IP Library Granted Patent US 12,745,152
Granted Patent B2
US 12,745,152 · App. 18/244,156 · Granted Sep 22, 2026

Methods and apparatus for optimizing UE re-authentication during mobility across different non-3GPP access points under a NSWOF

Inventors: Umamaheswar Achari Kakinada (Greenwood Village, CO); Imtiyaz Shaikh (Irving, TX); Maulik Vaidya (Escondido, CA); Yildirim Sahin (Englewood, CO); Paul L. Russell, Jr. (Lawrence, NJ)
Assignee: Charter Communications Operating, LLC
H04W36/22H04W12/06H04W36/0061H04W36/08H04W36/324H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,745,152
App. No.
18/244,156
Granted
Sep 22, 2026
Kind
B2
Abstract

Methods and apparatus for supporting EAP re-authentication for devices, e.g., UEs, connecting to APs such as WiFi APs, which are not 3GPP base stations such as gNBs are described. In accordance with the invention an ER service which supports EAP re-authentication is incorporated into an NSWOF which is coupled to multiple different APs. Once authenticated through the NSWOF via an EAP authorization process the ER service in the NSWOF stores UE re-authorization information and uses the information to re-authenticate a UE when it attaches to another AP to which the NSWOF is coupled. By supporting EAP re-authentication the need to contact an AUSF as part of a full authentication process is avoided and a UE can rapidly move between APs without having to perform a full EAP authentication involving contacting the AUSF each time the UE moves.

Claims (52)

1 . A method for use in a communications system, the method comprising:

operating a Non-Seamless Wireless Local Area Network (WLAN) Offload Function (NSWOF) including an Extensible Authentication Protocol (EAP) Re-authentication (ER) server to send a first User Equipment (UE) authentication request message to an Authentication Server Function (AUSF) for a first UE, said first UE authentication request message including a first ER indicator indicating that the NSWOF sending the first UE authentication request has ER server capabilities; and

operating the NSWOF to receive a first UE authentication response message from the AUSF, said first UE authentication response message including a second ER indicator, said second ER indicator being an ER acknowledgment (ACK) indicating that ER is supported for the first UE or an ER negative acknowledgement (NACK) indicating that ER is not supported for the first UE.

2 . The method of claim 1 , wherein the first UE authentication request message is sent from the NSWOF in response to the NSWOF receiving a message from a WLAN access node (AN) to which the first UE is seeking to establish a connection.

3 . The method of claim 1 , further comprising:

operating the NSWOF to send a second UE authentication request message to the AUSF for the first UE; and

operating the NSWOF to receive a second UE authentication response message, from the AUSF, in response to the second UE authentication request message, said second UE authentication response message indicating EAP success and including a MSK and one, more than one or all of: i) a Domain Specific Root Key (DSRK), ii) an Extended Master Session Key (EMSK) name (EMSKname) and iii) a DSRKLifetime.

4 . The method of claim 3 , further comprising:

operating the NSWOF to store the DSRK, the EMSKname and the DSRKLifetime corresponding to the first UE for possible re-authentication of the first UE; and

operating the NSWOF to send a protocol message to a WLAN AN indicating successful authentication (EAP-Success) of the first UE and including said MSK but not said DSRK.

5 . The method of claim 4 , wherein said first UE is a UE which is capable of supporting re-authentication through interaction with an ER server, the method further comprising:

operating the NSWOF to receive from a second WLAN access node with which the first UE is attempting to establish a connection, an initial EAP re-authentication message; and

operating the NSWOF to use the stored DSRK corresponding to the first UE to re-authenticate the first UE.

6 . The method of claim 5 , further comprising:

operating the NSWOF to signal successful re-authentication to the second WLAN access node.

7 . The method of claim 1 , further comprising:

operating the AUSF to communicate to a UDM information corresponding to the first UE as part of a UE authentication Get request message relating to the first UE, said UE authentication Get request message including an indicator indicating that re-authentication is supported by the NSWOF; and

operating the AUSF to receive from the UDM a UE authentication Get response message with a third ER indicator indicating whether ER services are to be provided to the first UE.

8 . The method of claim 7 , further comprising:

operating the UDM to determine if ER services are to be provided to the first UE based on one, more than one or all of: i) a service subscription associated with the first UE, ii) a UE identifier; iii) operator policy, iv) a profile associated with the first UE, v) a domain associated with first UE, vi) network usage information associated with the first UE, and vii) a security status associated with the first UE.

9 . The method of claim 8 , wherein the UDM controls re-authentication services provided to the first UE at one of the NSWOF or AUSF by sending re-authentication control information to the NSWOF and/or AUSF.

10 . The method of claim 1 , wherein the first User Equipment (UE) authentication request message further includes a Non-Seamless Wireless Local Area Network (WLAN) Offload (NSWO) indicator, said NSWO indicator being in addition to said first ER indicator.

11 . A communications system, comprising:

a first Wireless Local Area Network (WLAN) Access Node (AN);

a second WLAN AN; and

a Non-Seamless WLAN Offload Function (NSWOF) including an Extensible Authentication Protocol (EAP) Re-Authentication (ER) server and a first processor, the NSWOF being coupled to the first WLAN AN and the second WLAN, said first processor being configured to operate the NSWOF to:

send a first UE authentication request message to an Authentication Server Function (AUSF) for a first UE, said first UE authentication request message including a first ER indicator indicating that the NSWOF sending the first UE authentication request message has ER server capabilities; and

receive a first UE authentication response message from the AUSF, said first UE authentication response message including a second ER indicator, said second ER indicator being an ER acknowledgment (ACK) indicating that ER is supported for the first UE or an ER negative acknowledgement (NACK) indicating that ER is not supported for the first UE.

12 . The communications system of claim 11 , wherein the first UE authentication request message is sent from the NSWOF in response to the NSWOF receiving a message from a WLAN access node to which the first UE is seeking to establish a connection.

13 . The communications system of claim 11 , wherein the first processor is further configured to operate the NSWOF to:

send a second UE authentication request message to the AUSF for the first UE; and

receive a second UE authentication response message, from the AUSF, in response to the second UE authentication request message, said second UE authentication response message indicating EAP success and including a MSK and one, more than one or all of: i) a Domain Specific Root Key (DSRK), ii) an Extended Master Session Key (EMSK) name (EMSKname) and iii) a DSRKLifetime.

14 . The communications system of claim 13 ,

wherein said NSWOF further includes memory; and

wherein said first processor is further configured to operate the NSWOF to:

store, in memory, the DSRK, the EMSKname and the DSRKLifetime corresponding to the first UE for possible re-authentication of the first UE; and

send a protocol message to the first WLAN AN indicating successful authentication of the first UE and including said MSK but not said DSRK.

15 . The communications system of claim 14 , wherein said first UE is a UE which is capable of supporting re-authentication through interaction with an ER server; and

wherein said first processor is further configured to operate the NSWOF to:

receive from the second WLAN access node with which the first UE is attempting to establish a connection; and

use the stored DSRK corresponding to the first UE to re-authenticate the first UE.

16 . The communications system of claim 15 , wherein the re-authentication of the first UE by the NSWOF is performed without the NSWOF contacting the AUSF as part of the first UE re-authorization procedure.

17 . The communications system of claim 15 , wherein said first processor is further configured to operate the NSWOF to:

signal successful re-authentication to the second WLAN access node.

18 . The communications system of claim 11 , further comprising said AUSF, said AUSF including a second processor configured to operate the AUSF to:

communicate to a UDM information corresponding to the first UE as part of a UE authentication Get request message relating to the first UE, said UE authentication Get request message including an indicator indicating that re-authentication is supported by the NSWOF; and

receive from the UDM a UE authentication Get response message with a third ER indicator indicating whether ER services are to be provided to the first UE.

19 . The communications system of claim 18 , further comprising said UDM, said UDM including a third processor configured to:

determine if ER services are to be provided to the first UE based on one, more than one, or all of: i) a service subscription associated with the first UE, ii) a UE identifier; iii) operator policy, iv) a profile associated with the first UE, v) a domain associated with first UE, vi) network usage information associated with the first UE, vii) a security status associated with the first UE.

20 . The communications system of claim 19 , wherein the UDM controls re-authentication services provided to the first UE at one of the NSWOF or AUSF by sending re-authentication control information to the NSWOF and/or AUSF.

21 . The communications system of claim 11 , wherein the first User Equipment (UE) authentication request message further includes a Non-Seamless Wireless Local Area Network (WLAN) Offload (NSWO) indicator, said NSWO indicator being in addition to said first ER indicator.

22 . A non-transitory computer readable medium including machine executable instructions, which when executed by a processor of a Non-Seamless Wireless Local Area Network (WLAN) Offload Function (NSWOF) including an Extensible Authentication Protocol (EAP) Re-authentication (ER) server, cause the NSWOF to perform the steps of: operating the NSWOF) to send a first User Equipment (UE) authentication request message to an Authentication Server Function (AUSF) for a first UE, said first UE authentication request message including a first ER indicator indicating that the NSWOF sending the first UE authentication request has ER server capabilities; and operating the NSWOF to receive a first UE authentication response message from the AUSF, said first UE authentication response message including a second ER indicator, said second ER indicator being an ER acknowledgment (ACK) indicating that ER is supported for the first UE or an ER negative acknowledgement (NACK) indicating that ER is not supported for the first UE.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: VAIDYA, MAULIK
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 064990/0836 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: RUSSELL, PAUL L., JR.
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 064997/0353 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: SAHIN, YILDIRIM
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 065020/0457 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: KAKINADA, UMAMAHESWAR ACHARI
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 064990/0798 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: SHAIKH, IMTIYAZ
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 064990/0827 →
Continuity (2)
Provisional Application 63532674 · Aug 14, 2023
Related Publication 20250063449A1 · Feb 20, 2025
References Cited (43)
US 11032710B2 · Faccin · 2021 [cited by examiner]
US 11290882B2 · Zaus · 2022 [cited by examiner]
US 12170899B2 · S Bykampadi · 2024 [cited by examiner]
US 20150156686A1 · Kikuchi · 2015 [cited by examiner]
US 20150208309A1 · Taneja · 2015 [cited by examiner]
US 20200267554A1 · Faccin · 2020 [cited by examiner]
US 20200344606A1 · Zaus · 2020 [cited by examiner]
US 20210385283A1 · Talebi Fard · 2021 [cited by examiner]
US 20220103540A1 · Prasad · 2022 [cited by examiner]
US 20220408249A1 · Zamora · 2022 [cited by examiner]
US 20230016347A1 · Nair · 2023 [cited by examiner]
US 20230044847A1 · Palanigounder · 2023 [cited by examiner]
US 20230268982A1 · Li · 2023 [cited by examiner]
US 20230368077A1 · Yao · 2023 [cited by examiner]
US 20230370879A1 · Chou · 2023 [cited by examiner]
US 20230388871A1 · Guo · 2023 [cited by examiner]
US 20240073685A1 · Zhang · 2024 [cited by examiner]
US 20240121663A1 · Malik · 2024 [cited by examiner]
US 20240224028A1 · Khare · 2024 [cited by examiner]
US 20240251239A1 · Gupta · 2024 [cited by examiner]
US 20240298174A1 · Rajadurai · 2024 [cited by examiner]
US 20240397362A1 · Yao · 2024 [cited by examiner]
US 20240414067A1 · Yao · 2024 [cited by examiner]
US 20250097747A1 · Bhangu · 2025 [cited by examiner]
US 20250168635A1 · Stojanovski · 2025 [cited by examiner]
US 20250184084A1 · Mondal · 2025 [cited by examiner]
US 20250254639A1 · Salkintzis · 2025 [cited by examiner]
US 20250260976A1 · Huang · 2025 [cited by examiner]
US 20250301318A1 · Lehtovirta · 2025 [cited by examiner]
US 20250301437A1 · Lehtovirta · 2025 [cited by examiner]
US 20250365286A1 · Baskaran · 2025 [cited by examiner]
US 20250393089A1 · Li · 2025 [cited by examiner]
WO 2022146034A1 · 2022 [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects for support for Wireless and Wireline Convergence Phase 2 (5WWC), (Release 18), 3GPP TR 33.887 V1.… [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, International Search Report and Written Opinion of the International Searching Authority f… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 18), 3GPP TS 23.501 V18.2.2, Jul. 2023, 684 pages. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 18), 3GPP TS 33.501 V18.2.0, Jun. 2023, 308 pages. [cited by applicant]
Aboba et al., Request for Comments (RFC) 3579 entitled “RADIUS (Remote Authentication Dial In User Service) Support for Extensible Authentication Protocol (EAP)”, The Internet Society, Sep. 2003, 46 pages. [cited by applicant]
Aboba et al., Request for Comments (RFC) 3748 entitled “Extensible Authentication Protocol (EAP)”, The Internet Society, Jun. 2004, 67 pages. [cited by applicant]
Salowey et al., Request for Comments (RFC) 5295 entitled “Specification for the Derivation of Root Keys from an Extended Master Session Key (EMSK)”, The IETF Trust, Aug. 2008, 21 pages. [cited by applicant]
Arkko et al., Request for Comments (RFC) 5448 entitled “Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA')”, IETF Trust, May 2009, 29 pages. [cited by applicant]
Cao et al., Request for Comments (RFC) 6696 entitled “EAP Extensions for the EAP Re-authentication Protocol (ERP)”, Internet Engineering Task Force, Jul. 2012, 47 pages. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 18), 3GPP TS 23.502 V18.2.0, Jun. 2023, 895 pages. [cited by applicant]