Techniques for privacy protection across security domains

By generating a privacy-protected UE identifier (S-UEID) to replace SUPI in authentication processes, the system addresses security threats and privacy breaches in wireless communication systems hosting non-public networks, ensuring robust privacy and security for users.

WO2025154046A1PCT designated stage Publication Date: 2025-07-24LENOVO (SINGAPORE) PTE LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/053043
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2025-03-21
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Existing wireless communication systems face security threats and privacy breaches when hosting non-public networks (NPNs) outside the control of the mobile network operator (MNO), as sensitive identifiers like SUPI are exposed, leading to potential attacks and privacy violations.

Method used

Implementing a mechanism for SUPI exposure restriction by generating a privacy-protected UE identifier (S-UEID) within the UDM, which is used instead of SUPI during authentication processes, ensuring that sensitive information is not disclosed to entities outside the MNO's trust domain.

Benefits of technology

Enhances security and privacy protection by preventing unauthorized access to sensitive user information, thereby reducing the risk of attacks and maintaining user privacy in wireless communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025053043_24072025_PF_FP_ABST
    Figure IB2025053043_24072025_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to techniques for privacy protection across security domains. An apparatus is configured to transmit, to a serving wireless network, an indication that the UE is capable of identifier privacy protection, receive, from the serving wireless network, privacy protection information for the UE, and determine a privacy protection identifier for the UE based on the privacy protection information received from the wireless network. The privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNIQUES FOR PRIVACY PROTECTION ACROSS SECURITY DOMAINSTECHNICAL FIELD

[0001] The present disclosure relates to wireless communications, and more specifically to techniques for privacy protection across security domains.BACKGROUND

[0002] A wireless communications system may include one or multiple network communication devices, such as base stations (BSs), which may support wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY

[0003] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall beconstrued in the same manner as the phrase “based at least in part on.” Further, as used herein, including in the claims, a “set” may include one or more elements.

[0004] In one embodiment, an apparatus may be configured to support a means to transmit, to a serving wireless network, an indication that the UE is capable of identifier privacy protection, receive, from the serving wireless network, privacy protection information for the UE, and determine a privacy protection identifier for the UE based on the privacy protection information received from the wireless network, the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

[0005] In one embodiment, a method may be configured to support a means to receive an indication that a UE is capable of identifier privacy protection for a serving wireless network, receive a subscription permanent identifier (SUPI) for the UE, and derive a privacy protection identifier associated with the SUPI for the UE for use in the serving wireless network, the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

[0006] In one embodiment, a processor may be configured to support a means to receive privacy protection information for a UE, determine a privacy protection identifier for the UE based on the privacy protection information, the privacy protection identifier for the UE is for authentication of the UE by a serving wireless network during communications, and provide the privacy protection identifier to the UE during a primary authentication procedure for use in a serving wireless network.BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.

[0008] Figure 2 illustrates an example of a privacy support capability exchange during the primary authentication initiation procedure, in accordance with aspects of the present disclosure.

[0009] Figure 3 illustrates an example of SUPI disclosure restriction and privacy protected UE ID usage in a hosted non-public network (NPN) or serving networking scenario during primary authentication with extensible authentication protocol-authentication and key management (EAP-AKA1), in accordance with aspects of the present disclosure.

[0010] Figure 4 illustrates an example of SUPI disclosure restriction and privacy protected UE ID usage in a hosted NPN or serving networking scenario during primary authentication with 5G AKA, in accordance with aspects of the present disclosure.

[0011] Figure 5 illustrates an example of NAS security mode command (SMC) for UE ID privacy support capability protection and provisioning UE with privacy protected UE ID, in accordance with aspects of the present disclosure.

[0012] Figure 6 illustrates an example of a UE in accordance with aspects of the present disclosure.

[0013] Figure 7 illustrates an example of a processor in accordance with aspects of the present disclosure.

[0014] Figure 8 illustrates an example of a network equipment (NE) in accordance with aspects of the present disclosure.

[0015] Figure 9 illustrates a flowchart of a method performed by an NE in accordance with aspects of the present disclosure.

[0016] Figure 10 illustrates a flowchart of a method performed by a device in accordance with aspects of the present disclosure.

[0017] Figure 11 illustrates a flowchart of a method performed by an NE in accordance with aspects of the present disclosure.DETAILED DESCRIPTION

[0018] Some wireless communication systems may include NPNs. As used herein, NPNs may refer to a private network that is a network that is intended for the nonpublic (or private) use. When an NPN is hosted by a public land mobile network (PLMN), there is a possible deployment scenario where a dedicated user plane function (UPF) and part of control plan (CP) functions (e.g., an access and mobility management function (AMF), a security anchor function (SEAF), or the like) are deployed in customer premises with a service-based architecture (SBA) interface with operator premises.

[0019] Considering a primary authentication and authorization procedure, e.g., as specified in clause 6.1.3 in TS 33.501 (incorporated herein by reference), if an identifier for the UE, such as a SUPI, is available in clear text to the network functions (NFs) in the customer premises, then it can be misappropriated and potentially lead to security threats, privacy breaches, UE location tracking, targeted attacks, or the like.

[0020] Aspects of the present disclosure are described in the context of a wireless communications system. In particular, the subject matter disclosed herein provides solutions that improve the security, reliability, and robustness of communications that utilize NPNs and other wireless communication systems, and ultimately enhances privacy protection for users that utilize these wireless communication systems.

[0021] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE-Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.

[0022] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link,which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.

[0023] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas 112 associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.

[0024] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Intemet-of-Things (loT) device, an Intemet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.

[0025] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link 114 may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0026] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N2, or network interface). In some implementations, the NE 102 may communicate with each other directly. In someother implementations, the NE 102 may communicate with each other or indirectly (e.g., via the CN 106. In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmit-receive points (TRPs).

[0027] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.

[0028] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).

[0029] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different framestructures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0030] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., ^=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., jU=O) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., ^=1) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., ^=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., jU=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., [1=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.

[0031] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0032] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, ju=l, ju=2, ^=3, ^=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., jU=O) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0033] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0034] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., ^=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., ^=1), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., jU=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., jU=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., jU=3), which includes 120 kHz subcarrier spacing.

[0035] As background, clause 8.2 of TS 22.261 (incorporated herein by reference) explains that the 5G system shall enable a PLMN to host an NPN without compromising the security of that PLMN. Dedicated network entities of an NPN can be deployed in customer premises that are outside the control of the PLMN operator.

[0036] When an NPN is hosted by a PLMN, there are two possible deployment scenarios. For scenario 1, a dedicated UPF is deployed in customer premises, with an N4 interface (non-SBA interface) with the operator premises. For scenario 2, a dedicated UPF and part of CP functions are deployed in customer premises with SBA interface with operator premises.

[0037] Considering primary authentication and authorization procedure, if a SUPI is available in clear text to the NFs in a customer premises, then it may potentially lead to security threats, privacy breaches, UE location tracking, targeted attacks, or the like.

[0038] The privacy sensitive SUPI is the home network operator provided identifier and is used exclusively to identify its subscribers and related subscription information to handle the related services. It is not a security best practise to expose the privacy sensitive SUPI external to the operator’s trust domain. Especially in cases where a PLMN hosts the NPN, exposing SUPI beyond an Operator Trust domain (e.g., PLMN) to NFs in the NPN, which is in a different trust domain, should be avoided.

[0039] The key issue is to study how to avoid exposure of the sensitive parameters (specifically, permanent identifier) to the entities outside the mobile network operator (MNO) premises (in other security domains).

[0040] As the security at the customer premise might be weaker than that of operator premise even with the existing network domain security (NDS) / IP or SBA security, an attacker can compromise NFs in a customer premise and can retrieve the SUPI to launch targeted attacks.

[0041] If the dedicated NFs could be compromised in customer premises, then theSUPI is available or exposed to the attacker, which can potentially lead to security threats, like privacy breaches, UE location tracking, mapping of the user to the identifiers, targeted denial of service (DoS), or the like.

[0042] As a potential security requirement, the 5G system shall support a mechanism to ensure protection of the sensitive parameters (e.g., SUPI) against the risk caused by a PLMN hosting the NPN.

[0043] In one conventional solution, an authentication procedure for EAP-AKA', e.g., as described in TS 33.501 clause 6. 1.3. 1 (incorporated herein by reference). In case of roaming, the SUPI is sent from the home network unified data management (UDM) and authentication service function (AUSF) to the serving network’s SEAF (co-located with AMF, following the successful primary authentication of the UE. This allows SUPI’s exposure to the AMF / SEAF.

[0044] In another conventional solution related to an authentication procedure for 5G AKA described in TS 33.501 clause 6. 1.3.2 and clause 6.1.3.2.0 (incorporated herein by reference), in case of roaming, the SUPI is sent from the home network UDM and AUSF to the serving network’s SEAF (co-located with AMF), following the successful primary authentication of the UE. This allows SUPI’s exposure to the AMF / SEAF.

[0045] The conventional solutions, however, are insufficient for protecting the UE identifier. In case of PLMN hosting an NPN in the customer premise, which is outside the trust domain or control of the PLMN operator, if the primary authentication procedures described above are applied, both methods will expose the UE’s privacy sensitive SUPI to the AMF / SEAF in NPN leading to privacy risks.

[0046] Figure 2 illustrates an example of a privacy support capability exchange during the primary authentication initiation procedure, in accordance with aspects of the present disclosure. In this embodiment, a method for the UE to indicate its capability (e.g., UE ID privacy support capabilities) to support a privacy protected identifier for the hosted NPN (e.g., a public network integrated (PNI) NPN) or serving (wireless) network (SN) (e.g., in case of roaming) is described. Further, in one embodiment, the UDM determines to enforce SUPI exposure restriction based on the received ‘UE’s capability to support a privacy protected identifier’, the SN ID / NPN ID and the operator policy.

[0047] In 1 (see messaging 202), in one embodiment, the UE 203, if it is capable to support SUPI privacy protection or UE identifier privacy protection, indicates the corresponding ‘UE ID privacy support indication’ to the network in any non-accessstratum (NAS) message / Nl transport (e.g., Registration Request, Mobility Registration update, Periodic Registration update, any initial NAS message, PDU session establishment, modification request message, or the like) along with a UE identifier (e.g., subscription concealed identifier (SUCI), a 5G-globally unique temporary identity (GUTI), or the like).

[0048] In one embodiment, the UE 203 can send ‘UE ID privacy support indication’ as part of the UE 5G security capabilities. In one embodiment, the ‘UE ID privacy support indication’ can also be referred to as ‘UE ID privacy support capabilities’, ‘SUPI privacy capability’, ‘SUPI privacy protection capability’, ‘SUPI exposure restriction capability’ or ‘SUPI hiding / masking’.

[0049] In one embodiment, a ‘UE ID privacy support capabilities indication’ means the UE 203 is capable of using the privacy protected identifier instead of SUPI in the key Kamf derivation. Further, the UE 203 may be able to use the privacy protected identifier if received from the network or the UE 203 can derive the privacy protected identifier, wherein the UE 203 can use the privacy protected identifier instead of SUPI in the key Kamf derivation.

[0050] At 2 (see messaging 204), in one embodiment, the SEAF 205 may initiate an authentication with the UE 203 during a procedure establishing a signaling connection with the UE 203, according to the SEAF's policy. The UE 203 shall use SUCI or 5G- GUTI and the UE ID privacy support indication in the Registration Request.

[0051] In one embodiment, the SEAF 205 shall invoke the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message to the AUSF 209 whenever the SEAF 205 wishes to initiate an authentication.

[0052] In one embodiment, the Nausf_UEAuthentication_Authenticate Request message shall contain a UE ID privacy support indication, the serving network name, and either a SUCI or a SUPI.

[0053] In one embodiment, the SEAF 205 shall include the SUPI in the Nausf_UEAuthentication_Authenticate Request message in case the SEAF 205 has a valid 5G-GUTI and re-authenticates the UE 203. Otherwise, the SUCI is included in Nausf_UEAuthentication_Authenticate Request.

[0054] In one embodiment, the local policy for the selection of the authentication method does not need to be on a per-UE basis but can be the same for all UEs 201. Further, the Nausf_UEAuthentication_Authenticate Request may furthermore contain a Disaster Roaming service indication, as specified in TS 23.502 clause 4.2.2.2 (incorporated herein by reference).

[0055] At 3 (see messaging 206), in one embodiment, upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF 209 shall check that the requesting SEAF 205 in the serving network 201 identified by the 3gpp-Sbi- Originating-Network-Id header, e.g., specified in TS 29.500 (incorporated herein by reference) is entitled to use the serving network name in the Nausf_UEAuthentication_Authenticate Request.

[0056] In one embodiment, for Disaster Roaming, the AUSF 209 shall check the local configuration and, if allowed, the AUSF 209 sends Nudm_UEAuthentication_Get Request to the UDM 211. In one embodiment, the Nudm_UEAuthentication_Get Request sent from the AUSF 209 to the UDM 211 includes a SUCI or SUPI, the serving network name, a Disaster Roaming service indication (if received from the SEAF 205), and a UE ID privacy support indication (if received in step 2).

[0057] At 4a (see block 208), in one embodiment, upon reception of the Nudm_UEAuthentication_Get Request, the UDM 211 shall invoke a subscriber identity deconcealing function (SIDF) 211 if a SUCI is received. The SIDF 211 shall de-conceal SUCI to acquire the SUPI before the 211 UDM can process the request.

[0058] At 4b (see block 208) in one embodiment, based on the SUPI, the UDM or authentication credential repository and processing function (ARPF) 211 shall choose the authentication method. In one embodiment, the Nudm UEAuthentication Get Response in reply to the Nudm_UEAuthentication_Get Request and the Nausf_UEAuthentication_Authenticate Response message in reply to the Nausf_UEAuthentication_Authenticate Request message are described as part of the authentication procedures in below. In one embodiment, for Disaster Roaming, the UDM 211 shall check the local configuration and, if allowed, the UDM 211 proceeds with the chosen authentication method.

[0059] At 4c (see block 208), in one embodiment, the UDM 211 manages the SUPI exposure restriction information / policies for one or more of hosted NPNs or servingnetworks (identified with their NPN ID, SN ID, or the like). In one embodiment, SUPI exposure restriction information or policies may state whether SUPI exposure is allowed or not (for the UE 203 during a hosted NPN / serving network access).

[0060] In one embodiment, the SUPI exposure restriction information or policies may state whether SUPI exposure enforcement is needed or not (for the UE 203 during a hosted NPN / serving network access).

[0061] In one embodiment, based on the SUPI exposure restriction information, policies, or operator policy, the SN ID or NPN ID, and the UE ID privacy support indication, the UDM 211 determines not to disclose SUPI to the hosted NPN 201, VPLMN, serving network, or the like.

[0062] In one embodiment, the SUPI exposure restriction information or policy is referred to as a ‘SUPI disclosure policy’.

[0063] In one embodiment, if the UDM 211 determines not to disclose the SUPI(e.g., to enforce SUPI exposure restriction), the UDM 211 generates or assigns the serving network UE ID (S-UEID) for the SUPI and stores the SUPI and S-UEID pair in the UDM / UDR 211.

[0064] In one embodiment, the UDM 211 may generate the serving network UE ID (S-UEID) based on a ID Type and a Privacy protected UE identifier (P-Intemational Mobile Subscriber Identity (IMSI)ZP-Network Slice Instance Identifier (NSI)ZP-Global Line Identifier (GLI)ZP-Global Cable Identifier (GCI)), where P stands for ‘privacy protected’ . In another embodiment, the UDM 211 may generate the serving network UE ID (S-UEID) based on an ID Type and a privacy protected Equivalent UE identifier (E-IMSI / E-NSI / E-GLI / E-GCI), where E stands for ‘privacy protected equivalent’.

[0065] In one embodiment, E-IMSI includes a mobile country code (MCC), mobile network code (MNC), SNN / SN ID, and / or an EMSIN, where EMSIN identifies the UE subscription data within the serving network and it is a privacy protected Mobile Subscriber identification number (MSIN).

[0066] In one embodiment, E-NSI includes an equivalent username @ MCC, MNC and SNN or Serving NID or NPN ID. In one embodiment, E-GLI and E-GCI can be constructed with equivalent username and realm information same as E-NSI.

[0067] In one embodiment, as an alternative, the S-UEID can include the E-IMSI, E-NSI, E-GLI, E-GCI, or the like. In such an embodiment, the E-MSIN part of E-IMSI is a MAC (comprising a SUPI, SNN / SN ID / NPN ID, a freshness parameter (e.g., Nonce, random challenge (RAND), Counter) known to the UE 203 and network or provided by the network to the UE 203). The rest of the E-IMSI is the same as described above e.g., MCC, MNC, SNN / SN ID. In one embodiment, the E-IMSI composition can be an MCC, MNC, SNN / SN ID / NPN ID, EMSIN, and / or the like.

[0068] In one embodiment, the E-usemame part of E-NSI / E-GLI / E-GCI is the MAC (Usemame / SUPI, SNN / SN ID / NPN ID, a freshness parameter (e.g., Nonce, RAND, Counter) known to the UE 203 and network or provided by the network to the UE 203). The rest of the E-NSI / E-GLI / E-GCI is the same as described above e.g., @ MCC, MNC, SNN / SN ID. E-IMSI composition can be an E-usemame@MCC, MNC, SNN / SN ID / NPN ID, and / or the like.

[0069] Figure 3 illustrates an example of SUPI disclosure restriction and privacy protected UE ID usage in a hosted NPN or serving networking scenario during primary authentication with EAP-AKA’, in accordance with aspects of the present disclosure.

[0070] In one embodiment, the process of SUPI exposure restriction (during the EAP-AKA’ based primary authentication run) includes providing a privacy protected UE ID (instead of SUPI) such as S-UEID constructed by the UDM (described above) is provided to the serving network or NPN, to enable the serving network or NPN and the UE to use the privacy protected UE ID (e.g., S-UEID) in the further primary authentication and key establishment process such as Kseaf and Kamf derivation. The privacy protected UE ID (S-UEID) generation at the UDM is described with reference to Figure 2 and its respective usage is detailed in Figure 3.

[0071] At 1 (see block 302), in one embodiment, the UDM / ARPF 307 shall first generate an authentication vector with Authentication Management Field (AMF) separation bit = 1, e.g., as defined in TS 33.102 (incorporated herein by reference). The UDM / ARPF 307 shall then compute the cipher key (CK1) and integrity key (IK1) as per the normative Annex A and replace CK and IK by CK' and IK'.

[0072] At 2 (see messaging 304), in one embodiment, the UDM 307 shall send the transformed authentication vector AV (RAND, authentication token (AUTN), expected response (XRES), CK', IK) to the AUSF 305 from which it received theNudm_UEAuthentication_Get Request together with an indication that the authentication vector (AV) is to be used for EAP-AKA' using a Nudm_UEAuthentication_Get Response message.

[0073] In one embodiment, the exchange of a Nudm_UEAuthentication_Get Request message and an Nudm_UEAuthentication_Get Response message between the AUSF 305 and the UDM / ARPF 307 described in the preceding paragraph is the same as for trusted access using EAP-AKA' described in TS 33.402, sub-clause 6.2, step 10 (incorporated herein by reference), except for the input parameter to the key derivation, which is the value of <network name>. In one embodiment, the “network name” is a concept from RFC 5448 (incorporated herein by reference), which is carried in the AT KDF INPUT attribute in EAP-AKA'. The value of the <network name> parameter is not defined in RFC 5448, but rather in 3GPP specifications. For EPS, it is defined as “access network identity” in TS 24.302 (incorporated herein by reference), and for 5G, it is defined as “serving network name”.

[0074] In one embodiment, in case SUCI was included in the Nudm_UEAuthentication_Get Request, if the UDM 307 determines not to disclose SUPI to the hosted NPN / VPLMN / serving network (based on Figure 2 and if it constructs a S-UEID), the UDM 307 will include the S-UEID in addition to SUPI and SUPI disclosure restriction indication in the Nudm_UEAuthentication_Get Response.

[0075] In one embodiment, if a subscriber has an AKMA subscription, the UDM 307 shall include the AKMA indication and Routing indicator in the Nudm_UE Authentication_Get Response .

[0076] At 3 (see messaging 306), in one embodiment, the AUSF 305 shall send the EAP-Request / AKA'-Challenge message to the SEAF 303 in a Nausf_UEAuthentication_Authenticate Response message. In one embodiment, if the AUSF 305 receives only SUPI disclosure restriction indication and freshness parameters along with SUPI and rest of information, the AUSF 305 generates and constructs the S- UEID in this step or later in 10b (as described in Figure 2 for the UDM 211).

[0077] At 4 (see messaging 308), in one embodiment, the SEAF 303 shall transparently forward the EAP-Request / AKA'-Challenge message to the UE 301 in a NAS message Authentication Request message. The UE 301 shall forward the RAND and AUTN received in EAP-Request / AKA'-Challenge message to the universalsubscriber identity module (USIM). This message shall include the ngKSI and antibidding down between architectures (ABBA) parameter. In one embodiment, the SEAF 303 shall include the ngKSI and ABBA parameter in EAP -Authentication request messages. The ngKSI may be used by the UE 301 and AMF to identify the partial native security context that is created if the authentication is successful. The SEAF 303 shall set the ABBA parameter, e.g., as defined in Annex A.7.1. During an EAP authentication, the value of the ngKSI and the ABBA parameter sent by the SEAF 303 to the UE 301 shall not be changed.

[0078] In one embodiment, the SEAF 303 needs to understand that the authentication method used is an EAP method by evaluating the type of authentication method based on the Nausf_UEAuthentication_Authenticate Response message.

[0079] At 5 (see block 310), in one embodiment, upon receipt of the RAND and AUTN, the USIM shall verify the freshness of the AV by checking whether AUTN can be accepted, e.g., as described in TS 33.102 (incorporated herein by reference). If so, the USIM computes a response RES. The USIM shall return RES, CK, IK to the UE 301. If the USIM computes a Kc (i.e., GPRS Kc) from CK and IK using conversion function c3, e.g., as described in TS 33.102 (incorporated herein by reference), and sends it to the UE 301, then the UE 301 shall ignore such GPRS Kc and not store the GPRS Kc on USIM or in the UE 301. The UE 301 shall derive CK' and IK according to Annex A.3.

[0080] In one embodiment, if the verification of the AUTN fails on the USIM, then the USIM and UE 301 shall proceed as described in sub-clause 6.1.3.

[0081] At 6 (see messaging 312), in one embodiment, the UE 301 shall send the EAP-Response / AKA'-Challenge message to the SEAF 303 in a NAS message Auth- Resp message.

[0082] At 7 (see messaging 314), in one embodiment, the SEAF 303 shall transparently forward the EAP-Response / AKA'-Challenge message to the AUSF 305 in Nausf_UEAuthentication_Authenticate Request message.

[0083] At 8 (see block 316), in one embodiment, the AUSF shall verify the message by comparing the XRES and RES, and if the AUSF 305 has successfully verified thismessage it shall continue as follows, otherwise it shall return an error to the SEAF 303.The AUSF 305 shall inform the UDM 307 about the authentication result.

[0084] At 9 (see block 318), in one embodiment, the AUSF 305 and the UE 301 may exchange EAP-Request / AKA'-Notification and EAP-Response / AKA' -Notification messages via the SEAF 303. The SEAF 303 shall transparently forward these messages.

[0085] In one embodiment, EAP Notifications, e.g., as described in RFC 3748 (incorporated herein by reference), and EAP-AKA Notifications, e.g., as described in RFC 4187 (incorporated herein by reference), can be used at any time in the EAP-AKA exchange. These notifications can be used e.g., for protected result indications or when the EAP server detects an error in the received EAP-AKA response.

[0086] At 10a (see block 320), in one embodiment, the AUSF 305 derives the extended master session key (EMSK) from CK’ and IK’, e.g., as described in RFC 5448 and Annex F (incorporated herein by reference). The AUSF 305 uses the most significant 256 bits of EMSK as the KAUSF key and then calculates KSEAF key from KAUSF key, e.g., as described in clause A.6. The AUSF 305, based on SUPI disclosure restriction indication received in step 2 from the UDM 307, determines to provide the S- UEID instead of SUPI. In one embodiment, if the AUSF 305 receives only SUPI disclosure restriction indication and freshness parameters along with SUPI and the rest of the information, the AUSF 305 generates and constructs the S-UEID in this step or later in step 10b (e.g., as described with reference to Figure 2 for UDM).

[0087] At 10b (see messaging 322), in one embodiment, the AUSF 305 shall send an EAP Success message to the SEAF 303 inside Nausf_UEAuthentication_Authenticate Response along with S-UEID, which shall forward it transparently to the UE 301. In one embodiment, the Nausf_UEAuthentication_Authenticate Response message contains the KSEAF key. If the AUSF 305 received a SUCI from the SEAF 303 when the authentication was initiated, then the AUSF 305 shall also include the S-UEID instead of SUPI in the Nausf_UEAuthentication_Authenticate Response message. The AUSF 305 stores the KAUSF key and SUPI along with S-UEID based on the home network operator's policy.

[0088] In one embodiment, for lawful interception, the AUSF 305 sending the S- UEID instead of SUPI to SEAF 303 is necessary but not sufficient. By including the S- UEID instead of SUPI as input parameter to the key derivation of KAMF key from KSEAFkey, additional assurance on the correctness of S-UEID (instead of SUPI, which is indirectly related to S-UE ID) is achieved by the serving network from both the home network and the UE side.

[0089] At 1 la and 1 lb (see block 324 and messaging 326), in one embodiment, the SEAF 303 shall send the EAP Success message with S-UEID to the UE 301 in the N1 message. This message shall also include the ngKSI and the ABBA parameter. The SEAF 303 shall set the ABBA parameter as defined in Annex A.7.1.

[0090] In one embodiment, Step 11 could be a NAS Security Mode Command or Authentication Result. In one embodiment, the ABBA parameter is included to enable the bidding down protection of security features that may be introduced later.

[0091] In one embodiment, the key received in the Nausf_UEAuthentication_Authenticate Response message shall become the anchor key, KSEAF in the sense of the key hierarchy. The SEAF 303 shall then derive the KAMF key from the KSEAF key, the ABBA parameter and the S-UEID (if it is received instead of SUPI) by reusing Annex A.7 and send it to the AMF. Upon receiving the EAP-Success message, the UE 301 derives EMSK from CK’ and IK’ as described in RFC 5448 and Annex F. The UE 301 uses the most significant 256 bits of the EMSK as the KAUSF key and then calculates KSEAF key in the same way as the AUSF 305.

[0092] At 11c (see block 328), in one embodiment, the UE 301 shall derive the KAMF key from the KSEAF key, the ABBA parameter and the S-UEID (instead of SUPI if the S-UEID is received in the NAS message) by reusing Annex A.7.

[0093] In one embodiment, as an implementation option, the UE 301 creates the temporary security context as described in step 11 after receiving the EAP message that allows EMSK to be calculated. The UE 301 turns this temporary security context into a partial security context when it receives the EAP Success. The UE 301 removes the temporary security context if the EAP authentication fails.

[0094] In one embodiment, if the EAP-Response / AKA' -Challenge message is not successfully verified, the subsequent AUSF behaviour is determined according to the home network’s policy. In one embodiment, if the AUSF 305 and SEAF 303 determine that the authentication was successful, then the SEAF 303 provides the ngKSI and the KA F key to the AMF.

[0095] In one embodiment, as an alternative, in 2 (see messaging 304), the UDM 307 may send the SUPI disclosure restriction indication, S-UEID and a freshness parameter to the AUSF 305.

[0096] In one embodiment, as an alternative, in 10b (see messaging 322), the AUSF 305 sends the SUPI disclosure restriction indication, S-UEID and a freshness parameter received from the UDM 307 to the SEAF 303.

[0097] In one embodiment, as an alternative, in 11b (see messaging 326), the SEAF / AMF 303 sends (in NAS message) the SUPI disclosure restriction indication and a freshness parameter received in step 10b to the UE 301.

[0098] In one embodiment, the UE 301, upon receiving the the SUPI disclosure restriction indication, derives the S-UEID (similar to the UDM as described in Figure 2) and further uses the S-UEID to derive the Kamf key similar to the SEAF 303 and verifies the NAS messages (e.g., integrity protection of NAS message if it is a NAS security mode command message from the AMF).

[0099] In one embodiment, as an alternative, the S-UEID can include the E-IMSI, E-NSI, E-GLI, E-GCI, or the like. In such an embodiment, the E-MSIN part of E-IMSI is a MAC (comprising a SUPI, SNN / SN ID / NPN ID, a freshness parameter (e.g., Nonce, RAND, Counter) known to the UE 301 and network or provided by the network to the UE 301). The rest of the E-IMSI is the same as described above e.g., MCC, MNC, SNN / SN ID. In one embodiment, the E-IMSI composition can be an MCC, MNC, SNN / SN ID / NPN ID, EMSIN, and / or the like.

[0100] In one embodiment, the E-usemame part of E-NSI / E-GLI / E-GCI is the MAC (Usemame / SUPI, SNN / SN ID / NPN ID, a freshness parameter (e.g., Nonce, RAND, Counter) known to the UE 301 and network or provided by the network to the UE 301). The rest of the E-NSI / E-GLI / E-GCI is the same as described above e.g., @ MCC, MNC, SNN / SN ID. E-IMSI composition can be an E-usemame@MCC, MNC, SNN / SN ID / NPN ID, and / or the like.

[0101] Figure 4 illustrates an example of SUPI disclosure restriction and privacy protected UE ID usage in a hosted NPN or serving networking scenario during primary authentication with 5G AKA, in accordance with aspects of the present disclosure.

[0102] In Figure 4, the process of SUPI exposure restriction (during the 5G AKA based primary authentication run) includes providing a privacy protected UE ID (instead of SUPI) such as S-UEID constructed by the UDM 407 (e.g., as described in Figure 2) is provided to the serving network or NPN, to enable the serving network or NPN and UE 401 to use the privacy protected UE ID (i.e., S-UEID) in the further primary authentication and key establishment process such as Kseaf and Kamf derivation.

[0103] At 1 (see block 402), in one embodiment, for each Nudm_Authenticate_Get Request, the UDM / ARPF 407 shall create a 5G home environment (HE) AV. The UDM / ARPF 407 does this by generating an AV with the Authentication Management Field (AMF) separation bit set to “1”, e.g., as defined in TS 33.102. The UDM / ARPF 407 shall then derive KAUSF (as per Annex A.2) and calculate XRES* (as per Annex A.4). Finally, the UDM / ARPF 407 shall create a 5G HE AV from RAND, AUTN, XRES*, and KAUSF.

[0104] At 2 (see messaging 404), in one embodiment, the UDM 407 shall then return the 5G HE AV to the AUSF 405 together with an indication that the 5G HE AV is to be used for 5G AKA in a Nudm_UEAuthentication_Get Response. In case SUCI was included in the Nudm_UEAuthentication_Get Request, if the UDM 407 determines not to disclose SUPI to the hosted NPN / VPLMN / serving network (based on Figure 2 and if it constructs a S-UEID), the UDM 407 will include the S-UEID in addition to SUPI and SUPI disclosure restriction indication in the Nudm UEAuthentication Get Response after deconcealment of SUCI by SIDF. In one embodiment, if a subscriber has an AKMA subscription, the UDM 407 shall include the AKMA indication and Routing indicator in the Nudm UEAuthentication Get Response.

[0105] At 3 and 4 (see block 406), in one embodiment, the AUSF 405 shall store the XRES* temporarily together with the received SUCI or SUPI. In one embodiment, the AUSF 405 shall then generate the 5G AV from the 5G HE AV received from the UDM / ARPF 407 by computing the hash of the XRES* (HXRES*) from XRES* (according to Annex A.5) and KSEAF from KAUSF (according to Annex A.6), and replacing the XRES* with the HXRES* and KAUSF with KSEAF in the 5G HE AV.

[0106] At 5 (see messaging 408), in one embodiment, the AUSF 405 shall then remove the KSEAF and return the 5G SE AV (RAND, AUTN, HXRES*) to the SEAF 403 in a Nausf_UEAuthentication_UEAuthentication Response.

[0107] At 6 (see messaging 410), in one embodiment, the SEAF 403 shall send RAND, AUTN to the UE 401 in a NAS message Authentication Request. This message shall also include the ngKSI that will be used by the UE 401 and AMF to identify the KAMF and the partial native security context that is created if the authentication is successful. This message shall also include the ABBA parameter. The SEAF 403 shall set the ABBA parameter as defined in Annex A.7.1. The UE 401 shall forward the RAND and AUTN received in NAS message Authentication Request to the USIM. In one embodiment, the ABBA parameter is included to enable the bidding down protection of security features.

[0108] At 7 (see block 412), in one embodiment, at receipt of the RAND and AUTN, the USIM shall verify the freshness of the received values by checking whether AUTN can be accepted, e.g., as described in TS 33.102. If so, the USIM computes a response RES. The USIM shall return RES, CK, IK to the UE 401. If the USIM computes a Kc (i.e. GPRS Kc) from CK and IK using conversion function c3, e.g., as described in TS 33. 102, and sends it to the UE 401, then the UE 401shall ignore such GPRS Kc and not store the GPRS Kc on USIM or in UE 401. The UE 401then shall compute RES* from RES according to Annex A.4. The UE 401shall calculate KAUSF from CK||IK according to clause A.2. The UE 401shall calculate KSEAF from KAUSF according to clause A.6. A UE 401 accessing 5G shall check during authentication that the "separation bit" in the AMF field of AUTN is set to 1. The “separation bit is bit 0 of the AMF field of AUTN. In one embodiment, the separation bit in the AMF field of AUTN cannot be used anymore for operator specific purposes as described by TS 33.102.

[0109] At 8 (see messaging 414), in one embodiment, the UE 401 shall return RES* to the SEAF 403 in a NAS message Authentication Response.

[0110] At 9 (see block 416), in one embodiment, the SEAF 403 shall then compute HRES* from RES* according to Annex A.5, and the SEAF 403 shall compare HRES* and HXRES*. If they coincide, the SEAF 403 shall consider the authentication successful from the serving network point of view. If not, the SEAF 403 proceeds asdescribed in sub-clause 6. 1.3.2.2. If the UE 401 is not reached, and the RES* is never received by the SEAF 403, the SEAF 403 shall consider authentication as failed, and indicate a failure to the AUSF 405.

[0111] At 10 (see messaging 418), in one embodiment, the SEAF 403 shall send RES*, as received from the UE 401, in a Nausf_UEAuthentication_Authenticate Request message to the AUSF 405.

[0112] At 1 la (see block 420), in one embodiment, when the AUSF 405 receives as authentication confirmation the Nausf_UEAuthentication_Authenticate Request message including a RES* it may verify whether the 5G AV has expired. If the 5G AV has expired, the AUSF 405 may consider the authentication as unsuccessful from the home network point of view. Upon successful authentication, the AUSF 405 stores the KAUSF based on the home network operator's policy according to clause 6. 1. 1. 1. AU SF 405 shall compare the received RES* with the stored XRES*. If the RES* and XRES* are equal, the AUSF 405 shall consider the authentication as successful from the home network point of view. AUSF 405 shall inform UDM 407 about the authentication result.

[0113] At 1 lb (see block 422), in one embodiment, the AUSF 405, based on SUPI disclosure restriction indication received in step 2 from the UDM 407, determines to provide the S-UEID instead of SUPI. In one embodiment, if the AUSF 405 receives only SUPI disclosure restriction indication and freshness parameters along with SUPI and rest of information, the AUSF 405 generates and constructs the S-UEID in this step (as described in Figure 2 for the UDM). In one embodiment, it is left to implementation to temporarily store the KAUSF received in step 2 in AUSF 405 until the RES* verification is done successfully (e.g., at step 1 la).

[0114] At 12 (see messaging 424), in one embodiment, the AUSF 405 shall indicate to the SEAF 403 in the Nausf_UEAuthentication_Authenticate Response whether the authentication was successful or not from the home network point of view. If the authentication was successful, the KSEAF shall be sent to the SEAF 403 in the Nausf_UEAuthentication_Authenticate Response along with S-UEID. In case the AUSF 405 received a SUCI from the SEAF 403 in the authentication request (see subclause 6.1.2 of the present document), and if the authentication was successful, then the AUSF 405 shall also include the S-UEID instead of SUPI in theNausf_UEAuthentication_Authenticate Response message. In one embodiment, the AUSF 405 may store the SUPI along with S-UEID.

[0115] In one embodiment, if the authentication was successful, the key KSEAF received in the Nausf_UEAuthentication_Authenticate Response message shall become the anchor key in the sense of the key hierarchy. Then the SEAF 403 shall derive the KAMF from the KSEAF, the ABBA parameter and the S-UEID (instead of SUPI if S-UE ID is received) by reusing / according to Annex A.7. The SEAF 403 shall provide the ngKSI and the KAMF to the AMF. If the AUSF 405 indicates that the authentication was successful from the home network point of view, then the AMF shall initiate NAS security mode command procedure (as described in Figure 5, which enhances NAS SMC specified TS 33.501 clause 6.7.2) with the UE 401, to take the newly generated partial native 5G NAS security context into use. Upon receiving the valid NAS Security Mode Command message from the AMF, the UE 401 shall consider the performed primary authentication as successful.

[0116] In one embodiment, if a SUCI was used for this authentication, then the SEAF 403 shall only provide ngKSI, S-UEID and KA F to the AMF after it has received the Nausf_UEAuthentication_Authenticate Response message containing KSEAF and S- UEID (instead of SUPI). In one embodiment, no communication services will be provided to the UE 401 until the S-UEID (instead of SUPI) is known to the serving network.

[0117] In one embodiment, as an alternative, in 2 (see messaging 404), the UDM 407 may send the SUPI disclosure restriction indication, S-UEID and a freshness parameter to the AUSF 405.

[0118] In one embodiment, as an alternative, in 11b (see block 422), the AUSF 405 sends the SUPI disclosure restriction indication, S-UEID and a freshness parameter received from the UDM 407 to the SEAF 403.

[0119] In one embodiment, as an alternative, the SEAF / AMF 403, after step 13 (see block 426), during NAS SMC, sends (in NAS message) the SUPI disclosure restriction indication and a freshness parameter received in step 10b to the UE 401.

[0120] In one embodiment, the UE 401, upon receiving the the SUPI disclosure restriction indication, derives the S-UEID (similar to the UDM as described in Figure 2)and further uses the S-UEID to derive the Kamf key similar to the SEAF 403 and verifies the NAS messages (e.g., integrity protection of NAS message if it is a NAS security mode command message from the AMF).

[0121] In one embodiment, as an alternative, the S-UEID can include the E-IMSI, E-NSI, E-GLI, E-GCI, or the like. In such an embodiment, the E-MSIN part of E-IMSI is a MAC (comprising a SUPI, SNN / SN ID / NPN ID, a freshness parameter (e.g., Nonce, RAND, Counter) known to the UE 401 and network or provided by the network to the UE 401). The rest of the E-IMSI is the same as described above e.g., MCC, MNC, SNN / SN ID. In one embodiment, the E-IMSI composition can be an MCC, MNC, SNN / SN ID / NPN ID, EMSIN, and / or the like.

[0122] In one embodiment, the E-usemame part of E-NSI / E-GLI / E-GCI is the MAC (Usemame / SUPI, SNN / SN ID / NPN ID, a freshness parameter (e.g., Nonce, RAND, Counter) known to the UE 401 and network or provided by the network to the UE 301). The rest of the E-NSI / E-GLI / E-GCI is the same as described above e.g., @ MCC, MNC, SNN / SN ID. E-IMSI composition can be an E-usemame@MCC, MNC, SNN / SN ID / NPN ID, and / or the like.

[0123] Figure 5 illustrates an example of NAS SMC for UE ID privacy support capability protection and provisioning UE with privacy protected UE ID, in accordance with aspects of the present disclosure.

[0124] In one embodiment, the UE’s capability on support of privacy protected identifier (that is received by the AMF 503 from UE 501 in initial NAS message) is replayed / sent to the UE 501 in the NAS security mode command message (which is integrity protected) and / or the UE 501 replays the UE’s capability on support of privacy protected identifier in the NAS security mode complete message (which is confidentiality and integrity protected).

[0125] Additionally, in case of the 5G-AKA’, following a successful primary authentication, the AMF 503 may provision the privacy protected UE Identifier (i.e., S- UEID (or) the SUPI disclosure restriction indication and any freshness parameter (to let the UE generate the privacy protected UE Identifier) in the NAS security mode command message. The NAS SMC shall be used to establish NAS Security context between the UE 501 and the AMF 503. This procedure consists of a roundtrip of messages between the AMF 503 and the UE 501. The AMF 503 sends the NASSecurity Mode Command message to the UE 501 and the UE 501 replies with the NAS Security Mode Complete message.

[0126] In one embodiment, the NAS SMC procedure is designed such that it protects the Registration Request against a man-in-the-middle attack where the attacker modifies the IES containing the UE security capabilities provided by the UE 501 in the Registration Request. It works as follows - if the method completes successfully, the UE 501 is attached to the network knowing that no bidding down attack has happened. In case a bidding down attack was attempted, the verification of the NAS SMC will fail, and the UE 501 replies with a reject message meaning that the UE 501 will not attach to the network.

[0127] At la (see messaging 502), in one embodiment, the UE 501, if it is capable to support SUPI privacy protection or UE identifier privacy protection, indicates the corresponding ‘UE ID privacy support indication’ to the network in any NAS message / Nl transport (e.g., Registration Request / Mobility Registration update / Periodic Registration update / any initial NAS message / PDU session establishment / modification request message etc.,) along with UE identifier (SUCI / 5G-GUTI).

[0128] In one embodiment, the UE 501 can send ‘UE ID privacy support indication’ as part of UE 5G security capabilities. In one embodiment, the ‘UE ID privacy support indication’ can be referred to as, ‘UE ID privacy support capabilities’ or ‘SUPI privacy capability’ or ‘SUPI privacy protection capability’ or ‘SUPI exposure restriction capability’ or ‘SUPI hiding / masking’.

[0129] In one embodiment, ‘UE ID privacy support capabilities / ty indication’ means the UE 501 is capable of using the privacy protected identifier instead of SUPI in the Kseaf and Kamf derivation. Further the UE 501 may be able to use the privacy protected identifier if received from the network or the UE 501 can derive by itself the privacy protected identifier and the UE 501 can further use it instead of SUPI in the Kamf derivation, following a successful primary authentication. In one embodiment, the UE 501 and the network have performed a successful primary authentication.

[0130] At lb (see block 504), the AMF 503 activates the NAS integrity protection before sending the NAS Security Mode Command message.

[0131] At 1c (see messaging 506), the AMF 503 sends the NAS Security Mode Command message to the UE 501. The NAS Security Mode Command message shall contain the replayed UE security capabilities (including the UE ID privacy support indication), the selected NAS algorithms, and the ngKSI for identifying the KAMF.

[0132] The NAS Security Mode Command message may contain K_AMF_change_flag (carried in the additional 5G security parameters IE specified in TS 24.501 (incorporated herein by reference)) to indicate a new KAMF is calculated, a flag requesting the complete initial NAS message (see subclause 6.4.6), ABBA parameter, S-UEID or SUPI disclosure restriction indication and freshness parameter (if received from SEAF during the primary authentication). In the case of horizontal derivation of KA F during mobility registration update or during multiple registration in same PLMN, K_AMF_change_flag shall be included in the NAS Security Mode Command message.

[0133] In one embodiment, the message shall be integrity protected (but not ciphered) with NAS integrity key based on the KAMF indicated by the ngKSI in the NAS Security Mode Command message. In one embodiment, in case the network supports interworking using the N26 interface between MME and AMF 503, the AMF 503 shall also include the selected EPS NAS algorithms (e.g., defined in Annex B of TS 33.401 (incorporated herein by reference)) to be used after mobility to EPS in the NAS Security Mode Command message. The UE 501 shall store the algorithms for use after mobility to EPS using the N26 interface between MME and AMF 503. The AMF 503 shall store the selected EPS NAS algorithms in the UE security context.

[0134] In one embodiment, when the AMF 503 change happens either due to N2- handover or idle mode mobility, the selected EPS NAS algorithms is always included in the 5G UE security context and provided to the target AMF 503 as part of the 5G UE security context.

[0135] At Id (see messaging 508), in one embodiment, the AMF 503 activates NAS uplink deciphering after sending the NAS Security Mode Command message.

[0136] At 2a (see block 510), in one embodiment, the UE 501 shall verify the NAS Security Mode Command message. This includes checking that the UE 501 security capabilities sent by the AMF 503 match the ones stored in the UE 501 to ensure that these were not modified by an attacker and verifying the integrity protection using theindicated NAS integrity algorithm and the NAS integrity key based on the KAMF indicated by the ngKSI.

[0137] In one embodiment, in case the NAS Security Mode Command message includes a K_AMF_change_flag, the UE 501 shall derive a new KAMF as described in Annex A. 13 and set the NAS COUNT to zero.

[0138] In one embodiment, if the verification of the integrity of the NAS Security Mode Command message is successful, the UE 501 shall start NAS integrity protection and ciphering / deciphering with the security context indicated by the ngKSI.

[0139] At 2b (see messaging 512), in one embodiment, the UE 501 shall derive the KA F from the KSEAF, the ABBA parameter and the S-UEID (instead of SUPI if the S- UEID is received in the NAS message) by reusing Annex A.7 In one embodiment, if the S-UEID is not received in NAS message and instead a SUPI disclosure restriction indication and freshness parameter are received, the UE 501 derives / constructs the S- UEID (as described in Figure 3, similar to the UDM / AUSF), the further the UE 501 derives the KAMF from the KSEAF, the ABBA parameter and the derived S-UEID.

[0140] In one embodiment, the UE 501 sends the NAS Security Mode Complete message to the AMF 503 ciphered and integrity protected. The NAS Security Mode Complete message shall include PEI in case AMF 503 requested it in the NAS Security Mode Command message. The AMF 503 shall set the NAS COUNTs to zero if horizontal derivation of KAMF is performed.

[0141] In one embodiment, the UE 501 may include the complete initial NAS message along with UE security capabilities (including the UE ID privacy support indication) (see below with enhancements to TS 33.501 subclause 6.4.6 (incorporated herein by reference) for details). In one embodiment, if the verification of the NAS Security Mode Command message is not successful in the UE 501, it shall reply with a NAS Security Mode Reject message (see TS 24.501). The NAS Security Mode Reject message and all subsequent NAS messages shall be protected with the previous, if any, 5G NAS security context, i.e., the 5G NAS security context used prior to the failed NAS Security Mode Command message. If no 5GNAS security context existed prior to the NAS Security Mode Command message, the NAS Security Mode Reject message shall remain unprotected.

[0142] In one embodiment, the AMF 503 shall de-cipher and check the integrity protection on the NAS Security Mode Complete message using the key and algorithm indicated in the NAS Security Mode Command message. NAS downlink ciphering at the AMF 503 with this security context shall start after receiving the NAS Security Mode Complete message.

[0143] At Id (see block 514), in one embodiment, the AMF 503 activates NAS downlink ciphering. In one embodiment, if the uplink NAS COUNT will wrap around by sending the NAS Security Mode Reject message, the UE 501 releases the NAS connection instead of sending the NAS Security Mode Reject message. In one embodiment, if the AMF 503 successfully validated the NAS SMC Complete message, the AMF 503 has successfully confirmed the SUPI received from the home network and the SUPI used by the UE match (as required in clause 5.5.3). However, integrity check failure of the NAS SMC Complete message at the AMF 503 could have other causes than a mismatch of the SUPIs.

[0144] In one embodiment, related to enhancements to protection of initial NAS message, which includes UE ID privacy support capability protection, the initial NAS message is the first NAS message that is sent after the UE transitions from the idle state. The UE shall send a limited set of IES (called the cleartext IES) including those needed to establish security along with S-UE ID, UE security capabilities (including the UE ID privacy support indication) in the initial message when it has no NAS security context. When the UE has a NAS security context, the UE shall send a message that has the complete initial NAS message along with UE security capabilities (including the UE ID privacy support indication) ciphered in a NAS Container along with the cleartext IEs with whole message integrity protected. The complete initial message is included in the NAS Security Mode Complete message in a NAS Container when needed (e.g. AMF cannot find the used security context) in the latter case and always in the former case as described below.

[0145] In one embodiment, the UE selects a PLMN other than Registered PLMN / EPLMN in the 5GMM-IDLE state and the UE has a NAS security context containing the NEA0, then the UE shall discard the NAS security context and shall follow the procedure specified in this clause for protection of initial NAS message.

[0146] In one embodiment, at step 1, the UE shall send the initial NAS message to the AMF. If the UE has no NAS security context, the initial NAS message shall only contain the cleartext IES, i.e. subscription identifiers (e.g. SUCI or GUTIs), UE security capabilities with the UE ID privacy support indication), ngKSI, indication that the UE is moving from EPC, Additional GUTI, and IE containing the TAU Request in the case idle mobility from LTE.

[0147] In one embodiment, if the UE has a NAS security context, the message sent shall contain the information given above in cleartext and the complete initial NAS message (with the UE ID privacy support indication) ciphered in a NAS container which is ciphered. With a NAS security context, the sent message shall also be integrity protected. In the case that the initial NAS message was protected, and the AMF has the same security context, then steps 2 to 4 may be omitted In this case the AMF shall use the complete initial NAS message that is in the NAS container as the message to respond to.

[0148] In one embodiment, at step 2, if the AMF is not able to find the security context locally or from last visited AMF, or if the integrity check fails, then the AMF shall initiate an authentication procedure with the UE. If the AMF fetches old security context from the last visited AMF using the S-UEID, the AMF may decipher the NAS container with the same security context, and get the initial NAS message, then the step 2b to 4 may be omitted. If the AMF fetches new K AMF from the last visited AMF (receiving keyAmfChangelnd), the step 2b may be omitted.

[0149] In one embodiment, at step 3, if the authentication of the UE is successful, the AMF shall send the NAS Security Mode Command message as described above. If the initial NAS message was protected but did not pass the integrity check (due either to a MAC failure or the AMF not being able to find the used security context) or the AMF could not decrypt the complete initial NAS message in the NAS container (due to receiving "keyAmfChangelnd" from the last visited AMF), then the AMF shall include in the Security Mode Command message a flag requesting the UE to send the complete initial NAS message in the NAS Security Mode Complete message.

[0150] In one embodiment, at step 4, the UE shall send the NAS Security Mode Complete message to the network in response to a NAS Security Mode Command message. The NAS Security Mode Complete message shall be ciphered and integrityprotected. Furthermore, the NAS Security Mode Complete message shall include the complete initial NAS message with UE security capabilities (including the UE ID privacy support indication) in a NAS Container if either requested by the AMF or the UE sent the initial NAS message unprotected. The AMF shall use the complete initial NAS message that is in the NAS container as the message to respond to.

[0151] In one embodiment, at step 5, the AMF shall send its response to the Initial NAS message. This message shall be ciphered and integrity protected.

[0152] Figure 6 illustrates an example of a UE 600 in accordance with aspects of the present disclosure. The UE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608. The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0153] The processor 602, the memory 604, the controller 606, or the transceiver 608, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0154] The UE 600 may be configured to support a means to transmit, to a serving wireless network, an indication that the UE is capable of identifier privacy protection, receive, from the serving wireless network, privacy protection information for the UE, and determine a privacy protection identifier for the UE based on the privacy protection information received from the serving wireless network. In one embodiment, the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

[0155] In one embodiment, the UE 600 may be configured to support a means to determine whether the UE is capable of identifier privacy protection. In one embodiment, the UE 600 may be configured to support a means to transmit theindication as part of a NAS message, a registration request message, a security mode complete, or a registration update message.

[0156] In one embodiment, the UE 600 may be configured to support a means to transmit the indication as part of a UE security capabilities transmission. In one embodiment, the privacy protection identifier for the UE is received as part of the privacy protection information.

[0157] In one embodiment, the UE 600 may be configured to support a means to derive the privacy protection identifier using the received privacy protection information.

[0158] In one embodiment, the privacy protection information comprises a subscriber permanent identifier restriction flag and a freshness parameter, which are used to derive the privacy protection identifier.

[0159] In one embodiment, the privacy protection identifier is associated with a SUPI for the UE and is used in place of the SUPI within the serving wireless network. In one embodiment, the serving wireless network comprises a PLMN, NPN, a PNIPNP, or a hosted NPN.

[0160] The processor 602 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 602 may be configured to operate the memory 604. In some other implementations, the memory 604 may be integrated into the processor 602. The processor 602 may be configured to execute computer-readable instructions stored in the memory 604 to cause the UE 600 to perform various functions of the present disclosure.

[0161] The memory 604 may include volatile or non-volatile memory. The memory 604 may store computer-readable, computer-executable code including instructions when executed by the processor 602 cause the UE 600 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 604 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place toanother. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0162] In some implementations, the processor 602 and the memory 604 coupled with the processor 602 may be configured to cause the UE 600 to perform one or more of the functions described herein (e.g., executing, by the processor 602, instructions stored in the memory 604). For example, the processor 602 may support wireless communication at the UE 600 in accordance with examples as disclosed herein.

[0163] The controller 606 may manage input and output signals for the UE 600. The controller 606 may also manage peripherals not integrated into the UE 600. In some implementations, the controller 606 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 606 may be implemented as part of the processor 602.

[0164] In some implementations, the UE 600 may include at least one transceiver 608. In some other implementations, the UE 600 may have more than one transceiver 608. The transceiver 608 may represent a wireless transceiver. The transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.

[0165] A receiver chain 610 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 610 may include one or more antennas for receiving the signal over the air or wireless medium. The receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 610 may include at least one demodulator configured to demodulate the received signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 610 may include at least one decoder for decoding and processing the demodulated signal to receive the transmitted data.

[0166] A transmitter chain 612 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) orquadrature amplitude modulation (QAM). The transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0167] Figure 7 illustrates an example of a processor 700 in accordance with aspects of the present disclosure. The processor 700 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 700 may include a controller 702 configured to perform various operations in accordance with examples as described herein. The processor 700 may optionally include at least one memory 704, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 700 may optionally include one or more arithmetic -logic units (ALUs) 706. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).

[0168] The processor 700 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 700) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).

[0169] The controller 702 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein. For example, the controller 702 may operate as a control unit of the processor 700, generating control signals that manage the operation of various components of the processor 700. These control signals include enabling ordisabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.

[0170] The controller 702 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 704 and determine subsequent instruction(s) to be executed to cause the processor 700 to support various operations in accordance with examples as described herein. The controller 702 may be configured to track memory address of instructions associated with the memory 704. The controller 702 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 702 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 702 may be configured to manage flow of data within the processor 700. The controller 702 may be configured to control transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 700.

[0171] The memory 704 may include one or more caches (e.g., memory local to or included in the processor 700 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 704 may reside within or on a processor chipset (e.g., local to the processor 700). In some other implementations, the memory 704 may reside external to the processor chipset (e.g., remote to the processor 700).

[0172] The memory 704 may store computer-readable, computer-executable code including instructions that, when executed by the processor 700, cause the processor 700 to perform various functions described herein. The code may be stored in a non- transitory computer-readable medium such as system memory or another type of memory. The controller 702 and / or the processor 700 may be configured to execute computer-readable instructions stored in the memory 704 to cause the processor 700 to perform various functions. For example, the processor 700 and / or the controller 702 may be coupled with or to the memory 704, the processor 700, the controller 702, and the memory 704 may be configured to perform various functions described herein. In some examples, the processor 700 may include multiple processors and the memory 704 may include multiple memories. One or more of the multiple processors may be coupledwith one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.

[0173] The one or more ALUs 706 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 706 may reside within or on a processor chipset (e.g., the processor 700). In some other implementations, the one or more ALUs 706 may reside external to the processor chipset (e.g., the processor 700). One or more ALUs 706 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 706 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 706 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 706 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 706 to handle conditional operations, comparisons, and bitwise operations.

[0174] The processor 700 may support wireless communication in accordance with examples as disclosed herein. In one embodiment, the processor 700 may be configured to or operable to support a means to transmit, to a serving wireless network, an indication that the UE is capable of identifier privacy protection for a serving network, receive, from the serving wireless network, privacy protection information for the UE, and determine a privacy protection identifier for the UE based on the privacy protection information received from the serving wireless network. In one embodiment, the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

[0175] In one embodiment, the processor 700 may be configured to or operable to support a means to determine whether the UE is capable of identifier privacy protection. In one embodiment, the processor 700 may be configured to or operable to support a means to transmit the indication as part of a NAS message, a registration request message, a security mode complete, or a registration update message.

[0176] In one embodiment, the processor 700 may be configured to or operable to support a means to transmit the indication as part of a UE security capabilitiestransmission. In one embodiment, the privacy protection identifier for the UE is received as part of the privacy protection information.

[0177] In one embodiment, the processor 700 may be configured to or operable to support a means to derive the privacy protection identifier using the received privacy protection information.

[0178] In one embodiment, the privacy protection information comprises a subscriber permanent identifier restriction flag and a freshness parameter, which are used to derive the privacy protection identifier.

[0179] In one embodiment, the privacy protection identifier is associated with a SUPI for the UE and is used in place of the SUPI within the serving wireless network.

[0180] In one embodiment, the processor 700 may be configured to or operable to support a means to receive an indication that a UE is capable of identifier privacy protection for a serving wireless network, receive a SUPI for the UE, and derive a privacy protection identifier associated with the SUPI for the UE for use in the serving wireless network. In one embodiment, the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

[0181] In one embodiment, the processor 700 is configured to check a privacy policy prior to deriving the privacy protection identifier to determine if SUPI exposure is restricted. In one embodiment, the processor 700 is configured to store the association between the SUPI and the privacy protection identifier and the UE.

[0182] The processor 700 may be configured to support a means to receive privacy protection information for a UE, determine a privacy protection identifier for the UE based on the privacy protection information, and provide the privacy protection identifier to the UE during a primary authentication procedure for use in a serving wireless network.

[0183] In one embodiment, the privacy protection information comprises the privacy protection identifier for the UE. In one embodiment, the processor 700 is configured to derive the privacy protection identifier using the received privacy protection information.

[0184] In one embodiment, the privacy protection information comprises a subscriber permanent identifier restriction flag and a freshness parameter, which are used to derive the privacy protection identifier.

[0185] In one embodiment, the privacy protection identifier is associated with a SUPI for the UE and is used in place of the SUPI within the serving wireless network. In one embodiment, the primary authentication procedure comprises an EAP-AKA’ procedure. In one embodiment, the primary authentication procedure comprises a 5G- AKA procedure. In one embodiment, the serving wireless network comprises a PLMN, NPN, a PNIPNP, or a hosted NPN.

[0186] Figure 8 illustrates an example of a NE 800 in accordance with aspects of the present disclosure. The NE 800 may include a processor 802, a memory 804, a controller 806, and a transceiver 808. The processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0187] The processor 802, the memory 804, the controller 806, or the transceiver 808, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0188] The NE 800 may be configured to support a means to receive an indication that a UE is capable of identifier privacy protection, receive a SUPI for the UE, and derive a privacy protection identifier associated with the SUPI for the UE for use in the serving wireless network. In one embodiment, the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

[0189] In one embodiment, the NE 800 is configured to check a privacy policy prior to deriving the privacy protection identifier to determine if SUPI exposure is restricted.In one embodiment, the NE 800 is configured to store the association between the SUPI and the privacy protection identifier and the UE.

[0190] The NE 800 may be configured to support a means to receive privacy protection information for a UE, determine a privacy protection identifier for the UE based on the privacy protection information, and provide the privacy protection identifier to the UE during a primary authentication procedure for use in a serving wireless network.

[0191] In one embodiment, the privacy protection information comprises the privacy protection identifier for the UE. In one embodiment, the NE 800 is configured to derive the privacy protection identifier using the received privacy protection information.

[0192] In one embodiment, the privacy protection information comprises a subscriber permanent identifier restriction flag and a freshness parameter, which are used to derive the privacy protection identifier.

[0193] In one embodiment, the privacy protection identifier is associated with a SUPI for the UE and is used in place of the SUPI within the serving wireless network. In one embodiment, the primary authentication procedure comprises an EAP-AKA’ procedure. In one embodiment, the primary authentication procedure comprises a 5G- AKA procedure. In one embodiment, the serving wireless network comprises a PLMN, NPN, a PNIPNP, or a hosted NPN.

[0194] The processor 802 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 802 may be configured to operate the memory 804. In some other implementations, the memory 804 may be integrated into the processor 802. The processor 802 may be configured to execute computer-readable instructions stored in the memory 804 to cause the NE 800 to perform various functions of the present disclosure.

[0195] The memory 804 may include volatile or non-volatile memory. The memory 804 may store computer-readable, computer-executable code including instructions when executed by the processor 802 causes the NE 800 to perform various functions described herein. The code may be stored in a non-transitory computer-readablemedium such the memory 804 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0196] In some implementations, the processor 802 and the memory 804 coupled with the processor 802 may be configured to cause the NE 800 to perform one or more of the functions described herein (e.g., executing, by the processor 802, instructions stored in the memory 804). For example, the processor 802 may support wireless communication at the NE 800 in accordance with examples as disclosed herein.

[0197] The controller 806 may manage input and output signals for the NE 800. The controller 806 may also manage peripherals not integrated into the NE 800. In some implementations, the controller 806 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 806 may be implemented as part of the processor 802.

[0198] In some implementations, the NE 800 may include at least one transceiver 808. In some other implementations, the NE 800 may have more than one transceiver 808. The transceiver 808 may represent a wireless transceiver. The transceiver 808 may include one or more receiver chains 810, one or more transmitter chains 812, or a combination thereof.

[0199] A receiver chain 810 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 810 may include one or more antennas for receiving the signal over the air or wireless medium. The receiver chain 810 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 810 may include at least one demodulator configured to demodulate the received signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 810 may include at least one decoder for decoding and processing the demodulated signal to receive the transmitted data.

[0200] A transmitter chain 812 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 812 may include at least one modulator for modulating data onto a carrier signal, preparing the signal fortransmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 812 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 812 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0201] Figure 9 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions.

[0202] At 902, the method may transmit, to a serving wireless network, an indication that the UE is capable of identifier privacy protection. The operations of 902 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 902 may be performed by a UE as described with reference to Figure 6.

[0203] At 904, the method may receive, from the serving wireless network, privacy protection information for the UE. The operations of 904 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 904 may be performed by a UE as described with reference to Figure 6.

[0204] At 906, the method may determine a privacy protection identifier for the UE based on the privacy protection information received from the serving wireless network. The operations of 906 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 906 may be performed by a UE as described with reference to Figure 6.

[0205] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0206] Figure 10 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by an NE asdescribed herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0207] At 1002, the method may receive an indication that a UE is capable of identifier privacy protection. The operations of 1002 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1002 may be performed by an NE as described with reference to Figure 8.

[0208] At 1004, the method may receive a subscription permanent identifier (SUPI) for the UE. The operations of 1004 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1004 may be performed by an NE as described with reference to Figure 8.

[0209] At 1006, the method may derive a privacy protection identifier associated with the SUPI for the UE for use in a serving wireless network. The operations of 1006 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1006 may be performed by an NE as described with reference to Figure 8.

[0210] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0211] Figure 11 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by an NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0212] At 1102, the method may receive privacy protection information for a UE. The operations of 1102 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1102 may be performed by an NE as described with reference to Figure 8.

[0213] At 1104, the method may determine a privacy protection identifier for the UE based on the privacy protection information. The operations of 1104 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1104 may be performed by an NE as described with reference to Figure 8.

[0214] At 1106, the method may provide the privacy protection identifier to the UE during a primary authentication procedure for use in a serving wireless network. The operations of 1106 may be performed in accordance with examples as described herein.In some implementations, aspects of the operations of 1106 may be performed by an NE as described with reference to Figure 8.

[0215] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0216] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

CLAIMSWhat is claimed is:1 . A user equipment (UE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the UE to: transmit, to a serving wireless network, an indication that the UE is capable of identifier privacy protection; receive, from the serving wireless network, privacy protection information for the UE; and determine a privacy protection identifier for the UE based on the privacy protection information received from the serving wireless network, wherein the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

2. The UE of claim 1, wherein the at least one processor is configured to cause the UE to determine whether the UE is capable of identifier privacy protection.

3. The UE of claim 1, wherein the at least one processor is configured to cause the UE to transmit the indication as part of a non-access stratum (NAS) message, a registration request message, a security mode complete, or a registration update message.

4. The UE of claim 1, wherein the at least one processor is configured to cause the UE to transmit the indication as part of a UE security capabilities transmission.

5. The UE of claim 1, wherein the privacy protection identifier for the UE is received as part of the privacy protection information.

6. The UE of claim 1, wherein the at least one processor is configured to cause the UE to derive the privacy protection identifier using the received privacy protection information.

7. The UE of claim 6. wherein the privacy protection information comprises a subscriber permanent identifier restriction flag and a freshness parameter, which are used to derive the privacy protection identifier.

8. The UE of claim 1, wherein the privacy protection identifier is associated with a subscription permanent identifier (SUPI) for the UE and is used in place of the SUPI within the serving wireless network.

9. The UE of claim 1, wherein the serving wireless network comprises a public land mobile network (PLMN), a non-public network (NPN), a public network integrated NPN (PNIPNP), or a hosted NPN.

10. A method performed by a user equipment (UE), the method comprising: transmitting, to a serving wireless network, an indication that the UE is capable of identifier privacy protection; receiving, from the serving wireless network, privacy protection information for the UE; and determining a privacy protection identifier for the UE based on the privacy protection information received from the serving wireless network, wherein the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

11. The method of claim 10, further comprising determining whether the UE is capable of identifier privacy protection.

12. The method of claim 10, further comprising transmitting the indication as part of a non-access stratum (NAS) message, a registration request message, a security mode complete, or a registration update message.

13. A network equipment (NE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the NE to: receive an indication that a user equipment (UE) is capable of identifier privacy protection;receive a subscription permanent identifier (SUPI) for the UE; and derive a privacy protection identifier associated with the SUPI for the UE for use in a serving wireless network, wherein the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

14. The NE of claim 13, wherein the at least one processor is configured to cause the NE to check a privacy policy prior to deriving the privacy protection identifier to determine if SUPI exposure is restricted.

15. The NE of claim 13, wherein the at least one processor is configured to cause the NE to store the association between the SUPI and the privacy protection identifier for the UE.

16. The NE of claim 13, wherein the at least one processor is configured to cause the NE to check a SUPI exposure policy for the serving wireless network to determine whether to derive the privacy protection identifier for the UE in the serving wireless network.

17. The NE of claim 13, wherein the serving wireless network comprises a public land mobile network (PLMN), a non-public network (NPN), a public network integrated NPN (PNIPNP), or a hosted NPN.

18. A method performed by a network equipment (NE), the method comprising: receiving an indication that a user equipment (UE) is capable of identifier privacy protection; receiving a subscription permanent identifier (SUPI) for the UE; and deriving a privacy protection identifier associated with the SUPI for the UE for use in a serving wireless network, wherein the privacy protection identifier for the UE is for authentication of the UE by the serving wireless network during communications.

19. The method of claim 18, further comprising checking a privacy policy prior to deriving the privacy protection identifier to determine if SUPI exposure is restricted.

20. The method of claim 18, further comprising storing the association between the SUPI and the privacy protection identifier for the UE.

Citation Information

Patent Citations

  • Providing UE capability information to an authentication server

    US20220159457A1

  • Management of user equipment security capabilities in communication system

    US20220201488A1

  • Using a pseudonym for access authentication over non-3GPP access

    US20230224704A1

  • Method and system of authentication and authorization in an msgin5g server

    WO2022149874A1