Implementation of user equipment mobility based on non-seamless WLAN offload authentication

WO2025012842A8PCT designated stage expired Publication Date: 2025-08-07NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2024/056739
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-07-11
Filing Date
2024-07-10
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Current 5G specifications do not enable user equipment (UE) to connect to wireless local area networks (WLANs) using 5G credentials for non-seamless wireless offload (NSWO) authentication, requiring repeated authentication when UE moves between WLANs, leading to connectivity delays and inefficiencies.

Method used

The solution involves maintaining an NSWO UE context with a temporary ID and master session key (MSK) during initial authentication, allowing UE to connect to different WLANs without re-authentication by using the NSWO UE temporary ID to establish a secure communication link, thereby reducing the need for full authentication processes.

Benefits of technology

This approach enables seamless UE mobility between WLANs using existing 5G credentials, reducing connection latency and maintaining security without the need for repeated authentication, thus enhancing user experience and network efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024056739_07082025_PF_FP_ABST
    Figure IB2024056739_07082025_PF_FP_ABST
Patent Text Reader

Abstract

Methods and apparatus are provided for enabling mobility a user equipment (UE) that has been previously authenticated to a 5G wireless network through a selected wireless local area network (WLAN) access network (AN) based upon non-seamless WLAN offload (NSWO). Methods and apparatus are presented that create a temporary NSWO-UE identification that is stored in NSWO UE context at both the UE and the network entity supporting mobility (NSWO function, or authentication service function), where upon movement of a UE from a first WLAN AN (used to establish NSWO authentication) to a second WLAN AN, the authentication process need not be repeated. The UE instead presents the NSWO UE temporary ID to the network entity for confirmation of previous authentication.
Need to check novelty before this filing date? Find Prior Art

Description

IMPLEMENTATION OF USER EQUIPMENT MOBILITY BASED ON NONSEAMLESS WLAN OFFLOAD AUTHENTICATIONTECHNICAL FIELD

[0001] This disclosure is related to the field of communication systems, with example embodiments generally related to mobile or wireless telecommunication systems, such as fifth generation (5G) radio access technology. For example, certain embodiments may relate to systems and / or methods for providing user equipment (UE) mobility when the UE moves from one wireless local area network (WLAN) to another after invoking non-seamless WLAN offload (NSWO) authentication.BACKGROUND

[0002] Telecommunications networks, such as 5G networks bring many improvements in the mobile network user experience. For instance, 5G networks should provide new technical solutions allowing a greater throughput, lower latency, higher reliability, higher connectivity, and higher mobility range. As the cellular system including 5G networks support an increasing number of UEs and services including applications with a wide range of use cases and diverse needs with respect to bandwidth, latency, and reliability requirements, the cellular system may need to enable UEs to connect to the wireless access network that support non- seamless wireless offload (NSWO) using the UE’s 5G credentials.BRIEF SUMMARY

[0003] In some example embodiments, a method is provided comprising requesting, by a user equipment (UE), a wireless connection to a network entity through a first wireless local area network access network (WLAN AN), receiving, by the UE, from the network entity, an identity request, and in response to the identity request, causing transmission, by the UE, of an identity response comprising a UE identifier and a non-seamless WLAN offload (NSWO) mobility support indicator to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identification and further configured to maintain an NSWO UE context for subsequent mobility purposes.

[0004] Following on the above, in some example embodiments the method further comprises requesting, in response to a relocation of the UE, a wireless connection to the network entity through a second, different WLAN AN, receiving, by the UE, from the network entity, an identity request, and in response to the identity request, causing transmission, by the UE, of an identity response comprising the NSWO UE temporary ID to the network entity such thatthe network entity recognizes the mobility of the UE and confirms connection without additional authentication.

[0005] In some embodiments, a method is provided for receiving, by a network function, from a network entity, a UE identifier and an NSWO mobility support indicator, creating, by the network function, upon authentication of the UE and the generation of an MSK, an NSWO UE temporary ID for use in mobility applications, and storing, at the network function, an NSWO UE context including the NSWO UE temporary ID and the MSK.

[0006] Following on the immediate above embodiments, the method is further provided for receiving, by the network function, from the network entity, from the UE, the NSWO UE temporary ID, fetching, from the NSWO UE context, the MSK associated with the NSWO UE temporary ID, and using the NSWO UE temporary ID and MSK, generating a mobility key for permitting access of the UE to the network entity from a second WLAN.

[0007] In some example embodiments, an apparatus is provided comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: requesting, by a user equipment (UE), a wireless connection to a network entity through a first wireless local area network access network (WLAN AN); receiving, by the UE, from the network entity, an identity request; and in response to the identity request, causing transmission of, by the UE, an identity response comprising a UE identifier and a non-seamless WLAN offload (NSWO) mobility support indicator to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identification and further configured to maintain an NSWO UE context for subsequent mobility purposes.

[0008] Following on the above, in some example embodiments the apparatus is further caused to perform: requesting, in response to a relocation of the UE, a wireless connection to the network entity through a second, different WLAN AN; receiving, by the UE, from the network entity, an identity request; and in response to the identity request, causing transmission of, by the UE, an identity response comprising the NSWO UE temporary ID to the network entity such that the network entity recognizes the mobility of the UE and confirms connection without additional authentication.

[0009] In some example embodiments, an apparatus is provided comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, by a network function, from a network entity, a UE identifier and an NSWO mobility support indicator; creating, by the network function, upon authentication of the UE and the generation of an MSK, an NSWOUE temporary ID for use in mobility applications; and storing, at the network function, an NSWO UE context including the NSWO UE temporary ID and the MSK. Following on the immediate above embodiments, the apparatus may be further caused to at least perform: receiving, by the network function, from the network entity, from the UE, the NSWO UE temporary ID; fetching, from the NSWO UE context, the MSK associated with the NSWO UE temporary ID; and using the NSWO UE temporary ID and MSK, generating a mobility key for permitting access of the UE to the network entity from a second WLAN.

[0010] In addition to the methods and apparatuses just described the present disclosure also provides methods for re- authorizing and re-authenticating UE to connect to a wireless network. One exemplary method may comprise: generating a first re-authorization identification (ID) by an AUSF based on a MSK key and a constant value; sending the first re-authorization to an NSWOF; sending the constant value to the UE; generating a second reauthorization ID by the UE based on the MSK key and the constant value; sending the second re-authorization ID from the UE to the NSWOF as the UE moves from a first WLAN Access Node to a second, different nearby WLAN Access Node; and re-authorizing and reauthenticating the UE based on the second re-authorization ID received by the NSWOF; and a second method may comprise: sending a MSK key from an AUSF to an NSWOF; generating a first re-authorization identification (ID) by the NSWOF based on the MSK key and a selected constant value; sending the selected constant value to UE; generating a second re-authorization ID by the UE based on the MSK key and the selected constant value; sending the second re-authorization ID to the NSWOF as the UE moves from a first WLAN Access Node to a second, different nearby WLAN Access Node; and re-authorizing and reauthenticating the UE based on the second re-authorization ID received by the NSWOF. It should be understood that the constant values discussed above and herein may be the same value or selected form a plurality of different values.BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Having thus described certain example embodiments of the disclosure in general terms, reference will now be made to the accompanying drawings, wherein:

[0012] FIG. 1 illustrates an example of a portion of a 5G wireless network, in accordance with some example embodiments;

[0013] FIG. 2 is a signal diagram illustrating a known process for provided NSWO authentication for a UE;

[0014] FIG. 3 is a flow diagram illustrating an example signaling arrangement between network entities via a network infrastructure, in accordance with the present disclosure, thataccommodates UE mobility from one WLAN to another without requiring NSWO reauthentication;

[0015] FIG. 4 is a flow diagram, following the example of FIG. 3, illustrating a signaling arrangement between network entities subsequent to the movement of a UE to another WLAN;

[0016] FIG. 5 is a diagram showing an example key generation for the arrangement discussed in FIGs. 3 and 4;

[0017] FIG. 6 is a flow diagram illustrating another example signaling arrangement between network entities via a network infrastructure, in accordance with the present disclosure, that accommodates UE mobility from one WLAN to another without requiring NSWO reauthentication, in this case provided by the AUSF;

[0018] FIG. 7 is a flow diagram, following the example of FIG. 6, illustrating a signaling arrangement between network entities subsequent to the movement of a UE to another WLAN;

[0019] FIG. 8 is a diagram showing an example key generation for the arrangement discussed in FIGs. 6 and 7;

[0020] FIG. 9 illustrates an example of a network-side apparatus, in accordance with some example embodiments;

[0021] FIG. 10 illustrates an example of a UE-side apparatus, in accordance with some example embodiments;

[0022] FIG. 11 is a flow chart illustrating example operations perform by a UE, for example, in accordance with one or more embodiments, to indicate NSWO mobility support;

[0023] FIG. 12 is a flow chart illustrating example operations perform by a UE, for example, in accordance with one or more embodiments, to effectuate movement to a second WLAN AN;

[0024] FIG. 13 is a flow chart illustrating example operations perform by a network entity, for example, in accordance with one or more embodiments, to perform operations necessary to support NSWO mobility, and FIG. 14 is a flow chart illustrating example operations perform by a network entity, for example, in accordance with one or more embodiments, during a UE mobility event.

[0025] FIGs. 15 and 16 are flow diagrams illustrating signaling arrangements between network entities subsequent to the movement of a UE to another WLAN in accordance with one or more embodiments and FIG. 17 is a diagram showing an exemplary generation of a reauthorization identifier.DETAILED DESCRIPTION

[0026] Some embodiments of the present invention will now be described more fully hereinafter with reference to the accompanying drawings, in which some, but not all, embodiments of the invention are shown. Indeed, various embodiments of the disclosure can be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will satisfy applicable legal requirements. The term “or” is used herein in both the alternative and conjunctive sense, unless otherwise indicated. The terms “illustrative” and “exemplary” are used to be examples with no indication of quality level. Like reference numerals refer to like elements throughout. As used herein, the terms “data,” “content,” “information,” and similar terms can be used interchangeably to refer to data capable of being transmitted, received and / or stored in accordance with certain embodiments of the present invention. Thus, use of any such terms should not be taken to limit the spirit and scope of embodiments of the present invention.

[0027] Additionally, as used herein, the term ‘circuitry’ refers to (a) hardware-only circuit implementations (e.g., implementations in analog circuitry and / or digital circuitry); (b) combinations of circuits and computer program product(s) comprising software and / or firmware instructions stored on one or more computer readable memories that work together to cause an apparatus to perform one or more functions described herein; and (c) circuits, such as, for example, a microprocessor(s) or a portion of a microprocessor(s), that require software or firmware for operation even if the software or firmware is not physically present. This definition of ‘circuitry’ applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term ‘circuitry’ also includes an implementation comprising one or more processors and / or portion(s) thereof and accompanying software and / or firmware. As another example, the term ‘circuitry’ as used herein also includes, for example, a baseband integrated circuit or applications processor integrated circuit for a mobile phone or a similar integrated circuit in a server, a cellular network device, other network device, and / or other computing device.

[0028] Additionally, as used herein, the terms “node,” “entity,” “intermediary,” “intermediate entity,” “go-between,” and similar terms can be used interchangeably to refer to computers connected via, or programs running on, a network or plurality of networks capable of data creation, modification, deletion, transmission, receipt, and / or storage in accordance with an example embodiment of the present invention. Thus, use of any such terms should not be taken to limit the spirit and scope of embodiments of the present invention.

[0029] Additionally, as used herein, the terms “user equipment,” “user device,” “device,” “apparatus,” “mobile device,” “personal computer,” “laptop computer,” “laptop,” “desktop computer,” “desktop,” “mobile phone,” “tablet,” “smartphone,” “smart device,” “cellphone,” “computing device,” “communication device,” “user communication device,” “terminal,” and similar terms can be used interchangeably to refer to an apparatus, such as may be embodied by a computing device, configured to access a network or plurality of networks for at least the purpose of wired and / or wireless transmission of communication signals in accordance with certain embodiments of the present disclosure. Thus, use of any such terms should not be taken to limit the spirit and scope of embodiments of the present disclosure.

[0030] As used herein, a “computer-readable storage medium,” which refers to a non- transitory physical storage medium (e.g., volatile or non-volatile memory device), can be differentiated from a “computer-readable transmission medium,” which refers to an electromagnetic signal. Such a medium can take many forms, including, but not limited to a non-transitory computer-readable storage medium (e.g., non-volatile media, volatile media), and transmission media. Transmission media include, for example, coaxial cables, copper wire, fiber optic cables, and carrier waves that travel through space without wires or cables, such as acoustic waves and electromagnetic waves, including radio, optical and infrared waves. Signals include man-made transient variations in amplitude, frequency, phase, polarization or other physical properties transmitted through the transmission media.

[0031] Examples of non-transitory computer-readable media include a magnetic computer readable medium (e.g., a floppy disk, hard disk, magnetic tape, any other magnetic medium), an optical computer readable medium (e.g., a compact disc read only memory (CD-ROM), a digital versatile disc (DVD), a Blu-Ray disc (BD), the like, or combinations thereof), a random access memory (RAM), a programmable read only memory (PROM), an erasable programmable read only memory (EPROM), a FLASH-EPROM, or any other non-transitory medium from which a computer can read. The term computer-readable storage medium is used herein to refer to any computer-readable medium except transmission media. However, it will be appreciated that where certain embodiments are described to use a computer- readable storage medium, other types of computer-readable mediums can be substituted for or used in addition to the computer-readable storage medium in alternative embodiments.

[0032] In the following, certain embodiments are explained with reference to communication devices capable of communication via a wireless network and communication systems serving such communication devices. Before explaining in detail certain example embodiments, certain general principles of a wireless communication system andcommunication devices are briefly explained to assist in understanding the technology underlying the described examples.

[0033] The 3rd Generation Partnership Project (3GPP) is a standards organization which develops protocols for mobile telephony and is known for the development and maintenance of various standards including second generation (2G), third generation (3G), fourth generation (4G), Long Term Evolution (LTE), and 5G standards. The 4G network system allows for NSWO (i.e., enabling a UE to connect to a WLAN access network using subscriber identity module (SIM) based access authentication via the mobile network core and to offload selected traffic to the WLAN). This is a deployed feature in 4G networks, and enables 4G UEs to connect, for example, to a Wi-Fi venue like a hotel or stadium using SIM based access authentication. Further, such feature allows the use of mobile network subscription and roaming agreements for WLAN access and for offloading selected traffic to the WLAN where the selection of the traffic to offload is based on policies and where the offloaded traffic is not using 3GPP defined entities. However, such capabilities are not supported by current 5G specification such that a UE cannot connect to a WLAN access network using its 5G credentials (e.g., SIM) and have traffic offloaded to the WLAN, as in the 4G Evolved Packet Core (EPC).

[0034] Despite the issue that current 5G specifications do not i) enable UEs to connect to deployed WLANs that support NSWO, using the UEs' 5G credentials and ii) offload selected traffic directly to these WLANs, for 5G access authentication, two authentication methods: an extensible authentication protocol authentication and key agreement (EAP-AKA') and 5G AKA are supported over both 3GPP access and non-3GPP access for accessing the 5G system of the operator owning the SIM or of one of its roaming partners. Currently, the procedure used for 4G NSWO over trusted non-3GPP access anticipates that the UE may send its international mobile subscriber identity (IMSI) in unencrypted form to the authorization and accounting (AAA) server in the core network. To support NSWO for users with credentials defined in a 5GC, the NSWO authentication procedure would need to make use of credentials provided by the 5GC (e.g., by the unified data management (UDM) / authentication credential repository and processing function (ARPF) in the 5GC). Such new NSWO authentication procedures should also support the same or a similar level of security and privacy as in 5G system (5GS) such that to never expose the WISP subscription permanent identifier (SUPI). Accordingly, since the UEs may be provisioned by the operators to use EAP-AKA', EAP-AKA' may be the preferred authentication method to be adopted for 5G NSWO. Currently, already deployed (enterprise) WLAN APs support only EAPauthentication framework over RADIUS or diameter interfaces to an operator owned AAA. Since the 5GC is able to support a unified authentication method, including EAP-AKA' the same interfaces could be extended to support NS WO using the same credentials (e.g., IMSI / SUPI). As such, reusing the same EAP-AKA' infrastructure for the NSWO authentication can provide 5G equivalent authentication security to enterprise users as well.

[0035] As such, UEs need to be authenticated when they are connected to WLAN ANs for availing NSWO, otherwise the NSWO could be misused by fraudulent UEs. Fraudulent UEs accessing enterprise WLAN without authentication can consume the WLAN resources and prevent the NSWO for legitimate UEs. This can cause distributed denial-of-service (DDoS) scenarios for NSWO UEs. Furthermore, if subscriber identity privacy is not available during authentication procedure, then tracking of the subscriber with “IMSI catchers” can lead to trackability and linkability attacks. In this, 5GS shall support EAP-AKA' authentication method using 5GC credentials for NSWO and providing hiding of the Permanent User Identifier (IMSI / SUPI) from eavesdroppers.

[0036] Provided herein are some example embodiments of methods, apparatuses, and computer program products for enabling UEs to connect to deployed WLANs, that support NSWO interworking, such as with 4G 3GPP networks, using the UEs’ 5G credentials and to offload selected traffic directly to these WLANs.

[0037] By way of example, but not of limitation, the method, apparatus and computer program product of an example embodiment will be described in conjunction with a 5G wireless network. In other embodiments, however, the method, apparatus and computer program product may be utilized in conjunction with other types of networks. For purposes of illustration, however, FIG. 1 depicts an example of a portion of a 5G wireless network 1 , in accordance with some example embodiments. Wireless network 1 (e.g., 5G wireless network) may communicate with a user equipment (UE) 10 configured to wirelessly couple to a wireless local area network (WLAN) access point (AP) being served by a wireless local area network access network (WLAN AN) 14 (containing one or more WLAN AP, and / or other type of wireless access entities). In accordance with the disclosed principles, 5G wireless network 1 includes a plurality of network entities including a non-seamless wireless offload network function (NSWOF) 12 configured to support NSWO authentication.NSWOF 12 is connected to WLAN AN 14 and to an authentication server function (AUSF) 16. At times, AUSF 16 may also be referred to as an extensible authentication protocol (EAP) authenticator, which is configured to carry out the authentication of UE 10 as well as store data for authentication of UE 10. FIG. 1 also depicts AUSF 16 as connected to a unified datamanagement element (UDM) 18 which is configured to store user subscription data, and to be able to decipher a subscription concealed identifier (SUCI), etc.

[0038] As long as UE 10 maintains its communication path through WLAN AN 14, the NSWO-based authentication remains intact. However, if UE 10 moves out of the communication range of WLAN AN 14 (as illustrated by the dotted line in FIG. 1) and desires to communication with 5G network 1 via a different WLAN AN also connected to the same NSWO 12 (such as WLAN AN 14A), previous procedures required that the complete NSWO authentication process should be repeated from this updated WLAN. At times, this may be referred to as “inter- WLAN AN mobility”. The disclosed principles relate to a method, apparatus and system for providing UE mobility in the context of NSWO authentication. As described below, the UE is configured utilize “NSWO mobility”, maintain a designated “NSWO UE context”, and communicate an indication of its mobility capability during the initial NSWO authentication process (or, more generally, include the mobility indicator in any message sent to the network entity). A network entity (such as NSWOF 12 or AUSF 16) is configured to also maintain the NSWO UE context and create a temporary ID for later use during mobility of UE 10 to a different WLAN AN that is also connected to NSWOF 12.

[0039] Prior to describing the disclosed principles in detail, an example NSWO authentication process will be described in association with the signal diagram of FIG. 2. In particular, FIG. 2 illustrates an example signal diagram of a procedure for UE authentication in NSWO, with reference to 5G wireless network 1 of FIG. 1. As illustrated, at element 100, a connection is established between UE 10 and WLAN AN 14. In some embodiments the connection may be established using procedures specified in IEEE 802.11. As illustrated in element 110, WLAN AN 14 may transmit an identity request to UE 10 in order to perform the authentication. For example, WLAN AN 14 may transmit an EAP Identity (ID) Request to UE 10. In response to the identity request, UE 10 may respond with an identity response comprising a UE identifier or its UE credential.

[0040] In the case as here where UE 10 is configured to use 5G NSWO, element 112 as shown in FIG. 2 uses the SUCI in NAI format (i.e., username @ realm format as specified in clause 28.7.3 of TS 23.003) as its identity. As illustrated in element 114, WLAN AN 14 routes the EAD identity response (with SUCI) over an SWa interface to NSWOF 12. As shown, NSWOF 12 functions as an AAA-Proxy between WLAN AN 14 and USF 16. And as illustrated in element 116, NSWOF 12 configures a request message (e.g., Nausf_UEAuthentication_Authenticate Request) with SUCI, Access Network Identifier(here, “5G:NSWO”) and NSWO_indicator towards AUSF 16. In some embodiments, the NSWO_indicator conveys the information that the authentication procedure is triggered for non-seamless WLAN offload purposes. As shown in element 118, AUSF 16 (functioning as an EAP authentication server) sends a Nudm_UEAuthentication_Get Request to UDM 18, the request including SUCI, Access Network Identifier “5G:NSWO” and NSWO_indicator. Upon receiving the Nudm_UEAuthentication_Get Request, UDM 18 invokes a deconcealment of the subscriber permanent identification (SUPI) from the SUCI so that the request may be processed. In other words, UDM 18 triggers the subscriber identity deconcealing function (SIDE) which is a functional element of UDM 18 responsible for decrypting the SUCI to reveal the UE's SUPI before UDM 18 can process the wireless connection registration request. Based on NSWO_indicator, the UDM selects the EAP- AKA' authentication method (element 120) and generates an authentication vector using “5G:NSWO” as the key derivation function (KDF) input parameter. UDM 18 shall include the EAP-AKA' authentication vector (e.g., RAND,AUTN,XRES, CK' and IK') and transmits the authentication parameters along with the SUPI to AUSF 16 in an authentication response message such as Nudm_UEAuthentication_Get Response message. In some embodiments, AUSF 16 stores at least one parameter such as the expected result (XRES) for future verification.

[0041] Upon receipt of this message at AUSF 16 and as illustrated in element 122, AUSF 16 then transmits an authentication challenge message to NSWOF 12 in a Nausf_UEAuthentication_Authenticate Response message, which continues to include the Access Network Identity (“5G”NSW0”) in the response. Thereafter and as illustrated in element 124, NSWOF 12 sends an SWa protocol message with EAP-Request / AKA'- Challenge message to WLAN AN 14. WLAN AN 14 will then forward the same authentication challenge message (such as EAP-Request / AKA'-Challenge message) to UE 10 as illustrated by element 126.

[0042] In some embodiments and as illustrated in element 128, UE 10 calculates a proper authentication response. For example, at receipt of the RAND and AUTN, the USIM of UE 10 may verify the freshness of the AV' by checking whether AUTN can be accepted as described in TS 33.102. If so, the USIM computes a response RES. The USIM may then return parameters such as RES, CK, IK to the ME. The ME may then derive CK' and IK' using the Access Network Identity as the KDF input parameter. If the verification of the AUTN fails on the USIM, then the USIM and ME may proceed as described in TS 33.501sub-clause 6.1.3.3. UE 10 may derive the master session key (MSK) from CK' and IK' as per Annex F and as described in RFC 5448.

[0043] As illustrated in element 130, UE 10 may transmit the EAP-Response / AKA'- Challenge message to WEAN AN 14 and in element 132, WLAN AN 14 forwards the EAP- Response / AKA' -Challenge message in SWa protocol message to NSWOF 12. NSWOF 12 will transmit the Nausf_UEAuthentication_Authenticate Request with EAP-Response / AKA'- Challenge message to AUSF 16 as illustrated in element 134. AUSF 16 may verify if the received response RES matches the stored and expected response XRES as shown by element 136. If AUSF 16 has successfully verified the received response, it will continue as follows to element 138; otherwise AUSF 16 will return an error to NSWOF 12.

[0044] AUSF 16 will then inform UDM 18 about the authentication results as described in TS 33.501 sub-clause 6.1.4. AUSF 16 then derives the required master session key (MSK) from CK' and IK' as per Annex F and as described in RFC 5448, based on the NSWO_indicator previously received (see element 116). AUSF 16 then sends the Nausf_UEAuthentication_Authenticate Response message with EAP-Success and MSK to NSWOF 12. In some embodiments, AUSF 16 may also provide the SUPI to NSWOF 12 for storage at that function. NSWOF 12 transmits a SWa protocol message with EAP-success and the MSK to WLAN AN 14 as illustrated in element 140. The EAP-success message (including the MSK) is forwarded from WLAN AN 14 to UE 10 as illustrated by element 142. Upon receiving the EAP-Success message, UE 10 derives the MSK as specified in process 128 (if not already derived). UE 10 then uses the first 256-bit portion of the MSK as a PMK to perform a 4-way handshake to establish a secure connection between WLAN AN 14 and UE 10 (as illustrated by elements 144-U and 144-W).

[0045] While the procedure as described above is useful in performing NSWO-based authentication, when UE 10 moves to a different WLAN, its authentication disappears and the entire NSWO process needs to be repeated. While the previous 4G specifications allow for UE movement to another WLAN, the 5G specifications contain no similar provisions. That is, UE 10 cannot connect to a new WLAN AN using its 5G credentials established in the method described above and have traffic offloaded to the new WLAN. Thus, in the current environment UE 10 must again perform the full NSWO authentication process, leading to delay in the UE connection. Avoiding the need to re -perform the full authentication is considered to be beneficial to cable operators, since UE connect time to NSWO will reduce.

[0046] It is this limitation that is addressed by the principles of this disclosure, which allow for UEs to connect with other deployed WLANs that support NSWO interworking, usingtheir 5G credentials as previously established. Inasmuch as the UE is already authenticated via the core network in the previous NS WO authentication, the UE is now permitted to connect without the need to re-establish its authorization.

[0047] As will be discussed below and evident from the signal diagrams of FIGs. 3, 4, 6, and 7, the disclosed capabilities are based on a network entity (for example, NSWOF 14 or AUSF 16) maintaining an NSWO UE context at the completion of authentication, and thereafter have access to this information for mobility purposes. In particular, the network entity generates an NSWO UE temporary ID and retains this ID in combination with the MSK as the “NSWO UE context.” As part of the procedure, the UE is required to indicate that it is capable of supporting “NSWO mobility” during the initial steps of the NSWO authentication process (referred to hereinafter as an “NSWO mobility indicator”). An example embodiment of UE mobility in NSWO authentication where NSWOF 12 is utilized as the network entity to support mobility is first described below with reference to FIGs. 3 - 5. Another example embodiment of UE mobility is discussed in association with FIGs. 6 - 8, which describe the use of ASUF 16 as the network entity that supports mobility.

[0048] FIG. 3 contains a signaling diagram of initial NSWO authentication similar to that of FIG. 2, but includes detailed elements configured to support NSWO mobility in accordance with the principles of the present disclosure. In particular, the example as shown in FIG. 3 is based upon using NSWOF 14 itself to maintain the NSWO UE context information (that is, the information that UE 10 is configured to permit for the equipment to be moved from one location to another and, as a result, to move its communication link from one WEAN to another). The ability of NSWO authentication to recognize UE mobility is shown in particular in FIG. 3 during the initial EAP request and response phase of NSWO authentication. In particular, element 112A (in contrast to element 112 of FIG. 2) includes having UE 10 communicate its ability to support NSWO mobility as part of its response to WLAN AN 14. That is, in response to the initial EAP request, UE 10 may send both its SUCI and (if supported) its NSWO mobility indicator. Particulars regarding apparatus associated with UE mobility capability will be described below in association with FIG. 10; for the purposes of the signal diagram explanation, UE mobility support will be presumed. It is to be noted that this is only one example process. More generally, UE 10 may send its NSWO mobility indicator toward NSWOF 12 (or AUSF 16, depending on implementation) at any point during its connection to 5G network 1 through the original WLAN AN 14. The following discussion presumes the transmission of this mobility capability during the initial authentication steps for the sake of brevity.

[0049] Following element 114A shows that WLAN AN 14 includes the receiver NS WO mobility indicator as part of the SWa message sent to NSWOF 12 at the initiation of the authentication process. In this example, the NSWO mobility indicator remains stored at NSWOF 12, and the rest of the initial NSWO authentication process continues in the manner outlined above in association with FIG. 2 until reaching completion (element 138). Recall that it is at this point that EAP-Success and MSK key are received at NSWOF 12 from AUSF 16. In accordance with the disclosed principles, a new element 200 is added to the procedure at this point, where NSWOF 12 creates an NSWO UE temporary ID which will later be used to effectuate mobility. Element 200 is further identified as causing NSWOF 12 to retain the NSWO UE temporary ID, linked with the MSK, as the NSWO UE context.

[0050] A following updated element 140A is shown in FIG. 3 as including this NSWO UE temporary ID as part of the SWa protocol message sent from NSWOF 12 to WLAN AN 14. Following that and as shown in element 142A, the NSWO UE temporary ID is sent to UE 10, which also maintains a NSWO UE context, including both the NSWO UE temporary ID and MSK as shown in element 210. The same four-way handshake between element 146-U and element 146-W is performed to establish a secure communication link between UE 10 and WLAN AN 14.

[0051] Unless and until UE 10 moves out of the communication range of WLAN AN 14, the interactions between UE 10 and 5G network 1 continue in the same manner as described above.

[0052] With reference back to FIG. 1, once UE 10 moves to a location where it is no longer in communication with WLAN AN 14, it may desire to access its 5G home network 1 via communication with another WLAN AN (denoted in FIG. 1 as WLAN AN 14A).Previously, UE 10 would need to use the complete NSWO authentication process as outlined in the diagram of FIG. 2 to create this communication link. In accordance with the disclosed principles, the elements associated with the NSWO UE context may now be used to quickly establish communication between UE 10 and 5G network 1 through this new WLAN AN 14A without the need to again perform the complete NSWO authentication process. FIG. 4 is a signal diagram illustrating one example of updating the connection of UE 10 to 5G network 1 through the new WLAN AN 14A.

[0053] For example as shown in FIG. 4, the new WLAN AN 14A may transmit an EAP Identity (ID) Request to UE 10 as shown in element 300, as would occur to initiate any communication upon the establishment of an IEEE 802.11 connection. In response to the identity request and in accordance with one example of the disclosed procedure, UE 10responds in element 310 with an EAP identity response including its NS WO UE temporary ID. That is, in accordance with the disclosed principles, the NS WO UE temporary ID is used in place of SUCI (as used for initial authentication) for the EAP response. As illustrated in element 312, WLAN AN 14A sends an SWa protocol message of the EAP identity response (including the NSWO UE temporary ID) toward NSWOF 12 within 5G network 1. Upon recognizing the presence of the NSWO UE temporary ID, NSWOF 12 responds by fetching (element 314) the MSK stored in context with this particular NSWO UE temporary ID (i.e., element 200 of FIG. 3).

[0054] As long as NSWOF 12 is able to find an MSK based on the presented NSWO UE temporary ID, UE 10 may be authenticated without requiring any additional challenge / response transmissions. If NSWOF 12 does not recognize the presented temporary ID, it may send an error message back towards UE 10 requesting a retransmission. Alternatively, NSWOF 12 may request both the SUCI and the NSWO UE temporary ID so that a full NSWO authentication can be executed if the provided NSWO UE temporary ID is not recognized.

[0055] Presuming that the MSK associated with the NSWO UE temporary ID has been retrieved, NSWOF 12 generates a new MSK (referred to hereinafter as a mobility key) in element 316 and returns an SWa protocol message including EAP_success and mobility key generation identification back to WLAN AN 14A in element 318. WLAN AN 14A forwards this message on to UE 10 in element 320, where UE 10 then generates the new mobility key in element 322. Thereafter, the new mobility key is used to perform a four- way handshake between UE 10 and WLAN AN 14A to establish a secure communication path. As the NSWO UE temporary ID is used only once by NSWOF 12 (that is, in the generation of a mobility key), a new NSWO UE temporary ID is created at NSWOF 12 for the next mobility event, where the new NSWO UE temporary ID is also sent to UE 10.

[0056] FIG. 5 illustrates an example method of generating a mobility key as may be performed by NSWOF 12 in element 316 and UE 10 in element 322. With reference to diagram A in FIG. 5, a mobility key may be generated by a KDF 500, having as inputs the NSWO UE temporary ID, the existing MSK and the function code (FC), where FC is used to select the particular derivation function to be employed. The generated mobility key is shown as MSKNSWO_MOBILITY. The example shown in diagram A is only one possibility; another example is shown in diagram B, where a random number input (RAND) is used in combination with the NSWO UE temporary ID and MSK in a KDF 510 to generate the mobility key MSKNSWO_MOBILITY- If RAND is used as part of the process in element 316,NSWOF 12 sends the RAND as part of the SWa protocol message sent to WLAN AN2 (element 318). Diagram C in FIG. 5 shows yet another example of mobility key generation, where the output of a counter (COUNT) is used in combination with the NSWO UE temporary ID and MSK as inputs to a KDF 520 to generate the mobility key MSKNSWO_MOBILITY- If COUNT is used, it is required that both NSWOF 12 and UE 10 maintain the counters and increment by a constant value to generate the new keys.

[0057] The procedure as described above with the signal diagrams of FIGs. 3 and 4 illustrate only one example of permitting UE mobility from one WLAN to another based on existing NSWO authentication. FIGs. 6 and 7 show another possibility, in this case where the additional UE context is controlled within AUSF 16 (as opposed to NSWOF 12). That is, AUSF 16 is the network entity selected to effectuate UE mobility in NSWO authentication. With reference to FIG. 6, the initial enhancements associated with this example are shown. During the initial EAP request and response phase of NSWO authentication, element 112A (similar to that of FIG. 3 and again in contrast to element 112 of FIG. 2) includes having UE 10 communicate its ability to support NSWO mobility as part of the response to WLAN AN 14; that is UE 10 sends in response both its SUCI and “NSWO mobility indicator” (again, in the broadest context of this disclosed principles, the NSWO mobility indicator may be sent to WLAN AN 14 at any point in time during the established communication between UE 10 and WLAN AN 14). Following element 114A shows that WLAN AN 14 forwards both SUCI and the NSWO mobility indicator to NSWOF 12. These are essentially the same initial steps as described above when using NSWOF 12 as the network entity supporting mobility.

[0058] In this example, however, NSWOF 12 forwards the UE’s information with respect to supporting NSWO mobility to AUSF 16 in element 116A, where it is retained until AUSF 16 receives a message that UE 10 has established communication via a different WLAN. Thus, the remainder of the authentication process shown in FIG. 6 continues in the manner outlined above in association with FIG. 2 until reaching element 136. Upon successful completion of NSWO authentication, a new element 400 is added to the procedure where AUSF 16 creates an NSWO UE temporary ID, which is linked with the MSK key information. In this example, AUSF stores this combination of the NSWO UE temporary ID and the MSK as the NSWO UE context (which may also be identified as the AUSF context).

[0059] A following updated element 138A is shown in FIG. 5 as including this NSWO UE temporary ID as part of the SWa protocol message sent from AUSF 16 to NSWOF 12, with an updated element 140A showing the forwarding of the NSWO UE temporary ID to WLAN AN 14. Following that and as shown in element 142A, the NSWO UE temporary ID is sentto UE 10, which maintains the NSWO UE context (element 410), including both the NSWO UE temporary ID and MSK. Until UE 10 moves out of communication with WLAN AN 14, the interactions between UE 10 and 5G home network 1 continue in the same manner as described above.

[0060] With reference again back to FIG. 1, once UE 10 moves to a location where it is no longer in communication with WLAN AN 14, but desires to maintain communication with its 5G home network 1 via different WLAN AN 14A, the elements associated with the NSWO UE context may be used to quickly establish communication between UE 10 and WLAN AN 14A. FIG. 7 is a signal diagram illustrating an example procedure following on the outline of utilizing AUSF 16 as the network entity for supporting mobility in the example as described above in association with FIG. 6.

[0061] For example as shown in FIG. 7, new WLAN AN 14A may transmit an EAP Identity (ID) Request to UE 10 as shown in element 600. In response to the identity request and in accordance with this another example of the disclosed procedure, UE 10 responds in element 610 with an EAP identity response including its NSWO UE temporary ID. As illustrated in element 612, WLAN AN 14A sends an SWa protocol message of the EAP identity response with the NSWO UE temporary ID toward NSWOF 12 within 5G network 1.

[0062] Following in element 614, NSWOF 12 sends an authentication request message (e.g., Nausf_UEAuthentication_Authenticate Request) including the NSWO UE temporary ID towards AUSF 16. Using the NSWO UE temporary ID, AUSF 16 fetches in element 616 the MSK from the stored NSWO UE context in element 400 (see FIG. 6). AUSF 16 proceeds at element 618 to generate a mobility key using a KDF in a manner discussed below in association with FIG. 8. Following this, AUSF 16 in element 620 sends Nausf_UEAuthentication_Authenticate response message including the mobility key indicator (e.g., RAND / COUNT) toward NSWOF 12. NWSOF 12 sends an SWa protocol message with EAP-success towards UE 10 via WLAN AN 14A in element 624, with UE 10 thereafter generating the new mobility key (based on the received key indicator) required for communication with 5G network 1 through WLAN AN 14A. Thereafter, the new mobility key is used to perform a four- way handshake between UE 10 and WLAN AN 14A to establish a secure communication path.

[0063] FIG. 8 depicts examples that may be used for generation of the AUSF mobility key. Diagram A shows the use of a random number (RAND) in combination with the MSK and FC as inputs to a selected KDF element 800. Based on the FC value, KDF 800 generates a mobility key MSKNSWO / AUSF_MOBILITY- Diagram B shows a similar arrangement, in this caseused a counter input (COUNT) in place of the RAND input to a KDF element 810. Again, if RAND is used as an input to the key generation step, it needs to be included in the message returned to UE 10. If COUNT is used, both AUSF 16 and UE 10 need to include counters that perform a like increment in value.

[0064] For either example of implementing UE mobility in an NSWO authentication environment, the NSWO UE temporary ID may be generated by many various means to preserve its privacy. For example, the temporary ID may be:<PLMNID><NSWOF_IDxTemp Id>.In the NAI format, the temporary ID may take the form of: username© realm where <Temp Id>.@<PLMNIDxNWSOF_ID>, or<Temp Id>.@<PLMINID>, where “Temp Id.” is the uniquely generated number.

[0065] FIG. 9 depicts a block diagram of an apparatus such as a network entity 900, in accordance with some example embodiments. Network entity 900 may be configured to provide one or more network-side operations as performed within 5G home network 1. Moreover, network entity 900 may have a plurality of network functions. For example, the network entity may be incorporated into one or more of the network entities and functions 12, 16, and 18, described above with regard to FIG. 1. The network entity 900 may include a network interface 902, a processor 904, and a memory 906, in accordance with some example embodiments. The network interface 902 may include wired and / or wireless transceivers to enable access other entities, nodes, and / or functions including base stations, entities 14, 12, 16, and 18, the Internet, functions, and / or other entities. The memory 902 may comprise volatile and / or non-volatile memory including program code, which when executed by at least one processor 904 provides, among other things, the processes disclosed herein including NSWO UE temporary ID creation and mobility key generation.

[0066] FIG. 10 illustrates a block diagram of an apparatus 1000 such as user equipment 10. Apparatus 1000, or portions therein, may be implemented in other network entities including base stations / WEAN access points, functions, as well as the other network entities (e.g., devices 12, 16, and 18). Apparatus 1000 may include at least one antenna 1002 in communication with a transmitter 1004 and a receiver 1006. Alternatively, transmit and receive antennas may be separate. Apparatus 1000 may also include a processor 1008 configured to provide signals to and receive signals from the transmitter and receiver,respectively, and to control the functioning of the apparatus. Processor 1008 may be configured to control the functioning of the transmitter and receiver by effecting control signaling via electrical leads or wirelessly to the transmitter and receiver. Likewise, processor 1008 may be configured to control other elements of apparatus 1000 by effecting control signaling via electrical leads or wirelessly connecting processor 1008 to the other elements, such as a display or a memory. Processor 1008 may, for example, be embodied in a variety of ways including circuitry, at least one processing core, one or more microprocessors with accompanying digital signal processor(s), one or more processor(s) without an accompanying digital signal processor, one or more coprocessors, one or more multi-core processors, one or more controllers, processing circuitry, one or more computers, various other processing elements including integrated circuits (for example, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), and / or the like), or some combination thereof. Accordingly, although illustrated in FIG. 10 as a single processor, in some example embodiments processor 1008 may comprise a plurality of processors or processing cores.

[0067] Apparatus 1000 may be capable of operating with one or more air interface standards, communication protocols, modulation types, access types, and / or the like. Signals sent and received by the processor 1008 may include signaling information in accordance with an air interface standard of an applicable cellular system, and / or any number of different wireline or wireless networking techniques, comprising but not limited to Wi-Fi, WLAN techniques, such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, 802.16, 802.3, ADSL, DOCSIS, and / or the like. In addition, these signals may include speech data, user generated data, user requested data, and / or the like. One or more memory elements 1010 may be used to store information such as NS WO UE context information and interact with processor 1008 in a known manner.

[0068] For example, apparatus 1000 and / or a cellular modem therein may be capable of operating in accordance with various communication protocols, such as first generation (1G) communication protocols, second generation (2G or 2.5G) communication protocols, third- generation (3G) communication protocols, fourth-generation (4G) communication protocols, fifth-generation (5G) communication protocols, Internet Protocol Multimedia Subsystem (IMS) communication protocols (for example, session initiation protocol (SIP) and / or the like. For example, apparatus 1000 may be capable of operating in accordance with 2G wireless communication protocols IS- 136, Time Division Multiple Access TDMA, Global System for Mobile communications, GSM, IS-95, Code Division Multiple Access, CDMA, and / or the like. In addition, for example, apparatus 1000 may be capable of operating inaccordance with 2.5G wireless communication protocols General Packet Radio Service (GPRS), Enhanced Data GSM Environment (EDGE), and / or the like. Further, for example, apparatus 1000 may be capable of operating in accordance with 3G wireless communication protocols, such as Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), Wideband Code Division Multiple Access (WCDMA), Time Division-Synchronous Code Division Multiple Access (TD-SCDMA), and / or the like. Apparatus 1000 may be additionally capable of operating in accordance with 3.9G wireless communication protocols, such as Long Term Evolution (LTE), Evolved Universal Terrestrial Radio Access Network (E-UTRAN), and / or the like. Additionally, for example, apparatus 1000 may be capable of operating in accordance with 4G wireless communication protocols, such as LTE Advanced, 5G, and / or the like as well as similar wireless communication protocols that may be subsequently developed.

[0069] It is understood that processor 1008 may include circuitry for implementing audio / video and logic functions of apparatus 1000. For example, processor 1008 may comprise a digital signal processor device, a microprocessor device, an analog-to-digital converter, a digital-to-analog converter, and / or the like. Control and signal processing functions of apparatus 1000 may be allocated between these devices according to their respective capabilities. In general, processor 1008 and stored software instructions may be configured to cause apparatus 1000 to at least perform certain actions. For example, processor 1008 may be capable of performing authentication procedures, such as key generation, security handshakes, and the like. The connectivity program may allow apparatus 1000 to transmit and receive web content, such as location-based content, according to a protocol, such as wireless application protocol, WAP, hypertext transfer protocol, HTTP, and / or the like. It is to be understood that the apparatus as shown in FIGs. 9 and 10, include at least one processor, at least one memory including computer program code, and the at least one processor, with the at least one memory and the computer program code, being arranged to cause the apparatus to at least perform at least the method according to at least one of signal diagrams as shown in FIGs. 3, 4, 6, and 7, and their related descriptions.

[0070] FIG. 11 depicts a method 1100 for wireless communications by a UE that is configured to support inter- WLAN AN mobility. The method comprises requesting, by a user equipment (UE), a wireless connection to a network entity through a first WLAN at step 1100-1. In an example embodiment, the wireless connection is a non-seamless wireless offload (NS WO) connection to the network entity during an extensible authentication protocol (EAP) procedure. Said requesting 1100-1 can be carried out using any suitableapparatus comprising means, e.g., an apparatus such as described above in association with FIG. 10. The method further comprises receiving, by the UE, from the network entity, an identity request at step 1100-2. The identity request being an EAP-ID-Request. Said receiving 1100-2 can be carried out using any suitable apparatus comprising means, e.g., an apparatus comprising one or more processors and one or more memories, such as apparatus 1000. The method further comprises step 1100-3, where in response to the identity request, causing transmission of, by the UE and to the network entity, an identity response comprising: (1) a UE identifier to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identifier, and (2) an NSWO mobility indicator, identifying the UE as capable of supporting mobility of its NSWO authentication through another WLAN.

[0071] FIG. 12 depicts a method 1200 for wireless communications. The method comprises at step 1200-1 requesting, in response of a relocation of an NSWO-authenticated UE, a wireless connection to the network entity through a second, different WLAN AN. At step 1200-2, the method includes receiving, by the UE, from the network entity, an identity request. Lastly, in step 1200-3, in response to the identity request, the method includes causing transmission of, by the UE, an identity response comprising the stored NSWO UE temporary ID such that the UE is enabled to maintain contact with the network entity based on the previous NSWO authentication.

[0072] FIG. 13 depicts a method 1300 for wireless communications associated with networkside preparations for UE mobility. The method comprises receiving, at a network entity, a request from a user equipment (UE) for a wireless connection to the network entity at step 1300-1. In an example embodiment, the wireless connection is a non-seamless wireless offload (NSWO) connection to the network entity during an extensible authentication protocol (EAP) procedure, and the request includes both the UE identifier and an NSWO mobility indicator. The method continues at step 1300-2 by creating, upon authentication of the UE at the network entity (and the generation of a master session key (MSK)), an NSWO UE temporary ID for use in mobility applications. Thereafter, at step 1300-3, the network function stores the NSWO UE temporary ID and associated MSK as the “NSWO UE context”, as will be used later during mobility of the UE.

[0073] FIG. 14 depicts a wireless communication method 1400 for effecting NSWO mobility of a UE from a first WLAN AN to a second WLAN AN. Step 1400-1 begins with receiving, by a network function, from a network entity, a user equipment (UE) identifier in the form of its NSWO UE temporary ID. The network function recognizes the temporary ID asassociated with “mobility” (as opposed to the reception of the SUCI as associated with authentication) and proceeds at step 1400-2 with fetching, from the NDWO UE context within the network function, the MSK associated with the presented NSWO UE temporary ID. Following this, at step 1400-3, the network function generates, using the NSWO UE temporary ID and the MSK, a mobility key for permitting access of the UE to the network entity from a second, different WLAN AN without requiring additional NSWO authentication.

[0074] In addition to the embodiments above, the disclosure addresses a scenario where two WLANs, such as WLAN AN1 14 and WLAN AN2 14A, are close together (i.e., nearby or even overlapping). In such a scenario the UE’s 10 connectivity to the network 1 may be broken as the UE 10 attempts to connect to WLAN AN2 14A that is nearby WLAN AN 14. Further, the closeness of the two WLANs may cause the UE 10 to complete another full authentication procedure at the NSWOF 12 as defined in annex S of TS 33501, even though both WLAN AN1 14 and WLAN AN2 14A are connected to the same NSWOF 12. Such an additional, full authentication may lead to additional signaling and may cause latency in the UE 10 connection. This is inefficient and disrupts the user experience.

[0075] Accordingly, the present disclosure provides embodiments that do not require a UE (e.g., UE 10) to complete an additional full authentication while ensuring the connection of a UE to a nearby second WLAN AN (e.g., WLAN AN 14A) remains secure.

[0076] As will be explained in more detail below, the present disclosure provides the following exemplary methods of re- authorizing and re-authenticating the UE 10 so that the UE may connect to the wireless network 1.

[0077] In a first method, the method may comprise: generating a first re-authorization identification (ID) by the AUSF 16 based on a MSK key and a constant value; sending the first re-authorization to the NSWOF 12; sending the constant value to the UE 10; generating a second re-authorization ID by the UE 10 based on the MSK key and the constant value; sending the second re-authorization ID from the UE 10 to the NSWOF 12 as the UE 10 moves from the first WLAN AN 14 to the second, different nearby WLAN AN 14A; and reauthorizing and reauthenticating the UE 10 based on the second re-authorization ID received by the NSWOF 12.

[0078] A second method for re-authorizing and re-authenticating the UE 10 to allow the UE 10 to connect to the wirelsss network 1 may comprise: sending a MSK key from the AUSF 16 to the NSWOF 12; generating a first re-authorization ID by the NSWOF 12 based on the MSK key and a selected constant value; the sending the selected constant value to UE 10; generating a second re- authorization ID by the UE 10 based on the MSK key and the selected constant value; sending the second re-authorization ID to the NSWOF 12 as the UE 10 moves from the first WLAN AN 14 to the second, different nearby WLAN AN 14A; and reauthorizing and reauthenticating the UE 10 based on the second re-authorization ID received by the NSWOF 12.

[0079] In the discussion above it should be understood that the constant value referred to therein may be the same value or selected form a plurality of different values, for example.

[0080] From our earlier discussion related to FIG. 6 we mentioned that during element 400 the AUSF 16 may generate and store an NSWO UE temporary ID based on MSK key information. It is the temporary ID that now be used as a “re-authorization ID” or “reauth id”. This allows MSK keys to be derived or refreshed without performing full authentication. Upon generating the re-authorization ID the AUSF 16 may store the combination of the NSWO UE temporary ID or reauth id and the MSK key as the AUSF UE context.

[0081] The AUSF 16 may send the re-authorization ID and a UE “constant” value that is used to generate the reauth id to NSWOF 12. Thereafter, the NSWOF 12 provides the MSK key and re-authorization ID to the WLAN AN 14, and WLAN AN 14 provides the same to UE 10. When the UE 10 moves or tries to reconnect to a different WLAN, such as WLAN AN 14A for NSWO, the UE 10 provides the re-authorization ID in an EAP response to the second WLAN AN 14A which allows the NSWOF 12 or AUSF 16 to identify the UE 10 based on the re-authorization ID and then help NSWOF 12 or AUSF 16 to further refresh the MSK and NSWO UE temporary ID.

[0082] Further, thereafter the NSWOF 12 may generate a new re-authorization ID based on a new random number (also called RAND) and send the new re-authorization ID and a RAND value to UE 10 via the second WLAN AN 14A. The UE shall refresh the MSK key based onthe RAND value, secure the connection via the MSK key and store the re-authorization ID for further future reconnection to the network.

[0083] For the reader’s reference the above steps (and additional steps) are set forth in further detail in elements 1500 to 1520 in FIG. 15.

[0084] It should be noted that Instead of the AUSF 16 storing the context, the NSWOF 12 may also store the context and derive the MSK keys. In such a case, AUSF 16 provides MSK to NSWOF and NSWOF generates the further key material.

[0085] In an embodiment, the re-authorization ID may be configured to a size and format that is compatible with the following message:<NSWO-UE-Reauth-ID = <AUSFID><TEMPORARY_NUMBER»@homeRealm, where (i) < AUSFID > equals <MCC><MNC><AUSF SET ID>, (ii) MCC and MNC have the same field size as in earlier 3GPP systems, (iii) the TEMPORARY_NUMBER will be 32 bits in length, (iv) the AUSF Set ID will be 10 bits in length and (v) the “HomeRealm” should be in the form "5gc.mnc<MNC>.mcc<MCC>.3gppnetwork.org".

[0086] Alternatively, instead of using an AUSF Set ID, a group ID can be used.

[0087] In yet another embodiment the re-authorization ID may include an AUSF pointer for security. In such an embodiment, the re-authorization ID may be configured to a size and format that is compatible with the following message:<NSWO-UE-Reauth-ID = <AUSFIDxTEMPORARY_NUMBER»@ Homerealm, where (i) < AUSFID > equals <MCCxMNCxAUSF Identified, (ii) <AUSF Identified equals <AUSF Set ID»<AUSF Pointed, (iii) MCC and MNC have the same field size as in earlier 3GPP systems, (iv) the TEMPORARY_NUMBER will be 32 bits in length, (iv) the AUSF Set ID will be 10 bits in length, (v) the AUSF pointer will be 6 bits in length, and (vi) the “HomeRealm” should be in the form "5gc.mnc<MNC>.mcc<MCC>.3gppnetwork.org".

[0088] Alternatively, instead of using an AUSF Set ID, a group ID can be used.

[0089] In the embodiments just discussed, the re-authorization ID is generated by the AUSF 16. However, in yet another alternative embodiment the re-authorization ID may be generated by the NSWOF 12 and sent to UE 10. Upon receiving the re-authorization ID the UE 10 may store it and then use the re-authorization ID to reconnect to the second WLAN AN 14A.Thereafter, WLAN AN 14A may select the correct NSWOF based on the re- authorization ID.

[0090] In more detail, the AUSF 16 may generate an MSK key which can be sent to, and used, by the NSWOF 12 to generate a re-authorization ID.

[0091] A new (or second) WLAN AN 14A may transmit an EAP Identity (ID) Request to UE 10. In response to the identity request, UE 10 may respond to WLAN AN 14A with an EAP identity response including the UE’s re-authorization ID. The WLAN AN 14A may send an SWa protocol message of the EAP identity response with the NSWO UE re-authorization ID toward NSWOF 12 within 5G network 1. Using the re-authorization ID, NSWOF 12 may fetch the MSK key and temporary ID that was previously stored as a NSWO UE context.NSWOF 12 may proceed to generate a new MSK key, and a new re-authorization ID based on the new constant value or RAND value. Thereafter, NSWOF 12 may send an SWa protocol message with an EAP-success indicator that includes the new MSK indicator and new re-authorization ID to WLAN AN 14A. Upon receiving the SWa message the WLAN AN 14A may send the EAP-success indicator that includes a RAND and the re- authorization ID to UE 10. Thereafter, the UE 10 may refresh its MSK (mobility) key. The refreshed MSK key may be used to generate a new re-authorization ID based on the received RAND value.

[0092] For the reader’ s reference the above steps (and additional steps) are set forth in further detail in elements 1600 to 1618 in FIG. 16.

[0093] In such an embodiment, the re- authorization ID may be configured in a format and size that is compatible with the following message:<NSWO-UE-Reauth-ID> = <NSWOFID><TEMPORARY_NUMBER>@ Homerealm, where (i) < NSWOFID > equals <MCC><MNC><NSWOF Set ID>, , (ii) MCC and MNC will have the same field size as in earlier 3GPP systems, (iii) a TEMPORARY_NUMBER will be 32 bits in length, and (iv) and the HomeRealm should be in the form: "5gc.mnc<MNC>.mcc<MCC>.3gppnetwork.org".

[0094] In yet another embodiment the re-authorization ID may include a NSWOF pointer for security. In such an embodiment, the re-authorization ID may be configured to a size and format that is compatible with the following message:<NSWO-UE-Reauth-ID = <NSWOFIDxTEMPORARY_NUMBER»@HomeRealm, where (i) < NSWOFID > equals <MCC><MNC><NSWOF Identifier^ (ii) <NSWOF Identified equals <NSWOF Set ID»<NSWOF Pointed, (iii) MCC and MNC have the same field size as in earlier 3GPP systems, (iv) the TEMPORARY_NUMBER will be 32 bits in length, (iv) the NSWOF Set ID will be 10 bits in length, (v) the NSWOF pointer will be 6 bits in length, and (vi) the “HomeRealm” should be in the form "5gc.mnc<MNC>.mcc<MCC>.3gppnetwork.org".

[0095] FIG. 17 depicts a simplified block diagram illustrating how a re-authorization ID may be generated. In an embodiment, the re-authorization ID may be generated by an element 1700 (e.g., NSWOF) having the following inputs:FC = OxxP0 = temporary UEIDE0 = length of temporary UEID MSK is used as root key.Alternatively, P0 may also comprise a RAND or constant value.Based on the inputs, the element 1700 may generate a re-authorization ID configured to have a format and size TEMPORARY_NUMBER@HomeRealm.

[0096] As described above, the referenced flowcharts of methods that can be carried out by an apparatus according to related computer program products comprising computer program code. It will be understood that each block of the flowcharts, and combinations of blocks in the flowcharts, can be implemented by various means, such as hardware, firmware, processor, circuitry, and / or other devices associated with execution of software including one or more computer program instructions. For example, one or more of the procedures described above can be embodied by computer program instructions. As will be appreciated, any such computer program instructions can be loaded onto a computer or other programmable apparatus (e.g., hardware) to produce a machine, such that the resultingcomputer or other programmable apparatus implements the functions specified in the flowchart blocks. These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture, the execution of which implements the function specified in the flowchart blocks. The computer program instructions can also be loaded onto a computer or other programmable apparatus to cause a series of operations to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide operations for implementing the functions specified in the flowchart blocks.

[0097] In some further example embodiments, a computer program product is provided, said computer program product may be stored by or on an apparatus or a component thereof. Said computer code can be executed by an apparatus (e.g., a network entity). A computer program product is therefore defined in those instances in which the computer program instructions, such as computer-readable program code portions, are stored by at least one non-transitory computer-readable storage medium with the computer program instructions, such as the computer-readable program code portions, being configured, upon execution, to perform the functions described above. In other embodiments, the computer program instructions, such as the computer-readable program code portions, need not be stored or otherwise embodied by a non-transitory computer-readable storage medium, but can, instead, be embodied by a transitory medium with the computer program instructions, such as the computer-readable program code portions, still being configured, upon execution, to perform the functions described above.

[0098] Accordingly, blocks of the flowcharts support combinations of means for performing the specified functions and combinations of operations for performing the specified functions. It will also be understood that one or more blocks of the flowcharts, and combinations of blocks in the flowcharts, can be implemented by special purpose hardware-based computer systems which perform the specified functions, or combinations of special purpose hardware and computer instructions.

[0099] In some embodiments, certain ones of the operations, methods, steps, processes, apparatuses, or the like, above can be modified or further amplified. Furthermore, in some embodiments, additional optional operations, methods, steps, processes, hardware, or the like, can be included. Modifications, additions, subtractions, inversions, correlations, proportional relationships, disproportional relationships, attenuation and / or amplifications to theoperations above can be performed in any order and in any combination. It will also be appreciated that in instances where particular operations, methods, processes, or the like, required particular hardware such hardware may be considered as part of an apparatus for any such embodiment.

[0100] Many modifications and other embodiments of the inventions set forth herein will come to mind to one skilled in the art to which these inventions pertain having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the inventions are not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of the appended claims.

[0101] Moreover, although the foregoing descriptions and the associated drawings describe certain example embodiments in the context of certain example combinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions can be provided by alternative embodiments without departing from the scope of the appended claims. In this regard, for example, different combinations of elements and / or functions than those explicitly described above are also contemplated as can be set forth in some of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

1. A method comprising: requesting, by a user equipment (UE), a wireless connection to a network entity through a first wireless local area network access network (WLAN AN), the UE configured to support inter- WLAN AN mobility and the request comprising a UE identifier and a nonseamless WLAN offload (NSWO) mobility support indicator; receiving, by the UE, an authentication success indication including an NSWO UE temporary ID for use in inter- WLAN AN mobility; requesting, by the UE, a wireless connection to the network entity through a second WLAN AN, the request comprising the NSWO UE temporary ID; receiving, by the UE, a connection confirmation including a mobility key generation indicator; and generating, by the UE, the mobility key for creating secure communication with the network entity through the second WLAN AN.

2. The method according to claim 1, wherein the request for connection to the network entity through the second WLAN AN further comprises the UE identifier.

3. The method according to claim 1, wherein the UE identifier and the NSWO mobility indicator comprise a single request message sent to the network entity.

4. The method according to claim 1, wherein the UE identifier and the NSWO mobility indicator comprise separate request messages sent to the network entity.

5. The method according to claim 1 wherein the network entity is an NSWO function element (NSWOF).

6. The method according to claim 1 wherein the network entity is an authentication server function (AUSF).

7. The method according to claim 1, wherein the step of generating the mobility key includes presenting as inputs to a selected key derivation function (KDF), the NSWO UE temporary ID and the MSK, and an FC to generate the mobility key.

8. The method according to claim 1, wherein the step of generating the mobility key includes presenting as inputs to a selected key derivation function (KDF), the MSK, an FC used to identify a particular derivation function and an additional parameter selected from the group consisting of: RAND, COUNT, NSWO UE temporary ID, a combination of RAND and NSWO UE temporary ID, and a combination of COUNT and NSWO UE temporary ID.

9. A method comprising: receiving, by a network entity, from a UE configured to support inter- WLAN AN mobility, a request for a wireless connection to the network entity through a first WLAN AN, the request comprising a UE identifier and an NSWO mobility support indicator; creating, upon authentication of the UE and the generation of an MSK, an NSWO UE temporary ID for use in mobility applications; and storing, at the network entity, an NSWO UE context including the NSWO UE temporary ID and the MSK.

10. The method according to claim 9, further comprising: receiving, by the network entity, from the UE, a request for a wireless connection to the network entity through a second, different WLAN, the request comprising the NSWO UE temporary ID; fetching, by the network entity, from the NSWO UE context stored at the network entity, the MSK associated with the NSWO UE temporary ID; generating, using the NSWO UE temporary ID and MSK, a mobility key for permitting secure communication between the UE and the second WLAN AN; and sending, by the network entity, an access success message toward the UE, the access success message including a mobility key generation indicator for use by the UE in generating the mobility key.

11. The method according to claim 10, wherein the step of generating the mobility key includes presenting as inputs to a selected key derivation function (KDF), the NSWO UE temporary ID and the MSK, and an FC to generate the mobility key.

12. The method according to claim 10, wherein the step of generating the mobility key includes presenting as inputs to a selected key derivation function (KDF), the MSK, an FC used to identify a particular derivation function and an additional parameter selected fromthe group consisting of: RAND, COUNT, NSWO UE temporary ID, a combination of RAND and NSWO UE temporary ID, and a combination of COUNT and NSWO UE temporary ID.

13. The method according to claim 10, further comprising creating, at the network entity, a new NSWO UE temporary ID; storing the new NSWO UE temp ID in the NSWO UE context with the generated mobility key; and sending the new NSWO UE temporary ID to the UE.

14. The method according to claim 13, wherein the step of creating a new NSWO UE temporary ID creates the following:<PLMNID><NSWOF_IDxTemp Id>. where “Temp.Id” is a uniquely generated number.

15. The method according to claim 9 wherein the network entity comprises one of an NSWOF and an AUSF.

16. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least perform: requesting, by a user equipment (UE), a wireless connection to a network entity through a first wireless local area network access network (WLAN AN), the UE configured to support inter- WLAN AN mobility and the request comprising a UE identifier and a nonseamless WLAN offload (NSWO) mobility support indicator; receiving, by the UE, an authentication success indication including an NSWO UE temporary ID for use in inter- WLAN AN mobility; requesting, by a UE, a wireless connection to the network entity through a second WLAN AN, the request comprising the NSWO UE temporary ID; receiving, by the UE, a connection confirmation including a mobility key generation indicator; and generating, by the UE, the mobility key for creating secure communication with the network entity through the second WLAN AN.

17. The apparatus according to claim 16, wherein the apparatus is further caused to performing: sending the UE identifier and the NS WO mobility indicator in separate messages.

18. The apparatus according to claim 16, wherein the apparatus is further caused to perform: generating the mobility key by presenting as inputs to a selected key derivation function (KDF), the NS WO UE temporary ID and the MSK, and an FC.

19. The apparatus according to claim 16, wherein the apparatus is further caused to perform: generating the mobility key by presenting as inputs to a selected key derivation function (KDF), the MSK, an FC used to identify a particular derivation function, and an additional parameter selected from the group consisting of: RAND, COUNT, NSWO UE temporary ID, a combination of RAND and NSWO UE temporary ID, and a combination of COUNT and NSWO UE temporary ID.

20. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least processor, cause the apparatus to at least perform: receiving, by a network entity, from a UE configured to support inter- WLAN AN mobility, a request for a wireless connection to the network entity through a first WLAN AN, the request comprising a UE identifier and an NSWO mobility support indicator; creating, upon authentication of the UE and the generation of an MSK, an NSWO UE temporary ID for use in mobility applications; and storing, at the network entity, an NSWO UE context including the NSWO UE temporary ID and the MSK.

21. The apparatus of claim 20, further caused to perform: receiving, by the network entity, from the UE, a request for a wireless connection to the network entity through a second, different WLAN, the request comprising the NSWO UE temporary ID; fetching, by the network entity, from the NSWO UE context stored at the network entity, the MSK associated with the NSWO UE temporary ID;generating, using the NSWO UE temporary ID and MSK, a mobility key for permitting secure communication between the UE and the second WLAN AN; and sending, by the network entity, an access success message toward the UE, the access success message including a mobility key generation indicator for use by the UE in generating the mobility key.

22. The apparatus of claim 21, wherein in generating the mobility key, the apparatus is further caused to perform: presenting as inputs to a selected key derivation function (KDF), the MSK, and an FC, and another parameter selected from the group consisting of: RAND, COUNT, NSWO UE temporary ID, a combination of RAND and NSWO UE temporary ID, and a combination of COUNT and NSWO UE temporary ID.

23. The apparatus of claim 20 wherein the network entity comprises an NSWOF.

24. The apparatus of claim 20 wherein the network entity comprises an AUSF.

25. The apparatus of claim 20, further caused to perform: creating, at the network entity, a new NSWO UE temporary ID; storing the new NSWO UE temp ID in the NSWO UE context with the generated mobility key; and sending the new NSWO UE temporary ID to the UE.

26. The apparatus of claim 20, where the apparatus is further caused to perform: creating the NSWO UE temporary ID to comprise:<PLMNID><NSWOF_IDxTemp Id>. where “Temp.Id” is a uniquely generated number.

27. A method for re-authorizing and re-authenticating user equipment (UE) to connect to a wireless network comprising: generating a first re-authorization identification (ID) by an AUSF based on a MSK key and a constant value; sending the first re-authorization to an NSWOF; sending the constant value to the UE;generating a second re- authorization ID by the UE based on the MSK key and the constant value; sending the second re-authorization ID from the UE to the NSWOF as the UE moves from a first WLAN Access Node to a second, different nearby WLAN Access Node; and, re-authorizing and reauthenticating the UE based on the second re-authorization ID received by the NSWOF.

28. A method for re-authorizing and re-authenticating the user equipment (UE) to connect to a wirelsss network comprising: sending a MSK key from an AUSF to an NSWOF; generating a first re-authorization identification (ID) by the NSWOF based on the MSK key and a selected constant value; sending the selected constant value to UE; generating a second re- authorization ID by the UE based on the MSK key and the selected constant value; sending the second re-authorization ID to the NSWOF as the UE moves from a first WLAN Access Node to a second, different nearby WLAN Access Node; and re-authorizing and reauthenticating the UE based on the second re-authorization ID received by the NSWOF.