US2023016347A1PendingUtilityA1

Method, apparatus, and computer program product for authentication using a user equipment identifier

Assignee: NOKIA TECHNOLOGIES OYPriority: Jul 19, 2021Filed: Jul 14, 2022Published: Jan 19, 2023
Est. expiryJul 19, 2041(~15 yrs left)· nominal 20-yr term from priority
H04W 84/12H04L 63/162H04W 12/06H04W 12/72H04W 12/069H04W 12/041
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, computer program products, and apparatuses are provided for enabling a user equipment (UE) to connect to the wireless access network that support non-seamless wireless local area network (WLAN) offload (NSWO), such as using the UE's fifth generation (5G) credentials. An apparatus may include a processor and a memory storing computer program code configured to cause the apparatus to request, by the UE, a wireless connection to a network entity; receive, by the UE, from the network entity, an identity request; and in response to the identity request, cause transmission, by the UE, an identity response including a UE identifier to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identifier.

Claims

exact text as granted — not AI-modified
That which is claimed is: 
     
         1 . A method comprising:
 requesting, by a user equipment (UE), a wireless connection to a network entity;   receiving, by the UE, from the network entity, an identity request; and   in response to the identity request, causing transmission, by the UE, of an identity response comprising a UE identifier to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identifier.   
     
     
         2 . The method according to  claim 1 , wherein the wireless connection is a non-seamless wireless offload (NSWO) connection to the network entity during an extensible authentication protocol (EAP) procedure. 
     
     
         3 . The method according to  claim 1 , wherein the UE identifier is a subscription concealed identifier (SUCI) used for regular 3rd generation partnership project (3GPP) access or non-3GPP access to a fifth generation core (5GC). 
     
     
         4 . The method according to  claim 1 , wherein the wireless connection is a non-seamless wireless offload (NSWO) connection, and wherein the UE identifier serves as a fifth generation core (5GC) credential used in the NSWO connection. 
     
     
         5 . A method comprising:
 receiving, by a network function, from a network entity, a user equipment (UE) identifier;   causing transmission, by the network function, to an authentication function, of the UE identifier and a wireless connection indicator; and   upon successful authentication using the UE identifier, sending a master key received from the authentication function to the network entity.   
     
     
         6 . The method according to  claim 5 , further comprising storing, by the network function upon successful authentication using the UE identifier, a permanent UE identifier received from the authentication function, wherein the permanent UE identifier is a subscription permanent identifier (SUPI) derived from the UE identifier. 
     
     
         7 . The method according to  claim 5 , wherein the wireless connection indicator indicates that an extensible authentication protocol (EAP) procedure is triggered for non-seamless wireless offload (NSWO) connection purposes. 
     
     
         8 . The method according to  claim 5 , wherein the authentication function is configured to determine an authentication type using the wireless connection indicator and trigger an extensible authentication protocol (EAP) procedure for non-seamless wireless offload (NSWO) connection purposes in accordance with the authentication type. 
     
     
         9 . The method according  claim 5 , further comprising:
 causing transmission, by the network function, to a unified data management (UDM), of a registration request message for registering the UE; and   upon receiving, at the network function, from the UDM, a deregistration message for deregistering the UE, triggering a termination of a wireless connection to the network entity.   
     
     
         10 . The method according  claim 5 , further comprising:
 receiving, at the network function, the master key and a subscription permanent identifier (SUPI), wherein the master key is established as a result of a key derivation process based on, at least in part, a serving network name provided by the network function.   
     
     
         11 . The method according to  claim 5 , wherein the network function is configured to be used as an access and mobility management function (AMF) proxy towards an authentication server function (AUSF) in a fifth generation core (5GC) and as an authentication, authorization, and accounting (AAA) proxy towards a wireless connection. 
     
     
         12 . The method according to  claim 5 , wherein the UE identifier is a subscription concealed identifier (SUCI). 
     
     
         13 . The method according to  claim 5 , wherein the UE identifier serves as a fifth generation core (5GC) credential used in a non-seamless wireless offload (NSWO) connection. 
     
     
         14 . An apparatus comprising:
 at least one processor; and   at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to at least:   request, by a user equipment (UE), a wireless connection to a network entity;   receive, by the UE, from the network entity, an identity request; and   in response to the identity request, cause transmission, by the UE, an identity response comprising a UE identifier to the network entity such that the UE is configured to establish a security context with the network entity upon successful authentication using the UE identifier.   
     
     
         15 . The apparatus according to  claim 14 , wherein the wireless connection is a non-seamless wireless offload (NSWO) connection to the network entity during an extensible authentication protocol (EAP) procedure. 
     
     
         16 . The apparatus according to  claim 14 , wherein the UE identifier is a subscription concealed identifier (SUCI) used for regular 3rd generation partnership project (3GPP) access or non-3GPP access to a fifth generation core (5GC). 
     
     
         17 . The apparatus according to  claim 14 , wherein the UE identifier serves as a fifth generation core (5GC) credential used in a non-seamless wireless offload (NSWO) connection. 
     
     
         18 . An apparatus comprising:
 at least one processor; and   at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to at least:   receive, by a network function, from a network entity, a UE identifier;   cause transmission, by the network function, to an authentication function, of the UE identifier and a wireless connection indicator; and   upon successful authentication using the UE identifier, send a master key received from the authentication function to the network entity.   
     
     
         19 . The apparatus according to  claim 18 , wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus, upon successful authentication using the UE identifier, to store, by the network function, a permanent UE identifier received from the authentication function, and wherein the permanent UE identifier is a subscription permanent identifier (SUPI) derived from the UE identifier. 
     
     
         20 . The apparatus according to  claim 18 , wherein the wireless connection indicator indicates that an extensible authentication protocol (EAP) procedure is triggered for non-seamless wireless offload (NSWO) connection purposes. 
     
     
         21 . The apparatus according to  claim 18 , wherein the authentication function is configured to determine an authentication type using the wireless connection indicator and trigger the extensible authentication protocol (EAP) procedure for non-seamless wireless offload (NSWO) connection purposes in accordance with the authentication type. 
     
     
         22 . The apparatus according  claim 18  wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus to at least:
 cause transmission, by the network function, to a unified data management (UDM), of a registration request message for registering a UE; and 
 upon receiving, at the network function, from the UDM, a deregistration message for deregistering the UE, trigger a termination of the wireless connection to the network entity. 
 
     
     
         23 . The apparatus according to  claim 18 , wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the apparatus to at least:
 receive, at the network function, the master key and a subscription permanent identifier (SUPI), wherein the master key is established as a result of a key derivation process based on, at least in part, a serving network name provided by the network function.   
     
     
         24 . The apparatus according to  claim 18 , wherein the network function is configured to be used as an access and mobility management function (AMF) proxy towards an authentication server function (AUSF) in a fifth generation core (5GC) and as an authentication, authorization, and accounting (AAA) proxy towards the wireless connection. 
     
     
         25 . The apparatus according to  claim 18 , wherein the UE identifier is a subscription concealed identifier (SUCI). 
     
     
         26 . The apparatus according to  claim 18 , wherein the UE identifier serves as a fifth generation core (5GC) credential used in a non-seamless wireless offload (NSWO) connection.

Join the waitlist — get patent alerts

Track US2023016347A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.