Determining credentials for device-to-device services

By determining authentication vectors based on Serving Network Names, the method secures device-to-device communication by ensuring trusted UE-to-UE proximity services, addressing the challenge of secure authentication in wireless networks.

JP2025536296AActive Publication Date: 2025-11-05NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025522020
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-11-01
Publication Date
2025-11-05
Estimated Expiration
2042-11-01

AI Technical Summary

Technical Problem

Existing communication systems face challenges in securely establishing device-to-device proximity services, particularly in determining authentication vectors for user equipment (UEs) in wireless networks, which is crucial for ensuring secure communication links.

Method used

The apparatus and methods involve determining an authentication vector based on a Serving Network Name (SNN) for UE-to-UE proximity services, using network nodes and user equipment to exchange and derive authentication information through Extensible Authentication Protocol (EAP) messages, ensuring secure communication between UEs.

Benefits of technology

This approach enhances the security and reliability of device-to-device communication by establishing secure authentication vectors, enabling trusted proximity services between user equipment in wireless networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025536296000001_ABST
    Figure 2025536296000001_ABST
Patent Text Reader

Abstract

An apparatus for a network node is provided, comprising: means for receiving notification of a serving network name of a first user equipment; a first user equipment configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and the second user equipment; means for determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; and means for providing notification of the serving network name of the first user equipment to the second user equipment.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present application relates to methods, apparatus, computer programs and systems for determining authentication information for device-to-device services, particularly but not limited to determining an authentication vector based on a Serving Network Name (SNN) for use in Proximity Services (ProSe). [Background technology]

[0002] A communication system may be considered as a facility that enables communication sessions between two or more entities, such as user terminals, base stations, and / or other nodes, by providing carriers between the various entities involved in the communication paths. A communication system may be provided, for example, by a communication network and one or more compatible communication devices. A communication session may include, for example, communication of data to carry communications such as voice, video, electronic mail (email), text messages, multimedia and / or content data. Non-limiting examples of services provided include two-way or multi-way calls, data communication or multimedia services, and access to a data network system such as the Internet.

[0003] In a wireless communication system, at least a portion of a communication session between at least two stations is conducted over a radio link. Examples of wireless systems include public land mobile networks (PLMNs), satellite-based communication systems, and various wireless local area networks such as wireless local area networks (WLANs). Some wireless systems can be divided into cells, and are therefore sometimes called cellular systems.

[0004] A user can access a communication system by means of a suitable communication device or terminal. A user's communication device may be referred to as user equipment (UE) or user device. The communication device comprises suitable signal transmission and reception equipment to enable communication, e.g., to enable access to a communication network and direct communication with other users. The communication device can access a carrier provided by a base station, e.g., a cell base station, and transmit and / or receive communications on the carrier.

[0005] Communication systems and associated devices typically operate according to predefined standards or specifications that define what various entities associated with the system are allowed to do and how they should accomplish it. The communication protocols and / or parameters used for connectivity are also typically defined. An example of a communication system is UTRAN (3G Radio). Other examples of communication systems include the Long Term Evolution (LTE) of the Universal Mobile Telecommunications System (UMTS) radio access technology and so-called 5G or New Radio (NR) networks. NR is standardized by the 3rd Generation Partnership Project (3GPP®). Summary of the Invention

[0006] In a first aspect, there is provided an apparatus for a network node, the apparatus comprising: means for receiving notification of a serving network name of a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and a second user equipment; means for determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; and means for providing notification of the serving network name of the first user equipment to the second user equipment.

[0007] The apparatus further comprises means for providing authentication information to the second user equipment, the authentication information including an indication of a serving network name of the first user equipment.

[0008] The apparatus may further comprise means for providing authentication information in at least one of a proximity services authentication response, a proximity services authentication request, or an extensible authentication protocol message.

[0009] The apparatus may further comprise means for receiving a serving network name for the first user equipment via at least one of an access and mobility management function associated with the first user equipment or an authentication server function associated with the second user equipment.

[0010] The network nodes may implement unified data management.

[0011] The apparatus may include, be or be contained within a network node.

[0012] In a second aspect, there is provided an apparatus for a first user equipment, comprising: means for receiving notification of a serving network name of a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; and means for determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment.

[0013] The apparatus further comprises means for receiving authentication information at the first user equipment, where the authentication information may include an indication of a serving network name of the second user equipment.

[0014] The apparatus may further comprise means for receiving authentication information in an Extensible Authentication Protocol message.

[0015] The apparatus may further include, be, or be included in a first user equipment.

[0016] In a third aspect, there is provided an apparatus for a network node, the apparatus comprising: means for obtaining a serving network name of a first user equipment; and means for determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network.

[0017] The apparatus may further comprise means for providing an Extensible Authentication Protocol message to the first user equipment, where the Extensible Authentication Protocol challenge message may include a serving network name of the first user equipment.

[0018] The serving network name of the first user equipment may be stored in a universal subscriber identity module of the first user equipment.

[0019] The apparatus may further comprise means for obtaining a serving network name for the first user equipment by obtaining a serving network name for the first user equipment from the storage function.

[0020] The network nodes may implement unified data management.

[0021] The apparatus may include, be or be included in a network node.

[0022] In a fourth aspect, there is provided an apparatus for a first user equipment, comprising: means for obtaining a serving network name of the first user equipment; and means for determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network.

[0023] The apparatus further comprises means for receiving authentication information, the authentication information including a serving network name for the first user equipment.

[0024] The apparatus may further comprise means for receiving authentication information in an Extensible Authentication Protocol message.

[0025] The apparatus may further comprise means for obtaining a serving network name for the first user equipment by obtaining it from a universal subscriber identity module associated with the first user equipment.

[0026] The apparatus may include, be, or be included in a first user equipment.

[0027] In a fifth aspect, there is provided a method comprising: receiving, at a network node, notification of a serving network name of a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and the second user equipment; determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; and notifying the second user equipment of the serving network name of the first user equipment.

[0028] The method further includes providing authentication information to the second user equipment, the authentication information including an indication of a serving network name of the first user equipment.

[0029] The method may further include providing the authentication information in at least one of a proximity service authentication response, a proximity service authentication request, or an extensible authentication protocol message.

[0030] The method may further include receiving a serving network name for the first user equipment via at least one of an access and mobility management function associated with the first user equipment or an authentication server function associated with the second user equipment.

[0031] In a sixth aspect, there is provided a method that includes: receiving, at a first user equipment, notification of a serving network name of a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; and determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment.

[0032] The method further includes receiving authentication information at the first user equipment, the authentication information including an indication of a serving network name of the second user equipment.

[0033] The method may further include receiving the authentication information in an Extensible Authentication Protocol message.

[0034] In a seventh aspect, there is provided a method including: obtaining, at a network node, a serving network name of a first user equipment; and determining, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and the network.

[0035] The method further includes providing an Extensible Authentication Protocol message to the first user equipment, the Extensible Authentication Protocol challenge message including a serving network name of the first user equipment.

[0036] The serving network name of the first user equipment may be stored in a universal subscriber identity module of the first user equipment.

[0037] The method may further include obtaining a serving network name for the first user equipment by obtaining a serving network name for the first user equipment from a storage function.

[0038] In an eighth aspect, there is provided a method including: in a first user equipment, obtaining a serving network name of the first user equipment; and determining, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network.

[0039] The method further includes obtaining authentication information, where the authentication information includes a serving network name of the first user equipment.

[0040] The method may further include receiving the authentication information in an Extensible Authentication Protocol message.

[0041] The method may further include obtaining a serving network name for the first user equipment by obtaining it from a universal subscriber identity module associated with the first user equipment.

[0042] In a ninth aspect, there is provided an apparatus for a network node, the apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform at least: receiving notification of a serving network name of a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and the second user equipment; determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; and notifying the second user equipment of the serving network name of the first user equipment.

[0043] The apparatus may further cause the second user equipment to provide authentication information, where the authentication information may include notification of a serving network name of the first user equipment.

[0044] The device may further provide the authentication information in at least one of a proximity services authentication response, a proximity services authentication request, or an extensible authentication protocol message.

[0045] The apparatus may further receive a serving network name for the first user equipment via at least one of an access and mobility management function associated with the first user equipment or an authentication server function associated with the second user equipment.

[0046] The network nodes may implement unified data management.

[0047] The apparatus may include, be or be included within a network node.

[0048] In a tenth aspect, there is provided an apparatus for a first user equipment, the apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform at least: receiving notification of a serving network name of a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; and determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment.

[0049] The apparatus may be adapted to perform receiving authentication information at the first user equipment, where the authentication information may include an indication of a serving network name of the second user equipment.

[0050] The device may further be adapted to receive authentication information in an Extensible Authentication Protocol message.

[0051] The apparatus may further include, be, or be included in a first user equipment.

[0052] In an eleventh aspect, there is provided an apparatus for a network node, the apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: obtain a serving network name of a first user equipment; and determine, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network.

[0053] The apparatus may further cause the first user equipment to provide an Extensible Authentication Protocol message, where the Extensible Authentication Protocol challenge message may include a serving network name of the first user equipment.

[0054] The serving network name of the first user equipment may be stored in a universal subscriber identity module of the first user equipment.

[0055] The apparatus may further be configured to obtain a serving network name for the first user equipment by obtaining the serving network name for the first user equipment from the storage function.

[0056] The network nodes may implement unified data management.

[0057] The apparatus may include, be or be included in a network node.

[0058] In a twelfth aspect, there is provided an apparatus for a first user equipment, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: obtain a serving network name for the first user equipment; and determine, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network.

[0059] The apparatus may further be adapted to receive authentication information, where the authentication information may include a serving network name for the first user equipment.

[0060] The device may further be adapted to receive authentication information in an Extensible Authentication Protocol message.

[0061] The apparatus may further be configured to obtain a serving network name for the first user equipment by obtaining the serving network name from a universal subscriber identity module associated with the first user equipment.

[0062] The apparatus may include, be, or be included in a first user equipment.

[0063] In a thirteenth aspect, a computer-readable medium is provided that includes instructions that, when executed by an apparatus, cause the apparatus to at least receive, at a network node, notification of a serving network name of a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and the second user equipment; determine an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; and notify the second user equipment of the serving network name of the first user equipment.

[0064] The apparatus may further be caused to provide authentication information to the second user equipment, where the authentication information may include notification of a serving network name of the first user equipment.

[0065] The apparatus may further be configured to provide the authentication information in at least one of a proximity services authentication response, a proximity services authentication request, or an extensible authentication protocol message.

[0066] The apparatus may further be configured to receive, via at least one of an access and mobility management function associated with the first user equipment or an authentication server function associated with the second user equipment, a serving network name for the first user equipment.

[0067] The network nodes may implement unified data management.

[0068] The apparatus may include, be or be included in a network node.

[0069] In a fourteenth aspect, a computer-readable medium is provided that includes instructions that, when executed by an apparatus, cause the apparatus to at least: receive, at a first user equipment, notification of a serving network name of a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; and determine an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment.

[0070] The apparatus can further cause receiving authentication information at the first user equipment, where the authentication information can include notification of a serving network name of the second user equipment.

[0071] The device may further be adapted to receive authentication information in an Extensible Authentication Protocol message.

[0072] The apparatus may further include, be, or be included in a first user equipment.

[0073] In a fifteenth aspect, a computer-readable medium is provided that includes instructions that, when executed by an apparatus, cause the apparatus to at least: obtain, at a network node, a serving network name of a first user equipment; and determine, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network.

[0074] The apparatus may further be configured to provide an Extensible Authentication Protocol message to the first user equipment, where the Extensible Authentication Protocol challenge message may include a serving network name of the first user equipment.

[0075] The serving network name of the first user equipment may be stored in a universal subscriber identity module of the first user equipment.

[0076] The apparatus may further be configured to obtain a serving network name of the first user equipment by obtaining the serving network name of the first user equipment from the storage function.

[0077] The network nodes may implement unified data management.

[0078] The apparatus may include, be or be included in a network node.

[0079] In a sixteenth aspect, a computer-readable medium is provided that includes instructions that, when executed by an apparatus, cause the apparatus to at least: obtain, at a first user equipment, a serving network name of the first user equipment; and determine an authentication vector based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network.

[0080] The apparatus may further include means for receiving authentication information, where the authentication information may include a serving network name for the first user equipment.

[0081] The apparatus may further comprise means for receiving authentication information in an Extensible Authentication Protocol message.

[0082] The apparatus may further comprise means for obtaining a serving network name for the first user equipment by obtaining it from a universal subscriber identity module associated with the first user equipment.

[0083] The apparatus may include, be, or be included in a first user equipment.

[0084] In a seventeenth aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least a method according to any of the fifth to eighth aspects.

[0085] In an eighteenth aspect, there is provided a system comprising an apparatus according to the first aspect and an apparatus according to the second aspect.

[0086] In a nineteenth aspect, there is provided a system comprising an apparatus according to the third aspect and an apparatus according to the fourth aspect.

[0087] A number of different embodiments have been described above, and it should be understood that any two or more of the above-described embodiments may be combined to provide further embodiments. [Brief explanation of the drawings]

[0088] Exemplary embodiments will now be described with reference to the accompanying figures. [Figure 1] FIG. 1 is a schematic diagram of an example 5GS communication system. [Figure 2] FIG. 2 is a schematic diagram of an example mobile communication device. [Figure 3] FIG. 3 is a schematic diagram illustrating an example of a control device. [Figure 4] Figure 4 shows the signaling flow of the 5G ProSe UE-to-network relay security procedure. [Figure 5] Figure 5 shows the signaling flow for ProSe authentication. [Figure 6]FIG. 6 shows a flowchart of a method according to an exemplary embodiment. [Figure 7] FIG. 7 shows a flowchart of a method according to an exemplary embodiment. [Figure 8] FIG. 8 shows a flowchart of a method according to an exemplary embodiment. [Figure 9] FIG. 9 shows a flowchart of a method according to an exemplary embodiment. [Figure 10] FIG. 10 illustrates a signaling flow according to an exemplary embodiment. [Figure 11] FIG. 11 illustrates a signal flow according to an exemplary embodiment. [Figure 12] FIG. 12 illustrates a signaling flow according to an exemplary embodiment. [Figure 13] FIG. 13 illustrates a signaling flow according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0089] Before describing the embodiments in detail, some general principles of wireless communication systems and mobile communication devices will be briefly described with reference to FIGS. 1 to 3 to facilitate understanding of the technology underlying the described embodiments.

[0090] An example of a suitable communication system is the 5G or NR concept. The network architecture of NR may be similar to that of LTE-Advanced. Base stations in an NR system are called next-generation Node Bs (gNBs). Changes in the network architecture may depend on the need to support various radio technologies and more granular QoS support, as well as on-demand requirements such as quality of service (QoS) levels to support user quality of experience (QoE). Network-aware services and applications, as well as service- and application-aware networks, may also lead to architectural changes. These are related to information-centric network (ICN) and user-centric content delivery network (UC-CDN) approaches. NR may use multiple-input-multiple-output (MIMO) antennas, more base stations or nodes than LTE (the so-called small cell concept), and macro sites operating in cooperation with smaller base stations.

[0091] 3GPP (registered trademark) has defined a service-based architecture (SBA) for mobile networks, in which the control plane functions and common data repository of a mobile network are provided as a set of interconnected network functions (NFs), each authorized to access at least some of the services of other network functions. Network functions expose their functionality through a service-based interface (SBI). A service-based interface is, for example, a well-defined Representational State Transition (REST) ​​interface based on HTTP / 2. Network functions may be operationally connected or linked to provide services. Network nodes, such as network elements or general-purpose servers, can implement one or more network functions. Mobile networks may utilize network function virtualization (NFV), in which case network functions may be implemented as virtualized network functions (VNFs) that include one or more virtual machines running on a virtualization platform. The virtualization platform includes one or more virtualized servers, and may be implemented, for example, using general-purpose servers or customized hardware. Cloud computing and data storage may also be utilized. In wireless communications, this may mean node operations being performed, at least in part, on a server, host, or node operatively coupled to a remote radio head. It may also be that node operations are distributed across multiple servers, nodes, or hosts. It should also be understood that the division of roles between core network operations and base station operations may differ from that of LTE or may even not exist.

[0092] 1 illustrates a 5G system (5GS) 100. The 5GS may include a user equipment (UE) 102 (sometimes referred to as communication equipment or terminal), a 5G radio access network (5G RAN) 104, a 5G core network (5G CN) 106, one or more internal or external application functions (AFs) 108, and one or more data networks (DNs) 110.

[0093] An exemplary 5G Core Network (CN) includes functional entities. The 5G CN 106 may include one or more Access and Mobility Management Functions (AMFs) 112, one or more Session Management Functions (SMFs) 114, an Authentication Server Function (AUSF) 116, a Unified Data Management (UDM) 118, one or more User Plane Functions (UPFs) 120, a Unified Data Repository (UDR) 122, and / or a Network Publishing Function (NEF) 124. The UPF is controlled by the SMF (Session Management Function), which receives policies from the PCF (Policy Control Function).

[0094] The CN is connected to the UE via a Radio Access Network (RAN). The 5G RAN may include one or more gNodeB (GNB) distributed unit functions connected to one or more gNodeB (GNB) centralized unit functions. The RAN may include one or more access nodes.

[0095] A User Plane Function (UPF), called a PDU Session Anchor (PSA), may be responsible for forwarding frames back and forth between the DN and the tunnel established over 5G towards the UEs that exchange traffic with the DN.

[0096] A possible mobile communications device will now be described in more detail with reference to FIG. 2 , which illustrates a schematic, partial cross-sectional view of a communications device 200. Such communications devices are often referred to as user equipment (UE) or terminals. A suitable mobile communications device may be provided by any device capable of transmitting and receiving wireless signals. Non-limiting examples include a mobile station (MS), such as a mobile phone or what is known as a “smartphone,” or a mobile device, a wireless interface card or other wireless interface equipment (e.g., a USB dongle), a personal data assistant (PDA) or tablet with wireless communications capabilities, a voice-over-IP (VoIP) phone, a portable computer, a desktop computer, an image capture terminal such as a digital camera, a gaming terminal, a music storage and playback appliance, an in-vehicle wireless terminal, a wireless endpoint, a mobile station, a laptop embedded equipment (LEE), a laptop mounted equipment (LME), a smart device, a wireless customer premises equipment (CPE), or any combination thereof. A mobile communications device may provide data communications for communicating, for example, voice, electronic mail (email), text messages, multimedia, and the like. In this manner, the user equipment may provide a multitude of services via the communications device. Non-limiting examples of these services include two-way or multi-way calls, data or multimedia services, or simply access to a data network system such as the Internet. Broadcast and multicast data may also be provided to users. Non-limiting examples of content include downloads, television programs, radio programs, videos, advertisements, various alerts, and other information.

[0097] A mobile device typically comprises at least one data processing entity 201, at least one memory 202, and possibly other components 203 for use in software- and hardware-assisted execution of the tasks it is designed to perform, including controlling access to and communication with access systems and other communication devices. Data processing, storage, and other related control devices may be provided on a suitable circuit board and / or within a chipset. This functionality is indicated by reference numeral 204. A user may control the operation of the mobile device by means of a suitable user interface, such as a keypad 205, voice commands, a touch-sensitive screen or pad, or a combination thereof. A display 208, a speaker, and a microphone may also be provided. Additionally, the mobile communication device may comprise suitable connectors (either wired or wireless) for connecting to other devices and / or external accessories, e.g., hands-free devices.

[0098] The mobile device 200 can receive signals via an air or wireless interface 207 via suitable devices for reception and can transmit signals via suitable devices for transmitting wireless signals. In Figure 2, a transceiver unit is shown diagrammatically by block 206. The transceiver unit 206 can be provided, for example, by a radio section and associated antenna unit. The antenna unit can be located inside or outside the mobile device.

[0099] FIG. 3 illustrates an example of a controller 300 for a communications system, connected to and / or controlling RAN nodes, e.g., base stations, eNBs or gNBs, relay nodes, or core network nodes such as MMEs, S-GWs, or P-GWs, or core network functions such as AUSFs, UDMs, AMFs, or SMFs, or stations of an access system, e.g., servers or hosts. The method may be implemented in a single controller or across multiple controllers. The controller may be integrated with or external to a core network or RAN node or module. In some embodiments, a base station includes a separate controller unit or module. In other embodiments, the controller may be another network element, such as a radio network controller or spectrum controller. In some embodiments, each base station may have such a controller, similar to a controller provided in a radio network controller. The controller 300 may be arranged to provide control over communications within a coverage area of ​​the system. The controller 300 comprises at least one memory 301, at least one data processing unit 302, 303, and an input / output interface 304. Through the interface, the controller 300 can be coupled to a receiver and a transmitter of the base station. The receiver and / or transmitter can be implemented as a radio front end or a remote radio head. The controller 300 can include one or more network functions that can be implemented as virtualized network functions. The controller 300 can be a network node. The controller 300 can be a chip and / or module configured within the network node.

[0100] This paper describes secure authentication, authorization, and key management between 5G ProSe Layer 3 UEs using 5G ProSe remote UE-specific authentication to establish PC5 keys. The network functions AMF, AUSF, and UDM are involved in key derivation and distribution of keys used for communication between 5G ProSe UEs. UEs are provided with the policies and parameters required to use 5G ProSe services as part of the UE ProSe policy information. The PCF provides authorization policies and parameters for network relay discovery between 5G ProSe UEs and the network.

[0101] The procedure for establishing a PC5 link between a 5G ProSe remote UE and a 5G ProSe UE-to-network relay (UE-to-network relay) is described. This procedure includes how the 5G ProSe remote UE is authenticated by the AUSF of the 5G ProSe remote UE and the AMF of the 5G ProSe UE-to-network relay via the 5G ProSe UE-to-network relay during the establishment of the 5G ProSe PC5. This mechanism can be used when the 5G ProSe remote UE is out of coverage.

[0102] Figure 4 shows the signaling flow of the security procedure between 5G ProSe UEs to set up a network process security context during the establishment of a PC5 link.

[0103] In step 0, the 5G ProSe remote UE and the 5G ProSe UE-to-network relay are registered with the network. In step 0a, the 5G ProSe remote UE is authenticated by the network and authorized to receive the UE-to-network relay service. In step 0b, the 5G ProSe UE-to-network relay is authenticated and authorized by the network to provide the UE-to-network relay service. PC5 security policies are provided to the 5G ProSe remote UE and the 5G ProSe UE-to-network relay, respectively, during this authentication and information provisioning procedure.

[0104] In step 1, the 5G ProSe remote UE initiates a detection procedure using either Model A or Model B.

[0105] In step 2, upon detecting the 5G ProSe UE-to-network relay, the 5G ProSe remote UE sends a Direct Communication Request (DCR) to the 5G ProSe UE-to-network relay to securely establish a PC5 unicast link. The 5G ProSe remote UE includes its security capabilities and security policy for PC5 signaling in the DCR message. The message also includes a Relay Service Code (RSC) and Nonce_1.

[0106] If the 5G ProSe remote UE does not have a valid 5GPRUK (5G Prose Remote User Key), the 5G ProSe remote UE must include SUCI in the DCR, trigger 5G ProSe remote UE-specific authentication, and establish a 5GPRUK.

[0107] If the 5G ProSe remote UE already has a valid 5GPRUK, the 5G ProSe remote UE shall include the 5GPRUK ID in the DCR to indicate that it wants to obtain a relay connection using the 5GPRUK.

[0108] In step 3, upon receiving the DCR message, the 5G ProSe inter-UE relay sends a Relay Key Request including the SUCI or 5GPRUK ID, RSC, and Nonce_1 received in the DCR message to the AMF of the 5G ProSe inter-UE relay. For subsequent messages via the 5G ProSe UE-to-network relay's NAS message, the 5G ProSe UE-to-network relay includes a transaction identifier that identifies the 5G ProSe remote UE in the message.

[0109] In step 4, the AMF of the 5G ProSe UE-to-network relay verifies whether the 5G ProSe UE-to-network relay is authorized to provide UE-to-network relay service.

[0110] In step 5, the AMF of the 5G ProSe inter-UE relay selects an AUSF based on the SUCI or 5GPRUK ID and forwards the parameters received in the relay key request to the AUSF in a Nausf_UEA Authentication_ProseAuthenticate Request message. The Nausf_UEA Authentication_ProseAuthenticate Request message includes the SUCI or 5GPRUK ID of the 5G ProSe remote UE, the relay service code, and Nonce_1. If the 5GPRUK ID is received from the AMF of the 5G ProSe inter-UE relay, the AUSF of the 5G ProSe remote UE skips steps 6 to 9. If the SUCI of the 5G ProSe remote UE is received from the AMF of the 5G ProSe inter-UE relay, the AUSF of the 5G ProSe remote UE performs steps 6 to 9 and skips step 10.

[0111] In step 6, the AUSF initiates 5G ProSe remote UE-specific authentication using the received ProSe-specific parameters (such as RSC).

[0112] The AUSF of the 5G ProSe remote UE obtains the authentication vector and RoutingIndicator of the 5G ProSe remote UE from the UDM via the Nudm_UEAuthentication_GetProseAv Request message. Upon receiving the Nudm_UEAuthentication_GetProSeAvRequest, the UDM invokes the SIDFde-concealSUCI and obtains the SUPI before processing the request. The UDM checks whether the UE is authorized to use the ProSe UE-to-network relay service based on the authentication information in the UE's subscription data. If the UE is authorized, the UDM selects an authentication method based on the SUPI.

[0113] In step 7a, if EAP-AKA' is selected by the UDM, the AUSF of the 5G ProSe remote UE triggers authentication of the 5G ProSe remote UE based on EAP-AKA'. The AUSF of the 5G ProSe remote UE generates an EAP-Request / AKA'-Challenge and sends the EAP-Request / AKA'-Challenge message to the AMF of the 5G ProSe UE-to-network relay in a Nausf_UEAuthentication_ProSeAuthenticateResponse message.

[0114] In step 7b, the AMF of the 5G ProSe inter-UE relay forwards the Relay Authentication Request (including the EAP-Request / AKA´-Challenge) to the 5G ProSe inter-UE relay on an NAS message, which includes the transaction identifier of the 5G ProSe remote UE. The NAS message is secured using the NAS security context created for the 5G ProSe UE-to-network relay.

[0115] In step 7c, based on the transaction identifier, the 5G ProSe UE-to-UE relay forwards the EAP-Request / AKA´-Challenge to the 5G ProSe remote UE in a PC5 message.

[0116] The Universal Subscriber Identity Module (USIM) of the 5G ProSe remote UE verifies the freshness of the received value by checking whether it can accept the AUTN.

[0117] For EAP-AKA´, the USIM calculates the response RES. The USIM must return RES, CK, and IK to the ME. The ME must derive CK´ and IK´.

[0118] In step 7d, the 5G ProSe remote UE returns the EAP-Response / AKA´-Challenge to the 5G ProSe UE-to-UE relay on a PC5 message.

[0119] In step 7e, the 5G ProSe inter-UE relay forwards the EAP-Response / AKA´-Challenge together with the transaction identifier of the 5G ProSe remote UE to the AMF of the 5G ProSe inter-UE relay in a NAS message relay authentication response.

[0120] In step 7f, the AMF of the 5G ProSe UE-to-UE relay forwards the EAP-Response / AKA´-Challenge to the AUSF of the 5G ProSe remote UE via Nausf_UEA Authentication_ProSeAuthenticate Request.

[0121] The AUSF of the 5G ProSe remote UE performs authentication of the UE by verifying the received information.

[0122] For EAP-AKA´, the AUSF of the 5G ProSe remote UE and the 5G ProSe remote UE can exchange EAP-Request / AKA´-Notification and EAP-Response / AKA´-Notification messages via the 5G ProSe UE-to-network relay and the AMF of the 5G ProSe UE-to-network relay. After the exchange, the 5G ProSe remote UE and the AUSF of the 5G ProSe remote UE derive the KAUSF_P in the same way that the KAUSF is derived.

[0123] In step 8, if the authentication is successful, the 5G ProSe remote UE and the AUSF of the 5G ProSe remote UE generate a 5GPRUK.

[0124] The 5GPRUK ID is in NAI format, i.e. username@realm, where the username part contains the routing indicator from step 6 and the 5GPRUK ID*, and the realm part contains the home network identifier.

[0125] In step 9a, the AUSF of the 5G ProSe remote UE selects a PAnF (ProseAnchorFunction) based on the 5GPRUK ID and sends the SUPI, RSC, 5GPRUK, and 5GPRUK ID to the PAnF in an Npanf_ProseKey_RegisterRequest message.

[0126] In step 9b, the PAnF stores the Prose context information (SUPI, RSC, 5GPRUK, 5GPRUK ID) of the 5G ProSe remote UE and sends an Npanf_ProseKey_Register Response message to the AUSF.

[0127] In step 10a, the AUSF of the 5G ProSe remote UE selects a PAnF based on the 5GPRUK ID and sends the received 5GPRUK ID and RSC in a Npanf_ProseKey_getRequest message.

[0128] In step 10b, the PAnF obtains the 5GPRUK based on the 5GPRUK ID and checks whether the 5G ProSe remote UE is authorized to use the UE-to-UE relay service based on the received RSC. If the 5G ProSe remote UE is authorized and the obtained 5GPRUK is valid, the PAnF sends an Npanf_ProseKey_get Response message containing the 5GPRUK to the AUSF.

[0129] In step 11, the AUSF of the 5G ProSe remote UE generates Nonce_2 and derives the KNR_ProSe key using the 5GPRUK, Nonce_1, and Nonce_2.

[0130] In step 12, the AUSF of the 5G ProSe remote UE sends KNR_ProSe, Nonce_2 in a Nausf_UEAuthentication_ProseAuthenticateResponse message to the 5G ProSe UE-to-network relay via the AMF of the 5G ProSe UE-to-network relay. If step 7 is executed successfully, an EAPSuccess message is included. The AUSF of the 5G ProSe remote UE must also include the 5GPRUK ID in the message if generated in step 8.

[0131] In step 13, upon receiving KNR_ProSe from the AUSF of the 5G ProSe remote UE via the AMF of the 5G ProSe UE-to-UE relay, the 5G ProSe UE-to-UE relay derives the PC5 session key Krelay-sess, confidentiality key Krelay-enc (if applicable), and integrity key Krelay-int from KNR_ProSe. The KNR_ProSe ID and Krelay-sess ID are established in the same way as the KNRP ID and KNRP-sess ID. The EAPSuccess message and 5GPRUK ID, if received from the AUSF, are also sent from the AMF of the 5G ProSe UE-to-network relay to the UE-to-network relay.

[0132] In step 14, the 5G ProSe UE-to-network relay sends the received Nonce_2 and the 5G ProSe remote UE's PC5 signaling security policy to the 5G ProSe remote UE in a DirectSecurity Mode Command message that is integrity protected using Krelay-int and, if received from the 5G ProSe UE-to-network relay's AMF, includes an EAPSuccess message.

[0133] In step 15, the 5G ProSe remote UE generates the KNR_ProSe key to be used for remote access via the 5G ProSe UE-to-UE relay in the same manner as defined in step 11. The 5G ProSe remote UE derives the PC5 session key Krelay-sess and confidentiality and integrity keys from KNR_ProSe in the same manner as defined in step 13.

[0134] In step 16, the 5G ProSe remote UE sends a Direct Security Mode Complete message including its PC5 user plane security policy to the 5G ProSe UE-to-UE relay. This message is protected by Krelay-int and / or Krelay-enc derived from Krelay-sess according to the PC5 signaling policy negotiated between the 5G ProSe remote UE and the 5G ProSe UE-to-UE relay.

[0135] In step 17, after the direct security mode complete message is securely verified successfully, the 5G ProSe UE-to-UE relay receives a direct communication accept message from the 5G ProSe remote UE, terminates the PC5 connection establishment procedure, and stores the 5GPRUK ID in the security context associated with the PC5 link with the 5G ProSe remote UE.

[0136] The Serving Network Name (SNN) is the service code and SN ID with a separator ":" appended, where the service code is prepended to the SN ID. The Serving Network Name (SNN) is used to derive the anchor key. The SNN serves two purposes: it binds the anchor key to the serving network by including the Serving Network Identifier (SN Id), and it ensures that the anchor key is unique for authentication between the 5G core network and the UE by including the service code set to "5G".

[0137] In 5G AKA, the Serving Network Name has a similar purpose of binding RES* and XRES* to a serving network.

[0138] The Serving Network Name does not use parameters such as "Access Network Type" as it relates to access network independent 5G Core procedures. The SN Id identifies the serving PLMN and is defined as SNN-network-identifier, except for standalone closed networks.

[0139] The UE constructs the SNN as follows: The UE sets the service code to "5G", sets the network identifier to the SN Id of the authenticated network, and concatenates the service code and SN Id with a separator ":".

[0140] The SEAF constructs the serving network name as follows: The SEAF sets the service code to "5G", sets the network identifier to the SN Id of the serving network to which the authentication data is sent by the AUSF, and concatenates the service code and SN Id with a separator ":".

[0141] The AUSF obtains the serving network name from the SEAF. Before using the serving network name, the AUSF verifies that the SEAF is authorized to use the serving network name.

[0142] For authentication of the 5G ProSe remote UE in the AUSF, for example, the ProseAuthenticate service operation in step 0a of Figure 4 can be used.

[0143] The NF service consumer (AMF) requests authentication of the 5G ProSe Remote UE by providing the 5G ProSe Remote UE related information, relay service code, and Nonce_1 to the NF service producer (AUSF), and the NFServiceProducer obtains the 5G ProSe Remote UE related data and authentication method from the UDM. In the example of Figure 5, the obtained authentication method is EAP-AKA. Then, the NF service consumer (AMF) returns the result received from the 5G ProSe Remote UE to the AUSF.

[0144] In step 1, the NF service user (AMF) sends a POST request to the AUSF. The body payload includes the UE ID, the relay service code, and Nonce_1.

[0145] In step 2a, if successful, "201 Created" shall be returned. The payload body shall contain a representation of the created resource and the "Location" header shall contain the URI of the created resource (e.g., ... / v1 / prose_authentications / {authCtxId}). The AUSF shall create a sub-resource called "prose-auth". There shall be only one sub-resource "prose-auth" per UE identified in supiOrSuci of ProSeAuthenticationInfo. The AUSF shall provide a hypermedia link to this sub-resource in the payload to indicate to the AMF where to send the POST containing the EAP packet response. The body payload shall also contain the EAP packet EAP-Request / AKA´-Challenge.

[0146] Alternatively, in step 2b, in the case of failure or redirection, specify one of the HTTP status codes. For 4xx / 5xx responses, the message body MAY contain a ProblemDetails structure with the "cause" attribute set to one of the application errors.

[0147] In step 3, based on the relationship type, the NF Service Consumer (AMF) sends a POST request containing the EAP-Response / AKA' challenge received from the 5G ProSe remote UE. The POST request is sent to a URI provided by the AUSF or derived by the NF Service Consumer (AMF).

[0148] Steps 4 and 5 are optional.

[0149] In step 4a, if successful, and if the AUSF and the UE have signaled the use of a protected successful result indication, the AUSF shall respond with a '200 OK' HTTP message containing an EAP Request / AKA' Notification and a hypermedia link pointing to the sub-resource 'prose-auth'.

[0150] Alternatively, in 4b, in case of failure or redirection, one of the HTTP status codes listed in Table 1 MUST be returned. For 4xx / 5xx responses, the message body MAY contain a ProblemDetails structure with the "cause" attribute set to one of the application errors listed in Table 1.

[0151] [Table 1]

[0152] In step 5, the NF service consumer (AMF) sends a POST request containing the EAP Response / AKA´ Notification received from the UE. The POST request is sent to a URI provided by the AUSF or derived by the NF service consumer (AMF).

[0153] In step 6a, if the ProSe authentication exchange is completed successfully (with or without the optional Notification Request / Response message exchange), a "200 OK" is returned to the NF service consumer (AMF). The payload contains the authentication result, EAP success / failure, and KNR_ProSe if authentication was successful. If the 5G ProSe remote UE is not authenticated, the AMF sets authResult to AUTHENTICATION_FAILURE.

[0154] In step 6b, in case of failure or redirection, one of the HTTP status codes shown in Table 1 MUST be returned. For 4xx / 5xx responses, the message body MAY contain a ProblemDetails structure with the "cause" attribute set to one of the application errors listed in Table 2. Table 2 shows the definition of ProSeAuthenticationInfo. [Table 2]

[0155] The NF Service Consumer (AUSF) uses this operation to request ProSe authentication vector(s) for a 5G ProSe remote UE from the UDM. If a SUCI is provided, the UDM calculates the SUPI from the SUCI. The UDM calculates the authentication vectors taking into account the information received from the NF Service Consumer (AUSF) and, if EAP-AKA is selected, the current representation of this resource. This operation must support the request data structure specified in Table 3 below. The ProSeAuthenticationInfoRequest is as shown in Table 4. [Table 3] [Table 4]

[0156] It is not clear which SNN the UDM uses to generate the authentication vector. The SNN could be the SNN of the remote UE or the SNN of the relay UE.

[0157] If the SNN of the remote UE is used, the AUSF of the remote UE in the ProSe direct communication procedure must know the SNN, and the SNN must be sent from the AUSF to the UDM of the remote UE.

[0158] If the SNN of the relay UE is used, the ProseAuthenticate from the AMF of the relay UE to the AUSF of the remote UE does not contain the SNN information element, so the AUSF of the remote UE cannot recognize the information.

[0159] If the SNN of the relay UE is used for AV generation and EAP-AKA is used for ProSe-specific authentication, the USIM and UDM of the remote UE use the same SNN for authentication vector generation since they are shared in the AKA challenge message of the EAP message.

[0160] However, this approach is not suitable when 5G AKA is used for ProSe authentication, where the remote UE USIM and UDM use the SNN independently without sharing the network in the AKA challenge message.

[0161] 6 shows a flowchart of a method according to an exemplary embodiment, which can be performed in a network node such as a UDM.

[0162] At S1, the method includes receiving notification of a serving network name of a first user equipment at a network node, the first user equipment being configured to act as a relay between the second user equipment and the network by providing proximity services between the first user equipment and the second user equipment.

[0163] At S2, the method includes determining an authentication vector for proximity service authentication of the second user equipment based on a serving network name of the first user equipment.

[0164] At S3, the method includes providing notification of a serving network name of the first user equipment to the second user equipment.

[0165] In the method described with reference to FIG. 6, the first user equipment may be referred to as a relay UE and the second user equipment may be referred to as a remote UE.

[0166] 7 shows a flowchart of a method according to an exemplary embodiment, which can be performed in a UE.

[0167] At T1, the method includes receiving notification of a serving network name of a second user equipment at a first user equipment, the second user equipment being configured to act as a relay between the first user equipment and the network by providing proximity services between the first user equipment and the second user equipment.

[0168] At T2, the method includes determining an authentication vector for proximity service authentication of the first user equipment based on a serving network name of the second user equipment.

[0169] In the method described with reference to FIG. 7, the first user equipment may be referred to as a remote UE and the second user equipment may be referred to as a relay UE.

[0170] 8 is a flowchart of a method according to an exemplary embodiment, which can be performed in a network function such as a UDM.

[0171] In R1, the method includes obtaining, at a network node, a serving network name of the first user equipment.

[0172] At R2, the method includes determining an authentication vector based on a serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and the network.

[0173] 9 shows a flowchart of a method according to an exemplary embodiment, which can be performed in a UE.

[0174] At U1, the method includes obtaining, at the first user equipment, a serving network name for the first user equipment.

[0175] At U2, the method includes determining an authentication vector based on a serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and the network.

[0176] In the methods described with reference to Figures 8 and 9, the first user equipment may be referred to as a remote UE and the second user equipment may be referred to as a relay UE.

[0177] The proximity service authentication may be EAP AKA' or 5G AKA, or any other suitable proximity service authentication procedure.

[0178] In a first exemplary approach for EAP AKA' or 5G AKA, as shown in Figures 8 and 9, the AMF of the relay UE does not share its SNN with the AUSF, and the AUSF does not share its SNN with the UDM. Instead, the UDM acquires the SNN of the remote UE for authentication vector generation. Acquiring the SNN of the first user equipment includes acquiring the SNN of the first user equipment from a storage function.

[0179] The method as described with reference to Figure 9 may include receiving authentication information at a first user equipment, where the authentication information includes a serving network name of the first user equipment. The authentication information may include an Extensible Authentication Protocol (EAP) message. The method according to Figure 8 may include providing an EAP message to the first user equipment, where the EAP message includes the serving network name of the first user equipment.

[0180] For example, in the first approach, if EAP AKA' is used, the UDM may share the remote UE's SNN with the remote UE in an authentication and key agreement (AKA) challenge message.

[0181] Alternatively, the serving network name for the first user equipment may be stored in a USIM of the first user equipment. Obtaining the serving network name for the first user equipment at the first user equipment may include obtaining the serving network name for the first user equipment from a universal subscriber identity module associated with the first user equipment.

[0182] For example, if 5G AKA is used, the UDM and remote UE use the SNN ("Remote UE SNN") stored from the previous procedure (last registered AMF). The UDM and remote UE retrieve the SNN from memory / storage (e.g., USIM in the case of the UE) and use it to generate the authentication vector.

[0183] The method as described with reference to FIG. 6 may include receiving a serving network name from the first user equipment via at least one of an AMF associated with the first user equipment or an AUSF associated with the first user equipment.

[0184] In the second exemplary approach, as shown in Figure 6 for EAP AKA' or 5G AKA, the AMF of the relay UE sends the SNN of the relay UE to the AUSF and then to the UDM. The SNN of the relay UE is then used in authentication vector generation.

[0185] 6 can include providing authentication information to the second user equipment, the authentication information including notification of a serving network name of the first user equipment, the authentication information being provided in at least one of a proximity services authentication response, a proximity services authentication request, or an EAP message.

[0186] Figure 10 shows an example of the signaling flow for ProSe EAP AKA authentication according to the first approach. The AMF of the relay UE does not share its SNN with the AUSF, and the AUSF does not share its SNN with the UDM.

[0187] Figure 11 shows an example of the signaling flow for ProSe 5G AKA authentication according to the first approach. The AMF of the relay UE does not share its SNN with the AUSF, and the AUSF does not share its SNN with the UDM.

[0188] In step 1a of Figures 10 and 11, once the remote UE is registered and authenticated by the network, the UDM stores the result and time of the authentication procedure, including the SUPI, the authentication timestamp, the authentication type (e.g., EAP method or 5G-AKA), and the serving network name (referred to as the remote UE SNN).

[0189] In Figure 10, when a remote UE triggers a ProSe-specific authentication request via the relay UE-UE network and the request reaches the UDM, after the SUCI is deciphered, the remote UE SNN is retrieved from the UDM storage and used to generate the ProSe authentication vector.

[0190] The same "Remote UE SNN" is used in AT_KDF_INPUT and passed to the remote UE / USIM in the EAP AKA challenge for ProSe-specific authentication.

[0191] In the case of 5G AKA, the UDM obtains the SNN from its stored memory, and the remote UE obtains the SNN from the USIM. In messages 6c to 9a in Figure 11, in the case of 5G AKA, there is no exchange of the SNN information of the remote UE.

[0192] In Figure 11, when the remote UE triggers a ProSe-specific authentication request via a UE-to-UE relay and it reaches the UDM, after the SUCI is deciphered, the "remote UE SNN" is retrieved from the UDM storage and used to generate the ProSe-specific authentication vector.

[0193] FIG. 12 shows an example of a signaling flow for ProSe EAP AKA authentication according to the second approach.

[0194] Figure 13 shows an example signaling flow for ProSe 5G AKA authentication according to the second approach.

[0195] In Figures 12 and 13, the AMF of the relay UE sends the "Relay UE SNN" in step 5 of the Nausf_UEA Authenticate_Prose Authenticate_Request message towards the AUSF. The AUSF forwards the "Relay UE SNN" in step 6a of the Nudm_UE Authenticate_Get Prose AV_Request message towards the UDM. The "Relay UE SNN" is used in the authentication vector generation.

[0196] In Figure 12, the same relay UE's SNN is used in AT_KDF_INPUT and passed to the UE / USIM in the AKA challenge.

[0197] In Figure 13, the Relay UE SNN is sent in the 5G AKA authentication message from the UDM to the AUSF to the remote UE, which uses the "Relay UE SNN" in the AKA challenge calculation in the RES.

[0198] The network node apparatus may comprise: means for receiving notification of a serving network name of a first user equipment; the first user equipment configured to act as a relay between the second user equipment and the network by providing proximity services between the first user equipment and the second user equipment; means for determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; and means for providing notification of the serving network name of the first user equipment to the second user equipment.

[0199] Alternatively, the network node apparatus may comprise means for obtaining a serving network name of a first user equipment, and means for determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and the network.

[0200] The apparatus may include, be, or comprise a network node, or perform at least some of the operations of a network node / a chipset for a network node. The network node may implement a UDM.

[0201] The first user equipment apparatus may comprise: means for receiving notification of a serving network name of a second user equipment; the second user equipment configured to act as a relay between the first user equipment and the network by providing proximity services between the first user equipment and the second user equipment; and means for determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment.

[0202] Alternatively or additionally, the apparatus may comprise: means, in the first user equipment, for obtaining a serving network name of the first user equipment; and means for determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and the network.

[0203] The apparatus may be a first user equipment, including a first user equipment such as a mobile phone, or may be configured in the first user equipment, or may be a chipset for performing the operations of / at least part of the user equipment.

[0204] The system comprises, at a network node, means for receiving notification of a serving network name of a first user equipment; a first user equipment configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and the second user equipment; means for determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; means for providing notification of the serving network name of the first user equipment to the second user equipment; means at the second user equipment for receiving notification of the serving network name of the first user equipment; and means for determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment.

[0205] The system may comprise: means for obtaining a serving network name of a first user equipment in a network node; means for determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication between the first user equipment and a second user equipment configured to act as a relay for proximity services between the first user equipment and the network node; means for obtaining the serving network name of the first user equipment; and means for determining, based on the serving network name of the first user equipment, an authentication vector for proximity-based service authentication of the first user equipment in proximity-based services between the first user equipment and the second user equipment configured to act as a relay between the first user equipment and the network.

[0206] It is to be understood that the apparatus may include or be coupled to other units or modules, such as radio components or radio heads, used for transmission and / or reception. Although the apparatus has been described as one entity, the different modules and memories may be implemented in one or more physical or logical entities.

[0207] It should be noted that although some embodiments have been described in the context of 5G networks, similar principles may be applied in the context of other networks and communication systems. Thus, although exemplary embodiments have been described above with reference to particular exemplary architectures for wireless networks, technologies, and standards, the embodiments may be applied to any other suitable form of communication system other than that shown and described in the examples.

[0208] Also, although exemplary embodiments have been described in this example, it should be noted that several variations and modifications can be made to the disclosed solutions without departing from the scope of the present invention.

[0209] As used herein, the terms "at least one of: ", "at least one of ", and similar expressions where a list of two or more elements is joined by "and" or "or" mean at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0210] In general, various embodiments may be implemented in hardware or special-purpose circuits, software, logic, or any combination thereof. Some aspects of the present disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device, although the present disclosure is not limited thereto. Although various aspects of the present disclosure may be illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it will be appreciated that these blocks, apparatus, systems, techniques, or methods described herein may be implemented in, by way of non-limiting example, hardware, software, firmware, special-purpose circuits or logic, general-purpose hardware or controller or other computing device, or some combination thereof.

[0211] As used in this application, the term "circuitry" may refer to one or more or all of the following: (a) hardware-only circuit implementations (e.g., analog and / or digital-only implementations); (b) a combination of hardware circuitry and software (if applicable); (i) a combination of analog and / or digital hardware circuitry and software / firmware; (ii) software (including digital signal processors), hardware processor portions with software and memory that cooperate to cause a device, such as a mobile phone or server, to perform various functions; (c) A hardware circuit or processor, such as a microprocessor or part of a microprocessor, that requires software (e.g., firmware) to operate, but the software may be absent when not necessary for operation.

[0212] This definition of circuit applies to all uses of the term in this application, including any claims. As a further example, as used herein, the term circuit also covers simply a hardware circuit or processor (or processors) or part of a hardware circuit or processor and its (or their) accompanying software and / or firmware implementation. The term circuit also covers, for example, a baseband or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device, if applicable to particular claim elements.

[0213] Embodiments of the present disclosure may be implemented by computer software executable by a data processor of a mobile device, such as in a processor entity, or by hardware, or a combination of software and hardware. Computer software or programs, also referred to as program products, including software routines, applets, and / or macros, may be stored on any device-readable data storage medium and include program instructions for performing specific tasks. A computer program product may consist of one or more computer-executable components configured to perform embodiments when the program is executed. One or more computer-executable components may be at least one software code or portion thereof.

[0214] Further in this regard, it should be noted that the blocks of logic flow, such as those shown, may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. Software may be stored on physical media, such as memory chips, memory blocks implemented within a processor, magnetic media such as hard disks or floppy disks, or optical media such as DVDs or their data variants, CDs. The physical media is non-transitory. As used herein, the term "non-transitory" refers to the media itself (i.e., tangible, not signal) as opposed to the data storage persistence (e.g., RAM vs. ROM).

[0215] The memory may be of any type suitable for the local technology environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed and removable memory, etc. The data processor may be of any type suitable for the local technology environment and may comprise, by way of non-limiting examples, one or more of a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), an FPGA, a gate-level circuit, and a processor based on a multi-core processor architecture.

[0216] Embodiments of the present disclosure can be implemented in a variety of components, such as integrated circuit modules. The design of integrated circuits is generally a highly automated process. Complex and powerful software tools are available for converting logic-level designs into semiconductor circuit designs that can be etched onto semiconductor substrates.

[0217] The scope of protection sought for various embodiments of the present disclosure is defined by the independent claims. If embodiments and features described herein do not fall within the scope of the independent claims, they are to be construed as exemplary embodiments useful for understanding various embodiments of the present disclosure.

[0218] The foregoing description has provided, by way of non-limiting example, a complete and informative description of the exemplary embodiments of the present disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant art in light of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar variations of the teachings of the present disclosure will still fall within the scope of the present invention as defined by the appended claims. Indeed, further embodiments exist that involve combinations of one or more of the embodiments with any of the other embodiments described above.

Claims

1. An apparatus for a network node, comprising: means for receiving notification of a serving network name of a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and a second user equipment; means for determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; means for providing notification of the serving network name of the first user equipment to the second user equipment; An apparatus comprising:

2. The apparatus of claim 1 , further comprising: means for providing authentication information to the second user equipment, the authentication information including the indication of the name of the serving network of the first user equipment.

3. The apparatus of claim 2 , further comprising: means for providing authentication information in at least one of a proximity services authentication response, a proximity services authentication request, or an extensible authentication protocol message.

4. 4. The apparatus of claim 1, further comprising: means for receiving the serving network name of the first user equipment via at least one of an access and mobility management function associated with the first user equipment or an authentication server function associated with the second user equipment.

5. The device according to claim 1 , wherein the network node implements unified data management.

6. 6. An apparatus according to any preceding claim, wherein the apparatus comprises, is or is contained within the network node.

7. 1. An apparatus for a first user equipment, comprising: means for receiving notification of a serving network name of a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; means for determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment; An apparatus comprising:

8. The apparatus of claim 7 , further comprising: means for receiving authentication information at the first user equipment, the authentication information including the indication of the serving network name of the second user equipment.

9. The apparatus of claim 8 , further comprising: means for receiving the authentication information in an Extensible Authentication Protocol message.

10. 10. Apparatus according to any of claims 7 to 9, wherein the apparatus comprises, is or is included in the first user equipment.

11. An apparatus for a network node, comprising: means for obtaining a serving network name of the first user equipment; means for determining an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network, based on the serving network name of the first user equipment; An apparatus comprising:

12. 12. The apparatus of claim 11, further comprising: means for providing an Extensible Authentication Protocol message to the first user equipment, the Extensible Authentication Protocol challenge message including the serving network name of the first user equipment.

13. The apparatus of claim 11 , wherein the serving network name of the first user equipment is stored in a universal subscriber identity module of the first user equipment.

14. 14. The apparatus of claim 11, further comprising: means for obtaining the serving network name of the first user equipment by obtaining the serving network name of the first user equipment from a storage function.

15. 15. The apparatus of claim 11, wherein the network node implements unified data management.

16. 16. Apparatus according to any of claims 11 to 15, wherein the apparatus comprises, is or is included in the network node.

17. 1. An apparatus for a first user equipment, comprising: means for obtaining a serving network name of the first user equipment; means for determining an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network, based on the serving network name of the first user equipment; An apparatus comprising:

18. 20. The apparatus of claim 17, further comprising means for receiving authentication information, the authentication information including a name of the serving network for the first user equipment.

19. 20. The apparatus of claim 18, further comprising: means for receiving the authentication information in an Extensible Authentication Protocol message.

20. 20. The apparatus of claim 17, further comprising: means for obtaining the serving network name for the first user equipment by obtaining it from a universal subscriber identity module associated with the first user equipment.

21. 21. Apparatus according to any of claims 17 to 20, wherein the apparatus comprises, is or is included in the first user equipment.

22. receiving, at a network node, notification of a serving network name for a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and the second user equipment; determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; notifying the second user equipment of the serving network name of the first user equipment; A method comprising:

23. receiving, at a first user equipment, notification of a serving network name of a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment; A method comprising:

24. obtaining, at a network node, a serving network name of the first user equipment; determining, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network; A method comprising:

25. At a first user equipment, obtaining a serving network name of the first user equipment; determining, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network; A method comprising:

26. An apparatus for a network node, comprising: at least one processor; When executed by the at least one processor, the device includes at least: receiving notification of a serving network name for a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and a second user equipment; determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; notifying the second user equipment of the serving network name of the first user equipment; at least one memory storing instructions for executing the An apparatus comprising:

27. 1. An apparatus for a first user equipment, comprising: at least one processor; When executed by the at least one processor, the device includes at least: receiving notification of a serving network name for a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment; at least one memory storing instructions for executing the An apparatus comprising:

28. An apparatus for a network node, comprising: at least one processor; When executed by the at least one processor, the device includes at least: Obtaining a serving network name of a first user equipment; determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network; at least one memory storing instructions for executing the An apparatus comprising:

29. 1. An apparatus for a first user equipment, comprising: at least one processor; When executed by the at least one processor, the device includes at least: Obtaining a serving network name of the first user equipment; determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network; at least one memory storing instructions for executing the An apparatus comprising:

30. When executed by an apparatus, the apparatus performs at least receiving notification of a serving network name of a first user equipment at a network node, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and a second user equipment; determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; notifying the second user equipment of the serving network name of the first user equipment; A computer-readable medium containing instructions for performing the following:

31. When executed by an apparatus, the apparatus performs at least receiving, at a first user equipment, notification of a serving network name of a second user equipment, the second user equipment being configured to act as a relay between the first user equipment and a network by providing proximity services between the first user equipment and the second user equipment; determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment; A computer-readable medium containing instructions for performing the following:

32. When executed by an apparatus, the apparatus performs at least obtaining a serving network name of the first user equipment at a network node; determining an authentication vector based on a serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network; A computer-readable medium containing instructions for performing the following:

33. When executed by an apparatus, the apparatus performs at least At a first user equipment, obtaining a serving network name of the first user equipment; determining, based on the serving network name of the first user equipment, an authentication vector for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network; A computer-readable medium containing instructions for performing the following:

34. means, in a network node, for receiving notification of a serving network name of a first user equipment, the first user equipment being configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and a second user equipment; means for determining, at a network node, an authentication vector for the proximity service authentication of the second user equipment based on the serving network name of the first user equipment; means for providing notification of the serving network name of the first user equipment to the second user equipment; means for receiving, at the second user equipment, notification of the serving network name of the first user equipment; means, in the second user equipment, for determining the authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; A system comprising:

35. means for obtaining a serving network name of the first user equipment in the network node; means, in the network node, for determining an authentication vector based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for proximity services between the first user equipment and a second user equipment configured to act as a relay between the first user equipment and a network; means in the first user equipment for obtaining the serving network name of the first user equipment; means for determining the authentication vector at the first user equipment based on the serving network name of the first user equipment for proximity service authentication of the first user equipment for the proximity service between the first user equipment and the second user equipment configured to act as a relay between the first user equipment and the network; A system comprising:

Citation Information

Patent Citations

  • Terminal, method, and program

    JP2022523936A

  • Methods and systems for identifying AUSF and accessing related keys in 5g prose

    WO2022019725A1