Apparatus, method, and computer program
Patent Information
- Application Number
- PCT/EP2026/052572
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-18
- Filing Date
- 2026-02-02
- Publication Date
- 2026-08-27
Smart Images

Figure EP2026052572_27082026_PF_FP_ABST
Abstract
Description
[0001] APPARATUS, METHOD, AND COMPUTER PROGRAM
[0002] Field of the disclosure
[0003] The present disclosure relates to techniques for authenticating an application in a communication system.
[0004] Background
[0005] A communication system can be seen as a facility that enables communication sessions between two or more entities such as communication devices, base stations (BSs) and / or other nodes by providing carriers between the various entities involved in the communications path.
[0006] The communication system may be a wireless communication system. Examples of wireless systems comprise public land mobile networks (PLMN) operating based on radio standards such as those provided by 3GPP, satellite-based communication systems and different wireless local networks, for example wireless local area networks (WLAN). The wireless systems can typically be divided into cells, and are therefore often referred to as cellular systems.
[0007] The communication system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. Examples of standard are 4G, 5G or 6G standards.
[0008] Summary
[0009] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to perform: receiving, from an authentication server function via an access and mobility management function, an application identifier identifying an application and configuration information; receiving, from the application, the application identifier and a request to access an application function; and determining whether at least one rule to trigger authentication of the application is met based on the configuration information.Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is met based on the configuration information; and wherein the at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: sending, to the authentication server function via the access and mobility management function, the application identifier and application data at least one of encrypted or integrity protected based on an application secret to perform authentication of the application at the authentication server function.
[0010] Generating the application secret based on the application identifier may comprise: generating the application secret based on the application identifier, an authentication server function key KAUSF and at least one key derivative function.
[0011] The apparatus may generate (i.e., derive) the authentication server function key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one key derivative function. The at least one of the cipher key CK or the integrity key IK may be derived by a universal subscriber module based on a long-term key K and at least one key derivative function.
[0012] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: receiving, from the authentication server function via the access and mobility management function, the application secret.
[0013] Receiving, from the application, the application identifier and the request to access the application function may comprise: receiving, from the application, the application identifier, an application token and the request to access an application function.
[0014] Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is met based on the configuration information; and wherein the at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: sending, to the authentication server function via the access and mobility management function, the application identifier and the application token to perform authentication of the application at the authentication server function.
[0015] Receiving, from the authentication server function via the access and mobility management function, the application identifier identifying the application and configuration information maycomprise: receiving, from the authentication server function via the access and mobility management function, the application identifier identifying the application and configuration information, an application token and an authentication resource locator.
[0016] Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is met based on the configuration information; and wherein the at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: sending, to the application function via the authentication resource locator, the application identifier and the application token to perform authentication of the application function at the application function.
[0017] Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is not met based on the configuration information; and wherein the at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: abstaining from sending, to the application function via the authentication resource locator, the application identifier and the application token to abstain from performing authentication of the application function at the application function.
[0018] The application token may be generated based on a random number, a key and at least one key derivative function.
[0019] The configuration information may comprise at least one of: an indication of whether to authenticate the application to access the application function; an indication of a data network; an indication of a slice; an indication of a radio access technology; an indication of a time period; an indication of an access type; or an indication of an apparatus.
[0020] The indication of the data network may comprise a data network name..
[0021] The indication of the slice may comprise single network slice selection assistance information.
[0022] The indication of the radio access technology may comprise 5G, 6G or Wifi.
[0023] The indication of the access type may comprise a cellular access type or a non-cellular access type.The indication of the apparatus may comprise a permanent equipment identifier.
[0024] Determining that the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the indication of whether authenticating the application is required to access the application function in the configuration information indicates that authenticating the application is required to access the application function; determining that the application attempts to use a data network matching the data network indicated in the configuration information; determining that the application attempts to use a slice matching the slice indicated in the configuration information; determining that the application attempts to use a radio access technology matching the radio access technology indicated in the configuration information; determining that the application attempts to access the application function within a time period matching the time period indicated in the configuration information; determining that the application attempts to use an access type matching the access type indicated in the configuration information; or determining that the apparatus matches the apparatus indicated in the configuration information.
[0025] The apparatus may comprise a mobile equipment.
[0026] The application and the mobile equipment may form a user equipment.
[0027] According to an aspect there is provided a method comprising: receiving, from an authentication server function via an access and mobility management function, an application identifier identifying an application and configuration information; receiving, from the application, the application identifier and a request to access an application function; and determining whether at least one rule to trigger authentication of the application is met based on the configuration information.
[0028] The method may be performed by an apparatus.
[0029] Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is met based on the configuration information; and wherein the method may comprise: sending, to the authentication server function via the access and mobility management function, the application identifier and application data at least one ofencrypted or integrity protected based on an application secret to perform authentication of the application at the authentication server function.
[0030] Generating the application secret based on the application identifier may comprise: generating the application secret based on the application identifier, an authentication server function key KAUSF and at least one key derivative function.
[0031] The apparatus may generate (i.e., derive) the authentication server function key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one key derivative function. The at least one of the cipher key CK or the integrity key IK may be derived by a universal subscriber module based on a long-term key K and at least one key derivative function.
[0032] The method may comprise: receiving, from the authentication server function via the access and mobility management function, the application secret.
[0033] Receiving, from the application, the application identifier and the request to access the application function may comprise: receiving, from the application, the application identifier, an application token and the request to access an application function.
[0034] Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is met based on the configuration information; and wherein the method may comprise: sending, to the authentication server function via the access and mobility management function, the application identifier and the application token to perform authentication of the application at the authentication server function.
[0035] Receiving, from the authentication server function via the access and mobility management function, the application identifier identifying the application and configuration information may comprise: receiving, from the authentication server function via the access and mobility management function, the application identifier identifying the application and configuration information, an application token and an authentication resource locator.
[0036] Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is met based on the configuration information; andwherein the method may comprise: sending, to the application function via the authentication resource locator, the application identifier and the application token to perform authentication of the application function at the application function.
[0037] Determining whether the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the at least one rule to trigger authentication of the application is not met based on the configuration information; and wherein the method may comprise: abstaining from sending, to the application function via the authentication resource locator, the application identifier and the application token to abstain from performing authentication of the application function at the application function.
[0038] The application token may be generated based on a random number, a key and at least one key derivative function.
[0039] The configuration information may comprise at least one of: an indication of whether to authenticate the application to access the application function; an indication of a data network; an indication of a slice; an indication of a radio access technology; an indication of a time period; an indication of an access type; or an indication of an apparatus.
[0040] The indication of the data network may comprise a data network name..
[0041] The indication of the slice may comprise single network slice selection assistance information.
[0042] The indication of the radio access technology may comprise 5G, 6G or Wifi.
[0043] The indication of the access type may comprise a cellular access type or a non-cellular access type.
[0044] The indication of the apparatus may comprise a permanent equipment identifier.
[0045] Determining that the at least one rule to trigger authentication of the application is met based on the configuration information may comprise: determining that the indication of whether authenticating the application is required to access the application function in the configuration information indicates that authenticating the application is required to access the application function; determining that the application attempts to use a data network matching the data network indicated in the configuration information; determining that the application attempts touse a slice matching the slice indicated in the configuration information; determining that the application attempts to use a radio access technology matching the radio access technology indicated in the configuration information; determining that the application attempts to access the application function within a time period matching the time period indicated in the configuration information; determining that the application attempts to use an access type matching the access type indicated in the configuration information; or determining that the apparatus matches the apparatus indicated in the configuration information.
[0046] The apparatus may comprise a mobile equipment.
[0047] The application and the mobile equipment may form a user equipment.
[0048] According to an aspect there is provided an apparatus comprising means for performing the steps of any of the above methods.
[0049] According to an aspect there is provided an apparatus comprising circuitry configured to perform the steps of any of the above methods.
[0050] According to an aspect there is provided a computer program comprising computer executable instructions which when run one or more processors perform the steps of any of the above methods.
[0051] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to perform: receiving, from an application function, an application identifier identifying an application; and sending, to a mobile equipment via an access and mobility management function, the application identifier and configuration information.
[0052] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: generating an application secret based on the application identifier; receiving, from the mobile equipment via the access and mobility management function, the application identifier and application data at least one of encrypted or integrity protected based on the application secret; and authenticating the application based on the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment and the application secret generated by the apparatus.Generating the application secret based on the application identifier may comprise: generating the application secret based on the application identifier, an authentication server function key KAUSF and at least one key derivative function.
[0053] The apparatus may generate (i.e., derive) the authentication server function key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one key derivative function. The at least one of the cipher key CK or the integrity key IK may be derived based on a long-term key K and at least one key derivative function.
[0054] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: sending, to an application function, the application secret.
[0055] Authenticating the application based on the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment and the application secret generated by the apparatus may comprise: performing at one of decryption or integrity protection verification of the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment; and determining that the application data matches expected application data.
[0056] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: generating an application token; receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application token; and authenticating the application based on the application token received from the mobile equipment and the application token generated by the apparatus.
[0057] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: sending, to the application function, the application token.
[0058] Authenticating the application based on the application token received from the mobile equipment and the application token generated by the apparatus may comprise: determining that the application token received from the mobile equipment matches the application token sent to the application function.Receiving, from the application function, the application identifier identifying the application may comprise: receiving, from the application function, the application identifier identifying the application, an application token and an authentication uniform resource locator; and wherein sending, to the mobile equipment via the access and mobility management function, the application identifier and configuration information may comprise: sending, to the mobile equipment via the access and mobility management function, the application identifier, configuration information the application token and the uniform resource locator.
[0059] Sending, to the mobile equipment via the access and mobility management function, the application identifier may comprise: sending, to the mobile equipment via the access and mobility management function, the application identifier and configuration information in a first non-access stratum packet; and wherein receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application data at least one of encrypted or integrity protected based on the application secret may comprise: receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application token in a second non-access stratum packet.
[0060] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: determining authorized services amongst services provided by the application; and sending, to the mobile equipment via the access and mobility management function, an indication of authorized services amongst services provided by the application.
[0061] The apparatus may store subscription information for the mobile equipment.
[0062] Determining authorized services amongst services provided by the application may comprise: determining authorized services amongst services provided by the application based on subscription information for the mobile equipment.
[0063] The apparatus may comprise an authentication server function.
[0064] According to an aspect there is provided a method comprising: receiving, from an application function, an application identifier identifying an application; and sending, to a mobile equipment via an access and mobility management function, the application identifier and configuration information.The method may be performed by an apparatus.
[0065] The method may comprise: generating an application secret based on the application identifier; receiving, from the mobile equipment via the access and mobility management function, the application identifier and application data at least one of encrypted or integrity protected based on the application secret; and authenticating the application based on the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment and the application secret generated by the apparatus.
[0066] Generating the application secret based on the application identifier may comprise: generating the application secret based on the application identifier, an authentication server function key KAUSF and at least one key derivative function.
[0067] The apparatus may generate (i.e., derive) the authentication server function key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one key derivative function. The at least one of the cipher key CK or the integrity key IK may be derived based on a long-term key K and at least one key derivative function.
[0068] The method may comprise: sending, to an application function, the application secret.
[0069] Authenticating the application based on the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment and the application secret generated by the apparatus may comprise: performing at one of decryption or integrity protection verification of the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment; and determining that the application data matches expected application data.
[0070] The method may comprise: generating an application token; receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application token; and authenticating the application based on the application token received from the mobile equipment and the application token generated by the apparatus.
[0071] The method may comprise: sending, to the application function, the application token.
[0072] Authenticating the application based on the application token received from the mobile equipment and the application token generated by the apparatus may comprise: determining that theapplication token received from the mobile equipment matches the application token sent to the application function.
[0073] Receiving, from the application function, the application identifier identifying the application may comprise: receiving, from the application function, the application identifier identifying the application, an application token and an authentication uniform resource locator; and wherein sending, to the mobile equipment via the access and mobility management function, the application identifier and configuration information may comprise: sending, to the mobile equipment via the access and mobility management function, the application identifier, configuration information the application token and the uniform resource locator.
[0074] Sending, to the mobile equipment via the access and mobility management function, the application identifier may comprise: sending, to the mobile equipment via the access and mobility management function, the application identifier and configuration information in a first non-access stratum packet; and wherein receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application data at least one of encrypted or integrity protected based on the application secret may comprise: receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application token in a second non-access stratum packet.
[0075] The method may comprise: determining authorized services amongst services provided by the application; and sending, to the mobile equipment via the access and mobility management function, an indication of authorized services amongst services provided by the application.
[0076] The apparatus may store subscription information for the mobile equipment.
[0077] Determining authorized services amongst services provided by the application may comprise: determining authorized services amongst services provided by the application based on subscription information for the mobile equipment.
[0078] The apparatus may comprise an authentication server function.
[0079] According to an aspect there is provided an apparatus comprising means for performing the steps of any of the above methods.According to an aspect there is provided an apparatus comprising circuitry configured to perform the steps of any of the above methods.
[0080] According to an aspect there is provided a computer program comprising computer executable instructions which when run one or more processors perform the steps of any of the above methods.
[0081] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to perform: sending, to an authentication server function, an application identifier identifying an application.
[0082] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: receiving, from the authentication server function, an application secret.
[0083] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: receiving, from the authentication server function, an application token.
[0084] Sending, to the authentication server function, the application identifier identifying the application may comprise: sending, to the authentication server function, the application identifier, an application token and an authentication uniform resource locator.
[0085] The at least one memory and the computer code may be configured, with the at least one processor, to cause the apparatus at least to perform: receiving, from a mobile equipment via the authentication uniform resource locator, the application identifier and the application token; and authenticating the application based on the application token sent to the authentication server function and the application token received from the mobile equipment.
[0086] Authenticating the application based on the application token sent to the authentication server function and the application token received from the mobile equipment may comprise: determining that the application token sent to the authentication server function matches the application token received from the mobile equipment.The apparatus may comprises an application function.
[0087] According to an aspect there is provided a method comprising: sending, to an authentication server function, an application identifier identifying an application.
[0088] The method may be performed by an apparatus.
[0089] The method may comprise: receiving, from the authentication server function, an application secret.
[0090] The method may comprise: receiving, from the authentication server function, an application token.
[0091] Sending, to the authentication server function, the application identifier identifying the application may comprise: sending, to the authentication server function, the application identifier, an application token and an authentication uniform resource locator.
[0092] The method may comprise: receiving, from a mobile equipment via the authentication uniform resource locator, the application identifier and the application token; and authenticating the application based on the application token sent to the authentication server function and the application token received from the mobile equipment.
[0093] Authenticating the application based on the application token sent to the authentication server function and the application token received from the mobile equipment may comprise: determining that the application token sent to the authentication server function matches the application token received from the mobile equipment.
[0094] According to an aspect there is provided an apparatus comprising means for performing the steps of any of the above methods.
[0095] According to an aspect there is provided an apparatus comprising circuitry configured to perform the steps of any of the above methods.According to an aspect there is provided a computer program comprising computer executable instructions which when run one or more processors perform the steps of any of the above methods.
[0096] According to an aspect, there is provided a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
[0097] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
[0098] According to an aspect, there is provided a non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods.
[0099] In the above, many different aspects have been described. It should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above.
[0100] Various other aspects are also described in the following detailed description and in the attached claims.
[0101] List of abbreviations
[0102] AAA: Authentication , Authorization and Accounting
[0103] AF: Application Function
[0104] AMF: Access and Mobility management Function
[0105] AS: Access Stratum
[0106] ALISF: Authentication Server Function
[0107] BS: Base Station
[0108] CN: Core Network
[0109] DNN: Data Network Name
[0110] gNB: gNodeB
[0111] HN: Home Network
[0112] ID: Identifier
[0113] IMEI: International Mobile Equipment Identifier
[0114] loT: Internet of Things
[0115] KDF: Key Derivative Function
[0116] MAC: Message Authentication CodeME: Mobile Equipment
[0117] MS: Mobile Station
[0118] MTC: Machine Type Communication
[0119] NAS: Non-Access Stratum
[0120] NEF: Network Exposure Function
[0121] NF: Network Function
[0122] PDU : Packet Data Unit
[0123] PEI: Permanent Equipment Identifier
[0124] RAM: Random Access Memory
[0125] (R)AN: (Radio) Access Network
[0126] ROM: Read Only Memory
[0127] SEAF : Security Anchor Function
[0128] SMF: Session Management Function
[0129] SN: Serving Network
[0130] S-NSSAI: Single Network Slice Selection Assistance Information
[0131] UDM: Unified Data Management
[0132] UE: User Equipment
[0133] UICC: Universal Integrated Circuit Card
[0134] USIM: Universal Subscriber Universal integrated circuit card
[0135] 4G: 4thGeneration
[0136] 5G: 5thGeneration
[0137] 6G: 6thGeneration
[0138] Brief Description of the Fioures
[0139] Embodiments will now be described, by way of example only, with reference to the accompanying Figures in which:
[0140] Fig. 1 shows a schematic representation of an example 5G communication system;
[0141] Fig. 2 shows a schematic representation of an example control apparatus;
[0142] Fig. 3 shows a schematic representation of an example user equipment;
[0143] Fig. 4a and Fig. 4b show a signaling diagram of a first example process for authenticating an application in a communication system;Fig. 5a and Fig. 5b show a signaling diagram of a second example process for authenticating an application in a communication system;
[0144] Fig. 6a and Fig. 6b show a signaling diagram of a third example process for authenticating an application in a communication system;
[0145] Fig. 7a and Fig. 7b show a signaling diagram of a fourth example process for authenticating an application in a communication system;
[0146] Fig. 8 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by a mobile equipment;
[0147] Fig. 9 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an authentication server function;
[0148] Fig. 10 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an application function;
[0149] Fig. 11 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by a mobile equipment;
[0150] Fig. 12 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an authentication server function;
[0151] Fig. 13 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an application function;
[0152] Fig. 14 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by a mobile equipment;
[0153] Fig. 15 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an authentication server function;
[0154] Fig. 16 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an application function; andFig. 17 shows a schematic representation of a non-volatile memory medium storing instructions which when executed by a processor allow a processor to perform one or more of the steps of the method of any of Fig. 8 to Fig. 16.
[0155] Detailed Description of the Figures
[0156] FIG. 1 shows a schematic representation of an example communication system. The communication system may comprise a 5G communication system.
[0157] It will be understood that although one or more aspects are discussed in the context of a 5G communication system, these aspects may be used with other communication systems, such as a 6G communication system. A 6G communication system may comprise some or all of the components of a 5G communication system.
[0158] The communication system may comprise a user equipment, a radio access network RAN, one or more core networks (CNs), an application vendor and an authentication, authorization and accounting (AAA) server. The application vendor may comprise an application function (AF).
[0159] The one or more CNs may comprise a serving network (SN) and a home network (HN).
[0160] The RAN may comprise one or more base stations (BSs). The one or more BSs may comprise one or more gNodeBs (gNBs). The gNodeBs may comprise one or more gNB distributed unit functions connected to one or more gNB centralized unit functions.
[0161] The SN may comprise one or more network functions (NFs). The one or more NFs may comprise an access and mobility management Network Function (AMF), a session management function (SMF) and a network exposure function (NEF). The MM NF may be an access and mobility management function (AMF).
[0162] The HN may comprise one or more network functions (NFs). The one or more NFs may comprise a unified data management (UDM), an authentication server function (AUSF) and a NEF.
[0163] Fig. 2 illustrates an example of a control apparatus 200 for controlling a function of the RAN, the SN or the HN as illustrated on Fig. 1. The control apparatus may comprise at least one random access memory (RAM) 211a, at least on read only memory (ROM) 211b, at least one processor212, 213 and an input / output interface 214. The at least one processor 212, 213 may be coupled to the RAM 211 a and the ROM 211b. The at least one processor 212, 213 may be configured to execute an appropriate software code 215. The software code 215 may for example allow to perform one or more steps to perform one or more of the present aspects. The software code 215 may be stored in the ROM 211b. The control apparatus 200 may be interconnected with another control apparatus 200 controlling another function of the RAN, the SN or the HN. In some embodiments, each function of RAN, the SN or the HN comprises a control apparatus 200. In alternative embodiments, two or more functions of the RAN, the SN or the HN may share a control apparatus.
[0164] Fig. 3 illustrates an example of a user equipment 300, such as the user equipment illustrated on Fig. 1 . The UE 300 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples comprise a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) device or any combinations of these or the like. The UE 300 may provide, for example, communication of data for carrying communications. The communications may be one or more of voice, electronic mail (email), text message, multimedia, data, machine data and so on.
[0165] The UE 300 may receive signals over an air or radio interface 307 via appropriate apparatus for receiving and may transmit signals via appropriate apparatus for transmitting radio signals. In Fig.
[0166] 3 transceiver apparatus is designated schematically by block 306. The transceiver apparatus 306 may be provided for example by means of a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device.
[0167] The UE 300 may be provided with at least one processor 301 , at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access systems and other communication devices. The at least one processor 301 is coupled to the RAM 302b and the ROM 302a. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more of the present aspects. The software code 308 may be stored in the ROM 302a.The processor, storage and other relevant control apparatus can be provided on an appropriate circuit board and / or in chipsets. This feature is denoted by reference 304. The device may optionally have a user interface such as keypad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of the device.
[0168] One or more aspect of this disclosure relates to authenticating an application in a communication system.
[0169] Fig. 4a and Fig. 4b show a signaling diagram of a first example process for authenticating an application in a communication system. The first example process may involve a LIE, an AMF (not illustrated), an AUSF, a UDM, a NEF (not illustrated) and an application vendor. The application vendor may comprise an AF (e.g., non 3GPP external entity). The UE may comprise an application and a mobile equipment (ME). The application may be installed and / or run on the ME.
[0170] At step 0, the ME may communicate with the AUSF via the AMF. The AUSF may authenticate the UE.
[0171] At step 1a, the AUSF may receive, from the application vendor via the NEF, an application identifier identifying the application (e.g., for provisioning in UDM).
[0172] At step 1b, the AUSF may generate (e.g., derive) an application secret based on the application identifier. The AUSF may generate the application secret based on the application identifier, an AUSF key KAUSF and at least one key derivative function (KDF).
[0173] The AUSF may generate (e.g. derive) the AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) based on a long-term key K and at least one KDF.
[0174] The AUSF may generate (e.g. derive) a security anchor function (SEAF) key KSEAF based on the AUSF key KAUSF and at least one KDF. The AUSF may send the SEAF key KSEAF to the SEAF.
[0175] The SEAF may generate (e.g. derive) an AMF key KAMF based on the SEAF key KSEAF and at least one KDF. The SEAF may send the AMF key KAMF to the AMF.The AMF may generate (e.g. derive) a non-access stratum (NAS) key KNASenc for encryption and / or a NAS key KNASint for integrity protection based on the AMF key KAMF and at least one KDF.
[0176] The AUSF and / or the UDM may store the application identifier, the application secret and subscription information and / or configuration information at the AUSF and / or the UDM.
[0177] At step 1 c, the AUSF may send, to the application vendor via the NEF, the application secret. The application vendor may store the application secret.
[0178] At step 2, the AUSF may send, to the ME via the AMF, the application identifier and the configuration information. The AUSF may send, to the ME via the AMF, the application identifier and the configuration information in an encrypted and / or integrity protected NAS packet. The encrypted and / or integrity protected NAS packet may be encrypted and / or integrity based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0179] The configuration information may comprise an indication of whether to authenticate the application to access the application vendor, an indication of a data network, an indication of a slice, an indication of a radio access technology, an indication of an access type, an indication of a time period and / or an indication of a UE.
[0180] The indication of whether to authenticate the application to access the application vendor may comprise a flag. The flag may be set to ‘true’ to indicate that authenticating the application is required to access the application vendor. The flag may be set to ‘false’ to indicate to indicate that authenticating the application is not required to access the application vendor.
[0181] The indication of the data network may comprise a data network name (DNN).
[0182] The indication of the slice may comprise single network slice selection assistance information (S-NSSAI).
[0183] The indication of the radio access technology may comprise 5G, 6G or Wifi.
[0184] The indication of the access type may comprise a cellular access type or a non-cellular access type.The indication of the time period may comprise a start time and / or an end time.
[0185] The indication of the apparatus may comprise a permanent equipment identifier (PEI). The PEI may comprise an international mobile equipment identity (IME I) .
[0186] The ME, like the AUSF, may generate (e.g. derive) the AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) by a universal subscriber module (USIM) based on a long-term key K and at least one KDF.
[0187] The ME may generate (e.g. derive) the SEAF key KSEAF based on the AUSF key KAUSF and at least one KDF.
[0188] The ME may generate (e.g. derive) the AMF key KAMF based on the SEAF key KSEAF and at least one KDF.
[0189] The ME may generate (e.g. derive) the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection based on the AMF key KAMF and at least one KDF.
[0190] The ME may decrypt and / or verify the integrity protection of the NAS packet based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0191] The ME may store the application identifier and the configuration information.
[0192] At step 3a, the ME may receive, from the application, the application identifier and a request to access the application vendor.
[0193] At step 3b, the ME may generate (e.g., derive) the application secret based on the application ID. The AUSF may generate the application secret based on the application identifier, the AUSF key KAUSF and at least one KDF. Alternatively, the ME may receive, from the AUSF, the application secret. The ME may receive, from the AUSF, the application secret in the encrypted and / or integrity protected NAS packet at step 2.
[0194] At step 4, the ME may determine whether one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information. Here, the ME maydetermine that one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information.
[0195] In an implementation, the ME may determine that the indication of whether authenticating the application is required to access the application vendor in the configuration information indicates that authenticating the application is required to access the application vendor (e.g. flag set to ‘true’).
[0196] In an implementation, the ME may determine that the application attempts to use a data network matching the data network indicated in the configuration information.
[0197] In an implementation, the ME may determine that the application attempts to use a slice matching the slice indicated in the configuration information.
[0198] In an implementation, the ME may determine that the application attempts to use a radio access technology matching the radio access technology indicated in the configuration information.
[0199] In an implementation, the ME may determine that the application attempts to access the application vendor within a time period matching the time period indicated in the configuration information.
[0200] In an implementation, the ME may determine that the application attempts to use an access type matching the access type indicated in the configuration information.
[0201] In an implementation, the ME determine that the LIE matches the LIE indicated in the configuration information.
[0202] At step 5, the ME encrypt and / or integrity protect application data (e.g., application challenge) based on the application secret and at least one KDF.
[0203] The ME may send, to the AUSF via the AMF, the application identifier and the encrypted and / or integrity protected application data. The ME may send, to the AUSF via the AMF, the application identifier and the encrypted and / or integrity protected application data in an encrypted and / or integrity protected NAS message. The encrypted and / or integrity protected NAS packet may be encrypted and / or integrity based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.At step 6, the AUSF may decrypt and / or verify the integrity protection of the encrypted and / or integrity protected NAS message based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0204] At step 7a, the AUSF may decrypt and / or verify the integrity protection of the encrypted and / or integrity application data based on the application secret.
[0205] The AUSF may determine that the application data matches expected application data stored at the AUSF and / or the UDM. As a result, the AUSF may authenticate the application.
[0206] The AUSF may determine authorized services amongst the services provided by the application. The AUSF may determine authorized services amongst the services provided by the application based on the subscription information.
[0207] At step 7b, the AUSF may send, to the ME, an indication of a result of authentication (Auth result) and an indication of authorized services amongst the services provided by the application.
[0208] At step 7c, the ME may send, to the application, the indication of the result of authentication (Auth result) and the indication of authorized services amongst the services provided by the application.
[0209] Fig. 5a and Fig. 5b show a signaling diagram of a second example process for authenticating an application in a communication system. The second example process may involve a UE, an AMF (not illustrated), an AUSF, a UDM, a NEF (not illustrated) and an application vendor. The application vendor may comprise an AF (e.g., non 3GPP external entity). The UE may comprise an application and a ME. The application may be installed and / or run on the ME.
[0210] At step 0, the ME may communicate with the AUSF via the AMF. The AUSF may authenticate the UE.
[0211] At step 1a, the AUSF may receive, from the application vendor via the NEF, an application identifier identifying the application (e.g., for provisioning to the UDM).
[0212] At step 1b, the AUSF may generate (e.g., derive) an application token. The AUSF may generate the application token based on a random number. The AUSF may generate the application token based on the random number, a key Kand at least one KDF.The AUSF and / or the UDM may store the application identifier, the application token, subscription information and / or configuration information at the AUSF and / or the UDM.
[0213] The AUSF may generate (e.g. derive) an AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) based on a long-term key K and at least one KDF.
[0214] The AUSF may generate (e.g. derive) a SEAF key KSEAF based on the AUSF key KAUSF and at least one KDF. The AUSF may send the SEAF key KSEAF to the SEAF.
[0215] The SEAF may generate (e.g. derive) an AMF key KAMF based on the SEAF key KSEAF and at least one KDF. The SEAF may send the AMF key KAMF to the AMF.
[0216] The AMF may generate (e.g. derive) a NAS key KNASenc for encryption and / or a NAS key KNASint for integrity protection based on the AMF key KA F and at least one KDF.
[0217] At step 1c, the AUSF may send, to the application vendor via the NEF, the application token. The application vendor may store the application token.
[0218] At step 2a, the application vendor may send, to the application, the application identifier and the application token. The application vendor may send, to the application, the application identifier and the application token out of band. That is, the application vendor may not send, to the application, the application identifier and the application token via the NEF, the AUSF and the AMF (i.e., via 3GPP or cellular access type). The application vendor may send, to the application, the application identifier and the application token via the Internet (i.e., via non-3GPP or non-cellular access type). The application may store the application identifier and the application token.
[0219] At step 2b, the AUSF may send, to the ME via the AMF, the application identifier and the configuration information. The AUSF may send, to the ME via the AMF, the application identifier and the configuration information in an encrypted and / or integrity protected NAS packet. The encrypted and / or integrity protected NAS packet may be encrypted and / or integrity based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.The configuration information may comprise an indication of whether to authenticate the application to access the application vendor, an indication of a data network, an indication of a slice, an indication of a radio access technology, an indication of an access type, an indication of a time period and / or an indication of a UE.
[0220] The indication of whether to authenticate the application to access the application vendor may comprise a flag. The flag may be set to ‘true’ to indicate to indicate that authenticating the application is required to access the application vendor. The flag may be set to ‘false’ to indicate to indicate that authenticating the application is not required to access the application vendor.
[0221] The indication of the data network may comprise a DNN.
[0222] The indication of the slice may comprise S-NSSAI.
[0223] The indication of the radio access technology may comprise 5G, 6G or Wifi.
[0224] The indication of the access type may comprise a cellular access type or a non-cellular access type.
[0225] The indication of the time period may comprise a start time and / or an end time.
[0226] The indication of the apparatus may comprise a PEI.
[0227] The ME, like the AUSF, may generate (e.g. derive) the AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) by a universal subscriber module (USIM) based on a long-term key K and at least one KDF.
[0228] The ME may generate (e.g. derive) the SEAF key KSEAF based on the AUSF key KAUSF and at least one KDF.
[0229] The ME may generate (e.g. derive) the AMF key KAMF based on the SEAF key KSEAF and at least one KDF.
[0230] The ME may generate (e.g. derive) the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection based on the AMF key KAMF and at least one KDF.The ME may decrypt and / or verify the integrity protection of the NAS packet based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0231] The ME may store the application identifier and the configuration information.
[0232] At step 3a, the ME may receive, from the application, the application identifier, the application token and a request to access the application vendor.
[0233] At step 3b, the ME may determine whether one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information. Here, the ME may determine that one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information.
[0234] In an implementation, the ME may determine that the indication of whether authenticating the application is required to access the application vendor in the configuration information indicates that authenticating the application is required to access the application vendor (e.g. flag set to ‘true’).
[0235] In an implementation, the ME may determine that the application attempts to use a data network matching the data network indicated in the configuration information.
[0236] In an implementation, the ME may determine that the application attempts to use a slice matching the slice indicated in the configuration information.
[0237] In an implementation, the ME may determine that the application attempts to use a radio access technology matching the radio access technology indicated in the configuration information.
[0238] In an implementation, the ME may determine that the application attempts to access the application vendor within a time period matching the time period indicated in the configuration information.
[0239] In an implementation, the ME may determine that the application attempts to use an access type matching the access type indicated in the configuration information.In an implementation, the ME determine that the LIE matches the LIE indicated in the configuration information.
[0240] At step 4a, the ME may send, to the AUSF via the AMF, the application identifier and the application token. The ME may send, to the AUSF via the AMF, the application identifier and the application token in an encrypted and / or integrity protected NAS message. The encrypted and / or integrity protected NAS packet may be encrypted and / or integrity based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0241] At step 5a, the AUSF may decrypt and / or verify the integrity protection of the encrypted and / or integrity protected NAS message based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0242] The AUSF may determine that the application token matches the application token generated at step 1b. As a result, the AUSF may authenticate the application.
[0243] The AUSF may determine authorized services amongst the services provided by the application. The AUSF may determine authorized services amongst the services provided by the application based on the subscription information.
[0244] At step 5b, the AUSF may send, to the ME, an indication of a result of authentication (Auth result) and an indication of authorized services amongst the services provided by the application.
[0245] At step 5c, the ME may send, to the application, the indication of the result of authentication (Auth result) and the indication of authorized services amongst the services provided by the application.
[0246] Fig. 6a and Fig. 6b show a signaling diagram of a third example process for authenticating an application in a communication system. The third example process may involve a UE, an AMF, an SMF, an AUSF, a UDM, a NEF (not illustrated), an application vendor and an AAA server. The application vendor may comprise an AF (e.g., non 3GPP external entity). The UE may comprise an application and a ME. The application may be installed and / or run on the ME.
[0247] At step 0, the ME may communicate with the AUSF via the AMF. The AUSF may authenticate the UE.At step 1a, the AUSF may receive, from the application vendor via the NEF, an application identifier identifying the application (e.g., for provisioning to the UDM).
[0248] At step 1b, the AUSF may generate (e.g., derive) an application token. The AUSF may generate the application token based on a random number. The AUSF may generate the application token based on the random number, a key Kand at least one KDF.
[0249] The AUSF and / or the UDM may store the application identifier, the application token, subscription information and / or configuration information at the AUSF and / or the UDM.
[0250] The AUSF may generate (e.g. derive) an AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) based on a long-term key K and at least one KDF.
[0251] The AUSF may generate (e.g. derive) a SEAF key KSEAF based on the AUSF key KAUSF and at least one KDF. The AUSF may send the SEAF key KSEAF to the SEAF.
[0252] The SEAF may generate (e.g. derive) an AMF key KAMF based on the SEAF key KSEAF and at least one KDF. The SEAF may send the AMF key KAMF to the AMF.
[0253] The AMF may generate (e.g. derive) a NAS key KNASenc for encryption and / or a NAS key KNASint for integrity protection based on the AMF key KA F and at least one KDF.
[0254] At step 1c, the AUSF may send, to the application vendor via the NEF, the application token.
[0255] At step 2a, the application vendor may send, to the application, the application identifier and the application token. The application vendor may send, to the application, the application identifier and the application token out of band. That is the application vendor may not send, to the application, the application identifier and the application token via the NEF, the AUSF and the AMF (i.e., via 3GPP or cellular access type). The application vendor may send, to the application, the application identifier and the application token via the Internet (i.e., via non-3GPP or non-cellular access type).
[0256] At step 2b, the AUSF may send, to the ME via the AMF, the application identifier, the configuration information and / or the subscription information. The AUSF may send, to the ME via the AMF, theapplication identifier, the configuration information and / or the subscription information in an encrypted and / or integrity protected NAS packet. The encrypted and / or integrity protected NAS packet may be encrypted and / or integrity based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0257] The configuration information may comprise an indication of whether to authenticate the application to access the application vendor, an indication of a data network, an indication of a slice, an indication of a radio access technology, an indication of an access type, an indication of a time period and / or an indication of a UE.
[0258] The indication of whether to authenticate the application to access the application vendor may comprise a flag. The flag may be set to ‘true’ to indicate to indicate that authenticating the application is required to access the application vendor. The flag may be set to ‘false’ to indicate to indicate that authenticating the application is not required to access the application vendor.
[0259] The indication of the data network may comprise a DNN.
[0260] The indication of the slice may comprise S-NSSAI.
[0261] The indication of the radio access technology may comprise 5G, 6G or Wifi.
[0262] The indication of the access type may comprise a cellular access type or a non-cellular access type.
[0263] The indication of the time period may comprise a start time and / or an end time.
[0264] The indication of the apparatus may comprise a PEI.
[0265] The ME, like the AUSF, may generate (e.g. derive) the AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) by a universal subscriber module (USIM) based on a long-term key K and at least one KDF.
[0266] The ME may generate (e.g. derive) the SEAF key KSEAF based on the AUSF key KAUSF and at least one KDF.The ME may generate (e.g. derive) the AMF key KAMF based on the SEAF key KSEAF and at least one KDF.
[0267] The ME may generate (e.g. derive) the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection based on the AMF key KAMF and at least one KDF.
[0268] The ME may decrypt and / or verify the integrity protection of the NAS packet based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0269] The ME may store the application identifier and the application token.
[0270] At step 2c, the application may store the application identifier. The AMF may store the application identifier, the application token and the subscription information.
[0271] The AUSF may send, to the SMF, the application identifier, the application token and the subscription information.
[0272] The SMF may store the application identifier, the application token and the subscription information.
[0273] At step 3a, the ME may receive, from the application, the application identifier, the application token and a request to access the application vendor.
[0274] At step 3b, the ME may determine whether one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information. Here, the ME may determine that one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information.
[0275] In an implementation, the ME may determine that the indication of whether authenticating the application is required to access the application vendor in the configuration information indicates that authenticating the application is required to access the application vendor (e.g. flag set to ‘true’).
[0276] In an implementation, the ME may determine that the application attempts to use a data network matching the data network indicated in the configuration information.In an implementation, the ME may determine that the application attempts to use a slice matching the slice indicated in the configuration information.
[0277] In an implementation, the ME may determine that the application attempts to use a radio access technology matching the radio access technology indicated in the configuration information.
[0278] In an implementation, the ME may determine that the application attempts to access the application vendor within a time period matching the time period indicated in the configuration information.
[0279] In an implementation, the ME may determine that the application attempts to use an access type matching the access type indicated in the configuration information.
[0280] In an implementation, the ME determine that the LIE matching the LIE indicated in the configuration information.
[0281] At step 4a, the ME may send, to the SMF via the AMF, the application identifier and the application token. The ME may send, to the AUSF via the AMF, the application identifier and the application token in an encrypted and / or integrity protected NAS message. The encrypted and / or integrity protected NAS packet may be encrypted and / or integrity based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0282] At step 4b, the SMF may decrypt and / or verify the integrity protection of the encrypted and / or integrity protected NAS message based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0283] The SMF may determine that the application token matches the application token generated at step 1 b and received at step 2c. As a result, the AUSF may authenticate the application.
[0284] The SMF may determine to trigger authentication of the application at the AAA server. The SMF may determine to trigger authentication of the application at the AAA server based the subscription information.
[0285] At step 4c, the SMF may trigger authentication of the application at the AAA server.At step 5b, the AUSF may determine authorized services amongst the services provided by the application. The AUSF may determine authorized services amongst the services provided by the application based on the subscription information.
[0286] At step 5c, the AUSF may send, to the ME, an indication of a result of authentication (Auth result) and an indication of authorized services amongst the services provided by the application.
[0287] The ME may send, to the application, the indication of the result of authentication (Auth result) and the indication of authorized services amongst the services provided by the application.
[0288] Fig. 7a and Fig. 7b show a signaling diagram of a fourth example process for authenticating an application in a communication system. The fourth example process may involve a UE, an AMF, an AUSF, a UDM, a NEF and an application vendor. The application vendor may comprise an AF (e.g., non 3GPP external entity). The UE may comprise an application and a ME. The application may be installed and / or run on the ME.
[0289] At step 0, the ME may communicate with the AUSF via the AMF. The AUSF may authenticate the UE.
[0290] At step 1a, the AUSF may receive, from the application vendor via the NEF, an application identifier identifying the application, configuration information, an application token and / or an authentication uniform resource locator (URL).
[0291] The configuration information may comprise an indication of whether to authenticate the application to access the application vendor, an indication of a data network, an indication of a slice, an indication of a radio access technology, an indication of an access type, an indication of a time period and / or an indication of a UE.
[0292] The indication of whether to authenticate the application to access the application vendor may comprise a flag. The flag may be set to ‘true’ to indicate to indicate that authenticating the application is required to access the application vendor. The flag may be set to ‘false’ to indicate to indicate that authenticating the application is not required to access the application vendor.
[0293] The indication of the data network may comprise a DNN.
[0294] The indication of the slice may comprise S-NSSAI.The indication of the radio access technology may comprise 5G, 6G or Wifi.
[0295] The indication of the access type may comprise a cellular access type or a non-cellular access type.
[0296] The indication of the time period may comprise a start time and / or an end time.
[0297] The indication of the apparatus may comprise a PEI.
[0298] At step 1b, the AUSF and / or the UDM may store the application identifier, the application token, the configuration information, authentication URL and / or subscription information at the AUSF and / or the UDM.
[0299] The AUSF may generate (e.g. derive) an AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) based on a long-term key K and at least one KDF.
[0300] The AUSF may generate (e.g. derive) a SEAF key KSEAF based on the AUSF key KAUSF and at least one KDF. The AUSF may send the SEAF key KSEAF to the SEAF.
[0301] The SEAF may generate (e.g. derive) an AMF key KAMF based on the SEAF key KSEAF and at least one KDF. The SEAF may send the AMF key KAMF to the AMF.
[0302] The AMF may generate (e.g. derive) a (NAS key KNASenc for encryption and / or a NAS key KNASint for integrity protection based on the AMF key KA F and at least one KDF.
[0303] At step 1 c, the AUSF may send, to the application vendor via the NEF, a confirmation of reception of the application identifier, the application token, the configuration information and / or authentication URL.
[0304] At step 2, the AUSF may send, to the ME via the AMF, the application identifier, the configuration information, the application token and / or the authentication URL. The AUSF may send, to the ME via the AMF, the application identifier, the configuration information, the application token and / or the authentication URL during a registration procedure or during a packet data unit (PDU)procedure. The ALISF may send, to the ME via the AMF, the application identifier, the configuration information, the application token and / or the authentication URL in an encrypted and / or integrity protected NAS packet. The encrypted and / or integrity protected NAS packet may be encrypted and / or integrity based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0305] The ME may decrypt and / or verify the integrity protection of the NAS packet based on the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection.
[0306] The ME, like the AUSF, may generate (e.g. derive) the AUSF key KAUSF based on at least one of a cipher key CK or an integrity key IK and at least one KDF. The at least one of the cipher key CK or the integrity key IK may be generated (e.g., derived) by a universal subscriber module (USIM) based on a long-term key K and at least one KDF.
[0307] The ME may generate (e.g. derive) the SEAF key KSEAF based on the AUSF key KAUSF and at least one KDF.
[0308] The ME may generate (e.g. derive) the AMF key KAMF based on the SEAF key KSEAF and at least one KDF.
[0309] The ME may generate (e.g. derive) the NAS key KNASenc for encryption and / or the NAS key KNASint for integrity protection based on the AMF key KAMF and at least one KDF.
[0310] At step 3a, the ME may receive, from the application, the application identifier and a request to access the application vendor.
[0311] At step 3b, the ME may determine whether one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information. Here, the ME may determine that one or more rules to trigger authentication of the application at the AUSF are met based on the configuration information.
[0312] In an implementation, the ME may determine that the indication of whether authenticating the application is required to access the application vendor in the configuration information indicates that authenticating the application is required to access the application vendor (e.g. flag set to ‘true’).In an implementation, the ME may determine that the application attempts to use a data network matching the data network indicated in the configuration information.
[0313] In an implementation, the ME may determine that the application attempts to use a slice matching the slice indicated in the configuration information.
[0314] In an implementation, the ME may determine that the application attempts to use a radio access technology matching the radio access technology indicated in the configuration information.
[0315] In an implementation, the ME may determine that the application attempts to access the application vendor within a time period matching the time period indicated in the configuration information.
[0316] In an implementation, the ME may determine that the application attempts to use an access type matching the access type indicated in the configuration information.
[0317] In an implementation, the ME determine that the LIE matches the LIE indicated in the configuration information.
[0318] At step 4, the ME may send, to the application vendor via the authentication vendor, the application identifier and the application token.
[0319] The application vendor may determine that the application token matches the application token sent at step 1a. As a result, the application vendor may authenticate the application.
[0320] Alternatively, the ME may determine that one or more rules to trigger authentication of the application at the AUSF are not met based on the configuration information (e.g., the indication of whether authentication of the application is required indicated that authentication of the application is not required).
[0321] The ME may not send, to the application vendor via the authentication vendor, the application identifier and the application token.
[0322] The application vendor may not determine that the application token matches the application token sent at step 1a. As a result, the application vendor may not authenticate the application.Fig. 8 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by a ME.
[0323] At step 800, the ME may receive, from an ALISF via an AMF, an application identifier identifying an application and configuration information.
[0324] At step 802, the ME may receive, from the application, the application identifier and a request to access an AF.
[0325] At step 804, the ME may determine whether at least one rule to trigger authentication of the application is met based on the configuration information.
[0326] Fig. 9 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an ALISF.
[0327] At step 900, the AUSF may receive, from an AF, an application identifier identifying an application.
[0328] At step 902, the AUSF may send, to a ME via an AMF, the application identifier and configuration information.
[0329] Fig. 10 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an AF (e.g., application vendor).
[0330] At step 1000, the AF send, to an AUSF, an application identifier identifying an application.
[0331] Fig. 11 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by a ME.
[0332] At step 1100, the ME may receive, from an AUSF via an AMF, an application identifier identifying an application and configuration information.
[0333] At step 1102, the ME may receive, from the application, the application identifier and a request to access an AF.At step 1104, the ME may determine that at least one rule to trigger authentication of the application is met based on the configuration information.
[0334] At step 1106, the ME may send, to the AUSF via the AMF, the application identifier and application data at least one of encrypted or integrity protected based on an application secret to perform authentication of the application at the AUSF.
[0335] Fig. 12 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an AUSF.
[0336] At step 1200, the AUSF may receive, from an AF, an application identifier identifying an application.
[0337] At step 1202, the AUSF may generate an application secret based on the application identifier.
[0338] At step 1204, the AUSF may send, to a ME via an AMF, the application identifier and configuration information.
[0339] At step 1206, the AUSF may receive, from the ME via the AMF, the application identifier and application data at least one of encrypted or integrity protected based on the application secret.
[0340] At step 1208, the AUSF may authenticate the application based on the application data at least one of encrypted or integrity protected based on the application secret received from the ME and the application secret generated by the AUSF.
[0341] Fig. 13 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an AF (e.g., application vendor).
[0342] At step 1300, the AF may send, to an AUSF, an application identifier identifying an application.
[0343] At step 1302, the AF may receive, from the AUSF, an application secret.
[0344] Fig. 14 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by a ME.At step 1400, the ME may receive, from an ALISF via an AMF, an application identifier identifying an application and configuration information.
[0345] At step 1402, the ME may receive, from the application, the application identifier, an application token and a request to access an application function.
[0346] At step 1404, the ME may determine that at least one rule to trigger authentication of the application is met based on the configuration information.
[0347] At step 1406, the ME may send, to the AUSF via the AMF, the application identifier and the application token to perform authentication of the application at the AUSF.
[0348] Fig. 15 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an AUSF.
[0349] At step 1500, the AUSF may receive, from an AF, an application identifier identifying an application.
[0350] At step 1502, the AUSF may generate an application token.
[0351] At step 1504, the AUSF may send, to a ME via an AMF, the application identifier and configuration information.
[0352] At step 1506, the AUSF may receive, from the ME via the AMF, the application identifier and the application token.
[0353] At step 1508, the AUSF may authenticate the application based on the application token received from the ME and the application token generated by the AUSF.
[0354] Fig. 16 shows a block diagram of a method for authenticating an application in a communication system, wherein the method is performed by an AF (e.g., application vendor).
[0355] At step 1600, the AF may send, to an AUSF, an application identifier identifying an application.
[0356] At step 1602, the AF may receive, from the authentication server function, an application token.Fig. 17 shows a schematic representation of non-volatile memory media 17000 storing instructions which when executed by a processor allow the processor to perform one or more of the steps of the method of any of Fig. 8 to Fig. 16.
[0357] It is noted that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.
[0358] The embodiments may thus vary within the scope of the attached claims. In general, some embodiments may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. For example, some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although embodiments are not limited thereto. While various embodiments may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0359] The embodiments may be implemented by computer software stored in a memory and executable by at least one data processor of the involved entities or by hardware, or by a combination of software and hardware. Further in this regard it should be noted that any procedures, e.g., as in any of Fig. 8 to Fig. 16, may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD.
[0360] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), gate level circuits and processors based on multi-core processor architecture, as non-limiting examples.Alternatively or additionally some embodiments may be implemented using circuitry. The circuitry may be configured to perform one or more of the functions and / or method steps previously described. That circuitry may be provided in the base station and / or in the communications device.
[0361] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[0362] (a) hardware-only circuit options (such as options in only analogue and / or digital circuitry); (b) combinations of hardware circuits and software, such as:
[0363] (i) a combination of analogue and / or digital hardware circuit(s) with software / firmware and
[0364] (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as the communications device or base station to perform the various functions previously described; and
[0365] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0366] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an option of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example integrated device.
[0367] The term “means” as used in the description and in the claims may refer to one or more individual elements configured to perform the corresponding recited functionality or functionalities, or it may refer to several elements that perform such functionality or functionalities. Furthermore, several functionalities recited in the claims may be performed by the same individual means or the same combination of means. For example, performing such functionality or functionalities may be caused in an apparatus by a processor that executes instructions stored in a memory of the apparatus.
[0368] The foregoing description has provided by way of exemplary and non-limiting examples a full and informative description of some embodiments However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description,when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings will still fall within the scope as defined in the appended claims.
Claims
42WE CLAIM:
1. An apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to perform:receiving, from an authentication server function via an access and mobility management function, an application identifier identifying an application and configuration information;receiving, from the application, the application identifier and a request to access an application function; anddetermining whether at least one rule to trigger authentication of the application is met based on the configuration information.
2. The apparatus of claim 1, wherein determining whether the at least one rule to trigger authentication of the application is met based on the configuration information comprises:determining that the at least one rule to trigger authentication of the application is met based on the configuration information; andwherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:sending, to the authentication server function via the access and mobility management function, the application identifier and application data at least one of encrypted or integrity protected based on an application secret to perform authentication of the application at the authentication server function.
3. The apparatus of claim 2, wherein generating the application secret based on the application identifier comprises:generating the application secret based on the application identifier, an authentication server function key KAUSF and at least one key derivative function.
4. The apparatus of claim 2, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:receiving, from the authentication server function via the access and mobility management function, the application secret.
5. The apparatus of claim 1 , wherein receiving, from the application, the application identifier and the request to access the application function comprises:43receiving, from the application, the application identifier, an application token and the request to access an application function.
6. The apparatus of claim 5, wherein determining whether the at least one rule to trigger authentication of the application is met based on the configuration information comprises:determining that the at least one rule to trigger authentication of the application is met based on the configuration information; andwherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:sending, to the authentication server function via the access and mobility management function, the application identifier and the application token to perform authentication of the application at the authentication server function.
7. The apparatus of claim 1 , wherein receiving, from the authentication server function via the access and mobility management function, the application identifier identifying the application and configuration information comprises:receiving, from the authentication server function via the access and mobility management function, the application identifier identifying the application and configuration information, an application token and an authentication resource locator.
8. The apparatus of claim 7, wherein determining whether the at least one rule to trigger authentication of the application is met based on the configuration information comprises:determining that the at least one rule to trigger authentication of the application is met based on the configuration information; andwherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:sending, to the application function via the authentication resource locator, the application identifier and the application token to perform authentication of the application function at the application function.
9. The apparatus of claim 7, wherein determining whether the at least one rule to trigger authentication of the application is met based on the configuration information comprises:determining that the at least one rule to trigger authentication of the application is not met based on the configuration information; andwherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:44abstaining from sending, to the application function via the authentication resource locator, the application identifier and the application token to abstain from performing authentication of the application function at the application function.
10. The apparatus of any of claims 5 to 9, wherein the application token is generated based on a random number, a key and at least one key derivative function.
11. The apparatus of claim 10, wherein the configuration information comprises at least one of:an indication of whether to authenticate the application to access the application function; an indication of a data network;an indication of a slice;an indication of a radio access technology;an indication of a time period;an indication of an access type; oran indication of an apparatus.
12. The apparatus of claim 11, wherein determining that the at least one rule to trigger authentication of the application is met based on the configuration information comprises:determining that the indication of whether authenticating the application is required to access the application function in the configuration information indicates that authenticating the application is required to access the application function;determining that the application attempts to use a data network matching the data network indicated in the configuration information;determining that the application attempts to use a slice matching the slice indicated in the configuration information;determining that the application attempts to use a radio access technology matching the radio access technology indicated in the configuration information;determining that the application attempts to access the application function within a time period matching the time period indicated in the configuration information;determining that the application attempts to use an access type matching the access type indicated in the configuration information; ordetermining that the apparatus matches the apparatus indicated in the configuration information.
13. The apparatus of any of claims 1 to 10, wherein the apparatus comprises a mobile equipment.
14. An apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to perform:receiving, from an application function, an application identifier identifying an application; andsending, to a mobile equipment via an access and mobility management function, the application identifier and configuration information.
15. The apparatus of claim 14, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform generating an application secret based on the application identifier;receiving, from the mobile equipment via the access and mobility management function, the application identifier and application data at least one of encrypted or integrity protected based on the application secret; andauthenticating the application based on the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment and the application secret generated by the apparatus.
16. The apparatus of claim 15, wherein generating the application secret based on the application identifier comprises:generating the application secret based on the application identifier, an authentication server function key KAUSF and at least one key derivative function.
17. The apparatus of claim 15 or claim 16, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:sending, to an application function, the application secret.
18. The apparatus of any of claims 15 to 17, wherein authenticating the application based on the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment and the application secret generated by the apparatus comprises:performing at one of decryption or integrity protection verification of the application data at least one of encrypted or integrity protected based on the application secret received from the mobile equipment; anddetermining that the application data matches expected application data.
19. The apparatus of claim 14, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:generating an application token;receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application token; andauthenticating the application based on the application token received from the mobile equipment and the application token generated by the apparatus.
20. The apparatus of claim 19, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:sending, to the application function, the application token.
21. The apparatus of claim 19 or claim 20, wherein authenticating the application based on the application token received from the mobile equipment and the application token generated by the apparatus comprises:determining that the application token received from the mobile equipment matches the application token sent to the application function.
22. The apparatus of claim 14, wherein receiving, from the application function, the application identifier identifying the application comprises:receiving, from the application function, the application identifier identifying the application, an application token and an authentication uniform resource locator; and wherein sending, to the mobile equipment via the access and mobility management function, the application identifier and configuration information comprises:sending, to the mobile equipment via the access and mobility management function, the application identifier, configuration information the application token and the uniform resource locator.
23. The apparatus of any of claims 14 to 22, wherein sending, to the mobile equipment via the access and mobility management function, the application identifier comprises:47sending, to the mobile equipment via the access and mobility management function, the application identifier and configuration information in a first non-access stratum packet; and wherein receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application data at least one of encrypted or integrity protected based on the application secret comprises:receiving, from the mobile equipment via the access and mobility management function, the application identifier and the application token in a second non-access stratum packet.
24. The apparatus of any of claims 14 to 23, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:determining authorized services amongst services provided by the application; and sending, to the mobile equipment via the access and mobility management function, an indication of authorized services amongst services provided by the application.
25. The apparatus of claim 24, wherein determining authorized services amongst services provided by the application comprises:determining authorized services amongst services provided by the application based on subscription information for the mobile equipment.
26. The apparatus of any of claims 14 to 25, wherein the apparatus comprises an authentication server function.
27. An apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to perform:sending, to an authentication server function, an application identifier identifying an application.
28. The apparatus of claim 27, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform receiving, from the authentication server function, an application secret.
29. The apparatus of claim 27, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform receiving, from the authentication server function, an application token.4830. The apparatus of claim 27, wherein sending, to the authentication server function, the application identifier identifying the application comprises:sending, to the authentication server function, the application identifier, an application token and an authentication uniform resource locator.
31. The apparatus of claim 30, wherein the at least one memory and the computer code are configured, with the at least one processor, to cause the apparatus at least to perform:receiving, from a mobile equipment via the authentication uniform resource locator, the application identifier and the application token; andauthenticating the application based on the application token sent to the authentication server function and the application token received from the mobile equipment.
32. The apparatus of claim 31 , wherein authenticating the application based on the application token sent to the authentication server function and the application token received from the mobile equipment comprises:determining that the application token sent to the authentication server function matches the application token received from the mobile equipment.
33. The apparatus of any of claims 27 to 32, wherein the apparatus comprises an application function.
34. A method comprising:receiving, from an authentication server function via an access and mobility management function, an application identifier identifying an application and configuration information;receiving, from the application, the application identifier and a request to access an application function; anddetermining whether at least one rule to trigger authentication of the application is met based on the configuration information.
35. A method comprising:receiving, from an application function, an application identifier identifying an application; andsending, to a mobile equipment via an access and mobility management function, the application identifier and configuration information.
36. A method comprising:sending, to an authentication server function, an application identifier identifying an application.
37. A computer program comprising computer executable instructions which when run one or more processors perform the methods of any of claims 34 to 36.