Communication methods, communication devices, communication equipment, and computer storage media

The AKMA Anchor Function addresses the challenge of UE roaming by managing AKMA keys across networks, enhancing key management and service delivery efficiency in roaming scenarios.

JP7876644B2Active Publication Date: 2026-06-19CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2023-06-15
Publication Date
2026-06-19

AI Technical Summary

Technical Problem

Current application authentication and key management (AKMA) processes are limited to when user equipment (UE) is located at its designated site, lacking effective solutions for roaming scenarios.

Method used

The introduction of an AKMA Anchor Function (AAnF) that interacts with an Application Function (AF) to manage and distribute AKMA keys across different networks, including Home Public Land Mobile Networks (HPLMN) and Visit Public Land Mobile Networks (VPLMN), facilitating key management and service provision during UE roaming.

Benefits of technology

Enables seamless AKMA service provision during UE roaming by reducing interaction and management costs between AF and home networks, thereby optimizing key management and service delivery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007876644000001
    Figure 0007876644000001
  • Figure 0007876644000002
    Figure 0007876644000002
  • Figure 0007876644000003
    Figure 0007876644000003
Patent Text Reader

Abstract

Embodiments of the present application provide a communication method, a communication device, a communication apparatus, and a computer storage medium. The method includes: a step in which an Application Authentication and Key Management (AKMA) Anchor Function (AAnF) receives a first message sent from an Application Function (AF) or receives a first message sent from the AF via a first device, where the first message is for obtaining a key; and a step in which, when the AAnF checks that it can provide a service to the AF, the AAnF sends a second message to the AF or sends a second message to the AF via the first device, where the second message includes at least a key.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This application relates to the field of telecommunications technology, and more particularly to telecommunications methods, telecommunications devices, telecommunications equipment, and computer storage media.

[0002] (Cross-reference to related applications) This application claims priority to the Chinese patent application No. 202210701088.4, filed with the China National Intellectual Property Office on June 20, 2022, and all of its contents are incorporated into this application by reference. [Background technology]

[0003] Currently, the application authentication and key management (AKMA) process only applies when the user equipment (UE) is located at its designated site. There is currently no effective solution for when the UE roams to a different network (i.e., roaming scenarios). [Overview of the project] [Problems that the invention aims to solve]

[0004] Embodiments of the present application provide a communication method, a communication device, a communication equipment, and a computer storage medium. [Means for solving the problem]

[0005] The technical solution of the embodiment of the present application is realized as follows.

[0006] In the first aspect, an embodiment of the present application provides a communication method, the method is The AKMA Anchor Function (AAnF) receives a first message transmitted from an Application Function (AF), or receives a first message transmitted from an AF via a first device, wherein the first message is key K AF The steps to obtain If the AAnF checks that it can provide service to the AF, it sends a second message to the AF, or sends a second message to the AF via the first device, wherein the second message is at least key K AF Includes, steps, and

[0007] In some alternative embodiments of the present application, the AAnF is located in a Home Public Land Mobile Network (HPLMN), and / or the first device is located in a Visit Public Land Mobile Network (VPLMN), and / or the AF is located in the VPLMN.

[0008] In some alternative embodiments of the present application, the first message includes an AKMA key identifier (A-KID) and / or an identifier of the AF.

[0009] In some alternative embodiments of the present application, the communication method is such that the AAnF uses an AKMA anchor key (K AKMA ) based on the key K AF This further includes the step of deriving the result.

[0010] In some alternative embodiments of the present application, the second message is: The aforementioned key K AF Information on the validity period, Subscription Permanent Identifier (SUPI), It further includes at least one Generic Public Subscription Identifier (GPSI).

[0011] In some alternative embodiments of the present invention, the communication method further includes the step of the AAnF receiving a third message sent from an Authentication Server Function (AUSF), wherein the third message is for registering a key, and the third message contains A-KID, K AKMA This includes at least one of the following: SUPI, and device roaming information.

[0012] In some alternative embodiments of the present application, the terminal roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0013] In some alternative embodiments of the present invention, the roaming information of the terminal is obtained by the AUSF from Unified Data Management (UDM).

[0014] In some alternative embodiments of the present invention, the terminal roaming information obtained by the AUSF from the UDM is the terminal roaming information associated with the terminal SUPI.

[0015] In some alternative embodiments of the present invention, after receiving the first message, the communication method further includes the step of the AAnF obtaining terminal roaming information from the UDM, wherein the terminal roaming information relates to the terminal corresponding to the A-KID in the first message.

[0016] In some alternative embodiments of the present application, the step of checking whether the AAnF can provide services to the AF includes a step of checking whether the AAnF can provide services to the AF based on the roaming information of the terminal.

[0017] In a second aspect, an embodiment of the present application further provides a communication method, and the method includes: A first device receives a first message sent from an AF and sends the first message to an AAnF, where the first message is for obtaining a key K AF ; and When the AAnF can provide services to the AF, the first device receives a second message sent from the AAnF and sends the second message to the AF, where the second message includes at least the key K AF .

[0018] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0019] In some alternative embodiments of the present application, the first message includes an A-KID and / or an identifier of the AF.

[0020] In some alternative embodiments of the present application, the second message further includes at least one of the validity time information of the key K AF , SUPI, and GPSI.

[0021] In a third aspect, an embodiment of the present application further provides a communication method, and the method includes: A first device receives a first message sent from an AF, where the first message is for obtaining a key K AF ; and If the first device checks that it can provide service to the AF, the step is to send a second message to the AF, wherein the second message is at least the key K AF Includes, steps, and

[0022] In some alternative embodiments of the present application, the first message includes the A-KID and / or the identifier of the AF.

[0023] In some alternative embodiments of the present invention, the communication method further includes the step of the first device receiving first information transmitted from the AAnF, the first information including AKMA context information.

[0024] In some alternative embodiments of the present application, the first information is A-KID, AKMA anchor key (K AKMA ), including at least one of the SUPIs.

[0025] In some alternative embodiments of the present application, the communication method is such that the first device is K AKMA Based on the key K AF This further includes the step of deriving the result.

[0026] In some alternative embodiments of the present application, the AAnF is located in the HPLMN and / or the first device is located in the VPLMN and / or the AF is located in the VPLMN.

[0027] In a fourth aspect, an embodiment of the present application further provides a communication method, the method further comprising the step of AAnF transmitting first information to a first device, the first information including AKMA context information.

[0028] In some alternative embodiments of the present application, the first information is A-KID, AKMA anchor key (K AKMA ), including at least one of the SUPIs.

[0029] In some alternative embodiments of the present application, the communication method further includes the step of the AAnF receiving a third message transmitted from the AUSF, the third message being for registering a key, and the third message being A-KID, K AKMA This includes at least one of the following: SUPI, and device roaming information.

[0030] In some alternative embodiments of the present application, the terminal roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0031] In some alternative embodiments of the present invention, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0032] In some alternative embodiments of the present invention, the terminal roaming information obtained by the AUSF from the UDM is the terminal roaming information associated with the terminal SUPI.

[0033] In some alternative embodiments of the present invention, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN.

[0034] In a fifth aspect, the embodiments of the present application further provide a communication method, the method being: The AF transmits a first message to the first device or AAnF, wherein the first message is key K AF The steps to obtain If the first device or the AAnF checks that it can provide services to the AF, the AF receives a second message transmitted from the first device or the AAnF, wherein the second message contains at least key K AF Includes, steps, and

[0035] In some alternative embodiments of the present application, the AAnF is located in the HPLMN and / or the first device is located in the VPLMN and / or the AF is located in the VPLMN.

[0036] In some alternative embodiments of the present application, the first message includes an AKMA key identifier (A-KID) and / or an identifier of the AF.

[0037] In some alternative embodiments of the present application, the second message is: The aforementioned key K AF It further includes at least one of the following: validity period information, SUPI, or GPSI.

[0038] In the sixth aspect, the embodiments of the present application further provide a communication method, the method being: AUSF includes the step of obtaining authentication-related information from UDM, and said authentication-related information is The information includes at least one of the following: a third instruction information indicating that AKMA key material needs to be generated for the terminal; a fourth instruction information indicating that AKMA key material does not need to be generated for the terminal; routing identifier (RID) information for the terminal; and roaming information for the terminal.

[0039] In some alternative embodiments of the present application, the terminal roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0040] In some alternative embodiments of the present application, the communication method further includes the step of the AUSF sending a third message to the AAnF, the third message being for registering a key, and the third message being A-KID, K AKMA This includes at least one of the following: SUPI, and the roaming information of the terminal.

[0041] In the seventh aspect, the embodiments of the present application further provide a communication method, the method being: The steps include the UDM sending authentication-related information to AUSF, the authentication-related information including at least one of the following: third instruction information indicating that AKMA key material needs to be generated for the terminal; fourth instruction information indicating that AKMA key material does not need to be generated for the terminal; RID information for the terminal; and roaming information for the terminal.

[0042] In some alternative embodiments of the present application, the terminal roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0043] In some alternative embodiments of the present invention, the communication method further includes the steps of: the UDM receiving a fourth message transmitted from the AAnF, the fourth message being for requesting terminal roaming information; and the UDM transmitting a fifth message to the AAnF, the fifth message being for including terminal roaming information.

[0044] In the eighth aspect, an embodiment of the present application further provides a communication device applicable to AAnF, the device comprising a first communication unit and a first processing unit, The first communication unit is configured to receive a first message transmitted from AF, or to receive a first message transmitted from AF via a first device, and the first message is key K AF This is for obtaining, The first processing unit is configured to check whether it can provide service to the AF, The first communication unit is further configured to send a second message to the AF, or to send a second message to the AF via the first device, if the first processing unit checks that it can provide services to the AF, and the second message is at least key K AF Includes.

[0045] In the ninth aspect, an embodiment of the present application further provides a communication device applicable to the first device, the device comprising a first receiving unit and a first transmitting unit, The first receiving unit is configured to receive a first message transmitted from AF and to transmit the first message to AAnF, and the first message is key K AF This is for obtaining, The first transmitting unit is configured to receive a second message transmitted from the AAnF if the AAnF can provide service to the AF, and to transmit the second message to the AF, wherein the second message contains at least the key K AF Includes.

[0046] In a tenth aspect, an embodiment of the present application further provides a communication device applicable to a first device, the device comprising a second communication unit and a second processing unit, The second communication unit is configured to receive a first message transmitted from AF, and the first message is key K AF This is for obtaining, The second processing unit is configured to check whether it can provide service to the AF, The second communication unit is further configured to send a second message to the AF if it checks that the second processing unit can provide service to the AF, and the second message contains at least the key K AF Includes.

[0047] In an eleventh embodiment, an embodiment of the present application further provides a communication device applicable to AAnF, the device comprising a second transmitting unit, the second transmitting unit configured to transmit first information to a first device, the first information including AKMA context information.

[0048] In the twelfth aspect, an embodiment of the present application further provides a communication device applicable to AF, the device comprising a third transmitting unit and a third receiving unit, The third transmission unit is configured to transmit a first message to the first device or AAnF, and the first message is key K AF This is for obtaining, The third receiving unit is configured to receive a second message transmitted from the first device or the AAnF when it checks that the first device or the AAnF can provide service to the AF, and the second message contains at least key K AF Includes.

[0049] In a thirteenth aspect, an embodiment of the present application further provides a communication device applicable to AUSF, the device comprising a fourth receiving unit configured to acquire authentication-related information from a UDM, the authentication-related information including at least one of third instruction information indicating that AKMA key material should be generated for a terminal, fourth instruction information indicating that AKMA key material should not be generated for a terminal, RID information of the terminal, and roaming information of the terminal.

[0050] In a fourteenth aspect, an embodiment of the present application further provides a communication device applicable to a UDM, the device comprising a fifth transmitting unit, the fifth transmitting unit configured to transmit authentication-related information to the AUSF, the authentication-related information comprising at least one of third instruction information indicating that AKMA key material should be generated for the terminal, fourth instruction information indicating that AKMA key material should not be generated for the terminal, RID information of the terminal, and roaming information of the terminal.

[0051] In the 15th embodiment, the embodiment of the present application further provides a computer-readable storage medium in which a computer program is stored, and when the program is executed by a processor, it realizes the steps of the communication method described in any of the first to seventh embodiments of the embodiment of the present application.

[0052] In the sixteenth embodiment, an embodiment of the present application further provides a communication device comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor, when executing the program, performs the steps of the communication method described in any of the first to seventh embodiments of the present application. [Effects of the Invention]

[0053] According to the communication method, communication apparatus, communication equipment and computer storage medium provided by the embodiments of the present application, the method includes the step of AAnF receiving a first message transmitted from AF, or receiving a first message transmitted from AF via a first device, wherein the first message is key K AF The steps are to obtain, and if the AAnF checks that it can provide services to the AF, to send a second message to the AF or to send a second message to the AF via the first device, wherein the second message is at least key K AF The above interaction process enables the AKMA service, where the terminal roams on the visiting network.

[0054] On the other hand, the first device receives the first message transmitted from AF, and the first message is key K AF This is for obtaining the key K, and if the first device checks that it can provide service to the AF, it sends a second message to the AF, and the second message contains at least the key K AF This includes the following. In this embodiment, a first device for managing and storing AKMA key material obtained from the home network is introduced into the network architecture, and AKMA key services are provided to the visited terminal and AF, thereby reducing interaction and management costs between the AF and each home network. [Brief explanation of the drawing]

[0055] [Figure 1]This is a schematic diagram of the AKMA network architecture. [Figure 2] This is another schematic diagram of the network architecture. [Figure 3] This is a schematic diagram of a system architecture to which the communication method of the embodiment of the present invention is applied. [Figure 4a] This is a schematic diagram of a model of a system architecture to which the communication method of the embodiment of the present application is applied. [Figure 4b] This is a schematic diagram of a model of a system architecture to which the communication method of the embodiment of the present application is applied. [Figure 5] This is flowchart 1 of the communication method of the embodiment of the present invention. [Figure 6] This is flowchart 2 of the communication method of the embodiment of the present invention. [Figure 7] This is flowchart 3 of the communication method of the embodiment of the present invention. [Figure 8] This is flowchart 4 of the communication method of the embodiment of the present invention. [Figure 9] This is flowchart 5 of the communication method of the embodiment of the present invention. [Figure 10] This is flowchart 6 of the communication method of the embodiment of the present invention. [Figure 11] This is flowchart 7 of the communication method of the embodiment of the present invention. [Figure 12] This is interaction flowchart 1 of the communication method of the embodiment of the present application. [Figure 13] This is interaction flowchart 2 of the communication method of the embodiment of the present application. [Figure 14] This is interaction flowchart 3 of the communication method of the embodiment of the present application. [Figure 15] This is a schematic diagram 1 showing the configuration of the communication device according to an embodiment of the present invention. [Figure 16] This is a schematic diagram 2 showing the configuration of the communication device according to the embodiment of the present invention. [Figure 17] Figure 3 is a schematic diagram showing the configuration of the communication device according to the embodiment of the present invention. [Figure 18] Figure 4 is a schematic diagram showing the configuration of the communication device according to an embodiment of the present invention. [Figure 19] Figure 5 is a schematic diagram showing the configuration of the communication device according to an embodiment of the present invention. [Figure 20] Figure 6 is a schematic diagram showing the configuration of the communication device according to an embodiment of the present invention. [Figure 21] Figure 7 is a schematic diagram showing the configuration of the communication device according to the embodiment of the present invention. [Figure 22] This is a schematic diagram showing the hardware configuration of the communication device according to the embodiment of the present invention. [Modes for carrying out the invention]

[0056] The present application will be described in more detail below with reference to the drawings and specific embodiments.

[0057] The technical solutions in the embodiments of this application can be applied to various communication systems, such as Global System of Mobile communication (GSM) systems, Long Term Evolution (LTE) systems, or 5G systems. Optionally, a 5G system or 5G network may also be called a New Radio (NR) system or NR network.

[0058] Exemplary, the communication system to which the embodiments of the present application apply may include network equipment and terminal equipment (which may also be called terminals, communication terminals, etc.), and the network equipment may be equipment that communicates with terminal equipment. Here, the network equipment can provide communication coverage within a certain area and can communicate with terminals located within this area. Optionally, the network equipment may be a base station in each communication system, for example, an evolutionary node B in an LTE system, or a base station (gNB) in a 5G system or an NR system.

[0059] In the embodiments of this application, devices with communication functions in a network / system may be referred to as communication devices. Communication devices may include network devices and terminals with communication functions, and network devices and terminals may be the specific devices described above, which will not be repeated here. Communication devices may further include other devices in a communication system, such as other network entities such as network controllers and mobile management entities, but the embodiments of this application are not limited to these.

[0060] The terms "system" and "network" as used herein are always interchangeable. The terms "and / or" as used herein describe only the relationship between the related objects and indicate that three relationships may exist. For example, A and / or B can represent three cases: A existing independently, both A and B existing, or B existing independently. The symbol " / " as used herein usually indicates that the relationship between the preceding and succeeding related objects is "or".

[0061] The terms “first,” “second,” and so on in the specification and claims of this application are not intended to limit any particular order or sequence, but rather to distinguish similar subjects. Furthermore, since the data used in this manner can be interchanged where appropriate, the embodiments of this application described herein may be carried out in an order other than that illustrated or described herein. In addition, the terms “includes,” “has,” and their variations are intended to be non-exclusive. For example, a process, method, system, product, or apparatus incorporating a series of steps or units does not have to be limited to those explicitly listed, but may include other things not explicitly listed or specific to those processes, methods, products, or apparatus.

[0062] Before describing the embodiments of this application in detail, we will first briefly explain AKMA's related technologies.

[0063] Figure 1 is a schematic diagram of the AKMA network architecture. As shown in Figure 1, the core network elements of the AKMA network architecture mainly include AAnF, AF, AUSF, etc., where, AAnF is an anchor function located within a home operator (or home network), and AAnF uses an AKMA anchor key (K) for AKMA services. AKMA ) is stored, and after 5G master authentication is successfully completed between the UE and AUSF, AUSF sends this key to AAnF. AAnF simultaneously sends key K for use between the UE and AF. AF It also generates and maintains the UE's AKMA context.

[0064] AF with AKMA service sends the AKMA application key K to AAnF via AKMA Key Identifier (A-KID). AF AF can request this. AF obtains authentication and authorization for the operator's network before obtaining key K AF You can obtain it.

[0065] AUSF is a UE identifier and AKMA key material, e.g., A-KID and K AKMA These will be provided to AAnF.

[0066] Currently, no network architecture or response processing process has been proposed for AKMA roaming scenarios. However, based on the AKMA network architecture shown in Figure 1, if the application function AF also contracts with the visited network each time the UE roams to the visited network, the architecture of the AKMA service is assumed to be as shown in Figure 2. In such a network architecture, on the other hand, the same AF provides application services to UEs belonging to multiple public land mobile networks (PLMNs). When these UEs roam to the visited PLMN (VPLMN) where the AF is located and the UEs use AKMA services, the AF will use AKMA key material (K AFThis means that in order to obtain (etc.), these UEs need to interact with their home PLMN (HPLMN). Here, HPLMN may also be called the home network or home network, and VPLMN may also be called the visiting network or destination network.

[0067] On the other hand, the same UE may contract for AKMA services with multiple AFs in the locations it visits. This means that when the UE uses AKMA services, these AFs will interact with the HPLMN where the UE is located in order to obtain AKMA key materials.

[0068] The problems that arise in this way are as follows: 1) The AF needs to interact with multiple HPLMNs to obtain AKMA key material. That is, the AF needs to contract with multiple HPLMNs and the corresponding AKMA roaming protocols, which increases the management costs of the AF. 2) When the UE interacts with the AF and uses the AKMA service, the AF needs to interact with HPLMNs to obtain key material, which increases the latency of the AKMA service.

[0069] Figure 3 is a schematic diagram of a system architecture to which the communication method of the embodiment of the present application is applied, and Figures 4a and 4b are schematic diagrams of a model of a system architecture to which the communication method of the embodiment of the present application is applied, respectively. Referring to Figures 3, 4a and 4b, in the embodiment of the present application, a first device is added located in the VPLMN, and its functions include at least the following: 1) It functions as a proxy between the visited AF (vAF) and the AAnF (HAAnF) to which it belongs. 2) It addresses the home network and HAAnF corresponding to the UE and establishes secure communication with the HAAnF. 3) It verifies the legitimacy of the vAF and authorizes the AKMA key material requested by the vAF.

[0070] In each embodiment of the present application, the first device has a plurality of implementable embodiments, and the first device may be called, for example, a proxy, a proxy function, a proxy network element, a network element, a proxy, a proxy function, a proxy NF, a network function (NF), etc., and may be a device that has at least one of the following functions: proxy function, management function, transmission function, key management function, key storage function, and key distribution function. The first device may have only the above-mentioned network function, or it may have other network functions, that is, the above-mentioned network function and other network functions may be provided together.

[0071] When actually deployed or implemented, the first device may be co-located with other network elements within the VPLMN, or the logical function may be implemented by other network elements. For example, if an AKMA service is deployed in the VPLMN, the proxy function is the AAnF of the VPLMN; if an AKMA service is not deployed in the VPLMN, the proxy function may be an independent network element, or it may be co-located with the NEF, UPF or other network elements of the VPLMN, or the logical function of the proxy function may be implemented by other network elements.

[0072] Furthermore, the first device may be an optional feature, and the VPLMN may deploy the first device as needed. For example, if the VPLMN has several locally located AFs that use the AKMA service provided by the HPLMN, the VPLMN may choose to deploy the first device locally to proxy these AFs' interactions with the HPLMN's AANF to obtain AKMA keys, or if an AF deployed in the VPLMN serves multiple HPLMN UEs and uses the AKMA service, the VPLMN may choose to deploy the first device locally to proxy these AFs' interactions with the HPLMN's AAnF to obtain AKMA keys.

[0073] If the AF is a third-party AF, the AF interacts with the first device or AAnF via a Network Exposure Function (NEF), as shown in Figure 4b.

[0074] Based at least on the network architecture described above, we propose the following embodiments of this application.

[0075] The embodiments of the present application provide a communication method. Figure 5 is a flowchart 1 of the communication method according to the embodiments of the present application, and as shown in Figure 5, the method includes the following steps.

[0076] In step 101, AAnF receives a first message transmitted from AF, or receives a first message transmitted from AF via a first device, and the first message is key K AF This is for obtaining [something].

[0077] In step 102, if it is checked that the AAnF can provide service to the AF, a second message is sent to the AF, or a second message is sent to the AF via the first device, and the second message contains at least key K AF Includes.

[0078] In some alternative embodiments, the AAnF is located on the home network (HPLMN), and / or the first device is located on the visitor network (VPLMN), and / or the AF is located on the VPLMN.

[0079] Exemplary, this embodiment is applicable to an AKMA roaming scenario. For example, if a UE roams to a visiting network and an AF is also an application function contracted with that visiting network, and the UE uses AKMA services, the AF uses key K AF You will need to obtain AKMA key materials such as the following. AAnF for home networks, from AF, key KAF Upon receiving the first message to obtain and checking that the AF can provide service, at least key K AF Send a second message containing the above to AF.

[0080] In one embodiment, if the first device is present, the first device addresses the home network and AAnF corresponding to the UE and establishes secure communication with the AAnF, thereby transmitting the first message to the AAnF via the first device, and in response, the second message is sent to the AF via the first device. In another embodiment, if the first device is not present, the AF can search for the AAnF of the home network corresponding to the UE and establish secure communication with the AAnF, and the AF can send the first message directly to the AAnF, and in response, the AAnF sends the second message directly to the AF. Optionally, the AF can send a query message to a Network Repository Function (NRF) to obtain relevant information about the AAnF (such as the AAnF address), and further send the first message based on the obtained relevant information about the AAnF.

[0081] In some alternative embodiments, the first message includes the A-KID and / or the identifier of the AF.

[0082] In some alternative embodiments, the communication method is such that the AAnF is K AKMA Based on the key K AF This further includes the step of deriving the result.

[0083] In this embodiment, during or after the authentication process between the terminal (or UE) and AUSF, AUSF uses the AKMA anchor key (K AKMA ) is sent to AAnF. AAnF is a function within the home operator (or home network) and is used for AKMA services. AKMA It remembers. After receiving the first message, AAnF sends K AKMA Based on key K AFWe can derive the key K AF This can also be called an application key.

[0084] In some alternative embodiments, the second message is: The aforementioned key K AF It further includes at least one of the following: validity period information, SUPI, or GPSI.

[0085] In this embodiment, the key K AF The validity period information is for key K AF The validity period of, or key K AF Represents the expiration time of key K AF You may also display it as "expiration time".

[0086] In some alternative embodiments of the present application, the communication method further includes the step of the AAnF receiving a third message transmitted from the AUSF, the third message being for registering a key, and the third message being A-KID, K AKMA This includes at least one of the following: SUPI, and device roaming information.

[0087] In this embodiment, AAnF registers the key after receiving the third message. Optionally, the communication method further includes the step of AAnF sending a response message of the third message to AUSF.

[0088] In some alternative embodiments, the terminal's roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0089] In this embodiment, if the terminal is not in a roaming state, i.e., if the terminal is within the home network, the terminal's roaming information may include a second instruction information indicating that the terminal is not in a roaming state. If the terminal is in a roaming state, i.e., if the terminal is within the visiting network, the terminal's roaming information may include at least one of the following: a first instruction information indicating that the terminal is in a roaming state, roaming destination information, contract information at the terminal's roaming destination, and policy information at the terminal's roaming destination.

[0090] Here, the roaming destination information may be information indicating the roaming destination network (or visited network), such as the roaming destination network name / identifier, or for example, the service network name (SN name).

[0091] The contract information for the roaming destination of the above-mentioned device may specifically include a list of service agreements between the device and the roaming destination, and contract policies between the device and the roaming destination.

[0092] The policy information for the roaming destination of the above-mentioned device may specifically include whether the home network allows the device to use AKMA services at the visited location, whether the visited network allows the device to use AKMA services, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, and the legitimate monitoring policy of the visited network.

[0093] In some alternative embodiments, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0094] Optionally, the terminal roaming information obtained by the AUSF from the UDM is the terminal roaming information associated with the terminal SUPI.

[0095] In some alternative embodiments of the present invention, after receiving the first message, the communication method further includes the step of the AAnF obtaining terminal roaming information from the UDM, wherein the terminal roaming information relates to the terminal corresponding to the A-KID in the first message.

[0096] In this embodiment, after receiving the first message, AAnF can search for the SUPI of the corresponding terminal based on the A-KID in the first message, and use that SUPI to obtain the roaming information of the corresponding terminal from the UDM.

[0097] In some alternative embodiments, the step of checking whether the AAnF can provide services to the AF includes the step of checking whether the AAnF can provide services to the AF based on the identifier of the AF.

[0098] In some other alternative embodiments, the step of checking whether the AAnF can provide services to the AF includes the step of checking whether the AAnF can provide services to the AF based on the terminal's roaming information.

[0099] In this embodiment, the AAnF can check whether it can provide services to the AF by combining the identifier of the AF with the terminal's roaming information (for example, contract information and / or policy information at the terminal's roaming destination).

[0100] Based on the above embodiments, embodiments of the present application further provide a communication method. Figure 6 is a flowchart 2 of the communication method of embodiments of the present application, and as shown in Figure 6, the method includes the following steps.

[0101] In step 201, the first device receives the first message transmitted from AF, transmits the first message to AAnF, and the first message is key K AF This is for obtaining [something].

[0102] In step 202, if the AAnF can provide service to the AF, the first device receives the second message transmitted from the AAnF, transmits the second message to the AF, and the second message contains at least the key K AF Includes.

[0103] In some alternative embodiments, the AAnF is located in the HPLMN and / or the first device is located in the VPLMN and / or the AF is located in the VPLMN.

[0104] In this embodiment, the first device, as a proxy function or proxy device located in the visiting network, provides a proxy function between the visited AF and the AAnF to which it belongs. After receiving a first message transmitted from the AF, it addresses the corresponding AAnF to which it belongs and transmits the first message to the AAnF. If the AAnF can provide services to the AF, it receives a second message transmitted from the AAnF and transmits the second message to the AF.

[0105] In some alternative embodiments, the first message includes the A-KID and / or the identifier of the AF.

[0106] In this embodiment, A-KID is used as an AKMA key identifier. After receiving the first message, the first device can look up the identifier of the corresponding terminal, for example SUPI, based on the A-KID in the first message. Furthermore, based on the terminal identifier, it can look up and determine the information of the corresponding AAnF to which it belongs (the identifier and / or address of the AAnF).

[0107] In some alternative embodiments, the second message is the key K AF It further includes at least one of the following: validity period information, SUPI, or GPSI.

[0108] In this embodiment, the key K AF The validity period information is for key K AFThe validity period of, or key K AF Represents the expiration time of key K AF You may also display it as "expiration time".

[0109] Embodiments of the present invention further provide a communication method. Figure 7 is a flowchart 3 of the communication method of an embodiment of the present invention, and as shown in Figure 7, the method includes the following steps.

[0110] In step 301, the first device receives a first message transmitted from AF, and the first message contains key K AF This is for obtaining [something].

[0111] In step 302, if it is checked that the first device can provide service to the AF, a second message is sent to the AF, and the second message contains at least the key K AF Includes.

[0112] In some alternative embodiments, the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0113] Exemplary, this embodiment is applicable to an AKMA roaming scenario. For example, if a UE roams to a visiting network and an AF is also an application function of the said visiting network contract, and the UE uses AKMA services, the AF uses key K AF It is necessary to obtain AKMA key materials such as the above. The first device, as a proxy function or proxy device placed in the visiting network, has the function of verifying the legitimacy of the AF and authorizing the AKMA key materials requested by the AF.

[0114] In some alternative embodiments, the first message includes the A-KID and / or the identifier of the AF.

[0115] In this embodiment, the first device can check whether it can provide services to the AF based on the identifier of the AF, and if it is determined that it can provide services to the AF, key KAF Allow sending to AF.

[0116] Optionally, the first device is key K AF If it is determined that there is no such device, the communication method is such that the first device is K AKMA Based on the key K AF This further includes the step of deriving the result.

[0117] In this embodiment, the first device acts as a proxy between the visited AF and the affiliated AAnF, receiving K from AAnF. AKMA If the previously acquired K is obtained and stored, and it is checked that the AF can provide the service, then the previously acquired K AKMA Based on the key K AF Derive the following.

[0118] In some alternative embodiments, the communication method further includes the step of the first device receiving first information transmitted from the AAnF, the first information including AKMA context information.

[0119] In this embodiment, the step of the first device receiving first information transmitted from AAnF includes several feasible embodiments. In one embodiment, the first device sends a request message to AAnF for requesting AKMA context information, and the first device receives first information transmitted from AAnF. In another embodiment, the first device receives first information that is actively pushed by AAnF. In the second embodiment described above, the embodiments of the present application do not limit the temporal order in which the first device receives first information that is actively pushed by AAnF and receives first messages transmitted from AF.

[0120] In some alternative embodiments, the first information is A-KID, K AKMA , including at least one of SUPI.

[0121] Optionally, AAnF is located in HPLMN.

[0122] Based on the above embodiments, embodiments of the present application further provide a communication method. Figure 8 is a flowchart 4 of the communication method of embodiments of the present application, and as shown in Figure 8, the method includes the following steps.

[0123] In step 401, AAnF transmits first information to the first device, and the first information includes AKMA context information.

[0124] In some alternative embodiments, the first information is A-KID, K AKMA , including at least one of SUPI.

[0125] In this embodiment, the step of AAnF transmitting first information to a first device includes several feasible embodiments. In another embodiment, AAnF receives a request message transmitted by the first device, the request message is for requesting AKMA context information, and AAnF transmits first information to the first device based on the request message. In another embodiment, AAnF actively pushes the first information to the first device.

[0126] In this embodiment, after key registration is complete, AAnF adopts one of the above embodiments to transmit AKMA context information to the first device.

[0127] In some alternative embodiments, the communication method further includes the step of the AAnF receiving a third message transmitted from the AUSF, the third message being for registering a key, and the third message being A-KID, K AKMA This includes at least one of the following: SUPI, and device roaming information.

[0128] In this embodiment, the above key registration process is a key registration process initiated by AUSF to AAnF, and AUSF uses terminal identifier information (such as SUPI) and AKMA key material (A-KID, K) for key registration. AKMAAUSF can send information such as (etc.) to AAnF, and optionally, AUSF can also provide AAnF with terminal roaming information.

[0129] Optionally, the roaming information of the terminal includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0130] In this embodiment, if the terminal is not in a roaming state, i.e., if the terminal is within the home network, the terminal's roaming information may include a second instruction information indicating that the terminal is not in a roaming state. If the terminal is in a roaming state, i.e., if the terminal is within the visiting network, the terminal's roaming information may include at least one of the following: a first instruction information indicating that the terminal is in a roaming state, roaming destination information, contract information at the terminal's roaming destination, and policy information at the terminal's roaming destination.

[0131] Here, the roaming destination information may be information indicating the roaming destination network (or visited network), and may be, for example, the roaming destination network name / identifier, for example, the SN name.

[0132] The contract information for the roaming destination of the above-mentioned device may specifically include a list of service agreements between the device and the roaming destination, and contract policies between the device and the roaming destination.

[0133] The policy information for the roaming destination of the above-mentioned device may specifically include whether the home network allows the device to use AKMA services at the visited location, whether the visited network allows the device to use AKMA services, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, and the legitimate monitoring policy of the visited network.

[0134] In some alternative embodiments, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0135] Optionally, the terminal roaming information obtained by the AUSF from the UDM is the terminal roaming information associated with the terminal SUPI.

[0136] In some alternative embodiments, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN.

[0137] Based on the above embodiments, embodiments of the present application further provide a communication method. Figure 9 is a flowchart 5 of the communication method of embodiments of the present application, and as shown in Figure 9, the method includes the following steps.

[0138] In step 501, AF sends a first message to the first device or AAnF, and the first message is key K AF This is for obtaining [something].

[0139] In step 502, if it is checked that the first device or the AAnF can provide service to the AF, the AF receives a second message transmitted from the first device or the AAnF, and the second message contains at least key K AF Includes.

[0140] In some alternative embodiments, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0141] In some alternative embodiments, the first message includes the A-KID and / or the identifier of the AF.

[0142] In some alternative embodiments, the second message is the key K AF It further includes at least one of the following: validity period information, SUPI, or GPSI.

[0143] In this embodiment, the key K AF The validity period information is for key K AF The validity period of, or key K AF Represents the expiration time of key K AF You may also display it as "expiration time".

[0144] Embodiments of the present application further provide a communication method. Figure 10 is a flowchart 6 of the communication method of an embodiment of the present application, and as shown in Figure 10, the method includes the following steps.

[0145] In step 601, AUSF obtains authentication-related information from the UDM, and the authentication-related information is The information includes at least one of the following: a third instruction indicating that AKMA key material needs to be generated for the terminal; a fourth instruction indicating that AKMA key material does not need to be generated for the terminal; the terminal's routing identifier (RID: Router ID) information; and the terminal's roaming information.

[0146] In this embodiment, both the AUSF and UDM are located on the home network (HPLMN). In the authentication process between a terminal and the AUSF, the AUSF sends an authentication request associated with the terminal to the UDM, which may include a terminal identifier. The UDM can perform a check based on the terminal identifier in the authentication request to determine the authentication-related information (or authentication information) of the terminal and send this authentication-related information to the AUSF via an authentication response.

[0147] In this embodiment, AUSF can determine that it is necessary to generate AKMA key material for the terminal based on the third instruction information described above, for example, K AUSF From K AKMA And derive the A-KID. Alternatively, AUSF may determine, based on the fourth instruction information, that it is not necessary to generate AKMA key material for the terminal.

[0148] Here, optionally, the terminal identifier may be a SUPI and / or a Subscription Concealed Identifier (SUCI).

[0149] In some alternative embodiments, the terminal's roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0150] In this embodiment, if the terminal is not in a roaming state, i.e., if the terminal is within the home network, the terminal's roaming information may include a second instruction information indicating that the terminal is not in a roaming state. If the terminal is in a roaming state, i.e., if the terminal is within the visiting network, the terminal's roaming information may include at least one of the following: a first instruction information indicating that the terminal is in a roaming state, roaming destination information, contract information at the terminal's roaming destination, and policy information at the terminal's roaming destination.

[0151] Here, the roaming destination information may be information that indicates the roaming destination network (or visited network), such as the roaming destination network name / identifier, or for example, the SN name.

[0152] The contract information for the roaming destination of the above-mentioned device may specifically include a list of service agreements between the device and the roaming destination, and contract policies between the device and the roaming destination.

[0153] The policy information for the roaming destination of the above-mentioned device may specifically include whether the home network allows the device to use AKMA services at the visited location, whether the visited network allows the device to use AKMA services, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, and the legitimate monitoring policy of the visited network.

[0154] In some alternative embodiments, the communication method further includes the step of the AUSF sending a third message to the AAnF, the third message being for registering a key, and the third message being A-KID, K AKMA This includes at least one of the following: SUPI, and the roaming information of the terminal.

[0155] Based on the above embodiments, embodiments of the present application further provide a communication method. Figure 11 is a flowchart 7 of the communication method of embodiments of the present application, and as shown in Figure 11, the method includes the following steps.

[0156] In step 701, the UDM sends authentication-related information to the AUSF, and the authentication-related information is The information includes at least one of the following: a third instruction information indicating that AKMA key material needs to be generated for the terminal; a fourth instruction information indicating that AKMA key material does not need to be generated for the terminal; the terminal's RID information; and the terminal's roaming information.

[0157] In this embodiment, both the AUSF and UDM are located on the home network (HPLMN). In the authentication process between a terminal and the AUSF, the AUSF sends an authentication request associated with the terminal to the UDM, which may include a terminal identifier. The UDM can perform a check based on the terminal identifier in the authentication request to determine the authentication-related information (or authentication information) of the terminal and send this authentication-related information to the AUSF via an authentication response.

[0158] Here, optionally, the terminal identifier may be SUPI and / or SUCI.

[0159] In some alternative embodiments, the terminal's roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0160] In this embodiment, if the terminal is not in a roaming state, i.e., if the terminal is within the home network, the terminal's roaming information may include a second instruction information indicating that the terminal is not in a roaming state. If the terminal is in a roaming state, i.e., if the terminal is within the visiting network, the terminal's roaming information may include at least one of the following: a first instruction information indicating that the terminal is in a roaming state, roaming destination information, contract information at the terminal's roaming destination, and policy information at the terminal's roaming destination.

[0161] Here, the roaming destination information may be information that indicates the roaming destination network (or visited network), such as the roaming destination network name / identifier, or for example, the SN name.

[0162] The contract information for the roaming destination of the above-mentioned device may specifically include a list of service agreements between the device and the roaming destination, and contract policies between the device and the roaming destination.

[0163] The policy information for the roaming destination of the above-mentioned device may specifically include whether the home network allows the device to use AKMA services at the visited location, whether the visited network allows the device to use AKMA services, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, and the legitimate monitoring policy of the visited network.

[0164] In some alternative embodiments, the communication method further includes the steps of: the UDM receiving a fourth message transmitted from the AAnF, the fourth message requesting terminal roaming information; and the UDM transmitting a fifth message to the AAnF, the fifth message including terminal roaming information.

[0165] The communication method of the embodiment of this application will be described in detail below with reference to specific examples.

[0166] Regarding Example 1 Figure 12 is an interaction flowchart 1 of a communication method according to an embodiment of the present application, and as shown in Figure 12, the method includes the following steps.

[0167] In step 801, during the master authentication process between the UE and AUSF, AUSF sends a UE authentication request to the UDM, which may include a UE identifier.

[0168] Here, the UE identifier may include SUPI and / or SUCI.

[0169] In step 802, the UDM sends a UE authentication response to the AUSF, which may include a subscription certificate (e.g., an AKA authentication vector) and an authentication method.

[0170] Here, the UDM instructs the AUSF to provide AKMA instructions (AKMA Ind) (i.e., whether the AUSF needs to generate AKMA key material for the UE, for example, A-KID and K AKMAIn addition to returning the UE's RID information (including, etc.), the UE's roaming information (i.e., the terminal's roaming information), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc. can also be carried.

[0171] In step 803, based on the AKMA instruction received by the AUSF from the UDM, after the master authentication process is successfully completed, the AUSF derives the keys K AUSF from K AKMA and A-KID. Correspondingly, the UE derives the keys K AUSF from K AKMA and A-KID.

[0172] In step 804, the AUSF addresses the AAnF of the home network and sends a key registration request to the AAnF. The request message can carry A-KID, K AKMA , and the UE's SUPI. The UE's roaming information (i.e., the terminal's roaming information), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc. can also be carried.

[0173] In step 805, the AAnF sends a key registration response to the AUSF.

[0174] In step 806, the UE establishes communication with the AF. The UE sends an Application Session Establishment Request to the AF, and the request message may include A-KID.

[0175] In step 807a, when the first device is located within the visited network and there is no AKMA context associated with the A-KID in the AF, the AF addresses the first device located locally according to the local configuration or policy, or according to the policy obtained from other network elements (such as NRF), and sends a key acquisition request to the first device. After receiving the key acquisition request, the first device sends the key acquisition request to the AAnF, and the request message can carry the A-KID and the identifier of the AF (AF ID).

[0176] In step 807b, when the first device is not located within the visited network and there is no AKMA context associated with the A-KID in the AF, the AF selects to address the AAnF of the home network according to the local configuration or policy, or according to the policy obtained from other network elements (such as NRF), and sends a key acquisition request to the AAnF, and the request message can carry the A-KID and the identifier of the AF (AF ID).

[0177] In step 808, if there is no key K AF derive the AKMA application key (K AKMA ) based on K AF .

[0178] In step 809a, when the first device is located within the visited network, the AAnF sends a key acquisition response to the first device. After receiving the key acquisition response, the first device sends the key acquisition response to the AF, and the response message can carry the key K AF , the validity time information (such as life cycle) of the key K AF , and the SUPI.

[0179] In step 809b, when the first device is not located within the visited network, the AAnF sends a key acquisition response to the AF, and the response message can carry the key K AF , the key K AFIt can transport information about the effective time (lifecycle, etc.) and SUPI.

[0180] In this example, AAnF checks whether it can provide services to the AF using the AF ID, according to the configured local policy or according to authorization information or policies provided by the NRF, or it checks whether it can provide services to the AF using the AF ID in combination with the UE's roaming information (e.g., contract information and / or policy information at the UE's roaming destination). If it determines that it can provide services to the AF, it proceeds with step 808 and subsequent processes. Otherwise, AAnF refuses to proceed with step 808 and subsequent processes.

[0181] In step 810, the AF sends an Application Session Establishment Response to the UE.

[0182] Regarding Example 2 Figure 13 is an interaction flowchart 2 of a communication method according to an embodiment of the present application, and as shown in Figure 13, the method includes the following steps.

[0183] In step 901, during the master authentication process between the UE and AUSF, AUSF sends a UE authentication request to the UDM, which may include a UE identifier.

[0184] Here, the UE identifier may include SUPI and / or SUCI.

[0185] In step 902, the UDM sends a UE authentication response to the AUSF, which may include a subscription certificate (e.g., an AKA authentication vector) and an authentication method.

[0186] Here, the UDM instructs the AUSF to provide AKMA instructions (AKMA Ind) (i.e., whether the AUSF needs to generate AKMA key material for the UE, for example, A-KID and K AKMA In addition to returning RID information of the UE (including, etc.), it can also carry roaming information of the UE (i.e., terminal roaming information), such as a first instruction indicating that the UE is in a roaming state, a second instruction indicating that the UE is not in a roaming state, roaming destination information (such as an identifier or name of the roaming destination), contract information at the UE's roaming destination, and policy information at the UE's roaming destination.

[0187] In step 903, based on the AKMA instructions received from UDM, AUSF will, after the master authentication process is successfully completed, use key K AUSF From K AKMA And A-KID is derived. In response to this, UE is key K AUSF From K AKMA And derive A-KID.

[0188] In step 904, AUSF addresses the AAnF of the home network and sends a key registration request to the AAnF, and the request message contains A-KID, K AKMA The UE can also carry its SUPI, and can carry the UE's roaming information (i.e., terminal roaming information), such as a first instruction indicating that the UE is in a roaming state, a second instruction indicating that the UE is not in a roaming state, roaming destination information (such as an identifier or name of the roaming destination), contract information at the UE's roaming destination, and policy information at the UE's roaming destination.

[0189] In step 905, AAnF sends a key registration response to AUSF.

[0190] In step 906, AAnF transmits the AKMA context information of the UE to the first device in accordance with the local policy, and the AKMA context information is A-KID, K AKMAThis includes, among others.

[0191] Here, step 906 may be completed before step 905, or it may be performed simultaneously with step 905.

[0192] In step 907, the UE establishes communication with the AF and sends an Application Session Establishment Request to the AF, which may include an A-KID in the request message.

[0193] In step 908, if there is no AKMA context associated with the A-KID within the AKMA AF, the AF may address a locally located first device according to its local configuration or policy, or according to a policy obtained from another network element (such as an NRF), and send a key acquisition request to the first device, the request message of which may carry the A-KID and the AF identifier (AF ID).

[0194] In step 909, the first device checks whether it can provide services to the AF using the AF ID, in accordance with the configured local policy or authorization information or policy provided by the NRF. If it determines that it can provide services to the AF, it proceeds with the subsequent processes; otherwise, the first device refuses to proceed with the subsequent processes. The first device has key K AF If not, K AKMA Based on the AKMA application key (K AF Derive the following:

[0195] In step 910, the first device sends a key acquisition response to AF, and the response message contains the key K AF , key K AF It can transport information about the effective time (lifecycle, etc.) and SUPI.

[0196] In step 911, the AF sends an Application Session Establishment Response to the UE.

[0197] Regarding Example 3 Figure 14 is an interaction flowchart 3 of a communication method according to an embodiment of the present invention, and as shown in Figure 14, the method includes the following steps.

[0198] In step 1001, during the master authentication process between the UE and the AUSF, the AUSF sends a UE authentication request to the UDM, and the UE authentication request may include a UE identifier.

[0199] Here, the UE identifier may include SUPI and / or SUCI.

[0200] In step 1002, the UDM sends a UE authentication response to the AUSF, which may include a subscription certificate (e.g., an AKA authentication vector) and an authentication method.

[0201] Here, the UDM instructs the AUSF to provide AKMA instructions (AKMA Ind) (i.e., whether the AUSF needs to generate AKMA key material for the UE, for example, A-KID and K AKMA In addition to returning RID information of the UE (including, etc.), it can also carry roaming information of the UE (i.e., terminal roaming information), such as a first instruction indicating that the UE is in a roaming state, a second instruction indicating that the UE is not in a roaming state, roaming destination information (such as an identifier or name of the roaming destination), contract information at the UE's roaming destination, and policy information at the UE's roaming destination.

[0202] In step 1003, based on the AKMA instructions received from UDM, AUSF will, after the master authentication process is successfully completed, use key K AUSF From K AKMA And A-KID is derived. In response to this, UE is key KAUSF From K AKMA And derive A-KID.

[0203] In step 1004, AUSF addresses the AAnF of the home network and sends a key registration request to the AAnF, and the request message contains A-KID, K AKMA The UE can also carry its SUPI, and can carry the UE's roaming information (i.e., terminal roaming information), such as a first instruction indicating that the UE is in a roaming state, a second instruction indicating that the UE is not in a roaming state, roaming destination information (such as an identifier or name of the roaming destination), contract information at the UE's roaming destination, and policy information at the UE's roaming destination.

[0204] In step 1005, AAnF sends a key registration response to AUSF.

[0205] In step 1006, the UE establishes communication with the AF and sends an Application Session Establishment Request to the AF, which may include an A-KID in the request message.

[0206] In step 1007a, if a first device is located within the visiting network and there is no AKMA context associated with the A-KID within the AF, the AF addresses the locally located first device according to its local configuration or policy, or according to a policy obtained from another network element (such as an NRF), and sends a key acquisition request to the first device. After receiving the key acquisition request, the first device sends the request to the AAnF, and the request message may carry the A-KID and the AF identifier (AF ID).

[0207] In step 1007b, if the first device is not located within the visiting network and there is no AKMA context associated with the A-KID within the AF, the AF may choose to address the AAnF of the home network according to its local configuration or policy, or according to a policy obtained from another network element (such as an NRF), and send a key acquisition request to the AAnF, which may carry the A-KID and the AF identifier (AF ID).

[0208] In steps 1008 to 1009, after receiving the key acquisition request, AAnF sends a roaming information acquisition request to UDM, the request message may include a SUPI, UDM queries and acquires the corresponding UE's roaming information (i.e., terminal roaming information) based on the SUPI, and sends a roaming information acquisition response to AAnF, the response message including the UE's roaming information (i.e., terminal roaming information).

[0209] Here, the UE's roaming information (i.e., terminal roaming information) may include a first instruction information indicating that the UE is in a roaming state, a second instruction information indicating that the UE is not in a roaming state, roaming destination information (such as an identifier or name of the roaming destination), contract information at the UE's roaming destination, policy information at the UE's roaming destination, and so on.

[0210] In step 1010, key K is assigned to AAnF. AF If not, K AKMA Based on the AKMA application key (K AF Derive the following:

[0211] In step 1011a, if the first device is located within the visiting network, AAnF sends a key acquisition response to the first device, and after the first device receives the key acquisition response, it sends the key acquisition response to AF, and the response message contains the key K AF , key K AF It can transport information about the effective time (lifecycle, etc.) and SUPI.

[0212] In step 1011b, if the first device is not located within the visited network, AAnF sends a key acquisition response to AF, and the response message contains the key K AF , key K AF It can transport information about the effective time (lifecycle, etc.) and SUPI.

[0213] In this example, AAnF checks whether it can provide services to the AF using the AF ID, according to the configured local policy or according to authorization information or policies provided by the NRF, or it checks whether it can provide services to the AF using the AF ID in combination with the UE's roaming information (e.g., contract information and / or policy information at the UE's roaming destination). If it determines that it can provide services to the AF, it proceeds with steps 1010 and subsequent processes. Otherwise, AAnF refuses to proceed with steps 1010 and subsequent processes.

[0214] In step 1012, the AF sends an Application Session Establishment Response to the UE.

[0215] Based on the above embodiment, the embodiment of the present application further provides a communication device applicable to AAnF. Figure 15 is a schematic diagram showing the configuration of the communication device of the embodiment of the present application, and as shown in Figure 15, the device comprises a first communication unit 11 and a first processing unit 12. The first communication unit 11 is configured to receive a first message transmitted from an application function (AF), or to receive a first message transmitted from an AF via a first device, and the first message is key K AF This is for obtaining, The first processing unit 12 is configured to check whether it can provide service to the AF, When the first communication unit 11 further checks that the first processing unit 12 can provide services to the AF, it is configured to transmit a second message to the AF or transmit the second message to the AF via the first device. The second message includes at least the key K AF and is included.

[0216] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0217] In some alternative embodiments of the present application, the first message includes the A-KID and / or the identifier of the AF.

[0218] In some alternative embodiments of the present application, the first processing unit 12 is further configured to derive the key K AKMA based on K AF and is configured to derive it.

[0219] In some alternative embodiments of the present application, the second message further includes at least one of the validity time information of the key K AF , the SUPI, and the GPSI.

[0220] In some alternative embodiments of the present application, the first communication unit 11 is further configured to receive a third message transmitted from the AUSF. The third message is for registering a key, and the third message includes at least one of the A-KID, K AKMA , the SUPI, and the roaming information of the terminal.

[0221] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of the first indication information indicating that the terminal is in a roaming state, the second indication information indicating that the terminal is not in a roaming state, the roaming destination information, the contract information at the roaming destination of the terminal, and the policy information at the roaming destination of the terminal.

[0222] In some alternative embodiments of the present invention, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0223] In some alternative embodiments of the present invention, the terminal roaming information obtained by the AUSF from the UDM is the terminal roaming information associated with the terminal SUPI.

[0224] In some alternative embodiments of the present invention, the first communication unit 11 is further configured to obtain terminal roaming information from the UDM after receiving the first message, the terminal roaming information relating to the terminal corresponding to the A-KID in the first message.

[0225] In some alternative embodiments of the present invention, the first processing unit 12 is configured to check whether it can provide service to the AF based on the roaming information of the terminal.

[0226] In the embodiments of the present invention, the first processing unit 12 in the communication device can be implemented in actual applications by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU), or a field-programmable gate array (FPGA), and the first communication unit 11 in the communication device can be implemented in actual applications by being coupled with a communication assembly (including a basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna.

[0227] Embodiments of the present application further provide a communication device applicable to the first device. Figure 16 is a schematic diagram showing the configuration of the communication device of the embodiment of the present application, and as shown in Figure 16, the device comprises a first receiving unit 21 and a first transmitting unit 22. The first receiving unit 21 is configured to receive a first message transmitted from AF and to transmit the first message to AAnF, and the first message is key K AF This is for obtaining, The first transmission unit 22 is configured to receive a second message transmitted from the AAnF if the AAnF can provide service to the AF, and to transmit the second message to the AF, wherein the second message contains at least the key K AF Includes.

[0228] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0229] In some alternative embodiments of the present application, the first message includes the A-KID and / or the identifier of the AF.

[0230] In some alternative embodiments of the present application, the second message is: The aforementioned key K AF It further includes at least one of the following: validity period information, SUPI, or GPSI.

[0231] In the embodiments of the present invention, the first receiving unit 21 and the first transmitting unit 22 in the communication device can be realized in actual applications by being coupled with a communication assembly (including a basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna.

[0232] Embodiments of the present application further provide a communication device applicable to the first device. Figure 17 is a schematic diagram showing the configuration of the communication device of the embodiment of the present application, and as shown in Figure 17, the device comprises a second communication unit 31 and a second processing unit 32. The second communication unit 31 is configured to receive a first message transmitted from AF, and the first message is key K AF This is for obtaining, The second processing unit 32 is configured to check whether it can provide service to the AF, The second communication unit 31 is further configured to send a second message to the AF if it checks that the second processing unit 32 can provide service to the AF, and the second message contains at least the key K AF Includes.

[0233] In some alternative embodiments of the present application, the first message includes the A-KID and / or the identifier of the AF.

[0234] In some alternative embodiments of the present invention, the second communication unit 31 is further configured to receive first information transmitted from the AAnF, the first information including AKMA context information.

[0235] Some alternative embodiments of the present application, the first information is A-KID, K AKMA , including at least one of SUPI.

[0236] In some alternative embodiments of the present application, the second processing unit 32 further comprises K AKMA Based on the key K AF It is configured to derive the following.

[0237] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0238] In the embodiments of the present invention, the second processing unit 32 in the communication device can be implemented by a CPU, DSP, MCU, or FPGA in an actual application, and the second communication unit 31 in the communication device can be implemented by coupling with a communication assembly (including a basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in an actual application.

[0239] Embodiments of the present application further provide a communication device applicable to AAnF. FIG. 18 is a schematic diagram 4 showing the configuration of the communication device according to an embodiment of the present application. As shown in FIG. 18, the device includes a second transmission unit 41, and the second transmission unit 41 is configured to transmit first information to a first device, and the first information includes AKMA context information.

[0240] In some alternative embodiments of the present application, the first information includes at least one of A-KID, K AKMA , and SUPI.

[0241] In some alternative embodiments of the present application, the communication device further includes a second reception unit 42, and the second reception unit 42 is configured to receive a third message transmitted from an AUSF. The third message is for registering a key, and the third message includes at least one of A-KID, K AKMA , SUPI, and roaming information of the terminal.

[0242] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0243] In some alternative embodiments of the present application, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0244] In some alternative embodiments of the present application, the roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI.

[0245] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN.

[0246] In the embodiments of the present invention, the second receiving unit 42 and the second transmitting unit 41 within the communication device can be realized in actual applications by being coupled with a communication assembly (including a basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna.

[0247] Embodiments of the present application further provide a communication device applicable to AF. Figure 19 is a schematic diagram showing the configuration of the communication device of the embodiment of the present application, and as shown in Figure 19, the device comprises a third transmitting unit 51 and a third receiving unit 52. The third transmission unit 51 is configured to transmit a first message to the first device or AAnF, and the first message is key K AF This is for obtaining, The third receiving unit 52 is configured to receive a second message transmitted from the first device or the AAnF when it checks that the first device or the AAnF can provide service to the AF, and the second message contains at least key K AF Includes.

[0248] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0249] In some alternative embodiments of the present application, the first message includes the A-KID and / or the identifier of the AF.

[0250] In some alternative embodiments of the present application, the second message is: The aforementioned key K AF It further includes at least one of the following: validity period information, SUPI, or GPSI.

[0251] In the embodiments of the present invention, the third receiving unit 52 and the third transmitting unit 51 within the communication device can be realized in actual applications by being coupled with a communication assembly (including a basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna.

[0252] Embodiments of the present application further provide a communication device applicable to AUSF. Figure 20 is a schematic diagram showing the configuration of the communication device of an embodiment of the present application, and as shown in Figure 20, the device comprises a fourth receiving unit 61, the fourth receiving unit 61 is configured to acquire authentication-related information from a UDM, the authentication-related information includes at least one of third instruction information indicating that AKMA key material should be generated for a terminal, fourth instruction information indicating that AKMA key material should not be generated for a terminal, RID information of the terminal, and roaming information of the terminal.

[0253] In some alternative embodiments of the present application, the terminal roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0254] In some alternative embodiments of the present application, the communication device further comprises a fourth transmitting unit 62, the fourth transmitting unit 62 configured to transmit a third message to AAnF, the third message being for registering a key, the third message being A-KID, K AKMA This includes at least one of the following: SUPI, and the roaming information of the terminal.

[0255] In the embodiments of the present invention, the fourth receiving unit 61 and the fourth transmitting unit 62 within the communication device can be realized in actual applications by being coupled with a communication assembly (including a basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna.

[0256] Embodiments of the present application further provide a communication device applicable to a UDM. Figure 21 is a schematic diagram showing the configuration of the communication device of an embodiment of the present application, and as shown in Figure 21, the device comprises a fifth transmitting unit 71, the fifth transmitting unit 71 is configured to transmit authentication-related information to the AUSF, the authentication-related information includes at least one of third instruction information indicating that AKMA key material should be generated for the terminal, fourth instruction information indicating that AKMA key material should not be generated for the terminal, RID information of the terminal, and roaming information of the terminal.

[0257] In some alternative embodiments of the present application, the terminal roaming information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state; second instruction information indicating that the terminal is not in a roaming state; roaming destination information; contract information at the terminal's roaming destination; and policy information at the terminal's roaming destination.

[0258] In some alternative embodiments of the present invention, the communication device further comprises a fifth receiving unit 72, the fifth receiving unit 72 receiving a fourth message transmitted from AAnF, the fourth message being for requesting terminal roaming information, and The UDM is configured to perform the steps of sending a fifth message to the AAnF, wherein the fifth message includes roaming information of the terminal.

[0259] In the embodiments of the present invention, the fifth receiving unit 72 and the fifth transmitting unit 71 within the communication device can be realized in actual applications by being coupled with a communication assembly (including a basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna.

[0260] It should be explained that when the communication device provided in the above embodiment performs communication, only the division of each program module described above was used as an example. However, in actual application, the above processes may be assigned to different program modules as needed and completed; that is, the internal structure of the device can be divided into different program modules to complete all or part of the above processes. Furthermore, the communication device provided in the above embodiment belongs to the same concept as the embodiment of the communication method, and the specific implementation process can be found in the embodiment of the method, which will not be explained again here.

[0261] Embodiments of the present application further provide a communication device, which may be, for example, an AAnF, a first device, an AF, an AUSF, or a UDM. Figure 22 is a schematic diagram showing the hardware configuration of a communication device according to an embodiment of the present application, and as shown in Figure 22, the communication device comprises a memory 82, a processor 81, and a computer program stored in the memory 82 and executable by the processor 81, wherein the processor 81, when executing the program, implements steps of a communication method applicable to an AAnF according to an embodiment of the present application, or steps of a communication method applicable to a first device according to an embodiment of the present application, or steps of a communication method applicable to an AF according to an embodiment of the present application, or steps of a communication method applicable to an AUSF according to an embodiment of the present application, or steps of a communication method applicable to a UDM according to an embodiment of the present application.

[0262] Optionally, the communication device may further include one or more network interfaces 83. Here, each component within the communication device is coupled via a bus system 84. Understandably, the bus system 84 provides connectivity and communication between these components. In addition to the data bus, the bus system 84 includes a power bus, a control bus, and a status signal bus. However, for clarity, in Figure 22, all types of buses are represented as the bus system 84.

[0263] Understandably, memory 82 may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Here, non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM®), flash memory, magnetic memory, compact disk, or compact disc read-only memory (CD-ROM), and magnetic memory may be magnetic disk memory or magnetic tape memory. Volatile memory may be random access memory (RAM) used as an external cache.To the extent of illustrative but non-limiting examples, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synclink dynamic random access memory (SLDRAM), and direct memory bus random access memory (DRRAM). The memory 82 described in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.

[0264] The methods disclosed in the embodiments of this application may be applied to or implemented by a processor 81. The processor 81 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method may be completed by instructions in the form of integrated logic circuits or software in the processor 81. The processor 81 may be a general-purpose processor, a DSP, or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The processor 81 can implement or execute each method, step and logic block diagram disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application may be performed directly by a hardware decoding processor or by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in memory 82, and the processor 81 reads the information stored in memory 82 and combines it with its hardware to complete the steps of the above method.

[0265] In exemplary embodiments, the communication device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the above method.

[0266] In an exemplary embodiment, the embodiment of the present application further provides a computer-readable storage medium, such as memory 82 containing a computer program, the computer program being executed by a processor 81 of a communication device to complete the steps of the method described above. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic memory, optical disk, or CD-ROM, or it may be a variety of devices containing one or any combination of the above memories.

[0267] Embodiments of the present application further provide a computer-readable storage medium in which a computer program is stored, and when the program is executed by a processor, it implements steps of a communication method applicable to AAnF according to embodiments of the present application, or steps of a communication method applicable to a first device according to embodiments of the present application, or steps of a communication method applicable to AF according to embodiments of the present application, or steps of a communication method applicable to AUSF according to embodiments of the present application, or steps of a communication method applicable to UDM according to embodiments of the present application.

[0268] The methods disclosed in some embodiments of the methods provided herein can be arbitrarily combined without contradiction to obtain new embodiments of the methods.

[0269] The features disclosed in the embodiments of some of the products provided in this application can be arbitrarily combined without contradiction to obtain embodiments of new products.

[0270] The features disclosed in some of the embodiments of methods or apparatus provided herein can be arbitrarily combined without contradiction to obtain new embodiments of methods or apparatus.

[0271] In some embodiments provided herein, the disclosed devices and methods can be implemented in other ways. The embodiments of the devices described above are illustrative only, and for example, the division of the units is merely a division of logical functions, and in actual implementation, there may be other methods of division, for example, multiple units or components may be combined, integrated into another system, and some features may be ignored or not implemented. Furthermore, the interconnections, direct connections or communication connections between each illustrated or described component may be indirect connections or communication connections via several interfaces, devices or units, and may be in electrical, mechanical or other forms.

[0272] The units described as separation members may or may not be physically separated, and the members shown as units may or may not be physical units, and may be located in one place or distributed among multiple network units. Depending on the actual needs, some or all of these units can be selected to realize the objectives of the technical proposal of this embodiment.

[0273] Furthermore, each functional unit in each embodiment of the present invention may be integrated into a single second processing unit, each unit may be used individually as a single unit, or two or more units may be integrated into a single unit. The integrated unit can be embodied in the form of hardware, or in the form of a combination of hardware and software functional units.

[0274] Those skilled in the art will know that all or some of the steps of the embodiments of the above-described method can be completed by hardware relating to program instructions, the program can be stored in a computer-readable storage medium, and when the program is executed, the steps of the embodiments of the above-described method are performed, the storage medium includes various media capable of storing program code, such as removable storage, ROM, RAM, magnetic memory, or optical disks.

[0275] Alternatively, the integrated unit described above in the present application may be implemented in the form of a software function module and, if sold or used as an independent product, may be stored on a computer-readable storage medium. Based on this understanding, the essential parts of the technical solutions of the embodiments of the present application, i.e., the parts that contribute to the prior art, may be embodied in the form of a software product, the computer software product being stored on a storage medium and containing several instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The storage medium includes a variety of media capable of storing program code, such as removable storage, ROM, RAM, magnetic memory, or optical disks.

[0276] The above description is merely an embodiment of the present application, and the scope of protection of this application is not limited thereto. All modifications or substitutions that a person skilled in the art could easily conceive of within the technical scope disclosed herein should be included within the scope of protection of this application. Accordingly, the scope of protection of this application shall be subject to the scope of protection of the claims.

Claims

1. A method of communication, The steps include: an application authentication and key management (AKMA) anchor function (AAnF) receiving a first message sent from an application function (AF), or receiving a first message sent from an AF via a first device, wherein the first message contains key K AF The purpose is to obtain the first message which includes the AKMA key identifier (A-KID) and / or the identifier of the AF, If the AAnF checks that it can provide services to the AF, it sends a second message to the AF, or sends a second message to the AF via the first device, wherein the second message is at least key K AF Steps including, After receiving the first message, the communication method A communication method comprising the step of obtaining terminal roaming information from a UDM, wherein the AAnF is related to a terminal corresponding to the A-KID in the first message.

2. The AAnF is located on the home network (HPLMN), and / or the first device is located on the visiting network (VPLMN), and / or the AF is located on the visiting network (VPLMN), The second message is, The aforementioned key K AF Information on the validity period, Subscription Permanent Identifier (SUPI), Further including at least one of the General Public Subscription Identifiers (GPSIs), The communication method according to claim 1.

3. The aforementioned communication method is, The aforementioned AAnF is AKMA anchor key K AKMA Based on the key K AF The step further includes deriving the following: The communication method according to claim 1.

4. The aforementioned communication method is, The AAnF further includes the step of receiving a third message sent from the authentication server function (AUSF), the third message being for registering a key, and the third message being: A-KID, AKMA anchor key K AKMA , including at least one of SUPI and the roaming information of the terminal, The roaming information of the aforementioned terminal is: The information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state, second instruction information indicating that the terminal is not in a roaming state, roaming destination information, contract information at the terminal's roaming destination, and policy information at the terminal's roaming destination. The roaming information of the aforementioned terminal is obtained by the AUSF from Integrated Data Management (UDM). The roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal's SUPI. The communication method according to claim 1.

5. The step of checking whether the AAnF can provide service to the AF is: The step includes checking whether the AAnF can provide service to the AF based on the terminal's roaming information, The communication method according to claim 1 or 4.

6. The communication method is: The AAnF further includes the step of transmitting first information to the first device, wherein the first information includes AKMA context information. The communication method according to claim 1.

7. The first piece of information mentioned above is A-KID, AKMA anchor key K AKMA , including at least one of SUPI, The communication method according to claim 6.

8. A method of communication, The UDM includes the step of sending authentication-related information to the AUSF, wherein the authentication-related information is: The system includes at least one of the following: a third instruction information indicating that it is necessary to generate AKMA key material for the terminal; a fourth instruction information indicating that it is not necessary to generate AKMA key material for the terminal; the terminal's RID information; and the terminal's roaming information. The roaming information of the aforementioned terminal is: The information includes at least one of the following: first instruction information indicating that the terminal is in a roaming state, second instruction information indicating that the terminal is not in a roaming state, roaming destination information, contract information at the terminal's roaming destination, and policy information at the terminal's roaming destination. The aforementioned communication method is, The steps include: the UDM receiving a fourth message transmitted from the AAnF, the fourth message requesting roaming information for the terminal; A communication method further comprising the step of the UDM transmitting a fifth message to the AAnF, wherein the fifth message includes roaming information of the terminal.