Method, device and system for SUPI protection in communication networks

The introduction of the PLMN-NPN UE ID and associated network functions addresses the security risks in interconnecting public and private wireless networks by encrypting and protecting sensitive user subscription data across different security domains.

WO2025156430A1PCT designated stage Publication Date: 2025-07-31ZTE CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/085892
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-03
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

The interconnection between public and private wireless networks poses significant security challenges, particularly in protecting sensitive user subscription data such as SUPI, which is vulnerable to exposure and privacy breaches when transmitted across different security domains.

Method used

Introduce an alternative UE identifier, PLMN-NPN UE ID, derived from SUPI and encrypted for secure transmission across security domains, and implement network functions like SPNF to manage the transformation and protection of this identifier.

Benefits of technology

Ensures the confidentiality and integrity of sensitive user data by preventing unauthorized exposure and maintaining user privacy during inter-domain communication, thereby enhancing network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024085892_31072025_PF_FP_ABST
    Figure CN2024085892_31072025_PF_FP_ABST
Patent Text Reader

Abstract

This disclosure generally relates to protecting sensitive user subscription data in wireless communication. Performed by first network element, the method includes: receiving, from a wireless device, a first message for a service request with a wireless network, the first message carrying at least one of: a SUCI of the wireless device; or a first 5G-GUTI of the wireless device; and transmitting, to a second network element, a second message for authentication request, the second message carrying at least one of: a SN name of an SN serving the wireless device; the SUCI of the wireless device; a UE identifier of the wireless device that is associated with a SUPI of the wireless device; a service indicator indicating that a service associated with the second message is initiated from a security domain different from the second network element; or an identifier of the first network element.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, DEVICE AND SYSTEM FOR SUPI PROTECTION IN COMMUNICATION NETWORKSTECHNICAL FIELD

[0001] This disclosure relates to wireless communication, and in particular, to protect sensitive user subscription data in a communication network, such as 4G, 5G, and 6G wireless communication network.BACKGROUND

[0002] The proliferation of mobile devices and increasing data demands have led to the widespread deployment of public wireless networks by mobile operators, as well as private wires networks by enterprises. Private wireless networks are typically deployed within a defined geographic area, such as a campus, factory, or facility. The interconnection between public wireless networks and private wireless networks presents a significant challenge from a security perspective. It is crucial to establish secure inter-network operations that enable seamless and protected communication between these two distinct network environments. Implementing robust security measures at the interface of public and private wireless networks is critical to ensure the confidentiality and integrity of wireless communications.SUMMARY

[0003] This disclosure discloses methods, systems, devices, and storage medium relates to wireless communication, and in particular, to protecting sensitive user subscription data in a wireless communication network, such as 4G, 5G, and 6G wireless communication network, as well as private network.

[0004] In one embodiment, the present disclosure describes a method for wireless communication. Performed by a first network element, the method includes: receiving,  from a wireless device, a first message for a service request with a wireless network, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; or a first 5G Global Unique Temporary Identifier (5G-GUTI) of the wireless device; and transmitting, to a second network element, a second message for authentication request, the second message carrying at least one of: a Serving Network (SN) name of an SN serving the wireless device; the SUCI of the wireless device; a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; a service indicator indicating that a service associated with the second message is initiated from a security domain different from the second network element; or an identifier of the first network element.

[0005] In another embodiment, a method for wireless communication is disclosed. Performed by a first network element, the method includes: receiving, from a wireless device, a first message for a service request with a wireless network, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; a first 5G Global Unique Temporary Identifier (5G-GUTI) of the wireless device; and transmitting, to a second network element, a second message for authentication request, the second message carrying at least one of: a Serving Network (SN) name of an SN serving the wireless device; the SUCI of the wireless device; a Subscription Permanent Identifier (SUPI) of the wireless device; a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; a service indicator indicating that a service associated with the second message is initiated from a security domain different from the first network element; or an identifier of the first network element.

[0006] In another embodiment, a method for wireless communication is disclosed. Performed by a first network element, the method includes: receiving, from a second network element, a first message for an authentication request initiate from a wireless device, the first message carrying at least one of: a Serving Network (SN) name of an SN serving the wireless device; a SUCI of the wireless device; a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; an identifier of the  second network element; or a service indicator indicating that a service associated with the first message is initiated from a security domain different from the first network element; and an indication that the authentication request for the wireless device is initiated from a first security domain that is different from a second security domain to which the first network element belongs; and transmitting, to a third network element, a second message for authentication request for the wireless device, the second message carrying at least one of: the SN name of an SN serving the wireless device; the SUCI of the wireless device; the UE identifier of the wireless device that is associated with the SUPI of the wireless device; an identifier of the second network element; or the indication that the authentication request for the wireless device is initiated from the first security domain that is different from the second security domain to which the first network element belongs.

[0007] In another embodiment, a network element or wireless device comprising a processor and a memory is disclosed. The processor may be configured to read computer code from the memory to implement any of the methods above.

[0008] In yet another embodiment, a computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon is disclosed. The computer code, when executed by a processor, may cause the processor to implement any one of the methods above.

[0009] The above embodiments and other aspects and alternatives of their implementations are explained in greater detail in the drawings, the descriptions, and the claims below.BRIEF DESCRIPTION OF THE DRAWINGS

[0010] FIG. 1 shows an exemplary communication network including various terminal devices, a carrier network, data network, and service applications.

[0011] FIG. 2 shows exemplary network functions or network nodes in a communication network.

[0012] FIG. 3 shows exemplary network functions or network nodes in a wireless communication network.

[0013] FIG. 4 shows an exemplary network model for a Non Public Network (NPN) hosted by a Public Land Mobile Network (PLMN) .

[0014] FIG. 5 shows an example wireless network node (or network element, network function, network entity, entity, application function) .

[0015] FIG. 6 shows an example user equipment.

[0016] FIG. 7 shows an exemplary logic flow for interaction between NPN and PLMN with SUPI protection.

[0017] FIG. 8 shows another exemplary logic flow for interaction between NPN and PLMN with SUPI protection.DETAILED DESCRIPTION

[0018] An exemplary communication network, shown as 100 in FIG. 1, may include terminal devices 110 and 112, a carrier network 102, various service applications 140, and other data networks 150. The carrier network 102, for example, may include access networks 120 and a core network 130. The carrier network 102 may be configured to transmit voice, data, and other information (collectively referred to as data traffic) among terminal devices 110 and 112, between the terminal devices 110 and 112 and the service applications 140, or between the terminal devices 110 and 112 and the other data networks 150. Communication sessions and corresponding data paths may be established and configured for such data transmission. The Access networks 120 may be configured to provide terminal devices 110 and 112 network access to the core network 130. The Access network 120 may, for example, support wireless access via radio resources, or wireline access. The core network 130 may include various network nodes or network functions configured to control the communication sessions and perform network access management  and data traffic routing. The service applications 140 may be hosted by various application servers that are accessible by the terminal devices 110 and 112 through the core network 130 of the carrier network 102. A service application 140 may be deployed as a data network outside of the core network 130. Likewise, the other data networks 150 may be accessible by the terminal devices 110 and 112 through the core network 130 and may appear as either data destination or data source of a particular communication session instantiated in the carrier network 102.

[0019] The core network 130 of FIG. 1 may include various network nodes or functions geographically distributed and interconnected to provide network coverage of a service region of the carrier network 102. These network nodes or functions may be implemented as dedicated hardware network elements. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or as software entities. A network node may each be configured with one or more types of network functions. These network nodes or network functions may collectively provide the provisioning and routing functionalities of the core network 130. The term “network nodes” and “network functions” are used interchangeably in this disclosure.

[0020] FIG. 2 further shows an exemplary division of network functions in the core network 130 of a communication network 200. While only single instances of network nodes or functions are illustrated in FIG. 2, those having ordinary skill in the art readily understand that each of these network nodes may be instantiated as multiple instances of network nodes that are distributed throughout the core network 130. As shown in FIG. 2, the core network 130 may include but is not limited to network nodes such as access management network node (AMNN) 230, authentication network node (AUNN) 260, network data management network node (NDMNN) 270, session management network node (SMNN) 240, data routing network node (DRNN) 250, policy control network node (PCNN) 220, and application data management network node (ADMNN) 210. Exemplary signaling and data exchange between the various types of network nodes through various communication interfaces are indicated by the various solid connection lines in FIG. 2.  Such signaling and data exchange may be carried by signaling or data messages following predetermined formats or protocols.

[0021] The implementations described above in FIGs. 1 and 2 may be applied to both wireless and wireline communication systems. FIG. 3 illustrates an exemplary cellular wireless communication network 300 based on the general implementation of the communication network 200 of FIG. 2. FIG. 3 shows that the wireless communication network 300 may include user equipment (UE) 310 (functioning as the terminal device 110 of FIG. 2) , radio access network (RAN) 320 (functioning as the access network 120 of FIG. 2) , data network (DN) 150, and core network 130 including access management function (AMF) 330 (functioning as the AMNN 230 of FIG. 2) , session management function (SMF) 340 (functioning as the SMNN 240 of FIG. 2) , application function (AF) 390 (functioning as the ADMNN 210 of FIG. 2) , user plane function (UPF) 350 (functioning as the DRNN 250 of FIG. 2) , policy control function 322 (functioning as the PCNN 220 of FIG. 2) , authentication server function (AUSF) 360 (functioning as the AUNN 260 of FIG. 2) , and universal data management (UDM) function 370 (functioning as the UDMNN 270 of FIG. 2) . Again, while only single instances for some network functions or nodes of the wireless communication network 300 (the core network 130 in particular) are illustrated in FIG. 3, those of ordinary skill in the art readily understand that each of these network nodes or functions may have multiple instances that are distributed throughout the wireless communication network 300. While the AF 390 is depicted as part of the core network 130 in FIG. 3, they may be considered as associated with particular service applications 140 and may be considered as being outside of the core network 140. In this disclosure, various functions deployed in the wireless network as described above may also be referred to as function entities, which may be implemented as a network node, a network element, a logical function, via hardware, software, or a combination thereof.

[0022] In FIG. 3, the UE 310 may be implemented as various types of mobile devices that are configured to access the core network 130 via the RAN 320. The UE 310 may include but is not limited to mobile phones, laptop computers, tablets, Internet-Of-Things  (IoT) devices, distributed sensor network nodes, wearable devices, and the like. The UE may also be Multi-access Edge Computing (MEC) capable UE that supports edge computing. The RAN 320 for example, may include a plurality of radio base stations distributed throughout the service areas of the carrier network. The communication between the UE 310 and the RAN 320 may be carried in over-the-air (OTA) radio interfaces as indicated by 311 in FIG. 3.

[0023] Continuing with FIG. 3, the UDM 370 may form a permanent storage or database for user contract and subscription data. The UDM may further include an authentication credential repository and processing function (ARPF, as indicated in 370 of FIG. 3) for storage of long-term security credentials for user authentication, and for using such long-term security credentials as input to perform computation of encryption keys as described in more detail below. To prevent unauthorized exposure of UDM / ARPF data, the UDM / ARPF 370 may be located in a secure network environment of a network operator or a third-party.

[0024] The AMF / SEAF 330 may communicate with the RAN 320, the SMF 340, the AUSF 360, the UDM / ARPF 370, and the Policy Control Function (PCF) 322 via communication interfaces indicated by the various solid lines connecting these network nodes or functions. The AMF / SEAF 330 may be responsible for UE to non-access stratum (NAS) signaling management, and for provisioning registration and access of the UE 310 to the core network 130 as well as allocation of SMF 340 to support communication need of a particular UE. The AMF / SEAF 330 may be further responsible for UE mobility management. The AMF may also include a security anchor function (SEAF, as indicated in 330 of FIG. 3) that, as described in more detail below, and interacts with AUSF 360 and UE 310 for user authentication and management of various levels of encryption / decryption keys. The AUSF 360 may terminate user registration / authentication / key generation requests from the AMF / SEAF 330 and interact with the UDM / ARPF 370 for completing such user registration / authentication / key generation.

[0025] The SMF 340 may be allocated by the AMF / SEAF 330 for a particular communication session instantiated in the wireless communication network 300. The SMF  340 may be responsible for allocating UPF 350 to support the communication session and data flows therein in a user data plane and for provisioning / regulating the allocated UPF 350 (e.g., for formulating packet detection and forwarding rules for the allocated UPF 350) . Alternative to being allocated by the SMF 340, the UPF 350 may be allocated by the AMF / SEAF 330 for the particular communication session and data flows. The UPF 350 allocated and provisioned by the SMF 340 and AMF / SEAF 330 may be responsible for data routing and forwarding and for reporting network usage by the particular communication session. For example, the UPF 350 may be responsible for routing end-end data flows between UE 310 and the DN 150, between UE 310 and the service applications 140. The DN 150 and the service applications 140 may include but are not limited to data network and services provided by the operator of the wireless communication network 300 or by third-party data network and service providers.

[0026] The PCF 322 may be responsible for managing and providing various levels of policies and rules applicable to a communication session associated with the UE 310 to the AMF / SEAF 330 and SMF 340. As such, the AMF / SEAF 330, for example, may assign SMF 340 for the communication session according to policies and rules associated with the UE 310 and obtained from the PCF 322. Likewise, the SMF 340 may allocate UPF 350 to handle data routing and forwarding of the communication session according to policies and rules obtained from the PCF 322.

[0027] While FIGs. 1-3 and the various exemplary implementations described below are based on cellular wireless communication networks, the scope of this disclosure is not so limited and the underlying principles are applicable to other types of wireless and wireline communication networks.

[0028] Network identity and data security in the wireless communication network 300 of FIG. 3 may be managed via user authentication processes provided by the AMF / SEAF 330, the AUSF 360, and the UDM / ARPF 370. In particularly, the UE 310 may first communicate with AMF / SEAF 330 for network registration and may then be authenticated by the AUSF 360 according to user contract and subscription data in the UDM / ARPF 370.  Communication sessions established for the UE 310 after user authentication to the wireless communication network 300 may then be protected by the various levels of encryption / decryption keys. The generation and management of the various keys may be orchestrated by the AUSF 360 and other network functions in the communication network 300.

[0029] Security Domains -Operator Premises and Customer Premises

[0030] FIG. 4 illustrates an exemplary network model 400 that includes an operator premises and a customer premises. The operator premises may include, for example, a Unified Data Management (UDM) entity, a Network Exposure Function (NEF) entity, a Network Repository Function (NRF) entity, a Policy Control Function (PCF) entity, a User Plane Function (UPF) entity, an Authentication Server Function (AUSF) entity, an AMF entity, a Session Management Function (SMF) entity, and may further include an Application Function (AF) entity. The customer premises may include, for example an AMF entity, an SMF entity, a UPF entity, and a Data Network (DN) .

[0031] In the network model 400, the operator premises may include a Public Land Mobile Network (PLMN) , which is managed and operated by a public operator. The customer premises may include a private network, such as a Non-Public Network (NPN) by 3rd Generation Partnership Project (3GPP) . The NPN may be operated or manage by, for example, a private entity such as a private enterprise or a private operator. The NPN may be deployed as Stand-alone NPN (SNPN) , which do not rely on services or applications provided by a PLMN. The NPN may also be deployed as Public Network Integrated NPN (PNI-NPN) , which has inter-connection with a PLMN. In some example implementations, The PNI-NPN may share Radio Access Network (RAN) with a PLMN. In some example implementations, the PNI-NPN may share at least part of Control Plane (CP) functions and / or User Plane (UP) functions with a PLMN.

[0032] In wireless network such as a 5G network, a Service Based Architecture (SBA) framework is implemented to expose the functionality of various network elements to each  other. The SBA framework enhances network deployment flexibility by providing enriched configuration options. Through SBA implementation, various components and functions within the wireless network (including PLMN and private network) can seamlessly interact and leverage each other’s functions, facilitating more agile and modular network deployments that can adapt to diverse operational requirements.

[0033] In some network deployment as shown in FIG. 4, a dedicated UPF and part of CP functions are deployed in the customer premises. The dedicated Network Functions (NFs) in the customer premises may communicate with the NFs in the operator premise via the SBA interface. In this example deployment, the CP functions hosted by the NPN in the customer premises includes the AMF entity and the SMF entity.

[0034] In some other network deployments, a dedicated UPF is deployed in customer premises, which may interact with the operator premises via, for example, an N4 interface (non-SBA interface) .

[0035] FIG. 5 shows an example of electronic device 500 to implement various network nodes, network elements, network entities, such as a network base station (e.g., a radio access network node) , a core network (CN) , a core network element / entity (e.g., an AMF, a UDM, an AAnF, etc. ) , an operation and maintenance (OAM) , and the like. Optionally in one implementation, the example electronic device 500 may include radio transmitting / receiving (Tx / Rx) circuitry 508 to transmit / receive communication with UEs and / or other base stations. Optionally in one implementation, the electronic device 500 may also include network interface circuitry 509 to communicate the base station with other base stations and / or a core network, e.g., optical or wireline interconnects, Ethernet, and / or other data transmission mediums / protocols. The electronic device 500 may optionally include an input / output (I / O) interface 506 to communicate with an operator or the like.

[0036] The electronic device 500 may also include system circuitry 504. System circuitry 504 may include processor (s) 521 and / or memory 522. Memory 522 may include an operating system 524, instructions 526, and parameters 528. Instructions 526 may be  configured for the one or more of the processors 521 to perform the functions of the network node. The parameters 528 may include parameters to support execution of the instructions 526. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.

[0037] In this disclosure, a network function / network entity / entity, such as an AMF, an AUSF, a UDM, an AAnF, an NEF, an AF, may be implemented in hardware, software, a combination of hardware and software, and may be implemented or integrated in the electronic device 500. They may also be implemented as a logical entity hosted by the electronic device 500.

[0038] FIG. 6 shows an example of an electronic device to implement a terminal device 600 (for example, a UE) . The UE 600 may be a mobile device, for example, a smart phone or a mobile communication module disposed in a vehicle. The UE 600 may include a portion or all of the following: communication interfaces 602, a system circuitry 604, an input / output interfaces (I / O) 606, a display circuitry 608, and a storage 609. The display circuitry may include a user interface 610. The system circuitry 604 may include any combination of hardware, software, firmware, or other logic / circuitry. The system circuitry 604 may be implemented, for example, with one or more systems on a chip (SoC) , application specific integrated circuits (ASIC) , discrete analog and digital circuits, and other circuitry. The system circuitry 604 may be a part of the implementation of any desired functionality in the UE 600. In that regard, the system circuitry 604 may include logic that facilitates, as examples, decoding and playing music and video, e.g., MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user inputs; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections for, as one example, internet connectivity; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on the user interface 610. The user interface 610 and the inputs / output (I / O) interfaces 606 may include a graphical user interface, touch sensitive display, haptic feedback or other haptic output, voice or facial recognition inputs, buttons,  switches, speakers and other user interface elements. Additional examples of the I / O interfaces 606 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headset and microphone input  / output jacks, Universal Serial Bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors) , and other types of inputs.

[0039] Referring to FIG. 6, the communication interfaces 602 may include a Radio Frequency (RF) transmit (Tx) and receive (Rx) circuitry 616 which handles transmission and reception of signals through one or more antennas 614. The communication interface 602 may include one or more transceivers. The transceivers may be wireless transceivers that include modulation  / demodulation circuitry, digital to analog converters (DACs) , shaping tables, analog to digital converters (ADCs) , filters, waveform shapers, filters, pre-amplifiers, power amplifiers and / or other logic for transmitting and receiving through one or more antennas, or (for some devices) through a physical (e.g., wireline) medium. The transmitted and received signals may adhere to any of a diverse array of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM) , frequency channels, bit rates, and encodings. As one specific example, the communication interfaces 602 may include transceivers that support transmission and reception under the 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS) , High Speed Packet Access (HSPA) +, 4G  / Long Term Evolution (LTE) , 5G, and 6G standards. The techniques described below, however, are applicable to other wireless communications technologies whether arising from the 3rd Generation Partnership Project (3GPP) , GSM Association, 3GPP2, IEEE, or other partnerships or standards bodies.

[0040] Referring to FIG. 6, the system circuitry 604 may include one or more processors 621 and memories 622. The memory 622 stores, for example, an operating system 624, instructions 626, and parameters 628. The processor 621 is configured to execute the instructions 626 to carry out desired functionality for the UE 600. The parameters 628 may provide and specify configuration and operating options for the instructions 626. The memory 622 may also store any BT, WiFi, 3G, 4G, 5G, 6G or other data that the UE 600 will  send, or has received, through the communication interfaces 602. In various implementations, a system power for the UE 600 may be supplied by a power storage device, such as a battery or a transformer.

[0041] UE Identify Protection in Wireless Network

[0042] In wireless communication networks, in the primary authentication and authorization procedure, if a UE identity, such as the Subscription Permanent Identifier (SUPI) is available in clear text to the Network Functions (NFs) in customer premises, then it may potentially lead to security threats, privacy breaches, UE location tracking and targeted attacks.

[0043] Further, with the evolution of the roaming architectures (e.g., Roaming Hub) and Core Network (NPN, Edge computing) , distributed CN (multi-site CN) , as there is no direct trust relationship between Home Network (HN) and various other networks, such as Serving Network (SN) , Visiting PLMN (VPLMN) , and Edge network (i.e., between the different security domains) , there is serious security concern for the HN to expose permanent and / or sensitive information (e.g., UE identifiers and other parameter) to the NFs that are not in the HN.

[0044] In this disclosure, the term “security domain” is employed to denote a distinct realm encompassing a network infrastructure, physical premises, or entities involved in the network ecosystem. For various reason, in wireless networks (PLMN and NPN) , there are different security domains. The security domain may be classified by the owner / operator of the network. For example, a PLMN may be owned and / or operated by a communication service provider, whereas an NPN may be owned and / or operated by a private enterprise, a private entity, etc. The security domain may also be classified by regulatory compliance and risk management. For example, a PLMN may be categorized as relatively low risk when compared to an NPN. The embodiments described below may use the terms “customer domain” and “operator domain” to represent different security domains. The underlying concept and principles apply to all other types of security domains, irrespective of  specific terminology.

[0045] The privacy-sensitive SUPI is the home network operator-provided identifier used exclusively to identify its subscribers and related subscription information to handle the related services. A robust mechanism is essential to address the potential risks involved with sharing sensitive subscriber data across different security domains. Such mechanism is critical to protect sensitive information (e.g., SUPI) from risks that may arise when a PLMN hosts an NPN, and vice versa.

[0046] In this disclosure, the SUPI of a UE, as a sensitive piece of information associated with a user’s identity within the PLMN (whether it’s Home PLMN (HPLMN) or VPLMN) , should be protected to maintain user privacy and prevent security breaches. The SUPI of a UE is not allowed to be sent across security domains, or the SUPI is not allowed be transmitted between different security domains without proper protection mechanisms in place.

[0047] To accommodate the inter-connection between the two security domains, an alternative UE identifier is introduced. First, this newly introduced alternative UE identifier is distinct from various existing UE identifiers in wireless standards, such as SUCI, SUPI, or 5G-GUTI (5G Globally Unique Temporary Identifier) . Second, the alternative UE identifier may be dedicated for information exchange between the two security domains. Third, the alternative UE identifier may be derived or generated from the SUPI of the UE, but it may undergo a secure transformation process to ensure its confidentiality and integrity. For example, it may involve encrypting the SUPI using one or more security keys. Specifically, the transformation process differs from the process used to generate existing UE identifiers, such as SUCI. This ensure that even in the event that the alternative UE identifier is compromised in one security domain, other UE identifiers still remain secure and protected. In this disclosure, this newly introduce alternative UE identifier may be referred to as PLMN-NPN UE ID, or PLMNNPN UE ID, in the sense that it may be used across PLMN and NPN domains. The name is for exemplary purpose only and other names may be chosen to represent this alternative UE identifier.

[0048] There are multiple solutions to generate PLMN-NPN UE ID. In some example implementations, the PLMN-NPN UE ID may be generated from the SUPI of the UE, using encryption technologies. In some example implementations, a uniqure random number may be acquired and mapped to each SUPI, therefore the random number is a representation of SUPI via the mapping relationship. When a random number is received, it may be mapped back to the SUPI. As an extra layer of security protection, the random number may be further encrypted before passing between security domains. In some example implementations, once the PLMN-NPN UE ID is generated in one security domain, it may be passed to a different security domain for future use.

[0049] Embodiment 1: UE Authentication via AMF in Customer Premises with SPNF Co-located with UDM

[0050] In this embodiment, the network deployment includes two security domains. For example, as shown in FIG. 4, one security domain is the customer premises and the other security domain is the operator premises.

[0051] In this embodiment, the UE is in the customer premises, and may initiate service request using AMF1 deployed in the customer premises. The UE authentication may be initiated from AMF1. The exemplary steps of an AMF1 initiated UE registration / authentication procedure for are described in details below with reference to FIG. 7. An exemplary method may include a portion or all of the following steps. In this disclosure, the SEAF and AMF may be co-located, and the term SEAF and AMF may be used interchangeably. In some example implementations, the functions associated with both SEAF and AMF are performed by the same entity within the network. In FIG. 7, AMF1 is in a first security domain, such as a customer premise. AMF2 is in a second security domain, such as an operator premise.

[0052] Step 1: The UE sends a registration request message to AMF1. The registration request message may carry a SUCI or a 5G-GUTI of the UE. The AMF1 may implement a local policy such that, in case the registration request message carries the 5G-GUTI and the  5G-GUTI points to an AMF that is not in the same premises (or security domain) as AMF1 (e.g., AMF1 is in customer premises, whereas 5G-GUTI points to an AMF in operator premises) , then AMF1 may initiate an identity request procedure with the UE, to obtain the SUCI of the UE.

[0053] Step 2: The AMF1 may initiate a UE authentication procedure. For example, AMF1 may invoke an Nausf_UEAuthentication service by sending, for example, an Nausf_UEAuthentication_Authenticate Request message to the AUSF. The Nausf_UEAuthentication_Authenticate Request message may carry either SUCI or the newly introduced alternative UE ID -PLMNNPN UE ID. The Nausf_UEAuthentication_Authenticate Request message may further carry the Serving Network (SN) name of the UE. The SN may be the network in which UE initiates the registration request. The Nausf_UEAuthentication_Authenticate Request message may further carry a PLMNNPN service indication.

[0054] In this disclosure, the PLMNNPN service indication may indicate that the service request (or more broadly, message / signaling) is cross security domain. For example, the source of the message / request / signaling is in one security domain and the destination is in another security domain. As shown in FIG. 7, the PLMNNPN service indication indicates that the message is from the customer premises which is different from the operator premises. In a network deployment scenario in which both customer premises and operator premises are deployed, the PLMNNPN service indication indicates to network element in the operator premises that a corresponding message / request / signaling is from the customer premises.

[0055] In this disclosure, the PLMNNPN service indication may include at least one of:

[0056] ● The SN name (indicating the SN from which the message is initiated) ;

[0057] ● The PLMNNPN UE ID;

[0058] ● The AMF ID (indicating the AMF from which the message is initiated) ;

[0059] ● A PLMNNPN service indicator (e.g., represented as an Information Element (IE) , a bit, a parameter, etc. ) ; or

[0060] ● The name and / or type of the message / signaling (e.g., a keyword, a particular string in the message name) . As an example, the Nausf_UEAuthentication_Authenticate Request message may be renamed to “Nausf_PLMNNPN_UEAuthentication_Authenticate Request” .

[0061] Step 3: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF sends an Nudm_UEAuthentication_Get Request to UDM. The Nudm_UEAuthentication_Get Request may carry at least one of: SUCI of UE; PLMNNPN UE ID which is used in the customer premises; the serving network name of the UE; a PLMNNPN service indication, if it is carried in the Nausf_UEAuthentication_Authenticate Request message in step 2.

[0062] Step 4: Upon receiving the Nudm_UEAuthentication_Get Request, if SUCI is received, the UDM may invoke the Subscription Identifier De-concealing Function (SIDF) to de-conceal SUCI to obtain the SUPI, before UDM can process the request.

[0063] If PLMNNPN UE ID is received, a newly introduced function, namely Security for PLMNNPN Network Function (SPNF) , will be invoked in order to obtain SUPI of the UE. The SPNF is capable of de-concealing the PLMNNPN UE ID to obtain SUPI of the UE. For example, SPNF may decrypt the PLMNNPN UE ID to obtain SUPI of the UE. For another example, the SPNF may use the mapping of (SUPI, PLMNNPN UE ID) to obtain the SUPI of the UE.

[0064] As a response, the UDM may respond back to the AUSF with, for example, a Nudm_UEAuthentication_Get response message. The response message may carry an Authentication Vector (AV) created by the UDM (or ARPF) . If a SUCI is received in step 3, Nudm_Authenticate_Get Response may further contain a PLMNNPN UE ID which is newly created. On the other hand, if a PLMNNPN UE ID is received in step 3, there are two  options based on operator’s policy. In the first option, UDM may refresh / update the PLMNNPN UE ID, and the response message may carry the refreshed PLMNNPN UE ID. In the second option, there is no need to refresh the received PLMNNPN UE ID, and the PLMNNPN UE ID received in step 3 is carried in the response message.

[0065] Step 5: The AUSF may send an Nausf_UEAuthentication_UEAuthentication Response message to AMF1, carrying the AV.

[0066] Step 6: The AMF1 may send an authentication request message to the UE, and UE may respond with an authentication response message carrying an authentication challenge result (RES*) .

[0067] Step 7: The AMF1 may send an Nausf_UEAuthentication_Authenticate Request message to AUSF carrying RES*.

[0068] Step 8: The AUSF may indicate to the AMF1 in an Nausf_UEAuthentication_Authenticate Response message whether the authentication was successful or not from the home network point of view. If the authentication was successful, the anchor key (KSEAF) will be sent to the AMF1 in the Nausf_UEAuthentication_Authenticate Response message.

[0069] In case the AUSF received a SUCI or PLMNNPN UE ID from AMF1 in the authentication request (in step 2) , and if the authentication was successful, then the AUSF may also include the PLMNNPN UE ID in the Nausf_UEAuthentication_Authenticate Response message. In case AUSF received a SUCI in step 2, the PLMNNPN UE ID may be a newly created PLMNNPN UE ID. In case AUSF received a PLMNNPN UE ID in step 2, the PLMNNPN UE ID may be a refreshed PLMNNPN UE ID, or the original PLMNNPN UE ID sent in step 2.

[0070] AMF1, upon receiving the Nausf_UEAuthentication_Authenticate Response message, may derive its key, KAMF, from KSEAF, by using a Key Derivation Function (KDF) . The KSEAF, which may be 256 bits, is the input key for the KDF. The equation below may  be used to form the input string S to the KDF:

[0071] S = FC || P0 || L0 || P1 || L1 || P2 || L2 || P3 || L3 ||... || Pn || Ln

[0072] where:

[0073] “||” is the concatenation operator, n is an integer.

[0074] FC is used to distinguish between different instances of the algorithm. FC may be a single octet, or consists of two octets in the form of FC1|| FC2. Exemplarily, FC1 = 0xFF and FC2 is a single octet.

[0075] P0 ... Pn are the n+1 input parameters, and

[0076] L0 ... Ln are the two-octet representations of the length of the corresponding input parameter encodings P0 ... Pn.

[0077] In some example implementations, P0 is a predefined ASCII-encoded string.

[0078] The final output, i.e., the derived key is equal to the KDF computed on the string S using the input key. For example, derived key = HMAC-SHA-256 (Key, S)

[0079] As an example, the input may be set to:

[0080] FC = 0x6D (for illustration purpose only, may be set to other values) .

[0081] P0 = PLMNNPN UE ID (for illustration purpose only, depending on what is the UE identifier used in customer premise) .

[0082] L0 = P0 length -number of octets in P0.

[0083] P1 = ABBA parameter.

[0084] L1 = P1 length (e.g., number of octets in P1) .

[0085] The input key KEY is the 256-bit KSEAF.

[0086] Further note that for P0, PLMNNPN UE ID is used as an example. It may be any other UE identifier that is used in PLMN host NPN. P0 may be set to PLMNNPN UE ID in in a Network Access Identifier (NAI) format, i.e., username@realm.

[0087] Step 9: The AMF1 may send a registration accept message to the UE, if the authentication is successful. The AMF1 may assign a new 5G-GUTI for the UE.

[0088] In some scenarios, AMF1 in customer premises needs to transfer UE context to AMF2 in the operator premises. For example, AMF1 may be the old AMF for the UE, and AMF2 may be the new AMF for the UE There are two cases which are described below.

[0089] Case 1: UE context transfer during the mobility registration (shown in FIG. 7)

[0090] Step 10: The UE may send a registration request message carrying 5G-GUTI (received from step 9) to AMF2 in the operator premises.

[0091] Step 11: AMF2 sends a Namf_Communication_UEContextTransfer message to the AMF1 in the customer premises.

[0092] Step 12: AMF1 in the customer premises response to AMF2 in the operator premises with the UE context. The UE context may include PLMNNPN UE ID.

[0093] Step 13: AMF2 may decide to trigger a primary authentication between UE and the AMF2. AMF2 may send an identity request to the UE to request SUCI of the UE. Alternatively, AMF2 may request SUPI of the UE from the UDM, using PLMNNPN UE ID as input to the inquiry.

[0094] Step 14: AMF2 may send a registration accept message to the UE carrying a newly assigned 5G-GUTI. The new 5G-GUTI points to the AMF2 (which is the new AMF serving the UE) .

[0095] Case 2: UE context transfer during the N2 handover (not shown in FIG. 7)

[0096] In this scenario, AMF1 in the customer premises is the source AMF, and the  AMF2 in the operator premises is the target AMF.

[0097] Upon reception of the NGAP HANDOVER REQUIRED message, AMF1 may send a Namf_Communication_CreateUEContext Request message to AMF2. AMF2 in the operator premises may decide to trigger a primary authentication between UE and AMF2. AMF2 may send an identity request to the UE to request SUCI of the UE. Alternatively, AMF2 may request SUPI of the UE from the UDM, using PLMNNPN UE ID as input to the inquiry.

[0098] Embodiment 2: UE Authentication via AMF in Operator Premises with SPNF Co-located with UDM

[0099] In this embodiment, the network deployment includes two security domains. For example, one security domain is the customer premises and the other security domain is the operator premises. The UE is in the operator premises, and may initiate service request using AMF2 deployed in the operator premises. The UE authentication may be initiated from AMF2. The exemplary steps of an AMF2 initiated UE registration / authentication procedure are described in details below with reference to FIG. 8. An exemplary method may include a portion or all of the following steps.

[0100] Step 1: The UE sends a registration request message to AMF2. The registration request message may carry a SUCI or a 5G-GUTI of the UE. The AMF2 may implement a local policy such that, in case the registration request message carries the 5G-GUTI and the 5G-GUTI points to an AMF that is not in the same premises (or security domain) as AMF2 (e.g., AMF2 is in operator premises, whereas 5G-GUTI points to an AMF in customer premises) , then AMF2 may initiate an identity request procedure with the UE, to obtain the SUCI of the UE.

[0101] Step 2: The AMF2 may initiate a UE authentication procedure. For example, AMF2 may invoke an Nausf_UEAuthentication service by sending, for example, an Nausf_UEAuthentication_Authenticate Request message to the AUSF. The  Nausf_UEAuthentication_Authenticate Request message may carry either SUCI or SUPI of the UE. The Nausf_UEAuthentication_Authenticate Request message may further carry the Serving Network (SN) name of the UE. The SN may be the network in which UE initiates the registration request. In this case, the SN is the customer premises network. The Nausf_UEAuthentication_Authenticate Request message may further carry a PLMNNPN service indication. In this scenario, the PLMNNPN service indication may indicate that the service request is initiated from the customer premises, and / or that the service request is initiated from a different security domain. Detailed description on PLMNNPN service indication may be found in embodiment 1, and is omitted herein for the sake of simplicity.

[0102] Step 3: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF sends an Nudm_UEAuthentication_Get Request to UDM. The Nudm_UEAuthentication_Get Request may carry at least one of: SUCI of UE; the serving network name of the UE; a PLMNNPN service indication, if it is carried in the Nausf_UEAuthentication_Authenticate Request message in step 2.

[0103] Step 4: Upon receiving the Nudm_UEAuthentication_Get Request, if SUCI is received, the UDM may invoke the SIDF to de-conceal SUCI to obtain the SUPI, before UDM can process the request.

[0104] As a response, the UDM may respond back to the AUSF with, for example, a Nudm_UEAuthentication_Get response message. The response message may carry an Authentication Vector (AV) created by the UDM (or ARPF) .

[0105] The UDM may check the subscription of the UE and generate a new PLMNNPN UE ID, which may be carried in the Nudm_Authenticate_Get Response message. If a SUCI is received in step 3, the UDM may create a new PLMNNPN UE ID for the UE, which may be carried in the Nudm_Authenticate_Get Response message. On the other hand, if a PLMNNPN UE ID is received in step 3, there are two options based on operator’s policy. In the first option, UDM may refresh / update the PLMNNPN UE ID, and the response message may carry the refreshed PLMNNPN UE ID. In the second option, there is no need  to refresh the received PLMNNPN UE ID, and the PLMNNPN UE ID received in step 3 is carried in the response message.

[0106] Step 5: The AUSF may send an Nausf_UEAuthentication_UEAuthentication Response message to AMF2, carrying the AV.

[0107] Step 6: The AMF2 may send an authentication request message to the UE, and UE may respond with an authentication response message carrying an authentication challenge result (RES*) .

[0108] Step 7: The AMF2 may send an Nausf_UEAuthentication_Authenticate Request message to AUSF carrying RES*.

[0109] Step 8: The AUSF may indicate to the AMF2 in an Nausf_UEAuthentication_Authenticate Response message whether the authentication was successful or not from the home network point of view. If the authentication was successful, the anchor key (KSEAF) will be sent to the AMF2 in the Nausf_UEAuthentication_Authenticate Response message.

[0110] In case the AUSF received a SUCI or PLMNNPN UE ID from AMF2 in the authentication request (in step 2) , and if the authentication was successful, then the AUSF may also include the PLMNNPN UE ID (if received from UDM in step 4) in the Nausf_UEAuthentication_Authenticate Response message.

[0111] AMF2, upon receiving the Nausf_UEAuthentication_Authenticate Response message, may derive its key, KAMF, from KSEAF, by using a Key Derivation Function (KDF) . Details on the key derivation procedure may be found in embodiment 1 and is omitted herein.

[0112] Steps 9-11: AMF2 may register with the UDM using, for example, an Nudm_UECM_Registration message, in order for the access to be registered. After AMF2 has successfully completed the Nudm_UECM_Registration operation, and if AMF2 does not have subscription data for the UE, AMF2 may retrieve the subscription data, such as Access  and Mobility Subscription data, SMF Selection Subscription data, UE context in SMF data, Location Services (LCS) mobile origination, and the like, using Nudm_SDM_Get. The UDM may send a newly generated PLMNNPN UE ID in the Nudm_UECM_Registration response message or Nudm_SDM_Get response message. After a successful response is received, the AMF2 may subscribe to be notified using Nudm_SDM_Subscribe when the data requested is modified. The UDM may send a notification to the AMF2 if a new PLMNNPN UE ID is generated. For example, a PLMNNPN UE ID may be configured with a lifecycle, and it has to be updated / refreshed once the lifecycle is reached.

[0113] Step 12: AMF2 may send a registration accept message to the UE, if the authentication is successful. The registration accept message may include a 5G-GUTI which points to the AMF2 in the operator premises.

[0114] In some scenarios, AMF2 in operator premises needs to transfer UE context to AMF1 in the customer premises. For example, AMF2 may be the old AMF for the UE, and AMF1 may be the new AMF for the UE. There are two cases which are described below.

[0115] Case 1: UE context transfer during the mobility registration (shown in FIG. 8)

[0116] Step 13: The UE may send a registration request message to AMF1 in the customer premises. The registration request message may carry the 5G-GUTI pointing to AMF2 in the operator premises (which UE receives in step 12) .

[0117] Step 14: AMF1 in the customer premises sends an Namf_Communication_UEContextTransfer message to AMF2 in the operator premises.

[0118] Step 15: AMF2 in the operator premises responds to AMF1 in the customer premises with the UE context. The response message may include an Namf_Communication_UEContextTransfer response message. In the UE context transferred to AMF1, AMF2 may replace SUPI of the UE with PLMNNPN UE ID of the UE.

[0119] AMF1 in the customer premises may decide to trigger a primary authentication.  AMF1 may send an identity request to the UE to request SUCI of the UE. Alternatively, AMF2 may request SUPI of the UE from the UDM, using PLMNNPN UE ID as input to the inquiry.

[0120] Step 16: AMF1 may send a registration accept message to the UE carrying a newly assigned 5G-GUTI. The new 5G-GUTI points to AMF1 (which is the new AMF serving the UE) .

[0121] Case 2: UE context transfer during the N2 handover (not shown in FIG. 8)

[0122] In this scenario, AMF2 in the operator premises is the source AMF, and the AMF1 in the customer premises is the target AMF.

[0123] Upon reception of the NGAP HANDOVER REQUIRED message, AMF2 may send a Namf_Communication_CreateUEContext Request message to AMF1. In the UE context transferred to AMF1, AMF2 may replace SUPI of the UE with PLMNNPN UE ID of the UE.

[0124] AMF1 in the customer premises may decide to trigger a primary authentication between UE and AMF1. AMF1 may send an identity request to the UE to request SUCI of the UE. Alternatively, AMF2 may request SUPI of the UE from the UDM, using PLMNNPN UE ID as input to the inquiry.

[0125] In this disclosure, message types and / or message names (e.g., as shown in FIGs. 7-8) are for exemplary purpose only. Different message types and / or message names may be chosen in implementation, and should still be covered by this disclosure, as far as the underlying principle is the same, for example, if the messages are used for a same purpose.

[0126] In this disclosure, a single information element in a message may be split into multiple information elements. Multiple information element may also be combined into a single information element.

[0127] In this disclosure, the steps in each embodiment are for illustration purposes only and other alternatives may be derived based on the disclosed embodiments as desired. For example, only part of the steps may need to be performed. For another example, the sequence of the steps may be adjusted. For another example, several steps may be combined (e.g., several messages may be combined in one message) . For yet another example, a single step may be split (e.g., one message may be sent via two sub-messages) .

[0128] The embodiments described in this disclosure are for exemplary purpose. Multiple embodiments may be combined, to form a new embodiment.

[0129] The accompanying drawings and description above provide specific example embodiments and implementations. The described subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is intended to be construed as not being limited to any example embodiments set forth herein. A reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, systems, or non-transitory computer-readable media for storing computer codes. Accordingly, embodiments may, for example, take the form of hardware, software, firmware, storage media or any combination thereof. For example, the method embodiments described above may be implemented by components, devices, or systems including memory and processors by executing computer codes stored in the memory.

[0130] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase “in one embodiment / implementation” as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment / implementation” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter includes combinations of example embodiments in whole or in part.

[0131] In general, terminology may be understood at least in part from usage in context. For example, terms, such as “and” , “or” , or “and / or, ” as used herein may include a variety of  meanings that may depend at least in part on the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a, ” “an, ” or “the, ” may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for existence of additional factors not necessarily expressly described, again, depending at least in part on context.

[0132] Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present solution should be or are included in any single implementation thereof. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, discussions of the features and advantages, and similar language, throughout the specification may, but do not necessarily, refer to the same embodiment.

[0133] Furthermore, the described features, advantages and characteristics of the present solution may be combined in any suitable manner in one or more embodiments. One of ordinary skill in the relevant art will recognize, in light of the description herein, that the present solution can be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the present solution.

Claims

1.A method for wireless communication, performed by a first network element, comprising:receiving, from a wireless device, a first message for a service request with a wireless network, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device; ora first 5G Global Unique Temporary Identifier (5G-GUTI) of the wireless device; andtransmitting, to a second network element, a second message for authentication request, the second message carrying at least one of:a Serving Network (SN) name of an SN serving the wireless device;the SUCI of the wireless device;a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device;a service indicator indicating that a service associated with the second message is initiated from a security domain different from the second network element; oran identifier of the first network element.2.The method of claim 1, wherein the first network element comprises an Access and Mobility Management Function (AMF) , and wherein the second network element comprises an Authentication Server Function (AUSF) .3.The method of claim 1, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.4.The method of claim 1, wherein the first network element is in a first security domain and the second network element is in a second security domain different from the first security domain.5.The method of claim 1, wherein the service indicator indicates that the service associated with the second message is initiated or triggered from a customer premises.6.The method of claim 1, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the UE identifier of the wireless device;the identifier of the first network element;an indicator indicating that the service associated with the second message is initiated or triggered from a customer premises; ora name or a type of the second message.7.The method of claim 1, wherein the first message comprises an Nausf_UEAuthentication_Authenticate request message and the second message comprises an Nausf_UEAuthentication_Authenticate response message.8.The method of any one of claims 1-7, further comprising:receiving, from the second network element, a third message as a response to the second message, the third message carrying an Authentication Vector (AV) .9.The method of claim 8, further comprising:transmitting, to the second network element, a fourth message carrying an authentication challenge result from the wireless device; andreceiving, from the second network element, a fifth message as a response to the fourth message, the fifth message comprising at least one of:an anchor key (KSEAF) ;the UE identifier of the wireless device; ora refreshed UE identifier of the wireless device.10.The method of claim 9, wherein the fourth message comprises an Nausf_UEAuthentication_Authenticate request message and the fifth message comprises an Nausf_UEAuthentication_Authenticate Response message.11.The method of claim 9, further comprising:deriving an AMF key, KAMF, based on at least one of: the UE identifier of the wireless device; the refreshed UE identifier of the wireless device; or the anchor key.12.The method of claim 9, further comprising:transmitting, to the wireless device, a sixth message as a response to the first message accepting the service request of the wireless device, the sixth message comprising a second 5G-GUTI allocated to the wireless device, the second 5G-GUTI pointing to an AMF located in a same security domain as the second network element.13.The method of claim 12, wherein the sixth message comprises a registration accept  message.14.The method of any one of claims 1-7, further comprising:in response to an AMF identified by the first 5G-GUTI and the first network element belonging to different security domains, triggering an identity request with the wireless device, to get the SUCI of the wireless device.15.The method of any one of claims 1-7, further comprising:receiving, from a third network element, a seventh message requesting transferring UE context of the wireless device from the first network element to the third network element; andtransmitting, to the third network element, an eighth message carrying the UE context of the wireless device, wherein the SUPI of the wireless device is replaced with the UE identifier of the wireless device.16.The method of claim 15, wherein:the third network element comprising an AMF; andthe third network element is in a security domain that is different from the first network element.17.A method for wireless communication, performed by a first network element, comprising:receiving, from a wireless device, a first message for a service request with a wireless network, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device;a first 5G Global Unique Temporary Identifier (5G-GUTI) of the wireless device; andtransmitting, to a second network element, a second message for authentication request, the second message carrying at least one of:a Serving Network (SN) name of an SN serving the wireless device;the SUCI of the wireless device;a Subscription Permanent Identifier (SUPI) of the wireless device;a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device;a service indicator indicating that a service associated with the second message is initiated from a security domain different from the first network element; oran identifier of the first network element.18.The method of claim 17, wherein the first network element comprises an Access and Mobility Management Function (AMF) , and wherein the second network element comprises an Authentication Server Function (AUSF) .19.The method of any one of claims 17-18, wherein the wireless device is in a first security domain, and wherein the first network element and the second network element are in a second security domain which is different from the first security domain.20.The method of claim 19, wherein the wherein the service indicator indicates that the service associated with the second message is initiated from a customer premises.21.The method of claim 20, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the identifier of the first network element; oran indicator indicating that the service associated with the second message is initiated or triggered from a customer premises; ora name or a type of the second message.22.The method of claim 17, wherein the first message comprises a registration request message, and wherein the second message comprises an Nausf_UEAuthentication_Authenticate request message.23.The method of any one of claims 17-22, further comprising:receiving, from the second network element, a third message as a response to the second message, the third message carrying an Authentication Vector (AV) .24.The method of claim 23, wherein the third message comprises an Nausf_UEAuthentication_Authenticate response message.25.The method of claim 24, further comprising:transmitting, to the second network element, a fourth message carrying an authentication challenge result from the wireless device; andreceiving, from the second network element, a fifth message as a response to the fourth message, the fifth message comprising at least one of:an anchor key (KSEAF) ; ora User Equipment (UE) identifier of the wireless device that is associated with the SUPI of the wireless device.26.The method of claim 25, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.27.The method of claim 25, wherein the fourth message comprises an Nausf_UEAuthentication_Authenticate request message and the fifth message comprises an Nausf_UEAuthentication_Authenticate Response message.28.The method of any one of claims 25-27, further comprising:transmitting, to a third network element, a sixth message to register the wireless device with the third network element, or retrieve subscription data of the wireless device from the third network element; andreceiving, from the third network element, a seventh message as a response to the sixth message, the seventh message carrying an updated UE identifier of the wireless device.29.The method of claim 28, wherein the sixth message comprises at least one of: an Nudm_UECM_Registration message; or an Nudm_SDM_Get message.30.The method of any one of claims 25-27, further comprising:receiving, from a fourth network element, an eighth message requesting transferring UE context of the wireless device from the first network element to the fourth network element; andtransmitting, to the fourth network element, a ninth message carrying the UE context of the wireless device, wherein the SUPI of the wireless device is replaced with the UE identifier of the wireless device.31.The method of claim 30, wherein:the fourth network element comprising an AMF; andthe fourth network element is in a security domain that is different from the first network element.32.A method for wireless communication, performed by a first network element, comprising:receiving, from a second network element, a first message for an authentication request initiate from a wireless device, the first message carrying at least one of:a Serving Network (SN) name of an SN serving the wireless device;a SUCI of the wireless device;a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device;an identifier of the second network element; ora service indicator indicating that a service associated with the first message is initiated from a security domain different from the first network element; andan indication that the authentication request for the wireless device is initiated from a first security domain that is different from a second security domain to which the first network element belongs; andtransmitting, to a third network element, a second message for authentication request for the wireless device, the second message carrying at least one of:the SN name of an SN serving the wireless device;the SUCI of the wireless device;the UE identifier of the wireless device that is associated with the SUPI of the wireless device;an identifier of the second network element; orthe indication that the authentication request for the wireless device is initiated from the first security domain that is different from the second security domain to which the first network element belongs.33.The method of claim 32, wherein:the first network element comprises an Authentication Server Function (AUSF) ;the second network element comprises an Access and Mobility Management Function (AMF) ; andthe third network element comprises a Unified Data Management (UDM) .34.The method of claim 33, wherein the UDM is capable of deriving the SUPI of the wireless device from the UE identifier of the wireless device.35.The method of claim 32, wherein the first network element is in a first security domain and the second network element is in a second security domain different from the first security domain.36.The method of claim 32, wherein the first network element is in a same security domain as the second network element.37.The method of claim 32, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.38.The method of claim 32, wherein the first security domain comprises a customer premises and the second security domain comprises an operator premises.39.The method of claim 32, wherein the service indicator indicates that the service associated with the first message is initiated or triggered from a customer premises.40.The method of claim 32, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the UE identifier of the wireless device;the identifier of the second network element;an indicator indicating that the service associated with the first message is initiated or triggered from a customer premises; ora name or a type of the first message.41.The method of claim 32, wherein the first message comprises an Nausf_UEAuthentication_Authenticate request message and the second message comprises an Nudm_UEAuthentication_Get request message.42.The method of any one of claims 32-39, further comprising receiving, from the third network element, a third message as a response to the second message, the third message carrying at least one of:an Authentication Vector (AV) ;a SUCI based UE identifier of the wireless device that is derived based on the SUCI of the wireless device;the UE identifier of the wireless device; ora refreshed UE identifier of the wireless device that is a refreshed version of the UE identifier of the wireless device.43.The method of claim 42, wherein the third message comprises an Nudm_Authenticate_Get response message.44.The method of claim 42, further comprising:transmitting, to the second network element, a fourth message as a response to the first message, the fourth message comprising the AV.45.The method of claim 44, further comprising:receiving, from the second network element, a fifth message carrying an authentication challenge result generated by the wireless device; andtransmitting, to the second network element, a sixth message as a response to the fifth message, the sixth message comprising at least one of:an anchor key (KSEAF) use for generating an AMF key, KAMF of the second network element; orthe refreshed UE identifier of the wireless device.46.The method of claim 45, wherein the fifth message comprises an Nausf_UEAuthentication_Authenticate request message and the sixth message comprises an Nausf_UEAuthentication_Authenticate response message.47.A method for wireless communication, performed by a first network element, comprising:receiving, from a second network element, a first message for authenticating a wireless device, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device;a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; ora Serving Network (SN) name of an SN serving the wireless device; andtransmitting, to a second network element, a second message as a response to the first message, the second message carrying at least one of:the SUPI of the wireless device;the UE identifier of the wireless device; oran updated UE identifier of the wireless device.48.The method of claim 47, wherein the wireless device is in a first security domain, and wherein the first network element and the second network element are in a second security domain which is different from the first security domain.49.The method of claim 47, wherein the first message comprises an Nudm_Authenticate_Get message, and wherein the second message comprises an Nudm_Authenticate_Get Response message.50.The method of any one of claims 47-49, wherein the first message indicates a property of the first security domain, the property of the first security domain comprising at least one of:the first security domain being in a customer premises;a name of the first security domain; ora type of the first security domain.51.The method of claim 50, wherein the second message indicates the property of the first security domain via at least one of:the SN name of the SN serving the wireless device;a indicator indicating that a service request associated with the second message is initiated or triggered from the first security domain; ora name or a type of the second message.52.The method of any one of claims 47-51, wherein the first message carrying the SUCI of the wireless device, the method further comprising:obtaining the SUPI of the wireless device based on the SUCI; andgenerating the UE identifier of the wireless device based on the SUPI.53.The method of claim 52, wherein generating the UE identifier of the wireless device  comprises:encrypting the SUPI to obtain the UE identifier of the wireless device; ormapping the SUPI to the UE identifier of the wireless device.54.The method of any one of claims 47-51, wherein the first message carrying the UE identifier of the wireless device, the method further comprising updating the UE identifier of the wireless device, to obtain an updated UE identifier of the wireless device.55.A device or a network element comprising a memory for storing computer instructions and a processor in communication with the memory, wherein the processor, when executing the computer instructions, is configured to implement a method in any one of claims 1-54.56.A computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon, the computer code, when executed by one or more processors, causing the one or more processors to implement a method of any one of claims 1-54.

Citation Information

Patent Citations

  • Secure communication method and device

    CN113645621A

  • Method for preventing encrypted user identity from being subjected to replay attack

    CN115699672A

  • UE onboarding and provisioning using one way authentication

    US20220330022A1

  • Authentication using slice capability indication

    US20230262457A1

  • Methods and apparatus relating to authentication of a wireless device

    WO2020198991A1