Authentication of wireless communication devices by an external authentication server
By initiating primary authentication with an external server and using an asserted identifier, the network authenticates wireless devices while preserving privacy, addressing the challenge of anonymous identifiers in wireless communication networks.
Patent Information
- Application Number
- JP2024517376
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-09-20
- Filing Date
- 2022-09-15
- Publication Date
- 2025-10-15
- Estimated Expiration
- 2042-09-15
AI Technical Summary
Challenges exist in leveraging external authentication and authorization in wireless communication networks while preserving identifier privacy, particularly when a wireless communication device triggers primary authentication using an anonymous identifier.
The wireless communication network initiates primary authentication with an external authentication server, receives signaling indicating successful authentication, and includes an identifier asserted by the external server to authenticate the device, even when an anonymous identifier is used, thereby preserving privacy.
Enables authentication of wireless communication devices using external servers while maintaining identifier privacy, allowing the network to learn a non-anonymous identity for authentication purposes.
Smart Images

Figure 0007755057000001 
Figure 0007755057000002 
Figure 0007755057000003
Abstract
Description
[Technical Field]
[0001] TECHNICAL FIELD This application relates generally to wireless communication networks, and more particularly to authenticating wireless communication devices with an external authentication server outside the wireless communication network. [Background technology]
[0002] A wireless communication network implements a procedure for authenticating and authorizing a wireless communication device as a prerequisite for providing the wireless communication server to the device. In some cases, such as when the wireless communication network is a standalone private network (SNPN), the wireless communication network may support authentication and authorization of the wireless communication device based on credentials from an external authorization server outside the wireless communication network, i.e., in a credential holder (CH). Such authentication and authorization may be referred to as primary authentication and authorization, i.e., such authentication and authorization is not secondary, as may occur in the case of network slice-specific authentication and authorization.
[0003] However, challenges exist in leveraging external authentication and authorization and preserving identifier privacy, for example, when a wireless communication device triggers a primary authentication that uses an anonymous identifier to preserve privacy. Summary of the Invention
[0004] Some embodiments herein facilitate authentication of a wireless communication device by an external authentication server external to the wireless communication network. According to some embodiments, the external authentication server sends to the wireless communication network an identifier asserted by the external authentication server as authentically identifying the wireless communication device, e.g., an identifier that is or is associated with an identifier authenticated by the external authentication server. The wireless communication network may then authenticate the wireless communication device with the wireless communication network based on the asserted identifier. In this way, even if the wireless communication device triggers authentication using an anonymous identifier, the wireless communication network can still learn a non-anonymous identifier for the wireless communication device after authentication. Some embodiments thereby advantageously facilitate external authentication while also preserving identifier privacy.
[0005] More particularly, embodiments herein include a method implemented by an authentication server in a wireless communication network. The method includes initiating a primary authentication of a wireless communication device with an external authentication server external to the wireless communication network. The method also includes receiving signaling indicating successful primary authentication of the wireless communication device with the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device. In some embodiments, the method further includes authenticating the wireless communication device with the wireless communication network based on the identifier included in the received signaling.
[0006] In some embodiments, initiating the primary authentication includes initiating a primary authentication of the wireless communication device with an external authentication server using an anonymous identifier that does not identify the wireless communication device. In one such embodiment, the identifier included in the received signaling is a non-anonymous identifier. For example, in some embodiments, the anonymous identifier is an anonymous subscription persistent identifier (SUPI), and the non-anonymous identifier is a non-anonymous SUPI.
[0007] Alternatively or additionally, initiating the primary authentication may include initiating a primary authentication of the wireless communication device with an external authentication server using a presented identifier that the wireless communication device presented to the wireless communication network as identifying the wireless communication device. In this case, authenticating the wireless communication device with respect to the wireless communication network based on the identifier included in the received signaling may include verifying that the presented identifier corresponds to the identifier included in the received signaling. In one embodiment, such verifying includes sending the presented identifier to a network device implementing unified data management (UDM) functionality and performing the verifying based on a response received from the network device implementing UDM functionality.
[0008] In some embodiments, the primary authentication is initiated as part of a procedure for registering the wireless communication device with the wireless communication network. In one such embodiment, the method further includes registering the wireless communication device with the wireless communication network based on successful authentication of the wireless communication device with the wireless communication network.
[0009] In some embodiments, the wireless communication network is a stand-alone private network.
[0010] Embodiments herein also include a method performed by an external authentication server external to a wireless communication network, the method including performing a primary authentication of a wireless communication device by the external authentication server for access by the wireless communication device to the wireless communication network, the method further including sending signaling to the authentication server in the wireless communication network indicating successful primary authentication of the wireless communication device by the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device.
[0011] In some embodiments, the method further includes receiving signaling that triggers the external authentication server to perform a primary authentication of the wireless communication device with the external authentication server. In one such embodiment, the signaling includes an anonymous identifier for the wireless communication device. In some embodiments, for example, the anonymous identifier is an anonymous subscription persistent identifier (SUPI).
[0012] In some embodiments, the identifier included in the transmitted signaling is a non-anonymous identifier. In one such embodiment, the non-anonymous identifier is a non-anonymous SUPI.
[0013] In some embodiments, the wireless communication network is a stand-alone private network.
[0014] Embodiments herein further include a method implemented by a network node in a wireless communication network, the method including receiving, from an authentication server in the wireless communication network, a request for primary authentication of a wireless communication device by an external authentication server for access by the wireless communication device to the wireless communication network, the method further including transmitting a response to the authentication server in the wireless communication network indicating successful primary authentication of the wireless communication device by the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device.
[0015] In some embodiments, the request includes an anonymous identifier for the wireless communication device, and the identifier included in the transmitted signaling is a non-anonymous identifier. In one embodiment, for example, the anonymous identifier is an anonymous subscription persistent identifier (SUPI), and the non-anonymous identifier is a non-anonymous SUPI.
[0016] In some embodiments, the wireless communication network is a stand-alone private network.
[0017] In some embodiments, the authentication server implements an authentication server function (AUSF) and / or the network node implements a network slice specific authentication and authorization function (NSSAAF).
[0018] Embodiments herein also include a method implemented by a network node in a wireless communication network, the method including receiving a request for authentication data for a wireless communication device from an authentication server in the wireless communication network, the method further including sending a response to the authentication server indicating that primary authentication of the wireless communication device should be performed by an external authentication server outside the wireless communication network and including an identifier to be presented to the external authentication server.
[0019] In some embodiments, the request includes an anonymous identifier for the wireless communication device, and the identifier included in the response is the anonymous identifier for the wireless communication device. In one embodiment, for example, the anonymous identifier is an anonymous subscription persistent identifier (SUPI).
[0020] In some embodiments, the method further includes determining, based on the realm portion of the anonymous identifier, that primary authentication of the wireless communication device should be performed by an external authentication server outside the wireless communication network.
[0021] In some embodiments, the wireless communication network is a stand-alone private network.
[0022] Embodiments herein also include corresponding apparatus, computer programs, and carriers for those computer programs.
[0023] For example, embodiments herein include an authentication server configured for use in a wireless communication network, the authentication server comprising: communications circuitry and processing circuitry configured to: initiate a primary authentication of a wireless communication device with an external authentication server external to the wireless communication network; receive signaling indicating successful primary authentication of the wireless communication device with the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device; and authenticate the wireless communication device with the wireless communication network based on the identifier included in the received signaling.
[0024] Embodiments herein also include an external authentication server external to the wireless communication network, the external authentication server comprising communications circuitry and processing circuitry configured to perform a primary authentication of the wireless communication device by the external authentication server for access by the wireless communication device to the wireless communication network, and to send signaling to an authentication server in the wireless communication network indicating successful primary authentication of the wireless communication device by the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device.
[0025]
[0009] Embodiments herein further include a network node configured for use in a wireless communication network, the network node comprising: a communications circuit; and a processing circuit. The processing circuit is configured to receive, from an authentication server in the wireless communication network, a request for primary authentication of the wireless communication device by an external authentication server for access by the wireless communication device to the wireless communication network. The processing circuit is also configured to transmit, to the authentication server in the wireless communication network, a response indicating successful primary authentication of the wireless communication device by the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device.
[0026] Embodiments herein further include a network node configured for use in a wireless communication network, the network node comprising: communications circuitry and processing circuitry configured to receive a request for authentication data for a wireless communication device from an authentication server in the wireless communication network, and to transmit a response to the authentication server indicating that primary authentication of the wireless communication device should be performed by an external authentication server outside the wireless communication network and including an identifier to be presented to the external authentication server. [Brief explanation of the drawings]
[0027] [Figure 1] 1 is a block diagram of a wireless communication network 10 according to some embodiments. [Figure 2] FIG. 1 is a block diagram of authentication via a credential holder in 5GS, according to some embodiments. [Figure 3] FIG. 1 is a call flow diagram for authentication with an external authentication server, according to some embodiments. [Figure 4] FIG. 10 is a call flow diagram of authentication with an external authentication server according to some embodiments in which a wireless communication device uses an anonymous identifier. [Figure 5] FIG. 10 is a call flow diagram of authentication with an external authentication server according to some embodiments in which a wireless communication device uses a non-anonymous identifier. [Figure 6] FIG. 1 is a logic flow diagram of a method implemented by an authentication server, according to some embodiments. [Figure 7] FIG. 1 is a logic flow diagram of a method implemented by an external authentication server, according to some embodiments. [Figure 8] 1 is a logic flow diagram of a method performed by a network node (eg, implementing NSSAAF) according to some embodiments. [Figure 9] 1 is a logic flow diagram of a method performed by a network node (eg, implementing UDM) according to some embodiments. [Figure 10] FIG. 2 is a block diagram of an authentication server, according to some embodiments. [Figure 11] FIG. 1 is a block diagram of an external authentication server, according to some embodiments. [Figure 12] 1 is a block diagram of a network node (eg, implementing NSSAAF) according to some embodiments. [Figure 13] 1 is a block diagram of a network node (eg, implementing UDM) according to some embodiments. [Figure 14] 1 is a block diagram of a communication system according to some embodiments. [Figure 15] FIG. 2 is a block diagram of a user equipment according to some embodiments. [Figure 16] FIG. 2 is a block diagram of a network node according to some embodiments. [Figure 17] FIG. 2 is a block diagram of a host, according to some embodiments. [Figure 18] FIG. 1 is a block diagram of a virtualized environment, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0028] 1 illustrates a wireless communication network 10, according to some embodiments. In some embodiments, the wireless communication network 10 is a Standalone Private Network (SNPN). Regardless, the wireless communication network 10 is configured to provide wireless communication services, for example, to wireless communication devices 12 that have subscriptions to the wireless communication network 10. As a prerequisite for providing such services to the wireless communication devices 12, the wireless communication network 10 is configured to authenticate and authorize the wireless communication devices 12, for example, as part of a procedure for registering the wireless communication devices 12 with the wireless communication network 10.
[0029] As shown in this regard, an authentication server 14 in the wireless communication network 10 is configured to initiate a primary authentication of the wireless communication device 12 with an external authentication server 20 external to the wireless communication network 10. The external authentication server 20 may, for example, be outside the control and / or management of the operator of the wireless communication network. In some embodiments, the authentication server 14 initiates such primary authentication via one or more other network nodes 16 in the wireless communication network 10. As shown, for example, the authentication server 14 sends an authentication request 22 to a network node 16 that implements, for example, a Network Slice Specific Authentication and Authorization Function (NSSAAF). In this case, the authentication request 22 may indicate or request that the primary authentication be performed by the external network, and the network node 16 may select the external authentication server 20 for such purpose.
[0030] According to some embodiments, the authentication server 14 receives, e.g., via the network node 16, signaling 24 in response to the authentication request 22. The signaling 24 indicates successful primary authentication of the wireless communication device 12 by the external authentication server 20. Notably, the signaling 24 also includes an identifier 26 asserted by the external authentication server 20 as authenticating and identifying the wireless communication device 12. For example, in some embodiments, the asserted identifier 26 is an identifier actually authenticated by the external authentication server 20 as identifying the wireless communication device 12. The identifier 26 may be, for example, an Extensible Authentication Protocol (EAP) ID. In other embodiments, the asserted identifier 26 may relate to an identifier actually authenticated by the external authentication server 20 as identifying the wireless communication device 12. The identifier 26 may be, for example, a public identifier (e.g., a General Public Subscription Identifier (GPSI)) mapped to an EAP ID. In either case, the asserted identifier 26 identifies the wireless communication device 12, for example, in a non-anonymous manner.
[0031] The authentication server 14 , in some embodiments, may thereby authenticate the wireless communication device 12 with respect to the wireless communication network 10 based on the identifier 26 included in the received signaling 24 .
[0032] In particular, by having the external authentication server 20 provide the asserted identifier 26 to the authentication server 14 in the wireless communication network 10, some embodiments enable authentication even when the wireless communication device 12 initiates primary authentication using an anonymous identifier, such as an anonymous subscription concealment identifier (SUCI) or an anonymous subscription persistent identifier (SUPI). Indeed, if the wireless communication device 12 initiates primary authentication using an anonymous identifier, the authentication server 14, according to embodiments herein, can learn the non-anonymous identity of the wireless communication device 12 from the external authentication server 20 (by the external authentication server 20 informing the authentication server 14 of the asserted identifier 26) and thereby authenticate the wireless communication device 12 with respect to the wireless communication network 10.
[0033] Consider now some example embodiments in which the wireless communication network 10 is exemplified as a Standalone Private Network (SNPN), the wireless communication device 12 is exemplified as a User Equipment (UE), the authentication server 14 is exemplified as implementing an Authentication Server Function (AUSF), and the external authentication server 20 is exemplified as implementing an Authentication, Authorization, and Accounting Server (AAA-S).
[0034] The SNPN supports UE access using credentials owned by a credential holder separate from the SNPN. The AUSF in the SNPN may support primary authentication and authorization of the UE using credentials from an AAA server in the credential holder (CH). Figure 2 shows a 5G system architecture for an SNPN with a credential holder that uses an AAA server for primary authentication and authorization.
[0035] If the Unified Data Management (UDM) determines that primary authentication is to be performed by the AAA server in the CH based on the UE subscription data and the UE's SUPI deciphered by the UDM from the SUCI received from the AUSF, the UDM instructs the AUSF that primary authentication by the AAA server in the CH is required. The AUSF shall discover and select an NSSAAF and then forward the EAP message to the NSSAAF. The NSSAAF shall select an AAA server based on the domain name corresponding to the realm part of the SUPI, relay the EAP message between the AUSF and the AAA server (or AAA proxy), and perform the relevant protocol conversion. The AAA server acts as an EAP server for the purpose of primary authentication.
[0036] The SUPI is used to identify the UE during primary authentication and authorization towards the AAA. The Access and Mobility Function (AMF) and Session Management Function (SMF) shall use the SUPI to retrieve the UE subscription data from the UDM.
[0037] If the UE provides a SUCI based on a SUPI that can be deciphered by a UDM in the SNPN, the resulting SUPI can be provided to the AAA-S via the AUSF, where the SUPI is used between the AUSF in the SNPN and the AAA-S in the CH to identify the UE during the primary authentication procedure.
[0038] However, the UE may instead provide an “anonymous SUCI” during UE registration, which triggers the primary authentication procedure, as described, for example, in 3GPP TS33.501 v17.2.1, which specifies the use of Extensible Authentication Protocol (EAP) Transport Layer Security (TLS) for primary authentication. Such may be the case, for example, in a 5G system (5GS), as described, for example, in informative Annex B of TS33.501 v17.2.1, or in the context of a non-5G-capable (N5GC) device behind a residential gateway (RG) in a private network, or in an isolated deployment scenario with wired access, as described, for example, in informative Annex O of TS33.501 v17.2.1. In any event, in such an embodiment, during UE registration, which triggers the primary authentication procedure, the UE utilizes a SUPI / SUCI that omits the username portion from the network access identifier (NAI) (hereinafter referred to as an “anonymous SUPI / SUCI”).
[0039] Nevertheless, a "null method" can be used at the Non-Access Stratum (NAS) layer to still preserve subscription identifier privacy by omitting the username portion from the NAI, as described in RFC 4282, section 2.3. This is similar to using anonymous identifiers in EAP, which means that only the realm portion from the NAI is included in the SUCI sent at the NAS layer. Thus, the formed SUCI can still be used to route authentication requests to the AUSF.
[0040] In cases where an anonymous identifier is used, the UDM is not able to resolve the SUPI for the anonymous SUCI provided by the UE, and it is the responsibility of the AUSF, acting as the EAP server, to request the SUPI from the UE during EAP-TLS. If the SUPI received from the UDM is anonymous, the AUSF derives the SUPI from the client identifier in the TLS client certificate.
[0041] Some embodiments make the AUSF / UDM in the SNPN aware of the UE's SUPI even in this case when an anonymous identifier is used, i.e., when the EAP server role is provided by the AAA-S in the CH instead of the AUSF.
[0042] Some embodiments also provide the possibility that the SUPI of the UE in the SNPN can be exchanged with an external AAA server from the CH. When the SNPN and the CH belong to the same entity, it is expected that it will be acceptable to use the SUPI as the user identifier for EAP authentication under the control of the AAA-S in the CH. However, the CH may be provided by a different entity than the SNPN, and furthermore, the CH may provide its services to multiple SNPNs. In that case, depending on the trust relationship between the CH / AAA-S and the SNPN, it may be necessary that the user identifier used by the AAA-S in the CH during the primary authentication procedure is not the SUPI used within the SNPN for the remainder of the procedure.
[0043] According to embodiments herein, if a UE applies an anonymized SUCI when registering with an SNPN, the AUSF / UDM in the SNPN cannot learn the UE's actual SUPI based on the initial message from the UE. The AAA in the CH learns the UE's identity (UE ID) only after authentication between the UE and the AAA is performed. In some embodiments, the UE ID is returned to the AUSF along with a successful authentication result. The UDM / AUSF then learns the SUPI from the UE ID.
[0044] According to another embodiment, if an anonymized SUPI is not used, the UE applies the actual SUPI when registering with the SNPN. The AUSF / UDM in the SNPN can then resolve the UE's actual SUPI from the UE. However, since UE authentication relies on the CH's AAA, the UE is only authenticated after authentication by the CH's AAA, which returns the authenticated UE ID to the SNPN, which the UDM / AUSF can then be sure is the authenticated UE's actual SUPI. Thus, again, the UE ID is returned from the CH's AAA to the SNPN's AUSF after successful authentication, in some embodiments.
[0045] In either case, the UE ID returned by the AAA to the AUSF / UDM may be the SUPI if the AAA / CH is trusted by the SNPN, or an association ID otherwise, which may be based on the public UE ID, i.e., GPSI.
[0046] FIG. 3 illustrates primary authentication by an external domain, according to some embodiments. 0. The UE shall be configured with credentials from the credential holder, for example, a SUPI containing a network specific identifier and credentials for any key generation EAP methods. Furthermore, it is assumed that a trust relationship exists between the SNPN and the credential holder AAA server: these entities must be mutually authenticated, and information transferred over the interface must be confidentiality, integrity, and replay protected. 1. The UE shall select an SNPN and initiate UE registration at the SNPN. For the construction of the SUCI, the method in clause 6.12 of TS33.501 v17.2.1 may be used. If the home network public key of the SNPN is not provisioned in the UE, the UE shall create the SUCI using the null method with an anonymized SUPI as described in Annex B of TS33.501 v17.2.1. 2. The AMF in the SNPN shall initiate primary authentication for the UE using the Nausf_UEAuthentication_Authenticate service operation with the AUSF. The AMF shall select the AUSF based on the Home Network Identifier (HNI) of the SUCI presented by the UE (i.e., the realm for the NSI SUPI type) as specified in TS 23.501 v17.1.1. In this case, the "anonymous SUCI" is used in step 1, and the realm of the "anonymous SUCI" shall facilitate the selection of the AUSF / UDM in the corresponding SNPN owner of the subscription for the SNPN UE. 3. The AUSF shall initiate the Nudm_UEAuthentication_Get service operation. The AUSF shall also select a UDM using the SUCI / SUPI provided by the AMF as specified in TS23.501 v17.1.1. NOTE 1: In the case of recertification, the SUPI will be used instead of the SUCI. 4. When the UDM receives a SUCI, the UDM shall resolve the SUCI to a SUPI and then examine the authentication methods applicable to the SUPI. The UDM determines to perform primary authentication with an external entity based on subscription data or by looking at the realm portion of the SUPI in NAI format. When an anonymous SUCI is used, the UDM can still determine that primary authentication should be performed by an external entity based on the realm portion of the SUPI, possibly in combination with subscription data. Alternatively, the AUSF may skip interaction with the UDM and determine to perform primary authentication based on local configuration of the realm portion of the SUPI. 5. The UDM shall provide the UE SUPI to the AUSF and shall indicate to the AUSF that it will perform primary authentication with an external credential holder. When a pseudonymous SUPI is used, the UDM returns the pseudonymous SUPI to the AUSF. Depending on the trust relationship with the AAA server, the UDM may provide the user SUPI (if the AAA server is trusted for the SNPN) and further an alternative identifier (e.g., GPSI) suitable for presentation to or communication with the AAA server. 6. Based on the instruction from the UDM, the AUSF shall select an NSSAAF as specified in 3GPP TS23.501 v17.1.1 and initiate an Nnssaaf_AIWF_Authenticate service operation towards the NSSAAF as specified in section 14.4.x of TS23.501 v17.1.1. In some embodiments, this step illustrates, for example, signaling 22 in FIG. 1 for initiating primary authentication. Depending on the trust relationship with the AAA server, the AUSF includes the SUPI or GPSI as the UE ID in the message. Note that the SUPI can be an anonymous SUPI if it is received from step 5. 7. The NSSAAF shall select an AAA server based on the domain name corresponding to the realm part of the UE ID (e.g., SUPI, anonymous SUPI, or alternate ID / GPSI) provided to the AUSF by the UDM in step 5. The NSSAAF shall perform the relevant protocol conversion and relay the message to the AAA server. Note that the NSSAAF may optionally send the received UE ID in the message (not shown in the flow). 8. The UE and the AAA server shall perform mutual authentication. The AAA server shall act as an EAP server for the purpose of primary authentication. When an anonymous SUCI / SUPI or an alternative UE ID / GPSI for SUPI is used, the AAA server shall request an identity from the UE using an EAP Identity Request and then perform the EAP authentication method. 9. After successful authentication, the MSK and authenticated UE identity (SUPI or Alternate UE ID / GPSI) shall be provided from the AAA server to the NSSAAF. The AAA server may derive the authenticated UE identity from the EAP identity from the authentication or use the EAP identity as the authenticated UE identity. Alternatively, if the NSSAF provided a UE identity in step 7, the AAA server may check for a match between the received UE identity and the authenticated identity and determine the authentication result (e.g., whether EAP success should be sent) based on the match result. 10. The NSSAAF returns the MSK and the UE ID received from step 6 and / or the authenticated UE ID (SUPI or Alternate UE ID / GPSI) received from step 9 to the AUSF using an Nnssaaf_AIWF_Authenticate service action response message. In some embodiments, this step illustrates signaling 24 received by authentication server 14 in FIG. 1, e.g., asserted identifier 26 in FIG. 1 is illustrated as the authenticated UE ID. 11. The AUSF checks the match of the SUPI received from step 5 with the authenticated UE ID / SUPI to determine the authentication result in the SNPN. If an anonymous SUPI or no SUPI is received from step 5, the AUSF shall check the UDM of the UE's subscription and authentication profile based on the received authenticated UE ID / SUPI. For example, if the authenticated UE ID is GPSI, the AUSF shall invoke the UDM service to convert GPSI to SUPI using the Nudm_SDM_Get(identifier conversion) service operation. 12. The AUSF divides the most significant 256 bits of the MSK into K AUSF AUSF shall also be used as K as specified in Annex A.6 of TS33.501 v17.2.1. AUSF From K SEAF Let us derive the following. 13. AUSF is obtained K SEAFand sends a success indication to the AMF together with the SUPI of the UE. 14. The AMF shall send EAP success in a NAS message. 15. The UE derives the MSK from K as described in step 12. AUSF Let us derive the following.
[0047] Figures 4 and 5 show different cases depending on the type of SUCI provided by the UE. The steps in Figures 4 and 5 are the same as those described above with respect to Figure 3, except as noted below.
[0048] GPSI is used when the AAA-S is not trusted. In other cases, SUPI may be shared between the AUSF and the AAA-S.
[0049] Figure 4 illustrates primary authentication by an external domain, particularly when an anonymous SUCI is used. Compared to Figure 3, in this case, the UE provides an anonymous SUCI (A-SUCI) in NAI format to the AMF in the registration request (step 1), which is then propagated to the AUSF and UDM. The UDM correspondingly returns an anonymous SUPI (A-SUPI) corresponding to the A-SUCI to the AUSF in step 5. Here, GPSI is not used because the AAA-S is trusted.
[0050] In the case of an A-SUPI received from the UDM, the AUSF sends the A-SUPI to the NSSAAF in its authentication request (step 6). The AAA-S authenticates the UE and returns a SUPI or GPSI as the authenticated UE ID (step 9), which is relayed to the AUSF (step 10). If a GPSI is returned, the AUSF, with the assistance of the UDM, converts the GPSI into the UE's SUPI. Operation then proceeds as described in Figure 3.
[0051] Figure 5 shows primary authentication by an external domain when a non-anonymous SUCI is used. In this example, the UDM returns to the AUSF (step 5) the GPSI corresponding to the non-anonymous SUCI provided by the UE in step 1. The UDM also returns a non-anonymous SUPI corresponding to the non-anonymous SUCI.
[0052] In one embodiment, the AUSF correspondingly provides the GPSI to the NSSAAF in its authentication request (step 6), for example, if the AAA-S is not trusted. In this case, the GPSI is relayed to the AAA-S. The AAA-S may then return the GPSI based on which the UE is authenticated (step 9). Because the AUSF already understands the relationship between the GPSI and the SUPI from step 5, the AUSF does not need to employ the assistance of the UDM to convert the returned GPSI to a SUPI. Thus, operation may proceed as described above in FIG. 3.
[0053] In another embodiment, by contrast, the AUSF provides the SUPI to the NSSAAF in its authentication request (step 6), for example, if the AAA-S is trusted. In this case, the SUPI is relayed to the AAA-S. The AAA-S may then return a SUPI based on which the UE is authenticated (step 9), at which point operation may proceed as described above in FIG. 3.
[0054] In view of the above modifications and variations, FIG. 6 illustrates a method implemented by an authentication server 14 in a wireless communication network 10 according to a particular embodiment. The method includes initiating a primary authentication of the wireless communication device 12 with an external authentication server 20 external to the wireless communication network 10 (block 600). The method also includes receiving signaling 24 indicating successful primary authentication of the wireless communication device 12 with the external authentication server 20 and including an identifier 26 asserted by the external authentication server 20 as authenticating and identifying the wireless communication device 12 (block 610). The identifier 26 may be, for example, an authenticated identifier based on which the external authentication server 20 authenticated the wireless communication device 12 via the primary authentication, or may be related to an authenticated identifier. Regardless, the method, in some embodiments, also includes authenticating the wireless communication device 12 with respect to the wireless communication network 10 based on the identifier 26 included in the received signaling 24 (block 620).
[0055] Additional aspects of the method in Figure 6 are listed in the Group A embodiments herein.
[0056] For example, in some embodiments, initiating includes initiating a primary authentication of the wireless communication device with an external authentication server using an anonymous identifier that does not identify the wireless communication device. In one example, the anonymous identifier is an anonymous subscription persistent identifier (SUPI).
[0057] In some embodiments, the identifier included in the received signaling is a non-anonymous identifier, for example, in one embodiment, the non-anonymous identifier is a non-anonymous SUPI.
[0058] In some embodiments, the identifier included in the received signaling is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network. For example, in one embodiment, the public identifier is a General Public Subscription Identifier (GPSI). Alternatively or additionally, in some embodiments, the method further includes translating, or requesting translation of, the public identifier into an identifier that identifies the wireless communication device to the wireless communication network.
[0059] In some embodiments, the identifier included in the received signaling is or is associated with an authenticated identifier based on which the external authentication server authenticated the wireless communication device via primary authentication. For example, in one embodiment, the authenticated identifier is an Extensible Authentication Protocol (EAP) identity.
[0060] In some embodiments, initiating includes initiating a primary authentication of the wireless communication device with an external authentication server using a presented identifier that the wireless communication device presented to the wireless communication network as identifying the wireless communication device. In one such embodiment, authenticating the wireless communication device with respect to the wireless communication network based on the identifier included in the received signaling includes verifying that the presented identifier corresponds to the identifier included in the received signaling.
[0061] In some embodiments, the primary authentication is initiated as part of a procedure for registering the wireless communication device with the wireless communication network. In one such embodiment, the method further includes registering the wireless communication device with the wireless communication network based on successful authentication of the wireless communication device with the wireless communication network. For example, if successful authentication of the wireless communication device with the wireless communication network is a prerequisite for registration of the wireless communication device with the wireless communication network, the procedure for registering the wireless communication device with the wireless communication network may in fact result in registration of the wireless communication device, provided any other requirements for registration (e.g., authorization) are met. On the other hand, if authentication of the wireless communication device with the wireless communication network fails, the procedure for registering the wireless communication device with the wireless communication network similarly fails.
[0062] In some embodiments, the wireless communication network is a stand-alone private network.
[0063] In some embodiments, the authentication server implements an authentication server function (AUSF).
[0064] 7 illustrates a method performed by an external authentication server 20 external to the wireless communication network 10 according to another particular embodiment. The method includes performing a primary authentication of the wireless communication device 12 by the external authentication server 20 (block 700) for access by the wireless communication device 12 to the wireless communication network 10. The method also includes sending signaling 24 to an authentication server 14 in the wireless communication network 10 (block 710) indicating successful primary authentication of the wireless communication device 12 by the external authentication server 20 and including an identifier 26 asserted by the external authentication server 20 as authenticating and identifying the wireless communication device 12.
[0065] Additional aspects of the method in FIG. 7 are listed in Group B embodiments herein.
[0066] In some embodiments, the method further includes receiving signaling that triggers the external authentication server to perform a primary authentication of the wireless communication device with the external authentication server, the signaling including an anonymous identifier for the wireless communication device. In one embodiment, the anonymous identifier is an anonymous subscription persistent identifier (SUPI).
[0067] In some embodiments, the identifier included in the transmitted signaling is a non-anonymous identifier, for example, the non-anonymous identifier is a non-anonymous SUPI.
[0068] In some embodiments, the identifier included in the transmitted signaling is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network, for example, the public identifier is a General Public Subscription Identifier (GPSI).
[0069] In some embodiments, the identifier included in the transmitted signaling is or is associated with an authenticated identifier based on which the external authentication server authenticated the wireless communication device via primary authentication, e.g., the authenticated identifier is an Extensible Authentication Protocol (EAP) identity.
[0070] In some embodiments, the wireless communication network is a stand-alone private network.
[0071] In some embodiments, the authentication server implements an authentication server function (AUSF).
[0072] 8 illustrates a method performed by a network node 16 (e.g., implementing NSSAAF) in a wireless communication network 10 according to another particular embodiment. The method includes receiving a request from an authentication server 14 in the wireless communication network 10 for a primary authentication of the wireless communication device 12 by an external authentication server 20 for access by the wireless communication device 12 to the wireless communication network 10 (block 800). The method also includes sending a response to an authentication server 13 in the wireless communication network 10 indicating successful primary authentication of the wireless communication device 12 by the external authentication server 20 and including the identifier 26 asserted by the external authentication server 20 as authenticating and identifying the wireless communication device 12 (block 810).
[0073] Additional aspects of the method in FIG. 8 are listed in the Group C embodiments herein.
[0074] For example, in some embodiments, the request includes an anonymous identifier for the wireless communication device, for example, the anonymous identifier is an anonymous subscription persistent identifier (SUPI).
[0075] In some embodiments, the identifier included in the transmitted signaling is a non-anonymous identifier, for example, the non-anonymous identifier is a non-anonymous SUPI.
[0076] In some embodiments, the identifier included in the transmitted signaling is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network. For example, the public identifier is a General Public Subscription Identifier (GPSI).
[0077] In some embodiments, the identifier included in the transmitted signaling is or is associated with an authenticated identifier based on which the external authentication server authenticated the wireless communication device via primary authentication, e.g., the authenticated identifier is an Extensible Authentication Protocol (EAP) identity.
[0078] In some embodiments, the wireless communication network is a stand-alone private network.
[0079] In some embodiments, the authentication server implements an authentication server function (AUSF).
[0080] In some embodiments, the network node implements a Network Slice Specific Authentication and Authorization Function (NSSAAF).
[0081] 9 illustrates a method performed by a network node (e.g., implementing UDM) in a wireless communication network according to another specific embodiment. The method includes receiving a request for authentication data for a wireless communication device from an authentication server in the wireless communication network (block 900). The method also includes sending a response to the authentication server indicating that primary authentication of the wireless communication device should be performed by an external authentication server outside the wireless communication network and including an identifier to be presented to the external authentication server (block 910).
[0082] Additional aspects of the method in FIG. 9 are listed in Group D embodiments herein.
[0083] For example, in some embodiments, the identifier included in the response is an anonymous identifier for the wireless communication device, hi some embodiments, the anonymous identifier is an anonymous subscription persistent identifier (SUPI).
[0084] In some embodiments, the identifier included in the response is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network. In one example, the public identifier is a General Public Subscription Identifier (GPSI).
[0085] In some embodiments, the request includes an anonymous identifier for the wireless communication device. In one such embodiment, the method further includes determining, based on the realm portion of the anonymous identifier, that primary authentication of the wireless communication device should be performed by an external authentication server outside the wireless communication network.
[0086] In some embodiments, the wireless communication network is a stand-alone private network.
[0087] In some embodiments, the authentication server implements an authentication server function (AUSF).
[0088] Embodiments herein also include a method implemented by a network node in a wireless communication network, the method including receiving a request to convert a public identifier that identifies a wireless communication device to an external network outside the wireless communication network into a private identifier that identifies the wireless communication device to the wireless communication network, the method also including converting the public identifier to the private identifier and transmitting a response including the private identifier.
[0089] In some embodiments, the public identifier is a General Public Subscription Identifier (GPSI).
[0090] In some embodiments, the private identifier is a subscription persistent identifier (SUPI).
[0091] In some embodiments, the wireless communication network is a stand-alone private network.
[0092] In some embodiments, the request is received from an authentication server, hi some embodiments, the authentication server implements an authentication server function (AUSF).
[0093] Embodiments herein also include corresponding apparatus, for example, an authentication server 14 configured to perform any of the steps of any of the embodiments described above for authentication server 14.
[0094] The embodiment also includes an authentication server 14 comprising a processing circuit and a power supply circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the authentication server 14. The power supply circuit is configured to provide power to the authentication server 14.
[0095] Embodiments further include an authentication server 14 comprising processing circuitry configured to perform any of the steps of any of the embodiments described above for authentication server 14. In some embodiments, authentication server 14 further comprises communications circuitry.
[0096] The embodiment further includes an authentication server 14 comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit to configure the authentication server 14 to perform any of the steps of any of the embodiments described above for the authentication server 14.
[0097] The embodiment also includes an external authentication server 20 comprising a processing circuit and a power supply circuit. The processing circuit is configured to perform any of the steps of any of the embodiments described above for the external authentication server 20. The power supply circuit is configured to supply power to the external authentication server 20.
[0098] Embodiments further include an external authentication server 20 comprising processing circuitry configured to perform any of the steps of any of the embodiments described above for the external authentication server 20. In some embodiments, the external authentication server 20 further comprises communications circuitry.
[0099] The embodiment further includes an external authentication server 20 comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit to configure the external authentication server 20 to perform any of the steps of any of the embodiments described above for the external authentication server 20.
[0100] Embodiments herein also include a network node 16 configured to perform any of the steps of any of the embodiments described above for the network node 16 .
[0101] The embodiment also includes a network node 16 comprising a processing circuit and a power supply circuit, the processing circuit configured to perform any of the steps of any of the embodiments described above for the network node 16. The power supply circuit is configured to supply power to the network node 16.
[0102] Embodiments further include a network node 16 comprising processing circuitry configured to perform any of the steps of any of the embodiments described above for the network node 16. In some embodiments, the network node 16 further comprises communications circuitry.
[0103] The embodiment further includes a network node 16 comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit to configure the network node 16 to perform any of the steps of any of the embodiments described above for the network node 16.
[0104] More specifically, the apparatus described above may perform the methods and any other processes herein by implementing any functional means, modules, units, or circuits. In one embodiment, for example, an apparatus comprises a respective circuit or circuitry configured to perform the steps illustrated in the method diagrams. The circuit or circuitry, in this regard, may comprise one or more microprocessors along with circuitry and / or memory dedicated to performing certain functional processes. For example, the circuitry may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), dedicated digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory, such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, and the like. The program code stored in memory may, in some embodiments, include program instructions for executing one or more communication and / or data communication protocols, as well as instructions for performing one or more of the techniques described herein. In embodiments that employ memory, the memory stores program code that, when executed by one or more processors, performs the techniques described herein.
[0105] FIG. 10 illustrates, for example, an authentication server 14 implemented in accordance with one or more embodiments. As shown, the authentication server 14 includes a processing circuit 1010 and a communication circuit 1020. The communication circuit 1020 is configured to transmit information to and / or receive information from one or more other nodes, for example, via any communication technology. The processing circuit 1010 is configured to perform the processes described above, for example, in FIG. 6, such as by executing instructions stored in a memory 1030. The processing circuit 1010 may implement several functional means, units, or modules in this regard.
[0106] FIG. 11 illustrates an external authentication server 20 implemented in accordance with one or more embodiments. As shown, the external authentication server 20 includes a processing circuit 1110 and a communication circuit 1120. The communication circuit 1120 is configured to transmit information to and / or receive information from one or more other nodes, e.g., via any communication technology. The processing circuit 1110 is configured to perform the processing described above, e.g., in FIG. 7, such as by executing instructions stored in a memory 1130. The processing circuit 1110 may implement several functional means, units, or modules in this regard.
[0107] FIG. 12 illustrates a network node 16 implemented in accordance with one or more embodiments. The network node 16 may, for example, implement the NSSAAF. As shown, the network node 16 includes a processing circuit 1210 and a communication circuit 1220. The communication circuit 1220 is configured to transmit information to and / or receive information from one or more other nodes, for example, via any communication technology. The processing circuit 1210 is configured to perform the processing described above, for example, in FIG. 8, such as by executing instructions stored in a memory 1230. The processing circuit 1210 may implement several functional means, units, or modules in this regard.
[0108] 13 illustrates a network node 1300 implemented in accordance with one or more embodiments. The network node 1300 may, for example, implement a UDM. As shown, the network node 1300 includes a processing circuit 1310 and a communication circuit 1320. The communication circuit 1320 is configured to transmit information to and / or receive information from one or more other nodes, for example, via any communication technology. The processing circuit 1310 is configured to perform the processing described above, for example, in FIG. 9, such as by executing instructions stored in a memory 1330. The processing circuit 1310 may implement several functional means, units, or modules in this regard.
[0109] Those skilled in the art will also appreciate that the embodiments herein further include corresponding computer programs.
[0110] The computer program comprises instructions which, when executed on at least one processor of the apparatus, cause the apparatus to perform any of the respective operations described above. The computer program may in this regard comprise one or more code modules which correspond to the means or units described above.
[0111] Embodiments further include a carrier containing such a computer program, which may comprise one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.
[0112] In this regard, embodiments herein also include a computer program product comprising instructions stored on a non-transitory computer-readable (storage or recording) medium that, when executed by a processor of the device, cause the device to perform as described above.
[0113] Embodiments further include a computer program product, which may be stored on a computer-readable recording medium, comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by a computing device.
[0114] FIG. 14 illustrates an example of a communication system 1400, according to some embodiments.
[0115] In this example, the communications system 1400 includes a communications network 1402 including an access network 1404, such as a radio access network (RAN), and a core network 1406 including one or more core network nodes 1408. The access network 1404 includes one or more access network nodes (one or more of which may be generally referred to as network nodes 1410), such as network nodes 1410a and 1410b, or any other similar Third Generation Partnership Project (3GPP) access nodes or non-3GPP access points. The network nodes 1410 facilitate direct or indirect connectivity of user equipment (UE), such as by connecting UEs 1412a, 1412b, 1412c, and 1412d (one or more of which may be generally referred to as UEs 1412), to the core network 1406 over one or more wireless connections.
[0116] Exemplary wireless communication over a wireless connection includes sending and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, communication system 1400 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals, whether via a wired or wireless connection. Communication system 1400 may include and / or interface with any type of communication, telecommunication, data, cellular, wireless network, and / or other similar type system.
[0117] The UE 1412 may be any of a wide variety of communication devices, including a wireless device configured, configured, and / or operable to communicate wirelessly with the network node 1410 and other communication devices. Similarly, the network node 1410 is configured, capable of, configured, and / or operable to communicate, directly or indirectly, with the UE 1412 and / or with other network nodes or equipment in the communications network 1402 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration, in the communications network 1402.
[0118] In the illustrated example, the core network 1406 connects the network node 1410 to one or more hosts, such as the host 1416. These connections may be direct or indirect via one or more intermediate networks or devices. In other examples, the network node may be directly coupled to the host. The core network 1406 includes one or more core network nodes (e.g., the core network node 1408) structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, and therefore, those descriptions are generally applicable to the corresponding components of the core network node 1408. Exemplary core network nodes include one or more of a Mobile Switching Center (MSC), a Mobility Management Entity (MME), a Home Subscriber Server (HSS), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Subscription Identifier De-concealing Function (SIDF), a Unified Data Management (UDM), a Security Edge Protection Proxy (SEPP), a Network Publishing Function (NEF), and / or a User Plane Function (UPF).
[0119] The host 1416 may be owned or under the control of, and operated by or on behalf of, a service provider other than the operator or provider of the access network 1404 and / or the communication network 1402. The host 1416 may host various applications to provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data about various ambient conditions detected by multiple UEs, analytics functions, social media, functions for controlling or possibly interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.
[0120] 14 enables connectivity between UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as a particular standard, including, but not limited to, Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G), a wireless local area network (WLAN) standard such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard (WiFi), and / or any low power wide area network (LPWAN) standard such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, near field communications (NFC) ZigBee, LiFi, and / or LoRa and Sigfox.
[0121] In some examples, the communication network 1402 is a cellular network that implements 3GPP standardized features. Thus, the communication network 1402 may support network slicing to provide different logical networks to different devices connected to the communication network 1402. For example, the communication network 1402 may provide Ultra-Reliable Low Latency Communication (URLLC) services to some UEs, while providing enhanced Mobile Broadband (eMBB) services to other UEs and / or providing Massive Machine-Based Communication (mMTC) / Massive IoT services to still further UEs.
[0122] In some examples, the UE 1412 is configured to transmit and / or receive information without direct human interaction. For example, the UE may be designed to transmit information to the access network 1404 on a predetermined schedule, when triggered by an internal or external event, or in response to a request from the access network 1404. Furthermore, the UE may be configured to operate in a single or multi-RAT or multi-standard mode. For example, the UE may operate on any one or a combination of Wi-Fi, NR (New Radio), and LTE, i.e., configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Enhanced UMTS Terrestrial Radio Access Network) New Radio-Dual Connectivity (EN-DC).
[0123] In this example, the hub 1414 communicates with the access network 1404 to facilitate indirect communication between one or more UEs (e.g., UEs 1412c and / or 1412d) and a network node (e.g., network node 1410b). In some examples, the hub 1414 may be a controller, a router, a content source, a content analyzer, or any of the other communication devices described herein with respect to UEs. For example, the hub 1414 may be a broadband router that enables access to the core network 1406 for the UE. As another example, the hub 1414 may be a controller that sends commands or instructions to one or more actuators in the UE. The commands or instructions may be received from the UE, the network node 1410, or may be due to executable code, scripts, processes, or other instructions in the hub 1414. As another example, the hub 1414 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 1414 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker, or other media distribution device, the hub 1414 may retrieve, via a network node, VR assets, video, audio, or other media or data related to sensory information, which the hub 1414 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In yet another example, the hub 1414 acts as a proxy server or orchestrator for the UEs, particularly in the case where one or more of the UEs are low-energy IoT devices.
[0124] The hub 1414 may have a constant / permanent or intermittent connection to the network node 1410b. The hub 1414 may also enable different communication schemes and / or schedules between the hub 1414 and the UEs (e.g., UEs 1412c and / or 1412d) and between the hub 1414 and the core network 1406. In other examples, the hub 1414 is connected to the core network 1406 and / or one or more UEs via a wired connection. Moreover, the hub 1414 may be configured to connect to an M2M service provider over the access network 1404 and / or to another UE over a direct connection. In some scenarios, a UE may establish a wireless connection with the network node 1410 while still connected via a wired or wireless connection through the hub 1414. In some embodiments, the hub 1414 may be a dedicated hub, i.e., a hub whose primary function is to route communications from / to the UE to / from the network node 1410b. In other embodiments, the hub 1414 may be a non-dedicated hub, i.e., a device that is capable of operating to route communications between the UE and the network node 1410b, but that is further capable of operating as a communication initiation and / or termination point for some data channels.
[0125] Figure 15 illustrates a UE 1500, according to some embodiments. As used herein, a UE refers to a device capable of, set up, configured, and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smartphone, a mobile phone, a cell phone, a voice-over-IP (VoIP) phone, a wireless local loop phone, a desktop computer, a personal digital assistant (PDA), a wireless camera, a gaming console or device, a music storage device, a playback appliance, a wearable terminal device, a wireless endpoint, a mobile station, a tablet, a laptop computer, a laptop embedded equipment (LEE), a laptop mounted equipment (LME), a smart device, a wireless customer premises equipment (CPE), a vehicle-mounted or vehicle-embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrowband Internet of Things (NB-IoT) UE, a machine-type communications (MTC) UE, and / or an enhanced MTC (eMTC) UE.
[0126] A UE may support device-to-device (D2D) communications, for example, by implementing 3GPP standards for sidelink communications, dedicated short-range communications (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE does not necessarily have a user in the sense of a human user who owns and / or operates an associated device. Instead, a UE may represent a device (e.g., a smart sprinkler controller) that is intended for sale to or operation by a human user, but may not be associated with or initially associated with a particular human user. Alternatively, a UE may represent a device (e.g., a smart power meter) that is not intended for sale to or operation by an end user, but may be associated with or operated for the user's benefit.
[0127] The UE 1500 includes a processing circuit 1502 operably coupled to an input / output interface 1506, a power source 1508, a memory 1510, a communication interface 1512, and / or any other components, or any combination thereof, via a bus 1504. Some UEs may utilize all or a subset of the components shown in FIG. 15. The level of integration between components may vary from UE to UE. Additionally, some UEs may include multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0128] The processing circuit 1502 is configured to process instructions and data and may be configured to implement any sequential state machine operable to execute instructions stored in memory 1510 as a machine-readable computer program. The processing circuit 1502 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, a field programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.), programmable logic together with appropriate firmware, one or more stored computer programs such as a microprocessor or digital signal processor (DSP) together with appropriate software, a general-purpose processor, or any combination of the above. For example, the processing circuit 1502 may include multiple central processing units (CPUs).
[0129] In this example, the input / output interface 1506 may be configured to provide one or more interfaces to an input device, an output device, or one or more input and / or output devices. Examples of output devices include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smart card, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 1500. Examples of input devices include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a webcam, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smart card, etc. A presence-sensitive display may include a capacitive or resistive touch sensor for detecting input from a user. The sensor may be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, a light sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as the input device. For example, a universal serial bus (USB) port may be used to accommodate input and output devices.
[0130] In some embodiments, the power source 1508 is structured as a battery or battery pack. Other types of power sources may be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or a battery. The power source 1508 may further include power circuitry for delivering power to various portions of the UE 1500 from the power source 1508 itself and / or from an external power source via an input circuit or an interface such as a power cable. Delivering power may be for charging the power source 1508, for example. The power circuitry may perform any formatting, conversion, or other modification on the power from the power source 1508 to make it suitable for the respective component of the UE 1500 being powered.
[0131] The memory 1510 may be or be configured to include memory, such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, hard disk, removable cartridge, flash drive, etc. In one example, the memory 1510 includes one or more application programs 1514, such as an operating system, a web browser application, a widget, a gadget engine, or other applications, and corresponding data 1516. The memory 1510 may store any of a variety of different operating systems or combinations of operating systems for use by the UE 1500.
[0132] The memory 1510 may be configured to include several physical drive units, such as a redundant array of independent disks (RAID), flash memory, a USB flash drive, an external hard disk drive, a thumb drive, a pen drive, a key drive, a high-density digital versatile disc (HD-DVD) optical disc drive, an internal hard disk drive, a Blu-ray optical disc drive, a holographic digital data storage (HDDS) optical disc drive, an external mini dual in-line memory module (DIMM), a synchronous dynamic random access memory (SDRAM), an external micro-DIMM SDRAM, a smart card memory such as a tamper-resistant module in the form of a universal integrated circuit card (UICC) containing one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may be, for example, an embedded UICC (eUICC), an integrated UICC (iUICC), or a removable UICC, commonly known as a "SIM card." The memory 1510 may enable the UE 1500 to access, offload, or upload data, instructions, application programs, etc. stored on a temporary or non-transitory memory medium. An article of manufacture, such as an article of manufacture utilizing a communication system, may be tangibly embodied as or in the memory 1510, which may be or comprise a device-readable storage medium.
[0133] The processing circuit 1502 may be configured to communicate with an access network or other networks using a communication interface 1512. The communication interface 1512 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 1522. The communication interface 1512 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or network node in the access network). Each transceiver may include a transmitter 1518 and / or a receiver 1520 suitable for providing network communication (e.g., optical, electrical, frequency allocation, etc.). Moreover, the transmitter 1518 and receiver 1520 may be coupled to one or more antennas (e.g., antenna 1522) and may share circuit components, software, or firmware, or may alternatively be implemented separately.
[0134] In the illustrated embodiment, the communication capabilities of communication interface 1512 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication such as using a Global Positioning System (GPS) to determine location, another similar communication capability, or any combination thereof. Communications may be implemented in accordance with one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, Transmission Control Protocol / Internet Protocol (TCP / IP), Synchronous Optical Networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), etc.
[0135] Regardless of the type of sensor, the UE may provide an output of data captured by the UE's sensors to a network node via a wireless connection through the UE's communications interface 1512. Data captured by the UE's sensors may be communicated to a network node via another UE over a wireless connection. The output may be periodic (e.g., once every 15 minutes when reporting detected temperature), in response to a triggering event (e.g., an alert is sent when humidity is detected), in response to a request (e.g., a user-initiated request), random (e.g., to even out the load from reporting from several sensors), or a continuous stream (e.g., a live video feed of a patient).
[0136] As another example, the UE may include an actuator, motor, or switch associated with a communications interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input, the state of the actuator, motor, or switch may change. For example, the UE may include a motor that adjusts a control surface or rotor of a drone in flight according to the received input, or a robotic arm that performs a medical procedure according to the received input.
[0137] When in the form of an Internet of Things (IoT) device, the UE may be a device for use in one or more application areas, including, but not limited to, urban wearable technology, augmented industrial applications, and healthcare. Non-limiting examples of such IoT devices are devices that are or are embedded in a connected refrigerator or freezer, a TV, a connected lighting device, an energy meter, a robotic vacuum cleaner, a voice-controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a water inundation / humidity sensor, an electronic door lock, a connected doorbell, an air conditioning system such as a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for augmented reality (AR) or virtual reality (VR), a wearable for haptic augmentation or sensory augmentation, a water sprinkler, an animal or product tracking device, a sensor for monitoring plants or animals, an industrial robot, an unmanned aerial vehicle (UAV), and any type of medical device such as a heart rate monitor or a remote-controlled surgical robot. A UE in the form of an IoT device comprises, in addition to the other components described with respect to UE 1500 shown in FIG. 15, circuitry and / or software depending on the intended application of the IoT device.
[0138] As yet another particular example, in an IoT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements and transmits results of such monitoring and / or measurements to another UE and / or network node. The UE, in this case, may be an M2M device, which may be referred to as an MTC device in a 3GPP context. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, bus, truck, ship, and airplane, or other equipment capable of monitoring and / or reporting on its operating status or other functions related to its operation.
[0139] In practice, any number of UEs may be used together for a single use case. For example, a first UE may be a drone or be integrated in a drone and provide the drone's speed information (obtained through a speed sensor) to a second UE that is a remote controller that operates the drone. When a user makes changes from the remote controller, the first UE may adjust a throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone's speed. The first and / or second UE may also include two or more of the functions described above. For example, a UE may include a sensor and an actuator and handle communication of data for both the speed sensor and the actuator.
[0140] 16 illustrates a network node 1600 according to some embodiments. As used herein, a network node refers to a device capable of, set up, configured, and / or operable to communicate, directly or indirectly, with UEs and / or other network nodes or devices in a communication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., wireless access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), and NR Node Bs (gNBs)).
[0141] Base stations may be categorized based on the amount of coverage they provide (or, stated another way, their transmit power level) and may therefore be referred to as femto, pico, micro, or macro base stations depending on the amount of coverage provided. A base station may be a relay node or a relay donor node that controls a relay. A network node may also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU), sometimes referred to as a remote radio head (RRH). Such remote radio units may or may not be integrated with an antenna, as in an antenna-integrated radio. Portions of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).
[0142] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, MSR equipment such as a multi-standard radio (MSR) BS, a network controller such as a radio network controller (RNC) or base station controller (BSC), a base transceiver station (BTS), a transmission point, a transmitting node, a multi-cell / multicast coordination entity (MCE), an operation and maintenance (O&M) node, an operation support system (OSS) node, a self-organizing network (SON) node, a positioning node (e.g., an evolved serving mobile location center (E-SMLC)), and / or a minimization of drive test (MDT).
[0143] The network node 1600 includes a processing circuit 1602, a memory 1604, a communication interface 1606, and a power source 1608. The network node 1600 may be assembled from multiple physically separate components (e.g., a Node B component and an RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In some scenarios in which the network node 1600 comprises multiple separate components (e.g., a BTS component and a BSC component), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple Node Bs. In such scenarios, each unique Node B and RNC pair may, in some instances, be considered a single separate network node. In some embodiments, the network node 1600 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 1604 for different RATs) and some components may be reused (e.g., the same antenna 1610 may be shared by different RATs). Network node 1600 may also include multiple sets of the various shown components for different wireless technologies, e.g., GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, radio frequency identification (RFID), or Bluetooth wireless technologies, integrated into network node 1600. These wireless technologies may be integrated into the same or different chips or sets of chips and other components within network node 1600.
[0144] The processing circuit 1602 may comprise one or more combinations of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable to provide the network node 1600 functionality, either alone or in conjunction with other network node 1600 components such as memory 1604.
[0145] In some embodiments, the processing circuit 1602 comprises a system on a chip (SOC). In some embodiments, the processing circuit 1602 includes one or more of a radio frequency (RF) transceiver circuit 1612 and a baseband processing circuit 1614. In some embodiments, the radio frequency (RF) transceiver circuit 1612 and the baseband processing circuit 1614 may be on separate chips (or sets of chips), boards, or units, such as a radio unit and a digital unit. In alternative embodiments, some or all of the RF transceiver circuit 1612 and the baseband processing circuit 1614 may be on the same chip or set of chips, board, or unit.
[0146] The memory 1604 may comprise any form of volatile or non-volatile computer-readable memory, including, but not limited to, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disk), removable storage media (e.g., flash drive, compact disc (CD) or digital video disc (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions that may be used by the processing circuit 1602. The memory 1604 may store any suitable instructions, data, or information, including applications including one or more of computer programs, software, logic, rules, code, tables, and / or other instructions that can be executed by the processing circuit 1602 and utilized by the network node 1600. The memory 1604 may be used to store computations performed by the processing circuit 1602 and / or data received via the communications interface 1606. In some embodiments, the processing circuit 1602 and the memory 1604 are integrated.
[0147] The communications interface 1606 is used in wired or wireless communication of signaling and / or data between network nodes, access networks, and / or UEs. As shown, the communications interface 1606 comprises port(s) / terminal(s) 1616 for sending and receiving data to and from a network, e.g., over a wired connection. The communications interface 1606 also includes radio front-end circuitry 1618, which is coupled to an antenna 1610 or, in some embodiments, may be part of the antenna 1610. The radio front-end circuitry 1618 comprises a filter 1620 and an amplifier 1622. The radio front-end circuitry 1618 may be connected to the antenna 1610 and the processing circuit 1602. The radio front-end circuitry may be configured to condition signals communicated between the antenna 1610 and the processing circuit 1602. The radio front-end circuitry 1618 may receive digital data to be sent to other network nodes or UEs via a wireless connection. The radio front-end circuitry 1618 may convert the digital data into radio signals having appropriate channel and bandwidth parameters using a combination of filters 1620 and / or amplifiers 1622. The radio signals may then be transmitted via the antenna 1610. Similarly, when receiving data, the antenna 1610 may collect the radio signals, which are then converted into digital data by the radio front-end circuitry 1618. The digital data may be passed to the processing circuitry 1602. In other embodiments, the communication interface may comprise different components and / or different combinations of components.
[0148] In some alternative embodiments, the network node 1600 does not include a separate radio front-end circuit 1618; instead, the processing circuit 1602 includes the radio front-end circuitry and is connected to the antenna 1610. Similarly, in some embodiments, all or a portion of the RF transceiver circuitry 1612 is part of the communications interface 1606. In still other embodiments, the communications interface 1606 includes one or more ports or terminals 1616, the radio front-end circuitry 1618, and the RF transceiver circuitry 1612 as part of a radio unit (not shown), and the communications interface 1606 communicates with baseband processing circuitry 1614 that is part of a digital unit (not shown).
[0149] The antenna 1610 may include one or more antennas or an antenna array configured to send and / or receive wireless signals. The antenna 1610 may be coupled to the radio front-end circuitry 1618 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, the antenna 1610 is separate from the network node 1600 and connectable to the network node 1600 through an interface or port.
[0150] The antenna 1610, the communication interface 1606, and / or the processing circuit 1602 may be configured to perform any receiving operation and / or some obtaining operation described herein as being performed by a network node. Any information, data, and / or signals may be received from a UE, another network node, and / or any other network equipment. Similarly, the antenna 1610, the communication interface 1606, and / or the processing circuit 1602 may be configured to perform any transmitting operation described herein as being performed by a network node. Any information, data, and / or signals may be transmitted to a UE, another network node, and / or any other network equipment.
[0151] The power supply 1608 provides power to the various components of the network node 1600 in a form suitable for each component (e.g., at the voltage and current levels required for each respective component). The power supply 1608 may further comprise, or be coupled to, power management circuitry for supplying power to the components of the network node 1600 for performing the functions described herein. For example, the network node 1600 may be connectable to an external power source (e.g., a power grid, an electrical outlet) via an input circuit or interface, such as an electrical cable, whereby the external power source supplies power to the power circuitry of the power supply 1608. As a further example, the power supply 1608 may comprise a power source in the form of a battery or battery pack connected to or integrated in the power circuitry. The battery may provide backup power in the event that the external power source fails.
[0152] Embodiments of network node 1600 may include additional components other than those shown in Figure 16 to provide certain aspects of the network node's functionality, including any of the functionality described herein and / or functionality necessary to support the subject matter described herein. For example, network node 1600 may include user interface devices to enable input of information into network node 1600 and output of information from network node 1600. This may enable a user to perform diagnostic, maintenance, repair, and other administrative functions for network node 1600.
[0153] 17 is a block diagram of a host 1700, which may be an embodiment of the host 1416 of FIG. 14, in accordance with various aspects described herein. As used herein, the host 1700 may be or comprise various combinations of hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, a container, or processing resources in a server farm. The host 1700 may provide one or more services to one or more UEs.
[0154] The host 1700 includes a processing circuit 1702 operably coupled to an input / output interface 1706, a network interface 1708, a power supply 1710, and a memory 1712 via a bus 1704. In other embodiments, other components may be included. Features of these components may be substantially similar to those described with respect to the devices of previous figures, such as FIGS. 15 and 16, and therefore, those descriptions are generally applicable to the corresponding components of the host 1700.
[0155] The memory 1712 may include one or more computer programs, including one or more host application programs 1714 and data 1716, which may include user data, e.g., data generated by the UE for the host 1700 or data generated by the host 1700 for the UE. An embodiment of the host 1700 may utilize only a subset or all of the shown components. The host application programs 1714 may be implemented in a container-based architecture and may provide support for video codecs (e.g., Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for multiple different classes, types, or implementations of UE (e.g., handsets, desktop computers, wearable display systems, heads-up display systems). The host application program 1714 may also provide user authentication and license checks, and may periodically report health, route, and content availability to a central node, such as a device in the core network or a device on the edge of the core network. Thus, the host 1700 may select and / or indicate a different host for over-the-top services for the UE. The host application program 1714 may support various protocols, such as HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP), Real-Time Streaming Protocol (RTSP), Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.
[0156] FIG. 18 is a block diagram illustrating a virtualization environment 1800 in which functionality implemented by some embodiments may be virtualized. In this context, virtualizing means creating a virtual version of an apparatus or device, which may include virtualizing a hardware platform, storage devices, and networking resources. Virtualization, as used herein, may apply to any device described herein, or components thereof, and relates to implementations in which at least a portion of functionality is implemented as one or more virtual components. Some or all of the functionality described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1800 hosted by one or more of the hardware nodes, such as a network node, a UE, a core network node, or a hardware computing device acting as a host. Furthermore, in embodiments in which the virtual node does not require wireless connectivity (e.g., to a core network node or host), the node may be fully virtualized.
[0157] An application 1802 (which may alternatively be referred to as a software instance, a virtual appliance, a network function, a virtual node, a virtual network function, etc.) is run in the virtualized environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.
[0158] Hardware 1804 includes processing circuitry, memory that stores software and / or instructions executable by the hardware processing circuitry, and / or other hardware devices described herein, such as network interfaces, input / output interfaces, etc. Software is executed by the processing circuitry to instantiate one or more virtualization layers 1806 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 1808a and 1808b (one or more of which are generally referred to as VMs 1808), and / or implement any of the functions, features, and / or benefits described with respect to some embodiments described herein. Virtualization layer 1806 may present to VMs 1808 a virtual operating platform that appears to be networking hardware.
[0159] The VMs 1808 may comprise virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and may be run by a corresponding virtualization layer 1806. Different embodiments of the virtual appliance 1802 instances may be implemented on one or more of the VMs 1808, and the implementations may be done in different ways. Hardware virtualization is referred to in some contexts as network functions virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry-standard high-volume server hardware, physical switches, and physical storage that may be located in data centers and customer premises equipment.
[0160] In the context of NFV, a VM 1808 may be a software implementation of a physical machine that runs programs as if those programs were running on a physical, non-virtualized machine. Each VM 1808 and the portion of the hardware 1804 on which it runs, whether hardware dedicated to that VM and / or hardware shared by that VM with other VMs, form a separate virtual network element. Further, in the context of NFV, a virtual network function is responsible for handling a particular network function running in one or more VMs 1808 on the hardware 1804 and corresponds to the application 1802.
[0161] The hardware 1804 may be implemented in a standalone network node with general or specific components. The hardware 1804 may implement some functions via virtualization. Alternatively, the hardware 1804 may be part of a larger cluster of hardware (e.g., as in a data center or CPE) where many hardware nodes cooperate and are managed via a management and orchestration 1810 that, among other things, oversees the lifecycle management of the application 1802. In some embodiments, the hardware 1804 is coupled to one or more radio units, each including one or more transmitters and one or more receivers, which may be coupled to one or more antennas. The radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with virtual components to provide a virtual node with wireless capabilities, such as a wireless access node or base station. In some embodiments, some signaling may be provided using a control system 1812, which may alternatively be used for communication between the hardware nodes and the radio units.
[0162] While the computing devices (e.g., UEs, network nodes, hosts) described herein may include the depicted combinations of hardware components, other embodiments may comprise computing devices with different combinations of components. It should be understood that these computing devices may comprise any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. The determining, calculating, obtaining, or similar operations described herein may be performed by processing circuitry, which may process information by, for example, transforming the obtained information to other information, comparing the obtained or transformed information to information stored in a network node, and / or performing one or more operations based on the obtained or transformed information and as a result of the processing making a decision. Moreover, while a component is illustrated as a single box located within a larger box or nested within multiple boxes, in reality the computing device may comprise multiple different physical components that make up the single depicted component, and functionality may be partitioned among the separate components. For example, a communications interface may be configured to include any of the components described herein, and / or the functionality of those components may be partitioned between the processing circuitry and the communications interface. In another example, non-computationally intensive functionality of any of such components may be implemented in software or firmware, and computationally intensive functionality may be implemented in hardware.
[0163] In some embodiments, some or all of the functionality described herein may be provided by a processing circuit executing instructions stored in a memory, which in some embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuit without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hardwired manner. In any of these particular embodiments, the processing circuit may be configured to perform the described functionality, regardless of whether or not it executes instructions stored on a non-transitory computer-readable storage medium. Benefits provided by such functionality are not limited to the processing circuit alone or to other components of the computing device, but are enjoyed by the computing device as a whole and / or by end users and wireless networks generally.
[0164] Exemplary embodiments of the techniques and apparatus described herein include, but are not limited to, the following listed examples. Group A Embodiments A1. A method implemented by an authentication server in a wireless communication network, the method comprising: Initiating a primary authentication of the wireless communication device with an external authentication server external to the wireless communication network; receiving signaling indicating successful primary authentication of the wireless communication device by the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device; authenticating the wireless communication device with respect to the wireless communication network based on an identifier included in the received signaling; A method comprising: A2. The method of embodiment A1, wherein the initiating includes initiating a primary authentication of the wireless communication device with an external authentication server using an anonymous identifier that does not identify the wireless communication device. A3. The method of embodiment A2, wherein the anonymous identifier is an anonymous subscription persistent identifier (SUPI). A4. The method of any one of embodiments A1 to A3, wherein the identifier included in the received signaling is a non-anonymous identifier. A5. The method of embodiment A4, wherein the non-anonymous identifier is a non-anonymous SUPI. A6. The method of any one of embodiments A1 to A4, wherein the identifier included in the received signaling is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network. A7. The method of embodiment A6, wherein the public identifier is a General Public Subscription Identifier (GPSI). A8. The method of embodiment A6 or A7, further comprising translating or requesting translation of the public identifier into an identifier that identifies the wireless communication device to a wireless communication network. A9. A method according to any one of embodiments A1 to A8, wherein the identifier included in the received signaling is an authenticated identifier or is associated with an authenticated identifier based on which an external authentication server has authenticated the wireless communication device via primary authentication. A10. The method of embodiment A9, wherein the authenticated identifier is an Extensible Authentication Protocol (EAP) identity. A11. A method according to any one of embodiments A1 to A10, wherein the initiating includes initiating a primary authentication of the wireless communication device by an external authentication server using a presented identifier that the wireless communication device has presented to the wireless communication network as identifying the wireless communication device, and authenticating the wireless communication device with respect to the wireless communication network based on the identifier included in the received signaling includes verifying that the presented identifier corresponds to the identifier included in the received signaling. A12. A method according to any one of embodiments A1 to A11, wherein the primary authentication is initiated as part of a procedure for registering the wireless communication device with the wireless communication network, and the method further includes registering the wireless communication device with the wireless communication network based on successful authentication of the wireless communication device with the wireless communication network. A13. The method of any one of embodiments A1 to A12, wherein the wireless communication network is a standalone private network. A14. The method of any one of embodiments A1 to A13, wherein the authentication server implements an authentication server function (AUSF). Group B Embodiments B1. A method implemented by an external authentication server external to a wireless communication network, the method comprising: performing a first authentication of the wireless communication device with an external authentication server for access by the wireless communication device to the wireless communication network; sending signaling to an authentication server in the wireless communication network indicating successful primary authentication of the wireless communication device by the external authentication server and including an identifier asserted by the external authentication server as authenticating and identifying the wireless communication device; A method comprising: B2. The method of embodiment B1, further comprising receiving signaling that triggers the external authentication server to perform a primary authentication of the wireless communication device with the external authentication server, the signaling including an anonymous identifier for the wireless communication device. B3. The method of embodiment B2, wherein the anonymous identifier is an anonymous subscription persistent identifier (SUPI). B4. The method of any one of embodiments B1 to B3, wherein the identifier included in the transmitted signaling is a non-anonymous identifier. B5. The method of embodiment B4, wherein the non-anonymous identifier is a non-anonymous SUPI. B6. The method of any one of embodiments B1 to B4, wherein the identifier included in the transmitted signaling is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network. B7. The method of embodiment B6, wherein the public identifier is a General Public Subscription Identifier (GPSI). B8. The method of any one of embodiments B1 to B7, wherein the identifier included in the transmitted signaling is or is associated with an authenticated identifier based on which an external authentication server has authenticated the wireless communication device via primary authentication. B9. The method of embodiment B8, wherein the authenticated identifier is an Extensible Authentication Protocol (EAP) identity. B10. The method of any one of embodiments B1 to B9, wherein the wireless communication network is a standalone private network. B11. The method of any one of embodiments B1 to B10, wherein the authentication server implements an authentication server function (AUSF). Group C Embodiments C1. A method implemented by a network node in a wireless communication network, the method comprising: receiving, from an authentication server in the wireless communication network, a request for a primary authentication of the wireless communication device by an external authentication server for access by the wireless communication device to the wireless communication network; sending a response to an authentication server in the wireless communication network indicating successful primary authentication of the wireless communication device by the external authentication server and including the identifier asserted by the external authentication server as authenticating and identifying the wireless communication device; A method comprising: C2. The method of embodiment C1, wherein the request includes an anonymous identifier for the wireless communication device. C3. The method of embodiment C2, wherein the anonymous identifier is an anonymous subscription persistent identifier (SUPI). C4. The method of any one of embodiments C1 to C3, wherein the identifier included in the transmitted signaling is a non-anonymous identifier. C5. The method of embodiment C4, wherein the non-anonymous identifier is a non-anonymous SUPI. C6. The method of any one of embodiments C1 to C4, wherein the identifier included in the transmitted signaling is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network. C7. The method of embodiment C6, wherein the public identifier is a General Public Subscription Identifier (GPSI). C8. The method of any one of embodiments C1 to C7, wherein the identifier included in the transmitted signaling is or is associated with an authenticated identifier based on which an external authentication server has authenticated the wireless communication device via primary authentication. C9. The method of embodiment C8, wherein the authenticated identifier is an Extensible Authentication Protocol (EAP) identity. C10. The method of any one of embodiments C1 to C9, wherein the wireless communication network is a standalone private network. C11. The method of any one of embodiments C1 to C10, wherein the authentication server implements an authentication server function (AUSF). C12. The method of any one of embodiments C1 to C11, wherein the network node implements a Network Slice Specific Authentication and Authorization Function (NSSAAF). Group D Embodiments D1. A method implemented by a network node in a wireless communication network, the method comprising: receiving a request for authentication data for the wireless communication device from an authentication server in the wireless communication network; sending a response to the authentication server indicating that primary authentication of the wireless communication device should be performed by an external authentication server outside the wireless communication network, and including an identifier to be presented to the external authentication server; A method comprising: D2. The method of embodiment D1, wherein the identifier included in the response is an anonymous identifier for the wireless communication device. D3. The method of embodiment D2, wherein the anonymous identifier is an anonymous subscription persistent identifier (SUPI). D4. The method of any one of embodiments D1-D3, wherein the identifier included in the response is a public identifier that identifies the wireless communication device to an external network outside the wireless communication network. D5. The method of embodiment D4, wherein the public identifier is a General Public Subscription Identifier (GPSI). D6. The method of any one of embodiments D1 to D5, wherein the request includes an anonymous identifier for the wireless communication device. D7. The method of embodiment D6 further comprising determining, based on the realm portion of the anonymous identifier, that primary authentication of the wireless communication device should be performed by an external authentication server outside the wireless communication network. D8. The method of any one of embodiments D1 to D7, wherein the wireless communication network is a standalone private network. D9. The method of any one of embodiments D1 to D8, wherein the authentication server implements an authentication server function (AUSF). DD1. A method implemented by a network node in a wireless communication network, the method comprising: receiving a request to convert a public identifier that identifies the wireless communication device to an external network outside the wireless communication network into a private identifier that identifies the wireless communication device to the wireless communication network; converting the public identifier to a private identifier; sending a response including the private identifier; A method comprising: DD2. The method of embodiment DD2, wherein the public identifier is a General Public Subscription Identifier (GPSI). DD3. The method of embodiment DD1 or DDD2, wherein the private identifier is a subscription persistent identifier (SUPI). DD4. The method of embodiment DD1 or DD2, wherein the wireless communication network is a standalone private network. DD5. The method of any one of embodiments DD1 to DD4, wherein the request is received from an authentication server. DD6. The method of embodiment DD5, wherein the authentication server implements an authentication server function (AUSF). Group E Embodiments E1. An authentication server configured to perform any of the steps recited in any one of the embodiments of Group A. E2. An authentication server comprising processing circuitry configured to perform any of the steps recited in any one of the embodiments of Group A. E3. Communication circuits and a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group A; An authentication server comprising: E4. A processing circuit configured to perform any of the steps recited in any one of the embodiments of Group A; a power supply circuit configured to supply power to the authentication server; An authentication server comprising: E5. An authentication server comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit, whereby the authentication server is configured to perform any of the steps recited in any one of the embodiments of Group A. E6. A computer program comprising instructions that, when executed by at least one processor of an authentication server, cause the authentication server to perform the steps recited in any one of the embodiments of group A. E7. A carrier comprising the computer program of embodiment E6, the carrier being one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. E8. An external authentication server configured to perform any of the steps recited in any one of the Group B embodiments. E9. An external authentication server comprising processing circuitry configured to perform any of the steps recited in any one of the Group B embodiments. E10. Communication circuits and a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group B; an external authentication server comprising: E11. A processing circuit configured to perform any of the steps recited in any one of the embodiments of Group B; A power delivery circuit configured to power an external authentication server. an external authentication server comprising: E12. An external authentication server comprising a processing circuit and a memory, the memory including instructions executable by the processing circuit, whereby the external authentication server is configured to perform any of the steps recited in any one of the embodiments of Group B. E13. A computer program comprising instructions that, when executed by at least one processor of an external authentication server, cause the external authentication server to perform the steps recited in any one of the group B embodiments. E14. A carrier comprising the computer program of embodiment E13, the carrier being one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. E15. A network node configured to perform any of the steps recited in any one of the embodiments of Group C or Group D. E16. A network node comprising processing circuitry configured to perform any of the steps recited in any one of the embodiments of Group C or Group D. E17. Communication circuits and a processing circuit configured to perform any of the steps recited in any one of the embodiments of Group C or Group D; A network node comprising: E18. A processing circuit configured to perform any of the steps recited in any one of the embodiments of Group C or Group D; a power supply circuit configured to supply power to the network node; A network node comprising: E19. A network node comprising a processing circuit and a memory, the memory containing instructions executable by the processing circuit, whereby the network node is configured to perform any of the steps recited in any one of the embodiments of Group C or Group D. E20. A computer program comprising instructions that, when executed by at least one processor of a network node, cause the network node to perform the steps recited in any one of the embodiments of Group C or Group D. E21. A carrier containing the computer program of embodiment E20, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium.
Claims
1. A method implemented by an authentication server (14) in a wireless communication network (10), the method comprising: Initiating (600) a primary authentication of the wireless communication device (12) with an external authentication server (20) external to the wireless communication network (10); receiving (610) signaling (24) indicating successful primary authentication of the wireless communication device (12) by the external authentication server (20) and including an identifier (26) asserted by the external authentication server (20) as authenticating and identifying the wireless communication device (12); authenticating (620) the wireless communication device (12) with respect to the wireless communication network (10) based on the identifier (26) included in the received signaling (24); Including, the initiating includes sending a request for primary authentication to a network node (16) in the wireless communication network (10), the signaling (24) being received from the network node; The method, wherein the authentication server (14) implements an authentication server function (AUSF) and the network node implements a network slice specific authentication and authorization function (NSSAAF).
2. 2. The method of claim 1, wherein the initiating includes initiating a primary authentication of the wireless communication device by the external authentication server using an anonymous identifier that does not identify the wireless communication device, and the identifier included in the received signaling is a non-anonymous identifier.
3. The method of claim 2 , wherein the anonymous identifier is an anonymous subscription persistent identifier (SUPI) and the non-anonymous identifier is a non-anonymous SUPI.
4. 2. The method of claim 1, wherein the initiating includes initiating a primary authentication of the wireless communication device by the external authentication server using a presented identifier that the wireless communication device has presented to the wireless communication network as identifying the wireless communication device, and authenticating the wireless communication device with respect to the wireless communication network based on the identifier included in the received signaling includes verifying that the presented identifier corresponds to the identifier included in the received signaling.
5. 5. The method of claim 4, wherein the validating comprises: transmitting the presented identifier to a network device that implements a unified data management (UDM) function; and performing the validating based on a response received from the network device that implements the UDM function.
6. 2. The method of claim 1, wherein the primary authentication is initiated as part of a procedure for registering the wireless communication device with the wireless communication network, the method further comprising registering the wireless communication device with the wireless communication network based on successful authentication of the wireless communication device with the wireless communication network.
7. The method of claim 1, wherein the wireless communication network (10) is a standalone private network.
8. A method implemented by an external authentication server (20) external to a wireless communication network (10), said method comprising: receiving signaling from a network node (16) in the wireless communication network (10) triggering the external authentication server (20) to perform a primary authentication of the wireless communication device (12) with the external authentication server (20) for access by the wireless communication device (12) to the wireless communication network (10); performing (700) the primary authentication of the wireless communication device (12) with the external authentication server (20) for access by the wireless communication device (12) to the wireless communication network (10); sending (710) to an authentication server (14) in the wireless communication network (10) signaling (24) indicating successful primary authentication of the wireless communication device (12) by the external authentication server (20) and including an identifier (26) asserted by the external authentication server (20) as authenticating and identifying the wireless communication device (12); Including, The method, wherein the authentication server (14) implements an authentication server function (AUSF) and the network node implements a network slice specific authentication and authorization function (NSSAAF).
9. The method of claim 8, wherein the signaling includes an anonymous identifier for the wireless communication device (12).
10. The method of claim 9 , wherein the anonymous identifier is an anonymous subscription persistent identifier (SUPI).
11. 9. The method of claim 8, wherein the identifier (26) included in the transmitted signaling (24) is a non-anonymous identifier.
12. The method of claim 11 , wherein the non-anonymous identifier is a non-anonymous SUPI.
13. The method of claim 8, wherein the wireless communication network (10) is a standalone private network.
14. A method implemented by a network node (16) in a wireless communication network (10), the method comprising: receiving (800) a request from an authentication server (14) in the wireless communication network (10) for a primary authentication of the wireless communication device (12) by an external authentication server (20) for access by the wireless communication device (12) to the wireless communication network (10); sending (810) a response to the authentication server (14) in the wireless communication network (10) indicating that the primary authentication of the wireless communication device (12) by the external authentication server (20) was successful and including an identifier (26) asserted by the external authentication server (20) as authenticating and identifying the wireless communication device (12); Including, The method, wherein the authentication server (14) implements an authentication server function (AUSF) and the network node implements a network slice specific authentication and authorization function (NSSAAF).
15. 15. The method of claim 14, wherein the request includes an anonymous identifier for the wireless communication device (12), and the identifier (26) included in the transmitted signaling (24) is a non-anonymous identifier.
16. The method of claim 15 , wherein the anonymous identifier is an anonymous subscription persistent identifier (SUPI) and the non-anonymous identifier is a non-anonymous SUPI.
17. The method of claim 14, wherein the wireless communication network (10) is a standalone private network.
18. An authentication server (14) configured for use in a wireless communication network (10), said authentication server (14) comprising: A communication circuit (1020); A processing circuit (1010) 8. An authentication server comprising: a processing circuit (1010) configured to perform the method of any one of claims 1 to 7.
19. An external authentication server (20) external to the wireless communication network (10), said external authentication server (20) comprising: A communication circuit (1120); A processing circuit (1110) 14. An external authentication server (20) comprising: a processing circuit (1110) configured to implement a method according to any one of claims 8 to 13.
20. A network node (16) configured for use in a wireless communication network (10), said network node comprising: A communication circuit (1220); A processing circuit (1210) 18. A network node comprising: a processing circuit (1210) configured to perform a method according to any one of claims 14 to 17.
21. 8. A computer program comprising instructions that, when executed by at least one processor of an authentication server (14) configured for use in a wireless communication network (10), cause the authentication server (14) to perform the method of any one of claims 1 to 7.
22. 14. A computer program comprising instructions that, when executed by at least one processor of an external authentication server (20) configured for use in a wireless communication network (10), cause the external authentication server (20) to perform the method of any one of claims 8 to 13.
23. 18. A computer program comprising instructions that, when executed by at least one processor of a network node (16) configured for use in a wireless communication network (10), cause the network node (16) to perform the method of any one of claims 14 to 17.