IP Library Granted Patent US 12666261
Granted Patent B2
US 12666261 · App. 18/363,543 · Granted Jun 23, 2026

Methods and systems for providing home network routing information of remote user equipment (UE) following authentication failure during establishment of UE-to-network (U2N) relay communication

Inventors: Hongil Kim (San Diego, CA); Soo Bum Lee (San Diego, CA)
Assignee: QUALCOMM Incorporated
H04W12/06H04W12/037
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12666261
App. No.
18/363,543
Granted
Jun 23, 2026
Kind
B2
Abstract

Disclosed are methods and systems for providing home network routing information (HNRI) of remote user equipment (UE) following authentication failure, e.g., during establishment of UE-to-network (U2N) relay communication. In some aspects, a first UE may detect an authentication failure during establishment of a secure connection with a second UE, and in response to detecting the authentication failure, notifies the second UE of the authentication failure. In addition, the HNRI of a first authentication node within the home network of the first UE is provided to a second authentication node within the home network of the second UE, either by the first UE, by the second UE, or from being stored by the second authentication node from a previous interaction involving the first UE.

Claims (118)

1 . An apparatus for wireless communication at a first user equipment (UE), comprising:

one or more memories; and

one or more processors coupled to the one or more memories, the one or more processors configured to cause the first UE to:

send, in response to detecting an authentication failure during establishment of a secure connection with a second UE, a notification of the authentication failure to the second UE; and

provide the second UE with home network routing information (HNRI) for an authentication node within a home network of the first UE.

2 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to detect the authentication failure during establishment of the secure connection with the second UE are configured to cause the first UE to at least one of:

detect the authentication failure during establishment of the secure connection with the second UE operating as a UE-to-network (U2N) relay;

detect the authentication failure during establishment of a PCS connection with the second UE; or

detect a synchronization failure.

3 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to send the notification of the authentication failure to the second UE and provide the second UE with the HNRI for the authentication node within the home network of the first UE are configured to cause the first UE to send the notification of the authentication failure and provide the HNRI in a same message.

4 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to detect the authentication failure are configured to cause the first UE to detect the authentication failure during a user plane security procedure or during a control plane security procedure.

5 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to provide the second UE with the HNRI are configured to cause the first UE to provide the second UE with at least one of:

a ProSe relay user key (PRUK) identifier (PRUK ID); or

an HNRI extracted from a SUCI.

6 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to provide the second UE with the HNRI are configured to cause the first UE to at least one of:

modify a user identification portion of the HNRI to obscure an identity of a user and provide the second UE with the HNRI having the modified user identification portion;

at least one of confidentiality protect or integrity protect the HNRI based on provisioned discovery security materials and provide the second UE with the HNRI that has been confidentiality and/or integrity protected; or

provide the second UE with a home public land mobile network (HPLMN) identifier of the home network of the first UE.

7 . The apparatus of claim 1 , wherein the one or more processors configured to provide the second UE with HNRI for the authentication node within the home network of the first UE are configured to provide the second UE with at least one of:

the HNRI for a ProSe key management function (PKMF) within the home network of the first UE; or

the HNRI for an authentication server function (AUSF) within the home network of the first UE.

8 . The apparatus of claim 1 ,

wherein the one or more processors configured to cause the first UE to send the notification of the authentication failure to the second UE are configured to cause the first UE to send the notification of the authentication failure in a first message; and

wherein the one or more processors configured to provide the second UE with the HNRI for the authentication node within the home network of the first UE are configured to cause the first UE to provide the HNRI in a second message.

9 . The apparatus of claim 1 ,

wherein the one or more processors configured to provide the second UE with the HNRI for the authentication node within the home network of the first UE are configured to cause the first UE to provide the HNRI in a first message; and

wherein the one or more processors configured to cause the first UE to send the notification of the authentication failure to the second UE are configured to cause the first UE to send the notification of the authentication failure in a second message after the first message.

10 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to provide the second UE with the HNRI for the authentication node within the home network of the first UE are configured to cause the first UE to provide the HNRI in the first message prior to detecting the authentication failure.

11 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to provide the second UE with the HNRI are configured to cause the first UE to provide the second UE with an HNRI extracted from a SUCI.

12 . The apparatus of claim 1 , wherein the one or more processors configured to cause the first UE to provide the second UE with the HNRI are configured to cause the first UE to provide the second UE with a home public land mobile network (HPLMN) identifier of the home network of the first UE.

13 . An apparatus for wireless communication at a first user equipment (UE), comprising:

one or more memories; and

one or more processors coupled to the one or more memories, the one or more processors configured to cause the first UE to:

receive, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE;

receive, from the second UE, home network routing information (HNRI) for a first authentication node within a home network of the second UE; and

send the HNRI for the first authentication node within the home network of the second UE to a second authentication node within a home network of the first UE.

14 . The apparatus of claim 13 , wherein the one or more processors configured to receive the notification of the authentication failure are configured to receive notification of a synchronization failure.

15 . The apparatus of claim 13 , wherein the one or more processors configured to receive the HNRI from the second UE are configured to:

receive the HNRI from the second UE before receiving the notification of the authentication failure;

store the HNRI; and

retrieve the HNRI in response to receiving the notification of the authentication failure.

16 . The apparatus of claim 13 , wherein the notification of the authentication failure comprises the HNRI and wherein the one or more processors configured to receive the HNRI from the second UE are configured to receive the HNRI from the second UE as part of the notification of the authentication failure.

17 . The apparatus of claim 13 , wherein the one or more processors configured to receive the HNRI from the second UE are configured to receive the HNRI from the second UE after receiving the notification of the authentication failure.

18 . The apparatus of claim 13 , wherein the one or more processors configured to receive the HNRI from the second UE are configured to receive at least one of a subscription concealed identifier (SUCI) or a ProSe relay user key (PRUK) identifier (PRUK ID).

19 . The apparatus of claim 13 , wherein the one or more processors configured to receive the notification of the authentication failure during establishment of the secure connection between the second UE and the first UE are configured to receive notification of the authentication failure during establishment of a PC5 connection.

20 . The apparatus of claim 13 , wherein the one or more processors configured to receive the notification of the authentication failure are configured to receive the notification of the authentication failure during at least one of a user plane security procedure or a control plane security procedure.

21 . The apparatus of claim 13 , wherein the one or more processors configured to determine the HNRI for the first authentication node within the home network of the second UE are configured to determine the HNRI for at least one of a ProSe key management function (PKMF) within the home network of the second UE or an authentication server function (AUSF) within the home network of the second UE.

22 . The apparatus of claim 13 ,

wherein the one or more processors configured to receive the HNRI for the first authentication node within the home network of the second UE are configured to receive the HNRI in a first message; and

wherein the one or more processors configured to receive the notification of the authentication failure during establishment of the secure connection between the second UE and the first UE are configured to receive the notification of the authentication failure in a second message after the first message.

23 . The apparatus of claim 13 , wherein the one or more processors configured to receive the HNRI from the second UE are configured to receive the HNRI from the second UE before receiving the notification of the authentication failure.

24 . The apparatus of claim 13 , wherein the one or more processors configured to receive the HNRI from the second UE are configured to receive a home public land mobile network (HPLMN) identifier of the home network of the second UE.

25 . An apparatus for wireless communication at a network entity, comprising:

one or more memories; and

one or more processors coupled to the one or more memories, the one or more processors configured to cause the network entity to:

receive a request for security materials for a secure connection between a first user equipment (UE) in a first home network of the network entity and a second UE having a second home network that is different from the first home network, the request comprising a transaction identifier (TXI);

determine, based on the TXI, home network routing information (HNRI) for the second home network;

determine, based on the HNRI for the second home network, an authentication node within the second home network; and

forward the request to the authentication node within the second home network.

26 . The apparatus of claim 25 , wherein the one or more processors are further configured to, prior to receiving the request for security materials:

receive, from the first UE, mapping information that maps the TXI to the HNRI for the second home network; and

store the mapping information.

27 . The apparatus of claim 26 , wherein the one or more processors configured to receive the mapping information are configured to receive the TXI and at least one of a subscriber concealed identifier (SUCI) or a ProSe relay user key (PRUK) identifier (PRUK ID).

28 . The apparatus of claim 26 , wherein the one or more processors configured to determine the HNRI for the second home network are configured to determine a home public land mobile network (HPLMN) identifier of the second home network.

29 . The apparatus of claim 25 , wherein the one or more processors configured to forward the request to the authentication node within the second home network are configured to forward the request to a ProSe key management function (PKMF) within the second home network or to an authentication server function (AUSF) within the second home network.

30 . The apparatus of claim 25 , wherein the network entity comprises at least one of a ProSe key management function (PKMF) or an access and mobility management function (AMF).

31 . A method for wireless communication at a first user equipment (UE), the method comprising:

sending, in response to an authentication failure during establishment of a secure connection with a second UE, a notification of the authentication failure to the second UE; and

providing the second UE with home network routing information (HNRI) for an authentication node within a home network of the first UE.

32 . The method of claim 31 , wherein detecting the authentication failure during establishment of the secure connection with the second UE comprises at least one of:

detecting the authentication failure during establishment of the secure connection with the second UE operating as a UE-to-network (U2N) relay;

detecting the authentication failure during establishment of a PC5 connection with the second UE; or

detecting a synchronization failure.

33 . The method of claim 31 , wherein sending the notification of the authentication failure to the second UE and providing the second UE with the HNRI for the authentication node within the home network of the first UE comprises sending the notification of the authentication failure and providing the HNRI in a same message.

34 . The method of claim 31 , wherein detecting the authentication failure comprises detecting the authentication failure during a user plane security procedure or during a control plane security procedure.

35 . The method of claim 31 , wherein providing the second UE with the HNRI comprises providing the second UE with at least one of:

a ProSe relay user key (PRUK) identifier (PRUK ID); or

an HNRI extracted from a SUCI.

36 . The method of claim 31 , wherein providing the second UE with the HNRI comprises at least one of:

modifying a user identification portion of the HNRI to obscure an identity of a user and providing the second UE with the HNRI having the modified user identification portion;

at least one of confidentiality protecting or integrity protecting the HNRI based on provisioned discovery security materials and providing the second UE with the HNRI that has been confidentiality and/or integrity protected; or

providing the second UE with a home public land mobile network (HPLMN) identifier of the home network of the first UE.

37 . The method of claim 31 , wherein providing the second UE with HNRI for the authentication node within the home network of the first UE comprises providing the second UE with the HNRI for a ProSe key management function (PKMF) within the home network of the first UE or the HNRI for an authentication server function (AUSF) within the home network of the first UE.

38 . The method of claim 31 ,

wherein sending the notification failure to the second UE comprises sending the notification failure in a first message; and

wherein providing the second UE with the HNRI comprises providing the HNRI in a second message.

39 . The method of claim 31 ,

wherein providing the second UE with the HNRI comprises providing the HNRI in a first message; and

wherein sending the notification failure to the second UE comprises sending the notification failure in a second message after the first message.

40 . The method of claim 31 , wherein providing the second UE with the HNRI in the first message comprises providing the HNRI in the first message prior to detecting the authentication failure.

41 . The method of claim 31 , wherein providing the second UE with the HNRI comprises providing the second UE with an HNRI extracted from a SUCI.

42 . The method of claim 31 , wherein providing the second UE with the HNRI comprises providing the second UE with a home public land mobile network (HPLMN) identifier of the home network of the first UE.

43 . A method for wireless communication at a first user equipment (UE), the method comprising:

receiving, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE;

receiving, from the second UE, home network routing information (HNRI) for a first authentication node within a home network of the second UE; and

sending the HNRI for the first authentication node within the home network of the second UE to a second authentication node within a home network of the first UE.

44 . The method of claim 43 , wherein receiving the HNRI from the second UE comprises:

receiving the HNRI from the second UE before receiving the notification of the authentication failure;

storing the HNRI; and

retrieving the HNRI in response to receiving the notification of the authentication failure.

45 . The method of claim 43 , wherein receiving the HNRI for the first authentication node within the home network of the second UE comprises receiving the HNRI in a first message; and

wherein receiving the notification of the authentication failure during establishment of the secure connection between the second UE and the first UE comprises receiving the notification of the authentication failure in a second message after the first message.

46 . The method of claim 43 , wherein receiving the HNRI from the second UE comprises receiving the HNRI from the second UE before receiving the notification of the authentication failure.

47 . The method of claim 43 , wherein receiving the HNRI from the second UE comprises receiving a home public land mobile network (HPLMN) identifier of the home network of the second UE.

48 . An apparatus for wireless communication at a first user equipment (UE), comprising:

means for sending, in response to an authentication failure during establishment of a secure connection with a second UE, a notification of the authentication failure to the second UE; and

means for providing the second UE with home network routing information (HNRI) for an authentication node within a home network of the first UE.

49 . An apparatus for wireless communication at a first user equipment (UE), comprising:

means for receiving, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE;

means for receiving, from the second UE, home network routing information (HNRI) for a first authentication node within a home network of the second UE; and

means for sending the HNRI for the first authentication node within the home network of the second UE to a second authentication node within a home network of the first UE.

50 . A non-transitory computer-readable medium storing computer-executable instructions that, when executed by a device, cause the device to:

send, in response to an authentication failure during establishment of a secure connection with a second UE, a notification of the authentication failure to the second UE; and

provide the second UE with home network routing information (HNRI) for an authentication node within a home network of the first UE.

51 . A non-transitory computer-readable medium storing computer-executable instructions that, when executed by a device, cause the device to:

receive, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE;

receive, from the second UE, home network routing information (HNRI) for a first authentication node within a home network of the second UE; and

send the HNRI for the first authentication node within the home network of the second UE to a second authentication node within a home network of the first UE.