Method and apparatus for user identification using a control plane procedure in a wireless communication system
The User Authentication Function (UAF) addresses user identification and authentication challenges in 3GPP networks by interfacing with user databases, enabling differentiated services and optimized performance for non-3GPP devices and users.
Patent Information
- Application Number
- PCT/KR2025/001264
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-02
- Filing Date
- 2025-01-23
- Publication Date
- 2025-08-07
AI Technical Summary
Current 3GPP wireless networks struggle to identify and authenticate users behind UEs, especially non-3GPP devices, and provide differentiated services based on user-specific identities, leading to inefficiencies in service provision and user experience.
Implement a User Authentication Function (UAF) that interfaces with a user database to discover and authenticate user identities, allowing for user-specific service differentiation and authorization, even in roaming scenarios, using REST-based APIs and AAA/EAP procedures.
Enables efficient user identification and authentication, ensuring differentiated services and optimized performance for both non-3GPP devices and users, supporting enhanced user experiences and network management.
Smart Images

Figure KR2025001264_07082025_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR USER IDENTIFICATION USING A CONTROL PLANE PROCEDURE IN A WIRELESS COMMUNICATION SYSTEM
[0001] Embodiments disclosed herein relate to wireless communication networks, and more particularly to devices, systems and methods for enabling a wireless network identify human users, devices or applications that are accessing the network provided services through a UE (which has a subscription to the network), in order to provide differentiated services.
[0002] Considering the development of wireless communication from generation to generation, the technologies have been developed mainly for services targeting humans, such as voice calls, multimedia services, and data services. Following the commercialization of 5G (5th generation) communication systems, it is expected that the number of connected devices will exponentially grow. Increasingly, these will be connected to communication networks. Examples of connected things may include vehicles, robots, drones, home appliances, displays, smart sensors connected to various infrastructures, construction machines, and factory equipment. Mobile devices are expected to evolve in various form-factors, such as augmented reality glasses, virtual reality headsets, and hologram devices. In order to provide various services by connecting hundreds of billions of devices and things in the 6G (6th generation) era, there have been ongoing efforts to develop improved 6G communication systems. For these reasons, 6G communication systems are referred to as beyond-5G systems.
[0003] 6G communication systems, which are expected to be commercialized around 2030, will have a peak data rate of tera (1,000 giga)-level bit per second (bps) and a radio latency less than 100μsec, and thus will be 50 times as fast as 5G communication systems and have the 1 / 10 radio latency thereof.
[0004] In order to accomplish such a high data rate and an ultra-low latency, it has been considered to implement 6G communication systems in a terahertz (THz) band (for example, 95 gigahertz (GHz) to 3THz bands). It is expected that, due to severer path loss and atmospheric absorption in the terahertz bands than those in mmWave bands introduced in 5G, technologies capable of securing the signal transmission distance (that is, coverage) will become more crucial. It is necessary to develop, as major technologies for securing the coverage, Radio Frequency (RF) elements, antennas, novel waveforms having a better coverage than Orthogonal Frequency Division Multiplexing (OFDM), beamforming and massive Multiple-input Multiple-Output (MIMO), Full Dimensional MIMO (FD-MIMO), array antennas, and multiantenna transmission technologies such as large-scale antennas. In addition, there has been ongoing discussion on new technologies for improving the coverage of terahertz-band signals, such as metamaterial-based lenses and antennas, Orbital Angular Momentum (OAM), and Reconfigurable Intelligent Surface (RIS).
[0005] Moreover, in order to improve the spectral efficiency and the overall network performances, the following technologies have been developed for 6G communication systems: a full-duplex technology for enabling an uplink transmission and a downlink transmission to simultaneously use the same frequency resource at the same time; a network technology for utilizing satellites, High-Altitude Platform Stations (HAPS), and the like in an integrated manner; an improved network structure for supporting mobile base stations and the like and enabling network operation optimization and automation and the like; a dynamic spectrum sharing technology via collision avoidance based on a prediction of spectrum usage; an use of Artificial Intelligence (AI) in wireless communication for improvement of overall network operation by utilizing AI from a designing phase for developing 6G and internalizing end-to-end AI support functions; and a next-generation distributed computing technology for overcoming the limit of UE computing ability through reachable super-high-performance communication and computing resources (such as Mobile Edge Computing (MEC), clouds, and the like) over the network. In addition, through designing new protocols to be used in 6G communication systems, developing mechanisms for implementing a hardware-based security environment and safe use of data, and developing technologies for maintaining privacy, attempts to strengthen the connectivity between devices, optimize the network, promote softwarization of network entities, and increase the openness of wireless communications are continuing.
[0006] It is expected that research and development of 6G communication systems in hyper-connectivity, including person to machine (P2M) as well as machine to machine (M2M), will allow the next hyper-connected experience. Particularly, it is expected that services such as truly immersive eXtended Reality (XR), high-fidelity mobile hologram, and digital replica could be provided through 6G communication systems. In addition, services such as remote surgery for security and reliability enhancement, industrial automation, and emergency response will be provided through the 6G communication system such that the technologies could be applied in various fields such as industry, medical care, automobiles, and home appliances.
[0007] By enabling a Fifth Generation (5G) system to allow for the creation and utilization of user-specific identities, operators will be able to offer services to devices and users that are not part of the operator's Third Generation Partnership Project (3GPP) network. For example, the network settings can be adapted, and services can be offered to users according to users' needs, using a different subscription identifier from the identifier used by the user to establish the connection.
[0008] The user to be identified could be an individual human user using a UE with a certain subscription, an application running on or connecting via a User Equipment (UE), or a device (e.g., a Personal IoT Network (PIN) Element (PINE)) behind a gateway UE (e.g., a PIN Element with Gateway Capability (PEGC)).
[0009] Use cases are discussed in 3GPP TR 22.904 and include:
[0010] - One or more users (i.e., humans) sharing one UE;
[0011] - One or more users (i.e., devices) behind one gateway UE; and
[0012] - One or more users (i.e., gaming applications) running on the same UE and each is treated as a different user.
[0013] Support for the identification of non-3GPP devices that communicate via a gateway UE, may also enable use cases such as, but not limited to, the deployment of a 5G Mobile Virtual Private Network (VPN) that is managed by the network. A 5G Mobile VPN that can provide a secure and reliable connection between an enterprise's equipment, which includes non-3GPP devices, and authorized UEs that are located off-premises. In 3GPP Rel-18 specifications, support was added for Authenticable Non-3GPP (AUN3) devices behind a 5G - Residential Gateway (5G-RG). Support for AUN3 devices requires that each device has its own subscription permanent identifier (SUPI), its own subscription data, and that a separate Non-Access Stratum (NAS) context be maintained by the Access and Mobility Management Function (AMF) and 5G-RG for each AUN3.
[0014] Furthermore, the 5G-RG establishes a separate Packet Data Unit (PDU) Session on behalf of each AUN3 device. A goal of this work is to enable the non-3GPP devices to be identified and to use only the subscription of the UE or RG to access the 5GC. Currently 3GPP has been started a study on user identities including three work tasks for the release-19 as follows:
[0015] - Supporting the use case where the user identifier of a human is associated with traffic that is to / from the UE; and
[0016] - How users are authenticated and authorized, how user identifier related functionality and information is exposed, and how the network restricts user identifiers.
[0017] The case where non-3GPP devices behind a UE or RG (5G-RG) need to be identified. The focus of this work task is how an identifier is used by the network to control and identify the traffic to / from UE or RG (5G-RG) when the traffic is associated with the non-3GPP devices. This objective differs from existing support for AUN3 devices because the objective is to enable the non-3GPP devices to be identified, and to use only the subscription of the UE or RG (5G-RG) to access the 5G Core network (5GC) (i.e., the UE or RG should have to maintain only a NAS Context itself and not for each non-3GPP device). Also, it may be possible for the non-3GPP devices to share a PDU Session.
[0018] In current state of art, wireless networks based on 3GPP technologies, for example, identify a user equipment based on a subscription identity (e.g., SUPI), which has been pre-provisioned into the mobile device (e.g., in a Subscriber Identity Module (SIM)). The device itself is further identified using an International Mobile Equipment Identity (IMEI). Such a UE could be used by different users at same or different point of times, with each user requiring a different type of service and / or treatment of traffic sent to / from the device. For example, premium users may activate superior Quality of Service (QoS) while connecting to the network through a common mobile device, while other users may use default QoS. Similarly, it may be desirable to restrict some devices to, e.g. certain human users only.
[0019] 3GPP group intends to study and support User Identification, Authentication and Authorization in its Release-19 version of specifications. By enhancing the 5G System to allow for the creation and utilization of user-specific identities, operators will be able to provide enhanced user experience, optimized performance, and offer services to devices and users that are not part of the operator's 3GPP network. This will allow the operator to charge and provide service differentiation based on the user identifier.
[0020] It is expected that the 5GS system is able to meet following requirements:
[0021] - It should be able to link or unlink a user with a specific UE subscription (e.g., SUPI).
[0022] - It should be able to ensure that a user connects to the network using a specific set of UE Subscriptions (e.g., SUPIs) only.
[0023] - It should be able to ensure only a limited set of users are able to operate via a UE subscription (e.g., SUPI).
[0024] - Network should be able to work with 3rd party user identities.
[0025] - User validation may be done at application layer.
[0026] - 3rd parties should be able to initiate authentication when a user accesses a 3rd party application.
[0027] - Network should be able to restrict some users when the associated UE is roaming based on the user profile.
[0028] Hence, there is a need in the art for solutions which will overcome the above mentioned drawback(s), among others.
[0029] The principal object of embodiments herein is to disclose an enhanced network architecture to enable network service providers to identify users behind UEs while ensuring above requirements, authenticate and authorize them and then provide differentiated services.
[0030] Another object of embodiments herein is to disclose methods for enabling network service providers to identify users behind UEs while ensuring above requirements, authenticate and authorize them and then provide differentiated services.
[0031] Another object of embodiments herein is to disclose methods and systems for providing an enhanced user experience, optimized performance, and offer services to devices and users that are not part of the operator's 3GPP network, the 5G System can be enhanced to allow for the creation and utilization of user-specific identities.
[0032] Another object of embodiments herein is to disclose methods and systems for allowing a particular user to use the UE using a user identifier in a PLMN.
[0033] Another object of embodiments herein is to disclose methods and systems for disallowing / restricting a user from using the UE using a user identifier in a PLMN.
[0034] Another object of embodiments herein is to disclose methods and systems for sending the user identifier in the PDU session, so that the network selects the user profile for that user identifier and performs the authentication.
[0035] Another object of embodiments herein is to disclose methods and systems for restricting and / or allowing the user by verifying whether the policy allows that particular user identifier, in case of a Local Breakout Roaming scenario.
[0036] Another object of embodiments herein is to disclose methods and systems for restricting and / or allowing the user upon getting the indication from the Home SMF (H-SMF) and / or by verifying the subscription data, in case of a Home Routed Roaming scenario.
[0037] Another object of embodiments herein is to disclose methods and systems for verifying whether a legitimate user is using the service.
[0038] Another objective of embodiments is to ensure and / or verify that the Authentication message received from the user is fresh and has not been previously sent by the home network (integrity and replay protection of the message received from the user / UE).
[0039] Accordingly, the embodiments herein provide a method for performing user authentication and authorization in a Third Generation Partnership Project (3GPP) network. The method comprises receiving, by the UAF 102, a user authentication request from a User Equipment (UE) via a Session Management Function (SMF). The method comprises discovering, by the UAF, a user database, based on the received user ID; and forwarding , by the UAF, an authentication request to the user database to trigger user authentication. The method further comprises relaying transparently , by the UAF, to at least one authentication message between the user database, and the UE, via the SMF.
[0040] Accordingly, the embodiments herein provide a User Authentication function (UAF) comprising a processing module; a memory; and a transceiver. The processing module is coupled with the memory, and the transceiver, and configured to receive a user authentication request from a User Equipment (UE) via a Session Management Function (SMF). The processing module is configured to discover a user database, based on the received user ID; and forward an authentication request to the user database to trigger user authentication. The processing module is further configured to relay transparently to at least one authentication message between the user database, and the UE, via the SMF.
[0041] Accordingly, the embodiments herein provide a User Authentication function (UAF) comprising a processing module; a memory; and a transceiver. The processing module is coupled with the memory, and the transceiver, and configured to receive a user authentication request from a User Equipment (UE). The processing module is configured to select a User Authentication function (UAF) based on at least one of a domain name in the received user ID, and a Public Land Mobile Network (PLMN) ID of home network of the UE, on successfully authenticating the UE; and send the user authentication request to the selected UAF.
[0042] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating at least one embodiment and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein without departing from the spirit thereof, and the embodiments herein include all such modifications.
[0043] Aspects of the disclosure are to address at least the above-mentioned problems and / or disadvantages and to provide at least the advantages described below. Accordingly, an aspect of the disclosure is to provide efficient communication methods in a wireless communication system.
[0044] Embodiments herein are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the following illustratory drawings. Embodiments herein are illustrated by way of examples in the accompanying drawings, and in which:
[0045] FIG. 1 depicts a wireless communication network, according to embodiments as disclosed herein;
[0046] FIG. 2 depicts an example non-roaming architecture, according to embodiments as disclosed herein;
[0047] FIG. 3 depicts an example non-roaming architecture, according to embodiments as disclosed herein;
[0048] FIG. 4 depicts an example roaming architecture, according to embodiments as disclosed herein;
[0049] FIGs. 5A and 5B show an example call-flow for user-authentication and / or authorization procedure, according to embodiments as disclosed herein;
[0050] FIGs. 6A and 6B depict the procedure when User Authentication is performed locally at the UE, and network is only responsible for ensuring authorization, according to embodiments as disclosed herein;
[0051] FIGs. 7A and 7B depict the procedure where User Access to the device triggers the Registration and / or PDU Session Establishment and / or PDU Session Modification procedure from the associated UE, according to embodiments as disclosed herein;
[0052] FIGs. 8A and 8B showcase the procedure when the User access is triggered by the UE by sending PDU Session Establishment Request, PDU Session Modification Request or Registration Request message (similar to FIGs. 7A and 7B), wherein the user authentication is not performed locally, according to embodiments as disclosed herein;
[0053] FIG. 9 depicts the process of validating the list of allowed users in the subscription data, according to embodiments as disclosed herein;
[0054] FIG. 10 depicts the process of performing user ID verification in the home network, according to embodiments as disclosed herein; and
[0055] FIG. 11 depicts the process of performing user ID verification and integrity check in the visited network, according to embodiments as disclosed herein.
[0056] FIG. 12 is a flowchart depicting a method for performing user authentication and authorization in a Third Generation Partnership Project (3GPP) network, according to embodiments as disclosed herein;
[0057] FIG. 13 depicts the UAF, according to embodiments as disclosed herein; and
[0058] FIG. 14 depicts the SMF, according to embodiments as disclosed herein.
[0059] FIG. 15 illustrates is a structure of a user equipment according to embodiments of the disclosure.
[0060] FIG. 16 illustrates is a structure of a network entity according to embodiments of the disclosure.
[0061] Aspects of the disclosure are to address at least the above-mentioned problems and / or disadvantages and to provide at least the advantages described below. Accordingly, an aspect of the disclosure is to provide a terminal and a communication method thereof in a wireless communication system.
[0062] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.
[0063] For the purposes of interpreting this specification, the definitions (as defined herein) will apply and whenever appropriate the terms used in singular will also include the plural and vice versa. It is to be understood that the terminology used herein is for the purposes of describing particular embodiments only and is not intended to be limiting. The terms "comprising", "having" and "including" are to be construed as open-ended terms unless otherwise noted.
[0064] The words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.," , "i.e.," are merely used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein using the words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.," , "i.e.," is not necessarily to be construed as preferred or advantageous over other embodiments.
[0065] Embodiments herein may be described and illustrated in terms of blocks which carry out a described function or functions. These blocks, which may be referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by a firmware. The circuits may, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments may be physically separated into two or more interacting and discrete blocks without departing from the scope of the disclosure. Likewise, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the disclosure.
[0066] It should be noted that elements in the drawings are illustrated for the purposes of this description and ease of understanding and may not have necessarily been drawn to scale. For example, the flowcharts / sequence diagrams illustrate the method in terms of the steps required for understanding of aspects of the embodiments as disclosed herein. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein. Furthermore, in terms of the system, one or more components / modules which comprise the system may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.
[0067] The accompanying drawings are used to help easily understand various technical features and it should be understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the present disclosure should be construed to extend to any modifications, equivalents, and substitutes in addition to those which are particularly set out in the accompanying drawings and the corresponding description. Usage of words such as first, second, third etc., to describe components / elements / steps is for the purposes of this description and should not be construed as sequential ordering / placement / occurrence unless specified otherwise.
[0068] The embodiments herein achieve systems and methods for enabling a wireless network identify human users, devices or applications that are accessing the network provided services through a UE with subscription to the network, in order to provide differentiated services. Referring now to the drawings, and more particularly to FIGS. 1 through 14, where similar reference characters denote corresponding features consistently throughout the figures, there are shown embodiments.
[0069] Embodiments herein use the term "User" to refer to a human, and / or device, and / or application which is connecting to the network via a user device (for example, UE). The term "UE" or mobile device is used to indicate a user equipment configured with subscription to access the network using, for example, a SIM / eSIM.
[0070] FIG. 1 depicts a wireless communication network 100. Embodiments herein disclose two network functions in the 3GPP Packet Core architecture; a user database (herein referred to as an Authentication Function (AuF), a Unified Data Management (UDM), a Unified Data Repository (UDR), or a User Information Database Function (UIDF) interchangeably) 101; an interface between existing the 3GPP core network and the user database (hereinafter referred to as a User Authentication Function (UAF)) 102, at least one User Equipment (UE) 103, an Access and Mobility Management Function (AMF) 104, and a Session Management Function (SMF) 105, at least one Unified Data Repository (UDR) 106, and a Unified Data Management (UDM) 107.
[0071] The user database 101 can expose one or more Representational State Transfer (REST) based APIs to allow other network functions perform read and / or write operations into the network function. The user database 101 can comprise authentication data, subscription data, context data, and so on. In an embodiment herein, the authentication data may include the selected authentication method, authentication vectors, and other possible parameters.
[0072] In an embodiment herein, the Subscription information may include allowed UEs (terminals that a user is allowed to connect from), allowed countries from where the user is allowed to connect from (which may be identified using, for example, MCC); and allowed PLMNs (Serving Networks) that the user is allowed to connect from. The user subscription data may include the allowed UEs for the user, allowed Mobile Country Code (MCC) / Allowed PLMNs / Allowed Tracking Area identities (TAIs), allowed serving networks, user consent and other possible parameters.
[0073] In an embodiment herein, the context data may include authentication Status, Virtual ID / User Identity, and so on, connected UE Details (the last known UE that the user connected from); and serving Network / Country (last known country and / or PLMN that the user connected from). The user database may also comprise the user's current authentication status, roaming status, and so on.
[0074] In an embodiment herein, the user database 101 can be independent from the UDR / UDM 106 / 107, which comprises a UE Subscription database. In an embodiment herein, the user database 101 can be co-located with other network functions such as, but not limited to, the UDR / UDM 106 / 107. In an embodiment herein, the user database 101 can be combined into the UDR / UDM 106 / 107; for example, by defining additional services. Alternatively, the functions defined for the user database 101 may be divided into multiple existing or new network functions.
[0075] In an embodiment herein, the discovery of the user database 101 can be done based on input(s) from the UE 103 which will contain the user details. In an embodiment herein, the discovery of the user database 101 can be based on input(s) present in the subscription for that particular user profile. In an embodiment herein, the discovery of the user database 101 can be based on a domain name contained in a User-ID provided by the UE 103.
[0076] The UE subscription data (which is stored in the UDR / UDM 106 / 107) can include the type of users (human / machine) allowed to use the UE (subscription); allowed user identities (users allowed to connect using this subscription); allowed user domain names (user domains allowed to connect using this subscription); maximum simultaneous users / devices; and the UAF responsible for interfacing with the user database of the user.
[0077] The UAF 102 can be an interface between existing 3GPP core network and the user database 101. The UAF 102 can store the user's context in the core network, initiating user's authentication with the user database 101, supporting roaming, playing the role of EAP Proxy and / or AAA Proxy, and / or a general authentication proxy between the UE 103 and the user database 101, depending on the authentication method chosen. In an embodiment herein, the UAF 102 can be present / located either in the home Public Land Mobile Network (PLMN) (HPLMN) and / or the visited PLMN (VPLMN).
[0078] In an embodiment herein, the UAF 102 and / or the user database 101 can be selected by the AMF / SMF / NEF can be based on the user's domain name, and / or the UE's home network.
[0079] The UAF 102 can expose REST based APIs to allow other network functions perform read and / or write operations into the network function. In an embodiment herein, the UAF 102 can be co-located with other network functions, such as, but not limited to, AMF / SMF 104 / 105. In an embodiment herein, the functionality can be combined with such network functions. Alternatively, the functions of the UAF 102 can be divided into multiple existing or new network functions.
[0080] With these additional network functions, FIGs.2, 3, and 4 depict proposed network architectures for roaming and non-roaming scenarios, and the network functions which are expected to be majorly involved in a user's authentication and / or procedure.
[0081] FIG. 2 depicts an example non-roaming architecture, wherein the UE 103 sends the user authentication and / or authorization request to the AMF 104, and the AMF 104 forwards the request to the UAF. The UAF 102 then interfaces with the user database 101 to initiate user authentication and / or authorization. The network architecture further comprises a User Plane Function (UPF) 108, a Network Exposure Function (NEF) 109, a Policy Control Function (PCF) 110, and an Authentication Server Function (AUSF) 111.
[0082] FIG. 3 depicts an example non-roaming architecture, wherein the UE 103 sends the user authentication and / or authorization request to the SMF 105 (via the AMF 104). The SMF 105 forwards the request to the UAF 102. The UAF 102 then interfaces with the user database 101 to initiate user authentication and / or authorization.
[0083] FIG. 4 depicts an example roaming architecture, wherein the UE 103 sends the user authentication and / or authorization request to the AMF 104 and the AMF 104 forwards the request to the UAF 102. The UAF 102 then interfaces with the user database 101 to initiate User Authentication and / or Authorization. As shown in FIG. 4, the AMF 104 may connect to a local UAF (V-UAF) 102B, which is then responsible to connect to the user's user information (present in a user database). The user database 101 can further be located in the home network of the UE 103, in which case, the V-UAF 102B may contact the H-UAF 102A which then connects to the user database 101. Alternatively, the V-UAF may reach the user database 101 directly, when for example, the User database 101 belongs to a partner with which visited network has a direct relationship. In an alternate implementation, the V-UAF 102B may decide to reach the User database 101 via the H-UAF 102A, in case the V-UAF 102B was not able to serve the UE 103 by reaching the user database 101 directly. Alternatively, the AMF 104 may directly interface with the H-UAF 102A.
[0084] When the functionality of user authentication is implemented via SMF 105, the H-SMF may be responsible to interface with the UAF 102 in the home network. For local breakout scenarios, the SMF 105 in the visited network will be responsible for interfacing with H-UAF directly, or via a V-UAF 102B similar to the AMF case.
[0085] FIGs. 5A and 5B shows an example call-flow for user-authentication and / or authorization procedure with above architecture.
[0086] Control-Plane procedure after Registration or PDU Session Establishment:
[0087] As depicted in FIG. 5A, in step 501A, the UE 103 performs registration procedure and / or PDU Session Establishment Procedure as detailed in 3GPP TS 23.502. In step 502A, a user triggers the device access using implementation specific methods on the UE 103 (for example, by tapping on an option in an App on the UE). In step 503A, the UE 103 sends a user authentication and / or authorization request to the AMF 104 and / or SMF 105. If the AMF 104 interfaces with UAF (as depicted in FIG. 2), the request is provided to the AMF 104 in a new or existing NAS message. If the SMF 105 interfaces with the UAF (as depicted in FIG. 3), the request first goes to the AMF 104 in a new or existing NAS message, which then forwards the request to the SMF 105 using SBI. The UE 103 may include the User ID provided by the user and other possible information in the Authentication and / or Authorization request. In an embodiment herein, the User ID may contain a real user identity. In an embodiment herein, the User ID may contain an anonymized user identity. On receiving the User Authentication and / or Authorization request, in step 504A, a NF in the Serving-PLMN (which can be one of the AMF / SMF / UAF, hereinafter referred to as a requesting NF) initiates the UE subscription retrieval procedure with the user database 101. Initiating the UE subscription retrieval procedure request comprises determining the users and / or user-domains allowed to access the UE 103. On receiving the subscription data request, the user database 101 checks whether the user subscription data is available for the received UE ID. If available, the user database 101 provides the user subscription data to the requesting NF in a UE Subscription data response message. Alternatively, the requesting NF can provide the received User ID and or USER-Domain to UDM so that UDM itself can perform the required validation. On receiving the subscription data from the UDM, in step 505A, the AMF 104 and / or SMF 105 performs the subscription validation check. When performing the subscription validation check, the VPLMN NF should have the knowledge whether the user ID is allowed to access the services via the respective UE. In an embodiment herein, the requesting NF can perform the subscription validation only if the real user ID in step 503A. In an embodiment herein, if the UDM provides user-domain(s) allowed to access the UE, the validation can be performed even if the UE 103 had provided anonymous user-id along with the domain name. In an embodiment herein, the AMF and / or SMF and / or UAF can perform the subscription validation check after retrieving the UE subscription data from the user database 101. If the subscription validation fails, in step 506A, the requesting NF sends the User Authentication and / or Authorization Reject message to the UE 103. If the subscription check succeeds, in step 507A, the AMF 104 and / or SMF 105 performs the UAF (User Authentication Function) selection (either HPLMN UAF / VPLMN UAF) based on a plurality of factors, wherein the plurality of factors comprise of the domain name contained in User ID, the UE's home network PLMN ID, and so on. In step 508A, the AMF 104 and / or SMF 105 sends the user authentication and authorization request to the selected UAF.
[0088] As depicted in FIG. 5B, in step 501B, the UAF 102 proceeds with performing user authentication and / or authorization. This procedure may be done at the application layer, or using AAA / EAP procedures (wherein the UAF 102 plays the role of an AAA / EAP Proxy). For the purpose of illustration, assume that the procedure succeeds. A real or a virtual user identity may be provided to the UAF 102 at the end of the procedure, especially when an anonymous user identity was used in step 503A of FIG. 5A. On receiving the user identity, in step 502B, the UAF 102 initiates the user subscription data validation for that particular user. In an example, this may involve retrieval of the user subscription data from the user database 101, wherein the retrieved user subscription data may include the allowed UEs for the user, allowed MCC / Allowed PLMNS / Allowed TAIs, allowed Serving networks, user consent and other possible parameters. If the User Subscription check fails, in step 503B, the VPLMN / HPLMN UAF 102 may send the authentication and authorization reject message to the AMF / SMF 104 / 105. Upon receiving the authentication and authorization response message from the UAF 102, in step 504B, the AMF / SMF 104 / 105 may send the user authentication and / or authorization response to the UE 103, wherein the response includes the authentication results and the reject cause. If the subscription check succeeds, in step 505B, the VPLMN / HPLMN UAF 102 sends the user authentication and / or authorization accept message to the AMF / SMF 104 / 105, which may include the User ID as received in step 501B. After receiving the authentication and / or authorization accept message, in step 506B, the AMF / SMF 104 / 105 may perform the UE subscription validation. This step is similar to step 505A of FIG. 5A, and is performed if the user identity was not known earlier. In an embodiment herein, the AMF 104 and / or SMF 105 and / or UAF 102 can perform the subscription validation check after retrieving the UE subscription data from the user database 101, wherein the validation comprises checking if the UE 103 is being operated by an authorized user only. If the AMF / SMF 104 / 105 is not provided with the real user ID, the UE subscription validation is performed after obtaining the real user identity. Based on the UE subscription validation results, in step 507B, the VPLMN AMF / SMF 104 / 105 can reject the user authentication and / or user authorization request and send a response to the UE 103 (step 507Ba). Further, based on the UE subscription validation, the AMF 104 and / or SMF 105 can send a negative acknowledgement to the UAF 102 (step 507Bb). The UAF 102 can accordingly proceed with updating the user context information in the user database 101. Based on the UE subscription validation results, in step 508B, the VPLMN AMF / SMF 104 / 105 can send a user authentication and / or user authorization response to the UE 103, wherein this response includes the user authentication and / or user authorization accept message (if the subscription is valid). Based on the user authentication and / or user authorization accept, the VPLMN AMF / SMF 104 / 105 sends the UE context update message with the user information to the user database 101.
[0089] The same flows can be re-used for the roaming case by considering the roaming architectures disclosed herein.
[0090] FIGs. 6A and 6B depict the procedure when User Authentication is performed locally at the UE, and network is only responsible for ensuring authorization. Consider FIG. 6A, this procedure is similar to FIG. 5A with the only difference in step 602A, where the User's authentication is performed locally (for example, using biometrics, triggered by a local App). Following this, the UE 103 proceeds with user authorization using a real or anonymized identity.
[0091] Similarly, in FIG. 6B, the procedure is similar to FIG. 5B, with the only difference in step 601B. Step 601B may be performed if the UE 103 had used an anonymized user id in step 603A of FIG. 6A and the real or virtual user identity needs to be provided to the 5GC (e.g. UAF / SMF / AMF). This procedure does not involve User authentication.
[0092] Control-Plane procedure during Registration or PDU Session Establishment with local authentication at the UE:
[0093] FIGs. 7A and 7B depict the procedure where user access to the device triggers the Registration and / or PDU Session Establishment and / or PDU Session Modification procedure from the associated UE. The call-flow is depicted for the scenario where user authentication is performed locally, similar to FIGs. 6A and 6B. Similar procedure can be applicable for the scenario where User Authentication is performed between the UE 103, and the user database 101, as in FIGs. 5A and 5B.
[0094] As depicted in FIG. 7A, when a new user accesses the UE 103, in step 701A, an app in the UE 103 authenticates the user locally by verifying the user; for example, using user biometrics, password / key, pattern, and so on. On successful authentication, in step 702A, the UE s101 ends one of a PDU Session Establishment Request, a PDU Session Modification Request, or a Registration request to the serving network (AMF / SMF 104 / 105). In an embodiment herein, the UE 103 can include the User ID in the request, wherein the User ID can be the real user ID, or an anonymized user ID. In step 703A, the AMF 104 and / or SMF 105 proceeds with performing the PDU Session Establishment, PDU Session modification, or Registration procedure as detailed in 3GPP TS 23.502. At any time when above procedures are progressing at the AMF 104, or the SMF 105, in step 704A, the AMF 104 and / or SMF 105 may retrieve the UE subscription data for allowed users from the user database 101 using a request, wherein the request may include the User-ID (if the user-ID has been received from the UE 103), and / or the domain of the User-ID. Upon receiving the subscription data request, the user database 101 may check whether the user subscription data is available for the received UE ID, and / or if the user or the user's domain is allowed to access the network via the respective UE. If the user subscription data is available for the received UE ID, and / or if the user or the user's domain is allowed to access the network via the respective UE, the user database 101 provides the subscription data to the requesting NF in a UE Subscription data response message for that particular UE ID, and includes the allowed user list. On receiving the subscription data from the UDM, in step 705A, the AMF 104 and / or SMF 105 performs the subscription validation check. Performing the subscription validation check comprises the VPLMN NF (i.e., AMF 104 and / or SMF 105) checking if the User ID or the user's domain is allowed to access the network, via the respective UE. If the subscription check fails, in step 706A, the VPLMN NF may send a Registration Reject, a PDU Session Establishment Reject, or a PDU Session Modification Reject message to the UE 103, with a cause-code indicating that the respective user is not allowed to access the UE 103. Alternatively, the VPLMN NF may send a Registration Accept, a PDU Session Establishment Accept, or a PDU Session Modification Accept message to the UE 103 with a cause-code indicating that the respective user is not allowed to access the UE 103. If the subscription check succeeds, in step 707A, the VPLMN NF performs the UAF (User Authentication Function) selection (which can be the HPLMN UAF / VPLMN UAF). In step 708A, the VPLMN NF sends a User Authentication and Authorization Request to the UAF 102.
[0095] As depicted in FIG. 7B, in step 701B, the UAF 102 proceeds with User Identity Retrieval from the user database 101, especially if an anonymous user identity was provided in step 702A of FIG. 7A. The procedure may involve a communication between the UE and the user database 101, via the UAF 102. At the end of this procedure, the user database 101 may provide a real user identity, or a virtual user identity to the UAF 102. A virtual identity ensures that the serving network does not store the user identity for a long term, as the virtual identity is typically time-bound. In an embodiment herein, the user database 101 stores the mapping of the real user identity and the provided virtual user identity. On receiving the user identity, in step 702B, the UAF 102 initiates the user subscription data retrieval from the user database 101 for the received User ID. The user subscription data includes the allowed UEs for the user, allowed MCC / Allowed PLMNS / Allowed TAIs, allowed Serving networks, user consent and other related parameters. Upon receiving the user subscription data, the VPLMN UAF / HPLMN UAF 103 validates the user subscription data and checks whether the requesting user is allowed to use the claiming services via the respective UE. If the subscription check in step 702B is not successful (for example, the user is not allowed to access from the respective UE), in step 703B, the VPLMN / HPLMN UAF 103 sends the user authentication and authorization reject message to the AMF / SMF 104 / 105. On receiving the user authentication and authorization reject message, in step 704B, the AMF / SMF 104 / 105 sends a Registration Reject, PDU Session Establishment Reject, or a PDU Session Modification Reject message to the UE 103 with a cause-code indicating that the respective user is not allowed to access the UE 103. Alternatively, the AMF / SMF 104 / 105may send a Registration Accept, a PDU Session Establishment Accept, or a PDU Session Modification Accept message to the UE 103 with a cause-code indicating that the respective user is not allowed to access the UE 103. If the subscription check in step 702B was successful, in step 705B, the VPLMN / HPLMN UAF 102 sends a user authentication and authorization accept message to the AMF / SMF 104 / 105 including the user ID. If the user identity was not validated against UE subscription in step 705A of FIG.7A, in step 706B, the AMF / SMF 104 / 105 proceeds with validating if the user is allowed to access the given UE. In an embodiment herein, the AMF 104, and / or the SMF 105, and / or the UAF 102 can perform the subscription validation check after retrieving the UE subscription data from the user database 101. This validation is performed to check whether the allowed UE is allowed to be operated by the user. If the AMF / SMF 104 / 105 is not provided with the real user ID, the AMF 104, and / or the SMF 105, and / or the UAF 102 can perform the UE subscription validation after obtaining the real user identity. If the subscription check is not successful, in step 707B, the AMF / SMF 104 / 105 may send a negative acknowledgement to the UAF 102 (step 707Bb), so that the UAF 102 can update the user database 101 that the user is not allowed to use the UE in the serving-network (step 707Bd). This may additionally result in the AMF / SMF 104 / 105 sending a Registration Reject, a PDU Session Establishment Reject, and / or a PDU Session Modification Reject message to the UE 103 with a cause-code indicating that the respective user is not allowed to access the UE 103. Alternatively, the AMF / SMF 104 / 105 may send a Registration Accept, a PDU Session Establishment Accept, and / or a PDU Session Modification Accept message to the UE 103 with a cause-code indicating the respective user is not allowed to access the UE 103 (step 707Ba). On the other hand, if the subscription check is successful, the AMF / SMF 104 / 105 may send a Registration Accept, a PDU Session Establishment Accept, and / or a PDU Session Modification Accept message to the UE 103 with a cause-code indicating the respective user is allowed to access the UE 103 (step 707Ba). Additionally, the AMF / SMF 104 / 105 may update the user database 101 that the UE 103 is being accessed by the User ID (step 707Bc).
[0096] Control-Plane procedure during Registration or PDU Session Establishment:
[0097] FIGs. 8A and 8B showcase the procedure when the User access is triggered by the UE by sending PDU Session Establishment Request, PDU Session Modification Request or Registration Request message, similar to FIGs. 7A and 7B, but the user authentication is not performed locally.
[0098] In FIG. 8A, the only difference from FIG. 7A is that, on the user triggering device access, the UE triggers a PDU Session Establishment, a PDU Session Modification or a Registration procedure with the network by sending a request, wherein the requests comprise the user identity. Rest of the procedure is same as FIG. 7A.
[0099] In FIG. 8B, step 801B involves the UAF 102 initiating user authentication between the UE 103, and the user identification database 101. Upon successful authentication, the UAF 102 provides User identity to the UAF, especially when anonymous identity was used earlier. Rest of the procedure is same as FIG. 8A.
[0100] User Authentication by validating the list of allowed users in the subscription data:
[0101] FIG. 9 depicts the process of validating the list of allowed users in the subscription data. In this embodiment herein, a UAF in the VPLMN (V_UAF) 102A sends the subscription data request (both UE and user subscription) to the user database 101 via the NEF 109. The NEF API exposure can be reused to get the UE 103, and user subscription data from the user database 101.
[0102] In another embodiment herein, the V_UAF 102A gets the user subscription data from the user database 101 using the NEF API exposure.
[0103] In another embodiment herein, the V_UAF 102A sends the subscription data retrieval message to the user database 101, via the H-UAF 102A.
[0104] Adding user Identifier in the PDU session:
[0105] For home routed based roaming, the V-SMF 105A sends a PDU session establishment request to the H-SMF (not shown). The H-SMF checks whether the User ID is allowed to be used in the VPLMN by verifying the user subscription data / policy and allows / rejects / restricts the user ID based on the subscription and / or policy.
[0106] For the LBO case, based on the local policy, the V-SMF 105A allows / rejects / restricts the user for the respective user identities.
[0107] Based on the user ID provided in the PDU session, the network (AMF / SMF) can select the user profile for that particular user ID and authenticate the user that is requesting the service.
[0108] User ID verification in the home network:
[0109] FIG. 10 depicts the process of performing user ID verification in the home network. In step 1001, the user creates a user ID using a public user ID, password, freshness parameter (for example, Nonce,) and other related parameters. In an embodiment herein, a hashing function can be used to create the public user ID. In step 1002, the UE 103 sends the user registration and / or user authentication request to the home network (H-AMF) 104A, wherein the request includes the SUCI / SUPI, user ID and other possible parameters. In step 1003, the H-AMF 104A forwards the user registration and / or user authentication request to the H-UAF 102A, wherein the forwarded request includes the SUCI / SUPI, User ID, TAI and related parameters. On receiving the User Registration and / or User Authentication request, in step 1004, the H-UAF 102A verifies the user ID either by checking with a third party (wherein the third party is the ID provider) or by generating a user ID at the network side for the requesting User. For generating the user ID for example, the H-UAF 102A can use a Nonce / Hashing function as the hash function for ensuring data integrity and message authentication. If the user ID verification is successful at the network, in step 1005, the H-UAF 102A sends the subscription data update / UE context update message to the user database 101. If the user ID verification is successful at the network, the H-UAF 102A rejects the request from the UE 103. In step 1006, the user database 101 performs the subscription data update based on the request from the H-UAF 102A. In step 7, the user database 101 sends the acknowledgement to the H-UAF 102A. In step 1008, the H-UAF 102A sends the User Registration and / or User Authentication response to the UE 103, wherein this response includes the User Registration and / or User Authentication accept message.
[0110] User ID verification and integrity check in the visited network:
[0111] FIG. 11 depicts the process of performing user ID verification and integrity check in the visited network. In step 1101, the UE 103 sends the authentication request to the VPLMN AMF (V-AMF) 104A, wherein the authentication request includes the UE ID, user ID, the registration time, and other related parameters. Upon receiving the request from the UE 101, in step 1102, the V-AMF 104A sends the authentication request to the VPLMN UAF. The message includes the UE ID, User ID, Registration time, TAI, SN Name / SN ID and other possible parameters. On receiving the request from the V-AMF 104A, in step 1103, the V-UAF 102B forwards the authentication request to the H-UAF 102A, wherein the authentication request includes the UE ID, User ID, Registration time, TAI, SN Name / SN ID and other related parameters. In step 1104, the H-UAF 102A checks the freshness of the timestamp and initiates the user verification. In step 1105, the H-UAF 102A sends the subscription data request to the user database 101 for the requesting user ID, wherein the subscription data request includes the UE ID, User ID, Registration Time, TAI, SN Name / SN ID, new time stamp and other related parameters. In step 1106, the user database 101 provides the subscription data for the received User ID and the UE ID, wherein the subscription data includes the allowed user ID, allowed UE ID, allowed PLMNs, Allowed SN Name and Allowed MCC. On receiving the subscription data from the UDM, if the user ID is allowed, in step 1107, the H-UAF 102A performs mutual authentication for the user with the third party (wherein the third party is the ID provider). If the subscription data is not allowed, then the H-UAF 102A rejects the request. In step 1108, the H-UAF 102A sends the user authentication response to the V-UAF 102B, wherein the user authentication response includes the authentication results, and the new time stamp. On receiving the user authentication response from the H-UAF 102A, in step 1109, the V-AMF 104A sends the user authentication response to the UE, wherein the user authentication response includes the authentication results, and the new time stamp.
[0112] In an embodiment herein, the V-AMF 104A can directly send the authentication request to the H-UAF 102A, and the H-UAF 102A can accordingly perform the user authentication procedure.
[0113] FIG. 12 is a flowchart depicting a method for performing user authentication and authorization in a Third Generation Partnership Project (3GPP) network. In step 1201, a user triggers the device access using implementation specific methods on the UE 103 (for example, by tapping on an option in an App on the UE). In step 1202, the UE 103 sends a user authentication request to the UAF 102, via the AMF 104 and / or the SMF 105, wherein the user authentication request comprises the user ID of the user (which can be the real ID or the anonymized user ID). In step 1203, the UAF 102 receives the user authentication request from the UE 103, wherein the user authentication request comprises the user ID of the user. Based on the received user ID, in step 1204, the UAF 102 discovers the user database 101, which will contain the details of the user who triggered the device access. In an embodiment herein, the discovery of the user database 101 can be done based on input(s) from the UE 103 which will contain the user details. The user database comprises user subscription information, user authentication information, current authentication status of the user, and context data, wherein the user subscription information comprises at least one UE that the user is allowed to use, and the user authentication information comprises at least one selected authentication method, and at least one authentication vector. The user database is one of an AuF, a UDM, a UDR, and a UIDF. In an embodiment herein, the discovery of the user database 101 can be based on input(s) present in the subscription for that particular user profile. In an embodiment herein, the discovery of the user database 101 can be based on a domain name contained in a User-ID provided by the UE 103. In step 1205, the UAF 102 forwards an authentication request to the discovered user database to trigger the user authentication. In step 1206, the user database 101, the UAF 102, and the UE 103 perform user authentication and / or UE authentication, wherein the UAF 102 replies transparently to at least one authentication message between the user database 101, and the UE 103, via the AMF 104 and / or the SMF 105.
[0114] In an embodiment herein, the UE 103 sends the user authentication request to the SMF 105. On receiving the user authentication request, the SMF 105 authenticates and authorizes as to whether the user is allowed to use the UE 103. The SMF 105 further selects the UAF 102 based on at least one of a domain name in the received user ID, and the PLMN ID of home network of the UE 103, on successfully authenticating the UE 103. The SMF 105 further sends the user authentication request to the selected UAF 102.
[0115] In an embodiment herein, the UE 103 sends the user authentication request to the SMF 105. On receiving the user authentication request, the SMF 105 selects the UAF 102 based on at least one of a domain name in the received user ID, and the PLMN ID of home network of the UE 103. The SMF 105 further sends the user authentication request to the selected UAF 102. On receiving the user authentication request, the UAF 102 authenticates and authorizes as to whether the user is allowed to use the UE 103.
[0116] In an embodiment herein, the SMF 105 validates the profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE 102.
[0117] In an embodiment herein, the UAF 102 validates the profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE 102.
[0118] In an embodiment herein, the UAF 102 stores the user's context in the core network, wherein the UAF 102 supports roaming. The UAF plays the role of a proxy between the UE 103, and the user database 101. The UAF 102 further exposes one or more REST based APIs. The various actions in method 1200 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 12 may be omitted.
[0119] FIG. 13 depicts the UAF. The UAF 102, as depicted, comprises a processing module 1301, at least one memory 1302, and at least one transceiver 1303. The processing module 1301 can be at least one of a single processor, a plurality of processors, multiple homogeneous or heterogeneous cores, multiple Central Processing Units (CPUs) of different kinds, microcontrollers, special media, and other accelerators. The processing module 1301 may be an Application Processor (AP), a graphics-only processing unit such as a Graphics Processing Unit (GPU), a Visual Processing Unit (VPU), and / or an Artificial Intelligence (AI)-dedicated processor such as a Neural Processing Unit (NPU).
[0120] In an embodiment herein, the at least one transceiver 1303 is configured to enable communication between the UAF 102, and at least one external entity (such as, but not limited to, the SMF 105, the AMF 104, the user database 101, and so on) through a network or cloud. The transceiver 1303 through which the UAF 102 and the at least one external entity communicate may include wired and / or wireless communication medium compatible with one or more different communication protocols. The transceiver 1303 may be configured for communication through a network. The network may comprise, but are not limited to, Global Positioning System (GPS), Global System for Mobile Communications (GSM), Local Area Network (LAN), Wireless Fidelity (Wi-Fi) compatibility, Bluetooth Low Energy (BLE), Near-field Communication (NFC), and so on. The wireless communication may further comprise one or more of Bluetooth, Zonal Intercommunication Global Standard (ZigBee), short-range wireless communication such as Ultra-wideband (UWB), medium-range wireless communication such as Wi-Fi, or long-range wireless communication such as Third Generation (3G), Fourth Generation (4G), Fifth Generation (5G), Sixth Generation (6G), or Worldwide Interoperability for Microwave Access (WiMAX), according to the usage environment.
[0121] In the embodiment shown herein, the at least one memory 1302 may comprise one or more volatile and non-volatile memory components that are capable of storing data and instructions to be executed. Examples of the at least one memory 1302 can be, but are not limited to, NAND, embedded Multimedia Card (eMMC), Secure Digital (SD) cards, Universal Serial Bus (USB), Serial Advanced Technology Attachment (SATA), solid-state drive (SSD), and so on. The at least one memory 1302 may also include one or more computer-readable storage media. Examples of non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the at least one memory 1302 may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted to mean that the at least one memory 1302 is non-movable. In certain examples, a non-transitory storage medium may store data that can, over time, change (for example, in Random Access Memory (RAM) or cache).
[0122] The processing module 1301 can receive a user authentication request from the UE 103 via the SMF 105, on a user triggering device access on the UE 103. The user authentication request comprises a user ID of the user, which can be one of a real user ID or an anonymized user ID. Based on the received user ID, the processing module 1301 can discover a user database, which will contain the details of the user who triggered the device access. In an embodiment herein, the discovery of the user database 101 can be done based on input(s) from the UE 103 which will contain the user details. The user database comprises user subscription information, user authentication information, current authentication status of the user, and context data, wherein the user subscription information comprises at least one UE that the user is allowed to use, and the user authentication information comprises at least one selected authentication method, and at least one authentication vector. The user database is one of an AuF, a UDM, a UDR, and a UIDF. In an embodiment herein, the discovery of the user database 101 can be based on input(s) present in the subscription for that particular user profile. In an embodiment herein, the discovery of the user database 101 can be based on a domain name contained in a User-ID provided by the UE 103. The processing module 1301 can forward an authentication request to the discovered user database to trigger the user authentication. The processing module 1301 can relay transparently to at least one authentication message between the user database 101, and the UE 103, via the SMF 105.
[0123] In an embodiment herein, the processing module 1301 can authenticate the UE, on receiving the user authentication request.
[0124] In an embodiment herein, the processing module 1301 can validate a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE.
[0125] In an embodiment herein, the processing module 1301 can store the user's context in a core network. In an embodiment herein, the processing module 1301 can support roaming. In an embodiment herein, the processing module 1301 can play a role of a proxy between the UE, and the user database. In an embodiment herein, the processing module 1301 can further expose one or more REST based APIs.
[0126] FIG. 14 depicts the SMF. The SMF 105, as depicted, comprises a processing module 1401, at least one memory 1402, and at least one transceiver 1403. The processing module 1401 can be at least one of a single processor, a plurality of processors, multiple homogeneous or heterogeneous cores, multiple Central Processing Units (CPUs) of different kinds, microcontrollers, special media, and other accelerators. The processing module 1401 may be an Application Processor (AP), a graphics-only processing unit such as a Graphics Processing Unit (GPU), a Visual Processing Unit (VPU), and / or an Artificial Intelligence (AI)-dedicated processor such as a Neural Processing Unit (NPU).
[0127] In an embodiment herein, the at least one transceiver 1403 is configured to enable communication between the SMF 105, and at least one external entity (such as, but not limited to, the AMF 104, the UE 103, and so on) through a network or cloud. The transceiver 1403 through which the SMF 105 and the at least one external entity communicate may include wired and / or wireless communication medium compatible with one or more different communication protocols. The transceiver 1403 may be configured for communication through a network. The network may comprise, but are not limited to, Global Positioning System (GPS), Global System for Mobile Communications (GSM), Local Area Network (LAN), Wireless Fidelity (Wi-Fi) compatibility, Bluetooth Low Energy (BLE), Near-field Communication (NFC), and so on. The wireless communication may further comprise one or more of Bluetooth, Zonal Intercommunication Global Standard (ZigBee), short-range wireless communication such as Ultra-wideband (UWB), medium-range wireless communication such as Wi-Fi, or long-range wireless communication such as Third Generation (3G), Fourth Generation (4G), Fifth Generation (5G), Sixth Generation (6G), or Worldwide Interoperability for Microwave Access (WiMAX), according to the usage environment.
[0128] In the embodiment shown herein, the at least one memory 1402 may comprise one or more volatile and non-volatile memory components that are capable of storing data and instructions to be executed. Examples of the at least one memory 1402 can be, but are not limited to, NAND, embedded Multimedia Card (eMMC), Secure Digital (SD) cards, Universal Serial Bus (USB), Serial Advanced Technology Attachment (SATA), solid-state drive (SSD), and so on. The at least one memory 1402 may also include one or more computer-readable storage media. Examples of non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the at least one memory 1402 may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted to mean that the at least one memory 1402 is non-movable. In certain examples, a non-transitory storage medium may store data that can, over time, change (for example, in Random Access Memory (RAM) or cache).
[0129] The processing module 1401 can receive a user authentication request from the UE 103. The processing module 1401 can select the UAF 102based on at least one of a domain name in the received user ID, and a PLMN ID of home network of the UE 103, on successfully authenticating the UE. The processing module 1401 can send the user authentication request to the selected UAF 102.
[0130] In an embodiment herein, the processing module 1401 can authenticate the UE 103, and select the UAF 102, on successfully authenticating the UE 103.
[0131] In an embodiment herein, the processing module 1401 can validate a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE 103.
[0132] FIG. 15 illustrates is a structure of a user equipment according to embodiments of the disclosure.
[0133] As shown in FIG. 15, the UE according to an embodiment may include a transceiver 1510, a memory 1520, and a processor 1530. The transceiver 1510, the memory 1520, and the processor 1530 of the UE may operate according to a communication method of the UE described above. However, the components of the UE are not limited thereto. For example, the UE may include more or fewer components than those described above. In addition, the processor 1530, the transceiver 1510, and the memory 1520 may be implemented as a single chip. Also, the processor 1530 may include at least one processor. Furthermore, the UE of FIG. 15 corresponds to a UE according to embodiments of the disclosure.
[0134] The transceiver 1510 collectively refers to a UE receiver and a UE transmitter, and may transmit / receive a signal to / from a base station or a network entity. The signal transmitted or received to or from the base station or a network entity may include control information and data. The transceiver 1510 may include a RF transmitter for up-converting and amplifying a frequency of a transmitted signal, and a RF receiver for amplifying low-noise and down-converting a frequency of a received signal. However, this is only an example of the transceiver 1510 and components of the transceiver 1510 are not limited to the RF transmitter and the RF receiver.
[0135] Also, the transceiver 1510 may receive and output, to the processor 1530, a signal through a wireless channel, and transmit a signal output from the processor 1530 through the wireless channel.
[0136] The memory 1520 may store a program and data required for operations of the UE. Also, the memory 1520 may store control information or data included in a signal obtained by the UE. The memory 1520 may be a storage medium, such as read-only memory (ROM), random access memory (RAM), a hard disk, a CD-ROM, and a DVD, or a combination of storage media.
[0137] The processor 1530 may control a series of processes such that the UE operates as described above. For example, the transceiver 1510 may receive a data signal including a control signal transmitted by the base station or the network entity, and the processor 1530 may determine a result of receiving the control signal and the data signal transmitted by the base station or the network entity.
[0138] FIG. 16 illustrates is a structure of a network entity according to embodiments of the disclosure.
[0139] As shown in FIG. 16, the network entity according to an embodiment may include a transceiver 1610, a memory 1620, and a processor 1630. The transceiver 1610, the memory 1620, and the processor 1630 of the network entity may operate according to a communication method of the network entity described above. However, the components of the network entity are not limited thereto. For example, the network entity may include more or fewer components than those described above. In addition, the processor 1630, the transceiver 1610, and the memory 1620 may be implemented as a single chip. Also, the processor 1630 may include at least one processor. Furthermore, the network entity of FIG. 16 corresponds to a network entity according to embodiments of the disclosure.
[0140] The transceiver 1610 collectively refers to a network entity receiver and a network entity transmitter, and may transmit / receive a signal to / from a terminal (UE) or a network entity. The signal transmitted or received to or from the terminal or a network entity may include control information and data. The transceiver 1610 may include a RF transmitter for up-converting and amplifying a frequency of a transmitted signal, and a RF receiver for amplifying low-noise and down-converting a frequency of a received signal. However, this is only an example of the transceiver 1610 and components of the transceiver 1610 are not limited to the RF transmitter and the RF receiver.
[0141] Also, the transceiver 1610 may receive and output, to the processor 1630, a signal through a wireless channel, and transmit a signal output from the processor 1630 through the wireless channel.
[0142] The memory 1620 may store a program and data required for operations of the network entity. Also, the memory 1620 may store control information or data included in a signal obtained by the network entity. The memory 1620 may be a storage medium, such as read-only memory (ROM), random access memory (RAM), a hard disk, a CD-ROM, and a DVD, or a combination of storage media.
[0143] The processor 1630 may control a series of processes such that the network entity operates as described above. For example, the transceiver 1610 may receive a data signal including a control signal transmitted by the terminal, and the processor 1630 may determine a result of receiving the control signal and the data signal transmitted by the terminal.
[0144] In an embodiment, A method (1200) for performing user authentication and authorization in a Third Generation Partnership Project (3GPP) network (100), the method comprising: receiving (1203), by a User Authentication function (UAF) (102), a user authentication request from a User Equipment (UE) (103) via a Session Management Function (SMF) (105); discovering, by the UAF (102), a user database (101), based on the received user ID; forwarding, by the UAF (102), an authentication request to the user database (101) to trigger user authentication; and relaying transparently, by the UAF (102), to at least one authentication message between the user database (101), and the UE (101), via the SMF (105).
[0145] In an embodiment, wherein the method further comprises: sending, by the UE (101), the user authentication request to the SMF (105), on a user triggering device access on the UE (103), wherein the user authentication request comprises a user ID of the user; authenticating and authorizing, by the SMF (105), whether the user is allowed to use the UE (103); selecting, by the SMF (105), the UAF (102) based on at least one of a domain name in the received user ID, and a Public Land Mobile Network (PLMN) ID of home network of the UE (103), on successfully authenticating the UE (103); and sending, by the SMF (105), the user authentication request to the selected UAF (102).
[0146] In an embodiment, the method further comprises: sending, by the UE (103), the user authentication request to the SMF (105); selecting, by the SMF (105), the UAF (102) based on at least one of a domain name in the received user ID, and a Public Land Mobile Network (PLMN) ID of home network of the UE (103); sending, by the SMF (105), the user authentication request to the determined UAF ((102)); and authenticating and authorizing, by the UAF (102), whether the user is allowed to use the UE (103).
[0147] In an embodiment, the method further comprises validating, by one of the SMF (105), and the UAF (102), a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE (103).
[0148] In an embodiment, wherein the user database (101) comprises user subscription information, user authentication information, current authentication status of the user, and context data, wherein the user subscription information comprises at least one UE (103) that the user is allowed to use, and the user authentication information comprises at least one selected authentication method, and at least one authentication vector. the user database (101) is one of an Authentication Function (AuF), a Unified Data Management (UDM), a Unified Data Repository (UDR), and a User Information Database Function (UIDF).
[0149] In an embodiment, wherein the method further comprises: storing, by the UAF (102), the user's context in a core network; supporting, by the UAF (102), roaming; playing, by the UAF (102), a role of a proxy between the UE (103), and the user database (101); and exposing, by the UAF (102), one or more Representational State Transfer (REST) based APIs.
[0150] In an embodiment, A User Authentication function (UAF) (102) in a Third Generation Partnership Project (3GPP) network comprising: a processing module (1301); a memory (1302); and a transceiver (1303), wherein the processing module (1301) is coupled with the memory (1302), and the transceiver (1303), and configured to: receive a user authentication request from a User Equipment (UE) (103) via a Session Management Function (SMF) (105); discover a user database (101), based on the received user ID; forward an authentication request to the user database (101) to trigger user authentication; and relay transparently to at least one authentication message between the user database (101), and the UE (103), via the SMF (105).
[0151] In an embodiment, wherein the processing module (1301) is configured to authenticate the UE (103), on receiving the user authentication request. wherein the processing module (1301) is configured to validate a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE (103).
[0152] In an embodiment, wherein the processing module (1301) is configured to: store the user's context in a core network; support roaming; play a role of a proxy between the UE (103), and the user database (101); and expose one or more Representational State Transfer (REST) based APIs.
[0153] In an embodiment, A Session Management Function (SMF) (105) in a Third Generation Partnership Project (3GPP) network comprising: a processing module (1401); a memory (1402); and a transceiver (1403), wherein the processing module (1401) is coupled with the memory (1402), and the transceiver (1403), and configured to: receive a user authentication request from a User Equipment (UE) (103); select a User Authentication function (UAF) (102) based on at least one of a domain name in the received user ID, and a Public Land Mobile Network (PLMN) ID of home network of the UE (103), on successfully authenticating the UE (103); and send the user authentication request to the selected UAF.
[0154] In an embodiment, wherein the processing module (1401) is configured to: authenticate the UE (103); and select the UAF (102), on successfully authenticating the UE (103).
[0155] In an embodiment, the processing module (1401) is configured to validate a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE (103).
[0156] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.
[0157] The embodiments disclosed herein describe systems and methods for enabling a wireless network identify human users, devices or applications that are accessing the network provided services through a UE with subscription to the network, in order to provide differentiated services. Therefore, it is understood that the scope of the protection is extended to such a program and in addition to a computer readable means having a message therein, such computer readable storage means contain program code means for implementation of one or more steps of the method, when the program runs on a server or mobile device or any suitable programmable device. The method is implemented in at least one embodiment through or together with a software program written in e.g., Very high speed integrated circuit Hardware Description Language (VHDL) another programming language, or implemented by one or more VHDL or several software modules being executed on at least one hardware device. The hardware device can be any kind of portable device that can be programmed. The device may also include means which could be e.g., hardware means like e.g., an ASIC, or a combination of hardware and software means, e.g., an ASIC and an FPGA, or at least one microprocessor and at least one memory with software modules located therein. The method embodiments described herein could be implemented partly in hardware and partly in software. Alternatively, the invention may be implemented on different hardware devices, e.g., using a plurality of CPUs.
[0158] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of embodiments and examples, those skilled in the art will recognize that the embodiments and examples disclosed herein can be practised with modification within the scope of the embodiments as described herein.
Claims
1.A method performed by a network entity in a wireless communication system, the method comprising:receiving, from a user equipment (UE), a first message for a user authentication and authorization request including a user identifier (ID);performing a validation based on subscription data;selecting a user authentication function (UAF) entity based on the user ID, andtransmitting, to the UAF entity, a second message for the user authentication and authorization request.2.The method of claim 1, wherein the subscription data is retrieved from a user data management function (UDM) entity.3.The method of claim 1, further comprising:receiving, from the UAF entity, third message including a result of the user authentication and authorization request; andtransmitting, to the UE, fourth message including the result of the user authentication and authorization request.4.The method of claim 1, wherein the network entity includes a session management function (SMF) entity, andwherein the receiving of the first message is triggered based on a user of the UE.5.A method performed by a user authentication function (UAF) entity in a wireless communication system, the method comprising:receiving, from a network entity, a first message for a user authentication and authorization request including user identifier (ID); andtransmitting, to the network entity, a second message including a result of the user authentication and authorization request.6.The method of claim 5, wherein the UAF entity is selected based on the user ID.7.The method of claim 5, wherein the network entity includes a session management function (SMF) entity.8.The method of claim 5, wherein the receiving of the first message is triggered based on a user of the UE.9.A network entity in a wireless communication system, the network entity comprising:a transceiver; anda controller coupled with the transceiver and configured to:receive, from a user equipment (UE), a first message for a user authentication and authorization request including a user identifier (ID);perform a validation based on subscription data;select a user authentication function (UAF) entity based on the user ID, andtransmit, to the UAF entity, a second message for the user authentication and authorization request.10.The network entity of claim 9, wherein the subscription data is retrieved from a user data management function (UDM) entity.11.The network entity of claim 9, the controller further configured to:receive, from the UAF entity, third message including a result of the user authentication and authorization request; andtransmit, to the UE, fourth message including the result of the user authentication and authorization request.12.The network entity of claim 9, wherein the network entity includes a session management function (SMF) entity, andwherein the receiving of the first message is triggered based on a user of the UE.13.A user authentication function (UAF) entity in a wireless communication system, the UAF comprising:a transceiver; anda controller coupled with the transceiver and configured to:receive, from a network entity, a first message for a user authentication and authorization request including user identifier (ID); andtransmit, to the network entity, a second message including a result of the user authentication and authorization request.14.The UAF entity of claim 13, wherein the UAF entity is selected based on the user ID.15.The UAF entity of claim 13, wherein the network entity includes a session management function (SMF) entity, andwherein the receiving of the first message is triggered based on a user of the UE.
Citation Information
Patent Citations
Method of managing connection to local area data network (LADN) in 5g network
JP2023120188A
Method and apparatus for network access
US20190036924A1
Methods and systems for providing FIDO authentication services
US20200045046A1
Apparatus and method for providing subscription data to non-subscriber registered terminal in wireless communication system
US20220337995A1
Bridging Digital Identity Validation And Verification With The FIDO Authentication Framework
US20220407721A1