US2023403554A1PendingUtilityA1

Handling of multiple authentication procedures in 5g

Assignee: ERICSSON TELEFON AB L MPriority: Apr 29, 2019Filed: Aug 29, 2023Published: Dec 14, 2023
Est. expiryApr 29, 2039(~12.8 yrs left)· nominal 20-yr term from priority
H04W 12/06H04W 12/106H04W 12/0431H04W 12/0433H04L 63/0884H04L 9/3297H04L 9/0891H04L 9/0894
76
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method by an AUSF of a home PLMN configured to communicate through an interface with electronic devices is provided. A first authentication request is received from a first PLMN that is authenticating an electronic device. A first security key used for integrity protection of messages delivered from the home PLMN to the electronic device is obtained. A second authentication request is received from a second PLMN that is authenticating the electronic device. A second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device is obtained. A message protection request is received. Which of the first security key and the second security key is a latest security key is determined. The latest security key is used to protect a message associated with the message protection request.

Claims

exact text as granted — not AI-modified
1 . A host computer, comprising:
 processing circuitry configured to provide user data; and   a communication interface configured to forward the user data to a cellular network for transmission to a user equipment (UE), wherein the cellular network comprises an Authentication Server Function, AUSF, of a home public land mobile network, PLMN, configured to communicate through an interface with electronic devices, the AUSF configured to perform operations comprising:   receiving a first authentication request from a first PLMN that is authenticating an electronic device;   obtaining a first security key used for integrity protection of messages delivered from the home PLMN to the electronic device, wherein the first security key is obtained in response to successful authentication based on the first authentication request;   receiving a second authentication request from a second PLMN that is authenticating the electronic device;   obtaining a second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device, wherein the second security key is obtained in response to successful authentication based on the second authentication request;   receiving a message protection request;   determining which of the first security key and the second security key is a latest security key; and   using the latest security key to protect a message associated with the message protection request.   
     
     
         2 . The host computer of  claim 1 , wherein the operations further comprise:
 generating a first time stamp indicating a first time when the first security key is obtained and associating the first time stamp with the first security key; and   generating a second time stamp indicating a second time when the second security key is obtained and associating the second time stamp with the second security key.   
     
     
         3 . The host computer of  claim 2 , wherein determining which of the first security key and the second security key is the latest security key comprises:
 obtaining the first time stamp;   obtaining the second time stamp;   responsive to the first time of the first time stamp being later than the second time of the second time stamp, determining that the first security key is the latest security key; and   responsive to the second time of the second time stamp being later than the first time of the first time stamp, determining that the second security key is the latest security key.   
     
     
         4 . The host computer of  claim 1 , wherein the operations further comprise:
 incrementing a counter when the first security key is obtained and associating a value of the counter with the first security key; and   incrementing the counter when the second security key is obtained and associating a value of the counter with the second security key.   
     
     
         5 . The host computer of  claim 4 , wherein determining which of the first security key and the second security key is the latest security key comprises:
 obtaining the value of the counter associated with the first security key;   obtaining the value of the counter associated with the second security key;   responsive to the value of the counter associated with the first security key being higher than the value of the counter associated with the second security key, determining that the first security key is the latest security key; and   responsive to the value of the counter associated with the second security key being higher than the value of the counter associated with the first security key, determining that the second security key is the latest security key.   
     
     
         6 . The host computer of  claim 1 , wherein the operations further comprise:
 responsive to the first security key being the latest security key, deleting the second security key; and   responsive to the second security key being the latest security key, deleting the first security key.   
     
     
         7 . The host computer of  claim 6 , wherein the first PLMN is of a first access type and the second PLMN is of a second access type, wherein the first security key is generated by a first instance of the AUSF associated with the first access type and the second security key is generated by a second instance of the AUSF associated with the second access type, and wherein deleting the second security key comprises:
 sending a second indication to the second instance of the AUSF to delete the second security key; and   deleting the first security key comprises:   sending a first indication to the first instance of the AUSF to delete the first security key.   
     
     
         8 . The host computer of  claim 6  wherein deleting the second security key comprises deleting the second security key responsive to the first security key being stored and deleting the first security key comprises deleting the first security key responsive to the second security key being stored. 
     
     
         9 . The host computer of  claim 1 , wherein the message protection request is a message protection request for one of a steering of roaming, SoR, message or a UE parameter update message. 
     
     
         10 . A non-transitory computer readable medium comprising instructions that, when executed by a processor in a host computer of a communication system, cause the host computer to perform operations comprising:
 providing user data; and   forwarding the user data to a cellular network, via a communication interface, for transmission to a user equipment (UE), wherein the cellular network comprises an Authentication Server Function, AUSF, of a home public land mobile network, PLMN, configured to communicate through an interface with electronic devices, the AUSF configured to perform operations comprising:   receiving a first authentication request from a first PLMN that is authenticating an electronic device;   obtaining a first security key used for integrity protection of messages delivered from the home PLMN to the electronic device, wherein the first security key is obtained in response to successful authentication based on the first authentication request;   receiving a second authentication request from a second PLMN that is authenticating the electronic device;   obtaining a second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device, wherein the second security key is obtained in response to successful authentication based on the second authentication request;   receiving a message protection request;   determining which of the first security key and the second security key is a latest security key; and   using the latest security key to protect a message associated with the message protection request.   
     
     
         11 . The non-transitory computer readable medium of  claim 10 , wherein the operations performed by the AUSF further comprise:
 generating a first time stamp indicating a first time when the first security key is obtained and associating the first time stamp with the first security key; and   generating a second time stamp indicating a second time when the second security key is obtained and associating the second time stamp with the second security key.   
     
     
         12 . The non-transitory computer readable medium of  claim 11 , wherein determining which of the first security key and the second security key is the latest security key comprises:
 obtaining the first time stamp;   obtaining the second time stamp;   responsive to the first time of the first time stamp being later than the second time of the second time stamp, determining that the first security key is the latest security key; and   responsive to the second time of the second time stamp being later than the first time of the first time stamp, determining that the second security key is the latest security key.   
     
     
         13 . The non-transitory computer readable medium of  claim 10 , wherein the operations performed by the AUSF further comprise:
 incrementing a counter when the first security key is obtained and associating a value of the counter with the first security key; and   incrementing the counter when the second security key is obtained and associating a value of the counter with the second security key.   
     
     
         14 . The non-transitory computer readable medium of  claim 13 , wherein determining which of the first security key and the second security key is the latest security key comprises:
 obtaining the value of the counter associated with the first security key;   obtaining the value of the counter associated with the second security key;   responsive to the value of the counter associated with the first security key being higher than the value of the counter associated with the second security key, determining that the first security key is the latest security key; and   responsive to the value of the counter associated with the second security key being higher than the value of the counter associated with the first security key, determining that the second security key is the latest security key.   
     
     
         15 . A method performed by a host computer in a communication system, comprising:
 providing user data; and   forwarding the user data to a cellular network, via a communication interface, for transmission to a user equipment (UE), wherein the cellular network comprises an Authentication Server Function, AUSF, of a home public land mobile network, PLMN, configured to communicate through an interface with electronic devices, the AUSF configured to perform operations comprising:   receiving a first authentication request from a first PLMN that is authenticating an electronic device;   obtaining a first security key used for integrity protection of messages delivered from the home PLMN to the electronic device, wherein the first security key is obtained in response to successful authentication based on the first authentication request;   receiving a second authentication request from a second PLMN that is authenticating the electronic device;   obtaining a second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device, wherein the second security key is obtained in response to successful authentication based on the second authentication request;   receiving a message protection request;   determining which of the first security key and the second security key is a latest security key; and   using the latest security key to protect a message associated with the message protection request.   
     
     
         16 . The method of  claim 15 , wherein the operations performed by the AUSF further comprise:
 generating a first time stamp indicating a first time when the first security key is obtained and associating the first time stamp with the first security key; and   generating a second time stamp indicating a second time when the second security key is obtained and associating the second time stamp with the second security key.   
     
     
         17 . The method of  claim 16 , wherein determining which of the first security key and the second security key is the latest security key comprises:
 obtaining the first time stamp;   obtaining the second time stamp;   responsive to the first time of the first time stamp being later than the second time of the second time stamp, determining that the first security key is the latest security key; and   responsive to the second time of the second time stamp being later than the first time of the first time stamp, determining that the second security key is the latest security key.   
     
     
         18 . The method of  claim 15 , wherein the operations performed by the AUSF further comprise:
 incrementing a counter when the first security key is obtained and associating a value of the counter with the first security key; and   incrementing the counter when the second security key is obtained and associating a value of the counter with the second security key.   
     
     
         19 . The method of  claim 18 , wherein determining which of the first security key and the second security key is the latest security key comprises:
 obtaining the value of the counter associated with the first security key;   obtaining the value of the counter associated with the second security key;   responsive to the value of the counter associated with the first security key being higher than the value of the counter associated with the second security key, determining that the first security key is the latest security key; and   responsive to the value of the counter associated with the second security key being higher than the value of the counter associated with the first security key, determining that the second security key is the latest security key.   
     
     
         20 . The method of  claim 15 , wherein the operations performed by the AUSF further comprise:
 responsive to the first security key being the latest security key, deleting the second security key; and   responsive to the second security key being the latest security key, deleting the first security key.

Join the waitlist — get patent alerts

Track US2023403554A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.