Systems and methods for authenticating user devices

US11616770B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11616770-B2
Application numberUS-202017072084-A
CountryUS
Kind codeB2
Filing dateOct 16, 2020
Priority dateOct 16, 2020
Publication dateMar 28, 2023
Grant dateMar 28, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method may include receiving, from a user device, a registration request that includes a subscription concealed identifier (SUCI), identifying a network element to decode the SUCI and forwarding the SUCI to the identified network element. The method may also include decoding the SUCI to identify a subscription permanent identifier (SUPI), identifying a unified data management (UDM) device associated with the SUPI and transmitting an authentication request to the identified UDM device to obtain authentication information associated with the user device. The method may further include receiving the authentication information and authenticating the user device based on the received authentication information.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: receiving, from a user device and by an access and mobility management function (AMF) device, a registration request that comprises a subscription concealed identifier (SUCI); identifying a subscriber identity de-concealing function (SIDF) device to decode the SUCI; forwarding the SUCI to the SIDF device; decoding, by the SIDF device, the SUCI to identify a subscription permanent identifier (SUPI); identifying, by a network repository function (NRF) device, a unified data management (UDM) device associated with the identified SUPI; transmitting, by an authentication server function (AUSF) device, an authentication request to the identified UDM device to obtain authentication information associated with the user device; receiving, by the AUSF device, the authentication information; and authenticating the user device based on the received authentication information. 2. The method of claim 1 , wherein identifying the SIDF device comprises: transmitting, by the AMF device, a discovery request to the NRF device. 3. The method of claim 2 , wherein the identifying the SIDF device further comprises: selecting, by the NRF device, the AUSF device located closest to the AMF device, and transmitting, by the AMF device and to the selected AUSF device, a message including the SUCI, and wherein the AUSF device transmits a message including the SUCI to the SIDF device and receives, from the SIDF device, the SUPI. 4. The method of claim 3 , further comprising: using, by the AUSF device, the SUPI for subsequent signaling after the SUPI is received. 5. The method of claim 2 , wherein identifying the SIDF device comprises: identifying, by the NRF device, the SIDF device to decode the SUCI. 6. The method of claim 5 , further comprising: transmitting, by the NRF device, a message including the SUCI to the SIDF device; and receiving, from the SIDF device, the SUPI. 7. The method of claim 1 , further comprising: providing the SUPI to the AUSF device. 8. The method of claim 1 , wherein the SIDF device is included in or co-located with a second UDM device. 9. The method of claim 1 , wherein the identifying the UDM device is performed without using a routing indicator included in the SUCI. 10. A system, comprising: at least one device comprising at least one processor, wherein the at least one device is configured to: receive, from a user device, a registration request that comprises a subscription concealed identifier (SUCI); identify a network element to decode the SUCI; forward the SUCI to the identified network element; decode the SUCI to identify a subscription permanent identifier (SUPI); identify a unified data management (UDM) device associated with the identified SUPI; transmit an authentication request to the identified UDM device to obtain authentication information associated with the user device; receive the authentication information; and authenticate the user device based on the received authentication information. 11. The system of claim 10 , wherein the at least one device comprises: an access and mobility management function (AMF) device, a network repository function (NRF) device, an authentication server function (AUSF) device, a subscriber identity de-concealing function (SIDF) device and the UDM device. 12. The system of claim 11 , wherein the registration request is received by the AMF device and wherein when identifying the network element, the at least one device is further configured to: transmit, by the AMF device, a discovery request to the NRF device. 13. The system of claim 12 , wherein when identifying the network element, the at least one device is further configured to: select, by the NRF device, an authentication server function (AUSF) device located closest to the AMF device; transmit, by the AMF device and to the selected AUSF device, a message including the SUCI; identify a subscriber identity de-concealing function (SIDF) device to decode the SUCI; transmit, by the AUSF device, a message including the SUCI to the SIDF device; and receive, from the SIDF device, the SUPI. 14. The system of claim 13 , wherein the at least one device is further configured to: use, by the AUSF device, the SUPI for subsequent signaling after the SUPI is received. 15. The system of claim 11 , wherein the registration request is received by the AMF device, and wherein when identifying the network element, the at least one device is further configured to: identify, by the NRF device, a subscriber identity de-concealing function (SIDF) device to decode the SUCI. 16. The system of claim 15 , wherein the at least one device is further configured to: transmit, by the NRF device, a message including the SUCI to the SIDF device; and receive, from the SIDF device, the SUPI. 17. The system of claim 11 , wherein the at least one device is further configured to: provide, by the SIDF device, the SUPI to the AUSF device. 18. The system of claim 10 , wherein the at least one device is configured to identify the UDM device without using a routing indicator included in the SUCI. 19. A non-transitory computer-readable medium having stored thereon sequences of instructions which, when executed by at least one processor, cause the at least one processor to: receive a request to identify a subscriber identity de-concealing function (SIDF) device associated with a subscription concealed identifier (SUCI) included in a registration request from a user device; identify the SIDF device to decode the SUCI; forward the SUCI to the identified SIDF device; receive, from the SIDF device, the SUPI; identify a unified data management (UDM) device associated with the SUPI; transmit an authentication request to the identified UDM device to obtain authentication information associated with the user device; receive, from the UDM device, the authentication information; and forward the authentication information to an access mobility function (AMF) device, wherein the authentication information is to be used to authenticate the user device. 20. The non-transitory computer-readable medium of claim 19 , wherein the instructions further cause the at least one processor to: identify the UDM device without using a routing indicator included in the SUCI.

Assignees

Inventors

Classifications

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • H04W12/06Primary

    Authentication · CPC title

  • Subscriber identity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11616770B2 cover?
A method may include receiving, from a user device, a registration request that includes a subscription concealed identifier (SUCI), identifying a network element to decode the SUCI and forwarding the SUCI to the identified network element. The method may also include decoding the SUCI to identify a subscription permanent identifier (SUPI), identifying a unified data management (UDM) device ass…
Who is the assignee on this patent?
Verizon Patent & Licensing Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 28 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).