Handling of multiple authentication procedures in 5g
Abstract
A method by an AUSF of a home PLMN configured to communicate through an interface with electronic devices is provided. A first authentication request is received from a first PLMN that is authenticating an electronic device. A first security key used for integrity protection of messages delivered from the home PLMN to the electronic device is obtained. A second authentication request is received from a second PLMN that is authenticating the electronic device. A second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device is obtained. A message protection request is received. Which of the first security key and the second security key is a latest security key is determined. The latest security key is used to protect a message associated with the message protection request.
Claims
exact text as granted — not AI-modified1 . A host computer, comprising:
processing circuitry configured to provide user data; and a communication interface configured to forward the user data to a cellular network for transmission to a user equipment (UE), wherein the cellular network comprises an Authentication Server Function, AUSF, of a home public land mobile network, PLMN, configured to communicate through an interface with electronic devices, the AUSF configured to perform operations comprising: receiving a first authentication request from a first PLMN that is authenticating an electronic device; obtaining a first security key used for integrity protection of messages delivered from the home PLMN to the electronic device, wherein the first security key is obtained in response to successful authentication based on the first authentication request; receiving a second authentication request from a second PLMN that is authenticating the electronic device; obtaining a second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device, wherein the second security key is obtained in response to successful authentication based on the second authentication request; receiving a message protection request; determining which of the first security key and the second security key is a latest security key; and using the latest security key to protect a message associated with the message protection request.
2 . The host computer of claim 1 , wherein the operations further comprise:
generating a first time stamp indicating a first time when the first security key is obtained and associating the first time stamp with the first security key; and generating a second time stamp indicating a second time when the second security key is obtained and associating the second time stamp with the second security key.
3 . The host computer of claim 2 , wherein determining which of the first security key and the second security key is the latest security key comprises:
obtaining the first time stamp; obtaining the second time stamp; responsive to the first time of the first time stamp being later than the second time of the second time stamp, determining that the first security key is the latest security key; and responsive to the second time of the second time stamp being later than the first time of the first time stamp, determining that the second security key is the latest security key.
4 . The host computer of claim 1 , wherein the operations further comprise:
incrementing a counter when the first security key is obtained and associating a value of the counter with the first security key; and incrementing the counter when the second security key is obtained and associating a value of the counter with the second security key.
5 . The host computer of claim 4 , wherein determining which of the first security key and the second security key is the latest security key comprises:
obtaining the value of the counter associated with the first security key; obtaining the value of the counter associated with the second security key; responsive to the value of the counter associated with the first security key being higher than the value of the counter associated with the second security key, determining that the first security key is the latest security key; and responsive to the value of the counter associated with the second security key being higher than the value of the counter associated with the first security key, determining that the second security key is the latest security key.
6 . The host computer of claim 1 , wherein the operations further comprise:
responsive to the first security key being the latest security key, deleting the second security key; and responsive to the second security key being the latest security key, deleting the first security key.
7 . The host computer of claim 6 , wherein the first PLMN is of a first access type and the second PLMN is of a second access type, wherein the first security key is generated by a first instance of the AUSF associated with the first access type and the second security key is generated by a second instance of the AUSF associated with the second access type, and wherein deleting the second security key comprises:
sending a second indication to the second instance of the AUSF to delete the second security key; and deleting the first security key comprises: sending a first indication to the first instance of the AUSF to delete the first security key.
8 . The host computer of claim 6 wherein deleting the second security key comprises deleting the second security key responsive to the first security key being stored and deleting the first security key comprises deleting the first security key responsive to the second security key being stored.
9 . The host computer of claim 1 , wherein the message protection request is a message protection request for one of a steering of roaming, SoR, message or a UE parameter update message.
10 . A non-transitory computer readable medium comprising instructions that, when executed by a processor in a host computer of a communication system, cause the host computer to perform operations comprising:
providing user data; and forwarding the user data to a cellular network, via a communication interface, for transmission to a user equipment (UE), wherein the cellular network comprises an Authentication Server Function, AUSF, of a home public land mobile network, PLMN, configured to communicate through an interface with electronic devices, the AUSF configured to perform operations comprising: receiving a first authentication request from a first PLMN that is authenticating an electronic device; obtaining a first security key used for integrity protection of messages delivered from the home PLMN to the electronic device, wherein the first security key is obtained in response to successful authentication based on the first authentication request; receiving a second authentication request from a second PLMN that is authenticating the electronic device; obtaining a second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device, wherein the second security key is obtained in response to successful authentication based on the second authentication request; receiving a message protection request; determining which of the first security key and the second security key is a latest security key; and using the latest security key to protect a message associated with the message protection request.
11 . The non-transitory computer readable medium of claim 10 , wherein the operations performed by the AUSF further comprise:
generating a first time stamp indicating a first time when the first security key is obtained and associating the first time stamp with the first security key; and generating a second time stamp indicating a second time when the second security key is obtained and associating the second time stamp with the second security key.
12 . The non-transitory computer readable medium of claim 11 , wherein determining which of the first security key and the second security key is the latest security key comprises:
obtaining the first time stamp; obtaining the second time stamp; responsive to the first time of the first time stamp being later than the second time of the second time stamp, determining that the first security key is the latest security key; and responsive to the second time of the second time stamp being later than the first time of the first time stamp, determining that the second security key is the latest security key.
13 . The non-transitory computer readable medium of claim 10 , wherein the operations performed by the AUSF further comprise:
incrementing a counter when the first security key is obtained and associating a value of the counter with the first security key; and incrementing the counter when the second security key is obtained and associating a value of the counter with the second security key.
14 . The non-transitory computer readable medium of claim 13 , wherein determining which of the first security key and the second security key is the latest security key comprises:
obtaining the value of the counter associated with the first security key; obtaining the value of the counter associated with the second security key; responsive to the value of the counter associated with the first security key being higher than the value of the counter associated with the second security key, determining that the first security key is the latest security key; and responsive to the value of the counter associated with the second security key being higher than the value of the counter associated with the first security key, determining that the second security key is the latest security key.
15 . A method performed by a host computer in a communication system, comprising:
providing user data; and forwarding the user data to a cellular network, via a communication interface, for transmission to a user equipment (UE), wherein the cellular network comprises an Authentication Server Function, AUSF, of a home public land mobile network, PLMN, configured to communicate through an interface with electronic devices, the AUSF configured to perform operations comprising: receiving a first authentication request from a first PLMN that is authenticating an electronic device; obtaining a first security key used for integrity protection of messages delivered from the home PLMN to the electronic device, wherein the first security key is obtained in response to successful authentication based on the first authentication request; receiving a second authentication request from a second PLMN that is authenticating the electronic device; obtaining a second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device, wherein the second security key is obtained in response to successful authentication based on the second authentication request; receiving a message protection request; determining which of the first security key and the second security key is a latest security key; and using the latest security key to protect a message associated with the message protection request.
16 . The method of claim 15 , wherein the operations performed by the AUSF further comprise:
generating a first time stamp indicating a first time when the first security key is obtained and associating the first time stamp with the first security key; and generating a second time stamp indicating a second time when the second security key is obtained and associating the second time stamp with the second security key.
17 . The method of claim 16 , wherein determining which of the first security key and the second security key is the latest security key comprises:
obtaining the first time stamp; obtaining the second time stamp; responsive to the first time of the first time stamp being later than the second time of the second time stamp, determining that the first security key is the latest security key; and responsive to the second time of the second time stamp being later than the first time of the first time stamp, determining that the second security key is the latest security key.
18 . The method of claim 15 , wherein the operations performed by the AUSF further comprise:
incrementing a counter when the first security key is obtained and associating a value of the counter with the first security key; and incrementing the counter when the second security key is obtained and associating a value of the counter with the second security key.
19 . The method of claim 18 , wherein determining which of the first security key and the second security key is the latest security key comprises:
obtaining the value of the counter associated with the first security key; obtaining the value of the counter associated with the second security key; responsive to the value of the counter associated with the first security key being higher than the value of the counter associated with the second security key, determining that the first security key is the latest security key; and responsive to the value of the counter associated with the second security key being higher than the value of the counter associated with the first security key, determining that the second security key is the latest security key.
20 . The method of claim 15 , wherein the operations performed by the AUSF further comprise:
responsive to the first security key being the latest security key, deleting the second security key; and responsive to the second security key being the latest security key, deleting the first security key.Join the waitlist — get patent alerts
Track US2023403554A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.