Method and related apparatuses for key management
The method addresses the gap in 5G network key management by providing a service-based architecture for negotiating and managing security protection and key information, enhancing security and trustworthiness in network communications.
Patent Information
- Application Number
- PCT/CN2025/089131
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-10-23
- Filing Date
- 2025-04-15
- Publication Date
- 2026-04-30
AI Technical Summary
Existing API specifications in 5G networks fail to meet the requirements of future network capabilities, particularly in managing key information for security protection and communication between devices and network components, leading to gaps in privacy and trustworthiness.
A method for key management services that includes negotiating and managing various types of security protection, key levels, and expiration periods for communications between devices and network nodes, utilizing a service-based architecture to provide secure and trustworthy communication.
Enhances security and trustworthiness in network communications by effectively managing key information, ensuring secure interactions between devices and network components, and supporting advanced network functionalities like 6G systems.
Smart Images

Figure CN2025089131_30042026_PF_FP_ABST
Abstract
Description
METHOD AND RELATED APPARATUSES FOR KEY MANAGEMENTCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to US provisional patent application No. 63 / 710,902, filed on October 23, 2024, which is hereby incorporated by reference in its entirety.TECHNICAL FIELD
[0002] The present disclosure relates to the field of communication technologies, and in particular, to a method and related apparatuses for the management of keys for devices seeking to benefit from one or more services rendered by the network or by service providers.BACKGROUND
[0003] Many emerging trends are driving the consideration and design of wireless networks, such as 6G networks, including new network infrastructure capabilities, advances in maturing technologies, including large-scale Artificial Intelligence (AI) models, data de-privacy techniques, and blockchain, emerging applications and services, such as AI-driven solutions, data sensing services, and digital world services, and a shift towards global, open, and collaborative operations.
[0004] New expectations and stricter requirements on future networks also drive rethinking and development of a new generation of wireless networks. These requirements include privacy and trustworthiness, simplified standardization and rapid deployment.
[0005] In the fifth generation (5G) era, a new core network has been introduced by 3GPP, relying on an open and modular service platform, the Service-Based Architecture (SBA) . SBA provides a cloud-native service framework, in which mobile core network functionalities (authentication, mobility management, etc. ) are supported by network functions (NFs) . Service providers can provide services to any other authorized service consumer through Application Programming Interfaces (APIs) .
[0006] In this service framework, each NF can consume the services provided by other NFs and expose services as well. There can be a centralized repository, the Network Repository Function (NRF) , in which NFs can publish new services. The service information maintained in the NRF is accessible to all the NFs to enable service discovery. The consumer NFs can also retrieve required routing information from the NRF to interact with the service producer NFs.
[0007] To expose services to consumers, a service provider may describe its services using API specifications. For example, the OpenAPI specification provides a formal standard for describing HTTP APIs. An OpenAPI description allows both people and computers to discover and understand how an API works, including available resources and authorized operations on each resource, operation parameters, input and output for each operation, etc.
[0008] However, there are gaps between the requirements of future network capability descriptions and existing API specifications.
[0009] This background information is provided to reveal information believed by the applicant to be of possible relevance to the present disclosure. No admission is necessarily intended, nor should be construed, that any of the preceding information constitutes prior art against the present disclosure.SUMMARY
[0010] In a first aspect, a method performed at a first node for providing a key management service is provided. The method comprises receiving, from a device, a request which includes identification information of the device and a request to negotiate key management information between the device and the first node, transmitting the key management information to the device, and receiving negotiation results from the device, wherein the negotiation results comprise a selection of one or more key information items from the key management information received from the first node. The one or more key information items include at least one of one or more types of security protection, one or more levels related to one or more keys, respective expiration periods related to the one or more keys, and respective identifiers of a plurality of protection algorithms.
[0011] In possible implementations, the types of security protection may include session protection between the device and a gateway, radio bearer protection between the device and a radio bearer handler, and end-to-end (E2E) protection between the device and a second node configured to provide one or more services to the device.
[0012] In possible implementations, the gateway may be a control and management plane gateway or a data plane gateway.
[0013] In possible implementations, the one or more levels related to the one or more keys may include a key per device, a key per session, a key per end-to-end (E2E) connection, a key per service, a key per application, or a key per radio access network (RAN) .
[0014] In possible implementations, the plurality of protection algorithms may include encryption algorithms and / or integrity preservation algorithms.
[0015] In possible implementations, for execution of the method, the first node has a subscription of the device to a basic service or has received an update of the selection of the one or more key information items by the device.
[0016] In possible implementations, after the execution of the method, a subscription of the device to the key management service is complete.
[0017] In possible implementations, the first node creates or updates a security profile associated with the device, based on the selection of the one or more key information items by the device.
[0018] In possible implementations, the method constitutes an action to subscribe the device to the key management service, the action being called by a third node which provides autonomous services.
[0019] In a second aspect, a method performed at a first node for providing a key management service is provided. The method comprises transmitting a session key message to a second node. The session key message includes session key management information for protecting communications between a device and the second node. The session key management information in the session key message comprising at least one of an identifier of the device, one or more types of session security protection, one or more levels related to one or more session keys, respective expiration periods related to the one or more session keys, one or more types of the one or more session keys, and an identifier of a root key.
[0020] In possible implementations, the one or more types of security protection may indicate whether the protection is applied to communications between the device and a control and management plane gateway and / or to communications between the device and a data plane gateway.
[0021] In possible implementations, the one or more levels related to the one or more session keys may correspond to a session key per device, a session key per session, a session key per service, or a session key per application.
[0022] In possible implementations, the one or more session keys may include a key for encrypting or decrypting session communications on the control and management plane, a key for encrypting or decrypting session communications on the data plane, a key for protecting the integrity of session communications on the control and management plane, and a key for protecting the integrity of session communications on the data plane.
[0023] In possible implementations, for execution of the method, the first node has established a security profile for the device, which comprises one or more key information items selected by the device for protecting session communications between the device and a control and management (C / M) plane gateway and / or session communications between the device and a data plane (DP) gateway.
[0024] In possible implementations, for execution of the method, mutual authentication between the device and the first node has been performed, and the first node has the root key.
[0025] In possible implementations, after execution of the method, the session key management information related to the key management service has been provided to the second node.
[0026] In possible implementations, the first node performs the method when one or more key information items selected by the device for protecting communications at the session level between the device and the second node have been updated.
[0027] In possible implementations, the second node is a node that controls control and management (C / M) gateways and / or data plane (DP) gateways of the network.
[0028] In possible implementations, the method constitutes an action to provide the session key management information to the second node, the action being called by a third node that provides autonomous services.
[0029] In a third aspect, a method performed at a first node for providing a key management service is provided. The method comprises transmitting a session key message to a device, wherein the session key message includes one or more session key parameters for protecting communications between the device and a second node at a session level and an identifier of a root key, wherein the one or more session key parameters enable the device to generate one or more session keys.
[0030] In possible implementations, the first node has access to a security profile of the device, which comprises an identifier of the device for communicating with the device and session protection information indicating whether the device requires security protection on communications between the device and a control and management (C / M) plane gateway and / or a data plane (DP) gateway.
[0031] In possible implementations, the one or more session key parameters may include at least one of a sequence number (SQN) , a scramble operation (XOR) , an encryption algorithm identifier for protecting communications occurring on a control and management (C / M) plane session, an integrity algorithm identifier for protecting communications occurring on a control and management plane session, a C / M gateway identifier, a session downlink count, a data plane (DP) gateway identifier, an encryption algorithm identifier for protecting communications occurring on a data session, an integrity algorithm identifier for protecting communications occurring on a data session, and a service identifier.
[0032] In possible implementations, for execution of the method, mutual authentication between the device and the first node has been performed, and both the first node and the device have the root key.
[0033] In possible implementations, after the execution of the method, the one or more session key parameters have been provided to the device.
[0034] In possible implementations, the first node performs the method when one or more key information items selected by the device for protecting communications at the session level between the device and the second node have been updated.
[0035] In possible implementations, the second node is a node that controls the control and management (C / M) gateways and / or data plane (DP) gateways of the network.
[0036] In possible implementations, the method constitutes an action to provide the one or more session key parameters to the device, the action being called by a third node that provides autonomous services.
[0037] In a fourth aspect, a method performed at a first node for providing a key management service is provided. The method comprises transmitting a radio bearer (RB) key message to an RB handler. The RB key message includes RB key management information for protecting communications on an RB interface between a device and the RB handler. The RB key management information in the RB key message comprises at least one of: an identifier of the device, one or more types of RB security protection, one or more levels related to one or more RB keys, respective expiration periods related to the one or more RB keys, one or more types of the one or more RB keys, and an identifier of a root key.
[0038] In possible implementations, the one or more types of RB security protection may indicate whether the protection is applied to communications between the device and the RB handler for signalling messages on a control and management plane and / or to communications between the device and the RB handler for data on a data plane.
[0039] In possible implementations, the one or more levels related to the one or more RB keys may correspond to at least one of an RB key per device, an RB key per Radio Access Network (RAN) node, an RB key per service, or an RB key per application.
[0040] In possible implementations, the one or more RB keys may include a key for encrypting or decrypting RB communications on the control and management (C / M) plane, a key for encrypting or decrypting RB communications on the data plane, a key for protecting the integrity of RB communications on the control and management plane, and a key for protecting the integrity of RB communications on the data plane.
[0041] In possible implementations, for execution of the method, the first node has established a security profile for the device, which comprises one or more key information items selected by the device for protecting communications between the device and the RB handler on the control and management (C / M) plane and / or the data plane (DP) .
[0042] In possible implementations, prior to transmitting the RB key message, mutual authentication between the device and the first node has been performed, and the first node has the root key.
[0043] In possible implementations, after the execution of the method, the one or more RB keys have been provided to the RB handler.
[0044] In possible implementations, the first node performs the method when one or more key information items selected by the device for protecting communications between the device and the RB handler have been updated.
[0045] In possible implementations, the method constitutes an action to provide the one or more RB keys to the RB handler, the action being called by a third node that provides autonomous services.
[0046] In a fifth aspect, a method performed at a first node for providing a key management service is provided. The method comprises transmitting a radio bearer (RB) key message to a device, wherein the RB key message includes one or more RB key parameters for protecting communications between the device and a radio bearer (RB) handler, and an identifier of a root key. The one or more RB key parameters enable the device to generate one or more RB keys.
[0047] In possible implementations, the first node has established a security profile of the device, which comprises an identifier of the device for communicating with the device and RB protection information indicating whether the device requires security protection on communications with the RB handler for signalling messages on a control and management (C / M) plane and / or for data on a data plane (DP) .
[0048] In possible implementations, the one or more RB key parameters may include at least one of a sequence number (SQN) , a scramble operation (XOR) , an encryption algorithm identifier for protecting communications occurring on the control and management plane of the RB, an integrity algorithm identifier for protecting communications on the control and management plane of the RB, an uplink session count, a Physical Cell Identifier (PCI) , a Next Hop (NH) , an encryption algorithm identifier for protecting communications on the data plane of the RB, an integrity preservation algorithm identifier for protecting communications on the data plane of the RB, a service identifier, and an application identifier.
[0049] In possible implementations, for execution of the method, mutual authentication between the device and the first node has been performed, and both the first node and the device have the root key.
[0050] In possible implementations, after the execution of the method, the one or more RB key parameters have been provided to the device.
[0051] In possible implementations, the first node performs the method when one or more key information items selected by the device for protecting communications between the device and the RB handler have been updated.
[0052] In possible implementations, the method constitutes an action to provide the one or more RB key parameters to the device, the action being called by a third node that provides autonomous services.
[0053] In a sixth aspect, a method performed at a first node for providing a key management service is provided. The method comprises transmitting an end-to-end (E2E) key message to a service provider node, wherein the E2E key message includes E2E key management information for protecting end-to-end communications between a device and the service provider node. The E2E key management information in the E2E key message comprises at least one of: an identifier of the device, one or more types of E2E security protection, one or more levels related to one or more E2E keys, respective expiration periods related to the one or more E2E keys, one or more types of the one or more E2E keys, and an identifier of a root key.
[0054] In possible implementations, the one or more types of E2E security protection may indicate whether the protection is applied to communications between the device and the service provider node for signalling messages on a control and management (C / M) plane and / or for data on a data plane.
[0055] In possible implementations, the one or more levels related to the one or more E2E keys may correspond to an E2E key per device, an E2E key per session, an E2E key per service, or an E2E key per application.
[0056] In possible implementations, the one or more E2E keys may include a key for encrypting or decrypting end-to-end communications between the device and the service provider node on the control and management plane, a key for encrypting or decrypting end-to-end communications between the device and the service provider node on the data plane, a key for protecting the integrity of end-to-end communications between the device and the service provider node on the control and management plane, and a key for protecting the integrity of end-to-end communications between the device and the service provider node on the data plane.
[0057] In possible implementations, for execution of the method, mutual authentication between the device and the first node has been performed, and the first node has the root key.
[0058] In possible implementations, the first node performs the method when one or more key information items selected by the device for protecting communications between the device and the service provider node have been updated.
[0059] In possible implementations, the method constitutes an action to provide the one or more E2E key parameters to the service provider node, the action being called by a third node that provides autonomous services.
[0060] In a seventh aspect, a method performed at a first node for providing a key management service is provided. The method comprises transmitting an end-to-end (E2E) key message to a device, wherein the E2E key message includes one or more E2E key parameters and an identifier of a root key, wherein the one or more E2E key parameters are used for protecting end-to-end communications associated with an E2E connection between the device and a service provider node and the one or more E2E key parameters enable the device to generate one or more E2E key.
[0061] In possible implementations, the first node has established a security profile of the device, which comprises an identifier of the device for communicating with the device and E2E protection information indicating whether the device requires security protection on communications with the service provider node for signalling messages on a control and management (C / M) plane and / or for data on a data plane (DP) .
[0062] In possible implementations, the one or more E2E key parameters may include at least one of a sequence number (SQN) , a scramble operation (XOR) , an encryption algorithm identifier for protecting communications occurring on a control and management plane of the E2E connection, an integrity algorithm identifier for protecting communications occurring on a control and management plane of the E2E connection, an identifier of the service provider node, an encryption algorithm identifier for protecting communications occurring on a data plane of the E2E connection, an integrity algorithm identifier for protecting communications occurring on a data plane of the E2E connection, a service identifier, and an identifier of the E2E connection.
[0063] In possible implementations, for execution of the method, mutual authentication between the device and the first node has been performed, and both the device and the first node have the root key.
[0064] In possible implementations, the first node performs the method when one or more key information items selected by the device for protecting the E2E communications between the device and the service provider node have been updated.
[0065] In possible implementations, the method constitutes an action to provide the one or more E2E key parameters to the device, the action being called by a third node that provides autonomous services.
[0066] In another aspect, an apparatus is provided, being configured to perform any of the methods described in the previous aspects. The apparatus comprises one or more processors and one or more memories storing instructions which, when executed by the one or more processors, cause the apparatus to perform the method according to any of the implementations described above.
[0067] In another aspect, a computer-readable medium is provided, storing computer execution instructions which, when executed by a processor, cause the processor to execute any of the methods described in the previous aspects.
[0068] In another aspect, a computer program product is provided, comprising program code for performing any of the methods described in the previous aspects.
[0069] In another aspect, a computer program is provided, comprising computer execution instructions which, when executed by a processor, cause the processor to execute any of the methods described in the previous aspects.
[0070] In another aspect, a chip is provided, comprising an input / output (I / O) interface and a processor, wherein the processor is configured to call and run a computer program stored in a memory, to enable a device installing the chip to perform any of the methods described in the previous aspects.BRIEF DESCRIPTION OF THE DRAWINGS
[0071] The accompanying drawings are used to provide a further understanding of the present disclosure, constitute a part of the specification, and are used to explain the present disclosure together with the following specific embodiments, but should not be construed as limiting the present disclosure.
[0072] FIG. 1 shows a simplified schematic illustration of a 6G system conceptual structure according to one or more example implementation of the present disclosure.
[0073] FIG. 2A shows a simplified schematic illustration of an example of an apparatus in a communication system according to one or more example implementation of the present disclosure.
[0074] FIG. 2B shows connections related to a wireless device in a communication system according to one or more example implementation of the present disclosure.
[0075] FIG. 3 shows a schematic flowchart of a method, according to one or more embodiments of the present disclosure, for negotiating key management information.
[0076] FIG. 4 shows a schematic flowchart of another method according to one or more embodiments of the present disclosure, for transmitting a session key message to a second node.
[0077] FIG. 5 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure, for transmitting a session key message to a device.
[0078] FIG. 6 shows a schematic flowchart of yet another method, according to one or more embodiments of the present disclosure, for transmitting a radio bearer (RB) key message to an RB handler.
[0079] FIG. 7 shows a schematic flowchart of yet another method, according to one or more embodiments of the present disclosure, for transmitting a radio bearer (RB) key message to a device.
[0080] FIG. 8 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure, for transmitting an end-to-end (E2E) key message to a service provider node.
[0081] FIG. 9 shows a schematic flowchart of yet another method according to one or more embodiments of the present disclosure, transmits an end-to-end (E2E) key message to a device.
[0082] FIG. 10 shows a block diagram of an example of a procedure of session key configuration.
[0083] FIG. 11 shows a block diagram of an apparatus according to one or more embodiments of the present disclosure.
[0084] FIG. 12 shows a block diagram of another apparatus according to one or more embodiments of the present disclosure.
[0085] FIG. 13 shows a schematic structural diagram of a communication apparatus according to one or more embodiments of the present disclosure.
[0086] FIG. 14 shows a schematic diagram of an architecture of a computing device cluster according to one or more embodiments of the present disclosure.
[0087] FIG. 15 shows a schematic diagram of a connection between computing devices over a network according to one or more embodiments of the present disclosure.DETAILED DESCRIPTION
[0088] In the following description, reference is made to the accompanying figures, which form part of the present disclosure, and which show, by way of illustration, specific aspects of embodiments of the present disclosure or specific aspects in which embodiments of the present disclosure may be used. It is understood that embodiments of the present disclosure may be used in other aspects and include structural or logical changes not depicted in the figures. The following detailed description, therefore, is not to be taken in a limiting sense, and the scope of the present disclosure is defined by the appended claims.
[0089] The solution described in the present disclosure is applicable to a next generation (e.g., sixth generation (6G) or later) network, or a legacy (e.g. 5G or 4G) network.
[0090] The proposed 6G System architecture is defined to support 6G ‘X’a s a service (XaaS) or anything-as-a-service (XaaS) services by using techniques such as Network Function Virtualization and Network Slicing. The 6G System architecture utilizes service-based interactions between 6G services.
[0091] The 6G System leverages service-based architecture and the XaaS concept. XaaS services in the 6G System are categorized into three layers. The 6G System conceptual structure is shown in FIG. 1.
[0092] Infrastructure Layer includes infrastructures supporting 6G services. Among them are wireless networks (radio access network (RAN) , core network (CN) ) infrastructures, Cloud / data center infrastructures, satellite networks, storage / database infrastructures, and sensing networks, etc. These infrastructures can be provided by a single provider or by multiple providers. As shown in FIG. 1, each of the infrastructures on the infrastructure Layer could have its control and management functions, denoted as C / M functions, for infrastructure management. Each of these infrastructures is one type of Infrastructure as a Service.
[0093] Control and Management (C / M) layer includes control and management services of the 6G System. They are developed and deployed by using slicing techniques and utilizing resource provided by infrastructure layer. 6G services in Control and Management (C / M) layer are: -Resource Management (RM) as a Service provides a capability of life-cycle management of a variety of slices and over-the-air resource assignment to wireless devices. -A 6G mission is defined as a service provided to customers by the 6G System. A mission can be a type of service which is provided by a single 6G XaaS service or a type of service that needs contributions from multiple XaaS services. -Mission Management (MM) as a Service provides a capability to program provisioning of XaaS services at Service Layer to provide mission services. -Confederation Network (CONET) as a Service provides a capability to enable multiple partners jointly provide 6G services. This capability is provided by confederation formation, mutual authentication, mutual authorization among partners and negotiation of agreement on recording and retracing of selected actions performed by partners, in order to assure a trustworthy environment of 6G System operations. -Service Provisioning Management (SPM) as a Service provides a capability of control and management of 6G service access by customers and provisioning of requested services. The capability is provided by unified mutual authentication, authorization and policy, key management, QoS assurance and charging between any pair of XaaS service provider and customer. The customers include end-customers not only in physical world, but also digital representatives in digital world. -Connectivity Management (CM) as a Service leverages 5G connectivity management functions, but with extension to include digital world. -Protocol as a Service provides a capability to design service customized protocol stacks for identified interfaces. -The protocol stacks could be pre-defined for on-demand selection, or could be on-demand designed. -Network Security as a Service provides a capability for owners of infrastructures to detect potential security risks of their infrastructures. -XaaS services in C / M Layer support control and management of the 6G System itself and also provide support to verticals if requested. One example is that RM service can serve RAN for over-the-air resource management and can also provide service to a vertical for the vertical’s over-the-air resource allocation to its end-customers. The XaaS in C / M layer can be deployed by using slicing technique.
[0094] Service Layer includes 6G services which provide services to customers. In the 6G System conceptual structure: -AI service is denoted as NET4AI as a Service. Artificial Intelligence service provides AI capability to support a variety of AI applications. -Service of data collection, data sanitization, data analysis and data delivery are denoted as DAM as a Service, this service provides a capability of lifecycle management of statistic data, including acquisition, de-privatization, analysis and delivery of data which are information statistic data from any types of sensors, devices, network functions, etc. -Service of storage and sharing of data is denoted as NET4Data as a Service, this service provides a trustworthy capability to store and share data under the control of owners of data and following recognized authorities’ regulations on control of identified data. -Service to provide digital world is denoted as NET4DW as a Service, Digital World service provides a capability to construct, control and manage digital world. Digital world is defined as digital realization of physical world. -6G block chain service is denoted as NET4BC as a Service. 6G connectivity service is denoted as NET4Con as a Service. This service provides a capability to support 6G block chain services. -Enhanced connectivity service, e.g., network for connectivity (NET4CON) as a service. This service provides a capability to support the exchange of messages and data among new 6G services.
[0095] All XaaS services at this Layer are developed and deployed by using resources provided in infrastructure and utilizing Network Function Virtualization and Slicing techniques. The capability of each of 6G services is provided by its control and management functions and service-specific data process functions.
[0096] In addition to supporting 6G XaaS services at Service Layer, 6G System leverages 5G System for provisioning of vertical services. The difference between 6G XaaS services and other verticals are that a vertical is a pure customer who needs other XaaS services to enable its operation, while each of XaaS services provide their capabilities to 6G customers.
[0097] Any pair of XaaS services of the 6G System could also be mutual customer and provider of each other. Some examples are that an infrastructure owner provides its resource to XaaS services in Service Layer and C / M Layer; RM services may need the capabilities provided by NET4AI, DAM and NET4DW for its resource management for vertical slicing; CONET service and NET4Data service may need the capability provided by NET4BC for their operation.
[0098] Concepts of a 6G Systems includes: -Define Basic XaaS Services by decoupling comprehensive types of services into basic XaaS services. A basic XaaS service provides unique capability to enable a specific type of service, such as NET4AI service, NET4DW service, DAM service, NET4Data service, Block chain service, mission management service, etc. -Allow joint operation of the 6G System by multiple partners. -Define Data Plane of the 6G System which includes processing functions of data plane of XaaS services. Programing the interconnection of these functions, by mission management service, enables them to support a variety of customized customer services. -Simplify 6G System architecture by categorizing basic control services and management services and combining them as basic XaaS services in Control and Management (C / M) Layer. -Define C / M Plane of the 6G System which includes C / M functions in XaaS services and may include 5G CP (e.g., AMF) depending on implementation options. -Define Basic Architecture Structure (BAS) which is a unified basic structure with minimized number of interfaces and is independent of types of infrastructures. -Simplify standardization, development and deployment of the 6G System using the BAS concept, while supporting a variety of infrastructure deployment scenarios. -Adapt to a variety of deployment scenarios by applying the BAS or a subset of it to infrastructures based on capability, capacity and requirement of the infrastructure networks. -Leverage SBI interface concept and apply SBI interaction in both 6G C / M plane and 6G data plane. -Simplify SBI interfaces by introducing trustworthy (TW) GWs in Data Plane and C / M Plane of the 6G System. -Improve trustworthiness from perspectives of operation of the 6G System by introducing CONET capability, NET4BC capability and anonymous service provisioning provided by the trustworthy GWs in the C / M plane and data plane of the 6G System. -Improve trustworthiness from perspective of end customer privacy protection by unified mutual authentication, IDM, data sanitization etc. provided by SPM service, DAM service and 6G Block Chain service. -Simplify roaming management of wireless devices, in the physical world and digital world, by unified authentication including all participated partners and customers. -Support multiple development paths from 5G System to 6G System by defining multiple architecture options without incurring many efforts due to the introduction of the BAS concept. -Support backward compatibility by utilizing the benefits of SBA and its add-on feature. 5G users can use the 6G System to access 5G services. -Support future extension by adding new XaaS services with minimized impact on standardization and deployment, due to the introduced anonymous service provisioning concept implemented in trustworthy GWs in 6G C / M plane and in 6G data plane.
[0099] In the present disclosure, the 6G customer can be of various types, including a device (e.g., electronic device ED, terminal device) , apparatus, a chip, an equipment (e.g., user equipment) etc. For example, the customer may be an individual customer, a business customer, etc. The 6G customer is used to connect persons, objects, machines, etc. The 6G customer may be widely used in various scenarios including, for example, cellular communications, device-to-device (D2D) , vehicle to everything (V2X) , peer-to-peer (P2P) , machine-to-machine (M2M) , MTC, internet of things (IoT) , virtual reality (VR) , augmented reality (AR) , mixed reality (MR) , metaverse, digital twin, industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and mobility, etc.
[0100] Each 6G customer represents any suitable end user device for wireless operation and may include such devices (or may be referred to but not limited to) as a user equipment (UE) or a user device or a terminal device, a wireless transmit / receive unit (WTRU) , a mobile station, a fixed or mobile subscriber unit, a cellular telephone, a station (STA) , a MTC device, a personal digital assistant (PDA) , a smartphone, a laptop, a computer, a tablet, a wireless sensor, a consumer electronics device, a smart book, a vehicle, a car, a truck, a bus, a train, or an IoT device, wearable devices (such as a watch, a pair of glasses, head mounted equipment, etc. ) , an industrial device, or an apparatus in (e.g., module, modem, or chip) or comprising the forgoing devices, among other possibilities. Future generation 6G customer may be referred to using other terms. When a 6G customer performs (or is configured to perform) a method described herein, it may be interpreted as the ED, one or more module (or units) in the ED, a circuit or chip, or a combination thereof, may perform the method. For example, the circuit or chip may include a modem chip, also referred to as a baseband chip, a system on chip (SoC) including a modem core, or system in packages (SIP) ) , and the like, and may be responsible for one or more communication functions in the ED.
[0101] FIG. 2A shows a simplified schematic illustration of a deployment of a 6G system according to one or more example implementations of the present disclosure. In more detail, FIG. 2A illustrates an example of an apparatus 320 in a communication system (e.g., the 6G system) . The apparatus 320 may be a device (e.g., a device representing the customer) , a network node such as RAN, any components in RAN, CN or any Network Function in the 6G service of the present disclosure, or an apparatus includes one or more of the network functions (as mentioned above) . As shown in FIG. 2, the apparatus 320 may include at least one processor 260. Only one processor 260 is illustrated to avoid congestion in the drawing. The processor 260 may perform (or control the apparatus 320 to perform) operations (or methods) described herein as being performed by the apparatus 320.
[0102] When the apparatus is RAN, components of the RAN or the apparatus is the UE, the apparatus 320 may further include a transmitter 252 and a receiver 254 coupled to one or more antennas. One, some, or all of the antennas may alternatively be panels. The transmitter 201 and the receiver 203 may be integrated, e.g., as a transceiver. The transceiver is configured to modulate data or other content for transmission by at least one antenna or network interface controller (NIC) . The transceiver is also configured to demodulate data or other content received by the at least one antenna. Each transceiver includes any suitable structure for generating signals for wireless or wired transmission and / or processing signals received wirelessly or by wire. Each antenna includes any suitable structure for transmitting and / or receiving wireless or wired signals. In present disclosure, the transceiver (or transmitter 252 and / or receiver 254) may be viewed as an interface circuit.
[0103] The apparatus 320 may include at least one memory 258. The memory 258 stores instructions used to perform operations described herein. The memory 258 may also store data used, generated, or collected by the apparatus 320. For example, the memory 258 could store software instructions or modules configured to implement some or all of the functionality and / or embodiments described herein and that are executed by one or more processor 260.
[0104] For ease of understanding, different connections related to the device will be described in the first place. As shown in FIG. 2B, the device would be connected to its serving gateways, including a C / M gateway shown as C / M-TW-GW-1 and a data gateway shown as Data-TW-GW-1, it should be noted that although C / M-TW-GW-1 and Data-TW-GW-1 are shown as being deployed on the infrastructure of CN (e.g., CN infrastructure as shown in FIG. 1) , they could also be deployed on other infrastructures, such as RAN infrastructure, which is not limited in the embodiments of the present disclosure.
[0105] The connections related to the device may include but are not limited to following: 1) Device CN-C / M RB: an RB between a wireless device and its serving RAN (Cell, RB handler) that carries C / M session traffic; 2) Device CN-data RB: an RB between a wireless device and its serving RAN (Cell, RB handler) that carries data session traffic; 3) Device RAN-C / M RB: an RB between a wireless device and its serving RAN that carries RAN related C / M traffic; 4) Device RAN-data RB: an RB between a wireless device and its serving RAN that carries RAN related data traffic; 5) Device data session: a logical connection between a device and its serving Data-TW-GW, e.g., Data-TW-GW-1; 6) Device C / M session: a logical connection between a device and its serving C / M-TW-GW, e.g., C / M-TW-GW-1; 7) Device-NC connection: a logical connection between a device and a Network Capability (NC) (C / M NC or data NC) . The connection carries data / information traffic; the connection would be a downlink connection or an uplink connection; 8) Device-ext (external) connection: a logical connection between a device and an entity, e.g., server, located in external networks. A GW that has connection with external networks is an ext-Data-TW-GW or an ext-C / M-TW-GW, e.g., C / M-TW-GW-2 and Data-TW-GW-2 in this figure. Network needs to establish a tunnel between the device and an ext-GW to support a device-ext connection.
[0106] In 6G system, both new 6G XaaS services and network C / M XaaS services are categorized as basic XaaS services, a XaaS service (which is also referred to as service herein) is defined as a NC. The NCs at the C / M layer may be referred to as C / M NCs, and the NCs at the service layer may be referred to as data NCs.
[0107] There would be downlink and uplink RBs, downlink and uplink sessions, downlink and uplink device-NC connections, which are not shown in details.
[0108] With respect to the RBs between the device and the RAN shown in FIG. 2B, the RBs generally include device CN RB and device RAN RB. The device CN RB includes the above device CN-C / M RB and device CN-data RB, and the device RAN RB includes the above device RAN-C / M RB and device RAN-data RB. From the perspective of directions, the RB may be a downlink RB from RAN to a wireless device or an uplink RB from the wireless device to RAN, so the RB can be of a downlink type or an uplink type, the downlink and uplink RB may be referred to as a pair of RB; from the perspective of traffic types, the RB could be a C / M RB for carrying control signalling traffic on the C / M plane or a data RB for carrying data traffic on the data plane, so the RB can be of a C / M type or a data type; from the perspective of traffic destinations, the RB could be called a RAN-RB or a CN-RB, the RAN-RB is a RB that carries signalling messages or data traffic between a wireless device and RAN, the CN-RB is a RB that carries signalling messages or data traffic between a device and core network (CN) on the over-the-air interface, so in this case, the RB can be of a RAN-RB type or a CN-RB type. When combining the above different perspectives, different RBs may be downlink / uplink RAN-C / M RB (RAN-RB for carrying signalling messages on the C / M plane) , downlink / uplink RAN-data RB (RAN-RB for carrying data traffic on the data plane) , downlink / uplink CN-C / M RB (CN-RB for carrying signalling messages on the C / M plane) , downlink / uplink CN-data RB (CN-RB for carrying data traffic on the data plane) . That is, a RAN-RB may be an uplink / downlink RAN-C / M RB or RAN-data RB, a CN-RB could be an uplink / downlink CN C / M RB or CN-data RB; a C / M RB could be an uplink / downlink RAN-C / M RB or uplink / downlink CN-C / M RB, a data RB could be an uplink / downlink RAN-data RB or uplink / downlink CN-data RB.
[0109] With respect to the session related to a wireless device, from the perspective of traffic types, the session could be a C / M session which is a logical connection between a wireless device and its serving C / M-TW-GW for control signalling exchanging therebetween on the C / M plane, or a data session which is a logical connection between a device and its serving data-TW-GW for data exchanging therebetween on the data plane, so the session can be of a C / M type or a data type; from the perspective of directions, the session may be a downlink session from a serving GW (serving C / M-TW-GW or serving data-TW-GW) to a wireless device or an uplink session from the wireless device to the serving GW, so the session can be of a downlink type or an uplink type, the downlink and uplink sessions may be referred to as a pair of session. When combining the above different perspectives, different sessions may be downlink / uplink C / M session (C / M session for control signalling exchanging therebetween on the C / M plane) , or downlink / uplink data session (data session for data exchanging therebetween on the data plane) . That is, a session may be an uplink / downlink C / M session or data session.
[0110] With respect to the NC connection between a wireless device and a NC, from the perspective of traffic types, the NC connection could be a C / M NC connection which is a logical connection between a wireless device and a C / M entity of the NC, or a data NC connection which is a logical connection between the wireless device and a data entity of the NC, so the NC connection can be of a C / M type or a data type; from the perspective of directions, the NC connection may be a downlink NC connection from a entity (C / M entity or data entity) of the NC to a wireless device or an uplink NC connection from the wireless device to the entity, so the NC connection can be of a downlink type or an uplink type, the downlink and uplink NC connections may be referred to as a pair of NC connections. When combining the above different perspectives, different NC connections may be downlink / uplink C / M NC connections, or downlink / uplink data NC connections. That is, a NC connection may be an uplink / downlink C / M NC connection or a data NC connection.
[0111] As described above, both new 6G XaaS services and network C / M XaaS services are categorized as basic XaaS services, a XaaS service is defined as a NC. Each of these NCs can provide a single or a group of specific capabilities to enable 6G system control and management and 6G service provisioning, an NC can provide one or more sub-services, each sub-service being enabled by one or more basic network capabilities, i.e., actions. Each basic network capability or action could be described in a consistent format, and could be AI / LLM (large language model) friendly (for AI enabled full automation) , such a consistent format is defined as a network capability description language (NCDL) . In a possible implementation, a XaaS service can be implemented / achieved through execution of one or more actions corresponding to the XaaS service, the one or more actions are used for reflecting one or more capabilities for implementing a requirement of the service, the one or more actions may correspond to the one or more capabilities one-by-one, or a combination of multiple actions may correspond to one capability. Taking a case where the XaaS service is NET4AI service as an example, NET4AI service can provide AI-related services to 6G customers or to other NCs. These AI-related services can be enabled by its inference capability or sub-service, training capability or sub-service, and model management capability or sub-service. That is, the requirement for NET4AI service can include but is not limited to: a training requirement, an inference requirement, a model management requirement which can be related to storing of a model or a library related to provision of NET4AI service, enhancement / improvement of the model, or the like; for the training requirement, and there could be multiple algorithms / schemes such as algorithm / scheme A, algorithm / scheme B and algorithm / scheme C for implementing the training requirement, then the multiple algorithms / schemes can be regarded as multiple actions corresponding to NET4AI service. It should be noted that here the algorithm / scheme is just an implementation of the action, the action of a service may be characterized in other forms, which are not limited in the implementations of the present disclosure. For the purposes of this disclosure, a network capability (NC) may encompass one or more services related to a common purpose, such as providing connectivity, making predictions using AI models, or maintaining decentralized ledgers with blockchains, as examples. Accordingly, the terms "network capability" and "service" may be used interchangeably. A network capability provider, or service provider, refers to an entity comprising both physical and logical components that deliver services to other entities, whether users or other services.
[0112] The NCDL defines a language which could be understandable by both parties, i.e., a first NC calling the action and a second NC executing the action called by the first NC. The actions may be classified into different types as follows: Type 1: In-out-action: when being called, action codes are run based on input and produce output. (Input-> action-> output) ; Type 2: In–action: when being called, action codes are run based on input and local configuration / update is then conducted (input->action-> local update) ; Type 3: Out-action: when a local condition (triggering condition) is met, action codes are run to provide output (local ->action->output) .
[0113] For Type 1 action and Type 2 action, the first NC calls an action to be performed by the second NC, the first NC provides an NCDL input to the second NC. The NCDL input follows a certain agreement for the second NC to correctly recognize the NCDL input and execute the action. For Type 1 action, the second NC provides an NCDL output corresponding to the NCDL input. This NCDL output may be provided to the first NC, or to other NC (s) , which is not limited in the embodiments of the present disclosure. For Type 2 action, the second NC performs a local configuration update based on the NCDL input, and no NCDL output is transmitted.
[0114] For Type 3 action, there is no NCDL input, and when a local condition (triggering condition) is met, the second NC automatically executes the operation associated with the action and provides an NCDL output to the first NC which subscribes to this action.
[0115] For an NCDL of a C / M NC, the input dimensions (NCDL input) can include one or multiple input information without defining corresponding input information format; for an NCDL of a data NC, this dimension can include one or multiple input data dimensions along with the definition of corresponding input data format.
[0116] For an NCDL of a C / M NC, the input dimensions (NCDL input) can include one or multiple input information without defining corresponding input information format; for an NCDL of a data NC, this dimension can include one or multiple input data dimensions along with the definition of corresponding input data format.
[0117] Before discussing in greater detail, the objectives of the various embodiments of the invention, the problems they solve, and how they operate, definitions of concepts to which we will refer in the remainder of the disclosure are presented below.
[0118] As explained in the previous paragraphs, a Network Capability (NC) can refer to a XaaS (Anything as a Service) provided by a 6G system. A NC can encompass one or more services with a common purpose or function. A NC may also be called a service. NCs can be provided by NC providers, which manage and operate different physical and / or logical components, collectively called “nodes” , to render the services supported by a NC.
[0119] A node may comprise one or more processors; and one or more tangible, non-transitory memories. A network node may refer to any device or point within a communication network that can send, receive, process or forward data. Network nodes may include devices such as computers to more complex equipment such as routers, switches, and servers. A node can also be a virtual entity, implemented by logical functions, command blocks and / or software modules.
[0120] Action (provided by an NC) : The functionalities of an NC provider can be supported by one or multiple operations. Each of the operations is defined as an action provided by the NC. An “action” may be defined as a set of code executed by a network capability (NC) provider to deliver a specific function to a customer, via his / her devices. An action may require agreed-upon parameters, including input and output formats, and operational rules. Actions can be negotiable, where customers or clients select, via their devices, from available options, or non-negotiable, where the provider defines all parameters. Actions can be triggered on-call when explicitly requested or autonomously when predefined conditions are met. Depending on execution, actions may process inputs to generate outputs, update local configurations, or produce results based on internal conditions. Actions enable network automation and ensure seamless service interaction in 6G systems.
[0121] Network Capability Description Language (NCDL) : The collection of information on network capability description. To provide this capability, a NC provider defines its supported actions and provide capability description of each action.
[0122] Mission service: Mission service is a novel concept of the proposed 6G System. The provisioning of a mission service results from the contribution of one or multiple NCs, i.e., mission involved NCs, and one or multiple actions are required for the mission service provisioning.
[0123] Mission operation: Each action that is required by the mission service is known as a mission operation. Thus, the execution of the mission consists of the execution of its mission operation (s) .
[0124] Mission instantiation: The creation of an instance of a mission.
[0125] Mission session: A mission session is a collection of actions performed, in a certain order, by one or multiple NCs (entities) involved in executing the mission. Also involved in a mission session are 6G devices and mission service consumers.
[0126] Data plane NC (entity) : an NC (entity) which can contribute to a data plane mission service, i.e., can be involved by a data plane mission session.
[0127] C / M plane NC: an NC which can contribute to a C / M plane mission service i.e., can be involved in a C / M plane mission session.
[0128] Radio Bearer (RB) : A Radio Bearer may refer to a logical channel established between a device, its serving RAN (or gNB) , used for transmitting data session traffic or control and management (C / M) session traffic.
[0129] Extended Master Session Key (EMSK) : an EMSK key may refer to a cryptographic key used for deriving session and encryption keys.
[0130] Autonomous Capability Programming (A-CAP) : a mechanism or service for providing an autonomous network capability programming (A-CAP) service.
[0131] 6G Key Set Identifier (6gKSI) : A 6gKSI may be defined as a unique identifier for key sets in 6G networks, used for managing security credentials across sessions and devices.
[0132] Next Hop (NH) : A key derivation function that provides forward security for encrypted communications.
[0133] Physical Cell ID (PCI) : An identifier assigned to network cells to facilitate radio communication.
[0134] Key management is an important aspect for securing communications between devices, service providers and networks, particularly in 6G environments where dynamic and scalable security solutions are available. The present disclosure provides a novel approach to key management through the use of different actions defined by a NCDL, enabling devices to subscribe to key management services and obtain the necessary cryptographic materials for secure communications at different levels, with the network or with service providers.
[0135] The key management service, which can be provided by one or more nodes responsible for the control and management of 6G service access by customers and for the provisioning of services, may support multiple level of security, including session key management, RB key management and end-to-end (E2E) key management. Session Key Management involves the secure exchange of session keys between devices and serving GWs (e.g., C / M-TW-GW-1, Data-TW-GW-1) . RB key management ensures that communications with the radio bearers are protected through encryption and integrity keys. E2E key management ensures secure communications / connections between devices and NCs (C / M NCs or data NCs) .
[0136] By using of key management actions defined by the NCDL, devices can dynamically select security parameters, including key level or granularity, expiration, and supported cryptographic algorithms (e.g., encryption algorithms) . This structured approach provides a scalable and effective key management solution that adapts to different network and security requirements, while enabling the automation of key management.
[0137] The technical problems addressed by the present invention arise from the need for an efficient and scalable mechanism for managing cryptographic keys in next-generation network architectures, particularly in 6G networks. Existing network security frameworks do not provide a standardized, flexible, and dynamic method for defining, provisioning, and managing keys across multiple security domains, including session protection, radio bearer (RB) protection, and end-to-end (E2E) communication security.
[0138] A key challenge is the lack of a structured and automated way to describe and manage security capabilities across different network components. Traditional key management mechanisms do not provide a formalized language that can dynamically express security requirements and configurations for different entities, such as devices, network capability nodes (NCs) , gateways, and service providers. This results in an inefficient way of establishing secure communications, particularly in scenarios where devices interact with multiple network elements and / or service providers and require varying levels of security protection.
[0139] Another problem is the inefficiency of conventional methods in handling security subscriptions and negotiations. Current solutions do not offer flexibility for devices when they need to subscribe to key management services based on their specific security needs, nor do they allow for seamless negotiation of security parameters between different network elements. The absence of a standardized negotiation process results in redundant key provisioning, delays in establishing secure sessions, and increased computational overhead for both network nodes and end devices.
[0140] Moreover, existing key management systems do not adequately address the need for automated updates and adaptations of security policies based on real-time network conditions. Without an effective framework for dynamically updating security parameters, networks may either over-provision security resources, leading to unnecessary overhead, or under-provision security, exposing communications to potential vulnerabilities.
[0141] The present disclosure proposes various methods to address these challenges by introducing a Network Capability Description Language (NCDL) framework for key management. These methods may be managed and / or made available to devices and / or network providers through one or more nodes responsible for managing service provisioning, referred to as Service Provision Management (SPM) . This framework enables the dynamic definition, subscription, and negotiation of security attributes between network entities, including for example devices, radio handlers and service providers. By leveraging NCDL, a structured and efficient mechanism for devices and network components is provided for negotiating different aspects relating to key management and encryption / decryption of communications, allowing for automated security provisioning and enforcement. The invention further supports flexible key management granularity (or protection / security levels) , ranging from per-device keys to per-session and per-service keys, ensuring optimal security without excessive resource consumption.
[0142] In addition, the invention facilitates automated synchronization and distribution of cryptographic keys among different nodes, enabling real-time adaptation to changes in security policies. The introduction of structured capability descriptions for key management further ensures interoperability among diverse network elements while maintaining compliance with security protocols. This enhances the security, efficiency, and scalability of key management in 6G networks, reducing the operational complexity and improving the reliability of secure communication services.
[0143] In a possible implementation, a method performed at a first node for providing a key management subscription service is provided. In this context, the first node is a node configured to manage service provisioning, and may be referred to as a Service Provisioning Management (SPM) node, which interacts with a device requesting secure traffic protection. FIG. 3 illustrates possible steps of the method. An objective of this method is to enable a device to subscribe to a key management service, ensuring security protection on traffic exchanged between the device and different network components. This action may be autonomous and negotiable, as it may be executed automatically when predefined conditions are met, and the parameters can be determined by a device from multiple options provided by the first node.
[0144] In Step S301, the first node receives, from a device, a request that includes identification information of the device and a request to negotiate key management information between the device and the first node. This request may be triggered when a device seeks to subscribe to a basic service or when the device updates one or more key information items.
[0145] In Step S302, the first node processes the received request and transmits the key management information to the device. The key management information may be information necessary to ensure proper management of the keys required to protect communications between the device and other nodes, including network nodes and / or service provider nodes. The key management information may include the types of security protection options available, the levels of security related to the keys (which may also refer to the “protection granularity level” ) , respective expiration periods for the different keys, and identifiers of protection algorithms. A protection algorithm can correspond to the algorithm to be used for the encryption and decryption of messages with a given key or for ensuring the integrity of the content of a message. The security protection options may involve session protection between the device and a gateway, radio bearer protection between the device and a radio bearer handler, or end-to-end (E2E) protection on connections / communications between the device and a second node (e.g., any NC) responsible for providing additional services. A gateway may be a control and management plane gateway or a data plane gateway, for example, C / M-TW-GW-1 or Data-TW-GW-1, as per the examples provided in FIG. 2B.
[0146] In Step S303, the first node receives the negotiation results from the device. These results include the device’s selection of one or more key information items from the key management information provided by the first node. The selection may be based on the security policies and requirements of the device, and the response may specify details such as the specific encryption algorithms and / or integrity preservation algorithms to be used, and the key expiration periods.
[0147] Following a successful negotiation, the first node may update the security profile associated with the device, reflecting the agreed-upon key management configurations. This ensures that the device is subscribed to the key management service and that the selected security protections are applied.
[0148] Upon completion of the process, the subscription of the device to the key management service is finalized. The first node ensures that the necessary security configurations are in place and that the device can securely communicate using the selected protection mechanisms. If required, the first node may notify relevant network entities about the updated key management subscription, as will be described in more detail below.
[0149] The steps described above constitute or form an action to subscribe a device to the key management service. This action can be called by a third node providing autonomous (or autonomic) programming services. The third node may facilitate service provisioning and network automation by ensuring that key management actions are properly configured and executed.
[0150] The following paragraphs will describe an exemplary description (NCDL) of the action for key management of subscription.
[0151] Name of the action: key management subscription.
[0152] Purpose of the action: a device subscribes to a key management service when the device wants a secure protection on traffic.
[0153] Pre-condition of the action: a customer opens an account or changes the protection settings of communications for one of his / her devices.
[0154] Post-condition of the action: key management subscription has been conducted. Table 1 –Capability dimensions of the action “key management subscription”
[0155] The parameters shown represent different capability dimensions (or fields) for the action of key management subscription.
[0156] The definitions of the capability dimensions illustrated in Table 1 are as follows: -Device identifier: indicates the name of the device when accessing the network. This device name may be termed as a Subscriber Temporary Identifier (STID) . An STID may correspond to the identifier of a device or customer used for subscribing to a service. This identifier may be a temporary identifier and may be generated by a node, such as a service provisioning management node (SPM) for each device to access a network, such as a 6G network. -Type of security protection: this field or dimension indicates the type of security protection to apply on the device’s communications, e.g., session (C / M, data) protection between the device and a control and management plane gateway (C / M-TW-GW) or session protection between the device and a data plane gateway (Data-TW-GW) , RB (C / M, data) protection between the device and a RB handler (e.g., a RAN node or a gNB) –on the C / M plane or on the data plane, and E2E protection on connections between the device and a service provider node (NC) . The types of protection are combinable, i.e., the protection can be applied at the session level and at the RB level, and the session, RB and E2E level, at the E2E level only, etc. -Level related to the key: this field indicates the level of security protection on traffics (or key granularity) , e.g., key per device, key per session, key per device-NC connection, key per service, key per RAN. Again, there may be more than one value selected, if a client decides to protect the client’s communications at more than one level. “Per device” or “Per service” could be used for selection of any type of security protection. “Per session” could be used for selection of session (C / M, data) protection between device and C / M-TW-GW / Data-TW-GW. “Per E2E connection” could be used for selection of E2E connection protection between device and a service provide node (NC) . “Per RAN” could be used when selecting RB protection (C / M, data) between the device and a RB handler. -Key’s expiration (or key expiration period) : this field indicates a time window or duration of the key to be valid, e.g., one year, two months, 4 weeks, 10 days. Other ways of indicating the validity period of the key are possible. -List of protection algorithms: indicates a list of available algorithms that a SPM supports. There may be different algorithms available for encryption / decryption and for verifying the integrity of the data. The list of algorithms IDs should indicate the specific algorithms to be used for each type of protection, including for example, the ID of an encryption algorithm, or the ID of an integrity algorithm. If different security levels are selected, each security type can be associated with a specific encryption and / or an integrity-preserving algorithm.
[0157] When a field value is set to “NA” , this means that the information is not available when the action is called.
[0158] Use of this NCDL: -This NCDL should be subscribed by a device / customer. -This NCDL can be used by a device to select preferred security protection on traffics. This NCDL is used for allowing a first node (such as a SPM node) to obtain preferences of a device for protection to be applied on traffics. -This NCDL may be called when a customer opens an account or when a customer changes the protection settings of his / her communications. -When called, the customer / end-user, can select, via his / her device, preferred protection settings or key information items. For example, a device can select a session (C / M, data) protection between device and gateway (C / M-TW-GW / Data-TW-GW) . Level related to the key may be per session, or per device, or others. The key’s expiration may be set in years, months, weeks or days. The device may select for each security level the algorithm to be used, from a list of available encryption algorithms and a list of available integrity algorithms. -This action can be called by a node providing autonomous programming services (which may be referred to as a A- CAP node) that is triggered by a device or other service provider nodes (NCs) . -The effect of the action is that the first node (SPM) initializes or updates a security profile of the customer / device, and the customer / device has established preferred security protections to be applied on traffic. A security profile for a device may comprise the protection settings (or key information items) chosen or imposed to a device for the protection of his / her communications (traffic) at different levels, including at the session, RB, and E2E protection for communications. For each level, a specific key profile can be established.
[0159] According to a possible implementation, a method is performed at the first node for providing a session key to a second node, ensuring secure communication between a device and a second node. In this context, the first node is a SPM, which interacts with the second node responsible for connectivity management. The second node may support a service which owns one or more C / M and data trustworthy gateways C / M-TW-GWs and Data-TW-GWs) . This service may provide a capability to control and manage different types of connections. Each gateway (C / M-TW-GW or Data-TW-GW) may be responsible for C / M plane or data plane traffic forwarding / routing based on configuration from the service C / M functions. These GWs may also be responsible for information / data traffic protection and or inspection, based on the configuration of the C / M function. FIG. 4 illustrates a possible step of the method.
[0160] In Step S401, the first node transmits a session key message to the second node. This message contains session key management information required for protecting communications between the device and the second node. The session key management information may include a plurality of security parameters, including for example: the identifier of the device, one or more types of session security protection, different levels related to session keys, expiration periods, types of session keys, and an identifier of a root key. A root key can be used to derive session keys.
[0161] The session security protection may involve encryption and integrity preservation mechanisms applied to communications between the device and the control and management (C / M) plane gateway and / or the data plane (DP) gateway. The level of session keys refers to granularity levels, such as a key per device, a key per session, a key per service, or a key per application, ensuring flexible security configurations based on the device's needs. The session keys may include keys for encrypting or decrypting session communications on the control and management plane, keys for encrypting or decrypting session communications on the data plane, keys for protecting integrity of session communications on the control and management plane, and keys for protecting integrity of session communications on the data plane.
[0162] Upon receiving the session key message, the second node processes the key management information provided and configures its own security settings accordingly. The security profile established for the device at the first node ensures that the session key exchange is in accordance with the device’s selected security preferences.
[0163] As mentioned previously, the second node may control “control and management” (C / M) gateways and / or data plane (DP) gateways of the network.
[0164] For executing this method, the first node must have already performed mutual authentication with the device and has established a security profile that includes the selected root key information for protecting session communications.
[0165] After the transmission of the session key message, the second node applies the received key information to enforce security policies on the session traffic. This ensures that all communications between the device and the second node are properly encrypted and integrity-protected, enhancing the security of network interactions.
[0166] If any updates to the session key management information occur, such as changes in key expiration periods or modifications in the session security protection to enforce, the first node may perform the method again to transmit updated session key information to the second node. This dynamic key provisioning mechanism allows for continuous adaptation to security requirements.
[0167] This method constitutes an action to provide session key management information to the second node in charge of C / M and / or data plane gateways, which can be called by a third node responsible for autonomous service management (A-CAP) . The third node may oversee security policy enforcement and network automation by ensuring that session key provisioning actions are correctly executed.
[0168] The following paragraphs will describe an example NCDL of the action for the provisioning of session keys to a second node, which may control and manage gateways of a network, and which may be referred to as a “network for connection” node.
[0169] Name of the action: provision of session key to a second node / network for connection (NET4CON) node.
[0170] Purpose of the action: the second node obtains session keys that are generated by a first node, in charge of service provisioning management.
[0171] Pre-condition of the action: the first node has a subscription of device regarding session (C / M, data) protection between the device and one or more gateways (C / M-TW-GW / Data-TW-GW) . This action may be conducted when a mutual authentication between a device and a network has been successfully completed, and when the first node has a root key (such as a EMSK) . This action may also be conducted when the first node updates session keys.
[0172] Post-condition of the action: a second node has obtained the session keys. Table 2 -Capability dimensions of the action “provision of session key to a second node / NET4CON node”
[0173] The parameters shown represent different capability dimensions (or fields) for the action for providing session key (s) to the second node.
[0174] The definitions of the capability dimensions illustrated in Table 2 are as follows: -Device identifier: indicates the name of the device when accessing the network. This device name may be termed as a Subscriber Temporary Identifier (STID) . -Type of session security protection: indicates the type of session (C / M, data) protection needed between the device and the C / M or data plane gateways (C / M-TW-GW / Data-TW-GW) , e.g., session C / M protection between device and C / M-TW-GW, session data protection between device and Data-TW-GW. -Level related to the session key: indicates of the granularity of the security protection on traffic, e.g., per device, per session, per service. -Key’s expiration period: indicate a time window or a duration for the key to be valid. -Types of session Key: indicates keys to be used for sessions security protection, e.g., C / M session key-int, C / M session key-enc, data session key-int, data session key-enc. Key-int refers to a key to ensure the integrity of the communications / traffic, while key-enc refers to a key to encrypt communications / traffic transiting via the gateways. -Root Key identifier: indicate an ID of the root key to be used for key derivation. For example, the ID of a root key may be the ID of an EMSK.
[0175] Use of this NCDL: -This NCDL should be subscribed by the second node (i.e. a gateway controlling node) -This NCDL is conducted when the first node (for example, a node in charge of managing service provisioning) generates session keys when a device subscribes a security protection on a session interface between a device and the second node. This action may be conducted when a mutual authentication between a device and a network is successful done and the first node has a root key (e.g., EMSK) . This action may be conducted when the first node updates one or more session keys. -When conducted, the output may include an identifier of the device; one or more types of session security protection; one or more levels related to one or more session keys; respective expiration periods related to the one or more session keys; one or more types of the one or more session keys; and an identifier of a root key. -This action can be called by a third node, in charge of autonomous service programming (A-CAP) that is triggered by a device or other service provide nodes (NCs. )
[0176] According to a possible implementation, a method is performed at a first node for providing session key messages to a device, ensuring secure session-based communication with a second node. The second node may support a service which owns one or more C / M and data trustworthy gateways C / M-TW-GWs and Data-TW-GWs) . In this context, the first node is a SPM, which transmits key management information to the device, allowing it to generate one or more session keys. FIG. 5 illustrates a step of the method according to a possible implementation. An objective of this method is to securely provision session key parameters to the device, enabling it to establish protected session communications.
[0177] In Step S501, the first node transmits a session key message to the device. This session key message contains one or more session key parameters required for securing session-based communications between the device and the second node. The session key parameters include a combination of security attributes, such as an identifier of the root key, encryption and integrity protection algorithms, sequence numbers, and relevant session identifiers.
[0178] The key parameters are specifically designed to allow the device to generate one or more session keys based on the cryptographic information provided. These session keys ensure that all transmitted data / traffic remains encrypted and integrity-protected, thereby preventing unauthorized access or tampering during communication.
[0179] For execution of this method, the first node must have access to a security profile of the device, which includes an identifier of the device and session protection information. The session protection information indicates whether the device requires security mechanisms for communications with a control and management (C / M) plane gateway and / or a data plane (DP) gateway. The security profile ensures that the session key messages (or key materials) provided to the device align with its security preferences and network policies.
[0180] The session key parameters transmitted in Step S501 may include specific attributes, including for example: a sequence number (SQN) , an encryption algorithm identifier, an integrity algorithm identifier, a gateway identifier, a session downlink count. Other cryptographic values are possible. These parameters may also include a scramble operation (XOR) and a service identifier. These parameters collectively enable the device to generate secure session keys for authentication, encryption, and integrity verification.
[0181] After the device receives the session key messages, it processes the provided information to derive one or more session keys. These session keys are subsequently used to establish secure communication channels between the device and the second node, ensuring that all transmitted data / traffic remains protected against potential security threats.
[0182] If any updates or modifications occur in the key management policies, such as changes in encryption algorithms or session expiration periods, the first node may repeat the method to provide the updated session key messages to the device. This ensures that the security configurations remain up to date and effective.
[0183] For execution of this method, mutual authentication between the first node and the device must have been performed. Both the first node and the device must possess the root key to enable the secure generation of session keys. This mutual authentication mechanism ensures that only authorized devices receive session key messages.
[0184] Upon completion of the process, the session key parameters have been successfully provided to the device, enabling it to securely generate session keys for future communication. The method constitutes an action to provision session key messages to the device, which can be called by a third node providing autonomous security services. The third node may facilitate network automation and security policy enforcement by managing session key provisioning actions.
[0185] The following paragraphs will describe an example NCDL of the action of provisioning session key messages to device.
[0186] Name of the action: provision of session key messages to a device.
[0187] Purpose of the action: a device obtains session key messages that are used for generation session keys. This action may be called when a device wants a security protection on a session interface between the device and the second node, as described previously.
[0188] Pre-condition of the action: the device subscribes to a session (C / M, data) protection service between device and a gateway (C / M-TW-GW / Data-TW-GW) . This action may be conducted when a mutual authentication between the device and the network has been successfully completed, and the first node (SPM) has a root key (e.g., EMSK) . This action may be conducted when a device updates session keys.
[0189] Post-condition of the action: the device has obtained session key messages. Table 3 -Capability dimensions of the action “provision of session key messages to a device”
[0190] The parameters shown represent different capability dimensions (or fields) for the action of provisioning of session key messages to device. -The definitions of the capability dimensions illustrated in Table 3 are as follows: -Device identifier: indicates the name of the device used to access the network. This device name may be termed as a Subscriber Temporary Identifier (STID) . -Session protection information: this field indicates a type of session (C / M, data) protection between device and a given gateway (either a C / M plane gateway or a data plane gateway (C / M-TW-GW / Data-TW-GW) , e.g., session C / M protection between device and C / M-TW-GW, session data protection between device and Data-TW-GW. -Session Key parameters: indicates factors for session key generation. The values can be combined. In other words, the session key parameters may comprise one or more of the listed items (depending on whether the session protection is to be applied at the C / M plane, data plane or both) . -Root key identifier: this field indicates the ID of the key to be used for key derivation.
[0191] Use of this NCDL: -This NCDL should be subscribed by a device / customer. -This NCDL is called when a device wants a security protection on a session interface between a device and the second node. -When called, the input should include a device name and an indication of security protection on session. The output could be key parameters and a root key ID. The key materials could be as followers: 1. If a device selects a session C / M protection between device and C / M-TW-GW, the key parameters may be SQN, XOR, ID of selected encryption algorithm for session C / M protection, ID of selected integrity algorithm for session C / M protection, C / M-TW-GW ID, session downlink COUNT. 2. If a device selects a session C / M protection between device and C / M-TW-GW, the key parameters may be SQN, XOR, ID of selected encryption algorithm for session data protection, ID of selected integrity algorithm for session data protection, Data-TW-GW ID, session downlink COUNT. -This action can be called by a third node (A-CAP) that is triggered by a device or other NCs. -The effect of this action is that a device obtains key messages to generate session keys.
[0192] According to another possible implementation, a method is performed at a first node for providing a radio bearer (RB) key to an RB handler, ensuring secure communication between a device and the RB handler. In this context, the first node is a SPM, which transmits RB key management information to the RB handler, allowing it to enforce security mechanisms on RB communications. FIG. 6 illustrates the flow of the method according to one or more embodiments of the present disclosure. The goal of this method is to securely provision RB key management information to the RB handler, ensuring the confidentiality and integrity of data / traffic transmitted over the RB interface.
[0193] In Step S601, the first node transmits an RB key message to the RB handler. This RB key message contains RB key management information required for protecting communications between the device and the RB handler. The RB key management information includes a set of security parameters, such as the identifier of the device, one or more types of RB security protection, different levels related to RB keys, expiration periods, types of RB keys, and an identifier of a root key.
[0194] The various types of RB keys include keys for encrypting or decrypting RB communications on the control and management (C / M) plane, keys for encrypting or decrypting RB communications on the data plane, keys for protecting integrity of RB communications on the C / M plane, and keys for protecting integrity of RB communications on the data plane.
[0195] The RB security protection may include encryption and integrity preservation mechanisms applied to communications over the RB interface. The levels of RB keys may be defined based on different security granularity levels, such as a key per device, a key per RB, or a key per service, ensuring flexible security configurations that align with network policies.
[0196] For execution of this method, the first node must have access to a security profile of the device, which includes an identifier of the device and RB protection information. The RB protection information specifies the security mechanisms applicable to RB communications, ensuring that the key management process aligns with the device’s security needs. The RB security protection may indicate if the protection is to be applied on communications between the device and the RB handler for signalling messages on a control and management plane and / or on communications between the device and the RB handler for data on a data plane.
[0197] The RB key message transmitted in Step S601 may include specific attributes such as encryption and integrity protection algorithm identifiers, RB security level indicators, and expiration time values. These attributes collectively enable the RB handler to enforce security policies on the RB interface, preventing unauthorized access and data manipulation.
[0198] Upon receiving the RB key message, the RB handler processes the provided key management information and configures its security settings accordingly.
[0199] If any updates to the RB key management information occur, such as changes in encryption algorithms or RB key expiration policies, the first node may perform the method again to transmit the updated RB key information to the RB handler. This ensures that the RB security configurations remain adaptive to evolving network requirements.
[0200] For the execution of this method, mutual authentication between the first node and the device must have been performed and a root key that is used for deriving RB keys, is obtained by the first node.
[0201] Upon completion of the process, the RB key management information has been successfully provisioned to the RB handler, enabling it to enforce secure RB communications. The method constitutes an action to provide RB key management information to the RB handler, which can be called by a third node responsible for autonomous security services. The third node may facilitate network automation and security policy enforcement by managing RB key provisioning actions.
[0202] The following paragraphs will describe an example NCDL of the action for providing a RB key to a RB Handler.
[0203] Name of the action: Provision of RB key to RB handler.
[0204] Purpose of the action: an RB handler obtains RB keys that are generated by the first node (SPM) , when a device wants a security protection on an RB interface between a device and an RB handler.
[0205] Pre-condition of the action: a device subscribes to an RB (C / M, data) protection between the device and the RB handler. This action may be conducted when a mutual authentication between the device and the network has been successfully completed and the first node has a root key (e.g., EMSK) . This action may be conducted when a device updates the RB keys.
[0206] Post-condition of the action: the RB handler has obtained the RB keys. Table 4 -Capability dimensions of the action “provision of RB key to RB handler”
[0207] The parameters shown represent different capability dimensions (or fields) for the action of provision of RB Key to RB Handler.
[0208] The definitions of the capability dimensions illustrated in Table 4 are as follows: -Device identifier: indicates a name of a device that accesses to the network. It could be termed as a device STID. This device name may be termed as a Subscriber Temporary Identifier (STID) . -Type of Security protection on RB: indicates that an RB (C / M, data) protection between the device and the RB handler is to be applied, e.g., RB C / M protection between the device and the RB handler, RB data protection between the device and the RB handler. -Levels related to the RB Key: indicates a granularity of security protection on traffics. The values are combinable, meaning that the protection can be applied at the device, RAN and / or service level. -RB Key’s expiration period: indicate a time window of the key to be valid, e.g., one year, two months, 4 weeks, 10 days. -Types of RB Keys: indicates keys to be used for security protection on RBs, e.g., C / M RB key-int, C / M RB key-enc, data RB key-int, data RB key-enc. -Root Key identifier: indicate an ID of key to be used for key derivation.
[0209] Use of this NCDL: -This NCDL should be subscribed by an RB handler. -This NCDL is conducted when a device wants a security protection on an RB interface between a device and an RB handler. This action may be conducted when a mutual authentication between a device and a network has been successful and the first node (SPM) has a root key. This action may be conducted when a device updates one or more RB keys. -When conducted, the output should include the device name, type of security protection, level related to the key, key’s expiration, one or more RB keys and a root key ID. -This action can be called by A-CAP that is triggered by a device or other NCs. -The effect of this action is that the RB has obtained the RB keys.
[0210] The present embodiment describes a method performed at a first node for providing radio bearer (RB) key message to a device, ensuring secure communication between a device and an RB handler. In this context, the first node is a SPM, which transmits RB key management information to the device, allowing it to generate one or more RB keys for secure data transmission. FIG. 7 illustrates a step of the method according to one possible of the present disclosure. An objective of this method is to securely provide RB key parameters to the device, enabling the device to establish protected radio bearer communications.
[0211] In Step S701, the first node transmits an RB key message to the device. This RB key message contains one or more RB key parameters necessary for securing communications between the device and the RB handler. The RB key parameters include an identifier of the root key, encryption and integrity protection algorithm identifiers, security level indicators, expiration periods, and RB identifiers.
[0212] The key parameters are specifically designed to allow the device to generate one or more RB keys based on the provided cryptographic information. These RB keys ensure that all transmitted data over the RB interface remains encrypted and integrity-protected, thereby preventing unauthorized access or tampering during transmission.
[0213] For execution of this method, the first node must have access to a security profile of the device, which includes an identifier of the device and RB protection information. The RB protection information specifies whether the device requires encryption, integrity protection, or other security measures for its RB-based communications. This security profile ensures that the RB key message provided to the device aligns with the network’s security policies.
[0214] The RB key parameters transmitted in Step S701 may include specific attributes such as a sequence number (SQN) , encryption algorithm identifier, integrity algorithm identifier, RB security level indicators, and expiration times. The RB key parameters may also include a scramble operation (XOR) , a Physical Cell Identifier (PCI) , a Next Hop (NH) , a service identifier, and an application identifier. These parameters collectively enable the device to generate secure RB keys for authentication, encryption, and integrity verification.
[0215] After the device receives the RB key message, it processes the provided information to derive one or more RB keys. These keys are subsequently used to establish secure communication channels between the device and the RB handler, ensuring that all transmitted data over the RB interface remains protected against potential security threats.
[0216] If any updates or modifications occur in the key management policies, such as changes in encryption algorithms or RB key expiration periods, the first node may repeat the method to provide updated RB key messages to the device. This ensures that the security configurations remain up to date and effective.
[0217] For execution of this method, a mutual authentication between the first node and the device must have been performed. Both the first node and the device must possess the root key to enable the secure generation of RB keys. This mutual authentication mechanism ensures that only authorized devices receive RB key messages.
[0218] Upon completion of the process, the RB key parameters have been successfully provided to the device, enabling it to securely generate RB keys for future communication. The method constitutes an action to provision RB key messages to the device, which can be called by a third node providing autonomous security services. The third node may facilitate network automation and security policy enforcement by managing RB key provisioning actions.
[0219] The following paragraphs will describe an example NCDL of the action of providing RB key messages to a device.
[0220] Name of the action: Provision of RB key messages to a device.
[0221] Purpose of the action: a device obtains RB key messages that can be used for generating the RB keys, when the device wants a security protection on an RB interface between the device and an RB handler.
[0222] Pre-condition of the action: a device subscribes to an RB (C / M, data) protection between the device and an RB handler. This action may be called when a mutual authentication between a device and a network has been successful and the first node has a root key (e.g., EMSK) . This action may also be called when the device updates a given RB key.
[0223] Post-condition of the action: the device has obtained the RB key messages. Table 5 -Capability dimensions of the action “provision of RB key messages to a device”
[0224] The parameters shown represent different capability dimensions (or fields) for the action of provisioning of RB key message to a device.
[0225] The definitions of the capability dimensions illustrated in Table 5 are as follows: -Device identifier: indicates a name of a device that accesses to the network. This identifier may be a temporary identifier, also referred to as a Subscriber Temporary Identifier (STID) . -RB protection information: indicates that an RB (C / M, data) protection between device and an RB handler is to be applied / enforced, which may be applied at the C / M plane or at the data plane, e.g., RB C / M protection between device and RB handler, RB data protection between device and RB handler. -RB Key parameters: indicates factors for RB key generation. The values of the factors for key generation are combinable, e.g., SQN, XOR, ID of selected encryption algorithm, ID of selected integrity algorithm, name of serving RB handler, Uplink session COUNT, PCI, NH. -Root key identifier: indicate an ID of key to be used for key derivation, e.g., 6gKSI, ID of EMSK.
[0226] Use of this NCDL: -This NCDL should be subscribed by a device / customer. -This NCDL is called when a device subscribes an RB (C / M, data) protection between device and RB handler. This action may be conducted when a mutual authentication between a device and a network is successfully done and a SPM has a root key (e.g., EMSK) . This action may be conducted when a device updates RB keys. -When called, the input should include a device name and an indication of security protection on RB; the output should include key parameters and a root key ID. For example: If a device selects a RB C / M protection between device and RB hander, the key parameters may be SQN, XOR, ID of the selected encryption algorithm for RB C / M protection, ID of selected integrity algorithm for RB C / M protection, RB hander ID, Uplink session COUNT, PCI, NH. If a device selects a RB data protection between device and RB handler, the key parameters may be SQN, XOR, ID of selected encryption algorithm for RB data protection, ID of the selected integrity algorithm for RB data protection, RB hander ID, Uplink session COUNT, PCI, NH. -This action can be called by a third node (A-CAP) that is triggered by a device or other NCs. -The effect of this action is that a device obtains the RB key messages.
[0227] According to a possible implementation, a method is performed at a first node for providing an end-to-end (E2E) connection key to a network capability (NC) , ensuring secure communication between a device and a service provider node In this context, the first node is a SPM, which transmits E2E key management information to the service provider node (NC) , allowing it to enforce security mechanisms on end-to-end connections / communications. FIG. 8 illustrates a step the method according to one possible embodiment of the present disclosure. One objective of this method is to securely provision E2E key management information to the service provider node, ensuring confidentiality, integrity, and authentication for data exchanged across the network.
[0228] In Step S801, the first node transmits an E2E key message to the service provider node. This E2E key message contains key management information required for protecting end-to-end communications between the device and the service provider node. The E2E key management information includes a set of security parameters, such as the identifier of the device, one or more types of E2E security protection, different levels related to E2E keys, expiration periods, types of E2E keys, and an identifier of a root key.
[0229] The E2E security protection indicates if the protection is to be applied on communications between the device and the service provider node for signaling messages on a control and management plane and / or between the device and the service provider node for data on a data plane. The E2E security protection may involve encryption, authentication, and integrity preservation mechanisms applied to communications across the network. The levels of E2E keys may be defined based on different security (or granularity) levels, such as a key per device, a key per E2E connection, a key per service, or a key per application, ensuring flexible security configurations that align with network security policies.
[0230] For the execution of this method, the first node must have access to the security profile of the device, which includes an identifier of the device and E2E protection information. The E2E protection information specifies the security mechanisms applicable to end-to-end communications, ensuring that the key management process aligns with the device’s security needs.
[0231] The E2E key message transmitted in Step S801 may include specific attributes such as encryption and integrity protection algorithm identifiers, E2E security level indicators, and expiration time values. In particular, the E2E keys may include keys for encrypting or decrypting end-to-end communications between the device and the service provider node on the control and management plane, keys for encrypting or decrypting end-to-end communications between the device and the service provider node on the data plane, keys for protecting the integrity of end-to-end communications between the device and the service provider node on the control and management plane, and keys for protecting integrity of end-to-end communications between the device and the service provider node on the data plane. These attributes collectively enable the service provider node to enforce security policies on end-to-end communications, preventing unauthorized access and data manipulation.
[0232] Upon receiving the E2E key message, the service provider node processes the provided key management information and configures its security settings accordingly. This ensures that all communications between the device and the service provider node are encrypted and integrity-protected, thereby enhancing network security and preventing potential cyber threats.
[0233] If any updates to the E2E key management information occur, such as changes in encryption algorithms or key expiration policies, the first node may perform the method again to transmit the updated E2E key information to the NC. This ensures that E2E security configurations remain adaptive to evolving network requirements.
[0234] For execution of this method, mutual authentication between the first node and the device must have been performed, ensuring establishment of a root key that known by the first node and the device.
[0235] Upon completion of the process, the E2E key management information has been successfully provided (or provisioned) to the service provider node (NC) , enabling it to enforce secure end-to-end communications. The method constitutes an action to provide E2E key management information to a service provider node, which can be called by a third node responsible for autonomous programming services. The third node may facilitate network automation and security policy enforcement by managing E2E key provisioning actions.
[0236] The following paragraphs will describe an example NCDL of the action of for the provisioning of E2E connection key to a service provider node (NC) .
[0237] Name of the action: Provision of E2E connection key to a service provider node (NC) .
[0238] Purpose of the action: a service provider node (NC) obtains E2E connection keys that are generated by the first node (SPM) , when a device wants a security protection on an E2E connection between the device and a service provider node (NC) .
[0239] Pre-condition of the action: the device has subscribed to an E2E connection (C / M, data) protection between the device and a service provider node (NC) . This action may be conducted when a mutual authentication between a device and the network has been successful and when the first node (SPM) has a root key (e.g., EMSK) . This action may also be conducted when a device updates E2E connection keys.
[0240] Post-condition of the action: the service provider node (NC) obtains E2E connection keys. Table 6 -Capability dimensions of the action “provision of E2E connection key to a service provider node (NC) ”
[0241] The parameters shown represent different capability dimensions (or fields) for the action of provisioning of E2E connection key to NC.
[0242] The definitions of the capability dimensions illustrated in Table 6 are as follows: -Device identifier: indicates a name of a device that accesses to the network. This identifier may be a temporary identifier, also referred to as a Subscriber Temporary Identifier (STID) . -Type of security protection on E2E connection: indicates an E2E connection (C / M, data) protection between the device and the service provider node (NC) , e.g., E2E connection C / M protection between device and NC, E2E connection data protection between device and NC. -Levels related to the E2E key: indicates a granularity of security protection on traffics. These values may be combined (i.e. more than one parameter may be selected) . -E2E Key’s expiration: indicate a time window (or duration) for the validity of the key, e.g., one year, two months, 4 weeks, 10 days. -Type of E2E Keys: indicates keys to be used for security protection on connections between a device and a service provider node (NC) , e.g., C / M E2E connection key-int, C / M E2E connection key-enc, data E2E connection key-int, data E2E connection key-enc. -Root Key identifier: indicate an ID of the key to be used for key derivation.
[0243] Use of this NCDL: -This NCDL should be subscribed by the service provider node. -This NCDL is conducted when a device subscribes to an E2E connection (C / M, data) protection between the device and a service provider node (NC) . This action may be conducted when a mutual authentication between the device and the network has been successful and the first node has a root key (e.g., EMSK) . This action may also be conducted when the device updates one or more E2E connection keys. -When conducted, the output should include the device name, type of security protection, granularity of key, key expiration, key and a root key ID. -This action can be called by a third node (A-CAP) that is triggered by a device or other service providers. -The effect of this action is that a service provider node obtains E2E connection keys.
[0244] According to a possible implementation, a method is performed at a first node for providing end-to-end (E2E) connection key messages to a device, ensuring secure communication between the device and a service provider node. In this context, the first node is a SPM, which transmits E2E key management information to the device, allowing it to generate one or more E2E keys for secure end-to-end communications. FIG. 9 illustrates the as step of the method according to one or more embodiments of the present disclosure. An objection of this method is to securely provision E2E key parameters to the device, enabling it to establish protected end-to-end connections.
[0245] In Step S901, the first node transmits an E2E key message to the device. This E2E key message contains one or more E2E key parameters necessary for securing end-to-end communications between the device and the service provider node. The E2E key parameters include an identifier of the root key, encryption and integrity protection algorithm identifiers, security level indicators, expiration periods, and E2E connection identifiers.
[0246] The key parameters are specifically designed to allow the device to generate one or more E2E keys based on the provided cryptographic information. These E2E keys ensure that all transmitted data over the end-to-end communication channel remains encrypted and integrity-protected, thereby preventing unauthorized access or tampering during transmission.
[0247] For the execution of this method, the first node must have access to a security profile of the device, which includes an identifier of the device and E2E protection information. The E2E protection information specifies whether the device requires encryption, integrity protection, or other security measures for its E2E communications. This security profile ensures that the E2E key messages provided to the device align with the network’s security policies.
[0248] The E2E key parameters transmitted in Step S901 may include specific attributes such as a sequence number (SQN) , encryption algorithm identifier, integrity algorithm identifier, E2E security level indicators, and expiration times. The E2E key parameters may also include a scramble operation (XOR) , an identifier of the service provider node, a service identifier, and an identifier of the E2E connection. These parameters collectively enable the device to generate secure E2E keys for authentication, encryption, and integrity verification.
[0249] After the device receives the E2E key messages, it processes the provided information to derive one or more E2E keys. These keys are subsequently used to establish secure communication channels between the device and the service provider node, ensuring that all transmitted data remains protected against potential security threats.
[0250] If any updates or modifications occur in the key management policies, such as changes in encryption algorithms or E2E key expiration periods, the first node may repeat the method to provide updated E2E key messages to the device. This ensures that the security configurations remain up to date and effective.
[0251] For the execution of this method, mutual authentication between the first node and the device must have been performed. Both the first node and the device must possess the root key to enable the secure generation of E2E keys. This mutual authentication mechanism ensures that only authorized devices receive E2E key messages.
[0252] Upon completion of the process, the E2E key parameters have been successfully provided to the device, enabling it to securely generate E2E keys for future communication. The method constitutes an action to provision E2E key messages to the device, which can be called by a third node providing autonomous security services. The third node may facilitate network automation and security policy enforcement by managing E2E key provisioning actions.
[0253] The following paragraphs will describe an example NCDL of the action of provisioning of E2E connection key messages to the device.
[0254] Name of the action: Provision of E2E connection key messages to a device.
[0255] Purpose of the action: a device obtains E2E key messages that are used for the generation E2E connection keys, when a device wants a security protection on an E2E connection between a device and a NC.
[0256] Pre-condition of the action: a device subscribes an E2E connection (C / M, data) protection between the device and a service provider node (NC) . This action may be conducted when a mutual authentication between a device and a network has been successful and the first node has a root key (e.g., EMSK) . This action may also be conducted when a device updates E2E connection keys.
[0257] Post-condition of the action: a device obtains E2E connection key messages. Table 7 -Capability dimensions of the action “provision of E2E connection key messages to a device”
[0258] The parameters shown represent different capability dimensions (or fields) for the action of provisioning of E2E connection key messages to device.
[0259] The definitions of the capability dimensions illustrated in Table 7 are as follows: -Device identifier: indicates a name of the device to access the network. This can be a temporary name (STID) . -E2E protection information: indicates an E2E connection (C / M, data) protection between the device and a service provider. This can be an E2E connection C / M protection between the device the service provider or an E2E connection data protection between the device and the service provider. -Key parameters: indicates factors required for the E2E connection key generation. The values of the factors for the key generation are combinable, and they may include one or more of: an SQN, a XOR, the ID of the selected encryption algorithm, the ID of the selected integrity algorithm, a service provider ID, a connection ID and a service ID. -Root key identifier: this field indicates an ID of the root key to be used for key derivation, key encryption / decryption, e.g., 6gKSI, ID of EMSK.
[0260] Use of this NCDL: -This NCDL should be subscribed by a device / customer. -This NCDL is called when a device subscribes an E2E connection (C / M, data) protection between the device and a service provider node. This action may be conducted when a mutual authentication between the device and the network has been successful and the first node (SPM) has a root key (e.g., EMSK) . This action may also be conducted when a device updates E2E connection keys. -When called, the input should include a device name and an indication of security protection on E2E connection; the output should include key parameters and a root key ID. For example: -If a device selects an E2E connection C / M protection between the device and a service provider node, the key parameters could be SQN, XOR, ID of the selected encryption algorithm for E2E connection C / M protection, ID of the selected integrity algorithm for E2E connection C / M protection, NC ID, service ID or connection ID. -If a device selects a E2E connection C / M protection between device and a service provider node, the key parameters could be SQN, XOR, ID of the selected encryption algorithm for E2E connection data protection, ID of the selected integrity algorithm for E2E connection data protection, service provider ID, service ID or device-NC connection ID. -This action can be called by a third node (A-CAP) that is triggered by a device or other service providers. -The effect of this action is that a device obtains E2E connection key messages.
[0261] FIG. 10 provides an example of possible steps for configuring session keys, according to an exemplary method 1000. In this example, the first node may be a node in charge of managing service provisioning (i.e., service provisioning management (SPM) ) . This first node already has a subscription for the device, to ensure session protection between the device and a second node. The second node may be a node which controls C / M (Control and Management) plane gateways and / or DP (data plane) gateways of the network, and is labelled as NET4CON in FIG. 10. It is also understood that mutual authentication between the device and the first node has already been performed, and that both the first node and the device possess the root key. Finally, the first node must also have established and have access to a security profile of the device, which comprises one or more key information items selected by the device for protecting session communications between the device and the second node.
[0262] Method 1000 of FIG. 10 uses the actions of providing (or provisioning) the session keys to the second node, and of providing (or provisioning) the session key materials to the device, so that the device and the second node can communicate security with one another, based on the security settings selected by the device. These actions have been described previously in relation with FIGs. 4 and 5.
[0263] In this example, the first node transmits a session key message to the device and to the second node. The steps illustrated are performed after the device has updated one or more of the key information items it had previously selected. Here is a detailed description of each step presented in FIG. 10:
[0264] In step 1, the device sends the inputs required by the action for the provisioning of session key materials to the device, as in step 1010. The input may include the device ID and session key management information. The device ID can be a temporary identifier (e.g., STID) , and the session key management information may specify that the type of session security protection is for C / M protection between the device and a C / M gateway (which may also be referred to as a C / M-TW-GW) and for session data protection between the device and a Data gateway (DP-TW-GW) .
[0265] In step 2, the first node (SPM) implements the action of provisioning the session key materials to the device, as indicated in 1012.
[0266] In step 3, the first node (SPM) sends an output of the action, i.e. the first node sends the session key materials to the device, as in step 1014. The output may include the key materials and a key ID. If the device has selected a session C / M protection between the device and the C / M gateway, the key materials may include the following key parameters : a sequence number (SQN) , a scramble operation (XOR) , an identifier of the selected encryption algorithm for session C / M protection, and identifier of the selected integrity algorithm for session C / M protection, an identifier of the C / M gateway and a session downlink COUNT. If a device selects a session C / M protection between the device and DP gateway, the key parameters may include a sequence number (SQN) , a scramble operation (XOR) , an identifier of the selected encryption algorithm for session data protection, an identifier of the selected integrity algorithm for session data protection, an identifier of the DP gateway, and a session downlink COUNT.
[0267] In step 4, the first node (SPM) implements an action of providing the session key to the second node (NET4CON) 1016.
[0268] In step 5, the first node (SPM) sends a session key message to the second node, to provide (or provision) the session key to the second node (NET4CON) , as in step 1018. The information in the session key message includes to the output of the action. The output may include a C / M session-integrity protection algorithm, a C / M session-encryption protection algorithm, a data session-integrity protection algorithm, a data session-encryption protection algorithm and a key, such as a 6gKSI.
[0269] This example illustrates that leveraging a network capacity description language (NCDL) enhances the efficiency of exchanges between the device and the different network nodes.
[0270] FIG. 11 shows a schematic structural diagram of an apparatus according to one or more implementations of the present disclosure. As shown in FIG. 11, the apparatus 1101 may include: a receiving module 1101, configured to receive, from a second node, a request related to the management of an identifier of a device for one or more services, wherein the request comprises at least one operation to be performed by the first node; a processing module 1102, configured to manage the identifier of the device based on the request; a transmitting module 1103, configured to a response to the second node, wherein the response is based on the at least one operation performed by the first node.
[0271] FIG. 12 shows a schematic structural diagram of an apparatus according to one or more implementations of the present disclosure. As shown in FIG. 12, the apparatus 1200 may include: a receiving module 1201, configured to receive, from a second node, generate credentials for a device, the request comprising information including an identifier of the device, an authentication method and a corresponding algorithm; a processing module 1202, configured to generate the credentials for the device based on the information in the request; and a transmitting module 1203, configured to a response to the second node, wherein the response comprises the credentials generated for the device based on at least one of the identifiers of the device, the authentication method and the corresponding algorithm.
[0272] FIG. 13 shows a schematic structural diagram of an apparatus according to one or more implementations of the present disclosure. The apparatus may be a transmitting node or a receiving node. As shown in FIG. 13, the apparatus 1300 includes a processor 1301, an interface 1302 for communicating with other devices, a memory 1303 is coupled to the processor 1301. The memory 1303 may be stored with computer execution instructions, and the processor 1301 executes computer execution instructions stored in the memory 1303 to enable the apparatus to execute any of the above methods. In some implementations, the memory 1303 may be included or may not be included in the apparatus.
[0273] In some aspects of the present disclosure, there is provided an apparatus which includes a processor and a memory. The memory is storing instructions that cause the processor to perform any of the above methods.
[0274] It should be understood that the processor may be an integrated circuit chip and has a data processing capability. In an implementation process, steps of the foregoing method embodiments may be completed by using a hardware integrated logic circuit in the processor, or by using instructions in a form of software. The processor may be a general-purpose processor, a central processing unit (CPU) , a graphics processing unit (GPU) , a neural processing unit (NPU) , a system on chip (SoC) or another programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor may implement or perform the methods, the steps, and the logical block diagrams that are disclosed in the embodiments of the present disclosure. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor or the like. The steps of the methods disclosed with reference to the embodiments of the present disclosure may be directly performed and completed by a hardware decoding processor, or may be performed and completed by using a combination of hardware in the decoding processor and a software module. The software module may be located in a mature storage medium in the art, such as a random-access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, or a register. The storage medium is located in the memory, and the processor reads information in the memory and completes the steps of the foregoing methods in combination with hardware in the processor.
[0275] It may be understood that the memory in the embodiments of the present disclosure may be a volatile memory or a non-volatile memory, or may include both a volatile memory and a non-volatile memory. The non-volatile memory may be a read-only memory (Read-Only Memory, ROM) , a programmable read-only memory (Programmable ROM, PROM) , an erasable programmable read-only memory (Erasable PROM, EPROM) , an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) , or a flash memory. The volatile memory may be a random-access memory (Random Access Memory, RAM) and is used as an external cache. By way of example rather than limitation, many forms of RAMs may be used, and are, for example, a static random access memory (Static RAM, SRAM) , a dynamic random access memory (Dynamic RAM, DRAM) , a synchronous dynamic random access memory (Synchronous DRAM, SDRAM) , a double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDR SDRAM) , an enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM) , a synchronous link dynamic random access memory (Synchronous link DRAM, SLDRAM) , and a direct rambus random access memory (Direct Rambus RAM, DR RAM) .
[0276] It should be noted that the memory described in this specification includes but is not limited to these memories and could be a memory of any other appropriate type.
[0277] In some aspects of the present disclosure, there is provided a system, including apparatuses used to execute the steps in any of the above methods.
[0278] In some aspects of the present disclosure, there is provided a computing device cluster, including a processing circuitry for performing any of the above methods.
[0279] FIG. 13 shows a schematic diagram of an architecture of a computing device cluster according to one or more embodiments of the present disclosure. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0280] As shown in FIG. 14, the cluster of computing devices described includes at least one computing device 1400. As shown in FIG. 14, for each of the at least one computing device 1400, it includes a processor 1402, an interface 1404 and optional a memory 1406, where the processor 1402, the interface 1404 and the memory 1406 may be connected through a bus 1408. The memory 1406 in one or more of the computing devices 1400 in the cluster of computing devices can hold the same instructions, so that the processor 1402 executes the instructions to execute the method described in the above embodiments.
[0281] In some possible implementations, some of the instructions for performing the method described in the above embodiments can also be separately held in the memory 1406 of the one or more computing devices 1400 in the cluster of computing devices. In other words, a combination of the one or more computing devices 1400 can jointly execute instructions for performing the method described in the above embodiments.
[0282] It is noted that the memories 1406 in the different computing devices 1400 in the cluster of computing devices can store different instructions for performing some of the functions of the computing devices 1400, respectively.
[0283] In some possible implementations, one or more computing devices in a cluster of computing devices can be connected via a network. Among other things, the network can be a wide area network or a local area network, etc. FIG. 15 illustrates one possible implementation. FIG. 15 shows a schematic diagram of a connection between computing devices 1500A and 1500B over a network according to one or more embodiments of the present disclosure. As shown in FIG. 15, the computing device 1500A includes a processor 1502A, an interface 1504A and optional a memory 1506A, where the processor 1502A, the interface 1504A and the memory 1506A may be connected through a bus 1508A; the computing device 1500B includes a processor 1502B, an interface 1504B and optional a memory 1506B, where the processor 1502B, the interface 1504B and the memory 1506B may be connected through a bus 1508B. The memory 1506A and the memory 1506B may be stored with computer execution instructions, and the processor 1502A and the processor 1502B execute computer execution instructions stored in the memory 1506A and the memory 1506B to enable the computing devices 1500A and 1500B to execute any of the above methods. The two computing devices 1500A and 1500B are connected to each other via a network. Specifically, the connection to said network is made through a communication interface in each computing device. In this class of possible implementations, the memory 1506A in the computing device 1500A holds instructions for performing a part of the method described in the above embodiments. At the same time, the memory 1506B in the computing device 1500B holds instructions for performing other part (s) of the method described in the above embodiments.
[0284] The functions of computing device 1500A illustrated in FIG. 15 can also be accomplished by multiple computing devices. Similarly, the functions of computing device 1500B can be accomplished by multiple computing devices.
[0285] In some aspects of the present disclosure, there is provided a computer program product including computer execution instructions which, when executed by a processor, cause the processor to execute any of the above methods.
[0286] In some aspects of the present disclosure, there is provided a computer program including computer execution instructions which, when executed by a processor, cause the processor to execute any of the above methods.
[0287] In some aspects of the present disclosure, there is provided a computer-readable medium storing computer execution instruction which, when executed by a processor, cause the processor to execute any of the above methods.
[0288] In some aspects of the present disclosure, there is provided a chip, including an input / output (I / O) interface and a processor, where the processor is configured to call and run computer execution instructions stored in a memory, to enable a device installing with the chip to execute any of the above methods.
[0289] A person skilled in the art should understand that embodiments of this application may be provided as a method, an apparatus (or system) , computer-readable storage medium, or a computer program product. Therefore, this application may use a form of a hardware-only embodiment, a software-only embodiment, or an embodiment with a combination of software and hardware. Moreover, this application may use a form of a computer program product that is implemented on one or more computer-usable storage media (including but not limited to a disk memory, an optical memory, and the like) that include computer-usable program code.
[0290] Features disclosed herein in the context of any particular embodiments may also or instead be implemented in other embodiments. Method embodiments, for example, may also or instead be implemented in apparatus, system, and / or computer program product embodiments. In addition, although embodiments are described primarily in the context of methods and apparatus, other implementations are also contemplated, as instructions stored on one or more non-transitory computer-readable media, for example. Such media could store programming or instructions to perform any of various methods consistent with the present disclosure.
[0291] Although the present disclosure describes methods and processes with steps in a certain order, one or more steps of the methods and processes may be omitted or altered as appropriate. One or more steps may take place in an order other than that in which they are described, as appropriate.
[0292] Note that the expression “at least one of A or B” , as used herein, is interchangeable with the expression “Aand / or B” . It refers to a list in which you may select A or B or both A and B. Similarly, “at least one of A, B, or C” , as used herein, is interchangeable with “Aand / or B and / or C” or “A, B, and / or C” . It refers to a list in which you may select: A or B or C, or both A and B, or both A and C, or both B and C, or all of A, B and C. The same principle applies for longer lists having a same format.
[0293] Although the present disclosure is described, at least in part, in terms of methods, a person of ordinary skill in the art will understand that the present disclosure is also directed to the various components for performing at least some of the aspects and features of the described methods, be it by way of hardware components, software or any combination of the two. Accordingly, the technical solution of the present disclosure may be embodied in the form of a software product. A suitable software product may be stored in a pre-recorded storage device or other similar non-volatile or non-transitory computer readable medium, including DVDs, CD-ROMs, USB flash disk, a removable hard disk, or other storage media, for example. The software product includes instructions tangibly stored thereon that enable a processing device (e.g., a personal computer, a server, or a network device) to execute examples of the methods disclosed herein. The machine-executable instructions may be in the form of code sequences, configuration information, or other data, which, when executed, cause a machine (e.g., a processor or other processing device) to perform steps in a method according to examples of the present disclosure.
[0294] The present disclosure may be embodied in other specific forms without departing from the subject matter of the claims. The described example implementations are to be considered in all respects as being only illustrative and not restrictive. Selected features from one or more of the above-described implementations may be combined to create alternative implementations not explicitly described, features suitable for such combinations being understood within the scope of this disclosure.
[0295] All values and sub-ranges within disclosed ranges are also disclosed. Also, although the systems, devices and processes disclosed and shown herein may include a specific number of elements / components, the systems, devices and assemblies could be modified to include additional or fewer of such elements / components. For example, although any of the elements / components disclosed may be referenced as being singular, the implementations disclosed herein could be modified to include a plurality of such elements / components. The subject matter described herein intends to cover and embrace all suitable changes in technology.
[0296] Although implementations have been described above with reference to the accompanying drawings, those of skill in the art will appreciate that variations and modifications may be made without departing from the scope thereof as defined by the appended claims.
Claims
1.A method performed at a first node for providing a key management service, the method comprising:receiving, from a device, a request which includes identification information of the device and a request to negotiate key management information between the device and the first node;transmitting the key management information to the device; andreceiving negotiation results from the device, wherein the negotiation results comprise a selection of one or more key information items from the key management information received from the first node, wherein the one or more key information items include at least one of:one or more types of security protection;one or more levels related to one or more keys;respective expiration periods related to the one or more keys; andrespective identifiers of a plurality of protection algorithms.2.The method of claim 1, wherein the one or more types of security protection comprise at least one of: session protection between the device and a gateway; radio bearer protection between the device and a radio bearer handler; and end-to-end (E2E) protection between the device and a second node configured to provide one or more services to the device.3.The method of claim 2, wherein the radio bearer handler is a radio access network (RAN) node or a gNB.4.The method of claim 2, wherein the gateway is a control and management plane gateway or a data plane gateway.5.The method of any one of claims 1 to 4, wherein the one or more levels related to the one or more keys comprise at least one of: a key per device, a key per session, a key per end-to-end (E2E) connection, a key per service, a key per application, or a key per radio access network (RAN) .6.The method of any one of claims 1 to 5, wherein the plurality of protection algorithms includes encryption algorithms and / or integrity preservation algorithms.7.The method of any one of claims 1 to 6, wherein for execution of the method, the first node has a subscription of the device to a basic service or has received an update of the selection of the one or more key information items by the device.8.The method of any one of claims 1 to 7, wherein after execution of the method, a subscription of the device to the key management service is complete.9.The method of any one of claims 1 to 8, wherein the first node creates or updates a security profile associated with the device, based on the selection of the one or more key information items by the device.10.The method of any one of claims 1 to 9, wherein the method constitutes an action to subscribe the device to the key management service, the action being called by a third node which provides autonomous services.11.A method performed at a first node for providing a key management service, the method comprising:transmitting a session key message to a second node, wherein the session key message includes session key management information for protecting communications between a device and the second node, the session key management information in the session key message comprising at least one of:an identifier of the device;one or more types of session security protection;one or more levels related to one or more session keys;respective expiration periods related to the one or more session keys;one or more types of the one or more session keys; andan identifier of a root key.12.The method of claim 11, wherein the one or more types of security protection indicate if the protection is applied to communications between the device and a control and management plane gateway and / or to communications between the device and a data plane gateway.13.The method of claim 11 or 12, wherein the one or more levels related to the one or more session keys correspond to a session key per device; a session key per session, a session key per service or a session key per application.14.The method of any one of claims 11 to 13, wherein the one or more session keys comprise at least one of: a key for encrypting or decrypting session communications on the control and management plane, a key for encrypting or decrypting session communications on the data plane; a key for protecting integrity of session communications on the control and management plane; and a key for protecting integrity of session communications on the data plane.15.The method of any one of claims 11 to 14, wherein for execution of the method, the first node has established a security profile for the device which comprises one or more information items selected by the device for protecting session communications between the device and a control and management (C / M) plane gateway and / or session communications between the device and a data plane (DP) gateway.16.The method of any one of claims 11 to 15, wherein for execution of the method, mutual authentication between the device and the first node has been performed and the first node has the root key.17.The method of any one of claims 11 to 16, wherein after execution of the method, the session key management information related to the key management service has been provided to the second node.18.The method of any one of claims 11 to 17, wherein the first node performs the method when one or more key information items selected by the device for protecting communications at a session level between the device and the second node, have been updated.19.The method of any one of claims 11 to 18, wherein the second node is a node which controls control and management (C / M) gateways and / or data plane (DP) gateways of the network.20.The method of any one of claims 11 to 19, wherein the method constitutes an action to provide the session key management information to the second node, the action being called by a third node which provides autonomous services.21.A method performed at a first node for providing a key management service, the method comprising:transmitting a session key message to a device, wherein the session key message includes one or more session key parameters for protecting communications between the device and a second node at a session level and an identifier of a root key, wherein the one or more session key parameters enable the device to generate one or more session keys.22.The method of claim 21, wherein the first node has access to a security profile of the device which comprises:an identifier of the device for communicating with the device; andsession protection information indicating whether the device requires security protection on communications between the device and a control and management (C / M) plane gateway and / or communications between the device and a data plane (DP) gateway.23.The method of claim 21 or 22, wherein the one or more session key parameters comprise at least one of: a sequence number (SQN) ; a scramble operation (XOR) ; an encryption algorithm identifier for control and management (C / M) session protection; an integrity algorithm identifier for C / M session protection; a C / M gateway identifier, a session downlink count; a data plane (DP) gateway identifier; an encryption algorithm identifier for data session protection; an integrity preservation algorithm identifier for data session protection, and a service identifier.24.The method of any one of claims 21 to 23, wherein for execution of the method, mutual authentication between the device and the first node has been performed and both the first node and the device have the root key.25.The method of any one of claims 21 to 24, wherein after execution of the method, the one or more session key parameters have been provided to the device.26.The method of any one of claims 21 to 25, wherein the first node performs the method when one or more key information items selected by the device for protecting communications at the session level between the device and the second node, have been updated.27.The method of any one of claims 21 to 26, wherein the second node is a node which controls the control and management (C / M) gateways and / or data plane (DP) gateways of the network.28.The method of any one of claims 21 to 27, wherein the method constitutes an action to provide the one or more session key parameters to the device, the action being called by a third node which provides autonomous services.29.A method performed at a first node for providing a key management service, the method comprising:transmitting a radio bearer (RB) key message to an RB handler, wherein the RB key message includes RB key management information for protecting communications on an RB interface between a device and the RB handler, the RB key management information in the RB key message comprising at least one of:an identifier of the device;one or more types of RB security protection;one or more levels related to one or more RB keys;respective expiration periods related to the one or more RB keys;one or more types of the one or more RB keys; andan identifier of a root key.30.The method of claim 29, wherein the one or more types of the RB security protection indicate if the protection is to be applied on communications between the device and the RB handler for signalling messages on a control and management plane and / or on communications between the device and the RB handler for data on a data plane.31.The method of claim 29 or 30, wherein the one or more levels related to the one or more RB keys correspond to at least one of: an RB key per device; an RB key per Radio Access Network (RAN) node, an RB key per service or an RB key per application.32.The method of any one of claims 29 to 31, wherein the one or more RB keys comprise at least one of: a key for encrypting or decrypting RB communications on the control and management (C / M) plane, a key for encrypting or decrypting RB communications on the data plane; a key for protecting integrity of RB communications on the C / M plane; and a key for protecting integrity of RB communications on the data plane.33.The method of any one of claims 29 to 32, wherein for execution of the method, the first node has established a security profile for the device which comprises one or more key information items selected by the device for protecting communications between the device and the RB handler on the control and management (C / M) plane and / or on the data plane (DP) .34.The method of any one of claims 29 to 33, wherein prior to transmitting the RB key message, mutual authentication between the device and the first node has been performed, and the first node has the root key.35.The method of any one of claims 29 to 34, wherein after execution of the method, the one or more RB keys have been provided to the RB handler.36.The method of any one of claims 29 to 35, wherein the first node performs the method when one or more key information items selected by the device for protecting communications between the device and the RB handler, have been updated.37.The method of any one of claims 29 to 36, wherein the method constitutes an action to provide the one or more RB keys to the RB handler, the action being called by a third node which performs autonomous services.38.A method performed at a first node for providing a key management service, the method comprising:transmitting a radio bearer (RB) key message to a device, wherein the RB key message includes one or more RB key parameters for protecting communications between the device and a radio bearer (RB) handler, and an identifier of a root key, wherein the one or more RB key parameters enable the device to generate one or more RB keys.39.The method of claim 38, wherein the first node has established a security profile of the device which comprises:an identifier of the device for communicating with the device; andRB protection information indicating whether the device requires security protection on communications with the RB handler for signalling messages on a control and management (C / M) plane and / or for data on a data plane (DP) .40.The method of claim 38 or 39, wherein the one or more RB key parameters comprise at least one of: a sequence number (SQN) ; a scramble operation (XOR) ; an encryption algorithm identifier for protecting communications occurring on the control and management plane of the RB; an integrity preservation algorithm identifier for protecting communications on the control and management plane of the RB; an uplink session count; a Physical Cell Identifier (PCI) , a Next Hop (NH) , an encryption algorithm identifier for protecting communications on the data plane of the RB; an integrity preservation algorithm identifier for protecting communications on the data plane of the RB, a service identifier and an application identifier.41.The method of any one of claims 38 to 40, wherein for execution of the method, mutual authentication between the device and the first node has been performed and both the first node and the device have the root key.42.The method of any one of claims 38 to 41, wherein after execution of the method, the one or more RB key parameters have been provided to the device.43.The method of any one of claims 38 to 42, wherein the first node performs the method when one or more key information items selected by the device for protecting communications between the device and the RB handler, have been updated.44.The method of any one of claims 38 to 43, wherein the method constitutes an action to provide the one or more RB key parameters to the device, the action being called by a third node which provides autonomous services.45.A method performed at a first node for providing a key management service, the method comprising:transmitting an end-to-end (E2E) key message to a service provider node, wherein the E2E key message includes E2E key management information for protecting end-to-end communications between a device and the service provider node, the E2E key management information in the E2E key message comprising at least one of:an identifier of the device;one or more types of E2E security protection;one or more levels related to one or more E2E keys;respective expiration periods related to the one or more E2E keys;one or more types of the one or more E2E keys; andan identifier of a root key.46.The method of claim 45, wherein the one or more types of the E2E security protection indicate if the protection is to be applied on communications between the device and the service provider node for signalling messages on a control and management plane and / or between the device and the service provider node for data on a data plane.47.The method of claim 45 or 46, wherein the one or more levels related to the one or more E2E keys correspond to an E2E key per device; an E2E key per session, an E2E key per service or an E2E key per application.48.The method of any one of claims 45 to 47, wherein the one or more E2E keys comprise at least one of: a key for encrypting or decrypting end-to-end communications between the device and the service provider node on the control and management plane, a key for encrypting or decrypting end-to-end communications between the device and the service provider node on the data plane; a key for protecting integrity of end-to-end communications between the device and the service provider node on the control and management plane; and a key for protecting integrity of end-to-end communications between the device and the service provider node on the data plane.49.The method of any one of claims 45 to 48, wherein for execution of the method, mutual authentication between the device and the first node has been performed and the first node has the root key.50.The method of any one of claims 45 to 49, wherein the first node performs the method when one or more key information items selected by the device for protecting communications between the device and the service provider node, have been updated.51.The method of any one of claims 45 to 50, wherein the method constitutes an action to provide the one or more E2E key parameters to the service provider node, the action being called by a third node which provides autonomous services.52.A method performed at a first node for providing a key management service, the method comprising:transmitting an end-to-end (E2E) key message to a service provider node, wherein the E2E key message includes one or more E2E key parameters and an identifier of a root key, wherein the one or more E2E key parameters are used for protecting end-to-end communications associated with an E2E connection between a device and the service provider node and the one or more E2E key parameters enable the device to generate one or more E2E keys.53.The method of claim 52, wherein the first node has established a security profile of the device which comprises:an identifier of the device for communicating with the device; andE2E protection information indicating whether the device requires security protection on communications with the service provider node for signalling messages on a control and management (C / M) plane and / or for data on a data plane (DP) .54.The method of claim 52 or 53, wherein the one or more E2E key parameters comprise at least one of: a sequence number (SQN) ; a scramble operation (XOR) ; an encryption algorithm identifier for protecting communications occurring on a control and management plane of the E2E connection; an integrity algorithm identifier for protecting communications occurring on a control and management plane of the E2E connection; an identifier of the service provider node; an encryption algorithm identifier for protecting communications occurring on a data plane of the E2E connection; an integrity algorithm identifier protecting communications occurring on a data plane of the E2E connection; a service identifier and an identifier of the E2E connection.55.The method of any one of claims 52 to 54, wherein for execution of the method, mutual authentication between the device and the first node has been performed and both the device and the first node have the root key.56.The method of any one of claims 52 to 55, wherein the first node performs the method when one or more key information items selected by the device for protecting the E2E communications between the device and the service provider node, have been updated.57.The method of any one of claims 52 to 56, wherein the method constitutes an action to provide the one or more E2E key parameters to the device, the action being called by a third node which provides autonomous services.58.An apparatus, configured to perform the method according to any one of claims 1 to 10, the method according to any one of claims 11 to 20, the method according to any one of claims 21 to 28, the method according to any one of claims 29 to 37, the method according to any one of claims 38 to 44, the method according to any one of claims 45 to 51, or the method according to any one of claims 52 to 57.59.An apparatus comprising:one or more processors; andone or more memories storing instructions which, when executed by the one or more processors, cause the apparatus to perform the method according to any one of claims 1 to 10, the method according to any one of claims 11 to 20, the method according to any one of claims 21 to 28, the method according to any one of claims 29 to 37, the method according to any one of claims 38 to 44, the method according to any one of claims 45 to 51, or the method according to any one of claims 52 to 57.60.A computer program product comprising program code for performing the method according to any one of claims 1 to 10, the method according to any one of claims 11 to 20, the method according to any one of claims 21 to 28, the method according to any one of claims 29 to 37, the method according to any one of claims 38 to 44, the method according to any one of claims 45 to 51, or the method according to any one of claims 52 to 57.61.A computer program comprising computer execution instructions which, when executed by a processor, cause the processor to execute the method according to any one of claims 1 to 10, the method according to any one of claims 11 to 20, the method according to any one of claims 21 to 28, the method according to any one of claims 29 to 37, the method according to any one of claims 38 to 44, the method according to any one of claims 45 to 51, or the method according to any one of claims 52 to 57.62.A computer-readable medium storing computer execution instructions which, when executed by a processor, cause the processor to execute the method according to any one of claims 1 to 10, the method according to any one of claims 11 to 20, the method according to any one of claims 21 to 28, the method according to any one of claims 29 to 37, the method according to any one of claims 38 to 44, the method according to any one of claims 45 to 51, or the method according to any one of claims 52 to 57.63.A chip, comprising an input / output (I / O) interface and a processor, wherein the processor is configured to call and run a computer program stored in a memory, to enable a device installing with the chip to perform the method according to any one of claims 1 to 10, the method according to any one of claims 11 to 20, the method according to any one of claims 21 to 28, the method according to any one of claims 29 to 37, the method according to any one of claims 38 to 44, the method according to any one of claims 45 to 51, or the method according to any one of claims 52 to 57.
Citation Information
Patent Citations
Method, devices and system for performing key management
US20230308868A1
Systems and methods for key management
WO2022121285A1
Ciphertext policy attribute based encryption in 5g core service based interface
WO2024205145A1