IP Library › Granted Patent US 12,432,559
Granted Patent B2
US 12,432,559 · App. 18/610,092 · Granted Sep 30, 2025

Methods and apparatus for secure access control in wireless communications

Inventors: Samir Ferdi (Kirkland, CA); Alec Brusilovsky (Downingtown, PA); Guanzhou Wang (Brossard, CA)
Assignee: INTERDIGITAL PATENT HOLDINGS, INC.
H04W12/08H04W12/106H04W60/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,559
App. No.
18/610,092
Granted
Sep 30, 2025
Kind
B2
Abstract

Method and apparatus for secure access control in wireless communications are disclosed. In an example, a method includes receiving a broadcast message including system information, identifying a first set of hashed identifiers (IDs) and a first random number based on the system information, and each ID of the first set of hashed IDs is individually hashed using at least the first random number. The method also includes calculating a first hash value for each ID of a second set of IDs using at least the first random number, determining whether at least a hashed ID of the second set of IDs matches a hashed ID of the first set of hashed IDs, and sending a request message based on a determination that at least a hashed ID of the second set of IDs matches a hashed ID of the first set of hashed IDs.

Claims (46)

1. A method for wireless communications, performed by a wireless transmit/receive unit (WTRU) the method comprising:

sending, to a network entity, a first registration request via a first closed access group (CAG) cell, the first registration request indicating a capability for CAG;

receiving a registration reject message having new CAG identifier (CAG-ID) information;

updating a CAG configuration using the new CAG-ID information;

selecting a second CAG cell based on the new CAG-ID information; and

sending, to the network entity, a second registration request via the selected second CAG cell.

2. The method of claim 1 , wherein updating the CAG configuration comprises removing stored CAG-ID information and adding the new CAG-ID information.

3. The method of claim 1 , wherein receiving a registration reject message having new CAG-ID information comprises receiving the registration reject message as integrity protected.

4. The method of claim 1 , wherein receiving a registration reject message having new CAG-ID information comprises receiving new CAG-ID information from an access and mobility management function.

5. The method of claim 1 , further comprising, before the sending of the first registration request:

identifying a first set of hashed identifiers, IDs, and a first random number based on received system information, wherein each ID of the first set of hashed IDs is individually hashed using at least the first random number;

calculating a first hash value for each ID of a second set of IDs using at least the first random number; and

determining whether at least a hashed ID of the second set of IDs matches a hashed ID of the first set of hashed IDs.

6. The method of claim 5 , further comprising:

calculating a second hash value, using at least a second random number, for at least an ID associated with a hashed ID of the second set of IDs that matches a hashed ID of the first set of hashed IDs, based on the determination that at least a hashed ID of the second set of IDs matches a hashed ID of the first set of IDs, wherein the first registration request is a message comprising any of: information of the second random number, and the ID hashed by the second random number.

7. The method of claim 6 , wherein the second hash value is calculated using the second random number and a wireless transmit/receive unit, WTRU, ID assigned by a network.

8. The method of claim 5 , wherein the first set of hashed IDs comprises one or more hashed CAG-IDs and wherein the second set of IDs comprises one or more pre-configured allowed CAG-IDs.

9. A wireless transmit/receive unit (WTRU) comprising circuitry, including a transmitter, a receiver, a processor, and memory, the WTRU configured to:

send, to a network entity, a first registration request via a first closed access group (CAG) cell, wherein the first registration request indicates a capability for CAG;

receive a registration reject message having new CAG identifier (CAG-ID) information;

update a CAG configuration using the new CAG-ID information;

select a second CAG cell based on the new CAG-ID information; and

send, to the network entity, a second registration request via the selected CAG cell.

10. The WTRU of claim 9 , wherein the WTRU update of the CAG configuration comprises removing stored CAG-ID information and adding the new CAG-ID information.

11. The WTRU of claim 9 , wherein the WTRU is configured to receive an integrity protected registration reject message.

12. The WTRU of claim 9 , wherein the WTRU is configured to receive the registration reject message from an access and mobility management function.

13. The WTRU of claim 9 , wherein the WTRU is further configured, before the sending of the first registration request, to:

identify a first set of hashed identifiers, IDs, and a first random number based on received system information, wherein each ID of the first set of hashed IDs is individually hashed using at least the first random number;

calculate a first hash value for each ID of a second set of IDs using at least the first random number;

determine whether at least a hashed ID of the second set of IDs matches a hashed ID of the first set of hashed IDs; and

calculate a second hash value, using at least a second random number, for at least an ID associated with a hashed ID of the second set of IDs that matches a hashed ID of the first set of hashed IDs, based on the determination that at least a hashed ID of the second set of IDs matches a hashed ID of the first set of IDs, wherein the first registration request is a message comprising any of: information of the second random number, and the ID hashed by the second random number.

14. The WTRU of claim 13 , wherein the second hash value is calculated using the second random number and a wireless transmit/receive unit, WTRU, ID assigned by a network.

15. The WTRU of claim 13 , wherein the first set of hashed IDs comprises one or more hashed CAG-IDs and wherein the second set of IDs comprises one or more pre-configured allowed CAG-IDs.

16. A non-transient computer-readable storage device having instructions thereon, which when executed by a computer, performs a method comprising:

sending, to a network entity, a first registration request via a first closed access group (CAG) cell, the first registration request indicating a capability for CAG;

receiving a registration reject message having new CAG identifier (CAG-ID) information;

updating a CAG configuration using the new CAG-ID information;

selecting a second CAG cell based on the new CAG-ID information; and

sending, to the network entity, a second registration request via the selected second CAG cell.

17. The device of claim 16 , wherein updating the CAG configuration comprises removing stored CAG-ID information and adding the new CAG-ID information.

18. The method of claim 1 , wherein receiving a registration reject message having new CAG-ID information comprises receiving the registration reject message as integrity protected.

19. The method of claim 1 , wherein receiving a registration reject message having new CAG-ID information comprises receiving new CAG-ID information from an access and mobility management function.

20. The method of claim 1 , further comprising, before the sending of the first registration request:

identifying a first set of hashed identifiers, IDs, and a first random number based on received system information, wherein each ID of the first set of hashed IDs is individually hashed using at least the first random number;

calculating a first hash value for each ID of a second set of IDs using at least the first random number; and

determining whether at least a hashed ID of the second set of IDs matches a hashed ID of the first set of hashed IDs.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: FERDI, SAMIR; BRUSILOVSKY, ALEC; WANG, GUANZHOU
To: IDAC HOLDINGS, INC.
Reel/Frame 066844/0706 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: IDAC HOLDINGS, INC.
To: INTERDIGITAL PATENT HOLDINGS, INC.
Reel/Frame 066849/0046 →
Continuity (5)
Continuation 17440574
Provisional Application 62861773 · Jun 14, 2019
Provisional Application 62839553 · Apr 26, 2019
Provisional Application 62826926 · Mar 29, 2019
Related Publication 20240224035A1 · Jul 4, 2024
References Cited (37)
US 11490291B2 · Talebi Fard · 2022 [cited by examiner]
US 20090262684A1 · Khetawat et al. · 2009 [cited by applicant]
US 20140331052A1 · Suffling · 2014 [cited by applicant]
US 20150009878A1 · Kim et al. · 2015 [cited by applicant]
US 20150156722A1 · Kim et al. · 2015 [cited by applicant]
US 20150264666A1 · et al. · 2015 [cited by applicant]
US 20200275279A1 · Tangudu et al. · 2020 [cited by applicant]
US 20200314701A1 · Talebi et al. · 2020 [cited by applicant]
US 20210400448A1 · Adjakple et al. · 2021 [cited by applicant]
US 20220007274A1 · Jin et al. · 2022 [cited by applicant]
US 20220124579A1 · Han et al. · 2022 [cited by applicant]
US 20220132626A1 · Xu et al. · 2022 [cited by applicant]
US 20230021988A1 · Park et al. · 2023 [cited by applicant]
CN 102612114 · 2012 [cited by applicant]
CN 110536293A · 2019 [cited by applicant]
CN 110536331A · 2019 [cited by applicant]
JP 2015508628A · 2015 [cited by applicant]
JP 2015516121A · 2015 [cited by applicant]
WO 2014030105 · 2014 [cited by applicant]
3GPP S3-190995, “New solution of CAG access control in Non-standalone NPNs,” 2019. [cited by applicant]
3GPP TS 33.501, “Security architecture and procedures for 5G system”, v15.2.0, 2018. [cited by applicant]
3GPP TS 23.502, “Procedures for the 5G System”, V15.4.1, 2019. [cited by applicant]
3GPP TS 38.300, “NR; NR and NG-RAN Overall Description”, Stage 2 (Release 15) V15.4.0, 2018. [cited by applicant]
3GPP TS 23.501, “System Architecture for the 5G System”, V15.4.0, 2018. [cited by applicant]
Whitfield Diffie and Martin E. Hellman, “New directions in cryptography”, IEEE Transactions on Information Theory, 22(6):644-654, 1976. [cited by applicant]
3GPP TS 23.122, “NAS functions related to MS in idle mode,” V16.0.0, 2018. [cited by applicant]
S3-190861, Revision of S3-19abcd, “New Solution for CAG access control in Non-Standalone NPNs”, 3GPP TSG SA WG3 (Security) Meeting #94-Ad Hoc, Mar. 11-15, 2019, Kista, Stockholm (Sweden), 3 pages. [cited by applicant]
IETF RFC 7748, “Elliptic Curves for Security,” A. Langley, M. Hamburg, and S. Turner, 2016, Internet Research Task Force (IRTF). [cited by applicant]
3GPP S2-1902810, “TS 23.502: Introducing Non-public network—CAG,” 3GPP TSG-SA WG2 Meeting #131, Tenerife, Spain. [cited by applicant]
3GPP 52-1902898, “introducing support for Non-Public Networks,” Mar. 2019. [cited by applicant]
S2-1903423, “Change Request”, 23.501, v. 16.0.1 3GPP TSG-SA WG2 Meeting #132, Apr. 8-Apr. 12, 2019, Xi'an, China, 7 pages. [cited by applicant]
3GPP TR 33.813, “Study on Security Aspects of Enhanced Network Slicing”, V0.4.0, 2019. [cited by applicant]
S2-1904667, “Change Request”, 23.501, v. 16.0.1 3GPP TSG-SA WG2 Meeting #132, Apr. 8-Apr. 12, 2019, Xi'an, China, 7 pages. [cited by applicant]
3GPP S3-190994, “Key issue on CAG access control in Non-standalone NPNs,” 2019. [cited by applicant]
3GPP TR 33.846, “Study on authentication enhancements in the 5G System,” VO. 1.0 2019. [cited by applicant]
Samsung, “New solution for CAG access control in Non-standalone NPNs”, 3GPP Tdoc S3-190995, 3GPP TSG SA WG3 (Security) Meeting #94-Ad Hoc, Mar. 11-15, 2019, Kista, Stockholm (Sweden), 3 pages. [cited by applicant]
3GPP TR 33.819, “Study on security for 5GS enhanced support of Vertical and LAN Services,” VO.2.0, 2019. [cited by applicant]