Registering a user equipment with a network
By enabling user equipment and network nodes to manage registration requests with indicated parameter sizes and redirecting to compatible nodes, the solution addresses security vulnerabilities and ensures proper cryptographic key allocation, enhancing network security and compliance.
Patent Information
- Application Number
- PCT/IB2025/051648
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-15
- Filing Date
- 2025-02-14
- Publication Date
- 2025-08-21
AI Technical Summary
Existing communication networks face challenges in managing user equipment registration due to mismatched support for authentication procedure parameter sizes, leading to potential security vulnerabilities and improper allocation of cryptographic keys, especially with the introduction of larger key sizes like 256 bits.
User equipment and network nodes implement mechanisms to send and receive registration requests with indicated parameter sizes, allowing for redirection to compatible nodes or functions that support the required sizes, and utilize subscription data to determine and enforce appropriate key sizes based on operator policies.
Ensures secure and proper allocation of cryptographic keys by rejecting or redirecting registration requests to nodes that support the required parameter sizes, enhancing network security and compliance with user requirements.
Smart Images

Figure IB2025051648_21082025_PF_FP_ABST
Abstract
Description
[0001] REGISTERING A USER EQUIPMENT WITH A NETWORK
[0002] TECHNICAL FIELD
[0003] Various example embodiments of this disclosure relate to a method, apparatus, system and computer program and in particular but not exclusively to registration of a user equipment with a network.
[0004] BACKGROUND
[0005] A communication network can be seen as a facility that enables communications between two or more communication devices or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.
[0006] Such communication networks operate in accordance with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards provided by 3GPP are the so-called 3GPP standards for cellular technology generations, such as 3GPP standards for 4G technology and 3GPP standards for 5G technology.
[0007] SUMMARY
[0008] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure. For example, it should be appreciated that further aspects may be provided by the combination of any two or more of the various aspects described below.
[0009] According to an aspect, there is provided a user equipment comprising means for: sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request
[0010] The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment .
[0011] The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
[0012] The means may be further for: sending a further registration request towards the further access node.
[0013] The response message rejecting the user equipment’s registration request may comprise information indicating that an access and mobility management function to which the registration request was forwarded does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment.
[0014] The response message rejecting the user equipment’s registration request may comprise the information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0015] The means may be further for: sending a further registration request towards the further access and mobility management function.
[0016] According to an aspect there is provided an access node comprising means for: receiving, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receiving, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, sending, to the user equipment, a response message accepting or rejecting the registration request.
[0017] The means may be further for: determining, based at least on the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment, whether the access node and the user equipment support the required size; and when the access node and the user equipment support the required size, the sending comprises sending, the response message accepting the user equipment’s registration request; or when the access node and / or the user equipment does not support the required size, the sending comprises sending the response message rejecting the user equipment’s registration request.
[0018] The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0019] The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
[0020] The message indicating the required size may further comprise an indication that the access and mobility management function does not support the required size; and wherein the response message rejecting the user equipment’s registration request may comprise information indicating that the access and mobility management function does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0021] The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards; and wherein the response message rejecting the user equipment’s registration request may comprise the information indicating the further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0022] According to an aspect there is provided an apparatus comprising means for: receiving, from an access node, a further registration request, the further registration request comprising an indication of a a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to a unified data management function, a request for subscription data relating to the user equipment; receiving, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and sending, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0023] The means may be further for: determining the required size of the one or more parameters associated with the authentication procedure based on the received subscription data and operator policy information.
[0024] The means may be further for: determining that the apparatus does not support the required size, wherein the message indicating the required size may further comprise information indicating that the registration request is to be rejected and an indication that the apparatus does not support the required size.
[0025] The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0026] According to an aspect there is provided an apparatus comprising means for: receiving subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receiving, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, sending, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0027] According to an aspect, there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: : send, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receive, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request
[0028] The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment .
[0029] The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
[0030] The at least one processor may be configured to further cause the user equipment to: send a further registration request towards the further access node.
[0031] The response message rejecting the user equipment’s registration request may comprise information indicating that an access and mobility management function to which the registration request was forwarded does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment.
[0032] The response message rejecting the user equipment’s registration request may comprise the information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0033] The at least one processor may be configured to further cause the user equipment to: send a further registration request towards the further access and mobility management function. According to an aspect, there is provided an access node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the access node at least to: receive, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; send, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receive, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, send, to the user equipment, a response message accepting or rejecting the registration request.
[0034] The at least one processor may be configured to further cause the access node to: determining, based at least on the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment, whether the access node and the user equipment support the required size; and when the access node and the user equipment support the required size, the sending comprises sending, the response message accepting the user equipment’s registration request; or when the access node and / or the user equipment does not support the required size, the sending comprises sending the response message rejecting the user equipment’s registration request.
[0035] The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0036] The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards. The message indicating the required size may further comprise an indication that the access and mobility management function does not support the required size; and wherein the response message rejecting the user equipment’s registration request may comprise information indicating that the access and mobility management function does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0037] The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards; and wherein the response message rejecting the user equipment’s registration request may comprise the information indicating the further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0038] According to an aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from an access node, a further registration request, the further registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; send, to a unified data management function, a request for subscription data relating to the user equipment; receive, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and send, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0039] The at least one processor may be configured to further cause the apparatus to: determine the required size of the one or more parameters associated with the authentication procedure based on the received subscription data and operator policy information.
[0040] The at least one processor may be configured to further cause the apparatus to: determine that the apparatus does not support the required size, wherein the message indicating the required size may further comprise information indicating that the registration request is to be rejected and an indication that the apparatus does not support the required size. The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0041] According to an aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receive, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, send, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0042] According to an aspect, there is provided a method performed by a user equipment, the method comprising: sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request
[0043] The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment .
[0044] The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
[0045] The method may comprise: sending a further registration request towards the further access node. The response message rejecting the user equipment’s registration request may comprise information indicating that an access and mobility management function to which the registration request was forwarded does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment.
[0046] The response message rejecting the user equipment’s registration request may comprise the information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0047] The method may comprise: sending a further registration request towards the further access and mobility management function.
[0048] According to an aspect there is provided a method performed by an access node, the method comprising: receiving, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receiving, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, sending, to the user equipment, a response message accepting or rejecting the registration request.
[0049] The method may comprise: determining, based at least on the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment, whether the access node and the user equipment support the required size; and when the access node and the user equipment support the required size, the sending comprises sending, the response message accepting the user equipment’s registration request; or when the access node and / or the user equipment does not support the required size, the sending comprises sending the response message rejecting the user equipment’s registration request. The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0050] The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
[0051] The message indicating the required size may further comprise an indication that the access and mobility management function does not support the required size; and wherein the response message rejecting the user equipment’s registration request may comprise information indicating that the access and mobility management function does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0052] The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards; and wherein the response message rejecting the user equipment’s registration request may comprise the information indicating the further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0053] According to an aspect there is provided a method performed by an access and mobility management function, the method comprising: receiving, from an access node, a further registration request, the further registration request comprising an indication of a a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to a unified data management function, a request for subscription data relating to the user equipment; receiving, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and sending, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment. The method may comprise: determining the required size of the one or more parameters associated with the authentication procedure based on the received subscription data and operator policy information.
[0054] The method may comprise: determining that the access and mobility management function does not support the required size, wherein the message indicating the required size may further comprise information indicating that the registration request is to be rejected and an indication that the access and mobility management function does not support the required size.
[0055] The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0056] According to an aspect there is provided a method performed by a unified data management function, the method comprising: receiving subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receiving, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, sending, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0057] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a user equipment, cause the user equipment to perform at least the following: sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request
[0058] The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment . The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
[0059] The instructions, when executed by the user equipment, may cause the user equipment to further perform: sending a further registration request towards the further access node.
[0060] The response message rejecting the user equipment’s registration request may comprise information indicating that an access and mobility management function to which the registration request was forwarded does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment.
[0061] The response message rejecting the user equipment’s registration request may comprise the information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0062] The instructions, when executed by the user equipment, may cause the user equipment to further perform: sending a further registration request towards the further access and mobility management function.
[0063] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by an access node, cause the access node to perform at least the following: receiving, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receiving, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, sending, to the user equipment, a response message accepting or rejecting the registration request. The instructions, when executed by the access node, may cause the access node to further perform: determining, based at least on the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment, whether the access node and the user equipment support the required size; and when the access node and the user equipment support the required size, the sending comprises sending, the response message accepting the user equipment’s registration request; or when the access node and / or the user equipment does not support the required size, the sending comprises sending the response message rejecting the user equipment’s registration request.
[0064] The response message rejecting the user equipment’s registration request may comprise information indicating that the access node does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0065] The response message rejecting the user equipment’s registration request may comprise information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
[0066] The message indicating the required size may further comprise an indication that the access and mobility management function does not support the required size; and wherein the response message rejecting the user equipment’s registration request may comprise information indicating that the access and mobility management function does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
[0067] The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards; and wherein the response message rejecting the user equipment’s registration request may comprise the information indicating the further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0068] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by an access and mobility management function, cause the access and mobility management function to perform at least the following: receiving, from an access node, a further registration request, the further registration request comprising an indication of a a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to a unified data management function, a request for subscription data relating to the user equipment; receiving, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and sending, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0069] The instructions, when executed by the access and mobility management function, may cause the access and mobility management function to further perform: determining the required size of the one or more parameters associated with the authentication procedure based on the received subscription data and operator policy information.
[0070] The instructions, when executed by the access and mobility management function, may cause the access and mobility management function to further perform: determining that the access and mobility management function does not support the required size, wherein the message indicating the required size may further comprise information indicating that the registration request is to be rejected and an indication that the access and mobility management function does not support the required size.
[0071] The message indicating the required size may comprise information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
[0072] According to an aspect, there is provided a computer readable medium comprising instructions which, when executed by a unified data management function, cause the unified data management function to perform at least the following: receiving subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receiving, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, sending, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0073] According to an aspect, there is provided a method performed by a user equipment, the method comprising: sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request.
[0074] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.
[0075] In the above, many different aspects have been described. As previously noted, it should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above. Other features, aspects, and elements will become apparent in view of the following.
[0076] DESCRIPTION OF FIGURES
[0077] Some example embodiments will now be described, by way of non-limiting and illustrative example only, with reference to the accompanying Figures (FIGs.) in which:
[0078] FIG. 1 shows a representation of a 5thgeneration communication system;
[0079] FIG. 2 shows a representation of an apparatus for the communication system of FIG. 1 according to some example embodiments;
[0080] FIG. 3 shows a representation of an apparatus according to some example embodiments;
[0081] FIGs. 4a-d show methods according to some examples;
[0082] FIG. 5 shows a signalling procedure according to some examples; and
[0083] FIG. 6 shows a schematic representation of an apparatus according to some examples.
[0084] DETAIEED DESCRIPTION In the following various example embodiments are explained with reference to communication devices capable of communication with a communication system. Before explaining in detail the various example embodiments of the this disclosure, a 5thgeneration communication system (5GS), an access network and a core network (5GC) thereof, and communication devices are briefly explained with reference to FIG. 1, 2 and 3.
[0085] FIG. 1 shows a schematic representation of a 5G communication system (5GS). The 5GS may comprise a user equipment (UE) or Terminal 100, an access network such as a 5G radio access network (5G-RAN) 101 or next generation radio access network (NG-RAN), a 5G core network 102, and one or more application functions 103. An application function 103 may be deployed in the 5GS as trusted application function or may be deployed or host on one or more application servers of the data network (DN) 104. Such application functions are untrusted application functions. The 5GS connects the UE to the data network 104, the access network 101 and the 5GC 102 (e.g., a UPF of the 5GC).
[0086] The 5G-RAN 101 may comprise one or more radio access nodes, such as gNodeB (gNB). A gNB may include one or more gNodeB (GNB) distributed units connected to one or more gNodeB (GNB) centralized units.
[0087] The 5GC may comprise the following network functions: Network Slice Selection Function (NSSF); Network Exposure Function (NEF) 105; Network Repository Function (NRF); Policy Control Function (PCF); Unified Data Management (UDM) 106; Application Function (AF) 103; Authentication Server Function (AUSF) 107; an Access and Mobility Management Function (AMF) 108; Session Management Function (SMF) 109; and a user plane function (UPF) 110. FIG. 1 also shows the various interfaces (Nl, N2 etc.) that may be implemented between the various elements of the system.
[0088] FIG. 2 illustrates an example of a control apparatus 200 for controlling a function of the access network (e.g., a 5G-RAN or the NG-RAN illustrated in FIG. 1) illustrated on FIG. 1. The control apparatus 200 may comprise at least one random access memory (RAM) 21 la, at least on read only memory (ROM) 211b, at least one processor 212, 213 and a network interface
[0089] 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211b. The at least one processor 212, 213 may be configured to execute an appropriate software code
[0090] 215. Execution of the software code 215 may for example may cause the apparatus to perform operations for controlling a function of the access network. The software code 215 may be stored in the ROM 211b. The control apparatus 200 may be interconnected with another control apparatus 200 for controlling another function of the 5G-RAN or the NG-RAN. In some embodiments, each function of the 5G-RAN or the NG-RAN is deployed or hosted on a control apparatus 200. In alternative embodiments, two or more functions of the 5G-RAN or the NG- RAN may share a control apparatus.
[0091] FIG. 3 illustrates an example of a communication device 300, such as the UE illustrated on FIG. 1. The communication device 300 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of a communication device 300 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like. The communication device 300 may comprise a transceiver for transmitting and / or receiving, for example, wireless signals carrying communications, for example radio signals. The communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.
[0092] The communication device 300 may receive wireless signals (e.g., radio signals) over an air or radio interface 307 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals. In FIG. 3 transceiver is designated schematically by block 306. The transceiver 306 may comprise, for example, a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements. The antenna arrangement may be a multi-input multi output (MIMO) antenna.
[0093] The communication device 300 may be provided with at least one processor 301, at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access networks (e.g., the 5G-RAN or NG-RAN illustrated in FIG. 1) and other communication devices. The at least one processor 301 is coupled to the RAM 302b and the ROM 302a. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more operations of the communication device. The software code 308 may be stored in the ROM 302a.
[0094] The processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device (e.g., a modem) can be provided on a circuit board, in chipsets, or in a system on chip. The circuit board, chipsets or system on chip is denoted by reference 304. The communication device 300 may optionally have a user interface such as keypad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of communication device.
[0095] In some networks it may be necessary for a UE to undergo an authentication and key agreement (AKA) procedure to access the services provided by the network. The AKA procedure may involve the UE and the home network of the UE (e.g., at least one of an authentication server function (AUSF), authentication credential repository (ARPF), subscriber identity deconcealing function (SIDE), or UDM of the home network) generating one or more cryptographic keys, which may include a first output key (generated by the UE) and a second output key (generated by the home network). A network node (e.g., the AUSF) may compare the first and second output keys, and if the first and second output keys match, the UE is authenticated by the network.
[0096] 3GPP TS 33.501 describes examples of known AKA procedures, which utilize 128 bit size cryptographic keys. However, recent developments, such as 3GPP TR 33.841, have considered utilizing 256 bit size cryptographic keys, which may provide enhanced security protection. However the introduction of 256 bit size cryptographic keys may introduce additional challenges to the proper functionality of the network.
[0097] For example, some access nodes within the communication network may not support the use of 256 bit size cryptographic keys, and may instead only support 128 bit size keys. Certain UEs (e.g., mission critical UEs) may be required to utilize 256 bit size keys. Therefore, some access nodes may not be able to serve certain UEs properly.
[0098] Furthermore, some users may be required to use 256 bit size keys. The user’s requirements may be configured in subscription information associated with that user, which may be stored in the 5GC, for example in a UDM / UDR. However the access stratum layer of the network may be unaware of such subscription information. As a result, when a user that is required to use 256 bit key size (according to the subscription information) attempts to access the network using a device (e.g., UE) that does not support the required 256 bit key size, the UE may inadvertently be allocated a 128 bit size key.
[0099] However, by using 128 bit size keys, the UE may be less secure than is required. It may be beneficial in such cases to enable the network operator to properly reject the access request or restrict the UE’s access accordingly, which may for example help avoid “bidding down” attacks where even if the network supports 256 bit size keys and the UE is supposed to be provided with 256 bit size keys, the UE may be allocated 128 bit size keys.
[0100] Some examples of the present disclosure may address one or more of these issues.
[0101] Reference is made to FIG. 4, which shows methods according to some examples.
[0102] With reference to FIG. 4a, at 400 a method comprises sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by a user equipment, wherein the supported size comprises one of at least a first size and a second size. At 402 the method comprises receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request. The method of FIG. 4a may be performed by the user equipment.
[0103] With reference to FIG. 4b, at 404 a method comprises receiving, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size. At 406 the method comprises sending, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment. At 408 the method comprises receiving, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment. At 410, the method comprises, based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, sending, to the user equipment, a response message accepting or rejecting the registration request. The method of FIG. 4b may be performed by an access node.
[0104] With reference to FIG. 4c, at 412 a method comprises receiving, from an access node, a further registration request, the further registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size. At 414 the method comprises sending, to a unified data management function, a request for subscription data relating to the user equipment. At 416 the method comprises receiving, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment. At 418 the method comprises sending, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment. The method of FIG. 4c may be performed by an access and mobility management function.
[0105] With reference to FIG. 4d, at 420 a method comprises receiving subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment. At 422 the method comprises receiving, from an access and mobility management function, a request for subscription data relating to the user equipment. At 424 the method comprises, based on the request, sending, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment. The method of FIG. 4d may be performed by a unified data management function.
[0106] In some examples, subscription information associated with a user or UE comprises information indicating a required size of one or more parameters associated with an authentication procedure for the user or UE. When a UE attempts to register with the network via an access node, the AMF may determine the required size of the one or more parameters. For example, the AMF may obtain the subscription information from a UDM / UDR. The AMF may indicate the required size to the access node, and the access node may determine whether to accept or reject the UE’s request based on the indicated required size. For example, if the access node determines that either the UE or the access node do not support the required size, the access node may reject the UE’s registration request.
[0107] Reference is made to FIG. 5, which shows a signalling procedure according to some examples. In the example of FIG. 5, it is assumed that the UDM / UDR is configured with information indicating a required size of one or more parameters associated with an authentication procedure for the UE.
[0108] At 500, a UE sends, to an access node, a registration request. The registration request may comprise an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment. The supported size may comprise one of at least a first size and a second size.
[0109] In some examples the first size may be 128 bits and the second size may be 256 bits. However, in other examples the first size and second size may be another value to the 128 / 256 bit example, or the supported size may be one of more than the first size and the second size - for instance, the supported size may comprise one of a first size (e.g., 128 bits), a second size (e.g., 256 bits), and a third size (512 bits). The one or more parameters may for example comprise one or more cryptographic keys associated with the authentication procedure, such as the keys and parameters described in 3GPP TS 33.501.
[0110] At 502, the access node sends, to an AMF, a further registration request. The further registration request may comprise the indication of the size of the one or more parameters associated with an authentication procedure supported by the user equipment.
[0111] At 504, the AMF sends, to a UDM or UDR, a request for subscription data relating to the user equipment. In some examples the AMF may send the request for subscription data in response to receiving the further registration request.
[0112] At 506, the UDM / UDR sends, to the AMF, the subscription data. The subscription data comprises the information indicating a required size of one or more parameters associated with the authentication procedure for the UE. In some examples the UDM / UDR may receive the subscription data relating to the user equipment. For example, the UDM / UDR may receive input from the network operator, where the input indicates the subscription data.
[0113] At 508, the AMF sends, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure for the UE.
[0114] In some examples the AMF may determine the required size of the one or more parameters based on the received subscription data and operator policy information. The operator policy information may for example be configured at the AMF or received from the PCF. In some examples the AMF may determine whether the AMF supports the required size of the one or more parameters. If the AMF does not support the required size, then the AMF may include, in the message to the access node, an indication that the registration request is to be rejected and information indicating that AMF does not support the required size. In some examples the AMF may determine a further AMF that supports the required size to redirect the UE’s registration request towards and include information indicating the further AMF in the message sent to the access node.
[0115] At 510, the access node may send, to the UE a response message accepting or rejecting the registration request. The response may be based at least on the access node’s capability to support at least the first size and the second size of the one or more parameters, and the required size.
[0116] In some examples the access node may determine, based on the indicated required size of the one or more parameters, whether to accept or reject the UE’s registration request. In some examples, when the UE and the access node support the required size of the one or more parameters, the access node may accept the request. In some examples, when either the UE and / or the access node do not support the required size of the one or more parameters, the access node may reject the UE’s request.
[0117] The access node may for example determine whether the UE supports the required size based on the registration request (received at 500). The access node may be assumed to know it’s own capability for supporting the required size of the one or more parameters. In some examples, when the access node does not support the required size, the access node may include in the response message rejecting the request, information indicating a further access node to which the UE’s registration request is to be redirected. The further access node may support the required size.
[0118] In some examples, when the access node receives an indication that the AMF does not support the required size, the access node may determine to reject the UE’s registration request. The access node may include information indicating that the AMF does not support the required size of the one or more parameters in the response message sent to the UE. If the AMF has sent the information indicating the further AMF to redirect the registration request towards, the access node may include such information in the response message to the UE.
[0119] At 512, the UE may either complete registration with the network (if the access node sent a response message accepting the registration request at 510), or may terminate the registration procedure (if the access node sent a response message rejecting the registration request at 510), or may send a further registration request towards the further access node or AMF (e.g., if the access node sent a response message rejecting the registration request and comprising information indicating the further access node or further AMF to redirect the registration request towards at 510).
[0120] Thus in some examples, methods are provided whereby an access node can determine whether to accept or reject a UE’s registration request. The determination may be based at least in part on the access node’s capability to support the required size of one or more parameters associated with an authentication procedure for the UE. In some examples the UE may indicate to the access node a size of the one or more parameters supported by the UE, where the supported size comprises at least one of a first size (e.g., 128 bits) and a second size (e.g., 256 bits), and the access node may determine whether the UE can support the required size based on the indication. Therefore, the network may reject registration requests from UE’s that are unable to support the required size, and may therefore avoid allowing access for UE’s that are unable to support sufficiently complex authentication parameters (that is to say, UE’s that are less secure in their authentication). Furthermore, the network may be able to readily reject registration requests from UE’s when the access node through which the request is received is unable to support the required size of the one or more parameters. In some examples there is provided a user equipment comprising means for: sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request
[0121] In some examples there is provided an access node comprising means for: receiving, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receiving, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, sending, to the user equipment, a response message accepting or rejecting the registration request.
[0122] In some examples there is provided an apparatus comprising means for: receiving, from an access node, a further registration request, the further registration request comprising an indication of a a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to a unified data management function, a request for subscription data relating to the user equipment; receiving, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and sending, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0123] In some examples there is provided an apparatus comprising means for: receiving subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receiving, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, sending, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0124] In some examples there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: : send, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receive, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request
[0125] In some examples, there is provided an access node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the access node at least to: receive, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; send, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receive, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, send, to the user equipment, a response message accepting or rejecting the registration request.
[0126] In some examples, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from an access node, a further registration request, the further registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; send, to a unified data management function, a request for subscription data relating to the user equipment; receive, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and send, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0127] In some examples, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receive, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, send, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
[0128] FIG. 6 shows a schematic representation of non-volatile memory media 600a (e.g., computer disc (CD) or digital versatile disc (DVD)) and 600b (e.g. universal serial bus (USB) memory stick) storing instructions and / or parameters 602 which when executed by a processor allow the processor to perform one or more of the steps of the method of FIG. 4.
[0129] It is understood that references in the above to various network functions (e.g., to an AMF, an SMF, TNF etc.) may be implemented by apparatus that perform at least some of the functionality associated with those network functions. Further, an apparatus configured to implement a network function may further be configured to implement a virtual network function instance of that network function.
[0130] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities. It is noted that whilst some example embodiments have been described in relation to 5G networks, similar example embodiments can be applied in relation to other networks and communication systems. Therefore, although certain example embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, further example embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.
[0131] It is also noted herein that there are several variations and modifications which may be made to the various example embodiments described herein without departing from the scope of this disclosure.
[0132] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements. As used herein, the expression “and / or” includes any and all combinations of the listed terms, including at least any one of the elements, at least any two or more of the elements, or at least all of the elements.
[0133] As used herein, the term “or” refers to a non-exclusive “or” unless otherwise indicated (e.g., use of “or else” or “or in the alternative”).
[0134] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included. Analogously, performing a step or functionality “based on A” does not indicate that the step or functionality is performed solely based on “A” as one or more additional conditions may be included.
[0135] In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting and illustrative examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0136] As used herein, the term “circuitry” may refer to one or more or all of the following:
[0137] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and
[0138] (b) combinations of hardware circuits and software, such as (as applicable):
[0139] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and
[0140] (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[0141] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that utilizes software (e.g., firmware) for operation, but the software may not be present when it is not utilized for operation.”
[0142] This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0143] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus- readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it. Further in this regard it should be noted that any blocks of the logic flow as in the FIGs. may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media, such as hard disk or floppy disks, and optical media, such as DVD and the data variants thereof, CD. The physical media is a non-transitory media.
[0144] The term “non-transitory,” as used herein, is a limitation of the medium itself (e.g., tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0145] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.
[0146] Various example embodiments of the disclosure may be practiced in various components, such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.
[0147] The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims. The example embodiments and features thereof, if any, described in this disclosure that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure.
[0148] The foregoing description has provided, by way of non-limiting and illustrative examples, a full and informative description of the various example embodiments of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of this disclosure, when read in conjunction with the drawings and the claims. However, all such and similar modifications of the teachings will still fall within the various example embodiments of this disclosure. By way of non-limiting and illustrative example, there is a further example embodiment comprising a combination of one or more example embodiments with any of the other example embodiments previously discussed.
Claims
Claims:
1. A user equipment comprising means for: sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request.
2. The user equipment of claim 1, wherein the response message rejecting the user equipment’s registration request comprises information indicating that the access node does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment.
3. The user equipment of claim 2, wherein the response message rejecting the user equipment’s registration request comprises information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
4. The user equipment of claim 3, wherein the means is further for: sending a further registration request towards the further access node.
5. The user equipment of any of claims 1 to 4, wherein the response message rejecting the user equipment’ s registration request comprises information indicating that an access and mobility management function to which the registration request was forwarded does not support the size of the one or more parameters associated with the authentication procedure supported by the user equipment.
6. The user equipment of claim 5, wherein the response message rejecting the user equipment’s registration request comprises the information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards.
7. The user equipment of claim 6, wherein the means is further for: sending a further registration request towards the further access and mobility management function.
8. An access node comprising means for: receiving, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receiving, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, sending, to the user equipment, a response message accepting or rejecting the registration request.
9. The access node of claim 8, wherein the means is further for: determining, based at least on the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment, whether the access node and the user equipment support the required size; andwhen the access node and the user equipment support the required size, the sending comprises sending, the response message accepting the user equipment’s registration request; or when the access node and / or the user equipment does not support the required size, the sending comprises sending the response message rejecting the user equipment’s registration request.
10. The access node of claim 8 or 9, wherein the response message rejecting the user equipment’s registration request comprises information indicating that the access node does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
11. The access node of claim 10, wherein the response message rejecting the user equipment’s registration request comprises information indicating a further access node to which the user equipment’s registration request is to be redirected towards.
12. The access node of any of claims 8 to 11, wherein the message indicating the required size further comprises an indication that the access and mobility management function does not support the required size; and wherein the response message rejecting the user equipment’s registration request comprises information indicating that the access and mobility management function does not support the size required by the user equipment of the one or more parameters associated with the authentication procedure.
13. The access node of claim 12, wherein the message indicating the required size comprises information indicating a further access and mobility management function to which the user equipment’s registration request is to be redirected towards; and wherein the response message rejecting the user equipment’s registration request comprises the information indicating the further access and mobilitymanagement function to which the user equipment’s registration request is to be redirected towards.
14. An apparatus comprising means for: receiving, from an access node, a further registration request, the further registration request comprising an indication of a a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to a unified data management function, a request for subscription data relating to the user equipment; receiving, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and sending, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
15. The apparatus of claim 14, wherein the means is further for: determining the required size of the one or more parameters associated with the authentication procedure based on the received subscription data and operator policy information.
16. The apparatus of claim 14 or 15, wherein the means is further for: determining that the apparatus does not support the required size, wherein the message indicating the required size further comprises information indicating that the registration request is to be rejected and an indication that the apparatus does not support the required size.
17. The apparatus of claim 16, wherein the message indicating the required size comprises information indicating a further access and mobility managementfunction to which the user equipment’s registration request is to be redirected towards.
18. An apparatus comprising means for: receiving subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receiving, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, sending, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
19. A user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment at least to: send, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receive, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request20. An access node comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the access node at least to: receive, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associatedwith an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; send, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment; receive, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, send, to the user equipment, a response message accepting or rejecting the registration request.
21. An apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from an access node, a further registration request, the further registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; send, to a unified data management function, a request for subscription data relating to the user equipment; receive, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and send, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
22. An apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receive, from an access and mobility management function, a request for subscription data relating to the user equipment; and based on the request, send, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
23. A method performed by a user equipment, the method comprising: sending, to an access node, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; and receiving, from the access node, a response message accepting the user equipment’s registration request or rejecting the user equipment’s registration request24. A method performed by an access node, the method comprising: receiving, from a user equipment, a registration request, the registration request comprising an indication of a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to an access and mobility management function, a further registration request, the further registration request comprising the indication of the size of the one or more parameters associated with the authentication procedure supported by the user equipment;receiving, from the access and mobility management function, a message indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and based on access node’s capability to support the required size of the one or more parameters and the required size received from the access and mobility management function, sending, to the user equipment, a response message accepting or rejecting the registration request.
25. A method performed by an access and mobility management function, the method comprising: receiving, from an access node, a further registration request, the further registration request comprising an indication of a a size of one or more parameters associated with an authentication procedure supported by the user equipment, wherein the supported size comprises one of at least a first size and a second size; sending, to a unified data management function, a request for subscription data relating to the user equipment; receiving, from the unified data management function, subscription data indicating a required size of the one or more parameters associated with the authentication procedure required by the user equipment; and sending, to the access node, a message indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
26. A method performed by a unified data management function, the method comprising: receiving subscription data relating to a user equipment, wherein the subscription data indicates a required size of one or more parameters associated with an authentication procedure required by the user equipment; receiving, from an access and mobility management function, a request for subscription data relating to the user equipment; andbased on the request, sending, to the access and mobility management function, the subscription data indicating the required size of the one or more parameters associated with the authentication procedure required by the user equipment.
Citation Information
Patent Citations
Cipher longness negotiating method
CN101184339A
Method for negotiating security capability of 5G mobile communication network
CN111787532A
Security negotiation method, terminal device and network device
CN113423104A