PDU session secondary and slice-specific authentication and authorization using L3 WTRU-to-network relay
A wireless transmit/receive unit (WTRU) may be configured to receive a key identifier. The key identifier may be associated with a second WTRU. Additionally, or alternatively, the key identifier may include a 5G ProSe remote user key (5GPRUK) identifier (ID). The WTRU may be configured as a WTRU-to-network relay for the second WTRU. The key identifier may be received during a key request procedure. The key request procedure may be performed by the WTRU on behalf of the second WTRU. The WTRU may be configured to send the key identifier to a network function. The key identifier may be sent to the network function to initiate a secondary authentication procedure. The WTRU may be configured to receive an authentication response message from the second WTRU. The WTRU may be configured to receive a response from the network function.
1 . A network node comprising:
a processor configured to:
receive, from a relay wireless transmit/receive unit (WTRU), a remote WTRU report message that comprises a ProSe remote user key (PRUK) identifier (ID) of a remote WTRU;
send, to a network function, a request message to obtain a subscription permanent identifier (SUPI) of the remote WTRU, the request message comprising the PRUK ID of the remote WTRU; and
receive, from the network function, a response message that comprises the SUPI of the remote WTRU, wherein the SUPI of the remote WTRU was determined using the PRUK ID of the remote WTRU.
2 . The network node of claim 1 , wherein the processor is further configured to store the PRUK ID and the SUPI of the remote WTRU in a context of the relay WTRU.
3 . The network node of claim 1 , wherein the PRUK ID comprises a 5G PRUK ID.
4 . The network node of claim 1 , wherein the network node is a session management function (SMF) and the network function is a ProSe key management function (PKMF) or a ProSe Anchor Function (PAnF).
5 . The network node of claim 1 , wherein the processor is further configured to send, to the relay WTRU, a remote WTRU report response message that comprises the PRUK ID.
6 . The network node of claim 5 , wherein the remote WTRU report response message indicates one or more of an authentication result or an authorization result.
7 . The network node of claim 1 , wherein the processor is configured to check for data network authorization for the remote WTRU using the SUPI of the remote WTRU.
8 . The network node of claim 7 , wherein the processor is further configured to trigger a secondary authentication by a data network (DN) for the remote WTRU.
9 . The network node of claim 8 , wherein the secondary authentication is triggered based on a determination of one or more of DN being authorized, DN requiring secondary authentication, or a prior authentication.
10 . The network node of claim 8 , wherein the processor is further configured receive, from the relay WTRU, an authentication response message associated with the remote WTRU.
11 . A method performed by a network node, the method comprising:
receiving, from a relay wireless transmit/receive unit (WTRU), a remote WTRU report message that comprises a ProSe remote user key (PRUK) identifier (ID) of a remote WTRU;
sending, to a network function associated with the remote WTRU, a request message to obtain a subscription permanent identifier (SUPI) of the remote WTRU, the request message comprising the PRUK ID of the remote WTRU; and
receiving, from the network function, a response message that comprises the SUPI of the remote WTRU, wherein the SUPI of the remote WTRU was determined using the PRUK ID of the remote WTRU.
12 . The method of claim 11 , further comprising storing the PRUK ID and the SUPI of the remote WTRU in a context of the relay WTRU.
13 . The method of claim 11 , wherein the PRUK ID comprises a 5G PRUK ID.
14 . The method of claim 11 , wherein the network node is a session management function (SMF) and the network function is a ProSe key management function (PKMF) or a ProSe Anchor Function (PAnF).
15 . The method of claim 11 , further comprising sending, to the relay WTRU, a remote WTRU report response message that comprises the PRUK ID.
16 . The method of claim 15 , wherein the remote WTRU report response message indicates one or more of an authentication result or an authorization result.
17 . The method of claim 11 , further comprising checking for data network authorization for the remote WTRU using the SUPI of the remote WTRU.
18 . The method of claim 17 , further comprising triggering a secondary authentication by a data network (DN) for the remote WTRU.
19 . The method of claim 18 , wherein the secondary authentication is triggered based on a determination of one or more of DN being authorized, DN requiring secondary authentication, or a prior authentication.
20 . The method of claim 18 , further comprising receiving, from the relay WTRU, an authentication response message associated with the remote WTRU.