Devices and methods for secure subscription binding for users in a mobile network
The solution allows secure cross-UE subscription sharing in 3GPP networks by using a master UE to generate a slave subscription certificate verified by the network, addressing authentication and authorization challenges and reducing key transfer risks.
Patent Information
- Application Number
- PCT/CN2024/108586
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-30
- Publication Date
- 2026-02-05
AI Technical Summary
Existing solutions for cross-UE subscription sharing in mobile networks, such as 3GPP networks, face challenges in securely authenticating and authorizing users without requiring them to be collocated with the UE device, and there is a high security risk in transferring secret keys, which can be stolen or misused.
A master UE generates a slave subscription certificate using its private key, allowing a slave UE to access network services securely without sharing secret keys, and the network verifies the certificate using the master UE's public key, ensuring authentication and authorization.
Enables secure cross-UE subscription sharing by verifying user identities and policies independently of the slave UE, reducing security risks associated with key transfer.
Smart Images

Figure CN2024108586_05022026_PF_FP_ABST
Abstract
Description
DEVICES AND METHODS FOR SECURE SUBSCRIPTION BINDING FOR USERS IN A MOBILE NETWORKTECHNICAL FIELD
[0001] The present disclosure relates to wireless communications. More specifically, the present disclosure relates to devices and methods for secure cross-UE subscription sharing in a mobile network, in particular a 3GPP network.BACKGROUND
[0002] The operation and service models of the current telecom networks are on the way to hopefully diversify their offered services according to customized needs from different users. Specifically, with the same subscription or tariff plan, users are expected to be treated differently when serving their requests. For example, assuming a father has a mobile phone with a subscription from an operator, his son may want to use his father’s phone to access the Internet. In another example, a guest may want to use the father phone with the same subscription (tariff) plan. For these two users, obviously the service policy for each of them shall be different. The service policy for the father’s son should consider the limited access to certain content providers; on the other hand, the service policy for the father’s friend should consider limiting the speed and a cap on the data volume consumption of the guest user.
[0003] This new feature is under intensive and extensive 3GPP Release-19’s study with two study item descriptions (SIDs) . The first SID is entitled with “Study on User Identities and Authentication Architecture” , which is delivered as TR 23.700-32; and the second SID is entitled with “Study on security aspects of User Identities and Authentication” , which will be delivered as TR 33.700-32.The major enhancement is that a 3GPP mobile network will store not only a UE subscription profile, but also one or multiple user identity profiles (UIPs) , in the core network functions (e.g., user data management (UDM) ) . A UIP describes a user with attributes, among which one mandatory attribute is a linkage to at least one UE’s subscription permanent identifier (SUPI) .
[0004] It is expected that in the future a user can share a UE’s subscription if its UIP links to the UE’s SUPI. When registration or activation, the operator verifies whether or not such a binding exists and the credentials of the user. If so, the user is authorized to access the network but uses the linked UE subscription. Thus, instead of working as a hotspot, a human user and / or a non-3GPP device shall be able to directly access 3GPP networks where their own profiles will be used in authentication.
[0005] To achieve UE subscription sharing, a key issue is how a UIP shall be authenticated and authorized when a user sends a registration or activation request to the operator network. Most of the currently proposed solutions follow a two-time primary authentication scheme. Specifically, the first-time primary authentication is done against the UE’s credentials (e.g., a SUCI) , while the second-time primary authentication is done against the UIP where the network side verifies (a) whether or not the user holds valid credentials and (b) whether or not the user does have a binding of the UE that was previously authenticated. If the two-time primary authentications can be successfully done, there are two different ways to issue credentials to the user for service access. According to a first conventional approach a set of shared secret keys is generated at both UE and the network sides. Both the UE and the network will use the symmetric / shared keys for secure communication. According to a second conventional approach a certificate is issued by the network side to the User. In the certificate, the network side certifies the information / attributes of both the UE and the user with the signature of the network side. In either way, the UE subscription can be shared with multiple users.
[0006] The major problems of the prior art can be summarized as follows. Firstly, given the proposed conventional solutions, a user who wants to access with its UIP and share the linked UE subscription, has to collocate with the UE device that shares its subscription with the user. This is because the two-time primary authentications have to be done together in order to make the final authentication succeed. In other words, if the user uses a further UE device and accesses the network with its own UIP, the second-time authentication will fail because: (a) the network cannot identify an existing subscription binding between the further UE device and the user, and (b) even if the UIP can contain the binding to the subscription of the sharing UE device, the network cannot confirm if the sharing UE device really allows such access request from the user (e.g., a malicious user could impersonate the actual user who is not aware of its UIP being used) . Secondly, the proposed solutions can still support a cross-UE subscription sharing but that can only be done if the generated shared secret keys can be transferred to a new device, e.g., copying a QR-code and so on.However, this introduces a high security risk where the secret key materials might be stolen or illegally used by attackers. Thus, none of the existing solutions enable a secure cross-UE subscription sharing.SUMMARY
[0007] It is an objective of the present disclosure to provide improved devices and methods for secure cross-UE subscription sharing in a mobile network, in particular a 3GPP network.
[0008] The foregoing and other objectives are achieved by the subject matter of the independent claims. Further implementation forms are apparent from the dependent claims, the description and the figures.
[0009] According to a first aspect a master user entity with a valid subscription for using communication services provided by a mobile network is provided. The master UE according to the first aspect is configured to receive a master subscription certificate from a network entity (herein also referred to as Subscription Certification Function, SUCF) of the mobile network, wherein the master subscription certificate is electronically signed with a private key of the network entity or a further network entity and certifies the valid subscription of the master UE and comprises a public key of the master UE. Moreover, the master UE according to the first aspect is configured to generate a slave subscription certificate based on the master subscription certificate by electronically signing the slave subscription certificate with a private key of the master UE, wherein the slave subscription certificate comprises a public key of a user on a slave UE. The master UE according to the first aspect is further configured to provide the slave subscription certificate to the slave UE for enabling the slave UE (more specifically the user on the slave UE) to use, based on the slave subscription certificate, the communication services provided by the mobile network with the subscription of the master UE. Thus, the master UE according to the first aspect allows secure cross-UE subscription sharing with the slave UE. More specifically, independent of the slave UE, the User-ID may still be verified and authenticated by the network side, while the transfer of private secret key materials across different UEs is avoided.
[0010] As will be appreciated, the master UE and the slave UE make use of public and private key pairs, which are associated with the respective master UE and the user of the slave UE.
[0011] In a further possible implementation form, the master subscription certificate from the network entity, in particular the SUCF of the mobile network comprises an indication, i.e. certification of a validity period of the master subscription certificate, wherein the master subscription certificate from the network entity expires after the validity period of the master subscription certificate. Defining a validity period for the master subscription certificate allows further increasing the security.
[0012] In a further possible implementation form, the master subscription certificate from the network entity, in particular the SUCF of the mobile network further certifies a subscription derivation policy for generating the slave subscription certificate based on the master subscription certificate. This allows to define the slave subscription for the user of the slave UE with a fine granularity.
[0013] In a further possible implementation form, the master UE is configured to receive the master subscription certificate from the network entity, in particular the SUCF of the mobile network, in response to sending a subscription certificate request to the network entity, wherein the subscription certificate request comprises the public key of the master UE. This allows the master UE to request the master subscription certificate on demand.
[0014] In a further possible implementation form, the master UE is configured to generate the slave subscription certificate based on the master subscription certificate by electronically signing the slave subscription certificate with the private key of the master UE and to provide the slave subscription certificate to the slave UE, in response to receiving a subscription derivation request from the slave UE, wherein the subscription derivation request comprises the public key of the user of the slave UE. This allows the user of a slave UE to request the slave subscription certificate on demand.
[0015] According to a second aspect a method is provided for operating a master user entity, UE, with a valid subscription for using communication services provided by a mobile network. The method according to the second aspect comprises the steps of:
[0016] receiving a master subscription certificate from a network entity, in particular a Subscription Certification Function, SUCF, of the mobile network, wherein the master subscription certificate is electronically signed with a private key of the network entity or a further network entity and certifies the valid subscription of the master UE and comprises a public key of the master UE;
[0017] generating a slave subscription certificate based on the master subscription certificate by electronically signing the slave subscription certificate with a private key of the master UE, wherein the slave subscription certificate comprises a public key of a user of a slave UE; and
[0018] providing the slave subscription certificate to the slave UE for allowing the slave UE to use, based on the slave subscription certificate, the communication services provided by the mobile network with the subscription of the master UE.
[0019] The method according to the second aspect allows the slave UE to use the subscription of the master UE in a mobile network in a secure manner. The method according to the second aspect can be performed by the master UE according to the first aspect. Thus, further features of the method according to the second aspect result directly from the functionality of the master UE according to the first aspect as well as its different implementation forms described above and below.
[0020] According to a third aspect a slave user entity, UE, is provided for using communication services provided by a mobile network, in particular a 3GPP network. The slave UE according to the third aspect is configured to receive a slave subscription certificate from a master UE with a valid subscription for using the communication services provided by the mobile network, wherein the slave subscription certificate is electronically signed with a private key of the master UE and comprises a public key of the user of the slave UE. Moreover, the slave UE according to the third aspect is configured to send a request (herein also referred to as user registration or activation request) to an access and mobility management entity of the mobile network for using the communication services provided by the mobile network based on the valid subscription of the master UE, wherein the user registration request comprises the slave subscription certificate. Thus, the slave UE according to the second aspect allows secure cross-UE subscription sharing with the master UE.
[0021] In a further possible implementation form, the slave subscription certificate further comprises an identifier of the user of the slave UE and / or an identifier of the master UE. Identifying the user of the slave UE and / or the master UE allows further increasing the security.
[0022] In a further possible implementation form, the slave subscription certificate further comprises an indication, i.e. certification of a validity period of the slave subscription certificate. Defining a validity period for the master subscription certificate allows further increasing the security.
[0023] In a further possible implementation form, the slave UE is configured to receive the slave subscription certificate from the master UE, in response to sending a subscription derivation request to the master UE. This allows the user of the slave UE to request the slave subscription certificate on demand.
[0024] In a further possible implementation form, the subscription derivation request to the master UE comprises a requested service description indicative of the communication services allowed to be used by the slave UE using the valid subscription of the master UE.This allows to define the slave subscription for the user of the slave UE with a fine granularity.
[0025] According to a fourth aspect a method is provided for operating a slave user entity, UE, for using communication services provided by a mobile network. The method according to the fourth aspect comprises the following steps:
[0026] receiving a slave subscription certificate from a master UE with a subscription for using the communication services provided by the mobile network, wherein the slave subscription certificate is electronically signed with a private key of the master UE and comprises a public key of the user of the slave UE; and
[0027] sending a request (herein also referred to as user registration or activation request) to an access and mobility management entity of the mobile network for using the communication services provided by the mobile network based on the valid subscription of the master UE, wherein the user registration request comprises the slave subscription certificate.
[0028] The method according to the fourth aspect allows the slave UE to use the subscription of the master UE in a mobile network in a secure manner. The method according to the fourth aspect can be performed by the slave UE according to the third aspect. Thus, further features of the method according to the fourth aspect result directly from the functionality of the slave UE according to the third aspect as well as its different implementation forms described above and below.
[0029] According to a fifth aspect a network entity, in particular a Subscription Certification Function, SUCF, in a mobile network is provided. The network entity, in particular SUCF, according to the fifth aspect is configured to generate a master subscription certificate, wherein the master subscription certificate is electronically signed with a private key of the network entity or a further network entity and certifies a valid subscription of a master UE and comprises a public key of the master UE. Moreover, the network entity, in particular SUCF, according to the fifth aspect is configured to provide the master subscription certificate to the master UE. Thus, the network entity, in particular SUCF according to the fifth aspect supports secure cross-UE subscription sharing between the master UE and a slave UE.
[0030] In a further possible implementation form, the network entity is configured to generate the master subscription certificate, in response to receiving a subscription certificate request from the master UE, wherein the subscription certificate request comprises the public key of the master UE. This allows the master UE to request the master subscription certificate on demand.
[0031] In a further possible implementation form, the subscription certificate request further comprises a subscription derivation policy indicative of one or more communication services of the mobile network allowed to be used by a slave UE using the valid subscription of the master UE. This allows to define the slave subscription for the user of the slave UE with a fine granularity.
[0032] In a further possible implementation form, the network entity is further configured to verify the subscription derivation policy. This allows to make sure that the subscription derivation policy and, thus, the slave subscription complies, for instance, with regulations defined by the operator of the mobile network.
[0033] In a further possible implementation form, the master subscription certificate further comprises an indication, i.e. certification of a validity period of the master subscription certificate, wherein the master subscription certificate expires after the validity period. Defining a validity period for the master subscription certificate allows further increasing the security.
[0034] According to a sixth aspect a method is provided for operating a network entity, in particular a Subscription Certification Function, SUCF, in a mobile network. The method according to the sixth aspect comprises the steps of:
[0035] generating a master subscription certificate, wherein the master subscription certificate is electronically signed with a private key of the network entity or a further network entity and certifies a valid subscription of a master UE and comprises a public key of the master UE; and
[0036] providing the master subscription certificate to the master UE.
[0037] The method according to the sixth aspect allows a slave UE to use the subscription of the master UE in a mobile network in a secure manner. The method according to the sixth aspect can be performed by the network entity according to the fifth aspect. Thus, further features of the method according to the sixth aspect result directly from the functionality of the network entity according to the fifth aspect as well as its different implementation forms described above and below.
[0038] According to a seventh aspect an access and mobility management entity in a mobile network is provided. The access and mobility management entity according to the seventh aspect is configured to receive from a slave user entity, UE, a request (herein also referred to as user registration and / or activation request) for using communication services provided by the mobile network based on a valid subscription of a master UE. The user registration request comprises a slave subscription certificate based on a master subscription certificate, wherein the slave subscription certificate is electronically signed with a private key of the master UE and comprises a public key of the user of the slave UE. Moreover, the access and mobility management entity according to the seventh aspect is configured to verify the slave subscription certificate based on a public key of the master UE for allowing, i.e. enabling the slave UE to use the communication services provided by the mobile network based on the valid subscription of the master UE. Thus, the access and mobility management entity according to the seventh aspect supports secure cross-UE subscription sharing between the master UE and the slave UE.
[0039] In a further possible implementation form, the slave subscription certificate further comprises an identifier of the user of the slave UE and / or an identifier of the master UE. Identifying the user of the slave UE and / or the master UE allows further increasing the security.
[0040] In a further possible implementation form, the access and mobility management entity according to the seventh aspect is further configured to verify whether the communication services requested to be used by the slave UE based on a valid subscription of a master UE comply with a subscription derivation policy for the master UE. This allows to make sure that the subscription derivation policy and, thus, the slave subscription complies, for instance, with regulations defined by the operator of the mobile network.
[0041] In a further possible implementation form, the access and mobility management entity according to the seventh aspect is further configured to send a User registration status message to the master UE, wherein the User registration status message is indicative of whether the slave UE is allowed to use the communication services provided by the mobile network based on the valid subscription of the master UE. Based on this information the master UE may take further actions.
[0042] According to an eighth aspect a method is provided for operating an access and mobility management entity in a mobile network. The method according to the eighth aspect comprises the following steps:
[0043] receiving from a slave user entity, UE, a request (herein also referred to as user registration or activation request) for using communication services provided by the mobile network based on a valid subscription of a master UE, wherein the user registration request comprises a slave subscription certificate based on a master subscription certificate, wherein the slave subscription certificate is electronically signed with a private key of the master UE and comprises a public key of the user of the slave UE; and
[0044] verifying the slave subscription certificate based on a public key of the master UE for allowing, i.e. enabling the slave UE to use the communication services provided by the mobile network based on the valid subscription of the master UE.
[0045] The method according to the eighth aspect allows a slave UE to use the subscription of the master UE in a mobile network in a secure manner. The method according to the eighth aspect can be performed by the access and mobility management entity according to the seventh aspect. Thus, further features of the method according to the eighth aspect result directly from the functionality of the access and mobility management entity according to the seventh aspect as well as its different implementation forms described above and below.
[0046] According to a ninth aspect, a computer program product is provided, comprising a computer-readable storage medium for storing program code which causes a computer or a processor to perform the method according to the second aspect, the method according to the fourth aspect, the method according to the sixth aspect and / or the method according to the eighth aspect, when the program code is executed by the computer or the processor.
[0047] Details of one or more embodiments are set forth in the accompanying drawings and the description below. Other features, objects, and advantages will be apparent from the description, drawings, and claims.BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In the following, embodiments of the present disclosure are described in more detail with reference to the attached figures and drawings, in which:
[0049] Fig. 1 shows a schematic diagram illustrating a mobile network including a master UE, a slave UE, a network entity and an access and management entity according to an example allowing the master UE to bind the user of the slave UE with the subscription of the master UE;
[0050] Fig. 2a shows a signalling diagram illustrating a master UE according to an example requesting a subscription certificate from a network entity according to an example for sharing a subscription with a user on a slave UE according to an example;
[0051] Fig. 2b shows a signalling diagram illustrating a user on a slave UE according to an example requesting a certificate from a master UE according to an example for sharing the subscription of the master UE with the user of the slave UE;
[0052] Fig. 2c shows a signalling diagram illustrating a slave UE according to an example interacting with an access and mobility management entity according to an example for sharing the subscription of the master UE with the user of the slave UE;
[0053] Fig. 3 shows a flow diagram illustrating a method of operating a master UE according to an example for sharing a subscription of the master UE with a user of a slave UE;
[0054] Fig. 4 shows a flow diagram illustrating a method of operating a slave UE according to an example for sharing a subscription of a master UE with the user of the slave UE;
[0055] Fig. 5 shows a flow diagram illustrating a method of operating a network entity according to an example for providing a subscription certificate to a master UE for sharing the subscription of the master UE with the slave UE; and
[0056] Fig. 6 shows a flow diagram illustrating a method of operating an access and mobility management entity according to an example for receiving a request from a user of a slave UE for sharing a subscription of the master UE with the user of the slave UE.
[0057] In the following, identical reference signs refer to identical or at least functionally equivalent features.
[0058] DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] In the following description, reference is made to the accompanying figures, which form part of the disclosure, and which show, by way of illustration, specific aspects of embodiments of the present disclosure or specific aspects in which embodiments of the present disclosure may be used. It is understood that embodiments of the present disclosure may be used in other aspects and comprise structural or logical changes not depicted in the figures. The following detailed description, therefore, is not to be taken in a limiting sense, and the scope of the present disclosure is defined by the appended claims.
[0060] For instance, it is to be understood that a disclosure in connection with a described method may also hold true for a corresponding device or system configured to perform the method and vice versa. For example, if one or a plurality of specific method steps are described, a corresponding device may include one or a plurality of units, e.g. functional units, to perform the described one or plurality of method steps (e.g. one unit performing the one or plurality of steps, or a plurality of units each performing one or more of the plurality of steps) , even if such one or more units are not explicitly described or illustrated in the figures. On the other hand, for example, if a specific apparatus is described based on one or a plurality of units, e.g. functional units, a corresponding method may include one step to perform the functionality of the one or plurality of units (e.g. one step performing the functionality of the one or plurality of units, or a plurality of steps each performing the functionality of one or more of the plurality of units) , even if such one or plurality of steps are not explicitly described or illustrated in the figures. Further, it is understood that the features of the various exemplary embodiments and / or aspects described herein may be combined with each other, unless specifically noted otherwise.
[0061] Figure 1 shows a schematic diagram illustrating a mobile network 100 configured to provide mobile communication services to user entities, UEs, in particular user entity, such as the UE 110 (also referred to herein as UE-Aor master UE 110 for reasons described in the following) and the UE 120 (also referred to herein as UE-B or slave UE 110 for reasons described in the following) . In an embodiment, the mobile network 100 may be a current or future 3rd Generation Partnership Project (3GPP) mobile network 100, for instance, a 5G or a 6G network. In the example illustrated in figure 1 the master UE 110 has a valid subscription for using the communication services provided by the mobile network 100 and is configured to share the subscription with a user of a slave UE 120 by enabling the user of the slave UE 120 to use at least some of the communication services provided by the mobile network 100 based on the valid subscription of the master UE 110. As will be described in more details in the following, to this end, a network entity 130, in particular a Subscription Certification Function, SUCF, 130 of the mobile network 100 is configured to issue a UE subscription profile certificate 115 (herein also referred to as master subscription certificate or UE-SUB-CERT 115) to the master UE 110, i.e. the actual subscriber. Based on the master subscription certificate 115 from the SUCF 130, the master UE 110, when needed, may issue a temporary user derived subscription certificate 125 (herein also referred to as slave subscription certificate or USER-dSUB-CERT 125) to the user of the slave UE 120 that may or may not be collocated with the subscriber master UE 110. The user may use the slave subscription certificate 125, i.e. USER-dSUB-CERT 125 on the slave UE 120 device for accessing the mobile network 100 by means of a registration / activation procedure, where the network 100 may verify the slave subscription certificate 125 based on the information contained in the master subscription certificate 115 that is available to the network 100.
[0062] More specifically, in a first stage illustrated in figure 1 the network entity 130, in particular SUCF 130 is configured to issue a master subscription certificate 115, i.e. UE-SUB-CERT 115 to the master UE 110, wherein the master subscription certificate 115 comprises a public key of the master UE 110 (corresponding to a private key of the master UE 110) . In an embodiment, the master subscription certificate 115 may further comprise am indication of a subscription derivation policy (as will be described in more detail below) and / or indication of a valid period of the certificate. The master subscription certificate 115 is digitally signed by a private key of the network entity 130, in particular SUCF 130 or a further network entity.
[0063] In a second stage illustrated in figure 1, a user, for instance, the user of the slave UE 120 may request a slave subscription certificate 125, i.e. USER-dSUB-CERT 125) from the master UE 120, wherein the slave subscription certificate 125 comprises a public key of the user of the slave UE 120. In an embodiment, the slave subscription certificate 125 further comprises a user-ID, information about the slave UE 120 and / or information about a derived service policy. The slave subscription certificate 125 is digitally signed by the private key of the master UE 110.
[0064] In a third stage illustrated in figure 1, an access and mobility management entity 140a, b of the mobile network 100, such as an Access and Mobility Management Function 140a and / or an Authentication Server Function 140b receives a user’s registration request 135 from the slave UE 120, wherein the request includes the slave subscription certificate 125, and is configured to check the authenticity of the slave subscription certificate 125 using the public key of the master UE 110. Moreover, the access and mobility management entity 140a, b of the mobile network 100 may check the ownership of the User-ID#b (challenge / response against User-b’s pubKEY information and / or authorization against subscription derivation policy of the master UE 110, i.e., check if the derivation is allowed according to the profile of the master UE 110) .
[0065] In an embodiment, the master subscription certificate 115, i.e. UE-SUB-CERT 115 may comprise in addition to the public key of the master UE 110 one or more of the elements listed in the following table 1:
[0066] Table 1: Fields in UE-SUB-CERT
[0067] As can be taken be taken from table 1, in an embodiment, the subscription derivation policy may define: the maximum number of users the master UE 110 can share its subscription with; the types of users that the master UE 110 is allowed to share its subscription with; the allowed bandwidth for a user using the subscription of the master UE 110; the QoS policy for a user using the subscription of the master UE 110, such as latency and priority; and / or the charging policy for a user using the subscription of the master UE 110, i.e., the pricing scheme for a user could be different from the pricing scheme for the UE subscriber.
[0068] Figures 2a-c illustrate by means of signaling diagrams more details of the interactions between the master UE 110, the slave UE 120 and the network entities 130, 140a, b for sharing the subscription of the master UE 110 with the user of the slave UE 120. More specifically, figure 2a shows a signaling diagram illustrating the master UE 110 according to an embodiment requesting a master subscription certificate 115 from the network entity 130, in particular SUCF 130 according to an embodiment, while figure 2b shows a signaling diagram illustrating the user of the slave UE 120 according to an embodiment requesting a slave subscription certificate 125 from the master UE 110 and figure 2c shows a signaling diagram illustrating the user of the slave UE 120 according to an embodiment interacting with an access and mobility management entity 140a, b according to an embodiment for sharing the subscription of the master UE 110 with the user of the slave UE 120.
[0069] More specifically, in step 1 of figure 2a, the master UE 110 sends a request to the SUCF 130 to ask for certifying its subscription. To this end, the master UE 110 locally generates a private-public key pair <UE-PrivKEY, PubKEY>, where the private key is held, i.e. stored in a secure memory of the master UE 110 and the public key is sent to the SUCF 130 as part of the request. In an embodiment, the request may be sent via the AMF 140a and the AUSF 140b to the SUCF 130 together with the other data described above in the context of table 1, such as the subscription derivation policy and SUCI.
[0070] In step 2 of figure 2a, the SUCF 130 sends a request to the UDM 150 of the mobile network 100 for verifying the subscription information of the master UE 110 defined by a profile 155 of the master UE 110. To this end, the SUCF 130 may interact with the UDM 150 to check the subscription status (e.g., UE tariff plan and the feasibility of subscription derivation policy proposed by the master UE 110) .
[0071] In step 3 of figure 2a, the UDM 150 sends a response to the SUCF 130. The response confirms: 1) whether the subscription of the master UE 110 is valid, 2) the subscription period and 3) the feasibility of the subscription derivation policy.
[0072] In step 4 of figure 2a, the SUCF 130 sends a response back to the master UE 110 with the master subscription certificate 115, i.e. UE-SUB-CERT 115 already described above. In other words, if the response from the UDM 150 approves the UE subscription and its subscription derivation policy, the SUCF 130 issues the master subscription certificate 115, i.e. UE-SUB-CERT 115 to the master UE 110 with the digital signature of the SUCF 130, i.e. using a private key of the SUCF 130.
[0073] As already mentioned above, figure 2b shows the slave subscription certificate derivation procedure implemented according to embodiments disclosed herein, i.e. the procedure of the user of the slave UE 120 requesting a slave subscription certificate 125, i.e. USER-dSUB-CERT 125 from the from the master UE 110 having a valid subscription.
[0074] In step 5 of figure 2b, the user (herein referred to also as Bob) of the slave UE 120, i.e. UE-B 120 sends a User Subscription Derivation Request to the master UE 110, i.e. UE-A110. The request contains the User-ID, User-PubKEY (contained in a User Profile) , UE-B-ID (contained in a profile) and a requested service description. The requested service description contains the services (subscription) that the user expects to share under the subscription of the master UE 110.
[0075] In the optional step 6 of figure 2b, the master UE 110, i.e. UE-A110 verifies the information (User Profile and UE Profile) with a (3rd-party) service provider and / or any other entity that can play the role.
[0076] In step 7 of figure 2b, the master UE 110, i.e. UE-A110 creates a slave subscription certificate 125, i.e. USER-dSUB-CERT 125 for the user of the slave UE 120. The slave subscription certificate 125, i.e. USER-dSUB-CERT 125 may contain the approved service sharing policy to the User (identified as User-ID / User-PubKEY) and is signed by the master UE 110, i.e. UE-Awith the private key of the master UE 110, i.e. UE-A’s privKEY. Before digitally signing the slave subscription certificate 125, i.e. USER-dSUB-CERT 125 the master UE 110 may be configured to verify whether the requested service description from the user fulfills the UE-description derivation policy authorized by the operator.
[0077] In the optional step 8 of figure 2b, the master UE 110 my provision the issued slave subscription certificate 125, i.e. USER-dSUB-CERT 125 for the slave UE 120 to the UDM 150.
[0078] In an embodiment, the slave subscription certificate 125, i.e. USER-dSUB-CERT 125 for the user of the slave UE 120 may comprise one or more of the elements listed in the following table 2:
[0079] Table 2: Fields of USER-dSUB-CERT
[0080] As already mentioned above, figure 2c illustrates the user registration, i.e. activation procedure according to embodiments disclosed herein. More specifically, figure 2c illustrates the procedure of a user using the slave subscription certificate 125, i.e. USER-dSUB-CERT 125 issued by the master UE 110 to access the mobile network 100.
[0081] In step 9 of figure 2c, the user of the slave UE 120 (referred to as Bob in figure 2c) sends a user registration / activation request to access the 3GPP network 100. The request contains the User-ID, UE-B-ID and the slave subscription certificate 125, i.e. USER-dSUB-CERT 125 created by the master UE 110, i.e. UE-A110 in step 7 of figure 2b.
[0082] In step 10 of figure 2c, the UDM 150 identifies the User-ID in the User registration request from the AMF / AUSF 140a, b. This aims to make sure the sender does own the User-ID in the registration / activation request. This may be done by challenge / response messages (e.g., verifying if the user owns the corresponding privKEY in hand) .
[0083] In step 11 of figure 2c, the UDM 150 authenticates the slave subscription certificate 125, i.e. USER-dSUB. -CERT 125 in the user registration / activation request. This is done by using the public key of the master UE 110 stored in the UDM 150 or retrieved from the SUCF 130 in step 4 of figure 2a. Meanwhile, if any, deregister the service of the same User-ID active on other UEs.
[0084] In step 12 of figure 2c, the UDM 150 sends a User Registration Response to the AUSF 140b and then the AMF 140a to inform the registration / activation result with a temporal identifier similar to GUTI.
[0085] In the optional step 13 of figure 2c, the AUSF / AMF 140a, b sends the User registration status to the master UE 110, i.e. UE-A 110 (to inform the use of its derived subscription) .
[0086] In the optional step 14 of figure 2c, the user of the slave UE 120 uses the assigned temporal identifier for accessing the mobile network 100 and establishing a flow session to a DN 160.
[0087] Figure 3 shows a flow diagram illustrating a method 300 of operating the master UE 110 according to an embodiment for sharing the subscription of the master UE 110 with the slave UE 120 according to an embodiment. The method 300 comprises a step 301 of receiving a master subscription certificate 115 from the network entity 130, in particular SUCF 130 of the mobile network 100. As already described above, the master subscription certificate 115 is electronically signed with a private key of the network entity 130, in particular SUCF 130 or a further network entity and certifies the subscription of the master UE 110 and comprises a public key of the master UE 110. Moreover, the method 300 comprises a step 303 of generating a slave subscription certificate 125 based on the master subscription certificate 115 by electronically signing the slave subscription certificate 125 with a private key of the master UE 110, wherein the slave subscription certificate 125 comprises a public key of a user of a slave UE 120. The method 300 further comprises a step 305 of providing the slave subscription certificate 125 to the user of the slave UE 120 for allowing the user of the slave UE 120 to use, based on the slave subscription certificate 125, the communication services provided by the mobile network 100 with the subscription of the master UE 110.
[0088] The method 300 can be performed by the master UE 110. Thus, further features of the method 300 result directly from the functionality of the master UE 110 as well as the different embodiments thereof described above and below.
[0089] Figure 4 shows a flow diagram illustrating a method 400 of operating the user of the slave UE 120 according to an embodiment for sharing the subscription of the master UE 110 with the user of the slave UE 120. The method 400 comprises a step 401 of receiving a slave subscription certificate 125 from the master UE 110 with a subscription for using the communication services provided by the mobile network 100. As already described above, the slave subscription certificate 125 is electronically signed with the private key of the master UE 110 and comprises the public key of the user of the slave UE 120. Moreover, the method 400 comprises a step 403 of sending a request to the access and mobility management entity, such as the AMF 140a and / or the AUSF 140b of the mobile network 100 for using the communication services provided by the mobile network 100 based on the subscription of the master UE 110, wherein the request comprises the slave subscription certificate 125.
[0090] The method 400 can be performed by the slave UE 120. Thus, further features of the method 400 result directly from the functionality of the slave UE 120 as well as the different embodiments thereof described above and below.
[0091] Figure 5 shows a flow diagram illustrating a method of operating the network entity 130, in particular SUCF 130 according to an embodiment for providing a subscription certificate 115 to the master UE 110 for sharing the subscription of the master UE 110 with the user of the slave UE 120. The method 500 comprises a step 501 of generating a master subscription certificate 115, wherein the master subscription certificate 115 is electronically signed with a private key of the network entity 130, in particular SUCF 130 or a further network entity and certifies the valid subscription of the master UE 110 and comprises a public key of the master UE 110. Moreover, the method 500 comprises a step 503 of providing the master subscription certificate 115 to the master UE 110.
[0092] The method 500 can be performed by the network entity 130, in particular SUCF 130. Thus, further features of the method 500 result directly from the functionality of the network entity 130, in particular SUCF 130 as well as the different embodiments thereof described above and below.
[0093] Figure 6 shows a flow diagram illustrating a method 600 of operating an access and mobility management entity, such as the AMF 140a and / or the AUSF 140b illustrated in figure 1 for receiving a request from the user of the slave UE 120 for sharing the subscription of the master UE 110 with the slave UE 120. The method 600 comprises a step 601 of receiving from the user of the slave UE 120 a request for using communication services provided by the mobile network 100 based on the subscription of the master UE 110, wherein the request comprises a slave subscription certificate 125 and wherein the slave subscription certificate 125 is electronically signed with a private key of the master UE 110 and comprises a public key of the user of the slave UE 120. Moreover, the method 600 comprises a step 603 of verifying the slave subscription certificate 125 based on the public key of the master UE 110.
[0094] The method 600 can be performed by the access and mobility management entity 140a, b, such as the AMF 140a and / or the AUSF 140b illustrated in figure 1. Thus, further features of the method 600 result directly from the functionality of the access and mobility management entity 140a, b, such as the AMF 140a and / or the AUSF 140b illustrated in figure 1 as well as the different embodiments thereof described above and below.
[0095] The person skilled in the art will understand that the "blocks" ( "units" ) of the various figures (method and apparatus) represent or describe functionalities of embodiments of the present disclosure (rather than necessarily individual "units" in hardware or software) and thus describe equally functions or features of apparatus embodiments as well as method embodiments (unit = step) .
[0096] In the several embodiments provided in the present application, it should be understood that the disclosed system, apparatus, and method may be implemented in other manners. For example, the described embodiment of an apparatus is merely exemplary. For example, the unit division is merely a logical function division and may be another division in an actual implementation. For example, a plurality of units or components may be combined or integrated into another system, or some features may be ignored or not performed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections may be implemented by using some interfaces. The indirect couplings or communication connections between the apparatuses or units may be implemented in electronic, mechanical, or other forms.
[0097] The units described as separate parts may or may not be physically separate, and parts displayed as units may or may not be physical units, may be located in one position, or may be distributed on a plurality of network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the solutions of the embodiments.
[0098] In addition, functional units in the embodiments of the disclosure may be integrated into one processing unit, or each of the units may exist alone physically, or two or more units may be integrated into one unit.
Claims
1.A master user entity, UE (110) with a subscription for using communication services provided by a mobile network (100) , wherein the master UE (110) is configured to:receive a master subscription certificate (115) from a network entity (130) of the mobile network (100) , wherein the master subscription certificate (115) is electronically signed with a private key of the network entity (130) or a further network entity and certifies the subscription of the master UE (110) and comprises a public key of the master UE (110) ;generate a slave subscription certificate (125) based on the master subscription certificate (115) by electronically signing the slave subscription certificate (125) with a private key of the master UE (110) , wherein the slave subscription certificate (125) comprises a public key of a user of a slave UE (120) ; andprovide the slave subscription certificate (125) to the slave UE (120) for allowing the slave UE (120) to use, based on the slave subscription certificate (125) , the communication services provided by the mobile network (100) with the subscription of the master UE (110) .2.The master UE (110) of claim 1, wherein the master subscription certificate (115) from the network entity (130) of the mobile network (100) comprises an indication of a validity period of the master subscription certificate (115) and wherein the master subscription certificate (115) from the network entity (130) expires after the validity period of the master subscription certificate (115) .3.The master UE (110) of any one of the preceding claims, wherein the master subscription certificate (115) from the network entity (130) of the mobile network (100) further certifies a subscription derivation policy for generating the slave subscription certificate (125) based on the master subscription certificate (115) .4.The master UE (110) of any one of the preceding claims, wherein the master UE (110) is configured to receive the master subscription certificate (115) from the network entity (130) of the mobile network (100) , in response to sending a subscription certificate request to the network entity (130) , wherein the subscription certificate request comprises the public key of the master UE (110) .5.The master UE (110) of any one of the preceding claims, wherein the master UE (110) is configured to generate the slave subscription certificate (125) based on the master subscription certificate (115) by electronically signing the slave subscription certificate (125) with the private key of the master UE (110) and to provide the slave subscription certificate (125) to the slave UE (120) , in response to receiving a subscription derivation request from the slave UE (120) , wherein the subscription derivation request comprises the public key of the user of the slave UE (120) .6.A method (300) of operating a master user entity, UE (110) with a subscription for using communication services provided by a mobile network (100) , wherein the method (300) comprises:receiving (301) a master subscription certificate (115) from a network entity (130) of the mobile network (100) , wherein the master subscription certificate (115) is electronically signed with a private key of the network entity (130) or a further network entity and certifies the subscription of the master UE (110) and comprises a public key of the master UE (110) ;generating (303) a slave subscription certificate (125) based on the master subscription certificate (115) by electronically signing the slave subscription certificate (125) with a private key of the master UE (110) , wherein the slave subscription certificate (125) comprises a public key of a user of the slave UE (120) ; andproviding (305) the slave subscription certificate (125) to the slave UE (120) for allowing the slave UE (120) to use, based on the slave subscription certificate (125) , the communication services provided by the mobile network (100) with the subscription of the master UE (110) .7.A slave user entity, UE, (120) for using communication services provided by a mobile network (100) , wherein the slave UE (120) is configured to:receive a slave subscription certificate (125) from a master UE (110) with a subscription for using the communication services provided by the mobile network (100) , wherein the slave subscription certificate (125) is electronically signed with a private key of a master UE (110) and comprises a public key of a user of the slave UE (120) ; andsend a request to an access and mobility management entity (140a, b) of the mobile network (100) for using the communication services provided by the mobile network (100) based on the subscription of the master UE (110) , wherein the request comprises the slave subscription certificate (125) .8.The slave UE (120) of claim 7, wherein the slave subscription certificate (125) further comprises an identifier of the user of the slave UE (120) and / or an identifier of the master UE (110) .9.The slave UE (120) of claim 7 or 8, wherein the slave subscription certificate (125) further comprises an indication of a validity period of the slave subscription certificate (125) .10.The slave UE (120) of any one of claims 7 to 9, wherein the slave UE (120) is configured to receive the slave subscription certificate (125) from the master UE (110) , in response to sending a subscription derivation request to the master UE (110) .11.The slave UE (120) of claim 10, wherein the subscription derivation request to the master UE (110) comprises a requested service description indicative of the communication services allowed to be used by the slave UE (120) using the valid subscription of the master UE (110) .12.A method (400) of operating a slave user entity, UE, (120) for using communication services provided by a mobile network (100) , wherein method (400) comprises:receiving (401) a slave subscription certificate (125) from a master UE (110) with a subscription for using the communication services provided by the mobile network (100) , wherein the slave subscription certificate (125) is electronically signed with a private key of a master UE (110) and comprises a public key of a user of the slave UE (120) ; andsending (403) a request to an access and mobility management entity (140a, b) of the mobile network (100) for using the communication services provided by the mobile network (100) based on the subscription of the master UE (110) , wherein the request comprises the slave subscription certificate (125) .13.A network entity (130) in a mobile network (100) , wherein the network entity (130) is configured to:generate a master subscription certificate (115) , wherein the master subscription certificate (115) is electronically signed with a private key of the network entity (130) or a further network entity and certifies a subscription of a master UE (110) and comprises a public key of the master UE (110) ; andprovide the master subscription certificate (115) to the master UE (110) .14.The network entity (130) of claim 13, wherein the network entity (130) is configured to generate the master subscription certificate (115) , in response to receiving a subscription certificate request from the master UE (110) , wherein the subscription certificate request comprises the public key of the master UE (110) .15.The network entity (130) of claim 14, wherein the subscription certificate request further comprises a subscription derivation policy indicative of one or more communication services of the mobile network (100) allowed to be used by a slave UE (120) using the subscription of the master UE (110) .16.The network entity (130) of claim 15, wherein the network entity (130) is further configured to verify the subscription derivation policy.17.The network entity (130) of any one of claims 13 to 16, wherein the master subscription certificate (115) further comprises an indication of a validity period of the master subscription certificate (115) and wherein the master subscription certificate (115) expires after the validity period.18.A method (500) of operating a network entity (130) in a mobile network (100) , wherein the method (500) comprises:generating (501) a master subscription certificate (115) , wherein the master subscription certificate (115) is electronically signed with a private key of the network entity (130) or a further network entity and certifies a subscription of a master UE (110) and comprises a public key of the master UE (110) ; andproviding (503) the master subscription certificate (115) to the master UE (110) .19.An access and mobility management entity (140a, b) in a mobile network (100) , wherein the access and mobility management entity (140a, b) is configured to:receive from a slave user entity, UE, (120) a request for using communication services provided by the mobile network (100) based on a subscription of a master UE (110) , wherein the request comprises a slave subscription certificate (125) and wherein the slave subscription certificate (125) is electronically signed with a private key of the master UE (110) and comprises a public key of a user of the slave UE (120) ; andverify the slave subscription certificate (125) based on a public key of the master UE (110) .20.The access and mobility management entity (140a, b) of claim 19, wherein the slave subscription certificate (125) further comprises an identifier of the user of the slave UE (120) and / or an identifier of the master UE (110) .21.The access and mobility management entity (140a, b) of claim 19 or 20, wherein the access and mobility management entity (140a, b) is further configured to verify whether the communication services requested to be used by the slave UE (110) based on a subscription of a master UE (110) comply with a subscription derivation policy for the master UE (110) .22.The access and mobility management entity (140a, b) of any one of claims 19 to 21, wherein the access and mobility management entity (140a, b) is further configured to send a User registration status message to the master UE (110) , wherein the User registration status message is indicative of whether the slave UE (120) is allowed to use the communication services provided by the mobile network (100) based on the subscription of the master UE (110) .23.A method (600) of operating an access and mobility management entity (140a, b) in a mobile network (100) , wherein the method (600) comprises:receiving (601) from a slave user entity, UE, (120) a request for using communication services provided by the mobile network (100) based on a subscription of a master UE (110) , wherein the request comprises a slave subscription certificate (125) and wherein the slave subscription certificate (125) is electronically signed with a private key of the master UE (110) and comprises a public key of a user of the slave UE (120) ; andverifying (603) the slave subscription certificate (125) based on a public key of the master UE (110) .24.A computer program product comprising a computer-readable storage medium for storing program code which causes a computer or a processor to perform the method (300) of claim 6, the method (400) of claim 12, the method (500) of claim 18, or the method (600) of claim 23, when the program code is executed by the computer or the processor.
Citation Information
Patent Citations
Subscription network access using verification digital identification
CN116391378A
Method and apparatus for subscription sharing
US20130247161A1
Network authentication method, and related device and system
US20190149329A1
Mobile network authentication method, terminal device, server, and network authentication entity
US20190208417A1
Download of a subscription profile to a communication device
WO2023169682A1