IP Library › Granted Patent US 11,575,509
Granted Patent B2
US 11,575,509 · App. 16/372,751 · Granted Feb 7, 2023

Secondary authentication of a user equipment

Inventors: Noamen Ben Henda (Stockholm, SE); David Castellanos Zamora (Madrid, ES); Vesa Torvinen (Sauvo, FI)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L9/0844H04L63/0884H04L63/0892H04L63/16H04W12/041H04W12/0431H04W12/062H04W12/068H04W76/11H04W76/25H04W80/10H04W88/023H04L63/061H04L63/08H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,575,509
App. No.
16/372,751
Granted
Feb 7, 2023
Kind
B2
Abstract

A user equipment is configured to receive an extensible authentication protocol (EAP) request from a session management function (SMF) that serves as an EAP authenticator for secondary authentication of the user equipment. The secondary authentication is authentication of the user equipment in addition to primary authentication of the user equipment. The user equipment is also configured to, responsive to the EAP request, transmit an EAP response to the SMF.

Claims (47)

1. A method of secondary authentication of a user equipment, implemented by the user equipment, wherein the method comprises:

receiving, from a session management function (SMF) that serves as an extensible authentication protocol (EAP) authenticator for secondary authentication of the user equipment, an EAP request for an identity of the user equipment to be used in the secondary authentication, wherein the secondary authentication is:

authentication of the user equipment for authorizing establishment of a packet data unit session with a data network external to a wireless communication network comprising the SMF; and

performed in addition to primary authentication of the user equipment executed between the user equipment and an authentication function via a security anchor function to authorize access of the user equipment to the wireless communication network comprising the SMF; and

responsive to the EAP request, transmitting an EAP response comprising the identity from the user equipment to the SMF.

2. The method of claim 1 , wherein the SMF is configured to forward the EAP request and the EAP response between the user equipment and an EAP server that executes an EAP authentication method for the EAP authenticator.

3. The method of claim 2 , wherein the EAP request and the EAP response are transmitted between the SMF and the EAP server via a user plane function selected by the SMF.

4. The method of claim 1 , wherein the EAP request and the EAP response are encapsulated within respective non-access stratum (NAS) protocol messages between the SMF and the user equipment.

5. The method of claim 1 , further comprising:

transmitting a session establishment request that triggers the secondary authentication of the user equipment, wherein the session establishment request comprises a secondary identity of the user equipment used for the secondary authentication;

receiving a session establishment response comprising either an EAP success message indicating success of the secondary authentication or an EAP failure message indicating failure of the secondary authentication.

6. A method of secondary authentication of a user equipment, implemented by an authentication system, wherein the method comprises:

transmitting, to a user equipment from a session management function (SMF) that serves as an extensible authentication protocol (EAP) authenticator for secondary authentication of the user equipment, an EAP request for an identity of the user equipment to be used in the secondary authentication, wherein the secondary authentication is:

authentication of the user equipment for authorizing establishment of a packet data unit session with a data network external to a wireless communication network comprising the SMF; and

performed in addition to primary authentication of the user equipment executed between the user equipment and an authentication function via a security anchor function to authorize access of the user equipment to the wireless communication network comprising the SMF; and

responsive to the EAP request, receiving at the SMF from the user equipment an EAP response comprising the identity.

7. The method of claim 6 , further comprising forwarding the EAP request and the EAP response between the user equipment and an EAP server that executes an EAP authentication method for the EAP authenticator.

8. The method of claim 7 , further comprising transmitting the EAP request and the EAP response between the SMF and the EAP server via a user plane function selected by the SMF.

9. The method of claim 6 , wherein the EAP request and the EAP response are encapsulated within respective non-access stratum (NAS) protocol messages between the SMF and the user equipment.

10. The method of claim 6 , further comprising:

receiving a session establishment request from the user equipment that triggers the secondary authentication of the user equipment, wherein the session establishment request comprises a secondary identity of the user equipment used for the secondary authentication;

transmitting a session establishment response to the user equipment, the session establishment response comprising either an EAP success message indicating success of the secondary authentication or an EAP failure message indicating failure of the secondary authentication.

11. A user equipment comprising:

processing circuitry and memory, the memory containing instructions executable by the processing circuitry whereby the user equipment is configured to:

receive, from a session management function (SMF) that serves as an extensible authentication protocol (EAP) authenticator for secondary authentication of the user equipment, an EAP request for an identity of the user equipment used in the secondary authentication, wherein the secondary authentication is:

authentication of the user equipment for authorizing establishment of a packet data unit session with a data network external to a wireless communication network comprising the SMF; and

performed in addition to primary authentication of the user equipment executed between the user equipment and an authentication function via a security anchor function to authorize access of the user equipment to the wireless communication network; and

responsive to the EAP request, transmit an EAP response comprising the identity to the SMF.

12. The user equipment of claim 11 , wherein the SMF is configured to forward the EAP request and the EAP response between the user equipment and an EAP server that executes an EAP authentication method for the EAP authenticator.

13. The user equipment of claim 12 , wherein the EAP request and the EAP response are transmitted between the SMF and the EAP server via a user plane function selected by the SMF.

14. The user equipment of claim 11 , wherein the EAP request and the EAP response are encapsulated within respective non-access stratum (NAS) protocol messages between the SMF and the user equipment.

15. The user equipment of claim 11 , further configured to:

transmit a session establishment request that triggers the secondary authentication of the user equipment, wherein the session establishment request comprises a secondary identity of the user equipment used for the secondary authentication;

receive a session establishment response comprising either an EAP success message indicating success of the secondary authentication or an EAP failure message indicating failure of the secondary authentication.

16. An authentication system comprising:

processing circuitry and memory, the memory containing instructions executable by the processing circuitry whereby the authentication system is configured to:

transmit, to a user equipment from a session management function (SMF) that serves as an extensible authentication protocol (EAP) authenticator for secondary authentication of the user equipment, an EAP request for an identity of the user equipment to be used in the secondary authentication, wherein the secondary authentication is:

authentication of the user equipment for authorizing establishment of a packet data unit session with a data network external to a wireless communication network comprising the SMF; and

performed in addition to primary authentication of the user equipment executed between the user equipment and an authentication function via a security anchor function to authorize access of the user equipment to the wireless communication network comprising the SMF; and

responsive to the EAP request, receiving at the SMF from the user equipment an EAP response comprising the identity.

17. The authentication system of claim 16 , further configured to forward the EAP request and the EAP response between the user equipment and an EAP server that executes an EAP authentication method for the EAP authenticator.

18. The authentication system of claim 17 , further configured to transmit the EAP request and the EAP response between the SMF and the EAP server via a user plane function selected by the SMF.

19. The authentication system of claim 16 , wherein the EAP request and the EAP response are encapsulated within respective non-access stratum (NAS) protocol messages between the SMF and the user equipment.

20. The authentication system of claim 16 , further configured to:

receive a session establishment request from the user equipment that triggers the secondary authentication of the user equipment, wherein the session establishment request comprises a secondary identity of the user equipment used for the secondary authentication;

transmit a session establishment response to the user equipment, the session establishment response comprising either an EAP success message indicating success of the secondary authentication or an EAP failure message indicating failure of the secondary authentication.

21. The authentication system of claim 16 , further comprising the SMF, an EAP server, or both.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2019
From: BEN HENDA, NOAMEN; CASTELLANOS ZAMORA, DAVID
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 048766/0993 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2019
From: TORVINEN, VESA
To: OY L M ERICSSON AB
Reel/Frame 048767/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2019
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 048767/0087 →
Continuity (3)
Continuation PCTEP2017084383 · Dec 22, 2017
Provisional Application 62451645 · Jan 27, 2017
Related Publication 20190230510A1 · Jul 25, 2019