User equipment authentication and security in emerging cellular networks
By splitting AMF functionalities into CMF and RMF and utilizing SEAF for UE authentication, the solution addresses the inefficiencies in existing 5G systems, providing efficient and secure UE authentication and security in emerging 5G architectures.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2025-01-27
- Publication Date
- 2026-07-30
AI Technical Summary
The existing 5G system's Access and Mobility Management Function (AMF) manages too many functionalities, making it inappropriate for deployment close to the Radio Access Network (RAN), leading to frequent re-allocation in mobility scenarios, and there is a need for improved User Equipment (UE) authentication and security in alternative architectures where AMF functionalities are split into Connection Management Function (CMF) and Registration Management Function (RMF).
The proposed solution involves splitting AMF functionalities into CMF and RMF, with CMF or RMF acting as the Security Anchor Function (SEAF) to manage UE authentication and security, including steps for identifier exchange, authentication procedures, and security context establishment, utilizing Authentication Server Function (AUSF) and other network functions to ensure secure communication.
This approach enables efficient UE authentication and security in emerging 5G architectures by reducing frequent re-allocation and enhancing security management, ensuring robust communication and integrity protection in mobility scenarios.
Smart Images

Figure CN2025075524_30072026_PF_FP_ABST
Abstract
Description
USER EQUIPMENT AUTHENTICATION AND SECURITY IN EMERGING CELLULAR NETWORKSTECHNICAL FIELD
[0001] This disclosure is directed generally to digital wireless communications.BACKGROUND
[0002] Mobile telecommunication technologies are moving the world toward an increasingly connected and networked society. In comparison with the existing wireless networks, next generation systems and wireless communication techniques will need to support a much wider range of use-case characteristics and provide a more complex and sophisticated range of access requirements and flexibilities.
[0003] Long-Term Evolution (LTE) is a standard for wireless communication for mobile devices and data terminals developed by 3rd Generation Partnership Project (3GPP) . LTE Advanced (LTE-A) is a wireless communication standard that enhances the LTE standard. The 5th generation of wireless system, known as 5G, advances the LTE and LTE-A wireless standards and is committed to supporting higher data-rates, large number of connections, ultra-low latency, high reliability and other emerging business needs.SUMMARY
[0004] In existing 5G system, Access and Mobility Management Function (AMF) functionalities include both connection management (CM) functionalities and registration management (RM) functionalities. A consensus has been reached within the industry that the AMF is currently managing too many functionalities, which makes it inappropriate to deploy AMF close to service, e.g. close to the Radio Access Network (RAN) . If AMF were deployed close to RAN, it would be frequently re-allocated in mobility scenarios. Accordingly, there has been a proposal to split AMF functionalities into two network function (NFs) : the first being a Connection Management Function (CMF) , and the second being a Registration Management Function (RMF) . In this alternative architecture, the RMF, which manages RM state, does not have to be re-allocated frequently in the aforementioned mobility scenarios.
[0005] Embodiments of the disclosed technology are directed to methods and systems for User Equipment (UE) , e.g., mobile devices, authentication and security in the alternative architecture where AMF functionalities have been divided into CMF functionalities and RMF functionalities.
[0006] In an example aspect, a wireless communication method includes receiving, by a first network function from an authentication function, a first message that includes an identifier associated with a wireless device, and transmitting, to a second network function, a second message that includes the identifier. In some examples, the first network function is the CMF, whereas in other examples, the first network function is the RMF. In both sets of examples, the authentication function is an Authentication Server Function (AUSF) .
[0007] In another example aspect, the above-described methods are embodied in the form of processor-executable code and stored in a non-transitory computer-readable storage medium. The code included in the computer readable storage medium when executed by a processor, causes the processor to implement the methods described in this patent document.
[0008] In yet another example aspect, a device that is configured or operable to perform the above-described methods is disclosed.
[0009] The above and other aspects and their implementations are described in greater detail in the drawings, the descriptions, and the claims.
[0010] BRIEF DESCRIPTION OF THE DRAWING
[0011] FIG. 1 is block diagram of the existing 5G system architecture.
[0012] FIG. 2 shows an example Non-Access Stratum (NAS) protocol and NAS transport for messages between the UE and other network functions in the architecture of FIG. 1.
[0013] FIG. 3 is a block diagram showing an example of a network architecture with distinct Connection Management Function (CMF) and Registration Management Function (RMF) NFs.
[0014] FIG. 4 shows an example NAS protocol and NAS transport for messages between the UE and other network functions in the architecture of FIG. 3.
[0015] FIG. 5 is a timing diagram for UE authentication and security with CMF as Security Anchor Function (SEAF) .
[0016] FIG. 6 is a timing diagram for UE authentication and security with RMF as SEAF.
[0017] FIG. 7 shows a flowchart for an example wireless communication method.
[0018] FIG. 8 shows a block diagram of an example hardware platform that may be a part of a network device or a communication device.
[0019] FIG. 9 shows an example of wireless communication including a base station (BS) and user equipment (UE) based on some implementations of the disclosed technology.DETAILED DESCRIPTION
[0020] The example headings for the various sections below are used to facilitate the understanding of the disclosed subject matter and do not limit the scope of the claimed subject matter in any way. Accordingly, one or more features of one example section can be combined with one or more features of another example section. Furthermore, 5G terminology is used for the sake of clarity of explanation, but the techniques disclosed in the present document are not limited to 5G technology only, and may be used in wireless systems that implemented other protocols.
[0021] 1 Introduction and Evolving 5G System Architecture
[0022] 5G stands for the "fifth generation" of wireless network technology, representing a significant leap forward from its predecessors, such as 4G LTE. This advanced technology operates at higher frequencies, specifically in the millimeter-wave spectrum, which ranges from 24 GHz to 100 GHz. These higher frequencies enable 5G to offer substantially greater bandwidth and faster data transfer rates compared to earlier generations.
[0023] FIG. 1 is a block diagram of the existing 5G system architecture. As shown therein, the 5G system includes the following entities and network functions (NFs) :
[0024] –User Equipment (UE) .
[0025] –Radio Access Network (RAN) .
[0026] –Access and Mobility Management Function (AMF) . This NF includes functionalities such as UE Mobility Management, Reachability Management, Connection Management and Registration Management. The AMF terminates the RAN Control Plane (CP) interface N2 and NAS interface N1, NAS ciphering and integrity protection. It also distributes message to corresponding NFs via corresponding interfaces.
[0027] –Unified Data Management (UDM) . This NF manages the subscription profile for the UEs. The subscription data may be stored in the Unified Data Repository (UDR) . The subscription information includes access and mobility subscription data needed for UE registration and mobility management, slice selection subscription data needed for slice selection, Session Management Function (SMF) selection subscription data needed for SMF selection, and / or session management subscription data needed for Packet Data Unit (PDU) session establishment. Other NFs, e.g. AMF and SMF, retrieve subscription data from the UDM.
[0028] –Network Slice Selection Function (NSSF) . This NF supports selecting the set of Network Slice instances serving the UE; determining the Allowed Network Slice Selection Assistant Information (NSSAI ) and, if needed, the mapping to the Home Public Land Mobile Network (HPLMN) Single–NSSAIs (S-NSSAIs) ; determining the Configured NSSAI and, if needed, the mapping to the HPLMN S-NSSAIs; determining the AMF Set to be used to serve the UE, or, based on configuration, a list of candidate AMF (s) , possibly by querying the Network Repository Function (NRF) . In some embodiments, the NSSAI includes a list of network slice identifiers, e.g., Allowed NSSAI includes a list of allowed network slice identifiers.
[0029] –Session Management Function (SMF) . This NF supports session establishment, modification and release, UE IP address allocation &management, selection and control of user plane (UP) function, etc.
[0030] –User Plane Function (UPF) . This NF serves as an anchor point for intra- / inter-radio access technology (RAT) mobility and as the external PDU session point of interconnect to Data Network (DN) . The UPF also routes and forwards the data packet according to the indication from the SMF, and additionally buffers the downlink (DL) data when the UE is in idle mode.
[0031] –Policy Control Function (PCF) . This NF supports unified policy framework to govern network behavior. The PCF provides access management policy to AMF, or session management policy to SMF, or UE policy to the UE. The PCF can access the UDM to obtain the subscription information relevant for policy decisions.
[0032] –NAS Protocol for Mobility Management (NAS-MM) . This NF supports both registration management functionality and connection management functionality. It is also responsible of ciphering and integrity protection of NAS signaling. There are multiple cases of protocols between the UE and a core network function (excluding the AMF) that need to be transported over N1 via NAS-MM protocol, e.g., Session Management Signaling, SMS, UE Policy, LCS, and the like. FIG. 2 shows an example of the NAS protocol and Nas transport in the existing 5G system architecture (which was illustrated in FIG. 1) .
[0033] FIG. 3 is a block diagram of an alternative (or emerging) 5G architecture in which the AMF functionalities have been split into CMF functionalities and RMF functionalities. As shown therein, CMF terminates both N1 and N2 interface. Herein, CMF is responsible for ciphering and integrity protection of NAS signaling, and RMF is responsible for registration management. The corresponding NAS protocol and NAS transport for this CMF-RMF split architecture is shown in FIG. 4, wherein the NAS protocol functionality supports connection management functionality. Furthermore, it is also responsible of ciphering and integrity protection of NAS signaling. As further shown in FIG. 4, there are multiple protocols between the UE and a Core Network (CN) function (excluding the CMF) that need to be transported over N1 via NAS protocol, e.g., RM signaling to RMF, SM signaling to SMF, UE Policy to UE-PCF, LCS to LMF, and the like.
[0034] The 5G system also includes the Security Anchor Function (SEAF) , which is a 5G security feature that allows devices to be reauthenticated between networks without having to perform a full authentication process. SEAF acts as a middleman between a UE and its home network during the authentication process. The described embodiments are directed to UE authentication and security in two cases: (i) CMF serving as SEAF and (ii) RMF performing the functionalities of SEAF.
[0035] 2 Example Embodiments with CMF Performing as SEAF
[0036] In some embodiments, CMF serves as SEAF in accordance with the timing diagram shown in FIG. 5. The operations (or steps) described in FIG. 5 include:
[0037] Step 1. UE to CMF: The UE sends initial NAS message, e.g. initial registration request message to CMF. If the UE has no security context, the initial message only contains the cleartext Information Elements (IEs) , e.g., subscription identifier (e.g. Subscription Concealed Identifier (SUCI) or Globally Unique Temporary Identity (GUTI) ) , UE security capabilities, Key Set Identifier (KSI) , etc.
[0038] Step 2. CMF to Old CMF: Transmit the Ncmf_Communication_UEContextTransfer message, which includes the complete initial NAS message. If GUTI is included by UE and the serving CMF has changed, the CMF may invoke Ncmf_Communication_UEContextTransfer service operation on the old CMF (and which includes the complete initial NAS message, which may be integrity protected, as well as GUTI and Access Type) to request the UE's Subscription Permanent Identifier (SUPI) and UE Context.
[0039] Step 3. Old CMF to CMF: Response to Ncmf_Communication_UEContextTransfer is transmitted. Here, old CMF searches the data of the UE in the database and checks the integrity protection on the initial NAS message, e.g., a Registration Request message. The old CMF uses the NAS security context corresponding to the Access Type to perform the integrity check.
[0040] In some embodiments, if the UE is found and the integrity check succeeds, old CMF sends a response that includes an identifier (e.g., SUPI) and security context for the UE. If the CMF receives a response with a SUPI, it creates an entry and stores the security context that may have been received. In other embodiments, if the UE cannot be identified or the integrity check fails, then the old CMF sends a response indicating that the temporary identifier GUTI cannot be retrieved or indicating integrity check failure. Herein, if the CMF receives a response indicating that the UE could not be identified, it initiates the subscription identification procedure.
[0041] Subscription identification procedure
[0042] Step 4. CMF to UE: The CMF may determine to initiate identity request procedure by sending an identity request message to the UE to request the UE to send its SUCI.
[0043] Step 5. UE to CMF: The UE calculates a fresh SUCI from SUPI using the Home Network Public Key, and responds with Identity Response message that includes the newly calculated SUCI.
[0044] Authentication procedure
[0045] Step 6. CMF: CMF performs as SEAF, and determines to initiate authentication procedure. Herein, CMF selects an Authentication Server Function (AUSF) based on a local configuration or by invoking Nnrf_NFDiscovery_Request to NRF, e.g., using the SUPI.
[0046] Step 7. CMF to NRF: The Nnrf_NFDiscovery_Request message includes, for example, NFType as AUSF, SUPI / SUCI, AUSF Group Identifier that includes the UE's SUPI, Routing Indicator information that allows routing of network signaling with SUCI to an AUSF, Home Network Public Key Identifier that can be served by the AUSF instance, Home Network Identifier (e.g., Mobile Network Code (MNC) and Mobile Country Code (MCC) , realm) of SUCI / SUPI. In some embodiments, Home Network Public Key Identifier is provided when, for example, Routing Indicator is not enough to provide SUPI range granularity and Home Network Public Key Identifier should be provided together with Routing Indicator.
[0047] Step 8. NRF to CMF: The NRF sends Nnrf_NFDiscovery_Response message to the CMF. The response message includes the selected AUSF information for the SUPI / SUCI, and at least one of the addressing parameters (e.g., Fully Qualified Domain Name (FQDN) , IPv4 address, IPv6 address, etc. ) .
[0048] Step 9. CMF to AUSF: The CMF invokes the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message to the selected AUSF. The request message includes, for example, SUCI or SUPI, the serving network name, etc.
[0049] Step 10. AUSF: Upon request from CMF, the AUSF executes authentication of the UE. The AUSF selects a UDM based on a local configuration or information obtained from NRF based on an input UE identifier, e.g., SUPI or SUCI.
[0050] Step 11. AUSF to UDM: The AUSF sends Nudm_UEAuthentication_Get Request message to selected UDM to get the authentication data from UDM. The request message includes, for example, SUCI or SUPI, the serving network name, etc.
[0051] Step 12. UDM: Upon reception of the Nudm_UEAuthentication_Get Request, the UDM de-conceals SUCI to gain SUPI before UDM can process the request. Then based on SUPI, the UDM chooses the authentication method, e.g., Extensible Authentication Protocol–Authenticated Key Agreement (EAP-AKA') or 5G AKA.
[0052] Step 13. UDM to AUSF: The UDM returns Nudm_UEAuthentication_Get Response message to the AUSF. In case SUCI was included in the Nudm_UEAuthentication_Get Request, UDM will include the SUPI in the Nudm_UEAuthentication_Get Response after deconcealment of SUCI. The response message includes authentication related information, e.g., authentication and / or security keys, algorithms, etc.
[0053] Step 14. AUSF to CMF: The AUSF generates authentication-related information based on the authentication-related information received from UDM and then returns Nausf_UEAuthentication_Authenticate Response message to the CMF.
[0054] Step 15. CMF to UE: The CMF sends authentication request message to the UE. The request message includes authentication-related information that will be used by the UE. For example, the message includes the KSI that will be used by the UE and CMF to identify the KCMF and the security context that is created if the authentication is successful.
[0055] Step 16. UE to CMF: The UE returns authentication response message to the CMF.
[0056] Step 17. CMF to AUSF: Based on authentication information received from AUSF and UE, the CMF determines whether the authentication is successful or not from the serving network point of view. The CMF forwards the authentication related information received from UE to AUSF in a Nausf_UEAuthentication_Authenticate Request message to the AUSF.
[0057] Step 18. AUSF to CMF: The AUSF determines whether the authentication is successful or not from the home network point-of-view and indicates the result to the CMF in a Nausf_UEAuthentication_Authenticate Response message. If the authentication is successful, the AUSF provides relevant security related information including security context and KCMF to the CMF. If the CMF provided a SUCI to AUSF, the AUSF shall return the SUPI to CMF only after the authentication is successful. Upon successful authentication, the AUSF stores the KAUSF based on the home network operator's policy. Furthermore, AUSF also informs UDM about the authentication result.
[0058] Security procedure
[0059] Step 19. CMF: If the AUSF indicates that the authentication was successful from the home network point of view, then the CMF initiates a security mode command procedure with the UE, to take the newly generated security context into use. The CMF activates the integrity protection before sending the Security Mode Command message to the UE. The CMF activates uplink deciphering after sending the Security Mode Command message.
[0060] Step 20. CMF to UE: The CMF sends security mode command message to the UE. The message includes, for example, the replayed UE security capabilities, security context, integrity algorithm, ciphering algorithm, the KSI for identifying the KCMF, a flag requesting the UE to send the complete initial message in the Security Mode Complete message, etc.
[0061] Step 21. UE: Upon receiving the valid Security Mode Command message from the CMF, the UE shall consider the performed primary authentication as successful. Thereafter, the UE verifies the security mode command message, e.g., by determining the UE security capabilities sent by the CMF match the ones stored in the UE, it ensures that these were not modified by an attacker, and / or verifies the integrity protection using the indicated integrity algorithm and the integrity key. If the verification of the integrity of the Security Mode Command message is successful, the UE shall start integrity protection and ciphering and / or deciphering with the security context indicated by the CMF.
[0062] Step 22. UE to CMF: The UE sends the Security Mode Complete message to the CMF in response to a Security Mode Command message. The Security Mode Complete message is ciphered and integrity protected. The Security Mode Complete message includes the complete initial message.
[0063] Step 23. The CMF de-ciphers and checks the integrity protection on the Security Mode Complete message using the key and algorithm indicated in the Security Mode Command message. Downlink ciphering at the CMF with this security context starts after receiving the Security Mode Complete message. In some embodiments, the UE security context includes, for example, KSI, security key (s) , KCMF, UE security capabilities, integrity algorithm, and ciphering algorithm, and is stored in the CMF.
[0064] Step 24. CMF to RAN: The CMF initiates a Next Generation Application Protocol (NGAP) procedure to provide RAN with UE security context. RAN stores the security context and acknowledges to the CMF. The RAN uses the security context to protect the messages exchanged with the UE.
[0065] Step 25. CMF: The CMF performs RMF selection. After successful authentication and security procedure, if the CMF does not have RMF ID and RMF address for the UE identified by the UE identifier stored and there is no local configured RMF for the UE, the CMF selects a RMF by invoking Nnrf_NFDiscovery_Request service operation from the NRF to find a proper target RMF for the UE. In some embodiments, the request message includes NF type set to RMF. The request message may also include UE location and / or CMF service area and / or UE identifier (e.g., SUPI) . NRF replies Nnrf_NFDiscovery_Response with potential target RMF (s) .
[0066] Step 26. CMF to RMF: CMF forwards the registration request message from UE to selected RMF by invoking corresponding RMF service, e.g., Nrmf_UEregistration_request. In some embodiments, the request message includes SUPI. RMF uses SUPI for subsequent registration procedure processing, e.g., RMF selects UDM for the UE based on SUPI.
[0067] Step 27. RMF to CMF: Send response message, e.g., Nrmf_UEregistration_response.
[0068] Step 28. After handling of the initial message and possibly interactions with other network functions by RMF, the RMF sends response to the initial message to UE via CMF. This message is ciphered and integrity protected by CMF.
[0069] 3 Example Embodiments with RMF Performing as SEAF
[0070] In some embodiments, RMF serves as SEAF in accordance with the timing diagram shown in FIG. 6. The operations (or steps) described in FIG. 6 include:
[0071] Step 1. UE to CMF: The UE sends initial NAS message, e.g. initial registration request message to CMF. If the UE has no security context, the initial message only contains the cleartext Information Elements (IEs) , e.g., subscription identifier (e.g. Subscription Concealed Identifier (SUCI) or Globally Unique Temporary Identity (GUTI) ) , UE security capabilities, Key Set Identifier (KSI) , etc.
[0072] Step 2. CMF to Old CMF: Transmit the Ncmf_Communication_UEContextTransfer message, which includes the complete initial NAS message. If GUTI is included by UE and the serving CMF has changed, the CMF may invoke Ncmf_Communication_UEContextTransfer service operation on the old CMF (and which includes the complete initial NAS message, which may be integrity protected, as well as GUTI and Access Type) to request the UE's Subscription Permanent Identifier (SUPI) and UE Context.
[0073] Step 3. Old CMF to CMF: Response to Ncmf_Communication_UEContextTransfer is transmitted, and one of the following two options is available.
[0074] Option 1: CMF sends, to old CMF, a message that includes RMF information (e.g., RMF ID or RMF address) associated with the GUTI. In this case, CMF forwards the initial message to RMF and if RMF can handle the initial message, the RMF responds with a success indication, whereas if RMF cannot handle the initial message, the RMF responds with a failure indication. If RMF responses failure indication, CMF proceeds from step 4.
[0075] Option 2: Old CMF searches data associated with the UE in the database, and checks the integrity protection on the initial NAS message, e.g. the Registration Request message. The old CMF then uses the NAS security context corresponding to the Access Type to perform the integrity check.
[0076] In some embodiments, if the UE is found and the integrity check succeeds, old CMF sends a response that includes an identifier (e.g., SUPI) and security context for the UE. If the CMF receives a response with a SUPI, it creates an entry and stores the security context that may have been received. In other embodiments, if the UE cannot be identified or the integrity check fails, then the old CMF sends a response indicating that the temporary identifier GUTI cannot be retrieved or indicating integrity check failure. Herein, if the CMF receives a response indicating that the UE could not be identified, it initiates the subscription identification procedure.
[0077] Subscription identification procedure
[0078] Step 4. CMF to UE: The CMF may determine to initiate identity request procedure by sending an identity request message to the UE to request the UE to send its SUCI.
[0079] Step 5. UE to CMF: The UE calculates a fresh SUCI from SUPI using the Home Network Public Key, and responds with Identity Response message that includes the newly calculated SUCI.
[0080] Step 6. CMF: The CMF performs RMF selection. If the CMF does not have RMF ID and RMF address for the UE identified by the UE identifier stored and there is no local configured RMF for the UE, the CMF selects a RMF by invoking Nnrf_NFDiscovery_Request service operation from the NRF to find a proper target RMF for the UE. In some embodiments, the request message includes NF type set to RMF. The request message may also include UE location and / or CMF service area and / or UE identifier (e.g., SUPI, SUCI) . NRF replies Nnrf_NFDiscovery_Response with potential target RMF (s) .
[0081] Step 7. CMF to RMF: CMF sends the initial NAS message to selected RMF by invoking corresponding RMF service, e.g., Nrmf_UEregistration_request. In some embodiments, the request message further includes UE location.
[0082] Step 8. RMF to CMF: Send response message, e.g., Nrmf_UEregistration_response.
[0083] Authentication procedure
[0084] Step 9. RMF: RMF performs as SEAF and determines to initiate authentication procedure. Herein, RMF selects an AUSF based on a local configuration or by invoking Nnrf_NFDiscovery_Request to NRF, e.g., using the SUPI.
[0085] Step 10. RMF to NRF: The Nnrf_NFDiscovery_Request message includes, for example, NFType as AUSF, SUPI / SUCI, AUSF Group Identifier that includes the UE's SUPI, Routing Indicator information that allows routing of network signaling with SUCI to an AUSF, Home Network Public Key Identifier that can be served by the AUSF instance, Home Network Identifier (e.g., Mobile Network Code (MNC) and Mobile Country Code (MCC) , realm) of SUCI / SUPI. In some embodiments, Home Network Public Key Identifier is provided when, for example, Routing Indicator is not enough to provide SUPI range granularity and Home Network Public Key Identifier should be provided together with Routing Indicator.
[0086] Step 11. NRF to RMF: The NRF sends Nnrf_NFDiscovery_Response message to the RMF. The response message includes the selected AUSF information for the SUPI / SUCI, and at least one of the addressing parameters (e.g., Fully Qualified Domain Name (FQDN) , IPv4 address, IPv6 address, etc. ) .
[0087] Step 12. RMF to AUSF: The RMF invokes the Nausf_UEAuthentication service by sending a Nausf_UEAuthentication_Authenticate Request message to the selected AUSF. The request message includes, for example, SUCI or SUPI, the serving network name, etc.
[0088] Step 13. AUSF: Upon request from RMF, the AUSF executes authentication of the UE. The AUSF selects a UDM based on a local configuration or information obtained from NRF based on an input UE identifier, e.g., SUPI or SUCI.
[0089] Step 14. AUSF to UDM: The AUSF sends Nudm_UEAuthentication_Get Request message to selected UDM to get the authentication data from UDM. The request message includes, for example, SUCI or SUPI, the serving network name, etc.
[0090] Step 15. UDM: Upon reception of the Nudm_UEAuthentication_Get Request, the UDM de-conceals SUCI to gain SUPI before UDM can process the request. Then based on SUPI, the UDM chooses the authentication method, e.g., EAP-AKA'or 5G AKA.
[0091] Step 16. UDM to AUSF: The UDM returns Nudm_UEAuthentication_Get Response message to the AUSF. In case SUCI was included in the Nudm_UEAuthentication_Get Request, UDM will include the SUPI in the Nudm_UEAuthentication_Get Response after deconcealment of SUCI. The response message includes authentication related information, e.g., authentication and / or security keys, algorithms, etc.
[0092] Step 17. AUSF to RMF: The AUSF generates authentication-related information based on the authentication-related information received from UDM and then returns Nausf_UEAuthentication_Authenticate Response message to the RMF.
[0093] Step 18. RMF to UE: The RMF sends authentication request message to the UE via CMF. The request message includes authentication-related information that will be used by the UE. For example, the message includes the KSI that will be used by the UE and RMF to identify the KRMF and the security context that is created if the authentication is successful.
[0094] Step 19. UE to RMF: UE returns authentication response message to RMF via CMF.
[0095] Step 20. RMF to AUSF: Based on authentication information received from AUSF and UE, the RMF determines whether the authentication is successful or not from the serving network point of view. The RMF forwards the authentication related information received from UE to AUSF in a Nausf_UEAuthentication_Authenticate Request message to the AUSF.
[0096] Step 21. AUSF to RMF: The AUSF determines whether the authentication is successful or not from the home network point-of-view and indicates the result to the RMF in a Nausf_UEAuthentication_Authenticate Response message. If the authentication is successful, the AUSF provides relevant security related information including security context and KRMF to the RMF. If the RMF provided a SUCI to AUSF, the AUSF shall return the SUPI to RMF only after the authentication is successful. Upon successful authentication, the AUSF stores the KAUSF based on the home network operator's policy. Furthermore, AUSF also informs UDM about the authentication result.
[0097] Step 22. RMF: Perform RMF re-selection. RMF may perform RMF re-selection based on a local configuration or by invoking Nnrf_NFDiscovery_Request service operation from the NRF to find a proper target RMF for the UE. In some embodiments, the request message includes, for example, a UE identifier (e.g., SUPI) . NRF replies with Nnrf_NFDiscovery_Response message that includes target RMF information (e.g., RMF ID or RMF address) . RMF then sends target RMF ID and target RMF address to CMF. Additionally, in other embodiments, RMF sends the initial message received from CMF to target RMF and forwards the response from target RMF to CMF along with target RMF ID and target RMF address. In yet other embodiments, this step may be performed before step 31.
[0098] Step 23. RMF to CMF: RMF sends SUPI, authentication result, security related information, e.g. NAS security context, KSI, security key (s) , integrity algorithm, ciphering algorithm, UE security capabilities, etc. to CMF. Herein, CMF uses SUPI for subsequent registration procedure processing, e.g., CMF re-selects RMF for the UE based on SUPI as in step 24, or CMF sends initial message received from UE to RMF and uses SUPI to identify the UE as in step 31.
[0099] Step 24. CMF: The CMF performs RMF re-selection based on a local configuration or by invoking Nnrf_NFDiscovery_Request service operation from the NRF to find a proper target RMF. In some embodiments, the request message includes a UE identifier (e.g., SUPI) . NRF replies Nnrf_NFDiscovery_Response with target RMF information (e.g., RMF ID, RMF address) . CMF sends initial message to re-selected RMF and sends indication to the initial RMF that CMF has re-selected another RMF for the UE. In other embodiments, this step may be performed before step 31.
[0100] Security procedure
[0101] Step 25. CMF: If the RMF indicates that the authentication was successful from the home network point of view, then the CMF determines to initiate a security mode command procedure with the UE, to take the newly generated security context into use. The CMF activates the integrity protection before sending the Security Mode Command message to the UE. The CMF activates uplink deciphering after sending the Security Mode Command message.
[0102] Step 26. CMF to UE: The CMF sends security mode command message to the UE. The message includes, for example, the replayed UE security capabilities, security context, integrity algorithm, ciphering algorithm, the KSI for identifying the KCMF, a flag requesting the UE to send the complete initial message in the Security Mode Complete message, etc.
[0103] Step 27. UE: Upon receiving the valid Security Mode Command message from the CMF, the UE shall consider the performed primary authentication as successful. Thereafter, the UE verifies the security mode command message, e.g., by determining the UE security capabilities sent by the CMF match the ones stored in the UE, it ensures that these were not modified by an attacker, and / or verifies the integrity protection using the indicated integrity algorithm and the integrity key. If the verification of the integrity of the Security Mode Command message is successful, the UE shall start integrity protection and ciphering and / or deciphering with the security context indicated by the CMF.
[0104] Step 28. UE to CMF: The UE sends the Security Mode Complete message to the CMF in response to a Security Mode Command message. The Security Mode Complete message is ciphered and integrity protected. The Security Mode Complete message includes the complete initial message.
[0105] Step 29. CMF: The CMF de-ciphers and checks the integrity protection on the Security Mode Complete message using the key and algorithm indicated in the Security Mode Command message. Downlink ciphering at the CMF with this security context starts after receiving the Security Mode Complete message. In some embodiments, the UE security context includes, for example, KSI, security key (s) , KCMF, UE security capabilities, integrity algorithm, and ciphering algorithm, and is stored in the CMF.
[0106] Step 30. CMF to RAN: The CMF initiates an NGAP procedure to provide RAN with UE security context. RAN stores the security context and acknowledges to the CMF. The RAN uses the security context to protect the messages exchanged with the UE.
[0107] Step 31. CMF to RMF: CMF sends the de-ciphered and integrity checked initial message from UE to RMF by invoking corresponding RMF service, e.g., Nrmf_UEregistration_request. In some embodiments, the request message includes SUPI to identify the UE.
[0108] Step 32. After handling of the initial message, and other possible interactions with other network functions, the RMF sends a response to the initial message to UE via CMF. This message is ciphered and integrity protected by CMF.
[0109] 4 Additional Embodiments and Implementations
[0110] Embodiments of the disclosed technology are directed to CMF and RMF (operating as SEAF) providing functionalities that enable UE authentication and security in emerging system architectures where AMF functionality has been split into CMF and RMF functionalities.
[0111] In some embodiments, SEAF is configured to receives SUPI from AUSF and sends SUPI to another NF for registration procedure processing. In some examples, SEAF is CMF and another NF is RMF, e.g., step 26 in Section 2. In other examples, SEAF is RMF and another NF is CMF, e.g., step 23 in Section 3.
[0112] In some embodiments, CMF is configured to:
[0113] –Initiate authentication procedures including AUSF selection (e.g., steps 6-8 in Section 2) and invoke UE authentication service of AUSF (e.g., steps 9 and 14-18 in Section 2) ;
[0114] –Initiate a security mode command procedure, which includes sending a security mode command message to UE (e.g., steps 19-20 and 22-23 in Section 2, and steps 25-26 and 28-29 in Section 3) ;
[0115] –Send UE security context to RAN (e.g., step 24 in Section 2, step 30 in Section 3) ;
[0116] –Select RMF based on UE location and / or CMF service area and / or UE identifier (e.g., SUPI) (e.g., step 25 in Section 2 and step 6 in Section 3) ;
[0117] –Send SUPI to RMF (e.g., step 26 in Section 2) ;
[0118] –Re-select RMF based on SUPI (e.g., step 24 in Section 3) .
[0119] In some embodiments, RMF is configured to:
[0120] –Initiate authentication procedure including AUSF selection (e.g., steps 9-11 in Section 3) and invoke UE authentication service of AUSF (steps 12 and 17-21 in Section 3) ;
[0121] –Re-select RMF based on SUPI (e.g., step 22 in Section 3) ;
[0122] –Send SUPI, authentication result, and security related information to CMF (e.g., step 23 in Section 3) .
[0123] FIG. 7 shows a flowchart for an example wireless communication method 700. The method 700 includes, at operation 710, receiving, by a first network function from an authentication function, a first message comprising an identifier associated with a wireless device. Herein, the first network function performs the functionalities of Security Anchor Function (SEAF) . In some embodiments, the first network function is Connection Management Function (CMF) , whereas in other embodiments, the first network function is Registration Management Function (RMF) .
[0124] The method 700 includes, at operation 720, transmitting, to a second network function, a second message comprising the identifier. In some embodiments, the second network function is the RMF, whereas in other embodiments, the second network function is the CMF.
[0125] The described features can be implemented to further provide one or more of the following technical solutions:
[0126] S1. A wireless communication method, comprising: receiving, by a first network function from an authentication function, a first message comprising an identifier associated with a wireless device; and transmitting, to a second network function, a second message comprising the identifier.
[0127] S2. The method of solution S1, wherein the first network function comprises a Security Anchor Function (SEAF) and the authentication function comprises an Authentication Server Function (AUSF) , and wherein the identifier comprises a Subscription Permanent Identifier (SUPI) associated with the wireless device.
[0128] S3. The method of solution S1 or S2, further comprising: determining to initiate an authentication procedure; and selecting, prior to receiving the identifier, the authentication function.
[0129] S4. The method of solution S3, wherein the first network function comprises a Connection Management Function (CMF) and the second network function comprises a Registration Management Function (RMF) . Solution S4, where CMF performs as SEAF, is further discussed in Section 2.
[0130] S5. The method of solution S4, further comprising: initiating, subsequent to receiving the identifier, a security mode command procedure with the wireless device.
[0131] S6. The method of solution S4, further comprising: selecting the second network function for the wireless device by using the identifier to invoke a discovery operation from a network repository.
[0132] S7. The method of solution S6, wherein the network repository comprises a Network Repository Function (NRF) , and wherein the discovery operation comprises a discovery request service operation.
[0133] S8. The method of solution S4, wherein the second message is a registration request message for the wireless device, and wherein the second network function is configured, subsequent to receiving the registration request message, to: perform, based on the identifier, a registration procedure for the wireless device.
[0134] S9. The method of solution S8, wherein the registration request message comprises a registration request message.
[0135] S10. The method of any of solutions S6 to S9, further comprising: receiving, from the second network function, a response message.
[0136] S11. The method of solution S10, wherein the response message comprises a registration response message.
[0137] S12. The method of solution S3, wherein the first network function comprises a Registration Management Function (RMF) and the second network function comprises a Connection Management Function (CMF) . Solution S12, where RMF performs as SEAF, is further discussed in Section 3.
[0138] S13. The method of solution S12, wherein the second network function is configured to: select the first network function by using an input to invoke a discovery operation from a network repository, wherein the input comprises the identifier or a location of the wireless device.
[0139] S14. The method of solution S13, wherein the discovery operation comprises a discovery request service operation, and wherein the network repository comprises a Network Repository Function (NRF) .
[0140] S15. The method of solution S12, wherein the second network function is configured to: send, to the first network function, a request message comprising a location of the wireless device.
[0141] S16. The method of solution S15, further comprising: transmitting, to the second network function, a response message.
[0142] S17. The method of solution S16, wherein the request message comprises a registration request message and the response message comprises a registration response message.
[0143] S18. The method of solution S12, further comprising: re-selecting the first network function by using the identifier to invoke a discovery operation from a network repository.
[0144] S19. The method of solution S12, wherein the second network function is configured to: re-select the first network function for the wireless device by using the identifier to invoke a discovery operation from a network repository
[0145] S20. The method of solution S18 or S19, wherein the discovery operation comprises a discovery request service operation, and wherein the network repository comprises a Network Repository Function (NRF) .
[0146] S21. The method of solution S12, wherein the second message further comprises a result of the authentication procedure and security information.
[0147] S22. The method of solution S21, wherein the security information comprises at least one of a Non-Access Stratum (NAS) security context, a Key Set Identifier (KSI) , one or more security keys, an integrity algorithm, a ciphering algorithm, or security capabilities of the wireless device.
[0148] S23. An apparatus for wireless communication comprising one or more processors, configured to cause the apparatus to implement the method recited in one or more of solutions S1 to S22.
[0149] S24. A non-transitory computer readable program storage medium having code stored thereon, the code, when executed by one or more processors, causing the one or more processors to implement the method recited in one or more of solutions S1 to S22.
[0150] FIG. 8 shows a block diagram of an example hardware platform 800 that may be a part of a network device (e.g., base station) or a communication device (e.g., a user equipment (UE) ) . The hardware platform 800 includes at least one processor 810 and a memory 805 having instructions stored thereupon. The instructions upon execution by the processor 810 configure the hardware platform 800 to perform the operations described in FIGS. 5 to 7 and in the various embodiments described in this patent document. The transmitter 815 transmits or sends information or data to another device. For example, a network device transmitter can send a message to a user equipment. The receiver 820 receives information or data transmitted or sent by another device. For example, a user equipment can receive a message from a network device.
[0151] The implementations as discussed above will apply to a wireless communication. FIG. 9 shows an example of a wireless communication system (e.g., a 5G or NR cellular network) that includes a base station 920 and one or more user equipment (UE) 911, 912 and 913. In some embodiments, the UEs access the BS (e.g., the network) using a communication link to the network (sometimes called uplink direction, as depicted by dashed arrows 931, 932, 933) , which then enables subsequent communication (e.g., shown in the direction from the network to the UEs, sometimes called downlink direction, shown by arrows 941, 942, 943) from the BS to the UEs. In some embodiments, the BS send information to the UEs (sometimes called downlink direction, as depicted by arrows 941, 942, 943) , which then enables subsequent communication (e.g., shown in the direction from the UEs to the BS, sometimes called uplink direction, shown by dashed arrows 931, 932, 933) from the UEs to the BS. The UE may be, for example, a smartphone, a tablet, a mobile computer, a machine to machine (M2M) device, an Internet of Things (IoT) device, and so on.
[0152] Some of the embodiments described herein are described in the general context of methods or processes, which may be implemented in one embodiment by a computer program product, embodied in a computer-readable medium, including computer-executable instructions, such as program code, executed by computers in networked environments. A computer-readable medium may include removable and non-removable storage devices including, but not limited to, Read Only Memory (ROM) , Random Access Memory (RAM) , compact discs (CDs) , digital versatile discs (DVD) , etc. Therefore, the computer-readable media can include a non-transitory storage media. Generally, program modules may include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer-or processor-executable instructions, associated data structures, and program modules represent examples of program code for executing steps of the methods disclosed herein. The particular sequence of such executable instructions or associated data structures represents examples of corresponding acts for implementing the functions described in such steps or processes.
[0153] Some of the disclosed embodiments can be implemented as devices or modules using hardware circuits, software, or combinations thereof. For example, a hardware circuit implementation can include discrete analog and / or digital components that are, for example, integrated as part of a printed circuit board. Alternatively, or additionally, the disclosed components or modules can be implemented as an Application Specific Integrated Circuit (ASIC) and / or as a Field Programmable Gate Array (FPGA) device. Some implementations may additionally or alternatively include a digital signal processor (DSP) that is a specialized microprocessor with an architecture optimized for the operational needs of digital signal processing associated with the disclosed functionalities of this application. Similarly, the various components or sub-components within each module may be implemented in software, hardware or firmware. The connectivity between the modules and / or components within the modules may be provided using any one of the connectivity methods and media that is known in the art, including, but not limited to, communications over the Internet, wired, or wireless networks using the appropriate protocols.
[0154] While this patent document contains many specifics, these should not be construed as limitations on the scope of an invention that is claimed or of what may be claimed, but rather as descriptions of features specific to particular embodiments. Certain features that are described in this document in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a sub-combination or a variation of a sub-combination. Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. As used in this patent document, “or” is inclusive in its scope, e.g., (A or B) represents { (A) , (B) , (A+ B) } .
[0155] Only a few implementations and examples are described and other implementations, enhancements, and variations can be made based on the description and drawings herein.
Claims
1.A wireless communication method, comprising:receiving, by a first network function from an authentication function, a first message comprising an identifier associated with a wireless device; andtransmitting, to a second network function, a second message comprising the identifier.2.The method of claim 1, wherein the first network function comprises a Security Anchor Function (SEAF) and the authentication function comprises an Authentication Server Function (AUSF) , and wherein the identifier comprises a Subscription Permanent Identifier (SUPI) associated with the wireless device.3.The method of claim 1 or 2, further comprising:determining to initiate an authentication procedure; andselecting, prior to receiving the identifier, the authentication function.4.The method of claim 3, wherein the first network function comprises a Connection Management Function (CMF) and the second network function comprises a Registration Management Function (RMF) .5.The method of claim 4, further comprising:initiating, subsequent to receiving the identifier, a security mode command procedure with the wireless device.6.The method of claim 4, further comprising:selecting the second network function for the wireless device by using the identifier to invoke a discovery operation from a network repository.7.The method of claim 6, wherein the network repository comprises a Network Repository Function (NRF) , and wherein the discovery operation comprises a discovery request service operation.8.The method of claim 4, wherein the second message is a registration request message for the wireless device, and wherein the second network function is configured, subsequent to receiving the registration request message, to:perform, based on the identifier, a registration procedure for the wireless device.9.The method of claim 8, wherein the registration request message comprises a registration request message.10.The method of claim 9, further comprising:receiving, from the second network function, a response message.11.The method of claim 10, wherein the response message comprises a registration response message.12.The method of claim 3, wherein the first network function comprises a Registration Management Function (RMF) and the second network function comprises a Connection Management Function (CMF) .13.The method of claim 12, wherein the second network function is configured to:select the first network function by using an input to invoke a discovery operation from a network repository, wherein the input comprises the identifier or a location of the wireless device.14.The method of claim 13, wherein the discovery operation comprises a discovery request service operation, and wherein the network repository comprises a Network Repository Function (NRF) .15.The method of claim 12, wherein the second network function is configured to:send, to the first network function, a request message comprising a location of the wireless device.16.The method of claim 15, further comprising:transmitting, to the second network function, a response message.17.The method of claim 16, wherein the request message comprises a registration request message and the response message comprises a registration response message.18.The method of claim 12, further comprising:re-selecting the first network function by using the identifier to invoke a discovery operation from a network repository.19.The method of claim 12, wherein the second network function is configured to:re-select the first network function for the wireless device by using the identifier to invoke a discovery operation from a network repository.20.The method of claim 19, wherein the discovery operation comprises a discovery request service operation, and wherein the network repository comprises a Network Repository Function (NRF) .21.The method of claim 12, wherein the second message further comprises a result of the authentication procedure and security information.22.The method of claim 21, wherein the security information comprises at least one of a Non-Access Stratum (NAS) security context, a Key Set Identifier (KSI) , one or more security keys, an integrity algorithm, a ciphering algorithm, or security capabilities of the wireless device.23.An apparatus for wireless communication comprising one or more processors, configured to cause the apparatus to implement the method recited in one or more of claims 1 to 22.24.A non-transitory computer readable program storage medium having code stored thereon, the code, when executed by one or more processors, causing the one or more processors to implement the method recited in one or more of claims 1 to 22.