Method and apparatus for authentication of Integrated Access and Backhaul (IAB) node in wireless network
Accordingly, the embodiments herein provide a method for authentication of an IAB node by an IAB-donor node in a wireless network. The method includes obtaining an IAB authorization information of the IAB node from one of an Access and Mobility Management Function (AMF) and a Mobility Management Entity (MME) of the wireless network, determining whether the IAB authorization information of the IAB node indicates the IAB node is authorized, and allocating a unique identity/parameter to the IAB node during an IAB-Mobile Termination (MT) setup and/or Backhaul Radio Link Control (RLC) channel establishment and/or Routing update phase. Further, the method includes storing the unique identity/parameter in a user equipment (UE)-context, which is used to identify the UE-context during an IAB-Distributed Unit (DU) part setup for authorization check and/or authentication.
1. A method for authentication of an Integrated Access and Backhaul (IAB) node in a wireless network performed by an IAB-donor node, the method comprising:
obtaining an IAB authorization information of the IAB node from a network entity during an initial context setup procedure;
sending, to the IAB node, an Internet Protocol (IP) address of a distributed unit (DU) of the IAB node to identify a security context information of the IAB node in response to a request for the IP address from the IAB node;
identifying the security context information of the IAB node based on the IP address of the DU of the IAB node;
generating a security parameter, based on the security context information of the IAB node; and
establishing an Internet Protocol Security (IPsec) connection with the IAB node, based on the generated security parameter.
2. The method as claimed in claim 1 ,
wherein the IAB authorization information of IAB node is obtained based on a subscription profile of the IAB node from a core network.
3. The method as claimed in claim 1 , wherein the identifying the security context information of the IAB node comprises:
identifying the security context information of IAB node by using at least one of:
a Cell Radio Network Temporary Identifier (C-RNTI);
a Globally Unique Temporary ID (GUTI) of the IAB node;
an IAB node DU ID, and
an IAB node context ID.
4. The method as claimed in claim 1 , wherein the security context information of the IAB node comprises an Access Stratum (AS) context with the IAB-donor node.
5. The method as claimed in claim 1 , wherein the IP address of the DU of the IAB node is allocated by at least one of an operations, administration and management (OAM) server, a central unit (CU) of the IAB-donor node, and a DU of the IAB-donor node.
6. An Integrated Access and Backhaul (IAB) donor node for authentication of an IAB node in a wireless network, the IAB donor node comprising:
a memory;
a processor coupled with the memory; and
an authentication controller, coupled with the processor, configured to:
obtain an IAB authorization information of the IAB node from one of a network entity during an initial context setup procedure;
send, to the IAB node, an Internet Protocol (IP) address of a distributed unit (DU) of the IAB node to identify a security context information of the IAB node in response to determining that the IAB node is authorized;
identify the security context information of the IAB node based on the IP address the DU of the IAB node;
generate a security parameter, based on the security context information of the IAB node; and
establish an Internet Protocol Security (IPsec) connection with the IAB node, based on the generated security parameter.
7. The IAB-donor node as claimed in claim 6 ,
wherein the IAB authorization information of IAB node is obtained based on a subscription profile of the IAB node from a core network.
8. The IAB-donor node as claimed in claim 6 , wherein the security context information of the IAB node is identified by using at least one of:
a Cell Radio Network Temporary Identifier (C-RNTI);
a Globally Unique Temporary ID (GUTI) of the IAB node;
an IAB node DU ID; and
an IAB node context ID.
9. The IAB-donor node as claimed in claim 6 , wherein the security context information of the IAB node comprises an Access Stratum (AS) context with the IAB-donor node.
10. The IAB-donor node as claimed in claim 6 , wherein the IP address of the DU of the IAB node is allocated by at least one of an operations, administration and management (OAM) server, a central unit (CU) of the IAB-donor node, and a DU of the IAB-donor node.
11. A method for authentication of an Integrated Access Backhaul (IAB) node performed by the IAB node, the method comprising:
performing an IAB-Mobile Termination (MT) setup procedure;
requesting an Internet Protocol (IP) address of a Distributed Unit (DU) of the IAB node used to identify a security context information of the IAB node to an IAB-donor node, after proceeding the IAB-MT setup procedure;
receiving the IP address of the DU of the IAB node from the IAB-donor node;
transmitting a F1 setup message to the IAB-donor node; and
establishing an Internet Protocol Security (IPsec) connection with the IAB-donor node, based on a security parameter generated by the IAB-donor node.
12. The method as claimed in claim 11 , wherein the IAB-MT setup procedure comprises at least one of:
performing Radio Resource Control (RRC) connection establishment with the IAB-donor node;
performing authentication with a core network; and
performing establishment an Access Stratum (AS) context with the IAB-donor node.
13. The method as claimed in claim 11 , wherein the F1 setup message comprises an IAB node DU ID.
14. The method as claimed in claim 11 , wherein the security parameter is generated based on the security context information which is identified by using the IP address of the DU of the IAB node.