WO2025210568A1 - Enhanced deregistration of user equipment and/or user profiles associated with user equipment - Google Patents

Enhanced deregistration of user equipment and/or user profiles associated with user equipment

Info

Publication number
WO2025210568A1
WO2025210568A1 PCT/IB2025/053547 IB2025053547W WO2025210568A1 WO 2025210568 A1 WO2025210568 A1 WO 2025210568A1 IB 2025053547 W IB2025053547 W IB 2025053547W WO 2025210568 A1 WO2025210568 A1 WO 2025210568A1
Authority
WO
WIPO (PCT)
Prior art keywords
identifier
user
user equipment
enhanced
registration
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/IB2025/053547
Other languages
French (fr)
Inventor
Bighnaraj PANIGRAHI
Saurabh Khare
Srinivas GARIKIPATI
Ranganathan MAVUREDDI DHANASEKARAN
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nokia Technologies Oy
Original Assignee
Nokia Technologies Oy
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nokia Technologies Oy filed Critical Nokia Technologies Oy
Publication of WO2025210568A1 publication Critical patent/WO2025210568A1/en
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • H04W60/06De-registration or detaching
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • H04W60/04Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration using triggered events

Definitions

  • This disclosure is related to the field of communication systems and, in particular, to next generation networks.
  • Next generation networks such as Fifth Generation (5G) and beyond (e.g., Sixth Generation (6G)), denote the next major phase of mobile telecommunications standards beyond Fourth Generation (4G) standards.
  • 5G Fifth Generation
  • 6G Sixth Generation
  • next generation networks may be enhanced in terms of radio access and network architecture to deliver faster data rates and more reliability.
  • communications may be intercepted or suffer from other kinds of attacks.
  • 3GPP 3rd Generation Partnership Project
  • 3GPP has set forth security mechanisms for mobile networks, and the security procedures performed within the mobile networks. Due to the importance of security in 5G systems and beyond, it is desirable to continue to develop improved security mechanisms.
  • a subscription of a UE may be shared among multiple (e.g., human) users. Thus, one or more user profiles may be linked to the subscription of the UE.
  • the UE may register with the core network without a user login (referred to herein as a UE registration), or the UE may register a user profile with the core network according to the present user login (referred to herein as a user registration). In either case, when a new user logs into the UE, for example, the UE will initiate a subsequent registration procedure to register the new user profile associated with the new user login.
  • an enhanced deregistration procedure is used to “softly” deregister the previous registration to the UE or the previous user profile.
  • the previous registration is held in a suspended state and data related to the previous registration (e.g., context information) is retained in the core network and/or the UE, instead of being released as with a full or complete deregistration procedure.
  • data related to the previous registration e.g., context information
  • the previous registration may be re-activated based on user login changes at the UE.
  • One technical benefit is end-to-end signaling may be reduced at each switch of a user at the UE, as full deregistration may be avoided.
  • Another benefit is re-authentication of the UE or a user may be avoided when a previous registration is reactivated, as data related to the previous registration is retained.
  • security information e.g., security keys
  • data related to the previous registration e.g., context information
  • an apparatus comprises an access and mobility management function (AMF) of a core network.
  • the AMF comprises at least one processor, and at least one memory storing instructions, that when executed by the at least one processor, cause the AMF at least to perform identifying subscription data comprising a UE subscription for a UE, and one or more user profiles linked to the UE subscription.
  • the AMF further performs a registration procedure to register a first identifier from a plurality of identifiers corresponding with the user equipment, where the plurality of identifiers comprises a UE subscription identifier of the UE and one or more user profile identifiers of the one or more user profiles.
  • the AMF further receives a registration message from the UE regarding registration of a second identifier from the plurality of identifiers different than the first identifier, and initiates an enhanced deregistration procedure for the first identifier in response to the registration message by transitioning the first identifier to a suspended state, and retaining context information associated with the first identifier when in the suspended state.
  • FIGS. 6A-6B illustrate a UP security mechanism.
  • FIG. 7 illustrates a key hierarchy of a 5G system.
  • FIG. 8 illustrates the NAS functional layer and the AS functional layer in a 5G system.
  • FIG. 9 is a diagram illustrating a shared subscription in an illustrative embodiment.
  • FIG. 10 is a block diagram of network elements/functions for providing security management in an illustrative embodiment.
  • FIG. 12 is a flow chart illustrating a method of performing an enhanced deregistration procedure in an illustrative embodiment.
  • FIG. 13 illustrates registration procedures in an illustrative embodiment.
  • FIG. 18 is a flow chart illustrating a method of registration management at a UE in an illustrative embodiment.
  • FIG. 19 is a flow chart illustrating a method of enhanced deregistration at an SMF in an illustrative embodiment.
  • FIG. 20 is a flow chart illustrating a method of enhanced deregistration at a UPF in an illustrative embodiment.
  • FIG. 21 is a flow chart illustrating a method of enhanced deregistration at a PCF in an illustrative embodiment.
  • FIG. 22 is a flow chart illustrating additional steps of an enhanced deregistration procedure in an illustrative embodiment.
  • FIG. 23 is a flow chart illustrating additional steps of registration management at an AMF in an illustrative embodiment.
  • FIG. 24 is a flow chart illustrating additional steps of registration management at an AMF in an illustrative embodiment.
  • RAN 102 provides radio or wireless connectivity to a UE 106, and connects the UE 106 to the 5GC 104.
  • RAN 102 may comprise a Next Generation Radio Access Network (NG-RAN), a non-3GPP access network, and/or another type of RAN connecting to 5GC 104.
  • RAN 102 may support Evolved-UMTS Terrestrial Radio Access Network (E-UTRAN) access (e.g., through an eNodeB (eNB), gNodeB (gNB), and/or ng-eNodeB (ng-eNB)), Wireless Local Area Network (WLAN) access, satellite radio access, new Radio Access Technologies (RAT), etc.
  • E-UTRAN Evolved-UMTS Terrestrial Radio Access Network
  • eNB eNodeB
  • gNB gNodeB
  • ng-eNB ng-eNodeB
  • WLAN Wireless Local Area Network
  • a 5G access network may also support fixed access.
  • 5GC 104 interconnects RAN 102 with a data network (DN) 108.
  • 5GC 104 is comprised of Network Functions (NF) 110, which may be implemented either as a network element on dedicated hardware, as a software instance running on dedicated hardware, as a virtualized function instantiated on an appropriate platform (e.g., a cloud infrastructure), etc.
  • Data network 108 may be an operator external public or private data network, or an intra-operator data network (e.g., for IP Multimedia Subsystem (IMS) services).
  • IMS IP Multimedia Subsystem
  • a UE 106 also referred to as a mobile terminal
  • UE 106 may include an end user device, such as a mobile phone (e.g., smartphone), a tablet, a computer with a mobile broadband adapter, etc.
  • UE 106 may be enabled for voice services, data services, Machine-to-Machine (M2M) or Machine Type Communications (MTC) services, and/or other services.
  • M2M Machine-to-Machine
  • MTC Machine Type Communications
  • the control plane of the 5GC 104 further includes a Network Exposure Function (NEF) 224, a NF Repository Function (NRF) 226, a Service Communication Proxy (SCP) 228, a Network Slice Admission Control Function (NSACF) 230, a Network Slice-specific and SNPN Authentication and Authorization Function (NSSAAF) 232, and an Edge Application Server Discovery Function (EASDF) 234.
  • the user plane of the 5GC 104 includes one or more User Plane Functions (UPF) 240 that communicate with data network 108.
  • UPF User Plane Functions
  • a UE 106 is able to access the control plane and the user plane of the 5GC 104 through RAN 102.
  • FIG. 3 illustrates security mechanisms 300 within a 5G system 100.
  • One of the security mechanisms 300 is primary authentication and key agreement between the network (e.g., AMF 212/UDM 218) and the UE 106.
  • Other security mechanisms 300 are used to protect signaling between the network and the UE 106.
  • a security mechanism 300 is used to protect Non-Access Stratum (NAS) signaling between the AMF 212 and the UE 106.
  • NAS Non-Access Stratum
  • Yet another security mechanism 300 is used for roaming and interconnect security, such as to protect control plane signaling between a Security Edge Protection Proxy (SEPP) 310 and another network 301 (e.g., a visited 5G network), and/or to protect user plane data between the UPF 240 and the other network 301.
  • SEPP Security Edge Protection Proxy
  • FIGS. 4A-4B illustrate the primary authentication procedure that provides mutual authentication between the UE 106 and the network (e.g., AMF 212/UDM 218).
  • the purpose of the primary authentication and key agreement procedures is to enable mutual authentication between UE 106 and the home network of the UE 106, and provide keying material that can be used between the UE 106 and the serving network in subsequent security procedures (e.g., NAS and AS security procedures).
  • the home network e.g., Home Public Land Mobile Network (HPLMN)
  • HPLMN Home Public Land Mobile Network
  • the serving network has radio access equipment able to communicate with the UE 106 via radio signals.
  • the keying material generated by the primary authentication and key agreement procedure results in an anchor key (called the KSEAF key) provided by the AUSF 210 of the home network to the Security Anchor Function (SEAF) of the serving network.
  • the SEAF provides authentication functionality via the AMF 212 in the serving network, and supports primary authentication using a Subscription Concealed Identifier (SUCI) that contains the concealed Subscription Permanent Identifier (SUPI).
  • SUCI Subscription Concealed Identifier
  • the SUPI is a globally unique 5G identifier allocated to each subscriber in the 5G system 100.
  • the SUCI is composed of a SUPI type, a Home Network Identifier (HN-ID) identifying the home network of the subscriber, a Routing Indicator (RID) that is assigned to the subscriber by the home network operator and provisioned in the Universal Subscriber Identity Module (USIM) of the UE 106, a Protection Scheme Identifier, a Home Network Public Key Identifier, and a Scheme Output.
  • the anchor key (KSEAF) is derived from an intermediate key called the KAUSF key.
  • the KAUSF key is established between the UE 106 and the home network (AUSF 210) resulting from the primary authentication procedure.
  • FIG. 4A is a signaling diagram that illustrates initiation of primary authentication, such as described in 3GPP TS 33.501 (Release 18), which is incorporated by reference as if fully included herein.
  • the UE 106 transmits an N1 message 411 (i.e., an initial NAS message) to the serving network 406 (e.g., the AMF 212 of the serving network 406), such as a Registration Request.
  • the serving network 406 may also be referred to as a serving PLMN, a visited-PLMN (VPLMN), etc., in a roaming scenario.
  • the UE 106 uses the SUCI or a 5G Global Unique Temporary Identifier (5G-GUTI) in the Registration Request.
  • 5G-GUTI 5G Global Unique Temporary Identifier
  • SEAF 402 of the AMF 212 may initiate an authentication with the UE 106 during any procedure establishing a signaling connection with the UE 106.
  • SEAF 402 invokes the Nausf_UEAuthentication service toward the home network 404 (e.g., HPLMN) by sending a Nausf_UEAuthentication_Authenticate Request message 412 to AUSF 210 to initiate an authentication.
  • the home network 404 e.g., HPLMN
  • Nausf_UEAuthentication_Authenticate Request message 412 includes the SUCI or SUPI, and the serving network name (SN-Name).
  • AUSF 210 Upon receiving the Nausf_UEAuthentication_Authenticate Request message 412, AUSF 210 checks that the requesting SEAF 402 in the serving network 406 is entitled to use the serving network name (SNN) in the Nausf_UEAuthentication_Authenticate Request message 412 by comparing the serving network name with the expected serving network name. When the serving network 406 is authorized to use the serving network name, AUSF 210 sends a Nudm_UEAuthentication_Get Request message 413 to UDM 218 of the home network.
  • the Nudm_UEAuthentication_Get Request message 413 includes the SUCI or SUPI, and the serving network name.
  • FIG. 4B is a signaling diagram that illustrates a primary authentication procedure, such as described in 3GPP TS 33.501.
  • 5G Authentication and Key Agreement AKA
  • GAP- AKA' Extensible Authentication Protocol AKA prime
  • UDM 218 creates a 5G Home Environment Authentication Vector (5G HE AV) for the selected authentication method.
  • UDM 218 derives the KAUSF key and calculates an expected response (XRES*) to a challenge.
  • UDM 218 creates the 5G HE AV comprising an authentication token (AUTN), the expected response (XRES*), the KAUSF key, and a random challenge (RAND).
  • AUTN authentication token
  • XRES* expected response
  • RAND random challenge
  • AUSF 210 removes the KSEAF key to generate a 5G Serving Environment Authentication Vector (5G SE AV) that includes the authentication token (AUTN), hash expected response (HXRES*), and the random challenge (RAND).
  • AUSF 210 sends a Nausf_UEAuthentication_Authenticate Response message 415 to SEAF 402 that includes the 5G SE AV.
  • SEAF 402 sends the authentication token (AUTN) and the random challenge (RAND) to the UE 106 in a NAS message Authentication Request message 416.
  • the ME of the UE 106 computes RES* from RES, and calculates the KAUSF key from CKIIIK and the KSEAF key from The UE 106 sends a NAS message Authentication Response message 417 to SEAF 402 that includes RES*.
  • SEAF 402 computes HRES* from RES*, and compares HRES* and HXRES*. If they coincide, SEAF 402 considers the authentication successful from the serving network point of view.
  • SEAF 402 sends RES*, as received from the UE 106, in a Nausf_UEAuthentication_Authenticate Request message 418 to AUSF 210.
  • 5G divides UE management into the Non-Access Stratum (NAS) and the Access Stratum (AS).
  • the NAS layer protocol manages the connection between a UE 106 and 5GC 104 (i.e., AMF 212), and the AS layer protocol manages the radio layer between a UE 106 and the RAN 102 (e.g., gNB 302) using RRC protocol.
  • NAS security ensures that NAS signaling between a UE 106 and AMF 212 is protected on the control plane
  • AS security ensures that RRC messages on the control plane and user plane traffic (e.g., IP packets) on the user plane are protected.
  • FIG. 5 illustrates NAS and AS security procedures, such as described in 3GPP TS 33.501 (sections 6.4 and 6.7, respectively).
  • a NAS security mode command procedure is performed to establish a NAS security context between the UE 106 and the AMF 212.
  • Each AMF 212 is configured via network management with lists of algorithms that are allowed for usage. Presently, there is one list for NAS integrity algorithms and one for NAS ciphering algorithms that are ordered according to a priority decided by the operator.
  • AMF 212 selects one NAS ciphering algorithm and one NAS integrity protection algorithm, and derives the NAS integrity key and the NAS encryption key (e.g., KNASint and KNASenc) for the selected algorithms.
  • KNASint and KNASenc the NAS encryption key
  • AMF 212 initiates the NAS security mode command procedure by sending a NAS Security Mode Command message 511 to the UE 106.
  • AMF 212 activates NAS integrity protection before sending the NAS Security Mode Command message 511.
  • the NAS Security Mode Command message 511 contains the previously received UE security capabilities, the selected NAS algorithms, a key set identifier (i.e., ngKSI (next generation key set identifier)), and a message authentication code (NAS- MAC) generated by the AMF 212 for integrity protection of the NAS Security Mode Command message 511.
  • the NAS Security Mode Command message 511 is integrity protected (but not ciphered) with the NAS integrity key based on the KAMF key indicated by the ngKSI.
  • AMF 212 activates NAS uplink de-ciphering after sending the NAS Security Mode Command message 511.
  • the UE 106 On receipt of the NAS Security Mode Command message 511, the UE 106 verifies the integrity of the NAS Security Mode Command using the indicated NAS integrity algorithm and the NAS integrity key based on the KAMF key indicated by the ngKSI. The UE 106, with the received algorithms, generates the NAS integrity key and the NAS encryption key in the same manner as AMF 212. If verification is successful, the UE 106 begins NAS integrity protection and ciphering/deciphering with the security context indicated by the ngKSI. The UE 106 sends a NAS Security Mode Complete message 512 to AMF 212 that is ciphered and integrity protected.
  • the UE 106 replies with a NAS Security Mode Reject message (not shown).
  • AMF 212 de-ciphers and checks the integrity of the received NAS Security Mode Complete message 512 using the key and algorithm indicated in the NAS Security Mode Command message 511.
  • AMF 212 activates NAS downlink ciphering after receiving the NAS Security Mode Complete message 512.
  • AS security includes RRC security and User Plane (UP) security.
  • RRC security RRC integrity protection and RRC confidentiality protection are provided by the Packet Data Convergence Protocol (PDCP) layer between a UE 106 and a gNB 302.
  • the 5GC 104 supports a PDU connectivity service that provides exchange of PDUs between UE 106 and a data network 108 (identified by a Data Network Name (DNN)) over the user plane.
  • DNN Data Network Name
  • Security of user plane traffic in 5G networks is controlled by the UP security policy.
  • the SMF 214 provides the UP security policy for a Packet Data Unit (PDU) session to the gNB 302 (or ng-eNB) during the PDU session establishment procedure.
  • the UP security policy indicates whether UP confidentiality protection and/or UP integrity protection are activated for Data Radio Bearers (DRBs) belonging to that PDU session.
  • DRBs Data Radio Bearers
  • An AS security mode command procedure is performed to establish an AS security context between the UE 106 and the NG-RAN 502.
  • AMF 212 sends the UE 5G security capabilities with ciphering and integrity protected algorithms and the K 8 NB key in an NG Application Protocol (NGAP) Initial Context Setup message 513 to the NG- RAN 502 (e.g., gNB 302).
  • NGAP NG Application Protocol
  • each gNB 302 is configured via network management with lists of algorithms that are allowed for usage. There is one list for integrity algorithms and one for ciphering algorithms that are ordered according to a priority decided by the operator.
  • the gNB 302 sends an integrity protected AS Security Mode Command message 514 to the UE 106, which contains the selected AS integrity algorithm and AS ciphering algorithm, and the message authentication code (MAC-I) generated by the gNB 302 for integrity protection of the AS Security Mode Command message 514.
  • MAC-I message authentication code
  • the UE 106 On receipt of the AS Security Mode Command message 514, the UE 106 derives the RRC integrity key (KRRCint) and the RRC ciphering key (KRRCenc) similar to the gNB 302 based on the selected AS integrity algorithm and AS ciphering algorithm. UE 106 verifies the AS Security Mode Command integrity and, if successful, starts RRC integrity protection and RRC downlink de-ciphering. The UE 106 then sends an AS Security Mode Complete message 515 with integrity protection to the gNB 302. The AS Security Mode Complete message 515 contains the MAC-I generated by the UE 106 for integrity protection of the AS Security Mode Complete message 515. The RRC uplink ciphering at the UE 106 starts after sending the AS Security Mode Complete message 515. Integrity of the AS Security Mode Complete message 515 is verified at the gNB 302, and the gNB 302 starts RRC uplink deciphering.
  • KRRCint the RRC integrity key
  • KRRCenc R
  • FIGS. 6A-6B illustrate a UP security mechanism.
  • SMF 214 stores a UP security policy regarding integrity protection and encryption for the user plane of a PDU session.
  • integrity protection is a mechanism where the receiver of data is able to verify that the received data was actually sent by the sender (i.e., unaltered by an intermediary).
  • a sender may use an integrity algorithm (NIA) to compute a message authentication code (MAC), which is appended to a message when sent.
  • MAC message authentication code
  • a receiver computes an expected MAC (XMAC) on the message received in the same way as the sender computed its MAC on the message sent, and verifies the data integrity by comparing the computed MAC to the received MAC.
  • NIA integrity algorithm
  • XMAC expected MAC
  • Encryption or ciphering is a process of encoding data so that it may not be accessed by unauthorized parties.
  • a sender may use a ciphering or encryption algorithm (NEA) to encrypt a plaintext block with an associated encryption key to produce a ciphertext block.
  • the plaintext may be recovered, such as at a receiver, by decrypting the ciphertext block in a similar manner with the encryption key.
  • SMF 214 is configured to provide the UP security policy for the PDU session to NG-RAN 502 (e.g., gNB 302) during the PDU session establishment procedure, as specified in 3GPP TS 23.502 (Release 18), which is incorporated by reference as if fully included herein.
  • the UP security policy indicates whether UP confidentiality protection and/or UP integrity protection is activated or not for all DRBs belonging to that PDU session.
  • the UP security policy is used to activate UP confidentiality protection and/or UP integrity protection in the UE 106 and NG- RAN 502 for all DRBs belonging to the PDU session.
  • FIG. 6A illustrates an abbreviated version of the PDU session establishment procedure.
  • PDU session establishment is the process of establishing a user plane data path between a UE 106 and the 5GC 104.
  • a PDU session is a logical connection or association between a UE and a data network, such as the internet or a private network.
  • AMF 212 receives a PDU session establishment request 611, such as from UE 106, requesting establishment of a new PDU session.
  • AMF 212 selects an SMF 214, and sends a Nsmf_PDUSession_CreateSMContext Request 612 to the SMF 214 indicating the PDU Session ID along with other information.
  • SMF 214 creates a session management (SM) context for the PDU session, which includes determining and/or storing a UP security policy 620 for integrity protection and encryption of the user plane for the PDU session.
  • SMF 214 replies to AMF 212 with a Nsmf_PDUSession_CreateSMContext Response 613.
  • the SMF 214 provides the UP security policy 620 for a PDU session to the gNB 302 during the PDU session establishment procedure.
  • SMF 214 invokes the Namf_Communication_NlN2MessageTransfer service operation, and sends a Namf_Communication_NlN2MessageTransfer message 614 to AMF 212.
  • the Namf_Communication_NlN2MessageTransfer message 614 includes N2 SM information, which carries information that the AMF 212 forwards to the NG-RAN 502.
  • the N2 SM information includes UP security enforcement information 622 determined by the SMF 214.
  • the UP security enforcement information 622 provides the NG-RAN 502 with the UP security policy 620 for the PDU session.
  • the UP security enforcement information 622 indicates whether UP integrity protection is: “Required” (i.e., UP integrity protection shall apply for all traffic on the PDU Session), “Preferred” (i.e., UP integrity protection should apply for all traffic on the PDU Session), or “Not Needed” (i.e., UP integrity protection shall not apply on the PDU Session).
  • the UP security enforcement information 622 also indicates whether UP confidentiality protection is: “Required” (i.e., UP confidentiality protection shall apply for all traffic on the PDU Session), “Preferred” (i.e., UP confidentiality protection should apply for all traffic on the PDU Session), or “Not Needed” (i.e., UP confidentiality shall not apply on the PDU Session).
  • SMF 214 determines, at PDU session establishment, the UP security enforcement information 622 for the user plane of a PDU session based on the subscribed UP security policy which is part of SM subscription information received from UDM 218, the UP security policy stored locally in the SMF 214 that is used when UDM 218 does not provide UP security policy information, and/or the maximum supported data rate per UE for integrity protection for the DRBs, provided by the UE 106 in the integrity protection maximum data rate Information Element (IE) during PDU Session Establishment.
  • IE integrity protection maximum data rate Information Element
  • the UP security enforcement information 622 is communicated from SMF 214 to the NG- RAN 502 for enforcement as part of PDU session related information. If the UP integrity protection is determined to be “Required” or “Preferred”, SMF 214 also provides the maximum supported data rate per UE for integrity protection.
  • AMF 212 sends an N2 PDU Session Request 615 to the NG-RAN 502.
  • the N2 PDU Session Request 615 includes the N2 SM information received from the SMF 214, such as the UP security enforcement information 622.
  • NG-RAN 502 may issue an AN-specific signaling exchange with the UE 106 that is related with the information received from SMF 214.
  • the gNB 302 may initiate the RRC Connection Reconfiguration procedure, which is used to add DRBs for the PDU session.
  • the RRC Connection Reconfiguration procedure is performed after RRC security has been activated as part of the AS security mode command procedure.
  • the gNB 302 sends an RRC Connection Reconfiguration message 616 to the UE 106 for UP security activation.
  • the RRC Connection Reconfiguration message 616 contains indications for the activation of UP integrity protection and UP ciphering for each DRB according to the UP security policy 620.
  • UP integrity protection is activated for a DRB as indicated in the RRC Connection Reconfiguration message 616 and the gNB 302 does not have the Kupint key
  • the gNB 302 derives the Kupint key and UP integrity protection for the DRB starts at the gNB 302.
  • the gNB 302 derives the Kupenc key and UP ciphering for the DRB starts at the gNB 302.
  • the UE 106 On receipt of the RRC Connection Reconfiguration message 616, the UE 106 verifies the RRC Connection Reconfiguration integrity protection. If successful, the UE 106 performs the following. When UP integrity protection is activated for a DRB as indicated in the RRC Connection Reconfiguration message 616 and the UE 106 does not have the Kupint key, the UE 106 derives the Kupint key and UP integrity protection for the DRB starts at the UE 106. Similarly, when UP ciphering is activated for the DRB as indicated in the RRC Connection Reconfiguration message 616 and the UE 106 does not have the Kupenc key, the UE 106 derives the Kupenc key and UP ciphering for the DRB starts at the UE 106. The UE 106 sends an RRC Connection Reconfiguration Complete message 617 to the gNB 302.
  • FIG. 7 illustrates a key hierarchy 700 of a 5G system 100, such as in 3GPP TS 33.501.
  • the keys related to authentication include the following keys: K 701, and CK/IK 702.
  • the key hierarchy 700 includes the following keys: KAUSF 703, KSEAF 704, KAMF 705, K N ASint 706, K N ASenc 707, K N3 IWF 708, K gNB 709, K RRC int 710, K RR cenc 711, Kupint 712, and Kupenc 713.
  • the keys for AUSF 210 in the home network 404 include the KAUSF key 703 derived by the ME of a UE 106 and AUSF 210 from CK', IK' in case of EAP-AKA', or by the ME and the ARPF of UDM 218 from CK, IK 702 in case of 5G AKA.
  • the KSEAF key 704 is the anchor key derived by the ME and AUSF 210 from the KAUSF key 703.
  • the key for AMF 212 in the serving network 406 is the KAMF key 705 derived by the ME and the SEAF 402 from the KSEAF key 704.
  • the keys for NAS signaling include the KNASint key 706 derived by the ME and AMF 212 from the KAMF key 705, which is used for integrity protection of NAS signaling with a particular integrity algorithm.
  • the keys for NAS signaling also include the KNASenc key 707 derived by the ME and AMF 212 from the KAMF key 705, which is used for encryption of NAS signaling with a particular encryption algorithm.
  • the key for the NG-RAN is the K 8 NB key 709 derived by the ME and AMF 212 from the KAMF key 705.
  • the keys for RRC signaling include the KRRCint key 710 derived by the ME and the gNB 302 from the K 8 NB key 709, which is used for integrity protection of RRC signaling with a particular integrity algorithm.
  • the keys for RRC signaling further include the KRRCenc key 711 derived by the ME and the gNB 302 from the K 8 NB key 709, which is used for encryption of RRC signaling with a particular encryption algorithm.
  • the keys for UP traffic include the Kupint key 712 derived by the ME and the gNB 302 from the K 8 NB key 709, which is used for integrity protection of UP traffic between the ME and the gNB 302 with a particular integrity algorithm.
  • FIG. 8 illustrates the NAS functional layer 802 and the AS functional layer 804 in a 5G system 100.
  • the UE 106 is operatively coupled to 5G network 101.
  • the NAS functional layer 802 is between the UE 106 and AMF 212 (or Mobility Management Entity (MME)), and therefore, NAS signaling 812 may be exchanged between the UE 106 and AMF 212.
  • the AS functional layer 804 is between the UE 106 and a RAN node 800 (e.g., gNB 302).
  • RRC signaling 814 may be exchanged between the UE 106 and the RAN node 800 via one or more Signaling Radio Bearers (SRB) 816.
  • SRB Signaling Radio Bearers
  • UP traffic 818 may be exchanged between the UE 106 and the RAN node 800 via one or more Data Radio Bearers (DRB) 820.
  • DRB Data Radio Bearers
  • the UP traffic 818 may comprise UP packets 822, such as IP packets 824.
  • a subscription in a PLMN is mapped or linked to a UE 106, such as a SUPI provisioned on the USIM of the UE 106.
  • a subscription of a UE 106 may be shared by multiple users. For example, a parent may have a mobile phone with a subscription to a carrier, and the subscription may be shared by the parent and one or more of the children.
  • FIG. 9 is a diagram illustrating a shared subscription in an illustrative embodiment.
  • a subscription 910 (also referred to as a UE subscription or a 3GPP subscription) is associated with a UE 106 by a carrier operating a core network 104, such as of a 5GS 100.
  • UE 106 has a UE Identifier (ID) 906 (or UE Identity, UE subscription ID, a user subscription ID, etc.), such as a SUPI, and the subscription 910 is mapped or linked to that UE ID 906.
  • the UE 106 may also have an associated UE subscription profile 908 linked to the UE ID 906 and/or the subscription 910.
  • the core network 104 may therefore authenticate and authorize the UE 106 to access services according to the subscription 910, the UE profile 908, the UE ID 906, etc.
  • one or more users 902 may share UE 106 to access services under the subscription 910.
  • one or more user profiles 914 may be linked to the subscription 910 of the UE 106.
  • a user profile 914-1 of a first user 902-1 may be linked to the subscription 910
  • a user profile 914-2 of a second user 902-2 may be linked to the subscription 910.
  • one of the users 902 may login to the UE 106 through a user login 904.
  • one of the users 902 may be logged into their associated user profile 914 at a time to access services.
  • the user profile 914 of the logged-in user 902 is “attached” to the UE 106, and services are provided based on parameters of that user profile 914.
  • the core network 104 through one or more of its NFs 110 (such as a UDM 218, a Unified Data Repository (UDR), etc.), is configured to create or support an association between a user ID 912 (or user identity) and the subscription 910, also referred to as an identifier link.
  • the user ID 912 (e.g., user@example.com) is at least unique within the core network 104.
  • user ID 912-1 is associated with user 902-1 (which may be considered a primary user), and user ID 912-2 (which may be considered a secondary user) is associated with user 902-2.
  • the core network 104 is also configured to create or support a user profile 914 associated with a user ID 912, which is also linked to the subscription 910.
  • a user profile 914 (also referred to as a user identity profile) comprises a collection of information associated with a user 902.
  • the information of a user profile 914 may include, for example, the user ID 912, a user profile ID 916 (also referred to as a user profile reference ID) that uniquely identifies the user profile 914, authentication information or security credentials, one or more devices that can use this user profile 914, PDU session-related control data (e.g., one or more applications associated with this user profile 914, user-specific QoS settings to apply to the traffic associated with this user profile 914, a list of services available for this user profile 914, how a user is authenticated and authorized, etc.), and/or other information.
  • UE 106 is also configured with the user IDs 912 and associated user profiles 914 (or at least user profile information).
  • the subscription 910 and associated user profiles 914 may be referred to generally as subscription data related or corresponding with a UE 106.
  • an enhanced or soft deregistration procedure is introduced.
  • the enhanced deregistration procedure may be used in the core network 104 and/or the UE 106 when switching between users 902 of a UE 106 and/or switching between a user 902 and the UE 106 itself (i.e., no user 902 logged in).
  • a new user 902 e.g., user 902-2
  • the core network 104 and/or the UE 106 may initiate the enhanced deregistration procedure to “suspend” the previous registration.
  • FIG. 10 is a block diagram of network elements/functions for providing security management in an illustrative embodiment. More particularly, system 1000 of FIG. 10 comprises a UE 106 and a plurality of network elements/functions 110 (i.e., a first network element/function 110-1 and a second network element/function 110-N). It is to be appreciated that UE 106 and the network elements/functions 110 are configured to interact to provide security management. Examples of network elements/functions 110 may include, but are not limited to, an AMF 212, an SMF 214, a PCF 216, a UDM 218, a UPF 240, etc.
  • Network element/function 110-N comprises a processor 1022-N coupled to a memory 1026-N and interface circuitry 1020-N.
  • the processor 1022-N of network element/function 110-N includes a security management processing module 1024-N that may be implemented at least in part in the form of software executed by the processor 1022-N.
  • the security management processing module 1024-N performs security management described in conjunction with subsequent figures and otherwise herein.
  • the memory 1026-N includes a security management storage module 1028-N that stores data generated or otherwise used during security management operations.
  • the memories 1026-1 and 1026-N of the respective network elements/functions 110-1 and 110-N may be used to store one or more software programs that are executed by the respective processors 1022-1 and 1022-N to implement at least a portion of the functionality described herein.
  • security management operations and other functionality as described in conjunction with subsequent figures and otherwise herein may be implemented in a straightforward manner using software code executed by processors 1022-1 and 1022-N.
  • a given one of the memories 1026-1 and 1026-N may therefore be viewed as an example of what is more generally referred to herein as a computer program product or still more generally as a processor-readable storage medium that has executable program code embodied therein.
  • processor-readable storage media may include disks or other types of magnetic or optical media, in any combination.
  • Illustrative embodiments can include articles of manufacture comprising such computer program products or other processor-readable storage media.
  • the memories 1026-1 and 1026-N may more particularly comprise, for example, an electronic random-access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory.
  • RAM electronic random-access memory
  • SRAM static RAM
  • DRAM dynamic RAM
  • the latter may include, for example, non-volatile memories such as flash memory, magnetic RAM (MRAM), phase-change RAM (PC-RAM) or ferroelectric RAM (FRAM).
  • MRAM magnetic RAM
  • PC-RAM phase-change RAM
  • FRAM ferroelectric RAM
  • memory as used herein is intended to be broadly construed, and may additionally or alternatively encompass, for example, a read-only memory (ROM), a disk-based memory, or other type of storage device, as well as portions or combinations of such devices.
  • Interface circuitry 1020-1 and 1020-N of the respective network elements/functions 110-1 and 110-N illustratively comprise transceivers or other communication hardware or firmware that allows the associated system elements to communicate with one another in the manner described herein.
  • Network element/function 110-1 is configured for communication with network element/function 110-N, and vice-versa, via their respective interface circuitry 1020-1 and 1020-N. This communication involves network element/function 110-1 sending data to the network element/function 110-N, and the network element/function 110-N sending data to the network element/function 110-1. However, in alternative embodiments, other network elements may be operatively coupled between the network elements/functions 110-1 and 110-N.
  • data as used herein is intended to be construed broadly, so as to encompass any type of information that may be sent between network elements/functions (as well as between UE 106 and a core network 104) including, but not limited to, messages, identifiers, keys, indicators, user data, control data, etc.
  • FIG. 10 It is to be appreciated that the particular arrangement of components shown in FIG. 10 is an example, and numerous alternative configurations may be used in other embodiments. For example, any given network element/function can be configured to incorporate additional or alternative components and to support other communication protocols.
  • system elements may each also be configured to include components such as a processor, memory and network interface. These elements need not be implemented on separate stand-alone processing platforms, but could instead, for example, represent different functional portions of a single common processing platform.
  • FIG. 11 is a block diagram of a UE 106 in an illustrative embodiment. From a functional standpoint, the UE 106 is composed of at least two parts: Mobile Equipment (ME) 1100 and a Universal Subscriber Identity Module (USIM) 1160.
  • ME 1100 comprises a radio interface component 1102, one or more processors 1104, a memory 1106, and a user interface component 1108.
  • the UE 106 may also comprise a battery 1110.
  • Radio interface component 1102 is a hardware component or means that represents the local radio resources of the UE 106, such as a Radio Frequency (RF) unit 1120 (e.g., one or more radio transceivers) and one or more antennas 1122.
  • RF Radio Frequency
  • User interface component 1108 is a hardware component for interacting with an end user.
  • user interface component 1108 may comprise a display 1150, screen, touch screen, and/or the like (e.g., a Liquid Crystal Display (LCD), a Light Emitting Diode (LED) display, etc.).
  • User interface component 1108 may include a keyboard or keypad, a tracking device (e.g., a trackball or trackpad), a speaker, a microphone, etc.
  • USIM 1160 is an integrated circuit that provides security and integrity functions for the UE 106.
  • USIM 1160 includes or is provisioned with a subscription profile associated with a subscription of a subscriber.
  • a subscription profile may include a variety of information, such as subscription credentials (e.g., SUPI) used to uniquely identify a subscription and to mutually authenticate the UE 106 and a network.
  • subscription credentials e.g., SUPI
  • the UE 106 may comprise various other components not specifically illustrated in FIG. 11.
  • FIG. 12 is a flow chart illustrating a method 1200 of performing an enhanced deregistration procedure in an illustrative embodiment.
  • the steps of method 1200 will be described with reference to an apparatus, which may comprise a network element/function 110, a UE 106, etc.
  • the steps of the flow charts described herein are not all inclusive and may include other steps not shown, and the steps may be performed in an alternative order.
  • a previous registration (also referred to as first registration) may be to the UE ID 906 of the UE 106 (i.e., no user 902 logged into the UE 106).
  • a previous registration may be to a user ID 912 (or user profile ID 916) of one of the user profiles 914 (i.e., when a user 902 is logged into the UE 106).
  • the previous registration therefore has an associated identifier, such as the UE ID 906 or a user ID 912.
  • the apparatus may detect a switch or change from the previous registration to a subsequent or second registration, or otherwise determine, such as by receipt of information, a message, or the like that a registration change has occurred (step 1204).
  • the subsequent registration may be to the UE ID 906 of the UE 106 (i.e., a user 902 logs out of the UE 106).
  • the subsequent registration may be to a new or different user ID 912 of a user profile 914 (i.e., when a new user 902 logs into the UE 106).
  • the subsequent registration therefore has an associated identifier that is different than the identifier of the prior registration. Due to the switch from the previous registration to the subsequent registration, the apparatus initiates the enhanced deregistration procedure for the previous registration (step 1206).
  • FIG. 13 illustrates registration procedures in an illustrative embodiment.
  • UE 106 (through UE ID 906) or user 902- 1 (through user ID 912-1) has a previous registration 1302 with the core network 104.
  • the apparatus detects a switch from the previous registration 1302 to a subsequent registration 1304 of a different identifier from the previous registration 1302, the apparatus transitions the previous registration 1302 to a suspended state 1306.
  • a new user 902-2 logs into the UE 106, and the subsequent registration 1304 may be to the user ID 912-2 of the new user 902-2.
  • the apparatus may also update state data for the UE subscription profile 908 and/or user profile(s) 914 (optional step 1208 of FIG. 12).
  • FIG. 14 illustrates the UE subscription profile 908 and/or user profile(s) 914 associated with a subscription 910 in an illustrative embodiment.
  • the UE subscription profile 908 and/or user profile 914 may indicate or include state data 1404.
  • the state data 1404 may comprise an active state 1406 and an inactive state 1408, although other states may be considered herein.
  • a UE 106 (and its associated UE subscription profile 908) may be considered in an active state 1406 when the UE ID 906 is registered to the core network 104 (i.e., has been authenticated and authorized to the subscription 910 to access the core network 104).
  • the UE 106 may be considered in an inactive state 1408.
  • a user 902 (and its associated user profile 914) may be considered in an active state 1406 when the associated user ID 912 or user profile ID 916 is registered to the core network 104 (i.e., has been authenticated and authorized to use a linked subscription 910 to access the core network 104). Otherwise, a user 902 (and its associated user profile 914) may be considered in an inactive state 1408.
  • a single one of the UE subscription profile 908 and the user profiles 914 may be in an active state 1406 at a time.
  • the state data 1404 may further include the suspended state 1306.
  • a UE subscription profile 908 or user profile 914 may be considered in a suspended state 1306 when not in an active state 1406 from a previous registration 1302 and not deregistered from the core network 104.
  • the previous registration 1302, the UE subscription profile 908 or user profile 914, etc. may be considered in a suspended state 1306.
  • the apparatus may store or retain data (e.g., context information) and/or resources attached to the previous registration 1302 (optional step 1210 of FIG. 12) instead of tearing down or releasing the data, resources, etc.
  • data e.g., context information
  • Control plane data and/or user plane data associated with the previous registration 1302 may be idle while in the suspended state 1306.
  • the apparatus may also provide an enhanced deregistration indicator to one or more NFs 110 or UE 106 instructing the NFs 110 or UE 106 to maintain the previous registration 1302 in a suspended state (optional step 1212).
  • the apparatus may initiate an enhanced re-registration procedure (step 1214).
  • the enhanced re-registration procedure data and/or resources attached to the previous registration 1302 were retained and may be re-used.
  • the apparatus transitions the previous registration 1302 from the suspended state 1306 to an active state 1406.
  • the apparatus may update state data 1404 for the UE subscription profile 908 and/or user profile(s) 914 associated with the previous registration 1302 to the active state 1406 (optional step 1216).
  • the UE subscription profile 908 and/or user profile(s) 914 associated with the previous registration 1302 are again activated so that the previous registration 1302 is valid.
  • the apparatus may also provide an enhanced re-registration indicator to one or more NFs 110 or UE 106 instructing the NFs 110 or UE 106 to reactivate the previous registration 1302 (optional step 1218). If a request, instruction, or event is not detected to reactivate the previous registration 1302 (such as within a configurable time period), the apparatus may release the data for the previous registration 1302 and/or initiate a full deregistration procedure (step 1220).
  • an enhanced deregister procedure is described in further detail below, and the processes, systems, and methods described may be incorporated in above embodiments as desired.
  • an enhanced deregister procedure may be implemented via one or more network functions (e.g., AMF 212, SMF 214, PCF 216, and UPF 240) and a UE 106.
  • network functions e.g., AMF 212, SMF 214, PCF 216, and UPF 240
  • FIGS. 15A-15C illustrate registration procedures in illustrative embodiments. Any omitted messages for registration may follow the existing registration procedure.
  • a UE 106 needs to register with the core network 104 to get authorized to receive services, to enable mobility tracking, and to enable reachability.
  • the UE 106 initiates a registration procedure using a registration type, such as initial registration or a Mobility and Registration Update (MRU), which is described in further detail in 3GPP TS 23.502.
  • MRU Mobility and Registration Update
  • FIG. 15A a UE 106 registers with the core network 104 with its UE ID 906 and without a user ID 912 (i.e., no user 902 logged into the UE 106).
  • the UE 106 sends a registration request 1501 (e.g., an initial registration request) to the AMF 212 (through a RAN).
  • the registration request 1501 includes the UE ID 906 (e.g., SUCI, 5G-GUTI or Permanent Equipment Identifier (PEI)) along with other parameters, but does not include a user ID 912 for a particular user 902 of the UE 106.
  • AMF 212 is configured to perform or support registration management within core network 104.
  • Registration management allows a UE 106 or a user 902 of a UE 106 (i.e., through an associated user profile 914) to register and deregister with the core network 104, handles initial registration to authorize a UE 106 and create a UE context or to authorize a user 902 and create a user profile context, to manage periodic registration updates, etc. Messages, steps, processes, etc., of registration management are described in further detail in 3GPP TS 23.502.
  • AMF 212 triggers primary authentication (through AUSF 210 and UDM 218) to authenticate the SUPI reported by UE 106. During the registration procedure, AMF 212 also retrieves subscription data 911 associated with the UE ID 906, such as from UDM 218.
  • the NFs 110 and UE 106 maintain information regarding a previous registration. If, for example, registration reverts back to a previous registration (i.e., back to the UE 106 with no associated user 902 or to a previous user profile 914-1), context information (e.g., security keys), PDU session data, etc., is available, and reauthentication can be avoided.
  • context information e.g., security keys
  • PDU session data e.g., PDU session data, etc.
  • Each of the UE context 1522 and the user profile context 1524 may include an SM context 1614, such as generated at the SMF 214.
  • Each of the UE context 1522 and the user profile context 1524 may include policy information 1616 and/or charging information 1618, such as generated at the PCF 216.
  • Each of the UE context 1522 and the user profile context 1524 may include PDU session data 1620, such as handled by UPF 240.
  • FIG. 16 illustrates general context information 1600 as an example, and other information may be attached to a registration of a UE 106 or user profile 914. NFs 110 and/or UE 106 may retain this and/or other data when performing an enhanced deregistration procedure.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Registration management in a mobile network. In an embodiment, an access and mobility management function (AMF) identifies subscription data comprising a user equipment (UE) subscription for a UE, and one or more user profiles linked to the UE subscription. The AMF performs a registration procedure to register a first identifier from a plurality of identifiers corresponding with the UE, where the plurality of identifiers comprises a UE subscription identifier of the UE and one or more user profile identifiers of the one or more user profiles. The AMF receives a registration message from the UE regarding registration of a second identifier different than the first identifier, and initiates an enhanced deregistration procedure for the first identifier by transitioning the first identifier to a suspended state, and retaining context information associated with the first identifier when in the suspended state.

Description

ENHANCED DEREGISTRATION OF USER EQUIPMENT AND/OR USER PROFILES ASSOCIATED WITH USER EQUIPMENT
Technical Field
This disclosure is related to the field of communication systems and, in particular, to next generation networks.
Background
Next generation networks, such as Fifth Generation (5G) and beyond (e.g., Sixth Generation (6G)), denote the next major phase of mobile telecommunications standards beyond Fourth Generation (4G) standards. In comparison to 4G networks, next generation networks may be enhanced in terms of radio access and network architecture to deliver faster data rates and more reliability. With mobile networks widely used across the country and the world, communications may be intercepted or suffer from other kinds of attacks. To ensure security and privacy, the 3rd Generation Partnership Project (3GPP) has set forth security mechanisms for mobile networks, and the security procedures performed within the mobile networks. Due to the importance of security in 5G systems and beyond, it is desirable to continue to develop improved security mechanisms.
Summary
Described herein are enhancements to registration procedures regarding User Equipment (UE) and a core network. A subscription of a UE may be shared among multiple (e.g., human) users. Thus, one or more user profiles may be linked to the subscription of the UE. For a registration procedure, the UE may register with the core network without a user login (referred to herein as a UE registration), or the UE may register a user profile with the core network according to the present user login (referred to herein as a user registration). In either case, when a new user logs into the UE, for example, the UE will initiate a subsequent registration procedure to register the new user profile associated with the new user login. In embodiments described herein, an enhanced deregistration procedure is used to “softly” deregister the previous registration to the UE or the previous user profile. With the enhanced deregistration procedure, the previous registration is held in a suspended state and data related to the previous registration (e.g., context information) is retained in the core network and/or the UE, instead of being released as with a full or complete deregistration procedure. Thus, the previous registration may be re-activated based on user login changes at the UE. One technical benefit is end-to-end signaling may be reduced at each switch of a user at the UE, as full deregistration may be avoided. Another benefit is re-authentication of the UE or a user may be avoided when a previous registration is reactivated, as data related to the previous registration is retained. Yet another benefit is security information (e.g., security keys) do not need to be re-generated, as data related to the previous registration (e.g., context information) is retained. This advantageously saves network resources.
In an embodiment (also referred to as an aspect), an apparatus comprises an access and mobility management function (AMF) of a core network. The AMF comprises at least one processor, and at least one memory storing instructions, that when executed by the at least one processor, cause the AMF at least to perform identifying subscription data comprising a UE subscription for a UE, and one or more user profiles linked to the UE subscription. The AMF further performs a registration procedure to register a first identifier from a plurality of identifiers corresponding with the user equipment, where the plurality of identifiers comprises a UE subscription identifier of the UE and one or more user profile identifiers of the one or more user profiles. The AMF further receives a registration message from the UE regarding registration of a second identifier from the plurality of identifiers different than the first identifier, and initiates an enhanced deregistration procedure for the first identifier in response to the registration message by transitioning the first identifier to a suspended state, and retaining context information associated with the first identifier when in the suspended state.
In an embodiment, an apparatus comprises user equipment (UE) communicatively coupled to a core network. The UE comprises at least one processor, and at least one memory storing instruction that, when executed by the at least one processor, cause the UE at least to perform identifying subscription data comprising a UE subscription for the UE, and one or more user profiles linked to the UE subscription, where a plurality of identifiers corresponding with the UE comprise a UE subscription identifier of the UE and one or more user profile identifiers of the one or more user profiles. The UE further detects a change of user login, sends a registration message to an AMF of the core network to switch registration from a first identifier of the plurality of identifiers to a second identifier of the plurality of identifiers different from the first identifier. The UE further initiates an enhanced deregistration procedure for the first identifier by transitioning the first identifier to a suspended state, and retaining context information associated with the first identifier when in the suspended state.
Other embodiments may include computer readable media, other systems or apparatus, or other methods or means as described below. Also, one or more embodiments as described above may be combinable as described herein.
The above summary provides a basic understanding of some aspects of the specification. This summary is not an extensive overview of the specification. It is intended to neither identify key or critical elements of the specification nor delineate any scope of the particular embodiments of the specification, or any scope of the claims. Its sole purpose is to present some concepts of the specification in a simplified form as a prelude to the more detailed description that is presented later.
Description of the Drawings
Some embodiments of the invention are now described, by way of example only, and with reference to the accompanying drawings. The same reference number represents the same element or the same type of element on all drawings.
FIG. 1 illustrates a high-level architecture of a 5G system.
FIG. 2 illustrates a non-roaming architecture of a 5G system.
FIG. 3 illustrates security mechanisms within a 5G system.
FIGS. 4A-4B illustrate the primary authentication procedure that provides mutual authentication between user equipment and the network. FIG. 5 illustrates non-access stratum (NAS) and access stratum (AS) security procedures.
FIGS. 6A-6B illustrate a UP security mechanism.
FIG. 7 illustrates a key hierarchy of a 5G system.
FIG. 8 illustrates the NAS functional layer and the AS functional layer in a 5G system.
FIG. 9 is a diagram illustrating a shared subscription in an illustrative embodiment.
FIG. 10 is a block diagram of network elements/functions for providing security management in an illustrative embodiment.
FIG. 11 is a block diagram of user equipment (UE) in an illustrative embodiment.
FIG. 12 is a flow chart illustrating a method of performing an enhanced deregistration procedure in an illustrative embodiment.
FIG. 13 illustrates registration procedures in an illustrative embodiment.
FIG. 14 illustrates the UE subscription profile and/or user profile(s) associated with a subscription in an illustrative embodiment.
FIGS. 15A-15C illustrate registration procedures in illustrative embodiments.
FIG. 16 is a diagram illustrating context information attached to a registration of a UE or a user profile in an illustrative embodiment.
FIG. 17 is a flow chart illustrating a method of registration management at an AMF in an illustrative embodiment.
FIG. 18 is a flow chart illustrating a method of registration management at a UE in an illustrative embodiment.
FIG. 19 is a flow chart illustrating a method of enhanced deregistration at an SMF in an illustrative embodiment.
FIG. 20 is a flow chart illustrating a method of enhanced deregistration at a UPF in an illustrative embodiment.
FIG. 21 is a flow chart illustrating a method of enhanced deregistration at a PCF in an illustrative embodiment. FIG. 22 is a flow chart illustrating additional steps of an enhanced deregistration procedure in an illustrative embodiment.
FIG. 23 is a flow chart illustrating additional steps of registration management at an AMF in an illustrative embodiment.
FIG. 24 is a flow chart illustrating additional steps of registration management at an AMF in an illustrative embodiment.
Description of Embodiments
The figures and the following description illustrate specific exemplary embodiments. It will thus be appreciated that those skilled in the art will be able to devise various arrangements that, although not explicitly described or shown herein, embody the principles of the embodiments and are included within the scope of the embodiments. Furthermore, any examples described herein are intended to aid in understanding the principles of the embodiments, and are to be construed as being without limitation to such specifically recited examples and conditions. As a result, the inventive concept(s) is not limited to the specific embodiments or examples described below, but by the claims and their equivalents.
FIG. 1 illustrates a high-level architecture of a 5G system 100. A 5G system (5GS) 100 is a communication system (e.g., a 3GPP system) comprising a 5G Access Network ((R)AN) 102 (referred to generally herein as a RAN) and a 5G core network (5GC) 104 that communicate with 5G User Equipment (UE) 106. The RAN 102 and 5GC 104 together may be referred to as a 5G network 101, a 5G mobile network, a 5G communication network, a next generation network, etc. Although the term “5G” is used herein as an example, any next generation or future generation networks beyond 4G are considered, such as 6G. Thus, a “mobile network” and the concepts described herein apply to 5G and beyond.
RAN 102 provides radio or wireless connectivity to a UE 106, and connects the UE 106 to the 5GC 104. RAN 102 may comprise a Next Generation Radio Access Network (NG-RAN), a non-3GPP access network, and/or another type of RAN connecting to 5GC 104. RAN 102 may support Evolved-UMTS Terrestrial Radio Access Network (E-UTRAN) access (e.g., through an eNodeB (eNB), gNodeB (gNB), and/or ng-eNodeB (ng-eNB)), Wireless Local Area Network (WLAN) access, satellite radio access, new Radio Access Technologies (RAT), etc. A 5G access network may also support fixed access. 5GC 104 interconnects RAN 102 with a data network (DN) 108. 5GC 104 is comprised of Network Functions (NF) 110, which may be implemented either as a network element on dedicated hardware, as a software instance running on dedicated hardware, as a virtualized function instantiated on an appropriate platform (e.g., a cloud infrastructure), etc. Data network 108 may be an operator external public or private data network, or an intra-operator data network (e.g., for IP Multimedia Subsystem (IMS) services). A UE 106 (also referred to as a mobile terminal) includes a 5G capable device configured to register with 5GC 104 to access services. UE 106 may include an end user device, such as a mobile phone (e.g., smartphone), a tablet, a computer with a mobile broadband adapter, etc. UE 106 may be enabled for voice services, data services, Machine-to-Machine (M2M) or Machine Type Communications (MTC) services, and/or other services.
FIG. 2 illustrates a non-roaming architecture 200 of a 5G system 100. The architecture 200 in FIG. 2 is a service-based representation, as is further described in 3GPP TS 23.501 (Release 18), which is incorporated by reference as if fully included herein. Architecture 200 is comprised of Network Functions (NF) for a 5GC 104, and the NFs for the control plane (CP) are separated from the user plane (UP). The control plane of the 5GC 104 includes an Authentication Server Function (AUSF) 210, an Access and Mobility Management Function (AMF) 212, a Session Management Function (SMF) 214, a Policy Control Function (PCF) 216, a Unified Data Management (UDM) 218, a Network Slice Selection Function (NSSF) 220, and an Application Function (AF) 222. The control plane of the 5GC 104 further includes a Network Exposure Function (NEF) 224, a NF Repository Function (NRF) 226, a Service Communication Proxy (SCP) 228, a Network Slice Admission Control Function (NSACF) 230, a Network Slice-specific and SNPN Authentication and Authorization Function (NSSAAF) 232, and an Edge Application Server Discovery Function (EASDF) 234. The user plane of the 5GC 104 includes one or more User Plane Functions (UPF) 240 that communicate with data network 108. A UE 106 is able to access the control plane and the user plane of the 5GC 104 through RAN 102.
There are a large number of subscribers that are able to access services from a carrier or home network operator that implements a mobile network comprising a 5G system 100, such as in FIGS. 1-2. Communications between the users or subscribers (i.e., through a UE) and the mobile network are protected by security mechanisms, such as the ones standardized by the 3GPP. Subscribers and the carrier expect security guarantees from the security mechanisms.
FIG. 3 illustrates security mechanisms 300 within a 5G system 100. One of the security mechanisms 300 is primary authentication and key agreement between the network (e.g., AMF 212/UDM 218) and the UE 106. Other security mechanisms 300 are used to protect signaling between the network and the UE 106. For example, a security mechanism 300 is used to protect Non-Access Stratum (NAS) signaling between the AMF 212 and the UE 106. Other security mechanisms 300 are used to protect Access Stratum (AS) communications between a RAN node (e.g., gNB 302) and the UE 106, such as Radio Resource Control (RRC) signaling between a gNB 302 and the UE 106, and User Plane (UP) traffic (also referred to as UP data) between the gNB 302 and the UE 106. Within the network, a security mechanism 300 may be used to protect IP connectivity between the gNB 302 and the 5GC 104 (e.g., AMF 212/UPF 240), such as Internet Protocol Security (IPSec). Yet another security mechanism 300 is used for roaming and interconnect security, such as to protect control plane signaling between a Security Edge Protection Proxy (SEPP) 310 and another network 301 (e.g., a visited 5G network), and/or to protect user plane data between the UPF 240 and the other network 301. There may be additional security mechanisms 300 defined or used, which are not discussed for the sake of brevity.
FIGS. 4A-4B illustrate the primary authentication procedure that provides mutual authentication between the UE 106 and the network (e.g., AMF 212/UDM 218). The purpose of the primary authentication and key agreement procedures is to enable mutual authentication between UE 106 and the home network of the UE 106, and provide keying material that can be used between the UE 106 and the serving network in subsequent security procedures (e.g., NAS and AS security procedures). The home network (e.g., Home Public Land Mobile Network (HPLMN)) represents an operator network or carrier network through which a subscriber (e.g., UE 106) has a subscription for services. The serving network has radio access equipment able to communicate with the UE 106 via radio signals. The keying material generated by the primary authentication and key agreement procedure results in an anchor key (called the KSEAF key) provided by the AUSF 210 of the home network to the Security Anchor Function (SEAF) of the serving network. The SEAF provides authentication functionality via the AMF 212 in the serving network, and supports primary authentication using a Subscription Concealed Identifier (SUCI) that contains the concealed Subscription Permanent Identifier (SUPI). The SUPI is a globally unique 5G identifier allocated to each subscriber in the 5G system 100. The SUCI is composed of a SUPI type, a Home Network Identifier (HN-ID) identifying the home network of the subscriber, a Routing Indicator (RID) that is assigned to the subscriber by the home network operator and provisioned in the Universal Subscriber Identity Module (USIM) of the UE 106, a Protection Scheme Identifier, a Home Network Public Key Identifier, and a Scheme Output. The anchor key (KSEAF) is derived from an intermediate key called the KAUSF key. The KAUSF key is established between the UE 106 and the home network (AUSF 210) resulting from the primary authentication procedure.
FIG. 4A is a signaling diagram that illustrates initiation of primary authentication, such as described in 3GPP TS 33.501 (Release 18), which is incorporated by reference as if fully included herein. The UE 106 transmits an N1 message 411 (i.e., an initial NAS message) to the serving network 406 (e.g., the AMF 212 of the serving network 406), such as a Registration Request. The serving network 406 may also be referred to as a serving PLMN, a visited-PLMN (VPLMN), etc., in a roaming scenario. The UE 106 uses the SUCI or a 5G Global Unique Temporary Identifier (5G-GUTI) in the Registration Request. SEAF 402 of the AMF 212 may initiate an authentication with the UE 106 during any procedure establishing a signaling connection with the UE 106. SEAF 402 invokes the Nausf_UEAuthentication service toward the home network 404 (e.g., HPLMN) by sending a Nausf_UEAuthentication_Authenticate Request message 412 to AUSF 210 to initiate an authentication. The
Nausf_UEAuthentication_Authenticate Request message 412 includes the SUCI or SUPI, and the serving network name (SN-Name). Upon receiving the Nausf_UEAuthentication_Authenticate Request message 412, AUSF 210 checks that the requesting SEAF 402 in the serving network 406 is entitled to use the serving network name (SNN) in the Nausf_UEAuthentication_Authenticate Request message 412 by comparing the serving network name with the expected serving network name. When the serving network 406 is authorized to use the serving network name, AUSF 210 sends a Nudm_UEAuthentication_Get Request message 413 to UDM 218 of the home network. The Nudm_UEAuthentication_Get Request message 413 includes the SUCI or SUPI, and the serving network name. Upon reception of the Nudm_UEAuthentication_Get Request message 413, UDM 218 identifies the SUPI (if received), or invokes a Subscription Identifier De-concealing Function (SIDF) that de-conceals the SUPI from the SUCI (if received). UDM 218 (or an Authentication credential Repository and Processing Function (ARPF) of UDM 218) selects or chooses the authentication method for primary authentication based on the SUPI.
FIG. 4B is a signaling diagram that illustrates a primary authentication procedure, such as described in 3GPP TS 33.501. In this example, 5G Authentication and Key Agreement (AKA) is described, but similar concepts apply for Extensible Authentication Protocol AKA prime (GAP- AKA'). For a Nudm_UEAuthentication_Get Request 413, UDM 218 creates a 5G Home Environment Authentication Vector (5G HE AV) for the selected authentication method. UDM 218 derives the KAUSF key and calculates an expected response (XRES*) to a challenge. UDM 218 creates the 5G HE AV comprising an authentication token (AUTN), the expected response (XRES*), the KAUSF key, and a random challenge (RAND). UDM 218 then sends a Nudm_UEAuthentication_Get Response message 414 to AUSF 210 with the 5G HE AV to be used for authentication (e.g., 5G AKA in FIG. 4B). In case the SUCI was included in the Nudm_UE Authentication_Get Request 413, UDM 218 includes the SUPI in the Nudm_UEAuthentication_Get Response message 414 after deconcealment of the SUPI from the SUCI. If a subscriber has an Authentication and Key Management for Application (AKMA) subscription, UDM 218 may include an AKMA indication and the RID in the Nudm_UEAuthentication_Get Response message 414.
In response to the Nudm_UEAuthentication_Get Response message 414, AUSF 210 stores the expected response (XRES*) temporarily with the received SUCI or SUPI. AUSF 210 then generates a 5G Authentication Vector (5G AV) from the 5G HE AV received from UDM 218, by computing a hash expected response (HXRES*) from the expected response (XRES*) and the KSEAF key from the KAUSF key, and replacing the XRES* with the HXRES* and the KAUSF key with the KSEAF key in the 5G HE AV. AUSF 210 removes the KSEAF key to generate a 5G Serving Environment Authentication Vector (5G SE AV) that includes the authentication token (AUTN), hash expected response (HXRES*), and the random challenge (RAND). AUSF 210 sends a Nausf_UEAuthentication_Authenticate Response message 415 to SEAF 402 that includes the 5G SE AV. In response, SEAF 402 sends the authentication token (AUTN) and the random challenge (RAND) to the UE 106 in a NAS message Authentication Request message 416.
Although not shown in FIG. 4B, the UE 106 includes Mobile Equipment (ME) and a USIM. The ME receives the authentication token (AUTN) and the random challenge (RAND) in the NAS message Authentication Request message 416, and forwards the authentication token (AUTN) and the random challenge (RAND) to the USIM. The USIM of the UE 106 verifies the freshness of the received values by checking whether the authentication token (AUTN) can be accepted. If so, the USIM computes a response (RES), a cipher key (CK), and an integrity key (IK) based on the random challenge (RAND), and returns the response (RES), the CK key, and the IK key to the ME. The ME of the UE 106 computes RES* from RES, and calculates the KAUSF key from CKIIIK and the KSEAF key from The UE 106 sends a NAS message Authentication Response message 417 to SEAF 402 that includes RES*. In response, SEAF 402 computes HRES* from RES*, and compares HRES* and HXRES*. If they coincide, SEAF 402 considers the authentication successful from the serving network point of view. SEAF 402 sends RES*, as received from the UE 106, in a Nausf_UEAuthentication_Authenticate Request message 418 to AUSF 210. When AUSF 210 receives the Nausf_UEAuthentication_Authenticate Request message 418 including a RES* as authentication confirmation, AUSF 210 stores the KAUSF key based on the home network operator’s policy, and compares the received RES* with the stored XRES*. If the RES* and XRES* are equal, then AUSF 210 considers the authentication successful from the home network point of view. AUSF 210 informs UDM 218 about the authentication result (not shown). AUSF 210 also sends a Nausf_UEAuthentication_Authenticate Response message 419 to SEAF 402 indicating whether or not the authentication was successful from the home network point of view. If the authentication was successful, the KSEAF key is sent to SEAF 402 in the Nausf_UEAuthentication_Authenticate Response message 419. In case AUSF 210 received the SUCI from SEAF 402 in the authentication request, AUSF 210 includes the SUPI in the Nausf_UEAuthentication_Authenticate Response message 419 if the authentication was successful.
As described above, 5G divides UE management into the Non-Access Stratum (NAS) and the Access Stratum (AS). The NAS layer protocol manages the connection between a UE 106 and 5GC 104 (i.e., AMF 212), and the AS layer protocol manages the radio layer between a UE 106 and the RAN 102 (e.g., gNB 302) using RRC protocol. NAS security ensures that NAS signaling between a UE 106 and AMF 212 is protected on the control plane, and AS security ensures that RRC messages on the control plane and user plane traffic (e.g., IP packets) on the user plane are protected.
FIG. 5 illustrates NAS and AS security procedures, such as described in 3GPP TS 33.501 (sections 6.4 and 6.7, respectively). For NAS security, a NAS security mode command procedure is performed to establish a NAS security context between the UE 106 and the AMF 212. Each AMF 212 is configured via network management with lists of algorithms that are allowed for usage. Presently, there is one list for NAS integrity algorithms and one for NAS ciphering algorithms that are ordered according to a priority decided by the operator. To establish the NAS security context, AMF 212 selects one NAS ciphering algorithm and one NAS integrity protection algorithm, and derives the NAS integrity key and the NAS encryption key (e.g., KNASint and KNASenc) for the selected algorithms. AMF 212 initiates the NAS security mode command procedure by sending a NAS Security Mode Command message 511 to the UE 106. AMF 212 activates NAS integrity protection before sending the NAS Security Mode Command message 511. The NAS Security Mode Command message 511 contains the previously received UE security capabilities, the selected NAS algorithms, a key set identifier (i.e., ngKSI (next generation key set identifier)), and a message authentication code (NAS- MAC) generated by the AMF 212 for integrity protection of the NAS Security Mode Command message 511. The NAS Security Mode Command message 511 is integrity protected (but not ciphered) with the NAS integrity key based on the KAMF key indicated by the ngKSI. AMF 212 activates NAS uplink de-ciphering after sending the NAS Security Mode Command message 511.
On receipt of the NAS Security Mode Command message 511, the UE 106 verifies the integrity of the NAS Security Mode Command using the indicated NAS integrity algorithm and the NAS integrity key based on the KAMF key indicated by the ngKSI. The UE 106, with the received algorithms, generates the NAS integrity key and the NAS encryption key in the same manner as AMF 212. If verification is successful, the UE 106 begins NAS integrity protection and ciphering/deciphering with the security context indicated by the ngKSI. The UE 106 sends a NAS Security Mode Complete message 512 to AMF 212 that is ciphered and integrity protected. If the verification of the NAS Security Mode Command message 511 is not successful, the UE 106 replies with a NAS Security Mode Reject message (not shown). AMF 212 de-ciphers and checks the integrity of the received NAS Security Mode Complete message 512 using the key and algorithm indicated in the NAS Security Mode Command message 511. AMF 212 activates NAS downlink ciphering after receiving the NAS Security Mode Complete message 512.
AS security includes RRC security and User Plane (UP) security. For RRC security, RRC integrity protection and RRC confidentiality protection are provided by the Packet Data Convergence Protocol (PDCP) layer between a UE 106 and a gNB 302. The 5GC 104 supports a PDU connectivity service that provides exchange of PDUs between UE 106 and a data network 108 (identified by a Data Network Name (DNN)) over the user plane. Security of user plane traffic in 5G networks is controlled by the UP security policy. The SMF 214 provides the UP security policy for a Packet Data Unit (PDU) session to the gNB 302 (or ng-eNB) during the PDU session establishment procedure. The UP security policy indicates whether UP confidentiality protection and/or UP integrity protection are activated for Data Radio Bearers (DRBs) belonging to that PDU session.
An AS security mode command procedure is performed to establish an AS security context between the UE 106 and the NG-RAN 502. When the AS security context is to be established in the gNB 302, AMF 212 sends the UE 5G security capabilities with ciphering and integrity protected algorithms and the K8NB key in an NG Application Protocol (NGAP) Initial Context Setup message 513 to the NG- RAN 502 (e.g., gNB 302). Presently, each gNB 302 is configured via network management with lists of algorithms that are allowed for usage. There is one list for integrity algorithms and one for ciphering algorithms that are ordered according to a priority decided by the operator. The gNB 302 selects the AS integrity algorithm and the AS ciphering algorithm which has the highest priority from its configured list and present in the UE 5G security capabilities received from AMF 212. The gNB 302 derives the RRC integrity key (KRRCint), the UP integrity key (Kupint), the RRC ciphering key (KRRCenc), and the UP ciphering key (Kupenc) for the selected AS algorithms. The gNB 302 starts integrity protection for RRC messages.
The gNB 302 sends an integrity protected AS Security Mode Command message 514 to the UE 106, which contains the selected AS integrity algorithm and AS ciphering algorithm, and the message authentication code (MAC-I) generated by the gNB 302 for integrity protection of the AS Security Mode Command message 514. RRC downlink ciphering at the gNB 302 starts after sending the AS Security Mode Command message 514.
On receipt of the AS Security Mode Command message 514, the UE 106 derives the RRC integrity key (KRRCint) and the RRC ciphering key (KRRCenc) similar to the gNB 302 based on the selected AS integrity algorithm and AS ciphering algorithm. UE 106 verifies the AS Security Mode Command integrity and, if successful, starts RRC integrity protection and RRC downlink de-ciphering. The UE 106 then sends an AS Security Mode Complete message 515 with integrity protection to the gNB 302. The AS Security Mode Complete message 515 contains the MAC-I generated by the UE 106 for integrity protection of the AS Security Mode Complete message 515. The RRC uplink ciphering at the UE 106 starts after sending the AS Security Mode Complete message 515. Integrity of the AS Security Mode Complete message 515 is verified at the gNB 302, and the gNB 302 starts RRC uplink deciphering.
FIGS. 6A-6B illustrate a UP security mechanism. For UP security, SMF 214 stores a UP security policy regarding integrity protection and encryption for the user plane of a PDU session. In general, integrity protection is a mechanism where the receiver of data is able to verify that the received data was actually sent by the sender (i.e., unaltered by an intermediary). For example, a sender may use an integrity algorithm (NIA) to compute a message authentication code (MAC), which is appended to a message when sent. A receiver computes an expected MAC (XMAC) on the message received in the same way as the sender computed its MAC on the message sent, and verifies the data integrity by comparing the computed MAC to the received MAC. Encryption or ciphering is a process of encoding data so that it may not be accessed by unauthorized parties. For example, a sender may use a ciphering or encryption algorithm (NEA) to encrypt a plaintext block with an associated encryption key to produce a ciphertext block. The plaintext may be recovered, such as at a receiver, by decrypting the ciphertext block in a similar manner with the encryption key.
SMF 214 is configured to provide the UP security policy for the PDU session to NG-RAN 502 (e.g., gNB 302) during the PDU session establishment procedure, as specified in 3GPP TS 23.502 (Release 18), which is incorporated by reference as if fully included herein. The UP security policy indicates whether UP confidentiality protection and/or UP integrity protection is activated or not for all DRBs belonging to that PDU session. The UP security policy is used to activate UP confidentiality protection and/or UP integrity protection in the UE 106 and NG- RAN 502 for all DRBs belonging to the PDU session.
FIG. 6A illustrates an abbreviated version of the PDU session establishment procedure. PDU session establishment is the process of establishing a user plane data path between a UE 106 and the 5GC 104. A PDU session is a logical connection or association between a UE and a data network, such as the internet or a private network. For the PDU session establishment procedure, AMF 212 receives a PDU session establishment request 611, such as from UE 106, requesting establishment of a new PDU session. AMF 212 selects an SMF 214, and sends a Nsmf_PDUSession_CreateSMContext Request 612 to the SMF 214 indicating the PDU Session ID along with other information. SMF 214 creates a session management (SM) context for the PDU session, which includes determining and/or storing a UP security policy 620 for integrity protection and encryption of the user plane for the PDU session. SMF 214 replies to AMF 212 with a Nsmf_PDUSession_CreateSMContext Response 613.
As described above, the SMF 214 provides the UP security policy 620 for a PDU session to the gNB 302 during the PDU session establishment procedure. Thus, SMF 214 invokes the Namf_Communication_NlN2MessageTransfer service operation, and sends a Namf_Communication_NlN2MessageTransfer message 614 to AMF 212. The Namf_Communication_NlN2MessageTransfer message 614 includes N2 SM information, which carries information that the AMF 212 forwards to the NG-RAN 502. The N2 SM information includes UP security enforcement information 622 determined by the SMF 214. The UP security enforcement information 622 provides the NG-RAN 502 with the UP security policy 620 for the PDU session. The UP security enforcement information 622 indicates whether UP integrity protection is: “Required” (i.e., UP integrity protection shall apply for all traffic on the PDU Session), “Preferred” (i.e., UP integrity protection should apply for all traffic on the PDU Session), or “Not Needed” (i.e., UP integrity protection shall not apply on the PDU Session). The UP security enforcement information 622 also indicates whether UP confidentiality protection is: “Required” (i.e., UP confidentiality protection shall apply for all traffic on the PDU Session), “Preferred” (i.e., UP confidentiality protection should apply for all traffic on the PDU Session), or “Not Needed” (i.e., UP confidentiality shall not apply on the PDU Session). SMF 214 determines, at PDU session establishment, the UP security enforcement information 622 for the user plane of a PDU session based on the subscribed UP security policy which is part of SM subscription information received from UDM 218, the UP security policy stored locally in the SMF 214 that is used when UDM 218 does not provide UP security policy information, and/or the maximum supported data rate per UE for integrity protection for the DRBs, provided by the UE 106 in the integrity protection maximum data rate Information Element (IE) during PDU Session Establishment. Once determined at the establishment of the PDU session, the UP security enforcement information 622 applies for the life time of the PDU session. The UP security enforcement information 622 is communicated from SMF 214 to the NG- RAN 502 for enforcement as part of PDU session related information. If the UP integrity protection is determined to be “Required” or “Preferred”, SMF 214 also provides the maximum supported data rate per UE for integrity protection.
In response to the Namf_Communication_NlN2MessageTransfer message 614, AMF 212 sends an N2 PDU Session Request 615 to the NG-RAN 502. The N2 PDU Session Request 615 includes the N2 SM information received from the SMF 214, such as the UP security enforcement information 622.
In FIG. 6B, NG-RAN 502 may issue an AN-specific signaling exchange with the UE 106 that is related with the information received from SMF 214. For example, the gNB 302 may initiate the RRC Connection Reconfiguration procedure, which is used to add DRBs for the PDU session. The RRC Connection Reconfiguration procedure is performed after RRC security has been activated as part of the AS security mode command procedure. The gNB 302 sends an RRC Connection Reconfiguration message 616 to the UE 106 for UP security activation. The RRC Connection Reconfiguration message 616 contains indications for the activation of UP integrity protection and UP ciphering for each DRB according to the UP security policy 620. If UP integrity protection is activated for a DRB as indicated in the RRC Connection Reconfiguration message 616 and the gNB 302 does not have the Kupint key, then the gNB 302 derives the Kupint key and UP integrity protection for the DRB starts at the gNB 302. Similarly, if UP ciphering is activated for the DRB as indicated in the RRC Connection Reconfiguration message 616 and the gNB 302 does not have the Kupenc key, then the gNB 302 derives the Kupenc key and UP ciphering for the DRB starts at the gNB 302.
On receipt of the RRC Connection Reconfiguration message 616, the UE 106 verifies the RRC Connection Reconfiguration integrity protection. If successful, the UE 106 performs the following. When UP integrity protection is activated for a DRB as indicated in the RRC Connection Reconfiguration message 616 and the UE 106 does not have the Kupint key, the UE 106 derives the Kupint key and UP integrity protection for the DRB starts at the UE 106. Similarly, when UP ciphering is activated for the DRB as indicated in the RRC Connection Reconfiguration message 616 and the UE 106 does not have the Kupenc key, the UE 106 derives the Kupenc key and UP ciphering for the DRB starts at the UE 106. The UE 106 sends an RRC Connection Reconfiguration Complete message 617 to the gNB 302.
FIG. 7 illustrates a key hierarchy 700 of a 5G system 100, such as in 3GPP TS 33.501. The keys related to authentication include the following keys: K 701, and CK/IK 702. The key hierarchy 700 includes the following keys: KAUSF 703, KSEAF 704, KAMF 705, KNASint 706, KNASenc 707, KN3IWF 708, KgNB 709, KRRCint 710, KRRcenc 711, Kupint 712, and Kupenc 713. The keys for AUSF 210 in the home network 404 include the KAUSF key 703 derived by the ME of a UE 106 and AUSF 210 from CK', IK' in case of EAP-AKA', or by the ME and the ARPF of UDM 218 from CK, IK 702 in case of 5G AKA. The KSEAF key 704 is the anchor key derived by the ME and AUSF 210 from the KAUSF key 703. The key for AMF 212 in the serving network 406 is the KAMF key 705 derived by the ME and the SEAF 402 from the KSEAF key 704. The keys for NAS signaling (i.e., of a NAS security context) include the KNASint key 706 derived by the ME and AMF 212 from the KAMF key 705, which is used for integrity protection of NAS signaling with a particular integrity algorithm. The keys for NAS signaling also include the KNASenc key 707 derived by the ME and AMF 212 from the KAMF key 705, which is used for encryption of NAS signaling with a particular encryption algorithm. The key for the NG-RAN is the K8NB key 709 derived by the ME and AMF 212 from the KAMF key 705. For an AS security context, the keys for RRC signaling include the KRRCint key 710 derived by the ME and the gNB 302 from the K8NB key 709, which is used for integrity protection of RRC signaling with a particular integrity algorithm. The keys for RRC signaling further include the KRRCenc key 711 derived by the ME and the gNB 302 from the K8NB key 709, which is used for encryption of RRC signaling with a particular encryption algorithm. The keys for UP traffic include the Kupint key 712 derived by the ME and the gNB 302 from the K8NB key 709, which is used for integrity protection of UP traffic between the ME and the gNB 302 with a particular integrity algorithm. The keys for UP traffic further include the Kupenc key 713 derived by the ME and the gNB 302 from the K8NB key 709, which is used for encryption of UP traffic with a particular encryption algorithm. For non-3GPP access, the KNSIWF key 708 is derived by the ME and the AMF 212 from the KAMF key 705 for non-3GPP access. There are other keys as part of the key hierarchy 700 of a 5G system 100, which are not discussed for the sake of brevity.
FIG. 8 illustrates the NAS functional layer 802 and the AS functional layer 804 in a 5G system 100. The UE 106 is operatively coupled to 5G network 101. The NAS functional layer 802 is between the UE 106 and AMF 212 (or Mobility Management Entity (MME)), and therefore, NAS signaling 812 may be exchanged between the UE 106 and AMF 212. The AS functional layer 804 is between the UE 106 and a RAN node 800 (e.g., gNB 302). RRC signaling 814 may be exchanged between the UE 106 and the RAN node 800 via one or more Signaling Radio Bearers (SRB) 816. Additionally, when a PDU session 830 is established, UP traffic 818 may be exchanged between the UE 106 and the RAN node 800 via one or more Data Radio Bearers (DRB) 820. For example, the UP traffic 818 may comprise UP packets 822, such as IP packets 824.
Traditionally, a subscription in a PLMN is mapped or linked to a UE 106, such as a SUPI provisioned on the USIM of the UE 106. In an embodiment, a subscription of a UE 106 may be shared by multiple users. For example, a parent may have a mobile phone with a subscription to a carrier, and the subscription may be shared by the parent and one or more of the children.
FIG. 9 is a diagram illustrating a shared subscription in an illustrative embodiment. In this embodiment, a subscription 910 (also referred to as a UE subscription or a 3GPP subscription) is associated with a UE 106 by a carrier operating a core network 104, such as of a 5GS 100. UE 106 has a UE Identifier (ID) 906 (or UE Identity, UE subscription ID, a user subscription ID, etc.), such as a SUPI, and the subscription 910 is mapped or linked to that UE ID 906. The UE 106 may also have an associated UE subscription profile 908 linked to the UE ID 906 and/or the subscription 910. The core network 104 may therefore authenticate and authorize the UE 106 to access services according to the subscription 910, the UE profile 908, the UE ID 906, etc.
In certain use cases, one or more users 902 (e.g., human users) may share UE 106 to access services under the subscription 910. Thus, one or more user profiles 914 may be linked to the subscription 910 of the UE 106. For example, a user profile 914-1 of a first user 902-1 may be linked to the subscription 910, and a user profile 914-2 of a second user 902-2 may be linked to the subscription 910. At any point in time, one of the users 902 may login to the UE 106 through a user login 904. Thus, one of the users 902 may be logged into their associated user profile 914 at a time to access services. The user profile 914 of the logged-in user 902 is “attached” to the UE 106, and services are provided based on parameters of that user profile 914. The core network 104, through one or more of its NFs 110 (such as a UDM 218, a Unified Data Repository (UDR), etc.), is configured to create or support an association between a user ID 912 (or user identity) and the subscription 910, also referred to as an identifier link. The user ID 912 (e.g., user@example.com) is at least unique within the core network 104. For example, user ID 912-1 is associated with user 902-1 (which may be considered a primary user), and user ID 912-2 (which may be considered a secondary user) is associated with user 902-2.
The core network 104 is also configured to create or support a user profile 914 associated with a user ID 912, which is also linked to the subscription 910. A user profile 914 (also referred to as a user identity profile) comprises a collection of information associated with a user 902. The information of a user profile 914 may include, for example, the user ID 912, a user profile ID 916 (also referred to as a user profile reference ID) that uniquely identifies the user profile 914, authentication information or security credentials, one or more devices that can use this user profile 914, PDU session-related control data (e.g., one or more applications associated with this user profile 914, user-specific QoS settings to apply to the traffic associated with this user profile 914, a list of services available for this user profile 914, how a user is authenticated and authorized, etc.), and/or other information. UE 106 is also configured with the user IDs 912 and associated user profiles 914 (or at least user profile information). The subscription 910 and associated user profiles 914 may be referred to generally as subscription data related or corresponding with a UE 106.
In an initial registration procedure to the core network 104, for example, UE 106 may register its UE ID 906 without a user login (i.e., a UE registration), which may comprise a default registration when the UE subscription profile 908 is used for registration. In another example, UE 106 may register a user ID 912 of a user profile 914 according to the present user login (i.e., a user registration), where the user profile 914 associated with the logged-in user 902 is used for registration. After the initial registration procedure, a new user 902 may login to UE 106 to access services. For example, assume that user 902-1 initially logs into UE 106, and the initial registration procedure registers the user profile 914-1 associated with the user 902-1 to core network 104. When another user 902 (e.g., user 902-2) logs into UE 106, the UE 106 will initiate a subsequent registration procedure to register the user profile 914-2 associated with the other user 902-2 to core network 104. Because a single user 902 (e.g., single user profile 914) is allowed to be active with the subscription 910 at a given time, one issue is how to handle deregistration of the previous registration to the UE 106 or a previous user profile 914.
In embodiments described herein, an enhanced or soft deregistration procedure is introduced. The enhanced deregistration procedure may be used in the core network 104 and/or the UE 106 when switching between users 902 of a UE 106 and/or switching between a user 902 and the UE 106 itself (i.e., no user 902 logged in). As a general overview, when a new user 902 (e.g., user 902-2) logs into UE 106 and UE 106 initiates a registration procedure for the new user 902-2, the core network 104 and/or the UE 106 may initiate the enhanced deregistration procedure to “suspend” the previous registration. Thus, even though the previous registration is not active, data related to the previous registration is retained in the core network 104 and/or the UE 106 instead of being released as with a full or complete deregistration procedure. One technical benefit is end-to-end signaling may be reduced when switching of users 902 occurs at the UE 106, as full deregistration may be avoided. For example, if the previous user 902-1 logs back into the UE 106, the UE 106 does not need to initiate a full registration procedure of the previous user 902-1 as data related to the previous user 902-1 is held within the core network 104 and/or the UE 106. Another benefit is re-authentication of the UE 106 or a previous user 902-1 may be avoided when a previous registration is reactivated. Yet another benefit is security information (e.g., security keys) do not need to be re-generated. This advantageously saves network resources.
An enhanced deregistration procedure is described in further detail below. In general, the enhanced deregistration procedure may be implemented or supported by one or more network functions (e.g., NF 110) of a core network 104 and/or a UE 106. FIG. 10 is a block diagram of network elements/functions for providing security management in an illustrative embodiment. More particularly, system 1000 of FIG. 10 comprises a UE 106 and a plurality of network elements/functions 110 (i.e., a first network element/function 110-1 and a second network element/function 110-N). It is to be appreciated that UE 106 and the network elements/functions 110 are configured to interact to provide security management. Examples of network elements/functions 110 may include, but are not limited to, an AMF 212, an SMF 214, a PCF 216, a UDM 218, a UPF 240, etc.
Network element/function 110-1 comprises a processor 1022-1 coupled to a memory 1026-1 and interface circuitry 1020-1. The processor 1022-1 of network element/function 110-1 includes a security management processing module 1024- 1 that may be implemented at least in part in the form of software executed by the processor 1022-1. The security management processing module 1024-1 performs security management described in conjunction with subsequent figures and otherwise herein. The memory 1026-1 includes a security management storage module 1028-1 that stores data generated or otherwise used during security management operations.
Network element/function 110-N comprises a processor 1022-N coupled to a memory 1026-N and interface circuitry 1020-N. The processor 1022-N of network element/function 110-N includes a security management processing module 1024-N that may be implemented at least in part in the form of software executed by the processor 1022-N. The security management processing module 1024-N performs security management described in conjunction with subsequent figures and otherwise herein. The memory 1026-N includes a security management storage module 1028-N that stores data generated or otherwise used during security management operations.
The processors 1022-1 and 1022-N of the respective network elements/functions 110-1 and 110-N may comprise, for example, microprocessors, application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), digital signal processors (DSPs) or other types of processing devices or integrated circuits, as well as portions or combinations of such elements. Such integrated circuit devices, as well as portions or combinations thereof, are examples of “circuitry” as that term is used herein. A wide variety of other arrangements of hardware and associated software or firmware may be used in implementing the illustrative embodiments.
The memories 1026-1 and 1026-N of the respective network elements/functions 110-1 and 110-N may be used to store one or more software programs that are executed by the respective processors 1022-1 and 1022-N to implement at least a portion of the functionality described herein. For example, security management operations and other functionality as described in conjunction with subsequent figures and otherwise herein may be implemented in a straightforward manner using software code executed by processors 1022-1 and 1022-N.
A given one of the memories 1026-1 and 1026-N may therefore be viewed as an example of what is more generally referred to herein as a computer program product or still more generally as a processor-readable storage medium that has executable program code embodied therein. Other examples of processor-readable storage media may include disks or other types of magnetic or optical media, in any combination. Illustrative embodiments can include articles of manufacture comprising such computer program products or other processor-readable storage media.
The memories 1026-1 and 1026-N may more particularly comprise, for example, an electronic random-access memory (RAM), such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memories such as flash memory, magnetic RAM (MRAM), phase-change RAM (PC-RAM) or ferroelectric RAM (FRAM). The term “memory” as used herein is intended to be broadly construed, and may additionally or alternatively encompass, for example, a read-only memory (ROM), a disk-based memory, or other type of storage device, as well as portions or combinations of such devices.
Interface circuitry 1020-1 and 1020-N of the respective network elements/functions 110-1 and 110-N illustratively comprise transceivers or other communication hardware or firmware that allows the associated system elements to communicate with one another in the manner described herein.
Network element/function 110-1 is configured for communication with network element/function 110-N, and vice-versa, via their respective interface circuitry 1020-1 and 1020-N. This communication involves network element/function 110-1 sending data to the network element/function 110-N, and the network element/function 110-N sending data to the network element/function 110-1. However, in alternative embodiments, other network elements may be operatively coupled between the network elements/functions 110-1 and 110-N. The term “data” as used herein is intended to be construed broadly, so as to encompass any type of information that may be sent between network elements/functions (as well as between UE 106 and a core network 104) including, but not limited to, messages, identifiers, keys, indicators, user data, control data, etc.
It is to be appreciated that the particular arrangement of components shown in FIG. 10 is an example, and numerous alternative configurations may be used in other embodiments. For example, any given network element/function can be configured to incorporate additional or alternative components and to support other communication protocols.
Other system elements may each also be configured to include components such as a processor, memory and network interface. These elements need not be implemented on separate stand-alone processing platforms, but could instead, for example, represent different functional portions of a single common processing platform.
FIG. 11 is a block diagram of a UE 106 in an illustrative embodiment. From a functional standpoint, the UE 106 is composed of at least two parts: Mobile Equipment (ME) 1100 and a Universal Subscriber Identity Module (USIM) 1160. ME 1100 comprises a radio interface component 1102, one or more processors 1104, a memory 1106, and a user interface component 1108. The UE 106 may also comprise a battery 1110. Radio interface component 1102 is a hardware component or means that represents the local radio resources of the UE 106, such as a Radio Frequency (RF) unit 1120 (e.g., one or more radio transceivers) and one or more antennas 1122. Radio interface component 1102 may be configured for 5G New Radio (NR), Long Term Evolution (LTE), WiFi, Bluetooth, etc. Processor 1104 represents the internal circuitry, logic, hardware, means, etc., that provides the functions of the UE 106. Processor 1104 may be configured to execute instructions 1140 for software that are loaded into memory 1106. Processor 1104 may execute an Operating System (OS) 1134 for the UE 106 that manages hardware and software resources, and one or more application clients 1135 for an application. Processor 1104 may also execute a security controller 1136, which comprises a component or means for performing security mechanisms within the UE 106 (i.e., within the ME 1100), such as integrity protection mechanisms and/or encryption mechanisms. User interface component 1108 is a hardware component for interacting with an end user. For example, user interface component 1108 may comprise a display 1150, screen, touch screen, and/or the like (e.g., a Liquid Crystal Display (LCD), a Light Emitting Diode (LED) display, etc.). User interface component 1108 may include a keyboard or keypad, a tracking device (e.g., a trackball or trackpad), a speaker, a microphone, etc.
USIM 1160 is an integrated circuit that provides security and integrity functions for the UE 106. USIM 1160 includes or is provisioned with a subscription profile associated with a subscription of a subscriber. A subscription profile may include a variety of information, such as subscription credentials (e.g., SUPI) used to uniquely identify a subscription and to mutually authenticate the UE 106 and a network.
The UE 106 may comprise various other components not specifically illustrated in FIG. 11.
FIG. 12 is a flow chart illustrating a method 1200 of performing an enhanced deregistration procedure in an illustrative embodiment. The steps of method 1200 will be described with reference to an apparatus, which may comprise a network element/function 110, a UE 106, etc. The steps of the flow charts described herein are not all inclusive and may include other steps not shown, and the steps may be performed in an alternative order.
The apparatus identifies subscription data 911 regarding a subscription 910 for a UE 106 (step 1202). As above, one or more users 902 may share the subscription 910 linked to UE 106, so multiple, different user profiles 914 may be linked to the subscription 910. Thus, a plurality of identifiers (e.g., UE ID 906 and one or more user IDs 912 and/or user profile IDs 916) correspond with the UE 106.
The enhanced deregistration procedure assumes there was a previous or prior registration regarding the UE 106. For example, a previous registration (also referred to as first registration) may be to the UE ID 906 of the UE 106 (i.e., no user 902 logged into the UE 106). In another example, a previous registration may be to a user ID 912 (or user profile ID 916) of one of the user profiles 914 (i.e., when a user 902 is logged into the UE 106). The previous registration therefore has an associated identifier, such as the UE ID 906 or a user ID 912.
The apparatus may detect a switch or change from the previous registration to a subsequent or second registration, or otherwise determine, such as by receipt of information, a message, or the like that a registration change has occurred (step 1204). For example, the subsequent registration may be to the UE ID 906 of the UE 106 (i.e., a user 902 logs out of the UE 106). In another example, the subsequent registration may be to a new or different user ID 912 of a user profile 914 (i.e., when a new user 902 logs into the UE 106). The subsequent registration therefore has an associated identifier that is different than the identifier of the prior registration. Due to the switch from the previous registration to the subsequent registration, the apparatus initiates the enhanced deregistration procedure for the previous registration (step 1206).
For the enhanced deregistration procedure, the apparatus holds, maintains, or transitions the previous registration in a suspended state. In other words, the previous registration is held dormant instead of initiating a full or complete deregistration procedure. FIG. 13 illustrates registration procedures in an illustrative embodiment. In this example, UE 106 (through UE ID 906) or user 902- 1 (through user ID 912-1) has a previous registration 1302 with the core network 104. When the apparatus detects a switch from the previous registration 1302 to a subsequent registration 1304 of a different identifier from the previous registration 1302, the apparatus transitions the previous registration 1302 to a suspended state 1306. In the example of FIG. 13, a new user 902-2 logs into the UE 106, and the subsequent registration 1304 may be to the user ID 912-2 of the new user 902-2.
The apparatus may also update state data for the UE subscription profile 908 and/or user profile(s) 914 (optional step 1208 of FIG. 12). FIG. 14 illustrates the UE subscription profile 908 and/or user profile(s) 914 associated with a subscription 910 in an illustrative embodiment. In an embodiment, the UE subscription profile 908 and/or user profile 914 may indicate or include state data 1404. The state data 1404 may comprise an active state 1406 and an inactive state 1408, although other states may be considered herein. A UE 106 (and its associated UE subscription profile 908) may be considered in an active state 1406 when the UE ID 906 is registered to the core network 104 (i.e., has been authenticated and authorized to the subscription 910 to access the core network 104). Otherwise, the UE 106 may be considered in an inactive state 1408. A user 902 (and its associated user profile 914) may be considered in an active state 1406 when the associated user ID 912 or user profile ID 916 is registered to the core network 104 (i.e., has been authenticated and authorized to use a linked subscription 910 to access the core network 104). Otherwise, a user 902 (and its associated user profile 914) may be considered in an inactive state 1408. A single one of the UE subscription profile 908 and the user profiles 914 may be in an active state 1406 at a time. In an embodiment, the state data 1404 may further include the suspended state 1306. A UE subscription profile 908 or user profile 914 may be considered in a suspended state 1306 when not in an active state 1406 from a previous registration 1302 and not deregistered from the core network 104. Thus, the previous registration 1302, the UE subscription profile 908 or user profile 914, etc., may be considered in a suspended state 1306.
When the previous registration 1302 is in a suspended state 1306, the apparatus may store or retain data (e.g., context information) and/or resources attached to the previous registration 1302 (optional step 1210 of FIG. 12) instead of tearing down or releasing the data, resources, etc. Control plane data and/or user plane data associated with the previous registration 1302 may be idle while in the suspended state 1306. The apparatus may also provide an enhanced deregistration indicator to one or more NFs 110 or UE 106 instructing the NFs 110 or UE 106 to maintain the previous registration 1302 in a suspended state (optional step 1212).
When/if a request, instruction, or event is detected to reactivate the previous registration 1302, the apparatus may initiate an enhanced re-registration procedure (step 1214). For the enhanced re-registration procedure, data and/or resources attached to the previous registration 1302 were retained and may be re-used. The apparatus transitions the previous registration 1302 from the suspended state 1306 to an active state 1406. For example, the apparatus may update state data 1404 for the UE subscription profile 908 and/or user profile(s) 914 associated with the previous registration 1302 to the active state 1406 (optional step 1216). Thus, the UE subscription profile 908 and/or user profile(s) 914 associated with the previous registration 1302 are again activated so that the previous registration 1302 is valid. The apparatus may also provide an enhanced re-registration indicator to one or more NFs 110 or UE 106 instructing the NFs 110 or UE 106 to reactivate the previous registration 1302 (optional step 1218). If a request, instruction, or event is not detected to reactivate the previous registration 1302 (such as within a configurable time period), the apparatus may release the data for the previous registration 1302 and/or initiate a full deregistration procedure (step 1220).
An enhanced deregistration procedure is described in further detail below, and the processes, systems, and methods described may be incorporated in above embodiments as desired. In general, an enhanced deregister procedure may be implemented via one or more network functions (e.g., AMF 212, SMF 214, PCF 216, and UPF 240) and a UE 106.
FIGS. 15A-15C illustrate registration procedures in illustrative embodiments. Any omitted messages for registration may follow the existing registration procedure. A UE 106 needs to register with the core network 104 to get authorized to receive services, to enable mobility tracking, and to enable reachability. The UE 106 initiates a registration procedure using a registration type, such as initial registration or a Mobility and Registration Update (MRU), which is described in further detail in 3GPP TS 23.502. In FIG. 15A, a UE 106 registers with the core network 104 with its UE ID 906 and without a user ID 912 (i.e., no user 902 logged into the UE 106). UE 106 sends a registration request 1501 (e.g., an initial registration request) to the AMF 212 (through a RAN). The registration request 1501 includes the UE ID 906 (e.g., SUCI, 5G-GUTI or Permanent Equipment Identifier (PEI)) along with other parameters, but does not include a user ID 912 for a particular user 902 of the UE 106. AMF 212 is configured to perform or support registration management within core network 104. Registration management allows a UE 106 or a user 902 of a UE 106 (i.e., through an associated user profile 914) to register and deregister with the core network 104, handles initial registration to authorize a UE 106 and create a UE context or to authorize a user 902 and create a user profile context, to manage periodic registration updates, etc. Messages, steps, processes, etc., of registration management are described in further detail in 3GPP TS 23.502. AMF 212 triggers primary authentication (through AUSF 210 and UDM 218) to authenticate the SUPI reported by UE 106. During the registration procedure, AMF 212 also retrieves subscription data 911 associated with the UE ID 906, such as from UDM 218. AMF 212 updates state data 1404 of the UE subscription profile 908 to the active state 1406. After successful authentication/registration, AMF 212 responds to UE 106 by sending a registration accept 1502 that includes an indication that service for UE 106 is allowed. AMF 212 establishes or creates a UE context 1522 for UE 106, which is a block of information associated with an (one) active UE 106. UE 106 also stores a UE context 1522.
A user 902 needs to register with the core network 104 through the UE 106 to get authorized to receive services. In FIG. 15B, a UE 106 registers to the core network 104 with a user ID 912 (e.g., a user 902-1 has logged into the UE 106). UE 106 sends a registration request 1501 (e.g., an initial registration request) to the AMF 212. UE 106 may include a variety of information in the registration request 1501. For example, UE 106 may include a user ID 912-1 (i.e., USER ID_1) for the user 902-1, a user profile ID 916-1 (i.e., USER PROFILE ID_1) associated with the user ID 912-1, and/or other data/parameters. AMF 212 may trigger primary authentication (through AUSF 210 and UDM 218) to authenticate the SUPI reported by UE 106, if not already performed. During the registration procedure, AMF 212 retrieves subscription data 911 for the subscription 910 associated with the user ID 912, such as from UDM 218. More particularly, AMF 212 retrieves data for one or more of the user profiles 914 linked to the subscription 910, such as the user profile 914-1 associated with the user ID 912-1 and/or user profile ID 916- 1 provided by UE 106. AMF 212 may trigger authentication of the user ID 912-1 provided by the UE 106, although other network functions or the UE 106 may trigger authentication of the user ID 912-1. AMF 212 updates state data 1404 of the user profile 914-1 to the active state 1406. AMF 212 responds to the UE 106 by sending a registration accept 1502 that includes an indication that service for the user ID 912-1 is allowed. AMF 212 establishes a user profile context 1524 for the user profile 914-1 associated with the user ID 912- 1 , which is a block of information associated with a (one) user profile 914. UE 106 may also store data for one or more of the user profiles 914 linked to the subscription 910, such as user profile contexts 1524, user profile IDs 916, capabilities, a log-in state of multiple user profiles 914, etc.
After registration with or without a user ID 912, a new or different user 902 (e.g., user 902-2 associated with user profile 914-2) may intend to use UE 106 by logging in through user login 904. In response to a new user login to UE 106, UE 106 triggers a registration procedure to register a new user profile 914-2 in the core network 104. In FIG. 15C, UE 106 sends a registration message 1503, such as a new registration request or an MRU (Mobility and Registration Update) message, to switch registration to the new or different user profile 914-2 (e.g., from UE 106 or user profile 914-1 to user profile 914-2). UE 106 may include a variety of information in the registration message 1503 to indicate switching or change to a new user 902-2. For example, UE 106 may include a user profile switching indicator 1512 in the registration message 1503. UE 106 may include a new user ID 912-2 (i.e., USER ID_2) for the new user 902-2, a user profile ID 916-2 (i.e., USER PROFILE ID_2) associated with the new user ID 912-2, a user ID 912-1 (i.e., USER ID_1) for a previous user 902-1 (if applicable), a user profile ID 916-1 (i.e., USER PROFILE ID_1) associated with a previous user ID 912-1 (if applicable), and/or other data/parameters.
During the registration procedure, AMF 212 may retrieve data for the user profile 914-2 associated with the user ID 912-2 and/or user profile ID 916-2 provided by UE 106, if not already acquired, such as from UDM 218. AMF 212 may trigger authentication of the user ID 912-2 provided by the UE 106, although other network functions or the UE 106 may trigger authentication of the user ID 912-2. AMF 212 updates state data 1404 of the user profile 914-2 to the active state 1406 (not shown).
AMF 212 also initiates or performs an enhanced deregistration procedure of a previous registration to the UE 106 or a previous user profile 914-1. For the enhanced deregistration procedure, AMF 212 stores or retains data attached to the previous registration, such as the UE context 1522 (i.e., SM context, security context, access and mobility (AM) context, etc.) or the user profile context 1524. Thus, AMF 212 does not initiate a deregistration procedure for the UE 106 or a previous user profile 914-1 in response to the new/current registration procedure, and/or release context information for the previous registration. Instead, AMF 212 retains the context information for the previous registration when switching to a new user profile 914-2 (or to the UE 106). AMF 212 may also update the state data 1404 in the UE subscription profile 908 or the user profile 914-1 associated with the user ID 912-1 to the suspended state 1306.
AMF 212 responds to the UE 106 by sending a registration accept 1504 that includes an indication that service for the user ID 912-2 is allowed. AMF 212 may also include an enhanced deregister indicator 1514 (or cause code) in the registration accept 1504 instructing UE 106 to perform an enhanced deregistration procedure. AMF 212 may also inform or instruct other NFs 110, such as those involved in any PDU sessions attached to the UE 106 or a previous user profile 914- 1, to perform enhanced deregistration. For example, AMF 212 may send a Session Management (SM) request/message 1505 to SMF 214 that includes an enhanced deregister indicator 1514. In response to the enhanced deregister indicator 1514, SMF 214 may suspend a PDU session attached to the UE 106 (i.e., when UE 106 was previously registered without an associated user 902) or a previous user profile 914-1 (i.e., when a user profile 914-1 was previously registered). SMF 214 may therefore suspend session management for the PDU session, store or retain any context information for the UE 106 or the previous user profile 914-1, such as SM context information. SMF 214 may also send a PDU session request/message 1506 to a UPF(s) 240 involved in the PDU session, that includes an enhanced deregister indicator 1514. In response to the enhanced deregister indicator 1514, UPF 240 may suspend the PDU session attached to the UE 106 (i.e., when UE 106 was previously registered without an associated user 902) or a previous user profile 914- 1 (i.e., when a user profile 914-1 was previously registered). UPF 240 may therefore suspend data packet routing and forwarding for the PDU session, may buffer the data packets, etc. SMF 214 may send a policy control request/message 1507 to PCF 216 that includes an enhanced deregister indicator 1514. In response to the enhanced deregister indicator 1514, PCF 216 may suspend policy control for the UE 106 (i.e., when UE 106 was previously registered without an associated user 902) or a previous user profile 914-1 (i.e., when a user profile 914-1 was previously registered). PCF 216 may store or retain any policy and/or charging information for the UE 106 or the previous user profile 914-1.
One technical benefit of the enhanced deregistration procedure is the NFs 110 and UE 106 maintain information regarding a previous registration. If, for example, registration reverts back to a previous registration (i.e., back to the UE 106 with no associated user 902 or to a previous user profile 914-1), context information (e.g., security keys), PDU session data, etc., is available, and reauthentication can be avoided.
FIG. 16 is a diagram illustrating context information 1600 attached to a registration of a UE 106 or a user profile 914 in an illustrative embodiment. The context information 1600 may include a UE context 1522 associated with a UE subscription profile 908 when a UE 106 registers with the core network 104. The context information 1600 may include a user profile context 1524 associated with a user profile 914 when a user 902 registers with the core network 104. Each of a UE context 1522 and a user profile context 1524 may include a security context 1610, such as a NAS security context 1612 between the UE 106 and the AMF 212. Each of the UE context 1522 and the user profile context 1524 may include an SM context 1614, such as generated at the SMF 214. Each of the UE context 1522 and the user profile context 1524 may include policy information 1616 and/or charging information 1618, such as generated at the PCF 216. Each of the UE context 1522 and the user profile context 1524 may include PDU session data 1620, such as handled by UPF 240. FIG. 16 illustrates general context information 1600 as an example, and other information may be attached to a registration of a UE 106 or user profile 914. NFs 110 and/or UE 106 may retain this and/or other data when performing an enhanced deregistration procedure.
FIG. 17 is a flow chart illustrating a method 1700 of registration management at an AMF 212 in an illustrative embodiment. AMF 212 performs a registration procedure to register a first identifier corresponding with UE 106 (step 1701), such as a UE ID 906 or a user ID 912 of the one or more user profiles 914. The UE 106 or a user 902 of the UE 106 (i.e., a user profile 914) is therefore registered in the core network 104 (referred to as a previous registration) based on their associated identifier. Subsequently, AMF 212 receives a registration message from UE 106 to switch registration to a different or second identifier (step 1702). For example, the registration message, such as an initial registration request or an MRU message, may be to switch registration from the UE ID 906 to a user ID 912 of a new user profile 914 (or vice-versa), or from a user ID 912 of a previous user profile 914 to the user ID 912 of a new user profile 914. In response to the registration message, AMF 212 performs registration management to register the second identifier in the core network 104 (step 1704). As part of registration management, AMF 212 may trigger authentication of the second identifier (optional step 1706). AMF 212 may create or establish context information 1600 associated with the second identifier, if not already created. AMF 212 may update state data 1404 in a UE subscription profile 908 or a user profile 914 associated with the second identifier, to the active state 1406 (optional step 1708).
AMF 212 initiates an enhanced deregistration procedure for the previous registration to the first identifier (step 1710). For the enhanced deregistration procedure, AMF 212 stores or retains context information 1600 associated with the first identifier or otherwise attached to the previous registration (step 1712), such as the UE context 1522 (i.e., when UE 106 was previously registered without an associated user 902) or the user profile context 1524 (i.e., when a user profile 914- 1 was previously registered). In other words, AMF 212 does not release the UE context 1522 or the user profile context 1524 in response to the subsequent registration. Instead, AMF 212 maintains context information 1600 for the previous registration, at least temporarily. AMF 212 may also update the state data 1404 in the UE subscription profile 908 (when the previous registration was to the UE 106) or in the user profile 914 associated with a previous user profile 914 (when the previous registration was to the user profile 914), to the suspended state 1306 (optional step 1714).
AMF 212 may also inform or instruct other NFs 110 or the UE 106 to perform enhanced deregistration. For example, AMF 212 may provide an enhanced deregister indicator 1514 (or cause code) to the UE 106 (optional step 1716), such as in a registration accept or in another NAS message. The enhanced deregister indicator 1514 informs or instructs the UE 106 to perform enhanced deregistration of the previous registration, or otherwise retain context information 1600 attached to the previous registration. AMF 212 may send an SM context update message to SMF 214 with an enhanced deregister indicator 1514 (optional step 1718). The enhanced deregister indicator 1514 informs or instructs the SMF 214 to perform enhanced deregistration of the previous registration, or otherwise retain context information 1600 attached to the previous registration, such as an SM context 1614.
AMF 212 may perform other actions as part of the enhanced deregistration procedure so that context information 1600 regarding the previous registration is preserved, at least in part, within the core network 104 and/or the UE 106.
AMF 212 sends a registration accept message to the UE 106 that includes an indication that registration of the second identifier to the UE 106 or a new user profile 914 is successful, and service is allowed for the new user 902 (step 1720).
FIG. 18 is a flow chart illustrating a method 1800 of registration management at a UE 106 in an illustrative embodiment. An assumption for method 1800 is that the UE 106 or a user 902 of the UE 106 (i.e., a user profile 914) is registered in the core network 104 (referred to as a previous registration) via a first identifier. UE 106 detects a change of user login 904 (step 1802). For example, UE 106 may detect a login of a new (or different) user 902, a logout of a present or current user 902, etc. In response to the login change, UE 106 sends a registration message to AMF 212 to switch registration to a different or second identifier (step 1804). For example, the registration message, such as an initial registration request or an MRU message, may be to switch registration from the UE 106 to the new user profile 914 (or vice-versa), or from a previous user profile 914 to the new user profile 914. In an embodiment, UE 106 may include a user profile switching indicator 1512 in the registration request (optional step 1806), to signal to AMF 212 that a switch occurred at UE 106.
After sending the registration request, UE 106 may respond to a query or challenge to authenticate the second identifier, such as a new user ID 912 and/or new user profile ID 916 associated with a new user profile 914. UE 106 receives a registration accept message from AMF 212 with an indication that registration of the second identifier is successful, and service is allowed for the new user 902 or user profile 914 (step 1808). UE 106 may create or establish a context information associated with the second identifier being registered, if not already created. UE 106 may update state data 1404 in a UE subscription profile 908 or a user profile 914 associated with the second identifier, to the active state 1406 (optional step 1810).
UE 106 initiates enhanced deregistration of the previous registration to the UE 106 or previous user profile 914 (step 1812). In an embodiment, the registration accept message may include an enhanced deregister indicator 1514 informing or instructing the UE 106 to perform enhanced deregistration of the previous registration, or otherwise retain context information 1600 for the previous registration. Alternatively, UE 106 may be configured via local policy to perform enhanced deregistration. For the enhanced deregistration procedure, UE 106 stores or retains the UE context 1522 (i.e., when UE 106 was previously registered without an associated user 902) or the user profile context 1524 (i.e., when a user profile 914 was previously registered) attached to the previous registration (step 1814). In other words, UE 106 does not release the UE context 1522 or the user profile context 1524 in response to the registration of the second identifier. Instead, UE 106 maintains context information 1600 for the previous registration, at least temporarily. UE 106 may also update the state data 1404 in the UE subscription profile 908 (when the previous registration was to the UE 106) or in the previous user profile 914 (when the previous registration was to the user profile 914), to the suspended state 1306 (optional step 1816). UE 106 may perform other actions as part of the enhanced deregistration procedure so that context information 1600 regarding the previous registration is preserved, at least in part.
FIG. 19 is a flow chart illustrating a method 1900 of enhanced deregistration at an SMF 214 in an illustrative embodiment. SMF 214 receives an SM context update message from AMF 212 with an enhanced deregister indicator 1514 (step 1902). The enhanced deregister indicator 1514 informs or instructs the SMF 214 to perform enhanced deregistration of the previous registration (e.g., retain context information 1600 for the previous registration, such as an SM context 1614). SMF 214 initiates enhanced deregistration of the previous registration to the UE 106 or previous user profile 914 (step 1904). In an embodiment, SMF 214 stores or retains the SM context 1614 attached to the previous registration (step 1906), at least temporarily. SMF 214 may also send a PDU session message to a UPF 240 (or multiple UPFs) with an enhanced deregister indicator 1514 (optional step 1908). The enhanced deregister indicator 1514 informs or instructs the UPF 240 to perform enhanced deregistration of the previous registration (e.g., retain PDU session data 1620 for the previous registration). In an embodiment, SMF 214 may send a policy control message to PCF 216 with an enhanced deregister indicator 1514 (optional step 1910). The enhanced deregister indicator 1514 informs or instructs the PCF 216 to perform enhanced deregistration of the previous registration, or otherwise retain policy information 1616 and/or charging information 1618 attached to the previous registration.
FIG. 20 is a flow chart illustrating a method 2000 of enhanced deregistration at a UPF 240 in an illustrative embodiment. UPF 240 receives a PDU session message from SMF 214 with an enhanced deregister indicator 1514 (step 2002). The enhanced deregister indicator 1514 informs or instructs the UPF 240 to perform enhanced deregistration of the previous registration (e.g., retain PDU session data 1620 for the previous registration). UPF 240 initiates enhanced deregistration of the previous registration to the UE 106 or previous user profile 914 (step 2004). In an embodiment, UPF 240 stores, retains, or buffers PDU session data 1620 (e.g., packets) attached to the previous registration (step 2006), at least temporarily. UPF 240 may also suspend resources related to the PDU session.
FIG. 21 is a flow chart illustrating a method 2100 of enhanced deregistration at a PCF 216 in an illustrative embodiment. PCF 216 receives a policy control message from SMF 214 with an enhanced deregister indicator 1514 (step 2102). The enhanced deregister indicator 1514 informs or instructs the PCF 216 to perform enhanced deregistration of the previous registration, or otherwise retain policy information 1616 and/or charging information 1618 for the previous registration. PCF 216 initiates enhanced deregistration of the previous registration to the UE 106 or previous user profile 914 (step 2104). In an embodiment, PCF 216 stores or retains policy information 1616 (e.g., a UE policy, a user policy, etc.) and/or charging information 1618 attached to the previous registration (step 2106), at least temporarily.
FIG. 22 is a flow chart illustrating additional steps of an enhanced deregistration procedure in an illustrative embodiment. Enhanced deregistration may be temporary or time bounded. Thus, AMF 212, for example, may set a deregistration timer (step 2214) to a configurable time period. AMF 212 monitors state data 1404 in the UE subscription profile 908 or the previous user profile 914 attached to the previous registration (step 2216), such as whether there is a state change from the suspended state 1306 to the active state 1406. For example, the present or current user 902 of the UE 106 may log out of UE 106, a previous user 902 may log back into the UE 106 prompting a new registration message, etc. When this occurs, AMF 212 may update the state data 1404 in the UE subscription profile 908 or in the previous user profile 914 associated with the previous registration to the active state 1406. When the deregistration timer expires before the state change (i.e., state data 1404 changed to the active state 1406), AMF 212 initiates full or complete deregistration of the previous registration (step 2218). For example, AMF 212 may release or delete the UE context 1522 or the user profile context 1524 attached to the previous registration (optional step 2220). AMF 212 may also inform or instruct other NFs 110 or the UE 106 to perform full or complete deregistration of the previous registration. One technical benefit is if a previous user 902, for example, does not log back into the UE 106 within the time period, context information 1600 may be released and corresponding network resources made available.
UE 106 and other NFs 110 may perform a similar operation as described in FIG. 22 for AMF 212.
FIG. 23 is a flow chart illustrating additional steps of registration management at an AMF 212 in an illustrative embodiment. At some point, the UE 106 or the previous user profile 914 that were (enhanced) deregistered, may be reregistered in the core network 104. When this occurs, AMF 212 initiates an enhanced re-registration procedure for the UE 106 or the previous user profile 914 (step 2302). AMF 212 activates or reactivates the UE context 1522 or the user profile context 1524 attached to the previous registration (step 2304), which was retained by AMF 212. AMF 212 also updates the state data 1404 in the UE subscription profile 908 or in the previous user profile 914 attached to the previous registration, to the active state 1406 (step 2306). One technical benefit is the UE 106 or the previous user profile 914 may be re-registered with reduced end-to-end signaling, the UE 106 or the user profile 914 do not need to be re-authenticated, and keying material and the like do not need to be re-generated, which saves network resources.
UE 106 may perform a similar operation as described in FIG. 23 for AMF 212.
FIG. 24 is a flow chart illustrating additional steps of registration management at an AMF 212 in an illustrative embodiment. AMF 212 may automatically switch back to the previous registration. In an embodiment, AMF 212 detects that the present or current user 902 of the UE 106 logs out of UE 106 (step 2402). In response to the logout, AMF 212 may update the state data 1404 in the user profile 914 associated with the logged-out user 902 to the inactive state 1408, and initiate an enhanced deregistration procedure for the logged-out user 902, as described above. Additionally, AMF 212 automatically initiates the enhanced re-registration procedure of the UE 106 or the previous user profile 914 (step 2302). After enhanced re-registration is complete, AMF 212 may exchange NAS messages with the UE 106 that are protected based on the UE context 1522 or the user profile context 1524 that were reactivated (step 2404). For example, AMF 212 may send a registration request to UE 106 (regarding the previous registration) that is integrity protected based on an integrity key of the UE context 1522 or the user profile context 1524. AMF 212 will be able to identify the UE 106 via the GUTI in the context information 1600, and will able to verify the integrity protection of NAS messages via other keys available in the AMF 212. One technical benefit is the UE 106 or the previous user profile 914 may be re-registered with reduced end-to-end signaling, the UE 106 or the user profile 914 do not need to be re-authenticated, and keying material and the like do not need to be re-generated, which saves network resources.
UE 106 may perform a similar operation as described in FIG. 24 for AMF 212.
Any of the various elements or modules shown in the figures or described herein may be implemented as hardware, software, firmware, or some combination of these. For example, an element may be implemented as dedicated hardware. Dedicated hardware elements may be referred to as “processors”, “controllers”, or some similar terminology. When provided by a processor, the functions may be provided by a single dedicated processor, by a single shared processor, or by a plurality of individual processors, some of which may be shared. Moreover, explicit use of the term “processor” or “controller” should not be construed to refer exclusively to hardware capable of executing software, and may implicitly include, without limitation, digital signal processor (DSP) hardware, a network processor, application specific integrated circuit (ASIC) or other circuitry, field programmable gate array (FPGA), read only memory (ROM) for storing software, random access memory (RAM), non-volatile storage, logic, or some other physical hardware component or module.
Also, an element may be implemented as instructions executable by a processor or a computer to perform the functions of the element. Some examples of instructions are software, program code, and firmware. The instructions are operational when executed by the processor to direct the processor to perform the functions of the element. The instructions may be stored on storage devices that are readable by the processor. Some examples of the storage devices are digital or solid-state memories, magnetic storage media such as a magnetic disks and magnetic tapes, hard drives, or optically readable digital data storage media.
As used in this application, the term “circuitry” may refer to one or more or all of the following:
(a) hardware-only circuit implementations (such as implementations in only analog and/or digital circuitry);
(b) combinations of hardware circuits and software, such as (as applicable):
(i) a combination of analog and/or digital hardware circuit(s) with software/firmware; and
(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); and
(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
Although specific embodiments were described herein, the scope of the disclosure is not limited to those specific embodiments. The scope of the disclosure is defined by the following claims and any equivalents thereof.

Claims

Claims:
1. An apparatus comprising: an access and mobility management function of a core network, comprising: at least one processor; and at least one memory storing instructions, that when executed by the at least one processor, cause the access and mobility management function at least to perform: identifying subscription data comprising a user equipment subscription for user equipment, and one or more user profiles linked to the user equipment subscription; performing a registration procedure to register a first identifier from a plurality of identifiers corresponding with the user equipment, wherein the plurality of identifiers comprises a user equipment subscription identifier of the user equipment and one or more user profile identifiers of the one or more user profiles; receiving a registration message from the user equipment regarding registration of a second identifier from the plurality of identifiers different than the first identifier; and initiating an enhanced deregistration procedure for the first identifier in response to the registration message by: transitioning the first identifier to a suspended state; and retaining context information associated with the first identifier when in the suspended state.
2. The apparatus of claim 1, wherein the at least one memory and the at least one processor further cause the access and mobility management function at least to perform: initiating the enhanced deregistration procedure by updating state data of a user equipment subscription profile or a first one of the user profiles associated with the first identifier, to the suspended state.
3. The apparatus of claim 2, wherein the at least one memory and the at least one processor further cause the access and mobility management function at least to perform: updating the state data of the user equipment subscription profile or a second one of the user profiles associated with the second identifier, to an active state.
4. The apparatus of claim 1 , wherein the at least one memory and the at least one processor further cause the access and mobility management function at least to perform: initiating the enhanced deregistration procedure by sending a non-access stratum message to the user equipment with an enhanced deregister indicator instructing the user equipment at least to retain context information associated with the first identifier.
5. The apparatus of claim 1, wherein the at least one memory and the at least one processor further cause the access and mobility management function at least to perform: initiating the enhanced deregistration procedure by sending a session management update message to a session management function with an enhanced deregister indicator instructing the session management function at least to retain a session management context associated with the first identifier.
6. The apparatus of claim 1, wherein the at least one memory and the at least one processor further cause the access and mobility management function at least to perform: initiating the enhanced deregistration procedure by: setting a deregistration timer; monitoring state data of a user equipment subscription profile or a user profile associated with the first identifier, for a state change to an active state; and releasing the context information associated with the first identifier when the deregistration timer expires before the state change.
7. The apparatus of claim 1, wherein the at least one memory and the at least one processor further cause the access and mobility management function at least to perform: detecting a log out of a current user of the user equipment; and automatically initiating an enhanced re-registration procedure of the first identifier by activating a user equipment context or a user profile context associated with the first identifier.
8. The apparatus of claim 7, wherein the at least one memory and the at least one processor further cause the access and mobility management function at least to perform: exchanging, after the enhanced re-registration procedure, one or more non-access stratum messages with the user equipment protected based on the user equipment context or the user profile context.
9. A method, comprising: in an access and mobility management function of a core network: identifying subscription data comprising a user equipment subscription for user equipment, and one or more user profiles linked to the user equipment subscription; performing a registration procedure to register a first identifier from a plurality of identifiers corresponding with the user equipment, wherein the plurality of identifiers comprises a user equipment subscription identifier of the user equipment and one or more user profile identifiers of the one or more user profiles; receiving a registration message from the user equipment regarding registration of a second identifier from the plurality of identifiers different than the first identifier; and initiating an enhanced deregistration procedure for the first identifier in response to the registration message by: transitioning the first identifier to a suspended state; and retaining context information associated with the first identifier when in the suspended state.
10. The method of claim 9, wherein the initiating the enhanced deregistration procedure comprises: updating state data of a user equipment subscription profile or a first one of the user profiles associated with the first identifier, to the suspended state.
11. The method of claim 10, further comprising: updating the state data of the user equipment subscription profile or a second one of the user profiles associated with the second identifier, to an active state.
12. The method of claim 9, wherein the initiating the enhanced deregistration procedure comprises: sending a non-access stratum message to the user equipment with an enhanced deregister indicator instructing the user equipment at least to retain context information associated with the first identifier.
13. The method of claim 9, wherein the initiating the enhanced deregistration procedure comprises: sending a session management update message to a session management function with an enhanced deregister indicator instructing the session management function at least to retain a session management context associated with the first identifier.
14. The method of claim 13, further comprising: in the session management function: sending a packet data unit session message to a user plane function with the enhanced deregister indicator instructing the user plane function at least to retain packet data unit session data associated with the first identifier.
15. The method of claim 13, further comprising: in the session management function: sending a policy control message to a policy control function with the enhanced deregister indicator instructing the policy control function at least to retain one or more of policy information and charging information associated with the first identifier.
16. The method of claim 9, wherein the initiating the enhanced deregistration procedure comprises: setting a deregistration timer; monitoring state data of a user equipment subscription profile or a user profile associated with the first identifier, for a state change to an active state; and releasing the context information associated with the first identifier when the deregistration timer expires before the state change.
17. The method of claim 9, further comprising: detecting a log out of a current user of the user equipment; and automatically initiating an enhanced re-registration procedure of the first identifier by activating a user equipment context or a user profile context associated with the first identifier.
18. The method of claim 17, further comprising: exchanging, after the enhanced re-registration procedure, one or more non-access stratum messages with the user equipment protected based on the user equipment context or the user profile context.
19. An apparatus comprising: user equipment communicatively coupled to a core network; the user equipment comprising: at least one processor; and at least one memory storing instruction that, when executed by the at least one processor, cause the user equipment at least to perform: identifying subscription data comprising a user equipment subscription for the user equipment, and one or more user profiles linked to the user equipment subscription, wherein a plurality of identifiers corresponding with the user equipment comprise a user equipment subscription identifier of the user equipment and one or more user profile identifiers of the one or more user profiles; detecting a change of user login; sending a registration message to an access and mobility management function of the core network to switch registration from a first identifier of the plurality of identifiers to a second identifier of the plurality of identifiers different from the first identifier; and initiating an enhanced deregistration procedure for the first identifier by: transitioning the first identifier to a suspended state; and retaining context information associated with the first identifier when in the suspended state.
20. The apparatus of claim 19, wherein the at least one memory and the at least one processor further cause the user equipment at least to perform: initiating the enhanced deregistration procedure by updating state data of a user equipment subscription profile or a first one of the user profiles associated with the first identifier, to a suspended state.
21. The apparatus of claim 20, wherein the at least one memory and the at least one processor further cause the user equipment at least to perform: updating the state data of the user equipment subscription profile or a second one of the user profiles associated with the second identifier, to an active state.
22. The apparatus of claim 19, wherein the at least one memory and the at least one processor further cause the user equipment at least to perform: initiating the enhanced deregistration procedure in response to receiving an enhanced deregister indicator from the access and mobility management function in a non-access stratum message.
23. The apparatus of claim 19, wherein the at least one memory and the at least one processor further cause the user equipment at least to perform: initiating the enhanced deregistration procedure by: setting a deregistration timer; monitoring state data of a user equipment subscription profile or a user profile associated with the first identifier, for a state change to an active state; and releasing the context information associated with the first identifier when the deregistration timer expires before the state change.
24. The apparatus of claim 19, wherein the at least one memory and the at least one processor further cause the user equipment at least to perform: detecting a log out of a current user of the user equipment; and automatically initiating an enhanced re-registration procedure of the first identifier by activating a user equipment context or a user profile context associated with the first identifier.
25. The apparatus of claim 24, wherein the at least one memory and the at least one processor further cause the user equipment at least to perform: exchanging, after the enhanced re-registration procedure, non-access stratum messages with the access and mobility management function protected based on the user equipment context or the user profile context.
26. The apparatus of claim 19, wherein the at least one memory and the at least one processor further cause the user equipment at least to perform: including a user profile switching indicator in the registration message to signal that a registration switch occurred at the user equipment.
PCT/IB2025/053547 2024-04-04 2025-04-03 Enhanced deregistration of user equipment and/or user profiles associated with user equipment Pending WO2025210568A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
IN202411027897 2024-04-04
IN202411027897 2024-04-04

Publications (1)

Publication Number Publication Date
WO2025210568A1 true WO2025210568A1 (en) 2025-10-09

Family

ID=95446586

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/IB2025/053547 Pending WO2025210568A1 (en) 2024-04-04 2025-04-03 Enhanced deregistration of user equipment and/or user profiles associated with user equipment

Country Status (1)

Country Link
WO (1) WO2025210568A1 (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20220086789A1 (en) * 2019-05-28 2022-03-17 Vivo Mobile Communication Co., Ltd. Registration switching method, request processing method, information sending method, and related device
US20220377528A1 (en) * 2019-11-04 2022-11-24 Nokia Technologies Oy Dynamically unsubscribing from a plmn/npn service
US20230276237A1 (en) * 2020-08-11 2023-08-31 Telefonaktiebolaget Lm Ericsson (Publ) Resource isolation via associated identifiers

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20220086789A1 (en) * 2019-05-28 2022-03-17 Vivo Mobile Communication Co., Ltd. Registration switching method, request processing method, information sending method, and related device
US20220377528A1 (en) * 2019-11-04 2022-11-24 Nokia Technologies Oy Dynamically unsubscribing from a plmn/npn service
US20230276237A1 (en) * 2020-08-11 2023-08-31 Telefonaktiebolaget Lm Ericsson (Publ) Resource isolation via associated identifiers

Similar Documents

Publication Publication Date Title
US11985496B2 (en) Security solution for switching on and off security for up data between UE and RAN in 5G
US12081978B2 (en) System and method for security protection of NAS messages
US20210168594A1 (en) Secure Session Method And Apparatus
JP2022536924A (en) Method and system for handling closed access group related procedures
US20140304777A1 (en) Securing data communications in a communications network
US11889308B2 (en) Multi-access edge computing (MEC)-key id derivation in authentication between UE and edge servers
WO2019194155A1 (en) An authentication method for next generation systems
US12549946B2 (en) Authentication proxy for AKMA authentication service
US20240276213A1 (en) Security for store and forward service via satellite access
US20250056219A1 (en) Negotiation of security mechanisms that implement combined integrity and encryption algorithms
US20230209337A1 (en) Mec authentication between edge enabler client and edge configuration or enabler server based on akma
WO2025210544A1 (en) Enhanced deregistration of user equipment and/or user profiles associated with user equipment
US20250055678A1 (en) Key generation for combined integrity and encryption algorithms
US20250133475A1 (en) Local routing in non-terrestrial network (ntn) access
WO2025158368A1 (en) Partial user plane protection in mobile networks
WO2024213965A1 (en) Management of akma services to user equipment

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25719462

Country of ref document: EP

Kind code of ref document: A1