IP Library Granted Patent US 12,593,206
Granted Patent B2
US 12,593,206 · App. 18/502,799 · Granted Mar 31, 2026

Method for authentication for NSWO service, device, and storage medium

Inventors: Bo Zhang (Shenzhen, CN); Fei Li (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04W12/06H04L9/3271H04L63/0892H04L2209/80H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,593,206
App. No.
18/502,799
Granted
Mar 31, 2026
Kind
B2
Abstract

Embodiments of this application are applicable to the field of communication technologies, and provide a method for authentication for an NSWO service, a device, and a storage medium, applicable to a 5G network. The method for authentication for an NSWO service includes: After determining to perform the NSWO service, the UE sends a SUCI to an AN device. The AN device sends a second request message to an NSWO network element. After determining to perform authentication for the NSWO service, the NSWO network element sends a first authentication request message to an AUSF. After determining to perform authentication for the NSWO service, the AUSF sends a second authentication request message to a UDM. The UDM determines to use an EAP-AKA′ authentication method. Then, the UDM, the AUSF, the NSWO network element, the AN device, and the UE sequentially complete an authentication procedure based on EAP-AKA′ authentication.

Claims (66)

1 . A method of authentication for a non-seamless wireless local area network offload (NSWO) service, comprising:

receiving, from an NSWO network element, a first authentication request message, wherein the first authentication request message comprises a subscription concealed identifier (SUCI) and fourth NSWO indication information, and the fourth NSWO indication information indicates to perform authentication for the NSWO service;

sending, based on the fourth NSWO indication information, a second authentication request message to a unified data management, wherein the second authentication request message comprises the SUCI and fifth NSWO indication information, and the fifth NSWO indication information indicates to perform authentication for the NSWO service;

receiving a second authentication response message from the unified data management, wherein the second authentication response message comprises a second extensible authentication protocol-authentication and key agreement (EAP-AKA′) authentication vector and a subscription permanent identifier (SUPI) of a terminal device, and the SUPI is corresponding to the SUCI;

sending a first authentication response message to the NSWO network element based on the second authentication response message, wherein the first authentication response message is an authentication response message corresponding to an EAP-AKA′ authentication algorithm;

receiving a fifth authentication request message from the NSWO network element; and

performing authentication on the terminal device based on the fifth authentication request message and the second EAP-AKA′ authentication vector.

2 . The method according to claim 1 , the method further comprising:

determining, based on the fourth NSWO indication information, that authentication is to be performed for the NSWO service.

3 . The method according to claim 1 , wherein the second authentication response message comprises RAND and AUTN, and the sending the first authentication response message to the NSWO network element based on the second authentication response message comprises:

sending the first authentication response message including the RAND and the AUTN to the NSWO network element.

4 . The method according to claim 1 , wherein the first authentication response message comprises an extensible authentication protocol/authentication and key agreement-challenge.

5 . The method according to claim 1 , wherein the fifth authentication request message comprises RES, the second EAP-AKA′ authentication vector comprises XRES, and the performing authentication on the terminal device based on the fifth authentication request message and the second EAP-AKA′ authentication vector, comprises:

verifying whether the RES and the XRES are equal.

6 . The method according to claim 1 , wherein the second EAP-AKA′ authentication vector comprises a key CK′ and a key IK′, after the performing authentication on the terminal device based on the fifth authentication request message, the method further comprising:

forgoing calculating a key KAUSF, wherein the key KAUSF is calculated based on the key CK′ and the key IK′.

7 . The method according to claim 1 , wherein the first authentication request message is an authentication service request message for user equipment (UE) authentication, the first authentication response message is an authentication service response message for UE authentication, the second authentication request message is a get service request message for user equipment (UE) authentication, and the second authentication response message is a get service response message for UE authentication.

8 . The method according to claim 1 , wherein the first authentication request message further comprises an access network identity, and the second authentication request message further comprises the access network identity, and the access network identity is used to perform authentication for the NSWO service.

9 . The method according to claim 1 , wherein the second EAP-AKA′ authentication vector comprises a key CK′ and a key IK′, and the sending the first authentication response message to the NSWO network element based on the second authentication response message comprises:

deleting the key CK′ and the key IK′ from the second EAP-AKA′ authentication vector; and

sending the first authentication response message to the NSWO network element, wherein the first authentication response message comprises the second EAP-AKA′ authentication vector with the keys deleted.

10 . A method of authentication for a non-seamless wireless local area network offload (NSWO) service, comprising:

receiving a second authentication request message from an authentication server function, wherein the second authentication request message comprises a subscription concealed identifier (SUCI) and fifth NSWO indication information, and the fifth NSWO indication information indicates to perform authentication for the NSWO service;

calculating a subscription permanent identifier (SUPI) based on the SUCI;

determining, based on the second authentication request message, to use an extensible authentication protocol-authentication and key agreement (EAP-AKA′) authentication method;

obtaining a first EAP-AKA′ authentication vector based on the SUPI; and

sending a second authentication response message to the authentication server function, wherein the second authentication response message comprises a second EAP-AKA′ authentication vector, and the second EAP-AKA′ authentication vector is associated with the first EAP-AKA′ authentication vector.

11 . The method according to claim 10 , wherein the second EAP-AKA′ authentication vector is associated with the first EAP-AKA′ authentication vector comprises:

the second EAP-AKA′ authentication vector is the same as the first EAP-AKA′ authentication vector.

12 . The method according to claim 10 , wherein the second EAP-AKA′ authentication vector is associated with the first EAP-AKA′ authentication vector comprises:

the second EAP-AKA′ authentication vector is a part obtained after a key CK′ and a key IK′ are deleted from the first EAP-AKA′ authentication vector.

13 . The method according to claim 10 , wherein the second authentication request message further comprises an access network identity, and the access network identity is used to perform authentication for the NSWO service.

14 . The method according to claim 10 , wherein the second authentication request message is a get service request message for user equipment (UE) authentication, and the second authentication response message is a get service response message for UE authentication.

15 . A method of authentication for a non-seamless wireless local area network offload (NSWO) service, comprising:

after determining to perform the NSWO service, sending a subscription concealed identifier (SUCI) of a terminal device to an access network device, wherein the SUCI is used to determine an address of an NSWO network element;

receiving a third authentication request message that is from the NSWO network element via the access network device, wherein the third authentication request message is an authentication request message corresponding to an extensible authentication protocol-authentication and key agreement EAP-AKA′ authentication algorithm;

performing authentication verification on a network by using the EAP-AKA′ authentication algorithm;

after the authentication verification succeeds, calculating RES; and

sending the RES to the NSWO network element via the access network device, wherein the RES is used to perform authentication on the terminal device, wherein after the authentication verification succeeds, the method further comprises:

calculating a key CK′ and a key IK′, and forgoing calculating a key K AUSF , wherein the key K AUSF is calculated based on the key CK′ and the key IK′.

16 . The method according to claim 15 , wherein the method further comprises, after the calculating the key CK′ and the key IK′, deleting the key CK′ and the key IK′.

17 . A communication apparatus, comprising at least one processor and at least one memory, wherein the at least one memory is configured to store instructions, and the at least one processor is configured to execute the instructions thereby causing the communication apparatus to:

after determining to perform a non-seamless wireless local area network offload (NSWO) service, send a subscription concealed identifier (SUCI) of the communication apparatus to an access network device, wherein the SUCI is used to determine an address of an NSWO network element;

receive a third authentication request message from the NSWO network element via the access network device, wherein the third authentication request message is an authentication request message corresponding to an extensible authentication protocol-authentication and key agreement (EAP-AKA′) authentication algorithm; and

perform authentication verification on a network by using the EAP-AKA′ authentication algorithm;

after the authentication verification succeeds, calculate RES; and

send the RES to the NSWO network element via the access network device, wherein the RES is used to perform authentication on the communication apparatus, wherein the at least one processor being further configured to further execute the instructions thereby further causing the communication apparatus to:

after the authentication verification succeeds, calculate a key CK′ and a key IK′, and forgo calculating a key K AUSF , wherein the key K AUSF is calculated based on the key CK′ and the key IK′.

18 . The communication apparatus according to claim 17 , wherein the at least one processor being further configured to further execute the instructions thereby further causing the communication apparatus to:

after calculating the key CK′ and the key IK′, delete the key CK′ and the key IK′.

19 . A system, comprising at least one of an authentication server function or a unified data management, wherein

the authentication server function comprises at least one first processor and at least one first memory, wherein the at least one first memory is configured to store first instructions, and the at least one first processor is configured to execute the first instructions thereby causing the authentication server function to:

receive, from an NSWO network element, a first authentication request message, wherein the first authentication request message comprises a subscription concealed identifier (SUCI) and fourth NSWO indication information, and the fourth NSWO indication information indicates to perform authentication for the NSWO service;

send, based on the fourth NSWO indication information, a second authentication request message to the unified data management, wherein the second authentication request message comprises the SUCI and fifth NSWO indication information, and the fifth NSWO indication information indicates to perform authentication for the NSWO service;

receive a second authentication response message from the unified data management, wherein the second authentication response message comprises a second extensible authentication protocol-authentication and key agreement (EAP-AKA′) authentication vector and a subscription permanent identifier (SUPI) of a terminal device, and the SUPI is corresponding to the SUCI;

send a first authentication response message to the NSWO network element based on the second authentication response message, wherein the first authentication response message is an authentication response message corresponding to an EAP-AKA′ authentication algorithm;

receive a fifth authentication request message from the NSWO network element; and

perform authentication on the terminal device based on the fifth authentication request message and the second EAP-AKA′ authentication vector; and

the unified data management comprises at least one second processor and at least one second memory, wherein the at least one second memory is configured to store second instructions, and the at least one second processor is configured to execute the second instructions thereby causing the unified data management to:

receive the second authentication request message from the authentication server function;

calculate the SUPI based on the SUCI;

determine, based on the second authentication request message, to use an extensible authentication protocol-authentication and key agreement (EAP-AKA′) authentication method;

obtain a first EAP-AKA′ authentication vector based on the SUPI, wherein the second EAP-AKA′ authentication vector is associated with the first EAP-AKA′ authentication vector; and

send the second authentication response message to the authentication server function.

20 . The system according to claim 19 , wherein the second EAP-AKA′ authentication vector comprises a key CK′ and a key IK′, and the at least one first processor is configured to execute the first instructions thereby further causing the authentication server function to:

after performing authentication on the terminal device based on the fifth authentication request message, forgoing calculating a key KAUSF, wherein the key KAUSF is calculated based on the key CK′ and the key IK′.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2025
From: ZHANG, BO; LI, FEI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 072597/0287 →
Priority Claims (1)
CN 202110502550.3 · May 8, 2021 · national
Continuity (2)
Continuation PCTCN2022091523 · May 7, 2022
Related Publication 20240073685A1 · Feb 29, 2024
References Cited (12)
US 6950521B1 · Marcovici · 2005 [cited by examiner]
US 20110010764A1 · Lei · 2011 [cited by examiner]
US 20190215691A1 · Salkintzis · 2019 [cited by examiner]
US 20210068048A1 · Chauhan · 2021 [cited by examiner]
US 20240056446A1 · Castellanos Zamora · 2024 [cited by examiner]
US 20240298174A1 · Rajadurai · 2024 [cited by examiner]
3GPP TS 33.501 V17.1.0 (Mar. 2021), 3rd Generation Partnership Project; Technical Specification Group Services and. System Aspects; Security architecture and procedures for 5G system (Release 17), Apr. 6, 2021, XP052000… [cited by applicant]
AT and T et al: “New SID on Non Seamless WLAN Offload in 5GC using 3GPP credentials”, 3GPP TSG-SA Meeting #91-e, e-meeting, Mar. 18-29, 2021, SP-210262, total 3 pages. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Architecture enhancements for non-3GPP accesses (Release 17), 3GPP TS 23.402 V17.0.0 (Mar. 2021), Technical Specification, t… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 17), 3GPP TS 23.502 V17.0.0 (Mar. 2021), Technical Specification, total… [cited by applicant]
Atandt et al., “New SID on Non Seamless WLAN Offload in 5GC using 3GPP credentials”, 3GPP TSG-SA Meeting #91-e e-meeting, SP-210121, Mar. 18-29, 2021, total 4 pages. [cited by applicant]
Huawei et al., “Editorial corrections”, SA WG2 Meeting #128, S2-187083, Jul. 2-6, 2018, total 15 pages. [cited by applicant]