Mobile network operator exposure of human identification authentication for external network servers

MNOs authenticate human identities through user device profiles, addressing compliance challenges by linking human identifiers to subscriptions, enabling secure and monetizable identity verification and traffic management.

WO2025172556A1PCT designated stage Publication Date: 2025-08-21TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Patent Information

Application Number
PCT/EP2025/054070
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-16
Filing Date
2025-02-14
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Current mobile network operators (MNOs) and operating systems lack the capability to authenticate human identities, making it difficult to comply with regulatory laws requiring human identity verification for accessing restricted content, and existing authentication methods rely on device access rather than user identity, which is insufficient for compliance and security.

Method used

MNOs provide a human identification authentication service by associating human identifiers with user device profiles, leveraging existing network architecture to securely authenticate users and enable differentiated traffic management, using methods such as biometric verification and cryptographic keys to link human identities to user subscriptions.

Benefits of technology

Enables secure and compliant human identity authentication, allowing MNOs to monetize this service and apply differentiated traffic management, ensuring regulatory compliance and user-specific access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025054070_21082025_PF_FP_ABST
    Figure EP2025054070_21082025_PF_FP_ABST
Patent Text Reader

Abstract

A method performed by a first network node for performing human identification authentication is disclosed. In one example, the method includes receiving a human identification authentication inquiry from a first content host, wherein the human identification authentication inquiry includes a subscriber phone number and a requested content category parameter corresponding to a subscriber user device. The method further includes sending a human identification authentication request to a first authentication network node wherein the request includes the subscriber phone number and requested content category indicator corresponding to the subscriber user device, and receiving a human identification authentication response that includes an indication of a successful authentication or a rejected authentication of a human identifier with respect to the requested content category parameter. The method also includes sending, to the first content host, a human identification authentication reply message that includes the indication of the successful authentication or the rejected authentication.
Need to check novelty before this filing date? Find Prior Art

Description

MOBILE NETWORK OPERATOR EXPOSURE OF HUMAN IDENTIFICATION AUTHENTICATION FOR EXTERNAL NETWORK SERVERSTECHNICAL FIELD

[0001] The present disclosure relates generally to communications, and more particularly to methods and related devices and network nodes performing wireless and / or cellular based communications and signaling.BACKGROUND

[0002] Presently, governments of various nations are promoting regulatory laws for enabling restricted content filtering (e.g., adult content filtering). When enacted, these laws and / or regulations will require a user to login to the content provider using that person’ s human identity to access certain web resources. Nowadays, there is no way for content providers to identify the human that is behind and / or operating the device. Moreover, mobile network operators (MNOs) and operating systems (OSs) currently do not have the capability to authenticate a human identity, much less monetize the use case.

[0003] Today, procedures are used to (indirectly) identify users based on a subscriber identification module (SIM) which is inserted or stored in a device. A service provider, like a provider of financial services, may provide an identification app which is associated with the SIM and may thus control access to its services via the app and based on the authentication provided by the SIM. However in such cases, anyone having access to the respective device will be able to access the service, and it is usually not possible to discriminate different users of a device. It is under the responsibility and in the interest of the (main) user of the device to make sure that no authorized person gets access to these services, e.g. by further password protection etc.. However this type of authentication and reliance on user’s responsibility may put an undesired burden on a main user of a device and may not be sufficient for compliance with regulatory requirements.SUMMARY

[0004] The present disclosure proposes a mechanism for MNOs to provide a new human identification authentication service, based on network exposure, for authenticating human users operating both 3rdGeneration Partnership Project (3GPP) devices or non-3GPP devices. The new human identification authentication service can be provided by the MNOs to Internetservers (e.g., content providers, service providers, etc.) for the validation of subscriber users and to comply with regulatory laws. As a pre-requisite, an MNO shall register human identifiers per an MNO user subscription.

[0005] More specifically, the disclosed subject matter pertains to human identification association with a MNO user subscription (e.g., mapping to a subscriber identity module (SIM)) and an associated user device profile (e.g., UE profile) generation. The disclosed subject matter further entails utilizing MNOs to provide human identification authentication services for Internet servers in accordance with relevant government laws and regulations.

[0006] In one embodiment, the disclosed subject matter includes a method performed by a user device for associating a human identifier to a user device profile including receiving a human identifier request from a first network node; generating a new user device profile in response to selecting a human identifier stored on the user device; establishing a binding link between the selected human identifier and the new user device profile; and sending the human identifier and the new user device profile to the first network node.

[0007] In one embodiment, the disclosed subject matter includes a method performed by a first network node for associating a human identifier to a user device profile (e.g., UE profile), including receiving a session management policy control message corresponding to a first user device from a second network node; sending a human identifier request message to the first user device via the second network node in response to determining a human identification authentication for the first user device is required; and receiving a human identifier and associated user device profile from the first user device in response to the human identifier request.

[0008] In one embodiment, the disclosed subject matter includes a method performed by a first network node for performing human identification authentication includes receiving a human identification authentication inquiry from a first content host, wherein the human identification authentication inquiry includes a subscriber phone number and a requested content category parameter corresponding to a subscriber user device; sending a human identification authentication request to a first authentication network node wherein the human identification authentication request includes the subscriber phone number and requested content category indicator corresponding to the subscriber user device; receiving, from the first authentication network node, a human identification authentication response that includes an indication of a successful authentication or a rejected authentication of a human identifier with respect to the requested content category parameter, wherein the human identifier corresponds to the subscriber phone number; and sending, to the first content host, a human identificationauthentication reply message that includes the indication of the successful authentication or the rejected authentication.

[0009] In one embodiment, the disclosed subject matter includes a method performed by a first authentication network node for authenticating a human identifier includes receiving a human identification authentication request from a first network node, wherein the human identification authentication request includes a subscriber phone number and requested content category parameter corresponding to a subscriber user device; obtaining a subscription permanent identifier, SUPI, corresponding to the subscriber phone number; sending, to a first mobility network node, a modified human identification authentication request containing the SUPI; receiving, from the first mobility network node, a human identification authentication response that includes a human identifier associated to the SUPI; and sending, to the first network node, a modified human identification authentication response that includes an indication of a successful authentication or a rejected authentication of the human identifier with respect to the requested content category parameter.

[0010] According to other embodiments, a network node and a non-transitory computer readable medium is provided to perform each of the above methods.

[0011] Further, a method is provided for associating a mobile network subscription with a human identity based on a verification of the human identity. Therein, first verification information is created and stored by a server. Based on second verification information provided by a subscriber of the mobile network subscription matching the stored first verification information, the mobile network subscription is associated with the human identity.

[0012] Certain aspects of the disclosure and their embodiments may provide technical advantages. For example, the disclosed subject matter allows the network operator to leverage existing network architecture and / or signaling to securely provide and monetize a human identification authentication method for 3GPP and non-3GPP devices. Further, the disclosed subject matter enables a network operator to identify the human user operating a UE to apply differentiated traffic management actions for the identified individual human user utilizing a user device (e.g., UE) associated with a particular subscription.BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The accompanying drawings, which are included to provide a further understanding of the disclosure and are incorporated in and constitute a part of this application, illustrate certain non-limiting embodiments of inventive concepts. In the drawings:

[0014] Figure l is a block diagram of an example 5G system architecture;

[0015] Figure 2 is an example signaling diagram for generating a UE profile associated with a human identifier obtained via PDU session establishment signaling according to some embodiments;

[0016] Figure 3 is a block diagram of UE profiles associated with human identifiers on a UE according to some embodiments;

[0017] Figure 4 is an example signaling diagram for generating a UE profile associated with a human identifier using a MNO application provisioned on the UE according to some embodiments;

[0018] Figure 5 is a block diagram of a UE profiles associated with human identifiers on a UE using an MNO application according to some embodiments;

[0019] Figure 6 is a signaling diagram depicting an example authentication service provided by an MNO according to some embodiments;

[0020] Figure 7 is a flow chart illustrating example operations for associating a human identifier at a UE according to some embodiments;

[0021] Figure 8 is a flow chart illustrating example operations for associating a human identifier at a first network node according to some embodiments;

[0022] Figure 9 is a flow chart illustrating example operations for performing human identification authentication by a first network node according to some embodiments;

[0023] Figure 10 is a flow chart illustrating example operations for performing human identification authentication by a first authentication network node according to some embodiments;

[0024] Figure 11 is a block diagram of a communication system in accordance with some embodiments;

[0025] Figure 12 is a block diagram of a user device in accordance with some embodiments

[0026] Figure 13 is a block diagram of a network node in accordance with some embodiments;DETAILED DESCRIPTION

[0027] The disclosed subject matter presents a mechanism that allows a MNO to provide and monetize a human identification authentication method for services like Internet servers (e.g., content providers) to utilize and comply with regulatory laws. In some embodiments, the present disclosure includes the registration and / or mapping of a human identifier (ID) to anexisting MNO user subscription, thereby associating the human ID to one or more UE resp. user device profiles. The disclosed subject matter further utilizes network exposure to trigger an authentication process for a human user operating a 3GPP or non-3GPP device.

[0028] Figure 1 depicts a block diagram of an example 5G system architecture 100 as defined by 3GPP. Notably, the 5G system is one telecommunication system in which the disclosed subject matter can be configured to operate within. Although 5G system architecture 100 depicts a number of network functions and nodes, the relevant architectural aspects for the disclosed subject matter include, but not limited to, Application Function (AF) 102, Network Exposure Function (NEF) 104, Unified Data Manager (UDM) and / or Unified Data Repository (UDR) 106, Access and Mobility Management Function (AMF) 108, Policy Control Function (PCF) 110, Session Management Function (SMF) 112, User Plane Function (UPF) 114, and Authentication Server Function (AUSF) 116. Figure 1 further depicts user equipment (UE) 101, Radio Access Network (RAN) 118, and Data Network (DN) 120.

[0029] As used herein, AF 102 may be configured to interact with the 3GPP Core Network and permit external parties to use exposure application programming interfaces (APIs) offered by the network operator. Similarly, NEF 104 may be configured to support different functionalities, including different exposure APIs.

[0030] As used herein, UDR 106 can be configured to store data grouped into distinct collections of subscription-related information including i) Subscription Data, ii) Policy Data, iii) Structured Data for Exposure, and iv) Application Data.

[0031] As used herein, AMF 108 may be configured to support different functionalities, including Termination of NAS signaling, NAS ciphering and integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. Further, AMF 108 can be used to convey information from and / or to UE 101 through NAS signaling, including the UE policies provided by PCF 110.

[0032] Moreover, PCF 110 may be configured to support a unified policy framework to govern the network behavior. Specifically, the PCF provides Policy and Charging Control (PCC) rules to the Policy and Charging Enforcement Function (PCEF). Notably, the SMF / UPF (as indicated below) are configured to enforce policy and charging decisions according to provisioned PCC rules.

[0033] As used herein, SMF 112 may support different functionalities, such as receiving PCC rules from the PCF 110 and subsequently configures the UPF 114 accordingly.

[0034] Likewise, the UPF 114 can be configured to support handling of user plane traffic, including packet inspection, packet routing, packet forwarding, traffic usage reporting, and quality of service (QoS) handling.

[0035] The AUSF 116 may be configured to support handling of user authentication towards the 5G network.

[0036] Figure 1 further illustrates a user device, e.g., UE 101, communicating with a RAN 118, which in turn is connected to a data network 120 (e.g., Internet network) via UPF 114. Although the following disclosure typically references a ‘UE’ in the following figures, any like user device (e.g., mobile terminal, mobile device, etc.) can be utilized without departing from the scope of the disclosed subject matter.

[0037] A first aspect of the disclosed subject matter pertains to the associating (e.g., mapping, linking, binding, etc.) of human identifiers (IDs) with a mobile device user subscription (e.g., a MNO SIM) and the generation of new UE profiles. As previously indicated, the present disclosure proposes a mechanism to associate a UE profile with a user subscription in at least two ways. In some embodiments, the association is conducted through PDU session establishment signaling. For example, during PDU session establishment, and if required by the UE policies stored in the PCF, an indication can be sent to the UE (e.g., by the PCF) to specify the need for human ID authentication.

[0038] In a second aspect, an application from the MNO may be installed on the user device (i.e., UE device) and configured to obtain policies related with the human ID from a business support system (BSS) node (as opposed to using the PDU session establishment signaling).

[0039] For creation of a UE profile and / or its connection to a human ID, a verification step may be included, in which the person to which the UE profile is associated is verified. This can for example be done by another authorized person by checking an ID card, passport or some other verified identification of the person associated with the user profile.

[0040] Such verification step may be conducted in presence, e.g. at a shop or office, or in an online process in which the person is requested to show themselves by video and present their ID card, passport or some other verified identification. Such procedures are generally known e.g. as the German “postident” procedure. Alternatively, electronic ID functions, e.g. as available with modern ID cards, can be used.

[0041] Once the verification has been completed, the MNO can generate a token, cryptographic key or the like, e.g. based to some of the information provided during the register process or based on biometrical data, like fingerprint or faceprint. In the latter case, this datashould also be requested during the subscription registration. This token, key or the like can then directly or in a later step be used for creation of a UE profile for this person, then verifying the identity of the person for which the profile is to be created.

[0042] As an example, when someone buys a subscription, he or she may register himself / herself and his / her child. When inserting or activating the SIM or e-SIM, the device will ask for which allowed Human ID or IDs a device profile shall be generated. Then the person may select the respective Human ID(s), e.g. those of him / herself and of the child, whereupon the device will ask for the same information previously used to generate the respective cryptographic key(s) (e.g. fingerprint), or will request to input the token, key or the like. Then the MNO or the app provided by the MNO may check that the provided key or token matches the stored one and will allow the human to create the device profile(s). It is also conceivable that an (particularly online) verification procedure as described above is directly performed instead of inputting a key or token referring to an earlier verification process.

[0043] Apparently, this process of verification and association of a Human ID with a subscription can be performed for an arbitrary number of persons, be it only one or any other number.

[0044] Thereby, a method for associating a mobile network subscription with a human identity based on a verification of the human identity is provided. Therein, first verification information is created and stored by a server. Based on second verification information provided by a subscriber of the mobile network subscription matching the stored first verification information, the mobile network subscription is associated with the human identity.

[0045] The verification of the human identity may be based on biometric verification

[0046] The method may further comprise generating a cryptographic key at a network node based on the information provided during the identity verification, generating a cryptographic key at a terminal device based on the information requested by the network node and sending the cryptographic key generated at the terminal device to the network node for verification. Such verification may be accomplished through hash verification or public-private key verification.

[0047] Instead of the cryptographic key the device may send raw data representing the verification information, whereupon the network node may calculate a key.

[0048] The network node may then send to the terminal device an indication that the authentication is correct, allowing the creation of a profile.

[0049] Figure 2 is an example signaling diagram for generating a user device profile, i.e., a UE profile, associated with a human identifier obtained via PDU session establishment signaling according to some embodiments. Notably, Figure 2 depicts signaling messages communicated by a user device 220 (e.g., a UE) and / or OS 221, an AMF 222, a SMF 223, a PCF 224, and a UDM / UDR 225.

[0050] For example, in operation 201, the operating system of the UE (i.e., UE OS 221) is configured to unlock a new SIM card in the UE device. Upon unlocking the new SIM card, the UE OS 221 triggers a UE Requested PDU Session Establishment. Note that only the impacted signaling of the relevant PDU session Establishment procedure is indicated in the flow diagram of Figure 2.

[0051] In Figure 2, a PDU session establishment request message 202 is sent by the user device 220 (e.g., UE) to SMF 223. In particular, as part of the PDU Session Establishment, the SMF 223 is configured to obtain the policies for the UE. The SMF may execute this task by sending a SM policy control Get request message 203 (e.g., a Npcf_SMPolicyControl_Get message) to the PCF 224 that includes and / or indicates the SUPI associated with the UE in request message 203. In some embodiments, message 203 may be referred to as a session management policy control message.

[0052] After receiving request message 203, the PCF 224 generates and directs a human identifier request message 204 (e.g., a Npcf_SMPolicyControl_Get message) to UE OS 221 via SMF 223. Notably, the request message 204 includes a first information element (IE) that indicates that the UE shall identify the subscriber user via a human ID, and a second information element that includes a list of permissible human IDs that are allowed for the user’s MNO subscription (e.g., obtained from a ‘Know Your Customer’ (KYC) process).

[0053] Upon initially receiving human request message 204, the SMF 223 is configured to encapsulate the first and second IES in a non-access stratum (NAS) message 205 (e.g., a NIN2Message transfer) and forwards the message 205 to the user device 220 (and / or OS 221) through the AMF 222. In some embodiments, the NAS message 205 may also be referred to as a human identifier request message.

[0054] After receiving the NAS message containing the encapsulated first and second IEs, the user device 220 (and / or OS 221) triggers a profile generation operation for a human ID (see block 206). In operation 207, the operating system of user device 220 (and / or OS 221) generates a new UE profile. For example, for the creation of the UE profile, the user device 220 (and / or OS 221) may be configured to present a query to the human user to selected and / or provide his / her human ID. If the selected human ID that is provided to user device 220 (and / orOS 221) matches one of the human IDs received from the NAS message 205 (e.g., one human ID included in the list of allowed human IDs), then the operating system of the user device 220 (and / or OS 221) may be configured to create a new UE profile for the UE user.

[0055] In block 208, a human ID binding link and / or association is established. For example, the operating system of the UE may be configured to associate (e.g., link, bind, map, etc.) the new UE profile to the selected human ID. In some embodiments, the association may be protected and / or secured by the operating system of the user device 220 (and / or OS 221) via an applied security measure (e.g., such as a password, biometric pattern, etc.).

[0056] In the context of this step 208, i.e. before or during step 208, a verification of the person to which the human ID belongs, may be performed as described above. E.g, a verification based on an ID card or the like may be conducted, or a token, key or the like that has been previously created as described may be input.

[0057] After the UE profile creation, the user device 220 (and / or OS 221) sends a NAS message 209 (e.g., NIN2MessageTransfer message) to the SMF 223 through the AMF 222. Notably, the message 209 includes information elements comprising i) the registered human ID and ii) the associated / linked UE profile. In some embodiments, NAS message 209 may also include binding information that links the UE profile and the human ID.

[0058] In some embodiments, the SMF 223 is configured to update the policies for the user device 220 (and / or OS 221) stored in the PCF 224. For example, SMF 223 may accomplish this task by sending a SM Policy Control Update message 210 (e.g., a Npcf SMPolicyControl update message) that includes the SUPI, the registered human ID, and the associated UE profile.

[0059] In some embodiments, the PCF 224 may also be configured to provide and store this binding information in a UDM and / or UDR 225. For example, the same SUPI, the registered human ID, and the associated UE profile information received by the PCF 224 may subsequently be stored by the PCF 224 in the UDM and / or UDR 225.

[0060] In case a verification of the person to which the human ID belongs is to be performed, the respective information, like key or token, may be transmitted in any of the messages 209, 210 and / or 211, whereupon it can be checked by SMF 223, PCF, 224 or UDM / UDR 225. In this case, an association of the UE profile with the human ID may only be accepted, i.e. registered and / or stored, if the check is positive, e.g. the key or token matches with the previously determined one.

[0061] From this point forward, the user device 220 (and / or OS 221) and the nodes of the 5G core network may be configured to share and communicate the UE profile (i.e., instead ofthe human ID) in future signaling messages to avoid exposing sensitive subscriber user information.

[0062] Figure 3 is a block diagram of user device profiles (i.e., UE profiles) associated with human identifiers on a user device (e.g., UE) according to some embodiments. Notably, Figure 3 illustrates a UE 300 that includes an operating system (OS) 302, which in turn contains and / or stores a plurality of local OS profiles, e.g., OS profile 311 and OS profile 312. Notably, profile 311 (e.g., “Profile 1”) contains an MNO profile aggregation 321 that includes at least three data elements. For example, the three data elements contained in MNO profile aggregation 321 comprise i) a “SIM ID 1” (corresponding to the SUPI), ii) a first human ID “Human IDl” that corresponds to a first person / user (e.g., the primary user of the UE), and iii) an associated “UE Profile 1” that includes information on policies to be applied to Human IDl, e.g. quality of service (QoS) policies and disabled parental control policies for linked Human IDl. Likewise, profile 312 (e.g., “Profile 2”) contains an MNO profile aggregation 322 that similarly includes three data elements, i.e., “SIM ID 1” (i.e., corresponding to the same SUPI as Profile 1), a second human ID “Human ID2” corresponding to a second person / user (e.g., the primary user’s child who occasionally uses the UE), and a linked a “UE Profile 2” that includes information on policies to be applied to Human ID2, e.g. quality of service (QoS) policies and enabled parental control policies. In some embodiments, each of OS profiles 311- 312 further includes additional information (not shown), such as one or more scanned fingerprints and the UE OS settings, e.g., a list of apps to be displayed in UE screen.

[0063] Figure 4 is an example signaling diagram for generating a user device profile (e.g., a UE profile) associated with a human identifier using a MNO application provisioned on the user device according to some embodiments. Notably, Figure 4 depicts signaling messages communicated i) within a user device, e.g., UE 420 and more specifically its operating system 421 and a local MNO application (“App”) 422, and between UE 420 and a business support system (BSS) 423 (e.g., a host system server or node that supports a user portal for the BSS entity).

[0064] As a pre-requisite, a device user shall associate his / her human ID to his / her MNO subscription. Per KYC, this is already required to obtain an MNO subscription (SIM card) in most countries.

[0065] For example, in operation 401, the operating system of the UE 420 (i.e., UE OS 421) is configured to unlock a new SIM card in the UE device 420. Upon unlocking the new SIM card, the UE OS 421 is configured to send a request message 402 to obtain the policies of the UE’s MNO subscription.

[0066] In some embodiments, as depicted block 403, the UE policies may have been previously provided by BSS 423 to the MNO application 422.

[0067] At block 404, the MNO application 422 may be configured to determine if a human ID is required for the user’s MNO subscription. If a human ID association is required for the subscription, the UE OS 421 may trigger a connection (e.g., send a request message 405) towards a user portal supported by BSS 423 to permit the user to login in the user account and select the human ID (from among a plurality of human IDs enrolled with the user account) that will be associated with the UE.

[0068] After receiving message 405, the user portal of BSS 423 may send a response message 406 back to the MNO application 422 that contains a randomized human ID to avoid exposing sensitive information. The BSS 423 shall store the relationship (e.g., association, linking, binding, mapping, etc.) between the randomized human ID and the real human ID previously selected by the user via the BSS portal.

[0069] The MNO application 422 may then send a UE profile request message 407 containing the randomized human ID to the UE OS 421. For example, request message 407 may instruct the UE OS 421 to create a device profile (e.g., UE profile) for the randomized human ID.

[0070] After receiving message 407, the UE OS 421 generates a new UE profile. For example, the UE OS 421 may create a device profile for the received randomized human ID (see operation 408).

[0071] Similar to what has been described above with respect to Fig. 2, in the context of step 408, i.e. before or during step 408, a verification of the person for which the device profile shall be created and to which the human ID is assigned, may be performed as described above. E.g, a verification based on an ID card or the like may be conducted, or a token, key or the like that has been previously created as described may be input.

[0072] In some embodiments, the UE OS 421 responds back to the MNO application 422 via a profile generation response message 409 to notify the MNO application 422 of the successful action (i.e., device / UE profile generation).

[0073] If a verification step is to be performed, the respective information, like key, token or the like, is transmitted together with profile generation response message 409 and can then be checked by the MNO app 422. In this case, an association of the UE profile with the human ID may only be performed if the check is positive, e.g. the key or token matches with the previously determined one.

[0074] After receiving message 409, the MNO application 422 associates (e.g., links, binds, maps, etc.) the new device profile to the randomized human ID and may protect the association with a security measure (e.g., a password, biometric pattern, etc.) as shown in operation 410.

[0075] Once the device profile has been generated and associated with the randomized human ID, the UE 420 must notify the 5G core of the active randomized human ID associated with UE 420 and / or the UE profile.

[0076] Figure 5 is a block diagram of user device profiles (i.e., UE profiles) associated with human identifiers on a user device (e.g., UE) according to some embodiments. In particular, Figure 5 illustrates a UE 500 that includes an operating system (OS) 502, which in turn contains and / or stores a plurality of local profiles, e.g., profile 511 and profile 512. The OS 502 further stores a MNO Application 515 that is configured to store MNO profile aggregations 521 and 522, which are respectively associated with profile 511 and profile 512. Notably, each of MNO profile aggregation 521 and MNO profile aggregation 522 includes at least three data elements. For example, the three data elements depicted in MNO profile aggregation 521 comprise i) a “SIM ID 1” (corresponding to the SUPI), ii) a first human ID “Human IDl” that corresponds to a first person / user (e.g., the primary user of the UE), and iii) an associated “UE Profile 1” that includes information on policies to be applied to Human IDl, e.g. quality of service (QoS) policies and disabled parental control policies for linked Human IDl. Likewise, profile 312 (e.g., “Profile 2”) contains an MNO profile aggregation 522 that similarly includes three data elements, i.e., “SIM ID 1” (i.e., corresponding to the same SUPI as Profile 1), a second human ID “Human ID2” corresponding to a second person / user (e.g., the primary user’s child who occasionally uses the UE), and a linked a “UE Profile 2” that includes information on policies to be applied to Human ID2, e.g. quality of service (QoS) policies and enabled parental control policies. In some embodiments, each of OS profiles 511- 512 further includes additional information (not shown), such as one or more scanned fingerprints and the UE OS settings, e.g., a list of apps to be displayed in UE screen.

[0077] Figure 6 is a signaling diagram depicting an example authentication service provided by an MNO according to some embodiments. Notably, Figure 6 depicts signaling messages communicated by a user device 651 (also referred to as UE 651 in this example), a web browsing device 652 (e.g., 3GGP or non-3GGP device, such as a laptop, PC, or the UE of the user), an AMF 653, an AUSF 654, a UDR 655, a UDM 656, an NEF 657, and a AF 658. Notably, Figure 6 illustrates an example scenario that permits MNOs to operate as a human identification authentication provider for internet servers to comply with government laws andregulations related to restricted content. In some embodiments where the device profile (e.g., UE profile) has been unequivocally associated with a human ID (e.g., as described in Figure 2 or 4) and the 5G core is aware of the human ID association (e.g., based on a solution agreed for the 3GPP Rell9 SID on User Identities and Authentication Architecture (FS UIA ARC)), an MNO is able to expose the information to external network providers to offer a human identification authentication service.

[0078] For example, in operation 601 of Figure 6, a web browsing device 652 such as a 3GPP device (e.g., a UE) or non-3GPP device (e.g., laptop) initiates a web browsing session to an AF 658 (e.g., a network content server) associated with a uniform resource locator (URL) domain that requires human identification authentication.

[0079] In response to the initiation of the web browsing session, the AF 658 may respond back to the device with a human identification authentication request 602. In some embodiments, the human identification authentication request may be triggered by a web page for authentication based on the user’s mobile phone subscription (e.g., a MNO subscription).

[0080] Upon receiving request 602 at web browsing device 652, a human user may select the MNO authentication method (see operation 603) by inserting his / her mobile phone number (corresponding to UE 651) in a data entry form that is displayed in the authentication web page.

[0081] In response, the AF 658 sends a human identification authentication inquiry and / or request 604 to NEF 657 (e.g., the MNO). In some embodiments, this inquiry and / or request (e.g., Nnef HumanAuthentication Request message) for the authentication of the human user operating the UE (and the device 652) may include i) the user’s mobile phone number and ii) the content category of the data requested by the user as message parameters (e.g., information elements).

[0082] The NEF 657 may then request the authentication of the human operating the user device 651 (e.g., UE). For example, NEF 657 may trigger a human identification authentication request 605 (e.g., a Nausf HumanAuthentication Request message) to the AUSF 654 that includes the mobile phone number of user device 651 and the category of the content that the web browsing device 652 is trying to access as parameters (e.g., information elements).

[0083] Afterwards, the AUSF 654 may be configured to retrieve subscriber data (SUPI) from the UDM 656 by sending a request message 606 (e.g., a Nudm_UECM_Get Request message) that includes the UE mobile phone number as parameter. The UDM 656 then queries the UDR 655 with the mobile phone number to obtain a corresponding SUPI (see messages 607 and 608), which is then subsequently provided to the AUSF 654 via response message 609.

[0084] In some embodiments, the AUSF 654 may request to authenticate the human user by using the subscription of the SUPI. For example, the AUSF 654 may send a modified human identification authentication request (e.g., aNamf HumanAuthentication Request) containing the SUPI to AMF 653.

[0085] In response, the AMF 653 may be configured to send an SMS (via NAS) to the user device 651. In some embodiments, the SMS may include the SUPI corresponding to user device 651 and a hyperlink that allow a human user to login with the active device profile that is associated with a randomized human ID.

[0086] The user device 651 may then use the provided hyperlink to login with the device profile (e.g., UE profile) For example, utilizing the hyperlink will trigger a NAS SMS that includes the randomized human ID to be sent to the AMF 653.

[0087] In some embodiments, the AMF 653 responds to the AUSF 654 with a human authentication response message 613 (e.g., aNamf HumanAuthentication Response message) that includes the randomized human ID. Upon receiving the randomized human ID, the AUSF 654 queries the UDM 656 to retrieve the human ID subscription data. In some embodiments, the AUSF 654 sends a UECM Get Request message 614 (e.g., aNudm_Read Request message) that includes the randomized human ID and SUPI as parameters. The UDM 656 provides the randomized human ID and SUPI to UDR 655 (via request 615) to request the user’s subscription data. The UDM 656 subsequently receives a response message 616 containing the subscription data, which indicates the content categories the user is allowed to access. The UDM 656 then provides the content categories allowed for the human ID to the AUSF 654 via a response message 617 (e.g., Nudm_UECM_Get Response message).

[0088] In some embodiments, the AUSF 654 responds (i.e., in response to original request 605) to the NEF 657 by sending a human identification authentication response message 618 (e.g., aNausf HumanAuthentication Response message). Response message 618 may include an indication of SUCCESS or REJECT with regard to the content categories allowed (or disallowed) for the human ID.

[0089] In response to receiving message 618, the NEF 657 forwards the resolution code (e.g., SUCCESS or REJECT indication) to the AF 658 by sending a human identification authentication reply message 619 (e.g., a Nnef HumanAuthentication Response message).

[0090] Upon receiving message 619, the web server (i.e., AF 658) is configured to either allow or deny web browsing device 652 access to the restricted content based on the SUCCESS or REJECT indication and / or resolution code (see operation 620). If the device 652 is allowedaccess, the device 652 will be permitted to navigate through the restricted web content (see operation 621).

[0091] Figure 7 is a flow chart illustrating method 700 depicting exemplary operations for associating a human identifier to a user device according to one embodiment. Operations of the user device (e.g., UE, mobile device, mobile terminal, etc.) which may be implemented using the structure of the block diagram of Figure 12, will now be discussed with reference to the flow chart of Figure 7 according to some embodiments. For example, one or more modules may be stored in memory 1210 of Figure 12, and these modules may provide instructions so that when the instructions of a module are executed by respective processing circuitry 1202, the user device 1200 performs respective operations of the method 700.

[0092] In block 701, the method 700 includes receiving a human identifier request from a first network node. In some embodiments, the first network node is a PCF. In some embodiments, the human identifier request is received in response to sending a PDU session establishment request.

[0093] In block 702, the method 700 includes generating a new user device profile in response to selecting a human identifier stored on the user device.

[0094] In block 703, the method 700 includes establishing a binding link between the selected human identifier and the new user device profile. In some embodiments, the new user device profile is protected by at least one security measure. In some embodiments, the at least one security measure includes a password and / or a biometric pattern. In some embodiments, a new subscriber data record including the binding link between the selected human identifier and new user device profile is stored in a data management network node as part of a SUPI registration process. In some embodiments, the data management network node includes at least one of a UDR or a UDM.

[0095] In the context of blocks 702 and / or 703, a verification step as described above may be performed.

[0096] In block 704, the method 700 includes sending the human identifier and the new user device profile to the first network node.

[0097] Figure 8 is a flow chart illustrating method 800 depicting exemplary operations for associating a human identifier to a user device by a first network node according to one embodiment. Operations of the first network node (e.g., a PCF) which may be implemented using the structure of the block diagram of Figure 13, will now be discussed with reference to the flow chart of Figure 8 according to some embodiments. For example, one or more modules may be stored in memory 1304 of Figure 13, and these modules may provideinstructions so that when the instructions of a module are executed by respective processing circuitry 1302, the first network node 1300 performs respective operations of the method 800.

[0098] In block 801, the method 800 includes receiving a session management policy control message corresponding to a first user device from a second network node. In some embodiments, the session management policy control message is sent by the second network node in response to the second network node receiving a PDU session establishment request from the user device. In some embodiments, the second network node is a session management function (SMF). In some embodiments, the first network node is a policy control function (PCF).

[0099] In block 802, the method 800 includes sending a human identifier request message to the first user device via the second network node in response to determining a human identification authentication for the first user device is required. In some embodiments, the human identifier request includes a list of human identifiers allowed for a mobile network operator (MNO) subscription associated with the first user device. In some embodiments, each of the list of human identifiers and a human identifier requirement is included in a separate information element included in the human identifier request message.

[0100] In block 803, the method 800 includes receiving a human identifier and associated user device profile from the first user device in response to the human identifier request.

[0101] In the context of blocks 802 and / or 803, a verification step as described above may be performed.

[0102] Figure 9 is a flow chart illustrating method 900 depicting exemplary operations for performing human identification authentication by a first network node according to one embodiment. Operations of the first network node (e.g., an NEF) which may be implemented using the structure of the block diagram of Figure 13, will now be discussed with reference to the flow chart of Figure 9 according to some embodiments. For example, one or more modules may be stored in memory 1304 of Figure 13, and these modules may provide instructions so that when the instructions of a module are executed by respective processing circuitry 1302, the first network node 1300 performs respective operations of the method 800. In some embodiments, the first network node is a network exposure function (NEF).

[0103] In block 901, the method 900 includes receiving a human identification authentication inquiry from a first content host, wherein the human identification authentication inquiry includes a subscriber phone number and a requested content category parameter corresponding to a subscriber user device. In some embodiments, the first contenthost is an application server that hosts restricted content that is designated as requiring human identification authentication for access.

[0104] In block 902, the method 900 includes sending a human identification authentication request to a first authentication network node wherein the human identification authentication request includes the subscriber phone number and requested content category indicator corresponding to the subscriber user device. In some embodiments, the first authentication network node is a authentication server function (AUSF). In some embodiments, the human identification authentication inquiry is received from the first content host in response to the first content host receiving a web browsing query from a user device associated with the human identifier.

[0105] In block 903, the method 900 includes receiving, from the first authentication network node, a human identification authentication response that includes an indication of a successful authentication or a rejected authentication of a human identifier with respect to the requested content category parameter, wherein the human identifier corresponds to the subscriber phone number. In some embodiments, the human identifier is a random human identifier originally selected by the subscriber user device corresponding to the subscriber phone number.

[0106] In block 904, the method 900 includes sending, to the first content host, a human identification authentication reply message that includes the indication of the successful authentication or the rejected authentication.

[0107] Figure 10 is a flow chart illustrating method 1000 depicting exemplary operations for performing human identification authentication by a first authentication network node according to one embodiment. Operations of the first network node (e.g., a AUSF) which may be implemented using the structure of the block diagram of Figure 13, will now be discussed with reference to the flow chart of Figure 10 according to some embodiments. For example, one or more modules may be stored in memory 1304 of Figure 13, and these modules may provide instructions so that when the instructions of a module are executed by respective processing circuitry 1302, the first authentication network node 1300 performs respective operations of the method 1000. In some embodiments, the first authentication network node is an AUSF.

[0108] In block 1001, the method 1000 includes receiving a human identification authentication request from a first network node, wherein the human identification authentication request includes a subscriber phone number and requested content categoryparameter corresponding to a subscriber user device. In some embodiments, the first network node is a NEF.

[0109] In block 1002, the method 1000 includes obtaining a subscription permanent identifier, SUPI, corresponding to the subscriber phone number.

[0110] In block 1003, the method 1000 includes sending, to a first mobility network node, a modified human identification authentication request containing the SUPI. In some embodiments, the first mobility network node is an access and mobility function (AMF). [OHl] In block 1004, the method 1000 includes receiving, from the first mobility network node, a human identification authentication response that includes a human identifier associated to the SUPI.

[0112] In block 1005, the method 1000 includes sending, to the first network node, a modified human identification authentication response that includes an indication of a successful authentication or a rejected authentication of the human identifier with respect to the requested content category parameter. In some embodiments, the indication of the successful authentication or the rejected authentication is obtained by the first authentication network node from a first data management network node via a query containing the SUPI and the human identifier. In some embodiments, the first data management network node includes at least one of UDR or UDM.

[0113] Figure 11 shows an example of a communication system 1100 in accordance with some embodiments. In the example, the communication system 1100 includes a telecommunication network 1102 that includes an access network 1104, such as a radio access network (RAN), and a core network 1106, which includes one or more core network nodes 1108. The access network 1104 includes one or more access network nodes, such as network nodes 1110a and 1110b (one or more of which may be generally referred to as network nodes 1110), or any other similar 3rdGeneration Partnership Project (3GPP) access nodes or non- 3 GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 1102 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network 1102 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement oneor more functionalities of any node in the telecommunication network 1102, including one or more network nodes 1110 and / or core network nodes 1108.

[0114] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O- CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the 0-RAN Alliance or comparable technologies. The network nodes 1110 facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs 1112a, 1112b, 1112c, and 1112d (one or more of which may be generally referred to as UEs 1112) to the core network 1106 over one or more wireless connections.

[0115] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 1100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 1100 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0116] The UEs 1112 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 1110 and other communication devices. Similarly, the network nodes 1110 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 1112 and / or with other network nodes or equipment in the telecommunication network 1102 to enable and / or provide network access, such as wireless network access, and / or toperform other functions, such as administration in the telecommunication network 1102. Particularly UEs 1112 may correspond to the UE or user device described above on which one or more user profiles are created.

[0117] In the depicted example, the core network 1106 connects the network nodes 1110 to one or more hosts, such as host function 1116. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 1106 includes one more core network nodes (e.g., core network node 1108) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 1108. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF). Example core network nodes also include AMF, SMF, PCF and UDM / UDR as described above.

[0118] The host function 1116 may be under the ownership or control of a service provider other than an operator or provider of the access network 1104 and / or the telecommunication network 1102, and may be operated by the service provider or on behalf of the service provider. The host function 1116 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server. Host function 1116 may correspond to BSS and or AF as described above, and / or to any entity providing or requesting verification / authorization of a human ID as described above.

[0119] As a whole, the communication system 1100 of Figure 11 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / orother suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0120] In some examples, the telecommunication network 1102 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network 1102 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 1102. For example, the telecommunications network 1102 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0121] In some examples, the UEs 1112 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 1104 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 1104. Additionally, a UE may be configured for operating in single- or multi-RAT or multi -standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN- DC).

[0122] In the example, the hub 1114 communicates with the access network 1104 to facilitate indirect communication between one or more UEs (e.g., UE 1112c and / or 1112d) and network nodes (e.g., network node 1110b). In some examples, the hub 1114 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 1114 may be a broadband router enabling access to the core network 1106 for the UEs. As another example, the hub 1114 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 1110, or by executable code, script, process, or other instructions in the hub 1114. As another example, the hub 1114 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 1114 may be a content source. For example, for a UE that is a VR headset, display,loudspeaker or other media delivery device, the hub 1114 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 1114 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 1114 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0123] Figure 12 shows a user device 1200, e.g., a UE, in accordance with some embodiments, e.g. corresponding to a UE or user device as described above. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop -embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0124] The user device 1200 includes processing circuitry 1202 that is operatively coupled via a bus 1204 to an input / output interface 1206, a power source 1208, a memory 1210, a communication interface 1212, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 12. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0125] The processing circuitry 1202 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 1210. The processing circuitry 1202 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general -purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry 1202 may include multiple central processing units (CPUs).

[0126] In the example, the input / output interface 1206 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the user device 1200. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0127] In some embodiments, the power source 1208 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source 1208 may further include power circuitry for delivering power from the power source 1208 itself, and / or an external power source, to the various parts of the user device 1200 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source 1208. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 1208 to make the power suitable for the respective components of the user device 1200 to which power is supplied.

[0128] The memory 1210 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 1210 includes one or more application programs 1214, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 1216. The memory 1210 may store, for use by the user device 1200, any of a variety of various operating systems or combinations of operating systems.

[0129] The memory 1210 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, externalhard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD- DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory 1210 may allow the user device 1200 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 1210, which may be or comprise a device-readable storage medium.

[0130] The processing circuitry 1202 may be configured to communicate with an access network or other network using the communication interface 1212. The communication interface 1212 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 1222. The communication interface 1212 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 1218 and / or a receiver 1220 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter 1218 and receiver 1220 may be coupled to one or more antennas (e.g., antenna 1222) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0131] In the illustrated embodiment, communication functions of the communication interface 1212 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking(SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0132] Figure 13 shows a network node 1300 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), 0-RAN nodes or components of an 0-RAN node (e.g, O-RU, O-DU, O-CU).

[0133] The network node 1300 includes a processing circuitry 1302, a memory 1304, a communication interface 1306, and a power source 1308. The network node 1300 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 1300 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 1300 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 1304 for different RATs) and some components may be reused (e.g., a same antenna 1310 may be shared by different RATs). The network node 1300 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 1300, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 1300.

[0134] The processing circuitry 1302 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 1300 components, such as the memory 1304, to provide network node 1300 functionality.

[0135] In some embodiments, the processing circuitry 1302 includes a system on a chip (SOC). In some embodiments, the processing circuitry 1302 includes one or more of radio frequency (RF) transceiver circuitry 1312 and baseband processing circuitry 1314. In some embodiments, the radio frequency (RF) transceiver circuitry 1312 and the baseband processing circuitry 1314 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 1312 and baseband processing circuitry 1314 may be on the same chip or set of chips, boards, or units.

[0136] The memory 1304 may comprise any form of volatile or non-volatile computer- readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computerexecutable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 1302. The memory 1304 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 1302 and utilized by the network node 1300. The memory 1304 may be used to store any calculations made by the processing circuitry 1302 and / or any data received via the communication interface 1306. In some embodiments, the processing circuitry 1302 and memory 1304 is integrated.

[0137] The communication interface 1306 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 1306 comprises port(s) / terminal(s) 1316 to send and receive data, for example to and from a network over a wired connection. The communication interface 1306 also includes radio front-end circuitry 1318 that may be coupled to, or in certain embodiments a part of, the antenna 1310. Radio front-end circuitry 1318 comprises filters 1320 and amplifiers 1322. The radio front-end circuitry 1318 may be connected to an antenna 1310 and processing circuitry 1302. The radio front-end circuitry may be configured to condition signals communicated between antenna 1310 and processing circuitry 1302. The radio front-end circuitry 1318 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 1318 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 1320 and / or amplifiers 1322. The radio signal may then be transmitted via the antenna1310. Similarly, when receiving data, the antenna 1310 may collect radio signals which are then converted into digital data by the radio front-end circuitry 1318. The digital data may be passed to the processing circuitry 1302. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0138] The antenna 1310, communication interface 1306, and / or the processing circuitry 1302 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 1310, the communication interface 1306, and / or the processing circuitry 1302 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0139] The power source 1308 provides power to the various components of network node 1300 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 1308 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 1300 with power for performing the functionality described herein. For example, the network node 1300 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 1308. As a further example, the power source 1308 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0140] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxeslocated within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0141] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

Claims

CLAIMSWhat is claimed is:

1. A method performed by a user device (220) for associating a human identifier to a user device profile, the method comprising: receiving (701) a human identifier request from a first network node (224); generating (702) a new user device profile in response to selecting a human identifier stored on the user device; establishing (703) a binding link between the selected human identifier and the new user device profile; and sending (704) the human identifier and the new user device profile to the first network node.

2. The method of claim 1 wherein the first network node is a policy control function, PCF (224).

3. The method of any one of claims 1-2 wherein the human identifier request is received in response to sending a protocol data unit, PDU, session establishment request.

4. The method of any one of claims 1-3 wherein the new user device profile is protected by at least one security measure.

5. The method of claim 4 wherein the at least one security measure includes a password and / or a biometric pattern.

6. The method of any one of claims 1-5 wherein a new subscriber data record including the binding link between the selected human identifier and new user device profile is stored in a data management network node as part of a subscription permanent identifier, SUPI, registration process.

7. The method of any of claims 1-6, further comprising sending verification information related to the human identifier to the first network node.

8. The method of any one of claims 1-7 wherein the data management network node includes at least one of a unified data repository, UDR, or a unified data manager, UDM.

9. A user device (220, 1200) comprising: processing circuitry (1202); and at least one memory (1210) storing instructions executable by the processing circuitry to perform operations to: receive (701) a human identifier request from a first network node (224); generate (702) a new user device profile in response to selecting a human identifier stored on the user device; establish (703) a binding link between the selected human identifier and the new user device profile; and send (704) the human identifier and the new user device profile to the first network node.

10. The user device of claim 9, wherein the at least one memory stores further instructions executable by the processing circuitry to perform further operations comprising operations of any one of claims 2 to 8.

11. A computer program product comprising a non-transitory computer readable medium storing instructions executable by processing circuitry (1202) of a user device (1200), the instructions executed by the processing circuitry to perform operations comprising: receiving (701) a human identifier request from a first network node (224); generating (702) a new user device profile in response to selecting a human identifier stored on the user device; establishing (703) a binding link between the selected human identifier and the new user device profile; and sending (704) the human identifier and the new user device profile to the first network node.

12. The computer program product of claim 10, wherein the non-transitory computer readable medium storing further instructions executable by the processing circuitry of the user device, the further instructions executed by the processing circuitry to perform further operations comprising operations of any one of claims 2 to 8.

13. A method performed by a first network node (224, 1400) for associating a human identifier to a user device profile, the method comprising: receiving (801) a session management policy control message corresponding to a first user device (220) from a second network node (223); sending (802) a human identifier request to the first user device via the second network node in response to determining a human identification authentication for the first user device is required; and receiving (803) a human identifier and associated user device profile from the first user device in response to the human identifier request.

14. The method of claim 13 wherein the session management policy control message is sent by the second network node in response to the second network node receiving a protocol data unit, PDU, session establishment request from the first user device.

15. The method of any one of claims 13-14 wherein the second network node is a session management function, SMF (223).

16. The method of any one of claims 13-15 wherein the first network node is a policy control function, PCF (224).

17. The method of any one of claims 13-16 wherein the human identifier request includes a list of human identifiers allowed for a mobile network operator, MNO, subscription associated with the first user device.

18. The method of claim 17 wherein each of the list of human identifiers and a human identifier requirement is included in a separate information element included in the human identifier request message.

19. The method of any of claims 13-18, further comprising receiving verification information related to the human identifier from the user device; associating the human identifier with the user device profile based on the received verification information matching with stored verification information.

20. A first network node (224, 1400) comprising: processing circuitry (1402); and at least one memory (1412) storing instructions executable by the processing circuitry to perform operations to: receive (801) a session management policy control message corresponding to a first user device (220) from a second network node (223); send (802) a human identifier request message to the first user device via the second network node in response to determining a human identification authentication for the first user device is required; and receive (803) a human identifier and associated user device profile from the first user device in response to the human identifier request message.

21. The first network node of claim 20, wherein the at least one memory stores further instructions executable by the processing circuitry to perform further operations comprising operations of any one of claims 14 to 19.

22. A computer program product comprising a non-transitory computer readable medium storing instructions executable by processing circuitry (1402) of a first network node (1400), the instructions executed by the processing circuitry to perform operations comprising: receiving (801) a session management policy control message corresponding to a first user device (220) from a second network node (223); sending (802) a human identifier request message to the first user device via the second network node in response to determining a human identification authentication for the first user device is required; and receiving (803) a human identifier and associated user device profile from the first user device in response to the human identifier request message.

23. The computer program product of claim 20, wherein the non-transitory computer readable medium storing further instructions executable by the processing circuitry of the first network node, the further instructions executed by the processing circuitry to perform further operations comprising operations of any one of claims 14 to 19.

24. A method performed by a first network node (657, 1400) for performing human identification authentication, the method comprising: receiving (901) a human identification authentication inquiry from a first content host (658), wherein the human identification authentication inquiry includes a subscriber phone number and a requested content category parameter corresponding to a subscriber user device (651); sending (902) a human identification authentication request to a first authentication network node (654) wherein the human identification authentication request includes the subscriber phone number and requested content category indicator corresponding to the subscriber user device; receiving (903), from the first authentication network node, a human identification authentication response that includes an indication of a successful authentication or a rejected authentication of a human identifier with respect to the requested content category parameter, wherein the human identifier corresponds to the subscriber phone number; and sending (904), to the first content host, a human identification authentication reply message that includes the indication of the successful authentication or the rejected authentication.

25. The method of claim 24 wherein the first network node is a network exposure function, NEF (657).

26. The method of any one of claims 24-25 wherein the first authentication network node is a authentication server function, AUSF (654).

27. The method of any one of claims 24-26 wherein the human identification authentication request is received from the first content host in response to the first content host receiving a web browsing query from a web browsing device (652) associated with the human identifier.

28. The method of any one of claims 24-27 wherein the first content host is an application server that hosts restricted content that is designated as requiring human identification authentication for access.

29. The method of any one of claims 24-28 wherein the human identifier is a random human identifier originally selected by the subscriber user device corresponding to the subscriber phone number.

30. A first network node (657, 1400) comprising: processing circuitry (1402); and at least one memory (1412) storing instructions executable by the processing circuitry to perform operations to: receive (901) a human identification authentication inquiry from a first content host (658), wherein the human identification authentication inquiry includes a subscriber phone number and a requested content category parameter corresponding to a subscriber user device (651); send (902) a human identification authentication request to a first authentication network node (654) wherein the human identification authentication request includes the subscriber phone number and requested content category indicator corresponding to the subscriber user device; receive (903), from the first authentication network node, a human identification authentication response that includes an indication of a successful authentication or a rejected authentication of a human identifier with respect to the requested content category parameter, wherein the human identifier corresponds to the subscriber phone number; and send (904), to the first content host, a human identification authentication reply message that includes the indication of the successful authentication or the rejected authentication.

31. The first network node of claim 30, wherein the at least one memory stores further instructions executable by the processing circuitry to perform further operations comprising operations of any one of claims 25 to 29.

32. A computer program product comprising a non-transitory computer readable medium storing instructions executable by processing circuitry (1402) of a first network node (657, 1400), the instructions executed by the processing circuitry to perform operations comprising: receiving (901) a human identification authentication inquiry from a first content host (658), wherein the human identification authentication inquiry includes a subscriber phone number and a requested content category parameter corresponding to a subscriber user device(651); sending (902) a human identification authentication request to a first authentication network node (654) wherein the human identification authentication request includes the subscriber phone number and requested content category indicator corresponding to the subscriber user device; receiving (903), from the first authentication network node, a human identification authentication response that includes an indication of a successful authentication or a rejected authentication of a human identifier with respect to the requested content category parameter, wherein the human identifier corresponds to the subscriber phone number; and sending (904), to the first content host, a human identification authentication reply message that includes the indication of the successful authentication or the rejected authentication.

33. The computer program product of claim 32, wherein the non-transitory computer readable medium storing further instructions executable by the processing circuitry of the first network node, the further instructions executed by the processing circuitry to perform further operations comprising operations of any one of claims 25 to 29.

34. A method performed by a first authentication network node (654, 1400) for authenticating a human identifier, the method comprising: receiving (1001) a human identification authentication request from a first network node (657), wherein the human identification authentication request includes a subscriber phone number and requested content category parameter corresponding to a subscriber user device (651); obtaining (1002) a subscription permanent identifier, SUPI, corresponding to the subscriber phone number; sending (1003), to a first mobility network node, a modified human identification authentication request containing the SUPI; receiving (1004), from the first mobility network node (653), a human identification authentication response that includes a human identifier associated to the SUPI; and sending (1005), to the first network node, a modified human identification authentication response that includes an indication of a successful authentication or a rejected authentication of the human identifier with respect to the requested content category parameter.

35. The method of claim 34 wherein the first network node is a network exposure function, NEF (657).

36. The method of any one of claims 34-35 wherein the first mobility network node is an access and mobility function, AMF (653).

37. The method of any one of claims 34-36 wherein the first authentication network node is an authentication server function, AUSF (654).

38. The method of any one of claims 34-37 wherein the indication of the successful authentication or the rejected authentication is obtained by the first authentication network node from a first data management network node via a query containing the SUPI and the human identifier.

39. The method of claim 38 wherein the first data management network node includes at least one of unified data repository, UDR (655), or a unified data manager, UDM (656).

40. A first authentication network node (654, 1400) comprising: processing circuitry (1402); and at least one memory (1412) storing instructions executable by the processing circuitry to perform operations to: receive (1001) a human identification authentication request from a first network node (657), wherein the human identification authentication request includes a subscriber phone number and requested content category parameter corresponding to a subscriber user device (651); obtain (1002) a subscription permanent identifier, SUPI, corresponding to the subscriber phone number; send (1003), to a first mobility network node, a modified human identification authentication request containing the SUPI; receive (1004), from the first mobility network node (653), a human identification authentication response that includes a human identifier associated to the SUPI; and send (1005), to the first network node, a modified human identification authentication response that includes an indication of a successful authentication or a rejected authentication of the human identifier with respect to the requested content category parameter.

41. The first authentication network node of claim 40, wherein the at least one memory stores further instructions executable by the processing circuitry to perform further operations comprising operations of any one of claims 35 to 39.

42. A computer program product comprising a non-transitory computer readable medium storing instructions executable by processing circuitry of a first authentication network node, the instructions executed by the processing circuitry to perform operations comprising: receiving (1001) a human identification authentication request from a first network node (657), wherein the human identification authentication request includes a subscriber phone number and requested content category parameter corresponding to a subscriber user device (651); obtaining (1002) a subscription permanent identifier, SUPI, corresponding to the subscriber phone number; sending (1003), to a first mobility network node, a modified human identification authentication request containing the SUPI; receiving (1004), from the first mobility network node (653), a human identification authentication response that includes a human identifier associated to the SUPI; and sending (1005), to the first network node, a modified human identification authentication response that includes an indication of a successful authentication or a rejected authentication of the human identifier with respect to the requested content category parameter.

43. The computer program product of claim 42, wherein the non-transitory computer readable medium storing further instructions executable by the processing circuitry of the first authentication network node, the further instructions executed by the processing circuitry to perform further operations comprising operations of any one of claims 35 to 39.

Citation Information

Patent Citations

  • Performing service delivery for multi-user mobile terminals cross-reference to related application

    US20220264503A1

  • Method and device for activating 5g user

    US20220338000A1

  • Content Filtering Support for Protocols with Encrypted Domain Name Server

    US20240015512A1

  • Performing service delivery for multi-user mobile terminals cross-reference to related application

    WO2020247764A1

  • User equipment (UE) data anonymization

    WO2022053301A1

Cited By

  • Initating a network detach upon occurence of a device block event in a wireless communication network

    US20260025779A1