IP Library Granted Patent US 10,993,161
Granted Patent B2
US 10,993,161 · App. 16/814,690 · Granted Apr 27, 2021

Authenticating user equipments through relay user equipments

Inventor: Adrian Buckley (Tracy, CA)
Assignee: BlackBerry Limited
H04W36/36H04B7/15592H04W8/06H04W12/06H04W60/00H04W88/04H04L63/08H04L63/0884H04W12/03H04W12/75
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,993,161
App. No.
16/814,690
Granted
Apr 27, 2021
Kind
B2
Abstract

In some examples, a first user equipment (UE) sends an indication to an application server that the first UE is to use a relay UE to access a network. The first UE receives, from the application server, a first identity different from a second identity of the first UE. The first UE uses the first identity to register with the network to authenticate the first UE.

Claims (51)

1. A method comprising:

sending, by a remote user equipment (UE), an indication to an application server that the remote UE is to use a wireless relay UE to access a wireless network;

receiving, by the remote UE from the application server, a first identity different from a second identity associated with the remote UE, wherein the first identity is obtained by the application server from a mobility management function; and

using, by the remote UE, the first identity for authentication and registration with the wireless network.

2. The method of claim 1 , wherein the application server comprises a Non-3GPP Inter-Working Function (N3IWF) of a 5G network or an Evolved Packet Data Gateway (ePDG).

3. The method of claim 1 , further comprising receiving, by the remote UE from the wireless relay UE, information of the wireless relay UE.

4. The method of claim 3 , wherein the information of the wireless relay UE is selected from among an identity of the wireless relay UE, information of a network the wireless relay UE is attached to, a location of the wireless relay UE, and an Internet Protocol (IP) address of the application server.

5. The method of claim 1 , wherein the remote UE tunnels, via the wireless relay UE, to the application server to perform the sending and the receiving.

6. The method of claim 5 , wherein the tunneling is based on the wireless relay UE having a connection that only allows access to the application server and is based on an Internet Protocol (IP) address of the application server.

7. The method of claim 1 , wherein the first identity is allocated by the application server or an access and mobility function (AMF) for a 5G network.

8. The method of claim 1 , further comprising establishing, by the remote UE, a secure connection with the application server, wherein the sending and receiving are performed in the secure connection.

9. The method of claim 1 , wherein the sending and the receiving use an Extensible Authentication Protocol (EAP) or an OAuth Protocol.

10. The method of claim 1 , comprising:

as part of the registration with the wireless network:

sending, by the remote UE to the wireless relay UE, an attach message that contains the first identity, the attach message causing the wireless network to send a request for authentication information to a network node that has received, from the application server, the first identity;

receiving, by the remote UE from the network node, the authentication information; and

responding, by the remote UE, to the authentication information to perform authentication of the remote UE in the wireless network.

11. The method of claim 1 , wherein the first identity is received by the remote UE from the application server that obtained the first identity from the mobility management function using messaging according to a second protocol different from a first protocol used to send the indication by the remote UE to the application server.

12. A user equipment (UE) comprising:

a wireless interface to communicate wirelessly; and

at least one processor configured to:

send an indication to an application server that the UE is to use a wireless relay UE to access a wireless network;

receive, from the application server, a first identity different from a second identity associated with the UE, wherein the first identity is obtained by the application server from a mobility management function; and

use the first identity for authentication and registration with the wireless network.

13. The UE of claim 12 , wherein the application server comprises a Non-3GPP Inter-Working Function (N3IWF) of a 5G network or an Evolved Packet Data Gateway (ePDG).

14. The UE of claim 12 , wherein the at least one processor is configured to receive, from the wireless relay UE, information of the wireless relay UE, wherein the information of the wireless relay UE is selected from among an identity of the wireless relay UE, information of a network the wireless relay UE is attached to, a location of the wireless relay UE, and an Internet Protocol (IP) address of the application server.

15. The UE of claim 12 , wherein the at least one processor is configured to:

as part of the registration with the wireless network:

send, to the wireless relay UE, an attach message that contains the first identity, the attach message causing the wireless network to send a request for authentication information to a network node that has received, from the application server, the first identity;

receive, from the network node, the authentication information; and

respond to the authentication information to perform authentication of the UE in the wireless network.

16. An application server comprising:

a communication interface; and

at least one processor coupled to the communication interface and configured to:

receive, from a remote user equipment (UE), an indication that the remote UE is to use a wireless relay UE to access a wireless network;

obtain, from a mobility management function, a first identity associated with the remote UE; and

send, to the remote UE, the first identity different from a second identity associated with the remote UE, the first identity for use by the remote UE in authentication and registration with the wireless network.

17. The application server of claim 16 , wherein the at least one processor is configured to:

send a request to the mobility management function for the first identity of the remote UE, the request sent in messaging according to a second protocol different from a first protocol of the indication.

18. The application server of claim 17 , wherein the first protocol is one of an Extensible Authentication Protocol (EAP) or a Network Access Stratum (NAS) over Internet Protocol (IP), and the second protocol is a NAS protocol.

19. The application server of claim 17 , wherein the at least one processor is configured to:

receive an authentication challenge in messaging according to the second protocol from the wireless network;

send, to the remote UE, the authentication challenge in messaging according to the first protocol;

receive, from the remote UE, an authentication challenge response in messaging according to the first protocol;

send, to the wireless network, the authentication challenge response in messaging according to the second protocol;

receive, from the wireless network, a response to the request, the response being in messaging according to the second protocol and including the first identity; and

send, to the remote UE, the first identity in messaging according to the first protocol.

20. The application server of claim 16 , wherein the application server is a first application server, and wherein the at least one processor is configured to:

receive, from the remote UE, a request to establish a secure connection between the remote UE and the first application server;

in response to determining that the first application server is unable to establish the secure connection, send information associated with the request to a second application server;

receive, from the second application server, the first identity.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2020
From: BUCKLEY, ADRIAN
To: BLACKBERRY CORPORATION
Reel/Frame 052082/0943 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2020
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 052083/0019 →
Continuity (2)
Continuation 15725563 · Oct 5, 2017
Related Publication 20200213927A1 · Jul 2, 2020
Cited By (1)
US 12,603,924