Authentication method for next generation systems
Abstract
The present disclosure relates to authentication methods supported by the User Equipment (UE) to the core network and authentication method (selected by the core network) to the UE. These can be used for negotiating any primary or secondary (or any) authentication method and are applicable when multiple authentication methods are supported at the UE and the network (authentication server). Further, the present disclosure also offers security solution to prevent modification or tampering of the parameters in the mechanisms in order to prevent attacks such as bidding-down, Denial of Service (DoS) and Man-In-The-Middle (MITM).
Claims
exact text as granted — not AI-modified1 . An authentication method of a Unified Data Management (UDM) node, the method comprising:
receiving, from an Authentication Server Function (AUSF) node, a Nudm_UEAuthentication_Get Request message including a Subscription Concealed Identifier (SUCI) and information related to a User Equipment (UE), wherein the SUCI and the information were included in a Nausf_UEAuthentication_Authenticate Request message received by the AUSF node from an Access and Mobility Management Function/SEcurity Anchor Function (AMF/SEAF) node; and selecting an authentication method using the received information.
2 . The method of claim 1 , wherein the information is different from a Subscription Permanent Identifier (SUPI).
3 . The method of claim 1 , wherein the AMF/SEAF node receives a registration message from an access network that connects the UE.
4 . The method of claim 1 , further comprising:
sending, to the AUSF node, a Nudm_UEAuthentication_Get Response message, wherein the Nudm_UEAuthentication_Get Response message is configured such that the AUSF node sends, using the Nudm_UEAuthentication_Get Response message, a Nausf_UEAuthentication_Authenticate Response message to the AWF/SEAF node that sends an Authentication Request message.
5 . A Unified Data Management (UDM) node comprising:
a memory configured to store instructions; and a processor configured to execute the instructions to: receive, from an Authentication Server Function (AUSF) node, a Nudm_UEAuthentication_Get Request message including a Subscription Concealed Identifier (SUCI) and information related to a User Equipment (UE), wherein the SUCI and the information were included in a Nausf_UEAuthentication_Authenticate Request message received by the AUSF node from an Access and Mobility Management Function/SEcurity Anchor Function (AMF/SEAF) node; and
select an authentication method using the information.
6 . The UDM node of claim 5 , wherein the information is different from a Subscription Permanent Identifier (SUPI).
7 . The UDM node of claim 5 , wherein the AMF/SEAF node receives a registration message from an access network that connects the UE.
8 . The UDM node of claim 5 , wherein the processor is further configured to execute the instructions to:
send, to the AUSF node, a Nudm_UEAuthentication_Get Response message, wherein the Nudm_UEAuthentication_Get Response message is configured such that the AUSF node sends, using the Nudm_UEAuthentication_Get Response message, a Nausf_UEAuthentication_Authenticate Response message to the AWF/SEAF node that sends an Authentication Request message.
9 . The method of claim 1 , wherein the Nausf_UEAuthentication_Authenticate Request message is received by the AUSF node in response to the AMF/SEAF node receiving a registration message from an access network that connects the UE.
10 . The method of claim 1 , wherein the information does not comprise any SUPI.
11 . The method of claim 4 , wherein the Authentication Request message is sent to the UE.
12 . The method of claim 4 , wherein the Authentication Request message is sent to the UE in response to the AWF/SEAF node receiving the Nausf_UEAuthentication_Authenticate Response message.
13 . The method of claim 1 , wherein the information does not comprise any SUPI.
14 . The method of claim 1 , wherein the information comprises a UE 5G security capabilities parameter.
15 . The UDM node of claim 5 , wherein the Nausf_UEAuthentication_Authenticate Request message is received by the AUSF node in response to the AMF/SEAF node receiving a registration message from an access network that connects the UE.
16 . The UDM node of claim 5 , wherein the information does not comprise any SUPI.
17 . The UDM node of claim 5 , wherein the Authentication Request message is sent to the UE.
18 . The UDM node of claim 5 , wherein the Authentication Request message is sent to the UE in response to the AWF/SEAF node receiving the Nausf_UEAuthentication_Authenticate Response message.
19 . The UDM node of claim 5 , wherein the information does not comprise any SUPI.
20 . The UDM node of claim 5 , wherein the information comprises a UE 5G security capabilities parameter.Join the waitlist — get patent alerts
Track US2022103540A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.