IP Library › Granted Patent US 12,532,171
Granted Patent B2
US 12,532,171 · App. 18/378,830 · Granted Jan 20, 2026

Network equipment and user equipment

Inventor: Haorui Yang (Dongguan, CN)
Assignee: InterDigital Patent Holdings, Inc.
H04W12/06H04L63/0892H04W48/18H04W84/042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,532,171
App. No.
18/378,830
Granted
Jan 20, 2026
Kind
B2
Abstract

A network device and user equipment (UE) are provided. The network device includes a memory, a transceiver, a processor, and a bus system, the processor is configured to execute the instructions in the memory to perform operations of: in response to receiving an authentication request, sending a first authentication message to a first UE, the authentication request being used to trigger an authentication flow for a second UE requesting to use a target network slice, the second UE accessing the first network equipment through the first UE, the first authentication message comprising a first indication and a first extensible authentication protocol (EAP) message, the first indication indicating that the first EAP message is to be used by the second UE, the first EAP message being used to authenticate legality of use of the target network slice by the second UE.

Claims (63)

1 . A network equipment, comprising a memory, a transceiver, a processor, and a bus system,

wherein the memory is configured to store instructions,

wherein the transceiver is configured to receive or send information as controlled by the processor,

wherein the processor is configured to execute the instructions in the memory,

wherein the bus system is configured to connect the memory, the transceiver, and the processor to allow communication among the memory, the transceiver, and the processor,

wherein the processor is configured to call the instructions in the memory to implement operations of:

in response to receiving an authentication request, sending a first authentication message to a first user equipment (UE), the authentication request being used to trigger an authentication flow for a second user equipment (UE) requesting to use a target network slice, the second UE accessing the first network equipment through the first UE,

the first authentication message comprising a first indication and a first extensible authentication protocol (EAP) message, the first indication indicating that the first EAP message is to be used by the second UE, the first EAP message being used to authenticate legality of use of the target network slice by the second UE.

2 . The network equipment of claim 1 , wherein the first UE and the second UE are of a same home public land mobile network (HPLMN).

3 . The network equipment of claim 1 , wherein the authentication request is sent by the first UE or a first authentication authorization accounting-server (AAA-S), the first AAA-S being a home AAA-S of the second UE.

4 . The network equipment of claim 1 , wherein the authentication request comprises at least one of: an identification (ID) of the second UE, single-network slice selection assistance information (S-NSSAI) corresponding to the target network slice, or an HPLMN ID of the second UE.

5 . The network equipment of claim 1 , wherein the processor is further configured to call the instructions in the memory to implement operations of:

receiving a second authentication message sent by the first UE; and

sending the second authentication message to a first authentication authorization accounting-server (AAA-S),

wherein the second authentication message comprises a second indication and a second EAP message, the second indication indicating association of the second EAP message with the second UE, the second EAP message being used to authenticate the legality of use of the target network slice by the second UE.

6 . The network equipment of claim 1 , wherein the processor is further configured to call the instructions in the memory to implement operations of:

before sending the first authentication message to the first UE, sending an authentication command to the first UE based on the authentication request, the authentication command comprising an EAP identification (ID) request and a third indication, the third indication indicating that the EAP ID request is used to be used by the second UE; and

receiving an authentication command response sent by the first UE, the authentication command response comprising a fourth indication and an EAP ID response, the fourth indication indicating association of the EAP ID response with the second UE.

7 . The network equipment of claim 1 , wherein the processor is further configured to call the instructions in the memory to implement operations of:

after sending the first authentication message to the first UE, receiving a result of authentication sent by a first authentication authorization accounting-server (AAA-S), the result of authentication comprising an authentication result for the target network slice requested by the second UE; and

sending the result of authentication to the first UE.

8 . A first user equipment (UE), comprising a memory, a transceiver, a processor, and a bus system,

wherein the memory is configured to store instructions,

wherein the transceiver is configured to receive or send information as controlled by the processor,

wherein the processor is configured to execute the instructions in the memory,

wherein the bus system is configured to connect the memory, the transceiver, and the processor to allow communication among the memory, the transceiver, and the processor,

wherein the processor is configured to call the instructions in the memory to implement operations of:

receiving a first authentication message sent by a first network equipment, the first authentication message comprising a first indication and a first extensible authentication protocol (EAP) message, the first indication indicating that the first EAP message is to be used by a second UE, the first EAP message being used to authenticate legality of use of a target network slice by the second UE; and

sending the first EAP message to the second UE, wherein the second UE accesses the first network equipment through the first UE.

9 . The first UE of claim 8 , wherein the processor is further configured to call the instructions in the memory to implement an operation of:

before receiving the first authentication message sent by the first network equipment, sending an authentication request to the first network equipment, the authentication request being used to trigger an authentication flow for the second UE requesting to use the target network slice.

10 . The first UE of claim 9 , wherein the authentication request comprises at least one of: an identification (ID) of the second UE, single-network slice selection assistance information (S-NSSAI) corresponding to the target network slice, or a home public land mobile network (HPLMN) ID of the second UE.

11 . The first UE of claim 8 , wherein the processor is further configured to call the instructions in the memory to implement operations of:

receiving a second EAP message sent by the second UE, the second EAP message being used to authenticate legality of use of the target network slice by the second UE; and

sending a second authentication message to the first network equipment,

wherein the second authentication message comprises a second indication and the second EAP message, the second indication indicating association of the second EAP message with the second UE.

12 . The first UE of claim 8 , wherein the processor is further configured to call the instructions in the memory to implement operations of:

before receiving the first authentication message sent by the first network equipment, receiving an authentication command sent by the first network equipment, the authentication command comprising an EAP identification (ID) request and a third indication, the third indication indicating that the EAP ID request is to be used by the second UE; and

sending the EAP ID request to the second UE.

13 . The first UE of claim 12 , wherein the processor is further configured to call the instructions in the memory to implement operations of:

after sending the EAP ID request to the second UE, receiving an EAP ID response sent by the second UE; and

sending an authentication command response to the first network equipment, the authentication command response comprising a fourth indication and the EAP ID response, the fourth indication indicating association of the EAP ID response with the second UE.

14 . The first UE of claim 8 , wherein the processor is further configured to call the instructions in the memory to implement operations of:

after sending the first EAP message to the second UE, receiving a result of authentication sent by the first network equipment, the result of authentication comprising an authentication result for the target network slice requested by the second UE; and

in response to that the result of authentication denotes success of authentication of the target network slice requested by the second UE, performing, for the second UE, relay on data in the target network slice.

15 . The first UE of claim 8 , wherein the processor is further configured to call the instructions in the memory to implement an operation of:

before receiving the first authentication message sent by the first network equipment, sending a discovery message, the discovery message comprising a home public land mobile network (HPLMN) identification (ID) of the first UE.

16 . A second user equipment (UE), comprising a memory, a transceiver, a processor, and a bus system,

wherein the memory is configured to store a program and an instruction,

wherein the transceiver is configured to receive or send information as controlled by the processor,

wherein the processor is configured to execute the program in the memory,

wherein the bus system is configured to connect the memory, the transceiver, and the processor to allow communication among the memory, the transceiver, and the processor,

wherein the processor is configured to call the instructions in the memory to implement an operation of:

receiving a first extensible authentication protocol (EAP) message sent by a first UE, the first EAP message being used to authenticate legality of a target network slice requested to be used by the second UE, the second UE accessing a first network equipment through the first UE.

17 . The second UE of claim 16 , wherein the processor is further configured to call the instructions in the memory to implement an operation of:

before receiving the first EAP message sent by a first UE, sending an authentication request, the authentication request being used to trigger an authentication flow for the second UE requesting to use the target network slice.

18 . The second UE of claim 17 , wherein sending the authentication request comprises:

sending the authentication request to the first UE through a port PC5; or

sending the authentication request to a first authentication authorization accounting-server (AAA-S) through an application stratum, the first AAA-S being a home AAA-S of the second UE.

19 . The second UE of claim 17 , wherein the authentication request comprises at least one of:

an identification (ID) of the second UE, single-network slice selection assistance information (S-NSSAI) corresponding to the target network slice, or an HPLMN ID of the second UE.

20 . The second UE of claim 16 , wherein the processor is further configured to call the instructions in the memory to implement an operation of:

sending a second EAP message to the first UE, the second EAP message being used to authenticate legality of use of the target network slice by the second UE.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2025
From: GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP., LTD.
To: INTERDIGITAL HOLDINGS, INC.
Reel/Frame 069911/0769 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2025
From: INTERDIGITAL HOLDINGS, INC.
To: INTERDIGITAL PATENT HOLDINGS, INC.
Reel/Frame 069911/0994 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2023
From: YANG, HAORUI
To: GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP., LTD.
Reel/Frame 065183/0591 →
Continuity (2)
Continuation PCTCN2021087685 · Apr 16, 2021
Related Publication 20240056807A1 · Feb 15, 2024
References Cited (19)
US 10904731B2 · Breuer · 2021 [cited by applicant]
US 20180368061A1 · Yu · 2018 [cited by applicant]
US 20190335330A1 · Salkintzis · 2019 [cited by examiner]
US 20200053083A1 · Kunz · 2020 [cited by applicant]
US 20200107173A1 · Breuer · 2020 [cited by applicant]
US 20210058833A1 · Basu Mallick · 2021 [cited by examiner]
US 20220159460A1 · Ben Henda · 2022 [cited by examiner]
CN 109417687A · 2019 [cited by applicant]
CN 109699031A · 2019 [cited by applicant]
CN 108924883B · 2020 [cited by applicant]
CN 112291784A · 2021 [cited by applicant]
CN 112512096A · 2021 [cited by applicant]
WO 2020035732A1 · 2020 [cited by applicant]
Supplementary European Search Report in the European application No. 21936450.2, mailed on Apr. 29, 2024. 10 pages. [cited by applicant]
“3 Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP Standard; Technical Specification; 3GPP TS 33.501, 3rd… [cited by applicant]
China Mobile et al, “Remote provisioning of credentials for NSSAA or secondary authentication/authorisation”, 3GPP TSG-SA WG2 Meeting #144-e S2-2102263, E-Meeting, Apr. 12-Apr. 16, 2021, section 5.15.10, and section 5.X… [cited by applicant]
International Search Report in the international application No. PCT/CN2021/087685, mailed on Dec. 23, 2021. 5 pages with English translation. [cited by applicant]
Written Opinion of the International Search Authority in the international application No. PCT/CN2021/087685, mailed on Dec. 23, 2021. 8 pages with English translation. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enhancement for proximity based services in the 5G System (5GS) (Release 17)”, 3GPP TR 33.847 … [cited by applicant]