Non-public network authentication in 5G

US12335728B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12335728-B2
Application numberUS-202017432835-A
CountryUS
Kind codeB2
Filing dateFeb 24, 2020
Priority dateFeb 27, 2019
Publication dateJun 17, 2025
Grant dateJun 17, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method by a core network node of a core network of a wireless communication system for authenticating a user equipment, UE, to the core network includes receiving a first authentication request to authenticate the UE to the core network, determining that the UE should be authenticated by an external authentication entity that is external to the wireless communication system, transmitting a second authentication request to the external authentication entity, the second authentication request identifying the UE, receiving an authentication response from the external authentication entity verifying authenticity of the UE, the authentication response including a master key, and deriving a first key for securing communications with the UE from the master key.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method by a first core network node of a core network of a wireless communication system for authenticating a user equipment, UE, to the core network, comprising: receiving a first authentication request to authenticate the UE to the core network; transmitting an identifier associated with the UE to a second core network node in response to receiving the first authentication request; receiving a message from the second core network node instructing the first core network node to transmit the authentication request to an external authentication entity; determining that the UE should be authenticated by the external authentication entity that is external to the wireless communication system; transmitting a second authentication request to the external authentication entity, the second authentication request identifying the UE; receiving an authentication response from the external authentication entity verifying authenticity of the UE, the authentication response including a master key; and deriving a first key for securing communications with the UE from the master key. 2. The method of claim 1 , further comprising: performing an extensible authentication protocol, (EAP) exchange, with the external authentication entity after transmitting the authentication request to the external authentication entity. 3. The method of claim 2 , further comprising: transmitting an indication to the UE to derive the first key from the master key in an EAP message in the EAP exchange. 4. The method of claim 3 , wherein transmitting the indication comprises transmitting the indication in an Anti-Bidding down Between Architectures (ABBA) parameter. 5. The method of claim 1 , wherein the core network comprises a 5GC core network, wherein the first core network node comprises a Authentication Server Function (AUSF) node, and wherein the second core network node comprises a Unified Data Management, (UDM) node. 6. The method of claim 1 , wherein the external authentication entity is associated with a non-public network. 7. The method of claim 1 , wherein the first authentication request includes a subscriber concealed identity, SUCI, of the UE, the method further comprising: determining a subscriber permanent identity, SUPI, of the UE, wherein determining that the UE should be authenticated by the external authentication entity is performed based on the SUCI or the SUPI of the UE. 8. The method of claim 1 , wherein determining that the UE should be authenticated by the external authentication entity is performed based on a home network of the UE. 9. The method of claim 1 , wherein: the core network comprises a 5GC core network; the first core network node comprises a Authentication Server Function, AUSF, node; the master key comprises a master session key, MSK; and the first key comprises an AUSF security key, K AUSF . 10. The method of claim 1 , further comprising: transmitting an indication to the UE to derive the first key from the master key. 11. The method of claim 1 , wherein determining that the UE should be authenticated by the external authentication entity is performed according to a predetermined static configuration. 12. The method of claim 1 , wherein the authentication response includes an encapsulated message for the UE indicating successful authentication. 13. The method of claim 1 , wherein the first authentication request is received from an Access and Mobility Management Function (AMF) node in the core network. 14. A network node, comprising: a first core network; a processor circuit; a transceiver coupled to the processor circuit; and a memory coupled to the processor circuit, the memory comprising machine readable program instructions that, when executed by the processor circuit, cause the network node to perform operations of: receiving first authentication request to authenticate the UE to a core network; transmitting an identifier associated with the UE to a second core network node in response to receiving the first authentication request; receiving a message from the second core network node instructing the first core network node to transmit the authentication request to an external authentication entity; determining that the UE should be authenticated by the external authentication entity that is external to a wireless communication system that includes the core network; transmitting a second authentication request to the external authentication entity, the second authentication request identifying the UE; receiving an authentication response from the external authentication entity verifying authenticity of the UE, the authentication response including a master key; and deriving a first key for securing communications with the UE from the master key. 15. A method by a user equipment, UE, in a wireless communication system, comprising: transmitting a registration message to a core network node of the wireless communication system; receiving an indication from the core network node that the UE should derive a security key for communicating with the core network from a master key (MSK) known to an authentication entity outside the wireless communication system; deriving the security key from the MSK; and securing communications with the core network node using the security key. 16. The method of claim 15 , wherein the indication is received in a non-access stratum security establishment message from the core network node. 17. The method of claim 16 , wherein the indication is received as part of an extensible authentication protocol (EAP) exchange performed in response to the registration message. 18. The method of claim 17 , wherein the indication is received in an Anti-Bidding down Between Architectures (ABBA) parameter, of an EAP message received as part of the EAP exchange. 19. The method of claim 15 , wherein the security key comprises a Authentication Server Function (AUSF) key (K AUSF ). 20. A user equipment, UE, comprising: a processor circuit; a transceiver coupled to the processor circuit; and a memory coupled to the processor circuit, the memory comprising machine readable program instructions that, when executed by the processor circuit, cause the UE to perform operations of: transmitting a registration message to a core network node of wireless communication system; receiving an indication from the core network node that the UE should derive a security key for communicating with the core network from a master key (MSK) known to an authentication entity outside the wireless communication system; deriving the security key from the MSK; and securing communications with the core network node using the security key.

Assignees

Inventors

Classifications

  • Key generation or derivation · CPC title

  • using delegated authorisation, e.g. open authorisation [OAuth] protocol · CPC title

  • H04W12/069Primary

    using certificates or pre-shared keys · CPC title

  • applying further key derivation, e.g. deriving traffic keys from a pair-wise master key · CPC title

  • for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12335728B2 cover?
A method by a core network node of a core network of a wireless communication system for authenticating a user equipment, UE, to the core network includes receiving a first authentication request to authenticate the UE to the core network, determining that the UE should be authenticated by an external authentication entity that is external to the wireless communication system, transmitting a se…
Who is the assignee on this patent?
Ericsson Telefon Ab L M
What technology area does this patent fall under?
Primary CPC classification H04W12/069. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 17 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).