IP Library Granted Patent US 12,238,516
Granted Patent B2
US 12,238,516 · App. 17/421,302 · Granted Feb 25, 2025

Methods and apparatuses for slice-specific authentication

Inventors: Samir Ferdi (Kirkland, CA); Ulises Olvera-Hernandez (Montreal, CA); Guanzhou Wang (Brossard, CA); Saad Ahmad (Montreal, CA)
Assignee: INTERDIGITAL PATENT HOLDINGS, INC.
H04W12/06H04L63/0892H04W48/16H04W60/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,516
App. No.
17/421,302
Granted
Feb 25, 2025
Kind
B2
Abstract

A method for slice authentication in a mobile telephone network. A WTRU performs, during a registration procedure with an Access and Mobility management Function, AMF, of a network, primary authentication of the WTRU, during which registration procedure the WTRU receives from the AMF a message indicating successful registration and including at least one of an indication of at least one network slice-specific authentication and authorization for slice access, SSSA, procedure to be executed following the registration procedure, a list of slices for which the WTRU is allowed access, and a list of slices for which SSSA is needed for access by the WTRU, and performs, after successful registration, at least one SSSA of the WTRU for accessing a first slice in the network.

Claims (45)

1. A method for operation by a wireless transmit/receive unit, WTRU, the method comprising:

receiving a message indicating successful registration of the WTRU and further including a first list of slices for which slice-specific authentication and authorization for slice access, SSSA, is required after registration, and a second list of at least one currently allowed slice; and

performing, after successful registration of the WTRU, at least one SSSA for accessing a first slice included in the first list of slices included in the received message.

2. The method of claim 1 , further comprising:

performing SSSA for at least one further slice in the list of slices for which SSSA is required; and

accessing the at least one further slice after successful SSSA.

3. The method of claim 2 , further comprising:

receiving a message indicating successful SSSA of the at least one further slice.

4. The method of claim 3 , further comprising:

upon reception of the message indicating successful SSSA of the at least one further slice, updating a stored list of slices for which the WTRU is allowed access to include the at least one further slice.

5. The method of claim 1 , wherein the SSSA for the first slice is for accessing the first slice over a first access type, the method further comprising:

determining that a SSSA is being performed for the first slice over the first access type and waiting for an outcome of the SSSA for the first slice over the first access type before beginning a registration procedure for the first slice over a second access type.

6. The method of claim 5 , wherein the first access type is 3GPP access or non-3GPP access.

7. The method of claim 6 , wherein the second access type is non-3GPP access in case the first access type is 3GPP access, and 3GPP access in case the first access type is non-3GPP access.

8. The method of claim 7 , wherein the non-3GPP access is to a Wireless Local Area Network.

9. The method of claim 1 , wherein the message further comprises a list of slices for which the WTRU is allowed access including at least one slice for which a previous SSSA was successfully executed and for which the WTRU is allowed access regardless of access type.

10. The method of claim 1 , further comprising maintaining the list of slices for which SSSA is needed for access by the WTRU.

11. The method of claim 10 , further comprising updating the list of slices for which SSSA is required based on a result of a SSSA for a slice included in the list.

12. The method of claim 1 , wherein the WTRU refrains from accessing slices for which SSSA is required until a corresponding SSSA has been performed successfully.

13. The method of claim 1 , wherein the WTRU refrains from accessing slices until after reception from the network of a specific message that access is allowed.

14. A wireless transmit/receive unit, WTRU, comprising:

memory for storing processor-executable instructions; and

at least one processor configured to execute the processor-executable instructions to:

receive a message indicating successful registration of the WTRU and including a first list of slices for which slice-specific authentication and authorization for slice access, SSSA, is required after registration, and a second list of at least one currently allowed slice; and

perform, after successful registration of the WTRU, at least one SSSA for accessing a first slice included in the first list of slices included in the received message.

15. The WTRU of claim 14 , wherein the SSSA for the first slice is for accessing the first slice over a first access type, and wherein the at least one processor is further configured to execute the processor-executable instructions to:

determine that a SSSA is being performed for the first slice over the first access type and wait for an outcome of the SSSA for the first slice over the first access type before beginning a registration procedure for the first slice over a second access type.

16. The WTRU of claim 15 , wherein the at least one processor is further configured to execute the processor-executable instructions to update the list of slices for which SSSA is required based on a result of a SSSA for a slice included in the list.

17. The WTRU of claim 15 , wherein the first access type is 3GPP access or non-3GPP access.

18. The WTRU of claim 17 , wherein the second access type is non-3GPP access in case the first access type is 3GPP access, and 3GPP access in case the first access type is non-3GPP access.

19. The WTRU of claim 18 , wherein the non-3GPP access is to a Wireless Local Area Network.

20. The WTRU of claim 14 , wherein the message further comprises a list of slices for which the WTRU is allowed access includes at least one slice for which a previous SSSA was successfully executed and for which the WTRU is allowed access regardless of access type.

21. The WTRU of claim 14 , wherein the at least one processor is further configured to execute the processor-executable instructions to:

perform SSSA for at least one further slice in the list of slices for which SSSA is required; and

access the at least one further slice after successful SSSA.

22. The WTRU of claim 21 , wherein the at least one processor is further configured to execute the processor-executable instructions to receive a message indicating successful SSSA of the at least one further slice.

23. The WTRU of claim 22 , wherein the at least one processor is further configured to execute the processor-executable instructions to, upon reception of the message indicating successful SSSA of the at least one further slice, update a stored list of slices for which the WTRU is allowed access to include the at least one further slice.

24. The WTRU of claim 14 , wherein the at least one processor is further configured to execute the processor-executable instructions to maintain the list of slices for which SSSA is required.

25. The WTRU of claim 14 , wherein the at least one processor is further configured to execute the processor-executable instructions to refrain from accessing slices for which SSSA is required until a corresponding SSSA has been performed successfully.

26. The WTRU of claim 14 , wherein the at least one processor is further configured to execute the processor-executable instructions to refrain from accessing slices until after reception from the network of a specific message that access is allowed.

27. A method for operation by an Access and Mobility management Function, AMF, the method comprising:

provide to a wireless transmit/receive unit, WTRU a message indicating successful registration of the WTRU and including a first list of slices for which SSSA is required after registration, and a second list of at least one currently allowed slice; and

initiating, after successful registration of the WTRU, at least one SSSA for accessing a first slice included in the first list of slices included in the provided message.

28. The method of claim 27 , wherein the message further comprises a list of slices for which the WTRU is allowed further includes at least one slice for which a previous SSSA was successfully executed and for which the WTRU is allowed access regardless of access type.

29. The method of claim 27 , wherein the AMF determines to skip SSSA for a slice for which a previous SSSA was successfully executed regardless of access type.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2023
From: IDAC HOLDINGS, INC.
To: INTERDIGITAL PATENT HOLDINGS, INC.
Reel/Frame 062308/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: FERDI, SAMIR; OLVERA-HERNANDEZ, ULISES; WANG, GUANZHOU; AHMAD, SAAD
To: IDAC HOLDINGS, INC.
Reel/Frame 056785/0721 →
Continuity (4)
Provisional Application 62825159 · Mar 28, 2019
Provisional Application 62806190 · Feb 15, 2019
Provisional Application 62791224 · Jan 11, 2019
Related Publication 20220007184A1 · Jan 6, 2022
References Cited (32)
US 20140321406A1 · Marinier et al. · 2014 [cited by applicant]
US 20180227871A1 · Singh · 2018 [cited by examiner]
US 20180317086A1 · Ben Henda · 2018 [cited by examiner]
US 20180317157A1 · Baek et al. · 2018 [cited by applicant]
US 20180324577A1 · Faccin et al. · 2018 [cited by applicant]
US 20180343249A1 · Hahn · 2018 [cited by examiner]
US 20190037409A1 · Wang · 2019 [cited by examiner]
US 20200178196A1 · Wang · 2020 [cited by examiner]
US 20210067944A1 · Faccin · 2021 [cited by examiner]
US 20210153006A1 · Kim et al. · 2021 [cited by applicant]
US 20230139780A1 · Kunz · 2023 [cited by examiner]
US 20230300733A1 · Casati · 2023 [cited by examiner]
EP 3358887A1 · 2018 [cited by applicant]
KR 20180136171A · 2018 [cited by applicant]
RU 2654052C2 · 2018 [cited by applicant]
TW 201831038A · 2018 [cited by applicant]
TW 201844032A · 2018 [cited by applicant]
WO WO2018171863A1 · 2018 [cited by applicant]
Anonymous, “Introduction of Network Slice-specific Secondary authentication”, 3rd Generation Partnership Project (3GPP), 3GPP Tdoc S2-1901746, 3GPP TSG-SA WG2 Meeting #131, Tenerife, Spain, Feb. 25, 2019, 5 pages. [cited by applicant]
Anonymous, “Comments on contribution S3-161789 that proposes secondary authentication in the slice as the only means of authenticating UE's access to a network slice”, 3rd Generation Partnership Project (3GPP), 3GPP Tdo… [cited by applicant]
Anonymous, “Clarification on update of network slice configuration”, 3rd Generation Partnership Project (3GPP), 3GPP Tdoc S2-184910, 3GPP TSG-SA WG2 Meeting #127bis, Newport Beach, California, USA, May 28, 2018, 2 pages. [cited by applicant]
Anonymous, “UE security capability for the Slice-Specific Secondary Authentication and Authorization”, 3rd Generation Partnership Project (3GPP), 3GPP Tdoc S2-1811169 (updated revision of S2-1810110), SA WG2 Meeting #12… [cited by applicant]
Anonymous, “Section 5.6.3.3.1, Key Issue Details.”, 3rd Generation Partnership Project (3GPP), 3GPP Tdoc S3-171598 (revision of S3-171048), 3GPP TSG SA WG3 (Security) Meeting #87, Ljubljana, Slovenia, May 15, 2017, 9 pa… [cited by applicant]
Anonymous, “Study on Enhancement of Network Slicing (Release 16)”, 3rd Generation Partnership Project (3GPP), Technical Specification Group Services and System Aspects, 3GPP TR 23.740 V0.7.0, Dec. 2018, 71 pages. [cited by applicant]
Anonymous, “Security architecture and procedures for 5G system”(Release 15), 3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, 3GPP TS 33.501, v15.2.0, Sep. 2018, 175 pages. [cited by applicant]
Anonymous, “Procedures for the 5G System; Stage 2 (Release 15)”, 3rd Generation Partnership Project, Technical Specification Group Services Aspects, 3GPP TS 23.502 V15.3.0, Sep. 2018, 330 pages. [cited by applicant]
Anonymous, “Introduction of Network Slice-Specific Secondary authentication”, 3rd Generation Partnership Project (3GPP), 3GPP Tdoc S2-1902881, 3GPP TSG-SA WG2 Meeting #131, Tenerife, Spain, Feb. 25, 2019, 7 pages. [cited by applicant]
Anonymous, “Slice-specific Secondary authentication (SSSA)”, 3rd Generation Partnership Project (3GPP), 3GPP Tdoc S2-1901747, 3GPP TSG-SA WG2 Meeting #131, Tenerife, Spain, Feb. 25, 2019, 13 pages. [cited by applicant]
Nokia et al., Draft for network slice specific authentication procedures, 3GPP TSG-SA3 Meeting #97, S3-194541, Reno, US (Oct. 14-18, 2019). [cited by applicant]
NEC, “UE security capability for the Slice-Specific Secondary Authentication and Authorization,” SA WG2 Meeting #129, S2-1810110, Dongguan, P.R. China (Oct. 15-19, 2018). [cited by applicant]
Third Generation Partnership Project, “Technical Specification Group Services and System Aspects; Study on Enhancement of Network Slicing (Release 16)”, 3GPP Standard; Technical Report; 3GPP TR 23.740, V16.0.0, Dec. 19,… [cited by applicant]
Nokia et al., “Evaluation of solution in clause 6.3.2,” SA WG2 Meeting #129bis, S2-1813210, West Palm Beach, Florida, USA (Nov. 26-30, 2018). [cited by applicant]