The AUSF 150 may provide authentication server functionality and other suitable functions. The UDM 160 may support authentication credential generation, subscription management, and other suitable functions.
[0035] It will be understood that the number of devices and their connections shown in FIG. 1 are for illustrative purposes only, without implying any limitation. Communications environment 100 may comprise any suitable number of devices for implementing exemplary embodiments of the present disclosure. Although not shown, it will be understood that one or more additional devices may be disposed in communications environment 100 and one or more additional devices may be connected to communications environment 100. It will be understood that in some exemplary embodiments, communications environment 100 may include more or fewer devices or apparatuses. For example, communications environment 100 may not include AMF 140 or SEAF 145.
[0036] It will also be understood that the exemplary communication environment 100 is shown for illustrative purposes only, without implying any limitation on the scope of the present disclosure, and that embodiments of the present disclosure may be applied to communication environments having different structures.
[0037] Communications in communication environment 100 may be implemented via any suitable communications protocol, including, but not limited to, cellular communications protocols such as first generation (1G), second generation (2G), third generation (3G), fourth generation (4G), fifth generation (5G), sixth generation (6G), wireless local network communications protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocols now known or developed in the future. Furthermore, communications may utilize any suitable wireless communication technology, including, but not limited to, Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM), and / or other technologies now known or developed in the future.
[0038] As mentioned above, terminal devices may connect to a communication network via non-cellular mechanisms, such as non-3GPP access mechanisms, and in order to ensure the security of data communications of such terminal devices, an authentication or registration process needs to be performed on the terminal devices.
[0039] Some solutions have been proposed to address differentiated services (such as quality of service or charging) for various types of non-3GPP devices and terminal devices connected behind a 5G RG. Some other solutions have been proposed to certify non-5G capable (N5GC) devices. However, such N5GC certification processes only consider wired devices that connect to the RG using Ethernet and cannot cover non-3GPP devices such as AUN3 devices. Certification or authorization of non-3GPP devices has not yet been addressed.
[0040] Principles of Operation and Exemplary Signaling for Communication As described above, authenticating a device with non-cellular access is difficult. According to an exemplary embodiment of the present disclosure, a solution is provided for authenticating a device with non-cellular access. In this solution, a first device sends a registration request for a third device to a second device. The registration request indicates that the third device is accessing the network via a non-cellular mechanism. That is, the registration request indicates that the third device is a device with non-cellular access. The first device receives a message from the second device indicating that the third device has been authenticated. Upon receiving the message, the first device transmits security information to the fourth device to establish a connection between the third device and the fourth device.
[0041] In this way, the third device can be authenticated, a secure connection can be established between the third device and the network, and the security of both the third device and the network can be ensured.
[0042] Exemplary embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.
[0043] 2 illustrates a signaling chart 200 for authenticating devices according to some exemplary embodiments of the present disclosure. As shown in FIG. 2, the signaling chart 200 includes a first device 201, a second device 202, a third device 203, a fourth device 204, a fifth device 205, and a sixth device 206. In some exemplary embodiments, the first device 201 may be the W-AGF 130 of FIG. 1, the second device 202 may be the AMF 140 or the SEAF 145 of FIG. 1, the third device 203 may be the terminal device 110 of FIG. 1, the fourth device 204 may be the RG 120 of FIG. 1, the fifth device 205 may be the AUSF 150 of FIG. 1, and the sixth device 206 may be the UDM 160 of FIG. 1.
[0044] Although FIG. 2 shows one first device 201, one second device 202, one third device 203, one fourth device 204, one fifth device 205 and one sixth device 206, it will be understood that there may be multiple devices performing similar operations, as described below with respect to the first device 201, the second device 202, the third device 203, the fourth device 204, the fifth device 205 or the sixth device 206.
[0045] During operation, a connection may be established 210 between the third device 203 and the fourth device 204. For example, a WLAN connection may be established 210 between the third device 203 and a WLAN access network (AN) by using IEEE 802.11 or other suitable procedures. In another example, a wired connection may be established 210 between the third device 203 and the fourth device 204.
[0046] In some exemplary embodiments, the identity lookup process 213 may occur between the third device 203, the fourth device 204, and the first device 201. For example, a message (referred to as an identity message) having the identity of the third device 203 may be sent to the fourth device 204 and the first device 201. Alternatively, in some exemplary embodiments, the identity message having the identity of the third device 203 may be sent by the third device 203 to the fourth device 204. The fourth device 204 may forward the identity message to the first device 201.
[0047] The identity message or identity of the third device 203 may at least indicate that the third device 203 is accessing the network via a non-cellular mechanism. For example, the identity of the third device 203 may indicate a device type of the third device 203. The device type indicates an access type associated with the non-cellular mechanism used by the third device 203. That is, the device type may indicate a non-cellular mechanism.
[0048] The device type may include a non-cellular device type, a non-3GPP device type, an AUN3 device type, or any other suitable type. For example, the device type of the third device 203 being a non-cellular type may indicate that the access type of the third device 203 is non-cellular access. In other words, the non-cellular access type is associated with a non-cellular mechanism. That is, the third device 203 accesses the network via a non-cellular mechanism.
[0049] Similarly, the device type of the third device 203 being a non-3GPP type or an AUN3 type may indicate that the access type of the third device 203 is a non-3GPP access without NAS. In other words, the non-3GPP access type without NAS is associated with a non-3GPP mechanism without NAS. That is, the third device 203 accesses the network via a non-3GPP mechanism without NAS.
[0050] In some exemplary embodiments, the identity of the third device 203 may be in a network access identifier (NAI) format, such as "username@realm." In other words, the identity message may include the NAI of the third device 203 in a form such as "username@realm." It will be understood that the above exemplary names of NAI formats are for illustrative purposes only, without implying any limitation. Any other suitable format may also be applied.
[0051] In some demonstrative embodiments, the third device identity message may further include an identifier of the third device 203, for example, a subscription permanent identifier (SUPI) of the third device 203. Alternatively, the identification of the third device 203 may include a subscription concealed identifier (SUCI), an identifier in an NAI format such as a SUCI in an NAI format, or an identifier within a globally unique temporary identifier such as 5G-GUTI.
[0052] Alternatively, or additionally, in some exemplary embodiments, a layer 2 (L2) connection between the third device 203, the fourth device 204, and the first device 201 may be established. The L2 connection or L2 data link may support extensible authentication protocol (EAP) encapsulation. An EAP identity lookup process may occur over the L2 connection. For example, the first device 201 may send an EAP identity request to the third device 203. Based on receiving the EAP identity request, the third device 203 may send an EAP response or an EAP message along with its identity to the first device 201 and the fourth device 204. The EAP request, EAP response, or EAP message may be encapsulated within an L2 frame, such as EAP over line (EAPOL). The exemplary messages, requests, or responses described below may be encapsulated within an L2 frame, such as EAPOL. It will be understood that the identity lookup process 213 involving EAP requests and responses is for illustrative purposes only, without implying any limitation. Any suitable identity lookup process 213 may be applied.
[0053] Based on the identity of the third device 203, the first device 201 may generate 216 a registration request for the third device 203. For example, the first device 201 may generate 216 a registration request on behalf of the third device 203 based on the received identity message. The generated registration request indicates at least that the third device 203 is accessing the network via a non-cellular mechanism.
[0054] By indicating a non-cellular mechanism in the registration request, a non-cellular device, such as an AUN3 device, may be identified by other devices. In this way, other devices may distinguish the non-cellular device from other devices, such as 3GPP devices. Thus, other devices may recognize the need for authentication for a device, such as an AUN3 device.
[0055] In some demonstrative embodiments, the registration request may include an indication of the need for an encryption key for the third device 203. Alternatively, or in addition, the registration request may include an indication of the device type of the third device 203. For example, the indication of the need for a key encryption key may include an AUN3 device encryption required indication flag. This flag may indicate that the third device 203 is an AUN3 device (i.e., the third device 203 is accessing the network via a non-3GPP mechanism without a NAS) and that the encryption required indication for the third device is true. This flag may also indicate that the registration request is on behalf of an AUN3 device and may indicate that protection is required for the interface between the AUN3 device (which is the third device 203) and the fourth device 204. In other words, this flag may indicate that the AUN3 device is requesting encryption or security information.
[0056] The indication of device type may include an explicit indication such as a field such as "AUN3 Device". The indication of device type may be in NAI format. For example, the indication may be: "<5G_device_unique_identity>@nai.aun3.5gc-nn.mnc <mnc>.mcc <mcc>.3gppnetwork.org」、 「<5G_device_unique_identity>@5gc.aun3.mnc <mnc>.mcc <mcc>The device type indication may be an NAI with "AUN3" information, such as ".3gppnetwork.org". The device type indication may indicate that the third device 203 is an AUN3 device, i.e., an AUN3 device that accesses the network via a non-3GPP mechanism without a NAS is requesting registration.
[0057] Alternatively, or in addition, in some exemplary embodiments, the registration request may indicate an identification of the third device 203. For example, in examples in which the received identity of the third device includes an identification such as a SUPI of the third device 203, the registration request may include a SUCI of the third device 203. This SUCI may be generated by the first device 201 based on the SUPI by using a NULL scheme.
[0058] In some exemplary embodiments, the registration request may further include a wired network name, such as a Service Network Name (SN-name), if available. An exemplary registration request may include Registration Request (SUCI, SN-name, AUN3 Device Encryption Required Indication flag). It will be understood that the above example is for illustrative purposes only, without implying any limitation. Any other suitable information may be included in the registration request.
[0059] In some demonstrative embodiments, the first device 201 may perform additional operations, such as selecting a second device 202. For example, the first device 201 may select the AMF 140 or the SEAF 145 of Figure 1 as the second device 202. The first device 201 may select the second device 202 using any suitable method.
[0060] The first device 201 sends (219) a registration request for the third device 203 to the second device 202. The second device 202 receives (222) the registration request. The second device 202 sends (225) a first authentication request for the third device 203 to the fifth device 205. The first authentication request indicates at least that the third device is accessing the network via a non-cellular mechanism. The first authentication request may further include other information, such as identification information for the third device 203 or other information included in the registration request.
[0061] In an embodiment where the registration request includes Registration Request (SUCI, SN-name, AUN3 device encryption required indication flag), an example of the first authentication request may include Nausf_UEAuthentication_AuthenticateRequest (SUCI, SN-name, AUN3 device encryption required indication flag). It will be understood that the above example of the first authentication request is for illustrative purposes only, without implying any limitation.
[0062] The fifth device 205 receives (228) the first authentication request. The fifth device 205 sends (231) a second authentication request for the third device 203 to the sixth device 206. The second authentication may be similar to the first authentication. In some exemplary embodiments, the content of the first and second authentication requests may be the same. Alternatively, the second authentication may not indicate a non-cellular mechanism used by the third device 203.
[0063] In some example embodiments, the second authentication request may indicate that a session key is required by the third device 203. In examples in which the first authentication request includes Nausf_UEAuthentication_AuthenticateRequest(SUCI, SN-name, AUN3 device encryption required indication flag), the second authentication request may include Nudm_UEAuthentication_AuthenticateRequest(SUCI, SN-name, optional flag AUN3 device encryption required indication).
[0064] It will be understood that the above examples of first and second authentication challenges are for illustrative purposes only, without implying any limitation. Any other suitable authentication challenge may also be applied.
[0065] The sixth device 206 receives 234 a second authentication request for the third device 203 from the fifth device 205. In some demonstrative embodiments, the sixth device 206 may initiate an authentication procedure 237 for the third device 203. For example, the sixth device 206 may decipher the SUCI included in the second authentication request to obtain the SUPI of the third device 203. In addition, the sixth device 206 may perform an authentication selection, such as selecting an authentication procedure 237, based on the second authentication request. The sixth device 206 may initiate the selected authentication procedure 237. Any suitable selection method may be used by the sixth device. The scope of the present disclosure is not limited in this respect.
[0066] In some exemplary embodiments, authentication procedure 237 may include an EAP-transport level security (EAP-TLS) authentication procedure or may be referred to as an authentication procedure for EAP-TLS 237. Any suitable EAP-TLS authentication procedure may be applied. Alternatively, or in addition, other authentication procedures described below may be applied.
[0067] Taking the EAP-TLS authentication procedure as an example, if the authentication procedure is successful, the fifth device 205 may determine that the third device 203 has been authenticated based on the authentication procedure 237 initiated by the sixth device 206. In such a scenario, the fifth device 205 sends 243 an authentication response to the second device 202. In some example embodiments, the authentication response may indicate that the third device 203 has been authenticated.
[0068] Alternatively, or in addition, the authentication response may include security information of the third device 203. In embodiments in which the authentication response includes security information, the fifth device 205 may generate 240 the security information based on the authentication credentials of the third device 203, e.g., the EAP authentication credentials of the AUN3 device.
[0069] In some exemplary embodiments, the security information may include a session key of the third device, such as a master session key (MSK), an extended master session key (EMSK), etc. Although the generation of security information (240) is shown after the authentication procedure 237, it should be understood that in some exemplary embodiments, the generation of security information may occur before or during the authentication procedure 237.
[0070] An exemplary authentication response including security information may include Nausf_UEAuthentication_AuthenticateResponse(EAP-Success, EMSK). It will be understood that the above exemplary authentication response is for illustrative purposes only, without implying any limitation. Any other suitable authentication response may also be applied.
[0071] The second device 202 receives (246) the authentication response. The second device 202 sends (249) a first message to the first device 201 indicating that the third device 203 has been authenticated. For example, the second device 202 sends (249) the first message based on receiving the authentication response. Alternatively, in some exemplary embodiments, the second device may send (249) the first message under other conditions. The first device 201 receives (252) the first message.
[0072] In embodiments in which the authentication response includes security information of the third device 203, the first message may include the security information. In embodiments in which the authentication response includes Nausf_UEAuthentication_AuthenticateResponse(EAP-Success, EMSK), the first message may include Authentication_Result(EAP-Success, EMSK). It will be understood that the above exemplary first message is for illustrative purposes only, without implying any limitation. Any other suitable first message may also be applied.
[0073] The first device 201 transmits (255) the security information of the third device 203 to the fourth device 204 to establish a connection between the third device 203 and the fourth device 204. In such case, the fourth device receives (258) the security information. Examples of security information have been provided above and will not be repeated here.
[0074] In some demonstrative embodiments, first device 201 may send 261 a second message to third device 203 indicating that third device 202 has been authenticated. For example, first device 201 may send 261 an EAP-Success message to third device 203 over the L2 connection. Third device 203 may receive 264 the second message.
[0075] The third device 203 may generate (267) a key for communicating with the fourth device. Similarly, the fourth device 204 may generate (270) the same key for communicating with the third device 203. For example, the key may include a WLAN key. In some exemplary embodiments, the third device 203 may generate (267) a key, such as a WLAN key, based on authentication credentials of the third device 203. For example, based on receiving (264) the second message, the third device 203 may generate (267) a key, such as a WLAN key, based on the authentication credentials. In some exemplary embodiments, the fourth device 204 may generate (270) a key, such as a WLAN key, based on the security information received (258).
[0076] Some solutions propose establishing a connection between a terminal device and a network node by using the network node's slice information. However, such solutions expose the network node's slice information to the terminal device. This may pose a security threat to the company that owns the network or slice. How to select a trusted non-3GPP gateway function (TNGF) or non-3GPP interworking function (N3IWF) that supports the single network slice selection assistance information (S-NASSAI(s)) requested by the terminal device during authentication or registration via a non-3GPP access network remains a concern.
[0077] In some exemplary embodiments according to the present disclosure, the third device 203 and the fourth device 204 perform procedures with each other to establish a connection based on the above security information. Details regarding the establishment of the connection are described below.
[0078] In some demonstrative embodiments, the third device 203 and the fourth device 204 perform a procedure with each other to establish a connection based on security information. This procedure may include a handshake procedure 273. For example, the third device 203 and the fourth device 204 may perform the handshake procedure 273 using security information such as an EMSK. The handshake procedure 273 may include a four-way handshake procedure. By performing the handshake procedure 273, the third device can establish a secure connection with a WLAN AP (e.g., an RG).
[0079] By using the present connection establishment process illustrated in signaling chart 200, the slice information of the network node may not be used for authentication for the device with non-cellular access. For example, the third device may use the security information to generate a WLAN key for establishing a connection. The security information may be generated based on the authentication credentials of the third device. Thus, the slice information of the network node may be protected. The network and the company that owns the slice are protected.
[0080] An exemplary embodiment of authentication for devices using non-cellular mechanisms is described with respect to Figure 2. With such authentication for devices, devices with non-cellular access, such as AUN3 devices behind an RG connecting to a network, can be identified, authorized, and authenticated. In this way, a security connection is established so that communication security can be protected.
[0081] In the embodiment of Fig. 2, an EAP-TLS authentication procedure is used as an example of an authentication procedure, although other types of authentication procedures may alternatively or additionally be applied.
[0082] 3 shows another signaling chart 300 for authenticating devices according to some exemplary embodiments of the present disclosure. In the signaling chart 300, a different authentication procedure 310 may be applied than the authentication procedure 237 of FIG. 2, which will be described below. As shown in FIG. 3, similar to the signaling chart 200, the signaling chart 300 includes a first device 201, a second device 202, a third device 203, a fourth device 204, a fifth device 205, and a sixth device 206.
[0083] In some demonstrative embodiments, the first device 201 may be the W-AGF 130 of FIG. 1 , the second device 202 may be the AMF 140 or the SEAF 145 of FIG. 1 , the third device 203 may be the terminal device 110 of FIG. 1 , the fourth device 204 may be the RG 120 of FIG. 1 , the fifth device 205 may be the AUSF 150 of FIG. 1 , and the sixth device 206 may be the UDM 160 of FIG. 1 .
[0084] Although one first device 201, one second device 202, one third device 203, one fourth device 204, one fifth device 205 and one sixth device 206 are shown in FIG. 3, it is recognized that there may be multiple devices performing similar operations as described below with respect to the first device 201, the second device 202, the third device 203, the fourth device 204, the fifth device 205 or the sixth device 206.
[0085] In operation, the devices participating in the signaling chart may perform similar processes or actions before the authentication procedure 310 for the third device 203. For clarity of explanation, similar processes or actions designated with the same reference numerals will not be described again here. In the signaling chart 300, the sixth device 206 may select a different authentication procedure 310 than the authentication procedure 237. The sixth device 206 may initiate the authentication procedure 310.
[0086] In some example embodiments, the authentication procedure 310 may include an extensible authentication protocol-authentication and key agreement (EAP-AKA) procedure, an improved EAP-AKA (EAP-AKA') procedure, or a 5G authentication and key agreement (5G AKA) procedure. Any suitable EAP-AKA, EAP-AKA', or 5G AKA procedure may be applied.
[0087] In some exemplary embodiments, the second device 202 may generate (313) a first key for the first device 201. For example, the second device 202 may generate (313) the first key based at least in part on an access type associated with a non-cellular mechanism used by the third device 203. In some exemplary embodiments, the second device 202 may obtain the associated access type for the third device 203 based on the registration request it received (222). In some exemplary embodiments, the second device 202 may generate (313) its own key (K AMF ) and the associated access type of the third device 203, WAGF ) may be generated (313).
[0088] In some exemplary embodiments, the second device 202 derives the first key K using a key derivation function (KDF). WAGF The second device 202 may generate 313 the following parameters as input S to the KDF: FC=0x6E or 0x<To be defined>, Pl=Access type discriminator, LI = Length of Access Type Discriminator (i.e. 0x00, 0x01).
[0089] In some exemplary embodiments, the access type discriminator values for different devices may be determined based on a predetermined table, for example, Table 1 below.
[0090] [Table 1]
[0091] For example, in an embodiment where the associated access type of the third device 203 (e.g., a non-3GPP device) indicates non-3GPP access, the access type distinguisher may be K WAGF In an embodiment where the associated access type of the third device 203 (e.g., an AUN3 device) indicates a non-3GPP access without NAS, the access type discriminator may be set to a value of "non-3GPP access" when deriving K WAGF may be set to the value of "non-3GPP access without NAS", e.g., 0x03, when deriving
[0092] It will be understood that the above parameters for generating 313 the first keys and their corresponding values are for illustrative purposes only, without implying any limitation. Any suitable approach for determining the device key can be applied. For example, an additional parameter L0 representing the length of a device discriminator having a value (e.g., 0x00, 0x04, etc.) may be applied. In addition, an additional parameter P0 representing a device discriminator (which may be set to 0x01 for AUN3 devices, but set to 0x00 otherwise) may be applied.
[0093] The second device 202 sends a first message to the first device 201 indicating that the third device 203 has been authenticated (316). For example, the second device 202 may determine that the authentication procedure 310 for the third device 203 was successful. Based on the determination of successful authentication of the third device 203, the second device 202 sends a first message to the first device (316). The first message may include an authentication success message, such as an EAP success message, indicating successful authentication of the third device. For example, the first message may be a NAS security mode command mode having a zero-security algorithm, such as an N2 message - NAS Security Mode Command (Null security algorithm, [EAP-Success]). It will be understood that the example first message is for illustrative purposes only, without implying any limitation. Any suitable first message may be applied.
[0094] The first device 201 receives the first message (319). The first device 201 stores the first message (322), or may alternatively store the EAP success message included in the first message.
[0095] In some exemplary embodiments, the first device 201 transmits (325) a second message to the second device 202 indicating completion of the security mode. For example, based on receiving (319) the first message, or alternatively, based on storing (322) the first message, the first device 201 transmits (325) the second message. An example of the second message may include the N2 message NAS security mode complete. It will be understood that the example second message is for illustrative purposes only, without implying any limitation. Any suitable second message may be applied.
[0096] In some demonstrative embodiments, the second device 202 receives (328) the second message. Based on receiving the second message, the second device 202 may transmit (331) a first key to the first device 201. The first key may be generated (313) by the second device 202. For example, the second device 202 may generate (313) the first key K WAGF along with an N2 Initial Ctx setup request or other appropriate information to the first device 201.
[0097] In some exemplary embodiments, the first device 201 WAGF The first device 201 may receive (334) a first key such as K WAGF The third device 203 may generate (337) security information for the third device 203 based on the first key, such as the first key, e.g., the Pairwise Master Key (PMK) of the third device 203. For example, the security information may include a key for the third device 203, such as a Pairwise Master Key (PMK) of the third device 203.
[0098] In some example embodiments, the first device 201 uses the KDF to derive a first key K WAGF The PMK (K AUN3 For example, the first device 201 may input the following parameters to the input S to the KDF: FC=0x<To be defined>, P0 = Usage type discriminator (i.e., 0x01), L0 = Length of Usage type discriminator (i.e., 0x00, 0x01).
[0099] It will be understood that the above parameters for generating 337 security information such as a PMK and their corresponding values are for illustrative purposes only, without implying any limitations. Any suitable approach for determining a device key may be applied.
[0100] The first device 201 transmits (340) security information, such as a PMK, to the fourth device 204 for establishing a connection between the third device 203 and the fourth device 204. Based on receiving (319) the first message, the first device 201 transmits (340) the security information. For example, based on receiving (319) the first message, the first device 201 may receive (334) a first key from the second device 202, generate (337) security information based on the first key, and transmit (340) the security information. In some exemplary embodiments, the first device 201 may transmit an authentication success message, such as an EAP success message, to the fourth device 204 along with the security information. For example, the first device 201 may transmit (EAP-Success, PMK) to the fourth device 204.
[0101] Fourth device 204 receives (343) the security information from first device 201. In some exemplary embodiments, fourth device 204 may further receive an authentication success message, such as an EAP success message, from first device 201 along with the security information. For example, fourth device 204 may receive, for example, (EAP-Success, PMK) from first device 201.
[0102] In some demonstrative embodiments, the fourth device 204 may send (346) an authentication success message, such as an EAP success message, to the third device 203. The third device 203 may receive (349) the authentication success message, such as an EAP notification or (EAP-Success) message.
[0103] In some demonstrative embodiments, the third device 203 may generate 352 a key for communicating with the fourth device. Similarly, the fourth device 204 may generate 355 the same key for communicating with the third device 203. For example, the same key may include a WLAN key.
[0104] In some exemplary embodiments, the third device 203 may generate 352 a key, such as a WLAN key, based on an associated access type of the third device 203. For example, the third device 203 may generate a PMK (or K) based on an associated access type of the third device 203 (e.g., non-3GPP access without NAS). AUN3 The third device may generate a PMK using the same KDF. The method for generating a PMK by using a KDF has been described above and will not be repeated here.
[0105] The third device 203 may generate a WLAN key based on the PMK (352). In some exemplary embodiments, the fourth device 204 generates a WLAN key based on the PMK (or K AUN3 Based on the received (343) security information, such as a WLAN key, a key may be generated (355).
[0106] The third device 203 and the fourth device 204 perform a procedure with each other to establish a connection based on the security information. This procedure may include a handshake procedure 358. For example, the third device 203 and the fourth device 204 may perform the handshake procedure 358 using security information such as a PMK. The handshake procedure 358 may include a four-way handshake. By performing the handshake procedure 358, the third device 203 (e.g., an AUN3 device) can establish a secure connection with a WLAN AP (e.g., an RG).
[0107] In some demonstrative embodiments, a secure connection 361 between the third device 203 and the fourth device 204 may be established. The secure connection may include an L2 connection or a layer 3 (L3) connection. Alternatively, or in addition, the first device 201 may send (364) an N2 Initial Ctx Setup Response to the second device 202. For example, the N2 Initial Ctx Setup Response may correspond to an N2 Initial Ctx Setup Request received from the second device 202 along with the first key. The second device 202 may receive (367) the N2 Initial Ctx Setup Response.
[0108] An exemplary embodiment of authentication for devices with non-cellular access will be described with reference to Fig. 3. In the embodiment of Fig. 3, an EAP-AKA authentication procedure is used as an example of an authentication procedure. In such authentication for devices with non-cellular access, devices with non-cellular access, such as AUN3 devices behind an RG connected to a network, can be identified, authorized, and authenticated. In this way, a security connection can be established, and communication security can be protected.
[0109] Furthermore, by using the present connection establishment process illustrated in signaling chart 300, the slice information of the network node may not be used for authentication for devices with non-cellular access. For example, the third device may use the security information to generate a WLAN key for establishing a connection. The security information may be generated based on the third device's associated access type. Thus, the slice information of the network node can be protected. The network and company that owns the slice are protected.
[0110] It will be understood that authentication procedure 237 and authentication procedure 310 are shown for illustrative purposes only, without implying any limitation in scope. Any suitable authentication procedure may be applied to authenticate the third device. It will also be understood that signaling chart 200 of FIG. 2 and signaling chart 300 of FIG. 3 are shown for illustrative purposes only, without implying any limitation. Signaling chart 200 or signaling chart 300 may include additional processes or actions not shown and / or may omit some of the processes or actions shown, and the scope of the present disclosure is not limited in this respect.
[0111] Exemplary Methods 4 shows a flowchart of an example method 400 implemented in a first device according to some example embodiments of the present disclosure. In some example embodiments, the first device may include a network device such as the first device 201 of FIG. 2 or the W-AGF 130 of FIG. 1. For convenience of explanation, the method 400 will be described from the perspective of the first device 201 in FIG. 2.
[0112] In block 410, the first device 201 sends a registration request for the third device 203 to the second device 202. The registration request indicates at least that the third device 203 is accessing the network via a non-cellular mechanism. For example, the registration request may include an indication of the need for a key encryption key for the third device 203. Alternatively, or in addition, the registration request may include an indication of the device type of the third device 203.
[0113] In block 420, the first device 201 receives a first message from the second device 202 indicating that the third device 203 has been authenticated. In some example embodiments, the first message may further include security information. For example, the security information may include a session key for the third device 203, such as a master session key or an extended master session key.
[0114] In block 430, based on receiving the first message, the first device 201 sends security information to the fourth device 204 to establish a connection between the third device 203 and the fourth device 204.
[0115] In some exemplary embodiments, the first message may further include a request for security mode. In such a case, based on receiving the first message, the first device 201 may send a second message to the second device 202 indicating completion of the security mode. The first device 201 may receive a first key for the first device 201 from the second device 202. The first key may be determined by the second device 202 based on an access type associated with the non-cellular mechanism. The first device 201 may generate security information based on the first key. For example, the security information may include a pairwise master key of the third device 203.
[0116] In some demonstrative embodiments, first device 202 may receive a third message from third device 203 or fourth device 204 indicating at least that third device 203 is accessing the network via a non-cellular mechanism. Additionally, first device 202 may generate a registration request based on the third message.
[0117] In some demonstrative embodiments, the third message and the registration request may each further indicate an identification of the third device 203. For example, the identification of the third device 203 may include at least one of a subscription hiding identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.
[0118] In some exemplary embodiments, the first device 201 may include a wired access gateway function, the second device 202 may include an access and mobility management function or a security anchor function, the third device 203 may include an authenticatable non-3G Partnership Project device, and the fourth device 204 may include a residential gateway.
[0119] 5 illustrates a flowchart of an example method 500 implemented in a second device according to some example embodiments of the present disclosure. In some example embodiments, the second device may include a network device such as the AMF 140 or the SEAF 145 of FIG. 1 or the second device 202 of FIG. 2. For convenience of explanation, the method 500 will be described from the perspective of the second device 202 in FIG. 2.
[0120] In block 510, the second device 202 receives a registration request for the third device 203 from the first device 201. The registration request indicates at least that the third device 203 is accessing the network via a non-cellular mechanism. For example, the registration request may include an indication of the need for a key encryption key for the third device 203. Alternatively, or in addition, the registration request may include an indication of the device type of the third device 203.
[0121] In block 520, the second device 202 sends an authentication request for the third device to the fifth device 205. The authentication request indicates at least that the third device is accessing the network via a non-cellular mechanism.
[0122] At block 530, second device 202 sends a first message to first device 201 indicating that third device 203 has been authenticated. In some demonstrative embodiments, at block 530, second device 202 may determine that the authentication procedure for third device 203 was successful. Based on the determination that the authentication procedure was successful, second device 202 sends the first message.
[0123] In some demonstrative embodiments, the second device 202 further receives an authentication response to the authentication request from the fifth device 205. The authentication response may indicate that the third device has been authenticated. The authentication response may include security information of the third device 203. In such a case, the first message may further include the security information.
[0124] Alternatively, or in addition, the first message may further include a request for a security mode. In such a case, the second device 202 may further generate a first key for the first device based on an access type associated with the non-cellular mechanism. The second device 202 may further receive a second message from the first device 202 indicating completion of the security mode. Based on receiving the second message, the second device 202 may further transmit the first key to the first device 201.
[0125] In some exemplary embodiments, the first device 201 may include wired access gateway functionality, the second device 202 may include access and mobility management functionality or security anchor functionality, the third device 203 may include an authenticatable non-3G Partnership Project device, and the fifth device 205 may include authentication server functionality.
[0126] 6 shows a flowchart of an example method 600 implemented in a third device according to some example embodiments of the present disclosure. For example, the third device may include a terminal device such as the terminal device 110 of FIG. 1 or the third device 203 of FIG. 2. For convenience of explanation, the method 600 will be described from the perspective of the third device 203 in FIG. 2.
[0127] At block 610, the third device 203 sends a message to at least one of the first device 201 or the fourth device 204 indicating at least that the third device 203 is accessing the network via a non-cellular mechanism. For example, the third device 203 may send the message to the first device 201. Alternatively, or in addition, the third device 203 may send the message to the fourth device 204. In some exemplary embodiments, the message may further indicate an identification of the third device 203. For example, the identification of the third device may include at least one of a subscription hiding identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.
[0128] In block 620, the third device 203 determines security information for establishing a connection between the third device 203 and the fourth device 204. For example, the third device 203 may determine the security information based on authentication credentials of the third device 203. Alternatively, or in addition, in some exemplary embodiments, the third device 203 may determine the security information based at least in part on an access type associated with a non-cellular mechanism.
[0129] In some exemplary embodiments, the security information may include one of a session key for the third device or a pairwise master key for the third device. For example, the session key may include one of a master session key or an extended master session key.
[0130] In block 630, the third device 203 performs procedures to establish a connection with the fourth device 204 based on the security information.
[0131] In some demonstrative embodiments, the third device 203 may further generate a key for communicating with the fourth device 204 based on the security information.
[0132] In some exemplary embodiments, the third device 203 may include an authenticatable non-3G Partnership Project device, and the fourth device may include a residential gateway.
[0133] 7 shows a flowchart of an example method 700 implemented in a fourth device according to some example embodiments of the present disclosure. For example, the fourth device may include a network device such as RG 120 of FIG. 1 or fourth device 204 of FIG. 2. For convenience of explanation, method 700 will be described from the perspective of fourth device 204 in FIG. 2.
[0134] In block 710 , the fourth device 204 receives security information from the first device 201 to establish a connection between the third device 203 and the fourth device 204 .
[0135] In block 720, the fourth device 104 performs procedures to establish a connection with the third device 203 based on the security information.
[0136] In some demonstrative embodiments, the fourth device 204 may further generate a key for communicating with the third device 203 based on the security information.
[0137] In some demonstrative embodiments, fourth device 204 may further receive a first message from third device 203 indicating at least that third device 203 is accessing the network via a non-cellular mechanism. Based on receiving the first message, fourth device 204 may send a second message to first device 201 indicating at least that third device 203 is accessing the network via a non-cellular mechanism.
[0138] In some exemplary embodiments, the first device 201 may include wired access gateway functionality, the third device 203 may include an authenticatable non-3G Partnership Project device, and the fourth device 204 may include a residential gateway.
[0139] 8 illustrates a flowchart of an example method 800 implemented in a fifth device according to some example embodiments of the present disclosure. In some example embodiments, the fifth device may include a network device such as the AUSF 150 of FIG. 1 or the fifth device 205 of FIG. 2. For convenience of explanation, the method 800 will be described from the perspective of the fifth device 205 in FIG. 2.
[0140] In block 810, the fifth device 205 receives a first authentication request from the second device 202 for the third device 203. The first authentication request indicates at least that the third device 203 is accessing the network via a non-cellular mechanism.
[0141] In block 820, the fifth device 205 sends a second authentication request to the sixth device 206 for the third device 203. In some example embodiments, the second authentication request may indicate that the third device 203 is accessing the network via a non-cellular mechanism.
[0142] In some demonstrative embodiments, the fifth device 205 further generates security information for the third device 203 based on the authentication credentials of the third device 203. The fifth device 205 may determine that the third device 203 has been authenticated based on the authentication procedure initiated by the sixth device 206. Based on the determination that the third device 203 has been authenticated, the fifth device 205 may send an authentication response to the second device 202 that includes security information indicating that the third device 203 has been authenticated.
[0143] In some demonstrative embodiments, the security information may include a session key for the third device 203. For example, the session key may include one of a master session key or an extended master session key.
[0144] In some example embodiments, the authentication procedure may include one of an Extensible Authentication Protocol-Transport Level Security procedure, an Extensible Authentication Protocol-Authentication and Key Agreement procedure, or a 5G Mobile Communications Technology Authentication and Key Agreement procedure.
[0145] In some exemplary embodiments, the second device 202 may include access and mobility management or security anchor functionality, the third device 203 may include an authenticatable non-3G Partnership Project device, the fifth device 205 may include authentication server functionality, and the sixth device 206 may include unified data management.
[0146] It should be understood that method 400, method 500, method 600, method 700, or method 800 may include additional blocks not shown and / or omit some of the blocks shown, and the scope of the disclosure is not limited in this respect.
[0147] Exemplary Apparatus, Device and Medium In some demonstrative embodiments, a first device capable of performing any of method 400 (e.g., first device 201 in FIG. 2 ) may include means for performing each operation of method 400. The means may be embodied in any suitable form. For example, the means may be implemented as a circuit or a software module. The first device may be implemented as or included in first device 201 in FIG. 2 .
[0148] In some demonstrative embodiments, the first device includes means for sending to the second device a registration request to the third device, the registration request indicating at least that the third device is accessing the network via a non-cellular mechanism; means for receiving from the second device a first message indicating that the third device has been authenticated; and means for sending to the fourth device security information for establishing a connection between the third device and the fourth device based on receipt of the first message.
[0149] In some example embodiments, the registration request may include an indication of the need for a key encryption key for the third device. Alternatively, or in addition, the registration request may include an indication of the device type of the third device.
[0150] In some exemplary embodiments, the first message may further include security information, such as a session key of the third device, such as at least one of a master session key or an extended master session key.
[0151] In some exemplary embodiments, the first message may further include a request for security mode. In such a case, the first device may further include means for sending a second message to the second device based on receipt of the first message, the second message indicating completion of the security mode, means for receiving from the second device a first key for the first device, the first key determined by the second device based on an access type associated with the non-cellular mechanism, and means for generating security information based on the first key. For example, the security information may include a pairwise master key of the third device.
[0152] In some demonstrative embodiments, the first device may further include means for receiving a third message from the third device or the fourth device, the third message indicating at least that the third device is accessing the network via a non-cellular mechanism. Additionally, the first device may further include means for generating a registration request based on the third message.
[0153] In some demonstrative embodiments, the third message and the registration request may each further indicate an identification of the third device. For example, the identification of the third device may include at least one of a subscription hiding identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.
[0154] In some exemplary embodiments, the first device further includes means for performing other operations in method 400 or some exemplary embodiments of first device 201. In some exemplary embodiments, the means comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the first device to perform the operations.
[0155] In some demonstrative embodiments, a second device (e.g., second device 202 in FIG. 2 ) capable of performing any of method 500 may include means for performing each operation of method 500. The means may be implemented in any suitable form. For example, the means may be implemented by a circuit or a software module. The second device may be implemented as second device 202 in FIG. 2 or may be included in the second device.
[0156] In some demonstrative embodiments, the second device comprises means for receiving from the first device a registration request for the third device, the registration request indicating at least that the third device is accessing the network via a non-cellular mechanism; means for sending to the fifth device an authentication request for the third device, the authentication request indicating at least that the third device is accessing the network via a non-cellular mechanism; and means for sending to the first device a first message indicating that the third device has been authenticated.
[0157] For example, the registration request may include at least one of an indication of a need for a key encryption key for the third device, or an indication of a device type of the third device.
[0158] In some demonstrative embodiments, the means for transmitting the first message may further comprise means for determining that the authentication procedure for the third device is successful, and means for transmitting the first message based on a determination that the authentication procedure is successful.
[0159] In some exemplary embodiments, the second device may further include means for receiving an authentication response to the authentication request from the fifth device. The authentication response may indicate that the third device has been authenticated. The authentication response may include security information for the third device. In such a case, the first message may further include the security information.
[0160] Alternatively, or in addition, the first message may further include a request for a security mode. In such case, the second device may further comprise means for generating a first key for the first device based on an access type associated with the non-cellular mechanism, means for receiving a second message from the first device indicating completion of the security mode, and means for transmitting the first key to the first device based on receipt of the second message.
[0161] In some exemplary embodiments, the second device further comprises means for performing other operations in method 500 or in some exemplary embodiments of second device 202. In some exemplary embodiments, the means comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the second device to perform operations.
[0162] In some demonstrative embodiments, a third device (e.g., third device 203 in FIG. 2 ) capable of performing any of method 600 may include means for performing each operation of method 600. The means may be implemented in any suitable form. For example, the means may be implemented by a circuit or a software module. The third device may be implemented as third device 203 in FIG. 2 or may be included in the third device.
[0163] In some demonstrative embodiments, the third device comprises means for sending a message to at least one of the first device or the fourth device indicating at least that the third device is accessing the network via a non-cellular mechanism, means for determining security information for establishing a connection between the third device and the fourth device, and means for performing a procedure for establishing a connection with the fourth device based on the security information.
[0164] In some demonstrative embodiments, the message may further indicate an identification of the third device. For example, the identification of the third device may include at least one of a subscription hiding identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.
[0165] In some exemplary embodiments, the means for determining the security information may comprise means for determining the security information based on authentication credentials of the third device. Alternatively, or in addition, the means for determining the security information may include means for determining the security information based at least in part on an access type associated with the non-cellular mechanism. In such cases, the means for determining the security information may comprise means for determining the security information based at least in part on the associated access type.
[0166] In some exemplary embodiments, the security information may include one of a session key for the third device or a pairwise master key of the third device. For example, the session key may include one of a master session key or an extended master session key.
[0167] In some demonstrative embodiments, the third device may further comprise means for generating a key for communicating with the fourth device based on the security information.
[0168] In some exemplary embodiments, the third device further comprises means for performing other operations in method 600 or in some exemplary embodiments of third device 203. In some exemplary embodiments, the means comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the third device to perform operations.
[0169] In some demonstrative embodiments, a fourth device (e.g., fourth device 204 in FIG. 2 ) capable of performing any of method 700 may include means for performing each operation of method 700. The means may be implemented in any suitable form. For example, the means may be implemented as a circuit or a software module. The fourth device may be implemented as or included in fourth device 204 in FIG. 2 .
[0170] In some demonstrative embodiments, the fourth device comprises means for receiving, from the first device, security information for establishing a connection between the third device and the fourth device, and means for performing a procedure for establishing a connection with the third device based on the security information.
[0171] In some demonstrative embodiments, the fourth device may further include means for generating a key for communicating with the third device based on the security information.
[0172] In some demonstrative embodiments, the fourth device may further comprise means for receiving from the third device a first message indicating at least that the third device is accessing the network via a non-cellular mechanism, and means for, based on receipt of the first message, sending to the first device a second message indicating at least that the third device is accessing the network via a non-cellular mechanism.
[0173] In some exemplary embodiments, the fourth device further includes means for performing other operations in method 700 or in some exemplary embodiments of fourth device 204. In some exemplary embodiments, the means comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the fourth device to perform the operations.
[0174] In some demonstrative embodiments, a fifth device (e.g., fifth device 205 in FIG. 2 ) capable of performing any of method 800 may include means for performing each operation of method 800. The means may be embodied in any suitable form. For example, the means may be implemented as a circuit or a software module. The fifth device may be implemented as or included in fifth device 205 in FIG. 2 .
[0175] In some exemplary embodiments, the fifth device comprises means for receiving, from the second device, a first authentication request for a third device, the first authentication request indicating at least that the third device is accessing the network via a non-cellular mechanism, and means for sending a second authentication request for the third device to the sixth device. In some exemplary embodiments, the second authentication request may indicate that the third device is accessing the network via a non-cellular mechanism.
[0176] In some demonstrative embodiments, the fifth device comprises means for generating security information for the third device based on authentication credentials of the third device; means for determining that the third device has been authenticated based on the authentication procedure initiated by the sixth device; and means for sending an authentication response to the second device, based on the determination that the third device has been authenticated, indicating that the third device has been authenticated and including the security information.
[0177] In some example embodiments, the security information may include a session key of the third device. For example, the session key may include one of a master session key or an extended master session key.
[0178] In some exemplary embodiments, the authentication procedure may include one of an Extensible Authentication Protocol-Transport Level Security procedure, an Extensible Authentication Protocol-Authentication and Key Agreement procedure, or a 5G Mobile Communications Technology Authentication and Key Agreement procedure.
[0179] In some exemplary embodiments, the fifth device further comprises means for performing other operations in method 800 or in some exemplary embodiments of fifth device 205. In some exemplary embodiments, the means comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the fifth device to perform operations.
[0180] 9 is a simplified block diagram of a device 900 suitable for practicing an exemplary embodiment of the present disclosure. The device 900 may be configured to implement a communications device, such as the terminal device 110, the RG 120, the W-AGF 130, the AMF 140, the SEAF 145, the AUSF 150, or the UDM 160 as shown in FIG. 1 , or the first device 201, the second device 202, the third device 203, the fourth device 204, the fifth device 205, or the sixth device 206 as shown in FIG. 2 . As shown, the device 900 includes one or more processors 910, one or more memories 920 coupled to the processor 910, and one or more communications modules 940 coupled to the processor 910.
[0181] The communications module 940 is for two-way communication. The communications module 940 includes one or more communications interfaces that facilitate communication with one or more other modules or devices. The communications interfaces may correspond to any interface necessary for communication with other network elements. In some exemplary embodiments, the communications module 940 may include at least one antenna.
[0182] The processor 910 may be of any type suitable for a local technology network and may comprise, by way of non-limiting example, one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. The device 900 may comprise multiple processors, such as application-specific integrated circuit chips time-slaved to a clock that synchronizes a main processor.
[0183] The memory 920 may comprise one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memory include, but are not limited to, Read Only Memory (ROM) 924, electrically programmable read only memory (EPROM), flash memory, hard disks, compact discs (CDs), digital video discs (DVDs), optical disks, laser discs, and other magnetic and / or optical storage. Examples of volatile memory include, but are not limited to, random access memory (RAM) 922 and other volatile memory that does not persist during periods when power is turned off.
[0184] The computer program 930 includes computer-executable instructions that are executed by an associated processor 910. The instructions of the program 930 may include instructions for performing the operations / acts of some exemplary embodiments of the present disclosure. The program 930 may be stored in a memory, such as the ROM 924. The processor 910 can load the program 930 into the RAM 922 to perform any appropriate operations and processes.
[0185] An exemplary embodiment of the present disclosure may be implemented by a program 930 such that the device 900 may perform any process of the present disclosure as described with reference to Figures 2 to 8. An exemplary embodiment of the present disclosure may be implemented by hardware or a combination of software and hardware.
[0186] In some exemplary embodiments, the program 930 may be physically contained in a computer-readable medium, which may be contained in the device 900 (in memory 920) or other storage device accessible by the device 900. The device 900 may load the program 930 from the computer-readable medium into RAM 922 for execution. In some exemplary embodiments, the computer-readable medium may include any type of non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. The term "non-transitory" as used herein is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on the persistence of data storage (e.g., RAM vs. ROM).
[0187] 10 shows an example of a computer readable medium 1000, which may be in the form of a CD, DVD or other optical storage disc. The computer readable medium 1000 has a program 930 stored thereon.
[0188] In general, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described using block diagrams, flowcharts, or some other graphical representations, it will be understood that the blocks, apparatus, systems, techniques, or methods described herein may be implemented in, by way of non-limiting example, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing device, or some combination thereof.
[0189] Some exemplary embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer-readable medium, such as a non-transitory computer-readable medium. The computer program product includes computer-executable instructions, such as those included in program modules, that execute on a target real or virtual processor to perform any of the methods described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split among program modules as desired in various embodiments. The machine-executable instructions of a program module may be executed in a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0190] Program code for carrying out the methods of the present disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be performed. The program code may be executed entirely on the machine, partly on the machine and partly as a stand-alone software package, partly on the machine and partly on a remote machine, or entirely on a remote machine or server.
[0191] In the context of the present disclosure, computer program code or associated data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations as described above. Examples of carriers include signals, computer-readable media, etc.
[0192] The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, device, or any suitable combination thereof. More specific examples of the computer-readable storage medium include an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0193] Additionally, although operations are depicted in a particular order, this should not be understood as requiring such operations to be performed in the particular order or sequential order shown, or that all illustrated operations be performed, to achieve desirable results. In certain situations, multitasking and parallel processing may be advantageous. Similarly, while the above discussion includes details of several specific implementations, these should not be construed as limitations on the scope of the disclosure, but rather as descriptions of features that may be unique to particular embodiments. Unless expressly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless expressly stated, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable subcombination.
[0194] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the present disclosure, as defined by the appended claims, is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.< / mcc> < / mnc> < / mcc> < / mnc>
Claims
1. at least one processor; at least one memory storing instructions that, when executed by the at least one processor, cause the first device to: sending a registration request to the second device for the third device, the registration request indicating at least that the third device is accessing the network via a non-cellular mechanism; receiving a first message from the second device indicating that the third device has been authenticated; transmitting security information to the fourth device based on receiving the first message to establish a connection between the third device and the fourth device; at least one memory that causes at least A first device comprising:
2. The registration request an indication of the need for a key-encrypting key for a third device; or and an indication of a device type of the third device.
3. The first device of claim 1 , wherein the first message further includes security information.
4. 4. The first device of claim 3, wherein the security information includes a session key for the third device.
5. The session key is Master Session Key, or Extended Master Session Key, The first device of claim 4 , comprising one of:
6. the first message further includes a request for a security mode; a first device; transmitting a second message to the second device indicating completion of the security mode based on receipt of the first message; receiving, from the second device, a first key for the first device, the first key determined by the second device based on an access type associated with the non-cellular mechanism; generating security information based on the first key; The first device of claim 1 , further comprising:
7. 7. The first device of claim 6, wherein the security information includes a pairwise master key of the third device.
8. a first device; receiving a third message from a third device or a fourth device indicating at least that the third device is accessing the network via a non-cellular mechanism; generating a registration request based on the third message; The first device of claim 1 , further comprising:
9. The first device of claim 8 , wherein the third message and the registration request each further indicate an identity of the third device.
10. The identification of the third device is Subscription concealment identifier, an identifier in the Network Access Identifier format, or an identifier in the Globally Unique Temporary Identifier format, The first device of claim 9 , comprising at least one of:
11. the first device has a wired access gateway function; the second device comprises an access and mobility management function or a security anchor function; the third device comprises an authenticatable non-3G Partnership Project device; The first device of claim 1 , wherein the fourth device comprises a residential gateway.
12. at least one processor; at least one memory storing instructions that, when executed by the at least one processor, cause the second device to: receiving, from the first device, a registration request for a third device, where at least the third device is accessing the network via a non-cellular mechanism; sending an authentication request for the third device to the fifth device, the authentication request indicating at least that the third device is accessing the network via a non-cellular mechanism; sending a first message to the first device indicating that the third device has been authenticated; at least one memory that causes at least A second device comprising:
13. The registration request an indication of the need for an encryption key for a third device; or an indication of the device type of the third device; The second device of claim 12, comprising at least one of:
14. In a second device, 14. The second device of claim 13, further configured to receive an authentication response to an authentication request from a fifth device, the authentication response indicating that the third device has been authenticated and including security information for the third device.
15. The second device of claim 14 , wherein the first message further includes security information.
16. Sending the first message determining that the authentication procedure for the third device was successful; and transmitting a first message based on a determination that the authentication procedure was successful; and The second device of claim 12, comprising:
17. the first message further includes a request for a security mode; In a second device, generating a first key for the first device based on an access type associated with the non-cellular mechanism; receiving a second message from the first device indicating completion of the security mode; transmitting a first key to the first device based on receiving the second message; The second device of claim 12 , further comprising:
18. the first device has a wired access gateway function; the second device comprises an access and mobility management function or a security anchor function; the third device comprises an authenticatable non-3G Partnership Project device; The second device of claim 12 , wherein the fifth device comprises an authentication server function.
19. at least one processor; at least one memory storing instructions that, when executed by the at least one processor, cause the third device to: sending a message to at least one of the first device or the fourth device indicating at least that the third device is accessing the network via a non-cellular mechanism; determining security information for establishing a connection between the third device and the fourth device; performing a procedure for establishing a connection with a fourth device based on the security information; at least one memory that causes at least a third device comprising:
20. a third device; 20. The third device of claim 19, further configured to generate a key for communicating with the fourth device based on the security information.
21. Determining security information determining security information based on authentication credentials of a third device; or determining security information based at least in part on an access type associated with the non-cellular mechanism; 20. The third device of claim 19, comprising at least one of:
22. 20. The third device of claim 19, wherein the message further indicates an identity of the third device.
23. The identification of the third device is Subscription concealment identifier, an identifier in the Network Access Identifier format, or an identifier in the Globally Unique Temporary Identifier format, 23. The third device of claim 22, comprising at least one of:
24. Security information is a session key for a third device, or a pairwise master key of the third device; 20. The third device of claim 19, comprising one of:
25. The session key is Master Session Key, or Extended Master Session Key, 25. The third device of claim 24, comprising one of:
26. 20. The third device of claim 19, wherein the third device comprises an authenticatable non-3G Partnership Project device, and the fourth device comprises a residential gateway.
27. at least one processor; at least one memory storing instructions that, when executed by the at least one processor, cause the fourth device to: receiving security information from the first device for establishing a connection between the third device and the fourth device; performing a procedure for establishing a connection with a third device based on the security information; at least one memory that causes at least A fourth apparatus comprising:
28. A fourth device 28. The fourth device of claim 27, further configured to generate a key for communicating with a third device based on the security information.
29. A fourth device receiving a first message from a third device indicating at least that the third device is accessing the network via a non-cellular mechanism; based on receiving the first message, sending a second message to the first device indicating at least that the third device is accessing the network via a non-cellular mechanism; 28. The fourth apparatus of claim 27, further comprising:
30. the first device has a wired access gateway function; the third device comprises an authenticatable non-3G Partnership Project device; 28. The fourth device of claim 27, wherein the fourth device comprises a residential gateway.
31. at least one processor; at least one memory storing instructions that, when executed by the at least one processor, cause the fifth device to: receiving, from the second device, a first authentication request for a third device, the first authentication request indicating at least that the third device is accessing the network via a non-cellular mechanism; sending a second authentication request for the third device to a sixth device; at least one memory that causes at least A fifth apparatus comprising:
32. 32. The fifth device of claim 31, wherein the second authentication request indicates that the third device is accessing the network via a non-cellular mechanism.
33. A fifth device, generating security information for the third device based on the authentication credentials of the third device; determining that the third device is authenticated based on an authentication procedure initiated by the sixth device; based on determining that the third device is authenticated, sending an authentication response to the second device indicating that the third device is authenticated and including security information; 32. The fifth apparatus of claim 31, further comprising:
34. 34. The fifth device of claim 33, wherein the security information includes a session key for the third device.
35. The session key is Master Session Key, or 35. The fifth apparatus of claim 34, further comprising one of: an extended master session key;
36. The authentication procedure is Extensible Authentication Protocol - Transport Level Security Procedures, Extensible Authentication Protocol - authentication and key agreement procedures, or 5G mobile communication technology authentication and key agreement procedures; 32. The fifth device of claim 31, comprising one of:
37. the second device comprises an access and mobility management function or a security anchor function; the third device comprises an authenticatable non-3G Partnership Project device; a fifth device having an authentication server function; 32. The fifth device of claim 31, wherein the sixth device comprises a unified data management.
38. 1. A method comprising: sending a registration request from the first device to the second device for the third device, the registration request indicating at least that the third device is accessing the network via a non-cellular mechanism; receiving a first message from the second device indicating that the third device has been authenticated; transmitting security information to the fourth device based on receiving the first message to establish a connection between the third device and the fourth device; A method comprising:
39. 1. A method comprising: receiving, by the second device, from the first device, a registration request for a third device, where at least the third device is accessing the network via a non-cellular mechanism; sending an authentication request for the third device to the fifth device, the authentication request indicating at least that the third device is accessing the network via a non-cellular mechanism; sending a first message to the first device indicating that the third device has been authenticated; A method comprising:
40. 1. A method comprising: sending a message from the third device to at least one of the first device or the fourth device indicating at least that the third device is accessing the network via a non-cellular mechanism; determining security information for establishing a connection between the third device and the fourth device; performing a procedure for establishing a connection with a fourth device based on the security information; A method comprising:
41. 1. A method comprising: receiving, by the fourth device, from the first device, security information for establishing a connection between the third device and the fourth device; performing a procedure for establishing a connection with a third device based on the security information; A method comprising:
42. 1. A method comprising: receiving, by the fifth device, from the second device, a first authentication request for the third device, the first authentication request indicating at least that the third device is accessing the network via a non-cellular mechanism; sending a second authentication request to the sixth device for the third device; A method comprising:
43. 1. A computer-readable medium, comprising: A computer readable medium having stored thereon instructions for causing an apparatus to perform at least the method of claim 38, the method of claim 39, the method of claim 40, the method of claim 41, or the method of claim 42.
Citation Information
Patent Citations
Method and apparatus for providing security for connections over heterogeneous access networks
JP2021533680A
Methods and apparatuses for determining an authentication type
WO2021244737A1