Attachment authentication
By including timestamp information in authentication requests, the inefficiencies and resource waste in UE registration processes are mitigated, optimizing authentication procedures in non-terrestrial satellite networks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2026-04-02
AI Technical Summary
In non-terrestrial satellite communication networks with store-and-forward scenarios, the authentication procedures for user equipment (UE) registration can be inefficient due to delays and unnecessary resource usage, particularly when UE switches between terrestrial and satellite networks, leading to redundant authentication attempts and resource waste.
Incorporating timestamp information in the authentication data request to determine the reception time of the first request for the terminal device, allowing early rejection or provisioning of authentication information, thereby optimizing authentication procedures.
Reduces unnecessary authentication procedures and conserves network resources by enabling early rejection or completion of authentication processes based on timestamp information, improving efficiency in UE registration across terrestrial and satellite networks.
Smart Images

Figure EP2025072180_02042026_PF_FP_ABST
Abstract
Description
ATTACHMENT AUTHENTICATIONFIELD
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for attachment authentication.BACKGROUND
[0002] A communication network may serve as a facility that enables communications between two or more communication devices or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.
[0003] The communication network may operate in accordance with standards such as those provided by Third Generation Partnership Project (3 GPP) or European Telecommunications Standards Institute (ETSI). Examples of standards provided by 3 GPP are the so-called 3 GPP standards for cellular technology generations, such as 3 GPP standards for 4G technology, 5G technology, 6G technology etc.SUMMARY
[0004] In a first aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: transmit, to a second apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; and receive, from the second apparatus, an authentication data response to the authentication data request, the authentication data response either comprising a rejection indication to the authentication data request or comprising authentication information for the terminal device.
[0005] In a second aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatusat least to: receive, from a first apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; determine whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request; and transmit, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request or comprising at least authentication information for the terminal device.
[0006] In a third aspect of the present disclosure, there is provided a method. The method comprises: transmitting, to a second apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; and receiving, from the second apparatus, an authentication data response to the authentication data request, the authentication data response either comprising a rejection indication to the authentication data request or comprising authentication information for the terminal device.
[0007] In a fourth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a first apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; determining whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request; and transmitting, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request or comprising at least authentication information for the terminal device.
[0008] In a fifth aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises means for transmitting, to a second apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; and means for receiving, from the second apparatus, an authentication data response to the authentication data request, the authentication data response either comprising arejection indication to the authentication data request or comprising authentication information for the terminal device.
[0009] In a sixth aspect of the present disclosure, there is provided a second apparatus. The second apparatus comprises means for receiving, from a first apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; means for determining whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request; and means for transmitting, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request or comprising at least authentication information for the terminal device.
[0010] In a seventh aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the third aspect.
[0011] In an eighth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fourth aspect.
[0012] In some or all examples of the first, second, third, fourth, fifth, sixth, seventh, and eighth aspects, the first apparatus may be further caused to transmit, to the second apparatus, a provisional update location request for the terminal device, the provisional update location request comprising the timestamp information; and receive, from the second apparatus, a provisional update response to the provisional update location request, the provisional update response either comprising a rejection indication to the provisional update location request or comprising subscription information for the terminal device.
[0013] In some example embodiments, the first apparatus may be caused to transmit, to the second apparatus, the authentication data request comprising the timestamp information and an indication indicative of whether to request for provisioning of subscription information for the terminal device; and receive the authentication data response comprising one of the following: a rejection indication to the authentication data request, the authentication information, or both the authentication information and thesubscription information for the terminal device.
[0014] In some example embodiments, the indication may comprise a store and forward flag. In some example embodiments, the first apparatus may be further caused to: in accordance with a determination that the first request for the terminal device is received in a store-and-forward mode, add the indication in the authentication data request.
[0015] In some example embodiments, the first apparatus may be further caused to: in accordance with acquisition of both the authentication information and the subscription information for the terminal device, determine the validity of the subscription information; and in accordance with a determination that the subscription information is valid, perform an authentication procedure of the terminal device based on the authentication information.
[0016] In some example embodiments, the first apparatus may be further caused to: in accordance with a determination that the authentication data response or the provisional update response comprises a rejection indication, determine that the first request for the terminal device is rejected.
[0017] In some example embodiments, the first request may comprise an attach request or a tracking area update request, and wherein the first apparatus may be caused to transmit, to the second apparatus, the authentication data request for the terminal device by: in response to receiving the attach request or the tracking area update request for the terminal device, transmitting the authentication data request for the terminal device to the second apparatus.
[0018] In some example embodiments, the first apparatus may be or comprised in a mobility management entity (MME), and the second apparatus may be or comprised in a home subscriber server (HSS). In some embodiments, at least one of the first apparatus or the second apparatus may be in a Long Term Evolution (LTE) system.
[0019] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0021] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0022] FIG. 2A illustrates a signaling chart of an authentication procedure in accordance with some example embodiments of the present disclosure;
[0023] FIG. 2B illustrates a signaling chart of an example authentication procedure and an example location update procedure in accordance with some example embodiments of the present disclosure;
[0024] FIG. 2C illustrates a signaling chart of another example authentication procedure in accordance with some example embodiments of the present disclosure;
[0025] FIG. 3 illustrates a flowchart of an example process of responding to an authentication data request according to some example embodiments of the present disclosure;
[0026] FIG. 4 illustrates a flowchart of an example process of responding to an authentication data response according to some example embodiments of the present disclosure;
[0027] FIG. 5 illustrates a flowchart of another example process of responding to an authentication data request and an update location request according to some example embodiments of the present disclosure;
[0028] FIG. 6 illustrates a signaling chart of an example attach procedure in accordance with some example embodiments of the present disclosure;
[0029] FIG. 7 illustrates a signaling chart of another example attach procedure in accordance with some example embodiments of the present disclosure;
[0030] FIG. 8 illustrates a flowchart of a method implemented at a first apparatus in accordance with some example embodiments of the present disclosure;
[0031] FIG. 9 illustrates a flowchart of a method implemented at a second apparatus in accordance with some example embodiments of the present disclosure;
[0032] FIG. 10 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0033] FIG. 11 illustrates a block diagram of an example computer readable medium inaccordance with some example embodiments of the present disclosure.
[0034] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION
[0035] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0036] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0037] References in the present disclosure to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0038] It shall be understood that although the terms “first,” “second,”..., etc. in front of noun(s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun(s). For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0039] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the listof two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0040] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0041] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0042] As used in this application, the term “circuitry” may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and(b) combinations of hardware circuits and software, such as (as applicable):(i) a combination of analog and / or digital hardware circuit(s) with software / firmware and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0043] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the termcircuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0044] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0045] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaveslike a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0046] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user equipment” and “UE” may be used interchangeably.
[0047] A core network function as described herein may be implemented as a core network entity that includes a combination of hardware processing circuit and software and / or firmware comprising machine-readable instructions, or software comprising machine-readable instructions that are executable by at least one processor of hardware processing circuit of an apparatus. A hardware processing circuit includes at least one processor and at least one memory storing machine-readable instructions that are executable by the at least one processor of the hardware processing circuit. A processor includes any or some combination of an accelerator, a microprocessor, a core of a multicore microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digital signal processor, a central processing unit, a graphic processing unit, a tensor processing unit. Memory includes any or some combination ofvolatile or non-volatile memory (e.g., a flash memory, cache, a random-access memory (RAM), and / or a read-only memory (ROM)). The memory stores the machine-readable instructions of the software and / or firmware for execution by the at least one processor of the hardware processing circuit. The machine-readable instructions are executable by the at least one processor of the hardware processing circuit cause the hardware processing circuit to perform the actions or operations of the methods described herein. For example, the session management function described herein may be implemented as a session management entity and the session management policy control function described herein may be implemented as a session management policy control entity, respectively.
[0048] As used herein, the term “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0049] In communication systems, an attach procedure enables a user equipment (UE) to associate with the network. It involves the UE sending an attach request to the network and the network sending an attach response which may assign a temporary identity and other configuration details for the UE. In the attach procedure, UE needs to authenticate with the network, e.g., send an authentication data request to the network. The attachment authentication enables management of UE registration, security, and service provisioning, thus studies of the attachment authentication are desirable.
[0050] With development of communication technologies, various improvements of the attach procedure have been proposed. For example, in non-terrestrial networks (NTN, i.e. satellite access) and store and forward (S&F) scenarios, it is recently agreed in 3GPP TR 23.700-29 that a “Request Time” (timestamp) is added in the Update Location Request sent by the UE, to address a problem that may occur with the “Location Update”, which is part of the normal registration procedure in NTN S&F scenarios. The details aredescribed below.
[0051] The NTN S&F means that, for example, a satellite may store messages sent by the UE when currently the satellite has no link to the ground station. The stored messages will be forwarded when the satellite has again a connection to the ground station. Similarly, when the satellite has a connection to the ground station, but no link is available from any satellite to the UE, messages to the UE will be stored and delivered later on.
[0052] In the NTN S&F scenarios, when the UE initiates registration with the NTN, it could take some time (due to loss of connection, for example, between satellite and ground station) until the “Update Location Request” sent by the UE to the home subscriber server (HSS) is actually received at the HSS. In other words and more generally, it may take some time until the UE receives the registration acceptance.
[0053] In some cases, the UE may further register with a terrestrial network (TN). The TN’s Update Location Request may be received at the HSS earlier than the NTN’ s Update Location Request and the UE can be registered with the TN. If the NTN’ s Update Location Request is delivered to the HSS at a later point, this may cause a problem, i.e., the HSS will see the NTN’s Update Location Request as the “new” Update Location Request although it was sent later and not relevant anymore.
[0054] For example, if the UE attempted attach at 10:00 via the S&F system, the S&F system takes 10 mins to reach to ground connection to attempt location update. If the UE in the meantime, let’s say at 10:05 finds any terrestrial connection, it will go attach to the network. The HSS will save the location update for 10:05 with terrestrial network. If the HSS receives another location update at 10: 10, then it will cancel the terrestrial network registration (which happened at 10:05). This is a wrong behavior, as the UE might be already in service via the terrestrial network.
[0055] For this, it has been agreed to add a “Request Time” (timestamp) in the Update Location Request, i.e., a timestamp is also delivered with the NTN’s Update Location Request. Based on the timestamp, the HSS can see if the Update Location Request is actually (still) valid. The agreement is reproduced below for reference.
[0056] The MME may indicate to HSS the "Request Time", allowing the HSS to check that no other (e.g. terrestrial) MME has sent an Update Location Request after the "Request Time", and fetches the authentication vector and other details from the HSSfollowing current Authentication and security procedures. The MME may trigger Update location with the HSS and Update location ACK is received by the MME. i.e. all the subscription details are retrieved by the MME-ground. The Update Location Request includes an indication that this location update is provisional i.e. the HSS must not consider the UE as registered until it receives the final Update Location Request.”
[0057] In this disclosure, further improvements / enhancements for the attach procedure, especially for the attachment authentication, are proposed. It is recognized that, the Update Location Request being received at the HSS is not the “first contact” between the UE and the network. For example, the HSS may be contacted earlier during an attachment authentication procedure.
[0058] In this case, it might happen that the authentication procedure becomes unnecessary if the HSS later rejects the registration procedure based on the timestamp delivered with the Update Location Request. That is because sending the timestamp in Update Location Request will not restrict the authentication procedure. The MME might continue with the authentication request towards UE, which is unnecessary if, the location update fails later due to conflicting location updates in the HSS.
[0059] Particularly, in the NTN S&F scenarios, the update location needs to span a multiple change of satellites (e.g. at least 3 satellites) due to the iterative process nature of S&F, causing a substantial delay in MME contacting the HSS. The authentication procedure may be started and maybe even completely performed (which means involvement of quite some messages to and from the satellite) before the HSS will actually see that the UE’s NTN registration is in fact not needed anymore (for example, when the UE has newly registered with a TN, see above). Thus, there will be a waste of resources (e.g., at the satellite links) for the unneeded authentication procedure.
[0060] In accordance with some example embodiments of the present disclosure, there is provided a solution for the authentication procedure. In this solution, a first apparatus transmits, to a second apparatus, an authentication data request for a terminal device. The authentication data request at least comprises timestamp information indicating a reception time of a first request for the terminal device. The first apparatus further receives, from the second apparatus, an authentication data response to the authentication data request. The authentication data response either comprises a rejection indication to the authentication data request or comprises authentication information for the terminaldevice.
[0061] In this way, the timestamp information related to the first request for the terminal device can be delivered in an early authentication procedure (e.g., the “first contact” between the UE and the HSS), thereby saving resources for the authentication procedure.
[0062] As an example, with the timestamp information being sent in an authentication data request to the HSS, the HSS can deny the authentication for the UE earlier without waiting for the UE to get rejected due to failed location update. As another example, if a further (TN) registration is performed for the same UE after an earlier registration with the NTN, the HSS can abort (or not even start) the NTN’s authentication procedure due to its earlier Request Time, thereby reducing or avoiding the cost for the NTN’s authentication procedure.
[0063] Note that, although the above examples are provided for the attachment authentication, the solutions provided in this disclosure may be implemented in other suitable authentication scenarios. For example, the authentication procedure may be present in a tracking area update (TAU) scenario. In this scenario, when a UE enters a new tracking area, it may initiate an authentication procedure and a location update procedure. Likewise, with the timestamp information of the “first request / contacf ’ for the UE being sent along with an authentication data request, the cost for the unnecessary authentication procedure can be reduced or avoided.
[0064] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0065] FIG. 1 illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. The environment 100 involves one or more terminal devices 110, one or more terrestrial network devices 120, one or more non-terrestrial network devices for example on satellites 130-1 and 130-2, an NTN gateway 140, a CN 150, and one or more CN network devices (also referred to as core network device), e.g., CN network devices 155 and 156.
[0066] In some example embodiments, the CN network device 155 may be an MME and the CN network device 160 may be an HSS. A non-terrestrial access network device 1311, e.g., RAN, and a non-terrestrial CN network device 1312, e.g., MME-NT (MME on board satellite), may be on the corresponding satellite 130-1. A non-terrestrial access networkdevice 1321, e.g., RAN, and a non-terrestrial CN network device 1322, e.g., MME-NT, may be on the corresponding satellite 130-2.
[0067] In this case, the UE 110 may attach to the network via the MME-NT on the satellite 130-1, the MME-NT on the satellite 130-2 or the MME-T (also referred to as MME-ground) in the CN 150. The UE 110 may transmit an attach request to the MME-T via one or more satellites. The MME-T may transmit an authentication data request to the HSS based on the attach request and obtain an authentication data response from the HSS. Based on the authentication data response, an attach response may be later sent to the UE 110 via one or more satellites.
[0068] It is to be understood that the number of devices and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of devices configured to implementing example embodiments of the present disclosure. Although the 5G CN network devices are illustrated in the communication environment 110, network device(s) in the LTE system may be included in the environment 110 for implementation of example embodiments of the present disclosure. In the following, for the purpose of illustration, some example embodiments are described with the CN network device 155 operating as an MME and the CN network device 160 operating as an HSS.
[0069] In some example embodiments, a transmission direction from the network device 120 to the terminal device 110 is referred to as a downlink (DL), while a transmission direction from the terminal device 110 to the network device 120 is referred to as an uplink (UL). In DL, the network device 120 is a transmitting (TX) device (or a transmitter) and the terminal device 110 is a receiving (RX) device (or a receiver). In UL, the terminal device 110 is a TX device (or a transmitter) and the network device 120 is a RX device (or a receiver).
[0070] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division MultipleAccess (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0071] FIG. 2A illustrates a signaling chart 200 of an authentication procedure in accordance with some example embodiments of the present disclosure. As illustrated in FIG. 2 A, the signaling chart 200 involves a first apparatus 210 and a second apparatus 220. For the purposes of discussion, the signaling chart 200 will be discussed with reference to FIG. 1.
[0072] In some example embodiments, the first apparatus 210 may be or comprised in an MME, and the second apparatus 210 may be or comprised in an HSS. For example, the first apparatus 210 may be an example of the CN network device 155, e.g., MME-T, in FIG. 1 and the second apparatus 120 may be an example of the CN network device 160, e.g., the HSS in FIG. 1. In some other examples, the first apparatus 210 may be or comprised in a non-terrestrial core network device, e.g., the MME-NT on the satellite 130- 1 or 130-2. The second apparatus 220 may be or comprised in a non-terrestrial core network device configured for the authentication / registration / location update / attach procedures.
[0073] In some example embodiments, at least one of the first apparatus 210 or the second apparatus 220 may be in the LTE system. For example, the first apparatus 210 may be or comprised in an MME in the Evolved Packet Core in the LTE system. Alternatively or in addition, the second apparatus 220 may be or comprised in an HSS in the Evolved Packet Core in the LTE system. In some example embodiments, the at least one of the first apparatus 210 or the second apparatus 220 may be in the 5G system. For example, the first apparatus 210 may be or comprised in an access and mobility management function (AMF). The second apparatus 220 may be or comprised in a unified data management function (UDF).
[0074] As illustrated in FIG. 2 A, the first apparatus 210 transmits, to the second apparatus 220, an authentication data request 2020 for a terminal device (e.g., terminal device 110 110 in FIG. 1), and the authentication data request 2020 at least comprises timestamp information indicating a reception time of a first request for the terminal device.The second apparatus 220 receives the authentication data request 2020.
[0075] In some example embodiments, the first request for the terminal device may be an attach request or a tracking area update (TAU) request. That is, the first request may refer to a first contact between the UE and the network. In the attachment scenarios, the UE may initiate an attach procedure by sending a registration request to an MME. In this case, the registration request may be first request for the UE. In the TAU scenarios, the UE may initiate a TAU procedure by sending a TAU request. In this case, the TAU request may be the first request for the UE.
[0076] In some example embodiments, the first apparatus 210, in response to receiving the attach request or the tracking area update request for the terminal device, transmits the authentication data request 2020 for the terminal device to the second apparatus. The authentication data request 2020 comprises at least timestamp information indicating a reception time of the attach request or the tracking area update request.
[0077] For example, in the attachment scenarios, a reception time of an attach request / registration request may be considered as the “Request Time” of the first request / contact between the UE and the network. In some examples, if one or more MMEs are involved in the transmission of the attach / regi strati on request between the UE and the HSS, the first time that the request is received by MMEs may be used for determination of the timestamp information.
[0078] In some example embodiments, the first apparatus 210 transmits to the second apparatus 220, the authentication data request 2020 comprising the timestamp information and an indication indicative of whether to request for provisioning of subscription information for the terminal device. In other words, the authentication data request 2020 may further include, in addition to the timestamp information, an indication of whether provisioning of subscription information for the terminal device is requested, needed or expected.
[0079] In some example embodiments, the indication may comprise a S&F flag. The S&F flag may have a first value to indicate that provisioning of subscription information for the terminal device is requested, needed or expected. The S&F flag may have a second value to indicate that provisioning of subscription information for the terminal device is not requested, needed or expected.
[0080] An example of the authentication data request according to some example embodiments of the present disclosure is shown below. The authentication data request shown below is updated from the table of Auth info Request as defined in 3GPP TS 29.272.Table 1 : Authentication Data Request
[0081] As can be seen from the table, the ULR-Flags are added in the authentication data request. The S&F flag may be or comprised in the ULR-Flags. An example of the ULR-Flags according to some example embodiments of the present disclosure is shown below in Table 2. The ULR-Flags shown below is updated from the table of ULR-Flags as defined in 3GPP TS 29.272.Table 2: ULR-Flags
[0082] As can be seen from Table 2, the indication indicative of whether to request for provisioning of subscription information for the terminal device may be indicated by a bit named “S&F indication” in the ULR-Flags. This bit may indicate the HSS needs to provide evolved packet system (EPS) subscription along with authentication vectors.
[0083] In some example embodiments, the first apparatus 210 may in accordance with a determination that the first request for the terminal device is received in a store-and- forward mode, add the indication in the authentication data request. For example, the first apparatus 210 may choose to add or not add a S&F flag in the authentication data request based on whether S&F mode is implemented.
[0084] Referring back to FIG. 2 A, after receiving the authentication data request 2020, the second apparatus 220 determines whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request. As discussed above, the timestamp information indicates the reception time of the first request for the terminal device. Thus, the second apparatus 220 can understand when the “first contact” between the terminal device and the network is conducted, and decide, based on the timestamp information whether to reject the authentication data request.
[0085] In some example embodiments, the second apparatus 220 in accordance with presence of further timestamp information for the terminal device, may determine whether the timestamp information indicates a reception time earlier than a reception timeindicated in the further timestamp information. In accordance with a determination that the timestamp information indicates a reception time earlier than a reception time indicated in further timestamp information, the second apparatus 220 may determine that the authentication data request or the provisional update location request is to be rejected. In other words, the second apparatus 220 may check if the timestamp information in the authentication data request indicates the latest request for the terminal device, and reject the authentication data request if it is not the latest one.
[0086] Based on a determination of whether the authentication data request is to be rejected, the second apparatus 220 transmits to the first apparatus 210, an authentication data response 2050 to the authentication data request 2020. The authentication data response either comprises a rejection indication to the authentication data request or comprises at least authentication information for the terminal device.
[0087] In some example embodiments, if the S&F indication / flag is also comprised in the authentication data request, in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of requesting for provisioning of subscription information for the terminal device, the second apparatus 220 transmits, to the first apparatus 210, the authentication data response comprising both the authentication information and the subscription information for the terminal device. In some example embodiments, the subscription information for the terminal device may comprise evolved packet system (EPS) subscription.
[0088] In some example embodiments, in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of not requesting for provisioning of subscription information for the terminal device, the second apparatus 220 transmits, to the first apparatus 210, the authentication data response comprising the authentication information for the terminal device.
[0089] In other words, with the S&F indication / flag included in the authentication data request, the response to the authentication request may comprise subscription data as requested by the S&F indication / flag. An example of the authentication data response according to some example embodiments of the present disclosure is shown below in Table 3. The authentication data response shown below is updated from the table of authentication information answer as defined in 3 GPP TS 29.272.Table 3: Authentication Information Answer
[0090] As can be seen from Table 3, the authentication data response may comprise an information element (IE) named “Subscription-Data”. This Information Element may contain the complete subscription profile of the user. It may be present if success is reported, unless an explicit "skip subscriber data" indication was present in the request. For example, if S&F indication is set to a value indicating “skip subscriber data”, the authentication data response may not comprise the Subscription-Data IE.
[0091] In some example embodiments, the first apparatus 210 may in accordance with acquisition of both the authentication information and the subscription information for the terminal device, determine the validity of the subscription information. The first apparatus 210 may further in accordance with a determination that the subscription information is valid, perform an authentication procedure of the terminal device based on the authentication information. For example, the first apparatus 210 may proceed with the authentication procedure.
[0092] In some example embodiments, in accordance with a determination that the authentication data response comprises a rejection indication, the first apparatus 210 may determine that the first request for the terminal device is rejected.
[0093] Reference is now made to FIG. 2B, which illustrates a signaling chart of an example authentication procedure and an example location update procedure in accordance with some example embodiments of the present disclosure.
[0094] As illustrated in FIG. 2B, the first apparatus 210 further transmits, to the second apparatus 220, a provisional update location request for the terminal device, and the provisional update location request comprises the timestamp information. The timestamp information comprised in the update location request may be the same as the timestamp information comprised in the authentication data request. In some examples, the timestamp information may be the “Request Time” as defined in 3GPP TR 23.700-29.
[0095] At the other side, the second apparatus 220 may determine whether the provisional update location request is to be rejected based on the timestamp information comprised in the provisional update location request.
[0096] The second apparatus 220 transmits, to the first apparatus 210, a provisional update response to the provisional update location request based on a determination of whether the provisional update location request is to be rejected. The provisional update response may either comprises a rejection indication to the provisional update location request or comprising subscription information for the terminal device. The first apparatus 210 receives, from the second apparatus 220, the provisional update response to the provisional update location request.
[0097] Reference is now made to FIG. 2C, which illustrates a signaling chart of another example authentication procedure in accordance with some other example embodiments of the present disclosure.
[0098] As illustrated in FIG. 2C, the first apparatus 210 transmits to the second apparatus 220, the authentication data request comprising the timestamp information and an indication (e.g., S&F flag) indicative of whether to request for provisioning of subscription information for the terminal device. The first apparatus 220 receives the authentication data response comprising one of the following: a rejection indication to the authentication data request, the authentication information (e.g., authentication vector, or AV), or both the authentication information (e.g., AV) and the subscription information (e.g., EPS subscription) for the terminal device.
[0099] FIG. 3 illustrates a flowchart of an example process of responding to an authentication data request according to some example embodiments of the present disclosure. The example process may be implemented at the second apparatus 220 (e.g., HSS) and may be deemed as a detailed example of the process illustrated in FIG. 2A or FIG. 2C.
[0100] As illustrated in FIG. 3, at block 310, the second apparatus 220, e.g., HSS receives an authentication data request with timestamp information and a S&F flag. For example, the MME may include timestamp (when the attach request was received) and the S&F flag (explained below) in authentication request to HSS.
[0101] At block 320, the second apparatus 220, e.g., HSS, may validate if there is no location update request received after the time in the timestamp information, i.e., check if the timestamp in the authentication data request is the latest one. If yes, then at block 330, HSS may provide authentication vectors and EPS subscription information to MME. If no, at block 340, HSS may reject the authentication data request from the first apparatus 210,e g., MME.
[0102] FIG. 4 illustrates a flowchart of an example process of responding to an authentication data response according to some example embodiments of the present disclosure. The example process may be implemented at the first apparatus 210 (e.g., MME) and may be deemed as a detailed example of the process illustrated in FIG. 2A or FIG. 2C.
[0103] As illustrated in FIG. 4, at block 410, the first apparatus 210, e.g., the MME receives an authentication data response. At block 420, the MME may check if it gets successful authentication vectors and check the validity of EPS subscription data. If the subscription allows the UE to be serviceable, then at block 430, MME may initiate / proceed with the authentication procedure. If no, at block 440, MME may reject the attach procedure.
[0104] FIG. 5 illustrates a flowchart of another example process of responding to an authentication data request and an update location request according to some example embodiments of the present disclosure. The example process may be implemented at the second apparatus 220 (e.g., the HSS) and may be deemed as a detailed example of the process illustrated in FIG. 2A or FIG. 2B.
[0105] As illustrated in FIG. 5, at block 510, the second apparatus 220, e.g., HSS receives an authentication data request with timestamp and a provisional update location request with the timestamp. In other words, the MME may include the timestamp in the authentication request as well as provisional update location request.
[0106] At block 520, the HSS may check if another update location with a more recent timestamp (than the time indicated in timestamp information) is already received via some other access for the same UE, i.e., check the timestamp in the authentication data request to see if it is the latest one.
[0107] If yes, at block 530, the HSS may provide the authentication vectors to MME to proceed with the authentication procedure. If no, at block 540, the HSS will reject the authentication in a case that the time stamp received on the other access is more recent than the one received on the satellite access.
[0108] At block 550, if the HSS further receives a provisional update location request, the HSS may check the timestamp in the provisional update location request to see if itthe latest. If yes, at block 560, the HSS may provide the subscription data to MME, but keeps the update location context as provisional.
[0109] If no, at block 570, the HSS may also reject the update location request for the above reason based on time stamp comparison and indicate the failure to MME, so that MME, based on any rejection (auth or provisional update location), may reject the UE’s attach / TAU request.
[0110] Reference is now made to FIG. 6. FIG. 6 illustrates a signaling chart 600 of example S&F attach procedure involving multiple satellites according to some example embodiments of the present disclosure. The signaling chart 600 may be deemed as a detailed example of the signaling chart 200. In FIG. 6, the MME-T (MME in a terrestrial network) may be an example of the first apparatus 210 in FIG. 2 A and the HSS may be an example of the second apparatus 120 in FIG. 2.[OHl] As illustrated in FIG. 6, at step 1, a UE, camping on an E-UTRAN cell reads the related System Information Broadcast including whether supports S&F operation. If the UE is able to perform the S&F operation, it initiates the Attach procedure by the transmission, to the eNodeB, of an Attach Request (IMSI or old GUTI, Old GUTI type, last visited TAI (if available) and the S&F indication). The S&F indication in the Attach Request may be used to indicate MME-NT that the UE is trying to attach for S&F communication.
[0112] At step 2, the eNodeB (RAN-1) forwards the Attach Request message in a SIMMS control message (Initial UE message) towards MME -NT-1. In the case of satellite access for Cellular loT, the MME-NT- 1 may verify the UE location and determine whether the PLMN is allowed to operate at the UE location.
[0113] At step 3, if the MME-NT-1 is not in contact with the ground station when receiving a message in step2, MME-NT- 1 shall store the attach request message and, generate an interim GUTI if the UE has included S&F indication in attach request and send an new NAS clear text message towards UE asking to save the interim GUTI for future NAS transactions. MME shall also provide the validity time for this interim GUTI. (UE may send an ack for the same, not shown in the diagram).
[0114] At step 4, when MME-NT- 1 regains ground connectivity, it shall forward the attach request, IMSI along with the interim GUTI created for this request in step3 towardsMME-T. A UE having valid interim GUTI shall not reset the MM context.
[0115] If no UE context for the UE exists at the MME-T, and if the Attach Request (sent in step 1) was not integrity protected, or if the check of the integrity failed, then authentication and NAS security setup to activate integrity protection and NAS ciphering are carried out. The MME-T borrows the authentication vectors (AV) from HSS.
[0116] At step 5a, according to some example embodiments of the present disclosure, a MME-T initiates an authentication data request (Auth Req) with IMSI and timestamp information to the HSS. The timestamp information indicates a time when the attach request of UE is received.
[0117] At step 5b, according to some example embodiments of the present disclosure, the MME-T further initiates a provisional location update request to the HSS, the provisional location update request further includes the same timestamp information indicating the time when the attach request of the UE is received.
[0118] At step 5x, the HSS responds to the MME-T with an authentication data response (Auth Resp) including authentication information for UE, which may include authentication vectors or keys such as RAND, XRES, AUTN, KASME, and the like.
[0119] At step 5y, in response to the provisional location update request, the HSS responds to the MME-T with a provisional location update response. Subscription information related to the UE may be included in the provisional location update response.
[0120] At step 6, the MME-T, after getting the authentication information from the HSS, shall try to ascertain the next available satellite which can reach the UE next. When found, it shall create the Authentication NAS payload and forward it to a MME -NT -2 (the next available satellite to reach UE). The MME-T shall also provide the last known location of UE.
[0121] It is noted that the MME-T will need the information on next suitable satellite which can serve the UE in shortest possible time. This information can be provided within the PLMN, by a UE reachability Estimator (URE) (as presented in Solution #25), or from an external source.
[0122] At step 6, when the MME -NT -2 reaches the UE area, it will page the UE using either the IMSI or interim GUTI or both, or the UE can also reach out to the RAN when seeing the new cell and reattempt the attach procedure with the previously valid interimGUTI. In both cases, when the UE gets a radio resource control (RRC) connection, the MME-NT shall forward the stored (in step 6) Authentication Request message to the UE.
[0123] At step 7, the UE responds back with an authentication response towards the MME -NT -2, which MME -NT -2 shall store it till it regains ground connection.
[0124] At step 8, when the MME-NT-2 regains connectivity with the ground station, it shall forward the stored Authentication response from the UE to the MME-T. the MME- T validates the response.
[0125] At step 9, if the UE is authenticated by the MME-T successfully, the MME-T initiates security mode by selecting the next available satellite (as per NOTE 1) that can serve the UE next. When found, it shall relay the Security mode command to a MME -NT - 3 (shown as the MME-NT-1 in the diagram). The MME-NT-3 shall store the security mode command until it reaches the UE serving area. MME-T shall also provide the last known location of UE.
[0126] At step 10, when the MME -NT-3 reaches the UE serving area, it shall page the UE using the interim GUTI or IMSI or both, or the UE can also reach out to the RAN when seeing the new cell and reattempt the attach procedure with the previously valid interim GUTI. When the UE becomes connected, the MME -NT-3 will forward the stored security mode command message to UE.
[0127] At step 11, once the UE applies the security mode, it shall acknowledge the security mode command towards the MME-NT-3. The MME-NT-3 shall store it till it regains the ground connection again.
[0128] At step 12, when the MME-NT-3 regains ground connectivity, it relays the stored security mode ack message to the MME-T.
[0129] At step 13, after receiving the security mode ack from the MME-NT-3, the MME- T selects a Serving GW and allocates an EPS Bearer Identity for the Default Bearer associated with the UE. Then it sends a Create Session Request (IMSI, MSISDN, MME- T TEID for control plane, PDN GW address, PDN Address, APN) message to the selected Serving GW.
[0130] At step 14, the Serving GW creates a new entry in its EPS Bearer table and sends a Create Session Request (IMSI, MSISDN, APN, Serving GW Address for the user plane, Serving GW TEID of the user plane, Serving GW TEID of the control plane) message tothe PDN GW indicated by the PDN GW address received in the previous step, (not shown in this diagram and SGW+PGW are represented as SAE GW).
[0131] At step 15, when the create session is received from the SAE-GW, the MME-T shall store till it finds the next available satellite to serve the UE next. Once found, the MME-T shall send Attach accept along with Create session response information such as user plane address and TEID to a MME-NT-4. The MME-T shall also provide the last known location of UE.
[0132] At step 16, the MME -NT -4 shall store the message until it reaches the UE serving area again. When it reaches the UE serving area, it shall page the UE using the interim GUTI, IMSI or both. The UE can also connect on its own when it sees a new cell in a new satellite. In either case, when the UE comes to connected state, the MME -NT -4 shall forward the message to RAN and UE. The RAN will create its PDN resources based the user plane IP and TEID information. The UE shall receive the Attach Accept, new GUTI, along with the PDN information.
[0133] At step 17, the UE shall acknowledge by sending the Attach complete message to MME -NT -4. MME -NT -4 shall store it till it regains the ground connectivity.
[0134] At step 18, when the MME-NT-4 regains the ground connectivity, it shall forward the stored Attach complete message and uplink data if any to the MME-T.
[0135] At step 19, after receiving Attach Complete, the MME-T shall configure the PDN connection by sending a Modify bearer Request to SAE-GW by including RAN's tunnel ID and IP information, (not shown in the diagram).
[0136] Reference is further made to FIG. 7. FIG. 7 illustrates a signaling chart 700 of example S&F attach procedure involving multiple satellites according to some other example embodiments of the present disclosure. The signaling chart 700 may be deemed as a further detailed example of the signaling chart 200. In the example of FIG. 7, all the other steps are the same as or similar to those in the example of FIG. 6 except for steps 5a and 5b. Thus, the description of the other steps are omitted here for brevity.
[0137] In the signaling chart 700 of FIG. 7, at step 5a, according to some other example embodiments of the present disclosure, MME-T initiates an authentication data request (Auth Req) with IMSI, timestamp information as well as S&F indication to HSS. The timestamp information indicates a time when the attach request of UE is received. TheS&F indication indicates whether to request HSS for provisioning of subscription information for UE.
[0138] At step 5b, if the indication in the authentication data request indicates requesting for provisioning of subscription information for UE, HSS responds to MME-T with an authentication data response (Auth Resp) including both the authentication information and EPS subscription information for UE. In this way, through one round of signaling, MME-T may acquire from HSS both authentication and subscription information of UE for following subscription validation and authentication procedures.
[0139] FIG. 8 shows a flowchart of an example method 800 implemented at a first apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 800 will be described from the perspective of the first apparatus 210 in FIG. 2 A.
[0140] At block 810, the first apparatus 210 transmits, to a second apparatus (e.g., the second apparatus 220 in FIG. 2A), an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device.
[0141] At block 820, the first apparatus 210 receives, from the second apparatus, an authentication data response to the authentication data request, the authentication data response either comprising a rejection indication to the authentication data request or comprising authentication information for the terminal device.
[0142] In this way, the timestamp information related to the first request for the terminal device can be delivered in the authentication procedure in an early way, thereby reducing resources for processing the unnecessary authentication procedure.
[0143] In some example embodiments, the method 800 further comprises: transmitting, to the second apparatus, a provisional update location request for the terminal device, the provisional update location request comprising the timestamp information; and receiving, from the second apparatus, a provisional update response to the provisional update location request, the provisional update response either comprising a rejection indication to the provisional update location request or comprising subscription information for the terminal device.
[0144] In this way, with the timestamp information being also comprised in theprovisional update location request, the provisional update location request may rejected in an early way, thereby reducing resources for processing an unnecessary update location procedure. Moreover, with the same timestamp information in both the authentication data request and the provisional update location request, the two requests and / or related procedures may be managed / controlled / processed in a collaborative way.
[0145] In some example embodiments, transmitting the authentication data request comprises: transmitting, to the second apparatus, the authentication data request comprising the timestamp information and an indication indicative of whether to request for provisioning of subscription information for the terminal device; and receiving the authentication data response comprising one of the following: a rejection indication to the authentication data request, the authentication information, or both the authentication information and the subscription information for the terminal device.
[0146] In some example embodiments, the indication comprises a store and forward flag.
[0147] In some example embodiments, transmitting the authentication data request comprises: in accordance with a determination that the first request for the terminal device is received in a store-and-forward mode, adding the indication in the authentication data request.
[0148] In this way, with the indication being comprised in the authentication data request, the subscription information can be requested to be sent in the authentication data response, which may enable early processing the subscription information. Particularly, in the NTN S&F scenarios, early processing of the subscription information may bring more benefits because it may take a longer time for the update location request to actually arrive at the network.
[0149] In some example embodiments, the method 800 further comprises: in accordance with acquisition of both the authentication information and the subscription information for the terminal device, determining the validity of the subscription information; and in accordance with a determination that the subscription information is valid, performing an authentication procedure of the terminal device based on the authentication information. In this way, unnecessary processing of the authentication procedure may be reduced or avoided. For example, in a case where the authentication succeeds but the subscription validity check fails, the performing of the unnecessary authentication procedure can be avoided.
[0150] In some example embodiments, the method 800 further comprises: in accordance with a determination that the authentication data response or the provisional update response comprises a rejection indication, determining that the first request for the terminal device is rejected. In this way, either the authentication data response or the provisional update response comprises the rejection indication can prevent the processing of unnecessary procedures.
[0151] In some example embodiments, the first request comprises an attach request or a tracking area update request. The first apparatus may transmit, to the second apparatus, the authentication data request for the terminal device by: in response to receiving the attach request or the tracking area update request for the terminal device, transmitting the authentication data request for the terminal device to the second apparatus.
[0152] In some example embodiments, the first apparatus is or is comprised in a mobility management entity (MME), and the second apparatus is or is comprised in a home subscriber server (HSS).
[0153] In some example embodiments, at least one of the first apparatus or the second apparatus is in a Long Term Evolution (LTE) system.
[0154] FIG. 9 shows a flowchart of an example method 900 implemented at a second apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 900 will be described from the perspective of the second apparatus 220 in FIG. 2A.
[0155] At block 910, the second apparatus 220 receives, from a first apparatus (e.g., the first apparatus 210), an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device.
[0156] At block 920, the second apparatus 220 determines whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request.
[0157] At block 930, the second apparatus 220 transmits, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request orcomprising at least authentication information for the terminal device.
[0158] In this way, the timestamp information related to the first request for the terminal device can be delivered in the authentication procedure in an early way, thereby reducing resources for processing the unnecessary authentication procedure.
[0159] In some example embodiments, the method 900 further comprises: receiving, from the first apparatus, a provisional update location request for a terminal device, the provisional update location request comprising the timestamp information; determining whether the provisional update location request is to be rejected based on the timestamp information comprised in the provisional update location request; and transmitting, to the first apparatus, a provisional update response to the provisional update location request based on a determination of whether the provisional update location request is to be rejected, the provisional update response either comprising a rejection indication to the provisional update location request or comprising subscription information for the terminal device.
[0160] In this way, with the timestamp information being also comprised in the provisional update location request, the provisional update location request may rejected in an early way, thereby reducing resources for processing an unnecessary update location procedure. Moreover, with the same timestamp information in both the authentication data request and the provisional update location request, the two requests and / or related procedures may be managed / controlled / processed in a collaborative way.
[0161] In some example embodiments, the method 900 further comprises: in accordance with presence of further timestamp information for the terminal device, determining whether the timestamp information indicates a reception time earlier than a reception time indicated in the further timestamp information; and in accordance with a determination that the timestamp information indicates a reception time earlier than a reception time indicated in further timestamp information, determining that the authentication data request or the provisional update location request is to be rejected. In this way, processing of the latest requested procedure is performed, thereby saving resources of processing the unnecessary procedures.
[0162] In some example embodiments, receiving the authentication data request comprises: receiving, from the first apparatus, the authentication data request comprising the timestamp information and an indication indicative of whether to request forprovisioning of subscription information for the terminal device; in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of requesting for provisioning of subscription information for the terminal device, transmit, to the first apparatus, the authentication data response comprising both the authentication information and the subscription information for the terminal device; and in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of not requesting for provisioning of subscription information for the terminal device, transmit, to the first apparatus, the authentication data response comprising the authentication information for the terminal device. In some example embodiments, the indication comprises a store and forward flag.
[0163] In this way, with the indication being comprised in the authentication data request, the subscription information can be requested to be sent in the authentication data response, which may enable early processing the subscription information. Particularly, in the NTN S&F scenarios, early processing of the subscription information may bring more benefits because it may take a longer time for the update location request to actually arrive at the network.
[0164] In some example embodiments, the method 900 further comprises: in accordance with a determination that the authentication data request is to be rejected, transmitting, to the first apparatus, an authentication data response comprising a rejection indication to the authentication data request. In this way, the rejection of the authentication data request is informed.
[0165] In some example embodiments, the first request comprises an attach request or a tracking area update request.
[0166] In some example embodiments, the first apparatus is or is comprised in a mobility management entity (MME), and the second apparatus is or is comprised in a home subscriber server (HSS).
[0167] In some example embodiments, at least one of the first apparatus or the second apparatus is in a Long Term Evolution (LTE) system.
[0168] In some example embodiments, a first apparatus capable of performing any of the method 800 (for example, the first apparatus 210 in FIG. 2A) may comprise means for performing the respective operations of the method 800. The means may be implementedin any suitable form. For example, the means may be implemented in a circuitry or software module. The first apparatus may be implemented as or included in the first apparatus 210 in FIG. 2 A.
[0169] In some example embodiments, the first apparatus comprises means for transmitting, to a second apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; and means for receiving, from the second apparatus, an authentication data response to the authentication data request, the authentication data response either comprising a rejection indication to the authentication data request or comprising authentication information for the terminal device.
[0170] In some example embodiments, the first apparatus further comprises: means for transmitting, to the second apparatus, a provisional update location request for the terminal device, the provisional update location request comprising the timestamp information; and means for receiving, from the second apparatus, a provisional update response to the provisional update location request, the provisional update response either comprising a rejection indication to the provisional update location request or comprising subscription information for the terminal device.
[0171] In some example embodiments, the means for transmitting, to the second apparatus, the authentication data request comprises: means for transmitting, to the second apparatus, the authentication data request comprising the timestamp information and an indication indicative of whether to request for provisioning of subscription information for the terminal device; and means for receiving the authentication data response comprising one of the following: a rejection indication to the authentication data request, the authentication information, or both the authentication information and the subscription information for the terminal device.
[0172] In some example embodiments, the indication comprises a store and forward flag.
[0173] In some example embodiments, the means for transmitting, to the second apparatus, the authentication data request comprises: means for, in accordance with a determination that the first request for the terminal device is received in a store-and- forward mode, adding the indication in the authentication data request.
[0174] In some example embodiments, the first apparatus further comprises: means forin accordance with acquisition of both the authentication information and the subscription information for the terminal device, determining the validity of the subscription information; and means for in accordance with a determination that the subscription information is valid, performing an authentication procedure of the terminal device based on the authentication information.
[0175] In some example embodiments, the first apparatus further comprises: means for in accordance with a determination that the authentication data response or the provisional update response comprises a rejection indication, determining that the first request for the terminal device is rejected.
[0176] In some example embodiments, the first request comprises an attach request or a tracking area update request. The means for transmitting the authentication data request comprises means for transmitting , to the second apparatus, the authentication data request for the terminal device by: in response to receiving the attach request or the tracking area update request for the terminal device, transmitting the authentication data request for the terminal device to the second apparatus.
[0177] In some example embodiments, the first apparatus is or is comprised in a mobility management entity (MME), and the second apparatus is or is comprised in a home subscriber server (HSS).
[0178] In some example embodiments, at least one of the first apparatus or the second apparatus is in a Long Term Evolution (LTE) system.
[0179] In some example embodiments, a second apparatus capable of performing any of the method 900 (for example, the first apparatus 210 in FIG. 2 A) may comprise means for performing the respective operations of the method 900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The second apparatus may be implemented as or included in the first apparatus 210 in FIG. 2 A.
[0180] In some example embodiments, the second apparatus comprises means for receiving, from a first apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; means for determining whether the authentication data request is to be rejected based on the timestamp informationcomprised in the authentication data request; and means for transmitting, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request or comprising at least authentication information for the terminal device.
[0181] In some example embodiments, the second apparatus further comprises: means for receiving, from the first apparatus, a provisional update location request for a terminal device, the provisional update location request comprising the timestamp information; means for determining whether the provisional update location request is to be rejected based on the timestamp information comprised in the provisional update location request; and means for transmitting, to the first apparatus, a provisional update response to the provisional update location request based on a determination of whether the provisional update location request is to be rejected, the provisional update response either comprising a rejection indication to the provisional update location request or comprising subscription information for the terminal device.
[0182] In some example embodiments, the second apparatus further comprises: means for in accordance with presence of further timestamp information for the terminal device, determining whether the timestamp information indicates a reception time earlier than a reception time indicated in the further timestamp information; and means for in accordance with a determination that the timestamp information indicates a reception time earlier than a reception time indicated in further timestamp information, determining that the authentication data request or the provisional update location request is to be rejected.
[0183] In some example embodiments, the means for receiving, from the first apparatus, the authentication data request comprises: means for receiving, from the first apparatus, the authentication data request comprising the timestamp information and an indication indicative of whether to request for provisioning of subscription information for the terminal device; means for in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of requesting for provisioning of subscription information for the terminal device, transmit, to the first apparatus, the authentication data response comprising both the authentication information and the subscription information for the terminal device; and means for in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of not requesting for provisioning of subscription information for the terminaldevice, transmit, to the first apparatus, the authentication data response comprising the authentication information for the terminal device.
[0184] In some example embodiments, the indication comprises a store and forward flag.
[0185] In some example embodiments, the second apparatus further comprises: means for in accordance with a determination that the authentication data request is to be rejected, transmitting, to the first apparatus, an authentication data response comprising a rejection indication to the authentication data request.
[0186] In some example embodiments, the first request comprises an attach request or a tracking area update request.
[0187] In some example embodiments, the first apparatus is or is comprised in a mobility management entity (MME), and the second apparatus is or is comprised in a home subscriber server (HSS).
[0188] In some example embodiments, at least one of the first apparatus or the second apparatus is in a Long Term Evolution (LTE) system.
[0189] FIG. 10 is a simplified block diagram of a device 1000 that is suitable for implementing example embodiments of the present disclosure. The device 1000 may be provided to implement a communication device, for example, the terminal device 110 or the network device 120 as shown in FIG. 1. As shown, the device 1000 includes one or more processors 1010, one or more memories 1020 coupled to the processor 1010, and one or more communication modules 1040 coupled to the processor 1010.
[0190] The communication module 1040 is for bidirectional communications. The communication module 1040 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 1040 may include at least one antenna.
[0191] The processor 1010 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1000 may have multiple processors, such as an application specific integrated circuit chip that is slavedin time to a clock which synchronizes the main processor.
[0192] The memory 1020 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1024, an electrically programmable read only memory (EPROM), a flash memory, a hard disk, a compact disc (CD), a digital video disk (DVD), an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random-access memory (RAM) 1022 and other volatile memories that will not last in the power-down duration.
[0193] A computer program 1030 includes computer executable instructions that are executed by the associated processor 1010. The instructions of the program 1030 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 1030 may be stored in the memory, e.g., the ROM 1024. The processor 1010 may perform any suitable actions and processing by loading the program 1030 into the RAM 1022.
[0194] The example embodiments of the present disclosure may be implemented by means of the program 1030 so that the device 1000 may perform any process of the disclosure as discussed with reference to FIG. 2A to FIG. 9. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
[0195] In some example embodiments, the program 1030 may be tangibly contained in a computer readable medium which may be included in the device 1000 (such as in the memory 1020) or other storage devices that are accessible by the device 1000. The device 1000 may load the program 1030 from the computer readable medium to the RAM 1022 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0196] FIG. 11 shows an example of the computer readable medium 1100 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 1100 has the program 1030 stored thereon.
[0197] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0198] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non- transitory computer readable medium. The computer program product includes computerexecutable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0199] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0200] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrierinclude a signal, computer readable medium, and the like.
[0201] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0202] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0203] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
CLAIMS:
1. A first apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: transmit, to a second apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; and receive, from the second apparatus, an authentication data response to the authentication data request, the authentication data response either comprising a rejection indication to the authentication data request or comprising authentication information for the terminal device.
2. The first apparatus of claim 1, wherein the first apparatus is further caused to: transmit, to the second apparatus, a provisional update location request for the terminal device, the provisional update location request comprising the timestamp information; and receive, from the second apparatus, a provisional update response to the provisional update location request, the provisional update response either comprising a rejection indication to the provisional update location request or comprising subscription information for the terminal device.
3. The first apparatus of claim 1 or 2, wherein the first apparatus is caused to: transmit, to the second apparatus, the authentication data request comprising the timestamp information and an indication indicative of whether to request for provisioning of subscription information for the terminal device; and receive the authentication data response comprising one of the following: a rejection indication to the authentication data request, the authentication information, or both the authentication information and the subscription information for the terminal device.
4. The first apparatus of claim 3, wherein the indication comprises a store andforward flag.
5. The first apparatus of claim 3 or 4, wherein the first apparatus is further caused to: in accordance with a determination that the first request for the terminal device is received in a store-and-forward mode, add the indication in the authentication data request.
6. The first apparatus of any of claims 2 to 5, wherein the first apparatus is further caused to: in accordance with acquisition of both the authentication information and the subscription information for the terminal device, determine the validity of the subscription information; and in accordance with a determination that the subscription information is valid, perform an authentication procedure of the terminal device based on the authentication information.
7. The first apparatus of any of claims 1 to 6, wherein the first apparatus is further caused to: in accordance with a determination that the authentication data response or the provisional update response comprises a rejection indication, determine that the first request for the terminal device is rejected.
8. The first apparatus of any of claims 1 to 7, wherein the first request comprises an attach request or a tracking area update request, and wherein the first apparatus is caused to transmit, to the second apparatus, the authentication data request for the terminal device by: in response to receiving the attach request or the tracking area update request for the terminal device, transmitting the authentication data request for the terminal device to the second apparatus.
9. The first apparatus of any of claims 1 to 8, wherein the first apparatus is or is comprised in a mobility management entity (MME), and the second apparatus is or is comprised in a home subscriber server (HSS).4310. The first apparatus of any of claims 1 to 9, wherein at least one of the first apparatus or the second apparatus is in a Long Term Evolution (LTE) system.
11. A second apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus at least to: receive, from a first apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; determine whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request; and transmit, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request or comprising at least authentication information for the terminal device.
12. The second apparatus of claim 11, wherein the second apparatus is further caused to: receive, from the first apparatus, a provisional update location request for a terminal device, the provisional update location request comprising the timestamp information; determine whether the provisional update location request is to be rejected based on the timestamp information comprised in the provisional update location request; and transmit, to the first apparatus, a provisional update response to the provisional update location request based on a determination of whether the provisional update location request is to be rejected, the provisional update response either comprising a rejection indication to the provisional update location request or comprising subscription information for the terminal device.
13. The second apparatus of claim 11 or 12, wherein the second apparatus is caused to: in accordance with presence of further timestamp information for the terminaldevice, determine whether the timestamp information indicates a reception time earlier than a reception time indicated in the further timestamp information; and in accordance with a determination that the timestamp information indicates a reception time earlier than a reception time indicated in further timestamp information, determine that the authentication data request or the provisional update location request is to be rejected.
14. The second apparatus of any of claims 11 to 13, wherein the second apparatus is caused to: receive, from the first apparatus, the authentication data request comprising the timestamp information and an indication indicative of whether to request for provisioning of subscription information for the terminal device; in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of requesting for provisioning of subscription information for the terminal device, transmit, to the first apparatus, the authentication data response comprising both the authentication information and the subscription information for the terminal device; and in accordance with a determination that the authentication data request is to be accepted, and the indication indicative of not requesting for provisioning of subscription information for the terminal device, transmit, to the first apparatus, the authentication data response comprising the authentication information for the terminal device.
15. The second apparatus of claim 14, wherein the indication comprises a store and forward flag.
16. The second apparatus of any of claims 11 to 15, wherein the second apparatus is caused to: in accordance with a determination that the authentication data request is to be rejected, transmit, to the first apparatus, an authentication data response comprising a rejection indication to the authentication data request.
17. The second apparatus of any of claims 11 to 16, wherein the first request comprises an attach request or a tracking area update request.
18. The second apparatus of any of claims 11 to 17, wherein the first apparatus is or is comprised in a mobility management entity (MME), and the second apparatus is or is comprised in a home subscriber server (HSS).
19. The second apparatus of any of claims 11 to 18, wherein at least one of the first apparatus or the second apparatus is in a Long Term Evolution (LTE) system.
20. A method comprising: transmitting, by a first apparatus and to a second apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; and receiving, from the second apparatus, an authentication data response to the authentication data request, the authentication data response either comprising a rejection indication to the authentication data request or comprising authentication information for the terminal device.
21. A method comprising: receiving, by a second apparatus and from a first apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; determining whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request; and transmitting, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request or comprising at least authentication information for the terminal device.
22. A first apparatus comprising: means for transmitting, to a second apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; and means for receiving, from the second apparatus, an authentication data response tothe authentication data request, the authentication data response either comprising a rejection indication to the authentication data request or comprising authentication information for the terminal device.
23. A second apparatus comprising: means for receiving, from a first apparatus, an authentication data request for a terminal device, the authentication data request at least comprising timestamp information indicating a reception time of a first request for the terminal device; means for determining whether the authentication data request is to be rejected based on the timestamp information comprised in the authentication data request; and means for transmitting, to the first apparatus, an authentication data response to the authentication data request based on a determination of whether the authentication data request is to be rejected, the authentication data response either comprising a rejection indication to the authentication data request or comprising at least authentication information for the terminal device.
24. A computer readable medium comprising instructions stored thereon for causing an apparatus at least to perform the method of claim 20 or the method of claim 21.
Citation Information
Patent Citations
Privacy protection and extensible authentication protocol authentication and autorization in cellular networks
US20200068391A1