Authentication and authorization for wireless communications
The implementation of user-specific authentication and authorization methods during PDU session establishment and modification in 5G networks addresses the challenge of multiple users sharing a subscription, ensuring secure and efficient communication with differentiated service treatment.
Patent Information
- Application Number
- PCT/CN2024/076482
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-06
- Publication Date
- 2025-08-14
AI Technical Summary
Existing wireless communication systems struggle with efficient authentication and authorization for multiple user identifiers within a single subscription, particularly in 5G networks, where different users sharing a subscription require differentiated service treatment.
Implementing methods for secondary data network authentication and authorization procedures during PDU session establishment and modification, allowing individual user identifiers to be authenticated and authorized within a single subscription, using network functions like SMF, PCF, and DN-AAA servers to manage and enforce user-specific policies.
Enables differentiated service treatment for multiple users sharing a subscription, ensuring secure and efficient communication by authenticating and authorizing individual user identifiers, thereby enhancing service flexibility and security in 5G networks.
Smart Images

Figure CN2024076482_14082025_PF_FP_ABST
Abstract
Description
AUTHENTICATION AND AUTHORIZATION FOR WIRELESS COMMUNICATIONSTECHNICAL FIELD
[0001] This document is directed generally to digital wireless communications.BACKGROUND
[0002] Mobile telecommunication technologies are moving the world toward an increasingly connected and networked society. In comparison with the existing wireless networks, next generation systems and wireless communication techniques will need to support a much wider range of use-case characteristics and provide a more complex and sophisticated range of access requirements and flexibilities.
[0003] Long-Term Evolution (LTE) is a standard for wireless communication for mobile devices and data terminals developed by 3rd Generation Partnership Project (3GPP) . LTE Advanced (LTE-A) is a wireless communication standard that enhances the LTE standard. The 5th generation of wireless system, known as 5G, advances the LTE and LTE-Awireless standards and is committed to supporting higher data-rates, large number of connections, ultra-low latency, high reliability and other emerging business needs.SUMMARY
[0004] Techniques are disclosed for support authentication and / or authorization for a user identifier (ID) or per user ID.
[0005] A first wireless communication method includes receiving, by a first network device from a communication device, a first message that includes one or more user identifiers (IDs) ; and performing, by the first network device, an authentication and authorization procedure for the one or more user IDs in response to the first message.
[0006] In some embodiments, the performing the authentication and authorization procedure includes determining to trigger the authentication and authorization procedure for the one or more user IDs. In some embodiments, the performing the authentication and authorization procedure includes sending an authentication or authorization request message that includes the one or more user IDs to a DN server. In some embodiments, the method further comprises transmitting, in response to the performing the authentication and authorization procedure, the one or more user IDs or all user IDs associated with the subscription to a policy control function (PCF) . In some embodiments, the method further comprises receiving, by the first network device from the PCF, protocol data unit (PDU) session related policy information for the one or more user IDs.
[0007] In some embodiments, the method further comprises transmitting, by the first network device to the communication device, a PDU session establishment accept message or a PDU session modification command message that indicates one or more parameters. In some embodiments, the first message includes a session management (SM) protocol data unit (PDU) data network (DN) request container that includes the one or more user IDs. In some embodiments, the first message includes a capability indication of the communication device that indicates that the communication device supports authentication and authorization per user ID. In some embodiments, the first message is a protocol data session (PDU) session establishment request message or a PDU session modification request message.
[0008] In some embodiments, the first message is received from the communication device via an access and mobility management function (AMF) . In some embodiments, the first network device includes a session management function (SMF) . In some embodiments, the method further comprises transmitting, by the first network device to a second network device, the one or more user IDs; and receiving, by the first network device from the second network device, a second message comprising subscription data for the one or more user IDs associated with the subscription. In some embodiments, the subscription data includes: one or more allowed protocol data unit (PDU) session types, one or more allowed session and service continuity (SSC) modes, a 5G quality of service identifier (5QI) and allocation and retention priority (ARP) , a subscribed session-aggregate maximum bit rate (AMBR) , and / or an internet protocol (IP) index or static IP address / prefix.
[0009] In some embodiments, the second network device includes a unified data management (UDM) . In some embodiments, the second message comprises the subscription data for all user IDs associated with the subscription. In some embodiments, the authentication and authorization per user ID includes a secondary data network (DN) authentication and authorization per user ID, and the authentication and authorization procedure includes a secondary DN authentication and authorization procedure.
[0010] A second wireless communication method includes transmitting, by a communication device to a network device, a first message that includes one or more user identifiers (IDs) ; and receiving, by the communication device from the network device, an authentication or authorization message.
[0011] In some embodiments, the first message includes a session management (SM) protocol data unit (PDU) data network (DN) request container that includes the one or more user IDs. In some embodiments, the first message includes a capability indication of the communication device regarding whether the communication device supports authentication and authorization per user ID. In some embodiments, the authentication or authorization message includes the one or more user IDs. In some embodiments, the method further comprises transmitting, by the communication device to the network device, a second message comprising authentication or authorization information associated with the one or more user IDs.
[0012] In some embodiments, the second message includes the one or more user IDs. In some embodiments, the method further comprises receiving, by the communication device from the first network device, a PDU session establishment accept message or a PDU session modification command message that indicates one or more parameters. In some embodiments, the authentication or authorization message is received by the communication device from the network device via an access and mobility management function (AMF) . In some embodiments, the network device includes a session management function (SMF) .
[0013] In yet another exemplary aspect, the above-described methods are embodied in the form of processor-executable code and stored in a non-transitory computer-readable storage medium. The code included in the computer readable storage medium when executed by a processor, causes the processor to implement the methods described in this patent document.
[0014] In yet another exemplary embodiment, a device that is configured or operable to perform the above-described methods is disclosed.
[0015] The above and other aspects and their implementations are described in greater detail in the drawings, the descriptions, and the claims.
[0016] BRIEF DESCRIPTION OF THE DRAWING
[0017] FIG. 1 shows an example process for a protocol data unit (PDU) session establishment procedure.
[0018] FIG. 2 shows an example process for a PDU session establishment procedure with user identifier (ID) .
[0019] FIG. 3 shows an example process for secondary authentication / authorization of PDU session by a server.
[0020] FIG. 4 shows an example process for PDU session modification procedure with user ID.
[0021] FIG. 5 shows an exemplary block diagram of a hardware platform that may be a part of a network device or a communication device.
[0022] FIG. 6 shows an example of wireless communication including a base station (BS) and user equipment (UE) based on some implementations of the disclosed technology.
[0023] FIG. 7 shows an exemplary flowchart for performing an authentication and authorization procedure.
[0024] FIG. 8 shows an exemplary flowchart for receiving an authentication or authorization message.DETAILED DESCRIPTION
[0025] In a 5G system, there are at least two use cases to enhance usage of user identifiers: (1) one or more users (e.g., humans) sharing one UE; and (2) one or more users (e.g., non-3GPP devices) behind one gateway UE. For both use cases, one or more user identifiers identifying the corresponding users are associated with the same subscription of a UE identified by a subscription permanent identifier (SUPI) . Service differentiation can be supported when providing communication services by the 5G system (5GS) for different users sharing one subscription since different users may require different service treatment. However, how to perform authentication and authorization per user is unclear. This patent document describes methods to support authentication and / or authorization for a user identifier (ID) or per user ID.
[0026] The example headings for the various sections below are used to facilitate the understanding of the disclosed subject matter and do not limit the scope of the claimed subject matter in any way. Accordingly, one or more features of one example section can be combined with one or more features of another example section. Furthermore, 5G terminology is used for the sake of clarity of explanation, but the techniques disclosed in the present document are not limited to 5G technology only, and may be used in wireless systems that implemented other protocols.
[0027] I. Introduction to Protocol Data Unit (PDU) Session Establishment Procedure
[0028] FIG. 1 shows an example process for a PDU session establishment procedure. The operations shown in FIG. 1 are further described below.
[0029] 1. The UE initiates the UE Requested PDU Session Establishment procedure by sends a NAS message to the AMF containing a PDU Session Establishment Request within the N1 SM container. The PDU Session Establishment Request includes one or more of the following parameters: PDU session ID, requested PDU session type, requested session and service continuity (SSC) mode, 5G session management (5GSM) capability, protocol configuration options (PCO) , session management (SM) protocol data unit (PDU) data network (DN) Request Container.
[0030] The UE indicates in the 5GSM Capability whether the UE supports one or more of the following:
[0031] 1) Reflective QoS;
[0032] 2) Multi-homed IPv6 PDU session;
[0033] 3) Ethernet PDN type in S1 mode;
[0034] 4) ATSSS related capability;
[0035] 5) Transfer of port management information containers;
[0036] 6) Access performance measurements per QoS flow; and
[0037] 7) Secondary data network (DN) authentication and authorization over EPC.
[0038] The SM PDU DN Request Container contains information for the PDU session authentication and authorization by the external DN. The SM PDU DN Request Container contains DN-specific identity of the UE.
[0039] 2. The AMF selects a session management function (SMF) based on information received from UE and local configuration. The AMF sends Nsmf_PDUSession_CreateSMContext Request message to the selected SMF. The request message includes the PDU Session Establishment Request within the N1 SM container received from UE.
[0040] 3. If Session Management Subscription data for corresponding SUPI, DNN, S-NSSAI is not available, then SMF retrieves the Session Management Subscription data from UDM using Nudm_SDM_Get request including one or more of the following parameters: SUPI, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID.
[0041] 4. If the Session Management Subscription data is not available locally, the UDM may get this information from UDR by Nudr_DM_Query request including one or more of the following parameters: SUPI, Subscription Data, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID.
[0042] 5. The UDR responds by Nudr_DM_Query response including Session Management Subscription data.
[0043] 6. The UDM subscribes to be notified by the UDR when this subscription data is modified using Nudr_DM_subscribe including one or more of the following parameters: SUPI, Subscription Data, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID.
[0044] 7. The UDM responds by Nudm_SDM_Get response including Session Management Subscription data.
[0045] 8. The SMF subscribes to be notified by the UDM when this subscription data is modified using Nudm_SDM_Subscribe including one or more of the following parameters: SUPI, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID.
[0046] 9. Based on subscription information received from UDM or local configuration or both, if the SMF is able to process the PDU Session Establishment Request, the SMF creates an SM context and responds to the AMF by including SM Context ID in the Nsmf_PDUSession_CreateSMContext Response message.
[0047] 10. If the SMF determines that secondary authentication / authorization of the PDU Session Establishment is required, the SMF triggers the secondary authentication / authorization towards DN-AAA Server during the PDU Session establishment procedure.
[0048] 11. The SMF performs policy control function (PCF) selection and initiates SM Policy Association Establishment procedure to establish an SM Policy Association with the PCF.
[0049] If the SMF received the DN Authorization Profile Index in DN Authorization Data from the DN-AAA server in step 10, it sends the DN Authorization Profile Index to PCF to retrieve the PDU Session related policy information and the PCC rule (s) from the PCF.
[0050] If the SMF received the DN authorized Session AMBR in DN Authorization Data from the DN-AAA server in step 10, it sends the DN authorized Session AMBR within the Session AMBR to the PCF to retrieve the authorized Session AMBR.
[0051] 12. The PCF responds with SM Policy Association Establishment Response message. The message may include PDU session related policy information and PCC rule (s) .
[0052] 13. The SMF selects UPF and performs N4 Session Establishment procedure with the selected UPF.
[0053] 14. The SMF sends PDU Session Establishment Accept message to the UE via AMF.
[0054] 15. The SMF registers with the UDM for a given PDU session by sending Nudm_UECM_Registration Request message to the UDM. The message includes one or more of the following parameters: SUPI, DNN, S-NSSAI, PDU Session ID, SMF Identity, Serving PLMN ID.
[0055] 16. The UDM stores the received information and responses with Nudm_UECM_Registration Response message to SMF. The UDM may further stores the received information in UDR by Nudr_DM_Update (SUPI, Subscription Data, UE context in SMF data) service operation.
[0056] II. Example Embodiments
[0057] When one or more user identifiers identifying one or more users (i.e. humans or non-3GPP devices) are associated with one subscription, it proposes to enhance secondary DN authentication and authorization procedure during PDU session establishment procedure and PDU session modification procedure for authentication and authorization per user ID.
[0058] If the UE provides user ID during PDU session establishment procedure, the SMF initiates secondary DN authentication and authorization procedure for the user ID during PDU session establishment procedure.
[0059] If the PDU session was established without user ID information provided by the UE and the PDU session can be used for specific user ID (s) , or the PDU session was established with user ID information provided by the UE and the PDU session can be shared by multiple user IDs, the UE can initiate PDU session modification procedure to provide user ID information which identifies the additional user which intends to use this PDU session for traffic transmission, and the SMF initiates secondary DN authentication and authorization procedure for the user ID during PDU session modification procedure.
[0060] II. (a) . Example 1: PDU Session Establishment Procedure with user ID
[0061] FIG. 2 shows an example process for a PDU session establishment procedure with user ID. The operations shown in FIG. 2 are further described below.
[0062] 1.The UE initiates the UE Requested PDU Session Establishment procedure by sends a NAS message to the AMF containing a PDU Session Establishment Request within the N1 SM container. The PDU Session Establishment Request includes one or more of the following parameters: PDU session ID, Requested PDU Session Type, Requested SSC mode, 5GSM Capability of the UE, PCO, SM PDU DN Request Container and user ID (s) .
[0063] The UE indicates in the 5GSM Capability whether the UE supports one or more of the following:
[0064] 1) Reflective QoS;
[0065] 2) Multi-homed IPv6 PDU session;
[0066] 3) Ethernet PDN type in S1 mode;
[0067] 4) ATSSS related capability;
[0068] 5) Transfer of port management information containers;
[0069] 6) Access performance measurements per QoS flow;
[0070] 7) Secondary DN authentication and authorization over EPC; and
[0071] 8) Secondary DN authentication and authorization per user ID.
[0072] The secondary DN authentication and authorization per user ID indicates a capability of the UE and not a capability of each user ID. The SM PDU DN Request Container contains information for the PDU session authentication and authorization by the external DN. The SM PDU DN Request Container contains one or more of the following parameters: DN-specific identity of the UE and user ID (s) .
[0073] 2. The AMF selects an SMF based on information received from UE and local configuration. The AMF sends Nsmf_PDUSession_CreateSMContext Request message to the selected SMF. The request message includes the PDU Session Establishment Request within the N1 SM container received from UE.
[0074] 3. If Session Management Subscription data for corresponding SUPI, DNN, S-NSSAI and / or user ID is not available, then SMF retrieves the Session Management Subscription data from UDM using Nudm_SDM_Get request including one or more of the following parameters: SUPI, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID and user ID (s) .
[0075] 4. If the Session Management Subscription data is not available locally, the UDM may get this information from UDR by Nudr_DM_Query request including one or more of the following parameters: SUPI, Subscription Data, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID and user ID (s) .
[0076] 5. The UDR responds by Nudr_DM_Query response including Session Management Subscription data. The Session Management Subscription data may only include Session Management Subscription data for the user ID (s) included in the request message, or the Session Management Subscription data may include Session Management Subscription data for all user ID (s) associated with the subscription. For one user ID one or more of the following parameters are included: allowed PDU session type (s) , allowed SSC mode (s) , default 5G quality of service identifier (5QI) and allocation and retention priority (ARP) , subscribed session-aggregate maximum bit rate (AMBR) , IP index or static IP address / prefix and so on.
[0077] 6. The UDM subscribes to be notified by the UDR when this subscription data is modified using Nudr_DM_subscribe including one or more of the following parameters: SUPI, Subscription Data, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID and user ID (s) .
[0078] 7. The UDM responds by Nudm_SDM_Get response including Session Management Subscription data. The Session Management Subscription data may only include Session Management Subscription data for the user ID (s) included in the request message, or the Session Management Subscription data may include Session Management Subscription data for all user ID (s) associated with the subscription. For one user ID one or more of the following parameters are included: allowed PDU session type (s) , allowed SSC mode (s) , default 5QI and ARP, subscribed session-AMBR, IP index or static IP address / prefix and so on.
[0079] 8. The SMF subscribes to be notified by the UDM when this subscription data is modified using Nudm_SDM_Subscribe including one or more of the following parameters: SUPI, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID and user ID (s) .
[0080] 9. Based on subscription information received from UDM and / or local configuration, if the SMF is able to process the PDU Session Establishment Request, the SMF creates an SM context and responds to the AMF by including SM Context ID in the Nsmf_PDUSession_CreateSMContext Response message.
[0081] 10. If the SMF determines that secondary authentication / authorization of the PDU Session Establishment is required for at least one user ID, the SMF triggers the secondary authentication / authorization towards DN-AAA Server during the PDU Session establishment procedure as described in Example 2 below.
[0082] 11. The SMF performs PCF selection and initiates SM Policy Association Establishment procedure to establish an SM Policy Association with the PCF.
[0083] The SMF may provide user ID (s) received from UE to the PCF in the SM Policy Association Establishment Request message. Or the SMF may provide all user ID (s) related to the subscription received from UDM to the PCF in the SM Policy Association Establishment Request message.
[0084] If the SMF received the DN Authorization Profile Index for the user ID (s) in DN Authorization Data from the DN-AAA server in step 10, it sends the DN Authorization Profile Index to PCF to retrieve the PDU Session related policy information and the PCC rule (s) for the user ID (s) from the PCF.
[0085] If the SMF received the DN authorized Session AMBR for the user ID (s) in DN Authorization Data from the DN-AAA server in step 10, it sends the DN authorized Session AMBR within the Session AMBR to the PCF to retrieve the authorized Session AMBR for the user ID (s) .
[0086] 12. The PCF responds with SM Policy Association Establishment Response message. The message may include PDU session related policy information and / or PCC rule (s) for the related user ID (s) .
[0087] 13. The SMF selects UPF and performs N4 Session Establishment procedure with the selected UPF.
[0088] 14. The SMF sends PDU Session Establishment Accept message to the UE via AMF. The PDU Session Establishment Accept message includes one or more of the following parameters: S-NSSAI, DNN, Selected PDU session type, Selected SSC mode, Authorized QoS rules, Session AMBR and 5GSM network feature support.
[0089] 15. The SMF registers with the UDM for a given PDU session by sending Nudm_UECM_Registration Request message to the UDM. The message includes one or more of the following parameters: SUPI, DNN, S-NSSAI, PDU Session ID, SMF Identity, Serving PLMN ID, served user ID (s) .
[0090] 16. The UDM stores the received information and responses with Nudm_UECM_Registration Response message to SMF. The UDM may further stores the received information in UDR by Nudr_DM_Update (SUPI, Subscription Data, UE context in SMF data including served user ID (s) ) service operation.
[0091] II. (b) . Example 2: Secondary DN authentication and authorization procedure per user ID
[0092] FIG. 3 shows an example process for secondary authentication / authorization of PDU session by server (e.g., DN-AAA server) . The “user ID” shown in FIG. 3 refers to one or more user ID (s) . The operations shown in FIG. 3 are described below:
[0093] 0. The SMF determines that secondary authentication / authorization of the PDU session for the user ID by DN-AAA Server needs to be performed based on e.g. session management subscription data for the user ID received from UDM, SMF policy associated with the DN per user ID, the UE provided user ID(s) , the UE indication of support of secondary DN authentication and authorization per user ID in the 5GSM Capability and the UE provided SM PDU DN Request Container including DN-specific identity of the UE and user ID (s) .
[0094] The SMF identifies the DN-AAA Server based on local configuration or using the DN-specific identity of the UE and user ID (s) inside the SM PDU DN Request Container provided by the UE.
[0095] If the SMF needs to contact DN-AAA server via UPF, step 1 is performed and the interaction between SMF and DN are transparently relayed by the UPF. Otherwise, if the SMF can contact the DN-AAA server directly without involving UPF, step 1 is skipped and the interaction between SMF and DN are direct without involving UPF.
[0096] 1. If there is no existing N4 session that can be used to carry DN-related messages between the SMF and the DN, the SMF selects a UPF and triggers N4 session establishment.
[0097] 2. The SMF initiates the authentication procedure with the DN-AAA server via the UPF to authenticate the DN-specific identity of the UE and user ID (s) provided by the UE. The SMF includes DN-specific identity of the UE and user ID (s) in the Authentication / Authorization Request message sent to DN.
[0098] When available, the SMF provides the GPSI in the signalling exchanged with the DN-AAA server.
[0099] The UPF transparently relays the message received from the SMF to the DN-AAA Server.
[0100] 3a. The DN-AAA server performs authentication / authorization of the PDU session based on the DN-specific identity of the UE and user ID (s) received from SMF.
[0101] The DN-AAA server sends an Authentication / Authorization message including DN Request Container information towards the SMF via UPF. The DN Request Container information may include the user ID (s) and related Authentication / Authorization information.
[0102] 3b. SMF invokes Namf_Communication_N1N2MessageTransfer service operation of the AMF to transfer the DN Request Container information received from DN-AAA server within N1 SM information sent towards the UE.
[0103] 3c. The AMF sends the N1 NAS message including the DN Request Container information in the authentication / authorization message to the UE.
[0104] 3d. The UE responds with a N1 NAS message containing DN Request Container information to the AMF. The DN Request Container information may include the user ID (s) and related Authentication / Authorization information.
[0105] 3e. The AMF sends Nsmf_PDUSession_UpdateSMContext Request message to SMF to provide the DN Request Container information received from UE. And the SMF responds with Nsmf_PDUSession_UpdateSMContext response message.
[0106] 3f. The SMF sends the content of the DN Request Container information received from AMF to the DN-AAA server via the UPF.
[0107] Step 3 may be repeated several times until the DN-AAA server confirms the successful authentication / authorization of the PDU Session.
[0108] 4. The DN-AAA Server confirms the successful authentication / authorization of the PDU Session for the DN-specific identity of the UE and user ID (s) .
[0109] The DN-AAA Server may provide one or more of the following parameters to SMF:
[0110] a) an SM PDU DN Response Container to the SMF to indicate successful authentication / authorization;
[0111] b) DN Authorization Data;
[0112] c) a request to get notified with the IP address (es) allocated to the PDU Session and / or N6 traffic routing information or MAC address (es) used by the UE for the PDU Session;
[0113] d) an IP address (or IPV6 Prefix) for the PDU Session; and
[0114] e) N6 traffic routing information.
[0115] The DN authorization data for the PDU session may include one or more of the following parameters for the user ID (s) :
[0116] a) A DN Authorization Profile Index which is a reference to authorization data for policy and charging control locally configured in the SMF or PCF;
[0117] b) a list of allowed MAC addresses for the PDU Session, this applies only for PDU Session of Ethernet PDU type;
[0118] c) a list of allowed VLAN tags for the PDU Session, this applies only for PDU Session of Ethernet PDU type;
[0119] d) DN authorized Session-AMBR for the PDU Session, the DN Authorized Session AMBR for the PDU Session takes precedence over the subscribed Session-AMBR received from the UDM; and
[0120] e) Framed Route information for the PDU Session.
[0121] After the successful DN authentication / authorization, a session is kept between the SMF and the DN-AAA server.
[0122] II. (c) . Example 3: PDU Session Modification Procedure with user ID
[0123] FIG. 4 shows an example process for PDU session modification procedure with user ID. The operations shown in FIG. 4 are further described below:
[0124] If:
[0125] a) the PDU session was established without user ID information provided by the UE and the PDU session can be used for specific user ID (s) ; or
[0126] b) the PDU session was established with user ID information provided by the UE (e.g., as described in Example 1 above) and the PDU session can be shared by multiple user IDs, then the UE may initiate PDU session modification procedure to provide user ID information which identifies the additional user which intends to use this PDU session for traffic transmission.
[0127] 1. The UE initiates the UE Requested PDU Session Modification procedure by sends a NAS message to the AMF containing a PDU Session Modification Request within the N1 SM container. The PDU Session Establishment Request includes one or more of the following parameters: PDU session ID, 5GSM Capability, SM PDU DN Request Container and user ID (s) .
[0128] The UE indicates in the 5GSM Capability whether the UE supports secondary DN authentication and authorization per user ID.
[0129] The SM PDU DN Request Container contains information for the PDU session authentication and authorization by the external DN. The SM PDU DN Request Container contains one or more of the following parameters: DN-specific identity of the UE and user ID (s) .
[0130] 2. The AMF sends Nsmf_PDUSession_UpdateSMContext Request message to the corresponding SMF. The request message includes SM Context ID and the PDU Session Modification Request within the N1 SM container received from UE.
[0131] 3. If Session Management Subscription data for corresponding user ID (s) is not available, then SMF retrieves the Session Management Subscription data for the user ID (s) from UDM using Nudm_SDM_Get request including one or more of the following parameters: SUPI, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID and user ID (s) .
[0132] 4. If the Session Management Subscription data for the user ID (s) is not available locally, the UDM may get this information from UDR by Nudr_DM_Query request including one or more of the following parameters: SUPI, Subscription Data, Session Management Subscription data, selected DNN, S-NSSAI, Serving PLMN ID and user ID (s) .
[0133] 5. The UDR responds by Nudr_DM_Query response including Session Management Subscription data. The Session Management Subscription data may only include Session Management Subscription data for the user ID (s) included in the request message, or the Session Management Subscription data may include Session Management Subscription data for all user ID (s) associated with the subscription. For one user ID one or more of the following parameters are included: allowed PDU session type (s) , allowed SSC mode (s) , default 5QI and ARP, subscribed session-AMBR, IP index or static IP address / prefix and so on.
[0134] 6. The UDM responds by Nudm_SDM_Get response including Session Management Subscription data. The Session Management Subscription data may only include Session Management Subscription data for the user ID (s) included in the request message, or the Session Management Subscription data may include Session Management Subscription data for all user ID (s) associated with the subscription. For one user ID one or more of the following parameters are included: allowed PDU session type (s) , allowed SSC mode (s) , default 5QI and ARP, subscribed session-AMBR, IP index or static IP address / prefix and so on.
[0135] 7. Based on subscription information received from UDM and / or local configuration, if the SMF is able to process the PDU Session Modification Request and the SMF determines that secondary authentication / authorization of the PDU Session Establishment for the user ID (s) is required, the SMF triggers the secondary authentication / authorization for the user ID (s) towards DN-AAA server as described in Example 2 above.
[0136] 8. The SMF initiates SM Policy Association Modification procedure to modify the SM Policy Association with the PCF.
[0137] The SMF may provide user ID (s) received from UE to the PCF in the SM Policy Association Modification Request message. Or the SMF may provide all user ID (s) related to the subscription received from UDM to the PCF in the SM Policy Association Modification Request message. Or the SMF may provide user ID (s) received from UE and user ID (s) already related to this PDU session to the PCF in the SM Policy Association Modification Request message.
[0138] If the SMF received the DN Authorization Profile Index for the user ID (s) in DN Authorization Data from the DN-AAA server in step 7, it sends the DN Authorization Profile Index to PCF to retrieve the PDU Session related policy information and the PCC rule (s) for the user ID (s) from the PCF.
[0139] If the SMF received the DN authorized Session AMBR for the user ID (s) in DN Authorization Data from the DN-AAA server in step 7, it sends the DN authorized Session AMBR within the Session AMBR to the PCF to retrieve the authorized Session AMBR for the user ID (s) .
[0140] 9. The PCF responds with SM Policy Association Modification Response message. The message includes PDU session related policy information and PCC rule (s) for the related user ID (s) .
[0141] 10. The SMF may perform N4 Session Modification procedure with the UPF.
[0142] 11. The SMF responds to AMF by sending Nsmf_PDUSession_UpdateSMContext Response message to the AMF. The message includes PDU Session Modification Command message included in N1 SM Container. The PDU session modification command message may include one or more of the following parameters: Session AMBR, Authorized QoS rules, extended protocol configuration options.
[0143] 12. The AMF forwards the PDU Session Modification Command message to the UE.
[0144] 13. The UE acknowledges the PDU Session Modification Command by sending PDU Session Modification Command Ack message to the SMF via AMF.
[0145] 14. The SMF updates the UDM with the information for the given PDU session by sending an update message to the UDM. The message includes one or more of the following parameters: SUPI, DNN, S-NSSAI, PDU Session ID, SMF Identity, Serving PLMN ID, served user ID (s) .
[0146] 15. The UDM stores the received information and responds to SMF. The UDM may further updates the received information in UDR by Nudr_DM_Update (SUPI, Subscription Data, UE context in SMF data including served user ID (s) ) service operation.
[0147] In some embodiments, a SMF may be configured to perform any one or more of the following operations:
[0148] ● Receives PDU Session Establishment Request message or PDU Session Modification Request message including user ID (s) from the UE via AMF.
[0149] ○ The request message may include capability indication indicates whether the UE supports secondary DN authentication and authorization per user ID, and SM PDU DN Request Container including user ID (s) .
[0150] ● Sends session subscription information request message including user ID (s) to UDM.
[0151] ● Receives session management subscription data associated with the user ID (s) from UDM.
[0152] ● Subscribes to UDM to be notified when the subscription date for the user ID (s) is updated.
[0153] ● May determine to trigger secondary DN authentication and authorization procedure for the user ID (s) .
[0154] ○ May determine based on session management subscription data for the user ID (s) received from UDM, SMF policy associated with the DN per user ID, the UE provided user ID (s) , the UE indication of support of secondary DN authentication and authorization per user ID in the 5GSM Capability and the UE provided SM PDU DN Request Container including DN-specific identity of the UE and user ID (s) .
[0155] ● Sends Authentication / Authorization Request message including user ID (s) to DN.
[0156] ● Receives Authentication / Authorization message including DN Request Container information including user ID (s) and related information from DN.
[0157] ● Forwards the DN Request Container information received from DN to UE via AMF.
[0158] ● Receives DN Request Container information including user ID (s) and related information from UE via AMF.
[0159] ● Forwards the DN Request Container information received from UE to DN.
[0160] ● Receives Authentication / Authorization Response message including DN authorization data for the user ID (s) from DN.
[0161] ● Sends SM Policy Association Establishment Request message or SM Policy Association Modification Request message including user ID (s) to PCF.
[0162] ● Receives PDU session related policy information for the user ID (s) from PCF.
[0163] ● Sends PDU Session Establishment Accept message or PDU Session Modification Command message to UE via AMF.
[0164] ● Sends registration request message or registration update message including served user ID (s) to the UDM.
[0165] ● Receives registration response message from UDM.
[0166] In some embodiments, a UE may be configured to perform any one or more of the following operations:
[0167] ● Sends PDU Session Establishment Request message or PDU Session Modification Request message including user ID (s) to the SMF via AMF.
[0168] ○ The request message may include capability indication indicates whether the UE supports secondary DN authentication and authorization per user ID, and SM PDU DN Request Container including user ID (s) .
[0169] ● Receives Authentication / Authorization message including DN Request Container information from SMF via AMF.
[0170] ○ The message may include user ID (s) and related authentication / authorization information.
[0171] ● Sends DN Request Container information including user ID (s) and related authentication / authorization information to SMF via AMF.
[0172] ● Receives PDU Session Establishment Accept message or PDU Session Modification Command message from SMF via AMF.
[0173] FIG. 5 shows an exemplary block diagram of a hardware platform 500 that may be a part of a network device (e.g., base station) or a communication device (e.g., a user equipment (UE) ) . The hardware platform 500 includes at least one processor 510 and a memory 505 having instructions stored thereupon. The instructions upon execution by the processor 510 configure the hardware platform 500 to perform the operations described in FIGS. 1 to 4 and FIGS. 6 to 8 in the various embodiments described in this patent document. The transmitter 515 transmits or sends information or data to another device. For example, a network device transmitter can send a message to a user equipment. The receiver 520 receives information or data transmitted or sent by another device. For example, a user equipment can receive a message from a network device.
[0174] The implementations as discussed above will apply to a wireless communication. FIG. 6 shows an example of a wireless communication system (e.g., a 5G or NR cellular network) that includes a base station 620 and one or more user equipment (UE) 611, 612 and 613. In some embodiments, the UEs access the BS (e.g., the network) using a communication link to the network (sometimes called uplink direction, as depicted by dashed arrows 631, 632, 633) , which then enables subsequent communication (e.g., shown in the direction from the network to the UEs, sometimes called downlink direction, shown by arrows 641, 642, 643) from the BS to the UEs. In some embodiments, the BS send information to the UEs (sometimes called downlink direction, as depicted by arrows 641, 642, 643) , which then enables subsequent communication (e.g., shown in the direction from the UEs to the BS, sometimes called uplink direction, shown by dashed arrows 631, 632, 633) from the UEs to the BS. The UE may be, for example, a smartphone, a tablet, a mobile computer, a machine to machine (M2M) device, an Internet of Things (IoT) device, and so on.
[0175] FIG. 7 shows an exemplary flowchart for performing an authentication and authorization procedure. Operation 702 includes receiving, by a first network device from a communication device, a first message that includes one or more user identifiers (IDs) . Operation 704 includes performing, by the first network device, an authentication and authorization procedure for the one or more user IDs in response to the first message.
[0176] In some embodiments, the performing the authentication and authorization procedure includes determining to trigger the authentication and authorization procedure for the one or more user IDs. In some embodiments, the performing the authentication and authorization procedure includes sending an authentication or authorization request message that includes the one or more user IDs to a DN server. In some embodiments, the method further comprises transmitting, in response to the performing the authentication and authorization procedure, the one or more user IDs or all user IDs associated with the subscription to a policy control function (PCF) . In some embodiments, the method further comprises receiving, by the first network device from the PCF, protocol data unit (PDU) session related policy information for the one or more user IDs.
[0177] In some embodiments, the method further comprises transmitting, by the first network device to the communication device, a PDU session establishment accept message or a PDU session modification command message that indicates one or more parameters. In some embodiments, the first message includes a session management (SM) protocol data unit (PDU) data network (DN) request container that includes the one or more user IDs. In some embodiments, the first message includes a capability indication of the communication device that indicates that the communication device supports authentication and authorization per user ID. In some embodiments, the first message is a protocol data session (PDU) session establishment request message or a PDU session modification request message.
[0178] In some embodiments, the first message is received from the communication device via an access and mobility management function (AMF) . In some embodiments, the first network device includes a session management function (SMF) . In some embodiments, the method further comprises transmitting, by the first network device to a second network device, the one or more user IDs; and receiving, by the first network device from the second network device, a second message comprising subscription data for the one or more user IDs associated with the subscription. In some embodiments, the subscription data includes: one or more allowed protocol data unit (PDU) session types, one or more allowed session and service continuity (SSC) modes, a 5G quality of service identifier (5QI) and allocation and retention priority (ARP) , a subscribed session-aggregate maximum bit rate (AMBR) , and / or an internet protocol (IP) index or static IP address / prefix.
[0179] In some embodiments, the second network device includes a unified data management (UDM) . In some embodiments, the second message comprises the subscription data for all user IDs associated with the subscription. In some embodiments, the authentication and authorization per user ID includes a secondary data network (DN) authentication and authorization per user ID, and the authentication and authorization procedure includes a secondary DN authentication and authorization procedure.
[0180] FIG. 8 shows an exemplary flowchart for receiving an authentication or authorization message. Operation 802 includes transmitting, by a communication device to a network device, a first message that includes one or more user identifiers (IDs) . Operation 804 includes receiving, by the communication device from the network device, an authentication or authorization message.
[0181] In some embodiments, the first message includes a session management (SM) protocol data unit (PDU) data network (DN) request container that includes the one or more user IDs. In some embodiments, the first message includes a capability indication of the communication device regarding whether the communication device supports authentication and authorization per user ID. In some embodiments, the authentication or authorization message includes the one or more user IDs. In some embodiments, the method further comprises transmitting, by the communication device to the network device, a second message comprising authentication or authorization information associated with the one or more user IDs.
[0182] In some embodiments, the second message includes the one or more user IDs. In some embodiments, the method further comprises receiving, by the communication device from the first network device, a PDU session establishment accept message or a PDU session modification command message that indicates one or more parameters. In some embodiments, the authentication or authorization message is received by the communication device from the network device via an access and mobility management function (AMF) . In some embodiments, the network device includes a session management function (SMF) .
[0183] In this document the term “exemplary” is used to mean “an example of” and, unless otherwise stated, does not imply an ideal or a preferred embodiment.
[0184] Some of the embodiments described herein are described in the general context of methods or processes, which may be implemented in one embodiment by a computer program product, embodied in a computer-readable medium, including computer-executable instructions, such as program code, executed by computers in networked environments. A computer-readable medium may include removable and non-removable storage devices including, but not limited to, Read Only Memory (ROM) , Random Access Memory (RAM) , compact discs (CDs) , digital versatile discs (DVD) , etc. Therefore, the computer-readable media can include a non-transitory storage media. Generally, program modules may include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer-or processor-executable instructions, associated data structures, and program modules represent examples of program code for executing steps of the methods disclosed herein. The particular sequence of such executable instructions or associated data structures represents examples of corresponding acts for implementing the functions described in such steps or processes.
[0185] Some of the disclosed embodiments can be implemented as devices or modules using hardware circuits, software, or combinations thereof. For example, a hardware circuit implementation can include discrete analog and / or digital components that are, for example, integrated as part of a printed circuit board. Alternatively, or additionally, the disclosed components or modules can be implemented as an Application Specific Integrated Circuit (ASIC) and / or as a Field Programmable Gate Array (FPGA) device. Some implementations may additionally or alternatively include a digital signal processor (DSP) that is a specialized microprocessor with an architecture optimized for the operational needs of digital signal processing associated with the disclosed functionalities of this application. Similarly, the various components or sub-components within each module may be implemented in software, hardware or firmware. The connectivity between the modules and / or components within the modules may be provided using any one of the connectivity methods and media that is known in the art, including, but not limited to, communications over the Internet, wired, or wireless networks using the appropriate protocols.
[0186] While this document contains many specifics, these should not be construed as limitations on the scope of an invention that is claimed or of what may be claimed, but rather as descriptions of features specific to particular embodiments. Certain features that are described in this document in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a sub-combination or a variation of a sub-combination. Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results.
[0187] Only a few implementations and examples are described and other implementations, enhancements and variations can be made based on what is described and illustrated in this disclosure.
Claims
1.A wireless communication method, comprising:receiving, by a first network device from a communication device, a first message that includes one or more user identifiers (IDs) ; andperforming, by the first network device, an authentication and authorization procedure for the one or more user IDs in response to the first message.2.The method of claim 1, wherein the performing the authentication and authorization procedure includes determining to trigger the authentication and authorization procedure for the one or more user IDs.3.The method of claim 1, wherein the performing the authentication and authorization procedure includes sending an authentication or authorization request message that includes the one or more user IDs to a DN server.4.The method of claim 1, further comprising:transmitting, in response to the performing the authentication and authorization procedure, the one or more user IDs or all user IDs associated with the subscription to a policy control function (PCF) .5.The method of claim 4, further comprising:receiving, by the first network device from the PCF, protocol data unit (PDU) session related policy information for the one or more user IDs.6.The method of claim 1, further comprising:transmitting, by the first network device to the communication device, a PDU session establishment accept message or a PDU session modification command message that indicates one or more parameters.7.The method of claim 1, wherein the first message includes a session management (SM) protocol data unit (PDU) data network (DN) request container that includes the one or more user IDs.8.The method of claim 1, wherein the first message includes a capability indication of the communication device that indicates that the communication device supports authentication and authorization per user ID.9.The method of claim 1, wherein the first message is a protocol data session (PDU) session establishment request message or a PDU session modification request message.10.The method of claim 1, wherein the first message is received from the communication device via an access and mobility management function (AMF) .11.The method of claim 1, wherein the first network device includes a session management function (SMF) .12.The method of claim 1, further comprising:transmitting, by the first network device to a second network device, the one or more user IDs; andreceiving, by the first network device from the second network device, a second message comprising subscription data for the one or more user IDs associated with the subscription.13.The method of claim 12, wherein the subscription data includes:one or more allowed protocol data unit (PDU) session types,one or more allowed session and service continuity (SSC) modes,a 5G quality of service identifier (5QI) and allocation and retention priority (ARP) ,a subscribed session-aggregate maximum bit rate (AMBR) , and / oran internet protocol (IP) index or static IP address / prefix.14.The method of claim 12, wherein the second network device includes a unified data management (UDM) .15.The method of claim 12, wherein the second message comprises the subscription data for all user IDs associated with the subscription.16.The method of any one of claim 1 or 8,wherein the authentication and authorization per user ID includes a secondary data network (DN) authentication and authorization per user ID, andwherein the authentication and authorization procedure includes a secondary DN authentication and authorization procedure.17.A wireless communication method, comprising:transmitting, by a communication device to a network device, a first message that includes one or more user identifiers (IDs) ; andreceiving, by the communication device from the network device, an authentication or authorization message.18.The method of claim 17, wherein the first message includes a session management (SM) protocol data unit (PDU) data network (DN) request container that includes the one or more user IDs.19.The method of claim 17, wherein the first message includes a capability indication of the communication device regarding whether the communication device supports authentication and authorization per user ID.20.The method of claim 17, wherein the authentication or authorization message includes the one or more user IDs.21.The method of claim 17, further comprising:transmitting, by the communication device to the network device, a second message comprising authentication or authorization information associated with the one or more user IDs.22.The method of claim 20, wherein the second message includes the one or more user IDs.23.The method of claim 17, further comprising:receiving, by the communication device from the first network device, a PDU session establishment accept message or a PDU session modification command message that indicates one or more parameters.24.The method of claim 17, wherein the authentication or authorization message is received by the communication device from the network device via an access and mobility management function (AMF) .25.The method of claim 17, wherein the network device includes a session management function (SMF) .26.An apparatus for wireless communication comprising a processor, configured to implement a method recited in one or more of claims 1 to 25.27.A non-transitory computer readable program storage medium having code stored thereon, the code, when executed by a processor, causing the processor to implement a method recited in one or more of claims 1 to 25.
Citation Information
Patent Citations
Network slice specific authentication and authorization
CN115735371A
Apparatus and method for coordinating re-authentication / re-authorization procedures for access to unmanned air services
CN117083894A
Authority verification system, authority verification method, and computer-readable storage medium
US20180152441A1
Federated identity management in fifth generation (5G) system
WO2022159725A1