Methods, entities and computer readable media for non-3GPP access authentication
The present disclosure provides methods, entities, and computer readable media for non-3GPP access authentication. The method ( 1600 ) at a protocol translation entity includes: receiving (S 1601 ), from a Non-3GPP access point, an authentication request message of a first protocol type for a UE that includes an identity of the UE; translating (S 1603 ) the authentication request message of the first protocol type to a corresponding authentication request message of a second protocol type; and transmitting (S 1605 ), to an entity for authentication, the corresponding authentication request message of a second protocol type that includes the identity of the UE.
1 . A method performed by an authentication server function (AUSF), the method comprising:
receiving, from AAA-Interworking Function (IWF), an authentication request message of a second protocol type for a User Equipment ‘UE’ for traffic offload from a Non-3rd Generation Partnership Project ‘Non-3GPP’ access network, which comprises a SUbscription Concealed Identifier, SUCI, of the UE;
generating an authentication credential request message of the second protocol type that comprises the SUCI of the UE, based on the received authentication request message of the second protocol type; and
transmitting, to a unified data management (UDM) function, the authentication credential request message of the second protocol type.
2 . The method of claim 1 , wherein
the authentication credential request message of the second protocol type is transmitted to the UDM function for traffic offload from the Non-3GPP access network.
3 . The method of claim 1 , further comprising:
receiving, from the UDM function, a corresponding authentication credential response message of the second protocol type that comprises a SUbscription Permanent Identifier, SUPI, of the UE, for authentication of the UE with an authentication credential received in the authentication credential response message of the second protocol type;
generating an authentication response message of the second protocol type based on the received authentication credential response message of the second protocol type; and
transmitting, to the AAA-IWF, the authentication response message of the second protocol type.
4 . The method of claim 3 , wherein
the authentication request message of the second protocol type comprises an authentication request message over a Service Based Interface (SBI) interface with the AAA-IWF;
the authentication credential request message of the second protocol type comprises an authentication credential request message over an SBI interface with the UDM function;
the authentication credential response message of the second protocol type comprises an authentication credential response message over an SBI interface with the UDM function; and
the authentication response message of the second protocol type comprises an authentication response message over the SBI interface with the AAA-IWF.
5 . The method of claim 1 , wherein the second protocol type refers to a 5G Core ‘5GC’ protocol.
6 . A method performed by a unified data management (UDM) function, the method comprising:
receiving, from an authentication server function (AUSF), an authentication credential request message of a second protocol type for a User Equipment ‘UE’ for traffic offload from a Non-3rd Generation Partnership Project ‘Non-3GPP’ access network, which comprises a SUbscription Concealed Identifier, SUCI, of the UE; and
transmitting, to the AUSF, a corresponding authentication credential response message of the second protocol type that comprises a SUbscription Permanent Identifier, SUPI, of the UE, for authentication of the UE with an authentication credential received in the authentication credential response message of the second protocol type.
7 . The method of claim 6 , wherein
the authentication credential request message of the second protocol type comprises an authentication credential request message over a Service Based Interface (SBI) interface with the entity for authentication; and
the authentication credential response message of the second protocol type comprises an authentication credential response message over an SBI interface with the AUSF.