Determining Authentication Information for Inter-Device Services

JP7902358B2Active Publication Date: 2026-08-07NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2022-11-01
Publication Date
2026-08-07

Smart Images

  • Figure 0007902358000005
    Figure 0007902358000005
  • Figure 0007902358000006
    Figure 0007902358000006
  • Figure 0007902358000007
    Figure 0007902358000007
Patent Text Reader

Abstract

An apparatus for a network node is provided, comprising: means for receiving notification of a serving network name of a first user equipment; a first user equipment configured to act as a relay between the second user equipment and a network by providing proximity services between the first user equipment and the second user equipment; means for determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment; and means for providing notification of the serving network name of the first user equipment to the second user equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to a method, an apparatus, a computer program, and a system for determining authentication information for services between devices, and in particular, is not limited to determining an authentication vector based on a serving network name (SNN) for use in proximity services (ProSe).

Background Art

[0002] A communication system can be regarded as a facility that enables a communication session between two or more entities such as user terminals, base stations, and / or other nodes by providing a carrier between various entities involved in the communication path. A communication system can be provided, for example, by a communication network and one or more compatible communication devices. A communication session may include, for example, the communication of data for transmitting communications such as voice, video, email (E-mail), text messages, multimedia, and / or content data. Non-limiting examples of the services provided include two-way or multi-way calls, data communication or multimedia services, and access to a data network system such as the Internet.

[0003] In a wireless communication system, at least a part of a communication session between at least two stations is performed via a wireless link. Examples of wireless systems include various wireless local networks such as a public land mobile network (PLMN), a satellite-based communication system, and a wireless local area network (WLAN). Some wireless systems can be divided into cells and are sometimes called cellular systems.

[0004] Users can access the communication system through appropriate communication equipment or terminals. A user's communication equipment is sometimes called user equipment (UE) or user device. Communication equipment includes appropriate signal transceivers to enable communication, such as enabling access to a communication network or direct communication with other users. Communication devices can access carriers provided by base stations, such as cell base stations, and transmit and / or receive communications over the carrier.

[0005] Communication systems and related devices typically operate according to predetermined standards or specifications that define what various entities associated with the system are permitted to do and how they should do so. The communication protocols and / or parameters used for connection are also typically defined. One example of a communication system is UTRAN (3G radio). Other examples of communication systems include the Long-Term Evolution (LTE) of Universal Mobile Communications System (UMTS) radio access technology, and so-called 5G or New Radio (NR) networks. NR is standardized by the Third Generation Partnership Project (3GPP®). [Overview of the Initiative]

[0006] In a first embodiment, a device for a network node is provided, comprising: means for receiving notification of a serving network name of a first user device, wherein the first user device is configured to act as a relay between the second user device and the network by providing proximity services between the first user device and the second user device; means for determining an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device; and means for providing notification of the serving network name of the first user device to the second user device.

[0007] This device further includes means for providing authentication information to a second user device, the authentication information including notification of the serving network name of the first user device.

[0008] This device may further provide means for providing authentication information in at least one of the following: a proximity service authentication response, a proximity service authentication request, or an extended authentication protocol message.

[0009] The device may further provide means for receiving the serving network name of the first user device via at least one of the access and mobility management functions associated with the first user device, or the authentication server function associated with the second user device.

[0010] Network nodes can implement unified data management.

[0011] This device may include a network node, be a network node, or be contained within a network node.

[0012] In a second aspect, an apparatus is provided for a first user device, comprising means for receiving notification of a serving network name of a second user device, the second user device being configured to act as a relay between the first user device and the network by providing proximity services between the first user device and the second user device, and means for determining an authentication vector for proximity service authentication of the first user device based on the serving network name of the second user device.

[0013] This device further includes means for receiving authentication information on the first user device, and the authentication information may include notification of the serving network name of the second user device.

[0014] This device may further include means for receiving authentication information within extended authentication protocol messages.

[0015] This device may further include, be, or be included in the first user equipment.

[0016] In a third aspect, a device for a network node is provided, comprising means for obtaining the serving network name of a first user device, and means for determining an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to operate as a relay between the first user device and the network.

[0017] The device further comprises means for providing an extended authentication protocol message to a first user device, the extended authentication protocol challenge message may include the serving network name of the first user device.

[0018] The serving network name of the first user device may be stored in the universal subscriber identification module of the first user device.

[0019] This device may further provide means for obtaining the serving network name of the first user device by obtaining the serving network name of the first user device from a storage function.

[0020] Network nodes may implement unified data management.

[0021] This device includes a network node, is a network node, or may be included in a network node.

[0022] In a fourth aspect, an apparatus is provided for a first user device, comprising means for obtaining the serving network name of the first user device, and means for determining an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to operate as a relay between the first user device and the network.

[0023] The apparatus further comprises means for receiving authentication information, the authentication information including the serving network name of the first user equipment.

[0024] The apparatus may further comprise means for receiving authentication information in an Extensible Authentication Protocol message.

[0025] The apparatus may further comprise means for obtaining the serving network name of the first user equipment by obtaining it from a Universal Subscriber Identity Module associated with the first user equipment.

[0026] The apparatus may comprise the first user equipment, be the first user equipment, or be included in the first user equipment.

[0027] In a fifth aspect, there is provided a method in a network node for receiving a notification of the serving network name of a first user equipment, the first user equipment being configured to operate as a relay between a second user equipment and a network by providing a proximity service between the first user equipment and the second user equipment, the method including receiving, determining an authentication vector for proximity service authentication of the second user equipment based on the serving network name of the first user equipment, and notifying the second user equipment of the serving network name of the first user equipment.

[0028] The method further includes providing authentication information to the second user equipment, the authentication information including a notification of the serving network name of the first user equipment.

[0029] The method may further include providing the authentication information in at least one of a proximity service authentication response, a proximity service authentication request, or an Extensible Authentication Protocol message.

[0030] The method may further include receiving a serving network name of the first user equipment via at least one of an access and mobility management function associated with the first user equipment or an authentication server function associated with the second user equipment.

[0031] In a sixth aspect, in the first user equipment, receiving a notification of a serving network name of the second user equipment, wherein the second user equipment is configured to operate as a relay between the first user equipment and the network by providing a proximity service between the first user equipment and the second user equipment, and determining an authentication vector for proximity service authentication of the first user equipment based on the serving network name of the second user equipment. A method is provided that includes the above.

[0032] The method may further include receiving authentication information at the first user equipment, where the authentication information includes a notification of the serving network name of the second user equipment.

[0033] The method may further include receiving authentication information within an Extensible Authentication Protocol message.

[0034] In a seventh aspect, in a network node, obtaining a serving network name of the first user equipment, and determining an authentication vector for proximity service authentication of the first user equipment for proximity service between the first user equipment and a second user equipment configured to operate as a relay between the first user equipment and the network, based on the serving network name of the first user equipment. A method is provided that includes the above.

[0035] The method may further include providing an Extensible Authentication Protocol message to the first user equipment, where the Extensible Authentication Protocol challenge message includes the serving network name of the first user equipment.

[0036] The serving network name of the first user device may be stored in the universal subscriber identification module of the first user device.

[0037] This method may further include obtaining the serving network name of the first user device by obtaining the serving network name of the first user device from the storage function.

[0038] An eighth aspect provides a method in which a first user device obtains the serving network name of the first user device and determines an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to operate as a relay between the first user device and the network.

[0039] This method further includes obtaining authentication information, which includes the serving network name of the first user device.

[0040] This method may further include receiving authentication information within an extended authentication protocol message.

[0041] This method may further include obtaining the serving network name of the first user device by obtaining it from the universal subscriber identification module associated with the first user device.

[0042] In a ninth aspect, a device for a network node is provided, comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device to perform at least: receive notification of the serving network name of a first user device, the first user device being configured to act as a relay between the second user device and the network by providing proximity services between the first user device and the second user device; determine an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device; and notify the second user device of the serving network name of the first user device.

[0043] This device can further provide authentication information to a second user device, and the authentication information may include notification of the serving network name of the first user device.

[0044] The device may further provide authentication information in at least one of the following: a proximity service authentication response, a proximity service authentication request, or an extended authentication protocol message.

[0045] The device may also be configured to receive the serving network name of the first user device via at least one of the access and mobility management functions associated with the first user device, or the authentication server function associated with the second user device.

[0046] Network nodes may implement unified data management.

[0047] This device may include a network node, be a network node, or be contained within a network node.

[0048] In a tenth aspect, a device is provided for a first user device, comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device to perform at least: receive notification of the serving network name of a second user device, the second user device being configured to act as a relay between the first user device and the network by providing proximity services between the first user device and the second user device; and determine an authentication vector for proximity service authentication of the first user device based on the serving network name of the second user device.

[0049] This device may be configured to receive authentication information on the first user device, and the authentication information may include notification of the serving network name of the second user device.

[0050] The device may also be configured to receive authentication information within extended authentication protocol messages.

[0051] This device may further include, be, or be included in the first user equipment.

[0052] In an eleventh aspect, a device for a network node is provided, comprising at least one processor and at least one memory for storing instructions that, when executed by the at least one processor, cause the device to perform at least: obtain the serving network name of a first user device; and determine an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to operate as a relay between the first user device and the network.

[0053] This device can further cause the first user device to provide an extended authentication protocol message, and the extended authentication protocol challenge message may include the serving network name of the first user device.

[0054] The serving network name of the first user device can be stored in the universal subscriber identification module of the first user device.

[0055] This device may further obtain the serving network name of the first user device by retrieving the serving network name of the first user device from its storage function.

[0056] Network nodes can implement unified data management.

[0057] This device includes a network node, is a network node, or may be included in a network node.

[0058] In a twelfth aspect, a device for a first user device is provided, comprising at least one processor and at least one memory for storing instructions that, when executed by the at least one processor, cause the device to perform at least: obtain the serving network name of the first user device; and determine an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to operate as a relay between the first user device and the network.

[0059] The device may also be configured to receive authentication information, which may include the serving network name of the first user device.

[0060] The device may also be configured to receive authentication information within extended authentication protocol messages.

[0061] The device may further obtain the serving network name of the first user device by obtaining the serving network name from the universal subscriber identification module associated with the first user device.

[0062] This device may include, be, or be included in the first user equipment.

[0063] In a thirteenth embodiment, the device is provided with a computer-readable medium containing instructions that, when executed by the device, cause the device to receive notification of the serving network name of a first user device at a network node, the first user device being configured to act as a relay between the second user device and the network by providing proximity services between the first user device and the second user device, determine an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device, and notify the second user device of the serving network name of the first user device.

[0064] The device can also be configured to provide authentication information to a second user device, and this authentication information may include notification of the serving network name of the first user device.

[0065] The device can further be configured to provide authentication information in at least one of the following: a proximity service authentication response, a proximity service authentication request, or an extended authentication protocol message.

[0066] The device can also be configured to receive the serving network name of the first user device via at least one of the access and mobility management functions associated with the first user device, or the authentication server function associated with the second user device.

[0067] Network nodes can implement unified data management.

[0068] This device includes a network node, is a network node, or may be included in a network node.

[0069] In a fourteenth aspect, a computer-readable medium is provided which, when executed by the device, causes the device to perform at least the following actions: receive notification of the serving network name of a second user device in a first user device, the second user device being configured to act as a relay between the first user device and the network by providing proximity services between the first user device and the second user device; and determine an authentication vector for proximity service authentication of the first user device based on the serving network name of the second user device.

[0070] This device can further cause the first user device to receive authentication information, and the authentication information may include notification of the serving network name of the second user device.

[0071] The device may also be configured to receive authentication information within extended authentication protocol messages.

[0072] This device may further include, be, or be included in the first user equipment.

[0073] In the 15th aspect, the device is provided with a computer-readable medium that, when executed by the device, causes the device to perform at least the following actions: obtain the serving network name of a first user device at a network node; and determine an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to act as a relay between the first user device and the network.

[0074] The device can also be configured to provide an extended authentication protocol message to the first user device, and the extended authentication protocol challenge message may include the serving network name of the first user device.

[0075] The serving network name of the first user device can be stored in the universal subscriber identification module of the first user device.

[0076] This device can further retrieve the serving network name of the first user device by obtaining it from its storage function.

[0077] Network nodes can implement unified data management.

[0078] This device includes a network node, is a network node, or may be included in a network node.

[0079] In a sixteenth embodiment, the device is provided with a computer-readable medium containing instructions that, when executed by the device, cause the device to perform at least the following actions: obtain the serving network name of a first user device; and determine an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to act as a relay between the first user device and the network.

[0080] This device may further include means for receiving authentication information, which may include the serving network name of the first user device.

[0081] This device may further include means for receiving authentication information within extended authentication protocol messages.

[0082] This device may further include means for obtaining the serving network name of the first user device by obtaining it from the universal subscriber identification module associated with the first user device.

[0083] This device may include, be, or be included in the first user equipment.

[0084] In a 17th embodiment, a non-transient computer-readable medium is provided which includes program instructions for causing an apparatus to perform a method according to at least one of the 5th to 8th embodiments.

[0085] In the eighteenth embodiment, a system is provided which includes an apparatus according to the first embodiment and an apparatus according to the second embodiment.

[0086] In the 19th embodiment, a system is provided which includes an apparatus according to a third embodiment and an apparatus according to a fourth embodiment.

[0087] Many different embodiments have been described above. It should be understood that further embodiments may be provided by any combination of two or more of the embodiments described above. [Brief explanation of the drawing]

[0088] Next, an exemplary embodiment will be described with reference to the attached diagram. [Figure 1] Figure 1 is a schematic diagram of an example of a 5GS communication system. [Figure 2] Figure 2 is a schematic diagram of an example of a mobile communication device. [Figure 3] Figure 3 is a schematic diagram showing an example of a control device. [Figure 4] Figure 4 shows the signaling flow of the relay security procedure from 5G ProSe UE to the network. [Figure 5] Figure 5 shows the signaling flow for ProSe authentication. [Figure 6]Figure 6 shows a flowchart of the method according to an exemplary embodiment. [Figure 7] Figure 7 shows a flowchart of the method according to an exemplary embodiment. [Figure 8] Figure 8 shows a flowchart of the method according to an exemplary embodiment. [Figure 9] Figure 9 shows a flowchart of the method according to an exemplary embodiment. [Figure 10] Figure 10 shows the signaling flow according to an exemplary embodiment. [Figure 11] Figure 11 shows the signal flow according to an exemplary embodiment. [Figure 12] Figure 12 shows a signaling flow according to an exemplary embodiment. [Figure 13] Figure 13 shows the signaling flow according to an exemplary embodiment. [Modes for carrying out the invention]

[0089] Before describing the embodiments in detail, a brief explanation of some general principles of wireless communication systems and mobile communication devices will be given with reference to Figures 1 to 3 to help understand the underlying technology of the embodiments described.

[0090] Examples of suitable communication systems include the 5G or NR concept. The NR network architecture may be similar to LTE Advanced. Base stations in an NR system are called next-generation node B (gNB). Changes to the network architecture may depend on the need to support various radio technologies and finer-grained QoS support, as well as on-demand requirements such as quality of service (QoS) levels to support user-perceived quality of experience (QoE). Network-aware services and applications, and service and application-aware networks, may also bring about changes in the architecture. These are related to information-centric network (ICN) and user-centric content delivery network (UC-CDN) approaches. NR may use multiple-input multiple-output (MIMO) antennas, more base stations and nodes than LTE (the so-called small cell concept), and macrosites that work in cooperation with smaller base stations.

[0091] 3GPP® defines a service-based architecture (SBA) for mobile networks, where the control plane functions and common data repository of a mobile network are provided as a set of interconnected network functions (NFs), each network function having the authority to access at least some of the services of other network functions. Network functions expose their functions through service-based interfaces (SBIs), which are, for example, well-defined expressive state transition (REST) ​​interfaces based on HTTP / 2. Network functions may be operationally connected or linked to provide services. Network nodes, such as network elements or general-purpose servers, can implement one or more network functions. Mobile networks may utilize network function virtualization (NFV), in which case network functions may be implemented as virtualized network functions (VNFs) that include one or more virtual machines running on a virtualization platform. The virtualization platform includes one or more virtualization servers, which may be implemented using, for example, general-purpose servers or customized hardware. Cloud computing and data storage devices may also be utilized. In wireless communication, this may mean a node operation running on a server, host, or node operably coupled to a remote wireless head, at least in part. Furthermore, the node operation may be distributed across multiple servers, nodes, or hosts. It should also be understood that the division of roles between core network operations and base station operations may differ from, or even be absent, that of LTE.

[0092] Figure 1 schematically shows a 5G system (5GS) 100. The 5GS may include user equipment (UE) 102 (sometimes also referred to as communication equipment or terminals), a 5G radio access network (5G RAN) 104, a 5G core network (5G CN) 106, one or more internal or external application functions (AF) 108, and one or more data networks (DN) 110.

[0093] An exemplary 5G core network (CN) includes functional entities. The 5G CN 106 may include one or more access and mobility management functions (AMFs) 112, one or more session management functions (SMFs) 114, an authentication server function (AUSF) 116, an integrated data management (UDM) 118, one or more user plane functions (UPFs) 120, an integrated data repository (UDR) 122, and / or a network exposure function (NEF) 124. The UPFs are controlled by the SMFs (Session Management Functions) which receive policies from the PCFs (Policy Control Functions).

[0094] The CN is connected to the UE via a Radio Access Network (RAN). The 5G RAN may include one or more gNodeB (GNB) distributed unit functions connected to one or more gNodeB (GNB) centralized unit functions. The RAN may include one or more access nodes.

[0095] A user plane function (UPF) called a PDU session anchor (PSA) may be responsible for forwarding frames back and forth between the DN and the tunnel established over 5G to the UE that exchanges traffic with the DN.

[0096] Next, with reference to Figure 2, which shows a schematic partial cross-sectional view of the communication device 200, a possible mobile communication device will be described in more detail. Such communication devices are often called user equipment (UE) or terminals. A suitable mobile communication device can be provided by any device capable of sending and receiving radio signals. Non-limiting examples include mobile stations (MS), such as those known as mobile phones or "smartphones," or mobile devices, radio interface cards or other radio interface equipment (e.g., USB dongles), personal data assistants (PDAs) or tablets with radio communication capabilities, voice over IP (VoIP) phones, portable computers, desktop computers, image capture terminal devices such as digital cameras, game terminal devices, music storage and playback appliances, in-vehicle radio terminal devices, radio endpoints, mobile stations, laptop embedded devices (LEE), laptop mounted devices (LME), smart devices, wireless customer premises equipment (CPE), or any combination thereof. Mobile communication devices can provide data communications for communication such as voice, email, text messages, and multimedia. Thus, user equipment can provide a number of services through communication devices. Non-exclusive examples of these services include two-way or multi-way calls, data communications or multimedia services, or simply access to data communication network systems such as the Internet. They may also provide users with broadcast or multicast data. Non-exclusive examples of content include downloads, television programs, radio programs, videos, advertisements, alerts, and other information.

[0097] A mobile device typically comprises at least one data processing entity 201, at least one memory 202, and other possible components 203 for use in software and hardware-assisted execution of tasks it is designed to perform, including control of access to and communication with access systems and other communication devices. Data processing, storage, and other related control devices may be located on a suitable circuit board and / or within a chipset. This functionality is indicated by reference numeral 204. The user can control the operation of the mobile device by a suitable user interface, such as a keypad 205, voice commands, a touch-sensitive screen or pad, or a combination thereof. A display 208, speaker, and microphone may also be provided. Furthermore, the mobile communication device may include a suitable connector (either wired or wireless) for connecting to other devices, and / or a connector for connecting external accessories, such as hands-free devices.

[0098] The mobile device 200 can receive signals via air or a radio interface 207 through a suitable receiving device, and can transmit signals via a suitable transmitting device. In Figure 2, the transceiver device is schematically shown by block 206. The transceiver device 206 may be provided, for example, by a radio unit and associated antenna equipment. The antenna equipment may be located inside or outside the mobile device.

[0099] Figure 3 shows an example of a control device 300 for a communications system, which is connected to and / or controls, for example, RAN nodes, such as base stations, eNBs or gNBs, relay nodes, or core network nodes such as MMEs or S-GWs or P-GWs, or core network functions such as AUSF, UDMs, AMFs, or SMFs, or access system stations such as servers or hosts. The method may be implemented in a single control device or across multiple control devices. The control device may be integrated with or external to a node or module of the core network or RAN. In some embodiments, a base station includes a separate control device unit or module. In other embodiments, the control device may be other network elements such as a radio network control device or a spectrum control device. In some embodiments, each base station may have such a control device, as well as a control device provided in a radio network controller. The control device 300 may be configured to provide control over communications within the service area of ​​the system. The control device 300 comprises at least one memory 301, at least one data processing unit 302, 303, and an input / output interface 304. The control unit can be coupled to the base station's receiver and transmitter via an interface. The receiver and / or transmitter can be implemented as a radio front-end or remote radio head. The control unit 300 may include one or more network functions that can be implemented as virtualized network functions. The control unit 300 may be a network node. The control unit 300 may be a chip and / or module configured within a network node.

[0100] This document describes the security of authentication, authorization, and key management between 5G ProSe Layer 3 UEs using 5G ProSe remote UE-specific authentication to establish PC5 keys. The network functions AMF, AUSF, and UDM are involved in key derivation and the distribution of keys used for communication between 5G ProSe UEs. UEs are provided with the policies and parameters necessary to use 5G ProSe services as part of their UE ProSe policy information. The PCF provides authorization policies and parameters for network relay discovery between 5G ProSe UEs and the network.

[0101] The procedure for establishing a PC5 link between a 5G ProSe remote UE and a relay from the 5G ProSe UE to the network (UE-to-network relay) is described. This procedure includes how the 5G ProSe remote UE is authenticated during the establishment of the 5G ProSe PC5 by the AUSF of the 5G ProSe remote UE and the AMF of the relay from the 5G ProSe UE to the network. This mechanism can be used when the 5G ProSe remote UE is outside of coverage.

[0102] Figure 4 shows the signaling flow of security procedures between 5G ProSe UEs to set up the network process security context during PC5 link establishment.

[0103] In step 0, the 5G ProSe remote UE and the relay from the 5G ProSe UE to the network are registered with the network. In step 0a, the 5G ProSe remote UE is authenticated by the network and authorized to receive the relay service from the UE to the network. In step 0b, the relay from the 5G ProSe UE to the network is authenticated and authorized by the network to provide the relay service from the UE to the network. The PC5 security policy is provided to the 5G ProSe remote UE and the relay from the 5G ProSe UE to the network, respectively, during this authentication and information provision procedure.

[0104] In Step 1, the 5G ProSe remote UE initiates the discovery procedure using either Model A or Model B.

[0105] In step 2, upon detecting a relay from the 5G ProSe UE to the network, the 5G ProSe remote UE sends a Direct Communication Request (DCR) to the relay from the 5G ProSe UE to the network in order to securely establish a PC5 unicast link. The 5G ProSe remote UE includes its security features and the security policy for PC5 signaling in the DCR message. The message also includes the relay service code (RSC) and Nonce_1.

[0106] If the 5G ProSe remote UE does not have a valid 5GPRUK (5G Prose Remote User Key), the 5G ProSe remote UE must include the SUCI in the DCR, trigger 5G ProSe remote UE-specific authentication, and establish the 5GPRUK.

[0107] If a 5G ProSe remote UE already has a valid 5GPRUK, the 5G ProSe remote UE must include the 5GPRUK ID in its DCR to indicate that it wants to obtain a relay connection using the 5GPRUK.

[0108] In step 3, upon receiving the DCR message, the 5G ProSe UE relay sends a relay key request to the 5G ProSe UE relay's AMF, including the SUCI or 5GPRUK ID, RSC, and Nonce_1 received in the DCR message. The 5G ProSe UE to network relay includes a transaction identifier that identifies the 5G ProSe remote UE in subsequent messages via the 5G ProSe UE to network relay's NAS message.

[0109] In step 4, the AMF for the 5G ProSe UE to network relay verifies whether the 5G ProSe UE to network relay is authorized to provide the UE to network relay service.

[0110] In step 5, the AMF of the 5G ProSe inter-UE relay selects the AUSF based on the SUCI or 5GPRUK ID and forwards the parameters received in the relay key request to the AUSF in the Nausf_UEA Authentication_ProseAuthenticate Request message. The Nausf_UEA Authentication_ProseAuthenticate Request message includes the SUCI or 5GPRUK ID of the 5G ProSe remote UE, the relay service code, and Nonce_1. If the AUSF of the 5G ProSe remote UE receives the 5GPRUK ID from the AMF of the 5G ProSe inter-UE relay, it skips steps 6-9. If the AUSF of the 5G ProSe remote UE receives the SUCI from the AMF of the 5G ProSe inter-UE relay, it performs steps 6-9 and skips step 10.

[0111] In step 6, AUSF uses the received ProSe-specific parameters (such as RSC) to initiate 5G ProSe remote UE-specific authentication.

[0112] The AUSF of a 5G ProSe remote UE obtains the authentication vector and RoutingIndicator of the 5G ProSe remote UE from the UDM via the Nudm_UEAuthentication_GetProSeAvRequest message. Upon receiving Nudm_UEAuthentication_GetProSeAvRequest, the UDM invokes SIDFde-concealSUCI and obtains the SUPI before processing the request. The UDM checks whether the UE is authorized to use the relay service from the ProSe UE to the network based on the credentials in the UE's subscription data. If the UE is authorized, the UDM selects an authentication method based on the SUPI.

[0113] In step 7a, if EAP-AKA' is selected by the UDM, the AUSF of the 5G ProSe remote UE triggers authentication of the 5G ProSe remote UE based on EAP-AKA'. The AUSF of the 5G ProSe remote UE generates an EAP-Request / AKA'-Challenge and sends the EAP-Request / AKA'-Challenge message to the AMF of the relay from the 5G ProSe UE to the network in the Nausf_UEAuthentication_ProSeAuthenticateResponse message.

[0114] In step 7b, the AMF of the 5G ProSe inter-UE relay forwards a relay authentication request (including EAP-Request / AKA'-Challenge) on the NAS message to the 5G ProSe inter-UE relay, which contains the transaction identifier of the 5G ProSe remote UE. The NAS message is securely protected using the NAS security context created for the relay from the 5G ProSe UE to the network.

[0115] In step 7c, based on the transaction identifier, the 5G ProSe inter-UE relay forwards the EAP-Request / AKA'-Challenge to the 5G ProSe remote UE in a PC5 message.

[0116] The 5G ProSe remote UE's Universal Subscriber Identification Module (USIM) verifies the freshness of the received value by checking whether it can accept AUTN.

[0117] In the case of EAP-AKA', USIM calculates the response RES. USIM must return RES, CK, and IK to ME. ME must derive CK' and IK'.

[0118] In step 7d, the 5G ProSe remote UE returns an EAP-Response / AKA'-Challenge message on the PC5 message to the 5G ProSe UE relay.

[0119] In step 7e, the 5G ProSe UE relay forwards the EAP-Response / AKA'-Challenge, along with the transaction identifier of the 5G ProSe remote UE, to the 5G ProSe UE relay's AMF in the NAS message relay authentication response.

[0120] In step 7f, the AMF of the 5G ProSe inter-UE relay forwards the EAP-Response / AKA'-Challenge to the AUSF of the 5G ProSe remote UE via the Nausf_UEA Authentication_ProSeAuthenticate Request.

[0121] The AUSF of a 5G ProSe remote UE performs UE authentication by verifying the received information.

[0122] For EAP-AKA', the AUSF of the 5G ProSe remote UE and the 5G ProSe remote UE can exchange EAP-Request / AKA'-Notification and EAP-Response / AKA'-Notification messages via the AMF of the 5G ProSe remote UE to the network relay and the 5G ProSe remote UE to the network relay. After the exchange, the 5G ProSe remote UE and the AUSF of the 5G ProSe remote UE derive KAUSF_P in the same way that KAUSF is derived.

[0123] In step 8, upon successful authentication, the 5G ProSe remote UE and the AUSF of the 5G ProSe remote UE generate a 5GPRUK.

[0124] The 5GPRUK ID is in NAI format, i.e., username@realm. The username part contains the routing indicator from step 6 and the 5GPRUK ID*, and the realm part contains the home network identifier.

[0125] In step 9a, the AUSF of the 5G ProSe remote UE selects a PAnF (ProseAnchorFunction) based on the 5GPRUK ID and sends the SUPI, RSC, 5GPRUK, and 5GPRUK ID to the PAnF in the Npanf_ProseKey_RegisterRequest message.

[0126] In step 9b, PAnF saves the Prose context information (SUPI, RSC, 5GPRUK, 5GPRUK ID) of the 5G ProSe remote UE and sends the Npanf_ProseKey_Register Response message to AUSF.

[0127] In step 10a, the AUSF of the 5G ProSe remote UE selects a PAnF based on the 5GPRUK ID and sends the received 5GPRUK ID and RSC in an Npanf_ProseKey_getRequest message.

[0128] In step 10b, PAnF retrieves the 5GPRUK based on the 5GPRUK ID and checks, based on the received RSC, whether the 5G ProSe remote UE is authorized to use the inter-UE relay service. If the 5G ProSe remote UE is authorized and the retrieved 5GPRUK is valid, PAnF sends an Npanf_ProseKey_get Response message containing the 5GPRUK to AUSF.

[0129] In step 11, the AUSF of the 5G ProSe remote UE generates Nonce_2, and uses 5GPRUK, Nonce_1, and Nonce_2 to derive the KNR_ProSe key.

[0130] In step 12, the AUSF of the 5G ProSe remote UE sends KNR_ProSe, Nonce_2 in the Nausf_UEAuthentication_ProseAuthenticateResponse message to the relay from the 5G ProSe UE to the network via the AMF of the relay from the 5G ProSe UE to the network. If step 7 was executed successfully, an EAPSuccess message is included. The AUSF of the 5G ProSe remote UE should also include the 5GPRUK ID in the message if it was generated in step 8.

[0131] In step 13, when the 5G ProSe remote UE receives KNR_ProSe from the AUSF via the AMF of the 5G ProSe inter-UE relay, the 5G ProSe inter-UE relay derives the PC5 session key Krelay-sess, confidentiality key Krelay-enc (if applicable), and integrity key Krelay-int from KNR_ProSe. The KNR_ProSe ID and Krelay-sess ID are established in the same way as the KNRP ID and KNRP-sess ID. The EAPSuccess message and 5GPRUK ID are also sent from the AMF of the 5G ProSe UE to the network relay to the UE to network relay if received from the AUSF.

[0132] In step 14, the relay from the 5G ProSe UE to the network sends the received Nonce_2 and the 5G ProSe remote UE's PC5 signaling security policy to the 5G ProSe remote UE in an integrity-protected DirectSecurity mode command message using Krelay-int. If the relay from the 5G ProSe UE to the network is received from the AMF, it includes an EAPSuccess message.

[0133] In step 15, the 5G ProSe remote UE generates a KNR_ProSe key for remote access via the 5G ProSe inter-UE relay in the same manner as defined in step 11. The 5G ProSe remote UE derives the PC5 session key Krelay-sess and the confidentiality and integrity keys from KNR_ProSe in the same manner as defined in step 13.

[0134] In step 16, the 5G ProSe remote UE sends a direct security mode complete message containing its PC5 user plane security policy to the 5G ProSe inter-UE relay. This message is protected by Krelay-int and / or Krelay-enc derived from Krelay-sess, in accordance with the PC5 signaling policy negotiated between the 5G ProSe remote UE and the 5G ProSe inter-UE relay.

[0135] In step 17, after securely verifying the Direct Security Mode Completion message, the 5G ProSe Inter-UE relay receives a Direct Communication Acceptance message from the 5G ProSe Remote UE, terminates the PC5 connection establishment procedure, and stores the 5GPRUK ID in the security context associated with the PC5 link with the 5G ProSe Remote UE.

[0136] The Serving Network Name (SNN) is the Service Code and SN ID separated by a colon (:), with the Service Code preceding the SN ID. The Serving Network Name (SNN) is used to derive the anchor key. The SNN serves two purposes: to bind the anchor key to the serving network by including the Serving Network Identifier (SN ID), and to ensure that the anchor key is specific to authentication between the 5G core network and the UE by including the Service Code set to "5G".

[0137] In 5G AKA, the serving network names RES* and XRES* serve a similar purpose, binding them to the serving network.

[0138] Because it relates to the 5G core procedure which is independent of the access network, the serving network name does not use parameters such as "access network type". The SN ID identifies the serving PLMN and is defined as the SNN-network-identifier, except for standalone, private networks.

[0139] The UE constructs the SNN as follows: The UE sets the service code to "5G", sets the network identifier to the SN ID of the authentication target network, and concatenates the service code and SN ID with the separator character ":".

[0140] SEAF constructs the serving network name as follows: SEAF sets the service code to "5G", sets the network identifier to the SN ID of the serving network to which authentication data is sent by AUSF, and concatenates the service code and SN ID with the separator character ":".

[0141] AUSF obtains the serving network name from SEAF. Before using the serving network name, AUSF verifies that SEAF is authorized to use the serving network name.

[0142] For authenticating a 5G ProSe remote UE in AUSF, for example, the ProseAuthenticate service operation in step 0a of Figure 4 can be used.

[0143] The NF Service User (AMF) requests authentication of the 5G ProSe Remote UE by providing the NF Service Producer (AUSF) with 5G ProSe Remote UE-related information, relay service code, and Nonce_1. The NFServiceProducer retrieves the 5G ProSe Remote UE-related data and authentication method from the UDM. In the example in Figure 5, the retrieved authentication method is EAP-AKA. Next, the NF Service User (AMF) returns the results received from the 5G ProSe Remote UE to the AUSF.

[0144] In Step 1, the NF Service User (AMF) sends a POST request to the AUSF. The payload in the body includes the UE ID, relay service code, and Nonce_1.

[0145] In step 2a, if successful, "201 Created" should be returned. The payload body should contain a representation of the generated resource, and the "Location" header should contain the URI of the generated resource (e.g., ... / v1 / prose_authentications / {authCtxId}). AUSF will generate a subresource named "prose-auth". There should be only one "prose-auth" subresource for each UE identified by supiOrSuci in ProSeAuthenticationInfo. AUSF must provide a hypermedia link to this subresource in the payload to indicate where to send a POST containing the EAP packet response to AMF. The body payload must also contain the EAP packet EAP-Request / AKA'-Challenge.

[0146] Alternatively, in step 2b, specify one of the HTTP status codes in case of failure or redirection. For 4xx / 5xx responses, the message body may contain a ProblemDetails structure with the "cause" attribute set to one of the application errors.

[0147] In step 3, based on the relationship type, the NFServiceConsumer (AMF) sends a POST request containing the EAP-Response / AKA' challenge received from the 5G ProSe remote UE. The POST request is sent to a URI provided by the AUSF or derived by the NF Service Consumer (AMF).

[0148] Steps 4 and 5 are optional.

[0149] In step 4a, if successful, and if AUSF and UE notify the use of the protected success result instruction, AUSF must respond with an EAP Request / AKA' Notification and a "200 OK" HTTP message containing a hypermedia link to the subresource "prose-auth".

[0150] Alternatively, in 4b, if there is a failure or redirection, one of the HTTP status codes listed in Table 1 must be returned. In 4xx / 5xx responses, the message body may contain a ProblemDetails structure with the "cause" attribute set to one of the application errors listed in Table 1.

[0151] [Table 1]

[0152] In step 5, the NF Service Consumer (AMF) sends a POST request containing the EAP Response / AKA' Notification received from the UE. The POST request is sent to a URI provided by AUSF or derived by the NF Service Consumer (AMF).

[0153] In step 6a, if the ProSe authentication exchange is completed successfully (regardless of whether the optional Notification Request / Response message exchange occurred), "200 OK" is returned to the NF Service Consumer (AMF). The payload includes the authentication result, the success / failure of the EAP, and the KNR_ProSe if authentication is successful. If the 5G ProSe remote UE is not authenticated, AUSF sets authResult to AUTHENTICATION_FAILURE.

[0154] In step 6b, if there is a failure or redirection, one of the HTTP status codes shown in Table 1 must be returned. In a 4xx / 5xx response, the message body may contain a ProblemDetails structure with the "cause" attribute set to one of the application errors listed in Table 2. Table 2 shows the definition of ProSeAuthenticationInfo. [Table 2]

[0155] The NF Service Consumer (AUSF) uses the operation to request a ProSe authentication vector(s) for a 5G ProSe remote UE from the UDM. If a SUCI is provided, the UDM calculates the SUPI from the SUCI. The UDM calculates the authentication vector considering the information received from the NF Service Consumer (AUSF) and, if EAP-AKA is selected, the current representation of this resource. This operation must support the request data structure specified in Table 3 below. The ProSeAuthenticationInfoRequest is as shown in Table 4. [Table 3] [Table 4]

[0156] It is unclear which SNN the UDM uses to generate the authentication vector. The SNN could be the SNN of the remote UE or the SNN of the relay UE.

[0157] If a remote UE's SNN is used, the remote UE's AUSF in the ProSe direct communication procedure needs to recognize the SNN, and that SNN needs to be sent from the AUSF to the remote UE's UDM.

[0158] When the relay UE's SNN is used, the ProseAuthenticate from the relay UE's AMF to the remote UE's AUSF does not contain an SNN information element, and therefore the remote UE's AUSF cannot recognize that information.

[0159] If the relay UE's SNN is used for AV generation and EAP-AKA is used for ProSe-specific authentication, the remote UE's USIM and UDM will use the same SNN for authentication vector generation because they are shared in the AKA challenge message of the EAP message.

[0160] However, this approach is not suitable when 5G AKA is used for ProSe authentication. In 5G AKA, the remote UE USIM and UDM use the SNN independently without sharing the network in the AKA challenge message.

[0161] Figure 6 shows a flowchart of the method according to an exemplary embodiment. This method can be performed on a network node such as a UDM.

[0162] In S1, the method includes receiving notification of the serving network name of the first user device at a network node, and the first user device is configured to act as a relay between the second user device and the network by providing proximity service between the first user device and the second user device.

[0163] In S2, this method includes determining an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device.

[0164] In S3, this method includes providing the second user device with notification of the serving network name of the first user device.

[0165] In the method described with reference to Figure 6, the first user device is sometimes called a relay UE, and the second user device is sometimes called a remote UE.

[0166] Figure 7 shows a flowchart of the method according to an exemplary embodiment. This method can be executed in UE.

[0167] In T1, the method includes the first user device receiving notification of the serving network name of the second user device, and the second user device is configured to act as a relay between the first user device and the network by providing proximity services between the first user device and the second user device.

[0168] In T2, this method includes determining an authentication vector for proximity service authentication of the first user device based on the serving network name of the second user device.

[0169] In the method described with reference to Figure 7, the first user device is sometimes called a remote UE, and the second user device is sometimes called a relay UE.

[0170] Figure 8 is a flowchart of a method according to an exemplary embodiment. This method can be performed using a network function such as a UDM.

[0171] In R1, this method involves obtaining the serving network name of the first user device at the network node.

[0172] In R2, the method includes determining an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to act as a relay between the first user device and the network.

[0173] Figure 9 shows a flowchart of the method according to an exemplary embodiment. This method can be executed in UE.

[0174] In U1, this method includes obtaining the serving network name of the first user device on the first user device.

[0175] In U2, the method includes determining an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to act as a relay between the first user device and the network.

[0176] In the method described with reference to Figures 8 and 9, the first user device may be called a remote UE, and the second user device may be called a relay UE.

[0177] Proximity service authentication may be EAP AKA' or 5G AKA, or other appropriate proximity service authentication procedure.

[0178] In the exemplary first approach for EAP AKA' or 5G AKA, as shown in Figures 8 and 9, the relay UE's AMF does not share the SNN with the AUSF, and the AUSF does not share the relay UE's SNN with the UDM. Instead, the UDM obtains the remote UE's SNN for authentication vector generation. Obtaining the first user device's SNN involves obtaining the first user device's SNN from a memory function.

[0179] The method described with reference to Figure 9 may include receiving authentication information at the first user device, where the authentication information includes the serving network name of the first user device. The authentication information may include an Extensible Authentication Protocol (EAP) message. The method according to Figure 8 may include providing an EAP message to the first user device, where the EAP message includes the serving network name of the first user device.

[0180] For example, in the first approach, if EAP AKA' is used, the UDM can share the remote UE's SNN with the remote UE in the authentication and key agreement (AKA) challenge message.

[0181] Alternatively, the serving network name of the first user device may be stored in the USIM of the first user device. Retrieving the serving network name of the first user device may involve retrieving the serving network name of the first user device from the universal subscriber identification module associated with the first user device.

[0182] For example, when 5G AKA is used, the UDM and remote UE use the SNN ("Remote UE SNN") stored from the previous procedure (the last registered AMF). The UDM and remote UE retrieve the SNN from memory / storage (e.g., USIM in the case of the UE) and use it to generate the authentication vector.

[0183] The method described with reference to Figure 6 may include receiving the serving network name from the first user device via at least one of the AMF associated with the first user device or the AUSF associated with the first user device.

[0184] In an exemplary second approach, as shown in Figure 6 for EAP AKA' or 5G AKA, the relay UE's AMF sends the relay UE's SNN to the AUSF, and then to the UDM. The relay UE's SNN is then used for authentication vector generation.

[0185] The method shown in Figure 6 may include providing authentication information to a second user device, which includes notification of the serving network name of the first user device. The authentication information is provided in at least one of a proximity service authentication response, a proximity service authentication request, or an EAP message.

[0186] Figure 10 shows an example of the signaling flow for ProSe EAP AKA authentication using the first approach. The relay UE's AMF does not share the SNN with the AUSF, and the AUSF does not share the SNN with the UDM.

[0187] Figure 11 shows an example of the signaling flow for ProSe 5G AKA authentication using the first approach. The relay UE's AMF does not share the SNN with the AUSF, and the AUSF does not share the SNN with the UDM.

[0188] In step 1a of Figures 10 and 11, once the remote UE is registered and authenticated by the network, the UDM stores the results and time of the authentication procedure. This includes the SUPI, the authentication timestamp, the authentication type (such as EAP or 5G-AKA), and the serving network name (referred to as the remote UE SNN).

[0189] In Figure 10, a remote UE triggers a ProSe-specific authentication request via the relay UE network. Once the request reaches the UDM, the SUCI is decrypted, and the remote UESNN is retrieved from the UDM storage and used to generate the ProSe authentication vector.

[0190] The same "Remote UE SNN" is used in AT_KDF_INPUT and passed to the Remote UE / USIM in an EAP AKA challenge for ProSe-specific authentication.

[0191] In the case of 5G AKA, the UDM obtains the SNN from stored memory, and the remote UE obtains the SNN from the USIM. In messages 6c to 9a in Figure 11, there is no exchange of SNN information for the remote UE in the case of 5G AKA.

[0192] In Figure 11, the remote UE triggers a ProSe-specific authentication request via inter-UE relay. Once it reaches the UDM, the SUCI is desecrated, and the "remote UE SNN" is retrieved from the UDM storage and used to generate the ProSe-specific authentication vector.

[0193] Figure 12 shows an example of the signaling flow for ProSe EAP AKA authentication using the second approach.

[0194] Figure 13 shows an example of the signaling flow for ProSe 5G AKA authentication using the second approach.

[0195] In Figures 12 and 13, the relay UE's AMF sends the "Relay UE SNN" to the AUSF in step 5 of the Nausf_UEA Authenticate_Prose Authenticate_Request message. The AUSF forwards the "Relay UE SNN" to the UDM in step 6a of the Nudm_UE Authenticate_Get Prose AV_Request message. The "Relay UE SNN" is used for authentication vector generation.

[0196] In Figure 12, the same relay UE's SNN is used in AT_KDF_INPUT and passed to the UE / USIM in the AKA challenge.

[0197] In Figure 13, the relay UE SNN is transmitted from the UDM to the AUSF and then to the remote UE in the 5G AKA authentication message. The remote UE uses its relay UE SNN in the RES's AKA challenge calculation.

[0198] The network node device may include means for receiving notification of the serving network name of a first user device; a first user device configured to act as a relay between the second user device and the network by providing proximity services between the first user device and the second user device; means for determining an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device; and means for providing notification of the serving network name of the first user device to the second user device.

[0199] Alternatively, the network node device may include means for obtaining the serving network name of a first user device, and means for determining an authentication vector based on the serving network name of the first user device for proximity service authentication between the first user device and a second user device configured to act as a relay between the first user device and the network.

[0200] This device includes a network node, is a network node, or is a chipset for a network node that includes a network node or performs at least some of the operations of a network node. The network node may implement a UDM.

[0201] The first user device may include means for receiving notification of the serving network name of the second user device, the second user device configured to act as a relay between the first user device and the network by providing proximity services between the first user device and the second user device, and means for determining an authentication vector for proximity service authentication of the first user device based on the serving network name of the second user device.

[0202] Alternatively, or in addition thereto, the device may include, in a first user device, means for obtaining the serving network name of the first user device, and means for determining an authentication vector based on the serving network name of the first user device for proximity service authentication of the first user device for proximity service between the first user device and a second user device configured to operate as a relay between the first user device and the network.

[0203] This device may be a first user device, including a mobile phone, or it may be configured within a first user device, or it may be a chipset for performing the operations of / at least some of the operations of a user device.

[0204] The system comprises, at a network node, means for receiving notification of the serving network name of a first user device; a first user device configured to act as a relay between the second user device and the network by providing proximity services between the first user device and the second user device; means for determining an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device; means for providing notification of the serving network name of the first user device to the second user device; means for the second user device to receive notification of the serving network name of the first user device; and means for determining an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device.

[0205] The system may include means for obtaining the serving network name of a first user device at a network node; means for determining an authentication vector based on the serving network name of the first user device for proximity service authentication between the first user device and a second user device configured to act as a relay for proximity services between the first user device and a network node; and, at the first user device, means for obtaining the serving network name of the first user device; and means for determining an authentication vector for proximity-based service authentication of the first user device in proximity-based services between the first user device and a second user device configured to act as a relay between the first user device and the network, based on the serving network name of the first user device.

[0206] It should be understood that this device includes, or may be coupled with, other units or modules such as wireless components or wireless heads used for transmission and / or reception. Although the device has been described as a single entity, different modules and memories may be implemented in one or more physical or logical entities.

[0207] While several embodiments have been described in relation to 5G networks, it should be noted that similar principles may be applied in relation to other networks and communication systems. Thus, while exemplary embodiments have been described above with reference to specific exemplary architectures for wireless networks, technologies, and standards, the embodiments may be applied to any other preferred forms of communication systems other than those illustrated and described in these embodiments.

[0208] Furthermore, while exemplary embodiments have been described in this embodiment, it should be noted that several modifications and alterations can be made to the disclosed solution without departing from the scope of the present invention.

[0209] As used herein, “at least one of the following, <list of two or more elements>,” “at least one of the <list of two or more elements>,” and similar expressions in which lists of two or more elements are connected by “and” or “or” mean at least one of the elements, at least two or more of the elements, or at least all of the elements.

[0210] In general, various embodiments can be implemented in hardware or special-purpose circuits, software, logic, or any combination thereof. While some embodiments of this disclosure can be implemented in hardware, others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device, but this disclosure is not limited to these embodiments. Various embodiments of this disclosure can be illustrated and described using block diagrams, flowcharts, or any other graphic representation, but it is well understood that these blocks, devices, systems, techniques, or methods described herein can be implemented, in non-limiting examples, in hardware, software, firmware, special-purpose circuits or logic, general-purpose hardware or controllers or other computing devices, or any combination thereof.

[0211] As used in this application, the term "circuit" may refer to one or more or all of the following: (a) Hardware-only circuit implementation (such as implementation of analog and / or digital circuits only), (b) combination of hardware circuitry and software (if applicable), (i) combination of analog and / or digital hardware circuits and software / firmware, (ii) A part(s) of a hardware processor, including software (including a digital signal processor), software, and memory, that works together to perform various functions on a device such as a mobile phone or a server. (c) Hardware circuits or processors, such as microprocessors or parts of microprocessors, that require software (such as firmware) to operate, but may not exist when the software is not needed for operation.

[0212] This definition of circuit applies to all use of the term in this application, including in all claims. As a further example, in the use herein, the term circuit also includes not only a hardware circuit or processor (or more processors) or a part of a hardware circuit or processor and the accompanying software and / or firmware implementation. The term circuit also includes, for example, a baseband integrated circuit or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device, where applicable to the elements of a particular claim.

[0213] Embodiments of the present disclosure may be implemented by computer software or hardware, or a combination of software and hardware, that can be executed by a data processor of a mobile device, such as within a processor entity. Computer software or programs, also called program products, which include software routines, applets and / or macros, may be stored on any device-readable data storage medium and contain program instructions for performing a particular task. A computer program product may consist of one or more computer-executable components configured to perform an embodiment when the program is executed. The one or more computer-executable components may be at least one piece of software code or a portion thereof.

[0214] Furthermore, it should be noted that in this regard, the logic flow blocks shown in the diagram can represent program steps, or interconnected logic circuits, blocks, and functions, or combinations of program steps and logic circuits, blocks, and functions. Software can be stored on physical media such as memory chips, memory blocks implemented within a processor, magnetic media such as hard disks and floppy disks, and optical media such as DVDs and their data variants, CDs. Physical media are non-transient media. The term "non-transient" as used herein refers to the limitations of the medium itself (i.e., tangible, not signal-based) as opposed to the limitations of data storage persistence (e.g., RAM vs. ROM).

[0215] Memory may be of any type suitable for the local technological environment and can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processor may be of any type suitable for the local technological environment and, in non-limiting examples, may consist of one or more of the following: general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), FPGAs, gate-level circuits, and processors based on multi-core processor architectures.

[0216] Embodiments of this disclosure can be implemented in various components, such as integrated circuit modules. Designing integrated circuits is generally a highly automated process. Complex and powerful software tools are available to translate logic-level designs into semiconductor circuit designs that can be etched onto semiconductor substrates.

[0217] The scope of protection required for the various embodiments of this disclosure is defined by the independent claims. Where embodiments and features described herein that do not fall within the scope of the independent claims are described, they are construed as exemplary embodiments useful for understanding the various embodiments of this disclosure.

[0218] The foregoing description, by non-limiting examples, has provided a complete and useful description of the exemplary embodiments of the present disclosure. However, when read in conjunction with the accompanying drawings and claims, various modifications and adaptations may become apparent to those skilled in the art in consideration of the foregoing description. However, all such and similar modifications of the teachings of the present disclosure still fall within the scope of the invention as defined in the accompanying claims. In fact, further embodiments exist, including one or more embodiments in combination with any of the other embodiments described above.

Claims

1. A device for network nodes, Means for receiving notification of the serving network name of a first user device, wherein the first user device is configured to act as a relay between the second user device and the network by providing proximity service between the first user device and the second user device, Means for determining an authentication vector for proximity service authentication of the second user device based on the serving network name of the first user device, Means for providing the second user device with notification of the serving network name of the first user device, A device equipped with the following features.

2. The apparatus according to claim 1, further comprising means for providing authentication information to the second user device, wherein the authentication information includes the notification of the serving network name of the first user device.

3. The apparatus according to claim 2, further comprising means for providing authentication information in at least one of a proximity service authentication response, a proximity service authentication request, or an extended authentication protocol message.

4. The apparatus according to any one of claims 1 to 3, further comprising means for receiving the serving network name of the first user device via at least one of the access and mobility management functions associated with the first user device or the authentication server function associated with the second user device.

5. The apparatus according to any one of claims 1 to 3, wherein the network node performs unified data management.

6. A device for a first user device, Means for receiving notification of the serving network name of a second user device, wherein the second user device is configured to act as a relay between the first user device and the network by providing proximity services between the first user device and the second user device; Means for determining an authentication vector for proximity service authentication of the first user device based on the serving network name of the second user device, A device equipped with the following features.

7. The apparatus according to claim 6, further comprising means for receiving authentication information in the first user device, wherein the authentication information includes the notification of the serving network name of the second user device.

8. The apparatus according to claim 7, further comprising means for receiving the authentication information in an extended authentication protocol message.

9. The network node receives notification of the serving network name of the first user device, and the first user device is configured to act as a relay between the second user device and the network by providing proximity service between the first user device and the second user device. Based on the serving network name of the first user device, the authentication vector for proximity service authentication of the second user device is determined, To provide the second user device with notification of the serving network name of the first user device, Methods that include...

10. The method according to claim 9, further comprising providing authentication information to the second user device, wherein the authentication information includes the notification of the serving network name of the first user device.

11. The method according to claim 10, further comprising providing the authentication information in at least one of a proximity service authentication response, a proximity service authentication request, or an extended authentication protocol message.

12. The method according to any one of claims 9 to 11, further comprising receiving the serving network name of the first user device via at least one of the access and mobility management functions associated with the first user device or the authentication server function associated with the second user device.

13. The first user device receives notification of the serving network name of the second user device, and the second user device is configured to act as a relay between the first user device and the network by providing proximity service between the first user device and the second user device. Based on the serving network name of the second user device, the authentication vector for proximity service authentication of the first user device is determined, Methods that include...

14. The method according to claim 13, further comprising receiving authentication information on the first user device, wherein the authentication information includes the notification of the serving network name on the second user device.

15. The method according to claim 14, further comprising receiving the authentication information within an extended authentication protocol message.

Citation Information

Patent Citations

  • Terminal, method, and program

    JP2022523936A

  • Methods and systems for identifying AUSF and accessing related keys in 5g prose

    WO2022019725A1