Supporting subscription permanent identifier based lawful intercept

By mapping temporary UE identifiers to SUPI in the home network and deriving security keys, the method addresses security and privacy issues in hosted NPNs, enabling effective legal interception without exposing the SUPI, thereby safeguarding against threats and maintaining confidentiality.

WO2026009205A1PCT designated stage Publication Date: 2026-01-08LENOVO (SINGAPORE) PTE LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/058116
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-09
Filing Date
2025-08-08
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

In wireless communication systems where a non-public network (NPN) is hosted by a public land mobile network (PLMN), exposing the subscription permanent identifier (SUPI) to network functions in the customer premises can lead to security threats, privacy breaches, and inadequate legal interception (LI) due to the lack of SUPI disclosure to the hosted NPN.

Method used

A method where network functions in the hosted NPN request a mapping of a temporary UE identifier to the SUPI from the home network's UDM, allowing legal interception while keeping the SUPI concealed from the hosted network, and deriving security keys like KAMF in the home network.

Benefits of technology

Enables legal interception in hosted NPN scenarios without revealing the SUPI, ensuring security and privacy by using temporary UE identifiers and derived security keys, thus protecting against potential threats and maintaining SUPI confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025058116_08012026_PF_FP_ABST
    Figure IB2025058116_08012026_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to supporting subscription permanent identifier (SUPI) based lawful intercept (LI). A network equipment (NE) transmits a request that includes an LI target identity and an LI support activate indication. The NE receives a response that identifies a mapping of at least one of a SUPI or an associated generic public subscription identifier (GPSI) of the LI target identity that is mapped to a temporary user equipment (UE) identifier (ID).
Need to check novelty before this filing date? Find Prior Art

Description

SUPPORTING SUBSCRIPTION PERMANENT IDENTIFIER BASED LAWFUL INTERCEPTRELATED APPLICATION

[0001] This application claims priority to U.S. Patent Application Serial No. 63 / 681,588 filed August 9, 2024 entitled “SUPPORTING SUBSCRIPTION PERMANENT IDENTIFIER BASED LAWFUL INTERCEPT FOR SELECTIVE USER EQUIPMENT,” the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD

[0002] The present disclosure relates to wireless communications, and more specifically to supporting subscription permanent identifier (SUPI) based lawful intercept (LI).BACKGROUND

[0003] A wireless communications system may include one or multiple network communication devices, such as base stations, which may be otherwise known as network equipment (NE), supporting wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like)). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY

[0004] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or“one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). By way of another example, a list of at least one of A; B; or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on”. Further, as used herein, including in the claims, a “set” may include one or more elements.

[0005] An NE (e.g., a base station) for wireless communication is described. The NE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the NE may be configured to, capable of, or operable to transmit a request that includes a LI target identity and an LI support activate indication; receive a response that identifies a mapping of at least one of a subscription permanent identifier (SUPI) or an associated generic public subscription identifier (GPSI) of the LI target identity to a temporary UE identifier (ID).

[0006] A processor (e.g., a standalone processor chipset, or a component of an NE (e.g., a base station)) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to transmit a request that includes a LI target identity and an LI support activate indication; receive a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0007] A method performed or performable by an NE (e.g., a base station) for wireless communication is described. The method may include transmitting a request that includes a LI target identity and an LI support activate indication; and receiving a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0008] In some implementations of the NE, the processor, and the method described herein, the LI target identity includes at least one of a SUPI, a GPSI, a temporary UE ID, or a permanent equipment identifier (PEI). In some implementations of the NE, the processor, and the methoddescribed herein, the request further includes one or more of a secondary node (SN) name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity.

[0009] In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to store a mapping of the SUPI and the GPSI to the temporary UE ID, and an indication that the temporary UE ID is the LI target identity. In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to transmit the request based at least in part on the NE not having the SUPI corresponding to the LI target identity.

[0010] In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to transmit the request and receive the response via at least one of an authentication management function (AMF) or a security anchor function (SEAF) of a hosted non-public network (NPN). In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to transmit the request and receive the response via a core network function of a hosted NPN.

[0011] An NE (e.g., a base station) for wireless communication is described. The NE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the NE may be configured to, capable of, or operable to receive a request that includes a LI target identity and an LI support activate indication; transmit a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0012] A processor (e.g., a standalone processor chipset, or a component of an NE (e.g., a base station)) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to receive a request that includes a LI target identity and an LI support activate indication; transmit a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0013] A method performed or performable by an NE (e.g., a base station) for wireless communication is described. The method may include receiving a request that includes a LI target identity and an LI support activate indication; and transmitting a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0014] In some implementations of the NE, the processor, and the method described herein, the LI target identity includes at least one of a SUPI, a GPSI, a temporary UE ID, or a PEI. In some implementations of the NE, the processor, and the method described herein, the request further includes one or more of a SN name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity.

[0015] In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to retrieve a mapping of the SUPI and the GPSI to the temporary UE ID. In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to receive the request and transmit the response via at least one of a unified data management (UDM) function, an authentication credential repository and processing function (ARPF), an authentication server function (AUSF), or a subscription identifier de-concealing function (SIDF) of a home public land mobile network (PLMN).

[0016] An NE (e.g., a base station) for wireless communication is described. The NE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the NE may be configured to, capable of, or operable to generate, based at least in part on a SUPI and an anti-bidding down between architectures (ABBA), a key for authentication management function (KAMF); transmit the KAMF and the ABBA.

[0017] A processor (e.g., a standalone processor chipset, or a component of an NE (e.g., a base station)) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to generate, based at least in part on a SUPI and an ABBA, a KAMF; transmit the KAMF and the ABBA.

[0018] A method performed or performable by an NE (e.g., a base station) for wireless communication is described. The method may include generating, based at least in part on a SUPI and an ABBA, a KAMF; and transmitting the KAMF and the ABBA.

[0019] In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to generate the KAMF and transmit the KAMF via at least one of a SEAF or an authentication server function (AUSF) of a home PLMN. In some implementations of the NE, processor, and method described herein, the NE, processor, and method may further be configured to, capable of, performed, performable, or operable to transmit the KAMF to an AMF or a SEAF of NPN hosted by the home PLMN.BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.

[0021] Figure 2 illustrates an example of supporting SUPI based LI in accordance with aspects of the present disclosure.

[0022] Figure 3 illustrates an example of an LI architecture in accordance with aspects of the present disclosure.

[0023] Figure 4 illustrates an example of GPSI usage for UE context management in hosted NPN.

[0024] Figure 5 illustrates an example of SUPI privacy protection based on AMF register with UDM in accordance with aspects of the present disclosure.

[0025] Figure 6 illustrates an example of a technique for fetching a SUPI and corresponding UE temporary identifier in accordance with aspects of the present disclosure.

[0026] Figure 7 illustrates an example procedure to enable a core network function (NF) to indicate LI requirement and to fetch SUPI and UE temporary identifier mapping information from the UDM in accordance with aspects of the present disclosure.

[0027] Figures 8 A and 8B illustrate an example of a procedure to derive SEAF key (KSEAF) and KAMF in the home network in accordance with aspects of the present disclosure.

[0028] Figure 9 illustrates an example of a UE in accordance with aspects of the present disclosure.

[0029] Figure 10 illustrates an example of a processor in accordance with aspects of the present disclosure.

[0030] Figure 11 illustrates an example of an NE in accordance with aspects of the present disclosure.

[0031] Figures 12 to 14 illustrate flowcharts of methods performed by an NE in accordance with aspects of the present disclosure.DETAILED DESCRIPTION

[0032] When an NPN is hosted by a PLMN, there is a possible deployment scenario where a dedicated user plane function (UPF) and part of control plane (CP) functions (e.g., authentication management field or access and mobility management field (AMF) / security anchor function (SEAF)) are deployed in the customer premises with a service-based architecture (SBA) interface with the operator premises. Such a deployment is also referred to as the UE using a hosted network or hosted NPN. Considering primary authentication and authorization procedure specified in clause 6.1.3 of 3rdGeneration Partnership Project (3GPP) technical specification TS 33.501, if a subscription permanent identifier (SUPI) is available in clear text to the network functions (NFs) in the customer premises then it can potentially lead to security threats, privacy breach, UE location tracking, targeted attacks, and so forth. Solutions to protect the SUPI privacy include not disclosing the SUPI to the hosted NPN and instead of SUPI, a temporary UE ID is provided to the hosted NPN to handle the UE context in the serving network or hosted NPN to provide SUPI privacy on the customer premises. In such a case, for legal interception (LI) of one or more UE communications, if an intercept information (e.g., a warrant is issued with SUPI or any temporary UE identifier or PEI, generic public subscription identifier (GPSI)) is requested from a NF deployed in the hosted NPN, the LI requirements may not be fully met as SUPI is not disclosed to the hosted NPN and the LI related xIRI (e.g., LI X2 Intercept Related Information) may need SUPI in some cases.

[0033] A UE typically has a home network (also referred to as a home PLMN), which refers to a PLMN of the operator or provider of the UE or UE service account for wireless communication. When operating in a hosted NPN, the hosted NPN uses a temporary UE identifier rather than the SUPI. In one or more implementations, in response to an LI request received at the hosted NPN targeting a UE, a network function (NF) in the hosted NPN requests a UE mapping from the UDM in the home network. The NF can be, for example, an AMF or other NF. In response to the request, the UDM transmits, to the NF, a mapping of a temporary UE ID of the targeted UE to the SUPI of the UE (e.g., identifies the temporary UE ID being used in the hosted NPN by the UE having the SUPI identified in the LI request). This allows the hosted NPN to know which UE in the hosted NPN corresponds to the LI.

[0034] Alternatively, or additionally, a SEAF may be co-located with an AUSF in the home network. Security keys for the AMF in the hosted network that rely on the SUPI, such as KAMF, can be derived or generated by the SEAF co-located with the AUSF in the home network. The derived or generated security keys as well as additional information, such as ABBA information, are communicated to the AMF in the hosted network, giving the AMF in the hosted network access to one or more security keys (e.g., KAMF) without needing to reveal the SUPI to the AMF of the hosted network.

[0035] Accordingly, the techniques discussed herein allow operation of a UE in a hosted network without needing to reveal the SUPI of the UE to NFs in the hosted network. This allows LI requirements or requests to be satisfied while keeping the SUPI concealed from the NFs in the hosted network.

[0036] Reference is made herein to receiving, transmitting, or communicating data or information, such as signaling communication resources and / or communications that are transmitted or received between devices. It is to be appreciated that other terms may be used interchangeably with communicating, such as signaling, transmitting, receiving, outputting, forwarding, retrieving, obtaining, and so forth. Similarly, other terms may be used interchangeably with transmitting (e.g., communicating, signaling, outputting, forwarding, and so forth), and other terms may be used interchangeably with receiving (e.g., communicating, retrieving, obtaining, and so forth).

[0037] Aspects of the present disclosure are described in the context of a wireless communications system.

[0038] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a new radio (NR) network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultra wideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.

[0039] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a nextgeneration NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.

[0040] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a nonterrestrial network (NTN). In some implementations, different geographic coverage areas associatedwith the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.

[0041] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of- Everything (loE) device, or machine-type communication (MTC) device, among other examples.

[0042] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0043] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N6, or other network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other indirectly (e.g., via the CN 106). In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).

[0044] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects toexternal networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.

[0045] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N6, or other network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).

[0046] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0047] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and anormal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.

[0048] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0049] Additionally, or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, jU=l , / r=2, jU=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0050] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz),FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0051] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.

[0052] The wireless communications system 100 can include at least one PLMN and at least one hosted NPN. Information can be communicated between the NFs in the PLMN and the NPN while keeping a SUPI of the UEs 104 in the hosted NPN secret from the NFs in the hosted NPN. Despite keeping the SUPI secret from the NFs in the hosted NPN, techniques are discussed herein to allow LI requests or actions targeting a UE in the hosted NPN to be carried out.

[0053] Figure 2 illustrates an example 200 of supporting SUPI based LI in accordance with aspects of the present disclosure. In the example 200, a home network 202 includes at least one NF 204, such as a UDM, an ARPF, an AUSF, or a SIDF. A hosted NPN 206 includes at least one NF 208, such as an AMF. In response to a LI request or requirement (e.g., a warrant), the NF 208 communicates (e.g., sends, transmits, signals) a request 210 to the NF 204 indicating an identity of the target of the LI and an indication to activate, allow, or request LI support. In response, the NF 204 transmits a mapping 212 of the identity target to a temporary UE ID used to identify a UE in the hosted NPN that corresponds to the target of the LI.

[0054] SAI has captured the scenario for NPN security considerations in clause 8.2 of 3GPP TS 22.261, which is that the 5G system enables a PLMN to host an NPN without compromising thesecurity of that PLMN. Dedicated network entities of an NPN can be deployed in customer premises that are outside the control of the PLMN operator.

[0055] When an NPN is hosted by a PLMN, there may be two deployment scenarios as follows. For scenario 1, a dedicated UPF is deployed in the customer premises, with an N4 interface (non- SBA interface) with the operator premises. For scenario 2, a dedicated UPF and part of CP functions are deployed in the customer premises with an SBA interface with operator premises.

[0056] Considering the primary authentication and authorization procedure specified in 3 GPP TS 33.501, if a SUPI is available in clear text to the NFs in customer premises then it may potentially lead to security threats, privacy breach, UE location tracking, targeted attacks, and so forth.

[0057] The privacy sensitive SUPI is the home network operator provided identifier used exclusively to identify its subscribers and related subscription information to handle the related services. It is not a security best practice to expose the privacy sensitive SUPI external to the operator’s trust domain. Especially in a case of PLMN hosting NPN scenarios, exposing SUPI beyond the operator trust domain (e.g., PLMN) to NFs in the NPN (which is in a different trust domain) should be avoided.

[0058] One issue is how to avoid exposure of the sensitive parameters (specifically, permanent identifier) to the entities outside the mobile network operator (MNO) premises (in other security domains). With respect to security threats, as the security at the customer premise might be weaker than that of the operator premise even with the existing network domain security for IP-based control planes (NDS / IP) or SBA security, an attacker can compromise NFs in the customer premise and can retrieve the SUPI to launch targeted attacks. If the dedicated NFs could be compromised in customer premises, then SUPI is available to the attacker and it can potentially lead to security threats, like privacy breach, UE location tracking, mapping of the user to the identifiers, targeted DoS, and so forth.

[0059] With respect to potential security requirements, a mechanism to ensure protection of the sensitive parameters (specifically, SUPI) against the risk caused by PLMN hosting NPN can be supported. With respect to LI architecture and functions, the point of interception (POI) detects the target communication, derives the intercept related information or communications content from thetarget communications and delivers the POI output as xIRI to the MDF2 or as xCC to the MDF3. The output of a POI is determined by the type of the NF associated with the POI. A POI may be embedded within a NF or separate from a NF with which it is associated. Multiple POIs may be involved in executing a warrant.

[0060] With respect to LI at AMF and architecture, in the 5GC network, the AMF handles the access and mobility functions as well as provides or facilitates UE location information delivery to other NFs in the course of location-related service operations, such as location services (LCS) or location reporting. The AMF has LI capabilities to generate the target UE's network access, registration, connection management, and location update related xIRI. Extending the generic LI architecture gives a reference point representation of the LI architecture with AMF as a CP NF providing the IRI-POI functions. The lawful interception control function (LICF) present in the administration function (ADMF) receives the warrant from A law enforcement agency (LEA), derives the intercept information from the warrant and provides the same to the lawful interception provisioning function (LIPF).

[0061] The LIPF present in the ADMF provisions the IRI-POI (over LI Xl) present in the AMF and the MDF2. The LIPF may interact with the SIRF (over LI SI) present in the NRF to discover the AMFs in the network.

[0062] The IRI-POI present in the AMF detects the target UE's access and mobility related functions (network access, registration and connection management), generates and delivers the xIRI to the MDF2 over LI X2. The MDF2 delivers the IRI messages as part of the interception product to the law enforcement monitoring facility (LEMF) over LI HI2.

[0063] With respect to target identities, the LIPF present in the ADMF provisions the intercept information associated with the following target identities to the IRI-POI present in the AMF: SUPI, PEI, GPSI. The interception performed on the above three identities are mutually independent, even though an xIRI may contain the information about the other identities when available.

[0064] With respect to network topologies, the AMF provides the IRI-POI functions in the following network topology cases: non-roaming case; roaming case, in visited public land mobile network (VPLMN); roaming case, in home PLMN (HPLMN) for non-3GPP access. In a roamingcase, it is possible that the target UE may use non-3GPP access with the N3A Entity present in the HPLMN.

[0065] With respect to identifier reporting for AMF, the AMF provides identity event function (IEF) capabilities. The IEF present in the AMF support LI XEM1 interface and upon activation provide IEF events to the intent-based networking control function (ICF) over LI XER interface. The IEF need not generate events prior to UEs being successfully registered by the AMF onto the network.

[0066] With respect to IEF Events, the IEF present in the AMF generates report records when it detects the following specific events or information for any UE: association of a 5G globally unique temporary identifier (5G-GUTI) to a SUPI (this may also include subscription concealed identifier (SUCI) to SUPI association); de-association of a 5G-GUTI from a SUPI. The de-association event is generated if a new 5G-GUTI is not allocated to a SUPI to update a previous association (e.g., at inter- AMF handover). For SUCIs seen during registration, they are reported if UE registration is successfully completed. The association event is generated by the IEF in the AMF whenever the AMF initiates any action or procedure for which a new allocated 5G-GUTI is sent to the UE regardless of whether the action or procedure is completed successfully.

[0067] With respect to IEF Event parameters, the list of event parameters is specified in 3 GPP TS 33.128. Each event includes at the following information: subscription permanent identifier, observed temporary identifier(s), cell identity, time stamp of event, AMF identifier (including region and set identifiers), tracking area identifier, registration area (including tracking area identifier list). The permanent equipment identifier is included if it is available in the AMF when the event is reported to the ICF.

[0068] Figure 3 illustrates an example 300 of an LI architecture in accordance with aspects of the present disclosure. The example 300 is, e.g., a 5G core-anchored LI architecture in accordance with aspects of the present disclosure. The network functions include a network data analytics function (NWDAF) 302, an AMF 304, a session management function (SMF) 306, a policy control function (PCF) 308, a 5G equipment identity register (5G-EIR) 310, a UDM 312, a short message service function (SMSF) 314, a location management function (LMF) 316, a network exposure function (NEF) 318, a network repository function (NRF) 320, and a UPF 322. The LI elementsinclude intercept-related information points of interception (IRI-POIs) 324, a system information retrieval function (SIRF) 326, a content of communication - point of interception (CC-POI) 328, a LEMF 330, a media delivery function 2 (MDF2) 332, a media delivery function 3 (MDF3) 334, an LI ADMF 336, and a warrant 338 from a LEA 340. 3GPP TS 33.127 Clause 6 gives details for the configuration of the high-level LI architecture for network layer based interception and defines aspects of the LI configuration specific to each network under consideration (e.g., 5G).

[0069] A CC-POI 328 may also be present in the SMF 306 for roaming non-IP data delivery (NIDD) interception, which is not shown in Figure 3.

[0070] With respect to identity privacy, 3GPP TS 33.501 defines the ability to prevent the SUPI from being exposed over the 5GRAN through the use of SUCI. Where SUPI privacy is implemented by both the UDM and UE, the SUPI is not sent in the clear over the RAN. Therefore, the AMF relies on the UDM to provide the SUPI as part of the registration procedure as defined in 3GPP TS 33.501.

[0071] If the AMF receives a SUCI from the UE then the AMF ensures for every registration (including re-registration) that SUPI has been provided by the UDM to the AMF and that the SUCI to SUPI mapping has been verified as defined in 3 GPP TS 33.501. This shall be performed regardless of whether the SUPI is a target of interception.

[0072] The AMF IRI-POI provides both the SUPI and the current SUCI in all applicable events defined in 3GPP TS 33.501 clause 6.2.2.4.

[0073] Figure 4 illustrates an example 400 of GPSI usage for UE context management in hosted NPN in accordance with aspects of the present disclosure. The hosted NPN 402 is external to the operator’s security domain. The example 400 illustrates the hosted NPN 402 including a UE 104 and an AMF / SEAF 404, and a public network integrated NPN (PNI-NPN) 406 that includes an AUSF 408 and a UDM / ARPF 410.

[0074] At 412 (L), the authentication initiation steps are as indicated in 3GPP TS 33.501 clause 6.1.2. At 414 (2.), the UDM of the UDM / ARPF 410 following the SUCI de-concealment and authentication method selection, based on operator managed SUPI usage restriction policy, UDM / unified data repository (UDR) fetches a privacy protected identifier related to the SUPI assigned by the operator based on operator’s local policy, which can be an existing identifier likeGPSI containing external identifier defined in 3 GPP TS 23.003. A SUPI usage restriction policy can indicate if a SUPI usage is allowed or not for the UE context management external to operator’s security domain / network domain during a hosted NPNs or serving network access.

[0075] At 416 (3.), the UDM of the UDM / ARPF 410 provides GPSI additionally along with SUPI usage restriction indication to the AUSF 408 in an authentication response, as described in 3GPP 33.501 clause 6.1.3. It should be noted that for secure transfer of SUPI across different security domains to facilitate KAMF generation and to not impact the UE 104, suitable transport security can be applied as described in herein.

[0076] At 418 (4.), the AUSF 408 and the UE 104 exchange selected method specific authentication message based on 3GPP TS 33.501. At 420 (5.), following a successful verification of the response, the AUSF 408 communicates (e.g., transmit, sends, signals) received GPSI along with SUPI and SUPI usage restriction indication to the AMF / SEAF 404.

[0077] At 422 (6.), the SEAF following a successful KAMF derivation, deletes SUPI and uses GPSI instead of SUPI for further UE 104 context and subscription data management (e.g., for any Nudm service operation). If the AMF / SEAF 404 wants to initiate primary authentication, it follows 3GPP TS 33.501 clause 6.12.4 and clause 6.1.2. In a case of a PLMN hosting an NPN in the customer premise (which is outside the trust domain or control of the PLMN operator), if the SUPI privacy is applied and if there is a LI requirement / warrant, the AMF / SEAF 404 (as an IRI-POI) in the hosted NPN 402 will not be able to provide the SUPI of the UE 104 for the LI information.

[0078] Figure 5 illustrates an example 500 of SUPI privacy protection based on AMF register with UDM in accordance with aspects of the present disclosure. The example 500 illustrates a UE 104 and an AMF 502 at a customer premises 504 (e.g., a hosted NPN in a visited PLMN), and an AUSF 506 and a UDM 508 or ARPF at an operator premises 510.

[0079] At 512 (1.), the UE 104 performs the general registration as specified in 3 GPP TS 23.502 clause 4.2.2.2. At 514 (2.), the new AMF 502 registers with the UDM 508 using Nudm UECM Registration for the access to be registered. The message includes an AMF ID and SUPI.

[0080] At 516 (3 ), the UDM 508 response includes a PLMN NPN (PLMNNPN) UE ID, and the UDM 508 decides whether the AMF 502 can use SUPI based on the AMF ID. If the AMF 502can use SUPI (e.g., due to LI concern), the UDM 508 communicates (e.g., transmit, sends, signals) a SUPI usage indication to the AMF 502 to indicate to the AMF 502 to keep the SUPI. Otherwise, the UDM 508 communicates (e.g., transmit, sends, signals) a SUPI usage indication to the AMF 502 to indicate to the AMF 502 to remove the SUPI. The AMF 502 will use PLMNNPN UE ID instead of the SUPI for further UE 104 context and subscription data management.

[0081] In a case of PLMN hosting an NPN in the customer premise (which is outside the trust domain or control of the PLMN operator), if the SUPI privacy is applied, and at 516 if the UDM 508 indicates that the AMF 502 is to remove the SUPI, the AMF 502 will delete the SUPI. Later if there is an LI requirement / warrant, the AMF 502 (as an IRI-POI) in the hosted NPN (e.g., the customer premises 504) will not be able to provide the SUPI of the UE 104 for the LI information.

[0082] Returning to Figure 1, the techniques discussed herein include the following. In one or more implementations, an AMF or any NF in the 5G core (in a hosted NPN / PLMN) based on LI requirements and regulatory requirements can request and receive UE SUPI and temporary identifier mapping information from the UDM (in the home network, e.g., home PLMN / NPN). Alternatively, or additionally, any NF in the 5G core (in a hosted NPN / PLMN) based on LI requirements and regulatory requirements can request and receive UE SUPI and temporary identifier mapping information from the UDM (in the home network, e.g., home PLMN / NPN). Alternatively, or additionally, a SEAL can be co-located with the AUSF in the home network to avoid SUPI exposure to hosted NPN without impacting the KAMF and SEAL key (KSEAE) derivation which includes SUPI as one of the inputs. This involves an ABBA parameter to be exchanged over authentication request response between AMF / SEAF in hosted NPN to SEAF / AUSF located in the home network

[0083] In one or more implementations a technique to enable AMF to indicate LI requirement and to fetch SUPI and UE temporary identifier mapping information from the UDM is discussed herein. This technique describes how an AMF based on an LI requirement, during registration or following a successful registration, requests and receives a UE’s permanent subscription identifier (SUPI) and the associated / mapped UE temporary identifiers (and if any other UE identifiers) for one or more UEs from the UDM in the home network (PLMN / NPN).

[0084] LI requirements may include a trigger or a need to do xIRI and the AMF provides the IRI-POI functions. The LIPF present in the ADMF provisions the intercept information associated with one or more of the following target identities to the IRI-POI present in the AMF: SUPI, PEI, a temporary UE ID, GPSI. The interception performed on these identities can be mutually independent, even though an xIRI may contain the information about the other identities when available. The POI in the AMF supports one or more of the following target identifier formats in the European telecommunications standards institute (ETSI) TS 103 221-1 messages (or equivalent if ETSI TS 103 221-1 is not used): SUPI international mobile subscriber identity (SUPIIMSI), SUPI network access identifier (SUPINAI), PEI international mobile equipment identifier (PEIIMEI), PEI international mobile equipment identity - software version (PEIIMEISV), GPSI mobile station international subscriber directory number (GPSIMSISDN), or GPSI network access identifier (GPSINAI).

[0085] If the SUPI privacy is enabled, then the AMF may not have a SUPI at its side. But the AMF may receive a SUPI as part of intercept information to provide LI support. In such a case, to identify the UE context that is related to SUPI that is being currently identified with the temporary UE identifier in the hosted NPN, the AMF performs the following procedure shown in Figure 6 to request and receive the SUPI and the associated / mapped UE temporary identifier from the UDM to identify the UE context and connections related to the SUPI at the hosted NPN side for LI requirements.

[0086] Figure 6 illustrates an example 600 of a technique for fetching a SUPI and corresponding UE temporary identifier in accordance with aspects of the present disclosure. The example 600 illustrates a UE 104 and an AMF / SEAF 602 in a hosted NPN in a visited PLMN 604, and an AUSF 606 and a UD ARPF / SIDF 608 in a home PLMN 610. The example 600, e.g., allows the AMF of the AMF / SEAF 602 to indicate an LI requirement and to fetch the SUPI and UE temporary identifier mapping information from the UDM of the UDMARPF / SIDF 608 in accordance with aspects of the present disclosure.

[0087] At 612 (1.), the UE 104 communicates (e.g., transmit, sends, signals) an initial NAS message with SUCI or 5G-GUTI to the AMF / SEAF 602. At 614 (2.), primary authentication and registration procedure may happen. At 616 (3.), a LIPF present in the ADMF provisions the intercept information (related to an issued warrant) associated with the target identities(SUPI / PEI / GPSI) to the IRI-POI present in the AMF of the AMF / SEAF 602. The AMF of the AMF / SEAF 602 determines that it does not have any similar SUPI stored for a UE context related to the received SUPI to serve the LI requirements, so the AMF of the AMF / SEAF 602 determines to fetch the SUPI and associated UE temporary identifier from the UDM of the UDM / ARPF / SIDF 608.

[0088] At 618 (4.), the AMF of the AMF / SEAF 602 communicates (e.g., transmit, sends, signals) a request to the UDM of the UDM / ARPF / SIDF 608. For example, the request can be a get request in any Nudm service operation message (e.g., Nudm_UECM_Registration service operation / Nudm_UECM_Get service operation / Nudm_UECM_Update service operation / Nudm_SDM_Get service operation / Nudm_SDM_Info service operation / Nudm_UE Authentication Service / Nudm_UEAuthentication Service) to the UDM of the UDM / ARPF / SIDF 608, which includes one or more of SUCI if available, target identities (e.g., SUPI / PEI / GPSI) for one or more UEs (as received from the LIPF / ADMF or provisioned in the intercept information), a UE temporary identifier (if available in the UE context) for SUPI privacy reasons which is provided by the SEAF or AUSF 606 or UDM during primary authentication, SN name, LI support activate indication, and a UE identifier(s) required or requested indication or SUPI required or requested indication. It should be noted that the UE Identifiers required or requested indication can alternatively, or additionally, be referred to as “SUPI required indication” or “SUPI and associated UE IDs required indication”. It should also be noted that the target identities may include one or more of: SUPI, PEI, GPSI, SUPIIMSI, SUPINAI, PEIIMEI, PEIIMEISV, GPSIMSISDN, or GPSINAI.

[0089] At 620 (5.), the UDM of the UDM / ARPF / SIDF 608 fetches, retrieves, or obtains the UE identifiers as follows based on the LI support activate indication, and / or the UE identifiers required or requested indication or the SUPI required or requested indication. If SUPI is received in the request, the SUPI and associated GPSI / temporary UE ID mapping information are fetched, retrieved, or obtained; if GPS [ / Temporary UE ID is received in the request the SUPI and associated GPSI / Temporary UE ID mapping information are fetched, retrieved, or obtained; if SUCI is received in the request the SUPI and associated GPS [ / Temporary UE ID mapping information are fetched, retrieved, or obtained.

[0090] At 622 (6. ), the UDM of the UDM / ARPF / SIDF 608 stores the SN name along with LI requirement related UE ID retrieval incident information for records. Further the UDM of the UDM / ARPF / SIDF 608 communicates (e.g., transmit, sends, signals), in response to the request at 618, a response to the AMF of the AMF / SEAF 602. For example, the response can be a response in any Nudm message (e.g., Nudm_UECM_Registration service operation / Nudm_UECM_Get service operation / Nudm_UECM_Update service operation / Nudm_SDM_Get service operation / Nudm_SDM_Info service operation / Nudm_UEAuthentication Service / Nudm_UEAuthentication Service), and include the SUPI and associated GPS [ / temporary UE ID mapping information. At 624 (7.), the AMF of the AMF / SEAF 602 stores the received SUPI-GPSI / temporary UE ID mapping along with LI requirement indication and uses the SUPI and other available UE identifiers for LI purposes.

[0091] Returning to Figure 1, in one or more implementations a technique to enable any core NF to indicate LI requirement and to fetch SUPI and UE temporary identifier mapping information from the UDM is discussed herein. This technique describes how a core NF (e.g., AMF, SMF, PCF, NWDAF, SMSF, NEF, NRF, UPF, optionally LMF) based on an LI requirement, during UE registration or following a successful registration requests and receives UE’s permanent subscription identifier (SUPI) and the associated / mapped UE temporary identifiers (and if any other UE identifiers) for one or more UEs from the UDM in the home network (PLMN / NPN).

[0092] LI requirements may include a trigger or a need to do reporting and the NF provides the IRI-POI / CC-POI functions. The LIPF present in the ADMF provisions the intercept information associated with one or more of the following target identities to the IRI-POI present in the NF or CC-POI present in the NF: SUPI, PEI, a temporary UE ID, GPSI. The interception performed on these identities can be mutually independent, even though an xIRI may contain the information about the other identities when available. The POI in the AMF supports the following target identifier formats in the ETSI TS 103 221-1 messages (or equivalent if ETSI TS 103 221-1 is not used): SUPIIMSI, SUPINAI, PEIIMEI, PEIIMEISV, GPSIMSISDN, or GPSINAI.

[0093] If the SUPI privacy is enabled, then the NF may not have a SUPI at its side. But the NF may receive a SUPI as part of intercept information to provide LI support. In such as case, to identify the UE context that is related to SUPI that is being currently identified with the temporary UE identifier in the hosted NPN, the NF performs the following procedure shown in Figure 7 torequest and receive the SUPI and the associated / mapped UE temporary identifier from the UDM to identify the UE context and connections related to the SUPI at the hosted NPN side for LI requirements. It should be noted that POIs can be divided into two types for each category based on the type of data they send to the MDF (IRI-POI delivers xIRI to the MDF2, CC-POI delivers xCC to the MDF3).

[0094] Figure 7 illustrates an example 700 procedure to enable a core NF to indicate LI requirement and to fetch SUPI and UE temporary identifier mapping information from the UDM in accordance with aspects of the present disclosure. The example 700 illustrates an NF 702 in a hosted NPN in a visited PLMN 704, and a UDM / ARPF / SIDF 706 in a home PLMN 708.

[0095] At 710 (1.), a LIPF present in the ADMF provisions the intercept information (related to an issued warrant) associated with the target identities (SUPI / PEI / GPSI) to the IRI-POI / CC-POI present in the NF 702. The NF 702 determines that it does not have any similar SUPI stored for a UE context related to the received SUPI to serve the LI requirements, so the NF 702 determines to fetch SUPI and associated UE temporary identifier from the UDM of the UDM / ARPF / SIDF 706.

[0096] At 712 (2.), the NF 702 communicates (e.g., transmit, sends, signals) a request to the UDM / ARPF / SIDF 706. For example, the request can be a get request in any Nudm service operation message (e.g., Nudm_UECM_Registration service operation / Nudm_UECM_Get service operation / Nudm_UECM_Update service operation / Nudm_SDM_Get service operation / Nudm_SDM_Info service operation / Nudm_UEAuthentication Service / Nudm_UEAuthentication Service) to the UDM of the UDM / ARPF / SIDF 706, which includes one or more of SUCI if available, target identities (e.g., SUPI / PEI / GPSI) for one or more of UEs (as received from the LIPF / ADMF or provisioned in the intercept information), a UE temporary identifier (if available in the UE context) for SUPI privacy reasons which is provided by the AMF during UE registration / connection / UE context or session management procedures, an SN name / NF ID, an LI support activate indication, and a UE identifier(s) required or requested indication or SUPI required or requested indication. It should be noted that the UE Identifiers required or requested indication can alternatively, or additionally, be referred to as ‘SUPI required indication” or “SUPI and associated UE IDs required indication”. It should also be noted that the target identifies may include one or more of: SUPI, PEI, GPSI, SUPIIMSI, SUPINAI, PEIIMEI, PEIIMEISV, GPSIMSISDN, or GPSINAI.

[0097] At 714 (3.), the UDM of the UDM / ARPF / SIDF 706 fetches, retrieves, or obtains the UE identifiers as follows based on the LI support activate indication, and / or the UE identifiers required or requested indication or the SUPI required or requested indication. If SUPI is received in the request, the SUPI and associated GPSI / temporary UE ID mapping information are fetched, retrieved, or obtained; if GPSI / temporary UE ID is received in the request the SUPI and associated GPSI / temporary UE ID mapping information are fetched, retrieved, or obtained; if SUCI is received in the request the SUPI and associated GPSI / temporary UE ID mapping information are fetched, retrieved, or obtained.

[0098] At 716 (4.), the UDM of the UDM / ARPF / SIDF 706 stores the SN name along with LI requirement related UE ID retrieval incident information for records. Further the UDM of the UDM / ARPF / SIDF 706 communicates (e.g., transmit, sends, signals), in response to the request at 712, a response to the NF 702. For example, the response can be a response in any Nudm message (e.g., Nudm_UECM_Registration service operation / Nudm_UECM_Get service operation / Nudm_UECM_Update service operation / Nudm_SDM_Get service operation / Nudm_SDM_Info service operation / Nudm_UEAuthentication Service / Nudm_UEAuthentication Service), and include the SUPI and associated GPSI / temporary UE ID mapping information. At 718 (5.), the NF 702 stores the received SUPI-GPSI / temporary UE ID mapping along with LI requirement indication and uses SUPI and other available UE Identifiers for LI purposes.

[0099] Returning to Figure 1, in one or more implementations a technique to co-locate SEAF with AUSF to avoid SUPI exposure to a hosted NPN during primary authentication is discussed herein. This technique describes how a SEAF can be co-located with AUSF in the home network to avoid SUPI exposure to the hosted NPN without impacting the KAMF and KSEAF derivation which includes SUPI as one of the inputs. This involves an ABBA parameter to be exchanged over authentication request and response between the AMF / SEAF in the hosted NPN to the SEAF / AUSF located in the home network as shown in Figures 8 A and 8B.

[0100] The method describes the process of SUPI usage restriction (during the extensible authentication protocol - authentication and key agreement (EAP-AKA)75G AKA / any EAP based primary authentication run) includes providing a UE Temporary Identifier (e.g., GPSI / privacy protected UE ID / SUPITemp (instead of SUPI) to the Serving network / NPN / VPLMN, to enable the serving network / NPN and UE to use the UE Temporary Identifier in the further UE contextidentification and management aspects during primary authentication and key establishment process (e.g., for UE security context fetching for right key derivations such as KAMF / KAMF derivation) as shown in Figures 8A and 8B. Where the UE Temporary Identifier and usage is outside the scope of this document.

[0101] Figures 8A and 8B illustrate an example 800 procedure to derive KSEAF and KAMF in the home network in accordance with aspects of the present disclosure. The example 800 illustrates a UE 104 and an AMF / SEAF 802 (e.g., included in a hosted NPN in a visited PLMN), and an SEAF / AUSF 804 and a UDM / ARPF 806 (e.g., included in a home PLMN). The AUSF of the SEAF / AUSF 804 determines the UE is in a customer premises (e.g., in a hosted NPN in a visited PLMN) and derives the KAMF.

[0102] At 808 (1.), the UE 104 is in roaming in the visited PLMN / NPN and / or in a customer premises. The UE 104 communicates (e.g., transmit, sends, signals) a request, e.g., a registration request or initial NAS message to the AMF / SEAF 802 in the serving network, containing a SUCI or a 5G-GUTI.

[0103] At 810 (2.), on receiving the request at 808, the AMF / SEAF 802 invokes primary authentication by sending an authentication request, e.g., Nausf UEAuthentication Authenticate request to the AUSF of the SEAF / AUSF 804 in the home network containing the received SUCI and its serving network name. At 812 (3.), the SEAF / AUSF 804 verifies the serving network identifier in the authentication request to check if it is the same as the expected serving network name and determines the UE 104 is in the customer premises. If the verification is successful, the SEAF / AUSF 804 communicates (e.g., transmit, sends, signals) an authentication data request, e.g., Nudm UEAuthentication Get request, to the UDM of the UDM / ARPF 806, including the received SUCI and SN name.

[0104] At 814 (4-5.), upon reception of the request at 812 (e.g., theNudm UEAuthentication Get Request), the UDM of the UDM / ARPF 806 invokes SIDF if a SUCI is received. SIDF de-conceals the SUPI. The UDM / ARPF 806 chooses the authentication method. The UDM of the UDM / ARPF 806 manages the SUPI usage restriction information / policies for one or more hosted NPNs / serving networks (identified with their NPN ID or SN ID etc.,). SUPI usage restriction information / policies states if a SUPI usage is allowed or not for the UE 104 contextmanagement external to the operator’s security domain / network domain (e.g., for the UE 104 during a hosted NPN's / serving network’s access).

[0105] Based on the SUPI usage restriction information / policies / operator policy, and SN ID / NPN ID, the UDM of the UDM / ARPF 806 determines to additionally provide a UE temporary identifier (e.g., GPSEprivacy protected UE ID / SUPIiemp / the serving network UE ID (instead of SUPI) for the UE context management at the hosted NPN / VPLMN / serving network. Alternatively, or additionally, the SUPI usage restriction information / policies is referred to as “SUPI disclosure policy”.

[0106] If the UDM of the UDM / ARPF 806 determines not to disclose the SUPI (e.g., to not use for UE 104 context management purpose external to operator network or security domain), the UDM of the UDM / ARPF 806 generates or assigns a UE temporary identifier (e.g., GPSEprivacy protected UE ID / SUPIiemp specific to the hosted NPN / VPLMN / serving network / with additional home network ID for the UE or for the SUPI). The store SUPI and UE temporary identifier pair are stored in the UDM / UDR. Alternatively, or additionally, if there is an LI requirement for the UE 104, SUPI may be at 810.

[0107] At 816 (6.), the UDM of the UDM / ARPF 806 provides the authentication vectors, SUPI and other parameters to the AUSF in Nudm UEAuthentication Get Response message.Additionally, the UDM of the UDM / ARPF 806 derives the UE temporary identifier (e.g., GPSI / privacy protected UE fD / SUPIiemp / the serving network UE ID for the UE), stores it as part of subscription data and includes it along with SUPI usage restriction indication in the response message to the AUSF of the SEAF / AUSF 804. At 818 (7.), the SEAF / AUSF 804 communicates (e.g., transmit, sends, signals) the authentication challenge message to the AMF / SEAF 802 in a response, e.g., in a Nausf_UEAuthentication_Authenticate response message including authentication vector(s) (AV(s)).

[0108] At 820, 822, 824, and 826 (8-11.), the AMF / SEAF 802 transparently forwards the challenge message to the UE 104 in a NAS message authentication request message. On receiving the authentication request message, the UE 104 calculates the authentication response and communicates (e.g., transmit, sends, signals) the response to the AMF / SEAF 802. The AMF / SEAF 802 provides the ABBA parameter in the Nausf UEAuthentication Authenticate Request message.

[0109] At 828 (12.), the procedure follows as specified in 6.1.3 of 3GPP TS 33.501 except that there is a SEAF instance co-located with AUSF and SEAF / AUSF 804 derives KAMF. The derivation of KAMF includes KSEAF as the root key with inputs as: SUPI, SN ID, ABBA parameter Nausf UEAuthentication Authenticate Request message along with SUPI usage restriction indication.

[0110] At 830 (13.), the SEAF / AUSF 804 shares the KAMF to the AMF / SEAF 802 in the customer premises as part of a response, e.g., Nausf UEAuthentication Authenticate response along with the other parameters. Alternatively, or additionally, the response includes SUPI usage restriction indication, the received UE temporary identifier (e.g., GPSI / privacy protected UE ID / SUPlTemp / the serving network UE ID) and ABBA used in KAMF key derivation is provided to the AMF / SEAF for unique identification of the UE in the customer premise.

[0111] At 832 (14.) the AMF / SEAF 802 communicates (e.g., transmit, sends, signals) a message, e.g., an N1 message to the UE 104 with the success indication. The UE temporary identifier (e.g., GPSI / privacy protected UE ID / SUPIiemp / the serving network UE ID) and SUPI usage restriction indication is stored and is used further as UE’s subscriber identifier as long as the UE 104 is served by the AMF of the AMF / SEAF 802 in the same customer premises. At 834, 836 (15., 16.), the NAS security establishment and key generation at the UE side is performed as discussed in 3GPP TS 33.501.

[0112] Figure 9 illustrates an example of a UE 900 in accordance with aspects of the present disclosure. The UE 900 may include a processor 902, a memory 904, a controller 906, and a transceiver 908. The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0113] The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereofconfigured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0114] The processor 902 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 902 may be configured to operate the memory 904. In some other implementations, the memory 904 may be integrated into the processor 902. The processor 902 may be configured to execute computer-readable instructions stored in the memory 904 to cause the UE 900 to perform various functions of the present disclosure.

[0115] The memory 904 may include volatile or non-volatile memory. The memory 904 may store computer-readable, computer-executable code including instructions when executed by the processor 902 cause the UE 900 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 904 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0116] In some implementations, the processor 902 and the memory 904 coupled with the processor 902 may be configured to cause the UE 900 to perform one or more of the functions described herein (e.g., executing, by the processor 902, instructions stored in the memory 904). For example, the processor 902 may support wireless communication at the UE 900 in accordance with examples as disclosed herein..

[0117] The controller 906 may manage input and output signals for the UE 900. The controller 906 may also manage peripherals not integrated into the UE 900. In some implementations, the controller 906 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 906 may be implemented as part of the processor 902.

[0118] In some implementations, the UE 900 may include at least one transceiver 908. In some other implementations, the UE 900 may have more than one transceiver 908. The transceiver 908may represent a wireless transceiver. The transceiver 908 may include one or more receiver chains 910, one or more transmitter chains 912, or a combination thereof.

[0119] A receiver chain 910 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 910 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 910 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 910 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 910 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0120] A transmitter chain 912 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 912 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 912 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 912 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0121] Figure 10 illustrates an example of a processor 1000 in accordance with aspects of the present disclosure. The processor 1000 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 1000 may include a controller 1002 configured to perform various operations in accordance with examples as described herein. The processor 1000 may optionally include at least one memory 1004, which may be, for example, an Ll / L2 / L3 cache. Additionally, or alternatively, the processor 1000 may optionally include one or more arithmetic-logic units (ALUs) 1006. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).

[0122] The processor 1000 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 1000) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).

[0123] The controller 1002 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 1000 to cause the processor 1000 to support various operations in accordance with examples as described herein. For example, the controller 1002 may operate as a control unit of the processor 1000, generating control signals that manage the operation of various components of the processor 1000. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.

[0124] The controller 1002 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 1004 and determine subsequent instruction(s) to be executed to cause the processor 1000 to support various operations in accordance with examples as described herein. The controller 1002 may be configured to track memory addresses of instructions associated with the memory 1004. The controller 1002 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 1002 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 1000 to cause the processor 1000 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 1002 may be configured to manage flow of data within the processor 1000. The controller 1002 may be configured to control transfer of data between registers, ALUs 1006, and other functional units of the processor 1000.

[0125] The memory 1004 may include one or more caches (e.g., memory local to or included in the processor 1000 or other memory, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 1004 may reside within or on a processor chipset (e.g., local to the processor 1000). In some other implementations, the memory 1004 may reside external to the processor chipset (e.g., remote to the processor 1000).

[0126] The memory 1004 may store computer-readable, computer-executable code including instructions that, when executed by the processor 1000, cause the processor 1000 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 1002 and / or the processor 1000 may be configured to execute computer-readable instructions stored in the memory 1004 to cause the processor 1000 to perform various functions. For example, the processor 1000 and / or the controller 1002 may be coupled with or to the memory 1004, the processor 1000, and the controller 1002, and may be configured to perform various functions described herein. In some examples, the processor 1000 may include multiple processors and the memory 1004 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.

[0127] The one or more ALUs 1006 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 1006 may reside within or on a processor chipset (e.g., the processor 1000). In some other implementations, the one or more ALUs 1006 may reside external to the processor chipset (e.g., the processor 1000). One or more ALUs 1006 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 1006 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 1006 may be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 1006 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not- AND (NAND), enabling the one or more ALUs 1006 to handle conditional operations, comparisons, and bitwise operations.

[0128] The processor 1000 may support wireless communication in accordance with examples as disclosed herein. The processor 1000 may be configured to or operable to support at least one controller (e.g., the controller 1002) coupled with at least one memory (e.g., the memory 1004) and configured to or operable to cause the processor to: transmit a request that includes a LI target identity and an LI support activate indication; receive a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0129] Additionally, the processor 1000 may be configured to or operable to support any one or combination of where the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a PEI; where the request further includes one or more of a SN name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity; where the at least one controller is further configured to or operable to cause the processor to store a mapping of the SUPI and the GPSI to the temporary UE ID, and an indication that the temporary UE ID is the LI target identity; where the at least one controller is further configured to or operable to cause the processor to transmit the request based at least in part on the NE not having the SUPI corresponding to the LI target identity; where the at least one controller is further configured to or operable to cause the processor to transmit the request and receive the response via at least one of an AMF or a SEAF of a hosted NPN; where the at least one controller is further configured to or operable to cause the processor to transmit the request and receive the response via a core network function of a hosted NPN.

[0130] The processor 1000 may support wireless communication in accordance with examples as disclosed herein. The processor 1000 may be configured to or operable to support at least one controller (e.g., the controller 1002) coupled with at least one memory (e.g., the memory 1004) and configured to or operable to cause the processor to: receive a request that includes a LI target identity and an LI support activate indication; transmit a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0131] Additionally, the processor 1000 may be configured to or operable to support any one or combination of where the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a PEI; where the request further includes one or more of a SN name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity; where the at least one controller is further configured to or operable to cause the processorto retrieve a mapping of the SUPI and the GPSI to the temporary UE ID; where the at least one controller is further configured to or operable to cause the processor to receive the request and transmit the response via at least one of a UDM function, an ARPF, an AUSF, or a SIDF of a home PLMN.

[0132] The processor 1000 may support wireless communication in accordance with examples as disclosed herein. The processor 1000 may be configured to or operable to support at least one controller (e.g., the controller 1002) coupled with at least one memory (e.g., the memory 1004) and configured to or operable to cause the processor to: generate, based at least in part on a SUPI and an ABBA, a KAMF; transmit the KAMF and the ABBA.

[0133] Additionally, the processor 1000 may be configured to or operable to support any one or combination of where the at least one controller is further configured to or operable to cause the processor to generate the KAMF and transmit the KAMF via at least one of a SEAF or an AUSF of a home PLMN: where the at least one controller is further configured to or operable to cause the processor to transmit the KAMF to an AMF or a SEAF of NPN hosted by the home PLMN.

[0134] Figure 11 illustrates an example of a NE 1100 in accordance with aspects of the present disclosure. The NE 1100 may include a processor 1102, a memory 1104, a controller 1106, and a transceiver 1108. The processor 1102, the memory 1104, the controller 1106, or the transceiver 1108, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0135] The processor 1102, the memory 1104, the controller 1106, or the transceiver 1108, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0136] The processor 1102 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In someimplementations, the processor 1102 may be configured to operate the memory 1104. In some other implementations, the memory 1104 may be integrated into the processor 1102. The processor 1102 may be configured to execute computer-readable instructions stored in the memory 1104 to cause the NE 1100 to perform various functions of the present disclosure.

[0137] The memory 1104 may include volatile or non-volatile memory. The memory 1104 may store computer-readable, computer-executable code including instructions when executed by the processor 1102 cause the NE 1100 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 1104 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0138] In some implementations, the processor 1102 and the memory 1104 coupled with the processor 1102 may be configured to cause the NE 1100 to perform one or more of the functions described herein (e.g., executing, by the processor 1102, instructions stored in the memory 1104). For example, the processor 1102 may support wireless communication at the NE 1100 in accordance with examples as disclosed herein. The NE 1100 may be configured to support a means for transmitting a request that includes a LI target identity and an LI support activate indication; and receiving a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0139] Additionally, the NE 1100 may be configured to support any one or combination of where the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a PEI; where the request further includes one or more of a SN name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity; storing a mapping of the SUPI and the GPSI to the temporary UE ID, and an indication that the temporary UE ID is the LI target identity; transmitting the request based at least in part on the NE not having the SUPI corresponding to the LI target identity; transmitting the request and receive the response via at least one of an AMF or a SEAF of a hosted NPN; transmitting the request and receive the response via a core network function of a hosted NPN.

[0140] Additionally, or alternatively, the NE 1100 may support at least one memory (e.g., the memory 1104) and at least one processor (e.g., the processor 1102) coupled with the at least one memory and configured to or operable to cause the NE to: transmit a request that includes a LI target identity and an LI support activate indication; receive a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0141] Additionally, the NE 1100 may be configured to support any one or combination of the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a PEI; the request further includes one or more of a SN name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity; the at least one processor is further configured to or operable to cause the NE to store a mapping of the SUPI and the GPSI to the temporary UE ID, and an indication that the temporary UE ID is the LI target identity; the at least one processor is further configured to or operable to cause the NE to transmit the request based at least in part on the NE not having the SUPI corresponding to the LI target identity; the at least one processor is further configured to or operable to cause the NE to transmit the request and receive the response via at least one of an AMF or a SEAF of a hosted NPN; the at least one processor is further configured to or operable to cause the NE to transmit the request and receive the response via a core network function of a hosted NPN.

[0142] In some implementations, the processor 1102 and the memory 1104 coupled with the processor 1102 may be configured to cause the NE 1100 to perform one or more of the functions described herein (e.g., executing, by the processor 1102, instructions stored in the memory 1104). For example, the processor 1102 may support wireless communication at the NE 1100 in accordance with examples as disclosed herein. The NE 1100 may be configured to support a means for receiving a request that includes a LI target identity and an LI support activate indication; transmitting a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0143] Additionally, the NE 1100 may be configured to support any one or combination of where the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a PEI; where the request further includes one or more of a SN name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity; retrieving a mapping of the SUPI and the GPSI to the temporary UE ID; receiving the request andtransmit the response via at least one of a UDM function, an ARPF, an AUSF, or a SIDF of a home PLMN.

[0144] Additionally, or alternatively, the NE 1100 may support at least one memory (e.g., the memory 1104) and at least one processor (e.g., the processor 1102) coupled with the at least one memory and configured to or operable to cause the NE to: receive a request that includes a LI target identity and an LI support activate indication; transmit a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID.

[0145] Additionally, the NE 1100 may be configured to support any one or combination of the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a PEI; the request further includes one or more of a SN name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity; where the at least one processor is further configured to or operable to cause the NE to retrieve a mapping of the SUPI and the GPSI to the temporary UE ID; where the at least one processor is further configured to or operable to cause the NE to receive the request and transmit the response via at least one of a UDM function, an ARPF, an AUSF, or a SIDF of a home PLMN.

[0146] In some implementations, the processor 1102 and the memory 1104 coupled with the processor 1102 may be configured to cause the NE 1100 to perform one or more of the functions described herein (e.g., executing, by the processor 1102, instructions stored in the memory 1104). For example, the processor 1102 may support wireless communication at the NE 1100 in accordance with examples as disclosed herein. The NE 1100 may be configured to support a means for generating, based at least in part on a SUPI and an ABBA, a KAMF; transmitting the KAMF and the ABBA.

[0147] Additionally, the NE 1100 may be configured to support any one or combination of generating the KAMF and transmit the KAMF via at least one of a SEAF or an AUSF of a home PLMN; transmitting the KAMF to an AMF or a SEAF of NPN hosted by the home PLMN.

[0148] Additionally, or alternatively, the NE 1100 may support at least one memory (e.g., the memory 1104) and at least one processor (e.g., the processor 1102) coupled with the at least one memory and configured to or operable to cause the NE to: generate, based at least in part on a SUPI and an ABBA, a KAMF; transmit the KAMF and the ABBA.

[0149] Additionally, the NE 1100 may be configured to support any one or combination of the at least one processor is further configured to or operable to cause the NE to generate the KAMF and transmit the KAMF via at least one of a SEAF or an AUSF of a home PLMN; where the at least one processor is further configured to or operable to cause the NE to transmit the KAMF to an AMF or a SEAF of NPN hosted by the home PLMN.

[0150] The controller 1106 may manage input and output signals for the NE 1100. The controller 1106 may also manage peripherals not integrated into the NE 1100. In some implementations, the controller 1106 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 1106 may be implemented as part of the processor 1102.

[0151] In some implementations, the NE 1100 may include at least one transceiver 1108. In some other implementations, the NE 1100 may have more than one transceiver 1108. The transceiver 1108 may represent a wireless transceiver. The transceiver 1108 may include one or more receiver chains 1110, one or more transmitter chains 1112, or a combination thereof.

[0152] A receiver chain 1110 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1110 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 1110 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 1110 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1110 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0153] A transmitter chain 1112 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 1112 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phaseshift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 1112 may also include at least one power amplifier configured to amplify the modulated signal to anappropriate power level suitable for transmission over the wireless medium. The transmitter chain 1112 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0154] Figure 12 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0155] At 1202, the method may include transmitting a request that includes a LI target identity and an LI support activate indication. The operations of 1202 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1202 may be performed by a NE as described with reference to Figure 11.

[0156] At 1204, the method may include receiving a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID. The operations of 1204 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1204 may be performed by a NE as described with reference to Figure 11.

[0157] Figure 13 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0158] At 1302, the method may include receiving a request that includes a LI target identity and an LI support activate indication. The operations of 1302 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1302 may be performed by a NE as described with reference to Figure 11.

[0159] At 1304, the method may include transmitting a response that identifies a mapping of at least one of a SUPI or an associated GPSI of the LI target identity to a temporary UE ID. The operations of 1304 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1304 may be performed by a NE as described with reference to Figure 11.

[0160] Figure 14 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0161] At 1402, the method may include generating, based at least in part on a SUPI and an ABBA, a KAME The operations of 1402 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1402 may be performed by a NE as described with reference to Figure 11.

[0162] At 1404, the method may include transmitting the KAMF and the ABBA. The operations of 1404 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1404 may be performed by a NE as described with reference to Figure 11.

[0163] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0164] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. CLAIMSWhat is claimed is:

1. A network equipment (NE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the NE to: transmit a request that includes a lawful intercept (LI) target identity and an LI support activate indication; receive a response that identifies a mapping of at least one of a subscription permanent identifier (SUPI) or an associated generic public subscription identifier (GPSI) of the LI target identity to a temporary user equipment (UE) identifier (ID).

2. The NE of claim 1 , wherein the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a permanent equipment identifier (PEI).

3. The NE of claim 1, wherein the request further includes one or more of a secondary node (SN) name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity.

4. The NE of claim 1 , wherein the at least one processor is further operable to cause the NE to store a mapping of the SUPI and the GPSI to the temporary UE ID, and an indication that the temporary UE ID is the LI target identity.

5. The NE of claim 1 , wherein the at least one processor is further operable to cause the NE to transmit the request based at least in part on the NE not having the SUPI corresponding to the LI target identity.

6. The NE of claim 1 , wherein the at least one processor is further operable to cause the NE to transmit the request and receive the response via at least one of an authentication management function (AMF) or a security anchor function (SEAF) of a hosted non-public network (NPN).

7. The NE of claim 1 , wherein the at least one processor is further operable to cause the NE to transmit the request and receive the response via a core network function of a hosted non-public network (NPN).

8. A network equipment (NE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the NE to: receive a request that includes a lawful intercept (LI) target identity and an LI support activate indication; transmit a response that identifies a mapping of at least one of a subscription permanent identifier (SUPI) or an associated generic public subscription identifier (GPSI) of the LI target identity to a temporary user equipment (UE) identifier (ID).

9. The NE of claim 8, wherein the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a permanent equipment identifier (PEI).

10. The NE of claim 8, wherein the request further includes one or more of a secondary node (SN) name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity.

11. The NE of claim 8, wherein the at least one processor is further operable to cause the NE to retrieve a mapping of the SUPI and the GPSI to the temporary UE ID.

12. The NE of claim 8, wherein the at least one processor is further operable to cause the NE to receive the request and transmit the response via at least one of a unified data management (UDM) function, an authentication credential repository and processing function (ARPF), an authentication server function (AUSF), or a subscription identifier de-concealing function (SIDF) of a home public land mobile network (PLMN).

13. A network equipment (NE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the NE to:generate, based at least in part on a subscription permanent identifier (SUPI) and an anti-bidding down between architectures (ABBA), a key for authentication management function (KAMF); transmit the KAMF and the ABBA.

14. The NE of claim 13, wherein the at least one processor is further operable to cause the NE to generate the KAMF and transmit the KAMF via at least one of a security anchor function (SEAF) or an authentication server function (AUSF) of a home public land mobile network (PLMN).

15. The NE of claim 14, wherein the at least one processor is further operable to cause the NE to transmit the KAMF to an authentication management function (AMF) or a SEAF of non-public network (NPN) hosted by the home PLMN.

16. A method performed by a network equipment (NE), the method comprising: transmitting a request that includes a lawful intercept (LI) target identity and an LI support activate indication; and receiving a response that identifies a mapping of at least one of a subscription permanent identifier (SUPI) or an associated generic public subscription identifier (GPSI) of the LI target identity to a temporary user equipment (UE) identifier (ID).

17. The method of claim 16, wherein the LI target identity includes at least one of a SUPI, a GPSI, the temporary UE ID, or a permanent equipment identifier (PEI).

18. The method of claim 16, wherein the request further includes one or more of a secondary node (SN) name, an indication that at least one UE identifier is requested, or a temporary identifier of a UE corresponding to the LI target identity.

19. The method of claim 16, further comprising storing a mapping of the SUPI and the GPSI to the temporary UE ID, and an indication that the temporary UE ID is the LI target identity.

20. The method of claim 16, further comprising transmitting the request based at least in part on the NE not having the SUPI corresponding to the LI target identity.

Citation Information

Patent Citations

  • Lawful interception in a visited communications network

    WO2024158322A1

  • US202463681588P