IP Library Granted Patent US 12,402,003
Granted Patent B2
US 12,402,003 · App. 18/010,641 · Granted Aug 26, 2025

Using a pseudonym for access authentication over non-3GPP access

Inventors: Roozbeh Atarius (La Jolla, CA); Apostolis Salkintzis (Athens, GR); Andreas Kunz (Ladenburg, DE); Sheeba Backia Mary Baskaran (Friedrichsdorf, DE)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04W12/062H04L9/3239H04W12/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,402,003
App. No.
18/010,641
Granted
Aug 26, 2025
Kind
B2
Abstract

Apparatuses, methods, and systems are disclosed for using a pseudonym for access authentication over non-3GPP access. One apparatus includes a processor and a transceiver that communicates with a mobile communication network using a 3GPP access network and a non-3GPP access network. The processor sends a registration message to a first network function in the mobile communication network via the 3GPP access network, the first authentication message comprising a first indicator and a SUCI for the apparatus, wherein the first indicator comprises an indication that the apparatus has the capability for access authentication for non-3GPP access in an EPS. The processor receives a first identity pseudonym for the apparatus in response to the registration message comprising the first indicator and performs access authentication via a non-3GPP access network using the first identify pseudonym.

Claims (57)

1. A user equipment (“UE”) comprising:

a processor; and

a memory coupled to the processor, the processor configured to cause UE to:

determine whether an identity pseudonym is preconfigured;

send a registration message to a first network function in a mobile communication network via a Third Generation Partnership Project (“3GPP”) access network, the registration message comprising a first indicator and a subscription concealed identifier (“SUCI”) for the UE, wherein the first indicator comprises an indication that the UE has a capability for access authentication for non-3GPP access in an evolved packet system (“EPS”), and wherein the processor is configured to cause the UE to include the first indicator in response to determining that no identity pseudonym is preconfigured;

receive a first identity pseudonym for the UE apparatus in response to the registration message comprising the first indicator; and

perform access authentication via a non-3GPP access network using the first identity pseudonym.

2. The UE of claim 1 , wherein the first identity pseudonym is a one-time token for communicating a subscriber permanent identifier (“SUPI”) of the UE in a concealed manner.

3. The UE of claim 1 , wherein the indication comprises a fifth generation mobility management (“5GMM”) capability information element.

4. The UE of claim 1 , wherein, to perform access authentication via the non-3GPP access network using the first identity pseudonym, the processor is configured to:

send a first authentication message to a second network function to authenticate with the mobile communication network via the non-3GPP access network, the first authentication message comprising the first identity pseudonym;

receive a second authentication message from the second network function in response to the first authentication message, the second authentication message comprising a challenge packet and a second identity pseudonym,

complete authentication with the mobile communication network using the challenge packet; and

locally store the second identity pseudonym.

5. The UE of claim 4 , wherein the second network function comprises an authentication, authorization, and accounting (“AAA”) server in the mobile communication network, and wherein, to locally store the second identity pseudonym, the processor is configured to replace the first identity pseudonym with the second identity pseudonym.

6. A unified data management (“UDM”) comprising:

a processor; and

a memory coupled to the processor, the processor configured to cause the UDM to:

receive a registration request from a user equipment (“UE”), wherein the registration request contains a first indicator and a subscription concealed identifier (“SUCI”) for the UE;

acquire an identity pseudonym for the UE in response to receiving the first indicator, wherein the identity pseudonym is usable to authenticate the UE for non-3GPP access in an evolved packet system (“EPS”);

store a mapping of the identity pseudonym to a subscriber identity of the UE;

initiate a UE parameter update (“UPU”) procedure; and

send the identity pseudonym to the UE within UPU data.

7. The UDM of claim 6 , wherein the first indicator comprises an indication that the UE has a capability for access authentication for non-3GPP access in an evolved packet system (“EPS”) and a subscriber identity of the UE.

8. The UDM apparatus of claim 7 , wherein the indication comprises a fifth generation mobility management (“5GMM”) capability information element.

9. The UDM of claim 6 , wherein the identity pseudonym comprises a one-time token for communicating a subscriber permanent identifier (“SUPI”) of the UE in a concealed manner.

10. The UDM of claim 6 , wherein, to acquire the identity pseudonym, the processor is configured to create the identity pseudonym using:

a subscriber permanent identifier (“SUPI”) of the UE,

an international mobile subscriber identity (“IMSI”),

or a combination thereof.

11. The UDM of claim 6 , wherein, to acquire the identity pseudonym, the processor is configured to:

encrypt the subscriber identity,

generate a unique value using a random number generator and the subscriber identity, and

generate a hash value using a hash function and the subscriber identity,

or a combination thereof.

12. The UDM of claim 6 , wherein, to acquire the identity pseudonym, the processor is configured to send the subscriber identity to one of: a Home Subscriber Server (“HSS”) or an authentication server in a mobile communication network and receiving the identity pseudonym from the one of a HSS and an authentication server.

13. The UDM of claim 6 , wherein, to store the mapping of the identity pseudonym to a subscriber permanent identifier (“SUPI”) of the UE, the processor is configured to send the identity pseudonym to a Home Subscriber Server (“HSS”) in a mobile communication network.

14. The UDM of claim 9 , wherein, to send the identity pseudonym to the UE, the processor is configured to:

send the identity pseudonym in a registration accept message.

15. An authentication, authorization, and accounting (“AAA”) server comprising:

a processor; and

a memory coupled to the processor, the processor configured to cause the AAA server to:

receive a first authentication message to authenticate a user equipment (“UE”) with a mobile communication network via a non-3GPP access network, the first authentication message comprising a first identity pseudonym for the UE, wherein the first identity pseudonym is received by the UE during a previous registration with the mobile communication network via a Third Generation Partnership Project (“3GPP”) access network;

retrieve an authentication vector for the first identity pseudonym;

create a second identity pseudonym for the UE;

store the second identity pseudonym in the mobile communication network;

forward the second identity pseudonym to a home subscriber server (“HSS”);

send a second authentication message to the UE, the second authentication message comprising the second identity pseudonym and a challenge packet derived from the authentication vector; and

complete authentication with the UE.

16. The AAA server of claim 15 , wherein the first identity pseudonym and second identity pseudonym are each one-time tokens for communicating a subscriber permanent identifier (“SUPI”) of the UE in a concealed manner, wherein the first and second identity pseudonyms are mapped to the SUPI of the UE, wherein, to store the second identity pseudonym, the processor is configured to replace the first identity pseudonym with the second identity pseudonym.

17. The AAA server of claim 15 , wherein, to retrieve the authentication vector, the processor is configured to cause the AAA server to send the first identity pseudonym to the HSS in the mobile communication network and receive a subscriber permanent identifier (“SUPI”) of the UE, wherein the HSS stores a mapping of the first identity pseudonym to the SUPI of the UE, and wherein, to store the second identity pseudonym, the processor is configured to cause the AAA server to send the second identity pseudonym to the HSS.

18. The AAA server of claim 15 , wherein the second identity pseudonym is created using at least one of: a subscriber permanent identifier of the UE and an international mobile subscriber identity.

19. The AAA server of claim 15 , wherein, to create the second identity pseudonym, the processor is configured to:

encrypt a subscriber permanent identifier (“SUPI”) of the UE,

generate a unique value using a random number generator and the SUPI of the UE,

generate a hash value using a hash function and the SUPI of the UE,

or a combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2023
From: ATARIUS, ROOZBEH; SALKINTZIS, APOSTOLIS; KUNZ, ANDREAS; BASKARAN, SHEEBA BACKIA MARY
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 062270/0826 →
Continuity (1)
Related Publication 20230224704A1 · Jul 13, 2023
References Cited (18)
US 20180054730A1 · Hong · 2018 [cited by examiner]
US 20190007376A1 · Norrman · 2019 [cited by examiner]
US 20190014096A1 · Hancock · 2019 [cited by examiner]
US 20200305118A1 · Ryu · 2020 [cited by examiner]
US 20200351980A1 · Talebi Fard · 2020 [cited by examiner]
PCT/IB2021/066521, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration”, International Searching Authority, Feb. 11, 2021,… [cited by applicant]
P. Eronen et al., “Diameter Extensible Authentication Protocol (EAP) Application”, IETF RFC 4072 Standards Track, Aug. 2005, pp. 1-33. [cited by applicant]
J. Arkko et al., “Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA)”, IETF RFC 4187 Standards Track, Jan. 2006, pp. 1-79. [cited by applicant]
J. Arkko et al., “Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA')”, May 2009, pp. 1-29. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Numbering, addressing and identification; (Release 16)”, 3GPP TS 23.003 V16.2.0, Mar. 2020, pp. 1-140. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Architecture enhancements for non-3GPP accesses (Release 16)”, 3GPP TS 23.402 V16.0.0, Jun. 2019, pp. 1-314. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Access to the BGPP Evolved Packet Core (EPC) via non-3GPP access networks; Stage 3 (Release 16)”, 3GPP TS 24.302 V16.3… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3; (Release 16)”, 3GPP TS 24.501 V16.4.1, Mar. 2020, pp. … [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Cx and Dx interfaces based on the Diameter protocol; Protocol details (Release 16)”, 3GPP TS 29.229 V16.1.0, Dec. 2019… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Evolved Packet System (EPS); 3GPP EPS AAA interfaces (Release 16)”, 3GPP TS 29.273 V16.0.0, Mar. 2020, pp. 1-200. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security aspects of non-3GPP accesses (Release 15)”, 3GPP TS 33.402 V15.1.0… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15)”, 3GPP TS 33.501 V15.1.0, Jun. 2018, pp. 1-152. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NR; Radio Resource Control (RRC) protocol specification (Release 15)”, 3GPP TS 38.331 V15.8.0, Dec. 2019, pp. 1-532. [cited by applicant]