UE methods and UE
By deleting the old Kausf and resetting the counter to 0 upon receiving a new Kausf, the UE ensures synchronized and secure use of the latest Kausf, addressing synchronization issues and enhancing security in 5G AKA-based authentication and key agreement procedures.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- NEC CORP
- Filing Date
- 2026-01-20
- Publication Date
- 2026-04-28
AI Technical Summary
The synchronization of Kausf information between the UE and the network is unclear in 5G AKA-based authentication and key agreement procedures, leading to potential security vulnerabilities and inconsistencies in security procedures.
The UE method involves receiving a message from the AMF upon successful authentication, deleting the old Kausf, and resetting the counter to 0 when a new Kausf is received, ensuring both the UE and network use the same up-to-date Kausf in security procedures.
This approach ensures synchronized and secure use of the latest Kausf across various security mechanisms, preventing security breaches and maintaining consistent security procedures.
Smart Images

Figure 2026071258000001_ABST
Abstract
Description
[Technical Field]
[0001] This disclosure relates to general wireless telecommunications, and in particular, to the handling of security keys in authentication procedures in the embodiments. [Background technology]
[0002] The purpose of the primary authentication and key agreement procedure is to enable mutual authentication between the UE and the network, as defined in Non-Patent Document 5, and to provide keying material that can be used between the UE and the network in subsequent security procedures. Key K AUSF , K SEAF , and K AMF This is generated after the authentication process is successful.
[0003] Two methods are defined: primary authentication and key agreement procedures. a)EAP based primary authentication and key agreement procedure. b) 5G AKA-based primary authentication and key agreement procedure.
[0004] The UE and AMF must support both EAP-based primary authentication and key agreement procedures and 5G AKA-based primary authentication and key agreement procedures. If the authentication procedure fails on the network, the AMF returns an Authentication Reject message to the UE.
[0005] Figure 1 shows the start of the authentication procedure, the selection of the authentication method, and the selection of the authentication method. The authentication method applied to the UE is selected by the UDM.
[0006] Figure 2 shows the 5G AKA based primary authentication and key agreement procedure.
[0007] The K AUSF (Kausf) created by the UE and the AUSF is used in the security mechanism in the Steering of roaming (SoR) procedure defined in Non-Patent Document 5 and the security mechanism of UE parameters update via UDM control plane procedure.
[0008] Figure 3 shows the procedure for steering the UE in the VPLMN (Visited Public land mobile network) during registration. In the steering of the roaming procedure, Kausf is used by the UE and the AUSF to derive SoR-MAC-Iausf. When the UE receives SOR-MAC-Iausf from the network, the UE calculates SoR-MAC-Iausf and compares it with the SOR-MAC-Iausf received from the network. If SOR-MAC-Iausf matches within the UE, the UE determines that it has passed the security check for SoR transmission, and the UE saves the steering list, that is, a list of combinations of preferred PLMN / access technologies, in the UE.
[0009] Figure 4 shows the procedure for providing a list of combinations of preferred PLMN / access technologies after registration.
[0010] In the UE parameters update via UDM control plane procedure, when the UE receives UPU-MAC-Iausf from the network, the UE calculates UPU-MAC-Iausf and compares it with the UPU-MAC-Iausf received from the network. If the UPU-MAC-Iausf in the UE matches, the UE determines that the transmission of UE parameters via the UE parameters update via UDM control plane procedure is secure and stores the UE parameters transmitted by the UDM in the UE.
[0011] Furthermore, Kasuf is also used for the generation of AKMA (Authentication and Key Agreement for Applications) keys. When the UE is registered with two different PLMNs (for example, one via 3GPP access and the other via non-3GPP access), the UE and the AUSF only store the latest Kausf. This latest Kausf is used in various security procedures between the UE and the network.
Prior Art Documents
Non-Patent Documents
[0012]
Non-Patent Document 1
Non-Patent Document 2
Non-Patent Document 3
Non-Patent Document 4
[0013] The authentication and key agreement procedure defined in Non-Patent Document 5 is unclear. As mentioned in the background technology, synchronization of Kausf information between the UE and the network is crucial for 5GS because Kausf information is used in various security procedures. If Kausf is not synchronized between the UE and the network, security is extremely important and cannot be compromised, so 5GS should not provide any services on the 5GS. [Means for solving the problem]
[0014] In the first aspect of this disclosure, the User Equipment (UE) method receives a message from the Access and Mobility Management Function (AMF) when the 5G Authentication and Key Agreement (AKA) based primary authentication and key agreement procedure is successful, and when the UE receives the message, the first K AUSF Delete the second K when the UE receives the message. AUSFConsider it as a valid K AUSF and when the UE receives the message, reset the counter to 0.
[0015] In a second aspect of the present disclosure, a user equipment (UE) has means for receiving a message from an Access and Mobility Management Function (AMF) when a 5G Authentication and Key Agreement (AKA) based primary authentication and key agreement procedure is successful, and a first K AUSF means for deleting when the receiving means receives the message, and a second K AUSF means for considering it as a valid K AUSF and when the receiving means receives the message, reset the counter to 0.
Brief Description of Drawings
[0016] [Figure 1] FIG. 1 is a general signal diagram showing the start of an authentication procedure and the selection of an authentication method. [Figure 2] FIG. 2 is a general signal diagram showing an authentication procedure of 5G AKA. [Figure 3] FIG. 3 is a general signal diagram showing a procedure for providing a list of combinations of preferred PLMN / access technologies during registration to a VPLMN. [Figure 4] FIG. 4 is a general signal diagram showing a procedure of UE Parameters Update. [Figure 5] FIG. 5 is a signal diagram showing an embodiment of a procedure for establishing the latest Kausf in a UE. [Figure 6] FIG. 6 is a signal diagram showing an embodiment of a procedure for establishing the latest Kausf in a UE and a network. [Figure 7] FIG. 7 is a signal diagram showing an embodiment of a procedure for creating the latest Kausf in a UE and a network. [Figure 8] Figure 8 is a signal diagram illustrating an embodiment of the procedure for creating a modern Kausf for the UE and network. [Figure 9] Figure 9 is a signal diagram illustrating a modern Kausf establishment embodiment in the UE and network. [Figure 10] Figure 10 is a block diagram schematically showing the UE. [Figure 11] Figure 11 is a schematic block diagram of (R) AN. [Figure 12] Figure 12 is a schematic block diagram of the AMF. [Figure 13] Figure 13 shows the start of the authentication procedure and the selection of the authentication method. [Figure 14] Figure 14 is a diagram illustrating the authentication procedure for 5G AKA. [Figure 15] Figure 15 shows the authentication procedure for 5G AKA. [Figure 16] Figure 16 illustrates an authentication failure during the 5G AKA-based primary authentication and key agreement procedure. [Modes for carrying out the invention]
[0017] This disclosure provides procedures for establishing up-to-date security keys in the UE and network. Specifically, the procedures define various methods for establishing up-to-date Kausf in the UE and network and for ensuring that the UE and network use the same Kausf across various security procedures. To further clarify the advantages and features of this disclosure, a more detailed description of this disclosure will be made with reference to the specific embodiments shown in the accompanying figures. Please understand that these figures only illustrate typical embodiments of this disclosure and are therefore not intended to limit its scope. This disclosure will be further elaborated and detailed using the attached diagrams.
[0018] Furthermore, those skilled in the art will understand that the elements in the figures are simply illustrated and may not necessarily be drawn to scale. Moreover, with respect to the configuration of the apparatus, one or more components of the apparatus may be represented in the figures by general symbols, and the figures may only show specific details appropriate for understanding the embodiments of this disclosure, thus not obscuring details that would be readily apparent to those skilled in the art who benefit from the description herein.
[0019] For the purpose of facilitating an understanding of the principles of this disclosure, embodiments shown in the figures herein will be referenced and specific language will be used to describe them. Nevertheless, it will be understood that no limitation of the scope of the disclosure is intended therein. Such modifications and further modifications to the illustrated systems, as well as further applications of the principles of disclosure that would ordinarily occur to those skilled in the art, should be construed as being within the scope of this disclosure.
[0020] The terms “comprises,” “comprising,” or other variations thereof are intended to cover non-exclusive inclusion, and a process or method comprising a list of steps may include other steps not explicitly listed in such process or method, but rather than only those steps. Similarly, one or more devices or entities or subsystems or elements or structures or components following “comprises ~ a” does not preclude the presence of other devices, subsystems, elements, structures, components, additional devices, additional subsystems, additional elements, additional structures, or additional components, unless there are more constraints. The appearance of the phrases “embodiments,” “other embodiments,” and similar terms throughout this specification may, though not necessarily, all refer to the same embodiment.
[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those generally understood by those skilled in the art to the extent of this disclosure. The systems, methods, and examples provided herein are illustrative and not intended to limit the scope of this disclosure.
[0022] In the following specification and claims, numerous terms are used for reference and are defined as follows: The singular forms “a,” “an,” and “the” include multiple references unless the context explicitly indicates otherwise. As used herein, data is meaningful information and represents values resulting from parameters; therefore, information is associated with data and knowledge. Furthermore, knowledge means an understanding of abstract or concrete concepts. Note that this illustrative system has been simplified to facilitate the explanation of the disclosed subject matter and is not intended to limit the scope of this disclosure. Other devices, systems, and configurations may be used in addition to or instead of the system to implement the embodiments disclosed herein, and all such embodiments are construed as being within the scope of this disclosure.
[0023] <Example 1 of Task 1> This task 1 relates to the 5G AKA-based primary authentication and key agreement procedure.
[0024] If the UE has already successfully registered with PLMN, a valid Kausf is derived between the UE and the AUSF (Authentication Server Function). According to Non-Patent Document 5, the network can initiate the authentication procedure at any time. When the UE receives an Authentication Request message containing a 5G authentication vector (5G SE AV), it authenticates the network by validating the received AUTN (Authentication Token). If the AUTN is successfully validated, the UE creates a new Kausf and RES* and sends an Authentication Response containing the RES* to the network. At this point, the UE has two Kausfs: the old one and the new one. Based on the validation of the RES* by the AMF (Access and Mobility Management Function) or AUSF, the UE's authentication may succeed or fail with the network. If the authentication procedure is successful, the network does not send a NAS message to the UE. Therefore, unless the UE receives an explicit message from the network, it cannot be sure when the new Kausf becomes valid and when it can be used in various procedures. For example, various procedures include steering the roaming security mechanism and updating UE parameters via the UDM control plane procedure security mechanism.
[0025] <Example 2 of Problem 2> This challenge 2 relates to both EAP-based primary authentication and key agreement procedures and 5G AKA-based primary authentication and key agreement.
[0026] If the UE has already successfully registered with PLMN, a valid Kausf has been derived between the UE and AUSF. The network can initiate the authentication procedure at any time, according to Non-Patent Document 5. During the authentication procedure, a radio link failure may occur between the UE and the network, causing the authentication procedure to be aborted. For example, if AMF detects a radio link failure before receiving an authentication response message, it will abort the authentication procedure. In such a scenario, the UE and the network are not synchronized with the latest Kausf being used by the UE and the network. In some cases, the UE has multiple Kausfs (old and new Kausfs), and the UE is not sure which Kausf is being used in the network for various security procedures involving Kausf. For example, these procedures include steering of the roaming security mechanism and UE parameters update via the UDM control plane procedure security mechanism.
[0027] <Overview> The latest Kausf created in the following embodiment will be used in the following security procedures (security mechanisms). i) Steering of roaming security mechanism for calculating SoR-MAC-Iausf and SoR-MAC-Iue in UE and AUSF as defined in Non-Patent Document 5 ii) UE parameters update via UDM control plane procedure security mechanism for calculating UPU-MAC-Iausf and UPU-MAC-Iue in UE and AUSF, as defined in Non-Patent Document 5. iii) Derivation of the AKMA key as defined in Non-Patent Document 5
[0028] In the following embodiment, if the UE creates a new Kausf as the latest Kausf, the UE initializes the CounterSoR or CounterUPU to 0x00 0x00. The UE may initialize the CounterSoR or CounterUPU to 0x00 0x00 when the new Kausf becomes the latest or enabled, rather than when the Kausf is derived. In the following embodiment, the new Kausf is the latest Kausf when it becomes enabled in the UE and AUSF.
[0029] The embodiments defined for 5G AKA also apply to EAP-AKA, and vice versa. Furthermore, in the following examples, "AMF" may be interpreted as "SEAF (Security Anchor Functionality)." Additionally, in the following examples, "UDM" may be interpreted as "ARPF (Authentication credential Repository and Processing Function)." Note that the following embodiments are not limited to 5GS but also apply to communication systems other than 5GS.
[0030] If a security check fails during a Steering of Roaming (SoR) procedure or a UE Parameters Update (UPU) procedure, the UE shall include the Kausf used in the security verification procedure of the SoR or UPU procedure in a NAS message (e.g., a registration complete message or UL NAS transport message to the AMF) to notify the AMF. The AMF then forwards this Kausf to the UDM. In this case, the UDM has two options: the Kausf comparison is performed either in the UDM or the AUDF. Option 1: The UDM performs a Kausf comparison. The UDM obtains the Kausf used in the SoR or UPU procedure from the AUSF and compares the Kausf received from the UE with the Kausf received from the AUSF used in the SoR or UPU procedure. Option 2: AUSF performs a Kausf comparison. The UDM forwards the Kausf received from the AMF to AUSF. AUSF then compares the Kausf received from the UDM with the most recent Kausf used for the SoR or UPU procedure. AUSF then notifies the UDM of the comparison result. If the Kausf received from the UE differs from the Kausf stored in AUSF, the UDM initiates a new authentication process with the UE. In one example, if the UDM receives any signal from the AMF regarding the UE, the UDM requests the AMF to initiate a new authentication procedure. Alternatively, the UDM may request the AMF to initiate a re-registration procedure for the UE. In this case, the AMF performs the new authentication procedure during the registration procedure. After the authentication process is successful, the latest Kausf is synchronized between the UE and the network.
[0031] <First Embodiment (Solution 1)> The UE starts a timer, and after the timer expires, if the UE does not receive an Authentication Reject message, the new Kausf becomes active.
[0032] This embodiment applies to both 5G AKA-based primary authentication and key agreement procedures and EAP-based primary authentication and key agreement procedures.
[0033] Figure 5 shows the procedure for establishing the latest Kausf within the UE based on a timer within the UE.
[0034] The detailed process of the embodiment is described below.
[0035] 0. The UE is successfully registered with the PLMN, and Kausf is created for both the UE and the network. That is, the UE and the network each have (or maintain, hold, or store) a Kausf. If the UE has not yet registered with any PLMN, the UE does not have a valid Kausf.
[0036] 1. The network (e.g., AMF) initiates a 5G AKA-based primary authentication and key agreement procedure or an EAP-based primary authentication and key agreement procedure and sends an Authentication Request message to the UE. The AUSF stores the new Kausf received from the UDM during the authentication procedure, along with the old Kausf (created in step 0).
[0037] 2. The UE verifies the AUTN parameter received in the Authentication Request message, as shown in Non-Patent Document 6. After successful verification of the AUTN parameter, the UE calculates (or creates or generates) a new Kausf (or new Kausf parameter) based on the parameters received in the Authentication Request message and the USIM parameter, as shown in Non-Patent Document 5. The UE has both the old Kausf (created in step 0) and the new Kausf created in this step.
[0038] 3. The UE sends an Authentication Response message containing *RES to the network.
[0039] 4. The UE starts Timer T1 and saves both the old and new Kausf. While Timer T1 is running, the UE may treat the old Kausf as the latest Kausf and use it in security mechanisms involving Kausf, or the UE may treat the new Kausf as the latest Kausf and use it in security mechanisms involving Kausf. For example, the UE starts Timer T1 simultaneously with, or after, sending an Authentication Response message containing *RES. In other words, the trigger for starting time T1 is sending an Authentication Response message containing *RES.
[0040] 5. In the case of the 5G AKA-based primary authentication and key agreement procedure, upon receiving an Authentication Response message containing RES*, AMF and AUSF verify HRES* and RES* respectively, as shown in Non-Patent Document 5. After successful verification of HRES* and RES*, AMF and AUSF consider the Kausf to be successful, and AUSF begins using the new Kausf created in AUSF. In this case, Case 1, i.e., step 6a, occurs after step 5.
[0041] If HRES* or RES* verification fails in AMF or AUSF, AMF sends a Registration Reject message. AUSF treats the old Kausf as the latest and valid Kausf and uses it in security mechanisms involving Kausf. In this case, Case 2, i.e., steps 6b and 7b, occurs after step 5.
[0042] In the case of EAP-based primary authentication and key agreement, Case 3, i.e., steps 6c and 7c, takes place after step 5.
[0043] 6a. If the UE does not receive an Authentication Reject message and Timer T1 expires, the UE considers the 5G AKA-based primary authentication and key agreement procedure to have been successful, deletes the old Kausf, makes the new Kausf the latest valid Kausf, and uses the new Kausf in security mechanisms in which Kausf is involved.
[0044] 6b. While Timer T1 is running, the UE receives an authentication reject message from the AMF.
[0045] 7b. The UE stops timer T1, deletes the new Kausf and uses the old Kausf, and treats the old Kausf as valid with the latest Kausf.
[0046] 6c. While Timer T1 is running, the UE receives a NAS message from the AMF. The NAS message contains either an EAP success or an EAP failure.
[0047] 7c. The UE stops timer T1. If EAP success is received in step 6c, the UE deletes the old Kausf and uses the new Kausf, treating the new Kausf as the latest and valid Kausf. If EAP failure is received in step 6c, the UE deletes the new Kausf and uses the old Kausf, treating the old Kausf as the latest and valid Kausf.
[0048] In one example, if a wireless link failure occurs at any step during the execution of Timer T1 and the wireless link failure is detected by the UE (for example, if NG-RAN indicates to the UE that the UE radio contact has been lost while the next N1 NAS signaling connection is being established, or after the next N1 NAS signaling connection has been established), the UE shall restart Timer T1 when the N1 NAS signaling connection is established. Timer T1 shall start with the remaining value or the original value. In this case, if the first NAS procedure is rejected during the establishment of the N1 NAS signaling connection due to a failure in the authentication procedure (e.g., Registration Reject with cause #3 (incorrect UE) or Service Reject with cause #3 (incorrect UE)), the UE shall delete the new Kausf and treat the old Kausf as the latest and valid Kausf, and use the old Kausf in security mechanisms involving subsequent Kausf.
[0049] In one example, if a wireless link failure occurs and the network (e.g., AMF) detects the wireless link failure immediately after sending an Authentication Reject message, the network may send the Authentication Reject message again to the UE. For example, NG-RAN might indicate to AMF via an NGAP message that the UE wireless connection has been lost.
[0050] In one example, a UE may not have (or maintain, retain, save, or possess) an old Kausf. For instance, a UE may not have an old Kausf when it is first powered on or before it initiates the initial registration procedure.
[0051] In this case, all situations in the embodiment in which the old Kausf becomes valid mean that the UE does not have a valid Kausf. For example, "The UE deletes the new Kausf, treats the old Kausf as the latest and valid Kausf, and uses the old Kausf in subsequent Kausf-involved security mechanisms" in this embodiment means "The UE deletes the new Kausf, and the UE does not have a valid Kausf." In this case, the UE may initiate the registration procedure after deleting the new Kausf. For example, "(The UE) deletes the old Kausf, treats the new Kausf as the latest and valid Kausf, and uses the new Kausf in Kausf-involved security mechanisms" means "(The UE) treats the new Kausf as the latest and valid Kausf, and uses the new Kausf in Kausf-involved security mechanisms."
[0052] <Modified form of the first embodiment> While Timer T1 is running, the UE maintains both the old and new Kausf keys and treats them as the most up-to-date and valid. The UE shall use both the old and new Kausf keys in security mechanisms that involve Kausf. If a security mechanism succeeds using either of these keys, the UE shall treat that key as the most up-to-date and valid and delete the other key. For example, if a security mechanism succeeds using the old Kausf, the UE shall treat the old Kausf as the most up-to-date and valid and delete the new Kausf. Also, for example, if a security mechanism succeeds using the new Kausf, the UE shall treat the new Kausf as the most up-to-date and valid and delete the old Kausf.
[0053] <Second Embodiment (Solution 2)> After the authentication process is successful in AMF, AMF sends an Authentication Result.
[0054] This embodiment applies to a 5G AKA-based primary authentication and key agreement procedure.
[0055] Figure 6 shows the procedure for establishing up-to-date Kausf in the UE and network using explicit NAS signaling.
[0056] The following describes the detailed process of the embodiment. UE and AUSF each have (or maintain, retain, or store) an old Kausf.
[0057] 1. For a registration procedure that triggers a 5G AKA-based primary authentication and key agreement procedure, the UE sends a Registration Request message to the network that includes a first Information Element (IE) indicating support for receiving an acknowledgment message (e.g., Authentication Result) sent from the network in a successful authentication procedure. Sending this capability is optional in the Registration Request message; that is, this capability can also be sent in other existing NAS messages (e.g., Authentication Response) or new NAS messages during any NAS procedure. The registration procedure may be an initial registration procedure, a periodic registration, or a mobility registration procedure. The network (e.g., AMF) stores this UE capability.
[0058] 2. AMF sends a UE Authentication and Authorization request to AUSF / UDM to initiate the 5G AKA-based primary authentication and key agreement procedure.
[0059] 3. The UDM generates an AV (Authentication Vector). Then, a new Kausf is created in AUSF. At this point, AUSF maintains both the old and new Kausf.
[0060] 4. AUSF / UDM sends the UE Authentication and Authorization response to AMF.
[0061] 5. The AMF sends an Authentication Request message to the UE. The Authentication Request message may include network capability to send a NAS acknowledgment message when the 5G AKA-based primary authentication and key agreement procedure is successfully completed. When the UE receives the Authentication Request message, it stores this capability. Sending this capability is optional in the Authentication Request message. That is, this capability can be sent during any NAS procedure, either in other existing NAS messages (e.g., Registration Accept) or in a new NAS message. For example, if the UE indicates to the AMF that it supports receiving NAS acknowledgment messages sent from the network during a successful 5G AKA-based primary authentication and key agreement procedure, the AMF sends an Authentication Request message to the UE.
[0062] 6. Upon receiving an Authentication Request message, the UE verifies the AUTN as shown in Non-Patent Document 6. If the AUTN is successfully verified, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the most recent Kausf created before this step) and the new Kausf. The UE continues to use the old Kausf as the latest and valid Kausf in security procedures involving the Kausf.
[0063] If the network has previously indicated that it supports sending an acknowledgement message (e.g., Authentication Result) in a successful authentication procedure, the UE will wait for a NAS acknowledgement message and will not use a new Kausf in subsequent security procedures involving Kausf until it receives a NAS acknowledgement message indicating that the authentication procedure was successful.
[0064] 7. The UE sends an Authentication Response message containing RES* to the AMF.
[0065] 8. AMF performs a comparison between HRES* and HXRES*.
[0066] 9. Once HRES* verification in AMF is successful, AMF sends a UE Authentication and Authorization request to AUSF / UDM.
[0067] 10. AUSF performs a comparison between RES* and XRES*.
[0068] 11. If AUSF successfully verifies RES*, AUSF considers the new Kausf to be valid and deletes the old Kausf. AUSF then begins using the new Kausf as the latest and valid Kausf in subsequent security procedures involving Kausf.
[0069] 12. AUSF / UDM sends the UE Authentication and Authorization response to AMF.
[0070] 13. If the UE indicates to the AMF that it supports receiving NAS acknowledgement messages sent from the network during a successful 5G AKA-based primary authentication and key agreement procedure, the AMF will send an existing or new NAS message indicating the success of the 5G AKA-based primary authentication and key agreement procedure; otherwise, the AMF will not send a NAS acknowledgement message indicating the success of the 5G AKA-based primary authentication and key agreement procedure. For example, the AMF will send an Authentication Result to the UE indicating the success of the 5G AKA-based primary authentication and key agreement procedure.
[0071] 14. Upon receiving a NAS acknowledgement message, in security procedures involving Kausf, the UE deletes the old Kausf and begins using the new Kausf as the latest and most active version.
[0072] In one example, a UE might not have (or maintain, retain, save, or possess) an old Kausf. For instance, when a UE is first powered on, or before it begins its initial registration procedure, it might not have an old Kausf.
[0073] For example, in this embodiment, "The UE deletes the old Kausf and begins using the new Kausf as the latest and valid Kausf in security procedures involving Kausf" means "The UE begins using the new Kausf as the latest and valid Kausf in security procedures involving Kausf."
[0074] <Modification 1 of the second embodiment> After step 14, the UE may send an Authentication Acknowledgement message to the AMF to indicate that the UE authentication procedure was successful. Upon receiving the Authentication Acknowledgement message from the UE, the AMF confirms that the UE authentication procedure was successful and sends a UE Authentication and Authorization notify to the AUSF / UDM to indicate that the UE authentication procedure was successful. Upon receiving the UE Authentication and Authorization notify indicating that the UE authentication procedure was successful, the AUSF considers the new Kausf to be valid and deletes the old Kausf. The AUSF begins using the new Kausf as the latest and valid Kausf in subsequent security procedures involving Kausf. In this variation, step 11 is not performed by the AUSF; that is, the AUSF does not consider the new Kausf to be valid in step 11.
[0075] In one example, if the AMF sends an existing or new NAS message in step 13, it starts timer T3 to wait for an Authentication Acknowledgment message coming from the UE. Once timer T3 has expired, the AMF may resend an existing or new NAS message indicating the success of the 5G AKA-based primary authentication and key agreement, as shown in step 13.
[0076] In one example, the UE and the network perform the steps defined in the second embodiment without exchanging and checking the capability to receive an authentication result or send an authentication result message.
[0077] <Modification 2 of the second embodiment> If a UE has a PDU session for emergency services or for establishing an emergency services PDU session, and after sending an authentication response message, the UE receives a security mode command message with null encryption and null ciphering algorithms (NIA0 and NEA0), the UE shall not update the Kausf created during the authentication procedure. In other words, the UE shall not use Kausf in security procedures that involve Kausf. The UE may delete Kausf. For example, the UE deletes Kausf after a PDU session related to emergency services is released / deactivated, or after the UE enters the 5GMM DEREGISTERED state.
[0078] In one example, if the authentication result indicates that the authentication procedure failed and the UE receives a Security mode command message, the UE shall invalidate the Kausf created during the most recent authentication procedure. If the UE has an older Kausf being used in a security procedure, the UE shall continue to use that Kausf in the security procedure. This procedure applies to both 5G AKA and EAP AKA or other authentication methods used in 5GS.
[0079] <Third Embodiment (Solution 3)> The UE initiates the process of establishing the latest Kausf.
[0080] This embodiment applies to both 5G AKA-based primary authentication and key agreement procedures and EAP-based primary authentication and key agreement procedures.
[0081] Figure 7 shows the steps for creating the latest Kausf for the UE and network.
[0082] The detailed process of the embodiment is described below.
[0083] 0. The UE is successfully registered with the PLMN, and Kausf is created for both the UE and the network. This means that both the UE and the network each have (or maintain, keep, or store) a Kausf. If the UE has not yet registered with any PLMN, the UE does not have a valid Kausf.
[0084] 1. The network (e.g., AMF) initiates either a 5G AKA-based primary authentication and key agreement procedure or an EAP-based primary authentication and key agreement procedure and sends an Authentication Request message to the UE. The AUSF stores the new Kausf received from the UDM during the authentication procedure, as well as the old Kausf (created in step 0). The Authentication Request message may include network capability for receiving the first NAS message in step 7 if the UE detects a wireless link failure during the 5G AKA-based primary authentication and key agreement procedure or the EAP-based primary authentication and key agreement procedure. If the UE receives the Authentication Request message, it stores this capability. Sending this capability is optional in the Authentication Request message; that is, this capability can be sent in any NAS procedure, in other existing NAS messages (e.g., Registration Accept), or in a new NAS message.
[0085] 2. The UE verifies the AUTN parameter received in the Authentication Request message, as shown in Non-Patent Document 6. After successful verification of the AUTN parameter, the UE calculates (or creates or generates) a new Kausf (or new Kausf parameter) based on the parameters received in the Authentication Request message and the USIM parameter, as shown in Non-Patent Document 5. The UE has both the old Kausf (created in step 0) and the new Kausf created in this step.
[0086] 3. The UE sends an Authentication Response message containing *RES to the network.
[0087] 4. UE saves both the old Kausf created in step 2 and the new Kausf.
[0088] 5. The network will perform either a 5G AKA-based primary authentication and key agreement procedure or an EAP-based primary authentication and key agreement procedure, based on the selection made by the UDM.
[0089] 6. In the case of the 5G AKA based primary authentication and key agreement procedure, upon receiving an Authentication Response message containing RES*, AMF and AUSF verify HRES* and RES* respectively, as shown in Non-Patent Document 5. After successful verification of HRES* and RES*, AMF and AUSF consider the Kausf to be successful, and AUSF begins using the new Kausf created in AUSF. In this case, AMF sends an Authentication Result message to the UE indicating the success of the 5G AKA based primary authentication and key agreement procedure. If HRES* or RES* verification fails in AMF or AUSF, AMF sends a Registration Reject message to the UE.
[0090] In the EAP-based primary authentication and key agreement procedure, AMF sends NAS messages to the UE. Note that AMF may send multiple NAS messages to the UE during the EAP-based primary authentication and key agreement procedure.
[0091] In this procedure, Authentication Result messages, Authentication Reject messages, or NAS messages may be lost due to a wireless link failure between the network and the UE.
[0092] 7. If the UE detects a wireless link failure during the 5G AKA-based primary authentication and key agreement procedure or the EAP-based primary authentication and key agreement procedure, the UE sends a first NAS message to the AMF during the establishment of the next N1 NAS signaling connection. For example, if the UE sends an Authentication Response, the UE starts a timer, and if it does not receive an Authentication Result message, Authentication Reject message, or NAS message in step 6 and the timer expires, the UE detects a wireless link failure.
[0093] For example, NG-RAN may indicate to the UE that a radio link failure has occurred during the establishment of the next N1 NAS signaling connection, before sending the first NAS message to the AMF. The first NAS message can be a new NAS message or an existing NAS message (e.g., a Registration Request message if a registration procedure has been initiated, or a Service Request message if a service request procedure has been initiated). The first NAS message includes an Information Element (IE) indicating to the AMF that the UE has not completed a 5G AKA-based primary authentication and key agreement procedure or an EAP-based primary authentication and key agreement procedure. That is, if a 5G AKA-based primary authentication and key agreement procedure has been performed, either an Authentication Result message or an Authentication Reject message has not yet been received. If an EAP-based primary authentication and key agreement procedure has been performed, the NAS message carrying the next EAP message of the EAP-based primary authentication and key agreement procedure has not yet been received. The UE may also include ngKSI (5G Key Set Identifier) in the first NAS message. Upon receiving the first NAS message, AMF executes either Case 1 (Step 8a) or Case 2 (Step 8b).
[0094] After step 4, the N1 NAS signaling connection establishment procedure is performed, and if the UE receives a Security Mode Command message containing an ngKSI that matches the ngKSI associated with the new Kausf, the UE shall delete the old Kausf, make the new Kausf the latest and most active Kausf, and begin using the latest Kausf. The UE can make this decision because the ngKSI in the Security Mode Command message received from the AMF may serve as evidence that the AMF is maintaining the new Kausf as the latest and most active Kausf.
[0095] 8a. AMF initiates a new authentication procedure. Once the authentication procedure is successfully completed, the UE and AUSF begin using the latest Kausf created during the authentication procedure.
[0096] 8b. The AMF sends a second NAS message to the UE. The second NAS message can be the message from step 6, i.e., a NAS message containing an Authentication Result message, an Authentication Reject message, or an EAP message. The second NAS message may also be a DL NAS Transport message, a Registration Accept message, or a Service Accept message containing the result of the last performed EAP-based primary authentication and key agreement procedure. Upon receiving the ngKSI from the UE in step 7, the AMF sends the result of the EAP-based primary authentication and key agreement procedure corresponding to the received ngKSI.
[0097] 9. In the case of a 5G AKA-based primary authentication and key agreement procedure, if the UE receives an Authentication Result message as the second NAS message, the UE deletes the old Kasuf, marks the new Kasuf as the latest and valid Kasuf, and begins using the new Kasuf in subsequent security procedures involving Kausf. If the UE receives an Authentication Reject message as the second NAS message, the UE deletes the new Kasuf and continues to use the old Kasuf as the latest and valid Kasuf in security procedures involving Kausf.
[0098] In the case of an EAP-based primary authentication and key agreement procedure, the UE receives a second NAS message (EAP message) containing the authentication result. If the EAP authentication result contains an EAP failure message, the UE deletes the new Kausf and continues to use the old Kausf as the latest and valid Kausf in security procedures involving Kausf. If the authentication result contains an EAP success message, the UE deletes the old Kausf, makes the new Kausf the latest and valid Kausf, and begins using the new Kausf in subsequent security procedures involving Kausf. If the second message contains an ngKSI, the UE uses the received ngKSI to find the relevant Kausf within the UE. The UE uses the found Kausf as the latest and valid Kausf in subsequent security procedures involving Kausf.
[0099] In one example, a UE may not have (or maintain, retain, store, or possess) an old Kausf. For example, a UE may not have an old Kausf when it is first powered on or before it initiates the initial registration procedure. In this case, all situations in embodiments where an old Kausf would be effective mean that the UE does not have a valid Kausf. For example, in this embodiment, "The UE deletes the new Kausf and continues to use the old Kausf as the latest and effective Kausf in security procedures involving Kausf" means "The UE deletes the new Kausf and the UE does not have a valid Kausf." In this case, the UE may initiate the Registration procedure after deleting the new Kausf. For example, in this embodiment, "The UE shall delete the old Kausf, make the new Kausf the latest and effective Kausf, and begin using the latest Kausf" means "The UE shall make the new Kausf the latest and effective Kausf, and begin using the latest Kausf."
[0100] <Modification 1 of the third embodiment> Step 7 of this embodiment includes a list of Kausfs maintained by the UE (e.g., old Kausfs and new Kausfs). The AMF verifies which Kausfs in the list are being used by AUSF. The AMF then sends the matching Kausf being used by AUSF back to the UE in a second NAS message. The UE considers the received Kausf to be the latest and valid Kausf and begins using it in subsequent security mechanisms that require it. In one example, the UE does not include a list of Kausfs, and the AMF retrieves the latest Kausf from AUSF and sends this Kausf to the UE in a second NAS message.
[0101] In one example, the UE and AMF or AUSF maintain associations between Kausf and ngKSI. In the first NAS message in step 7, the UE sends a list of ngKSIs associated with the Kausf to be maintained. The network (AMF or AUSF) matches the received ngKSIs with the ngKSIs of the most recent Kausf. AMF sends back the matched ngKSIs used by AUSF to the UE. The UE shall make the Kausf associated with the received ngKSIs the most recent Kausf and enable it, and begin using it in security procedures that require Kausf. If the ngKSI list is not sent in the first NAS message, AMF shall send the ngKSIs of the most recent Kausf used by AUSF in a second NAS message. Upon receiving the second NAS message, the UE shall make the Kausf corresponding to the ngKSIs the most recent Kausf and enable it.
[0102] <Modified example 2 of the third embodiment> In this embodiment, a radio link failure detected by the UE may be considered a trigger for sending a first NAS message to the AMF.
[0103] As a variation of this trigger, if the UE sends an Authentication Response message to the AMF, the UE may start Timer T1, as described in Embodiment 1. When Timer T1 expires, the UE may consider the expiration of this timer as a trigger and send a first NAS message to the AMF. Therefore, when Timer T1 expires, the UE sends a first NAS message to the AMF.
[0104] When the UE receives the second message, it stops timer T1.
[0105] <Fourth Embodiment (Solution 4)> This embodiment applies to both 5G AKA-based primary authentication and key agreement procedures and EAP-based primary authentication and key agreement procedures.
[0106] In the first, second, and third embodiments, if a UE has multiple Kausfs and receives steering of roaming information in a Registration accept message or Configuration Update Command message, the UE shall use each Kausf to perform a steering of roaming security check. If the security check using the Kausf is successful (passes), the UE shall make the Kausf the latest and most active Kausf and begin using the Kausf in subsequent security procedures that require it. The UE applies the same process to UE Parameters Update procedures. For example, if the UE performs a security check of a security procedure or security mechanism (e.g., updating the steering of roaming or the UE Parameters Update procedure), and the UE has two Kausfs (e.g., an old Kausf and a new Kausf), and the security check using the old Kausf is successful (or completes successfully), the UE may make the old Kausf the latest and most active Kausf, begin using the old Kausf in subsequent security procedures that require it, and delete the new Kausf. Furthermore, if the UE performs a security check and has two Kausfs (for example, an old Kausf and a new Kausf), and the security check is successful using the new Kausf, the UE may consider the new Kausf to be the latest and most active Kausf, begin using the new Kausf in subsequent security procedures that require it, and delete the old Kausf.
[0107] Furthermore, for example, if a UE performs a security check and the UE has two Kausfs, the UE may initially use one of the two Kausfs to perform the security check. If the security check using one Kausf is successful, the UE may make that one Kausf the most up-to-date and active version, begin using that Kausf in subsequent security procedures that require a Kausf, and delete the other Kausf. If the security check using one Kausf is unsuccessful, the UE may perform the security check using the other Kausf. If the security check using the other Kausf is successful, the UE may make that other Kausf the most up-to-date and active version, begin using that other Kausf in subsequent security procedures that require a Kausf, and delete the first Kausf.
[0108] In one example, a UE may not have (or maintain, retain, save, or possess) an old Kausf. For instance, a UE may not have an old Kausf when it is first powered on or before it begins its initial registration procedure.
[0109] In this case, if the UE has one Kausf and receives steering of roaming information in a Registration accept message or Configuration Update Command message while the UE has not received an Authentication Result message, the UE shall use Kausf to perform a security check of steering of roaming. If the security check using Kausf is successful, the UE shall make Kausf up-to-date and active and begin using Kausf in subsequent security procedures that require it.
[0110] <Fifth Embodiment (Solution 5)> If the AMF is waiting for an Authentication Response message and detects a radio link failure, it will resend an Authentication Request message.
[0111] This embodiment applies to both 5G AKA-based primary authentication and key agreement procedures and EAP-based primary authentication and key agreement procedures. Figure 8 shows the procedure for creating a modern Kausf on the UE and network.
[0112] The following describes the detailed process of the embodiment. UE and AUSF each have (or maintain, retain, or preserve) an old Kausf.
[0113] 1. For registration procedures as triggers to UE authentication procedures, the UE sends a Registration Request message to the network containing a first Information Element (IE) indicating support for repeated reception of authentication-related messages (e.g., Authentication Result, Authentication Reject, DL NAS transport messages) sent from the network during the UE authentication procedure. Sending this capability is optional in the Registration Request message, and this capability can be sent in other existing NAS messages or in new NAS messages during any NAS procedure. The registration procedure can be an initial registration procedure, a periodic registration, or a mobility registration procedure. The network (e.g., AMF) stores this UE capability.
[0114] 2. The AMF sends a UE Authentication and Authorization request to the AUSF / UDM to initiate either the 5G AKA-based primary authentication and key agreement procedure or the EAP-based primary authentication and key agreement procedure.
[0115] 3. The UDM generates the AV. Then a new Kausf is created in AUSF. AUSF maintains both the old and new Kausf at this point.
[0116] 4. AUSF / UDM sends the UE Authentication and Authorization response to AMF.
[0117] 5. The AMF sends an Authentication Request message to the UE. In case authentication-related messages are lost between the UE and the AMF, the Authentication Request message may include a network capability to repeatedly send authentication-related messages (e.g., Authentication Result, Authentication Reject, DL NAS transport message). When the UE receives the Authentication Request message, it stores this capability. Sending this capability is optional with the Authentication Request message. That is, this capability can be sent during any NAS procedure, either in other existing NAS messages (e.g., Registration Accept) or in a new NAS message.
[0118] 6. The AMF starts Timer T2. For example, the AMF starts Timer T2 simultaneously with, or after, sending the Authentication Request message in Step 5. In other words, the trigger for starting Timer T2 is the sending of the Authentication Request message in Step 5. Timer T2 may be a new timer or an existing timer. T2 may also be T3560.
[0119] 7. Upon receiving the Authentication Request message, the UE verifies the AUTN as shown in Non-Patent Document 6. After successful verification of the AUTN, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the most recent Kausf created before this step) and the new Kausf. The UE still uses the old Kausf as the latest and valid Kausf in security procedures involving the Kausf.
[0120] If the network previously indicated that it supports repeated transmission of authentication-related messages (e.g., Authentication Result, Authentication Reject, DL NAS transport messages), the UE should be able to process these messages repeatedly, even if it only processed them once.
[0121] 8. The UE sends an Authentication Response message containing RES* to the AMF. However, this message is lost and cannot reach the AMF. For example, the Authentication Response message is lost and the AMF cannot be reached due to a radio link failure.
[0122] 9. Timer T2 expires at AMF.
[0123] 10. When Timer T2 expires, the AMF sends the authentication-related message sent in step 5 to the UE.
[0124] In one example, if the AMF detects a radio link failure while timer T2 is running, the AMF stops timer T2 and immediately sends an Authentication Request message to the UE upon detecting the radio link failure. In other words, the AMF does not wait for timer T2 to expire. For example, NG-RAN indicates to the AMF via an NGAP message that the UE radio connection has been lost, and the AMF detects the radio link failure based on the NGAP message. Furthermore, for example, if the AMF detects a radio link failure, the AMF keeps timer T2 running and, upon timer T2 expiring, sends the authentication-related message sent in step 5 to the UE.
[0125] 11. Upon receiving the Authentication Request message, the UE verifies the AUTN as described in Non-Patent Document 6. After successful verification of the AUTN, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the most recent Kausf created before this step) and the new Kausf. In security procedures involving Kausf, the UE still uses the old Kausf as the latest and valid Kausf.
[0126] 12. The UE sends an Authentication Response message containing RES* to the AMF.
[0127] 13. The network performs the UE authentication procedure.
[0128] 14. When the HRES* and RES* verifications are successful in AMF and AUSF respectively, AMF sends an Authentication Result message to the UE.
[0129] 15. Upon receiving the Authentication Result message, the UE deletes the old Kausf and begins using the new Kausf as the latest and most effective Kausf in security procedures that involve it.
[0130] In one example, a UE may not have an old Kausf (it may not maintain, retain, save, or possess it). For example, when a UE is first powered on, or before it initiates the initial registration procedure, it may not have an old Kausf. In this case, for example, "the UE deletes the old Kausf and begins using the new Kausf as the latest and valid Kausf in security procedures involving Kausf" in this embodiment means "the UE begins using the new Kausf as the latest and valid Kausf in security procedures involving Kausf."
[0131] <Modified form of Embodiment 5> In this embodiment, the repeated transmission of Authentication Request messages by AMF is disclosed upon the expiration of timer T2.
[0132] As one example, this repeated message sending mechanism triggered by the expiration of timer T2 can be used in the EAP-based primary authentication and key agreement procedure. Since multiple NAS messages are communicated between the UE and AMF during the EAP-based primary authentication and key agreement procedure, in this embodiment, any authentication-related NAS message from AMF to UE can be used for NAS message retransmission. That is, the NAS message containing the EAP message in step 5 can be repeatedly sent by AMF in step 10 when timer T2 expires.
[0133] <Sixth Embodiment (Solution 6)> If AMF detects a wireless link failure before receiving an Authentication Response message, it initiates a new authentication procedure.
[0134] This embodiment applies to both 5G AKA-based primary authentication and key agreement procedures and EAP-based primary authentication and key agreement procedures. Figure 9 shows the procedure for creating a modern Kausf on the UE and network.
[0135] The following describes the detailed process of the embodiment. UE and AUSF each have (or maintain, retain, or preserve) an old Kausf.
[0136] 1. For a registration procedure as a trigger to a UE authentication procedure, the UE sends a Registration Request message to the network that includes a first Information Element (IE) indicating support for repeated reception of authentication-related messages (e.g., Authentication Result, Authentication Reject, DL NAS transport messages) sent from the network during the UE authentication procedure. Sending this capability is optional in the Registration Request message; that is, this capability can be sent during the NAS procedure in other existing NAS messages or in new NAS messages. The registration procedure may be an initial registration procedure, a periodic registration, or a mobility registration procedure. The network (e.g., AMF) stores this UE capability.
[0137] 2. The AMF sends a UE Authentication and Authorization request to the AUSF / UDM to initiate either the 5G AKA-based primary authentication and key agreement procedure or the EAP-based primary authentication and key agreement procedure.
[0138] 3. The UDM generates the AV. Then a new Kausf is created in AUSF. AUSF maintains both the old and new Kausf at this point.
[0139] 4. AUSF / UDM sends the UE Authentication and Authorization response to AMF.
[0140] 5. The AMF sends an Authentication Request message to the UE. If authentication-related messages are lost between the UE and the AMF, the Authentication Request message may include network capability to repeatedly send authentication-related messages (e.g., Authentication Result, Authentication Reject, and DL NAS transport messages). When the UE receives the Authentication Request message, it stores this capability. Sending this capability is optional with the Authentication Request message. In other words, this capability can be sent in other existing NAS messages (e.g., Registration Accept) or in NAS messages during the NAS procedure.
[0141] 6. The AMF starts Timer T2. For example, the AMF starts Timer T2 at the same time as, or after, sending the Authentication Request message in Step 5. In other words, the trigger for starting Timer T2 is sending the Authentication Request message in Step 5.
[0142] 7. Upon receiving the Authentication Request message, the UE verifies the AUTN as shown in Non-Patent Document 6. After successful verification of the AUTN, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the most recent Kausf created before this step) and the new Kausf. In security procedures involving Kausf, the UE still uses the old Kausf as the latest and valid Kausf.
[0143] If the network previously indicated that it supports repeated transmission of authentication-related messages (e.g., Authentication Result, Authentication Reject, DL NAS transport messages), the UE should be able to handle repeated authentication-related messages, even if it only processed them once.
[0144] 8. The UE sends an Authentication Response message containing RES* to the AMF. However, this message is lost and cannot reach the AMF. For example, the Authentication Response message is lost and cannot reach the AMF due to a radio link failure.
[0145] 9. Timer T2 expires at AMF.
[0146] 10. When Timer T2 expires, AMF initiates a new authentication procedure by sending a UE Authentication and Authorization request to AUSF / UDM, as shown in Step 2 of Figure 9. Once the UE authentication procedure between the UE and the network is successfully completed, the UE and AUSF begin using the Kausf created during this new authentication procedure for security procedures involving Kausf.
[0147] In one example, if the AMF detects a radio link failure while Timer T2 is running, the AMF initiates a new authentication procedure. In this case, the AMF stops Timer T2 and immediately sends a UE Authentication and Authorization request to the AUSF / UDM, as shown in step 2 of Figure 9. That is, the AMF does not wait for Timer T2 to expire. For example, NG-RAN indicates to the AMF that the UE radio connection has been lost via an NGAP message, and the AMF detects a radio link failure based on the NGAP message. Alternatively, for example, if the AMF detects a radio link failure, the AMF continues to run Timer T2, and when Timer T2 expires, the AMF sends an Authentication and Authorization request to the AUSF / UDM, as shown in step 2 of Figure 9.
[0148] In one example, a UE may not retain old Kausf files. For instance, a UE may not retain old Kausf files when it is first powered on or before it initiates the initial registration procedure.
[0149] The process described above in this embodiment can be applied to this example.
[0150] User equipment (UE) Figure 10 is a block diagram showing the main components of UE(1000). As shown, UE(1000) includes transceiver circuits (1002) that are capable of transmitting signals to and receiving signals from connected nodes via one or more antennas (1001). Although not necessarily shown in Figure 10, UE naturally has all the usual functionality of conventional mobile devices (such as user interfaces), which may be provided by hardware, software, and firmware, or any combination thereof, as needed. Software may be pre-installed in memory and / or may be downloaded, for example, via a telecommunications network or from a removable data storage device (RMD).
[0151] The controller (1004) controls the operation of the UE according to software stored in memory (1005). The software includes, among other things, an operating system and a communication control module having at least a transceiver control module. The communication control module (using its transceiver control submodule) is responsible for processing (generating / sending / receiving) signaling and uplink / downlink data packets between the UE and other nodes, such as base stations / (R)AN nodes, MMEs, AMFs (and other core network nodes). Such signaling may include, for example, appropriately formatted signaling messages related to connection establishment and maintenance (e.g., RRC connection establishment and RRC messages), messages related to periodic location updates (e.g., tracking area update, paging area updates, location area update), etc. Such signaling may also include, for example, broadcast information (e.g., Master Information and System Information) in the received case.
[0152] (R)AN node Figure 11 is a block diagram showing the main components of an exemplary (R)AN node (1100), for example, a base station ("eNB" in LTE, "gNB" in 5G). As shown, the (R)AN node includes transceiver circuitry (1102) that is operable to transmit signals to and receive signals from connected UEs via one or more antennas (1101), and to transmit signals to and receive signals from other network nodes (directly or indirectly) via a network interface (1103). A controller (1104) controls the operation of the (R)AN node according to software stored in memory (1105). The software may be pre-installed in memory and / or may be downloaded, for example, via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system and a communications control module having at least a transceiver control module.
[0153] The communication control module (using its transceiver control submodules) is responsible for processing (generating / sending / receiving) signaling between (R)AN nodes and other nodes, such as UEs, MMEs, AMFs, etc., either directly or indirectly. The signaling may include, for example, appropriately formatted signaling messages relating to radio connectivity and location procedures (for a particular UE), particularly connectivity establishment and maintenance (e.g., RRC connectivity establishment and other RRC messages), messages related to periodic location updates (e.g., tracking area updates, paging area updates, location area updates), S1 AP messages and NG AP messages (i.e., messages from the N2 reference point), etc. Such signaling may also include, for example, broadcast information (e.g., master information and system information) when transmitted.
[0154] The controller, if implemented, is also configured (by software or hardware) to handle related tasks such as UE mobility estimation and / or moving trajectory estimation.
[0155] AMF Figure 12 is a block diagram showing the main components of AMF(1200). AMF(1200) is included in 5GC (5G Core Network). As shown, AMF(1200) includes transceiver circuitry (1201) that can operate to transmit signals to and receive signals from other nodes (including UEs) via a network interface (1204). A controller (1202) controls the operation of AMF(1200) according to software stored in memory (1203). The software may be pre-installed in memory (1203) and / or may be downloaded, for example, via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system and a communications control module having at least a transceiver control module.
[0156] The communication control module (using its transceiver control submodules) is responsible for processing (generating / sending / receiving) signaling between the AMF and other nodes, such as UEs, base stations / (R)AN nodes (e.g., "gNB" or "eNB"), either directly or indirectly. Such signaling may include, for example, appropriately formatted signaling messages related to the procedures described herein, such as NG AP messages (i.e., messages from the N2 reference point) for transmitting NAS messages from and to UEs.
[0157] In this disclosure, User Equipment (or "UE," "mobile station," "mobile device," or "wireless device") is an entity connected to a network via a wireless interface. The UEs of this specification are not limited to dedicated communication devices, but may be any device having communication capabilities as a UE as described herein, such as:
[0158] The terms "User Equipment (UE)" (as used in 3GPP), "Mobile Station," "Mobile Device," and "Radio Device" are generally intended to be synonymous with each other and may refer to standalone mobile stations such as terminals, mobile phones, smartphones, tablets, cellular IoT terminals, and IoT devices. It should also be understood that the terms "UE" and "Radio Terminal" can include devices that remain stationary for extended periods.
[0159] UE may be, for example, equipment for production or manufacturing and / or energy-related machinery (e.g., equipment and machinery such as: boilers; engines; turbines; solar panels; wind turbines; hydroelectric generators; thermal power plants; nuclear power plants; batteries; nuclear systems and / or related equipment; heavy electrical equipment; pumps including vacuum pumps; compressors; fans; blowers; hydraulic equipment; pneumatic equipment; metalworking machinery; manipulators; robots and their application systems; tools; molds or dies; rolls; conveying equipment; lifting equipment; material handling equipment; textile machinery; sewing machines; printing and / or related machinery; paper processing machinery; chemical machinery; mining and / or construction machinery and / or related equipment; agricultural, forestry, and fisheries machinery and equipment; safety and / or environmental protection equipment; tractors; precision bearings; chains; gears; power transmission equipment; lubrication equipment; valves; pipe fittings; and / or application systems such as the aforementioned equipment or machinery).
[0160] Furthermore, UE may also be, for example, a transport device (such as a vehicle, automobile, motorcycle, bicycle, train, bus, cart, rickshaw, ship and other watercraft, airplane, rocket, satellite, drone, balloon, etc.). Furthermore, the UE may also be, for example, information and communication equipment (such as computers and related devices, communication equipment and related devices, and electronic components). Furthermore, UE may also include, for example, refrigerators, refrigerator applications and equipment, commercial and service equipment, vending machines, automated service machines, office machinery and equipment, and consumer electrical and electronic machinery and appliances (such as audio equipment, video equipment, speakers, radios, televisions, microwave ovens, rice cookers, coffee makers, dishwashers, washing machines, dryers, fans, ventilation fans and related products, vacuum cleaners, etc.).
[0161] Furthermore, the UE may also be, for example, an electronic application system or electronic application device (such as an X-ray system, particle accelerator, radioactive material application device, sound wave device, electromagnetic application device, power application device, etc.).
[0162] Furthermore, UE may also include, for example, electronic lamps, lighting fixtures, measuring instruments, analyzers, testers, or surveying or sensing equipment (e.g., surveying or sensing equipment such as: smoke detectors; motion sensors; wireless tags, etc.), watches or clocks, laboratory equipment, optical instruments, medical equipment and / or systems, weapons, bladed items, hand tools, etc.
[0163] Furthermore, the UE may also be, for example, a personal digital assistant or related device with wireless communication capabilities (such as a wireless card or module designed to be attached to or inserted into other electronic devices, such as a personal computer or electrical measuring instrument).
[0164] Furthermore, a UE may be part of a device or system that provides the following applications, services, and solutions in the Internet of Things (IoT), for example, using wired or wireless communication technologies: An IoT device (or thing) comprises appropriate electronics, software, sensors, network connectivity, etc., that enable the device to collect and exchange data with each other and with other communication devices. An IoT device may also include automated devices that follow software instructions stored in internal memory. An IoT device may operate without requiring human supervision or response. An IoT device may be installed in a device for an extended period and / or remain in an inactive state for an extended period. An IoT device may be implemented as part of (generally) stationary equipment. An IoT device may be embedded in non-stationary equipment (e.g., a vehicle) or attached to animals or people that are being monitored / tracked.
[0165] It will be understood that IoT technology can be implemented on any communication device that can connect to a communication network that sends and receives data independently of human input or software instructions stored in memory.
[0166] It will be understood that IoT devices are sometimes called Machine Type Communication (MTC) devices, or Machine to Machine (M2M) communication devices, or Narrow Band IoT (NB-IoT) UEs. It will also be understood that a UE can support one or more IoT or MTC applications. Some examples of MTC applications are listed in Table 1 below (source: 3GPP TS 22.368 Annex B, whose contents are incorporated herein by reference). This list is not exhaustive and represents only examples of machine type communication applications.
[0167] Table 1: Some examples of machine-type communication applications [Table 1]
[0168] Applications, services, and solutions may include, for example, MVNO (Mobile Virtual Network Operator) services, emergency radio communication systems, PBX (Private Branch eXchange) systems, PHS / digital cordless telephone systems, POS (Point of Sale) systems, advertising broadcasting systems, MBMS (Multimedia Broadcast and Multicast Service), V2X (Vehicle to Everything) systems, train radio systems, location-related services, disaster / emergency radio communication services, community services, video distribution services, Femto cell application services, VoLTE (Voice over LTE) services, billing services, radio on-demand services, roaming services, behavioral monitoring services, communication carrier / communication network selection services, function restriction services, PoC (Proof of Concept) services, personal information management services, and ad-hoc network / DTN (Delay Tolerant Networking) services. It should be noted that the above-mentioned categories of UEs are merely examples of applications of the technical concepts and exemplary embodiments described herein. These technical concepts and embodiments are not limited to the above-mentioned UEs, and various modifications can be made to them.
[0169] The disclosure is shown and described in particular with reference to its exemplary embodiments, but the disclosure is not limited to these embodiments. It will be understood by those skilled in the art that various modifications of form and detail can be made without departing from the spirit and scope of the disclosure as defined herein. For example, the embodiments described above are not limited to 5GS and are applicable to communication systems other than 5GS.
[0170] The embodiments disclosed above, in whole or in part, may be described as follows, but are not limited thereto.
[0171] (Note 1) A method for a user device (UE) to store a first key, Calculate the second key, Send an Authentication Response message, A timer is started based on the sending of the Authentication Response message. If the UE does not receive an Authentication Reject message and the timer expires, delete the first key. If the UE does not receive an Authentication Reject message and the timer expires, the second key is enabled. If the UE receives the Authentication Reject message while the timer is running, the second key is deleted. A method for enabling the first key if the UE receives the Authentication Reject message while the timer is running. (Note 2) The method according to Appendix 1, wherein, when the timer is running and a predetermined process is being performed, the first key and the second key are used for the predetermined process. (Note 3) If the security check for the predetermined process is successful by using the second key, the first key is deleted. If the security check is successful by using the second key, the second key is enabled. If the security check is successful by using the first key, the second key is deleted. The method described in Appendix 2, wherein the first key is activated if the security check is successful by using the first key. (Note 4) The first piece of information is sent to the network device. The first piece of information indicates that the UE supports receiving messages. Calculate the first key, Receive second information from the network device, The second piece of information indicates that the network device supports sending messages. Calculate the second key, Send an Authentication Response message, If the UE supports receiving the message, it receives the message. When the aforementioned message is received, delete the first key. A method for a user device (UE) to enable the second key when the aforementioned message is received. (Note 5) The first piece of information is received from the user device (UE). The first piece of information indicates that the UE supports receiving messages. Send the second piece of information to the UE, The second piece of information indicates that the network device supports sending messages. Upon receiving the Authentication Response message, A method for a network device to send a message indicating the validity of a key, if the aforementioned UE supports receiving messages. (Note 6) A user device (UE) for storing a first key, A means for calculating the second key, A means of sending an Authentication Response message, A means of starting a timer based on the sending of an Authentication Response message, A means for deleting the first key when the UE does not receive an Authentication Reject message and the timer expires, Means for enabling the second key when the UE does not receive an Authentication Reject message and the timer expires, Means for deleting the second key when the UE receives the Authentication Reject message while the timer is running, A UE comprising means for enabling the first key when the UE receives the Authentication Reject message while the timer is running. (Note 7) The UE according to Appendix 6 further comprises means for using the first key and the second key for the predetermined processing when the timer is running and the predetermined processing is being performed. (Note 8) If the security check for the predetermined process is successful by using the second key, the means for deleting the first key, A means for enabling the second key if the security check is successful by using the second key, A means for deleting the second key if the security check is successful by using the first key, The UE described in Appendix 7, further comprising means for activating the first key if the security check is successful by using the first key. (Note 9) Means for transmitting first information to a network device, The first piece of information indicates that the UE supports receiving messages. A means for calculating the first key, Means for receiving second information from a network device, The second piece of information indicates that the network device supports sending messages. A means for calculating the second key, A means of sending an Authentication Response message, If the UE supports receiving the message, it receives the message. A means for deleting the first key when the aforementioned message is received, A user device (UE) comprising means for activating the second key when the aforementioned message is received. (Note 10) Means for receiving first information from user equipment (UE), The first piece of information indicates that the UE supports receiving messages. A means for transmitting the second piece of information to the UE, The second piece of information indicates that the network device supports sending messages. A means of receiving an Authentication Response message, A network device comprising: means for sending a message indicating the validity of a key when the aforementioned UE supports receiving messages. (Note 11) Key calculation policy Send an Authentication Response message, Based on the transmission of the aforementioned Authentication Response message, the timer is started. If the UE does not receive an Authentication Reject message and the timer expires, the key is enabled. A method for a user device (UE) to delete the key if the UE receives the Authentication Reject message while the timer is running. (Note 12) The method according to Appendix 11, wherein the key is used for the predetermined process when the timer is running and the predetermined process is being performed. (Note 13) If the security check for the predetermined process fails by using the aforementioned key, the key is deleted. The method described in Appendix 12, wherein the key is activated if the security check is successful when the key is used. (Note 14) The first piece of information is sent to the network device. The first piece of information indicates that the UE supports receiving messages. Key calculation policy The network device receives the second piece of information, The second piece of information indicates that the network device supports sending messages. Send an Authentication Response message, Receive the message if the UE supports receiving messages; A user device (UE) that activates the key upon receiving the aforementioned message. (Note 15) Key calculation policy A means of sending an Authentication Response message, Means for starting a timer based on the transmission of the aforementioned Authentication Response message, Means for enabling the key when the UE does not receive an Authentication Reject message and the timer expires, A user device (UE) comprising means for deleting the key if the UE receives the Authentication Reject message while the timer is running. (Note 16) The UE described in Appendix 15 further comprises means for using the key for the predetermined process when the timer is running and the predetermined process is being performed. (Note 17) A means for deleting the key if the security check for the predetermined process fails when the key is used, The UE described in Appendix 16 further comprises means for activating the key if the security check is successful by using the key. (Note 18) Means for transmitting first information to a network device, The first piece of information indicates that the UE supports receiving messages. Key calculation policy means for receiving second information from the aforementioned network device, The second piece of information indicates that the network device supports sending messages. A means of sending an Authentication Response message, If the UE supports receiving messages, the means for receiving messages; A user device (UE) comprising means for activating the key when the aforementioned message is received. (Note 19) A method for a user device (UE) to store a first key, During the authentication process, calculate the second key, Send an Authentication Response message, Detects wireless link failure, If the aforementioned wireless link failure is detected, a message indicating that the authentication procedure has not been completed is sent. Perform the aforementioned authentication procedure, Once the aforementioned authentication procedure is complete, delete the first key. A method for activating the second key when the aforementioned authentication procedure is completed. (Note 20) A method for a user device (UE) to store a first key, During the authentication process, calculate the second key, Send an Authentication Response message, Detects wireless link failure, If the aforementioned wireless link failure is detected, a first message indicating that the authentication procedure has not been completed is sent. Upon receiving a second message indicating whether the first key or the second key is valid, If the second message indicates that the second key is valid, delete the first key. If the second message indicates that the second key is valid, enable the second key. If the second message indicates that the first key is valid, delete the second key. A method for enabling the first key when the second message indicates that the first key is valid. (Note 21) The first message mentioned above includes a list, The aforementioned list includes the first key and the second key, If the first message includes the list, a third message is received indicating whether the first key or the second key is valid. If the third message indicates that the second key is valid, delete the first key. If the third message indicates that the second key is valid, enable the second key. If the third message indicates that the first key is valid, delete the second key. The method according to Appendix 20, further comprising enabling the first key if the third message indicates that the first key is valid. (Note 22) The first message mentioned above includes a list, The aforementioned list includes first information related to the first key and second information related to the second key, If the first message contains a list, a third message is received that indicates either the first information or the second information. If the third message indicates the second information, delete the first key. The second key is enabled when the third message indicates the second information. If the third message indicates the first information, delete the second key. The method described in Appendix 20, further comprising enabling the first key when the third message indicates the first information. (Note 23) A method for a user device (UE) to store a first key, During the first authentication procedure, calculate the second key. Send an Authentication Response message, Based on the transmission of the aforementioned Authentication Response message, the timer is started. If the timer expires, a first message indicating that the first authentication procedure has not been completed is sent. Perform the second authentication procedure, When the second authentication procedure is completed, delete the first key. A method for activating the second key when the second authentication procedure is completed. (Note 24) A method of Access and Mobility Management Function (AMF), Perform the first authentication procedure, Upon receiving a message indicating that the first authentication procedure described above has not been completed, A method for performing a second authentication procedure to demonstrate the validity of the key upon receiving the aforementioned message. (Note 25) A method for Access and Mobility Management Function (AMF), Perform the authentication procedure, During the above procedure, a first message indicating the validity of the key is sent, Upon receiving a second message indicating that the above procedure has not been completed, A method for sending the first message when the second message is received. (Note 26) A method for a user device (UE) to store a first key, Calculate the second key, Execute the first process based on the first key, The first key is activated when the first process based on the first key is completed. When the first process based on the first key is completed, the second key is deleted. A second process is executed based on the second key mentioned above. The second key is activated when the second process based on the second key is completed. A method for deleting the first key when the second process based on the second key is completed. (Note 27) A method for a user device (UE) to store a first key, Upon receiving the first Authentication Request message, Calculate the second key, Upon receiving the second Authentication Request message, Send an Authentication Response message, Upon receiving a message indicating the validity of the second key, When the aforementioned message is received, the second key is enabled. A method for deleting the first key when the aforementioned message is received. (Note 28) A method for Access and Mobility Management Function (AMF), Send the first Authentication Request message, A timer is started based on the sending of the first Authentication Request message. When the timer expires, a second Authentication Request message is sent. Upon receiving the Authentication Response message, A method for sending a message indicating the validity of a key. (Note 29) Detects wireless link failure, The method according to Appendix 28, further comprising sending the second Authentication Request message if a wireless link failure is detected while the timer is running. (Note 30) A method for a user device (UE) to store a first key, During the first authentication procedure, the first Authentication Request message is received. Calculate the second key, Perform the second authentication procedure, The third key is activated when the second authentication procedure described above is completed. The third key is created by the method described above in the second authentication procedure. (Note 31) A method for Access and Mobility Management Function (AMF), During the first authentication procedure, an Authentication Request message is sent. The timer is started based on the transmission of the aforementioned Authentication Request message. A method to perform a second authentication procedure to prove the validity of the key when the timer expires. (Note 32) A user equipment (UE) that stores a first key, means for calculating a second key during an authentication procedure; means for transmitting an Authentication Response message; means for detecting a radio link failure; means for transmitting a message indicating that the authentication procedure has not completed when the radio link failure is detected; means for executing the authentication procedure; means for deleting the first key when the authentication procedure is completed; and means for enabling the second key when the authentication procedure is completed. The UE comprises these means. (Appendix 33) A user equipment (UE) that stores a first key, means for calculating a second key during an authentication procedure; means for transmitting an Authentication Response message; means for detecting a radio link failure; means for transmitting a first message indicating that the authentication procedure has not completed when the radio link failure is detected; means for receiving a second message indicating whether the first key or the second key is valid; means for deleting the first key when the second message indicates that the second key is valid; means for enabling the second key when the second message indicates that the second key is valid; means for deleting the second key when the second message indicates that the first key is valid; and means for enabling the first key when the second message indicates that the first key is valid. The UE comprises these means. (Appendix 34) The first message includes a list, the list includes the first key and the second key, means for receiving a third message indicating whether the first key or the second key is valid when the first message includes the list; means for deleting the first key when the third message indicates that the second key is valid; means for enabling the second key when the third message indicates that the second key is valid; means for deleting the second key when the third message indicates that the first key is valid; means for enabling the first key when the third message indicates that the first key is valid, the UE according to Appendix 33 further comprising. (Appendix 35) The first message includes a list, The list includes first information related to the first key and second information related to the second key, means for receiving a third message indicating either the first information or the second information when the first message includes a list; means for deleting the first key when the third message indicates the second information; means for enabling the second key when the third message indicates the second information; means for deleting the second key when the third message indicates the first information; means for enabling the first key when the third message indicates the first information, the UE according to Appendix 33 comprising. (Appendix 36) A user equipment (UE) for storing a first key, means for calculating a second key during a first authentication procedure; means for transmitting an Authentication Response message; means for starting a timer based on the transmission of the Authentication Response message; A means for sending a first message indicating that the first authentication procedure has not been completed when the timer expires, A means of performing the second authentication procedure, A means for deleting the first key when the second authentication procedure is completed, A UE comprising means for activating the second key when the second authentication procedure is completed. (Note 37) A means for performing the first authentication procedure, Means for receiving a message indicating that the first authentication procedure has not been completed, An AMF comprising means for performing a second authentication procedure to demonstrate the validity of the key when the aforementioned message is received. (Note 38) Means for performing the authentication procedure, During the procedure described above, means for sending a first message indicating the validity of the key, Means for receiving a second message indicating that the above procedure has not been completed, An AMF comprising means for transmitting the first message when the second message is received. (Note 39) A user device (UE) for storing a first key, A means for calculating the second key, A means for executing a first process based on a first key, Means for activating the first key when the first process based on the first key is completed, A means for deleting the second key when the first process based on the first key is completed, Means for performing a second process based on the second key, Means for activating the second key when the second process based on the second key is completed, A UE comprising means for deleting the first key when the second processing based on the second key is completed. (Note 40) A user device (UE) that stores a first key, A means for receiving a first Authentication Request message, A means for calculating the second key, A means for receiving a second Authentication Request message, A means of sending an Authentication Response message, Means for receiving a message indicating the validity of the second key, Means for enabling the second key when the aforementioned message is received, A UE comprising means for deleting the first key when the aforementioned message is received. (Note 41) Access and Mobility Management Function (AMF), A means for sending the first Authentication Request message, Means for starting a timer based on the transmission of the first Authentication Request message, A means of sending a second Authentication Request message when the timer expires, A means of receiving an Authentication Response message, An AMF comprising means for sending a message indicating the validity of a key. (Note 42) Means for detecting wireless link failures, The AMF according to Appendix 41 further includes means for sending the second Authentication Request message when a wireless link failure is detected during the execution of the timer. (Note 43) A user device (UE) for storing a first key, A means for receiving a first Authentication Request message during the first authentication procedure, A means for calculating the second key, A means of performing the second authentication procedure, means for enabling a third key when the second authentication procedure is completed; The UE includes means for creating the third key in the second authentication procedure. (Appendix 44) means for transmitting an Authentication Request message during a first authentication procedure; means for starting a timer based on the transmission of the Authentication Request message; means for executing a second authentication procedure to indicate the validity of a key when the timer expires, the AMF comprising: (Appendix 45) calculate a key during the authentication procedure, send an Authentication Response message, detect a radio link failure, when a radio link failure is detected, send a first message indicating that the authentication procedure has not been completed, execute the authentication procedure, A method for a user equipment (UE) to calculate a key during an authentication procedure, send an Authentication Response message, detect a radio link failure, send a first message indicating that the authentication procedure has not been completed when the radio link failure is detected, execute the authentication procedure, and enable the key when the authentication procedure is completed. (Appendix 46) calculate a key during the authentication procedure, send an Authentication Response message, detect a radio link failure, when the radio link failure is detected, send a first message indicating that the authentication procedure has not been completed, receive a second message indicating whether the key is valid, delete the key when the second message indicates that the key is invalid, A method for a user equipment (UE) to calculate a key during an authentication procedure, send an Authentication Response message, detect a radio link failure, send a first message indicating that the authentication procedure has not been completed when the radio link failure is detected, receive a second message indicating whether the key is valid, delete the key when the second message indicates that the key is invalid, and enable the key when the second message indicates that the key is valid. (Appendix 47) The first message includes a key, when the first message includes the key, receive a third message indicating whether the key is valid, If the third message indicates that the key is invalid, delete the key. The method according to Appendix 46, wherein the third message indicates that the key is valid, and the key is enabled. (Note 48) The first message includes information related to the key, Upon receiving the third message indicating the aforementioned information, If the third message does not indicate the information, delete the key. The method described in Appendix 46, which enables the key when the third message contains information. (Note 49) During the first authentication procedure, the first key is calculated. Send the first Authentication Response message, Based on the transmission of the aforementioned Authentication Response message, the timer is started. If the timer expires, a first message indicating that the first authentication procedure has not been completed is sent. Perform the second authentication procedure, The second key is activated when the second authentication procedure described above is completed. The second key is created in the second authentication procedure, by the method of the user device (UE). (Note 50) Key calculation policy The process is executed based on the aforementioned key, When the processing based on the aforementioned key is completed, the aforementioned key is activated. A method for a user device (UE) that deletes the key when processing based on the key is completed. (Note 51) Upon receiving the first Authentication Request message, Key calculation policy Send the first Authentication Response message, Upon receiving the second Authentication Request message, Send a second Authentication Response message, Upon receiving a message indicating the validity of the aforementioned key, A method for a user device (UE) to activate the key upon receiving the aforementioned message. (Note 52) During the first authentication procedure, the first Authentication Request message is received. Calculate the first key, Perform the second authentication procedure, The second key is activated when the second authentication procedure described above is completed. The second key is created in the second authentication procedure, by the method of the user device (UE). (Note 53) A means of calculating the key during the authentication procedure, A means of sending an Authentication Response message, Means for detecting wireless link failures, A means for sending a first message indicating that the authentication procedure has not been completed when a wireless link failure is detected, Means for performing the aforementioned authentication procedure, A user device (UE) comprising means for activating the key when the authentication procedure is completed. (Note 54) A means of calculating the key during the authentication procedure, A means of sending an Authentication Response message, Means for detecting wireless link failures, A means for sending a first message indicating that the authentication procedure has not been completed when the aforementioned wireless link failure is detected, Means for receiving a second message indicating whether the key is valid, The means for deleting the key when the second message indicates that the key is invalid, A user device (UE) comprising means for enabling the key when the second message indicates that the key is valid. (Note 55) The first message includes a key, If the first message includes the key, means for receiving a third message indicating whether the key is valid, The means for deleting the key when the third message indicates that the key is invalid, The UE according to Appendix 54, further comprising means for enabling the key when the third message indicates that the key is valid. (Note 56) The first message includes information related to the key, means for receiving the third message indicating the aforementioned information, Means for deleting the key if the third message does not indicate the information, The UE described in Appendix 54 further comprises means for enabling the key when the third message indicates information. (Note 57) A means for calculating a first key during the first authentication procedure, A means for sending a first Authentication Response message, Means for starting a timer based on the transmission of the aforementioned Authentication Response message, A means for sending a first message indicating that the first authentication procedure has not been completed when the timer expires, A means of performing the second authentication procedure, A means for activating the second key when the second authentication procedure described above is completed, The user device (UE) further comprises the means by which the second key is created in the second authentication procedure. (Note 58) A means for calculating the key, Means for executing processing based on the aforementioned key, Means for activating the key when processing based on the key is completed, A user device (UE) comprising means for deleting the key when processing based on the key is completed. (Note 59) A means for receiving a first Authentication Request message, A means for calculating the key, A means for sending a first Authentication Response message, A means for receiving a second Authentication Request message, A means for sending a second Authentication Response message, Means for receiving a message indicating the validity of the aforementioned key, A user device (UE) comprising means for activating the key when the aforementioned message is received. (Note 60) A means for receiving a first Authentication Request message during the first authentication procedure, A means for calculating the first key, A means of performing the second authentication procedure, A means for activating the second key when the second authentication procedure described above is completed, The user device (UE) comprises the means by which the second key is created in the second authentication procedure.
[0172] The embodiments disclosed above, in whole or in part, can be described as follows, but are not limited thereto.
[0173] 3GPP TS 33.501 v 16.4.0
[0174] 6.1.2 Starting Authentication and Selecting an Authentication Method The initiation of primary authentication is shown in Figure 6.1.2-1 (see Figure 13 of this application). SEAF may initiate authentication with the UE during the procedure for establishing a signal connection with the UE, in accordance with SEAF's policies. The UE shall use SUCI or 5G-GUTI in the Registration Request. If the UE supports receiving the Authentication Result message, the UE shall include the capability to indicate that it supports receiving the Authentication Result. Whenever SEAF intends to initiate authentication, it shall invoke the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message to AUSF. The Nausf_UEAuthentication_Authenticate Request message shall contain one of the following: - SUCI as defined in the current specification, or - SUPI as defined in TS 23.501 [2]. SEAF shall include SUPI in the Nausf_UEAuthentication_Authenticate Request message if SEAF has a valid 5 G-GUTI and is re-authenticating the UE. Otherwise, SUCI shall be included in the Nausf_UEAuthentication_Authenticate Request. The SUPI / SUCI structure is part of the Stage 3 protocol design. The Nausf_UEAuthentication_Authenticate Request also includes the following: - The service network name as defined in section 6.1.1.4 of this document. NOTE 2: Local policies for selecting authentication methods do not need to be per UE; they can be the same across all UEs.
[0175] Upon receiving a Nausf_UEAuthentication_Authenticate Request message, AUSF shall verify that the requesting SEAF within the serving network has the right to use the serving network name in the Nausf_UEAuthentication_Authenticate Request by comparing the serving network name with the expected serving network name. AUSF shall temporarily store the received serving network name. If the serving network is not authorized to use the serving network name, AUSF shall respond with "serving network not authorized" in the Nausf_UEAuthentication_Authenticate Response. The Nudm_UEAuthentication_Get Request sent from AUSF to UDM includes the following information: - SUCI or SUPI; - Serving network name; Upon receiving a Nudm_UEAuthentication_Get Request, the UDM shall call SIDF if it has received a SUCI. Before the UDM processes the request, SIDF shall hide the SUCI in order to obtain the SUPI. Based on SUPI, the UDM / ARPF shall select the authentication method. NOTE 3: The Nudm_UEAuthentication_Get Response, which is a response to a Nudm_UEAuthentication_Get Request, and the Nausf_UEAuthentication_Authenticate Response message, which is a response to a Nausf_UEAuthentication_Authenticate Request message, are described as part of the authentication procedure in Section 6.1.3.
[0176] 3 GPP TS 33.501 v 16.4.0
[0177] 6.1.3.2.0 5G AKA 5G AKA enhances EPS AKA
[10] by providing the home network with proof of successful authentication of the UE from the visited network. The proof is sent from the visited network in an Authentication Confirmation message. The option to use 5G AKA is described in section 6.1.2 of this document. NOTE 1: 5G AKA does not support multiple 5G AV requests, and SEAF does not pre-fetch 5G AV from home networks for future use. Figure 6.1.3.2-1: 5G AKA certification procedure (see Figure 14 of this application)
[0178] The 5G AKA authentication procedure operates as follows. See also Figure 6.1.3.2-1 (see Figure 14 in this application): 1. For each Nudm_Authenticate_Get Request, the UDM / ARPF shall create a 5G HE AV. The UDM / ARPF does this by generating an AV with the Authentication Management Field (AMF) separation bit set to "1", as defined in TS 33.102 [9]. The UDM / ARPF then K AUSF Derive (according to Annex A.2) and calculate XRES* (according to Annex A.4). Finally, UDM / ARPF is calculated using RAND, AUTN, XRES*, and K AUSF We will create 5G HE AV from this.
[0179] 2. Subsequently, the UDM shall indicate in the Nudm_UEAuthentication_Get Response that the 5G HE AV will be used for 5G AKA and return the 5G HE AV to the AUSF. If the SUCI was included in the Nudm_UEAuthentication_Get Request, the UDM shall include the SUPI in the Nudm_UEAuthentication_Get Response after the SIDF has decrypted the SUCI. If a subscriber has an AKMA subscription, UDM will include an AKMA indication in the Nudm_UEAuthentication_Get Response.
[0180] 3. AUSF shall temporarily store XRES* along with the received SUCI or SUPI.
[0181] 4. Subsequently, AUSF calculates HXRES* from XRES* (according to Annex A.5), K AUSF From K SEAF Calculate (according to Annex A.6), convert XRES* to HXRES*, K AUSF 5G HE AV K SEAF By replacing it with this, 5G AV will be generated from 5G HE AV received from UDM / ARPF.
[0182] 5. Subsequently, AUSF is K SEAF Remove the relevant information and return 5G SE AV(RAND, AUTN, HXRES*) to SEAF in the Nausf_UEAuthentication_Authenticate Response.
[0183] 6. SEAF shall send RAND and AUTN to the UE in the NAS message Authentication Request. This message shall contain K AMFThis message shall include the ngKSI used to identify the user, and the partial native security context created upon successful authentication. The message shall also include ABBA parameters. SEAF shall set the ABBA parameters as defined in Annex A.7.1. ME shall forward the RAND and AUTN received in the NAS message Authentication Request to USIM. NOTE 2: The ABBA parameter is included to enable bid-down protection for the security feature.
[0184] 7. When the USIM receives RAND and AUTN, it verifies the freshness of the received values by checking whether AUTN is acceptable as described in TS 33.102 [9]. If so, the USIM calculates the response RES. The USIM shall return RES, CK, and IK to the ME. If the USIM calculates Kc (i.e., GPRS Kc) from CK and IK using the conversion function c3 as described in TS 33.102 [9] and sends it to the ME, the ME shall ignore such GPRS Kc and not store GPRS Kc in the USIM or the ME. The ME shall then calculate RES* from RES according to Annex A.4. The ME calculates K from CK||IK according to Section A.2. AUSF The following calculation shall be performed. ME is calculated according to section A.6, K AUSF From K SEAF The calculation shall be performed. ME accessing 5G shall ensure that the "separation bit" of the AMF field of AUTN is set to 1 during authentication. The "separation bit" is bit 0 of the AMF field of AUTN. NOTE 3: This separation bit in the AMF field of AUTN cannot be used for operator-specific purposes, as described in TS 33.102 [9], Annex F.
[0185] 8. The UE shall return RES* to SEAF in the NAS message Authentication Response.
[0186] 9. SEAF then calculates HRES* from RES* according to Annex A.5, and compares HRES* with HXRES*. If they match, SEAF considers authentication successful from the perspective of the serving network. If they do not match, SEAF proceeds as described in Section 6.1.3.2.2. If RES* does not reach the UE and is not received by SEAF, SEAF considers authentication a failure and reports the failure to AUSF.
[0187] 10. SEAF sends the RES* received from the UE to AUSF in the Nausf_UEAuthentication_Authenticate Request message.
[0188] 11. If AUSF receives a Nausf_UEAuthentication_Authenticate Request message containing RES* as authentication confirmation, it may check whether the 5G AV has expired. If the 5G AV has expired, AUSF may consider authentication to have failed from the perspective of the home network. If authentication is successful, AUSF will K AUSF The XRES* will be saved. AUSF will compare the received RES* with the saved XRES*. If RES* and XRES* are equal, AUSF will consider authentication successful from the perspective of the home network. AUSF will notify UDM of the authentication result (see Section 6.1.4 of this document for linking with the authentication confirmation).
[0189] 12. AUSF shall indicate to SEAF whether authentication was successful from the perspective of the home network using the Nausf_UEAuthentication_Authenticate Response. If authentication is successful, K SEAF The following shall be sent to SEAF in the Nausf_UEAuthentication_Authenticate Response. If AUSF receives SUCI from SEAF in the authentication request (see Section 6.1.2 of this document) and authentication is successful, AUSF shall also include SUPI in the Nausf_UEAuthentication_Authenticate Response message.
[0190] If authentication is successful, the key K is received in the Nausf_UEAuthentication_Authenticate Response message. SEAF This shall be the anchor key in the sense of the key hierarchy specified in Section 6.2 of this document. Subsequently, SEAF is K SEAF From the ABBA parameters and SUPI, according to Annex A.7, K AMF It shall be derived that SEAF is ngKSI and K AMF This shall be provided to AMF.
[0191] If SUCI is used for this authentication, SEAF will, K SEAF After receiving the Nausf_UEAuthentication_Authenticate Response message containing SUPI, AMF receives ngKSI and K AMF Only the following will be provided; no communication services will be provided to the UE until the SUPI is recognized by the service network. The subsequent steps taken by AUSF after the authentication procedure are described in Section 6.1.4 of this document.
[0192] 3 GPP TS 33.501
[0193] 6.1.3.2.0 5G AKA 5G AKA enhances EPS AKA
[10] by providing the home network with proof of successful authentication of the UE from the visited network. The proof is sent from the visited network in an Authentication Confirmation message.
[0194] The option to use 5G AKA is described in section 6.1.2 of this document. NOTE 1: 5G AKA does not support multiple 5G AV requests, and SEAF does not prefetch 5G AV from the home network for future use.
[0195] Figure 6.1.3.2-1: 5G AKA certification procedure (see Figure 15 of this application) The 5G AKA authentication procedure operates as follows. See also Figure 6.1.3.2-1 (see Figure 15 in this application):
[0196] 1. For each Nudm_Authenticate_Get Request, the UDM / ARPF shall create a 5G HE AV. The UDM / ARPF does this by generating an AV with the Authentication Management Field (AMF) separation bit set to "1", as defined in TS 33.102 [9]. The UDM / ARPF then K AUSF Derive (according to Annex A.2) and calculate XRES* (according to Annex A.4). Finally, UDM / ARPF is calculated using RAND, AUTN, XRES*, and K AUSF We will create 5G HE AV from this.
[0197] 2. Subsequently, the UDM shall indicate in the Nudm_UEAuthentication_Get Response that the 5G HE AV will be used for 5G AKA and return the 5G HE AV to the AUSF. If a SUCI was included in the Nudm_UEAuthentication_Get Request, the UDM shall include the SUPI in the Nudm_UEAuthentication_Get Response after the SIDF has decrypted the SUCI. If the subscriber has an AKMA subscription, the UDM shall include an AKMA indication in the Nudm_UEAuthentication_Get Response.
[0198] 3. AUSF shall temporarily store XRES* along with the received SUCI or SUPI.
[0199] 4. Subsequently, AUSF calculates HXRES* from XRES* (according to Annex A.5), K AUSF From K SEAF Calculate (according to Annex A.6), convert XRES* to HXRES*, K AUSF 5G HE AV K SEAF By replacing it with this, 5G AV will be generated from 5G HE AV received from UDM / ARPF.
[0200] 5. Subsequently, AUSF is K SEAF Remove the relevant information and return 5G SE AV(RAND, AUTN, HXRES*) to SEAF in the Nausf_UEAuthentication_Authenticate Response.
[0201] 6. SEAF shall send RAND and AUTN to the UE in the NAS message Authentication Request. This message shall contain K AMFThis message shall include the ngKSI used to identify the user, and the partial native security context created upon successful authentication. The message shall also include ABBA parameters. SEAF shall set the ABBA parameters as defined in Annex A.7.1. ME shall forward the RAND and AUTN received in the NAS message Authentication Request to the USIM. NOTE 2: The ABBA parameter is included to enable bid-down protection for the security feature.
[0202] 7. When the USIM receives RAND and AUTN, it verifies the freshness of the received values by checking whether AUTN is acceptable as described in TS 33.102 [9]. If so, the USIM calculates the response RES. The USIM shall return RES, CK, and IK to the ME. If the USIM calculates Kc (i.e., GPRS Kc) from CK and IK using the conversion function c3 as described in TS 33.102 [9] and sends it to the ME, the ME shall ignore such GPRS Kc and not store GPRS Kc in the USIM or the ME. The ME shall then calculate RES* from RES according to Annex A.4. The ME calculates K from CK||IK according to Section A.2. AUSF The following calculation shall be performed. ME is calculated according to section A.6, K AUSF From K SEAF The calculation shall be performed. ME accessing 5G shall ensure that the "separation bit" of the AMF field of AUTN is set to 1 during authentication. The "separation bit" is bit 0 of the AMF field of AUTN. NOTE 3: This separation bit in the AMF field of AUTN cannot be used for operator-specific purposes, as described in TS 33.102 [9], Annex F.
[0203] 8. The UE shall return RES* to SEAF in the NAS message Authentication Response. The UE shall start timer T. While timer T is running, the K created in step 7 AUSF The latest K AUSF It is not considered to be K AUSF KAUSF shall not be used in security-related procedures involving K. If timer T expires and the UE does not receive a NAS message, for example, if it does not receive an Authentication Reject indicating that the authentication procedure failed, the UE shall not use K. AUSF The latest K AUSF Toshi, K AUSF In subsequent security steps involving K AUSF Use this. If the UE encounters a wireless link failure before the timer expires, the UE stops the timer and the UE K AUSF It shall not be used. Once the next NAS signaling connection is successfully established, the UE will be K AUSF Start using K AUSF This shall be considered the latest KAUSF. If the establishment of the next NAS signaling connection fails due to the failure of the last authentication procedure (for example, if the UE receives a NAS message from AMF indicating authentication failure (5GMM cause #3 Invalid UE), the UE shall K AUSF Considering it invalid, UE is K AUSF This will be deleted.
[0204] 9. SEAF then calculates HRES* from RES* according to Annex A.5, and compares HRES* with HXRES*. If they match, SEAF considers authentication successful from the perspective of the serving network. If they do not match, SEAF proceeds as described in Section 6.1.3.2.2. If RES* does not reach the UE and is not received by SEAF, SEAF considers authentication a failure and reports the failure to AUSF.
[0205] 10. SEAF sends the RES* received from the UE to AUSF in the Nausf_UEAuthentication_Authenticate Request message.
[0206] 11. If AUSF receives a Nausf_UEAuthentication_Authenticate Request message containing RES* as authentication confirmation, it may check whether the 5G AV has expired. If the 5G AV has expired, AUSF may consider authentication to have failed from the perspective of the home network. If authentication is successful, AUSF will K AUSF The XRES* will be saved. AUSF will compare the received RES* with the saved XRES*. If RES* and XRES* are equal, AUSF will consider the authentication to be successful from the perspective of the home network. AUSF will notify UDM of the authentication result (see Section 6.1.4 of this document for the link to authentication confirmation).
[0207] 12. AUSF shall indicate to SEAF whether authentication was successful from the perspective of the home network using the Nausf_UEAuthentication_Authenticate Response. If authentication is successful, K SEAF The following shall be sent to SEAF in the Nausf_UEAuthentication_Authenticate Response. If AUSF receives SUCI from SEAF in the authentication request (see Section 6.1.2 of this document) and authentication is successful, AUSF shall also include SUPI in the Nausf_UEAuthentication_Authenticate Response message.
[0208] If authentication is successful, the key K is received in the Nausf_UEAuthentication_Authenticate Response message. SEAFThis shall be the anchor key in the sense of the key hierarchy specified in Section 6.2 of this document. Subsequently, SEAF is K SEAF From the ABBA parameters and SUPI, according to Annex A.7, K AMF It shall be derived that SEAF is ngKSI and K AMF This shall be provided to AMF.
[0209] If SUCI is used for this authentication, SEAF will, K SEAF After receiving the Nausf_UEAuthentication_Authenticate Response message containing SUPI, AMF receives ngKSI and K AMF Only the following will be provided; no communication services will be provided to the UE until the SUPI is recognized by the service network. The subsequent steps taken by AUSF after the authentication procedure are described in Section 6.1.4 of this document.
[0210] 3GPP TS 24.501
[0211] 5.4.1.3.7 Abnormal Cases a) Lower layer failure. If a lower-layer failure is detected before receiving an AUTHENTICATION RESPONSE message, the network shall continue running timer T3560 if it is already running.
[0212] b) Timer T3560 expires. When Timer T3560 first expires, the network shall resend the AUTHENTICATION REQUEST message, reset Timer T3560, and start Timer T3560 again. This resend shall be repeated four times, meaning that when Timer T3560 has expired five times, the network shall terminate the 5G AKA-based primary authentication and key agreement procedure and release the N1 NAS signaling connection.
[0213] c) Authentication error (5GMM cause #20 “MAC failure”). The UE sends an AUTHENTICATION FAILURE message with 5GMM cause #20 “MAC failure” to the network in accordance with Section 5.4.1.3.6 and starts timer T3520 (see example in Figure 5.4.1.3.7.1). Furthermore, the UE stops any running retransmission timers (e.g., T3510, T3517, T3521). Upon first receiving the AUTHENTICATION FAILURE message with 5GMM cause #20 “MAC failure” from the UE, the network may initiate the identification procedure described in Section 5.4.3. This is to allow the network to obtain the SUCI from the UE. The network may then check that the original 5G-GUTI used in the 5G authentication challenge corresponds to the correct SUPI. Upon receiving the IDENTITY REQUEST message from the network, the UE shall proceed as described in Section 5.4.3.3. NOTE 1: When the UE receives an AUTHENTICATION FAILURE message with 5GMM cause #20 “MAC failure”, the network may terminate the 5G AKA based primary authentication and key agreement procedure (see Section 5.4.1.3.5).
[0214] If the mapping of 5G-GUTI to SUPI in the network is incorrect, the network must respond by sending a new AUTHENTICATION REQUEST message to the UE. Upon receiving a new AUTHENTICATION REQUEST message from the network, the UE will stop timer T3520 if it is running and process the 5G challenge information as normal. If the mapping of 5G-GUTI to SUPI in the network is correct, the network must terminate the 5G AKA-based primary authentication and key agreement procedure by sending an AUTHENTICATION REJECT message (see Section 5.4.1.3.5).
[0215] If the network is successfully verified (receiving an AUTHENTICATION REQUEST message containing a valid SQN and MAC), the UE shall send an AUTHENTICATION RESPONSE message to the network, and if the retransmission timer was running and stopped when the first failed AUTHENTICATION REQUEST message was received, it shall start the retransmission timer (e.g., T3510, T3517, or T3521).
[0216] If the UE receives a second AUTHENTICATION REQUEST message and the MAC value is not resolved, the UE shall restart from the beginning according to the procedure specified in section c, or, if the message contains a UMTS authentication challenge, the UE shall follow the procedure specified in section d. If the SQN is invalid, the UE shall handle it according to the procedure specified in section f.
[0217] Figure 5.4.1.3.7.1: Authentication failure during the 5G AKA-based primary authentication and key agreement procedure (see Figure 16 of this application)
[0218] d) Authentication failure (5GMM cause #26 "non-5G authentication unacceptable"). The UE sends an AUTHENTICATION FAILURE message with 5GMM cause #26 "non-5G authentication unacceptable" to the network and starts timer T3520 (see example in Figure 5.4.1.3.7.1). In addition, the UE stops any running retransmission timers (e.g., T3510, T3517, or T3521). When the network first receives an AUTHENTICATION FAILURE message from the UE with 5GMM cause#26 "non-5G authentication unacceptable", the network may initiate the identification procedure described in Section 5.4.3. This is to allow the network to obtain the SUCI from the UE. The network may then check that the original 5G-GUTI used in the 5G authentication challenge corresponds to the correct SUPI. Upon receiving an IDENTITY REQUEST message from the network, the UE shall proceed with processing as described in Section 5.4.3.3. NOTE 2: If the UE receives an AUTHENTICATION FAILURE message with 5GMM cause#26 “non-5G authentication unacceptable”, the network may terminate the 5G AKA based primary authentication and key agreement procedure (see Section 5.4.1.3.5).
[0219] If the mapping of 5G-GUTI to SUPI in the network is incorrect, the network must respond by sending a new AUTHENTICATION REQUEST message to the UE. Upon receiving a new AUTHENTICATION REQUEST message from the network, the UE shall stop timer T3520 if it is running and process the 5G challenge information as normal. If the mapping of 5G-GUTI to SUPI in the network is correct, the network must terminate the 5G AKA-based primary authentication and key agreement authentication procedure by sending an AUTHENTICATION REJECT message (see Section 5.4.1.3.5). If the network is successfully verified (an AUTHENTICATION REQUEST message containing a valid 5G authentication challenge is received), the UE shall send an AUTHENTICATION RESPONSE message to the network, and if the retransmission timer was running and stopped when the first failed AUTHENTICATION REQUEST message was received, it shall start the retransmission timer (e.g., T3510, T3517, or T3521).
[0220] e) Authentication failed (5GMM cause #71 "ngKSI already in use"). The UE shall send an AUTHENTICATION FAILURE message with 5GMM cause #71 "ngKSI already in use" to the network and start timer T3520 (see example in Figure 5.4.1.3.7.1). In addition, the UE shall stop any running retransmission timers (e.g., T3510, T3517, or T3521). Upon first receiving the AUTHENTICATION FAILURE message with 5GMM cause #71 "ngKSI already in use" from the UE, the network shall perform the necessary actions to select a new ngKSI and send the same 5G authentication challenge to the UE. NOTE 3: If the UE receives an AUTHENTICATION FAILURE message with 5GMM cause #71 "ngKSI already in use", the network may restart the 5G AKA based primary authentication and key agreement procedure (see Section 5.4.1.3.2). When the UE receives a new AUTHENTICATION REQUEST message from the network, it stops timer T 3520 if it is running and processes the 5G challenge information as usual. If the network is successfully verified (an AUTHENTICATION REQUEST message containing a valid ngKSI, SQN, and MAC is received), the UE shall send an AUTHENTICATION RESPONSE message to the network, and if the retransmission timer was running and stopped when the first failed AUTHENTICATION REQUEST message was received, it shall start the retransmission timer (e.g., T 3510, T 3517, or T 3521).
[0221] f) Authentication failed (5GMM cause #21 "synch failure"). The UE shall send an AUTHENTICATION FAILURE message with 5GMM cause #21 "synch failure" to the network and start timer T3520 (see example in Figure 5.4.1.3.7.1). In addition, the UE shall stop any running retransmission timers (e.g., T3510, T3517, or T3521). Upon first receiving the AUTHENTICATION FAILURE message with 5GMM cause #21 "synch failure" from the UE, the network shall resynchronize using the AUTS parameter returned from the authentication failure parameter IE in the AUTHENTICATION FAILURE message. The resynchronization procedure requires the AMF to remove all unused authentication vectors of its SUPI and obtain new vectors from the UDM / AUSF. Once resynchronization is complete, the network shall initiate the 5G AKA based primary authentication and key agreement procedure. Upon receiving an AUTHENTICATION REQUEST message, the UE shall stop timer T3520 if it is running.
[0222] NOTE 4: If the UE receives two consecutive AUTHENTICATION FAILURE messages with 5GMM cause #21 "synch failure", the network may terminate the 5G AKA-based primary authentication and key agreement procedure by sending an AUTHENTICATION REJECT message.
[0223] If the network is successfully verified during the execution of T 3520 (a new AUTHENTICATION REQUEST message containing a valid SQN and MAC is received), the UE shall send an AUTHENTICATION RESPONSE message to the network, and if a retransmission timer was running and stopped when the first failed AUTHENTICATION REQUEST message was received, it shall start one of the retransmission timers (e.g., T3510, T3517, or T3521). When the UE receives an AUTHENTICATION REJECT message, it shall perform the actions specified in Section 5.4.1.3.5.
[0224] g) A network that failed the authentication check. If the UE determines that the network has failed the authentication check, it shall request the RRC to release the RRC connection locally and treat the active cell as prohibited (see 3GPP TS 38.304
[28] ). If a retransmission timer (e.g., T3510, T3517, or T3521) was running and stopped when the UE received the initial AUTHENTICATION REQUEST message containing invalid authentication challenge data that caused the authentication failure, the UE shall start one of the retransmission timers.
[0225] h) Failure to send an AUTHENTICATION RESPONSE message or AUTHENTICATION FAILURE message instruction from a lower layer (if the 5G AKA-based primary authentication and key agreement procedure is triggered by the registration procedure for mobility and periodic registration renewal). The UE shall stop timer T3520 if it is running and restart the registration procedure for mobility and periodic registration updates.
[0226] i) Failure to send an AUTHENTICATION RESPONSE message or AUTHENTICATION FAILURE message instruction involving a TAI change from a lower layer (when the 5G AKA-based primary authentication and key agreement procedure is triggered by the service request procedure). The UE shall stop timer T3520 if it is operating. If the current TAI is not included in the TAI list, the 5G AKA-based primary authentication and key agreement procedure will be terminated, and the registration procedure for mobility and periodic registration renewal will be initiated. If the current TAI is still part of the TAI list, it is up to the UE implementation to re-execute the ongoing procedure that triggered the 5G AKA-based primary authentication and key agreement procedure.
[0227] j) Failure to send an AUTHENTICATION RESPONSE message or AUTHENTICATION FAILURE message instruction without a TAI change from a lower layer (if the authentication procedure was triggered by a service request procedure). The UE shall stop timer T3520 if it is running. How the UE implementation re-executes the ongoing procedure that triggered the 5G AKA-based primary authentication and key agreement procedure is left to its own discretion.
[0228] k) Low-level instructions for NAS PDUs that are not being delivered due to handover If an Authentication Request message is not delivered due to an AMF handover and the target TA is included in the TAI list, the AMF will resend the Authentication Request message once the AMF handover is successfully completed. If a lower layer reports a failure in the handover procedure and an N1 NAS signaling connection exists, the AMF will resend the Authentication Request message.
[0229] l) Change the cell to the new tracking area. If a cell change to a new tracking area not on the TAI list occurs before an AUTHENTICATION RESPONSE message is sent, the UE may discard the transmission of the AUTHENTICATION RESPONSE message to the network and proceed with the registration procedure for mobility and the initiation of periodic registration, as described in Section 5.5.1.3.2.
[0230] Regarding items c, d, e, and f, whether or not you are registered for UE's emergency services. If the timer is running and the UE enters 5GMM-IDLE mode, the UE shall stop timer T3520 as a result of, for example, detection of a lower layer failure, release of the N1 NAS signal connection, or a system-to-system change from 5GMM-CONNECTED mode to S1 mode.
[0231] The UE shall consider the network to have failed the authentication check or the authentication to be invalid if any of the following occurs, and shall take the steps described in section g above: - Timer T3520 has expired; - During three consecutive authentication challenges, 5GMM detects any combination of 5G authentication failures: #20 "MAC failure", #21 "synch failure", #26 "non-5G authentication unacceptable", or #71 "ngKSI already in use". If the 5G authentication challenges causing the second and third 5G authentication failures are received by the UE while timer T 3520 has started after the previous 5G authentication failure has occurred, the 5G authentication challenges are considered to have failed consecutively.
[0232] Regarding items c, d, e, and f Depending on the operator's priority for local requests or emergency services, if the UE has an established emergency PDU session or is attempting to establish one, the AMF is not required to follow the procedures specified for authentication failures as defined in this section. The AMF may respond to the AUTHENTICATION FAILURE message by initiating the "null integrity protection algorithm" 5G-IA0, the "null ciphering algorithm" 5G-EA0, aborting the 5G AKA-based primary authentication and key agreement procedure and continuing to use the current security context, if any. The AMF shall release all non-emergency PDU sessions, if any, by initiating the PDU session release procedure. If there are ongoing PDU session establishment procedures, the AMF shall release all non-emergency PDU sessions upon completion of the PDU session establishment procedure. The network shall behave as if the UE were registered for emergency services.
[0233] If a UE has an established emergency PDU session or is attempting to establish one, and sends an AUTHENTICATION FAILURE message to the AMF with a 5GMM cause appropriate to these cases (#20, #21, #26, or #71), and receives a SECURITY MODE COMMAND message before timer T3520 times out, the UE shall consider the network to have succeeded in its authentication check, and shall stop timer T3520 and execute security mode control procedures, respectively.
[0234] If the UE has an established emergency PDU session or is attempting to establish an emergency PDU session when timer T3520 expires, the UE shall not consider the network to have failed the authentication check and shall not behave as described in item g. Instead, the UE shall continue to use the current security context, if any, and shall release all non-emergency PDU sessions, if any, by initiating the PDU session release procedure requested by the UE. If there is an ongoing PDU session establishment procedure, the UE shall release all non-emergency PDU sessions upon completion of the PDU session establishment procedure. The UE shall initiate one of the retransmission timers (e.g., T3510, T3517, or T3521) if: - If these retransmission timers were running and stopped when the UE received the AUTHENTICATION REQUEST message and detected an authentication failure. - If the steps associated with these timers have not yet been completed. If the UE is to behave as if it were registered for emergency services. Abbreviation For the purposes of this document, Non-Patent Document 1 and the abbreviations listed below apply. If an abbreviation defined in this document is also used in Non-Patent Document 1, its definition takes precedence over that definition. 4G-GUTI 4G Globally Unique Temporary UE Identity 5GC 5G Core Network 5GLAN 5G Local Area Network 5GS 5G System 5G-AN 5G Access Network 5G-AN PDB 5G Access Network Packet Delay Budget 5G-EIR 5G-Equipment Identity Register 5G-GUTI 5G Globally Unique Temporary Identifier 5G-BRG 5G Broadband Residential Gateway 5G-CRG 5G Cable Residential Gateway 5G GM 5G Grand Master 5G-RG 5G Residential Gateway 5G-S-TMSI 5G S-Temporary Mobile Subscription Identifier 5G VN 5G Virtual Network 5QI 5G QoS Identifier AF Application Function AKMF Authentication and Key Agreement for Applications AMF Access and Mobility Management Function ARPF Authentication credential Repository and Processing Function AS Access Stratum ATSSS Access Traffic Steering, Switching, Splitting ATSSS-LL ATSSS Low-Layer AUSF Authentication Server Function AUTN Authentication token BMCA Best Master Clock Algorithm BSF Binding Support Function CAG Closed Access Group CAPIF Common API Framework for 3GPP northbound APIs CHF Charging Function CN PDB Core Network Packet Delay Budget CP Control Plane DAPS Dual Active Protocol Stacks DL Downlink DN Data Network DNAI DN Access Identifier DNN Data Network Name DRX Discontinuous Reception DS-TT Device-side TSN translator ePDG evolved Packet Data Gateway EBI EPS Bearer Identity EUI Extended Unique Identifier FAR Forwarding Action Rule FN-BRG Fixed Network Broadband RG FN-CRG Fixed Network Cable RG FN-RG Fixed Network RG FQDN Fully Qualified Domain Name GFBR Guaranteed Flow Bit Rate GMLC Gateway Mobile Location Centre GPSI Generic Public Subscription Identifier GUAMI Globally Unique AMF Identifier HR Home Routed (roaming) IAB Integrated access and backhaul IMEI / TAC IMEI Type Allocation Code IPUPS Inter PLMN UP Security I-SMF Intermediate SMF I-UPF Intermediate UPF LADN Local Area Data Network LBO Local Break Out (roaming) LMF Location Management Function LoA Level of Automation LPP LTE Positioning Protocol LRF Location Retrieval Function MCX Mission Critical Service MDBV Maximum Data Burst Volume MFBR Maximum Flow Bit Rate MICO Mobile Initiated Connection Only MPS Multimedia Priority Service MPTCP Multi-Path TCP Protocol N3IWF Non-3GPP InterWorking Function N5CW Non-5G-Capable over WLAN NAI Network Access Identifier NEF Network Exposure Function NF Network Function NGAP Next Generation Application Protocol NID Network identifier NPN Non-Public Network NR New Radio NRF Network Repository Function NSI ID Network Slice Instance Identifier NSSAA Network Slice-Specific Authentication and Authorization NSSAAF Network Slice-Specific Authentication and Authorization Function NSSAI Network Slice Selection Assistance Information NSSF Network Slice Selection Function NSSP Network Slice Selection Policy NW-TT Network-side TSN translator NWDAF Network Data Analytics Function PCF Policy Control Function PDB Packet Delay Budget PDR Packet Detection Rule PDU Protocol Data Unit PEI Permanent Equipment Identifier PER Packet Error Rate PFD Packet Flow Description PNI-NPN Public Network Integrated Non-Public Network PPD Paging Policy Differentiation PPF Paging Proceed Flag PPI Paging Policy Indicator PSA PDU Session Anchor PTP Precision Time Protocol QFI QoS Flow Identifier QoE Quality of Experience RACS Radio Capabilities Signalling optimisation IAN (Radio) Access Network RG Residential Gateway RIM Remote Interference Management RQA Reflective QoS Attribute RQI Reflective QoS Indication RSN Redundancy Sequence Number SA NR Standalone New Radio SBA Service Based Architecture SBI Service Based Interface SCP Service Communication Proxy SD Slice Differentiator SEAF Security Anchor Functionality SEPP Security Edge Protection Proxy SMF Session Management Function SMSF Short Message Service Function SN Sequence Number SNPN Stand-alone Non-Public Network S-NSSAI Single Network Slice Selection Assistance Information SSC Session and Service Continuity SSCMSP Session and Service Continuity Mode Selection Policy SST Slice / Service Type SUCI Subscription Concealed Identifier SUPI Subscription Permanent Identifier SV Software Version TNAN Trusted Non-3GPP Access Network TNAP Trusted Non-3GPP Access Point TNGF Trusted Non-3GPP Gateway Function TNL Transport Network Layer TNLA Transport Network Layer Association TSC Time Sensitive Communication TSCAI TSC Assistance Information TSN Time Sensitive Networking TSN GM TSN Grand Master TSP Traffic Steering Policy TT TSN Translator TWIF Trusted WLAN Interworking Function UCMF UE radio Capability Management Function UDM Unified Data Management UDR Unified Data Repository UDSF Unstructured Data Storage Function UL Uplink UL CL Uplink Classifier UPF User Plane Function URLLC Ultra Reliable Low Latency Communication URRP-AMF UE Reachability Request Parameter for AMF URSP UE Route Selection Policy VID VLAN Identifier VLAN Virtual Local Area Network W-5GAN Wireline 5G Access Network W-5GBAN Wireline BBF Access Network W-5GCAN Wireline 5G Cable Access Network W-AGF Wireline Access Gateway Function
[0235] definition For the purposes of this document, Non-Patent Document 1 and the terms and definitions set forth below apply. Terms defined in this document take precedence over the definitions in Non-Patent Document 1 if the same terms are found therein.
[0236] While the present invention is shown and described in particular with reference to embodiments, the present invention is not limited to these embodiments. It will be understood by those skilled in the art that various modifications can be made in form and detail without departing from the spirit and scope of the invention as defined in the claims. This application is based on Indian Patent Application No. 202011045155, filed on 16 October 2020, which claims priority, and its disclosure is incorporated in its entirety by reference. [Explanation of Symbols]
[0237] 1000 UE 1001 Antenna 1002 Transmitter / Receiver Circuit 1003 User Interface 1004 Controller 1005 memory 1100 (R)AN node 1101 Antenna 1102 Transmitter / Receiver Circuit 1103 Network Interface 1104 Controller 1105 memory 1200 AMF 1201 Transmitter / Receiver Circuit 1202 Controller 1203 memory 1204 Network Interface
Claims
1. The first K AUSF A method for a user device (UE) to store a, In the 5G Authentication and Key Agreement (AKA) based primary authentication and key agreement procedure, The Access and Mobility Management Function (AMF) receives an authentication request message. Based on the aforementioned authentication request message, response information is created, Based on the aforementioned authentication request message, the second K AUSF Calculate, Send an authentication response message containing the aforementioned response information, After the 5G AKA-based primary authentication and key agreement procedure is successful, a Non-Access-Stratum (NAS) message is received from the AMF. When the UE receives the NAS message, the valid first K established between the network and the UE AUSF Delete, When the UE receives the NAS message, the second K AUSF Valid K AUSF A method of user equipment (UE) that considers it as such.
2. The first K AUSF A UE that stores, In the 5G Authentication and Key Agreement (AKA) based primary authentication and key agreement procedure, A means for receiving authentication request messages from the Access and Mobility Management Function (AMF), Means for creating response information based on the aforementioned authentication request message, Based on the aforementioned authentication request message, the second K AUSF Means for calculating, means for sending an authentication response message containing the aforementioned response information, A means for receiving a Non-Access-Stratum (NAS) message from the AMF after the 5G AKA-based primary authentication and key agreement procedure is successful, When the receiving means receives the NAS message, the valid first K established between the network and the UE AUSF Means of deleting, means for considering the second K when the receiving means receives the NAS message AUSF as a valid K AUSF and a user equipment (UE) comprising the same