User equipment-to-network relay security for proximity based services
Presented are systems, methods, apparatuses, or computer-readable media for authenticating remote wireless communication devices. An authentication server function (AUSF) may send, to a unified data management (UDM), a request for authentication vectors (AV) in association with a remote wireless communication device seeking authorization to access a network via a relay wireless communication device. The request may include an indicator to indicate to the UDM to bypass storing information related to the AUSF. The AUSF may receive, from the UDM, the AV in response to the request.
1 . A method comprising:
sending, by an authentication server function (AUSF) to a unified data management (UDM), a request for authentication vectors (AVs) in association with a remote wireless communication device seeking authorization to access a network via a relay wireless communication device, the request comprising an indicator to indicate to the UDM to bypass storing information related to the AUSF;
receiving, by the AUSF from a relay access and mobility management function (AMF), an authentication request comprising at least one of: an identifier of the remote wireless communication device, a subscriber concealed identifier (SUCI), a relay service code, a nonce, or a name of the network; and
receiving, by the AUSF from the UDM, the AVs in response to the request,
wherein after successful completion of authentication of the remote wireless communication device, the method further comprises:
generating, by the AUSF, a proximity services key;
sending, by the AUSF to a relay wireless communication device via the relay AME, an authentication response message comprising the proximity services key; and
causing the relay AMF to send a relay key response to the relay wireless communication device, wherein the relay AMF deletes information related to the remote wireless communication device.
2 . The method of claim 1 , comprising:
initiating, by the AUSF, authentication of the remote wireless communication device, in response to receiving the AVs.
3 . The method of claim 1 , wherein the indicator comprises at least one of: an identifier of the remote wireless communication device, a subscriber concealed identifier (SUCI), a subscriber permanent identifier (SUPI), or a name of the network.
4 . The method of claim 1 , wherein the indicator comprises a relay service code or other service code, a freshness parameter value, or a default or defined value.
5 . The method of claim 1 , wherein the information related to the AUSF includes at least one of: an identifier of the AUSF, or the AVs.
6 . The method of claim 1 , wherein after completion of the authentication, the relay AMF does not initiate a network access stratum (NAS) security mode command (SMC) procedure with the remote wireless communication device.
7 . The method of claim 6 , wherein the relay AMF does not initiate the NAS SMC procedure, based on information comprising at least one of: a relay service code, a remote wireless communication device's identity, or a subscriber concealed identifier (SUCI).
8 . The method of claim 1 , where the information related to the relay wireless communication device comprises at least one of: non access stratum security context information, an access and mobility management function (AMF) key, an identity of the remote wireless communication device, a subscriber concealed identifier (SUCI) or a subscriber permanent identifier (SUPI).
9 . A method comprising:
receiving, by a unified data management (UDM) from an authentication server function (AUSF), a request for authentication vectors (AVs) in association with a remote wireless communication device seeking authorization to access a network via a relay wireless communication device, the request comprising an indicator to indicate to the UDM to bypass storing information related to the AUSF; and
sending, by the UDM to the AUSF, the AVs in response to the request, wherein the AUSF receives from a relay access and mobility management function (AMF), an authentication request comprising at least one of: an identifier of the remote wireless communication device, a subscriber concealed identifier (SUCI), a relay service code, a nonce, or a name of the network,
wherein after successful completion of authentication of the remote wireless communication device, the AUSF generates a proximity services key, sends to a relay wireless communication device via the relay AMF an authentication response message comprising the proximity services key, and causes the relay AMF to send a relay key response to the relay wireless communication device, wherein the relay AMF deletes information related to the remote wireless communication device.
10 . A unified data management (UDM), comprising:
at least one processor configured to:
receive, via a transceiver from an authentication server function (AUSF), a request for authentication vectors (AVs) in association with a remote wireless communication device seeking authorization to access a network via a relay wireless communication device, the request comprising an indicator to indicate to the UDM to bypass storing information related to the AUSF; and
send, via the transceiver to the AUSF, the AVs in response to the request, wherein the AUSF receives from a relay access and mobility management function (AMF), an authentication request comprising at least one of: an identifier of the remote wireless communication device, a subscriber concealed identifier (SUCI), a relay service code, a nonce, or a name of the network,
wherein after successful completion of authentication of the remote wireless communication device, the AUSF generates a proximity services key, sends to a relay wireless communication device via the relay AMF an authentication response message comprising the proximity services key, and causes the relay AMF to send a relay key response to the relay wireless communication device, wherein the relay AMF deletes information related to the remote wireless communication device.
11 . An authentication server function (AUSF), comprising:
at least one processor configured to:
send, via a transceiver to a unified data management (UDM), a request for authentication vectors (AVs) in association with a remote wireless communication device seeking authorization to access a network via a relay wireless communication device, the request comprising an indicator to indicate to the UDM to bypass storing information related to the AUSF;
receive, from a relay access and mobility management function (AMF), an authentication request comprising at least one of: an identifier of the remote wireless communication device, a subscriber concealed identifier (SUCI), a relay service code, a nonce, or a name of the network; and
receive, via the transceiver from the UDM, the AVs in response to the request,
wherein after successful completion of authentication of the remote wireless communication device, the at least one processor is further configured to:
generate a proximity services key;
send, to a relay wireless communication device via the relay AMF, an authentication response message comprising the proximity services key; and
cause the relay AMF to send a relay key response to the relay wireless communication device, wherein the relay AMF deletes information related to the remote wireless communication device.
12 . The AUSF of claim 11 , wherein the at least one processor is configured to:
initiate authentication of the remote wireless communication device, in response to receiving the AVs.
13 . The AUSF of claim 11 , wherein the indicator comprises at least one of: an identifier of the remote wireless communication device, a subscriber concealed identifier (SUCI), a subscriber permanent identifier (SUPI), or a name of the network.
14 . The AUSF of claim 11 , wherein the indicator comprises a relay service code or other service code, a freshness parameter value, or a default or defined value.
15 . The AUSF of claim 11 , wherein the information related to the AUSF includes at least one of: an identifier of the AUSF, or the AVs.
16 . The AUSF of claim 11 , wherein after completion of the authentication, the relay AMF does not initiate a network access stratum (NAS) security mode command (SMC) procedure with the remote wireless communication device.