Apparatus, method and computer program for secure handover

WO2026189775A1PCT designated stage Publication Date: 2026-09-17NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/054079
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-10
Filing Date
2026-02-16
Publication Date
2026-09-17

Smart Images

  • Figure EP2026054079_17092026_PF_FP_ABST
    Figure EP2026054079_17092026_PF_FP_ABST
Patent Text Reader

Abstract

There is provided an apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform receiving an indication at a network function of a first network from an access node of the first network to initiate handover for a user equipment associated with the first network to a second network, providing an identifier of the user equipment and a temporary key to a home network, HN, in response to the providing, receiving authentication vectors from the HN, providing a handover command to the user equipment, the handover command comprising the received authentication vectors, receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful, verifying the received indication and providing an indication of the verification to the second network.
Need to check novelty before this filing date? Find Prior Art

Description

TITLEAPPARATUS, METHOD AND COMPUTER PROGRAMTECHNICAL FIELD

[0001] Various embodiments of this disclosure relate generally to methods, apparatus and computer programs, and in particular, but not exclusively, to 6G interworking mobility security with 5G and 4G.BACKGROUND

[0002] A communication system can be seen as a facility that enables communication sessions between two or more communication devices, or provides communication devices access to a network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.

[0003] A mobile or wireless communication network may operate in accordance with standard^), such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of mobile or wireless communication network that operate in accordance with 3GPP standards are generally referred to as 4G (4th Generation) networks, 5G (5th Generation) network, 5G-Advanced networks and 6G networks.SUMMARY

[0004] Some embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the various example embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure. For example, it should be appreciated that further aspects may be provided by the combination of any two or more of the various aspects described herein.

[0005] In a first aspect there is provided a method comprising receiving an indication at a network function of a first network from an access node of the first network to initiate handover for a user equipment associated with the first network to a second network, providing an identifier of the user equipment and a temporary key to a home network, HN, in response to the providing, receiving authentication vectors from the HN, providing a handover command to the user equipment, the handover com-mand comprising the received authentication vectors, receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful, verifying the received indication and providing an indication of the verification to the second network.

[0006] The network function of the first network may be a mobility management network function.

[0007] The second network may be a 4G network. The method may comprise comprising providing an indication of the verification to a mobility management entity of the second network.

[0008] The second network may be a 5G network. The method may comprise providing an indication of the verification to an access and mobility function of the second network.

[0009] The HN may comprise a unified data management function of the first network or a home subscriber service of the second network.

[0010] In a second aspect there is provided a method comprising receiving, at a user equipment associated with a first network, a handover command to a second network from a network function of a first network, the handover command comprising authentication vectors, performing an authentication procedure based on the received authentication vectors and providing an indication from the user equipment to an access node of the second network that authentication is successful.

[0011] The method may comprise initiating a non-access stratum and access stratum security mode procedure with a network function of the second network.

[0012] The second network may be a 4G network. The network function of the second network may comprise a mobility management entity of the second network.

[0013] The second network may be a 5G network. The network function of the second network may comprise an access and mobility function of the second network.

[0014] In a third aspect there is provided a method comprising receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful, providing an indication of the successful authentication to the first network, receiving an indication from the first network that the authentication has been verified and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.

[0015] The method may comprise initiating a non-access stratum and access stratum security mode procedure with the user equipment.

[0016] The second network may be a 4G network. The network function of the second network may comprise a mobility management entity of the second network.

[0017] The second network may be a 5G network. The network function of the second network may comprise an access and mobility function of the second network.

[0018] In a fourth aspect there is provided an apparatus comprising means for performing the method according to the first, second or third aspect.

[0019] In a fifth aspect there is provided an apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform a method according to the first, second or third aspect.

[0020] In a sixth aspect there is provided a non-transitory computer readable mediumcomprising instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the first, second or third aspect.

[0021] In a seventh aspect there is provided a computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the method according to the first, second or third aspect.

[0022] Some embodiments of the invention are defined in the dependent claims.

[0023] In the above, many different aspects have been described. As previously noted, it should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above (or otherwise in this disclosure).

[0024] Various other aspects are also described in the following detailed description and in the claims.BRIEF DESCRIPTION OF THE FIGURES

[0025] Some embodiments will be described, by way of non-limiting and illustrative example only, with reference to the figures, in which:

[0026] Fig. 1 shows an example of a communication network to which examples disclosed herein may be applied;

[0027] Fig. 2 shows an example signalling diagram of 5GS to EPS handover for singleregistration mode with N26 interface;

[0028] Fig. 3 shows an example signalling diagram of the preparation phase of EPS to 5GS handover using N26 interface;

[0029] Fig. 4 shows an example signalling diagram of the execution phase of EPS to 5GS handover for single-registration mode with N26 interface;

[0030] Fig. 5 shows a flowchart of a method according to an example embodiment;

[0031] Fig. 6 shows a flowchart of a method according to an example embodiment;

[0032] Fig. 7 shows a flowchart of a method according to an example embodiment;

[0033] Fig. 8 shows a signalling flow according to an example;

[0034] Fig. 9 shows a signalling flow according to an example;

[0035] Fig. 10 shows a flowchart of a method according to an example embodiment;

[0036] Fig. 11 shows a flowchart of a method according to an example embodiment;

[0037] Fig. 12 shows a signalling flow according to an example;

[0038] Fig. 13 shows a flowchart of a method according to an example embodiment;

[0039] Fig. 14 shows a flowchart of a method according to an example embodiment;

[0040] Fig. 15 shows a signalling flow according to an example;

[0041] Fig. 16 shows a flowchart of a method according to an example embodiment;

[0042] Fig. 17 shows a flowchart of a method according to an example embodiment;

[0043] Fig. 18 shows an example of an apparatus.DETAILED DESCRIPTION

[0044] The following embodiments are provided by way of non-limiting and illustrative example. Although the specification may refer to “an”, “one”, or “some” embodiment(s) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment(s), or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is described in connection of an embodiment, it intended such feature, structure, or characteristic may be applied in connection with other embodiments (whether or not explicitly described).

[0045] It shall be understood that although the terms “first,” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.

[0046] For the purposes of this disclosure, the phrases “at least one of A or B”, “at least one of A and B”, and “A and / or B” means (A), (B), or (A and B). For the purposes of this disclosure, the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).

[0047] As used herein, the term “or” refers to a non-exclusive “or” unless otherwise indicated (e.g., use of “or else” or “or in the alternative”).

[0048] As used herein, unless stated explicitly, performing a respective feature, step, or functionality “in response to A” does not indicate that the respective feature, step, or functionality is performed immediately after “A” occurs as one or more intervening features, steps, or functionalities may be performed (at least in part) between an occurrence of the respective feature, step, or function and “A”. Analogously, performing a respective feature, step, or functionality “based on A” does not indicate that the respective feature, step, or functionality is performed solely based on “A” as the respective feature, step, or functionality may be further based on one or more other features, steps, or functionalities in addition to “A”.

[0049] Embodiments described herein may be implemented in a communication network, such as any of the following radio access technologies (RATs): Worldwide Interoperability for Micro-wave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGE radio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W-CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, and enhanced LTE (eLTE), 5G (also called NR), or any future RAT such as 6G. Moreover, communication within the communication network may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), TimeDivision Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), and / or Discrete Fourier Transform spread OFDM (DFT-s-OFDM).

[0050] As used herein, the term “network device” or “network node” refers to a node in a communication network via which user equipment may access the network and / or which is configured to control radio communication and managing radio resources within a cell. The network node or network device may be referred to as a base station (BS), an access point (AP) or an access node. The network device may be, depending on the applied technology, for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node, a non-terrestrial network (NTN) or non-ground network device, such as a satellite network device, a low earth orbit (LEO) satellite, a medium earth orbit (MEO) and a geosynchronous earth orbit (GEO) satellite, or an aircraft network device.

[0051] Moreover, in connection of split radio access network (RAN), the network device may refer to a centralised unit (CU) of a base station and / or a distributed unit (DU) of a base station. An interface between CU and DU may be referred to as an F1 interface in NR. In the split RAN architecture, node operations may be carried out, at least partly, in the central / centralized unit, CU, (e.g. server, host or node) operationally coupled to the DU, (e.g. a radio head / node). One CU may control one or more DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some embodiments, the DUs may comprise e.g. a radio link control (RLC), medium access control (MAC) layer and a physical (PHY) layer, whereas the CU may comprise the layers above RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC) and an internet protocol (IP) layers. Other functional splits are possible too. In practice, any processing task may be performed in either the CU or the DU and the boundary where the responsibility is shifted between the CU and the DU may depend on the applied implementation.

[0052] The term “terminal device” refers to any end device that may be configured to perform wireless communication. By way of example, a terminal device may be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), or a Mobile Station (MS). The terminal device may include a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehiclemounted wireless terminal devices, USB dongles, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wirelessnetworks, and the like.

[0053] A term “resource”, as used herein, may refer to radio resources in time domain, in frequency domain, in space domain, and / or in code domain. Some examples of resources may include, e.g., a physical resource block (PRB), a radio frame, a subframe, a time slot, a sub-band, a frequency region, a sub-carrier, a beam, etc. The term “transmission” and / or “reception” may refer to wirelessly transmitting and / or receiving via a wireless propagation channel on radio resources.

[0054] Fig. 1 illustrates an example of a communication network to which examples disclosed herein may be applied. The communication network or a cellular communication network may comprise a network node 110 configured to provide one or more cells, such as cell 100, and a network node 112 configured to provide one or more other cells, such as cell 102. Each cell may, for example, be a macro cell, a micro cell, femto, or a pico cell. The cell may define a coverage area or a service area of the corresponding access node.

[0055] The network node (110, 112) may be configured to provide a user equipment (UE) 120 (one or more UEs) with wireless access to the communication network. The wireless access may comprise downlink (DL) communication from the network node (110, 112) to the UE 120 and uplink (UL) communication from the UE 120 to the network node (110, 112). Examples of uplink channels may comprise physical uplink control channel (PUCCH) for transmitting control information and physical uplink shared channel (PUSCH) for transmitting data towards the network. Examples of downlink channels may comprise physical downlink control channel (PDCCH) for transmitting control information and physical downlink shared channel (PDSCH) for transmitting data towards the user equipment.

[0056] There may be a plurality of UEs (120, 122) in the system. Each of the plurality of UEs may be served by the same or by different network nodes (110, 112). UE may be configured with dual connectivity (DC), wherein the UE, for example UE 120, may be connected to multiple network nodes (110, 112). The UEs (120, 122) may communicate with each other, in case device-to-device (D2D) communication interface is established between them via a so-called sidelink (SL). Such D2D communications may be referred to as machine-to-machine, peer-to-peer (P2P) communications, or vehicle-to-vehicle (V2V), for example.

[0057] In the case of multiple network nodes in the communication network, the network nodes may be connected to each other via an interface. LTE specifications, for example, refer to such an interface as an X2 interface. An interface between an LTE node and a 5G node, or between two 5G nodes may be called an Xn interface.

[0058] The network nodes 110 and 112 may be further connected via another interface to a core network 116 of the communication network. The LTE specifications specify the core network as an evolved packet core (EPC), and the core network may comprise a plurality of entities (e.g. a mobility management entity (MME) and a gateway node). The MME may handle mobilityof terminal devices in a tracking area encompassing a plurality of cells and handle signalling connections between the terminal devices and the core network. The gateway node may handle data routing in the core network and to / from the terminal devices. The 5G specifications specify the core network as a 5G core (5GC). The 5GC may, for example, comprise an access and mobility management function (AMF) and a user plane function / gateway (UPF) and other functions. The AMF may handle termination of non-access stratum (NAS) signalling, NAS ciphering & integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. The UPF node may, for example, support packet routing and forwarding, packet inspection and quality of service (QoS) handling.

[0059] Development of 6G networks is taking place. When 6G networks are be deployed, 6G to 5G / 4G / 3G handover will take place.

[0060] Fig. 2 shows an example procedure for a 5GS to EPS handover using N26 interface.

[0061] Fig. 3 shows an example preparation phase of the Single Registration-based interworking from EPS to 5GS procedure.

[0062] Fig. 4 shows the execution of Execution phase of Single Registration-based Interworking from EPS to 5GS procedure.

[0063] For HO from 6G to a lower, or older, G (e.g., 5G, 4G or 3G) a bidding down attack from 6G to the lower generation may occur. Older generation networks may be vulnerable for attack if, for example, an operator does not upgrade their legacy network for quantum attack. In 4G network, IMSI tracking is possible. An attacker may provide increased power of 4G BS (fake) so that a UE will fall back to 4G and is vulnerable to IMSI tracking.

[0064] It is desirable that 6G networks ensure fallback to lower generations (e.g., 5G / 4G) are trusted, and only then is handover to those networks allowed.

[0065] Fig. 5 is a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may comprise, be or be comprised in a network function (NF) of a first network. The NF of the first network may be a mobility management (MM) NF. The first network may be a 6G network.

[0066] At 501 , the method comprises receiving an indication at a network function of a first network from an access node of the first network to initiate handover for a user equipment associated with the first network to a second network.

[0067] At 502, the method comprises providing an identifier of the user equipment and a temporary key to a home network (HN).

[0068] At 503, the method comprises in response to the providing, receiving authentication vectors from the HN.

[0069] At 504, the method comprises providing a handover command to the user equipment, the handover command comprising the received authentication vectors.

[0070] At 505, the method comprises receiving an indication from the user equipment viaan access node of the second network that authentication based on the authentication vectors is successful;

[0071] At 506, the method comprises verifying the received indication.

[0072] At 507, the method comprises providing an indication of the verification to the second network.

[0073] Fig. 6 shows a flowchart of a method. The method may be performed at an apparatus. The apparatus may comprise, be or be comprised in a user equipment.

[0074] At 601 , the method comprises receiving, at a user equipment associated with a first network, a handover command to a second network from a network function of a first network, the handover command comprising authentication vectors;

[0075] At 602, the method comprises performing an authentication procedure based on the received authentication vectors.

[0076] At 603, the method comrpises providing an indication from the user equipment to an access node of the second network that authentication is successful.

[0077] Fig. 7 shows a flowchart of a method performed at a network function of a second network. The method may be performed at an apparatus. The apparatus may comprise, be or be comprised in a network function (NF) of a second network. The NF of the second network may be a MME or an AMF.

[0078] At 701, receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful.

[0079] At 702, providing an indication of the successful authentication to the first network.

[0080] At 703, receiving an indication from the first network that the authentication has been verified.

[0081] At 704, based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.

[0082] Methods as described with reference to Figs. 5 to 7 involve a direct verification of the authentication result at the first network, e.g. a 6G network. The HN may comprise a UDM function of a 6G or 5G network or a HSS of a 4G network, for example.

[0083] The first network in the methods described with reference to Figs. 5 to 7 may be a 6G network. The second network maybe a 4G network (in which case the network function of the second network is a MME).

[0084] In an example wherein the second network is a 4G network, i.e., when HO is triggered from 6G to 4G, and the temporary routing of data happens from 6G MM NF to 4G eNB, 6G MM NF will fetch the Authentication vectors from HN (this is an example of receiving authentication vectors from the HN) and will provide them to the LIE (e.g., in a HO command). LIE will send the calculated response to a 4G MME. The 4G MME forwards the response to 6G MM NF andthe 6G MM NF verifies if the authentication is successful. After the successful authentication, NAS and AS SMC will be run.

[0085] Fig. 8 shows a signaling flow according to an example where the second network is a 4G network.

[0086] In step 1, a UE is authenticated and is in connected mode with 6GS (e.g., a first network). In step 2, DL and UL user plane data is ongoing between UE and Data Network.

[0087] In step 3, 6G RAN decides that the UE should be handed over to the E-UTRAN. The 6G RAN sends a Handover Required (Target eNB ID, Direct Forwarding Path Availability, Source to Target Transparent Container, inter system handover indication) message to the 6G MM NF. 6G RAN indicates bearers corresponding to the 6G QoS Flows for data forwarding in Source to Target Transparent Container. The 6G MM NF determines from the 'Target eNB Identifier' IE that the type of handover is Handover to E-UTRAN.

[0088] When the 6G MM NF sends PDUSession ContextRequest the 6G MM NF provides also the target MME capability to the V-SMF or the SMF+PGW-C to allow it to determine whether to include EPS Bearer context for Ethernet PDN Type or non-IP PDN Type or not.

[0089] When the 6G MM NF sends PDUSession ContextRequest to the V- SMF or the SMF+PGW-C, the 6G MM NF indicates whether the target MME supports User Plane Integrity Protection with EPS. The 6G MM NF sends a Forward Relocation Request with the following information:

[0090] Parameter "Return preferred" may be included. Return preferred is an optional indication by the MME of a preferred return of the UE to the 6GS PLMN at a later access change to a 6GS shared network.

[0091] The SGW address and TEID for both the control-plane or EPS bearers in the message are such that target MME selects a new SGW.

[0092] The 6G MM NF determines, based on configuration and the Direct Forwarding Path Availability, the Direct Forwarding Flag to inform the target MME whether direct data forwarding is applicable.

[0093] The 6G MM NF includes the mapped SM EPS UE Contexts for PDU Sessions with and without active UP connections.

[0094] Subject to operator policy if the secondary RAT access restriction condition is the same for EPS and 6GS, the 6G MM NF may set EPS secondary RAT access restriction condition based on the UE's subscription data.

[0095] The Handover Request may contain information Handover Restriction List with information about PLMN IDs for eNodeB functions. MME and SGW will create indirect data forwarding tunnel temporarily. MME will send back the relocation response to 6G MM NF.

[0096] In step 4, the 6G MM NF checks if the HO request is from 6G to lower G like 4G, so the complete context is not transferred and only the temporary key is generated for HO. TheSlIPI or 6G LIE ID and temporary key are transferred to the target node. The 6G MM NF will fetch the Authentication vectors from HN (could be 6G UDM or 4G HSS).The HO command is sent from 6G MM NF to 6G-gNB to the LIE with the 6G AKA AV. This is an example of providing an identifier of the user equipment and a temporary key to a home network, in response to the providing, receiving authentication vectors from the HN and providing a handover command to the user equipment, the handover command comprising the received authentication vectors.

[0097] In step 5, temporary DL data is forwarded from 6G-gNB to 6G UP NF to SGW and then to eNB. When the UE sends the HO complete message to eNB, the HO notify will be forwarded to MME by eNB with 6G AKA RES. The AKA Res is an example of receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful. MME forwards the 6G AKA RES to 6G MM NF and it will check the received 6G AKA RES with XRES provided by 6G UDM. This is an example of verifying the indication (and thus the authentication). AKA run is successful and NAS SMC , AS SMC is also successful with 4G network entities. This is an example of initiating a non-access stratum and access stratum security mode procedure with a network function of the second network. New UE context is created in UE, eNB and MME.

[0098] If the Authentication at step 5d to 5h fails, then HO will be aborted towards 4G.

[0099] In step 6, the MME and 6G MM NF will have the relocation complete notification and acknowledgement.

[0100] In step 7, the PDU session release of context happens in 6G MM NF and 6G SM NF.

[0101] In step 8, DL and UL user plane data continues via 4G network entities as authentication is successful.

[0102] The second network in the methods described with reference to Figs. 5 to 7 may be a 5G network (in which case the network function of the second network is an AMF).

[0103] In an example where the second network is a 5G network, the Handover is triggered from 6G to 5G, and the temporary routing of data happens from 6G MM NF to 5G AMF. 6G MM NF fetches Authentication vectors from HN and provides them to a UE. The UE will send a calculated response to 5G AMF. 5G AMF forwards it to 6G MM NF and the 6G MM NF will verify if the authentication is successful. After the successful authentication, NAS and AS SMC will be run in 5G.

[0104] Fig. 9 shows a signaling flow according to an example where the second network is a 5G network.

[0105] In step 1, the UE is authenticated and in connected mode with 6GS. In step 2, DL and UL user plane data is ongoing between UE and Data Network.

[0106] In step 3, the 6G RAN decides that the UE should be handed over to the 5G. The 6G RAN sends a Handover Required (Target gNB ID, Direct Forwarding Path Availability,Source to Target Transparent Container, inter system handover indication) message to the 6G MM NF. 6G RAN indicates bearers corresponding to the 6G QoS Flows for data forwarding in Source to Target Transparent Container. The 6G MM NF determines from the 'Target eNB Identifier' IE that the type of handover is Handover to 5G.

[0107] When the 6G MM NF sends PDUSession ContextRequest the 6G MM NF provides also the target 5G AMF capability to the V-SMF or the 5G SMF to allow it to determine whether to include 5G Bearer context for Ethernet PDN Type or non-IP PDN Type or not.

[0108] When the 6G MM NF sends PDUSession ContextRequest to the V-SMF, the 6G MM NF indicates whether the target 5G AMF supports User Plane Integrity Protection with 5GS. The 6G MM NF sends a Forward Relocation Request with the following information:

[0109] Parameter "Return preferred" may be included. Return preferred is an optional indication by the 5G AMF of a preferred return of the UE to the 6GS PLMN at a later access change to a 6GS shared network.

[0110] The SGW address and TEID for both the control-plane or 5G bearers in the message are such that target 5G AMF / SMF selects a new UPF.

[0111] The 6G MM NF determines, based on configuration and the Direct Forwarding Path Availability, the Direct Forwarding Flag to inform the target 5G AMF whether direct data forwarding is applicable.

[0112] The 6G MM NF includes the mapped SMF UE Contexts for PDU Sessions with and without active UP connections.

[0113] Subject to operator policy if the secondary RAT access restriction condition is the same for 5G and 6GS, the 6G MM NF may set 5G secondary RAT access restriction condition based on the UE's subscription data.

[0114] Handover Request may contain information Handover Restriction List with information about PLMN IDs for eNodeB functions. 5G AMF and SGW will create indirect data forwarding tunnel temporarily. 5G AMF will send back the relocation response to 6G MM NF.

[0115] In step 4, the 6G MM NF checks if the HO request is from 6G to a lower generation such as 5G, so the complete context is not transferred and only the temporary key is generated for HO. SUPI or 6G UE ID and temporary key are transferred to the target node. The 6G MM NF will fetch the Authentication vectors from HN (could be 6G UDM or 5G UDM). The HO command is sent from 6G MM NF to 6G-gNB to the UE with the 6G AKA AV. This is an example of providing an identifier of the user equipment and a temporary key to a home network, in response to the providing, receiving authentication vectors from the HN and providing a handover command to the user equipment, the handover command comprising the received authentication vectors.

[0116] In step 5, temporary DL data is forwarded from 6G-gNB to 6G UP NF to SGW and then to eNB. When the UE sends the HO complete message to eNB, the HO notify will beforwarded to 5G AMF by eNB with 6G AKA RES. The AKA RES is an example of receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful. This is an example of verifying the indication (and thus the authentication). 5G AMF forwards the 6G AKA RES to 6G MM NF and it will check the received 6G AKA RES with XRES provided by 6G LIDM. This is an example of verifying the indication (and thus the authentication). AKA run is successful and NAS SMC, AS SMC is also successful with 5G network entities. This is an example of initiating a non-access stratum and access stratum security mode procedure with a network function of the second network. New LIE context is created in LIE, eNB and 5G AMF.

[0117] If the Authentication at step 5d to 5h fails, then HO will be aborted towards 5G.

[0118] In step 6, the 5G AMF and 6G MM NF will have the relocation complete notification and acknowledgement.

[0119] In step 7, PDll session release of context happens in 6G MM NF and 6G SM NF.

[0120] In step 8, DL and UL user plane data continues via 5G network entities as authentication is successful.

[0121] Fig. 10 shows a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may comprise, be or be comprised in a network function (NF) of a second network. The NF of the second network may be a MME or an AMF.

[0122] At 1001 , the method comprises receiving, from a user equipment associated with a first network at a network function of a second network, notification of a handover from the first network to the second network.

[0123] At 1002, the method comprises obtaining authentication vectors from a data management function of the second network.

[0124] At 1003, the method comprises providing the received authentication vectors to the user equipment.

[0125] At 1004, the method comprises receiving an indication from the user equipment of a successful authentication procedure based on the authentication vectors.

[0126] At 1005, the method comprises, based on receiving the indication of successful authentication, creating a user equipment context for the user equipment in the second network.

[0127] Fig. 11 shows a flowchart of a method according to an example. The method may be performed at an apparatus. The apparatus may be, comprise, or be comprised in a user equipment.

[0128] At 1101 , the method comprises receiving, at a user equipment associated with a first network, a handover command to a second network from a network function of a first network.

[0129] At 1102, the method comprises receiving authentication vectors from a network function of the second network.

[0130] At 1103, the method comprises performing an authentication procedure based on the received authentication vectors.

[0131] At 1104, the method comprises providing an indication from the user equipment to an access node of the second network that authentication is successful.

[0132] Methods as described with reference to Figs. 10 and 11 involve an indirect verification of the authentication result. That is, the network to which HO is trigger performs the authentication. The first network of the method described with reference to Figs. 10 and 11 may be a 6G network. The second network may be a 4G network, the data management function may be a HSS and the NF of the second network may be a MME. Alternatively, or in addition, the second network may be a 5G network, the data management function may be a UDM and the NF of the second network may be an AMF.

[0133] A method as described with reference to Figure 10 may comprise initiating a non-access stratum and access stratum security mode procedure with the user equipment.

[0134] In an example, when Handover is triggered from 6G to 4G, the temporary routing of data happens from 6G MM NF to 4G eNB. MME fetches the Authentication vectors from HN and provides it to LIE. LIE sends the calculated response to 4G MME. MME will verify if the authentication is successful. After the successful authentication, NAS and AS SMC will be run in 4G. If authentication is not triggered, UE reject the handover.

[0135] Fig. 12 shows an example signaling flow for a method as described with reference to Figs. 10 and 11.

[0136] In step 1 , UE is authenticated and in connected mode with 6GS. In step 2, DL and UL user plane data is ongoing between UE and Data Network.

[0137] In step 3, 6G RAN decides that the UE should be handed over to the E-UTRAN. The 6G RAN sends a Handover Required (Target eNB ID, Direct Forwarding Path Availability, Source to Target Transparent Container, inter system handover indication) message to the 6G MM NF. 6G RAN indicates bearers corresponding to the 6G QoS Flows for data forwarding in Source to Target Transparent Container. The 6G MM NF determines from the 'Target eNB Identifier' IE that the type of handover is Handover to E-UTRAN.

[0138] When the 6G MM NF sends PDUSession ContextRequest the 6G MM NF provides also the target MME capability to the V-SMF or the SMF+PGW-C to allow it to determine whether to include EPS Bearer context for Ethernet PDN Type or non-IP PDN Type or not.

[0139] When the 6G MM NF sends PDUSession ContextRequest to the V- SMF or the SMF+PGW-C, the 6G MM NF indicates whether the target MME supports User Plane Integrity Protection with EPS. The 6G MM NF sends a Forward Relocation Request with the following information:

[0140] Parameter "Return preferred" may be included. Return preferred is an optional indication by the MME of a preferred return of the UE to the 6GS PLMN at a later access change to a 6GS shared network.

[0141] The SGW address and TEID for both the control-plane or EPS bearers in the message are such that target MME selects a new SGW.

[0142] The 6G MM NF determines, based on configuration and the Direct Forwarding Path Availability, the Direct Forwarding Flag to inform the target MME whether direct data forwarding is applicable.

[0143] The 6G MM NF includes the mapped SM EPS UE Contexts for PDU Sessions with and without active UP connections.

[0144] Subject to operator policy if the secondary RAT access restriction condition is the same for EPS and 6GS, the 6G MM NF may set EPS secondary RAT access restriction condition based on the UE's subscription data.

[0145] The Handover Request may contain information Handover Restriction List with information about PLMN IDs for eNodeB functions. MME and SGW will create indirect data forwarding tunnel temporarily. MME will send back the relocation response to 6G MM NF.

[0146] At step 4, the 6G MM NF checks if the HO request is from 6G to lower G e.e.,g 4G, so the complete context is not transferred and only the temporary key is generated for HO. SUPI or 6G UE ID and temporary key is transferred to the target node. HO command is sent from 6G MM NF to 6G-gNB to the UE.

[0147] At step 5, temporary DL data is forwarded from 6G-gNB to 6G UP NF to SGW and then to eNB. When the UE sends the HO complete message to eNB, the HO notify will be forwarded to MME by eNB. This is an example of receiving, from a user equipment associated with a first network at a network function of a second network, notification of a handover from the first network to the second network. The MME triggers authentication by fetching the Authentication vector (AV) from HSS. This is an example of obtaining authentication vectors from a data management function of the second network (e.g., HSS of a 4G network). The AKA run is successful (i.e., the obtained authentication vectors are provided to the user equipment and an indication of a successful authentication procedure based on the authentication vectors is received form the user equipment). NAS SMC, AS SMC is also successful with 4G network entities. New UE context is created in UE, eNB and MME. This is an example of perform initiating a non-access stratum and access stratum security mode procedure with the user equipment.

[0148] If the Authentication at step 5d to 5g fails, then HO will be aborted towards 4G.

[0149] At step 6, the MME and 6G MM NF will have the relocation complete notification and acknowledgement.

[0150] At step 7, PDU session release of context happens in 6G MM NF and 6G SM NF.

[0151] At step 8, DL and UL user plane data continues via 4G network entities as authentication is successful.

[0152] Fig. 13 shows a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in a network function of a second network. The second network may be a 4G network and the network function may be a MME. The second network may be a 5G network and the network function may be an AMF.

[0153] At 1301 , the method comprises receiving, from a user equipment associated with a first network at a network function of a second network, notification of a handover from the first network to the second network, the notification comprising authentication response vectors.

[0154] At 1302, the method comprises receiving expected authentication response vectors from a network node of the first network.

[0155] At 1303, the method comprises verifying the authentication based on the authentication response vectors received from the user equipment and the network node of the first network; and

[0156] At 1304, the method comrpises, based on the verification, creating a user equipment context for the user equipment in the second network.

[0157] Fig. 14 shows a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in a user equipment.

[0158] At 1401 , the method comprises receiving, at a user equipment associated with a first network, a handover command to a second network from a network function of a first network, the handover command comprising authentication vectors.

[0159] At 1402, the method comprises performing an authentication procedure based on the received authentication vectors.

[0160] At 1403, the method comprises providing a notification of the handover to a network node of the second network, the notification comprising authentication response vectors.

[0161] A method as described with reference to Fig. 13 may comprise initiating a non-access stratum and access stratum security mode procedure with the user equipment.

[0162] The first network of the methods described with reference to Figs. 13 and 14 may be a 6G network.

[0163] Methods as described with reference to Figs. 13 and 14 are an example of indirect verification of the authentication result. In this case, the network to which HO occurs verifies the authentication based on authentication response vectors received from the first network and the user equipment.

[0164] In an example when the Handover is triggered from 6G to 4G, and the temporary routing of data happens from 6G MM NF to 4G eNB, 6G MM NF will fetch the Authenticationvectors from HN and will provide the authentication vectors to LIE. LIE will send the calculated response to 4G MME. MME will verify if the authentication is successful. After the successful authentication, NAS and AS SMC will be run in 4G.

[0165] Fig. 15 is an example signaling diagram for a method as described with reference to Figs. 13 and 14 where the second network is a 4G network and the network function of the second network is a MME.

[0166] In step 1 , UE is authenticated and in connected mode with 6GS. In step 2, DL and UL user plane data is ongoing between UE and Data Network.

[0167] In step 3, 6G RAN decides that the UE should be handed over to the E-UTRAN. The 6G RAN sends a Handover Required (Target eNB ID, Direct Forwarding Path Availability, Source to Target Transparent Container, inter system handover indication) message to the 6G MM NF. 6G RAN indicates bearers corresponding to the 6G QoS Flows for data forwarding in Source to Target Transparent Container. The 6G MM NF determines from the 'Target eNB Identifier' IE that the type of handover is Handover to E-UTRAN.

[0168] When the 6G MM NF sends PDUSession ContextRequest the 6G MM NF provides also the target MME capability to the V-SMF or the SMF+PGW-C to allow it to determine whether to include EPS Bearer context for Ethernet PDN Type or non-IP PDN Type or not.

[0169] When the 6G MM NF sends PDUSession ContextRequest to the V- SMF or the SMF+PGW-C, the 6G MM NF indicates whether the target MME supports User Plane Integrity Protection with EPS. The 6G MM NF sends a Forward Relocation Request with the following information:

[0170] Parameter "Return preferred" may be included. Return preferred is an optional indication by the MME of a preferred return of the UE to the 6GS PLMN at a later access change to a 6GS shared network.

[0171] The SGW address and TEID for both the control-plane or EPS bearers in the message are such that target MME selects a new SGW.

[0172] The 6G MM NF determines, based on configuration and the Direct Forwarding Path Availability, the Direct Forwarding Flag to inform the target MME whether direct data forwarding is applicable.

[0173] The 6G MM NF includes the mapped SM EPS UE Contexts for PDU Sessions with and without active UP connections.

[0174] Subject to operator policy if the secondary RAT access restriction condition is the same for EPS and 6GS, the 6G MM NF may set EPS secondary RAT access restriction condition based on the UE's subscription data.

[0175] The Handover Request may contain information Handover Restriction List with information about PLMN IDs for eNodeB functions. MME and SGW will create indirect data forwarding tunnel temporarily. MME will send back the relocation response to 6G MM NF.

[0176] At step 4, the 6G MM NF checks if the HO request is from 6G to lower G , e.g., 4G, so the complete context is not transferred and only the temporary key is generated for HO. SUPI or 6G UE ID and temporary key are transferred to the target node. The 6G MM NF fetches the Authentication vectors from HN (which may be 6G UDM or 4G HSS). HO command is sent from 6G MM NF to 6G-gNB to the UE with the 6G AKA AV. This is an example of receiving a HO command at a UE comprising authentication vectors. 6G MM NF will also send the expected response “XRES” (which is an example of expected authentication response vectors) to the MME.

[0177] At step 5, temporary DL data is forwarded from 6G-gNB to 6G UP NF to SGW and then to eNB. When the UE sends the HO complete message to eNB, the HO notify will be forwarded to MME by eNB with 6G AKA RES. This is an example of providing a notification of the handover to a network node of the second network, the notification comprising authentication response vectors. MME will check the received 6G AKA RES with XRES provided by 6G MM NF. This is an example of verifying the authentication based on the authentication response vectors received from the user equipment and the network node of the first network. AKA run is successful and NAS SMC , AS SMC is also successful with 4G network entities. New UE context is created in UE, eNB and MME. This is an example of creating a user equipment context for the user equipment in the second network based on the verification.

[0178] If the Authentication at step 5d to 5g fails, then HO will be aborted towards 4G.

[0179] At step 6, the MME and 6G MM NF has the relocation complete notification and acknowledgement.

[0180] At step 7, PDU session release of context happens in 6G MM NF and 6G SM NF.

[0181] At step 8, DL and UL user plane data continues via 4G network entities as authentication is successful.

[0182] Fig. 16 is a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may comprise, be or be comprised in a user equipment.

[0183] At 1601 , the method comprises receiving an indication at a user equipment associated with a first network that handover from the first network to a second network is not permitted for at least one condition.

[0184] Fig. 17 is a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in a node of a network. The node may be a RAN e.g. a base station such as an eNB, gNB or a RAN of a 6G network.

[0185] At 1701 , the method comprises for a user equipment associated with a first network, determining an area where handover from the first network to a second network is not permitted for at least one condition.

[0186] At 1702, the method comprises providing an indication to the user equipment that handover from the first network to the second network is not permitted for the at least one condition.

[0187] The first network may be, comprise or be comprised in a 6G network.

[0188] The second network may be, comprise or be comprised in a 4G or a 5G network.

[0189] The indication may be provided in NAS signalling, e.g., a NAS registration accept message or new NAS signalling.

[0190] The at least one condition may comprise at least one of the following: the generation of the second network (e.g. an indication that handover is not permitted to a lower generation network, i.e., handover to a 4G or 5G network from a 6G network), the band of the second network, the frequency of the second network or the signal quality of the second network.

[0191] The indication may comprise an indication that handover from the first network to the second network is not permitted outside a given band, frequency range or signal quality range.

[0192] The area may comprise a registration area.

[0193] In an example, a UE connects to a 6G network. The 6G network calculates the registration area and determines that in this registration area 4G handover is not permitted. A 6G MM node provides an indication to UE that 4G RAT is not allowed in this registration area. This indication may be provided by new NAS signalling or a NAS registration accept message. The UE will thus not select the 4G RAT for HO in that registration area.

[0194] In an example, the 6G network may provide the permissible limit of 4G signal, band, frequency, so that UE will select certain 4G networks only. This information may be provided by new NAS signalling or a NAS registration accept message

[0195] Fig. 18 shows, by way of example, a block diagram of an apparatus 10. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). In an example, the at least one memory and the instructions (e.g. a computer program code, software), are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof).

[0196] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with embodiments described herein.

[0197] As used herein, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) anyportions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0198] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may, for example, be at least in part external to apparatus 10 but accessible to apparatus 10.

[0199] The instructions 15 may be comprised in a computer readable medium or a non-transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM).

[0200] For example, the apparatus 10 is a terminal device, such as a UE. As another example, the apparatus is comprised in such a terminal device, e.g. as a chipset configured to control the terminal device. The apparatus 10 may be caused or configured or comprise means to perform at least the method of Figs. 6, 10, 13, 16 and / or any one or more of the embodiments described herein.

[0201] For example, the apparatus 10 may be a network node, such as a network function. As another example, the apparatus is comprised in such a node e.g. as a chipset configured to control the node. The apparatus 10 may be caused or configured or comprise means to perform at least the method of Figs. 5, 7, 11, 14 or 17 and / or any one or more of the embodiments described herein.

[0202] The apparatus 10 comprises a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellular standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than onetransceiver.

[0203] The apparatus 10 may comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10. For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.

[0204] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components of the apparatus 10. For example, the at least one processor 12, the memory 14, and the computer program code form means for carrying out the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C]”, is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.

[0205] Even though this disclosure has been described above with reference to non-limiting and illustrative examples according to the accompanying figures, it is clear that the scope of this disclosure is not restricted thereto - but can be modified in many different ways. As technology advances, it will become apparent to a person skilled in art as to how the disclosure can be further implemented and / or modified in various ways. Further, it is clear to a person skilled in the art that the embodiments described herein may, but are not required to, be combined in various ways with other embodiments described herein.

Claims

CLAIMS1. An apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform:receiving an indication at a network function of a first network from an access node of the first network to initiate handover for a user equipment associated with the first network to a second network;providing an identifier of the user equipment and a temporary key to a home network, HN; in response to the providing, receiving authentication vectors from the HN; providing a handover command to the user equipment, the handover command comprising the received authentication vectors;receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful;verifying the received indication; andproviding an indication of the verification to the second network.

2. The apparatus according to claim 1, wherein the network function of the first network is a mobility management network function.

3. The apparatus according to claim 1 or claim 2, wherein the second network is a 4G network, and configured to perform providing an indication of the verification to a mobility management entity of the second network.

4. The apparatus according to claim 1 or claim 2, wherein the second network is a 5G network, and configured to perform providing an indication of the verification to an access and mobility function of the second network.

5. The apparatus according to any one of claims 1 to 3, wherein the HN comprises a unified data management function of the first network or a home subscriber service of the second network.

6. An apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform:receiving, at a user equipment associated with a first network, a handover command to a second network from a network function of a first network, the handover command comprising authentication vectors;performing an authentication procedure based on the received authentication vectors; and providing an indication from the user equipment to an access node of the second network that authentication is successful.

7. The apparatus according to claim 6, configured to perform initiating a non-access stratum and access stratum security mode procedure with a network function of the second network.

8. The apparatus according to claim 7, wherein the second network is a 4G network, and wherein the network function of the second network comprises a mobility management entity of the second network.

9. The apparatus according to claim 7, wherein the second network is a 5G network, and wherein the network function of the second network comprises an access and mobility function of the second network.

10. An apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform:receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful;providing an indication of the successful authentication to the first network; receiving an indication from the first network that the authentication has been verified; and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.11 . The apparatus according to claim 10, configured to perform initiating a non-access stratum and access stratum security mode procedure with the user equipment.

12. The apparatus according to claim 10 or claim 11 , wherein the second network is a 4G network, and wherein the network function of the second network comprises a mobility management entity of the second network.

13. The apparatus according to claim 10 or claim 11 , wherein the second network is a 5G network, and wherein the network function of the second network comprises an access and mobility function of the second network.

14. A method comprising:receiving an indication at a network function of a first network from an access node of the first network to initiate handover for a user equipment as-sociated with the first network to a second network;providing an identifier of the user equipment and a temporary key to a home network, HN;in response to the providing, receiving authentication vectors from the HN; providing a handover command to the user equipment, the handover command comprising the received authentication vectors;receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful;verifying the received indication; andproviding an indication of the verification to the second network.

15. A method comprising:receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful;providing an indication of the successful authentication to the first network; receiving an indication from the first network that the authentication has been verified; and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.

16. A method comprising:receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful;providing an indication of the successful authentication to the first network; receiving an indication from the first network that the authentication has been verified; and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.

17. An apparatus comprising means for:receiving an indication at a network function of a first network from an access node of the first network to initiate handover for a user equipment associated with the first network to a second network;providing an identifier of the user equipment and a temporary key to a home network, HN ;in response to the providing, receiving authentication vectors from the HN; providing a handover command to the user equipment, the handover command comprising the received authentication vectors;receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful;verifying the received indication; andproviding an indication of the verification to the second network.

18. An apparatus comprising means for:receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful;providing an indication of the successful authentication to the first network; receiving an indication from the first network that the authentication has been verified; and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.

19. An apparatus comprising means for:receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful;providing an indication of the successful authentication to the first network; receiving an indication from the first network that the authentication has been verified; and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.

20. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform:receiving an indication at a network function of a first network from an access node of the first network to initiate handover for a user equipment associated with the first network to a second network;providing an identifier of the user equipment and a temporary key to a home net-work, HN;in response to the providing, receiving authentication vectors from the HN; providing a handover command to the user equipment, the handover command comprising the received authentication vectors;receiving an indication from the user equipment via an access node of the second network that authentication based on the authentication vectors is successful;verifying the received indication; andproviding an indication of the verification to the second network.21 . A computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform:receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful;providing an indication of the successful authentication to the first network; receiving an indication from the first network that the authentication has been verified; and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.

22. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform:receiving an indication from a user equipment associated with a first network, at a network function of a second network, that authentication based on authentication vectors received at the user equipment from the first network is successful;providing an indication of the successful authentication to the first network; receiving an indication from the first network that the authentication has been verified; and based on receiving the indication of verification, creating a user equipment context for the user equipment in the second network.