Authentication parameter alignment between network and user equipment

By determining and deriving authentication parameters based on specified sizes and algorithms, user equipment and network nodes align authentication processes, enhancing security and efficiency in communication networks.

WO2025172901A1PCT designated stage Publication Date: 2025-08-21NOKIA TECHNOLOGIES OY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/051571
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-15
Filing Date
2025-02-13
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing communication networks face challenges in aligning authentication parameters between user equipment and network nodes, leading to inefficiencies and potential security vulnerabilities.

Method used

User equipment and network nodes determine and derive authentication parameters based on specified sizes, using key derivation algorithms and combinations, to ensure accurate and secure authentication processes.

Benefits of technology

Enhances authentication security and efficiency by aligning parameters effectively, reducing vulnerabilities and improving communication integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025051571_21082025_PF_FP_ABST
    Figure IB2025051571_21082025_PF_FP_ABST
Patent Text Reader

Abstract

There is provided a user equipment comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] AUTHENTICATION PARAMETER ALIGNMENT BETWEEN NETWORK AND USER EQUIPMENT

[0002] TECHNICAL FIELD

[0003] Various example embodiments of this disclosure relate to a method, apparatus, system and computer program and in particular but not exclusively to authenticating a user equipment with a network.

[0004] BACKGROUND

[0005] A communication network can be seen as a facility that enables communications between two or more communication devices or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.

[0006] Such communication networks operate in accordance with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards provided by 3GPP are the so-called 3GPP standards for cellular technology generations, such as 3GPP standards for 4G technology and 3GPP standards for 5G technology.

[0007] SUMMARY

[0008] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure. For example, it should be appreciated that further aspects may be provided by the combination of any two or more of the various aspects described below.

[0009] According to an aspect, there is provided a user equipment comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0010] The one or more parameters may comprise the first output parameter and one or more intermediary parameters used for deriving the first output parameter.

[0011] The means may be further for: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0012] The means may be further for: receiving, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure, and determining the size of the one or more parameters may comprise determining the size of the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

[0013] Determining the size of the one or more parameters may comprise receiving, from the access and mobility management function, information indicating the size of the one or more parameters.

[0014] The means may be further for: sending, to the access and mobility management function, a requested size of the one or more parameters, wherein the information indicating the size of the one or more parameters may be based on the requested size.

[0015] The size of the one or more parameters may be selected from at least a first value or a second value.

[0016] The size of the one or more parameters may be variable between a first value and a second value. A first value may be 128 bits and the second value may be 256 bits.

[0017] The first output parameter may be an authentication response, RES*.

[0018] According to an aspect there is provided a network node comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

[0019] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0020] The authentication message may further comprise information indicating the determined size of the one or more parameters.

[0021] The means may be further for: sending, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

[0022] Determining the size of the one or more parameters may comprise: receiving, from the authentication server function, information indicating a requested size of the one or more parameters, wherein determining the size of the one or more parameters may be based on the requested size of the one or more parameters.

[0023] The size of the one or more parameters may be selected from at least a first value or a second value. The size of the one or more parameters may be variable between a first value and a second value.

[0024] The first value may be 128 bits and the second value may be 256 bits.

[0025] The second output parameter may be an expected authentication response, XRES*.

[0026] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0027] According to an aspect there is provided a user equipment comprising means for: receiving, from an access and mobility management function, information indicating a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the information indicating the size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0028] The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter.

[0029] The means may be further for: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0030] The means may be further for: receiving, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure; and deriving the one or more parameters may comprise deriving the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier. The size of the one or more parameters may be selected from at least a first value or a second value.

[0031] The size of the one or more parameters may be variable between a first value and a second value.

[0032] The first value may be 128 bits and the second value may be 256 bits.

[0033] The first output parameter may be an authentication response, RES*.

[0034] According to an aspect there is provided a network node comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter and information indicating the size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0035] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0036] The means may be further for: sending, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

[0037] The size of the one or more parameters may be selected from at least a first value or a second value.

[0038] The size of the one or more parameters may be variable between a first value and a second value. The first value may be 128 bits and the second value may be 256 bits.

[0039] The second output parameter may be an expected authentication response, XRES*.

[0040] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0041] According to an aspect there is provided a user equipment comprising means for: sending, to an access and mobility management function, a requested size of one or more parameters associated with an authentication procedure; receiving, from the access and mobility management function information indicating a size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0042] The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter.

[0043] The means may be further for: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0044] The information indicating the size of the one or more parameters may be based on the requested size of the one or more parameters.

[0045] The requested size of the one or more parameters and the size of the one or more parameters may be selected from at least a first value or a second value.

[0046] The requested size of the one or more parameters and the size of the one or more parameters may be variable between a first value and a second value. The first value may be 128 bits and the second value may be 256 bits.

[0047] The first output parameter may be an authentication response, RES*.

[0048] According to an aspect there is provided a network node comprising means for: receiving, from an authentication server function, information indicating a size of one or more parameters associated with an authentication procedure requested by a user equipment; determining a size of the one or more parameters based on the requested size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0049] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0050] The size of the one or more parameters may be selected from at least a first value or a second value.

[0051] The size of the one or more parameters may be variable between a first value and a second value.

[0052] The first value may be 128 bits and the second value may be 256 bits.

[0053] The second output parameter may be an expected authentication response, XRES*.

[0054] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0055] According to an aspect, there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0056] The one or more parameters may comprise the first output parameter and one or more intermediary parameters used for deriving the first output parameter.

[0057] The at least one processor may be configured to cause the user equipment to further: receive, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters; and derive the one or more parameters using the indicated one or more key derivation algorithms.

[0058] The at least one processor may be configured to cause the user equipment to further: receive, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure, and the at least one processor may be configured to cause the user equipment to further determine the size of the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

[0059] The at least one processor may be configured to cause the user equipment to receive, from the access and mobility management function, information indicating the size of the one or more parameters.

[0060] The at least one processor may be configured to cause the user equipment to further: send, to the access and mobility management function, a requested size of the one or more parameters, wherein the information indicating the size of the one or more parameters may be based on the requested size. The size of the one or more parameters may be selected from at least a first value or a second value.

[0061] The size of the one or more parameters may be variable between a first value and a second value.

[0062] A first value may be 128 bits and the second value may be 256 bits.

[0063] The first output parameter may be an authentication response, RES*.

[0064] According to an aspect, there is provided a network node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network node at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

[0065] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0066] The authentication message may further comprise information indicating the determined size of the one or more parameters.

[0067] The at least one processor may be configured to cause the network node to further: send, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters. The at least one processor may be configured to cause the network node to further: receive, from the authentication server function, information indicating a requested size of the one or more parameters; and determine the size of the one or more parameters based on the requested size of the one or more parameters.

[0068] The size of the one or more parameters may be selected from at least a first value or a second value.

[0069] The size of the one or more parameters may be variable between a first value and a second value.

[0070] The first value may be 128 bits and the second value may be 256 bits.

[0071] The second output parameter may be an expected authentication response, XRES*.

[0072] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0073] According to an aspect, there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: receive, from an access and mobility management function, information indicating a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the information indicating the size of the one or more parameters; and send, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0074] The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter.

[0075] The at least one processor may be configured to cause the user equipment to further: receive, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters; and derive the one or more parameters using the indicated one or more key derivation algorithms.

[0076] The at least one processor may be configured to cause the user equipment to further: receive, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure; and derive the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

[0077] The size of the one or more parameters may be selected from at least a first value or a second value.

[0078] The size of the one or more parameters may be variable between a first value and a second value.

[0079] The first value may be 128 bits and the second value may be 256 bits.

[0080] The first output parameter may be an authentication response, RES*.

[0081] According to an aspect, there is provided a network node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network node at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to an authentication server function, an authentication message comprising a second output parameter and information indicating the size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0082] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters. The at least one processor may be configured to cause the network node to further: send, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

[0083] The size of the one or more parameters may be selected from at least a first value or a second value.

[0084] The size of the one or more parameters may be variable between a first value and a second value.

[0085] The first value may be 128 bits and the second value may be 256 bits.

[0086] The second output parameter may be an expected authentication response, XRES*.

[0087] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0088] According to an aspect, there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: send, to an access and mobility management function, a requested size of one or more parameters associated with an authentication procedure; receive, from the access and mobility management function information indicating a size of the one or more parameters; derive the one or more parameters based on the determined size of the one or more parameters; and send, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0089] The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter. The at least one processor may be configured to cause the user equipment to further: receive, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters; and derive the one or more parameters using the indicated one or more key derivation algorithms.

[0090] The information indicating the size of the one or more parameters may be based on the requested size of the one or more parameters.

[0091] The requested size of the one or more parameters and the size of the one or more parameters may be selected from at least a first value or a second value.

[0092] The requested size of the one or more parameters and the size of the one or more parameters may be variable between a first value and a second value.

[0093] The first value may be 128 bits and the second value may be 256 bits.

[0094] The first output parameter may be an authentication response, RES*.

[0095] According to an aspect, there is provided a network node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network node at least to: receive, from an authentication server function, information indicating a size of one or more parameters associated with an authentication procedure requested by a user equipment; determine a size of the one or more parameters based on the requested size of the one or more parameters; derive the one or more parameters based on the determined size of the one or more parameters; and send, to the authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0096] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters. The size of the one or more parameters may be selected from at least a first value or a second value.

[0097] The size of the one or more parameters may be variable between a first value and a second value.

[0098] The first value may be 128 bits and the second value may be 256 bits.

[0099] The second output parameter may be an expected authentication response, XRES*.

[0100] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0101] According to an aspect, there is provided a method performed by a user equipment, the method comprising: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0102] The one or more parameters may comprise the first output parameter and one or more intermediary parameters used for deriving the first output parameter.

[0103] The method may comprise: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0104] The method may comprise: receiving, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure, and determining the size of the one or more parameters may comprise determining the size of the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

[0105] Determining the size of the one or more parameters may comprise receiving, from the access and mobility management function, information indicating the size of the one or more parameters.

[0106] The method may comprise: sending, to the access and mobility management function, a requested size of the one or more parameters, wherein the information indicating the size of the one or more parameters may be based on the requested size.

[0107] The size of the one or more parameters may be selected from at least a first value or a second value.

[0108] The size of the one or more parameters may be variable between a first value and a second value.

[0109] A first value may be 128 bits and the second value may be 256 bits.

[0110] The first output parameter may be an authentication response, RES*.

[0111] According to an aspect there is provided a method performed by a network node, the method comprising: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

[0112] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters. The authentication message may further comprise information indicating the determined size of the one or more parameters.

[0113] The method may comprise: sending, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

[0114] Determining the size of the one or more parameters may comprise: receiving, from the authentication server function, information indicating a requested size of the one or more parameters, wherein determining the size of the one or more parameters may be based on the requested size of the one or more parameters.

[0115] The size of the one or more parameters may be selected from at least a first value or a second value.

[0116] The size of the one or more parameters may be variable between a first value and a second value.

[0117] The first value may be 128 bits and the second value may be 256 bits.

[0118] The second output parameter may be an expected authentication response, XRES*.

[0119] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0120] According to an aspect there is provided a method performed by a user equipment, the method comprising: receiving, from an access and mobility management function, information indicating a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the information indicating the size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters. The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter.

[0121] The method may comprise: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0122] The method may comprise: receiving, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure; and deriving the one or more parameters may comprise deriving the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

[0123] The size of the one or more parameters may be selected from at least a first value or a second value.

[0124] The size of the one or more parameters may be variable between a first value and a second value.

[0125] The first value may be 128 bits and the second value may be 256 bits.

[0126] The first output parameter may be an authentication response, RES*.

[0127] According to an aspect there is provided a method performed by a network node, the method comprising: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter and information indicating the size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters. The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0128] The method may comprise: sending, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

[0129] The size of the one or more parameters may be selected from at least a first value or a second value.

[0130] The size of the one or more parameters may be variable between a first value and a second value.

[0131] The first value may be 128 bits and the second value may be 256 bits.

[0132] The second output parameter may be an expected authentication response, XRES*.

[0133] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0134] According to an aspect there is provided a method performed by a user equipment, the method comprising: sending, to an access and mobility management function, a requested size of one or more parameters associated with an authentication procedure; receiving, from the access and mobility management function information indicating a size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters. The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter.

[0135] The method may comprise: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0136] The information indicating the size of the one or more parameters may be based on the requested size of the one or more parameters.

[0137] The requested size of the one or more parameters and the size of the one or more parameters may be selected from at least a first value or a second value.

[0138] The requested size of the one or more parameters and the size of the one or more parameters may be variable between a first value and a second value.

[0139] The first value may be 128 bits and the second value may be 256 bits.

[0140] The first output parameter may be an authentication response, RES*.

[0141] According to an aspect there is provided a method performed by a network node, the method comprising: receiving, from an authentication server function, information indicating a size of one or more parameters associated with an authentication procedure requested by a user equipment; determining a size of the one or more parameters based on the requested size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0142] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0143] The size of the one or more parameters may be selected from at least a first value or a second value.

[0144] The size of the one or more parameters may be variable between a first value and a second value.

[0145] The first value may be 128 bits and the second value may be 256 bits.

[0146] The second output parameter may be an expected authentication response, XRES*.

[0147] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0148] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a user equipment, cause the user equipment to perform at least the following: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0149] The one or more parameters may comprise the first output parameter and one or more intermediary parameters used for deriving the first output parameter.

[0150] The instructions, when executed by the user equipment, may cause the user equipment to further perform: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms. The instructions, when executed by the user equipment, may cause the user equipment to further perform: receiving, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure, and determining the size of the one or more parameters may comprise determining the size of the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

[0151] Determining the size of the one or more parameters may comprise receiving, from the access and mobility management function, information indicating the size of the one or more parameters.

[0152] The instructions, when executed by the user equipment, may cause the user equipment to further perform: sending, to the access and mobility management function, a requested size of the one or more parameters, wherein the information indicating the size of the one or more parameters may be based on the requested size.

[0153] The size of the one or more parameters may be selected from at least a first value or a second value.

[0154] The size of the one or more parameters may be variable between a first value and a second value.

[0155] A first value may be 128 bits and the second value may be 256 bits.

[0156] The first output parameter may be an authentication response, RES*.

[0157] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a network node, cause the network node to perform at least the following: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

[0158] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0159] The authentication message may further comprise information indicating the determined size of the one or more parameters.

[0160] The instructions, when executed by the network node, may cause the network node to further perform: sending, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

[0161] Determining the size of the one or more parameters may comprise: receiving, from the authentication server function, information indicating a requested size of the one or more parameters, wherein determining the size of the one or more parameters may be based on the requested size of the one or more parameters.

[0162] The size of the one or more parameters may be selected from at least a first value or a second value.

[0163] The size of the one or more parameters may be variable between a first value and a second value.

[0164] The first value may be 128 bits and the second value may be 256 bits.

[0165] The second output parameter may be an expected authentication response, XRES*. The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0166] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a user equipment, cause the user equipment to perform at least the following: receiving, from an access and mobility management function, information indicating a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the information indicating the size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0167] The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter.

[0168] The instructions, when executed by the user equipment, may cause the user equipment to further perform: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0169] The instructions, when executed by the user equipment, may cause the user equipment to further perform: receiving, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of a plurality of different combinations that is to be used in the authentication procedure; and deriving the one or more parameters may comprise deriving the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

[0170] The size of the one or more parameters may be selected from at least a first value or a second value. The size of the one or more parameters may be variable between a first value and a second value.

[0171] The first value may be 128 bits and the second value may be 256 bits.

[0172] The first output parameter may be an authentication response, RES*.

[0173] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a network node, cause the network node to perform at least the following: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter and information indicating the size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0174] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0175] The instructions, when executed by the network node, may cause the network node to further perform: sending, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters may comprise an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

[0176] The size of the one or more parameters may be selected from at least a first value or a second value.

[0177] The size of the one or more parameters may be variable between a first value and a second value.

[0178] The first value may be 128 bits and the second value may be 256 bits. The second output parameter may be an expected authentication response, XRES*.

[0179] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

[0180] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a user equipment, cause the user equipment to perform at least the following: sending, to an access and mobility management function, a requested size of one or more parameters associated with an authentication procedure; receiving, from the access and mobility management function information indicating a size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0181] The one or more parameters may comprise the first output parameter and one or more intermediary parameter used for deriving the first output parameter.

[0182] The instructions, when executed by the user equipment, may cause the user equipment to further perform: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters may comprise deriving the one or more parameters using the indicated one or more key derivation algorithms.

[0183] The information indicating the size of the one or more parameters may be based on the requested size of the one or more parameters.

[0184] The requested size of the one or more parameters and the size of the one or more parameters may be selected from at least a first value or a second value.

[0185] The requested size of the one or more parameters and the size of the one or more parameters may be variable between a first value and a second value. The first value may be 128 bits and the second value may be 256 bits.

[0186] The first output parameter may be an authentication response, RES*.

[0187] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a network node, cause the network node to perform at least the following: receiving, from an authentication server function, information indicating a size of one or more parameters associated with an authentication procedure requested by a user equipment; determining a size of the one or more parameters based on the requested size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0188] The authentication message may comprise information indicating one or more key derivation algorithms to be used by a user equipment when deriving the one or more parameters, wherein the indicated one or more key derivation algorithms may correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

[0189] The size of the one or more parameters may be selected from at least a first value or a second value.

[0190] The size of the one or more parameters may be variable between a first value and a second value.

[0191] The first value may be 128 bits and the second value may be 256 bits.

[0192] The second output parameter may be an expected authentication response, XRES*.

[0193] The network node may be one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function. According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.

[0194] In the above, many different aspects have been described. As previously noted, it should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above. Other features, aspects, and elements will become apparent in view of the following.

[0195] DESCRIPTION OF FIGURES

[0196] Some example embodiments will now be described, by way of non-limiting and illustrative example only, with reference to the accompanying Figures in which:

[0197] FIG. 1 shows a representation of a 5thgeneration communication system;

[0198] FIG. 2 shows a representation of an apparatus for the communication system of FIG. 1 according to some example embodiments;

[0199] FIG. 3 shows a representation of an apparatus according to some example embodiments;

[0200] FIG.s 4a-f show methods according to some examples;

[0201] FIG. 5 shows a method according to some examples;

[0202] FIG. 6a shows an example method which the network node may use to derive the one or more parameters including the second output parameter;

[0203] FIG. 6b shows an example method which the UE may use to derive the one or more parameters including the first output parameter;

[0204] FIG.s 7 to 9 show methods according to some examples; and

[0205] FIG. 10 shows a schematic representation of an apparatus according to some examples.

[0206] DETAIEED DESCRIPTION

[0207] In the following various example embodiments are explained with reference to communication devices capable of communication with a communication system. Before explaining in detail the various example embodiments of the this disclosure, a 5thgeneration communication system (5GS), an access network and a core network (5GC) thereof, and communication devices are briefly explained with reference to FIG. 1, 2 and 3.

[0208] FIG. 1 shows a schematic representation of a 5G communication system (5GS). The 5GS may comprise a user equipment (UE) or Terminal 100, an access network such as a 5G radio access network (5G-RAN) 101 or next generation radio access network (NG-RAN), a 5G core network 102, and one or more application functions 103. An application function 103 may be deployed in the 5GS as trusted application function or may be deployed or host on one or more application servers of the data network (DN) 104. Such application functions are untrusted application functions. The 5GS connects the UE to the data network 104, the access network 101 and the 5GC 102 (e.g., a UPF of the 5GC).

[0209] The 5G-RAN 101 may comprise one or more radio access nodes, such as gNodeB (gNB). A gNB may include one or more gNodeB (GNB) distributed units connected to one or more gNodeB (GNB) centralized units.

[0210] The 5GC may comprise the following network functions: Network Slice Selection Function (NSSF); Network Exposure Function (NEF) 105; Network Repository Function (NRF); Policy Control Function (PCF); Unified Data Management (UDM) 106; Application Function (AF) 103; Authentication Server Function (AUSF) 107; an Access and Mobility Management Function (AMF) 108; Session Management Function (SMF) 109; and a user plane function (UPF) 110. FIG. 1 also shows the various interfaces (Nl, N2 etc.) that may be implemented between the various elements of the system.

[0211] FIG. 2 illustrates an example of a control apparatus 200 for controlling a function of the access network (e.g., a 5G-RAN or the NG-RAN illustrated in FIG. 1) illustrated on FIG. 1. The control apparatus 200 may comprise at least one random access memory (RAM) 21 la, at least one read only memory (ROM) 211b, at least one processor 212, 213 and a network interface

[0212] 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211b. The at least one processor 212, 213 may be configured to execute an appropriate software code

[0213] 215. Execution of the software code 215 may for example may cause the apparatus to perform operations for controlling a function of the access network. The software code 215 may be stored in the ROM 211b. The control apparatus 200 may be interconnected with another control apparatus 200 for controlling another function of the 5G-RAN or the NG-RAN. In some embodiments, each function of the 5G-RAN or the NG-RAN is deployed or hosted on a control apparatus 200. In alternative embodiments, two or more functions of the 5G-RAN or the NG- RAN may share a control apparatus.

[0214] FIG. 3 illustrates an example of a communication device 300, such as the UE illustrated in FIG. 1. The communication device 300 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of a communication device 300 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like. The communication device 300 may comprise a transceiver for transmitting and / or receiving, for example, wireless signals carrying communications, for example radio signals. The communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.

[0215] The communication device 300 may receive wireless signals (e.g., radio signals) over an air or radio interface 307 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals. In FIG. 3 transceiver is designated schematically by block 306. The transceiver 306 may comprise, for example, a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements. The antenna arrangement may be a multi-input multi output (MIMO) antenna.

[0216] The communication device 300 may be provided with at least one processor 301, at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access networks (e.g., the 5G-RAN or NG-RAN illustrated in FIG. 1) and other communication devices. The at least one processor 301 is coupled to the RAM 302b and the ROM 302a. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more operations of the communication device. The software code 308 may be stored in the ROM 302a. The processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device (e.g., a modem) can be provided on a circuit board, in chipsets, or in a system on chip. The circuit board, chipsets or system on chip is denoted by reference 304. The communication device 300 may optionally have a user interface such as keypad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of communication device.

[0217] In some networks it may be necessary for a UE to undergo an authentication and key agreement (AKA) procedure to access the services provided by the network. The AKA procedure may involve the UE and the home network of the UE (e.g., at least one of an authentication server function (AUSF), authentication credential repository (ARPF), subscriber identity deconcealing function (SIDE), or UDM of the home network) generating one or more cryptographic keys, which may include a first output key (generated by the UE) and a second output key (generated by the home network). A network node (e.g., the AUSF) may compare the first and second output keys, and if the first and second output keys match, the UE is authenticated by the network.

[0218] 3GPP TS 33.501 describes examples of known AKA procedures, which utilize 128 bit size cryptographic keys. However, recent developments, such as 3GPP TR 33.841, have considered utilizing 256 bit size cryptographic keys, which may provide enhanced security protection. However the introduction of 256 bit size cryptographic keys may introduce additional challenges to the proper functionality of the network.

[0219] In general, the impact of increasing the size of the cryptographic keys on AKA procedures needs to be considered and addressed to ensure that AKA procedures are adaptable for the increased size of the cryptographic keys. For example, if the UE and the network are not aligned in terms of the size of the cryptographic keys, then it may be the case that the AKA procedure fails due to the first and second output keys being different.

[0220] Some examples of the present disclosure may address one or more of these issues.

[0221] Reference is made to FIG.s 4a-f, which show methods according to some examples. With reference to FIG. 4a, at 400 a method comprises determining a size of one or more parameters associated with an authentication procedure. At 402 the method comprises deriving the one or more parameters based on the determined size of the one or more parameters. At 404 the method comprises sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters. The method of FIG. 4a may be performed by a UE.

[0222] With reference to FIG. 4b, at 406 a method comprises determining a size of one or more parameters associated with an authentication procedure. At 408 the method comprises deriving the one or more parameters based on the determined size of the one or more parameters. At 410 the method comprises sending, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters. The method of FIG. 4b may be performed by a network node.

[0223] With reference to FIG. 4c, at 412 a method comprises sending, to an access and mobility management function, a requested size of one or more parameters associated with an authentication procedure. At 414 the method comprises receiving, from the access and mobility management function information indicating a size of the one or more parameters. At 416 the method comprises deriving the one or more parameters based on the determined size of the one or more parameters. At 418 the method comprises sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters. The method of FIG. 4c may be performed by a UE.

[0224] With reference to FIG. 4d, at 420 a method comprises receiving, from an authentication server function, information indicating a size of one or more parameters associated with an authentication procedure requested by a user equipment. At 422 the method comprises determining a size of the one or more parameters based on the requested size of the one or more parameters. At 424 the method comprises deriving the one or more parameters based on the determined size of the one or more parameters. At 426 the method comprises sending, to the authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters. The method of FIG. 4d may be performed by a network node.

[0225] With reference to FIG. 4e, at 428 a method comprises receiving, from an access and mobility management function, information indicating a size of one or more parameters associated with an authentication procedure. At 430 the method comprises deriving the one or more parameters based on the information indicating the size of the one or more parameters. At 432 the method comprises sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters. The method of FIG. 4e may be performed by a UE.

[0226] With reference to FIG. 4f, at 434 a method comprises determining a size of one or more parameters associated with an authentication procedure. At 436 the method comprises deriving the one or more parameters based on the determined size of the one or more parameters. At 438 the method comprises sending, to an authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters. The method of FIG. 4f may be performed by a network node.

[0227] In some examples a network node (e.g., a UDM / ARPF / SIDF) may determine a size of one or more parameters associated with an authentication process. As used herein, “one or more parameters” may refer to the one or more parameters associated with the authentication process.

[0228] The network node may then determine the one or more parameters based on the determined size of the one or more parameters. The one or more parameters may comprise a second output parameter. The network node may then send, to an AUSF, an authentication message comprising the second output parameter and information indicating the size of the one or more parameters.

[0229] The AUSF may send the information indicating the size of the one or more parameters to the UE (e.g., via an AMF). In some examples the UE may receive, from the AMF, information indicating a size of the one or more parameters. The information indicating the size of the one or more parameters may for example be received in an authentication request sent from the AMF to the UE. The UE may derive the one or more parameters based on the information indicating the size of the one or more parameters. The one or more parameters may comprise a first output parameter. The UE may then send, to the AMF, an authentication message comprising the first output parameter.

[0230] The AUSF may therefore receive the first output parameter from the UE and the second output parameter from the network node. As the first output parameter and second output parameter have been derived based on the information indicating the size of the one or more parameters, the size of the first and second output parameters should be aligned. Therefore when the AUSF compares the first and second output parameters, the two parameter should match and the UE may be authorized.

[0231] In some examples the AMF may be comprised in a network serving the UE. The AUSF and network node may be comprised in a home network of the UE. The home network and network serving the UE may be the same or may be different.

[0232] In some examples the one or more parameters may comprise the first output parameter and one or more intermediary parameters used to derive the first output parameter.

[0233] In some examples the one or more parameters may comprise one or more cryptographic keys and / or one or more input parameters and / or output parameters used in the authentication process. In some examples the one or more parameters may comprise at least one of:

[0234] An authorization key (AK);

[0235] A ciphering key (CK);

[0236] An integrity key (IK);

[0237] A long-term key (K);

[0238] A message authentication code (MAC);

[0239] A random challenge (RAND);

[0240] An authentication response (RES*);

[0241] An expected authentication response (XRES*); and

[0242] A sequence number (SQN). In some examples the first output parameter may be RES* and the second output parameter may be XRES*.

[0243] In some examples the one or more parameters may comprise additional information to that listed above. For example, the one or more parameters may comprise an additional “entropy” value, which may for example be a random or pseudo-random value that may change between each authentication procedure. The additional value may add additional security to the authentication procedure as it changes each time authentication is performed, and so even if the value becomes known to a third party during one authentication procedure, the next time authentication is performed the known value is irrelevant for valid authentication.

[0244] In some examples the size of the one or more parameters may be selected from at least a first value or a second value. In some examples the size of the one or more parameters may be variable between two values. For example the size of the one or more parameters may be variable between the first value and the second value (that is to say, the size may be greater than or equal to the first value and less than or equal to the second value). In some examples the cryptographic keys may have different sizes - for example a first cryptographic key may have one size and a second cryptographic key may have a different size to the first cryptographic key. In some examples the first value may be 128 bits and the second value may be 256 bits.

[0245] In some examples the network node may determine the size of the one or more parameters based on a random selection. For example, the network node may randomly select between the first value or the second value; or may randomly select a value between the first value and the second value. By utilizing a random selection it may be possible to avoid forming a pattern in the selected size, which may make it harder for any potential hackers to predict the size, and may help avoid leakage of protected elements like SQN, etc. In some examples the network node may alternate between the first value and the second value each time a key size determination is performed. In other examples, the network node may utilize mechanisms suitable for determining the size of the one or more parameters other than those explicitly described above.

[0246] In some examples, the network node may utilize one or more key derivation functions (KDFs) when deriving the one or more parameters. The network node may send, to the AUSF, information indicating the one or more KDFs used by the network node to derive the one or more parameters. The AUSF may in turn send the information indicating the one or more KDFs to the AMF, which may send the information indicating the one or more KDFs to the UE. The UE may then determine the one or more parameters based on the information indicating the one or more KDFs. In this way, both the size of the one or more parameters and the one or more KDFs used to derive the one or more parameters may be aligned between the UE and the network node.

[0247] In some examples the network node may send, to the UE, information indicating a plurality of different combinations of sizes of the one or more parameters. The UE may store the received information. The information indicating a plurality of different combinations of sizes of the one or more parameters may be configured by the network node prior to performing an AKA procedure.

[0248] The information indicating a plurality of different combinations of sizes of the one or more parameters may for example comprise a table or list, where each row in the table or list comprises a size of each of the one or more parameters. Table 1 below illustrates one example where each row in the table represents a different combination and each column in the table indicates a size of one of the parameters in bytes (one byte = 8 bits).

[0249] Table 1 - example of different combinations of sizes of cryptographic keys

[0250] In some examples, as illustrated in Table 1, each combination may be associated with a respective identifier. When the network node determines the size of the one or more parameters, the network node may select the size of the one or more parameters corresponding to one of the combinations of sizes of the one or more parameters. The information indicating the size of the one or more parameters sent from the network node to the AUSF (and then from the AUSF ultimately to the UE) may comprise an identifier of the corresponding combination.

[0251] For example, with reference to Table 1, if the network node selected a size of the one or more parameters (in bytes) as:

[0252] AK = 12; CK = 32, IK = 32; K = 32; MAC = 32; RAND = 32; RES = 32; SQN = 12, corresponding to row three in Table 1, then the network node may send ID#3 to the AUSF to indicate the chosen size of the one or more parameters.

[0253] In some examples the UE may indicate, to the network node, a requested size of the one or more parameters. The network node may take the requested size into account when determining the size of the one or more parameters. For example, when the UE receives the information indicating a plurality of different combinations of sizes of the one or more parameters, the UE may send an indication to the network comprising an identifier requesting one of the combinations.

[0254] Reference is made to FIG. 5, which shows a method according to some examples. In the example of FIG. 5, the UE is configured with information indicating a plurality of different combinations of sizes of the one or more parameters, for example the information provided in Table 1 above.

[0255] At 500, the network node sends, to the UE, the information indicating a plurality of different combinations of sizes of the one or more parameters, for example in the form of Table 1 above.

[0256] At 502 the UE may generate an encrypted identifier of the UE. For example, the UE may generate a subscriber concealed identifier (SUCI) based on it’s subscriber permanent identifier (SUPI).

[0257] At 504 the UE sends, to the AMF of the network serving the UE, a registration request. The registration request may comprise an identifier of the UE, for example the encrypted identifier of the UE if it has been generated at 502. In some examples the registration request may comprise an identifier requesting one of the combinations. At 506, the AMF sends an authentication request to the AUSF of the home network of the UE. The authentication request may comprise the identifier of the UE (e.g., the encrypted identifier), and the identifier of one of the combinations (if received by the AMF at 504).

[0258] At 508, the AUSF sends a further authentication request to the network node. The further authentication request may for example comprise an authentication GET request. The authentication request may be for the second output parameter (e.g., XRES*). The further authentication request may comprise the identifier requesting one of the combinations (if received at 506).

[0259] At 510, the network node determines the size of the one or more parameters as described previously. For example, the network node may select one of the combinations of sizes comprised in the information sent to the UE at step 500. The selected one of the combinations may correspond to the identifier requesting one of the combinations (if received at 508).

[0260] At 512, the network node derives the one or more parameters, including the second output parameter, based on the determined size of the one or more parameters. FIG. 6a shows an example method which the network node may use to derive the one or more parameters including the second output parameter.

[0261] At 514 the network node may send, to the AUSF, an authentication message comprising the second output parameter and information indicating the size of the one or more parameters. The information indicating the size of the one or more parameters may comprise the identifier of the combination of sizes selected at step 510. The authentication message may further comprise information indicating the one or more KDFs used at step 512 to generate the second output parameter.

[0262] At 516, the AUSF may send an authentication response message to the AMF. The authentication response message may comprise the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs. At 518, the AMF may send an authentication request to the UE. The authentication request may comprise the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs.

[0263] At 520, the UE derives the one or more parameters (including the first output parameter) based on the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs. FIG. 6b shows an example method which the network node may use to derive the one or more parameters including the first output parameter.

[0264] At 522 the UE sends, to the AMF, an authentication response comprising the first output parameter.

[0265] At 524 the AMF sends an authentication request comprising the first output parameter to the AUSF.

[0266] At 526 the AUSF determines whether to authenticate the UE based on the first output parameter and the second output parameter. For example the AUSF may authenticate the UE when the first output parameter and second output parameter match.

[0267] Reference is made to FIG. 6a, which shows an example method which the network node may use to derive the one or more parameters including the second output parameter.

[0268] As shown in FIG. 6a, K, RAND, AMF and SQN may be provided as inputs into one or more cryptographic functions (fl ...f5). The size of K, RAND, AMF key (KAMF), SQN may correspond to the determined size of the one or more parameters.

[0269] The one or more cryptographic functions may generate, as output parameters, MAC, XRES, CK, IK, and AK. The output parameters may be provided as input parameters into one or more KDFs.

[0270] For example, as shown in FIG. 6a, a serving network name (SN-name), RAND, CK, IK and XRES may be provided as inputs into a first KDF to generate the expected authentication response XRES*. SN-name, CK, IK, and an authentication token (derived based on AK and SQN) may be provided as inputs into a second KDF to generate an AUSF key, KAUSF- KAUSF may be used by the AUSF in other AKA-related procedures.

[0271] Reference is made to FIG. 6b, which shows an example method which the UE may use to derive the one or more parameters including the first output parameter.

[0272] As shown in FIG. 6b, K, RAND, and the authentication token (AUTN - which may be received from the AMF) may be provided as inputs into one or more cryptographic functions (fl . . .f5). The size of K and RAND may correspond to the size of the one or more parameters received from the AMF.

[0273] The one or more cryptographic functions may generate, as output parameters, XMAC, RES, CK, and IK. The output parameters may be provided as input parameters into one or more KDFs.

[0274] For example, as shown in FIG. 6b, RAND, CK, IK and RES may be provided as inputs into a first KDF (along with the serving network name - SN-name) to generate the authentication response RES*. CK, IK, AK and SQN may be provided as inputs into a second KDF (along with the SN-name) to generate an AUSF key, KAUSF- KAUSF may be used by the UE in other AKA-related procedures, for example to derive the security anchor function (SEAF) key, KSEAF.

[0275] Reference is made to FIG. 7, which shows a method according to some examples where the network selects between a first parameter size (e.g., 128 bit) or a second parameter size (e.g., 256 bit).

[0276] At 700 the UE may generate an encrypted identifier of the UE. For example, the UE may generate a subscriber concealed identifier (SUCI) based on it’s subscriber permanent identifier (SUPI). The UE may in some examples also determine whether to request AKA procedures based on the first parameter size or the second parameter size.

[0277] At 702 the UE sends, to the AMF of the network serving the UE, a registration request. The registration request may comprise an identifier of the UE, for example the encrypted identifier of the UE if it has been generated at 700. In some examples the registration request may also comprise an indication of the requested parameter size, i.e. an indication of whether the first value or the second value of the parameter size is requested.

[0278] At 704, the AMF sends an authentication request to the AUSF of the home network of the UE. The authentication request may comprise the identifier of the UE (e.g., the encrypted identifier). In some examples the authentication request may further comprise the indication of the requested parameter size.

[0279] At 706, the AUSF sends a further authentication request to the network node. The further authentication request may for example comprise an authentication GET request. The authentication request may be for the second output parameter (e.g., XRES*). The further authentication request may comprise the indication of the requested parameter size.

[0280] At 708, the network node determines the size of the one or more parameters as described previously. In some examples the network node may determine the size of the one or more parameters based on the indication of the requested parameter size. For example, the network node may determine to use the requested parameter size.

[0281] At 710, the network node derives the one or more parameters, including the second output parameter, based on the determined size of the one or more parameters, for example using the method described in relation to FIG. 6a previously.

[0282] At 712 the network node may send, to the AUSF, an authentication message comprising the second output parameter and information indicating the size of the one or more parameters. The authentication message may further comprise information indicating the one or more KDFs used at step 710 to generate the second output parameter.

[0283] At 714, the AUSF may send an authentication response message to the AMF. The authentication response message may comprise the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs.

[0284] At 716, the AMF may send an authentication request to the UE. The authentication request may comprise the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs. At 718, the UE derives the one or more parameters (including the first output parameter) based on the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs, for example using the method described in relation to FIG. 6b previously.

[0285] At 720 the UE sends, to the AMF, an authentication response comprising the first output parameter.

[0286] At 722 the AMF sends the first output parameter to the AUSF.

[0287] At 724 the AUSF determines whether to authenticate the UE based on the first output parameter and the second output parameter. For example the AUSF may authenticate the UE when the first output parameter and second output parameter match.

[0288] As explained previously, in some examples the size of the one or more parameters may be variable between the first value and the second value. In some examples the parameters may have different sizes and may have different ranges of possible sizes. The network node may select a size for each of the one or more parameters each time it receives an authentication request and indicate the selected size of each of the one or more parameters when sending the authentication response.

[0289] Table 2 below illustrates an example of the different possible ranges of values (in bytes) each of the one or more parameters may have. It should be understood that the example of Table 2 is for illustrative purposes only, and that in some examples different values of the ranges for each of the parameter may be used.

[0290] Table 2 - example of possible ranges of size for different cryptographic keys Reference is made to FIG. 8, which shows a method according to some examples where the network selects the size of the one or more parameters dynamically from a range of values of each parameter, for example as shown in Table 2 above.

[0291] At 800 the UE may generate an encrypted identifier of the UE. For example, the UE may generate a subscriber concealed identifier (SUCI) based on it’s subscriber permanent identifier (SUPI).

[0292] At 802 the UE sends, to the AMF of the network serving the UE, a registration request. The registration request may comprise an identifier of the UE, for example the encrypted identifier of the UE if it has been generated at 800.

[0293] At 804, the AMF sends an authentication request to the AUSF of the home network of the UE. The authentication request may comprise the identifier of the UE (e.g., the encrypted identifier).

[0294] At 806, the AUSF sends a further authentication request to the network node. The further authentication request may for example comprise an authentication GET request. The authentication request may be for the second output parameter (e.g., XRES*).

[0295] At 808, the network node determines the size of the one or more parameters as described previously. In some examples the network node may determine a size of each of the one or more parameters that is within the range of values for each of the parametesr. For example, when the range of values is as shown in Table 2 above, the network node may select the following sizes (in bytes) for the one or more parameters:

[0296] AK = 12; CK = 32, IK = 20; K = 32; MAC = 8; RAND = 22; RES = 5; SQN = 18

[0297] At 810, the network node derives the one or more parameters, including the second output parameter, based on the determined size of the one or more parameters, for example using the method described in relation to FIG. 6a previously.

[0298] At 812 the network node may send, to the AUSF, an authentication message comprising the second output parameter and information indicating the size of the one or more parameters. The authentication message may further comprise information indicating the one or more KDFs used at step 810 to generate the second output parameter.

[0299] At 814, the AUSF may send an authentication response message to the AMF. The authentication response message may comprise the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs.

[0300] At 816, the AMF may send an authentication request to the UE. The authentication request may comprise the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs.

[0301] At 818, the UE derives the one or more parameters (including the first output parameter) based on the information indicating the size of the one or more parameters, and optionally the indicating the one or more KDFs, for example using the method described in relation to FIG. 6b previously.

[0302] At 820 the UE sends, to the AMF, an authentication response comprising the first output parameter.

[0303] At 822 the AMF sends the first output parameter to the AUSF.

[0304] At 824 the AUSF determines whether to authenticate the UE based on the first output parameter and the second output parameter. For example the AUSF may authenticate the UE when the first output parameter and second output parameter match.

[0305] In some examples, the size of the one or more parameters may be static. The network node may send, to the UE via the AMF, information indicating the (static) size of the one or more parameters prior to performing the authentication procedure. The UE and the network node may use the indicated static size of the one or more keys during authentication. The static size of the one or more parameters may be any suitable value, for example 128 bits or 256 bits.

[0306] Reference is made to FIG. 9, which shows a method where the UE is configured with a static size of the one or more parameters. At 900, the network node sends, to the UE via the AMF, the information indicating the size of the one or more parameters. The size of the one or more parameters may be static. The information indicating the size of the one or more parameters may be sent by an over-the-air update by the network operator, or by a steering of roaming (SoR) procedure or a UE parameter update (UPU) procedure

[0307] At 902 the UE may generate an encrypted identifier of the UE. For example, the UE may generate a subscriber concealed identifier (SUCI) based on it’s subscriber permanent identifier (SUPI).

[0308] At 904 the UE sends, to the AMF of the network serving the UE, a registration request. The registration request may comprise an identifier of the UE, for example the encrypted identifier of the UE if it has been generated at 902.

[0309] At 906, the AMF sends an authentication request to the AUSF of the home network of the UE. The authentication request may comprise the identifier of the UE (e.g., the encrypted identifier).

[0310] At 908, the AUSF sends a further authentication request to the network node. The further authentication request may for example comprise an authentication GET request. The authentication request may be for the second output parameter (e.g., XRES*).

[0311] At 910, the network node determines the size of the one or more parameters according to the information sent to the UE at step 900.

[0312] At 912, the network node derives the one or more parameters, including the second output parameter, based on the determined size of the one or more parameters, for example using the method described in relation to FIG. 6a previously.

[0313] At 914 the network node may send, to the AUSF, an authentication message comprising the second output parameter.

[0314] At 916, the AUSF may send an authentication response message to the AMF. At 918, the AMF may send an authentication request to the UE. At 920, the UE derives the one or more parameters (including the first output parameter) based on the information indicating the size of the one or more parameters received at step 900, for example using the method described in relation to FIG. 6b previously.

[0315] At 922 the UE sends, to the AMF, an authentication response comprising the first output parameter.

[0316] At 924 the AMF sends the first output parameter to the AUSF.

[0317] At 926 the AUSF determines whether to authenticate the UE based on the first output parameter and the second output parameter. For example the AUSF may authenticate the UE when the first output parameter and second output parameter match.

[0318] In some examples, the above-described examples may be applied to different authentication procedures. For example, the examples described herein may be applied to a 5G authentication and key agreement procedure, or to an Extensible Authentication Protocol (EAP) AKA Prime procedure. However it should be understood that these example authentication procedures are for illustrative purposes only and that the invention and concepts disclosed herein are not to be limited to only to these example authentication procedures.

[0319] By implementing some of the examples described above, if a hacker modifies the information indicating the size of the one or more parameters, then the first output parameter and second output parameter will not match, and the UE will not be authenticated. This may help improve the security of the authentication procedure.

[0320] In some examples there is provided a user equipment comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters. In some examples there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0321] In some examples there is provided a network node comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

[0322] In some examples there is provided a network node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network node at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to an authentication server function, an authentication message comprising a second output parameter , wherein the second output parameter is one of the derived one or more parameters.

[0323] In some examples there is provided a user equipment comprising means for: receiving, from an access and mobility management function, information indicating a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the information indicating the size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0324] In some examples there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: receive, from an access and mobility management function, information indicating a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the information indicating the size of the one or more parameters; and send, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0325] In some examples there is provided a network node comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0326] In some examples there is provided a network node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network node at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to an authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0327] In some examples there is provided a user equipment comprising means for: sending, to an access and mobility management function, a requested size of one or more parameters associated with an authentication procedure; receiving, from the access and mobility management function information indicating a size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0328] In some examples there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: send, to an access and mobility management function, a requested size of one or more parameters associated with an authentication procedure; receive, from the access and mobility management function information indicating a size of the one or more parameters; derive the one or more parameters based on the determined size of the one or more parameters; and send, to the access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

[0329] In some examples there is provided a network node comprising means for: receiving, from an authentication server function, information indicating a size of one or more parameters associated with an authentication procedure requested by a user equipment; determining a size of the one or more parameters based on the requested size of the one or more parameters; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to the authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0330] In some examples there is provided a network node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network node at least to: receive, from an authentication server function, information indicating a size of one or more parameters associated with an authentication procedure requested by a user equipment; determine a size of the one or more parameters based on the requested size of the one or more parameters; derive the one or more parameters based on the determined size of the one or more parameters; and send, to the authentication server function, an authentication message comprising a second output parameter and information indicating the determined size of the one or more parameters, wherein the second output parameter is one of the derived one or more parameters.

[0331] FIG. 10 shows a schematic representation of non-volatile memory media 1000a (e.g., computer disc (CD) or digital versatile disc (DVD)) and 1000b (e.g. universal serial bus (USB) memory stick) storing instructions and / or parameters 1002 which when executed by a processor allow the processor to perform one or more of the steps of the method of FIG. 4.

[0332] It is understood that references in the above to various network functions (e.g., to an AMF, an SMF, TNF etc.) may be implemented by apparatus that perform at least some of the functionality associated with those network functions. Further, an apparatus configured to implement a network function may further be configured to implement a virtual network function instance of that network function.

[0333] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.

[0334] It is noted that whilst some example embodiments have been described in relation to 5G networks, similar example embodiments can be applied in relation to other networks and communication systems. Therefore, although certain example embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, further example embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.

[0335] It is also noted herein that there are several variations and modifications which may be made to the various example embodiments described herein without departing from the scope of this disclosure.

[0336] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements. As used herein, the expression “and / or” includes any and all combinations of the listed terms, including at least any one of the elements, at least any two or more of the elements, or at least all of the elements.

[0337] As used herein, the term “or” refers to a non-exclusive “or” unless otherwise indicated (e.g., use of “or else” or “or in the alternative”).

[0338] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included. Analogously, performing a step or functionality “based on A” does not indicate that the step or functionality is performed solely based on “A” as one or more additional conditions may be included. In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting and illustrative examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0339] As used herein, the term “circuitry” may refer to one or more or all of the following:

[0340] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and

[0341] (b) combinations of hardware circuits and software, such as (as applicable):

[0342] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and

[0343] (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0344] © hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that utilizes software (e.g., firmware) for operation, but the software may not be present when it is not utilized for operation.”

[0345] This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0346] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus- readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.

[0347] Further in this regard it should be noted that any blocks of the logic flow as in the FIGs. may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media, such as hard disk or floppy disks, and optical media, such as DVD and the data variants thereof, CD. The physical media is a non-transitory media.

[0348] The term “non-transitory,” as used herein, is a limitation of the medium itself (e.g., tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0349] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.

[0350] Various example embodiments of the disclosure may be practiced in various components, such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate. The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims. The example embodiments and features thereof, if any, described in this disclosure that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure.

[0351] The foregoing description has provided, by way of non-limiting and illustrative examples, a full and informative description of the various example embodiments of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of this disclosure, when read in conjunction with the drawings and the claims. However, all such and similar modifications of the teachings will still fall within the various example embodiments of this disclosure. By way of non-limiting and illustrative example, there is a further example embodiment comprising a combination of one or more example embodiments with any of the other example embodiments previously discussed.

Claims

CLAIMS1. A user equipment comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

2. The user equipment of claim 1, wherein the one or more parameters comprises the first output parameter and one or more intermediary parameters used for deriving the first output parameter.

3. The user equipment of claim 1 or 2, wherein the means is further for: receiving, from the access and mobility management function, information indicating one or more key derivation algorithms to be used by the user equipment when deriving the one or more parameters, wherein deriving the one or more parameters comprises deriving the one or more parameters using the indicated one or more key derivation algorithms.

4. The user equipment of any preceding claim, wherein determining the size of the one or more parameters comprises receiving, from the access and mobility management function, information indicating the size of the one or more parameters.

5. The user equipment of claim 4, wherein the means is further for: receiving, from a network node, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters comprises an identifier of one of a plurality of different combinations that is to be used in the authentication procedure, anddetermining the size of the one or more parameters comprises determining the size of the one or more parameters based on the sizes of the one or more parameters in the combination corresponding to the received identifier.

6. The user equipment of any preceding claim, wherein the means is further for: sending, to the access and mobility management function, a requested size of the one or more parameters, wherein the information indicating the size of the one or more parameters is based on the requested size.

7. The user equipment of any preceding claim, wherein the size of the one or more parameters is selected from at least a first value or a second value.

8. The user equipment of any of claims 1 to 6, wherein the size of the one or more parameters is variable between a first value and a second value.

9. The user equipment of claim 7 or 8, wherein a first value is 128 bits and the second value is 256 bits.

10. The user equipment of any preceding claim, wherein the first output parameter is an authentication response, RES*.

11. A network node comprising means for: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

12. The network node of claim 13, wherein the authentication message comprises information indicating one or more key derivation algorithms to be used by a user equipmentwhen deriving the one or more parameters, wherein the indicated one or more key derivation algorithms correspond to one or more key derivation algorithms used by the network node to derive the one or more parameters.

13. The network node of claim 11 or 12, wherein the authentication message further comprises information indicating the determined size of the one or more parameters.

14. The network node of claim 13, wherein the means is further for: sending, to a user equipment, information indicating a plurality of different combinations of sizes of the one or more parameters, wherein the information indicating the size of the one or more parameters comprises an identifier of one of the plurality of different combination of sizes of the one or more parameters that corresponds to the determined size of the one or more parameters used to derive the one or more parameters.

15. The network node of any of claims 11 to 13, wherein determining the size of the one or more parameters comprises: receiving, from the authentication server function, information indicating a requested size of the one or more parameters, wherein determining the size of the one or more parameters is based on the requested size of the one or more parameters.

16. The network node of any of claims 11 to 15, wherein the size of the one or more parameters is selected from at least a first value or a second value.

17. The network node of any of claims 11 to 15, wherein the size of the one or more parameters is variable between a first value and a second value.

18. The network node of claim 16 or 17, wherein a first value is 128 bits and the second value is 256 bits.

19. The network node of any of claims 11 to 18, wherein the second output parameter is an expected authentication response, XRES*.

20. The network node of any of claims 11 to 19, wherein the network node is one of: a unified data management function; an authentication credential repository; or a subscriber identity de-concealment function.

21. A user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to an access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

22. A network node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network node at least to: determine a size of one or more parameters associated with an authentication procedure; derive the one or more parameters based on the determined size of the one or more parameters; and send, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

23. A method performed by a user equipment, the method comprising: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an access and mobility management function, an authentication message comprising a first output parameter, wherein the first output parameter is one of the derived one or more parameters.

24. A method performed by a network node, the method comprising: determining a size of one or more parameters associated with an authentication procedure; deriving the one or more parameters based on the determined size of the one or more parameters; and sending, to an authentication server function, an authentication message comprising a second output parameter, wherein the second output parameter is one of the derived one or more parameters.

Citation Information

Patent Citations

  • Security negotiation method, terminal equipment and network equipment

    CN110366175A

  • Method and apparatus for security configuration in wireless communication system

    US20180083972A1

  • Security context for target amf

    US20230262453A1