IP Library › Granted Patent US 12,634,688
Granted Patent B2
US 12,634,688 · App. 17/774,177 · Granted May 19, 2026

Home network initiated primary authentication/reauthentication

Inventors: David Castellanos Zamora (Madrid, ES); Helena Vahidi Mazinani (Lund, SE); Vlasios Tsiatsis (Solna, SE); Jesus Angel De Gregorio Rodriguez (Madrid, ES)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/06H04W12/0431
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,688
App. No.
17/774,177
Granted
May 19, 2026
Kind
B2
Abstract

Initiating primary reauthentication of a communication device by a home network (UDM or AUSF) is provided. A trigger to initiate a primary reauthentication request of a communication device is detected. An authentication status of the subscription permanent identifier (SUPI) of the communication device is checked. Responsive to the authentication status of the SUPI being obsolete or null, a reauthentication message is transmitted towards an access and mobility management function (AMF) node. A reauthentication confirmation message is received. A determination is made as to whether to continue, abort, or postpone any steering of roaming (SoR) updates, any user equipment parameter updates (UPU updates) or any authentication and key agreement for applications (AKMA) procedures based on the reauthentication confirmation message.

Claims (43)

1 . A method performed by a processor in a unified data management, UDM, node of a communication network to initiate primary reauthentication of a communication device, the method comprising:

detecting a trigger to initiate a primary reauthentication request of the communication device;

checking an authentication status, stored in the UDM, of a Subscription Permanent Identifier, SUPI, of the communication device;

responsive to the authentication status of the SUPI being obsolete or null, transmitting a primary reauthentication message towards an Access and Mobility Management Function, AMF; and

determining whether to continue, abort, or postpone any steering of roaming, SoR, updates, any user equipment parameter updates, UPUs, or any authentication and key agreement for applications, AKMA, procedures based on a reauthentication confirmation message.

2 . The method of claim 1 , wherein transmitting the primary reauthentication request comprises:

identifying an Access and Mobility Management Function, AMF, node registered in the UDM node via which the communication device registered to access the communication network; and

including an identification of the AMF node in the reauthentication message.

3 . The method of claim 1 wherein transmitting the primary reauthentication message towards the AMF comprises transmitting a reauthentication notification to an authentication server function, AUSF.

4 . The method of claim 1 wherein transmitting the primary reauthentication message towards the AMF comprises transmitting a reauthentication request to an authentication server function, AUSF.

5 . The method of claim 1 wherein transmitting the primary reauthentication message towards the AMF comprises responsive to a callback uniform resource identifier, URI, being provided by the AMF during AMF registration in the UDM, transmitting the primary reauthentication message to the AMF with the URI.

6 . The method of claim 1 wherein receiving the reauthentication confirmation message comprises receiving a reauthentication notification.

7 . The method of claim 1 wherein receiving the reauthentication confirmation message comprises receiving a reauthentication response message.

8 . The method of claim 1 further comprising:

prior to detecting a trigger to initiate a primary reauthentication request of the communication device, storing the SUPI of the communication device.

9 . The method of claim 8 further comprising:

storing at least one of an authentication result of the communication device, a timestamp of an authentication procedure of the communication device, and a serving network identifier of the communication device.

10 . The method of claim 1 further comprising at least one of:

responsive to determining to continue any SoR updates, any UPUs, or any AKMA procedures, continuing a SoR update, a UPU, or a AKMA procedure;

responsive to determining to abort any SoR updates, any UPUs, or any AKMA procedures, aborting a SoR update, a UPU, or a AKMA procedure; and

responsive to determining to postpone any SoR updates, any UPUs, or any AKMA procedures, postponing a SoR update, a UPU, or a AKMA procedure.

11 . A method performed by a processor in an Access and Mobility Management Function, AMF, node of a communication network, the method comprising:

receiving a primary reauthentication message from a unified data management, UDM, node, the primary reauthentication message including a request for reauthenticating a specified communication device;

initiating a primary reauthentication procedure with the specified communication device;

determining a result of the primary reauthentication procedure, the result indicating whether the primary reauthentication procedure was successful or unsuccessful; and

transmitting a reauthentication confirmation message to an Authentication Server Function, AUSF, node, the reauthentication confirmation message including the result of the primary reauthentication procedure.

12 . The method of claim 11 wherein receiving the primary reauthentication message from the UDM node comprises receiving a primary reauthentication notification from the UDM node.

13 . The method of claim 11 , wherein transmitting the reauthentication confirmation message to the UDM node comprises transmitting a reauthentication confirmation notification to the UDM node.

14 . The method of claim 11 , wherein transmitting the reauthentication confirmation message to the UDM node comprises transmitting a reauthentication confirmation response message to the UDM node.

15 . The method of claim 11 wherein receiving the primary reauthentication message from the UDM node comprises receiving a primary authentication request from the AUSF node.

16 . The method of claim 11 further comprising:

prior to initiating the primary reauthentication procedure with the specified communication device, paging the specified communication device.

17 . An Access and Mobility Management Function, AMF, node comprising:

processing circuitry; and

memory coupled with the processing circuitry, wherein the memory includes instructions that when executed by the processing circuitry causes the AMF node to perform operations comprising:

receiving a primary reauthentication message from a unified data management, UDM, node, the primary reauthentication message including a request for reauthenticating a specified communication device;

initiating a primary reauthentication procedure with the specified communication device;

determining a result of the primary reauthentication procedure, the result indicating whether the primary reauthentication procedure was successful or unsuccessful; and

transmitting a reauthentication confirmation message to an Authentication Server Function, AUSF, node, the reauthentication confirmation message including the result of the primary reauthentication procedure.

18 . The AMF node of claim 17 , wherein receiving the primary reauthentication message from the UDM node comprises one of receiving a primary reauthentication notification from the UDM node or receiving a primary authentication request from the UDM node.

19 . The AMF node of claim 17 , wherein transmitting the reauthentication confirmation message to the UDM node comprises one of transmitting a reauthentication confirmation notification to the UDM node or transmitting a reauthentication confirmation response message to the UDM node.

20 . The AMF node of claim 17 , the operations further comprising:

prior to initiating the primary reauthentication procedure with the specified communication device, paging the specified communication device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2022
From: ZAMORA, DAVID CASTELLANOS; MAZINANI, HELENA VAHIDI; TSIATSIS, VLASIOS; RODRIGUEZ, JESUS ANGEL DE GREGORIO
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 059883/0818 →
Priority Claims (1)
EP 19382985 · Nov 11, 2019 · regional
Continuity (1)
Related Publication 20220408249A1 · Dec 22, 2022
References Cited (13)
US 20200344606A1 · Zaus · 2020 [cited by examiner]
US 20210120416A1 · S Bykampadi · 2021 [cited by examiner]
US 20220167157A1 · Tiwari · 2022 [cited by examiner]
US 20240155342A1 · Faccin · 2024 [cited by examiner]
“3GPP TS 33.501 V16.0.0 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16)” Sep. 2019 (Year: 2019). [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority, PCT/EP2020/080529, mailed Dec. 22, 2020, 13 pages. [cited by applicant]
3GPP TS 33.501 V16.0.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16),” Valbonne, France, Sep. 2019, 196 … [cited by applicant]
3GPP TSG-SA WG3 Meeting #94Ad-Hoc, “Solution to support Fast Re-authentication in 5GS,” NEC, Intel, S3-190634, Stockholm, Sweden, Mar. 11-15, 2019, 5 pages. [cited by applicant]
3GPP TSG-SA WG3 Meeting #95, “UDM triggered authentication,” NEC, S3-191208, Reno, USA, May 6-10, 2019, 3 pages. [cited by applicant]
3GPP TS 23.502 V16.2.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16),” Valbonne, France, Sep. 2019, 525 pages. [cited by applicant]
3GPP TR 33.835 V1.0.1, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on authentication and key management for applications based on 3GPP credential in 5G (Release … [cited by applicant]
3GPP TS 23.122 V16.3.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) functions related to Mobile Station (MS) in idle mode (Release 16),” Valbon… [cited by applicant]
3GPP TS 29.503 V16.1.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Unified Data Management Services; Stage 3 (Release 16),” Valbonne, France, Sep. 2019, 234… [cited by applicant]