Method, device and system for UE identity protection in communication networks
The use of a secured PLMN-NPN UE ID and SPNFs addresses the security challenges in inter-network communication by protecting user data across different domains, ensuring confidentiality and integrity in public and private wireless networks.
Patent Information
- Application Number
- PCT/CN2024/085842
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-03
- Publication Date
- 2025-07-31
AI Technical Summary
The interconnection between public and private wireless networks poses significant security challenges, particularly in protecting sensitive user subscription and identification data, as existing methods fail to ensure confidentiality and integrity of communications across different security domains.
The introduction of a PLMN-NPN UE ID, derived from SUPI and secured through encryption, is used to protect user identity data across security domains, with network functions employing SPNFs as gateways to translate and secure UE identifiers, ensuring confidentiality and integrity.
This approach effectively safeguards sensitive user data by preventing exposure and maintaining privacy, even in the event of security breaches, while enabling seamless communication between public and private networks.
Smart Images

Figure CN2024085842_31072025_PF_FP_ABST
Abstract
Description
METHOD, DEVICE AND SYSTEM FOR UE IDENTITY PROTECTION IN COMMUNICATION NETWORKSTECHNICAL FIELD
[0001] This disclosure relates to wireless communication, and in particular, to protect sensitive user subscription and identification data in a communication network, such as 4G, 5G, and 6G wireless communication network.BACKGROUND
[0002] The proliferation of mobile devices and increasing data demands have led to the widespread deployment of public wireless networks by mobile operators, as well as private wires networks by enterprises. Private wireless networks are typically deployed within a defined geographic area, such as a campus, factory, or facility. The interconnection between public wireless networks and private wireless networks presents a significant challenge from a security perspective. It is crucial to establish secure inter-network operations that enable seamless and protected communication between these two distinct network environments. Implementing robust security measures at the interface of public and private wireless networks is critical to ensure the confidentiality and integrity of wireless communications.SUMMARY
[0003] This disclosure discloses methods, systems, devices, and storage medium relates to wireless communication, and in particular, to protecting sensitive user subscription and identification data in a wireless communication network, such as 4G, 5G, and 6G wireless communication network, as well as private network.
[0004] In one embodiment, the present disclosure describes a method for wireless communication. Performed by a first network element, the method includes: receiving, from a second network element, a first message associated with a service request for a wireless device, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; a Serving Network (SN) name of an SN serving the wireless device; or a service indicator indicating that the service request is initiated from a security domain different from the first network element; and transmitting, to a third network element, a second message based on the first message, the second message carrying at least one of: the SUCI of the wireless device; the UE identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; or the SN name of the SN serving the wireless device.
[0005] In another embodiment, a method for wireless communication is disclosed. Performed by a first network element, the method includes: receiving, from a second network element in a second security domain different from the first security domain, a first message associated with a service request for a wireless device, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; a temporary User Equipment (UE) identifier of the wireless device that is concealed from a UE identifier of the wireless device by the second network element; a Serving Network (SN) name of an SN serving the wireless device; or a service indicator indicating that the service request is initiated from a security domain different from the first network element; and transmitting, to a third network element, a second message based on the first message, the second message carrying at least one of: the SUCI of the wireless device; a UE identifier of the wireless device de-concealed from the temporary UE identifier and is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; or the SN name of the SN serving the wireless device.
[0006] In another embodiment, a method for wireless communication is disclosed. Performed by a first network element, the method includes: receiving, from a third NE in the first security domain, a first message associated with a service request for a wireless device, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; a User Equipment (UE) identifier of the wireless device; or a Serving Network (SN) name of an SN serving the wireless device; transmitting, to a second network element in a second security domain different from the first security domain, a second message associated with the service request for the wireless device, the second message carrying at least one of: a temporary UE identifier of the wireless device that is concealed from the UE identifier of the wireless device by the second network element; the Serving Network (SN) name of the SN serving the wireless device; or a service indicator indicating that the service request is initiated from a security domain different from the first network element.
[0007] In another embodiment, a network element or wireless device comprising a processor and a memory is disclosed. The processor may be configured to read computer code from the memory to implement any of the methods above.
[0008] In yet another embodiment, a computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon is disclosed. The computer code, when executed by a processor, may cause the processor to implement any one of the methods above.
[0009] The above embodiments and other aspects and alternatives of their implementations are explained in greater detail in the drawings, the descriptions, and the claims below.BRIEF DESCRIPTION OF THE DRAWINGS
[0010] FIG. 1 shows an exemplary communication network including various terminal devices, a carrier network, data network, and service applications.
[0011] FIG. 2 shows exemplary network functions or network nodes in a communication network.
[0012] FIG. 3 shows exemplary network functions or network nodes in a wireless communication network.
[0013] FIG. 4 shows an exemplary network model for a Non Public Network (NPN) hosted by a Public Land Mobile Network (PLMN) .
[0014] FIG. 5 shows an example wireless network node (or network element, network function, network entity, entity, application function) .
[0015] FIG. 6 shows an example user equipment.
[0016] FIG. 7 shows an exemplary service request model with an SPNF deployed in operator premises.
[0017] FIG. 8 shows an exemplary cross domain message interactions with an SPNF deployed in operator premises.
[0018] FIG. 9 shows an exemplary logic flow for interaction between NPN and PLMN with an SPNF deployed in operator premises.
[0019] FIG. 10 shows an exemplary service request model with SPNFs deployed in both customer premises and operator premises.
[0020] FIGs. 11A-11B show an exemplary logic flow for interaction between NPN and PLMN with SPNFs deployed in both customer premises and operator premises.
[0021] FIG. 12 shows another exemplary logic flow for interaction between NPN and PLMN with an SPNF deployed in operator premises.
[0022] FIG. 13 shows another exemplary logic flow for interaction between NPN and PLMN with SPNFs deployed in both customer premises and operator premises.DETAILED DESCRIPTION
[0023] An exemplary communication network, shown as 100 in FIG. 1, may include terminal devices 110 and 112, a carrier network 102, various service applications 140, and other data networks 150. The carrier network 102, for example, may include access networks 120 and a core network 130. The carrier network 102 may be configured to transmit voice, data, and other information (collectively referred to as data traffic) among terminal devices 110 and 112, between the terminal devices 110 and 112 and the service applications 140, or between the terminal devices 110 and 112 and the other data networks 150. Communication sessions and corresponding data paths may be established and configured for such data transmission. The Access networks 120 may be configured to provide terminal devices 110 and 112 network access to the core network 130. The Access network 120 may, for example, support wireless access via radio resources, or wireline access. The core network 130 may include various network nodes or network functions configured to control the communication sessions and perform network access management and data traffic routing. The service applications 140 may be hosted by various application servers that are accessible by the terminal devices 110 and 112 through the core network 130 of the carrier network 102. A service application 140 may be deployed as a data network outside of the core network 130. Likewise, the other data networks 150 may be accessible by the terminal devices 110 and 112 through the core network 130 and may appear as either data destination or data source of a particular communication session instantiated in the carrier network 102.
[0024] The core network 130 of FIG. 1 may include various network nodes or functions geographically distributed and interconnected to provide network coverage of a service region of the carrier network 102. These network nodes or functions may be implemented as dedicated hardware network elements. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or as software entities. A network node may each be configured with one or more types of network functions. These network nodes or network functions may collectively provide the provisioning and routing functionalities of the core network 130. The term “network nodes” and “network functions” are used interchangeably in this disclosure.
[0025] FIG. 2 further shows an exemplary division of network functions in the core network 130 of a communication network 200. While only single instances of network nodes or functions are illustrated in FIG. 2, those having ordinary skill in the art readily understand that each of these network nodes may be instantiated as multiple instances of network nodes that are distributed throughout the core network 130. As shown in FIG. 2, the core network 130 may include but is not limited to network nodes such as access management network node (AMNN) 230, authentication network node (AUNN) 260, network data management network node (NDMNN) 270, session management network node (SMNN) 240, data routing network node (DRNN) 250, policy control network node (PCNN) 220, and application data management network node (ADMNN) 210. Exemplary signaling and data exchange between the various types of network nodes through various communication interfaces are indicated by the various solid connection lines in FIG. 2. Such signaling and data exchange may be carried by signaling or data messages following predetermined formats or protocols.
[0026] The implementations described above in FIGs. 1 and 2 may be applied to both wireless and wireline communication systems. FIG. 3 illustrates an exemplary cellular wireless communication network 300 based on the general implementation of the communication network 200 of FIG. 2. FIG. 3 shows that the wireless communication network 300 may include user equipment (UE) 310 (functioning as the terminal device 110 of FIG. 2) , radio access network (RAN) 320 (functioning as the access network 120 of FIG. 2) , data network (DN) 150, and core network 130 including access management function (AMF) 330 (functioning as the AMNN 230 of FIG. 2) , session management function (SMF) 340 (functioning as the SMNN 240 of FIG. 2) , application function (AF) 390 (functioning as the ADMNN 210 of FIG. 2) , user plane function (UPF) 350 (functioning as the DRNN 250 of FIG. 2) , policy control function 322 (functioning as the PCNN 220 of FIG. 2) , authentication server function (AUSF) 360 (functioning as the AUNN 260 of FIG. 2) , and universal data management (UDM) function 370 (functioning as the UDMNN 270 of FIG. 2) . Again, while only single instances for some network functions or nodes of the wireless communication network 300 (the core network 130 in particular) are illustrated in FIG. 3, those of ordinary skill in the art readily understand that each of these network nodes or functions may have multiple instances that are distributed throughout the wireless communication network 300. While the AF 390 is depicted as part of the core network 130 in FIG. 3, they may be considered as associated with particular service applications 140 and may be considered as being outside of the core network 140. In this disclosure, various functions deployed in the wireless network as described above may also be referred to as function entities, which may be implemented as a network node, a network element, a logical function, via hardware, software, or a combination thereof.
[0027] In FIG. 3, the UE 310 may be implemented as various types of mobile devices that are configured to access the core network 130 via the RAN 320. The UE 310 may include but is not limited to mobile phones, laptop computers, tablets, Internet-Of-Things (IoT) devices, distributed sensor network nodes, wearable devices, and the like. The UE may also be Multi-access Edge Computing (MEC) capable UE that supports edge computing. The RAN 320 for example, may include a plurality of radio base stations distributed throughout the service areas of the carrier network. The communication between the UE 310 and the RAN 320 may be carried in over-the-air (OTA) radio interfaces as indicated by 311 in FIG. 3.
[0028] Continuing with FIG. 3, the UDM 370 may form a permanent storage or database for user contract and subscription data. The UDM may further include an authentication credential repository and processing function (ARPF, as indicated in 370 of FIG. 3) for storage of long-term security credentials for user authentication, and for using such long-term security credentials as input to perform computation of encryption keys as described in more detail below. To prevent unauthorized exposure of UDM / ARPF data, the UDM / ARPF 370 may be located in a secure network environment of a network operator or a third-party.
[0029] The AMF / SEAF 330 may communicate with the RAN 320, the SMF 340, the AUSF 360, the UDM / ARPF 370, and the Policy Control Function (PCF) 322 via communication interfaces indicated by the various solid lines connecting these network nodes or functions. The AMF / SEAF 330 may be responsible for UE to non-access stratum (NAS) signaling management, and for provisioning registration and access of the UE 310 to the core network 130 as well as allocation of SMF 340 to support communication need of a particular UE. The AMF / SEAF 330 may be further responsible for UE mobility management. The AMF may also include a security anchor function (SEAF, as indicated in 330 of FIG. 3) that, as described in more detail below, and interacts with AUSF 360 and UE 310 for user authentication and management of various levels of encryption / decryption keys. The AUSF 360 may terminate user registration / authentication / key generation requests from the AMF / SEAF 330 and interact with the UDM / ARPF 370 for completing such user registration / authentication / key generation.
[0030] The SMF 340 may be allocated by the AMF / SEAF 330 for a particular communication session instantiated in the wireless communication network 300. The SMF 340 may be responsible for allocating UPF 350 to support the communication session and data flows therein in a user data plane and for provisioning / regulating the allocated UPF 350 (e.g., for formulating packet detection and forwarding rules for the allocated UPF 350) . Alternative to being allocated by the SMF 340, the UPF 350 may be allocated by the AMF / SEAF 330 for the particular communication session and data flows. The UPF 350 allocated and provisioned by the SMF 340 and AMF / SEAF 330 may be responsible for data routing and forwarding and for reporting network usage by the particular communication session. For example, the UPF 350 may be responsible for routing end-end data flows between UE 310 and the DN 150, between UE 310 and the service applications 140. The DN 150 and the service applications 140 may include but are not limited to data network and services provided by the operator of the wireless communication network 300 or by third-party data network and service providers.
[0031] The PCF 322 may be responsible for managing and providing various levels of policies and rules applicable to a communication session associated with the UE 310 to the AMF / SEAF 330 and SMF 340. As such, the AMF / SEAF 330, for example, may assign SMF 340 for the communication session according to policies and rules associated with the UE 310 and obtained from the PCF 322. Likewise, the SMF 340 may allocate UPF 350 to handle data routing and forwarding of the communication session according to policies and rules obtained from the PCF 322.
[0032] While FIGs. 1-3 and the various exemplary implementations described below are based on cellular wireless communication networks, the scope of this disclosure is not so limited and the underlying principles are applicable to other types of wireless and wireline communication networks.
[0033] Network identity and data security in the wireless communication network 300 of FIG. 3 may be managed via user authentication processes provided by the AMF / SEAF 330, the AUSF 360, and the UDM / ARPF 370. In particularly, the UE 310 may first communicate with AMF / SEAF 330 for network registration and may then be authenticated by the AUSF 360 according to user contract and subscription data in the UDM / ARPF 370. Communication sessions established for the UE 310 after user authentication to the wireless communication network 300 may then be protected by the various levels of encryption / decryption keys. The generation and management of the various keys may be orchestrated by the AUSF 360 and other network functions in the communication network 300.
[0034] Security Domains -Operator Premises and Customer Premises
[0035] FIG. 4 illustrates an exemplary network model 400 that includes an operator premises and a customer premises. The operator premises may include, for example, a Unified Data Management (UDM) entity, a Network Exposure Function (NEF) entity, a Network Repository Function (NRF) entity, a Policy Control Function (PCF) entity, a User Plane Function (UPF) entity, an Authentication Server Function (AUSF) entity, an AMF entity, a Session Management Function (SMF) entity, and may further include an Application Function (AF) entity. The customer premises may include, for example an AMF entity, an SMF entity, a UPF entity, and a Data Network (DN) .
[0036] In the network model 400, the operator premises may include a Public Land Mobile Network (PLMN) , which is managed and operated by a public operator. The customer premises may include a private network, such as a Non-Public Network (NPN) by 3rd Generation Partnership Project (3GPP) . The NPN may be operated or manage by, for example, a private entity such as a private enterprise or a private operator. The NPN may be deployed as Stand-alone NPN (SNPN) , which do not rely on services or applications provided by a PLMN. The NPN may also be deployed as Public Network Integrated NPN (PNI-NPN) , which has inter-connection with a PLMN. In some example implementations, The PNI-NPN may share Radio Access Network (RAN) with a PLMN. In some example implementations, the PNI-NPN may share at least part of Control Plane (CP) functions and / or User Plane (UP) functions with a PLMN.
[0037] In wireless network such as a 5G network, a Service Based Architecture (SBA) framework is implemented to expose the functionality of various network elements to each other. The SBA framework enhances network deployment flexibility by providing enriched configuration options. Through SBA implementation, various components and functions within the wireless network (including PLMN and private network) can seamlessly interact and leverage each other’s functions, facilitating more agile and modular network deployments that can adapt to diverse operational requirements.
[0038] In some network deployment as shown in FIG. 4, a dedicated UPF and part of CP functions are deployed in the customer premises. The dedicated Network Functions (NFs) in the customer premises may communicate with the NFs in the operator premise via the SBA interface. In this example deployment, the CP functions hosted by the NPN in the customer premises includes the AMF entity and the SMF entity.
[0039] In some other network deployments, a dedicated UPF is deployed in customer premises, which may interact with the operator premises via, for example, an N4 interface (non-SBA interface) .
[0040] FIG. 5 shows an example of electronic device 500 to implement various network nodes, network elements, network entities, such as a network base station (e.g., a radio access network node) , a core network (CN) , a core network element / entity (e.g., an AMF, a UDM, an AAnF, etc. ) , an operation and maintenance (OAM) , and the like. Optionally in one implementation, the example electronic device 500 may include radio transmitting / receiving (Tx / Rx) circuitry 508 to transmit / receive communication with UEs and / or other base stations. Optionally in one implementation, the electronic device 500 may also include network interface circuitry 509 to communicate the base station with other base stations and / or a core network, e.g., optical or wireline interconnects, Ethernet, and / or other data transmission mediums / protocols. The electronic device 500 may optionally include an input / output (I / O) interface 506 to communicate with an operator or the like.
[0041] The electronic device 500 may also include system circuitry 504. System circuitry 504 may include processor (s) 521 and / or memory 522. Memory 522 may include an operating system 524, instructions 526, and parameters 528. Instructions 526 may be configured for the one or more of the processors 521 to perform the functions of the network node. The parameters 528 may include parameters to support execution of the instructions 526. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.
[0042] In this disclosure, a network function / network entity / entity, such as an AMF, an AUSF, a UDM, an AAnF, an NEF, an AF, may be implemented in hardware, software, a combination of hardware and software, and may be implemented or integrated in the electronic device 500. They may also be implemented as a logical entity hosted by the electronic device 500.
[0043] FIG. 6 shows an example of an electronic device to implement a terminal device 600 (for example, a UE) . The UE 600 may be a mobile device, for example, a smart phone or a mobile communication module disposed in a vehicle. The UE 600 may include a portion or all of the following: communication interfaces 602, a system circuitry 604, an input / output interfaces (I / O) 606, a display circuitry 608, and a storage 609. The display circuitry may include a user interface 610. The system circuitry 604 may include any combination of hardware, software, firmware, or other logic / circuitry. The system circuitry 604 may be implemented, for example, with one or more systems on a chip (SoC) , application specific integrated circuits (ASIC) , discrete analog and digital circuits, and other circuitry. The system circuitry 604 may be a part of the implementation of any desired functionality in the UE 600. In that regard, the system circuitry 604 may include logic that facilitates, as examples, decoding and playing music and video, e.g., MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user inputs; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections for, as one example, internet connectivity; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on the user interface 610. The user interface 610 and the inputs / output (I / O) interfaces 606 may include a graphical user interface, touch sensitive display, haptic feedback or other haptic output, voice or facial recognition inputs, buttons, switches, speakers and other user interface elements. Additional examples of the I / O interfaces 606 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headset and microphone input / output jacks, Universal Serial Bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors) , and other types of inputs.
[0044] Referring to FIG. 6, the communication interfaces 602 may include a Radio Frequency (RF) transmit (Tx) and receive (Rx) circuitry 616 which handles transmission and reception of signals through one or more antennas 614. The communication interface 602 may include one or more transceivers. The transceivers may be wireless transceivers that include modulation / demodulation circuitry, digital to analog converters (DACs) , shaping tables, analog to digital converters (ADCs) , filters, waveform shapers, filters, pre-amplifiers, power amplifiers and / or other logic for transmitting and receiving through one or more antennas, or (for some devices) through a physical (e.g., wireline) medium. The transmitted and received signals may adhere to any of a diverse array of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM) , frequency channels, bit rates, and encodings. As one specific example, the communication interfaces 602 may include transceivers that support transmission and reception under the 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS) , High Speed Packet Access (HSPA) +, 4G / Long Term Evolution (LTE) , 5G, and 6G standards. The techniques described below, however, are applicable to other wireless communications technologies whether arising from the 3rd Generation Partnership Project (3GPP) , GSM Association, 3GPP2, IEEE, or other partnerships or standards bodies.
[0045] Referring to FIG. 6, the system circuitry 604 may include one or more processors 621 and memories 622. The memory 622 stores, for example, an operating system 624, instructions 626, and parameters 628. The processor 621 is configured to execute the instructions 626 to carry out desired functionality for the UE 600. The parameters 628 may provide and specify configuration and operating options for the instructions 626. The memory 622 may also store any BT, WiFi, 3G, 4G, 5G, 6G or other data that the UE 600 will send, or has received, through the communication interfaces 602. In various implementations, a system power for the UE 600 may be supplied by a power storage device, such as a battery or a transformer.
[0046] UE Identify Protection in Wireless Network
[0047] In wireless communication networks, in the primary authentication and authorization procedure, if a UE identity, such as the Subscription Permanent Identifier (SUPI) is available in clear text to the Network Functions (NFs) in customer premises, then it may potentially lead to security threats, privacy breaches, UE location tracking and targeted attacks.
[0048] Further, with the evolution of the roaming architectures (e.g., Roaming Hub) and Core Network (NPN, Edge computing) , distributed CN (multi-site CN) , as there is no direct trust relationship between Home Network (HN) and various other networks, such as Serving Network (SN) , Visiting PLMN (VPLMN) , and Edge network (i.e., between the different security domains) , there is serious security concern for the HN to expose permanent and / or sensitive information (e.g., UE identifiers and other parameter) to the NFs that are not in the HN.
[0049] In this disclosure, the term “security domain” is employed to denote a distinct realm encompassing a network infrastructure, physical premises, or entities involved in the network ecosystem. For various reason, in wireless networks (PLMN and NPN) , there are different security domains. The security domain may be classified by the owner / operator of the network. For example, a PLMN may be owned and / or operated by a communication service provider, whereas an NPN may be owned and / or operated by a private enterprise, a private entity, etc. The security domain may also be classified by regulatory compliance and risk management. For example, a PLMN may be categorized as relatively low risk when compared to an NPN. The embodiments described below may use the terms “customer domain” and “operator domain” to represent different security domains. The underlying concept and principles apply to all other types of security domains, irrespective of specific terminology.
[0050] The privacy-sensitive SUPI is the home network operator-provided identifier used exclusively to identify its subscribers and related subscription information to handle the related services. A robust mechanism is essential to address the potential risks involved with sharing sensitive subscriber data across different security domains. Such mechanism is critical to protect sensitive information (e.g., SUPI) from risks that may arise when a PLMN hosts an NPN, and vice versa.
[0051] In this disclosure, the SUPI of a UE, as a sensitive piece of information associated with a user’s identity within the PLMN (whether it’s Home PLMN (HPLMN) or VPLMN) , should be protected to maintain user privacy and prevent security breaches. The SUPI of a UE is not allowed to be sent across security domains, or the SUPI is not allowed be transmitted between different security domains without proper protection mechanisms in place.
[0052] To accommodate the inter-connection between the two security domains, an alternative UE identifier is introduced. First, this newly introduced alternative UE identifier is distinct from various existing UE identifiers in wireless standards, such as SUCI, SUPI, or 5G-GUTI (5G Globally Unique Temporary Identifier) . Second, the alternative UE identifier may be dedicated for information exchange between the two security domains. Third, the alternative UE identifier may be derived or generated from the SUPI of the UE, but it may undergo a secure transformation process to ensure its confidentiality and integrity. For example, it may involve encrypting the SUPI using one or more security keys. Specifically, the transformation process differs from the process used to generate existing UE identifiers, such as SUCI. This ensure that even in the event that the alternative UE identifier is compromised in one security domain, other UE identifiers still remain secure and protected. In this disclosure, this newly introduce alternative UE identifier may be referred to as PLMN-NPN UE ID, or PLMNNPN UE ID, in the sense that it may be used across PLMN and NPN domains. The name is for exemplary purpose only and other names may be chosen to represent this alternative UE identifier.
[0053] There are multiple solutions to generate PLMN-NPN UE ID. In some example implementations, the PLMN-NPN UE ID may be generated from the SUPI of the UE, using encryption technologies. In some example implementations, a unique random number may be acquired and mapped to each SUPI, therefore the random number is a representation of SUPI via the mapping relationship. When a random number is received, it may be mapped back to the SUPI. As an extra layer of security protection, the random number may be further encrypted before passing between security domains. In some example implementations, once the PLMN-NPN UE ID is generated in one security domain, it may be passed to a different security domain for future use.
[0054] In some example implementations, an extra layer of security is added, such that the aforementioned PLMN-NPN UE ID is only used within a security domain, such as the customer premises. For message / signaling across security domains, a temporary UE ID is used in place of PLMN-NPN UE ID. Exemplarily, the temporary UE ID may be generate based on PLMN-NPN UE ID or SUPI using the similar methods as described above, for example, via encryption or mapping.
[0055] Embodiment 1: NF1 Request Service from NF2 via SPNF Deployed in Operator Premises
[0056] In this embodiment, the network deployment includes two security domains. For example, as shown in FIG. 7, one security domain is the customer premises and the other security domain is the operator premises.
[0057] In this embodiment, Network Function 1 (NF1) is in a first security domain (e.g., customer premises) , and may initiate service request (e.g., authentication request) with NF2 which is located in a second security domain (e.g., operator premises) . Specifically, a PLMNNPN Network Function (SPNF) is introduced in this disclosure and is deployed in the second security domain and may be used as a gateway / proxy for interactions between NF1 and NF2. Using SPNF, sensitive user data, such as user subscription data (e.g., SUPI) will not be passed between the two security domains. For example, user subscription data will be securely transformed before it is transmitted from one security domain to another security domain. The SPNF may be a stand alone entity / function, or may be co-located with an existing entity / function, such as a UDM. FIG. 7 illustrates an example according to this embodiment. An exemplary method may include a portion or all of the following steps.
[0058] Step 1: NF1 sends a service request to NF2 via Security for PLMNNPN Network Function (SPNF) . The request message may carry SUCI or PLMNNPN UE ID of a UE. The request message may further carry a PLMNNPN indication. The PLMNNPN service indication may indicate that the service request is initiated from an NF that is located in a customer premises. The PLMNNPN service indication may also serve as a basis for the recipient to determine that the service request is imitated from a different security domain. For example, as shown in FIG. 7, the service request is initiated from NF2, and received by NF2. Based on the PLMNNPN service indication, NF2 may determine that the service request comes from a customer premises, or a security domain different from the security domain in which NF2 is deployed.
[0059] In this disclosure, the PLMNNPN service indication may include at least one of:
[0060] ● The Serving Network (SN) name (indicating the SN from which the request is initiated) ;
[0061] ● The PLMNNPN UE ID;
[0062] ● The ID of the NF from which the request is initiated (e.g., AMF ID, Globally Unique AMF Identifier (GUAMI) ) ;
[0063] ● A PLMNNPN service indicator (e.g., represented as an Information Element (IE) , a bit, a parameter, etc. ) ; or
[0064] ● The name and / or type of the message / signaling (e.g., a keyword such as “NF1” , a particular string in the message name) . As an example, the Nausf_UEAuthentication_Authenticate Request message may be renamed to “Nausf_PLMNNPN_UEAuthentication_Authenticate Request” .
[0065] The service request message may include any messages / signaling. For example, it may include: authentication related message, UE context transfer related message, N2 handover related message, etc.
[0066] Step 2: If the service request carries SUCI of the UE, the SPNF forward the request to NF2.
[0067] If the service request carries PLMNNPN UE ID, based on the PLMNNPN UE ID generation method (e.g., encryption, mapping) , the SPNF may de-conceal PLMNNPN UE ID to obtain SUPI of the UE. For example, SPNF may decrypt the PLMNNPN UE ID to obtain SUPI of the UE. For another example, the SPNF may use the mapping of (SUPI, PLMNNPN UE ID) to obtain the SUPI of the UE. SPNF may then replace the PLMNNPN UE ID with SUPI (when forwarding the request to NF2) .
[0068] If the SPNF fails to de-conceal PLMNNPN UE ID or fails to obtain the SUPI according to the PLMNNPN UE ID, it may send a response to NF1 indicating the failure of obtaining / de-concealing the SUPI. Triggered by this failure indication, NF1 may trigger a primary authentication with UE, to obtain SUCI of the UE.
[0069] The SPNF sends a service request to NF2. Note that if the service request in step 1 carrying the PLMNNPN UE ID, it will be replaced with SUPI of the UE.
[0070] Step 3: If the service request carrying SUCI, then NF2 may perform a primary authentication with and respond back with a service response carrying the SUPI of the UE.
[0071] Step 4: If the service response carries SUPI, the SPNF may translate (i.e., encrypt / map) the SUPI to PLMNNPN UE ID, and send a service response back to NF1 carrying the PLMNNPN UE ID. Note that this response message is cross security domain, and the SUPI has been replaced with PLMNNPN UE ID for protection.
[0072] Embodiment 2: NF1 and NF2 Interactions via SPNF Deployed in Operator Premises
[0073] In this embodiment, the network deployment includes two security domains. For example, as shown in FIG. 8, one security domain is the customer premises and the other security domain is the operator premises.
[0074] In this embodiment, NF1 is in a first security domain (e.g., customer premises) , whereas NF2 and SPNF are located in a second security domain (e.g., operator premises) . Before NF1 and NF2 can interact with each other, the SPNF is invoked first, to translate UE identifier, such as SUPI, to PLMNNPN UE ID. Then NF1 and NF2 may interact with each other directly, using PLMNNPN UE ID. FIG. 8 illustrates an example according to this embodiment.
[0075] Steps 1-2: Before NF2 sends a message to NF1, if the message needs to carry SUPI, the NF2 may send a UE ID translate / convert request to SPNF, to translate / convert SUPI to PLMNNPN UE ID. The SPNF may translate / convert the SUPI based on PLMNNPN UE ID generation method as described earlier. NF2 then stores the mapping between SUPI and PLMNNPN UE ID for later use.
[0076] Steps 3-4: The NF2 sends a service request to NF1 carrying PLMNNPN UE ID as a substitute of SUPI.
[0077] Step 5: The NF1 sends a service request carrying a PLMNNPN UE ID to NF2.
[0078] Steps 6-7: If NF2 has not used this particular PLMNNPN UE ID sent in step 5 before, it may not obtain SUPI from the PLMNNPN UE ID locally. NF2 may send an UE ID translate request to SPNF to translate the PLMNNPN UE ID to SUPI.
[0079] Otherwise, if NF2 has used the PLMNNPN UE ID before (e.g., via steps 1-2) , it may map the PLMNNPN UE ID to SUPI by using its own mapping, or decrypt PLMNNPN UE ID to obtain SUPI. In this case, steps 6-7 may be skipped.
[0080] Step 8: Based on the SUPI translated from PLMNNPN UE ID, NF2 may generate a service response and send it to NF1.
[0081] Embodiment 3: NF1 Request Service from NF2 via SPNF Deployed in Operator Premises
[0082] In this embodiment, additional low-level details are provided, with reference to the concepts and principles described in previous embodiments, which are described in a high level. A more comprehensive set of detailed messages is utilized, involving the deployment of additional network elements.
[0083] The network deployment includes two security domains. For example, one security domain is the customer premises and the other security domain is the operator premises. The SPNF may be a stand alone entity / function, or may be co-located with an existing entity / function, such as a UDM. FIG. 9 illustrates an example according to this embodiment. An exemplary method may include a portion or all of the following steps. In this disclosure, the SEAF and AMF may be co-located, and the term SEAF and AMF may be used interchangeably. In some example implementations, the functions associated with both SEAF and AMF are performed by the same entity within the network.
[0084] Step 1: The AMF1 may initiate a service request, such as an authentication with the UE. This may happen when a signaling connection with the UE is required, according to the AMF1’s policy. The UE may use SUCI or 5G-GUTI in the Registration Request. As an example, based on AMF’s policy, if the 5G-GUTI points to an AMF which is not located in the current premises, such as AMF1 is in the customer premises while the 5G-GUTI points to an AMF which is located in the operator premises, AMF1 may send an identity request to UE, to obtain the SUCI of UE.
[0085] Step 2: The AMF1 may initiate a UE authentication procedure. For example, AMF1 may invoke an Nausf_UEAuthentication service by sending, for example, an Nausf_UEAuthentication_Authenticate Request message to the AUSF, using SPNF as a relay / bridge. The Nausf_UEAuthentication_Authenticate Request message may carry either SUCI or the newly introduced alternative UE ID -PLMNNPN UE ID. The Nausf_UEAuthentication_Authenticate Request message may further carry the Serving Network (SN) name of the UE. The SN may be the network in which UE initiates the registration request. The Nausf_UEAuthentication_Authenticate Request message may further carry a PLMNNPN service indication.
[0086] In this disclosure, the PLMNNPN service indication may indicate that the service request (or more broadly, message / signaling) is cross security domain, that the service request is from a customer premises. The PLMNNPN service indication may also serve as a basis for the recipient to determine that the service request is imitated from a different security domain. For example, the source of the message / request / signaling is in one security domain (e.g., customer premises) and the destination is in another security domain (e.g., operator premises) . For example, in a network deployment scenario in which both customer premises and operator premises are deployed, the PLMNNPN service indication indicates to network element in the operator premises that a corresponding message / request / signaling is from the customer premises.
[0087] In this disclosure, the PLMNNPN service indication may include at least one of:
[0088] ● The SN name (indicating the SN from which the message is initiated) ;
[0089] ● The PLMNNPN UE ID;
[0090] ● The AMF ID (indicating the AMF from which the message is initiated, in this case, AMF1 ID) ;
[0091] ● A PLMNNPN service indicator (e.g., represented as an Information Element (IE) , a bit, a parameter, etc. ) ; or
[0092] ● The name and / or type of the message / signaling (e.g., a keyword, a particular string in the message name) . As an example, the Nausf_UEAuthentication_Authenticate Request message may be renamed to “Nausf_PLMNNPN_UEAuthentication_Authenticate Request” .
[0093] Step 3: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, if PLMNNPN UE ID is received, the SPNF may convert it to SUPI. The SPNF is capable of de-concealing the PLMNNPN UE ID to obtain SUPI of the UE, based on a PLMNNPN UE ID generation / convertion method. For example, SPNF may decrypt the PLMNNPN UE ID to obtain SUPI of the UE. For another example, the SPNF may use the mapping of (SUPI, PLMNNPN UE ID) to obtain the SUPI of the UE.
[0094] If SPNF fails to obtain the SUPI from PLMNNPN UE ID, the SPNF may respond to AMF1 with a failure cause. AMF1 may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIG. 9) .
[0095] Step 4: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF sends an Nudm_UEAuthentication_Get Request to UDM. The Nudm_UEAuthentication_Get Request may carry at least one of: SUCI of UE; SUPI of UE; the serving network name of the UE; a PLMNNPN service indication, if it is carried in the Nausf_UEAuthentication_Authenticate Request message in step 2.
[0096] Step 5: Upon receiving the Nudm_UEAuthentication_Get Request, if SUCI is received, the UDM may invoke the Subscription Identifier De-concealing Function (SIDF) to de-conceal SUCI to obtain the SUPI, before UDM can process the request. If PLMNNPN UE ID is received, the SPNF will be invoked in order to obtain SUPI of the UE.
[0097] As a response, the UDM may respond back to the AUSF with, for example, a Nudm_UEAuthentication_Get response message. The response message may carry an Authentication Vector (AV) created by the UDM (or ARPF) .
[0098] Steps 6-7: The AUSF sends the AV in Nausf_UEAuthentication_UEAuthentication Response message to AMF1 using SPNF as a relay.
[0099] Step 8: The AMF1 may send an authentication request message to the UE, and UE may respond with an authentication response message carrying an authentication challenge result (RES*) .
[0100] Step 9: The AMF1 may send an Nausf_UEAuthentication_Authenticate Request message to AUSF carrying RES*.
[0101] Step 10: Using SPNF as a relay / bridge, the AUSF may indicate to the AMF1 in an Nausf_UEAuthentication_Authenticate Response message whether the authentication was successful or not from the home network point of view. If the authentication was successful, the anchor key (KSEAF) will be sent to the AMF1 in the Nausf_UEAuthentication_Authenticate Response message.
[0102] In case the AUSF received a SUCI from AMF1 in the authentication request (in step 2) , and if the authentication was successful, then the AUSF may also include the SUPI of the UE in the Nausf_UEAuthentication_Authenticate Response message.
[0103] Step 11: The SPNF may translate / convert the SUPI to PLMNNPN UE ID and forward the message to AMF1 in the customer premise. The PLMNNPN UE ID can be same with the PLMNNPN UE ID in step 2. Based on a predefined network policy, if an updated PLMNNPN UE ID is required (e.g., PLMNNPN UE ID has expired or reaches its lifecycle) , the SPNF may generate an updated / refreshed PLMNNPN UE ID.
[0104] Step 12. The AMF1 may send a registration accept message to the UE, if the authentication is successful. The AMF1 may assign a new 5G-GUTI for the UE.
[0105] In some scenarios, AMF1 in customer premises needs to transfer UE context to AMF2 in the operator premises. For example, AMF1 may be the old AMF for the UE, and AMF2 may be the new AMF for the UE. There are two cases which are described below.
[0106] Case 1: UE context transfer during the mobility registration (shown in FIG. 9)
[0107] Step 13: The UE may send a registration request message carrying 5G-GUTI (received from step 12) to AMF2 in the operator premises.
[0108] Step 14: AMF2 sends a Namf_Communication_UEContextTransfer message to the AMF1 in the customer premises.
[0109] Step 15: Using SPNF as a relay / bridge, AMF1 in the customer premises respond to AMF2 in the operator premises with the UE context. The UE context may include PLMNNPN UE ID.
[0110] Step 16: Based on the PLMNNPN UE ID generation method, the SPNF de-conceal PLMNNPN UE ID. For example, SPNF may decrypt the PLMNNPN UE ID to obtain SUPI of the UE. For another example, the SPNF may use the mapping of (SUPI, PLMNNPN UE ID) to obtain the SUPI of the UE.
[0111] If the SPNF fails to obtain the SUPI of UE, the SPNF may indicate the failure to AMF2, for example, by sending a message carrying the failure cause to AMF2. The AMF2 in the operator premises may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIG. 9) .
[0112] Step 17: AMF2 in the operator premises may send a registration accept message to the UE carrying a new 5G-GUTI. The new 5G-GUTI points to AMF2 (which is the new AMF serving the UE) .
[0113] Case 2: UE context transfer during the N2 handover (not shown in FIG. 9)
[0114] In this scenario, AMF1 in the customer premises is the source AMF, and the AMF2 in the operator premises is the target AMF.
[0115] Upon reception of the NGAP HANDOVER REQUIRED message, AMF1 may send a Namf_Communication_CreateUEContext Request message to AMF2, via SPNF. If the SPNF fails to obtain the SUPI of UE, the SPNF may indicate the failure to AMF2, for example, by sending a message carrying the failure cause to AMF2. The AMF2 in the operator premises may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIG. 9) .
[0116] Embodiment 4: UE Request via AMF in Customer Premises and SPNFs Deployed in Both Operator Premises and Customer Premises
[0117] In this embodiment, the network deployment includes two security domains. As illustrated in FIG. 10, one security domain is the customer premises and the other security domain is the operator premises.
[0118] In this embodiment, each security domain is deployed with a respective SPNF, serving as a gateway / proxy for interactions between NF1 and NF2. The two SPNFs, SPNF1 and SPNF2 are peer to each other. In some example implementations, another layer of security mechanism is added on top of the PLMNNPN UE ID, such that a temporary UE ID is introduced, which is passed between the two SPNFs. One of the advantages is that PLMNNPN UE ID can then be kept within the customer premises, preventing its exposure to the operator domain. FIG. 10 illustrates an example according to this embodiment. An exemplary method may include a portion or all of the following steps.
[0119] Step 1: NF1 sends a service request to NF2 via SPNF1 which interfaces with SPNF2. The request message may carry SUCI or PLMNNPN UE ID of a UE. The request message may further carry a PLMNNPN indication. The PLMNNPN service indication may indicate that the service request is initiated from an NF that is located in a customer premises. The PLMNNPN service indication may also serve as a basis for the recipient to determine that the service request is imitated from a different security domain. For example, as shown in FIG. 7, the service request is initiated from NF2, and received by NF2. Based on the PLMNNPN service indication, NF2 may determine that the service request comes from a customer premises, or a security domain different from the security domain in which NF2 is deployed. The detailed implementation on PLMNNPN service indication may be referred to previous embodiments, such as embodiment 1.
[0120] The service request message may include any messages / signaling. For example, it may include: authentication related message, UE context transfer related message, N2 handover related message, etc.
[0121] Step 2: If the service request carries SUCI of the UE, SPNF1 may forward the request to SPNF2.
[0122] If the service request carries PLMNNPN UE ID, SPNF1 may convert it to a temporary UE ID via, for example, a mapping (Temporary UE ID, PLMNNPN UE ID) . SPNF1 then forwards the request to SPNF2, carrying the temporary UE ID as a substitute for PLMNNPN UE ID.
[0123] If the SPNF fails to find a temporary UE ID according to the PLMNNPN UE ID, it may send a response to NF1 indicating the failure. Triggered by this failure indication, NF1 may trigger a primary authentication with UE, to obtain SUCI of the UE.
[0124] Step 3: SPNF2 in operator premises receive the service request from SPNF1 in customer premises.
[0125] If PLMNNPN UE ID is included, the SPNF in customer premises find the mapping (SUPI, PLMNNPN UE ID) or de-conceal PLMNNPN UE ID to get SUPI. If the SPNF cannot find the SUPI according to the PLMNNPN UE ID. The SPNF sends a response to NF1 or NF2 indicate the failure of getting SUPI. Then the NF1 or NF2 may get SUCI of UE and trigger primary authentication. Otherwise, the SPNF sends SUCI or SUPI in the service request.
[0126] Step 4: NF2 sends a service response to SPNF2. If the service request includes SUCI, the NF2 may perform a primary authentication with UE and includes SUPI of the UE in the response.
[0127] Step 5: If the service response includes the SUPI, SPNF2 may translate the SUPI to a temporary UE ID. In some example implementations, the PLMN (operator premises side) may update / refresh the temporary UE ID (i.e., refreshed from the temporary UE ID received in step 2) , and add both the original temporary UE ID and the refreshed temporary UE ID in the service response message, and forward the service response message to SPNF1.
[0128] Step 6: The SPNF1 in customer premises generate a PLMNNPN UE ID based on the temporary UE ID (or refreshed temporary UE ID) received in the service response message. If the SPNF1 receives the refreshed / updated temporary UE ID, SPNF1 may update the temporary UE ID accordingly. Based on a local policy, SPNF1 may also refresh / update the PLMNNPN UE ID (i.e., SPNF1 may generate a new PLMNNPN UE ID) .
[0129] Embodiment 5: UE Request via AMF in Customer Premises and SPNFs Deployed in Both Operator Premises and Customer Premises
[0130] In this embodiment, additional low-level details are provided, with reference to the concepts and principles described in embodiment 4, which are described in a high level. A more comprehensive set of detailed messages is utilized, involving the deployment of additional network elements.
[0131] The network deployment includes two security domains. For example, one security domain is the customer premises and the other security domain is the operator premises. The SPNF (SPNF1 / SPNF2) may be a stand alone entity / function, or may be co-located with an existing entity / function, such as a UDM. FIGs. 11A and 11B (FIG. 11B is a continuation of FIG. 11A) illustrate an example according to this embodiment. An exemplary method may include a portion or all of the following steps.
[0132] Step 1: The AMF1 may initiate a service request, such as an authentication with the UE.
[0133] This may happen when a signaling connection with the UE is required, according to the AMF1’s policy. The UE may use SUCI or 5G-GUTI in the Registration Request. As an example, based on AMF’s policy, if the 5G-GUTI points to an AMF which is not located in the current premises, such as AMF1 is in the customer premises while the 5G-GUTI points to an AMF which is located in the operator premises (e.g., AMF2) , AMF1 may send an identity request UE, to obtain the SUCI of UE.
[0134] Step 2: The AMF1 may initiate a UE authentication procedure. For example, AMF1 may invoke an Nausf_UEAuthentication service by sending, for example, an Nausf_UEAuthentication_Authenticate Request message to the AUSF, using SPNF1 as a relay / bridge. The Nausf_UEAuthentication_Authenticate Request message may carry either SUCI or the newly introduced alternative UE ID -PLMNNPN UE ID. The Nausf_UEAuthentication_Authenticate Request message may further carry the Serving Network (SN) name of the UE. The SN may be the network in which UE initiates the registration request. The Nausf_UEAuthentication_Authenticate Request message may further carry a PLMNNPN service indication. The details on the PLMNNPN service indication are described in previous embodiments and are omitted herein for the sake of simplicity.
[0135] Step 3: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, if the message carries PLMNNPN UE ID, SPNF1 in customer premises may generate a temporary UE ID based on PLMNNPN UE ID, and replace the PLMNNPN UE ID with temporary UE ID. Then SPNF1 in customer premises sends the Nausf_UEAuthentication_Authenticate Request message to SPNF2 in the operator premise, carrying the temporary UE ID.
[0136] Step 4: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, if the message carries temporary UE ID is received, SPNF2 may obtain the SUPI via, for example, decrypting the temporary UE ID, or mapping the temporary UE ID to the SUPI. SPNF2 may then forward the Nausf_UEAuthentication_Authenticate Request message to AUSF carrying the SUPI.
[0137] If SPNF1 fails to obtain the SUPI from PLMNNPN UE ID, the SPNF may respond to AMF1 with a failure cause. AMF1 may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIG. 9) .
[0138] If the request message carries SUCI of the UE, SPNF2 may forward the Nausf_UEAuthentication_Authenticate Request message to the AUSF carrying the SUCI.
[0139] Step 5: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF sends an Nudm_UEAuthentication_Get Request to UDM. The Nudm_UEAuthentication_Get Request may carry at least one of: SUCI of UE; SUPI of UE; or the serving network name of the UE.
[0140] Step 6: Upon receiving the Nudm_UEAuthentication_Get Request, if SUCI is received, the UDM may invoke the Subscription Identifier De-concealing Function (SIDF) to de-conceal SUCI to obtain the SUPI, before UDM can process the request. For each Nudm_Authenticate_Get Request, the UDM / ARPF shall create an authentication vector.
[0141] Steps 7-8: The AUSF sends the AV in Nausf_UEAuthentication_UEAuthentication Response message to AMF1 using SPNF2 as relay.
[0142] Step 9: The AMF1 may send an authentication request message to the UE, and UE may respond with an authentication response message carrying an authentication challenge result (RES*) .
[0143] Step 10: The AMF1 may send an Nausf_UEAuthentication_Authenticate Request message to AUSF carrying RES*.
[0144] Step 11: The AUSF may indicate to the AMF1 via SPNF2 in an Nausf_UEAuthentication_Authenticate Response message whether the authentication was successful or not from the home network point of view. If the authentication was successful, the anchor key (KSEAF) will be sent to the AMF1 in the Nausf_UEAuthentication_Authenticate Response message.
[0145] In case the AUSF received a SUCI from AMF1 in the authentication request (in step 4) , and if the authentication was successful, then the AUSF may also include the SUPI of the UE in the Nausf_UEAuthentication_Authenticate Response message.
[0146] Step 12: The SPNF2 translates the SUPI to temporary UE ID and forward the message to SPNF1 in the customer premise, and forward the Nausf_UEAuthentication_Authenticate Response to AMF1 via SPNF1, carrying the temporary UE ID. In some example implementations, the temporary UE ID may be same as the temporary UE ID received in step 3. In some example implementations, based on a local policy, the PLMN network in the operator premises may need to update / refresh the temporary UE ID (received in step 3) . In this case, SPNF2 may generate a new temporary UE ID. In the response message, SPNF2 may add both old Temporary UE ID and new Temporary UE ID to it.
[0147] Step 13: The SPNF1 in customer premises generate a PLMNNPN UE ID If the SPNF in customer premises does not have one. If the The SPNF1 in customer premises receive a new temporary UE ID, the SPNF1 update the temporary UE ID accordingly. If the network wants to updated the PLMNNPN UE ID, the SPNF1 generate a new PLMNNPN UE ID.
[0148] Step 14: The AMF1 sends UE a registration accept message to UE if the authentication is passed. AMF1 may assign a new 5G-GUTI for the UE.
[0149] In some scenarios, AMF1 in customer premises needs to transfer UE context to AMF2 in the operator premises. For example, AMF1 may be the old AMF for the UE, and AMF2 may be the new AMF for the UE. There are two cases which are described below.
[0150] Case 1: UE context transfer during the mobility registration (shown in FIG. 11B)
[0151] Step 15: The UE may send a registration request message carrying 5G-GUTI (received from step 9) to AMF2 in the operator premises.
[0152] Step 16: AMF2 sends an Namf_Communication_UEContextTransfer message to the AMF1 in the customer premises via SPNF2 and SPNF1.
[0153] Step 17: AMF1 responds to AMF2 in the operator premises via SPNF1 and SPNF2, with an Namf_Communication_UEContextTransfer response message carrying the UE context. The UE context may include PLMNNPN UE ID.
[0154] Step 18: Based on the PLMNNPN UE ID generation method (e.g., encryption, mapping) , SPNF1 may generate a temporary UE ID. For example, SPNF1 may encrypt the PLMNNPN UE ID to obtain temporary UE ID for the UE. For another example, the SPNF may use the mapping of (temporary UE ID, PLMNNPN UE ID) to obtain the temporary UE ID for the UE.
[0155] If SPNF1 fails to obtain the temporary UE ID, it may send a response to AMF1 indicating the failure of obtaining the temporary UE ID. Triggered by this failure indication, AMF1 may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIGs. 11A-11B) .
[0156] Step 19: Based on the PLMNNPN UE ID generation method as described earlier, the SPNF2 in operator premises may obtain SUPI of UE, based on the temporary UE ID. If SPNF2 fails to obtain the SUPI, it may send a message to AMF2 indicating such failure. Triggered by this failure indication, AMF2 may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIGs. 11A-11B) .
[0157] Step 20: AMF2 may send a registration accept message to the UE carrying a newly assigned 5G-GUTI. The new 5G-GUTI points to the AMF2 (which is the new AMF serving the UE) .
[0158] Case 2: UE context transfer during the N2 handover (not shown in FIGs. 11A-11B)
[0159] In this scenario, AMF1 in the customer premises is the source AMF, and the AMF2 in the operator premises is the target AMF.
[0160] Upon reception of the NGAP HANDOVER REQUIRED message, AMF1 may send a Namf_Communication_CreateUEContext Request message to AMF2 (e.g., via SPNF1 and SPNF2) . SPNF1 may replace PLMNNPN UE ID in the UE context with a Temporary UE ID.
[0161] If SPNF1 fails to obtain the temporary UE ID, it may send a response to AMF1 indicating the failure of obtaining the temporary UE ID. Triggered by this failure indication, AMF1 may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIGs. 11A-11B) .
[0162] Upon receiving the message carrying the UE context from SPNF1, based on the PLMNNPN UE ID generation method as described earlier, the SPNF2 in operator premises may obtain SUPI of UE. If SPNF2 fails to obtain the SUPI, it may send a message to AMF2 indicating such failure. Triggered by this failure indication, AMF2 may then initiate an identity request procedure with the UE, to obtain the SUCI of the UE, and trigger a primary authentication with UE (not show in FIGs. 11A-11B) .
[0163] Embodiment 6: UE Authentication via AMF in Operator Premises with SPNF Deployed in Operator Premises
[0164] In this embodiment, additional low-level details are provided for a UE authentication procedure involving UE context transfer. The UE in the customer premises initiates the authentication procedure with an AMF deployed in the operator premises, utilizing an SPNF located in the operator premises. The network deployment includes two security domains. For example, one security domain is the customer premises and the other security domain is the operator premises. The SPNF may be a stand alone entity / function, or may be co-located with an existing entity / function, such as a UDM. FIG. 12 illustrates an example according to this embodiment. An exemplary method may include a portion or all of the following steps.
[0165] Steps 1-9: The UE is authenticated via AMF2 in the operator premises.
[0166] In some scenarios, AMF2 in operator premises needs to transfer UE context to AMF1 in the customer premises. For example, AMF2 may be the old AMF for the UE, and AMF1 may be the new AMF for the UE. There are two cases which are described below.
[0167] Case 1: UE context transfer during the mobility registration (shown in FIG. 12)
[0168] Step 10: The UE may send a registration request message carrying 5G-GUTI (received from step 9) to AMF1 in the customer premises.
[0169] Step 11: AMF1 sends a Namf_Communication_UEContextTransfer message to the AMF2 in the operator premises, using the SPNF as a relay / bridge.
[0170] Step 12: Using the SPNF as a relay / bridge, AMF2 may respond to AMF1 with the UE context. The UE context includes SUPI of the UE.
[0171] Step 13. The SPNF generates a PLMNNPN UE ID and replace the SUPI in the UE context with PLMNNPN UE ID.
[0172] Step 14: AMF1 in the customer premises may send a registration accept message to the UE carrying a new 5G-GUTI. The new 5G-GUTI points to AMF1 (which is the new AMF serving the UE) .
[0173] Case 2: UE context transfer during the N2 handover (not shown in FIG. 12)
[0174] In this scenario, AMF2 in the operator premises is the source AMF, and the AMF1 in the customer premises is the target AMF.
[0175] Upon reception of the NGAP HANDOVER REQUIRED message, AMF2 may send a Namf_Communication_CreateUEContext Request message to AMF1, via SPNF. The UE context may include SUPI of the UE. The SPNF, which is located in the operator premises, may need to replace the SUPI with the PLMNNPN UE ID of the UE.
[0176] Embodiment 7: UE Authentication via AMF in Operator Premises with SPNFs Deployed in Both Customer Premises and Operator Premises
[0177] In this embodiment, additional low-level details are provided for a UE authentication procedure involving UE context transfer. The UE in the customer premises initiates the authentication procedure with an AMF deployed in the operator premises, utilizing an SPNF located in the operator premises. The network deployment includes two security domains. For example, one security domain is the customer premises and the other security domain is the operator premises. The SPNF may be a stand alone entity / function, or may be co-located with an existing entity / function, such as a UDM. FIG. 13 illustrates an example according to this embodiment. An exemplary method may include a portion or all of the following steps.
[0178] Steps 1-9: The UE is authenticated via AMF2 in the operator premises.
[0179] In some scenarios, AMF2 in operator premises needs to transfer UE context to AMF1 in the customer premises. For example, AMF2 may be the old AMF for the UE, and AMF1 may be the new AMF for the UE. There are two cases which are described below.
[0180] Case 1: UE context transfer during the mobility registration (shown in FIG. 13)
[0181] Step 10: The UE may send a registration request message carrying 5G-GUTI (received from step 9) to AMF1 in the customer premises.
[0182] Step 11: AMF1 sends a Namf_Communication_UEContextTransfer message to the AMF2 in the operator premises, using SPNF1 and SPNF2 as relays / bridges.
[0183] Step 12: Using the SPNF as a relay / bridge, AMF2 may respond to AMF1 with the UE context. The UE context includes SUPI of the UE.
[0184] Step 13. SPNF2 generates a temporary PLMNNPN UE ID and replace the SUPI in the UE context with the temporary PLMNNPN UE ID.
[0185] Step 14: SPNF1 in customer premises generates PLMNNPN UE ID and replace the temporary UE ID in the UE context with PLMNNPN UE ID.
[0186] Step 15: AMF1 in the customer premises may send a registration accept message to the UE carrying a new 5G-GUTI. The new 5G-GUTI points to AMF1 (which is the new AMF serving the UE) .
[0187] Case 2: UE context transfer during the N2 handover (not shown in FIG. 13)
[0188] In this scenario, AMF2 in the operator premises is the source AMF, and the AMF1 in the customer premises is the target AMF.
[0189] Upon reception of the NGAP HANDOVER REQUIRED message, AMF2 may send a Namf_Communication_CreateUEContext Request message to AMF1, via SPNF1 and SPNF2. Specifically, the UE context from AMF2 may include SUPI of the UE. The SPNF2, which is located in the operator premises, may need to replace the SUPI in the UE context with a temporary PLMNNPN UE ID of the UE. The SPNF1, upon receiving the UE context, may generate a PLMNNPN UE ID and use it to replace the temporary PLMNNPN UE ID in the UE context. SPNF1 then forward the UE context (now with PLMNNPN UE ID) to AMF1.
[0190] In this disclosure, message types and / or message names (e.g., as shown in FIGs. 7-13) are for exemplary purpose only. Different message types and / or message names may be chosen in implementation, and should still be covered by this disclosure, as far as the underlying principle is the same, for example, if the messages are used for a same purpose.
[0191] In this disclosure, a single information element in a message may be split into multiple information elements. Multiple information element may also be combined into a single information element.
[0192] In this disclosure, the steps in each embodiment are for illustration purposes only and other alternatives may be derived based on the disclosed embodiments as desired. For example, only part of the steps may need to be performed. For another example, the sequence of the steps may be adjusted. For another example, several steps may be combined (e.g., several messages may be combined in one message) . For yet another example, a single step may be split (e.g., one message may be sent via two sub-messages) .
[0193] The embodiments described in this disclosure are for exemplary purpose. Multiple embodiments may be combined, to form a new embodiment.
[0194] The accompanying drawings and description above provide specific example embodiments and implementations. The described subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is intended to be construed as not being limited to any example embodiments set forth herein. A reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, systems, or non-transitory computer-readable media for storing computer codes. Accordingly, embodiments may, for example, take the form of hardware, software, firmware, storage media or any combination thereof. For example, the method embodiments described above may be implemented by components, devices, or systems including memory and processors by executing computer codes stored in the memory.
[0195] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase “in one embodiment / implementation” as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment / implementation” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter includes combinations of example embodiments in whole or in part.
[0196] In general, terminology may be understood at least in part from usage in context. For example, terms, such as “and” , “or” , or “and / or, ” as used herein may include a variety of meanings that may depend at least in part on the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a, ” “an, ” or “the, ” may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for existence of additional factors not necessarily expressly described, again, depending at least in part on context.
[0197] Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present solution should be or are included in any single implementation thereof. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, discussions of the features and advantages, and similar language, throughout the specification may, but do not necessarily, refer to the same embodiment.
[0198] Furthermore, the described features, advantages and characteristics of the present solution may be combined in any suitable manner in one or more embodiments. One of ordinary skill in the relevant art will recognize, in light of the description herein, that the present solution can be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the present solution.
Claims
1.A method for wireless communication, performed by a first network element, comprising:receiving, from a second network element, a first message associated with a service request for a wireless device, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device;a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device;a Serving Network (SN) name of an SN serving the wireless device; ora service indicator indicating that the service request is initiated from a security domain different from the first network element; andtransmitting, to a third network element, a second message based on the first message, the second message carrying at least one of:the SUCI of the wireless device;the UE identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; orthe SN name of the SN serving the wireless device.2.The method of claim 1, wherein the first network element comprises a Security for Public Land Mobile Network Non Public Network (PLMNNPN) network function.3.The method of claim 1, wherein the second network element comprises an Access and Mobility Management Function (AMF) .4.The method of claim 1, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.5.The method of claim 1, wherein the first network element is in a first security domain and the second network element is in a second security domain different from the first security domain.6.The method of claim 5, wherein the first security domain comprises an operator premises and the second security domain comprises a customer premises.7.The method of any one of claims 1-6, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the UE identifier of the wireless device;the identifier of the second network element;an indicator indicating that the service request is initiated from a customer premises; ora name or a type of the first message.8.The method of any one of claims 1-7, wherein the first message comprises at least one of:an authentication message;a UE context transfer message; oran N2 handover message.9.The method of one of claims 1-7, wherein the service request comprises at least one of:an authentication service request;a UE context transfer service request; ora handover service request.10.The method of any one of claims 1-7, wherein the first message comprises the UE identifier of the wireless device, the method further comprising de-concealing the UE identifier of the wireless device via at least one of:decrypting the UE identifier to obtain the SUPI of the wireless device; ormapping the UE identifier to the SUPI of the wireless device.11.The method of claim 10, further comprising:in response to a failure of the de-concealing, transmitting, to the second network element, a response message to the first message indicating the failure.12.The method of claim 11, wherein the response message causes the second network element to trigger a primary authentication with the wireless device.13.The method of any one of claims 1-7, further comprising:receiving, from the third network element, a third message as a response to the second message, the third message comprising the SUPI of the wireless device.14.The method of claim 13, further comprising generating the UE identifier of the wireless device via at least one of:encrypting the SUPI of the wireless device to obtain the UE identifier of the wireless device; ormapping the SUPI of the wireless device to the UE identifier of the wireless device.15.The method of any one of claims 13-14, further comprising:transmitting, to the second network element, a fourth message as a response to the first message, the fourth message comprising the UE identifier of the wireless device.16.The method of any one of claims 13-14, wherein:the second message comprises an Nausf_UEAuthentication_Authenticate Request message; andthe third message comprises an Nausf_UEAuthentication_Authenticate Response message.17.The method of any one of claims 1-7, further comprising:receiving, from the second network element, a seventh message carrying UE context of the wireless device, the UE context comprising the UE identifier of the wireless device; andtransmitting, to a fourth network element, an eighth message carrying the UE context, wherein the UE identifier of the wireless device in the UE context is replaced with the SUPI of the wireless device.18.A method for wireless communication, performed by a first network element in a first security domain, comprising:receiving, from a second network element in a second security domain different from the first security domain, a first message associated with a service request for a wireless device, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device;a temporary User Equipment (UE) identifier of the wireless device that is concealed from a UE identifier of the wireless device by the second network element;a Serving Network (SN) name of an SN serving the wireless device; ora service indicator indicating that the service request is initiated from a security domain different from the first network element; andtransmitting, to a third network element, a second message based on the first message, the second message carrying at least one of:the SUCI of the wireless device;a UE identifier of the wireless device de-concealed from the temporary UE identifier and is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; orthe SN name of the SN serving the wireless device.19.The method of claim 18, wherein each of the first network element and the second network element comprises a Security for Public Land Mobile Network Non Public Network (PLMNNPN) network function.20.The method of claim 18, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.21.The method of claim 18, wherein the temporary UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.22.The method of claim 18, wherein the first security domain comprises an operator premises and the second security domain comprises a customer premises.23.The method of any one of claims 18-22, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the UE identifier of the wireless device;an identifier of a network element that is in the second security domain and is associated with the service request;an indicator indicating that the service request is initiated from a customer premises; ora name or a type of the first message.24.The method of any one of claims 18-23, wherein the first message comprises at least one of:an authentication message;a UE context transfer message; oran N2 handover message.25.The method of one of claims 18-23, wherein the service request comprises at least one of:an authentication service request;a UE context transfer service request; ora handover service request.26.The method of any one of claims 18-23, wherein the first message comprises the temporary UE identifier of the wireless device, the method further comprising de-concealing the temporary UE identifier of the wireless device via at least one of:decrypting the temporary UE identifier to obtain the SUPI of the wireless device; ormapping the temporary UE identifier to the SUPI of the wireless device.27.The method of claim 26, further comprising:in response to a failure of the de-concealing, transmitting, to the second network element, a response message to the first message indicating the failure.28.The method of claim 27, wherein the response message causes the second network element to indirectly trigger the wireless device to perform a primary authentication procedure.29.The method of any one of claims 18-23, further comprising:receiving, from the third network element, a third message as a response to the second message, the third message comprising the SUPI of the wireless device.30.The method of claim 29, further comprising one of:generating the temporary UE identifier of the wireless device via at least one of:encrypting the SUPI of the wireless device to obtain the temporary UE identifier of the wireless device; ormapping the SUPI of the wireless device to the temporary UE identifier of the wireless device; orgenerating an updated temporary UE identifier of the wireless device via at least one of:encrypting the SUPI of the wireless device to obtain the updated temporary UE identifier of the wireless device; ormapping the SUPI of the wireless device to the updated temporary UE identifier of the wireless device.31.The method of any one of claims 29-30, further comprising:transmitting, to the second network element, a fourth message as a response to the first message, the fourth message comprising the temporary UE identifier of the wireless device or the updated temporary UE identifier of the wireless device.32.The method of any one of claims 29-30, wherein:the second message comprises an Nausf_UEAuthentication_Authenticate Request message; andthe third message comprises an Nausf_UEAuthentication_Authenticate Response message.33.The method of any one of claims 29-30, wherein the third network element comprises an authentication server function (AUSF) .34.The method of any one of claims 18-23, further comprising:receiving, from the second network element, a seventh message carrying UE context of the wireless device, the UE context comprising the temporary UE identifier of the wireless device; andtransmitting, to a fourth network element, an eighth message carrying the UE context, wherein the UE identifier of the wireless device in the UE context is replaced with the SUPI of the wireless device.35.The method of claim 34, wherein before transmitting the eighth message, the method further comprises de-concealing the temporary UE identifier of the wireless device to obtain the SUPI of the wireless device.36.A method for wireless communication, performed by a first network element in a first security domain, comprising:receiving, from a third NE in the first security domain, a first message associated with a service request for a wireless device, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device;a User Equipment (UE) identifier of the wireless device; ora Serving Network (SN) name of an SN serving the wireless device; andtransmitting, to a second network element in a second security domain different from the first security domain, a second message associated with the service request for the wireless device, the second message carrying at least one of:a temporary UE identifier of the wireless device that is concealed from the UE identifier of the wireless device by the second network element;the Serving Network (SN) name of the SN serving the wireless device; ora service indicator indicating that the service request is initiated from a security domain different from the first network element.37.The method of claim 36, wherein each of the first network element and the second network element comprises a Security for Public Land Mobile Network Non Public Network (PLMNNPN) network function.38.The method of claim 36, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.39.The method of claim 36, wherein the temporary UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.40.The method of claim 36, wherein the temporary UE identifier of the wireless device is only allowed to be exchanged between the first network element and the second network element.41.The method of claim 36, wherein the first security domain comprises a customer premises and the second security domain comprises an operator premises.42.The method of any one of claims 36-41, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the UE identifier of the wireless device;an identifier of a network element that is in the second security domain and is associated with the service request;an indicator indicating that the service request is initiated from a customer premises; ora name or a type of the second message.43.The method of any one of claims 36-42, wherein the second message comprises at least one of:an authentication message;a UE context transfer message; oran N2 handover message.44.The method of one of claims 36-42, wherein the service request comprises at least one of:an authentication service request;a UE context transfer service request; ora handover service request.45.The method of any one of claims 36-42, wherein the second message comprises the temporary UE identifier of the wireless device, the method further comprising concealing the UE identifier of the wireless device to obtain the temporary UE identifier of the wireless device via at least one of:encrypting the UE identifier to obtain the temporary UE identifier of the wireless device; ormapping the UE identifier to the temporary UE identifier of the wireless device.46.The method of any one of claims 36-42, further comprising:receiving, from the second network element, a third message as a response to the second message, the third message comprising the temporary UE identifier of the wireless device or an updated temporary UE identifier of the wireless device.47.The method of claim 46, further comprising one of:obtaining the UE identifier of the wireless device via at least one of:decrypting the temporary UE identifier of the wireless device to obtain the UE identifier of the wireless device; ormapping the temporary UE identifier of the wireless device to the UE identifier of the wireless device; orgenerating an updated UE identifier of the wireless device via at least one of:decrypting the updated temporary UE identifier of the wireless device to obtain an updated UE identifier of the wireless device; ormapping the updated temporary UE identifier of the wireless device to the updated UE identifier of the wireless device.48.The method of any one of claims 46-47, wherein:the second message comprises an Nausf_UEAuthentication_Authenticate Request message; andthe third message comprises an Nausf_UEAuthentication_Authenticate Response message.49.The method of claim 47, further comprising:transmitting, to the third network element, a fourth message as a response to the first message, the fourth message comprising the UE identifier of the wireless device or the updated UE identifier of the wireless device.50.The method of any one of claims 36-42, further comprising:receiving, from the third network element, a fifth message carrying UE context of the wireless device, the UE context comprising the UE identifier of the wireless device; andtransmitting, to the second network element, a sixth message carrying the UE context, wherein the UE identifier of the wireless device in the UE context is replaced with the temporary UE identifier of the wireless device.51.The method of claim 50, wherein before transmitting the sixth message, the method further comprises concealing the UE identifier of the wireless device to obtain the temporary UE identifier of the wireless device.52.A device or a network element comprising a memory for storing computer instructions and a processor in communication with the memory, wherein the processor, when executing the computer instructions, is configured to implement a method in any one of claims 1-51.53.A computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon, the computer code, when executed by one or more processors, causing the one or more processors to implement a method of any one of claims 1-51.
Citation Information
Patent Citations
Network relay security
CN117204039A
Methods and systems for mitigating denial of service (DOS) attack in a wireless network
WO2020175941A1
Method and apparatus for selecting authentication mechanism for personal internet-of-things device, UE, network function, and storage medium
WO2023226051A1