Method and apparatus for establishing secure communication for an application

By generating AKMAID or RAND during the main authentication process, the problem of confusion in key generation and identification in the AKMA architecture is solved, and the secure communication reliability and system efficiency are improved between user equipment and service applications.

CN114766083BActive Publication Date: 2025-08-01ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202080082596.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-01-19
Publication Date
2025-08-01
Estimated Expiration
2040-01-19

AI Technical Summary

Technical Problem

When the existing AKMA architecture establishes secure communication between user equipment and service applications, key identification confusion may occur due to AUSF not generating AKMA keys or AUSF key identification errors.

Method used

Ensure the correct generation and management of keys by generating service application authentication and key management identifiers (AKMAID) or random numbers (RANDs) in authentication vectors during the main authentication process and establishing a secure communication session between user equipment and network nodes.

Benefits of technology

It improves the reliability of secure communication between user equipment and service applications, avoids key identification confusion and errors, and enhances the overall security and efficiency of wireless communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114766083B_ABST
    Figure CN114766083B_ABST
Patent Text Reader

Abstract

The present disclosure describes methods, systems, and devices for establishing secure communication between a user equipment and a service application in wireless communication. A method includes receiving, by a user equipment, a service application authentication and key management identifier (AKMAID) from an authentication server function (AUSF) upon successful completion of an authentication process for registering the user equipment with a communication network. The method further includes: storing, by the user equipment, the AKMAID; deriving, by the user equipment, an application key based on a basic authentication key; sending, by the user equipment, a communication request to the service application, the communication request including the AKMAID; and receiving, by the user equipment, an application session establishment response to the communication request from the service application to establish a secure communication session between the user equipment and the service application based on the application key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to wireless communication. In particular, the present disclosure relates to methods and devices for establishing secure communication for applications. Background Art

[0002] Wireless communication technologies are driving the world towards an increasingly interconnected and networked society. In a communication network, communication sessions and data paths can be established to support the transmission of data streams between terminal devices and service applications. The transmission of such data streams can be protected by encryption / decryption keys. During the registration process of authenticating a terminal device to a communication network and during the process of establishing a communication session between the terminal device and a service application, various levels of generation and validity management of encryption / decryption keys can be provided through the collaborative efforts of various network functions or network nodes in the communication network. Summary of the Invention

[0003] This document relates to methods, systems, and devices for wireless communication, and more particularly, to methods, systems, and devices for establishing secure communication for applications.

[0004] In one embodiment, the present disclosure describes a method for wireless communication. The method includes, when the authentication process for registering a user equipment to a communication network is successfully completed, receiving, by the user equipment from an Authentication Server Function (AUSF) network node, an Authentication and Key Management for Service Applications Identifier (AKMAID), and establishing secure communication between the user equipment and a service application in the communication network. The method further includes: storing, by the user equipment, the AKMAID; deriving, by the user equipment, an application key based on a basic authentication key; sending, by the user equipment, a communication request to the service application, the communication request including the AKMAID; and receiving, by the user equipment, an application session establishment response to the communication request from the service application to establish a secure communication session between the user equipment and the service application based on the application key.

[0005] In another embodiment, the present disclosure describes a method for wireless communication. The method includes: receiving an authentication vector from a user data management / authentication credential repository and processing function (UDM / ARPF) network node by an authentication server function (AUSF) network node, and establishing secure communication between a user equipment and a service application in a communication network. The method further includes storing, by the AUSF network node, a service application authentication and key management identifier (AKMAID); and sending, by the AUSF network node, the AKMAID to the user equipment when an authentication process for registering the user equipment with the communication network is successfully completed. Accordingly, the user equipment is configured to: store the AKMAID; derive an application key based on a basic authentication key; send a communication request to the service application, the communication request including the AKMAID; and receive, from the service application, an application session establishment response to the communication request to establish a secure communication session between the user equipment and the service application based on the application key.

[0006] In another embodiment, the present disclosure describes a method for wireless communication. The method includes establishing secure communication between a user equipment and a service application in a communication network by performing: an authentication process for registering the user equipment with the communication network by the user equipment using an authentication server function (AUSF) network node. The method further includes storing, by the user equipment, a random number (RAND) of an authentication vector when an authentication process for registering the user equipment with the communication network is successfully completed; deriving, by the user equipment, an application key based on a basic authentication key; sending, by the user equipment, a communication request to the service application, the communication request including the RAND; and receiving, by the user equipment, an application session establishment response to the communication request from the service application to establish a secure communication session between the user equipment and the service application based on the application key.

[0007] In another embodiment, the present disclosure describes a method for wireless communication. The method includes: receiving an authentication vector including a random number (RAND) from a user data management / authentication credential repository and processing function (UDM / ARPF) network node by an authentication server function (AUSF) network node to establish secure communication between a user equipment and a service application in a communication network; storing the RAND by the AUSF network node; and completing, by the AUSF network node, an authentication process for registering the user equipment with the communication network. Accordingly, the user equipment is configured to: store the RAND; derive an application key based on a basic authentication key; send a communication request including the RAND to the service application; and receive, from the service application, an application session establishment response to the communication request to establish a secure communication session between the user equipment and the service application based on the application key.

[0008] In some other embodiments, an apparatus for wireless communication may include a memory storing instructions and processing circuitry communicatively coupled to the memory. When the processing circuitry executes the instructions, the processing circuitry is configured to perform the above method.

[0009] In some other embodiments, a device for wireless communication may include a memory storing instructions and processing circuitry communicatively coupled to the memory. When the processing circuitry executes the instructions, the processing circuitry is configured to perform the above method.

[0010] In some other embodiments, a computer-readable medium includes instructions that, when executed by a computer, cause the computer to perform the above method.

[0011] The above and other aspects and their implementations are described in more detail in the drawings, the description, and the claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1A An example of a wireless communication system including one wireless network node and one or more user equipments is shown.

[0013] Figure 1B An exemplary communication network including a terminal device, a carrier network, a data network, and a service application is shown.

[0014] Figure 2 An example of a network node is shown.

[0015] Figure 3 An example of a user equipment is shown.

[0016] Figure 4 An example of a network function or network node in an authentication and key management (AKMA) architecture of a service application in a wireless communication network is shown.

[0017] Figure 5 Illustrates an exemplary logic flow for generating encryption keys at various levels for enabling encrypted communication between a terminal device and a service application in a wireless communication network.

[0018] Figure 6 Illustrates an exemplary logic flow of an embodiment for establishing secure communication between a user equipment and a service application in a communication network.

[0019] Figure 7A Illustrates an exemplary logic flow of an implementation for authentication and key management for completing authentication and generating an Application Key Management Application ID (AKMAID).

[0020] Figure 7B Illustrates an exemplary logic flow of another implementation for authentication and key management for completing authentication and generating an Application Key Management Application ID (AKMAID).

[0021] Figure 8 Illustrates an exemplary logic flow of an embodiment for establishing secure communication between a user equipment and a service application in a communication network.

[0022] Figure 9 Illustrates an exemplary logic flow of an embodiment for establishing secure communication between a user equipment and a service application in a communication network.

[0023] Figure 10 Illustrates an exemplary logic flow of an embodiment for establishing secure communication between a user equipment and a service application in a communication network.

[0024] Figure 11 Illustrates an exemplary logic flow of an embodiment for establishing secure communication between a user equipment and a service application in a communication network.

[0025] Figure 12 Illustrates an exemplary logic flow of an embodiment for establishing secure communication between a user equipment and a service application in a communication network.

[0026] Figure 13 Illustrates an exemplary logic flow of an embodiment for establishing secure communication between a user equipment and a service application in a communication network.

[0027] Figure 14 Illustrates an exemplary logic flow of an implementation for completing authentication and storing a random number (RAND) in an authentication vector.

[0028] Figure 15An exemplary logical flow of one embodiment for establishing secure communication between a user equipment and a service application in a communication network is shown. Detailed Description

[0029] The present disclosure will now be described in detail below with reference to the accompanying drawings, which form a part of the present disclosure and illustrate specific examples of embodiments by way of illustration. However, note that the present disclosure may be implemented in various different forms, and thus, the subject matter covered or claimed is intended to be construed as not limited to any one of the embodiments set forth below.

[0030] Throughout the specification and claims, terms may have subtle meanings that are suggested or implied in the context in addition to the explicitly stated meanings. Similarly, phrases such as "in one embodiment" or "in some embodiments" as used herein do not necessarily refer to the same embodiment, and phrases such as "in another embodiment" or "in other embodiments" as used herein do not necessarily refer to different embodiments. Phrases such as "in one implementation" or "in some implementations" as used herein do not necessarily refer to the same implementation, and phrases such as "in another implementation" or "in other implementations" as used herein do not necessarily refer to different implementations. For example, the claimed subject matter is intended to include, in whole or in part, combinations of exemplary embodiments or implementations.

[0031] Generally speaking, terms can be understood at least in part from their usage in context. For example, terms such as "and", "or", or "and / or" as used herein can include multiple meanings, which can at least in part depend on the context in which these terms are used. Generally, "or" if used to relate a list (such as A, B, or C) is intended to mean A, B, and C (used in an inclusive sense here), as well as A, B, or C (used in an exclusive sense here). Additionally, terms such as "one or more" or "at least one" as used herein (at least in part depending on the context) can be used to describe any feature, structure, or property in a singular sense, or can be used to describe a combination of features, structures, or properties in a plural sense. Similarly, terms such as "a", "an", or "the" can also be understood to convey a singular usage or convey a plural usage, which at least in part depends on the context. Additionally, the terms "based on" or "determined by" can be understood as not necessarily intended to convey an exclusive set of factors, and can alternatively allow for the presence of additional factors that are not necessarily explicitly described, which also at least in part depends on the context.

[0032] The present disclosure describes methods and devices for establishing secure communication for applications in a communication network.

[0033] The Authentication and Key Management for Service Applications (AKMA) framework can be used to support one or more user equipment (UEs) in establishing and conducting secure communication sessions between one or more UEs and one or more service applications. One or more UEs can securely exchange data with one or more service applications. The service applications can be located in one or more application servers.

[0034] In the current AKMA architecture, AKMA authentication can be generated by authentication between the UE and the network. Such authentication between the UE and the network can include primary / access authentication. There can be two sets of key identifiers associated with the keys used when establishing a secure transmission between the UE and the network. One set includes the AKMA key (K AKMA ), and the corresponding identifier of the AKMA key. The other set includes the Authentication Server Function (AUSF) key (AUSF key, or K AUSF ), and the corresponding identifier of the AUSF key.

[0035] Several problems can occur in the current AKMA architecture. As an example, when the UE uses the identifier of the AKMA key in a request for a service application to establish secure communication, a problem occurs if the AUSF does not generate the AKMA key and the AUSF does not respond correctly with the received identifier of the AKMA key. As another example, when the identifier of the AUSF key is used in a request to establish secure communication, another problem can occur if the AKMA key has been derived, and the identifier of the AUSF key can be used to identify the AKMA key, resulting in a situation where one key identifier identifies two different keys.

[0036] This disclosure describes methods and devices for establishing secure communication for applications in a communication network, solving at least some of the problems discussed above. In one implementation of solving the above problems, the identifier generated during the primary authentication process can be used by the UE and the network for the application session establishment process. For example but not limited to, the identifier generated during the primary authentication process can include the Service Application Authentication and Key Management Identifier (AKMAID) or the random number (RAND) in the authentication vector. Optionally and additionally, the AKMA key or the application key can be pre-derived or derived on demand.

[0037] Figure 1AFIG. 100 shows a wireless communication system 100 including a wireless network node 118 and one or more user equipments (UEs) 110. The wireless network node may include a base station, which may be a nodeB (NB, such as an eNB or a gNB) in a mobile telecommunications scenario. Each of the UEs may communicate wirelessly with the wireless network node via one or more wireless channels 115. For example, the first UE 110 may communicate wirelessly with the wireless network node 118 via a channel including multiple wireless channels during a specific time period.

[0038] Figure 1B FIG. 4 shows an example of a communication system 100. The communication system 100 may include one or more terminal devices 110 (e.g., user equipments), a carrier network 102, various service applications 140, and other data networks 150. For example, the carrier network 102 may include an access network 120 and a core network 130. The carrier network 102 may be configured to transmit voice, data, and other information (collectively referred to as data traffic) between the terminal device 110 and the carrier network 102, between the terminal device 110 and the service applications 140, or between the terminal device 110 and other data networks 150. Communication sessions and corresponding data paths may be established and configured for such data transmission. The access network 120 may be configured to provide network access to the core network 130 for the terminal device 110. The core network 130 may include various network nodes or network functions configured to control communication sessions and perform network access management and data traffic routing. The service applications 140 may be hosted by various application servers accessible to the terminal device 110 through the core network 130 of the carrier network 102. One or more service applications 140 may be deployed as data networks external to the core network 130. Similarly, other data networks 150 may be accessed by the terminal device 110 through the core network 130, and the other data networks 150 may appear as data destinations or data sources for a specific communication session instantiated in the carrier network 102.

[0039] The core network 130 of FIG. 1 may include various network nodes or functions that are geographically distributed and interconnected to provide network coverage of the service area of the carrier network 102. These network nodes or functions may be implemented as dedicated hardware network elements. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or as software entities. Each network node may be configured with one or more types of network functions. These network nodes or network functions may jointly provide the provisioning and routing functions of the core network 130. The terms "network node" and "network function" may be used interchangeably in the present disclosure.

[0040] Figure 2An example of an electronic device 200 implementing a network node is shown. The example electronic device 200 may include wireless transmit / receive (Tx / Rx) circuitry 208 to transmit / receive communications with a UE and / or other base stations. The electronic device 200 may also include network interface circuitry 209 to communicate the base station with other base stations and / or a core network (e.g., optical or wired interconnections, Ethernet, and / or other data transmission media / protocols). The electronic device 200 may optionally include an input / output (I / O) interface 206 to communicate with an operator, etc.

[0041] The electronic device 200 may also include system circuitry 204. The system circuitry 204 may include one or more processors 221 and / or a memory 222. The memory 222 may include an operating system 224, instructions 226, and parameters 228. The instructions 226 may be configured for one or more of the processors 124 to perform the functions of the network node. The parameters 228 may include parameters that support the execution of the instructions 226. For example, the parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.

[0042] Figure 3An example of an electronic device for implementing a terminal device 300 (e.g., a user equipment (UE)) is shown. The UE 300 can be a mobile device, e.g., a smart phone or a mobile communication module installed in a vehicle. The UE 300 can include a communication interface 302, a system circuitry 304, an input / output interface (I / O) 306, a display circuitry 308, and a storage device 309. The display circuitry can include a user interface 310. The system circuitry 304 can include any combination of hardware, software, firmware, or other logic / circuitry. The system circuitry 304 can be implemented, for example, using one or more system-on-chips (SoCs), application-specific integrated circuits (ASICs), discrete analog and digital circuits, and other circuitry. The system circuitry 304 can be part of the implementation of any desired function in the UE 300. In this regard, the system circuitry 304 can include, for example, logic for facilitating the following: decoding and playing music and videos, such as MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user input; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections, as an example, for Internet connectivity; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on the user interface 310. The user interface 310 and the input / output (I / O) interface 306 can include a graphical user interface, a touch-sensitive display, haptic feedback or other haptic output, voice or facial recognition input, buttons, switches, speakers, and other user interface elements. Other examples of the I / O interface 306 can include a microphone, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headphone and microphone input / output jacks, universal serial bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors), and other types of inputs.

[0043] Reference Figure 3, the communication interface 302 may include radio frequency (RF) transmit (Tx) and receive (Rx) circuitry 316 that processes the transmission and reception of signals via one or more antennas 314. The communication interface 302 may include one or more transceivers. A transceiver may be a wireless transceiver that includes modulation / demodulation circuitry, a digital to analog converter (DAC), shaping tables, an analog to digital converter (ADC), filters, waveform shapers, filters, preamplifiers, power amplifiers, and / or other logic for transmission and reception via one or more antennas or (for some devices) via a physical (e.g., wired) medium. The signals transmitted and received may conform to any of a variety of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM), frequency channels, bit rates, and codings. As a specific example, the communication interface 302 may include transceivers that support transmission and reception under 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA)+, 4G / Long Term Evolution (LTE), and 5G standards. However, the techniques described below apply to other wireless communication technologies whether originating from the 3rd Generation Partnership Project (3GPP), GSM Association, 3GPP2, IEEE, or other partners or standards bodies.

[0044] Reference Figure 3 , the system circuitry 304 may include one or more processors 321 and a memory 322. The memory 322 stores, for example, an operating system 324, instructions 326, and parameters 328. The processor 321 is configured to execute the instructions 326 for implementing the desired functions of the UE 300. The parameters 328 may provide and specify configuration and operation options for the instructions 326. The memory 322 may also store any BT, WiFi, 3G, 4G, 5G, or other data that the UE 300 will transmit or has received via the communication interface 302. In various embodiments, the system power of the UE 300 may be provided by a power storage device such as a battery or a transformer.

[0045] Figure 4 An exemplary AKMA architecture in a wireless communication system 400 is shown. The wireless communication system 400 may include a user equipment (UE) 410 (operating as the Figure 1B terminal device 110), a wireless network 403, and one or more service applications (AF) 460. In one embodiment, the wireless network 403 may be a part of the core network 130, as Figure 1B shown.

[0046] The wireless network 403 may include an access management function (AMF) 420. The AMF may include a security anchor function (SEAF), collectively referred to as AMF / SEAF.

[0047] The wireless network 403 may include an authentication server function (AUSF) 430. The AUSF may act as an authentication network node (AUNN).

[0048] The wireless network 403 may include a universal data management (UDM) function 440. The UDM may act as a network data management network node (NDMNN). In one implementation, the UDM may be referred to as user data management. In another implementation, the UDM may be referred to as unified data management.

[0049] Reference Figure 4 , the UDM 440 may form a permanent storage or database for user contracts and subscription data. The UDM may include an authentication credential repository and processing function (ARPF) for storing long-term security credentials for user authentication and for performing the calculation of encryption keys using such long-term security credentials as input, as described in more detail below. To prevent unauthorized opening of UDM / ARPF data, the UDM / ARPF 430 may be located in a secure network environment. In one implementation, the UDM / ARPF may not be directly and easily accessible by service applications or user equipment.

[0050] Reference Figure 4, the wireless network 403 may further include an AKMA Anchor Function (AAnF) network node 450. The AAnF 450 may cooperate with the AUSF 430 and one or more Application Functions (AFs) 460 associated with their corresponding service applications, and is responsible for generating and managing data encryption / decryption keys for various service applications. The AAnF 450 may also be responsible for maintaining the security context of the UE 410. For example, the function of the AAnF 450 may be similar to the Bootstrapping Server Function (BSF) in the General Bootstrapping Architecture (GBA). Multiple AAnF 450s may be deployed in the core network, and each AAnF 380 may be associated with one or more service applications and the corresponding AF 460 and is responsible for the key management of one or more service applications and the corresponding AF 460. In one embodiment, the wireless network 403 may include a Network Exposure Function (NEF) as a gateway for providing the exposure of the core network capabilities to the AF 460 associated with the service application. In another embodiment, the AKMA architecture may include an AKMA Authentication Function (AAuF) and / or an AKMA Application Function (AApF).

[0051] Figure 5An exemplary embodiment of the above - hierarchical AKMA is shown, and an embodiment 500 for generating a basic key and an anchor key for a communication session involving a service application and generating an application key associated with the service application to enable encrypted communication between the UE 410 and the corresponding AF 460 is described. Specifically, embodiment 500 may include a user authentication process 502 and an anchor key generation process 504. For example, the user authentication process 502 may involve actions from the UE 410, AMF / SEAF 420, AUSF 430, and UDM / ARPF 440. For example, when the UE 410 enters the wireless communication network, it may transmit a network registration and authentication request to the AMF / SEAF 420. Such a request may be forwarded by the AMF / SEAF 420 to the AUSF 430 for processing. During the authentication process, the AUSF 430 may obtain user contract and subscription information from the UDM / ARPF 440. For example, the authentication process of the 5G wireless system may be based on the 5G - AKA (Authentication and Key Agreement) protocol or EAP - AKA (Extensible Authentication Protocol - AKA). The authentication vector (AV) may be generated by the UDM / ARPF 440, and such an authentication vector may be transmitted to the AUSF 430. After a successful user authentication process 502, a basic key may be generated at both the UE 410 side and the AUSF 430 on the network side. Such a basic key may be referred to as a basic authentication key (e.g., AUSF key or K AUSF )

[0052] As Figure 5 further shown, in the anchor key generation process 510, the UE 410 may derive an anchor key based on the basic key. Such an anchor key may be referred to as an AKMA key (K AKMA ) ID In the identity generation process 512, an identity of the anchor key may be generated at the UE 410. Such an identity may be referred to as K

[0053] Referring Figure 5 , on the network side, in the anchor key generation process 520, the AUSF 430 may derive an anchor key based on the basic key. Such an anchor key may be referred to as an AKMA key (K AKMA ) ID In the identity generation process 522, an identity of the anchor key may be generated at the AUSF 430. Such an identity may be referred to as K

[0054] Referring Figure 5 , in step 542, the UE 410 initiates a communication session with the service application associated with the AF 460 by sending a communication request message. The request may include the identity K ID, and the anchor key K generated in step 510 AKMA In step 543, AF 460 may send a key request message to AAnF 450, wherein the key request message includes the anchor key identifier K ID and / or AF logo (AF ID In step 544, the AAnF 450 determines the anchor key identifier K ID The associated anchor key K AKMA Can it be located in AAnF 450? When it is determined that K is found in AAnF 450 AKMA , the logic flow continues to step 546; when it is determined that K is not found in AAnF 450 AKMA When the anchor key identifier K is set to 544, the AAnF 450 may send the AUSF 430 a packet carrying the anchor key identifier K. ID In response to the anchor key request from AAnF 450, AUSF 430 identifies the anchor key K ID Identification anchor key K AKMA Thereafter, the AAnF 450 receives the anchor key K from the AUSF 430 in step 545. AKMA In step 546, if K has not been previously derived at AAnF 450 AF or K AF has expired, then AAnF 430 is based on the anchor key K AKMA Export application key (K AF The derived K AKMA The AAnF 450 may send the application key K to the AF 460 in step 547. AF and the corresponding expiry time. AKMA Afterwards, in step 542, AF 460 may finally respond to the communication request sent from UE 410. For example, the response in step 548 may include K AF The expiration time may be recorded and stored by the UE 410.

[0055] In the AKMA architecture, the anchor key generation process 510 may not occur at approximately the same time as the anchor key generation process 520; and / or the identity generation process 512 may not occur at the same time as the identity generation process 522. ID And K has not yet been derived at AUSF 430 AKMA / K ID A problem may arise when, for example, AUSF 430 has not yet derived KAKMA and / or K ID During step 544, a problem may occur: when the AUSF 430 receives an anchor key request with K ID , the AUSF 430 may not recognize K ID , such that the AUSF 430 may be unable to retrieve K ARMA , because K ID and / or K ARMA has not been derived yet because step 520 and / or step 522 have not occurred yet.

[0056] The present disclosure describes several embodiments that can be implemented in a network communication system to solve at least some of the described problems. To solve the above problems, the identities generated during the primary authentication process can be used by the UE and the network for the application session establishment process. For example but not limited to, the identities generated during the primary authentication process can include the Service Application Authentication and Key Management Identity (AKMAID) or the random number (RAND) in the authentication vector. Optionally and additionally, the AKMA key or the application key can be pre-derived or derived on demand.

[0057] Example #1

[0058] The present disclosure describes embodiments of methods and devices for establishing secure communication between a user equipment and a service application in a communication network.

[0059] Figure 6 An exemplary logical flow of a method 600 for establishing secure communication between a user equipment and a service application in a communication network is shown. Method 600 may include step 610: successfully completing authentication and generating a service application authentication process and a key management identity (AKMAID). The authentication process can be the primary authentication process for registering the UE 410 with the communication network.

[0060] Figure 7A and Figure 7B Two alternative and / or substitutable implementations of step 610 are described.

[0061] In Figure 7A one implementation, step 610 may include step 611: the UDM / ARPF 440 generates an authentication vector (AV) and an AKMAID. In one implementation, the AKMAID can be generated based on the identity of the UE 410 and time (e.g., the time of the network). In another implementation, the AKMAID can be generated as a random number. The validity period of the AKMAID cannot be shorter than (i.e., longer than or equal to) the time interval between consecutive authentication processes.

[0062] Referring toFigure 7A , step 610 may include some or all of the following steps: Step 612: The UDM / ARPF network node 440 sends an authentication vector and an AKMA ID to the AUSF network node 430; Step 613: The AUSF network node 430 stores the AKMA ID in a storage device (e.g., a memory or a hard disk drive); Step 614: Perform an authentication process; Step 615: When the authentication is successful, the AUSF 430 sends the AKMA ID to the UE 410; and Step 616: The UE 410 stores the AKMA ID.

[0063] In Figure 7B In another embodiment, step 610 may include some or all of the following steps: Step 611-1: The UDM / ARPF 440 generates an authentication vector (AV); Step 612-1: The UDM / ARPF network node 440 sends the authentication vector to the AUSF network node 430; Step 613-1: Perform an authentication process; Step 614-1: When the authentication is successful, the AUSF network node 430 generates an AKMA ID; Step 615-1, the AUSF 430 sends the AKMA ID to the UE 410; and Step 616-1: The UE 410 stores the AKMA ID. In one embodiment, the AKMA ID may be generated based on the identity of the UE 410 and time (e.g., the time of the network). In another embodiment, the AKMA ID may be generated as a random number. The validity period of the AKMA ID cannot be shorter than (i.e., longer than or equal to) the time interval between consecutive authentication processes.

[0064] Referring back to Figure 6 , the method 600 may further include step 620: The UE 410 derives an anchor key (e.g., an AKMA key) based on a basic authentication key (e.g., an AUSF key) in the UE 410, and derives an application key (e.g., an AF key) based on the anchor key. The basic authentication key in the UE 410 may be obtained by the UE 410 during the authentication process.

[0065] Referring to Figure 6 , the method 600 may further include step 625: The AUSF 430 derives an anchor key (e.g., an AKMA key) based on a basic authentication key (e.g., an AUSF key) in the AUSF 430. The basic authentication key in the AUSF 430 may be obtained by the AUSF 430 during the authentication process. In one embodiment, step 625 may not occur substantially simultaneously with step 620, but occurs before step 640, as described below.

[0066] The method 600 may include some or all of the following steps.

[0067] Step 630: The UE 410 sends a communication request to the service application (AF) 460, and the communication request includes the AKMAID.

[0068] Step 632: When the AF 460 receives the communication request from the UE 410, it determines whether the service application has a pre-shared application key for the user equipment.

[0069] In response to determining that the service application does not have a pre-shared application key for the user equipment, Step 635: The AF 460 sends a first request for an application key to the AKMA anchor function (AAnF) network node 450, and the first request includes the AKMAID; Step 637: When the AAnF network node 450 receives the first request, it determines whether the AAnF network node 450 has an anchor key for the AKMAID; In response to determining that the AAnF network node 450 does not have an anchor key for the AKMAID: Step 640: The AAnF 450 sends a second request for an application key to the AUSF network node 430, the second request includes the AKMAID, and Step 642: When the AUSF network node 430 receives the second request, it retrieves the anchor key in the AUSF network node according to the AKMAID, and Step 645: Sends the anchor key to the AAnF network node, and the anchor key in the AUSF network node is pre-derived by the AUSF network node based on the basic authentication key in the AUSF network node; Step 650: The AAnF network node 450 derives the application key based on the anchor key; Step 655: The AAnF network node 450 sends response information to the AF 460, and the response information includes the application key and the parameter of the application key validity period.

[0070] Step 660: The AF sends an application session establishment response to the UE 410. Therefore, the UE 410 receives an application session establishment response to the communication request from the AF 460 to establish a secure communication session between the UE 410 and the AF 460 based on the application key (K AF )

[0071] Example #2

[0072] This disclosure describes another embodiment of a method and apparatus for establishing secure communication between a user equipment and a service application in a communication network. Figure 8 An exemplary logical flow of a method 800 for establishing secure communication between a user equipment and a service application in a communication network is shown.

[0073] The method 800 may include Step 610: Successfully complete authentication and generate a service application authentication process and a key management identifier (AKMAID).

[0074] Reference Figure 8 ,The method 800 may further include step 820: The UE 410 derives an anchor key (e.g., AKMA key) based on a basic authentication key (e.g., AUSF key) in the UE 410, and derives an application key (e.g., AF key) based on the anchor key. The basic authentication key in the UE 410 may be obtained by the UE 410 during the authentication process.

[0075] Reference Figure 8 ,The method 800 may further include step 825: The AUSF 430 derives an anchor key (e.g., AKMA key) based on a basic authentication key (e.g., AUSF key) in the AUSF 430, and derives an application key (e.g., AF key) based on the anchor key. The basic authentication key in the AUSF 430 may be obtained by the AUSF 430 during the authentication process. In one embodiment, step 825 may not occur substantially simultaneously with step 820, but occurs before step 840, as described below.

[0076] The method 800 may include some or all of the following steps.

[0077] Step 830: The UE 410 sends a communication request to the service application (AF) 460, and the communication request includes an AKMA ID.

[0078] Step 832: When receiving the communication request from the UE 410, the AF 460 determines whether the service application has a pre-shared application key for the user equipment.

[0079] In response to determining that the service application does not have a pre-shared application key for the user equipment, step 835: The AF 460 sends a first request for an application key to the AKMA anchor function (AAnF) network node 450, and the first request includes an AKMA ID.

[0080] Step 840: The AAnF 450 sends a second request for an application key to the AUSF network node 430, and the second request includes an AKMA ID.

[0081] Step 842: When receiving the second request, the AUSF network node 845 retrieves the application key in the AUSF network node according to the AKMA ID. The application key in the AUSF network node is pre-derived by the AUSF network node based on a pre-derived anchor key in the AUSF network node.

[0082] Step 8C45: The AUSF network node 845 sends the application key and parameters of the application key validity period to the AAnF network node.

[0083] Step 855: The AAnF network node 450 sends response information to the AF 460, and the response information includes an application key and an application key validity period parameter.

[0084] Step 860: The AF sends an application session establishment response to the UE 410. Therefore, the UE 410 receives an application session establishment response to the communication request from the AF 460 to establish a secure communication session between the UE 410 and the AF 460 based on the application key (K AF ).

[0085] Example #3

[0086] This disclosure describes another embodiment of a method and apparatus for establishing secure communication between a user equipment and a service application in a communication network. Figure 9 An exemplary logical flow of a method 900 for establishing secure communication between a user equipment and a service application in a communication network is shown. In this embodiment, the AUSF network node 430 may derive an anchor key (e.g., an AKMA key) "on demand" (i.e., when receiving a request from the AAnF 450).

[0087] Method 900 may be slightly different from Figure 6 method 600 therein: in method 900, deriving the anchor key (e.g., an AKMA key) in step 942 occurs after step 640; in contrast, in method 600, deriving the anchor key (e.g., an AKMA key) in step 625 occurs before step 640.

[0088] Step 942 may include that the AUSF network node 430, when receiving a second request, retrieves a basic authentication key (e.g., an AUSF key) in the AUSF network node according to the AKMAID, and derives an anchor key (e.g., an AKMA key) based on the basic authentication key (e.g., an AUSF key) in the AUSF 430. The basic authentication key in the AUSF 430 may be obtained by the AUSF 430 during the authentication process.

[0089] Other steps in method 900 may refer to Figure 6 method 600 described therein.

[0090] Example #4

[0091] This disclosure describes another embodiment of a method and apparatus for establishing secure communication between a user equipment and a service application in a communication network. Figure 10 An exemplary logical flow of a method 1000 for establishing secure communication between a user equipment and a service application in a communication network is shown.

[0092] Method 1000 may be slightly different from Figure 8 method 800 therein: In method 1000, the derivation of the anchor key (e.g., AKMA key) and the application key (e.g., KAF) occurs after step 1042; in contrast, in method 800, the derivation of the anchor key (e.g., AKMA key) and the application key (e.g., KAF) occurs before step 840.

[0093] Step 1042 may include that when the AUSF network node 430 receives the second request, it retrieves the basic authentication key (e.g., AUSF key) in the AUSF network node according to the AKMA ID, and derives the anchor key (e.g., AKMA key) based on the basic authentication key (e.g., AUSF key) in the AUSF 430; and derives the application key (e.g., K AF ). The basic authentication key in the AUSF 430 may be obtained by the AUSF 430 during the authentication process.

[0094] Other steps in method 1000 may refer to Figure 8 method 800 described therein.

[0095] Example #5

[0096] This disclosure describes another embodiment of a method and apparatus for establishing secure communication between a user equipment and a service application in a communication network. Figure 11 An exemplary logic flow of method 1100 for establishing secure communication between a user equipment and a service application in a communication network is shown. In this embodiment, the application key (e.g., K AF ) may be directly derived based on the basic authentication key (e.g., AUSF key); and the AUSF 430 may derive the application key (e.g., K AF ) as needed.

[0097] Method 1100 may be slightly different from Figure 10 method 1000 therein: In method 1100, in steps 1120 and 1142, the application key (e.g., K AF ) is derived based on the basic authentication key (e.g., AUSF key); in contrast, in method 1000, in steps 820 and 1042, the application key (e.g., K AF ) is derived based on the anchor key (e.g., AKMA key).

[0098] Step 1120 may include the UE 410 deriving an application key (e.g., AF key) based on a basic authentication key (e.g., AUSF key) in the UE 410. The basic authentication key in the UE 410 may be obtained by the UE 410 during the authentication process.

[0099] Step 1142 may include the AUSF network node 430 retrieving a basic authentication key (e.g., AUSF key) in the AUSF network node according to the AKMAID when receiving a second request, and deriving an application key (e.g., AKMA key) based on the basic authentication key (e.g., AUSF key) in the AUSF 430. The basic authentication key in the AUSF 430 may be obtained by the AUSF 430 during the authentication process.

[0100] Other steps in method 1100 may refer to Figure 10 method 1000 described in

[0101] Example #6

[0102] This disclosure describes another embodiment of a method and apparatus for establishing secure communication between a user equipment and a service application in a communication network. Figure 12 An exemplary logic flow of a method 1100 for establishing secure communication between a user equipment and a service application in a communication network is shown. In this embodiment, the application key (e.g., K AF ) may be directly derived based on a basic authentication key (e.g., AUSF key); and the AUSF 430 may derive the application key (e.g., K AF ). In this disclosure, "pre-derived key" may refer to "deriving a key before receiving a request for the key".

[0103] Method 1200 may be slightly different from Figure 8 method 800 in: in method 1200, in steps 1220 and 1225, an application key (e.g., K AF ) is derived based on a basic authentication key (e.g., AUSF key); differently, in method 800, in steps 820 and 825, an application key (e.g., K AF ) is derived based on an anchor key (e.g., AKMA key).

[0104] Step 1220 may include the UE 410 deriving an application key (e.g., AF key) based on a basic authentication key (e.g., AUSF key) in the UE 410. The basic authentication key in the UE 410 may be obtained by the UE 410 during the authentication process.

[0105] Step 1225 may include the AUSF network node 430 deriving an application key (e.g., K AF ) based on a basic authentication key in the AUSF 430 (e.g., the AUSF key). The basic authentication key in the AUSF 430 may be obtained by the AUSF 430 during the authentication process.

[0106] Other steps in method 1200 may refer to Figure 8 method 800 described in

[0107] Example #7

[0108] This disclosure describes embodiments of methods and apparatuses for establishing secure communication between a user equipment and a service application in a communication network. Figure 13 An exemplary logical flow of method 1300 for establishing secure communication between a user equipment and a service application in a communication network is shown.

[0109] There are some differences between method 1300 and Figure 11 method 1100 in Figure 11 . One difference is that different identifiers are used for the application session establishment process: the random number (RAND) of the authentication vector is used as the identifier in method 1300; in contrast, the service application authentication and key management identifier (AKMAID) is used as the identifier in method 1100 in

[0110] Method 1300 may include step 1310: successful authentication by the UE 410 and by the AUSF 430 and storing the RAND. The authentication process may be the primary authentication process for registering the UE 410 with the communication network.

[0111] Figure 14 One implementation of step 1310 is described. Step 1310 may include step 1311: the UDM / ARPF 440 generating an authentication vector (AV). The AV may have one or more elements, and the RAND is one element of the AV. In one implementation, the RAND may be generated as a random number. In another implementation, the authentication vector generated by the UDM / ARPF 440 may include, for example, an authentication token (AUTN), a random number (RAND), and / or various authentication keys. The AKMA service subscription information of the UE may include, for example, the identifiers of one or more AAnFs and / or the valid time period of the AKMA anchor key.

[0112] Referring back to Figure 13 , method 1300 may also include some or all of the following steps.

[0113] Step 1320: The UE 410 derives an application key (e.g., AF key) based on a basic authentication key (e.g., AUSF key) in the UE 410. The basic authentication key in the UE 410 can be obtained by the UE 410 during the authentication process.

[0114] Step 1330: The UE 410 sends a communication request to the service application (AF) 460, and the communication request includes RAND.

[0115] Step 1332: When receiving the communication request from the UE 410, the AF 460 determines whether the service application has a pre-shared application key for the user equipment.

[0116] In response to determining that the service application does not have a pre-shared application key for the user equipment, Step 1335: The AF 460 sends a first request for an application key to the AKMA anchor function (AAnF) network node 450, and the first request includes RAND.

[0117] Step 1340: The AAnF 450 sends a second request for an application key to the AUSF network node 430, and the second request includes RAND.

[0118] Step 1342: Step 1325: When receiving the second request, the AUSF 430 retrieves the basic authentication key (e.g., AUSF key) in the AUSF 430 according to RAND. The basic authentication key in the AUSF 430 can be obtained by the AUSF 430 during the authentication process.

[0119] Step 1345: The AUSF network node 845 sends the application key and the parameters of the application key validity period to the AAnF network node.

[0120] Step 1355: The AAnF network node 450 sends response information to the AF 460, and the response information includes the application key and the application key validity period parameters.

[0121] Step 1360: The AF sends an application session establishment response to the UE 410. Therefore, the UE 410 receives an application session establishment response to the communication request from the AF 460 to establish a secure communication session between the UE 410 and the AF 460 based on the application key (K AF ).

[0122] Example #8

[0123] This disclosure describes another embodiment of a method and apparatus for establishing secure communication between a user equipment and a service application in a communication network. Figure 15An exemplary logical flow of method 1500 for establishing secure communication between a user equipment and a service application in a communication network is shown.

[0124] Method 1500 may be different from Figure 13 method 1300 in AF : In method 1500, an anchor key (e.g., AKMA key) and an application key (e.g., K AF ) are derived in step 1520, an anchor key (e.g., AKMA key) is derived in step 1542, and an application key (e.g., K AF ) is derived in step 1550; differently, in method 1300, an application key (e.g., K AF ) is derived in step 1320, and an application key (e.g., K AF ) is derived in step 1342.

[0125] Step 1520 may include that UE 410 derives an anchor key (e.g., AKMA key) based on a basic authentication key (e.g., AUSF key) in UE 410, and derives an application key (e.g., AF key) based on the anchor key. The basic authentication key in UE 410 may be obtained by UE 410 during the authentication process.

[0126] Step 1542 may include that when receiving a second request, AUSF network node 430 retrieves a basic authentication key (e.g., AUSF key) in the AUSF network node according to RAND, and derives an anchor key (e.g., AKMA key) based on the basic authentication key (e.g., AUSF key) in AUSF 430. The basic authentication key in AUSF 430 may be obtained by AUSF 430 during the authentication process.

[0127] Step 1545 may include that AUSF network node 430 sends the anchor key to AAnF network node 450.

[0128] Step 1550 may include that AAnF network node 450 derives an application key based on the anchor key.

[0129] Other steps in method 1500 may refer to Figure 13 method 1300 described in

[0130] This disclosure describes methods, apparatuses, and computer-readable media for wireless communication. This disclosure solves the problem of establishing secure communication between a user equipment and a service application in a communication network. The methods, devices, and computer-readable media described in this disclosure can promote the performance of secure communication and enhance the security of wireless communication, thereby improving efficiency and overall performance. The methods, devices, and computer-readable media described in this disclosure can improve the overall efficiency of a wireless communication system.

[0131] References to features, advantages, or similar language throughout this specification do not imply that all features and advantages that can be realized by the present solution should or are included in any single embodiment of the present solution. On the contrary, the language referring to features and advantages is understood to mean that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, throughout this specification, the discussion of features and advantages and similar language may, but does not necessarily, refer to the same embodiment.

[0132] In addition, in one or more embodiments, the features, advantages, and characteristics of the present solution may be combined in any suitable manner. Given the description herein, those of ordinary skill in the relevant art will recognize that the present solution may be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized that may not exist in all embodiments of the present solution.

Claims

1. A method for wireless communication, comprising: Establishing secure communication between a user equipment and a service application in a communication network by performing the following: When the authentication process for registering the user equipment with the communication network is successfully completed, the user equipment receives a service application authentication and key management identifier (AKMAID) from an authentication server function (AUSF) network node; The user equipment stores the AKMAID; The user equipment derives an application key based on a basic authentication key by: The user equipment derives an anchor key based on the basic authentication key, and The user equipment derives the application key based on the anchor key; The user equipment sends a communication request to the service application, the communication request including the AKMAID; And The user equipment receives an application session establishment response to the communication request from the service application to establish a secure communication session between the user equipment and the service application based on the application key, Wherein, When receiving the communication request from the user equipment, the service application determines whether the service application has a pre-shared application key for the user equipment; In response to determining that the service application does not have a pre-shared application key for the user equipment, the service application sends a first request for the application key to an AKMA anchor function (AAnF) network node, the first request including the AKMAID; When receiving the first request, the AAnF network node sends a second request for the application key to the AUSF network node, the second request including the AKMAID.

2. The method according to claim 1, wherein: A user data management / authentication credential repository and processing function (UDM / ARPF) network node generates an authentication vector and the AKMAID; The UDM / ARPF network node sends the authentication vector and the AKMAID to the AUSF network node; and The AUSF network node stores the AKMAID in a storage device.

3. The method according to claim 1, wherein: A user data management / authentication credential repository and processing function (UDM / ARPF) network node generates an authentication vector; The UDM / ARPF network node sends the authentication vector to the AUSF network node; And The AUSF network node generates the AKMAID and stores the AKMAID in a storage device when the authentication process for registering the user equipment with the communication network is successfully completed.

4. The method according to any one of claims 2 to 3, wherein: The AKMAID is generated based on the identifier of the user equipment and time, or is generated as a random number; and The validity period of the AKMAID is longer than or equal to the time interval between consecutive authentication processes.

5. The method according to claim 1, wherein: The AAnF network node sending the second request for the application key to the AUSF network node includes: When the AAnF network node receives the first request, it determines whether the AAnF network node has an anchor key for the AKMAID; and in response to determining that the AAnF network node does not have an anchor key for the AKMAID: the AAnF network node sends a second request for the application key to the AUSF network node, the second request including the AKMAID; When the AUSF network node receives the second request, it retrieves the anchor key in the AUSF network node according to the AKMAID, and sends the anchor key to the AAnF network node, where the anchor key in the AUSF network node is pre-derived by the AUSF network node based on the basic authentication key in the AUSF network node; The AAnF network node derives the application key based on the anchor key; The AAnF network node sends response information to the service application, the response information including the application key and parameters of the application key validity period; and The service application sends the application session establishment response to the user equipment.

6. The method according to claim 1, wherein: When the AUSF network node receives the second request, it retrieves the application key in the AUSF network node according to the AKMAID, where the application key in the AUSF network node is pre-derived by the AUSF network node based on the pre-derived anchor key in the AUSF network node; The AUSF network node sends the application key and parameters of the application key validity period to the AAnF network node; The AAnF network node sends response information to the service application, the response information including the application key and parameters of the application key validity period; And The service application sends the application session establishment response to the user equipment.

7. The method according to claim 1, wherein: The AAnF network node sending a second request for the application key to the AUSF network node includes: When the AAnF network node receives the first request, it determines whether the AAnF network node has an anchor key for the AKMAID; and in response to determining that the AAnF network node does not have an anchor key for the AKMAID: the AAnF network node sends a second request for the application key to the AUSF network node, the second request including the AKMAID; When the AUSF network node receives the second request, it retrieves the basic authentication key in the AUSF network node according to the AKMAID, and derives the anchor key based on the basic authentication key in the AUSF network node, and The AUSF network node sends the anchor key to the AAnF network node; The AAnF network node derives the application key based on the anchor key; The AAnF network node sends response information to the service application, the response information including the application key and parameters of the application key validity period; and The service application sends the application session establishment response to the user equipment.

8. The method according to claim 1, wherein: When receiving the second request, the AUSF network node retrieves the basic authentication key in the AUSF network node according to the AKMAID, derives an anchor key based on the basic authentication key in the AUSF network node, and derives an application key based on the anchor key; The AUSF network node sends the application key and the parameter of the application key validity period to the AAnF network node; The AAnF network node sends response information to the service application, and the response information includes the application key and the parameter of the application key validity period; and The service application sends the application session establishment response to the user equipment.

9. The method according to claim 1, wherein: When receiving the second request, the AUSF network node retrieves the basic authentication key in the AUSF network node according to the AKMAID, and derives an application key based on the basic authentication key in the AUSF network node; The AUSF network node sends first response information to the service application, and the first response information includes the application key and the parameter of the application key validity period; The AAnF network node sends second response information to the service application, and the second response information includes the application key and the parameter of the application key validity period; and The service application sends the application session establishment response to the user equipment.

10. The method according to claim 1, wherein: When receiving the second request, the AUSF network node retrieves the application key in the AUSF network node according to the AKMAID, and the application key is pre-derived based on the basic authentication key in the AUSF network node; The AUSF network node sends first response information to the service application, and the first response information includes the application key and the parameter of the application key validity period; The AAnF network node sends second response information to the service application, and the second response information includes the application key and the parameter of the application key validity period; and The service application sends the application session establishment response to the user equipment.

11. A method for wireless communication, comprising: Establishing secure communication between a user equipment and a service application in a communication network by performing the following: Receiving, by an authentication server function AUSF network node, an authentication vector from a user data management / authentication credential repository and processing function UDM / ARPF network node; Storing, by the AUSF network node, a service application authentication and key management identifier AKMAID; and When the authentication process for registering the user equipment with the communication network is successfully completed, sending, by the AUSF network node, the AKMAID to the user equipment, such that the user equipment is configured to: Store the AKMAID, Derive an application key based on a basic authentication key, Send a communication request to the service application, the communication request including the AKMAID, and Receive an application session establishment response to the communication request from the service application to establish a secure communication session between the user equipment and the service application based on the application key, wherein, When receiving the communication request from the user equipment, the service application determines whether the service application has a pre-shared application key for the user equipment; In response to determining that the service application does not have the pre-shared application key for the user equipment, the service application sends a first request for the application key to the AKMA anchor function AAnF network node, the first request including the AKMAID, When receiving the first request, the AAnF network node sends a second request for the application key to the AUSF network node, the second request including the AKMAID, The application key is derived by the user equipment based on the anchor key, The anchor key is derived by the user equipment based on the basic authentication key.

12. The method according to claim 11, further comprising: The AUSF network node receives the AKMAID from the UDM / ARPF network node together with receiving the authentication vector for storage, the authentication vector and the AKMAID being generated by the UDM / ARPF network node.

13. The method according to claim 11, wherein: When the authentication process for registering the user equipment with the communication network is successfully completed, the AUSF network node generates the AKMAID.

14. The method according to any one of claims 12 to 13, wherein: The AKMAID is generated based on the identification and time of the user equipment or is generated as a random number; and The validity period of the AKMAID is longer than or equal to the time interval between consecutive authentication processes.

15. The method according to claim 11, wherein: The AAnF network node sending the second request for the application key to the AUSF network node includes: When receiving the first request, the AAnF network node determines whether the AAnF network node has an anchor key for the AKMAID; and in response to determining that the AAnF network node does not have an anchor key for the AKMAID: the AAnF network node sends a second request for the application key to the AUSF network node, the second request including the AKMAID, and The method further comprises: The AUSF network node receives the second request for the application key from the AAnF network node, The AUSF network node retrieves the anchor key in the AUSF network node according to the AKMAID in the second request, the anchor key in the AUSF network node being pre-derived by the AUSF network node based on the basic authentication key in the AUSF network node, and The AUSF network node sends the anchor key to the AAnF network node. The AAnF network node derives an application key based on the anchor key; The AAnF network node sends response information to the service application, where the response information includes the application key and parameters of the application key validity period; and The service application sends the application session establishment response to the user equipment.

16. The method according to claim 11, wherein: The method further includes: The AUSF network node receives a second request for the application key from the AAnF network node, The AUSF network node retrieves the application key in the AUSF network node according to the AKMAID in the second request, and the application key in the AUSF network node is pre-derived by the AUSF network node based on a pre-derived anchor key in the AUSF network node, and The AUSF network node sends the application key and parameters of the application key validity period to the AAnF network node; The AAnF network node sends response information to the service application, where the response information includes the application key and parameters of the application key validity period; and The service application sends the application session establishment response to the user equipment.

17. The method according to claim 11, wherein: The AAnF network node sending a second request for the application key to the AUSF network node includes: When receiving the first request, the AAnF network node determines whether the AAnF network node has an anchor key for the AKMAID; and in response to determining that the AAnF network node does not have an anchor key for the AKMAID: the AAnF network node sends a second request for the application key to the AUSF network node, and the second request includes the AKMAID, and The method further includes: The AUSF network node receives a second request for the application key from the AAnF network node, The AUSF network node retrieves the basic authentication key in the AUSF network node according to the AKMAID, derives an anchor key based on the basic authentication key in the AUSF network node, and The AUSF network node sends the anchor key to the AAnF network node; The AAnF network node derives an application key based on the anchor key; The AAnF network node sends response information to the service application, where the response information includes the application key and parameters of the application key validity period; and The service application sends the application session establishment response to the user equipment.

18. The method according to claim 11, wherein: The method further includes: The AUSF network node receives a second request for the application key from the AAnF network node, The AUSF network node retrieves the basic authentication key in the AUSF network node according to the AKMAID, derives an anchor key based on the basic authentication key in the AUSF network node, and derives an application key based on the anchor key, and The AUSF network node sends the parameters of the application key and the application key validity period to the AAnF network node; The AAnF network node sends response information to the service application, and the response information includes the parameters of the application key and the application key validity period; and The service application sends the application session establishment response to the user equipment.

19. The method according to claim 11, wherein: The method further includes: The AUSF network node receives a second request for the application key from the AAnF network node, The AUSF network node retrieves the basic authentication key in the AUSF network node according to the AKMAID, and derives the application key based on the basic authentication key in the AUSF network node, and The AUSF network node sends first response information to the service application, and the first response information includes the parameters of the application key and the application key validity period; The AAnF network node sends second response information to the service application, and the second response information includes the parameters of the application key and the key validity period; and The service application sends the application session establishment response to the user equipment.

20. The method according to claim 11, wherein: The method further includes: The AUSF network node receives a second request for the application key from the AAnF network node, The AUSF network node retrieves the application key in the AUSF network node according to the AKMAID, and the application key is pre-derived based on the basic authentication key in the AUSF network node, and The AUSF network node sends first response information to the service application, and the first response information includes the parameters of the application key and the application key validity period; The AAnF network node sends second response information to the service application, and the second response information includes the parameters of the application key and the key validity period; and The service application sends the application session establishment response to the user equipment.

21. A method for wireless communication, including: Establishing secure communication between a user equipment and a service application in a communication network by performing the following: The user equipment transmits an authentication process for registering the user equipment with the communication network using an Authentication Server Function (AUSF) network node; When the authentication process for registering the user equipment with the communication network is successfully completed, the user equipment stores the random number RAND of the authentication vector; The user equipment derives an application key based on a basic authentication key by: The user equipment derives an anchor key based on the basic authentication key, and The user equipment derives the application key based on the anchor key; The user equipment sends a communication request to the service application, and the communication request includes the RAND; And The user equipment receives an application session establishment response to the communication request from the service application to establish a secure communication session between the user equipment and the service application based on the application key. Wherein, When receiving the communication request from the user equipment, the service application determines whether the service application has a pre-shared application key for the user equipment; In response to determining that the service application does not have the pre-shared application key for the user equipment, the service application sends a first request for the application key to the AKMA anchor function AAnF network node, and the first request includes the RAND; When receiving the first request, the AAnF network node sends a second request for the application key to the AUSF network node, and the second request includes the RAND.

22. The method according to claim 21, wherein: The user data management / authentication credential repository and processing function UDM / ARPF network node generates an authentication vector including the RAND; The UDM / ARPF network node sends the authentication vector for the authentication process to the AUSF network node; and The AUSF network node stores the RAND when receiving the authentication vector.

23. The method according to claim 21, wherein: When receiving the second request, the AUSF network node retrieves the basic authentication key in the AUSF network node according to the RAND and derives an application key based on the basic authentication key in the AUSF network node; The AUSF network node sends first response information to the service application, and the first response information includes the application key and parameters of the application key validity period; The AAnF network node sends second response information to the service application, and the second response information includes the application key and parameters of the application key validity period; And The service application sends the application session establishment response to the user equipment.

24. The method according to claim 21, wherein: When receiving the second request, the AUSF network node retrieves the basic authentication key in the AUSF network node according to the RAND and derives an anchor key based on the basic authentication key; The AUSF network node sends the anchor key to the AAnF network node; When receiving the anchor key, the AAnF network node derives an application key based on the anchor key; The AAnF network node sends response information to the service application, and the response information includes the application key and parameters of the application key validity period; And The service application sends the application session establishment response to the user equipment.

25. A method for wireless communication, including: Establishing secure communication between a user equipment and a service application in a communication network by performing the following: The authentication server function AUSF network node receives an authentication vector including a random number RAND from the user data management / authentication credential repository and processing function UDM / ARPF network node. The RAND is stored by the AUSF network node; and the AUSF network node completes an authentication process for registering the user equipment to the communication network, such that the user equipment is configured to: store the RAND, derive an application key based on a basic authentication key, send a communication request to the service application, the communication request including the RAND, and receive an application session establishment response to the communication request from the service application to establish a secure communication session between the user equipment and the service application based on the application key, wherein, when receiving the communication request from the user equipment, the service application determines whether the service application has a pre-shared application key for the user equipment; in response to determining that the service application does not have the pre-shared application key for the user equipment, the service application sends a first request for the application key to the AKMA anchor function AAnF network node, the first request including the RAND; when receiving the first request, the AAnF network node sends a second request for the application key to the AUSF network node, the second request including the RAND, the application key is derived by the user equipment based on an anchor key, the anchor key is derived by the user equipment based on the basic authentication key.

26. The method according to claim 25, wherein: the UDM / ARPF network node generates an authentication vector including the RAND; and the UDM / ARPF network node sends the authentication vector for the authentication process to the AUSF network node.

27. The method according to claim 25, the method further comprising: the AUSF network node receives the second request for the application key from the AAnF network node, the AUSF network node retrieves the basic authentication key in the AUSF network node according to the RAND, and derives an application key based on the basic authentication key in the AUSF network node, and the AUSF network node sends first response information to the service application, the first response information including the application key and parameters of the application key validity period; the AAnF network node sends second response information to the service application, the second response information including the application key and parameters of the key validity period; and the service application sends the application session establishment response to the user equipment.

28. The method according to claim 25, the method further comprising: the AUSF network node receives the second request for the application key from the AAnF network node, the AUSF network node retrieves the basic authentication key in the AUSF network node according to the RAND in the second request, the AUSF network node derives an anchor key based on the basic authentication key in the AUSF network node, and the AUSF network node sends the anchor key to the AAnF network node; the AAnF network node derives an application key based on the anchor key; The AAnF network node sends response information to the service application, and the response information includes parameters of the application key and the application key validity period; and the service application sends the application session establishment response to the user equipment.

29. A wireless communication device, the wireless communication device includes a processor and a memory, wherein the processor is configured to read code from the memory and implement the method according to any one of claims 1 to 28.

30. A computer program product, the computer program product includes computer-readable program medium code stored thereon, and the code, when executed by a processor, causes the processor to implement the method according to any one of claims 1 to 28.