Method, device and system for UE identity privacy in communication networks

WO2025156497A1PCT designated stage Publication Date: 2025-07-31ZTE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/092137
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-10
Publication Date
2025-07-31

Smart Images

  • Figure CN2024092137_31072025_PF_FP_ABST
    Figure CN2024092137_31072025_PF_FP_ABST
Patent Text Reader

Abstract

This disclosure generally relates to protecting sensitive user subscription data in wireless communication. Performed by first network element, the method includes: the method includes: receiving, from a second network element, a first message associated with a service request for a wireless device, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; a Serving Network (SN) name of an SN serving the wireless device; or a service indicator indicating that the service request is initiated from a security domain different from the first network element.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, DEVICE AND SYSTEM FOR UE IDENTITY PRIVACY IN COMMUNICATION NETWORKSTECHNICAL FIELD

[0001] This disclosure relates to wireless communication, and in particular, to protect sensitive user subscription and identification data in a communication network, such as 4G, 5G, and 6G wireless communication network, as well as Non Public Network (NPN) .BACKGROUND

[0002] The proliferation of mobile devices and increasing data demands have led to the widespread deployment of public wireless networks by mobile operators, as well as private wireless networks by enterprises. Private wireless networks are typically deployed within a defined geographic area, such as a campus, factory, or facility. The interconnection between public wireless networks and private wireless networks presents a significant challenge from a security perspective. It is crucial to establish secure inter-network operations that enable seamless and protected communication between these two distinct network environments. Implementing robust security measures at the interface of public and private wireless networks is critical to ensure the confidentiality and integrity of wireless communications.SUMMARY

[0003] This disclosure discloses methods, systems, devices, and storage medium relates to wireless communication, and in particular, to protecting sensitive user subscription and identification data in a wireless communication network, such as a 4G, 5G, and 6G wireless communication network, as well as private network such as a Non Public Network (NPN) .

[0004] In one embodiment, the present disclosure describes a method for wireless communication. Performed by a first network element, the method includes: receiving,  from a second network element, a first message associated with a service request for a wireless device, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; a Serving Network (SN) name of an SN serving the wireless device; or a service indicator indicating that the service request is initiated from a security domain different from the first network element.

[0005] In another embodiment, a method for wireless communication is disclosed. Performed by a first network element, the method includes: transmitting, to a second network element, a first message associated with a service request for a wireless device, the first message carrying at least one of: a Subscription Concealed Identifier (SUCI) of the wireless device; a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device; a Serving Network (SN) name of an SN serving the wireless device; or a service indicator indicating that the service request is initiated from a security domain different from the first network element.

[0006] In another embodiment, a network element comprising a processor and a memory is disclosed. The processor may be configured to read computer code from the memory to implement any of the methods above.

[0007] In yet another embodiment, a computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon is disclosed. The computer code, when executed by a processor, may cause the processor to implement any one of the methods above.

[0008] The above embodiments and other aspects and alternatives of their implementations are explained in greater detail in the drawings, the descriptions, and the claims below.BRIEF DESCRIPTION OF THE DRAWINGS

[0009] FIG. 1 shows an exemplary communication network including various terminal devices, a carrier network, data network, and service applications.

[0010] FIG. 2 shows exemplary network functions or network nodes in a communication network.

[0011] FIG. 3 shows exemplary network functions or network nodes in a wireless communication network.

[0012] FIG. 4 shows an exemplary network model for Public Land Mobile Network –Non Public Network (PLMNNPN) in which an NPN is hosted by a Public Land Mobile Network (PLMN) .

[0013] FIG. 5 shows an example wireless network node (or network element, network function, network entity, entity, application function) .

[0014] FIG. 6 shows an example user equipment.

[0015] FIG. 7 shows an exemplary logic flow for interactions between NPN and PLMN with a Security for PLMNNPN Network Function (SPNF) co-located in a network function in operator premises.DETAILED DESCRIPTION

[0016] An exemplary communication network, shown as 100 in FIG. 1, may include terminal devices 110 and 112, a carrier network 102, various service applications 140, and other data networks 150. The carrier network 102, for example, may include access networks 120 and a core network 130. The carrier network 102 may be configured to transmit voice, data, and other information (collectively referred to as data traffic) among terminal devices 110 and 112, between the terminal devices 110 and 112 and the service applications 140, or between the terminal devices 110 and 112 and the other data networks  150. Communication sessions and corresponding data paths may be established and configured for such data transmission. The Access networks 120 may be configured to provide terminal devices 110 and 112 network access to the core network 130. The Access network 120 may, for example, support wireless access via radio resources, or wireline access. The core network 130 may include various network nodes or network functions configured to control the communication sessions and perform network access management and data traffic routing. The service applications 140 may be hosted by various application servers that are accessible by the terminal devices 110 and 112 through the core network 130 of the carrier network 102. A service application 140 may be deployed as a data network outside of the core network 130. Likewise, the other data networks 150 may be accessible by the terminal devices 110 and 112 through the core network 130 and may appear as either data destination or data source of a particular communication session instantiated in the carrier network 102.

[0017] The core network 130 of FIG. 1 may include various network nodes or functions geographically distributed and interconnected to provide network coverage of a service region of the carrier network 102. These network nodes or functions may be implemented as dedicated hardware network elements. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or as software entities. A network node may each be configured with one or more types of network functions. These network nodes or network functions may collectively provide the provisioning and routing functionalities of the core network 130. The term “network nodes” and “network functions” are used interchangeably in this disclosure.

[0018] FIG. 2 further shows an exemplary division of network functions in the core network 130 of a communication network 200. While only single instances of network nodes or functions are illustrated in FIG. 2, those having ordinary skill in the art readily understand that each of these network nodes may be instantiated as multiple instances of network nodes that are distributed throughout the core network 130. As shown in FIG. 2, the core network 130 may include but is not limited to network nodes such as access  management network node (AMNN) 230, authentication network node (AUNN) 260, network data management network node (NDMNN) 270, session management network node (SMNN) 240, data routing network node (DRNN) 250, policy control network node (PCNN) 220, and application data management network node (ADMNN) 210. Exemplary signaling and data exchange between the various types of network nodes through various communication interfaces are indicated by the various solid connection lines in FIG. 2. Such signaling and data exchange may be carried by signaling or data messages following predetermined formats or protocols.

[0019] The implementations described above in FIGs. 1 and 2 may be applied to both wireless and wireline communication systems. FIG. 3 illustrates an exemplary cellular wireless communication network 300 based on the general implementation of the communication network 200 of FIG. 2. FIG. 3 shows that the wireless communication network 300 may include user equipment (UE) 310 (functioning as the terminal device 110 of FIG. 2) , radio access network (RAN) 320 (functioning as the access network 120 of FIG. 2) , data network (DN) 150, and core network 130 including access management function (AMF) 330 (functioning as the AMNN 230 of FIG. 2) , session management function (SMF) 340 (functioning as the SMNN 240 of FIG. 2) , application function (AF) 390 (functioning as the ADMNN 210 of FIG. 2) , user plane function (UPF) 350 (functioning as the DRNN 250 of FIG. 2) , policy control function 322 (functioning as the PCNN 220 of FIG. 2) , authentication server function (AUSF) 360 (functioning as the AUNN 260 of FIG. 2) , and universal data management (UDM) function 370 (functioning as the UDMNN 270 of FIG. 2) . Again, while only single instances for some network functions or nodes of the wireless communication network 300 (the core network 130 in particular) are illustrated in FIG. 3, those of ordinary skill in the art readily understand that each of these network nodes or functions may have multiple instances that are distributed throughout the wireless communication network 300. While the AF 390 is depicted as part of the core network 130 in FIG. 3, they may be considered as associated with particular service applications 140 and may be considered as being outside of the core network 140. In this disclosure, various functions deployed in the wireless network as described above may also be referred to as  function entities, which may be implemented as a network node, a network element, a logical function, via hardware, software, or a combination thereof.

[0020] In FIG. 3, the UE 310 may be implemented as various types of mobile devices that are configured to access the core network 130 via the RAN 320. The UE 310 may include but is not limited to mobile phones, laptop computers, tablets, Internet-Of-Things (IoT) devices, distributed sensor network nodes, wearable devices, and the like. The UE may also be Multi-access Edge Computing (MEC) capable UE that supports edge computing. The RAN 320 for example, may include a plurality of radio base stations distributed throughout the service areas of the carrier network. The communication between the UE 310 and the RAN 320 may be carried in over-the-air (OTA) radio interfaces as indicated by 311 in FIG. 3.

[0021] Continuing with FIG. 3, the UDM 370 may form a permanent storage or database for user contract and subscription data. The UDM may further include an authentication credential repository and processing function (ARPF, as indicated in 370 of FIG. 3) for storage of long-term security credentials for user authentication, and for using such long-term security credentials as input to perform computation of encryption keys as described in more detail below. To prevent unauthorized exposure of UDM / ARPF data, the UDM / ARPF 370 may be located in a secure network environment of a network operator or a third-party.

[0022] The AMF / SEAF 330 may communicate with the RAN 320, the SMF 340, the AUSF 360, the UDM / ARPF 370, and the Policy Control Function (PCF) 322 via communication interfaces indicated by the various solid lines connecting these network nodes or functions. The AMF / SEAF 330 may be responsible for UE to non-access stratum (NAS) signaling management, and for provisioning registration and access of the UE 310 to the core network 130 as well as allocation of SMF 340 to support communication need of a particular UE. The AMF / SEAF 330 may be further responsible for UE mobility management. The AMF may also include a security anchor function (SEAF, as indicated in 330 of FIG. 3) that, as described in more detail below, and interacts with AUSF 360 and UE 310 for user authentication and management of various levels of encryption / decryption keys. The AUSF  360 may terminate user registration / authentication / key generation requests from the AMF / SEAF 330 and interact with the UDM / ARPF 370 for completing such user registration / authentication / key generation.

[0023] The SMF 340 may be allocated by the AMF / SEAF 330 for a particular communication session instantiated in the wireless communication network 300. The SMF 340 may be responsible for allocating UPF 350 to support the communication session and data flows therein in a user data plane and for provisioning / regulating the allocated UPF 350 (e.g., for formulating packet detection and forwarding rules for the allocated UPF 350) . Alternative to being allocated by the SMF 340, the UPF 350 may be allocated by the AMF / SEAF 330 for the particular communication session and data flows. The UPF 350 allocated and provisioned by the SMF 340 and AMF / SEAF 330 may be responsible for data routing and forwarding and for reporting network usage by the particular communication session. For example, the UPF 350 may be responsible for routing end-end data flows between UE 310 and the DN 150, between UE 310 and the service applications 140. The DN 150 and the service applications 140 may include but are not limited to data network and services provided by the operator of the wireless communication network 300 or by third-party data network and service providers.

[0024] The PCF 322 may be responsible for managing and providing various levels of policies and rules applicable to a communication session associated with the UE 310 to the AMF / SEAF 330 and SMF 340. As such, the AMF / SEAF 330, for example, may assign SMF 340 for the communication session according to policies and rules associated with the UE 310 and obtained from the PCF 322. Likewise, the SMF 340 may allocate UPF 350 to handle data routing and forwarding of the communication session according to policies and rules obtained from the PCF 322.

[0025] While FIGs. 1-3 and the various exemplary implementations described below are based on cellular wireless communication networks, the scope of this disclosure is not so limited and the underlying principles are applicable to other types of wireless and wireline communication networks.

[0026] Network identity and data security in the wireless communication network 300 of FIG. 3 may be managed via user authentication processes provided by the AMF / SEAF 330, the AUSF 360, and the UDM / ARPF 370. In particularly, the UE 310 may first communicate with AMF / SEAF 330 for network registration and may then be authenticated by the AUSF 360 according to user contract and subscription data in the UDM / ARPF 370. Communication sessions established for the UE 310 after user authentication to the wireless communication network 300 may then be protected by the various levels of encryption / decryption keys. The generation and management of the various keys may be orchestrated by the AUSF 360 and other network functions in the communication network 300.

[0027] Security Domains-Operator Premises and Customer Premises

[0028] FIG. 4 illustrates an exemplary network model 400 that includes an operator premises and a customer premises. The operator premises may include, for example, a Unified Data Management (UDM) entity, a Network Exposure Function (NEF) entity, a Network Repository Function (NRF) entity, a Policy Control Function (PCF) entity, a User Plane Function (UPF) entity, an Authentication Server Function (AUSF) entity, an AMF entity, a Session Management Function (SMF) entity, and may further include an Application Function (AF) entity. The customer premises may include, for example, an AMF entity, an SMF entity, a UPF entity, and a Data Network (DN) .

[0029] In the network model 400, the operator premises may include a Public Land Mobile Network (PLMN) , which is managed and operated by a public operator. The customer premises may include a private network, such as a Non-Public Network (NPN) by 3rd Generation Partnership Project (3GPP) . The NPN may be operated or manage by, for example, a private entity such as a private enterprise or a private operator. The NPN may be deployed as Stand-alone NPN (SNPN) , which do not rely on services or applications provided by a PLMN. The NPN may also be deployed as Public Network Integrated NPN (PNI-NPN) , which has inter-connection with a PLMN. In some example implementations, The PNI-NPN may share Radio Access Network (RAN) with a PLMN. In some example  implementations, the PNI-NPN may share at least part of Control Plane (CP) functions and / or User Plane (UP) functions with a PLMN.

[0030] In wireless network such as a 5G or a 6G network, a Service Based Architecture (SBA) framework is implemented to expose the functionality of various network elements to each other. The SBA framework enhances network deployment flexibility by providing enriched configuration options. Through SBA implementation, various components and functions within the wireless network (including PLMN and private network) can seamlessly interact and leverage each other’s functions, facilitating more agile and modular network deployments that can adapt to diverse operational requirements.

[0031] In some network deployment as shown in FIG. 4, a dedicated UPF and part of CP functions are deployed in the customer premises. The dedicated Network Functions (NFs) in the customer premises may communicate with the NFs in the operator premise via the SBA interface. In this example deployment, the CP functions hosted by the NPN in the customer premises includes the AMF entity and the SMF entity.

[0032] In some other network deployments, a dedicated UPF is deployed in customer premises, which may interact with the operator premises via, for example, an N4 interface (non-SBA interface) .

[0033] FIG. 5 shows an example of electronic device 500 to implement various network nodes, network elements, network entities, such as a network base station (e.g., a radio access network node) , a core network (CN) , a core network element / entity (e.g., an AMF, a UDM, an AAnF, etc. ) , an operation and maintenance (OAM) , and the like. Optionally in one implementation, the example electronic device 500 may include radio transmitting / receiving (Tx / Rx) circuitry 508 to transmit / receive communication with UEs and / or other base stations. Optionally in one implementation, the electronic device 500 may also include network interface circuitry 509 to communicate the base station with other base stations and / or a core network, e.g., optical or wireline interconnects, Ethernet, and / or other data transmission mediums / protocols. The electronic device 500 may optionally include an input / output (I / O)  interface 506 to communicate with an operator or the like.

[0034] The electronic device 500 may also include system circuitry 504. System circuitry 504 may include processor (s) 521 and / or memory 522. Memory 522 may include an operating system 524, instructions 526, and parameters 528. Instructions 526 may be configured for the one or more of the processors 521 to perform the functions of the network node. The parameters 528 may include parameters to support execution of the instructions 526. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.

[0035] In this disclosure, a network function / network entity / entity, such as an AMF, an AUSF, a UDM, an AAnF, an NEF, an AF, may be implemented in hardware, software, a combination of hardware and software, and may be implemented or integrated in the electronic device 500. They may also be implemented as a logical entity hosted by the electronic device 500.

[0036] FIG. 6 shows an example of an electronic device to implement a terminal device 600 (for example, a UE) . The UE 600 may be a mobile device, for example, a smart phone or a mobile communication module disposed in a vehicle. The UE 600 may include a portion or all of the following: communication interfaces 602, a system circuitry 604, an input / output interfaces (I / O) 606, a display circuitry 608, and a storage 609. The display circuitry may include a user interface 610. The system circuitry 604 may include any combination of hardware, software, firmware, or other logic / circuitry. The system circuitry 604 may be implemented, for example, with one or more systems on a chip (SoC) , application specific integrated circuits (ASIC) , discrete analog and digital circuits, and other circuitry. The system circuitry 604 may be a part of the implementation of any desired functionality in the UE 600. In that regard, the system circuitry 604 may include logic that facilitates, as examples, decoding and playing music and video, e.g., MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user inputs; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections for, as one example, internet connectivity; establishing, maintaining, and  terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on the user interface 610. The user interface 610 and the inputs / output (I / O) interfaces 606 may include a graphical user interface, touch sensitive display, haptic feedback or other haptic output, voice or facial recognition inputs, buttons, switches, speakers and other user interface elements. Additional examples of the I / O interfaces 606 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headset and microphone input  / output jacks, Universal Serial Bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors) , and other types of inputs.

[0037] Referring to FIG. 6, the communication interfaces 602 may include a Radio Frequency (RF) transmit (Tx) and receive (Rx) circuitry 616 which handles transmission and reception of signals through one or more antennas 614. The communication interface 602 may include one or more transceivers. The transceivers may be wireless transceivers that include modulation  / demodulation circuitry, digital to analog converters (DACs) , shaping tables, analog to digital converters (ADCs) , filters, waveform shapers, filters, pre-amplifiers, power amplifiers and / or other logic for transmitting and receiving through one or more antennas, or (for some devices) through a physical (e.g., wireline) medium. The transmitted and received signals may adhere to any of a diverse array of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM) , frequency channels, bit rates, and encodings. As one specific example, the communication interfaces 602 may include transceivers that support transmission and reception under the 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS) , High Speed Packet Access (HSPA) +, 4G  / Long Term Evolution (LTE) , 5G, and 6G standards. The techniques described below, however, are applicable to other wireless communications technologies whether arising from the 3rd Generation Partnership Project (3GPP) , GSM Association, 3GPP2, IEEE, or other partnerships or standards bodies.

[0038] Referring to FIG. 6, the system circuitry 604 may include one or more processors 621 and memories 622. The memory 622 stores, for example, an operating system 624,  instructions 626, and parameters 628. The processor 621 is configured to execute the instructions 626 to carry out desired functionality for the UE 600. The parameters 628 may provide and specify configuration and operating options for the instructions 626. The memory 622 may also store any BT, WiFi, 3G, 4G, 5G, 6G or other data that the UE 600 will send, or has received, through the communication interfaces 602. In various implementations, a system power for the UE 600 may be supplied by a power storage device, such as a battery or a transformer.

[0039] UE Identify Protection in Wireless Network

[0040] In wireless communication networks, in procedures such as the primary authentication and authorization procedure, if a UE identity, such as the Subscription Permanent Identifier (SUPI) is available in clear text to the Network Functions (NFs) in customer premises, then it may potentially lead to security threats, privacy breaches, UE location tracking and targeted attacks.

[0041] Further, with the evolution of the roaming architectures (e.g., Roaming Hub) and Core Network (NPN, Edge computing) , distributed CN (multi-site CN) , as there is no direct trust relationship between Home Network (HN) and various other networks, such as Serving Network (SN) , Visiting PLMN (VPLMN) , and Edge network (i.e., between the different security domains) , there is serious security concern for the HN to expose permanent and / or sensitive information (e.g., UE identifiers and other parameter) to the NFs that are not in the HN.

[0042] In this disclosure, the term “security domain” is employed to denote a distinct realm encompassing a network infrastructure, physical premises, or entities involved in the network ecosystem. For various reasons, in wireless networks (PLMN and NPN) , there are different security domains. The security domain may be classified by the owner / operator of the network. For example, a PLMN may be owned and / or operated by a communication service provider, whereas an NPN may be owned and / or operated by a private enterprise, a private entity, etc. In this case, the PLMN forms one security domain and the NPN forms a  different security domain. The security domain may also be classified by regulatory compliance and risk management. For example, a PLMN may be categorized as relatively low risk when compared to an NPN. The embodiments described below may use the terms “customer domain” and “operator domain” to represent different security domains. The underlying concept and principles apply to all other types of security domains, irrespective of specific terminology.

[0043] The privacy-sensitive SUPI is the home network operator-provided identifier used exclusively to identify its subscribers and related subscription information to handle the related services. A robust mechanism is essential to address the potential risks involved with sharing sensitive subscriber data across different security domains. Such mechanism is critical to protect sensitive information (e.g., SUPI) from risks that may arise when a PLMN hosts an NPN, and vice versa.

[0044] In this disclosure, the SUPI of a UE, as a sensitive piece of information associated with a user’s identity within the PLMN (whether it’s Home PLMN (HPLMN) or VPLMN) , should be protected to maintain user privacy and prevent security breaches. The SUPI of a UE is not allowed to be sent across security domains, or the SUPI is not allowed be transmitted between different security domains without proper protection mechanisms in place.

[0045] To accommodate the inter-connection between the two security domains, an alternative UE identifier is introduced. First, this newly introduced alternative UE identifier is distinct from various existing UE identifiers in wireless standards, such as Subscription Concealed Identifier (SUCI) , SUPI, or 5G-GUTI (5G Globally Unique Temporary Identifier) . Second, the alternative UE identifier may be dedicated for information exchange between the two security domains. Third, the alternative UE identifier may be derived or generated from the SUPI (or other existing identifiers, such as 5G-GUTI) of the UE, but it may undergo a secure transformation process to ensure its confidentiality and integrity. For example, it may involve encrypting the SUPI using one or more security keys. Specifically, the transformation process differs from the process used to generate existing UE identifiers, such  as SUCI. This ensure that even in the event that the alternative UE identifier is compromised in one security domain, other UE identifiers still remain secure and protected. In this disclosure, this newly introduce alternative UE identifier may be referred to as PLMN-NPN UE ID, or PLMNNPN UE ID, in the sense that it may be used across PLMN and NPN domains. The name is for exemplary purpose only and other names may be chosen to represent this alternative UE identifier.

[0046] There are multiple solutions to generate PLMNNPN UE ID. In some example implementations, the PLMNNPN UE ID may be generated from the SUPI of the UE, using various encryption technologies. In some example implementations, a unique random number may be acquired and mapped to each SUPI, therefore the random number is a representation of SUPI via the mapping relationship. When a random number is received, it may be mapped back to the SUPI. As an extra layer of security protection, the random number may be further encrypted before passing between security domains. In some example implementations, once the PLMNNPN UE ID is generated in one security domain, it may be passed to a different security domain for future use.

[0047] Based on a predefined policy, a PLMNNPN UE ID may have a limited lifespan and need to be renewed or refreshed once it reaches its expiration point. The lifespan of the PLMNNPN UE ID may be represented by a time duration, such as a specific number of minutes, hours, or days, or by a counter such as a usage count. As an example, once a particular PLMNNPN UE ID is transmitted via an un-protected channel such as an air interface, the PLMNNPN UE ID will need to be renewed, as a precautionary measure in case it’s compromised during transmission over the air.

[0048] In some example implementations, an extra layer of security is added, such that the aforementioned PLMN-NPN UE ID is only used within a security domain, such as the customer premises. For message / signaling across security domains, a temporary UE ID is used in place of PLMN-NPN UE ID. Exemplarily, the temporary UE ID may be generate based on PLMN-NPN UE ID or SUPI using the similar methods as described above, for example, via encryption or mapping.

[0049] In this disclosure, a new network function, namely Security for PLMNNPN Network Function (SPNF) is introduced, which may act as a gateway / proxy for interactions between two security domains (e.g., customer premises and operator premises) . Among its various functions, the SPNF may offer UE identification conversion service, facilitating the conversion of UE identification from one type to another. For example, the SPNF may convert between a SUPI and a PLMNNPN UE ID, or between a PLMNNPN UE ID and a temporary UE ID. Using SPNF, sensitive user data, such as user subscription data (e.g., SUPI) will not be passed between the two security domains. For example, user subscription data will be securely transformed to a PLMNNPN UE ID or a temporary UE ID, before it is transmitted from one security domain to another security domain. The SPNF may be a stand-alone entity / function, or may be co-located with another entity / function, such as a UDM. The SPNF may be implemented in the form of hardware, software, or a combination thereof.

[0050] Embodiment 1: UE Authentication with Co-located SPNF

[0051] In this embodiment, for signaling that requires to carry a UE identifier and traverse across security domains, the PLMNNPN UE ID is utilized. The network deployment includes two security domains. For example, one security domain is the customer premises and the other security domain is the operator premises, as shown in FIG. 7. The UE and AMF1 are located in the customer premises, whereas AMF2, AUSF, UDM / ARPF are located in the operator premises. Exemplarily, in this embodiment, the SPNF is co-located with the UDM so there is no standalone SPNF. In some example network deployments, the customer premises may be an NPN network, and the operator premises may be a PLMN network.

[0052] FIG. 7 illustrates an example according to this embodiment. An exemplary method may include a portion or all of the following steps. In this disclosure, the SEAF and AMF may be co-located, and the term SEAF and AMF may be used interchangeably. In some example implementations, the functions associated with SEAF and AMF are performed by the same entity within the network.

[0053] Step 1: The AMF1 may initiate a service request, such as an authentication request with the UE. This may happen when a signaling connection with the UE is required, according to the AMF1’s policy. As a response to AMF1’s request, the UE may send a Registration Request carrying SUCI or 5G-GUTI of the UE. As an example, based on AMF1’s policy, if the 5G-GUTI points to an AMF which is not located in the current premises, such as AMF1 is in the customer premises while the 5G-GUTI points to an AMF which is located in the operator premises (e.g., AMF2) , AMF1 may send an identity request to UE, to obtain the SUCI of UE.

[0054] Step 2: Triggered by the request from UE, the AMF1 may initiate a UE authentication procedure. For example, when AMF1 wishes to initiate an authentication, it may invoke the Nausf_UEAuthentication service by sending, for example, an Nausf_UEAuthentication_Authenticate Request message to the AUSF which is in the operator premises.

[0055] The Nausf_UEAuthentication_Authenticate Request message may carry either SUCI or the newly introduced alternative UE ID -PLMNNPN UE ID. The Namf_Commuincation_N1Message Notify message may further carry the Serving Network (SN) name of the SN serving the UE. The SN may be the network in which UE initiates the registration request. For example, in this scenario, the SN may be considered as belonging to the customer premises. The Nausf_UEAuthentication_Authenticate Request message may further carry a PLMNNPN service indication (or service indicator for simplicity) .

[0056] In this disclosure, the PLMNNPN service indication may indicate that the service request (or more broadly, message / signaling) is cross security domains, e.g., that the service request is initiated from a customer premises and is destined for an operator premises. The PLMNNPN service indication may also serve as a basis or a flag for the recipient to determine that the service request is imitated from a different security domain and should thus be handled / treated differently (e.g., with different security concerns) , compared with signaling initiated from the same security domain. For example, the source of the message / request / signaling is in one security domain (e.g., customer premises) and the  destination is in another security domain (e.g., operator premises) . For example, in a network deployment scenario in which both customer premises and operator premises are deployed, the PLMNNPN service indication indicates to network element in the operator premises that a corresponding message / request / signaling is from the customer premises.

[0057] In this disclosure, the PLMNNPN service indication may include at least one of:

[0058] ● The SN name (indicating the SN from which the message / service is initiated) ;

[0059] ● The PLMNNPN UE ID;

[0060] ● The AMF ID (indicating the AMF from which the message is initiated, in this case, AMF ID of AMF1) ;

[0061] ● A PLMNNPN service indicator (e.g., represented as an Information Element (IE) , a bit, a parameter, etc. ) ; or

[0062] ● The name and / or type of the message / signaling (e.g., a keyword, a particular string in the message name) . As an example, the Nausf_UEAuthentication_Authenticate Request message may be renamed to Nausf_PLMNNPN_UEAuthentication_Authenticate Request message.

[0063] Step 3: Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF sends an Nudm_UEAuthentication_Get Request to UDM. The Nudm_UEAuthentication_Get Request may carry at least one of: SUCI or PLMNNPN UE ID of UE (depending on which identifier is received in the Nausf_UEAuthentication_Authenticate Request message) ; the serving network name of the SN serving the UE; a PLMNNPN service indication, if it is carried in the Nausf_UEAuthentication_Authenticate Request message in step 2. For example, as described earlier, the PLMNNPN service indication may indicate that the service request comes from a network function that is located in the customer premises. As shown in FIG. 7, the service request is initiated by the UE / AMF1 located in the customer premises.

[0064] Step 4: Upon receiving the Nudm_UEAuthentication_Get Request, if SUCI is received, the UDM may invoke the Subscription Identifier De-concealing Function (SIDF) to de-conceal SUCI to obtain the SUPI, before UDM can process the request.

[0065] If PLMNNPN UE ID is received, the SPNF will be invoked in order to obtain SUPI of the UE. In this embodiment, the SPNF is co-located with the UDM. The SPNF is capable of de-concealing the PLMNNPN UE ID to obtain SUPI of the UE, based on a PLMNNPN UE ID generation / conversion method. For example, SPNF may decrypt the PLMNNPN UE ID to obtain SUPI of the UE. For another example, the SPNF may use the mapping of (SUPI, PLMNNPN UE ID) to obtain the SUPI of the UE.

[0066] For each Nudm_Authenticate_Get Request, the UDM / ARPF may create an Authentication Vector (AV) . As a response, the UDM may respond back to the AUSF with, for example, an Nudm_UEAuthentication_Get response message. The response message may carry the AV created by the UDM (or ARPF) .

[0067] If a SUCI is received, the Nudm_Authenticate_Get Response may further carry a PLMNNPN UE ID which may be newly generated (e.g., based on the SUPI that is de-concealed from SUCI) . If a PLMNNPN UE ID is received, the Nudm_Authenticate_Get Response may further carry a PLMNNPN UE ID of the UE. Specifically, based on operator’s policy (e.g., whether the received PLMNNPN UE ID expires, or a counter associated with the PLMNNPN UE ID is incremented) , the UDM may decide to use the same PLMNNPN UE ID received in step 4, or use a refreshed PLMNNPN UE ID. If the SUCI is received, the Nudm_UEAuthentication_Get response message may further carry the SUPI of the UE.

[0068] Note that in this step, the UDM is capable of de-concealing the PLMNNPN UE ID, to obtain SUPI of the UE (e.g., via SPNF co-locatd in the UDM) . If PLMNNPN UE ID is received from AUSF, then in the response message, the corresponding SUPI of the UE may be included.

[0069] Step 5: The AUSF may forward the AV to AMF1 using, for example, an Nausf_UEAuthentication_Authenticate Response message.

[0070] Step 6: AMF1 may send an Authentication request message to the UE.

[0071] Step 7: The UE may respond with an authentication response message carrying an authentication challenge result (RES*) to AMF1.

[0072] Step 8: The AMF1 may send an Nausf_UEAuthentication_Authenticate Request message to AUSF, carrying the authentication challenge result RES*.

[0073] Step 9: The AUSF may respond to the AMF1 with an Nausf_UEAuthentication_Authenticate Response message. This response message may carry an authentication result, indicating whether the authentication was successful or not from the perspective of the home network (i.e., the operator premises) . If the authentication was successful, the anchor key (KSEAF) will be sent to AMF1 in the Nausf_UEAuthentication_Authenticate Response message. The Nausf_UEAuthentication_Authenticate Response message may further carry SUPI of the UE.

[0074] Step 10: AMF1 may generate / derive its AMF key based on the anchor key, Kseaf, and SUPI of the UE. In some example implementations, once after AMF1 finish tasks that need SUPI as the input, it may immediately delete its local stored copy of the SUPI associated with the UE. In some other example implementations, the AMF1 may delete SUPI is following steps.

[0075] AMF1 may register with the UDM using, for example, an Nudm_UECM_Registration request message for the UE access to be registered. The message may carry at least one of: SUPI or PLMNNPN UE ID of the UE, AMF ID of AMF1.

[0076] In some example implementations, the AMF1 may desire to retain / keep the SUPI for the UE. This could be based on a predefined policy or other specific requirements. To accomplish this, the Nudm_UECM_Registration request message may include an additional indicator (e.g., SUPI retain indicator) , specifically indicating that AMF1 will or wish to retain  the SUPI for the UE.

[0077] In some example implementations, instead of an explicit indicator, the AMF ID of AMF1 itself could serve as an implicit indicator for the UDM. In this approach, the UDM may have a preconfigured database that maintains a list of AMF IDs corresponding to the AMFs that require to retain the SUPI for the UE. Therefore, upon receiving a request from an AMF1, the UDM is able to determine that AMF1 will or wish to retain the SUPI for the UE.

[0078] Step 11: Based on the AMF ID for AMF1, the UDM may determine whether the AMF is located in the customer premises (or more general, that the AMF1 is located in a different security domain) . If AMF1 is determined to be located in the customer premises, UDM may proceed to perform some PLMNNPN UE ID related tasks, which are described below.

[0079] In some example implementations, if SUPI is received in the Nudm_UECM_Registration message, the UDM may choose to generate a PLMNNPN UE ID based on the SUPI. Note that the newly generated PLMNNPN UE ID may be refreshed from a previous copy of the PLMNNPN UE ID assigned to the UE.

[0080] In some example implementations, if PLMNNPN UE ID is received in the Nudm_UECM_Registration message, based on operator’s policy (e.g., whether the received PLMNNPN UE ID expires, or a counter associated with the PLMNNPN UE ID is incremented) , the UDM may decide to retain the same PLMNNPN UE ID, or generate and use a refreshed PLMNNPN UE ID.

[0081] In some example implementations, the tasks of generating or deriving the PLMNNPN UE ID, as well as de-concealing or decrypting the PLMNNPN UE ID, may be delegated to the SPNF, which is co-located with the UDM in this example. In some other implementations, there may be a stand alone SPNF deployed in the operator premises. For example, SPNF may decrypt / de-conceal the PLMNNPN UE ID to obtain SUPI of the UE. For another example, the SPNF may use the mapping of (SUPI, PLMNNPN UE ID) to obtain the SUPI of the UE.

[0082] The UDM may respond to AMF1 with a registration response message, such as an Nudm_UECM_Registration response message. The response message may carry the PLMNNPN UE ID (whether it’s retained or refreshed) . The response message may further include an indication, which is used to instruct AMF1 to delete its local stored SUPI associated with the UE.

[0083] In some example implementations, in the request message in step 11, AMF1 may indicate it will or wish to retain SUPI for the UE, either using an explicit indicator or an implicit indicator (e.g., AMF ID of AMF1) . Based on the indicator, the UDM may grant AMF1 to retain the SUPI for the UE. In such case, UDM may add a grant indicator in the response message. Alternatively, if the response message does not carry the indicator instructing AMF1 to delete SUPI, then this absence of the indicator serves as an implicit authorization for AMF1 to retain the SUPI for that particular UE.

[0084] Step 12: In some example implementations, upon receiving the registration response message, if the message carries an explicit indicator instructing the AMF1 to delete its local stored copy of the SUPI associated with the UE, the AMF1 proceeds to delete this local copy of the SUPI.

[0085] In some example implementations, the registration response message will trigger AMF1 to delete its local stored copy of the SUPI associated with the UE, and no explicit indicator is required.

[0086] In some example implementations, AMF1 may have deleted its local stored copy of the SUPI in previous step, once after AMF1 use the SUPI information to perform certain tasks, such as deriving its AMF key.

[0087] The AMF1 may send a registration accept message to the UE, if the authentication is successful. The AMF1 may assign a new 5G-GUTI for the UE.

[0088] In this disclosure, message types and / or message names (e.g., as shown in FIGs.  7-13) are for exemplary purpose only. Different message types and / or message names may be chosen in implementation, and should still be covered by this disclosure, as far as the underlying principle is the same, for example, if the messages are used for a same purpose.

[0089] In this disclosure, a single information element in a message may be split into multiple information elements. Multiple information element may also be combined into a single information element.

[0090] In this disclosure, the steps in each embodiment are for illustration purposes only and other alternatives may be derived based on the disclosed embodiments as desired. For example, only part of the steps may need to be performed. For another example, the sequence of the steps may be adjusted. For another example, several steps may be combined (e.g., several messages may be combined in one message) . For yet another example, a single step may be split (e.g., one message may be sent via two sub-messages) .

[0091] The embodiments described in this disclosure are for exemplary purpose. Multiple embodiments may be combined, to form a new embodiment.

[0092] The accompanying drawings and description above provide specific example embodiments and implementations. The described subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is intended to be construed as not being limited to any example embodiments set forth herein. A reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, systems, or non-transitory computer-readable media for storing computer codes. Accordingly, embodiments may, for example, take the form of hardware, software, firmware, storage media or any combination thereof. For example, the method embodiments described above may be implemented by components, devices, or systems including memory and processors by executing computer codes stored in the memory.

[0093] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase  “in one embodiment / implementation” as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment / implementation” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter includes combinations of example embodiments in whole or in part.

[0094] In general, terminology may be understood at least in part from usage in context. For example, terms, such as “and” , “or” , or “and / or, ” as used herein may include a variety of meanings that may depend at least in part on the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a, ” “an, ” or “the, ” may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for existence of additional factors not necessarily expressly described, again, depending at least in part on context.

[0095] Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present solution should be or are included in any single implementation thereof. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, discussions of the features and advantages, and similar language, throughout the specification may, but do not necessarily, refer to the same embodiment.

[0096] Furthermore, the described features, advantages and characteristics of the present solution may be combined in any suitable manner in one or more embodiments. One of ordinary skill in the relevant art will recognize, in light of the description herein, that the  present solution can be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the present solution.

Claims

1.A method for wireless communication, performed by a first network element, comprising:receiving, from a second network element, a first message associated with a service request for a wireless device, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device;a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device;a Serving Network (SN) name of an SN serving the wireless device; ora service indicator indicating that the service request is initiated from a security domain different from the first network element.2.The method of claim 1, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.3.The method of claim 1, wherein the first network element comprises a Unified Data Management (UDM) .4.The method of claim 1, wherein the first network element is in a first security domain and the service request is initiated from a second security domain different from the first security domain.5.The method of claim 4, wherein the first security domain comprises an operator premises and the second security domain comprises a customer premises.6.The method of any one of claims 1-5, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the UE identifier of the wireless device;the identifier of the second network element;an indicator indicating that the service request is initiated from a customer premises; ora name or a type of the first message.7.The method of any one of claims 1-6, wherein the first message comprises an Nudm_UEAuthentication_Get request message.8.The method of one of claims 1-6, wherein the service request comprises at least one of:a registration request; oran authentication service request.9.The method of any one of claims 1-6, wherein the second network element comprises an Authentication Server Function (AUSF) .10.The method of any one of claims 1-9, further comprising at least one of:in response to the first message carrying the UE identifier of the wireless device, de-concealing the UE identifier of the wireless device via at least one of:decrypting the UE identifier to obtain the SUPI of the wireless device; ormapping the UE identifier to the SUPI of the wireless device; orin response to the first message carrying the SUCI of the wireless device, de-concealing the SUCI to obtain the SUPI of the wireless device.11.The method of claim 10, further comprising:generating an Authenticating Vector (AV) to be used for authenticating the wireless device; andtransmitting, to the second network element, a second message as a response to the first message, the second message carrying at least one of:the AV; orthe SUPI of the wireless device.12.The method of claim 11, wherein the second message comprises an Nudm_UEAuthentication_Get response message.13.The method of claim 11, wherein the second message triggers the wireless device to perform an authentication with the first network element based on the AV.14.The method of claim 11, further comprising receiving, from a third network element, a third message for registering the wireless device with the first network element, the third message carrying at least one of:the UE identifier of the wireless device;the SUPI of the wireless device; oran AMF identifier of the third network element.15.The method of claim 14, wherein:the third network element comprises an Access and Mobility Management Function (AMF) ;the third network element triggers the first message to be sent to the first network element; andthe third network element is in a security domain different from the first network element.16.The method of claim 14, wherein the third message comprises an Nudm_UECM_Registration message.17.The method of any one of claims 14-16, further comprising:in response to the third message carrying the SUPI of the wireless device, generating, based at least in part on the SUPI, a refreshed UE identifier of the wireless device which is an updated version of the UE identifier of the wireless device;in response to the third message carrying the UE identifier of the wireless device, and based on a local policy, generating the refreshed UE identifier of the wireless device; andtransmitting, to the third network element, a fourth message as a response to the third message, the fourth message carrying at least one of:the refreshed UE identifier of the wireless device; oran indicator indicating the third network element to delete its locally stored SUPI of the wireless device.18.A method for wireless communication, performed by a first network element, comprising:transmitting, to a second network element, a first message associated with a service request for a wireless device, the first message carrying at least one of:a Subscription Concealed Identifier (SUCI) of the wireless device;a User Equipment (UE) identifier of the wireless device that is associated with a Subscription Permanent Identifier (SUPI) of the wireless device;a Serving Network (SN) name of an SN serving the wireless device; ora service indicator indicating that the service request is initiated from a security domain different from the first network element.19.The method of claim 18, wherein the UE identifier of the wireless device does not belong to any one of: a SUCI; a SUPI; and a 5G-GUTI.20.The method of claim 18, wherein the first network element comprises an Access and Mobility Management Function (AMF) , and wherein the second network element comprises an Authentication Server Function (AUSF) .21.The method of claim 18, wherein the second network element is in a first security domain and the service request is initiated from a second security domain different from the first security domain.22.The method of claim 21, wherein the first security domain comprises an operator premises and the second security domain comprises a customer premises.23.The method of any one of claims 18-22, wherein the service indicator comprises at least one of:the SN name of the SN serving the wireless device;the UE identifier of the wireless device;the identifier of the second network element;an indicator indicating that the service request is initiated from a customer premises; ora name or a type of the first message.24.The method of any one of claims 18-23, wherein the first message comprises an Nausf_UEAuthentication_Authenticate request message.25.The method of any one of claims 18-23, further comprising receiving, from the second network element, a second message as a response to the first message, the second message carrying an Authentication Vector (AV) that is generated by a third network element and is to be used for authenticating the wireless device.26.The method of claim 25, wherein the third network element comprising a Unified Data Management (UDM) , and the third network element is in a security domain different from the first network element.27.The method of claim 25, wherein the second message comprises an Nausf_UEAuthentication_Authenticate response message.28.The method of claim 25, further comprising:initiating an authentication procedure with the wireless device;receiving a challenge result from the wireless device; andtransmitting, to the second network element, a third message for authenticating the wireless device, the third message comprising the challenge result.29.The method of claim 28, wherein the third message comprises an Nausf_UEAuthentication_Authenticate request message.30.The method of claim 28, further comprising receiving, from the second network element, a fourth message as a response to the third message, the fourth message carrying at least one of:an authentication result indicating whether an authentication of the wireless device with the second network element is successful or not;an anchor key generated by the second network element; orthe SUPI of the wireless device.31.The method of claim 30, further comprising:deriving an AMF key for the first network element based on the SUPI of the wireless device.32.The method of claim 30, further comprising transmitting, to the third network element, a fifth message for authenticating the wireless device with the third network element, the fifth message carrying at least one of:an AMF identifier of the first network element;the SUPI of the wireless device;the UE identifier of the wireless device; ora retaining SUPI indicator indicating that the first network element desires to retain SUPI of the wireless device.33.The method of claim 32, further comprising receiving, from the third network element, a sixth message as a response to the fifth message, the sixth message comprising at least one of:a refreshed UE identifier of the wireless device;a first indicator instructing the first network element to delete the SUPI of the wireless device; ora second indicator granting the first network element to retain the SUPI of the wireless device.34.The method of claim 33, further comprising:in response to receiving the sixth message or in response to the first indicator instructing the first network element to delete the SUPI, deleting the SUPI of the wireless device from the first network element.35.A device or a network element comprising a memory for storing computer instructions and a processor in communication with the memory, wherein the processor, when executing the computer instructions, is configured to implement a method in any one of claims 1-34.36.A computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon, the computer code, when executed by one or more processors, causing the one or more processors to implement a method of any one of claims 1-34.

Citation Information

Patent Citations

  • Method for preventing encrypted user identity from being subjected to replay attack

    CN115699672A

  • Method for preventing leakage of authentication serial number of mobile terminal

    CN116569516A

  • Method, device, and system for protecting sequence number in wireless network

    WO2022183427A1