Method, apparatus, and computer program product for authentication using a user equipment identifier
Abstract
Methods, computer program products, and apparatuses are provided for enabling a user equipment (UE) to connect to the wireless access network that support non-seamless wireless local area network (WLAN) offload (NSWO), such as using the UE's fifth generation (5G) credentials. An apparatus may include a processor and a memory storing computer program code configured to cause the apparatus to request, by the UE, a wireless connection to a network entity; receive, by the UE, from the network entity, an identity request; and in response to the identity request, cause transmission, by the UE, an identity response including a UE identifier to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identifier.
Claims
exact text as granted — not AI-modifiedThat which is claimed is:
1 . A method comprising:
requesting, by a user equipment (UE), a wireless connection to a network entity; receiving, by the UE, from the network entity, an identity request; and in response to the identity request, causing transmission, by the UE, of an identity response comprising a UE identifier to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identifier.
2 . The method according to claim 1 , wherein the wireless connection is a non-seamless wireless offload (NSWO) connection to the network entity during an extensible authentication protocol (EAP) procedure.
3 . The method according to claim 1 , wherein the UE identifier is a subscription concealed identifier (SUCI) used for regular 3rd generation partnership project (3GPP) access or non-3GPP access to a fifth generation core (5GC).
4 . The method according to claim 1 , wherein the wireless connection is a non-seamless wireless offload (NSWO) connection, and wherein the UE identifier serves as a fifth generation core (5GC) credential used in the NSWO connection.
5 . A method comprising:
receiving, by a network function, from a network entity, a user equipment (UE) identifier; causing transmission, by the network function, to an authentication function, of the UE identifier and a wireless connection indicator; and upon successful authentication using the UE identifier, sending a master key received from the authentication function to the network entity.
6 . The method according to claim 5 , further comprising storing, by the network function upon successful authentication using the UE identifier, a permanent UE identifier received from the authentication function, wherein the permanent UE identifier is a subscription permanent identifier (SUPI) derived from the UE identifier.
7 . The method according to claim 5 , wherein the wireless connection indicator indicates that an extensible authentication protocol (EAP) procedure is triggered for non-seamless wireless offload (NSWO) connection purposes.
8 . The method according to claim 5 , wherein the authentication function is configured to determine an authentication type using the wireless connection indicator and trigger an extensible authentication protocol (EAP) procedure for non-seamless wireless offload (NSWO) connection purposes in accordance with the authentication type.
9 . The method according claim 5 , further comprising:
causing transmission, by the network function, to a unified data management (UDM), of a registration request message for registering the UE; and upon receiving, at the network function, from the UDM, a deregistration message for deregistering the UE, triggering a termination of a wireless connection to the network entity.
10 . The method according claim 5 , further comprising:
receiving, at the network function, the master key and a subscription permanent identifier (SUPI), wherein the master key is established as a result of a key derivation process based on, at least in part, a serving network name provided by the network function.
11 . The method according to claim 5 , wherein the network function is configured to be used as an access and mobility management function (AMF) proxy towards an authentication server function (AUSF) in a fifth generation core (5GC) and as an authentication, authorization, and accounting (AAA) proxy towards a wireless connection.
12 . The method according to claim 5 , wherein the UE identifier is a subscription concealed identifier (SUCI).
13 . The method according to claim 5 , wherein the UE identifier serves as a fifth generation core (5GC) credential used in a non-seamless wireless offload (NSWO) connection.
14 . An apparatus comprising:
at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to at least: request, by a user equipment (UE), a wireless connection to a network entity; receive, by the UE, from the network entity, an identity request; and in response to the identity request, cause transmission, by the UE, an identity response comprising a UE identifier to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identifier.
15 . The apparatus according to claim 14 , wherein the wireless connection is a non-seamless wireless offload (NSWO) connection to the network entity during an extensible authentication protocol (EAP) procedure.
16 . The apparatus according to claim 14 , wherein the UE identifier is a subscription concealed identifier (SUCI) used for regular 3rd generation partnership project (3GPP) access or non-3GPP access to a fifth generation core (5GC).
17 . The apparatus according to claim 14 , wherein the UE identifier serves as a fifth generation core (5GC) credential used in a non-seamless wireless offload (NSWO) connection.
18 . An apparatus comprising:
at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to at least: receive, by a network function, from a network entity, a UE identifier; cause transmission, by the network function, to an authentication function, of the UE identifier and a wireless connection indicator; and upon successful authentication using the UE identifier, send a master key received from the authentication function to the network entity.
19 . The apparatus according to claim 18 , wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus, upon successful authentication using the UE identifier, to store, by the network function, a permanent UE identifier received from the authentication function, and wherein the permanent UE identifier is a subscription permanent identifier (SUPI) derived from the UE identifier.
20 . The apparatus according to claim 18 , wherein the wireless connection indicator indicates that an extensible authentication protocol (EAP) procedure is triggered for non-seamless wireless offload (NSWO) connection purposes.
21 . The apparatus according to claim 18 , wherein the authentication function is configured to determine an authentication type using the wireless connection indicator and trigger the extensible authentication protocol (EAP) procedure for non-seamless wireless offload (NSWO) connection purposes in accordance with the authentication type.
22 . The apparatus according claim 18 wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus to at least:
cause transmission, by the network function, to a unified data management (UDM), of a registration request message for registering a UE; and
upon receiving, at the network function, from the UDM, a deregistration message for deregistering the UE, trigger a termination of the wireless connection to the network entity.
23 . The apparatus according to claim 18 , wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus to at least:
receive, at the network function, the master key and a subscription permanent identifier (SUPI), wherein the master key is established as a result of a key derivation process based on, at least in part, a serving network name provided by the network function.
24 . The apparatus according to claim 18 , wherein the network function is configured to be used as an access and mobility management function (AMF) proxy towards an authentication server function (AUSF) in a fifth generation core (5GC) and as an authentication, authorization, and accounting (AAA) proxy towards the wireless connection.
25 . The apparatus according to claim 18 , wherein the UE identifier is a subscription concealed identifier (SUCI).
26 . The apparatus according to claim 18 , wherein the UE identifier serves as a fifth generation core (5GC) credential used in a non-seamless wireless offload (NSWO) connection.Join the waitlist — get patent alerts
Track US2023016347A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.