US2019191309A1PendingUtilityA1

Method for requesting authentication between terminal and 3rd party server in wireless communication system, terminal therefor, and network slice instance management device

Assignee: SAMSUNG ELECTRONICS CO LTDPriority: Aug 22, 2016Filed: Aug 21, 2017Published: Jun 20, 2019
Est. expiryAug 22, 2036(~10.1 yrs left)· nominal 20-yr term from priority
H04W 48/18H04W 12/06H04L 9/321H04L 9/3213H04M 15/8228H04L 12/1407H04L 12/14H04W 80/10H04L 9/32
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention relates to a communication method for merging, with IoT technology, a 5G communication system for supporting a data transmission rate higher than that of a 4G system, and a system therefor. The present invention can be applied to an intelligent service (for example, smart home, smart building, smart city, smart car or connected car, healthcare, digital education, retail, security and safety related services, and the like) on the basis of a 5G communication technology and an IoT-related technology. The present invention provides a method by which a terminal requests authentication from a 3 rd party server comprises the steps of: transmitting, to a common control function providing device (common control plane network function serving unit), a service request message including a tenant ID and a slice type provided by an application related to the 3rd party server; receiving a service response message including information on the limited data session from the network slice instance management device when a network slice instance management device (network slice instance unit) selected by the common function providing device generates a limited data session (limited packet data unit session) for authentication between the terminal and the 3 rd party server on the basis of the service request message; and transmitting an authentication request message requesting authentication of the terminal through the limited data session to the 3 rd party server on the basis of the service response message.

Claims

exact text as granted — not AI-modified
1 . A method for a terminal to request to a third party server for authentication, the method comprising:
 transmitting a service request message including a tenant identifier (ID) and a slice type provided by an application associated with the third party server to a common control plane network function serving unit;   receiving, if a limited data session (limited packet data unit session) for authentication between the terminal and the third party server is established by a network slice instance management device (network slice instance unit) selected by the common control plane network function serving unit based on the service request message, a service response message including information on a limited data session from the network slice instance management device; and   transmitting an authentication request message requesting for authentication on the terminal to the third party server through the limited data session based on the service response message.   
     
     
         2 . The method of  claim 1 , wherein the tenant ID and the slice type are stored in the terminal in association with the application while the application is installed on the terminal. 
     
     
         3 . The method of  claim 1 , wherein transmitting the service request message comprises transmitting, if the application is installed or executed on the terminal or an event for receiving a third party service via the application occurs, the service request message to the common control plane network function serving unit via a base station. 
     
     
         4 . The method of  claim 1 , further comprising:
 receiving, if the terminal is authenticated, an authentication response message including a token from the third party server;   transmitting a service authentication result message including the token to the network slice instance management device; and   transferring traffic of the application to the third party server through a data session updated based on the service authentication result message,   wherein at least one of the tenant ID and the slice type is determined based on a network identifier (public land mobile network ID) of a communication operator subscribed to by the terminal.   
     
     
         5 . A method for a network slice instance management device (network slice instance unit) to establish a data session, the method comprising:
 receiving a service request message from a terminal;   establishing a limited data session (limited packet data unit session) for authentication between the terminal and a third party server based on the received service request message; and   transmitting a service response message including information on the limited data session to the terminal to assign the limited data session between the terminal and the third party server.   
     
     
         6 . The method of  claim 5 , further comprising:
 receiving, if the authentication between the terminal and the third party server succeeds through the limited data session, a service authentication result message including an update rule from the third party server; and   establishing an updated data session based on the update rule.   
     
     
         7 . The method of  claim 5 , wherein receiving the service request message from the terminal of the wireless communication system comprises receiving the service request message from the terminal via a common control plane network function serving unit that has selected the network slice instance management device. 
     
     
         8 . The method of  claim 5 , wherein establishing the limited data session for authentication between the terminal and the third party server comprises:
 sending a session creation request message from a network session management device (core plane network function unit) of the network slice instance management device to a network data management unit (user plane network function unit) of the network slice instance management device based on the service request message; and   sending a session creation response message from the network data management unit to the network session management device in response to the session creation request message.   
     
     
         9 . A terminal requesting to a third party server for authentication, the terminal comprising:
 a communication unit configured to communicate with an external node;   a storage unit configured to store a tenant identifier (ID) and a slice type; and   a processor configured to:
 control the communication unit to transmit a service request message including a tenant identifier (ID) and a slice type provided by an application associated with the third party server to a common control plane network function serving unit, 
 receive, if a limited data session (limited packet data unit session) for authentication between the terminal and the third party server is established by a network slice instance management device (network slice instance unit) selected by the common control plane network function serving unit based on the service request message, a service response message including information on a limited data session from the network slice instance management device, and 
 transmit an authentication request message requesting for authentication on the terminal to the third party server through the limited data session based on the service response message. 
   
     
     
         10 . The terminal of  claim 9 , wherein the tenant ID and the slice type are stored in the terminal in association with the application while the application is installed on the terminal. 
     
     
         11 . The terminal of  claim 9 , wherein the controller is configured to control the communication unit to transmit, if the application is installed or executed on the terminal or an event for receiving a third party service via the application occurs, the service request message to the common control plane network function serving unit via a base station. 
     
     
         12 . The terminal of  claim 9 ,
 wherein the controller is configured to:
 control the communication unit to receive, if the terminal is authenticated, an authentication response message including a token from the third party server, 
 transmit a service authentication result message including the token to the network slice instance management device, and 
 transfer traffic of the application to the third party server through a data session updated based on the service authentication result message, 
   wherein at least one of the tenant ID and the slice type is determined based on a network identifier (public land mobile network ID) of a communication operator subscribed to by the terminal.   
     
     
         13 . A network slice instance management device (network slice instance unit) for establishing a data session, the network slice instance management device comprising:
 a communication unit configured to communicate with an external node; and   a controller configured to:
 control the communication unit to receive a service request message from a terminal, 
 establish a limited data session (limited packet data unit session) for authentication between the terminal and a third party server based on the received service request message, and 
 transmit a service response message including information on the limited data session to the terminal to assign the limited data session between the terminal and the third party server. 
   
     
     
         14 . The network slice instance management device of  claim 13 , wherein the controller is configured to control the communication unit to receive, if the authentication between the terminal and the third party server succeeds through the limited data session, a service authentication result message including an update rule from the third party server and establish an updated data session based on the update rule. 
     
     
         15 . The network slice instance management device of  claim 13 , wherein the controller is configured to control the communication unit to receive the service request message from the terminal via a common control plane network function servicing unit that has selected the network slice instance unit, a network session management device (core plane network function unit) of the network slice instance management device to send a session creation request message to a network data management unit (user plane network function unit) of the network slice instance management device based on the service request message, and the network data management unit to send a session creation response message to the network session management device in response to the session creation request message.

Join the waitlist — get patent alerts

Track US2019191309A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.