Methods and systems for handling user authentication in a wireless communication network

A 3GPP network architecture with AuF and UAF enhances user authentication and authorization, addressing the challenge of identifying and securing user access in 5G networks, optimizing resource allocation and service differentiation.

WO2025174042A1PCT designated stage Publication Date: 2025-08-21SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/002027
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-13
Filing Date
2025-02-12
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing 5G wireless networks lack efficient methods for identifying and authenticating human users, devices, or applications accessing network services through a shared User Equipment (UE), leading to inadequate service differentiation, security, and resource optimization.

Method used

Introduce a 3GPP standards-based network architecture with a User Information Database (AuF) and User Authentication Function (UAF) to manage user subscriptions, authenticate users at the application layer, and enable third-party identity verification, ensuring secure and differentiated service provision.

Benefits of technology

Enhances user authentication and authorization, optimizing resource allocation, and providing differentiated services by ensuring only authorized users access specific applications, thereby improving network security and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025002027_21082025_PF_FP_ABST
    Figure KR2025002027_21082025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Embodiments herein disclose systems and methods for handling user authentication in a wireless communication network involving receiving an authentication request with a User ID from a user authentication function entity (200), initiating authentication by communicating with the UE, and providing the result to the UAF. Embodiment herein disclose system and methods for handling user authentication, by an authentication server (100). The method includes receiving a user authentication request from a unified authentication function for at least one user identifier associated with a user equipment (UE). Further, the method includes initiating user authentication by communicating with the wireless network based on the user authentication request. The method includes providing a result of authentication procedure to the user authentication function (UAF) entity (200). The result comprises one of: an error message to the UAF entity (200), and a successful message including a user profile data to the UAF entity (200).
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND SYSTEMS FOR HANDLING USER AUTHENTICATION IN A WIRELESS COMMUNICATION NETWORK

[0001] Embodiments disclosed herein relate to a wireless network, and more particularly to methods and systems for identifying human users, devices or applications that are accessing the wireless network provided services through the device with a subscription to the wireless network, in order to provide differentiated services.

[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in “Sub 6GHz” bands such as 3.5GHz, but also in “Above 6GHz” bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz (THz) bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.

[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.

[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.

[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.

[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.

[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.

[0008] The present disclosure provides methods and apparatus for handling user authentication in a wireless communication system.

[0009] According to an aspect of an exemplary embodiment, there are provided methods and apparatus for handling user authentication in a wireless communication system.

[0010] Aspects of the present disclosure provide efficient communication methods in a wireless communication system.

[0011] Embodiments herein are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the following illustratory drawings. Embodiments herein are illustrated by way of examples in the accompanying drawings, and in which:

[0012] FIG. 1 illustrates an example of an authentication server depicting how information is stored in a User Subscription database, according to embodiments of the present disclosure;

[0013] FIG. 2 illustrates an example network architecture for user-authentication and / or authorization procedure in a wireless network, according to embodiments of the present disclosure;

[0014] FIG. 3 illustrates a sequence diagram for user-authentication and / or authorization procedure in a wireless network, according to embodiments of the present disclosure;

[0015] FIG. 4 illustrates an example sequence diagram for user-authentication and / or authorization procedure in the wireless network, according to embodiments of the present disclosure;

[0016] FIG. 5A illustrates an example flow diagram for user-authentication and / or authorization procedure in the wireless network, according to embodiments of the present disclosure.

[0017] FIG. 5B illustrates an example flow diagram for user-authentication and / or authorization procedure in the wireless network, according to embodiments of the present disclosure.

[0018] FIG. 6 illustrates various hardware components of an authentication server, according to the embodiments of the present disclosure;

[0019] FIG. 7 illustrates various hardware components of an UAF entity, according to the embodiments of the present disclosure;

[0020] FIG. 8 illustrates various hardware components of an AF entity, according to the embodiments of the present disclosure;

[0021] FIG. 9 illustrates various hardware components of the UE, according to the embodiments of the present disclosure;

[0022] FIG. 10 is a flow chart illustrating a method for handling user-authentication and / or authorization procedure by the authentication server, according to the embodiments of the present disclosure;

[0023] FIG. 11 is a flow chart illustrating a method for handling user-authentication and / or authorization procedure by the UAF entity, according to the embodiments of the present disclosure;

[0024] FIG. 12 is a flow chart illustrating a method for handling user-authentication and / or authorization procedure by the AF entity, according to the embodiments of the present disclosure; and

[0025] FIG. 13 is a flow chart illustrating a method for handling user-authentication and / or authorization procedure by the UE, according to the embodiments of the present disclosure.

[0026] FIG. 14 illustrates a block diagram of a terminal (or a user equipment (UE)), according to embodiments of the present disclosure.

[0027] FIG. 15 illustrates a block diagram of a network entity, according to embodiments of the present disclosure.

[0028] This application is based on and derives the benefit of Indian Provisional Application 202441009945, the contents of which are incorporated herein by reference.

[0029] In the present landscape of wireless networks, particularly those utilizing 3rdGeneration Partner Project (3GPP)-based technologies such as 5thGeneration (5G), a device or user equipment (UE) is primarily identified through a subscription identity, such as the Subscription Permanent Identifier (SUPI), which is pre-configured into a mobile device (for instance, within a subscriber identity module (SIM) card). Additionally, the device itself is uniquely recognized through its International Mobile Equipment Identity (IMEI) number. Further, The UE could be shared or used among different users, either simultaneously or at different times, with each user requiring a distinct type of service (e.g., game service, broadcast service, banking service or the like) and / or prioritization of the data traffic transmitted to and from the UE. For example, premium subscribers of the UE may enable higher levels of Quality of Service (QoS) when connecting to a network (or network entity) through the shared mobile device, while other users may only be provided with a standard QoS or a default QoS. In certain situations, restrictions may also be imposed on the use of specific devices, ensuring that they are only accessible to authorized human users.

[0030] The 3GPP group intends to study, support and incorporate features / advancements in User Identification, Authentication, and Authorization within a 3GPP framework of its Release-19 specifications. By enhancing the 5G System to allow for the creation and utilization of user-specific identities, operators (or service provider) will be able to provide enhanced user experience, optimized performance, and offer services to the devices and the users that are not part of the operator's 3GPP network. This will allow the operator to charge and provide the service differentiation based on the user identifier or subscription.

[0031] A 5thGeneration system (5GS) is expected to fulfill the following requirements to ensure robust functionality and security. For, example, 5GS must provide the capability to associate or dissociate the user with a specific User Equipment (UE) subscription, such as a Subscription Permanent Identifier (SUPI). The system should ensure that the users can connect to the network only by utilizing a predefined set of UE subscriptions (e.g., SUPIs) only. Furthermore, the 5GS should restrict the number of users allowed to operate under a single UE subscription to prevent unauthorized or excessive usage. The network must also support interoperability with third-party user identities, so as to enable the seamless integration. The user validation can occur at an application layer to ensure an additional layer of security. Additionally, third parties should be empowered to initiate authentication processes when the users access their applications. Lastly, the 5GS must include mechanisms to restrict certain users from the network access when their associated UE is in a roaming state, thereby ensuring compliance with network policies and security standards.

[0032] Hence, there is a need in the art for solutions which will overcome the above mentioned drawback(s), among others.

[0033] The principal object of embodiments herein is to disclose systems and methods for enabling a 3GPP standards-based wireless network for identifying human users, devices or applications that are accessing the network provided services through the UE with a subscription to the network, in order to provide differentiated services.

[0034] Another object of embodiments herein is to introduce a user plane procedure for user authentication and authorization.

[0035] Another object of embodiments herein is to disclose a network architecture (or wireless network) to enable a network service provider to link or unlink a user with a specific UE subscription (e.g. SUPI).

[0036] Another object of embodiments herein is to disclose the network architecture to enable the network service provider to ensure that a user connects to the network using a specific set of UE Subscriptions (e.g. SUPIs) only.

[0037] Another object of embodiments herein is to disclose the network architecture to enable the network service provider to ensure only a limited number of users are able to operate via a UE subscription (e.g. SUPI or the like).

[0038] Another object of embodiments herein is to disclose the network architecture to enable the network service provider to work with 3rdparty user identities.

[0039] Another object of embodiments herein is to disclose the network architecture to enable the network service providers to perform user validation at an application layer.

[0040] Another object of embodiments herein is to disclose the network architecture to enable the network service provider to enable third parties to initiate authentication when a user accesses a 3rdparty application.

[0041] Another object of embodiments herein is to disclose the network architecture to enable the network service provider to restrict some users when the associated UE is roaming.

[0042] Another object of embodiments herein is to support a metaverse service that will require human user validation by a 5GC.

[0043] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating at least one embodiment and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein without departing from the scope thereof, and the embodiments herein include all such modifications.

[0044] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.

[0045] The words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.,", "i.e.," are merely used herein to mean "serving as an example, instance, or illustration. Any embodiment or implementation of the present subject matter described herein using the words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.," , "i.e.," is not necessarily to be construed as preferred or advantageous over other embodiments.

[0046] Embodiments herein may be described and illustrated in terms of blocks which carry out a described function or functions. These blocks, which may be referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by a firmware. The circuits may, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments may be physically separated into two or more interacting and discrete blocks without departing from the scope of the disclosure. Likewise, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the disclosure.

[0047] It should be noted that elements in the drawings are illustrated for the purposes of this description and ease of understanding and may not have necessarily been drawn to scale. For example, the flowcharts / sequence diagrams illustrate the method in terms of the steps required for understanding of aspects of the embodiments as disclosed herein. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein. Furthermore, in terms of the system, one or more components / modules which comprise the system may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0048] The accompanying drawings are used to help easily understand various technical features and it should be understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the present disclosure should be construed to extend to any modifications, equivalents, and substitutes in addition to those which are particularly set out in the accompanying drawings and the corresponding description. Usage of words such as first, second, third etc., to describe components / elements / steps is for the purposes of this description and should not be construed as sequential ordering / placement / occurrence unless specified otherwise.

[0049] Throughout this document, the term "User" is used to indicate to a human, device, or application, which is connecting to the network via a User Terminal (e.g. cell phone). The term "UE" is used to indicate a User Terminal (e.g. cell phone) configured with subscription to access the network in, e.g. a SIM.

[0050] The embodiments herein achieve systems and methods for enabling a 3GPP standards-based wireless network for identifying human users, devices or applications that are accessing the network provided services through a UE with a subscription to the network, in order to provide differentiated services. Further, the embodiment herein discloses system and method verifying and confirming that a user accessing a network is who they claim to be (authentication) and ensuring they have proper permission to use the services they are trying to access (authorization). The advancement provides robust security, optimize resource allocation, and enhances the overall user experience, making the network smarter and more responsive to individual differential needs while accessing the services from same devices at different times.

[0051] The proposed method can be used to support a metaverse service that will require human user validation by a 5GC. For example, the authentication server determines if it needs to ensure that the user (e.g. first human) is indeed the one he / she is claiming to be (i.e. User-ID), before granting access to application, for example any high-throughput data (e.g. whether to allow user to access a metaverse service). Based on any or all of the User-ID (e.g. from the domain-name contained in the User-ID which may take form <user-id@domain.com>), A-KID (which may contain the network identity) or GPSI, the UAF entity receives the user ID from the AF entity and then select authentication server. The details explained is provided in the FIG. 3 and FIG. 4.

[0052] Embodiments herein introduce two network functions into a 3GPP packet core architecture. A first Network function is a user information database. The user information database may be owned by the network service provider, or a 3rdparty which the operator may have a partnership with. For the purpose of illustration, this database is called AuF (Authentication Function) entity. The AuF entity holds User subscription information, User authentication information etc. This network function is independent and different from a unified data repository (UDR) / unified data management (UDM), which holds a UE Subscription database.

[0053] Referring now to the drawings, and more particularly to FIGS. 1 through 13, where similar reference characters denote corresponding features consistently throughout the figures, there are shown embodiments.

[0054] FIG. 1 illustrates an example of an Authentication Server (100) depicting how information is stored in a User Subscription database, according to embodiments of the present disclosure. The authentication data may include a selected authentication method (e.g., Extensible Authentication Protocol (EAP)), authentication vectors and other possible parameters. The EAP is a procedure used to path authentication information like the user entered password between the user and the authentication server (100).

[0055] The Subscription data may include:

[0056] Allowed UEs (Terminals a User is allowed to connect from);

[0057] Allowed countries from where User is allowed to connect from (which may be identified using, e.g. MCC); and

[0058] Allowed PLMNs (Serving Networks) User is allowed to connect from.

[0059] The Authentication Server (100) is proposed to expose REST based APIs to allow other network functions perform read and / or write operations into the network function. The Authentication Server (100) can be co-located with other network functions like UDM / UDR, or the functionality of AuF entity may be combined into UDM / UDR, e.g. by defining additional services. Alternatively, the functionality provided may be split into multiple new or existing network functions.

[0060] In addition to the above, the UE subscription data, which is stored in UDM / UDR, is enhanced to include the following additional information:

[0061] Type of Users (Human / Machine) allowed us to use the UE;

[0062] Allowed User Identities (Users allowed to connect using this subscription);

[0063] Allowed User Domain Names (User Domains allowed to connect using this subscription);

[0064] Maximum simultaneous Users / Devices; and

[0065] The UAF / AuF is responsible for interfacing with the AuF of the (e.g. human) User.

[0066] The second network function, as disclosed herein, is responsible for managing user authentication. For the purpose of illustration, this network function is called the UAF (User Authentication Function) (200). The UAF entity is responsible for selecting and interfacing with authentication server (100), for example AuF entity (500), for triggering User Authentication and interfacing with 5GC, e.g. UDM entity (600) for UE (400) level subscription validation etc. In an embodiment, the UAF entity and / or AuF entity selection can be based on User's Domain Name and / or the UE's Home Network. The UAF entity (200) is proposed to expose REST based APIs to allow other network functions perform read and / or write operations into the network function. This may include e.g., exposing an API to allow an AF trigger User Authentication and Authorization request. The UAF entity (200) can be co-located with other network functions like AUSF / UDM / AAnF or the functionality can be combined with such network functions. Alternatively, the functionality provided may be split into multiple new or existing network functions.

[0067] FIG. 2 illustrates an example network architecture for user-authentication and / or authorization procedure in a wireless network, according to embodiments of the present disclosure

[0068] With these additional network functions, FIG. 2 illustrates proposed network architectures for roaming and non-roaming scenarios, according to embodiments of the present disclosure; the network functions which are expected to be majorly involved in a user's authentication and / or authorization procedure. In this architecture, the User Authentication and / or Authorization is triggered by an application function towards UAF entity (200). UAF entity (200) then interfaces with the AuF entity (500) to perform the required functions. The proposed network architecture (1000) outlined key network functions involved in user authentication and authorization process. The authentication is initiated by an Application Function (300), which triggers the User Authentication Function (UAF) entity (200). The UAF entity (200) interacts with the Authentication Server (100) and Authentication Server Function (AUSF) entity (302) to validate credentials using data stored in the Unified Data Repository (UDR) entity (602). The Unified Data Management (UDM) entity (600) manages user data, while the Session Management Function (SMF) entity (104) handles session control. The Network Exposure Function (NEF) entity (106) enables external network communication, and the Policy Control Function (PCF) entity (108) governs policies. The Access and Mobility Management (AMF) entity (102) manages mobility, and the user plane function (UPF) entity (604) directs user-plane traffic.

[0069] In an embodiment, for the case of roaming, it is possible for the UAF entity (200) in the VPLMN to have an interfaces with the HPLMN UAF (H-UAF) to trigger the User Authentication and / or Authorization functions. In another embodiment, if the AF entity (300) is outside the operator domain, using the NEF services, the AF reaches out to the home UAF entity (200) for triggering the User Authentication and / or Authorization procedure.

[0070] FIG. 3 illustrates a sequence diagram for user-authentication and / or authorization procedure in a wireless network (1000), according to embodiments of the present disclosure. The authentication server (100), for example, User Identity Function (UIDF) entity receives a user authentication request from a Unified Authentication Function (UAF) entity (200), which contains essential details such as a User ID linked to the User Equipment (UE) (400). Upon receiving this request, the Authentication Server (100) initiates the authentication process by interacting with the UE (400) through Application Function (AF) entity (300), ensuring the identity of the user corresponds to the provided User ID. During this verification, the user's identity is authenticated based on the User ID. If the authentication fails, an error message is generated to indicate the failure and is sent to the UE (400). Conversely, if the authentication is successful, a success response is created. The result of the authentication, whether successful or an error, is then conveyed back to the UAF entity (200). Finally, the UAF entity (200) forwards the authentication result to an Application Function (AF) entity (300), enabling it to proceed based on the user's authentication status.

[0071] At step 1, the UE (400) Registers to the network and establishes a PDU Session.

[0072] At step 2, the User (e.g. a human user) accesses the UE (400) by implementing specific means (e.g. by tapping on the application or the like), and starts communicating with an application function. The communication between UE (400) and the application function (AF) entity (300) is over data-path (e.g. from UE to UPF to the application function). The communication could be the start of a session establishment procedure (or an application-level) between the UE / User and the application function. The UE (400) provides the User-ID).

[0073] At step 3, the AF entity (300) determines that it needs to ensure that the user is indeed the one he is claiming to be (i.e. User-ID), before granting access to application. It selects a user authentication function (UAF) entity (200), which will handle User's authentication procedure, and proceeds with sending a User Authentication request to UAF entity (200) containing at-least the User-ID. The request may additionally include the GPSI of the UE (400). If AF entity (300) resides outside the trust-domain of network service provider, the request may be routed via an NEF entity (106), in which case the NEF entity (106) will be responsible for UAF entity (200) selection and then sending the request accordingly.

[0074] At step 4, the UAF entity (200) retrieves the UE's subscription data from AF entity (300). If the User is indeed allowed to use the UE then UAF shall proceed with authentication for the user.

[0075] At step 5, the UAF identifies the authentication server (100) based on the received User-ID and requests authentication server (100) to initiate User Authentication.

[0076] At step 6, the UE (400) and the authentication server (100) communicate to perform User Authentication. All the NFs will transparently forward the request between authentication server (100) and UE (400).

[0077] At step 7, the authentication server (100) provides results of authentication procedure to UAF entity (200). If the authentication was unsuccessful, the procedure stops here and authentication server (100) sends an error message to UAF entity (200), which then forwards it to AF entity (300) / NEF entity (106). If the authentication was successful, the authentication server (100) may provide the User's profile data to the UAF entity (200).

[0078] At step 8, the UAF entity (200) sending a successful response to the AF entity (300). AF entity (300) can then proceed with requesting specific QoS via PCF.

[0079] FIG. 4 illustrates an example sequence diagram for the user-authentication and / or authorization procedure in the wireless network, according to embodiments of the present disclosure. The UE (400) register with the network and establish a PDU session, during which a temporary identifier (T-KID) may be generated or assigned by either the 5GC or the UE (400) and registered with relevant network functions. A user accesses the UE (400) via specific means, initiating communication with an application function (AF) (300) over the data path, which may involve starting a session and including identifiers such as User-ID, UE identity, IP address, or PDU session ID. The UAF entity (200) validates the AF's (300) authorization to initiate authentication and forwards the User Authentication Request to an Authentication Function (AuF) (500), potentially involving third-party identity services. Upon successful authentication, the AuF entity (500) communicates the results and any user subscription data to the UAF (200), which performs further validations regarding the user's and UE's subscription, location, and device permissions. The UAF entity (200) may translate identifiers like T-KID or IP address into SUPI using network functions. Finally, the UAF entity (200) validates the user's subscription data against the User-ID and confirms whether the user can access the application, sending a successful response to the AF entity (300) if all checks pass.

[0080] In step 1, the UE (400) is registered with the network and a PDU Session is established. As part of any of these procedures, a temporary (key) identifier (T-KID) may be generated (in 5GC and / or UE), or assigned (by 5GC to the UE, or UE to the 5GC). Such an identifier may further be registered with AUSF / UDM / AAnF or at the UAF entity (200).

[0081] In step 2, a User (e.g. a human user) accesses the UE (400), by implementing specific means, and starts communicating with an application function. The communication between UE (400) and the application function is over data-path, from UE (400) to UPF to the application function. The AF entity (300) may be somewhere on Internet. The communication could be, e.g. start of a (application-level) session establishment procedure between the UE / User and the application function. The request includes the User-ID, which identifies e.g. the human user, and optionally the UE Identity. The request may optionally include the PDU session ID. User-ID may be an anonymous identity of the user, containing at-least a domain name to identify its identity provider. UE Identity could be a GPSI (General Public Subscription Identifier), or the T-KID from step 1.

[0082] In step 3, the AF entity (300) determines that it needs to ensure that the user (e.g. human) is indeed the one he / she is claiming to be (i.e. User-ID), before granting access to application (e.g. whether to allow user to access a metaverse service). Based on any or all of the User-ID (e.g. from the domain-name contained in the User-ID which may take form <user-id@domain.com>), A-KID (which may contain the network identity) or GPSI, it selects a UAF which will handle User's authentication request. AF entity (300) then proceeds with sending a User Authentication request towards UAF containing at-least the User-ID. It may additionally include the T-KID and / or GPSI and / or the IP address of the UE. If AF entity (300) resides outside the trust-domain of network service provider, the request may be routed via an NEF, in which case the NEF will be responsible for UAF entity (200) selection and then sending the request accordingly.

[0083] In step 4, the UAF entity (200) may validate if the AF entity (300) is allowed to initiate the User Authentication Request (e.g. based on information contained in the incoming request, or the AF entity (300) identity itself and / or based on the local configuration and / or based on the IP address of the AF). If not allowed, UAF may send an error message to NEF / AF. If allowed, UAF entity (200) identifies the AuF based on the received User-ID (e.g. from the domain-name contained in the User-ID). The AuF entity (500) could belong to a 3rd party if the operator partners with a 3rd party identity service. The UAF entity (200) then requests AuF entity (500) to initiate User Authentication by sending User Authentication Request to the AuF entity (500). The request includes at least the received User-ID.

[0084] In step 5, the UE (400) and the AuF entity (500) communicate to perform User Authentication. This communication procedure is outside the scope of this invention, and may entail, e.g. sending a PUSH message by the AuF entity (500) to the UE (400), whereby User is prompted to perform, e.g. biometric authentication. For the purpose of illustration, let us assume the procedure is completed and user is authenticated by the AuF entity (500).

[0085] In step 6, the AuF entity (500) provides result of authentication procedure to UAF entity (200). If the authentication was unsuccessful, the procedure stops here and AuF entity (500) sends an error message to UAF entity (200), which then forwards it to AF / NEF. If the authentication was successful, AuF entity (500) may provide the User's subscription data to the UAF entity (200) (as specified in FIG.1). The message may additionally include the actual user's identity if an anonymous User-ID was provided in Step #2.

[0086] In step 7, the UAF entity (200) performs User's subscription validation against parameters as defined in FIG.1. This may include validating whether User is allowed in the country and / or in the visited-network it is located in. It may additionally validate if the User is allowed to use the specific UE (400) from which it is accessing the application function. If not, the procedure stops here and UAF entity (200) sends an error message to the AF / NEF.

[0087] In step 8, the UAF retrieves the UE's subscription data from UDM. If a T-KID was provided in step 2, the UAF entity (200) may first translate T-KID to UE's GPSI and / or SUPI by communicating with AUSF / AAnF or UDM. Else, if T-KID was registered locally, it may translate the same locally. Alternatively, if an IP-Address was provided in step 2, the UAF entity (200) may consult BSF to translate the UE IP-Address to its SUPI.

[0088] In steps 9 and step 10, the UAF entity (200) performs validation of UE's subscription data (enhanced with User-ID information as specified earlier) against the User-ID. If the User is indeed allowed to use the UE (400), it proceeds with sending a successful response to the AF entity (300).

[0089] Thus, using the proposed method, a 3rdparty can request a network service provide to verify the identity of the human user that is trying to access its services.

[0090] FIG. 5A illustrates an example flow diagram (S5A00) for user-authentication and / or authorization procedure, according to embodiments of the present disclosure.

[0091] In step S5A02, the user authentication and authorization begin in a wireless communication network. In an embodiment herein, in step S5A04, the UE (400) registering with the network and establishing a PDU session, during which a temporary identifier (T-KID) may be generated or assigned by either the 5GC or the UE and registered with relevant network functions, in step S5A06. A user accesses the UE (400) via specific means, initiating communication with an application function (AF) entity (300) over the data path, which may involve starting a session and including identifiers such as User-ID, UE identity, IP address, or PDU session ID. In step S5A08, the AF entity (300) verifies the user's identity and selecting a User Authentication Function (UAF) entity (200) based on user's identifiers like User-ID, T-KID, or GPSI. If the AF is external to the network provider's trust domain, the NEF routes the request, as depicted in step S5A10. The UAF entity (200) validates the AF's authorization to initiate authentication and forwards the User Authentication Request to the Authentication Function (AuF) entity (500), potentially involving third-party identity services, depicted in step S5A12.

[0092] In step S5A14, the UE (400) and AuF entity (500) then conduct the user authentication, possibly through biometric verification. In step S5A14, upon the successful authentication, the AuF entity (500) communicates the results and any user subscription data to the UAF entity (200), which performs further validations regarding the user's and UE's subscription, location, and device permissions. The UAF entity (200) may translate identifiers like T-KID or IP address into SUPI using network functions. In step S5A16, the UAF entity (200) validates the user's subscription data against the User-ID and confirms whether the user is allowed to use the UE, sending a successful response to the AF entity (300) if all checks pass. In other words, for example, the authentication server (100) authenticates the user to check really the user is what it claims by sending user id but the UAF entity (200) checks whether the user is allowed to use the UE (400) because some UE (100) is given access for specific users like user1, user2 and user 3.

[0093] FIG. 5B illustrates an example flow diagram (S5B00) for user-authentication and / or authorization procedure, according to embodiments of the present disclosure.

[0094] In step S5B02, the Unified Authentication Function (UAF) entity (200) sends the user authentication request to the authentication server, containing the User-ID linked to the User Equipment (UE) (400). Once the request is received by the authentication server, it proceeds to initiate for Authentication Process. In step S5B04, the authentication server (100) triggers the authentication towards the UE (400) after receiving from the UAF entity (200). In an example, if the authentication is done, the authentication server (100) interacts with the UE (400) to verify the user identity.

[0095] If the User Identity corresponds to the provided User-ID (step S5B08), it proceeds to the next step, else generate an error message indicating authentication failure and return to the UAF entity (200). In step S5B12, a success response is created and returned to UAF entity (200), if not, an error message is generated indicating authentication failure and return to the UAF entity (200) (in step SS5B10). Further, in step S5B16, UAF entity (200) processes the result and forwards it to the AF entity (300) (in step S5B18. In step S5B22, AF entity (300) proceeds by providing QoS differentiation based on the user's successful authentication status, if not, then QoS differentiation is not given, as depicted in step S5B20.

[0096] FIG. 6 illustrates various hardware components of the authentication server (100), according to the embodiments of the present disclosures. The authentication server (100) can be, for example, but not limited to the UIDF entity (200) and the AuF entity (500). In an embodiment, the authentication server (100) includes a processor (110), a memory (120), and an authentication controller (130). The processor (110) is coupled with the memory (120), and the authentication controller (130). However, the components of the authentication server are not limited thereto. For example, the authentication server may include more or fewer components than those described above.

[0097] The authentication controller (130) determines that the authentication (100) receive the user authentication request from the UAF entity (200). The user authentication request includes at least a User-ID associated with the UE (400). The user authentication request also includes the GPSI.

[0098] Further, the authentication controller (130) initiates the user authentication by communicating with the UE (400) based on the user authentication request. The user authentication is performed by verifying an identity of the user request corresponding to the received User-ID.

[0099] Further, the authentication controller (130) provides the result of authentication procedure to the UAF entity (200). The result of the authentication procedure includes one of: an error message to the UAF entity (200), and a successful message including a user profile data to the UAF entity (200).

[0100] Further, the authentication controller (130) forwards the error message to at least one of: the AF entity (300), and the NEF entity (106) through the UAF entity (200).

[0101] The authentication server (100) includes user subscription information, user authentication information, current authentication status of the user, and context data. The user subscription information includes at least one the UE (400) that the user is allowed to use, and the user authentication information includes at least one selected authentication procedure, and at least one authentication vector.

[0102] The authentication controller (130) is implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by firmware.

[0103] The processor (110) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (110) may include multiple cores and is configured to execute the instructions stored in the memory (120).

[0104] Further, the processor (110) is configured to execute instructions stored in the memory (120) and to perform various processes. The memory (120) also stores instructions to be executed by the processor (110). The memory (120) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (120) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory (120) is non-movable. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0105] Although FIG. 6 shows various hardware components of the authentication server (100) but it is to be understood that other embodiments are not limited thereon. In other embodiments, the authentication server (100) may include less or more number of components. Further, the labels or names of the components are used only for illustrative purposes and does not limit the scope of the invention. One or more components can be combined together to perform the same or substantially similar function in the authentication server (100).

[0106] FIG. 7 illustrates various hardware components of the UAF entity (200), according to the embodiments of the present disclosure. In an embodiment, the UAF (200) includes a processor (210), a memory (220), and an authentication controller (230). The processor (210) is coupled with the memory (220), and the authentication controller (230). However, the components of the UAF entity are not limited thereto. For example, the UAF entity may include more or fewer components than those described above.

[0107] The authentication controller (230) determines that the UAF entity (200) receive the user authentication request from the AF entity (300). The user authentication request includes the User-ID, and the UE ID. Further, the authentication controller (230) is configured to validate whether the user of the UE (400) is allowed to use the UE (400). Further, the authentication controller (230) identifies the authentication server (400) based on the received User-ID.

[0108] Further, the authentication controller (230) transmits the authentication request to the authentication server (400) to initiate user authentication based on the identification.

[0109] Additionally, the authentication controller (230) receives the authentication result from the authentication server (400) based on the authentication request. The authentication result of the authentication procedure comprises one of: the error message, and the successful message including a user profile data.

[0110] In an embodiment, the authentication controller (230) validates the profile of the user, where validating the profile of the user includes checking if the user is allowed to use the UE (400). In an embodiment,

[0111] the authentication controller (230) provides the successful authentication response to the AF entity (300) to enable access to the application running in the UE (400).

[0112] In an embodiment, the authentication controller (230) identifies the authentication server (100) based on the received User-ID, where the UAF entity (200) requests the authentication server (100) to initiate the user authentication by sending the request to the authentication server (100).

[0113] In an embodiment, the authentication controller (230) initiates communication between the UE (400) and the authentication server (100) to perform the user authentication. The communication between the UE (400) and the AF entity (300) is over a data-path. When the AF entity (300) resides outside the trust domain of the network service provider, the authentication request is routed via the NEF entity (106) that is responsible for UAF selection and request transmission.

[0114] The authentication controller (230) is implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by firmware.

[0115] The processor (210) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (210) may include multiple cores and is configured to execute the instructions stored in the memory (220).

[0116] Further, the processor (210) is configured to execute instructions stored in the memory (220) and to perform various processes. The memory (220) also stores instructions to be executed by the processor (210). The memory (220) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (220) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory (220) is non-movable. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0117] Although FIG. 7 shows various hardware components of the UAF entity (200) but it is to be understood that other embodiments are not limited thereon. In other embodiments, the UAF entity (200) may include less or more number of components. Further, the labels or names of the components are used only for illustrative purposes and does not limit the scope of the invention. One or more components can be combined together to perform the same or substantially similar function in the UAF entity (200).

[0118] FIG. 8 illustrates various hardware components of the AF entity (300), according to the embodiments of the present disclosure. In an embodiment, the AF entity (300) includes a processor (310), a memory (320), and an authentication controller (330). The processor (310) is coupled with the memory (320), and the authentication controller (330). However, the components of the AF entity are not limited thereto. For example, the AF entity may include more or fewer components than those described above.

[0119] The authentication controller (330) determines that the AF entity (300) receive the request from the UE (400) wherein the request comprises at least one of: the User-ID, and the UE ID.

[0120] The authentication controller (330) selects the UAF entity (200) to handle the user authentication procedure based on the received User-ID. Further, the authentication controller (330) sends the authentication request to the UAF entity (200), where the request includes at least the User-ID and the UE ID.

[0121] Additionally, the authentication controller (330) receives the authentication response based on the user authentication request. The authentication response includes one of: the error message, and the successful message including the user profile data.

[0122] Further, the authentication controller (330) routes the user authentication request via the NEF entity (106) responsible for UAF entity (200) selection and request transmission, when the AF entity (300) resides outside the trust domain of the network service provider.

[0123] The processor (310) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (310) may include multiple cores and is configured to execute the instructions stored in the memory (330).

[0124] Further, the processor (310) is configured to execute instructions stored in the memory (330) and to perform various processes. The memory (330) also stores instructions to be executed by the processor (310). The memory (330) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (330) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory (330) is non-movable. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0125] Although FIG. 8 shows various hardware components of the AF entity (300) but it is to be understood that other embodiments are not limited thereon. In other embodiments, the AF entity (300) may include a less or more number of components. Further, the labels or names of the components are used only for illustrative purposes and does not limit the scope of the invention. One or more components can be combined together to perform the same or substantially similar function in the AF entity (300).

[0126] FIG. 9 illustrates various hardware components of the UE (400), according to the embodiments of the present disclosure. The UE (400) can be, for example, but not limited to a laptop, a desktop computer, a notebook, a Device-to-Device (D2D) device, a vehicle to everything (V2X) device, a smartphone, a foldable phone, a smart TV, a tablet, an immersive device, and an internet of things (IoT) device. In an embodiment, the UE (400) includes a processor (410), a memory (420), and an authentication controller (430). The processor (410) is coupled with the memory (420), and the authentication controller (430). However, the components of the UE are not limited thereto. For example, the UE may include more or fewer components than those described above.

[0127] The authentication controller (430) configured to register to the network to establish the PDU session with the network.

[0128] Further, the authentication controller (430) sends a request to the AF entity (300), where the request comprises at least one of: the User-ID, and the UE ID.

[0129] Further, the authentication controller (430) receives the user authentication message by communicating with the authentication server (100) based on the request.

[0130] Additionally, the authentication controller (430) receives the authentication response based on the authentication message. The authentication response includes one of: the error message, and the successful message including the user profile data.

[0131] The processor (410) may include one or a plurality of processors. The one or the plurality of processors may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an AI-dedicated processor such as a neural processing unit (NPU). The processor (410) may include multiple cores and is configured to execute the instructions stored in the memory (430).

[0132] Further, the processor (410) is configured to execute instructions stored in the memory (430) and to perform various processes. The memory (430) also stores instructions to be executed by the processor (410). The memory (430) may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In addition, the memory (430) may, in some examples, be considered a non-transitory storage medium. The term "non-transitory" may indicate that the storage medium is not embodied in a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted that the memory (430) is non-movable. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in Random Access Memory (RAM) or cache).

[0133] Although FIG. 9 shows various hardware components of the UE (400) but it is to be understood that other embodiments are not limited thereon. In other embodiments, the UE (400) may include a less or more number of components. Further, the labels or names of the components are used only for illustrative purposes and does not limit the scope of the invention. One or more components can be combined together to perform the same or substantially similar function in the UE (400).

[0134] FIG. 10 is a flow chart (S1000) illustrating a method for user-authentication and / or authorization procedure, according to the embodiments of the present disclosure. The operations S1002, S1004 and S1006 are handled by the authentication server (100).

[0135] At S1002, the method includes receiving the user authentication request from the UAF entity (200). The user authentication request includes at least one User identifier (ID) associated with the UE (400).

[0136] At S1004, the method includes initiating the user authentication by communicating with the UE (400) based on the user authentication request. The user authentication is performed by verifying the identity of a user request corresponding to the received User-ID.

[0137] At S1006, the method includes providing a result of authentication procedure to the UAF entity (200), wherein the result of the authentication procedure comprises one of: an error message to the UAF entity (200), and a successful message including a user profile data to the UAF entity (200).

[0138] In an embodiment herein, the method comprises forwarding, by the authentication server, the error message to at least one of: an Application Function (AF) entity (300), and a Network Exposure Function (NEF) entity through the UAF entity.

[0139] FIG. 11 is a flow chart (S1100) illustrating a method for user-authentication and / or authorization procedure, according to the embodiments of the present disclosure. The operations S1102, S1104, S1106 and S1108 are handled by the User Authentication Function UAF entity (200).

[0140] At 1102, the method includes receiving a user authentication request from an Application Function (AF) entity, wherein the user authentication request comprises at least one of: a User-ID, and a User Equipment (UE) ID.

[0141] At 1104, the method includes validating whether the user of the UE is allowed to use the UE (400).

[0142] At 1106, the method includes identifying an authentication server based on the received User-ID.

[0143] At 1108, the method includes transmitting the authentication request to the authentication server to initiate user authentication based on the identification. At 1110, the method includes receiving an authentication result from the authentication server based on the authentication request, wherein the authentication result of the authentication procedure comprises one of: an error message, and a successful message including a user profile data.

[0144] In an embodiment herein, the method comprises validating, by the UAF entity, a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE (400). In an embodiment herein, the method comprises providing, by the UAF entity, the successful authentication response to the AF entity (300) to enable access to an application running in the UE (400). In an embodiment herein, the method comprises identifying, by the UAF entity (200), an authentication server based on the received User-ID, wherein the UAF entity (200) requests the authentication server to initiate a user authentication by sending the request to the authentication server.

[0145] In an embodiment herein, the method comprises initiating, by the UAF entity (200), communication between a UE (400) and an authentication server to perform user authentication, wherein communication between a UE and the application function (AF) entity (300) is over a data-path. In an embodiment herein when the AF entity (300) resides outside a trust domain of a network service provider, the authentication request is routed via a Network Exposure Function (NEF) that is responsible for UAF selection and request transmission.

[0146] FIG. 12 is a flow chart (S1200) illustrating a method for user-authentication and / or authorization procedure, according to the of the present disclosure. The operations S1202, S1204, S1206 and S1208 are handled by the Application Function (300).

[0147] At 1202, the method includes receiving a request from a user equipment (UE), wherein the request comprises at least one of: a User-ID, and a UE ID.

[0148] At 1204, the method includes selecting a Unified Authentication Function (UAF) entity to handle a user authentication procedure based on the received User-ID.

[0149] At 1206, the method includes sending an authentication request to the UAF entity, wherein the request comprises at least the User-ID, and the UE ID.

[0150] At 1208, the method includes receiving an authentication response based on the user authentication request, wherein the authentication response comprises one of: an error message, and a successful message including a user profile data

[0151] In an embodiment herein, the communication between the UE and the AF entity is over data-path. In an embodiment herein, the method comprises routing the user authentication request via a Network Exposure Function (NEF) responsible for UAF entity selection and request transmission, when the AF resides outside a trust domain of a network service provider.

[0152] FIG. 13 is a flow chart (S1300) illustrating a method for user-authentication and / or authorization procedure, according to the embodiments of the present disclosure. The operations S1302, S1304, S1306, S1308 and S1310 are handled by the UE (400)

[0153] At S1302, the method includes registering with a network. At S1304, the method includes establishing the PDU session with the network.

[0154] At S1306, the method includes sending a request to an Application Function (AF) entity, wherein the request comprises at least one of: a User-ID, and a UE ID. At S1308, the method includes receiving the user authentication message by communicating with the authentication server (100) based on the request.

[0155] At S1310, the method includes receiving an authentication response based on the authentication message, wherein the authentication response comprises one of: an error message and a successful message including a user profile data.

[0156] FIG. 14 illustrates a block diagram of a terminal (or a user equipment (UE)), according to embodiments of the present disclosure. FIG. 14 corresponds to the example of the UE of FIG. 9.

[0157] As shown in FIG. 14, the UE according to an embodiment may include a transceiver 1410, a memory 1420, and a processor 1430. The transceiver 1410, the memory 1420, and the processor 1430 of the UE may operate according to a communication method of the UE described above. However, the components of the UE are not limited thereto. For example, the UE may include more or fewer components than those described above. In addition, the processor 1430, the transceiver 1410, and the memory 1420 may be implemented as a single chip. Also, the processor 1430 may include at least one processor.

[0158] The transceiver 1410 collectively refers to a UE receiver and a UE transmitter, and may transmit / receive a signal to / from a base station or a network entity. The signal transmitted or received to or from the base station or a network entity may include control information and data. The transceiver 1410 may include a RF transmitter for up-converting and amplifying a frequency of a transmitted signal, and a RF receiver for amplifying low-noise and down-converting a frequency of a received signal. However, this is only an example of the transceiver 1410 and components of the transceiver 1410 are not limited to the RF transmitter and the RF receiver.

[0159] Also, the transceiver 1410 may receive and output, to the processor 1430, a signal through a wireless channel, and transmit a signal output from the processor 1430 through the wireless channel.

[0160] The memory 1420 may store a program and data required for operations of the UE. Also, the memory 1420 may store control information or data included in a signal obtained by the UE. The memory 1420 may be a storage medium, such as read-only memory (ROM), random access memory (RAM), a hard disk, a CD-ROM, and a DVD, or a combination of storage media.

[0161] The processor 1430 may control a series of processes such that the UE operates as described above. For example, the transceiver 1410 may receive a data signal including a control signal transmitted by the base station or the network entity, and the processor 1430 may determine a result of receiving the control signal and the data signal transmitted by the base station or the network entity.

[0162] FIG. 15 illustrates a block diagram of a network entity, according to embodiments of the present disclosure. FIG. 15 corresponds to the example of the authentication server of FIG. 6, UAF of FIG. 7 or AF of FIG.8. Also network entity may include base station(BS).

[0163] As shown in FIG. 15, the network entity according to an embodiment may include a transceiver 1510, a memory 1520, and a processor 1530. The transceiver 1510, the memory 1520, and the processor 1530 of the network entity may operate according to a communication method of the network entity described above. However, the components of the network entity are not limited thereto. For example, the network entity may include more or fewer components than those described above. In addition, the processor 1530, the transceiver 1510, and the memory 1520 may be implemented as a single chip. Also, the processor 1530 may include at least one processor.

[0164] The transceiver 1510 collectively refers to a network entity receiver and network entity transmitter, and may transmit / receive a signal to / from a terminal or a network entity. The signal transmitted or received to or from the terminal or a network entity may include control information and data. The transceiver 1510 may include a RF transmitter for up-converting and amplifying a frequency of a transmitted signal, and a RF receiver for amplifying low-noise and down-converting a frequency of a received signal. However, this is only an example of the transceiver 1510 and components of the transceiver 1510 are not limited to the RF transmitter and the RF receiver.

[0165] Also, the transceiver 1510 may receive and output, to the processor 1530, a signal through a wireless channel, and transmit a signal output from the processor 1530 through the wireless channel.

[0166] The memory 1520 may store a program and data required for operations of the network entity. Also, the memory 1520 may store control information or data included in a signal obtained by the network entity. The memory 1520 may be a storage medium, such as read-only memory (ROM), random access memory (RAM), a hard disk, a CD-ROM, and a DVD, or a combination of storage media.

[0167] The processor 1530 may control a series of processes such that the network entity operates as described above. For example, the transceiver 1510 may receive a data signal including a control signal transmitted by the terminal, and the processor 1530 may determine a result of receiving the control signal and the data signal transmitted by the terminal.

[0168] In one example, the embodiments herein provide a method for handling user authentication in a wireless communication network. The method includes receiving, by an authentication server, a user authentication request from a Unified Authentication Function (UAF) entity. The user authentication request includes at least one User identifier (ID) associated with a User Equipment (UE). Further, the method includes initiating, by the authentication server, user authentication by communicating with the UE based on the user authentication request. The user authentication is performed by verifying an identity of a user request corresponding to the received User-ID. Further, the method includes providing, by the authentication server, a result of authentication procedure to the UAF entity. The result of the authentication procedure includes one of: an error message to the UAF entity, and a successful message including a user profile data to the UAF entity.

[0169] In another example, wherein the method comprises forwarding, by the authentication server (100), the error message to at least one of: an Application Function (AF) entity (300), and a Network Exposure Function (NEF) entity (106) through the UAF entity (200).

[0170] In another example, wherein the user authentication request comprises a General Public Subscription Identifier (GPSI), wherein the authentication server (100) comprises one of: a User Identity Function (UIDF) entity (200) and an Authentication Function (AuF) entity (500).

[0171] In another example, wherein the authentication server (100) comprises user subscription information, user authentication information, current authentication status of the user, and context data, wherein the user subscription information comprises at least one the UE (400) that the user is allowed to use, and the user authentication information comprises at least one selected authentication procedure, and at least one authentication vector.

[0172] In one example, the embodiments herein provide a method for handling user authentication in a wireless communication network. The method includes receiving, by a UAF entity, a user authentication request from an AF entity. The user authentication request includes at least one of: a User-ID, and a UE ID. Further, the method includes validating, by the UAF entity, whether the user of the UE is allowed to use the UE. Further, the method includes identifying, by the UAF entity, an authentication server based on the received User-ID. Further, the method includes transmitting, by the UAF entity, the authentication request to the authentication server to initiate the user authentication based on the identification. Further, the method includes receiving, by the UAF entity, an authentication result from the authentication server based on the authentication request. The authentication result of the authentication procedure includes one of: an error message, and a successful message including a user profile data.

[0173] In another example, wherein the method comprises validating, by the UAF entity (200), a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE (400).

[0174] In another example, wherein the method comprises providing, by the UAF entity (200), the successful authentication response to the AF entity (300) to enable access to an application running in the UE (400).

[0175] In another example, wherein the method comprises identifying, by the UAF entity (200), the authentication server (100) based on the received User-ID, wherein the UAF entity (200) requests the authentication server (100) to initiate the user authentication by sending the request to the authentication server (100).

[0176] In another example, wherein the method comprises initiating, by the UAF entity (200), communication between a UE (400) and the authentication server (100) to perform the user authentication, wherein communication between a UE (400) and the application function (AF) entity (300) is over a data-path.

[0177] In another example, wherein when the AF entity (300) resides outside a trust domain of a network service provider, the authentication request is routed via a Network Exposure Function (NEF) entity (106) that is responsible for UAF selection and request transmission.

[0178] In one example, the embodiments herein provide a method for handling user authentication in a wireless communication network. The method includes receiving, by an Application Function (AF) entity, a request from a UE. The request includes at least one of: a User-ID, and a UE ID. Further, the method includes selecting, by the AF entity, a UAF entity to handle a user authentication procedure based on the received User-ID. Further, the method includes sending, by the AF entity, an authentication request to the UAF entity, where the request includes at least the User-ID, and the UE ID. Further, the method includes receiving, by the AF entity, an authentication response based on the user authentication request. The authentication response includes one of: an error message, and a successful message including a user profile data.

[0179] In another example, wherein the communication between the UE (400) and the AF entity (300) is over data-path.

[0180] In another example, wherein the method comprises routing the user authentication request via a Network Exposure Function (NEF) entity (106) responsible for UAF entity (200) selection and request transmission, when the AF entity (300) resides outside a trust domain of a network service provider.

[0181] In one example, the embodiments herein provide a method for handling a user authentication in a wireless communication network. The method includes registering, by a UE, with a network. Further, the method includes establishing, by the UE, a PDU session with the network. Further, the method includes sending, by the UE, a request to an AF entity, where the request includes at least one of: a User-ID, and a UE ID. Further, the method includes receiving, by the UE, user authentication message by communicating with an authentication server based on the request. Further, the method includes receiving, by the UE, an authentication response based on the authentication message, wherein the authentication response comprises one of: an error message and a successful message including a user profile data.

[0182] In one example, the embodiments herein provide an authentication server including an authentication controller coupled with a processor and a memory. The authentication controller is configured to receive a user authentication request from a UAF entity. The user authentication request includes at least one ID associated with the UE. Further, the authentication controller is configured to initiate user authentication by communicating with the UE based on the user authentication request. The user authentication is performed by verifying an identity of a user request corresponding to the received User-ID. Further, the authentication controller is configured to provide a result of authentication procedure to the UAF entity. The result of the authentication procedure comprises one of: an error message to the UAF, and a successful message including a user profile data to the UAF entity.

[0183] In one example, the embodiments herein provide a UAF entity comprising an authentication controller coupled with a processor and a memory. The authentication controller is configured to receive a user authentication request from an AF entity, where the user authentication request includes a User-ID, and a UE ID. Further, the authentication controller is configured to validate whether the user of the UE is allowed to use the UE. Further, the authentication controller is configured to identify an authentication server based on the received User-ID. Further, the authentication controller is configured to transmit the authentication request to the authentication server to initiate user authentication based on the identification. Further, the authentication controller is configured to receive an authentication result from the authentication server based on the authentication request, where the authentication result of the authentication procedure comprises one of: an error message, and a successful message including a user profile data.

[0184] In one example, the embodiments herein provide an AF entity including an authentication controller coupled with a processor and a memory. Further, the authentication controller is configured to receive a request from a UE where the request comprises at least one of: a User-ID, and a UE ID. Further, the authentication controller is configured to select a UAF entity to handle a user authentication procedure based on the received User-ID. Further, the authentication controller is configured to send an authentication request to the UAF entity, where the request comprises at least the User-ID and UE ID. Further, the authentication controller is configured to receive an authentication response based on the user authentication request, wherein the authentication response comprises one of: an error message, and a successful message including a user profile data.

[0185] In one example, the embodiments herein provide a UE including an authentication controller coupled with a processor and a memory. The authentication controller is configured to register to a network. Further, the authentication controller is configured to establish a PDU session with the network. Further, the authentication controller is configured to send a request to an AF entity, where the request includes at least one of: a User-ID, and a UE ID. Further, the authentication controller is configured to receive user authentication message by communicating with an authentication server based on the request. Further, the authentication controller is configured to receive an authentication response based on the authentication message, wherein the authentication response comprises one of: an error message, and a successful message including a user profile data.

[0186] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.

[0187] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.

[0188] The embodiment disclosed herein describes systems and methods for enabling a 3GPP standards-based wireless network for identifying human users, devices or applications that are accessing the network provided services through a device with a subscription to the network, in order to provide differentiated services. Therefore, it is understood that the scope of the protection is extended to such a program and in addition to a computer readable means having a message therein, such computer readable storage means contain program code means for implementation of one or more steps of the method, when the program runs on a server or mobile deviceor any suitable programmable device. The method is implemented in at least one embodiment through or together with a software program written in e.g., Very high speed integrated circuit Hardware Description Language (VHDL) another programming language, or implemented by one or more VHDL or several software modules being executed on at least one hardware device. The hardware device can be any kind of portable device that can be programmed. The device may also include means which could be e.g., hardware means like e.g., an ASIC, or a combination of hardware and software means, e.g. an ASIC and an FPGA, or at least one microprocessor and at least one memory with software modules located therein. The method embodiments described herein could be implemented partly in hardware and partly in software. Alternatively, the invention may be implemented on different hardware devices, e.g., using a plurality of CPUs.

[0189] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of the embodiments as described herein.

Claims

1.A method for handling user authentication in a wireless communication network (101), the method comprising:receiving, by a User Authentication Function (UAF) entity (200), a user authentication request from an Application Function (AF) entity (300), wherein the user authentication request comprises at least one of: a User-ID, and a User Equipment (UE) ID;validating, by the UAF entity (200), whether the user of the UE (400) is allowed to use the UE (400);identifying, by the UAF entity (200), an authentication server (100) based on the received User-ID;transmitting, by the UAF entity (200), the authentication request to the authentication server (100) to initiate the user authentication based on the identification; andreceiving, by the UAF entity (200), an authentication result from the authentication server (100) based on the authentication request, wherein the authentication result of the authentication procedure comprises one of: an error message, and a successful message including a user profile data.2.The method of claim 1, wherein the method comprises validating, by the UAF entity (200), a profile of the user, wherein validating the profile of the user comprises checking if the user is allowed to use the UE (400).3.The method of claim 1, wherein the method comprises providing, by the UAF entity (200), the successful authentication response to the AF entity (300) to enable access to an application running in the UE (400).4.The method of claim 1, wherein the method comprises identifying, by the UAF entity (200), the authentication server (100) based on the received User-ID, wherein the UAF entity (200) requests the authentication server (100) to initiate the user authentication by sending the request to the authentication server (100).5.The method of claim 1, wherein the method comprises initiating, by the UAF entity (200), communication between a UE (400) and the authentication server (100) to perform the user authentication, wherein communication between a UE (400) and the application function (AF) entity (300) is over a data-path.6.The method of claim 1, wherein when the AF entity (300) resides outside a trust domain of a network service provider, the authentication request is routed via a Network Exposure Function (NEF) entity (106) that is responsible for UAF selection and request transmission.7.A method for handling a user authentication in a wireless communication network (101), the method comprising:registering, by a User Equipment (UE) (400), with a network;establishing, by the UE (400), a Packet Data Unit (PDU) session with the network;sending, by the UE (400), a request to an Application Function (AF) entity (300), wherein the request comprises at least one of: a User-ID, and a UE ID;receiving, by the UE (400), user authentication message by communicating with an authentication server (100) based on the request; andreceiving, by the UE (400), an authentication response based on the authentication message, wherein the authentication response comprises one of: an error message and a successful message including a user profile data.8.A User Authentication Function (UAF) entity (200), comprising:a processor (210);a memory (220); andan authentication controller (230) coupled with the processor (210) and the memory (220), configured to:receive a user authentication request from an Application Function (AF) entity (300), wherein the user authentication request comprises a User-ID, and a User Equipment (UE) ID;validate whether the user of the UE (400) is allowed to use the UE;identify an authentication server (100) based on the received User-ID;transmit the authentication request to the authentication server to initiate user authentication based on the identification; andreceive an authentication result from the authentication server based on the authentication request, wherein the authentication result of the authentication procedure comprises one of: an error message, and a successful message including a user profile data.9.The UAF entity of claim 8, configured to:validate, by the UAF entity (200), a profile of the user, wherein validate the profile of the user comprises checking if the user is allowed to use the UE (400).10.The UAF entity of claim 8, configured to:provide, by the UAF entity (200), the successful authentication response to the AF entity (300) to enable access to an application running in the UE (400).11.The UAF entity of claim 8, configured to:identify, by the UAF entity (200), the authentication server (100) based on the received User-ID, wherein the UAF entity (200) requests the authentication server (100) to initiate the user authentication by sending the request to the authentication server (100).12.The UAF entity of claim 8, configured to:initiate, by the UAF entity (200), communication between a UE (400) and the authentication server (100) to perform the user authentication, wherein communication between a UE (400) and the application function (AF) entity (300) is over a data-path.13.The UAF entity of claim 8, wherein when the AF entity (300) resides outside a trust domain of a network service provider, the authentication request is routed via a Network Exposure Function (NEF) entity (106) that is responsible for UAF selection and request transmission.14.A User Equipment (UE) (400), comprising:a processor (410);a memory (420); andan authentication controller (430) coupled with the processor (410) and the memory (420), configured to:register to a network;establish a Packet Data Unit (PDU) session with the network;send a request to an Application Function (AF) entity (300), wherein the request comprises at least one of: a User-ID, and a UE ID;receive user authentication message by communicating with an authentication server based on the request; andreceive an authentication response based on the authentication message, wherein the authentication response comprises one of: an error message, and a successful message including a user profile data.

Citation Information

Patent Citations

  • User identifier verification method and related device

    WO2021168829A1

  • Communication method and communication device

    WO2021197185A1

  • New method for external parameter provisioning for an AF session

    WO2022179367A1

  • Method and wireless network for application-specific authorization for network services in wireless network

    WO2023090799A1

  • Method and device for binding user and UE in mobile communication system

    WO2024019424A1