IP Library Granted Patent US 12,439,248
Granted Patent B2
US 12,439,248 · App. 17/464,104 · Granted Oct 7, 2025

Authentication result update method and communications apparatus

Inventors: Xuwen Zhao (Shenzhen, CN); Chengdong He (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04W12/06H04L63/1458H04L63/1466H04W12/122H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,439,248
App. No.
17/464,104
Granted
Oct 7, 2025
Kind
B2
Abstract

An authentication result update method and a communications apparatus, where the authentication result update method includes: determining that an authentication result of a terminal device in a first serving network needs to be updated; and sending a first service invocation request to an authentication server, where the first service invocation request is used to request to update the authentication result stored in a unified data management device, where visited network spoofing can be prevented after authentication is completed, and where network security can be improved.

Claims (46)

1. A method, comprising:

determining, by an access and mobility management function device, that an authentication result of a terminal device needs to be removed, wherein the authentication result is a result of authentication of the terminal device from an authentication server; and

sending, by the access and mobility management function device, a request to the authentication server,

wherein the request requests the authentication server to inform a unified data management device, which is configured to receive the authentication result from the authentication server and store the authentication result, to remove the authentication result that is stored in the unified data management device.

2. The method of claim 1 , wherein determining that the authentication result of the terminal device needs to be removed comprises determining, by the access and mobility management function device, that the authentication result of the terminal device needs to be removed in a non-access stratum (NAS) security mode command (SMC) reject scenario.

3. The method of claim 2 , wherein determining, by the access and mobility management function device, that the authentication result of the terminal device needs to be removed in the NAS SMC reject scenario comprises determining, by the access and mobility management function device, that the authentication result of the terminal device needs to be removed when receiving a security mode reject message from the terminal device.

4. The method of claim 1 , wherein determining that the authentication result of the terminal device needs to be removed comprises determining, by the access and mobility management function device, that the authentication result of the terminal device needs to be removed in a terminal device de-registration scenario.

5. The method of claim 4 , wherein determining, by the access and mobility management function device, that the authentication result of the terminal device needs to be removed in the terminal device de-registration scenario comprises:

determining, by the access and mobility management function device, that the authentication result of the terminal device needs to be removed when receiving a de-registration request message from the terminal device; or

determining, by the access and mobility management function device, that the authentication result of the terminal device needs to be removed when the access and mobility management function device initiates a de-registration procedure.

6. The method of claim 1 , wherein the request comprises identity information for uniquely identifying a serving network and the terminal device.

7. A method, comprising:

receiving, by a unified data management device, an authentication result from an authentication server, wherein the authentication result is a result of authentication of a terminal device;

receiving, by the unified data management device configured to store the authentication result, a request from the authentication server, wherein the request requests to remove the authentication result stored in the unified data management device; and

removing, by the unified data management device based on the request, the authentication result stored in the unified data management device.

8. The method of claim 7 , wherein the request comprises identity information of a serving network and subscription permanent identifier (SUPI).

9. The method of claim 7 , wherein before receiving the request, the method further comprises:

receiving, by the unified data management device, an authentication result confirmation request from the authentication server; and

sending, by the unified data management device, an authentication result confirmation response to the authentication server,

wherein the authentication result confirmation response indicates a status of storing the authentication result in the unified data management device.

10. An apparatus, comprising:

one or more processors; and

a memory coupled to the one or more processors and configured to store executable instructions for execution by the one or more processors to instruct the one or more processors to:

determine that an authentication result of a terminal device needs to be removed, wherein the authentication result is a result of authentication of the terminal device from an authentication server; and

send a request to the authentication server,

wherein the request requests the authentication server to inform a unified data management device, which is configured to receive the authentication result from the authentication server and store the authentication result, to remove the authentication result that is stored in the unified data management device.

11. The apparatus of claim 10 , wherein the executable instructions further instruct the one or more processors to determine that the authentication result of the terminal device needs to be removed in a non-access stratum (NAS) security mode command (SMC) reject scenario.

12. The apparatus of claim 11 , wherein the executable instructions further instruct the one or more processors to determine that the authentication result of the terminal device needs to be removed when receiving a security mode reject message from the terminal device.

13. The apparatus of claim 10 , wherein the executable instructions further instruct the one or more processors to determine that the authentication result of the terminal device needs to be removed in a terminal device de-registration scenario.

14. The apparatus of claim 13 , wherein the executable instructions further instruct the one or more processors to:

determine that the authentication result of the terminal device needs to be removed when the apparatus receives a de-registration request message from the terminal device; or

determine that the authentication result of the terminal device needs to be removed when the apparatus initiates a de-registration procedure.

15. The apparatus of claim 10 , wherein the request comprises identity information for uniquely identifying a serving network and the terminal device.

16. An apparatus, comprising:

one or more processors; and

a memory coupled to the one or more processors and configured to store executable instructions for execution by the one or more processors to instruct the one or more processors to:

receive an authentication result from an authentication server, wherein the authentication result is a result of authentication of a terminal device;

store the authentication result;

receive a request from the authentication server, wherein the request requests to remove the authentication result stored in the apparatus; and

remove the authentication result stored in the apparatus based on the request.

17. The apparatus of claim 16 , wherein the request comprises identity information of a serving network and subscription permanent identifier (SUPI).

18. The apparatus of claim 16 , wherein the executable instructions further instruct the one or more processors to:

receive an authentication result confirmation request from the authentication server; and

send an authentication result confirmation response to the authentication server,

wherein the authentication result confirmation response indicates a status of storing the authentication result in the apparatus, and

wherein the apparatus is a unified data management device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 27, 2022
From: ZHAO, XUWEN; HE, CHENGDONG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 062228/0622 →
Priority Claims (2)
CN 201910157246.2 · Mar 1, 2019 · national
CN 201910354210.3 · Apr 29, 2019 · national
Continuity (2)
Continuation PCTCN2020074250 · Feb 4, 2020
Related Publication 20210400482A1 · Dec 23, 2021
References Cited (35)
US 11722982B2 · Shan · 2023 [cited by examiner]
US 20110302639A1 · Matsuda et al. · 2011 [cited by applicant]
US 20160165077A1 · Shibata · 2016 [cited by applicant]
US 20160197917A1 · Lee et al. · 2016 [cited by applicant]
US 20200153871A1 · Lei et al. · 2020 [cited by applicant]
US 20210227392A1 · Zhu · 2021 [cited by examiner]
US 20210314899A1 · Shan · 2021 [cited by examiner]
US 20220046752A1 · Lee · 2022 [cited by examiner]
US 20220053449A1 · Shan · 2022 [cited by examiner]
US 20220070664A1 · Stojanovski · 2022 [cited by examiner]
US 20220095260A1 · Shan · 2022 [cited by examiner]
US 20220103540A1 · Prasad · 2022 [cited by examiner]
US 20220132315A1 · Kolekar · 2022 [cited by examiner]
US 20220141751A1 · Yao · 2022 [cited by examiner]
US 20220182822A1 · Ma · 2022 [cited by examiner]
US 20220338000A1 · Lee · 2022 [cited by examiner]
US 20240396893A1 · Kunz · 2024 [cited by examiner]
CN 1801706A · 2006 [cited by applicant]
CN 101998408A · 2011 [cited by applicant]
CN 102111272A · 2011 [cited by applicant]
CN 107040928A · 2017 [cited by applicant]
CN 108683690A · 2018 [cited by applicant]
CN 109041057A · 2018 [cited by applicant]
WO 2018199668A1 · 2018 [cited by applicant]
WO 2018202284A1 · 2018 [cited by applicant]
WO 2019011751A1 · 2019 [cited by applicant]
WO 2019017837A1 · 2019 [cited by applicant]
3GPP TS 29.503 V15.2.1, “3rd Generation Partnership Project;Technical Specification Group Core Network and Terminals; 5G System; Unified Data Management Services; Stage 3 (Release 15),” Dec. 2018, 175 Pages. [cited by applicant]
Ericsson et al., “Storing FQDN for S5/S8 interface of the PGW-C+SMF in UDM,” 3GPP TSG-SA WG2 Meeting #128bis S2-188530, Sophia Antipolis, France, Aug. 20-24, 2018, 17 Pages. [cited by applicant]
3GPP TS 29.509 V15.2.0, 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals;5G System; Authentication Server Services;Stage 3(Release 15), Dec. 2018, 39 Pages. [cited by applicant]
3GPP TS 33.501 V15.3.1, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system(Release 15),” Dec. 2018, 182 pages. [cited by applicant]
3GPP TS 23.501, V1.4.0, Sep. 2017, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15),” 151 pages. [cited by applicant]
3GPP TS 23.502, V15.4.1, Jan. 2019, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2 (Release 15),” 347 pages. [cited by applicant]
3GPP TR 33.899, V1.3.0, Aug. 2017, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the security aspects of the next generation system (Release 14),” 605 pages. [cited by applicant]
Samsung, “Corrections to multiple authentication vector text references,” 3GPP TSG SA WG3 (Security) Meeting #90-Bis S3-180815, Feb. 26-Mar. 2, 2018, San Diego, US, 12 pages. [cited by applicant]