Method and system for managing user identity in wireless networks

KR1020260134682APending Publication Date: 2026-09-09SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
KR1020267020903
Authority / Receiving Office
KR · KR
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-01-03
Filing Date
2025-01-17
Publication Date
2026-09-09

Smart Images

  • Figure P1020267020903_ABST
    Figure P1020267020903_ABST
Patent Text Reader

Abstract

The present disclosure relates to a 5G or 6G communication system for supporting higher data transmission rates. A first SMF obtains a first PDU session request associated with a first user identifier, queries a UDM to obtain established PDU session information, receives a response from the UDM that there is no PDU session, establishes a first PDU session associated with a first user identifier, a second PDU session request associated with a second user identifier is obtained by a second SMF, the UDM queries the second SMF to obtain established PDU session information, a response regarding the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and the second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The embodiments disclosed herein relate to wireless communication networks, and more specifically, to a system and method for managing user identity in a wireless communication network. Background Technology

[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in frequency bands below 6 GHz ('Sub 6 GHz'), such as 3.5 GHz, but also in ultra-high frequency bands ('Above 6 GHz'), known as millimeter wave (mmWave), such as 28 GHz and 39 GHz. In addition, for 6G mobile communication technology, which is referred to as a system beyond 5G, implementation in the terahertz band (e.g., the 3 terahertz (3 THz) band at 95 GHz) is being considered to achieve transmission speeds 50 times faster and ultra-low latency reduced to one-tenth compared to 5G mobile communication technology.

[0003] In the early stages of 5G mobile communication technology, aiming to satisfy service support and performance requirements for enhanced Mobile BroadBand (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and Massive Machine-Type Communications (mMTC), technologies included beamforming and Massive MIMO to mitigate path loss and increase transmission distance in ultra-high frequency bands; support for various numerologies (such as the operation of multiple subcarrier spacing) and dynamic operation of slot formats for the efficient utilization of ultra-high frequency resources; initial access techniques to support multi-beam transmission and broadband; the definition and operation of Band-Width Parts (BWP); Low Density Parity Check (LDPC) codes for high-volume data transmission; new channel coding methods such as Polar Codes for the reliable transmission of control information; and L2 Standardization has been carried out for L2 pre-processing, network slicing which provides dedicated networks specialized for specific services, and the like.

[0004] Currently, discussions are underway to improve and enhance the performance of the initial 5G mobile communication technology, taking into account the services that the 5G mobile communication technology was intended to support. Additionally, standardization of the physical layer is in progress for technologies such as V2X (Vehicle-to-Everything), which helps autonomous vehicles make driving decisions and enhance user convenience based on their own location and status information transmitted by the vehicle; NR-U (New Radio Unlicensed), which aims for system operation in unlicensed bands to comply with various regulatory requirements; NR terminal low power consumption technology (UE Power Saving); Non-Terrestrial Network (NTN), which is direct terminal-satellite communication for securing coverage in areas where communication with the terrestrial network is impossible; and positioning.

[0005] In addition, standardization is also underway in the field of wireless interface architecture / protocols for technologies such as the Industrial Internet of Things (IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) which provides nodes to expand network service areas by integrating wireless backhaul and access links, Mobility Enhancement including Conditional Handover and Dual Active Protocol Stack (DAPS) Handover, and 2-step Random Access for NR which simplifies random access procedures. Standardization is also underway in system architecture / services regarding 5G baseline architectures (e.g., Service-based Architecture or Service-based Interface) to combine Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) to receive services based on UE locations.

[0006] When such 5G mobile communication systems are commercialized, connected devices, which are increasing explosively, will be connected to communication networks. Accordingly, it is expected that there will be a need to enhance the functionality and performance of 5G mobile communication systems and to integrate the operation of connected devices. To this end, new research is planned to be conducted on 5G performance improvement and complexity reduction, support for AI services, support for metaverse services, and drone communication using eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).

[0007] Furthermore, the advancement of these 5G mobile communication systems serves as a foundation for developing new waveforms to provide coverage in the terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas, and massive antennas, metamaterial-based lenses and antennas to improve coverage of terahertz band signals, high-dimensional spatial multiplexing technologies using Orbital Angular Momentum (OAM), and Reconfigurable Intelligent Surfaces (RIS); as well as full-duplex technologies to increase frequency efficiency and improve system networks of 6G mobile communication technologies, AI-based communication technologies that achieve system optimization by utilizing satellites and Artificial Intelligence (AI) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technologies that implement services at complexity levels exceeding the limits of UE operational capability using ultra-high-performance communication and computing resources. will do. means of solving the problem

[0008] In a first aspect of the present disclosure, a method is provided which is performed by a first session management function (SMF) in a wireless communication system, the method comprising: obtaining a first protocol data unit (PDU) session request associated with a first user identifier; querying a unified data management (UDM) to obtain established PDU session information; receiving a response from the UDM that there is no PDU session; and establishing a first PDU session associated with a first user identifier, wherein a second PDU session request associated with a second user identifier is obtained by a second SMF, the UDM is queried from the second SMF to obtain established PDU session information, a response regarding the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and the second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.

[0009] In a second aspect of the present disclosure, a first session management function (SMF) is provided in a wireless communication system, wherein the first SMF comprises: a transceiver; and at least one processor coupled to the transceiver, wherein the at least one processor obtains a first protocol data unit (PDU) session request associated with a first user identifier, queries a unified data management (UDM) to obtain established PDU session information, receives a response from the UDM that there is no PDU session, establishes a first PDU session associated with a first user identifier, a second PDU session request associated with a second user identifier is obtained by a second SMF, the UDM queries the second SMF to obtain established PDU session information, a response regarding the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and the second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.

[0010] In a third aspect of the present disclosure, a unified data management (UDM) is provided in a wireless communication system, the UDM comprises: a transceiver; and at least one processor coupled to the transceiver, and the at least one processor receives a first query from a first session management function (SMF) to obtain established PDU session information and transmits a response to the first SMF that there is no PDU session, and the first PDU session associated with the first user identifier is established, and receives a second query from the second SMF to obtain established PDU session information and transmits a response to the first PDU session associated with the first user identifier to the second SMF, and the second PDU session associated with the second user identifier is rejected by the second SMF with a cause code. Brief explanation of the drawing

[0011] Embodiments of the present invention are illustrated in the accompanying drawings, but similar reference numerals throughout the drawings indicate corresponding parts in various drawings. Embodiments of the present invention will be better understood from the following description with reference to the following exemplary drawings. Embodiments of the present invention are illustrated by examples in the accompanying drawings, among which: FIG. 1 illustrates a schematic diagram of a wireless network for managing user identifiers in user equipment (UE) according to one embodiment of the present disclosure; FIG. 2 illustrates a flowchart of a method for managing a user identity for authentication of a user identifier in a wireless communication network according to one embodiment of the present disclosure; FIG. 3 illustrates a flowchart of a method for managing user identity to exempt authentication in a wireless communication network according to one embodiment of the present disclosure; FIG. 4 is a sequence diagram illustrating a method for managing user identifiers while ensuring authentication, re-authentication, and cancellation of user identifiers in a wireless communication network according to one embodiment of the present disclosure; FIG. 5 illustrates a block diagram of a wireless network for managing user identifiers in a UE according to one embodiment of the present disclosure; FIG. 6 illustrates a flowchart illustrating a method for managing user identities by restricting multiple users from using a UE simultaneously, according to one embodiment of the present disclosure; FIG. 7 illustrates a flowchart illustrating a method for managing user identities by restricting multiple users from using a UE simultaneously, according to one embodiment of the present disclosure; FIG. 8 is a sequence diagram illustrating a method for managing user identifiers in a wireless communication network to limit multiple user identities accessing a service through a single device, according to one embodiment of the present disclosure; FIG. 9 illustrates a block diagram of a wireless network for managing user identifiers in a UE according to one embodiment of the present disclosure; FIG. 10 illustrates a flowchart illustrating a method for managing user identities by restricting multiple users from using a UE simultaneously, according to one embodiment of the present disclosure; FIG. 11 is a sequence diagram illustrating a method for managing user identifiers in a wireless communication network during a UE mobility scenario between AMF entities according to one embodiment of the present disclosure; FIGS. 12 and 13 illustrate other block diagrams of a wireless network for managing user identifiers in a UE according to one embodiment of the present disclosure; and FIG. 14 illustrates an exemplary sequence diagram as an example of managing multiple user identities in a wireless communication network according to one embodiment of the present disclosure. Specific details for implementing the invention

[0012] Embodiments of the present invention and their various features and advantageous details are more fully explained by reference to non-limiting embodiments illustrated in the accompanying drawings and detailed in the following description. Descriptions of widely known components and processing techniques are omitted to avoid unnecessarily obscuring the embodiments of the present invention. The examples used herein are merely to facilitate understanding of the ways in which the embodiments of the present invention may be carried out and to further enable those skilled in the art to carry out the embodiments of the present invention. Accordingly, the examples should not be construed as limiting the scope of the embodiments of the present invention.

[0013] For the purpose of interpreting this specification, definitions (as defined in this disclosure) may be applied, and where appropriate, terms used in the singular form may include the plural form and vice versa. It should be understood that the technical terms used in this disclosure are for the purpose of describing specific embodiments and are not intended to be limiting. The terms “comprising,” “having,” and “comprising” should be interpreted as open-ended terms unless otherwise stated.

[0014] The words / phrases “exemplary,” “example,” “example,” “in an instance,” “and the like,” “and so on,” “etc,” “etcetera,” “for example,” and “that is,” are used in this disclosure only to mean “serving as an example, instance, or example.” Any embodiment or embodiment of the subject matter of the invention described in this disclosure using the words / phrases “exemplary,” “example,” “example,” “in an instance,” “and the like,” “etc,” “etc,” “etc,” “for example,” and “that is,” is not necessarily to be interpreted as being preferred or advantageous across other embodiments.

[0015] The embodiments of the present invention may be described and illustrated in terms of the described functions or blocks performing the functions. These blocks, which may be referred to in the present disclosure as managers, units, modules, hardware components, etc., are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, etc., and may be optionally driven by firmware. The circuits may be implemented, for example, within one or more semiconductor chips or on substrate supports such as printed circuit boards. The circuits constituting the blocks may be implemented by dedicated hardware, by a processor (e.g., one or more programmed microprocessors and associated circuits), or by a combination of dedicated hardware performing some functions of the blocks and a processor performing other functions of the blocks. Each block of the embodiments may be physically separated into two or more interacting and individual blocks without departing from the scope of the present disclosure. Similarly, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the present disclosure.

[0016] It should be noted that elements in the drawings are illustrative for the purposes of this description and for convenience of understanding, and may not necessarily be drawn to scale. For example, flowcharts / sequence diagrams illustrate methods in terms of steps required to understand aspects of the embodiments disclosed in this disclosure. Furthermore, in terms of the configuration of the device, one or more components of the device may be represented in the drawings by conventional symbols, and the drawings may only illustrate specific details suitable for understanding the embodiments thereof in order not to obscure the drawings with details that would be readily apparent to a person skilled in the art who benefits from the description of this disclosure. Furthermore, in terms of the system, one or more components / modules comprising the system may be represented in the drawings by conventional symbols, and the drawings may only illustrate specific details suitable for understanding the embodiments thereof in order not to obscure the drawings with details that would be readily apparent to a person skilled in the art who benefits from the description of this disclosure.

[0017] It should be understood that the accompanying drawings are intended to aid in the easy understanding of various technical features and that the embodiments are not limited by the accompanying drawings. As such, the present disclosure should be interpreted as extending to any modifications, equivalents, and substitutions in addition to those presented particularly in the accompanying drawings and the description. The use of words such as first, second, third, etc., to describe components / elements / steps is for the purposes of this description and should not be interpreted as a sequential order / arrangement / occurrence unless otherwise specified.

[0018] Generally, by enhancing the 5th generation system (5GS) to allow the creation and use of user-specific identities, telecommunications operators can provide an enhanced user experience and optimized performance, and the telecommunications operator's 3rd generation partnership project (3rd It will be possible to provide services to devices (e.g., user devices (UEs)) and users that are not part of the Generation Partnership Project (3GPP) network. For example, network settings can be adjusted according to user needs and services can be provided to users, separate from the subscriber identifier used by users to establish a connection.

[0019] In the context of this task, the user to be identified may be an individual human user using the UE through a specific subscription, an application running on or connected through the UE, or a device behind a gateway UE (e.g., a PIN Element with Gateway Capability (PEGC)) (e.g., a PIN Element (PINE)).

[0020] Use cases were discussed in depth, and key issues (KIs) were added to Technical Report (TR) 23.700-32.

[0021] This core issue is based on the human user identification case of Core Issue #1 and focuses on how users are authenticated and authorized, and how networks restrict user identifiers. Solutions to this core issue address the following:

[0022] A. How users are authenticated and how and for what purpose users are authorized; and

[0023] B. How the network restricts the use of user identifiers, including in roaming scenarios.

[0024] Before providing and applying different policies to services based on user identifiers while accessing via a subscription (e.g., Subscription Permanent Identifier (SUPI)), the 5th generation core (5GC) network needs to identify the user identifier and then authenticate and authorize it. Likewise, to enhance security and ensure that the same user identifier that initiated the session is still using the service, the 5GC or an Application Function (AF) needs to re-authenticate the user identifier and, if necessary, revoke access to that user identifier.

[0025] In addition, use cases are discussed in detail in TR 22.904 and include one or more users (i.e., people) sharing a single UE and one or more users (i.e., devices) behind a single gateway UE. The reason for utilizing operator user-specific identities in 3GPP networks is to enable telecommunications operators to charge and provide service differentiation based on user identifiers.

[0026] To address the requirement to provide user-specific services when multiple users share the same device, 3GPP initiated a study in Release 19. The purpose of this study is not to move subscriber information to user profiles, and information from user profiles should not be used to override subscriber information. For example, the slices and Data Network Names (DNNs) available to a UE are not changed based on the UE's user. The work tasks focus on supporting use cases where a human user identifier is associated with traffic transmitted to or from the UE.

[0027] In addition, the task defines the architectural assumptions necessary to support the identification of user identifiers associated with UE traffic.

[0028] Furthermore, when a user identifier is applied to a human, it is assumed that only a single user identifier is associated with the UE at any given time, and that the user identifier is associated with all services accessed by the UE during the time the user identifier and the UE are associated. If multiple users are associated with a device, the network cannot identify which service is used by which user.

[0029] Therefore, the relevant technical field requires solutions to overcome the aforementioned disadvantage(s), including other factors.

[0030] The primary objective of the embodiments of the present invention is to disclose a system and method for managing user identifiers in a wireless communication network.

[0031] Another objective of the embodiments of the present invention is to disclose a procedure for supporting authentication and authorization of user identity.

[0032] Another objective of this embodiment is to address scenarios regarding how a network successfully authenticates and re-authenticates a user identifier and revokes access.

[0033] Another objective of the present embodiment is to disclose a system and method for identifying a user using a 5G wireless device and restricting multiple users from using the device simultaneously, wherein the network ensures that at any given time only one user identified by a user profile ID or a predetermined unique ID uses one or more services.

[0034] Another objective of the present embodiment is to limit multiple user identities accessing the service through a single device (e.g., a single UE).

[0035] Additionally, another objective of the embodiments of the present invention is for the SMF to initiate refusal to establish a PDU session if, according to a set / received policy, another user is already receiving service from the network using the same UE.

[0036] Additionally, another objective of the embodiments of the present invention is for the SMF to query the UDM to determine whether another user has already established a PDU before making a decision.

[0037] In addition, another objective of the embodiments of the present invention is to support a metaverse service (e.g.) that requires user validation by 5GC.

[0038] Accordingly, embodiments of the present invention provide a method for managing user identifiers in a wireless network. The method comprises the step of receiving, by a first session management function (SMF) entity, one of a protocol data unit (PDU) session request and a PDU session modification request from a user device (UE). The PDU session request includes a first user identifier (ID). The method further comprises the step of obtaining service priority information by the first SMF entity. The method further comprises the step of determining by the first SMF entity whether service priority information associated with the first user ID is more important than service priority information associated with a second user ID among a plurality of user IDs. In one embodiment of the present disclosure, the method further comprises the step of, by the first SMF entity, performing one of accepting the PDU session request and the PDU session modification request and sending a PDU session acceptance message to the UE in response to determining that service priority information associated with the first user profile ID is more important than service priority information associated with the second user profile ID by determining whether one PDU already exists for the second user ID associated with the UE. In another embodiment, the method includes the step of rejecting one of a PDU session request and a PDU session modification request and sending a PDU session rejection message to the UE with a cause code, in response to determining whether a PDU already exists for a second user ID associated with the UE, and determining that the service priority information associated with the first user profile ID is not more important than the service priority information associated with the second user profile ID.In another embodiment of the present disclosure, the method comprises the step of accepting one of a PDU session request and a PDU session modification request and sending a PDU session acceptance message to the UE when the first SMF entity does not consider service priority information associated with the first user ID and service priority information associated with the second user ID. In another embodiment of the present disclosure, the method comprises the step of rejecting one of a PDU session request and a PDU session modification request and sending a PDU session rejection message including a cause code to the UE when a PDU session associated with the second user profile ID is currently in progress by determining that a PDU session has already been established for the second user ID associated with the UE.

[0039] Accordingly, embodiments of the present invention provide a method for managing user identifiers in a wireless network. The method comprises the step of updating a UE context associated with a first user profile in a data storage entity by a first network entity. This UE context includes at least one of user identification information, profile information, and subscription information when it is determined that the first user profile associated with the UE has been successfully authenticated and authorized when the first user profile associated with the UE triggers at least one network access procedure for the first user. A second user associated with a second user profile has already been authenticated by a second network entity. The UE context associated with the second user profile has already been updated in the data storage entity by the second network entity.

[0040] Accordingly, embodiments of the present invention provide a method for managing user identity in a wireless network, the method comprising the step of receiving, by a first Access and Mobility Management Function (AMF) entity, one of a Protocol Data Unit (PDU) session request and a PDU session modification request from a UE, wherein the PDU session request includes a first user profile identifier (ID). The method further comprises the step of obtaining service priority information by the first AMF entity. The method further comprises the step of determining by the first AMF entity whether service priority information associated with the first user profile ID is more important than service priority information associated with a second user profile ID among a plurality of user profile IDs. The method further comprises the step of, if a PDU has already been provided for the second user profile ID, by the first AMF entity accepting one of the PDU session request and the PDU session modification request and transmitting a PDU session acceptance message to the UE in response to the determination that service priority information associated with the first user profile ID is more important than service priority information associated with the second user profile ID. In another embodiment of the present disclosure, the method further comprises the step of rejecting one of a PDU session request and a PDU session modification request and sending a PDU session rejection message with a cause code to the UE in response to determining that service priority information associated with a first user profile ID is not more important than service priority information associated with a second user profile ID, when a PDU has already been provided for a second user profile ID.In another embodiment of the present disclosure, the method further comprises the step of accepting one of a PDU session request and a PDU session modification request and sending a PDU session acceptance message to the UE when the first AMF entity does not consider service priority information associated with the first user profile ID and service priority information associated with the second user profile ID. In another embodiment of the present disclosure, the method further comprises the step of rejecting one of a PDU session request and a PDU session modification request when a PDU session associated with the second user profile ID is currently in progress by verifying that a PDU session has been established for the second user profile ID associated with the UE, and sending a PDU session rejection message to the UE along with a cause code.

[0041] Accordingly, embodiments of the present invention provide a method for managing a user identifier in a wireless network. The method includes the step of receiving, by an SMF entity, a request to establish a PDU session for a first user identifier from a UE. The method further includes the step of querying at least one data storage entity by the SMF entity to retrieve subscriber data information along with user identifier information associated with the subscriber persistent identifier (SUPI) of the UE's first user identifier. The method further includes the step of determining by the SMF entity whether authentication for the first user identifier is enabled or disabled. The method further includes the step of obtaining, by the SMF entity, subscriber data information along with user identifier information associated with the SUPI from at least one data storage entity when authentication for the first user identifier is enabled. The method further includes the step of querying by the SMF entity to obtain information that there is no authentication result for the first user identifier. The method further includes the step of triggering authentication for the first user identifier by the SMF entity.

[0042] Accordingly, embodiments of the present invention provide a first session management function (SMF) entity for managing user identity in a wireless network, said SMF entity comprising a processor, memory, and a user identity management control unit combined with the processor and memory. This user identity management control unit is configured to receive one of a PDU session request and a PDU session modification request from a UE. The PDU session request includes a first user identifier (ID). The user identity management control unit is further configured to obtain service priority information. The user identity management control unit is further configured to determine whether the service priority information associated with the first user ID is more important than the service priority information associated with a second user ID among a plurality of user IDs. In one embodiment of the present disclosure, the user identity management control unit is further configured to perform one of accepting a PDU session request and a PDU session modification request and sending a PDU session acceptance message to the UE in response to determining that the service priority information associated with the first user profile ID is more important than the service priority information associated with the second user profile ID by determining whether a PDU already exists for a second user ID associated with the UE. In one embodiment of the present disclosure, the user identity management control unit is further configured to reject one of a PDU session request and a PDU session modification request and send a PDU session rejection message to the UE with a cause code in response to determining that the service priority information associated with the first user profile ID is not more important than the service priority information associated with the second user profile ID by determining whether a PDU already exists for a second user ID associated with the UE.In one embodiment of the present disclosure, the user identity management control unit is further configured to accept one of a PDU session request and a PDU session modification request and send a PDU session acceptance message to the UE when the first SMF entity does not consider service priority information associated with the first user ID and service priority information associated with the second user ID. In one embodiment of the present disclosure, the user identity management control unit is further configured to reject one of a PDU session request and a PDU session modification request and send a PDU session rejection message to the UE with a cause code when a PDU session associated with the second user profile ID is currently in progress by determining that a PDU session has already been established for the second user ID associated with the UE.

[0043] Accordingly, embodiments of the present invention provide a first network entity for managing user identity in a wireless network, wherein the first network entity comprises a processor, memory, and a user identity management control unit combined with the processor and memory. The user identity management control unit is configured to update a UE context associated with a first user profile in a data storage entity. The UE context includes at least one of user identification information, profile information, and subscription information when it is determined that the first user profile associated with the UE has been successfully authenticated and authorized when the first user profile associated with the UE triggers at least one network access procedure for the first user. A second user associated with a second user profile has already been authenticated by a second network entity. The UE context associated with the second user profile has already been updated in the data storage entity by the second network entity.

[0044] Accordingly, embodiments of the present invention provide a first Access and Mobility Management Function (AMF) entity for managing user identity in a wireless network, comprising a processor, memory, and a user identity management control unit coupled with the processor and memory. The user identity management control unit is configured to receive one of a PDU session request and a PDU session modification request from a UE. The PDU session request includes a first user identifier (ID). The user identity management control unit is further configured to obtain service priority information. The user identity management control unit is further configured to determine whether the service priority information associated with the first user ID is more important than the service priority information associated with a second user ID among a plurality of user IDs. In one embodiment of the present disclosure, the user identity management control unit is further configured to perform one of accepting a PDU session request and a PDU session modification request and sending a PDU session acceptance message to the UE in response to determining that the service priority information associated with the first user profile ID is more important than the service priority information associated with the second user profile ID by determining whether a PDU already exists for a second user ID associated with the UE. In one embodiment of the present disclosure, the user identity management control unit is further configured to reject one of a PDU session request and a PDU session modification request and send a PDU session rejection message to the UE with a cause code in response to determining that the service priority information associated with the first user profile ID is not more important than the service priority information associated with the second user profile ID by determining whether a PDU already exists for a second user ID associated with the UE.In one embodiment of the present disclosure, the user identity management control unit is further configured to accept one of a PDU session request and a PDU session modification request and send a PDU session acceptance message to the UE when the first SMF entity does not consider service priority information associated with the first user ID and service priority information associated with the second user ID. In one embodiment of the present disclosure, the user identity management control unit is further configured to reject one of a PDU session request and a PDU session modification request and send a PDU session rejection message to the UE with a cause code when a PDU session associated with the second user profile ID is currently in progress by determining that a PDU session has already been established for the second user ID associated with the UE.

[0045] Accordingly, embodiments of the present invention provide an SMF entity for managing user identifiers in a wireless network, wherein the SMF entity comprises a processor, memory, and a user identifier management control unit coupled with said processor and memory. The user identity management control unit is configured to receive a request to establish a PDU session for a first user identifier from a user device (UE). The user identity management control unit is further configured to query at least one data storage entity to retrieve subscriber data information along with user identifier information associated with the subscriber persistent identifier (SUPI) of the first user identifier of the UE. The user identity management control unit is further configured to determine whether authentication for the first user identifier is enabled or disabled. The user identity management control unit is further configured to obtain subscriber data information along with user identifier information associated with the SUPI from at least one data storage entity if authentication for the first user identifier is enabled. The user identity management control unit is further configured to query to obtain information that there is no authentication result for the first user identifier. The user identity management control unit is further configured to trigger authentication for the first user identifier.

[0046] These and other aspects of the embodiments of the present invention will be better recognized and understood when considered in conjunction with the following description and the accompanying drawings. However, it should be understood that the following description represents at least one embodiment and numerous specific details thereof, but is given as an example and is not intended to be limiting. Many changes and modifications may be made within the scope of the embodiments of the present invention, without departing from the scope thereof, and the embodiments of the present invention include all such modifications.

[0047] The embodiments of the present invention provide a system and a method for managing user identifiers in a wireless communication network.

[0048] In one embodiment of the present disclosure, according to a set / received policy, if another user is already being served from the network using the same UE, the SMF refuses to establish a PDU session. Before making a decision, the SMF queries the UDM to determine whether another user has already established a PDU. The proposed method supports a metaverse service that requires user verification by 5GC.

[0049] In one embodiment of the present disclosure, when a specific user calls a specific application, the UE triggers the establishment of a PDU session by providing the corresponding user identifier (e.g., a first user (user1)) to the network. After successful authentication and authorization of the user identifier, the SMF entity queries the UDM entity to check whether there is a PDU session established with the user identifiers. If it receives a response from the UDM entity that there is no PDU session, the SMF entity processes the ongoing PDU session, and then the PDU session is successfully established. The SMF entity stores this user identifier in the UDM along with the PDU session ID (PDU1).

[0050] In one embodiment of the present disclosure, when another user is running a different application (e.g., when the device is idle and the first user is not using the device), the UE triggers the establishment of a new PDU session by providing the corresponding user identifier (e.g., User2 (the second user)) to the network. If the same SMF that handled the previous PDU session receives the PDU session, the SMF entity can identify that a user identifier (the first user) has already established a PDU session. Then, the SMF entity rejects the PDU session for the second user by providing an appropriate cause code.

[0051] In one embodiment of the present disclosure, if another SMF receives a PDU session, the SMF first queries a UDM to check whether there is a PDU session established with user identifiers. If the SMF receives a response from the UDM regarding an already established PDU session (e.g., PDU1) with the user identifier of the first user, the SMF rejects the PDU session for the second user by providing an appropriate cause code.

[0052] In one embodiment of the present disclosure, there may be some policy provided by AF for user identifiers made available in an SMF entity that indicates priorities among user identifiers while accessing the service through the same subscription (e.g., may be received from a UDM entity while acquiring SM subscriber data, and may include associated user identifier details). If the policy indicates that a second user has a higher priority than a first user, the SMF provides instructions to the UDM to accept a PDU session for the second user and release a session for the first user. The UDM must trigger the release of the first user's PDU session.

[0053] The proposed method helps telecommunications operators identify actual users accessing devices (or UEs) to receive services from a network and provide service differentiation based on user identifiers.

[0054] Now, with reference to the drawings, specifically FIGS. 1 through 14, in which similar reference numerals consistently indicate corresponding features throughout the drawings, embodiments are illustrated.

[0055] FIG. 1 illustrates a schematic diagram of a wireless network (100) for managing user identifiers in a user device (UE) (102) according to one embodiment of the present disclosure. The wireless network (100) may be, for example, a fourth-generation wireless network, a fifth-generation wireless network, an Open Radio Access Network (ORAN), etc. The wireless network (100) includes one or more UEs (102), one or more network entities (NE) (104), and a data storage entity (106). The network entities (104) may include, but are not limited to, 5G / EUTRAN (5th generation evolved universal terrestrial radio access networks) core network entities, including an access and mobility management function (AMF) entity, a session management function (SMF) entity, an access and mobility management function (MME) entity, and a user plane function (UPF) entity. The wireless network may include (5G / EUTRAN) RAN entities including eNodeB (eNB), gNodeB (gNB), and NG-RAN. The UE (102) may be, for example, a laptop, smartphone, desktop computer, notebook, D2D (Device-to-Device) device, V2X (vehicle to everything) device, foldable phone, smart TV, tablet, television, connected car, immersive device, Internet of Things (IoT) device, or any other device capable of communicating using the wireless network, but is not limited thereto.

[0056] In one embodiment of the present disclosure, the data storage entity (106) may include at least one of a unified data management (UDM), a user data repository (UDR), an application function (AF) entity, and a network function (NF) entity.

[0057] In one embodiment of the present disclosure, a network entity (104) may include one or more network entities. The network entity (104) may include, but is not limited to, a first SMF entity (110), a second SMF entity (115), a first AMF entity (120), and a second AMF entity (125).

[0058] In one embodiment of the present disclosure, a data storage entity (106) may have already received user identifier information associated with a SUPI of a UE (102) for a specific service, which is stored as subscriber data information associated with a subscriber persistent identifier (SUPI). The user identifier information includes details regarding whether authentication and authorization for each user identifier are enabled or disabled on a service-by-service basis.

[0059] For example, assume a scenario in which some user identifiers are set on a user device (UE) (102), such as a first user and a second user. When the UE (102) registers with a network using a specific user identifier, the network needs to authenticate the user identifiers before the network entity (104). The network entity (104) is, for example, an AMF entity (at least one of the first AMF entity (120) or the second AMF entity (125). Now, assuming that only the first AMF entity (120) is used in this scenario, the first AMF (120) can receive a PDU session request from the first user. The first AMF entity (120) can query the data storage entity (106) for subscriber data information along with user identifier information associated with the subscriber persistent identifier (SUPI) of the UE (102)'s first user identifier. The first AMF entity (120) can determine whether authentication for the first user identifier is enabled or disabled. The first AMF entity (120) can query the data storage entity (106) to obtain information that an authentication result exists or does not exist for the first user identifier. If an authentication result for the first identifier does not exist but authentication for the first identifier is enabled, the first AMF entity (120) can trigger authentication for the first user identifier. The network entity (104) enables user identifiers to use services from the network. In one embodiment of the present disclosure, when a UE (102) registers with the network and the UE (102) provides all user identifiers, if the Access and Mobility Management (AMF) entity has user profile information for each of the user identifiers that enables the user identifier to use services using a specific subscription, the 5GC triggers authentication for all user identifiers.

[0060] In one embodiment of the present disclosure, there may be some user identifiers for which authentication is exempt. Based on subscription information received from the data storage entity (106), the first AMF entity (120) may trigger authentication only for certain specific user identifiers. In one embodiment of the present disclosure, when user identifiers are set on the UE (102), the UE (102) stores authentication credentials for each user identifier so that the device can transmit credentials when the network triggers authentication for the user identifiers.

[0061] In one embodiment of the present disclosure, it is assumed that a first SMF entity (110) receives a user identifier from a UE (102) (for an SMF entity (either the first SMF entity (110) or the second SMF entity (115)). The first SMF entity (110) checks, via a data storage entity (106), whether the first SMF entity (110) possesses user profile information for user identifiers that allows the user identifier to use the service using a specific subscription that is activated. The first SMF entity (110) triggers authentication for the user identifiers even when the specific user identifier has started using the service.

[0062] In one embodiment of the present disclosure, based on an authentication approach (before session establishment by the AMF entity (120, 125) or during session establishment by the SMF entity (110, 115), the network entity (104) determines that no user identifier exists in the request received from the UE (102). If no user identifier exists, the network entity (104) retrieves subscriber data information from the data storage entity (106). The subscriber data information may include user identifier information associated with the SUPI of the UE (102). If the subscriber data information is available in the data storage entity (106), the network entity (104) uses the default subscriber data information present in the data storage entity (106) for the SUPI without considering the user identifier information.

[0063] In one embodiment of the present disclosure, based on an authentication approach (before session establishment by the AMF entity (120, 125) or during session establishment by the SMF entity (110, 115), if the network entity (104) identifies that the user identifier does not exist in the request received from the UE (102) and that the subscriber data information received from the data storage entity (106) includes user identifier information associated with the SUPI, it is proposed that the network entity (104) resend a request to the UE (102) to notify it to add / share the user identifier. The UE (102) will then add the user identifier to the network.

[0064] In one embodiment of the present disclosure, it is proposed that some user identifiers be exempt from authentication, which means that the network entity (104) (the first SMF entity (110)) may trigger authentication only for some specific user identifiers based on subscription information from the data storage entity (106). In this case, since the user itself may provide credentials during authentication, it is not mandatory for the user identifiers set in the UE (102) to store authentication credentials.

[0065] In one embodiment of the present disclosure, it is proposed that the result of user identifier authentication by the first AMF entity (120) (if performed) be shared with the target AMF entity, i.e., the second AMF entity (125), in an AMF entity change scenario so that user identifiers are not authenticated every time. Similarly, if performed by the SMF entity (110), when another protocol data unit (PDU) session is received by the same first SMF entity (110), the first SMF entity (110) must store the authentication to grant an exemption for the same user identifier. For other SMF entities, for example, a user is authenticated for UE (102) through the first SMF entity (110), and a second user requests a PDU session from the same UE (102) on the second SMF entity (115), at which time the first SMF entity (110) has already updated the authentication result within the data storage entity (106) (UE_CM_Register or UE_CM_Update service operation). When the first SMF entity (110) receives any PDU session for a single user identifier, it first fetches the authentication result from the data storage entity (106). If a successful result is received, the first SMF entity (110) does not trigger authentication again. In a subsequent attempt, before triggering authentication for the second user identifier on the second SMF entity (115), authentication from the data storage entity (106) is fetched by the second SMF entity (115).

[0066] In one embodiment of the present disclosure, a network entity (104) may trigger re-authentication of a user identifier. If re-authentication fails, active sessions may be terminated (if any) based on AF / operator policy. A user identifier may have multiple active sessions using different subscriptions. If re-authentication fails while executing for a specific subscription, sessions using that specific subscription may be terminated or all subscriptions may be terminated based on AF / operator policy.

[0067] In one embodiment of the present disclosure, consider a scenario in which a UE (102) is already registered and one of the user identifiers having a user profile ID or a predetermined unique ID (e.g., a first user identifier) ​​enables the user to use the service from the network upon successful authentication and authorization of the user. For example, a first SMF entity (110) has successfully authenticated and authorized the user. During or after successful establishment of a PDU session, the first SMF entity (110) uses the Nudm_UECM_Create service operation to update the data storage entity (106) with a UE context having additional information about the user identifier associated with the user. If another user having a different user profile ID (e.g., a second user identifier) ​​initiates a PDU session and the request reaches the same first SMF entity (110) (which already has UE SM context information), the first SMF entity (110) may determine that one user (the first user identifier) ​​is already using the service. Then, the first SMF entity (110) may reject the PDU session for the second user identifier with an appropriate cause code for the UE (102). The first SMF entity (110) further proceeds with the authentication and authorization of the second user identifier only if the second user identifier is allowed to establish a PDU session based on user authentication information from the data storage entity (106) that there is no active ongoing PDU session on the UE (102) by another user identifier on any SMF entity, and if the request to establish a PDU session is rejected otherwise, the authentication and authorization may be skipped.

[0068] In one embodiment of the present disclosure, the SMF entity is (assuming the first SMF entity (110) receives a request to establish a PDU session from a user, the first SMF entity (110) or the second SMF entity (115)). The first SMF entity (110) may check priority information associated with all user identifiers associated with the UE (102). The SMF entity (110) may download only the user identifier information associated with the user identifier requesting the PDU session. In one embodiment of the present disclosure, the SMF entity (110) may download all user identifier information from the data storage entity (106). The user identifier information may be stored in the data storage entity (106) or in local settings available in the first SMF entity (110). These priority information per user profile for a single UE (102) may be set by a telecommunications carrier or a third party providing user identities. When the first user identifier is already using the service on the UE (102) and the second user identifier requests the establishment of a PDU session to the first SMF entity (110), the first SMF entity (110) checks the priority information of the first user identifier and the second user identifier. The first SMF entity (110) obtains that the second user identifier (who initiated the new PDU session) has a higher priority than the first user identifier, and then determines whether a PDU already exists for the user identifier associated with the UE (102), thereby allowing the existing PDU of the first user identifier to be released and the new PDU session for the second user identifier to be accepted by the first SMF entity (110).

[0069] In one embodiment of the present disclosure, consider a case where a first user identifier of a UE (102) has an established PDU session and is using a service through a first SMF entity (110). A request for a second PDU session of a second user identifier from the same UE (102) reaches a second SMF entity (115) (different from the SMF that processed the first PDU session from the first user identifier). The second SMF entity (115) may not have any context information about the UE (102) and cannot know whether the first user identifier has an established PDU session on any other SMF entity. In this case, the second SMF entity (115) identifies any existing PDU session on the UE (102) by querying the data storage entity (106) by transmitting a Nudm_UECM_Get operation. The second SMF entity (115) may receive information from the data storage entity (106) that the first user identifier has an active PDU session with the UE (102) through the first SMF entity (110). Then, the second SMF (115) may apply all logic as proposed for the same SMF scenario. The second SMF entity (115) may determine that the first user identifier is already using the service from the first SMF entity (110). Then, the second SMF entity (115) may reject the PDU session for the UE (102), including an appropriate cause code. The decision to allow or reject new PDU sessions and to release or maintain existing PDU sessions may be part of the carrier policy, or if the user identifiers are provided by a third party, the third party may provision the policy for that case.

[0070] In one embodiment of the present disclosure, instead of the SMF entity deciding to allow or reject PDU sessions from the second user identifier and to release or maintain the first PDU session of the first user identifier, the data storage entity (106) may be an anchor network function (NF). Here, when the first SMF entity (110) processing the second user receives a PDU session and transmits a Nudm_UECM_Create service operation to add the user identifier to the data storage entity (106), the data storage entity (106) may determine how to process the new PDU session of the second user identifier and the existing PDU of the first user identifier as described for the same SMF scenario. If there is an ongoing PDU session on the first SMF entity (110) by the first user, and the data storage entity (106) needs to reject the PDU session for the second user identifier, the data storage entity (106) may trigger a rejection message to the second SMF entity (115) including an appropriate cause code. The second SMF entity (115) may reject the PDU session with an appropriate cause code. If the data storage entity (106) decides to accept the PDU session for the second user identifier (based on available carrier or third-party policies), the data storage entity (106) sends a release message for the first user identifier to the first SMF entity (110) including an appropriate cause code. The first SMF entity (110) has released the PDU session for the first user identifier with an appropriate cause code.

[0071] The messages used or indicated in this embodiment are illustrated as examples. These messages may be any signaling messages between the UE (102) and network functions / entities (104) or between different network functions / entities (104).

[0072] Similarly, the service operation names given in this disclosure are for illustrative purposes only. Any other name may be used to convey information.

[0073] FIG. 2 illustrates a flowchart of a method (200) for managing user identity for authentication of a user identifier in a wireless communication network (100) according to one embodiment of the present disclosure. In step 202, (e.g.) an SMF entity (220) receives a request from a UE (102) to establish a Protocol Data Unit (PDU) session for a first user identifier. In step 204, the SMF entity (220) queries a data storage entity (106) to retrieve subscriber data information along with user identifier information associated with the subscriber persistent identifier (SUPI) of the first user identifier of the UE (102). In step 206, the SMF entity (220) determines whether to enable or disable authentication for the first user identifier based on the subscriber data information along with the user identifier information associated with the SUPI. When authentication for the first user identifier is enabled, the SMF entity (220) obtains subscriber data information from at least one data storage entity (106) along with user identifier information associated with SUPI, and at step 208, the SMF entity (220) queries the data storage entity (106) again to obtain information regarding the existence or absence of an authentication result for the first user identifier. At step 210, if an authentication result is absent and authentication for the first user identifier is enabled, the SMF entity (220) triggers authentication for the first user identifier. At step 212, if authentication for the first user identifier is disabled, the SMF entity (220) may not trigger authentication for the first user identifier. In one embodiment of the present disclosure, the SMF entity (220) skips authentication when authentication for the first user identifier is disabled. In one embodiment of the present disclosure, the SMF entity (220) skips authentication if the authentication result for the first user identifier or the user identifier requesting the PDU session already exists in the data storage entity (106).

[0074] Various actions in the method (200) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 2 may be omitted.

[0075] FIG. 3 illustrates a flowchart of a method (300) for managing user identity to exempt authentication in a wireless communication network (100) according to one embodiment of the present disclosure. In step 302, (e.g.) an SMF entity (220) receives a request to establish another PDU session for a second user identifier from a UE (102) to use a service. In step 304, the SMF entity (220) queries a data storage entity (106) to retrieve subscriber data information along with user identifier information associated with the subscriber persistent identifier (SUPI) of the second user identifier of the UE (102). In step 306, the SMF entity (220) determines whether to enable or disable authentication for the second user identifier based on the subscriber data information along with the user identifier information associated with the SUPI. The SMF entity (220) determines, for example, that user identifier authentication for the second user identifier is enabled and authentication for the received service request is exempted. At step 308, the SMF entity (220) avoids triggering authentication for the second user identifier based on a decision that authentication for the received service is exempted. In one embodiment of the present disclosure, the SMF entity (220) skips authentication if authentication for the user identifier requesting the PDU session is disabled.

[0076] Various actions in the method (300) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 3 may be omitted.

[0077] FIG. 4 is a sequence diagram illustrating a method (400) for managing user identifiers while ensuring authentication, re-authentication, and cancellation of user identifiers in wireless communication networks (100) according to one embodiment of the present disclosure. In step 402, a data storage entity (106) may receive associated user identifier information for a SUPI, or the user identifier information is set in the subscriber data of the data storage entity (106). The user identifier information and the subscriber data information include details such as the activation or deactivation of authentication for each user identifier. If authentication is activated for a user identifier, the authentication is performed on a service-by-service basis. In step 404, a first UE (102) transmits a PDU session establishment for a first user identifier. For example, the UE (102) is used by the first user identifier, or an application is invoked on the UE (102) and the first user is set in the application. In step 406, the SMF entity (220) obtains subscriber data information from the data storage entity (106) along with user identifier information associated with SUPI. The SMF entity (220) determines that user identifier authentication for the first user is enabled. In step 408, the SMF entity (220) queries the data storage entity (106) again for the authentication result of the first user identifier and obtains information that there is no authentication result for the first user identifier. In step 410, the SMF entity (220) triggers authentication for the first user identifier.

[0078] In one embodiment of the present disclosure, at step 412, the second user identifier transmits a PDU session establishment to the service (e.g., to make one IMS call). For example, the same UE (102) is used by the second user identifier, or another application is invoked on the UE (102) and the second user is established in that application. At step 414, the SMF entity (220) obtains subscriber data information from the data storage entity (106) along with user identifier information associated with the SUPI. If the SMF entity (220) determines that user identifier authentication for the second user identifier is enabled but user identifier authentication for the requested service (e.g., IMS DNN) is disabled, authentication is waived. At step 416, based on the fact that authentication for the requested service is waived, the SMF entity (220) does not trigger user identifier authentication for the second user identifier.

[0079] The SMF entity receives a re-authentication request from the application function (AF). Based on the re-authentication request, the SMF entity triggers authentication for the first user identifier by sending an authentication request to the UE.

[0080] In one embodiment of the present disclosure, an SMF entity receives a cancellation message from an application function (AF). Based on the cancellation message, the SMF entity terminates established PDU sessions associated with a first user identifier by providing an appropriate cause code.

[0081] Various actions in the method (400) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 4 may be omitted.

[0082] FIG. 5 illustrates a block diagram of a wireless network (100) for managing user identifiers in a UE (102) according to one embodiment of the present disclosure. In one embodiment of the present disclosure, the network entity (104) may include an SMF entity (220). The SMF entity (220) may include, but is not limited to, a processor (502), a memory (504), a user identity management control unit (508), and a transceiver (506). The user identity management control unit (508) is coupled with the processor (502), the memory (504), and the transceiver (506). The SMF entity (220) may communicate with the UE (102) and the data storage entity (106) through the transceiver (506). In one embodiment of the present disclosure, the UE (102) includes a control unit (512) and a transceiver (510). The control unit (512) communicates with the SMF entity (220) through the transceiver unit (510). The wireless network may include, but is not limited to, a plurality of network entities available within the network coverage area of ​​the UE. The first network entity, the second network entity, the first SMF entity, and the second SMF entity are used only for exemplary purposes.

[0083] Memory (504) is configured to store instructions to be executed by the processor (502). Memory (504) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of EPROM (electrically programmable memories) or EEPROM (electrically erasable and programmable memories). Additionally, memory (504) may be considered, in some examples, as a non-transient storage medium. The term "non-transient" may indicate that the storage medium is not implemented by a carrier wave or a propagating signal. However, the term "non-transient" should not be interpreted as meaning that the memory is non-removable. In some examples, memory (504) is configured to store a larger amount of information. In certain examples, the non-transient storage medium may store data that may change over time (e.g., in RAM (Random Access Memory) or a cache).

[0084] The processor (502) may include one or more processors. The one or more processors may be general-purpose processors such as a central processing unit (CPU) or an application processor (AP), graphics-only processing units such as a graphics processing unit (GPU) or a visual processing unit (VPU), and / or AI-only processors such as a neural processing unit (NPU). The processor (502) may include multiple cores and is configured to execute instructions stored in memory (504).

[0085] In one embodiment of the present disclosure, the transceiver (506) includes an electronic circuit specialized for a standard that enables wired or wireless communication. The transceiver (506) is configured to communicate internally between internal hardware components of the UE (102) and with external devices through one or more networks.

[0086] In one embodiment of the present disclosure, a user identity management control unit (508) identifies, authenticates, and re-authenticates a user before using any service from a network.

[0087] FIG. 6 illustrates a flowchart illustrating a method (600) for managing user identities by restricting multiple users from using the UE (102) simultaneously, according to one embodiment of the present disclosure. An embodiment of the present invention discloses the same SMF entity scenario. Operations 602 through 622 are processed by a user identity management control unit (508). In step 602, the first SMF entity (110) receives one of a PDU session request and a PDU session modification request from the UE (102) associated with the first user identifier (ID).

[0088] In step 604, the first SMF entity (110) queries the data storage entity (106) to retrieve subscriber data information along with user identifier information of the first user identifier or another user identifier associated with the UE (102) having an active ongoing PDU session.

[0089] In step 606, the first SMF entity (110) determines, based on a local policy, whether there is a PDU session associated with the second user identifier of the UE (102), or whether any other user identifier has an ongoing PDU session with the UE.

[0090] In step 608, the first SMF entity (110) obtains service priority information of the first user identifier. The first SMF entity (110) obtains service priority information from the data storage entity (106) or from the AMF entity (120 or 125) while downloading subscription information as part of PDU request processing.

[0091] In step 610, the first SMF entity (110) determines whether the service priority information associated with the first user ID is more important than the service priority information associated with the second user ID among the multiple user IDs.

[0092] In step 612, if it is determined that the service priority information associated with the first user profile ID is more important than the service priority information associated with the second user profile ID, and if it is determined that one PDU already exists for the second user ID associated with the UE (102), the first SMF entity (110) accepts either a PDU session request or a PDU session modification request. Regardless of whether the UE (102) is currently conducting a PDU session associated with a user identifier on any SMF entity, the PDU session is accepted because the priority of the first user ID is higher than that of the second user ID. The SMF entity (110) sends a PDU session acceptance message to the UE (102) in response to the accepted PDU session.

[0093] In one embodiment of the present disclosure, at step 614, the first SMF entity (110) releases the ongoing PDU session from the second user identifier of the UE (102) in order to establish a new PDU session with the first user identifier of the UE (102).

[0094] In one embodiment of the present disclosure, at step 616, if it is determined that the service priority information associated with the first user profile ID is less important than the service priority information associated with the second user profile ID by determining whether a PDU already exists for the second user ID associated with the UE (102), the first SMF entity (110) rejects one of the PDU session request and the PDU session modification request and sends a PDU session rejection message containing a cause code to the UE (102) in response to the rejection of the PDU session.

[0095] In one embodiment of the present disclosure, at step 618, if it is determined that there is no other user ID having an ongoing PDU session with the UE (102), and if the first SMF entity (110) does not consider service priority information associated with the first user ID and service priority information associated with the second user ID, the first SMF entity (110) accepts one of a PDU session request and a PDU session modification request. The first SMF entity (110) sends a PDU session acceptance message to the UE (102).

[0096] In one embodiment of the present disclosure, at step 620, when it is determined that a PDU session associated with a second user profile ID is currently in progress by determining that a PDU session for a second user ID associated with UE (102) has already been established, and when the first SMF entity (110) does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID, the first SMF entity (110) rejects one of the PDU session request and the PDU session modification request. When the first SMF entity (110) rejects the PDU session of the first user ID, it sends a PDU session rejection message containing a cause code to the UE (102).

[0097] In step 622, the first SMF entity (110) updates the UE context within the data storage entity (106) with at least one piece of information associated with the first user profile ID during at least one of the time during the PDU session establishment and after the successful establishment of the PDU session. The first SMF entity (110) updates the UE context within the data storage entity (106) with at least one piece of information associated with the second user profile ID during at least one of the time during the PDU session establishment and after the successful establishment of the PDU session. In one embodiment of the present disclosure, the first SMF entity (110) updates the UE context within the data storage entity (106) with at least one piece of information of the user profile ID using at least one of the Nudm_UECM_Create service operation and the Nudm_UECM_Update service operation.

[0098] In one embodiment of the present disclosure, when one of the PDU session request and the PDU session modification request is accepted, the first SMF entity (110) allows authentication and authorization of the first user identifier on the first SMF entity (110).

[0099] In one embodiment of the present disclosure, while accepting one of a PDU session request and a PDU session modification request and sending a PDU session acceptance message to the UE, the SMF entity releases an existing PDU session for a second user ID associated with the UE. In one embodiment of the present disclosure, while accepting one of a PDU session request and a PDU session modification request and sending a PDU session acceptance message to the UE, the SMF entity releases the UE context associated with the second user ID.

[0100] Various actions in the method (600) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 6 may be omitted.

[0101] FIG. 7 illustrates a flowchart illustrating a method (700) for managing user identities by restricting multiple users from using the UE (102) simultaneously, according to one embodiment of the present disclosure. An embodiment of the present invention discloses two different SMF entity scenarios. In step 702, a second SMF entity (115) receives one of another PDU session request and another PDU session modification request from the UE (102) associated with a second user identifier.

[0102] In step 704, the second SMF entity (115) queries the data storage entity (106) to determine whether any user having a PDU session with the second user or UE (102) is already associated with the UE (102) through the current PDU session or another PDU session.

[0103] In step 706, the second SMF entity (115) receives information regarding the existence of a user having a PDU session associated with the first user of the UE (102) or a PDU session with the first SMF entity (110) based on a local policy.

[0104] In step 708, when the second SMF entity (115) receives information regarding the existence of a user having a PDU session with the first user of the UE (102) or a PDU session with the UE (102), it rejects one of the request for another PDU session and another request for modification of the PDU session from the second user from the UE (102) with the cause code.

[0105] In step 710, the second SMF entity (115) accepts one of another PDU session request and another PDU session modification request from the UE (102) if the ongoing PDU session for the UE (102) is not received by the second SMF entity (115).

[0106] In one embodiment of the present disclosure, the second SMF entity (115) can check priority information associated with all user identifiers associated with the UE (102). The second SMF entity (115) can download only the user identifier information associated with the user identifier requesting the PDU session. In one embodiment of the present disclosure, the second SMF entity (115) can download all user identifier information from the data storage entity (106). The user identifier information may be stored in the data storage entity (106) or in local settings available in the SMF entities (220). These priority information per user identifier for a single UE (102) may be set by a third party providing user identifier information or a service provider. When the first user identifier is already using the service on the UE (102) and the second user identifier requests the establishment of a PDU session, the SMF entity (220) checks the priority information of the first user identifier and the second user identifier. The SMF entity (220) obtains that the second user identifier (the identifier that initiated the new PDU session) has a higher priority than the first user identifier, and then the existing PDU of the first user identifier can be released and the new PDU session for the second user identifier can be accepted.

[0107] In one embodiment of the present disclosure, when one of the PDU session request and the PDU session modification request is accepted, the AMF entity (125) allows authentication and authorization of the second user identifier on the second SMF entity (115).

[0108] In one embodiment of the present disclosure, a first SMF entity (110) receives a PDU session request from a UE (102) through a first access and mobility management function (AMF) entity (120). A second SMF entity (115) receives another PDU session request from a UE (102) through a second AMF entity (125). In one embodiment of the present disclosure, the first AMF entity (120) and the second AMF entity (125) are identical. In one embodiment of the present disclosure, the first AMF entity (120) and the second AMF entity (125) are different from each other.

[0109] Various actions in the method (700) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 7 may be omitted.

[0110] FIG. 8 is a sequence diagram illustrating a method (800) for managing user identifiers in wireless communication networks (100) to restrict multiple user identities accessing a service through a single device, according to one embodiment of the present disclosure. In step 802, a UE (102) is already registered with the network. The UE (102) has profiles of a first user identifier and a second user identifier that are locally configured. In step 804, the UE (102) transmits a request to establish a PDU session or modify a PDU session (or a new non-access stratum (NAS) message) to initiate authentication and authorization of the first user identifier. In one embodiment of the present disclosure, the PDU session request may be routed to a first SMF entity (110) by an AMF entity. At step 806, the first SMF entity (110) checks via the data storage entity (106) whether any other user identifier is already associated with the UE (102) through the same or another PDU session. Consider that the UDM returns a negative response indicating that there is no other user associated with the UE (102). At step 808, authentication and authorization of the first SMF entity (110) are performed. At step 810, the first SMF entity (110) updates the data storage entity (106) to indicate that the first user identifier is using the UE (102) through a specific PDU session. At step 812, consider that a new user (second user identifier) ​​starts using the UE (102) and triggers an authentication and authorization procedure (similar to step 804), and that a PDU session request is processed by the second SMF entity (115). In step 814, the second SMF entity (115) queries the data storage entity (106) to check if there is another user identifier already associated with the UE (102) through the same or another PDU session.The data storage entity (106) informs the second SMF entity (115) that another user (first user identifier) ​​has an active, ongoing PDU session associated with the UE (102). At step 816, based on a local policy, the second SMF entity (115) can now reject a request from the UE (102) to authenticate the second user identifier with an appropriate cause code by rejecting a request to establish a PDU session or modify a PDU session.

[0111] In one embodiment of the present disclosure, instead of an SMF entity or a data storage entity, an AMF may be an anchor network function that applies logic to allow or reject a PDU session from a second user identifier and to release or maintain a first ongoing PDU session.

[0112] Various actions in the method (800) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 8 may be omitted.

[0113] FIG. 9 illustrates a block diagram of a wireless network (100) for managing user identifiers in a UE (102) according to one embodiment of the present disclosure. In one embodiment of the present disclosure, the network entity (104) may include a first SMF entity (110) and a second SMF entity (115). The first SMF entity (110) may include, but is not limited to, a processor (902), a memory (904), a user identity management control unit (908), and a transceiver (906). The user identity management control unit (908) is coupled with the processor (902), the memory (904), and the transceiver (906). The first SMF entity (110) may communicate with the UE (102) and the data storage entity (106) through the transceiver (906). The second SMF entity (115) may include, but is not limited to, a processor (920), memory (922), a user identity management control unit (926), and a transceiver (924). The user identity management control unit (926) is combined with the processor (920), memory (922), and the transceiver (924). The second SMF entity (115) can communicate with the UE (102) and the data storage entity (106) through the transceiver (924).

[0114] In one embodiment of the present disclosure, the UE (102) includes a control unit (910) and a transceiver (912). The control unit (910) communicates with a first SMF entity (110) and a second SMF entity (115) through the transceiver (912). The wireless network may include, but is not limited to, a plurality of network entities available within the network coverage area of ​​the UE.

[0115] Memory (904) is configured to store instructions to be executed by the processor (902). Memory (904) may include non-volatile storage elements. Memory (922) is configured to store instructions to be executed by the processor (920). Memory (922) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of EPROM (electrically programmable memories) or EEPROM (electrically erasable and programmable memories). Additionally, memory (904 and 922) may, in some examples, be considered as a non-transient storage medium. The term "non-transient" may indicate that the storage medium is not implemented by a carrier wave or a propagating signal. However, the term "non-transient" should not be interpreted as meaning that the memory is non-removable. In some examples, the memories (904 and 922) are configured to store a larger amount of information. In certain examples, a non-transient storage medium (e.g., RAM (Random Access Memory) or cache) may store data that may change over time.

[0116] The processor(s) (902 and 920) may include one or more processors. One or more processors may be general-purpose processors such as a central processing unit (CPU) or an application processor (AP), graphics-only processing units such as a graphics processing unit (GPU) or a visual processing unit (VPU), and / or AI-only processors such as a neural processing unit (NPU). The processor (902) may include multiple cores and is configured to execute instructions stored in memory (904). In one embodiment of the present disclosure, the processor (920) includes multiple cores and is configured to execute instructions stored in memory (922).

[0117] In one embodiment of the present disclosure, the transceiver (906) includes an electronic circuit specialized for a standard that enables wired or wireless communication. The transceiver (906) is configured to communicate internally between internal hardware components of the UE (102) and with external devices through one or more networks.

[0118] In one embodiment of the present disclosure, the transceiver (924) includes an electronic circuit specialized for a standard that enables wired or wireless communication. The transceiver (924) is configured to communicate internally between internal hardware components of the UE (102) and with external devices through one or more networks.

[0119] In one embodiment of the present disclosure, a user identity management control unit (908 or 926) identifies, authenticates, and re-authenticates a user before using any service from a network.

[0120] FIG. 10 illustrates a flowchart illustrating a method (1000) for managing user identities by restricting multiple users from using the UE (102) simultaneously, according to one embodiment of the present disclosure. An embodiment of the present invention discloses an AMF entity scenario. In step 1002, a first AMF entity (120) receives from the UE (102) one of a PDU session request and a PDU session modification request from a first user identifier (ID).

[0121] In step 1004, the first AMF entity (120) checks for available subscription information and associated user identifiers downloaded during the registration process of the second user attempting to use the service from the subscription.

[0122] In step 1006, the first AMF entity (120) determines, based on a local policy, whether there is a PDU session associated with the second user identifier of the UE (102) or whether any other user identifier has an ongoing PDU session with the UE (102).

[0123] In step 1008, the first AMF entity (120) obtains service priority information of the first user identifier. The first SMF entity (110) obtains service priority information from the data storage entity (106) or obtains service priority information from the AMF entity (125) while downloading subscription information as part of PDU request processing.

[0124] In step 1010, the first AMF entity (120) determines whether the service priority information associated with the first user ID is more important than the service priority information associated with the second user ID among the multiple user IDs.

[0125] In step 1012, if it is determined that the service priority information associated with the first user profile ID is more important than the service priority information associated with the second user profile ID, and if it is determined that one PDU already exists for the second user ID associated with UE (102), the first AMF entity (120) accepts either a PDU session request or a PDU session modification request. Regardless of which user identifier on which AMF entity any ongoing PDU session associated with UE (102) is associated with, the PDU session is accepted because the priority of the first user ID is higher than that of the second user ID. In response to the accepted PDU session, the first AMF entity (120) sends a PDU session acceptance message to the UE (102).

[0126] In step 1014, the first AMF entity (120) releases the ongoing PDU session from the second user identifier of the UE (102) in order to establish a new PDU session with the first user identifier of the UE (102).

[0127] In step 1016, if it is determined that the service priority information associated with the first user profile ID is less important than the service priority information associated with the second user profile ID by determining whether a PDU already exists for the second user ID associated with the UE (102), the first AMF entity (120) rejects either the PDU session request or the PDU session modification request and sends a PDU session rejection message containing a cause code to the UE (102) in response to the rejection of the PDU session.

[0128] In step 1018, if it is determined that there are no other user IDs having an ongoing PDU session with the UE (102), and if the first AMF entity (120) does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID, the first AMF entity (120) accepts either a PDU session request or a PDU session modification request. The first AMF entity (120) sends a PDU session acceptance message to the UE (102).

[0129] In step 1020, if it is determined that a PDU session associated with a second user profile ID is currently in progress by determining that a PDU session for a second user ID associated with UE (102) has already been established, and if the first AMF entity (120) does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID, the first AMF entity (120) rejects either the PDU session request or the PDU session modification request. If the first AMF entity (120) rejects the PDU session for the first user ID, it sends a PDU session rejection message to the UE (102) along with a cause code.

[0130] In one embodiment of the present disclosure, when one of the PDU session request and the PDU session modification request is accepted, the AMF entity (120) allows authentication and authorization of the first user identifier on the AMF entity (120).

[0131] In one embodiment of the present disclosure, a first network entity updates a UE context associated with a first user profile in a data storage entity (106). The UE context includes at least one of user identification information, profile information, and subscription information when the first user profile associated with the UE (102) triggers at least one network access procedure for a first user identifier, and when it is determined that the first user profile associated with the UE (102) has been successfully authenticated and authorized. A second user identifier that may be associated with a second user is already authenticated by a second AMF entity (125). The UE context associated with the second user identifier is already updated in the data storage entity by the second AMF entity (125).

[0132] In step 1022, when the ongoing PDU session is released and a new PDU session is established, the data storage entity (106) updates the user profile database in the second network entity. In step 1024, the data storage entity (106) deletes the UE context associated with the second user profile in the second network entity.

[0133] Various actions in the method (1000) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 10 may be omitted.

[0134] FIG. 11 is a sequence diagram illustrating a method (1100) for managing user identifiers in wireless communication networks (100) during a UE mobility scenario between AMF entities (120 and 125) according to one embodiment of the present disclosure. Considering an AMF mobility scenario from a first AMF entity (120) to a second AMF entity (125), at step 1102, the first user identifier is considered to have already been authenticated by the network using the first UE (102). The first UE (102) is registered with the network through the first AMF entity (120). User information may be further updated in the data storage entity (106) by the first AMF entity (120) as part of the AMF registration procedure (Nudm_UECM procedure) for the first UE (102). User information may also be updated in a user profile database to indicate that the first user identifier is accessing the network using the UE (102). At step 1104, the second user identifier now begins to use the first UE (102) and triggers an access procedure using an implementation-specific method (e.g., selecting an option to change the user in the app). At step 1106, the first UE (102) initiates the second user identifier authentication and authorization procedure. It is assumed that the first UE (102) is now handled by a new network entity called a second AMF entity (125) that handles the authentication and authorization of the second user identifier. At step 1108, once the second user identifier is successfully authenticated and / or authorized, the second AMF entity (125) may trigger an update of the UE context within the data storage entity (106) to include the identification information of the second user identifier and (if any) other information.In step 1110, if it is determined that the second user identifier is using the first UE (102), the data storage entity (106) may trigger an update of the user profile database and the UE context within the first UE (102) to remove the association of the first user identifier from the network.

[0135] In one embodiment of the present disclosure, if a second user identifier initiates a PDU session through the same UE and the message is received by the same AMF entity (e.g., the AMF entity that processed the establishment of the first user identifier's PDU session), the AMF can check from the available subscription information and associated user identifiers already downloaded during the registration process that a new user is attempting to use the service from the same subscription where the first user identifier is already using the service. If the user identifier policy defines to reject a new PDU session, the AMF rejects the PDU session for the second user identifier. If the network policy defines user identifiers associated with some priorities and the second user identifier has a higher priority than the first user identifier, the second user identifier PDU session request is processed. The AMF entity (125) can send a message to the SMF to release the first user identifier's PDU session by providing an appropriate cause code. When the SMF entity receives a message from the AMF entity (125), it can release the PDU session for the first user identifier along with the appropriate cause code by sending it to the UE (102).

[0136] Therefore, the network maintains an association between a 5G wireless device and a single user, and ensures that the association of the existing user is deleted from the network when a new user is refused use of the device or when a new user takes over the device.

[0137] The solutions defined for NR(5GC) are also applicable to legacy RATs such as E-UTRA / LTE, and the corresponding CN entities need to be replaced by LTE entities, for example, AMF needs to be replaced by MME, g-nodeB by e-nodeB, UDM by HSS, etc. However, the principle of the solution remains the same.

[0138] The network used in this embodiment may be described using any 5G core network function, for example, AMF. However, the network may be any 5G / EUTRAN core network entity such as AMF / SMF / MME / UPF, or the network may be any 5G / EUTRAN RAN entity such as eNodeB (eNB) or gNodeB (gNB) or NG-RAN.

[0139] The messages used or indicated in this embodiment are illustrated as examples. These messages may be any signaling messages between the UE and network functions / entities or between different network functions / entities.

[0140] Similarly, the service operation names presented in this invention are for illustrative purposes only. Any other name may be used to convey information.

[0141] In one embodiment of the present disclosure, the user identifier is considered to be associated only with humans.

[0142] Various actions in the method (1100) may be performed in the order presented, in their respective order, or simultaneously. Additionally, in some embodiments, some of the actions listed in FIG. 11 may be omitted.

[0143] FIGS. 12 and 13 illustrate other block diagrams of a wireless network (100) for managing user identifiers in a UE (102) according to one embodiment of the present disclosure. In one embodiment of the present disclosure, the network entity (104) may include a first AMF entity (120) and a second AMF entity (125). The first AMF entity (120) may include, but is not limited to, a processor (1202), a memory (1204), a user identity management control unit (1208), and a transceiver (1206). The user identity management control unit (1208) is coupled with the processor (1202), the memory (1204), and the transceiver (1206). The first AMF entity (120) may communicate with the UE (102) and the data storage entity (106) through the transceiver (1206). The second AMF entity (125) may include, but is not limited to, a processor (1220), memory (1222), a user identity management control unit (1226), and a transceiver (1224). The user identity management control unit (1226) is combined with the processor (1220), memory (1222), and transceiver (1224). The second AMF entity (125) can communicate with the UE (102) and the data storage entity (106) through the transceiver (1224).

[0144] In one embodiment of the present disclosure, the UE (102) includes a control unit (1210) and a transceiver (1212). The control unit (1210) communicates with a first AMF entity (120) and a second AMF entity (125) through the transceiver (1212). The wireless network may include a plurality of network entities available within the network coverage area of ​​the UE (102), but is not limited thereto.

[0145] Memory (1204) is configured to store instructions to be executed by the processor (1202). Memory (1204) may include non-volatile storage elements. Memory (1222) is configured to store instructions to be executed by the processor (1220). Memory (1222) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of EPROM (electrically programmable memories) or EEPROM (electrically erasable and programmable memories). Additionally, memory (1204 and 1222) may, in some examples, be considered as a non-transient storage medium. The term "non-transient" may indicate that the storage medium is not implemented by a carrier wave or a propagating signal. However, the term "non-transient" should not be interpreted as meaning that the memory is non-removable. In some examples, the memory (1204) is configured to store a larger amount of information. In certain examples, a non-transient storage medium (e.g., RAM (Random Access Memory) or cache) may store data that may change over time.

[0146] The processor (1202 and 1220) may include one or more processors. The one or more processors may be general-purpose processors such as a central processing unit (CPU) or an application processor (AP), graphics-only processing units such as a graphics processing unit (GPU) or a visual processing unit (VPU), and / or AI-only processors such as a neural processing unit (NPU). The processor (1202) includes multiple cores and is configured to execute instructions stored in memory (1204). In one embodiment of the present disclosure, the processor (1220) includes multiple cores and is configured to execute instructions stored in memory (1222).

[0147] In one embodiment of the present disclosure, the transceiver (1206) includes an electronic circuit specialized for a standard that enables wired or wireless communication. The transceiver (1206) is configured to communicate internally between internal hardware components of the UE (102) and with external devices through one or more networks.

[0148] In one embodiment of the present disclosure, the transceiver (1224) includes an electronic circuit specialized for a standard that enables wired or wireless communication. The transceiver (1224) is configured to communicate internally between internal hardware components of the UE (102) and with external devices through one or more networks.

[0149] In one embodiment of the present disclosure, user identity management control units (1208 and 1226) identify, authenticate, and re-authenticate a user before using any service from a network.

[0150] As illustrated in FIG. 13, the network entity (104) includes, but is not limited to, a processor (1302), memory (1304), a user identity management control unit (1308), and a transceiver (1306). The user identity management control unit (1308) is coupled with the processor (1302), memory (1304), and the transceiver (1306). The network entity (104) can communicate with the UE (102) and the data storage entity (106) through the transceiver (1306). In one embodiment of the present disclosure, the UE (102) includes a control unit (1310) and a transceiver (1312). The control unit (1310) communicates with the network entity (104) through the transceiver (1312). A wireless network may include, but is not limited to, multiple network entities available within the network coverage area of ​​the UE. The first network entity and the second network entity are used only for exemplary purposes.

[0151] Memory (1304) is configured to store instructions to be executed by the processor (1302). Memory (1304) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memories, or forms of EPROM (electrically programmable memories) or EEPROM (electrically erasable and programmable memories). Additionally, memory (1304) may be considered, in some examples, as a non-transient storage medium. The term "non-transient" may indicate that the storage medium is not implemented by a carrier wave or a propagating signal. However, the term "non-transient" should not be interpreted as meaning that the memory is non-removable. In some examples, memory (1304) is configured to store a larger amount of information. In certain examples, non-transient storage media can store data that may change over time (e.g., RAM (Random Access Memory) or cache).

[0152] The processor (1302) may include one or more processors. The one or more processors may be general-purpose processors such as a central processing unit (CPU) or an application processor (AP), graphics-only processing units such as a graphics processing unit (GPU) or a visual processing unit (VPU), and / or AI-only processors such as a neural processing unit (NPU). The processor (1302) may include multiple cores and is configured to execute instructions stored in memory (1304).

[0153] In one embodiment of the present disclosure, the transceiver (1306) includes an electronic circuit specialized for a standard that enables wired or wireless communication. The transceiver (1306) is configured to communicate internally between internal hardware components of the UE (102) and with external devices through one or more networks.

[0154] In one embodiment of the present disclosure, a user identity management control unit (1308) identifies, authenticates, and re-authenticates a user before using any service from a network.

[0155] FIG. 14 illustrates an exemplary sequence diagram as an example of managing multiple user identities in a wireless communication network (100) according to one embodiment of the present disclosure. In step 0, the data storage entity (106) may already have user identifier information associated with a subscription provisioned. In step 1, the UE (102) transmits a registration request along with an indication of the ability to support the user identifier. In step 2, the AMF entity (125) receives subscriber data information from the UDM (106) along with the associated user identifier details. In step 3, the AMF entity (125) provides the user identifier details within the registration acceptance to the UE (102). In step 4, the first user identifier calls an application on the device (UE). In step 5, the UE (102) triggers a PDU session establishment request by providing the first identifier. In step 6, the AMF entity (125) selects the first SMF entity (110) and transmits the first identifier to the first SMF entity (110). In step 7, the first SMF entity (110) receives session management subscriber data along with user identifier details from the UDM (106). In step 8, the first SMF entity (110) queries the UDM (106) to obtain any established PDU session and receives a response that there is no PDU session. In step 9, the first SMF entity (110) transmits acceptance of the PDU session establishment to the UE (102). In step 10, the first SMF entity (110) updates the address of the SMF entity within the UDM (106) and provides the first user identifier along with the PDU session ID. In step 11, the second user identifier calls an application on the device (UE). In step 12, the UE (102) triggers a PDU session establishment request by providing a second user identifier.In step 13, the AMF entity (125) selects the second SMF entity (115) and sends the second user identifier to the second SMF entity (115). In step 14, the second SMF entity (115) queries the UDM (106) to obtain any established PDU session and obtains a response for the PDU session associated with the first user identifier. In step 15, the second SMF entity (115) sends a rejection of the PDU session establishment to the UE (102) along with an appropriate cause code.

[0156] According to one embodiment of the present disclosure, the step of acquiring a first PDU session request includes receiving a first PDU session establishment request message from a user device (UE) through an access and mobility management function (AMF).

[0157] According to one embodiment of the present disclosure, the method further includes the step of storing a first user identifier and an identifier of a first PDU session in a UDM.

[0158] According to one embodiment of the present disclosure, the method further comprises the steps of: obtaining a second PDU session request associated with a second user identifier; and rejecting the second PDU session associated with the second user identifier along with a cause code.

[0159] According to one embodiment of the present disclosure, the method further includes the step of identifying an established first PDU session associated with a first user identifier.

[0160] According to one embodiment of the present disclosure, the method further comprises the steps of: obtaining priority information among user identifiers; determining that a second user identifier has a higher priority than a first user identifier; and releasing a first PDU session associated with the first user identifier, wherein a second PDU session associated with the second user identifier is accepted.

[0161] According to one embodiment of the present disclosure, the step of obtaining priority information among user identifiers includes receiving user identifier details from a UDM.

[0162] According to one embodiment of the present disclosure, at least one processor is configured to receive a first PDU session establishment request message from a user device (UE) through an access and mobility management function (AMF).

[0163] According to one embodiment of the present disclosure, at least one processor is further configured to store a first user identifier and an identifier of a first PDU session in a UDM.

[0164] According to one embodiment of the present disclosure, at least one processor is configured to further acquire a second PDU session request associated with a second user identifier and to reject the second PDU session associated with the second user identifier along with a cause code.

[0165] According to one embodiment of the present disclosure, at least one processor is further configured to identify an established first PDU session associated with a first user identifier.

[0166] According to one embodiment of the present disclosure, at least one processor further obtains priority information among user identifiers, determines that a second user identifier has a higher priority than a first user identifier, is configured to release a first PDU session associated with the first user identifier, and accepts a second PDU session associated with the second user identifier.

[0167] According to one embodiment of the present disclosure, at least one processor is configured to receive user identifier details from a UDM.

[0168] The proposed method helps telecommunications operators identify actual users accessing devices (or UEs) to receive services from a network and provide service differentiation based on user identifiers.

[0169] The various actions, acts, blocks, steps, etc. in this method(s) may be performed in the presented order, in a different order, or simultaneously. Furthermore, in some embodiments, some of the actions, acts, blocks, steps, etc. may be omitted, added, modified, skipped, etc. without departing from the scope of the invention.

[0170] The embodiments disclosed in this disclosure may be implemented through at least one software program that is executed on at least one hardware device and controls network elements by performing network management functions. The elements include blocks that may be at least one of a hardware device or a combination of a hardware device and a software module.

[0171] The embodiments disclosed in this disclosure may be implemented through at least one software program that is executed on at least one hardware device and controls network elements by performing network management functions. The elements include blocks that may be at least one of a hardware device or a combination of a hardware device and a software module.

[0172] The embodiments disclosed herein describe a system and method for managing user identifiers in a wireless communication network. Therefore, it is understood that the scope of protection extends to such a program, and in addition to computer-readable means having a message, such computer-readable storage means includes means of program code for implementing one or more steps of the method when the program is executed on a server or a mobile device or any suitable programmable device. The method is implemented in at least one embodiment through or with such a software program written in, for example, VHDL (Very high speed integrated circuit Hardware Description Language), other programming languages, or implemented by one or more VHDL or multiple software modules running on at least one hardware device. The hardware device may be any type of portable device capable of being programmed. For example, the device may also include means which may be hardware means such as, for example, an ASIC, or a combination of hardware and software means, for example, an ASIC and an FPGA, or at least one memory in which at least one microprocessor and software modules are located internally. The method embodiments described in this disclosure may be implemented partially in hardware and partially in software. Alternatively, the present invention may be implemented on different hardware devices, for example, using multiple CPUs.

[0173] The foregoing description of specific embodiments will sufficiently reveal the general nature of the embodiments of the present invention, which allow others, by applying current knowledge, to readily modify and / or adapt these specific embodiments for various applications without departing from the general concept; therefore, such modifications and alterations should be understood and are intended to be understood within the meaning and scope of equivalents of the disclosed embodiments. It should be understood that the language or terms used in this disclosure are for descriptive purposes only and are not limiting. Therefore, although the embodiments of the present invention have been described in terms of embodiments and examples, those skilled in the art will recognize that the embodiments and examples disclosed in this disclosure may be modified and practiced within the scope of the embodiments as described in this disclosure.

Claims

Claim 1 A method performed by a first session management function (SMF) in a wireless communication system, comprising: obtaining a first protocol data unit (PDU) session request associated with a first user identifier; querying a unified data management (UDM) to obtain established PDU session information; receiving a response from the UDM that there is no PDU session; and establishing a first PDU session associated with the first user identifier, wherein a second PDU session request associated with a second user identifier is obtained by a second SMF, the UDM is queried from the second SMF to obtain the established PDU session information, a response regarding the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and the second PDU session associated with the second user identifier is rejected by the second SMF with a cause code. Claim 2 A method according to claim 1, wherein the step of acquiring the first PDU session request comprises receiving the first PDU session establishment request message from the UE (user equipment) through an access and mobility management function (AMF). Claim 3 A method according to claim 1, further comprising the step of storing the first user identifier and the first PDU session identifier in the UDM. Claim 4 A method according to claim 1, further comprising: a step of obtaining the second PDU session request associated with the second user identifier; and a step of rejecting the second PDU session associated with the second user identifier along with the cause code. Claim 5 A method according to claim 4, further comprising the step of identifying the established first PDU session associated with the first user identifier. Claim 6 A method according to claim 1, further comprising: a step of obtaining priority information among user identifiers; a step of determining that the second user identifier has a higher priority than the first user identifier; and a step of releasing the first PDU session associated with the first user identifier, wherein the second PDU session associated with the second user identifier is accepted. Claim 7 In claim 6, the step of obtaining priority information among the user identifiers comprises the step of receiving user identifier details from the UDM. Claim 8 In a wireless communication system, a first session management function (SMF) comprises: a transceiver; and at least one processor coupled to the transceiver, wherein the at least one processor obtains a first protocol data unit (PDU) session request associated with a first user identifier, queries a unified data management (UDM) to obtain established PDU session information, receives a response from the UDM that there is no PDU session, establishes a first PDU session associated with the first user identifier, a second PDU session request associated with a second user identifier is obtained by a second SMF, the UDM queries the second SMF to obtain established PDU session information, a response regarding the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and the second PDU session associated with the second user identifier is rejected by the second SMF with a cause code. Claim 9 In claim 8, the at least one processor receives the first PDU session establishment request message from the UE (user equipment) through the access and mobility management function (AMF), a first SMF. Claim 10 In claim 8, the at least one processor stores the first user identifier and the identifier of the first PDU session in the UDM, a first SMF. Claim 11 In claim 8, the first SMF, wherein the at least one processor acquires the second PDU session request associated with the second user identifier and rejects the second PDU session associated with the second user identifier along with the cause code. Claim 12 In claim 11, the at least one processor identifies the established first PDU session associated with the first user identifier, a first SMF. Claim 13 In claim 8, the at least one processor obtains priority information between user identifiers, determines that the second user identifier has a higher priority than the first user identifier, releases the first PDU session associated with the first user identifier, and accepts the second PDU session associated with the second user identifier, the first SMF. Claim 14 In claim 13, the at least one processor receives user identifier details from the UDM, a first SMF. Claim 15 A unified data management (UDM) in a wireless communication system comprises: a transceiver; and at least one processor coupled to the transceiver, wherein the at least one processor receives a first query from a first session management function (SMF) for obtaining established PDU session information and transmits a response to the first SMF that there is no PDU session, and a first PDU session associated with a first user identifier is established, and receives a second query from a second SMF for obtaining the established PDU session information and transmits a response regarding the first PDU session associated with the first user identifier to the second SMF, and the second PDU session associated with the second user identifier is rejected by the second SMF along with a cause code.