Methods and systems for managing user identity in wireless network

The SMF in wireless networks manages user identities by querying UDM to establish or reject PDU sessions, addressing multiple user scenarios and optimizing service access, thus enhancing user experience and resource management.

WO2025155132A1PCT designated stage expired Publication Date: 2025-07-24SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/001016
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-13
Filing Date
2025-01-17
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Existing wireless communication networks struggle to manage user identities effectively, particularly in scenarios where multiple users share a single device, leading to challenges in authentication, authorization, and service differentiation, which is crucial for providing enhanced user experiences and optimized performance.

Method used

Implementing a method where a Session Management Function (SMF) in a wireless communication system manages user identities by querying a Unified Data Management (UDM) to establish or reject PDU sessions based on user identifiers, ensuring only one user can access services at a time and prioritizing service requests according to configured policies.

Benefits of technology

This approach enhances user experience by ensuring secure, efficient management of user identities, allowing operators to provide differentiated services and optimize network resources, thereby supporting complex use cases like metaverse services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025001016_24072025_PF_FP_ABST
    Figure KR2025001016_24072025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A first SMF obtains a first PDU session request associated with a first user identifier, queries a UDM to obtain established PDU session information, receives, from the UDM, a response of no PDU session, establishes a first PDU session associated with the first user identifier, wherein a second PDU session request associated with a second user identifier is obtained by a second SMF, wherein the UDM is queried from the second SMF to obtain the established PDU session information, wherein a response of the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and wherein a second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND SYSTEMS FOR MANAGING USER IDENTITY IN WIRELESS NETWORK

[0001] Embodiments disclosed herein relate to wireless communication networks, and more particularly to systems and methods for managing a user identity in a wireless communication network.

[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.

[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.

[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.

[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.

[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.

[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.

[0008] In a first aspect of the disclosure, provided herein is a method performed by a first session management function (SMF) in a wireless communication system, the method comprising: obtaining a first protocol data unit (PDU) session request associated with a first user identifier; querying a unified data management (UDM) to obtain established PDU session information; receiving, from the UDM, a response of no PDU session; and establishing a first PDU session associated with the first user identifier, wherein a second PDU session request associated with a second user identifier is obtained by a second SMF, wherein the UDM is queried from the second SMF to obtain the established PDU session information, wherein a response of the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and wherein a second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.

[0009] In a second aspect of the disclosure, provided herein a first session management function (SMF) in a wireless communication system, the first SMF comprising: a transceiver; and at least one processor coupled to the transceiver and configured to: obtain a first protocol data unit (PDU) session request associated with a first user identifier, query a unified data management (UDM) to obtain established PDU session information, receive, from the UDM, a response of no PDU session, establish a first PDU session associated with the first user identifier, wherein a second PDU session request associated with a second user identifier is obtained by a second SMF, wherein the UDM is queried from the second SMF to obtain the established PDU session information, wherein a response of the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, and wherein a second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.

[0010] In a third aspect of the disclosure, provided herein a unified data management (UDM) in a wireless communication system, the UDM comprising: a transceiver; and at least one processor coupled to the transceiver and configured to: receive, from a first session management function (SMF), a first query to obtain established PDU session information, transmit, to the first SMF, a response of no PDU session, wherein a first PDU session associated with a first user identifier is established, receive, from a second SMF, a second query to obtain the established PDU session information, transmit, to the second SMF, a response of the first PDU session associated with the first user identifier, wherein a second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.

[0011] Embodiments herein are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the following illustrated drawings. Embodiments herein are illustrated by way of examples in the accompanying drawings, and in which:

[0012] FIG. 1 shows a schematic overview of a wireless network for managing user identifiers in a user equipment (UE), according to an embodiment of the disclosure;

[0013] FIG. 2 shows a flowchart for a method for managing the user identity for authentication of the user identifier in the wireless communication network, according to an embodiment of the disclosure;

[0014] FIG. 3 shows a flowchart for a method for managing the user identity for exempting authentication in the wireless communication network, according to an embodiment of the disclosure;

[0015] FIG. 4 is a sequence diagram depicting a method for managing user identifiers in the wireless communication networks, ensuring authentication, re-authentication and revocation for the user identifier, according to an embodiment of the disclosure;

[0016] FIG. 5 shows a block diagram of a wireless network for managing user identifiers in the UE, according to an embodiment of the disclosure;

[0017] FIG. 6 depicts a flowchart illustrating a method for managing user identities by restricting multiple users from using the UE simultaneously, according to an embodiment of the disclosure;

[0018] FIG. 7 depicts a flowchart illustrating a method for managing user identities by restricting multiple users from using the UE simultaneously, according to an embodiment of the disclosure;

[0019] FIG. 8 is a sequence diagram depicting a method for managing user identifiers in the wireless communication networks, for restricting multiple user identities to access service through a single device, according to an embodiment of the disclosure;

[0020] FIG. 9 shows a block diagram of a wireless network for managing user identifiers in the UE, according to an embodiment of the disclosure;

[0021] FIG. 10 depicts a flowchart illustrating a method for managing user identities by restricting multiple users from using the UE simultaneously, according to an embodiment of the disclosure;

[0022] FIG. 11 is a sequence diagram depicting a method for managing user identifiers in the wireless communication networks, during a UE mobility scenario between the AMF entities, according to an embodiment of the disclosure;

[0023] FIG. 12 and FIG. 13 show another block diagram of a wireless network for managing user identifiers in the UE, according to an embodiment of the disclosure; and

[0024] FIG. 14 shows an example sequence diagram as an example of managing multiple user identities in a wireless communication network, according to an embodiment of the disclosure.

[0025] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.

[0026] For the purposes of interpreting this specification, the definitions (as defined herein) will apply and whenever appropriate the terms used in singular will also include the plural and vice versa. It is to be understood that the terminology used herein is for the purposes of describing particular embodiments only and is not intended to be limiting. The terms "comprising", "having" and "including" are to be construed as open-ended terms unless otherwise noted.

[0027] The words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.,", "i.e.," are merely used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein using the words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.,", "i.e.," is not necessarily to be construed as preferred or advantageous over other embodiments.

[0028] Embodiments herein may be described and illustrated in terms of blocks which carry out a described function or functions. These blocks, which may be referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by a firmware. The circuits may, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments may be physically separated into two or more interacting and discrete blocks without departing from the scope of the disclosure. Likewise, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the disclosure.

[0029] It should be noted that elements in the drawings are illustrated for the purposes of this description and ease of understanding and may not have necessarily been drawn to scale. For example, the flowcharts / sequence diagrams illustrate the method in terms of the steps required for understanding of aspects of the embodiments as disclosed herein. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein. Furthermore, in terms of the system, one or more components / modules which comprise the system may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0030] The accompanying drawings are used to help easily understand various technical features and it should be understood that the embodiments are not limited by the accompanying drawings. As such, the disclosure should be construed to extend to any modifications, equivalents, and substitutes in addition to those which are particularly set out in the accompanying drawings and the corresponding description. Usage of words such as first, second, third etc., to describe components / elements / steps is for the purposes of this description and should not be construed as sequential ordering / placement / occurrence unless specified otherwise.

[0031] In general, by enhancing the Fifth Generation System (5GS) to allow for the creation and utilization of user-specific identities, operators will be able to provide enhanced user experience, optimized performance, and offer services to devices (e.g., user Equipment's (UEs)) and users that are not part of the operator's 3rdGeneration Partnership Project (3GPP) network. For example, network settings can be adapted and services can be offered to the users according to users' needs, different from the subscription identifier that is used by the user to establish the connection.

[0032] In the context of this work, the user to be identified could be an individual human user using the UE with a certain subscription, an application running on or connecting via the UE, or a device (e.g., a PIN Element (PINE)) behind a gateway UE (e.g., a PIN Element with Gateway Capability (PEGC)).

[0033] Use cases are thoroughly discussed and Key Issue (KIs) have been added to Technical Reports (TR) 23.700-32.

[0034] This key issue builds on the identifying human user case of key issue #1 and focuses on how users are authenticated and authorized and how the network restricts the user identifiers. Solutions to this key issue will address:

[0035] A. How are users authenticated and how and for what are users authorized; and

[0036] B. How the network restricts the usage of user identifiers, including in roaming scenarios.

[0037] Before providing and applying different policies for services based on the user identifier while accessing through a subscription (e.g. Subscription Permanent Identifier (SUPI)), a fifth generation core (5GC) network need to identify the user identifier and then authenticate and authorize it. Similarly, to strengthen the security and ensuring that the same user identifier is still availing the service, which had initiated the session, there is a need for the 5GC or the Application Function (AF) need to re-authenticate the user identifier and on need basic may revoke the access for the user identifier.

[0038] Further, the use cases are thoroughly discussed in TR 22.904 and include one or more users (i.e., humans) sharing one UE, and one or more users (i.e., devices) behind one gateway UE. The reason for utilizing operator user-specific identities in the 3GPP network is to allow the operator to charge and provide service differentiation based on the user identifier.

[0039] To address the requirement of providing user specific services in the case of multiple users shares the same device, the 3GPP has started to study in Release 19. The objectives of this study are not to move subscriber information into a user profile, and information from the user profile should not be used to override information in a subscription. For example, the slices and Data Network Names (DNNs) that are available to the UE do not change based on the user of the UE. Work Tasks focuses on supporting the use case where the user identifier of a human is associated with traffic that is to / from the UE.

[0040] Further, work task defines the architectural assumptions that are necessary to support identifying the user identifier that is associated with a UE's traffic.

[0041] Further, when the user identifier applies to a human, only a single user identifier is associated with the UE at the given time and it is assumed that the user identifier is associated with all of the services that the UE access during the time that the user identifier and UE are associated. If multiple users are associated with the device, the network cannot identify which services are used by which user.

[0042] Hence, there is a need in the art for solutions which will overcome the above mentioned drawback(s), among others.

[0043] The principal object of embodiments herein is to disclose systems and methods for managing user identifiers in a wireless communication network.

[0044] Another object of the embodiments herein is to disclose procedure for supporting authentication and authorization of user identities.

[0045] Another object of the embodiment herein is to address the scenario of how network successfully authenticate, re-authenticate the user identifier and revoke the access.

[0046] Another object of the embodiment herein is to disclose systems and methods for identifying a user using a 5G wireless device and restricting multiple users from using the device simultaneously, wherein the network ensures that at any point of time only one user identified by user profile id or some unique id is availing one or more services.

[0047] Yet, another object of the embodiment herein is to restrict multiple user identities accessing a service through a single device (e.g., single UE).

[0048] Yet, another object of the embodiment herein is to disclose that the SMF rejects the PDU session establishment if the another user is already getting the service from the network using the same UE, according to policy configured / received.

[0049] Yet, another object of the embodiment herein is to disclose that the SMF queries the UDM to know if another user had already established PDU before making a decision.

[0050] Yet, another object of the embodiment herein is to support of a metaverse service (for example) that will require the user validation by a 5GC.

[0051] Accordingly, the embodiments herein provide a method for managing a user identity in a wireless network. The method includes receiving, by a first session management function (SMF) entity, one of: a Protocol Data Unit (PDU) session request and a PDU session modification request from a User Equipment (UE). The PDU session request comprises a first user identifier (ID). The method further comprises obtaining, by the first SMF entity, a service priority information. The method further comprises determining, by the first SMF entity, whether the service priority information associated with the first user ID is important than a service priority information associated with a second user ID from a plurality of user IDs. In an embodiment of the disclosure, the method further comprises performing, by the first SMF entity, one of accepting one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE in response to determining that the service priority information associated with the first user profile ID is important than the service priority information associated with the second user profile ID by determining when one PDU is already present for the second user ID associated with the UE. In another embodiment, the method comprises rejecting one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE in response to determining that the service priority information associated with the first user profile ID is not important than the service priority information associated with the second user profile ID, by determining when the PDU is already present for the second user ID associated with the UE. In another embodiment of the disclosure, the method comprises accepting one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE when the first SMF entity does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID. In another embodiment of the disclosure, the method comprises rejecting one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE when a PDU session associated the with the second user profile ID is currently on-going by determining that the PDU session is already established for the second user ID associated with the UE.

[0052] Accordingly, the embodiments herein provide a method for managing a user identity in a wireless network. The method includes updating, by a first network entity, a UE context associated with a first user profile with a data storage entity. The UE context comprises at least one of: a user identity information, a profile information, and a subscription information, upon determining the first user profile associated with the UE is successfully authenticated and authorized, when the first user profile associated with the UE triggers at least one network access procedure for the first user. A second user associated with a second user profile is already authenticated by a second network entity. A UE context associated with the second user profile is already updated in the data storage entity by the second network entity.

[0053] Accordingly, the embodiments herein provide a method for managing a user identity in a wireless network, the method comprises receiving, by a first Access and Mobility Management Function (AMF) entity, one of: a Protocol Data Unit (PDU) session request and a PDU session modification request from a UE, wherein the PDU session request comprises a first user profile identifier (ID). The method further comprises obtaining, by the first AMF entity, a service priority information. The method further comprises determining, by the first AMF entity, whether the service priority information associated with the first user profile ID is important than a service priority information associated with a second user profile ID from a plurality of user profile IDs. The method further comprises performing, by the first AMF entity, one of: accepting one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE in response to determining that the service priority information associated with the first user profile ID is important than the service priority information associated with the second user profile ID when the PDU is already provided for the second user profile ID. In another embodiment of the disclosure, the method further comprises rejecting one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE in response to determining that the service priority information associated with the first user profile ID is not important than the service priority information associated with the second user profile ID, when the PDU is already provided for the second user profile ID. In another embodiment of the disclosure, the method further comprises accepting one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE when the first AMF entity does not consider the service priority information associated with the first user profile ID and the service priority information associated with the second user profile ID. In another embodiment of the disclosure, the method further comprises rejecting one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE when a PDU session associated the with the second user profile ID is currently on-going by verifying the PDU session is established for the second user profile ID associated with the UE.

[0054] Accordingly, the embodiments herein provide a method for managing a user identity in a wireless network. The method comprises receiving, by a SMF entity, a PDU session establishment request for a first user identifier from a UE. The method further comprises querying by the SMF entity, at least one data storage entity to retrieve a subscriber data information along with user identifier information associated with a subscription permanent identifier (SUPI) of the first user identifier of the UE. The method further comprises determining, by the SMF entity, whether an authentication for the first user identifier is enabled or disabled. The method further comprises obtaining, by the SMF entity, a subscriber data information from the at least one data storage entity along with the user identifier information associated with the SUPI when authentication for the first user identifier is enabled. The method further comprises querying, by the SMF entity, to obtain the information that the authentication result is not present for the first user identifier. The method further comprises triggering, by the SMF entity, authentication for the first user identifier.

[0055] Accordingly, the embodiments herein provide a first session management function (SMF) entity for managing a user identity in a wireless network, comprising a processor, a memory, and a user identity managing controller, coupled with the processor and the memory. The user identity managing controller is configured to receive, one of: a PDU session request and a PDU session modification request from a UE. The PDU session request comprises a first user identifier (ID). The user identity managing controller is further configured to obtain, a service priority information. The user identity managing controller is further configured to determine whether the service priority information associated with the first user ID is important than a service priority information associated with a second user ID from a plurality of user IDs. In an embodiment of the disclosure, the user identity managing controller is further configured to perform, one of accepting one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE in response to determining that the service priority information associated with the first user profile ID is important than the service priority information associated with the second user profile ID by determining when one PDU is already present for the second user ID associated with the UE. In an embodiment of the disclosure, the user identity managing controller is further configured to reject one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE in response to determining that the service priority information associated with the first user profile ID is not important than the service priority information associated with the second user profile ID, by determining when the PDU is already present for the second user ID associated with the UE. In an embodiment of the disclosure, the user identity managing controller is further configured to accept one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE when the first SMF entity does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID. In an embodiment of the disclosure, the user identity managing controller is further configured to reject one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE when a PDU session associated the with the second user profile ID is currently on-going by determining that the PDU session is already established for the second user ID associated with the UE.

[0056] Accordingly, the embodiments herein provide a first network entity for managing a user identity in a wireless network, comprising a processor, a memory, and a user identity manging controller, coupled with the processor and the memory. The user identity manging controller is configured to update, a UE context associated with a first user profile with a data storage entity. The UE context comprises at least one of: a user identity information, a profile information, and a subscription information, upon determining the first user profile associated with the UE is successfully authenticated and authorized, when the first user profile associated with the UE triggers at least one network access procedure for the first user. A second user associated with a second user profile is already authenticated by a second network entity. A UE context associated with the second user profile is already updated in the data storage entity by the second network entity.

[0057] Accordingly, the embodiments herein provide a first Access and Mobility Management Function (AMF) entity for managing a user identity in a wireless network, comprising a processor, a memory, and a user identity manging controller, coupled with the processor and the memory. The user identity manging controller is configured to receive, one of: a PDU session request and a PDU session modification request from a UE. The PDU session request comprises a first user identifier (ID). The user identity managing controller is further configured to obtain, a service priority information. The user identity managing controller is further configured to determine whether the service priority information associated with the first user ID is important than a service priority information associated with a second user ID from a plurality of user IDs. In an embodiment of the disclosure, the user identity managing controller is further configured to perform, one of accepting one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE in response to determining that the service priority information associated with the first user profile ID is important than the service priority information associated with the second user profile ID by determining when one PDU is already present for the second user ID associated with the UE. In an embodiment of the disclosure, the user identity managing controller is further configured to reject one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE in response to determining that the service priority information associated with the first user profile ID is not important than the service priority information associated with the second user profile ID, by determining when the PDU is already present for the second user ID associated with the UE. In an embodiment of the disclosure, the user identity managing controller is further configured to accept one of: the PDU session request and the PDU session modification request and sending a PDU session accept message to the UE when the first SMF entity does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID. In an embodiment of the disclosure, the user identity managing controller is further configured to reject one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE when a PDU session associated the with the second user profile ID is currently on-going by determining that the PDU session is already established for the second user ID associated with the UE.

[0058] Accordingly, the embodiments herein provide a SMF entity for managing a user identity in a wireless network, comprising a processor, a memory, and a user identity managing controller, coupled with the processor and the memory. The user identity managing controller is configured to receive a PDU session establishment request for a first user identifier from a user equipment (UE). The user identity managing controller is further configured query at least one data storage entity to retrieve a subscriber data information along with user identifier information associated with a subscription permanent identifier (SUPI) of the first user identifier of the UE. The user identity managing controller is further configured determine whether an authentication for the first user identifier is enabled or disabled. The user identity managing controller is further configured obtain a subscriber data information from the at least one data storage entity along with the user identifier information associated with the SUPI when authentication for the first user identifier is enabled. The user identity managing controller is further configured query to obtain the information that the authentication result is not present for the first user identifier. The user identity managing controller is further configured trigger authentication for the first user identifier.

[0059] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating at least one embodiment and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein without departing from the scope thereof, and the embodiments herein include all such modifications.

[0060] The embodiments herein achieve systems and methods for managing user identifiers in a wireless communication network.

[0061] In an embodiment of the disclosure, the SMF rejects PDU session establishment if the another user is already getting the service from the network using the same UE, according to policy configured / received. The SMF queries the UDM to know if another user had already established PDU before making a decision. The proposed method supports the metaverse services that will require the user validation by the 5GC.

[0062] In an embodiment of the disclosure, when a particular user invokes a particular application then the UE triggers PDU session establishment by providing the corresponding user identifier (e.g. first user (user1)) to the network. After successful authentication and authorization of the user identifier, the SMF entity queries with the UDM entity to check whether any PDU session is established with user identifiers. Upon getting response from UDM entity with no PDU Session, the SMF entity process the ongoing the PDU Session and then PDU Session is successfully established. The SMF entity stores this user identifier in the UDM along with PDU Session ID (PDU1).

[0063] In an embodiment of the disclosure, when a different user invokes another application (e.g. device is idle and the first user is not using the device) then the UE triggers a new PDU Session establishment by providing corresponding user identifier (e.g. User2 (second user)) to the network. If the same SMF is received the PDU Session which has handled the earlier PDU Session then the SMF entity can identify that already one user identifier has established PDU Session (first user). Then, the SMF entity rejects the PDU Session for the second user by providing a suitable cause code.

[0064] In an embodiment of the disclosure, if a different SMF receives the PDU Session then SMF first queries with UDM to check whether any PDU session is established with user identifiers. Upon getting response from UDM about already established PDU Session (e.g. PDU1) with user identifier first user, the SMF rejects the PDU Session for the second user by providing a suitable cause code.

[0065] In an embodiment of the disclosure, there can be some AF provided policy for user identifiers made available at the SMF entity (e.g. received from the UDM entity while getting SM Subscriber data, associated user identifiers details can be provided) which indicates the priorities among user identifiers while accessing service through the same subscription. If the policy indicates that the second user is having higher priority than the first user, then SMF accepts the PDU Session for the second user and provides indication to release the Session for the first user to UDM. UDM shall trigger the release of the PDU Session of the first user.

[0066] The proposed method helps for the operator to identify the actual user accessing the device (or the UE) to get the service from network and provide service differentiation based on the user identifier.

[0067] Referring now to the drawings, and more particularly to FIGS. 1 through 14, where similar reference characters denote corresponding features consistently throughout the figures, there are shown embodiments.

[0068] FIG. 1 shows a schematic overview of a wireless network (100) for managing user identifiers in a user equipment (UE) (102), according to an embodiment of the disclosure. The wireless network (100) can be, for example, but not limited to a fourth-generation wireless network, a fifth-generation wireless network, Open Radio Access Network (ORAN) or the like. The wireless network (100) includes one or more UEs (102), one or more network entities (NE) (104) and a data storage entity (106). The network entity (104) may include, but is not limited to a 5th generation evolved universal terrestrial radio access networks (5G / EUTRAN) Core Network Entities including Access and mobility management function (AMF) entity, session management function (SMF) entity, mobility management entity (MME) entity and a user plane function (UPF) entity. The wireless network may include (5G / EUTRAN) RAN entity comprising eNodeB (eNB), gNodeB (gNB), and NG-RAN. The UE (102) may be, for example, but not limited to a laptop, a smart phone, a desktop computer, a notebook, a Device-to-Device (D2D) device, a vehicle to everything (V2X) device, a foldable phone, a smart TV, a tablet, a television, a connected car, an immersive device, an internet of things (IOT) device, or any other device that can communicate using the wireless network.

[0069] In an embodiment of the disclosure, the data storage entity (106) may include at least one of a Unified Data Management (UDM), a User Data Repository (UDR), Application Function (AF) entity, and a Network Function (NF) entity.

[0070] In an embodiment of the disclosure, the network entity (104) may include one or more network entities. The network entity (104) may include but is not limited to a first SMF entity (110), a second SMF entity (115), a first AMF entity (120), and a second AMF entity (125).

[0071] In an embodiment of the disclosure, the data storage entity (106) may have already received a user identifier information associated with the SUPI of the UE (102) for a particular service, stored as a subscriber data information associated with the subscription permanent identifier (SUPI). The user identifier information comprises details of an authentication and authorization for each of the user identifier is enabled or disabled per service.

[0072] Consider the scenario where some user identifiers are configured in the user equipment (UE) (102), for example a first user and a second user. When the UE (102) is registering with the network with a particular user identifier then the network needs to authenticate the user identifiers before the network entity (104). The network entity (104) for example the AMF entity (at least one of the first AMF entity (120) or the second AMF entity (125)). Now assuming only first AMF entity (120) is used in this scenario, the first AMF (120) may receive a PDU session request from the first user. The first AMF entity (120) may query the data storage entity (106) for the subscriber data information along with user identifier information associated with a subscription permanent identifier (SUPI) of the first user identifier of the UE (102). The first AMF entity (120) may determine whether an authentication for the first user identifier is enabled or disabled. The first AMF entity (120) may query the data storage entity (106) to obtain the information that the authentication result is either present or absent for the first user identifier. The first AMF entity (120) may trigger authentication for the first user identifier, if the authentication result of first identifier is absent, however authentication for the first identifier is enabled. The network entity (104) allows the user identifiers to avail the service from the network. In an embodiment of the disclosure, when UE (102) register with the network and the UE (102) provides all the user identifiers then 5GC triggers authentication for all the user identifiers if the Access and Management Function (AMF) entity have the user profile information for each of the user identifiers which allows the user identifier to avail the service using the particular subscription.

[0073] In an embodiment of the disclosure, there may be some user identifiers are exempted from the authentication. Based on the subscription information received from the data storage entity (106), the first AMF entity (120) may trigger authentication only for some specific user identifier. In an embodiment of the disclosure, when user identifiers are configured on the UE (102), then the UE (102) shall store the authentication credential for the respective user identifiers so that the device can send the credentials when network triggers authentication for the user identifiers.

[0074] In an embodiment of the disclosure, (the SMF entity (either one of the first SMF entity (110) or the second SMF entity (115))) assuming that the first SMF entity (110) receives the user identifier from the UE (102). The first SMF entity (110) checks with the data storage entity (106) if the first SMF entity (110) have the user profile information for user identifiers which allows the user identifier to avail the service using the particular subscription is enabled. The first SMF entity (110), triggers the authentication for the user identifiers even when particular user identifier is started availing the service.

[0075] In an embodiment of the disclosure, based on the authentication approach (before session establishment by the AMF entity (120, 125) or during session establishment by the SMF entity (110, 115)), the network entity (104) determines that no user identifiers are present in the request received from UE (102). If no user identifiers are present, then the network entity (104) retrieves the subscriber data information from the data storage entity (106). The subscriber data information may be having user identifier information associated with SUPI of the UE (102). If the subscriber data information is available in the data storage entity (106), the network entity (104) shall use the default subscriber data information present in the data storage entity (106) for the SUPI without considering the user identifier information.

[0076] In an embodiment of the disclosure, it is proposed that based on the authentication approach (before session establishment by the AMF entity (120, 125) or during session establishment by the SMF entity (110, 115)), if the network entity (104) finds that no user identifiers are present in the request received from UE (102) and the subscriber data information received from data storage entity (106) is having user identifier information associated with SUPI, then the network entity (104) shall send the request back to UE (102) informing to add / share the user identifier. The UE (102) subsequently will add the user identifier to the network.

[0077] In an embodiment of the disclosure, it is proposed that some user identifiers are exempted from the authentication which means based on the subscription information from the data storage entity (106), the network entity (104) (first SMF entity (110)) may trigger authentication only for some specific user identifier. In this case, it is not mandatory for user identifiers configured in the UE (102) to store the authentication credential as the user itself can provide the credential during authentication.

[0078] In an embodiment of the disclosure, it is proposed that the user identifier authentication result (if done) by the first AMF entity (120) is shared to target AMF entity i.e. the second AMF entity (125) in AMF entity change scenario so that each timer user identifiers are not authenticated. Similarly, if it is done by the SMF entity (110) then the first SMF entity (110) shall store the authentication to give exemption for the same user identifier if another Protocol Data Unit (PDU) session is received by the same first SMF entity (110). In case of different SMF entity, for example, the user is authenticated over first SMF entity (110) for the UE (102), and a second user requests for the PDU session from the same UE (102) on the second SMF entity (115), then the first SMF entity (110) already updates the authentication result in data storage entity (106) (UE_CM_Register or UE_CM_Update service operation). When the first SMF entity (110) receives any PDU session for one user identifier then first it fetches the authentication result from the data storage entity (106). If received successful result then the first SMF entity (110) does not again trigger the authentication. In the subsequent attempt, the authentication from the data storage entity (106) is fetched by the second SMF entity (115) before triggering the authentication for the second user identifier on the second SMF entity (115).

[0079] In an embodiment of the disclosure, the network entity (104) may trigger re-authentication of the user identifier. In case of the re-authentication is failed then based on AF / operator policy, the active sessions (if any) may be released. The user identifier may have multiple active sessions using different subscription. If re-authentication is failed while executing for a particular subscription then based on AF / operator policy, the session using that specific subscription may be released or all the subscription will be released.

[0080] In an embodiment of the disclosure, consider a scenario the UE (102) is already registered, and one of the user identifiers having the user profile id or some unique id (for example, first user identifier) allows the user to avail the service from the network upon successful authentication and authorization of the user. For example, the first SMF entity (110) has successfully authenticated and authorized the user. The first SMF entity (110) updates the data storage entity (106) during PDU session establishment or after successful establishment, with the UE context having additional information of the user identifier associated with the user using Nudm_UECM_Create service operation. When another user with a different user profile id (for example, second user identifier) initiates a PDU session and the request reaches the same first SMF entity (110) (which has already having UE SM context information), the first SMF entity (110) may determine that one user (the first user identifier) is already availing the service. Then, the first SMF entity (110) may reject the PDU session for the second user identifier with a suitable cause code to the UE (102). The first SMF entity (110) further proceeds with authentication and authorization of the second user identifier only when the second user identifier is allowed to establish the PDU session, based on the user authentication information from the data storage entity (106) that no other user is availing any service or there is no active ongoing PDU session on the UE (102) by another user identifier on any of the SMF entities, otherwise if the PDU session establishment request is rejected, then the authentication and authorization can be skipped.

[0081] In an embodiment of the disclosure, the SMF entity (the first SMF entity (110) or the second SMF entity (115), assuming that the first SMF entity (110) has received a PDU session establishment request from the user). The first SMF entity (110) may check a priority information associated with all the user identifiers associated with the UE (102). The SMF entity (110) may download only the user identifier information related to the user identifier requesting the PDU session. In an embodiment of the disclosure, the SMF entity (110) may download all the user identifier information from the data storage entity (106). The user identifier information may be stored in the data storage entity (106) or may be stored in local configurations available with the first SMF entity (110). These priority information per user profile for one UE (102) may be configured by the operator or the third party that provide the user identities. When the first user identifier is already availing of the service on the UE (102), and the second user identifier requests a PDU session establishment on the first SMF entity (110), the first SMF entity (110) checks the priority information of the first user identifier and the second user identifier. The first SMF entity (110) obtains that the second user identifier (the one initiated the new PDU session) has a high priority in comparison to the first user identifier, then the existing PDU of the first user identifier can be released and a new PDU session for the second user identifier can be accepted on the first SMF entity (110) by determining when the PDU is already present for the user identifier associated with the UE (102).

[0082] In an embodiment of the disclosure, consider that the first user identifier of the UE (102) has the PDU session established and availing service through the first SMF entity (110). The second PDU session request from the second user identifier from the same UE (102) reaches a second SMF entity (115) (different than the SMF which handled the first PDU session from the first user identifier). The second SMF entity (115) may not have any context information for the UE (102) and cannot know whether the first user identifier has any established PDU session on any other SMF entity. In this case, the second SMF entity (115) queries the data storage entity (106) to know about any existing PDU sessions on the UE (102) by sending a Nudm_UECM_Get operation. The second SMF entity (115) may receive information from the data storage entity (106) that the first user identifier is having the active PDU session with the UE (102) with the first SMF entity (110). Then, the second SMF (115) can apply all the logic as proposed for the same SMF scenario. The second SMF entity (115) may determine that the first user identifier is already availing the service on the first SMF entity (110). Then, the second SMF entity (115) may reject the PDU session with a suitable cause code to the UE (102). The decision of allowing or rejecting new PDU sessions and releasing or retaining the existing PDU session can be a part of operator policy, or a third party can provision the policy for the case, where user identifiers are provided by them.

[0083] In an embodiment of the disclosure, instead of the SMF entity determining to allow or reject the PDU sessions from second user identifier, and release or retain the first PDU session of the first user identifier, the data storage entity (106) may be the anchor network function (NF). Here, when the first SMF entity (110) handling the second user receives a PDU session and sends a Nudm_UECM_Create service operation to add the user identifier to the data storage entity (106), the data storage entity (106) may determine on how to treat the new PDU session of the second user identifier and old PDU of the first user identifier as explained for the same SMF scenario. If the data storage entity (106) has to reject the PDU session for the second user identifier in case of an ongoing PDU session on the first SMF entity (110) by the first user, then the data storage entity (106) can trigger one reject message to the second SMF entity (115) with suitable cause code. The second SMF entity (115) may reject the PDU session with suitable cause code. If the data storage entity (106) (based on the available operator or third party policy) decides to accept the PDU session of the second user identifier, then the data storage entity (106) sends a release message to the first SMF entity (110) for the first user identifier with a suitable cause code. The first SMF entity (110) released the PDU session for first user identifier with suitable cause code.

[0084] The messages used or indicated in this embodiment are shown as an example. The messages could be any signaling messages between UE (102) and the Network Functions / Entities (104) or between different Network functions / entities (104).

[0085] Similarly, the service operation name given in the disclosure is illustration purposes only. Any other name can be used to convey the information.

[0086] FIG. 2 shows a flowchart for a method (200) for managing the user identity for authentication of the user identifier in the wireless communication network (100), according to an embodiment of the disclosure. At step 202, the SMF entity (220) (for example) receives the Protocol Data Unit (PDU) session establishment request for the first user identifier from the UE (102). At step 204, the SMF entity (220) queries the data storage entity (106) to retrieve the subscriber data information along with user identifier information associated with a subscription permanent identifier (SUPI) of the first user identifier of the UE (102). At step 206, the SMF entity (220) determines whether an authentication for the first user identifier is enabled or disabled, based on the subscriber data information along with user identifier information associated with the SUPI. The SMF entity (220) obtains the subscriber data information from the at least one data storage entity (106) along with the user identifier information associated with the SUPI when authentication for the first user identifier is enabled, at step 208, the SMF entity (220) again queries the data storage entity (106), to obtain the information that the authentication result is present or absent for the first user identifier. At step 210, if the authentication result is absent and the authentication for the first user identifier is enabled, the SMF entity (220) triggers authentication for the first user identifier. At step 212, if the authentication for the first user identifier is disabled, the SMF entity (220) may not trigger the authentication for the first user identifier. In an embodiment of the disclosure, the SMF entity (220) skips the authentication when the authentication for the first user identifier is disabled. In an embodiment of the disclosure, the SMF entity (220) skips the authentication when the authentication result is already present in the data storage entity (106) for the first user identifier, or the user identifier requesting PDU session.

[0087] The various actions in method (200) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 2 may be omitted.

[0088] FIG. 3 shows a flowchart for a method (300) for managing the user identity for exempting authentication in the wireless communication network (100), according to an embodiment of the disclosure. At step 302, the SMF entity (220) (for example) receives another PDU session establishment request for a second user identifier from the UE (102) for availing a service. At step 304, the SMF entity (220) queries the data storage entity (106) to retrieve a subscriber data information along with user identifier information associated with a subscription permanent identifier (SUPI) of the second user identifier of the UE (102). At step 306, the SMF entity (220) determines whether the authentication for the second user identifier is enabled or disabled, based on the subscriber data information along with user identifier information associated with the SUPI. The SMF entity (220) determines, for example, that the user identifier authentication for the second user identifier is enabled and an authentication for the received service request is exempted. At step 308, the SMF entity (220) avoids to trigger the authentication for the second user identifier based on the determination that the authentication for the received service is exempted. In an embodiment of the disclosure, the SMF entity (220) skips the authentication when the authentication for the user identifier requesting PDU session is disabled.

[0089] The various actions in method (300) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 3 may be omitted.

[0090] FIG. 4 is a sequence diagram depicting a method (400) for managing user identifiers in the wireless communication networks (100), ensuring authentication, re-authentication and revocation for the user identifier, according to an embodiment of the disclosure. At step 402, the data storage entity (106) may receive the associated user identifier information for the SUPI or the user identifier information is configured at the subscriber data in the data storage entity (106). The user identifier information and subscriber data information include details like whether authentication is enabled or disabled per user identifier. If the authentication is enabled for the user identifier then if the authentication is enabled then per service. At step 404, the first UE (102) sends a PDU Session Establishment for the first user identifier. For example, the UE (102) is being used by the first user identifier, or an application is invoked on the UE (102), and the first user is configured in the application. At step 406, the SMF entity (220) gets subscriber data information from the data storage entity (106) along with user identifier information associated with the SUPI. The SMF entity (220) determines that user identifier authentication for the first user is enabled. At step 408, the SMF entity (220) again queries the data storage entity (106) for the authentication result of the first user identifier, and obtains information that authentication result for first user identifier is not present. At step 410, the SMF entity (220) triggers authentication for the first user identifier.

[0091] In an embodiment of the disclosure, at step 412, the second user identifier sends a PDU Session Establishment for a service (for example, to make one IMS call). For example, the same UE (102) is being used by the second user identifier, or another application is invoked on the UE (102), and the second user is configured in the application. At step 414, the SMF entity (220) gets subscriber data information from the data storage entity (106) along with user identifier information associated with the SUPI. The SMF entity (220) determines that the user identifier authentication for second user identifier is enabled but the user identifier authentication for the service requested is disabled (for example, IMS DNN) the authentication is exempted. At step 416, based on the authentication exempted for the requested service, the SMF entity (220) does not trigger user identifier authentication for the second user identifier.

[0092] The SMF entity receives the re-authentication request from an Application Function (AF). Based on the re-authentication request, the SMF entity triggers the authentication for the first user identifier by sending the authentication request to the UE.

[0093] In an embodiment of the disclosure, the SMF entity receives a revocation message from an Application Function (AF). Based on the revocation message, the SMF entity terminates the already established PDU sessions associated with the first user identifier by providing suitable cause code.

[0094] The various actions in method (400) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 4 may be omitted.

[0095] FIG. 5 shows a block diagram of a wireless network (100) for managing user identifiers in the UE (102), according to an embodiment of the disclosure. In an embodiment of the disclosure, the network entity (104) may include the SMF entity (220). The SMF entity (220) may include but is not limited to a processor (502), a memory (504), a user identity managing controller (508), and a transceiver (506). The user identity managing controller (508) coupled with the processor (502), the memory (504), and the transceiver (506). The SMF entity (220) may be in communication with the UE (102) and the data storage entity (106) through the transceiver (506). In an embodiment of the disclosure, the UE (102) includes a controller (512) and a transceiver (510). The controller (512) communicates to the SMF entity (220) through the transceiver (510). The wireless network may include, but is not limited to, a plurality of network entities available in a network coverage area of the UE. The first network entity, second network entity, first SMF entity, second SMF entity, are used for illustrative purposes only.

[0096] The memory (504) is configured to store instructions to be executed by the processor (502). The memory (504) can include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (504) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory is non-movable. In some examples, the memory (504) is configured to store larger amounts of information. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0097] The processor (502) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (502) may include multiple cores and is configured to execute the instructions stored in the memory (504).

[0098] In an embodiment of the disclosure, the transceiver (506) includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver (506) is configured to communicate internally between internal hardware components of the UE (102) and with external devices via one or more networks.

[0099] In an embodiment of the disclosure, the user identity managing controller (508) identifies, authenticates and re-authenticates the user before availing any service from the network.

[0100] FIG. 6 depicts a flowchart illustrating a method (600) for managing user identities by restricting multiple users from using the UE (102) simultaneously, according to an embodiment of the disclosure. The embodiment herein discloses a same SMF entity scenario. The operations 602-622 are handled by the user identity managing controller (508). At step 602, the first SMF entity (110) receives one of: the PDU session request and the PDU session modification request from the UE (102) associated with the first user identifier (ID).

[0101] At step 604, the first SMF entity (110), queries the data storage entity (106) to retrieve a subscriber data information along with user identifier information of the first user identifier or another user identifier associated with the UE (102) having active ongoing PDU session.

[0102] At step 606, the first SMF entity (110) determines information about whether there is presence of the PDU session associated with the second user identifier of the UE (102) or any other user identifier is having an ongoing PDU session with the UE based on a local policy.

[0103] At step 608, the first SMF entity (110) obtains a service priority information of the first user identifier. The first SMF entity (110) obtains the service priority information from the data storage entity (106) while downloading the subscription information as part of processing the PDU request or obtains the service priority information from the AMF entity (120 or 125).

[0104] At step 610, the first SMF entity (110) determines whether the service priority information associated with the first user ID is important than a service priority information associated with a second user ID from a plurality of user IDs.

[0105] At step 612, upon determining that the service priority information associated with the first user profile ID is important than the service priority information associated with the second user profile ID and upon determining one PDU is already present for the second user ID associated with the UE (102), the first SMF entity (110), accepts the one of: the PDU session request and the PDU session modification request. The PDU session is accepted as the priority of the first user ID is more than the second user ID irrespective of any ongoing PDU session is associated with the UE (102), with any user identifiers on any of the SMF entity. The SMF entity (110) sends a PDU session accept message to the UE (102) in response to the PDU session accepted.

[0106] In an embodiment of the disclosure, at step 614, the first SMF entity (110) releases the ongoing PDU session from the second user identifier of the UE (102), in order to establish a new PDU session with the first user identifier of the UE (102).

[0107] In an embodiment of the disclosure, at step 616, upon determining that the service priority information associated with the first user profile ID is not important than the service priority information associated with the second user profile ID, by determining when the PDU is already present for the second user ID associated with the UE (102), the first SMF entity (110) rejects one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE (102) in response to the rejection of the PDU session.

[0108] In an embodiment of the disclosure, at step 618, upon determining that there is no other user ID with the ongoing PDU session with the UE (102), the first SMF entity (110) accepts one of: the PDU session request and the PDU session modification request when the first SMF entity (110) does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID. The first SMF entity (110) sends a PDU session accept message to the UE (102).

[0109] In an embodiment of the disclosure, at step 620, upon determining that a PDU session associated the with the second user profile ID is currently on-going by determining that the PDU session is already established for the second user ID associated with the UE (102) and when the first SMF entity (110) does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID, the first SMF entity (110) rejects one of: the PDU session request and the PDU session modification request. The first SMF entity (110) sends a PDU session reject message with a cause code to the UE (102) upon rejecting the PDU session of the first user ID.

[0110] At step 622, the first SMF entity (110) updates a UE context in a data storage entity (106) with at least one information associated with the first user profile ID during at least one of: a PDU session establishment and after a successful establishment of the PDU session. The first SMF entity (110) updates a UE context in the data storage entity (106) with at least one information associated with the second user profile ID during at least one of: the PDU session establishment and after the successful establishment of the PDU session. In an embodiment of the disclosure, the first SMF entity (110) updates a UE context in a data storage entity (106) with the at least one information of the user profile ID using at least one of: a Nudm_UECM_Create service operation and a Nudm_UECM_Update service operation.

[0111] In an embodiment of the disclosure, upon accepting the one of: the PDU session request and the PDU session modification request, the first SMF entity (110) allows authentication and authorization of the first user identifier on the first SMF entity (110).

[0112] In an embodiment of the disclosure, while accepting one of: the PDU session request and the PDU session modification request and sending the PDU session accept message to the UE, the SMF entity releases the PDU session already present for the second user ID associated with the UE. In an embodiment of the disclosure, while accepting one of: the PDU session request and the PDU session modification request and sending the PDU session accept message to the UE, the SMF entity releases the UE context associated with the second user ID.

[0113] The various actions in method (600) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 6 may be omitted.

[0114] FIG. 7 depicts a flowchart illustrating a method (700) for managing user identities by restricting multiple users from using the UE (102) simultaneously, according to an embodiment of the disclosure. The embodiment herein discloses a two different SMF entity scenario. At step 702, the second SMF entity (115), receives one of: another PDU session request and another PDU session modification request from the UE (102) associated with the second user identifier.

[0115] At step 704, the second SMF entity (115) queries the data storage entity (106) to determine if the second user or any user having the PDU session with the UE (102) is already associated with the UE (102) via the current PDU session or the another PDU session.

[0116] At step 706, the second SMF entity (115) receives, information about presence of the PDU session associated with the first user of the UE (102) or the user having the PDU session with the first SMF entity (110) based on a local policy.

[0117] At step 708, the second SMF entity (115) rejects one of: the another PDU session request and another PDU session modification request from the UE (102) with the second user with a cause-code, on receiving information about presence of the PDU session associated with the first user of the UE (102) or the user having the PDU session with the UE (102).

[0118] At step 710, the second SMF entity (115) accepts one of: the another PDU session request and another PDU session modification request from the UE (102) in case no ongoing PDU session for the UE (102) is received by the second SMF entity (115).

[0119] In an embodiment of the disclosure, the second SMF entity (115) may check a priority information associated with all the user identifiers associated with the UE (102). The second SMF entity (115) may download only the user identifier information related to the user identifier requesting the PDU session. In an embodiment of the disclosure, the second SMF entity (115) may download all the user identifier information from the data storage entity (106). The user identifier information may be stored in the data storage entity (106) or may be stored in the local configurations available with SMF entities (220). These priority information per user identifier for one UE (102) may be configured by the operator or the third party that provide the user identities. When the first user identifier is already availing of the service on UE (102), and the second user identifier requests a PDU session establishment, the SMF entity (220) checks the priority information of the first user identifier and the second user identifier. The SMF entity (220) obtains that the second user identifier (the one initiated the new PDU session) has a high priority in comparison to the first user identifier, then the existing PDU of the first user identifier can be released and the new PDU session for the second user identifier can be accepted.

[0120] In an embodiment of the disclosure, upon accepting the one of: the PDU session request and the PDU session modification request, the AMF entity (125) allows authentication and authorization of the second user identifier on the second SMF entity (115).

[0121] In an embodiment of the disclosure, the first SMF entity (110) receives the PDU session request from the UE (102) via a first Access and Mobility Management Function (AMF) entity (120). The second SMF entity (115) receives the another PDU session request from the UE (102) via a second AMF entity (125). In an embodiment of the disclosure, the first AMF entity (120) and the second AMF entity (125) are same. In an embodiment of the disclosure, the first AMF entity (120) and the second AMF entity (125) are different.

[0122] The various actions in method (700) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 7 may be omitted.

[0123] FIG. 8 is a sequence diagram depicting a method (800) for managing user identifiers in the wireless communication networks (100), for restricting multiple user identities to access service through a single device, according to an embodiment of the disclosure. At step 802, the UE (102) has already registered to the network. The UE (102) has profiles of first user identifier and second user identifier configured locally. At step 804, the UE (102) sends the PDU session establishment or the PDU session modification request (or a new non-access stratum (NAS) message) to initiate authentication and authorization of the first user identifier. In an embodiment of the disclosure, the PDU session request may be routed to the first SMF entity (110) by the AMF entity. At step 806, the first SMF entity (110) checks with the data storage entity (106), if any other user identifier is already associated with the UE (102) via the same or another PDU Session. Consider that, the UDM returns a negative response indicating that no other user is associated with the UE (102). At step 808, authentication, and authorization of first SMF entity (110) takes place. At step 810, the first SMF entity (110) updates the data storage entity (106) indicating first user identifier is using the UE (102) via a specific PDU Session. At step 812, consider that a new user (second user identifier) starts using the UE (102) and triggers the authentication and authorization procedure (similar to step 804), the PDU session request is handled by the second SMF entity (115). At step 814, the second SMF entity (115) queries the data storage entity (106) to check if any other user identifier is already associated with the UE (102) via the same or another PDU Session. The data storage entity (106) informs the second SMF entity (115) that another user (the first user identifier) is associated with the UE (102) and has an active ongoing PDU session. At step 816, based on local policy, the second SMF entity (115) may now reject the request from the UE (102) to authenticate the second user identifier, by rejecting the PDU Session establishment or a PDU session modification request, with a suitable cause-code.

[0124] In an embodiment of the disclosure, instead of the SMF entity or the data storage entity, the AMF can be the anchor network function to apply the logic to allow or reject the PDU session from the second user identifier and release or retain the first ongoing PDU session.

[0125] The various actions in method (800) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 8 may be omitted.

[0126] FIG. 9 shows a block diagram of a wireless network (100) for managing user identifiers in the UE (102), according to an embodiment of the disclosure. In an embodiment of the disclosure, the network entity (104) may include the first SMF entity (110) and the second SMF entity (115). The first SMF entity (110) may include but is not limited to a processor (902), a memory (904), a user identity managing controller (908), and a transceiver (906). The user identity managing controller (908) coupled with the processor (902), the memory (904), and the transceiver (906). The first SMF entity (110) may be in communication with the UE (102) and the data storage entity (106) through the transceiver (906). The second SMF entity (115) may include but is not limited to a processor (920), a memory (922), a user identity managing controller (926), and a transceiver (924). The user identity managing controller (926) coupled with the processor (920), the memory (922), and the transceiver (924). The second SMF entity (115) may be in communication with the UE (102) and the data storage entity (106) through the transceiver (924).

[0127] In an embodiment of the disclosure, the UE (102) includes a controller (910) and a transceiver (912). The controller (910) communicates to the first SMF entity (110) and the send SMF entity (115) through the transceiver (912). The wireless network may include, but is not limited to, a plurality of network entities available in a network coverage area of the UE.

[0128] The memory (904) and is configured to store instructions to be executed by the processor (902). The memory (904) can include non-volatile storage elements. The memory (922) and is configured to store instructions to be executed by the processor (920). The memory (922) can include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memories (904 and 922) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory is non-movable. In some examples, the memories (904 and 922) are configured to store larger amounts of information. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0129] The processor(s) (902 and 920) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (902) include multiple cores and is configured to execute the instructions stored in the memory (904). In an embodiment of the disclosure, the processor (920) include multiple cores and is configured to execute the instructions stored in the memory (922).

[0130] In an embodiment of the disclosure, the transceiver (906) includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver (906) is configured to communicate internally between internal hardware components of the UE (102) and with external devices via one or more networks.

[0131] In an embodiment of the disclosure, the transceiver (924) includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver (924) is configured to communicate internally between internal hardware components of the UE (102) and with external devices via one or more networks.

[0132] In an embodiment of the disclosure, the user identity managing controller (908 or 926) identifies, authenticates and re-authenticates the user before availing any service from the network.

[0133] FIG. 10 depicts a flowchart illustrating a method (1000) for managing user identities by restricting multiple users from using the UE (102) simultaneously, according to an embodiment of the disclosure. The embodiment herein discloses an AMF entity scenario. At step 1002, the first AMF entity (120) receives one of: the PDU session request and the PDU session modification request from the UE (102) from the first user identifier (ID).

[0134] At step 1004, the first AMF entity (120), checks from the available subscription information and associated user identifiers that are downloaded during registration procedure of the second user trying to avail a service from the subscription.

[0135] At step 1006, the first AMF entity (120) determines information about whether there is presence of the PDU session associated with the second user identifier of the UE (102) or any other user identifier is having an ongoing PDU session with the UE (102) based on the local policy.

[0136] At step 1008, the first AMF entity (120) obtains the service priority information of the first user identifier. The first SMF entity (110) obtains the service priority information from the data storage entity (106) while downloading the subscription information as part of processing the PDU request or obtains the service priority information from the AMF entity (125).

[0137] At step 1010, the first AMF entity (120) determines whether the service priority information associated with the first user ID is important than the service priority information associated with the second user ID from the plurality of user IDs.

[0138] At step 1012, upon determining that the service priority information associated with the first user profile ID is important than the service priority information associated with the second user profile ID and upon determining one PDU is already present for the second user ID associated with the UE (102), the first AMF entity (120), accepts the one of: the PDU session request and the PDU session modification request. The PDU session is accepted as the priority of the first user ID is more than the second user ID irrespective of any ongoing PDU session is associated with the UE (102), with any user identifiers on any of the AMF entity. The first AMF entity (120) sends a PDU session accept message to the UE (102) in response to the PDU session accepted.

[0139] At step 1014, the first AMF entity (120) releases the ongoing PDU session from the second user identifier of the UE (102), in order to establish a new PDU session with the first user identifier of the UE (102).

[0140] At step 1016, upon determining that the service priority information associated with the first user profile ID is not important than the service priority information associated with the second user profile ID, by determining when the PDU is already present for the second user ID associated with the UE (102), the first AMF entity (120) rejects one of: the PDU session request and the PDU session modification request and sending a PDU session reject message with a cause code to the UE (102) in response to the rejection of the PDU session.

[0141] At step 1018, upon determining that there is no other user ID with the ongoing PDU session with the UE (102), the first AMF entity (120) accepts one of: the PDU session request and the PDU session modification request when the first AMF entity (120) does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID. The first AMF entity (120) sends a PDU session accept message to the UE (102).

[0142] At step 1020, upon determining that a PDU session associated the with the second user profile ID is currently on-going by determining that the PDU session is already established for the second user ID associated with the UE (102) and when the first AMF entity (120) does not consider the service priority information associated with the first user ID and the service priority information associated with the second user ID, the first AMF entity (120) rejects one of: the PDU session request and the PDU session modification request. The first AMF entity (120) sends a PDU session reject message with a cause code to the UE (102) upon rejecting the PDU session of the first user ID.

[0143] In an embodiment of the disclosure, upon accepting the one of: the PDU session request and the PDU session modification request, the AMF entity (120) allows authentication and authorization of the first user identifier on the AMF entity (120).

[0144] In an embodiment of the disclosure, the first network entity updates a UE context associated with a first user profile with a data storage entity (106). The UE context comprises at least one of: a user identity information, a profile information, and a subscription information, upon determining the first user profile associated with the UE (102) is successfully authenticated and authorized, when the first user profile associated with the UE (102) triggers at least one network access procedure for the first user, identifier. A second user identifier may be associated with a second user is already authenticated by a second AMF entity (125). A UE context associated with the second user identifier is already updated in the data storage entity by the second AMF entity (125).

[0145] At step 1022, upon releasing the ongoing PDU session and establishing the new PDU session, the data storage entity (106) updates a user profile database at the second network entity. At step 1024, the data storage entity (106) deletes the UE context associated with the second user profile at the second network entity.

[0146] The various actions in method (1000) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 10 may be omitted.

[0147] FIG. 11 is a sequence diagram depicting a method (1100) for managing user identifiers in the wireless communication networks (100), during a UE mobility scenario between the AMF entities (120 and 125), according to an embodiment of the disclosure. Considering an AMF mobility scenario from the first AMF entity (120) to the second AMF entity (125), at step 1102, consider that the first user identifier is already authenticated by the network using a first UE (102). The first UE (102) is registered to the network via the first AMF entity (120). The user information may further be updated into the data storage entity (106) by the first AMF entity (120) as part of the AMF's registration procedure for the first UE (102) (Nudm_UECM procedure). The user information may also be updated in a User Profile Database indicating the first user identifier is accessing the network using the UE (102). At step 1104, the second user identifier now starts using the first UE (102) and triggers access procedures using implementation specific methods (for example, select an option to change user on an app). At step 1106, the first UE (102) initiates the second user identifier authentication and authorization procedure. Assume that the first UE (102) is now handled by a new network entity called the second AMF entity (125), which handles the second user identifier's authentication and authorization. At step 1108, once the second user identifier has been successfully authenticated and / or authorized, the second AMF entity (125) may trigger update of the UE context in the data storage entity (106) to include the second user identifier's identity and other information (if any). At step 1110, on determining that the second user identifier is using the first UE (102), the data storage entity (106) may trigger update of User Profile Database, and the UE context in the first UE (102) to remove the first user identifier association from the network.

[0148] In an embodiment of the disclosure, if the second user identifier initiates a PDU session through the same UE and the message is received to same AMF entity (e.g., the AMF entity which has processed the PDU session establishment of the first user identifier), can check from the available subscription information and associated user identifiers which AMF has already downloaded during registration procedure that a new user has been trying to avail a service from the same subscription for which already the first user identifier is availing service. If the user identifier policy defines to reject the new PDU session then AMF reject the PDU session for second user identifier. If the network policy defines the user identifiers associated with some priorities and second user identifier is having high priority than the first user identifier, then the second user identifier PDU session request is processed. The AMF entity (125) may send the message to SMF to release the PDU session of the first user identifier by providing some suitable cause code. On receiving the message from the AMF entity (125), the SMF entity may release the PDU session for the first user identifier with suitable cause code by sending to UE (102).

[0149] Thus, the network only maintains association of a single user with a 5G wireless device, and ensures that either the new user is rejected from using the device, or the older user's association is deleted from the network once new user takes over the device.

[0150] The solutions which are defined for NR (5GC) are also applicable to legacy RATs like E-UTRA / LTE, the corresponding CN entities needs to be replaced by LTE entities, for example, AMF with MME, g-nodeB with e-nodeB, UDM with HSS etc. But principles of the solution remain same.

[0151] The network used in this embodiment can be explained using any 5G Core Network Function; for example, the AMF. However, the network could be any 5G / EUTRAN Core Network Entities like AMF / SMF / MME / UPF or the Network could be any 5G / EUTRAN RAN Entity like eNodeB (eNB) or gNodeB (gNB) or NG-RAN etc.

[0152] The messages used or indicated in this embodiment are shown as an example. The messages could be any signaling messages between the UE and the network functions / entities or between different network functions / entities.

[0153] Similarly, the service operation name given in this invention is illustration purposes only. Any other name can be used to convey the information.

[0154] In an embodiment of the disclosure, the user identifier is considered to be associated with human only.

[0155] The various actions in method (1100) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 11 may be omitted.

[0156] FIG. 12 and FIG. 13 show another block diagram of the wireless network (100) for managing user identifiers in the UE (102), according to an embodiment of the disclosure. In an embodiment of the disclosure, the network entity (104) may include the first AMF entity (120) and the second AMF entity (125). The first AMF entity (120) may include but is not limited to a processor (1202), a memory (1204), a user identity managing controller (1208), and a transceiver (1206). The user identity managing controller (1208) coupled with the processor (1202), the memory (1204), and the transceiver (1206). The first AMF entity (120) may be in communication with the UE (102) and the data storage entity (106) through the transceiver (1206). The second AMF entity (125) may include but is not limited to a processor (1220), a memory (1222), a user identity managing controller (1226), and a transceiver (1224). The user identity managing controller (1226) coupled with the processor (1220), the memory (1222), and the transceiver (1224). The second AMF entity (125) may be in communication with the UE (102) and the data storage entity (106) through the transceiver (1224).

[0157] In an embodiment of the disclosure, the UE (102) includes a controller (1210) and a transceiver (1212). The controller (1210) communicates to the first AMF entity (120) and the second AMF entity (125) through the transceiver (1212). The wireless network may include, but is not limited to, a plurality of network entities available in a network coverage area of the UE (102).

[0158] The memory (1204) and is configured to store instructions to be executed by the processor (1202). The memory (1204) can include non-volatile storage elements. The memory (1222) and is configured to store instructions to be executed by the processor (1220). The memory (1222) can include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (1204 and 1222) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory is non-movable. In some examples, the memory (1204) is configured to store larger amounts of information. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0159] The processor (1202 and 1220) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (1202) includes multiple cores and is configured to execute the instructions stored in the memory (1204). In an embodiment of the disclosure, the processor (1220) includes multiple cores and is configured to execute the instructions stored in the memory (1222).

[0160] In an embodiment of the disclosure, the transceiver (1206) includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver (1206) is configured to communicate internally between internal hardware components of the UE (102) and with external devices via one or more networks.

[0161] In an embodiment of the disclosure, the transceiver (1224) includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver (1224) is configured to communicate internally between internal hardware components of the UE (102) and with external devices via one or more networks.

[0162] In an embodiment of the disclosure, the user identity managing controller (1208 and 1226) identifies, authenticates and re-authenticates the user before availing any service from the network.

[0163] As shown in FIG. 13, the network entity (104), but is not limited to a processor (1302), a memory (1304), a user identity managing controller (1308), and a transceiver (1306). The user identity managing controller (1308) coupled with the processor (1302), the memory (1304), and the transceiver (1306). The network entity (104) may be in communication with the UE (102) and the data storage entity (106) through the transceiver (1306). In an embodiment of the disclosure, the UE (102) includes a controller (1310) and a transceiver (1312). The controller (1310) communicates to the network entity (104) through the transceiver (1312). The wireless network may include, but is not limited to, a plurality of network entities available in a network coverage area of the UE. The first network entity, second network entity, are used for illustrative purposes only.

[0164] The memory (1304) is configured to store instructions to be executed by the processor (1302). The memory (1304) can include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (1304) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory is non-movable. In some examples, the memory (1304) is configured to store larger amounts of information. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0165] The processor (1302) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (1302) may include multiple cores and is configured to execute the instructions stored in the memory (1304).

[0166] In an embodiment of the disclosure, the transceiver (1306) includes an electronic circuit specific to a standard that enables wired or wireless communication. The transceiver (1306) is configured to communicate internally between internal hardware components of the UE (102) and with external devices via one or more networks.

[0167] In an embodiment of the disclosure, the user identity managing controller (1308) identifies, authenticates and re-authenticates the user before availing any service from the network.

[0168] FIG. 14 shows an example sequence diagram as an example of managing multiple user identities in a wireless communication network (100), according to an embodiment of the disclosure. At step 0, the data storage entity (106) may already have been provisioned with user identifier information associated with the subscription. At step 1, the UE (102) sends a registration request with capability indication of supporting the user identifier. At step 2, the AMF entity (125) receives the subscriber data information from the UDM (106) along with the associated user identifier details. At step 3, the AMF entity (125) provides the user identifier details in the registration accept to the UE (102). At step 4, the first user identifier invokes one application on the device (UE). At step 5, the UE (102) triggers PDU session establishment request by providing the first identifier. At step 6, the AMF entity (125) selects the first SMF entity (110) and sends the first identifier to the first SMF entity (110). At step 7, the first SMF entity (110) receives the session management subscriber data along with user identifier details from the UDM (106). At step 8, the first SMF entity (110) queries the UDM (106) to get any established PDU Session and get response of no PDU Session. At step 9, the first SMF entity (110) sends PDU session establishment accept to UE (102). At step 10, the first SMF entity (110) updates the SMF entity's address in UDM (106) and provides the first user identifier along with PDU Session ID. At step 11, the second user identifier invokes one Application on the device (UE). At step 12, the UE (102) triggers PDU session establishment request by providing the second user identifier. At step 13, the AMF entity (125) selects the second SMF entity (115) and sends the second user identifier to the second SMF entity (115). At step 14, the second SMF entity (115) queries the UDM (106) to get any established PDU session and get response of PDU Session associated with the first user identifier. At step 15, the second SMF entity (115) sends PDU session establishment reject to the UE (102) with a suitable cause code.

[0169] According to an embodiment of the disclosure, wherein the obtaining of the first PDU session request comprises: receiving, from a user equipment (UE), the first PDU session establishment request message via an access and mobility management function (AMF).

[0170] According to an embodiment of the disclosure, the method further comprises storing the first user identifier and an identifier of the first PDU session in the UDM.

[0171] According to an embodiment of the disclosure, the method further comprises obtaining the second PDU session request associated with the second user identifier; and rejecting the second PDU session associated with the second user identifier with the cause code.

[0172] According to an embodiment of the disclosure, the method further comprises identifying the established first PDU session associated with the first user identifier.

[0173] According to an embodiment of the disclosure, the method further comprises obtaining priority information among user identifiers; determining that the second user identifier has higher priority than the first user identifier; and releasing the first PDU session associated with the first user identifier, wherein the second PDU session associated with the second user identifier is accepted.

[0174] According to an embodiment of the disclosure, wherein the obtaining of the priority information among the user identifiers comprises: receiving, from the UDM, user identifier details.

[0175] According to an embodiment of the disclosure, wherein the at least one processor is configured to: receive, from a user equipment (UE), the first PDU session establishment request message via an access and mobility management function (AMF).

[0176] According to an embodiment of the disclosure, wherein the at least one processor is further configured to: store the first user identifier and an identifier of the first PDU session in the UDM.

[0177] According to an embodiment of the disclosure, wherein the at least one processor is further configured to: obtain the second PDU session request associated with the second user identifier, reject the second PDU session associated with the second user identifier with the cause code.

[0178] According to an embodiment of the disclosure, wherein the at least one processor is further configured to: identify the established first PDU session associated with the first user identifier.

[0179] According to an embodiment of the disclosure, wherein the at least one processor is further configured to: obtain priority information among user identifiers, determine that the second user identifier has higher priority than the first user identifier, release the first PDU session associated with the first user identifier, wherein the second PDU session associated with the second user identifier is accepted.

[0180] According to an embodiment of the disclosure, wherein the at least one processor is configured to: receive, from the UDM, user identifier details.

[0181] The proposed method helps for the operator to identify the actual user accessing the device (or the UE) to get the service from network and provide service differentiation based on the user identifier.

[0182] The various actions, acts, blocks, steps, or the like in the method(s) may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some of the actions, acts, blocks, steps, or the like may be omitted, added, modified, skipped, or the like without departing from the scope of the invention.

[0183] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.

[0184] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.

[0185] The embodiments disclosed herein describe systems and methods for managing user identifiers in a wireless communication network. Therefore, it is understood that the scope of the protection is extended to such a program and in addition to a computer readable means having a message therein, such computer readable storage means contain program code means for implementation of one or more steps of the method, when the program runs on a server or mobile device or any suitable programmable device. The method is implemented in at least one embodiment through or together with a software program written in e.g., Very high speed integrated circuit Hardware Description Language (VHDL) another programming language, or implemented by one or more VHDL or several software modules being executed on at least one hardware device. The hardware device can be any kind of portable device that can be programmed. The device may also include means which could be e.g., hardware means like e.g., an ASIC, or a combination of hardware and software means, e.g., an ASIC and an FPGA, or at least one microprocessor and at least one memory with software modules located therein. The method embodiments described herein could be implemented partly in hardware and partly in software. Alternatively, the invention may be implemented on different hardware devices, e.g., using a plurality of CPUs.

[0186] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of embodiments and examples, those skilled in the art will recognize that the embodiments and examples disclosed herein can be practiced with modification within the scope of the embodiments as described herein.

Claims

1.A method performed by a first session management function (SMF) in a wireless communication system, the method comprising:obtaining a first protocol data unit (PDU) session request associated with a first user identifier;querying a unified data management (UDM) to obtain established PDU session information;receiving, from the UDM, a response of no PDU session; andestablishing a first PDU session associated with the first user identifier,wherein a second PDU session request associated with a second user identifier is obtained by a second SMF,wherein the UDM is queried from the second SMF to obtain the established PDU session information,wherein a response of the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, andwherein a second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.2.The method of claim 1, wherein the obtaining of the first PDU session request comprises:receiving, from a user equipment (UE), the first PDU session establishment request message via an access and mobility management function (AMF).3.The method of claim 1,further comprising:storing the first user identifier and an identifier of the first PDU session in the UDM.4.The method of claim 1, further comprising:obtaining the second PDU session request associated with the second user identifier; andrejecting the second PDU session associated with the second user identifier with the cause code.5.The method of claim 4, further comprising:identifying the established first PDU session associated with the first user identifier.6.The method of claim 1, further comprising:obtaining priority information among user identifiers;determining that the second user identifier has higher priority than the first user identifier; andreleasing the first PDU session associated with the first user identifier,wherein the second PDU session associated with the second user identifier is accepted.7.The method of claim 6, wherein the obtaining of the priority information among the user identifiers comprises:receiving, from the UDM, user identifier details.8.A first session management function (SMF) in a wireless communication system, the first SMF comprising:a transceiver; andat least one processor coupled to the transceiver and configured to:obtain a first protocol data unit (PDU) session request associated with a first user identifier,query a unified data management (UDM) to obtain established PDU session information,receive, from the UDM, a response of no PDU session,establish a first PDU session associated with the first user identifier,wherein a second PDU session request associated with a second user identifier is obtained by a second SMF,wherein the UDM is queried from the second SMF to obtain the established PDU session information,wherein a response of the first PDU session associated with the first user identifier is transmitted from the UDM to the second SMF, andwherein a second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.9.The first SMF of claim 8, wherein the at least one processor is configured to:receive, from a user equipment (UE), the first PDU session establishment request message via an access and mobility management function (AMF).10.The first SMF of claim 8, wherein the at least one processor is further configured to:store the first user identifier and an identifier of the first PDU session in the UDM.11.The first SMF of claim 8, wherein the at least one processor is further configured to:obtain the second PDU session request associated with the second user identifier,reject the second PDU session associated with the second user identifier with the cause code.12.The first SMF of claim 11, wherein the at least one processor is further configured to:identify the established first PDU session associated with the first user identifier.13.The first SMF of claim 8, wherein the at least one processor is further configured to:obtain priority information among user identifiers,determine that the second user identifier has higher priority than the first user identifier,release the first PDU session associated with the first user identifier,wherein the second PDU session associated with the second user identifier is accepted.14.The first SMF of claim 13, wherein the at least one processor is configured to:receive, from the UDM, user identifier details.15.A unified data management (UDM) in a wireless communication system, the UDM comprising:a transceiver; andat least one processor coupled to the transceiver and configured to:receive, from a first session management function (SMF), a first query to obtain established PDU session information,transmit, to the first SMF, a response of no PDU session,wherein a first PDU session associated with a first user identifier is established,receive, from a second SMF, a second query to obtain the established PDU session information,transmit, to the second SMF, a response of the first PDU session associated with the first user identifier,wherein a second PDU session associated with the second user identifier is rejected by the second SMF with a cause code.

Citation Information

Patent Citations

  • Method and apparatus for supporting redundant PDU sessions

    US20210250788A1

  • Methods and systems for mitigating denial of service (DOS) attack in a wireless network

    US20220312215A1

  • Edge application server assignment for ad-hoc groups of user equipment

    US20230362598A1

  • Enforcing network slice simultaneous registration group (NSSRG) in evolved packet system (EPS) in a wireless communication system

    WO2023136590A1

  • Method for virtual network communication, apparatus, and storage medium

    WO2023137681A1