A method for network slice-specific authentication and authorization, corresponding user equipment and authentication, authorization and accounting server (AAA-s)
By implementing a method where the UE verifies slice-specific criteria in the KDF Input attribute, the method addresses the lack of secure authentication in 5G network slicing, particularly in roaming scenarios, ensuring only authorized slices are accessed, thus enhancing security and maintaining control over the used slice.
Patent Information
- Application Number
- PCT/EP2025/057764
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-26
- Filing Date
- 2025-03-21
- Publication Date
- 2025-10-02
AI Technical Summary
Current 5G network slicing technologies lack effective mechanisms for ensuring secure and slice-specific authentication and authorization, particularly in roaming scenarios where the AAA-S is external to the core network, leading to potential confidentiality breaches and unauthorized access.
The method involves sending a Key Derivation Function (KDF) Input attribute from the AAA-S to the UE, which includes specific criteria for the UE to verify, allowing it to authorize or abort authentication based on matching criteria, enhancing security by ensuring only authorized slices are accessed.
This approach enhances security by preventing unauthorized access to untrusted slices, maintaining control over the used slice, especially in roaming scenarios, thereby ensuring secure network slice-specific authentication and authorization.
Smart Images

Figure EP2025057764_02102025_PF_FP_ABST
Abstract
Description
[0001] A method for network slice-specific authentication and authorization, corresponding user equipment and Authentication, Authorization and Accounting Server (AAA-S)
[0002] FIELD OF THE INVENTION
[0003] The present invention concerns telecommunications and in particular 5G network slicing.
[0004] BACKGROUND
[0005] 5G network slicing is a network architecture that provides a way to divide a network to provide independent logical networks over physical network resources and functionality. This can help operators (MNOs) to provide differentiated services and more quickly deploy new cases.
[0006] An operator can use network slicing to logically allocate physical resources across one or more slices, where each slice may have a different Quality of Service (QoS) and other performance characteristics, as well as configurations and policies, to meet a variety of use cases and possible Service Level Agreements (SLAs).
[0007] For example, a slice supporting mobile broadband users may require high data rates and traffic volumes, a slice supporting Internet of Things devices may optimize high-density devices and power consumption, and a slice supporting autonomous driving may provide high-reliability and low-latency communications.
[0008] Today, 3GPP defines slice authentication (see for example 5G; 5G System; Network Slice- Specific Authentication and Authorization (NSSAA) services; Stage 3 (3GPP TS 29.526 version 16.2.0 Release 16).
[0009] Figure 1 represents the relationship 100 between primary authentication and slice-specific authentication and authorization, as described in European Telecommunications Standards Institute (ETSI) TS 133.501 version 16.3.0, figure 16.2-1.
[0010] In the figure 1 , six entities are represented: A UE (user equipment) 20, an AMF / SEAF (Access and Mobility Management Function / Security Anchor Function) 21 , a NSSAAF (Network Slice Specific Authentication and Authorization Function) 22, an AAA-P (Authentication, Authorization and Accounting Proxy) 23, an AAA-S (Authentication, Authorization and Accounting Server) 24 and an ARPF / UDM (Authentication Credential Repository and Processing Function / Unified Data Management) 25.
[0011] The procedure is as follows:
[0012] At step 1 , the UE 20 sends a Registration Request with a list of S-NSSAIs to the AMF / SEAF 21. The UE 20 shall not comprise those S-NSSAIs for which NSSAA procedures are ongoing, regardless of access types.
[0013] At step 2, for an initial Registration Request, the AMF / SEAF 21 shall invoke primary authentication. For a subsequent Registration Request, the Primary authentication may be skipped if the UE 20 has already been authenticated and the AMF / SEAF 21 has a valid security context.
[0014] At step 3, the AMF 21 determines whether NSSAA is required for each of the S-NSSAIs, based on information stored locally or from the UDM 25. This corresponds to the selection of a slice.
[0015] At step 4a, the AMF 21 sends the Registration Accept message to the UE 20. Optionally, the UE 20 sends a Registration Complete (step 4b).
[0016] At step 5, an Extensible Authentication Protocol (EAP) based NSSAA procedure is performed for each S-NSSAI if required, as determined in step 3. This is the purpose of the invention as it will be seen later. Step 5 is an optional step according to the above-mentioned technical specification (TS) and permits to establish a mutual authentication between the UE 20 and the AAA-S 24. EAP is the protocol and the algorithm used for the exchanges is not specified (TLS / EAP or others).
[0017] Finally, at step 6, based on the results of step 5, the AMF 21 sends UE Configuration Update to update the requested S-NSSAI status based on the NSSAA results.
[0018] The AAA-S 24 can be outside the core network of the MNO (Mobile Network Operator) according to this TS 33.501 : It can be in a private network for example (the MNO rents a slice to a Service Provider owning the AAA-S 24). The Service Provider is confident in the MNO but wishes however to have his own authentication with the UE 20. It is then necessary to establish a slice authentication mechanism (step 5 of figure 1). Moreover, if the UE 20 is in roaming (for example abroad), the slice supporting a communication is not necessarily the one that has been rented by the Service Provider (SP): A VPLMN (Visited PLMN) can attribute an equivalent slice as described in ETSI TS 123 501 V17.11.0 (2024 01) instead of the rented slice. The AAA-S 24 has no precise information of the allocated slice when the AAA-S 24 is not in the core network of the MNO (HPLMN).
[0019] For example, if a company has rented a slice for conveying confidential information (for example for EDF (Electricite de France) and the information is relative to a nuclear plant), EDF gets an information that he is on an EDF slice, but this is not true:
[0020] The MNO can, for infrastructure reasons, coverage, etc., share a slice between EDF and another company (McDonald). There is here a confidentiality problem because there is no strong isolation of the communications.
[0021] Moreover, the AAA-S 24 cannot know if the UE 10 is in roaming and the communication can then be intercepted by the authorities of the VPLMN.
[0022] The purpose of the invention is, among others, to indicate to the UE 10 that he is not allowed / authenticated to use a given slice or that he is not allowed / authenticated to validate the slice authentication when the UE 10 is in a given country.
[0023] Non-Patent Literature entitled “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 18)” describes a method for Network slice specific authentication and authorization.
[0024] International Patent Application Publication No. WO 2024 / 036462 A1 describes methods, apparatuses, and computer readable storage media for registration enhancements for multiaccess.
[0025] SUMMARY
[0026] The invention proposes a solution to this problem.
[0027] More precisely, the invention provides a method for network slice-specific authentication and authorization in a telecommunication network. The method comprises sending, from an Authentication, Authorization and Accounting Server (AAA-S) to a user equipment UE, a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, where the KDF Input attribute comprises at least one criterion that the UE has to verify. The method further comprises verifying at the UE that the criterion matches with a corresponding criterion stored at the UE. The method further comprises, if the criterion matches, authorizing the UE to proceed to an authentication according to Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA) with the AAA-S and, if the criterion does not match, aborting the authentication.
[0028] According to some example embodiments, the criterion is one of the following: localization of the UE (20), comprising a roaming situation, an exact S-NSSAI value, a matching Slice Service Type (SST) or matching Service Differentiator (SD), a roaming not allowed information, an allowed or not allowed geographical location of the UE, a list of authorized S-NSSAI, comprising mapped S-NSSAI, or forbidden S-NSSA and a reference to preconfigured rules in the UE.
[0029] According to some example embodiments, the EAP message further comprises Random challenge (AT_RAND), Authentication Token (AT_AUTN), Key Derivation Function Selection (AT_KDF), and Message Authentication Code (ATJ AC).
[0030] According to some example embodiments, the method further comprises retrieving the S-NSSAI from the KDF Input attribute. The method also comprising extracting an expected S-NSSAI and a matching criterion from a database.
[0031] According to some example embodiments, the verifying comprises comparing the retrieved S- NSSAI to the expected S-NSSAI.
[0032] Further, the invention provides an Authentication, Authorization and Accounting Server (AAA-S) for network slice-specific authentication and authorization in a telecommunication network. The AAA-S is configured for sending, from the AAA-S to a user equipment (UE), a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, where the KDF Input attribute comprises at least one criterion, that the UE has to verify.
[0033] Further, the invention provides a user equipment (UE) for network slice-specific authentication and authorization in a telecommunication network. The UE is configured for receiving, from an AAA-S in a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, where the KDF Input attribute comprises at least one criterion that the UE has to verify. The UE is configured for verifying that the criterion matches with a corresponding criterion stored at the UE. If the criterion matches, the method further comprises authorizing the UE to proceed to an authentication according to Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA) with the AAA-S and, if the criterion does not match, aborting the authentication.
[0034] Further, the invention provides a system for network slice-specific authentication and authorization in a telecommunication network. The system comprises a user equipment (UE) and an Authentication, Authorization and Accounting Server (AAA-S). The AAA-S is configured for sending from the AAA-S to the UE in a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, where the KDF Input attribute comprises at least one criterion that the UE has to verify. The UE is configured for receiving from the AAA-S in the attribute of the EAP message at least one criterion that the UE has to verify. The UE is further configured for verifying that the criterion matches with a corresponding criterion stored at the UE and if the criterion matches, authorizing the UE to proceed to an authentication according to Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA’) with the AAA-S and, if the criterion does not match, aborting the authentication.
[0035] BRIEF DESCRIPTION OF THE DRAWINGS
[0036] The invention will be better understood by reading the description below of a preferred embodiment of the invention, given as a non-exhaustive example, in view of the figures that represent: Figure 1 an extract of the ETSI standard TS 133 501 V16.3.0 (2020-08) entitled “5G; Security architecture and procedures for 5G System (3GPP TS 33.501 version 16.3.0 Release 16)” and represents figure 16.2-1 describing the “Authorization for network slice access”;
[0037] Figure 2 the EAP based NSSAA procedure, also called “network slice-specific authentication and authorization”, according to the present invention and based on ETSI TS 133 501 V17 from January 2024; and
[0038] Figure 3 a method for network slice-specific authentication and authorization in a telecommunication network.
[0039] The present invention will be better understood by reading the following description of the above figures.
[0040] DETAILED DESCRIPTION
[0041] The term “Network Slice-Specific Authentication and Authorization” refers to a process in 5G networks where a user's access to a specific network slice is verified and authorized based on their identity and the requirements of that slice. This procedure is typically managed by a dedicated function called the “Network Slice-Specific Authentication and Authorization Function (NSSAAF)” within the network infrastructure.
[0042] The term “private network” used in this disclosure refers to a Non-Public Network (or NPN in 3GPP specifications) or is also referred to as a Mobile Private Network (MPN).
[0043] Figure 1 has been described in regard of the state of the art.
[0044] Figure 2 illustrates the EAP based NSSAA procedure 200, also called “network slice-specific authentication and authorization”, according to the present invention and based on ETSI TS 133 501 V17 from January 2024.
[0045] In this procedure, at step 30, for S-NSSAIs that are requiring NSSAA, based on change of subscription information, or triggered by the AAA-S 24, the AMF 21 triggers the start of the NSSAA procedure. For example, if NSSAA is triggered as a result of the Registration procedure, the AMF 21 determines, based on UE 20 Context in the AMF 21 , that for some or all S-NSSAI(s) subject to NSSAA, the UE 20 has already been authenticated following a registration procedure on a first access. Depending on NSSAA result (e.g. success / failure) from the previous Registration, the AMF 21 determines, based on Network policies, whether to skip NSSAA for these S-NSSAIs during the Registration on a second access.
[0046] If the NSSAA procedure corresponds to a re-authentication and re-authorization procedure triggered as a result of AAA Server-triggered UE 20 for re-authentication and re-authorization for one or more S-NSSAIs, or triggered by the AMF 21 based on operator policy or a subscription change and if S-NSSAIs that are requiring Network Slice-Specific Authentication and Authorization are comprised in the Allowed NSSAI for each Access Type, the AMF 21 selects an Access Type to be used to perform the NSSAA procedure based on network policies.
[0047] At step 31 , the AMF 21 requests the UE 20 for User ID for Extensible Authentication Protocol (EAP) authentication (interchangeably referred to as “EAP ID”) for the S-NSSAI in a Non-Access Stratum mobility management (NAS-MM) Transport message comprising the S-NSSAI.
[0048] At step 32, the UE 20 provides the EAP ID for the S-NSSAI alongside the S-NSSAI in an NAS- MM Transport message towards the AMF 21 .
[0049] At step 33, the AMF 21 sends the EAP ID to the NSSAAF 22 which provides an interface with the AAA, in an NSSAAF 22_NSSAA_Authenticate Request. The request can comprise EAP ID Response, Generic Public Subscription Identifier (GPSI), and S-NSSAI message.
[0050] At step 34, if the AAA-P 23 is present (e.g., when the AAA-S 24 belongs to a third party and the operator deploys a proxy towards third parties), the NSSAAF 22 forwards the EAP ID Response message to the AAA-P 23, otherwise i.e. when AAA-P 23 is absent, the NSSAAF 22 forwards the message directly to the AAA-S 24. The NSSAAF 22 routes to the AAA-S 24 based on the S- NSSAI. The NSSAAF 22 / AAA-P 23 forwards the EAP Identity message to the AAA-S 24 together with S-NSSAI and GPSI. The AAA-S 24 stores the GPSI to create an association with the EAP ID in the EAP ID response message so that the AAA-S 24 can later use it to revoke authorization or to trigger reauthentication. The AAA-S 24 uses the EAP-ID and S-NSSAI to identify for which UE 20, slice authorization is requested. If the AAA-S 24 belongs to the 3rd party, the NSSAAF 22 optionally maps the S-NSSAI to External Network Slice Information (ENSI) and forwards the EAP Identity message to the AAA-S 24 together with ENSI and GPSI. In this case, the AAA-S 24 uses the EAP-ID and ENSI to identify the UE 20 for which slice authorization is requested.
[0051] During steps 35 to 41 , EAP-messages are exchanged with the UE 20. One or more iterations of these steps may occur.
[0052] In particular, at step 35, when the AAA-S 24 belongs to the 3rd party and EAP method such as Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA’), is used to send the following EAP message:
[0053] (EAP msg: EAP-Request / AKA'-Challenge (AT_RAND, AT_AUTN, AT_KDF, AT_KDF_INPUT, AT_MAC), GPSI, AF_Service_ldentifier).
[0054] EAP-AKA’ is an authentication method used in mobile networks. It is based on the AKA (Authentication and Key Agreement) mechanism used in cellular networks to authenticate users and establish encryption keys.
[0055] The EAP message may comprise EAP-AKA’ related information such as
[0056] • Random challenge (AT_RAND)- this attribute is used to verify the subscriber’s identity,
[0057] • Authentication Token (AT_AUTN),
[0058] • Key Derivation Function Selection (AT_KDF) - this attribute specifies the key derivation function (KDF) used for generating session keys,
[0059] • Key Derivation Function Input (AT_KDF_INPUT) (interchangeably referred to as KDF Input attribute) - this attribute contains additional input parameters used in the key derivation process, and
[0060] • Message Authentication Code (AT_MAC) - this attribute corresponds to a cryptographic integrity check comprised in the EAP-AKA' message to ensure message integrity and authenticity.
[0061] The RFC defining the EAP-AKA’ in general and the AT_KDF_INPUT in particular can be found here: https: / / datatracker.ietf.orq / doc / html / rfc9048#name-at kdf input In this attribute, the invention proposes, instead of the network name as defined in ETSI TS 124 302, to send at least one criterion. This criterion can comprise for example at least one of:
[0062] • an exact S-NSSAI value,
[0063] • a matching Slice Service Type (SST) or matching Service Differentiator (SD),
[0064] • a roaming not allowed information,
[0065] • an allowed or not allowed geographical location of the UE,
[0066] • a list of authorized S-NSSAI (comprising mapped S-NSSAI) or forbidden S-NSSAI, and
[0067] • a reference to preconfigured rules in the UE.
[0068] At steps 36 and 37, this message is forwarded to the AMF 21 and UE 20, respectively.
[0069] The UE 20 then, at step 38:
[0070] • Retrieves the criterion such as S-NSSAI from the KDF Input attribute;
[0071] • Extracts the matching criterion such as expected S-NSSAI and related information from the database;
[0072] • Compares the expected S-NSSAI to the connected S-NSSAI (and potentially to other criterion provided by AAA-S 24). This corresponds to a verification by the UE 20 that the received criterion(s) match with the corresponding criterion(s) stored at the UE 20. In particular, it checks the real slice on which authentication is ongoing with regard to the expected slice and the matching criterion provided by the AAA-S 24, and if the criterion matches, the UE 20 is authorized to continue the authentication (step 39) with EAP-AKA with the AAA-S 24.
[0073] • On the contrary, if the criterion does not match, the authentication is aborted (not represented).
[0074] The UE 20 is composed of a ME (Mobile Equipment) and a secure element (SIM card, UICC, eUlCC or iUICC for example) and the criterion(s) can be stored in the ME or in the secure element. The comparison can be done also in the ME or in the secure element.
[0075] The criterion is stored at the UE 20. It can be either pre-loaded therein (e.g. via the profile if it is stored in the secure element or even in the ME if it is very generic criteria). It is also possible to update the criterion (criteria) by Over-The-Air (OTA) (or OTA loading if no pre-loading). At step 40, the AMF sends a Nssaaf_NSSAA_Authenticate Request (e.g., comprising EAP msg, GPSI) message to the NSAAF 22 and at step 41 , the NSAAF 22 sends an AAA Protocol message (e.g., comprising EAP msg, GPSI, AF_Service_ldentifier) to the AAA-S 24. At step 42, the AAA- S 24 replies with an AAA Protocol message (e.g., comprising EAP success / failure, GPSI, AF_Service_ldentifier) to the NSSAAF 22.
[0076] At step 43, the NSSAAF 22 sends the NSSAAF _NSSAA_Authenticate Response to the AMF 21 . The authenticate response may comprise EAP-Success / Failure message, S-NSSAI, and GPSI.
[0077] At step 44, the AMF 21 transmits a NAS-MM Transport message to the UE 20. The NAS-MM Transport message may comprise EAP-Success / Failure message.
[0078] At step 45, based on the result of Slice specific authentication (EAP-Success / Failure), if a new allowed NSSAI or new rejected NSSAI needs to be delivered to the UE 100, or if the re-allocation of AMF 21 is required, the AMF 21 initiates the UE Configuration Update procedure, for each Access Type, as described in clause 4.2.4.2 of TS 23.502.
[0079] The invention also concerns an AAA-S 24 for network slice-specific authentication and authorization in a telecommunication network, the AAA-S 24 being configured for sending from the AAA-S 24 to a UE 20 in an AT_KDF_INPUT attribute of an EAP message. The message comprises at least one criterion instead of Network Name, that the UE 20 has to verify.
[0080] Finally, the invention also concerns a UE 20 for network slice-specific authentication and authorization in a telecommunication network. The UE 20 being configured for:
[0081] • receiving from an AAA-S 24 in an AT_KDF_INPUT attribute of an EAP message, the attribute may comprise at least one criterion instead of Network Name, that the UE 20 has to verify;
[0082] • verifying that the criterion matches with a corresponding criterion stored at the UE 20, and
[0083] • if the criterion matches, authorizing the UE 20 to proceed to an authentication per EAP-AKA with the AAA-S 24 and, if the criterion does not match, aborting the authentication.
[0084] The advantages of the invention are that:
[0085] • Security is increased by avoiding connection using untrusted and potentially unsafe slice; The SP renting a slice keeps control of the real used slice.
[0086] Figure 3 illustrates a method 300 for network slice-specific authentication and authorization in a telecommunication network.
[0087] At step 302, a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message is sent from an Authentication, Authorization and Accounting Server (AAA-S) 24 to a user equipment (UE) 20. The KDF Input attribute comprises at least one criterion that the UE 20 has to verify. In an embodiment, the criterion can comprise one or more of: localization of the UE 20, comprising a roaming situation; an exact S-NSSAI value; a matching Slice Service Type (SST) or matching Service Differentiator (SD); a roaming not allowed information; an allowed or not allowed geographical location of the UE; a list of authorized S-NSSAI, comprising mapped S-NSSAI, or forbidden S-NSSAI; and a reference to preconfigured rules in the UE.
[0088] In an embodiment, the method 300 further comprises retrieving the S-NSSAI from the KDF Input attribute, and extracting an expected S-NSSAI and a matching criterion from a database.
[0089] At step 304, it is verified at the UE whether the criterion matches with a corresponding criterion stored at the UE 20. In an embodiment, the step of verifying comprises comparing the retrieved S-NSSAI to the expected S-NSSAI.
[0090] At step 306, if the criterion matches, UE 20 is authorized to proceed to an authentication according to Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA) with said AAA-S 24. In other words, if the UE successfully verifies that the criterion (exact value of parameters) received from the AAA-S 24 server matches the stored criterion (expected value of the parameters), it proceeds with authentication using the Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA’) with the AAA-S 24 server. The UE is authorizing itself to proceed with authentication towards the AAA-S i.e. when the criterion matches, the AAA- S 24 will then continue the authentication process. At step 308, if the criterion does not match, the authentication is aborted. If the UE determines that the received criterion does not match the stored criterion, the authentication process is aborted. If the received slice authentication criteria do not match the UE’s stored slice information, the UE 20 determines that it is being connected to an unauthorized or untrusted slice. This can happen in roaming scenarios where the UE is assigned an equivalent but potentially less secure network slice. To prevent unauthorized access or security risks, the UE rejects the authentication request before completing the EAP-AKA’ process. This prevents the UE from being authenticated on an unauthorized or untrusted network slice.
[0091] This method is particularly useful in roaming scenarios where the visited network might provide a different slice than the one originally requested. The AAA server does not directly verify the slice but instead delegates the slice verification to the UE. The UE checks whether it is being authenticated on a valid slice and rejects the authentication if the slice does not meet the expected criteria.
[0092] Various embodiments of the invention may comprise one or more computer programs stored or otherwise embodied on a computer-readable medium, wherein the computer programs are configured to cause a processor or the computer to perform one or more operations. A computer- readable medium storing, embodying, or encoded with a computer program, or similar language may be embodied as a tangible data storage device storing one or more software programs that are configured to cause a processor or computer to perform one or more operations. Such operations may be, for example, any of the steps or operations described herein. In some embodiments, the computer programs may be stored and provided to a computer using any type of non-transitory computer-readable media.
Claims
CLAIMS1. A method (300) for network slice-specific authentication and authorization in a telecommunication network, said method (300) comprising:- sending (302), from an Authentication, Authorization and Accounting Server (AAA-S) (24) to a user equipment (UE) (20), a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, the KDF input attribute comprising at least one criterion that said UE (20) has to verify;- verifying (304) at said UE (20) that said criterion matches with a corresponding criterion stored at said UE (20), and- if said criterion matches, authorizing (306) said UE (20) to proceed to an authentication according to Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA) with said AAA-S (24) and, if said criterion does not match, aborting (308) said authentication.
2. The method (300) according to claim 1 wherein said criterion is one of: localization of said UE (20), comprising a roaming situation; an exact S-NSSAI value; a matching Slice Service Type (SST) or matching Service Differentiator (SD); a roaming not allowed information; an allowed or not allowed geographical location of the UE (20); a list of authorized S-NSSAI, comprising mapped S-NSSAI, or forbidden S-NSSAI; and a reference to preconfigured rules in the UE (20).
3. The method (300) according to claim 1 , wherein the EAP message further comprises: Random challenge (AT_RAND),Authentication Token (AT_AUTN),Key Derivation Function Selection (AT_KDF), and Message Authentication Code (AT_MAC).
4. The method (300) according to claim 1 , further comprising: retrieving the S-NSSAI from the KDF Input attribute; and extracting an expected S-NSSAI and a matching criterion from a database.
5. The method (300) according to claim 4, wherein the verifying comprises comparing the retrieved S-NSSAI to the expected S-NSSAI.
6. An Authentication, Authorization and Accounting Server (AAA-S) (24) for network slicespecific authentication and authorization in a telecommunication network, said AAA-S (24) being configured for sending from said AAA-S (24) to a user equipment (UE) (20) in a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, the KDF Input attribute comprising at least one criterion that said UE (20) has to verify.
7. A user equipment (UE) (20) for network slice-specific authentication and authorization in a telecommunication network, said UE (20) being configured for:- receiving from an Authentication, Authorization and Accounting Server (AAA-S) (24) in a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, the KDF Input attribute comprising at least one criterion that said UE (20) has to verify;- verifying that said criterion matches with a corresponding criterion stored at said UE (20), and- if said criterion matches, authorizing said UE (20) to proceed to an authentication according to Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA) with said AAA-S (24) and, if said criterion does not match, aborting said authentication.
8. A system for network slice-specific authentication and authorization in a telecommunication network, said system comprising: a user equipment (UE) (20); an Authentication, Authorization and Accounting Server (AAA-S) (24) configured for sending to the UE (20) a Key Derivation Function (KDF) Input attribute of an Extensible Authentication Protocol (EAP) message, the KDF Input attribute comprising at least one criterion that said UE (20) has to verify, wherein the UE (20) is configured for:- receiving from the AAA-S (24) in the attribute of the EAP message at least one criterion that said UE (20) has to verify;- verifying that said criterion matches with a corresponding criterion stored at said UE (20); and- if said criterion matches, authorizing said UE (20) to proceed to an authentication according to Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA) with said AAA-S (24) and, if said criterion does not match, aborting said authentication.
Citation Information
Patent Citations
Registration enhancement for multi-access
WO2024036462A1