Methods for user authentication in wireless systems associated with users behind an RG or gateway

The system addresses unauthorized user authentication issues by using a network node to detect and verify devices through EAP, enhancing network security and data management for users behind a residential gateway.

WO2025175201A1PCT designated stage Publication Date: 2025-08-21INTERDIGITAL PATENT HOLDINGS INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/016080
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-15
Filing Date
2025-02-14
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in effectively authenticating users behind a residential gateway (RG) or gateway, particularly in detecting and managing unauthorized source MAC addresses, IP addresses, and port numbers, which can compromise network security and data integrity.

Method used

Implementing a system where a first network node receives an indication of a detected unauthorized address, initiates authentication through an extensible authentication protocol (EAP), and communicates with a wireless transmit/receive unit (WTRU) to verify the device's authorization, involving a session management function (SMF), user plane function (UPF), and authentication, authorization, and accounting (AAA) server to manage traffic authorization and charging.

Benefits of technology

Enhances network security by accurately identifying and authorizing devices, ensuring authorized traffic, and managing data usage, thereby improving overall system integrity and user authentication processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025016080_21082025_PF_FP_ABST
    Figure US2025016080_21082025_PF_FP_ABST
Patent Text Reader

Abstract

Systems, methods, and instrumentalities are configured for user authentication in wireless systems associated with users behind a residential gateway (RG) or gateway. A first network node may receive, from a second network node, a first message. The first message may include configuration information indicating that the first network node is to initiate an authorization procedure based on a detection of one or more of an unauthorized source MAC address, an unauthorized source IP address, or an unauthorized source port number. The first network node may send a second message including information associated with the detection. The first network node may receive a third message including an indication that a source wireless transmit receive unit (WTRU) is authorized. The first network node may transmit the source WTRU, a fourth message comprising at least one or more of a packet associated with the source WTRU or a call data record (CDR).
Need to check novelty before this filing date? Find Prior Art

Description

METHODS FOR USER AUTHENTICATION IN WIRELESS SYSTEMS ASSOCIATED WITH USERS BEHIND AN RG OR GATEWAYCROSS REFERENCE TO RELATED APPLICATIONS

[0001] This application claims the benefit of United States Patent Application No. 63 / 553,981 , filed February 15, 2024, the contents of which are hereby incorporated by reference herein.BACKGROUND

[0002] Mobile communications using wireless communication continue to evolve. A fifth generation may be referred to as 5G. A previous (legacy) generation of mobile communication may be, for example, a fourth generation (4G) long term evolution (LTE).SUMMARY

[0003] Systems, methods, and instrumentalities are configured for user authentication in wireless systems associated with users behind a residential gateway (RG) or gateway. In examples, a first network node may be configured to receive, from a second network node, an indication including a detected address. The first network node may determine that traffic associated with the detected address is unauthorized. The first network node may send, to a wireless transmit / receive unit (WTRU), a first message including the detected address and including an extensible authentication protocol (EAP) payload to initiate authentication of a device associated with the detected address. The first network node may receive, from the WTRU, a second message including an EAP response associated with the device. The first network node may send, to a third network node, a third message including the EAP response and the detected address. The first network node may receive, from the third network node, a fourth message indicating that the device is authenticated. The first network node may send, to the second network node, a fifth message indicating that traffic associated with the detected address is authorized.

[0004] The first network node may include a session management function (SMF). The second network node may include a user plane function (UPF). The third network node may include an authentication, authorization, and accounting (AAA) server. The detected address may include at least one of a source IP address, an IP address prefix, a source port number, or a MAC address associated with the WTRU. The first message may include a PDU session identifier associated with the WTRU, and the EAP payload in the first message may include an EAP identity request. The first message may be transmitted in a Non-AccessStratum Session Management (NAS-SM) message that includes a PDU session modification command directed to the WTRU. The EAP response may be included in the second message. The second message may include an EAP identity response. The EAP identity response may include information associated with identifying the third network node. The information associated with identifying the third network node may include one or more of the following: a domain identifier field, a mobile network operator (MNO) identifier, a service provider identifier, or an AAA server identifier. The fifth message may include a charging identifier received from the third network node. The charging identifier may be provided to the second network node for recording data usage associated with the WTRU.

[0005] The first network node may receive, from the third network node, a first EAP message. The first network node may send, to the WTRU, the first EAP message. The first EAP message may be forwarded to the device. The first network node may receive, from the WTRU, a second EAP message generated by the device. The second EAP message may correspond to the first EAP message. The first network node may send the second EAP message to the third network node. The first network node may send to the WTRU, based on the device being authenticated, a sixth message indicating the authentication result associated with the device.

[0006] Systems, methods, and instrumentalities are configured for user authentication in wireless systems associated with users behind a residential gateway (RG) or gateway. A first network node may receive, from a second network node, a first message. The first message may include configuration information indicating that the first network node is to initiate an authorization procedure based on a detection of one or more of an unauthorized source MAC address, an unauthorized source IP address, or an unauthorized source port number. The first network node may detect one or more of the unauthorized source MAC address, the unauthorized source IP address, or the unauthorized source port number. The first network node may send, to the second network node, a second message including information associated with the detection. The first network node may receive, from the second network node, a third message including an indication that a source wireless transmit receive unit (WTRU) associated with one or more of the detected unauthorized source MAC address, the unauthorized source IP address, or the unauthorized source port number is authorized. The indication may include a charging identifier. The first network node may transmit to the source WTRU a fourth message including at least one or more of a packet associated with the source WTRU, a call data record (CDR), or a charging identifier associated with the CDR.

[0007] The first network node may include a user plane function (UPF), and the second network node may include a session management function (SMF).

[0008] The third message may include the charging identifier. The information associated with the detection may include a source address and a PDU session ID. The source address and the PDU session ID may be associated with the source WTRU.BRIEF DESCRIPTION OF THE DRAWINGS

[0009] FIG. 1 A is a system diagram illustrating an example communications system in which one or more disclosed embodiments may be implemented.

[0010] FIG. 1 B is a system diagram illustrating an example wireless transmit / receive unit (WTRU) that may be used within the communications system illustrated in FIG. 1A according to an embodiment.

[0011] FIG. 1 C is a system diagram illustrating an example radio access network (RAN) and an example core network (CN) that may be used within the communications system illustrated in FIG. 1 A according to an embodiment.

[0012] FIG. 1 D is a system diagram illustrating a further example RAN and a further example CN that may be used within the communications system illustrated in FIG. 1A according to an embodiment.

[0013] FIG. 2 illustrates an example procedure for user plane function (UPF) triggered device authentication.

[0014] FIG. 3 illustrates an example procedure for a residential gateway (RG) triggered device authentication.

[0015] FIG. 4 illustrates an example procedure for continuing communication when a device address changes, and a user does not change.DETAILED DESCRIPTION

[0016] FIG. 1A is a diagram illustrating an example communications system 100 in which one or more disclosed embodiments may be implemented. The communications system 100 may be a multiple access system that provides content, such as voice, data, video, messaging, broadcast, etc., to multiple wireless users. The communications system 100 may enable multiple wireless users to access such content through the sharing of system resources, including wireless bandwidth. For example, the communications systems 100 may employ one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), zero-tail unique-word DFT-Spread OFDM (ZT UW DTS-s OFDM), unique word OFDM (UW-OFDM), resource block-filtered OFDM, filter bank multicarrier (FBMC), and the like.

[0017] As shown in FIG. 1A, the communications system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a RAN 104 / 113, a CN 106 / 115, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, though it will be appreciated that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment. By way of example, the WTRUs 102a, 102b, 102c, 102d, any of which may be referred to as a “station” and / or a “STA”, may be configured to transmit and / or receive wireless signals and may include a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a cellular telephone, a personal digital assistant (PDA), a smartphone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi-Fi device, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. Any of the WTRUs 102a, 102b, 102c and 102d may be interchangeably referred to as a UE.

[0018] The communications systems 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b may be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d to facilitate access to one or more communication networks, such as the CN 106 / 115, the I nternet 110, and / or the other networks 112. By way of example, the base stations 114a, 114b may be a base transceiver station (BTS), a Node-B, an eNode B, a Home Node B, a Home eNode B, a gNB, a NR NodeB, a site controller, an access point (AP), a wireless router, and the like. While the base stations 114a, 114b are each depicted as a single element, it will be appreciated that the base stations 114a, 114b may include any number of interconnected base stations and / or network elements.

[0019] The base station 114a may be part of the RAN 104 / 113, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), relay nodes, etc. The base station 114a and / or the base station 114b may be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be in licensed spectrum, unlicensed spectrum, or a combination of licensed and unlicensed spectrum. A cell may provide coverage for a wireless service to a specific geographical area that may be relatively fixed or that may change over time. The cell may further be divided into cell sectors. For example, the cell associated with the base station 114a may be divided into three sectors. Thus, in one embodiment, the base station 114a may include three transceivers, i.e. , one foreach sector of the cell. In an embodiment, the base station 114a may employ multiple-input multiple output (MIMO) technology and may utilize multiple transceivers for each sector of the cell. For example, beamforming may be used to transmit and / or receive signals in desired spatial directions.

[0020] The base stations 114a, 114b may communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which may be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 may be established using any suitable radio access technology (RAT).

[0021] More specifically, as noted above, the communications system 100 may be a multiple access system and may employ one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, and the like. For example, the base station 114a in the RAN 104 / 113 and the WTRUs 102a, 102b, 102c may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may establish the air interface 115 / 116 / 117 using wideband CDMA (WCDMA). WCDMA may include communication protocols such as High-Speed Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA may include High-Speed Downlink (DL) Packet Access (HSDPA) and / or High-Speed UL Packet Access (HSUPA).

[0022] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which may establish the air interface 116 using Long Term Evolution (LTE) and / or LTE-Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).

[0023] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as NR Radio Access , which may establish the air interface 116 using New Radio (NR).

[0024] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement multiple radio access technologies. For example, the base station 114a and the WTRUs 102a, 102b, 102c may implement LTE radio access and NR radio access together, for instance using dual connectivity (DC) principles. Thus, the air interface utilized by WTRUs 102a, 102b, 102c may be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., an eNB and a gNB).

[0025] In other embodiments, the base station 114a and the WTRUs 102a, 102b, 102c may implement radio technologies such as IEEE 802.11 (i.e., Wireless Fidelity (WiFi), IEEE 802.16 (i.e., Worldwide Interoperability for Microwave Access (WiMAX)), CDMA2000, CDMA2000 1X, CDMA2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System forMobile communications (GSM), Enhanced Data rates for GSM Evolution (EDGE), GSM EDGE (GERAN), and the like.

[0026] The base station 114b in FIG. 1 A may be a wireless router, Home Node B, Home eNode B, or access point, for example, and may utilize any suitable RAT for facilitating wireless connectivity in a localized area, such as a place of business, a home, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a roadway, and the like. In one embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.11 to establish a wireless local area network (WLAN). In an embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.15 to establish a wireless personal area network (WPAN). In yet another embodiment, the base station 114b and the WTRUs 102c, 102d may utilize a cellular-based RAT (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR etc.) to establish a picocell or femtocell. As shown in FIG. 1A, the base station 114b may have a direct connection to the Internet 110. Thus, the base station 114b may not be required to access the Internet 110 via the CN 106 / 115.

[0027] The RAN 104 / 113 may be in communication with the CN 106 / 115, which may be any type of network configured to provide voice, data, applications, and / or voice over internet protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. The data may have varying quality of service (QoS) requirements, such as differing throughput requirements, latency requirements, error tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, and the like. The CN 106 / 115 may provide call control, billing services, mobile location-based services, pre-paid calling, Internet connectivity, video distribution, etc., and / or perform high-level security functions, such as user authentication. Although not shown in FIG. 1A, it will be appreciated that the RAN 104 / 113 and / or the CN 106 / 115 may be in direct or indirect communication with other RANs that employ the same RAT as the RAN 104 / 113 or a different RAT. For example, in addition to being connected to the RAN 104 / 113, which may be utilizing a NR radio technology, the CN 106 / 115 may also be in communication with another RAN (not shown) employing a GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or WiFi radio technology.

[0028] The CN 106 / 115 may also serve as a gateway for the WTRUs 102a, 102b, 102c, 102d to access the PSTN 108, the Internet 110, and / or the other networks 112. The PSTN 108 may include circuit- switched telephone networks that provide plain old telephone service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices that use common communication protocols, such as the transmission control protocol (TCP), user datagram protocol (UDP) and / or the internet protocol (IP) in the TCP / IP internet protocol suite. The networks 112 may include wired and / or wireless communications networks owned and / or operated by other service providers. For example,the networks 112 may include another CN connected to one or more RANs, which may employ the same RAT as the RAN 104 / 113 or a different RAT.

[0029] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communications system 100 may include multi-mode capabilities (e.g., the WTRUs 102a, 102b, 102c, 102d may include multiple transceivers for communicating with different wireless networks over different wireless links). For example, the WTRU 102c shown in FIG. 1A may be configured to communicate with the base station 114a, which may employ a cellular-based radio technology, and with the base station 114b, which may employ an IEEE 802 radio technology.

[0030] FIG. 1 B is a system diagram illustrating an example WTRU 102. As shown in FIG. 1 B, the WTRU 102 may include a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keypad 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power source 134, a global positioning system (GPS) chipset 136, and / or other peripherals 138, among others. It will be appreciated that the WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with an embodiment.

[0031] The processor 118 may be a general purpose processor, a special purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs) circuits, any other type of integrated circuit (IC), a state machine, and the like. The processor 118 may perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 may be coupled to the transceiver 120, which may be coupled to the transmit / receive element 122. While FIG. 1 B depicts the processor 118 and the transceiver 120 as separate components, it will be appreciated that the processor 118 and the transceiver 120 may be integrated together in an electronic package or chip.

[0032] The transmit / receive element 122 may be configured to transmit signals to, or receive signals from, a base station (e.g., the base station 114a) over the air interface 116. For example, in one embodiment, the transmit / receive element 122 may be an antenna configured to transmit and / or receive RF signals. In an embodiment, the transmit / receive element 122 may be an emitter / detector configured to transmit and / or receive IR, UV, or visible light signals, for example. In yet another embodiment, the transmit / receive element 122 may be configured to transmit and / or receive both RF and light signals. It will be appreciated that the transmit / receive element 122 may be configured to transmit and / or receive any combination of wireless signals.

[0033] Although the transmit / receive element 122 is depicted in FIG. 1 B as a single element, the WTRU 102 may include any number of transmit / receive elements 122. More specifically, the WTRU 102 may employ MIMO technology. Thus, in one embodiment, the WTRU 102 may include two or more transmit / receive elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.

[0034] The transceiver 120 may be configured to modulate the signals that are to be transmitted by the transmit / receive element 122 and to demodulate the signals that are received by the transmit / receive element 122. As noted above, the WTRU 102 may have multi-mode capabilities. Thus, the transceiver 120 may include multiple transceivers for enabling the WTRU 102 to communicate via multiple RATs, such as NR and I EEE 802.11 , for example.

[0035] The processor 118 of the WTRU 102 may be coupled to, and may receive user input data from, the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or organic light-emitting diode (OLED) display unit). The processor 118 may also output user data to the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128. In addition, the processor 118 may access information from, and store data in, any type of suitable memory, such as the non-removable memory 130 and / or the removable memory 132. The non-removable memory 130 may include random-access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, and the like. In other embodiments, the processor 118 may access information from, and store data in, memory that is not physically located on the WTRU 102, such as on a server or a home computer (not shown).

[0036] The processor 118 may receive power from the power source 134, and may be configured to distribute and / or control the power to the other components in the WTRU 102. The power source 134 may be any suitable device for powering the WTRU 102. For example, the power source 134 may include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, fuel cells, and the like.

[0037] The processor 118 may also be coupled to the GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to, or in lieu of, the information from the GPS chipset 136, the WTRU 102 may receive location information over the air interface 116 from a base station (e.g., base stations 114a, 114b) and / or determine its location based on the timing of the signals being received from two or more nearby base stations. It will be appreciated that the WTRU 102 may acquire location information by way of any suitable locationdetermination method while remaining consistent with an embodiment.

[0038] The processor 118 may further be coupled to other peripherals 138, which may include one or more software and / or hardware modules that provide additional features, functionality and / or wired or wireless connectivity. For example, the peripherals 138 may include an accelerometer, an e-compass, a satellite transceiver, a digital camera (for photographs and / or video), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands free headset, a Bluetooth® module, a frequency modulated (FM) radio unit, a digital music player, a media player, a video game player module, an Internet browser, a Virtual Reality and / or Augmented Reality (VR / AR) device, an activity tracker, and the like. The peripherals 138 may include one or more sensors, the sensors may be one or more of a gyroscope, an accelerometer, a hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor; a geolocation sensor; an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, and / or a humidity sensor.

[0039] The WTRU 102 may include a full duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for both the UL (e.g., for transmission) and downlink (e.g., for reception) may be concurrent and / or simultaneous. The full duplex radio may include an interference management unit to reduce and or substantially eliminate self-interference via either hardware (e.g., a choke) or signal processing via a processor (e.g., a separate processor (not shown) or via processor 118). In an embodiment, the WRTU 102 may include a half-duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for either the UL (e.g., for transmission) or the downlink (e.g., for reception)).

[0040] FIG. 1 C is a system diagram illustrating the RAN 104 and the CN 106 according to an embodiment. As noted above, the RAN 104 may employ an E-UTRA radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 may also be in communication with the CN 106.

[0041] The RAN 104 may include eNode-Bs 160a, 160b, 160c, though it will be appreciated that the RAN 104 may include any number of eNode-Bs while remaining consistent with an embodiment. The eNode-Bs 160a, 160b, 160c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the eNode-Bs 160a, 160b, 160c may implement MIMO technology. Thus, the eNode-B 160a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a.

[0042] Each of the eNode-Bs 160a, 160b, 160c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, and the like. As shown in FIG. 1 C, the eNode-Bs 160a, 160b, 160c may communicate with one another over an X2 interface.

[0043] The CN 106 shown in FIG. 1 C may include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (or PGW) 166. While each of the foregoing elements are depicted as part of the CN 106, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.

[0044] The MME 162 may be connected to each of the eNode-Bs 160a, 160b, 160c in the RAN 104 via an S1 interface and may serve as a control node. For example, the MME 162 may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a particular serving gateway during an initial attach of the WTRUs 102a, 102b, 102c, and the like. The MME 162 may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as GSM and / or WCDMA.

[0045] The SGW 164 may be connected to each of the eNode Bs 160a, 160b, 160c in the RAN 104 via the S1 interface. The SGW 164 may generally route and forward user data packets to / from the WTRUs 102a, 102b, 102c. The SGW 164 may perform other functions, such as anchoring user planes during inter- eNode B handovers, triggering paging when DL data is available for the WTRUs 102a, 102b, 102c, managing and storing contexts of the WTRUs 102a, 102b, 102c, and the like.

[0046] The SGW 164 may be connected to the PGW 166, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.

[0047] The CN 106 may facilitate communications with other networks. For example, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to circuit-switched networks, such as the PSTN 108, to facilitate communications between the WTRUs 102a, 102b, 102c and traditional land-line communications devices. For example, the CN 106 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers.

[0048] Although the WTRU is described in FIGS. 1 A-1 D as a wireless terminal, it is contemplated that in certain representative embodiments that such a terminal may use (e.g., temporarily or permanently) wired communication interfaces with the communication network.

[0049] In representative embodiments, the other network 112 may be a WLAN.

[0050] A WLAN in Infrastructure Basic Service Set (BSS) mode may have an Access Point (AP) for the BSS and one or more stations (STAs) associated with the AP. The AP may have an access or an interface to a Distribution System (DS) or another type of wired / wireless network that carries traffic in to and / or out ofthe BSS. Traffic to STAs that originates from outside the BSS may arrive through the AP and may be delivered to the STAs. Traffic originating from STAs to destinations outside the BSS may be sent to the AP to be delivered to respective destinations. Traffic between STAs within the BSS may be sent through the AP, for example, where the source STA may send traffic to the AP and the AP may deliver the traffic to the destination STA. The traffic between STAs within a BSS may be considered and / or referred to as peer-to- peer traffic. The peer-to-peer traffic may be sent between (e.g., directly between) the source and destination STAs with a direct link setup (DLS). In certain representative embodiments, the DLS may use an 802.11e DLS or an 802.11 z tunneled DLS (TDLS). A WLAN using an Independent BSS (I BSS) mode may not have an AP, and the STAs (e.g., all of the STAs) within or using the IBSS may communicate directly with each other. The IBSS mode of communication may sometimes be referred to herein as an “ad- hoc” mode of communication.

[0051] When using the 802.11ac infrastructure mode of operation or a similar mode of operations, the AP may transmit a beacon on a fixed channel, such as a primary channel. The primary channel may be a fixed width (e.g., 20 MHz wide bandwidth) or a dynamically set width via signaling. The primary channel may be the operating channel of the BSS and may be used by the STAs to establish a connection with the AP. In certain representative embodiments, Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA) may be implemented, for example in in 802.11 systems. For CSMA / CA, the STAs (e.g., every STA), including the AP, may sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by a particular STA, the particular STA may back off. One STA (e.g., only one station) may transmit at any given time in a given BSS.

[0052] High Throughput (HT) STAs may use a 40 MHz wide channel for communication, for example, via a combination of the primary 20 MHz channel with an adjacent or nonadjacent 20 MHz channel to form a 40 MHz wide channel.

[0053] Very High Throughput (VHT) STAs may support 20MHz, 40 MHz, 80 MHz, and / or 160 MHz wide channels. The 40 MHz, and / or 80 MHz, channels may be formed by combining contiguous 20 MHz channels. A 160 MHz channel may be formed by combining 8 contiguous 20 MHz channels, or by combining two non-contiguous 80 MHz channels, which may be referred to as an 80+80 configuration. For the 80+80 configuration, the data, after channel encoding, may be passed through a segment parser that may divide the data into two streams. Inverse Fast Fourier Transform (IFFT) processing, and time domain processing, may be done on each stream separately. The streams may be mapped on to the two 80 MHz channels, and the data may be transmitted by a transmitting STA. At the receiver of the receiving STA, the above described operation for the 80+80 configuration may be reversed, and the combined data may be sent to the Medium Access Control (MAC).

[0054] Sub 1 GHz modes of operation are supported by 802.11af and 802.11 ah. The channel operating bandwidths, and carriers, are reduced in 802.11 af and 802.11 ah relative to those used in 802.11 n, and802.11 ac. 802.11 af supports 5 MHz, 10 MHz and 20 MHz bandwidths in the TV White Space (TVWS) spectrum, and 802.11 ah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non- TVWS spectrum. According to a representative embodiment, 802.11 ah may support Meter Type Control / Machine-Type Communications, such as MTC devices in a macro coverage area. MTC devices may have certain capabilities, for example, limited capabilities including support for (e.g., only support for) certain and / or limited bandwidths. The MTC devices may include a battery with a battery life above a threshold (e.g., to maintain a very long battery life).

[0055] WLAN systems, which may support multiple channels, and channel bandwidths, such as802.11 n, 802.11 ac, 802.11 af, and 802.11 ah, include a channel which may be designated as the primary channel. The primary channel may have a bandwidth equal to the largest common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel may be set and / or limited by a STA, from among all STAs in operating in a BSS, which supports the smallest bandwidth operating mode. In the example of 802.11 ah, the primary channel may be 1 MHz wide for STAs (e.g., MTC type devices) that support (e.g., only support) a 1 MHz mode, even if the AP, and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier sensing and / or Network Allocation Vector (NAV) settings may depend on the status of the primary channel. If the primary channel is busy, for example, due to a STA (which supports only a 1 MHz operating mode), transmitting to the AP, the entire available frequency bands may be considered busy even though a majority of the frequency bands remains idle and may be available.

[0056] In the United States, the available frequency bands, which may be used by 802.11 ah, are from 902 MHz to 928 MHz. In Korea, the available frequency bands are from 917.5 MHz to 923.5 MHz. In Japan, the available frequency bands are from 916.5 MHz to 927.5 MHz. The total bandwidth available for802.11 ah is 6 MHz to 26 MHz depending on the country code.

[0057] FIG. 1 D is a system diagram illustrating the RAN 113 and the CN 115 according to an embodiment. As noted above, the RAN 113 may employ an NR radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 113 may also be in communication with the CN 115.

[0058] The RAN 113 may include gNBs 180a, 180b, 180c, though it will be appreciated that the RAN 113 may include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, 180c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the gNBs 180a, 180b, 180c may implement MIMOtechnology. For example, gNBs 180a, 108b may utilize beamforming to transmit signals to and / or receive signals from the gNBs 180a, 180b, 180c. Thus, the gNB 180a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a. In an embodiment, the gNBs 180a, 180b, 180c may implement carrier aggregation technology. For example, the gNB 180a may transmit multiple component carriers to the WTRU 102a (not shown). A subset of these component carriers may be on unlicensed spectrum while the remaining component carriers may be on licensed spectrum. In an embodiment, the gNBs 180a, 180b, 180c may implement Coordinated Multi-Point (CoMP) technology. For example, WTRU 102a may receive coordinated transmissions from gNB 180a and gNB 180b (and / or gNB 180c).

[0059] The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using transmissions associated with a scalable numerology. For example, the OFDM symbol spacing and / or OFDM subcarrier spacing may vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using subframe or transmission time intervals (TTIs) of various or scalable lengths (e.g., containing varying number of OFDM symbols and / or lasting varying lengths of absolute time).

[0060] The gNBs 180a, 180b, 180c may be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non-standalone configuration. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c without also accessing other RANs (e.g., such as eNode-Bs 160a, 160b, 160c). In the standalone configuration, WTRUs 102a, 102b, 102c may utilize one or more of gNBs 180a, 180b, 180c as a mobility anchor point. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using signals in an unlicensed band. In a non-standalone configuration WTRUs 102a, 102b, 102c may communicate with / connect to gNBs 180a, 180b, 180c while also communicating with / connecting to another RAN such as eNode-Bs 160a, 160b, 160c. For example, WTRUs 102a, 102b, 102c may implement DC principles to communicate with one or more gNBs 180a, 180b, 180c and one or more eNode-Bs 160a, 160b, 160c substantially simultaneously. In the non-standalone configuration, eNode-Bs 160a, 160b, 160c may serve as a mobility anchor for WTRUs 102a, 102b, 102c and gNBs 180a, 180b, 180c may provide additional coverage and / or throughput for servicing WTRUs 102a, 102b, 102c.

[0061] Each of the gNBs 180a, 180b, 180c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, support of network slicing, dual connectivity, interworking between NR and E- UTRA, routing of user plane data towards User Plane Function (UPF) 184a, 184b, routing of control planeinformation towards Access and Mobility Management Function (AMF) 182a, 182b and the like. As shown in FIG. 1 D, the gNBs 180a, 180b, 180c may communicate with one another over an Xn interface.

[0062] The CN 115 shown in FIG. 1 D may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one Session Management Function (SMF) 183a, 183b, and possibly a Data Network (DN) 185a, 185b. While each of the foregoing elements are depicted as part of the CN 115, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.

[0063] The AMF 182a, 182b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N2 interface and may serve as a control node. For example, the AMF 182a, 182b may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, support for network slicing (e.g., handling of different PDU sessions with different requirements), selecting a particular SMF 183a, 183b, management of the registration area, termination of NAS signaling, mobility management, and the like. Network slicing may be used by the AMF 182a, 182b in order to customize CN support for WTRUs 102a, 102b, 102c based on the types of services being utilized WTRUs 102a, 102b, 102c. For example, different network slices may be established for different use cases such as services relying on ultra-reliable low latency (URLLC) access, services relying on enhanced massive mobile broadband (eMBB) access, services for machine type communication (MTC) access, and / or the like. The AMF 162 may provide a control plane function for switching between the RAN 113 and other RANs (not shown) that employ other radio technologies, such as LTE, LTE-A, LTE-A Pro, and / or non-3GPP access technologies such as WiFi.

[0064] The SMF 183a, 183b may be connected to an AMF 182a, 182b in the CN 115 via an N11 interface. The SMF 183a, 183b may also be connected to a UPF 184a, 184b in the CN 115 via an N4 interface. The SMF 183a, 183b may select and control the UPF 184a, 184b and configure the routing of traffic through the UPF 184a, 184b. The SMF 183a, 183b may perform other functions, such as managing and allocating WTRU IP address, managing PDU sessions, controlling policy enforcement and QoS, providing downlink data notifications, and the like. A PDU session type may be IP-based, non-IP based, Ethernet-based, and the like.

[0065] The UPF 184a, 184b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 113 via an N3 interface, which may provide the WTRUs 102a, 102b, 102c with access to packet- switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPF 184, 184b may perform other functions, such as routing and forwarding packets, enforcing user plane policies, supporting multi-homed PDU sessions, handling user plane QoS, buffering downlink packets, providing mobility anchoring, and the like.

[0066] The CN 115 may facilitate communications with other networks. For example, the CN 115 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 115 and the PSTN 108. In addition, the CN 115 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers. In one embodiment, the WTRUs 102a, 102b, 102c may be connected to a local Data Network (DN) 185a, 185b through the UPF 184a, 184b via the N3 interface to the UPF 184a, 184b and an N6 interface between the UPF 184a, 184b and the DN 185a, 185b.

[0067] In view of Figures 1 A-1 D, and the corresponding description of Figures 1 A-1 D, one or more, or all, of the functions described herein with regard to one or more of: WTRU 102a-d, Base Station 114a-b, eNode-B 160a-c, MME 162, SGW 164, PGW 166, gNB 180a-c, AMF 182a-b, UPF 184a-b, SMF 183a-b, DN 185a-b, and / or any other device(s) described herein, may be performed by one or more emulation devices (not shown). The emulation devices may be one or more devices configured to emulate one or more, or all, of the functions described herein. For example, the emulation devices may be used to test other devices and / or to simulate network and / or WTRU functions.

[0068] The emulation devices may be designed to implement one or more tests of other devices in a lab environment and / or in an operator network environment. For example, the one or more emulation devices may perform the one or more, or all, functions while being fully or partially implemented and / or deployed as part of a wired and / or wireless communication network in order to test other devices within the communication network. The one or more emulation devices may perform the one or more, or all, functions while being temporarily implemented / deployed as part of a wired and / or wireless communication network. The emulation device may be directly coupled to another device for purposes of testing and / or may perform testing using over-the-air wireless communications.

[0069] The one or more emulation devices may perform the one or more, including all, functions while not being implemented / deployed as part of a wired and / or wireless communication network. For example, the emulation devices may be utilized in a testing scenario in a testing laboratory and / or a non-deployed (e.g., testing) wired and / or wireless communication network in order to implement testing of one or more components. The one or more emulation devices may be testing equipment. Direct RF coupling and / or wireless communications via RF circuitry (e.g., which may include one or more antennas) may be used by the emulation devices to transmit and / or receive data. Examples described herein may include the following acronyms:

[0070] Communication from devices (e.g., non-3GPP devices) behind RG / WTRU may be tracked based on an IP address / Prefix or MAC address. If the IP address / Prefix or MAC address is not recognized by the network, the network may trigger an authentication procedure with the non-3GPP device that is associated with the IP address / Prefix or MAC Address. The procedure may be used to authenticate the non-3GPP device based on the user identity of the non-3GPP device. The network may be able to track what user identity is associated with a MAC address or IP address / Prefix. Network functions (e.g., the UPF) may be able to create CDRs that record what services (e.g., how much data is sent and received) are consumed by a non-3GPP device.

[0071] FIG. 2 illustrates an example procedure for a UPF (e.g., second network node) triggered device authentication. A UPF may trigger user authentication. A UPF may, at 1 , receive configuration information from the SMF (e.g., a first network node) that indicates that the UPF should initiate an Authorization procedure if a (e.g., an updated) source MAC address, source IP address, or source port number is detected in uplink traffic.

[0072] The UPF may, at 3, receive a data packet and detect that the source IP address / Prefix, source MAC address, or source port number is not in a list of allowed addresses.

[0073] The UPF may, at 4, inform the SMF that unauthorized traffic is detected. The indication may indicate the detected source address and the PDU Session ID. The UPF may, at 8, receive a notification that the source address is authorized. The indication may include a charging identifier. The UPF may, at 8, forward packets that are associated with the source address. When forwarding packets, the UPF may send a message to create a CDR, and the message may include the charging identifier.

[0074] The UPF may trigger user authentication (e.g., WTRU / RG actions). A WTRU / RG may perform the following. The WTRU / RG may initiate a PDU session establishment procedure. In the PDU session establishment request, the WTRU / RG may indicate that the PDU Session may be used for forwarding traffic from other devices.

[0075] The WTRU may be triggered to establish the PDU Session when a device makes a layer-2 connection with the WTRU, at power up, or based on a request from an application (e.g., a GUI) that is received via an AT command.

[0076] The WTRU / RG may, at 1 , receive a packet from a device and forward the device in the PDU session. The packet that is sent in the PDU session may include a source MAC Address, source IP address, or source port number that is associated with the device. The WTRU / RG may, at 5a, receive a NAS-SM message that indicates that the device that is associated with the source MAC address, source IP address, or source port number may be authenticated and authorized.

[0077] The message may include the source MAC address, source IP address, or source port number. The message may include an EAP payload. The message may include a PDU session ID. The WTRU / RG may, at 5b, forward the EAP payload to the device. The WTRU / RG may, at 5d, receive an EAP payload response from the device. The EAP identity response may include a piece of information that may be used to identify the AAA server that may authenticate the device. The WTRU / RG may, at 6, forward EAP messages between the device and AAA server. The WTRU / RG may, at 8a, receive a notification of whether the device that is associated with the source address has been successfully authenticated.

[0078] The WTRU may use information in the notification to determine whether to forward traffic to and from the device via the PDU Session.

[0079] User Plane Function(s) may handle the user plane path of PDU Sessions. Deployments may be associated with a single UPF or multiple UPFs for a given PDU Session.

[0080] For an IPv4 type PDU Session or an IPv6 type PDU Session without multi-homing or an IPv4v6 type PDU Session, when multiple PDU Session Anchors are used (due to UL CL being inserted), an (e.g., one) IPv4 address and / or IPv6 prefix may be allocated for the PDU Session. For an IPv6 multi-homed PDU Session, there may be multiple IPv6 prefixes allocated for the PDU Session.

[0081] UPF traffic detection capabilities may be used by the SMF to control at least one of the following features of the UPF: traffic detection (e.g., classifying traffic of IP type, Ethernet type, or unstructured type); traffic reporting (e.g., allowing SMF support for charging); QoS enforcement; or traffic routing.

[0082] During a PDU Session Establishment procedure, the SMF may send the IP address to the WTRU via SM NAS signaling. The IPv4 address allocation and / or IPv4 parameter configuration via DHCPv4 may be used once the PDU Session is established. IPv6 prefix allocation may be supported via IPv6 Stateless Auto-configuration (e.g., if IPv6 is supported). In examples with RG connecting to a core (e.g., 5GC), features for IPv6 address allocation and IPv6 prefix delegation may be supported.

[0083] Features described herein may be associated with an IP PDU session. The WTRU may acquire the following configuration information from the SMF during the lifetime of a PDU Session: address(es) of P-CSCF(s); address(es) of DNS server(s); if the WTRU indicates support of DNS over (D) TLS to the network and the network wants to enforce the use of DNS over (D)TLS, the configuration information may be sent by the SMF via PCO and may also include the corresponding DNS server security information; the GPSI of the WTRU; the WTRU may acquire from the SMF, at PDU Session Establishment, the MTU that the WTRU may consider.

[0084] Features described herein may be associated with an Ethernet PDU Session type. For a PDU Session set up with the Ethernet PDU Session type, the SMF and the UPF acting as PDU Session Anchor (PSA) may support specific behaviors related to the fact that the PDU Session carries Ethernet frames.

[0085] Examples with a 1-1 relationship between a PDU Session and a N6 interface may correspond to a dedicated tunnel established over N6. For example, the UPF acting as a PSA transparently may forward Ethernet frames between the PDU Session and its corresponding N6 interface (e.g., the UPF may not need to be aware of MAC addresses used by the WTRU to route down-link traffic).

[0086] Examples may be associated with more than one PDU Session to the same DNN (e.g., for more than one WTRU) corresponding to the same N6 interface. For example, the UPF acting as PSA may be aware of MAC addresses used by the WTRU in the PDU Session to map down-link Ethernet frames received over N6 to the appropriate PDU Session. Forwarding behavior of the UPF acting as PSA may be managed by SMF.

[0087] Authentication and Authorization may be associated with a system (e.g., a 5G system). Security may include primary and secondary authentication. Primary authentication may be associated with one or more of the following mechanisms: Authentication and Key Agreement (AKA) (e.g., 5G AKA), Extensible Authentication Protocol AKA’ (EAP-AKA’), and the like.

[0088] Home Control may include authentication taking place in the home network. Subscription Concealed Identifier (SUCI) in the signaling may prevent the exposure of permanent subscriber ID toensure user privacy. Subscription Permanent Identifier (SUPI) may have the format of an International Mobile Subscription Identifier (IMSI). Secondary authentication may provide a mechanism for an external network to authenticate the user as part of the PDU Session establishment, with the support of a mobile operator.

[0089] Features described herein may be associated with types of authentication. The network slice (e.g., concept) may enable authentication at the network slice level. Features described herein may be associated with Authentication and Key Management for Applications based on 3GPP credentials (AKMA). This architecture may modify the existing (e.g., Generic) Bootstrapping Architecture (GBA)-based examples (e.g., of the 4G and 3G systems).

[0090] The EAP-AKA may be an EAP method for authentication and session key distribution that uses an AKA mechanism. Authentication and Key Agreement (AKA) may be based on challenge-response mechanisms and symmetric cryptography. AKA may run using a Universal Subscriber Identity Module (USIM).

[0091] Based on EAP-AKA, EAP-AKA' may be an EAP method that binds the derived keys to the name of the access network. EAP-AKA' may be a variant of EAP-AKA, which may be used for 3GPP and non- 3GPP access to a 3GPP core network. EAP-AKA' may use the SIM card and a challenge-response mechanism to verify the user's identity. EAP-AKA' may produce cryptographic keys used for encryption in the secure Wi-Fi network (802.1x).

[0092] Wireless Wireline Convergence may address whether and how to identify, authenticate, and authorize the Authenticable Non-3GPP devices and 3GPP devices (e.g., WTRU or N5CW devices) behind the Residential Gateway (RG) connecting to the network. An AUN3 device may connect to RG in a PLMN that is to the core (e.g., 5GC) by the RG (e.g., RG 5G-RG) or W-AGF and is authenticated by the core (e.g., 5GC) using EAP-AKA'.

[0093] The RG may initiate the EAP authentication procedure by sending an EAP request / ldentity to the AUN3 device. The AUN3 device may send back an EAP response / ldentity, including its Network Access Identifier (NAI) in the form of username@realm. If the RG is a 5G-RG, the 5G-RG may construct a SUCI from the NAI-based SUPI of the AUN3 device and send a NAS Registration Request message to the AMF, including the SUCI and an AUN3 device indicator. The authentication mechanism may be based on the subscription identifier like SUCI, SUPI, etc., related to the WTRU subscription. Users or Applications using the WTRU may not be identified.

[0094] A WTRU, such as an RG, may serve as a gateway to devices that connect to the WTRU. For example, the devices may connect to the WTRU using protocols such as Wi-Fi or ethernet. The WTRUmay establish a PDU Session and use the PDU Session to send traffic that originates from the devices and use the PDU Session to receive traffic that is forwarded to the devices.

[0095] The traffic from the devices may be IP-based traffic. The PDU Session type may be IP. The IP Address / Prefix that is associated with the device may change periodically. The traffic from the devices may be Layer-2 Frames (e.g., Ethernet). For example, the PDU Session type may be Ethernet. The MAC Address that is associated with devices may change periodically.

[0096] A device may have one or more user identities associated with and / or configured in the device using an application level mechanism by the device owner or administrator (e.g., of the device). When traffic is sent to and from the device, the network (e.g., the UPF) may be able to identify what user identity (e.g., what device) the traffic is associated with, so that the information may be recorded for charging purposes. System modifications may enable the authentication of user identities that are associated with devices that send traffic through the System via a gateway WTRU.

[0097] A Residential Gateway (RG) may be a WTRU, which may provide connectivity to 3GPP as well as non-3GPP devices. The connectivity may be connectivity to the Network and external data network. A 3GPP WTRU including RG may have a subscription identifier (e.g., a SUPI). A WTRU or RG may have an assigned user identity.

[0098] Devices (e.g., non-3GPP devices), connecting through RG, may have an assigned user identity. Communication from non-3GPP devices behind RG / WTRU may be tracked based on IP address / Prefix or MAC address. If the IP address / Prefix or MAC address is not recognized by the network, the network may trigger an authentication procedure with the non-3GPP device that is associated with the IP address / Prefix or MAC Address. The procedure may be used to authenticate the non-3GPP device based on the user identity of the non-3GPP device. The network may be able to track what user identity is associated with a MAC address or IP address / Prefix. Network functions (e.g., the UPF) may create CDRs that record what services (e.g., how much data is sent and received) are consumed by a non-3GPP device.

[0099] Examples described herein may be network initiated. Features described herein may be associated with PDU Session Establishment. A WTRU (e.g., RG) may establish a PDU session to a DNN / S-NSSAI combination. The WTRU may be configured to know that the DNN / S-NSSAI combination is for forwarding traffic to and from devices that connect via the WTRU. During PDU Session Establishment or PDU Session Modification, the WTRU may indicate to the SMF that the PDU Session is used for forwarding (e.g., GW services). When a PDU Session is configured for forwarding traffic to and from devices, the network may trigger an authentication procedure if the network detects that the traffic is from an IP address / prefix or MAC address, which may not be in the allowed list of IP address / prefix or MAC address.

[0100] A WTRU may initiate a PDU Session Establishment procedure. Assuming the WTRU may have already registered with the AMF and the AMF may have retrieved the user subscription data from the UDM. The WTRU may generate a PDU session ID. The WTRU may send a NAS message including a PDU Session Establishment Request within the N1 SM container. The PDU session establishment request may include one or more of the PDU session ID, Requested PDU session type, S-NSSAI from Allowed NSSAI, Requested SSC mode, or Request Type, among other information. The WTRU may include in the N1 SM Container that the PDU session is used for forwarding (e.g., GW services). The DNN may be configured as dedicated for GW services.

[0101] The WTRU may be triggered to establish a PDU Session that may be used for GW services when a device makes a layer-2 connection with the WTRU, by default at power up, or based on a request from an application (e.g., a GUI) that is received via an AT command.

[0102] The AMF may forward the PDU Session ID, together with the N1 SM container, including the PDU Session Establishment Request received from the WTRU, to the SMF.

[0103] The devices may not have generated traffic (e.g., may not have yet generated traffic). The devices may host an EAP client in a device and may be pre-provisioned with a user identifier and a credential that is associated with the user identifier. Examples of a credential may include one or more of a password, a key, and a certificate.

[0104] During PDU Session Establishment, the SMF may configure the UPF to know what traffic is authorized for the PDU Session. For example, the SMF may indicate to the UPF which MAC Address and IP address / Prefix are allowed to send and receive traffic in the PDU Session. During PDU Session Establishment, the SMF may indicate no IP Addresses / Prefixes or MAC Addresses are authorized to generate traffic. During PDU Session Establishment, the SMF may indicate that pre-configured IP Addresses / Prefixes or MAC Addresses are authorized to generate traffic. For example, the SMF may obtain pre-configured IP Addresses / Prefixes or MAC Addresses from the WTRU’s subscription information for the DNN / S-NSSAI combination or from a DN-AAA. The SMF may configure the UPF to be notified when detecting unauthorized traffic for this PDU Session. The SMF may inform the WTRU of acceptance of PDU Session establishment with an indication of per-user authentication support / activation.

[0105] When RG attempts to establish a PDU Session to a DN, the DN-AAA may not necessarily authenticate the RG-WTRU. The DN-AAA may provide authorization data, which may include any of an assigned IP address or a list of allowed MAC. The SMF may inform the UPF of allowed MACs for PDU Session eth type as part of the configuration of UPF. For example, an allowed MAC may trigger the A&A mechanism. MACs that are not allowed may be discarded by UPF.

[0106] A User Authentication may be UPF triggered. FIG. 2 illustrates an example procedure for UPF triggered device authentication. FIG. 2 illustrates an example procedure that may occur after the WTRU establishes a PDU Session for forwarding device traffic. The example procedure may include how a WTRU forwards an uplink packet from the device, and how the uplink packet’s arrival at the UPF triggers device authentication.

[0107] At 0, an RG (e.g., a WTRU) may establish a PDU session. The SMF (e.g., a first network node) may configure the UPF (e.g., a second network node) and indicate to the UPF that (e.g., only) authorized traffic (e.g., specific source MAC Address, source Port Number, or source IP Address) is permitted, and indicate that the UPF may (e.g., should) check for authorization when a (e.g., updated) source MAC address, source port number, or source IP address is detected. The allowed MAC / IP addresses may be obtained from a DN during the PDU Session establishment by the RG / WTRU (e.g., the RG / WTRU may or may not undergo an authentication with the DN-AAA or use the PDU Session for its own traffic).

[0108] At 1 , the device may send an uplink packet to the WTRU (e.g., RG). At 2, the WTRU may forward the uplink packet to the network. The uplink packet may be sent in the PDU Session that was previously established for forwarding device traffic.

[0109] At 3, the UPF may detect that the source IP address / prefix or MAC address is not in its list of allowed addresses. For example, the IP address / prefix or MAC address may not be in the list of allowed addresses that were received from the SMF in an N4 message during PDU session establishment or during a PDU session modification procedure.

[0110] The UPF may detect traffic originating from a device behind the WTRU. The UPF may detect that the IP address / prefix or MAC address is present in the allowed list and that the PDU session established is not for GW services.

[0111] At 4, the UPF may inform the SMF that unauthorized traffic is detected. The SMF may receive from the UPF an indication comprising a detected address. The UPF may send an Unauthorized traffic detected message to the SMF and indicate the PDU session ID and the detected Source IP address / Prefix or Source MAC address (e.g., the detected address may include one or more of the source IP address, source IP address prefix, a source port number, or a source MAC address). The message may be sent from the UPF to the SMF via the N4 interface.

[0112] At 5a, the Unauthorized traffic detected message may cause the SMF to trigger EAP Authentication of the non-3GPP device. The SMF may trigger the procedure by sending a NAS-SM message (e.g., a PDU session modification command) to the WTRU. The NAS-SM message may be included in a first message. The first message may include any of the detected addresses (e.g., the IP address / Prefix and applicable port number or MAC Address that was received from the SMF), the PDUSession ID, and an EAP payload. The EAP payload may be used for initiating authentication of the device associated with the detected address. The EAP payload may carry an EAP ID Request.

[0113] At 5b, the WTRU may receive the NAS-SM message. The WTRU may use the PDU session ID and detected address to determine what non-3GPP to forward the EAP payload to. For example, the WTRU may forward the EAP payload to the non-3GPP device that is associated with the detected address and whose data packet was forwarded in the PDU Session. The EAP payload may be sent to the device via an access link such as Ethernet, Wi-Fi, or Bluetooth.

[0114] At 5c, the device may receive the EAP payload from the WTRU by sending an EAP identity response payload. The EAP identity response (e.g., the EAP response) may include a piece of information that may be used to identify the AAA server that may authenticate the device. The piece of information may be the user identity of the device. The piece of information may be part of the user identity; for example, the user identity may include a domain identifier field, and the piece of information may be the domain identifier. The piece of information may be an MNO identifier. The piece of information may be a service provider identifier. The piece of information may be a AAA server identifier. The device may have been configured with the user identifier, credential, and piece of information that is used to identify the AAA Server. The configuration of the device may have been performed by an application, such as a GUI.

[0115] At 5d, the WTRU may receive the EAP identity response (e.g., EAP response) from the device. The WTRU may forward (e.g., send, in a second message) the EAP identity response to the SMF in a NAS-SM message. The WTRU may include the EAP identity response, PDU session ID, and detected address in the NAS-SM message.

[0116] At 5e, the SMF may receive the NAS-SM message from the WTRU. The SMF may use the PDU session ID and detected address in the NAS-SM message to determine which request the identity response is associated with.

[0117] If the NAS-SM message does not include an EAP Identity Response, a PDU Session, and a detected address, the SMF may determine that the WTRU received no EAP Identity Response and that the device’s traffic may not be allowed. The SMF may (e.g., immediately) respond to the UPF and indicate that traffic to and from the detected address may be blocked.

[0118] If the NAS-SM message includes an EAP Identity Response, a PDU Session, and a detected address, the SMF may use the information from the EAP Identity Response to determine what AAA Server to forward the EAP Identity Response to. The content of the EAP Identity Response may be sent in cleartext. The SMF may read the EAP Identity Response and use the content to determine a AAA-S identity or to determine what domain to forward the EAP Identity Response to.

[0119] In an example, before the SMF uses the user identity to determine a AAA Server, the SMF may, for example, check if the user identity is linked to the subscription of the WTRU or RG. Checking that the user identity is linked to the subscription of the WTRU or RG may mean that the SMF checks if the user that the device (or person) that is associated with the user identifier is allowed to use the subscription of the WTRU or RG to send and receive data. The SMF may perform the check by sending a query to a UDM / UDR to verify that the user profile associated with the user identity has information stored that indicates that the user identity is linked to the SUPI of the WTRU or RG. The SMF may perform the check by sending a query to a UDM / UDR to verify that the subscription that is associated with the WTRU or RG has information stored that indicates that the user identity is linked to the SUPI of the WTRU or RG.

[0120] If the SMF determines that the user identity and subscription are not linked, the SMF may send a NAS-SM response to the WTRU to indicate that the user identity and subscription are not linked. This NAS- SM message may trigger the WTRU or 5G-RG to use a different PDU Session for the device’s traffic. The processes at 5f, 6, and 7 may be skipped, and the SMF may notify the UPF at 8 that the traffic is not allowed.

[0121] If the SMF determines that the user identity and subscription are linked, the SMF may send the message of 5f to the AAA-S.

[0122] At 5f, the SMF may forward (e.g., in a third message) the EAP identity response (e.g., EAP response) to the AAA-S. The SMF may include a source IP address, source MAC address (e.g., the detected address), and a reference ID in this message.

[0123] At 6, the EAP Authentication procedure may be executed between the device and AAA-S. The EAP messages that are sent from the AAA-S may be sent to the SMF (e.g., from the AAA-S), forwarded to the WTRU in a NAS-SM message, and forwarded to the device by the WTRU (e.g., in a first EAP message). The EAP messages (e.g., a second EAP message) that are sent from the device may be sent to the WTRU, forwarded to the SMF in a NAS-SM message, and forwarded to the AAA-S by the SMF.

[0124] The NAS messages exchanged during the EAP authentication round trips may carry the user addressing information (IP address / Prefix or MAC address) to allow the RG-WTRU to route the EAP message to the proper device.

[0125] At 7, when the EAP authentication procedure is complete, the AAA Server may notify the SMF whether the device has been successfully authenticated (e.g., the SMF may receive, from the third network node / UPF, a fourth message indicating that the device is authenticated). The notification may include the reference ID and an indication of whether or not the device was authenticated. The notification may include a charging identifier. The charging identifier may be the user identifier. The charging identifier may include a value that the AAA-S has associated with the user identifier.

[0126] At 8, the SMF may notify (e.g., send a fifth message to) the UPF whether traffic to and from the detected address is allowed (e.g., the fifth message may indicate that the traffic associated with the detected address is authorized). The notification (e.g., the fifth message) may include the charging identifier (e.g., received from the AAA). The UPF may include the charging identifier in CDRs that record information about the traffic (e.g., data usage associated with the WTRU) that is sent to and from the detected address. The information in the CDRs may be used by the MNO to bill the service provider that is associated with the user identifier.

[0127] At 8a, the SMF may send a message to the WTRU to notify the WTRU whether the device that is associated with the detected address has been successfully authenticated (e.g., based on the device being authenticated). The notification message may be sent to the WTRU in a NAS-SM message, including the device addressing information and the EAP message (e.g., success / failure). The WTRU may forward the EAP authentication result message to the device. If the message indicates that the device was not authenticated, the WTRU may determine to forward traffic to and from the device via a different PDU Session (e.g., a PDU Session that does not require that devices be authenticated) or the WTRU may determine to block traffic from the device. If the message indicates that the device was authenticated, the WTRU may determine to forward traffic to and from the device via the PDU Session.

[0128] At 9, the device may send and receive traffic via the WTRU and the PDU session. At some point, the IP address / prefix or MAC Address may change. The device may send a packet with its (e.g., new) MAC address or IP address / prefix. The packet with the new IP address / prefix or MAC address may trigger actions associated with 10.

[0129] At 10, the UPF may receive the packet and detect that the source MAC Address or IP address / Prefix is not an address the SMF has indicated is allowed. The determination that the detected MAC Address or IP address / Prefix has not yet been allowed may trigger the UPF to repeat 4. In an example, 4 to 6 may be repeated.

[0130] At 11 , when the EAP authentication procedure is complete, the AAA Server may notify the SMF whether the device has been successfully authenticated. The notification may include the Reference ID and an indication of whether or not the device was authenticated. The notification may include a charging identifier. The charging identifier that is provided may be the same charging identifier that was provided to the SMF at 7.

[0131] At 12, the SMF may notify the UPF whether traffic to and from the detected address is allowed. The notification may include the charging identifier. The SMF notification from the SMF may include the IP address / Prefix or MAC Address that was formally associated with the device (e.g., the IP address / Prefix orMAC Address that was associated with the device before the device’s IP address / Prefix or MAC Address changed at 9).

[0132] At 13, the SMF may send a message to the WTRU to notify the WTRU whether the device that is associated with the detected address has been successfully authenticated.

[0133] NAT may be considered herein. The WTRU may be assigned an (e.g., one) IP Address for the PDU Session, and the WTRU may multiplex IP Flows for non-3GPP devices by different port numbers with a non-3GPP device. The procedure of FIG. 2 may be used. The UPF may trigger the authentication and authorization procedure when detecting the source IP Address / Port Number combination. The SMF may indicate to the UPF and WTRU which port numbers are authorized.

[0134] For example, the WTRU may indicate to the SMF that the WTRU may implement NAT functionality between the WTRU and non-3GPP devices so that the SMF knows to perform authentication and authorization on a port number basis. The WTRU may send the indication during the PDU Session Establishment.

[0135] A QoS Rule may be considered herein. In the procedure of FIG. 2, when the SMF receives a notification that traffic for a device is authorized (e.g., at 7 of FIG. 2), the SMF may trigger a PDU Session Modification procedure to send the WTRU new QoS Rules for the authorized MAC Address or IP Address.

[0136] A user may have re-authentication revoked. At any time, the DN-AAA may initiate a reauthentication for a particular user / device. The DN-AAA may initiate the re-authentication with the SMF by providing the user / device addressing information (e.g., MAC address / IP address and port number). The SMF may initiate an authentication (e.g., similar to 5-8a in FIG. 2). If the re-authentication fails, the SMF may remove the MAC or IP address from the list of authorized addresses before sending the reauthentication result to the RG-WTRU.

[0137] The DN-AAA may initiate the revocation of a particular user / device. The DN-AAA may initiate the revocation with the SMF by providing the user / device addressing information (e.g., MAC address / IP address and port number). The SMF may configure the UPF to remove the MAC or IP address from the list of authorized addresses and send a NAS message to the RG-WTRU, including revoked device addressing information.

[0138] In both examples, the RG-WTRU may decide to disconnect the device and release the PDU Session (e.g., if no more devices remain connected).

[0139] User Authentication may be WTRU triggered. FIG. 2 shows an example procedure where the UPF detects that traffic was generated by a MAC Address or IP address / Prefix that may be associated with a device that was not yet authenticated. The procedures of FIG. 2 may be modified as follows.

[0140] At 2, the WTRU may determine to send a NAS-SM message to the SMF. The WTRU may determine to send the NAS-SM message to the SMF because the source IP address / Prefix or MAC address of the packet was not yet indicated as allowed by the SMF. The NAS-SM message may include the IP address / Prefix or MAC address and additional information requesting authentication of the generated traffic by the device behind the WTRU / RG.

[0141] The WTRU may determine to send the NAS-SM message when the WTRU associates with the device (e.g., when the WTRU determines the device’s IP Address or MAC Address). The WTRU may determine to send the NAS-SM after receiving the uplink packet from the device.

[0142] At 3, the SMF may receive the NAS-SM message, and the NAS-SM message may trigger the SMF to initiate EAP Authentication of the non-3GPP device as described at 5.

[0143] User authentication during device registration may be initiated by the RG / WTRU. Authenticating users by RG, during registration, may enable a UPF to be configured in advance, with an allowed IP address or MAC address. When a user initiates communication, it may continue uninterrupted. Features described herein may be associated with a Device MAC / IP address and an User Identity authentication.

[0144] RG may be configured for User ID authentication using an IP address / Prefix or MAC address. A MAC address may become available during the registration of devices. For using an IP address, the RG / WTRU may wait until an IP address is assigned after successful registration. Once an IP address is allocated to the device, the RG / WTRU may trigger a user ID authentication procedure.

[0145] FIG. 3 illustrates an example procedure for RG-triggered device authentication. At 0, the devices behind the RG / WTRU may establish an L2 connection with the RG / WTRU. The RG / WTRU may initiate the EAP authentication procedure with the device by sending an EAP Identity request. The device(s) may respond with identity information. The EAP Identity Response may include a piece of information that may be used to identify the AAA Server that may authenticate the device. The piece of information may be the User Identity of the device.

[0146] At 1 , the RG / WTRU may initiate a registration procedure to register the devices with the system (e.g., the 5GS). The RG / WTRU may indicate to the AMF either with the registration message or in a separate message that the user may be authenticated. The RG / WTRU may send the EAP identity information and MAC address of the device to the AMF. The RG may know the MAC address of the device. Examples described at 1 may be used for IP address-based user identity authentication after the devices are registered and an IP address has been allocated.

[0147] At 2, the AMF may receive the request for User ID authentication, which may include EAP identity information and a MAC address or IP address / prefix of the device. The AMF may select an AUSF based on an EAP user identity. The AMF may send a User ID Authentication Request to the AUSF,indicating to initiate user identity authentication and include “user ID information” and device identifiers (e.g., a MAC address or IP address / prefix).

[0148] At 3, the AUSF may receive the User ID authentication request. The AUSF may select UDM based on User ID information. The AUSF may contact a UDM to obtain User Identity authentication information, such as user credentials, certificates, and keys. The AUSF may send a Get User identity authentication information to UDM, indicating to obtain user ID authentication information for a user identified by User ID information and MAC address or IP address / prefix of the device used by the user.

[0149] At 4, the UDM may select an authentication method based on the User Identity. The UDM may use the user identity to retrieve user authentication credentials (e.g., certificates, keys, etc.). The UDM may update user information with a device MAC or IP address / prefix information received from AUSF. The UDM may send a response, which may include the User Identity authentication information and an indicator of the selected method for user authentication, e.g., EAP-AKA', to AUSF.

[0150] At 5, the AUSF and Device may execute the selected method for user ID authentication. At 6, the AUSF may send to the AMF an EAP-Success message, which may include one or more of the following: User Identity identifier: an identifier that maps the User ID profile / details to Device / network subscription for any future use; and / or User Identity information, indicating user credentials, certificates, etc.

[0151] At 7, the AUSF may indicate to the SMF about the authenticated User Identity information and MAC address or IP address / prefix of the device, in a Configuration message. The configuration request from AUSF may indicate to the SMF that User ID-based service provisioning is requested (e.g., required) and may use the details of the user, which include the IP address / Prefix of the device, User ID, and User profile.

[0152] The SMF may configure the UPF to set an allowed MAC address or IP address / prefix for the authenticated User ID.

[0153] The SMF, after receiving the configuration request from AUSF, may configure the UPF to provide service to a (e.g., specific) user based on the user profile using the IP address / Prefix of the device the user is using. The service provisioning for UPF may be traffic from the IP address / Prefix is allowed or not allowed; traffic from the IP address / Prefix has certain priority over other traffic; or traffic from the IP address / Prefix may be subject to certain delay, dropped, etc.

[0154] After successful configuration, the SMF may respond back to the AUSF with the result of configuration.

[0155] At 8, the AMF may send to the RG the Authentication success information, e.g., EAP-Success message and Device MAC / IP address / prefix, an identifier for the user ID in an authentication response message.

[0156] At 9, the RG may send to the devices the EAP-Success message. In examples, when a user change occurs, the MAC / IP address may remain the same. If a user changes, logs out, and a new user logs in, the MAC address or IP address / Prefix may remain the same.

[0157] As a user logs out and a new user logs in, the device may not have access to the key that was sent from the RG to devices. Subsequent communication may fail. The following may occur: RG may reregister, as described at 4c in the authentication for MAC address; the RG / WTRU may re-initiate a User ID based authentication, as described at 1 for IP address / Prefix based authentication.

[0158] If the user does not change, the MAC / IP address may change. In examples, a user may not change, and the IP / MAC address may change (e.g., due to mobility or reallocation).

[0159] The RG / WTRU may know that the I P / M AC address changed and that the key between the device and RG is (e.g., still) valid. For example, the RG / WTRU may request the AMF to update the User ID based authentication information with the updated (e.g., new) IP / MAC address. EAP-based authentication may not be done (e.g., again), to save time and continue providing service to the user.

[0160] FIG. 4 illustrates an example procedure for continuing communication when a device address changes, and a user does not change. At 1 , the RG / WTRU may detect that a device’s IP / MAC address has changed, and the user has not changed, because the key used between the device and RG is (e.g., still) valid. The RG may decide to update the user identity information with the system (e.g., the 5GS). This may be to inform the system (e.g., 5GS) that the user is (e.g., still) the same, and the associated IP / MAC address has changed. The RG / WTRU may send an Update User Id Authentication request to the AMF. The request may include the User ID identifier, which was previously generated for the user, to identify the user identity that is to be updated. The RG / WTRU may provide the updated (e.g., new) IP / MAC address to the AMF.

[0161] At 2, the AMF may validate the User ID identifier, and based on the User ID identifier, retrieve user identity and user profile information. The AMF may identify the AUSF, which may process the Update User Id Authentication request. The AMF may send the request to the AUSF and include the User ID identifier, that identifies the user profile to the system (e.g., 5GS), to identify the user identity that is to be updated. The AMF may provide the new IP / MAC address to the AUSF.

[0162] At 3, the AUSF may send the update request to the UDM with the User ID identifier and updated (e.g., new) IP / MAC address. The UDM may verify, validate, and update its database. At 4, the UDM may send the result of the update to the AUSF, indicating that the update was successful. At 5, the AUSF may send the result of the update to the AMF, indicating that the update was successful. At 6, the AMF may reconfigure the SMF, which may reconfigure the UPF with the updated (e.g., new) IP / MAC address. At 7, the AMF may send the result of the update to RG, indicating that the update was successful.

[0163] Although features and elements described above are described in particular combinations, each feature or element may be used alone without the other features and elements of the preferred embodiments, or in various combinations with or without other features and elements.

[0164] Although the implementations described herein may consider 3GPP specific protocols, it is understood that the implementations described herein are not restricted to this scenario and may be applicable to other wireless systems. For example, although the solutions described herein consider LTE, LTE-A, New Radio (NR) or 5G specific protocols, it is understood that the solutions described herein are not restricted to this scenario and are applicable to other wireless systems as well.The processes described above may be implemented in a computer program, software, and / or firmware incorporated in a computer-readable medium for execution by a computer and / or processor. Examples of computer-readable media include, but are not limited to, electronic signals (transmitted over wired and / or wireless connections) and / or computer-readable storage media. Examples of computer-readable storage media include, but are not limited to, a read only memory (ROM), a random access memory (RAM), a register, cache memory, semiconductor memory devices, magnetic media such as, but not limited to, internal hard disks and removable disks, magneto-optical media, and / or optical media such as compact disc (CD)-ROM disks, and / or digital versatile disks (DVDs). A processor in association with software may be used to implement a radio frequency transceiver for use in a WTRU, terminal, base station, RNC, and / or any host computer.

Claims

CLAIMSWhat is Claimed:1 . A first network node comprising a processor configured to: receive, from a second network node an indication comprising a detected address; determine that traffic associated with the detected address is unauthorized; send, to a WTRU, a first message comprising the detected address and comprising an extensible authentication protocol (EAP) payload to initiate authentication of a device associated with the detected address; receive, from the WTRU, a second message comprising an EAP response associated with the device; send, to a third network node, a third message comprising the EAP response and the detected address; receive, from the third network node, a fourth message indicating that the device is authenticated; and send, to the second network node, a fifth message indicating that traffic associated with the detected address is authorized.

2. The first network node of claim 1 , wherein the first network node comprises a session management function (SMF), the second network node comprises a user plane function (UPF), and the third network node comprises an authentication, authorization, and accounting (AAA) server.

3. The first network node of claim 1 , wherein the detected address comprises at least one of a source IP address, an IP address prefix, a source port number, or a MAC address associated with the WTRU.

4. The first network node of claim 1 , wherein the first message further comprises a PDU session identifier associated with the WTRU, and wherein the EAP payload in the first message comprises an EAP identity request.

5. The first network node of claim 1 , wherein the first message is transmitted in a Non-Access Stratum Session Management (NAS-SM) message comprising a PDU session modification command directed to the WTRU.

6. The first network node of claim 1, wherein the EAP response included in the second message comprises an EAP identity response, and wherein the EAP identity response comprises information associated with identifying the third network node, and wherein the information associated with identifying the third network node comprises one or more of the following: a domain identifier field, a mobile network operator (MNO) identifier, a service provider identifier, or an AAA server identifier.

7. The first network node of claim 1 , wherein the fifth message further comprises a charging identifier received from the third network node, and wherein the charging identifier is provided to the second network node for recording data usage associated with the WTRU.

8. The first network node of claim 1 , wherein the processor is further configured to: receive, from the third network node, a first EAP message; send, to the WTRU, the first EAP message, wherein the first EAP message is forwarded to the device; and receive, from the WTRU, a second EAP message generated by the device, wherein the second EAP message corresponds to the first EAP message; and send the second EAP message to the third network node.

9. The first network node of claim 1 , wherein the processor is further configured to send to the WTRU, based on the device being authenticated, a sixth message indicating the authentication result associated with the device.

10. A method for a first network node , wherein the method comprises: receiving, from a second network node an indication comprising a detected address; determining that traffic associated with the detected address is unauthorized; sending, to a WTRU, a first message comprising the detected address and comprising an extensible authentication protocol (EAP) payload to initiate authentication of a device associated with the detected address; receiving, from the WTRU, a second message comprising an EAP response associated with the device; sending, to a third network node, a third message comprising the EAP response and the detected address; receiving, from the third network node, a fourth message indicating that the device is authenticated; andsending, to the second network node, a fifth message indicating that traffic associated with the detected address is authorized.11 . The method of claim 10, wherein the first network node comprises a session management function (SMF), the second network node comprises a user plane function (UPF), and the third network node comprises an authentication, authorization, and accounting (AAA) server.

12. The method of claim 10, wherein the detected address comprises at least one of a source IP address, an IP address prefix, a source port number, or a MAC address associated with the WTRU.

13. The method of claim 10, wherein the first message further comprises a PDU session identifier associated with the WTRU, and wherein the EAP payload in the first message comprises an EAP identity request.

14. The method of claim 10, wherein the first message is transmitted in a Non-Access Stratum Session Management (NAS-SM) message comprising a PDU session modification command directed to the WTRU.

15. The method of claim 10, wherein the EAP response included in the second message comprises an EAP identity response, and wherein the EAP identity response comprises information associated with identifying the third network node, and wherein the information associated with identifying the third network node comprises one or more of the following: a domain identifier field, a mobile network operator (MNO) identifier, a service provider identifier, or an AAA server identifier.

16. The method of claim 10, wherein the fifth message further comprises a charging identifier received from the third network node, and wherein the charging identifier is provided to the second network node for recording data usage associated with the WTRU.

17. The method of claim 10, wherein the method further comprises: receiving, from the third network node, a first EAP message; sending, to the WTRU, the first EAP message, wherein the first EAP message is forwarded to the device; receiving, from the WTRU, a second EAP message generated by the device, wherein the second EAP message corresponds to the first EAP message; and sending the second EAP message to the third network node.

18. The method of claim 10, wherein the method further comprises sending to the WTRU, based on the device being authenticated, a sixth message indicating the authentication result associated with the device.

Citation Information

Patent Citations

  • Method of authorization for network slicing

    US20220116816A1