Method and apparatus for authentication
By implementing EAP-based authentication procedures in 4G networks, security issues in PDN connections are mitigated, ensuring secure transitions between 4G and 5G networks.
Patent Information
- Application Number
- JP2023550687
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-02-23
- Filing Date
- 2022-02-23
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2042-02-23
AI Technical Summary
Security issues arise in communication networks when low-security authentication methods, such as PAP/CHAP, are used, leading to vulnerabilities in PDN connections, especially in 4G networks, where raw data is transferred without security in the PCO or ePCO.
Implementing a more secure authentication method, such as EAP, by triggering a procedure with an AAA server during session establishment in both 4G and 5G networks, ensuring higher security without requiring re-authentication during mobility between network generations.
Enhances network security by supporting EAP-based authentication for 4G PDN connections, reducing vulnerabilities and maintaining security integrity across network transitions.
Smart Images

Figure 0007772811000001 
Figure 0007772811000002 
Figure 0007772811000003
Abstract
Description
[Technical Field]
[0001] Non-limiting, exemplary embodiments of the present disclosure relate generally to the field of communications, and more particularly to methods and apparatus for authentication. [Background technology]
[0002] This section introduces aspects that may be helpful in improving the understanding of the disclosure. Accordingly, the statements in this section are to be read in this light and not understood as admissions about what is in the prior art or what is not in the prior art.
[0003] Communication service providers and network operators are constantly faced with the challenge of delivering value and convenience to consumers, including offering compelling network services and performance. With the rapid development of network and communications technologies, wireless communication networks, such as Long Term Evolution (LTE) / fourth generation (4G) networks and New Radio (NR) / fifth generation (5G) networks, are expected to deliver high traffic capacity and end-user data rates with low latency. To meet the diverse requirements of new services across a wide range of industries, the 3rd Generation Partnership Project (3GPP®) is developing various network function services for various communication networks.
[0004] In wireless communication networks, various authentication, authorization, and accounting (AAA) procedures may exist. For example, Section 16 of 3GPP® TS29.061 V17.1.0, the entire disclosure of which is incorporated herein by reference, describes the use of RADIUS (Remote Authentication Dial-In User Service) at the Gi / Sgi interface. Section 12 of 3GPP® TS29.561 V17.0.0, the entire disclosure of which is incorporated herein by reference, describes DN (Data Network)-AAA (Diameter) interactions.
[0005] According to clause 5.6.6 of 3GPP® TS23.501 V16.7.0, the entire disclosure of which is incorporated herein by reference, secondary authentication / authorization by the DN-AAA server is defined only during PDU (Protocol Data Unit) session establishment: If a UE (User Equipment) provides authentication / authorization information corresponding to a DN-specific identifier during PDU session establishment, a Session Management Function (SMF) determines that authentication / authorization is required for PDU session establishment based on the SMF policy associated with the DN.
[0006] Extensible Authentication Protocol (EAP) authentication is mandatory for 5G Core Networks (5GC) because it has higher security than traditional Password Authentication Protocol (PAP) and Challenge Handshake Authentication Protocol (CHAP) (username and user password from Protocol Configuration Options (PCO)).
[0007] Traditional PAP / CHAP (username and user password from PCO) continues to be used in 4G PDN (Packet Data Network) connection setup (including 4G users with 5G capabilities). EAP-based authentication is not defined for 4G PDN connections. Summary of the Invention [Problem to be solved by the invention]
[0008] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. It is understood that this Summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claims.
[0009] Security issues can arise when a low-security authentication method is used in a communication network. For example, security issues arise when a UE connects to an Evolved Packet System (EPS). The UE uses conventional PAP / CHAP (user name and user password from the PCO) during PDN connection setup. Raw data without security is transferred in the PCO or ePCO (extended protocol configuration option).
[0010] To provide higher security in communication networks, it may be desirable to provide a solution that supports authentication methods with higher security. For example, to increase the security of 4G PDN connections, it may be desirable to define a solution that supports EAP for 4G PDN connections in EPS. If EAP-based authentication is supported for 4G PDN connections, re-authentication is not required during mobility from 4G to 5G. [Means for solving the problem]
[0011] In a first aspect of the present disclosure, there is provided a method performed by a session management and gateway entity. The method includes receiving a session creation request from a mobile management entity, the session creation request including an identifier of a terminal device. The method further includes determining to use a second authentication method rather than the first authentication method. The second authentication method is more secure than the first authentication method. The method further includes triggering a procedure of the second authentication method associated with an authentication, authorization, and accounting (AAA) server.
[0012] In one embodiment, the method further includes sending an access request including the identifier of the terminal device to an AAA server. The method further includes receiving an access accept message from the AAA server including the authorization data.
[0013] In one embodiment, the access request further includes an invalid username or a locally configured username.
[0014] In one embodiment, the method further includes transmitting information to a policy control function indicating that authentication associated with the terminal device is pending. The method further includes receiving default quality of service (QoS) information from the policy control function.
[0015] In one embodiment, the procedure of the second authentication method is triggered after the session is successfully established.
[0016] In one embodiment, the method further includes receiving information from the AAA server indicating that the second authentication method was successful. The method further includes sending information indicating that the second authentication method was successful to a policy control function. The method further includes receiving at least one of a service policy and a charging control rule from the policy control function.
[0017] In one embodiment, the method further includes sending a message to a mobile management entity including information indicating that the second authentication method was successful and quality of service (QoS) information.
[0018] In one embodiment, during the procedure of the second authentication method, at least one bearer update request and at least one bearer update response including an extended protocol configuration option (ePCO) with an Extensible Authentication Protocol (EAP) message exchange are used between the session management and gateway entity and the mobility management entity.
[0019] In one embodiment, the method further includes determining that the second authentication method failed. The method further includes triggering a session deletion procedure.
[0020] In one embodiment, determining that the second authentication method has failed is based at least on receiving information from an AAA server indicating that the second authentication method has failed, or on the bearer update response from the mobile management entity failing or timing out.
[0021] In one embodiment, the second authentication method includes the Extensible Authentication Protocol (EAP).
[0022] In one embodiment, the first authentication method includes Password Authentication Protocol (PAP) or Challenge Handshake Authentication Protocol (CHAP).
[0023] In one embodiment, the decision to use the second authentication method rather than the first authentication method is based on at least one of an agreement with the AAA server, at least one parameter included in the session creation request, a local configuration of whether to use the second authentication method, the capabilities of the AAA server, and the capabilities of the terminal device.
[0024] In one embodiment, the agreement with the AAA server includes an agreement with the AAA server for a specific Data Network Name (DNN) or Single Network Slice Selection Assistance Information (S-NSSAI).
[0025] In one embodiment, the session management and gateway entity comprises a session management function combined with a packet data network gateway control plane (SMF+PGW-C).
[0026] In one embodiment, the AAA server includes a data network AAA (DN-AAA) server.
[0027] In one embodiment, the terminal device is accessing a fourth generation (4G) network.
[0028] In one embodiment, the session creation request does not include the actual username and user password specific to the data network name.
[0029] In a second aspect of the present disclosure, there is provided a method executed by a mobile management entity. The method includes receiving an attach request from a terminal device. The method further includes sending a session creation request including an identifier of the terminal device to a session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity instead of a procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0030] In one embodiment, the method further includes receiving a message from the session management and gateway entity, the message including information indicating that the second authentication method was successful and quality of service (QoS) information. The method further includes sending a message to the terminal device, the message including information indicating that the second authentication method was successful.
[0031] In one embodiment, during the procedure of the second authentication method, at least one Evolved Packet System (EPS) Bearer Context Modification Request and at least one EPS Bearer Context Modification Accept, including an Extended Protocol Configuration Option (ePCO) accompanied by an Extensible Authentication Protocol (EAP) message, are used between the terminal device and the mobile management entity.
[0032] In one embodiment, the attach request does not include the actual username and user password specific to the data network name.
[0033] According to a third aspect of the present disclosure, there is provided a method executed by a terminal device, the method including sending an attach request to a mobility management entity, wherein a procedure of a second authentication method is triggered by a session management and gateway entity instead of a procedure of a first authentication method, the second authentication method being more secure than the first authentication method.
[0034] In one embodiment, the method further includes receiving a message from the mobile management entity including information indicating that the second authentication method was successful.
[0035] According to a fourth aspect of the present disclosure, there is provided a method performed by a policy control function. The method includes receiving information from a session management and gateway entity indicating that authentication associated with a terminal device is pending. The method further includes sending default quality of service (QoS) information to the session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity instead of a procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0036] In one embodiment, the method further includes receiving information from the session management and gateway entity indicating that the second authentication method was successful. The method further includes sending at least one of a service policy and a charging control rule to the session management and gateway entity.
[0037] In a fifth aspect of the present disclosure, there is provided a method executed by an authentication, authorization, and accounting (AAA) server. The method includes receiving an access request including an identifier of a terminal device from a session management and gateway entity. The method further includes sending an access accept message including authorization data to the session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity, rather than a procedure of the first authentication method. The second authentication method has higher security than the first authentication method.
[0038] In one embodiment, the method further includes, after the procedure of the second authentication method is successfully completed, sending information to the session management and gateway entity indicating that the second authentication method was successful.
[0039] In one embodiment, the method further includes determining that the second authentication method procedure is not initiated after a period of time. The method further includes sending a disconnect request to the session management and gateway entity.
[0040] In a sixth aspect of the present disclosure, a session management and gateway entity is provided. The session management and gateway entity includes a processor and a memory coupled to the processor. The memory includes instructions executable by the processor. The session management and gateway entity is operative to receive a session creation request from the mobile management entity, the session creation request including an identifier of the terminal device. The session management and gateway entity is further operative to determine to use a second authentication method rather than the first authentication method. The second authentication method has higher security than the first authentication method. The session management and gateway entity is further operative to trigger a procedure of the second authentication method associated with an authentication, authorization, and accounting (AAA) server.
[0041] According to a seventh aspect of the present disclosure, there is provided a mobile management entity. The mobile management entity includes a processor and a memory coupled to the processor. The memory includes instructions executable by the processor. The mobile management entity operates to receive an attach request from a terminal device. The mobile management entity is further operable to send a session creation request including an identifier of the terminal device to a session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity, rather than a procedure of the first authentication method. The second authentication method has higher security than the first authentication method.
[0042] According to an eighth aspect of the present disclosure, there is provided a terminal device. The terminal device includes a processor and a memory coupled to the processor. The memory includes instructions executable by the processor. The terminal device operates to send an attach request to a mobility management entity. A procedure of a second authentication method is triggered by the session management and gateway entity, rather than a procedure of the first authentication method. The second authentication method has higher security than the first authentication method.
[0043] According to a ninth aspect of the present disclosure, there is provided a policy control function. The policy control function includes a processor and a memory coupled to the processor. The memory includes instructions executable by the processor. The policy control function operates to receive information from a session management and gateway entity indicating that authentication associated with a terminal device is pending. The policy control function is further operable to send default quality of service (QoS) information to the session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity, rather than a procedure of the first authentication method. The second authentication method has higher security than the first authentication method.
[0044] In a tenth aspect of the present disclosure, an authentication, authorization, and accounting (AAA) server is provided. The AAA server includes a processor and a memory coupled to the processor. The memory includes instructions executable by the processor. The AAA server is further operative to send an access-accept message including authorization data to a session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity, rather than a procedure of the first authentication method. The second authentication method has higher security than the first authentication method.
[0045] In an eleventh aspect of the present disclosure, a session management and gateway entity is provided. The session management and gateway entity includes a first receiving module, a first determining module, and a first triggering module. The first receiving module may be configured to receive a session creation request including an identifier of a terminal device from a mobile management entity. The first determining module may be configured to determine to use a second authentication method having higher security than the first authentication method rather than the first authentication method. The first triggering module may be configured to trigger a procedure of the second authentication method associated with an authentication, authorization, and accounting (AAA) server.
[0046] In one embodiment, the session management and gateway entity may further comprise a first sending module configured to send an access request including an identifier of the terminal device.
[0047] In one embodiment, the session management and gateway entity may further comprise a second receiving module configured to receive an access accept message including authorization data from the AAA server.
[0048] In one embodiment, the session management and gateway entity may further comprise a second sending module configured to send information indicating that an authentication associated with the terminal device is pending to the policy control function.
[0049] In one embodiment, the session management and gateway entity may further comprise a third receiving module configured to receive default quality of service (QoS) information from the policy control function.
[0050] In one embodiment, the session management and gateway entity may further comprise a fourth receiving module configured to receive information from the AAA server indicating that the second authentication method was successful.
[0051] In one embodiment, the session management and gateway entity may further comprise a third sending module configured to send information indicating that the second authentication method was successful to the policy control function.
[0052] In one embodiment, the session management and gateway entity may further comprise a fifth receiving module configured to receive at least one service policy and charging control rule from the policy control function.
[0053] In one embodiment, the session management and gateway entity may further comprise a fourth sending module configured to send a message to the mobile management entity including information indicating that the second authentication method was successful and quality of service (QoS) information.
[0054] In one embodiment, the session management and gateway entity may further comprise a second determination module configured to determine that the second authentication method has failed.
[0055] In one embodiment, the session management and gateway entity may further comprise a second trigger module configured to trigger a session deletion procedure.
[0056] According to a twelfth aspect of the present disclosure, there is provided a mobile management entity. The mobile management entity includes a first receiving module and a first sending module. The first receiving module may be configured to receive an attach request from a terminal device. The first sending module may be configured to send a session creation request including an identifier of the terminal device to a session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity instead of a procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0057] In one embodiment, the mobile management entity may further comprise a second receiving module configured to receive a message from the session management and gateway entity including information indicating that the second authentication method was successful and quality of service (QoS) information.
[0058] In one embodiment, the mobile management entity may further comprise a second sending module configured to send a message to the terminal device including information indicating that the second authentication method is successful.
[0059] According to a thirteenth aspect of the present disclosure, there is provided a terminal device, comprising: a sending module; the sending module may be configured to send an attach request to a mobility management entity; a procedure of a second authentication method is triggered by a session management and gateway entity, rather than a procedure of the first authentication method; the second authentication method is more secure than the first authentication method.
[0060] In one embodiment, the terminal device may further comprise a receiving module configured to receive a message from the mobile management entity including information indicating that the second authentication method is successful.
[0061] According to a fourteenth aspect of the present disclosure, there is provided a policy control function. The policy control function includes a first receiving module and a first transmitting module. The first receiving module may be configured to receive an attach request from a terminal device. The first transmitting module may be configured to transmit default Quality of Service (QoS) information to a session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity instead of a procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0062] In one embodiment, the policy control function may further comprise a second receiving module configured to receive information from the session management and gateway entity indicating that the second authentication method was successful.
[0063] In one embodiment, the policy control function may further comprise a second sending module configured to send at least one of the service policy and the charging control rule to the session management and gateway entity.
[0064] According to a fifteenth aspect of the present disclosure, there is provided an AAA server. The AAA server includes a first receiving module and a first sending module. The first receiving module may be configured to receive an access request including an identifier of a terminal device from a session management and gateway entity. The first sending module may be configured to send an access accept message including authorization data to the session management and gateway entity. A procedure of a second authentication method is triggered by the session management and gateway entity, rather than a procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0065] In one embodiment, the AAA server may further comprise a determining module configured to determine that the procedure of the second authentication method is not initiated after a certain period of time.
[0066] In one embodiment, the AAA server may further comprise a second sending module configured to send a disconnect request to the session management and gateway entity.
[0067] Embodiments herein may provide many advantages, a non-exhaustive list of examples of which is provided below: In some embodiments herein, security issues may be resolved for a UE that initially connects to an EPS. In some embodiments herein, security issues may be resolved for a UE that initially connects to an EPS and moves to 5GS during the session lifetime. In some embodiments herein, a gateway entity, such as a session management and SMF, may obtain 5GS attributes from a DN-AAA server as soon as the UE moves to 5GS. In some embodiments herein, the DN-AAA server may have the correct information when triggering re-authentication. Embodiments herein are not limited to the preferred features and advantages described above. Those skilled in the art will recognize additional features and advantages upon reading the following detailed description.
[0068] The above and other aspects, features, and advantages of various embodiments of the present disclosure will become more fully apparent from the following detailed description, taken in conjunction with the accompanying drawings, in which, by way of example, like or equivalent elements are designated by like reference numerals or characters, and in which the drawings are presented to facilitate a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale. [Brief explanation of the drawings]
[0069] [Figure 1] FIG. 1 illustrates a schematic diagram of a high-level architecture of a 5G network according to an embodiment of the present disclosure. [Figure 2] FIG. 1 illustrates a schematic diagram of a 4G network system architecture according to an embodiment of the present disclosure. [Figure 3] Diagram showing an example of RADIUS message flow on the SGI interface for GTP-based S5 / S8 (successful user authentication). [Figure 4] Flowchart for initial EAP authentication with an external AAA server. [Figure 5a] 1 is a flowchart of a method according to one embodiment of the present disclosure. [Figure 5b] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 5c] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 5d] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 5e] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 5f] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 5g] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 6a] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 6b] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 6c] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 6d] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 6e] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 6f] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 7] FIG. 1 is a block diagram illustrating an apparatus suitable for implementing some embodiments of the present disclosure. [Figure 8a] FIG. 2 is a block diagram illustrating a session management and gateway entity according to one embodiment of the present disclosure. [Figure 8b] 2 is a block diagram illustrating a mobile management entity according to one embodiment of the present invention. [Figure 8c] 1 is a block diagram illustrating a terminal device according to an embodiment of the present invention. [Figure 8d] FIG. 2 is a block diagram illustrating a policy control function according to an embodiment of the present invention. [Figure 8e] FIG. 2 is a block diagram illustrating an AAA server according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0070] Embodiments of the present disclosure will now be described in detail with reference to the drawings. It should be understood that these embodiments are not intended to imply any limitation on the scope of the present disclosure, but are described solely to enable those skilled in the art to better understand and therefore practice the present disclosure. Throughout this specification, references to features, advantages, or similar language do not imply that all features and advantages that may be realized in the present disclosure should or are present in any single embodiment of the present disclosure. Rather, language referring to features and advantages is understood to mean that a particular feature, advantage, or characteristic described in connection with one embodiment is included in at least one embodiment of the present disclosure. Furthermore, the described features, advantages, and characteristics of the present disclosure can be combined in any suitable manner in one or more embodiments. Those skilled in the relevant art will recognize that the present disclosure may be practiced without one or more of the specific features or advantages of a particular embodiment. In other examples, additional features and advantages may be recognized in certain embodiments that are not present in all embodiments of the present disclosure.
[0071] As used herein, the term "network" refers to a network that conforms to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced, Wideband Code Division Multiple Access (WCDMA), High Speed Packet Access (HSPA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single Carrier Frequency Division Multiple Access (SC-FDMA), and other wireless networks. A CDMA network may implement a radio technology such as Universal Terrestrial Radio Access (UTRA). UTRA includes WCDMA and other variants of CDMA. A TDMA network may implement a radio technology such as Global System for Mobile Communications (GSM). An OFDMA network may implement wireless technologies such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, ad hoc networks, wireless sensor networks, etc. In the following description, the terms "network" and "system" may be used interchangeably. Furthermore, communication between two devices in a network may be performed according to any suitable communication protocol, including, but not limited to, communication protocols defined by standards organizations such as 3GPP®. For example, communication protocols may include first generation (1G), 2G, 3G, 4G, 4.5G, 5G communication protocols, and / or other protocols now known or developed in the future.
[0072] The terms "network device," "network entity," or "network node" refer to any suitable network function (NF) that may be implemented in a network entity (physical or virtual) of a communications network. For example, a network function may be implemented as a network element on dedicated hardware, as a software instance running on dedicated hardware, or as a virtualized function instantiated on a suitable platform, such as a cloud infrastructure. For example, a 5G system (5GS) may include multiple NFs, such as an AMF (Access and Mobility Function), an SMF (Session Management Function), an AUSF (Authentication Service Function), an UDM (Unified Data Management), a PCF (Policy Control Function), an AF (Application Function), an NEF (Network Publishing Function), an UPF (User Plane Function), an NRF (Network Repository Function), a RAN (Radio Access Network), an SCP (Service Communication Proxy), an NWDAF (Network Data Analysis Function), an NSSF (Network Slice Selection Function), and an NSSAAF (Network Slice Specific Authentication and Authorization Function). For example, a 4G system (such as LTE) may include an MME (Mobility Management Entity), an HSS (Home Subscriber Server), a Policy and Charging Rules Function (PCRF), a Packet Data Network Gateway (PGW or PG-W), a PGW Control Plane (PGW-C), a PGW User Plane (PGW-U), a Serving Gateway (SGW), an SGW Control Plane (SGW-C), an SGW User Plane (SGW-U), an E-UTRAN Node B (eNB), etc. In other embodiments, the network functions may include different types of NFs, depending, for example, on the particular network.
[0073] The network device may be an access network device having an access function in a communication network through which a terminal device accesses the network and receives services. The access network device may include a base station (BS), an access point (AP), a multi-cell / multicast coordination entity (MCE), a controller, or any other suitable device in a wireless communication network. The BS may be, for example, a Node B (Node B or NB), an evolved Node B (eNode B or eNB), a next-generation Node B (gNode B or gNB), a remote radio unit (RRU), a radio header (RH), an integrated access backhaul (IAB) node, a remote radio head (RRH), a relay, a femto, a pico, or other low-power node.
[0074] Further examples of access network nodes include multi-standard radio (MSR) radio equipment such as an MSR BS, a network controller such as a radio network controller (RNC) or base station controller (BSC), a base transceiver station (BTS), a transmission point, a transmitting node, a positioning node, etc. However, more generally, a network node may refer to any suitable device (or group of devices) operable to configure, arrange, enable and / or provide terminal device access to a wireless communication network or capable of providing some service to terminal devices accessing the wireless communication network.
[0075] The term "terminal device" refers to any end device that can access a communications network and receive service. By way of non-limiting example, a terminal device may refer to a mobile terminal, user equipment (UE), or other suitable device. A UE may be, for example, a subscriber station (SS), a portable subscriber station, a mobile station (MS), or an access terminal (AT). Terminal devices may include, but are not limited to, portable computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback devices, mobile phones, cellular phones, smartphones, voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable devices, personal digital assistants (PDAs), portable computers, desktop computers, wearable terminal devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded equipment (LEE), laptop mounted equipment (LME), USB dongles, smart devices, wireless customer premises equipment (CPE), etc. In the following description, the terms "terminal device," "terminal," "user equipment," and "UE" may be used interchangeably. As an example, a terminal device may represent a UE configured to communicate in accordance with one or more communications standards promulgated by 3GPP (Third Generation Partnership Project), e.g., the 3GPP LTE or NR standards. As used herein, "user equipment" or "UE" does not necessarily have a "user" in the sense of a human user who owns and / or operates the associated device. In some embodiments, a terminal device may be configured to transmit and / or receive information without direct human interaction. For example, a terminal device may be designed to transmit information to a network on a predetermined schedule, in response to a request from the communications network, when triggered by an internal or external event, or when connected to a network. Alternatively, a UE may represent a device intended for sale to or operation by a human user, but not initially associated with a specific human user.
[0076] As yet another example, in an Internet of Things (IoT) scenario, a terminal device may represent an appliance or other device that performs monitoring and / or measurements and transmits results of such monitoring and / or measurements to another terminal device and / or network equipment. In this case, the terminal device is a machine-to-machine (M2M) device, which may be referred to in the 3GPP context as a machine-type communication (MTC) device. As a particular example, the terminal device may be a UE implementing the 3GPP Narrowband IoT (NB-IoT) standard. Specific examples of such appliances or devices are metering devices such as sensors, power meters, industrial machines, or household appliances such as refrigerators, televisions, and personal wearable appliances such as watches. In other scenarios, the terminal device may represent a vehicle or other appliance that can monitor and / or report its operating state or other functions related to its operation.
[0077] References herein to "one embodiment," "embodiment," "example embodiment," etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not all embodiments necessarily include the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described with respect to an embodiment, implementing such feature, structure, or characteristic in connection with other embodiments is presented as being within the knowledge of one of ordinary skill in the art, whether or not explicitly stated.
[0078] Although terms such as "first" and "second" are used herein to describe various elements, it should be understood that these elements are not limited by these terms. These terms are used only to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of the example embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0079] As used herein, the phrase "at least one of A and B" or "at least one of A or B" should be understood to mean "A only, B only, or both A and B." The phrase "A and / or B" should be understood to mean "A only, B only, or both A and B."
[0080] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. The singular forms "a," "an," "an," and "the" are intended to include the plural forms unless the context clearly dictates otherwise. As used herein, the terms "including," "having," "comprising," and the like specify the presence of stated features, elements, and / or components, but do not exclude the presence of one or more other features, elements, components, and / or combinations thereof.
[0081] Please note that these terms used in this document are only used for ease of explanation and to distinguish between nodes, devices, networks, etc. As technology develops, other terms with similar / same meanings may also be used.
[0082] In the following description and claims, unless defined otherwise, all technical and scientific terms used have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.
[0083] Although the subject matter described herein may be implemented in any suitable type of system using any suitable components, the embodiments disclosed herein are described with reference to a communication system conforming to the exemplary system architecture shown in Figures 1 and 2. For simplicity, the system architectures of Figures 1 and 2 show only a few example elements. In practice, the communication system may further include any additional elements suitable for supporting communications between terminal devices, or between a wireless device and another communication device, such as a landline telephone, a service provider, or any other network node or terminal device. The communication system may provide communications and various types of services to one or more terminal devices to facilitate the terminal device's access to and / or use of services provided by or through the communication system.
[0084] Figure 1 illustrates a schematic diagram of a non-roaming architecture for interworking between 5GS and EPC (Evolved Packet Core) / E-UTRAN (Evolved Universal Terrestrial Radio Access Network) according to one embodiment of the present disclosure. The architecture in Figure 1 is the same as Figure 4.3.1-1 described in 3GPP TS 23.501 V16.7.0.
[0085] As shown in Figure 1, the N26 interface is a CN (Core Network)-to-CN (Core Network) interface between the MME and the 5GS AMF to enable interworking between the EPC and the NG Core. Support for the N26 interface in the network is optional for interworking. N26 supports a subset of the functions supported in S10 (required for interworking). The PGW-C+SMF and UPF+PGW-U are dedicated to interworking between the 5GS and the EPC; they are optional and depend on the UE MM (Mobility Management) core network function and the UE subscription. UEs not subject to 5GS and EPC interworking can be served by entities not dedicated to interworking, i.e., either the PGW or the SMF / UPF. There may be another UPF (not shown in Figure 3) between the NG-RAN (Next Generation RAN) and the UPF+PGW-U; that is, the UPF+PGW-U can support N9 for additional UPFs, if needed. The diagrams and procedures in this specification depicting an SGW do not assume that the SGW will be deployed as a monolithic SGW or as an SGW separated into control plane and user plane functions.
[0086] Figure 2 schematically illustrates a non-roaming architecture for interworking between 5GS and EPC (Evolved Packet Core) / E-UTRAN (Evolved Universal Terrestrial Radio Access Network) according to another embodiment of the present disclosure. CHF stands for Charging Function. CDR stands for Charging Data Record. BS stands for Basic Service. As shown in Figure 2, the DN-AAA may comprise a DN-AAA shared server or a DN-AAA in-band server. The DN-AAA shared server may be connected to the PGW-C+SMF. The DN-AAA in-band server may be connected to the PGW-U+UPF.
[0087] Figure 3 shows an example of a RADIUS message flow over the SGI interface for GTP-based S5 / S8 (in the case of successful user authentication). Figure 3 is the same as Figure 25a.1 of 3GPP® TS 29.061 V17.1.0. As described in Section 16.4.1 of 3GPP® TS 29.061 V17.1.0, the Access-Request message (sent from the GGSN / P-GW to the AAA server) may include a username and a user password. The username is provided by the user to the GGSN / P-GW in a Protocol Configuration Option (PCO) or, in the case of the P-GW, in an Additional Protocol Configuration Option (APCO) received during the IP-CAN (IP (Internet Protocol)-Connectivity Access Network) session establishment procedure when multiple authentications are supported. If the PPP (Point-to-Point Protocol) PDP (Packet Data Protocol) type is used, it is provided by the user to the GGSN (Gateway GPRS (General Packet Radio Service) Support Node) during the PPP authentication phase. If no username is available, there is a generic username configurable per APN (Access Point Name). The user password is provided by the user to the GGSN / P-GW in the PCO, or in the case of the P-GW, if PAP is used, in the APCO received during the IP-CAN session establishment procedure when multiple authentications are supported, or by the user to the GGSN during the PPP authentication phase when the PPP PDP type is used. If no password is available, there is a generic password configurable per APN. From a security perspective, the PAP and CHAP protocols each have vulnerabilities, so PAP / CHAP does not provide adequate basic protection for authentication. For example, the username and user password are transmitted in the PCO or ePCO without security.
[0088] 4 is a flowchart of initial EAP authentication with an external AAA server. Figure 4 is the same as Figure 11.1.2-1 of 3GPP TS33.501 V17.0.0, the disclosure of which is incorporated herein by reference in its entirety.
[0089] As described in step 8 of section 11.1.2 of 3GPP TS33.501 V17.0.0, the H-SMF (Home SMF) triggers EAP authentication to obtain authorization from the external DN-AAA server. If there is no existing N4 session, the H-SMF selects a UPF and establishes an N4 session with it. The H-SMF informs the DN-AAA server of the GPSI (Universal Public Subscription Identifier), if available, and the UE's IP address assigned to the PDU session if the PDU session is of IP PDU type, or the MAC (Medium Access Control) address if the PDU session is of Ethernet PDU type.
[0090] Step 9. The H-SMF sends an EAP Request / Identifier message to the UE.
[0091] Step 10. The UE shall send an EAP Response / Identifier message contained within an SM (Session Management) PDU DN Request Container in an NAS (Non-Access Stratum) message. The SM PDU DN Request Container contains its DN unique identifier conforming to the Network Access Identifier (NAI) format and a PDU Session ID (Identifier).
[0092] To avoid additional round trips in steps 9 and 10, a secondary authentication identifier may be sent by the UE in step 4.
[0093] Step 11. If there is no existing N4 session, the H-SMF selects a UPF and establishes an N4 session with it. The SM PDU DN request container, if provided by the UE, is forwarded to the UPF. The H-SMF identifies the DN AAA server based on the SM PDU DN request container provided by the UE and the local configuration.
[0094] Step 12. The UPF forwards the SM PDU DN Request Container containing the EAP Response / Identifier message to the DN AAA server.
[0095] Step 13. The DN AAA server and the UE exchange EAP messages included in the SM PDU DN Request Container according to the requirements of the EAP method. In addition, additional authorization information may be sent as defined in section 5.6.6 of 3GPP TS33.501 V17.0.0.
[0096] Step 14. Upon successful completion of the authentication procedure, the DN AAA server sends an EAP success message to the H-SMF.
[0097] Step 15. This completes the authentication procedure in the SMF. The SMF may store the DN specific ID and DNN (or the AAA server ID of the DN, if available) in a list for successful authentication / authorization between the UE and the SMF. Alternatively, the SMF may update the list in the UDM.
[0098] If authorization is successful, PDU session establishment begins at step 7a of Figure 4.3.2.2.1-1 of 3GPP TS23.502 V16.7.1, the entire disclosure of which is incorporated herein by reference.
[0099] 5a is a flowchart of a method according to one embodiment of the present disclosure, which may be performed by a device in which a session management and gateway entity is implemented, or at the session management and gateway entity, or by a device communicatively coupled to the session management and gateway entity. Thus, the device may provide means or modules for accomplishing various portions of method 500 and means or modules for accomplishing other processes together with other components. The session management and gateway entity may be any suitable network entity capable of implementing session management and gateway functions. In one embodiment, the session management and gateway entity may include a session management function (SMF+PGW-C) combined with a packet data network gateway control plane.
[0100] In block 501, a session management and gateway entity may receive a create session request from a mobile management entity, the create session request including an identifier of a terminal device. For example, during an attach request, the mobile management entity may send the create session request to the session management and gateway entity. In one embodiment, in accordance with Section 5.3.2 and Figure 5.3.2.1-1 of 3GPP TS 23.401 V16.9.0, the entire disclosure of which is incorporated herein by reference, a mobile management entity such as an MME may send the create session request to a serving gateway (SGW). The serving gateway may then send the create session request to a session management and gateway entity such as an SMF+PGW-C.
[0101] At block 502, the session management and gateway entity may determine to use a second authentication method rather than the first authentication method, the second authentication method being more secure than the first authentication method.
[0102] The second authentication method may be any suitable authentication method. In one embodiment, the second authentication method includes the Extensible Authentication Protocol (EAP). In other embodiments, the second authentication method may include an authentication method used in sixth generation (6G) or later 6G communication networks defined by 3GPP.
[0103] The first authentication method may be any suitable authentication method. In one embodiment, the first authentication method includes Password Authentication Protocol (PAP) or Challenge Handshake Authentication Protocol (CHAP).
[0104] In one embodiment, the first authentication method is used in a fourth generation (4G) network. In one embodiment, the second authentication method is used in a fifth generation (5G) network.
[0105] In one embodiment, the terminal device is accessing a fourth generation (4G) network.
[0106] In one embodiment, the create session request excludes the actual username and user password specific to the data network name. For example, the create session request may exclude the username and user password as described in section 16.4.1 of 3GPP TS29.061 V17.1.0.
[0107] The session management and gateway entity may determine to use the second authentication method rather than the first authentication method in various ways. In one embodiment, the session management and gateway entity may determine to use the second authentication method rather than the first authentication method based on at least one of an agreement with an AAA server, at least one parameter included in the session creation request, a local configuration of whether to use the second authentication method, the capabilities of the AAA server, and the capabilities of the terminal device.
[0108] For example, the agreement with the AAA server may indicate whether to use the second authentication method. In one embodiment, the agreement with the AAA server includes an agreement with the AAA server for a specific Data Network Name (DNN) or Single Network Slice Selection Assistance Information (S-NSSAI).
[0109] The local setting of whether to use the second authentication method can be configured by an operator, and the local setting of whether to use the second authentication method can be configured for a single terminal device or for a group of terminal devices.
[0110] At least one parameter included in the create session request may include PAP / CHAP user credentials. For example, the UE may not provide PAP / CHAP user credentials in an ePCO IE (information element), such as when accessing an EPS. If such information is not provided to the session management and gateway entity, the session management and gateway entity may determine to use the second authentication method instead of the first authentication method.
[0111] If the capabilities of the AAA server indicate that the AAA server supports the second authentication method, the session management and gateway entity may decide to use the second authentication method instead of the first authentication method.
[0112] If the capabilities of the terminal device indicate that the terminal device supports the second authentication method, the session management and gateway entity may determine to use the second authentication method instead of the first authentication method.
[0113] The session management and gateway entity may trigger a second authentication method procedure associated with an authentication, authorization, and accounting (AAA) server at block 503. In one embodiment, the AAA server includes a data network AAA (DN-AAA) server.
[0114] In one embodiment, the procedure for the second authentication method is triggered after the session is successfully established. For example, after the session is successfully established, the SMF+PGW-C initiates an EAP-based authentication procedure. The SMF+PGW-C may trigger a Bearer Update Request message containing the new information EAP Request / Identifier. The EAP Request / Identifier may be included in the ePCO parameter. The MME may send the EAP Request / Identifier in a NAS message (such as an EPS Bearer Context Modify Request). The UE may send the DN-specific ID to the SMF+PGW-C in an EAP message. The SMF+PGW-C may use this EAP message to trigger an Access Request message to the DN-AAA server. The DN AAA server and the UE exchange EAP messages involving the Bearer Update Request / Response procedure, as required by the EAP method, similar to EAP authentication for the 5G PDU session.
[0115] In one embodiment, if the second authentication method is the Extensible Authentication Protocol (EAP), the EAP procedure may be similar to steps 8 to 15 in FIG. 4, except that the messages and network entities may be different in different networks.
[0116] In one embodiment, during the procedure of the second authentication method, at least one Update Bearer Request and at least one Update Bearer Response including an Extended Protocol Configuration Option (ePCO) with Extensible Authentication Protocol (EAP) message exchange are used between the session management and gateway entity and the mobile management entity. The Update Bearer Request and the Update Bearer Response may be similar to the corresponding messages described in 3GPP TS23.401 V16.9.0, except that they include an Extended Protocol Configuration Option (ePCO) with Extensible Authentication Protocol (EAP) message exchange.
[0117] 5b is a flowchart of a method 510 according to another embodiment of the present disclosure, which may be performed by an apparatus in which a session management and gateway entity is implemented, or in the session management and gateway entity, or by an apparatus communicatively connected to the session management and gateway entity. Thus, the apparatus may provide means or modules for achieving various parts of the method 510 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0118] In block 511, the session management and gateway entity may send an access request including the identifier of the terminal device to the AAA server. For example, after receiving a session creation request including the identifier of the terminal device from the mobility management entity, the session management and gateway entity may send an access request including the identifier of the terminal device to the AAA server. The identifier of the terminal device may be any appropriate identifier that can uniquely identify the terminal device. For example, the identifier of the terminal device may include an IMSI (International Mobile Subscriber Identity), an MSISDN (Mobile Subscriber ISDN (Integrated Services Digital Network) Number), an IMPI (IP Multimedia Private Identifier), an IMPU (IP Multimedia Public Identifier), or an application specific identifier.
[0119] At block 512, the session management and gateway entity may receive an access-accept message including authorization data from the AAA server. For example, the authorization data may include an assigned IP address, an idle timeout, or a session timeout, etc.
[0120] In one embodiment, the access request may further include an invalid username or a locally configured username. In another embodiment, the access request may further include an indication to perform authorization only. In this case, the AAA server first performs authorization using the identifier of the terminal device. The AAA server may assign an IP address to the terminal device. The AAA server may start a timer to wait for a message of the second authentication method (e.g., an EAP message). If the message of the second authentication method (e.g., an EAP message) is not received, the AAA server may send a disconnection request to the session management and gateway entity.
[0121] 5c is a flowchart of a method 520 according to another embodiment of the present disclosure, which may be performed by an apparatus in which a session management and gateway entity is implemented, or in the session management and gateway entity, or by an apparatus communicatively connected to the session management and gateway entity. Thus, the apparatus may provide means or modules for achieving various parts of the method 520 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0122] In block 521, the session management and gateway entity may send information to the policy control function indicating that authentication related to the terminal device is pending. This information may prevent any services (such as rules from the policy control function) from being triggered. For example, after receiving an access-accept message including authorization data from the AAA server, the session management and gateway entity may send information to the policy control function indicating that authentication related to the terminal device is pending. This information may be included in any appropriate message. In one embodiment, this information may be included in an Npcf_SMPolicyCreate request message.
[0123] At block 522, the session management and gateway entity may receive default quality of service (QoS) information from the policy control function. The default quality of service (QoS) information may be included in any appropriate message. In one embodiment, the default quality of service (QoS) information may be included in an Npcf_SMPolicyCreate response message.
[0124] 5d is a flowchart of a method 530 according to another embodiment of the present disclosure, which may be performed by an apparatus in which a session management and gateway entity is implemented, or in the session management and gateway entity, or by an apparatus communicatively connected to the session management and gateway entity. Thus, the apparatus may provide means or modules for achieving various parts of the method 530 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0125] At block 531, the session management and gateway entity may receive information from the AAA server indicating that the second authentication method was successful.
[0126] At block 532, the session management and gateway entity may send information to the terminal device indicating that the second authentication method was successful.
[0127] In block 533, the session management and gateway entity may receive at least one service policy and charging control rules from the policy control function.
[0128] At block 534, the session management and gateway entity may send a message to the mobile management entity that includes information indicating that the second authentication method was successful and quality of service (QoS) information.
[0129] For example, success of the second authentication method, such as EAP success, is received by a session management and gateway entity, such as the SMF+PGW-C, from an AAA server, such as a DN-AAA server. The SMF+PGW-C sends an Npcf_SMFPolicyUpdate request message including information indicating that the authentication was successful to the PCF, and obtains a service rule from the PCF. The SMF+PGW-C sends a bearer update request message, including the EAP success message and other QoS information, to the MME.
[0130] 5e is a flowchart of a method 540 according to another embodiment of the present disclosure, which may be performed by an apparatus in which a session management and gateway entity is implemented, or in the session management and gateway entity, or by an apparatus communicatively connected to the session management and gateway entity. Thus, the apparatus may provide means or modules for achieving various parts of the method 540 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0131] In block 541, the session management and gateway entity may determine that the second authentication method has failed. For example, the session management and gateway entity may determine that the second authentication method has failed based at least on receiving information from an AAA server indicating that the second authentication method has failed or the bearer update response from the mobility management entity has failed or timed out.
[0132] At block 542, the session management and gateway entity may trigger a session deletion procedure.
[0133] 5f is a flowchart of a method 550 according to another embodiment of the present disclosure, which may be performed in an apparatus in which a mobile management entity is implemented, in the mobile management entity, or by an apparatus communicatively connected to the mobile management entity. Thus, the apparatus may provide means or modules for achieving various parts of the method 550 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0134] The mobile management entity may receive an attach request from a terminal device in block 551. In one embodiment, the attach request excludes the actual username and user password specific to the data network name.
[0135] In block 552, the mobile management entity may send a session creation request including the identifier of the terminal device to the session management and gateway entity, where a procedure of a second authentication method is triggered by the session management and gateway entity instead of a procedure of the first authentication method, and the second authentication method has higher security than the first authentication method.
[0136] 5g is a flowchart of a method 560 according to another embodiment of the present disclosure, which may be performed in an apparatus in which a mobile management entity is implemented, in the mobile management entity, or by an apparatus communicatively connected to the mobile management entity. Thus, the apparatus may provide means or modules for achieving various parts of the method 560 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0137] In block 561, the mobile management entity may receive a message from the session management and gateway entity that includes information indicating that the second authentication method was successful and quality of service (QoS) information.
[0138] In block 562, the mobile management entity may send a message to the terminal device including information indicating that the second authentication method was successful.
[0139] In one embodiment, during the procedure of the second authentication method, at least one Evolved Packet System (EPS) Bearer Context Modification Request including an Extended Protocol Configuration Option (ePCO) accompanied by an Extensible Authentication Protocol (EAP) message and at least one EPS Bearer Context Modification Accept are used between the terminal device and the mobile management entity.
[0140] 5g is a flowchart of a method 600 according to another embodiment of the present disclosure, which may be performed by an apparatus in which a terminal device is implemented, in the terminal device, or by an apparatus communicatively connected to the terminal device. Thus, the apparatus may provide means or modules for achieving various parts of the method 600 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0141] In block 601, the terminal device may send an attach request to a mobile management entity. The procedure of the second authentication method is triggered by the session management and gateway entity, instead of the procedure of the first authentication method. The second authentication method has higher security than the first authentication method.
[0142] At block 602, the terminal device may receive a message from a mobile management entity that includes information indicating that the second authentication method was successful.
[0143] 6b shows a flowchart of a method 610 according to another embodiment of the present disclosure, where the method 6100 may be performed in an apparatus implementing a policy control function, in the policy control function, or by an apparatus communicatively connected to the policy control function. Thus, the apparatus may provide means or modules for achieving various parts of the method 610 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here. In one embodiment, the policy control function may be a PCF as described in 3GPP TS23.501 V16.7.0.
[0144] In block 611, the policy control function may receive information from the session management and gateway entity indicating that an authentication associated with the terminal device is pending.
[0145] In block 612, the policy control function may send default quality of service (QoS) information to the session management and gateway entity. The procedure of the second authentication method is triggered by the session management and gateway entity instead of the procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0146] 6c shows a flowchart of a method 620 according to another embodiment of the present disclosure, which may be performed in an apparatus implementing a policy control function, in the policy control function, or by an apparatus communicatively connected to the policy control function. Thus, the apparatus may provide means or modules for achieving various parts of the method 620 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here. In one embodiment, the policy control function may be a PCF as described in 3GPP TS23.501 V16.7.0.
[0147] In block 621, the policy control function may receive information from the session management and gateway entity indicating that the second authentication method was successful.
[0148] In block 622, the policy control function may send at least one of the service policy and charging control rules to the session management and gateway entity.
[0149] 6d is a flowchart of a method 630 according to another embodiment of the present disclosure, which may be performed by an apparatus in which an AAA server is implemented, or in the AAA server, or by an apparatus communicatively connected to the AAA server. Thus, the apparatus may provide means or modules for achieving various parts of the method 630 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here. In one embodiment, the AAA server may be DN-AAA as described in 3GPP TS23.502 V16.7.1.
[0150] In block 631, the AAA server may receive an access request from a session management and gateway entity that includes an identifier of the terminal device.
[0151] In block 632, the AAA server may send an access-accept message including the authorization data to the session management and gateway entity. The procedure of the second authentication method is triggered by the session management and gateway entity instead of the procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0152] Optionally, in block 633, after the second authentication method procedure is successfully completed, the AAA server may send information indicating that the second authentication method was successful to the session management and gateway entity.
[0153] 6e is a flowchart of a method 640 according to another embodiment of the present disclosure, which may be performed by an apparatus in which an AAA server is implemented, or in the AAA server, or by an apparatus communicatively connected to the AAA server. Thus, the apparatus may provide means or modules for achieving various parts of the method 640 and means or modules for achieving other processes together with other components. For the sake of brevity, detailed descriptions of some parts described in the above embodiments will be omitted here.
[0154] In block 641, the AAA server may determine that the second authentication method procedure has not been initiated after a certain period of time, which may be any suitable period that may be set by the network operator.
[0155] At block 642, the AAA server may send a disconnect request to the session management and gateway entity.
[0156] FIG. 6f is a flowchart of a method according to another embodiment of the present disclosure.
[0157] Step 1. The UE sends an attach request to the MME and SGW.
[0158] Step 2. The MME sends a create session request including the UE identifier (such as IMSI or MSISDN) to the SMF+PGW-C.
[0159] Step 3. The SMF can determine whether EAP-based authentication is required, for example, based on an agreement with the DN-AAA server for a specific DNN / S-NSSAI or a local configuration for whether to trigger EAP-based authentication. Therefore, the SMF+PGW-C can send an Access-Request message including the UE identifier (such as the MSISDN) to the DN-AAA server to obtain authentication data (such as assigned IP address, idle timeout, session timeout, etc.) from the DN-AAA server in an Access-Accept message. The Access-Request message may further include an invalid username or a locally configured username.
[0160] Step 4. The DN-AAA server first performs authentication using the UE identifier. The DN-AAA server may assign an IP address to the UE. The DN-AAA server may start a timer to wait for an EAP message. If no EAP message is received after the time has elapsed, the DN-AAA server may trigger a disconnect request.
[0161] Step 5. If the PCF is enabled, to avoid any service triggering (such as rules from the PCF), the SMF+PGW-C sends an indication that authorization is pending in the Npcf_SMPolicyCreate request message.
[0162] Step 6. A packet forwarding control plane (PFCP) association is established between the SMF+PGW-C and the UPF.
[0163] Steps 7 to 10: The SMF+PGW-C continues the session creation procedure and the session is set up successfully according to the current standard. Step 7: The SMF+PGW-C sends a session creation response to the MME&SGW. Step 8: The MME&SGW sends a DL (downlink) NAS (attach accept) to the UE. Step 9: The UE sends a UL (uplink) NAS (attach complete) to the MME&SGW. Step 10: The MME&SGW sends a bearer modification request to the SMF+PGW-C.
[0164] Step 11. After the session is successfully established, the SMF+PGW-C initiates the EAP-based authentication procedure. The SMF+PGW-C triggers a Bearer Update Request message containing the new information EAP Request / Identifier, which may be included in the ePCO parameter.
[0165] Step 12. The MME sends an EAP message, such as an EPS Bearer Context Modify Request, to the UE in a DL NAS message. The UE sends a DN-specific identifier to the MME in an EAP message, such as an EPS Bearer Context Modify Response.
[0166] Step 13. The MME sends an Update Bearer Response (ePCO: EAP Response / Identifier) to the SMF+PGW-C. If the Update Bearer Response fails or times out, the SMF triggers session deletion.
[0167] Step 14. The SMF+PGW-C sends an access request (EAP message) to the DN-AAA server.
[0168] Steps 15 to 22. The DNAAA server and the UE exchange EAP messages according to the requirements of the EAP method, and steps 15 to 22 are similar to the corresponding steps of EAP authentication for a 5G PDU session, but involve a bearer update request / response procedure.
[0169] In step 15, the DN-AAA server sends an access challenge (EAP message) to the SMF+PGW-C.
[0170] In step 16, the SMF+PGW-C sends an Update Bearer Request including an Extended Protocol Configuration Option (ePCO) accompanied by an Extensible Authentication Protocol (EAP) message to the MME.
[0171] In step 17, the MME sends a DL NAS message, such as an Evolved Packet System (EPS) Bearer Context Modify Request, including an Extended Protocol Configuration Option (ePCO) with an Extensible Authentication Protocol (EAP) message, to the UE. The UE sends a UL NAS message, such as an EPS Bearer Context Modify Accept, including an Extended Protocol Configuration Option (ePCO) with an Extensible Authentication Protocol (EAP) message, to the MME.
[0172] In step 18, the MME sends an Update Bearer Response including an Extended Protocol Configuration Option (ePCO) accompanied by an Extensible Authentication Protocol (EAP) message to the SMF+PGW-C.
[0173] In step 19, the SMF+PGW-C sends an access request (EAP message) to the DN-AAA server.
[0174] Step 20. The SMF+PGW-C receives EAP success from the DN-AAA server. If an access reject is received from the DN-AAA server, the SMF may trigger session deletion.
[0175] Step 21. When the SMF+PGW-C receives EAP success from the DN-AAA server, the SMF+PGW-C sends a bearer update request (EAP success message and other QoS information) to the MME.
[0176] Step 22. The MME sends a DL NAS message, such as an EPS Bearer Context Modify Request (ePCO with EAP message), to the UE. The UE sends a UL NAS message, such as an EPS Bearer Context Change Accept (ePCO with EAP message), to the MME.
[0177] Step 23. The MME sends an update bearer response (success) to the SMF+PGW-C.
[0178] Step 24. If the SMF+PGW-C receives EAP success from the DN-AAA server, the SMF+PGW-C sends an Npcf_SMFPolicyUpdate request message containing information indicating that the authentication was successful and notifying the PCF that the service rule can be obtained from the PCF.
[0179] 7 is a block diagram illustrating an apparatus suitable for implementing some embodiments of the present disclosure. For example, any one of the session management and gateway entity, the mobile management entity, the terminal device, the policy control function, and the AAA server described above may be implemented as or through the apparatus 700.
[0180] The apparatus 700 comprises at least one processor 721, such as a digital processor (DP), and at least one memory (MEM) 722 coupled to the processor 721. The apparatus 720 may further comprise a transmitter TX and a receiver RX 723 coupled to the processor 721. The MEM 722 stores a program (PROG) 724. The PROG 724 may include instructions that, when executed by an associated processor 721, enable the apparatus 720 to operate in accordance with embodiments of the present disclosure. The combination of the at least one processor 721 and the at least one MEM 722 may form a processing means 725 adapted to perform various embodiments of the present disclosure.
[0181] Various embodiments of the present disclosure may be implemented by computer programs executable by one or more of the processor 721, software, firmware, hardware, or combinations thereof.
[0182] MEM722 may be of any type suitable for the local technology environment and may be implemented using any suitable data storage technology, such as, by way of non-limiting example, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed and removable memory, etc.
[0183] The processor 721 may be of any type suitable for the local technology environment and may include, by way of non-limiting example, one or more of a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture.
[0184] In embodiments in which the apparatus is implemented as or with a session management and gateway entity, memory 722 includes instructions executable by processor 721 to cause the session management and gateway entity to operate according to any of the methods associated with the session management and gateway entities described above.
[0185] In embodiments in which the apparatus is implemented as or in a mobile management entity, memory 722 includes instructions executable by processor 721 to cause the mobile management entity to operate according to any of the methods associated with the mobile management entity described above.
[0186] In an embodiment in which the apparatus is implemented as or in a terminal device, memory 722 includes instructions executable by processor 721 to cause the terminal device to operate according to any of the methods associated with the terminal device described above.
[0187] In embodiments in which the device is implemented as or with a policy control function, memory 722 includes instructions executable by processor 721 to cause the policy control function to operate according to any of the methods associated with policy control functions described above.
[0188] In embodiments in which the device is implemented as or in an AAA server, memory 722 includes instructions executable by processor 721 to cause the AAA server to operate according to any of the methods associated with the AAA server described above.
[0189] 8a is a block diagram illustrating a session management and gateway entity according to one embodiment of the present disclosure. As shown, the session management and gateway entity 800 includes a first receiving module 801, a first determining module 802, and a first triggering module 803. The first receiving module 801 may be configured to receive a session creation request including an identifier of a terminal device from a mobile management entity. The first determining module 802 may be configured to determine to use a second authentication method having higher security than the first authentication method rather than the first authentication method. The first triggering module 803 may be configured to trigger a procedure of the second authentication method associated with an authentication, authorization, and accounting (AAA) server.
[0190] In one embodiment, the session management and gateway entity 800 may further comprise a first sending module 804 configured to send an access request including an identifier of the terminal device.
[0191] In one embodiment, the session management and gateway entity 800 may further comprise a second receiving module 805 configured to receive an access accept message including authorization data from the AAA server.
[0192] In one embodiment, the session management and gateway entity 800 may further comprise a second sending module 806 configured to send information indicating that an authentication associated with the terminal device is pending to the policy control function.
[0193] In one embodiment, the session management and gateway entity 800 may further comprise a third receiving module 807 configured to receive default quality of service (QoS) information from the policy control function.
[0194] In one embodiment, the session management and gateway entity 800 may further comprise a fourth receiving module 808 configured to receive information from the AAA server indicating that the second authentication method was successful.
[0195] In one embodiment, the session management and gateway entity 800 may further comprise a third sending module 809 configured to send information indicating that the second authentication method was successful to the policy control function.
[0196] In one embodiment, the session management and gateway entity 800 may further comprise a fifth receiving module 810 configured to receive at least one service policy and charging control rule from the policy control function.
[0197] In one embodiment, the session management and gateway entity 800 may further comprise a fourth sending module 811 configured to send a message to the mobile management entity including information indicating that the second authentication method was successful and quality of service (QoS) information.
[0198] In one embodiment, the session management and gateway entity 800 further comprises a second determination module 812 configured to determine that the second authentication method has failed.
[0199] In one embodiment, the session management and gateway entity 800 may further comprise a second trigger module 813 configured to trigger a session deletion procedure.
[0200] 8b is a block diagram illustrating a mobile management entity according to one embodiment of the present disclosure. As illustrated, the mobile management entity 820 includes a first receiving module 821 and a first sending module 822. The first receiving module 821 may be configured to receive an attach request from a terminal device. The first sending module 822 may be configured to send a session creation request including an identifier of the terminal device to the session management and gateway entity. The procedure of the second authentication method is triggered by the session management and gateway entity, rather than the procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0201] In one embodiment, the mobile management entity 820 may further comprise a second receiving module 823 configured to receive a message from the session management and gateway entity including information indicating that the second authentication method was successful and quality of service (QoS) information.
[0202] In one embodiment, the mobile management entity 820 may further comprise a second sending module 824 configured to send a message to the terminal device including information indicating that the second authentication method was successful.
[0203] 8c is a block diagram illustrating a terminal device according to one embodiment of the present disclosure. As illustrated, the terminal device 830 includes a sending module 831. The sending module 831 may be configured to send an attach request to a mobility management entity. The procedure of the second authentication method is triggered by the session management and gateway entity, rather than the procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0204] In one embodiment, the terminal device 830 may further comprise a receiving module 832 configured to receive a message from the mobile management entity including information indicating that the second authentication method was successful.
[0205] 8d is a block diagram illustrating a policy control function according to one embodiment of the present disclosure. As illustrated, the policy control function 840 includes a first receiving module 841 and a first transmitting module 842. The first receiving module 841 may be configured to receive an attach request from a terminal device. The first transmitting module 842 may be configured to transmit default quality of service (QoS) information to the session management and gateway entity. The second authentication method procedure is triggered by the session management and gateway entity instead of the first authentication method procedure. The second authentication method is more secure than the first authentication method.
[0206] In one embodiment, the policy control function 840 may further comprise a second receiving module 843 configured to receive information from the session management and gateway entity indicating that the second authentication method was successful.
[0207] In one embodiment, the policy control function 840 may further comprise a second sending module 844 configured to send at least one of the service policy and charging control rules to the session management and gateway entity.
[0208] 8e is a block diagram illustrating an AAA server according to one embodiment of the present disclosure. As illustrated, the AAA server 850 includes a first receiving module 851 and a first sending module 852. The first receiving module 851 may be configured to receive an access request including an identifier of a terminal device from a session management and gateway entity. The first sending module 852 may be configured to send an access accept message including authorization data to the session management and gateway entity. The procedure of the second authentication method is triggered by the session management and gateway entity, rather than the procedure of the first authentication method. The second authentication method is more secure than the first authentication method.
[0209] In one embodiment, the AAA server 850 may further comprise a determining module 853 configured to determine that the procedure of the second authentication method is not initiated after a certain period of time.
[0210] In one embodiment, the AAA server 850 may further comprise a second sending module 854 configured to send a disconnect request to the session management and gateway entity.
[0211] Embodiments herein may provide many advantages, a non-exhaustive list of examples of which is provided below: In some embodiments herein, security issues may be resolved for a UE that initially connects to an EPS. In some embodiments herein, security issues may be resolved for a UE that initially connects to an EPS and moves to 5GS during the session lifetime. In some embodiments herein, a gateway entity, such as a session management and SMF, may obtain 5GS attributes from a DN-AAA server as soon as the UE moves to 5GS. In some embodiments herein, the DN-AAA server may have the correct information when triggering re-authentication. Embodiments herein are not limited to the preferred features and advantages described above. Those skilled in the art will recognize additional features and advantages upon reading the following detailed description.
[0212] The term unit has its conventional meaning in the fields of electricity, electrical devices, and / or electronic devices and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logical solid state and / or discrete devices, computer programs or instructions described herein for performing respective tasks, procedures, calculations, output, and / or display functions, etc.
[0213] By using the functional units, the session management and gateway entity, the mobile management entity, the terminal device, the policy control function, and the AAA server do not require a fixed processor or memory, and any computing resource and storage resource can be arranged as the session management and gateway entity, the mobile management entity, the terminal device, the policy control function, and the AAA server in the communication system. The introduction of virtualization technology and network computing technology can improve the utilization efficiency of network resources and the flexibility of the network.
[0214] According to one aspect of the present disclosure, there is provided a computer program product comprising instructions tangibly stored on a computer-readable storage medium and that, when executed on at least one processor, cause the at least one processor to perform any of the methods set forth above.
[0215] According to one aspect of the present disclosure, there is provided a computer-readable storage medium storing instructions that, when executed by at least one processor, cause the at least one processor to perform any of the methods set forth above.
[0216] The present disclosure further provides a carrier containing the above-mentioned computer program, the carrier being one of an electrical signal, an optical signal, a radio signal, or a computer-readable storage medium, which may be, for example, an electronic memory device such as an optical compact disc, a RAM (random access memory), a ROM (read-only memory), a flash memory, a magnetic tape, a CD-ROM, a DVD, a Blu-ray disc, etc.
[0217] The techniques described herein may be implemented by various means, and an apparatus implementing one or more functions of a corresponding apparatus described in the embodiments may have not only conventional means but also means for implementing one or more functions of the corresponding apparatus described in the embodiments, which may include separate means for each separate function, or means that can be configured to perform one or more functions. For example, these techniques may be implemented in hardware (one or more devices), firmware (one or more devices), software (one or more modules), or a combination thereof. In the case of firmware or software, implementation may be by modules (e.g., procedures, functions, etc.) that perform the functions described herein.
[0218] The exemplary embodiments herein have been described above with reference to block diagrams and flowcharts of methods and apparatuses. It will be understood that each block of the block diagrams and flowchart diagrams, and combinations of blocks in each of the block diagrams and flowchart diagrams, can be implemented by various means, including computer program instructions. These computer program instructions can be loaded into a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce machine-generated instructions that execute on the computer or other programmable data processing apparatus to create means for implementing the function specified in the flowchart block or block.
[0219] Additionally, although acts are described in a particular order, there is no requirement that they be performed in the particular order shown or in sequential order, as all described acts may be performed to achieve desirable results. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although the above description includes some specific implementation details, these do not limit the scope of the disclosure, and description of features may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable subcombination.
[0220] While this specification contains many specific implementation details, these should not be construed as limitations on the scope of the implementation or claimed subject matter, but rather as descriptions of functionality specific to particular embodiments of a particular implementation. Certain features described in this specification in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented in multiple embodiments individually or in any suitable subcombination. Furthermore, while features may be described above as working in a particular combination, and may even initially be claimed as such, one or more features from a claimed combination may, in some cases, be deleted from that combination, and the claimed combination may be directed to subcombinations or variations of the subcombination.
[0221] It will be obvious to those skilled in the art that, as technology advances, the concept of the present invention can be implemented in various ways. The above-described embodiments are given to illustrate, not to limit, the present disclosure, and it should be understood that modifications and variations can be resorted to without departing from the spirit and scope of the present disclosure, as easily understood by those skilled in the art. Such modifications and variations are deemed to be within the scope of the present disclosure and the appended claims. The scope of protection of the present disclosure is defined by the appended claims.
Claims
1. 1. A method performed by a session management and gateway entity, comprising: receiving a session creation request from a mobile management entity, the session creation request including an identifier of the terminal device; determining to use a second authentication method having higher security than the first authentication method; triggering a procedure of the second authentication method associated with an Authentication, Authorization and Accounting (AAA) server, the procedure of the second authentication method being triggered after the session has been successfully established; and Including, The method, wherein determining to use the second authentication method rather than the first authentication method is based on at least one of an agreement with the AAA server, at least one parameter included in the session creation request, a local setting of whether to use the second authentication method, capabilities of the AAA server, and capabilities of the terminal device.
2. 10. The method of claim 1 further comprising: sending an access request to the AAA server, the access request including the identifier of the terminal device; receiving an access-accept message from the AAA server including authorization data; A method comprising:
3. 3. The method of claim 2, The method, wherein the access request further includes an invalid username or a locally configured username.
4. 4. The method of any one of claims 1 to 3, further comprising: sending information to a policy control function indicating that authentication associated with said terminal device is pending; receiving default Quality of Service (QoS) information from the Policy Control Function; A method comprising:
5. 5. The method of any one of claims 1 to 4, further comprising: receiving information from the AAA server indicating that the second authentication method was successful; sending information indicating that the second authentication method was successful to a policy control function; receiving at least one service policy and charging control rules from the policy control function; A method comprising:
6. 6. The method of claim 5, further comprising: sending a message to the mobile management entity, the message including information indicating that the second authentication method was successful and quality of service (QoS) information.
7. 7. The method of any one of claims 1 to 6, During the procedure of the second authentication method, at least one Bearer Update Request and at least one Bearer Update Response including an Extended Protocol Configuration Option (ePCO) with Extensible Authentication Protocol (EAP) message exchange are used between the session management and gateway entity and the mobility management entity.
8. 8. The method of any one of claims 1 to 7, further comprising: determining that the second authentication method has failed; triggering a session deletion procedure; A method comprising:
9. 9. The method of claim 8, Determining that the second authentication method has failed includes: receiving information from the AAA server indicating that the second authentication method failed; an update bearer response from the mobile management entity fails or times out.
10. 10. The method of any one of claims 1 to 9, The method, wherein the second authentication method includes the Extensible Authentication Protocol (EAP).
11. 11. The method of any one of claims 1 to 10, The method, wherein the first authentication method includes a Password Authentication Protocol (PAP) or a Challenge Handshake Authentication Protocol (CHAP).
12. 12. The method of any one of claims 1 to 11, The method, wherein the agreement with the AAA server includes agreement with the AAA server on a specific data network name (DNN) or single network slice selection assistance information (S-NSSAI).
13. 13. The method of any one of claims 1 to 12, The method, wherein the session management and gateway entity comprises a session management function combined with a packet data network gateway control plane (SMF+PGW-C).
14. 14. The method of any one of claims 1 to 13, The AAA server comprises a Data Network AAA (DN-AAA) server.
15. 15. The method of any one of claims 1 to 14, The method, wherein the terminal device is accessing a fourth generation (4G) network.
16. 16. The method of any one of claims 1 to 15, The method, wherein the session creation request does not include an actual username and a user password specific to a data network name.
17. a session management and gateway entity, a processor; a memory coupled to the processor; Equipped with the memory includes instructions executable by the processor; The session management and gateway entity: receiving a session creation request from a mobile management entity, the session creation request including an identifier of the terminal device; determining to use a second authentication method having higher security than the first authentication method; triggering a procedure of the second authentication method associated with an Authentication, Authorization and Accounting (AAA) server, the procedure of the second authentication method being triggered after the session has been successfully established; and It operates as follows: A session management and gateway entity, wherein the determination to use the second authentication method rather than the first authentication method is based on at least one of an agreement with the AAA server, at least one parameter included in the session creation request, a local configuration of whether to use the second authentication method, the capabilities of the AAA server, and the capabilities of the terminal device.
18. 18. A session management and gateway entity according to claim 17, comprising:
17. A session management and gateway entity, the session management and gateway entity further operative to perform a method according to any one of claims 2 to 16.
19. A computer readable storage medium storing instructions that, when executed on at least one processor, cause the at least one processor to perform the method of any one of claims 1 to 16.
Citation Information
Patent Citations
Equipment, systems, and methods for performing external authentication using EAP (Effective Access Program).
JP2014532381A
Next-generation system certification
JP2019533951A
Network security management method, and apparatus
US20200153871A1
Core network device, communication terminal, communication system, authentication method, and communication method
WO2020067112A1