IP Library Granted Patent US 12,568,365
Granted Patent B2
US 12,568,365 · App. 17/969,165 · Granted Mar 3, 2026

Authentication event processing method, apparatus, and system

Inventor: Xuwen Zhao (Shenzhen, CN)
Assignee: Huawei Technologies Co., LTD.
H04W12/06H04W36/0038
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,365
App. No.
17/969,165
Granted
Mar 3, 2026
Kind
B2
Abstract

Embodiments of this application disclose example authentication event processing methods and apparatuses. One example method includes receiving, by a unified data management network element, a second authentication event processing request from an authentication server network element. The unified data management network element can then query an authentication event corresponding to the second information. The unified data management network element can then process the authentication event. The unified data management network element can then send a third authentication event processing request to a unified data repository network element. The unified data management network element can then receive a third authentication event processing response from the unified data repository network element. The unified data management network element can then send a second authentication event processing response to the authentication server network element.

Claims (86)

1 . An authentication event processing method, comprising:

receiving by a unified data management network element, an authentication result confirmation request from an authentication server network element, wherein the authentication result confirmation request comprises a terminal identifier and an authentication event, and the authentication event comprises a serving network name;

storing, by the unified data management network element, the authentication event as an authentication status:

sending, by the unified data management network element, an authentication result confirmation response to the authentication server network element;

receiving, by the unified data management network element, a terminal authentication event confirmation delete request from the authentication server network element, the terminal authentication event confirmation delete request requesting to delete the authentication event, wherein the terminal authentication event confirmation delete request comprises the terminal identifier and the serving network name;

deleting, by the unified data management network element, the authentication event corresponding to the terminal identifier and the serving network name; and

sending, by the unified data management network element, a terminal authentication event confirmation delete response to the authentication server network element.

2 . The method according to claim 1 , wherein the method further comprises:

sending, by the unified data management network element, an authentication event repository request to a unified data repository network element, wherein the authentication event repository request comprises the terminal identifier and the serving network name; and

receiving, by the unified data management network element, an authentication event repository response from the unified data repository network element.

3 . The method according to claim 2 , wherein the authentication event repository response comprises a first authentication event identifier of the authentication event.

4 . The method according to claim 1 , wherein the method further comprises:

querying, by the unified data management network element, the authentication event corresponding to the terminal identifier and the serving network name, after receiving the terminal authentication event confirmation delete request.

5 . The method according to claim 1 , wherein the method further comprises:

sending, by the unified data management network element, a data delete request to a unified data repository network element, wherein the data delete request comprises the terminal identifier and the serving network name; and

receiving, by the unified data management network element, a data delete response from the unified data repository network element.

6 . An authentication event processing method, comprising:

sending, by an authentication server network element, an authentication result confirmation request to a unified data management network element, wherein the authentication result confirmation request comprises a terminal identifier and an authentication event, and the authentication event comprises a serving network name;

receiving, by the unified data management network element, the authentication result confirmation request;

storing, by the unified data management network element, the authentication event as an authentication status;

sending, by the unified data management network element, an authentication result confirmation response to the authentication server network element;

receiving, by the authentication server network element, the authentication result confirmation response;

sending, by the authentication server network element, a terminal authentication event confirmation delete request to the unified data management network element, the terminal authentication event confirmation delete request requesting to delete the authentication event, wherein the terminal authentication event confirmation delete request comprises the terminal identifier and the serving network name;

deleting, by the unified data management network element, the authentication event corresponding to the terminal identifier and the serving network name;

sending, by the unified data management network element, a terminal authentication event confirmation delete processing response to the authentication server network element; and

receiving, by the authentication server network element, the terminal authentication event confirmation delete response.

7 . The method according to claim 5 , wherein the method further comprises:

detecting, by a source mobility management network element, that a terminal moves and registers with a target mobility management network element;

sending, by the source mobility management network element, a context communication service request to the target mobility management network element, wherein the context communication service request comprises an authentication context identifier; and

sending, by the target mobility management network element, a context communication service response to the source mobility management network element.

8 . The method according to claim 5 , wherein the method further comprises:

generating, by the authentication server network element, an authentication context identifier based on at least one of the terminal identifier or the serving network name; and

sending, by the authentication server network element, the authentication context identifier to a mobility management network element.

9 . The method according to claim 6 , wherein the method further comprises:

sending, by the unified data management network element, an authentication event repository request to a unified data repository network element, wherein the authentication event repository request comprises the terminal identifier and the serving network name, or the authentication event repository request comprises the terminal identifier and a first authentication event;

saving, by the unified data repository network element, a correspondence between the terminal identifier and the serving network name or a correspondence between the terminal identifier and the first authentication event; and

receiving, by the unified data management network element, an authentication event repository response from the unified data repository network element.

10 . The method according to claim 6 , wherein the method further comprises:

sending, by the unified data management network element, a data delete request to a unified data repository network element, wherein the data delete request comprises the terminal identifier and the serving network name;

deleting, by the unified data repository network element, the authentication event corresponding to the terminal identifier and the serving network name;

sending, by the unified data repository network element, a data delete response to the unified data management network element; and

receiving, by the unified data management network element, the data delete response.

11 . An authentication event processing apparatus, comprising:

a transceiver;

at least one processor; and

one or more memories coupled to the at least one processor and storing programming instructions for execution by the at least one processor to:

receive, by the transceiver, an authentication result confirmation request from an authentication server network element, wherein the authentication result confirmation request comprises a terminal identifier and an authentication event, and the authentication event comprises a serving network name;

store, by the at least one processor, the authentication event as an authentication status;

send, by the transceiver, an authentication result confirmation response to the authentication server network element;

receive, by the transceiver, a terminal authentication event confirmation delete request from the authentication server network element, the terminal authentication event confirmation delete request requesting to delete the authentication event, wherein the terminal authentication event confirmation delete request comprises the terminal identifier and the serving network name;

delete, by the at least one processor, the authentication event corresponding to the terminal identifier and the serving network name; and

send, by the transceiver, a terminal authentication event confirmation delete response to the authentication server network element.

12 . The apparatus according to claim 11 , the programming instructions are for execution by the at least one processor to:

send, by the transceiver, an authentication event repository request to a unified data repository network element, wherein the authentication event repository request comprises the terminal identifier and the serving network name; and

receive, by the transceiver, an authentication event repository response from the unified data repository network element.

13 . The apparatus according to claim 12 , wherein the authentication event repository response comprises a first authentication event identifier of the authentication event.

14 . The apparatus according to claim 11 , the programming instructions are for execution by the at least one processor to:

send, by the transceiver, a data delete request to a unified data repository network element, wherein the data delete request comprises the terminal identifier and the serving network name; and

receive, by the transceiver, a data delete response from the unified data repository network element.

15 . An authentication event processing system, comprising:

an authentication server network element, configured to send an authentication result confirmation request to a unified data management network element, wherein the authentication result confirmation request comprises a terminal identifier and an authentication event, and the authentication event comprises a serving network name:

the unified data management network element, configured to:

receive the authentication result confirmation request;

store the authentication event as an authentication status; and

send an authentication result confirmation response to the authentication server network element;

the authentication server network element is further configured to send a terminal authentication event confirmation delete request to the unified data management network element, the terminal authentication event confirmation delete request requesting to delete the authentication event, wherein the terminal authentication event confirmation delete request comprises the terminal identifier and the serving network name;

the unified data management network element is further configured to delete the authentication event corresponding to the terminal identifier and the serving network name;

the unified data management network element is further configured to send a terminal authentication event confirmation delete response to the authentication server network element; and

the authentication server network element is further configured to receive the terminal authentication event confirmation delete response.

16 . The system according to claim 15 , wherein the system further comprises:

a source mobility management network element, configured to detect that a terminal moves and registers with a target mobility management network element, wherein

the source mobility management network element is further configured to send a context communication service request to the target mobility management network element, wherein the context communication service request comprises an authentication context identifier; and

the target mobility management network element, configured to send a context communication service response to the source mobility management network element.

17 . The system according to claim 15 , wherein:

the authentication server network element is further configured to generate an authentication context identifier based on at least one of the terminal identifier or the serving network name; and

the authentication server network element is further configured to send the authentication context identifier to a mobility management network element.

18 . The system according to claim 15 , wherein:

the unified data management network element is further configured to send an authentication event repository request to a unified data repository network element, wherein the authentication event repository request comprises fourth information, and the fourth information comprises one or more information comprising at least one of: the terminal identifier, the serving network name, or a second authentication event;

the system further comprises the unified data repository network element configured to store the one or more information in the fourth information; and

the unified data repository network element is further configured to send an authentication event repository response to the unified data management network element.

19 . The system according to claim 18 , wherein:

the unified data repository network element is further configured to generate a second authentication event identifier based on at least one of the terminal identifier or the serving network name; and

the unified data repository network element is further configured to store the second authentication event identifier and the second authentication event, wherein the authentication event repository response comprises the second authentication event identifier.

20 . The system according to claim 15 , wherein the unified data management network element is further configured to send a data delete request to a unified data repository network element, wherein the data delete request comprises the terminal identifier and the serving network name;

the system further comprises the unified data repository network element configured to delete the authentication event corresponding to the terminal identifier and the serving network name; and send a data delete response to the unified data management network element; and

the unified data management network element is further configured to receive the data delete response.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2022
From: ZHAO, XUWEN
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 062104/0542 →
Priority Claims (1)
CN 202010314067.8 · Apr 20, 2020 · national
Continuity (2)
Continuation PCTCN2021077264 · Feb 22, 2021
Related Publication 20230048268A1 · Feb 16, 2023
References Cited (26)
US 20190174449A1 · Shan et al. · 2019 [cited by applicant]
US 20200337012A1 · Tiwari · 2020 [cited by examiner]
CN 101610554A · 2009 [cited by applicant]
CN 101843126A · 2010 [cited by applicant]
CN 108023768A · 2018 [cited by applicant]
CN 110235458A · 2019 [cited by applicant]
CN 110366214A · 2019 [cited by applicant]
CN 110830422A · 2020 [cited by applicant]
CN 110913389A · 2020 [cited by applicant]
WO 2019076801A1 · 2019 [cited by applicant]
WO 2019204199A1 · 2019 [cited by applicant]
3GPP TS 23.501 V16.4.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16),” Mar. 2020, 430 pages. [cited by applicant]
3GPP TS 29.503 V16.3.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Unified Data Management Services; Stage 3 (Release 16),” Mar. 2020, 319 pages. [cited by applicant]
3GPP TS 29.571 V16.3.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Common Data Types for Service Based Interfaces; Stage 3 (Release 16),” Mar. 2020, 100 pag… [cited by applicant]
3GPP TS 29.504 V16.3.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Unified Data Repository Services; Stage 3 (Release 16),” Mar. 2020, 38 pages. [cited by applicant]
3GPP TS 33.501 V16.2.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16),” Mar. 2020, 227 pages. [cited by applicant]
3GPP TS 29.505 V16.2.0, “3rd Generation Partnership Project; 5G System; Usage of the Unified Data Repository services for Subscription Data; Stage 3 (Release 16),” Mar. 2020, 141 pages. [cited by applicant]
3GPP TS 29.501 V16.3.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Principles and Guidelines for Services Definition; Stage 3 (Release 16),” Mar. 2020, 70 p… [cited by applicant]
3GPP TS 29.500 V16.3.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 16),” Mar. 2020, 65… [cited by applicant]
Nokia et al., “AuthEvent deletion,” 3GPP TSG-CT WG4 Meeting #96e, C4-201121, E-Meeting, Feb. 17-28, 2020, 10 pages. [cited by applicant]
Office Action in Chinese Appln. No. 202010314067.8, dated Mar. 15, 2022, 16 pages (with English translation). [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/CN2021/077264, mailed on May 26, 2021, 17 pages (with English translation). [cited by applicant]
Huawei et al., “Discussion on removing the authentication result in the UDM,” 3GPP TSG-SA WG3 Meeting #95, S3-191417, Reno (US), May 6-10, 2019, 3 pages. [cited by applicant]
Huawei et al., “AUSF service update for the authentication result removal,” 3GPP TSG-CT Meeting #87e, CP-200264, E-Meeting, Mar. 16-18, 2020, 9 pages. [cited by applicant]
Huawei, “AUSF service update for the authentication result removal,” 3GPP TSG-CT WG4 Meeting #96e, C4-200837, E-Meeting, Feb. 17-28, 2020, 7 pages. [cited by applicant]
Extended European Search Report in European Appln No. 21791821.8, dated Jul. 27, 2023, 13 pages. [cited by applicant]