Method and apparatus for pre-fetching authentication information in wireless communication system
The method of pre-fetching authentication information and optimizing NAS SMC procedures addresses the challenges of authentication latency and security in satellite communication systems, enhancing efficiency and security in wireless communication systems.
Patent Information
- Application Number
- PCT/KR2024/097079
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-19
- Filing Date
- 2024-12-17
- Publication Date
- 2025-06-26
AI Technical Summary
Current wireless communication systems face challenges in efficiently managing authentication information, particularly in satellite communication scenarios where store and forward operations are involved, leading to delays and security concerns.
A method and apparatus for pre-fetching authentication information in wireless communication systems, specifically for satellite communication, which involves generating and storing authentication vectors (AVs) in advance based on user equipment (UE) parameters, and optimizing the Non-Access Stratum (NAS) Security Mode Command (SMC) procedure to ensure secure and efficient authentication.
This approach reduces authentication latency and enhances security by pre-fetching authentication information, optimizing NAS SMC procedures, and ensuring integrity protection and confidentiality in satellite communication store and forward operations.
Smart Images

Figure KR2024097079_26062025_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR PRE-FETCHING AUTHENTICATION INFORMATION IN WIRELESS COMMUNICATION SYSTEM
[0001] The present disclosure relates to wireless communication systems, and more particularly, the disclosure relates to a method and an apparatus for pre-fetching authentication information in a wireless communication system.
[0002] 5th generation (5G) mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6th generation (6G) mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.
[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced mobile broadband (eMBB), ultra eliable low latency communications (URLLC), and massive machine-type communications (mMTC), there has been ongoing standardization regarding beamforming and massive multiple-input multiple output (MIMO) for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of bandwidth part (BWP), new channel coding methods such as a low density parity check (LDPC) code for large amount of data transmission and a polar code for highly reliable transmission of control information, layer 2 (L2) pre-processing, and network slicing for providing a dedicated network specialized to a specific service.
[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as vehicle-to-everything (V2X) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, new radio unlicensed (NR-U) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, new radio user equipment (NR UE) power saving, non-terrestrial network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.
[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as industrial internet of things (IIoT) for supporting new services through interworking and convergence with other industries, integrated access and backhaul (IAB) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and dual active protocol stack (DAPS) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining network functions virtualization (NFV) and software-defined networking (SDN) technologies, and mobile edge computing (MEC) for receiving services based on UE positions.
[0006] As 5G mobile communication systems are commercialized, connected devices, which have been exponentially increasing, will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with extended reality (XR) for efficiently supporting augmented reality (AR), virtual reality (VR), mixed reality (MR) and the like, 5G performance improvement and complexity reduction by utilizing artificial intelligence (AI) and machine learning (ML), AI service support, metaverse service support, and drone communication.
[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as full dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using orbital angular momentum (OAM), and reconfigurable intelligent surface (RIS), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.
[0008] The above information is presented as background information only to assist with an understanding of the present disclosure. No determination has been made, and no assertion is made, as to whether any of the above might be applicable as prior art with regard to the disclosure.
[0009] The disclosure provides a method and an apparatus for pre-fetching authentication information in a wireless communication system.
[0010] These and other features, aspects, and advantages of the present embodiments are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the drawings, in which:
[0011] Fig. 1 is a sequence diagram that illustrates 5G authentication followed by a NAS SMC procedure;
[0012] Fig. 2 is a sequence diagram that illustrates an issue where a feeder link and service link are not available simultaneously;
[0013] Fig. 3 is a block diagram that illustrates a schematic of a UDM apparatus implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein;
[0014] Fig. 4 is a block diagram that illustrates a schematic of a UE implemented to carry out the disclosed subject matter according to an embodiment herein;
[0015] Fig. 5 is a block diagram that illustrates a schematic of an AUSF implemented to carry out the disclosed subject matter according to an embodiment herein;
[0016] Fig. 6 is a sequence diagram that illustrates an initial authentication procedure when the UE connects for the first time for accessing NR satellite communication according to an embodiment as disclosed herein;
[0017] Fig. 7 is a sequence diagram that illustrates a procedure for optimizing the NAS SMC for NR satellite access in case of S&F according to an embodiment as disclosed herein;
[0018] Fig. 8 is a sequence diagram that illustrates a scenario of provisioning using the UPU procedure with no storage of HE AVs at the AUSF according to an embodiment as disclosed herein;
[0019] Fig. 9 is a sequence diagram that illustrates a scenario of provisioning using the UPU procedure with storage of HE AVs at the AUSF according to an embodiment as disclosed herein;
[0020] Fig. 10 is a sequence diagram that illustrates a scenario of provisioning using NAS mechanism with storage of HE AVs at the AUSF according to an embodiment as disclosed herein;
[0021] Fig. 11 is a sequence diagram that illustrates optimized authentication and NAS procedure when the UE does not have NAS security context according to an embodiment as disclosed herein;
[0022] Fig. 12 is a sequence diagram that illustrates optimized authentication and NAS procedure when the UE has a NAS security context according to an embodiment as disclosed herein;
[0023] Fig. 13 is a sequence diagram that illustrates optimized authentication and NAS procedure when the UE is connected over a LTE / EPS network according to an embodiment as disclosed herein;
[0024] Fig. 14 is a flow diagram that illustrates a method for performing a UPU procedure when a NAS SMC exists in an S&F mode of a UE according to an embodiment as disclosed herein;
[0025] Fig. 15 is a flow diagram that illustrates a method for performing an optimized NAS procedure when a NAS SMC is not available in an S&F mode of the UE according to an embodiment as disclosed herein;
[0026] Fig. 16 is a flow diagram that illustrates a method for optimized authentication of a UE requesting for satellite communication in an S&F mode according to an embodiment as disclosed herein;
[0027] Fig. 17 is a diagram illustrating a UE 1700 according to an embodiment of the present disclosure;
[0028] Fig. 18 is a diagram illustrating a base station 1800 according to an embodiment of the present disclosure; and
[0029] Fig. 19 schematically illustrates a core network entity according to embodiments of the present disclosure.
[0030] It may be noted that to the extent possible, like reference numerals have been used to represent like elements in the drawing. Further, those of ordinary skill in the art will appreciate that elements in the drawing are illustrated for simplicity and may not have been necessarily drawn to scale. For example, the dimension of some of the elements in the drawing may be exaggerated relative to other elements to help to improve the understanding of aspects of the invention. Furthermore, the elements may have been represented in the drawing by conventional symbols, and the drawings may show only those specific details that are pertinent to the understanding the embodiments of the invention so as not to obscure the drawing with details that will be readily apparent to those of ordinary skill in the art having benefit of the description herein.
[0031] Throughout the present disclosure, the expression "at least one of a, b or c" indicates only a, only b, only c, both a and b, both a and c, both b and c, all of a, b, and c, or variations thereof. Throughout the specification, a layer (or a layer apparatus) may also be referred to as an entity. Hereinafter, operation principles of the disclosure will be described in detail with reference to accompanying drawings. In the following descriptions, well-known functions or configurations are not described in detail because they would obscure the disclosure with unnecessary details. The terms used in the specification are defined in consideration of functions used in the disclosure, and can be changed according to the intent or commonly used methods of users or operators. Accordingly, definitions of the terms are understood based on the entire descriptions of the present specification.
[0032] For the same reasons, in the drawings, some elements may be exaggerated, omitted, or roughly illustrated. Also, a size of each element does not exactly correspond to an actual size of each element. In each drawing, elements that are the same or are in correspondence are rendered the same reference numeral.
[0033] Advantages and features of the present disclosure and methods of accomplishing the same may be understood more readily by reference to the following detailed descriptions of embodiments and accompanying drawings of the disclosure. The disclosure may, however, be embodied in many different forms and should not be construed as being limited to the embodiments set forth herein; rather, these embodiments of the disclosure are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the disclosure to one of ordinary skill in the art. Therefore, the scope of the present disclosure is defined by the appended claims. Throughout the specification, like reference numerals refer to like elements. It will be understood that blocks in flowcharts or combinations of the flowcharts may be performed by computer program instructions. Because these computer program instructions may be loaded into a processor of a general-purpose computer, a special-purpose computer, or another programmable data processing apparatus, the instructions, which are performed by a processor of a computer or another programmable data processing apparatus, create units for performing functions described in the flowchart block(s).
[0034] The computer program instructions may be stored in a computer-usable or computer-readable memory capable of directing a computer or another programmable data processing apparatus to implement a function in a particular manner, and thus the instructions stored in the computer-usable or computer-readable memory may also be capable of producing manufactured items containing instruction units for performing the functions described in the flowchart block(s). The computer program instructions may also be loaded into a computer or another programmable data processing apparatus, and thus, instructions for operating the computer or the other programmable data processing apparatus by generating a computer-executed process when a series of operations are performed in the computer or the other programmable data processing apparatus may provide operations for performing the functions described in the flowchart block(s).
[0035] In addition, each block may represent a portion of a module, segment, or code that includes one or more executable instructions for executing specified logical function(s). It is also noted that, in some alternative implementations, functions mentioned in blocks may occur out of order. For example, two consecutive blocks may also be executed simultaneously or in reverse order depending on functions corresponding thereto.
[0036] As used herein, the term "unit" denotes a software element or a hardware element such as a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC), and performs a certain function. However, the term "unit" is not limited to software or hardware. The "unit" may be formed so as to be in an addressable storage medium, or may be formed so as to operate one or more processors. Thus, for example, the term "unit" may include elements (e.g., software elements, object-oriented software elements, class elements, and task elements), processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, micro-codes, circuits, data, a database, data structures, tables, arrays, or variables.
[0037] Functions provided by the elements and "units" may be combined into the smaller number of elements and "units," or may be divided into additional elements and "units." Furthermore, the elements and "units" may be embodied to reproduce one or more central processing units (CPUs) in a device or security multimedia card. Also, in an embodiment of the present disclosure, the "unit" may include at least one processor. In the following descriptions of the disclosure, well-known functions or configurations are not described in detail because they would obscure the disclosure with unnecessary details.
[0038] Hereinafter, for convenience of explanation, the present disclosure uses terms and names defined in the 3rd generation partnership project long term evolution (3GPP LTE) standards. However, the disclosure is not limited to the terms and names, and may also be applied to systems following other standards.
[0039] In the present disclosure, an evolved node B (eNB) may be interchangeably used with a next-generation node B (gNB) for convenience of explanation. That is, a base station (BS) described by an eNB may represent a gNB. In the following descriptions, the term "base station" refers to an entity for allocating resources to a user equipment (UE) and may be used interchangeably with at least one of a gNode B, an eNode B, a node B, a base station (BS), a radio access unit, a base station controller (BSC), or a node over a network. The term "terminal" may be used interchangeably with a UE, a mobile station (MS), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing communication functions. However, the disclosure is not limited to the aforementioned examples. In particular, the disclosure is applicable to 3GPP new radio (NR) (or 5th generation (5G)) mobile communication standards. In the following description, the term eNB may be interchangeably used with the term gNB for convenience of explanation. That is, a base station explained as an eNB may also indicate a gNB. The term UE may also indicate a mobile phone, NB-IoT devices, sensors, and other wireless communication devices.
[0040] The present disclosure is related to satellite communication. More particularly, the present disclosure is related to a method and system for UE authentication and optimization of a Non-Access-Stratum (NAS) Security Mode Command (SMC) in a Store and Forward (S&F) mode of a user equipment (UE).
[0041] A User Equipment (UE), such as an IoT device, connects to a satellite through a 'Service link.' The satellite, in turn, connects to a Non-Terrestrial Network (NTN) Gateway via a 'Feeder link.' This NTN Gateway is then linked to a Core Network and / or Home Network. When examining the Radio Access Network (RAN) architecture, the protocols that the satellite must support allow for the classification of the 'Transparent Satellite payload' and the 'Regenerative Satellite payload,' as considered in SA1 TR 22.865.
[0042] In the scenario involving the 'Transparent Satellite payload,' the Satellite does not conclude the NR-Uu connection; instead, the satellite mirrors the NR-Uu radio interface between the Feeder link and the Service link, and vice versa. Conversely, in the 'Regenerative Satellite payload' scenario, the Satellite accommodates all Radio Network layer protocols, thereby enabling the satellite to "regenerate the signals received from Earth." Given that the Satellite processes payloads, the satellite is capable of storing and forwarding information, as well as establishing communication with neighboring Satellites through the Inter Satellite Link (ISL).
[0043] SA1 is presently examining the Satellite Access Phase 3 as outlined in TR 22.865. The Store and Forward Satellite operation within a 5G framework that incorporates satellite access aims to deliver a certain degree of communication service for User Equipments (UEs) located within satellite coverage, particularly during periods of intermittent or temporary satellite connectivity. This includes scenarios where the satellite is not linked to the ground network through a feeder link or Inter-Satellite Link (ISL), facilitating delay-tolerant communication services as described in TR 22.865.
[0044] In the scenario involving Store and Forward - Mobile Originated (MO), the IoT remote monitoring user equipment (UE) is required to transmit a message to the TrackingInc application server. The UE remains in a standby mode until satellite network coverage is available, at which point the UE sends the message as the satellite comes into range. The interaction between the IoT remote monitoring UE and the satellite occurs via a service link, enabling the UE to relay the message to the satellite, which lacks direct connectivity to the ground segment. As a result, the satellite is obligated to locally store the received message, as outlined in TR 22.865. The following are the potential new requirements:
[0045] The 5G system equipped with satellite access will support store and forward functionality. It will also be capable of notifying the UE when the "store and forward" operation is in effect. Furthermore, the 5G system will ensure integrity protection and confidentiality for communications between an authorized UE and the network during the implementation of the store and forward operation.
[0046] There is also a use case for Store and Forward - Mobile Terminated (MT). The TrackingInc application server is required to transmit new parameters to the IoT remote monitoring the UE. The application server, informed by the network, recognizes that the communication with the UE is operating in Store and Forward mode. Consequently, the TrackingInc application server will dispatch new parameters via dedicated messages using standard methods (such as IP routing or tunnels) to the network entry point (for instance, a SCEF, PDN-GW, or SMSC). Additionally, the TrackingInc application server may convey further details regarding delivery priority, acknowledgments, and other relevant information to the network, as described in TR 22.865.
[0047] The network retains the message until the message can be transmitted to a satellite that is anticipated to pass overhead and provide coverage for the destination IoT remote monitoring UE. Once the satellite establishes a connection through the feeder link to the terrestrial network, the message is uploaded to the satellite. All stored mobile terminated (MT) messages are transferred to the satellite via the feeder link. Concurrently, all accumulated mobile originated (MO) messages are sent to the 5G Core (5GC) through the same feeder link, which may impact the performance of the feeder link, satellite, and 5GC. Therefore, a performance optimization strategy is necessary. When the satellite is in proximity to the IoT remote monitoring UE, the satellite initiates paging over the service link to facilitate the UE's connection to the network.
[0048] The message that has been stored is transmitted from the satellite to the IoT remote monitoring user equipment. An acknowledgment may be requested or issued. There may be mechanisms implemented to guarantee the integrity of the transmitted information. In the S&F scenario, potential improvements in architecture and mobility management for S&F satellite operations may have security implications regarding authentication, authorization, handling of NAS / AS security contexts, and the protection of data privacy.
[0049] Hence, is desirable to address the above mentioned problems and disadvantages or at least provide a useful alternative.
[0050] The principal object of the embodiments herein is to provide a system and method for UE authentication and optimization of NAS SMC in an S&F mode of the UE.
[0051] Yet another object of the embodiments herein is to provide methods to pre-fetch Authentication Vectors (AVs) for performing the authentication of the UE requesting for satellite communication in store and forward operation.
[0052] Yet another object of the embodiment herein is to provide methods to optimize the NAS SMC along with the authentication procedure for New Radio (NR) satellite store and forward operation.
[0053] Yet another object of the embodiment herein is to provide methods to optimize the NAS SMC along with the authentication procedure for EPS (Evolved Packet System) satellite S&F operation.
[0054] Yet another object of the embodiment herein is to provide methods to determine and trigger an initial registration request using the pre-fetched AVs by the UE during transition from ideal to connected state.
[0055] Yet another object of the embodiment herein is to provide methods to onboard the gNB and the Access Management Function (AMF) in the satellite for the S&F operation.
[0056] Yet another object of the embodiment herein is to provide methods to provide the list of Authentication Tokens (AUTNs) and Random Numbers (RANDs) as part of UE parameter update procedure (UPU) to the UE.
[0057] Yet another object of the embodiment herein is to provide methods to provide the list of AUTNs and RANDs as part of NAS message.
[0058] Yet another object of the embodiment herein is to provide the one or more ngKSI(s) for the list of RANDs, AUTNs and NAS ciphering and integrity procedures to be used by the UE and the UE stores the ngKSI for further use when required.
[0059] In one aspect, the objectives are achieved by providing a method for performing a UE parameters update (UPU) procedure when a non-access stratum (NAS) security mode command (SMC) exists in a store and forward (S&F) mode of a UE. The method includes receiving a UECM registration message from an access and mobility management function (AMF) to initiate an initial registration procedure between the UDM apparatus and the UE. Further, the method includes generating a plurality of authentication vectors (AVs) based on one or more parameters provided in the UECM registration message. In addition, the method includes transmitting the plurality of AVs generated along with a subscription permanent identifier (SUPI) of the UE to an authentication server function (AUSF).
[0060] In an embodiment, the AMF and a gNB (Node B) are embedded in a satellite for the S&F mode during an S&F operation.
[0061] In an embodiment, the method includes performing the UPU procedure via a control plane upon registration of the UE with the UDM apparatus. In the UPU procedure, the UDM apparatus provides a list of random numbers (RANDs) and a list of authentication tokens (AUTNs) to the UE based on the plurality of AVs generated.
[0062] In an embodiment, the one or more parameters comprise at least one of a location, a registration type, and a tracking area identity (TAI) of the AMF.
[0063] In an embodiment, the initial registration procedure is initiated only when a NAS security context exists between the UE and AMF when a service link is available, and when the UE transitions from an ideal state to a connected state.
[0064] In one aspect, the objectives are achieved by providing a method for performing an optimized NAS procedure when a NAS SMC is not available in an S&F mode of a UE. The method includes receiving a N1 message from a security anchor function (SEAF). The N1 message provides an indication for the UE to perform the NAS procedure. Further, the method includes selecting at least one AUTN from a list of AUTNs that is unused along with at least one RAND from a list of RANDs corresponding to the at least one AUTN selected. The list of AUTNs and the list of RANDs are received from a UDM apparatus and are stored in a memory of the UE. Further, the method includes determining a expected response (RES*) based on the at least one AUTN and the at least one RAND selected. In addition, the method includes determining a message authentication code for integrity (MAC-I) to be derived on a N1 request message to be transmitted to the SEAF based on the at least one AUTN and the at least one RAND selected. The MAC-I provides an integrity protection for the N1 request message transmitted to the SEAF.
[0065] In an embodiment, the NAS procedure comprises at least one of a registration procedure, a PDU session establishment procedure, a PDU session modification procedure, a service request, and an upper link (UL) NAS transport.
[0066] In an embodiment, the N1 request message comprises at least one of a SUPI of the UE, the RES*, the at least one AUTN selected, the at least one RAND selected, and the MAC-I.
[0067] In one aspect, the objectives are achieved by providing a method for optimized authentication of a UE requesting for satellite communication in an S&F mode. The method includes receiving an authentication request message from an SEAF. Further, the method includes determining whether at least one AV of a plurality of AVs is available with the AUSF for the SUPI of the UE upon receiving the authentication request message. In addition, the method includes performing one of: generating a UE authentication get request message to be transmitted to a UDM apparatus when at least one AV of the plurality of AVs is not available with the AUSF for the SUPI of the UE, and generating a UE authentication response message to be transmitted to the SEAF when at least one AV of the plurality of AVs is available with the AUSF for the SUPI of the UE.
[0068] In an embodiment, the UE authentication get request message comprises at least one of the SUPI of the UE, a serving network name, a list of RANDs, and a sequence number (SQN).
[0069] In an embodiment, generating, by the AUSF, the UE authentication get request message to be transmitted to the UDM apparatus when at least one AV of the plurality of AVs is not available with the AUSF for the SUPI of the UE includes receiving a UE authentication get response message from the UDM apparatus. The UE authentication get response message includes the plurality of AVs generated by the UDM apparatus based on at least one of the SUPI of the UE, the serving network name, the list of RANDs, and the sequence number (SQN).
[0070] In an embodiment, generating, by the AUSF, the UE authentication response message to be transmitted to the SEAF when at least one AV of the plurality of AVs is available with the AUSF for the SUPI of the UE includes comparing an expected response (XRES*) with a RES* received from the SEAF in the authentication request message. Further, the method includes generating a second set of AVs based on the plurality of AVs pre-fetched from the UDM apparatus. The second set of AVs are obtained by determining a home expected response (HXRES*) based on the XRES* and an anchor key (KSEAF) associated with the UE. In addition, the method includes transmitting the UE authentication response message to the SEAF. The UE authentication response message includes the second set of AVs along with the KSEAFgenerated.
[0071] In one aspect, the objectives are achieved by providing a UDM apparatus for performing a UPU procedure when a NAS SMC exists in an S&F mode of a UE. The UDM apparatus includes a memory, a processor coupled to the memory, and a UDM controller communicatively coupled to the processor and the memory. The UDM controller receives a UECM registration message from an access and mobility management function (AMF) to initiate an initial registration procedure between the UDM apparatus and the UE. Further, the UDM controller generates a plurality of authentication vectors (AVs) based on one or more parameters provided in the UECM registration message. In addition, the UDM controller transmits the plurality of AVs generated along with a subscription permanent identifier (SUPI) of the UE to an authentication server function (AUSF).
[0072] In an embodiment, the AMF and a gNB (Node B) are embedded in a satellite for the S&F mode during an S&F operation.
[0073] In an embodiment, the UDM controller performs the UPU procedure via a control plane upon registration of the UE with the UDM apparatus. In the UPU procedure, the UDM apparatus provides a list of random numbers (RANDs) and a list of authentication tokens (AUTNs) to the UE based on the plurality of AVs generated.
[0074] In an embodiment, the one or more parameters comprise at least one of a location, a registration type, and a tracking area identity (TAI) of the AMF.
[0075] In an embodiment, the initial registration procedure is initiated only when a NAS security context exists between the UE and AMF when a service link is available, and when the UE transitions from an ideal state to a connected state.
[0076] In one aspect, the objectives are achieved by providing a UE for performing an optimized NAS procedure when a NAS SMC is not available in an S&F mode of the UE. The UE includes a first memory, a first processor coupled to the memory, and a UE controller communicatively coupled to the first memory and the first processor. The UE controller receives a N1 message from a security anchor function (SEAF). The N1 message provides an indication for the UE to perform the NAS procedure. Further, the UE controller selects at least one AUTN from a list of AUTNs that is unused along with at least one RAND from a list of RANDs corresponding to the at least one AUTN selected. The list of AUTNs and the list of RANDs are received from a UDM apparatus and are stored in a memory of the UE. Further, the UE controller determines a expected response (RES*) based on the at least one AUTN and the at least one RAND selected. In addition, the UE controller determines a message authentication code for integrity (MAC-I) to be derived on a N1 request message to the transmitted to the SEAF based on the at least one AUTN and the at least one RAND selected. The MAC-I provides an integrity protection for the N1 request message transmitted to the SEAF.
[0077] In an embodiment, the NAS procedure comprises at least one of a registration procedure, a PDU session establishment procedure, a PDU session modification procedure, a service request, and an upper link (UL) NAS transport.
[0078] In an embodiment, the N1 request message comprises at least one of a SUPI of the UE, the RES*, the at least one AUTN selected, the at least one RAND selected, and the MAC-I.
[0079] In one aspect, the objectives are achieved by providing an AUSF for optimized authentication of a UE requesting for satellite communication in an S&F mode. The AUSF includes a second memory, a second processor coupled to the second memory, and an AUSF controller communicatively coupled to the second memory and the second processor. The AUSF controller receives an authentication request message from a SEAF. Further, the AUSF controller determines whether at least one AV of a plurality of AVs is available with the AUSF for the SUPI of the UE upon receiving the authentication request message. In addition, the AUSF controller performs one of: generates a UE authentication get request message to be transmitted to a UDM apparatus when at least one AV of the plurality of AVs is not available with the AUSF for the SUPI of the UE, and generates a UE authentication response message to be transmitted to the SEAF when at least one AV of the plurality of AVs is available with the AUSF for the SUPI of the UE.
[0080] In an embodiment, the UE authentication get request message comprises at least one of the SUPI of the UE, a serving network name, a list of RANDs, and a sequence number (SQN).
[0081] In an embodiment, the AUSF controller receives a UE authentication get response message from the UDM apparatus. The UE authentication get response message includes the plurality of AVs generated by the UDM apparatus based on at least one of the SUPI of the UE, the serving network name, the list of RANDs, and the sequence number (SQN).
[0082] In an embodiment, the AUSF controller compares an expected response (XRES*) with a RES* received from the SEAF in the authentication request message. Further, the AUSF controller generates a second set of AVs based on the plurality of AVs pre-fetched from the UDM apparatus. The second set of AVs are obtained by determining a home expected response (HXRES*) based on the XRES* and an anchor key (KSEAF) associated with the UE. In addition, the AUSF controller transmits the UE authentication response message to the SEAF. The UE authentication response message includes the second set of AVs along with the KSEAFgenerated.
[0083] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating preferred embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications be made within the scope of the embodiments herein.
[0084] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. Also, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments can be combined with a plurality of other embodiments to form new embodiments. The term "or" as used herein, refers to a non-exclusive or, unless otherwise indicated. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein can be practiced and to further enable those skilled in the art to practice the embodiments herein. Accordingly, the examples are not be construed as limiting the scope of the embodiments herein.
[0085] As is traditional in the field, embodiments are described and illustrated in terms of blocks that carry out a described function or functions. These blocks, which referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, and the like, and optionally be driven by firmware and software. The circuits, for example, be embodied in a plurality of semiconductor chips, or on substrate supports such as printed circuit boards, and the like. The circuits constituting a block be implemented by dedicated hardware, or by a processor (e.g., a plurality of programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments be physically separated into two or more interacting and discrete blocks without departing from the scope of the proposed method. Likewise, the blocks of the embodiments be physically combined into more complex blocks without departing from the scope of the proposed method.
[0086] The accompanying drawings are used to help easily understand various technical features and it is understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the proposed method is construed to extend to any alterations, equivalents and substitutes in addition to those which are particularly set out in the accompanying drawings. Although the terms first, second, etc. used herein to describe various elements, these elements are not be limited by these terms. These terms are generally used to distinguish one element from another.
[0087] The various actions, acts, blocks, steps, or the like in the method is performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some of the actions, acts, blocks, steps, or the like are omitted, added, modified, skipped, or the like without departing from the scope of the proposed method.
[0088] Fig. 1 is a sequence diagram that illustrates 5G authentication followed by a NAS SMC procedure. As shown, the sequence diagram includes a UE (102), a SEAF (104), an AUSF (106), and a UDM (108) in communication with each other. The UDM (108) may also be referred to as the UDM apparatus (108), where both terms have been used interchangeably.
[0089] Fig. 2 is a sequence diagram that illustrates an issue where a feeder link and service link are not available simultaneously. As shown, the sequence diagram includes the UE (102), a satellite (202), a non-terrestrial network (NTN) (204), the AUSF (106), and the UDM (108) in communication with each other. The satellite (202) includes a gNB (Node B) and an access and management mobility function (AMF).
[0090] In an embodiment, when the satellite (202) establishes a connection to the ground network through a feeder link, the satellite (202) receives messages, such as NAS messages, which are uploaded to the satellite (202). Additionally, all stored MT messages are transmitted to the satellite (202) via the feeder link. Concurrently, all stored MO messages are sent to the 5GC through the same feeder link, which may affect the performance of the feeder link, the satellite (202), and the 5GC. Therefore, a method for performance optimization is required. As the satellite (202) passes over the location of the IoT remote monitoring UE, the satellite (202) utilizes the stored messages to initiate paging over the service link, prompting the UE (102) to connect to the network. The stored message is delivered / downloaded from the satellite (202) to the IoT remote monitoring UE. Acknowledgment may be requested / issued. Mechanisms to ensure integrity of the delivered information may be in place.
[0091] In the S&F scenario, potential enhancements to architecture and mobility management for S&F satellite operations may introduce security implications related to authentication, authorization, NAS / AS security context management, and data privacy safeguards. Given the growing challenges in satellite communications, a new store and forward architecture enhancement is suggested for IoT remote UE to reduce the overall time required for transmitting uplink and downlink messages within both 5G and EPS frameworks. In the store and forward model, the network retains the message until the message can be delivered or relayed to a satellite that is anticipated to pass overhead and provide coverage for the target IoT remote monitoring UE in both 5G and EPS architectures.
[0092] Data transfer to the IoT remote monitoring User Equipment (UE) may be subject to certain restrictions. These restrictions could include: the estimated time required to deliver downlink messages to the UE in the absence of an active service link, and the estimated time needed to send uplink messages to the home network when the Feeder link is unavailable, which may also involve a lengthy acknowledgment process for the received data by the network. In scenarios where both the service link and Feeder links are simultaneously unavailable, strategies to be employed to retrieve authentication vectors (AVs) from the home Public Land Mobile Network (PLMN) without incurring significant delays is essential. Additionally, approaches should be taken to manage the Non-Access Stratum (NAS) and Access Stratum (AS) security contexts for satellite communications. Also, optimization of the S&F procedure within the Service Management and Control (SMC) framework is also essential.
[0093] It is essential to develop a mechanism for pre-fetching the authentication vectors in advance, depending on the availability of the feeder link and service link. This approach aims to reduce the time required for transmitting uplink and downlink messages in store-and-forward scenarios for both 5G and EPS architectures. Additionally, a streamlined mechanism for authentication and authorization of the user equipment (UE) is necessary, along with the optimization of the NAS SMC procedure for satellite communication in store-and-forward situations, ensuring minimal wait times for both 5G and EPS architectures.
[0094] Fig. 3 is a block diagram that illustrates a schematic of a UDM apparatus (108) implemented to carry out the disclosed subject matter according to an embodiment as disclosed herein. The UDM apparatus (108) is responsible for storing and managing user subscription information, including profiles, authentication credentials, and service-related data. For instance, the UDM apparatus (108) may work with a unified data repository (UDR) to store and retrieve subscriber data. As shown, the UDM apparatus (108) includes a processor (302), a memory (304), an I / O interface (306), and a UDM controller (308) communicatively coupled to the processor (302) and the memory (304). Each component is explained in further detail below.
[0095] The processor (302) communicates with the memory (304), the I / O interface (306) and the UDM controller (308). The processor (302) is configured to execute instructions stored in the memory (304) and to perform various processes. The processor (302) may include one or a plurality of processors, may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0096] The memory (304) includes storage locations to be addressable through the processor (302). The memory (304) is not limited to a volatile memory and / or a non-volatile memory. Further, the memory (304) may include a plurality of computer-readable storage media. The memory (304) may include non-volatile storage elements. For example, non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories.
[0097] The I / O interface (306) transmits the information between the memory (304) and external peripheral devices. The peripheral devices are the input-output devices associated with the UDM apparatus (108). Further, the UDM controller (308) communicates with the I / O interface (306) and the memory (304). The UDM controller (308) may be communicatively coupled to the memory (304) and the processor (302). The UDM controller (308) is an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0098] In an embodiment, the UDM controller (308) receives a user equipment context management (UECM) registration message from the AMF to initiate an initial registration procedure between the UDM apparatus (108) and the UE (102). The UECM registration message facilitates communication between the UE (102) and the AMF. This ensures that the AMF has up-to-date information about the state of the UE (102), the capability of the UE (102), and subscription details. The initial registration procedure refers to a process in which the UE (102) establishes a connection with the 5GC network for a first time or after losing connection. The initial registration procedure is crucial for enabling communication, verifying the user, and providing access to network services.
[0099] For instance, the initial registration procedure is initiated only when a NAS security context exists between the UE (102) and AMF when a service link is available. The NAS security context refers to a set of cryptographic parameters and keys established between the UE (102) and the AMF to ensure secure communication over a NAS signaling plane. This context is essential for protecting messages exchanged between the UE (102) and the 5GC network.
[0100] In an embodiment, the UDM controller (308) generates a plurality of authentication vectors (AVs) based on one or more parameters provided in the UECM registration message. The AVs or 5G AV include cryptographic information to ensure secure communication and validate the legitimacy of the UE (102) and the 5 GC. For instance, the one or more parameters include a location, a registration type, a tracking area identity (TAI) of the AMF, and the like. The location refers to specific geographical or network-related data that identifies where the UE (102) is located within the 5GC network. This ensures proper routing of services and efficient mobility management. The registration type refers to a type of registration being performing by the UE. For instance, the registration type may include initial registration, mobility registration update, periodic registration update, emergency registration, de-registration, and the like. Further, the TAI refers to a unique identifier for a logical grouping of cells managed by the AMF. The TAI helps the AMF identify where the UE (102) is located without requiring detailed position information. By including these parameters, the UECM registration message ensures accurate location tracking, secure registration management, and efficient service delivery for the UE (102).
[0101] In an embodiment, the UDM controller (308) transmits the plurality of AVs generated along with a subscription permanent identifier (SUPI) of the UE (102) to the AUSF (106). The SUPI of the UE (102) refers to a unique identifier of the UE (102) that is primarily used for subscriber identification, authentication, and service authorization. The SUPI is based on an international mobile subscriber identity (IMSI) format defined by 3GPP standards that includes enhancements to support 5G functionalities.
[0102] In an embodiment, the UDM controller (308) performs the UPU procedure via a control plane upon registration of the UE (102) with the UDM apparatus (108). The UPU procedure is a signaling mechanism used to update specific parameters of the UE (102) stored in the network. These updates ensure that the network's knowledge about the context, capabilities, or subscription information associated with the UE (102) is updated. This is essential for efficient mobility management, session handling, and service delivery. In the UPU procedure, the UDM controller (308) provides a list of random numbers (RANDs) and a list of authentication tokens (AUTNs) to the UE (102) based on the plurality of AVs generated. The RANDs refer to randomly generated number included in the authentication vector. Its primary purpose is to introduce uniqueness and freshness into each authentication procedure.
[0103] The AUTNs refer to tokens generated by the network to allow the UE (102) to verify the authenticity of the network. This ensures that the UE (102) is communicating with a legitimate and trusted network. For instance, the AUTNs include a sequence number (SQN), an authentication management field (AMF), and a message authentication code (MAC). The SQN tracks the sequence of authentication requests to prevent replay attacks. The AMF includes control information for the authentication process. Further, the MAC ensures integrity and authenticity by protecting the AUTNs.
[0104] Fig. 4 is a block diagram that illustrates a schematic of the UE (102) implemented to carry out the disclosed subject matter according to an embodiment herein. For instance, the UE (102) may include, but not limited to a smartphone, a tablet, a laptop, a personal computer (PC), a PDA, and the like. As shown, the UE (102) includes a first processor (302A), a first memory (304A), a first I / O interface (306A), and a UE controller (402) communicatively coupled to the first processor (302A) and the first memory (304A). The UE controller (402) communicates with the first I / O interface (306A) and the first memory (304A). The UE controller (402) may be communicatively coupled to the first memory (304A) and the first processor (302A). The UE controller (402) is an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0105] In an embodiment, the UE controller (402) receives a N1 message from the SEAF (104). The N1 message provides an indication for the UE (102) to perform the NAS procedure. The NAS procedure is a vital part of the signaling process in 5G networks, responsible for managing various functions such as session management, mobility management, and authentication. Upon receiving the N1 message, the UE controller (402) processes the information contained within it, which may include parameters and instructions necessary for the UE (102) to perform the required actions.
[0106] For instance, the NAS procedure includes a registration procedure, a PDU session establishment procedure, a PDU session modification procedure, a service request, an upper link (UL) NAS transport, and the like. The registration procedure refers to a process in which the UE (102) establishes a connection with the network for the first time or updates its state with the network after certain events, such as mobility or network access reestablishment. The PDU session establishment procedure is used to set up a data connection for transferring user data between the UE (102) and the network. The PDU session modification procedure allows either the UE (102) or the network to modify an existing PDU session. The service request is used to resume a previously established connection for signaling or data transfer when the UE (102) is in an idle or inactive state. Further, the UL NAS transport allows the UE (102) to sendNASmessages to the AMF over the control plane.
[0107] In an embodiment, the UE controller (402) selects at least one AUTN from a list of AUTNs that is unused along with at least one RAND from a list of RANDs corresponding to the at least one AUTN selected. The list of AUTNs and the list of RANDs are received from the UDM apparatus (108) and are stored in the first memory (304A) of the UE (102).
[0108] In an embodiment, the UE controller (402) determines an expected response (RES*) based on the at least one AUTN and the at least one RAND selected. The RES* refers to is a derived value that represents the expected response from the UE (102) during the authentication process. The RES* is determined based on the RAND selected, a K (shared secret key), and cryptographic function defined by 3GPP standards.
[0109] In an embodiment, the UE controller (402) determines a message authentication code for integrity (MAC-I) to be derived on a N1 request message to the transmitted to the SEAF (104) based on the at least one AUTN and the at least one RAND selected. The MAC-I is a cryptographic value that provides an integrity protection for the N1 request message transmitted to the SEAF (104). The integrity protection is a security mechanism designed to ensure the authenticity and integrity of signaling and data exchanged between theUE (102)and the network. It helps protect communication from unauthorized modification and ensures the message originates from a trusted source. The MAC-I is calculated using akeyderived from the shared security context established during the5G-AKAauthentication procedure. The N1 request message conveys specific requests or information from the UE (102) to the AMF. These requests may be related to mobility management, registration, or session management. For instance, the N1 request message includes a SUPI of the UE (102), the RES* determined, the at least one AUTN selected, the at least one RAND selected, the MAC-I determined, and the like.
[0110] Fig. 5 is a block diagram that illustrates a schematic of an AUSF (106) implemented to carry out the disclosed subject matter according to an embodiment herein. The AUSF (106) is responsible for managing and executing the authentication procedures for the UE (102). The AUSF (106) ensures that only authenticated and authorized devices can access the network, enabling mutual authentication between the UE (102) and the network while facilitating secure key distribution for ongoing communications. As shown, the AUSF (106) includes a second processor (502A), a second memory (504A), a second I / O interface (506A), and an AUSF controller (508) communicatively coupled to the second processor (502A) and the second memory (504A).
[0111] The AUSF controller (508) communicates with the second I / O interface (506A) and the second memory (504A). The AUSF controller (508) may be communicatively coupled to the second memory (504A) and the second processor (502A). The AUSF controller (508) is an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0112] In an embodiment, the AUSF controller (508) receives an authentication request message from the SEAF (104). The authentication request message is sent to theUE (102)to initiate the mutual authentication process between the UE (102) and the SEAF (104). For instance, the authentication request message may include RANDs, AUTNs, the authentication method being used, and authentication information required for specific use cases.
[0113] In an embodiment, the AUSF controller (508) determines whether at least one AV is available with the AUSF (106) for the SUPI of the UE (102) upon receiving the authentication request message. The AUSF controller (508) generates a UE authentication get request message to be transmitted to the UDM apparatus (108) when at least one AV is not available with the AUSF (106) for the SUPI of the UE (102). For instance, the UE authentication get request message includes the SUPI of the UE (102), a serving network name, a list of RANDs, the SQN, and the like. The UE authentication get request message allows the AUSF (106) to retrieve the necessary AVs from the UDM apparatus (108). It thus ensures secure and efficient mutual authentication of the UE (102).
[0114] In an embodiment, the AUSF controller (508) receives a UE authentication get response message from the UDM apparatus (108) upon successful transmission of the UE authentication get request message. The UE authentication get response message includes the plurality of AVs generated by the UDM apparatus (108) based the SUPI of the UE (102), the serving network name, the list of RANDs, the SQN, and the like. The UE authentication get response message enables the UDM apparatus (108) to authenticate the UE (102) and establish a secure communication channel.
[0115] In an embodiment, the AUSF controller (508) generates a UE authentication response message to be transmitted to the SEAF (104) when at least one AV is available with the AUSF (106) for the SUPI of the UE (102). The UE authentication response message is generated based on the RANDs and AUTNs associated with the AVs.
[0116] In an embodiment, the AUSF controller (508) compares an expected response (XRES*) with a RES* received from the SEAF (104) in the UE authentication request message. If theRES*matches theXRES*, the UE (102) is authenticated successfully, and the network can proceed with establishing secure communication by deriving the necessary encryption and integrity keys. If theRES*does not match theXRES*, authentication fails, and the UE (102) is not granted access to the network.
[0117] In an embodiment, the AUSF controller (508) generates a second set of AVs based on the plurality of AVs pre-fetched from the UDM apparatus (108). The second set of AVs are obtained by determining a home expected response (HXRES*) based on the XRES* and an anchor key (KSEAF) associated with the UE (102). The HXRES* is used to verify that theUE (102)has successfully authenticated itself to thehome network(for example, the UDM apparatus (108)) where the subscription associated with the UE (102) is stored. After the UE (102) sends theRES*, theHXRES*is compared with the response received from the UE (102). If they match, the UE (102) is considered successfully authenticated. Further, the KSEAFis derived from the K (the shared secret key) between theUE(102) and the UDM apparatus (108). The KSEAFis specifically tied to theSEAF(104) and is used for protecting the security context in the serving network. It is generated and used in a way that ensures the confidentiality and integrity of the signaling data.
[0118] In an embodiment, the AUSF controller (508) transmits the UE authentication response message to the SEAF (104). The UE authentication response message includes the second set of AVs along with the KSEAFgenerated.
[0119] Fig. 6 is a sequence diagram that illustrates an initial authentication procedure when the UE (102) connects for the first time for accessing NR satellite communication according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), the satellite (202), the AUSF (106), and the UDM (108) are in communication with each other. Pre-requisite: The UE (102) is preconfigured with multiple AVs for later use and the satellite (202) is in S&F mode and is embedded with the gNB and the AMF 5GC Network Functions. Each step is explained in further detail below.
[0120] At step 1, the UE (102) is in roaming in the visited PLMN and / or requesting for a satellite access. The UE (102) is pre-configured with Authentication Vectors (AVs) for later use (for e.g, let's say 5 AVs). In an embodiment, the AV is of the new type "pre-provisioned" or "Store and Forward". The new type is to identify that the AV is created for Store and Forward. At step 2, the UE (102) sends the Registration Request message (AN message) to the NG RAN node which includes the parameters as described in TS 23.502 clause 4.2.4. In an embodiment, during the registration time itself, for the NR satellite access case, the store and forward indication can be send.
[0121] At step 3, the NG RAN node performs the AMF selection and sends the Registration Request message (AN message) to the SEAF (104) and / or AMF in the serving network and / or in the satellite (202), containing either a SUCI (generated using the SUPI) or a 5G Globally Unique Temporary UE Identifier (5G-GUTI). The NG-RAN node additionally includes the NR Satellite S&F indication, if received from the UE (102) while receiving the registration request. The NG-RAN node also sends the other necessary parameters as defined in TS 23.502.
[0122] At step 4, the satellite (202) is currently in S&F mode and upon receiving the registration request, the SEAF (104) / AMF waits for the Feeder links to be available. At step 5, once the feeder link is available, the SEAF (104) / AMF invokes primary authentication by sending authentication request i.e., Nausf_UEAuthentication_Authenticate request to the AUSF (106) in the home network containing the received SUCI and serving network name (SNN) of the SEAF (104) / AMF. In an embodiment the Nausf_UEAuthentication_Authenticate request additionally includes the satellite ID / SAT ID.
[0123] At step 6, the AUSF (106) verifies the UE ID and SNN in the authentication request to check if the UE ID or the SNN is the same as the expected serving name. If the verification is successful, the AUSF (106) sends an authentication data request i.e., Nudm_UEAuthentication_Get request to the UDM (108), including the received SUCI and SN Id and other possible parameters. At step 7, upon reception of the Nudm_UEAuthentication_Get Request, the UDM (108) invokes subscription identifier de-concealing (SIDF) if a SUCI is received. SIDF de-conceals SUPI. The UDM (108) / authentication credential repository processing function (ARPF) selects the authentication method. The UDM (108) also checks data base of the UDM (108) and provides the generated first AV for calculating the RES.
[0124] At step 8, when the selected Authentication Method is EAP-AKA', the UDM (108) sends this transformed authentication vector AV' (RAND, AUTN, XRES, CK', IK') to the AUSF (106) from which the UDM (108) received the Nudm_UEAuthentication_Get Request together with an indication that the AV' is to be used for EAP-AKA' using a Nudm_UEAuthentication_Get Response message as described in TS 33.501. If the selected Authentication Method is 5G AKA, the UDM (108) then returns the 5G home environment (HE) AV to the AUSF (106) together with an indication that the 5G HE AV is to be used for 5G AKA in a Nudm_UEAuthentication_Get Response. In case SUCI was included in the Nudm_UEAuthentication_Get Request, the UDM (108) will include the SUPI in the Nudm_UEAuthentication_Get Response after deconcealment of SUCI by SIDF as described in TS 33.501.
[0125] At step 9, the AUSF (106) stores the XRES* temporarily together with the received SUCI or SUPI in case of 5G AKA. In case of 5G AKA, the AUSF (106) then generates the 5G AV from the 5G HE AV received from the UDM (108) / ARPF by computing the HXRES* from XRES* (according to Annex A.5 of TS 33.501) and KSEAFfrom KAUSF(according to Annex A.6 of TS 33.501), and replacing the XRES* with the HXRES* and KAUSFwith KSEAFin the 5G HE AV.
[0126] At step 10, the AUSF (106) then removes the KSEAFand return the 5G SE AV (RAND, AUTN, HXRES*) to the SEAF / AMF in a Nausf_UEAuthentication_UEAuthentication Response as detailed in TS 33.501 for 5G-AKA procedure. In case of EAP-AKA', the AUSF (106) sends the EAP-Request / AKA'-Challenge message to the SEAF (104) and / or AMF in a Nausf_UEAuthentication_Authenticate Response message as described in TS 33.501.
[0127] At step 11, when the Service link is available, the AMF / SEAF (104) sends the Authentication request to the UE. At step 12, upon receiving the Authentication request from the SEAF (104) / AMF, the UE (102) generates the RES* using the next sequence of preconfigured RAND and AUTN pairs. At step 13, the UE (102) returns RES* to the AMF and / or the SEAF (104) in a NAS message Authentication Response.
[0128] At step 14, the AMF and / or the SEAF (104) then computes HRES* from RES* according to Annex A.5 of TS 33.501, and the SEAF (104) / AMF compares HRES* and HXRES* in case of 5G AKA. If they coincide, the SEAF (104) considers the authentication successful from the serving network point of view. If not, the SEAF (104) proceeds as described in sub-clause 6.1.3.2.2 of TS 33.501. If the UE (102) is not reached, and the RES* is never received by the SEAF (104), the SEAF (104) considers authentication as failed, and indicate a failure to the AUSF (106).
[0129] At step 15, the AMF and / or the SEAF (104) sends RES*, as received from the UE (102), in a Nausf_UEAuthentication_Authenticate Request message to the AUSF (106). At step 16, upon receiving the Nausf_UEAuthentication_Authenticate Request message from the SEAF (104) / AMF, the AUSF (106) verifies the RES* in case of 5G AKA. In the case of EAP-AKA', the AUSF (106) verifies the message by comparing the XRES and RES, and if the AUSF (106) has successfully verified this message it continues as follows, otherwise it returns an error to the SEAF (104) as described in TS 33.501.
[0130] At step 17, the authentication is performed and subsequently the NAS SMC will be performed as described in TS 33.501 for the UE (102) upon the availability of the service link. In an embodiment, for the case of EAP-AKA', in the N1 message the AMF indicates the UE (102) that for the transition from ideal to connected mode, perform the NAS SMC negotiation in hand. In an embodiment for the 5G-AKA, a new message can be send to the UE (102) after successful primary authentication to indicate that for the transition from ideal to connected state, perform the NAS SMC negotiation.
[0131] Fig. 7 is a sequence diagram that illustrates a procedure for optimizing the NAS SMC for NR satellite access in case of S&F according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), the satellite (202), the AUSF (106), and the UDM (108) are in communication with each other. The UE (102) is in roaming in the visited PLMN and / or requesting for a satellite access. At step 1, the UE (102) is pre-configured with Authentication Vectors (AVs) for later use (for eg, let's say 5 AVs).
[0132] At step 2, it is assumed that the authentication is performed for the UE (102) successfully using the preconfigured first AV. It is also assumed that the satellite is provided with NAS and AS security contexts for the UE (102). If the selected Authentication method is EAP-AKA', then in the N1 message, in addition to the EAP Success message, the SEAF (104) and / or the AMF includes the indication to perform the NAS SMC procedure. If the selected Authentication method is 5G-AKA, then a new notification message is send to the UE (102) by the SEAF (104) and / or the AMF which includes the indication to perform the NAS SMC procedure. In an embodiment, it is assumed that the AMF has the prior knowledge of UE (102) being authenticated and indicated for the NR satellite S&F access. At the network side, the UDM (108) and the AUSF (106) has the knowledge of AVs assigned for the UE (102) for NR satellite S&F access. With the prior knowledge, the AUSF (106) stores HRES for the next Avs in sequence in case if the selected Authentication method is 5G AKA.
[0133] At step 3, the satellite (202) is in S&F mode and it is assumed that currently the service link is available. The UE (102) performs the state transition from ideal to connected mode. At step 4a, when the UE (102) decides to connect the satellite for the second time, the UE derives a new RES* using a new AUTN (2) and RAND (2) which are preconfigured earlier.
[0134] At step 4b, with the prior knowledge of the indication to perform the NAS SMC, the UE (102) performs the NAS security mode command negotiation and performs the security procedure selection (selects a ciphering procedure 2 and integrity procedure 2.
[0135] In an embodiment the KAMF1', KAMF2' and KAMF3' can be derived from the KAMF-SATkey. The KAMF-SATand the KAMFis interchangeably used in this document.
[0136] The key derivation can be performed as follows:
[0137] Derivation of KAMF1' from KAMFduring mobility can use the following input parameters.
[0138] - FC = 0xxx
[0139] - P0 = DIRECTION
[0140] - L0 = length of DIRECTION
[0141] - P1 = COUNT,
[0142] - L1 = length of COUNT
[0143] The input key KEY shall be KAMFand / or KAMF-SAT.
[0144] When KAMF1' is derived in idle mode mobility (i.e., mobility registration update), DIRECTION shall be 0xxx and COUNT shall be the uplink NAS COUNT of the 3GPP access used in the Registration Request as detailed in TS 33.501.
[0145] Similarly the KAMF2' and KAMF3' can be derived.
[0146] At step 5, the UE (102) sends the Authentication response to the AMF and / or the SEAF (104). This message includes the newly calculated RES* to the AMF / SEAF (104) in a NAS message Authentication Response. At step 6, the AMF and / or the SEAF (104) waits for the feeder link to be available. Once it is up, steps 7 to 9 are performed. At step 7, the AMF and / or the SEAF (104) sends RES*, as received from the UE (102), in a Nausf_UEAuthentication_Authenticate Request message to the AUSF (106). At step 8, upon receiving the Nausf_UEAuthentication_Authenticate Request message from the SEAF (104) / AMF, the AUSF (106) verifies the RES*.
[0147] At step 9, the AUSF (106) transmits, to the SEAF (104) / AMF, an Nausf_UEAuthentication_Authenticate Response message including result information related to an authentication. At step 9, the Authentication is performed successfully and the NAS SMC has been completed. In an embodiment, by the end of first registration procedure and / or the authentication procedure, the AMF has the knowledge that the UE (102) and / or the IoT device is operating and / or authenticated for the NR satellite (202) S&F access.
[0148] In an embodiment, from the earlier Authentication, the network identifies that the UE (102) is already authenticated. In an embodiment, the UDM (108) has a prior knowledge that the UE (108) is configured with multiple set of AVs and considers that the Network (AUSF (106) / AMF) sends an indication to the UE (102) to send NAS SMC complete along with the RES while the UE (102) tries to access the network for the second time.
[0149] Fig. 8 is a sequence diagram that illustrates a scenario of provisioning using the UPU procedure with no storage of HE AVs at the AUSF (106) according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), the SEAF (104), the AUSF (106), and the UDM (108) are in communication with each other. The UE (102) and the 5G CN may perform the Initial Registration procedure and NAS security context exists between the UE (102) and AMF. The identifier of the serving AMF serving the UE (102) in the access through which the UE (102) has registered is registered in the UDM (108).
[0150] At step 1, upon receiving the request from the AMF and / or based on at least one parameter in the Nudm_UECM_Registration (when the AMF registers with the UDM (108) using Nudm_UECM_Registration, location and / or registration type and / or TAI like so) and / or AMF ID (NF ID), the UDM (108) / ARPF generates a set of authentication vectors as defined in TS 33.102.
[0151] At step 2, the UDM (108) performs a protection of AUTNs and RANDs using the KAUSFin the AUSF (106), by requesting the AUSF (106) as like in SoR or UPU procedure. At step 3, the UDM (108) decides to perform the UE Parameters Update (UPU) using the control plane procedure while the UE (102) is registered to the 5G system as detailed in 6.15.2.1 of TS 33.501 and provides the list of RANDs and AUTNs to the UE (108). Upon receiving the list of RANDs and AUTNs, the UE (108) stores the list of RANDs and AUTNs for further use when required.
[0152] In an embodiment, the UE (102) verifies the received AUTNs and calculates the RES and other potential parameters like CK, IK and stores the RES, CK, IK, SQN, RAND.
[0153] Fig. 9 is a sequence diagram that illustrates a scenario of provisioning using the UPU procedure with storage of HE AVs at the AUSF (106) according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), the SEAF (104), the AUSF (106), and the UDM (108) are in communication with each other. The UE (102) and the 5G CN perform the Initial Registration procedure and NAS security context exists between the UE (102) and AMF. The identifier of the serving AMF serving the UE (102) in the access through which the UE (102) has registered is registered in the UDM (108).
[0154] At step 1, upon receiving the request from the AMF and / or based on at least one parameter in the Nudm_UECM_Registration (when the AMF registers with the UDM (108) using Nudm_UECM_Registration, location and / or registration type and / or TAI like so) and / or AMF ID (NF ID), the UDM (108) / ARPF generates a set of authentication vectors as defined in TS 33.102.
[0155] At step 2, upon generating the AVs, the UDM (108) sends the list of AVs and SUPI to the AUSF (106). At step 3, upon receiving the list of 5G HE AVs and SUPI, the AUSF (106) stores list of 5G HE AVs and the corresponding SUPI. At step 4, the AUSF (106) performs the protection of AUTNs and RANDs (as like in SoR or UPU procedure) and send the protected list of AUTNs and RANDs to the UDM (108).
[0156] At step 5, the UDM (108) performs the UE Parameters Update (UPU) using the control plane procedure while the UE (102) is registered to the 5G system as detailed in 6.15.2.1 of TS 33.501 and provides the list of RANDs and AUTNs to the UE (102). Upon receiving the list of RANDs and AUTNs, the UE (102) stores the list of RANDs and AUTNs for further use when required.
[0157] In an embodiment, the UE (102) verifies the received AUTNs and calculates the RES and other potential parameters like CK, IK and stores the RES, CK, IK, SQN, RAND.
[0158] Fig. 10 is a sequence diagram that illustrates a scenario of provisioning using NAS mechanism with storage of HE AVs at the AUSF (106) according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), the SEAF (104), the AUSF (106), and the UDM (108) are in communication with each other. The UE (102) and the 5G CN performs the Initial Registration procedure and NAS security context exists between the UE (102) and AMF. The identifier of the serving AMF serving the UE (102) in the access through which the UE (102) has registered is registered in the UDM (108).
[0159] At step 1, the serving SEAF (104) / AMF sends an AV provisioning request to the AUSF (106). This message includes the SUCI, SUPI and the SN Name. In an embodiment, the SEAF (104) / AMF sends the AV provisioning request to the AUSF (106) as part of Nausf_UEAuthentication_Authenticate Request message. In an embodiment, the SEAF (104) / AMF sends the AV provisioning request to the AUSF (106) as new service procedure defined for the AUSF (106) to get Request from the AMF for the UDM (108) to provision multiple AUTNs and RANDs to the UE (102).
[0160] At step 2, upon receiving the AV provisioning request and / or the Nausf_UEAuthentication_Authenticate Request message, the AUSF (106) sends Nudm_UEAuthentication_Get Request to the UDM (108). The Nudm_UEAuthentication_Get Request sent from the AUSF (106) to the UDM (108) includes the following information:
[0161] - SUCI or SUPI;
[0162] - the serving network name;
[0163] - if received from the SEAF (104), Disaster Roaming service indication;
[0164] - AV provisioning Request (or in other words, to provide one or more than one AVs)
[0165] At step 3, upon reception of the Nudm_UEAuthentication_Get Request, the UDM (108) invokes SIDF if a SUCI is received. SIDF de-conceals SUCI to gain SUPI before the UDM (108) can process the request. Based on SUPI, the UDM (108) / ARPF chooses the authentication method. At step 4, the UDM / ARPF generates a set of (one or more than one) authentication vectors. Generation of 5G HE AV is defined in TS 33.102. At step 5, the UDM (108) subsequently sends this transformed one or more authentication vectors AV' (RAND, AUTN, XRES, CK', IK') to the AUSF (106) using a Nudm_UEAuthentication_Get Response message.
[0166] At step 6, upon receiving the list of 5G HE AVs and SUPI, the AUSF (106) stores list of 5G HE AVs and the corresponding SUPI. At step 7, the AUSF (106) further sends the list of RANDs and AUTNs to the SEAF (104) / AMF using an AV provisioning response. In an embodiment, the list of RANDs and AUTNs are protected by the AUSF (106) using KAUSFas like in SoR and UPU procedure and provided to the UE (102) via the SEAF (104) / AMF.
[0167] At step 8, the SEAF (104) / AMF sends the N1 message to the UE (102) (N1 message can be a DL NAS Transport message) including the list of RANDs and AUTNs and NAS ciphering and integrity procedures to be used further by the UE (102). The message from the SEAF (104) / AMF to the UE (102) is protected by the NAS security context. Upon receiving the list of RANDs and AUTNs, the UE (102) stores the list of RANDs and AUTNs for further use when required. In an embodiment, the UE (102) verifies the received AUTNs and calculates the RES and other potential parameters like CK, IK and stores the RES, CK, IK, SQN, RAND. In an embodiment, the SEAF (104) / AMF sends the one or more ngKSI(s) for the list of RANDs, AUTNs and NAS ciphering and integrity procedures to be used by the UE (102). The UE (102) stores the ngKSI for further use when required.
[0168] Fig. 11 is a sequence diagram that illustrates optimized authentication and NAS procedure when the UE (102) does not have NAS security context according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), the SEAF (104), the AUSF (106), and the UDM (108) are in communication with each other. In a N1 message to the UE (102), the SEAF (104) may include the authentication request indication and / or the ciphering and / or the integrity procedure. Authentication request indication is to indicate the UE (102) to perform authentication when performing next NAS procedure. The NAS procedure can be Registration procedure or PDU session establishment / modification procedure or Service request or UL NAS transport, like so.
[0169] At step 1, when initiating a NAS procedure, the UE (102) selects an unused SQN / AUTN and corresponding RAND from the stored values. At step 2, the UE (102) derives the RES* from the selected AUTN and RAND, if not derived when storing the received AUTN and RAND.
[0170] At step 3, based on the keys derived from the selected AUTN / SQN and RAND and the network indicated integrity procedure (non-current 5G security context), the UE (102) derives the MAC-I on the N1 request message. The UE (102) then sends an N1 message request to the SEAF (104). The N1 message request includes the SUCI or 5G-GUTI, RES*, AUTN and / or RAND and / or SQN, NAS MAC-I and other possible parameters. The NAS MAC-I is used for integrity protection of the N1 message request. In an embodiment, the UE (102) may include the used Integrity procedure and also ciphering procedure to be used for encryption. In an embodiment, the N1 message (as part of NAS procedure) may include ngKSI (generated by the UE (102) or the assigned by network during provisioning of the AUTN and RAND) along with other possible parameters.
[0171] At step 4, upon receiving the N1 message request from the UE (102), the SEAF (104) stores the NAS MAC-I for the later integrity check and / or verification.
[0172] At step 5, the SEAF (104) invokes the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message to the AUSF (106) whenever the SEAF (104) wishes to initiate an authentication. This message includes SUCI or SUPI, SN-name, AUTN and / or RAND and / or SQN, RES*.
[0173] At step 6, upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF (106) sends Nudm_UEAuthentication_Get Request to the UDM (108), if there is no 5G HE AV available with the AUSF (106) for the SUPI. If the AUSF (106) is able to retrieve the 5G HE AV for the received SUPI and AUTN and / or RAND and / or SQN , then the AUSF (106) performs the step 10, skipping steps 6,7, 8 & 9 (interaction with the UDM (108)).
[0174] The Nudm_UEAuthentication_Get Request sent from AUSF to UDM includes the following information:
[0175] - SUCI or SUPI;
[0176] - the serving network name;
[0177] - if received from SEAF, Disaster Roaming service indication;
[0178] - AUTN and / or RAND and / or SQN
[0179] At step 7, upon reception of the Nudm_UEAuthentication_Get Request, the UDM (108) invokes SIDF if a SUCI is received. SIDF de-conceals SUCI to gain SUPI before the UDM (108) can process the request. At step 8, the UDM (108) / ARPF generates the authentication vectors for the received AUTN and / or RAND and / or SQN and the SUPI. At step 9, the UDM (108) subsequently sends the 5G HE AV to the AUSF (106) using a Nudm_UEAuthentication_Get Response message. At step 10, the AUSF (106) compares the XRES* with the RES* received from the SEAF (104) in the Nausf_UEAuthentication_Authenticate Request message.
[0180] At step 11, the AUSF (106) then generates the 5G AV from the 5G HE AV received from the UDM (108) / ARPF by computing the HXRES* from XRES* (according to Annex A.5 of TS 33.501) and KSEAFfrom KAUSF(according to Annex A.6 of TS 33.501), and replacing the XRES* with the HXRES* and KAUSFwith KSEAFin the 5G HE AV.
[0181] At step 12, the AUSF (106) indicates to the SEAF in the Nausf_UEAuthentication_Authenticate Response whether the authentication was successful or not from the home network point of view. If the authentication was successful, the KSEAFis sent to the SEAF (104) in the Nausf_UEAuthentication_Authenticate Response. The AUSF (106) also includes the 5G SE AV (RAND, AUTN, HXRES*) in the response message. In case the AUSF (106) received a SUCI from the SEAF (104) in the authentication request, and if the authentication was successful, then the AUSF (106) also includes the SUPI in the Nausf_UEAuthentication_Authenticate Response message.
[0182] At step 13, the SEAF (104) computes HRES* from RES* according to TS 33.501, and the SEAF (104) compares HRES* and HXRES*. If they coincide, the SEAF (104) considers the authentication successful from the serving network point of view. The SEAF (104) derives further keys to establish the NAS security context. At step 14, the SEAF (104) verifies NAS MAC-I received in Step 3 with the NAS MAC-I calculated at the network side, using the derived NAS security context. At step 15, once the verification is successful, the SEAF (104) starts Integrity protection, uplink deciphering and downlink ciphering.
[0183] At step 16, the SEAF (104) sends the N1 message to the UE (102). This message includes ngKSI (either generated or the received ngKSI from the UE (102)), UE security capabilities, NAS MAC-I and other possible parameters. At step 17, upon receiving the N1 message from the SEAF, the UE verifies the NAS message integrity and if successful, the UE starts the uplink ciphering and the downlink deciphering (i.e., UE makes the non-current 5G security context to current 5G security context).
[0184] Fig. 12 is a sequence diagram that illustrates optimized authentication and NAS procedure when the UE (102) has a NAS security context according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), the SEAF (104), the AUSF (106), and the UDM (108) are in communication with each other. At step 1, upon receiving the Authentication request from the SEAF (104) (in a N1 message), the UE (102) selects an unused SQN / AUTN and corresponding RAND from the stored values. At step 2, the UE (102) derives the RES* from the selected AUTN and RAND, if not derived when storing the received AUTN and RAND.
[0185] At step 3, the UE (102) derives the MAC-I on the N1 request message, based on the keys derived from the selected AUTN / SQN and RAND and the network indicated integrity procedure. The UE (102) then sends an N1 message request (Periodic / Mobility / PDU session establishment / modification request) to the SEAF. The N1 message request includes the SUCI or 5G-GUTI, RES*, AUTN and / or RAND and / or SQN, NAS MAC-I and other possible parameters. The NAS MAC-I is used for integrity protection and / or for verification of whether the keys derived in the UE (102) using the selected AUTN / SQN and RAND are in synchronization with the network. In an embodiment, the N1 messages carries two MAC-Is one using the established NAS security context (current 5G security context) and another using the selected SQN / AUTN and RAND (non-current 5G security context).
[0186] At step 4, upon receiving the N1 message request from the UE (102), the SEAF (104) stores the NAS MAC-I for the later integrity check and / or verification.
[0187] At step 5, the SEAF (104) invokes the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message to the AUSF (106) whenever the SEAF (104) wishes to initiate an authentication. This message includes SUCI or SUPI, SN-name, AUTN and / or RAND and / or SQN, RES*.
[0188] At step 6, upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF (106) retrieves stored 5G HE AV and compares XRES* and RES*. At step 7, the AUSF (106) then generates the 5G AV from the retrieved 5G HE AV. For example, the AUSF (106) may compute HXRES* and generate the 5G AV based on the HXRES*. At step 8, the AUSF (106) indicates to the SEAF (104) in the Nausf_UEAuthentication_Authenticate Response whether the authentication was successful or not from the home network point of view. If the authentication was successful, the KSEAFis sent to the SEAF (104) in the Nausf_UEAuthentication_Authenticate Response. The AUSF (106) also includes the 5G SE AV (RAND, AUTN, HXRES*) in the response message. In case the AUSF (106) received a SUCI from the SEAF (104) in the authentication request, and if the authentication was successful, then the AUSF (106) also includes the SUPI in the Nausf_UEAuthentication_Authenticate Response message.
[0189] At step 9, the SEAF (104) then computes HRES* from RES* according to TS 33.501, and the SEAF (104) compares HRES* and HXRES*. If they coincide, the SEAF (104) considers the authentication successful from the serving network point of view. The SEAF (104) derives further keys to establish the NAS security context (partial native 5G security context). At step 10, the SEAF (104) also verifies NAS MAC received in Step 3 with the NAS MAC calculated at the network side. Once the verification is successful, at step 11, the SEAF (104) starts Integrity protection, uplink deciphering and downlink ciphering using the newly generated keys.
[0190] At steps 12, the SEAF (104) sends an N1 message to the UE (102). This message includes ngKSI, KAMFflag, UE security capabilities, NAS MAC-I (generated using the newly establish NAS security context (newly generated keys)), includes K_AMF_change_flag and other possible parameters.
[0191] At step 13, upon receiving the N1 message from the SEAF (104), the UE (102) verifies the NAS SMC integrity and if successful, it starts the uplink and the downlink deciphering. The UE (102) uses the newly generated keys and establish the NAS security context and start using it (i.e., the UE (102) makes the non-current 5G security context to current 5G security context).
[0192] In an embodiment, the UE (102) derives the ngKSI and provides along with the AUTN and / or RAND and / or SQN and / or RES* to the AMF / SEAF (104). Once the authentication is successful, the SEAF stores it along with the KAMF.
[0193] In an embodiment, the SEAF (104) / AMF derives the ngKSI and provides it to the UE (102). Once the MAC-I verification is successful in the UE (102), then the UE (102) stores it along with the newly derived KAMF.
[0194] In an embodiment, the ngKSI is of the new type "pre-native" or "Store and Forward". The new type is to identify that the security context is created for Store and Forward feature.
[0195] In an embodiment, the SEAF (104) / AMF derives the ngKSI for each AUTN and RAND in the list and provides it to the UE (102) during provisioning of list of AUTN and RAND values. Once the verification of the MAC-I of the NAS message from the AMF (derived using the newly generated NAS security context and / or partial native 5G security context) is successful in the UE (102), then the UE (102) stores it along with the newly derived KAMF.
[0196] In an embodiment, the ngKSI will be used by the UE (102) and AMF to identify the partial native security context that is created if the authentication is successful as detailed in TS 33.501. In case of NAS mobility, if there are multiple satellite embedded and / or on board with AMF in each, the partial / mapped security context should be transferred from source to target AMF.
[0197] In an embodiment, invalidation of the security contexts (partial native 5G security context) should not be there unless all AVs and ngKSIs are completely utilised.
[0198] In an embodiment, the architecture should be enhanced with an AMF in 5G Core network (Ground) and another AMF on the satellite with support of partial functionality in case of store and forward operation.
[0199] Fig. 13 is a sequence diagram that illustrates optimized authentication and NAS procedure when the UE (102) is connected over a LTE / EPS network according to an embodiment as disclosed herein. As shown in the sequence diagram, the UE (102), a MME (1302), and a HSS (1304) are in communication with each other. At step 1, upon receiving the Authentication request from the MME (1304), the UE (102) selects an unused SQN / AUTN and corresponding RAND from the stored values.
[0200] In an embodiment, for the case of EPS, the RAND and the AUTNs should be pre-provisioned for satellite access operating in store and forward mode. The Authentication and NAS SMC procedures are followed as detailed in TS 33.401, except that the AVs are pre-provisioned at the UE (102) and periodically the UE (102) selects an unused SQN and corresponding RAND for the preceding Authentication Request.
[0201] In an embodiment, the procedures are followed as per Fig. 9 except that it is interchangeably uses the AMF / MME (1302) and UDM (108) / HSS (1304). The corresponding messages for 5G / EPS are used interchangeably.
[0202] Fig. 14 is a flow diagram that illustrates a method for performing a UPU procedure when a NAS SMC exists in an S&F mode of the UE (102) according to an embodiment as disclosed herein. The method includes steps (1402-1408). Each step is explained in further detail below.
[0203] At step (1402), the UDM apparatus (108) receives a user equipment context management (UECM) registration message from the AMF to initiate an initial registration procedure between the UDM apparatus (108) and the UE (102). The UECM registration message plays a vital role in facilitating communication between the UE (102) and the AMF. This mechanism ensures that the AMF is equipped with the latest information regarding the status, capabilities, and subscription details of the UE (102). The initial registration procedure describes the process by which the UE (102) connects to the 5G Core (5GC) network for the first time or re-establishes a connection after a disruption. This procedure is essential for enabling communication, authenticating the user, and granting access to network services.
[0204] The registration process begins only when a NAS security context is established between the UE (102) and the AMF, provided that a service link is available. The NAS security context comprises a collection of cryptographic parameters and keys that are created to facilitate secure communication over the NAS signaling plane. This context is crucial for safeguarding the messages transmitted between the UE (102) and the 5GC network.
[0205] At step (1404), the UDM apparatus (108) generates a plurality of authentication vectors (AVs) based on one or more parameters provided in the UECM registration message. The AVs of 5G AVs incorporate cryptographic data to facilitate secure communication and verify the authenticity of the UE (102) and the 5GC. The parameters involved may encompass aspects such as location, registration type, and Tracking Area Identity (TAI) associated with the AMF, and the like. The location parameter provides specific geographical or network-related information that pinpoints the position of the UE (102) within the 5GC network, which is essential for effective service routing and mobility management. The registration type indicates the nature of the registration process undertaken by the UE (102), which may include initial registration, mobility registration updates, periodic registration updates, emergency registrations, and de-registrations. Additionally, the TAI serves as a unique identifier for a logical cluster of cells overseen by the AMF, enabling the AMF to ascertain the location of the UE (102) without needing detailed positional data. By integrating these parameters, the User Equipment Context Management (UECM) registration message guarantees precise location tracking, secure registration processes, and streamlined service delivery for the UE (102).
[0206] At step (1406), the UDM apparatus (108) transmits the plurality of AVs generated along with a subscription permanent identifier (SUPI) of the UE (102) to the AUSF (106). The SUPI of the UE (102) denotes a distinct identifier for the UE (102), which is mainly utilized for subscriber identification, authentication, and service authorization. This SUPI follows the international mobile subscriber identity (IMSI) format established by 3GPP standards, incorporating enhancements to facilitate 5G capabilities.
[0207] At step (1408), the UDM apparatus (108) performs the UPU procedure via a control plane upon registration of the UE (102) with the UDM apparatus (108). The UPU procedure serves as a signaling mechanism designed to refresh specific parameters of the UE (102) that are stored within the network. These updates are crucial for maintaining the network's awareness of the context, capabilities, and subscription details related to the UE (102). This process is vital for effective mobility management, session handling, and service delivery. During the UPU procedure, the UDM apparatus (108) supplies the UE (102) with a set of random numbers (RANDs) and authentication tokens (AUTNs), which are derived from a series of generated AVs. The RANDs are randomly generated numbers included in the authentication vector, serving the primary function of ensuring uniqueness and freshness in each authentication process.
[0208] The AUTNs are tokens produced by the network that enable the UE (102) to confirm the network's authenticity. This process guarantees that the UE (102) is interacting with a valid and reliable network. Specifically, the AUTNs consist of a sequence number (SQN), an authentication management field (AMF), and a message authentication code (MAC). The SQN monitors the order of authentication requests to thwart replay attacks. The AMF contains control data pertinent to the authentication procedure. Additionally, the MAC safeguards the integrity and authenticity of the AUTNs.
[0209] Fig. 15 is a flow diagram that illustrates a method for performing an optimized NAS procedure when a NAS SMC is not available in an S&F mode of the UE (102) according to an embodiment as disclosed herein. The method includes steps (1502-1508). Each step is explained in further detail below.
[0210] At step (1502), the UE (102) receives a N1 message from the SEAF (104). The N1 message serves as a signal for the UE (102) to initiate the NAS procedure. This procedure is crucial within the signaling framework of 5G networks, overseeing essential functions like session management, mobility management, and authentication. Once the UE (102) receives the N1 message, it analyzes the information provided, which may encompass parameters and directives essential for executing the necessary tasks.
[0211] For instance, the NAS procedure includes a registration procedure, a PDU session establishment procedure, a PDU session modification procedure, a service request, an upper link (UL) NAS transport, and the like. The registration procedure involves the UE (102) initiating a connection with the network for the first time or updating its status following specific events, such as changes in mobility or the reestablishment of network access. The PDU session establishment procedure is designed to create a data connection that facilitates the transfer of user data between the UE (102) and the network. Meanwhile, the PDU session modification procedure enables either the UE (102) or the network to alter an existing PDU session. The service request is utilized to reactivate a previously established connection for signaling or data transfer when the UE (102) is in an idle or inactive state. Additionally, the UL NAS transport function allows the UE (102) to transmit NAS messages to the AMF via the control plane.
[0212] At step (1504), the UE (102) selects at least one AUTN from a list of AUTNs that is unused along with at least one RAND from a list of RANDs corresponding to the at least one AUTN selected. The list of AUTNs and the list of RANDs are received from the UDM apparatus (108) and are stored in the first memory (304A) of the UE (102).
[0213] At step (1506), the UE (102) determines an expected response (RES*) based on the at least one AUTN and the at least one RAND selected. The RES* is a calculated value that signifies the anticipated response from the UE (102) during the authentication procedure. This value is established using the selected RAND, a shared secret key (K), and a cryptographic function as outlined by 3GPP standards.
[0214] At step (1508), the UE (102) determines a message authentication code for integrity (MAC-I) to be derived on a N1 request message to the transmitted to the SEAF (104) based on the at least one AUTN and the at least one RAND selected. The MAC-I serves as a cryptographic value that ensures integrity protection for the N1 request message sent to the SEAF (104). This integrity protection acts as a security measure aimed at verifying the authenticity and integrity of the signaling and data exchanged between the UE (102) and the network. It safeguards communication against unauthorized alterations and confirms that the message is sent from a reliable source. The MAC-I is generated using a key that is derived from the shared security context established during the 5G-AKA authentication process. The N1 request message carries specific requests or information from the UE (102) to the AMF, which may pertain to mobility management, registration, or session management. For instance, the N1 request message includes a SUPI of the UE (102), the RES* determined, the at least one AUTN selected, the at least one RAND selected, the MAC-I determined, and the like.
[0215] Fig. 16 is a flow diagram that illustrates a method for optimized authentication of the UE (102) requesting for satellite communication in an S&F mode according to an embodiment as disclosed herein. The method includes steps (1602-1616). Each step is explained in further detail below.
[0216] At step (1602), the AUSF (106) receives an authentication request message from the SEAF (104). The authentication request message is sent to theUE (102)to initiate the mutual authentication process between the UE (102) and the SEAF (104). For instance, the authentication request message may include RANDs, AUTNs, the authentication method being used, and authentication information required for specific use cases.
[0217] At step (1604), the AUSF (106) determines whether at least one AV is available with the AUSF (106) for the SUPI of the UE (102) upon receiving the authentication request message. At step (1606), the AUSF (108) generates a UE authentication get request message to be transmitted to the UDM apparatus (108) when at least one AV is not available with the AUSF (106) for the SUPI of the UE (102). For instance, the UE authentication get request message includes the SUPI of the UE (102), a serving network name, a list of RANDs, the SQN, and the like. The UE authentication get request message enables the AUSF (106) to obtain the required AVs from the UDM system (108). This process guarantees a secure and effective mutual authentication of the UE (102).
[0218] At step (1608), the AUSF (106) receives a UE authentication get response message from the UDM apparatus (108) upon successful transmission of the UE authentication get request message. The UE authentication get response message includes the plurality of AVs generated by the UDM apparatus (108) based the SUPI of the UE (102), the serving network name, the list of RANDs, the SQN, and the like. The UE authentication get response message enables the UDM apparatus (108) to authenticate the UE (102) and establish a secure communication channel.
[0219] At step (1610), the AUSF (106) generates a UE authentication response message to be transmitted to the SEAF (104) when at least one AV is available with the AUSF (106) for the SUPI of the UE (102). The UE authentication response message is generated based on the RANDs and AUTNs associated with the AVs.
[0220] At step (1612), the AUSF (106) compares an expected response (XRES*) with a RES* received from the SEAF (104) in the UE authentication request message. If the RES* corresponds with the XRES*, the UE (102) is successfully authenticated, allowing the network to move forward with the establishment of secure communication by generating the required encryption and integrity keys. Conversely, if the RES* does not align with the XRES*, authentication is unsuccessful, and the UE (102) is denied access to the network.
[0221] At step (1614), the AUSF (106) generates a second set of AVs based on the plurality of AVs pre-fetched from the UDM apparatus (108). The second set of authentication vectors (AVs) is generated by calculating a home expected response (HXRES*) based on the XRES* and an anchor key (KSEAF) linked to the user equipment (UE) (102). The HXRES* serves to confirm that the UE (102) has successfully authenticated with the home network, such as the UDM apparatus (108), where the subscription information associated with the UE (102) is maintained. Once the UE (102) transmits the RES*, the HXRES* is compared to the response received from the UE (102). A match indicates that the UE (102) has been successfully authenticated. Additionally, the KSEAFis derived from the shared secret key (K) between the UE (102) and the UDM apparatus (108). This KSEAFis specifically associated with the SEAF (104) and is utilized to safeguard the security context within the serving network, ensuring the confidentiality and integrity of the signaling data.
[0222] At step (1616), the AUSF (106) transmits the UE authentication response message to the SEAF (104). The UE authentication response message includes the second set of AVs along with the KSEAFgenerated.
[0223] In accordance with an embodiment of the disclosure, a method for performing a UE parameters update (UPU) procedure when a non-access stratum (NAS) security mode command (SMC) exists in a store and forward (S&F) mode of a UE (102) is provided. The method may comprise: receiving, by a unified data management (UDM) apparatus (108), a user equipment context management (UECM) registration message from an access and mobility management function (AMF) to initiate an initial registration procedure between the UDM apparatus (108) and the UE (102); generating, by the UDM apparatus (108), a plurality of authentication vectors (AVs) based on one or more parameters provided in the UECM registration message; and transmitting, by the UDM apparatus (108), the plurality of AVs generated along with a subscription permanent identifier (SUPI) of the UE (102) to an authentication server function (AUSF) (106).
[0224] In an embodiment, the AMF and a gNB (Node B) are embedded in a satellite (202) for the S&F mode during an S&F operation.
[0225] In an embodiment, the method may comprise: performing, by the UDM apparatus (108), the UPU procedure via a control plane upon registration of the UE (102) with the UDM apparatus (108), wherein in the UPU procedure, the UDM apparatus (108) provides a list of random numbers (RANDs) and a list of authentication tokens (AUTNs) to the UE (102) based on the plurality of AVs generated.
[0226] In an embodiment, the one or more parameters comprise at least one of a location, a registration type, and a tracking area identity (TAI) of the AMF.
[0227] In an embodiment, the initial registration procedure is initiated only when a NAS security context exists between the UE (102) and AMF when a service link is available, and when the UE (102) transitions from an ideal state to a connected state.
[0228] In accordance with an embodiment of the disclosure, a method for performing an optimized NAS procedure when a NAS SMC is not available in a S&F mode of a UE (102)is provided. The method may comprise: receiving, by the UE (102), a N1 message from a security anchor function (SEAF) (104), wherein the N1 message provides an indication for the UE (102) to perform the NAS procedure; selecting, by the UE (102), at least one AUTN from a list of AUTNs that is unused along with at least one RAND from a list of RANDs corresponding to the at least one AUTN selected, wherein the list of AUTNs and the list of RANDs are received from a UDM apparatus (108) and are stored in a first memory (304A) of the UE (102); determining, by the UE (102), an expected response star (RES*) based on the at least one AUTN and the at least one RAND selected; determining, by the UE (102), a message authentication code for integrity (MAC-I) to be derived on a N1 request message to the transmitted to the SEAF (104) based on the at least one AUTN and the at least one RAND selected, wherein the MAC-I provides an integrity protection for the N1 request message transmitted to the SEAF (104).
[0229] In accordance with an embodiment of the disclosure, the NAS procedure comprises at least one of a registration procedure, a PDU session establishment procedure, a PDU session modification procedure, a service request, and an upper link (UL) NAS transport.
[0230] In accordance with an embodiment of the disclosure, the N1 request message comprises at least one of a SUPI of the UE (102), the RES*, the at least one AUTN selected, the at least one RAND selected, and the MAC-I.
[0231] In accordance with an embodiment of the disclosure, a method for optimized authentication of a UE (102) requesting for satellite communication in a S&F mode is provided. The method may comprise: receiving, by an AUSF (106), an authentication request message from a SEAF (104); determining, by the AUSF (106), whether at least one AV of a plurality of AVs is available with the AUSF (106) for the SUPI of the UE (102) upon receiving the authentication request message; performing, by the AUSF (106), one of: generating, by the AUSF (106), a UE authentication get request message to be transmitted to a UDM apparatus (108) when at least one AV of the plurality of AVs is not available with the AUSF (106) for the SUPI of the UE (102); and generating, by the AUSF (106), a UE authentication response message to be transmitted to the SEAF (104) when at least one AV of the plurality of AVs is available with the AUSF (106) for the SUPI of the UE (102).
[0232] In an embodiment, the UE authentication get request message comprises at least one of the SUPI of the UE (102), a serving network name, a list of RANDs, and a sequence number (SQN).
[0233] In an embodiment, generating, by the AUSF (106), the UE authentication get request message to be transmitted to the UDM apparatus (108) when at least one AV of the plurality of AVs is not available with the AUSF (106) for the SUPI of the UE (102) comprises: receiving, by the AUSF (106), a UE authentication get response message from the UDM apparatus (108), wherein the UE authentication get response message includes the plurality of AVs generated by the UDM apparatus (108) based on at least one of the SUPI of the UE (102), the serving network name, the list of RANDs, and the sequence number (SQN).
[0234] In an embodiment, generating, by the AUSF (106), the UE authentication response message to be transmitted to the SEAF (104) when at least one AV of the plurality of AVs is available with the AUSF (106) for the SUPI of the UE (102) comprises: comparing, by the AUSF (106), an expected response (XRES*) with a RES* received from the SEAF (104) in the UE authentication request message; generating, by the AUSF (106), a second set of AVs based on the plurality of AVs pre-fetched from the UDM apparatus (108), wherein the second set of AVs are obtained by determining a home expected response (HXRES*) based on the XRES* and an anchor key (KSEAF) associated with the UE (102); and transmitting, by the AUSF (106), the UE authentication response message to the SEAF (104), wherein the UE authentication response message includes the second set of AVs along with the KSEAF generated.
[0235] In accordance with an embodiment of the disclosure, a UDM apparatus (108) for performing a UPU procedure when a NAS SMC exists in an S&F mode of a UE (102) is provided. The UDM apparatus may comprise: a memory (304); a processor (302) coupled to the memory (304); and a UDM controller (308) communicatively coupled to the memory (304) and the processor (302), wherein the UDM controller (308): receives a UECM registration message from an access and mobility management function (AMF) to initiate an initial registration procedure between the UDM apparatus (108) and the UE (102); generates a plurality of authentication vectors (AVs) based on one or more parameters provided in the UECM registration message; and transmits the plurality of AVs generated along with a subscription permanent identifier (SUPI) of the UE (102) to an authentication server function (AUSF) (106).
[0236] In an embodiment, the AMF and a gNB (Node B) are embedded in a satellite (202) for the S&F mode during an S&F operation.
[0237] In an embodiment, the UDM controller (308): performs the UPU procedure via a control plane upon registration of the UE (102) with the UDM apparatus (108), wherein in the UPU procedure, the UDM apparatus (108) provides a list of random numbers (RANDs) and a list of authentication tokens (AUTNs) to the UE (102) based on the plurality of AVs generated.
[0238] In an embodiment, the one or more parameters comprise at least one of a location, a registration type, and a tracking area identity (TAI) of the AMF.
[0239] In an embodiment, the initial registration procedure is initiated only when a NAS security context exists between the UE (102) and AMF when a service link is available, and when the UE (102) transitions from an ideal state to a connected state.
[0240] In accordance with an embodiment of the disclosure, a UE (102) for performing an optimized NAS procedure when a NAS SMC is not available in an S&F mode of the UE (102) is provided. The UE may comprise: a first memory (304A); a first processor (302A) coupled to the first memory (304A); and a UE controller (402) communicatively coupled to the first memory (304A) and the first processor (302A), wherein the UE controller (402): receives a N1 message from a security anchor function (SEAF) (104), wherein the N1 message provides an indication for the UE (102) to perform the NAS procedure; selects at least one AUTN from a list of AUTNs that is unused along with at least one RAND from a list of RANDs corresponding to the at least one AUTN selected, wherein the list of AUTNs and the list of RANDs are received from a UDM apparatus (108) and are stored in a memory of the UE (102); determines a resource element spacing (RES*) based on the at least one AUTN and the at least one RAND selected; and determines a message authentication code for integrity (MAC-I) to be derived on a N1 request message to the transmitted to the SEAF (104) based on the at least one AUTN and the at least one RAND selected, wherein the MAC-I provides an integrity protection for the N1 request message transmitted to the SEAF (104).
[0241] In an embodiment, the NAS procedure comprises at least one of a registration procedure, a PDU session establishment procedure, a PDU session modification procedure, a service request, and an upper link (UL) NAS transport.
[0242] In an embodiment, the N1 request message comprises at least one of a SUPI of the UE (102), the RES*, the at least one AUTN selected, the at least one RAND selected, and the MAC-I.
[0243] In accordance with an embodiment of the disclosure, an AUSF (106) for optimized authentication of a UE (102) requesting for satellite communication in an S&F mode is provided. The AUSF may comprise: a second memory (504A); a second processor (502A) coupled to the second memory (504A); and an AUSF controller (508) communicatively coupled to the second memory (504A) and the second processor (502A), wherein the AUSF controller (508): receives an authentication request message from a SEAF (104); determines whether at least one AV of a plurality of AVs is available with the AUSF (106) for the SUPI of the UE (102) upon receiving the authentication request message; performs one of: generates a UE authentication get request message to be transmitted to a UDM apparatus (108) when at least one AV of the plurality of AVs is not available with the AUSF (106) for the SUPI of the UE (102); and generates a UE authentication response message to be transmitted to the SEAF (104) when at least one AV of the plurality of AVs is available with the AUSF (106) for the SUPI of the UE (102).
[0244] In an embodiment, the UE authentication get request message comprises at least one of the SUPI of the UE (102), a serving network name, a list of RANDs, and a sequence number (SQN).
[0245] In an embodiment, the AUSF controller (508): receives a UE authentication get response message from the UDM apparatus (108), wherein the UE authentication get response message includes the plurality of AVs generated by the UDM apparatus (108) based on at least one of the SUPI of the UE (102), the serving network name, the list of RANDs, and the sequence number (SQN).
[0246] In an embodiment, the AUSF controller (508): compares an expected response (XRES*) with a RES* received from the SEAF (104) in the UE authentication request message; generates a second set of AVs based on the plurality of AVs pre-fetched from the UDM apparatus (108), wherein the second set of AVs are obtained by determining a home expected response (HXRES*) based on the XRES* and an anchor key (KSEAF) associated with the UE (102); and transmits the UE authentication response message to the SEAF (104), wherein the UE authentication response message includes the second set of AVs along with the KSEAF generated.
[0247] Embodiments herein provide a method and a system for UE authentication and optimization of NAS SMC in an S&F mode of the UE (102). The method includes receiving a UECM registration message from an access and mobility management function (AMF) to initiate an initial registration procedure between a UDM apparatus (108) and the UE (102). Further, generating a plurality of authentication vectors (AVs) based on one or more parameters provided in the UECM registration message. In addition, transmitting the plurality of AVs generated along with a subscription permanent identifier (SUPI) of the UE (102) to an authentication server function (AUSF).
[0248] In accordance with an embodiment of the disclosure, a method performed by a user equipment (UE) is provided. The method may comprise: performing an initial registration procedure, the UE being registered to a fifth generation (5G) system; receiving, from a unified data management function (UDM) entity, information associated with a list of random numbers (RANDs) and authentication tokens (AUTNs) while the UE is registered to the 5G system; and storing values associated with the received information for a subsequent authentication.
[0249] In an embodiment, the method may further comprise upon receiving the list of RANDs and AUTNs, verifying the AUTNs and calculating a first authentication response (RES).
[0250] In an embodiment, the method may further comprise receiving, from a security anchor function (SEAF) entity, a N1 message including an authentication request indication indicating the UE to perform an authentication when performing a next non-access-stratum (NAS) procedure.
[0251] In an embodiment, the next NAS procedure may include a registration procedure or a protocol data unit (PDU) session establishment procedure.
[0252] In an embodiment, the method may further comprise in case of initiating a NAS procedure, selecting an unused sequence number (SQN) or AUTN and corresponding RAND from the stored values.
[0253] In an embodiment, the method may further comprise deriving a second RES from the selected AUTN and RAND in case that a first RES is not derived when storing the values.
[0254] In an embodiment, the method may further comprise deriving a message authentication code for integrity (MAC-I) on a N1 request message, based on a network indicated integrity algorithm and keys derived from the selected SQN or AUTN and RAND.
[0255] In an embodiment, the method may further comprise transmitting, to the SEAF entity, the N1 request message including a subscription permanent identifier (SUPI) or a 5G-globally unique temporary UE identifier (GUTI), the second RES, the RAND, the SQN and the MAC-I.
[0256] In an embodiment, the method may further comprise receiving, from the SEAF entity, a N1 response message including a key set identifier in 5G (ngKSI), UE security capabilities and an MAC-I.
[0257] In accordance with an embodiment of the disclosure, a user equipment (UE) in a wireless communication system is provided. The UE may comprise a transceiver and at least one processor coupled with the transceiver and configured to: perform an initial registration procedure, the UE being registered to a fifth generation (5G) system; receive, from a unified data management function (UDM) entity, information associated with a list of random numbers (RANDs) and authentication tokens (AUTNs) while the UE is registered to the 5G system; and store values associated with the received information for a subsequent authentication.
[0258] Fig. 17 is a diagram illustrating a UE 1700 according to an embodiment of the present disclosure.
[0259] Referring to the Fig. 17, the UE 1700 may include a processor 1710, a transceiver 1720 and a memory 1730. However, all of the illustrated components are not essential. The UE 1700 may be implemented by more or less components than those illustrated in the Fig. 17. In addition, the processor 1710 and the transceiver 1720 and the memory 1730 may be implemented as a single chip according to another embodiment.
[0260] The aforementioned components will now be described in detail.
[0261] The processor 1710 may include one or more processors or other processing devices that control the proposed function, process, and / or method. Operation of the UE 1700 may be implemented by the processor 1710.
[0262] The transceiver 1720 may be connected to the processor 1710 and transmit and / or receive a signal. In addition, the transceiver 1720 may receive the signal through a wireless channel and output the signal to the processor 1710. The transceiver 1720 may transmit the signal output from the processor 1710 through the wireless channel.
[0263] The memory 1730 may store the control information or the data included in a signal obtained by the UE 1700. The memory 1730 may be connected to the processor 1710 and store at least one instruction or a protocol or a parameter for the proposed function, process, and / or method. The memory 1730 may include read-only memory (ROM) and / or random access memory (RAM) and / or hard disk and / or CD-ROM and / or DVD and / or other storage devices.
[0264] Fig. 18 is a diagram illustrating a base station 1800 according to an embodiment of the present disclosure.
[0265] Referring to the Fig. 18, the base station 1800 may include a processor 1810, a transceiver 1820 and a memory 1830. However, all of the illustrated components are not essential. The base station 1800 may be implemented by more or less components than those illustrated in Fig. 18. In addition, the processor 1810 and the transceiver 1820 and the memory 1830 may be implemented as a single chip according to another embodiment.
[0266] The aforementioned components will now be described in detail.
[0267] The processor 1810 may include one or more processors or other processing devices that control the proposed function, process, and / or method. Operation of the base station 1800 may be implemented by the processor 1810.
[0268] The transceiver 1820 may be connected to the processor 1810 and transmit and / or receive a signal. The signal may include control information and data. In addition, the transceiver 1820 may receive the signal through a wireless channel and output the signal to the processor 1810. The transceiver 1820 may transmit a signal output from the processor 1810 through the wireless channel.
[0269] The memory 1830 may store the control information or the data included in a signal obtained by the base station 1800. The memory 1830 may be connected to the processor 1810 and store at least one instruction or a protocol or a parameter for the proposed function, process, and / or method. The memory 1830 may include read-only memory (ROM) and / or random access memory (RAM) and / or hard disk and / or CD-ROM and / or DVD and / or other storage devices.
[0270] Fig. 19 schematically illustrates a core network entity according to embodiments of the present disclosure.
[0271] The network entity described above may correspond to the core network entity 1900.
[0272] Referring to the Fig. 19, the core network entity 1900 may include a processor 1910, a transceiver 1920 and a memory 1930. However, all of the illustrated components are not essential. The core network entity 1900 may be implemented by more or less components than those illustrated in Fig. 19. In addition, the processor 1910 and the transceiver 1920 and the memory 1930 may be implemented as a single chip according to another embodiment.
[0273] The aforementioned components will now be described in detail.
[0274] The transceiver 1920 may provide an interface for performing communication with other devices in a network. That is, the transceiver 1920 may convert a bitstream transmitted from the core network entity 1900 to other devices to a physical signal and covert a physical signal received from other devices to a bitstream. That is, the transceiver 1920 may transmit and receive a signal. The transceiver 1920 may be referred to as modem, transmitter, receiver, communication unit and communication module. The transceiver 1920 may enable the core network entity 1900 to communicate with other devices or system through backhaul connection or other connection method.
[0275] The memory 1930 may store a basic program, an application program, configuration information for an operation of the core network entity 1900. The memory 1930 may include volatile memory, non-volatile memory and a combination of the volatile memory and the non-volatile memory. The memory 1930 may provide data according to a request from the processor 1910.
[0276] The processor 1910 may control overall operations of the core network entity 1900. For example, the processor 1910 may transmit and receive a signal through the transceiver 1920. The processor 1910 may include at least one processor. The processor 1910 may control the core network entity 1900 to perform operations according to embodiments of the present disclosure.
[0277] Methods according to the claims of the disclosure or the various embodiments of the disclosure described in the specification may be implemented in hardware, software, or a combination of hardware and software.
[0278] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. One or more programs stored in the computer-readable storage medium are configured for execution by one or more processors in an electronic device. The one or more programs may include instructions that cause the electronic device to perform the methods in accordance with the claims of the disclosure or the various embodiments of the disclosure described in the specification.
[0279] The programs (software modules, software) may be stored in a random access memory (RAM), a non-volatile memory including a flash memory, a read only memory (ROM), an electrically erasable programmable ROM (EEPROM), a magnetic disc storage device, a compact disc-ROM (CD-ROM), a digital versatile disc (DVD) or other types of optical storage device, and / or a magnetic cassette. Alternatively, the programs may be stored in a memory including a combination of some or all of them. There may be a plurality of memories.
[0280] The program may also be stored in an attachable storage device that may be accessed over a communication network including the Internet, an intranet, a Local Area Network (LAN), a wide area network (WAN), or a storage area network (SAN), or a combination thereof. The storage device may be connected to an apparatus performing the various embodiments of the disclosure through an external port. In addition, a separate storage device in the communication network may be connected to the apparatus performing the various embodiments of the disclosure.
[0281] In the various embodiments of the present disclosure, a component is represented in a singular or plural form. It should be understood, however, that the singular or plural representations are selected appropriately according to the situations presented for convenience of explanation, and the disclosure is not limited to the singular or plural form of the component. Further, the component expressed in the plural form may also imply the singular form, and vice versa.
[0282] While the disclosure has been shown and described with reference to various embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the spirit and scope of the disclosure as defined by the appended claims and their equivalents.
[0283] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of the embodiments as described herein.
Claims
1.A method performed by a user equipment (UE) in a wireless communication system, the method comprising:performing an initial registration procedure, the UE being registered to a fifth generation (5G) system;receiving, from a unified data management function (UDM) entity, information associated with a list of random numbers (RANDs) and authentication tokens (AUTNs) while the UE is registered to the 5G system; andstoring values associated with the received information for a subsequent authentication.2.The method of claim 1, further comprising:upon receiving the list of RANDs and AUTNs, verifying the AUTNs and calculating a first authentication response (RES).3.The method of claim 1, further comprising:receiving, from a security anchor function (SEAF) entity, a N1 message including an authentication request indication indicating the UE to perform an authentication when performing a next non-access-stratum (NAS) procedure.4.The method of claim 3, wherein the next NAS procedure includes a registration procedure or a protocol data unit (PDU) session establishment procedure.5.The method of claim 3, further comprising:in case of initiating a NAS procedure, selecting an unused sequence number (SQN) or AUTN and corresponding RAND from the stored values.6.The method of claim 5, further comprising:deriving a second RES from the selected AUTN and RAND in case that a first RES is not derived when storing the values.7.The method of claim 6, further comprising:deriving a message authentication code for integrity (MAC-I) on a N1 request message, based on a network indicated integrity algorithm and keys derived from the selected SQN or AUTN and RAND.8.The method of claim 7, further comprising:transmitting, to the SEAF entity, the N1 request message including a subscription permanent identifier (SUPI) or a 5G-globally unique temporary UE identifier (GUTI), the second RES, the RAND, the SQN and the MAC-I.9.The method of claim 8, further comprising:receiving, from the SEAF entity, a N1 response message including a key set identifier in 5G (ngKSI), UE security capabilities and an MAC-I.10.A user equipment (UE) in a wireless communication system, the UE comprising:a transceiver; andat least one processor coupled with the transceiver and configured to:perform an initial registration procedure, the UE being registered to a fifth generation (5G) system;receive, from a unified data management function (UDM) entity, information associated with a list of random numbers (RANDs) and authentication tokens (AUTNs) while the UE is registered to the 5G system; andstore values associated with the received information for a subsequent authentication.11.The UE of claim 10, wherein the at least one processor is further configured to:upon receiving the list of RANDs and AUTNs, verify the AUTNs and calculate a first authentication response (RES).12.The UE of claim 10, wherein the at least one processor is further configured to:receive, from a security anchor function (SEAF) entity, a N1 message including an authentication request indication indicating the UE to perform an authentication when performing a next non-access-stratum (NAS) procedure.13.The UE of claim 12, wherein the next NAS procedure includes a registration procedure or a protocol data unit (PDU) session establishment procedure.14.The UE of claim 12, wherein the at least one processor is further configured to:in case of initiating a NAS procedure, select an unused sequence number (SQN) or AUTN and corresponding RAND from the stored values.15.The UE of claim 14, wherein the at least one processor is further configured to:derive a second RES from the selected AUTN and RAND in case that a first RES is not derived when storing the values.
Citation Information
Patent Citations
Communication authentication method and related device
EP4030801A1
Methods and devices for establishing secure communication for applications
WO2021093170A1
KR20210103521A
Cited By
Techniques for configuring an access stratum security for a non-terrestrial network
US20250358764A1