Apparatus and method for assigning a temporary identity to a device for use in a wireless network
By employing a TWIF to indirectly assign a 5G-GUTI through a wireless access point, the method addresses the challenge of secure authentication for N5CW devices, ensuring privacy and security in 5G Core networks.
Patent Information
- Application Number
- PCT/IB2025/052499
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-15
- Filing Date
- 2025-03-07
- Publication Date
- 2025-08-14
AI Technical Summary
Non-fifth generation-capable over Wireless Local Area Network (N5CW) devices, lacking a 5G modem, face challenges in obtaining a Globally Unique Temporary UE Identity (5G-GUTI) for secure authentication in 5G Core networks due to their inability to support the Non-Access Stratum protocol, leading to potential privacy risks and security vulnerabilities.
The proposed solution involves indirect communication through a wireless access point, utilizing a Trusted WLAN Interworking Function (TWIF) to facilitate the assignment of a 5G-GUTI by the Access and Mobility Management Function (AMF) via various message exchanges, including EAP Success, IP configuration, or NAS Registration Accept, ensuring secure delivery of the 5G-GUTI to the N5CW device.
This approach enables secure and efficient provisioning of 5G-GUTI to N5CW devices, enhancing privacy and security by using protected air interfaces for identity assignment, thereby mitigating tracking and impersonation risks.
Smart Images

Figure IB2025052499_14082025_PF_FP_ABST
Abstract
Description
APPARATUS AND METHOD FOR ASSIGNING A TEMPORARY IDENTITY TO A DEVICE FOR USE IN A WIRELESS NETWORKRELATED APPLICATION
[0001] This application claims priority to U.S. Patent Application Serial No. 63 / 565,984 filed March 15, 2024 entitled “APPARATUS AND METHOD FOR ASSIGNING A TEMPORARY IDENTITY TO A DEVICE FOR USE IN A WIRELESS NETWORK,” the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD
[0002] The present disclosure relates to wireless communications, and more specifically to an apparatus and method for the assignment of a temporary identity to a device for use in a wireless network.BACKGROUND
[0003] A wireless communications system may include one or multiple network communication devices, which may be otherwise known as network equipment (NE), supporting wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), user devices, or other suitable terminology. The wireless communications system may support wireless communications with the one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like)). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY
[0004] In some implementations of the method and apparatuses described herein, an access request message can be sent to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type. The access request message can include a subscriptionidentity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type. The assignment of the temporary identifier for use with the network of the first type can be received via the wireless access point, associated with the network of the second type.
[0005] A device (e.g., a Non-fifth generation-Capable over Wireless local area network (N5CW) device) for wireless communication is described. The apparatus may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the apparatus may be configured to, capable of, or operable to send an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; and receive via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type.
[0006] A processor (e.g., a standalone processor chipset, or a component of a N5CW device) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to send an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the processor supports an assignment of a temporary identifier for use with the network of the first type; and receive via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type.
[0007] A method performed or performable by a device (e.g., a N5CW device) for wireless communication is described. The method may include sending an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; and receiving via the wireless access point, associated with thenetwork of the second type, the assignment of the temporary identifier for use with the network of the first type.
[0008] In some implementations of the device, processor, and method described herein, the wireless access point associated with the network of a second type has an interworking function (IF) for communicating with an access and mobility management function (AMF) of the network of the first type.
[0009] In some implementations of the device, processor, and method described herein, the assignment of the temporary identifier for use with the network of the first type is received from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request.
[0010] In some implementations of the device, processor, and method described herein, the N2 initial context setup request sent by the AMF of the network of the first type includes an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the device with the network of the first type.
[0011] In some implementations of the device, processor, and method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the wireless access point associated with the network of the second type from the AMF based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance.
[0012] In some implementations of the device, processor, and method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an IP configuration response message.
[0013] In some implementations of the device, processor, and method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) request message.
[0014] In some implementations of the device, processor, and method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an EAP success message.
[0015] An NE (e.g., a base station) for wireless communication is described. The NE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the NE may be configured to, capable of, or operable to receive an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the NE, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; generate a temporary identifier for the device for use with the network of the first type; and send via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
[0016] A processor (e.g., a standalone processor chipset, or a component of a NE (e.g., a base station)) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to receive an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the processor, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; generate a temporary identifier for the device for use with the network of the first type; and send via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
[0017] A method performed or performable by an NE (e.g., a base station) for wireless communication is described. The method may include receiving an access request message from a device, where the device does not support direct communication with a first type of network that iscompatible with the NE, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; generating a temporary identifier for the device for use with the network of the first type; and sending via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
[0018] In some implementations of the NE, the processor, and the method described herein, the wireless access point associated with the network of a second type has an IF for communicating with an AMF of the NE.
[0019] In some implementations of the NE, the processor, and the method described herein, the assignment of the temporary identifier for use with the network of the first type is sent from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request.
[0020] In some implementations of the NE, the processor, and the method described herein, the N2 initial context setup request sent by the AMF of the network of the first type includes an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the device with the network of the first type.
[0021] In some implementations of the NE, the processor, and the method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the wireless access point associated with the network of the second type from the AMF based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance.
[0022] In some implementations of the NE, the processor, and the method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an IP configuration response message.
[0023] In some implementations of the NE, the processor, and the method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an EAP request message.
[0024] In some implementations of the NE, the processor, and the method described herein, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an EAP success message.BRIEF DESCRIPTION OF THE DRAWINGS
[0025] FIG. 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure;
[0026] FIGS. 2A and 2B illustrate an example of a signal flow diagram for an assignment of a temporary identity to a device for use in a network in accordance with aspects of the present disclosure;
[0027] FIG. 3 illustrates an example of a device in accordance with aspects of the present disclosure;
[0028] FIG. 4 illustrates an example of a processor in accordance with aspects of the present disclosure;
[0029] FIG. 5 illustrates an example of a NE in accordance with aspects of the present disclosure;
[0030] FIG. 6 illustrates a flowchart of a method performed by a device in accordance with aspects of the present disclosure; and
[0031] FIG. 7 illustrates a flowchart of a method performed by a NE in accordance with aspects of the present disclosure.DETAIEED DESCRIPTION
[0032] According to Third Generation Partnership Project (3GPP) Technical Specification (TS) 33.501 and 3GPP TS 23.502, a Non-fifth generation (5G)-Capable over Wireless local area network(WLAN) (N5CW) device is capable of registering to a 5G Core network (5GC) with 3GPP credentials, such as using a Universal Subscriber Identity Module (USIM), and of establishing 5GC connectivity via a trusted WLAN access network. An example N5CW device can be a laptop, tablet, or other device with a SIM card for a 5G carrier. The N5CW device may not have a 5G modem but can have a 5G subscription identity that is used for authentication. The N5CW device may not support a Non-Access Stratum (NAS) protocol, which gets interworked on behalf of the N5CW device by a Trusted WLAN Interworking Function (TWIF).
[0033] In instances where the N5CW device does not support NAS, there generally is no assignment of a 5G-GUTI (Globally Unique Temporary UE Identity) as part of the NAS Registration Accept message. It is the NAS protocol that typically assigns the 5G-GUTI. The N5CW device could receive a 5G-GUTI if it is capable of supporting 3GPP access to the 5GC network and correspondingly could support NAS over 3GPP access. However, it is more likely that a device that supports 3GPP access and the NAS protocol would also support the NAS protocol over the non-3GPP access, e.g., for trusted or untrusted access. Therefore, it is assumed that the N5CW device does not have a 5G modem with 3GPP access capabilities and is rather a simpler device like a laptop that may only have a USIM and WLAN access capability. In such a case there will not be a 5G-GUTI assigned by the 5GC, and the N5CW device would have to use a Subscription Concealed Identifier (SUCI) when attempting to attach to a Trusted WLAN Access Point (TWAP).
[0034] However, a SUCI is not intended to be used all the time for authentication in 5GC and should just be used once at the time of an initial registration. Afterwards the 5G-GUTI should be used. The SUCI freshness and level of encryption depends on the scheme being used by the mobile operator and in a worst case, such as one involving a NULL scheme, the encryption might be turned off. The N5CW may be subject to privacy attacks like tracking, impersonation, or other attacks, especially when the Subscription Permanent Identifier (SUPI) is not encrypted (NULL scheme).
[0035] Further, neither 3GPP TS 33.501 nor 3GPP TS 23.502 describe the allocation of a 5G- GUTI to a N5CW device. It is assumed that the 5G-GUTI is assigned as part of 3GPP access:If the N5CW device has registered to 5GC over 3GPP access when the above procedure is initiated, then the Network Access Identifier (NAI) includes the 5G-GUTI assigned tothe N5CW device over 3GPP access. This enables the TWIF to select the same Access and mobility Management Function (AMF) as the one serving the N5CW device over 3GPP access.
[0036] For N5CW devices only supporting non-3GPP access there may be no possibility to retrieve a 5G-GUTI, the device would have to use the SUCI in every case, which is not intended for this purpose, especially if the protection profile of the SUPI to generate the SUCI is weak and / or not used.
[0037] At least some embodiments of the present application can introduce one or more of at least three possible options for the alternative provisioning of the 5G-GUTI to the N5CW device. Because the N5CW device generally does not support the NAS protocol, the N5CW generally cannot receive a Registration Accept message directly from the AMF, within which the 5G-GUTI would typically be conveyed. Correspondingly, the N5CW may need to indicate the ability to receive a 5G-GUTI through alternative means, such as with a flag, so that the AMF would allocate a 5G-GUTI for the device.
[0038] In a first one of at least three possible options (Option A), the AMF allocates the 5G- GUTI for the N5CW device and sends it to the TWIF together with the key for the TWIF (KTWIF). The TWIF includes the 5G-GUTI in the Extensible Authentication Protocol (EAP) Success message to the N5CW device. In such an instance, the EAP Success message via the over the air interface, at this point in time, may not be protected.
[0039] In a second one of at least three possible options (Option B), the AMF allocates the 5G- GUTI for the N5CW device and sends it to the TWIF in the NAS Registration Accept message. The TWIF provides the new 5G-GUTI to the N5CW with the Internet Protocol (IP) configuration (DHCP response) over the protected air interface.
[0040] In a third one of at least three possible options (Option C), the AMF allocates the 5G- GUTI for the N5CW device and sends it to the TWIF in the NAS Registration Accept message. The TWIF initiates a new EAP message exchange, such as an Identity request, and provides the new 5G-GUTI in the EAP Success message over the protected air interface.
[0041] Reference is made herein to sending or receiving data or information. It is to be appreciated that other terms may be used interchangeably with sending, such as communicating,signaling, transmitting, outputting, forwarding, and so forth. It is also to be appreciated that other terms may be used interchangeably with receiving, such as communicating, signaling, retrieving, obtaining, and so forth.
[0042] Aspects of the present disclosure are described in the context of a wireless communications system.
[0043] FIG. 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more device 104, and a network 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G- UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and / or IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.
[0044] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a nextgeneration NodeB (gNB), an access point, a transmission-reception point (TRP), or other suitable terminology. An NE 102 and a device 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a device 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
[0045] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more devices 104 within the geographic coverage area. For example, an NE 102and a device 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NEs 102.
[0046] The one or more device 104 may be dispersed throughout a geographic region of the wireless communications system 100. A device 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the device 104 may be referred to as a UE, a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the device 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of-Everything (loE) device, or Machine-Type Communication (MTC) device, among other examples.
[0047] A device 104 may be able to support wireless communication directly with other devices 104 over a communication link. For example, a device 104 may support wireless communication directly with another device 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a device 104 may support wireless communication directly with another device 104 over a PC5 interface.
[0048] The network 106 can include a core network, wireless communication network, a cellular telephone network, a WLAN, a TDMA-based network, a CDMA -based network, a FDMA- based network, an Orthogonal Frequency Division Multiple Access (OFDMA)-based network, a Long Term Evolution (LTE) network, a New Radio (NR) network, a Third Generation Partnership Project (3GPP)-based network, a 5G network, a satellite communications network, a high-altitude platform network, the Internet, and / or other communications networks.
[0049] An NE 102 may support communications with the network 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the network 106 through oneor more backhaul links (e.g., SI, N2, N2, or network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other or indirectly (e.g., via the network 106. In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more devices 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or TRPs.
[0050] The network 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The network 106 may be an evolved packet core (EPC), or a 5GC, which may include a control plane entity that manages access and mobility (e.g., a Mobility Management Entity (MME), an Access and Mobility Management Function (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a Serving Gateway (S-GW), a Packet Data Network (PDN) Gateway (P-GW), or a User Plane Function (UPF)). In some implementations, the control plane entity may manage Non-Access Stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more devices 104 served by the one or more NE 102 associated with the network 106.
[0051] The network 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more devices 104 may communicate with the application server. A device 104 may establish a session (e.g., a Protocol Data Unit (PDU) session, or the like) with the network 106 via an NE 102. The network 106 may route traffic (e.g., control information, data, and the like) between the device 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the device 104 and the network 106 (e.g., one or more network functions of the network 106).
[0052] In the wireless communications system 100, the NEs 102 and the devices 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and thedevices 104 may support different resource structures. For example, the NEs 102 and the devices 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the devices 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the devices 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the devices 104 may support various frame structures based on one or more numerologies.
[0053] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0054] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0055] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, / =l , / r=2, / r=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots persubframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0056] In the wireless communications system 100, an Electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the devices 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the devices 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the devices 104, among other equipment or devices for short-range, high data rate capabilities.
[0057] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.
[0058] FIGS. 2A and 2B are an example of a signal flow diagram 200 showing an assignment of a temporary identity to a device, such as a N5CW device, for use in a network, as part of an authentication procedure. In accordance with at least one embodiment, the flow diagram describesexemplary messaging that could takes place between an N5CW device, a trusted WLAN access network, which can include a trusted WLAN access point and a TWIF, an AMF / Security Anchor Function (SEAF), an Authentication Server Function (AUSF), and a Unified Data Management (UDM) entity.
[0059] As part of the illustrated embodiment, the steps for the authentication procedure include:
[0060] 1. An initial registration and PDU session establishment, where the N5CW device associates with the trusted WLAN network and the EAP- Authentication and Key Agreement (AKA) authentication procedure is initiated.
[0061] 2. The N5CW device provides its Network Access Identity (NAI). The Trusted WLANAccess Point (TWAP) selects a Trusted WLAN Interworking Function (TWIF), for example, based on the received realm, and sends an Authentication, Authorization and Accounting (AAA) request to the selected TWIF. If the N5CW device registers to 5GC over 3GPP access for the first time when the above procedure is initiated, then the NAI shall include the SUCI. If the N5CW device has registered to 5GC over 3GPP access when the above procedure is initiated, then the NAI includes the 5G-GUTI assigned to the N5CW device over 3GPP access. This enables the TWIF in step 4a to select the same AMF as the one serving the N5CW device over 3GPP access. The N5CW may include an indication that it supports the allocation of a 5G-GUTI, such as via the use of a 5G-GUTI support Flag.
[0062] 3. The TWIF creates a 5GC Registration Request message on behalf of the N5CW device. The TWIF uses default values to populate the parameters in the Registration Request message, which can be the same for all N5CW device that do not support 5G NAS. The Registration type indicates "Initial Registration".
[0063] 4. The TWIF selects an AMF (e.g., by using the 5G-GUTI in the NAI, if provided by theN5CW device) and sends an N2 message to the AMF including the Registration Request, the User Location and an Access Network (AN) Type and the indication that it supports the allocation of a 5G-GUTI (5G-GUTI support Flag). The TWIF recognizes based on this indication that it needs to include the 5G-GUTI in a later message (e.g., step 12, 16 and / or 17) to the N5CW device.
[0064] 5. If the AMF triggers an authentication procedure, the AMF sends a request to AUSF by sending an Nausf_UEAuthentication_Authenticate Request message. TheNausf_UEAuthentication_Authenticate Request message contains SUCI or SUPI (if a valid 5G- GUTI is received by the AMF). The request message also contains an indication that the request is from a N5CW device. Even if the AMF already has a security context identified by 5G-GUTI, the AMF initiates the primary authentication. Note: To avoid key stream reuse when deriving KTWIF from KAMF, the KAMF should be refreshed by a renewed primary authentication.
[0065] 6. The AUSF sends Nudm_UEAuthentication_Get Request to the UDM including SUCI or SUPI and the N5CW indication.
[0066] 7. Upon reception of the Nudm_UEAuthentication_Get Request, the UDM invokesSubscription Identifier De-concealing Function (SIDF) if a SUCI is received. SIDF de-conceals SUCI to gain SUPI before UDM can process the request. The UDM may select an authentication method based on the "realm" part of the SUPI, the N5CW device indicator, a combination of the "realm" part and the N5CW device indicator, or the UDM local policy.
[0067] 8. The EAP-AKA procedure will be trigged to perform mutual authentication between the N5CW device and the home network. EAP-AKA takes place between the N5CW device and AUSF. Over the N2 interface, the EAP messages are encapsulated within NAS Authentication messages. The EAP-AKA messages exchanged between the N5CW Device and the TWIF are encapsulated into the layer-2 packets, e.g., into IEEE 802.3 / 802. lx packets, into IEEE 802.11 / 802. lx packets, into Point-to-Point Protocol (PPP) packets, etc.
[0068] 9. The NAS security context is not required in this scenario. The AMF derives a KTWIF key from the received KAMF key. NAS security between AMF and TWIF is established similar to unauthenticated emergency calls, i.e., with NULL encryption and NULL integrity protection. NOTE: N5CW devices generally do not support NAS, therefore, using the NAS counter may not be possible in N5CW devices.
[0069] 10a. The AMF sends NAS Security Mode Command to the TWIF. The NAS SecurityMode Command contains the EAP-Success message and the NULL security algorithms.
[0070] 10c. The TWIF does not forward the EAP-Success to the N5CW directly. Instead, theTWIF stores the EAP-Success message and waits for KTWIF.
[0071] lOd. The TWIF sends the NAS Security Mode Complete message to the AMF.
[0072] In instances where option A is selected, steps 202, which includes steps lOe, 11, 12a, 12b and 12c are executed.
[0073] lOe. The AMF allocates a 5G-GUTI for the N5CW device, based on the received indication in step 4 [Option A] .
[0074] 11. The AMF sends an N2 Initial Context Setup Request and provides the KTWIF key and the 5G-GUTI [Option A] to TWIF.
[0075] 12. The TWIF derives a Trusted Non-3GPP Access Point (TNAP) key, KTNAP, from theK Trusted Non-3GPP Gateway Function (TNGF) key and sends the TNAP key and the EAP-Success message with the 5G-GUTI [Option A] to the Trusted WLAN Access Point, which forwards the EAP-Success with the 5G-GUTI [Option A] to the N5CW device. The TNAP key corresponds to the Pairwise Master Key (PMK) which is used to secure the WLAN air-interface communication according to IEEE 802.11. A layer-2 or layer-3 connection is established between the Trusted WLAN Access Point and the TWIF for transporting all user-plane traffic of the N5CW device to TWIF. This connection is later bound to an N3 connection that is created for this N5CW device.
[0076] 13. The TWIF sends N2 Initial Context Setup Response message to the AMF.
[0077] In instances where either option B and / or C is selected, steps 204, which includes steps 14 and 15 are executed.
[0078] 14. The AMF allocates a 5G-GUTI for the N5CW device, based on the received indication in step 4 [Options B, C].
[0079] 15. the AMF sends a Registration Accept message with the 5G-GUTI [Option B,C] toTWIF. At this point, the N5CW device is connected to the WLAN Access Network and is registered to 5GC.
[0080] In instances where option B is selected, steps 206, which includes steps 16a and 16b are executed.
[0081] 16a. The TWIF receives an IP configuration request (e.g., Dynamic Host ConfigurationProtocol (DHCP) Offer / Request) from the N5CW device [Option B].
[0082] 16b. The TWIF assigns IP configuration data with the 5G-GUTI [Option B] to N5CW device (e.g., with DHCP). The IP address assigned to N5CW device is the IP address allocated to the PDU session.
[0083] In instances where option C is selected, steps 208, which includes 17a, 17b and 17c are executed.
[0084] 17a. The TWIF sends an EAP Request (e.g., EAP Identity request) to the N5CW device.This request may already contain the new 5G-GUTI [Alternative #1]
[0085] 17b. The N5CW responds to the request to the TWIF. If it was an EAP Identity Request, the N5CW sends the identity (SUCI, “old” 5G-GUTI) as used in the step 2b previously. If the TWIF already allocated the new 5G-GUTI in step 17a, the N5CW may only acknowledge the receipt of the request.
[0086] 17c. The TWIF sends an EAP success to the N5CW device, if not included in step 17a, the TWIF includes the new 5G-GUTI in the message to the N5CW device [Alternative #2].
[0087] FIG. 3 illustrates an example of a device 300, such as a N5CW device, in accordance with aspects of the present disclosure. The device 300 may include at least one processor 302, at least one memory 304, at least one controller 306, and at least one transceiver 308. The processor 302, the memory 304, the controller 306, or the transceiver 308, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0088] The processor 302, the memory 304, the controller 306, or the transceiver 308, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0089] The processor 302 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In someimplementations, the processor 302 may be configured to operate the memory 304. In some other implementations, the memory 304 may be integrated into the processor 302. The processor 302 may be configured to execute computer-readable instructions stored in the memory 304 to cause the device 300 to perform various functions of the present disclosure.
[0090] The memory 304 may include volatile or non-volatile memory. The memory 304 may store computer-readable, computer-executable code including instructions when executed by the processor 302 to cause the device 300 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 304 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates the transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0091] The controller 306 may manage input and output signals for the device 300. The controller 306 may also manage peripherals not integrated into the device 300. In some implementations, the controller 306 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 306 may be implemented as part of the processor 302.
[0092] In some implementations, the device 300 may include at least one transceiver 308. In some other implementations, the device 300 may have more than one transceiver 308. The transceiver 308 may represent a wireless transceiver. The transceiver 308 may include one or more receiver chains 310, one or more transmitter chains 312, or a combination thereof.
[0093] A receiver chain 310 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 310 may include one or more antennas to receive the signal over the air or wireless medium. The receiver chain 310 may include at least one amplifier (e.g., a Low-Noise Amplifier (LNA)) configured to amplify the received signal. The receiver chain 310 may include at least one demodulator configured to demodulate the received signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 310 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0094] A transmitter chain 312 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 312 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as Amplitude Modulation (AM), Frequency Modulation (FM), or digital modulation schemes like Phase-Shift Keying (PSK) or Quadrature Amplitude Modulation (QAM). The transmitter chain 312 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 312 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0095] In some implementations, the processor 302 and the memory 304 coupled with the processor 302 may be configured to cause the device 300 to perform one or more of the functions described herein (e.g., executing, by the processor 302, instructions stored in the memory 304). For example, the processor 302 may support wireless communication at the device 300 in accordance with examples as disclosed herein. The device 300 may be configured to support a means for assigning a temporary identity to a device for use in a wireless network.
[0096] The device 300 may be configured to or operable to support a means for sending an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; and receiving via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type.
[0097] According to a possible embodiment, the device 300 can be a N5CW device in that it can have 5G credentials, but may not support NAS. The at least one processor 302 can be configured to or operable to cause the device 300 to send an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type. The access request message includes a subscription identity for use with the network of the first type and an indication, such as a 5G-GUTI support flag, that the device supports an assignment of a temporary identifier for use with the network of the first type. The assignment of the temporaryidentifier for use with the network of the first type is received via the wireless access point, associated with the network of the second type.
[0098] According to a possible embodiment, the wireless access point associated with the network of a second type can have an interworking function (IF) for communicating with an access and mobility management function (AMF) of the network of the first type. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be received from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request. Still further, the N2 initial context setup request sent by the AMF of the network of the first type can include an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the device with the network of the first type.
[0099] In some instances, the assignment of the temporary identifier for use with the network of the first type can be received by the wireless access point associated with the network of the second type from the AMF based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be received by the device from the wireless access point associated with the network of the second type as part of an IP configuration response message. In other of these instances, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) request message. In further other instances, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) success message.
[0100] FIG. 4 illustrates an example of a processor 400 in accordance with aspects of the present disclosure. The processor 400 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 400 may include at least one controller 402 configured to perform various operations in accordance with examples asdescribed herein. The processor 400 may optionally include at least one memory 404, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 400 may optionally include one or more arithmetic-logic units (ALUs) 406. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0101] The processor 400 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 400) or other memory (e.g., Random Access Memory (RAM), Read-Only Memory (ROM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Static RAM (SRAM), Ferroelectric RAM (FeRAM), Magnetic RAM (MRAM), Resistive RAM (RRAM), flash memory, Phase Change Memory (PCM), and others).
[0102] The controller 402 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, and reading) of the processor 400 to cause the processor 400 to support various operations in accordance with examples as described herein. For example, the controller 402 may operate as a control unit of the processor 400, generating control signals that manage the operation of various components of the processor 400. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0103] The controller 402 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 404 and determine subsequent instruction(s) to be executed to cause the processor 400 to support various operations in accordance with examples as described herein. The controller 402 may be configured to track memory address of instructions associated with the memory 404. The controller 402 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 402 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 400 to cause the processor 400 to support various operations in accordance with examplesas described herein. Additionally, or alternatively, the controller 402 may be configured to manage flow of data within the processor 400. The controller 402 may be configured to control transfer of data between registers, Arithmetic Logic Units (ALUs), and other functional units of the processor 400.
[0104] The memory 404 may include one or more caches (e.g., memory local to or included in the processor 400 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 404 may reside within or on a processor chipset (e.g., local to the processor 400). In some other implementations, the memory 404 may reside external to the processor chipset (e.g., remote to the processor 400).
[0105] The memory 404 may store computer-readable, computer-executable code including instructions that, when executed by the processor 400, cause the processor 400 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 402 and / or the processor 400 may be configured to execute computer-readable instructions stored in the memory 404 to cause the processor 400 to perform various functions. For example, the processor 400 and / or the controller 402 may be coupled with or to the memory 404, the processor 400, the controller 402, and the memory 404 may be configured to perform various functions described herein. In some examples, the processor 400 may include multiple processors and the memory 404 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
[0106] The one or more ALUs 406 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 406 may reside within or on a processor chipset (e.g., the processor 400). In some other implementations, the one or more ALUs 406 may reside external to the processor chipset (e.g., the processor 400). One or more ALUs 406 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 406 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 406 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation.Additionally, or alternatively, the one or more ALUs 406 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 406 to handle conditional operations, comparisons, and bitwise operations.
[0107] In operation according to a possible embodiment, the at least one controller 402 can be configured to or operable to cause the processor 400 to receive an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the NE, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type. The access request message can include a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type. The at least one controller 402 can cause the processor 400 to generate a temporary identifier for the device for use with the network of the first type, and send via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
[0108] The processor 400 may support wireless communication in accordance with examples as disclosed herein. According to a possible embodiment relating to a device, such as the N5CW device, the at least one controller 402 can be configured to or operable to cause the processor 400 to send an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type. The access request message includes a subscription identity for use with the network of the first type and an indication, such as a 5G-GUTI support flag, that the processor supports an assignment of a temporary identifier for use with the network of the first type. The assignment of the temporary identifier for use with the network of the first type is received via the wireless access point, associated with the network of the second type.
[0109] According to a possible embodiment, the wireless access point associated with the network of a second type can have an interworking function (IF) for communicating with an access and mobility management function (AMF) of the network of the first type. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be received from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the processor of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request. Still further,the N2 initial context setup request sent by the AMF of the network of the first type can include an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the processor with the network of the first type.
[0110] In some instances, the assignment of the temporary identifier for use with the network of the first type can be received by the wireless access point associated with the network of the second type from the AMF based upon the indicated support by the processor of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be received by the processor from the wireless access point associated with the network of the second type as part of an IP configuration response message. In other of these instances, the assignment of the temporary identifier for use with the network of the first type is received by the processor from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) request message. In further other instances, the assignment of the temporary identifier for use with the network of the first type is received by the processor from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) success message.
[0111] FIG. 5 illustrates an example of a NE 500 in accordance with aspects of the present disclosure. The NE 500 may include a processor 502, a memory 504, a controller 506, and a transceiver 508. The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0112] The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereofconfigured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0113] The processor 502 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 502 may be configured to operate the memory 504. In some other implementations, the memory 504 may be integrated into the processor 502. The processor 502 may be configured to execute computer-readable instructions stored in the memory 504 to cause the NE 500 to perform various functions of the present disclosure.
[0114] The memory 504 may include volatile or non-volatile memory. The memory 504 may store computer-readable, computer-executable code including instructions when executed by the processor 502 cause the NE 500 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 504 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0115] In some implementations, the processor 502 and the memory 504 coupled with the processor 502 may be configured to cause the NE 500 to perform one or more of the functions described herein (e.g., executing, by the processor 502, instructions stored in the memory 504). For example, the processor 502 may support wireless communication at the NE 500 in accordance with examples as disclosed herein.
[0116] The controller 506 may manage input and output signals for the NE 500. The controller 506 may also manage peripherals not integrated into the NE 500. In some implementations, the controller 506 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 506 may be implemented as part of the processor 502.
[0117] In some implementations, the NE 500 may include at least one transceiver 508. In some other implementations, the NE 500 may have more than one transceiver 508. The transceiver 508may represent a wireless transceiver. The transceiver 508 may include one or more receiver chains 510, one or more transmitter chains 512, or a combination thereof.
[0118] A receiver chain 510 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 510 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 510 may include at least one amplifier (e.g., a Low-Noise Amplifier (LNA)) configured to amplify the received signal. The receiver chain 510 may include at least one demodulator configured to demodulate the received signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 510 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0119] A transmitter chain 512 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 512 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as Amplitude Modulation (AM), Frequency Modulation (FM), or digital modulation schemes like Phase-Shift Keying (PSK) or Quadrature Amplitude Modulation (QAM). The transmitter chain 512 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 512 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0120] The NE 500 may be configured to or operable to support a means for receiving an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the NE, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; generating a temporary identifier for the device for use with the network of the first type; and sending via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
[0121] In operation according to a possible embodiment, the at least one processor 502 can be configured to or operable to cause the NE 500 to receive an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the NE, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type. The access request message can include a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type. The at least one processor 502 can generate a temporary identifier for the device for use with the network of the first type. The transmitter chain 512 and / or transceiver 508 can send via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
[0122] According to a possible embodiment, the wireless access point associated with the network of a second type can have an interworking function (IF) for communicating with an access and mobility management function (AMF) of the NE. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be sent from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request. Still further, the N2 initial context setup request sent by the AMF of the network of the first type can include an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the device with the network of the first type.
[0123] In some instances, the assignment of the temporary identifier for use with the network of the first type can be received by the wireless access point associated with the network of the second type from the AMF based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be received by the device from the wireless access point associated with the network of the second type as part of an IP configuration response message. In other of these instances, the assignment of the temporary identifier for use with the network of thefirst type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) request message. In further other instances, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) success message.
[0124] FIG. 6 illustrates an example flowchart 600 of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a device, such as a N5CW device, as described herein. In some implementations, the device may execute a set of instructions to control the function elements of the device to perform the described functions.
[0125] At 602, the method can include sending an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type. At 604, the method can include receiving via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type.
[0126] According to a possible embodiment, the wireless access point associated with the network of a second type can have an interworking function (IF) for communicating with an access and mobility management function (AMF) of the network of the first type. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be received from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request. Still further, the N2 initial context setup request sent by the AMF of the network of the first type can include an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the device with the network of the first type.
[0127] In some instances, the assignment of the temporary identifier for use with the network of the first type can be received by the wireless access point associated with the network of the secondtype from the AMF based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance. In some of these instances, the assignment of the temporary identifier for use with the network of the first type can be received by the device from the wireless access point associated with the network of the second type as part of an IP configuration response message. In other of these instances, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) request message. In further other instances, the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) success message.
[0128] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0129] FIG. 7 illustrates an example flowchart 700 of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE, such as at least one NE implementing the TWIF of FIGS. 2 A and 2B. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
[0130] At 702, the method can include receiving an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the NE, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type. The access request message can include a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type.
[0131] At 704, the method can include generating a temporary identifier for the device for use with the network of the first type.
[0132] At 706, the method can include sending via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
[0133] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0134] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
[0135] At least some methods of this disclosure can be implemented on a programmed processor. However, the controllers, flowcharts, and modules may also be implemented on a general purpose or special purpose computer, a programmed microprocessor or microcontroller and peripheral integrated circuit elements, an integrated circuit, a hardware electronic or logic circuit such as a discrete element circuit, a programmable logic device, or the like. In general, any device on which resides a finite state machine capable of implementing the flowcharts shown in the figures may be used to implement the processor functions of this disclosure.
[0136] At least some embodiments can improve operation of the disclosed devices. Various components of the embodiments may be interchanged, added, or substituted in the other embodiments. Also, all of the elements of each figure are not necessary for operation of the disclosed embodiments. For example, one of ordinary skill in the art of the disclosed embodiments would be enabled to make and use the teachings of the disclosure by simply employing the elements of the independent claims. Accordingly, embodiments of the disclosure as set forth herein are intended to be illustrative, not limiting. Various changes may be made without departing from the spirit and scope of the disclosure.
[0137] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,”and “at least one of one or more” may be interchangeable. For example, an element proceeded by "a," "an," or the like does not, without more constraints, preclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). For example, the phrase "at least one of," "at least one selected from the group of," or "at least one selected from" followed by a list is defined to mean one, some, or all, but not necessarily all of, the elements in the list. Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on.” Further, as used herein, including in the claims, a “set” may include one or more elements.
[0138] The terms "comprises," "comprising," "including," or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. Also, the term "another" is defined as at least a second or more. The terms "including," "having," and the like, as used herein, are defined as "comprising." Terms of approximation, such as “approximately,” “near,” “substantially,” and / or other related terms, unless otherwise defined, are defined as a range within + / - 5% of the approximated element, a range within + / - 10% of the approximated element, and / or a range close enough to the approximated element to achieve an intended result. All elements of the disclosed embodiments can be modified with such terms. In this document, relational terms such as "first," "second," and the like may be used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any actual such relationship or order between such entities or actions.
[0139] The background section is not admitted as prior art, is written as the inventor's own understanding of the context of some embodiments at the time of filing, and includes the inventor'sown recognition of any problems with existing technologies and / or problems experienced in the inventor's own work.
Claims
CLAIMSWhat is claimed is:
1. A device for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the device to: send an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; and receive via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type.
2. The device of claim 1 , wherein the wireless access point associated with the network of a second type has an interworking function (IF) for communicating with an access and mobility management function (AMF) of the network of the first type.
3. The device of claim 2, wherein the assignment of the temporary identifier for use with the network of the first type is received from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request.
4. The device of claim 3, wherein the N2 initial context setup request sent by the AMF of the network of the first type includes an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the device with the network of the first type.
5. The device of claim 2, wherein the assignment of the temporary identifier for use with the network of the first type is received by the wireless access point associated with the network of the second type from the AMF based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance.
6. The device of claim 5, wherein the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an IP configuration response message.
7. The device of claim 5, wherein the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) request message.
8. The device of claim 5, wherein the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) success message, type as part of an extensible authentication protocol (EAP) success message.
9. A method performed by a device, the method comprising: sending an access request message to a network of a first type, indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; and receiving via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use with the network of the first type.
10. The method of claim 9, wherein the wireless access point associated with the network of a second type has an interworking function (IF) for communicating with an access and mobility management function (AMF) of the network of the first type.
11. The method of claim 10, wherein the assignment of the temporary identifier for use with the network of the first type is received from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request.
12. A network equipment, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the network equipment to: receive an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the network equipment, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; generate a temporary identifier for the device for use with the network of the first type; and send via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type-13. The network equipment of claim 12, wherein the wireless access point associated with the network of a second type has an interworking function (IF) for communicating with an access and mobility management function (AMF) of the network equipment.
14. The network equipment of claim 13, wherein the assignment of the temporary identifier for use with the network of the first type is sent from the AMF via the wireless access point associated with the network of the second type based upon the indicated support by the device of theassignment of a temporary identifier for use with the network of the first type, as part of an N2 initial context setup request.
15. The network equipment of claim 14, wherein the N2 initial context setup request sent by the AMF of the network of the first type includes an encryption key in support of communication between the AMF and the IF of the wireless access point associated with the network of the second type in addition to the temporary identifier assignment for use by the device with the network of the first type.
16. The network equipment of claim 13, wherein the assignment of the temporary identifier for use with the network of the first type is received by the wireless access point associated with the network of the second type from the AMF based upon the indicated support by the device of the assignment of a temporary identifier for use with the network of the first type, as part of an N2 message indicating registration acceptance.
17. The network equipment of claim 16, wherein the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an IP configuration response message.
18. The network equipment of claim 16, wherein the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) request message.
19. The network equipment of claim 16, wherein the assignment of the temporary identifier for use with the network of the first type is received by the device from the wireless access point associated with the network of the second type as part of an extensible authentication protocol (EAP) success message.
20. A method performed by a network equipment, the method comprising: receiving an access request message from a device, where the device does not support direct communication with a first type of network that is compatible with the network equipment, and where the access request message is received indirectly, via a wireless access point, associated with a network of a second type, the access request message including a subscription identity for use with the network of the first type and an indication that the device supports an assignment of a temporary identifier for use with the network of the first type; generating a temporary identifier for the device for use with the network of the first type; and sending via the wireless access point, associated with the network of the second type, the assignment of the temporary identifier for use by the device with the network of the first type.
Citation Information
Patent Citations
Inspection device for containment liner plate of nuclear reactor
KR102671115B1
US202463565984P